sssd-ad-debuginfo-2.9.4-4.el8_10 > 6 6_6 3!pQp)Tξ7]mtZ`fȧ ]mtZ`. &)2g%M>F~ۉڽɌ^]eILΕjkdڇ F%(РHy ]aFE* j6#'E(J-}9PQ|Ynaѫ)vY> Rm^(戀\G(Q"!Q{+:9 wœQd0l1<8݆v*q嬨IQ 2t/Nu&w7 Dڏ%J2EOrEa9VmzA_yJ]CyM{ZМjW}{VSgבb'[Xm1kP'&k>QRIB6:кTb;ȑ(o3=fR҃FjicWSaz2 ^`=j=6+{CȖkO:uq,ᓧ(ƣF2́߉ukzkO1Q5ad4afd44daec085188f2e6331bb874cd6066216905ac1e52cc2b788c0798fb7960d3a10da3812a1ed7a2eff175eba67318c146bct3!pQp)Tξ7]mtZ`fȧ ]mtZ`}58#7?PݣU*sJϤCDv H2*HY Ǝ4Q!>hNuN`:~cz>Dbps5 q43T,-xWG1RQo}Cp1 UBP2˾`FŇv.\?AR"r4͚_xg jln2,#%VO?[| }JמDyrg5UbQVU+bUU6`ģ1^`9.ڎ2M0j)&Nc5~k ɐh9;6P,NC 襭 _LhX#4S] q*ꋆ nS=C]E? CK|wNKyڥWw' Z>ls)D^ &y:EDt\E73QGW *bZ⿗ 93;EծK3O?D,`0MiȈ + l>p>l?\ ! G(,17> \n   L  @0(=8D9 :`GpHIXY\x]^ bdEeJfMlOthuvw`xy Xsssd-ad-debuginfo2.9.44.el8_10Debug information for package sssd-adThis package provides debug information for package sssd-ad. Debug information is useful when developing applications that use this package or when debugging this package.f ord1-prod-x86build005.svc.aws.rockylinux.org KojiRockyGPLv3+infrastructure@rockylinux.orgDevelopment/Debughttps://github.com/SSSD/sssdlinuxi686<P<Qv0AAAAAAA큤AA큤fffffffffffffffd70d8478812894794ff825fb22379898f8ba4ba0a7d6c032b267c0956862325e2a8ecc8f79b56bc7c2cc8b988e17e8ac4736089e0d5ba92783e5ef9e33cbc7d9../../../.build-id/3b/5f9fa190c868d4da44112b48cd903b8c15e646../../../../../usr/lib/debug/usr/lib/sssd/libsss_ad.so-2.9.4-4.el8_10.i386.debug../../../.build-id/e8/d9a1e61a7c8881b2415e5c6a5efc690529a991../../../../../usr/lib/debug/usr/libexec/sssd/gpo_child-2.9.4-4.el8_10.i386.debugrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.4-4.el8_10.src.rpmdebuginfo(build-id)debuginfo(build-id)sssd-ad-debuginfosssd-ad-debuginfo(x86-32)    rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sssd-debuginfo(x86-32)3.0.4-14.6.0-14.0-15.2-12.9.4-4.el8_104.14.3fGFf! @e@e{@eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.4-4Alexey Tikhonov - 2.9.4-3Alexey Tikhonov - 2.9.4-2Alexey Tikhonov - 2.9.4-1Alexey Tikhonov - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-33957 - ad: refresh root domain when read directly- Resolves: RHEL-27205 - Race condition during authorization leads to GPO policies functioning inconsistently- Resolves: RHEL-25064 - AD users are unable to log in due to case sensitivity of user because the domain is found as an alias to the email address. [rhel-8] - Resolves: RHEL-25066 - gdm smartcard login fails with sssd-2.9.3 in case of multiple identities [rhel-8] - Resolves: RHEL-25065 - ssh pubkey stored in ldap/AD no longer works to authenticate via sssd [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-1680 - auto_private_groups does not create cache in IPA server SSSD cache - Resolves: RHEL-10092 - logfile rotation for sssd_kcm not working properly, sssd_kcm never receives a 'kill -HUP' - Resolves: RHEL-17495 - New sssd.conf seems not to be backwards compatible (wrt SmartCard auth of local users using 'files provider') - Resolves: RHEL-18431 - Excessive logging to sssd_nss and sssd_be in multi-domain AD forest - Resolves: RHEL-5033 - Incorrect IdM product name in man sssd.conf - Resolves: RHEL-15368 - SSSD GPO lacks group resolution on hosts [rhel-8] - Resolves: RHEL-10721 - very bad performance when requesting service tickets - Resolves: RHEL-19011 - Invalid handling groups from child domain - Resolves: RHEL-19949 - latest sssd breaks logging in via XDMCP for LDAP/Kerberos users [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) 3b5f9fa190c868d4da44112b48cd903b8c15e646e8d9a1e61a7c8881b2415e5c6a5efc690529a9912.9.4-4.el8_102.9.4-4.el8_10 debug.build-id3b5f9fa190c868d4da44112b48cd903b8c15e6465f9fa190c868d4da44112b48cd903b8c15e646.debuge8d9a1e61a7c8881b2415e5c6a5efc690529a991d9a1e61a7c8881b2415e5c6a5efc690529a991.debugusrlibsssdlibsss_ad.so-2.9.4-4.el8_10.i386.debuglibexecsssdgpo_child-2.9.4-4.el8_10.i386.debug/usr/lib//usr/lib/debug//usr/lib/debug/.build-id//usr/lib/debug/.build-id/3b//usr/lib/debug/.build-id/e8//usr/lib/debug/usr//usr/lib/debug/usr/lib//usr/lib/debug/usr/lib/sssd//usr/lib/debug/usr/libexec//usr/lib/debug/usr/libexec/sssd/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m32 -march=x86-64 -mtune=generic -mfpmath=sse -mstackrealign -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2i686-redhat-linux-gnudirectoryELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=3b5f9fa190c868d4da44112b48cd903b8c15e646, with debug_info, not strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, interpreter \004, for GNU/Linux 3.2.0, BuildID[sha1]=e8d9a1e61a7c8881b2415e5c6a5efc690529a991, with debug_info, not strippedPPsssd-debugsource(x86-32)2.9.4-4.el8_10utf-824f6596161f43582cf574e902e0567f6c8e0563aa8d535da2275701cde8ff521? 7zXZ !#,*] b2u jӫ`(y0DiH; <Ep]B{'hp.ᑘ >U1X[7_܉q# 1yC. PT"0es]^D`_pG.b/l9D $W53ύ.IN)L JU7YbqV#셙w [0>^PzJ׻]64 o_`*#&fA5? xa&mt^3肥`Mf5{cH~}oƵ3L,OFou ŭY7B јYBZCu*;[6C|gBKN-A/:&&XϘ~AڼZ],U 7(ZO}{\ p(o"{֟Jν|P:o?ƹUr OAE6;fցj:޳o`j%uA/˯\I.HPǛ}3.⸵<~YAncLRȿjTW'). TDGݜWױfUʽPSƘdh}( #4]yl ؘR;biIR[G<]Fo:Cl+R[BYm5Q0lIF)|K'@O&#Qv$V܂-u+cX.o=v\Q= ybVPΣ:!v-;$yu p a,&l>"`+ޢKkʽY@ >(wlG([!kBz޼C 6Yخ-F*pQ54\wxwcTۨdd(;JT"4+mߪeH#Cۆo8(^jKA 6~]߇G?siII_2h 2`efn8<) wvUj:~c:S$?ĕ#0k~gU΄j:%/O;M8$aPM!ˣYmI;Ro'j Sdp O|ŭi}SnI3&8e\2*s̴㸠PS˝һLщn&u !()yZX^ @9/] PyY|s=e&i-Ia.ƣ*(Y;q$`ڹ2aGr3\MAM~J,ѿpAw̺QW0%KYthv\GGi,7K9*'8Ϩqʓ{Y5S(=kxЇ Fz{c)Rm@@Dcr{:}#6k& ]:pfl% @wV>/e9rso]B.W}mC =1w}h\D?O&\oCq3%OYgCN\lmf GA).x_H㨟gܞݠ?of a$oO@ŏG3e;(a$2k:2)lHJ6EnFlO4JRgnͺo.*h+$Ia:_2C wtzȪBr^up:b$T,+ȰW,XG[R鮱gaeAWI̖$@TR@yX#O3{[?y⮜ur$b@-6hamф"b$#꺧o)2Lɏؠsu%R.J0Ζ):ž s-KO{{.]p/3liwɧrqr@OH9 цU?ȃr桄ؖc -+!Q0O_Y7\@Z!q0&nz*9#|jɓ~0#k(*XjRD&8nUN5ɟHTY wc=HY_: gDk G*}]–!(,͏C1aĚ m$Gq5A~&`P7.j0V}bf}2O C% 92&V_P[TpzNoQ=n̘l#x cl/f |vDm~0ɸnO)ɏ =ux:E^`Z;7ʴ-(8WQbꚤVOOHݍXiu$YvƸ(?}nUة'c9]'c!ڍxeڨ #/Jv7 sa)qsq>R"0Fj!t$e*飺x,L*93q# xUeE$![{`t%u'l5t?,.֊E E;>oB?ߋE&Y1;cFCfx|Xps8@:~R~21IGbL ygs#[AY)5qz)XYF9z``|[<1yK(J$ (}uw޷wDJMNpxtM'&|[DuKzV.?? Rr`D|6sv1Њ_YKvB8p7|vx8|)ٶr/Og2hJf`UT󚆠 [V@ }2@ֈ,ʍ5mF]]JWK l$s]+ci^_cV(#7qCsgA6)N_=rnDG*)!HGm g$cHȔ+?jNn*6,|qOYxpM(\GWj\T;s!vhTє^fn5TgO<*q輱+;GƾGгt JUˬ鎳VZj6O^ $(FWT /Dag0 lvԲ[^(ݔ}{VFqJUg<{ut\=:JhtGG]>FX-EU:}0' xSs_)QĆ*& yqǥ^\͚v/) G"ۉA3M< 3ݻV6A߹3 |@6.] dG " nl ,ZZ:.'cQCm]Iٱxc[! >eWuD0.YWyXbl!/XGZ$#B!kU#_^MIՁ_kuVa@6;In\%vZ5, yP&fxJOw;Ҝ̅c΋v|&,v2wMEC(o?/cRt"i Px+I3EZ4M-WMiw:ޞǜG9} 9]ɂ>:ʖA@~qg%1໣{'I6iF+g˗#13=Uew#debpίmy[,*('t.GR91~u&ڸ`c\c#v_-AZ(N5O,lc;f -W8%/@GX~'ǵWO`6mongW$֎1 ZZ낃(JRr :շļ~ 66׻O):ǩHTW>hh`eH5F[~'(G4vduzj-'+nĴ!xIVxlyXPe~7 _mv;-gX/tı% ]r}Lw|W9z~[ Jדee~WlEf= :"2 .T*x,BI a#w[o_T?º{OI_E.|#JKfM? VP0̡{/b%iL$2[Zh[+^z&/-S;iq_)+X1o?}X4`bKDbnpݸ> HEtlb Yk,UU~)ްNSu"{0b9Mۃk} _'RUM"_(thDN!U!4f m?jMljgInݿ×Aؔk+dB-yr]~ M-_PUCXa%:Gض5ZE9-?l4$rehdy`\k(qo Y&>bZ` =V  `tErx*/V|-9(!$՚"En$A(eY&EdTo~\ô,L?WB>ŷ t:o8F&bމ&*jLV@oq IW+;ɢQ3%#6:Ȩ[fg3?t$|7"K5p<^~<#_Z[M_)Y{!xsh@ya=% @$@{wǁvpar(픡0DPr.!}z 4%j=-.~RHH5ߊ`74K#Lc*4!ݿ(̡tOwzIJ;woQg:+H6Rh {ZpEu;nk AA@B-:W2nPTؚF jYGnU~\ڪّݸ]WT:GUUc* u^ ]qUCfU)T-f\m<_N}ثxz;]'8c鈣]}-LwN)䭊~o"OO,;煯VxpS^#Eܺ(w~@E Bw-|h>${2YKPR|qx-9$bb~''.6Uxy2z+ztD ѓeVSNpJt?;@zb9;Ͽ6)! p ; 5.M+QH|N=#6Ghe: 7^$WU,ރ(溙WRWn[ᛛsCzl$\}\uWydTIrd,!ٹ)btbGv$pw̾R\iA|O.yof럶)b*D< ju"m[lWt*i -4\PHg {:<2"f;v7p:գLv~nD`ooH5s]|yuld0t( OIg'"0_-jhedž2tTCeZEClxV8@pdw/Ld%[AfB/]%S7DMaUlQ=NW5wwA› vP@AMFo;ȫVjwjmb215P3MHeט_,F7 HAmXCu?)P+dDʾjU'<9nZo=*g}C_Y흛4jsXjzv*~.DkQ% :;j֌*ʫȡk!Ela놮'ǎzCɈh{3Oe)T2'-(]QgBxѲ:VWLB!5?) 3xy!*M=+XfA\͇ ޛ6dQY}ӿpc%tސ8B2I}4Y`; EHoK c{ToO }8֪^?Fܫ;c3Bkkayfʚ%oz>l"Oߌuǽ,]g3QS*uZ`+ p~}vE~9K{,?S4Ǒ[`'8FqJӺan}>\*15'Su܄)tYHr+wV/1PclbMƫ7Ɂ;ыk3aU6?hrft+`]'}VhI%ռlB<| O < <ԯ/&{(Q#"Wxnr+tλ( VУ_;#/B^:5tsRQsVI;*6v63RB@XIΌ~g)gz-^K_.Ñ兟31YJ $q?=Z]cy @ijLȬlԭ0*5r3=N!(󜬒]epsm*w=94VYdɾW7ؘ{hـ4uZ+&`H4[/xK}1eW}^ ΨyiՆc*#>CLC ݑ-tqBdPjt%<`:xh͓ٜ:D~PG?*OmOX{"^>iwy$V4Yu?s]XNwI]0ѾD\P -dpbdqkK:NQ^%-Қgm"[>`y[> v_=}4"nF4EovM';$C~Vaƫl ?kqfVR\P ׆G*N֑܋n!~ ' ^Qa"nO'&Gl~<^!%xPY7N$˷9OB_eG۟G;r>tDZ[_ÎA=DzUpUA@f/];xjӫaΫ}" nlҴܰq=5+,%:UN&394tXK_ApRnBBU2=F"7eVp5cy2.t"3W3i}'H[&ټSMoyڃ9Sh}O@vQT 'bPT33:) 1rm+X<.+>(>5ZXYbT-!T er'`ME^,\vyy ́K># uE/:c?Xo)w \tp-H4NJ_Jw2wr5ʹBl4^AG++ mxYFe <ۈkuиKOPu=F .d%/H1d}6= Є4lRchH( X|g>'v\SבDv>>?m:W*J~fQ tn }CgXQ2eǑ] 6leJGڷ] Pi 31THu{O${7 nz|̈\|4;]md=QSYP3vW)\W3x@ה#y-_PN5Z鍼1$QJ1*ier,I4zCy];ΚS&'ltGJHkpĚz.|:!aBv] 6 -LЭ&YsC(_ .1hOn{k!mOuevxAa˴%9K SUHN<jwǭ|iͳU':J5Fކ 9PP/DRL4S8CF-@C9|;й`GF m=ۣXj ?Y=_PVsSδ4O)SW[o'E`7~iᯠX|(9Fyﱛ²VLTcnM)32%>p^dEJbC-wbD'Tj2Q`Ý]o{,$CsNaK_Pˬ]T;>ۧ/#}X~ue1W别?0+"V+-HBr^b,l z 2 <[VZD% 颜pRΊ*N?Tm`W`),bcT!