sssd-client-debuginfo-2.9.4-4.el8_10 > 6 6_6 3!pQp)Tξ7]mtZ`f+ ]mtZ`&$ZQ곚ν"hX"` 5/j? Et,vogS>N^#œBAN,:!PrJ4 󞁿ZEceR}7>*)}]7*>tѲߋZXl}YT[fqa:T5@PŅPlLRZ?='wgD ~׍7=<!WTh_e¶76:;p^kƁCs7#5!K1'G^.ϱT(o=FSwMHk6(sE81ء,}+x:ȘpDbx>pyyټ j,^9JXTƪ@xl LD8z㚦zQ''ve)nX4Eᘯ';Ѷ\!DE#EUI[\ad!bJ*B4mq ݿ.D["ߵCC%,|/ܛcR*P;C8Zw)08c7c0ab1ff3f18181326fd2183fd22bb0c6d63996cae98040b5e018101248e43341c5489df49e06935f06e71ae94287c28b4b3bĠ3!pQp)Tξ7]mtZ`f+ ]mtZ`dAe1f ~`┇COo&20r4\Zc=E1bzLS?5M4JۈU6fH\TvakwHI]pN6q,qᩏzŠңX庙G覓`_͂Oˎ?0mwї\XVrs;< x3?AY3͟a'FjBFӲwT| v:eB gNY8jHlpdgΦo h|#ډH dgKW|3á.o mCռ>x 쿱Sk1*Bq(FYCG9Y86/ l}W탛6۾NXp>t?d % O48=CK i{+T+ + + + +  + + c+ : X+ f(89p:j:G+Hp+I+XH Yp \+]+^ bdeflt+u+vT wp+x+y`sssd-client-debuginfo2.9.44.el8_10Debug information for package sssd-clientThis package provides debug information for package sssd-client. Debug information is useful when developing applications that use this package or when debugging this package.ford1-prod-x86build003.svc.aws.rockylinux.org KojiRockyLGPLv3+infrastructure@rockylinux.orgDevelopment/Debughttps://github.com/SSSD/sssdlinuxx86_64<_<R<Z<m<V<s<k<RrSH8)X8èAAAAAAAAAAAA큤AAA큤A큤A큤AA큤ffffffffffffffffffffffffffêfëfëfëfêfêfëfëfëfëfëfëfëfëfëfìfìfìa27b9d4287230b1153aabbbac684e17f2e1d63be22f79bf1eba43672af04d0b9ce6ba44da7a7ca7626e4e673f56a12a2dbfdfa148d6fb5f06e13b07cab566366d6c8e92dcee678ad6b758a1759835032d0d6f8cc441cb8b02ab6315f53796510da0abe6fe356e6b67c5bf1b35dec7fe2e90846901e04f8e8c0be39ebc592ea237782387828e45fe3a8e36a130e5c36631f1c38f36fd21122da8f0d237fa651a12ca8d23eabc82ce1d0746a6cb8530f75b3916eb8d8fab920927910dc52194da0bbabe2d071a801de429b7808000bca46644b5f572729c248e09ececcf50f0f30d858c9f27a88dae8331bae32178336861cd2492c49efe11477e14acb441f04ea../../../.build-id/07/69484f73d80424c205cc7403d93583f12dbb52../../../../../usr/lib/debug/usr/lib64/cifs-utils/cifs_idmap_sss.so-2.9.4-4.el8_10.x86_64.debug../../../.build-id/0a/454bed07ca036283c6a20d68cb500299cea22c../../../../../usr/lib/debug/usr/lib64/libsubid_sss.so-2.9.4-4.el8_10.x86_64.debug../../../.build-id/10/da38bda08fa56994a5c07ccad510f2d225e00c../../../../../usr/lib/debug/usr/lib64/security/pam_sss_gss.so-2.9.4-4.el8_10.x86_64.debug../../../.build-id/21/57d88603a611d61ba4c0d9ce7cf44862ece90e../../../../../usr/lib/debug/usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so-2.9.4-4.el8_10.x86_64.debug../../../.build-id/2a/2c05a1eb6d99fdd9b1bf0143401c0c5e25cbfe../../../../../usr/lib/debug/usr/lib64/security/pam_sss.so-2.9.4-4.el8_10.x86_64.debug../../../.build-id/42/0a97695620c1a795392f4873977331f0a2b533../../../../../usr/lib/debug/usr/lib64/krb5/plugins/libkrb5/sssd_krb5_locator_plugin.so-2.9.4-4.el8_10.x86_64.debug../../../.build-id/43/95634ed2bcabf6ac8ba4fab13f0ab725b893f8../../../../../usr/lib/debug/usr/lib64/krb5/plugins/authdata/sssd_pac_plugin.so-2.9.4-4.el8_10.x86_64.debug../../../.build-id/fb/9c1ea56d8baf543efaf8950f2ea3a2665ec4c1../../../../../usr/lib/debug/usr/lib64/libnss_sss.so.2-2.9.4-4.el8_10.x86_64.debugrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.4-4.el8_10.src.rpmdebuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)debuginfo(build-id)sssd-client-debuginfosssd-client-debuginfo(x86-64)    rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sssd-debuginfo(x86-64)3.0.4-14.6.0-14.0-15.2-12.9.4-4.el8_104.14.3fGFf! @e@e{@eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.4-4Alexey Tikhonov - 2.9.4-3Alexey Tikhonov - 2.9.4-2Alexey Tikhonov - 2.9.4-1Alexey Tikhonov - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-33957 - ad: refresh root domain when read directly- Resolves: RHEL-27205 - Race condition during authorization leads to GPO policies functioning inconsistently- Resolves: RHEL-25064 - AD users are unable to log in due to case sensitivity of user because the domain is found as an alias to the email address. [rhel-8] - Resolves: RHEL-25066 - gdm smartcard login fails with sssd-2.9.3 in case of multiple identities [rhel-8] - Resolves: RHEL-25065 - ssh pubkey stored in ldap/AD no longer works to authenticate via sssd [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-1680 - auto_private_groups does not create cache in IPA server SSSD cache - Resolves: RHEL-10092 - logfile rotation for sssd_kcm not working properly, sssd_kcm never receives a 'kill -HUP' - Resolves: RHEL-17495 - New sssd.conf seems not to be backwards compatible (wrt SmartCard auth of local users using 'files provider') - Resolves: RHEL-18431 - Excessive logging to sssd_nss and sssd_be in multi-domain AD forest - Resolves: RHEL-5033 - Incorrect IdM product name in man sssd.conf - Resolves: RHEL-15368 - SSSD GPO lacks group resolution on hosts [rhel-8] - Resolves: RHEL-10721 - very bad performance when requesting service tickets - Resolves: RHEL-19011 - Invalid handling groups from child domain - Resolves: RHEL-19949 - latest sssd breaks logging in via XDMCP for LDAP/Kerberos users [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+0769484f73d80424c205cc7403d93583f12dbb520a454bed07ca036283c6a20d68cb500299cea22c10da38bda08fa56994a5c07ccad510f2d225e00c2157d88603a611d61ba4c0d9ce7cf44862ece90e2a2c05a1eb6d99fdd9b1bf0143401c0c5e25cbfe420a97695620c1a795392f4873977331f0a2b5334395634ed2bcabf6ac8ba4fab13f0ab725b893f8fb9c1ea56d8baf543efaf8950f2ea3a2665ec4c12.9.4-4.el8_102.9.4-4.el8_10     debug.build-id0769484f73d80424c205cc7403d93583f12dbb5269484f73d80424c205cc7403d93583f12dbb52.debug0a454bed07ca036283c6a20d68cb500299cea22c454bed07ca036283c6a20d68cb500299cea22c.debugda38bda08fa56994a5c07ccad510f2d225e00cda38bda08fa56994a5c07ccad510f2d225e00c.debug2157d88603a611d61ba4c0d9ce7cf44862ece90e57d88603a611d61ba4c0d9ce7cf44862ece90e.debug2a2c05a1eb6d99fdd9b1bf0143401c0c5e25cbfe2c05a1eb6d99fdd9b1bf0143401c0c5e25cbfe.debug420a97695620c1a795392f4873977331f0a2b5330a97695620c1a795392f4873977331f0a2b533.debug4395634ed2bcabf6ac8ba4fab13f0ab725b893f895634ed2bcabf6ac8ba4fab13f0ab725b893f8.debugfb9c1ea56d8baf543efaf8950f2ea3a2665ec4c19c1ea56d8baf543efaf8950f2ea3a2665ec4c1.debugusrlib64cifs-utilscifs_idmap_sss.so-2.9.4-4.el8_10.x86_64.debugkrb5pluginsauthdatasssd_pac_plugin.so-2.9.4-4.el8_10.x86_64.debuglibkrb5sssd_krb5_locator_plugin.so-2.9.4-4.el8_10.x86_64.debuglibnss_sss.so.2-2.9.4-4.el8_10.x86_64.debuglibsubid_sss.so-2.9.4-4.el8_10.x86_64.debugsecuritypam_sss.so-2.9.4-4.el8_10.x86_64.debugpam_sss_gss.so-2.9.4-4.el8_10.x86_64.debugsssdmodulessssd_krb5_localauth_plugin.so-2.9.4-4.el8_10.x86_64.debug/usr/lib//usr/lib/debug//usr/lib/debug/.build-id//usr/lib/debug/.build-id/07//usr/lib/debug/.build-id/0a//usr/lib/debug/.build-id/10//usr/lib/debug/.build-id/21//usr/lib/debug/.build-id/2a//usr/lib/debug/.build-id/42//usr/lib/debug/.build-id/43//usr/lib/debug/.build-id/fb//usr/lib/debug/usr//usr/lib/debug/usr/lib64//usr/lib/debug/usr/lib64/cifs-utils//usr/lib/debug/usr/lib64/krb5//usr/lib/debug/usr/lib64/krb5/plugins//usr/lib/debug/usr/lib64/krb5/plugins/authdata//usr/lib/debug/usr/lib64/krb5/plugins/libkrb5//usr/lib/debug/usr/lib64/security//usr/lib/debug/usr/lib64/sssd//usr/lib/debug/usr/lib64/sssd/modules/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2x86_64-redhat-linux-gnu directoryELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0769484f73d80424c205cc7403d93583f12dbb52, with debug_info, not strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4395634ed2bcabf6ac8ba4fab13f0ab725b893f8, with debug_info, not strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=420a97695620c1a795392f4873977331f0a2b533, with debug_info, not strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=fb9c1ea56d8baf543efaf8950f2ea3a2665ec4c1, with debug_info, not strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0a454bed07ca036283c6a20d68cb500299cea22c, with debug_info, not strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2a2c05a1eb6d99fdd9b1bf0143401c0c5e25cbfe, with debug_info, not strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=10da38bda08fa56994a5c07ccad510f2d225e00c, with debug_info, not strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2157d88603a611d61ba4c0d9ce7cf44862ece90e, with debug_info, not strippedPPPPPPPPsssd-debugsource(x86-64)2.9.4-4.el8_10utf-85f259fe351d58df1b4bdc06bcdda4bdd66acbab5a4901535215bbdfb53fb4419? 7zXZ !#,DX] b2u jӫ`(y0DU  qFuWKiybߚǽ ]7Aۗv`l\b6%+٫1,,@Ԙ.lM81nnZq{8 J RӚ~ S❫B"e30c#hZ+/{ LP6m1qνϿx֯)PY E$*abfUz]QzIG d3 )w G!WhNrEs]Iiۡn%*"ijvU{Z|Ŝ!+~T\T_DQί?Yu;[7SjmvsײGKe|n1oB.^#+T"AF}յCQz,?id (n9Fc=@~G3s¯ \zn%"=jC1C\>%,Ti`xqMq;qړ!TSPj-Cj)qW{}oic G-,ɭt ;k]IE^Z_rW ͕C4Yx-{eKĦ+5 6psx2oHz^`ꓸ_4Sev~Ǻ]bxoǙ'D dju{SnHpIܳ\O--zp"HTlkF VrW#|bWl*wܾՈc2 \6`lL\rU!TKTAK6өOǚ#xbx4<=j\Nd*` &]h4 :-9; fjp'2x=WJ0WmT)IɄbc).|0e=}4zdy*Vms$⁏ULba>7j?ԮtE 5@ eXcKVτoɿ7>lSVjaVeivXᙷF6WqRC!qF ?yM+v.8r_ ,y@U|j8uGH֒-u6(5|M&ާE2 u;X"|' "#Wԛ4_T?է/Cdeg{t\8Ҏnn&n@NeK,]|t_^lQ=#]*#>D$Gcux5k6= HaY-)jьL vE>kY@X(L%+thF?R+d&f ]O7L9 N\,I5RlzɯQrq14Q)UM:l+̫Yd8<j7Hfnտ =KB2\zh*m< z+]դVwe9UWenKi4}^o醷fcvIF[Y>&=Xnu*L\H_ }Ԫe0Gr듁! Y4=N'd'ι]C{^9l\!Xrgp[Em!a nRi‡x)AT;8eu-Fm1=?-6z G?fUE&;{ٓKT#(OrTOŐk_TV>@>4*zjC{˔MG"6)0٥z9կD9]E]̮^C|iLKD4Wā5@FB$B^n: h^=׍mM"pfV"ǘ/lYu`E :dkCB*ѣkЖ}dE@*ݔZ0iLpd[D_̈ҵa@t<`Ɵ cO.74N$X*Az'9+*NZ* ޓاtDh 8RzaBD0'QKB3e k 'c\~$V[|ħ?VJo} &֜YbZǮ_ + j/&-W9ډ3 p q)=aX-YU1㺅=~1*} 5. |w@b&tK!f]o0t%gu,mu"A+;W"hdxNtׅmzuHC49yoB: pgX,?OE"8OmGqoWc*T^tb)1 NYw+7%D}e:Q Qy3+ntM>Rf wSHCZ ☬*KdԦbGm!l91'e'ia8.ҥz{4_*_w@@]FɊ2\QMW0Mc8{}BKQ,RM=M` +K+ӫIʜ\eXBw;i$@v73JF'qT;pevrutg\fM&yfaц%h%O&7H`[6@Gsî]*hS&hK &d'q͠cez2Jyj *qep |>ћk rSݜ.EZI2[(t`V#3v50#޵Fq-$9-85k.hhtkSnuǖn_`n HScCɉ^ny\P`Mu j -%+2^'0~`_Jhކg5`:}%{MطN3x I`kڅO̗/jK:L{z\ {#Nwu4vԆ0T4 FbR== {Еzx]nl. Cƾ_D) ||-D^ xG̔UA.c3*NbUM8,5~ 6$L}\cP$Hg,hR =䐌RJTf"mDG݄xBzt2h !!9v`T{u&x_M<ލh$Nҕ?߾G c@HU`v*B)8K(R:,UqO(ҼIXG ?ж3 IUgq :Z:JzMB›>(25`1moSSwj^9xs^rRD)Ѣ<%GYԾ[q`ǚϳ^ũVU Ecզ¦AE7[֩PA3jWEt""ꥀ}bn~!b肉Z3Gq` |du{isi]|?7<{FQ_@2UXh-&!Dłט ˈ@P RP!7Z˄(wh CHm:@{9iA:Po1#2 3zSwsj[:7/`W)?;pSb ^S  hܚוFRVA`*1 浺?P*]#A=UUm8plbt%h_.i}bPmSIX C扏̓̈́Z+$P(;uފ&[xJ\x5;@ixkl4ԋtS΂lBH2xU) S۷yGAHhb"~<nY;f[}[BUgdRe7)< : 1!`*{CWh: A/6>fPSm?vE>p M%owUʂś$u(Kt&8ܮDvPi.n gDA~_$pEi^keBͩ.zcԭY }ꇺ]'|yIb3U*Sh-3?~gyt͌ 8Fw"\eEg" Rj -s6R` V=,og/ Cf?%F?^-ꐜ\ԍ@S~hBwJk!Ugf SI?