sssd-ad-debuginfo-2.9.4-5.el8_10.1 > 6 6_6 3!pQp)Tξ7]mtZ`ga! ]mtZ` 8Z19s#-0xתG%@?{䇝0~neuZo2J{! , 5?e{2fjwHBӄ[_n I]xkc-k%@[&.Q-U@FReF;🩌$͔,(BR^y?nϳUQUX 9EڥyAs GzjnF.&SF<7J~|6$P"r588e594a05fd03fc8aa4834373af740d54998d32d06bde3919d73b367c527b4169816e329f7d49dfb15d27b0f688986d13f0fb26bD3!pQp)Tξ7]mtZ`ga" ]mtZ`U9) f.LʹJ[^CӃ,r4!L?.O(v@K{7Ij_aH^Φ+M MdBnQ7!^Z|nLتvUiz6.2S%J=Cf-跕ȕY'iQ3Gs/Ė21@ڲRe5<,c T˩Px[!mȻf][o|Yˢhk6wb ]S,Ya 4WPk%ι&%eD*o9_hO`yr{BRQzeSi=W ־׾?QTlh<:QM:#I=(^_)iU$CrgtiLJ&.!YLmfIQݘΰWr4Nn5uQK{A $#K1gjs_|i)xgO'jd[ k c1= pd~y4 >p>? # I,05;B `r   P   H8(G8P9 0:a^GHIX(Y8\]^ bd}efltuvwxy5HLRsssd-ad-debuginfo2.9.45.el8_10.1Debug information for package sssd-adThis package provides debug information for package sssd-ad. Debug information is useful when developing applications that use this package or when debugging this package.gaeord1-prod-x86build002.svc.aws.rockylinux.org PKojiRockyGPLv3+infrastructure@rockylinux.orgDevelopment/Debughttps://github.com/SSSD/sssdlinuxi686<S<RwAAAAAAA큤AA큤ga[gabgabgabgabgabgabgabga/ga0ga0ga0ga/ga0ga02b361eed68dbfd8f3a8998960c7aa2b70c3ffcf8da62229be02da7e8cebf8a8d1b4c458e8e65d5856e0065709292bb4a7daafc31006cc52ab8545b365d2c0e51../../../.build-id/d0/74e75b03499ba6d2f07c024a357510dd9b8df9../../../../../usr/lib/debug/usr/libexec/sssd/gpo_child-2.9.4-5.el8_10.1.i386.debug../../../.build-id/e4/b2f0673936da3b9a769181b617dc73b2e97cbd../../../../../usr/lib/debug/usr/lib/sssd/libsss_ad.so-2.9.4-5.el8_10.1.i386.debugrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.4-5.el8_10.1.src.rpmdebuginfo(build-id)debuginfo(build-id)sssd-ad-debuginfosssd-ad-debuginfo(x86-32)    rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sssd-debuginfo(x86-32)3.0.4-14.6.0-14.0-15.2-12.9.4-5.el8_10.14.14.3g@r@f@fGFf! @e@e{@eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.4-5.1Anuar Beisembayev - 2.9.4-5Arun Bansal - 2.9.4-4Alexey Tikhonov - 2.9.4-3Alexey Tikhonov - 2.9.4-2Alexey Tikhonov - 2.9.4-1Alexey Tikhonov - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-67671 - Label DP_OPT_DYNDNS_REFRESH_OFFSET has no corresponding option [rhel-8.10.z] - Resolves: RHEL-68507 - sssd backend process segfaults when krb5.conf is invalid [rhel-8.10.z] - Resolves: RHEL-66267 - SSSD needs an option to indicate if the LDAP server can run the exop with an anonymous bind or not [rhel-8.10.z] - Resolves: RHEL-67128 - Excessive "Domain not found' messages logged to sssd_nss & sssd_be in multidomain AD forest [rhel-8.10.z] - Resolves: RHEL-66272 - sssd is skipping GPO evaluation with auto_private_groups [rhel-8.10.z] - Resolves: RHEL-66277 - possible regression of rhbz#2196521 [rhel-8.10.z]- Resolves: RHEL-39085 - [RfE] SSSD Failover Enhancements- Resolves: RHEL-33957 - ad: refresh root domain when read directly- Resolves: RHEL-27205 - Race condition during authorization leads to GPO policies functioning inconsistently- Resolves: RHEL-25064 - AD users are unable to log in due to case sensitivity of user because the domain is found as an alias to the email address. [rhel-8] - Resolves: RHEL-25066 - gdm smartcard login fails with sssd-2.9.3 in case of multiple identities [rhel-8] - Resolves: RHEL-25065 - ssh pubkey stored in ldap/AD no longer works to authenticate via sssd [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-1680 - auto_private_groups does not create cache in IPA server SSSD cache - Resolves: RHEL-10092 - logfile rotation for sssd_kcm not working properly, sssd_kcm never receives a 'kill -HUP' - Resolves: RHEL-17495 - New sssd.conf seems not to be backwards compatible (wrt SmartCard auth of local users using 'files provider') - Resolves: RHEL-18431 - Excessive logging to sssd_nss and sssd_be in multi-domain AD forest - Resolves: RHEL-5033 - Incorrect IdM product name in man sssd.conf - Resolves: RHEL-15368 - SSSD GPO lacks group resolution on hosts [rhel-8] - Resolves: RHEL-10721 - very bad performance when requesting service tickets - Resolves: RHEL-19011 - Invalid handling groups from child domain - Resolves: RHEL-19949 - latest sssd breaks logging in via XDMCP for LDAP/Kerberos users [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) d074e75b03499ba6d2f07c024a357510dd9b8df9e4b2f0673936da3b9a769181b617dc73b2e97cbd2.9.4-5.el8_10.12.9.4-5.el8_10.1 debug.build-idd074e75b03499ba6d2f07c024a357510dd9b8df974e75b03499ba6d2f07c024a357510dd9b8df9.debuge4b2f0673936da3b9a769181b617dc73b2e97cbdb2f0673936da3b9a769181b617dc73b2e97cbd.debugusrlibsssdlibsss_ad.so-2.9.4-5.el8_10.1.i386.debuglibexecsssdgpo_child-2.9.4-5.el8_10.1.i386.debug/usr/lib//usr/lib/debug//usr/lib/debug/.build-id//usr/lib/debug/.build-id/d0//usr/lib/debug/.build-id/e4//usr/lib/debug/usr//usr/lib/debug/usr/lib//usr/lib/debug/usr/lib/sssd//usr/lib/debug/usr/libexec//usr/lib/debug/usr/libexec/sssd/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m32 -march=x86-64 -mtune=generic -mfpmath=sse -mstackrealign -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2i686-redhat-linux-gnudirectoryELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=e4b2f0673936da3b9a769181b617dc73b2e97cbd, with debug_info, not strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, interpreter \004, for GNU/Linux 3.2.0, BuildID[sha1]=d074e75b03499ba6d2f07c024a357510dd9b8df9, with debug_info, not strippedPPsssd-debugsource(x86-32)2.9.4-5.el8_10.1utf-8121012a21aa0fda4b4c2789b7b92a0a2fc56669225c2953e8b3b869fa100b639? 7zXZ !#,{] b2u jӫ`(y1;xXُHtQP {pF;x*Dٷ "߀]^ !-JTD|%`ký4NM=y10 ep'MpGB=6Z$iTu8ݲbiFycpF4m0ZUZŪ^cb/u._;<^#}^Q(S;S{ͫFϝ%y`Pz'^YJg,GIkqȸtJc:qb%ct?te4q1GUq_6n`f ]86,3 i‘}Z,h"qR.Ylu+rF |k=33;Q@|L-u !ET/9)ۘ[JYjc52ڦ QhweH&( o HsN u~YY̰ֈS~YHCH_YD O  "i4wukRQ0\>+($pya/xy61G~ &ݭ a2h!J ]<Xؿ/ٛ+kP$ysu:e8a0{U=:s}Mv}DA/lF̾0t:"S!xl\2MRWqzjNIL$oXMU q9)ClzSvi_U'9V)!LCt#TqҞa ,T8$@Xcy#@љE1," :2?N_sw$8L/=zh|  OE<9.XPgl%ܯrP?^\TĞUT }@كԨ 5E[)~{ QMhnzUb0X .e­u~Z혔mWT90}N>j_I:QQ;?PUOI5JٺGuXSx\+l{8W_n+"GnPdz5g_!^-gSɋMO!>+,w,6jOprJǎ [xF  aU)%B?LKg։t^ ;qz`>RE7ƫL*hRx4Ugs])]9dm#}( L+$8NQE{U *w0S}~D/$kcEOP+F3(K<'pmXյ (އ0YX[רr#'t6V1XfG`i{"6yu9tL@nf=8%gIWTn PR!liaDod@PA!-Y4_:(:'=5!/φz,QQq97ʻ:A9P*MGq䬐DzJ.>9ʤLq2xPrA,Ԑb>]yS Z(qWm5o *:JpR\&^GlNiНRZ]8Yhx6/X?h3Ϋ5s&w?&'UbJlWdrf90[>ϖ}薝*ύ&pbz=(/5E^"gTw<8'Ł!V^?uÏ)o'@0fk6>3szH4e- ;D菜lecIf_S94"z0ŏͩL;9wry9coOb:qKVTp .Jl.C1n$?pD Nyr^TNF\?tD~l!4 T qlRg9ek O= XG|wi+?~vK!ԟ7̒YLTfj߀VjK>11]ܘwGk-a*ڳ Q":Gv7࠺LnxAzg. mx!lkk3\ENqYMFfTAɆ~!q3"._RE3R^ "j,FJ8EBly /N9 wt)oӰXRh%ɵ7s4 wf4s2[<7X)DUnd4u}R&n+e<zq^Pӯaz.gU}]- \=T;L81Rnn1pK*Aqoj5t9n;vtlzP쀳}l,"=kKQz tj=E.57%Yjp u‚? tµ%uGNٯQk!Iw)Is.K{iUN+W 9い߸[<9džFC,eXI)| e5䟙-#ڻe;T羉1q<ۑ6="3yP՜Cq [o{8HH&۹"= >:UXh1t/^"`w7= Xژ]]$F:$ÚTԘYM' ƣMd"µG%'=8ݘѕAwӧupSjBѺUN 27ƣmRl jc}~{F8½*(C':[TD쑌1&ҸF{@"(#qg/_2MYE/-x69]ٯ%I9ʱvi g+uNkQJbsOJRt)y!qsGn]s(Ve5̍*Ths=者R`bVm4Yzآmtᝪmdm} 2|2N n U{A(*b| gH8!"KzM-GW2IldQ S!KtK\B̛QWܙDДϯ|&0'jŬތLTҨH}'bZB! N?2: T-4+>*Q% 9--v>]p{:.Wxe=mOk6\ƟJD)AWEb 5`U\J5HdqX~UrvEIБܟ $[vZ& u貎/7 *>\;<'4B,YmA e|BTv+I($=!HLڨ3tCN8|ԓ?m!)DI6 .ǷJd{d~ӻ fr\ڬј׌?ƫd ;RUO'IO* 5GvU'i !tCzqx?5RөU]ݨBzKV,lVI@4FY8OqU2V/ѭpO)*&%Ԯ>}efXNWJ*oʍ̺0IX;ggVrW!` h!cվtF*r#'_YWߩ:\*(\i9V~4r:bzmڞJEHe  aڊľ,oқ^m'atf:v \\or3#w-%^h$/{9oZi,6W#y8PAժkӫi# I[h;ʖfVEĻ\FvdqJmFg.zVD^GKK.20[4\Ay_h@̦NvC*YPI4M"Ч Z:ι],9 n[}4OߗlRf0 ~ͦ7hS,8dll50 U[Q6F⨿H yk&EoDlCX5Sӹ$3鰤Ӎ'T`A u`^Sks~^s !w3oMSC;Һ;89m)Q^$h"/{iᨅ׺x"ӭ:%A`_}\Uc)J:,8##ŚWMJݹJ8^w.$F 8)K?Ho %1£ـ^Q6 60H|棶i??-Om @BW۶cB\`#ĦB!]!\-ГëqDLX]~KܒJo\* M0=\R]*&>`y霎\@p?uUp~}촥31-Vp!tQeePݮîr-/'\gHYfu^E^Vw+FXi%#L*952mE|i=FԮ&"L$IV}ݱY(1lndgnՆ,ˡ[zu\"$=%vr}db+roT$i~_AӌR,Aú 0SIka4 8 $E=^9ۘ)(7\L=L`'a!M~aҜE&U&o0s\; | , ǴSyw,3dP\ck#&#/aO FbpOmEj %DQjHC>i7?bwJ[`/N%%aAX(lDCMK Kl` - 64Blި¶4e҆k=7a͂3grH j9e>-w?tSj`1R%=RPe6~ @ʊKFm!qQVI^HlyꉝWX6y!ifVlE[[}ŵ`Y!AAcɅ}p7XBVT,7+-Ο{JZ=6_v.r`Z6wB߉Tmd< ,Xi񀆰.Gu3Eq@%q ̀? (!BHyX V'`rbk>gg1nȯ#񍪰9#0P+JTYˀNIY®c2'9N'xsy~O ::o5A0ZkEXbQ[uM H lw-dOMZu|qڿN[3%ϨB̷=:7lM_AB oZ^Pd^{;wB QnG[\ nw?cەY{Jme}.P[ K(@c;j Ms uҬq IWGbk>sMIel50t>/֡3׫ _BąLIyEט5k:m5D=ɂFr 8!V*)K{K0N\pG}ϙ1G@}9L__RUH,\-(N\@7obD}[M肋([}IشTH}U֡JQ{b'wXnTlP9!uBb]Gj7Tsh>,;HŌۻo=b(|_ NEz>kAu|T rHf0g\M<{ Q-8HrїS/}\R\xjWB IX\wZaq:HX+v67&i9X#XoS#Fd F*FiPBm=/x6)vS=>$@ ) %vhj}OfFBk*ۘ\ܳNv m[9;Z̍7[y>T{AJ1)[B[Cv;687SӼ]5P{d"~{:c+t*pS~tٗWYU;SP%,: x42?reaYseA @Ce) WLsCRIv'%{"{E#<7, ?*T44-HOXvȮ?ʲۛh_ 8,.,12m# h\Hc3czV"9[%FO&O#ycjCޜXï Diיg/m(F{Id5w]R.n U$6\4" ,~kbDWha)h*m 6fCE$$k{k_uQ#k^XmB):⎝\Ji9[A;jߎ3W0`rV~,԰lv[:%vW7bP,8] zhM#)2'9Z"MlBG=WJ ݲ>814ϩ[B+ġ_Kw!/<ՈwI ˬ܉˛v[ 'M,%.Fd퐠Xy;Bw l3% e#Y~\@:ˋ惖O5|I!dZ_n 8 ʚƭ0!2un;+0.qIApbw3XEŹwn5 ]ڞ&"pQ0pŚa}SwhNuYdg'hsp*DA %x6nZ_(T`Jbe0"Cuecľ\? Ӂҙ@\rxý(͐BapzJv#H>`Ko#VSzS^P}o\0csWS-gqe2;f&$[nH=xMɏ$yŦBN8x_~ y3v/%}6}(3s"5~(eMvpW%Qn+:+թRf)[2JgEqhic./IDmwMTs3e'v_/SBQDz%5 XyNaR7Gf-T9)Na# 1Fp~7Ql. ,ESVoZ,Ϫj$۷R".