sssd-client-debuginfo-2.9.4-5.el8_10.1 > 6 6_5 3!pQp)Tξ7]mtZ`ga ]mtZ`o59@'w{ d R\T7.kyi|)M,﯄L4@0@X;J%*\VRjL%2rfDR1^KҶ bBQNpb }r $sqmKᖣRAזNbv8oxY}e k"4eݓ'o괯j:ǭ'} Y8<~ԉo|Q$Rpїh@$;Moke7Xw3.7˂*GVϦ_ 3|Bf6SROcV`Xt(SV Diz)l [" &&[H8 vUhYLA(znN9h>p>? ' Q8<AGO m+X+ + + + +  + + + V t+  (89:jG +H+Id+X Y \$+]+^ob dLeQfTlVtp+u+v w +x+ydsssd-client-debuginfo2.9.45.el8_10.1Debug information for package sssd-clientThis package provides debug information for package sssd-client. Debug information is useful when developing applications that use this package or when debugging this package.gapord1-prod-a64build003.svc.aws.rockylinux.orgKojiRockyLGPLv3+infrastructure@rockylinux.orgDevelopment/Debughttps://github.com/SSSD/sssdlinuxaarch64<U<p<b<U<v<]<Y<ns([HK@10h(AAAAAAAAAAAA큤AAA큤A큤A큤AA큤gafgaigaigaigaigaigaigaigaigaigaigaigaigaigaigaigaigaigaigaigaigaigaigaigaiga1ga2ga2ga2ga0ga0ga2ga2ga2ga2ga2ga2ga2ga2ga2ga2ga2ga2a4d66b043322dd34ba3629b815e53f078402cb799a32329b80487f266bd12f9a1df09137fd17d9ac21781f84126254f85a3880a3bdd51b06ec787138e337d11049329aeed7035eacbe447cc7b7bea3d7119a5285f1bfc57b80ee09f274a926e5f23e8b5723817a101f2512c363f18b9bc3f10385f75c1702901456d4556d10bc176e158305d583aff28ad642a74111e4f2e783f8888493d0566b1e7b449e01ceb9a526f93e8cd095e6bcaaa01533c338f6cc8d7d762303f0bb9a0ef594cd7e7cbdb5bcb06f846be134c9076c77a5e68316336d2efea5472578452704f2e8af7ccdf33c93b2f8d8fc46fa50301285bc2bf974a6670773a46d5327b5da9d45b419../../../.build-id/10/446ed5768f263842abe925f809b17e7edd5e04../../../../../usr/lib/debug/usr/lib64/libnss_sss.so.2-2.9.4-5.el8_10.1.aarch64.debug../../../.build-id/60/ff1c50a7979176fa682cf9b00939b3ab01d435../../../../../usr/lib/debug/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so-2.9.4-5.el8_10.1.aarch64.debug../../../.build-id/9d/2a85bd736487d95a6194083504045790246295../../../../../usr/lib/debug/usr/lib64/cifs-utils/cifs_idmap_sss.so-2.9.4-5.el8_10.1.aarch64.debug../../../.build-id/b3/316a5dec09296d2329b7b28e114e199f6d5527../../../../../usr/lib/debug/usr/lib64/libsubid_sss.so-2.9.4-5.el8_10.1.aarch64.debug../../../.build-id/c1/9db917cd9a670d182641850be41c991c71ae25../../../../../usr/lib/debug/usr/lib64/krb5/plugins/libkrb5/sssd_krb5_locator_plugin.so-2.9.4-5.el8_10.1.aarch64.debug../../../.build-id/d0/f3219e4247a3b317e7d95d27337343b8ec3085../../../../../usr/lib/debug/usr/lib64/security/pam_sss_gss.so-2.9.4-5.el8_10.1.aarch64.debug../../../.build-id/d8/8f9480a646ea95c256b0ab8d351d262d3d6753../../../../../usr/lib/debug/usr/lib64/security/pam_sss.so-2.9.4-5.el8_10.1.aarch64.debug../../../.build-id/ed/2da8b90ca74dfc30af3e2239c3ccea68ca44ef../../../../../usr/lib/debug/usr/lib64/krb5/plugins/authdata/sssd_pac_plugin.so-2.9.4-5.el8_10.1.aarch64.debugrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.4-5.el8_10.1.src.rpmdebuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)sssd-client-debuginfosssd-client-debuginfo(aarch-64)    rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sssd-debuginfo(aarch-64)3.0.4-14.6.0-14.0-15.2-12.9.4-5.el8_10.14.14.3g@r@f@fGFf! @e@e{@eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.4-5.1Anuar Beisembayev - 2.9.4-5Arun Bansal - 2.9.4-4Alexey Tikhonov - 2.9.4-3Alexey Tikhonov - 2.9.4-2Alexey Tikhonov - 2.9.4-1Alexey Tikhonov - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-67671 - Label DP_OPT_DYNDNS_REFRESH_OFFSET has no corresponding option [rhel-8.10.z] - Resolves: RHEL-68507 - sssd backend process segfaults when krb5.conf is invalid [rhel-8.10.z] - Resolves: RHEL-66267 - SSSD needs an option to indicate if the LDAP server can run the exop with an anonymous bind or not [rhel-8.10.z] - Resolves: RHEL-67128 - Excessive "Domain not found' messages logged to sssd_nss & sssd_be in multidomain AD forest [rhel-8.10.z] - Resolves: RHEL-66272 - sssd is skipping GPO evaluation with auto_private_groups [rhel-8.10.z] - Resolves: RHEL-66277 - possible regression of rhbz#2196521 [rhel-8.10.z]- Resolves: RHEL-39085 - [RfE] SSSD Failover Enhancements- Resolves: RHEL-33957 - ad: refresh root domain when read directly- Resolves: RHEL-27205 - Race condition during authorization leads to GPO policies functioning inconsistently- Resolves: RHEL-25064 - AD users are unable to log in due to case sensitivity of user because the domain is found as an alias to the email address. [rhel-8] - Resolves: RHEL-25066 - gdm smartcard login fails with sssd-2.9.3 in case of multiple identities [rhel-8] - Resolves: RHEL-25065 - ssh pubkey stored in ldap/AD no longer works to authenticate via sssd [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-1680 - auto_private_groups does not create cache in IPA server SSSD cache - Resolves: RHEL-10092 - logfile rotation for sssd_kcm not working properly, sssd_kcm never receives a 'kill -HUP' - Resolves: RHEL-17495 - New sssd.conf seems not to be backwards compatible (wrt SmartCard auth of local users using 'files provider') - Resolves: RHEL-18431 - Excessive logging to sssd_nss and sssd_be in multi-domain AD forest - Resolves: RHEL-5033 - Incorrect IdM product name in man sssd.conf - Resolves: RHEL-15368 - SSSD GPO lacks group resolution on hosts [rhel-8] - Resolves: RHEL-10721 - very bad performance when requesting service tickets - Resolves: RHEL-19011 - Invalid handling groups from child domain - Resolves: RHEL-19949 - latest sssd breaks logging in via XDMCP for LDAP/Kerberos users [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+10446ed5768f263842abe925f809b17e7edd5e0460ff1c50a7979176fa682cf9b00939b3ab01d4359d2a85bd736487d95a6194083504045790246295b3316a5dec09296d2329b7b28e114e199f6d5527c19db917cd9a670d182641850be41c991c71ae25d0f3219e4247a3b317e7d95d27337343b8ec3085d88f9480a646ea95c256b0ab8d351d262d3d6753ed2da8b90ca74dfc30af3e2239c3ccea68ca44ef2.9.4-5.el8_10.12.9.4-5.el8_10.1     debug.build-id446ed5768f263842abe925f809b17e7edd5e04446ed5768f263842abe925f809b17e7edd5e04.debug60ff1c50a7979176fa682cf9b00939b3ab01d435ff1c50a7979176fa682cf9b00939b3ab01d435.debug9d2a85bd736487d95a61940835040457902462952a85bd736487d95a6194083504045790246295.debugb3316a5dec09296d2329b7b28e114e199f6d5527316a5dec09296d2329b7b28e114e199f6d5527.debugc19db917cd9a670d182641850be41c991c71ae259db917cd9a670d182641850be41c991c71ae25.debugd0f3219e4247a3b317e7d95d27337343b8ec3085f3219e4247a3b317e7d95d27337343b8ec3085.debugd88f9480a646ea95c256b0ab8d351d262d3d67538f9480a646ea95c256b0ab8d351d262d3d6753.debuged2da8b90ca74dfc30af3e2239c3ccea68ca44ef2da8b90ca74dfc30af3e2239c3ccea68ca44ef.debugusrlib64cifs-utilscifs_idmap_sss.so-2.9.4-5.el8_10.1.aarch64.debugkrb5pluginsauthdatasssd_pac_plugin.so-2.9.4-5.el8_10.1.aarch64.debuglibkrb5sssd_krb5_locator_plugin.so-2.9.4-5.el8_10.1.aarch64.debuglibnss_sss.so.2-2.9.4-5.el8_10.1.aarch64.debuglibsubid_sss.so-2.9.4-5.el8_10.1.aarch64.debugsecuritypam_sss.so-2.9.4-5.el8_10.1.aarch64.debugpam_sss_gss.so-2.9.4-5.el8_10.1.aarch64.debugsssdmodulessssd_krb5_localauth_plugin.so-2.9.4-5.el8_10.1.aarch64.debug/usr/lib//usr/lib/debug//usr/lib/debug/.build-id/10//usr/lib/debug/.build-id//usr/lib/debug/.build-id/60//usr/lib/debug/.build-id//usr/lib/debug/.build-id/9d//usr/lib/debug/.build-id/b3//usr/lib/debug/.build-id//usr/lib/debug/.build-id/c1//usr/lib/debug/.build-id/d0//usr/lib/debug/.build-id/d8//usr/lib/debug/.build-id/ed//usr/lib/debug/usr//usr/lib/debug/usr/lib64//usr/lib/debug/usr/lib64/cifs-utils//usr/lib/debug/usr/lib64/krb5//usr/lib/debug/usr/lib64/krb5/plugins//usr/lib/debug/usr/lib64/krb5/plugins/authdata//usr/lib/debug/usr/lib64/krb5/plugins/libkrb5//usr/lib/debug/usr/lib64/security//usr/lib/debug/usr/lib64/sssd//usr/lib/debug/usr/lib64/sssd/modules/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnu directoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=9d2a85bd736487d95a6194083504045790246295, with debug_info, not strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=ed2da8b90ca74dfc30af3e2239c3ccea68ca44ef, with debug_info, not strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c19db917cd9a670d182641850be41c991c71ae25, with debug_info, not strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=10446ed5768f263842abe925f809b17e7edd5e04, with debug_info, not strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b3316a5dec09296d2329b7b28e114e199f6d5527, with debug_info, not strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d88f9480a646ea95c256b0ab8d351d262d3d6753, with debug_info, not strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d0f3219e4247a3b317e7d95d27337343b8ec3085, with debug_info, not strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=60ff1c50a7979176fa682cf9b00939b3ab01d435, with debug_info, not strippedPPPPPPPPsssd-debugsource(aarch-64)2.9.4-5.el8_10.1utf-8c55b153bde60cd2f8969abca08b493f164f4e453accfd60e7c13d81e06827c29? 7zXZ !