=Fu8xvrD]ۍBZˆO9$N( [Th$U2?GI S%;PS(BJQnB{ѻgOV;qx[fBH>oljck}Z5)sՊݨ)hѰחpyS]T|tWLwzP/QͧF7?ASgJI6(ѮEXuEtk8=5KGK`[]Jw?S͡v^TjX)`;}Zkk26/.)M6_~|9as-6qEN>uMK˗0AVo tpۍ\x@2բ47S @ /~\ERCY%-̽`Ԫݍ+3؁&㦛(D \6֒>U$1)[5Lo5!pG|\gLpIFЬDzbZ`n-Nd-—Vۺ-gVN-`E/+ cJE;J)-%4~w{.'BT@x}pθuM. y$)LRo`w{mL?gkWJd_v9Ժ*i242`#Dd^ -7#%S%H-d !zX ;<ǧklhifð|l ]O(!~z_8U/W6?[vQa+缢}V9s\ n :|dw.7pf!@GU4OxՊ=埵▚QkQֹ}c 'ؚZrRŲ oK5"0fHFxaC'mz9;Ҹ0=/SOt1`h"=pp.Y5jaO7/VctʸC;;0APU($!eҜv (bd }D̫?FrOHŸ>hk^qRwK]hBB>0[wNۂ!$`'9_AjF@ M&7"T%!WoqMlS&3r  ƴ.B̥py^zKm:n+϶׏dΉ:"+ߣ:'n5&sW@(ʳ ѸkL rc$BU :'Yb'_C=5&^n7Gq[|O|S;iDWhG-!QXϱN x;hMQM|L$<]ݱ9 qyIa,J70#sŠ쀨<+uffuLA(%GFUC)KQJ?RGځ$$qq_,MPYeL H~@ûNg:_!> ͑X_[+ҙ0iU"t2LMO )B(ð#˻f.Ⱥ ,?2ta-X Ui`>)70ĽP06SЭ%ٞd!«:¾]$5 x%&jbo5y)P1q`{hdnW>e@T=ʝs\|>@2Ρ6WBN)iSF\~I\,YR)X舏qT> O1?W7@Ro΢t:.wn+W fKTBZ;f<2N}>DS)5ETGT \g'cllIXz^WzIk/;A;>ʠU=`(k1тbd#Bl +1CZ,aG_1i?FkGdr;HS3"kprk2v͛v #B&A~_ gd)^rΨۅ]JPStJ,8wB<߾F?T9?۹mT; qw-I6`.sD5C. `0d+xY9bU5 thd.?7PCix]CٝB񀊽/ 1`Pk&m|cz1d~eTe;PǣC"3ri>WBV-bV* *ӵVsv QžS6Lz3~h?Bٰ͈8^JzRm'D.ނvw#%xx? yp&Լ_ _oŁvӖC_:U]8 ?L2y1q;hkY̜ljTsx8!ґ[n|\+ 1*sR$yb%@B-Qt7Qy彴6 [=_[Ll3s3(Q1PlG߇9ó$v4ۜqvtCZʚz#AtJ뻩4Q(=zitJ(N 뽴Yt#:^첱Zї[h,앗NO. p eSRb'M4^g &Bp3lmHw H$g1ץTkTeaMU.i;1~g[w;yCzUirfv,\ 'G2f& xS w4,DX2r90?̪ˇ.f/XkF \l:uTs9š-%t[y/$0E7·{sRn Je!B]ZFWIwHl86|- r)zqXvp驩;)ӐkC;6M,V iY{1ђ&X>U 5ך,vl2Y׭]|sd9; #wSL3s`[o?Fmt!k,:8D#GWRQ ŢUw8w%|s_cѝ4Vvd:'j4ttwclq<A0z<iRis6uU6J:-ݐ#} .K Ͷ(=D&RŸi~o3WDi"e9v=㠽2TV2Hn1a*MſD]ﲋ&TFXh>ZGCb*_r2Z Ռ>g:T?-ZMմk+NUU60OTǕfX ca td@wϷNHq a$>PIk1n-RhЅ%^[IlPl=D@%:L/$gber ^nGYT{ISg՗M`:|oAu_4hac"! 믤3{kjۙ:M}{#@l벐>t&+jZk\pt*BOfvZ2~#;@!- .7ŹG ddo!1 s~a13:E}$Dc?QՈ!ڸ>/UC(Ht4Ul (Tjh^Ξj+5GD 1s-NS5Cqpl/ȣPI,OX_(T<\'/Q)# c-xfslh] Hԯ G+^Z@muGCM}`R3>=e\(x-(3-iUc ]Eb :ַpFH ؘUp2D@E A<Sfgl_J9/|iT AlŃŜ"Jz+XHpvO8e32,2N& .lP@BQ  c{`kY>i ƒa΢7tSX[bYT>0b=C?w . _; iDRÈJs80o?=`23/6'|(7$9шwG脔䵬8Onn6,; >v_bicn#Tˆ/,8v5i  35_ mc=90cA-ښu(yjE(舽 $N¨y- .o;uwk𶧪FDFV5f~9#P# &?Vh&_lφGv74M/7d'ZLtOoeZzCNw51V&c>eW{Z,JT C~pfcJ-#ؿQ>- (v;.-חC=E8P4g3A{D`ӥWiI1dݛ`,(V~?ɫ1&ULe> sG=A ʄYz$gӲdep^:"!y.sRȮarDv{t{{ lfqjSQ,ߓ gg ;Z #Qɻovy!y7gpm`v8^\m8 .tXADCv6i$y)SZ`07' *a8Zy$8NC\:®҃ nh?'H+`eV=3ψU~eFX+lf}tՈQ.\n>SWtsg& w->>+JcS+9y Jh~$8FL@7;G@i,ۀ.GSXMo'.z%ʴ6'xIVhe*eW2)fM{d>K"MQ3I k*7M4M"W|T>.?&םSȺ]8^y#6oVbOJ?+Jkq64u80.G@~b4㿀`Lx|_-7^A)30D Vu]/l Qt| yZhۓ*jHV0=v2Da=3a IjP+i!oĬgkۥn:zFťK<:C0`m;L(eW=ԚȒ 46h7mwoQ?|ݿ+3:?Y<>bXsLCP㖶rYmkj<ōmjۜV 1lnX(.x/3c]:QRq0Nܔ3&wP`!O9E`Jue7*ID^:&}`-V8t oeΨZ]j;e1khƻ)}2*=;SQ&<f%Mn3 O=7ܚ4J/CܹKʄ[6 Vg)E w5y/fkXo{ ^v~ĜNIS@<1zml︗[擁cp^_I7[UWoeF2!ܽx/O C,8'!j22=RO[5e\άqgUx'.~#2 CMYv*&6#hQ:2Z}"WB1<=YBjbIh qfJBr@^t%EC%jEm: aP/Rnۤ{L/:od;`RbFA;l+$Qg6+*%ca&9YQ'|@L:Վ_[6AŠnJ8_xJRlb߀@$#PǕ ;k'`RTbbZ:阵WJ]CsҗUY8-ID~BaL&-I͊DVe>%@mOTˀ">w8ytO7ݒuu1M2)A*u-antcRYvl'p&zFV*^%lcɕtb;[uwJVҪ84Uv #[el h!O!V;%t8~WC{5vμB*ҍв2Ǭq o2o:޼q J ]_`ZdKNjL57+r-kQpPmԿa1=Ed7Kq,VaL .X]=q>]A=FH!Љ+e(.8Bbx{# q5VzY#gF,q(vB DD^^(`\7Tw1Y^6[VwS=K$ <1UGX RSGR#OA IF9X-Ӷ]xk@,ۑ);*Rj QHU쳚9~ꁨu3WuM֩)?yBh^@*Bhė蓮+vVr4#j0Nkiŷr\GTzʭɴ$e/5bZ/۫l8. eaMM0L#y -yf?[Q"E@ZL'*CVT6> oxFWk5C_Ry^m_)j[v;Hz}R qNZ\cP42!|#x h`0>q]?" / ԕ#R kܻ]I)R~DNfSߑB>j-4e*o%0qG AHOj+1:#b җiȭ\mIe/9/ܹ]^3VqL pxҥRqZcblz)`ţx)^,dRkyNsommO"5e"+"l^ ۵W]ېش/En,%eb@F+bVHpX`yHN #S>˝#.:\-EZq_kl!/wL[_]ಒ>θ̚ttHګm=MfDRyL922Ff\.5bFBKU#;ezotfB a/ʞ yaUZSJYH? +5Jd<-7Mc]dElU}=tXt%1գU2&b寍g_ )HsTm!YAF,e >5`X9jj+vTb~}vJ# \Gc?),Ne˞%|OwѢWw.n6_ds7Iqkf ZWQ ebvIEiҩE3 Y%oןI7.LOgcR(\%5TrZH "q˿Z=>rl203!Exlj!=w ŒwQFw~Oc 'ӴRomUN`zhuΑC,mi#*G~EvY%"a\s9()Fp&+_V[ tv~2X,j[vvM!Jk6LhV-Z8}ƶେQvp8/a".+p=k0L~Z5 ]=Hoq P"5kʢaOAtR%h&:0_T#XĊ ͭ]oLyL~:[Y܉%o~G2VS+UV47h0jU 3k-ѯ LTy\jfHU:y*q/y,h55KPdDYJ2|, ew*w.o$=:E:>Cq3ͦ,)bO{֛T$jvMV3uBqCUB:xGńs;D0  m 멮48RLm8Cd/3YQDLkūժ{ Hy푗͎k(gؗ}<<۾Xg/ kw+{3|XDn1Tó|qr[1TMJ*&S mR~DBCgO;܄bm0f}+݆ܚhځjDζ[֪^DWǾk~&gq)f.>FM&ܺw6Nܻr|:Ys?upm84 yX0&_~ķ^07^~^-Q1{h-ۂY*0Wxҵ!+ u? L1z2yxæY,fp)uf@T-/FC6Xwxԟ/Al ]%k.f?h*"Ͳ"|Llj?38S?:L Y(2SQ_́^+:fN. k{~CҪ/ϩd) ֨NDę(F11/=G}zb8\/eU ?w ;aB>%j;3g%|Dx.6Kg Fcbt:>h0Xk~SA:b t! jrÔ tXGlWVcDw4a7eCuQ/ R[z#Z&t}0ܒ;8Gx NA' R*QR,\ar(o[joR_WLEZT(2[_N=є-Cg"`@Ʋ*y5_Kպׂb[hФ`[wK[]Qi٪ObY:T -.( RMн1 7PA14BPp $vJ7YK檛XZ`GYUD˙Sgi7"%-_. o+##px]DDwU, V^@k\}Ed<^ I %=4H!6GO0["TCDsb7Bq8'[/ NnCaebW=&mB2]X?1U2~BwOh(أ{ 39>y ΎwU Uqi*"e ?`'ByBo &w%*G']YZDDs%k>N%|x,1|Hwa7)[8x$='w dP]$ ޚEgɏ+0"/ KxL N= gg],*N. :8ǶvU\@zH6^FjȺ࿧u{!=Ù._fVDPkf9kuaTBLƊ3#Bǟ6M qw\vw Lo @CuHIIGTlu)4Q'$B$Ș^/jx97%Fja&'dejo]V (d2)1-!'=v}.W&k\.F3lI~e}v<$մۏw ZF AZ(f VH~!W+yu6@:!W-8n|@!HQCL$Wmx.sq /Pۮ|;J~k&T^ib/ȡvk7ldK5zͣZ1]~CS@wKd9pF30.!2 =BJ}D5;xʚBh[Vv _D<O.Db/ M,1`b7;x-R/?>pfՌ*i8D;34;f\x/;4yEB9, Ճ" Xi/F\d.:/B -WncX\DmQOpXhE Nj+% 7ʫ f{ Y L#SIv;C`3;yw1tVKkWK3GL &W$}858 4|~Hqv&y3:3.9:.oA3Vv89Y`T< :2յ[5ߡC{'*~H sب8MpŢCH"F`tF,cTzEJ-|>wp=5 N`1PjtLĘ tm1 L#!KO{X* PgDi2O RI\CɆHl4Rl84-WcH #NetZ0Uꫡ*ߣC*Ⱥ̵|qc8P3;\Ii+ %ov``|ڮ9 P- 12 8I :I(C)kr5ʈF5:%h< t򮁓q"@෨ZLA*2x M$ 黏9vk2(\jE"gi.=oteuc޽ &w'耛`d,wu @#7Yy5nXu͜*ۣ:S]>SHbNOE/&RS+BP>{oK"}B[!口 IO.F<{Ͻ3"(+0PTH*=2)87e+Vk뢨 *Y?J$~D&JgϠ!%\apX}RMeAN&ԥhu/\p%A*=hz[YOL( 2TANLj݊+(1}֠)k b,໹z M8ſCGd-̌ۥB!{T!gV2<:8$aXY Es{L'}SkwɿjNֹpr0#SLdڲ`KQ2lDOΝ0!AgzŠX8th(:ݙN̶ua|!1׫}jlp{_hDd5)DŽLn {41% r2DVұk3dq E+Ռi4\No!BA*o/˛#q/1A e~AHr#F2]S7Ԝ~lT9I6K\H֤oʚX[ꟸARiZsT5>1vdkF".*f?ph9"g'Sk0wư((mU# w;G3$dLgJzs~tM`}3|ɯo2Nj{+6C2W<? vՐSCtRժIciU %ҙ!;E{鶴 )P[{,S9|ݓ?