sssd-ad-2.9.4-4.el8_10 > 6 6_6 3!pQp)Tξ7]mtZ`f ]mtZ`IPp.\C fӹ_'k$;"Q]࿳fCX  +nYAq“^OmO~IdvY}j{~a:1ֻt^Ix@J4i؞wYƱ?O5Sٝ{^A-Y`Y"AۃUgt3ysMTZ{FږA} 18q/W؆Rf7a(5C-D5 .1-'skhxZD*Y(9(1b2][s. ,= Ugr.^lP@iuЉut71a96a4e06e6e46bcf65090f2e9e47ee065b0c54b2c7ca66d4dcfd5edab4b085d1ac29f41893d6e5967caf37f67daee565d1ff49h3!pQp)Tξ7]mtZ`f ]mtZ`wi*9^MR5p E ^p6o/_d A>NuI!!cj̀NqFMcCbU~[B2=Viu*ۓz]S~J#×'p+. PX?ϿM2Wmi&Kî*VF[Uk&E>!5ã`6!6@N=+N## ?QGڱ̃'!& O::aNI׌^7NMf:f'ilXU_%j$H݉wf=bIIkٞUdh+3y8YR3a>pE?d   5  0Dagp           4 h   <lEE Epty(89h:i2G H I$ X8YD\d ] ^Q bPd|eflt u vwl x yO%(0CTX^Csssd-ad2.9.44.el8_10The AD back end of the SSSDProvides the Active Directory back end that the SSSD can utilize to fetch identity data from and authenticate against an Active Directory server.f3ord1-prod-a64build004.svc.aws.rockylinux.orgNKojiRockyGPLv3+infrastructure@rockylinux.orgApplications/Systemhttps://github.com/SSSD/sssdlinuxaarch64'&FHK:N>oQAAAA큤f&f&f&f&f&fff&e+ffffaad1f3c3a2083819062301b43476e5ae1120b56add8bd48bef60d3f3f7ea98ba93798d292a6fe1ca85578948c588eaab6564f32e5230601d6360d30e9520b2eb8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9032dd0e1f82ce8da1ce127494e6aebcf70611f652fa11fba40d016a24c83e5cad2c4910d2fb3d7b1bfff2231e5d063de44cf1cc5cfbe974fa8d3da97e8242c33a1d49135da899fe6ce90bbf46d77c4b3f8e6b71e4480ad03ac4b3d2ca650c60cfbb763c8def7e244bf9c06e7742e4c347ccb5b1add5f96df1b7de1bf43d4a4a49c../../../../usr/lib64/sssd/libsss_ad.so../../../../usr/libexec/sssd/gpo_childrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.4-4.el8_10.src.rpmlibsss_ad.so()(64bit)sssd-adsssd-ad(aarch-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @ ld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libini_config.so.5()(64bit)libini_config.so.5(INI_CONFIG_1.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.3()(64bit)libndr.so.3(NDR_0.0.1)(64bit)libndr.so.3(NDR_0.0.6)(64bit)libndr.so.3(NDR_1.0.0)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libsasl2.so.3()(64bit)libselinux.so.1()(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsss_cert.so()(64bit)libsss_certmaplibsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.15.0)(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)samba-client-libssssd-commonsssd-common-pacsssd-krb5-common2.9.4-4.el8_102.9.4-4.el8_103.0.4-14.6.0-14.0-15.2-14.19.4-4.el8_102.9.4-4.el8_102.9.4-4.el8_102.9.4-4.el8_10sssd1.10.0-8.beta24.14.3fGFf! @e@e{@eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.4-4Alexey Tikhonov - 2.9.4-3Alexey Tikhonov - 2.9.4-2Alexey Tikhonov - 2.9.4-1Alexey Tikhonov - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-33957 - ad: refresh root domain when read directly- Resolves: RHEL-27205 - Race condition during authorization leads to GPO policies functioning inconsistently- Resolves: RHEL-25064 - AD users are unable to log in due to case sensitivity of user because the domain is found as an alias to the email address. [rhel-8] - Resolves: RHEL-25066 - gdm smartcard login fails with sssd-2.9.3 in case of multiple identities [rhel-8] - Resolves: RHEL-25065 - ssh pubkey stored in ldap/AD no longer works to authenticate via sssd [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-1680 - auto_private_groups does not create cache in IPA server SSSD cache - Resolves: RHEL-10092 - logfile rotation for sssd_kcm not working properly, sssd_kcm never receives a 'kill -HUP' - Resolves: RHEL-17495 - New sssd.conf seems not to be backwards compatible (wrt SmartCard auth of local users using 'files provider') - Resolves: RHEL-18431 - Excessive logging to sssd_nss and sssd_be in multi-domain AD forest - Resolves: RHEL-5033 - Incorrect IdM product name in man sssd.conf - Resolves: RHEL-15368 - SSSD GPO lacks group resolution on hosts [rhel-8] - Resolves: RHEL-10721 - very bad performance when requesting service tickets - Resolves: RHEL-19011 - Invalid handling groups from child domain - Resolves: RHEL-19949 - latest sssd breaks logging in via XDMCP for LDAP/Kerberos users [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) rusvuk2.9.4-4.el8_102.9.4-4.el8_10 .build-id9e21aab848ff0b613f2c867805a3b59e29e10c29ccc8652b666e86677824e9307c344ba6873c9b79libsss_ad.sogpo_childsssd-adCOPYINGsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gz/usr/lib//usr/lib/.build-id//usr/lib/.build-id/9e//usr/lib/.build-id/cc//usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ad//usr/share/man/man5//usr/share/man/ru/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnudirectoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=9e21aab848ff0b613f2c867805a3b59e29e10c29, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=ccc8652b666e86677824e9307c344ba6873c9b79, strippedASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)88PRRR9R:RR RRRRR RR6R0R$RRRRR#R2RRR*R1RRRRR3R"RRR R%R7R;RR RR!RR(R,RR+R8R5R R-R4R/RRR?RR R RRR'R6R R-R4RR R RR!RR&R#R8R5RRR?adclibind-utilssssd-winbind-idmap2.9.4-4.el8_10utf-82009c653b2cdb9af716a6504624a12e07b42cae3447ee4928a4533acdd89c8e2?7zXZ !#,] b2u jӫ`(y0Dih[*i.\/XJJ*'V{Sq:+lB= [E|0['~eTi<@ -edd+7 iF7EPwP-D.RVЩMM.cnA4,Z_VL_A]f] 0IZNEJ{h_"a JfFTFɪ-F&3$Q۲.5w*&-zba=TiUIq>m.$yi=ൠ.8潫kTm&9iBVܕ# 07yMm|$k_}i 1(~ T*:,i #6<.<WP "VN$=>e۞Fv#HO.Ozr/ X@A/}cpthI Δ"CЖ2 o\K5;m+Sn/5p `EPkƧ#tiV&B-ݣ3>PD FבgOᨡ\̗rW"^O+'1@"} * IIoT)udd!Q/{ *FHI%M*KWc?\&a7F=O^%\VV Vb}1e_:"*N bso]6b Ty(򏷚C}[TIS-A1%ҹX^]EāU _}ݱ- (t;5*V2&Tcy˽?jMN$4Xj)r6o;&o..O3D峿>skc{"ƒB+Ҙ!2[bxG-MOA“rX${'^ºZHfHZ8YY>4BL5Ҏ=@;eu [CT;GsT @yOcq2 }8AحPӅh@}H=uccи-On3t @tMc>ՃTP!k #,<7]{OZ4 ,e"])^Ǵ,7_-AlRL0NΔ2Q3b1A(>]=c0rQ( UkPɊ=E2(S&@)g{'w_ڪebνo/k/wp~) z / wG&"o}z 4ࡥE*w7t eM }HP r uXTjŠ!CCu߄ vmU. KߩTŔ57kJAZ+!>4U/i3P,||1(XwH 'WG_H.7Ӌ " e4=oedԒ?+} SSa{@̬_^*IQ!Liy_<9H}.mjQkmy^08B_KV"`b95K]J{yMtnL)+޷ @(7@%8&x6r2{8#Жn;om-hl$٪H \&nWdl[d0Gl|7{<|#@\ž.j9+\sZv&Ox ']GШz|? ~tYK, .x_32c:g 4qKkTbz):s MYfn;Ln*7ghj.|]v'ˌd}l ZR!z!}a#BaMĕgzw8dHb)18ʡX"{d?y_NVxd!"0kJQ| "vutbj]~;̌ƓÅ_*>5{+ƀ"[By"+u~GMPǷPܹEim]-[+ `Hڡ>xNQLR5SN *$\-Q)o%NB rf7(?%EմH㉹mpd@b+,[:!bM7:Obs.PӰt}|ڢb7S BƽO Gx~ƬNy,`;v_iRoK("aQUt~L~>+|@equFROqW蟁]̇SMOxRU z>buyca @/ZG9$q$t?qnba襺jEh1I xs-#B܆)z **:*#w}YpY-^#S#&?zg; R9^P6[/XUp Ǝ_]+hJfW悙ETmYfh1sV`y 1tksD{/pU8X9e ؀3[ O8ƄwUsjR{,:)-c)bz嚔TD[`d{˙5~\_-2dpsfg ;'C^ @:E@>Zvvث!ya.u/1rb{$)(>̀AJ+[z$]okH_Nlzm]=f#l/gy~wF\D}?l L\)`їt2R҅YF4);t0F`_2y} >.r)&n'~K4ЇХ+-L4GZCkJ jf< <2+DcxֽTO1=(00FK>F .$&#NK~3Q8BB?QDY7&QI"P jN#hDGڎ۴SR tY4Bq/_ri1[!['~zh!k]͚|jBT<_h UVB[i9vx"*)k:5 II5h5 YdCPsW27 ^.Y{DTbi*r̽PkFAt &#d_u^tA{J.7B'Y:* &]9B ")YueϪDHOޙ8L.')iFPT]-k5ӝzW5!HsҭI XGIgA"IS:4fׅ@( h[+qhfNa6Q#4^T<~F *ࢢ7Wt$խ.C:/huB'K-MqζiɠkW)eDu:X}뜁&aSk[8 rO]?O3>^vCj3L+04dQ`1F0aK4nEwPD$S;Wھ7oҤ Ɉ'Z)Eg4Ngũƫɑ Pu`T^Y fK~EO/)7F4l_`zc;NOPn@' )蝹Prc/~3zaUdo'#Vh%]6<_ŋ@,] ^h9g$沠0heXٗ5RK9):FX:q u]=@wOdnڂ`}ǣB:79 ʥ4~Q$/d϶]\JJJcq2!(ԍIx\:*4[/.9lX#ʶ4k65COzMq; &اk-é1|[j{-dZ[‘ 'nf5oȦ1W3zX0JW^ [Z^>6vE3H0v͠d7ɽ.nz>|RNDdW2Q0ze\/^ZқȒ‡5M~+(0_ |SFoK.]TV';]R<̏ |fgZrڂSѭ?lQb 4WT͂#LUn+OܪM5GcTF&Fl*m}ULl@3UFdB랥B/2k`ƥ&ɺ[mڟE>, g=!f M!>Hr '77E2WA B9ж^Ծ?.IjAhѺף":߶'>: 8wR2 jh/)9'ni_DX(<; {Nv&$m3oc5c^>P(%Qs"06heJ,p[7'l 3 9"LlY "A ĂӠ ZAdƅsxT#B,: _߂.B$"G\*s58,u;g6fssMY PL|)mE <8H 2,VF'9@]9q?Fy4^cdۻ2$bZb /㈹v*VjV `\KY'z93sbm$FqBq815M=?˖Xbb{B,ͫP0Gw_ [[fqt@F3ME1ݮ_(:ۉ6,DI*-ux9$}gQ@i.:wɅoSx` ^PHSg\do?eqBV,տ)>pAN@ًF(Jу gblC{6! C]JN9>McXFƩ#~Ղn\}ah?$~$ 4g<:ᶆj^hY~^׿ù(*&ӱ7;mi=FRj }{y)Vh'^%i>y̭3uvԾk*+`N D/uRA"=;{&`@[-9~'N%<$xŶWgivb{Z"d("<QMQCKh7t}VzjA x0+Zh8$:JaEF͝Ǭdxf>sPbiQ}4159-Ձ1pc?آ`j]nBӇLrs.p$:CHBVӮ*d紭H v x-6լU12CiG[GEc]!̺S`X ~u-B{ |, PIœhOw 3&O /k"KKvKOhm+IoPʈm8,&[YaK8FDb5 Fh"8,9JsM>x$!6K"fXyVQan?YVu ._ɳЖC/ҹ-H" vpDw.j:Wso)LӖh VUy+c4XBTo[kf$Mi |n2Fv斔֚\lfd: HQ^ϭi~@a"R;QĒBcy݅^} MvF-1z*$]Q^C>R&0%#ͶqC^!E$v. *P20gLYUA˺N?ǔC uTP-M#oҁ+dH@ %AN1e|w gt\h nw8K)I5b? {A{A\ze8xقOm~Ξ+$ߧL 5r*̎8c L,G&)@[Cx^ܸ8;wz7 =#˳dJ_֚)TA$@p l͖HZXHNz5&@t1]|z9:u$ ̓$ B(wNA 9"@nmvn6XOECjЕ맮eԼ1.+`}Hg#VA gؙfZahUךɒy2?q7Fё{(ۙ(NϖM^Ș#7#p+&̟klMd`z_Yo@'{uR (<Ix 3 |d17E%ߗou=u G~gv(=w &3,?X^ǘvm-tֲxXGc#R 5[>GvDUjrX:tp$'<3ِ#8aac\Ä/;4Gq436q0 @W3dATק/޷<\^aةÊ0~X$n9>b𓿃,ҐjU1K!k 2$(*SP3,g:9wQ&6`.Q-mnnWNL57[m&XDAFWk3~jN g 8 .i!܎FaaP9Ҷ]:iA>N _ *) %koz- TajcJsU|>Mꮍ i` u(1foMS|S3Xd "y~#w2s^`= d'QYGZ~X©a r((_ުe4S6Pȗ v-K~}\qK# kD bֽ>t@b2gT,kM:w`\ iM(TE)'$:2H%f91oD%/=4 4iqb̄{0a Y~Pej ݲa~ɲ~i"w 7^/r9q'PyW+ z䬩 Iozяqv;b4Yj@%9׍aptMϯעeegq=Zz޵E.v$Q[j%Λ/ynr%a_+Y>w4K H=ͫUL#9sh2ˀ$A[kB̈Q ԭoʹfne[`>bRiߡ2ӆdNe MC[sKR~§JLiH31?.9(m"ۢ`Jw:-<wȖTvZ^P)uIfa7W1ajTdS o`zzzޱ*Lj|"^ea P2*tκHnصAʰ2?ZU P3\Z eYh̳g"l.6]4z @0kς֙mqLSGK0 `÷m.