#,O] b2u jӫ`(y1.G&x;!L߻pA>(3>N@P#>}zV*R--Oo= )W]x2r%mHWƾ|ɑ#ۻ*&.O->A;u]6^ g%/e5Jƾc.v n,e|%Sly+!44`D9$ ^(=uu: EQsKn&3/y&& %4i=$8N?v#nI/UNlmǸT7MVEqu^8ޑo&vUAT+H/L?rn ^fS7ڰˌ~ᄳ!G,Fo}J971Pf ,@WJS}/ PY?v{Zg<3ES+oƦ@ RzjmZ>*igmi=$1GtgdNu"\{X1^įwe3׾AzH>³.?8Te. Ih[Ae4NAGWc!:嫯A[#d %*gd?L%Fu~Y1Q]b \qb.V .?p0eU8VKxG9_P(< !xg.ն#f^U~4B*]9tC#9* TmʸގuPIS6Eo6x}Tc,ՑDoLGwh$J4G_},";a01K>0{jYq+a3ەVד1G+Qa)T%>.-hSnSyу^A?忯v1x+®,0iq+y;X}z?;@K^N>e穐w*̏5u !X;yaڮ$ U'4/S f=ctڛoR촜R/Y~zLQ_ Oy*ޡ|)|Ed{Q0Tܠ.hgׇX< H:zבsDbbÑlu,eYzW- $돆>RDU0.bB<&Ӎ^w2/%QwaV~P%tm7E',H$C8o0)tח+ߖ7CYK&oJ @wc}c[Q.BM/Eq]S4]W'W ŌP vvp,e٨iTDV贶efڼ0d͍qlȐu3oc4psohj'a t"4HA<( ?]NB3n b8گ6>3>+[wpzÔ$=SM::3$͝P{SͶw-nljAgAk[+Wa{O #m]i$lB/&0|gKq(6pz^֨@pI*z-1&hԮ4ߖeT^q2\XuK*|6dϫ$ 1>{>ς oZADSI{ iW;ko}:؄mQ7rv< ^ C񻲢c-.?sǁ[h]ى{!gZ\{9nupa,C5E^3O\}/r&~!~)H N{ \bkŘv{Cx)W=h5/'GѝwG%ƣ`ZCM;JET! 䣜R~Wm|u'nVp݁t:&::"ʳg3:xC,HL z+_XaߡWT&Ƣ5Ǵ;n*7ƙ'jO: …a,(1$Fddo>R&VxN\/=w" <2V{Ca!F7 ,\1Iļ!b!L3k/X&=T9!Ԩx[/Fa߻c~X?"؇nrLFŖO )`өHHH#MlټCc\~=M1M yFs _,7 Y s KOTP':uT lt%VtΡf#;-ƿ!6z}\!x!{fSmǹD+kzXE:mV-je)nA<aTX|p f*'EҞ@"ҳ +M6I.ĴܾdW$SFq$,IȔjeʱ? E:ǏT['b!AK92_DWHD=Zk>ʗ¼Υ/cb'P,VkiTuKw?M&F{3K!g&c^Kf܄Z6۩"_;M9-Xtt! l3Mys yŎjX%+; ?zhߝ|n'wsbrr_ػxFn-}=i8ID"b%/pRg[@|\T@jc Ɗ](G7Q6Wx䠬^Z$Ixǘdh[(YK\Jz2+}/Ӛ/*>,J#Ņʊ&)ZO?<2beraN{ {AR>4]$`!4p̈́_ Zg#XA D x~С QH@u)ĻcN N+uz !Qe.Mclz#W:@O2I]'tL' &.dt^l`$LHJK|+`O $]RsjΞVLJ:wWya,孞~Zȡ{c,QɔQcy,YV/~tq8):ɹR[qH PU5#Н:hTYPR u([چiZ1*\T̏BZ.(^D4-C HֈEGF{1@!,A,opl:^@.7̂O^.0nY8OqܯP)D>LP$Z/9ȝaZ}TAT(D@u׹ɄG 8{o0<~LmpS]]AC H+_့EUw[;S>ԯ5dSac;{/4+{S дGMu'=sں5De K;5MIWjYuf)!w KdFC$n<[]npTxRK k'BɑO\TC LY5,RbQ7YMJ~̟txofd L]lFgV1 >TB{Rj)B9\snЛ*ʬg۳~T9hzs3 7AusϰDɧs/WCr zuKDUcҼ Lzs{2}6ɶrSSF9D8P }V ڡąh⥓kNlNs*WdCo[L5$ݚs<_҄ʋeug w%+m<߷>9OK1nQ#rZE]+߯yY)m8Au+Mة?)R^905݀AvA˅# dGOm: 9Bbd>¢k<̓?T0!;6":Zxf5Rvn{ Jƺ19a2rnT;䷚|PsKofU*[4zBYOYE/(@ߨo5MCf_P扂p^ҿP~_쀴G[ݘ@ۣXS]b!ClC_U7,=?ﰫp7Mfg (O5[6_HZ_g#$K/}KB e>q9!`Y؋3xqU.@4#v W΁u /xlkOG9v,;XP^\)o՛+YO̍]@?ʫY;5L?O2=SH*tInBr/18$%NaOY8C+Z }{û$+.@SDx^Y{y#ܺsӡ٨YO}#c/,K~ktMBBgU鱾{&-S*ĞctZ+",yPHyS3u0Rbb8VV8ֵ|r;UJfojulKQWU~~2*?Q`qpw֥88 `d v/j;Ug0X F/#"I7wb;r. ݥwѠGj9:&5mҍ=z/҆E @#my"9C2/JT$~c1_G-t:?H^g]3c?;Iw)$W'>;?QX9q K4v>>)ԡ+Q ӟ{0 Ŧ:K?iWՎJ!nKܶ&)F6gsp? mOWO9&)!K 9;I&%nϸ,ir#3܎8z'M/ ץv2!]|SԫMd ڽd=ϸ@"ֳVҊ:\4&UI뻖8Jo@?MμMfx_B]DIDpt b$[e*uX_DpT:ͪQh쁀8`~A K|g΃skP4cwvRiH0q?<;(Vؕ"-Qa4w4ޜyJeZ##e $2;[=ڦNOplGOr)NQ(:o Jԙ2 AFT[/u4gFտb;߄y3?T0 Tki9}ɰ{6E9^8Qԕԧ|{#cEƬ298ɪј)d%7o-꺼\Y7/a= mFK`'$/}#.pnĝ_(RſSozGM\Rg.H0=b5R*0ޞ] ²-L&,PZ=tESzcc}j,<&A<\vD8o \e0])l3 Zh [ wgQ#ppd_T+FHv.d)m0*_fu V1P&.Xt?O>#FUzlS9ϧưfJY*$mp[^S;_7*'\ *ܜǗ0 #%87s0V&V]]f6[m>*ѻބ?exk'Mчu΍u<;<.Ũ?櫚4/)BiG/C WQ SZ|&"|p~BPzG\)F?0,l#lP#Rs]Y>?: "$Lc_"ߊHy;D& {mwԯLFm%uG s u=f,f:µ92_$khIc>śɬ}ĿOG) OV$H[Kd "+j5/#xL=Ym* +@>ǡb c?|*΀a"VDkAJ/S- WF۱?...cV8E/ l,F3,6顣|h|e\9 WSd 2j#2āq\pP.2JX'n7-M#36yL]c6EI9/#Kj} Wz\ X+؈KK#$sBʏ=ܪ CM)&9F,Hgh㋑xRx/g>Tν XQ-jf^x!q(?!Qk9UL2fErSZw)A0#J80U[?>jBmG Sʼn- NHa)1jWng :1Eh`b7~=N_vJr&PAޡ0YLE#;a/ۅۆj5pJ7=ͳ-V+7sha}0ۡkyI#@ zRnM'Ȭ!8 S*tBy O{hE:WQY'5~u:^z.Nu7ZC3f{Pb0o<=ndÇ|eKD.!s+nAl8Fiwf~Pi7wV.STOQaI>lhdߧI+ 3m__AeFT(XN(o:#~Kk4*r#O-X&<&_ghДDD?7K8_˯e!\@ +B+V,jbn:`]1N"QΗ~/. RIk&b]^Z0$kR%([J/zN**6vTAց>@igbov=O9 pHChj {'+#AbDU ?OPFJK@ ?w`te(%6Q7G*"xGՌANJR W>81x&CPK;WN1`GR3z$`_j [L6tӣ^Ѽg5jtK֎x)ƏGX Vsg<z=Yu[B!Vpd ݋rg_<ա?1YG(EcBI6Ikxj7W/3 FceRUYMWJ키)4|ix[X*=Cwgo/Y2A?l%–$ ӯp=ۑBNʄBx7FnvC%'xb*DLZ FYqtpe~"xf\a"gk5}CiGtT$D$_Q룰kb BpfTĥt]?OuL W #5|W)vO˹V/Uv/Lq }IdA OԠ::,m'˘sB#E T_QQ>=ţO+S&Y{@T_خBm'jSIAqbIv2_{h]Q8η'*1a,axx|G۫7 DM6Oar.;گN="=*j1̉%YG: *s){ F.z)KVFk⾓e *b1, 59*x@SjPKEEBmZ: Whu3AN0#**%Wڇj-?g$5lO(3ױB" fܖsW5 ƽ[ U ;\yH*2Bh34Ta .]'yʤH01R¹p։ځ@L>EUjB1N~p\(Cle>v(\g\mtE:8U.g ŏ},V33 8O;Y3_,- >2\["-3CN? Dt%Lz>GQ>4.?^Dܯ؍>igDZ핍-a| Oi;!ZIAFcըl"w`$GB@6Gu2$p鎊Mŝ X6qtcXUY4͊rGf4tVqjJBjXJw0hFGY(^$JVlPdU[xb[j =04CIQ|=g*^u̽kuiC))4|F)i/tnxY({l'܏%ŘqG˦rL9߄ju+)P=3h 4@;Nmy]qt]͐jROKD657oo;w'Fs{ctqZ<kb oY|*MwǙ&o*Pu"X:=>qўm3!9Dh-&>͂:!Pr J$ Rj ES*܉]e( X\(NHc|g18cAb9Y+Mۚ8*;E@Z[J%򛼝"DjÒZMTSd滼oLVubQbOg"X$ -P1R :Ak|<.X㪞~y7ZvAM CeWb5=jhVm:DH "> nAbp H^ALz,"㪩DnRmb 3v w#/3Σ-V<*RFe2[Es7V7 ekz`vz?2 CmVNPؾVTFo f?Ut \>.ᄧ8oX :W,km>Qb'S>Uy_VIS/Z ʧX`lR>Mlh6:6ּHv&tSo=gmʐHrhCEY@[O X}DZT{en#F cтHr2`d}DF]¨b[u\#;VEN& {^"Sb43dNłUQ"ËH:&[M"i󥗯#H#6W&| mkrl@0"  ګU}X+lV{|_B ڮ_VE ]W=2oOēf) <]r쐈)'S,܍w9/,N(p3  fUO+]%FzhK?<_%HuK &UUb$ ZˁupVZjFJ_I2[±i~ޙӴQJO[AD 2]D`SYQ>$VFX::}])+_IK #zբ Wz#Qx/F>_`*s)sBQRDBKI"V:j-j:> Lř*1{M_kӕ5'x%-$?љ:ɑ9 h@_]KU8 8F_|Tͪ>14r;>_6EÍG65[~+lq\g M *qi5Oǟx/D m,-YYHBe5q٠^iw{jS+N@>DmA^h);=jD[̾(;–c:oϚR1t0Qw:)CʒNR* W4*KbD'v-q.Diɰ.X@y,tPcvtk%,L3jrg\Bϰ9"(l>P`zs\Mmn)m,Rʽ'!msˑ>㢖x&[OujYM^_=r~,1aYeSXtm6H8FP?DtuKh֧$s2 vTfLxw7=} 5x ƴӉQ  בڹ־v)(ԩF'N-eh:t8.-Fޖ9Y2c9x 6Bs=Hʗwn)`/V/j=ybZV5X);ݮn Ʈ̒. 5KLk6LXȗW_xĐC^lwڧ~v_XP (CZ|l ~OzFJ,=QpOjjNp?lC/[f3 QSb:1YsLT[-_+ ݶ2~ѭ"Y\?jDf@t*ATo?jdNp3Lƍdhycdgyr#U)y$ n%ܞbk v=.OEV]o\nlG}^D &7f/m8])uk牌%}*˥vv0ޜUM@N %=Na' ǃ Hx~?L}onzHz?w8 D !w02W"ǘt ^_VX\O5nL.yN>RΕP:*FQGE&|>X2 +Yd+0d[6 i#60 dg:WbAy%=@Oe$mϨpZ zKγ&;Q{?lQ))TZqVirA}>-v<Yn ?BG N,-G< "WIp9Z( ?bnEbv_}KaJ[v{dM_@DVWE"ҦcyږdqGQc 0G"bg>qV(_:!Ee((YyNuNyi6 n]=fm-?d,Y'`:?k<2JQ煛JarCו{ΈEwZ6 TQ;@ a3-,PsX(ΌU#K q9uyZg%Cs#n"k(l5@2ĥFNW؍)AVT,Ne p5UW{CON}qH=Ł!BuO8 S ,9KZn\cq:MLVxSgnVm /)VVʹY1(/&Br6Iެ8g,'Lb`ک0=JT{k`ӵf|Qg"arLϭzɻFǭIK ~ionS MzU}hH͐IJ3<@6B_2㺟Q\ΐ}0ZyK%;1EF_..j0zU]ͅ2ڡ"2#ML1uERcE{XqVB]y*+1-ou>񔡚(k,G'` *|薯 QRN.wJYY@a¡E:ֱH5lx0熓JMлWMcWә˛-,w^Ɲ͑jQ!~ٴWQ8〰 'ƢbDC!1)&,,B}7㓃((6ĝ]EuԤJY ӨT㟈?Rr"?HullSK4 c3iG˩Z^2;e%i4)IeHk^/}V;(IH\``~k}.Ѭ<lk@ryBy3GHbIZZ'[IUNi!3ze`ɐ[6\>14^e:VYS&UB\K[k 1sLX:hY#16DJPu>'Ic݄$VG 0:q0r4͏קG?OQȭ:Q5=%'?.kB"܈9L do}PΤ~nۊɶ)R>a-V_ed%C^ٛY_76'n7^ @B5R`Xg+~ $NӅ>a6 vpjۄrksDY(9]>zrXI<'5pm7O:Y?{44|فTnq.[+gj4}) Iܵ(bQ0Y0k5"jo!*hUdsʃ%j0rO~ִN9AXn 6q@[ޤ=KO zc>0ΩRaנ U콯.2}hGi)s6.QO^!gbywQE7tǬ K!*?^/{ c620/C wKd{XY J $;_AūT̵ d8ARN2rX=qӼ.@lFFf:wZ]Ɯ&*p_Etm1bϹ=hVUIx޲=9p7m6%VS/RJ cq&nSB"N"+Hu0QQ?`*0"!J8  \zVGby_Gye6WcO JRƍV\ʰ$!2يA$?/&< gLc^$Aۀ fn}0JRi2-4ٯ񒙳9[|!Bh笷Y*~G8DǩmM-t^" j;Ca:OPnǔ쀹ga޿Ib؛ @xfT L.F⼒x2ߒL-7\yE;u s-  v-:35j|IО}H$[25 $˦-!BJv?ѯ{h4-c"|+祐Y%KLÖ6a'e&tTFX`\i"k ˶kxcov1FbvZ"A<<YrJJwv!'I~q fwv+eDEokנ\dԀ[w^Ʉv%BC:w@ yj|49HBrIս sË޿OB&Ul s[wT+I1@q9% nOa@7I}za()ѱ3Ҡ{ %9QMlWXbXoMSMHUgˉt zanu(4D.IPtY4L@*rG;XL춴 UgH<3u<4k,6^p-)oIEв$5nۺO 7Y@|dkQN u? xhEo ~ɇ IeM\]ejۇ2PÕ~6|c? (;] x>htnl|}HWlq~]x_O#u2L׵"FoԜMw2or`1З j[cZp٘#FlpFp\KJCtr!9+f&/>NZ,A(Ъd駝J!>^졄YIbYWg*Aps;/=BM9ijYT)_mEܨȰl၆M#ȐD4b*!)7R82#5pdߊ2ncЩ#;_mޫ[+QiwkNC؞Q FѬ7M&KB a!ko52'B*vW݊[q0-ڣw~{Qloh&?9u/ "$-Hxg# |M>j  A H83~y}%ԭ] [oi:^Z5gϦqSD ^}b\ЯKj|p*zik":,g4tyȋw!hQoIUj|CGx1zՇ=R]bHgLI`MWWVp`A׍!ƹoYgǩm2֊P/:_ M^4/?e887͞'[ Uob0A*g&' _a [F ;~+[-!S$lp#aG|YkJϯ(uߴcm?Hk:Y?t.RW n暒8i ō*䀽ewP켎p[{;~4w]9r}D$lqƔ[ ft'TAaͭ UM8uR)UD+:J4<Ż$QC^~j _ςS@ 2Z/ TFŌQ UQ&?Uk W PT Zx W`Ǵ};qg~|guan&".2:T=K<>9{im6d70Q/pR`Ur8 tf8 Y.rc1W1Ǻ6o.sO%նpbޝAKDB*NJsĦe ru9-L.֗OGkTZ@[Sz/^cN g} s 0-1M_Tn]/>Xc]YaW%)P>κ,fp˩pNAw5\xt<ҩor,S]/9gQdpc@RF8{NĂHJ5'#`2$ o~g^&Oo.aU"i7L^'4;iSjkLEq /}5уVDKVH9Fۘ@T;[Yiṿ3G"ju^P k5xTlEO"]G,`a|A s1Cvc^d7>!l&sx-R3qnF-OHou+b@\RԆ◾Kov  5I47m8r<¥H Pa=MR73e}R)?] OÔ\AliܷT982Ǻp{YˠD3`."O2[/>{-} lq$UH+ߐ}򙭎3'߄}WzRi~a71RƨK<|bzte]ʷ)c'ijݧqXX(qx"~T+єg!h 6cgU2Hܹ VMZR6ܠ~9?K9̈ bwiNfl庐)bXLN$!u@|,(qYK|1y~tt3+m&mJY^uLZCA>DoKf mD-c5mR@] ~ <'۵5.QW.1..yL+q]yw+x}ά&*8إEI*oߤ:j!E ʂ!z(-&&^~p]y 殬I/KPjŰ^gjծ\6'lD:߼2qy)R;iJi;Tn=uSoɿ<9 ᶯwN.|h!z0كNMpt oH [KS?֦YiJ 3y Xn՞IXgU&Ptܬ~-O5T$Qp<&2zP!'T^Ln|"vFٖEGaE"?\cg#]0~BF'-.rEWI9,OKj<8ke5+TWYMٻR(O}y NM?jEV _ͲW%h< sN$lqR8rN\fCI4C[ :-& Yȸ/C[?Aez#KH]BTB/DO:r[w) U*;Ad\|vݔ~ "4UCF.?27DVFUTYB910NJqFaã2q!6X"(W8 yʘquO/Dq>#F3mYHi7Nk<"oT`G/O']s$Xk]KfWu qK/'0 !T5 CPǍ9[)d d TDZb"wTmwl,M9A nId_1D'.7% )Ab'r|n&d[|n61k)rN>ę+&9#$MgJ|wj3@ GE1ctέT;FVi_#%h)UtDh3tu]POIOF ȩ.L: ʼԍUOD1sM"Y"x>*r,wWw?ǂPI dD/ `dmfms U q]")̸g"o~Aku+Ѧ:jh>N`b; ?78jT+[s4տan5tRV:UqNl54fprTJ# FnzPls[LD~"_M`>Sh ٣2dq'Zl$C{uG2] ,ob1%Gyߢ|Ҕ+n{!cД9z79U\LYx;~+>%gFTT 6ւۮW('9d30DdR쨹; F&~7KDžRQ?ȩS(W&W{6`gϵX0*h|w͔P5NO}w}8Y/VU3B; C r'/E+rQ!Ɩ "vN}G![e|Eot5׌נ-Bzg@=inwз@6l&}ٶZBX 55hUD-ո?},SCDҢ1nۮ1e˅Othǃl%o=rxOL#}/pD5#oy0//n)FY-35x*^tU]ĹP)Fa!bL!ɛގ+ _c2ōFBD_lI3@gѻ80&gQ#)m2V9BYIρɣ5]ȺN r2fryEq~nkhH)cƻb03-v/gMӯ]0-B>E)%-gQr\s y8I%lKx̬-]L@KPp ُcD03 ]GCu42d*+?ԖaJIy8B"A> $K+;-ɨ$C |m3i}C.2(]J)xs%K V\rOU9akz%Yma\*u\gwŞbR8Pcн~M=xw2(Y5-!PK2c|*$Di!q*OqTJ+ϝτ>j;$1>D),$G]U<Wв>w7A\9d^K"'rIIvPb>MmM0+DA 5gf@3S4~uf"},1R6 ȤCgVۚPH%j)Ts~MEO†@"\]*0<ɚ8`m?0?e&Pe>%sTM3{!SF|<:Y6rz 22xӏԑf}WXMt{#'GƦsVj 27qڳ *ci. *ePTP&m,y 9`,OP>yJ`WTEgؾ _UfC+L:v"zVn7=q"2w 8K2L52|=ܧY{:PDs ?w+c( l%T삎H|u6u ΤDi-p~G9S䨓 #Lu1AI#k)QYvb!{0Xen&䘒L7ŋ=ȰeyysBd:ݔLt4&]JFj+y@W>l)U+ے- tjgڒ|~{,i)?. ov۹#nwooehA(,Ҏ|z[8faFov96YX /K<_To#ɭ’>f+Q~@~Oc]&Zf+N,:v&Ab|QY, Ty<`n_J(i^"*,@h0 g`5䰤>M֠ C^c-KXqg8/nYk7QhY{P!y@©"%N̾U hsxB859H7z=eЃg:бpB7Xe֖8 2jiS_YzI&m@tg,V6*,>bkښ理嘂IK;,v纁k:ߛ 6QD&! w Z;ӗGӧtؿ +#qzPx4?ǛQ.\uPVزC;"`.Bx~}9›z( 5MhI+ !P4{D,g_nȺU!.r&B"K}J/4~Ȕ w9<e IKad*ehx5W;! (]30?"ž@L-~$.O'/4EbRtܟ8} 'dȵbFoWƢ.y&HX2^ih[3{ظ*mAB92]-qb2d{NEMd}jNboIܐ4=&n؟q"C(`%# 41&擖oڒs\g~%i8O F.O)w]O#N;Kv D:uBYO?D7`k{>d).Ǵ5.HHd:ҜRD-N-bhR;XJĄՃ>]:FŠѕYn/7vqWDQ$4LfR+ԿO>=,K{KvZƷJUEgI=!u&\}zlMFx",?햺&&U^d,k IqYZD$*3BF{Zx25cybɣB)$rgPgd6l-}riim< WW"n;s蓝ReF&oUkz[1fiYUvOBϟR3%1e/w}J6:O;9PeSOr]sC6#2W9PJSPnȱ0f$id'zoaR‚64}_KgU dթ(\?UoxrՆiXV.^{^ ܻbЯBNdzYNaJ7!*nV'MEƗfV%ghҞE3xϧrZ23⃭NH]n}aćQ})RERk? WËC7h+udhos[9Fw?usir]GHj|kX=)y'Bs1se`mMD!rvh?T΍ܛ?|&U't{Xo(ZXSx@7BhtukòCHS19Q@~lH?Pߔ~Uhl%?