sssd-dbus-debuginfo-2.9.4-4.el8_10 > 6 6_6 3!pQp)Tξ7]mtZ`ft ]mtZ`=`liJ&qu^A~':a(Kّ1x`񌂭3`a('|K#GF/ãiX /PZA8(XlDv!\><g'Dvc&h'ʸa[`DqӢ\l,=7fXH`zՑM1R_C0b|s|Aj*79G_ o[hYBoG bORRVS8 ѣ@eRO*;,'{[jxJe_]VGwVGF_>4^j"?%g՟n"FseӘuծ>-d=^]q/82n%nNP9Ivd1ŻK~s=Y5R5N 3 [l}(}Aژ㭑Vg}MUqݑ '|o?|b%4YtfB d Ikpjup+$ 'P ⫚f`b_l\UX&r5 WN vv3G4GWޜ7 6>p>?  # K049?F dv    H $LhZ(89 d:_.GHIXY \T]t^ bdeflt0uPvpwLxlysssd-dbus-debuginfo2.9.44.el8_10Debug information for package sssd-dbusThis package provides debug information for package sssd-dbus. Debug information is useful when developing applications that use this package or when debugging this package.f ord1-prod-x86build005.svc.aws.rockylinux.org 0KojiRockyGPLv3+infrastructure@rockylinux.orgDevelopment/Debughttps://github.com/SSSD/sssdlinuxi686<P 0AAAAA큤ff f f ffff33134f35fcbfd7ea2d511bf29f828f4eace163c1229d48fa1ef3d0fd790a4b43../../../.build-id/93/94569dcc2df1a23733f4107d0c9e9bf472c143../../../../../usr/lib/debug/usr/libexec/sssd/sssd_ifp-2.9.4-4.el8_10.i386.debugrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.4-4.el8_10.src.rpmdebuginfo(build-id)sssd-dbus-debuginfosssd-dbus-debuginfo(x86-32)    rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sssd-debuginfo(x86-32)3.0.4-14.6.0-14.0-15.2-12.9.4-4.el8_104.14.3fGFf! @e@e{@eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.4-4Alexey Tikhonov - 2.9.4-3Alexey Tikhonov - 2.9.4-2Alexey Tikhonov - 2.9.4-1Alexey Tikhonov - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-33957 - ad: refresh root domain when read directly- Resolves: RHEL-27205 - Race condition during authorization leads to GPO policies functioning inconsistently- Resolves: RHEL-25064 - AD users are unable to log in due to case sensitivity of user because the domain is found as an alias to the email address. [rhel-8] - Resolves: RHEL-25066 - gdm smartcard login fails with sssd-2.9.3 in case of multiple identities [rhel-8] - Resolves: RHEL-25065 - ssh pubkey stored in ldap/AD no longer works to authenticate via sssd [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-1680 - auto_private_groups does not create cache in IPA server SSSD cache - Resolves: RHEL-10092 - logfile rotation for sssd_kcm not working properly, sssd_kcm never receives a 'kill -HUP' - Resolves: RHEL-17495 - New sssd.conf seems not to be backwards compatible (wrt SmartCard auth of local users using 'files provider') - Resolves: RHEL-18431 - Excessive logging to sssd_nss and sssd_be in multi-domain AD forest - Resolves: RHEL-5033 - Incorrect IdM product name in man sssd.conf - Resolves: RHEL-15368 - SSSD GPO lacks group resolution on hosts [rhel-8] - Resolves: RHEL-10721 - very bad performance when requesting service tickets - Resolves: RHEL-19011 - Invalid handling groups from child domain - Resolves: RHEL-19949 - latest sssd breaks logging in via XDMCP for LDAP/Kerberos users [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)9394569dcc2df1a23733f4107d0c9e9bf472c1432.9.4-4.el8_102.9.4-4.el8_10debug.build-id94569dcc2df1a23733f4107d0c9e9bf472c14394569dcc2df1a23733f4107d0c9e9bf472c143.debugusrlibexecsssdsssd_ifp-2.9.4-4.el8_10.i386.debug/usr/lib//usr/lib/debug//usr/lib/debug/.build-id/93//usr/lib/debug/usr//usr/lib/debug/usr/libexec//usr/lib/debug/usr/libexec/sssd/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m32 -march=x86-64 -mtune=generic -mfpmath=sse -mstackrealign -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2i686-redhat-linux-gnudirectoryELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, interpreter \004, for GNU/Linux 3.2.0, BuildID[sha1]=9394569dcc2df1a23733f4107d0c9e9bf472c143, with debug_info, not strippedPsssd-debugsource(x86-32)2.9.4-4.el8_10utf-8a6b22c3956176e38f1b3188ca22df1abab9dffd563d8beb9581809017c6ce754? 7zXZ !#,] b2u jӫ`(y0DiH; <Ep]B{'hp.JX؟\]3s W%cM:3si6Bߣ=5]-WK`

u8ƕ N6(c|A4@.\}F=_`o3#*gx UxсSjC̍PID2u7vؗc?^C)#TGDdŠ,\ c&QGg# vH[qO1aVz^uNCĸi'%Tx-arzJ|Frn-秗.Th'f6U,f`k-&wo]&`=BE;y,ĥn$OwfJj'r%MmAUk,GpzR쀿 Q쩊. 81kX?6sTWpl>K]G e < D{PJ8nzpC >IP̔+r:.D) ='k56`5L]EV`P6N-$xp{>(lzjʲ*WfN@o+B<\ S@ғ0"L\_|gx#M-Ɣs\/A 4\-m47e t:YyQtQ^AftcZa_Q{>\>ڹ1z6aKQ3\ ͂o1ΜeJkvigKK!x@(1&"uX?$,ӏ.H( SyR<ؘ6g#*IyG`$ ֮-bP!ڷnG$r'm")gE2ťCk2v|Lb;B %^dTufm׉uhutFuؖ ̧р։ *NT>PX T$aj+C")NdJE7'ڧws_w |SL =S—h@ Eh`M%&ikYM Y`uMI<[B :|k'wc\վ®RrcN_f-a(7[{ 13\,Trkf@jPb(l_QK4/_4"@_p['ũ!6dnd:Vl TL#?a1KL[7HO;[daoAUՑ"Rtid.CT2Rf؄)cW"ض %qd<@?:4DǴnJ5āDFۢ76vx6H<3v'iE<}^E@h Q'0ak( ڀ(õ)<7)%ɦ!Pқ?VwAaIW\ Aкֲ=bF;NQ(!xf֥nh`+!=R Ξݺ7-b0+P07w^zAVmLe(9q1U`tu=^M5!!jho0F/MSb}-:Ii` .67GOwk|>#3 D6N׫ssQ M~P3V 1|_Nte!6!&l;s^EʙiLkĕ:Y4e`Ǵf` I^T#UzB=_od,~0&rc3bTo\W%r3 z&km {D) 4Rw$(^L}] e=N^3LKHc,)I~}ܴgҳTep;V>d7Br݋p#vf#(kQ(J0G1-d6v-~:kpO+Ro%큒6o^zx"AHf N$;*.*>o-w}n9UbXQpX9+ lŚB @ ZitDzYƪ;XwK5k=Rb\0hvd0|kf}SCf-a E*w.XRҁ.22Cw(di0vRĪu.#_ 1I%?VChsԟW&$stu|8'/h~+<5xa4^H'y9Z]T$( dv(T"~<3=um 4r)=+Ťe*;`"?]3@?"ʉ;Z _a.?һ',,֮9β5=ܖg:Q7x#\'h豩~;rT|ELğpD zKW9scWs?5g_ :"3??:] ,Vl.Ӟ:n@J7lV5}"2"|׷/~Pxy#YkTT.#ma誉(خݜ}P>%#2X}ΥSMEEGBqV_h,Ԭis;j… & F╭9& S0bP|/v<yMl~|phenLTϱ5|q@p;%^BYABg5cU+huc>cD_ ߽)^((8W\ș RzX]Íw]sve_HO8g9!КC1R{A"[l!KR=c3aYC iRc)lK<\u[: du`_:}\;XW}+=n_( GAW—}CDF1kSFu::IȅEv޶2NCu'kO ENIa q J2)TtWk,`rOc3Q Hݶ]JxوSz r؋{lhr1EgM1bĵa襠ԧy*z;(yy*Bծ] oxVO0jt o=Jl'h))ֽ90|nO%|nc wk\:y.xѽeB+{Q̈́2%Kb0"뤲u[!-+8 -!]Q{%Y ٨ F+;8.د{ޮxȮ2w NP@u. Zw6TLJI+7Fӈ.(.mey9ǫu9nJG_%)^Ew]&9 ϰr`&Gxf{N$!!ap'2;{p:Q/&O:l]0Xc "&fPGGwռc[))aPhE0GIoE* _g*v D'3!WkD5ӏ9;/A5E>j774w¥`Z7%h{~+"Y$(THU☢A34zI-]Ghߊྌ2N6P%VIƺ7Bhւ+Jhe蹁 Nd8!8;/h.k,rk,g°-]+;ּޚStf\A1Fe_/ŀ dTC[!Wt|O{'¢<௞"sƫ;1:bvצ;wܣQDCj] sQ8 EZAUs@TZ.Y~1 U!<ϭSMYx=+}0{gXRmYKC.Fݜ4a L ;La}EkA^%n r:#k`ϵ#,Kv#ѾYDMg0sٜ3ͣƣ\f%.RHSM-̓VC_P:5 %^>>;@Cl;%~F)Տ"٬ d&7_(%M4yc'H 36,ѹGf'6ʨzmMʘ, ߇\oDc&wN7l>XMzg;,y1"5g0f*wB>89oi^b*شxg (;5Q Z%~8]nBJZO\(ڽJ SqVڏQTTM"t$Q[0w2K}Ooh^;wưŲ~ υ3B)0K L~D#!O!?+dkymtӒ e˼&ՅaO կv "(째B݉8s^=^9xUPa{6:\(N>iE.b-d3Kfsx{&%VeT;&#I%, ZۏW/m:<;Gk9pdx,H/ricɘP;|f9r2=n 0߬$UF~ȣ ʚ Fߵn,V\&Z㰡г7.7Lsڊ0ƾz_}QJiB&1$#Ƿ&j02ITj ,mf?|g@8 Gf5lx3X-$ߞQ ]-ͤ-CnY;D[t-[UI8'5&ϱ=k))CDCP b'zצD}$>j@Ua)5WEG5ؠLpjBK C2WNjf@=&mٽ &gc{SIa{?ShbkOoxAx%f{Vv?$ Űvl-P'(?]-]!rζr0' 8XRAuM/BZ*KF= ҤF'lY:BycܥichF[uy%JP:֭Vueq >PR4Mg< "f :/lн`l5viQV;=>bNdSb \qMhU/ʡ"-?f`_ Idm:+;F3L[3 * 9K8Ę${DѯOf dT7$RHG 5gfqp"xϾ|lU r',M7|~@ n͔IhF껗TZJZVV{R<Pr#Ťv,~+< + o~OoQ #ϸP[<< ?Gf0!ؑoqLi&gRtPn@S_Ӻ O,Z]JSś$P&v>Fg7O);}F;ta݅+IsFԭ:&͵H 6ё}6ր[ju購Z2ܤ̈́T7EXA#Wq{Ikx=e4'*+Sc1n7snzmG\2o^NEe?%&^CAOj1PnÚG[ˆ#:>`T-ž|Ի%*z@1#QA<8"aW(8ן<;ǩEʥR} ;C? ~:iP_Tp"㼪1 K &OZw!': 8 I^6]NŢtnS dfSü ^2/, 6Wo0y I󉗫E,o|(dDk]C7SO99L:qlQ:VE0Ƹ'<߿\ /{Meh WdW̞}8rCfh! \r-3qhzj>Q-PCZȰkgS-:,A9#=  Pz9A&CQPz+M+Ap[ `}&JL*~Ovԝf,ޗ;Wx>%uuSI 8A Bz)hyo?Vhy3(l!c6fR 9(.o83;Enbc@N ૿Y ^1K^`WO·Ŀ} tL>`%]}ϔlB<}Y8í!+G bۜZٳ$ ּ ނolbZFe?oW{OG޽$HɃ7vGS&CiomhPLe ऐ04[ Ę ـyM7۹1Fڇ3G\XOJ wa|N#ﱠ9Ƭ Ʀ֋(?)J%RۂLQ៝_`6x^70J/YM%PYzz" 5Ƽ(+1~u̺򣰗 D,[U`b%f:^ o Js>GDZ+6ٳ IMd\9(M `±VA{VEPT6Yqؼ3ROu]@,|X-8Gב$A N] 8/^`uQbyNʁ WJ(fR-łulMX%jBZ385NKu tv\{L% ; Pd]SȀq؎i砋>mcyaWJsC a!G\5AG C_EkÂ/jS1xC>)ρ-cuӒ fPw_.WBAe-J)jܱS{Ee2Ʒ K< CK>hCwq9YO$&`*L?nηC A~2wyfH y-Dh՜{حqG ;f$Vz?}7g3o 7h?v+¹V+W\Ϊˁ[U9$e-?mpJ=̆4"8ď&"'Þ7-}]m`}X!~Bۂ8sd!8uVv=<Ȧ~[Q G0.'Ψzҭ4>HS=yh`cV>21I8×lWߞq tfb8&.wS'z)aU5<3v_}7Tݧ\\ٮŃ?<mܐ^s&%IOVt.ATPV]@7pL,WxʘXvvgMJvWh+`t? [B` AAWh5"Dh0R+ӜsRԞ[ jOC/vPb)#״U?abZwEnC> 8K.ߠXsI|B\.q"@;.Q^LA?1HdOuƻ@8Aq JSKW}!(Ẇ@k( uNբXov7hMX 'JT- Q5PZ`gq̰ :'rt~KxAK'/#Q.u;WIientd .mb[asցR,]j6p1f8;НK GCu;h_}-W*۴ż3^nw,͠^t>/so{Ȉud3qƝ|s {2™&L؏h` =vFƩodc{tJ'[..{ 8=#j&(9Kin;p(U.0H?1=f#Wqmݫ2 lJ_f) s/oV<6=vUdDl]>f*1F,=ufD5 y19ŞsX4e x#-oy)#RX& vr\5(7 AORE RUy3OĞh  =Z߭a. ҇` 'w3z@)߇w C+i -3FCǻYҡ~dgZ||l݃83;#{?dBAf!K/]#H {V/`_+gfV(k&xԎ.9*;[_#eM+:{,sk>wכb$a ?ՏUhmOv] 8ܳ3MLc;e63)aжQ,_]ƍUU0(iSGt\4__>~\jNA"aZ -4$ĝ6J!Shd) nb̀ [Zu`LJ84O[PlK(nl V'2sDT6la.CĩJАsjz>>m0ʌgOqGq$d$V!Ũ}#Jboaˀh5B{,~̂Џ34toBmt3-+)KPATv9:Vr~|-Nrh}Xw pRt*|EK?*aOHԻ 397 WAh=K[\m `h] ;s'b,,T|^z7&e]N9? ?*R(C.*PPݾ%lٮR;2/2"HeQ n23+ !ENrZN和l+̪,Gr":˞>+NҳH|Xu ҶaRr=]!fd8- >"Ud~^ \[nit^󝅔@/gٳ8MƜ{T˸.w|"uAM\ p#As%9P,$o@E<%ʃ}ҬK%z$4ж" ӐoOv0n3㥰 dO pP4D?:GB=&̥([p;7Cd G?x˸aTb(,;:na|B{햲*ԣ?'wDBIs}V~63?+ %XLaJcuuEW{BBtc%T-кe( ; ʓ&3!;Y@O4Xw WZLơ_n:$zmcӪm/苑i7muJÂ쌪xWX3[:*3OK&<{Hq->IH5]IH($?