´U)\ȇe®?0>Aix ;'1~ѭ$ ޠ5a'MjŪ#'p)SêW9'eWȗ.1=^DsU,M_3=E㒟@|5MuQspjyuT45) AYi Ddʯ$ģ 0٤/E?w6Ɵ.PC~*h^y򾟼/ lsn Y} xmY:éj6adx(9I N븚8{9p00`e#Lm!"ynBqzW|&l <٫d!IHwZ"4]b"bjؘ_4lJgYՄѦ".ьBTj@Z!Frjn$ƢCrb:?:?J1|E xסbg #ة!'%aYGA&,zw|dH1D* ysza(j*6ёhA۴d˗lPȶj 0vcLQBhygb9EƝ(<잆-R%!;T<f[h g[}LS<)U& i܌W#5_ ?#.sParvc%IкKyG:Z8G1הI'< ̑W}9GE?y!a3Ø)( b#W g&:{3Nf?EX,; lop4ئJ]<ݡ!2v{aXv㒥)6.+caD ȯ`_5{G5hXyjYM+ŸrNVHq:ShkROyqS 8T|\3bbn`WvLfC$P,m+!&U%XQ(4>sGlumqк)l@BD)j^!TC2S g`>8'B: C!&Gz pa#ŋw r I&hCFdѵZ368Pmqz4t,=tI f&Sj'Ew$r~ᢃHdįs-C(x.X1=3%w]~)9+o5rLɍÈ]31`ב"?.gNY_Rt" x[ou!ܦg-iwmmPHfbp!3/:'?ӸUt/4Y~E <ȑp>Ə'(*b "8l!+NI?1>Bg?mggx{'{q)TB νDQvǯcJI&Fɉ9#9w-Kf?ߒI)kɬ2:;hl+ruAvJZ!zy`\2/7.XxzZSj:F͞tM!6 7yQyo ^xW")+% -'kaq/VfVvn&6pAne?\E`nw07Kn}$0e R1wn Q6xQDJlwX2NCIcJI+I:v.?5pbXf`ň"ÌUd(oSOFoKI xZڐ\}Oz}}hemXtz5{ؗgK ku"G YSIyW^9Oz5Z~l GGBh!'*ςJzKD%9@=h->:j'$1j@)&Eɡׄj?(2y3wj牰׷fK$}Q@(J!1l)]Ps ~<a$8Ydf ![jg,d8nPA08G,%ʑ1' mw?\xi#B+ltSXMN4\!}uVeOH>+RFjMf,v³6[g/yfx3-ܖM,24rPf0}@ Vhl. yLzblv/6 l􊏌1D>(aֶQ  +Vx^Jwϔ&ˠZ2bq`)9c~#B2>` ƦYhљ KGN{ ^J WVGwl)j ^2Yau*RƆP e=/Am+,qL5:驑VAEţ|*f\jԿ[z͝-kOI\h8n5lBoLtb,ݙ {ܤ7U}i|~Qm|7=jt+ybM4B:!CFsx7=)@28\;`2AVǎteDc6rх5ӥnmDm1ٙ$qΥ53fgDY&׆[6w49 sJA_1**V0麵rFܚ=h5o:BZElRҠ$^ëòTV4bt)NڽSټvk|>u=H2U ܜ+arHA&ʚ6,jR\c i[f2۟oY/%`0Ɇ9_$ 9ALv$ޖn>>xq"t¥v*W̍Z-k^Img7 Y{ߴ;ՅXٓL"ӈ֜*ߋ2~Y1I5G M,J( S!8 h]<CD15M3%IӸe d^N$-_caM++ތt"6F =-3vFy)!d%JH^H]8Mi Kͼ-4fv%] L_I=y4pڑܭFʢ/Lԩc1 sRN)ț\xȌPǁ"d?y qbE4}{=7Ie:O~s5_ⲳpsu^#o _rT[]eQǧ@%5BuAPiC$9P%v XLp6V>'x6˩(wDoGNN|qqN-Y ̺(  1v$$!KJ4(}q14[&S{î7[|\y'HHϪ-(m~xqhS8Z&KP)>Vŷ=][8({39K9$4mI^&@syU$oJTՎcid:a)Zh2IoTg}$WkmV/'}8(mU+-Ӡz .Wwp?`Fln8{o&݋QW枥o0jp=-(˙\}1kF(wst;MDNp$O W,V]c=ᰊz/ Sw̴Feq0A tX7Ibao5c1MRf\ haΘ5oQRݸUyF[m*_R`0Ub`"<h>d>i Cm ;X$^0ā} roZ (dtԸ 6bnC3N`$9؄ֵͦ(O$zQ엧@m +Ld+Xx4qDXGHOi JzE@q j]o*o ~b/uCդĐrt'!?'^ځyf F1د8Wj֔Yf,_BVyyoVzI++ 6jCz=%,\d)mA?^1EX}EOu ^)k{P?:I *v "r X:f۞+BH [A가jH\n1Svӟ? ;jl{p)v3VrFW/I\oF=?{ҡ$Ar;^%Qy" |=;ؑ0uY8cGt)?‚q qf7'!J1lQ*##Eoy*V^va/v}4(3oičKw{"2|:A0* $NSNT8ڦ[JcD׵$lK0?vq,˛WXJ1gi\)8u@7nև T  "oѰGʙ9`m_xԇGV' HK-;Ѿ9-c:6ň~swO'ko<0nva|e\YܬH4p0On͞ \s/L k;:G;I ~0 i-})=ͦ#N3bpL=_*|~LFd`tRZ&sS;8Fc]m.!QhIGq|KŜѡWU3estKjT sɖI)GGԥX6´XI}D~TnPۑQp7|HFH X1cF%%9j6)jX5,DLWAOl3w~xmCofgZ?Q2w. )*3hLȝb׎xf}-J_/s!ONW} z}aK&B j.Vx_rQ5\T.cet3'|J)՜cfF>smfv'}"jѐH^,]9Z7t_0ozg}=yU'7xV:+vUASoxxw·_pISqHp!Lcgv[ЦIwcl@j#P-5:$?lkjdZ]1_]m|;P\!jM(cA&2̓w.tpU*n7.;rMGiUSjuWӤ3ꍗ.dNm !ҷT]D?pX g2"axև y=MoGM[VfSsBqm|m"*դ砀oHOh(Vkh[EZl`Xn*ew`T NxO6:C3*nOy_C% O 9:QHR_xND BwTkVJ&5c XUчjC O$ y/c+ϲ"m\:'A f#CR8^G&k*`0EHC.A]:Hx)$q[z a^޽R -G$kajaCr<0H8Vt{6kiwL>5F^o5 i5W8 :թ {C\)gfx|`*xP:)݌);fI;xʉmT!536荄i~ĥ8op;'sdfjQmԣQ vSSpip۔&5s8(!9/v+~۞߈*mo[6ݪ]H ā8`Ƞ;'$(3?~u񹑀4Ӭ? Am"M1T"L .ѭasz-(9Q8F|Zfk`<Ji$}N\?2$Y$6Snp'I+v}XA,~bI}ڧn621哎^ۓ"H?S`иxKYc'R`Q+l@T_c` _l72╭@udaHarh&k+p1G+gn ͑77)2NWOu: OSY1R$AL E%Fտ109]h<_s·'pP2iQ81m1͙-|C"EQ挓֧ph j-mN( Cω菌ځT``TR?B.<+㷾D-'ud8p6ނU RاCu9ADC*knlp{^  :sOrE9>|R b`\c Hc-imiD8h:-&caU17/apzbJWcmg7LukNJxq dDk$a#1ppoS5rqC*NAD|v% D»v>Dsvw9v<`9?"$Aml=JÎtXJb@3NzŎ <'['p!r?B d-eZhMN>ׁr {k{xTr_a<_FH_澭iÂk L/j/G_Ѯu$HQR #[&[͏{ko>492Y(0v?x#P0\_6bSlHc?>hp1_-t7qe9l_5*I# |ᶃaq2Ui&M7d HV/yOr*ftoKC$\I TWwŹG;)I2+3:JQ)NGemC_L0tNz]7ěAzuvȽ~_A?FщoEpPx)u/!:1Z$$D§ZT~vwm<bu>t1K^,Rbb@A 5K/B=ALa[c+85r5_AI)05Pʜ*;URŵ7VJ~LIo/3jNq?,_@ycɘǻ6ʮj`ӓC:,h%q",`4Mj]ITL?rSHAj6n/q)͊@bQm],C~.GNH!φ ﻂ/V swnchw V4\aH.䓙np Ai"I1+!5Dûd Ö=UG؊eoVhE~<#ROa~t̉Vgk3t4 }ڮV:ʩL+k^YqYaQ%t.UP[r;\4PInvIi:(SbWgbyŴKغE uIo,^biEG x³0p#>Ȟ|sUu`ڃo ;74"D;+8 N )wb9F C*EaBX^~ ;0>rG @yJq|k9fݳdt)pOuYwHw+NVHnӲ[:TH M&y$FӒjL!mB ~_}5)pѿauiAit?N\} ܗ ꯈ~d.~utǍ ?rꍈ<E7!E&4md11E)q7 mBRC"J.N8R0ʇЛ`r5̧?iI!7\1~]ijVX PXd;,fu61}1DsT3_ܘGG +ee^tUfi<%rv)+ePYm,-&Zp\tXQc)&ο-Nm)a Fo;wʍPrI׍ņZ{-!ȟ~g jHiS>)@˃TY=3<"VPZ:!A=G:9-J8;l/fhJk gkAK/88X"ڪY2+<߻8S}S'T {2Լ{B&rRqmjN' %VЌSiElT^* $a)}-:◒PRe&>n7F˨whH>;D"mbMm{?7Rd]ưrjxIZH4)rGS_ZMKl y;؅hCM/)+ +sԗUbVqz֮/S+@`\?+?Bb%_jl\Er/0q-uv,UXjk@( Av;D>NNɸAx buOt:Li8Ng 깖Zȕ,)7䲿r}a*,E:nXp* An8Z$V7!r] &R2ʽD~5 2`^!jb aj 'ủgT~lkIdzgĻM_G`XMM;PaSØ~E!5GM\?I#cBEwtuX6 &@TS=]S&K&eA(IChd84_2L:?al5DẺtVq`6)q1[CvT s {!KbV?rhgR/۱*ěg;B̥a'QfKk,wLjTm6x1d.n݆( ̊S :RLA2$_鈼nO$9h\ޗqS&w$$13 NaӎweN~X`{?QubEkUs\VmyDbm93Rv>w6j*yJk>G@M 5PGM;.} vk< J$chyRoN43d]g΂uh@k{t42]̈́ű.!R+﷐X%8k>{+"|XPWd†XrRplx(X %¬ٹ.Ebb" R 2>=i>Ƞg?$>{;\(DTFp݌Cev1HyteN6RgD״r@?' i.5&vmD9hKݼH\M2D}D4Ш'| (.hw3(f; 62+у*5i+=Rf4G&̫LtWpskt$cނ&?ӟ& -WbyAfZ?dL`:;_ѰH!,[yZ^zXEvtjh=a@E]yp{ħ wO pEvߊ(_Sa&jEQx0S Ri(sٯO ?!S_wGqX]Ut#e 6DaV&/T8] F/C]m& aR# Gh )hU=Q5|vyHFudDmo)5r:ԿP`=G/"lrl|sa]kצ@OՄMHYmNJMymZ]hLJ=fjT*->&@ tś!8-9OFj h W,bB޼.pW3l`h yDw^<\k&.|_6M[|hk "J^nMQK$Z:gx[6 #ç]Z8vwSoQ俏tIL.=Lpɼ&rŢR[\ j ^G߭JH0MgRPZe#9ѝelb݆#Y;AM`qo4A=i3@QY +b*b]0ߙBX0nQҵw-E@t,'_Si`7ysjo<6nݓ)Dtr@OU`7S)t/VrMiߑnP$j-)nBܯ$^Z1&S<,0,hnE j@x1Xf(ۙ4 yڣ( D_}*eoL ?)P]]@ߐi:DDh@ aK11H#&6,ؐ[@ڰvj#'I5ګt0!02Ө8rWۄa k#ѡiqשK2lOЩƒ˧uQ2xao5y nR2Ԓ1upԹ`µ`avRKDy (;cMQ{3?Rl= %t9O1T)] ?(* 5 A*2.m:5S:ȑ>eNwaˤȚ9,MkČyoOZ# aN)*WƵfC 'W%dZ;zéhi3| + Ţ yL\꺧,d3>p6*,ܧ:@~6): eQO = ԝ2f!f0cԸǻ 7Vgi/|G7h)+B4!di\?ðƒ[׃&J?= ę. }{\ae= d̄xt2:,8`}Wm!#&O$]Zw9 YPI >cٷ4{DKʁp [z RZB^⩚Thv_:.7eMwz?ojѰ" ,.(H&sO1TN3'Egǽimĭy wdS6!?u%JhX\Yvc+% ^iCNzcK-.ը+cëT}TlF Dy!-N`:Γ7̀g{ZM&SxFy_iS)geY:J j,uw4bɳ4 : c*N-#Klk !>P.G6ʯlW8]-rY?yKG/(eAƪYbwb>o3-[>ȱ밑ƎBcRL2NQSYzb~hYgEo =䓌סC+ FXƻ0_&# W L<1 'zbvEލCR &W/}9^~;.={%C7uMܾ/;X**c.KK3-y4)j $GQ)ۉ 6b? *{^7.ER$Ǩ[~tMHo|Pnm-7=tO3Дd""o[ubG$Yk2~)@FF-Ҹt:gqTm,1hi alMİ9%CG Y&/% %KB N S}׹n \5xAM /٘=-0HjB4N&~ /aw)sa73Rk Pמai3s{Pt7R{./ݒqڄzg5 |zzQ5 ڕW7#CHBQAo¼$ F?H\-lK)@7'(0Wj IDS]p.>OyEH oQh`h0I7kn]7%̯[~Yu;yW@A &_4%fUO3JXwR'5]O|*"Lߒ?m6EMDd/Wmd'EQJD*ت|l4'T/F 9VYjI;~25/>;+}M8_MU"1ɻ. DH&B0ذ&=$C@ robu45ή.)Czӌϒ8ʣ|~֖1ZdQփ_ oIbwrNܹQ&MV~3[ATTh84mº)fC~M<k(a\ ʜ#UFAxyQ05-1b+45B[/rϏC왶t2EsdY#@Όf.+ļgz%a 8QN丸k8EF;u̒l)?!A_2$n!8{,o>e˞:fvnv',dz(;F[\w3.:ٔ&@V/Qi8O~iU_ڟyb"s}է).zb`ΤvSut觋9 B)sٵ8yL\(XV]K|!ilb-b11d(1cCQ0nH̖ Eý@[H`@6k3b,<qnU⫼09kkW-pB!"rܓvU8JGF<14vbtɂԖRQ|0m)TSKg ]22#(]y NҶ,Wq|#ُ>~#x_Q)HVh{ɞrVGOLQ'ygkk>\jt-f^ku֥j88jl4rmx"f)>&c4IO@qr;0Fm^}.ueeܝVM̈́nW}CFog~FpA+X0!`K83 8k:v8q 5 ;s(2fFwPRZl1ڛž2Wh!A~ԕrTV'v@]5"1>|ijesGrNc RQfEO]-t_I"D&\Vd[Jm߉|7(`يuv)}R^1kni%]w-Y D0HƀT譙Au,g3VjBg0cBIsw7%,(P'/]R\RoÓrJ25^pK<:)cf,6di߃Ŋ'DvN:V/"ctIƙ"fӧh*9~K*#9x~83qs13 12 ⅵ ;{2eHY^\{URe9tr.a%$Jn|ɶ:BjtBH+6F gO}\.3̕NZB0Fٯo8萯{x'/Uk+ю s) ]d;k3GWSlc%/ҮZQTwK(87݄)ihKu v# &9"@5TD%zo֒Pe)Pֳzl u(H怼|]"f~{9UGoXN; X"]'ˤ&5=%3vi1~b! "O ~1LlUJ]x4MR}ү>V3=e[{<)E/i@T? l/qOʌĸ na{7A&fgC5,*xCf3g_* ֊X5 9r2MfWrlvf]65/nzb6&K n=1G_YcNKJ:^8ˇlmAs!د-9q5oCT)Ff-R qtS2 s & ǭL?m۵<=!L2aJoI4j4%*'JٴpJܸCAR2NR-Z"Eڏ`VJ92/wbh̩vkZPט!enQ6șRVhLCca(5HMBqQWv a)/zO=R6ɄaxOa>$"g\qy!m"7%sl-]08K#mWp!yE2')0H[Sv={iT<(/ΐ1Ү2ڲžLj4hbrؔ*/Fi3\“$A9-t4c$S}VLFF$ޠ(b\JD#RC-j<܃JZ:[QURjcK-Q*Wf~a+υ6iG@`֣1^w'MPZ^}|w8[_ 0+ƮJS Ea 7XL'(WLF'TX6,:%v<и/Z8-Z<`X?|90'dU0H5h {gk qE* !Y"=ut1O|_&TZ\$uX%jd r5ID{cberɏ"̘?B}A-Ah%*$xov=HrGVكD=/VFQ);K|H,V%̙aҖК{Ws4m 46ٲT cܿ`%rf6.֭$iN`I\S`W5ga5iFRgט+7@YY+RoƖk/(ng1,++o7:\mHuWrNtY6z.;]LQFbbDv}-*%wT}m).H(ɚN7V}Y1.;>)[P#?2K{DdtbõKuc1PK%]Ryp~U2|D`^tqcSf`-.o՗[29 nwz%& nhBUlةCjw Jl%.k  -&Ɵ^uCÏ9 [qmJ=Y( :gܬ_~H C<܎23#.HbaN:ݾVka%Y9/++bΨt*W3e6 "g6GC*UTn+fQԼzFX:V^ qz%/Y}msucRH/,e;fg՞t]XC:>Vz:@^!ɦ@7C0T9s_O+}4s.*!H QGwhMڥu둿RR&ĂN [g*tB)"t\G.AɬȼuFfPƽzǃm#ގv&9VfI ;c %eFI}aONLlm!DeE46-;Pu۷li4B`\J4#ܲ*@l7ƭw:EY~Z3BXe¨ʔ_u/8rHym2H <$?UJ>T呦 =헳MJYbHsNOC&ygJ]a߀z4.B_0#J[, $lAļOE; OCqpCUЉw{ݼ;q:SD0j24F38p6njd$dM,KrY}4D&hȨ%@ppt(<iq~ALa<"}<[ \^@;I 5s^Qf{/uYJ[/eHֳQ.#2^l3%#[wd8Iﱸdwk&[$cmh3pi͓.98@!3_YZgO&a5H):b'Kj9y/kL_BӲ֡667(|kqlya[Ia=aJt2K #p(@?_:GLcp𘴓:W"GH0$+^A RAt:L}0;K sF,KIU^scߢ":ġ,x_t,?jY`1*1ׂY>J]Ws׉MTC_sÔ?o(o|(g*eMIFax p|K3oY/*, YCJYSi׊AN5XkԳvVTB4ަtˑ2 יr>f.xJ;d90!:l0*T _?XsMZ`[m 2 PXFI߃S OኘӢG$md#: }Ԏ@óX oE)>Q:G0FJr2gN:ë,`ψ%σ, ~:A=SPR6<)A*5J15'n28b]dw%Xr5l;=MXh:-"w f9h \`_.(辨VB`'cGٸ|:m&?dԜezҁ67(4zEGG x< Kw3dqD4c@\H$ <{ZAx3B"8,3@!)6u֔_v7,B6NSCb LjG]]:ٔZ0?]=z'7$ESp'd+bev!>ܖy" ng֩oa°(]eXc;j.yg ̍E@MfbD}?w!.]Qp̵=p 3#K,%qzM# Oq i0f[V?2s!"" Wh|'Mbhby&uW,HѧZ/bd+( BRV^rA6Mn5/Ou#3xWK~; ddbg"FٱXTI~^ Қx :cW+2н(:` V]B +ɭ ʐ7q& }^Tҿ_u<nQ:[Ii螏UgX/}xK%;l<Ļp5 ժ 8~u~x J^٪^Pg]uGp rE'H+y pPdfr-RP{&pZ*0JB?:R55a7,v긡 h ZZX@!cԡЃ>ֵ4~)q2m3(3Kv$<-Z%=E0[CI X:u]-ۘ=몂˶mR|-rhZaEWv2akx}-Ӥ'W804Zƕ '7 c\k?%ԾD`kǾT^}FdžZ(<^" )މIxs۠`PC(40C8TwU~V=xxEc2=ڸ3_/ MJ:R蜩Y$f~Ll$Ġ%"yM+]GvvEӾQ}F*gogBdxupdy)z"I^v~kvʻ#C2m fm:zFP .<Ð-ץK%lqGAY̕is',$"L@hjfXCm y7|w;2iksO@>wn%MeovE,ڍ.HGmѯ"X}/Q=Ou^}`77{dl ̝B }}5}LR*l-Z\:2^` NS!1Ζ_vSE ,gl>,+?^H؟|4"e(%d4+D@kF^ za Ϯ4(]^&r ÷_}F4 erǟΒxF,Hb'{T ~ZjVkY5k\]ROP1P%fqB<*3kV}3o@bG&o ܔe,160rjAinYVx7݅(9{J#e|ࣟOVK/rPM n*rZR^Ý}<'SpLȹzS`D\G9x';,qDݸ,+B~ 73UBtH1oq) UܒOdm@_G.