\=lvmj@~R\zeP4P"L0 *deFQYmMtTRޚB%k 75 ((/W~)r؟8gNQ=Cu6@Xȟ"(vDzٸpؿ!j>r՘V[i%JxhŒKho tc-Hua߻|8C+11Dh%`aovf>P)Wиz^B}bh syq[lnw1E)nayiGۛkJ:Twjn{Mڪ 9I2o/Evq4ΎܗIxpr;xphڸȖ=:׽ X+̀l3|OxO2w9@"Ž5$fûzCi+$ޑ -BЧ X*8~Dv{~L_ #/QS F҃F*uQe Okc ̼8@wW]i ¤g"g#pTͷd۠7䯛Fȍ|Y2 *GK~gvF+}4H[ !(ll5P YEw-@Lg.&[$~gUxb"7:Sh]G* @W"2fbݹL#LZu||FeyEQG.&Sӝ~+5W|?C7F&?dG/Zߢ pw3 CE{nq1])`H7p@-`|Dtյg@V1ѫ,1莼EP!g(o_wL]cO̮WǗh(2HAK6SbҴqe$͊X zy1c.uǿ"dcT&udߗufKiy ZT-ȩfRwGR^ }%dk4 zA ؍8: |9|}-W#nDd.!<C ngSEUf=$ CL[ bW Rj}Gc`35;LK^鋘!"aH8aKvnȍkR b/.yB%xwa7CH؄*( r-^? gW \WۍٺWM6Qص.m5"ۘ}Ƀ)ԣ-’'ol9aH9b/֬w R锧WkQuvJ"DDs53Mt Ɏ:ۥv=lыH 4WW5 eLY»t:wB[q(u>( xzj_y6_ÇM= /6j;%6:pԣm{aņP*zsX5Gm$u_P\U]'E]貯+Xnmr8&'bH"eyW ={&' -8xS@"VN}^㴒p Y,Snz1/{m;H܏W`.X/T_2OqH2@a7dA=U% qYw:_N!f6dj>QakH0 LXF u>l;D7MNq2 9յk\Wj"HBZp+*dwtע& A󯄚J̑'v=`:H{Vs7=h8*01C4[b=c&)Mv{T'$7R{5̞ا$']?ҔquC+0$g6LdfްL()7b@x6pN^j]^Z Eⷑ, @?2"F yBb2SCr)'Yϩu IVXzrjOFaQtre"U%31a \Ohkt3>ml+:r.NZC/<%>^lQ*^R_FPj{>7,6+ͫ ċ,6Bh;Ҵ85f\rݼvs*Jqv('ɤL סF)zI?5m2AgwbZЭա}+)كxOo5"q3ihYXiQД:D[o*?tVUnt< J"VcAf.F4:v}[F/'],yrղ;B|iyQJs\ͧA^?)CN2&#9zGҍgg=?@cBsTg%ɏ,˞2!QHŐcߢsݹ:R2 0_;lD1QH3E-|~ M:C3^ ? o6x7BП_2i8O&!+_}D7'  f9`8UYL4*+W`/|yH4}zkƧXW̕W9CGls@N`j %VF=0 ^.–TI=e 86xCAoTŰS$t%rV%aҫ-* DcwSXkԒxu>Kh w 'ٓRLv1kM'0v/L#W,jOAW}iW9Mx`].HNI Fkuo* kp#%~jV,f_L܋ )&so{)ݽ/LC~Hb4{%i鉓$AR; s?ޕ  2#>kDwWăHUG~fx\-%ƄH oܧ9vy#/1"Q@ UQfv/]YnGH8yGİ>K7MXXMކ惊7/NJ@K8 㥞`{pCn'aXB2|_/.5f5V$G5hPtTOW6{GZvad\K*)o##3?|-{d})\}! AJlCbc[2+H-@WnV%ύdK$QJR"wF p^mq`:d8%B'/ںuzuw}ȸs'V9M3~4<]-[mPvӔEGJ*y uj $ƎU)3#[Zy|cO˦筯RiWyJ lA؝ V.cS`i^*[h95g7kXQ[ 0Kg[ ڟ*g$k'śEÎ ʧv ƹJ@i=cy~u3/׿xL&@ٚm.5VUwpyzZqpGdOG'gRf Ww?0 (ȔΝB\NtB_WTRm޶čH(tj0 km:YJ(:IO$Rۗ _,ޝ |ҶЦDz$EV_:. Ya8d58۪od!ݣ ~LѓOtY"#/Ƥ5k$`P!^.]  tN[}H2dn>\.MG1#ס);0c~<<09@M<$7.>CI( hW='C? !zHg!P0!ȇȩ Wx(_5@u|%p:JZݏ ӵ tQү($nCO#pN؁j[”Tf <Ez NPMv4; 0qO'6 `ղGs(7'ٽ!T&3;R[X~HᓨW?R;K<*ˑ7SDIdV,'oFGy 0B΃!w |rM˯1"-C#s]y5$ݤEljN"bpWߜ ] l=V,+;>Mc|*<ϸgc@lsĂͫ"}lLaQe肌Xi߭PY[fa(8T޳~Eȡic('Yi£FRa# Y*8Ц&2ˑtijWNP♅cbɹDw,Lȃ3>~mEbɝm>3f>0 Qſ8x6)E5 EHadZ4WgYzp%02jqZ@'e"Z!Хy2|}e <;-Cڭ /*8wi91Z,O`C|~N[F[DFS!Ui,;[{X^5:?rhaͱVߓxZ5J3ܧ$([PTz p/&7"vt ͉C;@IB44 xM;R6o?I٤\΢'DE7[zn5Mzf]`½jrRx%-h`3dnǩ)LmN!3`QtHjckyCRJ+3m}upE5T#qy)(^1>"Wm2<̒[HGFF)J~AFS=eTGOoli`r?byVEZ#A0,{ȫO۶Xu#g;#sXs5f{"Mw'Rs^UM֛IGkX"BȯֲqH*9Z{%[5'1ܤW\aMa;(2Ai)(B3D^~ԯNWSVK@ }p&k nSN'#z}\' #hg Փn_V/ҫj22\D j*)a^/L{AMT,L 9<-m,VEMs:-}Wi-M${gwyF=s̎Ty5n%wo 1P)91dcyq!g_MUnZOߣ=ʽ{# !o%s=UcZX,}*Y;PDao@S~[ۓDlXY2!'lYiy ʇCTk\WDфM4+`co\a+trfbnvu3w]F1|?ҭq#oO̘b\O+vLLT7'\ d'|vff;@SL3 !ӄ9Cdylo8ŗ~hPjXXyֽCQ7yZX$P9KrPҽ*FT1<J.nJBMzڲc;>14]`Qr$ikD̠kb ܨ; Zy#TLOUkп Y5"`6-) d.DAYl$DIJK\̶p:z |’D#D B3)ٜ9~clĂo `%rE F>$$6F傇xc4}\sS6 vHTv `D+^vFC4>__LC%gDQ%aoeȫtcUHe-KI1Qr ŵvQ:JOi KRMFN+)>2x2XN}w/Ksx,K&o[ ʧ ߾P9_&Q鿩ٞm{O0h8aȫ[Wqk2#mCU$>AAwn=~j`GŚ}XBkC{R0-n*`IhhY G-^OA$PygƝ "9 .؞A: r[ܤ"T! -,HOǃn{g$&S PA خxeT$z #~7ߪePI>qRy\\'!" a B뷇ihz>5$sn/wY,v"!0TTGۤ\-?($jba8T~5; q<\}/2] 2 c^jr40ϋCw'}(ORv!]K%ܛfy4oi4wZ;*%ZHPf]f4܀!XͮEU{9&th( K)=4b[uiۤtfڲ@c(7FX\Ly^;3 x矈@8зa{׵1da{l@VκlP1iR~["kOI?e6 l;;'ʱ^AxܑhԴ饟wuSMWIoA5BTDs\'n+煔OujB0>Y|28bpXu78i$P!$֊wb7-[n .=jSᰠdKB.[f,vK]0aIѸS1INc'aMs'saFE9덡 ULxMXE@!Q]\*tʥuH|-sQoy= E &/Vy7,ww#-[OY(`:y7/3XcE#[U]"`jLof~,},ln DÙ;J$vVv?#Wa 1e/ͥ"-(cK]ԃXy/fq] sPE1V_JZE:JzVd/J寇Ў%b%j 7BxғO*XI>\m Oɣ4o ufܰ_U:ӽe>Jz%$3[(ʮQ:]m k#~ںV(;G')[[$Y il|" G,ex !jcB0U `o(|egI׳<ɀK)۔흡Gya  E6+* r[Nڃ>v-2WYԓٟl*QFhl.ӭָPtcK\6\GX-.԰vn\W|D\.^sB{*S_ٗB6pݶќDjy3#WL=מ~hg' ZhrMVj.;buή Q4B%Vׄw\@?˳2&_{WU?tk$Lf\~p (ZX)t!$p&d}@ eA媀C 3YI@P'-aoV8<7im„B`s~Yl#E(^}81̌*B]>bUw >GD&_- "Zcᒅ f^S{ޗ1/i3@8UnCÇg,nA:̀ }'KX8So7.:Q& ۢCD&3 '{M!g$s 1ZgB[vK>ܔ}ǎ#Vۨ| "'QZC>CGC I8{EK.'KxR`/{^`ls;&A&l{Oqx{u=6ed&AHT]v3>]唰.MX@wY<^scH>RnlO ~Vnndζo6m(N,v={J@r}QOJP8HݘأWzsۜhOOe`۠קA  f#v9Go<˧4ܒx $@)SwqM3$mŲ f0\Z99\N4{]~ps[iׇ/Gom,e/<ߛϣW2Pثw'8S{0 }wѽE8pp=R?/=`jI {T ճSO@Tl4Ilj,`/EQ2:h'p&K;>>ͽ-yֶq3GkDdNٙz{Ӕ@ SeZIBB=2/Iq.̝F'S|<5u>< †&yrfVAwPJt;SgNvZhS?ܒum4ձP,3ZZuy} T s6;&0򀚭Rڗt;z 3SWE7/A".M`[@ܡ zG=q(,Եv[:f: 8xH|:xlkꛌ\φv*,[f /Slݖx-`C6@ G Lqb״Do jr@GN0#rD.ľT)}DTo*ةh<(FpM[B&2ۚ5Pvwq} ^~ c =*bvVQ4n rJ%,VHB!@>y}{xUHdS^y[&$qA!Q2ce#6'MNgCLQT*WeNCW&~.?&b]W&_re(TH!h‚9,Y:/[u@>bOD8N\ۥ:daf@Ͱu~S 'kcuGY5͂;MǠn<${7Rd5#8:waԕ<`Ɇw$sFˋ.)7Yv45ʙ_ edL;oI;x1^T3 CSئ>$Dgg̱'k6C@( A¦tMVcdKbD9U8aQ&.F[lH]GCEl&O7Y )+,YnS'IFm:CN!1)^4v3I|-2#61dٙHGL+y|,  Ǚ&T4f)ue |h aҽ<H>{ԯTu`' %;El˾]Fޭ"iF&Ji4՜vBۍNO W,56]Oz˿e+ɔ7 5ˉhap(j1'?eDW?~JhX_'U,~]bwitE:5U}w?h 6\& cFk O ͑/?@9 {I?TSάOJW I/8fDXYUl4B?w O(;pSQ1FׅQBSqsxh[l>4>B|sme_տ-|Bزx7+: G߭Ub;"TMtO ۻGxN]`7]]&\&1(I~qT#,?y#K(b؅ VG^ӛ^x[Kcm3yiG! 4[4 B (mFRYpgoYmr>0Y6lA_yi࿢;rT1/QOf7 :%z!g 'GCk{ !nCY+-!a^r?MJ0Z4P-Зju)?vXq'XfF8ېpVEyLGSw1.E[40b%5{Y7 !xtO`oCFɶvGƵlnSLX ]y &!1r鍝*,kQn8,%UƗAЁ?YФq/t!_uUW" aU-+5ES"טMNZSH`m gה:>%j]hM B[POU59~3N(1H# HB@h #Tr̯FU$$82!"6/Ne1䙝*9j=xjww#6#e$yTczj|'_ߊQ_.O;p8n|#{2g?x.&w06Y˰zHqer.p"J*cN@xBaMD!"ZB~E'B@R1]k;af0T? >E L vOJ=ؚw0?Ʃyj1X:=HZ+y?y'ĚyؑHsi)&=wVWU3oO ` 0R]+tQ\Xdn l]#ןNGՐn7//^O#ɕܓ`޹IWToύzV΍Gx.;9<Pe[  \ xJ?8v/+>se`NcB=.?q%5fpc??|H(,H,k,] a`viqKA,H)c`uy'M}lmT[Þ 8*>tA󉩇l(dg\_q4{)*/^aZ|HD?Cj:qwaVx w&(WHT-̌FXؒ4P"kn[2u;dP+9E#y"6\?)W `{2ߎW"tHIC]`_L=:ڃl/h5$і)a%& jӺ_vWPJ=´w>,IHlUnx4ui{QbCXX{8r(DՈDǞ*Z`H&Ăj/Ÿa/w,+=&zduuڬ͒bOO7E?W8O_̕Qipn#ͼ2*?Y+GJNpq]aKmu_js?*.NˈG}Kc S7᭼`Vˬp l&۫H?q(H{sUz~_?