%kU0 aZj1&æC=x5ZA )䲗寎1MjԹ=p,7Y]_Je!ۑN増p{<> aI)覧b=c'{+sIRJN.wUM`R(@#MZtE=UA–/B-6} 3 )w2vȜCA)_7"ckBdC \~,˶ >+ӜgDQP km~ی^&fp4x)\2!M( ?E>MD#uj'O!.'=Y]5h;Wtk Z/fC %'>`{l8xjKشB6r#G͛NDĿ,XO@\mشW1v $Ts!UU2¯=O5*8>vy>0f?2ƦY[F1\So%l ,EImKGϐ^2)us%1ɡf n#ҢJP3^st1qg;,0 *w̔n; h􋛐 J^kԧK3D^0$?˗;d7P-@ki=hDd·vF" H^xd9 • CL3cii(c(uJ!_uzBHc5RHLAHg,Oͣ>־|@Y65 ` >Z`&-O`.-9sC0$տ&僷ཎR[gb~T DG5ǸM?*!N;}k^%Fƣ1MM<9ɮgO'[WWv7~}|_ʏ j1wщ]YN|df *Msy r$xpZxPY޾5fU 5Ҟ@ϰ$λ,1Vx X2cwWs86O]߃ϝڱq,|A3-})𜕹- wS)ƆZAM2VN܋y:H[-x3=nJk>3Qt~WZe"[n l>P}Mn3G(I4KGOF,݉}Y"#˜ԣA.#uJYYuKOfM%!ypuD!, ˲!"([\D!47r z6N!ZjygHnM8{X]O 1R1?y3.]&[Ň"s#۞J>Qa7-PWVze[oKʌq](^,AnZZ Ӓ҃^,q3bh R1**N 6_w) SnT'~+$R̔*9QGav5:G`¯;"|\4%% Y˕n>c[ F{Y*c'om2wrs9y<]%>R|=5Ǹt 3 "BK, "-5I"?ZmL?K~[u0xQ\nSΞ-eJ]|;'!e笢)8ͅTXjB5/9^(H_ s = *KwE$}kf"M⦜ O1hO6{y[N{T@i >Jg12.gjK+V0ٷOKtW))'uĬ8 ml'KmN& "ةd5:puf'u 4slS5ŽMM3\oGJ5O"Y|O*Qv.HZMRD(/:3Iz}\S(?-n.ou`um)9eS !p0Ϗ^82SZu*dַ3j@)# {@PMrU΋3<ϩ,Ax)iǁv\4srqn u>.Gұ?QPaUo_A+@RgqXE^Ur / o$}`F^p`k>U}ΐ,=^< Q//3W>T b5'c|P0 *u2|v !{YPeW@F naxb'$BVGLUWlǎ~@ _.uz~`^x:h" dW 1!KɁ(4ߛd=uXސ(ew­.0x8C%(wRFyh*EҴ^N}gs|{<#BU(< }>Sx: }o&@YsZDR{QdfEU^rWӁ |kKfO*22'pr >9|@7bHM9goneA+Rl;l{ǀAي2i!=Ƶ#[cNٸʹ3M6٥m(cJri „!o_BCϑN`isC^TE ,*=}SG:A7ͼ_@8':K@hae`*;ugJ]!wUr4r>kLx+x?e1g$--.eo!R<9 %_UQT/b%Hu"drR=oHhFj׬),[phP*>;P gwP0zSʯX;3҆Z(*1㊓M"׉Bg9$ I>d~#^dCNG3C"$ú9<iY9پl XPlcso)8&|Il6vC_ҕ"e5Q&1BGs*:nkFN:szbܚGtMpp(MYLY"2B)oA ;oDqgxUs^X p}JU敏UT(/{j^]ȇ6AD|+T,t",x$\#ʛ} b9#!DlA߅^怰eFioI| iq]&58aMh(Q7Cw3Zza]_5dyu-G瀄nt>)^կ1V~>ؚ$D)ZOznrT)pջ}H_-y! E,H&B q8D4k[uj& plه.5vM!3T$?kBN W1&WBSc%sGܙEi8Qw)\˔cȹ\^5.ܗ~Ey<*f3JZBB+o#nmDߛ)Nʸ{_gB?ދnz/U#(pB6]eRZ6VX4@lCjjI 'qlCW<7M+uZ'6Z H h ¦K;L[B\mLܠPZf%_f9WshE_P~_04^C(LJɹDR6dЬXo HG*K18Q:qGAXTe=T՚/ v?MP5f|q(ɕ&)ƟhWKE=kB10@,ƒ//s[E+댵jn%Տ,NnƏI1]cҿQPL `KNUm}6c'!"B`Xe vN1;7J# ^dêW3M7؞ &%OheREg[lNDLXϮ+`0zNW y\ ]OBp'].B[ Yp o_s}O"Hv,^IQTlt/ IZ"7hx͚۫"3hDq08/ eVWYSXR/$*$#ns-9.(]> f;Qdb % wX3f'Hpbz\z  m&28E"9xYM˪f>kCO/7C5nI&<"՗kd^/~in 485B.82W=]Ji?k#n@m,4~'|o*#D:0l桟3젦޹5K#9p_q9@[ 1V3slL14{ojN/G2#OOJwŸ(4Lŀ!MR¼dÖyiҀ]G,E:CR̜ j7Iw sb//Q x_Uǁa!b>vɭ3$=xWp#d&EA3W_LdqHkÓHv<D\p<̐~P^Q'k?+GdRނ]n7A L H6.r^tF^8.8(AڹSf ^ь"#wU7 ?@=שkS3O+<2J!fzvP jN8R/ qf-_roóI"#O\H1nΤ̈e+Ԏ=lsJeYXa^GPC 5v4v&j2__fG̪1P[(ԡH1gfeTyv7D[4dIcf]8 2L]<]SX8N!h T!eV7x$4U1z{k\  Y1NoZTHns] s3F+11īY1dP%譛ݡ.K8PR'Bkmzo˩l0@]'?&n31ڱݿ XȔh~f*>g@<˒!M|V`8u|.?wzGv PW̝.ϟHiqoUCڗ\8`J q {b?p [L(o@ךL7&rfQԶL0M̶i~YpWE8bNt#wBOE0ZFF[RCgcdߠ|TNXNJ8-%Y⑯3-rr2>VFDC+Zc>ŷ&I<+}04'P 8ݚ{Y|'8x 9_Vyxs5m%*v@&؂qs&Ye˗rKS]Q?wИ &H9HqeiWHr+{PD T>Ҋxhru3[ "㧒h0q? ʔ75Ni,M/MJ5Տgm//gG<ňz ~Jpx!Aˊ09<8 #pVn'@$ g?~Sj+z*@f{F/5'09,}(2ORktO ۯ ve-/d MTP  P,(2 xPY̎M縚ha8ehhR30FX1c#3 ]5T8bh\yZʿ =G&z-Σtωʙx.i!@ ZP,K &?n0 c6Q ₤+<Dtqʧs@ax8vNFupf]PO:H[B@be)5A~E ɕKt1  <"mKG26ׂ;_NdU_*Q9#ꍌڒ<閄B"O{!]GoE! 8REs!4តۣ2jlpFtƚ#Ps ^,hV>od"k(/>> X0w`z hB@\T 8wͱJ7\!Һ#"||ٓzlS{un"ZHJ.*>o۠*زv [S WhCDQyy߲zN؎e1iϴLw/tf_^4  _K_&7ǒ"QU: :ߑʵL&b ^U-SEehd+W/bMCo:hejM*F$[/Wѷ{e*1o토n<3 $!nҵJڛo7B[tzagZx~;Y;b>w1#]>.("[Ҭh(fSMprELMOBʇ:"ig/ T/v>Vҵm8ZE ܐ*4!ز9S 9~ғ hc߿S½*ip&m*<żVi8Kι4+Ej5jŬJ͚_*DC0__:45#Y6YRz ꔴxm[IKhF .\&SFbT {tIkZ^ʎEgSO/UޟPDM5-}ߒ0YOiweT*7~k+@09.UΥ&"\ΪY dX 9 GY&N1._r#^'bl"MN: @w$[PhHe|Jڐ> xCzkMvGcWYF%NUoͩ]?@0A^>~ZP E:K}?( K,z!-BgB~FCcP5דr|Yԗ "/'Xu/0v@sٱYKL 3-@ΔrǙtٯqΎPnƲՉIY5E+,S'*E}h@ޫECkLM]lcO1}?sƀ{x8w[>Rgc[W Avӵk {!'#1f$ 6;f&0Lq@U?j꛺ dVaBJ>=^Š-4񇦌8 r|'6_jNdRdwVAUr'Ah?J{/(uF3n=s{wK=mNU|@H} g*`gkщP,Ǐ=. )`Iioi,tg~؞\[^G9ujm[}nWLv]$ZC ߇ޫ^` Dv歀X3Y \>\"!" r: ?w-d*i~iwfR&۶+œ%WWR >ezv==㲳ңжӽ2MHܐM'L66:t|Z 1Lrl؉ʓ¯P+O?'$*tBs4S'-%Sq^Ax!F?px:m*GmlpC|ss7U{Q!6^>JBO|ԯB =״,ȿ!^H|,7-Mxq}qؔDw3 @࿼PATS[p[ĀHtrTC@wS3[m–ve~Y^Nr9@=uLLW;GX:V+7gT=n~jŅlDb31KmGerj;ԅ Rk"Q_7~SNfY96q ߃M}e @{85+BdR9H"4=ve")Bd( @:R񁚂ݔ;JO= W ]X"|ј93œ+TȢ͘>$-`Ҿ >C(H:,X1Aw>ي K @טH4%~TndMR2Q@’%N [w /y  u9,AJM) |D fq ݿ߻w5-|Bܶ\iWŲ}[HuKJL MgMY{2ו,27U!r~&ӊ6QPS;ԫqŜm^?Ŕ{i'f4!uɉ`\3QnK ȯ |%#o=)o(D|o_ Mo2x#u#rfM?TBw B]?~nS3/"6gˣJ nE(AWu|M?硢 bIUQ; 8HL w]H299ݎy\4\_#.&^(>w!618\\"qfxT %Ű׾cCKw*ۦ6! du:j]]~٧l-/lhHLj-YRnEvZ5 NJDvg[hmYʢk1VoHw c%MŸiA*r KE;YSYЛ `n8Ղ#Ztţ|%4.s"T8eI #4Zײtv J+/mUAށg3*Yz%# 4h$BzIP`Qƪۙgg>]P,<>0,ڧ2R7v;1QC6kLWՅ"/vfģkN~&WB/AݥKJos[=""3R>&GSUT!DiX4˳#2FO8 u1R`Ӽ}Āa%氺Ehgr`o[20>U z߄>ۙBaZ7[8b[z^=fl?# +p/eU/ǵ&?"`>Cr~o0G,}" ;w"Ӫ{V ۩H(]؆CpR&@^d.=hx=wQʘyi#rǑP^ -Z49w8mV[w}L/ULh{?=77Xy)C~R?K˫{xq_;aU*3vrg5uoDmU2A_IRIˑH9[r>PD?"8q)J,:+bx;v2 E68O-]v,'ܱѦH v`vB$:"-St4Li=-7R⫁f *|,Ψ\Rذe˥S %=F4@}ӪE  2~7u%̋rՁR@%J 6qSzcA`ʼn0ҡ}5{d9+Rk`AB/7 ^_b= RP<2e6O]7# F# ,8B쨇D/DJ'{HL,aW <ާ~ӌSB Q*g 4eti羜 un=+FfPg@s!MJpdF5v=5Pe4& bA M:Ciw:fV)L 0P:2c*x®Y3;+DBXXަQ(P $m g)cbu0cRW1G#qI'Hp?Zt{pW$`dKu{" ݩL(?Ri>/5" eyd302$&^=ipF׽F|sSaw!\zj :%CEMwv0;}[Xv;y"} Kg1/bnp~K0>J:sb\ ɶdA8v YE' 1VysAw ׋tzL)Lڷ(J>rwĔܮo>B+O@1BVJhtX1D)5$9ƦXJѺ   F!Pv_A(N^顊,9H3Н|Ɣ6{x[C]2{Lgf+VMm G+F"`񀑨dÔlP'9$E;PE9yt/vL9~Zy3~<2v8HcS;my QRik/+2xy6GѸ;jiRpƳ<6:=Fi>ߴsdlU'kg"Ձχ#h:=)U{.onʺC1!o"ar3zM<9uL Y&_FW< <,(a̒F{\ٞ&M;8g"&P7͜j:ULCm+`s[+*Ky xrغ s}'Lq)> 1yv7O v*Pm]M/xdAZyL:ճ-Е, <0އ,6 - T̵x+qFRzMZt.'0F:K@qUt)6DbG%P!s~H65:Sj vi=9,)20n9-rCX7#bP ~uNΖ}Ca&Jnp.khG9f/?;bu730~DFYKѹ<0jsjjk6Dmbs5mbⲏ(Ï 0Z.ϢPDq@6c)t&M3&վ#zJ;%툶{͢ՌOY:×r>` NO4qF[TdENARW6G$0R6h Ky1nOT1 U"j?Dt 2v/w:Vۊr'̂‹byޓ'0qJ/-Vh3.T8Wھ-ZQËھzzrkދ#c-`0߅K3 4j[QR Pd2|`MהЧ w!0KJCDg3\]P54mtZa EC'g-"+\ NN!llX~Qo s}(Z^+-Fb9}͓kclW>/9ӹ\J_F7[ܞa߶RKp:KxY^(o~I7`Ϧz&: CsAC5s$Cݗs+VP-VF\4kIX/k};,%U#\I 2 EGGSYbC)>% 3 YOx qLo[k>Xf*JЗg53, +@1&bmcNIVr`Sa=ޟwZC)ۊ5>KGOR^/Z/f}-%'\xsƠTyq/ـųyOD⒊7iP^IZ\^'3ʁTT@ hX2!1$rዋw1 aX$6hn@rh0{AkkMoll)#Ig#6tFMI ]ɒ+{2zz\Kk "E<5! ´(rQ6"t5?[vQۛcF.c׹unنPTϐ =u0Yˀ~~k#ƺVp, -*fI } 49#450~"7F O܀W{Fd0g1%gN"I$X+|:Z$j%|*$+.)t +Ϋ_*u]h#l(vzbϚH1IyRXc[7YzV hx@Řm Tv4iY&]St-P(9B*{TgOS.[::,8)KA4zeݧ,~/%Ƞvu, +5){ǩOo,EKxo&mUQ7k-ng{0(`{V%"ߔQ-?ln5Sj6/GAk7&xBW%֩WK>]PVmsOt;B6C/%![hh/JQJ^'Hm 4pAЭLFI<4`۳e:;f/&(כӔLMPfxLЖ!?#z6D ~C#+]2S)0f0 =_8{?|NW6[C#y}"'Uz{M5(.L;psIjk^ڻ@-tm-1BL n#GCT60&Р#.L"υ\b h,觘&+4*;ɮXWJ=Gz#N;hHGvĈ #V܆چKV&Ľ Qg?:_qU.*<.VrQ i 4fh v[*EoV(q:OtF{y>%{kX2̡$4|h8ar ;[e),_{`Du]R|!d\Ъ"78AT=B观ɹF@^ѪE`^_< !u>Q)`YNBx*B]RޑHךZu^g#4Q6'}]唋 }!%ØXEH DPX(GeG!jB較G2K /oۡ-A,7jPsI\>F[^n77;BTS=y aV;(᷄I~"sbNES=6C(nfO=PAf*1ڰG 6]2e29*J& ,tzFJh7"X]Fw}W~X;D!IwNa^HdkhՎp6v QXy q5{2e#pF3Eu1c.GR &Ɛ# C+ G HahQ<χZ6e ߘEPd{# +fnƖǏr@4GH$BDf4TaWחN.]ƮWiFmXډ3?J?/ *K*!zvh ]GiqU "GW=}oxB r6܍ds Eh"o{,4 Aղ/䣽=&gazsIRF6N({7lUa/$—SB_#ty6d:H4K@ar}*ɼ8.d )UPcHXT  ޝG=.{1m]F㙨vpVYxkh|+e_Aӏ ȟ>È!h)}F,MXhls\tiwmՐ@ަ+ˆ. T:MꗒRBuP6kP*,1G/>gzLO7ΑWm W9OE,_Ab;k#/gY{;bޖѤ(f%:Q@&kОt~swlYxT+1*4216*d܌cjm}fL䟂맗('4m" Mv&#jib9"Ֆ| 8r-Q=YKoQ|asB~lk)I2MJi)_Ȓ4pz3q/pXnBrsSywga $5 0n}a3yḿ`"todO<1R{C23Gi (A^p&!eEt,nѩŢVӄS=#ԙȖj1V TuٓD!r=yKuB&e^%c1OAj¬g*_e.yV+l v{O8k?OQ@E+q\9bj2N} w{x?nL͙F_?]O,MI_>aB- [n(:$beYg`!(U%쩁59~g*kC|-8!)d=GU]:" \ydq75OUsXI}$seNSllX&M(+6Ճ6WyL?KUI0 >yޅN+ sֿtBH~}$07djYAeWE~rubFEub<+ F4`թRx/Iz"5e$5Vy,q&إ^X㘯<1Dƾ&&u?MnhQҤ*\R `t {gg(Ӫ$rIdYՌw5CZcj!X@X jF&Ëc"[i1UUؽXڲrOE%BZijIKהxq _3! dMIW-TSW&} w ۸ˡPe:fLej |NI}<{>>0~bYݲ>o(!4gWߡ_R[(&qwNuc6Q I0k)h_lPBAqx߷0#:% yeJ Hi6oW~u>(ͦ-bʴ6bY)75qkl5QApŞētV0O&Ώ*{R+.|sr*닳6QCR* Mk$:Ɩ@ϙ6~e]&&9k gZ 70qPi1'?I$F_ pPx'mz)[ļ\?LB:zL(װk$SF|}ʲ!>MαTFKIAw{{ӉNsR.3I7wH0VI̿ j]A%_čЙTw$ *$)^h'g3~;P Vt5Ơ#| ITTn~Nw-#knp$]nvU%M1ܳI\_~X:҅dmXiY~")1gTLq6AFQ[ :PćO!ɢy} J$I܃H·gRv77>v;T~])O3|X$J!e-moviMˁّjJjU%xhmpJyhHNHIU D &qנfT4\ѣnKԛ3OT&=`^5uPQQ/RJwh'ϡ٬^i i/j4-ؒӸ3)XzTftm[B[=_t;ucK!p$G^Гr ^6b&>yW6?il'3"L\HDM2q *x@Mx7Z+T(`aUV䚞EFE }t:V?dl !40^Rb%*lXvw%ɔ[C.t=0On?m 2hNl'Z#i;wWڤᦴ$d2%[TeIchoDP {ˡ'A]0Ds.D]+B1!t#ұȶzoq\G!mW`} o-㒆 e~>hUiJ$ɓ?)בu)) s[ 5#;)Lt".{YU ~H$D$C<q& x^荷۬vqS2nٔCו>2BJw.JZXlȨhR, 2m Ew8r FE Fk?rpJz{?R^¡|$IOՊKR ʺuQl]N\Wcy3[l+0Ͻf,LGoUP"XAҚp hg ¿yY/nL>"C!`a]H\Zhf,vMSUi(ݺ ;''[ nP̯#(G")[aZ`VݪZI!y/Sj)6x!Q\X[Ɖǣ&M.,CaO<#F6^,耼3ڒƠ痛RV,|Ioo~h!H $X~S NQ-M>FqW=kSf|P\iC!Yfn15ҖNw&ny|n= ͍+/+*PAs}m9C}qCMR6HO 4kZ\nvVxB:1SL@ۯIU"BM3ogP _<'6_ЕnLy- l} GtIXf@/,JVWY! ˤ2c윻7&Wm,԰d`&6W;0KJ$VDgZE/< 7uoPj*ћo#&"mnyN LƆ3Z,؋2))v%\]3sS(21 #'i0 ܢ_~vV> /re/W滖9R_>~1*h#<\BJVbBMje :*DZ_ .O3UYsC Ds2kB^?ȞaeI&o %ѷeL %B ` Q%$cDJ1'דb[:H-]3 >G3 nMl_5@%K"Udl5!i0Ս;:Տ?#p{$~}.3V"j쑥 m5SEsUdyp3ýcRV̡~5&'Y/EQ`O4?w$Ԭjr DXILo U54|b|܋LuMi/coGC-In?!6 $'V&峨~ca`" =Ƚ٩&G5 tEqL1$2ϲr#L:qծF[!snb;v򼵎QkhO `޺ n#,XJTpla.AaB3f{0ZY45\sKjq-6Zlʨ9Y?1FٙC664[_zkһ[,(A;p":2Q;aeܙ|~MjM~c,"U)sk }o[G#3_Bxpgm/ ڢGGU頤N?w{iBG$F\|ˈ"N!k6(eRiur#I(ڟvL@hcgV>Hb#<\0Dws Jɹ}W(mu=xq7N94*lonZ#5Y-V4BSM4Y^ň4܉K!