@n˃lpz}ĽGȊ4xcy'Y$'9Ӵ3k laS[i+\^ȀSçjq`6)b0O;8=\)1Bn@R&L'J\y8F@,OG;{lGzYVw;|ɦύ{:44ֹtJ  zi4TH-5̘x]b4+~f~u@Zxn.KK ](l3#ww ggB}pAYGڈLa:֩Pp#$bh.N (d`&gV+֞ґ_fkQ(ўTd$(Nz?.A56r=(Q"$HZ9՝zv]"ƔSi}ԜtE%sՎr߹DeyR|ZXcwHY018NإO|-awԸ`^pI tUಛeB6sث"> viSkPⳐj 9$;ػG[*Y3K2'] zú~ټزߴ>`k(s bلl?yb?|]_}̟9e\uXV;w#!9$k(ia%AG#(b'|GBgatz MwS:t"_ H9.(ލɉĐp0s6B*ZH 磘Ct3'Y qA9Fdh 9sf[z}#Qܠ}m_Au;h3-:qĠ o  WNژ#|!^{j0@W0 qunYgGG4@\4MT*|>UL= rL0 a|N!w [7Oe%iߧ\W[@͗5<ֹ Gż95nș]VE imѝ;Tu,Eb7/DNa twm!? xܬ]@p&1@_C-_/^KA:L;?%^J6ުǴu4ɥ)0{)"(8C5]sr0 x8ѿBL \û}^ cDi&Dr<*)K:Qޭ$Bev2uNG<F 9$j=iiJKҵ+D?#.h o!\l-C`uq.)VL|#=8l蹀*#Cl-mK?<!b"LZm,6V[V*5K/zuJڢxN@/꫈Uf !qxpzTutKE37ݫ]\C3Eh?o͊r /墲޿oVӻBujM|fhP+PV^W {{M-0}j70#w >xL% {xflkyC$*X%VzAM"zTF+d_<}Oz [uIJM`JU$y$)H"O&UL: Wo'}6 },iϯDORդ5\¢:mk-)4LE<蓵kF=FO-|U{q]@Ll+ J6neGaqHcHϞPZ҃g"J0lqKs OZ8If[ĖUӱ9nU13ƈ/p IzpEނ&FocC@0iTK>Ő 2G^gtAI)j=qp綶$% kGcx5a]=D8ߓG1ju%"}?wn*qK UL׸0]D{WEveXAf6,t.Ddm.틉"˱9d<'vDN]P8 2tRk:P-~Qk(쩕z˝55%!.--xv3@Kޔs>;a)>mP=KZ3σ8?Gjѐ =Y2Dn)_U>Qp(fs٧Աy(degқy Ǿ߱ȃiUBC ݕȔ18[o)'[Ż_^M hL=lj0i3تBt5ױKR$fy* Xvwh聲)kdա׏L_|HEl{>N"bp[ҏhAϥڻ/9' bHҬۤY_Rkێ ~ 9$] l2NI'S|թO@xa\T2.*ȰLzPE45uaDTL{.,}T‘pn`{~F"Ev.)61mKbe~gt&-b4Y;Qd!EX;2Vsh@θ?uCp.@y-!(=O HvMó䤀K(;z@ڥw iTa辭kة:t3rW+1H@|[S*ݡ )F$h$ߴD3h5?ĕ{,yokVyx=7 mĎ`"{B/HfpV1qe%{sGq?OeU` rʰ빞|z1-[TxhI! ``®e)yΤЂY1u;[짩 ק: e=:&lZ7A8Aea;(zqú3=< ifoIƠQ ܄cpx(!FmŰtg)i=Ľ] 5s aZ`p3R zj 9J/EMq4KMByB%1WN(},S(5װz-c<&\|8ȢAy2ʡ`Wc/֡ž\:w#J,4Vq;0.BN],8}oE7l3J܇B(8=݆uu%$O1ɺXFt'7W{Yݚw;/z쎠9kbkoD\Z#:'Gv+#r4;~&]:_>iMrMcH4桩sY6.['\mi<%>6}, X(o%e%,<3c%-j/#P~ޱi\jey#]5-5cLۄzfbԘu31`^4КV T!->A%Ӆ5k&bb hlPIڇ Nk 'P Bu7zK! z ޺Ѡc'ef vOȉLA" oKֱ8o+}B[:Ns0DͤonY<2$RawP wW3~%)cO#_Y'QFYJ8dO3Փ섂H:Jz0DOaۍԸ Ujup ނ¡8 {z/u*K:-_ZǗ QfA*;0ح'vg9&\o7?tAn)d¡@2Tt38q@q Y 3e^'7r7ߡk4el Lk<W S3u:s^+ܽ~:r_Os?osiiTjpL^fg^Fa~6%3_xj)ˠQZ䩡K2vgj<mXt$J|BMg #j}}I ,D|K==fT(pӺsB2Xm'H:Nh5COXы' rBL"[C뗚rGmİvUK;hvZUfNo]dMXeCFQ!)hR+/GCLUk /v8}H+$1:`UUͪ1.ow h݌m)[2/е褛,8Z`blTH9,,,%>#b]斧KcPXYH3xw6p#/$ŠI~H/fhhzItO9cFG/!XMV_ oVcBhYA)c`maIC< ’j;].p!HfMB*HdL84D>浹COPG'o;`'E1# `aˆZ D{p +=0 \6[W"OO\2/Zwj;GD[4ECo0e0Bơ Nȭp\HTVڪx$eit} C.O9QKkt/9of)+,~Qy2`? jRzH2(h?K" ?Okf4o\ :63yE& 15҉oPՃ@'9FmQد#!YX$hPmS?3{kҮzKjcisX9)o4y(KtUeà3JL*]~*nhۛ%6ΫAn7M:Gw3JH_\hm]]IHŜN' iNLͿC٥#IDr?0Nm:mt,@I й{Jͥmy㕓8k:~c9o'pi>헊leHJ7g5\ҼdTe [7Y.Bdi @ɖf5`Q-R!C)FB@Bp}QКu\f>"OwЌsHDx $s6f jp}x/F)OM)Ai7f _ӛJ bG }u)hZ p]lŨұ Ij0o0Vѹ%flO^Q%824 YIGmv\<ܰCΌT ]qrakYm]Ee'jDC;Y,p27Y (*]xUz~P}3|uL hEOV&7EbsFLMW)}(uNwN?Ř\kw战P w#86QJq{"?E!إl!Dv̰yb5S*[Dj6I~h~!wI[rrR!25߁\PLX&*&k|OVrt-ʲGGV4q\Hb憓M9r6N]P3p\Gniuf#TT%{gU~EiY{ԥQsn;5ӀwqML8 `9 =H}-Hi<@K:;RyzJC!1E"xqu?Wk4w NzLo!nN8wLSTWkψAk0BIIJ ¶4m=uDX/Y,!Wb= k ((8b q@/ո2;SVC&5ڠX$~vJ.ZD J7{UHZaP@̺C+i2!.vKIJ%M\z[@p(6Tɸog"(%0L.s>+TC*PS{M1{?9U|q1]/m`ZmMUNgS:jgFY)s:TswB~4 qF=oϧg;)mM=-+nmX æ",NȷT.#* 9ѱsj_Q.\Sl+ D*kzVG]Q}H_6ڎk!dm\{AU˃ .)Y{{i `8 MuUnE ƌ)mlm7~qXcm&ڴL\tY K_=G[;j5[IEÉ Ŀ3x> @&^cݱ~[ZjAU2FnSA|}NF2~#־"O&z3?:ls2H@,mb,J6x@_ScNp)DYɖˈI;vRDwbgeH;V!, vhs#.W *}s syF{b|޻:pTd;JVIA`y`QH3qJ0 k:6Rտ1ʠ@sٝbtH*pmª{9MOTT K837$i%$Tyjʆi [pʭ7:x 4[%G# *!Kc^~oY"t?heͳv9x8 ?EhF*Lfzp-V\Y*̳`~C]g׳}P) HM*wt3;qe Ϛ@뵽 |4 o8 Y"[4v_Gzݙ_~&n}_-G\{g H7qvٚ 'JqԤ$WחZJӕ{XqOz'LP)np0`(X,L/4V2${ñ 4,2pɗ3Zy )袈S""Gi,Bv+\LA.P/1JRm2)pw϶Lkߒ-!'nvfC*T}ZPoG]ގ&uf|G[B*<|;eL,cUYE)OM gkfks$%&9+6>οj3$/w@xVXƜ:x. @u`FNxΖS+d\50pdx,^CM>}@ PJ6Kwz5Mc^іh}R͓tnw?wX _1ShPsW9AD})d&rx!262={?4DR]x]C7$BL>fQ-YB?wbKkQwT1N8~Z;4YӭGŸLH/J3EZbnk&"]kl?Zs̭y6AP{ņB`Q?F()a0_~!GGkiºyuB@xs5HMcrxa Y'ջmgE؃,tlz&tRs׬[)-Wč;6g$+| U8ǃ;~㑴^ yyY8VsFHvVcmS_63עXk#}!8hq]Q&X_ܬd 6JAN'e 9׭"|ȕnG~=]Ka^GK|0jd0Bw؍J6SPMW/m %4p]Vx6k,)آZ WAG 떂 ?ev`IE{>=HxN4V[_hX#Vyx ]VxƏqgd[|IRs%TKP[}prCqxM@!>L__1AeM6JRoe  H f݊qt^pnj-6:orj<,waW8sڤQ&(olO <@DuG_h@uёgеFST>V̔Y?o>=fH =)1oꤍ%"lJ ~ 񙴐fܯ^cB Lh '5|4)RS/(m"S>/ؚ)0EolDmʷlD1Nm w#G'R8ǤbbH8YKNr=d1Pz8Iqf;m0m=g̓*K#6ꕊ1 O"1 9| }h :COs[GzK1btݽf5vƤ fHjMnlঢ়S+o? QXѷr9']NBz+.@@lssv'!87`gadaۖN(QG*]prW,雥!{i)<`rԉH=,9r ƲRض"C߳=8X}ZJU=`+ٳB~$:gؽ,^N塌*I2 傱e%E^̗6 _G׻ \[3|fdÕKH~[ նA2gɣgslXŭP?TƺC!O:E^+Hz;&^([siSqoB̭Bm)! @j) ,;M`j/c/*7.V<(zQ4ڸIC؈8ꁝ'd0)A$8BmX)}ތJ^z7 q*b]BoWoi#pl Y2Y$ڙ<pI~S%gE)m\NJ&ȵRD)(x^,DTuQOaXivՏ_@Αf=YEP:{JMɛ6\ixGM&kd֠H?T딙-b%I@HzV, ;H)&vVz4̝7qB]A].h.V^s]֬R4s-%)hN%lFsn2Idӄ}ju~>\`(1wy1*\8Xn3i̳iK}g8\oE&2 *dn jNxѧAO _&~P-ÏχKI#9ӑ#} k'lE v|㗬/4y{мV_B$^W{ ZI$k4LD%cx*`X0SI*t5CTvK3*X?`ΩϦ6 o0nZsw'wB_ Ѝr5ĕf; ~ѫKnklGAnsŲ .'^'P `gDKYCfʅoydt{Mu 5tyB!j:lR' Q 9yQ(YZX_m{jwvU$}?ƥ'%&3,E2KhGw/ӝO}Rv*k,!k#Pd >[DwBO#%inlV*͞i`W@RpaCa6#nz4 <\@:,,+E!9#f{ѼJB%C 䧄'V z27 ZM~Pi\1$(Ih!*4aY5zM>OOoOۤt%7}H+Mz#OnhXj\lG41c)יKUK@o SVy0'Wq0RN?!sXx:Ysm2v{., dqf!\w % !'Ah4,ܬ[Ru]l&?ؿrSP!胬e(3$CRTfUA/b), ~&ՖȔxvC@zE@N QJqof~̌YA'A$H';T]eJw~ r*d :w݌56q ݾG]ϷQ{o9!|G Mۧ_Wumw Bu]Qyh_$<2&FeпHgl3H@ B;/Ffu\g[@ڊ~ɶ=7(*"IPv!aWM]C9_??hXCaZSDU~ΙKgfh#umȈKNʞj6}s7?Ei\fxR g@P5 uq< :ڊ p}f o\ HU1;o".wl,oϭ<g3`8Wd>VGp>9UdBNiRArG)q] v[[@e`D$A(!T[ ͖/8'>egmR\<]{(Ǒ*Q]U󗶒:N"wyh}.=xΈ/Hƙ=;k+> nst1N<K1. Y}a .L0v&@`i3n#EtO$8(_9d ߒ h9v9+QhRe¡aa 2gYg֜[ u'QId8|" d>1Tl{F]BuJ{X9\]m7fAq`l\F~ؾ4nzXG4oS!Cw^j XZ[&XB +4 LMT_B9akqV@ }id0h b5fi@2xVqXIqv7Cⵊ~- cOE2 r!Qa4(Y*fDGB#řN'lv]$,t c_Hug!-W.xD&{ܐAd>CCݗABiizN3|t{'hہ6xJ3 3B mb㵲s)We[#8&Gf'!c^/;TC_*G/ awU^zr@琏&$xpE*̞|ѫ״IYs +#ZqD JêtN}AOVU#r ,ۧXGiw^g9@ }߹*8f. ge.K]_?{ݵ_YZAx+sJ},^tG nt/|C9>nVF:;fȽ4&vj0SQiQeĿ#>S+̠E?܊ P@zJ*)1iMWVI{QkI3G9 Ēշ >VsK(Њ*_ǠҤ^Lj/MtKY4xyw]Y8{">Xf@)iJt >6s1wmOт C.4N}W%ӊ]\\,tX<%#M߳rFȵ_d?q`43\uˢԫw%1~1Sw󺙹)>X4WkI1=lxek >%=_MG\j[EؔXܡ9z{ծ}]젧cim7/g؛myHNGl/SSkɠ1I$f&,pEu\CQAt0p:稥2g;SdWrsaS"maC% mP.Df 92~" zcD@CHieW,=%Zdnc1HYO$s1R`B@V Jn&6SGG'lX|KO<]rv<7bA-j_EyNĀ={ک&2[T\nE.yI\uF5ms8E& Wa69wTVKf]CAL)bﺣb-jݍrQ P/]3 _D2QĂK C鰘o2. @oI2&:8\n } kc:ZN26~3O֒ I ^_=nE̋]&&у~/.#AgU-HœvS_kCaⷞ@qv:.ȩpޞ2^{⓽!]!{>ˇnPf#is=UIMθRKhۓ]?,yYB\j#ƋK>ۨG~4N/KfO骙 f~X-\2'*s6XHh2_1k@"oS}{xt݈28$,":myE\@B4Y#ja5Ym(}#x]$2&9= ng>$|bPcbXeT^L2fDe/g]g*F|rTE>{WwXⱥCce-0mm3!N-U>dw~7kGs9Uu>Zɷ֊ž+#d$j|'eD'& Ű?&}-‰\hwkf4*-fisij79E;$胱d!$ 5ͩ({䄳.PqC3ٕ笕/uh󌿾^{!  '%cf#Qhe܃4a5tђYΨ%0/mL 5|g<0cÈ.14uc;H-ez''gfPN#&˪R에j-L'´."'xƱKB `/ 4'ΏJ8bXڢ_S;) ђ 1p͋{] rS^sMWx# #Fq>Dm3ȮmкJxk+ 4\pyRafPK=._qXŞ`Vm}T@DZ%pCo, ^ joa{f2(~&QQb8.4VJbuvK͹~i޿To fYh}s2CFJ˸+9lRr8#͢>: ]R4|eٱA}V+YIy#aPZitkjtý(yc֒%q(Ctj"5:ɎoZ 5x(ptV摩++ofX+]u b5+?B=kGwOTtI|Ytʼܭ/?/?cyՐx^B1bmmSJO LT*Gތ6rc80*Qb9 mm~hn wK ,:TN"E !%}^ KxXWyb3q^U.vM`5xz?7!x%Bn0qj $vuܒ&,4ViSEלR)u)^o\=CC7 [W%qCt[t _҂ %:6:k9~J9Qӏ2+O/f&ؾhf彊)N028j){l̟Sco@;{oeX 1 DQnPpSM̊ jȰ;}2#ʍb0GrEJpyK^>z\bƴ`-Q 3.hcx/gKI_ 1b.B,$};F>bk_qj\4gCOs@8tVALOwF9Jc>*{ۣߡ -&b7odDj@B}FƏQ.9ӧYԫZgxFitgP!Վ*rrMǝZ캗KzpIRjyK1y_Ыwcd8ef(8e`AjyAedé\?Р_+EK[L*tC(Ts1dzw^<_dG$T2z>iØ!jMᪧYX=V.VskBiЙaI8, BĶ7r8Ed⼵B,SS*#Q.HI Rⵞ{PCE~TXNPnS#Fשh,Q ;}y @=VkqT<-{ۋoCCŪZӔDū4 m p攘.<o-. $u9vNW(Pr0F*-%)`}F8 k>ˆҞ4esj*L|^ːlGJ̜r5^$oK:$E^~Vju1"_ jO\xogTX"ǒu"Loww4J EuHB;n 3kqI$ .ٺW3TD1۟&{2YLv}RPULTU*ٯ4BzR]䏼pp`qТ_jw{~%h@#w@q=%#+X@Bf _%1i1p7 ͥsMXRR"LH :|,+S>PU`uwvH5M:;uTNvݍΔaP%K:|PÎ/i1|fnU/0lq[]Q fWKOL.^#-^'78zē!ײ&2':%8wmykV~j,𧈍R}o9Bj1쫬,ђ!edKO}GIvzi#'ӻ%qn}Yg,?=D71t 'B2qj9+KvT@3 #H]X[ߓ 6Q?C{OJÅ=#u׏I{ϦԴk(^͂q ?4gO Yc1!]*HsA#Dc+wK~E{H8Չ]0댐Wy{̺=Φ*8PA t_ T;Hb^Q:,ń1el1{{z X_F-'yH"BRەd&>gfDHl4.2avʗ {J.a$y.ux,rݐ7HLd~|zY`fF+"P׏njHiOVLEH_/{Q-A䃀Szx\H NQcFX"jpUW=)sp_=k׿g63,uBZR0G}B1*6 PŒ (NyRn{Y&@J;r*^5=L6Ga$H..)F#inm,Ža"zQ3tBG< ?WӱxpdqEu6<߾4, bH7'fbc1"Y>)N4#+zh"Uj3͔7%`DWr{B6rJ]]_i C5I%^l$UOӃx},vA0 fA%-i"Za <T(Ʀz՜o = |J]ǻ)< ))s;Q9YI^Sx=qʀW@S:X62aa BX=6 \@eSڴGh` ؂lR6(7v[۰Suc _Ē*w. e3;gO4d}$qC6 w{ K=.0IO?D~ i%>?ʕ~O\vo@(-U4(V^g RA3Cri+@jC -ܙ ᓁcazb{be4N!5`Mhr;rɗPmD6(7|9@"ePu+pAt*B F:5 Ou`lqd4=Lح 㭣)Puh-\U<^ҵ}#zǸiGsQяLTt rQ·:܎@')Rrjq E;ۓ%{#K`[;)gK AѤ[4'6i ~0ϪI,'zEmTumLrdfCy^j4Žqvgfɤ,/u˲(=vN$[*wHb=)B2rIIDl@RDS2BlajDs$@)PfJuyBfɞcR)xFvפ'5uu+4jO*]=LV+%VCHHh°-yIƆn,0X'Z@SBUmyh3vSSVqϰ|ӪTv +2"?e܄!<^iH@Т&C@\0ȁt3h$Mғ 6B4\NķY2 u GH/z&~h\4Zl.s<$_z. +S;tY]co 6m}$.`QpegeW[qM)ӷV2B½\$+ς0/`gҔAbPkHO h`@w'#!C#,;fLmWkH 8ݪ:n5=SίxÀ>C姴S>ǎqkmvRmoۆ^+;÷r1r7,agք`Vo+0ROu٬oEXa:-NW$0iȄgt8zg+Dbk|x V& %+s]-d877̗5|΃"  5Q( ϫ/ĻB娾l{ 8::~鴛 4ۊ4UPҲ^Ջ=K;Fc>4qSu9($ppe  "TotE!qI z0Ĩ-*gW)cjmorUUQxF@n/\\iq 08'YhvV]Jr2^"1eiIO !_x;xpG&7|[J9lR2rz-?/2"3O_$M[?4'鈓j _I!򲫴݉#N+{v[iFm>mfjWo3?i1P8z)vGi|GȘzP(yA)R.Ӂ1TPdkJOl3*+iنNYݫ*^3' CxkE/݊!=m0W4~$A gWpmdںzw_ڄj83-+gJ7dqn^'b//CK |wc֗Ҵ&UE2Yx^";8x7ң n^uhPRP} P?xZ.ڻֳC-~xO0#\].zEÊ (C{G y:5^8uJknހuGy=<a;d0ހukoM"%S^3Ig'y3?}`*)#E'-Ykln%p̞ /.@R'E?bA<[G/6,7$q/!?YotKK-, J%v<|h6S, 9ӝG |kR[^U Ͱĕ4Xx`=G".Ese470=ZIEG8'6:+ajGKE酞\6"pPPN&y~eNyrZW4T{1RIn_t >$V}>{(]APrKaAfZH+!@ j"Tو͔*lc +@l\CAIZvsC17X=)Ɇܔo>@(P3裥%o tŰs\)h]xvIm<vDB*M)~m}Ydn ,9{w|+5A?K:3q: B 3L9 S!3"p Ơ8A+>VnO~Av/{ji`s Hϑ[(nQQknc%0&Nm`YTu\>Il{0.Y*$KBU hF%9}(+HX-pnW&R l:3̷U p5A-+fhJЯ-ժ%Hr%2<4ZaqQl][=27 M4:_r)| 66evG&YP<;J:~ >rmα4̥myRYfl9#vB~pb輝!