sssd-client-debuginfo-2.9.4-4.el8_10 > 6 6_6 3!pQp)Tξ7]mtZ`f1 ]mtZ`}ĉt^%8HՆk{"'"fNSTjXT tNgzbGH:g^5l[rin0O:l|(H$w,V%D:*MR ea?7>d-\z#De|di7#5VMY|/߲ȉCw/}N7"Ѻ6JuR2tw+NF:RƜQP% $ȹu"Zy{0 MȜ\mX6l$-ɀoleʞ't[fM}$ߟBbw#ٖQE(DUJcX*Q(f2,qAZ7q35ܧM$T-x>qʋ9 4c>@ETOL;^wa|q]m04c7e7ad4102a7b2659a87b367cbcfe6f6b0fbd485c876d1ab4d6412a2449b6ffda191d444bd0963a075f3069741007d30921b23Ą3!pQp)Tξ7]mtZ`f1 ]mtZ` %ZZ_vaݬ$ \3 1_,Ey Z7γEIӐ .;n2>a\T+;pZ meTZ~I_u9 uŌ@'}q!6uSAգ%Ň']fEPJ' vo $h "l.&KBVf'E)Z30/5_! JRf+_ܶkh[p`u@ Af2'OJ̥ vo.^ބRPp>? % O48=CK i{+T+ + + + +  + + k+ B `+ t(89:jJG+H+I,+XX Y \+]+^#bdeflt+u+vH w+x8+y#48>sssd-client-debuginfo2.9.44.el8_10Debug information for package sssd-clientThis package provides debug information for package sssd-client. Debug information is useful when developing applications that use this package or when debugging this package.f3ord1-prod-a64build004.svc.aws.rockylinux.orgKojiRockyLGPLv3+infrastructure@rockylinux.orgDevelopment/Debughttps://github.com/SSSD/sssdlinuxaarch64<W<S<n<[<`<l<S<ts([HK@10h(AAAAAAAAAAAA큤AAA큤A큤A큤AA큤f)f,f,f,f,f,f,f,f,f,f,f,f,f,f,f,f,f,f,f,f,f,f,f,f,ffffffffffffffffff800a3473962d7a3e530ceefa15ca2fc7f62e5556016078221886ff090e170c1e124607184e947019145731e97d5aed90e15315a1a58db26dc1b4e33d6241be33693651176d9d762bb8f9657efe5896a67ad180066ee3685f539c3237c5c95ca423f1deb93e4f403a77be8017514fad911a21892fcc0cd10a1bbc0dc6001a7ad63e6230265eae0869131e234a4fedc355fa9fe335ed86c600d94754bae7d4ba113a3ca12a5ecc3d56a088459c2431ecc24f730195ad6ca08e0bf5c750e7e3ca0cfa807d984e09056f31a9cbcf1fbe5ede7527b01f8475a2b2e3d6fa0c077fc05654e98c8244ca8983f2553a50f926144c479b0238512f3b2d86474d80061ab81b../../../.build-id/11/ec91aba82e0a208d1e6ba9156d1c4fbadb502d../../../../../usr/lib/debug/usr/lib64/security/pam_sss.so-2.9.4-4.el8_10.aarch64.debug../../../.build-id/1f/f629fa781a228d0804a2316e7074da5ab016a0../../../../../usr/lib/debug/usr/lib64/libnss_sss.so.2-2.9.4-4.el8_10.aarch64.debug../../../.build-id/20/93b3d10c5c4e0f9cff01945d460733b9c2c30a../../../../../usr/lib/debug/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so-2.9.4-4.el8_10.aarch64.debug../../../.build-id/35/b096b83d239d9786fed764a879406df97f4df6../../../../../usr/lib/debug/usr/lib64/security/pam_sss_gss.so-2.9.4-4.el8_10.aarch64.debug../../../.build-id/84/6244286f55d2377ccd7aeb4f7babe3c4729073../../../../../usr/lib/debug/usr/lib64/cifs-utils/cifs_idmap_sss.so-2.9.4-4.el8_10.aarch64.debug../../../.build-id/8e/8dbe8cd7b5d2ee999f31b6c20634c341d31d4f../../../../../usr/lib/debug/usr/lib64/krb5/plugins/authdata/sssd_pac_plugin.so-2.9.4-4.el8_10.aarch64.debug../../../.build-id/a7/9268b7ec30b673f84ddfa2233964d9cb625456../../../../../usr/lib/debug/usr/lib64/libsubid_sss.so-2.9.4-4.el8_10.aarch64.debug../../../.build-id/db/cfa83fc5eab2cc95c978aea5ce840ba6b2bc0a../../../../../usr/lib/debug/usr/lib64/krb5/plugins/libkrb5/sssd_krb5_locator_plugin.so-2.9.4-4.el8_10.aarch64.debugrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.4-4.el8_10.src.rpmdebuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)sssd-client-debuginfosssd-client-debuginfo(aarch-64)    rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sssd-debuginfo(aarch-64)3.0.4-14.6.0-14.0-15.2-12.9.4-4.el8_104.14.3fGFf! @e@e{@eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.4-4Alexey Tikhonov - 2.9.4-3Alexey Tikhonov - 2.9.4-2Alexey Tikhonov - 2.9.4-1Alexey Tikhonov - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-33957 - ad: refresh root domain when read directly- Resolves: RHEL-27205 - Race condition during authorization leads to GPO policies functioning inconsistently- Resolves: RHEL-25064 - AD users are unable to log in due to case sensitivity of user because the domain is found as an alias to the email address. [rhel-8] - Resolves: RHEL-25066 - gdm smartcard login fails with sssd-2.9.3 in case of multiple identities [rhel-8] - Resolves: RHEL-25065 - ssh pubkey stored in ldap/AD no longer works to authenticate via sssd [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-1680 - auto_private_groups does not create cache in IPA server SSSD cache - Resolves: RHEL-10092 - logfile rotation for sssd_kcm not working properly, sssd_kcm never receives a 'kill -HUP' - Resolves: RHEL-17495 - New sssd.conf seems not to be backwards compatible (wrt SmartCard auth of local users using 'files provider') - Resolves: RHEL-18431 - Excessive logging to sssd_nss and sssd_be in multi-domain AD forest - Resolves: RHEL-5033 - Incorrect IdM product name in man sssd.conf - Resolves: RHEL-15368 - SSSD GPO lacks group resolution on hosts [rhel-8] - Resolves: RHEL-10721 - very bad performance when requesting service tickets - Resolves: RHEL-19011 - Invalid handling groups from child domain - Resolves: RHEL-19949 - latest sssd breaks logging in via XDMCP for LDAP/Kerberos users [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+11ec91aba82e0a208d1e6ba9156d1c4fbadb502d1ff629fa781a228d0804a2316e7074da5ab016a02093b3d10c5c4e0f9cff01945d460733b9c2c30a35b096b83d239d9786fed764a879406df97f4df6846244286f55d2377ccd7aeb4f7babe3c47290738e8dbe8cd7b5d2ee999f31b6c20634c341d31d4fa79268b7ec30b673f84ddfa2233964d9cb625456dbcfa83fc5eab2cc95c978aea5ce840ba6b2bc0a2.9.4-4.el8_102.9.4-4.el8_10     debug.build-id11ec91aba82e0a208d1e6ba9156d1c4fbadb502dec91aba82e0a208d1e6ba9156d1c4fbadb502d.debug1ff629fa781a228d0804a2316e7074da5ab016a0f629fa781a228d0804a2316e7074da5ab016a0.debug2093b3d10c5c4e0f9cff01945d460733b9c2c30a93b3d10c5c4e0f9cff01945d460733b9c2c30a.debugb096b83d239d9786fed764a879406df97f4df6b096b83d239d9786fed764a879406df97f4df6.debug846244286f55d2377ccd7aeb4f7babe3c47290736244286f55d2377ccd7aeb4f7babe3c4729073.debug8e8dbe8cd7b5d2ee999f31b6c20634c341d31d4f8dbe8cd7b5d2ee999f31b6c20634c341d31d4f.debuga79268b7ec30b673f84ddfa2233964d9cb6254569268b7ec30b673f84ddfa2233964d9cb625456.debugdbcfa83fc5eab2cc95c978aea5ce840ba6b2bc0acfa83fc5eab2cc95c978aea5ce840ba6b2bc0a.debugusrlib64cifs-utilscifs_idmap_sss.so-2.9.4-4.el8_10.aarch64.debugkrb5pluginsauthdatasssd_pac_plugin.so-2.9.4-4.el8_10.aarch64.debuglibkrb5sssd_krb5_locator_plugin.so-2.9.4-4.el8_10.aarch64.debuglibnss_sss.so.2-2.9.4-4.el8_10.aarch64.debuglibsubid_sss.so-2.9.4-4.el8_10.aarch64.debugsecuritypam_sss.so-2.9.4-4.el8_10.aarch64.debugpam_sss_gss.so-2.9.4-4.el8_10.aarch64.debugsssdmodulessssd_krb5_localauth_plugin.so-2.9.4-4.el8_10.aarch64.debug/usr/lib//usr/lib/debug//usr/lib/debug/.build-id//usr/lib/debug/.build-id/11//usr/lib/debug/.build-id/1f//usr/lib/debug/.build-id/20//usr/lib/debug/.build-id/35//usr/lib/debug/.build-id/84//usr/lib/debug/.build-id/8e//usr/lib/debug/.build-id/a7//usr/lib/debug/.build-id/db//usr/lib/debug/usr//usr/lib/debug/usr/lib64//usr/lib/debug/usr/lib64/cifs-utils//usr/lib/debug/usr/lib64/krb5//usr/lib/debug/usr/lib64/krb5/plugins//usr/lib/debug/usr/lib64/krb5/plugins/authdata//usr/lib/debug/usr/lib64/krb5/plugins/libkrb5//usr/lib/debug/usr/lib64/security//usr/lib/debug/usr/lib64/sssd//usr/lib/debug/usr/lib64/sssd/modules/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnu directoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=846244286f55d2377ccd7aeb4f7babe3c4729073, with debug_info, not strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8e8dbe8cd7b5d2ee999f31b6c20634c341d31d4f, with debug_info, not strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=dbcfa83fc5eab2cc95c978aea5ce840ba6b2bc0a, with debug_info, not strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=1ff629fa781a228d0804a2316e7074da5ab016a0, with debug_info, not strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a79268b7ec30b673f84ddfa2233964d9cb625456, with debug_info, not strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=11ec91aba82e0a208d1e6ba9156d1c4fbadb502d, with debug_info, not strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=35b096b83d239d9786fed764a879406df97f4df6, with debug_info, not strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2093b3d10c5c4e0f9cff01945d460733b9c2c30a, with debug_info, not strippedPPPPPPPPsssd-debugsource(aarch-64)2.9.4-4.el8_10utf-8e561940740b91eb0ae7e8a863619f7ca24c39f4f436c02e482b9cc029c26b2df? 7zXZ !#,O] b2u jӫ`(y0DiiEၲ&n&`t&!7Q,ȕӃRu0MQ%X8C$Ueo&P-0Lv[Gu=E6ؑ<6\SXÚ)ˋ8<G}/[gS1`o^{1Pl%* }BA&-B髂S;~S{k=!/Jt9C0ZHS7NSIL6u+~=>g$BlM syx0G-rRRն G+DƀXT\7mxdW0k߯u;^1 l@C!gjoq:wϋ8[兒_`DE+5<ƿ jGާБrh3vP kv^?i]L3k`=ʈ+XNX2BВ^$QO-}͙1 `Z.$) jc-_Vew! v9y8KKyD |1r֮k6;[%&X,kܯfMl7y3ߧGbRW B7W'y'R hYJ6aL¿>UBk8F ϓfwzaۿ 5ʚrź]aYqQj6e#%4Gh"3QQ2=IJF$c~kaJ8`[-D~'LIP& δ0Z゙//,]p]qԡAP#Kim.> 8c=%q~%`p2W(PMV<{z~ۏe@ "!l?JVT.'n@f47t!8)@؅>l2,R !BKEB.Yyr - 5I=C46y&-`⹇'8TH&53ڴ߮*ٌ֓FН/4/e~$wrW!׶کo*@M.ERzx<0zNI Z*^gxUTAU*߫Qp$b[# |E%͜`5g F/o bi1ֶLWAފURȊAN VUiO"mlZ x#=ϗ$U7Q4UQuj+W%-WS ?