sssd-dbus-debuginfo-2.9.4-3.el8_10 > 6 6_6 3!pQp)Tξ7]mtZ`f!M ]mtZ` zvgW哝4)S݇hy~ZȀSo=tf'S*;G% b)Ng\m"cI 90 /o<}˴V~`BBvcp+״$pMKoZF&B)dH6ZPW8|vD[r,ӬUXOK %S@r|>`b!70h;LP0m;#IJ9kCI{mAq$qɑԕ6Z icwWd!44UM\vc+{W4p'BìX=FOѓ Pj\7L Fuoq${bűɇQG9 YZe\`H ~tD  >U׃|4>$T.9)3ᤥ%Vj"K+C;Φ۞>:tNbDB~44Y܉,EPPZcP> 6>p>? # K049?F dv    H $LhZ(89 `:^GDHdIXY\]^b defltuvwxy 9HLRsssd-dbus-debuginfo2.9.43.el8_10Debug information for package sssd-dbusThis package provides debug information for package sssd-dbus. Debug information is useful when developing applications that use this package or when debugging this package.f!<ord1-prod-x86build002.svc.aws.rockylinux.org 0KojiRockyGPLv3+infrastructure@rockylinux.orgDevelopment/Debughttps://github.com/SSSD/sssdlinuxi686<P 0AAAAA큤f!;f!<f!<f!<f!;f!;f!;f!;b732a72bd5d9be5b6bfc43805de3af680919e8db02f3266fdc5f069b8aa2a6ec../../../.build-id/3b/7f8d8de2c0557e7e574754cc22bb25ab234aba../../../../../usr/lib/debug/usr/libexec/sssd/sssd_ifp-2.9.4-3.el8_10.i386.debugrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.4-3.el8_10.src.rpmdebuginfo(build-id)sssd-dbus-debuginfosssd-dbus-debuginfo(x86-32)    rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sssd-debuginfo(x86-32)3.0.4-14.6.0-14.0-15.2-12.9.4-3.el8_104.14.3f! @e@e{@eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.4-3Alexey Tikhonov - 2.9.4-2Alexey Tikhonov - 2.9.4-1Alexey Tikhonov - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-27205 - Race condition during authorization leads to GPO policies functioning inconsistently- Resolves: RHEL-25064 - AD users are unable to log in due to case sensitivity of user because the domain is found as an alias to the email address. [rhel-8] - Resolves: RHEL-25066 - gdm smartcard login fails with sssd-2.9.3 in case of multiple identities [rhel-8] - Resolves: RHEL-25065 - ssh pubkey stored in ldap/AD no longer works to authenticate via sssd [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-1680 - auto_private_groups does not create cache in IPA server SSSD cache - Resolves: RHEL-10092 - logfile rotation for sssd_kcm not working properly, sssd_kcm never receives a 'kill -HUP' - Resolves: RHEL-17495 - New sssd.conf seems not to be backwards compatible (wrt SmartCard auth of local users using 'files provider') - Resolves: RHEL-18431 - Excessive logging to sssd_nss and sssd_be in multi-domain AD forest - Resolves: RHEL-5033 - Incorrect IdM product name in man sssd.conf - Resolves: RHEL-15368 - SSSD GPO lacks group resolution on hosts [rhel-8] - Resolves: RHEL-10721 - very bad performance when requesting service tickets - Resolves: RHEL-19011 - Invalid handling groups from child domain - Resolves: RHEL-19949 - latest sssd breaks logging in via XDMCP for LDAP/Kerberos users [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)3b7f8d8de2c0557e7e574754cc22bb25ab234aba2.9.4-3.el8_102.9.4-3.el8_10debug.build-id7f8d8de2c0557e7e574754cc22bb25ab234aba7f8d8de2c0557e7e574754cc22bb25ab234aba.debugusrlibexecsssdsssd_ifp-2.9.4-3.el8_10.i386.debug/usr/lib//usr/lib/debug//usr/lib/debug/.build-id/3b//usr/lib/debug/usr//usr/lib/debug/usr/libexec//usr/lib/debug/usr/libexec/sssd/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m32 -march=x86-64 -mtune=generic -mfpmath=sse -mstackrealign -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2i686-redhat-linux-gnudirectoryELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, interpreter \004, for GNU/Linux 3.2.0, BuildID[sha1]=3b7f8d8de2c0557e7e574754cc22bb25ab234aba, with debug_info, not strippedPsssd-debugsource(x86-32)2.9.4-3.el8_10utf-85c32146de4f98bb521c30a2fce76675a466e44316ebeb905b990e4f9399b4fc8? 7zXZ !#,] b2u jӫ`(y0@o&yC[k ʺହGꯆ0"!qyѷJrC,F++4c:Oי GqZC4q0ޚ "C$F1EfԨ"DAZ)Sn=R$+ 6= * cXs0nA0ׄl{Ffm*,bJŊ ͙7R ʈ[˽jjHnAjmEci&;Q$Qv(b>0<@]䝱3B>; ]'YB T{,Y hY'Fi_ݿ LijA%3Pw#bbeń?pRJ+.XV0٩o!xZ5,?ƍW.pJ]U]rKݵQ{CP O-IiQ MMW<ی hiuN= g4 Ewaz]+D#rSBQTSwt^=E~`x*&Qdu-ϐ8ŷ}=ynOErݻB=b#N,xu ):h+\=\%T<+W~M/,5pw F+(-o=6uN;L`oyDcPW11Ոgd*Xr-\. 9Jr*J%zey, hR cA&Iq a_[B㦖-#bbFOe惑ɐjri}?6 'C>I=@^,ި99zڿRqymI곂+ى;m<{Cakhjt9:bcwdmd׶h:E!=)c6v]Qd7M;DjOTE *SMM.)D L4oDuKV9!v(;_ҙd$T栵*H }IkDBGtx{ome9)8%$6 S$G6#]kt"\^YM.S4_rU6Q됢X3'9ӶΙ0h0Y% >:m18Խ!0:_uY:dg?}\b꽨1;%H.jIm@eoKLbSrL m"hb˫- frBXyʨ6 '8wQwc  GNB@@Xi bT[ۮť/O41C_/X$um:`P%3r9u\$܊]q(M{θruI Kzng7I}QeZ!T_|lοn+::5" 9 \}?mx޳>!\Ka"d[8.e쒷4L#à7Uw]nY{WM' !/'pxȖ6goAT))O2Е`3δՊ)G/_4?ݦS 4i|o?v|˛NnwY!DƊ*![EL~ڊ' X2_q 1p{Τ}1jA YpzB7YFv\u_=ofn1`;^eo\^{YW44W"Nٽ,f?R9X7&{DWm i`aeXg;H#mt;0K+\>?( Bhw OB-?ti'Ez7.՝wvCStVYs`HJ0zЇ^qҢ qͨ_Dڙ pv#Yss 6cPj?.Ufϯ\=ԌywML6B*#۱W̌)c(|cGWWZhv -nvqsL! %0J ?j<Ԙk@zGS9aSDǻsch1oN#6=LE*jIw=~ĭA FH::}h >NAA{ĥr~Axjb{r\tF1uk87N|ԼE!1LM j,1Un$HKz3:@0ȤQh9~Hv%oQKrTF YſCKH<O  ʠW RTʾC2]Zٟe dlճ:sqGh풻hsظfi%0*[>grORB|7Dy RdWh@4J5:jy&J8fbLP75GST\BC(Pv(nl3sĥ>I/Blj4Cm;1C5bas0ؐqEo*~WRƦX Vitkzu>l+`bJDQ!f`iSLvGèwXD?&b1`\>xs`3"rBAxRѿւ03_ݏ]F]5I;^Ggt?;{qLD+s@K hC*Ʋ8:9W*w>uzs1}fЄDc"`FpO]mG_byt*?2jλMNKqں5s\AaTn꼶2Զb͇pU0rzDaOFEh9D4%HM %V%iw(-SiRp %뇸N %wڨ=9g6ΐ+յ26!ΖLsr@@%#~)_X1\; tΗՎZ)k]s:Πa8ƕծ,ULptݨgPlz4/^6,r)0wg vѝK Lj~[zg|}bq8r"D.[Y$3Z60 `5q-ڥVIBz[ӊ3x==n z>bMMoh@?7~8p"T%JRߏ%/C=ߠ%QT-w}p'%&#4>^:=NӄU $GDSF `QVUQvct%ʺׂ#τֺ]ٙ/޵gU,bl>da?4x=^г50@tx?7PseK#{?XJF/`do!Q းF2&v>a~HsR>6۴5hVL^1_9*³v O|u+L_kC^9Wlk=0 QS- _޹orr\#Pû}RIM$kRa4] u䃖0e H##r]H M[a'0|yڗ5gz}H<@+z,EqNi.lm +\({ݐ C褐TL#CT>GgȩH#JpxhEeH2ԍPfMxdQ:o^? ~~D?w6 p%٤{#~nxv~_Swgljv`@l?S1it8Pu2t7SKVU x?4F:dZua\9fྨ WNJUo:r.x2fz.:\s114_1S3Lob{FoFz@ӲT4L_vb{~M)fR f VW!O`haDYj6>fK6IqAMdA=K gLʴT,+d}PY%`d_c/(-{_";cj]nzod0x  xbgBK-ԖgCCy愮/bss2>1w*jDdT& .QyUΜHcs ՂxƓ.~#Yn4.czJ˹g͟j2Vvl8TE3 rA BnVj(A:xse(}tid(3c9g~ٜRBއh^G\!*,I$^eϞ~y4|e8j2c(~.fښ5g><*pɬo~w_,T%RzPTjڸ c"u9 0p(|pnSeL=;5Kbq`v l.+d+;8˂3+ɝi7-,<C~lvmץa=>]hJ~ 9K.@b5=82Ba (aPmڱc{]2x?Ҫt _Knmg>LS7( /rxxZ<MW/: ٬ ( WF,n6?>~Lq7p1GƂ龎(5|!!̓wp+lFڻ"|+[U2 {݃U!3 BȠand>y[,FqC>RGޏ/?RЄE:`̕Nq r+Zks W$̛d 6D{@0)k|dǝ75qPcb;D-DdZ 砻rŘLT,A7/mG'Q]a )fz*^a7>裐VdN{L AVsCNB«i.:1W̅tPbs?]6_ܙ9r^MATvDMEVUH0wt!##b ݥX{$X7N-\$vJ"|FԆ:j~"V&.)XXXxFIEy WJs`N* NѠV*`y1|v,[kx✰ɵmS3 5h235/DٸT%_/R@ sŏ.勂q))'1v*@X1 ڠW4wAl5h6BQ{/x1{$"Le<`SxdQmV=4)ڠPg\zզ7HU:IC$K2TQع蚖Ykq #hiN 9Zs:y}oR N/el k^iȣIܐ?|8>Db(> ػ%l!隚=I3aRwR4nuUcUGGwS=ynk;>VՋg-X|'CYG^u>/>[84(\z^qr,':#~ISQ}D BXm֨ۢ5u?~`!y""]Fm F#u"dTGDqk֛Dz ׄG kb!{}c",Ge-ȿQ*EDVgGM;oZ3KVĜrf2xWڢWdR1,_tv ݃c^C[#At%d'({520ZktopVYSLob,`J =KPtƜ lGB<^.R"B‡ ΀`ᚣWdһ~~-Ƿ,gh9Ga!"G#ɻο>&lg4qTRw [~CPkFRW{^y__Uxn/uvULH ɏ|M=!:30KW~ZXr B7@J Nc@0UD}kʂ~rW y+I^e`˂(v*PW^bCڊ~mN<R7y]:&h7GԆ( @Ϝ?za;K( 8$ F ֥Z/?RQpxSnƯAN2[T3/B@wpJ40?J u/ovEiwJFQTE)1'zp x=&aL1TӗmLxa]]+rBX?}p#x\62cI}mJl)p0\4D9D!BaZE0ǡ=qg$@ }\)G8u%+QF|JzK l&Jlpe[ns3w 󾛫¤$&*9@V-'xs_ _x>|M*+I]y@;9`.91tK=;ʻqMQF!+@X|rX DN8Ѭw9ZW;[BLzq#2 2?p~1 ^g[PV~4xa俵x:.uxL&Tr 7ڂcj am[F6Q`o5*+u}Aȇ^zsbO#` M~P8jt:eС8p$݂ϰw,jkFF+΄es8qL۾ }:@9e@+EI-Pse != X2յ#4T2a|g./+N!q \/ٹtЅǪ 1z`R 1zP;31=yEa+1 )oK!ty-v{{8Tljs?J%cfѨMlw1s*C!@{`I 05뒵L3 ~k{t+U>La=23D7 19OSge_p%J,A͕7`m/To?_5 sN։nv/1DED~gv` 9Hl(*kҴve簚b8bƌP :b$V` 0T`5c-R#4BD۹GxAT { K-KiX Q2`La}:>|48vCHBJv8Kzh(1q b;|Jzi I13 %OpiR ~c\>22|w@ïZR#hJ?ԥ$s!Mx8CNBK6-vx]턢 "FޜoJҊm\ e .7h55ev|ɱ`ۃNorY(:&04 -I@w"VmoX[a2տ'%] fF1"NU@n|˭.;N`TCiݥ!lDa.P,T룏2ҳ \uWZuF/9Me΂nJ4'x=уh^OfTݚ#xK#N#X*,bG[x&QY>v#2v:K߯m8K֭筆JpiCKiZ6RMyř*| O"jLdFg@QH60 $yp A2."XwzqqUt$}8g9\*%Ω;OB[HߕdW !ufOfP,X沯/&Fy ͟BZZgCִ4䬹M']Nz9=ȆGx)j+Ա'ZkGqA̵tiXEFGc}Ԉω"HA[:H0kۧ94/pn Ŋ&skQњ2mȯoO9IF.htlSΑ/M؍Fg7Ƿ.ݣJ>g!館EL#'7\7x9^ Byo«Gj Ǵmxtl~ם |iqc%11J$Qe_Jy2y}~)r&x;sA3`odV)VmJ3T(]b@pwRn:'a n6[^<ӫf޻]ktGŅHM{fhvl(lCm{P(}4¯ ?})5PxM& \w8 5HݤV퀙[M­|#e g٩8`VXrRWWl}8d+gHBE; jҠS(AFQr)_޴FS7VbpGjKBnxw %G6 ʅmC͓R|׋2Vh ٕ\E->Rq"2iuy,ڄмO ؀B~,({Py/4^aki0 Lz uIty!*I#)څɠw}SҬi0:OA\?63q?ʲxy1βG'TQƒK?҇FJ Gr>Oc- 5e{Bd*ׇA`͎}L5p)~cveK v篞SN=nr!d6?PQȐ,HmF1í P6`_C=WgSًIEs0"\pG _\}hwj7 hu.O$-w r^sPW Ta{\f{oc@vK2˜g׸/@Qf󻶶ԬZՓ0]GɜneUܮb:P4|$(j_]٘+w^48yO]--Z [}CC#3par͟w⒍4h ` mM5G֣P4;-^` H0n6Nd*U<WQ (g*eg#;;ԆpfntJxPv@V tT!/R!z;.6efeRQOdWj! L%`κn>و1,k ~ AX?5)!ڞ0hZ#^ٳxG ,(֨.Zс;bVM{<ևc=;N0Ȋ4?-s˯߃ƚh$F %T+ n|z:XϤokcدU#3els,T]3G)˖Þ05`/XdMe|'_^ϙ[> ocj|dO?3' Fu,m 4-Mdz-Jyv>a]Ӟi>*췏̨g)~:P2R3WOIT6I'?ɁUhe16>K}NS2upקĴKc`%_#ќ|w& 7c%5O(6XA.P-Ά"i zJڌ3j&6IӨb\.$:%VN UsS6<H&'_Gӭv=ď#6ntkILsTC7!)MTz܅b1b[@]1di`KtÌag`2pH{DЁ0֬8}@O3Fk&^/Emf 6-ibZVY)Eg75T vQQed A},95 t%։JKYMqKZp {'׋npUJ`b-KˣU\<©̅y0%W6)S2vGqkfֆT(Lvwb҄U?o/Ó &},Gׅ2x7/'oaP";ۑE?