~v5=zAN̻~I2 ( @`! 0%!XPI@%C\xNoyQ[.͜1- -Iq_%E@-22Dt"yESk{PHb7g=8>PѮ)d(FAǑ =1C$']3:sf^1n(D٪m?$&3VۛwE:pp)Of*T_յ.,}Oc$[v~NWy^[\~)EmRG c/9\ Dx?% 74䘬IAlvwDiIOK#[([Ha*Anũnwȅ҇GP! =k0ő4F k9Xr$.0~VvuoKz[G0\A륗Mil0 Ib\=k&?t"N][[^d8৽z~!i1N2ZR&9Eq'c[)K6zkl^?4Aqq媛lmdB=zf8A@՟F9k1Px_ bc%Pw0%9R XD(ulf,c^49PEoπ,KM7jN*SkB)@tC>*DIJ(z=e/< g]*Jx3@7]Fv0Z#1Ý] l8%lJ}[ekG9=av}ӏ%0f#zpxE(b'2M%0ZE?2.EɷycaMBa#>`vet+Z+{u:hљ[KIZt{Ǯ褛y-^M?T4>'|L?"ET<-#mb`h&RiX+vmh >SkQF0,jS݃lG|azRM8U8_+G} `n/IK׍n-i'lJf7aÉ !u#$GQ^rdU~y_1|h |SfR Zvs:`i3-Kz!s|L;~[|-C2RZαG͊/{o8 <2RFx3s>ݥqkcct0BEchPQ/_6R#WZj m&W{`TXXH8b̜b~@T֒00רuafb4@ 0IKV@9YRX}qi*~Lr5۲l#K cYɅan2ĥ!ޫu=fW5+eZUx90>2}0y YNbjRi*_{iʤG) ,6%IKfQǽ}x?%-o;ro<nǀVV鐅z1`ˬi̩~ xsI\/!iבq=z1hUE_%Fqf͐lÊ s}H tøWf^dekV>TK_/;P&ڠKII)+X@P8*pi $bX}I]Lr*Q g ޙW(?Mu_R#lb#Ĕv6}˫-u []JhJK8eKM .ANsQ ?O0J:[ETR* ջVz +9zYm rBrmL(|[[[ x(",N:hDž4j3F/9Bq$4Uc}ݢBdfvBt?PHxP˫xtMc,ue@mbn 7ӖPp֟CI@4QqHlSS0CW-6\Z9 KqװA9{ ~zlΜ>)sr42͜pK0s wXO)1t6sA "Ӣ_~/1 PtQ+1Cmrhn(# BkY"ӳD'H1 ;i_yd&U54[i`2ƻ^ x!scmBx}U2כdZQޔ޵ b ve$\I$kN8$KSmEuceo,-i&WK;ZLwM|`&:HDzGKM7 ^h3 vAm!Nnw9^d قh[Iݓת&g:bŤbM/ʈ Nx_|~u Ũ\Yt NE 8AD!WtQ]u)}ɘjXKk3gmj2p0Od_'~؍^HYEጞ];_>$pS]V&Znm..a{J,Cb/I"v}Wx S [Rm/[xi\13Sx<2 VD' <"US*Ga]ib[goʾ0+ܹ-c*Dr}Lh}HHYe GT-X/}jW2GQ['64~OGAw? ):&\VK H 2fO_VlP:A6(Db5CPc_7J:|m@4&p#DѫYf C &|:c6c|XAТpm|蟩 C1z:R{_nҎce:Tah2XXYx կ^IA };,.uתm/)edXw)4"ds!(T><)L+VQ>uM寱$6&8tNpwһ$WrQkWm/!- )3nL?M_a֖ tnuq3?sł'0yIe"n(2пĎK,?<)MA0/C~5D+;;~POV1gA%k[ t5cI}me&{u(0KĔ?pӚCժi[XU8ˏr^9~*!zWG~h}Ջt _Hnhn3TveI 9,B9фTKf FnfGH-)[M:yfHX8i:bXuƓ_e{9cn B;S5wǵ4Mjr(X(ɥj H0gUH2=Ofrofѩ[ QFR3W0jE/xNJ! pRz-F8_zo3I9bk+l"ljXJW3ά̎KϡϫsgSL8&MHŽڋF+^"C$]*QB&2 G0%|L0~ Yy^dC.ʼn/6L,?&D =SmhVzPAd>)*8Ll֧Q:?Be"ɂhJvG_A@TĮ{LM[J] f*!`v}I<[ Yat޻VLgz;+| {*yS\3ɧw8 $Pn+Wy2߼/Ai-^~e9ӟ?h? 3Fb6XFM(c\9;544S=İ25R@vh `mQ h-;ak:H46gږ჎cl7-8r) oV"+w'1k$a/$H{oxbˬ/,E4f+-@si ߚ.`W&|'|Nty6N~oFO(n`޿pf_ec| rыVJG0w򿁹, 9H7IkڦhΊd"jGpi")#DR,c(2;<yO2 b4Ц8R޿5"=wj\&xIߎQk)LRO\`~sy7gpsVQ- x]N|2pf8 88^&H\|x_DLj{yniGåe[fJUZ9lZ,"Bϛ &/҆rW!N>$Wg:>Y@ݠ_K&,?D\!*ȏB38 \7|׷/+ogu^PjQm?gH9c65PCjyM*xOH{Ľ%̳3_-moR4J.~m2bj"52֬mӛ#45Pjq,) Vv1GI@*SzFM\mD4:* 39t$|S'(B>f_Qklo o qBSt0n{ }8p7[U|2;g_:K׭C̷xUGuQZLs2P7;N<27{}Pfw#fѬ=xzaj$/eI>+kP%#8*^0 Ē:Uu+Ev4;PF;z(s[Dz\kB8 LSK?68ETliV>I( (V(VaE=E_'4+L0|0@K`,@`fx7 [M2,ln V%A5@1{%AxJKV?3W Sf0TӰ*TOg8:4EUKk8tgnreBy(oE UBB$ FM6R$~6s~M Hb**_^&oǰw|IZ*!!& 꾹:4. )իU$zf/SWpWm;2ůK6AѠ\TʏSGS6f~͵eF3RSwԾQ6Bqˑ/*P!JjmtKĝe>;Ѐ}Jb:" (3ÒyՁ?{{y' 75&Uac+ xeEK$:?!џTYGF>7꧊;ʗGmDeZ+V:3 &ghSݗҕ71cdrPucFjI D/˩Y@y$g:Du ńHdtcby֡+; JoR*J u`-S﫺6ّ8Sbјb95Vstlg1lQLtd78u.J RǂJR137('sQ\aU4$qc.py(I 7gE~;cWichGhYeQI8l q ŀگ.A~bm9Α=73mԶRl8Mf*b԰x1bV_!Nl#͂՛>v4- vzJWX ~\ͪ ӉFow"VEFĮg ݡT$šp ֱKIVB3'?tY:\yT>:>_@Biӷ4;^HϒT!e:qF5ڃzP1pɱW\g"CG_z(wVWE3O8]Ȕq2z/@-E~v]O *^W#j}˾I.7P jU8:_بdȰ~3D"ޟkL Y‹Wsb5X kGh]a#^̃^[Oc[gU~o2̮BG|ꉍKYձRL1~( _I9gfD"֭0+aΥv1WP1p"닛BeEG̝7N(Ry_ǗEc'c2 3vm0RX9 {GdS hlgx_tr&))Wr-0S^>sʷW`$e#FQ4xI92h\#,*{]{E~\۶!uXX`޴KLc췦IUNpyV[u?zCZkŮ7ִ_e!mv:'Q\;L,IUDK4-E؉;|$ 3 #E|cyu`^|'3#X]!/oc{hvXS4w4p #^b_JHE Vyg7`~tI9?kk5йC̹&4 BNJ}KKe\4Ӝ!cn]iFGlu4]ƄG萯~P|(}9xEx]sYЪiCM^F۟na&ޑ*ڧ\k9Y^^} ܰPrdsB3@F^]0GJ7gF5qrGc:SڦPO gj;pbLGVSLJJ!b[W7nYR8e0Or V̮n[0P@5X >_j%4?yNI`̀'&=Z;)mD/H̟Z9%xe>/g!H%+^Vs7P,:˼"hɬ:ۭJOs5} C83Gz̾գzEN^.xY}o&2$-V_@_|؊KRיqH\@/) 'cNԔԜ٘Krn&R=t GMA]ѓe@+4"^ԚmX t9\+)b$~]eTSI wN2GZ̒JbCZI~w9Tn0XsіNAr{8~u(P`c[ayc3}}ļ͸#ڕl,޲%z4NZ}0*bRoɖIGg7 ~,Lo7`XvEBuuX$m}1; Tҽ(R݅r4x <Ϥt$0FUE~G4u9> &^ݷUZ8"*ZpX!|;k4Z#F$a*^.- Ȣ ^ݩdXgzO}j ZÔ5: 9=ͪ/'YuSC6+Xndk삾Yi2aYaxMλ }k/x(##Ґj8—Ӊ5J3"IIbna6$;FA+b %|xp 7Sxg\0ZAN+: TuPh!ʘH 8Rt sGa.䏰dʳY!,OX\Y"Wߑ&>+ orr4guф5G4֏V&kyRb:}}e@VK|"TZ`z ƒ{6l\#jo43w (^_~4c_O5/Zx5l3)oaZ;JWNe~.qnݏ !*>= l0ydmeHTu#Jr&{ҟUǿHt|&kպaC+Wկ~/1tʗ_݌S_lJ<MMS`yNdvMQ.cy/sU竚iWGB ]ׁtF]`L`En 9,y(pyZ<-2bcīMkvO/ORP[}LA>;kWBoCu 'lyLIM脘;saB5,agXa%*"ۧaޞTW2ա\nG3^ **4)å5şZ~\dбCH'+D<˭\y~d@@rB,Oa+8> >^%Q%p-؈=V#̐$.loؚG($Xi 6Je:X|V;"&YS1>"hI ~0֒Ndj]3VӯǧM6PCnHhE}Z8gi39΅2tdž*ԅg0-+3>73٣/SN^m.tԟ-͹xAb;Vzvͩ"HM1aݚN,+`½߃Z,KD2Pl$~߹Wpخ $#;@b1̈́+s}*3-}ߣ}+&u`֔N]EWkpgeߕ o*}@dY:A߳4 Z}qnb1xh4G%c΍Q K<me;Bw*;I?{lɺRmՊn);^]ܥ?h"$"m98$6pZZ"ԔxQ6&99ڛM5'5uslފXs8Y@؞L G$WЏ")"Td8eurpหwQEvg][OkqۥvWihѭοX g oﰐ&/@z..Cݹy1+Rl}ZQ`rtDF eY/'ujԡ|\(`V!mVUk̦{ygȢy3ԓT>odTn o`fG^;M}in3yOx; yJܝn|rR[(#>"",myPohל37շ2fQ#\iFt]|FhHTі"}= ,IO%/ݭuL{~4a6{FdoZA@c/9֖4{!DڔGݴQVPk-ɩN&ʗtqku!^1 ݱ-L !y*|ƸMƵR,!ԙ2Exs^i0@\K!ڼd7:zqh4 7|C% As $w;(fPCa$)\ȴYV;5o)Ĵvu2B5+v5'\o!rE${%bmZ[u,ҥ|džV4}Y>$2W-c (;:Śv4"'Z10ݏAxjE6e-Z/6H3?bcMm 8`9]ޞBX6ՅLܰ*íR$cف$آܟ:K2Wc n6_MDJ}UP}Br<˥ݞ\?\4}t W(DI^:}l8aym^hF1x6WCr6X{XA\Ӣ'vUԢ ?~شN ϢUH 754^1 ,=B"H2(^So'"R|1'YU [ቿ؄IWُoG}{N߲&4 Gy#vT J\"W{)!ĺ߸Tw-b2%h=k(rWHX37]%#+򱏏lE;_28g cbFsSyS%֞<)bz?1KHi HayC ،%>w_nEX(wK[ڪ,ʋ?nXEgN˕݁1ݑɲ v5XY&; Fuux8+I!R͕ A-tg~r PS8.B]Yx<cRd $?ZD7-Z˺ΑA}D Dg|;D3s@R W);.'IGse#@gǗ.1g6! d~K3vѦ)NMB3ɏ{ynX ::8'\qQ$.vslGĞ['᠒zC 3}@fj?_)^`_hDehos´;"L?v8H"|o@K1sbajUYz1Q^ wJCZ&#^lS7q;\wϭĦɐ% od4̕gKhO*8 }Sj֋r9|O\Ӣ~K"ULq^*,$Y E{xa\Nq:^BHCD$oIq,N18z{ȹ:M녻3 шj9o9V.q[ގx31e2'#4 Zu+~iu +sEM37=OLw==ωs VTmͳ~pOdѨ·ڣ> ^t+vFOBa_ES/%9Bn 7'I#S(lo4 W8fs8#i?tf<3vTےe0X߫ 3TNkݔnw\w槃v7bzKce9K6Do%yMJXuA& d*jXUqSZpZ8uzfavP|.yme9$~L)TV'*,ծ7ow 8 4,FWn(x+ F^GXAVq3^Dp"]sk]*&;₍\HR<efa\!Vg?Ȃ")dۧ}~wDц)7J2÷#~*h”Ж-}ϱqmnJĎU7UI*be0wwŦw # ?b챂p#ٗ'3 $uO;gh'\<{ ؂V'/?TDK6t BkA5v(V_@MDw~3c/2P>]RVrCy1Ty7l9s˯9+Ÿ1Okj@,4~v8 w z!L}BC]qJr֘qB4)R֔;f yM^'FY΍wW2tw.ZAҘ٦h 0Y?Dѕ%e ]qm hL49ocl/&Rmkg^ RQ0m{CFO764@ ﲰo bD;тRaCPw$UJ\%ueH'֯+%BL;˺ ѠP%8-%GUdlx:xi['WްDyM\ٛ=5&5g6~M!Zާ̜:+*&YRf=?g/FgbOup 읕M%鼗Xe$Ly+||tՓW U+l]Yq7b}e) m6Q{tSAcgȝ`󗹣fPh '> lpF (K C`6D+a WZ{XQ LR~!; x+Lڞ Rk5L.Qʡ^aܤ':~;:~@~ؐk{>m^I(G"]92  74{\ h{EIO &{ t; cFv,Cz q3/r:&>SbCR<gGf-hS˘tv0[jvt|ٜԮ@PDž++59y"Xtʤ0e3w;dׯiFC*Yx2HF!mvuhT-U 9ª$%__3i&^x]*;G Nը Aj!3"&ȍ ԰L'G 9lkL]Zf.zy0uq&H-FVPVe*'yyzKҚJoy&-\͈<~Fo>UZYJFL$21SȂL@rdf>yT\CuhxPf:Zt{wp_޿9ԭDnS3G-ӳyx9,jziݗ 5!'.Ϻ8]>?z^~+:tYM|u/Jl_i8lpT ~4`I|.w"RYl^9ZG a90Hmn ֐leV,k!9=U]Ӧ;^ŋTj'K:e¹ \"(unyvfe`c>"rÇZv7l_-2 \Zwܞ]:h$E:8ƈA:Z7UrHZ.⇽c4*2^5(lZ0uo‚VDarm#JY-6C>~J=8Ұ&w]{Ή1 *TYnm:SW?: eBkjIn7깺e=#SJR]TG^XL,V*.^:;^Kl}TpoV0X&9:K2iTb3c=_HHJ63E䮃k?!4阁d!wk@Mtp]_XR#ˠߓD$iŻ8MR@G1& WRD!N%"?Ho_Oל-B8{ZJ~o*kqΝ븮$,?%Rng.܀ :fiS5K]5l(Qk맟/IN`+χ5Tt1җ?#M{XG$83ct=I:>nYAՋ< 81Iv)SΩPo^.u p8Dȟ z,`qehZ#5LZV{_)iBMYWXJS%Ab@`5-j3]wG(&n\d<0YӏFc[폒PlG?Sڽ6ڀD:17ӗ6>6U] )h}XS4JZ;*&>3B ͹8*x H(-SA '!\i0,|BJ5 @|)7Bvy7xCrdRl2FS[ҟΎ 1Sc/8[,, P;|c[ D1|\2 ~]v̴xԃE1@t߮B8sZƢiB+&{i`(l҆*'!:;r%6ۮh_~#hjEMZ>#Ii.^ [K5Lc 0|cn-Mxm\VDkLzPB7)RݗjPlDM=b/.<<>f_waJx6s\TPS>r$}gQ] eh^  slkg?6jړ4g-NtAN!4m.r#h~VP2HQWر#,3.tמ*\ʄ\;+Yc;͚rnl!i[;JILk^ }$uJ(8oVNKozZ8o&Pm"zt7fQev '̰<@ 1IT[o^p=isɦ[ 59nM`1Ǐ݋1pc#|"%&ȆTO*)i zs u8]Z%KRI8XiڦPp"Q<s_eͯP+vuHEٕhL}P.F4[@XI}68*d 06;.OˡꥌY/S|pG0JߕclЫM}'KG9%n{0Sd]E7cޝK}%d+Ȍ\;=M@ᾇ 1XfqTZqmXCQl@~T@ πff췧Epk" 1R8m՞YSW |P~¸,a{2{<{PS.%$Rg4-fWBP cIs$.4`[(dAСhGO-0 7BɒCS\ J-=I P+!q:A\`btTRpcɫun?:վmIZ?ЃArz9wtj3f!8xIƶy(ZrJ+4MWZ0΁ߗ '2^GwkOȭJ oUP&?t6zkQӆ{%{g;2h+!h0в+SK5xji7v<8JU#gsqCхR$<( /i[U,/Jf6(%FcR T?BAt~C*2DZ8IvPf j*ّj]ɾ}=sޫxc)tULKmXwwY'013n5KNrsC!b|7Bu#-i Jے `^өr`泥cO$=1Jsg*?^` L5ApP9TqZM" f}2樏 @Ÿ"*-Wg[+FGqL?\ODXb cS"gt`,DULt'f|CTxd o'":.c ZHhj;|#9"Vg}姗󡊠dq|[ҖmH<&RCN=q\GoRL*AΰмTy6闏dw [WlO*猛| NglGu3-8JɅN=u:!j9[at8]uBT$}x۳#ӝ?~Oiv#[g'QNȯ2NJw`EgϚ'FF*`]_M_A%K}~prW]7ܘMʃD2͋G:~O='Oj3wad@x~chwEüR~DhUAVwPы1CeUm̛l 7@ѻ\P`ԔHv ;a_VT̿x)U `U=DoA vJW\=]:nܚfV7[)'Aqp\^I|IhM1i{WB4L*B} 4݅ONKĺn=:HJuw/)b Gp/anbHu(Pu@5Y̊t\nz&>I# kK|MiO"1A it8PEp~2eu9cR>{!dOINNsV~pnlS 5h`?>Z;#ŪCa/քPCћ*zA9m{=!*#&BKɦݮl`TէҌn'͝]ؘBt*su>*?ityB>/FVDy:mbNe9U_ 20qBٴ?+z)x1~Oy`j_V5]QD\3de %e Wcb9{LlP[RTa\J#*&Z21Bɞ5/XBf!SA>/ý\eexi£B,}d&{9ujsgѰ;B+DvW2N i5EQC܍y;P 04b'_ Tz+}>|À*tŕƼE+v2x}BcVz%: n|\t$pW؎Ctw3Euq~ZmpވKs\Y>_c,vXWd(70 H;:*wu JjvJCnJ6^0͉4b^| AAtO5#TrG˓48!iH&?b/"}Y04ͤx+{#gjm"@JW:0K9m"Ox꽡C_.oܻ_5s}$|e*]Co&\~-*?DN桹OxցK4 H̃CFnk8a)?xUELE@tߨkl9<ú­׷g쾍`SZRdai Q48ݢnu.;;ݴ][+S_AT>4$I˙L{?aKgf첡Y5Hw,5 jdu':CR-rQ!\vb#iix1n0!^{c(]`O R=*00N>J39w͑*?,*W.z 3Og 6` ,""Kz09f&Y+p N\B@|t@4xלVfNޚIG9WWr2⥊l -BhS3iFpi ՗0SXqf  k8gK9(Z:T_$1,WƭCHo;ҨbO֨md3O){y;A6ýd=wTc V7J^B2p1(*U=D'LHӣ2jNĤ0;"tr,{`" rx7Aqڂ_&f[KV& 6dpAY$ *G4ཌྷQ{V?$JJT?$TQ"/D Q–믏kjCthVwڂv[ɶ)=m 5 uHomPƍ(y8??3Q1N ԱBπhЙyB4;m84c9+Ώdl[ëtNQo>8͓ ^WrV{Qzs;3<1FR6WMCwU <#<‑V zL$9tᒋ94<+;Gx$;7/E/l HiBfkkb;/DQ-<dLU:g#;ѽt%>=X@.q˷—~+?9>-1;Qq0))\}S:  l),o_TBo k4HڢΣ˧>^y-Qb 3L9RI-;wG# azb]Lb ui\N*ֵ+R¿ _[~eR8mGZ!grȄkS8% ]j,ۦs&ה>*95Bm +&x*8qo7CqKg $]4`aIV"3n3?}TWLUq[E!{d 4M.C۟ 盢?sӡG +k։?w:yv2K%›zm]L,OVĚ'ˌfʓCr>w4Z*2.D*LnlPKbͭB3@cGUL?r(t㲷A+@]lin(HSNcҷ!)pS:nF0k_þ##QPŪ-kH#e.W4FcXf B&0@Sfc/߁^|W\\#>Msr.0M%Հ]<\vK^[5Wo0mOTܧZׅf2(&sSA,@3%,7 '4 % Az(jܹΜM/J=\KgЉvjF0RaDI۰L`vhp7:gL12j$o`Ɣs*kzVgd~ۢEPC 2~jºi!