%oGC{UaZ CLe!V,5`|_aRsIt kzc\s x>]B}IA9- d HY3]ly _Kr]G,\AMC*ghRA׽ JTVa1C`O[aW9bޟ`SA*҉#:u#D L/wtUHHIYR &J_rщӘfm"WUYw0$_+}g5Z54`4ryܹ;:Sha=* q0Ԙ7m!5REh=ea2u~_s_S6=:O<Dop@F/L5l8N )Y0ش""rZAl|6RvSkF}jCfڲ-%,P0.ovM,e#!9)vϜk`r]̙!RǬ\o+K V3ΒGSOO>#Vqggo?~ĖU +MދJ`XlOo+A@>X.JL68K$j"/kzQU_)sBiͺE|@:0埮gyb3|PTqk3u<8хtK@3Vp"Pά{N-2~OKUdNF( . xQpFw`;j_eێ5Yިs1Yr_|l8sұJ?7$m'Z?ȳѐ7B( tw /GؔAG=ɟ==z>?*4nEAz(1~ bnsj4բv#H&H@`N5;k[a#۾,4[RRIK_8,Œ 8҄2ЅK8 HIR Q4g6Y% J:PrMR>5y1F6˳Us}1WATpi1:6YqbU?s[Bt\J\Efc(>sޜ>v.p~p]/)P찞wSn,:W"$tXg1w/ԮfPFDr;:`^LƭSy&tO+;Dh"X^Rf&~8oFICFt3tU,> D#gn_٤~dTD̀lẁ5yB+鋮qPFz"ۙwyk{X Kb91afLdo w3l;mn9!E9/%t։lEe7{KtL&#MIﮍOCaj@Dն?.6rnN'g _mq֠ob.,?Po2"^ۿG9ez5OD*[\xPru鯅 {@蟺nN䲈Kʨ8A ӣvX81~ [0I5^.e/oLP=;ekv=@ϯSJdoGP!nF~ކyfn`1f`Hu3A5XK碥- %~֎gX!!^ˀ>%̏Jj|1P%K-i=/T^ܱNFl7a**m IjNJaL?V4B3oI{Z?Ű6 ^#6^ EEjo1ҩ%H\b 9rɈ8‘"a-KY/ΰʸ3>{z_&f]u*EP)Z"uGtkZغ3u+!A;ѯT O֯zZs(p %e`VAdT¡apĖwp7'o@U֍9Ƚ?$ 3!)iYRH߫kbOW8'I`$$2Mn)BkhhvGS9W!pUo6XLPFUwb΀Za7G0Q흻@B:)G_Qڑ83/R8zxJ'P3guMU #JJKoeeEF2'U05R)ry W}K] V_#Ht)^n-I:;$z)nZ!+a)^x8 a InFiwM^Wչ*GS̾2Z3w1miIįQ+fpƁ,= 2 J٥edbfc(2l0Vty3k+\%44"#e#Qa1gF*vbŪ dC@PUD:Z1̥|Şh)L~Sv&)A`~QVUe`gӁǖF4~zW8ۨ2Y5E+X:()H̀z`vF~YY.!Ujəh:UapJ0qU ݩH%̨9g/'ɏ^ A'l2&z7dQ"ULy)싰xvXNA>W7&")y]~Jϻ@{*$m>G,ԹrL 6棛BDƦ]>Cd- ~D`z2}\K qdaƤlL*KHDQ~gu4k%EUw?#eQuWHB9 MQ9o~Dn$/0R"V_N$E[Y.h%4oUk{C M6j~W+k-_ӹP^a &jF+wCl2~(6 zS,}?: g8|(i%Cpy~LB Wy c @uLEy0PW&>DJtwrZ'*_xÔX hGHU~se{˒єɊ ]H$֎yh]E4ZWgf!W 􋅨hsEo`{Z`*QIuF !JEi`\f`^5Ǒ]=qΤF t!%ZwX#!̙bGӀfʹLz?pB?*GVŰy"R\K>;ޚp{M2NPE1$~_(K!3!.7N9uݼ:+ICviF,NBy_X=Eu l)]P͒|'A̗[ E>P&kN+Q2A9! >UgcBOrzYq{ف߸( -Rq5` 3x!gWx{80|]g ۵d)^C1Ua)_C6Z> jdW-6{KELl]mְ, qhřJyW %ط3[?j#%x(SgoQFÅsFA%lگ/)o@Q%z9ܫ0eRGq+1P`);'U=K_-}=nhLJoWßoLDXI{rvw奊nl< @;*a AV Z t1[W8T08W/m {)0\͛1-G&f-g7= .'<[gA.D85[*,w>`d[)# Zq6v3.+l)NSv'F1z]c7%[;ߎ+R;ڷ6^؅H>Pt!əe$'j=i<'25j^hɞTgYDzaB뻚\5_#(q3 r}rUev^4) хpyV'pk$]Pҫ{c\6`]3]:|1/B0SLByut>xQDlb±4dxۇyxgvy}0] ""al\0 DgDG?|h@Zn0T7n!R}iG_K=G\F;qE8WURҦ z5*K,ILW}r"oJ*";5qtӅ*tod-):]`AvI(lSp_3qJGȔh1. UU(])dt#?5a]s,tsvFGl`IVDU`abݴaq']!1mf7r,@>'= : ou*+{tX)PY診Bȣat^)QvE*/Ȕ7jX2gU2Q5rOC /{R~*V_M"6P o3!{yD3'+#4VcHw +tKA`ȱ_]p۰*2Oא:.HtL@_EJa/(i찗s#%pYMQn85L^Be/XQ [NVZTj7~p/5|js:Ƕ>烷mۗQOF<47}Xא8G&z~ӡ\v=khw:wZ<2;FE[~_fD\Lľ3Tsx;jL~T"Fw ' b+mH($ FJLn%&+KS꜐[IlgGKa#[=g)ݟ1"">̀ S"#mZ1ҧu\/Z?9Nx]=םi/ ^~8qmp1^Q ႁѿ&J%J`·a٬XE}%!hKPs #m5M&(߱`wU93/]DHs%$`ά(UJ40ܮGO>oTh8?x Z<5uM^[GR>I=2JWbQc$ F^ cVԎ 6:z}r訵 AÙ@q30P' x|][R:Rw#.<ԜNo.1m,ڮ Y9C_-'[4k"7C )i @!A]ˏ:?1^?uߗ`ŧn>•`VggW ʚfB7%A9-AL})+: 9^ܯD6Qh0"^`fqE<e a.c6Zz~5$p[%ƦRoHZJx{g~Mh s0*eubd8,X ;I3@5ۓDu}RdpZI9ڣjs%bKK% f݂2{Z="I#n5Ro(W$eH%ƍ?oY,nӱ;k. D6FK.HyV$ C9O*uϞ.pʿCG.pS;1,SBKu~E$KtmڀcquB%KM.w"<&CF9Nk+JjL.̓~UMݿbz<DIOXMH?q #YF5jd ͊Q6ϕzXdT~KJ܁%plsWhCѩ 9ѻppln(gr$^ɂK.1>i6EA&OPЦvy!Mh# !M\1ʎnKV"IkL`Y <՜{7o*X eNMZu_bjPE (#AmPkc-]{2<>n|Z*~eW$Yv3)Id3"X#ց5W,2M X5ōs%}mUJ ݩh~Bލod;Ѐ~`IOV 8\P 0겖H~ȟH}^ 2 P==XBGH#'jqD%(=:aRёDL7-}Z<ַ1΃GUy ŊĞլi Yhon~I_C+*ͯ*:Lz(=sN8hGv>,P* ͑SR zỄUš-%&=d^0`40Wxxv{#׏x{aIq 3xN U׈1VWtٶeNڣyD񅚂t'*=_# [eDžP+t=SD%~2ŭ4ڂc~GgT?<$ st#YA೑J͑PC":-{MwQKW$E, ؈ݳFE* aخYjSCa4g((fx[2;"xE|My bg"|21'asrum6^rP`܉gĝu"AS F*_rQ~,ELU+@DsnqΛqO0Q2ѧT`h?ds nu).؝ tۇGMά~@ڡ2kӂrQ`\{ rc3@k`s2eGުqKY䕎|+upx8#T}-xhB+v5GA?MV ȩ7 z>rd=|k3e@ [E gbxeJ/D͟2sj" MuϜ2d=S?fM" ?&NJ\,~w4)bb0 cpw)RgGω ̽go[M,q ͸=nL(FQ|Grw#M>![^I8cEeaf&RT֚j4؍Mds1>O 7F=Q3VOEck]#|iܱ^`W8yHSCIřR[=w*073T]tA5ce:QK3(?fhu<wKYWIwM~طm*^HF +8HDhmyhJ#ڛӯ[zBe۪7] 2։wL_.Ug nتPQbÆ.Eފ{vG12T'$ V`2HlwwUl]yN/j׉?Qq\cT=GFl5?.&XOa/cI*eLoC@*I% FkՊuEnXzɎUB%9T'8O-\'ͪoT6Ę 6d|٫lA͖DC3l΍ K=M@gX찶tlBYb*#( zql4ShK ڌ@B|ڙ9mV_݊_Ïo}-V n*'w:##Ů89WHjUƭ8#7#3P*D28vcoeAΐ*)#e3?9A*ἥ׍`a-L]h~@jI*ʆQigGY~O'8=4Q9w-yПdBt^a~,UVN[M@&;&DȦV BI=;~ (P0̫\2BIίej<"jo.CxB_eQBL00Z[Xʇb-B{f(]x_M]R-䶗[hzhDPLp2˜٠≕Ri~L=gSXbqQy.U{X@ZH^HD뜹$>EE-lTgMR'LD^>v Upc"QۢZhW)R&'3YC먾.ݓg" 0j[,,N&Rrvn E~5ϣSJw#׭Lpu8I{K)A Pg,%~CogvN1CA9 `T?N^/-_XBx#7[ /dެ$k{nv˭7a bm\fJ驀 67≥w|}d#kӤ&ڸzx\(dVgL82jዜKz,Mt Aװ@<߾B% ToYӉDRUvg\Wr|?`VDN5qgo Q1 ,#u$ |I<= ܣQ8xo쿐.3PDPΏ 1t/~oz J(˧J>G6HێKcCOCwVᢂ]*V(mF6qGJЈW/KVCtQS](pZzjafJLf^V_㫤V?Y⹄q9N(aټm>kT8pH){ic3^i$tA~[LY&0`:n8hiU zhV:wQHWb=U3C)߆7-;r׷qZ4ii(4Nr:քktɼbf%gBgQ6W.x:IѦ`).PkU:q`ׇgIdvE+TfX쐤eQ9%w-Kmt7Ź6XWUl5 ^aOP-JO'Oi1,yy@[{myf 9e\n<0].FxF\!7S iSA tṂAN`@BMwWHʏ> icE1gDH( *$ HPY2r CwoTW.Sa:""s*D aIZgeB}8S?+ ? $1*uv:%QT-j-L蘂 n9`'@T|f%U֏ AŃJҶ m΄@%(9֫iBJWk~l!w. r*n;lASm->iÍMt,o/WQSvyzp jYI|LpgBbDH{Moz`;ozm9U S߯$~R`!<>>#Qx]k$0-aR58u(}{FvVs^EYA/C$jDa>>m\G:b4o>3qA L&tF"S X~J`)}u9HXnbKF[J|/;8~["UDb:\@1_R4={xtUd:8GPX&;"d{FQ1Zj6?2\g@X슳]e.$8D?U2L:Jn0hw"lkjk>N$[,ˤw-m?^xnٜ^|VhKsp?dͨ8oP]PW%a|Ŷg&45_7J!ӎ:-[3Ak^֥R˜FD;6,H,f)tٮd."( j)>Ck{@^jgd<}ω4Z w}|9|CM2sڙfĐ!Pd*ybҬi̽E~"pg×^U)}_^@Xfof[ oe1!kؓ9Si kB#`*22w1KGH$^Q}8/_\R]6RkCUbyA#TL&e wsĤ~KD}[6^* MPb9tl4\4mxŔa>j jRS&x*P.'l?r&WYٷ?#w,l]@Ci|J~|]E]ksb햗% LPv(=-7PZ/ "S 0%#s.0H< }9U1՛/쳍;&h&R’\,#9lZy'tQg$F ƍ5tJϰ^w!ao dxzl>:HqZwfV.c!/#K'52kr }qE0nCF\/k`Qjt;ſq4H.`StN41Y R qPàT Jnp`M4GDBǤ؝'th^5f6`nfÅ cCd%{2䱦}HCYڗ*FەFp~_.ozϚ\{gCaVp-g T}S E2ZɱodϱW_͛4뱹%h? y 5~4HW% ߯ف[@`H-QTgg#'t35tYs|] TN:뇸?¸,sDL /8)Jp Cl Ut:x_IYbs.ݹG}xS\12, VFqwa{ߊ#K@@R}`eTKio5=,T%oG-\:U([.d3:8ҿ?OB$ {̣ c4&/HGäAϱuUKLS]خ2z*kG!97tl2ށGu43]߬jt&V<6a_2ϝGV4~"UAΠ0EPq!`Tobzv[vK"wr/h 5l{e?܎8B%H͋\T_╫]c"UQCm<'(hTvp" V!}Px$RoƻH#} <l$Պq'ȭq@++#-߶N ::槃B)DλFK l+WhKEld=Gb$K:CS=.9[ *ax!A9?s0R[dM_Dvޗ0V`-큷hv[}DRoqWtUgx~]4I. @\@YI++TQ2 Ppєtpt_j,PES x\#zI$N"yAEqѢRR'eFK8J`gV)OѪ(+^(+U&EN+q+,c= ~E*u2:S\J C ϟ=둉zLӡ;MZ2!0-\o2Y>%KRDmR/fHHF~˺s|.=p=iۙ}+cθwUͧ14~3$Ef9g#k\DhXKxckPt:Z4`cuXٸIr22QPu w;1}>_Yj7y卵JDl$vfg8NsUώX>{@|DQlrZ1ZfJNif/4;7\+Y&bQvokl{Sj?/P8=_"nĜp6#xÌ}"C m;yaZ㥩𫆺W* zsd&٧bN+!8kot31 2zJ;Sq'YV,nܜR=J0帉G+gYl^̹p~mQt|mRH2hՒ @lv.Zɯl pϸWJm^+0Ȩ<0ᄥ|mb@C^DXRPwU={\oYjnJw: sn#ś=OVBmQfQQ܁B$Yx P7wӆ_G]?OP֋$A1d> K %/b~4/o ))x%;!牊)>Gq xyT(k3 n+% yzR伬> I}*'\5"Ahʲ.Y(t5K*HU8[{wMX74Ho G[l|TMcݬn? Z#HH~58o?s\%4b5W4 dpNYx؛JeędfΪG/tsr*iN0AsV^ D {f&@毁{wXr 8G`l&*c@c7,ܟp&?&-SA] `«wUAz^$h>H&E#ԻzUމNPsdBe|TQ!Dଛ=^*78CDāQȵ M{TѫPW#t٭~{@ՃƞWgʚH dl&2q c8BA$t67-V&&|gh>?` mƶCBjvJFb}28YUȴ;, 4 @~'҄_J ЁR੽r Gڑ*-2h,N7m_Mem7Ԋ݈xL‡*yߗl>ƳvRy(eCO|q9CЮ ":y\kk]s.c,96d`\9~œW<=%v'ڢ,G/Ɗxk$(^\h~īWOg4ke2 ȩ0c܂ 5VRJERImte?[vQM*o$Nr=.1ZƚڳDqIA9kUaUB[{rGA8$!yF,Wu3 |흢6~}D6}gsΩDbŔ?V-/JIyZfwVZ@:8bڇR-aMN@3#"Ȉ6ɴ$@V3:C[y?H`Uډbwgi@5>cP1i"olW"Y\C>[2|z(amZJIhY ybo5HsHuS"Y}lYؙ[).nI41+2O˵Do Jc0o9pĹ2#{9AY%JcLoLvS#I9Hx߲ tm\q<eU`}#W@^^-Ww;۠> 3 ( 0p[CYՀ'g1 /d֐8j"ym+!J b.myUR-dI"_xϙӌcE]殯ɇKK&1Hdpos#Zt,:9ڴAj!sno. Zo0{u=}s&Ͳ[~Gw[׼[n Z˼M@+xN^2PwtAe"O2nRYL:r^d qPd/`OSEI2z*ag#y|H@^מ">؏.a}NPϹv?d?ROJ ̜QN EmoJA/{`ҁǣ-jtlY fw+wnY/CP\K='`]aSM|z Ok_eqJ6+9G߮{J|oëp'|6"RۢD^0}ll־%f頮IvBSI3ʜɡ [JqГ %^Eխ+fB {]4B#?}~rY=K)3Rn@hpE>?o`(3YuqB/ 7 Fq:ZUJ]z.>LEZb;%N]@FseSpTy:-!f` 42eJ ҆Oqld+JM?BD)rU[?2OE3ƗS11iY̳ j/T 1-ߣjpHAQO.g42~X,|LNy5Q< y7z䇶zM'F+aie͜of˯FsXo`.}0i6 C?3Ci0{e/rwѮ~bI-Fj\#p )s;S VUe#)൪eTk5 Nl*MI CڔKFe˷W)FYQ 53Vo{A;\b޻Kq1sbUz4X-iR=6W zތhJa%DGeO~ՅΈ}jAws;/jmȆ0Zg_m LHI OS](#@gxpuh~_\I뚔V%E`*!ꇷ,xNL3\pH]Fi`⤧1ӥ[h1P ǘ!2C0?BrpXf_h=4v,.=d ]uWNNf1Aǫ,qfC#|j:jYC&uO >f&z,OU+ErqR `8$,] aK^©5k))U8{X0Q*uwekpRﴹ[7Yx(B +gr7(ӶbUUL1R!<߻6%N:WC6Z;va |qAf/8GD L ѕbAUʵgaJ CQc[n) CW)eB_=ԁrlz";ʢ!?+&P2 D X^whqxzF3:QfOdLxA6PӉُ: :I-`jxgiSkcZM+7z,ū?_)[R qM â2|Q#$-DzkVc CT!qc p=,c򜕋C Ƙxj]jHAup6{oB+Ҏ%Yȣ ~'7Qw{:A׍Guj9|ƼwcB!p\f(o(,BIؖݥ {ORj<lE=! lѻ[;0RN`3uuZ0!j'(A+JyX ZH0TW\vq! p{q2"Bpn[=iMC:@D˖xƏ5d$YSEqyPR"҆`jŕl*H@V)9$f?Q0+L1ڶf˷!oaPu~8Mxq;3 q֝eZBe7u#-:}NrEuvu}qFףׁpTZ9Rd۴&_dL`oLXصm딏HXZ:\k V2OM)haMԊ%#T_ϗ)-YSchЉOZMUyMG>iz-(c>02ȨB[[(q!dfCc6[/}\JxXD sz/׭tjx{H'(F*)v䮁&9 Z&g`1XYrpWZN-N=| h/ cED q;=|C,n*3(skf̦dQ²n;*==8A{פsFO~00\wxEj"bA?Nْdg*V/Ώ~/f9D#x5c@[%ܮk q+@? Lql0"7˂پuEMd<4ehCv؁ZĈlyS#(Bvx[ IK dլ9{ J5*.o[>agsoPyм$ދGY%^a Bn53=?<Fd k]ΰi>e PuY՛+ \{|_d:-7.!L èI`D{x;8PFYB$,Cmΐz'5_;Kw5{gx1HhIbD@png 3?jK8F'zwE:eBAnY ;eN yx!?Eͳaؤqe$'(TgL`^Ph|j7%#osyU{X쎋YX5dÜs*M;` ·B&:Kl#&FT={AGϭc=YtIWSU#b]GNCf?`+b;@ Zºaj钱c2 \~{jDz2Qc:tʤ4gr<6l߮nT᪻p$`R y8/+ؔנ"K ~[wrOd#h:+gÀǴI9C]TNJ<ms~H$e)O͟= ŐZzГYkuP;kQ㥫yOx)FBB=C*i(]&.Ys6I0_tT J՗%Rv( t:cȦ+u1j!F/ld tr(u// N) !E3 {w l~ +l vCIU!G]9j1}wz^ڭIBK园OůL !0\~Տ-X,XhwC]чx6.+I~? -;7}M4wGo0Sh-&v\|s wIv`ezIkѧާVǢލ_R=m7A#V~AXPƂP M" +9DNioWSuCOӟU5VGOfUW 8&ΠKVX@ƞHc|B'ot0S}?Po)d(M" $"IErܶf<@wcG eDף/=Z֭//TgfƑRWkn3]?o&L?=mQ3|hz ^vÙʧ g!Mr&{/Ãb#A2%IC5t &6W(6pߕ삘+@o͋u̽I|O1?  uz@ 7)yu eb]SGGw"ܛ{ޖׂƆүɢ߰mշ<[J oL+4a}ck,<ۓ76@op#X(YT$8Q yEƛuc6m:Q$ N?|>4 ܟI:,>k( $ ,:eR6+p;HRҲBqpv4GQdWrsڅ!;|HNaQ4O(0 !)Ck[E+y 0LN~{:9J1q{-Đ:.W H4ܖ#ǹGKCH:wvcz!j2P6:25܅,6BMYɻ;>YZrP$h2H|k p}Z9tA;/e<-+e2tH\1Ƥ+IꄖJWؚ+gusl^AʷΙ5ڱmEѾx [8R 3d.7 zϚڎe>9yv{[Ws ~Nud5M#'kポvJDc "k#6rK=@qm~:nJ}tJu-7[%7yo۰ $(Cɒ<К$&xQ\ϿnEF3Zh#iG*0|X z}DcY%˜|Ewx^/;._NEs.0FC~ymG%FH7EVy d,_@~h3_'6BR].O5a ϔ&Ӕfլ. yF m}}׏Uepy$;Sb\ʾKǻAy3'>%(n/c&.gcp旗X]=)A8s#ޯrY,pFfx)U "SLl߃a 5^e}_5F͌ eF>C*jҋ;Sq˩>`8l.A cPLV1A{,D"hp ?sX $LLOe2U7"Va P8+K8)s[T0:f*8|n+84M78(6VnXnĆ<0 :ˡ( CRvx[W/o5Y fc2ۙ2e1NauG= eĒꣿ-聙zujDjvP0[ZT<-B˻SRd6h[C79/;:`5i) Oܜ< gq2sY mG r"T#Lj-o Sl gR_mV~Ƌe!0 ɤe=:~U&|u `ʋED>^}YdԪ(bCr=y%ؠ!0&hn#bMkjQlVMnXELأLRiVei6]7[ˑľLDTm 4,Qm칸o#qҢ"3ř`zqmu"{N%Ld]iKno!+N oKzoԳ8<|y>CZ]M㬩e=[)ԴF+9wwD(UǺ-} *hKpb~̈́Cn2N;ˢz \WN-9TUؘ//8ٶ &"Mgvlj,<|h ejP$睾iڃ6v}-d`d(\dhН,5=>6 }v(L $ݜ7J^@L g" ~_nsC^M<*ȶxiT,wv~N_⢶nE"qhYi1>~n8so8Nj:J׃tO>])=* J.)ƘQZ خ)٧}U,z N" rN1SԪFsw[j@؞sw*[pwoW:½/a;oKbM|]]TD*"b͞ne+5=LX?**(E MsMcëqW{jQ5oJ2x~['?DGM.