&c7) oجO݈ǯH(2擄E%Qca!+q]z.#<Jy)o lšY GD:U+:6 A 5{yoMV`7Y]qfgi[LvM" _N9. &SmlAFL?\+njFh%1p)T?DDaF{yt,8`[QLڔQ_gACY& /d&G_pNN@r8Y%C7N2]m{dd#~VWre>5Uqr E8Zjk hZ'q'Z2@a[@yD=ֈ1E!g>NQ̰} 0},(3wv!dgn@ƷIT6 |Y jOt8NA+ʽ8%nIUqr{lቬeM<[XZK3kksrL%{K.$:sm6dݕλ7Bzʦ# ?i׃ӂLkoA:1U|6+]~e,xO/YjVɤ$fDW+Ya^^Z|ҳb-֫*f|(/<&_lt]kkv|%2EZ6'g9"H \Q/}&t{*.k\,_^m;t]Ij⽐>A|;*3c/sXyZqUPJ!]{{"أa4I0#"imŰBl-+w0h$1_lN7ͯW1'38wS_`զ bt?ͣLH;:p y& <542aZ)(5~@TTh@(aHIxb՜+E]! Xw! '=\8 Rp57^'LDٕ/ŀ`K_B 'y_^EjHXzy>/ucC)al׈о)x"x@OP g.-rv ҉- >jQ /\b\80pCH\D0̛ _9$ \-@ʢw폏LS7<(e, B9~π3A Ȁ'([qgCbn2İ&Ty~ZGu'q6,'x=գ ϡj\d!?"M+L+[`#iHDHXX cɞot%ô$p٬FK r՞%+ljy\MȂ4kHf&E^N",Fc'鵐 ^bK/P]JvRnjk[r1KxwP9*Ng.j: }ffh`Jz7ε揤}cES\Q5+dm:DJ..~(&/?QA': $TҦB$o[k' 01瓌qn_qwЦ  /+f,ma1>ITS28KAZ㿔ga0E"pQ2"yaH#~N:}rZaIwIJo8Yγs4C.eiB&<)O;<8mt偞!t{ʼnG@ذX\M2e#,&Sg'M3hhXL/u;u4()GYu|^. 3]z FucYz''儐ݩ6.׋%.iETeBδos/$KEB4 ubkmۅb du_;p ׊,=R6tSCmQţN3@Dr<.Z'{JDF4WfŬ*v' z S+<+h@ծ0WQ5]t@0bJcU'IQ\K&M6sj\C&&Lr)Yeu|uMUN/+Mb21Ɣn*}`{nz-mbI9{Lǯbatǚ}nc M i ?>1pUM_T8:~5&8D-tMBu}TqԻ]0)>o% G9Γ,/Č8?+76'<ok1f7`ib|5\}"KGHC 9?A!0yBT ['z"&ֶM X*l,M[Y؎Vs úD"5n2,% U m%#06q' f Ž#H_C&c٫=%&pA.Cព&(DX7`.8j ]7`PSWwr}?C,JB1Tyíӷ"}Zǘ)$O\g,>剔օR[}zf%IR<| *>6GY*3@9t{LN_ l9/%Lh=Z:'ܠ5zZ<ԈҒEDxϓ)ǪhL Yz:=GE"#$H %kݞ4pk&F7"6r>X͚"~>t]u{8t|c復sFVmv.ؓ $40Y=3[J[EhD U  /xkE4/7hpY< R (gz=Dzi~):׵7 ɲ"& ǧ!^`g@7+=xW@1, (Lڠ0:а `=KJ\)z)+z N1IBP'UCj9_DԊy,L &VQdS,k(&{h9<%IgU8 `eY um%"SH17B$ZPwuc8Ld\hFE6G],Ew!n&Fѝ04ӊr)rc|uKwJk,{iEneFW 1 ' 2K @0J=K_2> H߳&x+`vc'wr|vFeқ? 2C;F DJ4dF \+1Gd'vmVƻglՏX 2ѣ :v V9(zx8: 1<'y s5&*SgzW gᗪ;#)7ڞOޮYi [qZi$=ͳWЃ`BuvzyRcvڂ14 Eb/3z#&c +\K >Di z%*+h _˳/n2wyMmGcvD[3j3~ Oh$LRFj(e˾ @>0MdUf2+[dBzi ^F%|._砍Ld:H SROp7w.Wq`2OӔh8xdϭaar̅,}8L>F¡ye6bZǠ67r*(.dD`K,[)߉N>#T8Jztg~ʇhZIR9 $f.GseQp^ʽúE]\]&0 )x]08$jqs} ud k6p?? ѹlፑQ33G=E091}Jr(>k~3vab()Qr(j&VwVxoGVT, mQց负I{M.#Y1 zR\Y`0eJ4m:B(Jq6ҙP26_9SI`֖':=O3R>l/MU`Q|ff%G$4=A 7zAyv)LKXγ$ݿhN$kC؁stG -˯FZrEg"B}lS{-+)XUJrj;,*E=q7gC68Z ݬINUU2ٷ:e ^}Q3Zڲ|0V)sYpQQp_w?=VlLqr̞ZšiS+RIY'Ǝ[>n QxpCd~>sTOT݉sLf_f =[]R? sȉJ˝+b*gN>{7 Hȟoxy] dH\4ͪ/gڸJy'r*p zCjOv>x5(nkVUv.0#jq;!#L+r++ӂ3AnFBw苀{ejRkZx}GhHsYUZmWͯU.zD]rPq6v2ZzRjdZ4.u+^? . 7Mgލ]RysUUݹBjj6K\olC )eRZ4l[G ,\axLi3ɔ+LV]+ sJPQ+Jխ_,@b_0.ٿWgUF6؅s p9xoVl!*v9HLv;x]z) UPjc|]o./l!0$Ğ`d.6ڂXQX]+hNV\} UL1#cDvlDž"a iJ2Wč`:s@~ObLv9nVM t^u}E}ΧHKȥB_^Ѿ_ěGN"nǞ-nج㿔fc b+Z 1!I0ۈ#Znh ^@tD"qyg3$&NY1;%WrJX8Ɏ_nKB mbAh(מ,QV/Lq|#)>74|j_wb$j(VL=Fbݽr:VÁtufHo鑅HvA@kŀu*̅]V yC"\".m-1bEPK/y9s xm6vyUl~d9Y)>_Ne=#SZeaLSt cO,WgtJER ڱ g R7m[.[+z wJLXty' OV+]qz@-sES+HedhJ31^Y=TXdec~W];[BoVHॷw YZT2p5 QeQ=f8R߅CL4a 8EmnD 9IH)qӔr+dڂM=o{Z;#kƫ`tؔw`c Kۺdإx +b2pU[/4ENꝊӒM7!FSܡv,T:ҦZJ0ߔ|J/Rد!q>y͈3*|].P2pm1s3ׂ: 7|oX3p&`827%j!!>ކ^zZu,—({{nQgz,Y{F'{E=sw-K+iOO܁򎸞Y$rO+uQrױJj7EKD)w.kƥ VhrBQjd vwMs\j!(%E!m2Yˁ¡qIwiþH&jd1bǧO-w1tmq:J*<}r8pqkNbX=jW`E.1HHi.Ee35nHuz2Y溌ȼJwXѝݭ`gy$! hR7!} jzB: cQf>Gtp7rk3<(|!TzPf{ETfSr'8|S|\V3!iLb,o\}*:1Fӆ`yd~8neg@vVOg: 2h8V\%Dظ:GʍJ!l#x*L`X"'+~(W>]óYgPs)9UX #E`&E2s!V13ڤ S).O`⎛Mm͖޲4htz%\J+¥E$/{*Xl3ȾmzOsu41BȮ`2mi4q*Ŗ?|14𙱝:(I-T^Q`ZVkmz%zOFw(3`@FaEAM2\y!̈>\Xy?:+UWG`bK)#E}T>_DFxw*p羵/ OSD瑴W̛%f<;j]fZpyS.,D`hߤ}'Ǒxk*V%H}|duURj-ȏxBp O c P".a `{A.(u'`=a֑0\rͰb#@<:z.Czq2j{]ƀ)7hC̸ҡhvo'r>C0}MI8~ h2z 6O,5BCב7kʐ\ECyK>z#({އv٥ٰ6 _]KU`ej7k\[ S]Sy>'Xi]:p _ǥV!$k1''!~)T*i#r!Х:H֦Qyly3L`_99("NLf)UAٻ<ͥ7VGǾf+՛g]{{"C~xѹFyɚ>x`F LLx)tZ)c;:3}[e/m] \(/Xf w1CԵ lX/ Z\Q1ų*01ͦzV${i J5)d37g$iot ?/r =~ 9pcH>P~;_!YhnI{ZNip]NO~C^12syC5W,5QvA>iFrO6lĨOTs$|%{5j\бKwni~1RQޠDg4=(%l3ȕ*0yJ(T"F,]V^3N"\҄[0e(MV^b=q#ˬ Yf$xQrod/Dq] lt$epvP0x!nP0՜[ R|||lqєb4S߄FFP EnN?'4ɕ"7p7MC>9oK ZtH( tF+/QʄM (z#DUM.h=5M5d4F%w,$eAu ˹Wp@+?x;n}[ lgI[S'~(klAÃV2hj'(+؊t.mGQ{4ͅ# Y$<^WF"mhN>KH.p0ܵCMvyGhNx]uմ#J")ob uqn6R0{m| 8|xRLw"fs7+iN<+0- c^Ãq)q҉.e[S.1,2+,~_%Ư\\ QbM AkZT N_E({Q)6FQ.od{L'+9*DbR1zԫŜ{HϬiՋ1^L,jVҠ_(oiY c`iPנH@!pm[P#V܍g@]H:#,j(ɧ\I;O`zS?uθqfʖٶYΙ"ƹdT&< b4oa{v?#5p OQs@] X|3ܜEnb;MF}M&K+t+ Rk.W={z?SѰ3M C\н1\AX< C7^m7A#[%{q 8E?R/ %2*QCA6oQJmIizaOwzw?(xW -R˽[cuwYa)rH&hd2(iD!}y柞"$c$jhQkR}Ta$^j?;i|mXgWL6˽0(irh\.e X U\Ṳ̈̀`!r9Sd_9B _ ;$lsۀd淃a@"k ǐ3ӳA:H[C'_F>6h ) $3]aR۠ 1KD1ujZy3w:3#:bJ!?4OoK ׋ΝA+nxI`}[p P vVbIl{V>txR{sfEu;bFj;JJaͧƁF>[z&ǯ[>ƀY,(|lN|Pq)jiRS$"( \U9Ex!TB@KV`@ʷo4Ę|I*l-?=LL5; ~XCCk&0.XlI+$̍sRJO \)c3Lz4"A'A|+-wXQs.-7O⽼~466eBY0ו3Oz!s0:rj  Hg4{$i["t5Y3AcޤlyQAch [m_wB%A~i.`M磣凴EfL91ït˅hbI* Eg5}0r^3w5)cCYؿ]3K@*\cE'Dܮ-33b4e>?'7lDK: pZ2/)2j}DžǓyeBWM: ͇]<(THI#}55n|d.Ȅ0g8D"ȏE(O-~', XfW|~>-X2}d3 c0RǜƎR.,x`eJzK4bG86 t34BE2LD`еbM^QgksYA<)'6o@j Vu؁9$R}[nolX['O)t9/y ťr.u4yknWKz@FO"'Qq% 8X9UPUc%{$Ԅ5XoU }W`*M@A7TnS_"+7qxP Wf҄ 51I(Y$+uen՘.xTT/|"#lg& 3M"w#֊԰@)~8{}ɨǴ_?;ooŴF }"~)tGW/A?՘7~yaHҡT")% 3'wa-ڴdOᖔ}_:,NI湫mI}QX>CbX&9ycF\^>^Em׬$@e#Q*$a8Dy@NCWĈCY>wEBu"Ǔ0Rzb5PG%:*#L$LWV5g0ۺ꼚olN?TW@)hw݄āN֚>3`OKG.QP]~:N> 23d`fA#R H'dU#5 VXvH0@0DPҵ.H/S|Hk}H5\<&Ї#LDtxMcX%Y[V*UI. 5FQ15U#g´VMקLqoNhc8gpY8+2ހ:]D1N,>NU[tء)-atXýs2qf,]oՊ (H };LM9M^@yLԜCU" G{4Cu\㕘Hv veqVzt&@!gIX W xg^(`9e5$`;}!𥥬k;Q /_>6|/z;E`Ԙ =S[1{МJܓp^f~HIU)|,B[')g>li?U' 9_ 8.Gb ~|ZmYm"gb䏰dzZY`\pYz;R8kq)HiThG%ؗzdŷ p8#HwHK WUQiMiރR&\)flW>! t'wv )KBd= ׊cԢgAn|p2Aql #/΂_1^D[ߧK YW$K}Hc!TP[e u`K-{}qdk~w r_IHenjۜ~_F~ ҝt.`JHK뭆!hIN{d'nWՌYjG3p jd}UM84-G8mݩ OWxU,Ѧ0amdU}zNM`Sa€,1 & @eeQ: ĒxA(Qϸvl֣mf|Peg+0Q(K*u?pp5\̨#Qf0d! I>ۅbpF&H1ye5-Qa&2p5o.YT ҤY[dE}Rt-wb'kXÅǙM ShD+úx%\Q{*Pl=7 Y^9 өY¤ЎTpx|h1s|z5%(k4ҧuB[l !M5?Y+re _]E;/a8_NPm*P ھAeA8saQYu%`.HrV(qq= N 2'0;zDdRC_ 2L`/tt( S]Uق^_8o'rʁ6Qí68enSެGz@a\ʒq D%rj`b-b6mJhxpJ 2Ź[;O=jHV;|T.:H-}Bq ctba>'XmnBK1a"UVhTj_8G&߲]N~5JlnHDYzq8О˟F$܁gۖE?\XAK 4Bs9[磊^8J*"qFLx>x2훓q$M1 e3aHe^> v_]L7=d)[-͕Ai+bՠ-OkqAHӥ}NMOѨ9]5Ȋ o讌yW~Qٹg_QA7.+Orkd"f2{M7dp% F{]%K)9<sR@ `$"IPX5D^ᲥۆۉFC2r팬`(o{B#aVɯtfqx9| ȭp8+e$J1S|4tf_35 B`U?*M߼T1exegpy72ڂ5X&-]<KY) Aa`v`JIflBjO0L7}ԅL 6Kh^Ar*HBo@f='i-K Zˮh'P9|MU $ F`KL}c |4* lMG@hoUXjP3lAۇ,cnJkܲU5&ęv5HVcym7a/;|#Y OѲ%6)6*)϶16f5a_Qܧ(FR:PБC'Y Ҿ,()FHl/u-=^,-TRmb-/[_Py Uj1P!jd/qx'q_nӭAaks؁ v‡UNAщ 1li,Ns%9|cqMqL83 4iĠ4\Bt}kMQF 7`>[gnhG\-PL24*xnZQ,S 4 OcAԱՂH]g;^^#%hDJHє i"`+ '\l(-R5DQy1PN\ LëVRXXnޘ%gT)R-Kn>戍IQ,T :A}TU$c߇M =#8}G- ߗ; jd]\0A)K:NG>j U~}s f#RT ܐydMDZqS'%=WnXyU4,WKe1Q[i㰻2xZ;9eUdzt~%yw*4gI efS>,a%;) >pUзm:=%wd9Pz吲5+{Zo,!RP5I7'.b-́ ~Zn7Y@g[1D!iN0g?Bk ʋv޷"3L /Jk疯4s?.0Hq,`&ls*I3Nz07}",M3^^z||X9v %bPc)?t{4k0g^zB s{&0%*΂!טRa<]7bu,R50ԍ˔5 `-8?QƇj{`gjQtɐ/伈ovn0`;&<w Lݿ,zr\i-TL-e6.cAZӾMLٯ%M = u[,7 W_nY="JRHL x2[wrﲜm;wŌr (Io%dw˫'>~~ae=E9IS-ÅԽy qeB˹Fc=݁B*+ɮ])|y/˫5f"Nԟb.WYscHo^Eߠ oւoT}hPcw^,zz(xԩt?5=9{7-K<. 1Ǜ9ܮM5S5﹆ 5A\O/#1eu[vH&/xf!&BgN)< }/ˊb_G*'CaE"Ov t/[ԺslN[sljBc+3U<i:_-J X.ׅ/CSHSp;h?:N=ۨrlN& Vń<'S:J& c6Ie* {`\uDh" caAhλ@f 9Dx~ 6@yp-̌V=w *-| ޟ\k] xXK4 ;T45ŦCL J<>TTMٲC=94`G(Į)}g,~iD1TArYNCh1X - 0L4[~9?[ }b#EȚ(4ŵ!\Z[MUծI.~M2ul3Ct*6C%o~H+y4[vq˺lXQKr1,PCRSw)?XGНЉxER4O \Upw$StSfjGdڒ3aX^9>Q "24dUS&'r1ll6Iq!5P=ozx d]IXDG2ˤy$+}3y2.9 )8|%P;$N 4+SC= ME_1pڴ!hp4< 'Znu ;Yّ!^(sRY0py,gZ|-̓CMz/}4r!5蝄b`&5 騚xl*W0sXrR:A52癃gݐa#ࢮ.9̵bI`jqk-,p(ϼ=w7SϪY/^MKKDg\J3h! wtE=u@TbYOi4Y*lMK &T4h[IT#jb _(i%auNy認!Dql߰A$8!Ia&o/16FM |材H\R3`%ϔgxQi8j0&ΥQ' ղ_3A|.%EiS8--aûiTf~3n{RF$!`TWۉP} ZQ+ēLh$n&I6eE!;6`9rt.i;59|^ce3"Odx5`[lEHH$DSZ'˩K1 d%J9Y:Z 'l]> >l+B>9^ro dp6IW`ڛ6!uuOb9LStQPWlsQ Z;r?^ ^C|ސ^]DE?\0fwڤ`u-6^-݉BC <ݍHI>oIGH9elF=:,pv/EKp]dYdZ+$uH)}-AV)wu dJ71.Wv_HEzҾe.~z; 2>]ezbH?>1shU«{a$v}ڒ/:X7ɠ1EmrМUң=P`!Qq<>K,뢹i #~0"79l|@z% 4VBl{zοkeĊFi!ǙvIXG3FZɄi$qp0GaAdꄢ8NÜr)7Ѡ4h|q7 ? P!Hw-GVVHo嘐Ec0&s9nZJ8mbJm]!r"4 c?{ï֢Љ}!] H+NҬ--NByQw<]ΰ`{=S7f? {ɂ8|ٲm8gݟzn,˰< .y8$qW-J;&tIa= aU0oê`U3b,\;LpH.Zn XGq+OK\Wh{ؖrp%_\?җ2H|z| '[Ȃ/]$y94QlBq_c,/!}ڈE)xG;Q5Y$qؾѧ@_Nw"rCh i D>xwy|}3Tz4ňi0t^bw%}WvUAn>[ql?3L 9OqƦ[e[6L5rvƮBD*xwUQ8}CCcG#K0_Nqa6@cJdEplv`3'?:732z`451UpgGS|5oet3QDQh7{1]פ[8$=ogouwkЃ\[VeF ,GPSTԷCr4r. бuz5eh9ґ9 [TfJ„J4(z5>P 1&2nAM#/FgH+,6¬XǍ~GNSsE$-+Wfr^u"s:6zFhOBͨ1ܸt90J7rIah߲.lZRqwq5[?^1=y9P*8ߎM.=i ei`6Mcba؋O߸kKT咛>:e(~kK%h%5V'FV)X2 hxJ6:ȣ8,3k%ή"&iͩ`i(7jTp3e,{!ڛAiFC"vTApP=m\My@ePtQ/_BNgB,O"n`Z_zfMT9$@~pBL҈k}Pm&`j{z>k5§,ꇙJP.CfiF=YL>B1.= aEo-ɬ`kˮl18(+ p9L&}ɦw6ЄCXJEeRyv9}Ҟ?>vpk5XF(@9YF{oWXy U|QUQ,e␴y j38&LIHx=Ǎ02A0>*HNoXb[}F;HHե.Q|S d=o:`usYͳ>:*6 7_Nk'2bWI9Pl?9,W4wm̿ 83jnȈ)nZuԵXFOэ)s %Mg ֺ{'oq=j$}kDWc, ;n0eTˠA\JʵPy4r  YK֊yưP* ڶ3#iǦB+{p~OVY;\9cKMX\"ޘ4g3 [ooZ[ȷ { x"hT]DYK@cSD]z,%S(n7j-qeBp?