ޚS!bߋ X(C+R>FbxJ_MJg5X L-wRGuV+CW?u@IqXknS { V &FH mrIKuE+>1㸥 La Nܚ)o绀UZhg$/ 镉P<2v*#-OYJDP4G-{c۲O q(Y| J,J}moůzX퍜+D1?47'3 \J+U}gdۤB"y9.@wO.1Nj .ĺRW۾~b_8C.xytRqB$?2ucQ*q!k(͔]ߧ"/Ml3*瘠7mq}p6ʟ= QnA$rv7H.-kFz!faR鬚 Ѝ{>*Y ߊİx[?~) fn}I7+dth͝=8 wb5GjѤAF^FߺS K]"ҹ* )x\R$4[C8 '"jJ&.(=o-M+?+NTHpegB͎zt"uk>T5TU8Ƽ}z3f錀yx.g y |1Kf۪ZZ.}n]pG~6r&RXpf/@lN.ߥn}JU=5R2考[Ba^2V ‡ʧuMѽ>xfzp%a3kcQ]u4ߝ|wfѤ_g2&xL7GdG!8rqñAm¤ 80S]|۽| #MVqn"R__ƛ]ԩ~q3䷚5!6AQ )7f_80l*hKX ׳wcc4j&}7R Clzuq>P{mnXF5QUc] ep01^=Uzs4GG0'4syp$XlIn.@4[#1ϼq@J3rUCa ^Ea>ccl bqjMpYyhrfEmYyA' vzx![>#@b|1}t8L}4Qwř#EݿKY 3st3mMQfFDk W*t('*ۿ0<,.۩+$H45ԋS@6-A6VȍT#Vأ‘e&hnZΉ$/yz&UeM5ZV-x@p5poVQ-P:AEr]2i2 % :Q{։(!yKh1vШ2KPk La[Z)(D<փoTzq .)G\,9ʏ쉫n-$R7MlEu-0A _&B% RݔUXL;򕣊|G&[Qн]eVx?xt#H RNڬ.3OO_]׳^[lGA3>J?%B2Y#s,SS^ύ 7`hAqO[Kl*v"|O ρ7>XL3 `y8ǻ΋iDXՄq.&UpgA yvIhzH VB%C˰}` bwq` ܬnIȺ<P쓀ŏ=Z6XWVhgbRR]QF*㫣|>lHOo<+V`4JoAT:зK:g Za{ }Ԭ()?ix F V;b-?KD /T?dr~T)^ m 1k`^7Mga$=3p'~5`eiZ{j1zq'LjMZAX|^il( a: Kץ2`lﰠFfFd!\βm&,=NaZnh45NzcH3HBJ&a$A k$G,5eRm ӿf Pzi$6IU?!=?]#k%LLyI^&Kk:kV'ދ``S<2Jns4eUᠩ|ãٖ 7JHV 7=fs2]s05vf)_"t2 ašW[16WR7R%L3NO`4C=6SކDŽ%p$u%eK!I5Fƌk$Ο't/S|5g֜[5Α˛ۤ>\HZ[% . bA(ID {T+ϟMv2ȸ:46%^lUst̮Tá]:1FcX1Bǵ씞)-1ʮkڴ5ȉ1z~*m֡_f;(]Oj6y2_.r$XvܩEm͢nz\e%9T)=+u5+#[Q;Ik9]FF!=4G8/Q|A]" 2Z+8IwrW򮖋g1FS[02s>$hjÊ|Zh….)C| |#?"&[F\F6C <5(~=*N=jtܳАF.ൃ[f8(*<k5cWN2]۩4Y;z|+{nt=8! 5qMT6'S\\[2lo*,Jh+T!="f|<=:D/Xϲ9R"K$!y8v A=@Yi &fۤW c,</. 9uuUYOT5OɎc=?jcA {th0l9Db}p+kM]akDD6MԽc&dS.YM<1 0s7gS2-,2)-|sx!>1qq_xn5:`BKPmn^ .H)Jf9`ϴ uL%c<"8bKX)qYJ$ILGH)X5`Z/=N%y"@maO-,E6}u1juha=OO]o/,FFAs2 t5.uEoc^7Z5z-m3'm\G '9c␃2z`0O)^O2_>RF*q{YD c])łmfҠV6iOr@ kyviSF߃g8I1!L-|nhȒs2?O)٧I71Iư]"%žږJ5B ȇv>;@!YeYy#NtE3&BAb~^#f`|%˜WBfu>s'FLNaeEǭ5UU.[ƛKN$e}6z1$԰7>JI ]t~<@eg94-*]\|Rt2m"ˊ ~6fMdn`PyeV~"vLjY窩j'[SC׼[d^T3ωK-}>kHUǚYm7?Dxݽ4&=4Ŵ{[W{n@PUJu>n?5olO2YN5wP{bFqn/JeӚZ.F>愉4'8h߬̃܌4T?NP .cN(l& ؠ)v \Jz0?uMOUq TgeXF=q7wήyVK?9/2wϙ }ċ] * KxUzffȩWҞVf~ ڿb ٷ,-[G>~~Q/X4XcOp6U3mUo[!Brm6'Wh9 (`.=v,g2t@qĎt5UdHp("`}gΑtݥĐz>v[sY[ҮSNh˫8AC3Oq=Mb2͖EqKMb0.m]zɾ,Kױ*uPao 6+!5K]"29ֹ)6~ܪ* .j6.+mYِ4͚FI f6WM{Θ Ŝb.::C$&(d;Jny_}A>>r)/uj"; }tv?]>5)Fd82STG)TՈaY??H-#Łws`Ef<ޱaM RJbz@[tUMmP7V%GԖ(SP{uV gW;BJdaŪzϨ.nz/a#WZ8cǰ| 5-U75C˳GZTAr)I@AXrҭ&@tyݙEs餘kW+P0tΕhќXr13%(5Z}̠0q2΅.4V06}Ub o@O_.=,\P)sM~O.bQDByE1v/7NBN(QEg$iԮmS Yz9!4C+SZf8 β3gLf>2g!.E_Dy oiFecT˙R&}f$qC+:k=l 'tK"{=;@!L[y[Yl,]h]ݧjqN]$%!pUKq L&h2"R|3j&VAZ gIT'/ RL>:`??oj,V žsɯOcÏ+ZDZ) [ć%VtC/ͪJJ>†SŬ>F8ĘB%e^ZwQV@,.*ucBrBNjJ)W:Wc$?5IwRGu1JND8 q݋"Ed< S2qeȖ7h`;sEYr}E p蛇q̰.\ qpV !b.;U2q,'9L&X֖Fl|=Q DV1rW! Wwr*&S/yKh']'UU?SC6[ϥj 7 RdzEwJtUJ#$&>j!Y'C8L9<^QhՒ9́}r-eZ@ѨbQAwBJe8(M?J2\)}W" O]nrV.5finӇ:ē 6!G#=-%B}ONI׌m©jiw*ik־=8? [uefIkymNp[vk e3֐rHޟR{؁&45vxb }K%b^.d.LY1UCQF 7gdkZIia&UD,2155DKd>Ik0E9ݶs$2TPFNX⪄Z+!ֿ j>G2]ژ.Gv܃Aw%*xs^U /=oƏw# |@nHq G&LNU-ts,pTNv1׶_Giufdˀa5[/,\P|Rc<-d`%qݞ(| \zz R"9豬ק +Ju! Qq& -Q4-撷/ "(n_ιmV[>蕤0|LW&aq oj5 V@]rm&lG 9݁ ;ޣP>!0M00CP}2kJƜ#6`zX:(^gN_s7+*aqS}?YzNYs<>'P}p4"|JxtsO\NTYbKl1S9"܅-j\ *!_w$<߹vxvKho, q4=~DV['eRQɆuB"V4Zjh?Z0;[UbNz:r[wt_p/bv>v^_1 uƷV,R%rҵ˓ Mr05Y8٢]ѩ _o*c.*RcCQò܁3pF'Lђ~EeDP? LFqRy=yT<~ $":I*l]-_LKMiJp"|'qU.hbm vd6 bպ'lA*x-@tDڑ8'¯ 4^%U-$#ABn#89^A3<+{P N.ė]~/|"}^dUCH/AW i6j<. fb;[Z(U5_VWMgH7[Zhpʆ*{7qQJeƪU>ma5ܑ1u>8Z)D_@3ٚb:pk26Wᇇ\4z$a2һJ!>hȊv)u[>X7RlA4GC6~X:Vr0c{}4>(mr3E4a N}hyh#bqbE rT?$bLqU hdݍ2d\3.[_\\m}\w´rF7hdL#_IqfQ sȒa<OD(5A()$K wr,J`~ּa8G@.<8@82\ lWۃ}I;4gwb.l-|u"Zj 0>Ĕzq6)u˒ 'NF\*u2#_ `o[uX~5>Β]=bu/]י_otUċ zx"j1\m(+p#RA*R蟖Ͻ~Wy*PlJ#q@k9t+kL(jG g(!wG[[:8T!!/IC4`{|RĶk# lڏ%pkmU D,}De`V ^ugΣ Zd|ކL̑YdgXXg[| AdCˡf*2>Έǎ4V;D_,ǖ#C lnk?cN;9NY#2 cD2O⎿(o* Ժ/,rhgud~dДeXL^GD%F`t<lynJῐ5b~";W>ǀAệ>` 7i(-Eݏʞ'.f:mj[dv.jB*v)THuY@Rt76'>EV/a~׾9 ׫rxz׫NݗLr"tlu]B^3bqftU0͠b6SN +_@Qcg*l%B*b'^z.(&((Slme$9@4!] @V):2"*)C dکj\Cߡ1 cCӈ7^_]Nǰ%4ɣܭ2Ox(~<2G %DVn!="ux \V+S*hݮׁB´8@[j{nKJ,_ijz}Δ;r¡϶248Y %>^>#H R&7o [Jb6ի#Bo,|=I5J[]d9Vӕg\<[T~f[=WXG`s#!gK;>ܯB~F#$,)fZ"CUGjc=hdKNꙜs[~CVт!;z;/·qy'8J_:٫fy70IzY,Ts²i`~uHeܪB ~x7ih'w?Z7ʳFߑ 2Hbu 4 e}-5p-0^d)6~눎kb={_>3*" j#%J?6fx&б cbHG:1<&VDΐP~ {u68=ʡ*o~x<;Hn7ɳ8/x)T ] N2ؿ'h FeOX' µ%m)ҩ .Q**O'$C蹿2:d)dl.%?KT83>!)Tw:}1B/ȨC1zWۥ'<ݱvP&ԍjQ6Q/6O, i8Kf筚,_ &멌߾N7DTňp)R %ީ QLܤJ!AFeVD=>nhL+2.aHx"292aތ2 *ƫ̕m邴ڈYq"x$ b\V~E} 1>Qag_7 V35ퟆ?w1<oAVI?k'* o`W7۱v{¤#G8H݁}dr-!;z‹ⲓ[3l~^ b@X]n|fs8?578Ds/(J/55,Zan7H絲ה8fHyytZ!UlԽqO9]0ǦL?]l0vdA0jpNo0u{xdƟAj=E :*iUP& Y%t:To~浄 ׬U}Nb%'sXQeԖQ:Βbܚ|+,!Gx%!xH1v IH $j6ne=cAp(tͪr ,đuI*תA@Jvږ:|CnDo}7^ h%pMI,۝T؜8iQ-X_ /Z~UqM|jng0 ;Z%(=:ZGX!\I[ƞuW&I݀J>Ie{#K^so U "9_d{nv(wIofz1eg{ƝBb yRN?x:;rg7~ژOh׉Xscq,ǡef/N^lǑ].&mdhuAs LqN[?(,UQw,8GMx<0|Ks6F˥Y陀ne eҽW)*BI;%C\K{VhqJ 9@f7mӏw743a | |xX,p<:dRܱc< Y|7 Y}Qf|8 (5ldP dL0 D6kX hl5bBmf ]<C Q%<[h / uoy?CtI_c~ҽ~/v)ξ{yi((o, jt 439)>+M%=,Á8/^%*7$ξLއT|]r7$0W|Tj1W‚H}m/R<))ZJ!2*{& %E؄2X%Ȼ5iB\<&G>Jl}jb2:.R@Z˅C{㒉Q&$FI!(} [hM)Ƨ2P x@ [n3(B? fmK qtq3>Ab<ӹ~gz%ɑjlV #cuoĶxfzzQA=Y{-Skݚpnxݛ*A%kzzBV+(5/d^7֛pgc-)bFD Y3C}WIDhjHIToj{Z&ws=KeLmPG NLs@88)m"nPJ_BYNh2!O8E&u|\sŻX7 B^]ޒs=4ΞZpTzw>{R?N1O8d.X܈ppǪXּ“ E} (hӯZ nF`n^=0PL1I;2S:3cX%f+J_E^ev"H<{g朰B i`eqI5ܹ|@ϭÒ@* n |hD4W?yކ_fNjA1cR SW-h .VGՁe=|9hC{F*96%m Mpp] pדI\@+TI`o\?h3G6tyq*'ݺ:X؜EGq@pz"X ("? i;MZWNBY{BLFֲv5;}e y UH-h:>ZOVZTpfC] xW$,e yN,D[i*<v8[&06K\vCNGuUh>5 ^cs }*=~vPG 9ֈfBE܂c蚇'lu|#`tAŎ 'X<,+?d6|K2>͗ іYRp` _o${=rتwt%pd@wXq,UDB8C&E vki !V͆ 2_/ԥVMn!V㮢`fCeXr]kHa h_N8BɈD0|րWx )VߋwpO5lJ'jt|rr*߭k&iW[ه(w3=q0i3e: RBy1@;w2J;DQ6aӥzZ1QU@^c3{x=y7a?Kzh[2'ςܒ%wnĀRts7S*yb$"F?ks+v|Z{#eﳕn쑚[DY<_K0|Ʃzߕ1kPhk7e]?\uWbsF -טu5/_:ܶ-~@0ieۡלItPWNT.+}Rl=Bt}GD'bx|ceh!_Zc>b1ygqXi1i?#|Kj I%ocX<-ysWZ9k$vj돓 7>M=/"]hTPT-c<֫&_ 3`H't}I-r_ӗHjk} NQlq^#B@ zV!ɨZz?0#jt)&T֨Kipe ,by1 J^luTV`J{ v{'i[nZUX;Ȩ`3i\"&-ܲUނz.^Z-IX~F˶a\  NMYft7Vv8,cA7w'rbiC5:3Gvu X$.y3F l"͡b}gkvQ.+6"VTNŪt{Om1C " *eщri `- @rb!h"w1%v'أQAg./eQeG [K艡KɀJLS슷pakin\[+,:}d;6:#:pr4Gh[ 8gk*-M3uΎbnIK;f{ %T+YHƨ~*eq<&B[@Ǖ+x$o/(r|T7Q  7>owe,Ă_ (ogĭ3rꙠCc 2Mș ?Y9@S _bdkr,}AN0mqsn?)B#$7ӏmfdצvI݂] {uPE 5&a2{Lf4xk.eӨ2{W4kL2uZ꺘o2!_LgpZFNlsdUZ^ﵥߺԋRFm>֭ZdUtk~oeC<(b̈́oH4"tX(ǘҜ +R\_Q4RN=d GQ7)^i?5c|+[Tu.8%D5?:A8,NĐ%PJI~g}?w=N׌N7^KϲIW}&7 L7y̝1τO-Tذ㪥B%%>Xi!H )6pβ®L-@Lo?ɛHb/Є-cU=?]N{jR{o[h]cF@N%?!Y 4o/nq*p[PNb^t+j"B{)@Gy~^O=9%LG9]DQHVך]b ,jCp;/1:!ggE*ӓ_-qZzs/4=s39|_Ï[A]q'nf΃_`p#΁:k N+b(SVV% Ŝl5]%)>JYfC+4!M X>~?Xf1&xW O"ܸEۘ nt'<1!f9y13#[OLwt]%rQ0(/Ȳ_fӉoewGdgᡨ~͔&LBm=Xqa`|~Oh1 Yz&7{|J0~<8L920Ibef!.-yFk\dOXۭ{@^ tb(\#UUPxBݬ bF}zOF:+8g41yfiƄ[#Հ~qƍgDT@4h#[6u /N*74, ?%!L~jW}en BJ*Y4p:ķFst wǥ}f &N7IT!'/4Ejq ɷ˝1Xp,JѳO5/j&G9з<9[3W5Ynl~qA Q:v+'1?k`L]w n6BHs֓2iN^7Zu~DvuSfOIl ߚ 87sjzj}cL0n3F]Á= M `aP i|o!Hs YTеd 䥢g_hXS+`~)x͗К (mxi*:O pYL-s& + O'T6<*Rg:"B})xY+;? Hız$-svk$DƞlA8/Հh0z@.Qo, L) >l}V *MgV!'H\;U66졅L{gmrO0?U\zfh:n|XsSYgw<j!lfTZ|тQ9 q)Dkv揄Ip!)t i"nWGYS6d޴'F΄x]C=!v{|gy_JnAN$f3o(bԱY&Qrɩ<0f2p*"\V52|VPk>>:{ߪ{F{%D) u5)dV3# g7N6RDp8QX|yBNtB ({b=|)J9.Ѻǻe0VfYKŋ} 7CCfeŊ:y  KyV!I|JVv;xp6kTPCݯ7 fcࢆRǩKd0v|I%U_ 13~ $`3ž4ɐiќU!mbV8صs S%kfi4}jVVDcHG|r,o+1m {!Yӽx a9W#0x ʺF{SO{sR}}u$U: 5?4 ,ʘSy77#tا3֯8v05X0^Q7F JVT@id0\6Z^r4O8v?ApdQAWn1az~Tq±yV<'/߫ޕX-r bnV'G ;w!G-ۑ݈QoAgc+rcNERL16B~7Łb^Rd 06w@N\˶8⺝%{\M ZJ#Lwav('vzbT-#ǎ[XEQ'ٙ5>)uH*C }=\lN*cXQ_//e;D%0.?ExM{#o)p҉\Ta Ϗl5 Uهki/i9eH,ɝ-QۍY![w2]u|qRMr $oS8dOYd}$%4aR—8Rљٹa`c]<^<0ZmR0i+P]I(]fV9a;NvF\H 4[}AGb㩯 4_ѽ7-6HI^bIO2?t$qdʘZwf$gݧyG7ൈg)'5j F0UN$!][ra˥EF Ll3Z4IzxsJcnӝ@ aL,G$qrlP'&&r: )G!LYA߂.e8N6T Xu`6ٕhn7seYVPyFt7 ӗYzޒ$`=C Hdr{7^_)]0;J.K ͋C-Z':2*S#[pğSZ ey6Z0%`F"D 8 NlI?USlg%J!Xx pG` #9+͘TjX1kK(W/ŠԲ-GB_3y&9u1Jb,>RH;^q +^LMb.0VDwŸ4fb3ݺe5ߵlnKF@ϳ2iYY:,f;{G aL刿Ë7e4ȫ f]6I\R nAx9Yz51slܕ8ar{O| -|Tv װfe 9 R;dJ$jyKh.)盀y94¿nrї6`+զ=9^aHp8l'?qphRCZ]U`(`nIbNj.b*1~*;z03E-U-㊹~f:_0P覉ʚ3#in0$x#ey֭JKhTsn/W̿;QlɄxETザ8UPA"Vq07I= tH7'F|=c˭+Gf0b"ēj)J+|~nc!.b&͉>ULT"dLdغL,X&O“4Wo0SۇO7 ָ944 Mpte! j9v:P߯-(_ ++R0j%tu8ufb8tddxbBZݮ~!^GaW MͣBZ>_u3]imyt(44o |Cf\H-xO&]'yЊ Nw֑a 6 hׁB,Xyr)gH mhs?TaVG8wgF=N:f)&\:R:4G&A)}uO BpϐMZJdmE_8rn C/w>XZs~4CėQ ȸw 2(.| laI4hB$`=P-e?Je@WmtPE!OAXL"$ Qɧt͋7z;d+E"fr.Bdw^r_|:"MK=vz0ʄɭ릻OJzRmN6p_$3!eQ>ߧ7`OQLwgc#qIʵr6]"@u7}N;/~/HIќVv O5b{~eq5lTob%~/악pr[b NMPb6YѫĤ0I"oh_9Eoؙ]ôu0!(i50R@W ,HU\4>p nV•BQhivX"+6 9an"[s))0b>Ҁ2 ؋h![^+g`(k3)/0)FBJ>{Em` 6՘.JGvK m2mn#*xTi:::r` ~e6r*瑀˳rL"Ͳ'21= ;"HV۬TV?aSP]\J&KT`vf UQSFQ=/F"Ņג"I O3 #3k p6.X#:byfdcDhS J1cuYO8+RQs^f@U}Z1Kӛιpʹ`lltMli}MkWV]n݈ aZx1s_vB-*wΑ ;t+sT*JܖJdHo(Ý%g=7X:S CPcG:HjS#e-UרJυVXKޘ1m.pQwt)ٳ(m1GKp)`#Y|3!.QtdZf7knO/L9!h;Q%}_]:dxB*6("h[HD'i3[&l)[G.ҍJU4ԑK rr%)WClo%b\Ӗ&kby ߌ8)'睹j% C_=@ N艓 [8i;t26oVW(!-YfZNZ}aLK`8zSMyBKPs麝øc`/#Up:RL.gǽgR6Y't elb E*׸ky ؗ0aḃ0CBt:$!u8%x+\Kwyn?>PjBk͝C L6<Ыd 3I1,R@:[3!Yi{zǖ\ez9J΍Q t7 4m Wt (X#x]1UiF%xe>8x[:d Bت}hYNnj4`pdTe1Hؓ5'tQ' ̠xr(}=D:Ie؊xPDőSW=]bZ# r (Zz[>LyJ!*u#**Ǐi"~uT@ո@|_x``A-' ˫ Su BCDj|Yb,"MYnmI?z5J9ƺgI> JMCJ`q.0%_>"&=6sG!mHw\Bɜcu+*}u; 7j>KoZamw 󕰠?(V%rU"D8 cp;ܬv\Jz\۷  Q$MAgʊj NH)ļ ^"l1+,֚R `n *P =!:TSHP!.~Ne ObZE)ͅo+R))DP뛍57mfH7 UV7z0%8yiɶ]P*vWrЏruS彵샬H6)WV,,P-Q1L/F*3(fgmjycZxK lL