ڋtҨ6?@s=wz %esK`5)|k fo%h荣ہ ex(cE݁x_j%Q_Ԛy "ci0aU;ye|^i zc]}aqB|\&Ή=*t "ƾf0D14dd+T&[\ck( !VIϚ<*fEyb-}Ee/zu9f{P5sq@> O-Z5 C7i/Y J"{H?K^xJ"ˑȩV"U 2hhN!R)0n!gbA,:D"W a/pDFiTϤ;yNLfE%T\tz$(>XrC&;Zoh3:ET 0)ITG[bƅ%ٓ[ y&؃Tg@+ Qt30I$&{ @Pj˭'Լ"}e^'g>Q.G}TYK%NbYEYdXZh ,1Z2:\.Ȑ1..OvIiGwFtcxHTIAt>#zך 5 h?NTSaR_]{<:mmYED8ԴgOW8e",`Wl ExWоDBg~fme](zE[&x`‚jBOXoċ[?-ɷ7"oqt'7w`?]e1[մb Q(zyX=}*24:L O_l/@&6W>O4@uKg|dH)^":n`mIC.|^6M,Ud~BI$~\N47΂fbnWr Fx=|˜i¤gS#ysA>",aoիkhнTw@1.O@Alv H -Y*hP6 ;FsgPmqΉ>y&]8oH賭7ϸj#(h_8wdI<ӎ 2si%P.:M"$$\a|PVf2%}*ϟ穫/|xlG'}-sO3ɇ1g츉vg`脒< K>g^sBhQAO)up`-H+x#%J8[=q|[T~B&Hp0aa\o8^x@vğs{k͕ u+v p:Dcic֎V: їH*85;ԫ0+rAv|Vo` A#-vwH SKat-EӴԵ\R-Πd_f8v"fgH6ѫAu\`0ut{TCe>9czNĿs- _H AgMM`BDj8N 7Y1z4?l _f7#[^. LjQ|xemC@Sۛ#Ӻp9S`ĚH y!s)xC_P^z/oΜu/*e bܰ)s:'&Ca7ZھK`եuDq,ϴ"S>^ No^la(c(*EIzF9c,O $(`_:qwhثJG*[:knrC~@h.Gٸ G!$f(4BXz}ވcg^dO_[d W fEM َ >nKyE f)uk~=s.2Ϗ}ѲM;T'4p}tGF!^7 ULc/CK ہ E䒲8.]5m*6KP̠J1U|z >z.TJΈ9_g fI5! N%!P9yY vox cl;! `fj1-{yhY  x^(BeFC1X`#Ag=6Yi,}~Wr%2>n(W5lu j"ؗ }Z~si;XU/[c^8c늱8 _:S ţGhE+,D !c:Hs%${C<g 5R`ۗ ld%X`:0mAς?MՇqO3 8Ƒ}c=Qؗ7Wg4,{'E=:pG)q'Z:.֢/އ+vIOuçKGth߭{SC`_'bYqF *ЊP%M8o~7=> Q?ћ76*v?Pכw{Tpq BL,b JTgEP1m Qbĉ1R\@pn("҄Ћ6ƝبZ`/50IPgyEF 1@QlhNJsG_t:c g g ?<kcqad'k. E'K+2F JP BClye^ ^V7 G5dvCN;qҠa[ -).ZQOo73!;뼝 i@,=tK颔e6'v1Q@ó8#aU'ua&KxO,"O?W՝glm~"6C3liG\Jg[ 0e3/m/_h nMR4$^2%so `yf Lo Br̫~4 cc E;Yw0IUV?m~ci&-"VNzQԦ Jy#˱P';Y%IA=՛Jպ/['>:ø [?Eu@&kh^d%3̈.dRr)LhaWި ~ )\gqiTy07nli1AQ|cmsWq n-1punUMLmz̓N5w8>PQY`[ 772F7&q8~\3˧k]Yn7TÞ= KZG/tzFVRA%1kbl櫍&;q#ea -v vۢPkԱbCOfZ{5lr-R U]?o$cRwP.oLy#p#(F`C0}&H)Xe R5vzǽHaMə3Pbo-(vL Jl#}IaFDc]zy7ip2P2ͣ|'P N:)@xpXiRǨt yp.r,1_mN@;|U :Xa b .sP-vFa)T}WX{Ѻ aЬ s2_ !9:n+@6}V\1UAivvQ 151&uuGO3h[ڪr5 K@7.u27,CW|sD҅}fV'YmZzO WFmՀW v8j栶*lx,:U{=&K g[fmRq_fOWdCGǗχ?:1&vGs`8:w/2Y ѡSsu|cېGZ A#啿G*?gQ4*FI\W Kp4wvMDS,@LE~sFM谙$\-2۔4f >"| C ܜsHxg/s見5Ť2H sLuKFSjjy9.Ae t?8yƜ%9PI. >ַ ½T9RBG~|kMAꮁա6bQ lDf  *vc?5DXBV{#y;S?J"O~xKf7Zp { 3ɩe~Z1&lAr$۩2܎MTPL'XP>A$݈9qE :} ZTx0CC҃KYG#M`)srNw-Pƽ˓$׈F!qkFk\Ds3f[c1vTcåD< aVpv` >PQJ"2p{?G R< >eBf.^L=_]%M#p{ VW&Mb4Lts X#gx=2nwf}i=t^yiIc-'=sC%G\` ]QAoo07Zu=9 bte栒ѭg3 ĥIAXv\SvJ`t[QǐܾV:u%fiNFvX]o[KuFo>CL'B+3;սi^>-]o[5zS|aK0 &pT@].%c'#౗Z!xK~8U0J#!˓o-I( ث֜Z+>O2󕍥%P{'$퓜9_>`E`Mr,)>oѕdRuL)FnLGQG6| bC~@* J9%Sʑohd[vn /BIŜ%g(+"8&v-wEqLe!F_Q8z:ͩ]|r ;hYyzli/8r͢QupFbM: %g,'xwe1o :b:Zvŋsr+HC%cL̒0O M'Tw<Y ^Xtxw `+cIq 3.ji] eQ2KN (M<37)1OeR{%)rJJbF!lcmKܐpAD\-쑞bP_PvIK2J3٤kW͵N,!ZZWuM[p=s(xs10Ɏ ?0]Yd)! $c ӽq7m&sQW&^iXA;7[ |8zvÞE^*K7˖wWt*6᳡brJlUsL*=vGJΥ=G-gC9М4je7bGE?FD+G }*!3\9tNa_oEZh3RG-?yR59&e%Ŗ ka2R9ψ")~EED5S Gg8Ɠr=tTO He䜲5rIB% xP熇E~o0@{%ټ_}X*WSSN%g4q]9s{5wOTÍrWMGYZBm̞P[aI׎@ϠzԾ[%u6kmdwBOr1&]C[Pe1ғbuk0`p])Y3|r} $1O8M;@JXvB#4$0':60Cs3*&5:1`VwYz%W@|"x)-q|?go٥7ڤP*%&زΫ3Iix_@ wSe5DxGhjן8)&~%B i7Ԛs7:qMaQ(wRPf*Qi^Fs+Y-4Cc7/HN,_tbnfϑ 8QQ6E({TqZ)0ky¾"hXM%׆EWކ%E}B$ؓ2v TÞ+ {~W>\o]+J 5OZ1#q|5׹voͽdAmMJ!"]Ȋ T^OM)]ȂrТ ScD\3,2YCk#tl0$㵗(_72v1|Q~DϐҸת߸TTuR;ɞϦBZ:*q-wH- B|!y<4AfkVz#A$W(eÑg{lM_r(^ TUܟ p1ۊ= e.(; M<.~*<8z\jԱl}ݝu4`yO+S.^XG&ccETQ =66gk&?$Zѭ}q. %O5CN.d5"ڽו'z`E(kCh>i`p{iQ}XT(ݞΖX[׽jVQ`,5Vv2nu5|g61y*[tܤgMIGS4H?qHO .CO02On,fS*gzәb䣕6hf9% 'W5 UxUIg!;W%d;J|E Z<< |raIb ]+ e1|ZˎCRlT ; |&/ N0 ^~ۿx *xbȳ4f*_n2 4d.92!S[Xz,p9y#zXuƒq_ `Н𑡘нb ^rLDcQӗZ@$^ a`S<_\6=BRRM1#њ80J8,̝b_me gܹ+`A0Jkmoqة; |[f{E9zIÐ,d8Ve7L`!Ra1I}rLn{۱ Mȅ5D|̙&gk:~8mRNBeѥhҦC6v*s\,nNFxŇ++V2W~?WCC&ZVe`*`΀$ ka6혩7݈'|T`d/Կk91/d8T٢^[Iccq ^LRyԺ2&=`ҜgeWtVkn n,o44:xdd |oν+ ~T74X4:kk/nja? ^]2Г{z 1Ӧ/.{hڛ0{{q׿N@ĕ+7ת..j͙,bCqZ%9qlh HI!bOb9GM0Q,Q[DM}Xf˿&6*K% f,?R$^d#u BEO1 x MB{+֏ГN6Ϸ IX\OދANɺGr&UW&J-+U[)?ՙT=y.n.qӈ"׉İt[+IDO9JJVNdcx>$Yn8e}a33}_jA¦4XccAؿ!C&":%DT9Pe!'$-l VܺK*8 AtњraHf<¤~ >d<ci+5Jǿ ZhҚVcjˁ p]9ڭÊ8:[̑Z۹:zh׺F sv9њ0,9LpQ-Q3UO,L#l$_b#GQ^fz<TJ5 BxbUbRm|5V*P" 3CGH䙬_zÛB ]:L_n&yOXK?m y467bX^ӯw 6Z#u2Y7 C)U-K:[3X|7X0Z~`q~V4kdtIι27Gj%#iYm2$%XuY<ˆ]99h箥Q>Լ"t~J5׊N:pR~z+EݞHC;OmBIϥKSsdw1SQpMSxwQHj{9/͊zч'э3ԇ{["Ѽ (mqxu?lmClORZ<܀KҎvogD)qaI4$s1:{V)2UF̶42{Z]N&GAOဣ):]NJq_eB٫I(7-8>1LEkI!g@DųY躖* h ޹Q<^*'^Rt RIDˇs[Ej2жٕяOݹcє턏nt3"NV|8[kuaކx_+FKM Cq pGW"gNx fz/(<>Jl޽@re0=[w`89'~xT^9ofgȊ0T}V6~a%.η8M5cG~#ty%j@;y; kMy{70L:nӦ/4Q\[m32kL|S>jok+R*tE<\-t`1j+Lە?7șrR h1+ I!\hosT CIG fJPn xP|TBӏxx !GOqS dPY Ý+AhyRϏWs,f\j'xItxuia5&tؚXS#',чH=!pKkmJU`wpvlE$i%~k N[n#2_tr٦_E-IoN8@F/pj@wf->V"3V7*Q0]EDG\,Ca/G;qPϲ+tl7y\kt@"[)ۦe<ܝhaP@zl[EljT,YO _ Bqe"$e+8']XE0Lk=QlRے(2aIu+N97R=]OLv:#$->YFX%F ڃ:j-NX3Vd}&=7L47zi!-,ѕhX1 j]Am2z{[gf,N IHxht$~gg/%sck9 -}K2:1%,6U WaݖF%C.&'yn.YR` AzyhR䂯!ʏI: ''"vmu(盚F*=JEH>ՅeAaD܎#^L\+l|T5~ol s0['|>`>KŽQS&[ ]u a<̼բWqs:vaD\ܩgH&Rɏhv2Akה8z#TpGýdcUxdk:)_Wߑ,%-5ѹvx j̀x_BuK=*qxg̪ݧ1Y:0q0?dyGY F#]hvWnM1,/_" "qD!ڣ>醤Iv^'BU[% N_63b+, ƀ\iJ(x>S* x0$>U$m9_`-9w!'B bJJ1cء?j5 K8nN6lac3}q7dZtV7p"D:9Ouː$ $.Hqu\nlW]1-x]'@WxʕeyR._Pd.4^02=`<5p}"l8:Y](F`7 Uag_@PqBpW1od{^'6̩|ᨔ]Uvޠ;Fg>6nT9Kۺ|sz?)FbUևp؏N. g<2Bpay?ap9$5"6;0:ƖW/ {pTzᚇ9eIRaغ'|bwPh%⌌jaznMO ŐڄCOr\kՍ>L4?wobe~ŁIt v#mG^\̙wA_M_»z/@6vYҝ y,toZؐwن3VoS黧¥m88?F}[—A:^(A{L*#0\03 L.MV EE > EA|)|(`|9*D&uU# 2>y$9Ё.s+F< :aKwX6 z/+K;IxڜZ\pr`laBIOjPm'J5,qeT_xaw%'?p6;-~Y,Ui9$r&eǃ@xM|71Úe7`^>U"ؒ4]VO'ql1w1b>3W "FCC L,_t )tc0ٷni] uVCޔO|]r>8RA rfY#D{?"p˦n< Y4sQA0HE>=MQu:-T!.%Me2- `;O1)BD' kVn{vyz1%ȗ|lA\OۓC 1|Kl[KH[I95XBb~H4b eb6L&vUG[KQbC%8^t*@@lOP*AIoqv}Eư٧7>] ɱIǪfs>.KNJJF C3ZCYm_%&K5hF0*܈bIe=gbF]VkI6(4l\&80k &jdҜrBΊɯ: O~d3dQAG,Y 3^~v<ߗT%dAiX]hc1>hUXAijy9\.Y F`yڃ Z;ntV[RqY'3o#12[YBfSPt(#t}n,]rdH ߋAG/\^. D6\0z P>| i}m_kT4T dpǎiDVz^׮&tT<) aV9`Le[NY&^*r yǟF +hTw&뎧uG轌T<֦yzB>F}3dY+}[fFzN-뮖i"t?T?c4)y*[~٫"ܦqoQAct#z7_ JbPQ^zu ,h3uuQ8s~Pwn+w[~ TI=#ʟHnyp^ =&)9njBi OMp0VԯIJD/l[@̐=r`zk.Ί˞dOuy l(i X3~ZK?PW16,?&,TɡxK!7^f! '?ĭ<;;l%Vr_rdI^/.t@vxLۂrU XXrDu)xn:}p `aS10>fwnw|PKh@?1>Haio>THX 0`28 xxڗol~n^d5Yz3 ]*`nt!Иa(@XGxA<CvSزc} l_-9 ]Wi=xU>A^GᎳ0-ⷔݨ׸ R ɷXM^ϭ?PN"S3mAGG>wEgf殯l298`Qi.e"C[O8kE=e=Y9>cԦ!P`\7f;F4݈sY:~} Fܒ]kx/rǧv!_pcd[L Ǯе &f+Xў@sNJz>뢧[9o\흭J'̀I!ec$!('ÿTυPRE5gC v׉YfvQ0IB+Iiь3Vb)'Т!#HSağy䤫$inGm{hK[ ƒVɶ+7yW'34gӔpΉZ8?k>tp C:G~8/1 ` *dx@ _*w&$QMiSb>BMv)DCK6RHyd,$D,"bjBN;,O04 e ԕgE,db6P:p*Cj&erƝCOb.)ۉRzI5!(MRǯ_&]<b$n]xN*CBIaѓ!<E xv4!;yS)hxʫ oX/$*2яCm4mÁ/T^QupWDL[KϘkUs7EࡻIfCub˘$tNw|1\XѦ\ #NҹOKaEzY͖);i=A't۵qaU֋3'4҈Hr96Rkqy?̛HƯY 3*ƞ[{_S$=Ad:'|jx=m;noWzE<1 rA{%w@& :5_ YY hLZ:]r}%ER,uCHNjʲDqu G61C*f=" q"#>>ԯD}?H9C\' '""F[btZ@xw9g)"JEz U 3 ;s>;FSxD_:9v[PΜi ,<rj; ms ֔`|qQ1907z5~u0mcP^w2ܢ;;m^ ϧvmőOa2 ~4%3JwEC7x`}UZ 8V^*q QDRQ~%3K}NK"*ԢW^_`djq-| I_odȇjR kេ Wm*5mw&EWD ѿaϔh$˛9n_YXi`z: /m¿43񄵥 '\CD>iirwsx/B "nb7']ۉQ?7(2 ɬ*;@vW*6ujжgq2GO3],Eĵsq.5dCTQe)rc"u#u˙MuBa~琳?Ʌ2FԮ-H@ȭ"]HnjxZ4ES$aDjJH`PE9-ϔuFz4 }5IKw-bIX2BM^9E9kR9aR|!Z6$BVx{ipRekq`NoA ڲ1iڜ"}~WY˿zMΪ kB/F98;4Qd#|u\-߽(| gKb!6/f1%Rn5 (/DXAyGˁ)f%osپpIjԜM>C{e]\VBbe;!iխWųX rV'oIWȻH~tl8yBWJdSa݅HV-NmE{7TJ( Y $ҹw~'6Dz2-a:+an49Y!Zv 90otkYeocun P@ ?=:c1eL6ϔ$]o /vk-zR^-#K  Ӛi:Lm}78d\U?8B\sz4SJNܤ=i0*i#")(ǷL#m/b! Y*4آ&M(RZQh0g8i;msۮ󼎊 {9˳ÀƼ.Q GhSڿV`uZ,0чYH43P3ѻ&tz:.QFBfc!O?(ԴI[s:<{GS3H!L!ҌCk,vvBn,>DbU,%JN hG9 kfV@,MFm` :Y]C-e Q%_|FyU%!LI Y M/'b(O ܈) Em0!B3s/8Ӗsk!UHF:Lz7z:.#?,kbT &9 k=\a@ucR- *piqˬS \/S9F.>66[m<^k;}-XϭF8$YO܎wbg"E`kT.o_AE1$98B/>$\c{ [Hh<7jjH*$! 1̀zaYl EqV0\z7cvt!\BaFg8c}cwqyP; BI pd1@G2+:T3 R5Xe@ؿV)Fmִzd<9yt6B(ѬoB*%ƥa" 9Q;O7' q[!X CGr%Mt4*rjQF@\J.}-6y\ ʌN o7.R.Ln9 j3f你"W|nqK8)2LM*صxJnZuX|d+J K W@Mv (ʍߓ dS4?d{·Gj[`S WnLH>DK31wS/-6\Zt.'WkyBMK}2K}ؐ}j)x| Ք5Mu2j6UKޘ]4~omc A8Z$8vzWJMyY1>0VRs /sIKAXob~RMn󃢕XEiså#D\lN>}|5|$;4>ti BxCN|Bgש4e7; iUd2ݥV80 ׸\ .IJ˓Ξ!!zP I9Z1TZJEZaw)Jf0:mոÚ]:5Q4?BEVL ,,JLq)(/|#){M[ouA";Y} `deia ً%vOg͎ ^d^p[:C@,,O8RoAv;._vICp"t̵$*b\ O5wE_Ws ,MЬˉфBUwL1_KY^_LH1 00b:M%YjپrmP>T(% "hmjiQ--QIsH(..f@ {btr@ΙJ-iF!gx=䀹\9ߺɌF6!:)W{婠OB€ß߀ ;o< Uك\%ih~ɃtG%yupf 6ݴRqm;_ޒa (|}.w]Z8(7J>lEu/aZ"λv /i+76 \ՔD1G}7)Q(^pJ;,n!,͖=i2`~XFȑc(&Ay8}ӂLQd&o1,&M?ǦD'Efi埙Bؑ3鲸`Ķ3g+r4:ombjKf7eޏIeVH+ng(JKGj"Q 0nMҞUle:׷N~ iݐ@|[XzV8p-qH8ϯgY+<0pj!!U^|3mkb~ݠl.0eG22t%"Ҧi|LqC3bNzWt23&eW.15=am%q> KZKnΧ&]!z)*s6 IJWL9jrC31?Ɖ)!!au=@`lT3k/bd] [\^~)1aX0gW7J3ְ"eB+im(q7]&t'aé ب>ٮ~^L sw'Ҷi*clɤoEkk8 Q^1jhXcGK/VIymұ@.ׄHdˆL/Qq ,*$deuĄ"Cs"򞌙;">Z~ſ釕3)JRA= =+0}DYC4Im D,|1\Y{UZ 3PiJ*W@-GƓ2"1rz{'7Nҳrj[qX]WsCC'ˑ9GY=(Jid*jiW6֋". j!.^xw򁈖}t g7UJK&b!gҙwyfpwLxt *RL3ԊW6PaBRV1z@j#<yHd%$/N}1;eaĥx`$rqSg lFeNFm)aM98/iiG)" B(; Ke-E:>eX(1:ҀXd B"UjX<aƽ5 oY$fjtM'.P.e>EZ.T/On,FME[d85yia#,E^ݔl /lQ2Uӎ58+~6aO'b^)y?WjV 9Rj~\=ɐØ IWqɢ"ayn`ǾFJ$pe]ʘ&+'3cNCȏkvg壜/l#ͬT&##Ŗ$K; >͐˹{Zqѳ-RFAvx+Dgrex8JF܂V.?4J%v,QwqS+{aL :5Mk3$=8S#2KJ(EF M&-אs*7N@Xٚ5 `_1MV³2O2uH}]QG0V3K^5ȷ7s@ aĶD4X!Uzk>dHN`gs4 rxϬ71*tj]᥈65 &:ep[{2_3֩?zl9uk ue ϼO'h nXG^q×;" >МP/(+qD.rECxpoY3m$T^FL{ ju]L6(w<}B Js@T%R+I߄:㹄AKn2RW. yPKea]j!> *=C X%I6~vcd}OlTsA4M\ sy>֔+z(Βg>a?Jʭ(>qx鼢>2v3ry&L6/0/_>kspwI?0jZD]㏘Yb~I$ݫ]vk4>O¿S$n6y<-LH|+Nw]>}1Ǡ߽yM\(׫/>qB+bA43[|f{)'ynv hg_-vL9 rZ hIc}U8 }IjW [h[(y,&bWRws2Q.Mvn i l緑( @`Tk-eOxS{EokO>7zRg`H|y .e[QbUUݮsYͪI0U~쐟r8da\8\n|1rxֹTX 5[V\ŃbM%4.z ƒ/`1"({ʻs}IzivaiHT9`43`f_.