(2Ia~l^ʷ,c/yQea՜R?L$u/N]\n^2YFrE2^~~dd|P9dIXG) yvaɜsj=\𨺝8bYt+ϮSeY:Ш#*=5$#%]aN뿏x~ub&y..7*[\>xs[@DS'ySRFvni٬<λA_{[we!\:Z&Q$ˏVy^AMmWwmܤ}yhG!5mބPlﵬw'h,i#6d4mȳT@ Du?!75*Rc5`R]+)v4(0F6$bDh+y`3K*cr(`:s(WI^a6о~-֭!wCcߣ{q60%aw)jlxj-Egsjapw sQr2{4yH.*j)L%ܖ!$iuQ"LĸwUꦝ~Sm !+?P9Q@J%m?/ps]w` @>΅:cH HsGIR7q"f*)lTśٝ肦'$EQ5uJ͕ivFݔ檔k_;v;Άs[jE0q D:%6d:2Ҟrn\ʎV44vE=Zǭ)YWѕ~$AA8юN:Ǡ OWKCoJ)qQriY6JL@BORˀrI\.,EP䈍,@ӛ^/Zw/4/ P^]R/B H]1=>~Џ~-U8FqQ$ `W^D>eQ0 0H<c62Ƚ׈/BlZW!#\/xw䂝oYxvU\焴/9BU1gd*M=eG/.]˜Z|yM[ZsM4jlK&܆bFWP0/u"<JfK!8k56Og?p`\0%l|⢫ж aᳺٕ]xˑt|%WO(G꛶yHHƙVlb-ҥOAvVͪ4٣QA==c&PmJ?=FiS7H8(yP˞P(B'u E^.x?ds2 yqNŸaF:`c |t@}y-!TDd-ꆄU0/ROOH=7"j|ߍK>RZ@Ur(CZ.7(&ʽPGO_U_ }%%2 K )QTIB:}.wmAlBTΒ5N[is#G:G>'SMs7×K$JnsayO~Vu3|L&g_GaUwk'uP?i)mX ¹V<@~YSZrް(fW-uП3پLZ|sC(MIm Ђ ş]q#F{WJ^~>]6ED1v%!9vݶJ-k+`4pbPR۲(هBJ"/-x Rbϑ'ӜeQR QOiL<9flAB÷iBv wA)| \M=Hd*p{p\a ˪=cuP`F%F9 PBjmF64i<:Ն4d%#=J rz 7k d2KWP4?̡,ŋX-X^R'Ҩc҉T,p?$qNC{e~bNs\|t{^4Lª8ǷkfϮRa(FݧK勭%Рo:kӏP-fYݡ-ƀǓ]D6A%.0 ,M]׆z.웨w;y%6ash{?3(QJLzsf[.JSPG5q–O݇9`5ddMk>R ,@rR?߬n\]\&.%xu(-2yP7ږH1׷>#mwfT]tʕ )&9aocd{-j22>+CU#>]|u Th%O{OgPB/_Ǜ9 Nq @%M`8К`@uEeA`clX)8N aD%'sڀɹF2J<Ir nj]Œo6 S ''mjdE)Ai |) ꊧZӿI.Q6B̘/aT:l-6L^&VpVF L&_o~gUADfK+,ϙ2dLmskF] \wkGaˢmI`q-s%Nd*A z;6ǤaKpzϐ;fIW @E]!?~tg$t-TDI#ծԯ;ei%i80$r\:sib'7%3^?鞉v=anhM .FRuKK#yreN*]V Gi@jF.p05߯a1u$id,WU3yw݄];]/YLe!H>OL<c0窻644 5Rția0V> {1 }NӖbFSjyG6jU j-}I‹Us vf:}M6<уЧK#Vߗe~tG hęL~<ҥ j 9Ͱyw(IpǸ×hi=)v] h[s ig3hz̴~ ɻ.#L.NȘ\/$2?0~gq?o+ylk.HWƂ}:z wY gO&9d[wHbOĨuGlMjͲ"+g4aDQ`DcU$G1r,+!wY9xiB2^h.FkB>Z NWfEfUShmpFYb@i5sE U,-T0UXϻ#7Y4Q%@>.OAJhq2TA"YSV)O(kS"Rhî|X2UTꝿMS nypllɀ  MOWT6Z}l[:|ۣ3I'Q"v;<1*`*RO%G|4Xn{ %F&G̔bݥμ9=.+zB18g3"K`#td3j2Y5UnZ;wvfr @dsoO{a-sA]:­@t2׎R dG&xź= BX}-g^NRJ ˘A=PuCccKYY)]!cݙu؜ʹNEgZwオ/RIcvݵ5Zbfq sG$Jk'bQ~bI-vm;:&#q8w6KnzPvrTXxIN.`f]풣2խ\{Ait!E34RS)'6z̺wMKqm;(&&KsL# 0a% # ݞ"KFGGz)Mo.ɡ-P@R(8,I}zjp8dsN+9]g=.1s3Y}Yξ?U]-Ak'+$Z TZxЂޙLA;P֭2룯* M:М>gj(6RO=T6&qj[Ѵ#꼶qT=t4.m0m\ڥ}K?Fzv/? EMn'E $~JšCѾ} H,:5phNpk뿹Xs^&g6|fakh\&pn[vxV~nz ix=x@DTbX{vKwI*G|$sROMſZL Y}I4"Zˆ;޷4ZIՎgk)/tAz!Ӌ6ld CV]o) sf ?бϚj`gi[]ؗߚnjܕgq@LGOXYJEe"?Jx,g+2-f @^Ԓ6}`ХmrI Gj^vDVn`0G"ً'j3PVx;~N{=sZ^.%l,}?DD3PKrաn t}s糐F+S.Wd|S0=&th:켔B(q}/]r`5q-P9m3,0 -Nh'4`w Lm|0 YH\E0*S$͒JV?i}3bAC ^_Ib7*Z& @JPS[[N8- $Yx4;m!>&yo]&q0AUMm~E`ۏXCɣl~cxAH +QgwgP_'i_u(L$CUDHrDŜ>[BH<r_4> R"-6iaSx5u0z!%iW)43;~ânrRg# ΰj̧Fxo3}2WSK>(tbT7Od`:#΅Ѓiv qT$6bzJ;l;o{i[JvPe2\lڍ1<M+VVFdf4 sl.egvxΪ'm>rdFZ7XU9ѝyk[ 6hvJ|ͼXԡ_h[)@v#J O0"IN$ֵ(KsPXF8vE,@R⧲L HP M[$f$᝝ؤҠD]nIflrL0hСbu6UB̧wQ粇W 6eB)`_nL|Jzt] ~LCjGkU xhCz k|@SP9mUb*+|7ymr닏{=F'_K\ dj515RΪ\>U7@d8g_t.<ݸ!q8FVpt5']C䣄Za2Kq)S,W@C[8BgHf2ƩpF[j qǮtg1 n pEo4'g&9`թpKzib?md2-9y u3S@) gv?:U:}@DRnJJMe^G=[c .Ҫajd>[^RP:I|:ǁ 6Zma&y?MFV"8 p_ʇ{jBJ`Ia/d" H|!>ąҽ 7SzB¡s+HUܤBwODZ.ǷH{)1 %XS\V{~}rCrV(3cTp]cC ҃ŨlM;㚺χ!14& 'XG?lB?">RTcosμ/TB z+^_G >c JS$ho*7шnSZ8yh]Bٻ(*<yUl_붌ڞr T-K >,\Q΁p253L(5`&A>> Ϥ<T_0@ ΍Gt`X]sH7S/BZwL3ũƺGtO"3/Uʐhn߀YˆJf"؆i0h_a ]Mc|[zau.(h_)y=PWÍ +]":~ IGR*O~y*A+?#:NW:>i3:Ќ&ԅP+MMrE4zДESy[Lo>Q`c h_e_i2%(s/vpS^ćGVk?>.BIrNOx}j{_M53(BTl3wȏBj: 4'*WϬ$֔ tMJ19@*g^:G\\:Ղo }V]V9{˥a Jnn.rtM~E>Λw>RNϕ_o4ph8&\Y3@GUa :bQI 红+6gnW|$G)vO=EeHL#TiKiz;(+P!cK;#@UjZ*Qҷtվ԰6ȈW霩'uHJ8t$]UхfZnثԯI*lˠ ΋< ֊w RE(@~x"@_fkNZΤvۏYڳ*26=Dt#KȽG{^"q LO?|$S6%x\3./Ka?@XG<؛q\t4R4V[J@ȓl8}ۦ{ǩV)1>qZv[J镥?M] gn|k0Q26/I2P_5@ӌ`LK^.1ЍK6yWLrsiZ]*G2ȉ ϼ:uaj;_ZWov"_yc!Ɓգr53bǫt vă@ sP0rmfvGybV:%']cFD$!8ZŜp m/LC܎Z|ƶy){'tiU~L">T=F+R1pI9g@, `? 78&%fl&v1Kk`8]^y%ai bǵyäM )K`j)g3`ՂM p'  ;-r 17p$6b̮!5Ҭ]E8))/S(=Иs[_]u? }tWA5k sw7uy?r?L`յvW ֥UDO&FF{i2&:麀zڗMn2JF$F{SEL+,w *c}YĠ6=5NSq Lْt7bøm aUOvf *pwVrmW9j>&;7Dyt6i]$DHE3konyBm('LV]6vvN^9nm5sI2z\}oNZ#nXta==-0,sT[`o'x$\Wū{ب5濡Wh36X>Ϭ)O t3zbG `TAÎ~ ߘב ݿ7F$ +;x6mdA(^GE*֕pAZmsc,8-2C.'cༀ=Y&d"ڑM"y0NӋ车"`DY]1_9nAT]SJ9_qյ!z ^g5exP525wZ:OpY؋Gq!v Ȧfx9֌lZ~e(jV!̷j'5IFED=:wRliK r\"*y]Oİ<.]YӇyqЮ+[~cipA04&wK 7ׁw|fKRijr-\4x@/ת UallKKk lyCfN\(Lҁ_bmqS0n tLjʉLi;jqo'߽|}+lkx8U6 փW4pv٣O Ήa6{ z3xX9'q1xwm<ŝiQdFs2ƹNkB+dқrzQ[UWbbwu$X)%vun6љF6l!+`vxC̱CZhhZ/ɠZΑo6z$@ BPg >*GPa Qs<4B`4)QbSƏ+T5JISS򖹁pU߉-j{Lj_YWn Ex}Xp҉NjH?,OQ7cʓ ImR7pO,X*?= z_D!5mx)8?;AV_b]=Q _()z"swtæw]`o߅e{v,X7gOLMREx5Fx4OμKzWΏԞʱT1ҊS?$Pap}ʋct=&r$x:*}!x|1iSѱ|U<qm`JFg*\NN7ɜ)]L)x #$٨>YO2s[ slb)bs oi󓌴wvm3Z +J$=W8+'rTRdJOcR ݤ PM^w/s%+}{APllOhG3 7$Ux Z/I@S;gTX6TPP9IؙPM[g^~M>leK M L Z[-+ '?Zm:Kc jޜ6R0%. n}֏ܩ\ %̀6Bνv >:\NbF ƨ57Cwu Zz*Fvι6X]^_'0 5!I|yH((#XxX;Ғ~( RR K_ l$UviySӏ9ޘ" [l7c>5,e`G졐Y(tMo-Ҧpcm0Oz @^a8+s(8a ,)7nw1uU~R9me$yRJ 9D(Y *-a Nʤ'Z}R XLJtam71p>YL%YuQ/N*A[c+*iQJQIIpQPwz Dgw S { |1.ʯM3y^F"L!|ϝ/ao7N}U6(嗬@ dh@$66T^.%mBer e\4$< QKou`u`9"+LK#75ʂGD?c`ܹ)nc9ނD|zۉ2WD<0!@Rcc<,{fuR3pZ88@fm"6 6%Ԧ/阐{iUi0$Z V"n)wdE4ӧPQ4XdG+˞ZKyq R/p 0cL#YƸ_êi%9Yq@DTf 2nhNl#:N>bJ^P-ۺ'?^ P(ݟ,k|`m}a~m~܊V 1vX'LNڐCJi_L9V|a}gݞj~f 1~A/tx0̖dESsƛۂwx@P<˯b lK Զ) 8;*θ*^{Uu&BcT^ȸdݐtlB[]33Qq۔N yL,a|qYySձ'J&e:n! Lɕߚk(HcQ@N%4ӫsU=4L=ƥGK$ iS27 evhJўr2[2`jaL eh?YXJ4 |M-0kp{0/2u bv,Nj'Rf^D{'b4=c2@Hڢ٬G|n{-/{Y9Paxd"Rș^# ź)C嗢Q[*inlI G\d#P&@MJ]Q,)~e Cwx88!>^l۫3]{Բ[4E՞oQYN%eW[:o4a\. D7N{Ԁ~'^i[)l_cUõ& [[sB<'};HAQgf%h92#&ǵ*u_Xe3m5{s!%P3"y?)q| V;@[ߜ gЁso"a4WtO%xJvb:MD':XB[Dt@2MQ&3MPl|s3XݐT,;[U{z ކσ6ZV=4ff>(_ҳZS#R2P5v{e=phmTN{2il94p?[^_~T- :bSzUFk+vf/fw!yV|ߥyD+kuT ;2  PF>! CX] 4!Qrh>,R}V+HY@צ3ْ*SXGmMz{m9Qk!ZՇ9 !\8߂}g๑υX;,>[Oo34lX5ٳϚ~& KoXS-CXǠ ?{ZD=KR^ɫx&pK-lLus;ZH'$YZq{\RF"A쇾D0¸uFHW`ɲR`Q^ `J /jkTt~Y=oXÃpISH)l[XA6>Qm%/3 eħ=}brS "' q\ݦO ]oAX.$bI Lŗb!D'/F"D5H,;;1 ADH%Mzmawp$FDA3a"dq0(!{ a=KִPvuJPWK -ig\_Nt%+ kSeSW-LAM PQ3 ꟒-,ypgJ6$D Ց_$]{_ʞMY男T]hz ܓʴНӁ;>icSH9=Й~ÌL{`u`V=<[$~U;)Ϊ.BrY<ҎRTڳРox=th2ݓU-{OD2!p`ql,5>]sy}׎GP%7H|%ak.$.В !ȘQ$+nTpRf)w"fJ,;9 pyf[B`o,˰ݚTCF)p9jSx Cxi f,z76,EQRtc)F;AyKSft St6A"/]-30M}-N9t!/ %~-Gf * noAeg+FdH<<$uǤ/ K^r)ĝ<*pMe͙y}xԿ]F)q'RJv(W@ʹ{M'ֶ%y*6yz^[yCvǠOEۮ@Yw 'Oy< [J:.ͤŐGuPǢҺ~xn6a8紖X {/fsӺ`3JQ5.su~RsyU w2]!tmPKs %OX{Ԥ Pr3퉖Ptɸxrg)Cia1{6dk:B0sZ{a14NYp>ve`vC "t0?HNStE/?cWSM@_9UI+e,WAOrU@-v߽GoN9]w:ļȮTl te'|^<Ⱛ[y9sSI3CdSgKǔJn&p~xpJyB@ϽWxУ@WԦ|rO6Y ԼćWFz" i]`㺛M)U/B{' Q7ΡѨ. 迳3&HxLVv 9crMuluOb1DCaW+H6 0Z"9ht: 1UBf]78DQNBj |IMHˎi i<}29.ƀ 1 2ϿE0T0dɁkLd >Bǵ^- ZJ԰ͻHRdUfa.g݊5n N V,w؈2Qb{ 8ap=~`+4Z] !".e".69]AFAپ,Nm*i#̱ނIRᕩ*ޭ@{{ﬓoYrV&э䘷kGk^?4Fc,~VH+2gx*CPD{sd+#uʶ-ޠ6Dd(P'ja8S|ޯ!2aoj g3eVW7ckά*2Zkbubvv$$ 5R=ztgI$rgd ͭ0cJpGƿ̒mvbЛE'H\% uM1MR Mq "R훅^UWGăQ3P zLc.~6 xߤ,nFU )ayrQCm5'upL7=iRJ2ɱ$8ȟj o82. 5HHeֿ"6ԉ5Gb IE,&G̥zsfɒ,$dpѩrj|j?ѭ:[I~)>҉(#~ҙj e(Z7ܺD;q RnuV7v]8ad0aB;>`>Zi\bWJJ^r}%6bLm"/.@eɍܪ{6—M>=S4נ#bqђGHd,;,0ۇ}#-:k6*( B!\!]YssjތmN&*EI=k_7>0U pT׎j#Tl@`VK-HߥGen+_4'󏱳4¼# GEvZ3.ଔe6ԾL=xn-=`=u0>]9:,"HQY <"5-t cw ǭ.4s تCZSM,A[Dz~a5t)1ѷjW~84?顩~x"XwI"0V 9Ls<4& $a[Fztjc˦.Jہ5#AVD8⭎UuVfywJٔcahu[_7U@L%ϗCo6a=cM;ʙN#?Μtj;"tc9qI^N?U$+"]g7W1pbك)$n~]~ms8y)DVETA<e#*S+gdHjY`M=, U-gz 3G;6^Md`D%yX;ǻ)4m[UuFOW_Q /33J) BbT~ՇvA5h>ܼ4oi>CYqM&;ңm!2C_Ok%GII7:/0NE*P:@6n}H38h;:xzQfM2cRBp7YvFuP26VC~fT"ƀ(e6an^иQtIM,av$_Ɍk3$D58u>%f;\)埘H;ǽufz ?Loy@7xZjAgSkOΗ@^7+pȤ3f;,5CLO+x$<L ү@XcL,R5|um7&2yhm,VӜc'-]`auT7 UrS lJ=Avq#\*6?,E0~˥ܮ4w//!m#6fu&N~Pߋ |F\lVƅI v;st)fJA1ZJOlwgJ0Rm8je<ᷓϭTyd$b?,˖K8EOZׁk뙨mV`d=Yod}:'~L |YoF.UN s& IF~ҮDBn;Ku:j ^*OAYj<ؑE|l3;,ă3[ř16+bcяw-`tOu Ahyp`0='^AnC3ajcȦ8dXh$`$ŕ|LB?YH>3lG78gB6T *~ T^KH7w 5MEZɭVpГgLt}otD)2+JNj{i! -(\@౿{ō̧^T3qS8 7/;X2q} g--@1n(:αC[Z3>s%Y`cjqwGB--}!K 0'f3Fn a6K$<\\UzHe]9 sCL _;=8y=kSQSzr]a 7K^:`f^nRx24Ҥ_BEEvx~r.jX\~ \7}G%=|ĭ?\t=ǻ؍0#_V'S f(-3_a 6(Ô1Y zPi gJsOFa4j%s/!M$99'**kp\?`⭔ t9gEMPm8SDſD~ 0$+RS>rߒ N+vcÆczN0:e2^Q+u9G;\q P/!Y&O*=C ̽w泋wr I]2>&bD wP@|qIe4I \aR~(#&n EvכUDa(e065~8ISXT 9\ ֚r^r2&@Z5,_Օ=!4O"H܄/|M4.VqƦִ_M s'[L'd@mDW_71we'9M=fVkNS0ȃXy76}zS,"oy!( gcqnGiX\< &M N6XqӋ&jm ZSL)2͟9^4Oc2= e{>}?vLW+sz JYr5'՘r䷋k7 Ա^Q۴8X轮[ o*Xˡ:mrvS g.lC]͍ ^Sbg IcuRᄊJ ]*4D+0P0_IA/xUיwÄ$)i\}6}G \^h}H+F)@&:B;$ `֒BG{]s[;~KL)m6?VA^}ʱ:0y؁=)Ne%Dw[C8RKm},}ˡ03BU-,A$cYn]}+O.=?_JHz96[O]L.pp(.Nܮ}DecN`;~ۼʝT6PkOu_ŪǢ)ݖ\<,pCѨٟ|iIH3v5[>]EVUʾe_9\">`/ Bt[N^;%٧\mY iO^M0TT $f736aq !e( )D&OW<,rpLs`/5 YF2sɹ%O=?Y)spV@wQ$Fǩ?, 3( &nS\:F_ֹGiPXF7I3TmOZۍ 2> _b *Db,v/Q&˜X?gzi\ɣ"'3úR@ OCx@mz0AJkE?牴S@F`;|F|]&g~D L@_6[b*>~9g1a;+]rs٘iOl'ѧQ>.>k'/>.75ʴ .tsX l _Bצ?r-G-g--L@k'(|Ex߆pge>~(Ӷ&: YQYl v8!"4p?SAɵKΠ_F=kMYG7^7X0Y?=PU?1*/\ x\E>Z9$20*mR^֨BSޜuYS&(kg݃yr 2U_V`8ƪQir!3Ғ3^H' ࣏&1LÁzbs3jݢP/ٱWŎrg6;ddC ׳N2r58ZuM%R =aX.Z v#$i2]wVԬ>:b) q/taqLm /OM V㔝l&25g]1oɮUGZ."j+kVC gJtu(Qc6z׼dԕmKͿݔ*X*ʣ+"w$kpC׆g e 3鸷,z$"QIWsP]& [1<0x[K~) l@մqpmz<2V߬rR.}%~BE /?*Aw6<.)sI /b9Pj5f vwVl&>[#!G*A ^qr0"–(sޒ~kj{9^p.