!%W0ulWDnĆʄ2H; YXa=s)@"`ԝ5ZEͻٴ,0Y`Hؖh=}7uRyE?u>O~>1) *[Y- B 3!Ȗ*`q1% Q'b>竦s=Mݔ #| Xv{lV;vZn̄=ln,p6.\mҵ̅u5R&ԩU-plÖ&0I4<MzAA3Sw %(Og3oݖ5 Lt#7Qdg&}(bzC~7K^U_∳X)>FPfO* &0-0[14Yoц"HI/ŷT(.Q/M-sZJJuF>tev֟jۚ۵QP Ћ5\gع@'n2:uwQLٚTRf Haœv;͇x3J/ܿUI6{ijL817Le?”6eǁ=J¾'" ?aЙc1i4Qò4lӅ0О##>[b3DU:axϩCi+gl.|ONf;Vj(JGzBhFgMLӬv' XMkZ~;Gw#)hݛMb,M m됞*٪Oяo:F% "o6U6 b40+ql =7xE,:9!ƫ&i^ڃ]"bKCƶ baM<MvXDT>A2ʔ+ in- ?Nnbx2^sc}XKEa2~{_)k#f5p~ 6(]d^pzϗ#b :+9<*Dz:dtZ׳x7!IxDKLODѼ\E6*1C6ldN>%/N"ˈV#Od$NT6X$6W3:~r2NQեfRY2#Ovr)$hߛn'2r7yiNj=O:&QiUAfχ"6a],3Q ޵~FPi/z<eĔ~>MO`g6?<6ѳGy/uAS BC>V{`=h.akH=wA)<о"x:X9 ]5•4DD 7>GN}]8@=/* ;G!4B:I\9۴r'r%^D'Zl]b<%R]M㥀O/g+(wy /}ǭM ^ۢne:U%Z1E#9Gc&\9x-'(L8忿A9kzUވ:G]т8ԉl۝vf̔uKK$L&eP3gMeLLfY(PSB'ff2ѿ^a~jB@SnK6[Y6P"l*h,IQM^6 'mo^`:!@"Iݭ $'g}/}EPL sQ hGGɖڽL?̀,!\ nPK>nf%2ʖL!OF%ju Le/[R!Yte[xH5_ozMy!'3yL֨eg{X_y`B*0뮏ʄ\j 0ƉC x}dחS%F]N硞j$|В5}L$wBS[}[k:eٷ^I̷MUsI1&ِgbig]MDNED[pē/h,pi=* Qm[(M~^ŦshgP`othxű}f +ũ26&L8.:6_3.)d*C`Z9* &҇\ZGFG_0 ^b  ?z TNp\'%5z%yTZspyϒhVSiPc,nI/X&v^@.}МZ m&[+ّ0+V)7E>|U##b:nEk{r4\IB 8=i9LfxZb 񳓄4t*u5 {ݳظAJv,{S6iUW2 )'ǃ#fި=j#pj Z$#cHXSUS63-,dYBV: MILJ-yWeR([;ݩ wHތ89:LIB##JD\U<2yP*~_թU(ƓƁG:1PJcɓH\1Q#M׈ĥ({ Mja94pWO`7lAHcd q]oxiG7h_˺,Q麤A˻Qbp 3'PL8;Zy|9!L/0n!@pۖ_FW/%&y9qyC^'Z־]`Ȯ<zRgBS<#uJrjKaVCUu/ U2_I w*0dt7׼)<}8Ѵ]Sցsi| wn[ʠ/R$wE*,;\"Gdm \8{OnTg[ KibSlۋ|{;ߐ^KZne{3II I²F"oDٿed>(vP O"Ap*kb"DF^|j#PN<_T:'ZVI;vy@AhP5]%CIwL.D}{ǃdF|]-d  8,zux@4zZ% @":o6 *LS:8cT<[qm/|?dhDq Cp,gavȽ`o"N+@X 7qiЬR\-ӵ#-l >e85%L3.tҞ57v f+Z|4d-#/hCrnpO(4@X7]_Jg*pU:eP奟?WnC~r~UJRT~;^Mt IC<883\Uͺݼ=S)#fj@-;eejtsx"hÀ^{(4kA OF δVxZJ+/ޛHZ9v$*e_DR.,SQ*[ .f=b^Ru/@߄+Mc5O S)~& FvDR%_Z}Cfڤ fVnYQ"M7`]qxl` \kPdci39Xm^笆H<w~[ g^{DoyT_1zNɽ5FhҒnv l4u)~A Jr[ HlK?Jp^=qօ&+nxWLa\wSD(>2:R FR]'~' 6-׏!G\69/RPwEVM)c{\+kbX,.Cըe_2w6O}ނVk)v %};+*ù8:NtQB`oh| wFLHTjB}~%Kpǁ4p2LmӐv7,8z&8>!F~SRk]qu\M:D(˒."7?K*DR 'kaNm?ެpB{./a tv`f >|4=sAP|y! ,&+g.æ>g{TKp;a-,m@QY0LJEd``ǩ2l Pq줱_R`Ip: =13ɇԙT6ZuVa*7?L[w"Otp0 s\- *g 2ƨX4˪;v3͸)I)\~aY-{<}rwF/ EIQFɫHg$g̗@lLǐ@0PC|W`&yv0_l>>Igw. ogjV*DhYf qq7;P Cs_aօ02(h o-E)kr Q<{aQe$&w 5oxUDWQ{^Z2%x>Fr֪.Cu6>*UOjT5Vp$ӷw;u:.G뒰J u `Q1BJ^8>_? ؓ\q9KBH$OhwHR4}~vT#cO⸨v1B [73DU2E >sPrB3#3|.oPF>e.rOS_,j06 =Ym8;)m+h[M*fQ%%&A!"}1(A֓bI׉4Kƨ Ph1%*(dZoF=͎y*TŴRwH{it؅_ovq.5DOO V )g~Ĩ@:Gwx!ݫiAqkV!E43.Jiy96۹+-v͗Mr:ܯko! dQ *Q~CAl;۬駹~|Y1kS0e\JiҸ3JVvIJxphhjv}Q D`Q;}1*j2oi9vkEGT\*,8DIpx{fc;k>^֏' N/IQ@ֲ@ 텒1nkXt/̮)rj/݇ [.nmn";$^ yjh[4 fKrD^Y 8 ? BjC|jgiۋ?͝;T5ǎ]A"4.L?M(*>N ֎48Ivef71s(xPgvȣcvE|Va/ (hЀ%{G U.rSeHvķt5DL2JLG8L6:ĠbHwK#$YP ̊h m4ԟyO-PtI{6܊ 1̺EṐ/DK7XEj0iUA:ĵё LC9R=zy`woc2rأ]KEw|3YݎI*ZHNeZ?irtrl/8@jeD S@w Bę8\Jֱ_1ݸ9Ax-2BMj`Mqc‘P *%RL.ߋ_.el)%`TR+㼰OizzM"mԺc)p'ARfSR.6 ]~ EzgbN3ڕi ATÃ#}XIy\,FxKzn lxR|S: z#-7$rN7a.úJHb@.AE^6DAQW'?"oʞzx(788(¥[}dE:hG3s%BCIp]hCXke-AD~d ~ztrϱQ/.CuoJ 8vC+e9BH\6lx5&z$.:3( Iu쑯v݃mPwfBЎ  =Qlxw}c:,hhs=XÀ:M'wB CNLm!C/^P6cpHLľ&>\(ܾ/n>}?Z<}7NKY2iu[-h|GrA$>֜ Hs<׹a=KA:#IK'̧Mri?"d3ጤ@Iԯ>m+v闬K L.q< noO"S-%S⬢Mߖ*U}#e} ]kvA){R'SBe7knj:g/N/2 <;}mnUܺ$zeo49}hUCL֠TL[P/p\x52 pb3' ^;PaұQ<\h b匉exj㫏߼қ#<;˯Jϲ6tަpq1"9#1Mن&4 d|BLr( Wl Y7QbKQ|oqu-LQ$p)KG0k _^㟸s}߀**&Dq=ߝm]**0Y!. 6l}/PyA.pQk ydZE#|xi:v %犜`!#?-WBa5Ppp4 @b+^dkq˂g1h:A#OFoO4rybimU5p5eh*D\~y*0O%>sI7*G y[/#[c7l;U,F;*; j$:eS?%Vqǂ f6REB֮}  r LBokrF'TY!#F#1c_sͱ(7BdV47nnvv}/+9GCANԽcTyg]vԄ32`[Ohz/Zuܪ[CFr5 1`XY_L%?h78YSqgA@[$Gmd-;UXkI!Օ8 ܗ'^l-ncd䒑Тz[u?TcL}prtRSl2 pT)hݼڸdR9Q`~8^ǩF_wOWbEK+`)/yOCE^ݴ@x Csk"^&ݎsذ  +~}`[ys.<驛S{PkbMUTٚJlkҕIeTb/jK3\G,{9nԕ6pkQskpqm.{rl.gc⏎m9&736;F]g0>Qs>+]>1GBUI4si6껌wW1w0^i>;Ʒ R [.~q@.o?EN8TRptrRO]ir\ctnRa ށ Era &-\o \SR3͇cyDfp#2HFRG@S2%5S9](12II_ZS٠Jw@yus`Qr뚒/ xV?o32"R݅k-|)+e?r4꯻\Du! uY)/RYWgK CU iwۓ3rt.FSE]u0 րOW͒FK ݊f(-Q4zy.Ax'1zb/{b(oeW se7[,!Wjqd< >Ѫb$ b\*G QE*%U뵎"'XMO_}(^nA=E2$R 6+dtxJ78 Hw͡ZM=\)lv0ԑKCG(߹/ Xnۣ5 ^GΪxCk sC,kbr3`kƕ'"cNYH|%&^{S_kk#ZSn))L±O6cr 1Y[ "MLQr06y DP=-@D4נ}[/4 {[KXAc|8 /+[iZW2Nb]YB`%?#Y=4]sv}S<*yy$}N]rU*p zy"V__BLPj}=3sh(K_JA5~#b$"+VO.p?1 S:)_k(\,Ol)ɑWvz_X]~D7p<,%n%XK/FB;N ѕ%8$iMp)>mϐ9͉*u ; (-Kg?g =\ ߏ}wnSK+97$#1זѕ`+hIs=4 G[E(OWݟ\VGgcWVcs oJ,fJ[n/cȢEx BCKwa=p^7Kro˄F$wq"V38sP+jR$V`j2%~[:M@_dzUi@rT95pkORWCnA11bDC +G[i|X~!UgDN4܍]7S6">NJRmfi3?M~wǩ7;h\'m;~u-Xn~[Auk;:kĸtMyY6zc;+ͯ&।\¬j{7Ag$UϊKd<Gf[055Quy!z]!L ;6m~WzĿĪ.|kа9= ^]2D)Zw,9dژRztn{=7+ +D#h>57OӣP{r)<;"Lu`|0kTw<jswC7cG#H"U\.90;{,}qeGT9J+sE b < 'X8Jڑb 6܍KK\Y\ <4/ 3MR#nAOBD10 ]`n!0on,HОu;l8$@VVCDE:Y5O0|bLjaC߾ z܁=Ǣ,LC{szph^bew2&nvd! Loۖ>#dpu!Wz<$?3/|PG}C5u(Yօ8%I n>hq'qE 8W"lF)BJF^;L?0Z&YTqβʘ"e8>dme~t:<ҋ؀Q I<յzFjDՈz Ljb7d]ΩJIJ>;Qr ח_ 4 p>+5ƯI'1YpTMˊNM1ٿPCIC HrB}vaFۏ8InӲSq V(jBSkDϘ.{P"FO_?'A݋<⩢.˞Zjv[/m9AjM⋹Y7DwHI֦d@ZT)jw۹QNeqMGMmc,mm햹 BdxBm܃~o'`9+Ja-F<ϓ58 8M[RUA&֫*a ~ Du1xgvL̊2E>';i{_1}<'[YW/ȆaПE3o<}CkJZϹ<1R>]m.Җ1; z?eM (vɐ4(Ưj9jzLs8Ehm0?7Ʃv.# &m٪H,Lj'5QK3hg6%=kHuOA9`9y(A"R֨FH5^crtJJSR#Zjw8.(ح!ϕN1i!(UQr72:߸C |5:p"xH;zaicPڝh7H~Z/6;z;۳a&88FP˔EL5"AȺ VD.a}}* Thm Dbt!8!1fȢT$H{h Qbו}хEsMZq(>)O$UjDӟ78oŋ_L~I*6PJCI!* @H@KjjIŘ#}^1•P;߮-ݼ6lܞe}/`{i_46RvE0GKa$2|A8K.QIT&qolUSneId|xW~-X AljPq%7 c{z'2'hP'qT.Dl-7Ժ}SVV:>*!wdH8 ؔ$of0Vw>.?Z.T 7S~ޣRw q[Y4w.F2+Rw"{Ӎ 4Nw!Mrսäq m&{ #0,Y!nyk6mD9hY>r c'@A,jdJc2Bgr*";($ϾcxHeF(q.P1N]lF|JiǵVijp3&>4[CAm0[*$Uky=>.oHNi3L]̩k?DdFŊ wTpTkōW`i{W ~KH@uud|W,u\hCn&7 kikFV=XT&2}Bَ6uQlO[A A,n²;?iYO"t1d$X]\KY6r*Eŷw `HxK STIh 'tD}?)"0܅h/pyreGM7_;ʦm)`w+[Y3fI{З &@|P* r$'_r*\(D^%v=c_fϜLlã#+X4Mh (]=n2#Af-7qİ.*L,?}.i<9jCku0%Bo㥵qId| z&|YfdNkw*:a֍ڢlŐAs l3vb@ӴZX qYBn04ѕuoTZAST2Ud$%v`wOu)dd2,î[5#SU^_'j0 گ~;_T}I;Jk71z~vUj,w18``L~3 4*o|VkL|?"Tku'7>Z݇^cnt f0n~9Seqޖ6_a<|USoSt!qeGh3J$\-8:Cna;",// MPjra4==9\'C7桞OMQ1LԮ3^HIiF ״>NѤcΖMij9iTMȮ97OL^Um0__FZYDֽ \MR- 1&4 Gn@T32H/\w UTr%|2eqDEw WlA0P`dxWfQ֤FTwZ&ԙ]=6/i\'cIh;7s_r-v>6IϹ5#'jd >tN#8u%kGF:bX G𦠗Y' '2L0Z=*v۩b?,\x| 1Kãh= [}േI?8Yd3$hMDk@Q_ށ5]l@E ߕ*zir\yJ2Mv1Z2)]T| B@X)ɹR}Ok;Q0o!h9cd=8ɲ͏oH$*cN 5& d7,kpHfՖ;z*@ RS@(Qp⇠2zJP< o5;>O"1XKaR+6`=z%EW\qdN-9C /p2'VTZ|_yM؍!AN@c-K7(2)ktKd>fkoSځw۹BXp1 ]cW[@&[ՏS*V08Ӎk0>m}!{?]x!^mq^jQվ1:sK`)2kC6~RܸFc YHL*nLq\$0!〸qbH}ǵuj(FwonJrvan5\lR"YG/ J].d?'1n: jJ4asM\Sk#ݥޚ_y&4D /o.LqO (ɴ\&xAW 80(C[ jɨ 8K?D~h#[D I LFhbZf?І,4&8#.r4,Xtիze @ B]߫s@Z~ whq^|KgOb.$@1:c'OpDj=45BS! zIRX+)2@^o ~Kt1ERt@x]NA.B̯J S ;$Q-<z,W$(<~_ 8eI޽kCo9ֿH^M#p3YNGQTp՜u%N>9Y=BU4@r߼gq\p8>ZOd=lZ(tb#\y{|߬y%Hh<q4ieYA_aL.O$3kMǿ':X_g~[ B)>YVve^wH[;_;509H;!~6J-@ ~$="B^B-wx2 ={DU5 !Gy #譐L:w g#Y-&Rȗj@"z@>~?hhڛJ͙[긟):7+9pu7~~1 Q-7 _b:Y=a`.ᑯ_k3Cj&Q>*&0R:,QBÂ`h|#pOY@B.z㡅Q5)>:_mI9we> t$-:͚k|#CkjA# ,-&h 8H\`\_ MThcuk9w C6NJ 񍍽 <᧾sPPMrs3"8ƒf6:| 0ٲ٦y[G^\Ý(?0 2 Li= !ܤ|5}>(GԎKb!Kk5`jDqgÑ(t4B tĤoG:M3pԑ4ы*ym@SEן(BKFW2N 7wvRHgNR`33쌤 |8h@f1E$ӥՔÆ- xm)\Н~{C0UU {fQ"! AiB<0}/­?:yXw> @D~LgRz"a1Y 1Az=]Jf \6Hr0:XsvaV2f9l'mǥu c/P> 6P*%Ԝxmo6Z]=׺#(pU\_R~ {9G2z h9rbG=rnlW̊x(V_YKaO,t0..CPӼIZ<ڲ1C}*F]\(Jў /k+W٠Io?pT=/.η#FT~%:ōg̑PuōEưy޵ZP^P<&J=*}k`Jo?m{v-| TܱsYgɻVKʧAW;|("0VіOY{jW;̶[R`4Hxl%yڛ4gPA?duz^FOúTWz :&i1Q}vG}1Wy{รkzN@ %6T7Bqro/.D9ٶv(55bY-\L;U+oEu0Cx1UU&_V%~6ηl+)?ccM(*Ti~ & b$Aо.y'#ѐtslEg@AVgڽX/SN&52xcx7 P&>\B7kh}Aia˄i (a$? M06)RꑈV pCW viaNBhM jQ(xqj=X\66NW] }suϮ(/ޝ؈[qeZ(Nǔ #UR<&\k906QQT~=IFZY 2;JvDJtJ2ӗ*Cc6=u CDǟ"X QPGtE&MvOܴIHo4H(vId:M-$%<.v<s{ ȡWrJ\7L~lŇ6Ѳ{ΏցMj/ vީAxeH;tM/ .ݺa0+C;ٸV@A= $@?^s*=V4q, $A Jre^|t~ &L^Dj6"t:9LMx+z^` DޓH,a1]q7}rչ5[Vu|99[qþhۭ34Ӷ$Sjڼ(en0yc[u Ҡ[pd 0%gAӮm? Re%x`VTTݬQQMժλU;(" z(qJ~U'Qy},^jkRYW)y@ x:橣rĨz\05,TXy .';;FNqo p6J:HۦR·gͫD޽|5ΡCTtFp(?!O¦twc#o`1_a}޳_4iYT Z/WhTc&5taCl&fnr 2gp,)J pa#)Z1vC}pSZZuF*d=ҵ=#D17`tҐ79H,1԰#zq HjoZ?kE=ˣ6dt(Xg wsSZU߅_SJf\yِ -u~BʃA٠G=CNZ4Nz͡ L!ŕ`@A3 easP5j`vP~dfQl%2R(s#4xR imYocѧ<uyXɒ,ckb۳3Y$4=՞ NY&x=[aEiμ d|)/ ){au ƦuU^7t|2ፆwZ4bKB 12We{ڑ6/8&M}zna8HiKx.'& y@N-y X59E!QGQmsWi"մ_)_sO~>L &/N\J,9^ErHuzp i"\/+c[ U本9j32GAzxF$#sϱd?XNUj-oLAvQfN ym|5*p_#1xg~ 4 %xoHˡX JEٟFhպv]+6&җ_D^> ̏=ZWz0Yp{XaǠɄ7ȂJvq5S,XaAM-o6{QNw*ffS2oʉ5 &s~A n6;rgBI6!.5j44{W|Ll;=;ޓ+X`Uls `S_RU**jaI(WB BJg Z +5Ϯ? ~}`_&[Vw!{,2ɛN#tfʿTZ%R `dYLgFxV "nStmWt5䳬RNW5i)#F2wAο4F;Ms/kvՇ/wHlj]oݗ+CgMfo+>ݭXNj>}QUDF~͟dD Rdc}DEx-Kݯ釴& ~rUo glU OK+lEU{mTHD_9_z"n (f( |gBQUh7OnU|) 2P+#@пOueCe%uSx8靽gcga ]n @ky]孾Mp)")x+Lb\:yqIJAijzY Ӯg2>2^a+ 9Gw 1q³;imXlset.No=2!9gY`@V"A@jvG69Y&$@ܻoZ6!rյYb+Dm-mZMIWC2`Y*?(Rc)̜phKߠIۮpbXC` E(D߽(:dG{љ_@x~ sePnghç'B:6v S Zg@D=~4k)N6YW鯃.atAJ|Z/ hvMB&`S٠s'1&Q1cG㻾 fj@lnLg']Ǹ{]n~{6mh4Y#i4eH19F뾰PTH^">LֈtLJ60wErS3wi'Prw")v7F@aB pR*yPoܼOZ]V"p1 وD0%Joi:P2L/ CN_ 3|8=۽ZiaK=drĚLLi-{ 0c'/u&|tWⳎcۦC|nz/א!=ODz)S&jlf"ĸl+JƟH ywg:SdwΕWaS&h B#y ,   rWx܆ն.