sssd-dbus-debuginfo-2.9.4-5.el8_10.1 > 6 6_6 3!pQp)Tξ7]mtZ`ga ]mtZ`׸U}jN6̏ G{ޕȤOey@=L]ЩM]s̏ yU+HT xl9kHW^NP\,?$=ٟɲjiـplLJDƔ4q:Hb T_<3&ȲH̑S{d24c34ee874b87aeff3b9e14ee15234419de8f1f5ee9c59ce957a6d81beed154ac63c643a3a4b9c37d99457dd8865732d9b5e26f3!pQp)Tξ7]mtZ`ga ]mtZ`hS#G[?aN1_Ty/"[WTMlyG+wKRw?2 ÃB_@w. 4aߔB=HWUjsc|7|VOM $0r9~٧,ykN^wv ۰$&J1׏ :!Ub^~ =K'C}PEߧ\2ғBṁv! J{onb+Z s6̨:Zlj]V-E\1I EJ,?.T{fܾϝO\bP#j`(ӂ =;ٗ!/.B[oD{|Y–SEWS  kqܡ{3J;އ:  CqzZϗ@WmQ .'6~TRH $ zOJp ?(^W'|ۙK\iE.d?~1:6K`-G7[g㟝!h 8>p>? % M049?F dv         U    = j ~(89 :_G H( IL XXYd\ ] ^qbdeflt u vw x y $=PTZsssd-dbus-debuginfo2.9.45.el8_10.1Debug information for package sssd-dbusThis package provides debug information for package sssd-dbus. Debug information is useful when developing applications that use this package or when debugging this package.gaeord1-prod-x86build002.svc.aws.rockylinux.org 1KojiRockyGPLv3+infrastructure@rockylinux.orgDevelopment/Debughttps://github.com/SSSD/sssdlinuxi686<R 1AAAAAA큤ga[gadgadgadgadga/ga/ga0ga03d3f6817359b2298940e4f948620b15a306fc2092b377ccdc8215ba2cd7989a1../../../.build-id/c5/425f3863ca41c18f29931ec5b989f1d9d90ad7../../../../../usr/lib/debug/usr/libexec/sssd/sssd_ifp-2.9.4-5.el8_10.1.i386.debugrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.4-5.el8_10.1.src.rpmdebuginfo(build-id)sssd-dbus-debuginfosssd-dbus-debuginfo(x86-32)    rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sssd-debuginfo(x86-32)3.0.4-14.6.0-14.0-15.2-12.9.4-5.el8_10.14.14.3g@r@f@fGFf! @e@e{@eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.4-5.1Anuar Beisembayev - 2.9.4-5Arun Bansal - 2.9.4-4Alexey Tikhonov - 2.9.4-3Alexey Tikhonov - 2.9.4-2Alexey Tikhonov - 2.9.4-1Alexey Tikhonov - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-67671 - Label DP_OPT_DYNDNS_REFRESH_OFFSET has no corresponding option [rhel-8.10.z] - Resolves: RHEL-68507 - sssd backend process segfaults when krb5.conf is invalid [rhel-8.10.z] - Resolves: RHEL-66267 - SSSD needs an option to indicate if the LDAP server can run the exop with an anonymous bind or not [rhel-8.10.z] - Resolves: RHEL-67128 - Excessive "Domain not found' messages logged to sssd_nss & sssd_be in multidomain AD forest [rhel-8.10.z] - Resolves: RHEL-66272 - sssd is skipping GPO evaluation with auto_private_groups [rhel-8.10.z] - Resolves: RHEL-66277 - possible regression of rhbz#2196521 [rhel-8.10.z]- Resolves: RHEL-39085 - [RfE] SSSD Failover Enhancements- Resolves: RHEL-33957 - ad: refresh root domain when read directly- Resolves: RHEL-27205 - Race condition during authorization leads to GPO policies functioning inconsistently- Resolves: RHEL-25064 - AD users are unable to log in due to case sensitivity of user because the domain is found as an alias to the email address. [rhel-8] - Resolves: RHEL-25066 - gdm smartcard login fails with sssd-2.9.3 in case of multiple identities [rhel-8] - Resolves: RHEL-25065 - ssh pubkey stored in ldap/AD no longer works to authenticate via sssd [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-1680 - auto_private_groups does not create cache in IPA server SSSD cache - Resolves: RHEL-10092 - logfile rotation for sssd_kcm not working properly, sssd_kcm never receives a 'kill -HUP' - Resolves: RHEL-17495 - New sssd.conf seems not to be backwards compatible (wrt SmartCard auth of local users using 'files provider') - Resolves: RHEL-18431 - Excessive logging to sssd_nss and sssd_be in multi-domain AD forest - Resolves: RHEL-5033 - Incorrect IdM product name in man sssd.conf - Resolves: RHEL-15368 - SSSD GPO lacks group resolution on hosts [rhel-8] - Resolves: RHEL-10721 - very bad performance when requesting service tickets - Resolves: RHEL-19011 - Invalid handling groups from child domain - Resolves: RHEL-19949 - latest sssd breaks logging in via XDMCP for LDAP/Kerberos users [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) c5425f3863ca41c18f29931ec5b989f1d9d90ad72.9.4-5.el8_10.12.9.4-5.el8_10.1debug.build-idc5425f3863ca41c18f29931ec5b989f1d9d90ad7425f3863ca41c18f29931ec5b989f1d9d90ad7.debugusrlibexecsssdsssd_ifp-2.9.4-5.el8_10.1.i386.debug/usr/lib//usr/lib/debug//usr/lib/debug/.build-id//usr/lib/debug/.build-id/c5//usr/lib/debug/usr//usr/lib/debug/usr/libexec//usr/lib/debug/usr/libexec/sssd/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m32 -march=x86-64 -mtune=generic -mfpmath=sse -mstackrealign -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2i686-redhat-linux-gnudirectoryELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, interpreter \004, for GNU/Linux 3.2.0, BuildID[sha1]=c5425f3863ca41c18f29931ec5b989f1d9d90ad7, with debug_info, not strippedPsssd-debugsource(x86-32)2.9.4-5.el8_10.1utf-8100a02b46ca8f6838ba8e597765a2ca6846cf7ff0c9e624b74e23ed403bb3e1f? 7zXZ !#,] b2u jӫ`(y1{4_c=_SO{hn#܋*߿5:ޢl,6ڐϙ,P T&|ǕɾڊwǤHTt|$P WYbr';@OJؙ@K#'d^ ECU|Ib4jw$on=lC#ͨe-G8P+^EJ}KH`۪'"he~15`a$Ř~v%., EjHQQܤ5\Ȑx 44ԉVD0|tNYv)g6ӌW@iDdMh3eDAY%Yf@-<+P* ~@i<#)IJK=hƔɖ] =A)wP<2^M^ĤcuDW=ohp( fq߹OeG$˺P΀AQ[Z6#3l`% @o+}Gl%ǤXrW\z [aOivaY/+ZӇUZg89WQujKxLf4Gɛ(9w1؄L ׳O,ߐiה yY_~qk4Cyqt7SLZݳ%4$'<%MW>\G+ +s8t*P8xz˱B{W-x:b:WM°QԴDW.EW5q?Ory7LB ѱxE-7T%xI:lb깿]L腔Pȑp\tgWްV a3yF80,E0 GLj_H IWGT2,mmu_OCN4P'[?f[z֚sSz췕ѥԝb"{=d6 Qg_1M}V*\ ±DHHC'uV`|Ĝّ%mSȪ߹s@,Y὜-? :>{sXwR"A+&`%{c-)$Mn3> 㒥S?뷨M(mɠd *RA0g_MO,MN^V2[ S5W+vejwULB^_chcTjݙ'4KR5d]+y,}{*Zz[^.} ̏!L"͡X>3*ZiM4" I|Fl}>wj13]c] Ӗ[(d/[E +_q_]A@~BJ}CC(W)cvMUm0ovrXFNVUD8a {Wg;2X ԃ2b󎿷& `C?aߟ6%pXU"BTaZ~z+$OOe+MwA@gw`)JZ$#=NolAD~4y"ߊgktMځ2a8bg83:UiJlI"~ Kq )u1&()@q##S0A?1U['3G1P>P&mЭ ¦^ҝkFnߖ LÛ J |ilόMe*oDAg}Dؤ ؖ޺rޯomxء{aJˣn<"K J~~Cg#+ۥȠh)Pl_ꔂ޲t4=ȟF:l!a+MۤTL M~Y$FOZ~c52Jo2Zo\UbF1`wheiRy[g1uciS!h@_/f4f%1 ~UDF^=d缮 \IbUVQfn)!N%In Aڲ6j`r &ɼECd!$h) )P8#jYO!GVh/)Ttf"T u&v27e­qaz)4bOr[z(R]Vf`*GD.[ή6!/ h3=\XeN;svcԹRHt A"!͊EFĤb ͟M_Y{{Ӣ8AvoRfk,aa'Uޮ\ Q7bq7{4KVp({|Ps',v;LfnS!!.# N$͟E7T(IRA1qjIejOɞ #^RX i%orrR֗ " VΤ?e)v ~53S>Sk*<9+{ }fU5͔QF(_%:0ݎT ;Gvor1~7=$3%Y]z8 9 $ Ew >}Hʏ:Sn)pFQ(T@-t(&7{eHȕͳހ- vv|V.K)s~&Εб]sc8 yFWaX^Ù2lɽ䃈"+Enur`ar[392Nqf7hv,u^o_Y,ɝ&ubәi;s 35%̵V7[9Jfŷy |:Yt7!p^v<:/_:7TS82Qq Ilb3Kl*'VVr-"}2yM Y0+kzO?! AxCҺ܅ <*WP{;ktuy+/ieqt4{YVВf& Q<$bc=x;QVa,K=_~=?4A*wD) PW01tfŢg i/#fyb6986]2 V EP|_د~k'ԾTfTN0W4szq [sLm-diRR 6]|\ l-$׾<ۮYy1p#N+DjYO`&"5If/Eqdx2U{` ޮcv3t%"TF/9{rj>qMCm!<\Rҕ5!Aٖ,[xm/ss!kQV+e ؐ^OPЉq!VǞ3ؘ9-dn!@ǔt'xOU2->(#7}8g9ű%b$ԼN 4GDgmͳIZc'~mjRo/q3~lEk/+,X8l&dNZ|4AUΌ&j9Cw8^= jŸ˨S6c%xDcB9NuJCil )`7'id'yX2H#"&q8`qcvL_D=9mV3i#y "p *Hr yW()dW\p4|JXѡX` 8EAL(W ffF|}S6b0y^ޟ!nXw9-(-*a>Amy:hDVfյ=H m7$ \Ld %{z] 'ۣ:_È$TNDy*#ޡ0ϝr_}E@dHaAZ^6[yWNUp<" .]wz:OD>.vc$ꍻ ')#U*Yhߜu.c!SY1&2-:(DBP }BPCo(JXlT(5;VsRiM~drG(5rGÕ7Ƥ[1#?)s=S1AZMw=NߗXE9$k1A E8dC#bs3>Z3艻7^/p=UbZG5Fyj6J*$'c 2CԾԉJܕꧠPg!f.~hEVv_h] 珓CD-^:NY3^D'T!ySNr:T,F2TkNWu5 <.jz;wilV!)R3YRhצ8v">f/ǞMOn}i/-1) 55KrHvگ(z)xnH/aT[;:QYwdjF́^fuϤ;BWz)0 n~c1OF@۝b1O]"8P7-Nesb0T'##MɞyA74O2\Κx61(I1V3 =$t'34޸hοɮY@ Fdv,`Z|̷]?S?чH!nB|io &Yێ|]#[_)6 Z6ArujK[=D.u-&1òѳ2xN,t=QvHNbpb里_n椛T;Ap|^Pf壩ϭ$o)[Kz)OP5Ë3KMgzp6I|/uFr>Ž58Aߴ}lׂ=aT-7]u>{{ĆWWp]^>cd朳+*1-/>>|1Fz](9щgg̉8tFާқi5o0UMu+Wl[$>glq-[ `gט^ H#M]YFBS}FKApC/8^Ҫ-n<,9ۛUٸ`'0^ut?s/h- CGm<7eSZa\'lY+|OҿWcKKͳ*Cv $K:a&*2oۙDfS4 8?n?@VeEHےD gC;U#Lv!U`ve Pյ9,!:\+<*pk9lj $'˜_SBVv#m(PKa@BYHHCJqGCBBΪuۖ_mf{Nj/r  ECM,9M]iRomdX?'1fא-ŝ pIvJB;NQًA"E)_87QXzif5?򐸒fy]_B1%gNxxVz3nT q Ċ@/st39T}W,CL0=U˭T3g' .%c7*##ܚ:Ƙ8cK8 ?C_G1瀴 @g$c2*`uK- (+R%@G[iJxFπ̠@0dylܖI8RçTC@ʱ% nь[I~|r-{qo"Q`ǽ!m,پ;bc+%a5ӿ4SfgnR8Nӥ+xP͙[W:UR&9!Bķp0Dc7h ~e|TFv}RQkR2O\l,R? ud ͐b :z Wڎ!uOJv#Ǻ! "]Aw4|FEK<f ?wϽIiԳ=Bm.#uB,Bc-5-~ /'u:${FW0I+RЗ+A7:W @Pg3w[hy{=e \c1Yaʿ\?_ags*TKFS ~Pm,lD /;#*SI%n 0U6&"r, + o8㷬+/ )7M\Ϙ`MɥVbX bҲ8d!+Y0<_rv7Drmz YF K|;Qa֓}m"؍(w,xdC$T5w tykUGc4pQyj1jٝ~3mKZOe ?TbS4OO5 f`1GH)t"_i;QM_2AXo+'t1̄hٙ0@NJ7ThO"m2͖pW2Gm8eK>3`QYl2~ ;"c/S) AY&sx_R_Q=YL[BAMy;vf/Rz (R+xEg#{1p̧2Z`eBnVnm=0nOsW,Lo+3 _/E__:dW m->jM"ZWܖf3>#r29ZP}z\|v|D^6_Ƈe0Ύ׳)F3EeO@-w~ū`g&Hm?X+c,آ̦* 5ɟ {Z{lad>þ(~yG3g7Kf4XAxXSO ?ּ3z1`zC C=ގ` 3ݝtRx" XɠeKWF1יr!#왬j-?F;%DG.3bOe|^W;mG#EJ Z3$\}ǡaB`s_8o1) K=[֟ 񈴗yTE'hSk _A;Q.og{ާ?}~*;7cPE&4쌓 F S5 Ʉ©v,ij-lY,*N)Zox\] HMd&YS6q*Qѳ_jiq/9e72y5;BSx;2m[8n$.iBM*{ç`sSf erf ;IDߨaX_X`[R ~ֶ/a88#/ WDGR)D5P^#[d 56)^ykjr} %p~*h'Q׼2NFj١u@=YوFOF'V=?;w|R 4D}dgMt.%8J "Zz[ۧ }R+~8:,AIO4GXuŔJ2G4666~u՚^X4 Ǘg\%YR(4Zφu*a\ַF=0 ~N+l">*0)f,G]Xҗ;t¡afW΍."