>g5Ba^xX7{Y t>՜WҪ(jQ)f#3i),oS{E˫ނd(ãiJԂ29rDyTmLB؝ysYg}x^s5_Uɭys:_Kx{aO%K:6{p4ϔIaw=K0R-;O&HEqG&hi)9D2mei.FCK]} lt)v(oɤHKf|pA39W冊q(T̩R'0q?#v@0AuׇG S =?^" 4C@3{1laٯĆܙs!R3G<Xy=2.ek ^הXmR݈\bZr[=&\V ߽i=/~f>Ov宖^̷ >Le3t?oJ"kq -UJ>)_En֟|WHsmDEa⑲I׵J!wC'ANwק$IK!˞Q۸D Z܀? vfq1lv܇4wZeB6:aeY|'Á2&gbJ?) eY Dž}0Ъ%ȸwqb57Onf.(9jHC~o1 '}}K>tk]EݯAm!GjaLecds3f!9Qs=9GGmÿ`^-!{[*g]>^~wк|2 B_e*tl)Z&W\SlNz+gVk&)}lnZ c HAh0t,8N֊ *A83m eFn_4\I<Aj+&'K @!n2yO(9py [QAzڪ$JcB?-)c> btC i[Q`׎iQToOi3*%w%%.@8Udwuμv+G&X)n ;\ 'ᛞ!UT6"ݮ0moϱŌ8ۿȨQن r a S(8A.uBNdkns4u 䇠9SD5K뛮NXwLf}zp}#E 杕.O'S$" d,q۳V-KD,'O?K2@LY[8,5(Hjřa[: N|ai.1vh =T=eE&"pvQ^Bf@7:"ð1| A>$><.gђ.Q17ngљoe;SuUHqeǫ9u9Eh )7mtq.r2;mBSÖ9* bXeϷYyXC+sX'p9ڐ꺣ժm#1#kA=^MZ7$IN\Ć {P2ɉDyض|9Pa`xŊrޫَB xZЯg e$N[w'4>8W-al"R'ȊC*l>ubs,ϒ!yHQ8"r<$bUG ]~ZrB"a{BK{J6Or_j' NyZhF?m%M8&s'Y\J 4bEρ 4Yo,3ogdrpVcGm5&cNO~"j' ,I]Xz7Yv':mMt\&M cBRI3!=_331݆_^\鑣O91 K`r3ymoͿkY{&w@QA2|PCАjJ!I.@q$jQ6us@m#S P7_pg8+ JCC>9 oіxf+}5WBA{R?U9 ԹÃ/5o)~jk Lز]F@07W3h7%}NzDϩbs~-߀yRŇQbHEbb 1ՎWVGK"0Ux߈FqZPBj5p/"C~3ǻԇz:"Tz50g͹Zg #:1^|HM=2^ZQNT@!ŧoRZ|:!N͇ e5 vvWfrŘ/K9\#*rGM HZ7H/ q:QT`ə4:epWd5ձa6Imsס4I`mM/=%HD|j(o=^$y85CNq[=? X7N <((m1Ǜ'N%X//4 EV !7诵JH _a| {5ZaX}@"Bk[(ۢi^9SC&awgؾ$7)%7 Y}܎@kJ1͢ܒ]qZCKvL ^GN=p| 4Φ%" ّu# K X"7#R21z.!n6:YppeuDd.,u$##29}#ʋLٹlP64hir٨YLXFmROF :=A7ۡ{7.q"׉nQI?3c~2Eu峌)wN*C+^Ÿ۵}cH%Yy$(;z$_IxfTNMk(Ae"&8UÚ4& |YvJAҴ G8VlHbw_M_50`|PLdj' [?pe>t$lmET*A#Ċa5v{5(|)1M [`ZՕAJXܝ0UctU9 ~NSX*pGdʞH*x}}Ђ4gYTS%/N@Md eqC9ҹ){x wmEARX %ؕ؞;1\d`+:!Ɠ|1Sys p[<5QȦГ$wgqM$㑖UB' &;>on(\x5Iп3pQp?R9b X'VprIsm$*V&/IR ˋe*)ߣ90=zX i^C,BJD-G"B<ʟe\`>{_Nl,380XXq3L hc"-\~E9 [ij ^gs9r{6"tZXa9'4quր־C]&P1 ~e6UvkVxhcx4 8E7r )MIcDaGk?~GY@ GA~܌dhZĹ+c|>p'<+`9l)f;LEٺ-ayĨ^2b3k~SAM~=AuG ~)s9 W٪]F  ?3 ./OEҿ]Ei(F H{!)D*5PL EŸ+v:[&v#,2ʆ}׈)}z|X/m=D.D륩u)*ӵ]zEu8lJT3ZJH6: 7DD _qN^ lS &B>qꮄo,Ci>jX-= `::m=챈 _]N_; 7G;ݸtA `MKL,!Lj ^R,3_REep!1:Q&@Oo8?88 pvHO\Hrǖ@OoVʍ4T/0Qʗ\pȑ9? Rmr'(WMnG. 9'xU= ӊS '(:c D&;r|1b1#eY⟃Ii2As RsctQ6cOi `B%!AMGKg㵩e` Y͜kjg/S*&k݀in6 0byv(_AIID\d2  0JHy˲uERń-4kStL̝a(qZZ9WŧP8_..@ +x\q4LPF&MNnI{b U]Jq}D>9|泵'[k|YV+%p`eax:"Y7=ɏ*$9mi!$H bKuie`ΦI=VF+ӂG,/ ,@M4fUE a^vU"7\}cӎ;LФ\SG8I6@q?hc# ЪG-nf㵬o:\%I|*&4>M-v2dCxA١6i6xvP{3") 22^i|#=3jX٤six9v\y-&QLn 鶘 kWwOz .DVKΆ.:h\\_U*xYWZbhvNJ ӕLgHM*IiWTڄ帴Ʈ^Wi,C*x&٨ZyNPW鬲E&p֯ӱ4"l.ɲ>s۞@V1bibyh5qBB^!x :שzwYA/΢pNQhcxHqsǵ X< nnvaF^e-k䛆Hje,,ovw-fߖD07^Oe5?Ncϐ;@U}U* ?:1ZNfUw[ꍴS)O'˯䘈FTe˧"a~R;C bs^UFaw1*b{gm] fϬ`youa,]sE2 VPkI80a&Oާ0ij¡&ExNM)$" >Hz bp4"N#T{}VMP;)n4e/tv Ə؉ז 3@l ^b*ḅXe 3ō _B^}ѡ>'̩̀)[:bV-7H[=rr:[!z3,u@{zLܕNX2óBXƀގ ؤAo4η |"]춊-f+/HC=2#| "nLs@58oG%͐YL1Ie ֫x]ָ=2-k!=9郓q<#JF (_}"Ol$єw*Pz@I^&l< :=O(X΅z=뇁3GK!ލY Jw_rlZFJt?yʑXarEapu>ՏPK2F,;5݂"lÈHUw`Ft5A*6\TE)UM(0u?LKyqNX۰Tf#zA*J2lTcKw \W )l=F& Z OHHxAًI#ą/ xn?%Bj@:9GO a 樲Y3/א`$<}dR›QQ}IoW/e3~kG7՟GQ4GVw"!Nᑁ)*u՗|TO|K˛UfPNVSP7Q(4E4RJ6;*BXq{UɫP3ep9Đ4lu h4]H$:?cG3599T?m"q˖Be\"]F-O oeg,ZTV {UF =چ?wM ;|U YNMUaX>%UQ޾6v! $#v)`4pArI}@&q;.LA3S[|{iR'Õl5[g`*73b"hg`8mys9Hakj6tJiypO3⳥&P =+}׼.uC4=:RK[YODG7@cGhML5s[*8@P~L2@' j!50ґc5F!F#G% yWuCYJ*xD "qCBr:؄x?n/a] wE^ 42zٳE$ȂmOw`ƑMT (nwI14HGuu /tX7… (\"ilVyͻ [ GT.&5RVvyƢy5ڐGcߡ#r KzEYda@sƎqϝW/T kuƁte s#pޙ 0p/^oGUƉpks mYPD77@|?s҇y $8'#!)p N Pr#UCi^ j~UWʉ/ D73o᫖gXEMckB zc )uKXFxZgvE;-$Q@D(lL+J>̍bcQWo8f2'k"1o줖sƖvu[jch-/aV"ȺfszѹE6}t]?ZȵI`#Z:{0kFҼn1P * 7M$$YZoZ݄XGqʓFAE˾*@ #+luM4$'cׇ6BfGv[XMCYe DVk#ɔ!R8oi+3gBF_t:d٩ш:걕b4r['/.1HO05 D l?k#GJ]W eϗ1kwY sa^E_@*{>@eG9}mc_5V}9tGw&,R^]JMT/8Cރ|۱3 '^[s|u~45%exƜ`~ pt :;P3$5Ȝ4"M+#^ ?ޅKZ8S.go89ft{4D ͚Pg9Ӓ t75ډ>ᔂrZPISphPmG KALqCODZB|fNoWg1X'&fe`vL](*e%{Qk8n J xw6VDY&2gPWWje+ yiI͖܆p餱b_uՒr=7R̵8#=`Ke7YāV/y 0*H >|,&-hC5¾A,to))tIL.bh}(6Im6G({y D?ZpBS#4YLݏ\Wx;|}et)⥯#2u`*l&$aHe}#ӈƓ1փ'Uu uM#bJ4=οн2 E}(HERzJqc[u-iߓK]Z \Ɣ4Y o| ?bjJhXk$fپN$5+F{S=G$D=m6vRIC2t) {GP*ZT%]Pۃ [u5wn2L-4A0ણd F`-s 2]+ p0>|2eeƐB>eU7 !~%9A<V:8t:!N7o.whW9W؋|/nHT2,oa 8C&r|Ga~K* iJ3!A,!Sڛ/]q=|b^f߃E=iTEzjy3A; Vzkr T1qz'">2AM/b8RlI}™\_dĜKAӢB"4~H@Jԗ]v6a*iUuom2~肂+ hPqqJvc7x[mc<0t"3ny@z@! ,X7_:G-u^8e (PlkN].&I2=VmcFӠH pcW(r9yinb "˸,5p UL貇-%f;N|G hSQ&M*Ũ>BcK(9(mŒ+|+B 4\qSG.L_=cJ1FNB9&EeroZ9 crQDm5 PpwJ]&%PIwȂr;nZs0lj"n55iQz^YN3OҴ X%]IRuIuq|C԰y 4ړMRBѭ+xІlA6ብiyy>_,Ec?l9<8Uۻ4/ N_[@+^uT2j^-UPV!ycH/jUA8NKjGʚr<ƷG~݌ D_vsBy&FzIztTѱ>\G+RҮ P7sGҀuæ(:-P[(2x.0w?~X8?ie gXxb@ZJ@7l$"El_׉P ʍL#v([my'_([@.vj3He((pCW;)3(jyuJ.oV|v"IKi{QCs`tQ|=Moڛ89,YՕw{b֢t ݱwczAN96`:Ӣ7׋r'wZwUPh)x0?v i^yH8RI4{,8`B~aECf dOvToD&5l!V LjqCI[Bɢ]:2XxUa[[nRMR/ך;*ؙYrT.:G`%Er56) ]M!~mœO~Q9o3 .uև^N -nFN*Bp@^jp6O5v㉋!a^ܭ?S;vzQ,^ *W>G~ʉo,oG3`SnvPIF1ADSmj;׾p֛ pm)KF.]gq}aaZ nVyvPDֹMKlC.pRG{Qcn{LxxqƒW{Ŝ- DRpr0ty[M7X)F8|&n{6 4`rkK@ '&0BwJɟ$Iɽ .6%j!QWo<>ubč"óK§$JgQ#rq-)q{u5@S'䭫$Y|a-!ߞ{'J8Dl hi Cq8FrifǺoa?=n.bAڗ8pn_p1ՊFCp-`ȷ6;N:w6JuJp%Vnh|$tF?\~S hS.XmiʔY^)PTOڪt^qF٩٦xUeBp#{|Q].yɘf)EkiL=k1# [Ϭ7sA3ҝK8fm]0?1 Bi򿚵h.;Z̏+Qo& )Y[z#/3Fz\V* #э:߁)5|2i;6艙JAKP̬d{ƶ&,u+(;ɩI_ k?ԣ;ymO2DiX?%Fo{`0 goh1ϯ^$ϷrWM(EZCk/Q$-ם 7(VaLI9S?U yŒ#ibp ]HOӯW/%eZ0 2W"@*&,J)ؕ=an)hkeVƑAhlz7K_֚);U3z4xa>iխ}f%s(ɟ ~Uc!DlMUjڲ1 jދz !y!}7SLGRک+L׏Y}YX"~g~cedn$fѽiӆ&v UЄ(ΤKH95, 1ʆ^E`3#";̣hb{Է\ALt||n`[th_Lq$s q2y?Ώ0h0cu(K` {:Cx%Z5컆A9>2^pS5 *U24z0~d0KڄOAuWH n96nfH/ǵu~]J)N X {#-Ta ez)Gǀf[^) ϻ߇swZoS+̽XH3ΩZ6#^'IGl߹ '`Ul|DtM?R},6nB 5x*Ee<2\o8\Нv}$ZehpCA,$sd_G9OMi7UzQ|օb=ƌ18H=cԵGF Ѡ',$U@ύZ$ul t7OE,(ѷ0ПBd>Z!|>(C]D΋+(c;d7q{6be2suZOѫ`q9nC٦;|_Vu?6ꔴ|d#Tg% $]Y<=ŷ5BG<༉r%褙>ҜZ}'5SQB } #)SED7 CȶPj-Ǻ@#>4}&jx.E!Fp{ϫp`Z52zp5Qwޮ=W"Tuvkv4s2+u`Ūs~hDW'g&J# sSo8qr8.i{p ^Оk+ Mi`^ ԥ/ΘT؇`~,flL p9٭kfW639YY%Hb#b D;^h U 89(]LƔ7xtڂ_( uocJ4+r 2HX`u#BG?tR8%Rt@ 55Mgy\^?,#0Phjb]Hlcf|9 j࢐۸ ~tϴ>w6S: >uEQq]Ж(h +; m!H߉0ѣŐs4/ N켴%N0ϒF"i瑚̖lBZ.6KHBg}9p{!6mmSS9UInG\ddPۦmkšv-[rL -A<0ދޘ51i`d#El 3tNf>fD܉c[[xArp$yl~, ,@ gD\͹tmH7+&׬jKhP/tTͲQ!1Fd+:eԷK<3`ҩ}._؎ɼۄ楡ө'IZ F`1&=:*jUIt ~| ae xLJ2^>)Wl'"V)sQZ%&\ʔF+<7:'sM,@nϾwK'ʟ4[ѹw],bU+05D]Up@ʕ`ݧCb=W[u ?e,3J9kovCM (%qdzOp[Ku`߭4wCIBO.g|iS[=plS2G')>O}BRvjmY{ߎ?7,qPi^qfcĵOz$hpsY;!'5BJ`$W=_!Hbq$42f35q"v2*s%~#BI޹@#Qa2O/g\+&V7 ?l&qv& E|44WTnj< WkaaK>ϣ;Ԁc[9P`dA0#ȭtoC?)l77)AH %x~h.OͨJ$/{Dw 3nឌH>a:+~&w!#Ird;7@TA9w 3)ָPr&{O? rGsD0`3]{bg\TdDg&|컭Y|&Қr &=puO#`5؀K2 X֤MhL94ޙPՋk).݀KPAJޅѠmw/8Z|Lg135嶍Q7Y~a%Bz 5t٥{iPRf^]>E s/1`mGYQ͵wFũ%G准*00m;pc^JJh+.b~XHQXEH}TPA4"í*= v?5ܝ;gYСj+58 ʁ0 ~9O bE`&ܾd~_ ZGq W@6/kyPEf5$_㵬#ϧM=cȇ!%G9E$ .}R,]?^{bX uZ|XNJ {H=ED78g=c*)~qr?pAPC%vXFڣ~6k 3~Gu+.nx FF>P^g(AriҿUt"ޭT\<66y J꾈p/Ngl4SR|~FBE,{} I_gW"'^^ԑGA1+~ob~nfxڏe%R ȫhDn3{jx|Dt[&*Te2AHrG\}a Y$ͅsXY# ǖh%wA^si|9ӟ gWdBuvٞ'"غquc4oϏ`3贍jk28A?1j|7͞OlΧ$`vqy:\6]gpf?,,Flk\(?dn{Jį0Vpu~>%q>`:l`޼wbwow6bd"6A1/< kG.F5"ZȳheG HpحB決/ԃ@sA[j& W.;pbG9fԬΥO@ܘ:uWB7AkO1dسHmqRr`DX!t)Dau>J8NDŽ2xou<*.\'(В,/~0^Yg2~ohɭo@ƆH\0ė47J9 N3GAF=/F#zW}tk%8oʊr !9ix!-vc'G"+jC0aSŚuzـLQ7EN iosc5MJٹ~jP@4xh1A-r0cjǪgf#Ǫ_ 1ڢ?JH߾1mM,lAhh 0 e> wE g tfn7n(hoo1&K_Jpu1S%fQ1}ț='1n ìUkD׈Uqg8YAp^:>ѭLr˖jͨ6!_Jh"ڋ $@exo,a4sZ<7k⴨ꝃ(>w\q\pe,N#cN"[Vv;Nv5mpfohӮ;dOM ob8rk*6k3WU_TfAT z~ BM=<+x40$[E,eJ!t6#VZAmTo\+Z0(lcWm&ýrݐ""AG)RR жdJ=<]$%7]RrFR9|+̯^ `lFPV<pZajt\]1_ѾIjGޣi$E$3pÇCg¦IE 5eQLfh^ǀW Іq.KgGX# . n.wq({-N􀒜J2+' 5Pv6Zὲq5LF&!d|m|3}ZszS~Єs J#I2 &GJfnϔ>na֝T2LCJd!߄X$-;]*R<|6T#aT~C^=ÌZ@¾2+ΞL,]04,hJBҢ6 ?*[J&e$ uWHa!1y|' re&2d0Kx)"ȓty QNze?RMfv1VBSzYx6۟mĄ|5<=1JKS^2Ȑ=1ol45}<3U9+HM`a:hִ:+lIT|z?+N"x.LtXLLnr9ڣ }0Y0TО8`m3wzy4eUr֖Jj'BgiuE]aOhl)`B:, Ҟ۰66j=jHRHC|v1D305|+MN*î Y9mP;+Hg}c0meΉ.S xbO:bXm55ayW%?7XRA/Zy=ZyO۰&HE_C ѡDώyC"]?\L`AZ雏]fMK'|ʂJ" klX.ޏtnƾBe#ZX-]mO;3m9UD#׷a2[Ol̑"YdAX}[`惆wkΎ0b!8-Z܄<^؂vS8T*`&P`C\6#RMRe=&/df@.ryְZBǵ}汹ޠ2=)cMȞf̻9[k\%Y+ O ĒDJX@_W=^KLm{ i5CŚìdRGLJ<2>sҌGć٣@F$(5%R=B>U r;O~ӟ~j(ca[\gzo ;Xu<4  ~#>*˨%%@0:qMigalt+sqA,p3O>R /_",L q\6_E= y7vvXuPYobFu?"#v"gnyx#| D, /ݕ0Y,%|RX-NhV˓kC%[&s\xlR\O=BL^8Wq'qFU'z^K) ȿv~4Yv+xu|Ry4ze*y\R S" Т7 s3|Έn!)Hr^jh kI绵^/n9d67gf,RpG$h)f@"q+U V>6٨msov'Xc4pSDLSg&/}5 2bxڌFD1pgH +/9?H&x'9_،_a˼TOUEL@35%' ؆6ga Rg2Ȫh$$Pa؄T/snc.=-koTW ڌJ]0ņ=f1hH0\ǂzbmɻRfEdEX=Z HcRR [͊VwL~Hx}}D vOt&9mV=j. KXt9p]eu>i'?!1] X4N{Vg@0ޞ7L7 VJ`F@[:T̶l"-)@+8PeBTto]QJФku\wr#;S;j@AT]NKMKN jE Hz͸6s b6^?+uy%_4I)D_P^^8nV*(a Qǰ`M42!s {О#Z 4U'hvi**т_fdƍǠR{x{:TVA҇IGdU|(k=4|̤/Kuh)5t:5o5̇}gh3Gof8.=.}ג>Fͭ0 |`kH+PAMdk,R_?'çń>h0( h.-zP{FՄK̇%Dq nȋwNlO+'\fVFړ3pԈp"m-9Iv̨#H1ޠ~~qۗukCLmD)<ܑSdY]ܶeGAL)tueח%)C&7d\^2I0-7 [&9W&Z 斝r9Rh~2Aٷ)Jx hKɒ?TJ ( q;/p{f3N4[T+r;m" ]E>j_(sPr\#HY]MNX.5zQnP mG UjueQBeGl}9sVr4QljﺏO)y#Zw`^t*< [z99{y ڛþUYQYro=ii^`[te"mr8˸GOǍ8QeaZ<j`wfۄu\PR(t'*\WRlMJcG6G9P_3Jk- b@R/ʊ ZL6a#sxͧ s3Mk|+v?