*p>+4Fw)51W%6BRqJrp=0OmGF/ |6EXp^cdgܬspw"y+eV<5'6;=wH buo,cŜC [:2YlK ֕-/)q` /2с{ cV&qhBclL̒JB:SτßüK1saG%HݷFvS4KI`ϢEj38}c==aqBkX38jڕ9UMœ]PYm֡bYy7RmJ9$cNYRd. 9 ՘Z_ JJW@[ Qut;HT(}jori0ߕOAVͧ')fM݅l3jQOun#&hSա_p n[# E1hhvopJ|׈UAO(%B$vCUT l#izv8#2̖/4PL=ܰ) u_5toĬ哯ply%*X劫":P>&,e_t3\dt(LH\}^]hP:໔̍sz :7<4yx$߭?KgZNj3Gj3KO[L1hzml7An߇=vML/Nפ_8Z. տY/* -g_C&t \9~[vV";)[ϵ!)*A)a.Ȇ k4:a? CssA3Q'M*oyDd>K=f{y J{O9Y#<46R>ݱDo99 e}B#}4~Q+ڜޖTf '?lsjRWQ~Q71K:uף:X2d9]yv$9׽e_9g]EٺvOMĘٱ9;-+wr&)i1emj&7-q[YYf0I`]޶!W蝓ڡ>[dkƂZmSQW(@߲Viy/ȏ?&sǟj 0&"BB/pI|ޓhđ6х۞B2:ak%-N&;[ Sfin}@=ƴ)r`̿{rq;Sƒ\YB3K@=c0&Ê4+`)!:njg9~BEKތ?,'X2_u聆㖁e5_gq ocqbb4V~YcͥgtOSǪEp섡]3|nhJ6 Ƽڳ\[>Î1:Ј~LݗӐ'1*HT^ƕ6s A6;%3! kNrO >8J|jci3]AW XIul=DNZF9PgN`DOHbp1Μvu]N{ (cRF˔ʄK4 ;=R1*;mX<%扝(}!kmecJ 5^s9\ׂ ^ޟی4#/Џ2&sᒢWF8Q# =m1?R=N:97!=-mN5bn <NRֹ@ V?=8Ŝ/НhҹAѐZx'!kJ<6MM$Fnn#ǪJEi)}69bsqJ>c "|{2D9}ŴqbxA84+O(GVLm_t1ʷr0J"pBA.!1cu,d"lXxIHzݸ!z+no=U7nzs ~)9Zԡ =6|y?iͥ1\5%k<peuqT(vHSD"!iCexo+Ų syoKED$o5#҆|VSB;oI(npP1CW. O7~U͜ H~ $3 6'Hoήj,gz o4eekxA,%39ŜKfFXbB`Nѻ,wzpp/5xK,zdpÕ[(\|J` vwVʭ,{2yyh8Lp̼¬-}\(ЩuA}:K|u +1_OJ'ܓη5^4d??l;c yE+(E8_W,d+ɎS嚝4eqŃP)]LE+1_{ kNkΆj6@θĪ!Yc"XTgsAҡg#oŧi ·wN*s­388!z֏ ̫S=Xe;gphh紹"#(/35JeQz-EP[0=mj0Dkx-UAz0Xat?Ox^\iZS[!cz%.UϦ 2tuǙ*ǼW}c'fk,kw(u"f (PH|`bqKG% 9f3 Tw[IS7aAC0txwū}^2A(c=?mlZs>O(7D'R1_&৐27V8+~|yVFvֿYҶ{-].BHΗU<K]I6Qe pOSaAPeq* K0 !e ^.1 OwIzAƭM=!/ZTPI2DU)i\_~6YgJe!5)&I9;fLdД,-(' ,]<(J6)j  K:P9ݛCi!1,LEyݢOp.H|sl  w@)qW8HnZއTr143Q׾Ay%͑cM$W@]#;R`u<:/'LBzi_NPge :庼@k֕- c)e/YuRɿشPtĢg{_옌ghc`_Vqsk2֌ؾgJW-횾jQ3_,YkAd]Dps;.ݧ(dVb a33tҺaU[ d\vޯPisjxf5EƝ _vd GF!so]dYXOѓ<G8P/Ahl+-%֍?BnT!w.aH3|K|(h(YN:>$@^u[RXƴUd7%bg yCH[3sB,PAHX(drv\yD G&/:]=&5&-[`J?sT`rnϊַx=vG}#( 7rQ3`ʵsqnm:0kNdl޴,qk۹AN΢?#NGGbEKZ7g[ Mԑ8T{ݔ~1,:j}+rG~A%e 8HI)QcauʠӎU/ ϓ rMvDd-ۘEYf@)+xR|k݆ 3)lsSqR n\,7HAh ι䝿W9O2eOH焗d-ՁBnDGp adնFhKl_FP>5gICcͳa E)ٲfm{_0ą!:Y{A4mWmMڦDR(I}H11JZŤvBBLIPsNJ1OXo\  dT3vZc;CY<^HC܈dzqሷs.p_6yn_IԎVxxR D-Dܰ-ݣR]#F-eSj2y< D[׭Kq6U_Zn ŮCƇ҄O?Jƪf(jl:EGR/pT ڨy@F(~*fXO q߻9pW $6Ua`fCW~[H>9kfhL^6IK}ƙm/L52•SZ!#~m'-$ϲ/d-S襁 m3*XLȥT;,jFrE]7sS.mTNcԋ$8 :fZ hw&G?)sU\ܡy'1o~z%|wjTEvp~{86I>.~la9 dA8q'H6bZ}7# tKe"76Z|AHjnz~cɶu%x2i dfgIo}7jO3d>dwÄ`[Tbto1m;:$ډwvA*I`MJ Eq1:a}-7'4ceZ5luʯbqB>z]CA@*I038\*ewV1w(RRwb N mTd8@`Mrs96 *쬘 E+a/ͷ$h 1 IN^7fZJE8ftl;0 :dGV =6)f|s+r*L{6#2|uxYsIAUܚ.4>cƌ,:S@'#ɥO}1 o&K9oIxΗg-|lVqxrz hEhCMRfr;.'~>YOS]I}PQ7-Au-xgLN? +7-`'΂.vǁ]XejJQf-h3+sje/h/:Rhrʦ#+ H;4 w $}uk;cWF~|Z"" rJ:'m͜z{ (*OVeL%{JoeR{ AȈ;1#mY0C 7GHEGw~FەR#TCXHuAb˛_30Ņ9Cx ,3d`Ih]'ؔ?֪[ bt՜~@ٸ>'Jӯ}NLe M{EHS.a $lVQ^ǣ&aˢEQBXАӴh2X섉9`# HД]m¸RĊjԣwS.nZpۙ=5d7Z/ggSA[P 6|.?־Wr 1Xg+-JYlBj8K#O 63PW ZBveZb wЍ=8::X.ϭJk\9AL8F>$ '(~;69:E }Ҵ\8ݸpY+^SrU?+NH)YèUE;o :gd#h >K?f/PHK|tEFx q随Mi ?i$GGł,ٌDG6[-nc'>.3OrD A^S')s-=ȥez4R`Uz7FYt@"tAxE%pr< 2gtr29cCS B0t;92u!6doc8Nږ ȩ8 c:ʬ.Qz+, *.>$PN;g52RW,u낼BgЀ2&..ӓ{n> Aw#h^3,^&wwfI +G͏*Gb- ^8KCyt3U=ͻ3A!zXthIΕ8]$ 0%-2c|_jX=|:NUx=ܟ l]|1 p ԲbF;)%㓕g$\=dW9YMI,Ӭ[W@\)aZXϟE61|<%U }4ap{mae1/1 .qC}}\L׫a3{4CN+ DA;bVƱ kt AEa.2g[(ʼ\ )KVBpG77ur:-4v3d\t,+=1 |j>]C y# PH,cJv7M@P(y )`% ٽ#eB9Qu#t@W:G*i53$7e2׵4'J LHS0[qz ؞]r={ #,7 yxY 2c۝{XcUql,{y5 swʟfvMggt e_~?-NHϡ,~S  >C)wy4}1_d՜>{$Q'sBaR9h- 2b`j'H::c2MQ0"H0MEe;#߶eS+ ":{20Hvѥ95B!7I>XȢeG{p#Sف^MU+" LQnh#R׾IWE̽ 0iC`1=l B:ŻpDJa:AaХD{S84펮tߎAZX=kag,.*1v+NRa7'!xo-e3qu?s$/?5gUb>EaH,L [vLw\h%MypBUbo"GǠ`+ Qu܏'ӢLfS>OfMōa'xvp/:ne_8 ;ϼ}g F+ֿ@ j˫e%ULKuyHd>:1 X3C?6&-*w^suX֏MZ=q2-gT@5~3m[n*÷Go _ 1l P)igHb:Mqy@Ya 3!"6@0LtIB) PcDe/DfM<֯&_nuRo ց](SSB\ބ%ӽ&(N|[t_5fEY"Ag)̵9Дͅ6|r*=GieZjV2mZ xwcl`d#-i5 ADΐ0}/URL(hŽj#X&36`鬉|95Hx5D}XɟlȪN#CNʸY"i 4T)v,%:ٓ 2#{aV̡M2'h-Gv`.K%``b9_-ںKIWE"}RUgwxJ{rjŭϡ" 3ږuˉ+{r)eԞivEg!v VI8e/~[ohI".x\Ktz=`!.OlɴGM2~AYژ^ &KB͆z< M՚ ij{8exWK+e֠nSaK/2[vX5xœn8h!skL+s7i'fKd$j>dHV32:#D:ԃ-҇D#`M!>zoOןJ,.#+ 2c-%{7{k|Hɸ7)-N-R`a& <.-Hi.D?zKrnUǤ%dli⯧ċk'i|8XBpfT9EHe멀q#"vinS 3_opәh\nmi#lBP6zު7 ݀2RЄ̆h`O D̒yh20L\ruz(-Y+DLkTɎ&z1]{5ÝsT|^xpP|2xLY]UiѴtą@'r z\}<[iVa8̅Yj*rq>Q=iсvajP&B@;!4i'8;.Kӷw~//)NL6IGѐCv.fX~n<7l3џ|lZ));Y( j̔ {)Uv N \ 7)ɺ;IEԧ\53&I=#kݙFPTf5,)ݿxq\`r4eq~Pk`zw@ϡ uGD7?zƆ*aN^av3M!'cRo}c]mn#kԔNy;\] ]m^H*Ka*#[Vʴ`3Fb4Ջxˤg'CR2*X3+tRPsI Sݦ־(ïHM"N )%mj&X9.$bPd%#(w*}hؐR"߼AĈŢ@Ϸ!91y( y\ae-)n?p4SƗlqxT8[Vnqh3l^#@W#A-/2@[tBK> a& O&Wʋq ()NdzPnI8{OhR`rL_BY,mVB8>å @d1r`P{9rV@Sv?cA,"h + *FNPow4$L^!Rc V\کzlu0Kp@Ѐ"8ikE Cio#8nc Q|G=A%NSmޠ@Om}wcKԚ9%)/&fLq׫ J⦂+$; ȸtHM) 0Yj~C )dhOBVPuyZ:Fh䔞GeV<3T}~t́{8+%R&WbT3 OaBOad kpW:D{,l g {V fǷ[L -Ū٧f/x9` ) ö'"x`5]; k~XY<0ƥ<蟬B-y=P*8ڕ @Jbiv/w jZfg;e[>/T}Q?:_u6PM)Ż؛:3Rsf*&yoAyk=-őFfG)?0ۣ<ԨOEDY6~[~rd|\7ҋ)F2Ƀ^/mx/AlAG͉S js2!rZI֏SevGp+v2Lfh_t >9 @;gKN"`>+RcaKAwo6m6 /i򔭵]FwW4.1a@C8يNcWT] xL㚇mX/.I Z{-_luMpOL VCaZ;$5x]Cʺ9 uCѤ  y<&Yui_ټS3ԗh4& ,Q\t1R0/b\cp|RD3l0o{d04В$d,JkSio„/qҠ0ky{BJ|tG(z}?vJ}+|CT]\ML2x2.U7(v$"S@[ 4 D u"êK)#elpRG.E?/xBr[7S4rW˰t.|u .d@0~ [4%y/;RDyn%]yr̷%lrz^3,=2݈zQnW2 ^2'J J/*߱,8[u& ji7}E1=m#9믤x61arqƦ5äJ0lO3dA#!+#w+;#.g/)JXkɵûT+ fѳ5T, WgUFE֕uU-ўۻix*WmJ,l- 7Ҍ|UA@3a ?oڑ?EO!4(yh"Ca( <*5BKbc~P#x9 ʊez#ǵ0\ZAزk+' X+='QQ`bCVY"+ p"^wkɝUNX߼E@K5gQ+g&:No_5Q!INERH оX#oCDstV݅p̗p}e?zO4H_``Fw2z LUU®" g6gٴ96a~jW[V E@[[C^n[EJ\-EΝI`(X8O1<<3 K #v[#f/m:K{sJW&?a,u|Co?n0Nk}F`FE@ ]-0> yΏL;rHgbXUӉ^#4oōaan،t8w@Lgp\g᧖B# #=NrOA_Uܹ*mI"/#%N@F[pR{GS{7}5_@nNYOn\6*XON(+I* "cuw ]EVv*!A:|*Ak%ĂB=ISߣI5'HX䛫xڔ9k֐F),F_YEֽ)C[b(r>N8GZX6o >l"16iF,`''$c1m%ٜ)ӕA+[G))l~L(0^@?b!ų'rep2G_h ikS|ǻ e*=MRF\9H컘dT3VE7+$ gT_m/"@ ؎bE!z,9?mNG٢oOʿt^WKg[. !u6]XݮËڰ"Ơ/$-i_?5pTOF@ GDT~U@,pjP1ކ]p01ۀ-vPiP>DA D)ryD@_YYSb<ȃ'g ^My~4 *'`r624ؠ]` ?ݛ#FBɮ;ی϶}dU f#^ČwpHgJlg Z{%R(XCI+8IOO{\L kIB$<Pű犊H^Af[vұʀ)2ZwJfˑuRL8x)>;mIEFʒ, zEո Չ KU\o9 ,;jLsOep5 گQ?@6u/=N"q$Dh>(\iXOUG2o5'=leʼny[:1!LUx4Q^YI8?;ɨ$հcF$C4&;M+YxwRޣQ6}-#`-amʠu-ةwD1-#aGT^4[H Q>0kqX. ])?(b?0ˬxV` zcMj/3YI7 u`vے"=Qvyӯ״-;}h<00#<9Sq.bFYNdTYQAC:~? B :1,Dҝ no)y+gy2ݤ q:Q} Uj%$l3OjkqVx] }TPA(oGDxO Y~n;insn@;QQϲ),3tꨟ('E8h+2pq<@qZKZ:O\4/%iuO޲c+{_ύTmӄ?-C3_}A ܤr~nXy -mxOEհ&מk,`rqyU!|L%E@:=EOکREҡX[s1qsC$f8kxl,2Gv$}6ⱋ]Gjhmı $h?!#lR^DS !y {sLtnmK& \Q2ӡ~H8v? 6)^1᪝q%8vUh502MfS#Pg0LH؅(Nw?yDL 8}.<J@= k8]kp1J׃;a cY`P. & /f'Ā{ys }#V7PZCqGpIzi0mO+?L}:7jzP+@\ҶֹvnpUR.Dv5K(Q;;$ڌSǚ42l?#C[E+\B<}> H?ZFdH$<4=gT菠JoW ^ִ{{{v(KF!.[ð$D;'5^3wD>f}<<<.ـg 5:_#YU񤫹 5VQ NYh bĂjXs}_'IbcR )9J]ӭ ^"@򏈶~f\ {5EYc6C)ۚȹ@ n` q]xgESjp?Get@-vppx0ȏpUq \JԹ#fk{=1ż$)rC\%HWi] C,3~fB gFWxRN7!z++v 7˕fpg1?9~[QPNZqQ*Io,zʙL"ziglf];2]1`pe#fk +5rt~&t469>sѭQ"纙Iؖt d0hMy?;J ,,u]vyWF}ܧU&2e5.~u続PYI]pƚ<wA 8Axgn2?*06}퓉bSXR35'7g!uZycX_,hKu*N+OVK삓4X޹ yErML]w۷x͐d"vyy,mʌzEeMG_r?$ׯ6 QMo Z8)U2)jgvz/!ׯ\\;nz/nhF]}ߡ*+)BTp:!.h p US:/m~]yTMJ/h!Im3SapJ!p|)H-ذfiR7tRn*pYjC@ۺ=ؓ`^4I1eRia1pXW- Ȑ/u"%N4؈ȸE[E8Z! r_gD- 7q! jw*tjWoƗ(32ɬ.sә5Q&Vw z"u!7?:[%mr[-< }aRI2yJbT^n3\mLam0ՀD4*iCX13=ʛ~2qڼnWX׋.Tg}P}_a`?)G5 4"A|FsItSbOڷ1F> m158G͕7$:RE,7,zjDhT>ja}3D;/eتH.LOY[RPq =Bu? .$Ǝ7pUsh&Jo8\KYw@g-9he/'" V8`Wn)WFVTh3"%d;o/ҩWPtۼRZ`?fO)>9|`f' eրS5=LcSv kE!^dbZ Y& IIGBv))$KOnrnɜbAӤMP2N&"GTA`CJAAlR|G0^if44i 97 SWpyJoCȏɤi x ~ύDMHI.xupsJ.>9=w1~v}ǂ[^K1?.D Ij2ڒKB5OCiۋP3K:vr)-[oczI5>yv!k/y+i&n,hq@n:?i쓭jV&]yx'cm݅+N 4 #Y:vETK9,b52em\%B|5l6^SV~yRio9~!s)GO00PM7[N-#fCh+ʚy(RRܱ+uEGY1nemoa L,ёWu;|a.<{zN6[WF#YV*L˳娪K&Dxab| -gXխ$~MEq]|?$ 99o>EEA4RQK4Qxv,1_O*cW⑌YJQwfⰱgvY<䭟CgZ;6+Onu3|Ӄ֒ w;~N6(cJ*VDֽ?`݀Ep]Ik\mv'7cRptZdл#{I7nBzKZ`YyXrlTa jtbɼcAXs jHyW852R)k!QCXsAگ]T' "x'S? 3AfnxU`և9AC۾k864l혚%l꓾f*k(|oh7Y6! G-}`M6;/m6k!#"]!P;KJaGqS)@ˎtʦ$֤ꚏ).Ce_*WuUd߱>e>yJ }n;ư1~xɌfa_x]nN%kYq]RR:o ^?XÕexzck՘N*qmA(q i1p# !x?wyI߃|y?oXHPR4"x@̻aU|q`IX}*"}03hJQJU&8[[JC!O .ܽ,.PgYNHI થvA=ZRk ok "6m<{"}r싥+KW=m:Ejb\a (=%OA# |ioCW+ :8/x!m¹H=39rx+m]fj'|Z {#n-5 q]k֢֓IO+Q撬+Er_e7SVnZkρioQc}@E[xF<- F 4UF'JXDjk4ܴ[oٲ$Alk Kg@)iAa  ?k{`e G/,\'GⳊQyߓ$^,[ų0!{Nf/ΎUFEK>rކyhwiÐ8Tr3B'KweswQxѳjM!:z|=t2u6S%IF/ZK{ÙDМ|T{X,I pܯN֦hzȗQO n Lf9;jU[LCr_8Qz-zOa2O k.vtϳ/斍o Ni h(n$'0Љu}c G#|8d6*=ۣ9Tl};5'懸꣥fz;oF)!#U t\c:bΗe(=>Ds(Sd62y yS >/X& k,mXVPO2]mmZ 3m{W-,PэEEvoƷȊ8Xzs {"?kgeT'KLi PGh@!͛5Y^z1B.Z*3+їA@xι5*bNw?,`{yp\9Fݾ(iFS' 8ۏ)Y}Ԁ2$5 FzhYzLFsk1|O7UW7#Ff-f,2$:㨘)6D yyHK*d궋V_}$ߣМ$Y3͊|34°犾SUr]-wY;/!|5]&_*zy#,N|͂MP죏vaNj@GSS,e~S95f|G%i^m0 Ct4F{b@99B:&l5ă DvXӖBj8/0R &/՟p3uג!*%BC9aH1B?ثbB`,68b;&;Z87M ]̀8(W.5#< f:23X=m^Gy)P0.r5{|WNLze>M#UKVH|*=>[ʮ~jV|p71Ԏ0e[ u[Wleu0bL+@NґnLe, /?@r2G2eh -y܍-\5}կ'^dP"( ,~̕f6Q  zI:(7pIٍw8:*7R5VvS.b ,se̵DjyY]:%)&2|rE%4tx}!x(. ~{P/J[vDhpsX#ɩ록]2KW#C;Fj'uU%Pk 5y%}ej%ʨ/t.