ʈRyW̶pKcr/fAZ&Y1Z$XI@,t kuUxdRd-E'3<7pP>݁Go6ch:Eyg+Ǩͪ# "ȑ"ywLx UCC*~J 7ݸs&*Bɰ;* ~ ܲ iN.îMog#]RJQ Qpskx<s2汛tjdkJ aPQ ,} 3yO/@Gbv 8Nqk.(w!MN0+o9+;0˜ݱQK z)hwN}.J6$BG;,czkp3FYTb]N %W#QFVf c_ަђӅ0? ЭeI@b3)H9)U>)PF| z}Aȭ}<.]D[\=2E[RM';t[g/TvĜPʆ)46 d^:u-q!sR*˽p@+B"#$g@<%h,gJD diy34u:2ЀÉ#q_E{}IMFr,~;wehfdf&Ԟ#=4z1'^D@n4IV.fN ;w5\] !_m6,OL̔~_>.njUl/Dj ȜU]]l,y|$$dYG8։C}KkͼkY=k;L!C{!Yh @ ny;tp 4z]QJAUw#8ZWun[7#_d)68xj( A6dctL-$Ui5/U-L6-~. ц@r:WQoҚ`^~Umup׵d`lzFL`\:"5<沈ԂjLY!7NJx*ٕ 6j?y4h;kfoHIh=<m0Csc^Z* jP }gT"*NA-wǫm_|fbsIP9{ TR%kہ0 ;轼pJ^#`OU|la]8|]s0쟃Z~'4"FI;n:ng36l<t{|m@`b 7pcl8賾fcY.^E(k_ ap 4x A op/o "9yv^+jmrxZA><ͦ/^ZI A8𔾮_5\*8 s{%^}IWб.KX)53fPus[$k1||pzbR'>P˻~Lfa.`06Z_֪yi@Wbk,+]m-q{)e2ctڭ??Tt[%νG!Lb%y hb ށ1ʟud0OZ*GKT]u+&s:f$v9e4k&E_Q7g̈n&m!"n?m-{@kґZ2Ea&*n)S2two=!.9qGo)ϖ@s?sJu/@Hbjrs5A5 A}^]OlY_vyGZIjnwj+1whAiBU;{Uvz vNs9}PjQkyd׏ì+!lu[7{rPJ,ט|n)w 2?bj㺡*^1q,P a|[W<"ZO +@?JFh6>%Jn[;g(m.nz;,h㋊Ε6"wUbh2>c,V;Z1jn:^:S&ѸhD9?zRӒ*(!4 5Njeb8c$hzt֓d2먏,2? ͇_nȹFpY15ł6t8&o XO_)r(:eǰ"0SXB 6*oAglUxy6vK L.1VcMU3ڧ .[&>o@CnʢDU.iқ^co^xg ?ϭUtG{\)!zHUo%G X$64sq|H][8&h~{].d`?A'6atl'8&*N-yn ~|開<"FЍ#VNZ{˹T|(%_`j,קi{.5 зaf*tc&E&T!j JᛢlV;4l~0{]WFC<6{ZɘBCnVRkB PNR!&ߙѤV$uxk:2^#PZ .Y.>x_ Y"iا*lVڈ U0jJbM)Amj>d-`ѻ:})qFWEEf&K׬%q|<%)CVzF@L\# "sJRpW_t:}8 B!k|YJȯ943,YExs%OҧQ"Ya& 4|W0k'֣Pގi!@_F1* Y o 3`jQ` WFLi!S^~ "Ìvz/c^UVSw+ zop:G% TGG;a{C,cew&BB.@>\D<za"3nBjwN0i̕hsVa/F'`IM=l-K{a-P>#:ӻܞJ&Xd>ڨj=q.V#~efG] |cEkg^cNjMk!']2R)B@>b&I۷e7},Č6$ w/YQMi/"ԝX9=h2MoCzC/B*D*UZ\q5wUd+T(-4WX0D }=dzKY#n3$VZ98ZGР͛h% &a*ck"OÕ՗R#p^s_C7)*Q%[ w>Lj"1K(c8Mb(笚\?@yG`ؽo7ь̓Jg8Oy9%8mƹ A<{6\5\@U,$[g(%!0y+-YwtSst?MOAkpDK_=\X OEH|f5]hĸ!1hK4hYx,( "X7w͓ju_tvb-ey'!#f "w_Mlht.=c̔FAwEd}w5eWG|XnoLcTPÙ4xGD5RalibՇ&r[U3|ͽ<ΈxZ{Yt.#m*F|H꧵|`{$׍aGdaձ}8MH nB/\5nռYJ>-2ȗ}oM%¼IW> _:CWc\ʈ%|P?r wJ#~=HslTsWmu^w"RKr_z\/ 9Qө4rPn@mڭ}$%uZdsBO,=p"$[[x1{5"O+pliA@5l|:s !с}0i * )]5UIM[KA~µzС(#h(h9@Lp!dS IG4v4@4Mr(3vUY6j> cw&f]9*9xp8\+(~WN#@dVb0@@5Og-ሇl+Dh~ݾG>qx7]~VZ ߬eGZg-RR?BB% G Q G^։8jK#yE顲E.ǞSj>3yD$Tj $"IKB=m\^%7_VlD;ɓeD49/s~<<] 8n IB<~N2D=LbQWˆ 89.On"Ss͂8-Mն^:xꨓAX dP7u Ȓ/OTF+epaH[M}"RkiWNlYh(l_U%gt={z58Ř Vv14b|woy}f< bGlK@VT9ʁD, ̳ ѐW8A9xPhn[~&<` dl=X;*v6j]vOj3&UT_s2&ީ?ֿqJls #B HIO݄nΉ68{ ɦ~G DOUo:1I(|i#QV( t{1IZž'70 fL*GZ VVn',3Нl׉El͵m5cƨ$bN1}~Pē-ܪ@uoV \F{R5ѹ4WP }G i2\&:&Uţssk]ӊ-i?w0JFX(-'h'n+53O=H*p ;˧eWp K{'6KBitHR,:!31(F،{nW:Pj&ȵ+n7H{Ҭ/Xb.I#fWdo 6#({j̆F Jn1H:fޯD-uXS &5N'RUlH@f+%skk8U84GJzbξA ^Ҕf\ҟ76&)!ʋu)jÊͷi[9e׵C5AN9|33&\wA.`Uݽq8~uaΐY<Xj ǘ{^0,b+J2QF  "&:ՅRGZCϡ\h5$֠<`Hfޡ 2K_Gcc_mf!훵r؇!J+51ajm-} ӣFfo@Pg^]Z6G`'eVi%h<2`=Q P{Q1>]ڡc%9r`)RCaUJ:A`4V?q4>e=(n)9A,S,9ϔzŅ|0M>#dw1#XvMz-YTT#fHuKI])k.Rmo@SMhzBd 69Uk34C1ɻ'Ñ}'wܛ5 Keju7̥it\^o"88e8B:b&Z%rAҶ+Ao>!몇5+k#]ة)ɉڭ'&4s))Gapxx3۪- #nLn3ģ^4]$t%Og)Xn-;xw+(GL ol eO{=_N*"W6|?͡\5pU mmhA +Z;閥C}}AZ-@/ ?D@9yUӦTQͣy cc.4o-qP*kzfjKkrNh[sTZBۅdPUph~ v 2ɣuG'TrRu# J=od.[H)1*tjZ/D3t9B;^W]s0f"2UE^4MRÃshuL`Y: em<`n6 ^M?׆k_Y{o:Z J狥I1D ={RӀ ւ~ b'f^u0)PTOq-*Gʘcc}o:J|ڠPv. 9_;C՘R|b꫇`S HkĐ{D&Ey1;K[qM؀G鎧2gҪ 6ЪWSfc6@ixJsIŁg /i0uu[*5jkzƻ(@A8 _y! X>t}읮uC96~]Ҏˢ̥ԁudҼT:tET^>u ȧSۆuRhc_tGMqLDq8Bl[AFͭ|)f< \aRC/K%6N@hI%a"IqQ|(btw,a8k&dvSpѡScJ_&@B\ƞ[B֛RQo?[GOM6L2irc̓dit?(9SXc\v\ XlΏ>e.]Sǒ3U;I\LL0Nb؍NfvN)QJ4?=N-[($ DrĨ&׏•R@(X^G}S"~Jq|kI ;'4 +C{z `DY8'3xzfo5< 5nk7`'QZXE8"p 0;9.qgy+ W>p kBo79#tdVbK,'2%cwfKę?Ki;tAP HV(7,owrqn95Lj%HGVU|_݇"e9!JλwL+#.5)mIpe*Ih:(7 vұj&]&T(Lx$xe9c0hPTIZC/X.DRnɶ  66Z+Xŵ4S kAVhHNᾢ-זHNH1/ tHL,oB(3{۸ 2xFU-j K|CpJ T =Ϸ&}%w2);:LZO ͅ|M/י<*0.w.Oҫ;l7µ=(1~#TG-+-P;/7:dVabZGtg2S:'/=o'3z}3:XF\VXO?^%r%\ҵDQՍӴе%o}2ĴqTAhƷYSy|lt[C“eH668<ӵO4R%r;~!&2r;leLaߠnt׹LON;e# dԛZNQkx?] I6;Ɯ\ Y~GL(N"_y6R㑽O(k:@yBI|KFց‚bIhUG6Gme"w %` qgt龬uJwKYjoz hK~z[P@x݋`t’i!lD@2&OjaY"wc"IAt+jMW޴K(Ŋŗ!rᰧHODѣw3v#* WԆn!ZEHɥCey;>SkIBoQk%HNwTO:) ^=o/@rlŔAr?f;ځ yzͧ`2{JSmv`UcG[~ʊwd B,ղx00&yo,-_'A¸~ENn(.po & %҂!R䔹 iby`TGb>flcw!TqrػoQ+sD0F2T ^w] K}7x]gw)FyplO`J|/`/u 53>o2T /,xids"{t- S"()1Zyh_.:*ͨh`Ex30k65mqRX |XfpOXodqE" 2%'صb>!CχP0O Nn5i8JO^vwxxKK (!BoT_*PȢ7ƛUȖ {\0ٗYR[HT'/c{r"ⱙUJBZħGLF/LdL Hj>k6KtRقi8jIglMq±tsg%ҍ RvҮ. bdֱ_S_0?Ne2\> m ea1}-ot*\eR?XTŽ j`QuO+TWslOt馝pl#Iz9+< A_ ] Z^FTLQu, V(m!dl)^lj_}c6P'UGkϒW|τh'RgFcר5Xh__Dz{^6MJD '\h)}h$`g M(o2`X=~[ (P*͏^b(dr SY"t5 H(|hjFrJtP*U ́1VYq󬲓DYǓq0V͈uK މ?57Rg4dP >S7UܱzXHXXT;`loH%ZF=gL06\k]Cf80n;q"&>w @3\q8j=,+^F j_"i|1PWx^7htYa+=3lp>H2y=t' \xc Өp.!zy(nO:UGDSEQ fm|jp0vwﭷ4~q!f6 Q1RצnDF Uw ub~]xO A:8tMyfd}ʂ{KXQ]=;0ԩtދC.Ӻ sV4qX~g'Wz7mT3V%w a)4uplI uKH:wTXڀ֍t_%VUia4)"Tfz,-C4#Vf\>Z_mEU;+Azx<īPk$3~] RBPX8K!ᙾU<}.Im$>!U]ĉ:{6PydkgeʃL*2ϭo7D#@bGj !1mS_Źj-GV Hxjs١=ϧbb)5mzGc˽c3d>rsˑf@grI)IJZnVw5&_aZA+vi8IF=d TRo?+43!I$2sO&@2g-l='YGB%V(-. R}sGƷ} - 1m|LrGѝc<і~HzU{6 4a(s=610 L,gq|dCĝ?)Cb';Z*BB='K +Bnim7 &4@U&-2 \t':Rit촘KwCY?,Yw,Wt^|ȢsOc3%wցzi{\pdG@Q>G;cq / ҹl fOkH .wKs@^P-u# WԞ[1 sK #INU,&patvds|;2L"~n)#B0{5cGpػU03ݑ6y'0l "gzw 8IW5 yd*T_\ n7( bx0jXY*Pdu۴vz'9o&c h;h|yNkE͡e7Di'51;'C)iƒAsrg>"8C&[RpR:RjJCл{ӂV4R%Ua ?2A?Y+]W1I s4jp euM 4:7IU #Yd@[iO豠jv`ix3NJ"2 H?ܫj[o6/#kRyH3LS'Od^}iG%\;^;V udZa!-3j9 $Ssu0)SDgzBכGM3Ҫ77)BFbТ0b2Q32g``~U-r3ʤDjLX7CϰV0Bn *lۉqު jKk4_ =?W3b&z V06pM`64ײFzlڮdBP_My]1@hglLF:dePg:O]Q)jK/'F\"N sUH~-\:H\Rez/{CrRKKu苓jEdgJ{lY2TJoYQ1q i 0|@*\G|Qrnll:] XF?,]F䪎ByMȲhk`H#I<)=ۢ+@&IT2 a':o-D3Dcj}71$f]VFCri]Q_D$|~HT`SㆇZ\x[״^$=`"O{յjmT7r0:3!t#Vb jz'?~%섓)5gB+K..m>i3!HUe'0e9$ɁϽݦJ|SFSk]?2iך3qc)zW.I's[ikDW۹:<*=12@^#3&X}'lvڒ+дCYD2 nmL ULnG5&D 8vGbّ%)%F@:KJ;Txfcʧ7 $+qi{ ꛝ%и8^G}WbJOlWDƖjmwgE'Aj76mi>5܋@Kp }Q#YKdyµ0(s5>:(!]Fj:;ë`|^J\PZD_S{sċ [r\{fa:p5(_j](aGSFwGyCxZP2I[a}9BǪwsڶDLJ_J2I&8ϤZLU>zm / UA7C]EӒSOiz4^KޜLrs)ױ Gx3uZ/7}\$K&23h7fq#[Zqpߞ }&ceܸ-\A:}j2ț`#*D:]P$}

S~gy5,&%*+I#bPD}uV.jd^+B؁e f1w \RNB.{-qŧA5ha&2 ckO-/Gg荦փԙ4Yl3276nqflOa,V<**X r iiV;2ZzȳF2ZuAYxק^PY|=mQwXϭY_ֽw$0%J_DUʡOߵ.+5Eˋ%3hBVUUJU<=dZZU"SC%ڷTs.S$bk?A?%RԻ)~LR!#yfȮj 2 *޳ܼ bOuwAZ7]<}ѿZTݣu B*t#d`Lx һϐTEsmCq27#xQ'(JfSV z^@A")q[Z'ˢ2c{7dM=B )@+Mw>]7;\%Wz ϓ &eXˆ/V,k*"ͱL,y``&1gꁬ)3#5T-찉f)U* gv$:71@LTLP nr5Wb\%$[MJh۔׍Hh}"$?1~"7 ;?Glh7WZjCwA0?wz4:uB뛾Q-} fz,7Y>l1 r\A*] X|x;&k)qPef$#¡<9E$3|ḽ]k,O mYR/ S/J$ j) p~JML7l(ޙk%HC}t^țaīѿn4oeDBB)~~ bʢ  s~CB/]-N|:} UYڤ5yo""7o};@~mѽkYƼ'N|P5'ߥh|Dy cdz4CuhR)~4K%&9_9ej//d/6O GRnq:~a#K+p ۥ'>>N-䊻&OI]/ g$](JP@{ɳnA7Yu y\ܖGu\.{Ƞ+xkwq~"c[8ДpwY_#$pzpDF E! tĖإ!!SqoV^zɶ:90Nb8tZ( Okp*bz^Cht%$ِLU[;LEV@l5^ DaꒃwkkPTp"҉_vB.qQ2Q1tY ˯=ץ׶ҥ8.:vN霢*Y1y' w^o)Sk*,j @H0N?ecB}f ϾVC6N>Fnaxr D(dؿpV/Y 6S8qgW:9{u\ C³`nCzJx'ƍQ@/u =ZPﱚ* FTĹi^D4Up |<ҷ!FRJ;b-"hUwrrsӘy; bN:^%$dl6"ЊT؄nas!@cGxXK= 7N/.vh#gp!p۱ߠa6c V۾ɞ~C ;ޭ@S'Qy;^s Ֆ9֣DS MCNk6\{M-uIY$ZgJ@>`n$ Ϣ"\NCeW{e.vp.$2b9 -Y: M{x2S$S4o-u`Ɔ1Dw !Ԅn5iafe0-N |rE7FnƊ haizw4ry1RwH؅Fde5ߔހMm_x>z&Y4rW_ۑb q[U0^t!Br*|d$%物iu)ZvdPf<׭HJZrZɾ9 rZwIg7UӻdXS+ K=nj?( 1!ْHRYXn/A$,h{hj'X˃tI=`#rnwrDZ?;getQq{Bilffd༉d~mƚTQs$=v7\uϿA 'l<( ܜ. CPaI޲lPX])_:n|-]n곉" 1\I !utX+]a ="u$jطvb{M/+kTI,'U'Ch9=Dc&/J>pDDiC6APR$BaXVW:{_f CR([a:lؐKm&®`7~{/aKL 6D?[xN*Y!dwo%w3|?9WUMcFG]Sch>۪o Vn N&XilcWiamjH]1mȥpB( L7m㯱 q+[hꆵ$[J==hkŒ_%i_ef* r!mt6c[&JRjGm ږ6(1*L{`?$ԏ0Q|'F?ޥ=Nֿ:U0O)j B U$/eBZ Jj޳C#[SP֚XQ]cG~OmbFni(܌sT)7Ly=[9%K=iLud/J;~Rmv]6$wvU/Ȧʑl zq. @9Mg gɎ$myp @U[hCAOdGƀ s} +HjEΙGߪ^@p^| @^Y5PA9$A,c8#Ni,yf @ ?d"VMhVL)ΦzdK|8 d5`CPVhq?&2 ,ƁLFB Kk3ɱ !c\./#T1\H:(v|^nˮdr3+g"f*{؊璜'0Rw ZM"G‰'_5z:[pVJ+W!C뛯Zb$f]n(/Pt7nX_`0M63UOEf*(| x-2nJRpr#_ ΘV\WԮ 8xV{}n%aSUf`pDČzM;,4Dȱ|dICqZ_e [h]:[KBݫTg覤W ɝgɽD#.(69V( gm6۫ [WJut2kC1L,j~soeƻ_LҎyVt0mӑ; Sz'hLs2Vn# I-D[R ~Oٯ-ׄ;0|~LO=y"sW8y1?r{aJ"NA"i=FLB0 Wr i1ݳzhG`֗o py7([f>e |8Dn85[@瞕ջ.̛,ԬddO ׏)o(r EEx%ez-L !*?c >#u}Rf-u:xX8%vjYV+veXs z7 9Twݨ ɃO쀛$~C ALX!q"lbc#KKD8|G>5aq"/Ǟ:0@"YI1@Y&;ħI 5iy! 'A*gP^}?־pX/룆َmCu;ř߅E_f Yga򌕛YV+ $LDkFW~QM g^}椮-s{K]:_^cG-Xܴ[XbylPu'8`w{Ch azvd9c~QĬxAC$q '1B7 ݴaKy _;Sռ%&4I{O|^^K9&`-H,VkZ aԧ "8n&+ݔ7w{ɡȾUa L@@.Ȧ Lx)ݦ ߟ.N쉡<+]wN ]41Gdl eSg`IZ,d7> k.dw Сo8/>yk;ʊwQ)/8RukMAڒRҷת90C8'gMu\N~bk~F6[%Ѵ]\l障BEy}&=a=9H23S_l-:ȮW_07N;/T˧ޥu;ty XRCyzK mc t^\闽#6.b}>*@ljD ˮwp59vͿbyGƥt(MC{x gKGW`kU;4}>0^cF(G'|ƿ@K1v>DKqgb6BW: JO S o:NXx3-,s-ߺũF}8fűGM.xַE~ZZkl$f apD:#D#+dէaz:ͷ2 Ka+_-F'9a\#,3o:Ũũ,z.$#(1L?*c0HfÌdӀn]$aif%z#ý\L(|6_j(ocp<Zd-EW묑[؏?ڒIn5K'-|C>iORda Lc !n|gW Sуc`һrk pm@TXO!jo9y@YÒK?+12RRV4UWϝ'nH9cl4҂ZPֱh2Qľjsƍ {>dS nX 2tߤV|Ȝva[Y߈5uGn6UžIϣ,8la%<SOk05[Mk(Y;6K!Β/Zbh~CA8p#8z_|WE0Ї%qK؂@:U'/L~oX䛤}T)q,X5MB wXd%I>Zȡgc5ZHNgİ1;ZKHugA9 g@vc4p! f#B V+|0Yt4w( qlzkBo:r89xM>vBE@Q y $,9SgjT~R9DT B'~E!vt33$t̃ɭS᤽ z;&~QszoV1⁎fEK>U}5+J7 a@lO#^>=4@b;5Gj N)ֿ>X~Dp%syqh20'eV;uq4Q|g^)[-i]A! vkujSK]Q%V_o[>x:Dwe1H+QblD.