& ~ n1X˖vVg/(a2wuG!? &̖a!ъi9}@LT`tNJ4o*F[{4CЗYӈ1$Ft8v;mkԈY1JɄ4^VNcT-e(>sje̳HDHy4ml90Y'eh† لR+\H0j{d,FnOB"H[i4ǯpP!K v4xbK ]O~mBmЦQ(0VҮCMYbUF2PL@tnw^V k/@ 0`*z3/Hkhd5iTs<άWNߕo$=o`bPgd<s%_PG+Bz>%θ[Yi1+%55{9Q ;x%p5vut0YOՄA\R,Oy/<dz9ttL|l88&Rq M1 xߙ?նx9+hJ3ά #؆l[+s0`O 15~4yw J7 ݛWx)UE ZtYyrd|J@^ZzY<]j ӷ͝!֕3q̢_l5.Qjh,ZBb^c@2'*^y|(~IR8fΏ)k?C?聴c (;:A]Ň BUxPpS0%d4)D鿧:!QM e:3ZAyS5h9o#A&DXJ!_jaojCY@_J&b)m,@@_ ?pѴ>6թ & ~+v-ϼ5ޜQ,7s n|r2vڗXkd~Oia '=.rOѰm6sp_sq5D4bJ Y[ Xy@9`U c5#$1잛ߥ7&\`'1fN"Ů㧔  xƜhaoKr(&@ JOi:Gc*[f#msKPۏ[GA[-=W\Ɣ9) Nҽ5OOf3W-=< r_& ^AN^f`kQA G8?KuEٿu޲RVkmKq.Wc9Kt<%rɬ[SHVN%k̥KuW]dZˣEk[XUymƼ'7!b|Df><st}/Yr32q84ߪ68||-;GCW'Mɯe{ʖ`|kWzA"qG]R(,,IޑQSkf(gt5g %_A}A*0A.Oѷ?>lbd+V3a1KL]}w}XXgdn|V &z_Er.U電&z؄>:`xÌ(/@x_70eryUh_r[=|co˴ԶƏ^#Ѥ`Y #t`^P*2=r$wS t jԫGCTЀ>>~qF}!H3pjQH{,ZU~3sPB ڐ(ӧL5lB(Or< uF=t]W#Uj;(#jO1\P*~LWWzh]FaTŁb%Jлg7Y@3 Шt1j(̊;j&( x7'TX&UtD>ߡ _9 A\RX!;/-6ʙ \$:7Tк\xD2@Yƛ ]l࿛T^P䢻6?/0KyEd+T>g&y<]9ËSu7.ovHm7>-frIlIkɜ:@ IfU$2$>+;7`9F"k;d;|AT bK Ft],[r~FỏnrTj 66Q4$}=r|h 瑀o|\XSpP#OHF2+1ź"U{W=hT13lzWtq;z2 0b; ѺU}ʽĒJa;+[ps}oeO L; #[`K [GLVXgqOYɉȬ2s %yˊAYӲT7LĩPE>t%!e(̃"DI;glMmv͍k]YQʓ'!A,+r( inBwʱ4_]*Z@w;.` )zJN+= ^Ь-A2>yfO:Wy;5&뷝u 2*ev 7z-y˚r}׈塚7؄Ҡ<@2 NF밂6Ov+)?RteSlO*ϗ\ >­nu f-AF*φƠ}?Wo׭#OeK1ƼAxG {O :14Ⱥ[n sra02u6I[A/#FMn M;q6X3]+:;ڜ*9toe`.`j͞@yr7X"b!z߅uQ0Rg6 71Gi~!x`,C"~ d°ls+=z_ _ .I/ `IuW>fh&gS~,+ f4$82\ zO 1j<9(=N 1E&_j3*d%X> g\(!!ܓLc(uueh*l ?¬~R~CbO8mت,I39 ]9 mֹBӰv4/J)1k-SoZ,u6DKi3V[+'3JdrD'*܇,p#y`wқrl>ZOvIC< mѺj%>Z[]Qř{녁[/y֎,Gb9Vݵ`oHJ"36ؙ3+:i|z}73(6''Wk]Ǫv;u\@C=FGyԶF<Śg58rM,;cLHsQ'PF=Aөe `j <# nY>;w&{$*P 8p\X e =/ s>LLGx?(%,60eۓg"?tS;yobp<9̊XkcnU =:z.ӂaj`|C]I Ca v?S$5WfX!P9THK !@;r`{]e5 ne4IڳBq1ߛ>ܮ6Y=wPyJ$,Àz ~jDLzE.f:Am,Ֆ@DH>x`RB: CT9D`q~iĵ*O F=:F-e\RQQJv>+I^zdT߆v!NF/૸~w N7֎}&/J.H*@}`ѡd-4 vGc^wC:w*ŷS\,W߆EKL5_nG&zԕH}79VGy#z!wNEk^x+ dD!38' 4`y޿֍)*H҅{q\ rDMD:+bZBHQڟ4:MH;fƈ2;m&0M`#*rnʋ8UG|oP _' xTZłr @R_fhoML$4SGœtFvn7e}{I%E{F-U@%nr$.Ycx0ȅ>!w\_UU!ǥ˰|aO7–e <䗕[>*ըIL;xJv|Z/…i~`UlHkVa@b Hn jKqKz{2[^.G {/ܰAxRob oZP+N12T ^uX(ꂂh f1Ý\gu01[˕푓CVSW:L F2¬tXwqQ(ȷz4)cTH.Q@=Z "ԝYVԆ4nWVS,{4ΣH ,Δ0Ezcߕlg?4& dx&7X@ϼHnh%ۅW O,`.ɛx2%`㷭`!"}L)Ay'Ie6["[-ȣΰvSD݃$hs+-̸!I%>\*WzO5QLqX۱?A!Bӵ%vpc-nkyǙj8]Wg:;~SZ &dӠk4i-p 1i, k7TG͉-EηѹXх.lЄd3bT naCV6bȮk`9}R[g afY*8崓?"#@Rc/*Xi}g9˧ÕʀP,8uhAѠ0nL&Z#tPS7PyߓՂܙ:i)T9!uJ&7q0*t:GG{M@2wko!փCSlȋ;P?A9DFN^~RҒBSfF$\|P}@ric7;,qڧH ZRD/sy1Hod-uJUЩ vord>3D>}x< Ro5<&iCIշa6NsN\;<֪k\1'@Jfݑ?,wvˉw籺Z pX*"qfe=ͻ<з P!s𵣤3 n\Xvb$ ꏵҚiKՆlbrt&A4Fĥ:,#KG1Wϱu $_]D ߉Iƭ-a" 첬= 3ŴȶB dӯڐ\Q?ʣ,S4Y)Qɚ?  NNwS<'eڄ xkOٲPg g@!RqȏFdU/FѝGӒm3:q=]AD!7whi1V6&&IMWF uN!Pa/SlT33e1?7OfqH rF$9!8h0 w?$<./h_6Bqtj1JV]IzJld\430H"WtӴcKΗLлKP],gj:G}"AZQ(%m]VI+E/-Qhp: *O>tw7x^+RVcpBK#lq_\/8kxɞZ@/S&wrm&|Eo$ 65. ګ[$JҦҢgP4]|UJ{1.U:2v "1ܡol3}')CYBG䟒`XPt$~`t1Ux~%Nm@7zB} kx+IvhdA R * 8dSqyk`#:uR;;g$H)qV"qӈZLP!;!]tG`7 5`Ӭ@Hk>&|/Yo[+B}%"n)$R"ֆ\$;"z&'aO^|?[W7$0#n]3SQqeT8m/Sl!!~?VC?Dn[y2)GݥѶ Ɋw=u4_CӉ1:T̾4w;PY]-1ڵ~?)Jn C n̑'ybw[_I(t'P_a )cT4W58@eP{.$HrgH-Xl*卹Zӻ5FT;@Z-$``q.%B%WȱRעQ &v|IfdZ،|׋A$zC78"OHuL](vpjM\@i8ܣPig}B=,RUnPgzdZ;!f9Pd <:DQt MOq#@swϘI0dX)džKT 2;#vDߖajmX!3$BIIj {UѬ:j ؋|_d[u6Y[J pRR 6ċ727[RI~"r[WZ%!W96Ѷs*AR&(@|.=>aOF*9GXԒfw}M)̀> 41(`,(Ǿ /}N+hƕ)wH~Pa!Xs7C'/$|wȕD樒[A1PI^gS.ijpuLRVx<K&$Ѵ='kX٭~ ~S9bih&R+{PQ9]^:蹵!pC;< ESZ_Bu.eOIYͧ\@Lu۪z>Fa4LègdDC,_{$sSY<J&: uSc{N]Ws u=~ ᎒h; 2ƒ R\xfFoƱ \^Ci~TU~Ifx/ x F׭/=[R.l"}i,>CxLexU(I+1!d-Dw[ED~ή)yAjjeޱm*Pr0 l#T=;\C eW @I{-́0"LΤ֌mC/|n䶑) Eژ?BCb{o e?9jdRTnD39o>G/6ĪH~t8uU5ZS ԇ$89L;N* =F=IP)>YS ey=҂nPo_]&4aPkd(7H/fƳ~=V)awVȼ EZWCإ zSx>"СJ>&dKDb8"~pMғS#پ[,kZ rƢW>F&HP!Rֱfo% eP9ʻšYjܚ(FrR<-JI5U(%rzC2T.k=8cHC1eD SKIW᜕?ȓ2L6%瓑8dH*FzTɖ5N)&#aV75M`6LK~3h9 Xj^=+gh4~G1묝UNbSA ZE~..*+ÂE[n >M( `/X/^Y|k؉y _}h!Sjrۀ5]A~+ŞZIeD MaʒͨM}G v[CzfǮϮUg^¨{zw"k;*qt2u]>Ŋ8ƕJNɻ|Hd d-Rzxg-,vB\vL ݲ3|͵ M 0Z 6wKT]XpWb؟=X:2_l&E+_NɔD\ofS+%Dy(?oZfຳd}F1`L} 'hi%vk"r珑5CP+c!FH28U[ۜh21#LC;cl8?⬅gظ)pk@0R|AmdžH7/$7忛csz\Ou%{cyKtk1G,^3Ӻem+aZ. '.⼐cp j#F|g[ γeN1`6s5Fi #nn Ū*t*(#g>Ea l.BZ<A&]h[Ir' sۦ!t?Bgٰ}blh\aۂeϼF~;8}&v{B0m9fi]`zLE/w^j]x8`I㵉,% ! kO.0x(SW3$={4%([2EjINV`?e#AU?[?KhDr7UW3t{@$H 8n% C^t:gkHR*5j6G-^$s>m_O55ZT[Pˈݔ#mH#+}g{<۲L|Q46*^fӥPG\ 8ҳG󦨂GsHlЙ)I$\:N |ZjhQ^@.[dr  {'6iĕA85)UM k^Մ=q}l fԮ =5AzH%^@-;#MיB]GSΔtI# 1ib*eJ_}B\6v7ۋ&-GOB ^X+ga),RB.@$+_Q#-IKV\7cQo .޸67*3H6*'z1~ &S^K@Do-OF <'^%b[&2ҝ"@WMM?Sjcλ!fh 4ܷz] ̅sڟ?iD$Rs;,#Vm+UX;oc}0Y M9+#G~ YVuC&5%t)7DdHa>ؿחL%[U U៙@{zkW `D~'dw ?Jx_j4}t FhJL_h5eEU/%V /P/EkGԭ^܃/tk2}D] dAXpkeRm Á<;aT+Iymc%';+ApۥdQ{cE r SWJfr:袨<r8/yF>`益^9m"zϧug(  6}8j88VF (ƧJwѥFeKcls!'TǙK*V;\&|&b$=E)y/9eipЕnC!=7i^, 7 metHc 4˧ S!x*$| _U`x1zZ3{ǀ gy-dOB:$*AR" ǿ+vJ ?$AY\Zr2SS~jV;Fߣ),:anvnv]*ڌ*("-?~ q#U/ќ0]k'BR(p-6;/{S #`H e7Z6b8]XT-izNO 6fZ]?G1q*^и q?@kD1m9m)  FL}{=} 檜A989n u-bXf7~w|H_i(OX&kTpX&sTϷg m Uy© $i"B+g/aY5 ji( 0X^4'0@rvQVGPqaW7t^#/kj0mo7@VNӷ?s+[/H=RzJ {ްpa%oE%~ (FQML@ 5!?U@`1(.,pLםVHtzB梕o?)MTM;e'T/SsisLp&zCB>;GZTFe-n'MDQǗ/{Jo7.f zLZ q*Dܢ0iN`bDsP_oD+%bEC| {1GA+vLXjk(mRF7@PhB)E'4"oD2K7"o!a]{KFV@yu$:HX疌A}Ad20DU-\#QjJQ?()LBSh0uKCi^3/n2qZEo]{/Bf 3;Ԉ+_hO#[wsI}q! I"jƗj[ߡ6[0&4{vֽ &,2)1Jgufڒ Fըk]pVUIb')vQր^K U*d+wz?׾ %9i gm-HHG$T>iIii?z']z\yuDG[:a-PSTsHKN cs>7s6^V'7A~|q5F)-ckLӠ^vVsT8}{R=#_6c5HǢ4%ẂVGapIvw2):;]%ϷgMSR9 s#U/Em.<-&CTR˂U*zl wھH`?X`=}X+1y.=G#TxE?;F7jw\b=9eY X?