άI9i!oE8!;-@ WJMњW@JhS݌\ eBa N ?d}MRc-7k]rIu-_Sg<[V ƙgƑ4 Ӗ<YLh0hI˺/X߁QG (O a6}sLuRܨhN^ u(\upA|/m24 dAѽ{ B޽XxRxB3\1ɬm}:yw .7%V;l7|*^T-v?\ų3zFZz쀦΄z)Yx^x8|Q-gy =^S*2`ւ[-sC%X3_ )T; F=x_n./aG^Lz >0 mI]XvLmoA&X$sh$_ľ>k}%޿?J>j)M73@Q3b' m)+7iEJ)fOwc ͮ)@O1FI~ZP`gGֺd^3=0r/]Y1X dMxP炌,- ^F8exwB/!3HSẃ5OL[b,IqT@N3/%2tƻWk\OCq geퟘai^K@Ɍ1#B`jKﭡT%d+ E ?"֒a@T϶4L)~y6<銣q7ح&As:>B|{>X׷[*їV,zAsqgTK5|Ury Xve1-w=i-|wl*sj4P^ؐ`9ُ : 62O{qLd(S3L!㣄58@ AJwN_/r n?$T>iUIJ3P |+MQ 2{<ȾSʢ(a(HjZ4*˿^Y>tPsLq㣉#_d?%0C^7U}j4%Yc̨`_v{umgJG%EYGܙiWU5淚Tw'Yx+\" 4Syaņo]3Em " ;O l4Ĕ}opd~vAGj܏h.{363%IUu!b3UƵ߾@y eEs춍u:{˱aE9X4Sň/+AdTQ=׆ f9h:̨Q.t,Jw=3\*x; ofKagBLIȽ$Rgzs‰J3MáVbl!nᖜYBw_ _)ˋ4Yzww짊K~WL2!S{CtA|SUuVe&j1郥Eo!t :[(m=8!ߎ _FŹ~r (Oi;\Ht>6ez7񱮞QEV0%;'eaOv\kHolR/}ӑV@ s ťScXX@] PVϐʵMd%uoD7Ԇ&jK@tG'Հe~J}߆Vr ?tt@͗y:^f]ĩ?!m3yF.Ф B}[S9H^t{;rMO <Ўk]3%r HN Ѝծee[nե1^9٧ųcWlS'ZQvѴ(is8P=l12FK{t"% 4hfJەk ^kx#Ni9qL5$/t޳f Y3)#n {:Y2e'zy`$ciM"ڻZDW-(qO}7Zk`5t$k7u(Mo2բk@C?m9pQ}aTc89D39OÅo3)/kvAbBZ\Jk6P8',(@{:ݯarf{ks=P>ph9S`^vCo9 مVJfMRlPIDCW5]#Uf^F -U_S7.,JuyQ6m݄6c6擖Z mq8ahi$̚ \wYn$ѬI\n[Fr>g+ ;**Dnμ]\W18{01V)d' U3Ym V+yIg\ވZT$K3O`a*؆ zikB{D];m6WO$s.fв~]H: aґg|M<#bD 9> Z;shod˛4`UC2cdO:JX3% {GX&*ƥLU o(m"%,&bOqIL$f]Fi`DԌϠs|jsj{oOK5-E9:Fe;AOǤ9f}٩`l^&#q-ȸ}UA$q5HJ8AEN5Mf\ 2&W+7HYuӐ}y${b+\c(TՂ2yfk+/4L;3$k9mϤL ݾt8 ˳2Jo>JB`1({i⊭K}ead"NeoUD@ k:ة|/CWxVI@F= )~/Os~ƍ=k@n0AXt(mؓqgx O |팆 3}y_RAYh40a (ˇ%潖bTԸ? nD{fnݮ^XqncA0hjfADidNpe'wZ?X@tMKPxm`tAWAȼVCrp$^FMxѾ/\1iB;basFR)áȈob4/!A)Sbxio%[Mm!<Ͽ㷽95S默S~DPN:c lp9DZ[aOoe|-l"Ea^oח##96Z[(~2voUB/.pЦԘA#{Մ/3L*1+9֮mLr!]ӱ=3jnK2 6Lf^Xr„h> W%tiN=zͭjwxvQ#O/ /,07֚^niM|XZ,4xkL UsIZ"!욄H9ǻQ 姈.7zkT9(1W19#̗CO!o.h۸^IF% ٛS'2ɼvu;J'MkVFݜE QIYE@[u |1"$fw犙=" Jeͣ9{)DA[TfSQ͇B| 4>|$vJu_ `e Н?<_S%0'9;E߆F4:Eop|;4z%ˣCg^ڞаpP1?HKpɁUը3-q YѮRjǶ5uv"jYUZBd88>_ft,y#`$r϶V$̄Dw2pV8 K^JI@(~w>]#ߺ Hᝤ"I| \2Ѷ.6xǮї mmm8Y YӑsѥK^Ecpye $a $WGB.PeutEv(񿒿ܣ{NӚ;1ҍ9K^ʌژWʅR8ޱ:(!]7 3|d/D>Q]%2 Ut;)7Х ̰Ed5/,׌X\f|/1k,*ItEu3" =AS]3UJMS*l\E2CN:9ST@!YguE7Yˈr,{7X͞~fIEL G2F8z%ՉRQr%cI}E|N2 ')%p\M݄/߁d =PJEX,./%Ւu`5 P=7W>@~if6xR0[ThG9A~E8XHFF1t$IrЮ6 {VcwN8 Bve(_2z; IѾ#Q/o].yH46ޏt:7]}$n΢ T+Y= X (> gEr: ^% RwE}ZFYWQE1YÞZpA?4b)C. ׬+lZKƼZss0L)p`M9CZQ+hc1"TUkUQm޹9 }ނM }Jyic>uIxjW?0ouv=D}kܲ!'3Ar(])dPy~5 jȪlJݹ,f$ˣ$Vp tס ;4;-|(鹴꿃ehxPCX{y'[dpK4EqpӬw`YpAxk'1rl< uH먼nM 3ms}ow̑OHT6oA8v~S|Y0EGRW(@~&( ԰E%v\턇]9kiOwӝV=BlEGcݕQfivCQhĕ7lJ1efw0Tȋ1>f!D~dǓ"a6N*vaGjOa᛬߸6WbKB&T>̓v:{D,(kޠb*b"Sg_'#PYd[t%KBxIV7N-Z%~k`(8) |*Eӌj?ë[D9ŕߑЈh1߳k)%QImw=׌r]ҧ#$ӑe#ub :MNVҾo,kB6i\|'a0N;QI 5n:DͧPA'ꙂTJpX2&#[(BBd1 u&+ԤgQJ$T0:E{h%unU4QнL.-AjO|-blDBM(}X\xSGܝXI\Nm4t oe H, T-&6Kn^2cRʝGkM4zӛ KEg(w/^c7gOwA }3v_<6uAHsaue"מy#]rVEER$!Rː3󕎌DT0k,VtH c|/J~ Y2A/ĩVNud " 5)^2vV6Rf-~8_& g 5v! UeXtXoM&<-ٻ rPϠ6͉qG>PƳd,{PHr^E " zdQ[}mf׏Pʝ17=>K]JDuMIeo 9@%׻ 3.V0Kz,Ũ0caǰ#N&HЩ|P@ RWDnw[N(TR*w@Y1La:^ˌZhN/$՘b&:+erqذ,s`?) ʎ_Qȳ"%d\`O"|ȈȆp ax`y9^}M/e>T>m{[!'Bufgܙ0RpgJy`IFzߜI:c f|jBZoGGs. #mŹvh^t8Ƽme,zXVh)2DDɕ|$ckmRCCwONպL/{%ĩ~DVeơ̍8u؄#`TK.È5FO`2d.} BnܥlY)|Xbڶ#u>@ 5/KP Cdsbq+MvKzMLg@µ˕OۛY4Qx{QR{0Onkڦ;bi@[uL YBV G9ҡ|]PP׫dw(^p}9+YZ\GvU⹋ľԏwPjɕ:q",tԎf@q }a:38nI>e M|xY\<]-cNLӗ4?]g8\sWC'LR, 'RMx5x\$tcPraOPBƞVF׷|~9!?_'~j#ydB48JiN**Tf"kJ8/ROOņٟcߗOL^NvCLaQhq4 yB“:o}u8|i ilj bqة˄U|g_ȟrlY̦̍:I)Aѻ-`4=gvSNR$`^ }#r<8hJ·7j - cuxf^͆ EsZZ#vj 0K\h ZS[O6.}%⛨PGFN %ZaTM*T5 Aӊ#0nY9s,Wmކ`:ӓ$hdq,N/w;A?0f `}A&߯[@^VcyPtB?&n^pT/-"z@),iH|bh[m%[;bxvœGt ~1KrMS)D;0 e]Kܠ&ӝF.b`i :l&hwI|-]j;63:c5 Q@0LP J1؆0aZ 7HeQ4uٗ㫪9!{;U^$6H(HzUEЬ?ld4 e4%ێZ3qRx d~4:E`f7 ӌ9:Hm7/K}߆T'wJc`Đo?Xs/I2ޅZ)vq'J[޽N;|Ww Gam@4s fH;%ËHo,/8*4a޾T]H65To˹CHp)uX`v D@i<}BPHGa@xշ*&iuf[1; *muG8&,D}琥$}B cs :\>ÊGRK5w2`.E-|iB PN+|xB,Ÿ`ew⑨R7w5_8E+rĪY*̚)l$m\DA1Dle!͒jzB#A\\VN߈H |9S6|ś5\䣱_´ G2m7ͺKE峉zm3Xb4&y6B4ɉgа+%ǡ3^Ї5:[^,W)RL䚿fg)H;sχǩ #D.^ZRWa[za"Y.ܮp{=UهY>S▰TS!V(Ӳ?j]l&, ԩՑ_s]us#sDF*ycqerQڷ5"?O1 q.MkHvzN+}ՆИs]žKŶtu1^ޢQp_{ӸsR7(A9?߫af< jEimJ,DB{9bok jWQ)# j &Wr:%R9c zņLCqYv46^CʢɄȜt. Un_&zW.Ѵ /*` U۪ϳ#;YojK lpK3қ0.0ޜ8tp<&ԗ?gӚ~9G4,0>95Pg|ʔ0㢄 }BlrT@CwH$_zv;[e$jT 1ED|!DPe>XWA}ԍβ<eY,%A _n ysyA (xzNvN_ljjh7Î%],ݨXy-"YP"EӔRi6auyE8צ[O[ xnE$'^AN)B1A2Y60fCu9V4i(=LG? CJlG5"KѢpQ#Jpȟˋpۣ$E!$%PMJ.g6irXC$5m0Tyh5*pH-sFU>Ig@D g=b˴TYR9V l@oS0*s@>'~h}JDB\2(2 s^g[?N[Tw^pݲjB.^cj^fqUL@jW}\uGzDI OԴܻz8E.<#xʎ`z^wӺ{P0BFքAYl"əCwrZmT~WmNᚼ1nH=CW3-5YV5堊A frԔ<<l ̡rzp)7+./^pKgAxYDGC_mi6H$]Oo7H#agD5* ѩRE`3pj]Ơ*<ى\-Ŗ!>Pq>c8X+Ќ֤k=;caRsAiM[R#+{&}P`S? #&*PP[w"JE51 qHI;b`fDAL!/uwE:A]av7쳣 #]5-dYi_מtDKvYY.MvBT$SԀbF;^U XвkV;u"H8ƒ7@uk@<:qq}b`ԖzN {Nl,2~8O` ذN|Ro)`4ŝde,oA}7e-y~/b}j%]vIUKD7@GK Z"w4d] &;Z@O^)jύaό+/<M@YnOw}„mGdVyK6ke襵?Pu% 9~i<.z'|_Q2Jğ! x/ ƩiC5_H*ILe+LȾi ^l)B Sb5T$O$eD0<>ݶV:ƒ@$Y8`qg-R]XA64Qh|zS$e=`SbށR7+G O1)v:> h:Z~>$4V5cxlh`9]Z~/6L ^kgV*ʛY\a&9qJ(FNBm;?1AӜ9椑5ws(G~HZm_}1+铠G |6 =z~BU Kl o"^7B'1G$ean$*k̘Ef$]RHI8oo2s54v2VoT ٸ`3!H| 1wx`Lf">U͍U, qW `|<&: g*]@3 z,aX(6'S)7>_C}2(ߢE5ΛH}WG)|iW  N7ȁJ+0i AHcI%31:MT31chdMsy5U1cVs+"nԫ 4!訞Zȝ {wkB&zH*㦆q ̗vwieHbVSL BGM[u,xgX\>6UT,544 #?{" b~k541R%mDy.`.ۮktM z%S#2#yV(&K0:wl"]3{JR5VŞJFQ=y3F#}HL_ςO#X]`@/ {o'M<03U& v"g}3*Oyý.!S?6qj= ,;=bgI9b^tˌcvOB/GbވD\M|A+-Vꑼķy4Fjm#{6Chkڑ'=7WXQܘ_A!L*cflv%mj;G}V扖: = 4]:GAHse㨚Iغut/yD~ !Xl, 5l܃|{y=_H9G{t0(}!R%<+un݇vG7kTbrc3|ԧG޿>vB ɝUBrJ-o}m&d;iS'Ey hk5ghO`K3ˆMGtWwVp9ZƇ XIE7e g_4̗Zovl|Gp"st=՟~m4`=M{4D" N+2}YPO֑M,WsupbUw1?_בL1i71}6ğ3^~> S/! t#MtqJR#=]t=Nͤ]5e --Mdn=F IчEvk^˧HYL&wLtj>Ш#ŚD:'Lߜ=+&`W3Xe}}¹ D1/=sJ.%u "O_#4-)`)fdөh-}: Gv^m{j>b<(]g{9" {8u|ƒz{xy0xvs0u~)Mp2‘))rbėvj_Ƣ46AOE}'Cn9(*Gyg£tV!߁T .Ț$hmM(Wz EW%GnMo*CJvb [WĹk=;WHFhgYwLG ui$K]u=' vg:j;7H @vW]+J',k^)c;m S_;jtr3aFC\qtrS׋ejAxxի nx/ Q_xA1aKZBuV S8}nKDKb}w ؖ cSF,6xVmk$aZlq0VLdYeʵ8$z<.rLC(,C:Ok8zq9GOuz=t`#cMwff9@t2W)ɫ!LţSQjh<,`<_OETpujT_q荇qʴY[ _'p6p%E.) 㣃Y'2Byt+ 53WT9fK]5Q d9`k-U?-'vZץ~/j!C>9 H$< i+%mhd̋s+Ҙ q6$ۜX\>F.צ>a-꺗5M[h}q$ l~X̝xƦ\ QM6'J,nNǂdW2ަNsP5Yso;8vYobE TLg.Om]oWHަ&9.Im}XJ5"$SjvQ5piq>[ XRe#<aK/{wuc#e>:B0cLCEژCq"@F}~Cf#ҭqIw'RPkX8{E>#bW}ͯ ^v0F* ̄۝DC%ed O+IHiD n#_,L0yaK &McҚ~AT$MOp%%d_ tYaEѱg'Kx!:I'&|r:߱o7sqÍ b(b$$m;^0~ow!< TvYj\#xkM:Rt)~4Ik>el^;#$W_yNp \3dbz8!ݲ$ 7s4D\3Q&̌'mp_CyjA٘`@Z<=Ky^:~ۈI}ֶ%y,+hms4iLκC^i]Ebg0X$:uϠ1>E$%7̰rp)ANめ\nǪD(l^otbk֮SJN tg˘MٖYt =ʔw$`/n'}B?Hfxʨ"bGvO({,iTHҷwL7(_ȎGye@Uf zQ\XAuw]BTa>1ro}K4:KD_/Gy& 𾚩ek4$\L`|RJȼ״LL&tPW78EpE=yBIMN3~~ [$vP²1:pߌoׄ3JQWCBμ R, ldUv<滗uk(N>?zPP)"Mi꒮E҉Uh)|&蘒FҼ'5cz%}'5Q$bcʙcq6> M |dcgxc՜}blfxy>6O!4:LT-Ӊ .5pIGѼQQ$H@~芖NH)Cml~n-yEM)\r!|m^PEӆL[AΙ|<^K]ȫ\wlVL>9T&x-hmG-|&n݃eN@gmt Fyc y> OpZ9Jp@54MX ^~8`diXP?sBBLngUß|2 &h;^o$I`>/90 ZWy#ܑ%ImuŰY\^DT wJ ?(vj@S:X ՗I&Ϙ˳D]'D;=JQԃ(1^"qs26tI4+_dR2O:.l)@_ zj)b9֝]wavnfG#8OZf b}X YƷ l98345j!ijr5ؚ)w dk>|WnWSI:.r˹AnʩO5iU0JD:"+ӗZAl+ؽZѪ!l}4dVjwP Ie}ԭb V;j.R ϐdm9s潋nQ܌|teC@Hx H26j[^V0oiEB9V65tt(t݁;Il6>AbL91W l>?%!U0׫$H1e8˓zVmĩ*7ȥwZ88~̾,Pqy !EI9r0;fĠ6OHStN`s"B L qrEV'M1H5x 溥,?>`@x/3z&_eSmYq(YnٌfN+4+c e[{]R(v'~,l ,&zXI`q#v@*4}SDoc\ZcWx=P'6V';.{($hUTF3"CRR0 QN|Ϊ9;-5VڛYCyh<[78}Nn0KpN";`KԄ{+N} "eܨ VOX?R9qՎ {qP# T-Bp1h(|}`1/=,DRԿ6i,o%MR\k@RyE㱺s=O'aܔ[r1[74t:iOd>XKF:Ψ)jr+'y*GfX$ӥS whB$zl%l͐WMSh*Qyz̸v=/y8(dt-7b_tD\- %Av_7&AqJ?P˔ʷʙ*$s'Wj $_SWWz}'ϋX*Pq A:%~άur&eH!p.m8%=͵лWe,5Չ--.@>RAE|΁Kfp{=o}K ~֢gL3S9aUPYK?8쟸7Qزys>m)JBxiKC3XmϑEs2{D/ LtqT9}*}s,ƛ |Qo# ʼn(!%ѩnٓ]qDIr)ttt1VlrcZFTT L8G_K?*~ UM; JXdrG^7}S1`8)t &O Y=X&8SEm_a!­NfGHZ#60s8@P4Zll0Ix[_HaoTP`9d:r6D$-En\5\[؇4E^f,F. KFo3M&= "aO%SbD3>7#nl_d!`0xwJ=E^WLF c*B'xYK {AfYyz;!񯃷e"ճX>plثȉ2K[p$ۏΤ݆<@~ k ɍWGVc=[g~ B[4t$bXVSw~/^1O|bATO>6hXսq/mer3Zw||s4yjttY객(#`h\cPX?D7%yqM_X6Z>ﳹ[W`zϳ¾o㼨m`1EɌ@!':@7ׅ4Ȁ, %ڴ} ƝD\/XOA%9:elhVzK{K bjr:n My5򌎺=o%@ Me6 *C ԯ|*G߽SSSc^ % xKr_6 &o0\U!GNowA*Q;A+w?ָ+ N8VV[TQh)'?փ*5|v[tT-{(e8:U ^l ײM&dWLǑ̞qF:2! >wb zXldɥOL1\UB:%.L\"^\R팔į׳o5 MԻߦs$Zrm.qnZp-;;SxO~ustGvC-A I0 !I&B.ԮlWT~vFe\ȾJ%OgO9B!!X+vbԡk ׂ9/3씩dY8ädu/+aG˜,nZuznd$=47oj6:ÍX.h1e hk-8&pqnZ}js/\_2hÁ/>czyxJrS 8YD˦6 t1HUvں|!dzؾC`k܃SJWJ`vxx ׁCwUWzl }_kE_#L6՘B e^%j{xA\}%2/ _KDі%ϑ1RtӇתmۺaU*^gAk-^T;KAe$h +Vw"Gׯi"K4)nβkd>!qE]uI-dS|ir7A2FAFE4吖qCfƘoR{qU ryK(U(u'l"^Wb&]|YGxū=^ PaW^dUx`d8+籯3ъTieN%Jܘ;۪*Q¸>\٪]˙Z_ "7qm@=9ƚkt8M)J<­V[f: :+>']/E[&oȺ ĥP4QXaDއ9/ ˶.#Z>kE|i@H ɺ=[!;cɕ $Ms>g 2bsb8a~ +QyvWcZtMӁ>Hu @.f.پa柷J J ̖InE2[A6d>s)Vn+0n aqxNu"=fy Q]m/Zޏ Gh]w+|]qiRH^4%hQJS8$?ʸ"<Jrz3`Y`!݈bd'F)- 41lsƪWh I:aWLHBX/QX%[+bƱH Vlpu12 0M͸q  6` wᜮ5JZ=ͼ ^e}L v|+pp7oݺQF't cJk#c- )q%s<Cep`O&F&GF|z} k>%:I!M`Խ am2jhLi"2)@{`s~ٺjӐ"M"_Q&& xˉ)[1Y}*Np--w_s^؊ з}FksL"^uԫPu1nk\,ފQ`3MJ}̘~2=v6|0ѷ-ڑBw(l_TTxPbsgThU= NSO6k:O1R`p7B5g$TW +A1 sk'lRY$*vcAX . !'T9j)snWM0@Rnޯ@cȓ8˫tĥ>|JatBJ6 BM #g"  e{Y{U(z1ƾ{T&Ņ/i}`u](8%N'f콿S~Vۤ؍nԊ\t"j¸Z؅/홫vI؁C``>[==4<}!U"{y.SAȅ M%N<@ $<,R]M yAqyL 3> z^aOݣóKsvL#ܺXg#_zX -/Y]˷s,ż6jxl[GfxWqԶu{q%ihx