עQMa&e)Ȍ$o G,~+ {bh!êנ7*EpG+³ֺ' E" #g{i譨T:HD̴t&ig4/4ݟe?)Yfē&|\E K@ G$y W1n$;#MQ"M"ʈҫUeVDN ew4)9v$r A(30^8p$Fw6N 8L+yH zbfu\6^3 > N_Vi1&v-YN{_ŲF |s8EDg3ﳈ C"ׅE?GFQVnJ-TV16<'Ҩ[>qxc2VD /Mؾ;19 (..i" ZBjR|# AC:u&&-c} rtȮoxL8[ fKMINP-G)xMU`X1.#L"|wr?,&m J ?Cs HT9^ s엹 ,[ [Y7 ف`sgS|V $;̹EAe~|luQw ^qSdHQ$vC*!߃S=+'T˩t/ԶQ%x0D\EȝӔ ^H1H|J|2f Z4yb2ڷMSQXvyYT{= Q;z4>4zjr*ҟt :ˏ,avydG]ND(l~%(#7E97-`{q5k:wE,2f>ߑ&.NWW3WK?2U[g]w um=rIP*޼ g2k6~ ^pDwEw]5k/WYKh$ bh{ue]Pc%si`ȫ.W<ûu#<نRσ,%🂫oP] ;e} ^?Wg~h|>׋HȅZmzvE91Ng%=UkbG NMS2g( Oՠk0-xIl*xz^.#"8[НƯJ\E+e#\y Kn]oA>ͦJ߱#ꔡL`7$q{ 0W}^4*f9i?>*99!\]0J"(Tjmp B7 dAZ+0 ӸR[/xbRӥg߂꺡kM-h/c0|7sAo딎Aܣ}9t}h^ճ5Ip1<~)F1GN5<t 8[BԹyo[q͝<~>ݖ܍Y1~KnOB5fZG's&gfUĎuVE~pKR jKla$UB#honz@nGOԕŘ ᫍЈJ{WX.49ft6!آ45zHHt62i9U].5J,/Ci^@D B)]~Le|ݭѤ6XGyJR! ]7hr~ʰ*2N1e~OО:5Z*ȸ`blYmc8#8RTCnzC7gR\U:ޛݲ@Kx?j4[I}ܒBH`-qe4m씴~&AeWN_nDt*MApž@K%OD}Znwl+4d:uتKVc 8v4Xp oSW S9j;f1ZX 4QPkܩO#bߑzeZwze9L- !M^:brG+ϙhR.v"|)BxJӗohk~k-Р./&W{vKYТB>3B9[hM~U4[ۭCmV^ĜR9WvuAD,LIpv0&O=:|nj$lo'>5"1KV:\wh퀡ݲY50x6& 90‹aQ?L6bP 3 ܿ J\IA&h-ziw|F˿ P-wAl)MSQS /FP0p2n"F& K Es`-@@[Mp C_[7*0H嫁;2&?Ʒ wLiԹT7Y0ɝM$>f>aY[õ܃ZN]o"r{FnhV]F27o)hEp'%)OBNf]UhglͣY[x nSbH(B3LtN5W8XץJogo?v?3YсA"J3 M`DrO>ry侫7_ڴ_yfsneͻgd Z~( 潫rU"=I}x;x9ľ.a Qp >ԨӣQ\{ X;mCu 5 T1mͥ ^(n@6( Qx$p m l޽C@Gmm0_@? 6LTu+YTC\X1y+qfPT @)x]>RQ=>w*s^ !H).B!\Uqc=GC#b_p EB:>SdXZkx=I-sT_c@` ktxgWĘ@XWcUpxd5j CI)ji7 YHZLQ}mN\ J~IQYPU+Οu|+h=VYJXpA:`{"-[$GOj-1JeǩSOl|ehڗaqnN[m0x)Da ެGg{WyL ƵQ= Cj4}_)Z]$e(%hvdZ$Z$082zx[|R)ţKeǼw"jݴAc)/2-a:TgvTO."prxTDÍ51¹QDܧ_0I3 .Y_ }R+mA1͢`J`kg8s_SWGSgm n8,i 2]*[y٫熚9 Vٻ -e3]dg\3R>HRhoIntk;F<`QyH*0E;<>ޱ?^B/l +=wZgYv j䲥fj X`x'0Y>!/uj/Y_it82OXP/,-lRr~+mIc\\%^MC JL VcL]:|o6#sƞ&H\ (a'zc3C8|]|!fS4Z<4Fw9K"%zɚDʷu†1)N}AF幢~935AZ"J8rQj|lF(Jv0 8*nb,9d}'"oJ^/&7t@ po4y>MT`bI6'ZN) ~{|P>r۠"۞9m)5y%묶yn+~|Kdu| #*A*a*u-{H,hE>"nZ}Viִ]nE >B MKrTG ĉ2!UO[q@S[1N鮊}~8*@)I,b%yYZ_ZwmTuͣ{bq{C^BUTHPS?t Ʊ#D:|ZY;#ywst&%/hK\KuV/?4t|*S:&F8l}XY"D<onAeˏIgIYmܜcF|}'C fs5mRہ[6*okb\6uMAxp.{9i,IRrȇ2^l` F4B^.ݫuHd$h{CDPy A-F %#qj9*4Sm̦G`W{ Vd޳oqD\bCݤ Ɖ<('Pq*j+m[-n))jO,;IuzT'zaio4]qC;o Y-( l?j=sm]P$+LdOȘѡ$2P_o4Y5~d^?0/?p:m:Bk-l&Lꤟ8^rv7"6pPAmQ8W^4W]Ǧ(kܩb 姩Xߞjec^#*3u Z ʧȣ'j)h3v ]bDٔq ǵ&!#i8TЙlNaZJE #+1:}C奷᱈8љu 62wv蚶G_ ]%(1<$1H  KNJe];Q|,dm`R37ID(.ڏPk:a(1< ,{|h$k5>; PDƱTDB 2~ !fnh x Ȼl~]V0>|?B)W9h[JkEn{HEkjǎ|d}HH+dC!iԳ-Ă21i2bHwb$? eQ:1 ƲͲadžl$8p|-& g9X/vs%GON/ތtƨIdg*luJ xD܁ ӥv Uw`1aG`Q-eN;?kjl,t@4-+([j%H;8oh`5PC3#Z1C2)`h2ؙI@RWS8Z:A7ؿ(:$-쌙=al\/3d Խ vNZz 7lݧg[;$Ne˽[1wtyg5`O&]w&~ UA+<~Zlb;ۇ'D|ӑTzC*y.x.*L.29 I4ėꙕ&uJ,ZTv?|utQP✆T'l3Z7Yfghf 5+X>P+-%TR'%h7DƴZA͔l`P'QN6״( ;!VFg'wIf}%AN,&7 !ٹrk/,Qѕ=\`u }FDu? ( m<-br[@s"X&["~lNY[bIKo!dB#([@p ee7[r+͘Q}euςǫgw0I/?Q@y`;EIZ[6s )qPDL/lj?\Aܘſ>sd]0E!RUep{?hYЮN䐠 mAFx:o;%Rfgn5U:(O[!gX?[>RoӖ '@8u,ķ;KayibDama~2]^4,&cX9a8UY\4] (B3PZfT1fŸbՏR껍=<o~nj\ @(Pp$Q/fk,zUi7GATdzD!v3"ql,u6(#Zj\`khL؃Oχm*uL5!٫K`,l+CG.s@bUuYh"hX=lWs-CkTꥆ {ɧwĶQ4rH ;Sd,=[Tm|O o@ 90耪 >wnIp0L6VC4(X(rdvmY5[_-Zl>&6*øw,~RqAz%̂szL[,vhw@WD7ҹFy[Ey &ٖ[nјj5 ekN{N#[2lZ'C\J]NCnOVtoܕ7QL:rȠ>VJ%ve~P h;_BHO"as2:ɃN? Xˏ;Bjc$UFKG"оd9VSܞR54N߮vjd˯ʥFA\j-d !׮9&t侳VA@P=dsրt˓'u;:=(/Z+Xfi=$)}T4`2D6S ZUPsJ'PB!LpRutkk9_BA+ti;|b_EC+@V}V\)`"1`ĨM& QOBba 7U)u}ǂMDթEja"SK0{"@ň.FUoGD`snI}iRIU?"D=od6ӓWmaK5Hk-ۃqjaw~N"vgAY_Ay-."6>\jTj0 #:W_?ۨ&? >[o¼;kϻm=_ǰ ~,zl'ҩ/"R 9w[7Uh5Y/A)bu N2p+z,$cfxwt4k&#G*"w3/%'J^XKpJq1H@HԧUބG&Y3Ra =4rjH/ĈɌ\\$@pT\CUCkMw@ȏ̆CDeQG :rkuAWuX iNoOji3$FfJƽf0tĆ-:^ WU 2*B'ȟLF/&BtU:OcьSCua=7Bb00C L3Ԍ&EԾ ´a7'DT{ Es4+ >Z3{,zhRRkgr*v`,P[Vg= >c׉= At?kh^gYXQ"̔wrt@`[k6=qĉ^jϻA$s7u7_~i qWE ;".͢uU]*$ y}/\P83\,6ؕ8'Bb)%T(gr5.ZOީpq: >8lD ˤDT'Mall$홾 K\޾@":iw D޷:J)N$2MT!+o%.۞1.8HPzظM_$WiS@wOBQȣ)_Lt͓UdykJ~֯&Ӡ_·$H T D&T\+w\xJș ZޔB3_AHCʭO|;]Qb ),p BRÊaC╁EPBck}`+sȊ*Y*l 0;2.IiS!@a0U ձL gE viP_]oAt+*=J:= gXo˞ 5}¸ZoB=zIkcQ6N#{KU ƿ?W*.W8_5sFGsN-!l Z%v$A |H饲ԆǸG?!!e*+#?DKsd^5 6,,inunk_q2ճ $n 7q5V:o 0Fj̸lAq 3l , wM} koI3N ]^D` ׌ ]'\ H,g W ʅidz]T Xi{2wLHo'3c6cAv2.ZV:6kUJ{7 w1G=~Qcߒs5dQ.;`@@JZ@kHBDT4 A8T-I${3bZUEW5x TH@n{q.V9x8K)AwKYLHϖ}exC\Vi,Lq6PSfHPXw{\9$X`9o{հ`ˇ|;h;7 IV14g|t@!P ;ݯpBe._h)?s,cv{D)X9;W~ ˋs v$Ex՞Ş?A!끑x2@S|uN3/iaFwSꉰ#r #PWl(0l/; 7y%=m: ! 0S" NF }.ZXXL\A&*:bYۆv&6,|#;P\mOdFҹPIZ]KĬr@F2\*ƈGgzz9w>hRMH]C-ŇbS wN9[p}8 xI~!5.wS"Fxv/J6%gKGKT9k) oٰ.DT|?:֐eF5R7Y!:[~<&7ߚ8bd1)R?I.h 0g*?|y~'+chE * _ײ=w8D Nq}l`؂ÃAd4hgM-^Iԭă9پapB4dD奰z^覻t!|4{ lpUm~f#: l7W;̈́lwbTfsk1i?逕6}L䟁@N6bbSK6-MK7` ;COq~l1rQ#yr_Wq`yaP B^cdYYPWN%Xhpk !"&|DHҾ|B@Oof,n@fPS.aI`?)|(q_'Qƶ _>G! .8+:{57SM" ΁@Lԍth@ZeeƭӉ;Sph8zd 0++M! \DoOdg+5jGMo ȣGon@Pu Uj~@.A' Znju,{yjݫ Ę^3>&*o 7u׫/O :r=D4&g}貏Ų\lgèiq UEW4&ۥGCtX\vU ʄ |hx6 |p<ڟu2g\2&i|^ ">όc2>qڀYg)!@-o<(dlS,~SXkl LYFS&.67prsI!]4rH~O]_h-jUme[w.CqeΟKM 8#Pr^ҞHhF˯Qs /jf@iۮ)EMqrTy"6Q4= `J͞Vul9CDWsXoIt_9T〦X %SCY ([9!O5o̾>d C-[Zj Vu+=R*D|?wWHmUڰ5Do_8`BU^$|qL@QɅ(y7t[6j-%#QӞ au%B3T"FA!pF[gn(-:6փ 0{Zv7!f#?0j* H:x$H5DJE]>E--bU% x1z+bdg2Vgq7u~vK|}F.exiۿ&G]AW3^W$v%/ lE~Ŝh^$Lb Wa,fћ34bHD3k@uCd|"%KDΑTb,e)6n wiED3w|_.%t7 %f vy7Px'& @Ԅ ӂ7Ӳ`$ZYe\LЗǭ'>NS'q4$R#;YS(FUj1B540z}.I7}~T, B$aU w97i{h vt8\§'zł2oU{SBsL]SL`5lh*p:<-)#~ȭdè:[ E Y)jx˶`83It4 ;ˋ='֜`7/&efVBwyk.KZ>/  B㋬up,`Giˣ|ыW"'%MJp%Zϔ;8  Ew ,DŽ:ZU-Kyu~R:8ʦ*V {E2y֠zJͽ9_nxXI6e%BTN矌!O8nD!$Q]3ׇTݐ XFn8/T nYGX%:x0 MYf/֍uR!)d-3^PϱuK֛ Ҕf7c{pOVZ!3KQ[M_c]H 6]_QOIQ`yz#?h29 !0_6 mA*GR.!sja&Z_oz1+|W[Od?4=WKy3Jl+Ƹ>2.TQѫ7Bu vܻx.Ar#I}!ƈ!p!xR"ZN.|^dg^ CFN9ܭ߆;BGuKyG#³|^kmc7wP/Q5~h(54WKͿ,PTj2Im1g_ Yu6p'S+¨z^JF$DMc9$)$Ě)ЎvF]FU%6CF"TQ[i<:j)agNlo#V!R¼EǖBzA UC0>s~mMuce0K!bDŽ(mY,ofHQvM~|98f3[rE/fjµdW:I P[5nD0ϛu]n#e4jٓ^6&V5V(H0W2jDh5f*ǖi B΂4[B 4 eN$A9֯8RMTdJF5L곴j _1ja(T m%k״ tArV$-awMSw19FjꀠA>+ .vz|)/){ij',8NE̓mqGD,R2QO.O 5:{Z3soۊPz莍Ŕ|Wid.bē!zRMFc6KYG9't Ⓓ-D3QuInf@>f~i//Z֬R@;J4B_(Y "uoys*Dƒm ${k2Ox)YM˴*5{Ӿ XM6AîVIgI˶]ܧJJaW5hZmRF$6bYJfEzMpS{Ypd`, X$8#`f i0E>ݟ-\1EL:{2S+Y(95KTC;#\?eS:~1 /;= @0ɏ z>Ġ-lŀ1j9;e_Bc2远 -~@P4[C5ֽ(M-*ױ 20-VEEaAbYmo^c% dG[RVAThU=jUR#kR~Oqa_YieG }9mSP:^w3J2Q~O@3p>A:PX !;yheدeϜ)I!}OvBW$VM{s6֑tVNi% )nndD'K$h̠QNpJVTTN5zzI} Ni!19Lؑxysj \}+N܅tmkmHmj0"-7 eu!'%xok< w$QGӻ+nϯ~9T;{`+:1đPq^E z߭u?Z$ìJ Vj}'pf߽ۦsw*Fh(#N!-_h9d[nӆCL抁mXw<*H}g j;Rؾ׸51BóL[qM^/ָA'gasu7@<>Zl!6[\U0 Na7U!}ƳϘ`p˿c+UrsVk_ʐ[ l.#HŹ. a4o0bzlh]$7GdV Gcw[ȏ/ݣK\5_am2N2-+fsq&;e[e'(kD>j4eGt`"?q5a '7Gy 'AiE!1Kfx[i C\xNK.N ܺ9x'Fd2XQ\du1a}8=ۧp__tw Py}&fa?K7C2sD#&jNbKȕWb9'7xH}Gsߍ7T:dw,rmV[ã$q1xVTe=/<ѯ4as3ifi.ϱ'gr\1;H*ac(ݧQK:dk恙rS%74xCK.yɱP+}JIK#tW3R&R]ʪή t9 ͠3M[֠$k~)b^u%UɊQ,[S,Iq8M,eԱƴyF8iP-W8{7zAqʹK]aJ8 >y^x~36HC`ceaz16X\-"Pts Ie{-ц<1EXi @$768Nv#AY.֠of) lԛT]VLud^9 KcpJ~C KWsr/X`E :5}qՠJ\HϷO-I6n\D&44vw Ae!բme{ABsp5G{S[յ4p!'~IGX  Bv,E]MZy#iל٧gF&F@nq! F|QW񖸚~Ȟ!ib[=H^u,_llҖ晗9X=e<- ֻby֑/E>QuKSJHBȍ}&˵=Xwz)Y+xEEP $:V1&XhXpr:ro(_2X4N?R$ﵐ[^q*#e S.pKhkf􍌿#t7}Y ?R$-Q/ "xď |KT*8nh,ENc{D($B![tiO0DLG4u\ॢIG˹0c+:= {Фy(g]PvSѷC Ϝa>44 r@3wLt6 ܂7T5-U#+ <>睐Guq"|Ղ*xh x?:U?S`\y›bma!):&f\1Lvl'YѾGJ+x)T(Eo J-м"Sfטctߟ]. .xzˉdc>7aϚg:*) c v O λ-z~`}C0`Tbbnoqudn#:K[("\Dm},Yr4c6_[y&rPefwqqe= Z@6M)ySeqU -?I ɂ"rd!ΚdT_{g7٬ '4qxg F_E(<_- ާC%/ࠇԌwqCיP45j؛rho}sodŷs_sb^ K Z/9g2:fڑ(7q([yH+Mdѭ&;޶afU.q>2t Y ӈ̣;MGg4W،Aיg׏$u8V{굞.ri4O\>/Z`+:.oL=T/Xaxa4@VT2HRnNʅ(LkΌ*F\cfBJHpr8I8YKɳ&/j.sc=4omCRlFD@\)BIaؖ\p2 97j1SWN!1rуhu1y6ގǬ^cKr;094v2J/UqMl;,yy^_V\M5`x\r!,(Rz*E7ؿowVI9 (\^-e6KXylf ̔Cn{OU; Xv* .SdhhPݹ *mp`9,dx[pq"݋_g[e@A \NNGlJ߇eL rBwsvU(J//ITc+͐_ +,T&/Ȱ]q҇pZK OF8iMH((Q"`%6( $w+!7p-$9_R;tKkQ-.Vt{QY@6F_Wࡪo֭Ѫm@&,7V-OJJ61uqdlº1s3v|U DZp CK٬V xFç63܎Jt\Xn<9/LJB1'P;R'wuX1(? ~L.D!*6d@YEG*)XG+Е F>G( _uf7Q(QUt &'#`N(G4d79!dO͋#@%çnEcR%T׳jQ%ͺ܂r~BduTyQ &#=^H*MxAM,YVS&}*#1  9zr81W& ;˺KO^_|eDgt*QLo#B75 ;Q~<",WmLBp;9Už+@y(u4%_ʓU1$ҵzV[ μK7i;=nܵޛmSį|x&:w/C&ܔDR,vijj8+Vyy5_No&{T>HdG8m84>\Hcj#e8f6+da$V~$A2-AM^` rWZ4J{f Q`i7$g> f!'NV(%4]޷d$+5^5J(>xdJ56?&c;ﲭ<Gwkr_8; c/>{[8`]Ƣ{̈>B":T/H$R@,R(hF뿦+ igH}W%U`t|%.mB_ oKѭK;i3/ kd.e{s7B1E9vD٪+!ө#_ Poc0sZn PvS}bROWZ{ְPIST mHqg< ǜqvƳkJe v XO\|5\!bC#7_tVn8aDNaCfzySV-|N6Nje'T'j@Òx$Y'~r%EDw-7FX|NY _]ߤV1򥋬JHFXʊ@/J+ling&1ZL5.` aDlߩ=CQz^KvJti C-? qIS{I>n1Lv{5(mOn!Gzk?]'ߵ"r+t /q9=xZo.Mfn?$\apWD1߶XU7=y.j"=>\dȺHM vP{vsl`}3׷Vtwk@HqBFߡ`R.}݌=W5wzG3vc{|GR"zi=GQ`)>Aţ~Vf|m.3;PT%#qna- ,w`tKxgVd±BMԺ)]l f?(0{$I+8)q)K hf<|"R񺦎ˎ @ .X޺nxЉqcb'TfG*/_ߣBzu2lFC+qoYUHpSPD=VgTFTNPQ7I(h ymKNyﳏu'ЈY=}x9z Xۤ:{vQ),gG ,%gHY^_D`MʠDi?1[fvH>T٥>NJnIi+G^ʼha8Pv9Aq]LDho3;8B7e ׸f43ČhGPS4]cdf{- a]ޚLGgG53:3rj?̣^:v>?=;W}c6Pgc_T6h(ash֒N>3Yy6kpUD!5%WGmԡI8ё֑'}|pu10VDYiUDl]f%:M 8{h+0FbYpvoEU_`Jt|%+ݦ/,I¼D;c]1˓D ~߳庪.