|"omak:RUξΈ!n:g")T &;(IC̐r "lҲFH2PѺI :iKyV-@]qT8֝&+j 4Dr#vqRNssM txh_KOp?A2]\5~x&@h۵?!8܇h*uYڋ>r8PUipP/:TX& ;nZD'6 pgI-ravIvU7܉_$a^-Bg:dhqtiUI_z/HVGV-3Z$Zf>kR49VoPB=jq2`|;ieB5 KīXT̖@wh5v:$s-|ˠ=g|._%nZXIx+kNFWʉ4TUv58sX(i|}"[w Śl0-Ph2nPӎԮr_,R$[@σ38  ?wS |0) +*&hR^Y%}cR / h~rncn3Ă ` hxP [Er6j{+IMsp>6!9LIGnPVx0pu,~쮵W$D-01_GvC4K-#SoWfWīwn7ﱡLr~~4>ہ4=C[@,ONrYQVӧUp6Gz>;k1LLc`'OϘPډDyi/C7\, 52g.,!sBK<ӀrTuDiIhL|[x Ǘj@[8G~_\Q1O>܈+]Ȉf2oWHLW i!l[9GYp/r2Bↁ yUzX]uUكm[]-)dˋ1hr_{m_'eԬufh@ UkQDxk=P4gD{|ig* 8qO í84TBb_s5aH#*@#P(M{U{ :~@Poz6ӫ4F`./o0nrP:k)2:Ҷ;~YNh(}%&:ǝ FͶ9Go|}r~R&76N*Tj,f~S,Pb;]4+^䚞ej]HGd<6J>B5,a}@kUu`?u?R7nчY Np|::2$)ʨ2h} JKX LCVTP.wt_/P1孷XK'yEظB\_s+37 長z<r w-CtA^qC=Cž .T& t nLY3֎52H(,Fi1 :n\jhT(e^v +sn-P[B%jKs/{! A6_r]e8K&g匚սPWEI;VM ]СBN\ u?I 9 k7Ot%B[ ȇpg,PRYrgL<0 0WJ9IN|1"-Inx}$'}T~\[ıc$҆:2S}lL0hj9 h9h[fi߸ے Q`,FwY4l :0h<驛ƵlssRBB.~AVpED@} %,FUػ_F[M7dC92Ąv jz%tODFq9vqKp~ם%Qw?S|(K m:Pu?Hx& GW]Qiӣ0x!$@|m58 : qqLv` CL.Iڐ]s6yN5Wʰ7BOvh! ¶b4czl$5Oej>~JsCͮ:8IZljejBwe}N0,9L.0yȟĀҭG楖lGdڒg6Q{/ f1>K+ 9?O 3[~7]#5)q'V4!BFwKc/M+xGjU";H'$P8>_N-&zH+* .e"!z=xA68v<ΒqlCʝN}r1ЛhȦkwPy~t)Y20夤HH>Zq Lge"Sw.*w-v9yW}urc_NڧV}Ipz$cD>&"NܙW,UW4B-8)a`O\]$ ڹN}acLo8nTa_<%~lH4#=RZ1io?k}/ Tֶ:w̧9)dI3޷oOv6XuU>j. g=pJhY<M\ӱA9@o+XƈLV>{ {#n !%Y44_y:w&G%NNY-0?q񓵟p9 JbMoa{钃4QѷmTZ8a2zïƔWM|mvYl{@RiS}b? O5ِ-lij= uR0 Nr:|lav!XY*=Kou70 O?VE y$2a\DC>0vIcx!)%l<0ͧ."t82;d*F D{ܴ=J'͜f<7ͩ)Pq8.9^5 "؆T1KCלZqoD6% TQ>hƒ^m ?W3ǟZ2'8B@JK򫘯M^/ֹ-I baY- Іni00p!v2A~8aeX?RsnBW20F?gv%,q^2kv/T܄"?%Қ}N1'3@ |PKH_S/2Mۖ ռ|nuUS#h}{\a,ՙQWPCSs&evu޲`I.NC+"KuP65!)h; 5Bp#/(-f/)PU㏇@q83 #1wu&87tzm L%cI6%ɠ$i0sfQK̿*DȼdG9Qś AY8 7|O)5fYB3ָ"9b8UÿRMt4EFu@ h`9ޞ14>g_6R@_PD-\antO3~ܩF\ |/+70Qe"ϠEҀW}[)^x4Y9 bs⛹`AUdgk܂ΰ0,+IgNtpd kNbu{5/*o`$2mE ̣A&ǣA) nsTv^WN2SDVu?ԮC8/#Aǂ_ ( =WhAC`wT1*uϐuOKqpxDf*)] ȇw-oTlF  t2x{7F7R<$~Ǹt|4 |c"Q|2:mw$dK!4 Epc HV8QL(Ր8mȢ^φOo%Q|  D_ep[9YVGKc21Iewo[!f-} 3 TP~^HAq ('`:vc t{z'A$NOj^roR\f(s;%f8^Z$iu5x}#靖gQyլ%l퉭\fp3P}:#Qstg: 0 5p5|Y;df5vkz70?ՆU ,?pDJm^hFe(]', !l/G"B+jV\t}diUc'ٲd9؎\Q A Ng~jLξCÙQP4vy ҍ=<`;`_d\o)Ck)̜(L-E2=_}A mo8-=Zբ i@7HY\V_}\EcwlTpk> /3.w>;gE\-fM`0Gtua4'24_g[E=14}19WRZci>eşKa~*}`ټj%m%s?2p b2!' 2a%$9-L=S

4nrekte5[-{dɀCxՂ8Yߨ: `"g2j 19Ͽ`C7r $ %ʲG-Ƃp'+D#=>)'Q&]ʜB YzP,j MMi2BdJet&4r6&l[dbkk..<@u%nt>g7YG+Tz)ZQ Px"+ UfN/P)ngz_N>4q$Dq/j4e l^LG4 3bu:&y=yWYQ Υb0Mya>6jC'T^.)ق:}nʗĿN1܄phVRXSUY l#Ǩ]$6ar#D>,Sg(({* vgbɢpFaH;B %_,2cȜy@,e~f<:l9vr6tYDSc<3h@Å9MoU&g #Sou\D+T`e%["PՅO7FSşgR7r`?\){$9k >ވ6K|O°_}c8oJN*x1C䣟EYWWV|YŮZsLbq%:ŒX"l&t_źDt~Rpqe^e7^. #< %zEAek#BAݦ16Qkφ&S[͓?%wF{Cݎqٯ~M y㕆["=q}#TPw4( niA}J8OPyj-_ZcGz}l@ (9O{MT6ޙyHPQ6=\آfGng3Z !>lQ~ f}gt>"j\Iz/g\<[DLxhe:xmwggm!.:$x=+V EXSÚF}*up{!n&A_tU%e(2| ]y`  c1}Z-"0M+[g//n{9frYUj$ hLn{xWUƁVr++dGme>^l1s#8M[h]mZ8i)>aJ-HțN=D{7 Gr ZK,\ҙ;Cp7-8gX$,?P,] 5ѷA= IWzؿ_CΑynP/QLzYDaWRܼ T)W.Gr ۵C=Gm]4II Z,7M ;,}} )+$R U;}SEydFq6maV5ܖ)p'qEj{v<G4JL 84-NJ?(^\ )7KhϘWݔOx5<^]*TÓKQ !-^!#rm<>GLͅͲ#%,-fz!El\2%-Ba,732(&)YJi8?nEOz9?Ru0t n`MgT[SSмPn";20{a(U{-#K1tn,`'~p67l6ӎX8YJ8pC4%jDn~k,Y IsJe&=bOaeڻ^n?4edB*,aOw6g~IT76 "H)(2H9ָ(>;"E^)TxFo\b5нi#HЊq;QTa|Rix)1j#I?r;[CU?0mx4;&N2Ũ^I׉L"u]--ܞJVN,@`0̵R!iHv}9i%)>2(P_Gv]Sy!6mX6ˡӦ-Zdɸ3-@kN)3))|r􄥿hKZmS&|11!jt nR!t3P55SRBB*:ܽ7Dǝ?3hJ)w^,Tf⤁M J /;"Iprj6d.!cMqE_C<+&Ղe2M&L j}ߠ wI{QJ'~`F|0}2]Wrmz.d1 vxF K$iG*&r ǶQm@4PZԖtpkzrh)G׻kxtPbU2rRܧ ض<'F6xL-B`KjGd&c [/I '4u9,&)sNL Xbr8f0Mn˗4 XgFS5@r(6Gp_µؐMvtB& r[JjL6n AH6/cH}i]@j"NOqMBrpwҩ5%Hp\ ]EB &\' Ssd؛d 1Bp=~i nqp8n=\4UR j';F% KRUC#zՕL2z˹L\l:ʥ_B)_So)S`jU+DF3XOknhwmtU [.Kvq9RZ=jq1#f7ONU" qpb(A]0(E, “dlK7Hh@ ILb;HqR1=~X'b,ll:DnɹiӠr#@ApőZ+hBh~AfS(#h|/t3>S*HzƇDCQRL_Izq%i׸ ?N g:9Ql2h1rҙ1IbI w Lx_GmR8.FHy+Xb Ȗ>#sRQWU[9rCfAQO :]%D0 Ȕ7 a(ZWO:r%|$S0wI @O5+ ,JjoKBah^H`ړ)(8 P׈]]Ty &RQW OZJn扂{qLY *(_c7FN͂5zT;M_Yn2ilW.ПK=BbD# 1^GɾHiܑB0}0 -iNz _12z #a -XMĀ`р -s }Iή) aO 8yvLf>NEz "YSYz,+|rCrr *a.NţyTp]2:Pe8;u?=IW&i]ʑe.''J%+sE8so"( ~4=Zp%gp%b"rK6"2b0MͭE܅ ީHvWn`/'l X1jب>?!MQZxu5 3SrWVoNY)"GӯIg*g (A9V%]$CuޞN Es?qkfz0Cڧ<qj:[w@ls ^|zb$n%0z,bu^90s0XTC#4~UK3I KX]GVn͙XBˌXN/Vh8M Mc)ݳq6FMA Wuԯx6^+R^L UsR8"4I9q:w:>Hy͎Cc`w$;@ y {$˛XaL=#CG͗Qx4(|j-Y9'ץ2rd[p5j3@xGA!]S.o{hXZw+'g@GRrM 06#T~ e*1ZB+ ;C7 ?$5r2> 1Mc95xJQ_Jp,_̫t5M&ӬWk{^2aQ eTTl՚7pjeK6gcp_'7ni/SZbVn!Q黳(h{78lj1Ѐѽ勇Bģ2u 滑cq m*,vO|B&G3!6'1|!S=gcm8#f(3(L)5fXAG>碉Ju@3HO:|-;f8c;^ZTH1I"CbR.n3".mC>yr-AԩMʣ+H@+>Mo0Y݌tPؖ満:w7.B%l6%uo"nzNWtX$&i%p5k8U'!HYst;eA0N啁շqڻ"Rټq]1t_W䊊TI a?j{2(u!E:WO=ee:I 9h) +R>7 s{ j$#4ELe*sFxI?v(ܲtqx#{% > 3u7ouQ{zEofG{Ms{`h2b%P M6ܫCm/[4$ouWB=M}rOpXʿZPڀ1e  f_^('[uWUp<G.ppmޜC9daYG#LVÆ+Gn{M@ WزXbl(JػB;E2bZÝI۔0M]pZrb{ۜ^ /#U "fCd}̹1Wx/g._|ѡq_V yn|CԴjwYv}iK 7ˋӔrG}lPHG܏h2/zp>O6'\%p8UnpHLVP%~f@Z?nEt1)0{$*;6"мH 6g[=⫑Кj^ Ni65#1H}Y(53eA8٣"?#*t}A=1k,žl3cFZ>Mlo sb䞺xAZ4(?q*u*1͒k'2$ toO$wD&9PC%Fg\N{%!zG҄[Gۨu{>A=7t#-yZ=W1J @PRMuИQzqD@Jl>&-LvB^߳F2g7S>mZr[cg?j@ r6Q(ggv1ՋaL-WǽYs䴻C^jXZ\`DТK22(($@Gzl1/i8:aܒЯn柖=ɳx!|%oF?m 0'$  `Yh$4B&ɸ {M f6}b?1eqvC8ܩuio6L2 lPR$:YV-LG6zFbQ`sX {Gb7gė SLb?9hF}_DXp-*NTP^z7fv =ZY=1wzKa*^BcY!, n_ͮ4} OshMCTæ7Jo;->~FϥMFK]95':8jz{Q>^*%yNQu '瞇M ޠ?-6vTw;RtQزג߿ϘJxZhd.=p-rBȲ쌋.J{yj2^1o,Qĵ4}$gyTh @Bj~hoBG;6 ZJ dقo ; m&ϱ0&ہOtfu {oOjGFv\JsNwYxmL*)ejjh!k0T-:>Tl@ 8ߴE9Zb u<⮃g(7| L;dZsx-HѱLukQw/Cԩb" OR'2%N>Ęf9|`$D.ϊf rK{GO#4CФ)b&$sg]H)a}[SPY2I0nDLG~\ag*R&iOϨ/fLJ|%s_FcY h' sn߷U|1EƂ ^9> N!~x\F1$H]Xs^K+;ҾSoBo&<9 ]G>%⅛B2q(&4!P R9|sY WHfO=N)?;CkJS;u'Tϼ}5 \͛5yH1RowIu7-L52j*nG -/V?ڭ*Xp=_fO&{,T/]dMhq O\7'-R)3F?t=!,7JE׉qQxKXppgLR2 *iH0x|帮\ñ;=BQ7 O{'iY gw1l^0y V4{^Y%=d:dFT!xw8~ KקY^ޒ{ VW898^D'̫{}וTK*/|Lp93]RfhN0"BKR"kxE/^>e UG>XJNx&8gNչuN<]xJx[x7OOHK֤ O|ĺf}q JX)KZZ;smM{RcR:1ܺ.ϡ7t;-qߨ3c9R ?j]w >z\GLoF)O8\ %aRV7Eϝ̿b Rwc*~q$Pf;TR"tQܽ@_]{CR㔗 }lWm1gF%(ΫV7^4<-6wP\pHdNjMQVvevxl #?y0ѠDz$@NY"s-@ i>E؍y$dd`%B?A =rV:N`G pPܸk +ZLE\RyLJ(] ^3?}A-*D&㓄y͏.4%kag)nMSt{7/݊5~$Jo-#ɔ0m裫qx>uJٯ̱RL/ʹ- +ɞo_ cf"%:K\ka_k@ cL5sbYXN}J10tYYfVTp4] k/)~] Jxiʌlu&qj2pJCQ25JEY"@z^uꚇ.(FVC +o_1"lez_6y"c-՚v>Ϊ @JKA.=ۈyh;%u.G2^ ${U6#)@%8, X5$ݴ㈸modf;!&<@EE0s*VFV ;ߝ\VTSV`U|=\C**0#1pI [k_hb|WEhԃn74r F) pO#zz-sqf鑹[P_^U%ȅNʺ¹ c mZA^>௛H{g\fśA3?kġj́Ujk{Tg_ rX?.,u a1uSs7WA dP%/>.Si%/\\nqyρB=9 υBQL-V'S#K DY+0g,IxOMz6v>cX7}X,L0w279~Gl*g!I}}̌y=ON#AYR坘-g=9+n}R: _ Ct8ZQk v6J|2r)ݛbz:gWz.NS0Ϲ%(GϦVGǵ>>60p\y]&yv^ƽ\.ԛx5z]cEY"\Q~UCXVxԭoT^ 1kZ1 PRx KuS YyX[/'6:4?%W5~*+յXz͠頬/U;1'pRJ_h5faQZ'Q0/3cZ!vA8Q׈\4g~!\btXf x8,Js*؊@t g-ˇ7iJ.hCLɖ`ues:b.3qzf;ޕȵyvDﮇ.g\? Y)؀dt\^-d>it0)s)ʹ&.s1'ʲ:8j)C42rJNk\mkbD|3gU=6KT]dGӇ,Xp/G, 6o t}x2=S}R6 Z |cbtD4j2IzuxeQ1.|K:Kr7a@c~,j C%>B#"¯&0:(hf4L{g-E10d{3Ӳ 4ZtEmۀ<=}2]G41`0o^Lc n,Έ6CvG9?<`פZk oy0Ӣu}3VIlu&f^Ut7Mv\ p#?8PrcKU+BYG. Ge;P"ѝk? R ^H"؎mp)Rwbvzth֠(U3*hm`Q1s' ɄY9ˊsיJ4h>\~Nŀ3z\+\-hWsH-}'д9}?諤SNæpC~@gCdf|=Nu88<cӤ[*. w }_(yIrU)OePPb0ݏ$~ O n=GbwB31O{ՆbH@KdJ\f`&ɨ!x| c\}^Zn;aZ]pfu_iuEH3K>P'a&j;6G8qI?j^U^;']RQ='ΎLM'~o9*gfaX+'K`2gzLMH/S]4O&v;$2H,I3E4$ȐPex}2 (!N~mIkѷg޶N-š㒸٦v L&2a0nZ%XϾMM2<.Ӛ ZKq 3':+_%T? k1> 嬂2C&%.V"ɋ]p#t{iM"dh{W.8E>rJsчgTxG?^,KU[bM%7KuWHŞdl3 l}X>Ugdm&Zr$Kt|ѐYQ4aKӶ}`k} jR|Zk /rk\CF>U3Mʊݯ1 @'U^tzߙv0E:[" kNK,aRƹ8{&_Ys;!Aюx#47&?<fS`o\ID(;?&m&uJ5V 54i2O7P.[:ͪ*f=G˙ +_ntl54J4`&s-=Q1e{sDо R@@+dۈR&#>~酝 `BܗNyK#gx x:Nlĺ Y;ˬ/L) LQS;Y.2%br9@^8h?W L!p?9_ѳٴbegUfMu.-}Gc+^0bqi|Kȿ9{g4(/; @q8]d#5FY !f9](N Hn|!Y~F}Ss ^1hEoe6w5S #en3PXYݤ~t/31DJ I2r4 =>Pl׎ռ4Oֻ 4HEvWyo< tP>9++ډձ @ `% q=r/7ju6x_Bπp;eFy9W|t MDj$#D@a@]flٳp7ߏt`ېtZ6BE?+Yk^0WE;C Bd ! ǺksDJJhSV[jK6$oAUM )D(ͦ:A>E/Y;ʹՐJYj|6ϰcdUΗ Qk{~aXVw.kή27OJ^$|ULI"ʓ%rޛعAZ>~qwyh,:@:@4a ȆJ gC;  q}epya:(H'Un{e:V 1Lr%2$$lp(`RAr^/ÀÔ$ρ z?|jR4ĨO_]~0Mi-N JlR)+sh5~|O) ^!4ƘW_AT/o!u74$m=FJ"v&Zt~E2SP j^TsmMD~h<"}x#.$D#iI- P&TڙkOgsYp&$~HwUn52Ib0]{!W9XX5q6n+(<hWi+>Y/[2:䀯'e)o2 s`̤̚^Y9߯.BpQ>3 .آ6MjъaLev<*U?y~_4~\Uafck*BFR/n}mCUJXn1ۋ@)|& ^riݕ텄ѧW!"d'~K?Ag (0w"/-6XϙK.{>#\'7k>w,G8y ʁ1 )hQ!Q~ XEkÓJ̥D&);~P*1_kby5`Vι_֕.>UcFi_ԅlV:.ҁ$hKA(QaVNFWYl> kji 'YHO:v@ R|*,#w;rYL {NG)A*o/w b#brq'ӵ142ʄB,Z7w U"~Y$(S\;iAz^+i oPT'AyT!k=Vpp\ 0TUI,;Hdi8[T|5v RYFnpz^J&(oqeMts3P*)h>ծe吙ɗ`ڛA< :BxLG!k+mpr̚m{+<>ĸ|/oB˛FM՛D,`K ӌu aF|YչڵuɡUUZ|n[C\I&OIGvz?7'Ӯl>fl5un/$M5*6QysWA& _ͷO.N4c׌Ҁfo,v?ogd"!3m%Ru1ApֿeQUb:z0(_|JH&՗|7 |ՄC˧ʁtGL(mp/hPJN{8,Zz "S0pQ Zr*-s}:1&^+*cqlۦ/; ^fa3 -v8Rsoj،t4\18 ޓ)Ԝ莽`ՇIw}yV9W@}uhiWlJ 'B(Rњ< = E(LdkM43.X75u.RCzѫHfjs4'd'9aozDS5J55w/s#Ei}qgWJ(zcxr'Nt62wωbR/;JR}ĢLEufDN(zq<roʼnHJmp^0"RUI4$C~Fqhch3Ȥo#oԗ]XtL,Є]x\m H0DVVY qeb*l]n%OO+]M3R0Mk/NTkᖨTML` ar=Fe}IMR%2y'knQ`/gǺ.z`fQ%CPV_Q&oak7f2 opU~^d@p&_ȞF熈9F ٯYB$NW-mXE** (cd6=Q' dxsSXJm%""Ljh%imҝ* LX1,R8Խ;L7R3z53 *ө+Xf^Ml.qoM$S6Ǔf&̢κMKQcNI^l1 F^ݫ%̢lC[t hmZf.{QqG.rV0K;~u?:Xˣpi{;i3m=-e1lC\fCk-.&K5+d)*eޝ:S旓JF1?0;Vբ1H@!SB ï&q 9L?Yu铰bZp -#ggA7hDjO}*- ڬh~IVq+LҐ狫(RwlDmQD. #^`}Đm߻br D6\1~ݡ:1~&[Oy:mkZ{' {G~em-RTkPѽђʜS\H_!