-Ba:\d=!MZKOJs6|7UL->VD-wݭKc[RN#Kq 4Y:\Jޗ;9MH٘ VTZ`eI[JUgVp(G5o;(pd}i7զ}gYV#\y]`AP"$u?\m0 wVZh5]_VRދ)7wDV280?Eo:Y 5NMHaBx~51CJݿ@Vb k.fEsfZ~iau c3eˍ5\_|8jA֗ mn^bťbp3f<?')z"[,m ؾ,G nsjNxFMhCCeƜ;)',+*b=ȃte?* 1D>juyI:#<&I ޗ,fOLEuZT04NK39[Agc.c(XjuMPUqqz~O}[݌$@$V:lܵLZ#LNjE1R1hT!Ietw'u|YB8XbZ|Af8ۨKmEզEuss>w@zOH*Bgef#2m޷tG/~ӻ`Lʝ->SW%Ԝo.$WfxD A%7%_=k v| JwOv)IC;+[JƓUy˜띋K p(q)pG6LāߜE?Rq__]/Ȧ䮝pQT$ qt;Tst&^|d ,++ n7`Mm|$ :k˰k/`-jMC, xz[]BGhfOmٱޭ;6!ń>q_ABxu\ǾN|jPEOI4hbhnг_qi~*L[7H" sjFYDW@nOh3#nr&P% iO˲GMЕ!|lr.$!9J)-plju"уzL_i[xnahrI6q 3 3X@O] HqGgJ]aq @бR<傾n`hOT3zĆ[tnNJ#w{nZ[%?RM]3DRH F7}**u``$zܸc?J%Z/bizְ~J2/sH] a:ދw |XDKVdjza#sWQNյ9uGIQzα#^܌fy(N״ @t"n8Ya\t'V5.\K8KvsRkzhGJNxP,w6](zN2Zl'|O6:Lh6{;Ց=\9࿠)oA4hpfL\>JuQm1ΝKTZbdOj%Ckl Wu6qTf*. 6v@[tNyS;l,w;(N}xً%ŤJR>Y-VBT<&gUΊ#\V=uNǒN'u@&4b\_``VAV(7 fH; ۭ:}YzxIMNr4FZQa4{iJs'w&>i6uqnAS0VЪoeJXKH,+̘A9(}bNtg"R`&z'7|~JÏHRͪ[^i2/ȼDpNhNG b/ΡS]ӹm`zMqw 4U%]XhqvlӔ&U&S oWd祛ќB ?\ 7՚WHՆ:C겘$<:=)F$ \#xlMx+ wr%V>eZ2i`]<;,{;6M8)i JI* `P}A[ٙ "3y0h!F}'M(Yo¥YS(u Qрc3js쵀vm8!Uۊ?p}>^}c]-iR45 ~`9ؒQx{$>2e(MG$An-WԛU蹧\*5.2: \XiԆ 7Cjw_rW1>tq][\ngdX܆ kUR{[^ äa(wȿ 2'Lv IMr?A)/ݯlJUgX'IAk@lho[ u^bZQ|[X>'J*vmb8 lW C L_mVm_d!>xUݝļsW;Oa/זaH +u'|ARXO\ `<"ܸ2+oS?blfkuOUq;fkpRU{/␌zOq3UBjY+m]A Gno aw˖6䠸3J8ڌ+k]u\K-zo xCA7,C# m P^s kQ4&vǣϼaA otJv-i@J҃!ty<adQXA? ہxκNC%t׭3R&!JuD||wv,XXG.Y pF ckΫX)@xT$QJ# $IC+92a.̅Bb9mp.?pb?t%RUf٫a6kWJ2JkOnx"R~Qh`ӌ@7 hbtU| RjQf bwC4}-O\Irϭexی&-Y|MA}'51F`j:inM0nAkD*iSSz=uQrtRqcmąLF{ yCq6TRi8W\Bϋ[Rwtq "'O7Lc Fٯ9% ^TDm^nDv~{OEML ,G'R˗wFӞqڡ@:C&:-D)]!f Xph朆94bܺGEI&v$'BV} O=,5B7õIZ]>)l#,'֭r6Y@4r{[AK`JZ mՋ7X/Ȫ@_ߞ͢Xc"{$'$z7p`aY͕;%&Fh=ac PP_ʺEښ)BhQMKÚ_Xֳ `rn.˛F"0θ2˾tOɲA(Ld)LZ$,о]r1Z߱rL]Y>.*Z1}]J2Ӌ**pEm;*~cyccBʹai.P|ug!d+py;vy"}4n> OMJ5(z"?_F+c=G:n]t'?o'10GH WGs&cTcsmF/g6=BD, %o рH/%>^7w eW=9IL*24P{4阥I酴T,!8#4ŝ3W&10F,׌! XieeY-C{TYE$wywAqDaK"ϣfֽ31hce͇ԽfےklRZ<9G|}WҢ r2Ba%&`720z n #Em"8wXzř*'K ?6Li+DbV0chk@Of+\#WMtݤ 6ͣl -7e^y bekݤ-=!+l`-⇡̠@UH-AZ q(XHuƵ/'sCK6+'knRyo6MqqLū><}w/WaHP.`31SpU|_:Roϋfjد)RSY_3AY8s )h\~vWȜvivѯؓ}z)Ww6E,ӽ^ yxUs zpƲ)Q_8Dz.7]T `7o~(O>n|(,DҐ@1&AC蛁Ht< o@##NNvD2G*Iϑ|\#SפE4 ˤ'yooBANzo2/|}6=P%%ߛVѿ r@3b";{\ǯxN_YN^[|B ,N3xńlKÇ{ISl]e:,`\fGe>LS mn#NHץ7 ~"k;m6# 3!sӧ|/Nv0,"c6[MF7^:$VsDy'5Px2?VQ*_W)39Y$0ArinojXVK02÷Zwc`Øb ACȹŵB[X@HQ+ xטmD uc a]H DEZ<[ʞwRMIZs/նIBN]"'uut>og5c?櫕.~/PCmҌ$G%(ȂVMVCG*W6G|v?$ '#Q5k>j',q}oo!^ PZ:x!rp6W7ս[\Hm9\K OIJf7nU19zxa>rU%PO?g 0w߰_lLjتw!Sq[ϐuv4CfSw3mW/c c zsm)Od3\"묉eH씈 3ڦK(e`GtבEO1'>c$;wA,ڽ̱E"TWjJ/:Ʒwt)8,|`d3}a|C :\-ZA.2xxCk84WHW-`]D!k77] $qf$Fb|pK;x ᕑAH3(:! Ò G?xGü#qaW2%a\юxB"@ے=@ 2 b&@S߸oM9M" 5B.j\f{ay9XQB76=}AXqꅑvZV v A 0[<5(Q?@q7/28IB!zӌuo*MwnFy ha[R6\Ud%iCʤ$aesۦ.\ɑ"e剛inZ KI$R\QwWmW˩{z|#"t=FC>r6iT"C6*pBmQiZb2XXZBR9Y|]9ѢZ94_ ׾PU\hޜxkBtn,}&>UHͪ>8j~R 㫻Nt^B/s}$AZH$4X e{uBT)4,5B\6 ?8))FLc}<.,;;UtEؗ=ۆO'^ˋjN`Ba:67=2 27FJPE`=&Ϋ9՝.-&^VSRM4R̅T2%f+)8[Z*j${c`T:ULv}cozaEb8;숤8< }RFxEK,K }dAk;4{w]-U`VLu `8Ts1ۻg)y<FxiՔm@UcTIHc~/dw"ڏ>P0~:,r{5{Q?tnAΰҼ,/^Yȳr|4{۰4q{>IEIFsv1K֡ YÎiS3hSVGea-Q}~O#YF𑂽bJZ3KQGJP:o7{Dx!1(R$$=!LKrT#2,>xAI#&nBO^ť˥;Nb-`ٿkxC 0`{4</b(.+Gn쏂_S3޴ձuIMe{C#]<#؈bڎAcjΨ@:&̼wzZ,Z;dsVq!qrkvc!n'jaЦT /`M! (!^&ܢ3l)0;0PjPP(dw~F;u݊8%i?Sp㠣f[Rn\r~ݼH [^vY GG {I~4|5d8H("FaϐЁiu Ksgcv䓅Eaq-NP;—|osmRCŀb@~!^]@ϥf[@>7f{u `˷hPǓ-7)oПںbP4ƁYB4S<7Q@?0i,Nϋ6DhH! )޺=Uũ=P*bibL(rY-{ěP06sh37yneLn@[Z5uzPT`Ec269C|sX@䘒$L0&t(6c )&85 j<$&wi4I6z:׀CxM,@f$νK M2/ x CF22m g]kf!g?,!!dJzΈ.TȽhC`V=9CZ(4bR,ohB:ܗ删 `e b-vh.Hel4ZUBmf)U.RS@б/%. qO@s$ă}6f'ݒe[r& hKҐz'QP]b[`G2Y la=a\t ,7QCp׵sr='5ѽX\ }mxoO6.ِ|Ee8qu9ٷ|+> U38!A-j_HvB2bp( LՃOtq(ߢܤNN)!u+-/: >oA9>V.rԸ7b9=I:/kHM1:xGC24kݵg[P^¥ z{Xe>I^u(U>~7m3E6/!{/{֋ڕW`%ʷtlR28u4lB;:yrcTW0K&L9uLu'0DmϬ!mg!h5rMM t~Fs;1`9'F=ī) b6rc FW'C-DsJfj>I> i}Xm8DNa7VFF9 NaS3`'wN`ZvI:Pt?"5BוR^ q+̔p񕿛͢\7TNO[G}i,6u;aD7XnS}f-^YPTc 1}WAaG<ӈZky?. ߝ_+!e t,UK5)dbMD).ee(fQ 8 3>H+ʕʳj}pRK.35)eg&2IC&TDAdMlmEU5\¤pO{xoMJ hn)+2_7$b9X gxۡ"Mgdq0 +Ir6E ߒU`TUϸF$$HWFݝz sߟf:A^8')o ԉȺ-\iqjSrEjI'@Ͷ(]@tc) /$+ͩڧ eaê%N=:ZqOe|mm`:Wǧϓ0v u7^9:w!^[%&x',kӥjvWWBJf3׋kxz5JlKo]"J $E:oo]-,L `ZQ<vw 0K[.{h1+6A;#@VJOWׯJ (U["~A2wbH:w;@ xt%0 )չH+fԟ+$*z;_ HoD2Ԧ;;i[ :"_(wxV0g&܅Y-(Ch !f] ˦ʛn f^[3\h/iQ5лJ/'lY& L4" H6Ϫ5u鏺C=I:Ȅt 5WqڔBHtruL"HQ8oN944\cﷃK an[M3dt|E#W?(K[)n\?W9X!h=K i65L[uWVPZ [mV=Uc"u Ȫv{g 8°,W^^lBgǭ%[#~:č|PK֡K/KD<5]#h`S;?^8DZpҵd!⋌١|:05 펏N'☫:3 +CYə_;"=#sX0<! pLa<-ow҇fӅ#HN20EY-YDH%:0f- 4}97"8ӉxV ( 6Fo&F]RƖDB-FFVe {R.x59X(:G@?Y*@R&<.(e˔+IoX[[0TLĊnnȱ;)LU1Rɼ|*_HχܒMRAMwidvyvrhmA@(-Zt)ƪ I *pjhT VIq_  ~3H.88-G G>ԩ'~{W<7mmT7{ffCvЕyW-eJEql$ ,qǰtč3ccco7VPoEyI/Ҷw ;R0V ]1$՘?H=|GuY{_{M۫Cfdh%<:]aɏXa.wˣIg6\jE+2$͙8GFwo{mϻrN emzbR6܏ wY ]"'b9~{ߢ[pS]PybTdtRW&vIp<‚!һ_V[:CplOIl%jFI-#pnƔ08k~G.}Ïֳ~`:񇤍[4s2V.f|BsLSy-?G!rl!ƘZl$'snџ(z=ҌwlD:+h.(H>Aw@jhaޟtt [{5[SnB j Mm,Qr㡞\ '&eĊjnٮPbz@(s拧A  ,:Gݖ aG7Bnja2Uh9EE- h {K+FDCccͮ$"orXg_oLvǰO$X ӎUai+t(=QޤVx:G:_\oiS~;W}!D W+Fy4I[Gtv FV+};t܄x]$Phk4e"l_T!c2%yS Vq &dmזgN[>:+[ hѯk5ra-q(^$?!3qKU\/ q>Ea085=T\w~z ]otS%-&H1%Zxn/0En/7P' 1 "Kaf@̏Za J:Uz, iA c>viHqL h4 93ܢ P+j!t@ č<=ފb1^!H\u6_y:Qݶ:p'Fcn|!UMZ_?9Ȟ,cq)cR.,&"H͸Dlfr,yp*=fB~B+F5KDFq3&bCCp*;È|Y(;>Vt%Mﯢ>#bK( g5Ju̥~\<tO|:)3*>lA$ZWy<bHhr^L Z^ !Y<> բYfg(sNtKPqBQ:AX 9JJ#ͮ=@y"Y1LPH`K}"2(Y̛P+31 `y^䪦C75;C_q`I銮91FW0dEy&Vȿ-8/8bm\"/)1=yYpY>Ckjh7lP<hO@:P jlc֑A]-uCRʢix Eb\ y\i y`icz.yeVEϏOxPUۨD5$.v޲E= (u;ԁ0| wi 82 nV0G5kIxgۡL3VE/H^E+ TQVsA.twJhf,S6a?vh;*W, 及7it"k`P z JvZ uRBi(PΪtkEWɠlC"f CsO(R_<.6t!s+Ǹ)abO}wҀR_{GQOV3$Ʃܧ\[&vCVaV”^2諙?lĵ:?yRn+phhYNhAjR8q5c(<@|6Dtiȭ6qIYčYg˯Mx<uJt$\`mk`bfD)y"9F |  D1Qx3kz t) aj)$yH0ㄡ)io jA/p1 ?X#ᾦ=v<+)V;x+~M7bsKaXu=g[UE;d[1ØO1$gSif!8.