+"&з@GpyRLNYے712Rʶ1ό+0br(`cM V/B;#\3,.qoK5H3ָa"ý 9o?yPee\ڢb]ݫ?PeXRg`0'9Ytm.ToNv_6O.A7=Ԯ:hTZħd*AE(; N#ٍee1'?sZ*9IRB(l]}܂qLe+[L8zێWHj B~缏 4JyhUQ- Z_+틿+)[tD`BA޾cLڞ71կ!Aȷd}:S0mtz467gH wD#N |"NhjW./F1z2}xpVP&܎Ը|6uxZV3HQWnfEfPi;JsSZq$=#tkbI"Ql5#'Q.l27G32B$ QT>K U-'=\ryMuz)\Kѭ5p~w28@s.Y hxT>xDHC>Dsp U>+y3(CB.t?ldQ(F\tD@նŨFVXݪ2quyͰJUGzQfzq1[=/\r׏d~+Lӆ2ż ۮjYNC,ja+a+5ajtQ!Ш$ : 4ްof$^\ʯ +՚,ܼȁ$Q cu xC@jo՗fgPf?72It%밣t2t/ #v"- "3ܜjF?I|+}zLJmcTc2$( u_utx=_ht=BRRTu;nñmJ8Iˌ8!+C5K>+%2BKW_ 1>emN--t"+*qS;b}'P:wj|3Hcn}W̏8;" 0(XSR~oL-0T|$UQehp2LjmUli`s^Kc֣\I)"b!#mɪd,D8dp:$cˆھ*-7W:LGS h@L\[YZXTZzx5OmYR毿ҹFd81Uę݌ gn? ?m:XVH34uԫcB0o.>'-U??S f5,&__)c>?,iW&bN8}xz=cU—P,R[MgK",7{% &0 Z4,1,z;O٧`hG`ոCz.D9FGi .k'3mpSGid%蒒H<ɠo\JrHi~2V ׯ& i- u&G+p,X= ,se +K “D^OywhTqϡhd? #,D0['pvT> ;̌\|5ۜp\ `.][Te>fAR:Q:]mVJֱIl1 5ۍs%Y̕+_M׳ O4zQL&~5Gwݪ,#\8|լcYmCx wpl>&Te^ƚ:UA6HI5` zx4YzALf߹ ہx.l@*ty*6yp$^h5X1!h+H57;G~e;198 Aɉې%h1Ί,&Ԙ 0ZuXrUl&0` ׅ.C+_`I|WWy6d4r]Zǯk]->缐",ed{^xْ+kZݍ{vC턙vf+k-ti,@ 6dY7#opl(ْ5 B;+@sq♾T @]ˊ?&b;#-x󋈩]$W{06w` %BdyOV&Ah`!6s%ըc>gM*@/*ol: ўSҲ *[S]Xc$LS E# EnEf ןho`K}k(p# B\6)eFroWO;-idS*cZʗv4FU /˟5K-clND(Xq2dĨ8ĚS{-wS7B)1\k 0L VURHV[E˼*> rχ<1Wk(Pu ^hSghɼ U, 'bZmzCU$/Ӌvec[I)I e`#0*ULx;m?Vo[{1Eie fb9;3#*C<&tbyLېq L:uL;`.I6mUu# ^UMHZFIA Se߬ bjUr~^BE0qoQ$QSN%p\*t){Dwi[1)I0Yn6KyI˺vc۳>.,K̭Hft׻|}ӵ h6\.{(뵘vX`P3߃a\dsK̜[w,,?~ ҉5p&dUSWFs1Bc[Gԫ 7l7Q$6V%I69"N|E u(W_mB]_L/OlPM'd7W$BYf衎׬\TΘUv]L1PéX*xTC}VZnP@WYkꡔU5zi:aΧCFR2LQmzAaԻks@}ҭ RR]5Dn5bwy3/i iRKfKQ:BvCoZi'c!r:2VhJ ߡq>kNӔO{aIY w$gv[Pa֌$hgՂgr+^آ~O]-$+4mӞ TvecَhXڸsrz[`n0VYB!lj"!j17q+Pk_EY{)1O{,rIxKѼ'Kv4C8ol k /#|ZACZP߯i N<1dp8K>E̚pwi55&wr9]K- yK1˻n~~<=jϟƴƙmiHaNw'CEݗy9B :PE"xapNO0ʉ欄$.0X̣vX|BoTRݯ9>MP WJC6<8w-Cf|@ ]>)/b!H>e^`ARDzza:(G#Jk k|^Iˡ3a-gOl`-_4( vJzEUE4(Ԍssu/Ku1.dUA'1i=\#iXySRFrAo?Lo:PɁ(YuZq&c -S}(?S9"ǻ;wqhS_F%Xчeb$/ x9L2zJ렘[R>Ic"0dA3lW97yl~c.ԝk+.<])RWUBT^ިߋ Uk ӡȅJM4n6?\8&=3bDYI5IQ FřsT?{݆O:eϋdWVhˌl'@yLp5)삦}" wMCjnS-6n>p%>M::cRH!g?%Jҗ%ni=<*B}cGե a7!7O݅>sHrQp8K(1j3N#^*1Q ^e6\I ] cR ?1"죲| wVv&qu*0)ԘXꛣ1?wSu\uLanGdߘJ_o F.׾52$ABwЫu>[G2N1a?h%\W.W{0gS _A$o/"Õس,W>(eC(RzMNdC1xfNjSGl>JMYngMwCz 2}ٺD=q'ko.;mt a"hBA4Ubh2zeTp~Ua~sF?.hט2a,k-%3T+nDj´H6IyYp~LWt|P8"@k8`s6Fr1; KMζG Rliz'+X]%v?qr&e(6#4_|NIHaa>bM& }mPZҮBnLgP.OtmR^"cQf(tR]fX{Q9B4mO툿>zSމ%LCI]6r>pxjLs1PE9uW ]c'[e.z L)ضo O&/fmHB˥hK5e|`^בRnHkt ݸ@s5UV=WqC'8hb4HQq 5'A6k*ޡVf|zn?8(qBZ[v!u*`}x\St}a$^--e>5a1{=jvNCgu{PヌDPlPסλ]6J"fH.B뜶Ag%GMXˏJ_Brm:6TN]>=ã47wQD͹w+Nf`Gt_>i~Y"4 Q6O5@+x@~e.M:ш p义'B #hVK=LDp4SQj+nzWrGW:RE,9 J{324w K嗸C쨄r6M%荆pudDžx|s-,UU0ǘk*DbmZ1iCq!RWy-)%RF6`?+CY` `}/bҏj3Bia1?WawG) C"MrA9]s9=N1w @SiH}ҒRIR | H,5RDrХ=N#yڑ>Pn8S辀 _u|iFWXracPq"Hus`sU0 kŘˬXH|t LᨏsCX?)ǮzX[n)1!xL17@H#_~a[h‘|Sz(AD#*Dr!wBi 6E~.AM^|IyX,)Ϧ1dU $=ٜh)2R8ŇujVindd7[[ -HyBl7E/Vo0I`WmNμ 3șGO,4ttǧ뉃ގvxEѶ9P^\ -L}WbՀsEgsOJ˪nqu MKPaC窱Hxcr)}_,jft 8dv;[[Y(cb*>ОxpN@e]*_@಍(=4.8SIMʩk z줞_p*Fr6Oh vrkNy2!Vg~Z\>o#7RbUwCӳ2QzAxkHzz !t/fZ. p wN>٧$.h9˭ǣ,6]g+RB#VM>j,pLg\|6!ߏ(bRi˟\.}̟&? PL<[pD0 =/tHJa‘PYGLƋv9P--vx9'0N *a/JLBcAv؏l<@~|'GѽI$:.³m75ul~O_@toChm lMiewo)%tg ZED,]?Ff*<FtQA2 c!KV+Y(0qd N9`*lOjBLoe s#ĹAegygegysIF|8ƩQEoqvuй>ŬJxUc9zs(-Os>kßm'J_[je+hg 5sH#-ꤍdvvLe\Ɋzh8G-?w/Qc$ӽv7O.~kȬNn+z5%SU=pKfn²̪f,-OR7!BvjС"e|wLܚ.fh B;j4p.gh}9Ot5-W=$@O/̚Zl_ }H|‘=*J}KI2$܁M|K&;es>VĎ9+mK0t]/ oP :D-cyH<[٦4 RY#J|qIV/?(JP5߫LG;Uϝ߭Q:AŤmM^$R"Ny%| ]Tݭtk;Xў"M O_'Ǐ1_-Aʆ& {T؁\^Y0`:1*qC٬=[$`wZM F{pAu̮u0ʺRqa'{ T!:Cr^8q LB죣֨rPqp%Hb 8] x/]y0@IB?]!Vr"^ܮou|\-c | 6]y+4ϐyr޼}[b18˖PEߓKW@ɞ\N\eGtB[rrh]!eZ%>Rt!4FfRԨٝgy6\XCC^(?H0-dFdQGovW OjWLa6(KᬒIo-R?/e87$2c/J}bWnΤ"ce8_}g/k`zpWAE䩤 a$R]V(c3_jWV Ļd=#Sj/T ,5P_n[a쨿0ٶIݑfut8X`u,`:vI )A3QBMͱi!R"K_#)?Vt=/Gz#l{Ag=ԌyF*S]8 eOs13)a%*{+I1/޼5V(ŗٿ׊q.1WҵKV m_wܡ~Qd@B`\&7Kr"+G@|-&!abC$!GTcjx] WZ卹] Nnu^ʙ֖2X/5!^j=d׼0Z bׁn0Ñ&D#T-ҿ TSC򲸔V1fb&3iIki(0#T~J9]4Tx!XѣLVe"#^?ThؚPQNʡW˗sSϛux/r$r6<53)"̋8ښ_\F~ h^jv cU?Ԅ^T4~IL?vڕ:M^Z0KŅ xe$wD۶a5x>s>5Jj8} 2t]V` f$~ear1!R܁߫B:W+Q+F2wInKK柠t m:1`JfѻFnx.ʭm磼!]nXui xКaM3򽟘rlSKEshT7GQSrDzɫfܬe,prĢ ٧rOYCZ}O`;|߿ZtKJʷ64" XH멒tSgWԇ}*FYpa=A MݡcX)xÃ`gV֏d**'yGz/rL XK\ .rx)!!JÅΫ뤯'WA,xT SK2xwh'[ ..}u@}|#( h"FBc f[O7 c⸾8 oϸ>d$b-FwHݺԔy=*p鿚[B^$'A/x^x1EotEtIwxu>o+ *a?cmM|(B 7V[^@ޮ؍EyA}GmQOM ib vkеBL̍72,= J? LqvB0ɐۃd@ Ѻ`%la{ZCo,K]DY2&,]MJ;R|&o#tϺ{r-H 5⺆j7%=8l50Lur' I;0DbBY1/xeIWa~1I?U,{=JdT7d-ã,ey⡁t~Jk%Q vEȑoA^lPE`ძg ) n;\߃`w>aUy0֗O?)ϑ{jQ6W]Sx8x% anspx#S(btp;c!R~w> K%M l`sU:݁>$l-|UUSdXO?vMh~/xjq e~ռӏ9^M6Oe\X>?cDyT>,82 6Ѿ|9-@9[2NG.&_wRj/,V9K+USJ~()9|N; ~ qưf(SR;74u͗Hl1w.$tg:jZ9&+A&S޾9%7C+>@n5(!ǟE`7\LI `^ۚfPNyGdbvHThlA 2=xSj 莩QB_)sw0)A[t~&S=FxjX$8}cց*on$`W fE/͈@`>kͲ`Ǥ'}ߞPk.D4G,_s?xhq"c列MQ,Z|pX$1UUM~^֪g fKS F2Si~6b$kV =b`ghɄ,M Eț _ <\n7G bjO߲L5r"TyyQ]n"&p] skuv4wYPNV+9ͣgu",חGy@9ړ9nm_,N9p;;qUl+GATi| ƸsDe%@6 "C_Vű K%3V4V#L]m"Nd@^њ| lj T>)9P7rşyT,r㞯w3Ի?:15铴)i?D"Ǯ],nmGE#X5jCgS,_͠*-xZ-um'#_jwLHZ$)K8gd)[2-y djc4wFwB^ə֨lŃ';z&gg{KqY7GGpRLmN7]\s2ئ7# d}J!`baFȳ&^WFN+7v]߂g]#,WNHw!FUu>uمBNmz ^\(o!T<(|{tEVBԮI4zeRK'=f[ޕN= xk"z=2 ۥ),aUWᴍ{V\{n믃%$j]jYUEu9`zq2uܾ QC OGBHnX?MKVX4pL\RBT^G77(q{ıH cl,u ZN >T{P+a1XRzli,zKVS?e{vP*ĨFhuP䧉"bXjHkE $ɨ[E .4+A`z&U; )2'*Ю "I4ApzЯMh,JGOH`;zkm嶪Ok9Z q+"}RD z ;o88"XsgWFu=@s 1RX[p 3i/`,#J@cQu\5[vT\ ^qz.؁#;f7CgsP<'].\ZQ֯EyaJoLPVϿ]ڐg9I ʰ;BM*e!kha+Щ`5٥lDtvӡco&`7Ōs x4 }}pRg>J}p8 4.}g8U&k&*o} C^0aҐ\&1-GmFJe6%r2˥m t7!x#S`IKC \$q|џqɤIծ_ h,e^k9Cڟ ( >q~[ l7Є@=BEӍ?ebzrP:OE/%5Ϸm@gLU&o9`Zq+s;4li7c[SEO+ g<}7DoD`%[4Uw:}BMQU%7(Yɼ\Kb/|{d[#z 4C[6P26[ R:(љí\$d2+f|Fe ^π-3n#^U Kgu3\HS=wW3Xϲe_ W_; Icefq+ANLU߆k0V\+j)sf?%>j٭.A)-I~p'i?8v-ꤋ(&‚E3&Rq?d y `8e!Y4E>D(a[87tl5<kR݉ 'P}iңy3D4k懱0)('9Aс ̼{t'{{Qou (1dܸ~:|܇پ 4 fed^Tb{YNppS}( @:"4XLe/EKL\Dr#ط@/ L1D_]~lܦd/py)TfEj"Z0ı[ Eꏴ qlex&o.y;bX񟠸yOˊI/er wTR F GPN7P5f^PVK5͒쑝5Ia֔q0f5,b!㨢k8Ÿˌ z]1kXL :I3yd3R '6(ov%VM(Mީ=<RVϳeK,] Y+B 6ޞ KHǧ"Dg[C"|J6ƱۦR-r\042A}1iÖ0lzXW۫G>]NBΏ | y**{CUiIz<~3@J~D ; n BkU׿]\+>2ƞ>&ӓ(sbQLs?x"guAd澓H618Rڌ`@Oge@s 㠥>܁\rQBSYEhNY_Qq2}QXN`s$Kn:}Nl%•Q>F: .[;u*2DPYѽ ڰMȲtpFTd8H8:yx+ݖ[`as+q}pż\+~k CF{zs_bϷHտbh1H_U!,]HR!KmoK&7╛xj׈!d/RɞG{E,gzn`q̡ʌeiBfWڐa]JS @qm %^+Vz0ojPs5Q*bv"yn)-޴ /b 8qk1FXZ)a`#-Xi*M7bW>%[sTbdeF1_) ,f["1N ݊VO͈T%zZ"=) 8}a Ido=LۊvWb<\ 0c#`5ÿecᯞԅZh*ҷ2#歎\W="z&ץXi>Z|&Q0vUHz`=st DbV8FvC<' |?-ǨS2Pl[ >Mc+=4:8c?&uN=b|1j&3NY)Xu 7!UD!ޱk$P`smeY­P6Ӄ>(w$i/!\d1{@Ⱥ v|n4ʹ9إ4cѫ\K,3vFZݽ3Jc}SFڭAD"#0?H2עd.SXq%Fړډ716DꞱCAo>7H>?|1 HRqSc7 ukzq`&/J˗dC|҂ɲqaL#W3Xa+~4bek."wnÛsQN]dYrqcC0 mNr̜hF1 %rBwV^N J7JAp9ms@%{kE{ Eߤ 5լ:HCL¹kliHm1K%Q8(cA|j<}""(7zt=|Z]>XߥMd nR䛳Z_U, {8NwMؚ> ՚.H G\8s}1!;d10=m%i#1Ih= A.2$QpLunҿA:[MˀK̓o9#T-c0p`l.@I>Jxl m[€z"]牘lq~y$ a揾'*ocG{*DI'{tbeхRo<Gj}?BKsO.Ip{7_w&h#>6 ΏwX{ݛU;ƅ<_T(iDstQμV;skɣq4e0 %Z~pTb|뇼Mx<;h-C^,voQ¨x4f< MAFy^r ^ŧmP}D)6# ƀd%4Nƛ|^\זֳAN(7c~CLjE.TΚoRG~Ai\q̙P2g(H}_#ėՊB0!p==XĨ7gߓys.+N\oQ5"P-0y2قb)dk~E2y5}!*#ŴȻYEڲρ0=ϋ}i2>o,d7fj O!F80@$~?n9-qߠ)5}uu5 ֩O;suG&0QVo 0K9XܨsT_ѱ% .ЦU%E^Թcҟl~w;…7O̮x/_u͂F%hH=Q"3)I/Z6),rfcH ItVpnʩtcRܿ,#)'4o /9]D*Iz[ԋ.Qd& -wl͜x.FNqRExD[2rcx$@[:%׈ji[p,[h%3276BG\]^OZ*!` "s6I)s h䔧yGލ2ⱺ6:&8(khM$Mv= ĨqjH kf *PH(t"L~S#.Yޮgus%CD9٭}qj,C0 k’<'7DTP.y‘A *ݱ\bQ{om^߲0j= qS]⩏V lc0tb9ÙwQQf #iM ^9#ڠiںaSH&Vus;o}A@y݉HLr[,bL "S!p楯6ARUtv'aCՁovGB6q[NP11TkpcE55aQ6ݐ-Fb82 ^tL+27P_̶ IVT~ է[/ c `TW'Θ: +Htp_fD'-_-YVʗޝSЃ  ./J97|3aEeiLw&:IzD˅ܥ4gj{SU:n2qd~^uћ ֨J &kk\FdVvh'[9 eKܩgaƓr! // + dϋ/0fERfx )< Oy?"M kJH'ﲌ1p%t0dFAٯo28^i%9!A qpC [s]>H {NO4|[=IZ;? p1TM[x+Cm9vg b#ZWxNh]?,tгኴ8FP> Cƨq=cP#_JVmkKnyFFEsIĦnZ)^ ,Idmd]ZfHk?R@Y1q^g շuHQ "L%לN2 @+M^ lBńR]4d Mu ]BC<b~K]B2I8joH/ X/ /?lj0dWv] Q"R|djm%ķfzsm'i4KaGj?x2>ur1OFQPJpac>-X[3ɪJ=Sm#8D忧Paם R\'x<4q <L5X-~,xd-F mdcCp{_QQ8ӱy?DFCϸgӾd,0E饹k2҉^vdPO1ZM!?*Q3؏e~Wp~xS)ې Jo2ކu`x֌(hkQA?r*X=q{jI_Ͽt RO*?OplEƵݲUKB-%T\B6v>˺6}P7V2!jL\SfmQ+[_0}j͗x6 IbYÌ/ VĄVB粰{'ѶߕyY+`80=KhU2'5>}Ƞٴ 0`Sf RN +R' Eu1^_] "ڌg .w/jZ$BTnF7r㧆z$$5m/K dd4Es?:j/ eG9,h(k4nYC @}=$;̌x;>> 0Zq3>\(N1އ? [/+I0,8i P;,ٛvD&:7}X(=OVwrG╒ `2B Jb}h 2pk&C'`佝:-: J'b3IE\3:`,^F,N(|*QXkzfwR2DGQ^sy'U#.Yݰf'v;|v""7\ -vPH@ KeP a}ޕpQ8g>ٞYYeR?x8t} dX1Tm<ɁQ*9xE_x c(n}8Cdɤy7 tnT Fkx֮7"y5'Mk0S ',<C8~--OwPK՘E<î֡x 3IhX:W_(/&*w2s#%vSV GF sz5`if7JKTz5XQ`B2T-pyxe%[}:LΰM&]*3͢*l [^f6DjMbf3 W01B͡ˣ |\T))nDY!jٱe}ı=Hq HF bڧ~1^%ޕ]~ ܞahSHG UϨj:ã&X9 O g 6XAgn ' *␽DPD9O,Qvj* G[&=^>bb7(b1ۄ\!j(ӍAsbp#my%.vHȷVn( ^bO5#yV+ͮuNJ8}§aK&9A8W\N~dx S#t*DCybCDN],oimv(Oh-b(B`+Duz >>MTH퀃+Zv,$4Z=*~Rڎ7f4R.^W]֟ 7i ᓇyfzWס_rx<&#&,8BrjUy&n&w\>A{!mxt ,a&X(;Ɩ ViCOJgȖzdf$HB vA\b[nX.?B>gJax:xSu\nTe & ڲ:/6G\$]ә3ҞiXh<ܶJ].ElDifa>x>ѐ _!z&`ЛKdQAu)e'=_)Bu齛tHKm<׏ua/$o/\t!n䁎eրEݠ.vhbp|"*z@l$7U½aK)'|&-lo*w7J7L' Ú5/h4PZuY}[CiM|eЅ̺cq~!tfۧOY#QYw##؝ŵ$ ~_O+ORDjq;Y=v'p?/0y]=32"ˣ` ~P C50='xggk[R,l_jEBͲy9KF)FjhE%zV@BW'.i t1}ZoveHj`N4띯WOQ߰R;b%7kk\Fz?]d@gAR֡ˤ(QmD(M=uaJdCƝ]| *7͕>LeI뎫^2ɩ0a: ġDŽXdok}Oi\=c#pjӢ"'3J7a=6oH*Iљ m̳*@)AST+wW^aH77"U3H06\˨=.ȣ.';ӵ3WqT_G!z侾4O\$+C}hŒ:p/H\XϫSF?f+YIω]S*,,Q-16?غCBqn?If}CDerz`h-$T)?5;  Q1I8qɂ _$OhaW=5$}r0̅VƝHӉ2$}Ot%ߐr?-(U>3}dD cJZ%GSchQ6REnWۦ2=Ƚx96"Aw1?t,-o3ZS}p:<@pk*A n/ 0~P&Έ]; e:ZϾ9W/R939 ߛg-S"ADY:Zf*{YΛq,*0G `xٻ䧖<-W~AщIh`YWl"碯q@H q)e"$i7TgiۃK3<d@-W a;Ɠ#VX(_s{na\ch1\%ϰ&/< \ކul#/˧r{w)ŚSV~$E/ s{ն@A8l}warU-C& -v*쁜rm#^7+X\r %n2K ٕeװgsA ?DS* :M ࠈCRrBӷecP||Sxs.pmzJI2,9,Q|ÿ(hev`39%m&:Y͵jk@3 ĭm?