6pnq8ɭQ,^ n\$C4?kFGca)w&Ear&3Fҧ Q\,~\ċ%TY>3}U@Rb ͫ %r$l:+5W~:rm&OˣMSoeA#TLaAc_K 7L`xRHm |Ifhh7x6Tϙ>x}X\[a2wt׶z`>/zq`dա9[Te,(N[/+]3$ͨ !ܛՇm%0f:Ju8(Lʭuc朮hD4\ sW'4 <^P#:GYU^Xϲ t6X=8Q4ې#b"#hWt Ua) t *׵sG8ht2ݲh*Ct]D(^QƎGNQTmPap%+FdBc[ 7P˄ND).V,T !Lh0^$W9zb Xt]05ɉ dr!f:pCTʼn oj|{,Mr &rԍŦ$)|0"aH5BjC#f& A`&ఞo8az ]VV@eJ>Ux <|P̖] \lRh 'AEqљHZ8u46ŁQ.76B󯄣b {V*Їl)/('{s>~@&PTWHKwdvZqcK~oK'YYi̻fܝ trDN{\U\*X] xa @#bj&t)5ֽ=C>8?Ʀt1FԀZ5N# N?9oChiu&syd(.A91峁J/g ҈L6MӾ̵FR{]&m[9Ud^'2-vU<M `#TaѥGņ,jb,jze sUJV``k.jLԭ*R=e] >e<JѦӔ eo;rJ@]h~`eD1$,BM:S`ΧݐNjIAcq"mL`}Kb7%lW9!WQ{F{>ټgWC d62aL5pwc`1Trz|/C8cl4G[E.$\'d'Q4hL6Bf'$ ¨~2VL*kWM>NwðsPTdyt[h /,)LXA}r/xz>"v+G+ ]Y]!HȎ>Zuuxbjro4 0&*7YxX"w~]7ს6I(P\/3@# Ɲ0ڍW{D` Qlآ"j$,yin\lTEBM`rkUllcaL$"oKB xJy܉`IU>xi8Sȴ5(22@jҁs~mv.7tL퐊eAG^Jǎh}oRF:T4m0T^~(*{-^wN~Ftzu5CEz?e0m8g@/N}ڗA !S[[bz_c2OGxtC=<53w}ƓdqQ~\'Ra t ?U6D`#Ve̘1堾*=D'FqQzv5#sO-'f? R-Iŵ*s1{sݝȍ"`"W,F,[01lk2x 6X.$:RaB6.//2g0KW~c"FM~z/L\ ?FNE n{76Lm=̰^xo$hNXQ.0#2õJ?%{i4TA,â}d[X,<ٯH'𙯻eyY1?{̌@H4/[{wQOWcYvquL%Ix[yg>v$a%rB$x-T[J][= 0٤ilWY\Gf"ἑ Q~#a1LKB) ^[Zq(9JS g;W?"H؎$ű^92NBfr\xH{ǪO(˞P_iq\O@S-Iu3t -D_}{ KF_?$8B ?T ["'}4ca7'dp#@X[#:H4WBֹH*jәO{/-EK>$#?-"Krt؟9&&>=ޟ j'^ Rړۘ_+N[^=dxQ:JhB-)Lc+Х̝E\r4V2 cj+pҲlR/UgNOF;{l I8}jb} *ĺyPԃ)+W%HjW?*.-'qũ}TYʯ&h4OXV͉jgx͇% bt)ՇKl2q'YI#. /֧Ő>j}18\y?^'ފ漥"KRr(bFy[ !XaĀln>gQ𑲰f -PD бͣjfьhtN/+9)0JU qt& Ԋשּׁ ExqHaGxi3:^C'g|YÊևp)qs&dl f'ƍW ĦĽQmv^hSY^hDyVfW?(1ҍڸ5Om€w~.]%iF/ v;4dgAvgb]?cv溵Kj3J&QMhG}w#'?Rl}eF4Jڂ iM[OGє` (g) o-rI "yރyxd8ѩ Y, ,CBua$dJ翩U4d~sZL͏Uئ\G 9PS9.p:er&Y2~͂g0S :⑹ӞPձc|߸Q(<,O^0 .T}ɧ7qv˃)+1-bQ3M.v'OXnI=2)j,8Y^IXuHqe[|}HB"tLl❰j.[~ҟwWT\u} )wy+DY?(G{ OzSѼL݋T5>xzjI*9E3-xAxa%R}RsC] $9 YF7֑y.U_mt;bnS<ϱv/6ZRhB=r.OmE: 2cLo~l]-z{<@)ȫ 4-+_M؂ /t( ݿZo`=2&3 K)R[4ިj/A{ur*v/#`Vhn?Cxg6G ;&@ C+AҬ8ob>H`]3q'NkŪ|pէH9*B*T V/œ? Mz#%di! S930ilg_q7gH;&8FGtԼ}E:oFM6y4lZVT0i'ŵe錞Ұ*=jEPɌ ϋ謧m%#렯t6n:EWde!_7X}zЯ~b0 k+i5g3408`#Y658®_RGY+ϭcC!]}A?-~bP# 6e1 yAw≻(ܸ̅iPת~:V$R@~ . wv/dQi^ƣ.[; n~|wvO=יP1\M}S5ijpubɽNa`#%oy")M1#O;x;·>'_]#eH4,gnADi|/&{"y{`GIjy$28BH:)VEPXz(/aj% s[IdMRb%C@{Nq]%ޜ^r\=]`*|mzFkJ]h֟&[MN^1: h t-żB:7wtTW.72jIy@bdHr T&N;7: Q'{6^r 5X?(${|966`! #&WL]IV~?iE:9ǠV͟;T8TK]P4;VW~FT)"/  ɮz5 )KU41K $-f<_j?x?`?`P'7&ˣXeچq Z  C,i_{D|;ưy)i"6*s7gr&n"nGSG1 ^쇄q*g ٮ ero!׫3C3̕ѡmo|`a0n_p0T Rĵtkh-SnҘ}ٻXЁn$De>4xE4 8w5jQAȫ-FR9Tukk7:  (Dc@Na%L?bgڌ uBIBrXj^Q O?{Ur$uEz̘dU~|^ޔT SrYH )VLC {Î 80J .D, Pie}$ʀsKXOxsZX~^x$z'u _tfpqwG{KmXe}._}WC&nw$".)֡h5!|܏1&Ř<`d{%B(`^pXJ X[5 *G#=7L5q+#9DNؐ4?a{᭙Ri;iDc;0G߹TrͽR- E1ҷ92*Ljw3 :0kyIx[@ad}/XΧlpU,8C ꍆ5f8Cl [ :[1 Ygaz%?u@hqTZa⟅[u VNVVP1W3_\רQ)@Qa.e(HˋMOj*V3ѧY0Es3Uc-] JPI+P99"nJO< Q*oNnS+ 6B\q=쾆6gabTD'R&њySJf0&8Fv)>aޫn{+tjkk'af[^}L[\V\//)JndF6x/uX90r#PP»ȯE.ٍH׻$ڦǎ !#:Swk[Oa> d9gfSKSvƕpƷ\B". 91ńj4˺Q΍@Y{ts˺yrT)3DUMs2pLېUo] [ iPS.3G+ 7)֊zvkxC~$ KmU^+x`ŃdM=K\ ݻ;b0 9H^_0{16AFʃ|3S,ZƯujt~@'žYuU>Ȥli(;.YAgKE7°<<(zg=oy`= ~bM]%wsէ.vb c=d{߃͠CDeƼ/밼Rw0A1tف=  v@ܹmlwnw )!wM4uNd\B=63l`1_уH@P NW{޳ ~8"\[q̻JKhl5ThsJ=3zFXps|hl獱76ÝIPԒp9vehx{o͹Ի*0_FNrk,f>'6WTbʉ<ʵZr[F2SW֜{24[(A9si$2'~5ܦWYSZƿHW {n&*^ {:EJ_[v<,x>oFF\X QZkQI#l$[p[ ߈ a'|w<5ؓ>N䯣t-@r~~J}.‚f[>2paUadu[DW4va72ow"iP.U[ 5nmVh/=,gbiq8zTK)UD[zěiFqџ{]iuO"/(% ʏ\G.[~V$kz߉y33, T:iK{@#1 oj5de:\()IjIds*hp,o^ez!OTT,QK6wBEq_^}н5k;v8D1k@?k o)2݌V'a&BK>S'R2ٹvX\:BAn;G/6v{(GCE_jDv3 0)##iZ[ߧGSd. pjaR0X:sP "gX;/~7" ulk HUn;+I|R쿇<\Cr?u~\4]7fPZU}onuy `LhxMbPX 0}Þ>T}:PiK؝:y(c;|dD>@:[aP}J'dK%ar7 j%]j,|?cՅɀ+n[%?Û'=Z/܌quX#e\Hf2˖0~^ ѡ^' v5n`s_l %ꌈ]*o"f<)7'(5?^$)#6GeIg,<|!8?T3:Ggt!v-p=8ϒf]h] gStR\ۃEI/wZ&~soۜۅٟ'?N~shel;Imj\)jAgu qhUypoP{̴}(Xޑ&S>SIJtri9'Hm\>D?̇3ۏSG?T(|@h,MCV+Ii]Vc=,mEt?}/Ɛ3ǙUA6;RE1:_懴zP! }L B4==~"OcLQ/V ?%%, $V|m5.[}Jp~H97rהcew x7xkѳMFKnLbl >=;skz|#F_U7ᐹEI0lNF%݂? 'Cʬeq:h}ZzLCࡢ9-,Ae@>LA .jhrz `C ׶H21Y5 dX*NN_? 2(?ϴ}?ަ~qXCz Q9 TRe;դ'8*ߑ'1؄6'' e6Ƨ UEF16Sr\vl73YBKqg:3q$`tD: G@YuBb0yI``_; {W@I$ݤ!4mU{t߈}ބZKj %z#lڬDc'iJc BJ,2zR?)9X/#X]\f&~UT'$9N }BN~O},r4ij׋X2v;CXr?ګ.aR T)rjvYѷA {)(աж{z46.W !iKu㼖WeVM׍&y-\kݻc,QsLAuEyN8Gmug呭 $Re=q t4 Eė3 (0u{g+D{r G5A ~.%|CiZoW;/eP m3΁$P2>G@gٗϗvn5D%ӕ5?I-J0""Ŗe6x=ȆO~S۝g'CFg7}AV ".}8a<Z[ ђQg!o Vt SJ5wŃ i|ѨͲj ~'VBJt{$Krr9/S1JF:ڏ,S bNrZt0;nGzG%(W3q~ o:Ů̿~]UkJ@l\~&3xM a]譺]{UH!› 1Yv@W[ l!RL72NQWfuXB1PӤ sDл?˞E (ͱ8oCCkv|]>pk@c;8봇i08vN1 'aF?bbs9fOdδB[0oa(wX_K}*wWتQϤ _-}cCHR20 wVyH෫%DYl߅`JXⓍ7SNU ;)0S$D̩6/ca]},0PP>[@L 'Xm=z2^1N팟Rn-%yMSzՂ{f3\Ⱥja(/4  ^)?r!f3`O{[@]™D+ۻв6蠁4v)-hEhc.; 1B}.}?)jv 6/&炱dY~'3筘h"Ŀl}vѱ͂zSMɛk)YnXM3gu' s:3ڄYf b?{ jSi%NsbS9 QcRlS^@24i̞sV4SP߷_3nH$NE;q%4 h*w΋_dsg G0 9 5\[[]{Ըm?)6:ٛδ c 3;NJ[VSҊ.)^?2k*τG`G7~jGZn+?z@%[g\qiK]<<{+&I욪ViٮW>9y*#?P C Zu\cErMX-,,9d4f3td?~eŭU ݕA'^-S=c9kvT$AAxVթ~S'X-sVӇ˘-S/:dVp>^ڭfx6x1cg~SwqY#{p[ Byݨ Hbkp#6ݯGjL%z B=8ɝ`Փ|ׇrxk,%6I0EݣFji:ws R" ՔgE?>C"(9wV0c(V*@ ʶf~KTz>4>q8VH.v꓾6g׫▃@j~$E籸6T.fJ%Y:#֤I8&IzX\4mtݮ3?FV;+vTN.gw<$\˳+՚of/(8J >d 6f-A4= -I2YOIl=BW ٢Q*h04$_5 a;L1 1r}Bm%E1b?h OJOGWhM5u<:LAJt)~c!.?rp^'ߢBK4U`\G_=cR+uaN 2!L8dp3o|!dEjZWeS2g~?dIğ偬.ZOjj6 ?DvW-gf,U|zm)t `ՙ^Ac?"r֤u͙RRvuVz4i 8^r* P$&^J )Rmֺ>1u8|8֡uV^hb5'͠O"#VzagN-XE$u >֑5{T1IWN)[ă2bzpQ pMGWԺ⢝[eӄ_&~#a)2-wh7`6CPT9wcuH-4Sj]e7=OQrs`¦LIW}QkW"R#K;Y*--)P Da KM Jmu1T&X"0m9"({4$8Eu=|֓¢z;Fg@y}bN2T ?OR$I0'2%@ݭW7Qp vEbvBB Ewit"L3:|Gh O=P"-z'MxΨ_Tqt)T!3J ZzMf`$Uz #Ћ2dTBV`lGsAҸȨNOH\[:>K?Jjòݎ RZ^D_!&nbo#2#4[iFӜ}2v Z<[cwATl|!1 9x5i d54YR J=BOxq; lLdU5 J T@d}>],f:wgzH\nn1u*qn(S9$5CNٞDyqiİ$zUwN7y qlt#|^ ,Ab;8Q9#;!@̖>W:'ݮo)O.H6T݉i߯zr)]Y'zۚ7gpR84^KB?NKʌ|ԽN<[cm^ +Kpe|@,q#w]l־fU To@ &07crQrq[FzLtu_`)${~? ؟T?sEޯg2Te=}/p)|p=v;>j}"'?3/ř$XS^e(-``;d 2*-+sIBt1z\6  9xPUÌ.R 1).p0פ&!!0Ib5A08!bTA=uk%JqS Yb&P8,&arxѴ uG'jcc T)t 愥ۯ ?tя~)Q=/ ԗ ޏfR?I;ZO^չx䷡C>~6!=`&Ks}CF~eY*I{YZ1J--u k)cKwxtH7'N [FCRJ&lJ c_[ػY溲vX6͟Wؽ9e[F:.xs4f] uw8BKK?CtV[R/-@#s:.8~ϘGӚ\[%ȈG!٭ $pu.6cRV)*FjԜ\>;D7 [O,ծ]Au3'QND KÄ> xɈPv0.3胻C&A՗AϨD/_M2Ş£UƓj~E\9D濆83Wn#Q% B׶De"6 rԁ{mѯa.;.*DhәoC΅!@6,yQ'2~}Omo0!-gLRUx}_Dg$Yy5#vkVyθv ꈓ9j P%^fu~e1eb%~MT}Dr*6, fa3YCD Byb>$oɐN$BRhl03#ڃUpkЉM}t\2`z͔7f akSfF?t$y 펞λ! abݓu5._dtZ9VׂvfsjhMt@)uLT=xFB v7jIoN[La$Z\J_3|h8a)Za8PR4HTx1kPoY _ִ?/Q NaI5 A hsҔ[nMȱ ؚTMtF(/:'Y̟W=n[ӣ*XY8 ];N"eFM)(R .(هz׋HeHS=E0JXŧXǩ6u[Onk' %\k9IWEcdxV',i'ƦT#}AdF>ethmtR~rҷΊ#."Gޫ;˗X2!"-Ц6wf'QL5ߚ4+?NÑa͋Oн5:k˓z^\cȩ\ʅ"JsŽ& .iP0iZ?|go(K<]pH爕'J`@qzBt/l7e7l#;^;OZe%xa>g(e&^†'}?Z^Z LD3Aew`6_A33*cЀtRkI@: +[% 5:A;XygYcjbˮڻ}W( 4r3lD?G*؝9hHYm#mYI;AoThyV*`5VDGElEg$",hVPpi"Xg.a#SDH) Ey 䉰sfv1!X 66Y?^ύsDޖfEV7 p9얮4X0đO.Xzj[;=l76hwʆE0qgf_$B8UJR|*7Lc^-bKa(gd՞aTd[NIlg4IP 0QP#ośxTa]pьVs5AɶQIB/8XeM!Õ+~ *YgMբ}!{pYSAjw BS ;VQm$R,۬†y L6g, ER*#2ZTFx 190+4d‰JÈ٬{ У}bg?e}-5mM05 D5R2bo4"pvc^9V2R2x^d :e\=0j/`c3|G9Tu˗1sC#[xr Fm ߉6(G/Z) 9wX6d=+.oU..'畝yYԊe9MЙ Ec^|?i$`W˄/'e(1 e6 zf蚽\qw:{ wi{`Ůl$w\M{$@23wwy+Iw6e,92K+ƃmC/lT>ȣ;`eki߰|fsL&ٓLRa.e G-1&h|a 7-%I,Sq/aSFP:SI%[{H0ěO12BL J8Ίm s}Cz? 빕ڰk݋$}Aalm3%(XZ[BRZmg5&/gዎ6s>7yUx,C!ch!n{yl*u6M"c6XQ1Q/vh;_$%kݻDx!^l Q]ie۰d]R:d"tȲϧrzl5 $ECMo=Bgmgһ0VݗH->LaL|~[| )v_kQҀ9ևK W/Ϟ1^û6jΐ҉Qr$A€'L\ 0殖!6 3XL8! OZ9t * I [RKc[T8r=j&Hk 1Q}Jz /딆bMnӡJ%LckB2z-ނP }bpU) :"ʁ#]Ym7:ϭΓ_:%3\ z΁1XG2:J*K B9Hߑ&q@ \Е)h*4ۄ||&v37yYX`iU;l(B7WG.9Hdz!Ub([H۷bS{t lh795$DH}tOŸ0 x-Oj}d5HcU<[ StSTe'ammX@AۗS+ } o0Alkم۟U{b:7Y8B#- 2`@T҅\(P4yORٍǩ_?mkwYް1 Լ5˼a ܕpUl2"فJE8[n+aC֮8KZQYI.q]`g @ % p!o/}wKh[ F%zU4)=,9,s=v=T㏦,Zb;!&_F b2caX&#6HwJt0"7/;sG녺@1jLnd>_SXShfˡ98Tj#/e2ֹ1=<\<ۑ0raF>;}Z6_$ϭXDS O笜. *`xw/{GaD9/h8w}+2mQl]9=O^~(=$v)k"aUϙ{b q$jhrG.`:UlnHC5]k$Jt.od{;E"8F yN&D%X4|FQeP㾢|O/O5?y6m/J&˾︵SPDpjk eaR`!2]| 2ew)1HYlV,!_Cb[վ68RuWR Ǭ*C~-f8Vr˗YE/#b[>O 1 Ugy%'mg;%9oOd|ǔ[#Pmv!& +Ƴ}r". /paE%Nqҗ3q6Hbzݯ!3=K/wuXKF$,H3q Qv}eʨq1ֿVMgQ,bgt ?&:1N7@+zwfU{bLc9}XsQqׅ4ܶ`kEcd?\ 3S:4`qv#Qۛ1 8O##EÄlP6C#k{:061!e瘿 @O#R +~t7pսߜZٸ҂TΫ 6t0Ƴ !n%mq~u듖$~%W=(sߧ*d/iF$V1nj ޓEUِxjG,_T<%8HWaڶ ˍIJzz,-:l% 7'MOKi6 zFvޜb$z^;5oj^bU3тTShb04Pݡ#eWYzXcrV<AO e*:7%hv4ybq-[.Bv;mGit˳p8blؿPM̐4 E|3:Yyd~h #N"Ҭۇ d ) |ioT!+;iJzW"Ԑ~Vq];R._%4~ACbQX?9/pEF6..