[HgUbxV*9}O4+pnHv{pu|p5M*`mF*3Y&\`QĆNjޓ U.9ZtA֏W[g8^/:fq" 72,h ٠7;e?kcYctZ2X, ˫,ۋ^{ J*^#BФq?gk;}tK&E6M:T!GkA PM\hqQ"PT# :*hTPP;m!-Id&Ͻ9q$,Vmd̬ن)]o&,lJhmmGo6àj1c<ױZ%Tq%8S5c~5nC Nm%f͂f2'SxLs2GM<(. <[^|jEIV6Ѕ8MKPH+dz㺴J5%NǏh݂]B%+$W/RlOՈX}ο[BꑻXv&Ufךb\F~>.Ky39`ӻ3;Y#!h"#Ffyع \$~IG|}NG7Zdz2 )mUUsVgUt-j$ :!7YjnFy8咜3d)*4 r*:썫rf4H /x%N *޷& ||1TPo~e Ld4ck},)*N~0oZgsPu4n ?&;w1G/,%UR=iO2GM%W_v.[ˊ](Ģ y#R'W%4>P\CGPuB,^mJ+O#r9h/?j_%g(@Q Ŗv/#U伞`}#WQFۙBn5^ErOWǘ'>Q LEP o>mrqnd>ϞM_EXh SVvUu3< BF7}x~P?xɖ~AS/${aD$ʃzM*6^MU3bA~LIp軱N#B3<&<fO%s+}N[=W{*% w|n27Mםz~UnMv}z)؂B=aΚyܷdXyV{#0:Aܦc'WIC:f|]pb6<+G HaƩNI׽b%S?t`iw!~h)B2]yzՊu3u w)ϕ 7n}`gFBشEQPRL$!_qA-Њ qOʭZ%l囸?D\izC2DNK,3*K n0xӨnY2f<;Khh1Kʇl<9%onew2 ctbaaXefrCi07DxJm$q'NrHǐ7y@E@KASH ]1֛s^lm >,vwg&MėCyl6/fÜlޫj-~};M`h!@][k][ZUe5INhHMH˺ms*#l9[Ted!>w|jͨCCx%W[B]p)Rǟݚ{x;`}Nb&Q:-բBs 9)=nl%×^"rWqBW`>fJh$ORXUvIX }%9QS&4}SOշg#\`.Zn;$ D{ q\0b'2Gg̿؁pW0޷0q*j J*baX'7V;r2-;A9;A+;A|/`Qxl\5@"KŸt'ŝkђ>0.5}/T%LK:gC>Gqb#,P﷭<^&UHE< Jii!EFc}I pQjpee"1_~щZAn`?Q Y 6dݳq{&bsYT՛s|ڳ'F+JBZ4P48 PG\xڮlĒyyQJhW8m2OzwU6b_ ?4$2CCH"ٶ}-&l GIܜtLl"/׾`bp8{f~6],Ja%B^Qz۽H+5Ū5EWJ`c^R `{F(q6 9 %۵Ii0 E/o6LxYH V+=۰FU4N *W]K Kӓ*٦Al+b">q* QEM5hq>\@ _p|XG&<]0P<Ûve`($2hP UɌsŇaG؏?9ѥ.z ?#:?=N >[2,5wǢ`bϻi+(&O;Ny >vѵym֟*rn4>ycd)j$&f=K;@NyM]h0 ܉V˜ 1|oM-9 @$qhGlvyc{h*AP4Ť*[f>HzztU)MCӰO>8,r YFt"):7O' ;fWx AIi)$/DruB Qjuk7=ZΪUGjh4o^p ƒkm[JW)£f'ɸa]ahfv*.iU'Z@>˪%.$nrP;5>[5,ʘ3&w}3ȴfD`h"Dt >!FU؅l.z=B_ȏ7h 4FX$faF[ej8 ΄J.nXeuluX_?'hАGzm6MTA K,E@D* os H9\Mm } kq[o%Ik՚6תAM~ƥ|pџX+˰!>B-F`s5kM6GaD̦vqÝ(B74fS_5xht'c&УFW9^zļWiîJ/ul73}u7)}bCĖ]ã񔜉OAgNgs`gNhʛ4d,G>S3>*ؤ9]j @J/O*px4ZYh_3}|B\Cg\ۜ@`OCn2Wϵes+NQ"k-"ujiGzq!"hr9򋀴n8 )Q/:{U[ϼ_ 82 6(PDWz$j'EXg!- %Ίʻ"|8w'9\fȄijtlMt}L!sL= p$τ(; ;{ds[Y{DT9tϲ[5=MwE!>Q˻&]xOubH "Fa٤EǡT^^n- ioM_ULFĎ{i:6wiR aCS:r-%cQ}۟+P׋WC䱯V PUo4 ibV-^:(BanߗH_ ~T= pZ%H C$I/skM}_/9}|)r/W .Oߏ>T ~j рjZ1\ O4{.O#ވv]9H*H$[:,B4GW*x:8b#:̌hG͡2z  ć{~!{r.uC|*|h3qo_||9 DGv̻5u\şيk&.-\1"$Yn^ 3sa(? O"c)M52B!MKfܽn`"5q H`C e 올[@%ԈWXO,;oɉ/ eyr"j|~A,Dk.Y TbyQK27wbZxLh`}EuHZYLK>8'vy(${(:!5f3u:8#Sa`.Ki4B0<ϴ7%k,Mu_>sئ^:A D%RST3Ձ"VxlbCf1? C+l\N \p$A$|7+}J a2hREޮёXw}@^:Fm ε&؏ 3,[ *F2z'ТQwg[%']4jsncMP#IU1ygqZ)'8*l>TpA 3H-A(k0:mFn3&o9 N-HnˈŐͲ{f@`,2_a͑RSۿ55[nᱮG'#awV(ῄp?s*>4_@IH<\A4PxB׋C gxe\ 0l;4ϋ5w}1Aa>݅ݵT]|c* t ~8Kw<ѲĶyڵ8yM&pbwh% iC^\lP!WweRTjJԉ2Q⨳KNZj?u/ka % gsocMjh+Z!QX~,$f݂T$*7ìbI=(ƕAr?FY:E)ܪLElӝ޲CԌs]P@BqLpuEå* c06sJ0o+,%(N'suuv K"WD\ؠ| 7dif@&$*HM-G8V_:sRZ/dlu]O'C M(V֏%;Uh]X] Dgi)Z^hFcwb an.K k%7f۰|1;mAJmN7=1 rkqXÆ` W|Y`2xGe$'c 8X S!!_/K!cC3[}^};-꺠 U6<8:,\Yn땈w})R#fg"2h[r@OX̀b"AX]r@s#)x$cتfV~^d*rEhwä@%S-J<LG[U9;PSӦYS׉v+ۥ|a)w#T}QКuWp%kt &qebkE@0ރQp]9m"P&ɓ߽`^hX-gE..>4pԜKf7hŲAA|yv+8wK'Ux-D A<~!ß-w["`ê4Li+TWDG۝ rsaʢ8:"Ko$4ufbWDK|hy\5NWdKuiKWPuKHZ ш6%uIhÎ4y t ٟ5ѿ^un߁ O)2SSVMSֲj~b Pą357ec=@ y `ڳFf6B8zA/Η癎f lQxF71@_-Gu0aAvzݠ3?w̐;k *[0nhz[eЏӎ łs1TsHgܹHyn Jn<QXE?:U]m^\N%CAy< b7 q'7S Kǡ^WψFaR G5m׭aqUA6"TF?KI<*$3ղ03dh&N#&i a|feKdɒXhҭ?<)W~d! @Sl|{V*4(yj;8hbQ3l`us3ll{ӵɵt:+}~ ":gg9JVґKYzpٖغf#acnFW7cV]˿Y0& DfnLdByߌ4](s[tl|njZ?纐rUS?wbyv|jN H,{d"z\رqCiͺ vgʑ 6Lc V\r] $êvV(&9*,N?8 bq*7\r|jُc+ ѝuaD&ؖq{tp|3U-BrH ɉ:bɚ`Rݛ`F}C8֍ U-ދ\w$Ԇ~ Pk3CdKA8vFp<rJf9Eūjkg;jŘpdDц~:ILipT`awKN;aggM-pY*]MEj`v؃bbau;&]uGE Li抟OЫw $`c.Ҍ'|^%SHe"ZFg> ݪU& !ѱSS#YIxXh qT3>7"04=k}e7VnJz,2 =TBbmF7öƸ542:d@jeM,hp Di!d4IpG׆xhw\,;+ C~*w`epUJ AjC [? Z8-W- Ҏ2MY&dfg,+'F,DZH9]ov\tX6lQ @0Z3 dYGyD޸׹,&Dɖ$M+?۲bc"HDDFZ*-@A ^P`KDžR,!hGF6Jb8JK+LnP4fCa g*ZɊ,az<ݗ牸)`,P¤K`;yrsB+Ck&\UAk݌Fby/H_o}U)N!!.f&d2 mҲ'đ '?MžB<E7T7ݍC9D -T&ޱ)IRFX|G =[6P,>Jt1/TSIm-LB^L@ZZN I(/Qu97m*mǸӺbJ7*X!]%ih*v {TWY,*ftʘXDqW9zw |zXBsBH[u-h2Og':({C:8~7cˡc{xul<^v{&GIQ#T\C"fsdUs`2jV9ɖ7.Y?)x "V`y*^8"q`T?뤸ȘFeMB9 [[u!_I/x/O{LWVzZM+1om^h 5C؟=VruR(dY@;z q}^2I%eΔ竰*7p8BXgepڱ5ʶKfܐ-{cFj%s$(HLE¶\O'NaJ\l`W>-dIP93q*!vm}q "}N^vfSDGq,Fx sG6@ԦړIq^j$OP-$yCN>3Ȁ:G5WT{L8W,[L8I<.9( @Jﮡ$'!jHW.alG=K$VOPByŖrdqm !V+~Ցo)[Q*ǥܟS0AI 58NdPsdRg.Hi6]gkP̾ĥbqJo G=%Q4J=h$Q, D&> iy~ͺE(Ũ";_"^4THmE20-4&wWj`-y \_> _ۤ2|!aY(1ۿ! ă3Xc%3 4m tǎ\?W0yuFпH{[\C՗8v³~'Xg>ڲ+$gy@ {&<Yk>6uh\hG3lTL~%N JܼJ N;̫cnD|}B.pC/kIy_z,x\L}H聰h*>\4$A#<^!w\q5S1iO\:%Z h[֤v0mphx'4} > l5;,fMDC L M6gH X>glU|O*&r 4L> ;yD!2>$Tiw%ʉ㱔`i,ʍأkڀ}zNn<^ǴvTEžu/3hӰ$eY Cƻfjf8ZkcϚ%)R;9 ?KpNPJ}4?x+42X;v\Y0o&; SfD`c 4DF}"s8.+"uco#?y3@D7 Noi<Eg ?Yߊ  3 W˘88>?Or$Z{cc AƕQ$;1* ,Y.ki&RUUSӀr⓿0|Ma2> g_.AsKJNٻ0O(©5s,Z!'2kp:Y#'#YFE L ,ȢIRw]J4'TgX6QYtU`xK-?F^!+TEjBKU5ٕLg!H~66.<+qkHkɳ0ɫ~s ysgDG0Fϩ!mٵ#b)8_I;\1[4tTʾRyCO^[KZq&_H4xܳrԡ3 ndoG>P7Vz2J2QMBxf<JT4Ñ[ Q:67%k%zo&W͹}P#̿ +̘S@ħr0]w(8ch"'t걔MwMZkv&ƣ| dwW Em9'faRG{#th ǫJ^[d4h{oE>|(٨F~fOot`(Uw7: ={D\<:G+ wgP(i62_H ~VP`4noC2;#IS?kbC9>P L)V F4/0S+#i5-jIo 2ViH 4N Op uYXqŠE~1F πvs~Ɲ9[ek `,qzǼp׏Njkn8LHY>U4BD& ܓ[v$K j%C9r:.!r( XG7!vQ ㇡Al <8Қ%TĽASt(J#`TiwT.\\%K{qD\4L#H1UO< ǫ8Z^8۲T$Lb{7ₛsB(l[RZ'ox' K4c=N-O@cV2&+Ae^Or}/#7`ye"; >J$XZД([}Ru:t^%S$"i r*Cy3؆~j7ZT΃ApTgT헯U=mڈpk蟽&nXFhXO)`IB 0Ң =V ^`lqks3Ա,oj 74LJؽznBWiX"U9D 4OmȮRgxr lYNN,t#x_k%í͓Fr$RB59uaB%wR 2:亼|5$Y0by{2"A#I^JGKkxvfĝ"iJHM`}ҔE؈DXشK].qF҂sit`iQi]2K4t)x"am3&QTs@ώW\t^GV [axV.A8xTzMI_cC"zuyt8h˸W!s,]q,HNJHgXe-Rۉ=X`U)/%Nr'd.ypBA5cr-76Q"lU|D~J%Y%iW|GN0DҝI36c3n>15T78"h'趞ti5Y-0۩<' 3MN=u,> DIc]@$Бj=n}86 0*=V'<\f|pe潕-VZm_H/o;b\5ojڬûKQ#͞):qY)ߛ:2+ԍEȍKBD1]Y`4%ESwm[Vz<+yKfP˖/Y#Fu>*Bv F f(!S\(;(XѶ#Mh0:|bn&_zúo۫ GR6Z&=( qwYDҽōd鋀.k@ kc&썎2/YKm6oWi3\3/7qx 9٩''i#@=ƃEps3͉l}WД0uYFSYG[3M Ԁ/~Uܰئ|RFΛ'sidЋeTWrc2+)Gzy=Nմ]4ui[!.HQIކ!fròi-G8wSgxˁ-6 '{Is6"֓#u"d/wHRېoyf29SSRBUeC/w^ׂfc0#%~o(9U> \ýfz^#Hˠ XШa4lGVgM7M6([rm ѦHxnc[5._@d Wmv<[;d;5VɇCօ@m_bPyZɷU; եBUGϤնB3B7zz&U|khF9ɊN;QlWxdˬ" ͭ(s,$ODM&\3`=K7PuodWX; h,y\}>s"ڔ~OF(Iw)lk0>~z>~Ӓq=1PT^^0wL/ 7iEJ4b ݼL={{ǭȳC1Ez_δƹfdg6ˇTn_:cR7ibY$I CgU;M'^ @Cc}. S#* A5}5W{0iY&S0Hkcraho}QxB%`TjDϝ.1|!OPF"a> & GXPT !B(t4 'MeeF5pF_*GW7A6j,>zs.ʴ@ 75)ZЁ*; g Qۺء%=Ʉ%ny`$7ʄuks*Vk29kR8gN`NSN޽IP3>4mЙbXSɥ'=(&g+7ca5͸ ):3Gz ou H"゗w_dQV`MeK+;xO5]웡JZ"Yts:itFU4|`g9" lxCu|zlCoy~'̓@E8:Xq*Ŵ 1b"<\y4'ʺ{S-/`۷U[0ߜ\ D*Y?gk7KU \z} C,s UZjU ʁ&ryP^ kcPT&&|NG-U0)Tkqz)ь:a?mkzX[|'o&з9 7vƝ29Q27Hϒ[faZ rf ۔Hd5iT5]#$t_lAB-jSih/Wa'6̆ˤT =4מAfШrdGS\qnv2} vU0=aE;1F(gދưBJsXgkcO:+Fb=/:rC bB45sHOޥ?й' m4o? ccQYX5hiv9JC.Mn2yQ*>p+fc8jLzLyCt={b d hhIn/ 9iʊxsxӽSO0d{GFH ։: 6! w-kai|Wȳs Ljunh1ZؤJަg]/Lj8;0 Of-+=<:cYG:E"UlŮE .ā7mbO_%3THlC`A ^c\ Ȍt,}CHq0څ( 4 ;\nw#HgN0"SDaD6ψ͈Vq6♧tf>GIfT/\a֭T3LV"0͎w/RY/W=ݞ3jWE~5P#'FGUhMF NE[!.;0UBI-Nn%OJNyKx' UiN[}|nK>asN4E#7gQGY*nJwg70#ܾF˧tXIFgMXX<>j7WYVv>.pFMkۋBac3O0ɴ/g'fTܖ~I~Fsn9#6*NFS$W{SĽc;iٿD#_z/! ril(ͰB{o$7Ty%Z7877KY4(՟*@_H_8:O>Vף6s5+ `zw|Cx졚b;*KZـ臼\#h-V |,6 ufEdzli7 &uGI`΃ óG Eo_T8{Qv aWG#ܪMs \ɰmg~:"kLvy",k%Wה#b)Ê$7Wl1cb^4_TqO_w1Kt;As.#!t+kљK;_СpuIվY ,H%,^^p'baNeJNWG'lȒ hx2%7"!Q~qLc* Bv$V4J$ւV W,;(kc_tZ~ e߃ {V@0ܡNZ.˦`Ttht|̿{~PN)~ {¹v`_f9RF rr4@?u|rZ# _O3h&b4)Fuh4S5|Ws̊QmWOuW`4!& `%y$#[1pf94! " Y%C OJ'7Kvpq&Y`GǶ2<*@2BJ9`:3 c[l)5f ւ56w c ڇ3Kĺu]Lأ=0@~@HƠ%W+V2TػmZRj;,c}X?$$z-qybӸ@ }F3'!MJ^T3 Aǯ)[;9|"!cSkHcyrYh"lG.urmHח;mט! z91TۏIE *0+\s@q2[·P>edZ{GS |]$HwR;W`7ڶ|Ѵ&`ag B+wy `h#myhiL=V%T7G7}QIV8YJRӧCG@Y떂*"NkH+]yρ{[" "ZqNäψ,\EޞԏR9%?_ub1x/iczHSUz䪚Vhjup;xW 1ѕM9v/\soEV&:lu<ܰ@3k+8$<]Ut=MDg) .g#-s6+B@8"9vPpv!R1t΅%iT1D<*0;;hx]07npz҄08`b,T,MM^MtY'۬VAlF+w, H!PQ7aJJ9U)G1!*W/:tRk&anN,ާmu;y}]-6/@pdq._u HRK%^{ Kyǿ`pY9h8⬪"`Fxfu/1#і(($0hRfOw~X![|X LV#γE%9~6&o򫩊h*Y*U*9cq9i04avTYAV{h{wᔧ~7 oy ~MBN"C99} ,M wuiϋJ`FHGu}%}ҖwKO(kK|͉Cz|5^ȾG8iYIVo{Ԥ͂iia:ڭ'EzP>3/;]qȮvfBRwсV-*z㛱k2N57@M` q[v a|V<[n;cU>T*u 9uR Uvm{>m4NqpSX]|cs$R7@d6{ݰ0!nIzQX?(['aL 6Zэ>w₣FO`.s-B*Ȅo?ax ֽ!]*Q Be|tЧsDw\r{4!޽ObBNUB6P3m0g y[7D&Fd귕m^ćjޓ=!'}6M>W &,a,'YMNPGWqD6ZҔ9h(Ѽ_UU?Z+GEW춎b]Y WUi8:yW-zmhx?@P~@zŸ;ORh/tWԁYYd˓D+bWsrgmY5۟ؠھW goˏ夃, M-qRϼYj`'g4O;~?CϾ~L7h+<1Dk HM~뀽q`qƌW$׶O{խHA؞v>ő}NXHUتTeզ/d=ܐ}k-ᱧB\vM#ptX0Z-I3[2ԃrSbwO/&I+%<y 3ubDXڶ9 W0tjh6.[fh6%DSץ yЩZHF~Wl\8gha"E/tA u2=p2D 18i/e͕Ԗ,xy/iꮜzV*ʱ!Up$\ZG֫ D wy#/DUxQf!kc}Y(̮3_F 3k-ꗇC—#p o VMK\|P+6e%G~VveӜc#iڣ`wI.pp pӘ=8hnQqzn,?{<ݟo>dzˏS U-5gQX-"`b8`20 w^r 4?IB<w?zZYc62~="کrw*8SOW&v٣'Q *w cQV8!?bM4jre!}*& Z'PվeǶy^'Ml;*l 4e_1?W;N/_r{FC9xHv7r?D/koz@.sԟվzηXǼ\ &:`-L0o%7OnR8fx Ԥg&OXe۠B!\G}|=W+=`ɵacrUj1r< ]w)4h׋kW5D2Z/[?AIc3Q)*#!kt,%Jrr!ޱ[q cҐsDdv ?90W|MLO'OFڶ,iDA3*̈= 'vVm0~/ˊ*OWamX;Qiz$/XQ H|v@@a0R@mUxcЄ v~4ZIV‘{eF@T4vㅻz*m>KIb V~Q3OF_#6Mj#]F\xDt7ݗ-;)`oC_zB.PcTpjX˷o0Y*VL6+ rL$fːK-Tuy{-9:vPdCRv&TF=iŴ 8~exO[ʍ5F<(!)K靦2h9+NH s~8i%'D/'m3"l:p>* )8 f"dnd\9R";ږ\=r8DxxTjB +>ÛLur,=z{CGa,yHf-C3}RAaA.G.E4j(w0̰l9愣BeYe,8b#S.@Ҹj2|Caryk#U7A?{]),__r7򿞾ݔ1Q.Ǔpx%w_#%­=F2}Ib.+sW\1$zˆeGg̷S & 0P;a;Xԥ/U?1`)gŞ4x/CAƂ^\Q D ಐ=Ah"b$e( qː{n<% _(r0yKzh|Q!