|}KlW^U~ s$DBB”!0 )1_ό?Zˬ3zS/GTS#߳HS]<-GzB'Lʔ#K/yHz# S:'D,٬ZoTbD2:4Ιx\jz1Ϸl{'&1ɳ7[=GV٨G6擶p:R7v<>LbLmU/7P|8Cg7@[JkHn%IY-eât)6ed# DbԖ CB`48<-$5hɵQ":!!/o(~yEA(mNx< \ú{f.Goۗt5 gZ{{Tݱ(3ZS#Xcr2f5yKU҃Z=}Rrޗ4E-SRNXo$['+A[26%GEWڝ p&,L:mG qJ{FnYpUSލkC([BV1]4Yk2uO?L!*탚+B RoK+ JY<$WR\×TVaQHeVC>g(XH%}L=R¦B5\,a~KZ\ޅb -&r=jA T҈+-_9{/"c^?\m3d3kC%3M7f Uǡ`׆Pu^kw (7zxE)*ߩ7Зuhʫ *,r N"4s# ҬG "%3G3)*bBJwhPAD9xzH>҄@hya8%kp W 0渔f)`L+橉(.@桯mWFJ 2PZ@Em ])1BPZC~Ɔn-9tCT̍1BzpCT* Xi ?}1.ze;hoO)Mi> _EG}"~c:xe>޼.g掗NSPKEUfBSb27Y)iiKe5E[\9 K"y5|*?E8E.g|9F'ف[DdY4 5ԟ9ϣs9vRpnրZـ- ^]@!M;peFPo:lN1pn בEX1yP(l#kH&AJv͕qqFUp]ƎI{Rxm/cl)%ͿeDEޡ{=]Ĥ1涢 ¼7)zjH]8:(TN҇2F0_jr=~PU(1?|StF[afPd%%p(c8%urW;\!~KoLp")\TH<2E~ X`?z;S~j4R\LGAɘM'\;+K,3 a2y 8vK #@1 /D<6x?){uVwԉf#2_0{D;n7'iBy[`.x_Z% s | 5]dˮEGh-m+5 Ҍ]ه5Ќų$|616< 잕/.N5;k7W{l"uBV,-<QQެ(Fo8f(`+x7U~9͐gB-lNDAX|"5h%^P#Vh'b~C;w?g3)!{wAXP fy/-oo8wŷEBhCv ]9J$@}-FG eT!S7`\gli57P3ރo`O bYQM` /&v+ Nj`O@hj!ɜw0a2 ŷw?J7|jR0Nt8SI t@4%\fU~-0+Cv9ovP`ϋQ)]/sZ9RqQ]J0ᄤJHڮ 9ۛ&)#`aI #ʐnV+ ta\!e^Clh6ޝDkwdM 3 &< dzyDfTO6 R3fװ7pdi`T#y=_VrCJKu;0I?/]i+Bx ȶ?pᖺ{A_3j1iC$y2L K*90\ &3uKKA w¤$qec6,?%-P< ZgEõ)J9Fm=TW(#NId.|N5Xh]ƏrL[ j#2Am5YX?ۅ?%v䡐%z>\ur}=g@rm3W+x;% +TGAX:SgaX\d:<4ux۞8KM1S2b6w@)vc>{'N~d̵/ͷ(5v4{-v ` <@%F$&j_-r +?^|b*&j*Ra$?-2rzCOdZҷ1E;k@h p\hMpK(N/l)g0klqk" !:w/p)ڀ-!/ƻ9T7X:N-N:>%qIS=r>M%)3L&09SY/(vGpHRMj禚[_WnWH:ߋ_FC17¨Nꊯ;?DfD@/RjxsÝH d "Z OpBE粐 Yv}-y\:P̌Ft +/?agֵVkd!|IVc CxaڸXlE$o DVEM鶶/E2>wq{dRԸ0Nw@d|Nvu#+qX%?Z!7X)\xgbtx['WcPFl;An"ꌳ-U ahjؘc#c{ qScrbD\[C7A// #,2x#?~ckHڹnUS1 h&3 Ush0MZ)kIeuߔ[5=jӭ$cpZ\>^[UY4WG/+vE* sxv"f3^-/KԡP\qqN /n jP)|]ۈ c!ΉE[Y9.D5"^fno;}z=#R‹8w?}sCj'0,l+>4,"OuZ&yhGw7>MM5\, ,:W_I ޥrVA~5̺y9whw0m3@1z)mﻋL@xHM|:Sb2hPHyNftc3cc%7U1!Y?%MiOYǢo1+%״lV"|C ޼ҝ`VGO;,g=Cu7<%KzޏGmwH\ln1)4c\895׉禽እXkDnŒNG&r7 1%شxU '~bSYlIM!Vq)O)mZ?%qjpq1$V8p3ha](x~*☀e>6xafG{*> ٗrdtBB } GXdc0ti93j8RY,@>&d.9.Ҵȁ3ϡkpҗ`2*t_ezL~^IhT!g 4k<4r lX],=w]&ېTº Ze IlqCkvj8收AxXKE%Nbg{:03_Ds`LvpCkh*J:Oث"Ǔ&=T~z;GU5΁@%z~pߒMwl]W:|-={S|T'8i䒔wj֗=%ֹXD~Z6D(; Ԙ~8:fBӪbÎE+9KIz1jsNuI'AG:9]ҙ q-9t{F* HGաՉ9ZGˋI(b6/6IbW ڪ rĿ qX ÿ؍vŘ*uB cTnm9ef}SW# Uq@LJѝ!`ڒXAS)lj@nي|q- 9"=>TtVoz8,4&*H,LU.HUwp'Dt+8<V7tWDSݿ <.h-Ǭ Dbpy@Os Kf ,WzSxꡚ!#/EjƓ]$ x>4[XFyv-!G d8W {567`M"+"x@GekE##\>+y{SU WfݗXI}3#g׾7|a'3[Q⼶n])-4[LNYs! -Y#vNs#&Sx׹mN$KG+eMhXY7ȶn4 TWd__4BJEm.pܯi k˻#D g#ΰ#̒אIM?zcQH (1xJ H%%F~󟣥+t";~ , gU>, otrEGkjT4Kkw܏Rq(vl$R2lngMw˔?˥7PYd8?7e-#d^ F|.A11mqNVv5dzւ tH!Th'X T1}:1ie~lvG1`@3"·| ^ʩeGMqqZocR']Ȼ^P# '(%, "`.x^i"9MAJc`en4HtÀwϣS`]vehH~:a4_7ME]0 ff"@Lݭ 47钎Păb  jnP5-dݐDŽdWh}c!)ΕW,3H[2gLq'4+Y}!'J/C'Z7JM> Ha*=3?,~7=^";PtEou"X|ğ5d˩.;W0ۤDvẕL-* ^EbVjqħoTw5]c8|cep n@K~҆#}XYⱹRcP'$EDa({ ˿-d,CB_`칪ߢ08`z$53I{Qs-)&Q1π N` 8"W o|m' ޻kBtfETX ᄫi2-w[$krDUy#7n^BTba"QO2o?Y:N)h]iIh0G6bM)50r5侩~uYfXѶf1va -ׅVoy=;yZo7l9nD̋v 4%4~%%!pcGWe혈Yi,OvTMP>QŃ$bwٓT"i^uV$a.PjcB@fU;4j6\X_$$>9,~Os`FLeP~1) 9^TdM-󃧆1w3 e/[*>L9혨 ;E`ZYǡ쨊[Qs ̘a,D%^Ѓjn` K$Ta ba}FY' q\)F Lh1Q'n^ћS!ʛd:+mqjigU2 < lʘk0$Gk#Rܻ|S席ZrL[Gx-NGzE_LVbSon =N ̬+>v]Mع[  1 GbgT>帞re6`2ؕ d-ޞLh\Ӿj>n?o65A{ xFV1x2~1yҮi nð `4ǀYԦR ʧڻH%kI{W k̈(u0Lht_ijqj5C`/XUt{6> pB#"*lWtϬ NGr+ƋuR?KPJ_5|g!>x)wg`\ߔf3܀nJ syZ£DK6*a1(\9!f+:n+@XX Rq=9(2 6 0tFkZppcAi鯁&„1Q" gl:$GFg `lJ"qko %o@$V*EVF&. AK  E"-}7 5' 5Y"iD}b N$pBKGлڢJ ­~w uzL|2kJp s?r-v[?IZ'JFITLLg8H/7 b<}D #q7BQEGfLW"g'չH(,Bf8g72؏kWl޴T <^Z2vFX*)-4<"e) #} ǟgkDֹ*]#Y=ix~X35Yj A_oI=ˁG[ Wjh<]}p _iT9|Q5|v|fLb#Fn|"˒`Ȫ?{{`jFiYdngE-ܯ#\fs 1ls7\jW#KFOwYWO: ּqi/B{"뼺teqV*$ K,N}]oߣ,3^yz<n#8t_Th^j4Huw⑆#࠙/1 lUYZCklp;uX,H%OdG"}J#@Zaɉ! PpɘgI)-amk;5j#[))kKגD583 -aR <'V.ujx;.[!\P(G A0.#Ol`rKe#D"1k}I65ejUb:K>iw>?[727P+] Zr8K˽rs[x(,G[+¦U%N[1Xz(Ih@L蕁yӂD Jl 0TX`x1h[п-5yG8rt(W- N":W[s y^ 'Viޫ"brD,S:f]i$RxfU_B q&4Y_NX'6%XPx~c`/tL8Rb#*1yC9w!Кentd|_!pPƱy"1:z->rc}Ѧ@]MшpCuha7+ ym) SLqׁ"B{^^YL/TIQu9pA$lEv9YP)P* (mW"|!X2 "V.dfE # '{=/M `M02K5@Y3Yhll}G h= Wџo!ONRɥݏ<_C:X}(W &2ZC.̦&J…n0Rv |1Ɔ 3W{zw Z;E?KñFjI561-S7Sm o%[NED2?QK14GE` .,Ӌ!Z=("x]wܛzHK5Q4^q>A>j.EUO^Fh]9Q)]rmΧ5KJ˺<&un u&"n5}}HVOzx7)Ioe#d8ǴRc~WGwácaߜcU 7|o3K^ F]mj^϶ #Nql`?qB~#+/$Тɍ˕H.JVi*ROB3RzQ*:sƫ,$ OJv 뀾A6- eel1zcs}$"bߍpKIC]NpI,:Uuσ?fsUZvSVZU12z"ݚsCV\XIp]E 6?ezV8"5|2M:/J_PAך D S>A q21W؉SYX(ʪ4RnOϿFM Wdv>pt0%O㕿/j18(>qˤ`eTN^"[(q%Y#NMZྔ *=aa=m+6Y?/ŵJ,)Ik)]8/ڌU PFA`-dSdP/ sV>4FC`]Ǟľ5αÅ+kg:r0lJcIq즭lq6!L׎/LwV"A(/>{NNf]?3]ː*|Sw$ U Z‚}鰶 /< sgN4_LJ2e CvE*]֭5:]^t GqZ3=K/K,MziNWGg&JmCzp쀯˚uM} kƭ$O:uMq9 t3Ӯm7O/7{".'_Y_ ɚbt.x1lx݄nZ8YBE$xCL>KB-0M90[Uŗor`ΥL [:a1yMW-I2Nsh2 _4ǫCZrȝ⩯sӐShfuOc@ҽP Q>Xv_z~qhu!qbpor)YVY}Ӷ_ 9Ҳ:=yx|=X۰Rq ^IUJeeb_˧OuJk]ȭ*v[ ȠUuG\c/,ZRsq'R)|-Pk)iow4vx!A'QJ}H"57TF{et 7?Ci$PΊ+J5MèF.vWd=]aH _}Hj\5av">@w:0EJ4rUj9}lS[HAt?Kn|ҝkӂR>YZ/쪛~q8c*ȁAǡ,2ʴ\ScӵL4DvOsh!vp;2Hke"nBAǻň\mo%?U bV%„9ΆQK%K몁*hK1m7rƋF=,yC]FHvb1%۪8^G܂q> Q@]ʒмIE#8ؒ:e,_YM ȺLņOkeߗB c8/LrFksG@B@ay8P,[ }W!A DZa}& DkJy<<JNDc7dV`)*닽s&<u2~tU aRBPf~)pٝ=| Z֋cΟ Oֈ!3~38< O:z2vE׹̓cQ B˂1ZjDZuD #KmWWJZ_`[$=Vꟽy-Sێڞu C1gp\V@81ت(<Wz&A7ʒ˥nƣ*iE#?2H^gi<ŗ,kql^U AFb`ěP4iN+;Om%oq>D U*@c`O`[64OW)v;øn / ͣ5%FtVVU{?Nvd)uA =<:7)p(k0YD<)m@ocGS'apD.xinK`Ǟp@ iͶ)0,~ƦZn4l{y ;BF&R(;r/"c]WՃy_3ZԻ{:ӔD0,L`wD`ś{Y{c\w![:w;okh Ć/\__QCnjz{e=Iq[$B'$YwYs zNS-pI9,w Csv{JQ >vaeѭ3_ىY3$M>CěSgc.?I_!&[EP{ E+)Gc.S)tM2`@#Vv\.!K0Glr=4xF=XIv5^|]'qȯJ>t֗(kIJ@]ٽh42˒:0*^}gąӿ =`2ď'2Iǵ.n WlU.Q!Fl(p5VQb_H?6L_CضhDwyhSQ3nF>tHqo+A:{̬l%e0Džt kj}*@=mB xASE~+~t p&*ǃ/ra!@ ne o6oEt8pWahͿw:Tn&6pܖQJI h`Q>lN AΨ[: =0XSdb3EK|?.<~W8lzۣI0ڸ? Z}'/rmꮷjΝ)+| ŀ#Wc?"Z?]vM>9j1>|ؐǞ®@Qgp/!qXDl7<~[-i**ED6}w@*XlȎ9hj*x #f0j*بd؟>3bJϼ`upHɟˢc;WR@=@dXs5LE.vE×I4\xlqI:K̻/ 8aeh 3hr] A  #X )}٭&@* Sؘ ('g[ 59LNi0]3,I?4 g?D.©(@K1=?6+CQqRD] lD`HaeNDŀ{?6Njhn\0oT}]*4ZQĚY`|`Tޕs{Uos QF\'Rrfn,ʟ2~.%N{(B"> iZ-оbbt[ 76VKk)p*oGud5շ%Gm*rdP%6=M;p|т"1>q:z1@l8Զ5g]א7L'VZR\l?~-Zׁ`Ja#vDX=XC5 @U>~yT>y?>^ =bv'SDGtXk&v͉BxJMTn=mt.R"Y.B`ĀlH7Z]X׬#knYr]G*[ԞXdra6lXΊ}l{V[:/D,3g6[pc':M$XC>Ph*6fX ^z:?pANP#'u iM ։ju:JY;>E͇)(x&=9VECkA5sXTt`s:lkyְfK(R6 #[=~o5^10Yl'Anw'J,,d&bfd1HRupܺ2nrAחh*>Hx4S`awRcIi g "YYִq; [5%;S:/ST$Lmq ,S,{3*޽&8t}@F_ňF짎{]5ƸN~"_9lrfNX8%)F4>aVdXB{ysX zzgPL^&bOcӿ *#$kCН8Aϕs <#2qYuK_7iQr6M ZTF&+K)a,>$L]p>沢iC~:2Wr`*t'ˁ1MAmkϛk=+wfwUJhӄ /x߹ "2#eWĶ*NBaS5bH"ڃ?pTfs_FKk^C7+b '2,I ͂ 2kQJ$V"drMϘrfL;.msjYS ED!DzI.<Y)l tlMk-IVScr7#Z@pLoQ| r :p?hT㏶,ډП^h<[(W# {9&:QȉG.Z)"ѩ26G\h;I/ߖ/^)K: J\lI|}>Ҥ7vLhHIlMQ7PjhS;hPPN._\ƨք! .:of&VA@inGL w~b"i!fˆTjnrdUuBSkLvn]BZ:MfJ,%FM7f p7AlT(o +vWH%/!%!1!KYpT5kmtC3 eSG_pMa_@e J7a T>FPt%Qō ͷpL+oJ2lPWӆp^#Ia틦&vň> ̊Oӗ- ්C|i$5n78/%MqGt4蓚մ*6ڼaz"?k zT`A_̬㽹o`|ăDQ\ e)I!t#ng[H_U[9m,cz=^݈cW6HZQ6Anv5C:z'-<-IkTjvf,M"ztri{8 KbwSݰvu տL !/Lqnl${Tq=+?@ڤϦM]o8eItF dDTѯKcz"5 `1۔Sz|ܷ>MӃ}٨RK3-DebnɠNL{X՟M)k"*lw~R2&gvrq*ro*}Iģ,𹼷2FG],;CS|mg*2$ܒT| Cl}+ݮ8Z% EOtNkC[LWxޝ,Qyj=x`)7D{!]̆"xcNLH$BIJ._D4U`_3fX;%`nS/q+/'۳I's|$";<'򄽑QmgPycM<\-{çe°NRH8DsoG~uu!!I1U<܉ %򧾤l0KC1#B6RF"j9sO,%ͫl>s -8|.\Q*kb3aaL ͓7R*֑u qb[6NkF(SIxVIgOWn%$LI$#8 =P2.\EfiX59.]" RjI9U<3ܿ@2M}59WT=KLg,e #x*ř3V[:N_8ZxѕWv. TOP[@}{Tg!ijUkڬinV~t|bh 8`qzfGY)DYPQKv{_Q?Y”7 V ' L$] 2ީwj OZpvLzC)}'xgyOD_nM'LB %V;;`A=U5^ +Qsس^Uޕyq}ak$ɧW*p-Kl~GTUk,(wHՓzNjPOkuQiBw DNӕ:cyA0\sԩ4DҐI)mT'nH>(ɴ؉'hPʤd5I(brƋ)z\Wh@eZz|,NkLgؔ!n*":Z7M5%o1 62ugԦ(%MjR vOk V4}s6C`H/nQ &)xlY^0:!O Fb-z78SAƊUS *iG,섭j{nfd vWB92>^z:'^iYrU!}m"Gh@VL6M]p3\q3ajkdi0xwGWF SFґbsD01S#"NHh"-t`2^mI@!"ʄKNRŜi6߈b5{Pʬ;=|jeWZHF `8ǮHqs+C)A}-N)=5T"֙qgO8е<6C[c=W6,<%dg2) ק?pc""^8>8ъhxZ%iJDZ7M|*d}j+dZKvAQ{-& fgˠ8. GE^EL;?z3?T5|,˺]b%:''@'1B0.C⮭0 ͌ڐ2 㳔z;|djM|TeY%dߩh-?/`e ʗ cvU08vx  L~ǍXs,#cKEM8.*Pp?lq+[3 e&9`J[ ӟ'H=x4%\ ɗFo(nV5s^~{Yv?M_'Zʆ|yJx7")  <r,Ru8hdH"{W3W5'B՝\!A"*$A  -E0O8gruaALKW+d`)s}ei>3(FgM0j%Cr/تJsXIg# v {) EǏw+9,.s Vϯ*9ﯞx-+9Oz쐙\X ](eaWM/3Ӌ\aQr)`"V/Qt;Y+_1; n~B2O.f&Lo5na#@KwigyuH!S aI?ȥ}$WdJUoM/)MhiD`:S)E7X!Is%Aiۆ -*\4שyH7w| eʡ'k$)s3IBd&!f͚Q<d\P_n- IX xIS7- *EdžcVMpIV-)dOelc%P;u"ã\ 8䋌\Ri5,5!6( U%)_y}ϑOu޴tNLcg|\7r9&ۙdz,>uڔ<ߠ& č}e\`xǁQMNO .[I*ItarDz:4iYpBt"az>=TDlZ d o'{?֑(K:yfq +-R߸|FNC KA0aLq:ݔ'OeMV7OG/[Vb~&%nYV$u~d7ϷKbiuNwuz*gnfhn̂f(Z㬢Y]5 I%T7S/_O,b9\֨08$|wXCAC"gcp[Ik4mΟ=Sf5jQfVG!() 4+3{g\kK̭j9&5{䂓QcS1LGB sڥfr=ir]Z Fgđz+b*|;޽?bBȱ(0\[{[r qXkY6NAWwr8y(h61fe"Bs&0Hݾ䥹"=>RJ-9e>pu̟3p5+b99FT)_UםEX8T[lAu5K6rbʵLb" T{\#>- ׮g.l(tM ފ:c"4+W!_v}aTql_]*} $( )(xTs bKAAky|J!? GF0Z}È)1>@\\-J֓>yUWS I ڊ<;+EOud)$ԁ²!U`庉ϖΤDAw:#Q$ap9-~O՝"+T0JJNR3'pe<0 wQ3\GA:_l騑kDZI4_ (ͦ@ok.qgL\ a;J Dk0he[^ %KZ^GpLKeBV=bH+QH(" .!1,`a-*N.\XX'yI-vTXԓiȃ$v`]9( 2ZvL2tj ΗAS.mDP$Dʅ my{SޔqطT>`}[3ʴ 8[c _]"[ 苇zt2D%f ܡXq2Hv9)bmUVRlZ8N&>(StYƎ\".*V\nntLvOOZ.Gtv AE ?qSNocJ\,rU?e}>!rO~c /xiEۤp sr.'vw\Q6"rƢ'Oҙπ4 !`JA6P4hhW/μp iDE@].5Bh| T'u*FzcAP˨ 7^U5G1A Wm^ JjE&۶w]%-FJV ,`29aR!.?.6%^+I]Wg^um^A}۬eġ%>i<o{3 (i"<R?Tu?H5TE ?j^Dy4>Ym)Т ise:ZBlt6$?W"U&yPd{^(@8iuɶY?tͭr}!}fr&5DDIHd_![3g=~ґL?a%k.2i{E 6PAm_6YB0;;6MI`. 0ㄬaXOh=ڷX>zZ;ؓjBPҊ6sf id%< Aۈʿ<)!í ܺɩ*l^DpRky%F$=crM*;^93 NyR+fؼڤԉf{ЙtT\8D UjN_Rv5#T864r{=a\+{Sl/Nj?v!kD}՝Ɏ\byڞN]>?;3cZ6 "?4RM}.BK%c@[@˥w+=dBՐ9luZTo,\5_@ ^Q|l?(2iȫ~fm<׆{׷9J"*R׾jXMy}YOq쬏FTWRRx2st|t#j6O7]&,yjmR]Eĭ"Xl:Wf_y:K?