ڜ~s3y? 8_d-P׈v鰳qQΛP8Z.jI5#^С XY{^gY4P''+Ra{EYh0'F,jDZN,F]<^|g]w䷝xAv8R _\nޖ=e|#ڀ&K Er> ᭼h'?e lRo ȱ S,O*8۰h!$tBԑeT -{`#N=`vkـ4`negW%VGE+J~FZ$_G=Ht\'3G2ipY3Vx <c_*PʿvU)?pS"z8n;,S:RuN>/+IU!CaB@aʺ5*_PaZrAίf\:Dz!SBXg69D`/j5K]rD<Aw1Sݥy!Pg k[wƷmB]}[Ǹ] 8Q%>42+{Ar'Utc>aM_OƔi붌 dֿ3q$LjqwQ%^zݢ/n3v A îW_((x^,ĚRIi|vgjzCнb~"TZ7")pktM&~etcN?Ak*=qōu#[ɂKrm15uVsmA$㕂[-4muXXn=5G ;?ۃ7!fB3OC臚S᩹# @lˆɘwQnmu"nyf!UOw dμC>qNL}SmtmG\>?$Q7vT hUtnIl~ .u2UE:ZiPjrYcԸ2ϻ< V.UKqWD*yww7"u+Tezz<´ה@E|vvLgy_cwuA(3yg6%Y准+fkyx=:qæxkCn3'MaT 254ő65VyC'ep!GG4 =?)/}:W+~'hr8'z0tMО%|G{"ŏ}\;e t(XK?7VJ%ZwvM^>CM~P#iSwF.J}oL3AsòDȔe g^{8_m}ȡ`T$ 3rs8Iv8Jq @DqFCN=1xSJ ֿj|Kka|<liEVIL*Mn ⳐiO-;Q. f;c(6 LK"oZ8̂ZE5br6G6>iK>2ø:c#] VM6CC)Mq. xdHjLǮ(GupLt%;» $E^)c:Lj EҸ}`Q;ȓ 1>>Ǒ $ kE'&rs<"UPl-? ^[&2Wt&#W6^Dj][2])KzC\k8 wKi:c#w {d"딗l2Ap&n0Dl^<MΚ*K(\,;O1;1R$scZI>1[A- MfJ@wZZW\!hѤ!HςeJ>6Aˆ7"5*0pS/Dwܒ-1F#_O=Xh`*OnYGK+Z) XF~'3 aEy|ȦXZ8;W@T/K-Rcl*wۑ%3tfa&cOXC_ׁL<ᜢ29 =wozyF:;z7;:u)O>\Dd'D鿱L` tJ}58)$&"HF^ 5)Nơ򸘻%e;V)ٳ @; @XV) >Eԥ4X;$VE|9%2R|2“!yK90pOX EȤV;FR[v7gsv!b>O]wHspUldB ̽R 3~ܤlbCCRо|M~-%*a"g_ Oy [kx1"e-p:N'Oe łj$_Rr3q=A~*ߙL=a1=9m7A<1iCfr~}퍺*C \ğrxhzΩ͢!+y:m{;S|ծп*0rW؎]ckA>u-Nl*[JR¬η #du>$ʁ֍\d۬*sղ%FOW\$8pG5EBw憁i(H1Ӄd{W 1zJK;[J~{w&قx^/ K]s5b؈.L>SD@4+ݸ?7dinO:@Kzp.+:yEOg$5Im];\[O\֪..ߐp9=MȪ&&U~! dhbxq@,/!Wœ77:ТCN4vj .K貾?*|rW-z=BZj%\ymK FD$7t; 8C&u4S2 |N'^19%t+iAh 8"gp"sSD[10o58Gq`:")$cRݬP{{!xղ[ 4bç #γSz?KgfΛޠb *5pXGhJ?U2Fkea#Tٟ-ox\ ά@HN,@sYzegkyxl7|v2yT% ]R]1C$>!:n[5^l\@C1b_`OYu% DrVu=M0ЌMh6 N+ExZ JtA>eDh`t8y ( ؘ7h7R(To wKL0B+A-?z}Ьg^*f5NT'?/ q] T0O3ǃ oP0r!`%KpM͈#kϧ'nk!$ˑ6@]xk,\D8Amix`_Q!g#iփ'; g7J 3.\[\Z6=yx-3zc&enɈ%2 1 w}&NTk_zVsf~NbŶ۶1'jX3IAؾz˚ߢCVM[ 2O!1ш%4y@XNc'#TV^Q@j8FG93I1E:5Ll&ژ:^7EԽH=2 rqj vR%#+@O%٫r]z.%0c0 _8hKk- >L8\@ؤ2`Z.F#VIN =Qm8Ɩ"tʢP<5,J4 3l7lknzǯVI6N>Sض×0,"|@`(_4Ews2MB#U1BU^y+ VU-d;d ~"dIE^.{l;L]r&]uh܁1L-}p,do/.W=pwĬݖ3 BLBaό0#s "x39 cNWxwm:%Yxi+X)RL$DFouB :P>~[(L>\,L7yuVE{K3^B׳[>b/5*洏ʊ@qdoS$;!PqUN:OՏsvD~jv1OUI_>~.C]JYXZE@O2IlJyϹ33uXNrdlI[2n*V";<(i\m&.6K->U. ŽeǓ"a7lR"`VSd\U W ~{fxm`Dae6 Z8qkB]SkGlq ݡ}mm b/3U;Zᰗ3m2 RbĈϙ箭<%#QJBѮr{7YQqjt>sw~AE_~*oH<`U^$\0I+X׻eslE@is `a`~D[WΆ6ImO53G8k ow9hW]N +?7QttݛLYeI277σ&A1rhnɴܲUn7!UFmH J ^ 0~"IsB"!GKW8Aw%Zd>4DEq"H xlAS-qtagON:ɋx|[{"[ N'<*M/L@eCai! ̚Xc&$U٨"\S4GB\jFk3I(b (D',Ar{ 5 WMh 7'T>\Ϭ{[togRcntS/(0 7@ťRj8_0oZpi c܈ >4?J:3Sٮ/GūzX"eC [vpXw,Aޤ`BpεCCM Yq#[oi\vqbܭ ]ʕ秊$OEHmV/n$Btn#pK:o Fd"L#qRfeGzM]ۮ}$ Udžճ`L ՐDd}/[wi!Vذ>M큺]}f)(8nd|lP)6-&*yTntdZ.=$ ͧ~i7wLPo]'i6u޶g,]S1Kg(mClUq4(KPu.rė%msMyE_Y7U Kglx&a;Myd1Cy6/mfaZz؅! } ցpΣ4B4X ɮٴD&쪷Vl4'ÁܛOӣ70%74בE~1a/v'h&y5F]K瓨2X T}.= p-QU4P7>XEoAOw`5{Xw}*,m]=\߶0QPs^3VDi©J`%w--!PO8sT " xlxJ 3NY,b{)5Kn$ }םgcۥ&VF-\n qKOǧV/s͹rF15NUWvǮ~ ldl*Gg4!)ZM"F򫇃~`9{:z?)0xqv0wֈK}=N=GYs]N tzek!.H"vEK8r/a8R8ԂmcOcŷ[ rVHL&@qYmCi:j 2.,5U>%,٤lFl?Cns]kՅi#&932B6"ѱY](޵=$/0 F HT6Q\8(V|Wn܋>,>9: Zr +Vffwp~mS؟zFI*iU[}^&5#P>epdȓu"}m B#8J˪EAAӑèa%\R%ݓVaRu zPh&5[V+EҍֱYͺ1OX֪TÔ1yo'BߦW$hK̛g&^XHRUK2tKTԮ†wFE BU@T·% Sys -kζ2۳> 2epYYH;[To=0;W_16ޜUo&'_>wUҀwf}]~ـXM?ml#qF0R[WU 5l9@=v$[XKxXdf99OPĖ m]%VmɗUg~}BV-YӴئ`W)'dܱ,eY*z\pŵKN1%irQnN|4APiVZ==!m=1BM /rU$Sw UH*>/*Kնf[-J'ԯ>—6Ql:Ɵn"܅qɽ&X߬b=\_M 牡I[F ^f?jeEǕņa,hE8_:0[C_CDe4Y>>:-Dc=(xfC@|"&!ۓR!I}O$onN[cѰQ+b3ixq\b\dRBSU+*j5å7¿26w*4t>c湳07x;;XT0Wv8KoŸ DSvď/h[ Z,y /egQ5\ƁTVNЫ1YALp,'Ai>p5ؽqЈ\LOxP02j"wQ@nxǪ|_17A ?y+| {{췙Wz\[Y<(ф9>q8O6}m-?բ_D" Cr:nZ88iwjZ+Eו&Q6-vG qA5# ;SSy+,F$ ㉰:Pxd:\1Q/cbNW+:"]"L;NʔK9fQdeoK$nS:r%A`05!^>C].8\p VD4blZJiu _2&Q nɮ Z}fD%y%sŠ@)m:&Ki8!A1"'M,p=^8#WEզ^Awޅ(35:GtS-OSNGл|u0B!U*FvUΐ%=PNZTk(cGՃK5H×9 8382SZ-g:TΆf9'MX%CK?D-KdC׭ |2'JFԑ'uehR0Eli y~A"x+M -B'DLۂգAmW\Hb\6ZmMc,@U/mjW3M-HѰM;#ơ!Sc>(tMwyi!CjC?>}J|փarq@E_Bj{6vw8a iYi%ǎ=kt\l*.I"ǷSd"u&{;:!iiiN* 'y7g5Fe hgQ vRyViǏ™#f0t{PnlP |c 'l]$e=ڽiP8]t B%vbR.1r֤2ȵU/g+WWgW)L0VW%ķLDdd$W@sV(|ȁi!J)v•< uV='tO2x)D*pJj10H л긱}]5!I-38sˣ{ϯ|B5.pH) U0{vI$Icj{"j8=i^O`\7pr+55_M=ݫ1ŵ334 MoJ fQί^^ Tep8!، [Ie_[mާv!~?N]1E$׮=LأP]sM$T> m.06Tc^P=ZFԳ6aL:铴4ƛiKp{M}3U:i>F4P3) ȶG/L=CS[XR>ri+~ٳ/dm\7. {z&O zT6pyj1٨Sk ,ۃAnͤ{:ebН:ʱ?k:c_r}")srD$!H)SL㱭يbϦMNMƸ`hN>n~#ՖI /@u«7Kx)u@_o\<4u֏%UGԞ/uϋf(p3B8voSXdɝVVro$&r{4d z$Eݱ g_mA3'/I6't]̗yD6{-N͡.U=ү'RYgo~&]I8ERY! ؉DNԈ$xp}0͸ʘL> ڰP!nDVb{Xx2~Մ*ֱ`{`$Zץ)-IM+]%G|OfEK>H$-"3͜ꇞ~@;6aCnYV"C؈y{$>LEqHycKc H'cfoz\`N<Ǽi YNnVQڸ@ ?n-58zCwڡ 3=52Cׇe4~ +ѱ1lOèŞxӀlNK=pz,W0/J}."wi tpf+`!7[+) փۛO=9Ļٕx6}k?ز^;&2kʱ?]B}'GmE c& 62Vٓ~CuJI/s‹@w qԦ{ >wfWJS(Mj5};`tZ+ómuMc&,[1C3(:֚vҺH! *?F3a4ǶTY)Ɠ )M9Pt.,_gB^㘅'!Gq*WWN ݃E߰F( Hgؒş=3]֖)6EQ_!MkC٧}-J[jahV O1)uVD/(ܨ9N72܏/ hO;biD]G,Jܛxu[81:}|m&,QS\{g{bn!ƞްʑQo5IX(sLJR,;xBTIBhDr y _9$ɧ TSC3i]G.Y8;saXٮIb6T&^qk2n OSQvNDБ`٭mԨ˿f Tt/qY=Z)/ gUM eKEVPY`w8I`~JWB/7'#v d;0i:GMU((&\B~Oq3}PflȺlol@d8*Shi$#G-"-gzW=uk1Y^$D58aXcU8*ո؅ʭ.^1>0b|SbGJ W-G%.씆n#PNwx г%8J+ӽ=އ+}N/2Fb>pF l}0bHƒ / Vo}4u{`]@a T4?`V菛-(7l葰sۦgVFs^\]_ rocPXAm5Fp %Ǡg bTҮ} zjb')K/͚Ξr:tZӢV{W"eu) 5q)6 Ƴs8oY5%ƾ2㸍QP~S.5):]sKok2rvPLq6+pҙ'ݐ`{F)5ku25c|mr'}Zx O&0Kxl?]Ss*F鵀G^s傮]Z/i+Mu^(ll p| &yA(lgR5N&o.tWՀ9axgF%,%!`DB3^5*LNJkXWYb_r>ᅻ.wW[ؒ;ZaOesb-@3="IY,MDV60~Rg޷E.wC+j$4b Li9 .:c=!F G[)Ǟ,<%ާ7%LZWnG? u, USۗ +RcaT)BI?" (tR-#[+m"8#4SA$8`.;'NkDQ(xaYRfo7Ƞgd?y*~+3,)'h=e/~qc<g5l-<1hLJK򸼪UU ID>G<8wWF@W1JII=ztS2#"z epM W:ZH] CUMb/z|[P: CGNxg$M(^(R&AB"U7 )v|DHrV18;;WWh٥fTˑ/J{,FLk\ x {:)훟5G1b#=y6!Q-)C7xn>g1N#tT:Tu+Bk> |{gŃ7g?ĕPA%C2 dztӁP O ijޛ>OtodaiApy~`"/wHļ{n#h$9]QF b; AUF4rW߰kc V~Xk"fQB Ie"#(ݏVL=PJ%@ܞАW|(ͫ/bX$ LJVdJ-K=м;Ǧ@l1}֥Q^>%CgY: ,.FA vz|GJQ^ond!N[ߔ(X+'j \~ Npy:za FR)ۚ59ZT.o;aWP>wbUQr_=FwM|=W6K̀'^Eu|/``: ЌAp;@auCM&r)"c1fqIjڼ !߼=#CqBg=`ycK35k_v:ؔ?wdċd&o<>~rCl'2@$>i26ؖJ-89YdZHV< P;aϿ=N,Pst\Oꕗ Vx{%Av<'KǞ}A vЗ: ?ʃHu\!>Ƥ &H#G U9aDaW!Z,W(^2ARYh 6W@Y3r=hQq3m~_ŪO=DenwоGf$*19xp]5Z2;pjasq;QV#,Mvo:PкD(-^vw3gW9rEiEEMrYBQNAQc[ca0H`6F SHzw3S;+MIgwݝ!OIjIy 6`{ZJ"! WR`JJ3CࡥNi|<^Ay/QZ̨ܶWL4cA^xQL[>Bm #hJ5qs|fa47i,l\kIoƫ(SͷOm3gdX}4+9jtepiܧ.ЌIV]Sҕ.L]>Mߺ1A 0IJȩtN5gT~Ii2).Ri Pfu[+`7uX_*VLWm|p9'|2wFE'_9[Xzd$ ߋ9 ݠ~a-5!쑸va"%ie:Gʳ8hcp|FPΉSߝŁ/z.rLȽ2 T%|aa`YX_ga4ѝp$(~"71ɒB^?PZ0d'~+6quo),k/Ys-pVt=Tw'kѪGS \d0y\Ѳ$y\~/".҅bNcFFhrcdN.xˁn7؟x„ =|ak?V~~i=Ϭ"ªA[,=cQ} .&>jIg(%o_Rm'=zL+Q +3F-?3]s)r%K[L++dsBV$rԆz9\@*ϟtv BcD%~=lA݃Gw|ܜn0 r|d~D z^@d~&{nFX%zP;(V}p]wTQU熥: juY3m E?ӎFQ\i'}z ]8uwahV-lhaϢ%\οrz¨ͫ<*ӳ0 .aujk&~ ='C5|zgnݩSB]W-zk ?D !k~G{9n}ɯN@ޡ&FMRgK5ir|IOX5h^2 8}O4:k{bq!;9꥗7ޒ9{x^誹:96fidQLÕ6hBS;EQIIܙJ^L/Rcf!1 9>r$ʗ֜ u\E$~LE!FFenPLUccsVJ{0Er.e6sw[aH|z\"s&dhN/B!%,:Ty=M*3=^=~1Mvnͣ7v,X8EE#ǰ͗S:?ߪR|/L]f_ Iu(kJϻ nۯu8ߟXYԒCyH=IlK:;AHQn>sm`Y 4-sZus ~[A=fxU6\BчndY`QW@?"d_s`1(g?ۅs/3с O!`i >&QZ/[}j2{'hn)sI3?Ɯ"Gi0Kϐ~]`RVYL ^=:ٍ qluc|:8DPFjqPǽ?x6_oJ y3O(jj5suoEY|HvjN/V\<bX[z`}Q^4S+8ϟRL/KI(x5Ύ|Ll1 [ᎅ0C.j oo&tFSEtT- ?6ywOtG<= ^`BSAW O3>:%KB.*OP !#Ŕ|V-pηO-:8I UY&?j P7dκA\Knt%7J _gQ ~za۟Bh1#V4^bցe~ (6EL缄ϵ~ڀM*}Do M0m߿2\ۍ[I`qxƬl ]"(Bt?SAU9Cԍ;y@QiNEMcn[n!,U݉Ëϙ*WTUbxAW#-2޻[aSw+EՄ< 5h>bh#e4v;8THމ>0rհ-UOaӥ|33]ldҔ"Y2z# n7ej3ORuH N ;+I>d!&7;5L, +sSMR_ ;`;z=F[qXɆixF7'f5͚Z CŢZgx78Xv4]\ &^m)|0H99g( YEe|_h,~;acL,g^Y;9y x|<rGwH'd 'Mf6r2S2sūň1eEƵFڭne|.5RZ9/* Ɍ=J0IdX\)ل{VvН>9vi֬/K k3VIR.4 ?nZ%R8w,Prݽ{ɗj4,[6dY6 wl1a]۷؈~^L? 拫,H?oG'ݢۡvrОK,wHqg!!;(NzaቢfҤӁL\kk0Pa;ƩM)dUι;$%KIܰFGSA|A,@3߷UJ\;Sdx4%ڶ?<~C!8z޴fp C$9_$6VaUui;8o7{%7\ɵ34Y3^  *(BWFCgm!o(Y7͛"ݨ6'sĶ+Ѿ>9uQrn=΃ 2ܻ_V>ws:G+k=DC8/*DBG8)ĀAX.wxRP]ѼMY Ӛu%S 2Jaع螵`ȇo "+GA{Hx /,0LFYBƕx}5 K~OXw*ԜIJVZ[^P]v0SIe9jT'HvRwNO ̛[5Tic9o1&s9 N:*rDX{Ѧ!oY"V ElNDž! ߺY# !Sc=_>Rf1RvOXpS#m购*D\Y.u;cC9 g-L&dfXNeȒAJ22ieژA^$}|=9ϖ ~th Ov? S?`y$t*e-{BnӁ#ΝADHTnI*"ީA'v[0O4U'()W-&q:geW_DpKM[O bsZ%a/NVYڬ}ˮ0$@ su>8w[1:tJ][Yrvu^h0q6U&K(.'TS%~蘝U|˾wbve>5oIBĭơbZ*uZ״IPG>hbovQ02 X?bM uR"@8;i--+k:xLk}^K?g a3FQY.7zV̌ȡA\\nSOfiL5&gФ)c]]%Q73Kxw#Դ{n'h)ߺW ?9(,u)_.~;KVM<?at|@$;/TGVUpb\e"ZX82lk86vwLмD*Z|&lp!탨se@HwSjyFf@ x[-|y;x >=MwDȿۈg~ObMBY3)[A 7=؞>+WьIZ(%1~jE,{̏ $Z!EWotS0ף>=AISSV:'Kn !,4`+%ymy:$ٺʤHDL-ÌΒ%{.,2e-HBm#4R2ƣB2T \R^SsAs52ya6.)uaS|]݋7,p~ڕ U#fr׫~>>dl.fG ^sצ)"`.l.[Ar4Pp1:+by3&^ *['T{2Rt첊ʰ֏#;STx޻5"qRŪPkcF^11Eޔ2y~-%^@'>d)"\ᾳ~%S*x]YraFA_~$ ƶts$B'Xz}d[,&_yyR|El@>A69*Hs^%╕/n5o8T"9؉-3D$a#.ܹƂjݼDQ397f(qbF*`8YYfvYbN{.,sGG_<ӛZ!)?ſ9j&K#EviIpFl\}"BH+Z9i;+ɩ95? !c8T~\c+qzkHO*BPeB\{u[~è5撏^Jz<QGF(=s*6jBwRa9}}Kl>W1ԴQ0Yb հ;s#D0=9i``}gfT S:.eٽλlG 0GCjХ26G_շGÓZ4|mƬR!ЛsQ-%N3 u9&/iғ)y8U&*˰jil[#6t[nm((X> o-=.6Iv G{y+akuly+]0wz wq/H^-d>PQDr.qU]0`Ki~ |1hQ 7eC=0r- 6a%~|xF;̹%SaS5J8!\n2 3 ,ovi -h[/=)]NO3#Pn!bnB8)rrE-= cDpGt}"2ΏwD%Xʉۭ#JPy %SzÃy˹A -.rh`Տ,FۅS҈ TAI0$[ѻ|\^BO4{V~[fCW6zu]![^qrYMGse@uR&|%3k$RhHDp 2 !V5x{3mm'mRAdnO M]Ol?%2}_EyVqSUOD8FNX^ ^V& ֓ Zc|gnffcWdu\',uހx53$%SgWbK~lk?WlK9(v,VXLW-8rD<0ATqIL {eXyq9 i˂\m3(H:  D [6iw7űfY !U+R;0sM ,+uj6o.Z8(s駃ބw;=dl` Sx{8L AX_uwHYwkvH,ATzD(x>7POG3G'?lWՓC)Qy*PTğXY%VO"˃E2hN"Yg] 4ʶshuۙY'QmY07NbƪYEP V56e.ZL6XNx?l, YP]fUpU:@bW_pDK}z烷 c5\=\wTyaDŊ,Y0wۼ DiKIv πL)\4ȁrɭZT;ؔ+ 1&F^Cz+wxްdDxi @ZKywc19BϵָYx%nRRQn>r Œj[5?s$w/!^`, R8#U$[N[0Pk9<SQ`Q[qLFb6m{u4G a<8v ~U裔 ~ ϻ6ԥԊ.tjC;&@ŕ7KfsNw$'I&o:r; JhVu\X]Ft-w{o\Rj))q)VJBki[>9J2% D^%mƪE1Nf>tUc!+aL1 G UdE_ZпZ#lT)'܄UPaiFCr~6nf}-?