ߟ`V_CT0 gIk S)Ļw:/dliA/7`gΤE=pc 3kXug('r@\]CƯ@ ؇_1WmA|QwmsW0m&%0h@jr: KΘS,| ,£{{9YAƖF"HߓS^4`4i~ypKJudŽmvtUݨ>92j]ն2H|4+-_UL'mّS*Ǘ*^踜1o&xȍ`IUgTenFn tMlK~0>vh3m3J$$;6yuuTYιf Bb}@F+6{PdwӘқȻܼl ?K`\2 IPi䢰 2E'hX],,%1˯u<{fM}=; @A 񞬠qen"'MdZ/'91>AѣE%l1@AnH)ηmgu1 ؐ;)E$}ޒsZD܇7ᙃ JUXGE-&@3/})f@i<.UxYejQz ¼ٽן_'S є("3α#mC$lH*Z0L h QO j;kW \")q5ʧhΘ)i`:<| '`ʦNhɒs)B r:{vZ)Tpw~өetu*Pn:nKrT{R ZԈE^CFNN%K6g%JXHMbmdU!>\F,P-|*Tt/V|.y F0mFi¶jdow h!iKH,GH@!êpFhM)A#vA9ڭRcڟS-H.˗Պ^*Rws,=4Il,I:XF|q[Z2TIlӀzkǤmIUgJg+ރfhJY&f]k$cĽzBIR`lMdFdqܥf5=mȀ^v ׇ4bmp\D­hi=U 3 _vjγ lUΙ3T6=Ix5\:ۉ$^<4v,g;6i(Hp;"3i6/m '2m;I~hZ:zJ<{ā ~wN`ݮ/O> 0r|RD R9ڑ)a1c8WG"x.E T+:q,  Jg'/v9u֧k)>5Dzl35's:!=|CqV 3 1$#M:ֹ%c_Xk9M0C>A*4 `~Fި0qRZq4.D†%V_㷜C٠Ѣ/#%',;lpC,oe"LQ#u5NDLp 40ʱFbl((V M iWd\b!ksX((2s|Ucw1'}ݪf&id&R<-=( d%ZcI.Ua%?1^ݟ z02RZʧ6LDԴ*Ϩ!Dp j>[,J×m+,1fTCl"a4| n-vH}}$u'O^/s61XWo6&:.VHV| j"gDGE.$ zc)uÞ|FV!c\Ψ=@>᷌U fgR7#nj&\^IO]wsb-nX ddkbLߞ` ZY{UgÀU s8%nK9 1֮)!V·T!U^9gD8oDKMnԾZK`q_gF:?0Bs7j>QKz\a2c҅\(&W\SOօ%;#_Zr5Uf{vuw>WB&:o9(Ryai.$c VD *4Ӵ(Sn{Hw!ai0Þk8^ѤՌ*q3/L6dZR]ԝƕZC)tW%[؇O\lOLLس sq]N!5qWZbcNQ(m. hPZh+)T>v z0M+VsiHmo54f{7.!bغǟ-Lq( Xe$4Th&~W9C}5 ç;ZI(T]$6cafzO͈BY14FڼoBO&U`(dy8} ss>\)V*BMxM-cuʤDvܷLRa}.eɋl;U#lkkPR QK7L_2`|᣿v_$M'9E\E8n6%ff5vH&\WF+XXV~$_)3{R B 2A2}%N]R^?-5xJ 0]R[mp}.~c$5 ]^q_=Y<hu Vrl\,|h1ë'TTZ8㴖1e).c we*r1&,w^Da#q4[8Az!rnAú/ tvzOIxf-_c1/5;P8-qNl۫[YIv̡~>eKS Ήp/w|~t]X&L߹?_zz\~5PF|C#t n+A\oi7y{bP|͋b!&afah M3dx! (F2*N@O+Aub֦"3/F^Ֆ Q#lC2A W8zTmxRS#}Q[rOAx%=zмɘM۔| {[Hf4qwIk .}5D`pt@Aޗ$]@eP*&V^_ǠD4{uD6CbCti=ͮ~t1G UqDV׼Ӌ`?8L%! E„x_xez1=ѹ˸;l{rG#Z2;NFN6ՓE/m_Yxpcj䴕xΠe[q7*g^毖ge Є˚J +wn I[o[8n Ţ?|X,=ڌ64( H2:`GlI:LPʛd g\qZWѝk8_NQݔ_J8kJkkǗݤ=7<_>$u%Jf)5Ef,gƐ].O# x :>L AVR"m}<9HdPRj?K0ßCtFWfBD D;%| MzG/w zb$ujJ^"$K+o=M] ٘Q"vO p] KNJChYAe׮и`Ky[Eإ$R2%igCR\T V[JT\1fXiSnap 8MxkrV s|b vp3pwb]%픩7 ofA73|yE@)gCr3>z@nã\h77\yv#P+ E91Ǚd3p# vXuUzP!UTCG;W?%sgף+0PSW%pX/TWfb9U!d+RI$(uDK)o@!ҩWϊg3}HT [Yj좍@xgr+VUTCM\}}s?NW?O~xpj@ɬ@.^RbVZ1bg!LIgJpG2D`*+vkSY>1J@0+oy%3c}޺E-#\sLy=MO(TD~LȬ9o $` F&x #i{Y | ?K}E_X\VFؚ<}N:׻ńOjFkk17%7^)ALW e`Ÿ4[I 1v-cw ۈ(/iƼj} X.b jxm 4=?{[ 8. 9oXx]Ty c&xy.QkF}Rz=_g/)0m0Pv*d;71`a`r1W}U1TwHxˠWWG9yDa(*?; #'0OBrЬ88匽6[҇S~aL L!P;<`=]T鏣>sh-.Qcn04L swnyL_]}s4QwzSSDym^&wٗkc#uE"g ]hwVRpcFc4\1ky,>\\3F2;".#)ǫi]-MH[$DRBX)4@>qM{c'}g2b2;q2xySR, PeME?YӸ}ߤ>h. uu=E"$ïj鏒~":cʦDE y}/m3{=*;WxTh XF+CxQ9ByM+җB9a*e3zw[Fd=d„|W[΁?LS^ >IF4*R VNRWh҂(tR"t1WNoI#t_,9#7,)!"L5t_HHGi֙u g ʑHR:~p/:n"E].Og=-λAxqOKۢȝ$ v;r^RG\c宏:];(Ei-_T w%9Ko{wn V?>ګ;"uf.zV ոeN5L蚙|cBQ/,-^X{d~|E&=[k]w|mi 0,%#`u5MKxdR2144h{+4o .~~rs⦖S+M#k3PEJ0<%z UnLhοi _ R5S{BM1$շ>NjL0_=`Hz"dljv!bB4ܯ G --RS5lxmT' KRc] ; fm{44.aؑDiȞҿ R ӟ->PvCqSB%Anf vgYL'ƖNFb ;v&rR3P3Vd˫Hp +ΗseXLǿBHҒa^~i-D41jgKN7E6ƀꪯQE"~ >d4yUF;I uI)Q/KB `@D{NHԯ'6LIˬaг~)&|p ^˵hzŖ 1B'{w;"˲PZW4CF<$Dh̯ə\ign ua/qOKZ݅9G#σ5f&p2{'M5]zVF(<u{cgQ|):{{9ʣYaՃox ޫuFQFPK#u܇!FZI(7%ю|ޔϼ{?yVe1/'.rcŃsحr,/R/+A=5i DȣR'rוE:KN;\ ߞ[;;pk$W `ccrQ7Z1~PgS(NΥsO`Ipz6]>6q'ڌPoi=[(zɈp0"#tͶHKhIԣMٴX_r ħjx#/Y/z;n@Oe<Oa}Ѷ {UXJ]H H>Q?d>մ܈4h!ǽb?A"L=> fm"X/X| C-1gbw$k:ߑ}`Vs?cs~ŴDsk\_UC(sɩoR6n2meeX/PPKM:WHW:\cDk%e}OlL jL.+4g"`81 tZcE ߨ=es{; AH:ApM8LѥK}ea(ʡkO}֝1}0S@҄wV:tidea(x҈! P39AʃU(nׂlLW6y#Gx8MWiy-jBv^2>Ae+e]="5йtx;_W|.slO (ޡw.jd$>,%i+ፓ,ƋzY8-3὚dL=w$4#:~ƊHT .uX`hs# P<_G vA _>IhQD`-A96ZG|l|% I^TD01 A` $VEA[SOܞ}X[=so{퐉&Җ 3P;aMTUu&G J7ܗ 6]:U&"):m:I~ۑ3&PӇf pf' A|uyɑ iDCt4由M|JRszZxNxf|X"t*.AW/D7xDiy6~H?db=#sclya|Iq`=-QPk@jE Ӧ?^A.̉KƳ/u yWS3$~V:6~fZ/Z!iW>F3vN)͑Y@DY@'0p>o4)!Dh$ǂF.AO}cGDi[C؃@$Kd|MxVFĂ!̢`f"Q(3ʽh]y: hPQMdIcfu ٽNv2h@Tf,|7+J N6+c&c4\0kMip '9_aX,yή&;_BS!Qp?.3RLGwc`4K∷=l{c9!FiG5cV#lѯl ^O7CN./k4_vj,tQmxe@ zqDr\#AK2r{Qq9|y8fh' N`;E :J.ίv}vG !'G w6euu;*>(iNdze+H14bGo}yqmPL@+"`*"tWM&WOy/mkK4~Zi‘e/ 4ORȻYPAz֞-QthzݍlNcˇb/BnגWQ[MfޘZV8*o#t>ꁺN?NTUd[YL~ ff~:(%tsb2yojܖ<.@`-e/ 7ݡBxR M  8Mo46h/n"hMښyZ7UEE.sLoluy)}KMCl&pL /d{lS} uEit)ڽ8+H%{r$шv}TXB`y#=΀/;T$b0iw@'|gr\2|K&~_b_G t蟥\@Γ-c\oy{ii䉢JN\-":*Uʮ7HO$}BeNzy0}:o\= JJN&E;׏M=M)9X"NQG #/,aLO w[pTunk 81c#EhHrHr+@tޔW[zX>uDNOHn{)w$(%fxdp[ޥH5߽9ՕǿǒETZDpzueX3$<>˪bI#Gi EӲp\`&c/ZٛȷB+pyﻪk͗`~{Ǽg{cszL}&ҚR},ܶwrEF׀J CpGvPxU)MqQsfX[/^кh7Ҁ:$~>br bv-%$"\·m,٧YbF|P9_K^S{ gR9V2+8,IwXW' ߏ34&s:5eL!u% ~ֆg`* 3ڑjeM4oh@ElUqVX6G682n tΝpAemL0Nrkr}7;6>[9s߰pf6}CLteHBWŵ-$:dkT(T:{xIlv-M 0/JWI]]Dԧn YԜ"9ĞSY=q*{g՚hd:,_ϛ.1v"jn7hU -?"^h+fso>Rsܺ/KOj4=K-AoiZ~*Oo-7ԣx+Rk,"tda1H%ίw3{#;Io8I9-V?ЊSgnx`k,|_赸"J<ʧ܅)pWH⯪btN[m(|Tҳ{x:(|ݤl͟3)pҾyVѠɕ2"h ^(EaXE\ڍN!cCZd%Rʜ!d?dՈBq/Vᕒ)<ԏ"L$ۺVoM|/vY_kM2U~aj~Ҝ~ ׫U(rB5<"Bğhrԝ.a߬ʱ/(gۻ٫O7ǒZxig]- ̜ G(9RקkaVv|>1yR`:ل7( ϐGZO,,$+;Fѧe82| =A ~tӥ'2? s"a.㋴I3c.GTQZ  Gqb.(|ub s7߾وޅW]6 uNOCJұ'K9~U\:uip 1w1"¬2ĻB!|ñՎ0<Ƴ#ߘ'%2ĵ *5rC@)/; t[E$$eX8Q#2W!26~,*-,-_NFsh<Fۭ3hY[?EQT\6"xG',W:F$I C!Dwo< _:2_:r&+fp{zhvv,UBߓlqLJմGIƑڎ3I]s)YAAQ Uc#A$pfkne)bޏX[bit(zk !A^t~9H:a_"ĽON$aNH Q6\oX[Na'- t1͠{_6&: Oɮ!;Z|Ec=|$j>QPWl'kp8kt`B09lABDMiG{> ,r iM4|q wn'|V2ɚ+7+[y"oh1WcO?)qJP Mƛ@Ji?Y}U gq5?U6i^tmX/*H ܂h~_*<}H|ڥph4ƏGBЂ]z +҄?rhh}d!4|0pJԘ2GtdЛfsXQ%Z F^T|N8^Z5#/RZf)Ęs=tR|^91/+~=V0` 9Du1Yed&4ŗlK{0ΰ ח1:Nwdcksx^j>ͽ'@ƒ|sZ|t B*:_ZCxHyH@ԛ!F5|1jg;!-:? (Ar{׸}:B170bЛ:Pw-C1G3¸ -nvbF_83mpsI(zubRN /WSӭL &r$R")m_OKdN1!=Ծ>#70L9^HnވߎN93AȹsFֳR{X,E*!J&c7?౎ANfu[˒/G#;#QuFW]thN:+^֖H?h[sf2vgS1tDu#jcy7ly0O:}}HlSϽ&7ts: &/9R7;QAZ6wJXBubȡ&6#@Bkh<|z}YOmxnQ 9whw\sT<k!NJ=uI[Ƨ` Jt*]sD۵Ջ ŖEpqZ ^n?TBeb:Nlλ-kc|mHɋk}Vcil(Tn wg@ Rt]Ohs]JqHXK`BWbJ}TrVK_4-JeI+4oV~R6a{ړhM#ۆkW%|oa KQ$qTh{rQ-wG9R6eHpAf#ʴL6MqQe؊uz3rܟFO2LR8z;W+spʏ8OԢ In 䙻FET;^+;e<"p鞽<3Et"T܂I㗜?]/%!r'&~-vf8`s I^jP[&սc`D |嶓:szWeOaXɄakepk TMޙb+l2k yB8wJ2-ʷ"X`G,$Q]:E7(JY8S^[ً-qc8dqD֐l6٣?@}K8qiߥzO:Lm {bڼl,!vw}T&0ݚ/X-7xu1/$Ȃ\.)Ƴ9|'vL}MKq#lȵ,l`#qXj$bK*y)]SxH4#=po]XlOg,[| ]qM yF8^Y3L!T;ƙ<2x+' *+bMkm=PJ^䵫ɵ9:Y>dr ,0Nn~,ZN9X/ #;/5/9W`9~Hva햣}@3V~f).1s&CnY L=m3Rt]Y@K͕ ! ԗ~!oqb"\rn@f`D4E6By/ 9=N0$?@ }5Њi k;1ӊ$H0:S]uoDmJ;k.蚮{Yy/J WAnkrw2mq++_weX( mjiS]^Hx-CHE ,]Q`_@"J6 l"kTf ۄ0'cj'N?l#u[;aoh<ρ3cOTeS9:z`+y%D`E8jUc@R2k%)ek(=~/Ȏ)豝edU +|XCp(܃B:0MjVgI;9ТHoeAP}M.tI,?+RzH[}]{"ܸ|k WPKG~_+&`mo0*+ڛ$cHȰS%skyPL#LD}FtsH2)z[&m:5g ʊ_~6/6L,%| nWI]A_קXvo8L67'#/U;s/éĸC\jY~,W܄UQ.]qcDOHU9."^+u"EDqDŽ ֛f3 Њ'ͥ? ɌNu~ h^wb8ʕ]VЭN^6rb}Htp<0v/gBa*'cl'N5яU\ͲAHb3vq⑌G?0)2׼J@GAv~ag@B+]ti6Ó@;%pWO4/L TZ uLq~yn}߁?r"DBEm +$ٙ f/8Xw?||rh)*f$8R@~IνϷy#*.wR*`%X ȨCL(zL1󵪄:d J$NtW]=#܂S;= [j=Uk\w(:E'AX3`LJYs3u8ߥ|;fS. 3ziG 2*u(ctϭ]]TIÞ<, N&C{(Li9[s3cϬF*ɧfؐY gc^u 55M39 %ܽ0θVYx履%hWcxRぺׇE}yKFfEA![F2w e@u@ =M Ʈ}[ X|6ܷx K U_ɥ3P6qNP`zKA~Y,#lgb4c6S1yN|%^Vi302f2ԯ{cACygt8?麥?PG B~$`[CҵpNlA>)0 6BpW "uT;')#Y`<e%z, 'Okl5,w显ٮ"IhĊv_fm.7\KLi\<5DNXsxRIGU]4U;/C+Ubfv"s vݗGl}nX΅\n&RdahNb$Wʁz_L?;@hjwg$`y춣i%]m{vt\ 3@LON7;k } rU#$G:G ]<ɚߋKWxXJJ*WŷUc[SL uժ\?(m~E cMWۑe)|߻CuW6 s7෠˞Vp`eĦH`d / RYM;DW29Pu]'aNN cV=rxs&Q\α:#g. hHxhJfhw$9{¨(϶oΤT:ݍpVe㱗CnL(A{X)%J{g 3z|UAif 랚d>G0b^ ^ΑDD d .f5ZQDOi`GM^wީUFd>Vcؚ.p0|=g/qw+1JI#ەe/x*M 9Ã]"`ސp٠)Ozrf$?qf B2QF9m*![6`KUOY|ǍGMyBa$/!3g6M897y \TLC_ m}LE[p/_tj&uٚeC?&G<L}RsG`[)ލ$rSһo3zSjHy M:wIxgG!ІGx*$STs/bC{sw`a#)YOCad?˓ +1Yhˣ)oA[]7P]$ҥ߷=:`aJ} XG$7e]Qٔ 9ʤQ-2/8z!٬Qľ)3) *x9$LL +@!JYHsSі-So{ƬwLi5B*UY.ٞۆCiLƮmyAYٶj;OCג6so=UU+hSWMîGV!.yf.Fعy_֗t';rD@͖52 [Z}P!arޘ6w+>õmpe|*TbBKzʰxe18V*)*9ޛ%տr݈"ckv)5E27 $3];_-{D;t$9&M׮Y|)^v86v諻<6cWѤ%jhi-|$sMSM]GFl|50; c6k$\DgX\R 2,,\lk؁4Y½K/ ⲉ9 JI#NT&ѥ$ ?)sp_HU;&jztSPXԴ8r}XVp-a/Y]ƫ{vRu"yg'$(^d0/9(1IUSW_m} g _Lu9 SV/AlHXu ؕpkg>R.ᤝ?l| c+Z &>2eBsܦZDZvy\r0u$iVqU/,(Qxl׋֡\W06O*j=wf9d>:.kZKmL5nUʭHHS*%{E%Կ[;D#RRrՋHwB ;#GWl8k슆M+RWv뺲7NSVd҄(6;xjh@ {/D>G2,~C_ MfP AX%׼{![(#]Ó,\$yԉT+ɌSjt<3y ,t6%t7W%mZ38UMS-@PϸKC56vcP}SauL=m7:w{CaKeH-<][RlB ƙvCDr-v\ܓ3M:k{ &p43K#6lX C'$a:`pO*.giv>?f^4s)FQ6UnZpN{@M63d(\-5Iu./ SE`Ǣ`Om/!u,#DMI(+M%ZyM2ol@\)(Aas0Ņ!T @LR]`ff4\e{6s@ߠ3u,?z\'BF\א?ao$$3YPESo Kp+m#E򯗴Pd50y7Q4OE#jn~S3w;K-ddU/8SXTYVvgL7O[S76^K1i?7CfeGіca&I*ф׻rn z)1d+ؠwnɮQ ,%%$SOPA^e`Z(NK\lv)Ød5`|^5vm6~+Ü"?ywUڋnƣW,srǥ &gE9w\:grU_K H sg*V*.~\KUҼJq/,2|eѡ;caN?F19⮁>Ok%;E~Apy[ 9 S0hJx`q@R|dOu'}=^p)J}]F E%86O19Q)vVo/3`ؼZ>z-1}|(ـd|qG)?(j-ek&_D+R&<ݡŪ$JPP`zѤ~.`rW ƞG0iLֹ͈%zFMYK܃1ڌӐxJ&hF:I80|i:VrfksRnvFI%K_ :/~S2Fv`RD[>yጢ.v&!Q~G!&; _( 쳪U 5#FޙȪ"Ee>6]дWc?VϳaF3NȖ)H%3k|:0THʪ@Bx]ƊXmTo}4t$`>vtCJj1RKOUhE 3TdiB@ >HXa{c<֥R=o'Q8M^%(b@V2<ā4t泍 2ഃ-YI#'HރMIf>kܤI-a*!7slYv[x:א[q\hqXq \lidߙKWK|C`0 Vf1d[?8Ջ`R5ff#bYZ:{02xx8VvE\Y Eh`n} l Bi F*#!  WyZ3[ƠPI40(~tj%l"z؎.F}r Fr,j d4ʥ尃S['T[;'7A*xoP6˜]f`gp;TNdm_p{{I/xĞKj| u=(h1ΦƬm2ÃG+2N`j6 $^hRڇIMW B {U#_0xc:LLj/sHT']3OqD5XKlMт+l7u>*! ""x mH|ݾͼ!ܛ:k}D =m34G G0&[ k 閻պ]-T!-jXmze䴠ވ^ B 77;Cy0ۿA$1"X?fD=NH5{ܠh ۉI~@7aUh 4[A̬)7E%WwQ?WqmT죆ukXUMf#0fot*āoi 9TXֽ㬸U+{-\< AL0Q+e) ˙]`8OLboiLoi~B+xK(ґ] ^?3U fo,~ +?Mk"-? .yT0ʿ(d|Wذ&'82eHNjG9YH)@q=g( uѡǏ4Rw^܆&`l'kҥ($q]~$sUJI c2<+qWfm`wlJs3nM R@dױ"̷587J?k~݅6ಜ_cWy1VUmU@țyp8mA"^B>wL%wA jRD6@P՟q` n ?&N'a,:< -\]~15J󀯪4ea%5>6$xa) TJ=M7GUoZEځĐ]/ )PqMdyR,r"9x.fA?H-^ X'w+;q{PN1*|NYRթ+K%NK ?9Aܣ\4[2X%|e<4t ,ՑMS?&{4YZ>%) %3fAgLNԝ6^(TnjuEh v Z_ aH<22}ĢK@nvZdY`@ĕ7}/zna Y.l_/^'`\cџ^ɏ&Xg[>f6މl/ud@w]TzkwFsiĖ);8ή+=4Wȼ~۴kiRP)yiԡRy F;?55~pEJViCyY^#1U)߿_nbbMG,'2 Ptd$Xܡj_6ܛC$I09썼1zZT ǂ,`=߱gbHUQs/J;8!'ƒŰ+l9Uif?4#~=${I2Öw}%K~L9rҞ6`0fj8D:kim,1訠phguf[ut 6{w,f'Ӕubjo([!*(o*lgOcܓ1 Ycp 0c n5JkLեwtgLd7Qi!R`r{,\ɤ; LjAW-Ԋ.e|dOKq{r klӒ}+]e60 ̋;IP!])NFӻɫGU,bsȢ\ R(N'oX%k>0k 7ԙ',d7](AIxGυ>LQM~IC'z^:^R'|Z85vh!D"Apre7[[7i/ZdXa@4hN@n!