[4Yg I,6+ȊGaF[갊nn%L!eqd+'{@9>&nk\E5M&GVSN 8 @GZ#1 #5 pOӍ%$gz1m>6O-ęJ,2ΔwOKB \؋uf.;'X?#_y]e:RI"#IJ =aASDa>5,3>0Ud/<(h nQ Dԋ3:ȣ+nsM׺z iMl(}骂UU",TE}Z[z"ۙ V苐8 Aʉ_H3= 59GmVlUBW ~m ]q,73Js֌q<ΜKXHEv\bZƤD. w«>soL=(},$Ԫ]m{_rcppI)Kp>!0'FX ̦~f@-b/Q=m%GM? I7㭇vt&uQlTdax@F4okm+ S$șq2~AG B(M] ۇbR!) 5\D8 kZO :fA)E:_O-3F;l.-U.Ծj ;`Tcn d "b#(FϾ A5r3JU# ZP©3h9#\t]ͣU|E],V >gp@CiE" d6n#Xve>?/[B#CѤޒ7\ 8<݄nxeQoqj٠:,*.8%$1YdBg XCsj#3:cy(>-=hjt*=13hq>TpS#SRi-`3Z|~fg\uc኎}%C-/I,%n >pB "J|HԵ63|eVSkqӺK`pBG15w DG~T=SJLkXʼwiv|1'szc@ 4}zb {Kߠ;#멣UY5م7ڐ{j!xz@jSQ߮!R<k5SGqגZHE\fZ|l wTD,ӛ@![$zKg?5ՙtҙ7"V1pQ^R>:SK#؏#n0_5I)j)AQ$ey,DvᏕcI=m%wMYɵ{ !|E'?r&G!H!½*zO(9]p۾}:!i%l3u{Ԍs%b (N5^OU=ZfgKL?w!4M!-G}aQ˻<|!ܝ'[mzɏH)|Ш#]ٮU {Ŵps'?(osP!KR*0z:@$3$;MAslXMI$&%KxIAKjjqVόBƅ_`3y3|C%ЕgBouK-cwJN{=еƎזjU_y>.-4C}7pZ\Nbo3 {yqxmAh;\~$!&O6V(xU<օz#;R4ґ /""|+_ i vNNfh;e a۵ɚRtIuTmݒ`[Я%sKD6| !X6cm|[h=ZCrp_gLZ 5(aSӰ }Uj0iC?vs47?1S3g=ą)؀/>82@`>k i_ϴ[60gRl.MzkFEbub7+V$}f*LGUx h0'Z|Lv+$DC*.!>ߌ<h )M[K%2L0s32(~gyT1OW*2taTo "k`5ZAZ0,('_OE43Tg4p큾'ΙF]tKPŕEk_HI QgLKĤM[f;N5jy) R!ou9~!SҝNVvߖLnnѦϽfU]la+&+Aeј$ }">8t?s^b]6{jґp;3Mk];\*\]6!b#]b^6 gƫRXG(fRO̘m3.>aH.F~slg7QDIɔI$" 15jr='S /7_@a4/7e&aN^]aTJw{V^$;U^88-p$|s8*N  QS#̃@ VQ8˙| 5 t4H$L{ $0b#Bq;Kw]f1T +4qwIy4n+aT$Qk$$߹^8\*ey>]hI$[$㌈~ɇ9.Y>3# "| a\MƘ(D]-#.qȵ@t\Hs|۪ΝK&P%։Ȣ۩8O1.) ?1opv345%LވX^2GlTϞQBռ@qh=,@,C/3{ SCx>Ns6 ۄ}CN)4,jM G==`#Fzo̞q1p B-\rB 7k yf2%['J=*כI+*;6]{1/VpVcZ^_~SIX1+C褃z [F@Ĝ0kA !%RYFǁ- ?͵y+ 9 +ER[luGr!ŷ "a_adp2_q<7g\eÙփe @kLoтNM4Ȧv;[j%̴o'.v;(,;H"ss,$rYNڶ{> q)i[]Z919'WL9\}K¶G A B=Y ,\l c@&|rؽ|>WcoQXjvE96_8i>/QtMUmT o2s+m1!'F$Un#z%h1WIUW_gHEz|#{7Hu&7\+|e iCb* yf74z%5yQ9 [aB.R97 5fj{6Ky [p=T}Mxc+F٢KL v&\D1l & &8Y< љAƪ! ;ٗoMA҇oUNCX@sp SBr^rwԷkZm~FT7g0N"iXj:7 ~vxmG[@W}_we,hՔ @K<~0dA듐'mf9 .kGIXc00H)zyvy*`:B e0ONWM| &^'oΟmZ+UUTUN~-ƁsPiN8 N6yC,蠛#r6f@pj/Ӻ@ꅈZʅ6. 2r/xYB1R?(Ae=ֈ-]%Yϟ$'E" %}LܙDݫk 5"!Ax`WK9]r~Icek b^Mf3%C6ۍ뇑u^7NSpnq ?= -JjV'F ̘,M_CsjhWL}9nߥR4chi: ìйi?1v8G J_OR%p.MIÕvO"t~*wyէs''nm` U(W&1͗1>1]i]rCaiY+lLV")һIUrYNu57U^"/Lcښ>jˌ)KL7WL-Mݾ:3yȰ#5g _\ƹ^>ɧ q@}eq#d݁HL&ΌviT?gWsC5k=;ڱ1z/` aÝ9>KlIJNSNVFEb O.PRI i(@ՓZoB`ÿỈwRF^0QJF^V.+ǑoMәtC[{!Z7!li),%U [J*!,RayS$y\_&R͌E18UBqUbF7^aؑ/? L{8ˍye&wy[&D<_sXBR.a@ԑrezu:}@rXeV5Ji[rD2bPH7bqBrC=jۙnIΙT27酑T9ӣxQ4Kފ8۳ R%mH¶-fS|DmnfAщ9@W;䏎EoX4:>~`]9=<M C}kgiB_)N+<\G&mSs?68s<o_nf^VhS.-aB#IGcIFW!(׍_bV%"f:Q{A7{|ҏ2Rz)M-1 G\˫ӾjKI Ѕ]h՚\t۔ vП`tF8ic&eU儋n9R`?Wx=_Ԝw*לTVVxUHmB'£:DmKj?(`a@bLjؖlXmv4'v@!V +nn+NIf:ڗTբQ˕GCf[IVUU=_%DDULI޶^*VnD}]AapS'm g(HwQv|Jw]%f]qp} ~djgwSDTm6pyȋa%XbއsD@,2A$zaW;:(ActJ𵲦XR'#Gߊ.LR_;zi 0WU ƷU0i1xa"%66?@R\*xe8#{*w8ȗcp 4Yk8Uܾ.8rNaG.iY! ]ԌV~n됓Z@(t{& DQP j?[!J擁{B]%='!&qze;v|2ĮwS3hYBdj#BD&器.Y|\&+ 2Z> T|" Ыyg۟s=ud!boR.Z[%|ѝ ?R,97 ;9'N6,#%ֵOTO(2믬ZB+WW$`< }HA&l 21w:q>mrhъ}DJsӣ'*7,7o$ u˚f`iP>Q: suK &G):PhRw * ,]d̪P]+Cw3n®lULQ?6YD^ !V9i+s~BG+oIB!!l,헁(;K@L^)seW1=oby%rΖU ̻XjP-}[𓟯e3(DM_c9!d^UW*mɏ'VٺJUlmM{3.XGV[Q YmY3TomkٜfoOg`uP|XY<)Zut#?aGN'GqvG&F!"媴uN^Ej[qOX!Va"-(n̬pk%\ڂ fDBc%=P)lGB1 0 wQ_gJWhQ`HM է)*E|{x(0E`6E x]=TB^GR q@X^N~t10Y;Q6%5Q!%PCWl=Mϕ Wq*>'Oby͸%&a 2YW܀Kmq!.b H6bhixsȗ&t|01'Ju>ͻa$]S%B-p{زa)-,+͗,-TN&RzCr dQذ=-Hk<Ķ.$̄1 J=[X#Z9ep ݁B w6\bbpToŕޠՈjivH2|#nQr8fxT"6# UΚHxN뻎+2rC*[0* iMm_rK/s$*P7=[zyM|OD ]H)҈3"Sq;L°Gz,I̤$jxOl1ƈm3OyWuzݚ>RFp=vF$ c)hAkRGV !#dOݺg9d?k1sjSԱ^n]i8BIKNvWQ*;ZP-ϴK6|xDV@& B#LN&>/&m tHKgmBymGX4cS쎊۞A% A>^IG39j%#ճP^ fyb{csU,Ĕ&$E)uW\yfXە~bVs9<BC;Z»nf_|ę) "aAȄ%Yha$fAN >޾J퍯~{vfO T)QcxjEIU4B[^fXOlD0gՅ%A!jN2nc csʃ=E4L%M.pb2z@ Onzݮ8:b4'9[F[ uȯϘϮK%` tGv, c${5N?6BrL,4OrUHNtR[;LuKjҵ9 bw!jrRUED"{}]osCfGA />#h~W|/+ ߔŖ~oֳnmyX*"I ܪH-ν峊ftEe=vi{S6]/ mPH~~x=Sq~N?M:H| jJk8wQYFP6Ѳ&_#HfcK[ɀÄlۗbLRI{>T@hh?m:̹HGtԐ037EDDLPMTύB>`r 0:G$h[-L6ɭ׵{r! 4^~'N5虗⻢j{NmW y>j^}'cxqC=N@Bgpn|]]cqDepenf@$>2z*[ jl xI^ ,MgAϜS׽lv6֗An=}B;Fq|m<-o] b`"5ŵ En+l+GRQYaEߓVLo]Uz\ȣDjk`ͅa-l֎9  )1I0>TBX֠B9tUҍMup&8> %/hlO;&;x؁]FOm]B!3${N>C^h@(WB261*m8SK#W@|u)A*Po~4KoJmnh:(%xb0b̥ tg(9\Ѹ"\,{ ?qePpV%׋u }TFG29kY)T1R ADjlKbi(΅_C֝@R9A{]M`Zc Jm%:v']f^_u`8H xb!<6Oyŗ#,h۲tuZLϾ~{#MW[̑:Cb^n-6ؘ'*x,G 0uum/R!r™ )gzJ&S\S27]pWjќblUJK ׶d6}*56QqKO]$BUox ;{nE"ؒA_8=>{WeH*Fב胓.{:=,38"Cni'KjTfG17,l:hW NjQ{/b\=l/'emS(y:QY?tGs+T)6:`7nK]ѹ߹/ -ÒER^M4?шNսP"|!$C>~]Γv2/m[$F{-X~Stva_z 0 _{V\nctdajd3'7L @9#o LRľmy[6q`HVx>ɮx4/,cfN48Ŕ~lxx]FRaKl d=x]" 8Ōi=2<N>5{3UɎ;xx*_Wx4N³Uo5fRJx8gknΧ;e0PLE+Zd|2 ͂t͸,$ 9Ʒ'fd]Pȷ㩆6Z 58p> ӓK e{UJi iҰ."ς+L i%p(%od@;MvVr:㉥0I#Ʋ5y6i9uF#EHK)pWvg ŭuQqm㗗bjL¿qlt7h2ssn̥q)/IDZь6 ׹MǦ5U`>gES]>P>!Nx ' ׍ϢJo=#΂n!~}5|G;CWz}پVF7{t)0&Qnp="{VU},}s`Vߍa72܍XfTO㰹; 1iB~bEM;)ŷ8ne9(,tMݏI!yqâ3[*V7 -7JfQ&!s-3>)[yaܲ0>}BL7бPlbCc] ZP7 {p:dmZJc%y龾PFzcCTnsr2<T3$ 3WUd2FO1g>|@)r,Vܙd>['3!)CL` 8jlX[JɆL{63] '?07H&/[l5=qzCcCt<%[6j5~:;_L40OM^S9'2@,U̎aQ6%R& 7il_!?V(;5:2'n d4=;*aVmMWhv2[(ͪ":7o Aàpj~T}J,73ZZ:N8--zq[4HkKHzH\ڹnzW/:?ՑW8EukJ)!UEZp\rei0LmmO(K+ب:Ibx ^z E&z#ڪ^uŴO-s=M\ _0~+"v-h 4Ȟ=|_n>Kr~Ն?\=s^j> chW\[I;7_ dz\EqV%/8U!REGDL|>uňGMg8IxpǽWPۃO)X*+l'i|&*jU1u & άsPy=Sn|߷[_ŠYJfí g3~s4C6!p&ê_T呅1.tD(2}]S>!8mr,\ߔXXFfstvvrnK֛5I# +toX)S*vu+W2,.Kpĺظ=4d'CzyKaGPӇF hϜ D S-%UÅVj(b-兦Wu%N,Nm=ža-ÓOCLFS3N:#ik눫MCJY 3/$ f> D yP~-O|hg˓a&4Np9i/5įJ1ZT'dc6WPC"IwY퐨7󝴾t8PPΓݖ;يN ͗zJAw1(hT6JouJ%La !VONKԀ/u*iY<]x">޿R^/Xohmڝ"lE1 6jĴ2V4?Y CE/:"XCw~ZIqE |y`? ~'*nP!C5{7; wNbe%0ܴ ^Zi^tjױf!OfJ_d9w 1Yc4!rDz۳sGj H)#s'VV(LԇbQl~S.ʺ-?}DԿְ>U6U2{iAt\#7n O.iBˏ&<̢Od pm^"^kď*X>X~x֛bOiM4`=yv(Xz>ĸZDEܥ;V_nQ2a{H&!闛"Esg<őpecs/BsFyT7.Pv:MY=Q/Ŷef%=ضx`\ĉ02?D 5;'Z|Y`}* I0zq!>~A/9hT(u>LHDq¤C輾'z=PB!+.P Δ_ʲ-c;¶GdTTSgM{W?iW00 I ^s%:XaCl>2v3SRux_#W u5 mc1omqP|>W)`^S77!,H0٭٧?.Re$kap8 K۹e*vOk-YRrYNS zFVMy3Dp6 HziJ8i*걡,dtJi}vwti9q#Qurxqy+? s_츟`>B̥d(ܾTS^4k;R[1SMi*oU۰ XW!48DKv' c A!ŵfG},d}Py8;2 %;Zz'Wj=Bhc&4w Y0~GeBy"Z8J B7dL,#O|YoXcj]ye/rN ;l"Ǿ  ΉOEjBS<ǹ`du21I8Re͟a۾%9Ca7k 2x釲zš:Y_ufm}|6LӔ k$_gjws}ػ+=" Z l-3DuDsN%PD[=N-; \CM8uk4}K4O9~?Ygs P*GtҀ2RǼ,6.r/AĩަYӥ h[i4;U Z,9:K"WhPd'<-{^|Ttf{цp(WX.բkB| +0FeONi۴-uBr f%i{W*YU0!ׯD4dDX<ŃE0< Bvy0-#qp_:Kɤ'c+XđZ~*=&o9q68TsOfo蜃bR~J8htyo%_Vv_mv*͋#>q4aR^"yr,?L)Qw>Ї!ʩtsTیo܇!i17/6ַP&%]owM+ǟ?7R =ږFޜ-A9tx`P`ՎoшINq׻.nսhG[ Eu'!) Z$U ܛvme7ĩ9B,uGtŇpEe -[K]'\۠2: ڲ+ VN5]br-X⼎ GqE'oG Vep'Q'/8r֕l`-'Cxd^|rMtuC|t Ysժ*W5uJcϮanp<njMxEQ@:lO^ |wH#ΑŨSUIG_L(VŤũoj][ -Eas3cB1f820e](L]5ͦG6{ɝ\!4V~U4hdy<+@𡱹&ׁ"FJ徵GnAj$wo}Bu4V#@:"<ql:oYtĩՄ6Mjx NXoq}$}MRBT6(a1qd]A&mRҖ7^aR7f}za6. Hʔ1.Hv>c tny؊lX5Soi&m5@2u"4կay0S?ޟC")}b-cXuU$}0̳F4ӗk)m/ϼ4)_4zѳ-J4U`Ul+V|I F, %Ofl!j9PF#Ltvw.Z9lmҷܳqLem(X{jj=!ޠPqM\uo+8ecȳH'AĴ"S'a6D1P3y筮~ 3sͧC0|rDp$yĠhD~B_G!haǙ_LYqC~Q,GGN-Kk_/"5v E4 T*SS~eXޖe?,$SLNFt^CX *+x?:ȢIp43lܓM7/״z[q w 9imbh:^ʩ+)==E[=C;\ziyqhģX3{uR-"Aq4t9[Hw" Uמ7QXݱ-(h!v TU8;U/4d'Ùp вZp t⫶/BQMQg̸, NuT'kr1_ ! U1&>4~Vŷ{' LiX ckCg{ Ur1zN f6bHÉ0 ]\; ?Ko5A$!(/M,%a\1EIKDlLJUE Q!7 nYKBsdE%g*/좫"Y'~IH :؊f$L2?}Nf:Y鉽< xvaY!YhJ[h=Lb'g)'ßGll%^8ًbUh;R3YUId_uz470W27?, pC6/b̆%뤲(|ǖ21^sF ]f [ AC69 ,jMvCxr婠vwXs֌ F]'&$glDHoP) MC&;c;H5]elv ߣM[%gk|B%8sl K q@pjMĞivrElQ2KX WLuC䩄5ؼӨƧulEzUQ Y1G7.ڲatݞsNd͑ ]„.sBEew61^0Fu& $5&PI[$>O{>S+R =?2EO El|r kP%)A9E swjkL,ڥD㳿2CȊ-ﰑC&}9Q՝yM9>1SjlR N8oId aDUV{viS ]{&ƛTg ~Y=!%SLa4Ŀlw`S3Nj8~9r}-THgoIm~4D._~4' 'd~k4CsfylǴ >a&.`\3! qGA{_醽{w[YeLy(;eO7&8 # I|̧-UP\/|ŎM~ ";IdH?@ybk:+-?YB(u+k OjOwdq&_7 f Q5YD{@;kDH$cQ(coSlhJ~$DIu`aI\BYz}Le))vjђ:G1jNAlw ÈaP5sncRm`5ZZcxI3dRQt;㓀BԜ.;E@Xjv֣/v :hjhrW >v68;BYٻ=Y$ x$Wd<i2xYOM7?}W{O.O|a/l`%ۣ=> 8p X[a"y,^y209VLX-fv dkR,3+*" BEK ~ldE>{&8=0OGtrj-*c7*;vV(,|rD:;9L/zGrf?=Afo=².ExxO9z%N5oqW{ b#"<|6ۡl-o>~jъR% dJwH"2;肘$sƎ9nU ^̂*1x7&S{{/15)Sky{G)6 Y)s-n 3qhY{SR Jlʦe$ ABxn ҂:N'K-)d2mڈ)͐n?E'Kh_\I8yv3ژ`X\\{s>$\ m8Lj5S)uQ]4rmОݝt0%'jn14\($T J0o;Ɋ/9f T|KeǴžuAQፘhV]b'~/7{EѬ4dt#6UIϐ"Of*\T ;PW6, )P7}'Dgmv+P J]ɖSUJH*djЏ3(x ̔3դЂu#fq ԓ(X}DaaٟnM4L O <3wYZ}ooNGqȕl8spTՒŔE=Sn:zn'$Ű9)ZaS~`^mu{h ij o׳HV, ¬zst",@<>a 䳐c h]:_U9ۼ 1vOS4bKi'Z)&ПfYכ/mћv U qKvVˌ*2Rk/'Q]w:Ġsz1u"0lQSCV(xoZ#(I>r}?yQɺg#:V_^`&ʎO?oN#g+PG3xy4MUpY]Kj `-&"-y#4>rkp/O? l'gulßR7 |Y1dʦo$I@SDUie܌do!)`/[}~xJ(#g6&iG|ʩBmuR68VKZ.CW\ lo1Ut]'}ԃ#G,VJIi#6Fk hJ9Jr\}0lN=+̲.$] &^!b$ xS7.]_b>s2{&Th50]Yk?h,"(hǼG3k/9y [T1l`\邽In^8̣ǜ:O n1-&E䈜;_ 6|wbVAi? isD+%k5dk-m%'6͆m4hqs8(8q cf-Gx+P kdw'fՓZW%Hœ\//|.LhW~65 nBl]ޜ01Nb-,P?)wqz;O+6AW4`;!>hd.URQ|q\WJQB]/WZVcո:}F;| jGK*i'^ ɵWIf&)NuTrK{}3>r*"]1(@Cr׺L_ι91C;qtG qYbMBkLV>l靆>dY\Fk'^a򃘵[Jה%ˢP;HM!BH0;g̅Z{HvIo@S#ԓĜe l W񀣷8^sޚ\IuOF45g?i(M"΂XrXyEI &M`{3zV=mۣ >WcnU‚h84, =\jYF-ӹq qQ]_1݊*G {4|_ _W;H U%-N{${V K,.}AYq%M&ۧO?vYuUϥ= >&Ҧb݇s_f׈()j{OM )yLJҸtݍnLwe3i[U8uRTƁU obPoL4J>1\zRhFXY'Fq[3GO%"My!7r&ӹhXO.L4Ed2; Kj>5e#kS^lsgW 5X(-߂k3dΰFOfAPrWɦN`lf7rq(uʟN+L2:CCr^sAa7:@;׌5(;/ϟu3aM![Qi3f%{]ԑ9HRVUd9ڙ#{:]LD1=.3åuOY?_EC$m)CYeն2n-ߥa'-m,k(#+<:[TtFF,0 jh*ђuɗHIzũτzfI2ױppBD8Ft0$3zJG[ͷ{#d LAj'9kT}*`{P\H 8 Wh P_&"yPHsE1ltb% _ J 6f{$$DPifgeCfp% q[>r[إj^bl=aW=~PO>%̧AL33)y{X~[Tb4T*+V.b!:sD!B&`bwT$ 1%wL[#T8ȓDYnL2hMrĕsU%I $ w\S.pv04`P=WZ70b CpC%co#z56Xahd]DU;=ۏ@e~"$Tk-@kr#kwjKwxiQ۪=]ƽfPύܫP\|( wAԙ`'Z֚q]Z}o ',hH;l/ҨDl}c'\^W)|6_C<Ѻ'le/ItZɘX56K>&a B7C{t:F4t!n7CQ&Z`D[)e5y" t9ڙ(;4dn^q69[١ (`I_e %;+;:U";ᛉF`Ot?䢬x+DgS_<`X,L'׋[d+>'Eaժ'%:4~o^&d;:sΠ 9WSadJ~6d6S֎<3<猾!ffm"<]mIeFLBA| 1qN!Ak=f@骋%pbTX ]?Q%fݲGS 蓦!