ΝyYt 6!z٣T`DKGeVkf"毡0Nޱ{lO 16?CϭUM4yMtJHisQ*,xR#LA`FVquK7C-gɧEj% Gswf]\ Rͪmyk/%|1?:bΈf"s)S٢9sp>]/妍Έ/{PTЉB҇]h%xy|;뾛@ŠN3\w:?{Y|{E Blїg+T=8oT,\eP;=nwOii3`ԦסVznx$U$ځB/Ug>b?0OI4[XbU)DyZ&q⥺embpWfAvk>Yұ!nY<a=Mrf0C%xGqa<Nf׽DHOx<"u_BUE48} pIk{,E8A"a;wL}#^1rI D_:笳y,١"^i4lL]:M+A?" Wr.Aղ9 Qr2(a\^ G]tP,s-k099YM2,OI~o^裇לyB R%Zv˔V/pira^gpGơ7it|69Kie zn17IbtSGc.4ΨF^e  *a6'PDÂ)]Iw \|a!\9QdcTdgwuqн%ͶߚWjMME%ӫݾS?'L3E4u|A@S8μ`C:LumqLpw†V 2\\PYC0jU4qFC|bw-=[, b[z/b֧AE|O0F ƅc +-'i9na3e+g.+Pr˼{ poȶt|J_,b4xN329 7" :oǃnaT!1_5SN5ţx<.>Y%A8)XǞjr{a_@xbÛ 鵇fsރHA1a}{|1^ _[n.3 *P墓3Lq _o]1poB$y|o!)?ˠp:d{xSBu0C$Nd[|RUx/'ŐGfUY!CE2_Fs]FBG3kSb%S~֡o\6׃/k7K %r1ꖏt?𧰹1nƊ8OmZ($2[l 0 px+d>tmB;ȩ lr>=Yk(Yv`O0ؖ;aRB= 1>չmSoA壑4Y=͆oV㉮Wfr$S1 *! UDG M[4IZї3A1 z!.V(^oTbTN5Q  Ce=Wc/؉Ν bJ~3laOՄ>'X7`SwM/a,,W75Y>2n[po7+ hEIf5<+CJl*4lB1 s5QT}fYfe "ib2TPy^cmk|6e>"ElNẋ: 㛁nv$f KC!EÕq\-0?9q/qգRwϹREI |/&q:^0Yvi |8M$ߖs A]ݑhKm΍mG{i5ȶfTnup r q  l|loaAFƹ"t>p_)f=.ԁ._˧RMb"圃y3l?[Zz$,|bxTfnK )F\6*] {wt\<̀ӳT5U~`83 c$۽_R["W8gⲇPoOhw58D* %:8w Q);S.lv:bpg vˣ-ߦg]M#̠k"$׳IH}Uel:r"],z5&QC'桂醺 Y@E*ͽš3;R lÈ^*l*lҖhњ6|[6ܨ wAASNklq\m͖ёyR \:AE35!ZO,|~l<2P?!PPnr/ Gc-y:$#IqKXS|_1%5bmInd"V.ob `0qaf- L4Yʟ ·4p OF x<6٣P!_ܫЪjQ[B$ ;Rp%.9dN2gAѨ܅Akף\2w;?~ٟ[Zj>v;PW߀Ґ%T"0!5&eDJ{QS|I0{\V4>fBs hfALRv !ZWoaOen?0 l 㒕{duˎLA|_T*^BоP_qEHk!O#nXE3"]˵4tU 򖴾$%Z>3֨x񚼆 jP44R1s(gXy4ϻ(|K_΁2AxesGȁ w?al1'Yca>RtQXTП*e bx8R=(n#eD{53vUq̽ĞK449 F5p> XF;15Uq.'t9~7t賍szKe9;IR9xKPt_ Rf{/(y4 87{vU$Dx.7:azx\tx=w:P=rnK9P,2$oKMv L^=T d\!^ͮO1ndgiiQCRpNX)iXRpBs|( ]<ÉX-HEӟimNDyB1aGActqϺ-e0Z*#^@Eޣxg9 ^2h>c4> `=cDܦ )΁fR)wUM2up"Qb14!=f {?ۼ#^٦pEWSDˎ%s/s<;9 f+b?]*Ɨ`Q~T'JIg+bʑRP̓˼|ɞK"_ {wy5寇c{=@<ڡ3ȖZPk} PŎrIqZ !%\ vEZ 趃Qyͅ }!7n`Yx,"Vָխl )cs4uP@k{5۩ct`P==o%x v̕Z HeXh$;<\$RaAmCe7w< 9)Wђ$#Dz= {ߧ>WJ)*gku c`bJ|/}˲i*8ߒfq z~bqɗaԑ3EYDݎчbq@oXpzb:YCA-=] yQg pNv/&tM`s,xbj#e+_n!Wԫ"PөOs3W/s8A۝ ?/Vs+Ȯ X2WO|'ؘO3/`'&)ϒUƴHjZ\2 Hn ^$֬mUg/Q% M. %IPR{Ю?$$V?جX.d:muA^2%)){ ƈm-_ 옵gRŦ& @)v1;e|R@WQ~%;{ 4)' { C-z-R[㨘oU.$˿loCA=1A *(T}WHӟNTlPjŗ9r& 6 y.(e v^pr0|dOH̻{%c#&f" Ϫ߰2(t}62t'A!fcn3K ȷKwYcl9챓d$S1D2yB(/a<(IϘҥ*xwrB,Czu*iogi{ %r7*F_ܕP;̡|]z>Dt%KȼNʖLEr/$RX]BE}3U,T/X(XeйQ mMNZnU-Ox;ԑ(_kgWj=,P7(e-k&OA1 ЌcaO6E`tp9FH9H[>8&-z9JSP}DϚ 1XK4 a0/y[ml*?u!3~BӐٚ`z5v-xNub m\heI)^ljr-<ʂٱA_c7h湶f$ {eXg۪uҚpblIJ^;KW(qE6q₠.WvH;2ο)C0=5IO4pK3dn~8,7Fk-ҡVAEj SE7"dsU@bbii6慘<^߂R_c`T<9Z׭ɘQLVBsUTWZK|Um-mrAv[ZiH!)O倧!Wˍә>ݐ"C"}փ$\r1qqz?G ?xnZEB?4Z$wj%k5Mɪn_$T҄l\îK wggԽYLQ:.Gn>#;ELginb+6xymx(i{\fy7LJ.4\˲C_U(['7f-u@Ɠ|BȄ <8i÷bd'SY=ktƬĘVHb]β:(@ƶbiJ|:7AGUu"!ám3d/w7 x H%Gu_Q y&k_+R p&j0ˠVV|2pM/po2܀e=NBݫ҇+ݾ39m6TK2 {3 딳SnG5pSq'%[jl{zG}gIsf19{ʶ I;AZ"#bӿ̈;äg@ Վ9y@j}of>FoL,D{hl1C}8"ŻBဤ*)e]1'Y' x{d԰TN F:W5*L츧n׷cP2A@dQ;4Fv% *#>A2@?Ҍw`#^SsTROwgQ7d@act^ S:Sf3];RN(Y#.("`e9eYYz{N)J3+Xi8?'7qefR h_hLF;E{F\Έ6/gYKOien"ǫk(^_WΔAq|M<}~͝ukwN~OLqKnܻ\PbxBbX-LUIRE;C#qԭrM  Pݞ;UO\4]\@cs)H$)UM%1UG=];ZYh97(~%jc+V׾_tt2|?NIwB>C[:YPsYC'G %tQ-Ka?lM~Yt<P+< k].ɢm)nfWvӀ▧rveߍ~e#VbD.@?@fʷ1_Ʉ߂!Rk=S k%q~=ҖR77Hx]\K$,Lڶ br`t†}.@25- b2ӅQЪ p5)]}"ӑyۓXp/_$0fd0]$RwrF2g7-ӠfLa/+I;$tuI8$RfVXaѫ|L/ Ls4o5ˡ rqSsXߌ]烳U{nKtaa{<. JSzB-! @υ;M1/]c2GP?=4Wq)6kH^Ox|lIӴ:!Š&ɯߟP)AOTB{`kTľ\b\Iݱ @>ArT5|Q__9V˯SSGrJl3"stz'z!3?G/=0pZ~aqE.sfyLj;ׂ3$ķ٣V<bPLGD .Yj{:/pOUrC9NQQIKWmjn5.sQu. {Ál7[]͒P)4ݦi(SH:ԝn[qsPR|TaJN TN|,Gb#ĎaZe0oEP.j+;SXv wYZ|Ѵ_[D$,xi&91Cc9#gOF ]0m`5 ˂ fJ7u>EbO+@ƶ zA IYoܫ:c< lN:~Jq2kj^ i *8GĽY+/) lבN:\Mq<[eh\N. wX4VgY }#<^<𢊲s|.*ݲ$e@ח°̃/: F}ֱxms|-im;\[T\3sO%@|5>fZ΀ָg<]Ѭ eԬ.k ښpWM\$ _{+ИGqBf׳)[{njˋ" SV#_{\W4Kg{)[~p O<\'ƛn ~|" QM /7r䠙€+EeA5-#gt +/jb] |*ii H v& u*@nI8I@8=5eҨo,Uq?Ϧ lwWotE8T> YVY)%ڮ4lQ[7 K&`ok^p%ziJOgjR&0#sA-yNƲJE kxmƆェNcZUvOXc_N1BK)e4q>1o K𶪏kWC6\3i у5UH:'33H7à*R$NBz{OdHbMBjS]|ފfs= Ld(ͷtޛ8Z R92) eMΧ ֟'q(E$V̜֦,qlǷ'SwG|3ѳT# 8A80F܁N оP@DYPU>5#l|hN7%=T `@6זY/Hեv6!<1n7=r$G//R\J~3DR 4FJ<>oQ&?wdjCˆqS!燰Oo̒״@YOm#Ru+JPV2049YSOTo')}C1<=K)p7h;RU͚cAd</Mbz7 ɶo6uksh9Nw!Ds[o,OHضy'ooU/gCQ'eGfZWL -)#"2ZM&uSo:+>רdiƍy*^S`17oj* HNis)V\jH=ńHI|7F5-cZIrpa>Vg];P@&:.Z򻮮xfʲ]ş=P[SV0?U+8T-MC[s ELD% Mh'۳C6=yaw-;rKQD3zmi.#БB;KջћFCc[?LRVs)*kn;,z7P U P ҚC(e.P,lx%ayk(̦ QPyx}9kVPrѢU4!@ӠIRW?J@ҟs `te2- #dL|YǢh8&]~!MT/{4z}`V[(ԶMp'3eʻ 9iͮxʯA2۟Qb#b6@nM90Y XF:{bFVGw}<Sj F؍p=H?3鏭EiޒGxH{ǓF8L~ o\exaG,n3iuw2QV̓[6fe=;_tpDt)byHš2mDJ`$!W26 `)i.j"Bpl¶ (t9H(:V@n3WUsXY_?cť*(`jw, Al`B3i@}`{zAEQ>E㥅EUb`gR&i&Z2W8V.:`ZsG,v?w#Ѽ]%Y !.qѪۙ !0$v4Gzgwǒ#ނ,Y/ &U5Bx` #)#nbCQ R*ШF}%,֚iR0h$.':*o>6;˳yVLڇӀ3mRŃpa#&l +h8AlN<2~#tLm;4O<4pB[^@ @:[XI6 c1vqOR~ b H@;a$2.CQ%b+a U݃E6?t`#ȝΤѝŭ.=s[ԜHw.wM F/oO9zA*A*e O76Ұ8ru莎K$ "9}ݑ_7Eu+ f4iIkîSBb֝=62\D$G+2{gkP);ZJKc+MVcqdLyy 6=lL ѹ6ni?Ÿ3y5C|azT|tpu-%'Ys\ˊ7,#M 2$ޙk4q:ڨaS}ٕ"kz"f!: M ŒzVQCA wD/SIx? Y%#g2/!{OfZջ螻-@ 6Kwg*z} ڳ8Kdl٥hz^BL:9ھav fZiO蔂|C[cp"Z«Qb &] YOBNw:Hni&&u:X$_8e߀b!m{ 敕,! DplOCu V34$uܳT񖺊iD>f&4("/Ud]GŒ{H cŪz9H^"Gar3^_QI&̟.mXBimmnlfם'UϝEf^$Ş҆u -k'ꕹ߱ȑ2$㱺qE\˘WysY| [y]UZi?RdFfKG -Q*W 1xs5`:(;~8HH@>)z@ݴ8IB77^Oɻ'p@Qǵ8H_5oyoYQrp.c/x(ZVlO(6)~|cD4i U11dK8h9]H rx'HHALvF'>@;] :$W yuΠ !% ',b, !8eR^KS"Já~.?cv#+iV#Slpϣ7ڕjmXqOcnsBu_*1Gqxϣd-)wܭ[Z{N28!T|g+ZY![maog @eT6q_(D>BI>[W_Koڗ7~&zCK'Ċcv hԘYP .ݚq9N'5&κPmBG4$lE!'ܨ˚ -_im6kRXY[_C_39)}No<¥J'cՍfRL$Wg!+d6m)nVp ;UTtD\}pM9r9<5K0K }`StB>fr/4c&AY=n{}Y58f1[)"']h;=Yf߄rЮNdn#3|e!Xփ59Ne>Ri#4G|C^_Q_>T:@bEU=v!f0eף"դZϐͲ%m,癖|6Beľ\xj,UlǛ8>քIxs@0YquArrh,s-{pgz0KzBZKU/=bS~9WQ#cVdܜM]ي#FPȾ_xutɅ |$yBZ`` pvoDt (+ޚSt;@UF+: dj Sc Y:RHV;啜 mx!_q0֠m6/]G"o孳 Ce~P}t+3 C31N^5'Qk"6U+ؿ:cBi)xV\L!}P(l.mˀV;JSlN=y~poy9BzDH#/( U;,J%Qg9,Gܭl2h8UC<־ck֡0"UU,w8V_d $QNk`>oPᡝD JP)P\3Bm2s{{'?޸{CZ,H46(ue  ?8ӆu Оj@& 5y XWk3,f'b+UV @k ;*0&5G!^C"yG]I1:ecYZ1 )e#[_{B(z̄f x=ghgI#zICqφΌ$i"WiL1Jt/xˆd4aỔE'UߴدzK ^[C6xp&d[md f] plZi0OylO溬BXqi9{;vN)ۘJc={ߡ:4Yy(04z턳24ǹd$%Dp@/c%`7qo++@ǸÖ Mr#هKf#Z_encUe+ ^~kTs:gbe+@9$'XnrZto`?r-#j^f8e݃} &41 VZTG(Bߺ2#Ѱ6m.K'PХAd7y![G$}P[_.ĺ]_tU$$(*0G,l@Yl㈗y6nH"}+H6cNϢO9 8ŃwR~A(U׍䄎Rȉ%$Bʟ]:1SgT3`c֝iQ~ vc*3 7mZ Sf~=+ߪ.FvS[hP7Xn1t̏oRhXL4߆Kr˶8*0eR&YSV(3"ڄ0(A<1`: BN  h+-_=Ҵ܀ޑBd5;%Pl\qɤh;4K ,ɼì$~!9k=62BIXpq.QvVhp*$}\~֏/L mPzBF#Y׻ GDnq8Cz/B rddRkf*(dﭫ6Bro#}8G%) bww3S&()RepFm,$hF2uGZB_Ќ@uc v=.G )G_0m@1#S܈BNەWrR+{ ]> $jF'P]sNn;\ aBK{؋ x|8@Uv†1ꝦލXF?N T pMeE)ezrj]!)# M-XLh{q~RBPgytk X"˭'/t 2[X hh:LM8wPU.xw+|al';Jaǁ`cd>S ,lOz裂A@S*heٴ̅qCMn` H4t"y5[3 c4<{Y>g<%>qF!hΔ>tWN8>g:" y' \v?-|1nqL6bf˱Ǒ_H*ٌB O`;e!H`/z%ml"QGS._<,M 'YXFzyJ(;Jeޚ,n!.8䔨׽.hH1&4SgPЮ 7-?x-T![,Q-/(}Kf2xEh񾿙*#ӣgQ\ĥ qz+U- ,~m!4}KRz53sS=]X5{,:;֊QEi {XW~=C\V#^tNxNz:H(I,ZLeN<(nhڿKs(ݼԃNSC|h"c(N"Y:[HHy9>\$Y"Z ^;8'1g2Gt~U:]L]Y4>/>~ ڌl$ 멗\nE qfcF?ǫ=#sn"NZ^)Q4ìFe [QoU/(Gnen-\: 7HR˫oW*2(dշ#hUpvχ_Ow2'|Wi33C˽=i[?=oDVm'SSBkVrq ?+v;C;(i+r%Z_<5jȉ>g&LoE|A ?ɟ>qm&KORĕԹ䢪~x?cx ^ŦluQOϣZ`y,B+1-[V„ʄ L/>;:)u+_9_|?M$>P TlPuu a5%{rA5דF"} 7kea YYLN>].$vcOtO2X8 A\R˄wۓ| /,7ǿQz6,r$t]'?[U>,a[H rAG33r?#.ڀZk)VOͷcA Ȇ&(D:*=ٍ匎.*-Ӆ>>,r~f ؝﷙0M (m 4boEQeqfo}@> 9i8ڄeͻy[%12<نu)S͠o[?urocpBUìUf{P-ҞRnUu:ԣa cZki"m6ܻFK7f\C"VuiUɹr ;<[bpb6ɀy83tT2:(lRQB{CL^vJpM]V$kᄌps7uyRV2g'5 1v6¡iOhC3G-,zn{{"q@&;þ)'Q]Nc6BLcÉ ؤ`6/ |!={r}.bj@BR5`?,#Lۙaj cnW|pkЇ^/8%nc{ v%8>F;b"'Fn['~I-ݤ'BLڣ=Ű .SPt&j`Cf* `׍M@߶Ĕp!<^ަ^ֹARkkqWoUlH 5ELm 7[otcd!U\@DrH_\Z8hYV{muC)4̅Q K9J"Z܏,$f5|Ƀ#ʒ=mIqԪ2t&FTz8=T |c|z}-7F !|p@% #& ThKj/ U7 kэ+|<_.uZꘌ)|PX ̆OL4!E7$So?kL3é]1G' [6ɽ5g۱2 ؈u<%Z+( ֕҇qu3DFl"y"yNvV>_. XSzx_ٽ1a+lCO/f?ʿOi骠`+O-}BfbOܧơNZH?_rop0NmRgl6Twq97 -;c[5-Pu*:I Ofbyd1·z/|'Vb"MR*OUlF_D>V^t:Oꑬ4\rKzоsyuM*QֶY%;AH $".<]߫J73u}#@>e8؄K\S y+X-9&.K)(DkYIiB:WncPUK^X+֪r]g/m;0\ V(v[V%BPL=v)gR.%˛#}9me_,mEMKbQw<6\7 "\݄rt(+A׿ 0 w8;x#?ejH5wb f4oJ˹]3$M! NeChk!~"+گ1׌ x4| &ױ9y:;V΂g;`/ {eUr=8w1тZ된E$ ~H^(Оlvć Ujd(Dڤߓy+bEjI'T6WJQ$_Y]hˇp5--fqvuoue}ŬL?)^]g޴4/k?R+cawmiIM@hׯ dwP-qJYɌg+qaG& mr^FlW=Y\k€BcͨsKjIszt j0wȅg4j3]OrΉl} sFXY$ ,![3,lE5Ȱ)e^E|| |Hq )07 r|_3|2hqVP\H9jFf4$&1#]t fСwA{(hR6ޫy }=žfߣQ-9K_ì՚W {e > ܑ %̢mqx_n4JHcmy[Zoj!@Z#1X2~X}vѤCǦ@3E|D\ ԵBӰ9T.|0b tV<- A%qyHJ;,f}1 $ zWٰ.NS+A1ut޺67ٙ>Z֟S>Qؑﷸ\7e쮌Wv0 Sjl 7}UFjnu@lr-F? ԙ8E~j4JBlZ0.GJh`Gj_ t{^ufB2!8wSޣ \Wxyĸy,9hmhIl[z~Z#lRT>#zeΧi]%97\8%2t7$v>^ KqS#k k)[M *~lsB3 =Id Jv J)FW8( RaE3cmWX"7߱X6o&:=?aetl]I(px)\)^zV2Y>10[ %yaAsNCƸ35Ӻ(#yŨhiK#Ab5W%//B c~ Fk % u`&l2CtȊnLZ7p-czۄ{0OGqeѰw3ɋ.J-; T4ݩ#ʔ *wbݨ:/JX>v**aJE&zYnTm}b#qx"T۫۹#OA# f!6!yZ $YRO$erSWŞ M '1۔U7NAh[@.貿ss<l:/chw&OݧcsWiEBːMVK p p]\܃!^hJU]6_- D;O4 G}yͲ 5V1Fpƕnj>֙B*/$' ypҎni t8fl LػY@@Zvw+j:ڷ%{jLZ\vHwBk.O1]ޗ\@*_IE7ѽe9b+f"V^Lyu=Ld.H0Nm鯇 c97A9ؼVG WTdhSL&j|Rpw %r0AY5n#hozc!cXۑwpf̿l=΃=QZhnHgF :ۦGLt4bPlz WN7n&X ,\xO:=O,XɆ$F\\%sfoZo Z1 [@bH{mPB.&XE?WVSЊrK)΁S'owgQ?2_|zE!"p)YEʮh`GI5A.޺k2Shjzj! RRukacik!uo%CbC\r^opg7ܵeEƂvx-& 4|ѧ\Wn|'m(ZS >C8W~y`dLkG~6G|L#t:e:=a(\c"2S;Hm*×tRL*.