_ZwMTKL7T>JQ[|/'Qݓ!T)>9#Ssٮ \,TnW3$gA~-d^kRT5Aӵ:bz}v+de0({I`A#env?2Or蒮,'sI]xIE`6)xK|iƅW6 Cq]dWPCQFw',(wi>?mW-n{vGj<+}6AǠ[}BXb9ŅDz\LйsŏGtl3ˡ-{ZE#D98k- VRsUjHi ڿLyL ?x}@C?^lgA$M{6=U (GMisˑG"XK4}ZIqJ 1q+VƻF`S]&S#cr[YP?P1LJJn⻮vrwBEuY@ё1XDCx/AwqDRvL&rHQ%=/`HُkeR걸׃ٞm -Lp"g[:pӵ yV2.j3^V~gJxf)f(4|sN'2۹&I*B9c,Ѭ! ,^;[5CM8o*/sj4gؿ<3u9(:~9"oo8Un3RWV_=5|C"B݅EdAC`zgy':"o'WܿC󺅱\N>dm!)ED xGQQ0˜'[(ǧpqwro$z` nGly&s\l !>a|UxmZ. uz4|WK@ OqE V|AħTضy(Fd|]fA]|FĶy]WZ,@lPU ˃oʖq:/ pg`!2 &yp} X /QFRrc䚳>%+c+DNj4mk}6Zj,K8H漋tJ] c Ŋ} y9zZ8=ʚ"BQ>Q4 ,c6mOFAҸ!d-v݆ۯdi{]Z5KBѫ%ɜx\9 &Ӣyan0{r¼u1IfG! 0EA4_M2t##|]Ha) 3{vQpßgTzK~ԓT-m`\G۴RLkslJj7bDRua*L}k#nj;>*ujbl`) lh1dkzA S̞cAp,eEz=KeXɚd*xr3kdY7OP+8kטGo R )|dfx|gVNQ˿]^6%r}X+CɺRW`Ata5nGPSI(BBv7 z-E҈#e3M]&H}ISp=2+ƍf_uAJxsHx/$p?"Ҝ6'[ L=ւNe?[.+ђz)޾ ;?D_R}6:dC]Unxl,VE@Oה976$u~HUIo&C2R?_ W\uU:AXS ׀6#H1Uxe8(c-f[+}Ahq0ABKPQbƗi4Q/m6;#,/- $B2ԇJgCB5oĵ1[MDSz43ݾ<2W1EL~YpQ>6z(GG\fD#NNWԬ"o 6DW-PXcE/{8nyk_Ex9|(&YuοUhG_^)M G˴Ȣ=/ӡ 9:|V s7KAiηw2{0MYƂڥA'䠘߸S[pVR 7ξkt6 ?O$8}:oW`-\_ctI(IpDIJ9ߞs8dvgdL 6)ý²ݢ'lFcճt8r>fR$Z"kYRWֳ-8|XKC{~Q:HC7SPyQ@)oa`,j2짜1& 2b Dax]åhd-%0Xfze} n.W6|<' ޿UT5q,7<``ajQr5^tPIwnC݉QY=jbk-D[NeWfpq,X;{-R8tgW񿔊˃1 y7vm4,x$oܦ9eAE\ZvIwz 1!}hZ)EV#ǶwLoTcdfmu_nuI2bOkIk䜷SR00>t9݉ȃ ;EN~+xC)le&Ak/cϒG!(υ3M:$7$P^o3 X޵L߶IL;ktv`ڒ1[q;"]Fi[p67"PW i< `S!p((GsAigQ]Wz~E*Mgo_gFf#p ;-NM5 NaC 7,(0ݹ &a^Oô`~MyMpWZRf"q:^.2U{nrLXm^8{S%N&ı4Y3xY;FʩK%-[*ҡ >b6={dJX&##_U#G1"iO䲷IJDdW$M4q68* >DZ{ ! '7#(! <!yt^5}N=P\,!ׯqjuXxC7y*,ͷKsaD%l3I[!i2'[ >F~m:3ݾIA9]'W1PDY X>SqϏrXuUU|o[ 8x^1P}zHx+f 't_Zȡ 6lt A7)+8 (Z,xQ6uz|GdXo$FRU7bd>m^] gbdb(B]3Hꀉguٛ ܊-Ǫ8 .[J0͜a0sEGsm# ׮AugЀr2U.bչ ׵A>J2O Z4PI$<1١7&n,ts4$W@P yc0w,:y@k!g @@Q$@}JNۇϙ~5}uRFVtx `*HT̈>7(H-sIQ"h n’h "_8 8H HvmPP9\Ɇo14Ņ#;%qead+'HcPvziYJd2f .~aq2$ӲS}]jֳFgTsu@~V>TGArӵ"D9 e VCYa R4:Ιh)9/hF9SWgVDq?+~BѶ':׳DVf"jD/ok/tؐ'kFG.q["nm_"쫽d+ z*`LɅoZYk YIG" / ~*eA;Wĵ.c:kbRA6^xڃpJ>jkkyaݐk}fa[;-2v}c+SvqG FVzXs]׸w[=ӥ|ΕA/zIV QlAqNZ.b㍎svG O;羌ʲ:}҂EWES&3T/"HɳKU(@ |g?FSъۜܕW0;0PmD&/-ݱ8 n{YX$r- jلHvPF#of_YbTv;r̶zBWY׫]<. <@Q>u΀NC.Bម=}&ǠǟC$: xV4` O(J L)[`N)]b,PqBOc#[:&ڒX,HSxЇT6"mWruqɡܚ·v RMpn=qzCwku^Mq:hv.I+wW'}hg؎5 QJvv?,J6\61y<_,QNV$$dۤvSƜV0}ʶN; @b㬝Jq̓~}21d a#;^$E:ݤTLeFQ d nhQ V*k^bU3Q *gv1Gu.t"RV3,FGv*zzagƁ)?jVҥ*Hڄ,B^rvnha˷;p^R|}U~_Ⱥ!å~Wto崉aC1y&rˮ -?BY& goLrl`Uy W.kJ5t\6eckK=yiQj_q$`Ĺt - c}q~;$H[T#˩&wq'מ?mf~/ХnY(ec-xm*j=61.}!s}*r).g kTS%*ֈr [BypZ1sG%ulv r-xa_HҜ{L:i '~lӿ2Ʌim_# 2FBv EsRouh6'SפK к b cӋ eagY !ذ+|Y BP,aU\{5[NNtЃQ`}Z`g7Yk:Hg k:qػQn/`~"Ђo2AZpX녈V^?iS3|tۉ)w?l2rgpsPw6R &O cDosneECa4aDw wU{O!z@%Fb1 N*Nuђ2?sqcN4^usߟ ńj(KHiIO$yH'OtM/Z䥾o"[8NQRTHZ[c=~ 0ToBUNo`ުjш*%9LI/u?c=` ̞,Қ4ǧ)hEL{BĆ!enDYA̵&egF>zm3cLۼ򶗢A4)%F/mX2z?ƣF$S q"<lJ"SNS+QW 'dN'W t_-3TrT~rZ[xr֪&OApݙӺx'.Pl{ g$<Uw z pй5˼ֻxJ͌vXɆ/7L(:?yl^1SY$BPc򁈋6HXLWfŎ ge ͆ҁdwv\p Ӽ>$BEv$q59<';"_n87p*e N̷h=IRXZs;g,| eH ݽT=Cb|`=-&Kxnlf]v?V*Eȣ'^ÿg5׷@bLT;਷R2 2ƴHpBRI"L\XE$?|/Puehp1POARpQn,Aw N5Cn@~ 5y2L f1:}^AR@3<yjMiH/$tx^k]+Oه Fkf$OubR6 =۴bƸ+*&_'뤵I "<87[i </21WnW)8l{U—F@(T3ث; HN2_`qscQP#^i Z֋8K2< oVؠ0x e%YSnJGoDvfEK[hTz3gqq0 K}kO±b4TKP9gl?3jn&n. 2/3h|3:%Jxf;7ۣ2qE5h1 Ʒh=TՑ(f7b/qG97#!FQ'$YpWF/0{Jrmiܔ3D۲{R2WŎ?;I=ȏ`  ~ge`G4 }+ҥ*fhfƔXHeEaԹ\/N_yip2Q yFa](čuz\Ӧ{RRI۠ӭD\3`@{d[i x~5ٿGĢ+2 mJ7Yd=$䎪E`bk߁;$AV˜野-0( 5ڊL^-R;#*R ? )۾N#xڻ S/T 7*:z|;nCa@܍_YcFICW- zy3٫x!1B8I_1%-і48lG&ڰBӏ@WpD&;ooLEtv5B.iK b+ Y:GM}E{ӠV-GZDeG@~T"}\w+qnJ}D-/BY]+Q*@Dsy>* N]-$M%`2!:La,R@B6||métɎxۣs::7٩b0gI¢^ v?8Hn5M(+fZ!'mLܝNTs/ײ" 6`[,ᣳB̹285jOe%p@fM {D g t{u^V"ᶚdtvO}zQaHE3eGBG"GQx:I(R]عh6 ӡlFٔ6DDEͰr,RЋMdQei;&wnOo0FRsRv<aΖq \ HS l{7 p"f7FF`5ݧ5KA59Q8 -]}ׂ'uy#TS6 ٚ.3TrK8`*lǪ A1f:[0n;UTLkV3;3^uqeQ0L@X%Bͤ@}%ڑ!1䜐}. 75Ü~#9ީRwjYQO.Q~4(!74'% F( R;$ufAg4'.NoI_vYH1%l&*<,pyR S Q3gMk\]JS#oiOSǢKyjsJaN ŤT*X'dwx\⽀rpDH.e<_+za6XR^ ǿ-;9Gmwp9_ȇ:$6 _,\ l?cJn ЧYp9\vy8z\KZ% l(ێ7w~ hd0\^?G)|mq%Idl)?UTE@~­~sT YdoԊEC/zMˌg;vaa2i(~*>ILW)ycsu~J&n tk2F>z2^}BXKL옕*٧N͇"|:Ĥ?'UMZ8:,BEA7ئ"@fYcBN~B#ׂeࡃMQjӐ >֩E0x$T y\KKxDe)Emng4T8覸O3"|4b e {d n7` z*;ZҞi!=qAsK^HPw}V  Kd=MůԵϰHv E Rۢic7tOMi3x ?V8V^`@t{ÛOXUlNyQ_Q0 ]lx/؞2JA3w:2]]/]s5gZakڏ_u_HaK}y9r@_$\N+ʚ`ˋ3+F:|Kh4{hkWt]o5E*CRv㲠/WGՠ#,1~-纮mlQ}ì?']Å\isbJe+w7%A(P~~Z\qfFl\k/Nec"3meT\FU_TnhbioW>d#6V4RaOrSo_[6jop8,H' 5˖{0(, Wx[Z|¯5βq,=HY2#*nlH7QL/"(,I18 <&_lp|+_ȯi]=aSQ xmUF%,םbWB"~ʊ)E=# wVS'Ր7wT/e$gs5al[wEH;˳O3`2dß?In ѐ7&Gs !ZގfGi؋jGPiK;Q42SY#Kyb5<*Ey-ACڵGOwoZ0JCHƯCC+erk xQhdēI|Qǧ[߬fq1a9f;orG V#te~G-d7-S&9ٳ$֍NyM%̏*i? 7`WF#@1؄4O1路A׎ !}Ύ*[&$l7}en"(W'Kiq ֡_meHu=M͗2;sPuZJw0/%׵P=ғKKOldwu_,{;[UBs CoS ^F7׀h8)x`R2/ֻ_ݹ\C6) {f W\熯}׉OKe3`'M`Q^.26Wv ijIӌgH;5gڝY[٠btه @Q 4˸/*pk?BNy3p zLYcyQƍ!e_I7La hhQstKx @KD֨*.b \t "`vLc#28RயiVL8*+)4^\C>\k Lah+UHSuycŶ3*?:Elf̾bJ鬯$<愜ЍŒ.Ȓt^ԛC$K_YioVd,{(EV]:;S*I)txS8@"ߌcDūE!bKQH»DgI?se hm~ 7 n Yd02r$0/O`̐`enWqMt& *.lVe"2eyo Зh@[Oe+x=cD_mubr[žhD¢{]>xg$/@Kdxyz`blL|.$@fNeZE,$q$Ԗ+Db1M@adI,X/Hn{liѠ3ۆeum'L *7&qYǪ&vh{ʉpuW iª"ȿONsqrPEv+ɴf~?AI%'p@̘d$Hq'NxФS*.rדR6O~ "W FkMnW:'z< `G%!Mv{|1feX G_ D|,{]hK|_,:"hQJhDA_kO_#gk7q OZ)0$7OޚUOu1=̶ wr3hęni=ڪ/]oQ e1i:l`OqJm7$y:1ˡaNLEE 1͙G}$9rb=N_5Q*{-hN7>gIzʂ dv%qկg3'BiNWRTYu'd/64zX+dHWV> ҇*01= } &$I'E"6 ~bmBa(_~%hx켏",kA5E[,(h}8D?5R8-Ec l5N_ԋ*v|gAF_9gG*nf]ҀSV(عkbqApBRTR"06an0xS6s % vepU*6AX:͆6#sj0ԟ6iA]l)mQ%/+^V3ťr /eFy-Xo(;Jֱ+m7$xw12o`&U*7<|Dxy>+HDZ~iVA{ ',w\0yQWp8bh@>:3yzhjX>> HRe.0&Nq/QaW֟K:r[H!2gjgZ0o+y Ղ5d xv**t6-d?OvCˁ1m%|<!"҅;P.c h.._ cK"0"at9&bXLo&X}S hav)KI0ТG-9E~a.# Mz,/ޙ Iw]%(Se-' 4U^FEKo96 < Ꭿ532"* o.\zH21L:J slz&E8gIan`݅PqPԴ(?n%뜚ɣZZO۵2A- J`T7?v?` W_bChU@(#{jё 0Rg3ЯJ?\T Roqϟ}lM?kB1e-N}Ys\p WhEV}Dn'*+ .n[]G>Y3 Q8=i'bP$ OWZʗ\meF$,Ub.k5|i&U'W৶Ai*^wXH6=1Ob0"n*.*'Z9m.OT6 UiydhX=i?*=Vbp"e) ?rĂO+3 )6aw8AѼ6v\gC{+ԀKȓޟE5??͏ƬR+B?KK#e:+)=8w>IY3H3Pc'EP06%3 M.Ix! Dp%.)[';f:|&@o`/; pohsm:[OW~4:{!z5d'stK:ӕ_έj{M%g5ՈH;L?Li[sGGCÏg&(̒SMg9rJkr zіP;KYy5؞*vŜR[~506 h2*Vi-}yo-_?dB)e}kEu|[P-Yt5LB8 ~IU.!*8_.@jTsam,)| e|P>)$mQ/Tj[xvÅsW^kB{R%v#x,V&͛P1H ۱$Ǒvh4AwT3s ]7^acC1Ҥ̥ʾH,h|a%wm'4'݁w)'΃1 EyI@ 4&Luݥ דeVfi?6%^QhHA C0`SKtWa]|Ý lR)?K*f$nD\n+u ?(O$WP9B@UĹU4_/tE0‚ւRl4yvVPZ=0$hQoQL13OXTucoyMŠs eUeS~hj:)Z GK\B zZخ^ˁ(4ǦrvgKs3G#v#iLJ_0\c s`2ǒBk2UR~:Uйm{ȓ l9]6hd-ò-3򫡐S.6E+FF*vCg1EDN+dP :q`v+]bdh5O)h߆E30;(N|i2fMJ\Pr< \Fz :X/N.#jY/gl_D3 DY޹n-wh411x(XuO"SE̵^>2 cNohP`lwثxm]P.D#l4^j$ 9$r^"H].- P%q<^$()XjtWYޞ_`y: %#jޮ4>6]lj@9|)΃܁1elCislta~ !CXD1;,:u6N[ $ј*^^n?º?l @^+zɭv O3a\^˨c0^]Q_N|갳&"xE>Q0L\.a!,g.g 9ls^98_~iakw@g;>S߹gPIfnU('RlsjSbBNaS-BH.r`h5)w_Bs??6Ƀv?y+WgCSg >Aƙ68(C{Da0ɸݘZ-L<bN32rdܷNg$Gf\dGDLDdɻY~: ]nu.nn_E6,/H&LEH;-/y6|"شP n[sCj"p=xAn:]QJ8hl,~0$Y[e[ls 8D;m$n ޒE%Xgn\x;θ` \9xbhU&%KVpXHRB7tƋ%5e<]gZ4ftծzW L-- Y@t$E}&_K6:|'ǝh"vx${B|J·S$X/-&wi%lmewu'buçFP%T|8xEGj^-,@Oݵ8W?2H@Xo"#7n[Kg1H*H#ٲ' `7{0[ik*Y4ŌI2 T87DUmOgV&L>𪳗bn|ab~aS0F ?kmgYdձ7M;UAkt4dh`6KZ{pƖ=T5,nXVNsyJ&_>e@2I{MYXSP @{Yi|1 Q J m%bY2bWSaI`XiM;Nՙ?Me1 ~.aJ~y=Ozm_KEރraQ&&re؁44U4c3R,+N e[`6VxW%%IRic2:~53H%]Nxۺ3~˥2έ2I dkwlB-SCa_\rVf[btBɼ$XI22etQ&7ƔB/f]~ Y\h ;@Y5$w;(ۋљ\t>cs Gro~߮T'|ㄐaah[2]Ո…gkxRcS}8MO+O|P7Pf{N.ѠijNŸUnf8ƭ :1LqNr`M x_"5 3zI_1sB,=Ϟ{eM 4r+R[JssϥO)B++,v`}/GFj>3@u[pԋ*S[PkT#bWq({(8T"N,pMx C;w>b>&9 θ+XKsQ4."p !~a\j&R[p; MS*;2P%_5ʆlcAvuj #7x+HM;OgN3rqrR(f srj7*c)k'q$vV.PCL `yao^<eP#P)|/bLԽ<- N=ltDm|ܚ{GIa8 Y_cdHO.98Yd8-apiSZb׌qaL J>kA%D/IuE8KSO}86 iYFW`͂vP܌>ȸ-C㋸u޵#35CGZ8r_XG3 _V ;t7**3P%%*(X= hS 3WOLMBΣULv-Se{'MA$ huv!69JOj-"6~,9ju3*58"LpKr3{bIPmqpg7tEN($/zvD3v+l#)RK[dNG W+9iW}d. oE]_>~w͹VeCop_B[pi$ ~^7n$8}A4S,lVaQ8ڿtQ|4 ?4"d5ogjJ8.yP ?ZKחwD[e]М)"Cß1Sd<&۫suFw1'$_07ѪXoݨaC? U1x#GϪZFskuo Z1Gw_h,lgVmو.O0QYA΢?nZLNFL#[E4M^Jb+SELƴ'h6qXXޘf-&8Bn;LO90h6͋AWV }7f[-.N&tz:4~h6Jmw|wm?Ǹ5PhӈD=macC&)N dXhC&k 0>McJ׸Cp|JOpojI3Q2G ddv.$"(sk98EwKmoЫؓ aI|urb+6 .NNfZD &$*$E (eѢU zX3S<)Z:灒3Bc]])F|P!nLԆ#f] t<M©Kw>U&$ǒLXI;,ZVϑW@{ d|LhleUffHAGengd9zJlxO%Mƛ݇\{:`X(3Dm3:=c{wZ(An#XhHU7 zEP=[S7G$a>CJ:'C5c]TK9@F.RwJ76#:t9_nhuVd pqP~o(`qڝJd Tl0QO= XCVW '}?MϨU rWTeUB#K8-TbU`` 05g j+ QJIcT94|3#.^.,Y)>.m"E(7d:>荨q__a;Z #\,}gEhz#4D;9wh+| oo}Y2Փ׍uBhJ6˲B(26Qk@}6c¡H`(veò=ښ#٘'jBdZ^a|B?>:8u8k/EzV7u5!#}t \rrZ*A6W`ݐ BMZ]wU]n8dK,l'%S$EoF3;h&qq^GzId ,TI6CSkû*݈$f@^+!{;QO2\H.rowB]8d$zrU\N Ye1:Y\"C#DbPFLі|WCz1&d܅Z.KWRR%j8g#'r>wQu篁懄oACYoXy2>CW3znjY8B> UCPM@d6m8{K̉8%s N?zv yg>*fqdͻi-D//b+nx&O(  D>6Y_%FlmمRP?Ğ!Q Xު璨{L$qaK=ԭlE%y F=F!L*rnSFڷf*0^8rN  AJ؂^^_L$UIAA (8aNRD;fhEjXBJn~dN!kX7OA_lj\ 6J2]{ Sh^th&GhV~L'ɐ6#r @H!'zӕyR<)b/Rx|An^^>j܋!RemK @wטߎ+{Zo UTAC430T /'ŠMxcx~>mt5o?Nri竎\xw9zӆp8*#r൞T$mT)+7,:9KDz>a3o{(ae} Xl9{eLi0w ,y}9 YI Y9âիdCi:^bn٬@ٝXEzJwzg]@PrhuZ WX VkydWWxk4]e$-Ii6sT$q2I_=#vB+ŹF۽纹;}̿˧nCϦLW=h릉 6VK)b:AO(C?J}ʧ|NҶ63.vY1т-ۺ)3" z>c x WOyӍ7u~`.oOD_$ NWg{&@ʅqYr1Q6r<!πWO.-_]x3YѕV_񾳐A6_;j1 #.BFw Pau[ L{.Վ)15;/'ZϠV?A\-Ad ^Ab` ŞP{"myI;܈3DR:QKVL=xFi ,[Xg>80"''87#ѠRfmE~-eݰt0~ۅ@(Cbx{6)4Dᄴ0nJ`. ,(aT6&6c=ˑl\ExyOM%w+3RxQn߀S@1{ã!Ñ&e f;G>LЎUq ~MlvJJ{'p2EMe8g{߆h9Lѻ <36Xj[L~"-A'ɽF`KQa`5B (&J!k ?+n!BqJL&m"O)$ezZ0nd{H_&J>񝄥>oqeؼ+Sҕy}lWbvjL{7nKڬE($OޟjIgܽ }>>Z+6UDɿ]tKOWf+?a/FU,JU}bdH572;")X"FPM q)Yg'ku'aTyo~aFJDQb~.j.%fNbIIxl8=dK*n-O>!8k{<\ÀP\iaɕ jwm_ m[M:oكD R~YGO10fVKZ>:FA,s('E3'rd>wă4CcJ2F&pf2u@Bon􂺶k G!&!M"-h[2%tEGɌh+xcg?oo(1n;mQQn fr0q~8 u q>"!"Jda>t41Ch'儵q;oMƄ#baG e$9 (upW14k@& 8G ij60`a]LUTuD=­o'&?f%CMڸ6}q"5Nr~f6NAR RDΓlHWy֧Ph 5aDO?&utF_^zH_1Ŏ] ,Z츶l:}i7+Ꮃ#rOul67ֲ?$xSrFf4/k!㋦xwĀ@+[ZerV.5 e;;8|*0 a-H%|Р'IEqD<br}m&7$zS_tqY3Leȑ']et1&ɀNJ zI1 ϲ /3(gni 1XnJ$o#!I\w'}\\ɾ dLoD1{N0A uPĵ\ R*^dǮDO-x코-U^lFeg}-c4(+@~Ct]\FO0xRywTGbQM{5vD6`kW"y(J#b Õ >U߭afCoCJC #P= wzˋ,BZ<=3l 2- ^RYZ_x`*WWa~|(̑ޥz( Hhlhfy콍 WU \?