ۘqķ5,&9%lޏ?7v7(߶ :wjq x4C% [ƘÂEBbmk,ҽkVqI 2bBK> ,--ꕠ'b'4Lфm? hhr o-fv 7k- un˾{gʦm̕Cד dwy05 ΪR;#V;4 ʖTrO=ɣw!ϸnI"S0p1V?}vJpٚw:\GBmӡ4~x~k}j1F7E0: ;IofTD휌>zZ$upRg>o \ʙt7JX `((}"G^1{Rn!c7@n=ѿb-CI&B-+q+T2rtP9!9\"5*3n6C@nR2aR]h4K%6xjK&RV0Q{ZϟG[9nfa<Ch9,cM `}p )B ՕUGiH/ S|\va]!lݨ ӯDv;-+J96PZQX SN$X(;_izE ;| Հ[gڨagB$!cl^ƿOz',wN:yj/_gXcv*=it C!ۄ1J5GV2s0PlSӟ#FE+c6n[׮wXɞZ*Vh'>o7O$\JU6olLH&]jghBQǒ9teh%ZgR={cmS?s,_zT]Ajqm![tKԏt['Ln !ߒQDIP';23F궱-6 7gKJN1eǙc3({p-KSd8C0x4$6NRmA!^zZ5@}_Es&M"3)ZOI(*|.=(\l 5n˸T]K7ixﵳ2 j+뿒v!#YSCQ>g$>ߓ W)kC妰 )6HtG;ŪScI@E҆jЈ:8'*NRcRHY/q׿ Gq4V7em`H|z#j/˃Ԝ.TޭR.U.\ä[6sMvY~үýr\>4 I5G~a6Wc䵡VjZz~#p|负[>Ž$B*sՆ}RߍjL-ԭ&PM!]]/aRQ"1꥝O>Q[w颸 ca!\ ?o";dn߈˿W$Ehj]f<< b ʘT*zS#[j93. T/ 1 ^31Fsf_xЬ~)xOG[{ez'Ώ [b-?MhЋS \Gqb<~TG.RϏ^@i!B2d6u)FHȭҾuU3,q;KcZY~}2j/@D)8#vDYdw?bcqD_~7:$$TX>(mJm%is[:VpyЧħ/}կ̀LӐbCTO_A(K@|•5 @G-ܳIg]`_]X20URp%,gbAV?P\}c0SZܻ#L]&EofqJzA6%' Ceev L8m4d\ٺ[! uEUHX@F_ՂBޗ?T'{"n9~(̠E%vP Zee ~i*LՎR\wѣ<|G & mT,oĝRH pƭΔ/v|i ɸ LYy# _xQZH)VC.eA@(shF`Bu;`;;}6kGȹT>3 o.NtF`Ň>NW̉y3щk,e {FJ.dPg眽pgtJqS'(n>JF\%_ad2/ I6;~u3`Ab1*kg>)#?uH_aV `iPwe3}OWz@m*=[7߇-(R >]2ځ; l8x _B|ur0lu/x4 L7% IӒr[fJqnտ&b%[dŸr,? )Vt~SV% p`Gx2 vd KFpTvw > -SABws/EMTIU!aI͂۽[Z:ڔU>b hHY)㭃p8i0> p0t=\ndXX U$aT(@Rjbrsp*MvP 'A/ZCtA̳Em )CC~B7pf_3%&'=kYzMƜ9w]9['E S6O.Byg$[3,3GQ  \4bEٺYYЍ nYj*. W=-uU,GȇCk-UFmGRr'+^,q 1Gӗ-_ɐ^cKqK^ kT&>(̭t3,Smm‚wgN6;d%@aQBrYOoWQ*n6 _oy* ׏L7Q-/(+Ds56~,gCS+DN[:J )|.05=|a!v5+[<':6CAaui< );wql@`NHdd|ؐ" TTpbx_ Rlo_hwt44xͥ>6{, /?.7.J \#W2$"fL}% B`5Wr_rQr|!j & e"W@: U`lBE1 x6 6v OdLuCW0rWM:5&!O=5 Ydl-D09=qTm!ҏ 8fYn]s^=|v pX)ڮS{=ߤ)pX{k+_z}=Pöɒ&%iĂy]&\.덯t2_%V0arn R| > IRxs~ÂD#Io8(rcd[A hOY~zbT$UoHӨd/)o͘_8Oe3qFvxGZ 5쳯5 ((HX3(IhEA"x 2(~eǞ>j4ϥ*RWڌG]}]Z{0C6[Mعl5-舱LItu +J9c-w*W/%][{VK(/w'CJ0"y],>Fȳayx4e@xKxo0 M l*o 'R{;-e;]a_iȍ6o]2ӮOx9d.nW8\:lIEÓvn|Uuu"asԘC-eA4 b0`Ǭ:W&픪\G,ESۧYK`V!uTmXu>sڞ+kWDYos`ro5 ]Y4>:f!@|)++]"pѼea\c@P)lʧ]4g <:ZTL|U~eBP5gt3\(i-73vSB&P` !!; OB7-ܻp+ZLMH,.ARk(N=u;E1XxDok~SJMl D`\~3 ĩ@1, W+0mL>$Z\SN ˛߈puїؼLEt*XL8r*dg]jjҜU_U C$"6Ir re2cB=uMjh5VUuC% 'J,&¹6\'7wcKpo# K<=s֕1(`eV|'Usޛ2+{(wރ._a]XܵzD2]W`E]LZǂdG)Jk2EN_QLlɎ'2@`31'4VʨJv}+gilv<]aTf_2;Ìq۵@_$`+di2^EP/o@r%Y%Kdjq*21%sEIR*'сV+S6^Z۷ WLskEx+;D ٳ3Ϩ2R,A /R-?=e@̣Pޢs5E7%qhҿVR] ,~?exz'7 @?Jeǐ~oI3TY SRkv30_|:5pW('#nelpV{$I5ԩla%0|oa:k#BYj={jx ķb b7]וtNųRPmt,er;{!Jy\>15TO{xP›*M|*-kIxh j6:"** J}b aK_OS'C+ґעvv̼|P 0S"Ywo (s%NO= *|T;ZFw13v\2]`p:],,!I.eL32qqscH<\S^\OIo!VtN*rBaK]3#杕)q ?V;PAX:H>of2+t`<yq:-GQI7L3/tՓ~3}W.dn=Z ݻ 3,łx&πQ*#*ʶDBU>9`%#}G>d%WqxgU&@^㵑=`" 2xa &&Ji]nDKVAG#!j3n<1g_Cĝ¦T0թf<&sɟ~k|r_Jډ胤ܼ5D% mI^9qʵY[I"hiȃs!ҬH+1]C"{nSD $p@4X T[%+;` 5(:ݖ>bv[D]4A#ۍ|zyN~Y겻Ql͒W[ӓ¥q"9l ꝱ"B$')۟cRrZa^hF iґ8eQ_#=n5GS'(WpvYC㭭rcT|?"td➦ˍVMԾktKt-˒(/7.ק;s"3B{[z!Q06|&8}B|HR?OU5"STFa&v'r!mǥI91Gf-xZV#`W!ih&'7'0W{K&#KhUTtpJݲ(Ҩ["a}4"E8b$'הOU{TBSceB>Kk\NO0TԌhnIwJ5 _*}LNrR> 9\_쨍s`.P-mc^;pdJK]>#"aU$k7'@HP}dZ`CJ)4x P!޽=r3VژnFc3ڶSKn. e8G\jd4c[ jj'㌭c(`/Nɮ jֆ ᥅6j3jeٻ DX8KҗnL_ ivI'$p"\8(dlwhpJtYУҴfuN̑0tVV{~?X#2Fɒ{m)0a{v͊ZT6C 3YsU ;ZKT?)tq\LjfZ-- \UDr&]jQ h.u|,q~YPDlXc/ )7&42ij+x|f<{>*Ԃ&,,U==Z6<ē&صN?jSӳ鏵Tv$\/lPl;T{֬x)@WgJ%A(Y.*:*t-eʙiT=2JP0}?a(뚍 Q8s[N;pH s7|⪑ڧVKmN*Nx*̷ I^=s0~K\It/F0( o:pPFZ:W dLja eT!P ʟw][\!wR׾_C{ǡu<b`-gMmms/˼_]RhVoSJ[Wk]%MQD"wl0!N/Cԩ*`Ǒ)=('j,κ@MڧȔ}|ʌ͉)a}K5 AO*~/}sV7GS_8P[{1b؈h mp`O7od,ZK C̩(kD*=Bj-9ڭծ#͏r҃zHRcՆ:9(! c()Xˀ}1ALK7>%|H `D}YK&3ˡ3/݋SY 3"/R=DJÚ\2[~#(EwOd 4'AZXSbjq+t| HL6BCՆvϱ+&dgG){$W0%X+D/t>q 'pV >qBС'rf8i8 mbI=ꞰFiAB5.d]nnY~'Zr.bSy0ݙV|bq F$~ 2#AvzeGDŽH6^|^UYvPefσ=] A>"Jx9&/i(eW ]38}rvv3ʕv\x+"AiHL\C%NB+A%f"GJbyde*TGa9QQ(a?mv1*I2t6nZ~U[S{E.$1׫ed=FzVOm r(|hO [W5̮3K㉠,'@=)d>@>d |uy$],a+h;UY;JT6H.Yl듚q ˑ2lOǕz0 "pqxn ڵа/[Xn։drˤρ&W6$@;}yLmLE`#15cMG{{;xCsM?A]Uf}h,2ݛv}a 1*&l9/bmw'@U|ءܴg.Wk ktnFQ* wClI k,TWfiF>?-+Too1 l_0ԏn׺cdRD!xe[]kTs΄7)΃j ,-/ljk^qZ^k+y{ov!RBp ^lzFuY=i$EtӓKTZ z$F5Nm| 0x6宵 _I#Ǯ ?,7ȨZ^β䌐(M3aXZH8 Ssg 7+-d#Xn<M7-+tH3,bfx|ՒDx"/ To:BZs@q Z}$,\{ 6Pr(r 0C2w+My0@us伕`j$}zǃ&Ǡ1?ㅃp "Җ0wh* |~̢Ql2p0,ǔR7C` 9+>֏@[Ѹ27Q`?,#W^O8 u<4a+.Cw-u> r> C[pr\ +^ jmE T=W}WqJ/ݿ޷Tb}Z!tM.L\*FUPΝnv F)tET{p>γ4~~b#|J!o a,x.4Ԝ{2=z$g $UxBn Ulk{ wMW$_L&)oKDFӨJ\pUl]5J, d}F {Re3n:zFW1xgD5~.-:u&1スWFb:|)ç~m$< !Gp74oȨ Y bvoݽյ׾"v"{=O 07qs66WH{V^Soe7Zd;gZtLϏ6<?Y/55& "6ufQWJG,4 B䎙buʥ@& !ol:pdٞܔCo<%SN,ӥ4?i*vE4W2lJP3OttDg`g.Wb$# lӃ &F0@2(I贠2e<5[z;E`:b峒* z(tn +ƨE^FBr*07~Vٺ;R%3[ )1QqVn HM 9~?Y>r`Ho_P4˞uI)BK@f>(v~0PgWq\*_+F?iv !S>ij Wވl ӝ6iYPwrE|l YJ=ӖU6Qꢵ/T(~.v!IU)hYU+<`B oF 4VF|dr}8ғX4YdBBiVsLGSo$xżőqpz+kɡA@B(rԖ[0_>ڼnXI㫃5.wWFF[}(GB\`d r̄⣎h5Ǽaߑ Fgd4/fڌ 4[C`nPԞn̉:$1/d&2x!9bn@\( 7En[DﱸQ% B1\飨_hc@TԻkZ{$*8ۻcKjҰOeTFo&oϴ.[( ~ug3tUBs4U JSɨw7&xřye^ACz+ i:[DLj~ʲǧ )oɱj"cm Qrѫr[6!B(PI XUcgDϩghI&{w'b X;ɐ :@^]90.۞%cȲq,<ӘQb;H,f.B{]]&@ pa:ĢwZ+SX[2-!򤫊YK7+|l* |r1qmv;0cf" dms:@Q= ҮDw ; XیR%E if&R3 Rz~!~Vi{h#9eltA]/̤|K=GQ=(Z2N jr*UG *Qĝ@';!gU, SR43Ź mwT c[[H؎nEy<v35ԣ{,1/15"0;0(_:/*?Jaw*:tFaY ~_ؑO\I4~n-QW$*bϙҐ-\Yu)=}kyo2I@=cDţ^῟Pzh;g!A~} ?6?;'G{ՕCֱCC@&pEX9=\(=S{W0(rs8]S_l?n7/]HYWI1c鑕ldszh;>*WƷOЋ']d ɽИ|:sSQίL*O1/<>2vzP ;|:6WZ?