_Qim_.g{ZEf0KCSn  E n3zyf>@.ٜbSh?`\_8 |4^nBNkE"f~'_ț74MߑzА-M]Ȅ0>A;|z8˙R % &݆'6Spv:M3Y4({El9)53z+a 0yLŇr+9DRVfİPc1uDgрz$ns5?xwx Th](!7dxNJR *;ķ P6|ʀ_ȥ\# x9_};LS 3Hu&1r74{Lo,4yz 3EהjK'-xDcjM! tg$K@A^@ Ӊ7If@USE&MYCY6:nuVk, &q nyΟ+$EпO]͓PFNb{.<\}[$WRjt_@'|M0kV;;r7QÐtCUl%´A T's %pgkl?Z.U5O*x 蚕@L꟝P7od J% ss:hY7HgQ<2+@ɠ7+2z\_Xy&I^J ͒8i8FOcmx|0vC6?~ܤz&۵4x+9+n0m8]3n$h[9Dsؠ<=˜KkSUz>r[MDأGß ^>ieOޜ{|WF'u+-`^X 8HYa5_f^(A0ɠLӰLND# f9gX=&([?:.x8S2[D % sp5{;,yAjt )O3<+*NR"@!r;ѣz̐b[ P $x82[i3Wս|9o{^yЙXm}xU<2X;P.RiL4wVK\ܫ |5fp%HE~ JZIUL ƒk;ݺ)7-hWτulfRz[uϤcwۻK.}0.EτewIA {2Mno2ƣg ]Ø[1jc)3?H?5kˌF!4Ul>?WI-,BGZwtPQGuN=u ?)U`UBE+3:0lWot!]׽Fͮ,nEyqX{|rBrY ˖ͼ]+vͼTl$&?&)i fd0HpKIb9u M1x|}0l\DlUc*ՐsP~PC1IjdO'\^Y{=Ρ#Ƃ!Tm7( ٶbV  =8v*'3h6ΥJH'OUd!* qX|9P,'jFf!T I%бs&2(ҏh?N\ՁwJ5J80ڛV"J q=W9VG1Xƫ~^,% WwL@5A?0-\e/+PtV5O2-.,`>Ȭao=iDV4<7@fEHO YP b@x7my x & Iz]@ яoe[W= ˍyEX[4&Ϥ^1;5W~Ǯ#ⅸLM6;YܼyKja `PU$2&P]>q=o``b߷6s)!3K jd%b]+L`3eIx`(N/֢\?ɬ$Da;1wu3xvKНFlf;ߏwC/z:? /+5S@]uέ+|UhX݀ Ȕq+5d &P[U Z]TjBY6<'pKsUiș ~A$UБ(C [`o;v[(V"/hxY b#D O r%(vm\{J0g5. l[Fffd4P$# |^Wđ ܛG5_DYR UpoQ8F6ux.sߘxO?5KLBThа!%ivʟ({ ܗc6N'+)F},#m ל ͞2]ۥ1NCj+I9}qRUQ?Q:֟g(8m ~ge׀)#$yg {)fѧcaG  l1Vixy`֐?/㒙yFM@͖I57=DABcLPd?N*viы+eh[rS4>$yhtZF|pf\C#(lk)"oj,cRPI,p9TȸTwX3=;k#y9@ۥlqHa x{ .[ful9:Pp@*B3?DׇƜe&t!3Z bٔTJU*ҕSNZA-f:!W^4"mEq!ӘWԫKZ+353X sCz Cz$Z!Tp\ҦbZ^3QVb%U#ǨN:js*:Pɕw{>*#Vn0{gc3\[cb|я$fa";q6;׻@6L+p4|2؟V0[5&p-'k>z<:"6|𖼈L@%l >de &i/DDWP;x2{\+1r~rn2o-rϟP#wx6԰GD|n}SQxaJ\k(\4jotӪ]ՏK}7sNW.CmO*3D' EA\ɘWaڽ E|isIiv#Y"esWd7LasG Dct ZVt?-dֵ07f>3҆ٲlF~UYkh >u]ѯVlgٴ6!N_-h9FKu:/ ČkjF4̺01NyFEEu> TSXDYx /2 l݈A}hЅ/p ZsHTPqA㳃+oQP}\vAg{u$c8ZȡlB#sϥLoKZ%nKV9?"Y#A5wg\wN $ǟ< PTq93\%;$+;C9:(Gcp̡b| [϶Ր,x㒉\fewĵ'hV 5l)0I4|oz{QJv0O1T:08! Lr|ƚKdK&U1:x+屗yC^A*LEIF;w_EABNw0Q\Fn1}} ؼ։"v?ެwQ"[n]d]WܱS5`XӓQdmcJ@YjJ@#q 9| {^unTB.b,밆6/,T(k~0=‚CD@(hѪv)mX\Q+sʙ1$3Mz|!sk;HrE8y6Gn$.xm2:[\M7j[&1>+ j?Vd-0pKh7Ke~+}1"Lq^êVnTs~fUT|ّ]ٷOS;xn,(Fa|BzB{na?Er؊sJk2-&ޢu\+$G燈x0066$naaD9\T29a^ o@tڜmODQ Cāڕγ] n&1Qh^/VnRrV]U63r]4M)*"㉼%sЗ`Da@9ܽ顷 h^ߊkwD 2 (RJٶ}vE„}^EVB*5Fq11#J:p7_PIO3Ӎ|mP\m~% I}D,>-1~RWM@ץc86שVC-X ΡNd]sBLq9€w74fqs)A[6;v0~8.@F\A1j 92`̿N 45+1̩1]ڰy|i4b! \1Yj˄ /&`)/CKHhM>&wU|i!?VXu ?ibniaAYLa e_rxHgb>,&, WWJ?C~]MpX!o?4e7a?W <7.^4MH&2za=G',`: 4>1 nZWh2 ahck]S Huaa P2M[$9=X&"lQ(}s*f k;Sҭ2i^5KIyAc2T2Lc6~BLO ,&Ur!Jx{io^9x#xXćCU|Mc]>"&r oG1K<^MWDr{WOm4B7 ?ɤuXm^̼ťe(vsvpݰ0DYN&{ƶl3Gb4Gvk 7 њP|mqX낳$%VGIz )>l&߭N8,-.TȺzQaqEC[gyLOL׺e1hoοI2gҢxFv8I~`iJӦ_PFU %U7ua0yNhūdhZӹ`-BșIqLI& qNao0 EJZ 0a L{>9WULr>:4yRq <^KL[ Ɯd9sMT7g"7|P&?xQd=GlonlWzK#O/ӵwp='@B]gq+|!ӇĊ4N Z0prlK4Z8%dQh![0 ܆>bRpAfg6NDe!.!<&BtεԁH,|__=#R1XrZ) oV 3d {3$aHi ˫!#qҝ2 i*q`#URQ~ ܖ Tj7m:Zh# {D$@Y'';/Ǽx>)VP~_́Wߕ&#QWil><{T{W3O`Yl K&X[ ~0$>jx;vx VDֈ;^Q1z°)wA&y2ki|$8,+6b," |VلBqЋƦzk>` L.P`G632I1.DSgxE!Zjjd>r`m*;Xzgn/aV%H\6#`g#yR@F f %0de I"x![]UK0AGƝWn)1Z?#| UǹSL9%u Ē US1.O39|HsvV 2&CO&ylXt:<גj/ՔɄ-]T4D=Y=ܟ 9Y 1Ū艐25:=5ض^L/GZ#LCޤ=0GP;gqSC7v\%PAH#r]{s0-}qPՐY~v&y/N&j_3*:Ld *;@ f'c B.i1#ݖŸn!?Q]Imj #(b)N(J]:v^=K,(TCFazL0-3bXj-DqampRKųW9kgH%̨jc"uI.n9 \w^h6$r\$ym}d}m8U2d X,~jn|u:.o`މy@PbrB#h[ "b R;aun_Ԏ,'ijUR nCN[27u eް_`P+ #*b'gqOaqlp/c%ۿV,%Q뽎HX̓S (y!B!E(:"$ OMM=o S%dES򈳱꘤m㊳?m/X YNϿgv95".=}&cq߯ n-6#(E .QmRxG-yu#y@[UmmA1qfɶ-DdpU,DƞQ!Kh%8EcA`o޾鋞 3%:҆Sd=AM r*lV6!&X(Yo$DTt`auJ"(5xs9Y"gd0cuvo}۸u,)~pA+ˠqYU :3kD^ǘS=OSjZ5WK0_rSy3誥 yz3dܷ y8ZI߰L0"LB2xTLpjmGOECJ8^\Gwi̩£=ivDjҗoOĸLpLm3=MB\5 B.A_@ |WKK-hPa:JRLq"rt-^CQiL"9Ц5* s (R-d,ltjvLSӵ"}MkzC'o;d[H2}5l[?Ó0|o$=%<2(GO_ON@TG-QȅVRO Զ|1UmSjT{2D"ށ"d)]O(R^}9XR%L-, # &TRS6q=yH a HFAvvp8g|*vۀK A ȝ3uܿDt`hEz>jUBrqRcyjza= FeEƁQ _DPn/MpX'}@̾'҆`+Y oL.60ΩT%^bYBRꤺ?g>;/ڏE7̥zlI&.z^QAd3ղQ*^"҃Oy7H.EλߡK!<@ψ Fw]67'?Wd1;d?.xAtn / 1@%Q`n-f/o_R55hGX (H3z &J`(vcT7[K+BƵ?RfSwDTp?3eW6Om*ڒjDzOT(Ϝ3#NoC}5/kk_BFoe|UB *iTQ䗍 GМPEO?i"Ÿ`xؒbޖ_C.,<D*'L BA'+f,5l,DӖBbV,BӤD%HCWkٚjxyzzM/!,5j\ z3xᯮPAߋbp ?VM l8xJ4K)6Kl,h:$Q3gFP54QD f0*%YSR7_)sof&&,V̔{IPSo@kAÙɥhCtyMhH ʚjC@D )V^hj~Is`7)=ˢfNڤEmѫ ZzʶK_]w4C6ĎFu^uFRb>ؕ1W xblJ!6rA- l‚'(@%c3lWsE'5 K]/?{! SJ?MC`nԉˠ`F*>27ve ĬF,5$W6ұo@6%a땄B5u·)t .N+zI-8iOfW[)b_k/.U]2ҫxs>bm?E' TQ6!\0'd㔓oPr4kk5w2i3gKu=~blL()5loØrZOqj)I8ym02MABy+;hFֲo:d4up}9bഀ7MAYz9h[ؗR/6.H9\h 0 -O/GuA$\0C3(GbOv5и*d؎EwI8p̤s;Lr -\7܆SGK!NMoCI[>,h6#r@>W).͐> )P RaH 7]ȕA8|q,TlRjw8~PP.nǶ=c- `^; ǿjږsPTv}=C >K$,rB64z7EU%[p'3tJA/.cyT"v vL]jtUs_2| PLGsjllh .R? AwS-ܔG  q֊gFTh `t }}[4[t'Yv vr('k BQvFrc$5W}>^dWoޚd*FH(\*_1l^.bnUR[DըZ7uUrc?p;߇&hC A@]2i e \dV1(G:XW SbV^Yo@T9A~pDS+C6n l `kQ"?|Cr\f %[7}Oly(֨@lڗ~MV8'0r-}(n3fpʾҝ(`*fDUv%UX|O{ZA3ޝ7(٢@pzl BmN4,+BʬPQ1y E6O4.rFСh_K-0mb&Ш1ij֓An&"vbG"'`j-^pRQD~ڰnJ˱S4b;5&d湬8 7I "!*)p?iɏ=M>8oן} LQ*^2 R0T|4-m G~)7·\_o,f lN Aj'jDAdU>Z!鋢ms IZOO|*@0DHI2.<ϧ/Y+/Z}2˪ ‘ g$+/,t>VvfA?DF>ɭ ٮJ͈Vƍ$ S@*PpLu:Ѡ4pN"V$Gh>4p E>0/}ƅ8: M>IV2f%!;3k% 2fi8Wyn]->)8&VS;`$`4`@s%A 7ԠXF߰"7JWm%)M,p|b ND f|җDsg&@:fmmxz3qg">?T- =:@1.5^5h팵X;2HĘ/y4’Yliwx\NBHߜ~#w)քa#c6bmm%E0w٫7kw1rww*I8E&Yx~qj vbB1W{\N@E)m1 @CHPiZY6~dFE_I\䜨:j;$#%Ib ˫r(ҀiMX5Ϗ%nZV A`tZ+qv\h\-W2hSzq1;HܗX#5_x*{Ei,3K  [I?"o% )].\eD ^'hS"mT8i% OP'%_2YeRle$Vy4Ǖ :ZѷF+=UaOv؁|{?ے $++Du$q!S(h,N/g9Ŕ sʮ[|{5x*ܡ\ )dAT$I=3@O|4k?s5Jmtq Dz<6Lw !:*&R»~Abm53m>NTzڅ}muup"RWpt>Ót?uo n{FȮ&Ȩ/y܆iRΡ~F}$rlaɨ?Ø.=a8H Z~V1y=VbT2L;-PJ;b'gi\+ߔ -]\WuYm!pbXU_<ֈř5j<++RqZ"FU=X0S+ZArk-lv ҋٙ:qp`R&QM Mqyx;Svຒ %*X8Ue-ctjtkBuC Ea{"c3L£9nKQqH^<vlbߓ.'O\4 ;>Pe+;Dt}m0ЕrW)mM˷X]E5$ZS6!1@fA7% ܧ͓[݆A>Qg׍G.;﹑v(I1 ̴Z2˙]F)`*3%R`{ZjJA5Hʻ`ev:z8˱VQ1ږ)&^j4gA a_lƉ Tv 3l rUe,4_3BJ8=c"xR<ʚ>ETq62Af]3v!A2r$)4C"bӑ(t\T-)5rLD:Jd^gRNޡvOI}/zd3vW)` S %Bb{P}hToE:2khbrR{I۠8adlF?.v2Ϗmy.G-0km!YQiFO}$!vtJ0›A8*aQ+VƘp1B:c礣u9 D]Cހ49pegy ;2\)8ׯ|F?}@& Zbt`պ7yhy](B43a:&׾fHmIǮ ~*!l[Ppy{Je\ ptYɃlHBn0͠>l-^i#Lfs»~ 6`^jC(ǖ*CI[MT3zpKn*J6QY`'>omoU;?]6K=Hn|^m)jFGl×HY?iX _<3} ^Tp+0oL_eI>ֵ>_|A,Eg! EIeBhi\]#r*Qxfh@ *I9ld@B3Ң3k(tRuqQSk 4;͉=hIЫ ~ ±)(x5'23|,~b>8Bf=qUQh\L/_` &(vV37q8p,?:/Dq~?-dۧ'̝39½w'>bu!:φ˿j4O]l+Z|Mz$F2=Ϲ hz@@(V)sJt.8`ŔU>"dtQط ҞF 1vh{*T\)BS Ol$MLSͮ>3P;'«QK ސi$L0ݝg%%"x,:kOg7CF;N{bWCVT/[ldJ1b]9t7(ִ>t ;_ʈ_p'B«J'gem?+NgRÚ8` v{0*J ֛0V&Az62!^a~읡)GqV!]+˜m UwlCz'X&ͭju"cAiq V-R^2ε3$RUq/}5 uF#.*q q ,{T,es*8鎫@ˑĴ$+x /\>/vӰ[Biu$$ KBi[zs.$l_~J"cvaEӎDqA΄Q*% '7f @UooM YSɰ^bɽ=`COb9]yLIϗEEj-M1߰l5+ }Dǵu4:k0ɹ- +'x$x^?XCKݷGT*&ᓧ6qG\ZVaQ(hqn,a(ha|hbzV(Aa!"9'gDG]c ]& C.~?A3\Rd4(=hFB4?tL@@>p*#jR^nᲧmmWk~&5eEEe: ΁]#,QLX suh*4VAѣJ! r`Vw|SaZ# $6`8b>K^|^|V $9rQyĚtgƖr5%SQet NG=7mGr͡cbTO4:ZnI5+xpՋq]R5!wiiѳf/'\AŽѾ? |Oe&TecǬ*E7яۯpW[aJ.IMm4[h;cEuhE> 0;18P^1vU֯Q^GgM~@ⲫྚ@ me#r;T8QwʧQ=Gp٧(*P,>~ HXRHv 49Ь91%ͽihc {-#ꤌ&Eyĥr{+Xa`E`2^g*vuPJ&H<#2_Krn<-5zèysP ؔYT'<ڔvF2-O}Yk;?p3%zi톞}=65)hO)b7{^zixgS@d!QmDM\'Źq"G0ANme1 @Tar %`0(vK0n9dbZCF Nvljê2!x$&n2(̉+;10eD}fy1aS-%?_J?g# }ـ41 9L}qb`z;mcxKښnx/)Ncc`!}%EX'kQtpR 7nhPEGR2C!Loz\W/o9؁KA nP{;.6pc߫ }.z!Inq:g?T8ȪO8N qS~C &FNdOݥ!))nYܳQ'טNQY|jQ,.Vh>f8rƮb=lYL2`{9&yA&oj&e"){Ah:"0gki3|l”wMq~Q 7[`&C/^LWA()^8#S25 u na _צ65.ۜ8" / Iq ѡem)tB Pak\Vcí!4 K5' my[ϓC]aZ:_h9$G>ËfZ2+l$~b@U4hR}N<þ\`;y\̗xe0̧17j˺ 㾂fTqi lF}X"M}\8cpRy;O@qz{=-o^0XE߼]7OoMpi1^{v5WX UOAN;t V C( R}*.…Eֲ{Kx×&KۤڭvsG`u252%s\Ϭ XZq Y) IP J5ƂJ8c+gE=@MqARMxwYt:uǬ>vY)YQ*f:4%̆&0N8PlC Wmɤqփ%/Z6f9-Qi{bYvDEdb &0DS1\_#d X2okH-+T?uTB0/t$) WBDzEC_gAAAdE5ij^hwr_|ԏH_iV]j BcMn/2RDܺ죣58`am{A< H:._C5+b2}ڿ:5ucqL",83D` 9,}8cNo,ԡ[++5|̭q!a?n?CS{Fx.Fȗu$bdxP:ٚVמUz?j}Bf#db 1`GF3\)uzL7":FT!bx nN<^w?#uzPs kLdvOm4Tc TJ2RW7iLPSV[%@Az, p׳fvvAEd!`}1} 6B'0:yDr%t!aСPzP鹡rբq*}?lۃ>{_;gY}0׏70<$ɞO{F@S2d]I >Oդ$ۍ;g@<`;+HKX?TSюMDr+_~NO\22=/z|RZ׀ V"wuVճNG.(03)u}Novw˱ Im~-ϵM9V7Ve}y T7}YF G2ÙlE 31x2\z"G;#A*cf2Wl58h#ϞK.cWX5LXgHZk 7+85 Lݽ5jcz[iW؀to9^+)G' X $$4MeBvg|Io3dwBz3ՎT``>bu w?-Z"F>;"HguKY7+A/#/:$H#ë:۞XI>4(*sSVq/_\Hc , )C%fjGzzr,{Оkgl"úb]F셥# (cog*aR5ܷҭXG4-p2.אIz,USzJGH,$nrJ@,WY&g> ١.)Jۊ!`_mQ8-!:(Ԓ eb>Ncyۨg5Lqd4ɉS8pZD@[S@Q֧X;`>0az-tEtWE%pevRw89baijk#'\:# a:A>) âeY"G^7kWdq,f> cb ,ô:_,v\kJGmCgaN@#oC̅%0Qkwx"k)&ӳTg= Niu~Ngz~aS>My-2GO(R*44mZ.k)<`ŽǪCqj58⃥wRסB(>9s @gĔPghO)Xy2#Z9QkAi&y}\!~MV2IȢ+tbd1+v/^r5JU9WTt|-=ath[+@RB epD3KLFDwp?zSNI$F)qiF.AF4TπaP0&t_cڈp 0b7qϩ>1bpd19A>6Yudn`pN ?(e2^Q%wTSB@9<?2eJ{.8#/I$9E8R_jCZ͡{`VI| ^=ˇ{2 mV(ۼ _Y:ƊCz'Z^mh"zo.>e|,2(T~0~' ^,'Xd-"I-.8k %mF vl@E ֽ#38 Y TֿF]|HD{Ir#eVH0IA#\ Q缡c;L m̙(!+gvt,M¸hn : a}Ōsr}aUCvIk@P<bdn]JȏD aW.RBv u}JKįq\΢6[ozpι폆*wŴ:=NmRt+"(C&gfu-k.yOP셫C/Prbl;GQ[Dz\zMGɣx,0$O:vmQώlLK]$W/2=eR/y֕1mhj o {&U' !쑄>p˷ReaisL l"bW /<\M#E&iqvN0qAJ"#K蝂lhu!"qpQt+y!/&F}e< 8gS@ H+,8!