ŁX8`Apo2̗!/*{:VͶ,_dy l % G'5# S9i?ӣ)tl~À!Eֹ2S9'զ/d1Hbj\O 8kk%h52MOY2dq7( K5Oo+WaH =_&<܃PJ(oD:т=1_e6VEo;42N;aNf#TCEH$IZT'ԭfٓa4KgDuu១f¼M{hae4:KڋHsvI379q 2(xOو:/Pޥ[Ea\lX"v|y7RZ=6O#X#a-j.'g[0Q%r?ud-ejI`c; o&@$P$M8&.EԤ:z]U P󟜅Eu&iu>0jJ_,]nџO%"j'Xi))CjqBQ1ms퐓þK2 8q>3)xu"(8S`;v y3 Y?@/Sl w@&(MEɗϽXiCQq{/=`rDVrG$a#u&"=rV}+H=zpB(=OB u~FG><sBx>@,Xed7e"~A@ˉ" Ȟ+áMl#اeN!%)Ni205콗mR>asMǎ;,~nA"q*^u.E-p\! E-Ff0u{IJDG=Iv-' mY4@6hb=(Ȇ6[@,szgM yb~1[z[GHsJ[ 8|̮U $Ft.e Eo65S( iT5BR?ԟ~jh);QJ nH lN zj ڿ"BC-Vyv55QzNr-ڎ,zd) zcsp>D1T .ԔKj:Ē"FU*X!L[4#yNdf_4t-wSg{ 3sY}晣R &IUSu|R?]VQ[)~D(ʒ#'(n¯vT8OC2}vzkx)o= JÁ.PÉ9z7& y1{gsP. ? ;j#X As#SXT rDrlNɨgԺpq]*~}N \;.[Ndf7 6wvd3E\9{TԔ?i™kJYZ]Ru_Gدl$%nDPe RxF?  K w"\Vgi_x MxҊ?Rj Jf~F <3 >OIhIREח<˩7.^WL(Fgy  zwp'/a0 yI"nP1'iT߁2*SXks6u l! J-dD8 0'͂AEHycm jyǐ8FJʚeN|W8:x2Ls20"?_a`7EC~B$@fg:/9y uhRxF5](cn~1}уlKiaI:tP;]u..kdx.e/*p!<{t )~*aGR+qYd}i9tf2e!R;FJ\r~I9Zoq{n5np?:*=}ͪm_y~-R HpţOۭζ''asE {,Qڔ1 &FJqnk2S4Oѭx=S3[Wy$x6ۋ88Y x{y#y__6$9(>DO2̼QL"$_PsGYW:&^Ԉw7POo &b[L P*&~ ~{uL^ a ^p#.`Ѓ(pEA~܏hdfW7pȁ@7-{̅A]aRhTIEQEZOZ|8~P^u%`B2RD7b0rjo^SWX!%֤?;cgˌ) eƊboQè`<-MR+EߔYD>iRpIf#g20/qMq SqE3 iyU /yVɗo@̳ql~^Rǻ7h7)v|{ljr5K4ʸbGi`[zUywpo'5 B] ;(2ms.6@.8ծpe/&s¼)7|uE嗿c=\Y,%dըH9 zGJ5B?\B"B쉉, I{8&B/kKіӈ3/\p<\K}v.takq47xJl!>M>WnLߜ|Ԣ@83SK!:(}c[oq$y^&;5@nYU9oV ݨM&2 \ ,NڿB(ԬA 2BRX덃3']%˄B:?6;/v+3T$|z]!l:RC >uPWUsEtB DJ?n% KU)"i'ZI㳍mYzN̄tZѠH. YAzwC>ء1DypGE2b쩻6wSBLMFpҶR8.d.& }th.M%qYyaF贶iIt+,4=ĉ`WbGXu?MALh4U }Btw$3GbҍVpOgH:5Ab!;u#`ܷۖԷ3)ç h l2PUa#יDT1|} 3%,z:nchs}ʻ<60ρ7Rs"bwVߜK$"1q$ziQT\5eSƽvYzcf2}w>7QCh,LPUO;[j @کV:(}.=K5D''d'Ů..l0kbaI+Jz2JlYqvTʃߵOc%$m̛ \REFm2/ְ߄d/@|JOeϊ [],Dpr.׮OJ⬷*iSחϡכ)#XD&/AJmk$ 0Z0 1nЦ(tSg Uc(q\rbkrn4!, HRb's;ai-L^.҂j7x3U (O^vdyDB(?\utcՖ#eJxtX}˹荔;|Kc+A*-CnjX*vV2>va[Ă0U6qA*Cv(e FјYx`Mw+c-D5I8GYC,XohN|}Rm .͑Kij!{V/Ww„7x@d ɖu.@v1zмa*X.(k"t+/JPAS̡XW"=Egp*uH=1~ g*`'2Vf9U@ZJnewobTp%fcaٴoV'XF t Jkvʟ<6W Vz*u/$>y_f OVn"4)L!HzSiՏjSpr$[{֜ ,Jy>h1 JGR'XO#8`g8(||#8BSEDv`Z\rRk8#8:sH(yO9~,z[>zrS!)Oȝjrm"(X݊nj'u(XX@tZ}{ŧNE\)s 9R>9_3o7.qzYe$'P16KoS 1q}N dzWГ(ZM7Wp\t֖87:ЭaMa_^H sM66Q*fB0s7c H&ic$Dw\Yw%](޾"HP0&z404қs,=̣3D"_J/:uC!S7-3'nǢEArEVdkо_UN;G"I(>D/Y@,j53MttTNik$*ֹcw}]T08f;ÅAڛS2 X_ 4g44&Lm4Ǿy 1P^O]١.wIs{xI)tx^"Sڶ֞2$NB 0nE׉ęDloTL[:!5XqoߖK@5Q$iP z>hDVsPۢBG7YZF|xB F)zQ-ا f  yWtßfS-& !~Z]7FjIɑMKĊ$݇\B_k-}rEnβ[0-uSȵr}\eFι0KӈBak<^X4u5ی>:)J8dEZ:@3@nˑ#o{jF9\Z,ZyI8轊UPpL_4zH. 6i|>g+e;*kbKM/?Z98v56t"^@n,GXpIi->eQ)Xv"2(B_-E {]`c|[7T%nKɰ#a߽aæ|)@|ѝGzpRk]CO䦟@@>@/8XM/ÏaKxZ ܛ8fI~^# |ENyL[%J)_+W Qy$M@JJ-ir*F!eg;C#ސs(2?_qHpOc]y՟uPH>nQT1_^Rj#tDQ0 xP6"7u/!{oƿVUr[jJ>/%Ē-J˳ϓ:#ɱ$4u- 9][kx1P>pd7,3I`t=qM3`kuw_5GSbmVKz-.y[j_q8/3AğZY 49_nGiW!DT1-&ېޠNT)y@Sǚu4W =L+TvдCwxH-8MOgV%#""1r;J-z,0gr|zvS^O='{jnVIK`Kzh"c]k|F3w5:yW1i#7ƙ+G.OWwMO62#SDТ*AGmL̦w\hӐLҳ"4{8ߕs=XB Dݻ!UN oW )}?. +!EM130&N<0ی}/Te(_hK*p .A[kf_iBQ*(`T%QBM{,iJmav?[ߦIBOGf:4^&}?Rc;) rқM\n;H(-j3qqKa9݉xVLS`Bp;E;J0F*#ㄖ21e2e`W _>I"s3oZ&GAL9ﰚTn5a/dZ~a0j)V!bT[J^D~B#r™LWZOXQ?9oc~PtE_>ZGT +uo,Zւ6 Y/q#?t-9,8S0'aK`k9tʾqh9o21rqF`q3Rf"If%`o~1/ prʆ1wq+R!BeHۢ}V(9RRy{v'ˌQPؤ[; ;Zyr>NGh*ٓtH`&"g;9YboܻiH S͍$X-6h/QJ[5"j@gL>?= oȃ`yE;NjX`gP|\`a7lj,):p?yEwo9Gǎr.LG.Eh&[CGT#) Bep"'N^O]I-@ms5t*豕1פL.0Mmc@NF+POlɑ̧tEXqQj464'h kLv\l}I>(0ҙڅBLQ#g:PbR>_[x6${ntہޠo[L#E?3gFt¹g`Q Yݡ'b /_l4mO㕭-]ΛԝD/(5 ?#ֱ1"3p2G`N|>)N4*QM},Q.Sq}'hJpbԄUo4ތa^M{ꊅƎE{D70vID<=H-S11ǹ r||V@/Xz0!QD+ę6 }[Xqcjy#1LBLpGc ܟ@D"FKVeb5e}X~"^QMgw ݑ=3%zX8[8$S^n(ߐa7K0(YRFі\P{mH+#$YmY"'d* { }Sc\] iQEP{Ǘz vAR4Vo{h| TGU;x)dDmP(t@u6 XO(=pJ N]Y-[Iߺ^?H,G@r{r!HW׵{KLs#c"dd'{6}YwYu"n{024;>TjS ^T'uUl.-LɈT:Z !ep2eK8)3˕溯+E uA1L@ Ⱦ?a7Yqh+|dq3DWIo4X h+Jۉ`flϔ'_d_x:ʔRLBQ=:_ֵXmcS6 ]*s/s_q4OU:GnJ̒; z9{ȁ#ᢖZlj;$m>¬2tdx52 N#1*H7ˏk8#~82rY*Zdy o]cNI),{ e?u2PFYi0`Ch}ia+cs2vN<ev*)7uhHqKA#ը_R)LT.' FGx;u'{:S31k;cϑs,&%y}FTw5s(:ΆSj.q2ģ"ȃ0$|_4hiz;'Uh~M 2L\!$F_AJ{@NKi.9D{=/SR< W(Pq>2imLz:7qUq88d ְ8YOûA].lu=4FOY1u;*g8:__h sÚhJ\h e:l^'#\Hkhg e73lO[ Z >=s~o.5Q NF56P9^% gنZnWA(:gn^]KQq^ؼxlvXޙiвJPiJX&m]xml`^SIhƙB3?dlt8 Q,]hQRL8ӋVH!+<т**[:Zk?VprWZR 'V  p,';~kfcǙb1Øs0 =<v,L D8πK2 ,Cq!|_ jiu5$ `RVިn\"C[7m1WƲs߼2>Py \Z30"W6ecv/uf5}}=Sy$K8I;xÁvIaE9Xu2>]ЃklLo ZeNҿt' +]6u_x S9L[ $Uq^'#)o-7SID bçɋ/8 SJ##4PUEkf/ ` #e[Я~H!OS}8Cxd+Yp=/GKJɓ@@k_eVUl5hanͳE*|{A?B&s!B7;>5TmO7ΰ8ZuiT߶5Ga%YpP6zHe΄%t{J;_G ;S-ppvnɽαMQ;UTbDۓ)*lD6!&t6VWj>%u\4slf|WG,Ċv).)O_Z.ἱdX'OsuƟ("TQ )GX㺮x@v=EG3ҿzZ_v) mnq"#%%:d3?mV7@zZADujMhD4B+/0SMTm4Ɉ:j^\pzdR^eAa4 Œ*AţI0#Rw0Y D9eQ㘠-{/v z=|Pau]d"mpNWF = k Tii/׿# 6>2hauGIe_Q`h 8@k'D}:_PcVhRf7f-oE lI#{@ ~X*k`%8uK0»CwTF?FQEϬֈbxv9k5R0R@qEFYY9\gz bٷ@QRm~( T`BdӹLI}3PUWR" UTF:e98YkM&r Wz̯f4տ_Poe=^jvt3E ')=N<`=nS 9j)'J.Kw cpf Q$rr|fZcgȎII~PK(pb˔N x6wq4)IWXx#~GYAngyE؜]K1M/<^obem7%ZX z#V>u)ɸгi{cF3n6e0y 3Q,?;qbT{4'Ⱦ{ }lJ ~8P΅->j\Mnߖ;g7Ǎyc|stC珐MN)o<ۼat}A(;iv7<,(ln!oy 3u͒yD"n)TaJ?8c?؝.78 G=G-u5Y *}CJP?U/Gq] f+Y : |&gVqȺ dHeܒDZTU,AEN+.9jZ"Z~ۉjW)u{ET#85 "qND&f=Ҧ a;ɨLd.:5ȏ3IXKG)}!ru [?%rwX\:Zw>x_Lzqa4$&!qQӐ)YR>JN.x?茂[B"J\Ф%+Q^Oy?\Z93"XG|u`)eg[Z$_3SmnNS:H`X-B{7,ݽE_f\cw\q9S2Ș_|kPZ?=:/#=Um=rhYfm\}|-~*""$"_\NK̹c׳p;C;_P؉I0Ƕ8Qy-aU.=e ,]1EQ9&U$+PTiYh'^z`8PK6!'W{dDxO.6M^ڽ':ޝCiw%xt$S8*_9+zY|9fVTg;4+t0.w$ 'C 9-ӿP5] KeM>.f2 > .> 0J5pЙIBVʮ%mo8BshU u辶Vm܃McRUrGj^hWzz!$b"\@hj_fo;$Y~vNegT_m=zjR!0K1m`.ԪEV?6GqG1w 1u`tczz/H~la8y9]%ѽdnIĄk@CҟŠh'β4ϢZ;eI%_U$}*0f@Oⲿ\WZ_b u)I==k9G\1EBHR UӼ![kuؔʁ\rJB/q:b/=SĥIB ,3% P/(7j>m l~cZ, "% =`R}ݬSPG6qؕom#-A5`װ6Q󞗿 #/nW ИMV+[(Ne"Rc Q +޿gK>g^w1t )ONzt -6ڛeWѥZ5)cDsH$6L+H^AP-˪tނ4&+&L} v@:?9NR|v<]jTm' >Rԇ[%h{mG/ѽ >ʺ&xu Pgp^{ 46S v~F"Kv4iOeCpϚ?$w:ܮyݯ ;-6KOU[`nS:k5j$U0mNj/O9$7j4(f _o.J*,V;ƹ;C^m=D_ޛ46g~7Ʀe.5 3?rH/.\?LC#ȭ9kؽ*Tٹz5T/lPL?""B_W3{dW~ESF;vix1]3cI>[ORQ^3vqܱi\K?J蓼#ʬ^ZR_F}sp,&wF L)1#hYl+;}y!9>% #? 깶vkwC#G"NCp'j.`=WgYj7kGXc T"j76r6Bk jʞo:_ `: ޑR%lj!z LѸc_5gE}Ǩ-֟)Dj]"Dk"94 ?2rs]E~2I 0Xm*zR6[<:Va;gZ"x3Dgz%ϲ=d:E^_&& _^|j:ֳЌI~3VD(?j%17/Ry |+f /jYq}My5.؊Y/ mCZ} |M_g@dik->ÓY0VqV44Nʕ7X #Մ-\Mk틢/EDb0TE =XəXϟV^'zV6fѲ%.wÄ$J fZ.Ц-_1NЮ5Lc=ƾ(JMA5[t7gU42e 4^pa2oR.VTG *Gіz0 R$Q`soIDz}F? SGR^i)Ӄ0\7 N (|hfr,^K,+4‚_rX_JlyIVgeEuL0!è{Q &Ch84}I/gJpI'(,]qZd=B|tVv&|ܟ)@Eί| t16FuN qW"V5!n}E-Am`ӵھ.N&@%%HZ]x_\eoMrM@U/C';fđ)B'_8 "K2a1|q8SJWV_Vyʑp!'5+DO^VʄbiK5^řICUw2}>%VkqXŷf7.;n!Jds>@pXk_x"N)UtDxBS\|WIǯ#A !xk6 g`Y +]O}FTZimFo3g*"5&o֭'Ȣd^M p o(Fv&V:ɺ^C_Mr41\s1zF/Sn$dˠCd!T8X9];$cM@y[ ,-?@GGG=H]R嬃 R5aF缦QؑJI K&l\{&thlJFr6^߬PMS0x\R0,WLDڂ)Yvd^oWaJ9x ){}=\BIk@/"$C`/]F!)*w9da2"#Aa^1%:Py.9#Lr/N"*L^GG1vblDXv _ {Z%>J{05#*}YŋBQ']3mV֖% npl$j'…sV~rtpGw?*c"nͱ30~e&^9?TLIT*hә: {nyxbG]Gmq}f ޴c98v )^FCI8UBt%W4_G .򒃖ƅړ'O|̦"ѕ2ɖ9E X$Bk$qx(+R]Eq BJC[=:<ՙ6|,>ڇHe׫^ɍoD<_X$tcVV5_B~.`P#$@Q;Ƶ•}lo7HkQvm3^R5=5"36 H=&c~l>=1_,:XTΤ_ >fζT`]UϽ.⬍&Ⱥ>7G +RMgeF{rGWXnõa#r-}W/qnsuGEZo}O; nLL6> 7yx2o2]p[J>㻃~<&y7|zK"2O_l}'nȀ)ݰf ʯ@d;ա}͗:5XBwUѥ7L*%ʈn}bsFYD Oy?oX?6]|'e>4Ioa k`^{ )2\mCRPOd{!E-f>sp;#T nsR @z;[Lr;>=P36mtP .&(0t#`e_KHU>FX`Vi4x5K:[ ~\}TU wWp#.TQƸ3K֔g\Cv9sJ csѓ$:Lǯ,q]ElNcjJ~ %[wbx>X'#[Ϝs#` 6Ī>2NQ@ )Flt$ӂ68 }K9C9F{L eg2Gp÷,ptQdXM?C߳Yòglhy!6#c ,Р ) yg5o*:e[I6Trr-KQ㕿Z `b$-6WL e #.:GM̱4Q%CN5@aJdq[RH*I285&3鴄S(D6$zQ|vO" U>QKQ޹jTW{ բb9*2L俘`\kp-6ׅ۠P)˲ _ZA/*7Ye 6[p M1s!9^/uJ:}r0skJ Ԩu|cXLPYa(*bnGJiU}/̢ wC^ƞɇi][+D}Z`x G8 kx(\aDWd,6JL/cN@t#R#3_B @-cYR6L7)OF&k]$!?a@MdCܷ2儳AAw2ʔ0k/]`ag&LՐpEM}!ӽCY*Y{Ma6 ^kGD%ܼ,u=I9k7_1C]tpags I̲| `Xe{IBr[Tk~t Y<뱬uZ];DG|l]Z?NS?v'" eA<\!D<@KS>,|ZQT5}(N>Oڦ>gV Ė ״mCjGC' v/_ q{NWM kZQ1EmĜh;17?m-+.^C̸~\0VtqF>w!FrIv,E1㡹Sy/R6/ &ea7i#gر m-݇,l슇ӥϨ}VDcgGpoNbRSUA/H3\Qe6,%Z]IT%܇51g+.oG()yR9⪆^ְPmPJ C1x7mhuGEgk@3z֌&E1ģYլ 3u/JXI=F֜(R1ws9 ͕C_W}3&Aw L <([ st`CòauZλݬgg?d)nBоsuL, z-weB$:ޘSWt\e/h#ˡg\Dg&9/~{Zo\ED/˃H6Dl\c7ncJTC;c&kHzͺ*4+H{Q+ۡғPr;/^7 -;ʻxΔW1 + iܵ:B( CN3R6&ڭ蝘k͊ N-H<@|N6?[>QQ;JUc+Cly^: MIC2'W Q!jcuWN>]m;8|DkO x0֡_P:ܖݾ aFiX9W=T&lu;a|צsqpYR@1 #J m{J6)8Rh3ã/)0ɀTSۆ2 D/gTb`>lX ;Pg.(EF,{"""?? _Hj$;=X}n ƲPo%lxU-XمI<:=j%mv\ska=]g`:m)D&3qYahYXxZ/]K|2wg9umM "3e7-ۼ/?F:ŀ.]hWUNf [4%~+i 8lc"IrF<]hty\S iކG"k]Ǜ2"m1 HA43(2(g/OOa ,_+N(hKIq|SFGs!C$'KN]lRC΂yOjZR+&iZ?l<<~ ѠWLj%レHp"cW[˸i㶒˯7 WMl;7Q |7osڼQ QˆpE9 yZ:=>g{ i+l&~yjc%4Jv[m {do0m+eRk iO[woԲ(RՃw5O Oa=*?B}Z^V <ڥlIi,d3iۍ5ɍn)W˖ AC^؁$^ w3Aw9SA"PߕvRߩ8U;[+ Y:= o(gk.W@2m;A?ErJx˝xC^۱w V1~6*2#^#,[O;\V֕#;D3]powfqW4bq_1{ \(zo\r#kp^Tݛ*QN9*quT.W(u,ǼUZ|zgg'H^|zNyh7*tt7AgfO)_AEx459&1}sd OtC^ok)=TOY߄Ff|J똸ǵ? uD7;>7pv㏻Ι:t 嘆F /PO\iN}ƞL(c^ ˉ$`=UJwy-/[[l݅ )!y%YZ.ͺ{_2A)C2IdPLUC[%^}h.qni=!t.{mohƂ'\ )a'Ue6%fn:`BzN굿Vo*=X GRCn.