=[>rxDuZ:Qu\df`'6C]p+MKV#Z1NO}EZrsc(X)aQJX_N.7.[]ud&1)MV( 72: qN>M&izNyX億 KccȲ5bi^ |z  Z̿ Ml\aS煱Xs jm0z_J{#hhI6aqs,v۞rdǰOI]LFj\"J8>xؤt XrJ Mx,,xOXy GmCgARm3J5z!N~p.!X(c؝7J}hˮv=<[ct9A "ĻI1p:eu_@h.v!%L_>嚍7~suGz׃͊CC'zD9ˁBUpG;ҢqdmM)O5yȌD!8u ,/Vv#SŹ]s{0R:Č?:!.0 ç2|{k.Qhgwm+x < kFDc HzJnւRPeP ,6=Sw1[t,a ?<áhh͛.`TnFDfwoF"ɍ.}@V?fNπ.]}`4@+Չ{- ֻ^'8L3А]ׇzNA 7I_%wx)B ԩYAc8b/I_;穃 cqqm=V ].#ܕ@Ss ^Cq OZ!I1Y߉l- Ћڊʷ:nfRږdFӽrʹʂ},߁ʠ8H·B6} f!/ O\WEdsΤmEix9w;awGе0| !(?,A{A&C?Բ@0d>@?rE~ xDj;QtH+qբ?pkU2[4r$| 85k2aZFw+(C{1垎'36OP= #PᅰTa7to2_F.W^ke66I-E-)6FK^zEb1?Tr(]V"uww02p\[4[Q1:"u=jnS`{\xyض寔0x<}(| ^(ђZ&Szm:Sڦ5g E0;[BU g ǽYT%h& bs| Z`a`;(gi&kïϐgkXՐqΣS~W˽VCSq!.bYFu'sN:`J4%A}Ex<$lMOi' 6 `ۻ+ #X5p$Ae<8uji&4%Cl3(7O|d5$ko::HdWl6Xnh%$Źsw!_$Z8p>^ "w:`OU F$7F!N$h9 htzPK: z{3,hPyAp~"~zeS}[ZMhIFNਵUBZH iϧXnC m" /Hp rd@{>Qi굝Ý+Y2S?0ϴ')\gĸ20+wvȭe=.v&!y nC T]_Jn:FeNЂ)Wtn$>rz[./rاư; 9J:y^;#mS>8{\<@X"yz]tl u 1VpvNH}·^n.zF-}_a],!+$48?@v5lu+\Hެg $^ĺ{TJ @%aoy, :$eVu,kuK-_X e0lC^C$ڛ>y7镌ZD KWsIeaB.FHa6*7Z>x q9?BL*S: I>kU+bxA!ߙ- 7v * pjp``sgCC$M⛝g}A)梎 |%ѣ7V$'tA Ws}7<,4 2e @2y&!R_6dg ;,w*.yrI ZYKPӊ[y 0ς3U*(Z]qt^ }&(-_`8*3),:aCJ3@:j/ou`Ȉɒ6oL ;1EoU R*ڤT&Y%E 50_b+3bY[G LEUGE#DwLQ%L7vpV+ \x10J,!K4K`Ȍ~aLJ)Y؀S'8n#8uTA|7ԍel񛵫*R_I Z+TTНd(uj6Z*#FJێC{$ ?icԺʙ#aNo9Xr :@#?|n3hIWɟJIʻdGY~f:f& iB'?kǤcyW¬oy X8.oF35W`/ʈ}g+ym`hWKdu;QSm}<(hi 9܂d cr7V~l:+&DְgьNPݟ=RY5p%d@@Kmrz]G؁o u cG^@yqR"OЖ[LWsB3J8'V!I:y={IܢA>}jCpjLk AY/j=ƔK!B^%2p.n4ISN-( dWI$9oYc,RV}7Ef 5 %.KQf`Y(b7eTm(,-ULrSrwfw<\0]{ݙT ]c9,Zkϸ>Yqx_^:F55X\L7{7y܍Ls̶f02IUB<ЯnSGj{?]nK>Y8TSfkTƘ+9c[3dъr$v@)E(':&9544!.b-]h`; ;Z< DKGrVqjm~6Jۺ4{0wz˲͐p^ 17vrW\# }ߔvdP rVc||F_a7KzyZG߮}Wz2Q>j6vdF&W٦eʭw`1"=Y}jTXֆSD]9ct֛{ם3v0;3V!Ni?d(Ӏs._Ny˼,1Dk,( #tk 4ľj[_CEwի oȂL3BpԲGÞW|o.ۄC~eBLP; +W71q>$M}!jZJ;`h=xጉMԥ̆ V4o26rS\\m ͫ&p b mJ"Ht/eF#`@H/)YZMH(K9.7"a]$ln-&%6CA$`5i@g*!]Z4aʑ3)oاW8< B6 ~I&w#<2xc/Ɔ62&f Q'9ؘACNL7C,Ϡ;S9Ǥ VC҇0__^6_Y!JC*HLE9a|c<_5aF = cױ>)od:Vxmwry kp9₨욌Wʡd)E!m qb_BHԒt٣S[StizZwdNS7)3A39z%NxWi*M9-&eȆ\` }鞒Ppx<? l {= E eqyE?8nuP14wEVVap{f <6omfF^0*{ֺ V:MQs ofY#]. I%`% M5*U/I8,'L$O9S`u?<2[ezۉב<+%cUMȘ;ssn:[^y> hd\a4t) e 0ID74Y-JfpAhqx,u]-Q8^Bswi= !alǓ5+c{l˜Z&T_*PY{hj'W/Eqv7#(~Vkʾ_*;j%7wtbC/}\{.Pò|FMs3/ BU/zps!>fL%<  VTP[xnоYBt295Wo]Eռnꙩ9/υ!5q^Rn wJ.{n*eOg{ }J ۞iHb1'8TMIH2c9T\K6B&['^E%l(IǦN۠)5=l͐MBn| L]M`Jf>)uD!Jm/5;5C9fɑбVW{kiR-N7^A{-1FH^|QAͲg/E! 4€ԪŪVQƄmXwUYә,0P_qNce,vÔ@Y*0>Tg妸:J,K=|g$- #ʢqE`lBR*/h,l]*;i~ Y-4*ekV&6ePVxQA ={pxh0~kh+H.&S:u GJ4PЧ(²X `NlНDzhRM2x" -fKD\ "ƹ'"y0aU m\wF 2HkJwghéՇ T{PY?ָJBES%dH0׽Lg^̷>> AB\vԗf Bֻ5}S+%,KVTޜ PAϏo·yz5wJ? P]@x-r7rCԹJ@"[S'`S;'e +|$*$Wj(=*ᜭBgxAM'MCe~aMZqy1s*e|S-}nh3M-͡lg\R1 Ab`/qObIsj9\w9_:1,DޖTg1+NԞ/~I UۣC)ʫ]M-,9jH4N; y1(XEowZ#bnL?E{,l$/`+2 Ij_!3g?Tw!x1-mޛ8DDMxW8ɧ:zK9g a{a4CʼnV֔ JJi?!2彔?30L< pOB5C(?U-Ǒ2DGH{W\ތ1/} Oo7+"3 B"0'`{u5YֶѵWԤƇ$߶iȔˮǷEźgcXww5%ztoV3yu?xrM±9!گ1yFIӛ>}TWlVdLC}4v͉7V7MDO#$!vpݹ7ސ"]glxpM (eŴ4c BwmK{DտwJ1?JP,\@* v5 Xpúq czz{`$SO2:@R6XK`op]?{;uBwe^cCk[YR?qUoߡ0j3 Ax&`q鎍}~.*Hϼ;g%ͧ`bK=T Nb0aPkh#U7`\TR0+}Őp\0V9Rȼ1݇Vc<ͷ^pzpV@!~{KB2}gg 5hsCA5дT5Dxa8Gy=E,~ "U~lR8dXUY5OfQ2PՃkfuN,qmeGD2U' |5YfnD @K|u[wIVTlVUZ_C}No[Yq _Sw5 K 6Q,=.ifjЁ-,`ؖkc4C^񏵤J@S[$S߫e 8PZc-ˢHBA{YG_YC $Uma֧?ung/=3`/h ǷPJ+ [1=kTdMv Oe{^QJOVTPA)c1 4ѿzsf:xϰB fxv0鉚tU/[BC]mj% Qv_=~,(0$[%]OA QըEj"kгC#I mjسq*ДEЪ+8hV);yLEϝTTF$CCӢrNS2~X̪0ՠԈ1<]~sQ:>9)$Bd]کx<>߀`Ǧ"(f۽3m(eSV6W+4t§!l]g,qnb8qvˁ@3Q7]'Шhf"N8">1pi-@[s" X5^(s9l].Bzf;؍GEqDa7"qAK}oљ4K_;: 5I?Y[" `&3GH#xh t%`BOQa$h{-dPIfګ@Ɇ*8x 1V

m7ܿs.t*H~:`+H)*N6k̬1= {H@O5$ BْZI$`)bY#}z]1ʲvpw"z1 ? 5@G;1TtҘ!Gtb %y8ՙК]3đ߀Wspd<&[.bW؂z?ud)xI阮rWIt Gnq7ˠ ~'ħyJxa Y,Զ"R>ct\v3n+-Y&Jț[[ uWYd dC/xV/ê~Uq]lPۦ`؈iKiczujwN%UuԝFru߲˼hZLEȕ^ U[_{MPhGi֜&0#,9L bn4`YW0+z }pCʰa=H7{@2ēO !=懷ω_v62{Î7(ȢxQ8n7QhU lUKp*Ƥ^jӹE_s[]TZ{(Ċ1IN5rl}L͖{Y brJMwiM,$NPʰhCkQ%LP͙CQ\~건fYUET o6  GZoe?zC0fQ~faqFn B~n8*BOJ:!qa;0Z1XsxU*AO)c#vpdt2{T|؛R+~ILf2*traeZSJmrSctKF4AfU [D=[(6d=N** ’%ĬzL*]᳤Vks:]w>^?<1'Q!Bgo7xsRvm" ˤTIJ9ڝ ږ`jc*׫i\ t8{`>1: )Dm^1␳xڲ&XR4&YZ">Ä2CC0DUDdUGjvѝrGnO, <䧝ViP~X߽cEsy<&fmh0ƙ6 pl)®Sf{caj{<`@]X:p][g׸)\fYB]4 fC^,E8OJgvy~ suT=-k%4׆&kED4R{7UE3«r2^ iV=@T8|paqjHU'nS&8AB]l dq" cάO$u(p*8N8u'Kiv 1>Iof4x>SqgL6TTZNa 9r!y>ģg~R9GqM7JZ$ޡU}ʟ?O]{ۜEN{TgZz!,E -|,> TmݯCg^]?4$uF^yL#byehg)kR)z/7-fny^jRDL,|OW.ts*ec[|k1 , PqTMX[[H}~KY>Q߈Sh$y/e܏'}_ oCUJWЄq+d:NS[\^Y3g΀ [H`L9eAc*y|ȯmNUyj \uޟf-rSŋ!WBY~6$::;;/"Z-cr1d&o7%E_+x%K -|,N֏ʅ/ QaO2J[-wѥujİ!m$QU]ZU'?^5) ޭ8̴1#fY.`X7,6}]!~_s9|\E \ B>l y] d6{ ,/Ud{HbEnTi.Y7w6uB:dQ7cZN݀iܱcjV7 =T-DnRD|BwhۺqP]csk)чd@4VrΊHsJ VLUru~4c eX. F!=Il2ژug*?Ē$g&W M"0R: cps-Sr_|Zlp^ޡtܮW0*z*9I/oI@H';]ȥR_~<ϗWkT!byqsmjn#q&x +ޗ=oQ ?`Le,ʋf81OYy*( ,SΠP.rgW?wJ,yclB/QlF-400 ߀>mV,;x/Op.11Af a`4f=L=cD9W;CK+@L(~5)ǷXE7L&Y:հC_uv ~`i&/I}Szhr* ]?~}CR}uEufWHj}Kbvr"iޱ3$"`T)O| _c$B<T [l3:9N`x(htX'jW lENEO)2SoiSP욈foyG^&R!!/*5R_-2(ׁEΨl5kG[~]@&^yGLxkhK b$uV \ŷO)bZYWw Mq^|c]R2QJLڇ4(Esg ʃ۹+|GwTYK4= ZeIvJcZY`QA5ã`aE ySG2ڵ`]}E8sExii+ [^V倀@< qhM+,)BiDh鋛yɞj7NWdc]|q55kӛ z(Lԋ~b=YAfik7"!_P[׀`־<]`k=8 k o `tkt!XTy1.|iujd’o&mu`oq,aKn4/M~ѱٳN@wI3{EOuKǦ7} k.iWY:RֵL=+K/.h38*#:i/-@e!(<40<㳯ˁ| ^c.qL$BYk]q*k7Hm% nbIN#jkgف.l5t/ez;mN0.\gk"l˘$TA}H 3tDh if)(ajq ,\6czTbMI6CC8bbWC|hG'.l XSAA1E8ci%#趬xONXwx1V-KdJ.~?t!>He]R~ا̏%KT×`0|NaI`g)ۣ|^5Lʙ;#3SZw.ZY m`BF3 lP ~qo_cECQBEn8 ˒6L'تN.Lt'.O&kj|MW f=暭\OcR0 OT\)GG*$A˻M2a|\49-.nׇՏ\3 (kou{_VD7ƪ82V*L%GKn~#_ Hwk>䬾=낼FG/ FƳJ䁪q~8Nm37[)|5mSzëw Nĩc;p#&V kC5|T#s^+ݹgWr9A#~<]uBDrmyMhi;l.~9@$a9=CKeNxX UԼ`Փ`} M'2c,18dcƙCl[*D--^e6jdR]5f}xӡș^݂Mp"Gx PBN~w̫R1[௞ >ZztQy#˞] \QayC.W^v6{1C"YxRPOkoxٵu 08a:~O˖Ʀe@ { BЗU 4bHXh5+ =nzZ(V0} 7/l1d2'yABY&Ws?G=~ ~~9^_eDm4ׂ[!(Ӓ,\^0 u:.~K旫—ag+/| U9|L.7qQ R>d3zcOw|LD3l'"򎏚cFLmcQl)v⣧jH(3ȃ(7)^_S`m͡о>z+x*d#SCX]3Je"RKhY aY /PYɩ1pCū^bJ' u57z"JImj ܍tlNVoev}Zoi説gvSSkշWˋqx%g"D/ ?jCHgc@x\Gl?qR{)hc%s1Y$ݼV;iS/f;?}D.|90x =cu7ܠD]67P" d\|fjjMxKnꎃ/"yTb=xxacJ :1cpZԱ6}6#VEj9Ӹ5zu=W LA3ڑ"mwФ[L2OJ;]7̛Lu=hp<\gg2]l#UA`܌fAgc}Zz7>_qR@{ӡ_L~7a{ KF{]u'_)aM!G'DnC\v *6œ,&4JR ܲ *?a>L$mʜ(jzɜJ yxCLvH+JWnu`Sm6gN.yjkYV~E6 ;>Eψ+[0$|bSq0kEX <#Ěoxbpq8Iv˻=<2`M`ucg5i[K0rBVMsйGVҦ㴂"겶5lmb|SP7cV]θw@̙  cqma>!:uMj93*#TؼCCG%kto חRmiNz|G7˛)d(0^km0R<>DEZqGXD)Uurs,8ՑTuu6TllaR#myvZ0ۢ;z ş'Ludmq#Ž\0%QҞcrUjR~vsb\VPd-<φ'.(:W9ɭ DG$uemǬϷ@z6ZZ54՟R?HcXFfVeK-SaE[Q*v?z}o߂ ^;$yѳ U09Џ|mL:e(dbS[rLK(ip6U p?Rm_}AL4p@z]7H I}/Q)J{ӧ@i$C5`r\#u*E|UZD=(|ݔFz=x -^cbF*OPfE54!E{$J)W>=0') \vZ 79ErbKvׄ 'TUㅁ^Bu߃71-8})~mg% do3 W|]D.(>bbONks d~O~|wFC/RogjxxC54l2G-Dʼ/s./oT*>S&(+рOE$F$qǘ ܳOdpam}~+} cdEtd%!p; \5-9}$er-|0ͺmI4 {ukxdKZ=P*t!fD`bJ<oaqrjtEjp Rfݖܮ`ݓ'>*c0EaH Pڲ^ǧ&3TlF߬[o:Hnċ31x)T+F.B+秭'<[OJ|: 3e[67^tӁ΀)q6&dQ4emM7D%RVF n) /GѝIdϖ^*$ix|h:i tM*NpWfr:zmݚ"io!1Ak:4ʗ p:KBb sCXL(}ͳS<ȴD]<z|$8VQ'!uT 94PRB(DrgWTC1 <0hS֓+%jI uJ:`oܲbBaS4*.:@XtoO*= Ug%?5C! NjxBz0m.kuB@ukpϟ-rRæ_Ms$y]WvI^=3DžA;D7j`yj7!PfcF<A3p\C Ѣ@ׁH| ]8{ ijpg '˿27--ah\Dc9 uЗ=6d94Fcz&G֐ X1Xe])O7nkCkVz\ jwsda{p-?!2jjB4CWN2*W& Dzl:s o5y7茷C{z렄2'ȉw1b@cɅ /==Ae m/N@<ʘÖJ.* huԉ'26P-YxoF@F7?ztlax׼ 3C` iFUU"2( "3OwQnm*y?n AãgɛQISF@5dB==9pZwuU@]>)-.fYXcF6{xe^xJ P~qt#Nz8w""C(Ha C?2{90x&+Me U? QW]~z -Cv9wosK)'?,&oCĝykH|3&S/;M5ޗznrx5ݒ p.:s "ZA*6=юn%Y@״i L(8AaM1%fMC=3Xw tLOP ` xdRM]UY 9pz5g~)Du~vIYbAW|Re:qվgAb!ߙ2DM& *G7I?h|w\Jk8@:C _U[_+Gۉ(',M|Q .= {nˆT5;eUũMsfφˊp|NT˨jvJ:) tSȰZ#Q !U6+O;T(%'pu8ܓ$l͈f!r!ڭ*duDW)dtA&Td&sP$RpEE qFtAձ ˽](|xX(Wd;:$[%Nh2zIDIPQګ*]ʖn\W3߃֖@>Ε<.0XGXW`jaLH E(:'Ӯs UfPsPG9ط/3cq3͎GHF)(G\eP5(GPN>W81l(9B/@> ʜB1f^/8lYخ\7g]aʪ-fB佖4W>I4~)L% > l腶g|Y0H\~D D|CY4z gܘVoXaf|ѫPNI/`jg:p%*5u3c@&g*Xa[XaSZɃh<  ر{Z;r!z1Ϝy6IV#Ue^S"^5Hf}+Ŵ" ή!Wfhy**x8I(*N+dkƱnL $@"@u-+# ^$(QqL7|ьV[fgrPF $6ίHETӲP7:tVonf(F6"$]"#}I-}y2˳O"&P,42yX!0w!`i4D@ѳ2],gHj#ݾԸapiŇ77{\a1AJ&V?G LD(}=RSSiģ’0V-FEX0\MRK er%mb[!N莕Xl9:UT ygUpKD.Pܹ͘R2/߀a_BHvVnB?h#@Ah}K3@7@I QIr%(hG&H`/ AI>.Gt-ٌ738ʟ'˻囬Eaw<&qJ1Br|N<XUktua3i#m$[ 'o a*xYQn04ȌHAo~MbUmXtIJ*9nI>B\uQYRn0lqNQseR2,!z,ۡ V8!Ӆ̺e7mt6Ӝ K^$۶u$~9ؔOEb`/1e*V+YQ@&3GYVѫrD=\fCw]SZ @v/ꞌL/i@Crgp]K\=@MCU 1ܹه!]Š6FuȎjA?yl_3Ao#[N4P'1j[&3Ǥ@= |<"(z\g6/XYʇZ9aq#֦d旰q/JrMa*-1}^ħ%IAڥE L j`$]I8/RY=ANHWyhOh.Gю6HLS- a[]:Ylx! Bu>xľy'-͚X7``'t{\yӗL1IvX}3qLhʸb6efgȣAHHZ׸T DWV8MDDʔ%*EGfCł )ļ<\ ^a5O}*gR;lV.5l3-}U 1d'~9=b7<ݼ\6CK'Zut /&U ޳ȓdKQUYϹsLX?FQ&!5Um1o"Yi_%$ ~ U`+^4"$FCpݗ1O'ƺx9NM?zd( DX*'" 5=EslOHm۸g{*]T..O@O50BQP\ʤSZ)7WXwɔ(azV/Ґ∡3iKGLɎHhzm̹2p[$*:uuMrQA2c!2Yu WlIds?mԃ.sCEd3TjxuxF.p W1',B9V:nc48=7 daU=KIn.wIR xfl0}zT" f^-k3@Fog( :%ˢObU7TkP nuiH9]gӠ2xqp96-;G<摁ƞqaHCpeGsU'6]H:_C/3J}ffK{}ș_ ƓQbm!h yw@U nǎF.d:r/|O ߟ:pKGvYL&(aG2r$Bݴ0/Qzs͞>ws!iQ;#Nx>kTp\ 0 &a4mPYG!&Fa^3"hn؊O9V%7iL>i\z}zL}u99<>U"r/1;/-ktۃkHN0PB`]jE;lJJ ņ9G1g{h_(Mɬ7Nۇ˝oqlk@8/,݅DWc :M=7t-ds>%P=N>@/t_~(]9=G/Ô ;ÜmkŊ]*E]B2D0Xi x(q9K̑IcǡmWe&Q4E*:ƃ8\l0JϽ [kWm:7we:t-d/n0ꄅš V9Ք|j5Ӹk6H沢E6 9kϴK؝CU&Rc> Ӟ@+^6,PLZpq{dn, U}f^n2فZ$oʡ{Sé;Ea{_dK\ԁ4LFr'J|Ypw[橏su gAA(v@+J劼jլ!@xnѯ"UgꄟKO¸k_Yِ2l@@ [yJPȪa)6m.j2}p p5~O 4j‚d.jx5+2E Tl6,U>uw'jl]OFW![2KHWLq̒,1c!X&Xn \{g'X%`Ϲ*n `+Fx53qˢ]7{oXanQG1pswY?r@ eQ5]U%YP#rGH7lesC/83By?!^ns``+S?