#|2隞-6 BY6 ĐR9Ko8 3Qmȯo#Kbk+澊e50é&pThؙjU 76A': ݇ 'eDx.Rymf\\a­IXﰼJ nʓ%n*?.4 ԗ$ci TlF.# UpV'.0G|^*t\O h~ T`$WZJG$tt,`{چvq鰮&)IZX=t ce놻˘R^ ΐ |.Ƅ,Σ Qs6H7&j#.O=*Х?՜{uXWկ:Տ3xy38T7f:@['W렜>7ʆ@14l!Wq!kXFhzgnMbȈ/!ST14kإ~#jʧX+OYe=FK'G~1Jhᆽ#b*"]&5>~M&zNB.1?/YllL:b&$d}^{r'(gi7e-]̈́A&r!b;S!m遊p^`5!Y6mt^O-m JEc>s!lL^s{LAu7[,B%B@6Zqi"s$s}LJ-a(7ù.ZYǦ)^ɾd߭C9iU-GO{DyvMYS*PHgqfO.'u^YK̔71 J.0Fyl,gSZHm O\ }\{+-Ls`y@:ot=qj[O`),62r080+aI!JstkޙMVG] ݳIqk҇]KC eg\'Ry骇e.# bDjlK+M;5x.XʣH:􂡃 l;%I/{ˠ)~5WlR\xcoZC2O*c0.غ. DD&L+N\s6 .~ƴ@ H5^([qQaȌ1 B3*scuʴU;A_2`I@ I_cd])˦~^Ͳǡc]mkqEFzW:5=&N7xahQGпzE$'\0P´c3tzFx#FY;nP rޥ Pdiwґa:j@QP=G;dOACHmSe>mI&'X D2~ţfCq%Lf86k{(gfvG4J)U Ust[;8A&= Lg94&SoC>"rո3Q ciX9oF"4gb# t]!h+ ܲ'Kc}{Mϐ~}V7 g 0ȹ .Q7J"Ȝ=%^:t)Ǐ·gFY|#K籱N`ˬA}H!h`HG~s!s9ۉ`gЀXq/} w- z!5 >Wɝ佨]`6 .?⼥85ΰLC&&Fd=F 1DK7 ɽܓ~)my]1!!Q|;?BD3LD5Me)z /DBM p&A'=K.N,xƨ4<(n;(YpٳJ Lx:]*7>,&2o .W+ds;rJFIt`H;_$Q ) 0jjqu< 3)7! 9\ =qLG:RnZ41U$|%wK5~NLLI[m0\VTO-Ïz/6hAx|DCTHIKw{f[V̰qZ%e ~P~Aϋ;晶cR/G-M6p8;"uUWc8%g&?eX?nf@Ꞣc^ʟ$UIG?CrQrku\CG<9iځDM'Q AH8Vs=vx8#{)6_i8з@<51b:|YCԵ+UM=6ۓA ??u+UeA[Lc9LYb@WZ oM)>+J0z_CJVgҧڙs:Ò8n{-u0|@|:]rW5Ñ׃+~ݺX4 Mx/kH)έ`vX bNfn )]p]=^1A8ޙ*yCm{K @ҟ1е heb_|N_A a,۶%N.4uh T鲮&֎[d\Q[ͥJ3]m)Uq69Ng몀*Dرq^7969My< 3 Fo_6vD&Dg{08g^7lxtz &`Dlol 3y(!^X!1P_6$xKmjfn%b`@P0%Qc{-oMޱf< \WN|*MT#)U?4föivRU@o g[Qx)2֙jtLʜ_FzIvM^lA Q  8eM<-h Oow>2S i% YqHOʄ7vˌhw8'n`ǿ=Lnև偶E2q! 1/'[{X"_fa}!C\|J&tGaشUxu .g͞;{`w;b$ƶ1Yv^/of({8{W /wC]J L;Y5aBH"mNjˉVFh'nfHe .;y3,L?y -<4`OsO&1w$Y6-^p=op UA 6vR1!jĉ+ Xw f223K~;&;z-|cB땺%+6$15Yr$ۖh^겥py~-zšW'uo(0*<#7Br+XaaFLzIZf6ʭBcb!vx̄lu!#'8]ʍv:=$UťP?hZ̻pJ $,,c=㖭vkez=IZg9ʶ_),"Hma|V(Hsѳ,4zɵzɷ1a&P`$sp=iʘ߭oTVϵΛH*S*-]pѣ EzHl5d"ς e"L^15fJgtY4`_=Y\R!2X#UÈ8 ػn3^#!u&#,.wG'^vK1%<vƗl쪮Z* 7*>?kRoiaDYɿTPeur*&S){Ϙo X [QiM @kDJ30#QLHX>carH#4.C ʍǜ)Z$f|UUƆE?ZF] j:"H/!Q GFK-kBHU'58Ocݴ֪OԍѫF,9u2͹ 7@=Y*SAJ礿N 7W6!>ֶںFLBNY;Q=7ր|B W",đs%:w`edi4 8Ehy88fkͺ1Am Zyr7-]30(v%5TI[M|ԇQ5.Xp4Z,UUsxelxHUw!n&u=Fpa?><=xEp=ق) 5I/jcǏc. BC b].|*QRf.[Xug%tgrrc9zB2ɗN!ny,5VN#gu8rbww$M36p:RYW+g/f !,kĵ͈4اWw#;'G.Iz$KLЩHGNU!mPT:Z ^xIioB(TVpwڎfYuKHСq{$PC5,ↂޔ6"άap*"4~6mĂ tQ. [0a"PaA107HxeG]{SUyF\a ,.gz5y `=]-vz8Y-%n$k^G ]I]! >1y^ҔJiUFf6Y}~-ɜ`qY65Nkk$wn%nФyIm?=e8 -Pb;Pg[ dPO^[1ozaS5tUҊЖ*GУ[0a^i$ 7"anHTGl)YC|kү`n|EZkdB N.>0vc˔Ua^8ʗ Ye wHv.4k ,ڻn6QAV?+ IX/p U"ۺ۠n@Qic{W:$teTqfO xr*}}f*qE`.1)nv*!LTe/Ι˺ZJWzRν{ta2B[Uw6t<2AjNRi )qAZI^`k8'qWnju +<)"v,K 8@;MLI>2d깰kg/Ly]bxFQSDk<"4T+wD4`Ě<;/RE-a T??1 WcJ ٝ*õAY7:<5U/*X<Q"G^>vTagyN{#SGT[Ey7[uADM; ˇ1rU$nbNo!b5-zĞ n_FXMi5g߫3п+% du,Fۺ4IX biYTS4 2=yYHR7#Eor>&rYj-B1P&5IJagU3P%/^#3T2<oV >x"b -c;5մYJX4 %ҥ]޴p8Ub?8~JeNYCt隉L e>t*WRy270~$trm#\p9HkdQr6 3r<Я{e6Ӵq(l?.+hzpe 3B[laʰl{yt / #1Y9iq&-gㄋֶo(P;Q!Ryz l%W59$ f{CU.F>etU#uab u#  ʠARN f6_²0+hwl̝ozT%U̺x\jII I]W~R2MZBbVR%]}ba_!4R4L,  v K~'Y(x?-5zti'elT&"WIoMl"-ҍ,"=#>r$ zA@:h.86o%]`V`yw>ar-g% ^vQA~9iiF TK f2$L1g`_}f tW<\kݩτ1 TxO;VΏ?>wyp"58߲lLŢ?相[|C; @{uxU/Q,? Hdk" =(o 5$73Dڊ3BYS9_m0~ߛYv6L@aWyMhdI\X8,9!g@v4>k${)%PŁ bIib wY4- *?NRrg"L5Gt@3L-2. ̉g%KATxTJ Ls G Cq צ_ UOU*g*}yu~hBJl$_sMDL890 sZHW$a)q.icZC+`0v؈#8s@`6Ȋ(7 o>6zKk;es9]V-"E5j@FvVSao7ۦKc B}|a$mZ5BTmn*`@xU x衒WeR-͙3xc~+jHt ڂ/DI-7ţهk-]~[9ecT,!Q*_h+TVm\b`^Q%LaPnh)e.[Vkڟ%krݧrB\"%,a!iSm=A `FV@5@˸.#J:('嬶oK|ɤbGiSX\˿<Djb(]ӧYHi$9CcW@wVd@2*Oᢃw u7ŢS)uFɒ< њ 1a mHBX|ɸTUl(TC-(45O=q%(kٶSX#.E|i5-b9ج+t,E|`,DNE, t0PT v>ޣ'N<#f֟H.l3ӯFx g$\j*!?Xh@VSK2ӑϢwA!8:cJ`CɸxNHItc|1uG 0ZaˡV9**2wk>㜡9+3~nhBNX`"D"YuJ=i^$ =8> ꎤRla2l={3Y|kZZeb6yϬ13C5P\͠B;SK?e}: Ηا9?";H?t0}xd}93՘Jÿb«F"wfSu|oZQQTXqJs-"-< Mn"/bsxi7P ո[?Ϯc(V?=ubvB"@.Cμ n=Uԝ2nFM|Y׬S74. Jmi:ş'y~י[tWC#YKi}^0;<. ǘG: oWh1'˶84dF  *e9-;*?3dPxt/dh^c~E6͜!㕓Vu.RnRm2⚉(ʡ/'V9hǜ#b0ŵ_59](AVG688i%F5ir_=Ϙg|ACLS% _p&;‘ 8MU,װ@S.YB1v>ioU<\"X>JmNDJp%5K @TNd8#ܨ5vqn]8Xd I@xMq W1a$z- EY2zAo1%Y{[sWHT-o%dqjТ[Szp1nc5Wx\;h$]LFZ2an>q\x2!Ȃ<(4PD" ǴJL4T 'SuRVde5S^,"!k.`p^RX\^_KDMpeuvH +!N+'7Ki[KZTU$g8md?$s=OzG H*2yjJ׬޽] 9;?+떞>#v+^/ʡaE1K EIC%{iM&Ğ [[i$ EYNFiLEӡ#|떚Lp:4RcDTd71/^"wd4Dxci8al>zD1A>>H02s&4ghjbeva/Cf婡o'+!Y2~>iK~˫kDmBѷI+]ϫSPhJy*첶&רQT-kdk`vq)-l5`zسy)}Sb,th]T27RQ6?D""QĶ (Br.8-V cgx3saEPPJoNTN D¦=ķ=4K8XeҎ sHG@ƢwP_eiR_ rF}R/%͊*1mJXzR|Tvz#lmKmY_fVٮx}yzڱnJ h`^O֙]C Gzzx vxhӑ0>A^FPu6Dtoʔa~{ ߏ6?##ȢW:`Itص; o`g RH XLcdos-:9DmnF;skJX@'|DƲN A]?Y?X[IoxWΕM=-CB9P>[`i0"{q]& cuU"rd9`F\z̩. 6KCn I:ϖtL"Zeo( FѾsL9C6HÔn۩$Krzz 4p/DqT2m{D0E2=ϵ?UƣWzP>$6&M' {3 ` = ]JXb"A'͒2YCy07T}T/% X}N;د5Ȍ"Jvux70ދV<:`XW5]nF1q{~&]luxK/iX'r m&$LN|.+Rl8:8m5"D>n.*);s}IxϭbÁ}P"avK7rxX3i?S4S@gՃ iݧG{4TY2L+}nh@ hR.zٮC>y)so'%%Gg=$RlZE 료% >t>Hͤ\}G}zx%H[5 !Q/d[7AaƔ7P6G4ئ3m$axnH+l.'_󛉈g#ZY?aFk joڹ׌JL`ǟ6]ҵrSֈ GV/ۘamj/Ui)$Li ivPU$hl,oN 6(&U:p~.v[p.`CI <+OTǍm o׆ Zh)%nĴ ?#?%,L+$eD K!Y_eP~KH2Qf'$IN}m+N-/s<ӽ}`UCxVLQolSRs6f: aF-"PRXg%7%C!^'kPiKNzE`V磙]6`rƳmb_P0NUtp҈ܺ,2_M{Da1Z-跺džE>/*PLv|q.TJBr4 wxcTk%BG#'v8Ȱe8̂潉n/tN4~gaNIu9wS NcU^=PCPO9ˆ%mh,Y'ųڗĸ2 MZق2n\;)"bP\aYk /R(ʾ緼PJ w: ,I֭L6 ~GiT߭AMDusg[²G(kus}Cn'zvZ\#mWخ{WmsEpOWׁNػf.B`*pt9D MHǍB tk1@|N)[ a$f"1f\]tO@|{$Uw :dFQ&=*,7FB5֭ "ɓ=I$jR8Q ScG,(fzݯU}Aoxή:Pj]մg8^iJOhiVj^L9UIg/lL{| {u+Tߕ5*0M=]gϕr[ Jg($&" ߌ?k!pJY{u쵳gךS?kYAf&h}Ms&h2_K/i]DjNfbˬ$KU=ҿODWƩ,MV//!_o`9O*%/kx'lMCo Mbg'23ru5anS݇2bL ſlRwڕ'_P@a;<7pj+eqb4ͼfe:v`=Uٽ*=["_.ʘY*  ˰ԗ,ahBCI9}pwHK}hxzcGӭ  &7\f99nPcHzHP+2e )I,^uQi!eOFdn \ۏc8Hiysu, W­iJ3Ud!TlMVB-:Zk1 DgeܲcT} odtQ[W+4E]n1m?kڳV%ibbhBhkCa\ 1T1Ճ)@8X#c~V`CՖub:=A'Jf;[swxAP#X/ ~ (Z}QKQkM;[/>w}EH ug*9Δ/ͤşWetZL< Xbb%':S%f/Q*a¾S.KM0 @ sRms62qb]T<)\TdlΖjRRՠ%']vS'8(He;Q!)PR5'^ZbJshBv h"$wiO``9E:VZ9x/\H'UGsfpڻ%{ٱh/)4]0ۿ8S0C!on@Jh W N; <LtmObяiލHIm޼(/uhP1qivnxU45aŒz\A:-d_ՠGד*;+ \mh{Z϶#tC'{Rc<DTEtsH}KGfqIՖ| 6WړYb}í4'_ʏ|θJ@o,:9zTzY@Hʌdy$!'xpu:S~{تK.iC t0ꍒ I'ۥ"tlR f\T!8$+~axCP < eH^RQs:&Bvjtʚ.$: j'R"{ς}Oo/izsL!/Ss?Mȱdq()7{NYy8p- h6 QZ#$Zx4/Yk\tH~NگsLHF̥$ CUɹŠEyyw( ^z.ǒ c@OPMfXHO"2y&߰!0@[#sl2gR{#;p.3:đnJ5uums|~~ b1L m!W^~%uZl(A}W?Фm!.sk; xD,!)̰/)pul%,85ɱԞ^L?+](rINrRfHF)@a; WP󏺞rl;e}f)'3 3ObŘ^ZQo#\>EJ-0U%1I;2ދé&VzČCٲd!7Z٠+[t33+|X /f.P:oyҘe)nDiX!I+ l$()\.B_ R6;3o 6P]AMXX:p._-anZcS}=.}ߧ(#@l\ػg^|D]P J,E9Q^j#XϤVs g2:Mre98RRY24&mޢp+ԫ{KKTLd9Ѫ\a f U8?s ?&O\R.XC2t*?=b$93&\@;x@υR=TFM=`>áyHLG,T|.$:wD#W>XbdpDqS f͡3?jn:.~3(@B ܸ]tg|EBDf3JO8'v8`v upn5 ȸeE#5"t{bm;u ˑ*0o 3 q*J, h]O̎)3@~ -X)6ugO?I 6sY }̘<a CX}ͪC@-!V1yWwMk^;Vru"j*k1@ j|笔9%NAvF",uL9фs%9"=YsCvuAu)+s]vXhu[]D@Xh+ !@K@w^ bsIij 8}<6jmRkN!ڰ#ҼTT WD]|$ęը}Ǟˮ99"@ ϶@UO X̐iR9nV!X-prDШz[o4f1䯞 $Vai+'ޤty=Q-^#۶?B_b`}㥩nՓr7e#Qiח}?OV!T0 :f;nGF^1( [c8gS|Wa!V+ qHB(7jS|KzH@{U|蓅Cqn7)Ì};/ak>~c&(xO!6W Q4y2J Ndq E4VP{]GUMnC=)X.c zMk&n=f&KQ$Œ.@ Dj4ٝ&"Šo[A8::dyHpwj. 4k9[lU/ҍ-κmb a2f5<8USjk4Pb1uI"᫟B\wz%;dH?>9Q74G%x[ZWOnb$~sF 5drNr3Z(ESͅ%WB{#?-ihcilgוZ3dґ'\C^He9 ag`Y:-V&e$H5zK|p|Fsve*0 ކGdƣu|T"kzy#}8kSo]f+7*MU}&۟<ĐEBiIfS]%[屋@[\w; ]+H :CP~_3ҋicL~aCgku3ɺΠ9 BDcO+VswÀ/yv\yݡlW=؅7ٲ4D@rDrT3md*{Mnԉ0 Jj$%e n']A`WC''j>[3Pj0l"L /2#̴010/zo&3cʀ'b?ΰ :I5ETkJۭS.ͣ>C̍arb(M oƟ !uu5d>-p$E{C\Iac)RO0tq\ᡱ 06 2Χ&_r[qL E47g8}^8(geuxhxFӛ }cLżBUjo]>nA*QߑipmSmMGU漞|?&VQQe!a ݑ@R44@4NTL`^[ ䷩0߄DH .):J.lELo.JH^ -L" jkG&O 4=} @QCϛ>Z1W٫;SF/ɖUʿ82FfYn&TP%&E?mі oz~t tnP5a?nlNp8Nָ/'s]"'#YЏwR2jq𭇐Bkb5{>EgX)Z媏*'{ N)AxWE쩩䝬FkXOiI8*F #!3y7*Ѐs ``& @`g+bf=gVa{჊wMq.9uZ2"YЌ߹3UdhUt$7QsZ=L8Pttzr60u)*)?1 H= P;r[xSs=&s!f-_u5쭯Ons LozzDŒpM5{9~˨bהMc_Z+|u%1)ΎB?ֽu6j]-.".cU\z3% IS]tnuؐ&1+9,S3[gcь5W,w##e3k H VAY<8쐯KTG)jƖ"T/Y&mjQBj/=y~;7!0:˜D &քmr}_tVF3'PɳpXX\<xTU2BeL\y.qi#ŵ& .@rБ<?PoV`(X"Z=>"2=R/ߠpJ:-S|ʕGckb'>:$S,DHvD5X٨zDf6|ꋖ4zhA @Yqբyk4ӢUf5Ћc; B]3N{Ap*KP=&"h"Jz {P7أc#hs;e1Ȃ/t jK<Kq#+sm`1ijL,ݭ`BRsk}rJC2(v;䰏`y aE Iζ &I~xw_eSn÷e -ed&٫lW[gp9wvN.+4ea7ZFF:L=7<vv{GC U6G] hUNMsnگ:"gZHZ/ϑ%GKw$ۊwǞy!hۚ|IWbEV 2u?[iJTap@؟bkXˀoqCW%hQPclY|tLDހkډuRLtdOɕXA5tT17 7@=="O,0Ewx Jv$ӫrJwKj]5i IQmUU0`qo+b@z{xݷ#FR.s-AJ<7BۻPН!ɬ]۴j>dlܺă˄ awLu:`t&D;ߥ+ŃMJYeJ9y6&ه?7 : bvk]<*aF?G|ᯔ=^ Kݩw'#\9H\l~4cuYz6{p>BDhdQȧ0cKlP@*&$U*#E]#&! &5ތ35m2a Rx.SĢD)_d!a@{$g 60QEo!\F,tUͭb~'&)lz2렋P (pEsM&v}X5G:D ptBt1BppKE̅߁6 BU/ LPM?DF s~P 1#AP!y߆T׵GK v ^eX ZkeXfނQX\DimI?m׉8CnHU>Пte:bq'_ 2v QWDSOJVxQ'\RWD*ݱ<۔[4.=+NuEJ\TQ˺H((KXZ'"pi tr >0?"F~^Kg+C(0˳jbg7sr8h -,g>h"hC%aRk/HhݐyZj[%#ShQrTn|hŒ &[;|FnW> |sBq&`5n{^ ~= %'o:˔I6ŷjaZZ:6BByT7!{ptVRڸA~a M*.싫C0A }.-kۡj&үY`bDt]o#}(]镜:%pClvW,~b5 &r8,{$cqJAU萀%"1$#O@童2Mz`W(9"dǽ]H?,9xf A .VzdҬ+JI%Ѵ`6=@ANPOc.yGq;sZ Ws__qc[J}/BIȶ7a8TqQ5G9D?e,Ga*7@g @1k~FgGWgrx,ͩwT-`@s{ͪ|(gM -1۰Ӵ%9?<:ewPb ^+b B7ӛS K?sIӑQ?Ɨ%i{9փ! fKG?lE+ӃvBP 쌼oӤLM;D֍%6e m&ffA4OGhm8ִurgƃ.Qn .vJ(Vxj 2-nk噇!gkj݇btQV6gj Ye1"X8FAw2:)&y68=ZLŕ'͛ɮqK Q͒ʈe5G9|AQ{:]k|H+#H-YC!OAr0?VgKAիlDRcmo M[林`9Ѧc/ik 䫟Cހg&ŀ,?