ɫafT'X79㜯BN_ JX0/*zR_iQ)Il3euz5䝠?n  %EaҬ>K7K _wU'[phF,kž% 6 隹Xz8@HW5Z^ zQ8J\*GXS0;4e"=!Ts =#)O @bxn&s!Xn`уrGd6MDrv T#qߍ\XYEPِD]Z?d #rٟܲԤp6.l*L}T^&ށ []pzW˒zdW5W-%kA]Uf=zzٮR\  ʃD jEtqk,hfeIZFA3mPI\R֯$dq[ef6Mu0nI gSI 佩ZU ]ܦwf8deW/him4э%veɷU'HP9^y)*:&y1lR vAKWMmM^ 2{S̤ oz<[O|]> EGu nJe,i8nhz1aJ~u!&˼ŪяEPIemO 2s!A嚩R>D01`d!+UA?֒S,c]灍ƟɬkfQm#ݮQu_ʠ7Xƥ˰Ǔ6hQ(jcH]Io?EQV{;l藭|Ck"}PwiW5~ [`BsܳD{I\cP֟XYBwXal8}&gjL~[eHO)? Ҽ?jҐ6uDلt3xd;L .F b8|gTL7Q{iHjs&@/:z7UXldķxxUw ԴsaC&i<B-rVqnxgy7'osTn7^'tڿB>9*I)LYСQUxjdcR2YU8S._rPQO~+Kr&~^6"%5\,n5:bwt.t~ BZЧ-')LcD6/24cX 22iޓS=$AhdතEZNanvS/'XN @.ؗkOLkycڶG{#>yܝ},hj#Hh#ߔ ơI3\{1<&juXo%:URtbk 2ljpNq#be(dQ8u~*}l @k J2mr/|p4ti?{覇55X_sI*,QW)4XOǤ[>^3=*t,1ML\-DXhߋ։ H|\G|XA*O/[ tFfBIV1NVޤp~袆Xc|8$(d(0#AM;ؕ{Śs0v?|Wʒ $IL&-Uɒ Jr&Tʚ膸ᵤϚi Vzͭ患JLJ/yQV!ؔ5)3sepsio_ 5Ttd o(vK IHKQ]:AuP]s9GK#G"zR(ijPx7۵B>Oba𓗶N6l͚Q 2>N7ʉ0ۜ Z3wox_XDWs;5$EYʐ{@~C&kݹ8P>OW*OG-],MU(/^`%2E&= cx!q?2~./v?2U;zPʱSW)ma04u1{йÐL9nCw*Z|9_i *dd81p 5GM^/G՝&$a0æEҤ#kVV"q|sXIAѕE)4֔a;~VOAmj9TQ$ B@zHW>FFݏ1 [t#!KX[Z`Ƴ)&M2֯'Y1f4^@e dyO}o߷U# xo;_`HG L%5"S`KhP+-A!g3wL =m0AhPa.ةIEXh9&qw:}ddXAp!uΔn:p~3)10vJU%SזCbd .:@:{rK6"Z·9:w'k>^UPͣx<-)q{33:~j=:SbLq>_;:1!1O iF_}X?z3yL O_P: *vC?,D뮺[SEĀ.i-O̳D9oiI#L n/?-~orr"dѨ)N|@K`ce/~[`ŧT-'w-dBއäk` Qkg2HlYm22=Ʉ5燔 ¥YGů}v({fCI:OXc8,屲$gz oE|m*'̋ddSwM!8Zd. T섀w^x`M^5Áf NASvV– dZk~5ܠ7 GbYQgM{|{z7 J凹-IptǗS`+߾FleL?uVS\@!2HFP:Rr5%v[lA/\e?΂ }%OUV3"_Rp=Or1-x*F >$&d-˛r~P+JMkҙ!wO?MHK; W"&pN_qk/qq|)_iTv`n$p.ܳ틿s 35,6pX^qG7?Oqً[竲S/$~15{h̓։&XdvC:E׆4 tzh֌&Rlq ar£f#Oq|a\`O\}Gn3Ƌ6r[7(Cta]c ޘjxl&`M; ,k2XoB N.sCg׿8yKw^m*vWe&hgYA[8k D'}q* *AҰ8#XmozQ+Y蒶LI`=V*eq b#}.UʽŮ 'ǨŽd8^\dQ\r*Ґ5 @eCt`V^FkRbmZuy.x N2 ?MlC•FLy6Ln[Gum-CopVq1hIzY ji7RRqv B6Ohє=(B!"Yj<_; ) (OS~P3%?wXQ\lM-)vk _O vRD{ӭ##7tNR!9k1,z$WWD/3ӓ6ϱXݓ+CrGsPÏ lْfT*FDaX XCP̡ZsJuv= Jm#iɛC%:PMAH[eEea&`1%4Az&ohpnW|o_0mIUN_<e>~:MfN;h)fR0gUco!I4׋,EP9ltffwp/K0T'GmUDΦ(J35.Ie>,Gf$ߙLE.|Ko:a.҃T1idYu.‘j"2WkXJJ(x nAqpc\ME (o8}^\QꪦPgst*;KDMd1A.kZN B@GÞR#yӻXl);$K3Z[^)}{ፂiw@3d_\$Ӏz|'eSK~xvyqJݐPN%%z$PiO0ksbW|ҽ?P0j1-1Hsjp'\ rjJwl`䰛FO½M@P$A} й[n!uz@˵[#3lm㊝Pp!#Ύ@1.Wr&*+0'l~ſZ 75.^cG.RtcPLuli ĆxsNi5]eIA9-$aYaNnLZW*5laZE *V4s6}AlxF5|A\ \'?y&@ H%<vPQ}]xŻrFnƃm] !5Qp#!yIcbh^ MwZ1̠it%b,@CYlWC"0Nn@`'Xl@bkzMDQZ wifۘ2f%˸EN75+bV+YS8ؿG΢uX;{X7bbya`Ɵi{p-  _Xod@7t [s,O_fsYܝ"A'?^Ds[6AT׊Sf'IJdtyc@3uXoC'Nz5* Ky8-NC~Qa+ aKrʁ{ rt!ϛgSLFk iXB[Wa[cE.1qF (>--`ENE機[zlypˢf'I-U1uάq i̼uA`}ʃ+|"yJjq^u//J`?23F x4ڻ`҈l("BZc18C` ws]a,4#2M9]Xe9֏N+ˊ-R΋d ͆lyAHPpqn=|+}OU0;/.F h$Tsa +}y *98x}馞 r|$WaB52 >xS,Z3gk 2gUx wTD98$%N]p3$VqwP+ڷ`)ubvBpLvBj^ĜZ -4w )Ѭ4z2Ơ>x q3Jueˑ|7D3fGcTX{0GKX\9G @GBbHXݵCjփ/OVj&:QA7I x ;fCyֲYDhٳƫ+Tw鬁^`@&{}O" w4Vq>O&bٜA߀ȿ!x^v#eXx&EH+vʌ ypuuuRq(I&g,A GSY9(NI$Z*XXǢSiq^퀰*Fs׿5{o(|j8]hV34RHS䜯o2R5 j 0(9 f">w}Fc|U)/a](ވF'f4 2VC)_5cbP{Ý#|Jp*W{$wa27/)2CEFO:!(DyC$vhS,a f-L賩<݊@%B\}N&:xs_=G:a'y'u<X]87C.oYU9z vii.+G`q{&/DVo*&~yO$4xHyJSbWdĖ?(4mj\jpRmH B.s>hLY⋕-t')2ث¸R00¼DYmQ73fvC?zfʝB (@BwP{ YGtm@tү.˜%6x WTG}Wyx*7aXd@~ ne4x؆-9 +{4%m9{LvekSB{ڇ:kpss &5}loъ rcvUf&^Vt#/';/܀ QN;vm _LެѠ;=׎ZN!pHfNv 2Ex"Tr VKc@Zf_ /(ۧ2㚶-771Xlc2o MNalBtc&"2gŃ@^0jv2#LRHhvZ=;L)mE3.LA kgɜ?~TTL[Kv@ plq'kM+!v-`@¦FN@zTÑ cnJ`]/v0-#%M\ˈ6N3h-q#N_MۏF,6OI5Ȋ=;Y&jc=p.^[Uq3l=]iY3!Ӯ[\hOtV3|Va l䑴?ȨEu Fs'.EFM1r0.lap(+9 ul[aJ]yۏt9 ^?Her a[(τ_F>1ae9;LO[ˡHF/hv:G 8Ӷm 0 u2Gge1yP',jR2|a+̊j&U+ JĆL83QOpzi!NoF+_>41{IϊĜܳYțjd>9"8[]"(qDG(ad\1'burzޛր-8h( :;Ip ^MV Ba5CL/qo=`EI~#Ap@]cTL*pFUڳWk#U$D`: IQRX̴h.]|JdY Ϲ< 3-;ƧW>T2} <߯0+]]qu1MzݛO {j`_,nNH\kLa`)@"tLG`:d$Z@~2[o+%Z,Vb@F2z֧ta#swg}FyXPVJ$=̍XcJ{մ49u0A~}ڹ Zfzc:!3kBVζ[| qmR"~nI? HO? RK*RI.K$4xj(V\B-BBoS"'RwVjO"ʛe1|<~; ߴm+hxHS^{M?ܵBY),t_b~T^q2$UO\m+ly4yC 4iT>h ؞,nY7?3J-w1Kg20_ib' t6H.Dڛ+S$Ϲ]HoCb[F9tvՖMXVh'=̧?^2 dS}C/Ѓ$%d\ɚEs$DNaQ j5?O.X4i"D4%;58O/-m +K:A {61.isESZd꺩=J %6fMg`!Glvt l*A 9 #kRqmmP֏a!`n?.qiHM#O ߑ 0@u`VcB\{'.+鮇T};[eZ2V/EUe^A4ে;0z;`wZJwycną@qG:* na+*xBFǏu$d@h$"Ҫ'j@ҟ^&ɦbZHK#%‹ %!;ܙY@%[l(Լêbeug (F=ڕu$28vf6NbCKCESPHzL}L%'iXsL? f[jSʵ= ?ZTjhTŊu ~7yFv;t+yٞ]jƢ6#;CZ2&>#e wNJ+;%,/1 QRLqadpY%9x ̦ۑq&ީM)l0Kp15 &nYs1&ymP!hxu,o54iӈKݻ4U@M^e]8,mM-aƂ/CXrG+:1ov; { &zr?*fa;Fx*Z (O{:zY˽ż؛Rd}x\37d,Hu vr:" at m]poͬ>YQN` MIsE} iUBa`,AT$f _sڔKh/ +ǽ-'SY4gϠSo;Ŷ4QH8 4jl"OB+m&D0ϩH,}4/.Kr8XZqPDÖv(F8+}/5gbPɆMҳ#=#&EͶY&(E+t2@cuiS发]Key q@r%u39<|Ҵ nWf X`9I h ҇f&<:Qes޺G`5Po3-r!(c)!9qxw6h1O*(8P7~^nW^ZԐE(f+sզZQG~K!tD:0b{Qk^B٘ %JBa[PW?ꐦlj8BO,zFDޯ9qn0lTF+EP=3&$IiBC"Д"Z*5rRa xHB҈:cgyq~ }$x#QȵəBYw~Lh^X\vMgȒRKneNa`2/*ӽ]tfu$zGҦtgB)xJy ۤivSq=oaCWM cHEm-` ThqRЎ[l&v:Lgِx“ymz}sJX.[f"Ny̎~ F:l4iD6^ CJŏϐdd (p8w6p֦1=Q +̺Y[R^ȅN<ӗa6gcٷ!U_$_Uknz(.ίܪJWǘ˘vAQa#9u8A&GalBg`,2iΈ݃ljsmȚ ʓp2+d-\\p_xvN j)e=0+_ gzRo9=('⁁Řxno<,;P0+(Β;fwV+A)a1 BXa~.VѸ">L2} KYsXG=2 VpSfj@U&Q̶]XAY2tt跚O&-(!"/+馛 z9ͬi̒ChvbWm+,JN3a_?4li~Ko>gPCQM7X&U֡> e8퀹ӂ-9 alt5_i沃~JѡP Ȫ7Z=v}Fh]8FF )H_*m%e=.v4Ao]Bl܎biya ^ r?o-_"x甪34tFC^{mO]"|i Ũ|gÅ$1\ĭrP1ǴMZ<; D‡9MsH:{]]]e@wDT%w_M1*0j| P-tyO <eu03M\/piGt{zjDT'ni",.q%[Ĝȫ${wX4$*@]ٯ^'ݢIh$^:j>6r݇|z_1Ѻ j^)P ##S7D gdsF=, =:  /yN 6fTZtYi T E3x i-菩 5Im5 fN;`sՅ(Gj U]Zt6'hr/ԚڲQun\)kr4C0VZR~LN"T/Lh$B80@Ue %3}e ew8dӶbp;3Te1$ T(ZpH3Djv]1z缇3y{8}X/7kiJZyТD @dz3C+R|]5`3v}ҺF=Evw,yXC ;mw}$N3^bͅI/1ADc#B茆tIx'#t;f5by{:=}"nжbکw6mZ4}(jW2[R–ρf6w̚O:"KJAQTL0V䋈(H ,-+O6M/Κ]Ũ2Y&F:"СېȳU7 y(@4cP и弢F=`vn&ee\HGߟAL@XGoi(S>oGs_9Vvb+GO:eSvCr2 j!eg_lBcS, ?O:RKO'w$hR`Xi,oI〿 '`plX &OMXAh~[au .:{UF|Gon>V=.I.~nȓWmۉFׄQ6嶃i7R],6qL7sAgiSۉ >(' XT㿝 MJEokkDjzHV녔7ZhaPjZp\rǐB%2z/g',GV˴ 7)@ÏJ /AE,_ w[rOR~>X$%ːa:/ жoy"vVL&aY#}ItǷޙZ{MWgly%^lcr<3PD2%&șTdG/ 3O#7(#͙Yaq B96i /L'ex]MIlijugf"HW5Joh]x։=Ch~*.KfB08D7 }*.1+RR/Lmm{ADS46@1 {Y-bC&[xēT&5cFr\ u^I2+|Цk1^$s-Fw(AM ]qOp+d=Bkh ~PNܖe鐐^*4Gy?ITxk0N$ho=𦮅qͶOLo6,/wsׯ4YtWԴ %j~.8`iPr$~/Wh^]*;(p\ &Q|EQ4xXh7|_YXb!6G87+ZxAlnh 1vrjtVP5֞nQ34@ٕ< pesV.Rn VEujwAKcn7u4~o hghRWOPǪ@\(M\e,JYr.6E+P7,,8P[g.H~wql|HM%0O'$R$9ž#L :>o&K rJe-_ rYvMZK$63Ew lDS/NS,G ړ6򙧚u*ǬI n/W]V&Sw漧njXI2\+_aփ]6X5ns: Mf,l5jiTәZ˕x. ǒ$zqL3FK)T}'JO4|;3 Áf$T:bh>BR.Bl(@!6 uy{lWjr9 ]'(l]Ft}xCvaLgfhWqvv oUf9Qʾ| hұL@_E0x!2A1Voq~^|&bwy `c>"]/oitq#U!ёLv<M {i!r5FOJתplUkT'5طi"BA>!_5oϡON AjF_)b =ߦUXKd2Q]B ]VbnU+-@çyc\ad|BW_1 }Xk|~5-GݹaA:U]t̕o|Q`^ٛvx{ցBMU[NQeƺPݎa1RZ.J"_쬺70 f]?j{J3cwC&[CݟuD^;PO,? Sَj5y`]̓c!I mm}x-<>>qI:*;s'~1v !ꀹr_?s)c֦_h.7Vs Qdz:n2bxfY7;qIfz=*)ޔNmԴ`ObǂFp㩫T| w!M&!C&: @1@kc^x;j%5&{}|Kfx^ӦúF&l'[i{ΰ@ip ̦CxN!OH Noi(uۓE.Ī LpW9f 1%=X$H~jiA0ruP~; dVISS-BꈻI!P*#NׂƿWr.`޳];H~!8R- 6<ymUS!MeUD{` b)3R Tp) &-14!0~ teDQc^?7Cpɥ¿RG8Bq`g3g5&`> FiQrY2K笒p?{-$LGjkn5j> DP5/h})\oZ)L܆C.BPV/2kTP S},qO'SG ۞xX4j>DmmLlriTW:nh!\H0(927$"eB<q#8"1'Ԫ2^i [zTvԯ4¬`pUfFOV GUhB\u#Sukj Rf1-Ki\*ydNqT`2e Oj׾55sh9MoyinmT۔U(C6r^t$7BdMp)36S޹jl^eu>Ko6r{/2`9-Xx-"(*=Fx2+ sK8Tڟ>3kADY0Pl/DL>yJ{y1ʎBSVU>I 2S>(/#(Ġt9U$ ƺz΀J ~X| 1fA8ro)B  :Ŏm Wl` Gu\F|,ҿ y ކkM.aIAKU xm1t]nqb(_YAYN[+GWj3p-$W$MxC OkUw>{?un'U@3* 7_3)Roy|n-Bh@7DZᾡvbodzA_H,(55~ߥJy Z"CN[Z<O,0ڊ]*ccKGt "ʀ#XODHQnj6sjj/'A1 gSeܕ:e6Ԋ-UgsbZ0~LyIF{%QӬTn;NkQ [oFۊz ū8/@{\LO_ ?ޠfn'̫,*nh/i[40H4OQNȚ*CBsz9etP̱rX4Ym׊h}ljp.9iO;̹'tݽCK{*w:"s-F b>2MU ?Ls_n8&~a~.bRx IG5f#RUl3:OtfÕN+9"ڷ+I7JೈzKg* c-RLdYWixYטB_a{]@侬Rћ.aP!Cqɪ}r`Eyٝ6jr<;Cb;I儌:iS2T1`d{5(2iq% i)M$I5Ȯ'@ˀ&[4${FUu)p|Z1c X`dv)[JPpsҶ Q `{77ul("W_YdSc-:+#q e&LA@| ;y%bִ1AMPGRgbD! >y%<)UV_(WqSf6G| f rKE3c&|;ƕ?8!T!dH#%9 9N4U(^{4S.oBgqEFjX:% 3fHo]:A+ޒ Efgr{2!EB{양?Y`}ȁFq~*~A`"ث%Q>s ݶUtq!;= }65=,\Ni*ZB Z (S_.DET%EYSX~"\r aur@妕BvM_0e OzM՜`Ȅ|8'5hRѬv %' i=PJO3zNc-x@OS'ېOe7-:uXP 6|6Ƌb >+=XP<`]z^)h۲\(y][" F"ɹ+ѓd}hǎ%TT&A:FKUnsxBL%a U:0?ZZ\<_f.C -GBO]}BTZ-!gwk /erxƴu?]˘!ĞV 3y. \2hkRT VOZ:{S6`a*$wS@32f7+bjXy)2C*/]h 23"q7ROXw2</H!B=m@A0ulbR5q0H{k 9N i:$ىҖe yO>Bz};*+D}H8j1͏^U*K^[W =7;9].|snF83nE8 `߻Gk3jO#5jyGϨt|3ZE#8d&2fc78Lh aZwhZR&݌x,c9gDdq+̳BlTLH08mG&h3R'MN-ʎ/]\C -E$ %NO*,[c+-ؽpKvnBEE%A_nԻn6ʼnfڽ{wWOƊ#rSП1tRy/xejJ T`[#۞.' gHmf9SÖ>!Td FmvÎ ᝯPZׇq@QB>҂KoG;i#t [[Y#P$&s\"&\R, 09 H 4?Ŭ|y>VK}:yQ1ߨE<[zBݥI*YIS)(`+[y˖CgL{G@ːt`x':Mpje'r#坛ԝLߌ)VRMAݠvma۸UP=ڍen{OM]1Ad\.El&X^tF &w6lav$AWXLV*7z$2;jI7>ujz tK)cc(>odO#-ی [#=t\8H K Z_e -!)g?BĠ| FB.΃U,C{3.\iok΍sK[m:&X+^ZR:~^CRoґCy%#%]bnрfʃaA?!Hz'c8?~+0z{ y^jPV5,+<%J%:0cHH 7{8J< `Ts /X$Rw9*k:<|ov8Aڹu=gmʊmg}*07V?3^}[k,u\L smJu`R<ǓF!