*߲>`kH1*ᆊ]g~{B*\x"a`h7`^ƤuX aA5b~K"hiS{b R*z^M۬C!l>0W7Z9:sHk-mA;~q=jp{/L kihW: ;e,<˕G0>=v^=w{4Zfe4Vvζ|W>miM@9% ?f*#;2*fub2hWtޱds}rm V71nL޷:5ρ=þF@'*Ft`mH"e|I07F_fy ?l' > 4O[MCh]8>`褢Dqwݧ`'ŧ(&k%"j-|sB{w"t$ʻΎZ˜`︝k&h< aF4$hE[m'^7ݍ='v F5KYZ 1#hhrQ4=Ti4 $r BV˄w LlΝPLGE@}EZ_?(鴔.Sø&+ٻ ʁEП\]44BLUر7h@䔊Q2FkRč2*@p;lO 1۩6YڇL =N1NKFYʒtig2* yHur` RdZMH|[[^ hnOۇ'@(KhGؼ蹴Ǻ#zFNrm4V( vKCF|eML 7DѧDD֟ Ih {kSuXBUvFdŰsƽ2~G4 X\w^ ȏsSA&iy4DKpc@yn1cyI_d6aS|a4\cuAɥHХ_]Ƒp<5KfaLX!at%}UnGm1/:!WOԫ_#NyН6ײduDxن-@mGz5vsJu'{fN~UܸSA?٣z?`Dt(dYV/A"<9{%Srj^rơ WJC 092Mڀy|Bm:չFRXx PH_DžϣDec1ROyMJ`,ժP "< dܥ0;m}o+a Sj^on+nD8 oX4[LʴYfKaY ~3k:5\MW4wm2$ЫݎϩJqm%颢WZ]UBY(1Sɺpx=%hսrNb.E%09¦Q>;G9:Ll!q^"絨l?MC%QAxk܂JR{|mfN0 y?\b)!#5?:lQPYLAo x8@eBU':"'bx,0E oJWF)&pPwwUZFu -/NZ%̧ V1BK܆:3hn?e5ɶDxcNQbUX.9; !źL6ןGǩ)m"Z>|>C%f c[h|lbB3ul`$ͼpe;$lՊ+*im. /j5>/4 &'UKv4ͩdSպTob%+T\)_7 4̶arŋl]HWLXjUjLx."Pǜ=)!p-3Jjbfkl WCD\jm-Ax ?$ sp1(MEWE^7FgdBDDA"s_o5TN9\?UE>R3r ¯Gycqz"| N:q9M?-{npR%H F:B -''KqaQd] p8P0QI' `7m -]=8\=-t˲Vx[Um[{x*lqkrKWD˱3Md%҃lK_a&5"D~YjIGŮ+"m)H͔7A z O(@eN&r J1BE9+iy SBfr&fXH\nړGaLЋ_}6DRy(J!;A&zծHlKxmRE{1mYzOv5~bT޸9ӀbLyhh4O)!Bމ/f "tzz3 ep7l89aaBU:@6_4gghZt9%7Oګӓfڹ'w4zp{^@ 4F+tvOby>.NLOE.hҼs`.@}ӿϵ3N}t98"jqF"9"nr-XDg~at e|]K)@qV>{ مKCˆO6;jA ؑOHr^j[m,IZ"%auk!}+4wG+,>(7Ak ̊HϬLl9'"z̈́#?6yOGÊC\#ggṵ\Q/PדF- K|5oy w:8IpcN&_,^oTe3{z fz#x :@;+T /%7` v,.qSzCF("ⵏGO`Yr*WlTբ l00XVSNpZ9ԇF7m:ʛ]=DFӿxJi:vZCp$H^Ɵ d۔ 3b/6\frݮ,ՕC&P h^o3omIZ8q'1~i1Z":;F[U3rQހxТ{_pfrEx0X_f"1anVڑm\z}otE8Ҳ&p P;%#^fjG$jP'* ұ׃i=ĴSmaTo$ k?ǣ6q"`e?41] \`Z҈HX­~6,'kK6sDla#divXZ֓^dָ`ViDWYN1:eЙ*^jg}8iUU9)Ge'8Z$MS.lu΄Qy߃:0UE `|4QFjg,f|N=pl7v9HjRmsԐP[cLbՍ Giu;Ρ^\;YtN@6 U9ôP'>4qP$d!f'kݻKeE2Eԉ9}qQ头CsCF_*k%Rԛ=H6Ic5˙kkR{"׻AelcBO[ƿx'EQυ㖄0u=:MMr4[>AcݶU+ yvFr`|sa|i"#L6kqO߾qn!qC`?9ޮ׌Fp;#6o_'z )j\^ոO2Io֟0ߢ&oHݬI8Ehl,M9KZ]𿀇LL2^:  6.<ĩ3I1.WXF3Qc@;i.mgIr%\GP FYEtٱHskԣqV{H|%Q&*-3Dϐ ;ѩ׃W'*Tc uΗ9ADEԑI'bةOoCøeդͳSy#{HUb\?)cO SP8j3$- ;#a^_4OU$Pxا-,̧a5|P5g Hd>8U_ó ?Hְ6dXObzkqna`=2@*͝ nM[vO>Ue5$2T.Ud{. cJGD4Øa^t.ZO5|sIΰ:4Ojʀ$ji^X-RuϽLt0U8e@uRA:qR5@&m¾>K &(U}Ò.>nZuJW3T";(bKD2{`٦~vG,HTUV]/CO>w |o^=KmxqXt#X%:V91Ij|h)1W?5L 󙇄2u+M)$Kl϶kS8+Rc:ogZwS*_ t*ܧ?u]2n{ֲ^Q~տezUBR':JΠGZ v6sx«}/k4:b|(>2rǛi/9d\O]v:j K{R]w5м rKBZtZ5frU,rT=c/|x|L ug:}I?pE6qXnL:gjJ%*j/ljhVȬ3a S\)S!qW +1E/p昪N<D k[2/̙J!Dd)q<8Ս9&`sbkeƥflZ7144m-\AF]0 mΫlX0QDǶ}*J Y2x Ř`IU0CVC|S\z'C) ELBrl1q/ٔ~MA@6Q 7HgnU IZ<;赅OV|bxL5Q} PRsƫ0zUh2RBNU: 7 <6W@sH'/们wĘr|~JV\.aXM'?2./pfV@Go !l7#PJĸH =t9*D}[oOuu4ϰ6 KIk}"NM5TwwԠ#+[s9i%l9pTI݇6'TwKX-}3O]2ǼۮV:~˖+!V9"0,a<.(XBN0ݪBٔ~@~WA$1V@6Wͫ }Z*Ey8P2T *cLmp!pA5 ׆Lم-ί'%Et%MENo(fwm(*f"ClW5m %VdΊCn d&"!(wqɊˣlR6~31(1;byk&_:oBJԓ+j!ݤd8!.1t,Z7FQfBcr󁩶ZG>ƁWڗJxTYjMCd* Gh>݋_V'm~#'m諤< VS~QsˮIfyip)Oa ͆D1Djʍ`Fϟ賻nC6'mof|DgV B큱3΁=LĖDM;Ŵa Y*p#YГ[-Lk○ b@r_AX( £b_{hVdj ճ[]AglR)r:LGמ¡rl3N6-ef5vA|l>s唏gIj! ƣݨTYkZ0mZ΄;ExoI-Iţ#ﴜpsJlVw=A }x"n(r NLb]<`b%c$|bi(+,AE& N[g> +xI M IoݽlӢg/*7*WywSBe*{Wa|[+Ahp_؞ddkfAT/=8&Ao4/ռ 8MrZc}[.|qy5W/6׋h&%U&Z%*!~l`:k*dfHzZ`Ly`vS& e{5Ȏ]2F0v H lu5c@_hs`;G3  (ҷ¦9 Vx@<1g q 83SC&]y3.puN47H@R{ _.a#c5k_п s@cICv~HkI SIU-Wi& >u͐khV]\jVLKm (`D|ZB_Q~_nh+_N`EG': vsZS N&7\ݧȝ84ntR~l)(@ʯۑ^4&n˕0sO(3aӚs LfAi5t{fE}{ Q(C+?#xTӚ?u@7e U '>%?ԓ]'ӵ5śy#VX;,(8|WWێ;R"aL |Wz$)}{jhK=jWX fp=rf_(iXAE>tQ횭˾ ԰vfq-g T5\A>j U1AE΍*M2y,ܥ=L/c_{؎ἄ6^ԕ8e1-)(q.Ω#P 3I N8ClaD0dȓq 3ڼ*yerޮ%P3Ut,}D uQ.{^]70 ]t:1P|;]ul KEMv E _}2tKPBd"2]1Ċk^Xi+_a-+/%gi&D9tNrc'>t`S P3z,hWw4蹝D~Zȿz£_'P!#S~$3ݷ#& ].ӥ3HЫ$ -0aIr\4A'(]K)0YQ|Jr]#10Pcp$V $l*A$b(Y2jd|ĩ+C놲vյ9 V:=<AUK br[T 3|zH1 26nټgc]V`'NK|/;,@03; LgԮ ?tFmM&oT u*l Ou:Q],hm1י7#CɽsߠIuotjn^D|cBdWkPv6.$Y.i|Tl<1PkWuĽfsNw`:C -b灦8 ',VOWxF9fH1-)T!X ?dm/^s" 6 KT>Qzυ}"BLXt⌼xbJnC|Kf<5 #j.|<|Mq$ B)'U8VJ|JDM_H`lR*^ƕZL]YV.\\5QT>e?%ww z*#)/Q84o.ӳT501FԮo\k`U3 eO㨣y~ R҉Ζ. ]qeOʂ|FQ[aX̼0p|\tJ U!&j3BMߵъ{0l_j}{v5j;t Fӏؿ}XZ~:.K~m KZjnY8:J;;H^@M̐i7iH1RM?aNj5m8i9|3rKQ&(!#I+/=:9pYEDZ0m 䀤}%{%!An˗P\yVWY%$o$SJ{ _<ָ66ΐu\2MyQK7=ixa1rz`RþMxV/6CӒ1Ne:8Hl@YmU s 2:jCVG-xxiL]k>PtisOvsz~A2,<po>WەkDQa*6=D/+S䈃_w%._s^<:%fzHynWה9_e4|r"~BOJt hgru} >HC+ul7)M :3Q"_O`2}vzMF_mW9Z$ꋰ0VQj@\']wBZ3]16c_YE4#!Q$(`6~߳Z>VڌTl1,kp",[˛CZx{%:N,=D/v߀er<ܴ 06`tI=-m&$W7{צ/⯇E$rp8]=?7¬HI%jj#Pux>y9#R5 9/8K+Bº+ NwAiC,-sK&n*h^%P`wKҒ.c/8eA3Jwvo?L] &"yH*+>+(d)qä$0QcG xwȋ-7hB,t^ =7X\a+0N )v46VtЩw:=brEH)nPPȜ62{k_;ֳu.۔a= z]-͇0u>cŦ(-G HvY%S+{Ulqc#77yHUd?~s̿2I^׏T%gBNcvZ c ]²1eZ@m,/ Yo9۱| 3`r?KT:[S XGyʈ<)`C&1*y_ r2_FB1eL|n9k.F_Z%6)p2ry_k {Ȑc_g*rӫ:eЁȫ. v^T\!AZ+WjxᦉB:UT+vETjYNͯx|M\QG=x'n fFb}C:Nh@ qi^r8sӵp6 IR %r@TE,oJrDgrOb\fk q&tN0phpiBBHx9_S5_g:?oe}PaI4Z1I mmLC:Fb/$ˬ(7G{r[_rB5eV<l&M(K&]X樂0Q-p%/!H~I,ݥf-Dls|P|:Tژ.*|cd|C) &RBm:DN!i~HLBfhDvUbv*6l7'˗Ĵ{asOHvKx\ ʪ>3KW;We2:ܤ{mÅ1֙ ў<.%%~6=acPF E6je8)Q6Ƨ7tǠJ54;?|S):h $OaZ$JÝe׾n$ߪW`Q&{DU oMn簿M\xlhuAw'Ws1A]f&nS)ݴSIPU0Tǖ!(n@\騟i8*F]Ԡn-{M$yB2}фEWL v1˩Ǻ wqvL1O80wOvjazXXSpYNE|= |eCjw=dJn` n3R!.mookOKAc2C8 *ݗWC[2RTRf?nEWTK+챿ì 49e$.q'0l|ĔDK<)ݹh3qItXڴ ,nlZSnd;+I K*T~&:#}.W}A:=漯TT-9\o~<$}^ҠiA '+m;ACj*B^-tF=o\ o\lw* $ҍvzsD F:*(`;(<@6ո/ؽ=dlR%XrBDl.,,c4gIT0 NIŨK5/\ SJr71jr˄n}>bGT܅=3<rZ|2A:of6Dž@O7Pdѝy _kK9BJ AaS. 'sP͈jgSSALzA8F6]Aq")XAׅT)'{KW%YJj-R/G;Q<꣨Hβ eϬ](7TRr9Ý^uMZɎa6>o~{OTA"IHbjVXل7mڕx(/ah $q~{>7R/'iMCx#Abg:Lb~_Cu".tlvvHM_ckY1т \:RZ1a#WthD:֠BSM|@t0A Ӭ"(]5*%=C8!o-Bb[fhXdCpk莙HNu7Ʒc\$g(P* q^~oPDaByBcPRI8Bt ]T#e6}3G2`1Jo8zD;*GUx5[Rvhݍ]W, i`@D-R[ӥuCKksn(Uؗ"K#9erBMԶ2:#1/Y%J 'v9>R8p @cmxH]z*>%l{@([DHdQt6GɯnR"?Z"3Bk&%"97`yB gMmQ. (8AϺ2_z^J}'97u[ VkF(&=14S7'*V2~˜Q<(ʵ ƶיcGA&̗ Y ?p@UnK-(`x|6ŹG&F~"0ѝ+4OiQ3G A~58}sר~U*YЅ}/|weiK 4c$_<آ #W)./o)0JȢGzplLsiF6++  ZBvf kCv?/YlE;tR&|DI?Jtuzާ4̓udj ϔ`3wx3iTFz~2G}<{;s/ eֆ))7FB׾4gxa‡S9(^L߮X|@E[W پݻM !^&v=a97aW N4io+$|l/rcS&ˇcnL=T@$ Kz<.A-WqR 6e릻m^ϖ%=@V2ܣtƪS6Y~>R),Wx^cBd:+XIZy}+ ލ9SZv 0mTo&c_rʖα%VoTDT8Q 'hf6mMʗ1z}9or+71J " 5F`RT=Pa}sb[FzԆ9 ;ŧB"6۬%IH4&?/C&sgν2:_Xyx,Id,W( I/zpdxAڡWs1wF2)9\0*jϯ 64KPK9}K8^W]9E =->色crKR kE/"P)_ ʶ JW:]W0_od?ls9鸝#xy 5GCZ^mL\&B"æ`Dc)\l`s" +V=_ClIsGfv_ᮜp[I`gwxUh2Rӭ[cS5KAVv0FA5 f7hϯVpjx]| IG|l$2?Cub]AĀ'](( O4a&_'uRLT _:WqNa2YQzX~E;iht^Q$CYPI@6r"P`i螽a]M)hϬ:Ru,}UvFִL-jၐ~w)_4mz2^xжSEGijiY ?D xJ//0=1:- \Pm.4ZΛʿSFK';; UR3V*9UA.T*qYW聝iiD#8G5ob6dӣzrwn|Y='naTEJR1p$V~P/dY m@jʀzٽ!`G? MB{q_1t`~9wά)T g;1N)ll&pW5E<]9ٯ47$jt0ٽu" hL|s_`9침U Rr,jÞu*$T1$@Y&] M kM0BdVC5Dg4 VH/;%[0;( YFwaa e$A^^FaH߈}v}fZ- 4H[h=y0U ?Esѱo"^)0D%l8wܛX!*c9RBu1%ZZc= R&t56 IxxOuul5e4끨uSk 81Y0 D}C#ݙܶ0g{ mw\g.q%uDcia!Ԅ8T17:֖b%yAkLDsjS֋N}G2_\|œ?2wr1l^(D0\lٕ4Q#{MIQ~pAvg_.ؤ%cȝ4WBVD!oBJvhy7NFfFZ F`X }59~DH+5Њ5FJ~_poosv#"UuNgKO ʎyH$PH5 ."e&ѓLJ* TktIk2"H>9_EV7_Tۍ u':PWdu٩3 ^xPB)?=, cU==Kcc\;`ÐU0VVJ7}jҹ6}ȩzw'. :*4iysH;p?lc'\s4teAQTƘ],c[UOsiZ@D5>ܻ{jϥZߌ|)tQ^=Nt)LTcDIIUv^{wfY!l|og";IQbODkFIx1 SrKdS?"dIÜk} xxļ9k+$r@iD6։w8[Ư..i~ .iY?L)'ȸGN RD)f0zx'PE4Y3r&bw2X m~(͌O*p}," }1:Fª ",䵃D~ W5O7l֦zlB [Pb4L(a+M5-`{$^;BD$:%y{ Kl2X"xF#d[;6Vą%JȤ_ J-Êd@ s%R!z—-Z_(H sE͌H{?8,c;D3_g kJyABNt~!eci&uˏJFJCrt׌z8 tHo_'eM;+,ާGouVUG3}B^pYR;9ź92 .#ǖ- P]b]eH`Z,j-uC+3Z7%rDwoi6>W*A򷒝`l!]Lz]u =:wYݳ@O'uk#hel6e݋nTCwҲG`uHY#)Lgd`o0-j7TfPxV$$&}$ٸF&oYj)]M%4싀| NdECQ>Hw?WbC F|!Ѵʵ3xLHwYYi[ܫFD# ٰ؂=Mŵ7R8[*!]"VS'Ix-HMjyl@siCpuq-4x0OϤ0J{*Bw)9cAͯK6d2[^ޕ-jr̚u;f 2l[e@$76uF tk. v:xt2q,&Zk (4?? u|^͡sΨ ~`?, G# A3Aۇeצ2u2fmϻṫ9GbT42S'!=w}~\,ӉN#v1F!Tb'jpQ*a &&/Tz6*xR-ν/-wGhy75M_.JXʒ e:Kv+O;{(#5}h)0r (x9a2ݟ`uWrnbyõ]'`ЂV3ϕ'z 8r76:58"l`h9JdN@P9eӄux1 gpaϘ"6ݘkeġ32orQ/XuLFj0Y. A{rТ1,oAUxߵ'GÙ(mC>e qGR+C-& 3;BfŠ0la+z؅.0-٥>ՙƢQ.VXɌ`pybm(7lfr<@u&;t@>6љ ڍ&ϛhPeXSm^@4`-x 6= @_{,i/ga/[]9c g]+ouom _OED%:ɂÖ]]S`T3&pӰ'H rG*Rjg?QFփI`QhG{\wF'N=W@N23CA7"񀏵UOx"q4O \B=AdmEkfRq'aRËBP#rq:J|u]%栖iGnO69y{O :0%:>pWN8KDzaWܱEv[O&/y(dvfg|!^]Q0JvQ>{LB7zt,v2NҗSr0>nN?t'K%Ziq AA{;F-; Y2Lȵ t]s۸&RPSO~2_g2=M6Sei@2-Or!8Ev"N"PROId)x_L’B~OWx'DOunB}ţeoQ—X"q\[, ysO}ßn33yXC]pwp(ܥFZ}egQX +e&хMq§m1g0Mk!IJO-%_(˖+am )( LNw DhbK+&aCPÓ1<pgԇ;,@ʕSZ8r3`~cۂVn. Rgw㮔#}J;cxLpJF ^OU;,s!i\nkbjWH8A}n~fqIP htq6Uę~PZ:m,dKMZ I-XA̽ 43cfdO/W&JՊ @[.k3VfBi&!@ sA;=;e-~&`<Ůr'unU\mWӤO\\hbckNG\ J1k#lRB_ qB, o84U5UЀZװQ SydpEsHJL-3JyS[yF3Z6JYy$ pZ $-1=l ScI^4EhToJ̀HdHf}`5y|˿@V-Ѳ֌$~1J3r,Ȥ5MŸ#VNئ w] A]ۿjEμe"\3/&,^eVoh #Cu4K\S`7n1b%9#OMh]aH4ij$/ȸU{eA8; 6m5@* ̞oΨTp~˯8 Wok !زEI$<{M U@S/ryG`(C]f}yX˽D^A8| !6`h 2xxKPJ}!Zo|] \L\+yr=wX\g TœfhUfoRe4x-2_UüC!̵|iAc^TŝO=ί>#u0tO+gz9Xo". ɀ|*%'H$N=Pd J,نq }2r38cdfCSeEUn-[{46!Rl_lڃXR6ް~Z{#vqH7wD&3UPƁ>WIshw<-ziռst,5L0 uuhۍux(!$ 鹕Ga3[> y5_Iq@Db`H7w#bWRJX[:쭈^z-T1Dw nc>1.Ȫys_[9J0?xzhemN'4kŪmgN~}|!b3Dcĵ&+AIPg6[?o@c*̢n[C de<kfyb" .1Z< yn#Q@ ` %Լ sŖ:+,\!|JP ^ne?M>H=3XM~=a6%jD>Y,+Sg߯X~Sf _fxU wcvO\\~,'"lmݭL`askm>& u#p6B01y8?NVJQL_cf=؝^sN նF[2fpr}qϋf$Es«[Xljg>I;sw[!]nm4wi^*nZRGK:=]&^js1 #fć,lkMua*&/vBѵ}'Ot Z7HZ/Hv޲֏׹b1rmM# 35׋'~5tԉ[`r9B(1{F@692pTm5=/&X>]z+UPЙamحO9G[Dɻ^fRF%Eϣ+粍v'rф8}5V .eQR ݠZB&~ :{c~9t(JU*QL/ [ .Pc>wxÖ7w "g{MAB(% E͸92`˸2l5i  W ˜yl+=S:МJ2JšFvnႍ{h:s[j9BmvZNQ[JBs~b6k݇,$}RSq,cc,޳ Cv $5Y= ᾅӖĤo("$/pM7fĂ0.cx"( ^i)62qa,G'ȃv$n[?`"leY&he Y[ "*rNE]:d^.3ػxR%Ø}$~%-*ѭbvR=ҭ‘%.g!s5 Ms00K@tb cWg Rd ̉pieO>y(_6ٻ՗QnDsi:Ҽ:FGn"}쯑y>Pc.(d{/.Ҩё\c#K,т i,&lG4Cڠ FY+E{u(T{`^r8e) #IITU$ d!ixӚ:DmVGɃ瞝;>}xġ(eIjxqXT.xIьe>4;!#'\MY{ /QbF5J{2tWwt@MtԔPE΀9=a^4W>X%+7i,1J{zF^Ci!Q)|MYPiWAfQ ij5rjy#wobX;_L~͍򐞁_.*H2 Bˏ&1pMÙ>wOtH3jq1F v(b:45v&H[ٹOߴi3$`f921Em-.B|05$_G>J&R _Zm׮bV ɏ"p:*62Di;mv%X4ZQ,ϣm V^Tc¤.v%~eicJC)̡-qF rxv&$\y{h~N]s?VabRpp Kebp46h I'Qо}ϥ|Cki(Vu˝[&Yt׈M0n`cȡ@9$5sC!A - LR  K7^U4;gjӪ~1"ğIQ.bbzs>Cr ;Z+m«.SXҋ;뎇GGDmTM.唒lr&ZQ#FaQrm?J߭!à͵,1drĜZ(l CVJ6tR| enHwj!cr{9iv#@;wYDdKA:o H>L J "'=7V5>'Ŕ?$MbECxWVUrFxQG6V3z>OnIm;[{a}$:Lr7WR^!HLJvvq\2Kَ,Ⴕ3{uJ2p-,N%6/1$4y#18%Ȍ¬] tЂpߝL/RfI NOs۝5w!O6!.O؏YosfCRZfgFg,4,4OreFBgh(ֱD |klƾJ#)eNd¢J!u}#fG$yߝbi{^깞q]1;;9߮';;k즬zO,:11LXʧrۿ xie`\鸣1' ȝeygҗy]M̻b z,)Ec1^!Sե}66%\?].]tLmFY\|Vܹb NlZ89)#Xg8_8mrr:j7";_ RR~%X=Ѕmժk/AhfB]){i֒EYyɸܽ