[4*O@g9lgefx0 Vhu'?W9# ӤvwQn+vB-8s ͿK7PMvEQA9ŬcѸV{;} "ȂE9迸|"Gp%ScxnS㏅&e [ n`-Ñf1&ݕ HYWo<z$v`K߻PsP5AԨ۩9SUMRg9 9$+?7>} ae-9=\9/RPYЈvtY83w7| NE,>Q8u*ol&^tWkCCk0at܀BIbL_I`K;*9d#Po]ے7αN\%vXa7I&G[eʁSg9|n3%/a; geHt|5Ol=`keZn*HBEڻR0sڐ{.N o2AN%$슄8ߌF L)gqw 㰎 0yV4Z]ƻ=w eDۥVixNQWtP5A{Sz":%QMU~K}!u!sa*)P;UGwI˟YK/gV8S$X_$.уj@4ߑ^ifj2ެR⬺o唲\ȳ,ܔaˁ`ib2 >(nmC c;XRwʻ&uC 86Fy硃#PIg={> {Ԕ,r" da1!M' 5ڍ'd .:>ն}>i>=9+Ü98dQ(n1u{4՞Nj$eR'jJ2[}[`hy*wezΨ -vȫ@ý|,CK:u܍)8YXhJeۍг.!7Ҟ&ajHgڿJ$ϯC~m+6{Y]ARe;jMe$~%/HϟT Pvх\f[A;q!lVt^YUF8 \Bco"m4!|GJi.1[U*dٟGh͆)bpM̜WgBUDgiv}d6NJN뮞sC%DjM葪MYv-!h|.Տ<8n8J@u aBE`$RIErL⻧Vxbj[GWm6~샘" Ц#"*(~t~Z1 777.'H.g1~Wf0r< n sa "&ELW[;1aaY`pZA&N^jrAʰxЫ6>l_lt;6 :/H={D埑T$-BL .cdE,BK.=WiޭZ^ar! :t yKw!//3z^$$:D'9.bgVu'{T/9<"2BO7FHnj3Q ".$NY&kߐ_ /,U`WI-Ege, ⾅E|f;SaOrc&P(|P]S4ɔy#W*^(<=CE@H~?fHc Sh$ay`t/8\{;8Xj'<]ɻNRrQC )3$ Be`ݥ콃dljw 롗#=}%>[ݫ}s\6Җqk3P&B5so4c ( t^nD,l]kׇu :>QLBu2gBApkzap}=q0[miΐS7RQ%|pM+ A.|Oҏ^JXnmJʊ r*t^gdH?'ٗnFˌL$#kinB~9V݌A:}JFB-MHa̳V2o0{zėxhpT>62w^1$#edWRy{p&; KgG|wt#r7e1,PM-aS}SNaL0 ;<.Jl>07 q4Z1ϐ+gv]2꧷:oZ–E!P>͢6 {3V^'J^j+5M>{$_jnԐ̋\SmL3L O:p5xRl|bQ3=rp4::hVuf/ʕB.6qҼ\z.ijredw$ħt &-.^C"`$[6]4  x晎ʎ@} &;O\QxXx$?2/eA 0{+VcQ\YwL79\l~R@!jbmA #r\[o3ۂp!fӫ.ƧCAH8RBjf@O0~d]V4T,8Qէ> u&&Qkig.Xސ p8NƱ-{cλD% 7}o\ QvV ,}EKZuh#rgh9wOGS#"ɏMCU79҆45-#n0h2h0jA7G{w:-~[5.a hQ_FF-2$@K/C-< q?"BTa?hԝsZek)R,c^a-.Hx)6."/|!OKՉʹA'lDڸp2q'4YQ_v)jcŌ/;c}U| x |^/zswM̬L09pM7O8%PuңڔC9EC2[Dn'TÌr *$S, 4zWi{yq6nIDIs8i$ ,1Ij\A`U ' <ŋO;q/ L`;Ӵ)WMxNnIѯ5ѭna/.QT=5>BH0 zD۽H(L Lw'd/.RvAԨc L!kўc%4~ח U: (^.73k̆X gn2$d~kkjuAp-KZbmYzM7C^mVOcmhJ%XR?3w U%$Z* 6F$\^!"@%A*-Ɂ,߁ qv]NB۱qxJÆ1D!e}:.` 4m#Ldc̛=1o2W 3YSma7 ;٨X%+4VlGDc̀xOGЬ!ݳy?);б:E+~h .d ɷ.˓rPgoX$~ѩqQ"'H*Il̸Z6b=`.ZTӣ# ͟'/ oKϏxt]֏W"džL4E@m:,Nd;9ܵ",v "T4)@ 4BM{جR,,/[qޒL$V8#(,Bqbt"ۗI尛=[trRo7㓷tDKu$i:`~ sĉ[KuڗMWFŅzu)l*YGK\*eW3Y| ]bCӥ䏅'B#G\Y5[*Dgf[4%R'iaREn\5fTg;9uS8m:?e* B˻^9C`\pt(=Q-8Eo:˄ b)Uޘ=xvv2|HJW܎͸jĉ {94HYVW]Vp҈=ȃ-61(M8!5}cLK뀙0FjJm~!sEv+GVI΋tZ:="CR\qEЀśLeVq BbbpY r%p+k"7۔Tnjlx>R't(hw4\zMXayZ~-S&I=u'{ԃ']5PQķjQ eS&̤h&=,p=]6e3hXPwRx`k4eO$)wkG"uAِ_T})}嬜Q[5ƂGjCNVC{g?YH\pPK,n,iߤiCe[ߦckeB\0l_\JU;hW&/*$ U["+bnimqAd!Bd~ ͅiW~'#&MáN-K맅j?}i2TŽkKPtj89RUN]~8S b-͉?_x/D1iXjCUM<-;P(%ϾOʔp4`w:dFCObPAD֘ U )x!ksMjet0MVQwCG0, ѵ<__lȞP5.@g 2MOʫ}J%|BST!sm,T$qB d *#ƕk" I/E 7>9Ԅ_Мh)QCln4*ì< g46޲FwrqmR 9s ˽.YʴI<2䆲TaDŽ@(:+P>2NϏ̓4bkx +]TJ! {,>U 4X(G9I1uqkS_s.= FQ:J E  C(=;ҁ#Aق;$6hcVϻHvao]Ȝ*$ 7AJsJq6qe H`'Hi˫nF8OQ)4w0IIG 9h+8ρRnN %)m^rb~ka d '6M;A5d!o ,&Cy* nKc3Fl'cYl`VɐM^ٹLQM@,ؔ`O6J"K`^3x(]T*SsdvZ9Nנ=CK <1:=`rp{ෑ֧H Ơ)U0sG|ܢU!}o~< ZYD&pOfk.;3[n7#,oqЊgc:B8ktrp J1_ws6Ժ=/$s1k6vK2#j!>QQם=akO:³'-!}61ĦsnsM0P"y$t|/gh̷AMGrv PcvmoNLln9ky:: q/ qv=}g0aB O]I lvX3HfN0HdaQ+zIzBB+oEStLnΐ(  y']Dq͖/uouhm儐\-DXj{L8V&]~|=.޳`;a(M?F5Dd |p(Ë@× |=jؙT AsFcztbE9{#xk"]:ԇ҇Pzq#T5a!b.sVK1CB~@LSKYy7' :y3*/)4eW=;7yGB9KFG'Fc4kgfl.VWn?%vo{T Zh[~ݩ?0O\S3JFp[W;6p?l]F3$䕜H(aN[u],DJIAnctu2\0!|v;eA&HĢ s+YᐒU,+Z( f F8eX@@=xˠ:Ӊ*H>90٥b9nh -wOkz[_Wb.-r375k4msxK+?ض(/lޗR.Ywe)&ُpg' 0Cyt~^(697Є\=󛻾n=gmc{KUhdz$J]ϺLTC 2h^\/j_"=gx2d :;HuDl<^W<޲v`N\5 {x4w]ǹ@Y$h.1Apwم3{)Fq ed`1ƭ$H3ܧaEIgP^oB7L =AbWE-ǁD?' &Xi]PLsTÆ8 5`n7P:]祎jF+kEpwwAal>7\؉w2Pkk(eĸFS<|eX}s֯uleeQ97A?c]hdvR5+Aۛ6ʏ[7|VbɠԠo< xѪFɨU/ iL^#>> 3 ;rh*1'GX[ێf Q=Ta%HS1~Wc+CѐN+"`&Mu$u?}N>G1iܿ̒ZFZT&t''i#z^NH z_S6LQH6ΕnSDu?;ՌS?OäMa&ǘ5ZlʊyVT ȡ56DZ¸tcM,lj>a!xgxR4ǃ^ґ6byiFw*(MQ7,1G^_]rɈYf -%u=bKH#|&˃7e?96nq<*3A&3%sYH0l8r./:јWycvT@#W.bE=%Ua /|%d`.psqIS# CfwX-Ė XԸ9݄nԞѻPg-~;֬8'ǟ267P}NgLG[:Cb(wgLl dRr[hn^CaB$,/d2^k- [FImO2;{;lWf ϭ94$e /{%3{phhAvr׽!? iVfZ1йR$gy{>f삟_Bh/3.y3i>*F/[/?8%B(Y<[8ήW;I_[ZtyVe\O<&٫b͸9^b]໘ngu|IN~u:'Tm}r|8D){a-uqĀDBjOx#W,Hm#՜QSdJu+ݝ_㘹#9'b3ZA™sGP{^P{mA縢y9D:կ=VP7mժ0,U`>J hKyh56&~8YȇigP-oZNĹApܥ7z=FWWB- 42q*WjG_~N.#&Z| ި( )ȵrcv1-rY!ʍУr C]S{,+,7rHlExuQV>̋XA n־&h tN$껁~F,f[NMy1в(׎P#5#~uZ=Zx^۽ ]57EU޺fل?S.ߊRk();4K:=I!Q1dxT j*0LCT䠇 Q37((G/@rZnTzb՚RAѐTv|1f[\ C֟f Cӯ3BœXhf~+jN6A}Uj~^cus~Hnku$LWp9#s[,C43lXYv6]\ ;٘b|ԅkG^"1pX7v'XCn.=ƍl&TN?&?~De$*<SU\ͩxQ[vu"s}G],r̰ϻVK6 ׃rtOTi̻B6{F%^R+4_.oد$l_ BC9>RaL%WB\3ήrARՋ% Y:t(WV "^k/i1=  :kkq\0,dz cZ vQJ*Zɲ͹s3_}mo+RQ|ok)Pd rBj16$#b  tOD|UF:}9J?H=HO^3_fxIR+IUnd|U͏$Ӏ}HwSմp_M1.} Mw6CB|\DbM ,$P;$0Sx2P0K?"WHX0Pu<~:`g3q2''r:@#م]{q6ܦUL2s_Ȯrp;Ao |M&oq -22V\[⥋`FMGs#xO=Ytӟ' }4dD;I D@VD%?@g@ʞ'ҍ|ߞ%(To Wsh{zNc6V]CaAwzQ$`D]'rֹ'OˮH\qX+/Y MB?m zOx~]gB+OGY逌99MLHq A;cD'D\LJ`0^Y?3mCף 5)#1]|;'d%w8mT k }34 zv&9@ܚ>\H\q=ȧi|2i•voZQ 2xD͜PѼ {y!r8'rgtJ&oA#N`IDyӻ9@$:_,X<#ޢ,3\i a7k )%}VmCgԇ'`xF񎙺f)*CI}>Qh?P0W (۠rq@}wDkBTk-ͫPjvJ{4O9ީЅN-uL~{\=Lnozs( k} ]}IxtJ> ޷n#$Ql|tcq6Ӵ\> /EB{Mu>&ݞ#ُDyl׷"[gDvQX>rӾIwYpJG  xURԠ#FbI(W3#L6k(pO/1N-N]cVqZ. ÊHeO5=0lV m0ě;8O3Dfq1졬7Dz2 dB rb*Ly8c!%Pnx7P %Ss74P7?dSJo}&'/>kDF%> UņؐuOf I6 MkM =npeEt'X|]-uUYo22hjGTjuYmipZ<BΏFyyxZڟ+@~>mv#|Fzv\h>eR=X,++EqiFZPeQ4(d_:DASxK cbODP%3_ :)V(RF)~*> 83Oڛb+݄9+1H:x.V|d7,6t\$`U8v>I9vQ<t $|wh r<ƧDV*K%eD0g/:6ԕS:}tpψ0|&kY,D1,;f2aHK : KNoء(H ~6 Rb /9bdTG[n; ԗ"gL0>H ] l>Xvd\C/fr }Qė-ہy *zoP^^aX0vC+U ]_4`cpn'ng`B[Z8p)jaTN|gX6aT9Wjq#el㢂$0eǪ7 ,_Xka;s,F΁xH-s4d @Eee}T-L?sDɉG#[ &׾PW{OsҲqPvjT(2ʰGyڣZ;-B8 kf6 Ġb$*@_EjԮe ! IEC(JsAZWTU<v Kݔ4hÿ͜} Ε2Hx%8|Ctw"e ׅNPzCU\(W g§6[Xv}πߊ#kA&< AZ@ w1)͈`}Cx ,sM-o ¨~b #,]l$"8aH^{{QrBZNGq] w|C&22r X9be=v_CDd*qB`('Y=7 ݣ;3$W hY‹,t $g@y DEX-8ҹI3d'$szϻdo]Ԛ&n{P,R,|mVq\#Au,zjw+|w.VU:yDr!nq¤)]8 brӰ'տL0i \妹C+)Ɵdh\KLAꒆS^Qf"7Tf~p?XAAPd8; VMiqh'%vNȠYVz8E1ܳ ySLS~hySjcu ^ ;YnBo׼\ro :NE |ϰ%KcO \#p[N2fbigmHZB%014 b=C=:a+loVNN Bs] kFTJINtr朤3X{'2 0+^nxHee A%s+3I+<;ZRl(c8,{Vq7:t;',seb\7wW$x^ZȊ>vԑ}+:;gγ1ˇ'-{&RL.&Het,O.#=ov#Mlʉ 37S3HHaZ1{B(b4:gn4^%GmcQ'C)5&]|r u#WHlMI.,Wq5U8M 'Y'4kU5,.ʃ[X&pd[+wg"]t&}҃#Crd( I]M#v={~"pf.mYZrM-n;E 6ãW#ep'M6Sm)Nxя@^n6kEԒ!VQ|6#-`y I\]ە@QeP5RaB}n.f+UMd y+5uu)͇*6K@n+Z'qtҸ vE` dXU~UN<?<Ƃa>^r~=7H4ƀ0xYBTllH~IGi1QY;4'47f]T4:B&aFv"kE7Qt<(s NDs33i/Gs VYA*si~ju}#`8PhFq˺mJ͟q=Vޫs}+;O>ZHM!|ta#/yCx4)|vEIO6Qۚ%A=Kuta"ׯs: |flp::Y\oSIwzRpOMZ^ӕon8l ]5%sٓ4J 7b05`Vqkᓢ"A7To}XbW;>A)+>jSYDx44-Cv Qs:V5 ]h b/R0Vor;Q ҐwIu&#Ba*R$Ɂ)ǚjC4)P)DV"WEjΟBN0zp%D lðdd%e|MRzsJ, NHs;恫[v%PLֆP}DYd3oP:VC͚LhxP#?΄3>MO4]b:h ҊI w6 )9ڎ ,F]JTg]wia )|rO)$^ rR}8goy\M Z3f bU>bs`#:JǶ'}&6j\ÏU[anZE/F"vi濵}PdLu8MM "jnfR;^cvAwm{sÑK^kDV6QpփV>h6類&(n/ g`]m JRB(c^AYOp+_ݛƶ[bM5-F.;΋0O=NZ mB(;A W)zM(@8XY8DԃРR21KMGUdc@7ȗlߍGo*MH>R` |J/cNp5ފ@P^ImvxT;{Pu&|>7)pؘK_IN/= f327` Dvmݴ1ȓnxcUh[F29HS}C'gd"!?c-V^nR[X@?wkM 墘#f#"+II&ܯʽ(ajf*gfE*%%,OxE6w\gT`x.w3k]FoNS{U".pᏝ]aBb20 B]Tx@ SK Z0z@㣆2'ѕ݁tSNJLXO㱹Lpq tҼ?qy%ded[O+ :@Mi.@ +Em\ XΝ;?CL^(C v JҐݿ@ /;<-??Dp M :$OS%I(ת`y/Ę"%.zg2gp:i w%4yJ'(9 Oqu@dG],e@;D}$?>A P:5ͪ[>uuor4<ǛmʰFiV y~.]hy Sa #~eV 0j8!})#: _*7IHQ}4Y߷/yàBKD 9, lMO:@߫ ijw|bs'K|׍lXrM,E څV1ۇ\v rlU>J=<%XI:CN_CorjvϘ>!wF=R^fk|p,hנ2ZZn.XS^4 he4~$ i62a'ʻxE牿FDa~kʶg\e^nȱ0w+S 7kZuJ\( 'y9=3%1R0v XwU?d!1,3akܴ`^R#BIo[;V!O8ڰU5jie)tƓ25{-B-:}3g5"W1Dݜ⧀ ={DXY[aBC"^܇o J 9W!N(+ߘ (SI= ,C+ZjE KNHݷcP%ЛWl6_ŕ:.es~ bLՓ@=g:fQDWm j|݅bUJC K2=MyhS6 kwz&#\&MYUɊFQ/#RA{ԚE{yXv` oIFAqA5c$ 7R]# #1]w poUӯΡUbxn"C|`R*ݭ Vrh}+AN1#LxAfT30Ɋ䚺ȇCt] `.#ӀǬt@%O+ L),mhb-vXTT.ޫJԞ{ۤT>AAyo@NUl+t%ݮ{B FH9K@L*U$#W%Fki nu%o2s4kn?i3Sƈ tvP#3+Bm;D ZIK yK>MUپ;T땴?O-ǖui[Xŏ Yn$b|Kln'?)ebBNo.}ظΒM0bO4ummQkvQ%Ti90 "&w߇Zbkǎ;+/_o vK> g_I?)0HscJbɅ`A=ʰbDy.e1{$G{}ĉW$}2T9JtiǞKMVysG}:H*8;גxHzr=%} <5AQ m)d j6snN^pN0\*P,/>=,=18>4'PH^d+cםcʋҚȡZFd> u8C]UNfuoD DY`-5Z_+SydIx~n0|֛, DP Zh0c"?/+wo+]4yp&hk"X&5tpfcxe[6%(;OHbNs0>SG<)ߎ&{LJBjih*܂)-<[ Tzh9-I7]U' 8 M> wU0B/-kiMs g'%ctuÕAӀB']u>޷ BچY &ao;u- Q?ylEUyG7z *< /Β_xS:vO^lmzR1.k=k/4Lf5Hn7Dz"K3 pZSHщKO|wPzKe9Dz_ٛ!Ez;D;8O.D1ȪrȂxZT X[؃n ~yxRE>5z[*(}R6,?䎯# YMd 3rYw;/Ӽxy;\U`7S'MZLG1 -Hk5g*u\}0Vv ,>i34-pB[\'` 5wsSH+$!/( 9>p^,O|w`c3ǫ-x4 0VO5כM$YWPz3_b߶{%9a9_8)OgW'ҹ ~ҾũyJd|)ov5-C[9?Qڧx:jEsqSYNor{ЄI۹J'@R=kLOjNKǫMȕ[߼o"/* k(i<3 ?vAMF##MjK%tc 2h\ز~*Uw|0 bn< n9j=>*Q˃y*VQ;D/ԩZQ{.τמ)?1Ӑ?It*DpNޥ%*7_\ZEZk`/n'aN|/2*iFn24*^ō=CiwTcE .»M LuSPF](T0|\.f;?6Il$7rb8RAnɦLZ[ZSGUJz^"'8$XbaLڨyE3L0;wFsπDfiLċCt3WHXj3+C\,Me $N]Zsvin t&DX`w_/+܊w#w'H+1 x8k ;ŝ@ :}B4.\#ەOxz@a7@1P N&ƻCcf˲ ;=6pGoszGMii:rBmݪcl>pNYA,]4: ҚvFEv)ж2ȣ &oeJg"">9j"W!J6%%wұoE{Lx0$#Бee|9&*kgzqx;>:/t5y|4m|r;b3.NJoQY̋,nW~vQ? ${R E~.9yC1w"ݳqhܯ(yz\NP*~#}A), wP_# % і,3=Ci3ZzMY-[rr 6V ݝQ= /?)x)Y\k"I)zC_ᩭc&]kIn]y I, 6n G%`"*Bn]rfWU)p83}-_*Y8VB!]U_: Piޝ琞!(ȑ'Z)G~&='7sga J[?a=r.shw(m4 >0Q|R{M8IqKbO_jX5, i(:nG"3ÏVjƘ> &t7IY~k=2sq:ՀNm} zV<~8F=֠8j;j>_B*5]u9y0]gMvIez_pjc#n,FLlmPѴyJ\<⾴dZ#`}aRx0 BmVcjj[*fW52Po`[엲XY2M3;G (a需!\ӢRWRF,7ӄ1>TK^$``5u'0oyV,ZX#JB(7I2\ѐvQvFsby7RḰ0ʀ.E¶ou^u5sĤTX5YAe.c<*8ߣ 1ސ*`s O7 *QP*S87sP-n} n6J 4 詄Ne*+ʂGƥ_F療VL \q)FL̀rZ=v# ǚl]N*P蚵/P{hye/m"s_ \m */ R-0qXĆ&[QI#c?dSNo[)~Pj~N"uuҼQ)Gf ds_8Y>A D݅d0G=uԠ!IAFXdvPz׿,_0)Q|)ay_I,&{L"R_} :qp%W?\]6vG 4b NLX퓀L9!VzGa9I@\FuC/=]q.w!(neb!YlE!XLQ ^5NFK5q'D~8(1v1&a?z͆UИ512@- Z svai!y"mU2Wnox%i@oY%UzZ0 lVCJH~Ϻ0q88:1Bf}U6L"?XŇp-m:IX~("JڝMdOb`!,g@0,/.յR%'FΫZIuFnwNNAX`rDi8H.E~C:o;W>nQٴ+ӛJ/oOΑp;޽2o\gF/n=u!֝lD34"'6NSݭ/h˪4U@S-h : 9h>?( N.l]G 2뚦zUKڏpEǁm=\/[ -𡾮m}q=IA QVN-JH^ÄX@p!5W*BICW}< t.WSh!o5pT&RqJs \:[gC^+Cћ,:𧆜KvCi!mo<0&FqǦk":Ӄh ǹ9=C9ృq&;frL{%q2LcLi%DzQAZc(<޽vvR !6u覗x5ġ"062 1lU6t:5YS)5;ЕTE鰸%s~G.N+;H"%@7L {Y:@& 1jFLR1(;H?:SGJK,ZJtV>v;A򛉳ua,3e0:s@H->5nEX8ֽH[}b+i\^|;?