ꑮӎDLz]dYzM)*EebLp^| 1 HeP >/X[:vmJl۪@la5n(±~Ż[ioB:U%$?8nY2"WwHw8[T':{X]guAz@ SIyKgwԐy֘̿dUjiGj b 7gD}8{ ip~R2ܵ$h$tR+u)@ ]=+=߇x/lNS~QܰL]:҅N6NGM<Ɉ*f%|ܠޙYBJo`1T0L+`Iyi8^ @kIMYԟ 9sYrDnXiRN$E!eѫtg3$1{Dein}jv)GW#ٜ)No.QKL"!w%'ovhZƇ@ )kn̤%#er/߿)w'x.X&`:}+&ܶ —O"pWpMueA}{{|;HDSʢKq?k~ySz6^ﱸB+A߁O7kkbYS5ŹJqXV菀zjތV=\ʹMmDWV槣:^ mV%Vm+H؊jw C2ǺWl8PSt9k uNxX{c 6+~r`%'&R{+CqЀ6W9>3eMXu!(3@;5qNI7̫f\8TjВ(]j4\w8DmI[CaE<:׎͟\4STP]L պN]؎R`Ń %#ײD 9<|"5 v(>J_A ó(w^跔ZQll>;;dI]H9&ؼ=n.&J6zSCƏ$ \ A~h_ed`mH_$GGImsg4-3ٯնȝ#9LnSS_G`ϏyC˩SX|P6$L`(QgP 1X b a >Hgk#,Ög4SQ;SUV]õbo5߱Oy-tP\ͮ3>Rg )"'wl25Jk#E{T[4XL>LzBb9J qᰫBW! Z0'}:q绕ETB)ׄ\!| h,?75i`5o:=" /Qؿ~FbiϘQA k6?g{]{&.])ؗ)腫g2 ~ſ0=YޱP@zu^|[D{XR/pP{6B]4|t}p Ine֊6`\")D7t>yRj [gqz&!NCkLXv͕SBR/!`Z͒2L|R/~9jw6NgJ ALv=^g|+7Gn;c֢чvOBP^{媍<6+m,*4`>b'gPM>.@q O>UQfsxց'2CQNN.7Sd `) V8'Jީx՝+Мf},> Npt0s/.fJDHHB}~8d>hJ)E'UqsEF>l@,uGw Gl#}6 ޵$Xb|]=4vv?~$jҘ)%+ 'GEX֞C, e :RK=oAw޴/KxEnvf&~E\*]u(`S\#iˎXfӸq=c`!ݣ`2 8U+ۏrgJ=SsfE%@Ə$Rǁ )ľ.+ h` UEJKK&H $6N秪Y&{s;$Py=37oxL?|8a! 6Yz5.ӹgĢ4)lPG Quut#vUgiA91UrU#"Jʚ=f{dUthqO\Y|YGЧ%UWe XX^TU`<mV%B(m\ViNw080f1GyC~IutHH/u>ѱ}8(Gcy!•-eBbQq7,3'w*WnÙQieqc>E":G n"r! + WlAhNGF1bF[_\ں:u]fC<>ː@+pG;\ SQ ZTh:)gFCR8/WM0el ӭq5jv"ޖZg]dyw CvdҚT%G`t/a4$ѽmgjCԕz{c~Fq  xUѴrW?M{Զ*XBgQB o.8t̑4$5COm[NL rÕ!7"5xcлּ>ԧCl`: hG@U?兯Qy0bX tAk ,%cLf 1j~Zg Gꭞpp0Ծ3Ð p*TRo+,gjфABa =8v O³x6IpR$?V&gj&%\"w.eT*49t4YLP订IZfQScUO40vϼ0Kߋ&Vd8ڑVLi|o a힫;v^`؞[T>~EE۰+ݧR o*zH_]Z呻O] F_Zǻ+͹5@kh|?ٹcC XfCyE+ߌ!x 5%KY#6Mz8k?:7fz 6Y䑛l"e+V#\Gj^k$M2IX4)i~5hC}bm).d ݉~oXCA<:$SM 3]sm@ެZ(  X-Uwhorw62߂4CF] Sx|r:]eV>M|'p# Ijl]7Uc8wΏX`NoiyMT"E}> rVH:^]"3^ZF5*`kWPik:iu uQ&;2m; ]N6[N`G~) .Ⱥ ӢtQQ_4 5#Wĭ뗎~JHŦ]$Q]Ӎ_+)lR!i<1kZBz-ldA$r@}Kwc,Vz@(*W@ <"{'y;?1=L$H\%7c3LحpE/R,s7t`3c4[K6h/&~^$~9R8pL|aXwZvp 61?bmQbXs}6]VxXlk܏QOpƛ1 ',;%ֵ6}%͵;Y1IJ^ {\pʎ-=?-< oͽr BT#ec`Ui֧p|}OO㷹&V{z_qNR_{* v F,582/ԴMTj5$a]%O.Wx О.SC#gjެ,xڑt]!R8tvZ?]bp )WWJHxĮ_,aa<臉8;Q>UO$L>߅Р>SQa_J Qߢkhߔwj[ @L $}6y3ζW4+&iѤ V_C\&{z5hFr+;7b[1̬} &ˋRȏch4 7=m i8t2_6Â2ϰAy\`T\nA2筬z1 GVpN)L5O -Jt?^j(fucu)ԌnTqlHKj u։%cN>G>`Ƙ4et!Ѻ}>"tK%dl6ٛ)z"fأ p$dn=_!=WIEss1opِ~jͷ7eq)B$Lr* ?H0={DE4^/0x/կ7^!e;g Mypv@P,q\ie+ Hdqk!q MF+"K fr+D-o`DM̜tLd_@8|5dHOѼmE=ZcS\ [3Ռ` }v);#@_sŦdFSa:HrsEN+6e9JZ1zIjHa侳p:Q2Sfjk68Xme6U6@n1ՙ(5Zi΁<+f]g^ ;Mr02G0(P Lsm*Ot_6{Y)v^ y%3JVUS^LoÚ40FVGOz4@s<.LTyU ]8ƍ04C~0KZBѮ#4g?G3AJJ;N=ωu)oӲ%5T1 #,T ΢,9%6dT &LȲϱQL4S#/9},+Xk,Oi+<.B^U[O |$t+0gQ >鹉.cz`(ԲDe:Ӂ]Y$CJ9;z$8 XH1JMK_sUcTQv.yDlP'lŨi +sS kD$"^k8I1hѬPr2'A9xh,;-lԒ",dTYv$sק?;> #=II\Bp^#:zY{/Oǃ\m=ŠNT ,%6fG ׸]31f7b hOm7|ZW4ŕp$7.6_Wa3?~XIy0Q{&\?g%}%yrY6¸z ]Ë6/Vi~CP$2EiFafۯ֠bhPo3kc\% ,)UpN);nD4(X1)CԟKBkN'2Jգ2,gȏO+ *^o76񆁖2=nza@nFq q("x /a%76qwm}$ʞ/5 I.tZ'O<#Ldĕo\9m$ǓFQxĠ r'XIVlaA16V aՉshsc]jx@"h> Dk DՏHVW^ջW(j§_c#}VgpH%OSfrFDt`0{֢V~aK}w Hhkdڞd *zF5:ʝ,2؅$PENZ3 îVKYK;LbJG5sS% urW6m˥|hZm}rM/H#f?ZPONqNz ~0'@~A}`DG960&a;C"B,"CX/JP&%Jh˵gv k1c^gvݜ*V\F?07tJ..w:R@ɾv@. ^CvTH6Ճ7-g.1\{%<$dOTƒq][ r쌫4LW{z^?i῍tqMIYeF55wg0t GB$ǭH~g~-:b"w%d_$ALc[D}?ER7T94(F\2lS29dt87J̢ ij+4dEY]5!56M < p:񩼉S.WL|{(sPdnh/f up&JaUbA|\ ?h,klW@t^猾3#T'FL<?XϡAǭGʽ{BRNT |: jHXj9۾/8,#j-ʫ+n\v5^C|ԐL>UWV7E]eQoMw_ڭ:[3iMMy{ٓ*+)0 2ݞB{Lx_S>DܘLNͩs/ yZfw`%7Ȁ!xw0Qd5,^ Z5uLfu @$F]!z*Z.WNXlʊr3u^'3=z 8h># r祚:mGϝbC{nuuj'ii L9n_L/;+*&xda+()_+鍡^3WjNcP $ԅMoc;Yz( 3q &^ڎzcokD?npkstFG !7[k],Ӈͺ|HKg]|VKKD)˜W{̻q 7=`''LM.7ǙPoAεW#U rYU0Yt> ^1T \2¦ -CAM~_!#2'wkʶ^a׍"j>T#@o<#?fLXIMB`.we Bw -*ius)8E'0=؋TtU7@> 8a~HegGD8U"AUMIX >3}P`t&` FǑ{f`κM':x|ZӃBpwuMpg*l(h=1+h w*r ZVT()p?NUk}#I(ܟa|(3LG,=}x-z%_rF T\}q{spZً$64}dRc δ+ĉ#Nz(d;.҇F"S画@ɭo0 F\uԹ{i:#l3ok !}@K^7LGzʟEU&ً]I̵dğ_Uv؏C7x_ ' &J[ g:HXM(cc/*5?rt9caȬ]O ŕg˺Adim/H$0t 8 Vb%i&B7 ('}/mM ^)xF{/᳏Ey|},*`x7oɊ׎`˷7x/S F2, -,ȋxziѼsvמ@}q&.SeAAPӡt[RZn"`*ަkVR:g۬UH9'1RVp[c ~.)ĉUQl7f2TfpZ`G>K7O%ƕKt=CQE8r/jTUr.,ScN7|@sK:vC P[A:<0,rmZue*%Yrol7%kW=KĮJmFӓwyltn_J!n 3慥e%Kc?:bLLA.U]k5}W<*!9ߛDf:,+[âӝ!9Yujn^SȐ P!gKN ~MFn=1X@7n2}|d}nKyA/֤Z7/)ed}NaMmcB'UQ7²-4-N9m0 GJ/}oKM)j.ʰN 8c ekh0E7P"4m)MV"!+dqp@i] O9Bڂ-J]ĻH?1k3H^D.܂PZk 1LFO6'B8Ӕ|ϣt忯3c? [Jl*S|f؋nwR*g+r:2-ܪnAJV`z-a g=2ݍ$jY*+n`4H s݌^B+ygˮ"F_x|-u>׿|uePW$G#dUӼ4("Ų%tzVgw:Q˵AL=1]a`Mw]=[b=}ڌGG҃Õ=uaWrs/d8р X]՚p@bU1E=:€]EXq` |1:B ϳu1ˆ;QZa Iz ش:Oţuu$Ɠ`;IT%BWvc 9ox,=R.'+;9tjLjiIĕY *op|}O*ΰ4)# n咴m \*p=⭛:sٌ.ӌ鼒Fו `v-$Xl9Ĭ*uP7um-ر(ա7n '[64Na>ai?WÒ3֩hK<5Y0]>d* V5*EoyQzʓ@Y[Wa|+CTD(%eҵҷRQ]GzO/cTusgHu7 EΌ$~۩k = )@fZ= F$R]O栈2CJ7 7{wg4@~myo0^.K"aYйޔA) vNkr 1NtN>T.sGMhKX>Gao[-}Ûs"t2OcFXOsO ٭%FZٕ$-N3-xղPwdqX7&wt]99,װ`,ʆUkAJHѠީJ^N\$BjV=Rc͗5;ȏ=Uͥe{Z,>;L_J菋NQ:)[ށ.`N`6ALs~z ӣcq5Њ.Q' E]dg@B|pm] t7^ <`-9 j.xhߌZ4J&*OOUM }{#lum[_<Ex7@Ԙ׳vs2=!kӏa3\ y MT{:J:6D]PisM@}Խ*8_6Abj%=,AكT+YgYKݝ\'y"Sx?5S?n׎O]e#3Qqw̫"3UTuu|/beIW(ʑj/wm<8kh9[h,LF>R^=t"j}$g\guj Ab*"[ŢvOWC +h?F?z2qݖ"Хq~kuNr wrZu첧3-Oc^UMf|URJqƣkל3`v<9ڔ#BUK  r>z2."YxN)UX 8#puFq5z25qBkw;dvfE RYoƎ?qmAvqQB{` Db7(|N1@O,gY_ѵUot]8ܴDOn黤Zw^]Sre{6bXcb) M5#Z+3 " h<O>.튮Mcu>l-UGbA{{6F.Fhʽ"{'@MP]~(CwEt *r/k܂BD8e탻E2qu:o'}DOFIF26)zA2Fj5a R <0]>PǴWlGe0GNX:WI bf@0kI)CnG=?>htCu"*b,<pceӴdx^ˀm1r6-f VLzr*m|Js1>Xw3]XHHfx5!wc*05ZW#AM'ΊG߂Z--@ü(((>ĖwM,2"x\Pk@Ql-!glj&(2(Y=)z#i?*L!z" xeYj)( se@U˰$efnШl1fmŧG*y˟5*ltٱng_1msn1ᓃ'#mq=$ z*iwdTB㽟K37>=Ш07^>tXhUo5#n N㒱K]q$\iI{^#ךf!4 QS{IKYcʉo?9CV={R+`Ӳ~22\^r#k5(cEs%?M|cbUp @UdH5Qc-0t-*+ quΡ*4= H 1Žܣ[8^JAYXxO[ AZQO "TF`>)z0 53^VmeY'DvU)_ I:QoqxX1lK+L҅/ !>7pư>J@4U`+I\&ɏUeeHqZf)d/Β]q8\JVJqe/I%(DkM1RhWrQS¡y%'"`w4jRۥz`_++t1̡Qk+9@ {6>WdO44Y:_D ]"B!6l$y7YyO̦]MM'X%3>q~NxlVOq3sC*~=!YN,BUo-4gԇ Ǹ`^"ܞɇ? ͓ʖ U>gULhl ʸ1Aה{c̽}vYWd>GLmg޾J!+qdͧ(#h8salnP__s y~6 ):c}/9{)4wfV<<3?|,R`^LF|:EpUw`1@|d}HT(^<Ï3@t=#=]@0)6Yav^%utlT1hGȌ][jN/OGz; Of{8UYڔ&P0.Շ\Zy8[.-H+.5|$XeJyLw6cU2%>/gӉZ| }Aq "^CX$v?UTN >1NM7PtAH}DjDЕg5\(Zr:/LVMTHtQs{;EAiq,ĭ>J뮭?||?MX+/v{+W07hc0¼]dgM7F_d9oAI U pw5%HZ[O]0E骋w9Ө2sEMCP(1Kf\YOޡ1widOGyR(fc'E_0$bqDfa)j'%0q^%5U^V|KbM*xEiBh֕Ю-fA~Qr d vTE! c3i| =>3O@PT@x9&48Hq#ȎF ݛE=9aL2bGPT0an9 b!QLqL#DR; ћk[P]- FCLMtyΡVW>[qv*p[ͦ-; F#MUD])3E1q3{TJXxvzD$J`(1=k>p"ٔka\!,kb?A!Q12N;7볳Po;L%zc&T.ZmohRH& *i-3*57+wT9pZrn<(EЄFl^ P?vf~(#EX k`f">\]^9ݧ9Ҕk%eԾ7*`q#{_fsݳClb6'N:\7z4[aDjT9{'ކu}.@'R,coFs.3ETDT޵Dh4USD_̶,FyuYAi]م-{U$HXآ;4:A L镋qm# gS8mdn/jQ(C ePsZ LwXSK1<]]>IMshôN"`["pFfAE#P5k'=[_kpZE3-z懝[ Xd.]27^sn%;apU J58IIe뉃6u)<^(}qPxǟaef3Fsz:O$ "_'2c1XYIP\Zcnfc 91 [#D!m`;7cY^7ERxy 3Id᮶ڸL Q-a @Ij +Ha?FuFri}9b.WqzvFa\IÆ.gxs} p|!UpV\<܅a̅xRh܁l ٩I!vUe[rnW1{^_ct1wMSߍڀ(hU ׳ 8sŝR:2n{MCI>{]655e--pd`$%r}Z ]jzee^g'rjдpK9 G AFp 3pfl82g3qx..lb<\&dԓþG[u>/)du:FYY6s/1Qq  W(rl)x)U'CYê^V F6mk6N"|f~Sqb&l!7i@2 mMS :7*m4@ڀI m!տI-#) P&}>Hp\-.JHFd50dIW{b`T3l6B` ]/.'hpPR7+1̫Y{ ^a;DOO_e9v]՛# @$Tb ؗB*TMe{k1~靬q6)C_Ch= *6 S3LŔ4"\zOEg+>&ނjvakB^lS[O\dF:@ӑ3݃5'Reuk*ּ}ñ홄YSPy6։>INb=:DD]bo]ުGx'--و&@tHv3wx6^w*]FnF!]d:a3WFQ!  C_+K7YGDUk)iR8b6JqH76"62a]7l%= .pիU%m*ɴfMᡨzA'Pbng4W;,Cn-9$0SEeO$]qˆT uIZڪ /Nt֙/{ٷ}Úu 'ULU+׫i.g5ܑB"8^-t2t ]I}oN3/'"끚 5υ}dVGxb~Bb7 zoZFd-L_)7j4!wvF7*$ۀ[=6#ex(LÞgŒDm_f|94R<`f ECxVbZVȺAp 4omυ[:"IsS @mT#,A8 "\ٟ}FxzyxpuFW_bU 5Fsҟ|o [LRQP-a~69H B#USYSWOŗ\"bCe5o}#I/pXLEH"O>4ڱ5 zޅ1_-ڟn1#pӈ Һ}C^"}S;'zuD"!_ckO--<)FƹJG~د!*j;>&Yh\4 ^&k] r}K MvkEC]A /,)U[TE$?{/ ٕb N֌%5e=*bP齵ٕ0;n~;$u#df}8칌t_ Ɗ|=ϭ~^g4OU[1}($vc-j&`Ta܂#oETUJ;)v򃲴`VX5EAc4J%C:cb{ *-kwzvxMWKt!&=Z'4(%:G,ߣދ|ѷ{BjC*@ 6}0}IƎ;F:xeAY.Z]9;|H@Y bK]lL`}j( [bO? w2)E_ž:F%Yo*S k@K9X2z`" O0 p|(oasBEKQفLvDK @ 6-m ]c≇̣cֺm?O$?@yǸʈ59M Arh*}CҾFʫ<EBH=c_JTnnBrq׶3 qXI=C_^R)D;cM fj /s+w~M l9@ԉ_D&:<@ZN 7-):ilt&1Y"8 *' d J ]?tGXF5j?%y#kuL}./!(ԄKWMd~aK P1R}1 (yKb9BH uxo=6O, 6vk,y^JBJ41lwK]tt}6 ȪRDsOTzZ+JL{"䚺-ecҿѯ]/ YMV[2H9ܺG3\ҵ2/c( Q0oh~wE5{"Xy:O|7H@yW^a,w|Erd,ıpaFH&C.lP*#ફ,v$um5{c|Y@)3Q6>Ҁ-Գr#ZR(60Cw!a5EpavdyBs~OguJʞ0a ¨p}nQq;}MODW&ޟ% wشo(qW a?M-Gn_Xm.?G":P1,4,2oS*NFKqԽI5!U,]WAPszW}p䕿lO c8oyڹ9%%vKj^~m4s'f guRL= f 1\qdLVw&!\~Ċ?\)b[id"aYf{KB_-ں~NՓ/Ő<ʭQ.gporv[}& CaӉCX,9&.n~#Es @zQV[;0o^a8t쀿.HzxPf&gn澧c-|})XCPV/'P/6)UBlC!fkM7lGR^h TN'[f.VQ9x؄XZvuѸa)^k0/8g=76 'Cpƍɾ_ĔV+l&qޔ|4A^{%^c-U}1Y_ɻUPP"a+T q) a+(/ђIp&c4pcGvST&aZ*rh-*JId|plv}$Rģ8qu-&%^L̨Ce~ʟ-@-ʕycvOgy24rz "s*#UA[={q3#kb8}1v:bv*%(0 h[Ţ(RI6<$3$ <% rlTOvVmhuFo?&Qv`_PX^1yD5'L )B{Mܮvm=D#YDH'FR %2:Ԍ$'!s1[`&\n`z ǵ5pΞ c $Ao#Wʜɇ'n;ζ՜Ugk8*;N;WXmASDг@KP!I})K҉`G/}H14lح].g" $T4gbK"n8x#,7ƺ7~@56l(xo{Gxxii9<-*}[c 2xB9~f'9+ros̀>=n&{>EbmHZf9|u_ Zwnk'Bm/-^V78,Yns,h(!E2KTƿKo#9  OϭE \=sZfYO^ ? Po#~*5#h?:O҈*p$A (R!vS!-vv>GiÖnI[#%ٟg#Fz^Iox=>t!s+ [)Hi 6M'1Um*hރQk"AVDT?4& 9z~]\͞u`%s1u.ʋ'pe<^‰Mv9ńg"^o$jcTEO9PڒyYChH#A~ yKv;VxAc{ 4Z :ED6yV`\o&jULsSOw4fMq=6 ͭF 4GB]6?Z $=OIZh- CeuG4-^-Ƣ##Vó:~@Tɠ˖֬iig`JdI!Z2fy[Up@]$ԬOeU%_ubIn ד{pTrۖy["8>$'MY U"\lkx|Ϸ뿲{TZaȾ"Os@v{B7CSزM_v9nT*(Ȋ~\^GWnL]V@hqrO`ްR"/{G`#IMg]sj:A-43۾?6_ky]ݞ(  @;6ZOGpmU^9xX9R 0|xYOHhcߕֿv6MfuZoA6yl0j Epo_G.BdʃуKs1OXM z]ZRû'W? qqeMt ՌBn,0aM؞j_4Fk$$3ľ3A, W;EE?e D R6rBٔk>XhBgZ"ЇE9r@+CCkzA} -~]ԓ/ -`uj`(52Y,(>G4'LwCrEgN`)3Y RV K2UWT" $ p_>j>T=ѱMr113k<'qrE[0"PS!ҡ+=.~ϝVLNaF[ 7">݋?j!(zҒuۻLCaaifWdO=2.xdPXthNϰs01-٨# Ғ)L0cBl`WZV ^.HLb4@ H!tTH,6o1 r+"R0J$ћ)=/iL#=Gu[Nsht9+A\n2XF-H$Wod8ͷhJ4ɳ iZl߳&h{Y \@>r:2(0 >K=^-؝3RJ2,;x̕SljR%\i| Jrn 8qZN9ک?wc=,|&.̇Ԣ0'cpP5( uÚc}` IhVV4Dg&CYF⎿vak8 [inu,lZ;䯊l|y* ll)8> Y\ S"ߚY(J$KR6bC"~?S?7ygeAWpEc. ׫]1S19vT_L,+gA8BH|#l :?L3Z:-ַvgU ]-|`1g 5Ax =(F9]~Y) =7 pWG4@ȯRt`_{Ew8ď}"r1d~~x_Frb|MK-}jPPGV1,lt.s̼gJ[OPJ:WR Q cvc<&d;rf͢TIp3|诺0F03IT m4 wA*m`M V4RfSb> P9fT IjbveN2 7SMӷP뉽mˣ%((]dAk Qn͍E>WtOn!Z>Dr.0SS).