&~zק4`sQC-{XɆşxܬ~Os6kZ?6ۃٷ6FKӈ(hC7z6\Yfvt\k1荢wG=ېXޅH G%3 j,yaq‚ wνHYaڡ)z].` hNGgz"0~x|CȔsQKJ3[I - 3uU%f~JǚNlA%w?0%%3JGq_ o-: QnWNÄdr*900qA>:Iu'cd$p$dJZqO'-)s_73rV ?5%AZ$^1iNtT߲^opp\ޓtd[x5qb'(Hywa% `R=&m"kx6 4,>&v'G'ɻwKL^6`aƢͳB$K#Zga6b0 $PЧq^#pNi UG K87vmJhA;d[cO)Qn|1T Lip:c>7C㷜ÖHMWSޙPݼ٢E}ziO7IY4FY`u L\h*>X;EM;$>A.njv/SU9Ltᆡ8XS8"7Cppn&/))R풕hZLv!# O.pykerCgUD5fPV v럯!({pȂ"ydMN()yj#CEGSꬠ`s!/5䬩wgYĶ7=HfƴHФp!5Y"Z ٗ•8Z(VBם6۬dz[m"(EAE5B:CeQ:tb.mox$M\O"oμB/΀THTMPDJCYkjBiiػرNw(!L$ 4v_X`:IKnO@]g-?IIqAF믻XfjOɑ^z29#JM b]a%\9~SZD&s!,Mf^a=*.[J}0A&5b~PE{=[zWmmhEhs|qfd0 %wPwe1:OD܍K M|pRt?"g] ;ޅ/#,J 赁2sYRc²Ҙ 9R9*?Nk5RxFp רZꍒa8d&OFɜyՀ}$h^s<Նtl{,NAvwle2 o $_S 79;O\)Ӹ@$UkgDTM>c]/o9p%ֱz6wnkJے}k mlW>AWui8ˑyh1guLu!= 6s euVnW8:C/EbI2;uA,9<; m9D!]> Vie,\$T$%${2RaC(ϲ"0a[xR% D'^N!lq~#(k8೽ٖFrNsژ}jE"}ö4u*30x0l}4NXKUWk7_jKfdBCR?G;a[dOU?$7 B%c0ZΘs4>]9^TNWba!aGGpӡOdVa:$dr[YQ奊E`uǶ2TH U#"_oY0m\—>=7gy#u8 ijzain0D(~S1Ot"D;%C5~m._CL;8 +'FZۇBx3Ǜtp `}˔X Ul>rh N(G=#G1Τb׎`UF]ux՗xC/xحӤHrmz5;Z~ v nכ #F,}+q^j<X[8LDr}CoLPJ´ѫcuK,}h F 0Wn-GcnVTvu!F۠wsMq0aX;f"l\ e|A^,H|Fu C Yo^ar2{bWK|R[Xm持'sqdN/ AP`e>p iW)h߻>eK+Zcª*Mz} –#MxlL ij̮&!38DjՔ7*2( ŷcH!-8+b?[⣾hx[<ƻ],zΎF1E1FkE0q͘r Y;'MaS{wI*rMs zKu Ru%YoہrA=ZҊ 2mTT)KIpU6. ]\w`KkD@I$0ڼǪbF(]U׉1pG8$P\T:Id]߾ @j>(G[y7#+עzE͂wsw(`j⹒ DFSy>:(L|pwQ`H [>a5q85s}r'nA{oobձ> rƷw4XHN Rl*X@QW9SZW/AՈ\J=d9AAb)a!:v%Z5Lvbz3Kݨ#`|0j?з/_(h|qf f]rIVUqE;d4)9t)m9OJt1ʸ4G<{Fk:n?AuA$lQEWu֔ :P"P>0 MNú=Ӕjh-h؁&$`f!@@_6i,#Ifs)PDED`I;qXe2tHN/ dϓpTGe &an%{Tz&WD_'rJNi1|tHVoa|8\c\s@˱ē{̑H˙:dIQz`ED%{v Cz0 r8cklٹ 2}LeL:AôYT~8_َG; $2sȞM|2a>]@LЩ؊SVFX壴#pB:XJHcpTAvmR`0gxdG<'HQ/o IC6/P7TlŊ=#:fT!71eK?iW2G=UNGE]1R:4>bN@NJ|ҥX`y9Oń vցfc1u~ J-i\*U{RY+3͸xY`4S;̍\̈jXۀ=+9Q j+z^Ɵ:Dxi 0rB*co1K箿-xa_!lM!s}WlonYc~pent!JK~S/"w~ S+PoJqsvu u 3T ]N KυByO}4(NiZAOYS0u/za6Y $Q/xd;+to~̡ @6NSm7}&%G9#S"d =I \]m=j'7E&O=}}3p׿1VY723jאa)mZU{,C3XZN\2j@cڹz9 syY)l`Ա,^_X|ɾu&D9(rPgJ+TT9oI*&Նmcay_O<Ƿ12GUGUXKp`uN@ҮPv҆sb?|vxiOW*ѷ"SL27ہ6~,b +0'4^3pcPS߸~MpQ#k·Q<IZY^ܠ+`؍$Dgu6#-YecYXXF(la}!޲MyU],KGoہ~4X@Ov]XͶnqoM|zZqRAKSmTOm~z $$; jLnTW8[?PЀx_@3l/hGߕcЦf 9_8Z:a=qs$ABc(&P^Y ae: 5@k8N%n|0g7(o%gLyM$= ~k|\<)Op[ iM Gni3@1&1oZ9pu@\mXT80Dua[MRO"BXپc;c&7~oBj M[!qyIsV ha8ZSRD[OᙿrIs,1ތE9sk1ǹ}!N'Oq'\Wj%!7AoޔpQ&0쫳'\ҿ38l$(]V"B`cEy,玵7| Z*}WIJI# ߏ[=[?p޾+~CIA4Sv PִV5['na#}sd|-:͊9OzqXn &XqX)*jP*iT~| ߑjۍ4*F{ǦgYX84:W@mP]nPA׿3˒F YZ4t靂=c:iG2ˌn&|+j0Ԗ+gAn`3n[ӓ߻BE g^Xu=!9=wv-"+ʵg.=6ZN4\?(e^H^2+,,>IΪAn|li;3S%mL(ӏ:fz=[#;4|KKTE|Yk΢*PO7ƣo _nVmOU:rҁy[iP"dW/A\yo*1T!AM>EԀuGlz8|?UΒjǜ]k,O,TPr]}#w 9w8J<lDCh13gߞFO8|}+eȣbE' (Wb;x;A'N~ :2 d=,gë q"kA&E0VmFzp/\Nxdԁ Vu("PX˟s Vx^bcL|G܌*EuͻVK[ҧƃF.^5lJQI1]_m2; T"4J7w9 6AP(~K?1d-C-=@AoJi@fÊA D%‰3x.ouB9D~+f*4 u?X5ެNAoVƆLvњ*7;@6kt9 жr2ϘX@̵sꅨ, Mew/G=yÍc<vrlWu:PГux9myu4Gd`OaH*pR\Vy G:74c&!={Zh3˜,9R\ʖV]JH߱&G?c2V$ucԖ4Ճsع9TbWꇫ3Γ,܀185+~O2xl7._/kV~.ɲv/: xN}d' Av, $6ㄫrқӰ|V͹#d/Hfq]JHpWX zI]L y+SaClECigJ~,.ƔݛT~i70 ҿP%{]y1y99И쀆aa|>@eךP]Fƻ.upi޲*Qk y$Ǽ?O"J` /jS:≍ӹ2j,hм~^hʗqiapתB/x=qʊLAVu'EYra垥N)ѩ|јxhgSLs}@ >o%D~uimr9HFa&Yk#+̯8Qobo>qPաˠ7P{ &K`nZ.V|vL2/=$ ,KcDxi˲ ^ϲw -;:FtϞtbh쉠^<-bu\y||=i!R.f8Tkv>"\֮҆}nf^xm&4zPD.V'جF.^}֖y.wZDʈfj QdGҊR_xk{G(&l98Ɣׇ4=]8jQ:?ǺW_/JfY,r!k0NiF6<>c9[3s6 %*N"/:!ٙeE_OLٗvHf^p|Fϑ$!' w?4#Dn$2n>GەAt ٜ1ڀ5N/$nwP6oJ^􂽁at<գ:;HmVF*2 Œ^\Hkq e #m 2%bN[oM;Ɂ6RrKʫA> R2cwg4k6p p&! 2LE 0 Tl|Q_v+/=t6tZ_1Ⱥ$:ѫ*?!Q-HЌ*+QG#jڢ_ Qθ#P~wt"=D hyф4OκyÀ Rz*?] y%-eߠM~FW@@ŷ]  )XJ1Ҧ)-V.|s J|o^-<D7Íe)dμ8A,ZiiaQZ^JZ;4\J aAfz9y#X|YbojdgB$ p0:e⹔eÉw`'N{õ'?bfbfy5Cs%Ϸ2:bcM}S_&8PCEsgdӘ3rDq" lx\ m;;3,T j`lu*4Oֻ+$>Uƍy5ՇI`=o.5s KX5BH cm|A1&I71(:{c W8y暳ϷOuM_ϔ+2h;ǀdm^ tELyl5CˇٙI{ 0KV(P#v`}uSk1EuS%^VZQD5,N;f}_Fl؍ a#wEpTUljͺA?>yd{ݚ4]ܦuJժ2tH@L L s{;^Ƒ#ү!/g%W"fߐY݆2k] y 0 1X.ũaPVMm[@1jussÝ޸![\8~T_u?Ey0ٽ6xećF-g*̘{JEv[[XV8[?Ö?0` PK6~q7({%!.?)-~SO D+Bz'G|$[)+F*\g3abf7 ^ᵖ葀Lwcwy܆ \pQf*Bnح或ƆU 69LsEXwa/bq*sj5={T-R)sp)jټ`٪D4!WoV'):̫(Tk2sܑF7 PN@,րMF') ębQu=W2Va@eʎz[@)֞Znq27u9w=d<+ ?H1T~ 2r[]5* ]r$YQ릳MXpWNm֢fU`7#a5(޴J$y2o"*K1!cמȕFDs๘뮸1|%f0BiPaOA#`b)w K%[>K> ܾIJAAG2nW=C6NA$\F?ÿ2X'ҦSETpyHW]K ӻ1׍"8(n"3TTg{2. UO XZLc\3v=IT?UL}PI!l36 BkJ0rNq+ ~w>Hh#9JZ;Qkk;WY1aqGwq(/u(*3/} F%³#b͞k@OƲOkkƀ0z%o%baQ0/\d܈/dT|z:j &BA0&!G|9CIZ܇%$<9 %KڙC6`ph'kP.ixgc1}pĖG3 mqտjA`&iTIq,x!+ʭ~H'Ր/ QcN2Tw*o6Nv:`P"gd^%QOU wK&m+̅"Ta V˩>}νzpΡ7uyQ re&n?:19[n,4L:{U*y‘ j6ZTG6ŏ0t!S:5(D{ܲ2ڄ8hMo"%1me$9 'xwd6xkPx)݂ RR(!S))eAC=J%cu oL&흵aU0No?-̘O+/\le a*,RSߢ!KM=vp/l>L[P5=!UB"*1g}+DxEKb% %jLkAolܴFds]K(W 9+|q>x,bd kƄc(F=(%e2v08# o~((/Fq硏3i]O#_QT`u?VEt6kW\EV\y"yXğ\Sj8H8Znfi{a@3ҡܩž$2-{8Ʋ̼xtձ^   X k&YZ61X$w2Hqr!,-(!uֳ4>~SXΤ㣄@;T(4ϒ@4>,^VTdHtx`<|qyC#}nI/C_w7vRɠKumVi.F 3oi g4lwLsj<55`_ gA?gNCm{qdG4ntVa^# ɳWQ{)W<@UDsWJӁiPg(YnM /g#M/nH* Jm,1yM]tPU>gWOhvZծ'mS9&Z>/[7"Ə}{j `QF޼hHrcpäEaŠ*\:SHJ5!<ʆVc"%TԸdz|//g,59<~[3@*nNjuPjNcǦڀ9}eوhb4)Pz~oEd4w/} }h.F1Mmbw&%WްQe9ǀڸZ9UvPxG3#mP@K*$`Ez^['4ByUZ_⒟C0Ɏ#)WM49q[d&t{ JڞDȧCUawơ[@m4>[}JġXۍ2!  e}zQN_Ղ4{C=_m!x~~Wu t5yr?Pː[F܉<4bL-WMR}ʧA<0[ۀ*FNr|T_#wاp ;NDMe FwG]qﯖ9ZlQB;|vNOBсJ)L Tn)j+zaj8)ɇt$ky8L_ E2 P ]G~ )!:1$wS `s6KF5bBZ'=K_Mb\3g$ r)YF f#RG9wrN( s*C"qqtǕh~`Z#~M87]e9E$ݲRI7%*L}IA,R^>>O( ̙[Z[4 !kC+Wu.2m\uM_S;NC]" :fػ$v9GD_2'ZDovH9H0Q  rGT p2K\V桻3]ΔǁGvPF4P-_s烨sZ饕Qg~ Ks*$ݹTf^}yOgM#حq-atʇ/!dD D(.~2kM*e7>P}8xQlU>YՇ_Z8CLDQBo>0|=aiEߚWo%lnʛrf`z`$#擐def%3nyh{%Jא>9lz8S|x/1qWfWrW['s"#S {ú*twGF; =Aª]u 3R9}/?Yn 77~t'<7vȒfp.߸ r[ ա+_z^yDa {9lprg#{ mBr5 X\]l+Q'E.2lb;LqX2x- ?;tKòB4+2D#ۤv\/?e1[C} |"<[cA}$~cd$K?-iy0H s skWbb1el`:B/KKJ^1Cg"[Xt,bzc,6z~!vޜe>>EDlLsO.q5 78wY~HUDhRyud/ۆBv#=~Y/9?D(6K0,IS'KPO&'X9C37_>#5 VLKwUoq.`T.7,ᦏWrS;Gt2;]SxilH[>d{!?iJ `>EK?7NK|ZDincVK"8j30IT^P\܌!o  U9rCZV=H?a-GDޔsKe7)<^L,Q&uc;SVs%"؋1(WիX&`ï ByQr\iPw i+/|oy U .=!6dka6&5 *k/*f[Yr!026ĝ%^  "Ȫ8AtTbA]rhUze0:'a:h#]?]lIԑZ̫N}GwvsYyUF,[R)iP O/ǚeӛr:LN:5=AxyI1wFc9Q%Q=Wa5NoE·۹i[5j'*J>Oxe#]+R 8;!0lcoүBk@`EaV):_ [ *͘,HX? }qO]x] U ߾cQAB`9T]MWQ*Dr)df"O~jܯBq^hel8G7wH4 #ɥm5ED)R.k:D cJwzA㓬I]pL4D "UXbW}[1g U`[U_k`L$&tvP*S*WkHrJsV8vvT%U@ӔD׆sGT%{Kthq7h b] #;shpQyrj5viG>|X/dnb,i`Ts4"T\eʛIK+"?I=kq0WOtnS#Խq0Qe|k CQpbx߀:wЌ0RyP*\'# 0{:QD;"lpyZYgji1/^u2wvfJ%E_%Fh5s]QL)mhTiH֜ӀudrVI>b@d܇ LBq! sf0L"Lfâ,p{"bZ"BOm=  HBһ$8B~,xtzs+KdF:%ڣN-Ccok{ O"s|i 4Y<,zS+ @˯qվmZ8Js5Xbέ@?yW }q->,v-{] LTOD17N NA/b1z/!/zM0Tad U'Sj@Iu`X`pVJۜ/weo>~V-1c}ˑi^qңƿ!as+{ D Ц Hh3맍8_0g_h U:G,v# ğL$MoCiF֚\ֻVceƷ:SNM'")VL硃vYAp ;aCD$+ {%>7ȃ1 X0Aw= hwF,);P](PFe=`V2wh,R@4Վejwd2ob$ \{!AXq$Oup+m]i-I_>>T~ RFxMP['"#8禥%,•uPM"[ #l>[O} k%E.LP-OV;B5`q]G;&[&){j?282#[Wz&^(q2!ct髐{FWU_FN*hyia?XLs%_iO8UlTBm}-l'm;,y y 9O6'Rυ.ZaY$GX`xhDS{[D C-C1+֐z{CD; a΋B/ lCc_G >^Ha|߸R澨DLG'O9OvCoaK3+x ;+"ӣ.ӪFL@v_ں볪勭zS43KD;%lG{t~vxL[CU{!ORQ.X[#-c ِpeD j ̐Ӧ<2 2ӣ |LR+FaۀL *^k V4Xg)%@e8 uW܈q&&8D`'Q,3y&GW27]^:5)J+]W,b<<7*Iz HF[TCrfFVE%%< AS !++4k94Y}!8L gV#{p? /I֚${?0{'|Y!zwpN9Q[SBU8&,5hA HL%O7KU^ϵod nK!&Vfc}i'+]/PV롅 N+dM(ݵ}~ rm@-iÒ+&yvp]f%QP*_E~$d=DEdYO)!𐗲5,Ċ>,;HгĆF*&?Y'2Qw`pADV9ȍ/J*zl܃\ , _*dKSu7+b*U 4yEF4ݡK)ww*FQQQ}_ O+n <1C/Ġķ㚑'Cr+A.{CzĒ|Z"}6q".. j|[6Dy+>Q&a1P> ,J,%`Oi-)q)y0bh%i˚Nč}%*^ l-tξIh%4|^&ό{EFFyB $=pZ+%J!D8#IW6[\ ʽ xEGj]a}njw M|EWyBIGBED?0!B(rj;KMiHaYd7G:Y׽~ `5Y﬉3Z(! E:ɠiZb_|gNq!3j5W:bu4NCG`J"xxgdBKݱ"7'?h07R'Of=pr+ sL~Nqlz,_k[C Hٙ@-WX[e Io%,¯S~-gW܋ѻ&^t-YȰO ~DpxgSB~.Gok4G)m *:X4Ҹ! 5M\t}rfouּa3갡 TWp:Pvm ӷGL=!