}Vѽ2zZIg xw];=oNCpkVbsH'.5V2u%YKVlW.`&ᵡ}K t`#}pjT'\i&ﳶC$ 쿵lnVޤY .m&ԁ}koբemB_d>*2Nɔ׆B`ƒ5 wxQkn[cYrRoGs gs~zX}W9~ +3QlM зaXP2 ߰FjB"ԻNU~^^2CBLUǞ0|.?>0V\O=AZ`F[|g@MAq Dt|n\k>(LflD9 m6-b'ZOMC9KZ{M.gw)Pm;"hmT2Jܠo/B*Jw5b^6X^"Wy5+:3N}f &ts2?~F\BnUpb ;=7Em!o+(1}c!3֙+VJrdES)уsF˃AbVe }#ES;Q t }"$︐Q0ZD,p+ncAj{ 5(ƴ"mVܫZr^x fЃ2GWdrjӗ4X&,aZ:[YrmXouײ\ʟ (_=`#}Rgnx v9tZx*cm af"O􂁔η|=V4ʡ/ /?-Iy&<#cc6ߩYbgY?/גS(Q{ʿ,8_:!($^QF,MĮw+|b>k6\9J:d`ߌj'f?gsJ]a6?k½uG}t q%)"CȠV &y2ǣZ'Y'GװMӢMk׀ILMYDwly;v䈤: W.Kp2)ryF]5J5w>_Z[E}2p R6$rʤ}~ f4碹iҷ&n3_@050#9 b1WwnNDlig=yB4o1o-~r \6`< xWigu0P`,?]\\Jxb,*`Sa&Pw rЪ&R|2xۍ`kĉO(_z2rW&wd<ᛥ)UO .im>Lz8Aׂ=TVU׮#4uW+%5d';sYh̯Pj= T+`IvDV7 *Oz$*,78xDܵqYr^'7n +dk{3%mJ )Ӎ7(@3U! ;A {qKm% =W8a͛fY(T ~}LfyBɀw~fu4Y}^C/>sUNh{P\֮֒V-4^j] 8peSVtp[Fmn{H і$I?08Z1j`h#=4diՂ"鷭7h}v%Ѿ6SV.oH%}3bvћ?ڻviCkfiiG]#@uUCд@}_.ۜ7S2sBlI/Q1Zo,S6=XŒMQ͞y0jo^HKWA=Eӟ1wnupݟiG"1ذ>ȹi'oГ?,SrHCK a 6U,Y2<;߷!?J -aqp%$DžȺ9ו䀃!z[,돦m*)GRA؞k;?OvPXXNvf* ddVJ5V>0G)85iW-zT{ֵWƢIJN!؛ c.yܤf.ny^UjVkz!⠌Wj!_kh3 C$-v9.`PG5Sg&`NM#vH `|nẞi:FgѨsw A֊LHtHӬ&C?Q|(7s(yu$f+J!*q* 3?6FdEQ5Jqs1`ϕť{3#SLR.Nv%۰6Q SOja ǻm@y.7N!h@vM^Q+N-:ZZ8WQS:*94*!1w>i>5;N={ pK]M=&/QXMgL=~X=+l9 C&ADHWv#$H핏j[hc+7%#q#?TXNrA޵%vnAZV>ZП2ZB;BkN]z^fPE k,>dn&ܚsN FhBI l%Ȼ$q/̞܁FQ.OL(kO+2{ 29#KO"t4ѳx2g_}ZпUVĢ2aw460 3ʱА] Eho*E؝#$|xtr&ljsHq$Fq ٚ4ͷڵPyʀZCx&\%ηQRӖI:X1@t:ǫ%?bM"t_H;G^ڠ.k g1ځk?M{L]<&+zV3J|SYn$mrc)Lu-<[ FhŻ !GNQvgaYW8tKURO 9J10U o>9#\9zsm\KK^4Pf*Lu)XZУXP3Kk1*T8SDʓJC@fcAUZd<56.=yvZ ,Lq*\!׷&ivD%.(P2_&ֶ'#=%_5L|9y-<[+hcy;j*P&?` c}P_ڔ;?B;{/6 GHÒy3Ȼ#_3ڃa][Y-䐽|>c>9,s~qSBdp&HEQHjɤJG_,|j* >&ͮ@{~TavABP_TqOjo?@ ^^|Kg+  6>.q%eiBgp2AQi =%\u\tsAb'$[F0})'_?6?\jc;}O"%d`92GU$? ^x5mYo|ET"e[j,99}4 TI`tA*Q^SL>W{/^!Sˊ/quɌ){5"mF y?UAۀ6\i8ؑYjb_K<7_QA?Nʟ4:G2gQ,D|1{xbD$K|dQt I+c5 ~-.B뛻95_Od@jھb<35+/T'Jh17tϣ k1+}qy,/ _aBf35moda Lf9>25=~,y:g䠯Sn9iA)Pz8T@"i6At;ʹj~ a|aG5V? Q*#xQ Wqzq^0w@k0WJ&%}Ъ8C?ۣ3}X,̝ nǃ'/wi}={t`āqx Su],lEYs_"_y8-ǵ%`5KiQZ1=y?p:ިtujv7$2Q+S[quQ*a29&dj ?Jь2K4(Q$SW̖ڥ ;O=I nP L1@cM K_ !ف 7Zh#̘fT[a|xp UOs#rQ~Ђ{S:UVʬ=d$~U y(jUbpun)Y!4yiP<Ѕ%mZOdg:N~ݝ|E*HF]ʁ3G' AtᚈPg ʋ3fکа}p|VrkI}ֆ#{SMvλ|Tpyh) -rb|O+K4N7e=Y̜:8yJt*6]y񟠟!S,Ұ0s!I 4.w\|U4nx6]ghw4xڥrB),͛/nv\~C4ջ8eU53 Μv? 1K5t\2KS g C},d"{snbև$ڝAdl"’@qZ}YCWXvybo`=P#ᛰT+Ww& =7*Ƿ涏mՇQȥ VA3~ik!_w۷ a9h=?r0 wŪo_zi+FiVars?L@EtN"T{(L[@>[@O" 6f#$iֵn铢U6O%sY(Z-%A,:vƢ+~jrq0S#B[e#PBP>#Z0y P \,CF*Wk]\86eOOh5i`h()V`?o\HXlMV/ۺ?>Yq&.%>fsRwp=ƣ+U·MϏbUy*+L̹!WckXόݥ(8\Ts8 Vb~c3 ڐHz#`q `aa?{Q`rj50FĶsyh*g5 ' h3R"AZ& X$zw -lVx8UjyvJ^K8=#Qcq8s 9i+0jrM3C?H & ۲Kv?~ZZ)˱A5 O?S37 3a:qd%oԀ| Sp!R]WTۤKGU|V7KVp|#m7!fl   , *K]"pc˜ٍdd{,>ҋ:[Do)N,Z^܁ٱAO/4QȐbGql5{EtR MV ? ~WHΒA6tic.Dp/T~^uL G v4/^cgҊOb68gyv8(+>@3FθI/c %_G$Gg]0}8ypzսӄ{'TP/]}\zqP$'#BH](4r'+$I2]la;_qVSտ~DNGݜ,r tx9sB]2(B:ȹs-Pn fvbHkYW Nc)O"Gč(xXSlmL)FS#RwS(*bYtcuw=ƧЎDQ"IR'8LO+a28-C~/ˇaqhƿIt尰R֋a$/(_VǠA$ف7CeСkK~pzPU#ڈ?պ/faDB^;XŪN\HvoH`P 62jjSf~{<ԎyqmD&%Τ:`ӳGWemAf_|}Q%mK._8&sseʀ.m0:>D4n_} CaXwSW]Ȅx(KSoZ٪}iB Q6RէZ_G\k ɂ~`iJ&aBɹ Ȗh8#zaƬBJY3ȅԭ2`ORI>0M@i`[NVƫB˷۽0OM2D*r&@ @"HH-g {o`k\% M-7#|x5P/ۂ&Ce2Ίgiafg9A\:a!-0ڒ8R (@nV-[ c̾79ck;[" oDT`Г尙QP4 Z{kUKC-8N"+9X72$;w6¼~*tLIJD,FxD PRN,tbߎ1Ƣ(a,p0-b.طub{FzĎA9nMOKWFbya-gz{$9R? z/&o&R|+Rk7i3Ap$P FKxYQp}I"*'FK`T6eH&GG/0v # G/Pj w1S i|%W<e&0%!ttdtzF]F{P#7g@TBy ΂#0*\5D蝢nAi"h:࿕&@O0/6d(]ٸxӥhQ#d&so<Ll{7=lA>yv/) ٶ|ʷ4>$YFxN0iqQ*>1)=!@ g=U+0R[3u DM+_姲56 A\60M+DTY^/O! gDZÕ2 svKd|o.U&slۢSB6kvɑ$y2л<X# Iwai(3N!KؔYoeW/4,gc!"$n:T1WCй>-/ r/GAF+i5VY|fΦ+j'0\dydX,?.9K]]Z{-n`/[GpjsՋ5eÙ%om ]!=_dW"­IHc.:Aa&w]V+\FMNR4-{O/;9w`'/wVy7wI5B?/XaRQ5HuHF$գ48$qf0ekں=N }Ur|~y}IA lq:ջ2Ki?3$[vfzo5*ǶκEqR%t3YPx‚f4FE2z܉Ep\пMn%ŝ 1ɪa q%O*!:HR~}S͇A3?3ı2};~ "5hV+ǺaZ04Bo1OC=C >V2P돩ZJ aW? _I /yyꁡ=I3 pI;TNJF\U b<*6 Y֧ϧhSmrn)I.ު5"4YІl/q+sȫh)7!U-YKnuJ.{-&}f?T>= Q& Jn޸LT/pD}7O;T+ (0*ą ÍrDls ի(O+@,D3mwG7ؼ1uy[dQΙDŽdf8:DzRѠ=F>db?FN3⏧ 4q$V&E NC!>4fm5)>Zn0spK<]6KΟ:l9+[2e9ҵM3mRi *OiSK/f ]u~8f.wՄh.t~.7֏fLK涺:Q?<;FIOZ5ZY%`48 a O\Z< UYȎ-hA\}KpµRE`g/7 4'7K7@@nE0B˘95:;Ɖ#m+v Mn?`Iz 2v8hʀQnj j2Y|Mk{Xu- ]=$YFE@$+ A,#O'|вTČ]9ۤ[AdlW#-#X2ONoǯ{:m#ʐR94r l/YS@s܆KZ**HdqDۋ P7dߜ{j5ARQ^afα|]{ VZ8JHI0yCAlTI8KXg"EL9wX4ΪQ>RvÏl,ѿ BD4(IY؅T6 h4NzfdaYڃ)GhV{kj^!T8z5i*A58@J:cCg$*,oPߥD%&W.mJjK_?XP{6kq ߗauXs1#ץ$n*d]?V_+qgH Rp_m+لo{Qin<`z3^p{=7F|p"!թ |T-mC{,èɴTF&Ntz(G@* [CwC87ò(]m kM3 Om `vۅZ qLajq\<bF[ߡ8B].7V]}{ )ҞRcߐXDʌqjDg+BVdH<-2[8y:8s%^\%]%ѸCILl)> JS#ܧO {{;^zD5}%1TEu,Zrz|UJݩ}j$FJ.)]I"0i1Wv-ǩ HaNE2+m wN-'6'D=h$%LؕbqA66UDso=ptxpChuFc: $^(Tn Wqm:wq]G儠)RdgplI@R~$q:\ԵYÛʣ4_loI\PFLJWE[H [iy|_4, G$rClgwV;,@N9C{Gtm[ppZ#-͸# ksKPtqbǒX҈B@)BE(:m0gq>+IO @giP8|,LF^ZGrbUeo5ƙ&OAW^1!kHi 8G E> i =K HO;(<،SU&%F@ "2ntgh!m<y,0| y@V$3-T4 HJ?* vW?x[Bx(Ab sjĿ$;S<k޼1q0Mr_WJ˹ g0tⷎg3In7T:FG Z2&(-N$lW v`6MšeScvU4n~W)Mp#s3p (Qr3?u(MFӈ"k}%1QYg5T6t$4}Q)ttIy}Y^2t>&z{f\l>FD8y!mnKg[^u;?]!cK/ʐ69 S l$4w]e 5sD1qѰ:O3t b[銂UU2N SOT̳}6hȖl36鑁J(Q2Y雊Lix꺔˱jd}B("݋Ō3fjpY&%ü eMIiȱTfr,z 2SWNR4ςLpuB_U8 ,i\B+l?G !2/e_XЛOsrO0oGl(K";lykib8B=?7sĊ-[!y}Gt|elzv_R4T?i3sO*$f=q-F %@)*cL^,5 =9#+ʔQ0WzŬȇ4U@=}EFrѻ2yӶdZ)mla`z2.V^d oe뺒'OǺw')p/f0?CY@$Li Aqi>H)eڤDL5xrۿH;LRs#aWPsS' sTI,M/nk,,U/*q2USPeU,acm=c;JmƊӊNص,AunVO2c+w4s@ӎFچ?B_Y A0?hYvt)Yx+z'~Eq3Yp{f)Ҭ1u'R (Nv58 >dr;0BZ0ɼW?( a>0ih""_{EXpɂkRFfdaEo_Sy-rF1){Rq +o9lHfg0@~x PאQS2>jobbA0P`˵W[hIvS-}(eb{rbf dkb<5Ꮊ X8B/8@qοcvC|{cBN s0iNwIe:kn^=iāլݱni|\**dĘ-hV=CZM ׈(vIfa=_"B2 yRRCud#>Brn4 EgxO9l {T #Vek_YΙ |AqяovЕj.ƌ6Dk 9: &V*`]'Bj6$uh\Aj; G8%gŽFJ(&j;|e-I,}qojm#`rߟ 'n@ 'P낫&A iLJ41 tFw 6:vUs?G=1zqUk|BFJp}䬩gg2.wK# l)}z7 >"F1[kV&MYɂ$x&D7og#RޫW2,e6~֊ |̻U52@[(qmS3R@)DΕB뻟@s<MVx!<!!S^uQ 3i&@R7j`<s)r)x%T~"1,u-rRAxg}ծ&#+ &'Y#(mmس_a]nݠ݁%]p!Ip ju|t}I! G0 [, NfgNگ>>MAVʑ췙kNyz -4?VHCT=Z,zS:z5-Ɓ- B8.zv*O6mu+}Xc1D7J+$nO(m*+)fIg=̅S7/UGVw2WڔvТGo0V 7F !x\yZIMTY3!=-=wYu=n%cf sNjL6rxlEKͱ 3VJ+u:K]8h^ HUM{YB]|mՌ _=I:a`cT@6Ω^26)ڬ.@tg9WFħjߟ*t$Ǧ5ٹhS9^ Ap%뼎JG"ᆒ &wfrArݢ4Jp"SWA6=ia>,cRiEF$GUB elH <>f4Y|h%[؟x5:[9_(ԐU{385NT9e!X.,}vmyY [$\0ss/[n2 #$fE .ec<k1pVl,{Rl1Ns|;`.BNy4a4B`KV؂UfLjB5l5^pWCJpMW6 HTn`9eaO4ܛ-<|'|Bƒ_0S;fD0v~t64wq*%yoҧ妛z5Sh#xq1Tpu?T. 鿪Q ņa XQHsB5MǚTGEqE bR2ec?Nե%>OY@䫐P/+!Wu9dF ,x]TW?(R"l/h*B?6HhRM &YkǕP7oNKmeǖnLT\|keoZa(=Lw m> ׃مgTڪKL7sRY+>vͷn<$6"!JQ#x!5RRI9F>7="U]ϭXf"avEX'EK 羯=.?Vl6E,қRI"Ӳx&H I1iU:Vik଄nuzpiH̸7g4A0[r'}+SBG~"<0F F58i~U 7WE^ǏAu]gG5I+W^)rGzwCM 1%h[ʫִTEx]{q/";_c1G.M"gm}z/cSf](!; O(.mv« H Vb]Rބd&H*(;0|IPQr}-5K*0z,WcZ-"Khg{3=|̣B'$pVqc prc"@;?.FŌ;<~;}lk%hVwG8WNHh-ŵ@^Hm@HfrXU Ҩ}j]\-23n ^]TE8WhIzš(,g_]VG¨vNTdӢ8bpeДYȱӃd1rveXOKLr:v,C+[^T}bv 62Tfu&Sq>`^?O07^_r3ll_z;a`> &^S:<&2ݻp"QMvu~BQ.B껝 %`9\X/J>8*q:OZ=؀W!h`_~pǖSIOږ L]JƶCkl<LxRVL3dh FwWVlShV3p@yPcJL¥rAK % q[+ϋ|'ܻ6Ŕˑ DlH+9s]Ҽ$ރG~e׆ huy< |"=Iqfuᯊ<];\{zog-s촮z$H.(z`h" 攙N:b #oV 4VIa y߶zVD݀~78)VF@|-UZ`qJ|+F_-_ogrB a!+~vYUn<, I{3_TڳUZ#yd BRƑi]F¥>{<͙Raϡ&^1w'aNzp\CЩ9:8`l: oDd_ 2ɔ!dM{}F/lKVVTi,z(v녒(HBM_%a.1˺Řoth-ț W(αW1XOJ$mf\+ʢ& SM~JVt/ xOS7c&2.]~g NҒ! ۂjrrf Nު# ߇{~ݼɚҵQ sE(ځU'HE<]22ʞyޒ-ۘ~%Ny]LPx$s$v%CoHr#Pgƴvʝk= ,#F7.q #J!X]jyP.G'?!K=#n] `XdKid@RB'2.+-m; 5ӸEZf0\I=/Ġ*[wPق.F2o7^?5M0叔M7' AY7{(]8T/%3ɮ[* fx0$RرzosYR 803ۄfȊNE^my"$mX)7!GGJp}ڶ[#mebfK3ttDٷU8{ jg͎"P=wrK5 ~07Es󯾔+gqAp<̟`.*ç/օVo-*KTs2tV-tro_V_YԹFJ5NXV=?*_جvYQ.{G`!Xe+EӚ5 >궮J?2?|aGqR+.UL8=A.#R"r /X͓]!q96F}]2̅姁z1,c U) BA|P|o bvK`cL@}Gw`ӶɚwL }9IgA4r1Cq;Dn\\\=\76("xduhmcͲvYN6u+ˇ8J_2{C9wlY$>; 0q?ON]-Aa_5$֍#%Bm64h8PVGҏwySYaiAhE)PU h)f&PPd'3I(Zkν}"BsI$i_@YC&5!%vjf\6S#aC|d+!$cݍdg~GdI3,(/bJ^Vý10^^-zPFB:e@ ~nYu[ծU\f\W"jB4 /ד_,+? IVW=ܵw*>@hP{%6>q@,,MpUw,]z o!2M:RG@#&$ByqY=}?4jh+MR  Xnb3^Cl\ʴN4䨲#1*kS0yWEB=GFϞX{Deo*>>9jf"IBS.(MG^HZvK\Ɲ#IxGOSs@[hH[9TÝ[њ3z3,,OZ-ܺo\{oT[5bD )|!+tܙЇg7Pq?.#qÐMpr}մHvX*yd(R6 ]jO Ww_t{@HYR}ISE+O} ƱFQD>T̹_}ZM^B!1H#C-l7|M 9PB)`Vΐ<RtSVQ8QiHfɻU%cK"f R.P ͱR !AB~[jaD&Ғ۱sp>SP(#K:͋So={[QqXLNE+8NM5$tX|ڴJ1$(+XQ5)Gl3% s*{Q['dIVPhŧrwfEeNd6 3 ޒƬ͌EL]hF[,;tɇi^]PТ!&\>c[ɦ 3>__Kh!v!ce<7n,>|]$\2d6$I?0MbrrBҠ;[QH4oȍ3t8)cYԆ7l,Uy|u`CaM)q%ʂ凱CW1_LE* o/L*.w6@s߉4N7qG2':b'x!i98!{i [4G^Nɜa:ݢy,c&>)\D-9Pz,D!; ?] LwNΖ|34)u1 NY%Q: xUtpe` _CrhZ1K mB_v߆r7?Vf">??);VO(Ao3(J-HHmyNr|3LHx!iMdd7hBw,mͥ\JQ(vU 8 7ƬYj) \Vȱ*nc_*)n>U'fd v1XAu1X<ڤ^HC-A j̼-% *D:G]9-} i b[3yk@pTQmQZ)U}خW/r!, !, ޛ)UN}J.VvNKHllG8C]u'P;#8,Iڍo=| XO&=ãgk@b6ezo{ptc` RsBpɹ-p:=1y˞s> ̳-]@t욉9^)eg]5 2V_W`!'q5-ʳ Â2ܕ1ƻ@Cie0.,2lDL΅\[>" *$蔥=s?/eh^KD۬AN%y$_hIKz>#VE!QLg*&8[c(/ZYoFK Ҽ5p_Ψ~il'5y^I QG5J\u"g6{878BqƄywG5HXmw8Ў*8q~B&<Ȓ?'/~HeznDJWu=loa6k_9P׊!D|1N1@M<=ES\`WĪ "vC }~4+:79cauf!)wyjt/3w-^S6-s@ "f6T0/U!C]vSgj;cLW!ů'@S2"%m}B]$_v2WaUW ?