~̉_c¦BHM-{5 VX!XM"Q Ov;WC[.FJvZAdf -9 0YmADzdtf#q:J>ȸyI̹d@"k |>Ck}(qG< {( `V6D\qK4yᯃ'$.E0_kql&PR6Y%J~8?M)6{>҉kiM2 弙7AOgSc+|ZRpYi6r0a{"E߆8_q]}kmwBl.LV;amj.c#N{ Z+DDndw!T~ oGKSPs/o*q\x0kz يج^Zp8c{/C 8 pZ] jSUٝLI˸0%Jl'6T0<.)6VIcHG=pd,%\q׺kX`O({QZ)݋(@oW$ѧ'yK1(KK XWFf#tBqc|{IjOUG|v{?2#`k(mxC@T-aS:00OԡNu'dtX&ehs/NESBe 9+4 *@'| ^^[r=!Hi8ts{/(%i\,>#^c q_nyT664R7 iۆMj%m;>ȧX8/5Va q[?`i._ h 5}"oQ% }.|/95r/_ 1&soK0'`9qcqwe\^^P{dم\f^i.af)qcn9԰dsV͌XrL@5^c\ E r-cuTY]lxLen:)ߕ!B3|pp.qc$+8#srJ`qKÛ ᫱z0'Xuۛ&LO$ݎhgkF( ?TP `i*xπuv0?5kOLC`Х6񞇻h3f_tm,UH2^A*xw\ Z2xQ4jm* ur Wɺv)e rEnzn06L zj,d!Pg3JYo*&2@=ɤX*A?TvjDX8P*i{i,jN@"N s$dE=l'Y:_c Ψ a\T i;@- Cl? A] 0dK -IH6-.\x -3*Uߕ:d{H@7uB= U/s.nr o݀-=uly.s5h٬P;D`TR^{gXt@`MMU "#‹o"TT2*[ ՉC ߟw7i ,8 Nxr ٖl#Qp&hOHmlP4GI"G0ӳ\vDq;3z lo#>Jc ͓`Hy9.DQ:q0QF3/ۉ<2ƙr~oVG)l)p29f&؞U|)pƸ`3,J"IC)mvD ako%`-^Ĭz'i_m.CiCalIP{`mܨ|} 8]uX=*Sp@4[1x氨m՞z3 @?̛1uTJLjOО ΝbV:"{~>}Kk-lsrJP׃&mܹ%*fX5(N?.ց: |sw!V-ښb?ǹ$/y$1}R&@auN"/˜Hfl'ڔi{} chZş8w!c_Eh)M1LBNQNi*9 RӽBYPߢq(t #1Y{Ǔ/gxO1g=0Q gbQfo7a|[ n Ab$ZYuxĨy%1p+b>>ؓxv߇taOWogV|a1n?RU=͙NKqWeHT/Iu醬YۄV@fdj,$fҤ-´9^5C)ގv' a-SL-Fإ:]6vϗvKš:*63ދw vcÙ8l[`ٮga%#"\Owf9_ua mBwq8.^ZXBBm J< TX8"Ƹ*k% 3L"9S,H킅X@=cs^(/\GDhZ5d̾0ςjcpg}[Ӑf5s4bKs-iBם|2TE8,lԔWr@3!"hԖͮV4qmQuRi*RN5Ja2Q}BՀmpTٴ" pb.a,."`tOvTn7'9H"s(WЛg)/{50FnT>BCc>qXڄ0UbWi'OW8_bZ"@_0SFH |G~}š%F7wN>FX~T֟b9&ea"m,:V#&kt.;ˆ2_X:hojή´6MMUCEP1JJ?E:uaˬfbNa]meSsņളxMmR13 XČ;34t}95c4QR@G}iCc/ ɤKuXRpIzT!N8{,wSJ"N WR4mILlr (U(Ͼ_LLAʨNYhIsO ^<;:N%l`bWIYH~zgZa_+DU/=cS6lɒ-*;!Ӎc>Ebv2a=Wញ&cLu47αC|&X 6#IBTHIM2< $4nҬ㥗Lx)|EFFgvs6:A&\~z*652dĨVֶXl0 8ktڼS4W>_Gbc6at:lKݹH[nDWuBf-Tp 3\/G1=Y0-͚5;_#-yOVv<oe/ Rr&UB7.0z[fmSLǘ/0UA1?_H"ڵ'Zt 5\@Xu.;Z)GX,k hfF8Re|%7Gp7"ݡifQ:b#%V(ws#U4O6KPeV=R0a/v%@(- ,NMuFςnKIAe"}d5f7&Ur/i+ S)O#I&@0|fp P;m=䐿m7|Zfҙ^MY@Z9;EW3汏Rê^] #4PrXzh4-嬗xVCk3aG/L=,$eY%|tR1\*~0%a-ת;G+}VA?]ʟ\"@n[W|!GN-#ٵ/u: ӿӦh^b('-cV XkG?0=k㐮)/߂(+Ϻ o\E!KJm0[\H&Eso`oAo|ඕ5A xSg]EZN!,ݬ]?|+^ߤbhY3=ܖzqii_m{ٗwL6SȼL"USY;t-=v 9F-$76[U_Cr^?wjV&i.4!S`S6 5ɁF2os3Ag9~B{I1x61.Q2 w;%3kWn5,Ѷݸ7).&N(Bѳ~ϛ5PN2;x7듹`6ڄg0pwSpշN3˒L R*Mf d+JW5}#,hձP^hX o1z>8 `@V8bAE퍝dzq2RA/?b֝vrLe t'{"n yy1anGvE"L,X$\'\:K BLR?FiC6j3uYؼ3i&W1fnj+9aq$݊n7~x%څ-. 1!OLь>Wk3d%On POa@($ڬI!kr!Yt=/E+w= l]3 .e i/ӬfM/J,aP$_n;$2`a0Ʉ+PME gb/ǶKab[O([GsoY*)0I۬=E#AU)Am<ӡ?: Rln݅j D9U Ew)7 XjP-Sl,N>x unx@{RÕĚ?zTÄp F9Q_Q'z9GTt(ۇđ=#:7B 0d ,B7;,&r@%|aHۣ?_YnjE_O= l F7iG6HƏѾ>ː58n 3$.ѹ(ޤXkʻy`m͋i m41kEAno#i^Q :SN]Џ6Ƿg 9ZM$j)o_vJ#@N@?8՘s0OX7I#%O;`8skQi<~ջ` wc\̠s ٔ%%=yG(H3L%i@7@ irAIeǀaM @껸Lok5GȾzQmk,0tSv<_b"QV,<dvSu_K 0.{{ޣn2zH?#cuߵi\۳F I95 ,;>wzL_WX8Z9sv‚de[c'_38r_dC7]` $"WTl vkQiMg\~i;6jE>>sL xʵyI&&wűё/5xoc~&Ep XB&v/ L2+75ȦLJ4!h{:C[+݅0XbCE՗*̨Ū&x :י#ޏ.j _[zPD-C ;;@ʥ1eɯ^lYљua |kt܄Vpm2ݎJS>d6:4fSGL h{\YF ZU8JaE10px-+*䷲{_0|I6Vi:{&xqDo,え /hVۥ ę`]\5\ xp{ر "p{̤[Cs=)1 fܸ\,jDė8)_sRYBrCpP4MMJ"yޓ K Vv-3zhd6 ] dqbkU1x0'N&RoYdV^}DOF'RP~קm`VX5zx&6s y7.M[I G C04j#[L<|DjóGL% :ڕwIY[s5ݖ+!؁֜@ې/3#)O# cN*&U:Bx1(W$L[Y sq 8XSDw.`pnNs~heOBt=7`Z6$6z; 椒"G<1mK!7W^&)9yAG6FEٞfьbݡW*[h}I^q ˆF3g35ea b(~9c|/)uQ~a;8%4AR sBiA/TRdr7 Ut Mס#Ixq1,/pMc"ĿSoA݉m7`sȔCIӔs;jgZj 7ZNqr `+,V_ ¥>:L3G[2` cPsЙ@ ƦiAA&o15~?!e2&S&oo, Ѯ@"}um \;z$eN߸ d_2U,:?KWOa^ëyP$O#i-c X;bLȷZ[ø#SV_ѰMsg-"cUeo[҆k7)񃤺m[=5OaG;OW ]zģ7+h2BKzMe+Oojs|>>5pQChÐ TT# 黐y}7m~e2 u/n{m(H;~'`dޖMfG ŶOKWZ2:%B N <§z\16?@0"w9*< pD0yGR9q⩘dDRtVdlB )xߩӇ" :2r]747hhxgģX!uDf&Rr`C/n̳d԰Cn?zLW!OR/kb@+DU-ՙ)wSWi֣?1C_+'(2aX}k_(\`)orA(Q(".xcx@n6}m#N4{lYq)Py&FavFOkuȬ&ko_奧-"::>M+&o#Lv5/g-Sna@,CUrPDcۏa&7:5,|#\ex%yJ(]c$|c%r 3G6Lǧ: E7߫6,17O睤@qIۜAzV7[Gm@=}Ĥ =oF w3M~ qh?(K<~(3BD8Ï5M=Kӑ* K}Z v Ŭ>Hٚtf V]o5 5Bڌ8Nڪ|nHۏ0;lm}0L({LxDQjj3=*|:ڗ wY|Nj_m@L?r`x#˂aܐͨ ˡ%$X#aY @#;uǙcpsp\AyԅEIX߷g2{6&}@AB_^MmH{e 叚f}vgagw>[^ 1 ty:Ż+,8 mzNdi,e.y޳29(fbl?%:$߭ oK!5qpcVX6V[02] 멤$FR7Ġ]4z5#v}˥RgVz(.c7i\w~~J|ZDYW3] ikF[?y ,X\yS"|i):lKv-<_Ɓhh|.JNbR n[=?(["dDAݒHS~; pZ7ÄG:I?*s{^Y8e-?Ppy$ Vhk[uGSBݨtu?0AH5RAj KAκ6I*Q,*Fꪱ5k%ThDE ̓%\Rw!W'Ư'>DςͣrMӅ@LJQ9fȡͳ&VoC_ }bS8pbzf 8uNo-/ >tcN60+,~&Xx|`<=QsqH@cϬ}]˞;?>ͧ <  8!l=AcPDPPELPGl'y8x&'Mш;Ǚ0ƃ YѶ,qRV-<)!1(2FʵǚH*'H;uc#}$=>MO:]Gqt3_/? fD[5[ פ1{.ey$0u׬ֶ!2vfL6fм9Bz|Ot Z˹U1i&r V2/iʲ9aǭ WrD#k##:6M6ܼYIq6WZTņp!_8b}jc)$WAHc4F_gd;Y}yau]tu AI5Dٰk_{TJ5V+H+zp`,-uѐpܖA"pcSN\Цne{6Kl4t%Jy  mW` NhY.//l~qq؊*Bhlɽ9%# /j< 5ױ}~Ka! m%9ƣ'8qTCvշ 6J" Ԙ7Ŭ p2S#~T[1ǿnbT!(h~-c)Nj YOɧ T-b)dtÈCWU2ׁ/.eGVXB" .l8cWbJJDQXHGa.؃/q9 TɴBͅuP0{g*I4Dzc'B(`XDd+@n7r1ToK 0!]_8F]og]`BC& w`q- >d]n>0e{R&{v*kqo9HYe7 ͺP0b2= FpUByd:F oZ7& zX{]D]P? IvUjLMqtۺ+}8>@׍Ћ6B{ZĹTQx;MN(.R|QfQ^ /D; ^EIb5hm`DWN喌*J`v7㊅q-،%<~$85bMvQe~㟣#ߟ(L4Uk Z vp(jxg&q.%։Zw!{A~"@)5I`^fjٗ]SRwm8[ؔ#`#xrnXoL6 K۴ðikqR\xjIi$4E˜@ep|"غt܋Caa}޹{K#S?)h%BiCIϲ'w)ӝXTQ M)i9SQ\uY 3q>ɿ"xPg~ aG Bf˼RUAAcm5^lrk.sa>Z[-CહIVC-Mc;E3fA4/#w7g@l;; c=g>Oq"(7\S47ԧG!7NI{t6)llѤfJ{g#Ҽ$0B⚏4ֹ6opl :Un+!|>N/r;0Ajʃķp Wr/tc?hFH{`&Iף3O"GI y_g^o+@( Y_xcQYL~o5e$9ɳ$ u1hwP53нBSOR*X]rTQ\>^*Dl((U"?ٽ{vx[õs!r (z<5k-P}Ź~A]C/Pz[Hrb>Cprs fO )=3wS58A>5SjjG5iuR8 w7Oփ<-_7]vt\~E>k7w&ӴՃ|ԉz_ :=8דJpH b Ǘ9d!gv:{(6#\^{ʽ1u2 nupXLyzJ$,$M7zzZZ8L518fu.ビ)Vqc!݆JɄp: *` ȿT<ҟv^06daj=/_je8ԍCj 9hO188LvR\1]e% ;l8.ɢK.*i]Z_ƌ.` ]s?RgHY c7H Ez"O.ot jU.3D!n?k_==j9zu3hIZrY{ud*hm7_ŲV}|#PzB%/>1]ҝEi]qa4;x6 NEщ)s0ne"ZPS V_.!Hbc)=|uجsreIH_ǒ3T)fw";թ(F.2G8n= 5׈jqϤ/seZij`Wm+ˍTPz3^W> /NJƲ֓|lOlW' ̄3=T=P'RJ `;4E,n[gʴ' )5tHY1R!ͧ(#J';bo#ݚ%&ARy]zb(U eKR2?3qyTmCkMM>1 b c<ta%= }^.ſ e3x92?aGRS5?#5G 9SJԓm!ņ@-[@[qfbЛTPOrY1BsB lMREr&nj#NjC,1GM3䥡6"~}fl!Ut7.D"/dmO"糃n-h5VIעkאUt$1=l96c =ܸ6'~6ɂ1Q Ȣ c6C5'\ !S/&r)9e c 0o歺zc Ezx:3-uuG3y )XԲTucl/iU7\ =|<7Sӗڣ\Ϙ EnVBrXxW% -E+h[XG &hjry- B,Qe/&6"% Ec1֓5#dME񏤡쩶s/'2/4I4haǤJ"ljB| me&LV'3ҥ3~Nc бD%쏴`NBd:mW3Р:צ(̈́T_.) zצBzu f@^q+&'DlHG U#DMڴ0٭okcƁ'(DjEݫgA56fAC^8t˫wQԇcxM:I|WXȧ<ى0L0()4퇫W);^ ?Ih8 qncC ~9K#m2>K3%5$ۃT՜2CEG[gWZSsmn'w8vJ`6Bp^`)9u鮇HQI"4zw6B㻉CnQ^Jι }y`>h{Ko@)5K㕮 b 8d$,ҩm#m9!(3مl8^m&a@v P72I>[* >&S&Wp"$BoT^64(b ]ce^Du2%`uZfr'46;4Ӊʱt ]NQhR+7=F7_TF!`W}G{TJPYa鳵&AytV3Vrb]_Lc$'~*҇%~fQNTs{Nd <֔^7LesY'RMٹk{ g]sĝ:!i_Agw4LM28ԄxX5l};uTW ^iq J|Õ-q> wT} X?8>T4ƨOg"AeBZLÚYgD=gϔC ~XՔW]qeq"ߥfnGjR9{yrUI(iXO:tH!of'Ъh7{jWaȚ jo maucZ'63LphzMR0Z}$spQ7i`0܃xf?\ew B,W|(%?xcZ4<#yɬL3 >#my|Gn>iV"H2?&Ҧ͵E_n\KV((%V90X 2=9Uc%F=RdZRtbrJR.u6R["?%i.kj`POSm3>mU$.BEsx + 64i8EYd+áaJg̍c)hu{\"$BѸ,OЫ uAU~%5sS0i[/渉(P+ˤQ誼/v?jQx0E>ାQvLbSݵݯ_>k'VLy 0=fcVunRW*_^ev:'a/L!9&4'sSn}&2T_wcwNʪ[d+I3-20 |e유sz`VUPJȜ} ^K82z;ڊ׉@- # @ٷFR1;u@GZ[pq,.d'*GY*b:Ax v0H(jsfhP(0RnOZ$ux+R)I"CkXD[*^ "(}vv* h[:L{YKvh #D EN4H<ϡϩ7nPEI.h|ZJZ5a\o^K$ba"'w[ {b:(':6t#O͹BH$1ᡩ=p[iu[z,ϫؤZh(KqV-G=\Q2@CFK8QѢ101nȺ9d8MUJ@ ~W;P<5[lXvaх猩D Z@w#X.A򝶱-2y/[.j-C`Ly]󐓐\(NepϻCr)^2Ob)'W;*Aam*&,Qǘ0~,C[M[ 5)yĂTVWm5{D!ޘ3A uo!8sSX |\mhq; GoݹD.wsp?VѠI^ HY~w `P̊cH5PpffiGH"UWN:?VrJ5y{+a9Č߻>gOF. TPйdTM~ӡWʛ_6Ѫ2i4:'I}+0^ %p-J0کuhKMfi4)ʍAVT!b\h`9ۛ{]eu(鄬]Xթŧ&hPR}\9+vei8VnHqKv`dPaYhMPbkeZo2«'9a*T3,LA¹U>v/vKD!7Sߏgiaɑԥ>?maCd %7;e KfF,Lseg`m'lC)ڬiaN2C ߙCyypyu:$Ln75ÎfV|{K%B SzJET&bL' 坴HtPO,xۢC^T,CYFzچlu4JEؐu^ :%|~SC»K@e'[#=˞hBnKA.-Yxvdߡ ݸpW,^]h!  -nrf%v:ҽyVωKuf_P/8<#FuE:,(ԏ͐ep%_VO}|+92it"6Cf|ץ֞9U/!&>zvbnV%t V'&@6rqT$82,*:.U&e Uw2M% x-hbW>$;8'I]l\}]dpWO(ʓAAEOcɩ&M@0fdAy7+80,(Q` J<4SjJ >Σ=7ǯQf&zc*GLuh /Ӝn'H4Rel= pmv3nY9憉^FW8 ZRXSX%z%[n9(k_.R|); H3YٖS@IK`a}EdBr=}|Ȭf\;ed菢JudC szĿd~U,ӳRJRʶsRe)1-MQShgnɹ!#I;X{Ib7Wv}X@@4F\>8Si㰉R),JOj!&RU1X6鱭UNтyoFQ|yG̓`uH3lqI3PL&38 ٳLPlʦN3"Z^%("r:O%\7 *6 Frx TyO j߱SkumW MiaS{|{՚PMd r0`"jy/?Z"먉v!_Dd8ٶG ]Q^.%YZX{p#J.Qq2RJ˄$q` cȈQOuW _Pk*],AV>o[RnQ|+5ܬh(,R>qv6*~ϠL49墝bG"llcUEnyբn\U+SA747YnrQ]#~LmqMFP=*~f;|(D?pܛSP64wֶMd}ۢo}C*J&\#\|u_'Ðb5HJTTP mco3qZiP8d0skɠ|0N_(OFpڳ 58dSÎnSIxHf?/\mч8^fA}H$E>4,^6a*GZٝxNv.e&fB((5-eҀM,{[!kX eE#Xh4~Ej.3~ I )Zb^ &++(Jmgt*)dJ̿MH)_runN;ʳiX='/dahssñ{YO k,Cp9\Ho|^h B V_cWP/ *9p_$)ڙTwddh~D Le3G;Fn KrUaPFCCRk)[_/Ghd+T ܦ_Ġw⽊u(p?ZЩ>)K-i4.#იlcI@T ' sϷ SJ-Z6:ҾoAcV%~Ypo&3k Jah$VfU>1L"YwPCaJ !jN? qQPL4q՚]5yNvǠc)=nNk3ZFFt7ɤ>j"4-oՔPzbxH \ ä.׮NCT;ቇޡ@p奱JTb)XFJ~ ،d=e1#:_2X"rV`f\`$'+S=M앸K5T}oaV$4d3f+ѨΜT,7"4kJNUSAvmҬ2\gM->Mֆ׈ɪs u?i0Hsm.T<$d^I(_aSg5}⮱<]!NˌN5vXX,/5<Ϳؔܽlb}f\_pQԄ'Y+_wBwo#of0a%2M?yz6'@Ias'+ __q%$/*?4ל-UiѰb%K*)*@8,d"frDTl#, gXU,vǭL$Z-/J;1Y1&]cQvQ݆Рy.Ls Ȥ̱&ʴO| :dƼYR SVCkD:PM#%wRA۴(LǼw"gL?Ԏ6SqҰV7Wu@#5V6`(_B3/*D[ֻ6h(nzTLl-`(%U(f9ilU>܌)Ю 1o3Pi3Dl+eDZfŕkdPY@;8sgCtE{k9Jf-5h;XŻSL-RDb_⯫uҲ&\[ts"y]23琏GK] ̈́*)")Xb&@fߢ0vQy+1 Zع1PԶ\fwzGH|5ܧ >nB(^[aZcR[2Qf\'qT))[q w)Q1Ӥ/ٽn o w Jxޚm;#VLZX:I?C3bG c\ANsYj\S@͌T_É|clgfr滝Zx2#O>@7\M(YHܔq]—Z Z<?-L'fi! ZNcM@c 1Lp%_ ТUR,#2R ѬΓ3}縙 woS.ÜBj{'\maUEڼ>Lzpʨj/;!=3B-ڟ@ض 35 fGU'R(zF3Y"TșƳ\ScɡçϷ/ɸp NF̑EmjWq\$qw 6$(8gkTLS :l.KyDbUas-X1r"rTNtoq7]\Sj~|8=;X@G"DuzTۦ w[xv=2b-V"'j=Y#k:,n8bJb&.