\WwRJBZ4L-hqes U \H1SDVXrH/Q1f$ (GҴ^; sb 9$1\k))dIm#/r*Ony/|>ɻ3S܆V#XX=$+3λ~O a'[dcX/+Q/8M6O< vIW۽׻~9U2KJj!1Ďܽ?Cj1 cg57InBdrâc^5RZUGԀgp=V4?'Ɓ 0ܷiP>u8Jװ^`&R_P-B{)-"&N8C\ >?8qԕ\Y5D+uH6<4 { [ z8wc|\ޣ?a3%av{ȝK~ţg/qHAx+DC,,LϾd٫C@p/}`*,P.㋡K1KՆov)h,51 W_c, |;5`4]3RNv|xL_Eɮ=cE8\~qf\.; )ٞ4:;v1<2Vaf=)\C!ywc߽/:6;zqE@.Wºmt*ճ4;1\>ܛMRjT8)7J2_fG59wIռX F`d&D=}{S'=0 7?F}F{a ?bPlb:T6o1sAI\V+L W*M0,$31q1i4ιt 8GۍPw'Cp}hi6Sycl3Z+J|O>l :"ZʻbD}8h4~4k(lPRh[  N=%S wo\6KrS#r l#Ao!}/ [!S <oH# &P6._Kh)ԕd=xm4;>w|S[>$K`Os* VuT(/?0qDdJw$%"TӚv!Y5|Ym꒿w:4a"cy5aGDQ~s;ݬHԷ`{]%-GГӥIՔt uQA5k]D}OntU>.,iĴ`Ù'<1b lQRKzˮ"`x1JUKiDXn9fܶYoyrӦmh:ܯ)![OJ&`~qFA"c#;;6@q uDȰ- 9Q7_.pq3[:-"6ݢSNhD1Jh B,\YPO =ⱈv G1fO5=ѥJ# Y$(nÊ7>3E_nr3Z$بByT]MJIG!/a5.VU%5^]o:LC>6wƭܧGKJm[|fRXSo2x3Vf͂m7cKpl{&46fdWK(] mAUjլmS3ҋ2|s:*K!:e 9k@6֐EC6л/v2vp+#@庩^DU$+-ZL*&}ˀ{cş{*mojiTT[>v4#;޼+<|X-VBRt ιz2_OaeYS֍a4H\yMC?'_c{Հh)YAi9AgZ.PZp &8ҍ2R8BeW9qG-#vּߣ&.tO .WS:mf7zmvk63 w8NV@_xB=oBh+j6NH Y&0?>s04!xO#齻?T'n^Ά]-^SB M;ڮ­4!nP4JI:seo&d.:ON}=uRWm\)É9=h?D}nf*_3\w$4j5'|w$l:N|Map`nLsPR`7]-X.&EqƜsp 3b W pOOLTN el)| 5 )WvA>3<%)½VhKEi({HED!ƕ[F^8K զQI 5$3)I,f**r b(~mLzby/ў6et#+!tGIVxj>!Qp{,I tkI>i1=QU fK MX;*D Y?gTəUu:3Y=P>w:/㝄ƛZGXN$&c]WR#y?YvXֆf<'ʬC! !+J!p[Ĥ5S>ׇS$CϜ>}Bݨ%ȳq9X;s)&EόcY0}[0¡g4] s79X inԨDRf;kZ Hdz!.(,eҁ(XE_=fBGPhK(lq+2FubNӠ/O0V1g2"uxl1<vx v.,bsdcd OBoZILj0]s08z٦uKLcxry*ma&p9{J$Fu;O5dh/?UqlHwj ec'y*)SSYn˶(V#*"\ 1^~<`*DcU@/OrAwVy_maT뗱ͻN=?F>WZݫT vչ!)40e'в:氩{ڇh{V :lRb1HN@/ع; E =@Ic@g@҄j=./W}L"Ͼ gGDv$gÝKa FKm. B~BYSVN\t3,Y0gjr [Il3x+[| }t2ǻ4/ yLWFW~y Cykp+rhh5|2߳n怬SL7Lߴj\\&@c]P)E}Rw.c8TOf9LOyIII.taG=y(jp?a&yz;7Js7G `<9rg|z-U~ΤȣNNq4H!g"WҶQSppAp @ 9ɊfcF~Yē{5-εNc^ |_v >O&wslĈoex/V R'fsMtKzLs :߸  g%0[+ƓFV2vE MO0 0KQ%̒U2SGr4`- y,`eX?=? yDgg׊y9S;VAwvir% 3UfgT;+7k|gHS}>Iǻ-CePz g9wƧk*#L +H_x$y3\&b!҃ܵ{ <.}h,j@CvvQfHΝg˾FQx$OZ/_,3EaFAIwxЅ,$qxJo0͂CqOGbbr}}4~ oy_\t,y֝c^z)};o NEH^|"k|J/snMd;h|"{ #- XeIMՈ fFmXc4v eik:v]yE(>q-s5%/T)cYܒ.[&w dǑ!^X`NbĦ;ɂ*( ƨ?t N<)Ͱa ɵr \hD"eш~ό oX( nE!]40"s 32S'Mr:` _SCM-L+u%Պ 4);yrf̙:pK /0='?-aʀYѯ+ ϧ B]cwΐ>p/1 utCEWw l{iŜk" 1 fiǪnk0ya3* +m*yKLӷI>ht2\)7vHTǝl-S`m>me]Khԑ B ")"H WFƜ\Y+(kM/Ez52 $# e>X3f岂&馦-hUp>!Pw2kjAJzoQcxnLn{~汶OL@ޠD4Ċ1 z{V!HP#T [NX2p*%w!xߨ}'W$0u,)$T@ftHńX5-r~!p撖#pz;Rjj30B|{%@j(ګ~Ӻn/h'f3&(8ӤiDIM* QNfX u;s!Bq.AE ]=2'm@ՆeJq R}G+I$/OtevG\GY'z~"  BY$18I] t,i Wa1'guZ5,-yxyhI^U 9N2)x#Uv~z2П&M;A >leM)zs?й֎k洎ݺ 2ʜiys"yL.#O6e?&C-PMUT{ gAռL;?*Lߺ~E=.ZbRx4aaـ?#'{'h]G? -5_GY`(8!Cuk`֩- =F7`]^a !a+DG 諣_"ijۦƫ& ΰ:fPSU$ZryƵ`[~`B](ԗ}'i)vpz-4G`/Y}ހӳe׫z21ױAa&ʪ7OAÑT*ˢZ>V.@ݖfStRw}@8v39օ(Ts8ݰhl#Fu9W)50ľ|TS+q.D"FBz1զݟޕ7|ӿfAI cKIgs*8`%MYxu1^ΙpO#K pdd8?Cp*(,JtF 4ڦ7{*/tXd$.#6ό/_HY Cn[  ܘr35?6^XuᔗBXr l3K>gH+zG( :B p}oAi֋XFٸ5}&YR/Hp3YDkJeovHA+5ZfTsZ_ -ʶSQ@)=sbL>Wx4;wZڶmo>m[9*_[NXx-K0_Ӝnsu5d h!6D>Nt[v?sz[N8h L{m^eGp}*Ӻ  <[ RpRycJb kޓ0wxen@0bÐyy0dmzbeylW+@uSٶ2B̮*3\/uJ&]]E`W?t&n475~ˀI}9^HܙOJN5T]@] M8smu<xieFXX(BrG|j!XR0{زD б.{KD ]YQ7?!֩QL7raȢ f`'DMFfsWάOz&q'{P uۮvlvmW8W^ug%E%/.P@2 szuXJ8w->)#Wm$-uhkbdBBc5-{ 0Ɲ.JQ7%AP = M9G H|Nw6tkJu+3ن +e2qPes@MG. &yS03 }E@yMr^^"7g.:}/3[MݟwQrP1Mʙ)іJa4R~Uɩ=@0P|b^IA?1ysAu }g@bAK!W2*6 E(6AS&8{~vY\7ٌDEg xHW1?=a;:ȪT`,Á@X|c#\5ArKwQ2 v1 GƤ_~oyYD6ww]u=Ï߅;iVI^ŧGZI_hz#DXȈhJ6fj}aUTZptˬ_O_Ja )w1l}K<ljI/ldrbB&HMt_Keb2 SKoOٯZVtQ祝l1l!ť]Z3?cڐ~mnnx~Qy|;뒨sU 弃%lp9ëx}/#O(<ۗ!Ub{B 1b+t> H¡Io+˄i^o!E٬}HXPB(yaÙCjP,[|CY.)r٘pl|pĤ7Z&ۿ,]N'\@EdB+Z'$mָ; 9;UrTa^ (: `ଛʘPf*(eɩ oR.J0:3%'ħXX[#u'\^X`H=9NѣG{摝+LWK  RH%XC̾G@^fYX'=K67qKűy3G֏"~ޱl3.“iuB56eKxT֦OadpހjvD cgߕCur]>A6􍞔A}PY\&)HʁP_+, oV4Y"lm` Q=ŭ0ZAPF^.vLz5˘^'Shd;Jo!wE<&ÁILKGV>:_!IO)±P67|FI|m(F|\u7-ƛi?Ԥ'HdPb`X^QrdЬ#Hz!N|߲^TԿ8&h24KBqg,ZRQ6ȅD\+.g>@_UL"҈wZ!B7l|vUO'% [m9'oQb5KFU}dU(flh;'ٜ; Q>[ ʋUY;KpVƈy-Kۛi=qyS iSm_-P Egm2lis%[`9 *a|W`NLKDm7Oo+"Ƞ7##y! HQX*^7˟XnNp([ɿ>(j9`7X ŸuS'eb΁Ox3b< Q A0mLLy6"_BR k]~%e=nGd#PFzfi^p]`Hvjv&YRv's(l:y&Wx-2X6jЬdc+Y@KrQD$c?/G.{,@W нTʾ@h}T)xЮIFB ¤q |moQU vVznG(YSE|S6_e< @1HOé0g(gM0!1+; T ϋoatu% A#Z`kSE2LWєT`N]0g dK堘?oP^_WW/_'~|:փh#V}ݑŏ;쭡::Oa*k,פL!+_ڦ񱚍&2/K&OFʍ'͏P^z~G HsiCHg?f}>g3#-b?$˼)Tu~Ct. :qBNqe/$]nNȤ7x-l#$!E~N`ݖ / 'LlQ. ˻ HIq)PQ1X |&P_"yvK㨳s!ړ@!5S;`stY:G~&cjUyKdާخiFؖt:Lӝi]9i۠g7|U@mR,|>mS7szO( emٰSu0xi]BO&סϥAeiT(3OՀ oa = 9:JnD}9u*?T7qe{|%50rwV1id5eo_!ix|K @q;L+}.z AF'pD&LNh]=T >̬R{BfC-&kܷ&A;- ^> tP.,-],tC+$+}[ӓb/k0Ζ#k(51fSd}T"O.9g}lU@^;nttGIHM>%pS -aB_k] BW*\ϖ+wM6s{+Ƞb5L&:.*ߍ)7U*e̦=sv+I B輩Qr(=чVYѣg/3rq]ҚJV*sc&1S|s8_q~׏8qߤ#,4:V"VMF0ЮV|T D yk #e5 ꤉U$jrX'R%F/P$΂2Q"g,ÈnZ%7iKٟUevkOďVӥǃ#@P]g6r@ VvS$oD$1$w c\g g[ M\q'oWJXƵ#d-5eqsf.缼ivhm.(UH-c< +puyuV`97(gF&yi„;!f3ȟy7RKH= PýͣJҏDtWnzEM#ZmWgĩ-ҭ/WT@RPY[UWa}?)/Έu5UBP;2%mfgdbӣ?}ߨ3LPaJ`Yj8̛NvM縆퐻 Nee6k BuU`_NJ^eb<3YѺZu;אp VL"I78oBa? n"\Q+9Tt0 l~FPwެUWUkҤ`GPm%|%fǙU  bb$.ݣ6FJ t\Tw؈3(V]ф 磻EȆEOZb$7x%B&ŇgЯ­}ɯ@*];AJ=#=B*YP(ʇX%^M'>bDݤ>#́ws'H#4ڏץ^(5zslY?f8$pd[U DQ s tofv|֦݇vp(ȼ | j!e0oX);5Q| ER`:q#, |D90!oS=zXoTy~V6 .ڧی}?DM_#'W)5tjhXzEgG?E>BgдVhLu4;%9 `ͤgqr(V aϔ& L2̥WbR;eAsÐbknX6>mj/H>@@am4B3>gkZfJ5Xt@ԉw]Zu~3nDމ(ppya9#SVyS?䶷rXfXU yMDЕj$PpDDH9*sA8=OH%!Zo) |7ŠïU%DyS]>^G27TKh-X+~F*L\nDD{9]챫 py?a :)U|( ;"Iu1M4{yݐ2K8792ͭ B+PQR'/# 3N?ᮔAg38̈[cDtAc~ddpR}[og g`:--i%6%3&R {\1|ag]"#t8UC \0!2Ne /] ߖtsBCcIF"9n (ab;23*Egq/Պz{qni)r)ŞmaMu<_i^|rVa"+,217ZcA~LϢIge^ bn"l/`Is%QYphG5 +@ڹ~%jNs7 ʃF[孰P&7k nvA{ٍ( *O6cրteZJ? g8weV{#1֏@/neWt\~qnsphDgjhH|arKPB~`9"vtclg@L8- ݦ*۝s#j|fPJQUaq/N9xVd/sM?C:w3;g&oekiscv"Ѐs [Bʐm ΍Huz 59o!v [o4O[ly3 'mTZC[w'be0jo vΔ޹܍Y^:{757 {{\13>[u"z?^f-^S;t}qca\j{V7q [$ Lz}|L9ѷl?}Ԫ?W zFu:"GT(*, ^ S&f9H, 2o#̯ d1PMп$_k4==+e~L3 ġe;΂ ~"WQ Q b(Xќjm=-2(pՄYڳ(쯧iT6ε?$+*TW$ }սS9ByOkא|4boscc .ڞiMԯ]?Nv6v|`bOr1(.A=<H&{d=(cnn9cL,Fjy?mqtx3)$@/ȴ;˴H` τ%Ro $GF38up+gvA3wHfJ;FZ (%'[(wd0O ~Suq-I$ l &vgg8uY/>FP3;[]WFډ'[=.;3V\O43H.U>E!zk%ݜ]#B"%6BH*j8Is Jc,?V|E_+aۿ8;'Zݯ/q>Tb/;B"{p/!jח._|2#QVf! yua)Ĕ;kdf%\DPغITafu]=pxjohd`%Z twv-@9Y\|mw3|_>]6 Wkί 3j͌P9F-RvvEs|NQfr( R)Z|W\SIzoIbkZ!}>0V4ljy6~qMPQ,\I.- \P m~PwK@@(}ؓG+q%GY'4Fb;8Nr?9ѾTk',Bi /iKvm0֣"&hҨ6{4w&JG@u юW9M",?Erߟ$iP` EF"j"93-.=Wg!}T=?b|E(`u([h-؋GQfD7+QFa8:MpmRyRFGB [[$c& ~1>{/q)Hb"ljf0f0da)` G }%2P(nVsF\v)+mʔ;s#nyKoZRC/L;؂T":)o.XNaVDO;f6UK"ʭ:$9˫:WBfsMwjr2%DGZԚ!lOjIu_I痰bbvI3Ѣ6jcG v0M2ܨ'RsCeZ<#7n A)? .I%66oE,q~VyZam`j F]+-A*DNnĀ&~]Sp`Իyj:)o|3 c' ( _)J|x魢U%вchL"-XYQ>fZ }B'!ę.wJ5&5q>>NɖE)VZpx+>(Ђ*Ľ'x7p?T##sa1эC"{4ӱZg2-ޱ)0]MQA-pV{_[rO?4y:"@s:XC[dh1z듡_m$4z\s. hAD` r#$_Dvr&shxwͽd#$1ҙKL[M?9`i#$d`7zN|:w亍<}I:xЄ ]NR4] 8q4U], #'Haӷ15v9Kp۞*}RŝcZqEZb$\`Q/aLK aR!DV2E[ (A6WH >xHm@eO& Jd~0[B)Qs7wPTI6 &;"hUm }OqmX!}8=oD ٴ"@7jm+B 픡+k!ebAbO `9=*yPw>Y:nVck|!q3pwPKߔ  X@˦~`tɮP^!{R->ȏG p]3y\t~8Sn@5 oRz-#ES&T @3F}iYYgIuV !rIgwm@+_ H7`g& Ok`p@{<@FvG*aaՙb_e< ['1S٘# R Q2RSAx@(u>k%Jw89C]QF(R2Reh3\; ]ڎH93 |Z9}=eN^笋~.Ԯtb EӾJ<ۥ hHxoBo:9fd,ˁ@1vPoV0غ^\xbdz>Cݕ;țH\ &]WMR>*w:m'iTNrAvNvqϡCarZ(G9;#/pi-yutnBU7K }{cu#e>˲\Puz 1%s L ~FzGbg}``#:P7%0c]!H Ѧ܍`n $J\E oFxyB? oکj3N]." xlFUս|a߸cZ|Hb[xK'cXk?H_9x夊mrfډ’S |un3JRGuQzт&C},VNxn6}GgMYNّYJ>_ w8{;8IP.dvmp&=Ty}J> h1.2IVπO"}L b*- Vܾd5Bq`BytDKhƞv EF%*dR ~IvɅGsXJ(ǘFJK *gy`"!U!:PAѳTx8+hx'NUitFnyfЄSYU\Qga yk&Qo!]238bUZ*XـEQzɇNC|g,z7 &rOiH-%;TяϟQ7b;&$h~$%S;[18zu\UP2x$ [pHKWށۚ"@fG6U=6C];4w[ł(Ƭ@g\@KX86Jr/ L }Q'QA&vcA[;%IЩ7Ӟ}{r`#]* Nܩv@!c ̯x!Vsd :X, Lmyo!{y痧7l8 ?Йy綇99_eyI?pBZ5dmh>)jf8t/&Ήyא^PPѭRkr7838 vR@ǹ|xl)!eGI_5b݁Lq P)(updA i 9L5SLS4ߜǂnla=zd$1]}WBYs`΅eaPS \wOf~, @/ #UmFLH涰ĴB%lݺ3m? rN M0.sPBNTqai]uhY%*YظpBzQh2hG 9Q])+kQ$TV,b|{ -$yCP VfhPRkO$!S`k+zl'֋uYRǕ$1!:C8pW8nIy=n"s>StrBKxYn1}1Je(bbtA2 zO_;uf6JwRb(jU+a~>`۸vxHB ^ǁyƒsm*w߉dK}g٦^.qߨĬQ@gaEu"i -ǰ%#~z'Џm#K:#'Ж{hv}5k`Mn1j'|qBurl5<<3˸+UٛRSĮFW$-0C Yt㽠 I>0'os褢q|`jڣ -{Ow 1ER(Cdu(:3{_mWE7L]֘x'CY~rnvPnGq^0JpnZ%ci(ßEt3 p<+lG4tG] V1>'~^M^p@'uylxa@\M5jm*oSf_ d=oWE8Z1Q8jwfL4(?܋뫂c#m Λ5̿,*D!;woE (\OyM@LZdǝ"o 孝'G2%;`ڛ\)k U\P ~eHmM@r֢6cv"kwP0Y6-AҐӐls>?iJGG$D Lz9<8RI>\RO7ۆi@uayD03#t `O.JN}.4$|ؿ3YypB4;#1AcƕXlY.3_g;` 94c2-Pȃ&дqYʒx⪘R~`WďuH4mv@.dp4bY H$f^f-ɰ z@21-ZSP$s]fRF J1"%A:*!w d5w&Mk$4IKS 3Zoy֨),@xR4>P\K:K茙- @S,![^2ÊTN(N=6M*d%3d3CpHB!|=J&89l[xM|xTJ[r8Tgi"8߯]\tvhذK4mha?(3Җ"6;5R j3FԔ0KYT^(F#Brn%W6]T.⩟')%tec/rbj*D"[m05/{PdXڍռ+1˲^[lZo 7(gnޞXG͇`cZԚ(w kb/tkXz\ [$֝B@ւ_-j̕O19 |$@6wԽ}*0ZV_GAW3Dfg($+؝ xs2U>4(Ŀ]k˫{l~{tR %D pqͻįWT-3̧+֌(ςz. g~O?::XV)<0X b$_ iO%ԣ?|^Ttqw`P]e&J[0<34-U:`y@EF&]ͣnХ,.#yI显_u@o6:Im68^5"ޠ''-H~?7h:*.a vYh9 <#Ő13OT7BUW҇T $Ӂ-^V?Z!H%g*DG$6K+6k5ѿB)L4O! upy8tBL7R,|w;VkH@G^FkmVtHŵx'{٦j λt)>uҐ*?Fi>;Noc#kFkBPNLqBixUtj/\/\\@$W ] T;J)qy^}%uz*\h1Z;R>cG3W=~ |Hcޫ,m?KS'r#ۘE֮+L>%-(b,,k?Z{lRC3bs:c\F"[A~m!A^ԞrK\x⏤ RzJ,;h_@0pkZL9<)үt LÕrƕ.U,,兀G k2~2t鞎&yhT呦}yM X1{3Qv#y{n.UM2NPZ/-HDz 72qiۂ^XӠ *gXާqYjBclĮ#y!|CSZDT/ [S3%zY^oGBBD Fa!pCK{|4"CeR2]GMe 6E7&Y& )| S uk]`'>Y9 ^Y맲tHyqum8Jn4GB#S1I;6qàVdJYFal5'\rGN􎜵W F8=yb5}#nm`3-hΏ^ar6?;}8"/T_e5 [A/TΜ&] :4 |Ixٻ֎r~P,emC$(!*مSIiA=Hfj;&fz9^:(ʄ]YWiq$e@ɹ)8xLxA=JmPdpo{?B] kT6Z@LW;lT,4Q /}ܔIu11;߲ۗ/aNzJ;ΥVOp@po ,n@77Vhjb[ )ռyf6+N^Nd3۠s½jz^"oÏ%5ƕs>ő)S,BCj_y 8c6x=ƃ%,a47 7xu9&93M'<2$_ɯ5 $_eAC~HX@CfOpԫ!j\>065V |!?