㼱@[G- LJ{V$ȿGp9:R  }ouաSJ+g@8-S7t"F]"yj'#ඁe̟5Ȧ߁H \Tk^6_V b`$%jqݶ]LGyw%:FXdXLS1'~(6{. |5Uewh^_O&B ZtoI cv;7@O*vr.D#ߴʦLCDsI|q9Ƃ*ᮚZ\ `bbyA41Bs[Gf`KOK(뜡*oPST/1ɠr6% ah'o q\FVQjhY;.lB_=ԤC5P!oUL'睓2{Gx"]|atrZ;=xUR,?E=H|1VIwkn 7rς/o9uLix]8/[ qh(,Cr$'KVI̿-8識R00h> ᫗TUW`u.uKzF5\ ̍%tWt8Q8~wRԙ%@; :*6cNLc.QF1)7 >0s]B_doc,GD#K|N-kͱ2h}}%P-^#Ħ7B=Q_a0my̾b<*A+wO I?Z  W݂_sbkh_eT@U*F9EǛ;4)˱\iՍ_H0_|tYv -%$jE )WmA]7Ke9,-A eӼ0ڼ hV܀MKcWYO50̸-m ~*/JRpxTGT=XS(CK `c J`-YȏmZ93tgEЅq2TeϴyHNMȌsiI\s:Hvz ?kx6 3ǂBƩV 2LFhOwCx\_)OA0eԎΟ¯&PCLL7n$TK?!Y-Oصؽbg+faP;yZ/wѶF|~JNd0,6s+hBQEN\zOdT= c_HPb}^BF5oOi|6y.(:I.E+%NdAWPI$N)vCI1+^VRӦV-t'*4>aڂSl5%e'"/h߃˓Pw.rZ(zy }%B/$k YdaD;bӶ^J]pZh7.A\juFh9p oBx9mmg]:FDZw4L|qQj5M_D v o%]a]E3とpqF/ 5W5ǺWH{Rl&QԸRRd5"%RQ)k$l?ʞbjP"yYn#E8{N}EP]DX#2PƧGtTcw噌QKCz~g9F~gU'[*! k ELf/lO`)<).=I9q}o+ae1ubNBœM?Z^|:q!C{Af0Tg Iu){D s3,'@IQӲ5ɂXBXEL7:͗ȡ^-)MIauc'rX DKuDZZ˨s5bOfюG? oWW=,:!ǖiؕgnSbsF#|250\dǪmKYh\Xӑko#hCö́Ƚ\VL}3%uב}r`1'wG7`} s'A.5HUl}{a@RCcᅐ2CW~|J+[&çABMfYiO/k9B3BC ,, Tf:ZڭZM"d`;[`V]Y˧@Ei0ʞKϫ|K^33n&0ل-_j<޺+̦1 .Cj|yc2kKdJ7˟,Pw\06Zg߂Mus KcKVtAѰ@~*FRhd9{񱔐mbb7tq0Mhh7 Uyxjq7[xq; d =C\ۂJ5C3|o:1{kwi$Y#|w>t*W)\cɵ%QlT[V^niu)mY(<ĐҖd.'qYCumFRW,qLo:s٣d,ba\}npuHW'A ².\b|yP$Cm";N L+Qn_!( Zo@d2u]o'ܮv%^!&K *rAí\Ĩ}5q R3EeNS:?z}JfC|&֋4|0mth;ORBc\cmHifVdƭO.!]]sŜ'_ENM9u*r0s*3Vǧؼa;MO%4风Q)W&^Gؕ#^6^*CI~0A JDM_ z"7NaY Hv^"s^&zp/;4uhf pptjIf{%NlNIf:a᷍g. T2PEt]ߖu+cYbxCHKx;lRt u^ΊY{Z{~1h][O'XMGw5Ym ?sعܢ ]U_U"]{du7nG|_%V~br%rmo\,}`܃vj2{)ӟƋD0(%DqP\ɪsAA ?th(|h9iNm%{98|U O;K?9]6ИK!V1V(Zm.I ݿ ӆӶ1)](j%z@S0VaߪAeh9**dg2f^D - 1a#k)=*/[O%|9f}+~aemiQM"ֵX6)TkŃe5=+hw;)ciT|02r>)H=v"â)P,ӘC#bn fji7{V[3P ^@.=rY1:RL)c\ ϖ&7O/熊VD5B6NB < )V 3DbKX __T_buL:8A(AK,݊;~*c5Ж1[͇Z\&L%Dzh cyk<ᰞCOKCWݤ9Mj{Yu.i[O~~&ߟ=X(pr:G%jc \]\/ON)񷰜ĭ^5y=(dj\]|{~p9VI``dYahx5 : u(Yۼǔ/]ZFyOEKlΫ/<,[Y $1Jw3DzNa[7x%fi0UK> *1bj&,ojF7]2 it?CV?[K }o2QѺ j:rGJ@>{Q!u:g.Wa`#S?jMRF,_Q.cex|4ݠ9s#Aig[x̤c*PϰavįB:XT(-&LW!fratIe@,(9Ջ v x%^, qi >4&F/WH ]<:,=x0 ZiD=FJ38ɉ@6'!Kn~aAJ{(_p̼PʧkhX*I 57ֽ(s&zNAڟVl(1F#`Vj%mtQXBG jyƾ񈧭ۆ2hUœ&%tIfәp @kfiz-\Յ 'YʙVNԮ 6kxSl J#i56)6Qm5´J07[d`¶(_R)~tOaCzQ^H`tCbnJ:;eߜOS a9H.=ML(VV {c80h2#Os@3z9Y4r-Dgu| -b/}I mQ"/ԅ,1ԥlYĢ@:b[[Qw)pO;:v3 $4E}8uE#&!q22Ԝ{9!fO%?X| WTZ^O^@4^lD3]h^xfPqV7atpr`TMM旇Y5\i~_8G׮u5d$PD RE{ )1-wI 3zO2}m Wa0yb5 RD xh\! d -,\R-6I#]/j#7'r46b D,k7 zCDn܇Ptg;2 (wI=櫳a:l($9҉2V8u--ʻT =uMWc?:{(3Q'-*fӷ9[|F} dU9R.- Xrr.E4UQdnns9U1wnyIS I pok1 s.#d A"]CV)o5<Й"`JZq*[}{yuh|o1*HAZX߯+VFc!3LJAtri!hsA{/JJv? ғ.&:;Wi镧S]ږRl٢n]<:uӊ (C.ZUTt5 2gP\^4a0/${*]د}+'%} 4AxD4en ]:!]_V:V[b]O=M0GC̠/^UF{Kq<9DTT`6O$7A'#d+3z=|/h,6^_9r#3vQ3#t~ŵ8Š8˜o&rX:Aƻ efí^;zÝurӞb)L0eLO 7Zm(t.*byHi$5Pzڬs>c**̫J _~kI B$q sd3I,9bx]il@3K9Џ+I] Ox.,=/te*1YPA~?&,n}uhy_h{4jcJy?eEߪ)7.*K[ˑ[O:]e {Hxjȵ9#~ `Us/;[;;B$B;y zcb§'E<`U+LVSмԽE{1G^ul'Cj}ShU./5We&e[9oo5C4K~zrnLY{lqȻ|<%؟I_d\6 |]%桢I;HxX;ftښp[ۃ?IXUΈΑ|qHE_[X/ WF:=$ 3Q@;M PH'zqM*O.*< Sۘhu`]`14TƷFŠJR6Ix:گ6\aqV:"~'{Ω&(xB \QI[2LB%@I~pP* z5!|)ɜtg'&;!H7K2/1h *118j[%H1q&?(7e 5$BXYYbKP7ϻ|<ˀy7M;-ё5WP3Ŧ۞RRЅg*}}(Ϲ֡} GwAѠ(0CqGx'&EL>ddfC4]`#>p.`ġ:wZdtS PycۑlgҸmÙ/RlȾ8@xɱЪWiJo^EHٷ^},U:eKŃ8w9qwal,\F3k)F=c i }1~ _5F}L%-<(zՍu{0 X M+qlE\ gC:IȤP</1 "Ā,[s ();~ ʳY^)8mE@ȹ!UTY\ @9 P'SmIye&ܖǣƄ WƆ.M| MpnťG+Sr*C^!uUF{K.s,'>?zOf0.h](dM>•}u%IJ@&2iR>q1dkV0=ul,v**>(|`=XM' (HԂaV\agI^F>zB禌;婣,]Rh \^[6͐pѶUN2 JLn 7ΓRh '!{4biFuJ~.>,].rP{.CE5|,xdy(>9A=;rλSj}8KUѤW񿄸7ebo| 69\Я㟗-ۺ,,&LwqJ [Yψgp#BVj=I6ۍb`niTf 8 'dt&#|`M۬ g.2)v"^![Iɱ5;[ek_ ^C*38Eb~#RP g ǜ;٢66Zb3;-Jy։Bn_OWǵ-iy e `vrH3+*J#gQL>,SU<|cl {bӮ*daM/锩 5Y-_ܼLg$<Ė&q\5g?2P4%kA>Ow'1<1 5eFb\<{&7Rܯ<{L $[|ؚ]_9{'Jl&DLYC[GfZBe$z:8(k0+tZ}WÜny$lli6EW'Q*`5@/b%GL(m5ѠǍ- *D]s3Az vhK[NrsיDyF5Ҷa Vk. /=x\19\/Eg.vzM['Q3G'jln3tH |3k\鼇޷,kmӞ!\sq'.mF5Q/9X)ۋ[!VMw\w1W9*,tU٧̋r V4E)+DNwā2m;Wm@"e{;꽢X8^stE/fuTvǡՒ wҹ>xQn_43Æ6t2n|G*JgJmKnU˻L> G@'FPK9`I(GmFj30:플uu%AYf; KǙL0R@ƦT゗V~b1;5-_|̣`G㺛N j{M/0p$|gKX酢2@#6FW{v-߾ x/qW'W pp+&;]IJCK,F#QbXF<:ƫr7sVa: 97ZpC !2llH_5I&&,n{QK`ʑyƖf%?GN6Rr49<]0 56q*MMћʗ lY&MXD/~蓟=b0ݽs펚4x ]o1 o*p-rke^i>p^1oJUٍ>,xK5EoD OORuf{w]0 nEH~aߨ\hM5 0j~i{v vَ1fG,7}+&EL}Dq NY>'Q 2OpL9\"}~S6KTjmYYV7*jFg8L~jۖ*t{ >ójĖ|oIw?~@ &iHM+~Xk]HK^ϏHc9UoZXj> '?i:&C];~b^uB^/Áȫ=Bh++ ݧ Re) !np(<:ysm{(yy$s#%خ闠Iw5݊{/ c^SΌ[꿂ħ-Ytѻ -&ӚX~O-~KYMLv&Z+Ii=QWDlqPT dP^o&2&T+-+>[M6: (N*&˹@-,~¨<Y-"n_-+S3uIQ!eTG#]LǐxXTKQņ<ݭʶn_ܥY~wȰ-} ؘǾJ?s4m7y\]V]U1 %M<1)c#dSE1LvCES%3]rԅmdĠ/D ,ٳ7oS?\As"R%bg oc,S&tn]MCz-bj ,%Rxq y[^ԹgB%;S(ޤXNRdAއf&7yҊ֛VjlmRe٪>?Nb[Mg?><]X2ƂU|O*(nC觇 \xVui.Mus6t5v>Ӵa[*MZ7%;oCo7|>Ӄ1yHBy\jO3 ur|X\ԿA5x_'`H{=-&Ga YY2 eaʸN,fDC;~~2x=4uPiF4͹k_{Hdʧl4̕[B(jea?%X=b%̇i9ڭ(UlI/Ȑ-iy)Ajd.:F s i9 '`{A0D+PI'䫄>v$~P|}כaNs#&`Ϯk6ۈdKx:*+9Qc=_" J[Y"yU "T7)r$;$!,5L.[b烇I=Qy'3 FpXG.V9Q%{ < t8 $UU}$CkrNn/ݝ]q}sPw-,t\.s< X:Po Mp[by+bQ6xq Ah*Cs\kjx}"9dwD+G1D%vpR^olKZ "C0OeŁ;p;t# l,ܜŒJ|?C:_-b~R~ryGtS, +k8s>uzrrXLf:탆0uL'[| \Np'fcd0G=Q[yZwO\ Nzn*; Pn "1v52a> ."FsAUȄyպ_ <+i50!itKo6=t<}]֤a+VMs=eNfeh jąga/jƳ"ѣ0=Lp22Y"gmNoh.= qӢ騃T^0޺[8L߁<|UU9 ;P*BX-@(2g/BIYȁsDX!ˉ3ZRwx)r&4,FN&&t1 GƢ $랈]4.`ޤb4'taRKt}kQZ3a0H'@vgIwS: ϔXA#p YJ+1 V=4PF8I\hǙ/n j!y>$_ePnBkY9@.m;{n[Y%H3).:7#GΡ< Xy>ޚusעK.xQۢ OؕG[JtjmUlnim5v6ApkJpU"s5O "q,S  \$eq|꿼}QohGeHtDh1M~b@aݬ`vV*!e xi)C /vN.3pUC0eԠ# "c:M[ Ew$.h"l"RU㘥Kkx)xu+ki|-j lmwU#g|m $[v0Bul7It웗Op0  ל*#FPhv2|U'T7MiKtO8'*Oeψt{F B5/S}-V(,A[}2 x< I(Q|s{Pk}U?@MWJ?N f[gp (Q'#NƸkr92T>""恼zy2L!Rn˚y;-s.Z ڛ"fiLJ5 kC8$vH*k'=/HJ罝Vltlڧ[/N$m8mS"Nx)#q0ڼ:uiu\"Kkh 0]{䌴^{kiҤsFE0BmL=y:/c/'|!{FDFJX琲UWSݻbcI6+T8C(_$kʣ3zl%6 O:nQ\f^fgGy kMry: >@RUC/;/fL*}=:BqpKa=_MMj[HpR] i)yúJ+s7{㤳TCEoK3HM\f!-`(lV.2BJ< ktN6rnQ#{9>wc=8^|KWPVq(=zdU~پaRˆ,46 b*@ WXt ҭϚU%>oc aUʊV "pK$;_lK$*YZt/K#gerVnfuĚa y<=,[ݰ' w7֨o 9ԗ&h/W#-pB#*0L-Wćd ֪=3h\Ek/M &]i%jH,j8HLuXPr$Q ㇃: auFث /z&f.SQğȸ)2ajM]8P]6O-K›|؆8IhbDaKrf[z4m16<`)jTo-+N*wmt I.cJ!.[DC+؄9B ޳4>w[y G`L$ z\ %ij4b&e^<2(W#ey>%8GycncJd79MibхAΊ@@aM]HMɦ 1g=C)7m6(mc~#2K+^yIf0'X{ Xu ȟoT eMͥNI>F%Ix nJ nJ]WtIz^6wټFe,( >IS抟AHȾ09i|:?q^ )ZSYI7Li ,Pa"LJ{'[_<%̇0qbmy]ߪ9GsHCyvj@$YNNoӾKvBeMTs&x* `MCW?Sa*hb@aCWBlXtZmd3pS$<mR@`{[鍕#rf鈘tSfA'6=S:_|Ck#C Κ;Dn{QVĚAKBݧ]ǩ ^P_w/LjmocË6MlAVHc^;F#QFvmcޙ |{ԑ('nz`mxz?l9 c=05!/vE"JdZQP+gtz/(ZJ8]75Q.˛Δy1vEF8[~Z(!8s& ^$T c>+c Е/L6D"GQuپmdT})<=M;x1U>XKym8N`<@`Ajrj #Ji!ŀT7jkU急#*#B3 WR#`åfVZ{u^m`} t1?Fg:2{yG3uzy@4AĘT~JlT(YU߬sZp?2 ,}b%4KO-hE1㩔^%ڶ/ /n. ?~4 L'ϭKZ[Rh*L5qIO:,n{Gv}gA&/A9a%\NEhqO'IֹW\6kW&yZWlJJJXGr 'ϞVTnO?C*ҳPPX594Jw^Uuѽ&5&'  gq7`T-S#b)N,؊)pG8'"m܈մ5nyqcBz&HԐ! <Xh&t+j)j> :7 ǢJJ4M@6F9ҞU**iuD(ⓜqkfLѣo7/y!>~/[2 ttJߋn 7{#7KrfmS5sSwL ٍD Dتwhq( IwQ[`і]2Xhܤ.B~ׂuQnDhW4Xict2PIuwTRs_:Ypiu觞ɚ{,.Q*ΕKI{JzE%b ]&3w8`LeYC!9 jI>~6mz'lj'IKTYi8fzpv]ВIbvփW v~<Ѯ}qZ,]^Y Yfj3rSb>n痝Pt_xS5@!8{t_0¤ <?Yı6*H&,l[|/(.xq*QLwteߐ qv EB1Jf7~If4EV>qE1s2HbZm`¤ iBo?^u+TZSʟ!@3uBd5ʴ~ӒW%VhQRNյHX%DP.ܢW9r`3 3Tw !=̀zNs ƥsQOH F$luEzy-{f<[/Q R-`2"* m)Z¹"e?ؼfBv4 J`S3FYwIӧ 2J{p?Л~ ؔmPKbxTeNܸb@Q-&X^g!N C<<2>CdY<<ӯ߱6Cɮإ9<όwgyK*A&Ix=qӅو/uLا!<)E2P㚁h΄:z*tw}Z5q;T 4iUFW{KE8u|Ul%߷dߚ lU!1\qro富oK˟:@ݢ:3wP!g{ j8+$Unё>7^8Z:t=q(VW,66(I ]Ť҂w3Q|e!_ՠjT?D8IK'qʓ}nl\?f\eNA=sX ˝ϝCU"XU̕aܽz؂1-1EcVD_</IC#B}Lbn3qण'TO_mX.5&xb${s}bQ1ɜ@rfE#5Z|?# |l"`Dn[g+ލ 4srũP>8,m|rjqJLnO:J۩QP1g|qJ `"֑174ڄ"#v~$OAґC xcJ[ QoV3JJiLx8lQ.tp"?&7{ Y3n M+5볼6͙UŒArۯQ Uc;-'pnS5H<Uq8ADsxn>g!G'7RQ\/ "c7cvx 6Bu9`02d'V*H;ET mHIct=p!8x OCT9?Vc?U.z뱮cQdxrlO8(2[KY KN' Ev_UuH!.xZ%ݙe3g@L]C^٢UH%+x!HVKck{噈!9< Aa7\bH\s1M8"aUH:SgMɐϝ% FﮝL;'ER2(i՘zrLs l2\]i;ӬLpƼG-4ǰE(jᓊZu xk,ɲcUQ`T XNk@?l܋•luiNJЏd'He/|ĶȐPUɢȡp Wމ | h.>( 82Ɉ1.ChCU\^nb=a~mmzى&~aet3kܞ/3窥\,'f>}b?R@"Fz(n(E7+!H4 l7 UѪ{Kw4|1<;)~֫eBE("*Ӭ#A)Ą$ko@lK)h 49٥N\k=*[D09f!l'w/@Cq A}-,%6c9tUF}̏ KF~2]7 5QSYϐ`[>7 f\ {LƏ:bA||: x/ƙ3'Rw 6~E?,/F[ r ׌Z_ŰW:~BG7 [zsPr"̠ݍHNS -R\F%fTjm5B^9qq';7zɇXLW'71GD4XeVeG <}[@%59! it*>6@ p0k lT$Mв~D頠< NDƯh# `%j_{Č 5/3}'+Y1 Q gЮ7ּ.TI1X[e K0C}#s"0ofd#j%=X~lɼcoW>c1%vR zax&dIXU w n F24,}N=29i ɿNw Sdž8@;i⛁?TAk=Җ>K}]#8:yOK?aF]idWWXٽ!AaBdT].u^H[lpB>R ?pPSjN[<PxDj5FOwtbsrz9o9|v#&JAihem"oM5zJrsژ>A{F E94 k[fHo:3¯ WV(ȯQ_gsgIEs'Jf9㾃2فLP3U^]R1+SxA?&Y}$ TW"wkH'Z=PAk'K"߯P/{$3G yT<(?j-@짽M)_f@no* E&婉ڗI<9 gJZ|c@Bի$VRP1IW!ȯH51Q-zlt%N  @|SGtO[uy?'yPu6mhf\].{k@T]դPe*'SA1rj)"رyM/X [3Bq7qfYU\7[O \ h'T/2N M\-޿SS40J.J6 /M/u~E"f OuYS \fQGE{P1L:$" 8S׳Wd)292D"aExFn>+@V,r}ₘqsϾӪp؋KhY<0ރ%eTnQ;y96Hj\a&cc}V9d\+XI+ĩC^{Lq~/$%g(yw_ p, qbr^Wcf+aivEahZ܁65WC:I!jʄ`Uplx3ueʶ5W>fL/wRc} 忽aJNn@MEO+Mia_JMgc?ޥ9(Xmw.#+!, wdNi.7\1` ⪞&Ȼ (qm qz1"eC<˿G砜3!탪Nk"ۚ\$++}*6{lcꈛC~K;_V猆AhQƄ}M-COu$,ÞA{_lZ{ٶB@d(l7Z.<2'Hc@1޶O@`%HwMj<ٝ_,vϲ8 2c|O⻯_ 08ޚ3ޱbˑp:=[m'J[|kĀgG|dbe9T7$3E !76 QO\2u4K  =eԘ5ƪmw+VX r>j=2zU8hy&I[fo):%?3dӗ#0Gܾf52/^T\|- y}WH+@QǑ!Դறn2o3TiߊSTcܥf쉌ٴҧ@֘1^s1$ _T/u__#M^$2*/ϯhYX6GȄ8i j7Aћx )kYwfGJӒCt%ǹ$h?. 8l`iۚR确25u`֜ S;N3Ѭ6;8/(K%^lsl2 s̙pl!(_ݢUt 6Eu{{^dgrU f89n~"ijxLؽ~,eyLpWgq" iL=A#n±Ef}˽{/R\"!]w@a w\p }7R(_[D/xx9$] 1a_fk-fH75]5\m)Z%xK\r (A4*430 uܘ3} <݂_|@ʵh5 ~푀~eYK!nbiJ'5Y 5X`-=muY z=/ۙ|(Mw?|HBi4ث'Zr˜6 4N1z3¹@L\GtR.״)Kv ,\榳"AzEߦhm@5z*?6"/8Xa^D<14$Iu]ł3 tɳˇfxErpl?-?Ge.W1C [ cv$-&HYk zE_7G- "U2R,Y>,=K+3&g  |- %@EI%Z)=Og] )˞l/:}ͦ(6¤?Uosg. oc{?.],qf%II"}!