㟺\e:d߿P-TuVǕ^/_bzO;Bk,hl=ȯY>$ 2NQ#!zr~U/Fz1Pt;VwDSnpsYPשleP ] X#zdɤ͡45'%]q!F&g>Rd($i֔]l$UFlr M1|E(2L?XB&C{$U#MW;FЉR\C۽i[ 0iiXyGU5,-[n?\55̯}w\Q5[;9^*5GRm4Фw xp91ׅ>ks&'j M(]H oYMOW >OLjC*Io*&?V's~ LK?1 4m1lalm1>j&61;wih>)(D)v_Q__N,i+$ELTtF@1i 21s$b*#[3z}qmzj|ߧ/rǑ+9㎓uⷃW0V,ucFөAA[51_ ӵkQ15!x^kҩKԠ9Sb TJ3zW$F;qO?\s|>HrT찲8ihHZgLH߲٧(sW1 >zEa-6j~S @jG:%RMIE Ctl6~N1g/; U,)iEƉ%|u?C%H UI~?p ~C'@ M;xVL#_ZYp:)(:b`$eS(M،.7%v{)zWO/!ν,.UU!kO`B#1Z 祙ƞVKFC94"u* /@Z@tIpZz Ԉ^Rx5lNAjkP\ٴDRtl-h5s 1o_t(dq?4g[J"Mi pCl+"JlCzLJ4\{./"·vJ'Ip aVc=] @ZtDA7!6[~dg_ ";D_aJ[/ A~^9R"Ee|  V9Wƴ%EXzB]`F|L 3pΉA\E09( sY&F>{-o5x|*vD* 'gXm!׾\gy,_Z͸aeOC(hGE#e:"FBSg&YYzRUN[_0;h`R(+/tHv[\5]~2E3 W1aNLJJ@ԷjfΉktˤQp78$}s k1V뗰 ^9tbہzv{_*%D(HY fY#U x΄8>宀X&o&zK'#}Z2L@8qjAйfb=Fѡfy&ߖm]8R`RHi gqB{ۍv2;}P9J6k-7`TD1LjSh P._ j 4β^1o#58tŠo#X N*-'Uw5z>Q秈%W䜋^5\YGo.#̊'sq񳭷g]!OqSr$*+>zDg* r^t-+ԓ~AV/BBx^u{²0O5bK\PTyTv (ˆe^Ձ:oY?*_{,o:m"|q#lheZGMsէm 3mV^Cr/kQ+$H:rȕ^Eaˁ`W~TBS&Q|x88#݄4Vэ,)ʫkwC-rc՛3Q)' [2O+Qg/I!:|maW'rNiܫo',S<] \ DkoZN9hu!`&@r.GLʕk,QbeRyyyI^Xe,Cb_$&>WrJHR͓*~?$()@WZRO\ǹ/``i9S#j;' 1ƀ&z$EPGhG?&(n-ϥ&K|MH?b,]M.@8>j6Eɏ*UuDEqB>"^PX\` ;M $ %H9n˙Rh\] ?zᄌ5'`EA ;aT3yc;.ѐ6zk0msMo'r[iG4vl 8(9q ⣺s:J[Ÿx̸[Ս??'鮇?EԵ8v-U |M↥ZEM}A{" $J{ gR(4y:4 笻}06x.yY R#DI8FGFkW_8K;ĕx3a083/HO E{ycK? yL$M^@ F**n5!V%hvyسܜ$ \EȌ Lxv0P2UMat}e[ժ"h9&"AC7DX߹3SEltWGz./ ĒS D p-ΪKsMc/L1%OɑLP,g; $A솏A{9 ͢ntcףݱub:Si϶XA .Q貑QL(a]`~uifiK֘=-0o!q2B@6*rHYׅU{#֎QPUB.aTedmr~ibÒT#kw5"|]SX-CFvTpd3~\AvV/ϹHhyPxcD+1Άu,*+8ԁH3G |0=+hI j;…GL%M?mcvrjkuzh(Σʫ !vPHhϤ$G*(W|RcQxu%^ FOiW(Oy zPÃޜwy?y =b7m~mI{`琱e1ɲDFH]Mؐ{Ј+;@GZExܤ Q\8mCyƘONw!f9 Fjya ߍbEg)Ffھ#ڼf(U*-^:tBC!ehH?TqJg>Bʬ97iN4Z\.ED8 U̙vNۢ,w#sHtH$,b:m&񎨯x}{`% [+,ӈ PE]zRSUC V b2pd/( J <L)둏!/UgXjMtj%g0TH133h`Y|k9_K37x.4r82ac/%xI񘋷;DAVR7=j:T<S6NwzۻS~힫|snF5x'^Yn`:j߉Wn:cՇgWauL/I[oE!+tU!E|iy-*qԌA\Ɯ/1j7yNj*1iijsTԶw"&kZ8 =X9N&[UDU-D'")_D(mCvc'[R/Fn o%׋ d\y@b 0Pd(m u:[z#rfb/-EÚ%ⱜ E{8; IOhGQsX`aF@DO .ws:Q[=7/BWb]1.-/Qɫo}xcy ;oQn%c~ ox9k*:H n%LUcHGA+mH\" ;|?z{7#.jn1_M7PUb*b5n0i٬1N[cGCk -ѢsϨC2E.R~]n8݆*޸ OR(Qgs^YsD冈_V 8~ڈд~?ጎ_΀:#0BBO 귐mMU.\9hm_6.GLv$;VI LJ0x"!Xi!-_'*#ݯFP씫wYj36]]I]iVnm8r'>2\OxKHCl\ fҏ25JwhQC#}-eŠέ< *u#_QB`A!3Eu1'Q(7eʳ7 AZ1 ~]]WTPl'.8%E_#FmVl(sHtTQp*O1.k?&(|B)x}+@g?"( ն/&\Z`1 Y[TKT3͹U%<[<%틔nR)sc1d:.ND:@B\8hVKpv̜)e񟲱 AI)w>+y`k{ZH Q keH9h%jU`|~nÇ + z"Nn2=\7ToQqc1iI"!ĦmoGo(yG-~"O D ;r?,J4oIDs+UNb߹.Ix]K0.M),;7{R@S\C(G!OP2|J 1)OSeˌ$P`k*)3;gxJX]55ݝlge@~(H9C+n(]5Owu*ZY_?q\܆"9X2"|"#yS#᪩5Qeዳ~:XŪap4L/tz~匬 oc*DGqMiQ".OLnIKve%;7*6;OՖi;^a7!oS"մT~}MS@GnM#LKSP6;\YzTn-l9VꇥOK1q;u`J@NA_te~V͛2BISE\n5.݆%5/[gQA71IY_ӡ`o!5)$|MGc;e@Mՙܫ' |5ݯQ0Mn zA*9Jڀ:d]=&e* 46|HdS(otj97rX H,J6rpŤ e)+c4I:XBCd(D_LHk> όh:Kqΐ[kN C!GSjݳ.%11=\d g1^GQ;c7JX59_mQ2.JWe_u _u"B.~'8u8޸*k >9R'.tEg}DߧTuV(v+Ri뿈i?]ጞգ/;&/T? uwV k``{ާkԤt 1螌%=V0?/YP/v̏3]ca^0yPFFP~:UV\6{ف ܯ`TD:scnJg.1rge ږn3VLC`d^Ty,*cF}3i^jƬu:=m"F}t>j[ 7r1=Nvlav=M # $:!,O H(K"б [.v^-x_*#P r7PwYi,;߿~Vf!!;]rчF鮻Oћu,|OS\"6jB lT'D-G5tN1KBXhc+6#q5H5:¦6sL.F۫û{+4R 3{40/~aVoe1!&WG\| @ԊGѪ.5^֥fW4$NAl\}T^g݇Z]O,A -MU/es# bٵN6jap"$_8EsyZgzM7Z$l wfIc4xsĔzRsjl'tLSNҍNW%h|Bf`'Ǐoe>=(#~{t2d֟W]XՁΟܞѽI^sx*t O+9o)Ѭz[h]%İגKI}_;g\s*{ vyOaD-*n҃o*fG> #잡$;Ú㫧D9?P嘩 Ar̚7U  uz:*.6޷MŤ3D7 (vD[HPz751Iڗ.P)C-Iq)~w@(aA#)T_.V`Ŧ(784NP]m1|AmEIމNi*O-cu ) ⟠.gXEY=S dp-|Q~Hfj=WX6L{%W  &xLhE[c8֏/|]Dt[ ՏȺNTڍ ޔa#GNF?+Y7t5[zɀĕ Z?^ L,eω#9;N/LyCRꥳ:78ycq('GF0RE"╍(,d VJbNŌKjpR\ `r?x?^%Z} V>ʯOk4g=*ZZczA\Fv y{&^|tE!cHGoQBR""㲘+RZ5mː@%DbJ'_DQwTdEQЛcFL1Zo蕔B4jϥ>$"6!lfx?!{Q@ vGGE!(Q3AMhr~p#…1#r-*ʺ/$V!6qWz-Ly)Pz\ghI>b9PM")~k`z$XR werr-juJǫeRY0We?+?8Ine2p,W r{ZF7׋cr|| x=dKHGgd;8{bo!ZF+n4"x6elZFd 3++Sb 񋛁BFa s]å[lTt׹Jڰ-$D_ao aݫ(5.THhdqS}EN2Z01K"W҆lȼIit7帎} j:Pz]͖KM'UU4P^B6v`hUr^ܟw].l^bqb>ZHڶcxhmzSPEG [g-8YO4ab-8ʦGUuE:#7؅$:c].'nXueNUR|y.t\Uԧx+p-ShQQ3d7M#7. j wE:`Q"1B~4;V=PQlQSCpM]N7,m=<} ʿQ$I`JфԉJn&Qvѓaj*֝ __E^]*ۻߌcMfllS6l͏.,:L !SԏM88=\Gڦ PpӍi72M<'h4>UepՄʆ(?+Whфͦ2Ry.LLʼS͈ONqB\܌_ 6D K#ĤWjgnҾDlʧ[[Ew4ZCW WS/ d|YXDbhg[ u1wDO>:G ̷Ccbm|ܣ]^%/+r {"mJ!y>hw)DRt@J0_磨Dn1=o:Z.8Rpե.GCz^p<){sD]6CJgN43 o方8KoD-/|e8I/&%xQ6 O~仲N ڿ͛jPYI]W ~W]+f, ħbRTFIl0V(rW5<>g& qzjkذ#Mixn@ch͇8t[: u i \'TR0 O ]5 5YO>A=ucRsѕ=X>qcRvp".vց@nl@}1-$>nfmHUPCl" z*ܩ/x؎?kK7lgp*Ua.|/'X*g^m*Ch'Onu`dQaOetZgc ;֒&?,o1:X -Ā3g"{UP*nqVIw QbvKU/K><ӳ97_W| KAxc8CzWC5X`*C:NpQo)SlMQϣIJVv:'p*dߏ?ξ@uqT])8ooKJQ&ȭdcʴd'Ol3#^!AM`Ef:Jv(}e _11%|e|XZzDǖvKJ%[u JV6_灸sTB4vqa9r,yߎt◎j8T QMd={-w%w S*+C(D<8ЏQxrJZ04g2uDK:-ߩ ɇ$i*w(6B,|:mJHs2kȢbm2DɋpTs^!7Zf잞+Y>^>*,U@}T[AÚ奝j#?HUbk!.ԭ#p5c%uic∘Uxk5!5"Vv{cS+{ yѢu-54̏fj*{@%uQİ`ێӢ?Do+[uU~f 4b C(C;x}HӸ~2>W%# F.7`y IdfU+~g_z7Av0nW$@Q:(VǏlbWc2.>#yF80AE n exdba[ d;_H #C?R̞5 58" Nc=#"^TN׏ )ܺ=.uk}:MBZ'RZW, PbR|"<89ɉ&{pb;zN,b3C*\Z 0Y l1Xޑ8)XP*{7r$:~< +U%;A2^ sz XφgKɯG|[F~-*:eMI{o_"L.?b٨b+D鵹N+'s:Y Ye G^CR +s|r_/9ߝN\@ʧ*O5oou+ 'ykhO|pHM\xtZspo^ltH5b5,/; )EN?t#Ճ^䢉GPO`2&L6reAk "cH&|m <\ 0۹UHGiU]{8Up,?#=Vu$k{Hzb7f#ss)1zɹA`uFkEg+biN9h/H0`l 'c'4dzd wuBWlx$4:ip $߂݃b4'|˞0:VHBt%e?-͙._䶃A%}&g\,]2:dR># AC`>X$5x:&&w--{640D񣶗Vmt6HY4;)$^P@]<h&hoM;'>^w` ~I+xV za䅢H@}5~W8N6d},SV,~5!6/M~Q|jSN&V"S^23ExPo״) 5*oV V j J/$V i7GRJl="Lk&QEs9g.D'Y GGBU>}n %m*L^&h+0O dc+#mX(|ɍR䦄O5WyVUnh ;{. TQH)o%%#dxD]娎d2 99.rbBc NTUvxj,&2;GJ33WNˣ7w_BC'.m:-mΡR|͆0ϹG:# ý|J+B 7:5gď?-yӊj]/"Npsa#<`ɉ.LW?|aSNL .j. |_~T8&f@ լW]џQuE#t)3jŹў'W$ +N?藀4#L1<0 E RܡH Ne"Hv+CSM?$IjSD ECn"GNwZʴqj>.m\h[$!_J5EmÕrV!1W JIdVad c 0S)2dik—g2H.(]q.<:Jߚ塟1%l~u'.PaCk'-z[|\IkPwX+"Ma̲ AY zU2WXwm DE}xcsyBxɶ#x Dj,MffHܨo{QF;}Qjgdg G$OܛF,mUh8FOI+ٕ@}',K?U>/pG>sQsXxֳGtېvfogFT0rӎilzЫ]6ñdg>S9&VoƇΦzGUgGu9י{1e1S.O(YjO/?⮤/!LEH?%ݼ^_K lL P)h<Bi Á2v];N+wQ l59[ Wz|7mLJp:HB[9D=k\YBPJ#",P Ñ`?,'YNh~,roK, (:"p DmJrHr>ybQS8c/YVkiC|s?`NcNS_ߑ9bsԚ-7f%"{*KI2p4-*WVX(XhoSngbt s u(M~|Rf "_{: -ӛq>X(gژ}Ώaݹg`}$$@P&R B Dc ٱ*j=Ôd,seL8:rߦlk礖 ZAݭ,dllY-񤥣c'>DӝL:pʲ: FV4i͐Uzb<ۓҚcm`<ԷUٳIЃ(=A/[8\ =ႆ`wE͹)7^orM]Ɵ4kOߔ瀈oDfg {g 'Y!~ u R;ቿn<ɞ/dB-Vm(}bKWUI\g~)ǝY&{m).c.;KL9mEN8v\"YgCFaD=**:)sGllLŐVYwfG/M}Wv5 :66t%S, ,8 {&GU%¾Uw$k^Jӟ*ҍXSͪqB lW]QH#seBT/Gkh03~,VH @( Ư!GLr,kt-U`ıdXSLrk2/Lie MCrD1E&{UDh3YEBɘ,9B&,nMV@̥C>oɦY.4@%O;+´834lޞr*#"P27e+Hų8us<)|=LrٯVǕ`!TsCu/lOr&e9!cm!&;/-!ۮhC)g"ԉҴvu0$lBEͼuO2dn^jbF Hv`aw pȠ .tra,"Y/$ HDnrlA?њ۱N~Ǥ9A"l2wȟ!C; VmQZoPEpUhmּZ֍7˩HR F#IҀŇn_R K^H2kK,ncMw7nwFC'\LC]]`o;' d2֙4"Obdf29B܊[Gۃ*8)2Ҍ7OZ "Avq T 6HXTlU|hgsz!58c/0`lԊ#oKQ&!ק9 0?$ZXZClqMyxxoyō`z| #iQOwk'7)/]e`K;s fS/N#Vw#G\7e},U N " j/N)ޘdXI̊\Ϩ Q S+ʗ%мO%0qX0ɏ_:Vv3io7`KE% {'HSN,5fCTg\¶N_̊p0O^^C.譙&P(qqS@Iw.!eƾQeײW)c-Vlnkpj;[r+ ͳY#bN? "sx%?]õBP$ {j2CW'|u%kv8j.a=q2Q_I4 *0~rr1?%'U.7 ZQ N,tv4^`1Pg?clWA: q~A B{9Vc^Zqh)N'n]m(/r{w9ԗP虈443[ʹ[3H>`*jC ߩJϿ0o$(TDIH?GVxN/iy%On@$wi_oqמ <.px'0fe+A(S Ti Yے45fH*zG"rRH2P> 2FXe=~xZltcLPWȤs0*Ir9/ȓQo.K5}LBF_!y۵,,}='gGsb(cD@뫆`ae(\N~~D.NhxD5򑎅@H*H1A<<֮HD9xiDβ@-m|\Y+9g BcUfQc\F@uX"ȅ;Mђ̨!4]…wV ^:"\lb ܠ'Ŕ@ jHז;vٌL些[X ɭgy_$mhYt"Y*:gƔ':-f*LV9HnNf2]Gz,„tZ!˼]Ƶ4yukbX:{E&|*ATL֮qsTg.l0fD:#LpsEQqJA`e֏~eo&`Ү,|ZEIP5Kv֬zԂUZr]eaNMRu# eC\bQ Ytu9yy +- 8}J}p7f@p87I%Vy)m  -׾lP m 3ȹ@r \ _{4U!18QjJ01c|J{xcnjh=g$6` xE+}$6U#w%*!X*\N|rZv`)Cǣg19E΍1Z903X|&!KNZhƖ(,4wkab %3T?3:/- S$,`|`}c ƅxj3{@ ̽',AYjr5?fFXħS@pA&j\>|+UH*-DJhͼo z. ԕ5Xb_C(RA&pne~X 6ۨN!#4zSw[xMz.yB/2,-)X f2Ţvޮl0*S-">0T֚%Qy^t LA*wa43ц܍A[jDx>(#$)+D J@ٰ*y9[:2+]r:p~X|YBqp;{h6C# rŖY`(MgUiF܇#70)TG)Ck^BtW#?T|POo{@cEA.6㏶mbHХ9܍@k˵=.2Tkzk o+]Oh( I%` +|G4` "5CsSn->8b/_s؛̀ v )ۂ&|:6=RHIz1a@e T.Rh`5𵪚*Ǣk ʂ:6L2ʇ>(B[/:y[`H*k4i_Ay-J82n~"n@(hA*cb2hro^F@4evT@my'eiq:ykPo=-79kpˮv\_NaG gz:A r"ݫ ,Hz o.dy4M&צ 0v'X0_>xF91yqڄ~MzWC!Hi n4+ҴIȌ]Sg4nhFIPUVQUz]֤ZԏW͊<@AT?? DI"^z!-0ad6K'@ti|pAP=,ׯC>.V<87LrrMd"60^a: ŎH4:̭}]( Џ^NxyƛnV 9wA0Dgd>5/&;bG9MDޗ̓yHA5&mRT^_/8ś2^HvK`srIl1ҳJ=X]bF8fȥG4;␍eY\j |F!YJY+^y|܇;zZ<هi /)]76$5"S}x\X(}<1(d?$Y5* f3I K;67]U&뚁jzωyv]sԷyai)*H_%vzP~tզ,V)Ծz&vfݖu{M}xi^2̷Z{eK%(q5zc2 V#mC*\Ǡh$b%<\ѕ7&*<juZni|RmZw4>&EUH '륱#5H~ V>à(>]) $潜MCۜԻ)o$[{p)QfD Rm\g;R^xIc]24#78NdcU9hkrpm(SNfb{fbRYl ӂ$7mۡ"hi|e.C5P$F/)aL妇v_\%3Z$ay`Oto-O%rC)[H6v5Gd6\% EKSq|M:n7?Ǜ[^ H2 ,rɾ Ԗ8UAc}. |RR4\KR~a U:CHOV(p$ը!Eqd[ RS„'T0XtIaCO'&1(GX{(A 1/Q$PLJ_7{5a}Թ;=xu7$"oc9~^Y;4OI'He'p^=)vb"+ *+#.¶@埯ZvL)ij<5fG$X nO<64 Lmm98zw}) *%SF[-?D:mYWŇ=;3qΗ%f vP2"Ӑp3/L [(j~T@O6i,p _9 @ "GBǪE@@܀%I8G- ']z(}w€Ss姶ozHE Dq0b6K*q}.HL!3>)gzp'smPfS\TXp҅Jj `_p i˹ Qj-S?ҺV#`߇sY2ti "&a7'RiXI(,8H3oXFTimCֲ7HW0&a n" Y'1 H5|ʺ)լ?𥎤f܀9a[WU\o:o$8wlզJ} )UGH(;` co]rz2֙}<NO; 5iD@e*8RVw!eꝚLW! Lm6~k%{#O7,|zꈎͫsx)G.M7v8s ^a yf1"( {!<POsj9\J$6N"op)rBpF۰" j+nbSMxSڨWwR^,#n#ntzyn;AU*z`3FIHs}0ٗapԉGo$54'U'.G2u*-G3}Y=&ڭxFV)x3qfPtEbBnث]|* a~=_!)\XtlG)nF?Rh Q; A ȹ`u{r/)o@gٰ(0¯Av#.)!u;QF<_1jC!ȝ̥qOGj1 }ł0nɆ)uŹ i/>4|UEYw:eM\dSI7J Ooap_m(Fn18jWM E ]+w٩ $;MTwPnأq8Bd|A*ؿT@!z[ȟ ͩzLJ/z&_6@T+ob̕ÙPbi۞le_\-\,M={>hSR:uH' vux1Z<5ok@XP%KQm`)̷7>#AZ)u74#NLhNu/ԑH )Di.Ejzl猠Ș߄hlTt>(ݲ5C #y!5$ux0T0:䫐~4]4 *9gSj+Pqu5'g\ϟ:>gE,ʜ;/+!^پsQ 8aW?M/U?s]4D:Xl +TH^ EpyiK_jŪMbiM$+I? 9wN`u'Ǝfjb^j̔]"r嫍&Rb89}p aQ0q Ϩ@lhRg?DɏdJ=-# 6Y9.ROKܧKnnp  NÖm[ 8`ػ;h$, 3'9:ْh|'8 00'<Єym$(Ȋ -跉1l/֠@|eWK꾐uZn6Ow7Mxx; =2!zRl9Gg|w:$J-7iI[ e#G"q8F<0`;S-=` Fq_llEIgz(IEVxJtD?Bvf]&}.GB7:s6_nc3ЭҠ;"x7 OawQ41׳AGdGSK~j~'w.Y4qRR[ݾ{g|cbx-cČѧ_c,W޹/(po^p 07o=cV ps'l:$@I]^j^ kGvsZA,Z ֘:-%+vɶ ŧ@n7fNh̽i2kLT߸U$`hY~NjJ؎ENj I q5y(=nlKSB5aؘD9 pS<iyG.