̭z TڒVl%OZU!6~;-}:k(Rik >&QUV?nNPk>@9<9n3%}.:A|ܚ}Q$]psP "FFCQ_VlN%^|p S+>Xeۊ*IJ/6۝yj T椺@:W$Pȃ }YBBgkpa-lGlXw,?xUCiAMҊvYu ĎZe1=9\OΡjvf8!GѤ_,2Ewe)G|VX+xW(%ߐ,?iF|Ek!l`!2oeSG~ vv hCeȅ5x+JCAܛBsc{P|g@ȇurҵNzo:js OpHJO`hӟmQPdWÅ'Ϝj~G!?x*lQ%NYN/#KC96OV>ա"+`~_Sf=g(]~qjl^iꈑ+`Ώ X*^6 sqM4S1`V9Kݝ⇉@4n0IIᐲ6tN+avVYqee"b=8=DŸZ/ɚYF.Q?;'nQGb;,KQ&i}U5LyO ͥac @Br"MxU3n=rD+9N%룤u@ЏkNyD|QCXb>CEpx A`ZN+c6mjb\\}Oч3"{؉!Ҡ3MTڥ$=|{vkW ߴ7`K{ƍ8EzH1Mbw߰cMEO%?3#X* ͦ3Um2DE3Vŷ3ԐCUDs^CDvEr9s: N(?`Lѡ -W'1֎$3R \QgH MLe{H3η-=/֖SEf ]+ կ\Hq9僙,pWZ<ڳr+0 :^ F ׾Y}yw}dǔ( r5ϻu %ms(_K_8`(-* V*BMxg{(6i!O8|t/ {Qvx: (l mV\ȩ8ΰmbSgC^`ƚHaF[?MK &B4'rhV˨5 42 (w8{T To^ x͵ BКϩx16x3|*> "ϱQRz^,::8Viuvc#ni-•KW5 iQ]ᒢ‹?o%縩W̴FS@x@a/ Wˁavvέ+%V Ӣcġ׭kE[DӃ oEmNʵ`qR,(LΚM5b zp1W4j5c2-].w X W%=?A?߾D*(" g2rxM%&X⭨M^~b0;3:9e $A 3S#@ +T ;G/&? Vwf/}$-` &/GAhxrHR,spe#} nw[$cPd nQ{#K= `[aí0 ir`ȑ@7]f&3`_@=D˕>k1zh8 MwWF{)?^@e(uj%봤T\ ;f rAS(v:GkѪ4 <-EI̫|-c~٨ji_?W^W)P溼.#4\ВPql0Ҙ)5 !p]"Ԡ3Gd%s[ j[eƇd"AR-rSfq+z0+$? V'| п ʾ/q*I0aٌB֯Yߝ( c8yROO;:e0b= 0+qm4qL7bpR2k h?1 ,V1Xx~P҇k: ޕ1B}w>l>ڿuNvJ!j80m[E"j 1.;`SSkfĊbT1:q mDM {e>?٣cE$is'#FU`g *r>TFQA#Τ- }SfNb '7\.hBxIOQ~Wj!"J 9eu@{v Y ~%iGz!Fs%K*RNS6l&nx.(ƹe/q3lTEo79iFq 4sgbT[͋Q2똪>cֽħH拰z} U8Fnz=1wgD@Ʈmb'{ZE%Fy"05F;恼&­[`,vkuZn)lEb[BزߙLM :h!ZZy-)AΝP*a8rvƍ({ѩl}-xW_3dmt%4C`S:;/m(~78<>.@:]Lm%Nٚב`agn{ҳˏ Vj{_i"TFcv7[/鎴dʊ(W[T+J2OƆ W `T=ؾRB`'FyvE*?.5T``-P2Tڇ`\aj1T/Sbvv^C'yK33 nKu=@@H< ~.$Jا] 3n?LP?Z-^F'җ%\-2-ٙن=GA Cn`#'oz^fhč Fטc,:(X&j{! Ş>g(M"A:Akz spȆzR R;q9 i?kB,.,!ȁ9!YsUW-ԽMI `V0!/X ONE7 eSO祙vFpB6Oeʚ[RRc 'n&/XO?誝ZoȖ+ |8j Y0Μ!3BKtiYEEHd>p^?xZF$K[tK0E#ܧh=bJOfZoj3" - Z/^($naeშtnNG;Mt/Qt,aJoJ7gfl:"t]@8b?KGw8UVOQ'&*n}hVUށXDe/D"{>IڇWw=JRg!,c{T{[tCቒGb"Q ߡfZsV@mbBMfmYվIADz-C)zyE3F"W%Gk*L =SBJ\K1`m)( 7`ge3%h$hW`'!坖SF?SﭶZTI 8I-29;] OY$8}!۴^=D?sɿ9K])QnzL$1EKw[G]8e"OnJ}vGQUԞV\N\iiY3Kk)SVx O[0Leq\〹V˕cpfIhq #G^ǩ,%vi+h}sb^!wOk)>b1bA8 {wbq˞+aOJc݋Hj&ϙljiLmo{0yjͳέXNoGm=E4UTR%b)9e=/$>2.ϣ#\m$ǍE&Y{ގ>_pMW_@[.o$mA!~EB `HFXvڡnbVxSpɗR>}[?|Ԥj3gU#0L01msZhL} wi MlVjnsЪclm2Y]װq5!9`> %Qze뼫,帔-| Il.3BY}cM7fp *1S.+,f)Y#1\@v Sr!˥QCBPm؏ę 1բ8dw= 0a/CEkEaLA2Q(0 7+v.L*(G;ʿ727GH*EGՄHie9/y?}3hDO ?s (!x0%եȝF/ynkjZҫS69`|rbMPIJ2 `iɋ}p{+i3Ỷ((>5'@-ׄ[jWw'XGsp6sAL=ʤ3hՄ&Gv"QDFbM['(#f,GS;uTIVW Gi=@3`9Iv=ؙiWUԢ}P6m9iOK-jTEl\d x[dlŒ$"0e&H;iFyL/F2s)۷ˮkӧqĜ"gŸE3 )!kBkӸ!Y Mzk<Y<$c[{; dKM6e8k&.PLz7W2۝p}c9r`f+vpOgߴTbFBbfGb`@L*ȥ8752wg3+Ya ;kCa/./^wǟ2iQ/EJj/&iкhSJ78˵:td4qM#r0l=@"n0֡YMa1Y1Dp)[nBHb8HqɹŹ`$ӝ~8Z\dLNoL5=I`rRjxt=%,E*$~~t1ݶ>^; }L3s|\q)dEz A%֟!5y:pJYFLqNU͢LGKwߵ蔳B)1f`MSOLz]ST/\o2y!wUs6S%TPM瘴4<"E4,jhOUu)zeU曵86\@$ar<aWXܡ4ZVRɡ 0m$Cx:KA^r 77tF-slptr( E5DjBm+OQtv2>B^^:#fg<MbxVD, ?Δ︪AM¨܇`U M4,PbZ0efkagZsʿ$7@: MJy)Y!2"^s01Lc?\Oاjsd6mvkkW%+9NDk1RlCdT%/X3@AC]$(O~A3'AX)0ߤuN?W|}+&VvqtƎ_VT}{ѕH,70ân ~vg}FYmȹ_qD>?/ 9!`m-1` je @jZrCT+ζuDgVwQ~ݬ#k,&GV$b4pJC6vif-r)UWeF\4h1jb}ȲF{ۗ0`qϴo*o,4Dt'"BxD{#Q*eBZUvS N84ݟT6gG+|#9N{|tm/ƒ"50+?zb픾D;=]u 8/Ë#TQ4a(ʋoD(&ج]0[C<)_Hog]v>T-e@E=A$/FܡZ ]4}IF*s!fAÄ]uaZqE)9;0`BK Is2RdR%KZQ*oe{}46meM=cRϐ%g5X|'bn1lQZf W'$#H 3ت-%U#; %g3/|j1[vUjS S*"GgЌKoR՗~& oS2]$`-U-9^ n|z JlA·H! ښ̝IeaK'pdP5o+/ϕHtGޝ,Sm'v.f]$?jg˖H˦#l_#ҬR!9gĎqAwmDQW%eue^'Ģ+Smz1d+^GT-LrOˌ|Yxy+zί,Ԕhr!dy8,_4AcՁתޛA-^=ct$KdՂ1 LW~CoxC[(5nlrǭ8XKpd~2i"S$Vtʘp${PaS2 ˰7d0+bYg!$zϒzN)uKPw2-y0 U1\DeOӖvM/<^F6sNM\8@!osX.vAMAP0޿yځCJ ^p&!)x/#`#HPGku>x9'HVh"S!!ҐEܯX,,Lryy&'ᾈ$Z{}jxd;h&fT>w䫄GA` pPWD/ǭ;_{ 5]76qsih髚ߧq >@*mrLDkՍx9L,JѴݼzԻJrz  F p.=?m 鑔MP]fɴUF[+ꦅ ݢ̆12 QcB!iőf*G Pq [G_-3B[?O-˭9٣ˀcbTK, sjcw OHWvt/;5HMQNZM0йP*'Wp%Aتp],;O;yntABTXX!,Bih4^&Vp&B:ξwV@\r|}}ȁBje8#IuF9gTR,n M@Dzz, *lWPH8@hx $6nNw6=y\AҠ$p[|t4A8e:M b2^ h>RNk9>J 3anӻPjA)HfA;THT%Ո@PS76{K0+Ԁ(NA}rZGw S!Oђfʥo2O%-׸辮p2U:3Q:ZI6d7CB}$sYxSdOIL]\ KcHugHtcy7dFz `5 ᆽ'{r hzE9LXtPB}Dgyz(;y4$O뇙Bd+-e$ي8@15y`7ŏ̹?.ܷ̀mf%qioRw.1,y)׭$U72*]Q/LFF^]q;,=NԌzh _DC s*͔okj rUê4po+T*SQOT'C_{? (lk:?)KrBA%gƟFev;EfÎܢZ) npu C5vYrcA`\?p!!e|UOqd]&bO@) ;N]WGw"5(:y҆)x-QV`ץi\,ч'[ɛQ5$r~z\*&פs=hK}/ƺ,Bt}Z݈";^MUT:<(orG/:)CöμS%]xMն Ʌ_RK ؤneDqL[HZ`+JF;{zAK]\L1BvmװaJ!%}늬B(G6u<OU݌tAZ)>24堻6|^~?ު`KG8u, XwaN#6SE]a8a\0lytŀӾUn}\._"ZSd8`%9 ηdlg:j-ZTEQ#ߣfTබS\( !NHȫc%8lÌ |Q՟ث k ťz*JJ ^g|J|V?sv$MuR4S2Z=_cC 3~  =+ϭklO3._8ܨ/iQ> dn]bu!tGVM`\C yJtS~퀍Q0BҼxV;:w&A7WMX, .<<8l@nj>-ܦP@gT?V`cGP1yjw#w(\؈-uHoZdWx2q[Pm"+ق!RC}hP.(P"m q$[Cl"%n%!0| wP`+^lxFw]]" &wĺ)ߣd:#(F.kl%N*&Zʩ^|;fCÜPMӕ,nJͅ4?M=v$"=_ݏ)sFZ]mش#v3U^MPLmq:ѷZV^G6fᕇ*]HH)ѳ#KĎ?=e)w:%DO`eAphn+{MOO!`"T6kU95n- Cq.vyI@]ߒ%{Pmvt.Ic@nӉhyZi\l?R'j2xdg&<غܑ6UyeD\t@ Uݺ!FrvoDJ'i Ĕ^j55mblS*)Y`h/Dn JGظK 3?8e((L3sZ%^6{Qm Pů> .`ȂH&C5?K*i:CR$EOb6Z \ T(Rfs|H?3L֍ ]TcGݛzn5XH6v Ҧ6hfE 32yN }_GՍsMLkZ \;I G!;1Sy8ƹBg{]"sl{9fLP%;MFq޻],z90&hMEhz{Lݧ9${ /$.0N+aW*~.uLmx(ȅItyBtج?:f$Vjv2UUn$ݎ.EvĉFz?B[Xh6HK]j\v1S{^WoE #+"FL ./ 8@9"T1ިj:[1f(3G^ ϡȕ!ܺ,Hd7%$~݌XZP?6׮A8&6I~wN($e!O Vx%Qs;$)_[Mhghsm o J +w, Ȱ7 ZiB\8:[H?}tѢwfbwdk'MH]v@igPtY‘,iö~$PCa!qyPDaգ{H y0aLxơ:ab|e|-"{y($óAyT[[FznG,Pv%}:</zb 9C7<#Cm7dv*7Fҡw` ]7oqp7v 4IKP#8MKԑ`ZJ˦xn:MLx&0f`y uor{~Ylñd%7D_>m(#|N;LI#i[Og,/d}eBrԀMcqnROyw|9;Y|ǂ&'5um;s]ب^}WiX+cc껷MbQ TĤ'AB#wRxn =EUb\[[:%)©oY'L/EZ&B+,M 4yai*ԔJHsv.c)*Iڵ~.+0$~Q |O1 F U=嘓4&j ɧ (n^6|d7pn ~71$ `1)?Cա_h6,q Mu }y1?qך8~.-gjTͺ5nJ|>6O AéV;[ճ{{p`+ګ|Q9:kBHf³fNvI2zC"e.NX/d>ZSF }6cʡVkIҪp9~F[1ďM$Bl?@uE-qɀx,V \ڠZy#XVY41dNk3QĜ:?i gӄ__w1^3#7οEUR[ D pS tx"a3oPiZFZ*0Ehv&N x,jd ׫^I};휣{R~ȵ^/m. vW dX7W@eeԖI x,j->hI̟(?עHSV>ILAFWD.5 lPs4WtJoҙ7]L@Z-mWRϤIV[s@)qN]eYzD酹Ǔn!H$5께8^g+u{[2"JYk XSY?%AzWlk;f^W-Nm$UrKlȡv,L|AWם ma6݅sS"|pTpɢSX~?ZjR)mT]qN?&HxmVuB5x6j ~ !<,e(\Z '*Fõ_03hֹE{ך{6 ׆SiD]m`7cJl*Q컄ԕTHۋ [g饃2b"{P""ibi/LxQve%9+OGxy56;M=Yn i%PMz*JoU 0<ڛ< ڗ><\~S{TR5S cXM5.9LVl5谦u$RZ`O.,85SOSmeI/YG֑V oo9i<&S:hE{0^RQYI#`:Fhn ꀣƌ&=^5^w[^_fw϶ҵȐrJPjCXl¦x#H|! Cs,xڰo5OOއ0b3e#ClWVڳ7#oOC̴SIÚ+fw&ogiP{Ħ9;/2GXP ?.5Q@8c/ՕT|(.Kc+"fdEO㠺8M)sF_s"|4>\ z!P Ma z FٖOVT-jiNb8f^k(-zT-Yт;8HYGؽu–@%1&_DٟVE8&_A{^dLsJIKY~UW;粇 ;8VREwfBML  ﬖ{Z*BҒ/^wܭFOB)OØB' 3բ @i9薱F| %*I8 ;U~62HmyS >cjaS22ǩ YY4bޫ/a@'z/>C(f/P64FaFjyE8 }nr}z_ƿ<лNLvm"+rƤ ^ Vcolx) HH9Ǩ9 gW {|jQSE^p*oKf#n; F3\*;vǴ7'"R4 I3xG$޿T݆4D6Bִ&8oE32g*,]'v5$D*+S2F &"q| pۊדɀ-UKy=50Is֞OC,/>u62& I1Y_/5ehǛ0%UwFbL3% ~zG*ZCbxܿ\:jBi�tZEsiO(h]/? fהf#Ty1MϜ@\soX(lz2E}.1I)vֿh֌a- sĪ,Ӫ?dONRr(ĀPa7X[SfԽZsaN<đE`X0ԤA - Y ŧFÔln[4ȐLp# fV`d->.2tIzcVy7FʨKƛ,Kڭs|%Ƴza|QlS ӑ"\PJo VǼЭP#AJj_kx- 'W_.θX:xTBRy"-"1#,ŏLg.ZtNՌАC3N5_{sFKN8jh6Vm#_xhv먾2'PMqK=SwZSN9M/5 R -?J%ZnbSU 3mxz82 Eo9M'@: xSQлS;~o7gɄkRB8nD'C#~x< Deh8suK^$vjdGG|#9F=GdΣ@ƢX\DA6=v#DU:99#{ݰ eWya@*GV.YhA c?ݫ4IfQPW?OA$1tgs! % uGE(=wVxj}x \ ASitDWvr?aEy֘ؑ i,.'''+Ū+! ckfF/'Ϫ 1'] O3\Hֶѻwj Diō 6XӀ$I:̂HFF"Ͽ 0ivgl enG'&w<1Y%zqoߧ > Umr&}`UP-'y] ngE)HXpEL]'u L~2y璙{άɾմ&,ѥVyg&WzPM;ܚԮ֗U %k0VhfWQHhﲝ{Q.ůD;Va*^T1?'!%'7;@{,~qpS@I}xfDž2 , |A~[ScQz;mz5}\s /'cHTkoBC` 7t燤STJg%WNK+naSa,}aݖ*oy5##"Ǖ(O.Z90v+r;~YzbwBee @w2GZR&e. ·ְوK.Zdm*ܬL_c+TOa3E3HbT%Estnw(')kw'QYdb7b;4 +nV(޵-F#b?$ UK\`m8.+JC8n?-cs:E&c;II,ǴDԛ=Iy|R)BǹqK{=ي;\v]!w xfFJ2Оza^Cz cc(bG88[/%"qdCS#<&+'La H~l!1@4J!rcp8hX^7 Jz]y$B4y2ʒ{*fm/LOOW I%p'clg̀idMh[Ȱ%GQ OJ 6o8z)}MSB7ȵ1*Ul|Cdnp [#9 a/x\Wè~0utw.Z8lSeA)?>j8#M磉_;>[ jzk%F2!Nq򎝍\%(/7䋈Y]/:#vϤwy"[TEJ/#K۾^lap7yip4CCX ݆7Y)G=rrrz.&l񕣞4CY Nv $L0tcldJ N@tοuJ\3WP`&ʄxR_HCj>{&,E;yE3eߛKvi9-x-,]. \<1` Sʛ9HVWkϞNˍ A%PO׿]u΂:k:/RNC?5Bh$D(<0cD҆G{͏ V?5nJO+h*qCn1Z_RsDCG>𑍨5lTV5 6HЋ2ZL$$'a8 AOЮ^zOD骅=Z:, ,bymq҆!Z3k"qqUZaY,~%'5P] S#N4D:ї`cMxi1"+tqC*Tb۹pA^!Ih; p3'a=%]ҍQXL Cl$t^P%[KWk}`jJNc5I c@VkX?9k+V}S]QoPslV6#:C!_!ɽǜ"&b ФzIax5UzXb[!~<⴮LdXE)6͐,q~< ,yZ S|($9ءZUw8OV3x9pΪvszMJeFqa:wm yKV6} W{S9{WdRZU{1OlZ]_^cD0 -c7q8zQ=.L9Bbڄp %WaR,'ߧaZYzU(xi#h*Y9lլr=Y[y[Sn8@]b93qjQl[f݇L}XK7+-[Em4'P:/v~^Lw @X|mZ/-g^ ";{0O =-'=ث˘UPFg^Gq*ͯN@x,2.BA<=o{'ﰲ:B#aϙ +~ڼAWx}sb^ h_8 1]+{8۵62vDcwY=jxOO8<퓁|Fyx Ռ"|󳲵ywG4a, Fso(Fᒝt|ĺ.*8Re`oPd! aJQ-Kpo@sٵYH0wlUɶ^WcvzPj"pQ @S3òuFE{r"䪴6@"/B\MϜ& $)r*Bqfa]Ia.z lsRX^z&T < ?D 7^G/RX[_r N<x.H֊]o~g=X!&ŪeGgq^ͬ1ie_03HP4?**lfNϕÒpe͐i2i{D="4ϗOX~S9@ X?Eڹglcٍ=E J 9k&>B2ёdSaFN@wfvۛRiz6L`ΧB;RX6d '=# nS !$z^pN/n&u&`t㴔`4$jNMǰ.ё}1y~i$Dr=<Ī'fHD 6fwqs!]_[<]йzؾ?l_os\u??Q[HvIv]CoVekw׷7=/="]i~U:dX\6R!?d`嬺6k`ol'D ?L'G 86kaiI7J%jLCxRiőfS֭* gpkͽRq&_`9ڎꂥYAgrM z ER: 7譅_r2h,nî"*͹jVN6uXlPlѤhj61zyo%U` C5J%{zn`oj?-n󇴖?4wq;b:~ w:P_{^dijťLi9|6bT1o 8=s{pNnzqM{5MfaҼP"T9PO$C+pm FƒÎvzCtg':%Gidlcw53f])gS9 -= 5DJOn$&ۙFz&Z3pE'n#A:?Gх hтIaH<+}ÿ6^e q[lgh͛r)݀7}wG\H!+C֪59!$bKX3O!wJeM !&wV 6@ujq7pdւo[ơKEHDӚ}Ox et3k4y07~ e񯺼tA_ F:lX~Y$`]|=(ޏWqiB ^N <UWbXkTy2zaou{s#2jOwq-@bw,1vve K`N#β,di>ĺZ{+W"eNjӳڍ.;L:_䄧87Ӗ8 S}I\+iHOEi9 qt|z\n>RM (6 YZ