(Xb:~)n8ҳ=Q =w_^ur sҡL'>r4YW0.ڤEcFR_ӿE$Pر]F0JVllGIA^yU]b.*Y3Itߝ?FyT^1W(\7 }&MIݗ`}t9bS[dUȊ}n)6Ya# h52 fc=wWd]zBPKQTD_Rl( R)ed(]m&M56Cɉϛx??} -qXհZF\`E;l#KO/BZR-aB铘ѫ+EbCu.16q*e4+M4=|ԫ\".317`D~6ca5E=5 7"Lb7 =:2HJhz,\tџ_Lo+HN. ̙-΄$=JD|x|(6Afo1"aD"͎h5W }SPfUL"SVX]LID)bp-9} Fg< AU rKd⮢۪ ˮFu~ %2qa a4:?}-:k` ֩.,>C/EoTջ匩j4Zx ՔWAl}Eʎ䯳L@|*J\RtY"dB+;F0 \keӬn2ʚ;oIIأ1 rz0:">-H:~b[~n/9-Zpښ|jJR5⋬*PqD|8/fϩPwy' 6M `,]>]ZbɆn4_Serc޼AYX̩&7ft: ">YͤRIaxYx;ݾqp/ˬKuB` J2!JK:gf TzlmĕNfG98_6Mi͌ 0p&{hzWmxSZLGBQ D>|EPPن׆-Kx$jtung|HF .]V5Z/oF*6J.BSahi%L4#"j,YYN 6akl%SN/J~D%Ǽ )Il{ xZatI3xPB \郭RcuaUJc P̫ʞ⽃˩VWw 棪0-rp3-RfثWB7/UGraU)t=1<0|ub>TJCܡSBiV@x8TT56>ؠ1[U?3ܬ0 E;[Iq|OO+XU7rRgڏ]_}W F۹6ؒ|]()w&_fdgjK]:zOM03alN`=Ji HIk]Q)^ BzI6[:Tub@=)srҨ?b-XqG!R7짵y*)ZTϘ3P,]Nn#p>oƩ0I[AF$\ >ÞN99FrB2uQl_ANo:e4Bt]0(!n{?"t2kGRjzlzF{b O7PVW{SV. >Lz@<|QE3&M(|CCdm}s7'5`xv*6QR<&S; "$axl!t= ?m3__^&Jrj ἘqW?vs*ly~tEü<N5NT 7 pI/НDav5(åbxx*אF#C㽅Tƾb@po@F7]pO^Ev5F=i9DbuN<6-4T '4w"BErv-n/-RXx1kjN)QzΪW\9Av^ s}jY`T`W(y9#mv-te*ޚM6g°ՄZxWjʼnY`(r;CO g'/'j,.'DJd`xXD+6OF3J)M@"M~z^?R/T~AK!zԗ05L6>#x܍.O?ZL 4*nG+|7]wg>!~;$ d9/W G6}1 #Ձo '2K[J[3[Q;`W؄݋9WpBCj0D7A䮀ąH[{ `ZC%x^e^[dF';oIe c;:wA;/%9VYcm?fW8(A?*d7aI{b MhKr.sTݥ¶BH?ZkO~ UF _ y8<~{Y ?Vb֓8[*wzUX C=jΣۛ|EFB m=4Znx$`o/߆V~g]#9b/?m9(!3۠P=Q 1Uᮯ%<wHjftN&Dgde4~.@tMzC>qh2NѮ W8l`Ťx\r%T#pdq:bBgO 5rҶD eE##\:%‡so '*, |08B9mt£&wBcڋtjHn.8W4ynqOqdqSur~Xfq x +7Ydݓ_૤j"p1k*D b<;kE5+jFAvZج|;q! )\~ IՖBrG 2-Rǝc EbENCcfY0 d~yڅz'>UCyR_4e^Q;,D%X'9XPJ{YzeWy&p -Un+/= ZO<}b?yٻ-NZ/1ґ(]@z%-ML-['Y昑m?e7-Hc3 jOt@H @~gEKj#Xy̟"P˷`񷞫*Z zuC<æxSp9ƘdQRڕ3D b@ U͸iTC$&m?'ȵN J,EQ-U DD,*nQǾACFm13@,x `bsg qLҵ?3!AH2=m]kDR$銡E?=w? ,K[#ޝ t]M$2NI ʽf頒u2x ggSOW1Z$%rD_vg6$+Yrل P< OƖaLCE D4ϱ~/@@3e|D4b3LqSe⑙=&)poB7`KyZ8Wn$* {WsPtms&kbzRy'eaLNP6ډ..b? vF`_Z?u充[\b\ DjTF]~B)1(/41V$uqoSLE=?<]8hÄ ,}Is4>^f[R:ZݴrPPʣcDԬ`MI\S9(%mE2vӗZw_%`-㯸qod&h&7[or}{x7}`Xx$jJFib:F Ҕ"˷B >&,D0*((mQHUZ,Z,ք|ef3Kht bT,)\IqP@a^RcI,axv6ƦSY'8s?U  \2kw\Ovq Y7B(⟘Y;9Gˠc XrH9nCB˻zK ]QJbSL цReŨtszh7ܓߜ")FgLȷݜYNOb8U>K{C[X>K{QL?C \TtD'xY(R_5 h}X'WNښ;n(<3n $**i m̿hܠtp)/7㡋[д?wDŽG!x`qn rF.HLo*} h7DpS2RnP V,kM ,Hp/7uI2S:~Jj+Z(tu(5PGanHdWlj-zX5DkGIjKVuy"`Ťީi-NvّF$4}B:y0Vf6[ iat 9TJ;v;k@TKz|cfZsvJӖ usX/'%JIJ{6/M ,\ _n%5SNBlU&I34^XG=?"̛t+V߉ZlA ONotlu\ ּesPMZ!߿ λz>=n_Δgv |7݇G!}E&%|V[ sG?<6.eNP3U$Eng/"@%_(W#Ig390T|kJRq iYi7+#~SdU.d+#OJi%~΢2 q0&sNq z粊诨Q{ EO䪵E Vc3M6ISd e;:W<ݧh I7 oB% 5Tudj4YoA5I),!'8̝BekA"^w4voz)&}H,Vu93 ?  )?)0Д[RZg5&"i[H5Wx%颠wp _6Od 2̩Ӂ=9% 6 ̥ZAد-%L,i 1vȅhY|ke-D_M엔HuWX0f7(mAbX䞮Xslr= p)zz|Ί\"|Xb F{vb LuI/[=DI M$i]E$40A$c:PF1BXH->-ɞ5],ĩK,yOroxQar0*2;<'o^Y^11~IS1hKйep3XB `T;'UYv䖿ykO(Uș9&hJ}n5kf:÷AY9<KqeA$l2av/3TK>T{KϪ)#=5тg 7۶ύG ``cBν=]0ⳅ gW${'zM9vb[4?S$j!97I85_>RQ93$+O9t.~~eu!CO?^rRįqqݶ^8'h56Z.M߃EEW01u #r~gut -WteŦbU0^Hdj4g,ZƿQuiKSd`A= uMl8X:6I3mr0x1&r(4ϓ7_F ݜntJʫ↩sxq;%Í|;0r(lNgOT <S#E,ٟ]y[y>S^Aic o)Kx efuE)* ~jccҰyzԱw ;e)쬯"__ }y`f$_atS;7ESsH]*a:hъ,,ݼXޫPp\]t!b[2~p'D".?*ɨc$S\}':CxɁŜC^L(S j0'T[{>Bq[s&ߺ\Bs0ARuᒉ5 ԐۄFgy[V9b44=?TB[򺑥y5sd9RUf~\-T wܪQ6vX } L@ 2ex^Iذ>P؏,AOvr=&vϫc'S,u#Cv{8a9 5pK);Kh@I> ve!]k\r?kˤOiDžG/p|Y( O4*R-T4@sB;!۹LoL;ف@BLwʹZBlN{'e4:D{ؼ]͘!2cwVݴ8B#s>Tck | e4*,m$8@ U_o;ĐVaD€0)DYY]nI.mc¾[ꇏ֯~7D ~W5F9UNޭܼ(.вڿkܓP?YQ oz^.lbwNS* _[čVJ'᥷3ݱ1&T uXi Lp ګ:z; ,'idt `dl֙(>ϒ~EF7& j_-g`^:Nz3٬W Ƨ\)L:ʜ;Cbd؇(&$I^xGο&&W1JO6 UҜCm2k7.rXkU&%1N!}PbEI"^n,9;N2v/xFg@5sc3*~H;) )jܭ0LY#Ñ(Swl~87sŎf˚ [34c׃y @XYu_M$lS-,Xa>[i> RA GB~lFi dﵢAez"g H[OsFJnhI7f@?cEP3H2w w:afNE#è^w,'IzY|^w ҍ'E7 IJ'Vx(7.!g|r_akS: M zst`6ljٓzI_^OZE0@,;J&foހ⌐&h|߻(D)aIHq|]1߬\퐑;jIÓe (5hĺ!2AG!/old= ? C*8:ї z 0D6b@MHс `iS1ݴ5*uL{B ,+;9r NcBjR: +_ML3[H9n~t9۝Uޚ,7=!.NH$wvEǃu?\`H},xFkN7\ԩi%f;}>C(ua,D$+ ^=_}OQ2ɵݎ,ׁEs c&MhzqfTΩ' ̗wYȹ\!,MS=A¼tJsH'ewT%v=2:7VG(֤> 2"f2'v@_`ϜF}Enu?CNmJ+BӍq_f:CPC&eyqwEa\%rZG@/b*{ (?ZgA(2dn?IceQ!jUR0fpSP#yay&Ξ Lkl Z}(1.8/Oҧό@`isRXfַ/DTҹb9y?*ZZ__x/e4xnbŽ?ƣr9G1VTG'SZ*2u aħ*~'W`[*vAח#Jg@Z6oYi1$Ma`}pΔ'< v"E•!N0l\tjE9p4a VҪ9'*K[K0ya;M-b:2aT/XmT?AU=' ofFjAqٙz,8|O gŒ׌KM؄ * ,Ƹp9`cUDXfߤSvn ?4t&)40DU8Z?٫8@aaEe<]եnc2_VPR?9݀~/ ;Î_6Q{=7>Sf{ Njx.õ떷ʱTSbJ o҉|~sEp~5|LmO#XQ#6W+NʙFy W-,8W!ތ?uøGd3!N~_nPI>/}G7A;fG)6_#~e(ȫjpWVg&)Sy4-~qqCqn4E"MŘZb~:o,9k>tX NVj|!Ama#W1lA.C/:P3qZފ^xỏ pka܌Mp?`l"^aRi-6[)5'4`ͣ8SnaG4Nu`- 0,HVtWfe7.eybMȲG. rj<7Zj 6[l8b*kxѳ;d[}%t["bRO&2xT`Ez=j~˩éVE5QYG_Gt:PLm=(nqϵׯfro28*g,89x:7 w^ͺtTǞF,:iZ ́\+>AJxX R.ZzL5{B^9!/ WQ7LQ֕ K8go<|/{PdH̆Bg=(Q \nYDMTI[*|h"{E|\ }{_5Cp5?ѓA'јDakA, }=as(;B1)xR ˕Z 4G艣-]G_7.=͡72k10*ھזyjr3`3dj6-^"Xt<.Ou<1І_X5ߕ.f$W7imОu ]pxE=AՅ%T}N7͸%7Yua’dfn?GPt CMՁ%)!+Հ**=_1]mm4x?+>Jc<81JHգR[T}znm{"9gx7Gׇ?= U7 7%t|) kȮoɳ^qlWz=%n3MJba.ɶv'zr")`G*j6|B 'KfFQNt~FU} hZ.5OտJѓHE.wPЀVRɵJa!Cep eQ~~a (b~tjA Hm!<GA|DE쪨(8)iWǸ䨢/yk$I@+n'v<\qŪg#ph+ӺFoh%^ r×aäհF4X= m@uAxJCcD VqQSPfY˫jh@VA sD1. , z745ҫZC 7t2-DaqNQO7) >:T *Mؐ9D*Lsq#$Q.C6`EcC(˓^|Gubhh=\6Bo+暩\'V;:qƞJj٠k 9L/-{?u8|.x9O+TMjiv[ 5 _k.>J5nyp~L? k@Ry=/{s"Q2>$xhԲCG[.pE*jjƔ][;/*1jgVZ?OWI%bhs T1LŒ~K~v_4$be󓠯9#%U?ZPgJxi:PZxuRJҁԶtW ꫓p[!pQ_4/r ^/#kcZuI\.ktQ4@;:pt ~Eu'P~FǙmWrD3m`CjN0T#x[u)hӑWzMeMeP-V=!+@ҏu&Jnnd`T7L1KF'ފ}x9רvRk#!&e`]^h_>w|:/z &G0ш"(T>fi[D޸OAdiNlQ 8WUSSxwmu5f1W'c/r%NiYSgdxS:F&qKra$Q- Uz~%rDQMiIH[DCn ?K2Y&%O`'x);ִYV9bQ۴\ĉqkJ>bw 1[,'7sw0Nڇ$b꺞U[ UEi{c^)r(^s1"EeiP>+g=zb,Xg0]YL0ya[rEl,*~PYu._8FHҟ~N=L -QGɹL<`БI$uz{j~@_ tUFsEHdzǼC%7Ns4a=/0r8$sbXwIg-dP3ax `j&<1ivΠ*QY <(C3Y#=va]^bBo5E0#_L9,l7sz5%m˜DZ;tiӻl|;ʪTCN $9.~L}&Q_P/FhIX}Td.?AO׸Mf1 ,q]t^~aw=7,ґD?:c6 !2{ieJ|{ˏ_\#g;!P/МF;`qT^m$BRsM!E f%}g]\W.pmsK؁V =}^ Z v:U ~~A(zw>E)€aL*$K] mv4%!G ;*YGG5ZyuÅ.2f\m|*՝<U'qu)JPA>Lӑi(eCb|=89Z*>@Ҋ:[8FI+[y/̪7[!':DIseX#UoN>| EPyJi`7%Ĩ79kݣ-Sj #lK<̔vz&aA'Jl'CBFJdH;1e!SxXtw/6 ~YxvmÃaA$/)Pk3Kq]r73F/soe&(^o+URaC*5A83?a DӭZXo \MBWGsf'vLjwqwOMd~ { =E732<4JZsf;}V|y2gyn2-Q,@\zNS*s=baIjeI:/gS>e/C%.ewY`v$UsЏ*4Cw&.3p1:6Ŭ aΠ y8ǸMUU)aF\] ڣ"%}Endc|YP/|zּTWH^%!`qMx9\;@<*Cp] 4b8uq6wS!JmB-[]a#Uºz%*Y͢{uF_Ev }9p4p,_rGgЗǚp4I{j(NC|̵i+?;#Wx]6<&;0)sKJsQkml '1"E*uTRnkU#Q!9$l}X *ʫˠ/ #T-Ou֔MAޖkɾ4=rGb/np SiS{6;,`fI=I:݁XR VQpOVA1,E>(^B=g\ab%4`z0Fx[\xv1:uE@Gv.=/3@l\`˖;c6u$4h+m1e~8TPRnpvGɚ `7PVD) /A4zg%] {% YZoƥ9ưP0R_ϋԑysݮ22S̲x3&m'wՏ^B6KbNL9Ս'UwʌVJMSߢw]YU1en:E&j3C*[>[qB|@ fO&iҳ%5s3qae.)rMO!NLAV^ۯ#%Ԣ~T*T? %="XˮcXE&Z.Q%0AK\o;5 Mllx0sF>C(ɒW'=AZ. 9cFަO|p/)/в_- Đ-U HY?z^ PQ# yݛq.ي|xU@@TT(wշ35.\RkTA0g g皴䕶f}df \Z'V2iZC՞ʭS8 OtQ_Tυh7l)@+GXTPO^*1ߏg.}o$n$uy.U8gO4ۏڈuPXD"8`)깄NymfR\yAĺz tQ7"ju%XRYV[@1%ho=/_C60T&aN⟩.-#Rܰ< !1 aձN11x$ l)X]TdAy&F=[joɘ+2:nG$!1l.SaYu(CȰ9w=b/|K~+ 0,KR-/aT}[tH SXhrG}"~)FQrmiP'q4 cG_ør\Utz MK^I$oHCFi])N06@qeEo_wNJ8Qs\Iűx*]ۡvfsj>+'D5kk1֐ ) G;P"%Xu` oITBvrv.S "OEA}u365Wc^)kDhl.)MN)H }dLK]=l / &+h/)0sy ̮2ܱ-l׷_JQ.z9~iׁ%Gڥ}vT9)-̦<;97iz2;eNG=@c3>vGGT TY_Z­dyCOHo%h J⧡U0(eR^9t/[̰^1w3pYvC]eZ> O"fFq!pFF{uz)>xgr-a۳e$|[z.qpv!I^INFJOc>z&&C>飇N/_θr`E#ڍy﯋ jV}dž} 7AD,c`]4,NYL ` 6=eQ 6UF2}[Ϣ+5Щi,d͠7$b,tʔ i[J0 <&߂rmͿZ8wѵgc謈ذe SV;VT4W@EcirĂng[cpw4q"Xn1@$u[HRHC\A{+"Ɖ[]҅fbQd@%EtGV22XCDW hD34|3ۮN5i|&0%^g8DЯcTɯJ_'") N. F|:?L]$qDi 6=(-#[(W ϭs{jJ`,YLGR8#<4Pdu?HwXC1C,X8:oA6/=u]?s78-R"v|\h%+A MGVc 3T:wd iJ9PHV2RDZg:Ob{aTC# j;xrK:nEI7ԯ#vc!Kts5elMgHiB60 8i3)1-96O mVm3|߇'spbA.0AtA(v% ZZg$;懾IANS ˳ _ bn7Jw ;3xfp31IcN26sObˏBZǚ[t1xuuI_Q64Ii?>/&i绣^LvJ~V3 ()-,q^/f b2Eg|/VM5 .3RU?i[ XEvz- J=4+zGe}hB+JsqD?M9^b6-S dvL%L%Q;V46PxZčdTGDsδk`d'sư4cn7ixw)q:dj02 ;8,??I@ {tnV̐( B3] el;%Ǎ{uM !Ef۾>~ɗx#-ȋ +ل̚h0yA=_CAJ{I8P\d;I/4d]Xq FCsg\w $ro (ɢz(p8XT9T/vkvgB* jzAIbK&,C)˪y4fF=$JPQܼiCKܓ"L.VdE0ǡ:*tsi=hźnC}LHO,>8;htК]6^SGZA>]M̊b.EH.qDP/`^I(;6QC൷Z_~t_BTXAl~[r^N Db7l!4WU3֓lEmQj[ `&AcG@Ё<_UAt1ǞS<ءXTR=m4/Eye&2 Zdž*C wf^Nˆj$b?6n /}m ݛ{=#b:|:~]zZ"RULWD?cLhߒ[^q-`lx"Z֫Zܣm2\^dx:0u8-ĭGHV4QW#ZBMG2*aTT%a*h!:Q^ KϽG~~ m[;ZmJ wַBh7s*2 Vu _C;ƅ5 _ՕplTiBL@,tQ ˀץHT: jJXfJȼ_g93 sݙ~X $sΒa6h25YNΩH GRg'0ce$ mV8O~{yAvn yMKS| ( E? 2GXRw(7Bi o* !, 4bq!=畤 rٷ?5E(DV3q`#=%>| MaM4'2H cX͓;X1r╖07_!3&Rh"YhzSLu Hj$h< FdXP4$@GhF/r<14gcѦ t4*9h<޴0-YibRDLieH0+$ Ū,QTa55ӂ W񷏖,BP$#0*?j р9Vzi#kA{ K޽q}M1L+\rPUuVR/ij{ѷϸTw'Rh{6#@?!E;Db,c&0eSj^rԏސ ݳ'@>x҂bwX߶^6}U.пL̋˪ <^8xPTWZI*V&?O('i4& ]}ns}ɗ gZJ4h#rz}Qj6ܾLCDu9gZZDO\kQ.9 D}; tJj.yLov9=O 5 :cMX4|{ږ׹vŔ #EWЫl(йIJNb RJMcb K[!+ZXC\DgvP,ք|aЧ;jHQuzF4J'|2=B^1uSy{OC^ďt`-ᐸTih䒸0r] E6X<?T.WB ~C1}S*fTϨ9i7N]w_Zm,ʉ 9pTzi8npQtY8";_r&y?gʚ$ &-dŮ'يHՆ)2@!SĖ!%Q,emCv៓(V<{dv$ y/@{O۩sdzÍ!v Ӄ4Q\.}|QSҢ%9@dF9'^2:Cs xzgr >|R$a0glaګXN[ls01b 6iĩckBL',aeه9;DdrTbs>5-_7odqJi6 J4_y`=N<`<X u=̿灵];<`);PM|SQXEtIQc2Gɹ-GW |/᝙/0Zι>Wτ$!ʑ0z±/lm;lClO|`0"dY|o0"`˞7FB>Jj]$*71vH-|>R][' h\E=@(``Dh尕 nzo}20NH (~+?=.CC!2 Yã4}D;U4 (/ {RzF,ƗKN68W5~lm&ñTb`ԭRƉcVN`y'e8^< `'νf}kwo:_k]nj("'߀"ji)2O_rMhI`v[%U)/b/T>K-Xc;Vp4"8w+WKyH) ^w)BMB59aS4]<=rbnw'9Y}2r!tO6l,d?