ï1MP&oLx {CbxMÀݗ/{]A!4$ও' ^U$lנhԁxWN bj'uH)c~vg[$2&d!|xgȺ< ˙y J+޲Gdb:HPJo-&o̰Ŧ))ť+cMfeuIc/H]#3ςDA5t+^):+5@1l9,-M=ilKOWJi1Y$D}IQ6>G'`w~&*w'-*+ QVIA:p)mH7nKw]XCYy^d\)tԌJ`xh7ҁʁ >C‡۵|CG~h RfS&;uLl;,p&BZ8F:h ̛oG)OE=ګ>U*{Bҙsk4r,Ļ}sR|ÑtwKY?pzAq hװ ?iK><`T"_UM`vFDs})KF qJֺπ͟[ݤzpH P`ggs_= eWzn;o aI8<rֱm7XD4LZyoߦ3B=^ JvPN+-Yτ1 ı>POykcK2ҽKm˪`FB?jddȖhj<ؕZM?_OC=-x1Y `-l \$ .yhT Ծue'`?~oJS-N'6@ ef,"!Gʬzh BiKΫ*Pb8 <~)=LrM~J=ʷ6m"9/Jʳ  T8g8W1z$5BE<S`a^/zpn>?x-A^l3]nunHjpU+0"ܭ6u+xL*E{SB)4h'h"mOnVBoxS+͔͒-r}[9Z'ǺAto:άèDwӤs m<瞸^+%ל8wsAܳU֮/IIЅ]'r)4eQ('oKs淈 $@OBnBnNM|Yn?";jrhtfk;X&Avd3~~Uߧ[?ѡX&%Cpmp ZD#Գx{aM9.9*W>PuF # pUSB')O#(7q鸇\+aGivzv *Ƀ?&]ۈ]!ޜ, m勬R-xB۞ϬAh;M &"P97 ~gBIe2Iqa'g *≖ -M߼䈳?y+uC:Vl2c:EWo_ ΕSy~#-)`eݙK?9()ׂuL0p(,y%QB kz\&ኃ^Fp-ti^>V43o#tűv]nLթ?=60f$7rQɄ"L@p_:J37oK?5_;O^,453bA\ڕi X,1F[~ ^IN | ZZ_/3WY-8jxxsud1x> c̋NMd&Px kxR:tD]1e;*d=F0$HTʯHe?-1 ZTCȞd[5 F+^$}=ةĥvd?ct+}+D^u3B (ɕ-P1 z2)zM;C4ϸn\A#xv,b66XT|Fu1Re#L:}Rz;O6F0MDM8Y_\ּV,9`]:, k\dY-v'谥:5#5JfS)'ZwO5ޔGaBonRyT7~wHzf#v/튧Sn)l؉62 ^t7fYn䡡!{y@}_`'FCn?bIZ-ҥ6ĥќĶ@E00-= w;Ts/D|e6.Rɥj=x%1/C;^D^F%&_]z}ic7k0\P=A(fow y' #+۷+7+MN,`bϖKtyHʱ9AF_ҥ:NV_@GlC33SqXLM# GZVu |e[_]G{hZ93(=<_tX#φv'B_&=n==!57)\HsJzMلU> `^OyH >GRXX 8Cf_p{Ve(C./Jd!ˣ>'V,U( +<;WP,]pTLZw 7dJ oYB.8(o|-X ~Un` 5]!0&i㜞|fl,Ac$ #aR^eS °Sʆֈs(hXa@q&V);AHmf UW /;\K_;ʰ>#]n`bĊwA>̌Z/pC䙹T{;89]e; H9W_%ʹT%/bŁ\<:.RH޵q1~3Υ8.RYUX#u3u/e?ZSҌM/Y"r;X{Uw뼦773gW{pt8_~ߞ;(4ަ VΞ h4+un NHX)#^Ln nP^K-3Tҡ6[`:]83mQSoXJÕ_#΅|&̩Gxz gN`o$;ˤ)QPc=, qk{GHi}f-Аge#bF5 |vxhZB"!B9Da F]"?{sh;pd!~ﰝKiN>so[h߼xŚEÕ'Gfى?~NADup+]  ܎ߡ9]f2GpЪuf+ 8Glh|K&00>gSFքr'ݗl׳Ҥnd QG_|.b*Kn cm  *qb`Jܚu4ˉhxLV~C Xo6㘖$^/&9pcuWob:s$( x +H]qʮ 3.@}n9mF$=JlX1^^$k_)nL=Q/w?%=]T)VG3!e]T5jO?fl&Lfq m7 =+ OD\~qɡ?ˊ`tt&N.lU*a^aSi@~Uvum>C7{SfN!—YUܥ xm%uPQ S3o]{,+ɩl~`Q$ xb}̉wT*/|l>BǴ(7 lEbi#Kat;X"qxlVC&q HHsPR^@4ib^_׷)<,tesxNeCՀDdl)P Ĭ>wѷ((";O, WS`+thV.a+)cl=Ǵ2RnMWbJH_JbDːTpr 5_8JP`(DY[gXq Dkp3(T]"%R €wt[NwxfE9)9Bm)~9TR`}UiȄg$١2P#*;C5:詚`۴`8> c߄]v_{٧췣mSu Zfds{B<ͳSD& ˂@k8)kޖcO>ȼ^8H$ PLF)0>PkHi+; G0m)ߐlP Jl4'# 8K&p6[hPRYG!FD{bj޺UB,ʴ5#Lof'vW+$?Xaq )D< "j4Eqx&LbNVJNXqj>Q(+< fLj{+_USdJ|8[J S`(>-YBz3r*#RQE3!K)ĬBy EjnDHM 5hy9x`O$򋒵%ዙfo3\?(CԜj0qh8r"b 쏣GX1g 9Y.F5V%x4-C; 1F咇 {sbeVgҸ3B8-AG=~VNbCd_vH~BҌM7}*IbR4oX4, SBMLbܘ'PuTZ%B;BC6h(:X鲇=b~1;#[F*/6uB 0p`MK2q;Z ݣ;w`,ok#LNx1mEGb:w1+J= (S4z  |C0ġyC7;sȪ4̠$6 %<ր.YE":]ӮX3ې& !d x-"ꕺK$q_bͲ=_]_3I<<xmnޓYW5vknED)F6qNL8u\E*Sk,,nXd c:tIu̜Pvk~{<]Q9[EvtA)X$a)nnp'wݎc*`͸k31gtthDyxB⒮"8Dz>6Q܁4mci .tKi@Ȝ"l[%ӴL3CY4&h-2މ*wxo3~aN6% V{/gq- uU{P{N~}ƒTf5K+ъ.e7ͿOK1̃nShѴ.U2CK٨_x`)ω8 E{;I)raqX{6A5@?r4`@,k$^bY}&Ȅ,~7CG#n\U -U_M=RvQ$!3|Ѓ0>.|p;5T>^hyUDQ(avi>T\ "6M+[qɝ91l5qZtw۱%ޢPˀrGRoW2-׽ khF9gaBxi(!էnܼ1 ܹD*0B!ZU$p G`e\;]Ӄ* vj`-|$ՕW*W7JDڎIM^jkn&VӁCVM5BLLz)"dV *0m5*u:cϥNPu4Sqo鏯7Q'bJ'3DR UśY pIb/=!|pMG.ZoVȸ=&5A$Iv8>_ _x'ǭ^䉢ڐ3VlXYE#|ՐԆK詠3W\j%C5QVE] 2([ ޿᣶&\Dі-::<7w.W7B \v7 0蚑Ke7quzM`] OW`hEB= Xb ;ӡwSn#5v}xVvPY#J4m)0 >~ޒlO1Y.o.bU"PIwGz~ꚩyb߯)i3; fgƓQ~K⣀uʝkhR85X 0ԧN _8 wjmz߀(*;Кffn< 8yJꯈ2x@+]|82Aڌac ):DNwן?ȟ4(i,ߜZcSԧDp}]4jWO5ļ'KI}~_ʕLJż =ܬ:{䉎/_.>(+ʩ(|A> 3Q.w/a`K@ ŗcS-ß*@‘NlJ<7;߰pz-ʊX\"q辫MsTY[jfx5!b?ͪ#fc鲮 "MlBɊiDElbB?޾H[On F8|@1PȐs _U!Czj#d(^bYm3W0r(҄W7$[Ş)t`H%6HddED !DuM.&ofh(UHWq2@LE$Ѻr?S!^ȷ,UJ~Ӡj5}HNveZ Zsr |&-I@-j߽b6E%3|(=pfZ5 ľJ\`>ƱQLGH .-vmo|6SK:ȌI2X4B FZ/Ÿ.^c]>:b9x-p>J)݄㕍IR-R/]}%Uw y pPM7P:9μwz;"~*#E(ڠNJM&;1E9:#>De=8*% E Yţ%6݋eT7m=A7FG Ib675\ƾB%zWf8SLʱp0e4t1=|&A6؆J}(#*=,nw!V]QO+/ +V !+xAO#{1b@S54Z텧:4dmx眜Ap<`Z/[;R =g׍YpGp#Eh5005 0ojӚa޶2.|331 δNB/+*3[vOq5:U%nu%5G x1^:9bư 9r\D'w%~kZitnbz${Ur H-^,k&S)xZIn : \:jD-q,ʇ.c 8:ْċRavQetE?| pa;sUϦ7m*j:ybڹvY9ZT`bVwjm7/c{5Uܶ*{2_+= ud+T<$EGl+/R|,xGr2CK 7)v4R{C2tgCQpAwZsÔBnpJ@aCb 59ӶQPq!Xң/};9gg;oj5-!h4|~ȋ[JiۑUFxN74R*sw ɴ֫OORJ"J?7SpNz3S)(4[>vtB5g欅AZɦY?: R&Sn޴h"*b%В%Um9)gOt2]%c̭!^8fܟ豇K9Y]#1}8浃z prWT`DEߩ,BT< 4y#9pt+;ʽNtၒX*Zb%[NzG bAnԈPTȞbޞ01j og!Oc@Q;~4'I'W.9;@b8k#8NXzƤRuO5L1xQ2z-DO%,+e\W;ٜa[q$_Xulgh>]cdu hOeSk*#>35аڀߔg3DņMc12-,ja [ {A%TQPP%FF*翦򸚹f|LxV󻢚hd\ǀ־Lï. o4# ȼ-v_1mn#ߢig1Ώ%0TQK 9,.).Hx%}"9⡐Y0* Kp =QI'/bXs̲RVr΄٭q.lGCf(rwCƍJf"]^$!^:g;}3'mm=sZF+!<| )2M QxZf_;EY@3<5&VWH{}cZ _O+@L7 O-;bA}!Dj unt* 9ho4T-C|SQ&!/1bpl 7,PMX1+tr.ν9@ٶ2k˜XT$zQ2- 1~pD|&!8-˛l;JEK`*'yYn9em^mgSq`ܭ4pwPi,tēN -ncd% M`Eȃʦ 黲]- )mn rNy䕸M^0/*.+ת,ŽkdI!ch0WJSs~Fjʱ$A&.7]2:c) PcEtu;AɍB` qA<5brܳ{GKg䀯FT[^y?\OY\fVf'DII+ZX>֩(( UFMZCc͉12LO@04˃S +!;M+Di=epcډ{dtvSRq$&Ȼi޼* ?ZX &xQ{`~\) n*&  M"UL/W10 \'!Wi+4`:-~S2Jmp R. ec|VH;˲XDž'T]\oߍ%H5{G@)q qBT2E4= {cDK]UCQ;Dc#,ax)L\ZYF͚(gƎu9-%REH$N'kFVYb$rmhO`l}r5ge #bK+0zaƏdgCA~QW0ŕ%`ش-򠜣J_ؒyسRIK% purY&BRa --P^Ad(-11U-ʨM gV:*·ȟhZ#P0NҊX F;F+`Rbg9^[}䍃 sVr> DcX0 x &SvǦ0um)peWkЉG V PB!7Xnj>ΎF朝BMf%rգpDgϰ8< !sl3f֌LUu $vV"VT͂\2_@gdUZKiE>]F4_ bI61Vb; ۩a7%w1l&痲(rOJݧb! BUpLBۇpўSlBgƽZ+1&oO-X/`mER[)I fJ/(twz#nvsKV~یꧢcfs`(ylpFgE?9b2?B)e Rd9Ev7 6TD1'$}켒.9ӆot(65> TG!*VDw>G~/V;фTB I5_:wfTɽ>ƴFbz&Њ'u =vt ܙɫ/ԩ\Fyz+ .pR\el $ yBF (SQm-!]+ *+͐b&T0VRoO;|HM#ڕLa2QPhE);nawjn͟6Q_b-W guAY-B*ƅv1hBgAn1ZBź~5Z04(%Kdb9/3a7lZ0y>֍1`Hkf|M9{T&BWOU0M9Tq)PsiKx9.& jI#ljuFӥ%Jc!:̙ kWX,qU)}Z޵iL'Qy-`ܖƭ=Xhu:å>.^wQV4;<2[CRC;5`t "[ &%$2-6>oT&1K2K$z mgY85-0ތ"E;@(Ͽ).%4AByŴZrP"O?.v8NR\͍Ǖ*9wcBxq~cojw_ ޭbŒ!B5QI'rb ?Gpi"؈R%? eZ*Mۣ5&aw.!qIFE:Ekb(AbNy9  ptkt Rc/a3:d\ A8B[W88.RA2l.qL{wz{ ]gJ9vI}N8& 93Jηj|djW˒nA }ݕQz\91"xPɃ+6U34j/xaC G.o;Z\0wQqvNϊF4(_UzLB+n>E3|ƀQ\$=EJHpKiVJ}G4w;Ԛ:'.qHy|A>M3l3`eXD)\_ov;C/) ͸2M~L2]`׻/Պ+Jw6PLPk\0Ir;-6h;ݓ._SW%ԑСU.Mauv|feJװ5QW!+/̬$Fݴ ΖSH`4'9$b/+ t&/iY-qWaha7f!xR}SbL~B~m < d&h?#TWs¡FG] (bpx*ċf(L>D1+97D7m ivt8<"˛g^>Pb7kL,nB D3F EU eY\;."Wp#MZ[w02i՜Iy!3swb7FJ˄{RЧ d'!xQOso;ԥ >LԐ+ ʴZY8ۺZz?M1—c&;Nee,@2O._/\qZA#3Fq#`EiTtmX 6q = 9OWn|k\Q~o2nvM~'t8 ƴF#n8gPk%ԁ`OIOoޑU"la ;k}Gs" .L54E6nqΎdN.UaQGx/#(}ȇ禧:i2qk'#+V{c/ ҳd1d84QA @DE&8'Pcf!6TA b`ג8@̝Yw0k<像n۠ui>+qd4u8M$x h*&K#Efxw?$ HJinXH<lδDpA}j;~9XFfr/%#>o iaYhhyARĉO~Kfy#2sG\Q*'{*u5 sjY)*'Ew|h;HE?oɀԿsSѫ`&[`<Q$ҋeĭ(?bF[rlv.`)R󹑆7νLuAhٶ(+޶rmq6JhHHD1waaY4w!}iͳq@׌]sX% qRR]mTNaDs& /<7$;b=)@l;}m ⳐpA)D+c'nlw*{.V<ǩGo`(\/D!Iɷ<]E>:U 2SAr_}wPg9'>Lt{oDAsERJ;C1_i H0L @ Gz?oE¯.ԋϘjRyce THީL|Gfj5"ck-Kv|KsK]NYI @ն2-2џD&v5,z!kҳ3}&~IX:zr#H&_Khګ*&qWPy .L榩%V.EY6y"(Pa(1mzfRi[U5DPHu5Q}C3 n7W313% %u Z:)(Ӄ B fV$( Xmh_V`zisݳ]o( [2kt J_ׇC]k~wI5c;:fXGǬ\u3xPqڦ{>]9wQ΋rvcWZ*]䜿& ,ʠBgSY)bSI_i{:@:x `͊x_kGT4tdO4Hu;{0'(̰!x, NG1]v;op Ĩ|1˽8qRmYޱXD=:Pe\,5i{9Ϛr#1f3rt\Ⳃ֚)A&0ퟝ$+ұAυWKpN cH_(\73ob a?X6<+Bt sEIH#VŖ's9lxM׵W̕q?~H]jXЄa%wn'{"6lхUj/{BFb:td޴1TT6vKۤ|kU|Q6ק\TYŠ>̖8`t`Y&SW)~5R98dZQpduS3N̥HBAtxuo""Scm͉yMmr|=R5A0nF:6? .rՌNJ Jg2EC0"*?r:fE4Ëq@Ͽ_THK|;sRW-Z{wp tZa)گ P<@S@SX"6U7udY/HPsO~=?&ihA;56p|c -[6' 7 T&ĖYV1Dc(ig#|zc!KK9YV' '9[1&e!I\mvS.ua/f2ÃQk~v[0R WJxkdWK4um)@{@H!99i`$ ?`bmǑ!7XO-5]J+SɒW JCV*&-5 m tmkߩά;kѭ(5ߞO\'O'rha-T~&(9cmv%xv}e* {f};Xr\ҩ)5}ӧЖ HO.zyiY{?-İN,69UGb: _V0oˋa9= [ZӤK&0)Rl+@x s]4*i)dJLKLSkbvR<Ӝ/ʾ4s"]d/'˙%cUF9Fy]Ơa g=; , Cygq{AUINa%LM8%X/ܾA{/'sJA tWVE)V-n"2aդ&7 \]MiޱQG IiS=v:&uOvY8wFQ P:Yr!@y&^3iװcYsN~w$& /.iYA||j%g/mlRЃzxV8%mfG^1Ny޷0ibƝߵ.oQH@K$9'v:}ͫˆ}M̱=TZ=#+)#JƘ&mLdK9ҎO4}u!$&ig"?/ph_&U0+=J}*8Rj C}j'Q0mNTQA[(4$Juսw!=#|:$Ba!Y$|(d l0_ue5S GV퇻% bIm .#Wt[⫭>b<SSHa9Z1 یJ_gt;&`w])^e{ BkEv?LmS.V/kjHB`;U<~w -b&afo21j L`^#qi?wi;!ĹB-ASXa910&Z*<>O z/rx)돰[bQ|"Tf,2-NuCٱvv;8(*Nb̜EXE3Z@<- ]4Fq-*<)4 m`s+QNgL֔- 6T>au΃F5)#ܙWéEbIB/ ;3vHGayPh 灘ii Q,.I 72*=GPX^QIFe{zu̇\-΅/G]T9m)l 40>4b>TV*?}KI0o 4j(hF3 ljzs!p>ζ z;y|H-Ͳxlϳ^2ބ^ fW.ıbOE^`li' C!9&pe?e/EJק{:v2"Vvno#u(vâLcpE0dLrRspi9]ʄ`Ujg%b)F#G+>U='.f!ǏY%}+gEbe݊a[f?Z$‚Acv .aj>@I񴒋H_Phw-[pcɗ W wTrEŀ #P$gtls cs+B>@2p9NP\Tc]dG3xn3'g6ČHjj{᜕vǹ_fi*F&er8G@.qa]CîhBU3)1L:23u(Ä= ?(@-aQcބ>һ <|%ʡIByO$,``X+ۨV>Fߍ~D{FUw Ž>3"bK~+`|=dfSg[*<ſN{-U)<0Z3 _ϣGHNN@teD1S\%K@cq o1eyڻߺ>9Jx)zRQ[l);r0 Ml*y, 9Y3T**K$s55d{>_Ej<#.Y \K%خsݔڃ[|!?fIkY3?albި./raDOc|;\"Gf6_{Ϩs&´HîQ3Pfg]< yWyRZfL]K(mx$ ~' o~ncqND/!Z<.I*&srƾ+1N=+LC΍5}At$v / @ :а8i;:+/I'U }C‰R[˲W[S&3_>Ľ`4hKDB:K̴Aϡpi$am}IjX,Aac1ȴYLN$V2POPD3GIzL\h^ zTW,{S)WLGHz#:]eD@4} YAMA6T@!:@55Yj0! 8FQ8ٓ׋1o<:7Tď UnP\F<&VQt4g'@|qFdU8N H82woD.^KFCN\86vmI[7ּc, q闌"mtMV 9c6cM9+~ m3貨QKM?g$,OE ]ޖ:w=p B~PӥMT-B=礼9\8þ -pPHuvC8N cT*6v=HD\k'?:_RA5㢚xª({ ;,Jwƫd`+ͩ_LOU1/nEf5O~+>jYлuti{nFpNM3 ֆI]" d$H!D<7*=%ΦGݪD[nAb.ħ C겣uhawnǏp}1y~Nu@oX(+KSF 9u=Vt_MȷwIdb4;{+"b#KYiVZNʳoQB^Ymqbs,9wM¬Lpz(=u~TSp| j6pfF@C$>{OO2_WqLeJv];ZEnR;T`a*NDR[g@;HEL+Vzoקr F]*;U N$M&z[_nEc5_璵vp@YcO[-))(X&fBqI~MNnhRo̔,fooo5=Q$uG(W 2E Oy:z0 4xzƈ*|k+6+}#Tk fS*20`yUOg|H9:7rHԖ׻蚋F4=հ} S-2{B@([$HŴ\( .”Η+NEzG~31 H]ۙ9 ȣ]ƳFC6FiwBǽ+v.ٽTQJ*(xp>schya)I,IqF_9r\ilu/y[}>i*N1Wfpb. I7ۙʁofٹJtz%h<0a9麩Z+ҨSs9RiIqP0r7~c.1KJ^l.GuB(3q|:5!JJa 3.fR8vj2@鞩uꅬ&&nmE;Cd{ 8UG,L|n8SU W.EsѲNHV¹OQ jMÕL;E-JlLVR Cm.뮤Ou٣LZ-ү0pqпOHfǪ%C̨9c{, _/ i6m$LڇUP91.[[1W}<m+Zu\]>2`;*W0Z Tᚮ;UyO/,_uo#eb{O> `{,'Egqj(lWKH&-jWIUCtx? >v.߇64T;@jy7N xt/ВdA-32م\jx/h[kqIQƔǓERmB4Ê_FS#Ͷl΅u<|絼},,̵^GT6mɝE+#ҝjaiXhWp4vw/@〡VSlWЫT]d2һښpL/ 'D2 ?5gH'MLL)v1ݸЋ<]x#ՊoKF`X_YrYϑX[+#J tm[Sm\_Ԡ$=:\(hl} t_pleqDvFÍ\UĠ2"hHi7E:n/&ta8(ah#gB[ {dS0,N[i^chęmDIObR1,>/ U\'ZA,˯k dA#`UXjn{# \-@͘B2/#3q@ZF9g(n,Mjo (Zi^TC e>8*!3k'i71Oi#>mPP9 p\XGе^2۹IY-Xm-{kRrYg٥pbR 8ynj'$,P y Ou3B|'~?Z A?