\Py\\ OQdg̐D˵lSeTA#Ev&_iT?C |þ$ފrħ+NVAE;m #dXwR}q_8ߜY+aJn3N֕K):"'1jֲQ(b,} 1@a8xFVpߜ1ylَ]dm"%k'bGrişӨD}eKǺ!Kiv _8iP}򷬢if(pr*:iƁh+.X"ֻ%ڄLH3>;ȆT/%תr<9>> L|OT5\X=i;f/-iR@=auq+Op,) 'LO>R1\-r[w&wj!fu)M@U: &\MOgK^:PRGѷ?a8KMm.077j~h/^ :8H.c| ..::3HFԤH󡰗$eˎͱ("8%y86UAYKKACΤS] EVI dךG1횼K0ٚ4ǢdJ 6N>$ROjy nYe;W?"Bû2 hVr{RmVb˟#.РR'W#mZUhb$Ay8sn5q-c<MMe?BRc\^[PjWVԥV2Dig> {&i۹Ni3Ű6 F=*?8w"Dzb%@msarc#\C Hb –c 9N} 94D1r@?X.d$-A\6 4)sj"]!p7z6JVAC=CNj KݡUx,|k_ _:Qx$! @_g}8FNPF`=dxjUqH&&`LkШ3ݬ=O=[ f:$"gq6gzfu'-Y!n-/uw5Thu;{>EOȖ ڿf~kݮ(t G'!VX@$?^흄v>4Z^G\'s5K%'Kf-j$;fp:Wb>H{id&w` |)RuU\M 53QG56~1P@2P8+s?_ͱׯΥɛy+fM ^G{k!cO7{sHZ,4zq! X⃻۫MoO/U@JY#Mp?/Đ5ֽm0#bA 7:Ms&P9A3m\e&Vk$,l:q_Qߞ`dJN̙877tn&O)rbF#F 26=䷵BpWDd$UFA{6`] scd˄Ư)@zDɬz"ΕO OKbBX"ē3q./mB@@Y EI:){=% I}q7G?76 ;ɪ:+`fF:؇%s;!o nǾv8Xtjlv.0+1l($&'"މJϐ'Qo[3YwqD!1Oޘ l_8>cc;kp+Gн$?}id\|Nut-͑n@/yD6jtj(Lo=:tJu%dH I r_sl7~-HdQ']sbeuZ꦳TBʷ29|QV>͖>^j7f3p q(HεM| ?ۨnjL Ah|]Բ&N̟ɝ[Z,ԮZ/c<:Y?Ra<.ZW2qSsX) i X/%[~-h]&\⌨<%n;P?EDa 1d ]uȎRFh^@6ש;tН{k >57?"2Q&6~ϗ;nPQ~S7c^iA٭Sti>%qfr 4Ln@:7Ra:3oT7 A86\̦p`s]JPYÐKB؉ۧLrNu`^Z+fY0ۚT@Z9)+k؏b7=tqF%QXJNA5l)>׿xI{z0.8J]׊4'3]˷e[Dvz ;fMLs$ 33KQF!pYGB_#(qkO \50E?׸8n;F^s<ͪ}WTm1J#\urzfBf/1X*> t?J롿ReEY4HˉoR0X϶'XxƟ>>QއwG\V{8H)/N{\Ռ?,pQu:Z'" /M$({'Jw't0#!Oy Z f=6FsRظZH 07}Cjs!9퍼#: sS~KKH"i^B4b7̰kJRv(YߖF{q..-yгcǕU6텀?`ozۗ=#Ui}S s9i7mjQ!3᛽T?4vߑ>+L?w7|9z;h`z/@л^ ޭ QhGdDe>ڔ9֙uO -V+GjY#i$?֐{CnOɑaX~p 4쟚tsO5c9`vOʌc0K ұ!eP80d\\O7M!܎dt6H)lٛUty0lf0Ed)[1!΄i/S؅?hr+!p$, tSc. N ;A-f6?Kg:d¨8iw(B7䦐^otUXV!XБc.C(g?Rܾ#Ε2\p:o0!M\/-0uW:x#Ж`&KW>*Bj͂}xIJ=Nsvs5vW;S)Mġ.wLr- Kwclt~ߎZ1=G/t['|Y0B&MPaa=ڙa \IN9a;"| S5g5b۹ohua{O'g)#҃vW6S ]p)o܁`W4&.dW`ƛ|TK6t>0*N&r^1;5f<́DCѺo2r-\Z4됈(XBҟ]i7x gc^[kaEUfxQzb7͍4Qd 9mJjؤr,]ɇYV A-9y0 E󍺑M>H\L|_Laؤ_Mwwr%!}^5nK c -z!)#EsKqӫq vV#^VfvXŁn5}O|Xͩp:7Η>@2svt@,qdsR#S$.Y> 2ʫ[_Y”Jݛ]`J[פӘ_CzG{CJl<:z9m qw:֝ 8Yֈ]󛘇Ŗ޿EZ!e60aI- ƘYd?!DtEvT(o>rϚ5fK !4+5-՜YuNip.~q3iR~NϠ08r6JFk*Y*VvDmVc(>=NѰ,xԑ*``811o+Bƕ eVcj)ײg)C6ꆼE9ֶ9<kO[mu9g%mlHV lL 4t6edLrGB)6lPJ+ 9b :u={Вdi8Y3t+⢔әù %_LZx`YXG ;t~@TgN*bsϗa71n4 kk0Fqz@y)q;1#B񉨸jn|˫q;_nR䶦yz??lBvpJ7@*Jƹ=X2Uߤ5.ݰQ wdarMȟf%g g -5M0[sNR6pvT${Ņ}Xݞ(z #Z ʞago WϺ)1u2p rKRN^i(}$kjwi=3.Q~o?hEe52Ū,HUa p\M+-K~֊DoGr+un"u/x5"m4&-Nfj%2e+UV!%ǟH1ކ h ~0fA]L(AnEr^]= yU*VI}eRUw+6S:\A"&ނ;LSr7Me@834"eFGv/wr{>&?}GϽ0J@q+\Ez}2* 7S0Άk pENp 3maSòid#`-v?TbuE ǩ dXpB-fPbga#pr|^HOfOoP]țhȁhTp& T_nڶ- }3 [ߣ }+vu|墴*NMޣ-!*M(t)wzzvuƜ_{)!F]S>_8at;x۪=/):nwϷX[L؏ x~1I (UH:f|\k?)1kI[ }.8xI du)4ײ+b<q0HsbI2iZ!Jx Sw?gApf|~Yn4zܺG޾}2@o?q 0K#R.j9sk}pX&Zxk9LBf0!ʪ`eJ?3,=9@` އ%\rvAF:Y im>s `j*YNV;mAZyOU-0{ް"5eoQ`E89} *0DjDE c}'@w%/'ƏGKcYx9GUz?1-n}CLJFVD>a.9B8qA(VXgo}2NJRN{{$rlu.׈sAtLFtП;i85gw{p:p&2t2*;ET#;9u 4$mf;&z3فgx&?yJ/j(ݕFitEH*'Q\b*vbG@صwO1p+cV?8SLb:lLJv|/HL7 '7$m{}y帋ibq7pY&v踈7̔-þ|,ݔꂳ`-rfSeƅxJaE*46{Ժ$*nż-͇}~yT›H*lJwL>5L%o` I!GΈ'EoRO8wWLX߅cfA{֪L^ElM"X[WAlMŕ϶"+!!Kikt/ހ Js>i9p~ph`,2bQnA*e~o'8NY|د?Oe7wHkru?7[r`޽nԒV]{]m8XtJ0%qY]k̃p8v$_'*hUV Ls_^}t̀Ij5NX A hqGHrT`&,(vNTΰ}qgx˦%2_q½ɥ ic[f.󟫩j>P' lԎHlz`fɿ b(U0 #ޢ̱ԐG;27ڨJ,2`8 S-^uyf8JK Bdyz@[j{ U3ej0Ef'?\02bB^-sװ0:#*ry!>%aC?Vk}[lCTI%??B B]c#OqBTw :$YE^t;ކO oAHF7BDلo2jΦ8wy$zGgQiϡG|TumZAf(zkg54Ey=7|;4;밃a̕ºع KUfL=mڙ9 6{h?7.Wc%BɈu)oGfx꘯rl^(=$wkO ܅k!¾.ړU?C֩v \Ec.7DY"2/r{˒s0pXcLUsZӑ/p硥^u@"dCZ!!Ð&#Gݙ"k%^Yk1;;7 8M5:|_c: XZ`ۇAz6`DPOWz4֟ jok?Q7'K 3b*1u71Kq7vp:)&?k]%Gu|)e}#i+0kXR tۆ&_Gk x3ӹ#1}֒OYjM-R(Δ#ٺOϣSI7y)bffw[^8 \PԜ[ x$w’NPZAy9_qt߈4=]֪/~7zwF'u$9"Lj;NJ%>^t./qďYP${$`R뎞6hA=4l+.i>U Cɚ2'٩4j"q}.JlLE+1a(F5 bux "2;)m8\77~9 w,'E>Q1ږ(HR˧(OOxPPlDți]jXBp>e~G6c\E-#ƼX<`|İJNHH/`Fid)'CMkh+f0 z7!i|> 5d@Ë?D׉^QVi+%YD4Pa\`N.{x@N~"v`<\)s!k*4Tx^nqA!m:q`z%tSN1Mp fJƦ 0D4ftZc-Kґ19W~##Jw` @SX+LiA,_!(P;:Qдs6ESΎM_wC$V[@eAYɾ}BmmgPASO!A*7YFl7ņ?0Js>T0QǔvQ0H:S|=Zfb wcTNy]<.<_^}9 (* ]UF(fu$Ewg>ktM 7C\_X;_Г_C3Duvy\`!]Mx;^ >;,,.ՙ;]:H>=bBfhL@p%Z\Nn x=Y@V30E4KYA掯̓KS08Rx^";̦ݛɸx.)ُ&>ܣ|LЦX& YjJw;CQ)*`jcPC3wԧsH}{[CS5!uuTa2E.WWaMAvo@2<+}aF6rr ԑyK4HJsCS93gEҷRjmUl@4,/#թ*gʤ-(~,}`HZ$fW 7Qw|ZSh`d^߻"HhVME4>D/:P9bl W[-kIOf %FMP%X3>AFB8VfQCu~6l~N7 [u.NҮ5?<~5a 2.ջ;x$TCpٰ%;+-qW/wcx& ĐY&<7N9b?~f:Dx=+w@;wr_TDOᕎ)VLs cٿ@@yy*țR/r0C!O{ᤞ``b T+3ϩdԘ/آ?nG8[_~}utSJ3hg~U?B#X,QaPV&:ٟSvqӇbuLm'u?ܜ %4 [[K`pV;s6?뎧-C.GV x_nU%\CWsǧ㴁xAͷF (O~׷r!Nf̔m>:РX5T"yE<ڎr}hP? y%BARNG- f`h3} ַ $"֐n|$sF3>TTK,lt5l,lt)!ue98d"ej:i2j3"SUld"OD*w+t–}ZA*M _Z@mD}_)ɕ甥Cj¸JKs NLWcSBʊgjw565K׸ׄ;:uTvl7Im ! KKpu.WaGDl7)b*Q[)|pnN"4%y\wr9a%Tѹ2ar-` Lvjqڮ|/_#zp #U(ˉ~m:-jnH ?bƑzvx|W&//BOO幐~G.O[toLN{eN&^ysC㞛2^DGH >k+@/Xmx.#2O;T UГ%bgol3ܢC`_ S r8bra2`uc1ZK}Bص'R2u$CRDKDl:x>/=IH Rm`Akc4'c"p8˄X<ۣ8Җ?:Zh7vօTXkW4c[|bk!aͣ(>\v`X5H6@8}: e.ʹc:+T# H[Cygn 6O!,ԣZ|e?A<[\J,O!ڶ+/henDr{= `mS]zne"7GV̏ZŴ4CG_`ؼ>#$Q?Y䲗j̅ʤu[1uw/;'Jdzh~G[By{V KHFjRTE_hj3]6k򃆃4IwjKs`e,d*ǰ,|xgWbFښ@LYV3q𿈊;F2w}dXxԨz? ҡ ow4\vkiAz1ivެ42&'#ϛ8gճ}+j6ϖ\3$O_3Exu}999a0;W@^Yp.]Y?y9VUwslw3 Y9te\ƄikW?Q73 ܬd'ީ }ߒjmrO2>*Zkվ-oJU7ޠu}OxmvZGg(ȥgj<o 4}AκnvMW_ͩFb˾X-T^.r:QxC5 h >%*Rfꢿ+1*a<!E7,Htﰶ/?(US/[z>2xOut*·Dž.R !zzG{Q[ԐEƲ1c䀹 mBN]Jہ='{>-rp nѮEtzđf}{!H̽KT |lЋ\\D0'p SnOsfl$\f1>m *qu|4ۇ]6Y=Mب4 [1jO4ĒyIza7ݙ˔fxԎ_? >$MG&=8Y]O3b*XzQExOv$5G "jD&\8߆*yrY0F́XYpV\P"L[&;  V#!%?]C|~0dkex.@_uc[=]c;w@4Pqv'oQn:k"`Gd7 MˤՎQ!}|HߗhqIWE?6SYɓVWzj"F睽_ڪέ.>(-d e#[uTCpg]3zT:8'i `5]ëӍ{tvI{*U"W:D-=X]Ty2q1;BDOY@FbC5w}C 0○Äeş([\7zk*)iV|Ɯ6V&G;_A=ZCD!RRߺvpVR0 3 xG∛3yk:)c!>FzV7dY%[_!8Bs 񙧹m[[}UGs# }ֿGqVk;QSԊJX,IArܕ9" xx2Pk(K-J6oņC`d2޾qXCDm-Z4@pJfݩFRE#VS\k~҂pat#=&.C>k.̛W :6]x(Ϣ~gd>RJ,υ' k]\#еJ->Eq˒Q8.+4)LFvxBIA1DɸQUQʕ4eaLBv574Wq{δY:yee{BxK{2ngi;5(nɵgM1t+S=?ay`n|qyYwlT~2u0 ѫ)-y>|6PdcrRʑĮ3MY>M=#ܭ`Bk*?;jJ_D"~ h1"uwOhTeVE;Q_[;:fl `u\sPչ7'YSg{rKL$N6TiXz,?I5 FWޞ!ẎK0"= h MbjoVJUhO;/.ebR?S mBHp'T0jU 0M{Ubwc1SNބXEs*yN!oev5e(L#eԎ O~XδY͹9>&,uA.˳?aBEX`Et>nI\M}O/ aX9`ŕEjm8 Y LIpd c`'Mu F\6(Is$o skYZ) KIhRZA{Q%H)Mep)Օ5(xE+0`diwɻT1P<NHm!Я>EKv:>fhe2:U z6 ('=)j QoHQu_ԻreCQnMOkL$HmG5,Ɔ͘9:bl8M5}tׄ5+8u=zfiދWv}iywF?'Q5f^RmHoℇ}$Ը'pv~4E*?"TO);4"kk}G>ԲnD .z۫`; -*5z'$,tzkCCȼ=[]iؕOLV])6'YWF%pfX,q8Q"$'%af@U@wH DP|Ab-11LL}ӹ.ԩ?D ojP)m'IvUAo-M{?&M˿%-Gՙoyăd&-/Wsg;G\ߤ|2TƳ;LH=8r$5_*p*y/{žgFe\%&Iq:[`&ؾ5lOcx Lw7kE"q2N*%~P$xR i] sAo|9ж$lp< *v\'9s-ULnmqgg#T1iKų<9v:5V!aaLF;V1Wsu^4#ߕ[߅֡JEԽcMo׍$t5,sVu[ KyQYpԣ* 'ᘲ ىk_}Et>lW~QThsSo7'+Y;lI0?KUYzD<8r=U6veI?X+YV؆ dklMTJJ]r]5P.b$c$'"3Hv l>qBqen mP5@}m_b.r0fZ)+.ZtoOjY>T4C&B]gI4nvJ:l*3$B\8tczgh%8Xh׫|>b,,Os`0G6 3[193vyWN6~5REF5 x Vo<I,*GiWGcP/Afzο&fIߩ;x{?4ܘuh{,8zDOrJ)A.2 &u{`Xxu{c};`89Y),nv: 6c?q_mH;Lz=AqA˺ $)7Gy;",ԣAh _Ө>v۽W:MMbL]<&OV!$bx-RԽzvjsi3d>TSŏ9eF<٢H6fE2W~H$Hq>++ZT|7=-~lO);5tZ* VnY$|H@h~|NO!Bl)o4 s\ dxr9;~R,.*P!u_?$O?0r>Smc\BԊV4)p *ck0}~ |5P^~$6o6yǔݚ4@eK9?,oR-}4/.d`KЯͽy掄HUopji>,g#)Y-rO]y3Tƀ!mݜ>dz9ef`H|BIf7)Y^<2GlW䘏 ?tu5[..#! |~ Us|˫`6 ARg)k'hd(GO]H ~jqz1WJ%Nq@ ^Ǿt].Nfcjȣef`HN )Bj9Yѓ`A EM|KS;Rmr/n"( ?\b߀M|VFv#&ml_X/ :-M qy#cjF{?֖9Q`Wh ly֎e~e3mSPshz_Ji[-7W_V?+sUWϿry#߹p*Lhlq jZ #-1qhҟuoҿqSɁ0 Z]$|Mdy"jncǩp6 8(M:Fr6@8ňÃM)2?KMgVoW? 矗H Qt[GrrքDoFej% Pyxq :=5b3RpWVz ^Ȉ!6#3S8UјTqN'+Xj7J/KԀI7ʓyԝ9%f.VTe5|7z+?HM}ZHʿMzq@V DZo*3{}"x-`!4m MewTLe I0 GQ50KhɯT)J68kǚX5Ƴ[^`'wr1a%vh%3x@Pk/뫁tH{RN@.צf,ƻѓ{q.Nj 4Ls 0#ĺMlӱvE k~ ڭ_A *KQYLlPhs2=_v<-t}\6{1 Oŀ主2[Iyܑ^~Xv52cm>>Y8Pp5Lum¿!撫j}2r >hiCW2'XX!ݳDdqw_b}#uPz͎=؋1er $aPߒs;%ߙLΑ/+cĔ+R94ʷ?ae|M;?V^0a_SC \N36iuR`X<9<6hu;aU.f~%rmڱJrx6ؒȜ݈{n Λ ~LIuB2o$mnN07ϪI$B ڷEYi&Nog%Nrqj1iMUqˠURBM|GQA|gV  DqKW(ᔗqƺ#?c& 8Ł9%ցڂvLP;U rj$}RTi-J.FFuL,}4?mub[DyGy=(Em' ./X HȑjZ?sbxM_(>ƀOD\Z^z EeLo<D BctaՄ|\ u`Ju^9 Yg\|Y&!6v,?g##{ՌmtVIr'[cKo]BQX_˚7gP6;n8y/+0hi7M):;Lȁ6O jفKk53 y1'yO+8RsOһ7 K?F+g>rx+<_z)^8QPoh^(z,;"Sm㱗N0qlpnm8PU "NG/<*@P9=Yl<त봗p W'\$Zj9TjM%e 9OHÃ`dysN˫:'_vS N#DuaQRuzo{})O+CƔ&# o'˻ݩʦA-sF-#UٸdmWE )pk4pv飐l{:>#OŸEf5_o0[eT]xdY2>#@,+--R)fc+(`EƈqW@.UJ,~XXJD%H &1_U/:{bNzwAeInNlLz>^UR?eU<ID J׋tQ˻fXy$0>^)= +,ZC?ɐk {*3nGF!J?Lk<#-W;KO]Q&ĕJb aǥma8RX? Pg<;wPM./,@Ln.ΗJy@V۽@&գr^+rMdZ60FNL=/Y3nOsҏ񐌵;J!_sJe) U7Pcn_Bx:[%.< Hm[﫭 Dw K~ED^-k 2Pl92;ڷQ,֔s/~d/Լ6lYe<60&ȼDCe3(^΂ l#e I$c;{o#^MdI}?wWz?X$ur y9\lb7HܲgYH&qصM[ \!3]qYS9Wzؼzz򀀾tc"W;!GEZzB#LF|, [o\si(85%a|q`$rps& 9e"od3/ ( Lǯʋ%sr74jdLQ9S$o9Z-ÿBhk2g< FiAʞXU@ڮϩ` Hɛ50,ld|%~=΀BZYƼ>;ǔ5ef1YۄkYIP89x*ExػnՖeP]dm )7$ujjڸ/Koq} J7κt0uCQmZ~ TF ɸo1, J+P|G?I>?AFy#06doEP0pMɪUH/ +5+H\-W $ʱǭb>mjd1CVQ`{ՙ~\dlm>8e%Q̾G p\"Y)!qC#6KYj""u-P-*eR>p(~g[l[ ^sWEBq3~ߺUudƠ==AtD;`j/j!W0A|:m8=<, z(g8ۀթ0 -/H ?x6n!N~^v0ӉC<P\0GF@;=/ͅ'- [&M.|™Dhi$/HQw_ݯ]k?xo=4wb X1V s4 reo6e0ls˄EyeM2ZN!S˭B適(3ɰ'ևigFixj(SAPsIͩDJ>tHOj΀ovwOY:dۓs!FdF=Nr_QYfC{3c-qE.^"3 '鄃^Wcf*fm3uWdʆ[Ň 0O˨47\4y8@w?3Z%pq٢D6rUpω$f6#QXd`4$`~GP@;ObPѸ@u Z 0./{nnn 9ѻi@i)x?L|;MDg -GV#+ )-l/v9:zY} .85k"6^T_g>E܇JXZ~bF7}{ܡN}?׹RV!幭3#s~ μ4&Vʐ?ք'D KF+Ze_3-y ڋ20(~l|\S#avQ`9!TtݝqOԥZ€ W AJЍ5VJ Kԥ}+&N/ޓQ?(;-솃GqdM&Ur9MDPZ C9yiOhyݫ# y}-GhTb, ]qʦ)ӺJ;$ڍ\螊F3R`v-uCgO|-HCx+%3+_f\AxBLO=@21It,:G 4KYLy&Iod*F0t ˏ0TvAaLX [EeU(W#.| 0xtRُ > IΊȲ8y\LtPOcjHYEFy-zZ@ȥ2 @N}p-.rb]`YǷ/@EвӄԬG[ ࿾5'fav!^~{pbiڣF{&J&)Uͨ9U~2_c2u]G+wd,9tU# :ARƵ"|Ujl43(l^AH#uJ5r?QjN)>M#?ދo ->,?s5ĺeAu4SIx=%ZhtnI@bH'|Kf30%EZ"lB*uǸǿnEb1ғ Hշ{ExDL5)A绢0wؖ;l8N%|<j{DžfArkЅJQ](67)ĐJXVgޤZfҡ ؛EFOZ+ أL pgv>V[ߜaH$ef@ԒQ/jN!|| d Y2Wy',fzۿ"&ǵʖ#}_=`L J҉MY7x%dxpZ7gyw &nB~YDwVQaJ!E%܈A:yyC]yh5O$R͒45??h3%igJ#ϵWTP1NY5P5,u Qvd+ny~}-d21y;:ƀ0A%c [VUy՗c.g;/ It7sRN| wD1TAőBƊsɎ?#$F̷Rɇw f6}|V{)׌VZiurO$Nߤ.Na7}l`}P޷H126,M{+S"oש.;oO|mY^ٔ=X1m7kЙbQҿ@Co!