׿{#؟%_&3"|a{鉤eqEzIJq`W~>L!a$OGՎE m>{e_Hm|!#BЪ5mENā3IVVM0˙r7No(&Œ(3$y/Q{!@LeE9k p+U\;X E?CZtdEw3-iHG&|04vEef0޶uJ9yɾ^pa8|\q#Ƿp(o"z5&ԍpØj~>CeBJ!O6m!ýN#< Р-K@C$CϪ897Doqo5/f^.6+ʷKSUeIq*GnK 2Yeo ݄0Y4-~s-G%.jhznismh~irH71*\&(|„vug=:NЫ[B:ײrp~6uFUXH3J`ZˌG&DR9}iR16uQ[mG֮5qzm ق0rzF-;z[aBYA!{/a:uBA^`n̡"6Hx{mu[@,$eTt*R!gug}Jɀ.6gA˼8Wz_HN|ЎtvtJ#AǪC*S?pq(jfWԕDoŔ`< uAPeX< 'gF<D`ָlIl<y=%<'@Cm}|HU DvQǬnB&bK LPH"K g ?Swmw4WJӚ7ev⩖I>Vl,Ap1$8o+nPܗ4Rv>K 8 Cf2ÛL'6Sn9kP$ؓXd71}T#jmC7tHW",$kp̷y6pa_۷*x}bp"_xǜ/=5ԽM)p{Dܴ' ÂU>bU5&wސCk{5V٦ܗctd#< "Od}7I 1^ ̻@v<8Q&L;h[nq$3\ /zr螙`g,--;Υԋo=f; -Hfm?Tϼ8+3(#tiK%˭S!ق c@PH( CnM-|yq7>(]VJ_^+!" FsZce5d`gܾK5q1q |Ԣg5 K\oћXaMߓm1GdM-h 8;v3A?(zhO61nu 8xEsIc-b1` Md Ϯ~*V?ۏ,)M-pus uX MA1DP@2 ClQ5Dl4I?Pv*̋Df9Pӵ`ʚr_5`x=aSI8 ƚ#[}u ׺蠳/W nfGgXT0W?q ܎^qF_lʘ&3w1<7Z %S`$IGo  t_.Npm@O~G=6/%sD;c4@[u>nڦ2c1tz_LMwhcMwSQ,:PJj&Xtjal/Ok31J#yI!(yG!"m| b`T|}Mv+DE{Nm($ Bܢ!^ܰds|r09p,*o$l56|?1bNMq@e43r=1=͸Am'/10bl/8O[s3YshyA 9640w{BjV! _q+? BmjgDjorÿ4frcfIi ,t{܊?5Lj @UpXՀpOn[+rzBS@3sGp N;_. asCečע N׫AT*s0Ǿw[05 L]Pe|L^\_u,Nډ(qW;o5ʔw>oעTM|J:ްa3&>з'b 6Yd(RGtaG- 5nHw|z\gŰ^S!هf \)Sy+,|;Eru ͒poEtGk0@ 㘞¯$lHKf^8 )[2uZ=c²cWt/.X" QbA*z3:)/TQCDio OӶ@_e7Tp3: 4Jyb?h9M`H`rr[ӮrC*T*Աr A'_qtUnd'@2ƊEGZ:y? :?,-3%൅K㩋8>W N( noSĂM4c\pi=󘦰!O$HdCܪ,4l 4I ~SWa\P%Zao<䦅ԅxqjLȰvdo'Zz$('+b[*P-8~wɲAQCK)}3zDۥ@fpwO"N M1k E$ ]&3xPN@ k3[C&)*&p~]"W)ܾ(fELmJ88!Pk%d3rކ6=i1k'̈́Laȗ>zPˊ]}7Y F9G)pr٠m?~&ӣQYFo, 9X'DuV`境]|g8qF+vfPU,O fC a~1Unn2 n0ZJ^% )}9YBxͧWz0'_lnUy y@ߟg\QBJ `cTqO-al쐛WLtj`|5괥˦xTDJ˪A`( <+!X]ѝ bJ(C@) ~IRmM{qQut{X4<{PӓUa;]eYF 4\f9k*cGڥlWu]q*ҒO!`˓ͪRJlקлY@CA^>`_+; qgFGE jyS~ՐgF(X_o:!xh#3eoL{¹͛)&* uNJr7+j/O_føВt߽]`ioN=V 9?8 8q0jN`06aP Ņ`s4ɭ7^i=/w;hvlIo$ o B|֑T le`ovmS u@8x'ө -|w'1v9޾O7RȠA&X. _dEGR*څu}f_ԏY1{ZMHb mKGq,ϋX"ŒWbCw(hS ^$cE"tq7lUL(zn f5O_X0.܀$A7D=&8׈ |Wv7xel[u&Vvwp֗\6'g;;j12uL q"K1kv3ƹ+д% c\ojOn1VTv~֐Jr<䎋Kþwj/x +jT:=,!`F d g:@,Š%]C<; J._11[sWz ?D J嗯O4q_vgΣ0ڱv ( ZD!>4s-=0+hNc[,Uܸv~>uP;4ˤ-ZE Q\[cCCQmY*qᚳ'|#Sl C*ۆGyE{8)kAcτ&r2Z( y_7;l89`Z5C]HE GELAhɬT[C%CcKAn0@>Bqa_ƟUnuŏ8??<:ߟ <:L5_yA3jRCG@89u \ \k쪊NrwlDN'a]'/ڧ' 9^iROWfu1{mD|,g"1,bI; qh Wz[^I>eaRyaT7<.'Bo,]T YBD`˓RhD+D{QJcUSp`N!r8\ > / j6n3yE֌_qݾc[ǤwfT5:jZ6?*~?~ +|=2}ld*U( o&SBS͒QT?T߄UmFV+srxJ, (6tROTܭh|sVwTm}Vc. 8F.|:|5/]㒃n_ݧFF@>3_ԝ r-`h*E5Y fHKgEňDmE\E^ YXtavhxK+5;Y8ޯb$/-ҭqC,tZIyg | Im.ͦʟJ68$?![ o$ p+AAl_YM`dxs80?D ]t.mb0lUprR ;&/m,2bq4*cCԧCb"4LY;Ic8[ A7s$'/12{ ۇ7i*|g5$]KpstҌWఄL= Kl[ͦRYҊ? *{HX!N3@Tax]YNf&*LqnbՂt\LȓN%f(FPK87y4/k_ɤn({Lwc/*= !!(Iy%3(o?6=C2,xumu @a:LEoqhq{Tʝfp1\5:^G~AEJ ͝9L͡u 0}$4eE[KIX}LfUͿMM7].uOy ^1E{ti/ 2{2Jw53ʒ+C U`7}gg P0?8O~?0U77OX?#uq~"?K2#j'`sk?V K,>RYȿ Dߢ4s=H6L G /Rmd/0q%jE~eOܤbo4G-,L#9E59 Ϲ_Ý0/_CG2q̉dem8z.יgvPŸq'+ݙ˛' %&AW?X0@RGvʋ[?o-U?JXcR.H:ˣXI$m@Iq\a pV1LЅdlԈ'f7e뤴ѻpXX媄AaËeҘEH9vXNzs,&z5|On֟{+`IцV}iLN^3{ͣK1D 96[6K/'OUƄG#JL߭{YdF6:Ъ3H4棭 X.6 ]sDZ? x%Ez^z.H,_,F d|Eo/ₓ_l餓 wxYdP!DiL"\ S1,s  K%.g޺t-eTòUuK.EKaqWQ}\oOy`-g35I +r뾰]"Dx]Q^&$m-伓ᴝT R e͐1!{Tf&; BA>(FXj 0fCϵcpW0''4b7dylgBIkuYngWPdEWE0QB;u?k4 1S# E~4)z;vh>p`-!u?ހHNļ*9řϗQh{fo=A^rh׎lc=+V`ۄ3CRe6_Ɗod&lv_u,#r=xfPs/Ee6ՐY ^-? aumu̓Vͫ͘5ft0eCЌ8w) [1\"'($9kG&}z>.D?ŵΪ_" Em ڌU4P-40/K' 1^OFbW2ت/a6pTs\:X2zQg;\DSG|mǁ)_ᐓl0j%Js2F _%&<^FwqXۢF#8L$~I4e"0JW:е&Fֆs0D՗eP^|J bxt ŝ޲.m6<{0q5LtAPIwTSi{A /x`@ 2v͗AllQ ͣoV8)kɠqv[B_u ͹GOө oƕIL:c 0hab>ފ`¶EQ~[g2{k8BoD=;Pءwr1xCE An@$Ki1Qe!4uR @8akp{55c<ݦ&N{IP"w &˅xenUI]Zkó  -2Uߔ >[]RՈc CTp&&g}127*p$M>jx$?{@._NDܨ>.3IWvm9#-K`yKaI"qe.rD շ~ 9-?Һ- IswydH%[; 6񑅺q*BO6 5Ɯs/MDT ISf[@y?\]/(D-րl;|Ri0{VO}4ΧebN㐳Td54bzjcȥuwRwBܠ]էGnN g 7Ln'"y}~du_ `y>$*n[\c̾o%,$SsI%@ڇӚB\VT 6JP8>{9;vI=|s4ؽOQ\T?|&"şya+SZ$TUj"+|vT6,*uAd'FJٲcvt(Ҿ 6 : #Ih+F!^5XM5 F_vP%ؽ q2 wn_Pn(bKog.By%ۇ;t v0ĔˈhYxBXEAil H%˻x@sX{ j]dCbdBQ"Y cD(D M% Ez=A%g xb$&&X l. }{ ˢi-;؇ڍkϾ?a+ 1 Iw[-b^<"3%L9GX84 kXt&6f_HՆ$^˺^ڥ*wK!|\ت*e+Ű;֔ah~mA(+?* ~.Y;kOZFwTS^qjHKF0&~O&C+G[ȲV\7Bk5+ت8jE@y )Ưߨ#q׊gЙ&H] `F^ĸ &!z"g±*a -'Y$XD66%Cp4*=^Z.{~_ l-I ɗG*T LV[ gpw9twFRʗfP޶H{fYщXrׇa4x)ĩn Ee/SiE])e YϲTdÑ*T;'|ӟZ­Ѷ+_"GblL!t6J:. +: IR!˔88p'Ԁ8fJ-C0~LiZ1|hh_pm/8>٧ qmae{'9㌝mT%3>p},w[YU4j{ ƫE*ZkBr0R+P9 5mxfvN/r)l O2& qJx<g/e-܀>FH:"蘷iCb_[)4`RJFB0+Rl.'U϶l؛3!d]*0@ԜROC/ή[~ sM54dݗ?6[G@\EUdt/mGGk5]tʸFl|[e[A(s0 Ljf5b* UFH@BR$ 5R8We{|<Ѓ&*Oxz g8hV8;}?ĵ;" rpRϔY} Exqb8_i@xzJ%#] 1w~U {!PUӮF ' ;.[w] V74ZvQfb* lPϷUAܭi7}?Z5 &Cb#?D$b; ?Su ^̕lpT7c;<+]0{WǢzԭIꚍy0GxrW=fK BuR0ʞ[fdB3e`mĿGc0.&\޻0P&cyJ]?ޘo'k:%Pp? udr̹–Weu./@4Jצz@M^N}[5$颶րc64]E[79-vQlZ.wW~|2k֩vg&o~^j[~DM)0uFKNO0qn9x"[ނ-]_OQ##}`5iuoEV{w6_P(SO':*9\/L'F8 iJy ;p"{٨8{:Z[*c/7G9lRb_H-'R\j`&uL}s*bXvn:E:;ϽL? O?09ϢKp5O]$֚"A͓ n,e1?ņvp!HeA b3*֪]&˄&׸'yޔp@ *6KJ<ū%iS&} I cH-QOkEҴ .Vk}N6s}@.`Enk \gc? ?M#>wi7c!ČPLyۂS-vꮐuUtoZ R Eru,"MJ f0ܽd7/koieӽ`rz#ö6^P7sIKmTM%e:yͣ Zt}i0 KjlG,pqfGQV/1k?<7wES:iYQ*8X'MdU~m\Eo}yU+}֚aI2 걚kEӅԷx Q4d~ys-xYASjG.:(gen-'$bE홐0g H0,(3?.d0{HI$ێ_z(P.Zd{Y gÜ̓цZx#"ShHQ2}$Ί/3OyGb;&xD1B[+ZC1u^/tX {(]e*l͂Bs)B(3V{ÜY#=F.Q ]s2ԔfRʁ=1+od)h|9LӌՒZ)FǤ% y%>xfƙDy0%݉5%ĝC? 0(a ~<@ ~2>q"՜k4OhvH9e0Vrlհ+Hsе+eKjA B!hx*w8&]˜9qI8nrcJvu*nAn1)orӫ$=s>`23`Nˏ #ָˊ.!tN/dxVt!"[M_I Do2Tl+X36TfVL@ft&Mn ukV1L"RMIajV%is  2̈́gwBh"Y ݱӎOoFatg 5=R +6($?`8Ϸ@͓rX}Lp뒢d: @`{fr)̏͂k'Ev͟d2.:/;S?>ÚnX) a6Ҭ2t Tb븈"篅26ժQKИSrNbP VP[x;n'%/id=ҹ\$ ÒZ?TF9"ZM1CdVbӈ1*w˚R顱8 >~5 IJy_ a'{@l9DSXES1\OP1n"J0#g(]01<- ;ٯѢEsJ g!=hKm6 s.Vk]u]6Ċf2G6lPœ ;T}އSʗx;Qox7sf@ƺ[#Mvo[P/1P}*-_*0y[jMӂEI4̦":$n97.Z ~%wy2Uۄ6۳m)=b\Bt#rS%#TRSFb}Qs_̪D%N=_4c$+L ]ˆL̕C==U69*/`$?0Ͳ9~LA*Dlg46 \P4Yc:$M2-u=1V&\b4Ž[>_l%um"gO?1nBl>+f?2ң$79m@7KX%=SG~\#No*Ods)%Z[;ABT zL[ V5!]/N<ב;<,OCӬHj;OMk;|[0*105D%|GՔ1wJY&q ip(Gȼ1̿sK(4)ngD1)1x}F*R5;PL"n^,fE$֎v, {״QA|^xQmݬ8`zo/a t1P;1S;yLn@AmۓWg=x/[E7(Q^|(tex"7[ѱ1xE&E&:y]3"=LS2j Ie Yp[k;\)^pTɮ8$I@4Ox':A51b"T;ooM5QԀ}HO<7~J|؊#2o͎' wIS {cR㉚-&hr[xYG 2j} ar3}:dUK)TG̏[(oo BT^^=-=CqˬiP3t"= nâFi'c?N۩-8Ea-6Oݿ2~+ ]BaHSad}j)zxeEYB'F½ڑJEyʬ >-tԴMgӦL ޙH\vRkm愌8-m%sG)SMN+ 5J8϶Q>Al>B"RjV6a*D{[IyimjܣnCR4epnO3 "[)M~WO [[jT-lz9s&,Z:;T״l$:m[ʦd)(nrV!r!<'=V\)ɃqGYGf a{eTvt`a_${obx[;mٖ[@G]=Ca@AaowHrF|'O$j[{ᲯUs£9ՄEwKO13 %iN-!5u92:Dߵ?E{&cy+ippHaKǯރpdnX M{;1UZGNr={!R{tAQP$֑ib^ũRO'L_;2`P5PFQ`toiv?/ro%Fp՘,6+w+֢o?:VILC2Xdc2x@Eo) u|I:$j#4a^ !ߺ>q] +[_2Qn栍*/K:!Rrq MU֧qYvaW;ɴVI#W= r#i}CD쉙KxT6% [&)F!ܨr9CzGlV@76|wN6RG-W`s Sг{Ω[-mx/z7r>\R=|?x^yQ#o p|gT9#SiYJ=#egU0ocT^r eŬ~QV- kV8nG6cTD8Sna(({Xbd!>S=;FݢM"C}@Fq3ti=>T$=rۑ%p{=&V>fv-9uhq\a|K^&#`4{hQB":) QQf%Gpaw7u b\+"0 ٧bh4'Pԉh]f&Җwd#FˑLz+UN:z_˼y93)r+nD[k;%}kX6ع>z\bȁxCxABhթ*h"8Y0!N㍈x4>h48 zi1^W YЏA=z+ˈ#>ԨLHiD>).ɼ)cpTacIk;K&=fP3C|D=D&߉̉$eݢYfή7 yѮ .,T XGЛ"`\3T"afƶHT[9ETo=bv9@ŭ9Hym艚@-u厏(*@6*ڂRط^ǩm'[np׆Mg^rK~ 2[FTMhj,j,?+ Q69@26M2ɯ_P"ttg+57֛$,*t5*&aW=y~\W^XѶidji 1V11];#MhwJ. kv[V־T4{`i[I}&΋? @3N)) ="쇙܌MٟLCN):ܓ)> 'jC*jDnJ{||AAS9@ϣ soU]n 2e^Y,onuͯ\-|y8贒x{ˆd%oYku򌐼qN/m~15&(ypɱ& $!бpvJSU^ST{+nRQHsԽPѭ"B" V b4 yjźZTL iZ;PUl&+ nT̋3Vw&i]? V4 p"$~D+z3#xU IS( l]r¯džy]KA~i +anj{)"wh qz㕽wmM_szMO1i 'E;^(UbM&É#(*;NިRZmz56: aMDVG0~%rof iW,3?n'Dx1."֕`³p8Ybg-N +bW :2l ,7Q CK]ˋބCk^dE,}ʞſ`(bf3H 3My'>I`ND@S@ǭpA/b׋~:o^m]Mr0AL."C xTCg:)O 9^;cp  qf!دis2ŷniy4Zͅ;}s4o}bZSTrc8Lv=SX!2;f1僋r8%[S8* D?h<"FQ]к+?OE $t1両Jo/m#_'meOM/$AߴuMt>,f*|bG;]ݞe{= \x6=^H^3ZMAcܭ*ѨjSTݸ7RW'n=գr2 %OhYk"}$?5ג<Hrd\j 5(5Ҕrz4͸c1" !׬TX@%Zi1 ޽Xu BV̪( (a;ity|R]?x,dȦ}vb䪋،?/*Q'LgoJ N3u $\6]48@ui7P|h~7~,1@nW;i~<跦U1 fgf.;Y]?p?lb)ӚaTF u".X8%sb#PT)؛)@ۂbA!\=2wj]Ò56Pi0dwaAV~|QhĦk1jrH#;}d?]<DsA>RL5z"aH@5os/vIYW X9l9.؀rl,LH:āz.΢*t:^.=>2gtX }))9k8G| US//Ką\"֒6:zR<5j6p1Kct/ΎBGS_ AD%3'^#y>c i,#2lqNrk[S7):k<H:A L:tvڨ11"j"nƅe )1WkK;U\O>z)<&?*kM୸PSk+X?׃.Ts'^\q ħ[`u'mm!p쟻ֱKJ(WG>/H I}"-xP@E.7XZb]kE脦XX䟐|>,mNryI qkuYd-Yڵ!((V}|F**!0-QAC] =z'Mw`A.=bʎ#TR!qKs`PVorсAf"Ix hJ:hY8it6,XÁ,0"3WQ]P4{TBZhB١w/rK쨟vJ̪ :*ag70Y;U oCos 9.kLӮCQJ~'z\y#cp՛%XiJMe4jAϺc Ï\#F2ׂZabw 2a+&[+e@\WQ9f `v^H!ZJFlz)m`nd6=[ b֛&0 .\h^c LѭOFpe3=ʠX7TFq?`銽n֎iXi^=#阅̫vfmR:e\bbG4ԉy\\~kmJAK!QpG&:p3  @iwb_q%kCq#\5I1 Ჿ&\3h# s^_ LYRs= ̵b} V8$fkOmC{J]\C5u3xp#'˷oPt2/d$q]0'ұu5`õ*̓1ݘy< KpNp˭U6(k ->\_3Y"qX FYkBN0${rF"@7>VܕM`ep:&ud;l]+'9BJxF~zqɷ0n(uk /Ԗ1gNsƺoٔeSj:],~1<ܫ(S~ؗ3cl& }~/[$BQ5=]!KN/:ٝOk'] -27D8ɦIt!]mWRo(<]TZx+ᛕ W:UL[OƸ !0B#Hھ``J\(Ļ-oiHݪȝƎ'4y`C h*+yB|[`W(lWdBYǸ*%Ic :dh 3}0ڄ/92';h{-VTb c,hQ=RjAA{LE˥CIS߄nՎ )~e$w,0h!he£krx dT-pH` FٖG )έgR]#쭥uM@-괽,% },kBXm(T3XGF۹EfB9 9fLx, /@$!gS֛+1/cEkEV{o7bp3esX"kCh(;nc˛{Y סMߝ=Oy_̋IƋxuAqO"L*st"K_p&ENYۣ Ϥb|{]E=i{uZZI/As v0ݎ֊BPw:IBK|C/_j}{r-g"ޓ {Fjs XxZs tg6m}G{MaMJwrt :mHP8A33zR &FߊXO~|E)|4n"¯1ad< r2{udChȱsDkZ`cYz鬬|P0o !8_MĮvCM`6E"d8nΣEJh>sDpTՔi&_8*ꋜ򜽻g~尧 ;K ?