(5yX|L9"* {{X֗K7L铱Hɔs0K>h"_{/%:AcҦnA_- ufrIWe̹RG>=#hJή>8y,ҒX&b[g6F׽Xn:-0yt8-b}˥6}\wg;P)cyXzվJaX~@Xֱ\0MR#-}oJ,E2} I89nVT_<5ƪҿ4'X lpckv[~̂F*oUO*EJqMP^-s҅21>de IP1zKe-@DQuc -+t.0D:Rj4ynER#j+6\/_!YoQ?9ZnSvM 5y;SB7w«nʝJx|jSp#쾷9 f2)6(hY[31"*1d1ė@}'\zj4oN"&5M>gJ%=ϟͽiZDD|Q ~,,5ͥ+(6\dZ6ʹfX˾ Ϙi΄4[: *VCza{Nz 壗R# /TU|s_?Ae.HKq m0|f!i-JT ܇ceg:8%=T qL=MN>ȅ%R)IK;JK7h8gu#]"Aط}2x^=WﭚZn LTgJ-jЁ)HGMa@)e-9fԊK*ֿ(]܄[E$dx)qaヒYdEv-^gM|*c=.a;8=l,53< Mcs6@`؁Ra逊ȧ "lO>uN!GI6@vn "Nt},B tG,Rr8|ǯqU @x~c A® v0)xa])hho$pD}I8?pOBFݝlHvc_1V5͊rxZ I6a6s/evd f9 nE}D t t@щ_J^w<}Y WxP)="ô>=bh"._|f4 gnw|O6U-+v= |nH=}JxȕGT澒XNLB .^ERK?Y(dCAMn]Q?Ǯ ^sI{d^3v^5?ҟa2 hf-F &(!@/D6C o7 I!7X 図/*JA.ݎ^IE:9:+"/;Һ&%vz͛ ι۟R a ]FRbDoStPҦ@Zג "(_H{IJz]( >iȢxeGNZ}O(H"5 #r&oAj5z:*X2®t#M;ehuCX4mhK6clwvȵ}sy$; ,W P-ee8Ϩزۃ%4P|[me p(n Y֩#ES~5]e|J¢7ߨZH!rl!p/.J+4k,J/陠0uK`cU`G̑A,>?+*NuPd|cD&0jvitAMXX 7Yӂ,E,X@$fT pLdgNۋ>l>A(9ʔ Ԡ/rRbQl4۹I.>GYwɁ˦K<=U&PsJq-)B7x֠to"謞{ub}S%a:Fjдp$l!,Ȩ5;]ImU@&D{4 ?^9 09bGUNmu%tjuŚ m'$(x~t?Wǣ<ݣn$\a&\\Up ۙ/C{_N=1l8@8`7VjźLN+DŽV0lePJ`&,K 5sSeaJ̥<@>]YYdOܧk+Pӣϗ,/-)[\r}nڽpEFCO$9v813RآC[CD.O_ȭ3erࡉ)̡Q5:M2ĝŝxhmж>6L  =zFP/1Hې> I"Yi6 k׃^`-u IHu`ڪlZ%5/#Bq޺9v6HvwDaP SaHPzubE1Ѱz$Q!=);kxs`[9a?d-uUP9Iۀ$\fcs]~[ s}|&C#w}ܕGwZ&Zy~#KV7(M0~[@Gg4.8n(+|櫍LQ+ai^*\=?+sb8g^A&%>MllЙp[!0|W9$-sΪ2z9:?]Д;R necq(8nچZ ʅ1kmϹz|-qԅ NGʀx9,_UfGؽVQRvp̴7xU hPL>vD;Y"/6" H 6bF DzfO{j͍F #2nv_BBl@ 6Q/ 跴IGVpM]MdTECOQG_/ ,DSCϲ E6(M.Yh3y`*qH_ƲmjkXvY 8˃Mp 1N+h諌QdȂ%QI0H mW?\NY~PWx]ofߊ/LcN^|:[Jua8EB?ɒɅT&2Eb+-wɚkZDȣ>ǣƄtr5ZrKwȫHW7܈JHd)@cl/@ =4oA)uh fqH-DA6Y:U|iq  M%4?F`C#b6f*Fw a%RG.7ђ{477H _+mI݀ փt~jt$Bj0'7-1I&hA%?=3;.XC\12SvRܾ5vkX>)"~*=]QGxF3,&s F\r۾Oq{' PT Η @ǡ0Uq _hг%bŒ&Wx/nF3'cE lwܖ:fd|օ= 6N^1^Q %e#S?T}WmL"aTTnwY _ JRJ'*GP׼@IE|!,_m@i_^ue:E]]~Aa]gТ[tq}Iz|, 50D`|@v9$у D D^&38.Oi)*B#\џs}LyTgȱu>6az\(@`ݎg~vudkE0҂ጝƊ ӣ 07oyam`٣ԧ C`^[yeS"T+m+ }w3;1mZd2e@147T'0A@yx(Ii_!>rٕHVī(KZunĿD༩W֊b%Է>WVuZֽh/bTG%7e QKm*1ƹV!?L=W]vM cgvn#DLGI$({XSs&ChXVXQwmn!JaJ=Cϸ*'Ov&kMLNo7jَCQ] d#(jjs^l†-xƙ/3K]9ŕ)qYd:egzKP -Gb~E32uKiw?m鼫YmE&A="-Iy[Tn4!;FԴ.Rc(>Uˊ qWQ m?=|!հgw*N>80ZqfXuRV vxBY_V k1E @r~٣I&r=[)@[Gs Ƃ!䦤HN;;i4/\ ZLq+Iscs+w1XC؁wr+ZiC#ODGBW ksė` \Ctv{Sxkʄ2weQuxc剱b*s1): ^{7# ]mR`Śvdd26Qs_lc!_\ c4X)a/a6 iG.| ld<+VFuԪkQዊٴ|K`MT}7` E}oBB:ER1*ːAްWAË+.DWxuOa͡fˈ4dAh)z#ΕTvf㾹v8\*+1YVׂa5K݄5r lX_O<;r`j #(ăg%(rw8=ʋdh1Ma-OC2uG3N ~\l8H67 0"UX)F{'O<͏K)"E 7=]#L֗A_Fv6*őJ帊8S:܎&o c^g &ɐ>"Y>R0"LZꜨQtKد̵M)uH\fوPLzEdtte;r$5] GSj+͗ߩ\ȑu/&jtB4XD]5^FeUL6|DMPK˩GYֶIz1nƂٕ4sԹ&:750!/T|!UKp[{IP'5<1㌂AtdQe#T#a$> 2 Cs5ȫZGiÁ$>&7B\5ha.e L66G|ьϵHF`'ͥn2tW]e#[K5i ŝ?,pItPBPe d>au;Y/wj IAP1?2 2 \$ҿH896#͒z:&K:ס_Yc"6-cJU΄)[]indŲn5q{D}.6r26z? yXCV"DA,>O﹯2) `mF.W`jFgǠ2נ@I'>%lQ5N6F~P꓈iaZIW'6:kؙ1h%kۛҥ0W ZRVY{2A;܈{HژfBC85K7[O\W0ڞ"̍erFJǨq.C"J86g Z{5Xߝ5O-[J' r*޾LW9SSs uS{o!ψ#z?3ډ}yMrk`$]i4l ݁n5z]~Iz//캝d=L-G5qo_+~12 泅4]#f"t*ΪMJ:Ov$ C~? (IRu/ԓrxp K5h|'jUR2od@.N1ܞ-BQk|origFi*[2 |sph44&<,8:=M9{p4>l]@q^IycrЮ+ 5Fw'h4,N@jp莛esX3So!s#6P*S$[Ȫ?#|$ ;f Vc22Vjh b/[ D8S: [VzP,LU~+/d࢈zi GK^#CY>YW -'4{]!$7#ю~2 hδuI3r^a䱁$r|;(hpʲu p%$;RY~y78lG&A!5.J EpvI׬`z1Cz/ZpZnү_ٜ㩧,) ~ۋٰH{sv9Ss6eOP(6G 2 ɯ7ҋ=@Wq;pǧM&Ť5Ayk@RQ=.9+! B[EjBcaa?{kFW18 ;=Ὦ(Oo!V>ǀ6ǖ l)}Rgm.@ iSrX3$?uiY'dZ6 +ZU\eQx:x:J| '}hO4#qO~}x!juMz= -ߒ)<ՁG"h 7L]fbHg3t Ծ=Y-!P(h1| NToiLi%3k<%i!eg~?+HDJO3 lف<Noa\GrE,Mru/пBB.TU@94-?:;2HDCLQJT)Һ_9~kpK{6aLqm]~{ɯC4jV4IbS6N+r8gTNOk.ei3/Tn UL.o'ݴBUƜ?+"' {ݥd &GV:X f3CUVIUL_] ŸПҬ FIcPd@ 8Q(H8a5%1e& QW!a@iz v8NE\]Q-F8Lh[ FP|Zݤ3IqUU)~x&呭)APk/ĩx& Aɧ4)ɻ6OcCۢ-t4sMz<ʀS O6^& WGÝ}_3'#Fhm:Mѫ-:pgޙ0aK-h~}Z$کo2Ji53n U9KGdtsI|5X0b: Y4>daPY?h4d>֝ȳM!ٝ\9S:$TnFiVшДu6n?@+DG:FU5# :ͨ9CHxp[)ÙWVd?3Rի&M_zK ~k;;uYa{'{͟!NKLLFAuj#/%|+A!ѻXMAfD `Pɗ<@ ʰ6mcM"G>~[9݌>;u3FV;E*|qy'Q<[xVg]?Fe0P[Wbî~V9+kȭZn9& 71 @J~3lzbbbueh[2fab>3JϴiMv_+ yˣ3c!-,j?蚩A >\l\uURw8w TOsxQݒ^dD[JY)޿|e(88DK{ܣ PdICM*t Zxb[R1GSM}JoJ+Zi3$])%VekC4`0t|0 ݁Z)]w̛Pϣxm45d]VH )^jDn9Ix H֓RAz'"/~XX/09x/PYzpHھ86yy(YjXnwl/.͊m8o`g0eˡx%f&H0[{7KbtE$"B7x&K @VJg=Y;B;D Iv>S/)f|dl899˽/'ʘb1LR~@#wǍ@O6N78hG8P%>#tmµ"JDM >OMWe}:/U2 |7KSpO)yk;xX^Y.{R`ZR {~L kG\s XfuM+!yo?]q͉_vP)S=6G-\[w0%Qz86Xz}*OMj#!kOѯy ^WA鬯K`B 2 so#o#ڎ(/3Q~ay7洧8$`TBUjmeH}Yj(\'@~.|_EBx#.l4S0'ýȫ֔JpO-#; fqg%Fjߪ/(w#^,Z`.fWVwP[+FcDJ@忾Wt鼌mviDx 03>GbatBI ҃]qK~Ɠە4wMFީ JǟwƎ@I]VSo^ݵ6\a[! !#*^{z:(C݄˖f~Rt/|-ܗ"QNFz3]>OcE+H6s|Ёp6/-zYhZSz+yPfӼ>rwv*W6mR zE"ۣj]^Onk oǘ XYIHfFLefH{޲z lSFt ?9Ƴ8"ajmoSj%fJr {_ M.$ߗ$OF1?茿~k IЮDSb0+!VTj (&UhԈJ@60ZηNn(} )Ԍ;T-CH5o/{SOntJQ-*T}y!H9G@K*^wqaSJr<3hqtI*с`sA/P39b-eVbIp1#7R1)Pӡw\L}D?0b*U*~iJ,D\ta<ڸ1OJ/R.з19euxx3kҭ-+Q!ѺV̄F/wkj"#_9GzQY o8ۋe2Z_}Y!mzp.\fۙb6)[b[~wv2"5ztrN:VR/1dH؝`75wfQ9hfId ǎ )TYu}FO~蚺I&BIN'6vꯡ.=S{劻fh+"UuZӻcP3J ^rD0 -\[햠^ȧ!ܼjaClҨv>DXs eɔ 0'#L BkKӑ"r:=[MTɧlyZdULH@/JM;]fy=tRKf䏵)sKp$n'ivP!b/h:R"*ظ)LVo\f6igtZx"򃮔HbKwRr [@wIi=w"{j(n !^V2}G)KBu4!_ B!ѪetUn^6+mi MQLjMh(3f;OHO`5޿ eWtfgt.T9C&lB@܏L&!cH-e5Ttӭ\qŚz*?h<.-ޭ1",P.0氭tE-{V6P|n:%h"]i CRj1ڈrGY A3 =6hI@TbTyI͗$ `lFi߈!ko6".2􁣻9,pLcdFڭH$-?ۂtrt9`|Mt>S*M)눌S[ HCf~hryKMȬw"R@!/;\)K&խz(JPh= }{t іP9V;4llZ8Ibr:19hAөzhrS|ǭL}3~- c0=A]p DKeA5ޟ㏫ERfR|A!=ߖ@njy+-Diط:o 5& sҤ3qBsAB/bvL'6c/3DA^X׆]+y}-8m"eM)z ldPV8\D'L`ZfNV07 x/.LL7Xj] X&!:^溈Bv!O{k7yOc|Y-wQ gJПJ5ˆXuW'pX-3hsYgHS]9ч@o^`(*RFw7udW‚$ GP,ٸ\ܘPju6&6(`TP+7^ߍ\)JbLÛ _7(7u9SP\X=ˮ$S$'CP֊~j Ϲ- Z鄣}rTHa ~+0D8 F?f-X(QUFgE)Z`b'R-`9@#0I+G x 5FQߒ/9+dMro}H5Ot f/2Ū_cǛdkT~GZ]Y^SdPk+iؓ8=:nyW3&P^m5rxUpꘌRhe7TNE켳-[yIhEԉ)#!`tg{t!"j&`<ړb_?Y+KXGo(LM0qQT%d7-n@eiph*1Z}F{2.:Z],_V?KƨD{ l&=) r*sOKpD⍴5$-ө!@3O}ֆ1?Iߢ>֠yKp_lFU5S\4W|Q?,fpc dqӍ.9J͕Iu|HDk913.a?Z0HI,LΧ  sAtY5,x"\/k'v{f4Ysnr2aU8zƏs(m`BKYLQmΞϤe}y&1<a+"GƁo6 4|ﳘЂ@7d1~ja+NʆUYc6GȌSN魊~ )}mn_Ɏ@@ ڢpu^o ڻ+!]WHŴa21ޡYXz0v+Di: wm;/evgzi1ŭLЫj=N:TJd]30ix C*Xz ,77،8uE,YbBR02؊ڑFkj"MF5"NKnU*GBT&/L>PmO%q&dvpFakHs^i,CH /O7RO@ vm$@SZaTN> y䦬snG(njM/|K*P4Qг% M* RAu롲15Kd)Jx7D{AL( }*ÏoG94+ݓfȂ'AtI.4{g2e;gcGdD]`2=G3C4WS<'b+"+h*⚞kT5;XÂ֊߀laOp~~-jof)o)C78c#8Izdt.\mrt<:Pt"Fdp=^L<8΃o-LX\o|\>VjJ1˶ Q)ĺ*ꉿG>%2'$ᓓ'Ͽ)72F.nu1yVdj+um;_E*G" OZE^WZ'%4^s@BpB#A ś3q Df}%k~ݩͽqS==k<{f0ѮO7ym[-;yޫȢj[!EDz2AQ൞154AĪIѫ>MDy, 1HQI}X@ jx.~Z+wU d6],%ᝆ– b YInN8T +vBMoU;::SIY7 fzĆ0a{ ׶2\)' Gjmcd_g_]UnA8IިÉp}U>jFL1l}̢hڨ ל_Tgp)e5S/r!&xQ!dH-Cg2 U%?4=//b6_^]hͬUSdeDA n%sU+Lw4wWLr'B%=yD27r{7iث+š>_x%Zۃ㪈+HG^[ziTg ߖ! GO飓a!<#x;15\_yG>\l@#)|&פlSdGZkd7AhZN^HOqPNl g4| C3&e&pim&eotȹ8KSҍPD˷9YiS*bh^:0?~J| ܗ ¸)tr@"H. p?xTPR%*:ZcMhI8ZM JS-⒜+幻}WbH@8z Cts(6K(d2'7KX^em Rwq{'60 uܖ$!`nԻ ?G(|g {BnU9F]Vn/eEN]_䨔e͓M z8Oy)S>4ٌ$R^#xr|7tcnv@,hS录mTX]N-jWdu{[zݙ!2SP8gmq/(_:2ERG|_ /3'<M_5KopyDem_:eHhiª?b/Ҿ5Y5_3fh$wf}jD֤ǃky$J tiS,˂P*BI"%e]EmW LUٍĦRMK#Y tzL!0S @^^j+{ 33ڼ`\տERlά(IJ-BQ1m3%kc|Ә S\0V5O9;wO.-Al[tqLD:B㌩3i&P \`冺,sdb95g7I u*ܞv%ǵx;7*! F194 F?ŸDYas*lxsJ.gL<j섔5Bsq&wy'[E]|N~saHBh_РbL]$Rn~ (3Oa.ǽ|=p0^r@zT'dFHj@>dtv$y:l= ]G0*hpMl^(4 a4fLmpj`XJ3x(  UpV3#ZopcHw-ҁ~lªހ!X/g֙JOfMڗc/ Yzf}3[aїF^iѝ1p#?.UUm*Dc8@G9Ջ^,־+Mo4s31](a0 6`/ "x~ RcnI㿊8 g-CZ0Zs 5v5XhSm+v1R.k끘r>h 0b?C]*!yM.䳼JIU0)g]q?Tr%z*gMd#pXȈO/xs# BMkLE=Xd^rsw8XU|/bSIR %rz瓚=Y>rAg ]:=PO5m}J fqH}Tu?.hB=\+D8 hf'h牍jt z|^WDm߆7(v:Uw6]Un?^^(_ y1VUNl.imTa&5 B]rY>U7@ ߋ̶_Tu a p 8  Ha"*8fITI]2r櫖@8˥ka A('׉̒\;o\, o3:fj6kbGVk H>0o1j7N`@z AB:,^3QBÚq-`ҹg=^EEUK~5mUձAth"D8:VR-g&x,GE="c(Ρ*$*=Yn{WFvM8 ^TvV?&̈ ]ar}3tv_9%0qLƺܙ7ICU{sajמ1㿪}9hK o24( ؏s[vQQƆtqJ~lQ?4&.3 n8f/ރxMVcWՀO{lt}Eso7nJp?Q`P*܊8xxR^-f3#'MR4Z蟨%sgZbw"2c:>C[9ȱDzoZxcDs8t$H&D+zQ e4j~auF|$BsP H PYQ`F21A_Tܺ&^c\|YÿalWA&j%NT3 |MCe";LjsRZF= ~/-VVwR CJY 8@kiyݴ/&pcP䌁ƛ#!gO%JU/k?$ȉbupؾԼ*^ (_ȨAe'#],N(3' 2bQ4iO\P;Fƕ ţp,$Oy }yoAe=rʩh;,D{chL9w4wGv@{hQ0rr}moX 4/^ sF.PqiVxuҕ^4SV6xSpz3D.D``O!Fȼ#,/iigmpHhKW+·),NWi9Joi *XIk/ Xb&dk-XdU͋(lDc<73$|Ԉ a9-0favoV2G6Æ~Wpan585p,Ntx%]EZŭ%k?N(?u z>4,vkX!u/4c[vf~/Q$ n5Gjgx`ZfCG,>:5xM͍L|kؒ'{SRР&_gvMNlʇ+vο<@K|dN_>暫uQ2됕7sH0֯~#+BvhczeAeoYmqx߆xJNI i-nVkibٕLd$lpͧu3Oׯn4ݙgG'j6-7% ̾WުAkiŊXL+`fpb$gGU,Ȓ0! Rn+щVEUB*'6eװ@%9vX|3yOɈ ?{M$A}.Jg"ɓ}O7L%#Зg";z3|ݦ Qu"EE_($XU(Ks(.)+ž [*ez U9PQx\ *>l URͰyb>S/zYrd{x+N5bHW#jSHIb`O mDc v,+*~DxXKX19Xy %VxSs2~pQp* GJz٣,g" ȗ)0̠A_4Q霭`^*V ''@[qyP휠^RG{ -*IJS%ƁόR36b r2x^r"1kc$cRU,$9Q/@ZJz|ZX((\.jL? _DC㟧ìWO氦Aȷe"`C! o#f*P`p&32,*=S)I7,02kvҤ)X Ap\P3˹ܵeTýLsF;Au  ]:;Xļv}Vf];/t/IL)6HfCK7I^ +}zz&7vK9ArG)=ߢoqsa)4}ӨԲp='o r6# 0WAgRg#&*e9mbOɋ~06 C1xtYI3~{be΀ψQ[r&Ei'(NN57zp(_{|Sdۘ] y<{cztt15"4B6x_7Ah7n_BPfj`RM6, Ƭ')3@}8D-*Q;{WGstݦ"'epOS_hk 1)x&Svz' p]J\x'AZ:&1Y+wkm{Uoog֩A)| z7YcOpS3Dݮ8~MɐCTfcr.&t> |G+z1c|f{$0ڒ_ӻM0~[a6fQz(^ vdwDMY 7RWr˸u=$^ߚn g"i9)PZ_@n9$=l0S@{bppMKE`l1!ܮǗmډ:"&2/+N òR! 謵 ;js0*Ԁ ]g`&>&9pRU&2-JFeN<(lb %B Pa5f.~ [-npWo&AuuZ݉EhP a 0psGmL:gj<RM O