\ '4 %mo=!Le׭+9o.GIJe\F ;.EQfRU gۂmٻz.N2fnXLo,llkxq^_M[YAZ0S3!3LJ hkoΤTӑ1Q#j.E&cNKJdTekgX[D70Ϗ-$(Z Ho}(@'HJ#1WR辐|7 V&S, fe&1| ksx8, ȆZ޿FayMV#CTv2%&kfRTIohC2JY-: G>M'/^$lƥhq\0#送Z|V컾NClY M2me X+4` ]+]!Ȏ=N`R {?Y+țՄuI]0įX¨PxrO]!Z0 7D^·MH:4i?>+XگqCF=yVx~"&lf? oM@r`xd""u hkAmTҝ|/.cVɁUlƒ&\"%&pl5YO?F ;{pډƷ5}QZ% E{~tT`kj.qu|6NhLq3*o~},4Xt +<2MgvSq,T$>D6Ucc#c? JR^mPܒv,=+9}Lo*/,_u xVV IWx;A~c>~RKާRlDpQF&} %I'ђe3#59C}hFyzkUW9gUGZ:/Б[`3LiBfp5*\D 0%'lQj̉ma4+ aLnj\+N5#")/rvi*iQ]="bC% vh랣XNtGG?ԕZeOsEXVxxtӐ[C2 b=!.ZV{uY*k&bhQe㊪U=>32b%4o',H;}j>* #cEn,x8&5kQ#K< ƀ-UwZZcԶH##D}'Ћi3eD_8Q@XbϷZMzS& u 6belT˝ ђ˨(K?SX+wSIVCri_xYDfc{lEqBhw`tOkup2!j0YՐV[:FKJe4;퇀&PEGJf)@:SoLK v378<+/ۇbuD=ڑNVJ>&b*,#8▶+n턅ο%Lє-W+:6VUiF>zGFn儡VĊd\o ޣ1{'-7Xfւ=f:)9@1_YSsA$f-K vd'Q?:p@qtRz?@7D*]u =Vq匉5G18!#do~0,*{\-,|YMi7Z`Z 2v6V/IFHpGqdJl/B@Њ+$C q!wWO%@aiyPNW3"T8o7o!quvs{i).hBxPm8E2l5B%Sji+S&Շ͟mp[XOD'(m v˧8gK;-ᢻ!F厮6p{|;F?=ٝgãw!P:(Thu~?{t&8+`F70.ɀz3\auH1ee.YT^'iKrsw-Ֆ[+j|kօ1Dy'bIoV;rreNG7@Rt3ۛ}!#4eg~WK(2RF4p b= :m5#nLw`'{}glve D$%#w.Q!ˑ]O.YmODtcK \??Lͥ㌊/ug PrvY(TyMz_qak%I `[iÓ myiI}f$)+MkNm _- :i". E&;h:v΄?uG9KO=۴DrKR`URD2)Lw]-s,|߫'eZ4A"2ħJgE?Gdxt)WqV띲Lͱ7So)E-t ,:B@" mA~&hQZkhA&X{d+0P+3L>xoUi?݄Ԍ)ݓYLgiJ"PCn44m+0>x(ub]>L]O.=[ ^>/XGa/PdQIgag-RHl)2YG!DzY;&zM/YT eP>cIl' eofqe9{s U^K">^ro?=YI-/y{ڡhX}RS_϶DESat<|z )(9]|^GѼ& P_>C'}hay Hvrㆀ<`rp3n{ǎcA,1b ֝XZl}/ˮ $E`Z;ʎŇU>g g>:k^V%ɖ!9WACvN{汯iwGYeTn}V O6B6*<+@^{&.c}xhp%lL^QHt#;C?C t+iMȥ{A?3AQa?ןw뗘 ͅE +[#Ho Z)ϻlvK 6OV|~O*v0BhHƒ8AXU"`ѵ\I؄ CE+M 59JEg/HHle} 1wz/'&Bd֯1\zQڹ`^;JEHȯ :EKC x}`W/9=jw& IA!D ;ld?Ccv_u&֢RU4[ޤD Py7n0`'MwasxbWP\fI𤒱~ƙB;_,:={Am^t AHW[S }/IQqJY$l]\$hpyi%vjo&xwgd:"]3? zT?DAulV3;[sEPfu] k㹂z{6L7.h^D]Y5E4]g km1^J[2[fiyI&N[aܶE2CQD w(yl k]hO5{gDGaqʘo)?,CtYZP48A`Ϳ1Sc ä|Ve:hn%$]ˣ)bh<#<&)W" 9 ( Gl74 [v0۔a\Υp*SSU(0Y qHx1Pv:b6~Bțyԃf^DEV{Ċ D:޺_pbF.ձ&PxBڠW+`t,}s "pBkKɂ+zОWUjK"r-3Uh8zOB}8tHImM7XND)\,9eZZft16MPXXiMj'֙*o"Uy<c%i흤%{+Ɩȇ_sD@OP}h1rb.lH,+lxDxgF$}CWGe{ @H vוx7^wZ?Xvw@1#zu_BUuҩpTӫr B2 åy$)Z9a2QC䞅PaaX:$A$aDWoۓ80}Oq6Ѳ,H0cQώv;Τ8=BW`j/29$@,uDI TXs#C(Y¬ j&SXoըǩb{,~(rTsSj։E&Ѓ}"i[]2Y}xw5IL,I1:nn ` -wvR@3G*> o{C]IXp8Wu1d7tPws r8U|6 Fk $ /jR`ɑR6JwQ ۗKPTm'ļvWj}<)Z&K'%;6Z/]9GEUB'>lq ?涽vKM|j2| =^i=lAv\_"?ZjV57J 3J"vUJQAusuGo@jq,bA|*xf|08q!/kl=dwP݉feM,6C6ˢ;FW!*O}v=MI]? }#gYL7ϳp+;iv=: ;pDH)b+|{4ɗ #::8Wo/aȡ%KC&Ӛ೴~J&Af zkN㡕 S٬خmɑ)6!vSRDF@M0e?a\bs2bn]u$i(4/XrUXK@ӻ/sӎĥn}qMw^Mnϛq5ct1R~F;Mʾ XBrZy^3IJS}!կ@ t%>tKRq 4s3WC-f:ܔՁ ?lO#J8i S'8G2ȖD2{6idˑq8P&ov= dEb?fH-X. 2EQW aGK#zخA9%Z A~ Hh.8M_;tUK{'vnl*xK݅+{3lq@s!z`Z:Q%H_9 u?X*潁]`aE$/7ī׶) f'usսQ-C|s$5ౌ427>pAEH6'1czשHnP2sӏ+zlAn["ldqV1&}x1KRą=P33juS<`|kJ>O5%",PG5ADZFoMgA=s29pwhb\"9=92Vp%I\E:6DxG23q9M * (zy}?^I(ʚf8.cGF;%\TTdX^1z>~h\?ay{~3i?o)y+ҁ9[ ޳"$ۤ>yTtT)s>9B q77%vc<5+i Ń[B\6>$!I Ɍ*BʚIT6 G!*'-DPЖgԐ˘EabLR&x@ăa5T~ =J 5{9 ߿wd,.4eKXwt^|\CB:i'_Ps-1c%cJ&f{|S_h<(i8Vu^#\cP B #NƚʕozA$m4*L&YUw ALO^0:ړ;/z\} l7엩4 0h-Pqx'w/ Sn.Ǡ̈U^ 08,:\ꧩPJI.i2Qo/5LlLb-?r}6ĺUkJJ$Ukb#ꯅ|h[τ7x**Ki?Y8Aiɷm|@?k1W%I/郌=У@+I ]`ai$Kme&ɪ"Gj+i.XP>(5KС^S=o|j&\oBp [3$z3@i> #bN]}'v#c+ma2X8ÄE0/ǡY#ڏ$j@,/l *׋ !ڌs7͘Ҕk<&m!d?2ys(}1i6 l2H%_TznrbGmbGٟWvQug@"A Hu]] o( ߌmI~ KΜ^䌼kh|y4@E"E5""p3g!N}nʢ,5xr^7&_L7>#On^[zt1G[_ 䕎Ṫ@"*(zÙ#Il[h_jr?G jT[j͝r`BGi: k.\\@J?/ ~T, f+gyꥁvx`n78~rgaOF+n#p̹TחcT$&ĉ)([Mz_9fU-4(kϛ l ı)`cS.& 0h>Ukoz9zw1AETM<GLeS-tb}vDdG6WL{E\GlX*+%B<^IwV84|1u0jBo-6:k'-ЄVQLBa4ZajՂ獓Jnf l3U7ĜKR _j\tEu}a&"cIPk|%ۣb툼=J9oE/S_<} *< G\3HOS,@/SX9 =h35fHsȶ|J-p +a$l Oyd,+I!TL^I\=kQ^P@υ+CVz3!Q_n'hʹ4D<\E?<,CK{zV4u^g7KWH;i\7XUWJiد8a&)ŭe;ZXiH=M4PwZi\\?"ept7X(,Ӭd?g\\#51li7%$V=>oRf|ör\Ozi_Uu٦ Xh6jfap羖vrVMqGG:Yk8;>f\"c{D_F999K`v̎#[-ܒA.Ku; w+,ZbMq+QU50Y#<28jC d\!()T-S ?HswA̠Su}l(]]uA62QknöK.R_+?;@LHAi iWEu%,;D*c^lEl]bqv u)A.B=R. |Ф(,c(|eu?PLE3OW%8) [BጴBXrh[ro^}AOXx~\i7aLHܹY7ژ|.FOZūT6u3s pߧn EpR8V-/f;%4(c0o ?K!BIZw VLJjוZ Yݻ랪X|zֆȋUR?(ַBaJOVLV솦&&Cn@P@`E;+aჱxX})/`̂@9+V}tHF9,»[Xf6w{ cc^PGC^"`~W8pPgPu rdO~H%$ޕ[4֡OQEiO_Zr0Y1M+ڵČlVBոϳ?^\2LG.Jޗ~ZrIB_mU~f6hJPmKc@93Wh #~7g{֤{syh}Uئ{j_`^1ۨ1J>ҰR {\.R#dq""8Myj=y롦c/2R fb. &{3o Dj$A%qﭠ],)@vƼMnQV~~ȵj /k2b6 7cP+B7i,BX]v@x~_EX!(DeȴQaOC+Sz>< k$iZ*/ pg݃$Xf"S:֍۱"ď23 挈jJ]LKb Uj6i% B@ޠ1tcY0 6_˲"*8,5Gn'iķ>b9~;a56Czn]?o]k@Q7*OM}<'~PIK+&/";{Ta[k~bξ6vٍ6˾k3n~*`GH9Qd$҉u 3QI=c,C&X/9L^v$ F۸ZkjD& "ib6d[[Fi[qOR ”KbE<tw >00]ߞ=^i( 9TxaiQ&iO2ה{Er%*rlrCbTѶ9a) "FPL S|]s☿PŤO&Tu,T@l7ONrt X/mmއ:̽yT_cV ؒU43/8ڡCV`[tиX2lZs|q|[Q\m6 7?^E.|@+4e XWV@ކI.T檟3s LFm;',o(y4KMx)Z2v0퍇pI@U&ySEVwѢ^ sHecM^mn'V&_o&dR+mK\gk$xeO0ląh 3GQ9Ay0"RqG|ƿI-̘^ky[KKէWfZ) sv}M-]K̝R{aWGeg^Ճju`]uƌ5s/Z!buw~p0Rw]n\lJ)j,A? l߸15c6R(IΘy[tR5[rePxNiB56'BjVtTciih}zqpjRy=yŌe/8ڵY8QXYu Fu5jXʫ.4%Kt}d[/4d%aYd"Ui_EPXྲྀ|V4w$?`?=^J|CG<4N)WnvڻWc zޮ4g$&Ñ[811pT/#8x͸jR@sVT30A8P\xd@l]Lo )ڙYʀ8|] O{AL.t5ALeX4 pAϙeb"1H4DVADf_8F̮< Kg"o hŠ™)M?5Bj= kR"#{_ ]B|R iVwQ{t')yr5CEO %_\VUKO3S IҎ9K\Hhźn$Wɇز-&CLpqǑ+g9V2څۃrqgв@U4^kPuS sF9DIǺ]I$Š P= b 1J.S{e ps։c;V\يI('9A:N%>^6>VVX/b$v :<܊HW* B *5+mt]HP-YbU;dxZϮaLo,|1n nӼZu˾mۈ%K Wz&p>|:{|ߪao`PںjQ2iLx-M?"^jYKܘob:iƳqkvZ^Xڴ-:[x]^j@Ⱥ!$o8๺kFI[Tn2 [{b fZЂ tODwBZ%+c^pVS ES)12GPl­ߐTb^Zߺ{bY잳ִA Ȯs9hЉ= M4ґD&wl(L&BqˈkeX_l;#R>%k睍Z0(Qc_(|kҫtF%_5`-?\d22vupY޻F0dTwxS{WBADTݡ _,|O@Oju~HKJ*ڻo[)4ڻz MNBX 4"UjAv=Zav^`P^'+3oD.?ǯqh` l* vr-}$*o.Ѭe{B[X7GAn#EkS H2X5Lgj#SY$ ]T;6! k6ъ%`;ԥpT }}j2 =Ц_! ># 'Z[ ^#M!sifP.)=cSkk+!|MғaGx-GmVj R쓄Q_4w٧ Ñо: KdDưj|4w2dc_{9T8=WDpXj_JG+vl:-2(/{ǚ;n< ?:#&c`Iw 8wRْ7ŬҌ#d.skoZMp5Eԇ_ z;pqѥ<@qx]ULÈ)fMnpRg7Qxz3%NMzɑk_-#蓀;f?,~3sjp†u*bb'"wtƚG3 =h!c>z.Cer/M۾=Qw;[YȈ2KEN6@*}]~,Ez2#bO}}?:.rU8mxucϷc@ Tw|E"RZ:  i3޾LwuLd\?pO5U1,z|kD( k Q@jzJylM{F_?uIawк |L? %5w%OF_gf~S*@(-@vPS"k(; f F:.`mx6ZlOk}iE)LsӉɹx>)1d&X䋍9{ހnbպtf?нH뺝߂\sKs(Wh¼xvfDfߚt|QdU)Im.uҧQyAmCB6[mB42uޫMi#8zV!fz(IH9nmd&b^i` Ju O2.KWv%+!3@*)/7DHUs;4];|꼇l# q3=NˌU+74ٵCkc9 }6Hy# f"V~w&YDR~-J ݼZE[[q.*Qo d#at5ޔ' V؜Z 6㈚[ip68 *"ҕ[OS?&!W~GK+&v΁,TnK֨[hMD]~ MDyM*Ьp4DTlo]3ٸncM2!keMhNҵ.[hdY 9oB^Yhv}@qʣYA*#ޅUXbw9|A?u.,vd)X5 ƵՈHmH=wx렿ۻt;ÀhrF…ϒK8?~nw3X$"-6dx:7- A `1 gW  h _hipchCQ µAa@A?Or @?eT57sF{HgZYE9fK1c_.2&;[:k?.@?A:ӾTm-qTn݄]َ/pR1f<ןn#?' )DOA|q)"$[q9}>]6_fA#tA]")/}h*0\ᑯOY$N,?\a9~<6R55D* EIKHʛнPd&%OSe S*g@@5 =F'}mi :nsINJ}&##'yW&dKErzDZ;Tt<GٵU .oQ_$ߎ/=(`Kh@$Z+>G*^]FZ7K0ѰHܯM}nť1lj&81%gB#Vk"RR;/CV@z3rTDʘ%/;hU!Y}okVI G LC}p dHlSXS*y"%Ӓu!<¿y>= yJV-3kTBAa\{tmpf.)[qKQ('P*+@|G1^DwIe6_: }v6 k'6!l'aRxCj~[n 4il Bp:"I8<`MfnU^DL 6tя!8^TdcrJ6qG^ v6aAd= ٘2F>~.f;koPK(B8A^P |M+P)Y=V.E㕧 iz#u$?DCKM,͍'~xPEpGc 1R8xkmEEן_Sd<]Bj86΅eG[Ư|k]U[J!it76b31s$[^5IE+zMwaR%MĶz2j⢢x 3SBFqn:i"]ܜ.x2D3ȆiF:Jo&p 4֡uI0X8q] ivZU*U5/e;I (N>Ѫ aDcHx%}RG!>#'Le 0c1{_6D({َWwtW[=<9v^3c ʳዘҭ]DJ>g'iӃ0te #ҹd/>X;{tjDR 2c 嵇E_JR MUշ蕓ۥf܁JʤspmAȝYU2] _]@O`cF^-U`&\W D8T8 m"]:5s0iV{1m|2ckvAKШ.tvy} x:T1By\9Hr5&J2z2^zB[UgN5q#]`]1y$C96kRUiخ]#lµJaD_ܔYkAॾV-^?wk,+"`ꪅ*%X@JjL 2&vf>s+z;3Xlbj3h Mܱp#_5,Ju40[ FeoU9޽E)D(S&ADDwx] *X!PKoYbcr|n6R^qB(T%@t_Zc]u3:= L7e9Yn,nFfNp3fefB[TY8ELjcJ[n[˽>tZ5ߴ'C G$@"1EEF%o ۗ+ױ^#/3 krp+:1ABP[Ɉ|q4l+VT oz6hÞ$|&*:Բ|L`G4~H啬PhX#q[:ATU~cA?9Ɂ-YɠHp߼ƊݜbΪ)|iPDZ I{wpW3Wu=f= o~FT͗p9,R W-h6i3l]G!P7vKKAC.'ܯ\w|y2ݰ&;qi.1,,d̪{ ky&SjxԆU<\ i87Gow5618ய? }.9n@yQ<(ke5QDS;Aȵ1X4^!ȳly#)Ee]8qljn^̩K> F2 !#aBƞP9A|eP9l `dCr/$`!:A-=Jw|'qL) Dޛ28C5gw7m[Uִ&;eP,uVpS|Նn.ԡ-, A+6GEn>#C#k --BZ#7 ]$x?:me8ڡ6&, 8՟eQ7dsixI[ _}Ќ߯˵1ء7ձO(r\^̎Q&ڌK:bʳ d 6/TCIUl~6 4MR]c.0] Hc|PF_ڙVe[P? 3)F_Y(mԿgV}Z]H 3"9:ɌP'@`%3TwvP䈇j4X黥d+ڿPb;qdک"AϽxH 6g,/]͙ \ӂnulDty2(#ߧZ+tGH%C?{-SR6i r@fJ~WeqoN,3T3Ѓ١^ä!^;ɞ )uͨE kJ3Wb#o9o\'| {s+# v*!(x1qv-2րW5 ;zyF%xNU2Z$Rx, xN:R:lmDDX1' dUP#gذƮ#k5a:!%ಫn ^(rCv'$w7u"bW T2.qW)tl'={P6jQ_lKA< ?OFJ4or;]IxdF?@"$[z4a4ws9Z?{ =_{_kn{ɕ7sr8RAz~B ĕܭ5xH$Y^0׌_D< &eK ;ЏZi]V68/75j4(u18u⑇ﱷwԱgTAN~;CX3Aa|^2P<7ӭŎ2PsYQ_f_lܠm"]۵5T#E\5`&'6kն,!S!-I1%tR<[Qm=Eg=1k]UcVav.Ѥ9k?S-ȫlRB{#v'KlEV%Z^O+|5z`(X+O⽧yd话CiVp&J֬5*9 d1BZ4_a2v*b u4XZyJNQR#ۑ >{7XHޏrq3?eS}:GT ?V H@@R@RWxP5'P{41U3>'S9p!lpgv?q& ;u; {Sf>vR!n#/oĨqu՛+ea;F,=6 OvK,r Fz]4 )$!oB~ %pm6.,.hmѠTh4TZ\$!iHi%W+;_>{.tH]҉G535>dÈh>nq:Agr>gE!uD%w< S[!$Qt(8F??jNUt(lp=5w. 1у"eًj„h=[8az4[Kʊ54VAH}87),UyE~+ofWp\;f/I]eM.-N\"opp5U|"pjD~X2d9͞hTNw#TQ|өh0FWx8#6T]nGwOf|&$'vu^{?:ZY|BFwš_"Q 'X4ݚKeL=cp`$됈;h.׹hTh;! @qfzxnIEDʅF43w-):O[-vWq΃ເ@&E; ]-Gx{ nl䢅Hg(98[* 3IOխn}0U A3 pAZf-^l)Xf0,vL];%Ёʇp2= "ay`Y{;;~?'K I[ Q oa%d!8doye 14{v`aq'!Wd)MNhMWn=S!}g[0X'Ӌnc '~fP6->ҽ{Neg΃hJ7!]VOr{YT+FVlxg.W!(@V 2߹Šu 倦x`}2WT/t}ͷ@ۡW1\Nt58`h#X_Ȯ7vH8 &χ買~tw)VM\1&Z\@c "Brmnl$rdf(!_m-lMmူO\%wgDQI/|o"IC^YM{f}ā2léF2"e>-z&GDy"FOG&$;&"?٤ #w>P3SMT!FC]TyٟW#%Kr35qf nHht`Z vpq4[,.-a 16>N 3%곃֤ h`ʑ;lIS x|ڭܝađX&گyMٖ`Ԭxl׮'#dYA?RôDM! uy.4,:tbepukkR;[MN]VZcN(=^)ԫ—v:>sEXLob7"n &:|MW(& t!v²jxMص"oZJ29ިOg{-eΒzTk!|G!a&CP*q 7kg>/~I겷_0yc Mr*ʦ9QgQ0% ;<@?S/ 7?2/E^x!Ģ+J*ڂ!#0<'{ܤ)=Tj+2Xur~'QSIE7w5ȬU"F#`im2!h0;%#5]>=&9E$@F<|ŀwVBϓ̦v0ֻݝ ,̎\gMG|ŏKF), }눶ӲE~đl0Szo|>Hy#*FiEM|ـ >؄ea_1 M+^Q!Dz]Eh駠DD-V|A|4E`f0s͕$_*نEp BC(z5u0Cnԍ-I8Tʒ5PVy٤@ c"ciCZoj&oBOxDn*uJOi&z1w5o׽L1v/ZeI#SM q@;YQ/geŕ^5O ( G^hk0deNiZ?