-!z|w儗 2*@ns#Lc\}}.B[FHh$ ڼRnI1Cz-<8 l|v{Y8!R_ |%9b*Ikΐi$*L兵4Ad/rWMRWk>&[ uc@2h]L2ݴ|KVƫ?GY= Er}-ln^߅A$]F8¹%&fbf `7rYXʝd6$rЖufo<)oċP9e1[aY]`#ؙu7ň^A=~jKŏ^JVesH83Qqμ:m7 '_]?-J~ ^Y#AH e*/|hqޢ128X,mH-Ŋ,[<>? f{Vƈ}'E)o"Z˪;!;[HNݟ`% R=!l?P;ӪY+O'PNOiE_\'N.ueTM\vCѸ}cZ5 [j+`oE*l(҈W$F Ynh}cUÞ4&'N3Đ"|eT_pi$AlvCM2E_4Ij<¯&Yd( zه7 $m94Yd{nQ q,=\%'.o9TseysN~ rI @g4!wFҳ`D0ezq?BOkM02FkPyEcVH|عAՅ엿cl 8 D\ [vjie/9/[9cOps<95}VʳYpB(FN'?6YLY~[l8d0)p둩y`8-6V 4cX)c0Ijbr//'!YD!a/wo||`j%嶺ya8i Dw=LXByw#*)b_嗅`s3N#vɽ /S6I r{ο,hdo1!\)R@[( ̡lTNBc|L-_YQ)5|-\ @I-t|An24wCm̋/}FڧQ1)SM\x_S6^rkGj!lOX(f>2Ru򊜢J0/[krf]Z C>͛;q)SA麶Xڲ;H23o7bz\+㟪SΙ;+&/cAS{ax_)+/՝[kiv{*d(^>QzTX͗Lm0UY0 K!]5*mؐ|+C%0Mu60 NeC$&oc]coK4k *ŤfuR p? udK76Im˄fe?t'|(kz8̢Rll928њ@+·Di8!E! ٘%$7{U%gX|&VoUr.e@M t8C rmnMa~Ȝ5E}kyOM\{Y3G@4!1X\3X4;xxvt#q'1$[)6 G5EFP+{]zڄH^vj0hZ ؅tP[xC9*#VWwƼM'g )sƩˑ\"WV f){pfہI{z.6OG%XN! 7ó 3%|Gݧ6w쬂tDN|T[ߠoGW7xU#zɸd;?BU]%tz#io5/g,clKH9h7^=Z4gFI\ 4IZͨm9 V|E( Oq9HRC_Sj@"Aj)HiF.޾5ODU8KL\0;zB2kY{E:kHSгc|׌Ma{ΓQqrd)`-<߄ aA"Kˣ!gZ!_+%. ZhEbc]TPSH]veDy ^][D$ }-b Ud1LMqaèB! V1E= ֱ㷴hwFzЃuP7Qt/Y)[d};O=elu!,~5[#Oɤ7M~0K>\";C Tvx}SLJ-D$'R3en8WDG xs!n7;&~k;7;Y~8@ U4հt!!d^^ s#y)y\݀GNJu, k(sIkW*{AVMi'g N -);_N;O7& TSTT'|g%3 ݎ{ jtek[͚-Y)foGCKo׌y%](`Q&:H-;٠{No۝؜rQQuAX74/mU n-=$Dr\H,FbL;)eOg%Í-Z^qj2lm",l/C_&sϽNyXٟJ/x߈;iʅ Bz;U =z5ِBnyI 7uQ!rTsf6 F6@|aQ 4q D{t-0,و5e;BQFi  ^AaC94-N'qOl';LPb `fV;BR%Eu:(> oX۟=Wa;Vb9Ȕ5+namEQflsC/d9@:DP3TJD&;!QłĀ Yor=sRZuX+U\Ӗ * ]9kU`ed ^-QVJ&X?Fي\L>l@${ٚ\D/CȳTU{ xaOUT!&C*Qk(o \T 1b@ </ 9;".BsAVK \;nC@8Zo-s~c50\d[|FВQfrB΂>?1Wf-ba*C۔4@%c4;^6[D[C-; (p&iyNF$dܨҡEioZ@ e"}> vpfԩzvL9>XKI7xQBkڒ)w3~CV/԰զw)2ᨧdu@b9UT6Bv-fձ}}Օ-25@pb=kcɇxsUCb ʱ::N^WFfU*azrQםLO>GTcJhlAҚgn( e"qubXsz37Aq@`5prFċkJ~y%SCpqB@NI,M(_<i|780 pd@Qȓ#g] ,6lib̌EibM씼ZJqSb1D ER}ZA-'*TgxfLH&!f*;#ʡls~"T.\?){\\?෧\eQ݊*oC?Cj3d!jIjDz #9܌^T|Y׽Jtb@? F2_1Y,\d:gbڛB3~a?׭f٤^DcIg ϹaXvd,U]=3$vk0<:M\QAmb4q'B ğj,+wÜ[g(բ9-Gi~Iu/F j1'{ѷ,=?! @x 6l;ƦȋvW޹ȃ=~eNrX&&KnⳜzwSBR1_Ar2QX/㠁hg۝]ns)z -A(Zz0QqEE̯s,}π=$ 8^K{8G=w 8[n)Y[V{!tM_AP$pI*11:r7c"} v-{m9yؾh桠U"K{W2pCh_ _7N2n mkqO=rR:~|s'ZV:Ψ+SZ?`9ZN2{)P9vA YXHB=Ԋ,C/DfߙOa(%%O7 %V6sþ,ˡ顮Fp䠇/Zlf fHK ~p4;QbG&EzJWВ|`o jz(>_%BTɌ 0wP [6+h,Hq gDVyk' ꬰ*KۓU޴ВXC>ٝp_uU: Ď.XqO.=(V IVe ]~(k[lB#XJ͠\,N\%iEK'13;Ɓ !BRhjfteަB Tc># !ODj~ 97UP<77jC~k}ivJRKWYXo $PR: sTO`ާ2k@%'⸆uIxU+`^ Ƈ\e^$xw jFdU{چ~'fe#`shj H~oݚ@1H_(E(u"1o"ˌTǒkQXE}%:5EёITT_1I4ܿ*k[C%;V`3k0[uM wDb #  /!DN4H)8Hp Z7\1Q ygMB^ʮiw['ĉ$ {5ogÚ"KhRYJC2ӹ: 9XXHysA  li|͊EUQMCD#m|+r`[ J̜_t`<(Q9tRc ujUzw翐ˌc=1RŗJyt>|䳑PV*sZoh*!E`Ϥ=w38Nf#zT; y`bx]G.5tqO2:p?/d>=L{9{"|I cQ)G[ [?b`hJ>Npov)PpMd] t@!J(?ghbf͝: ϵ x늞(B f4+8sy]%|ÉP!~ :'Rg a&R̾1uק1񀻉fmUx Kxzp>b{"uF8q@0tlѤ񐔉,&·M{ pH| !) >N[UtuR7/Fo3EtG$?ZM$_5 #kV@ ~G E't6 oHU!JR1 ßȥGS\rIS#)",v%jct4T1iX*V֨nY2 z!~&3Dow${(Lcpfyw83eFPeGgĥe[\i +vqBgmyޅ:d9\[D ltd9LzLl:r8³l4pUJR +uoI-|gbeP@ G?ϣwY vغXҖH+8 )("2W 3Z# TGEH%UTgʛ¥?5x^o ij6U՛j.SHcTŽT16;Q bY8 \id>Js 4 @Q'eHJɃj ZX2yNgPTJ*.׊Qw䷝&YgxKrV@GoϮ|Xo}&RkE$}4M;7¶īևNIzɣEx5G5OK5$E/h @+ -4緩}O 6C.S}wޱT~Fj՛!5Xbbc"=%3F.(1şA ~!ΟUSt=߉I|4(oy|8dgvz,/Mn$O,Ȅm JP6h׏FCCN|NwQc@SWA^Myi o$o6霢kS1.F5N(A1{;|) \p)AYfMHEd]#Wle],CUoW" ޲g 3}d1RA gde!f ;mF썬Q|9F{F7ʚ> duJmmK=L X?ۧKNavv|U{7PPRH2,_A:":+%<Ŭ2Zna+8ܾ IRxg|d\!TL/~xV1o΅4FbR~Rtu9RC\\0QFZ'~dS p75o"otqQ) Ŋ̈́"{0FsgxOfe'g=0lJ8dtY[le.ⴲכ `HQo|d^pįƯ<d2`%NcD͓JV(m1xȭ%[;-jwsjTQH.ꊼfX̠,㩷3YlKX#/,'%٫>_<)`IpѫKĪ/uO$;*0@905BmelIe&f] 78|#W q_ys$RRjamv*VXdRd8wMcʵ:|&wǤ˖Κ(;beH c:Rҿ i.wl,)kK$?+yI(} ]GW0{; r0 TW}=)| :=z&P-Xp-9Wښ| jK:Y̋ ɕ&CI^7wmf.\8Q~l`6mPYhnAXhEWr;?Ź@ o֘!~/WxN07 '& no7!R]Pߍ7j0? *ʔ[~AlEV+41XebR&ONV3w{*Nݎi/,mvhʒ;flop.yh>H5ͦf$DzppUXI!}U% /K~x%/I5礨jD6t\C6"7DWC-/c^˯ཱ&x 'M B`o~4BB1f22! g@J4[%O{8'^'TB&FƍsO.LU:)w"\ TY^{xl蝠p^ kegZOyQ2s]=4%<mLoKKV|n a> /A+(svNvG.FB mu^ITI7?-,w;U[T_I]LH[lI}J5DZ$mvvj-<2FZ+Kad,3.z/ăXX'gΰS&2J U_6t^ڳX!ƿY+&mxL8 ߚSIu{&([u9{4Bq4îH2,)oFYcrA=GHzU."{mIrYY~DhHYwX7ʂbrWq~{,ljϐ҆>bw4?;c(q~Riz Pe+vwuI'+d"&v[bÏWh!9q¤3Yu x'\kkc1fǤF&=LCꥐoAy~88Fe}-x]PdHq2ݥoCI5ކt4cK`Cd@>*.n+Vx ;#p{.el!pqν k+!Rf?0㷤j=2Hg=OG55A$ϓHF<8,ddJw߭W 6 뱈b I"co1vk6 `#Նw1!}/omKplWKC2+m=xuf^ &AAg2 'ӣw5;|Rś9X('LJYDtj`DhasM=Y |~B\S! T\)޻Sh#՚TIp4ޯjt=}浝s7 {5тbvVlC$^*ҹFcqnɛꁎWsxws9&WhDyG&_ac(lߧoDS4jՊS3m€'TZ1y@&,iʆ.V'"u }]b_ye&/kU䈂&oGך:%ϨEW73OL;DXJSCxxk\Oၘcs?7=ٞZt#GPϪ=KѠ%r s(tBnxWbVvLo(]ժ镵f P ~L!Ӿ/˼5BdU([u.2P99FP4)tX饌4}ü1&u|\LGKZ} TM+\~/.$z)u !T>`kpDDSfސUt0Z3hCNL F޳A&lcۑ r)`XI3U,ژ<<#moU mbNگp =e~VȧVd9̎.R^SF԰ I'\bv-;ԅ`L !ၝ 8iHY|fŭJBG3Si Oوej^ ތ7g s{mTql\G[N8I$JЮ,*-:b›2;dW+ޙu{126)XGowv4/iV`C0۪ wT ˘Zᙎ OE; C; MŇj׬T78HJ`d-`$&4{ZLp҂ @gq{0`VĦM@W/h6+C^!zDkzS^:GO1f3yG&L!ѥY5`st ja hx{$mUrwP,^Zt4Ryi*jd|BWܕ劯G YIJJVB۸}7ĆuKc ԻMrC[. &gsrOk/ʜ!)& -4k~̊p75;@`Eue#".YQ-a9—$LԪ=kZh¯员2IPޭGAy:3 -Ydq u!okAp‹!S(^XR+r}~MO.YԈ`zez3kWF1b=w(yo]&U0ۊ%Mѻ6fǽ)X䘲 e:͋p~߽R޼[q/- ncyx=qUT N|>!_!"ȑ đVӪ db?!`cy{W #jgby<I^ͪRSG?TmllyA4);G4Pev % ë^&Rgiv3H6nJX7WC2MbLI6WYf(Blmj )Nt޻@ŚihJ Ti)b7LQCtQ^SJb߲*GLxX01%HyvQBmE{m[XHLn} ٬] %n;PQM^SR[i!2y]qL9?Mƙط;,Ȕ*ٌ컉Gù 9M-0A `d3]YY^e+Fa#~m0yռ7Ko ` . eTUgӣ?C훥@ ֌"P`MBd.J7Jy3 W8dL߉]8An10*vhގ‡l&3)Ub|-/(g7S,K5:SыGB1# =/BhMeI k>SU V47pk>=+$b偀V)W2$j BƝ|Sh gda}sT"N FRN#w͙Wir![cuN6Q>KW1КmU% J>7]( ~$2_s(N}>CC֩{ +ºzv7 $vL]~\T&%_0\_+sHf_9Ihs~nX`DhɣO, =͎\0-p|N£ٔV-Mٍn; h;{0z kG-w[J+1 o^a Qu2}YqN>2O@\ci >YIÙ ɴ?;kPo24dRY湿Fp0(Xo3'a{ :}K&6XToՏFˊpeRf0wġn`E.rznՋaەe7 oK/׵kY=Y~@'nÿm h<=?!6D%-f?*O1X{IRaDM_h8᧋sָGr3WWA駂[-v#KN2XB IH p-2q0!Z=xr̝Z-l Ѓ̀͋<UyvRYZlms '@V$]a9w1N K1bT2+7n9?c}VS"D6,֎tN ሌhH LKvqs^A6psBh$"S7Y#3j$֔Y ZS)`ﳗcGj=KQWZ(K[䪟}vLwϓcEtkJuthBmRǠe-!iHifFٮ'SRS};%=~r 6慍cl c:-kߌ%-8r0`"ֳ1db'>,t67#ZD* -9f\' &y0*нi%>)AئpCǐHIbƟ@]tAugFd.1+xHy`f ]fWB'8@W{[UH ,ڤ=6(_ BƯK_cXw"a=&Qzͷ~3"ޯ:đ p47?`x43$Av,ߧvV1#7w*$\ .>I!?HW*Ya~#"b <  P*{"M@Ȳ>kzG W۟11KCz+ަٱZ\(*G!`š ~x<+=hz%x1*rqR\ޤy-) aSRC:[InoR@Rh(>v_$ur՞!wRp .wO?/˲.3Gplju?Eި %(*Wy)re~ywRmD,ܿIŝnM='ow5"8L ^J\@ž\&8paڥ.eOP\ GNAiBpF'p mSsٌQFϺ#`/Q0mz;g~j VSɤ<7Oκoiw6jOz< Fw[IJ@=0x3&|in,H9Ӳ!>;vRdİpcZr+(cxg|lY9jmBc}5`j LIg&ipX/xց;N*#6U`ze4+xI`!=DF`ZK}i$eB: z?z{8}Z&=MϬt+/ϫ"TN4HtDRIRZ3…8OdSss"ѵ훁n*@/Q 'L%t qHg ,( |p)•_V) #pU{-Pu_9ی$\&[pCWJgy@=oI)M?"V;h`9w?w .Eْ#JY5c_`ORo"tBvuX#L[7ӭ&b;GLV (Xֽ omOU^ҵdfE a$ժГ4xk W\ pp.XgxlW6_$07gg3,R_Ob?Z=:X9naUK|k4mdj7iLYlpcnT5i{RݧhV\1#:dyUFirnξz { Sd#lMW|4LwpG[ib}5JglbLv Xܱh%J gh钴Dc#DMw8([lm^{K@NC6(bc;7TZ8=ܧPa&_ŵmݳڽ5>0b6ݑxl]Mr~2yZE?|:0qhHy{8)1qx0;"ZƯ!d}D,r=YxX3k_)i2!-~[fN>+ TtyuZZqzbKkS.ʷ%,\vHtr1"c8 A2Xv1ܭn"woys"$M4ﵳܞG Uz!6j<[8*i $ ~ ,"ܙM H(z)Pl!/14|y6 "Kqh hD" ?&mUjRH)eeEש` ћt-\*t:kO}I,d 0ˊ@j,[8Bq\ Ƌ-;ɜ|hoءw ׼ PLA'kqAp,P:/n|VN@OE<ԍ5?H2^5+U0+k03(6(NU0mJjpB33ACDɕ7=)&}j*T.)lk93H57w_'u(H2)c&סg`AR֣HPI]Fmeo)߻-)}k|=oktwtC N1KiIHMi-*t[lzcX [VSБ0ee;偼dߕo}A>I-K4{k ˇJ=c*gPHsz 2VbPP>[m-Wmޡ܃ȋ:& _R}Ο״̺%_VCj&@e"3)`*lI0i<{1|D@Щ8^x=!Ju<l v_jg4zY尫_"HR6񢑧:`o NBÆ@~EE$ f+&9¢%UH݌i~9=&yaְdFJLPϦuYUi vG$ >9M+;PM?eڿsؑ1;wִn&nOPZ̲!Ͼ *Qg Uk)-vqGg(OFŕb=I rC>&VeW#oȗCZ׆ ,BBo/}y"Kn#.>ҳ3'sO %t8A~o +IA>͸7]<Wd!y(Z?]jiq UI iC )/;0Er r&YzNL_c-Ҿ} x#J15q!i3#Ŧ%Ak o Hc'\YRDի2U_ fFf3'KL ?ho2CAKv|4l>VNG*_^[﹯AUyoȅ|/ Ûi J. rlƺz\0[ZW7<N{ʲ2O*{<cݡNrǽK!˒[ N\y9)2#C0\Φ }m@0R{b1 7յ }LQ^I&dPa=i \ :ö`!)~ se1bo(6#9mF:7J+")F|"9Nh$ȧE/ P Yn2"+JdܬUCFc/|eq @unb+gS{+X04[vW0t1]pɒ25$c*`,;w;!{刺 "0\j$A>"!>ǻUԗ"^VUY Q٣qz܅sy#P :^paejG 1|'I**).@6r4L5+quڧ]~ȏgFw%"3Um)Uag`^FAV>cy.gA4?4y/e(ZOP:j@B.д]~_nOE__.aȓ)Z}fKM œyUDo'^J 7P ҀM'p$L- @r O-c.dbsW?V<}UJ$JźCН.T^^du _Sc 3UX 'Ci'!b!1K ^ `хs{Jַ{*L&liH+_˄7Pӏ^V\{x)sA0i9_>L?+}[IL|ҨrI :7wJԄM,}n*uI'IsК&:Yx{>.PpT@b:moAG@|GǑ*r6ZoOc>e P }:҂̑5d>e( Mv9MKߙ b"qq~k6qh띺_%%좶5Ϳ ʽ*u/%͵7=(L*i[АP)x}LPddG vsېrI4D Bp䶟j<N;7]Q .! /o+ `Y϶dAaSh}Ǹ[&3i1rem,6IsT:Lȼd2:u8sIz\҃~ZOa76 %l,O 㖫$~]tFIy$` qc!R\}D,[|,$pQ&=xZ5B"l.ޖieȇL\xټ}VWhu5k('}ixw(AʪXtP}Q钟*c$Q jC!ƒ.u'UV@5~{>ckя{|yT|}mYThԝ$)]?W O b%P닀W xFɁ{*څhoR@Zޛ}tg<JW}J9jХM&߭gʶ%g3LgգmPre:cm]vm<[;u%wJy\Sd_Q\rmZqq>?uaZC|d5PQ{ȍ4a!3jt/ˮ}03,yb؁~w@D8E9N`3s|`kИ~1tts8𻪺~lFVoW?5Í:QSS&sd &4 EUO Qjsq:= KM&Vc'eT`} 7tAe燻KPs8 zvwJ@GgҠ݊*5sa Me;l_ r0zPw79 NlVXqT_VjCȪqJmt{ztou엍ӿEdU?k#' KJqa:K}o5L?^͜BEt[RTw6CM˴O(EX ku^J<4A"Y->@f˭\@Um3ʊɀ=/r2rZ>m*1Ⱦ}MO. NfBr'aB:xD{Vh|S_ߡMٚKNZ0Ϋ}]ajm0+Z>oJ|}fi^ @~c#>5Ly՛5WC'NSu9HOuPZ!ַ!\ #~֘8b:?Τ#̨jվ}DTL"t? TuG{oF<}/xD&Xlo?IvϒMd^,cڶ]Wt-S*@4d"eg_3SEL%# u荅s}y{$OJZ&1tBt,7θNڪ䘎K~Ej];SGFaBCjTxErWfL t&i<o&\g2 =V d?:!7+eJ Ur:٥wQSQ^RϺSRrz5(MHY6k bCĚq.d| H%%;ƆCpBz1M5ow1?$q``Ѣ`Il54Lb]&zJv[]\ݠI=KG딙p%ZG@xi9Ca0GLRz"u纩H5^(p4Fn\a+tQҼ~j>r3Lי8m0f23m]'Y-BOGMl3_f)bA?:=*P޺ϫ}8>"(DOCrn#`lT7 y(aq:H0!Dظ#l+ZfP]‚,)D#g66ր@ W;zBg6fN+N^txϳUW-#7L_4 H zF"\)A&JIDrTzP\Z>eh>s&58tK=@wȚjKQߞ? (鑼 YZ