=&X8)&S›k?w'#.iQ}"KMGC==ȗQsMw^Gf:Rpf,RU9!bodOx6vpIl:p^t@ $$dL DRw|Ul&_U0#\Smg6S%[_ e\oI",vBJG`،-?g&ET5J(g^M5| qf|7N;u!gFM1ڐ%|LƝ=*"d{EZ=w^>O`m9ObXTA ?9m9<CQs/Uv naj 6Þ8U.MܜQ,7c\\cX{E'RgK)'7,6ڨ(^&tѝ&NZxc#+Z< 8턝Se[=9;ąMzswz{ko Ì.X>HgZN9hm˳Nz,iyxCFBKWT1*Pֶưਯ3N%@ bO.WK evoW#_iԸ'v\iyw_1Ҕhna3^BtxA~w)/]gĨWEGk5v3X!PZ7gޟU|I${@:K MGp"b81;` Wٗ!(FKcq/R GAQr{Vը&fϦa>H4(! ;_QmR>l.tGBm(O¥wϬ-_jޥ|Ï鞜4ˌ@+~+X-YFS<>=)ca =[є&yZ(eːEʚvD֋0L M:!ȗCBEȸ -ʴ%mQ3o۰7:( > 6>\/=r =H%%Rl3Bk|*|@ptS,_b:Ȣv٘d%)$aEq=i)Qilȷ QH#75~DMp0=WĬ /$k`1Wuiub탵N'9O)$w6JlYIt9ƥ0<@ASiY)2LG=Q {pn.~ҤtBsXOa[@H|jR>9;k2jV4).,^LD \+$17-o)(fnzTޱh\7)@p˛\@` 4EP|_HT˼l|U· [)|lc!B&¥Irb}$DM{WLXTO揫,lZ^,6'vxx" ie)!ˀr/y&e {w֋+m Kc>g#$jO@vS)A?%& O!ioڥQLTr8p$!U8FJWT%QW+~i0=mG{Lyߕ=w.1(v ;ԓ0[7^D&XϖP@W(|n!rVeIH`l#"4-QfD$ |"l@sz`FLRݏ+92=bVW+{SZHn(AOz4rxHCj,-06c)?UC$Q=ņ%T0IXEG\-R23GĮ*MY@}x5XώMw a~+&0~ :"֬F ACX+PhK[m+#+7?l&Y(yxhƟ&O$‚r'Ӣ.$CɄiG6I=;쑽퇱$Ahr%+ޛ_˱\һ}'gtG-1HRfkj*?Ksytr W*ͻߩyDPPiK+OqaŠ$d0~4|6z:f8GLD8r[79;2h 3s%A]c~ )p>#KiDG=tq䕅(;C- I|ڿ1sLǗ=f(Z0|֘oz Z$[et^a]'+ݖNd)Lw,N-Z .GRF+B7s z̲`<ěmUc0iFi۹bmavυX<ʼ6aUo)Xnͷ.v.v)|Ȼ̾jP,YB~:F72c{.+# i6WAqQp`I*V`zZIA q6F-` [@89YoDhŕ-O+=1\Kي ٬Nh[zA 4L%tnkq[cz"P7./sdI׬ظΓI/rBA&~p-jPJU_J1ՌZ&FZi 1 mR.!t!իοwU._O1?cBEXj k9F*ONPyܛ, sE\w>Co"k (%0mb+$vgY0*x|QA xCq "-e^:L ?>wy#|lioLښ8w0ľb~C`'9'L]5a{ljÃɈif ] )b߬KE+|3 ;<UPۭczԮZ0퀉hauW\?rlErO+|}b, hJwA\/,4F:s_H[rT)cL3(,,̩w(2Tx=r9.?j#vM kf7U_n'Ŝ?_@-̀[*cxoVscT.)pωn@H@)BĊ,@.4\s-sbhn1A\E6(7LRU: u|1S֐x7 3o~18ܔ-3lP_S%6C;BiIX>X!P $%aņ,6w¹t8fErҋNK*ω2b$'NjbtMEw(<1jPuD=ƬZ= {=R,z` V ͚VމdmwHD+k쁕nyvJ$ >`_c-f-&`+BT*x#·9^3I<l/TB3[J'<^a+k3V " 1)Чkm5bA܋E,(ŸR!cN?O=7]3KmQ>&ק۪UՓ, H|PywcJm"N =5NT~F ML LnC;}$ c ܡBִSTYi1xjIn&M| vtOd=pa$&2V/#9Ҟ럧ՉYoH܎!vlm2# 9n䍐QM1sU㸢k~@ͬ8h{},'ì"1°(k=э=J% qКe wQ'j )Cw#7TCʡ!FRmK# mFwicPOHTK#gN$:qMM̧C㻏{ }brfF$Khʓ-(`ꮸ䬩uQ=A.Xh\aЃ1#oe }ͣIB ֲ+ E#̟up:1)"v1JX0alGRу}.˒9pU24:h}0!žmcf:QՋ_v6*@/D^ ohׇNy&e(;Rt-TT(jx|[7A;j׽f7,^pTC{BbolL,ͣB!.J į4(74qp}iY4.UٚPLRTt>,1sJɴ=Y%Y_A0 Pvb̛L*jd咕+0s'Jѐ=/D &$L*;y8G7+%Z3AUz!VDDsK̳L0WUKY!5JhLt* XY%ktpktј ;/M8>/tZ9a+?E U3 rQj8xQ6Q\uhf/c6,u_̘Q܀Pyu7}jI4S[&!H>(򕲦N,$m ]hܨIocdaLɺ``#C ַsOPAXv!(TF:~*C@ d"͆?ovb\IR.8"}k};S0m3R0$IKFyP,y^弿J5*EcvL#џ9ൣ)a`es4Cn k|įTݟ޿;@{L5wSowu/>L^j,֐$ݡ~C4_@o`֟M,/@vQ}͌`4䳑P@26 ǧ H^vwT.ITdzʱKo G(>2&ov m L? Z %y tC+Y8˱f2$%f?'gON(܅̡ 3x+GiƤ9λcjU;t߰IZT& hPl 8Cv2ijgKێCet),n7f3+Uf؅\DUMȣ*;1VV{Q8Xܐ2{e|+B~.5+ G| я0Z^:b0&`ס,-^VT{&1TBc]C,z5mQj8p>hL\oUd0/*$׭r'*%:t~xO"1q9;EsuBOnT,~!IN}D4Q Bb$DeVg, {;bYE맴{7}qnC$1Y?0O"^C%B+A54T?F|P'zZq81:U̳w\d-k'ZbfhdxX6y xvuCwxaGcZ6/LVA^;)!YHwXCgc =xLNy(֯yIKZ/ S~,; ;e*O tMTYn˲ "-3ާZe,B`&ke=T4Dx BraYsD:;` E4AUdt!͝LFN DxK&f%xf.NGvS1PG*z_0B\}B2tA D9<QYI2{GJ5@|~P'Z&A/|z`J<;1""8t 2Z>Q֊b@D6UkVMЭ0J0=`|?OI]Ћa$Z:# P$=5P,F"[-`OScQs%U'rpؕNjz gyѝ 2+X̥\t+\ G韻>= /paSOOY:Î\Eaц0 GByc_2 `gbPCy'rw6HIcF%!S1noUs[ d 0EcrozK2 Y:Sܨ?RΎ7,$2ЯЫťssʆE-GU2ްCKqPkvErd*7Y?8j~B4}ΙE0Y:/$M5A{yZR:u]"njZp *LGcgHw2:w`&aFlR]"$b !(ٵ7k3, Dd%-*?mtE|<\\FF u̥KZPyМh0 l7JM{J, L7wkYau^DK`?1W(S)JCh7 `. 8k= ˒/ ~nshXd?ोcu ~"8a )\#N.ljvS?j>ӻX.X L_d*?:ܯ?_U9?-}󇨄씪eqMY/jس#y¨B FuOϼE_s<`b6o9jldK`̛w% Mz*])tƶpl\fEd{"8o6)xTy<2 UsX=%RZ=zOK>"69 +"lw;#>^Ҩ?gyydtJUr`M3[ ",h;;cH[)Mrɓ=\g٧5,©9FYZbr=V9œPKNm8̋.N-W&mԴEͧHpb`o j,-'ZbXT< VQRvg'\o h@}H][tPRZC}ƘI-3!|5Eoqtyt\H1LF.Qt-> rnUn@ %96]cA"{CQJB/وsm AiodDʩ^A@i. q$ jRYF򃜋ȟ}MunAEKX#QZTuд/l9͘ῗu;;Ηr`R vV:6_;!|!֯>rrjۈ&Қ5)rf W{ERHY8c׽&` h.ǩ]< yœ NԹ' ?,_lZ ۛh#1znXiE,#>6 В5d@63K1zY8dHC/&3@ndW>>'LP*^іU}+=Nj%O.wQ|Zj\v!Xz0khypb #.3v $;NĨldX~]% .g DxzT~9):GfbsU%d8'e!exqgsukCNkmܥ7 zoKϾ'RuENŭrR;'-kݥ9 h lsQ&h2|w5k v#Ā#䌵'hRb q'|&"LjҺamNT*:UY  nGC:*GpOZ4D^< 'JoޗDCp$ݎKpKIbt[f!@vGc=HkɄMKß.ۄ:*y?y62.t |Oڻ3&3\A$I 1b؞YCSk\X5 tq50C+V[N:xV-RApUJHpKp{\v|tQFȣI,[ZѸb)[g.vw:]rLsrb)l,+F£3q%pYbqZ]\x -'}ltKtN@*oB/~U(y+Q]HCf Ug3z:"ghr~4F2*K>۠1 &0!NYZX8Tfl A${ PǚGZ-gU|Qƕ֫EcFM ^ۼd㘛H;-EQ^ E-YdGk;Wz`M%J*K"9Tىk. Cz?m׿u$-Ǜ. ƺ&wty?6f=gP':ةE^v#s!Ʌ%n7=ܳ@Kr؄oD~NޫF=c"w o"C]B?L!>QڪSWMveu%ReE}eYZ(y;w-]%*꽴UiN^{[!uZyg9pn5 A`zxTy*(Y'oƘj+/%M `O&l >t7\\l]Na ȽF~i $s~HnJU-o`EN .\Ji-X:7ƈBM@d;K)yywp_vO-n'iО#P<Vr[YزX$tVqQQ kiI\NweT$OeY'$4 oEy4'LRr;|]rHTVlD+H]8؛qY>NBO F-2jj^%}jU6547EH\We0Tb0n0U<:/мn2@&L~>~ҋ!~vÿ5L״'#tLv/:9?1~SN;wYԑ3ԕ7UF8ҕ4+Ns{w^Z]̄uc*E;*ca{f 8gDmC66jC6vGU% ]UhVtdTC"V1P"M]^5g0xIǑ7HlJ#x|Ż:ƷV/C`L֫]fNdZ\ITJwïC3`$r ɓ"Z`#Dǔ.Ռzi\!W˺M5]vӌ@¬cG 0 v+-?>Td  Pp8xG/'hBm8vL?UJYBbP WתC8:G;ȁ\eHJ9^J Oh {u{OU!l//WȕFljŠ-[]\+޲ hKq$ʒQbs%wүIOi^쉐 *3? ,]'qp{ǹL| 0ؚ}~q,B]u:}H'345ЮHFR3 IcSxlTg]‡ZFֶlU 3eVYC"Jn˴O0u: 9QTM׿:%EoT`y{ܸۍ0_9@cW.QWэx="ZN4Jv29X~T (IY+ŗ usp]]"pٴP;a#FaԳѹǐ/)B*Xtu(ҸV(hb@X$!Tъ{}2oEj?ayc&HQ|U]>R-/YEW/%|NM Sp{~:5Wu_b1jW7rsHqΧ{uDZuCQ8"Uc֝7(-2cov"rd7j}e>rV=?\jk4/~U^Dd]oVVThaeq ">ʘlJكNv' `e3스Kٚ T{!8T^" {!eQ|IFR[*L2EBO u>.Y[ |-gԘK0Z~CH[r|?a*o-4rwiՔ9jܷꠊPfV_k[f%ʎ!K"^&dpmk3gyc-?؁u|24z~8!Sf@˧JH+xHlVd)dF cqщ ܱr Pᙃ刯dG F`""% u1eLD=wvffc4OJ QGdB'~XeDuG6x>#2q *5 ]K<T c)',Tao28io_r;a%}Wflլ "Hg 9a"+3(vog؀LA?+̞,(iQmxS5K yME#d 2 G3q"\(ZFE^`k 7CUyuԟg&?% &Ca8akwݚB'oܮ ~Cp7{WPC5Y$ S#ߠjK\-P͚ aT2'_#hcc2 [6jUÜ P8 G|̚4#Kyi6ِN'Gş4:1+q<1O5f2> $$LHX@aE MP<'ϷUCo^PFwd{.9AzY{mWlZϕ!tiޱjl( u2M:5 +14j`Cj- I,,yחbt.<ʿ )A{0~˭0uבkngW4'S܉i? Wb@{Dm5B/x>>mDdbD,[֋b3LE`Y; k2 CP15QSB8,!_"6$4eWD֞QaYoA쵿 9y 6L&Z[dҨs0y)~w߶ 1{VZy`axf?#>K>xG`1%)yeӁqP#O!Ddx(`8)'їTpJ`GhFc}޽lAfC1N+_3oOu MmĬɍw=ػ n@93j!21(1~͡`hMֱDHo$nH 7!Nug>o;w'$xm|^ n8?boaɁ#V@hUBIw=p,֩=(_{ L];]_Ut< xxNB򐭁o^=qG[(w;٩,5vEtQQ1 Nu߲g L,ӤP"x(˸{Y| ]wg~M/J̹k3z&_CG3B2(W&{ C r9c :y:%5EFiL'•` 'Z 8XJA6",nT6gCȈcpyY_ATJNئ5F\sqj#(?‘&0.mivk0#Q78F^!LϏz<ГA^> / R]x q8/53!:Hx* pHc> IQ2[gnIHNfqc\F8GE(NצX]Ը32~DxklԳЧ3{[[V vX'؞ָ Eֲy#F>.Qe%2u#/T:5b!zBiFi[]_]8b°ƫ~.v,9Jh.(WO}~,r'e);d3qe89. -x k$wBq 1)(I~@>iݩ48o=u3UWoXa^ր@zu@6*-FE[1戝cT[5neŧZH^/fQK D 8[Ε[{3Ozwn{e&FaX>iť+ mZ-زq@ 'n~=U@&J_S$޸QW% +BSBDVf7c6~760d?Fhͺh~RцR#]Z6 p2HìLSkt P2niR؜\b?ߘQmnNGr1vyW"$_@ڙ#Xʣ|K j;1 2"a3T#!ެj7/g-(1phjJ "- U.S8E&<+Prڨ^[B0 w4;),GɱySW `tE.\ w?̔[֤f vc_. s)ߔQKKY~drm񤛰kHZfdEtD<Ľ4zQ h ]*YdttA|DCnz K5ԧDaDoNwΨ-Jj^jA{, 2wTb܂FH4" %}/{-mG 8Uk\Ƹ+Ddyd2;ò9г%4(䋟ӨRqzr"4y$)/6c~@1?Ս~F.˛qNri) \VOre tͮЌ7=5'H)O`ßG 1rjYGhv @=jݫWw @ni|9h-_JHOEU NXA&LzlNXϰ5T߄ᯫ9Wֻ;ov@IxP␰%ZOS*S Xŭlg!yӤB7p萓/ZcI,$jjhR펶 i+8>wc4 aΐƏʔ+D+9yA^!^DIO2E{TeQر6<]/ԅc"E{xcC_I_E~׈p}񢒀>6v鿏 M&XRZJ>FP߳Q cD֩ gڍ̚bI5;=)HzEkCG[.gT@9B ɩV$RC?)*sD\6aJrؤn&{聅,Rq*T-Tf!2U\3EY;~ _r-B+}ny+gϟ8#pEib m|Mʨ M3K_I¦կ.O_s=aQqNl9?#⅗v> %=Jk2")SPl*TSdd@k*8rg'*lG&VhM 3pk]Ej\k^*p8JC胭va0>[VFTxŬ'GQXa-6 JQK1_#3 A2F䰋&hѯftw\vqGwMiw˗`Mk_ S0}-(wZsXxX_ޙK;/=<ުan8Axx_ȹr|䬨~WB7M$:"XoȥÈ(,'C-A`tZ4B!2Rys{rP l0`.e# [!8!dpT,;{,6Ũ''Tv~e G|;uA^XArԛF.=zf=r["WcX. 02c7'7`/B#Ջu=?)OȻhLji=s;#_CXe>d̢U5Q^ dT kƮ >! ES0s[m"Js|sOl սZ҄ RYj$xdp.6"ӡAP9N-G ρlM7_Y&7jɎβvNpR _ރBr"nDo;Z94  JwUj<@5SdJ5%o+Wv vO$+P5PՎdX%?$w"Z9\& UKRӛ)qZ .)"ߜB'( jXp}v^Q&Y4Ax8Rd+Ě}=1o(*1#Q]K$NZHA(JGC:-Ud0\ΦӾv|iic,9>9h(Vɵ/; jomj`{Kz2P)r/,eoH4sBQGnUG\aRyQ_p".\17GV0 V$l rU׋IiT aV65ecS279na\V)~˸2D4?Yg~,6nVa+߭Tm.sI2c jo UlC? t*/G&5iXX>LU풍t_cz!$/| & NSN-GUZr͸e(AH+i JGq6{8_O 2eHkWU j HsSY(0; z2;!VנUsPW~Б^b*GA-%Ypa(Bb.vn@3A{_J񚋣4' L9.AyEՃ߯f xC*\peUX31͟wX7^x+x~Ah;=ז2,%O{.$%b I{7bd)tYNSĐt vsM*G-.#߲1JXT܅Vɞ?LiA$qTn(jr(8 P_`|?yF.2dHHR!fìhnxJPe8L. l&l*}}ߕ\H] |f'c`}$~zB.P'{h:0(CK\',/[}Y!5- &{:c_?f(p ڇ]/@?<\Ox2DLj;+ui;1Q?ǪO9րբY Ms͞ HP_;%, |KJȅUU>\Hf- AG$}M8I'-"jtK/ɋ)M5hHEkG/e 4NU9W!mdԮ 9"CY[_ҙUeg#~Q{><^ $\FwC  \ɳc=ӒS}6@Mt+6,ʹ;)=A4=*iQ̳la[d4<@yJr}ˇe؅'&]R$u=;?Vâ*sD^%r:ɠ_5;y ڏvoaPo9p8oVuEK+iBcrl(td|^>"F|:dZ\)YXDZMN⼜\Tl]Ey#'k2n7oT ~̀Z2WH!h0]o֦W%(V&Z  i2OflQ"€v6!sT*/[h" ڧy508cvtIsUL1+!,z10[_ AG}&F/ypﵮ 6P{tk8bx36GyKs(ז:hP/^]o;Əia;??=5S`NB.BNidTM]I&wSAB){ jh> 3F]^IBWEj!Y8`>cU3^&ݤ^\~3 JoOag-Y @b)5ΩfA+vKNXȍtB8q HˠJd^7BqPS[xz*%Rlz!.$tnZ#YBD+p,]rw4 ѸR&KRu VS&JK8jK5s6odߎEjm&ϘDD)9Y+DZS≅>1"i} bә,|W_?OңHR]a {ֹ t<;ЈTuҼ9E}ZCUD/^EJtUAﭠBď3Y-l#n9  SBXup?GXl%2ڀ J^V 0f6NO',O|-aQi׏WxA=?CH~4̹H @'rAݧNG0=FJϋ-;in?g/QزdIܟ"ں/ZS5ۃ#si vEd1!|>3a/ቡ/ko$11 ҥ uQ,I?ck#˝`r TxPZ4"jFo4s:%;h=-썚Q'; W{'gC!r ߹±|2Kމ^fg_/ekm0"IzD6lBRk6 LY?%ꘑ\cS* ouVF%).faC{\)T-0ZCgH~ P%2Pfm@08^0^8e0: u`MdEJ\.!a)VPȿ}*f ,1LO9in̿~:CΉS7_MFɹR!łDH~} gl;c6۲,%SMpfC#@ڤ.~yҙ ֯ .}蜬N"uHbX!ҫhv'[^UNWTx3/̓q*ZRkS4UAtwHkKJn1äXBe4cV+J)‹T/DY#28ՒD$Tu&{6yy11%zvV%U0=:Qm!"Gˠܳܕ0k 1D8 (p %ҿl~2 jr=Yfø>'d|q6cxsd*F/E:D B1BfcGz7jhD9b(kg(xjtje[VEv TXL~߀'x˜I2Ö5,@$ l8* 5 uL'p%GF9 ry(F̰[ k#L$/+5vDHIE w:! `/Z3`ւ]]?J1O?-$7p2ڊ˪'gꪟje)U-}Y$i3(U('Iウ["CqM ysbJv9,'!=7ׯJ ^0%zwBFRj]EI%=Ew3n2/YF)I6.r=>>u۔ VoF+,>h yFAផ\tg;B5" 9[)dN6L#,pn2$Y-dق'Oia9M#6%>ާYrB*I@ٱ́i䇊cQ8JKa؏XޢD ׺}5oX<;g$4MagR_9P;^}faAoOZfS@EZqaWջJPe 0Fq]; _1Cmd`/,;f,XИli)B Ӽ vRN KܠpͶzRNiAMqS]5a-ф;Cf)`D#Ԥ|M;nd9CS߇)~Óo:?l2((S}6 >-6Fʪ"z/@˸Wj4Ӯ Vb80LwOk\%I۶tSƻcb']>?gT=[~Nr(G"ͺ*$>h1/VhKZNP;-x䯂0CxЋ4'$3)->jf㴳ADG]ZwicI_,Txm> p-IX|٪?)|*,2"ZTfBlTOXB{hr5}g]u=g +FTCcŤ-~=!P^t3r 6tmsܙ$k3f=Vj%{󁔨I'pX9ܳaw٘˒Mtŵ:U[O÷+들䧼qѩ/ެ25V7>_<:J)/VV&+J'zɾ}A1t{~ѩՓBmz$f(M>h)m뗦l zuxdVHݵ }_{[ZPcݰ05HSqxVVMyawzsn!†Z؇8>&E{i)B,Ɠn}FS;hv mM`i'cXZ۸aE9/=.:|yXޤCgjD2$ߊ쿚~yemIȔh}%l,BÖ>կ>V;pa\Tn^Wy?A<2$4nl3q;"3,d_)'Ҟh/<~ c#%=Z$.΀řtӟAn!xcђ8.+=(tk [#\g?~vyـ8luh)M<ŗ\hM8GWƴB#wxT4'/xc4), Z~!xS mʥK 9<)<  e@ KDb 2(Uq/?ʟil.I ?$%U?:=*ӥxOhR/(\JWfCp rqf_.g3JlBY Qr~:<}\ȼ#?TI CtOV.(jQP]SҬǟNtx~K Ӧų`1ܛm65`;WHj(GdߑLr?C./(Rtxai" !@58gC$X|@|qݒa| "kS䧓qùOXG7xl.bw̻QuF5RoqS0 MB:65a }ilCˉY!{6sv>D)NES&iofhsgtVYCW"v6^k]s56;L;WTq[ ݎո@Ċy1opvpesvDo_ 5}1P