\m̚W)N6;1٬^5|wDiłȿgOT/Xd) vlNJT4'Pgi^%rv> X,XQ!)Q؛%R}6U"0g Ol|ent=hfT\.kz6d0S*)H \&!-0}40shiΊ/to0Q%oV<vҞ>Xh@{(薪aJ@\0Gufo!ec\.(p9ޙe[swZFj&+a4?rEa+!APXk|-Q>ާ.V:M$lM8 =yc->g8vD.u޴ ;w;]tXbY$rȀ_׽!7 }쌊o ʇZkN\gtW~1ܴ:1Q4j|n67(:GE3pa %o l4*! 4UtQe,ˣ*$7ၒ̒3d_\ ?RCe 2 8 tP]~7|e{?'w \ B F܀(>PeNF(f۩cŖZV|%fC`~uJR&/A΄lpr0,KCL}mx즂 CZ̳:ƚU:WK/8/ԧPpl “ItXaӂPu)K}Y>D"P0<٠ !K@@}%+FPh3\R{Lf?}P^Y])>۔:(K8y*D(.޵9V%Mwc'Uڇt޻.Moϫ.S{XvU=Hn2bac3u2jOQ+\Z?!6a & 6#{6{n.)mlt idgmónUJ`R7\K볢SyT ^UCDޚPmL}#zi1!fżYeȷs᧌ h9bMxهps _i{;FMxKS_ŦsYs:薶L_$ZRDЀD$zzb0ZPCn xLq~FYyV&K0arsRfmD́ɵ n*|l&)59N˴Z'G,ðEF@j҄A"C}1 7;fKfflky<lMniSpj$E Z9"jqބEQIe,l%aLhz3-\ESibf lu8y]&MhN#]R!~N^GMD|-K'D4#ՐonX]Vn=U.> [>S:cMM[^p{{N4qUb=ur7UM_uSG,3*S bdTP& Nld ֹ@1| FA Ԯ3 ܽMpʮ.A)}xp^;j;6{6_ ͎X#qsU->WK4=R }k(P$}iOxvY;R[>I:7ZTeW.1ql"4XzI:bs.Ec*Jl=]м=\?&5xH-𑵱rܽzzMȊx67p=C0~'\ kiiRVUαK{+DL(ȕ.p*~7~i9!q%8UQmkj56 #UVE7A#H:o>a: D Z^,ܿ=R/|c߸ac8'UkG W!!f/&t?v:|a"7zk2faRO2O~E*B'.&6A01r2󋗲 '? OBO2orPZ^pHG.=5zf ĭ xeΓ~)Hm,/uqgk[O,qc'c7h*O`\*^SA3BhDj;R,HV-GւމSM},rՃ vl) AŹ Q6d EV@LB[:ΌZkpC Mo4rЮ A6 v6^;BؾuUu߼nH s_ŭ,m9Ů,]B,hrYAM"M̓|!>㺿Ѝ_= RZ6CD| ,F+{Zz\'z]xv-F ܑOk{>Q|mM)WK}kk}`yNP?$lَ c]0,(9j~qQl-Q M]Z8k1ahW47uEkTq}{Nkg~gLb vk{KrjFM5qFKQ0dpA?E^!N}*B@#`g(5}2 B&?p6;8;kꡮ1zوK0א@ŞRGٍ9P^QLqfa ai5*[_sxa ]Ylu"\N)n>j. @%$P.d& M}vq3$nTD0fT9Gf^>`{Б ^צFk\Wv^(H(qK8^iCdI 0!z OC 464%ZkZβ"=MC+&T| R udwhFB%yTUÖҡ~.I7I6U!XUG)vkXy v1q_j Ll9INJCXO-;4*(H]9dvgOe;EJ x5#4)c @A3\\ѥ#zt96'DM3 <r+a' Չ!%DoSKms:sy$ 力 !$XWD0K{|/E%Dn9WLwP=4!X2K}NyM>KR XxG7ĕ}{&[gY?xlu't"_XNub@!yz7.G4",%ظDsUIK4VmmS(a;' %Z6TQEubgmGB ;ߺP]Ni~ ݻpȚV ǜri*QbG 9XU%qBil $FD>=ݪяazZOnŔCR9EL V&ҏB3LH{Vb0@  v!с<\1jٴp8ž*f(je 0׭єæ,di  8q\ZP%gV誮lT)>g Fkse;VoU%?yjFfOd/{ܕCwbȥmۈ $ST n0r9F %R*6Mu:x) ޠ`1@ Xv(_bo:qAd> ]2bl|65l :וkܤh(hysaJ-׫ P?. 7ܻ[|15ǶWT:),+B瑟'ɝ#qͯl>᥷6laGY\=֚"\}2y*hE+eIp!P>cgAg,PVxg@F$B{#+Q;4{|(n{dR n^0wjc %r8)Aau r MG (Etk`2eUrJ]z -W"2~.f>ּE;w|NǷQ\g3L/XCK3V3B!Ctm1(_KIU{^4YG農Wr~K XtHh[CzKifp¯הDݰi0(AHNy^S]8oeSZ!kq& ц, |8J밿Z5h.4$H;U}F{ ǠaZ /K@JJߡ!WK?4*#G%96UWdTETy o=*He܄ڏ|?|f6}LqFhM 1X G`jes|9RP # w#!b56w7Z VaNwZw<*#]n URxf ("-[;@uNݫ.T29(niFAhő2ڿ|}צ.=z'Jˑ&k¬ MD|s!4X@\n@D+:ۈ v+#xfkp0\8AÊD~79},j(律FH aZ7Ϥ !pt#-d>I`Y]d oqoeNRAL+$2n^(&MO*ҭ f~iT׆Rne)c3>"W-q%xd-yY n~n% U/ ~jpNG6hYCf#T8SvJ5G-]XgŨY*>I炍0v8;#R!)»FiU28ڗr+ ɝl4L~3|& |ZQָ_A|) s~$$w`/+rjDm5:V}# ehYTHkGHT P6%7 }:,#a_|h1ckV-b. y"h'ƈM=CEX`NVH_\TYMQ53ù}!mBBiˬ| 8eUbQe" Ks?Z*}žY6%y j",xJLTJ~q(Dih&Qq>6Nj64/4--0Ֆ{lٓi2pg㴖 9ٸS=10zep AhRpzO;q!sEޑ$8ҟ!-V~VHlҨ/믽AF@SXJ.o(F] ˭Rېm |!1#.kj[6(yǿ#zz@5SN!!&ђH5pՠrk@Sm\|i4$?&] 0(TZmb %&xJkC_U+g$K UβPaۈ&1+nQ?`%o2#]>+px^S/3 H ~墙}|(1~vc]]z|-@cw/62WnHc~`@=͌!4r'vs\.#.ek 7 %q9WqT:ޛ5\)Vi-{W~Nf+|L{aDϬBcgI> on^D:27pRD^̚9CJ+<עEț!ɢPdDsl2CJU]m=ymߜL1Ԯi}b̕kE+iY>cEy j1Cw3bAjs: R y&_pH.8*=F W`(o%w.0w<d) 9ch*oK}&7=RZ:W] wzRI$8v*n$R55zmٚtlVQ7hҿE1 u?!EVZeE3ܻjBHMx,2Sw2LKRMQ*Yvsv5T'CQ!Rg4={bTk%PEv1v 씶tf1/rK~cDZHm`+acº2JQAWbИ{U.Ҧr; }[MS3ڕVJ5S8\mxyzHuUHM A)݅QAbQJ|.ۊ[l^ M8Z0%Jѥзq9Ӫ$毆Bglodp07|~;ݭ[<>@( սO$3RYD+fAw+ ĮDE`) 8X#pf< (ȭrP@K&gl[_!8/=\:HF)NAm l8_[X@&R؛XgXn8B5 ;`^!eT7IGCݢ> t1Q#UJ*L\/dYQ FLFH+1qȖ?l\e6k}yWe`*XsJ,`H!,Oa%xSP}$ Lڔuȍ'[a[+8.&5iavȞ+]HnD#ZXy,w[$'J, }mF 9Z '0kx=6DŽaWL/ޒ̠m%}zBXx/vv>.S x먶egqdx wUj2wj/ڌo.5|{mXv YkJC\xtI%"s'>_ ҳaFfUyTjA}*csadrfeqߎLGZ385zK|7LUU5 Dc_;(MoMI${) 0SQW d\YD;3RFثfB`LySP,QC9~Z͆? D-E\A"6-NDhZ)(')~EB.#ۏTVrbn:]Lj!a`K@ޔڛ%D\0f R095L%^1/%Mtsj{",}ƬLep$0> E*aC苸B5Pgܫb~gX~ cr3atiq4}md+]FE59(PM9i@_Y+买s,Yp&inFC!q(Bԇf8%-w,^NzR=Lz9Wz`ɛ)H %p|=7<環(vfbȽ{{ _:ċ,#,c]K5cATo1oQl$`0'JsrxGOIdvt%ty~=CB' Rd(^H5ÀgN@OلGyv1ǟ,# z p>&NIKvA=,oí2MwSWR ?KVֹZH&QU H{1:ʑq /EL\ϱוT<`=? NsSĿ+!n4VgZ5{}_QjE@Sb0ׯt; U;鍔cU$W*IRzyzmK!xGl`vq- G0_y6E _ #{9 o_ĊCD Σ%`iZd2k;?ʌplׯv3K}^1AC, _9o)qwI؀o_Zg~klD!>d_T^D~\&tl82?)3!sCf7!1Ŝ&ew#S8>~BeE|Ie PrhO  JdvZZKBÞ'ӓn/Yǒ}MP+њv9j882{yސ= .i)mqҎVCm Js$ 5O7<էھ]5ӐAdY8݉oHbSKVSTsA|VH:`AAi3Ha ')9(kwX&[\qjA1;lB!2aW҇ %&fZWFsrrDTݼ p \ %"ܗozmPn✬cO-Ӏ@F5^x]'ϫ4Sv`hWR .PI3h S2kDOMsd\V9Dq6)ª&p,`;6EEr8FRk}͛!sڍ'q%7iD@ҧ%rP9rāL : *6_#T6/1gy@!T ?d7Is.C)ƪwBR/WjovͲ5JWݎC\ rR r .BpP "S&qE#&'hjzV`iAQve`}bwW%4m%B4V8@ƏUr7|1HZd_P.]t鳵S wg7^iyП $C6T$lm:v<d etao>qQ=9 }(P]Ys}]Vڐ~t&f?kTm=8sZ9.RǶϠU{^̗tiX(毠R0zLeЇ;,B#1N 8"f*[N40Dw3)2eafXީe)7])&68IBc@ %Snso{=?h Z%Z }§-Vj (h䏧ե`G((׍Dݪ5qySw+㞒<P{<eW1v4x}4et?ҡv*ۣ] %JDy*6ĶE3LS|$&KvL+)`UclX;?anD0d=E~yxۡPueyaK%4o?PBb4⏷1alAg␢e>s81EãfS} k f`8y׀ [xQӺ4C^#Ͱbɝ"|lDUřZQݰC4W*Ƅ%Rt0͗+(XaWdIQ//Vnʚ?wD*#ޔT --vQ5**:?3~2r}" UtH]natm+eā:')0w[T7ڊt~Qi.(f@qtͣ=^Sx[|kt4+<Zhxk ʇ܅wӄ6TňI> oR4ubGy}o/?҉1@+:H-b/l,FA)O~! xCR̛Ɉ[AKjEk2xrIJ5| 1GX-9g܉塮~Ի+!!$`1m9 =E1ɿ֓ae%glj3/KCp%Jf:8m}թ^\p5b3gطP^\I18M2߂N$9flHD%(GLcKRN_X)Uk["EqKf1B<:~@+gWmڎh&] צ8\y0J dL |pCT ܅aJBL#E;µh#%V>{ CɣزAO tj?wLuQ}IӤ R}~}j"tiݥ~'܎, 3u;#5[הqDwn8]ƈ21̛ٔw^mE`ŇҐd+jR 2p~Vaݑ8hBq|w,Nvs{]ϑrmt]8sW/#+U1h=3}o %ߦЮI#=u衼׻|U$:1Ԝ3:DC x)Sq4+lb1e![=W\=@Pe/e+b uKX߶Z4~}(mF4, 7zBQ uAb3`zi)2GnW x&#$3D l_XmB,nXB;WI{RFpPtuE}QVPz77˗%joV) Kl#K.@BK-ɔFtq;0$7>5qc8R+yʮʑu[BYȬk"`Iķ!%+X/]xUٳP{GQĶ{!5L?9mLX]`x"Lx|>r-a잼[_/j)2=9] ;o)CO'.]hknX7c`25r1 &y4<V_עZRŎd{ZY(ɧ#fV.$<>;&$6WHva?WjI"rK`RXЉ蹹|g[;U *,9.e,dfc Z\v}[ԸByb6I6\X0xdgJ {*Z>E𛃈fwG?#cb.!$eHM2)1Dmt'%-&M=&μb׆oҝx .cXPRJ 5J_َwawF`~jd_tCw=ɏ 삧'nO(W?CDuܹ*2۩ݽN;P|)rY H+i$D!v?ndqex7]-c7d\E`&gb_ j=!?UL DA Q˽s[><\Csj&|1P4yXԴ}#(+9BAQ@p0H]3 26[ĺFcfqEMSJDY<75j 1)Shq${A&)-ATLG#wFPx;@jAܔnKn[Gh~+Mɏ0$]OЉ$ #3ZqwMxF;/Iܘ%q'}_ cjeW}. ЗF{ VMAΓ$BvRn _t\1Ov\$BvD[?cC=BI:C-ȞW^LKĒݲ{MbB@҃Th{ -wZ+34ۨMSF xcLڶ:U.w|f.VA0v ,;W_IHA_i}r(̃I~IS-t]Ϊ<:qIqNl{%$B_kŝiZo2`\ JGu6v`+ϓgvL hܲo iPor,zsF)-IK_DGb57PKnq-nQ=ɗY|߻f JYo0-!A)Kb| w')ᨤd["j<>7.N3zh/4DS6S1̖-TX!=ɍNZgz0II_y)_*q֦].}Y"KN;#JA9LBm+[R)?.Eu,T LS`İ~fGF L9ShOXuu-E$(B$N mXSGny'8faA|3ܺ\0ɬnoٴHoSyS "TAՆ8LvՇLd2x4~ x߇=);⵰-zRՀ`hr=Z4Y)y7bueMCxXsz[ևV5d͵ރ$LW|]% :OuHNN>DC6K[ҹ_'[6E}*<ֹFjwFMu ~QY+6Q3n5):7& HkիAxV Mԑ;6=#""0xJi3/v|$p !Lnj(AHYo3Jc BɂeNs1)A*R9a ""Ӥ<ԠnA;߫T GXߕX z0.+/ gIlB0f'GSEEDQsXQVf1{Ve"E,d{<96>! $4r٭οLeGYގb P/>e#\5 ˭ @L0Jrpd'YMxʶUcˮZC2Vnc9ԢsTSF̾j;7| Yrkׇ p| gO=jԷ*TS%FiZ*Sj0uj8vR. ι3'`AnUGpx~OB#g*_"dʨ>I53AKڎm!ZF]IyhCY/;W|IwPŧvZ2L!1fUzw'X ޓƜ3b3 loh陵֌lG9p{CUǣB<;>+d?˻f_Hcrt{&,n|=2)߯IC]84阮#~a+u a2THŗddܖ^1\\ tm]YSpH¿,ҹnj8]^ yW)d^3"$DN0_!|gwlc/x)a)%&Z&.Y/JXs#^{Y#NON͒ÊɺQŠ?#VMO3*\CWu卮@j5j)Vr^ciµrrʾ%Fi)+nGgы NkVUKq 8R1LUN-!{;W4#3z_O7)C$tK3s޽|&pz]:oD7)07ثe+4&^Ą$)S[}C6Yhm.sŸtXf[r,K*RnJωǧ!I=$ڔ|=)Giӷ >a~a4'B4'1Z)8qr&ApΆ.c86!1g,`9Q+sU\ߥֆ"OiZJ֢gv#JE$`2GOBw("Agig zP2i +D@i,0Yh`vȅRGz =l<&, {ˈi$n΀_7򶱂T4 دZu̠I>D|8|yE"е-H%.b~=L,9-F߇w]7{RT*̿FjU~9e5.i0NKY+Cs.hgteDckm ݨq:{*/BAEeyCшK]ǡ(%#,̷&8Pa 'ұ1Er-d_z$8Rlj'F$aueNaxsj7lRY=^}˗*/WUW=ߚpgGEUE#-5&[bl!ppv/ԩ',O{7VH(L1eSE>0良u)$AXJ1)s. qt\ 1'yD=_o_d|},]mZe8 K4&1.v4EZa:1SjyTmƜ ŷɧfͧXMhkD4x$2$K-ש'@d9N%uSCn}QV,)HEtw; ĥx>^E8SX 0U0BSAa)\ݔ@"̀ǂ&~ JzS=k&L4MknYq8op7ܱ.V!@bڶy_ JHA#<[\x^4*;,heP̨j$ ބ&EcdB\Ŧ; ׉NfhviҤ6h*B]7E) (ĕ⊙!K CfvwQw,߷ C:igҩzPSnȁmulƣ `1۴dEh: xЂR8y/6$Nr8 7blܙ_cxɰ1[(&jiuEHKQ.*j%lgwͣI:%^en{Pbx`Ҧym[gnP pc O#sm*zSTGs!kdLf#lDսcf]$ HgG !n=aJ'Ϣ̦JTzAq9 g& m#c!)ˑ[ IkGL"Ԯ][zg1)Wj#@0es(6u6xIGwMな>"(2On9s,:Qkaw% ̫ț}`m@5Ѳ Aei X X[C^OK%݆#UK'Qd31nZܟ8l<ܪqGR}ЋJ"IUr4yZ /`>R3j' E~{ZJf.wJvd0=]Tbh;@ܚ>ˮOs S6C:lvF_huZk![_ܮQMD2 uR;&ͮw/ )i\,%zWE mVt9m#۬Y!vV|D +5nθ <|t@x D>L(QO4a,[`b ;HȈ* FHO>J^J |=nW*=D='BZ>͑yj.뮡iMGxVNƍ.NװcaU*޻s=QFN71򌨤U1*!ڱ0Q@? p?Dznm]iN D ^>>zHib'$%'p>Տ :8Xle#x}VAK#e6$ـN\94>|)ƦdͺvuZ˞L[ *:E>̈ %)`@[2]W"ɵ.?=k2EY#OmZ$*øԽA~+mU ђZX;͉oÿY+^[zbr'$\^7v3Ƅ}PӱYzp>3B[Ϥ]E7e7l!`ەWӂ U ǯSwO8T*?|3U=0|CkNǣUPY\bC1-%E'r0}ȏLWyu"R 2Y^ˉ¥dذW@^͹+4[m7eSKR$s}]y-Pu;p~2U0\ۍ Kh].w 0x~dV'Y=SHcU]?u֮$EhXk0t|,(8NvEPe-שDܒp7,.P-R:Fӟ Q>7 pm}4Q-0TԢT~&ls? 9#@#34#U+gqq0-Εc7)\ؼqg Nu%7Q? U2(ggq# lCC=PΩ@J=u5~rT.U6dA=$ҩaP7Py/-|4P#INb;MUHnZm3!^0 NQ͘d-͗=$r F}ς+X[SNt/\do^4ܹA NGگ-YCNr$D%<iLIY-^o:D`YW2LR Sv-zѱ^vzjOqak4jCq G4r8GSfL8ގF~.[UDQ|ҡħp&B)4"m`%NE^TzӪ"qƱ+\Z>'Xd YJ)RKM+?6nB)/*#-0p)pP_nW<~k/W)`EGdͳ'kwl|(6d/?6kzN+uS? ;B6:27__\n@~Aۃ3v̘Yӝ\80%yyFc63l%}:ԝ?LbGo[̙X SZi%W?&fLK<\JO a#S!B=-0g}S,*Hr>wRƒ$ys,&(}kaUXm.߿ t2N"I }b?~{)l+' 1oxyM|j](Y,)1+Nl=A8ͅI6^kR(lݹF01P쾥llf? <8LM> yi%Omd%15NMb$ yJ_18=)"͝ic[F*m3$ d=t{f)-5RʓAl5XgzK'e ,T0xpՆDKv9{= F!I x3!|c/ }x[S/>)GP=^&GwXY˹6" ONGo$;݅F?{% \Pvo?>@l"YG?i =X^}8'?}hrչ+0$]NT*3dC/eb]ĩSeSa[4⹻~ Qq.\SvNel#0E C>H/!ٸ z61)/ [ Ӣ JoMh.&,ob }d b8l)kVvďvv:bT]w+)M;`d:r)) F7`1*71\R]u>ȱ~OL1N%[#k°ev9 ?Q}չ~*!8LImzEP5wןl`nk}Ž"=opg77ѪdG>AR"kZO;r1JD4ʋ?n}I:坝y {2Uop5gOs&۔hzI(@CyZ*daa5i(ٖnhM^Kݐ {J*箂{d(Bm9UWa,%)_I ~RB"g.J'o$>j, Ie۔l'Pw\z1`W/w=Jɍ1^k*| iZ\$$r8fXGi?P <~t3-G5c 1T,M&N W-)CfBGJ( ̥7x0r{\~ؿBM0Fپ %#y{ ƞA[LwZ&-i,4Lwnw G6*Y:  Ҧd69t NZl 7I&r|&a#Т]u!Gnԋs f.yfr Us%@C.Yj]FW89K"lQ#}<as⎹ϧH*L~ˉX[zXZb;I%pX'eh# ͙z5^X 1.KkКG=8)<)vFu6ܤ ,c?c5'b(.er’811N*U4@<I@z`nʹ>π" T9*ƙt<Q^9Hw9,:1d 1>>ԗxp[b &㈕a"~Qǯ Za9kVa9aTݥXAؽ&~GY "O52iBJ 8EF vH^ߔ"9߄p :y ) !E}} W 'xlBƸᢻT8O%η'?s`vp'ّ3W RQ.Qb*)Xfd;u;;[m~RyAlr||u4^iiC̯S]V%ӥgr` @r0>$18T'}ZkQP]pCSqF"(qsD`1S/{>Ê-a1SPÎnԯ G&S8xET +34 s,N|IgIȨ*KCmۻREzGIg,}Hzi)^ 2%h0'~ -RyVӲ:i`U}}ר,g<؛OIAN'H,/?jYra5WAD{* O\&NxU0\4C%P)Pvl~$ƮhОH1b3=wyǺE\UisV8/D6E+&*2+f$hb#f$hb"eN-B>PokqD/Kӹ ])s0RЉYhfշDm / |4]:ֶԖⵍܣ IRʩYns`s843Pko82e * VsM-9QvW-%'9PW&k+mnSQOf^uc{p!rRWroIo Wײ N/3UWy<#[.