ȅFhH`&>t-TE9nvT?lC$}^^5c(5Y[? y3 ,]>=2^'Y. ࢉ˿ό]Ʊ@ln-dGk_@ODʲ|?O b0cgƼsMkeR UR5I&Mw;r9(3#!H搅ΛnxKȜTVfo*0Č9D\AX3"}c gNC[Hw:+dC!q@7o&(=ӘT (&8ॻТG׷s,85`@Ѿٛ=ӓ-V4zmQlN)mx0#`.9\_Y`Pr-qg}4s4D &wivR&$@xD?C\\rUIrU _7^Po@u%\=4P#(Bo񜇅ZD#s8"+Q1y$Y-$֓Iކ@?0@PJu 71MHB,{zno/ؚۙ43mE)FOCK 5b2ܐ3^겤\{hRۖ> RHb]k#:|)]@ uG&le0$,kT 1QaDw@n7Olإ(>thO:C~Ҭ2ȿzoVrvV\S4Ftc7'T pG!kg ,\gxj0gիbl!}v!鮪C8WL(cݤEOmN}DĶq.p`~\ TtSLizdGOR*?ɾ˾>Cn89ζ,%RF\)m2" we]#9 ɷ32`'f|-:6DY09O_L|rV.:5˜={AxWNg]xLuvMV 4MrO[:0S5}lNd͵)?u0L~J:g*dHB+'"ml{TIm$\fO}0B$ՎPUoӕ8VWoMub Kg\75$-͸K:&@Q5|ivs/p?;s-dOQDRRyQCJmJpڏB d (4/F5@M.YofFBg~qF=aFK4_wpPG[m=Rkðs_#z$:u1Vebp\7[D؂<-8+SAWgcxb? IJT.=n!JqN"8Y;}H%`'ZoYLJQ,e0!61o>O>W."Va7S&֟OcSb3 VEz`~fX)V-lĤ}+kIvDYYr!ZkCgpriqt^ZYBMi;pf]hIUmcNJ=ײ\e -"3o7_)RR?ød>JU5:A,b5R5~֩c _!kL2ӕ} d(HR6#Ҁ.~7L$!* s6Èm"[QHJlT%Q8K\UpC<)׌жxNgccHq*[Ӯl[^4d o6\>~!5<|e٤sFܔU }Gw(sFRYxοs{n'ۦL͛r$ƈ8enV#4Ln_Í iЯtRg@D!,"^؅x?YvoCٺ8m{yDeVsIH˨/\y*Qtiܥ* jC>1/7ڨ rTnrJ)6J̖ڳsVy߾W޾dB"e{mHp:L5&f_.qQSm }R1HO2BI}౮~j辢Vs|JC @H 6Q SȢ ꯁNu&APoPvҠv0.ço<Ƥ~"|)c)>V/.CCF AC(F¿=u%Ǐ߰.HWkGbHJ -7e5qHT=.ȦPnPI,.ҙΠG1Gw155ܜ#ɆLCB\/°u; i@ON?az3G>y`{od9t=}}"*+dLyՠz{FQeDFU)]8XH8>;bzn?:.ʧfߊ"M"k/vUVc^^VN "T:8v֠6Y x1~2_ݸT -`jJJ9 qXتuv#' (yk_߃)MPD \"rKpa ,kT?(dI'W]iA]AsEt0L{Eju2{H28NKC 4 UW~#8dΎ8oќX8d>O ,5| cr쐗sGyyDV\<fcUעM%.0<D^[z'F#(5Ӆ0J< X!,-E:@@tiS-W@zV_{7ei|]$k:b@S| l;]ӒBW "8'Z2$.ud򅵤{~ ˬ*Rwf<["eIF ӻ,qr?G+mwLMXZN8uADžn-څ/tljLE)<(s $A|Nc)`@bxX;kS\ZCޱoca|s1ƌa]bD@ڽ~6~ҷ-7|i[fQr[W`"Gκ(Qw3w Q+8d/^"r$?hbͿ} }{FL[+6.ʹ߀uPK객 kL Pl)wс!wwfx&/td g-h _&߼.?w%*V , qh?{~[!k>~[R7I'9#Ty6ܶ+L˸ /8*d?Mn3'FH\!Pt,4F{n3tWLgnelϗN1?4@a-ʽ(e&ЛP\ @gW!;1:ݽ<w'%dGլ/V01;a ]eK]<3UsW . C٥=h P&=SQ_*LFRoMձj,;Bw6i?h8IaSus#Jjo*)TR=R8]eoP~d{{6 [ׄ>[Ӯs*W7t.ͳq,e֠yr%* O5VK)E =_CTuf36Q,.O:OxDgtU^i^>{c'WCL/;`5io':/’} ZlfZz)'ۯ2gpQynפ~}D}df] j(t0 u=91Z;9H³ǐ',\fYaUtlt8$tH0Pǧr==a?t׉aB8OT s>Q.#UG,-SkPc&sɥ&PK#Mp(^Pn2:\" IXc& :n^ ^lYD:٩A֒=P[h?(t_-/VGR!ӊq-Ӛ[ssdi]8r`L6a@=:ץ&2upHR_HpΛ{|< aa]~DDm.ć2a  '2O01pey7dG:/!0??pe%%CnWW[~텹EX(];AJ]C#W3} <.:,} #.5hڌŒi@7js(PFd~t:ֱ;yu3ei#+~E5;ёF 2sU X}*9⅒I9.XՒToGE,&ዎx!?FChUgzveE鶋 QZp)H-7 *_!0.ю6XRBCY9 cȕƽP쇩T4Oh!K8t# BX[:_LZ?f*&LL;IeLF3e J[`85GW-cf8`2 Sz (/qN$\I"_eE{[ڄU݂^V×5]I~q i7PzPr"~t{^Wy=gQ{տk1|ãt"P5JXSw6[MӣDBXl9YI !tI.'ljpCfb4 @ԐYFH񘟍.*+^+ޱ_ިg >Ʌ}_/gr务`SRLZ}CަoKm*(2:Ho1K`M8B$$tIɻܮγHd<r3WwNr8.\UxVrsB [y tt"ZPD'hǴ/{$}cǔ 5wǀ]&?ml9}ޠ)3`6z]NU}z'`޸/mYݨ쀰g4V_{} Rr52gn`k>0Hy:%m[r{asG?EL>JPOh<أgRw/Զb k+*a48Bϋenuy]vf/-)'CDd0,g}l,n¿FH\XP1kh(c3V*[|q:߽\HŁf%Mh2c1VHƔQY7JC+XL _}30EkME۾M{IVM.jg@JYϫN&fhK# =Ƌ$ǯX@9^&A;ZUN\yVCz_*ܣ0;?*[x!D0OV ˫28X/eB>zͼ /$J`~݈X?ù5'zIwkf/oRyDˢ">;<<&OXo4^]>F qWJg%W̭$.jB܋̞d!F5rnplx߄^UC"}p!X ^PO{;]ei ZR'ǦPLT<]df#hY;n?տʟJ| zV 0 {,2)ױknh|ȁ;dQ4?v"ڕı<ҍ `tܣx9w_Q$oO0ךyN&Mk|%xHtgJ}Fjy;eYEwILl]/ͽN! cH)p]#6̫b'JIJ$4KqUDO5h &֓נTu'%< bfEP5<̝Ȳhf]0ݦVbNݸy!q(:ɢ3yͥc(Q- iCí%2ml&*0U  k` ~[I*5ijPHZ*l!%W,JyHe nh8T}AIںɢ;u#/R` 8"uF @Ozb:`bz2Ϛ~^ 8]d؏Y|QOLyP3oz9 _KIV}ʿݒ2/7Ԓ%1Ce6)jquPوS^?V.ɖN&ryypj~煮c1)TK9"] M$Wq6'2%Y !h_W[Fgxg]!b~%PTkR'pX0sg^ZB{Z|5pm2RIK 5i:yC&$U˪"SbTVvŠH=kـ J A,ni1&pD8;s)/uTh V!IdFLQZ[iKMÀ!rˑpAIa. [,L eAm=a 3Y]|^(cQf+9;tg4J@(Rtq󂙍z;s|Qe?8ajX%_M@?̌^Zj=O9kv([)wFDi~4rAsseN>7 "XHKU]mW Ot; E#FÒncM5|:se|^\.WFo1p)˘f?lKws` ^bxnI.oT8κAMR]4(r[k;1lC HM+g U|Bdl׻nsPX1q".S5 FAZDx5u'>;=bf!TVQi.Tn'b;BL>3Iʆ|}H{pQObqSnrqQ9f@ֽ@Wms]f)^ze8ΛZi H|Ptڦj<£v3U(0.ؑO~KJ\}Ήv >~y<.{qۇnjUP/C$9Z&kQ2y`ō̅VFB!Pß0(Ã^Yr^_Q%U7u tܔߛ:?L[ [޷ ¦褜>d R|aʴr0TߊD?#w lxT`!_A"tk@ɍhs,F+qӊfi Y\trP1m=cx{ \\SA(#ag<~A*h.ܡh2z}z ^)0Lr~\؁?k%Yatl;Ow:tM}FK>QJIhA95SEvfjAqLzxIEJbuTo>Z$rKZ(SmvFt >=A 84\dzׅD~$dه N/6ﲭj=v +n$DV?c|$f7*꩚N[DGz|M.FB6ɏIchcU8ˤHevg [ZV:YuD_? )=-vml!5f@ C+>K=vF빮O=/ΐ'S]/"89"8Z9tˡ5 ռJ%y2_1 XtL̀BArnĀlLH׏UuFB'X~ИjGL:`OB8 e9rppR~'Fۍc%w_nvϻ<̈ m f/0=s c=:.!Ϭ,X_u{DE/<3͏叺H )2}Hè\V;jϊ9i蛝'v {fݱkw*<+|]e}0k+ʲ<+n;ZD h=t=|]Lߊ&^0#ɂ3^} Av~Dz- tmhpf#qW+Pdus@YDiJɕB 3 #lV :|JO6/sRHټ79zk̉z8eD!&WENhRbǦ v9ǟtI R4|zū|(:s,?ĵ= ~Iɐ]ў-׳V |1h!S3'g&.:qꅉ"8?Ը>jQ^{.x /o#Psʥ7߼099dhMFǺI 4i3}B\(&#Ô $ER`/iwe DszǞF)\*my0njM̀ӜWu YGΊQv*YX8p+hQ$2 [K߁&͹VZoUJ|$|`0j` &G&t͌d~IʓM( H,_ Γ!i771"w8$>rZj(RNw 䩡yE0"}>,%EA)MtK{rY):y@+QXW_(Pd#0?sĨi|2ƞ_7HM6kk]rC3wkkқ͈5 6m&Kzw35JS~DN;guHKPtH첕C63Ge1UhnYD͔Q;g" srb9U?n!A3ťkc,*:nOpBhnچ9F 5|uO*[Ƕ|Ob'6? snGqV s2loW+{`ř{:Jû+j?W!;ݵ8'> a7nGR;٤zt"O_F!&d0# %e`;3ylNKCS)k S 2pz=cg+w?sL5ߡ<^N*;O=T"jFoKVm{~+(^q}qU nIPT U%e65 t ]zC!r$TOzQ_swh+E sUU8 iJTE&omq@qp^SB\iʸ_{*?n|!n3{jK9VkͭxI=$Zvn5^.A ? CGQ'oDi?SS5,8Z)VȧC4ˍ$U/p+,2kOM@5RCH :?p*u#uYj'ii-׋vك̣ԃzw Bx<ĭڅSSD>Am6O >/Lc٨f;kXUQz 6FwfPJ}8IEH Yg\&3-f}K=*"dG^g0k+"lٰQe8Y];Vo@DNu;ʍ " hGWEC'C^ Y2%tf!6@4튊i@" i7eћH,y"D>yJMF[D[5%.cd_G,(SSϩýI9Z aJ7;I;&LW8wRJPmqmv{n# jO\jͷJ4 ^ajbq!g儖We<7A¿\@* \Լ UzTeE(FMJ[IvQnqGZ %f3a rfe Zus/Qag He.Nҫ٭,kS3y壏xSZ/"(G?[N)?CMY &/rnqA8 ^H[?{qoDaeH0B"h3 |oњZM{ڸr+%aGWfp`~iuu<,!ة|&'tb\lQ@zbg0:3GAe=jbe8]۝j|_[>n ;$/Ķ nu|Y1_m}Ln7[n \ۜT ' -g tAȡI2W9^,(.:2BɂNk)$"-eǟd_f/~4] *o;9`؎c7OKNL:V~]b˴%Yk$ lBc#OF/}A#W.ϢdemIyʝmb 44EX ={9:CV[K´|dvjr|B#inuu- / cn&^ٸS]xacX ؐ¾8v<ˈodƣ.ǰ8ODeG8Nz^X?tz_sMKpX#N8"aϭó=SF'|av l[fw E -Y&[ ѭRHn2dPJ&%(t2 {lZ7^Ab~Cut]_JDw W -Erd9"~]QS#G 4nK~VzWs1 V3* "NH+Œ@) ^jc@TE3?tzتyFX.a'2/@BnIA[3-X;\k xqj ^#mVzgzI$1>Q'0𵴓,֦y?V%eG^ș_vTղˍLz{lEԼVN[cΫpe|1q]t/d9Gq]$aS^ϸpcƑטev]Oϐ[u;MCy( ~{٪[lb[>t+{$cÕp_S-=dϰ0En}qXskW,aN9pmP#se1{T;TPX9rE ls?x~t̺ WDzyL -<t8r 6I%ٻT_\^TVBMfgFWrܼ3]U=ʱEmb^Pw4}HedDwv c,S)QpQ-7v2 I30n̴:mXU-nf6XY{lG:ޓ+ofoYX߀)m!1HP09{sm@w")bJtKTU^[@YOZfbX`z0Yss(j.>tJ%AH1 *w%^{ѱWύFg^p-2>I [KX @v^m< Hvp/˫a myM'm3\&a,PǙE}6ئnn ;@7ól?-UбES `s47Z^nђD9W^NF-^JRߵh%ܝKz6mUv->[l܈ތ;1<Ͼr浓7Ti ^9J= PtRϘ!'\ *i ?zvH%vBε`:m&'/599~KÓW/_xJx=EuȑR!t *] iPR=5g.Pk- V4@VzT7^u+٥oƞ)#.-éN_Δ "FiY}q~UWwUk`δu6Z0jFܛUvQc^v-[p՚F@K6Kn)a touT z" J,DFF~=rɱq-tڢC]uz@w]rx@7U_B~hFD\M2HZ]Vj/ vZ4NU]Ij_ L]}}˨]힒}^N] ϑ{~>EwWvR jhn`?/Hq?sH\S#lvnsC|2%lk~=ǖ+\2yjY}\{ơ!MlMMF NfӐE۵1-~V?Wg(b|[7!XHڳIΒ WU FdEt@z?i"f9E/cLHZLO]=N sAݍ&޾p):7֡kxW65_GU/|'O!J$sj_\r7N0L55uIfs7EΞm3i i wZ;Iӵz#}ʧ܅Y!.#( 8ծ+dUPQ*b$e{}et4m?ؕaFx8.Prz/|D\~  Z~ 1Er:jeY7m)MMUsPѺFX)Q~zQ;7M5)% շv.>ヸ!9:r1uvC`YNGR(w͗#ֽrX'ΆL,۬R9yC؍`)[[cgbP"%N>N0әQUw(lcO^|mY_,R*pvY/ō2guwQ..&زt1]$ݍPw!C=d;n0kYY m wqك,Kd X fٴlpAa?ѤyW19-oᵍv?,Sl?gtt[M6}fY@3x,.B-8'rڢtr ,cXZ`el%E_"A#D3uR{*d-kLYc7y0VdUUV1Xȳ)Js+,/d0<[l cBARS0_?W}͒΃9g[Ht>\QJ"/e>w0ƹrFK GƱ? @u1QS!n 7.$U|m j\^g\5V{N>>@ =qژYLR<9ƍT=MstyRh xy?A^SJ)uE'߾21uy W֯KTsU"Iy'q@YEb٣ % #7IB]jJ1\'HW_'9n)^rȂ\r#xE%L5!UɊ4 j1Kp4{언 Kzq<"Wl7nStS qW04X3tp3JEЧGP q[ZCd!}O[CF7[[7rN'-/{#v۹á9$0eNw$oj۸sk[SQl bDHvπ 9-":'ԲӜNQu ?oFP^!O}K9?MԵY'h~dME{qNUyު|QvQ?ܲg4|ߩ?c?—=k\eJ:Qqmm 0/)db c{2FLdMXHp/.B9\mRv-sLJ*.> raC[[,62/I1/!~O0+=5A /1>;o5ZVqqw+M#0z/hлP* -&(s$%hI|Dfaq8? M*ˇͣ ̀TO[QX{\+x4=Pvz.h7оbk2y<{B[UʴΈld!M؎һR4 a+1qS5cm~N.tfd}pӾ6pc{|XXi2p!y ] ?5ӭ•#-Q\.DFx̣Z!AvDI'7'I"5{;p`Z|]".dZs3I8Z-$#h ?6cc; ppgG\I^Ck2lU[:62x.৬>&9Tc{,*; jT}fkB WN֎6 !/9&TPRIL}xjF[rURg,JVth~R+a){J[ B8)|-h9'6U<0ۺ=fu?P9 B) ɢ;S' gI&3j_(*IfӁ&.wщ"="pvۺP W jW{tȊΠP~d~>aXaX8:Y 9?.ŒYt"{`䗗N[!>xÉCJN[W>VNJ^MTdWLɁz kRG"K80q͂*Z¶k9u6=g0m#2p5,sCzIj|9tS_LZc$6mb2=ς6Iu>=̋m) &WL"0r09۔˦+CKBO=n[iNA5߭u {&}m/k8%g (>oﰿat ׳R eTΧՐh.G%˔(_Ư+~'W{:>g FIK(1g,*/&XW%sZ9jNR =玭˹^ր +{֔@mWB&nisIySET^kN(Ͷ kkF--5*LCϖxj%vWx3`Ws5\ O{S{߲іSխK*dॣP:MU'B$byGx b3q#ǝYQhY&d؝m 'PwJׇ9_T k6Yzr\/e,J\PI 13QJZWQ.( 'T!7EKa3)LQj\$H4?~6&k{yCGw؁ osШo@y E㴿#]$`ͮ-5SO/?S454z=E'W7ǖ-_c"[np۾(/]0!2z.QF/kgp M'j3!2c>A"rkp&Eh+!(0g1JMg)er{5YW{\]^^M4ykٚximv.o`Nphc*Sh Zo,g홿:dP7&mN`c+$5@܁9`*r;\0(8˹[ \r,sg_ Z<\u! NXMl 6EBa Ƨ+NS5`*TmUwS:ϲV+r^h[rfh0zoA=Lfzћ\r'(b}+OCۊ 1T}Fud41E[F2.$dTFsU{ '.S \+"⑘u9s{(c.ܴ8=vV&q&x;&2p}HTX䅃Obw L3CK]]<4oNbǶyc yC22tǥ$u ̕ێjEPֳ4;ځb8pa܍rId:75%σ Ze J]`:ܻ{l6,F*gVx>l\rd~Dh)'zoNA4_$HA5V3bt~]7̗MiҶJHǸ N\4YFh!_?rBu(2݋#yd$1^]"b WEk,%' (ۓ0h8F! xO_V*'lz.#sZSg54@"}d) jINLfEWC4#gu:toYOjQZ~5mFN=z _Uًʞw[>'gQ޷& 9xCiq g3nFe2^ڂB]H"g!}N)"9ٕkQ7CL["3[@.',C4y"yجB,u?;AJT7Dh?=:a C\3*idӢ3eqeMQЭQ2vnNgMOu^ܙcD}Y3րaB\ڞic+X:{ydztWCMX 6}&%r iw+M IbP-)k4{& )Aǯ I,kkUcy54@:w~Th/–lvOWu&b\tSTfrbE@ @ X3sAɯ(n7w_zgԪڅ_'C$;g aClp}g Wg@J u@E[066<(+K8N*C9шOG?LSs`T(쭾,"\i0۩z':N;V5s5.dxG˳$~߼68F?? /uMhQ|2XoW~Qs'g̔>>c|y!e`G3t ?-X\pp!H׺*#uy_AA߳aW"cYb7X@-iz[|e\j#=lu0Ytf7)ӝ; [L2i]fWގň_xB5.%g١⏎ ("u˰ ('\B#>\&0쉮NJx ܰA'/#?S<@ESTc5R"򋧱eݕb4o {}MoUBuqۻ3"g]a;i;FTtn!?a\7,Ŗ}]um YnKge*7a~jfv3&KcUjx[5yr/y}zUBjYc+cOQ8 8B]j(Cb Q{bWd9kv#: 7 ^^fϣCم~k{JJCm@2?k? Gݐpyǻ/4kEQ.cX;;Nl s?1DY`b%b-FP+a Ki(8P0tsP;A[S#u^!e HRdF▲t$ow?kegpNuÐlȭBe%Y/l/1-$ Ӊge,/Z1nM<?SmGMr]gg>xyY)˝Ev %'vv31KҒOxB7OɹTseQP+rDsO`n&*~yJݸ=X'ܲ \otMѶ+݊svTD\TH|ӟAjܶ5"+?5Sti oK.O]|s|ˡOӒy݋.^ImϱQgZ*[ *;/x)x%E$ŋKh1_ ۽|3}\mb$')uly͙ ˃jd_s҅굙vz-i z/UIz/V̋qkU<9 >F=ivBbaUArLt h$%aJ^"L*AKlEޏaoh]6 =V#e*wT<^QU|}(] <+g@T6ea:{6A}7G$Bc׭ؽ/F.C(U+nF.M\JڋɎ;B5 l7}ݟokы'^\ڂG Se7IԙcWw)_ap^XKápȸFE&v݀D'lqB&~晳FzNTԿW$ߝg98"*}X8繕fIL*J}U[#V՛#̥¸PCrym8Dig;I~{ZZGZ_\}F\ke^S jQlޜw?ЯՒFAh-^O߷X Z홥|+]~r-E2E$r8G׼ A,ŋK< ^nε,va&9i-2#oؓkdANg)Y!Ro#Lug]2u䗢ӧ^pM>}׋