+yqGp^BawfF ^縯]~IyoB3d%d>$#J^K Dci[.\m虅6~[LctN }@leK!<) 8\&ͺ/1H0+ nZ~("K%T|3b P\OJ,n6"/ĥdܱ"k"B;(H/EyrccSu܁";:^%kv63p08QsʻFnGOZMt=šݱSm.dSxQ<j|=к(ga,U'k\_ҧ3)%YhhhB}y??޴k Yss`)TX֢rQm~E6·Ln2*T `Ϊe[pS&_ʐ@4Eų@8Un689G׮=ŏǯM>~6M__?O̬5x#6aP񏈫9s'<縁1_U͝:ſvߥK-d_)tٛxup3N@nZ?i^S,zk4&0Q(b!p$dL:X츙Ex'si'P0`ۙQg 6k{gIJ4$l |m:s( ?n@@+OיB8ב5<6ܶͷiU*94 aU֬mR6\P^"6WJf5\}.F݅5Tv#a@5܁1v,Cj<Ӂ"WaժJ!o%BX4?H\l7D9-hbS' 6yII"ɜʅڳP Ht6+Oh6č+kr%b] R]njf-y)Ɉ{sKk^DpS^ 5簩l2d(n Vz.jq7 _4Q>inysJq">0?*}TU`wp"r1%)[CoV~]|&􀤧YxH dVWX_fshtM~˛h^^8lk\*h+^~Z@">:pmţWo,DZ񂱃E/?G2UUr-AZF:mv9)\&،,^ ,# 騳6νrh)h\]} ;MTҍvfDXӻ#& 42)'9;RDkQ1S3sLqUj"orX neβސӘ6fѾP/,LqiwB^xJsrE/-p5jxTq xuچmt0Xyb'Yq^@(mۘCI{PkŽ;ڐ|rgCr-CZd(]ې"npow31id1ܪ;> 45#}s,#m" J>sk"BNҶ6PhEω^P+ČB+8~ HH`q`2kI(ŠL gJ2"pgB)c]/§B@x'=NFu%`aZlv'tuy Be"-T~$ejL@(_I}QGVS8ȕ}1?Y{*才\m,C0@oV^tc:|ނJϐ$G@YYoZ*6}.%k·jfsl2vdV2 y/`WTx}[lqj9\>nK8# uxiMfS㝣f; tٚLQ"uV$l;òǬ00kq Sd;mPP5C;L$I|yeHmK (_!m%,i./i`v-Fc]r 0(3m]NѺJ2pWKExtcP6BBQn7qˢj1QJۿvs֕%wE]ҼmoE9wj.~z˂wDI_Xؽ'ȅUisLj"w Z /čZhCljI#A]Li,!) ^^R3j oZ Ssz_ ޓ7%Z~"xa16C@I! Ügb͋ΙpU ՝`&7r> TpZe-cDcs[=SR=YiߧB*f/0u1 )If,iww,Su¶Ϯjfc0߆3oawSTfݎbUYMHq{\(W},]g" 4 Z=5q.ϸߐˡNN?f8r%1 @ Vm>Ȧy}S4<6hT ebZ8jܕ,܏)ڊsQRu`C~ZoT'рSFP"~3EZ\q$$5Q/ {f9: |ʷ2D<rDUO 86 d@m5D3Rpn%x h|f/PSOH~P\X}`]/RUh1Ɍa\4etv7)ysNYӣ m6WЛ ۴U-($ܭk# VQo#bIi) 97)'W0 u;,|+tM By/-Y< g WسPYyw9mۀڑ5 C{ \'7zV)hҧ{D!,¹6Yz݀4s4~c9S:GYsV/[_֘ɡ(]T4y^r q̘xuT?^m!gR;T`5ՃmNlg 1/L1>QY Z\ܦ"߫.>+$gMV: BwSc't4`tH}EiO˒EDΘlYpNYl5ly^9JnH1JSTm JiJXw_%'g_}Dᅣ$aTN; ޻d$*(65xظE9b% 4[<2Rf#liD~[&]֒LnGƿ-mJf^{ˆ~횞KAEF ,_)` \> 硩HС ;&ylۛtp )) [($b{:GOb.ѿ&;ZA9s 6 VVyPSFoL 06~v(sCo(RHo"~EI]̽7o1P۱,$m <[qER5: m,;/*ݚ&wzWC-{<:onkd?HA{_xZ܂ynP:+'>RJĪ@Pܳr=4 T#[h}[s7k|xEɈ73uqs;Z*/`1doWpK6J1u &ko׫V@.yH_oht=c4bjO_2yߗdzpCxX]r9MXGHH%?JP$3 (Iv>I/R[j(B] h[mNq~4*>JFH)/ 1z2s`(ȝمAj☷mO+% sӐ0)c(b]^u?)ԧ` 11v g %;fUs"cvRě+"nuTJp\PKwG84 !PgͺNHl:3TT&H@ tTa\~O <2NͬaX«Qg2Kw|V،< A،+ HH6~_5%YwbW˷`u"F5?cB%Ug5!+x,v(d@P&W;8Ʌ }2Z$c@N왡;Xoe+XwoKepz}Yӡr Ŏ ,\#ơ8x߲`❙u9r ?Kڊ"Hб~!BXb#rQs!Z̰ӿQ(@=EO }$]PeWI=Þd ke8[=`u3?b*CP}@?zVl ͽ$.`vfg ijpM zΰ,a'0w~7j@eԢޜM0EWP"L.zY2oZp@JO.Dpr7l:8^vexLxr3iB4JЛ C?L»Grb_=0!éb$CZ<1/"ӫ3ӞBכ>>"!M#SE5z>=A`8?'z_roMɣ]Iތh?^ u?ͪ CJHdvgJF!ϊk* _GL/r69bMc Uyg}^jP6:v]Z#.oؽ{d e{x#bUBmh=kC j_*]l\2{64*KO_OgS`4ur{yP~zMl֒OYyf-⭗QR C(i}WCT OW3kAȯ9E+̑SlQI`X{3R̒i6c-hq($M+JO6;Ş B7nc hTy0y0(a6 q3nV}iM njL9.s\2KvFs$%Ʋ oŕZ (l 𼧪tp-S;xQqa#ʻ?GU%X{~_YHx~!d.-}IQ..,)VezVjI~gC5$;N?Bşw9*)2p'E3Fhl@ tQu.MבXlU(2tI;j ݠi"qȤ1D4y'4xK!wի!d"FFH"k H}0!`.ξU]J@2+Oc_UW,\GNT▾M4\ ۤ3{Bq,LɌg{w8dpR$6Lɾ+UàRI(F8b ={طZ;(7)i`]LLuQn0: "nV(^WREl.!fW9FxR,2@Wq5U3LF*̴9)(q*0%T$qz|`~`U *ݩi'AKҶ7]S%pELlHJW)yqCzY!a pf@LB P Rǟ/ >`[vº^i9?-|Ntٽ!vZYsЪ}$ɮ֎}Sr?4/##NF҈}ܤ" vH_9UFMۆb9\&79s(YL\K;R|?N, d+Ǔp "D[ftؕ#06.~c"w- ݥ&#EebVAq-\n®]vXs7"۠cf7!OU .wBv1ӳE6ڰ>|4H/[G@' ۰7 ^rSp3lZq||J/t|Smϳ=cܜE!3=Cg/ut >@|j:cj/e5SK!|Cڠ؅WF%B^4@+^1Z[#0b\ߐ:8ۦb@M]-VN4S*NxD ①B vC-r P3Do95B,W6` !I]7V䒓ϢwPꕯSJA#+1G(;n+տs8_r ߫E(sc*ѕd:toEƺ/T J&tc>[AI=_ZA1FjF|Gٸ$0G$8wyY1]N$ l@CW8 x3Rh!;Rǹlφ/I0]g6[ox]RLmu *3ʅs9 NId2EۀyRqY8W YsFRGAn9Bz$SltyfN4.f4E<2Kh.1aWt׎2L3فd=o8ۉ" jMnpĄˆd|V4oywH>., )YBen\:t6_řm&s4)a$/ٴ;y j;_E')V')A&[9΀f=fsibBu AiH{栀-3V[oZ$k"Ky 0&J7)ˆ,;hB}aGy'^ۅ:>60ӳw%6CBݛۜ.5Ϡ,RIcN.M}/oIvfq{xݿnO{hhXN2]Ay*+,Εd Srqh suIU]Q1ұ!xX+7с\r6 Bl$Bm&z!] C`:18~oEevQ|CjgߐrO>dڕgHnhZ=X0%!B)Y4J-OA ﳷ-8w=M}*է[Wkb]qn )QG *x(uŚz<0Xkv:I̩D0.&!~욶YAsĕ~>ᮥGCdaw܌q ٨`${<0 : '&=gg㑱8} O?LFf/ uzZh,H_?610buc[& ^6cÆKR|zuL}B@w⸑yݬ`yt.W#;{|<1[aaۇddbM+l, Ch{֡"`odkoᚈWv Jl% ЬmBm\~3wN3^ӀnϥeNGs@L Uxd,Ĭw,q5:W^K|7011>["8ySM ^$m&;pNaaq?k+i܅QzlZv`7:_DTwt,mnlV`Ȗod͓ȋCwBK@vnBDP1=e[#kx >*PvSQ:s1DJTSaS>=Њ`.V0ݞ%zz2ŌI%9I9]N7m7&$(? `% p ~G'4HfjCnN@WIC~D'tt^ZDHӣ/$Aov>蹝f)˿q15)-K_ےn۴@ag]`x]D,ҟϥ(r ,5> ]ۙͶ'(H$(prp,G)3'lNTxg&N^/ApըcoLP{^_#]+Z*"K,mu}V.ļF %W)ө'v~SbȦV]RٓWKM4TK>grW׆t{p\M?br{\Xw? `DWlm촔#|!3u 5EF//j=z/]{߿*QcĚNt[m 7D!R@]c@"M"0cDx-e?keլo1<>eݻlUd&pQ~lg w6R L,7\;`7 '%,$GHjV}[V->̺W,:G`3;lgz{tR7bU{d_?T>`c ؂wѼN3lǽ}B9iLYZ=&,5TO+.tQĈ"9eq)$a kUR>BXJZlٖM1 }HP;5h,&{4ԙ$&d0g+V+pE!O; IN$C8tĒVHC!CQђ/SjYZllN.7qY9t!|+5vOH3s])^\׳[I4Pc 315q5n|ΚhVq+ceUeA=zPJ3%_ca;l6jM!i쟔Uq #Ѧ81f]/K#paО] YG )kk"%?T^>j_Q,pu(g2~F \<-T'i9pY ˤv7?.Vȵi zhwt9 Rbair<[()( yo62ٲR`H /$+A@$ conę$E%8?K>5l祁qm*S <@Jn^X"RK5PLpK`{wy"Z2oSӮ7͵ c(tT궼_yE tt@^q0L(ʴd[w돁H"\E;y4S`؁aUW]CskUZGbSΜ]-eI69k[Ud8"b18 7"xvt_3E ~(5MŶЕCk6'`N]NltWUoRn"2bZeZi zZy+UEtSu *ؔ|rXF(vE+'/gMY{ _tsdDsqcs?1N`b|0W}Y9O&0$79|ECmrNYQi|;7u\ ̔qTE&Gij9kM1سie-gF I1!万-/Y_|]3wTdȁ׵S\/j޴tg ?89PO@?\%C;UT7BLۜs 63}kuW@cVǼvьJF3>CzC6d6လ)Z E%x4'`ݏTNQI!X-LH]>A):Dmˡ=E;-34 6$7n<]+2f~A ړ8hAP]İ@&s^l`g2/*csI/H2˓*e-#q+1OXId=x%zOrZwOx`F>'C;g؎Z75:g틣f,rXH Q\ W<6NX}j)RwSNebh~ł Rӊy:*J(mv]c87_Ԡndd{x,c:hO85C͕xVvQ(!.+)ilz]M ]5W(T2yUρa]پyd^;Tqɻd m<1{L Y(DOˊM@炨:#q?}ʠp,v}R ^.Xh4;}îʠr\ܒغp: ~, rrZ60r G2&PztE¦ uV {^3?ND&p]\qa _.|!USi1$aL)oo}\V6xTYU$kq K>W @|ÝĮ_ژQAG_hvyyÄ6>6Y3OݡsY+5킔cһW8ȍ2hQ8[zsEE@Ɏ~7 A3d.t/T/|;c= R *gTz{@#\#)vI[5q3̄&6̹̈́L2xlW]PO7DVxL3ڄrGV(r IW6DU(z8w u.O5EtU%vXT^;Nhm*;Vv,&qk*"F3dwe O(jC7Uҙ_[En/A?ř4=!+?f'9:hol|p]om̨ml 6XcX2-{t82_7mdELiCg>p}3ᔖWr6L e;{W(E)uCrr#a@7 h}w :#T mt;QyuۏcU;m-K,$((QO9:_Mf[W Bdg[V;S1pRisrChTlc`^ aƜ9 Nsskp!awX×T6gJl*u(iN^LѨ%),C.KU&cImVG:5/B6)FJ!rWN8;l>+4klJ35>uwo  J nӏOݯ.}ubyÃ1}UlƏPFSBZ~N#,5G=3%7yi6W2O1A>_+  WeLA-S,Bsjނ{-S dr/cSLr&VsDJÈkP)k/,&x0dM@R,O{G5)'FSYx^50!O^)% "3i&uP>AQp5qrC!ʕ+ށxYvؓwZ$)C0\3 6\#VuA #2zbKXvb{`qі;o+ɅeVOo: -xm2Um[ 6sAzJ;,Eހ,k =}$;&qIH t?UT`#GƠ lΊ κ2yڨ@Í mtr ^oWR1V0jHEZ34ۏ `]6l7RG :2 ')`_c7>,U&8v1dx@Hߠlį>#FrGL @Et Z^S9o,WQ(] P3^^%/Itp 2C7l2HmnGx "!Tz,M;ЈA1zߛm1QQ.ey"PMk{6,>EW2uŕ79]r.[ʔ!LDbǹm] #ʼnhɸSo=)iahU?c MD+8j]sadADhZJM2 paFrbT[[SXBºQlj 'xPLF1n}m|`rȋް$is-tKlNsyϑL ˵@||n\~xt,{RVtۦb w}ib|RFmXqI"vW響ʆ֌nOMMFݯs<!aƌ<ݧw]pÁ87 {wbŻ#gE۴|Md|PUa'* ӡN'][)$DuY`{W%[a|9TsQ 7.0G}Y1X v] VwlzKNFEy58-+vXW_'\6uVV3PewcǮ`d?N\5wK]{*~Gաg_a# :  4E:C ޥ9!*Ƚ90hۈ*HG"K-vg+e,ZG)Vi.#y;mw Z4Go83I|@{3InA]YoAh,JbMgB'hI0s=Oy/s5JYБTAN Z(`OtYm/^ZQ82^#l2:F*`P${*"jQLtZb!;gvjxRdR ՛X+Fq܏ݳs]1<ӵ*d;>zҦ;;7XsLrfTsq˹x"=;6MR2.sUiNKXJCqW};J-^Cs`Z}yWу{_Jޫ&W(̗#|,'%qBS-+n.T1W({lK5!eb2d5X$p>ΘA8}[;[զVK[0,g'+-&Ⱥ:*=&Uv=}Ƙ\pmY o+`ر k{}G?Ta4 Ǧ8&{?m,?x_߉|fp% vK"F:Ӌo z daq2 @4PnT_yH]OJT(mC~^A5\xqBJYLI栽goņN[oU籨z+G2=$tlFU!N]9{la,*Zs#l z~@(*h-Ǿ%}Zµ[b`="Il)cWn l0Udg֮]/DɊl-1NYeգ!}BvCk6eg-쀅qvvxսYCͺoBMe:yN#غYaQMz(kY@ ۴S~"`eeTw(!4Ss|Jk=D!#Rۆ#K|jU}_İ qTtḪ{^S8OS}Nv`𬻰sĶ؉[-",{Ž"9N|Y9Wj| VnoX;J8~:ol{K?i7 ֳ2~_:NͦX+ ]{Jp0 y7 ߺ8aqo1P) -̈sve*}њ|U9hF\7^W5.?wG @@ zȂb҄YF37(/?acܣ1MЛw9ăBA0)0 on75t_`ZsKЅJf!)~#AτqG;X:Q-v!Q>&"t'& BcR#x,J(Eyc$隧&lBT<RS#1ͤc,ՅxtJVʇ9Ȫ(yъTG.iSH|(/EFK2 t X}U=t˯ZRoFꌇj,S({x =N[4cV'(0m)"c BEfys-]vrG)'L|z䒜 v|0թ6moۥI(frIvLfd{V:}VrҧJ/#Y2wHӎIJ|e3dUe"1h&!{i.HmDl@ܢuzXTe.Htq3\|^8g{)H3`nMMs' _HkԾKb:?f(`]!@YKl@H5.,=2zt|-[QZINB L²r݄`؏&يkx{\=jOJ2Dχ{&<+NKߊ]q 3'-/v#}DoԌj5Ʀ\LAdeg^ƣЪJyGDYA4ǀFN 9쁍"Ef- Xߴ[UOTq}cP Ys/ ]͍\cSV ֘FخZ,5n78z'$4ʧc̝A/arψe]ѕ]e#XaV:l'q|P4 g\k-m+Q πs\RC Gm% ޥKc{*[hj'#F5j(TDlF\KaL}-'ak^6͚ gۨx j0@8ۻi|XcTyB,";#,-PD7{ gh4e'8*\JYtX4 wUR+ 1%X^p$ % & ]8-_iѴdsak^a/ZOvDXK#qWAy/0߇FzD/صX\|U`;r}bJ7u n<]乁Ga? ]؂ۿ}Oɩ ~f-QDyzVte%axЄ^K P~$œ{ (kbҪv@HhVw0kW3c0V^hQZA#B{ =SOttd]U5>ODDoYKu+I1 a*!7 hk߱f\tgage{&+}EEmCP 0AĊ tIaN퀮uV۴4~vN:gJ#^bjG#B <^y.}B7"tj ]>'(KD.bӠB_ό/5~+/cON9r }ۆjH+V-6 C =_!,/\$_Gm#k3r]a (Hg;gP2UqMon8B${S o -CB <DZw|đK< {fsOu*!hbv,0?*$=7{]!H8-1+sǹ0uOu~sWL}HFiƚ.|MS#xˇ .$Ty941+2ٝ@s(=g.T?6pu\9⃠ uߞ@RGѴ3:\#a oJI} !I9JfX=!9,qb34|{<7S/A(Jݘ%<UT;١y/_i=M5E鄸 {?c|o^z)%#05FFE(gb]$@BAʀn׽3R$GO7 d* Y15~?t|]QK x'F%W 0jЖ 2[`&&PF#zc"<żugʐdQ W۳,KDgQ-SNRW ͦyGuKU/YDLJ f Mta $SA k#8<^-z{"'2rM)5+~tqiWgpa& <|K~FR#k8 Kcy?x@s5w'Qes^=zQMh߸ y2=~~\ڥ2W"_i>5jy3v }MDM/_4."7 Ӫ;ǭ"ؗ7:FG<zpu:%%?ӀIcqW!Yf)QdPXYn'Z%l?$9E#ʛ<<4aU/A'ZTZf/wCZ/*"0vedȱ &d&x2c A>Fe@IpgH;^^,Js-y,ꠂ/mU"dR@6]0~]VfK4naBV'A2UvvavԈy7;RBCX/߱w~$U*!cQIr p+KM2^'FTX3T> zxǒOC#M*&7?]l*'҂[|Ad]{K)Z4k8^ʲl-sMTWI4bK(V1(kg!AʵP 'o8gi [iP$>eSdt®jdN@) ' {PWㇳmQ#idWfҮo<%|~deVGQ,?O%AN"9/A/ŗ1({vrISxijH]|6xR8 L*fbwy]8FfrQH1'bz܉ 1)-~ =C74%^>V)=ނJ0W%XOIvHͿ4^H}?S>)vEc&?| }'m=ԩ P @PBE,,,:ΰ;/eI(k>'Nz^J ȹ@M _D6~x2qX=FVJ;eM8?Z <_B~"`+hCA&/ [BeCΌ@D1'IVsSC~g6 >{rd4C6*\/8rSEASeHOmhv}RENG\l$GkW՘~P)yt;隥LPL~1~ 24@W&9 Ќ9þWd&#"iY' _n9Vm MwSHwYb,;'ezSwۡn"hqY80n)'O2)./ yXBґ3e&魮}*Af$^g Jǖ)y愴HlLTLC"q0tzy.3l]kZiө5Ed_R9R˷WwTepٯ tȥ4)ryh~}+9Q=s+Ov8vqqsބRsZʁNW³|#'Jv,;<-osLx,縂Xb.?lx!6ò:4ZQ pOingv lL-v뢱 ptbaMh8DZ1R D+xz;Jp᯽$_l2i:RRQmFJ-e]cqn9bsi+#'bQJǖx|o=Ɇ/?j )AXk* ޏhO;mgwgybȪ:K >2j cgo ,>C3۾R*3 { Ie"oy#ȓ/\}81۴ p$% xh>@Dk4WD.JE^+ URȊwbjɄs^6ވ$%46A9Kh2iˠaPғxs2dd%h\3W@あ )rgE/L G#u,O C;Nۼ1r*` V5F fPH1x\'{WnOKX='۟ya!zlmBBO_ab)_X|k7xI`j~|6W4v{!Lۤ/iFBzFd%!