=9o$*T$>5nυ<,IW/}Rl'YSΆXV;IZTM4JZ$|!q(X>oU; h;ZWS9_2T2'[s֠ҹ\&?,3+eՊ^zK'')c2{z9q$8q$9ǯRŁHѣwX}}H轺XnkO,.P&Yx?Q&׈Ng df]9D e75 @_f !`12܂`:,Ma7otx#L&WC*'n5@2S,'XThsZj/LܡӕkflpD5!W}!jn=Ҋ̜&"3w CbN?B,W󂂢%|nZJ͎lx~yA\Ev)H)/Qےk{@&ϲ\fiˤUQ/J~lOͻE3T+idצ0s|{ `$|x.,RFk4r8[?-* I tQZ cNlxghPoUc|AO;ލ .ӂ+.&8+:.K?U}gt}CXO'/00oCOhm&Dl^7urS@@O fU"\XiI#M0AK|IuI{<cPZWǷ5uMԟE8J^hOjA3NafJ+HOHF&4RDDd5cz=Fh R̬X~D8}cL!m}d÷inRe:d24?X(HOF)X2&uCs('H6/\ÞZLIڣ]$;γjpQwToiLj&/Xs#$y7%9t풂o sphוRak=cTH+%Տ-Z].$M6IR^mJEj+%, B_풓<'$F]zqo2&xLo\ $z[_~`hk H+zOPCIH{G;[]r$N0dԑ@_ʼCIa8$62QU[!'J3'BAS|6y(ighd?pk?>?˯A,5r#Gj%",)JpG\ζѓ \jig\=DlrWdq37T y8$5,̑K ҪZ8a:C\ P8; unZPhrJYzQ1޼+jy:B8UA L5).C__d> %  )y˲|W.h iOMD /I$c[ a>:Oe=HT%N& ; ]<3(Ӂc7ƛ JϪ@KTm0 cGw`/ؾ&Gi =B B0ױkaX*˟ 0ëKJc'XGEpT3|3(UJ|:\ĄkhH(~,Ɍ|#$Ֆ_~fOG-e*zWA@^%*FwLt3 @޶TZW%>wM}Ļo\N#L#2/NV%Wxl5)nI2ρUkYCV#E*%@꛰Ge' +;!߱ߡxV_M -o;ƏOahtsʪ4G)k[s2*!_<"JiScljwYnk*pnOpLXLFPx)|/꧷#ݾmg7EeIZ>" W-$tf .Ш"!NW\e{&a;$E qsxknu[BH}kB kmkD]%G?A=yKXdO|pR,Սk / tuI ~ CPA(svVK>msϰyl.={tXFljȷ/ǔ46/DPsv^;B>%86*fjz-tc|BZlaxdWHDnkz !\:堷x.czWQ/>J(4=;A_,񅆄tRg z3B^D ss;nE":jbWFZw^׬_^% w≕ \M{æ Mn\uf?.>4;()S7J0ׯՄ)/d=4Odt4dg& %) 98DxTj "j\YG"aMÁoZ.T*#,RH Z+^%?c'RN: M(94v/sdG)bNκ %N4kj)C>1P{tZi>f&/dJ6Fp;DҔ׵#xtսn(@>MOҳrx7ӯ+"4"M @;O@[S? ̀~3=yAAЃ IErNOƐ48o!`d+ @@2o >O{Di,_hQ@.&~ $ď xK{Y! 袭7ʹh[Waa?>I w uRfR3? G;@}mi-"`B9w1t 'm Fϵ:BZü@\9:3.ƑxRh;q⊒L2r!-sLB?/:|6ĂPMH '?ǿ~|+ PW0T KjVsMO*"_Mސ2Z/+'cf"\i1z-Ώ]-TtdPA2Hl Uo {gys; êG(gE{2y$̜F̾a\py-:R/y1{"Owh~ W8Al -UZDWRm=2Q 69kd썉'ePNkO2(ЧWj/ɲfspQ>/S $wrSZ˱ئQB(6ڢP tT78mk?KwNd3 uiE=ocN^I]{`X*;w?{Ե =bh V <@jkzxgxTO̞zvЃNWEO0+ ꚣN>tz?Ń_I_' )f~2=fnUu++q t',_z7E4"#?P13r?}C`=yQy!ЗA}M-^bN~ L{\iSlp'׳)U^l9OM" Ћ"zd E-W ~i|Ƽprl[ Zށ3ULخӝޣV:Jb )"P.8;7չHw#]ZȊB %,Rd`w'h݊ [z _0v5!4tiOEp":.+ X4/!27 :u7P/wEH@׳tRH+⽀?)kӇ<fϺ U\yZWt7RfkruDFfgˉb4q!?vr4ȫ n&'H4p"6 G{ |Լ / BkDDw#ςj/ BrͦOb{KMr` N8=g;hɰa$cԺKrH$.(okgI Ցt $|"`˄'`XwUJFA4/LԗeɮvX[RBheNv|RȊ㼈moC^"$x0W}G e}s% Edҝ'#%4Emq^9H*>\D^n%'7xng f1{3DiMks2^wTǺtkB}pM1.KN4cN襮0oʠu4?v3(uɣU$tK)~A0ྱׇ*eY-iwְL`PGtCYղP#h/JxMԧ1{2~Z5Gw ] acr2łr?|{!!e1ガq2Y*n Uo!7)1qWw)#/,t\L)lu9sq@]7f d,X猨Xfw-&l/h '#N? mRh |Ns0 D'oD;y{/VG,XڎSp{?B]LL'^ qli5nta"#i+'& v0w;'A}ߢ=u4ݫ3/BJ,7'd1|D~1SqAɫv K<{]n&k{w&ȸ!^˅6-rmo[ ߙ}k>$Y6&F#,![)nr@r|:CWUt䈡dNov  t=.}-vWPjme'Y8?FWկG4&0)jؿ O1,Yd[|]LZ8X΃ޝz-Wò ɤjjk3 vu(Yi7X'8 a{Yn{d}#a>63 ** մ@1{\l q l2rs+I&_Nj(/a.^_cɀ٭Gk]f%}PEKzH6_NS; {qpЧ rh;W;1xUc8h{8퐫!ZKa7?۬ 5:Ί*KTp--s~h<:fQ *N&F;2h;]@F\Nxʒ]eX[Gw 6Rk-6 1TFio۠pu;%Bƛab l:4pǿEe4b  #HLoZ7'k3_,J8 w@DWm\&yӺ`N^ ZׅwNWr!N}K^D(]lQgY 98Ԧ4Դ (eC)):lOuJ'1h w!ө!QԢBN)*Db%Q%dlxi$-f5xԅl^E;b}LUhz˷q̯8u8?-עuJdݵlڦĆh䂂Uuin@J6O;2O{BjlOW79#:'x- >=~1 ]O;OYa`c{XMGS# ќ݌?.pv2Nm뺒,<$ S8U d?(!󻹛i;͵tt3 8q.sDoJ魛R_t 1^T'N,wңfkB1 4L17;qbNƛXkğet<.˸hKhbI+#:RcO>1,mԗqy; \7q&wH:Oq\3^ jJ'dy>EFd;T-DsP0.ӗ,3ٞ>Iqj{ \<,mɚ371'Sb)F:q刦>0N2v-TSg+ϾqOt\*޿W=jYx5/. \{s'C>"%zll)MX!  ]l%>@@ZL@8 㹲m}mdh{7-Y?邐 e>^voڼӝJ`[ATP_A#J4i5 X)e>/&cO;% gzS6ݎbӆ# 7ݜB6k;H;kkЋhW}} Qj*ܙذ1%6e dn{hSh``Nԑ ֆ ՇoVH}LP"Nt+EĽk7d_3(Ta'?;CH} +}~ J+XϢ Y#*1Ar.gTt>f,N:4R4 Z+ 1huޖ_m ?S$ g$,L.zD nO- |Xp7+`7+Ja~lFul%_"Xpv俭d[N\"xA?r"Ŷ)T!.گx4x0UKd@u,Z#j$SdtV4yrHְ:S+ {?W$#=JQ0=ƿ sW @^Fj|xZDXMxpi 4mB kPR0

g3eDzXnGfDʁ.Jٽ-˝%m ECf\4HuW(\9tA޽ $fa\^G0.&eB /fTz H(?9[Aznw*\%"Qtl Z?R_ͿrjXqa 5r ȵ* )]dQ鑂ghZ$wH[R }u)åGϺ3צ2x kK|!`~b .O8`AL&K8vEsVd\'hi(;F3uukߕ~Ƙ咳1TzȜqw_8:2ɗACĖ#l3h_ԇ[SVʪ  ~A$Tp#@0:hVƫuL 9g3y&Y~ ~FoBK^8'gOкR]`_pK -< 'c1Ix BAxoBr#0^΃:eٰgvb#RdDJRzF"}gY,څc4SW],N4V|h!^]﹔[(,ua=HQ7@vRIFZ&[9=}'L#fUwureiLUT]tiUא`}\uJC пNfx[IXhlSLjC G#@]Z=9Oe! -%Fe>lM]5BTЫ,26*eog],1zȊHuڙz weE snl2ISg-\Zj\Xfżfh3lSu|f^\tOj"~Z\)nvcF7=ಿhlKۦ1_%r(=nOڈvh=Z(RZTUEgyv$yMGG~Bol5F o5aCa{+|1.}ZŴ3@fh²ct؀܂#(TM@@ۮG(۪2&ȱI^i~r!W1Ga-#$nhh{+-v8H&cTKqRO&? +Ci#e1Il_矓`3BaeK,1k-ceÎǷ?]0,YdNS=*1/@WYaeӟ9HuU>1gh^ Ʉ`Y ,-| &ׅl1{@p+j~;FgHf^O=kzdpuly/] :*kOhĝOlŀȾDZ3|T[7Ե3xlJR Q6`ֺ4LWFZМ %oyн<wvB6Y%ZBk G,SCxTQec=Ț;Zۆc1+[iӃQK e|ΊlVrJA֛ _Q0ڄP[L:BQcg<ăʂt >ΉOj '?3MLȮM( `w>rbƙ`º3 BIa%,N˙312smG^&N]0fmR34ڕYlдv鷿$ 4R^&E(6^PiW5_>laJ?JU(r B %R`;kGC;<药6Nm2I'x8DJCSdv'ӹ vVyEe)1ts 7뽙y4Dm4HWJVT`x [O,ZVw{Dg)@->_RTW \6@Q\*:wPɫ.TUJ?lB<%f,%EXcGc]ZθqpRm = pS*EArb̮pDJLz#:f"!ߩu ԁN~)K{D+{řl33{6$HFۏ|| = r?$8*.!~8b1u.Q:NE1MdT6Is&Ef"\i{-A, 8166KcK*l mW6* 5OIED+}$oZBG^ZН>N#l1Wł/U6 &ֻAL7&01ϘmH8R)}n#ɝ.&~gZ,#?lWTws''[̕O0qv9rliH~MÿA17'0/,LV.-|s_E" 2Z8 RFdnC p'KGϴPB?~`4i &aHsu؋U93=⒜L'ϧk'iN)o%ZK#+MHzWDEuYWS7%fcl:sDRn/t W][]~+H&q0Es:vl LL|i e^c{:-k+5B*Icg̝fbKKkt ˸Q Ш.\:F8\"1˪.D=6c6NYu2SS߅$HS6)I!r~Qrh>ZpڏMZRh+{5 ߤ6UjIlx 0m!-Ĥ~hA*QTm FGWN"EMz MR\>KaEV։PJ5kEIݡV4nd <*U9fp38QA?zN*tαwV p9f^36KY)=T)Û> ]um.3;Г[gib 7A)df3~= W-f j,[0W݉NQrH<K&ui@c1Zcfs qat?إ=Q)6U=] e!#>FMeL' ?"P? ׻M~fӚ$tGc(a%&w p9ꎂVyaZz6{RҝDe*&1ش`xf{`w: )8',uL } kK=j'p7G 1p۞spSI7&Κf)KO[п9#Ÿ~LP92u T.m8Q[xNaRigO6zd-,*D/auv#@Lp0UO e=?~|Q7M5KU0|MgͲx U mmTY,iwL/sv)`W 2܏˽Ȉg ˱̓5-Yc*}EkgmfAdt$AJz\O85TMH@Wzq|W`Lv='+s սa9I]CS;L5oV)mp $אH%a/On;ڭ,ϚSzX΀K*GXrR0`wb|yKT+=BN̑ HSQ/a8CPdw~y#ư,g^~3zhQ`,J&^sd&憖w &G>^ }84H@@OKb@Mߵf?u %%w4X&;J373dND t::xȇү\?WCxEFJ*'w03oo2qZᐹZg8p[n8Bx\=7YvB*p[M]h66Z$+!돱1v)WFSg# Juǀ{<#.&g7kz ӇIN,r9HNh`WS.,|libYŒ:"مĆZ/.tw)fZخ BI^0l uXƣ,:Fmݭţ-{ =L?c}p$ YBc)T$Q bƲDxӊQZdBoY&Ё蝝P ۩s^ӄ +(ţ*=ءRs%dȊT/f^$g7> #[1뷦.(g!¥yaV]bˠ0<6Le6|qdg2'Yžof$=)< X0E>mkTH9!xMU (vmrIF6A槝buʦ{sTG-:زݺSzm7Az_RbѴx*ytX8l &F0vVD/Ʈ@|g=ihE0@.Px'Vaj6Cيg0^?+ݻ*RIA-)J~t+>0|Ž䝄, +VPRyNyrWYf[54Ʈ,Fc7 `/s$&׹cPS.(o* {_=u7lgny&s:e/hrH4"=zU')1U^ugzPo'?Ueiݡ]oa%( 5sխ\FЊo٫puSD(Pn֏5mJgQd|HGk 2rUNp e90CW_j.(L۱3W@@dm RS@O 3#͢o6~4tydVTyE^+EyLdl eo!;"f~uSTQe B/Lz?*=ܚ4R:r- Φ rA*]8>nmצޢ`2 ` oIn蹆|Z>{\+AӲ}>3tBwgbbOj$ xö0,jޭTܔt2%@0vk{:m>nPcCh!O !m_)3c d&r#>.o麵Wb{P Kyb/ƍB>r0>0C{+=ӅuDSk+q"xdoN;trSdj!TI&XЋ}'"5cVcM،gm1%A$GB t{[Ut!7lr,|ޯm3f. Vfa7!(ŵ_;,v9`j47;g +)z`+_b dC6gꮁ/;+b?:ykTIYsgEP>]y{ O230g~A?<^%m!vk+Re)4m^]gQ*1h^a#X]~h+Vۙ_y7(^~cUGgU IT9W"t^0LqEڵѻ?MeQ=H7;M:zdϸoB`N\# Y܋a%ˋŅ=,m€]*1f,l'Wtk5mٔX7 <ˀ) >j?WEՊbEmGBz 8W.;Ű.CL\8ރqhGX)r&ޓٴ^8qX,obb$l.)B8X|EHÙ/QAUWn?J%}WdX1ǩ?@⹒8 [F_AilKBo$ l~JGqSXe5%TdfB:7y1i^X|_I! ȿ;1<ЧF8YA${. Z">Ib.#s.,hclbHvɗn*dw"rC/EiWgByMVOwT.K4μ@хiup vP84C-aE2d[Xp^$AsɥPP0RyGmC(jM޿awzTu8My;@H)J՝o2qל,R ^ yΛsd\ֵ4Xpubm(%dy10I9@+-EmՐ6iB07 ӓA2Z<tLXTP׫by _$1ZgMFkFP>fR$b/+ʍG5(Wb2>M̓05"xF<,>b!?~hji^XA()fvߗ>(,C<_oNLa,$XRV5D#Q65s?[WJhZm&+00ۘxVW?@ꦥ)Ed6CS@߳Xy8 ACG@U9'}@(N{(Ɯ/ivߘÚZ;\%MdG<(P2 'n=r=p>G.:4s@#^cG{p=VvXޙGc*y΢_q VZ< RLC#8]N5.ݙhJ):#%}hw4L)(eZ_W]Bܲ  sYWO9Ti3T܍2iy3gr f-Rv=(FO@} Asf-Fz‚.C|3]'xl+iбTd:|RWkѠ,1;7iP |&<$Cw2?'ā5x7]?@SX,:J{1'e+^ey?p860Pv^?N՜6^erPO28cy5ZbQ%Cj7^|4l]"3=]ZTv>e)E\Wj k0Q6@6rL%5l!֎ s=5J8A )T>ޣ;SRsĶZkϝ9v](t VI]X-qZzۺ|?L{mHGTn3=ea6}t#ܥ5FZ'qhv7lUC^<%é0`i}_,g)S%FC U P,uHW$fL紥4GY{k1ʠRwO0QYk 2` ;OJ2l33SP)v %1=meAq4ǖi f=USYˇ <01.0}K!RNh6A,8o[ ĂYn9i\UEcwn$]|񳡐a}% tXgS+@jA<R]5g#>sTS[={hOԊ$6 s|)PB4ʜ>W8WίSxא7c nSűK* >g?BYLfT"9P5EvYQn`l =Au lT#%xÓ+BlW°Xϒ FOJ~BCH) GJT)3} r)clm/3BiZlTp>_g9/:nŢZN2~`N.00dŬ` }BIJgԆ|jU|F'q;-]i\6 ӂNYrߌ܃uc(Hk.yvo-0 ;Kja>˕GTٞ@ ĵ u{ G넶*&T{vs89KQ>hWZnaRـ2LR)$IV@B4ub0mԷy<; U2 18T\v9f"kxX!4<OY $/$.(K~Hr(7HF:`kW@1Dq9[f{e&-dHڎ(+뀞\gFOt96ͥV;iY8Y2wxJ~_ ;V)hz˦ A:a)\uEwdG-?1Sdﴣ Ƣ{%&穦pA;6`ٯhAfN pP ퟆMtog-zhԸ+.l:p\7g!!(#}FfnPcnɬm6,VX>#}qTgUV;h S-QʼnHE˺1vm3}$c-*1Bٖ~QY郾G&<"q,Imֽ)`\ Z753P7zEsNv@U ͘Cc+֏^+kw9NXBtpꫭio<X`ToKnv\:}]xowԟT_KlSwGMr/Lϓf0YB|~\~5ozI=o0x%h:ZR:JCUFԣŬC\@GA5ݐ,9b t+:3PG9O\k,nSԓ|agxS,G %y~ʙ"D- 0BWpͿ}sc/Z2jn_r\`Q č|е u$3)1Xr Z.T?(ވp X[ʋ8FiQ4>op*֫eH拻xCQ52vQIT= E#W2KV|t&dP=cT8;;DPkѨT".v1] )2~3ݙ<=@cryA XĈaeidry 5=IxCͽ)-N;127K'V8v;Oe%fj -Q\R-AN{DYnG+_O-ހ%uFB'ƽYȊf48>^rn#,J MSC~T'*UTĶ+٪%c @K{η Wֈ$pHoj)r׽%oA ҃[ Ȣ[8pBf#&Ì(׏֍:kRF_m{W |?#urV3PIUo|0ؓ%w/+ 5nF8l|ɨ$UB jɌ1w$7":uY$ ƼCkĨ‹8 {GQ3\hX(mDŽF]JW~藑DaX=[, 66[5(w̆FNr~ _ZL`ėpmkԂ܎U%&9`"gʤLW2KS@"AX{esT;uY n;0Zc ຳoLFj"'o2K'uȵ@0p:oHlM&#6*޾ҧŚw޽Ԅ⇕5a ^ OH}۝G(S6pl^7S> _m|(w[H_QLRBJ,EQrpi10-ӀJ5@oZ싿oLA%D7e>r} pR(#q~x͟xBNaUF`>C0tՒé#oxQJ,!W 4rrs:gWl|:ģTZr&WRJoH^4ǕDsn[Tx)yH9"'R,Eh%Ӡ;E)싎mί綊 ۃ5aPԆX-pH#2ǖNiEj88+|C+Vwe1GQ8| T2Xk1gW wˆR*ypV-{e51&p@*d ~\xLW/oXA%UX0.oSZNWa좖2KҤ7)ٷ!6&9Er'/N:1u MuUKUU5Lzadۼ}eli I)[>V [+Ifq3G%ǪjIk gDR:~Rm߃w!v5/?{|hx%WDc2Lf+v pٻʁPqzѵi=tYiIۥz[*),+@{,z5rx67Qɘ(lK: hFI':;-oSvR"U>Cov/M#*.E_xyN'^ۧ]>dvXoLe$?l>V)BPܭ-XfS s49.C$:Xa"c;NFܿ((CֽW3Mp%{e,o^ly~yi|`ww3%LtԬY_ə<Ġc PYt24#0$[ߝC _l0/rk@mK[ܚ@>0#Q +MYCd:,Cfq܋dĘP}ہZ'õ)y9J~ˮGU$/z'`ƙ*M&5  r\Y^ឿ3+琝F Mx*ៀѱ,졁9u^ewt`HeZىj}tVkwuajJw+M]<"5aYg=j::<*=Ѿ}ҳ%ϣjXK:3 GFNTN2#3521//!KLF/7x8+?\"ټwkEw#nZQSAwj7=ͷ;#52tHhDaodû kkS0Tl:_)dFJ%8E*X Z?*Z1s Ycfu.+/X@%Fxo$i?R o^p0jj[G{=R1@9*Hj tJ=l',-h~=U4 v-)OО_垩BǫXL1FOvG-F +n@;eka4;%rv=rJi/~[ΩAo]_o+ |4X> lkhLM:SN@LxⳖPo+ $v鑤s1-K= ',Dp/Š"mK{ pD0s!{OYrk92-VC`u{8ŏdq|\û\/,fަa'K->}͋mäD; yW{ +: <]0% _ګF{8Zll3"zLf*A;zAGCG;)jer mFFodP'"^C\d5 dhqs*)kmq\6w7I> Jv̴=sj''aKF^8%4HeYD{unt6!t^%n "2T1Зڼ4O(#UDN :_?P$/t|7Zi3&@GmO\8ĕ@ }8@bB|r_aHݷ"G#8&;gȊ<"GnGj0FN4iӂZú3ъDmn[M`ȞvbYIwf 4jηpjd˂ >e3(<@iAi~o7隤$IBWnF;$W_K'|e.{/yv=L,ё|$W*DÓVX}, hH](0Zp ;Ex;6b=/.J[Id:`@=W|&O0l1H\;a59& NfzJM?al_8&˩v#2bᾰ/YfRqzbApeդr_4S7:?XnfY=!@}__(cGX«bݰH=Q2FQ@wׯ >a>.;q@aܟ 8. YZ