ގnS_G/>z-Wp(A@6.BH KKH0 R5D+aXV9H4`'Fq0DC%[a@$|3XP/ Dif !#$"(2~xȾ sbFlObW UY9Jڈ<{~cTrABwRl@>>2 fRjSiNũ`zRϹ/(-_`0k plN?[[A{CEig oLtȇQA>7s+yxUFRbה$k) cxogmweU}XpǩN5ďn1/b1qC*EO`}|jdUh IZWX[Im:\Ǖ󼹠`Pȅ]+M$E ƅ\y@|GiZ&5ge-=C6.OT_ ɈS9NX\񂄏;h<9;M:&gs2Q c$>{G.Ѭ6C,$@< xe4}Hkh]~\F2}䐟O0ް]-\K8u+ቄ>|q&E'""l>W8{ rn 9)Y m|A%1b#K;hpϼ-K#Mg~goSTl8f;]aE[i˂EeV"6γdД=8VS(qN!՛N ,5tx%T;vX|Y&_). h'mP#bM>1A`7Ȁd+yS s"e7^\{aq |SqpCR)(kubW7 |"`caUgޓ8='tjU^@)}98X +OώzU څoJ5ĕ9k΄ݐUNqt#wsbm xҽn ^_.\?Lu98p6ITPxҜ0 L;1# &OIf Wz˵_bԍgk:[ro(NW-yXCMlAS72sGP+=0ʵ$IP̲𸰝Zxsbџֿh݉5QaKH2\1An %;q-A*υ'߁tt ^wXd>W5>+ xiH[]%e 깍ȯcmq+Aɦ+qNwOa3U&{J)*Fy\#>Z+~+nth*s{>f3HH4NYW|/Al^9$~q]Vr44\?f1.N74ewu>q_J{j,Nu8h-:0NV_(nX+)"#z4'/yg@ ֎Rr41$)/gQ(}+Zlk @FxnDg+1/ B 6^~-Lxq`؝ tEv{@m|ˣz|4?KСXwӪܩ%f,F jD UIBQz^-Ji!JQB>ʆ%K=fe-*.M@oA>r+& /D7E|^9魳YПN O&?z~LuP*aT syFU">JN0 jpjBB9fFrv\3.@R_pMxS.}WOGZ qS=9i6#tXUTQ=0ckiwl[Cuzġe>uDUp/ \!fs∃1 6aUʼ CfAQı\m{{־)QFAZcѲ/Cƒ/h&w&J*jb.uYVn~&u^l灜SqP7&PT F֞XZc8uFLdP\Ff1:ڥfC{3R!%$Hia;5LsZAȫ5oGe€ UnBCe4rn\A5u<򜏗)r4. L p_^HR_(~іCw3B)Hntyl~ZW?*YAS4~;Loj5Λ'T$L:Qb`V_dÓnRjy11^>8"G)v\kU? /swAEZ O" fF'L-D$hl̹1SuRaR7*cɪdO YX[lE65^qAB4JM+f9GyN  2X Z ..)ou'NiHz qJ:S1u@TJckLA o@>M;Lrla{\[6ĝ Ot`0-u[e };ll4ikM'RA)KhAi4#xS.B#]W[#dGgQ E6Jp#hsO YXZٛ{h#-w+>9[`\":9W>Jx h9hj (P y~[)[(Yw|.U:8_eL{,y={(NūӸJ~Zӱ7Td`,_%2]$!uUd<צ\1,Qr2{0. #'=slw~K/33aP"\󲮝BU74k",*k>8H%8{bެ\> QyzsF %2>̫CJ'5q[5c1{ÙCp.2(իϷ%t#zY2\T݌ j>ځmZ)kj1w^oG1rA3<;PgRhm|!eB3[|Ȉ'SP>9k55*H|^`"zPC۵76lڧv`$ƕw0RyҤc]& u@Rkȹ+X߿޻` Xk |ǫBuq8@qN@Q.: Sh3?EїA1I}"äL FkF 1x~h\9stJȼ]}{wGے{8eмգJ!3_kAЩ<!$FyWn[o*>h@)ڐťy)YUōFiPl46X-dTl*uhvif0/IM8]Am+1g#-! #͘Sj6v:rOF5v@`Cג}YAY9JıZbLʛ=X?V6FtV|1l_/\LV|x^D"|_JF&F.4o$}Plʗ#bUgԝ裠X& ߈ԡJcBڱ\<NsUhHvjY3tu(9I5ݢ[&(.C:">~KĶv&hȟxv:ǔu033CN4}΄ ES)723`]tx_eٽPۓFF& 1|H9Ì a\sHiՒxcXᛉ(Bdcزk$00+?n${w??ڿG? Z&evWk\(5"NpN$WM˂־C*Wjs.7HSPh}-,w,U=pGK ݓBh Ή~:`c@5SJ(%:,U8h'+ $Y'~Yѹ ʙ[V.Þ0`[\uo.T sExboOBUҏL1Ҽ1񍛃&Zx+c*ӭ0` `}@ 1sGN@IY 089qxYDf%ϳ_ h+|h\VFHab è2ɧ}O³<:}郺 OR+G)%K9Vq 1gY[d^s!(S~4G X[Z+j{q{9HX1ؚ\^m] 95z<;A]yFh}V/QOk7~M3HJK&S1;:ᮥw"`ܺ+ Kߗt)y[`Y,uGM2Ύh(McΧ:/vkSIH3xUHJB]nT(C3(Pꄢdj"06=q~XM8#hrw#$d$QJu*UXޟlEx;[e(2O{e%j;$&kNޡr![fp9H(WsdzBY݊qGc{5)vM~j&Xst*~H$1fc-z[ 'Y9-ZN Gk2+ N<k;~Wxͧ@ό, 0QGj MkggsKXskne.sFm%'wZT֏ÞnD\ga$T߹Tv>nRE~C@$N|h|*¢Q^ޜBF7~X`s"7rF,/%(ge$~C@C7ը~4ٰ< '9\-?6t}m8if^;hG1 Z q#ԲɺR5r$Yζ0M'1 jЈId T?{TCUE\K,5Aw0A?,~IՔ h uuf ~)Ȥ4`o7rŤ2'B?;5dupoEY!_V$lyx䗃E>a>#.Ǘ63BmgA1T7;\OY3xc~AZ_I NO2E魙p>D2R6nH*8p Ŷ+)??tLx{n%di1r|w> R(no9y^gqUؚi%^#4#OxOmf~ڴKBê'.49k WrKYcU6!E]*+?!vZ ~ݒɣ'߼ə>ܻ^u(I{}̕judqMftQ B1@;WA9_tTJٱ_IU 4tG..dC츝w"+kfVÌɗ@;3ֲۛe;^kߡ4P.'gb?S6bȍ+K%DZfNB9]k&~AHUKy!5(g@6_5o>gmN ~œ0ovKMMt*;KQ}^-1u Gv".O4ꐜn O Ij 1^f*2~EPUj1Oߊԃzan@"Mwxe#`,q1髞pl cxlp{s0P nNY;)A<+7@{K|BCtضi7cRbX"R4+A ٓM9nKb#DCNo~锇D AC8l)!u$E{[dC=^Η!$ S]ۘ^J[Upu j~Mpx} wdN.Ez$}o9 XyaI}k@&fqa +z'i(kɐg/FE\h{CfU8dQF^Dέ.c__#dtCF*͋܆]fml˥`z_i& Cx(%ټEƅ y<^qykug/h6$ r, 6ؚYҕ6B$\mASzG񥤅$n~fCSZU'W0ڷ]wЭOٺ^ZƔ#9Z+c=Jn&4LsIs9 ͏ro:Rb,[72@_A8p0@`\uiG 0nm]ˎ(5$΀7" m3Zu}TΙdp-ac4 T_,\ )&+Fb7lhc׈K<Dqn.7Dl Vz'qztEV;aI\&.`q95끽˞qK*DJGOPkq]&j Sh{3%kᰤQ*-$u9덇{<揜ލO^0cAa|9j{VYq2j7zMB݅[&zlV9g_@`v4kzt;VΔ ڀ6z/Y33I(`{az#K Ǥ M'үxzWl )oR5b$>_ Iˈ3UPaJ'3T#aѣ׮w!X3KuE!N$Ϧ`I'pCeN8~saDO/ъ8y}!! QR(Z?ѰqVmXރm[bds.B Vg@j=;h;Bm$֘ܧY ~ٺ3dO{ XTхC Y1!\G k68<55!k 5WWXBF(4S=/-@DMVM4,wĄ.?c;%JxiZh)k|| .4ҬHʩR}80ޥiH bz1\jwZ*[,K8ޞ 4#4B?p`羶5CԪeސRB.> A)9[G]$kSi^)niRPYNb/T~~c/h~D0.{'lϩy2t, /ėQ W1D>d|%v N̘q8^PZ x>*,U).l23MU`Xt0K-b9E^gw1rzs)O^$)ޏ H,0P/ yŽƓе$(޻Z{rMbOzO#@{W-K=rAvrϊf֑P Y tJѺ=49P1m~+ H_eoۭB8<XAmR|n AY=sMx̭""NdJ7:eK\˃_%Kw,P;Q.8Lo5r"Y3uxC6Rܻ◝lF)1Q9GRh[-I]OFy*v3'NKj %̯9ڃ䏪]Y{A0;*<QFR75 Auyqp-)7km܁j(RxRSARnDY.tޣL+Us5UɃ)#q1ȬGHZn ?TiGϥW,nFȜ La/5[6BƬA~لnxھPz;<Й:f7e@wo4߉B5~Vvp=mzLhD, Kb}"% %0h:9`p^ hc{%4FHp{5v(P={5  5MdܳD!Q|SP]FZjQYs7",PXS̶'S}=kɄbӂE [JI+r7*@}s&t9-MnJyR0jA<2!QdVe B=AMRNZb~YeJ?QiZxϋz!N T]EZ UtTF 2Fa#,kmKjv uet9 mf^kDa")z17$dY7\eVPLx,]C8i/)?w/`Zi;08]$oDKc(Xk$]*i4Όf[pW7JJXhhbẾúaNв"}.J;7tDץg.DdFIuqVPz 6sur4kJLFXswHö/#h/ dⓈl2Q礁[mA :FL\#o,P:eK/TIa%;^MSX|2pny>{7:.}9*l6()V@mzat#z^b^-b”!NV*p H hD~G[esǕU_LA($bM2Y|n(8#*W4Q5O&qU[ίӃ(~FA98?|!w4 $ Hkxqw]E,1vU X@ׯk'g @:d.V\]PycDGp&xE*\=8 >5x>8p-qQ(xm_S7.rGt|-o ~AZ4x!s 'Crg׌I52u%h\EH@>OMNE$~{IT+EOR0 Qi=T]Ir?Ò!6T')x[[A+& hDv/o=3Ǫ kܙAEʔ2dبM^󶿺$1( 4,pdG8/Lp,BԌޣT^mu>K_}D[`wDAsDl|] (,$$#G8r!'22l~J%L5BJӍc~AWm : W|9&L7ňE^_DϨSܞ.l͛AfԧZD_ƻRi[ y,8` ;k&`Z4.۽™+~m>Xjr*@+aW-"~zpzl:^"+yVy„V]RQDمcEsEX8nr7omBҗvgZ+.'+y2ȫYLp|7KzF1RSXgX[ <~#ǧ^{$v@{0J\Cm%D iP+‰MĿ򊗚XDxt'5p,(= =W )x \#f=9meW!s]Z4Dm=߇E | KǥABrh#b=_MB9ή YSݖ&d vāxxqxShFBSNB$>4-|EM)0;,n+}ϼ.)^9c)(7ٚ&G]bvNib lgTW5+ag8PJ#d+pz!`|;@Sh=}nC[1 Gz3!b>5*:GQE~ڼ7煔Ǿ. Zm2ڝA3[:&75>D9sfȍ?s9X'?,Gin/9tcypvI_}SQ<Ԏ ]8ޱ W߀/FQK)^ȍu̕ќ[ H4B wK;5"C-#nb$z!!^vBh\9 vOy6WZr2_ IʛߑGW=|1kF f%cl+4WӺ Iq_ A:>9V`ۗ_ KFjV<^ i rANZ-s· M+'Pm8;AzYIb’qwj1Tg+;ށg1ȹwԳ`dxO(mkͿ8'x?}T W tcCn<x {5TGubuڱ H9GBc#b}mVY(4 =^rzdb6ŊNDfhW vI]jx%b1qA@qWTbx%r$Q?ʅ-|=GD۳ r,@7&)BVN^w(:dd[̳%b~Z1\ͺOʛnMI?.QK39,AJBAL 菁S=ೖ\Bcgg+B3HՂ\SiBhrd3;8;<_)YKsȥsZeUf&A ʙxt l/' Oij$<^VvcR#j|W"C/ܘ!LHAQ y|9ExT 7 lͿ-cM|sMjjݗybe؂17"I..V-\G1 fv7 .Gr`ijwNqudiw,S-Yxk{9a}tѓAd_Pnr7[D]Qfxa~xY5d&q.ZL75 L$?̮Mƙa !iknyDhsV'*`x!X*d敮QN*3K<:0A_ܩ&Y5  S$**?, 4T~bQ &#=(va2!u݇k?+ ғg *R$'J_Ë2׍BL wUw7d^RPX}Db@< 5 t22>䀺Q΍D G|Zτ]7Y)?=> &oV[kt]' .lf Nҡ_;\0-M"KJZnIȋmje]mucz㒼?Ms`. /۟?jk`0V:_jlHT4a:ち['pFyGxBZꞠhՙ|/aN5 MY[(O4~;q*vS}|`/$f/B)/UIzV9VT]%v0dt*Ӻ wGjq<&zŃwd )ECS?̲|O*_ 49k cG'IQ ЊJTOoҜqqtҘi4kʓ5.jp>寲NÎMXtf ZҘp9vEh0^/ W)?wLjdfٽݬ8rtʖ;\+ F{v)]TMzq dci{)J^rs}8ȁ &fZźn="ӦJR׬CS* 'Kj?{,ujD܃ k*f(}[-q*%t ?m<N{O,<@ˣ&9f&FqD z%I_hk| X %I?oemI}@!PՀ&fѷ@ d#~9 eDޯc8SEskAz +0I bE$'R f!0+1QK7 ȋC5n4/ȕbjF)>y͠ISb[nQlsЁcKE@U7 rHwV{?4H(m_-[ȥ[GlnGt/9epzƂ*uM >hۉZ뾐L-fSqD%[zS+b$f1*Q:e>t1;$[m|KCZ] >JrhnLyD6~ ^- /=Jlx8dY$ɤd蒃JƸ|hh!)ׂ~ fTVLw%Y2vz7 n;.cBRGpg/7O*9!I\R- G;o @eiv3TiFA*pӐQ!cn#a99YZw"K"ޘI9)t?:0i$OW e`ܟ ]+*Q58x4XlWh_ҙlwGp ur٪~6 "~D8 v99v]1ц*\xIn0zaJIy%v|0zE4g *f.bytvvY#5`-gգYWt6˹H /< Ӑ&7gPtsv*Jô'ߑ)1ơCHऑeO &"jEh VMY&s^P9m[§F[H`0{v!;! a۔ s*&3k,ϊpx+KB"O&7oL{kiRt\q25;'#Fn Aj;3SUX+HI !.| ȏ h7f1OOY?4?n|) !j 1V|OT oL,$n;5)^]p`HxɭJ|Hѩ@`& R# q&>`-B*f*?gRdNHLs ! u䥟)Bȼy@g%-xA]r*ZxS" MI+& YtF,=,f/餿:OPFZ%<2fi\8o~-q=rj>܉fQdIұ#`ϰ=+H6g{D)$;kt?uUk"8Wv5m~ǒkZԇU+ $:Dɚb.,*dЫxᩝnʱW;EWjIJ7}l;ޭuVGomRotKph8 5NV+S{,P-7 X!nuPDRkT/3]+#Ǐ3,ޙn kTwM>Z3/i7u wkY֪.Sr 7xs$qw;1pygZfUr(rwK?_J qdWz{.g05ewYGGy/Z46FƜs/,F[^69xCh0d1Zm#Xҝ';=cR[(ɚz6oV<= [AV;׽yX1;:WAJ p!.hB!{qY=hFNN9*/J8*2 VG.]YCb 蚾YFb(dO)R1Io=TV:B G\ "G7]XGVSBgR7-!ӽrV??*EЛuvc!M?h/o/2/̡ Pk;E?ݢ_]HAIzI_F&mƓW[5)-r0xm{&bc~l<P|{d. 4S |QHHX'sqs9ɷ?L+x%w7ooBA(2;aNM8AJ#/Ʈ̆Ϸƴcƺ"00hHYTEkcp rzb'f3dnn [.18VkCtO\8E>[zPA1괽Dk h!rHim3w_:S&Y!!( XIGm*pVeXwyk$boiF`}^+rToڰ[9Iq pQrz𾆚hEZMN ;$F/'! T𛡔|=|杖E ]q!%{"T_C/xfWG9smV !%H̃<".&Jb l|.);^HW-Vܡos=REB"g@"+t> (倇_J#"ߨ98Å *9!Gi~97o9RԵԱ-uƈ_)#Eu"6'%)%@i瘫RD* jmKt6U5<Q?/kV 1WC%. y)}vkHuۺu3!8% Y x\Y`wiAWkeek\'N+4?:x7)sLXv,bWu!bH v%@AA}gDlj"#iĆa!Ah% i"d'Hģ꿠 v6Lek<˚I5\IA@סSa-@@[+GRx&C_=pT8t=\sx`:Kj\?E1S]DΧ_YAʺ/B%^s:İۀ ?˱2 )tcFdω;iFk&d۸Maԫ߂6>-1Nm"ɣ % r{'[g;Xۤǹco el$|m9΂뉚h)!6t+g1 ^S9Kd+kQFݢ#6EP %/1p(n Ÿq-?*_ p\e+ج{ƀgJ1=âǢsT|<@D]Y1v||U~-|y jz exuz~86%xಞ[b+[PC}砱y>)vn4;/8SYҊ C>Q/2C0Bki PG*꩚x|'D-,I5ZRk%4BBk?5s*IA b690yXk]zv`ՙM4Rm jp9(NVRTq'p+ !e8k+q\^3,h,}Y㣇zwvoܑ/K_?٫ h<rE ݉ ;"Pxcx*t Dg+V$jT9_B NBE}-%j8t 1>̓)X_Kbbרǽ6"RmlO@y}N5WS: ϽQVn݊kv'Lf%E]ol=Ga*O3h5׵hd=/h;4(fRî+6Mf D/|TFcx$'%|/3.%Es(xܡgbBR~pZNj9:"ˮ1llyvF7-rڵK^7kǡQ"Q\FʇFKz wQ!/4 v =RzD4WyE[1I940& ɉ* [qj|$So7x _Zvw<3LFU[ם$}'Xt_nut1Sv4rO3~9pɦqsZ>Q dЂԢ[{J1]F\ O{(6l7Z!lԔAE8@R ˹.xO3z.1tس{,xlӠJ΁JI&|s (}B25E-36-*N|Հg6 ٵτ~\́sPW_fu++?,wTP7ni%"]#Gd %*igz~w2ʈF2޴Ů#ʃ.qYJ<9`ehK MkpH->}-kFVEiQ 6"gYcX[k1ؐFк|tëWjEA25*Z( ;);&zJk_*ݥ"' 0i`9-{ZCAt:kȋSOؒH5SHt8Vڈa0uk;\";Z{ݭl Qíd=%_qX&k;0x"8L/beMx=O5U5:]Ӳe3zT6 c4?\q'XS}y.nϻ֮Xlo{WR 礰n9:)AIb?&8@FDYZC-%q$yმ_/gR_~#BSgA#-k.W4c_†[1ُM%6xlFoݓ|"2/1 &fZ\lOOI*Q' Bt5!Z ڰN. x ;3l G 쇬HXd No4EeS`fڲ7Sӭ]ͽ ^kloVjߨd7QI!e?35vi^FV)#wM^څ0(onC.WC)#MWvYހ|*Tkrmg7YqCd=* GEsY,^lkNw=$o7YP.m(eaP !x@h} fnTɕjKm8~lZLkp2K@J:;7iaNH?8 ĝ{b5b%ɩHi|ռ]T>Ex*-z~Z"^8*4U!6[ ~܎OgԲVby{K2 p@NDD%ǝZV+LHz@_WK-N_׵7E 'Ϣ.gX1:rjl3j6'煮1V1C=J0ǯơKӓ'P)gr尥14<|-߹塎u4E[諌ۆڀL NwtWSbpk2mT5k pBumpPz;i#ě~1P&&YvڪԹɆS2QܖY[%pQ*~ ԬV!6]ԕR(ͅ~ZLSR wdžka_kҜ9;20rX4@o lT}zs$p)FeFC7amI[(LC3Xf0%Lcעb͍A!qt pqfLtsbD`anyo=Ad#4=K1E$&=#g拹io>:y S^MRD9<?è27WVk7Э.xMiy7mw9s+xb!'1l=jE~o\A!^3'$JVm`A۾sq_du5'n2'{ ,c0g/tMmRtXZ ܅q-v<;qnjb:;FܹUwbeBfaԧO~o3yi@fwllR8#S,fC  q"-y|/Q ^HW Y6rs7Uֽl&Ghғ"ͪ[Gm=XQҹn8g2EJMZix+$pw?Ƿwǃj5f-gM %kiD[f]`k}A;s^{Z otC/<LCM0ifb\G)hγ#V-<"1k;=^khEi-z~#+,BI^<& j<FXUUh O-W'^xXsfĽzW/Ƣ53^Y3R69.Hx{@տĦ@5C {)i&Og1k`Ƶzm@*0S:\rzDP]BXqǏgV=S I؈4Gi~67TA@L孖 fJmqqȐL]f+<1 cǁJe۟"ėW|{b Q""ƌ/&(yqR#VÕg "#fLkDy}p%0" Cuث]\"3 DI{\H"sjt Jxm<;PMiM¥Ah@4f!{cCjgPl1 tNLx1ڌ&VN&U"xj[^цW yEqL.;HL=zkb:NEAiS2ܚyY\yi&XפAqཔ^a zV%{lE7fcnžՂF0]gDwߝ8}tpSartY%>J;o]MʝfiR bOdAŒb,+$W!s?wKwXG/IHŽ6z*V3LX\uk:%4j`W@}!.o Amc֛CmxXFj6"5r}!-Mo V5] ,` $B3? YZ