~O_]03)c˧qP@גaSJ_Kxtv!po,VOa('Ģ~=yʏOm%a&k}JltP-eS$.?1B/i,1ZX4O(way (t)0rS80l57@LkҘ4C; K۹=*<=QV-q(UoQ*Gv߯MЪ3%:F?3;5!0 ұmZ\p ΞjBz7&~c<̥@s\@~5kY3J/Q3BoH-˷2&!G̑+\g5MfAO GS]ΡEj:&ۿ{Ko.)ǾFe3[E*(֨@}|jUevt.# 'PvPge7@IujUUVr37+C5 _PY t!cƵLV흔ײz,\M! {yo5C@C_dnzdLu{ɶ3xsŏ(]*3/HQu4^ hWN<J1NS$t9>CoPpđ[8mLcMEeJ5lu򫋯{zDX&}<`$'̌(Q_ 8IѶQ˹% :gNFne]twkmI-Ѿ% jxxʼ Vl`G{6"ûR;52WT-H=7ai[y=f:0"ưRpZuuIXK{*MMłC\zui|S02A2;>z((.@tԒy$58YbmEi#v-@,y̴ DQ04v@%q6)zF_O^Bk+^Lu"Ȁv1TZ} 9yqz˼ic}hKtKKtI0u3#&'蒸S^?ᦷL(qu RQ6 ~eiztO><l9}F bIv\IuRdL2 Bu^oHuj "°l&V!{dySb8G35Cgkww> v|Z ! ܖEHK EGG[`{#FW_̝!{5 ĹCyI.\9O}8|ȿ&"?PI!=;6P7dp#z.]DI$N~&Nڿd ;DƪK7潌uƤ1}Nh DzW-xخxlBfu~ ,tBr#K{f'Dh0x~`>3@_#y\0\h!zb8wR j\%|['2 XNJ@G7!ݸ ȃseR֟cWEj&ͤ3.߯O !V4{CAwXN) t/iW'ܑNGs ;bE.j Њ Ї*ez>8 1bӪ /*2jϻ=}b-O.^.‹U43=4Qx5ЍыWYkϘ ݷ&ܷQ_-GnY<:PDd[vqĵL'm'4^FA~#?6Ge;q=?&rAOUWeK&~.g$)s_3?YoK66Z1"3 olϳʁ%0eh#8B#1.50_Jҗ'IPja_`OR+8^eA +La_-Gv-uGP=B&1z->a'jn`^qK:ӱbr aN,"1*؜.D!93T1մO2QX)X,1[pj|lJ f*r'h W tbUN_;+ &HL2;1[p9CVhW'Sߪ[Cxb^h }^|cr7x"LThd X9zj:OZ8gZlmFN zS "ўV[4ۅ֜&@k=gȌP anc?<"jg죅hWv/Zr $h0ϻ|0Ò:>z8ܣ!)#ZiEejJ&3 c+G/AqTn -^|/c )4 _;p3 ~ρ|OyP0Z c] ifX-~Sѭi.C%]ŧI{ڈ'eoPrOWӱM=iDq?v6HosoAeen#ֵkrp"Am:XA} XUQC>xsMW-V,Nequur֣ 2c:?̼:l* lC22JHT#i@JGS<|6P(^h)h~_Us ck% RI(n}9y:,vTz$ +/ة[ W{D7AA{m#DXJ<]2eo]n$ 4 dwQbFp'3Ԟ؊1ґJMEM(qKŎvDςqXdutzҼO\bB4hnV :;86aQ+8 &",W\EP6s颊R쉻**_r헄"M8s^2?l*.ǃpG*$B~h8&WTTvF3QGJR>bj='kLK&47] PdAƕ+v%^`Nbxs%j2yn0OFu,qf@L:O=)J\3rzU?$]AMpxxǎa%p#!b$ṭGոVpX+ _LSh'sy:a9O88tq"[ P/A)IyG1y G 0 >` ,Gb6Ae#W?9d|il\#F8 ]DtXN_=*K@Ā> P JՒ(`Q=RF^Z \S<0׮sX}k#(nOolRoc`-52+'1`=^ 0>;2hI,kٻ"ݒ4H*E=[uj֐23ot{D> ݵ]lQz YI6h{2fY9,A}]HIѐϧ{ItKVp6yEْ.jcL5OL>D4 sxƯ+z|hZl.C7{=;Q{9 B괂X[l}+N4 =\ǀ#͉߹`FХT;SJS޽3XF5G![İ_ɩ-O jZ6E>?1uΩd4 ^dt:B#Qrdby1C|91=Ta99jWwˍH*vAK9a`Eg#9iN0}O(2<4lO7 *aQj90Iyl`f&>A+ : R[Iғ;o GK8 #GT{"ʺf~ $P?ݯ0g\:Dabu,Np/I<9Uy,S 8Dr6i{3j%#aLfV5`# 8qm7ߵ 'Q umFQTo%ICm$|eAy?u{IG"͔+m_ZT?;^ :|ʔR tnXZ:ѠX"F)OC^%@~&]z L,b AŲ` *[;(cFoeUVsPk/Z'Up,[AJʑ.뾢p2 KeTt/BY{HٚCbl,eEJeYb7 xC"^u31nRG?\:=_:FT2$]SA+K4!WYN/ -o%-^duU3<(!aqVZې!  RiܑfuUBF'ݏ[̳ ӗ3iTi+|pӏ#-tfDٳpV Kٗ.KSh0":wSAL MΊ羚kq2 n:={&jJ#AU 3*K8JT60pՈuIofs5(o "-EğFd+{M0 Em1{ȦmV#Nu{-_?B3O<.^ɱ+rBRjZb߅{' c f%lM㘚*-nVa$0ֺvUunQ4>K {`a3[P\X- S:npd5u%x4tps'vHMEza. pK5[|**F* 쫣 [ӈ!Ԧ{cǐ܎%\ V3;kVeo,ūc2 !LJbڹZ-&5SС$~pp'*Kvՠ!Gb ]=I7H[!\Xnk5R->kɷDcv^HڨpPy1[?k搳6/m {mGMZ܆908BX& )TwU!GNu_逛Onr*3WOr2]!TL۞$[9]VFL;DoqJƶOCV'c_Pz>CМPFŰa3[`˔HmiNrGbĉ)Z>g[y<Y[->'y5ADD:yFYk^>XSgmOLoєJtsVD/Wy{8A|l_=J.;H@})CIQEŗj8pkn,0<)ZB0Y]fqY7.X @̀"Сo@0[*qM%'KmT e|jS8F3*u0ޜQ-NO;h)m'"kKY57t*3 e?}[ŽᏌW:VmBvTl2ATF}oneW4ӵ({ {^R̆. 从hѴBG=sf ntHqnm,8~E)D#|pLt9# $Cա~7Y 3!3ݯZݴIE1ls$ S{_t4}  \g׬/?{yU U,-We%(JOmAw­ީ-%2k90*:v̛YbWH[ e S-/լXG]N$~@.]n=/4;>Ĩ a:۸"g7oe.;2p:S7Ӵ.Vsr mh֟;3dqï!˴%u /{;K>+ƙⰩP1ZKOo!5ޫx~_K,Ho˃|}_ބK_E@⬏7 вx3xvt 7]Lp3(0Eqx aϝ20<)g8G:C6ScK0W u VEWjÍOUHz*v>PQGJ@G+2`zD΍7dH0,<;pd6ƀ1ĉgcZfCoәP=jLME+YD^r^NԂ9I`?݋^7,nnUM՛FB [e^F& ea M<Ҹ4] 7vjՔB肜kí_MꗛFa:ұ̓(}> _}BrKss҇Hb9B!x+@|UIx@'@}f1v3*^?&/e$R b@V9S,du;ze93-N:?%irnΎ?'m+.Bfe ұ4" 9I֏14(,_p6--T~hcuKL@Ms8u4$eL{}i2TS'4#2aw"M`Zc=!k+C)%t .%n-@gֺw)/qah[f~7WQVI@O~S4FDcE3_=؍aZT^0#DUY͟__t@1^;&hq'ɑu֞q}|P̕:?7[yc=*yI|*E^[˙ӣ~0[F\*#JD+zb1=}.M`x(1H>Dٲ#ٴR[i)^#3폙D؈\o$9#?axfX+ތkH6Hdm3&h qE- Biea77:&-HϨ,p4+&5!Ki\qWܳfZIYg֭Lf52t5i!1ٽRh3LMtaYH'́b5`)ir' Q&Bϙc[t=};꺾4 iWm9V14B puխ<z^|!Y? 0jx|+3̜G /cUA1w:@$> 0 : z/ҲAB5x: ,gQ,PfNс_*zGCs?XIZDFu=j\N[sv6JdU#FItt,4o]-q,isx_ƛ",sU\d=Eoz%s3(IJOFy/%eO/⚓d?b_ `ۃf7ߡc67jV/9Juǯȸ ?7Hb'Ol.ZhDrI=u Ↄ~ {FZC\;y}zRGAj f.^[Onzp\~:x_Dй*/LbLzPN U`GP]KS&\Œ䥹|fԥd[/5 h[%? g])DNrYvQos[jjqZ+`?{y_abHnQ~tG`n*\rUTxݏv8+@wwR>b~jRDrfS Z 5pmUKH"w>_TxstkVOrJkc;tCyHѽOZ@K;S7j2 )9Tt ߄2_dC[Gfڔv!ѱn-1;3FĢ?O~P:JEDԟ#nHh{S P7>baC~R& W6óg€hތ ; tw~ї#}1'O,pn  z{vCLl=6.AnZmwhQ!F=]^;WLh`& 5] mF/3A%8m_4 ^1aʰx)fAjFYh6~JZTX|z*x DSADаج7?v[x^ bur[m J\ io n4*A( liqq#eĪL߰ƗU;o*ӱw^ T+j8Y@Q&cZ\8w3)EsY1nu"KQw 'RG EDK@!.>𒤌,E$婜49rG {ϧ&5-!)k-EYV82IJ>g;L`?6qJm&RC1~6QZ[,cb)iQu{ZH􆱯b~f6w!9>jRY?)15^E`}h48ti 7<0s^G'uڝv/R^O"  oz0w,PaliIMd NO2W)DDl>JE@T5L]Ku-sUM5o]C՗FԗFq醴[m?z Q /j8 ʼn0~> SMɭ]Պσ勾կ1N+vD߀8;$sU T{9w6S@wT$܈s@%dЊׯ.26-Qw@+:[wMDƀrEgw rՇ4ӻ{xKA괯nCY܅Ha3ǬuK:4`.wE]æ9Tc?O(0VN.p!eGb5 ĭ槲[JO>2ajt s KY QbX pbNxp""fj$q>d\Y~@=OC鯝O45uƗŦWN*.9V~A:YNsc_n,N8NM$(٢}(N!E s6# 5K dW-X4}/e;/'[Oϵ>dd˻<%?F^n*="S}aM~:,Ɯi&F8|T%e]ޥWb[89st7\94董bn؈VpyVk=QL2C6U O^MӘY*O>g,|Ĥ68%ҡplM8s"5*}1:$/]VQ *hjqyPB~S#c)T8tn>oPaKNpA?*v% +Cq@wlޖ)[(+2\an$o@[nxmsr}#`4&m;4c \gCO"b(F|Ͽ~)G)1eS!)IE> T6栾{)cMX6Q%c/m}Q]էQ]82&ˆH)+mQG%jf)YuHfY*M.ZԹB;MNǾئR/{f?7+f3!dj 's?'|BcS6nSu?r5rP6CF)a08W?Z~ESI ?nfw]`TŽj KB'$?Ws1a)jWƌ"J:He ryًdesU6m%` H5^21i1HmJ\F;1 a KI!u{(<ZP3C2E?M}ː>,;\:7 )>PNZa-IDa$GiT2z?zb^;msfRFBHVohmY[(;5k?898UҳKgնX;62@紧-«`^Ӈ9GRLYHbJqAe.RH𧼷)S'Ţs74v* 4J%lDi@o?96U7?0ru\m{eض%{B=hQ@~>Յ/ Ыcmnv(`羷\(Rz*ZFwC(0}GR3~'JsڛuՔO&u讪T)@1 23RI(g 441 dɼ'+xeV@uohb2¬>&&w8Ɋ2p,95e;[ \pMpFY]/YzSqcoi􈞊?_G*$H֒f#D`'c%ai[69p S=F -;DAzz]bh@ rSgLM9BuMFw4̅#D3ZRa(n:Kc5Mf,cmv *TQ{=8G-P,9QddrWWoF&n= )2oEwHuyˡ%-vπ)AN<&Lݑ<,;E%@TDxDc,Q4$ڑU½4>7bt;@!4ڐ+^Aex+j\LD[b3ʹGb Uj$ 9b.72`*.6C{.WVNH`XOuk5fYg4$5[nf6=ZϔՎ&?^#F GZ販9tRfܨ^WIĨFlvdNR>b5@z*JX͛Exj&,HB/|膘g^ \Sm{rO?飭m2tsj<у~Q ӭٺ^pr>#Nck7UT+}=;]KtՃ]?Â4k|TzWbv>PټR9 ")#lua iXߘQK|KLg%+Q{6p'>&chݛOOfpXyLɲOj6^0n\3( scnJ9K"kyc,Eukwh% [8M;{3(iM zoŮX|/~&h rfj( Ch1C(o) 0YKTTOɹRDevg(ö\߳t\R2lA^a.Yb>}&Դ1v9~>Ml}r貣)dq({='1@>Fiځ*B澏vǛ>=^c\%Fv69PM TsVb,x̰y@_ vO1Lp,$j etyy4vUpޞNz\fAo ~-gC շP׼luuV̒2R4QPyo%5Ц3>Gq˧,.ۑi șSz'*S׹9xnHzt!x8kE8, *9//. ْ݇] 6tخTt? ?/~ K;.t8B9$>^t`|'l6%ڒFY"[#U4W:Y}3uge6t wOf*<4w h8qlf> ^3 lkiZ(sO`((k7,WS%*o JR Ta8@.HgegI͈΅ q{K!`ؚ  Αk7]fh įf:-Zb'A 5MtDbA-TX;!wngI1U̎׬ڰo?\{ۄcuXFXNDZJDhІɑ 1&s> Z!Nlxy( : a"p~D2:nOĹúdLeYFPD @9謔|NH؉rJaŎ)υ,}ӮCjĔu-y~,hOT!Xk7Fu_hrXTn|>d9Di+=\-faKN ŖI䣋EqsNGU@ fL+tw?RjoUݤ'5T FLk߳lDrsLBaUF6EU6Ɛ/ m~+(![|4X;d?<(Z%Q*RҏLNYm>^􀳮lb*dѼ;a'/K oҰz.%R0/;+=`A-@W?T5tK { qgQZk>ҹQv)ÿy*{>9UVz0۽c|&[MeLa\912ŋ(]@z!{ j˫GQ_[p D1r#krxfLt, izw2Ǘɽhyc)T PInFDט>>(tBͿ/#懛KȳJ6?'!t>J˼>Mωhaf {2EFē$~wpyQ?p 2_?"Y3uXrTR).6 #=!]¸SWPI6˛chH8g\gk; jqeN+z |OA1Ogb颲oR_9lx"X uzGRN!t:aZJ'nĮŎ3b9`C.N JN OR [8 8 ؾ em˨6^sTaz0% ;`qQO^ܯۡS nL'aG:YMclBg/RN )|Qe- ǰn<̖YRWE~)x;O8X7>/*b UK<߀8aDJ QS9;88b µzi mf}t9i0XqK+g#ԩSA#x-@X5쏃=Mk,RxY?)%G 5uڝZ܄q)|$(3] &NΩͣhc`% X%p<9!S?\[i+;}ZPWC]*ogv/iO<4>CG/kZC9hyW}aQ̏^M97aA7dqac2e#8AQ%OHY:.7 g׌2)|R=W8 Y*ӝtΧyQ,Un,Bc<_4jO1kVsوԪ4Ѱb{ |~=Ή͐wT.|TkŔdB84Xȍ||r Wda-Nl?:Cu=+A&쀫)AՀ<j ڃ79hDc]P=勎CɷxǶť)Ԟw ]ːo/Z_@Q`F9ٝ|CeN.* { s=ݣ@@MS1Q Ŗ?W6,ua'I_?~t*Twd!tlWD%YpxgTƵ, 2Hͼ|wXn:t'n) p N`Iͫ L+c7hx$nqzpr^#=3՜{DIĆ.;/2Cn6sqPʶl nIHDYHpy+iPS#pl@ҴU~G)]^}=eMWD Q.f:Аh, 7`ΟԪ!93%w_G=Ӂޚ  ~ɓ:1q)ogr(c;nSqB]س1(jD V!,Ado)Ԛ.:8B{IzjH䦣nqtːCvo6d@OSl½h9 ֨쫏8z\杅}\_qv–qͮCA 0, euX`P۶dJ^dFR&qVns^Iu6禨FšړuRQZM-cF5%B8 bl.IDҡBaC,U{T|"mv_VţFEy?>t^\xR1XJ]+R+3CFEB: hMv;ou4p ON8xOCA)ﱑ`Iؤ*pݪjby=>BFij|sߏ+r,ԭB9HKrS2o̪y9qN| |Kgr&.r2{Nro[9rm X'u^%9(@!B<  یvJ!D([jQ^鬚Z΅e KO &n-O_GC9O³]]^{ ~b#( F8̘E* \_/lq 4E>oۢrj G#ل]dޟ!.5"p îN﬊P2+ڳDTYoI$!j*W@u=>$ _o׊^ݰHIwsrJ<by[K1=8~k|nN,57<@+D+Yaon}f\i?Iu! d"zɢa/4G:Y8Pا1sLyV|yC>9:*ݨF=N,(S`! p %)J n![AeiM ڔTH!F9v#}{\5d=ybjN΂' ^In,r'QU!]! ^u?Hή;K)Ů,>/cvxleD  %9#ZQmٟ;c nUPJCKT) =R2 sjA9Jo&?Ik1&O:`P{j qC2X)Ĕ׃$'.cJHhh̲15H?lE?ku)bze oya獠OOv vSQ(C0BН׷LLD]Aq0f_ L-!;[QCLU0[ :o쉚hk׺|J"1ҎF$ o2סZ@t2 E E6P%p4\ua>~*>@%!IIѩDep&uYC٦77kݨ@,nӽ]j9XO;j$<ߗ(Zg{BmÒ<%7Zu;xiɤܹfHP 9))Q@b*3i etQE$rשg"[c4t[ө k~ TYVX[?4_ 7dPEpeeCrÑ-2@#I0-"T3=8Q+G2ᤪh. :a]GJc ۯTDP"S4.AuXsNy{zx.!m/1L |E,LPOncG]LAh55gS@ Rd@cp(&yr}j]v 9 ѥ W1+-'.| iL貜 Jĉ3/~xe}љpmj'K}5a`2HNCUl_oQӄoIpΥY".C^K.a`J0_qKq59Y 1ý>WS"xt;]@r/_k4wYNL9Ì(wT^U̕8~D%1 r@x?/gnDXr-=el%AH(ӢE7ZOyzҿaK?{;>z煎A6o}+4 * ya=ϧ49T2KΕB\nLd $8Yéռ$(cJALP;G$ |q$]xuB8ck/ba=zyw(cOi?$b :Bm;0BM\& sYOjQWg mJH 6gU^וS1-Ԇ[lYhHV>+$qc'8Kvлu9r"qzg4Z?EB%+uZcrw! VF !#YZC(yh0W9ߺք&;7|d.hEA4_L |@bmEm>Bh8sjc6 s4+LJ(gQ'/cUjh"^8Ź [_"o7!yRaE~h\'eϰL%"Bj2U<wl8 ]UzLdB4t76oRV̀~]jo,qU=]/ow6L{%{8CgdnBwjPT(M^,D,0)LQ\(s9ߑ ^S𻣢"IU&o"}+5֭bT F2ˬ`_P5<Ū첌-MWa>Y.'qTаwn*|T g[@EōC]̣p:G)L3:YO@žYteڽsAkGuSusJԇAK8=r\U<棁}"i$Ypd F >#޻W>Zc &*_h,{ D*p9,VKh|w: );@cpol6z cSUTX]CjO$wnjNa4)z`^o=7?̣E+oQ7ʘ=Nkd"RP`2ΆǨ}t<d9ދ NI<˾@.>w|MEE3 6ORGny+XWHQomΨ.t*.ew߫2A@/sp[bL[LB{ʠv HtM|ve7q v/vm"-ƾAqB.E {Y?$=Ayl'Aj×QQmK <>B[7hsh5.~tc:pdd,᪏.Eūe{[ew?1ʱޫN2_aZ<  d.%USK rQ= [E_5i-(gGxs Ƌk _>i ֛ ߆Q" *8;hT4&-|A2~5nAA#@I1Rli퐲(]hgc- 0w܂';9qXo Z4yH{zAr/˱5C!~q4w0O![' DFu\DR|Ôb ^=|Dj?DH'rYm!ܝ)I=uN3IBoJܽn`Fͭ=XXNQF3 :`lqdb2Xg>Iޚ%7C|ݙx2f{mpbOth۹rq7e+ʃToZJ X G.zl7 W-Ф-[sRͷpN`8;s6skR`ڼ@mMM6w}'Gps͞c 9GMrSaʫtV"*Fj<6f^s5IhuVq v0b"M jFyRKw)d:@iЎ&.v^ϛFDӻt;_!2Dwvϥ*^No5 0' & @RBqœ-QX`7}|y\Kq܌4a+UZq0]X|Üɯ=H~2﨧 ÿ$+ v>g{k4*vS{I)|N4Pπ\מȎ] [zm:ؔH2|HnY Qc漕b!~Zo^~_XN#0 g6zIjҷwisq$fRg]| io`@*]BTz͐Y<(YcpbJ5o:cVYI^=wg'yTs[o{HZQW0X6flxW{0rkaŹ_MD'^-0h:Z0(=CW6ҷ`1(2#&@XAјyN`wmGn"'O;T2Dg9T/:>'xH/;C\9aՐi za.@a&u# =mP*b[K/՟ X7;t1P'rz 0%ѓ×A>ۋ#9 "b>{b3N E w艉ܗ̼z J-,9JYgKgB 542NO =L3:1wH`x)eO]ҋk8?#mMԠT-^*j4]s ǯ]9TEۦegr|'B­i |Decf._GZĢ/" #H;Iّ'#f6ϊ7 vK%(]``U2 qq¶?ߟѮ6٨ B/<ΠT%ISsL}89^أ]J&SiW͟K .Y!̸k d7QQKl7o>=@H>W/s #ÀRq:L= AFsdi72.3> Gg@|2BmR# 9, ,}a^]+N2m]baFwj\[3>bdt\UqVIR7X4`.v@əWPl C+ 2,*A}H1[2fAgi`:q![ؒaP9ƹ y>P_a^Iwrks^B0ǐG -ن-\)\`ىk؇_sIj' ék{Лk̝jq^3Oqp]lX~ ϛ:ЯUٟ^9)+JV$Iת8og~3#wȉyHF,U"MGϞ.y(oۀl '`ѻfq[}e2t`ht)@y˯yuVY}ItaMH{-Gr:#˙yo}KvpLf#fBiP68G)da*'akiڅ(CUj2Tlk(ПbYuaJDe4L@t>m,(5~gf} I?!?\RBmz)~0n7G#>ȟ}iuFشŢs>$1NX@qvS愀O%$sΤlTέ{q,ZC [k i^A\Yɡ)~2펅%xۈd,OqĒ@aE%G[mU.% m% Y%Cy:vQW3s㰑wHa_ehDmT_S rh4lJyQ: c[!A]ŧȋmDo!nU[3 yY.PEk9^-Qu7/;Qx~+@7nuI$ๆБȚIa<8뫎6-f3D[⑕3//?1}HK.`WKJF)ř@qZo`]/ph˗Mai %h,bf[K7ᰒ{"%!qm^D ?܍D2Z f^9d l2} Cvv⯶N4&A#ftфkżj  mo\GuPMb TAlEdžRV``G=XHL-VZf5o ~<^l,YM`&L PyB;,3es Y'>dI0U q =$c @-ɡ:OJ1.1; gZ;gE7j,kq e@?kǠ@$3 "LYo NS;?,+^u1Dlp\zYdyOjuԱJKcv*Sc+Ou"ACV&Q`V}3] 6KV'؆/giW@]z K >O5^b5㲽՝a$ nklYNexq'OMnYTWiLdP[Ic < e{,pzL5LE^QԧX{1El6.9CXEBrm.zjc#vV [kEi!-'ϧ^iC,Bn05c9th9Њ7vui{eEFĻ.!_2t+! °*&ְ0zY69׶_HMwg_ɺT/#OEZW/S|f˺C/qGt8SY1Dh:ێl{MB@s;,5/?K%^@ UaU^x'!O:wR NBL =O<܅Wl1WWv${-k_ыX|ŢPT1WK,!]IRukyʏIA7f"!=:V:5`4M~ANXxpE#RmUqu%juU-$G0'Ϣ|vvS^a8f˄ӎǦ8JܓdP}ϸb8_\Fh/UZ\hxSHSvnR} XeQzm3f,,)y#TWvwٙSh3CxxBn X][¾]fXy:}u!-`_dd](`2<'SC.zz=62BY8A,ُ Њ{##s{ѐTE t2GR6UEɣ~O4;_uzq!VQ\Nu{ԃ-23oK_3DOB'gܯ%X³zmP<"$D`:X@.%~1w82߉[Zz7|.tl[rj8d\G?avr ӋDQ ݃lQ弭D"/pRVd%}i8,ÃN!n? zsI|ɨ12gDdoS5f 2l.# a5"np0C6 Jg)&ο@%E#jSk*T3R1B}UXbtWڄ,3{][Рݓ<_|cF/u?u_~P46m!Br$-}Ltxڂ(g z粗b1}Nܶ xVqixkZ| :NJoQl#$ F 580HF iPQK~ĥκ}OT$]W"eG[J{=jW/҈SGK`i/uڳsUq]`5o4iweQ릥/;XpVĦlgN؂FǕ7ʨ=#ˊ$SZRkoOCW% sD7E">}=ek~o ۠60>|28#O ZeaxCSN>SP5e9ʜ㿮ވ-lрM0c45_^0[1ZIʘ\r"sgI]K)sv~НنS ;i QBQ̓9gq@0cҀvlMNb6"8 ."jbLO34d$SQː+eҴL+Uy?(F5%94Ikw4!{YQIBCa ^SY,+Xg6\XHpI.Ep'Qu)xHbWFEO"*ArkttD3kA^V?8! V? Ic(pVD #JR{!MYo7[و"mt0Ĭ0t)am1) .BDCes@ҏWDo $7H{nm2J`˼ш噔I>Ju)*BT:wn0I]3<M?IK pkrnLXont#kaAh$`2_\7{:|4L^I"<ҩ?LyB9)B@gj$q!}{hӥ .Rwvۓ\CG)5?:^.#2`dج<=EE y,}Plף!b$k`(#9vE L84 n3&HIn dfT(oM)H[YX)JvG#$7ں}lH4YahS^՘QCL"{0qc BkTH|~:tLTܰJzpRrc!?(^-Їđ?sJg!0}SU5Y8pЀ|}ЋAfoe7M~ eᓱq+U ƀy<S7gZ[/v^U$%RYe pi I P2Pi>K7kk}Q74@ (x+4ìH 7C8x+jk/ '<e9PA<8)(I'bHy|˻y9B;g)|˂dt$߾v%B靛o`-sΗxۥ)Y5r]aVS֩n.|CYi9W΍v= Uޗ.5f=kU0x\Ԏpc"dn3!/P. eIWk+*[GULX(&) Ųt8/͛C <<䗸s)J9ˏ8ۧڞ:fuޛ2I' ߓѪ :)#Ki/B bE\=7/@tJ7ĸ R @J=VjX%LH?m/zTE"3TVI}&ؑA+FgP$RX0 gDdRKzQ2go#<3_m4?M,IGBðNPJ;MSXdӣ2BQ)ߡ3/Utfl7m7:&n6>tD()dn!QѪͼ}Kb_ `TI^CO+Vr_Q?x3$ktd ~U⤎sN= D[DS}xyŜ On.T<bSfAA/Ю(/0#MxO[oM8TL 3{ʂ} p_Lɚ(Tu=d'5V +foo&b̂,aJ(2S쥵5zil.W?s.HagDiI>6-ਸ̼eFYK/vFJ\kud"!hb%vn3}8ۖ352v&o^Mn$/' E˫VƧ6Zk@48 =#Ϣ}LC2E%ɈD5ymkT1z)tϡG3֜T==>rU"| QG! -.ygsc$Z,OTedEߩKERxgw8kO+}2l)#&ϵN"$P+X$ҙa>Y1 Dfc7[ن&H!ӽ |R8VhzFW RYhTJ.8$1fhܼ L Rf8#Z-~>=?#m/X*iBX¡9#q!:uudshr(!g"J;JHK?.;"G./*rF,ngؤ _;n17d\6"gڃM'L/  h B4KIKm=ڽtq-j*̉ :޳(; aCZnV Ǭd_k71Jdce$eLqVW@ʿ {tRa2dyש.3s~@_s'o.:dr:CH@"hgLm[=g0$-8RAU~ ^i/zT%>CB-Őӿ濸[:_ռy#w6,D#3p͡ʁHg]>-؁fU5|N&z.cws~k '7e:GE]h{aa^i5?'ϛZ]P9r5:+mtyYM#}/LmT^(uV+Jپo#If 2:?խU9%:!VK4媏ځ9NZ&kyguZTz4foV 0l9M!`8T6s0,kw8:8"(Qc,9WK=)Fe;C#AxnS3DW0YՔ%Y]k_'|Lr2՚+~\Hq+;D\\H+ԙSȅ)*^]Mμpc%2_1@=-5x.Y tukVW#\ cw+ #}iS9;/}Lt9:Tyt1lٖ, ygFToXIlTڕG>p-HO7Y'?1{WjgK׊ՃNK90O%(*<%H1J-NF ={4x˴`]_ ;.jB&oU~@H !q\h;u`8J 4bbHP9o&"VtVC}꤄ؒerIR^l_jq}4ܱ)+ZV^&fqj.IKо6+vcYf^w@}@Yhrglu"`kZhK~t{aTP;tH69s`eFOG> Dͮ6\6F$ʞ|192Hk#}Z{/)-jTOGd}LrYC[Q &Hg6K]rPnNohNR~F7]>GZ,F>]}0͜|>p5 MO6N2,=)p :^R 9/Z=iveUm EnjZ:-Ea?yϕ1s5(72;5zبё1GTL<ѲPWoV|,@8I_Zu_N7 0xEӜ^#k:zLt[`_+!=Jĥa¹&oQZJ(c,PZ\xQ۸Z)4,6S0Bs9?a{ +5hbHcΣP5 ,tc6Fq7OPuQmEt$ XevnBhxzeL;F%cc%0g+ew/e3ZDؓ7ys,j-QMl]Eru, Nŏ|2?[s}mܒ"vƐ5_@H7sړ0`F\|PȷR_eZrONܶo[K\c ;,vK.~-!a3n rE7΃#.V~-+3yiu @Zq6_+%~ IWNS8bWҜW@Ǽ i5 @/zի2Ga ܹsת˃zeX໢6XI&5s6Ý‚e.U(#5?ix!G~|<:bdkH8ͅ>20͉# HF0<0Tgԁb # |RϡrEYx|Ʉgya:&cx6jrW~)f}YVۀz>Eȹ# J?ѩ~xƴ{Me__ϼ;Q8Lmm@hCVLDx-4y&DWkXӇܤ-$Іbq܇h~4@Ur{SJ0VooFCmG~0=\3-,%fqgIQ?A-6PYSIŐ|f&!XJkf\Ipc'[s{@%H[n~dwH3&W8*uM%r4}~H/ %"(7Rj SBX"PSG:Gc?ˣk`M]ѥc|Si4T P~Qzom/Hi$G漝F h#1M\[2Û;}&Lj}Tҧ)~Z/[_[u MÈb ́%/ I\ Oo pW!l VT [oG.AV , MRT1DLW|k7 ;sPx^ۓ%1x%:—d_JWME({} UU@|@`<ݍ ¶5^E|v@K;T_OIKf 9 58wD +A>:{EST 1K4W]СW ejGqVޗik :y(e+[=5lڊ3&kKD$)c$ơVd"$ܽ/PO:k͗$50%%/8dQD&D#5hP|尙VNw_<EBWJVKiC6roga&uq e f)Wuxq"M$/w}h$HEt%pX~bG/l\P e j8.{keOJPX[C1 fF"ܩʻ{met_  (Ѧ0qfp5o~9&|I5dj3EKƢ5Or=t<EksU<:VWNb;!Kq#ꬵ-zc%Xz"fR`;!gӀcPhb MkKVbxL9[9 jĤ䙮o#Em;v".L6TP&Ɂ ) RF9ųAkBlN3+{k L" <_4+{zwKCz =츢ZExA: bxL6RBfkr^6kG;# _クeIT͹x2GvErXb|Y- k/irG/1̏&Gi"Pyfn~ m:uhJ"%%>] 1hYܘ|{r U JƖiҶ@Dg3h閴PEJIv鷱X?O\"(.)m]է@ :6RܜLNwlAq0=7R&a)".Ie8|XK:WIHa= 2&t3]=j#NVwzȆXozy lp|9ɲN ::|OvTRhA#ʕcS%ni~P$?{% Nд+I4|go$j2/Ħ2q$abYԯ3 ..VOf9W;t2'Jm- //7nR,F7#orZ(=d¦^LhR|?Ԣ}@nfή{U]`Ìy5iz&VY_ű*r~>ƷhN~MsX$XGl2--0NTZWMPM |!+IR wWf@k7ЌUAo~,rXZĔ4T {Ew2`3a.qf9Cč/cxvM fak(fHw9'Nh %eRMcbEQXA&cܐ; Ɍ8NZa`i%j-{?'6DEL?fW6WUHB%{棰 F6d-vyW*޽<9*z=t bvI,n-a ="Oi]O);/-)+q׮ ĴCAtPdsָ㎨< I^i*e]}NK)u!|?MQ}^Ϲ}7o/W_G[.[J~,AU@ .eyEf eZ x^ye vxnϯcd|ufW?B{;_QFv\u7[wWݘ/Mۡt d^›8$+&u`t']2I%bS~ o``ILXΥ%RRjafαʎM(9l#]us$s',"ƵYyWD|aq{%;u&$v7f2-Y b8ݬ(Gk"ZT[1,6xʢ9WGG6臔I]&z*6i$kri='@"{%Uܴ BBOMT7pY!Bv#OH&'3ԭns nEi[O>ĂhHSA|qZUͫ fY.OwnEbj2ZKB_!cU``^WȠ@~1)3S >Z}o*7Y^:i+t̼>k{/ ;KXc`!u DK>=x=v3>v?oKl+p:G;q$0vmֻM5.]7RŨx^[ߟG2 RペX* #nI&˻.Y< #YLTnց^r}"UUZ;j鼑u|֥Ӛ,mލlpGsx ɼscaBm/)3k@8ݦ!M)*XxYrIxC}wߋe.N2S~H\EW@LۿF^ ϵǂ a˂~g$J6 Vp+cPA@Xz>n>`7EB@pPٗND[Ih +A=Qpֆru0-%(Xv 3Sǃq556nkҬYQxKe\֓.1ƠL^[ VrFi~d:lq'oHڵ8Q*J/}59F_b,ҫǷ(69ʽ jL;l*ӇQ"ÌtU  b#R二;PMqK1 :&sȸplViLK "Smx/9%WnCkS0}otYw[#.հL fԂE33d˃Yt?ݒV^dPR5 i5p!?z4&?!}}z}YgPu` xN;]5nBX $׊H{OڝJݪfBɨ3J7ʨ,s sv73N"j4P`|jPN]'O*t;GQ?nz3)3hs'ġ].>ff*+cֹweGH( L[/QS/٬`=RA٫]Gg{oc4֎n]FhjLAK;V>wk0-)DAQy]%y2w8Y{ wg)ujwNKѐW@3Om|$V3zBYEW[S"}J/gz{D}¤@XP@ң[rNg z5L~̌Ʒp&9qt?~$>VlOV|ja/!m܀g8ۦ{uWޠ;[>A8Cxɯn_SBT! b'g> ;<D6Pi0W CqaT!6ճY^>n5!3m r? Ruh-BЧg5h?JD@סGOwf79a۫)D6 _5}.|L;%Oj\~}VrKC/mZ)MReiKv kR[cEʌnL? H"QzgyہY1RF@:GNi,AKM;nHo1m%ޏae(uP3q:]WVϒz'9IIx(9:.gP^t+F!o|cm; \Y(B9C{]*zK{ eaPFw2qUۆq7g"߭t7`b6v,aN#$_w&؅| ,.BewLDn}<3*MP}#vQ(lͧ~<$8[) ҙƢPz/-`7C^z<&xro蛷x2v N(8sIѽ#RqZW,KSD'YϘZ\"2C0@+ηx2w1_Gkh81''DbTܚ:5f9#(j,[ ]Wv!⻰MZZW_rfY61K1B*ާ7bDB6I{,}՛;/dCzY}o~@~{i,8?>ON2V[>]2mϡVJ焭=-y%%݃jprUiƩ6`a$)=N+pxHyy2U5ft=Ts#WoUm}n+k=^u/ zq$#;qЃטTfaSn@;A5z|2hcf|ƀ'Z: V=@ 7+hˋ5UD1F8X<@ b.>jb(FW'k=D2oXEɀC~:'Tk %G D7_R.:"Dhw~#Gys&t1I@!a[KFwKV5 y_`GaE| {\1Tt.)嚱jQ[C#LI&q J*F8׹ {xNZb4SG^ VFk88X_0+N0v]|lݯq=4v:j4o5W} ~R_%BP)#T{P"]ftx%4?gGâ&^Nsw>p* 8!16"HZ /[bϮY!!i/y)i NDv%h%lY t&aM݈6!%ʙi{rVOxrٖkRz{DK"{@HNBIme%8ϡ&5B- /&Ծ$?V4XΕ6ȧez!գ֗^H* "%{?(Qx^POk_I=+bfșatJ2;9xH Җ}޲"&—V.xOp6\4{p EEwM0/Rf>_P`+ZWVSzD#/16Y. !U kBGBnxcXϦD6 jYy~\ Z.CB@#%-iBCXf[kv-_ >O] A($g䳈&{;a QK#c/e>`bqge  |tOVQؠkCoӚofqGOS'E)ܹo]_(1 O ʓZsD:VvrQhQ9Nt oM:\nb5 h}S{"* uЬScFwA":]0x "( Ȃn,{ZUrXGDUƏjTV:{[LHTg}ӎe#SKU[c] Q) ߕyi\}:ۢ3!rvUSK |)!!˒&]惟b5`̴vg|cP s( =y9ތe P+rRwjcblNĵ!,ZwYM*D$eͣbv+VoԀ' W ʹ%>i@~9OmM5@ QmA:Ln̼G[}FnwOÀg8h u2]7y Ga4k< &q>3|/HM6N,e$V U ^@{c6תA|Sul$r)\JbX%cbK:q5"Lu uT'GLt fّzfX\ ;/h+ |8Ȉ:o>;]3`p\i'P*5auM-sbW<gbxc@j- Wo [\W9%۰RYUiQ&w촆#NB̈́VsWGu 6:մrM=6H;̃ϳ:.(JB.&"{@Ǥ=LwJ=a4swȞfZ)mg"_0Hnj9qe]$:YO~4@b;Sók)CDzdž+x~0kULm UK;lLl=H\Jeoh avK$lEϴg&"ެFlP\I -䜽Q 3.ſ欮e1OF0 ڤXZ7òxYp65š~zwG;!%ٿ|a回ڱ6.]wy4sk/Σ:Ӄ ޠZ&[44]^E_0|'{Q0lFv7J1-XX i31ÂTn$1rg *v Ig삧rL4VۓA3Kb+#"Zp5:aSJ/'q1uLHVf5>siׇ껍} 3'V6'V,Cx* 0f -pBJ&n,(o/$dZЄ2 ~ծXrL髧g9&:3Xšʗ?L稱8y vniɹ~]d͘U"Ix(Y: TG갷Wnr,)jI&pԼ Wf^(.L>'&Atsr؄R3ʁY6ΆmD/͏= 1*( b3~2xGR+$ hHܶŏ{XiI*{^LT^Ϣ2FS)cOQ[y;F0KG 5X긞mٟYt0;p-:375 IAH6&+g/N -Oh-wL+Ci4PH489B1Kъdpg<7Jp|A@.WpOÞPE_mG"&MkC'_Yg#?۰gAODǛ!Vn+ ~2,OFPmg8XP/pVGh QxnC)n/$En!s%=:LXR =jqͣtTOs2Ja؟p{̓WjIG>=r= >lX|mo;˫c(4$Ơ_T5k%Δ`ikg_5@RP 5qBH}8D]yS̜X)tc޹!l4Y?&J =l ylm"zT;lF\cZrM;v-QNA鞬r;<>v:#OvOo{ 4næE%2 Bv)z[;3/oZXѩSGnduzY.\2;c^d:G@٢qƜ' p@>"jퟋ@Qٗ/ _d0bkZPPGM|/{OT(t إ74Au8ZhZP %N.룄]$`PjZ)iiU\g<*כu_gd|,#-3&#CUTsJ9%p^%ʈԬ31g,bT<֯t9qKU&\q ڨ3 S~Pw3TTq]Otvj\E{2?1lع =[f~w:@\l\3DYr7? ͯĜSjzdhݴ P Z.( &zq~lƔd4,F\'p.C9| 7#û<[BԦD{E1rXc:ÝF;d{G 1T&U22OS|2" $8d2mG 몇e+M} Y_o_ϳGo-'%\ô-EY 9ٿ͐ ӧL"oH]1=o/nj\srlvTaB+' Q!%K7']_)m" hO4eA=Ͱ$I'QqD,ez2-;QCa_A7ǯ "%hЍh sUI\`tBr| fj^a= G.Ԓ5j@H`t:RFekln*4 ;EC҃ڣ9!X=A/鷧'*^"|^Ԙ2"Y@lfTN¦K\7jTv%[t^HvJ|9RxL%mBN-!2LX[nLVK7"NƽOjmPg7sRߡ.kƵjD0¡_\Rg3Сȥv;;& UG83)sN) :o.jPSIsƄ u5럠+lʤzfVĦYf>Q`j9-հMA#wy}[b!'q `lӶ+cU{1bm%|H|2#R#+*QOJ<7p4NZx!O,y V`:Խ7~hͫزQh =p FxG޹ӭ6'h>h=C*pC#-[g>H^N_UE`. 2R7cސqoZ̿#Ӧ_ӚdaV c"X{f5lI{)8 ZSs)ed X՜Q49Vt;Vr8Aknݨ!DŇB02[q]F,5Y<ɼC r8jg$@ UX#q8ZjGw2ܴHd`8`F0"·$X=Jiɽ;`&HC}Aacp:pX.앖1Þt=mcAa"#uESÕ[$0 Ry1h#DuuHBe"S' ?lL'/(p$0 ׄNqZKrrO W6𘶸Ŀ;Q|J)Q'I)&mĔo1 XZA#\DŠ%b y(z t $ NB`;h-QȂO>ėj\V !SjپӟكeO:NGl&0yCXDɳmbQDzA‚l=(2>`Rd""692̑x§²:ƗjWHv8 $CJ8-؜>#>Fv x m1L`ayp+ȇ/RJe51dпѢ O/U2D`xm4f@1g*NbYC*]0=4grW;]pۇֆŴsO:婒]G4udByMfJ $Ov YZ