="M:zֳ#JB5)m\cؓ H* ;$hj* -wB$_^a|&rk~>ZA%_XS|#0%mI:(x5v8~I,(@*6EOI8) $ֳN4ly|{i_]VA{jcpzU2r|&^v=-ԈGDƛ8ɏo1a]tz֜2kG^x=mX0VN5~NcnImzn_e&iutAb_{%h]R#eL8Y`#[JssR S6l<8Hj*dY6c4?5m0k^?'pH !2^O8=fZV@V/~Mr]fWx-=q/$trOB7 p2|aSDI0mߊM@ښܗ0CN-@37uΠh9" !cZ?G&|-xt{p+jvDa)'$XA ŷoT[HfbFD`觲v"O#K4ݙ$~mTwOpdpafN3Y)wBz~G7Ji{ 9j2"]m1[fTj FQRst@;# ċ jҦD5v 44tSNp>MO  IicrTKEOl6yBz4+H )K%L-XD3Qkw/V]ZȒq2j1m?6{W 2i{FpH&e\֚mboPmJb)o ,~-$A.(IrƕQyD>4zt$ВQA e(h+X 9閙*bb-RZlSw~³-L%#do١ k7qM*a/D~U}P FJ˄ktv./CM[`pxu6E($rl_}:)5x_6</Z(-^VτMEGC ;kMCz{>FA|{ {fdBڤ drE_,sQm*TоQ0Ψ r٦yEk*^q5IЕIxan[(Iefh4Q>~+#ep ~P;^7T݉bA3ًH)qz5/`ؗKBӂڑ5PlǾ0w TIfC7/"чYP=ͽ'o7kr+VLP|4N|TLwaٺO;>2^Sqr;T۽a!pϧ/ܧMIWaIDN"^u{)_0K/խ6M|-HnmA*xzBG趉#x+ גzfN>۔f+}4-cZL:SSwQc?e BxCg7`Bu{s jmvO7'<.;`{QI+p9~jì yW^QWJZ,g) dчt1u3yWbP/ѰHM;蘨Z pԷT% lmr0̝]񯨥#@H\#SndhL׋P)$u|4L1mX9քDSJٽCG{oYZ4bh.[[[Do`ZB;OP392I ύnOec?bPgml$0Ӣ6[b`fSb[|2F8ƆiBW> OVci!a 8Ɏg" C1wKxeQGIWCՄ:D tŌ&OM7kxkϔfw8t~$b'h7%XAJ /ߟ5M=bn^] iDO@*xx X-20G \^J#GqE8t|̡ء.m I>mr@t^3^&yѷxd;@#7 Y1Bj(!#B` ?iǻx9W/awluw%r 8tEvAGhWe SK'"ٺ-Pٍ PTzVv"9ǬH4j}36LG3R&fܑ7 2$!`Z=OqWw8UI]TCߙEJhLfL('̴Q_G]E7|-=zKyr]yX^ f9߄*y0 8j'ђeb+"$]! yѪsb+P=&F?>uvr :AD+F7zVjHwɄ,%%2&֞j+.͡iF*KYP.Mr}<푋l:؜ 9lHʝLnhZ0.bw><)G{s!VE xHSW\.$&SsA êjc־iwi V'1'}I8qeʗpYPA,xSar-bLW]514G_ )/j61:<(mXdz3`sk!O#Bo7OӨd^y709X^Ga'yhQbO-̅{N\2;$mX,Lр1UXU&3Rc 4*)<&|5.NWJ3bx*9Xɋz`,y,*sY愀5'93Tz]yS͞s* x|hgH}_7& K {jS.cՉ|@"T'wU~6VgQxZ2ꌩ|gEuʎ_ͪ=q @?a ê\ ɸl_' ctڸ?9U䄼LFH"֖':>$̥0ev|1#76MYTrсRo*" M;s D܌/hf#GL5ܓ^i yY\e<|H4Za;9WΛ3z/NY%/}6lgHrY=1L+;tMÎt 0)a̡S]]Vu2jτȋ}}Y_3*N5r8]\)Xd !0֊d0;ú䐲̬J{Y>_/K;WϰfJ&"_OY784 #VstǤ e*07?4c,ٴNCvq֖Ay;YemJ꫽8#[# `w\ $z' E0?e%Җ'럒R[:| D2y3r misvQ'aRt(BGm(bqTEC3{?7\8d-1"GFC.쌊Hps娱_QΈ FKtGV)ӉNi(hj F- r^X}O%v.48 o%QPܧC>-5|~UJ h$KpJZPmKV,ѥJpw3U3BkXjNѠps(_~- uDLܳ80gKW~MC 1:=`fMonCYKn|THQ7~E<,J#b~^65h;7A^$yLr7o/7*B sc]>3..3/D> l3c,Hы^ #yNZ9bj>ձoC`m4m?;uń<(j$VEO'8 Wl8_5Upj.C6vjw4<0]\*ljKE00V?/Uo +yGž4WS>++vUFvX(fKv4E3C FLcge-UAivje ed.܈_|ku:wݟgW`lީi bM :/rMhɠ%6'NyBQR r3)jހ % V|+C_UBp}p~V(yUWȆȑ㯧4*hUa,m|%oQ]iHj8ndOz]ZZ9W^m|s?=E !/c~/q!VJNH߾'aclW'oYn[-&ěYRG}xb:XҒc. h;)ŝkbdHOXJNYs ],2#EwΑ.e[ |'fsd(.643' ƨqABr F<<88!w":/yoK{> b{<* nB\ՊI2bbeIJcçشLgg_E+BUt ];MPmK=VPR8!ߟp]5i0)Ps8I5:U&M̦6F"bQL\YNT9g2Ago'1 qֵ,j4:V:h7junE%-276B4N/~1?|:zW>V0 "mi#j [fgl6.ĩg[>TWٓk6ͻabŒ>8χ:ˆ6TUx QWNT͡2!=f':>]Wzo>O*Y=;\(>.L7yټ eAZiie$l)U3oi2rz)^xɽ+(;eshJ@DW/yh VƻnEBQ< eOg-C) O-`ɠcUE훡륝뚥ldcM-V$Ҳφ]  fJA~$BL]ٮGC54}솴۝dO\Iw~[f =?K=f[p`] Mek_pۣz=Eq썖cG]`dSLzp5ZY3L#]q1@.8]yT7gא}Q],[Lb%W* ȢI;EHٞ_D) eNJp ;DfR#(.:N}H 98ݬA/\#F{ʫAx(/d4Y *ZۗcYcS~Kx{Pd cKf'nUC/sX|/)Ҽ$4q kE|/ ْ€,ҫcȇ\؋ˀc6iQrx)%2^{NuD5dy \>,6%`Fa w黮Ee3"e7hTEς)E uG:נ DCl&?PX'-f,rošʟr6³); b)~qל =PsCʼL,yuuJzo(٘aس%.S+8pdz ݅*U)N]\Ch6kʸ'6|O3-1v3?,gW JYޚ8g`/^2Iy@3+B;Bz#b7ݳ [#?)[Odz j1 }ǂa'k}⦼dM fG!nZzȒ P4s F-+J'$'?O[~F5:Qlo.dG@IR.*ˮo]Lpo_Q1w\ly,>bt"򉏲;nʵ9Jkt!. ?2ǞG1Y ]˽(*| _w_5(Kx9zpzm7^"dFÞ5Ğ5F>\ "%#NmV|3Ҙ+wxUYH! DAs^tE5IKzBZ&>mvp q.TY!dܛ/ma10QϿwL{ mu֗J/̻rak(]] ]V=<46OSS̢ܥqM:1c)=eb?Hܖ*'LBS!PbktÇvz 'rGOBKƕ8ZiWr'~v+w$Li@ʗ3U]YJ1>l V+񌺥6'n]#Bn@_ߐխJ5FkgSzp^ppĽ,T[8 ηnaiU[vIRIb)]v[a0x7d?m0~dӾMI)mEN-}GlWJK_Ăz-)`,M=:uY Nt1zKpWz΋|ep}U%/p8ˁ]rj cTFX®C,WC % 5sQ=Y#u>M%dp\ vǿ>4 qqQQXEu2^r-"pm UyXz+Ya!'ڤ@Q:w-{X?' @ =`rm,DޮH^#ɝUrEYVoTD'"4Wzh&sdaV(dTz瞉VgǞQ[*b'uYוN/u'J x{=Tx#)3j)>$SNnm06@ƪԉ` *.zyz^GO&_UZ(T:XbMk3":Nn{^ͰuƖ"%$ BRe<x1(W[V˅poz961@M<ٜ4 I'țP?EN)D1FOR!Ο4+yi1LpU>.Ksqӕ5ޔsŸDŽQqJܴlNR{%}DV\wG_M Ztt_Ҭ˻XPe"R>6APes`VCԴy Gtl/Hr49kiǿ:TPX5WQWSJ}ڼn%t׊OgJyƊ|1*oMlv)=+5;:|l9͓pdL4Qn,C̼jF*NZdeB潃`{icvbiKj\UӜo~(\iwNSΰl4\®w||:u[jW#0-GN3!4Sg~MH`\0n/NUw0Rv%$o_FWke+'<{1o)tmA)zQ5$bZ8ɴ$:0n&!h5T A@,+-z@,IPW޼oh,~-Aq/h>{@[XM]Q,eJn38t]0a7~MnZw<nZ5G2m\T7Gj9NsGsM+0M?3:^F(¬\eBst* "EH:KI[o'y{ J#\Q @ OvSq4P`P,qA$}};0.5%uL|66a/.FB wOݖ:cR{X!7Hh$%W7j?]F[8͓s79Xsى b:?@[<HI&w]I?S%?[D#hPrْR4'eA(IYji:1z.+n@7]cFP+L%ś?)/ٰ5@G/qM.Ԕ+T xZaX`̍] A]j~f&vhװXs PvJYF수}k2 Zk&R?{5~2sb\(k I]<tv Kwɠ.D8#L6f?b5,C__gf{kǃ$skܛrv67JQVgzǽ /ȓŎ_x-_3J:X]öe#Y1 3޵ȧ-u߱\F:>;]gJ_'е<1$|a+_,LkJHzU9%lzĎ銘?6:lr^Z~rDvctOj` x|MZ2 #fD/8!(R〥 a~?fa­wHKYbYOM=Q%D+d%#86j@KöQ!|qHq1o )7 /C_0hZ<ȧ ^>)N KՒ60PmNdgOlg])IMLWK\I3Géra˾ Xic)pK&\5&p7qi ^i'D{9,Jg }j12Tͱ '1EI"iqcn9%7@;UۯS%Z8`=y b˞/(PbUg髱c; #}[x̠X_Oj 4m)I}]f? fU p90^͐pd"d \:X Os^ԡzMN'Y|'5S&-wق#D%(n:z}c;{\oU`qkPX"S g5ЀqԸuV1B7V.ƥw[qd̞G :%ٕsAVrH6wYO!P1jPGh/7 l!TL+a",M">CO8Q֖i` QC9|>>u*<sLӺU>0hId벻vd>d\8{ޅ6nK26̽p/E~JP X=atZe7g"[& .]C1wO,ڸ]x*QCajm"J047..{92xs<%*.HU#ΊYMfjݕW/V+CBbBTi/$MQDcϕ&eebʻ]p3Gn>gZyd(LToŏ@{MQs* E7L-ȑlp{6K=d6[G<;oԺxF"PVmMqg\Ɣ(g@܏ERJ cg ~Cw5lk1/ï>ۖ=]/Kj6^j Deq`=pNk \Jw$2r@?;HBLQp'Yycmz׼?kpd)+P_taI|gc“VeUg+[gfok\zLFHzuCTlŸpnp)65nn 4#SP"HUe.Ld& BOj/bYHvo;@Lʿ x7dzȍrK[/=*a@lÐ!X8!Ei ic|S8shmOHetTwۻnq`-f~Ca@[ȏ.;ZӪa =*?`rVN k2[b "_%uܨgr-۪q; f*\ڽϴ4B&.[^=¹K9rK?vt5UKd=[uW}X>QxL[5?6E ،B_ B@DDz)?0Z4ĆEz)6IFoP$ E^X_ĩC5sGs0ӄ  d6`W^+u$}pɥ ,Qb Z~KKsDz Q/:`"Gʊ׶3jf Ё[[m~%oY_+_!)A]y&}o?o5['s2=ڳ6Xxh";|$wNٯ<ۘ6;'Arg9Z>ŭD45qd$ &U0'a֒wZBN~b{Jy)s:#x (_V+VQJ)>v%u v,f ~^$ך.O2<`"+wO|[iCޒT1Sfn'}*H@ӱP8p`MƏ9(ōeYw~{v8Kլ!V E"fܝĹl~%J,Yx\ǝTn$5Fxz:Xz̜`RP8]?Pѕfg!ȝY6+s}'F'U+bAC`svmE84e?aq"EBK㸨 V.KAvE{l%qFYUp#.!yDA`9*f7t09iAtc W5.7w{Ik8h]Ʊ6~6{z,psJmVQk^:ԯ&06 #~DcyίO|sv7*9O fj̃Qcܨliw% NGu(wH^`!^؞Kou&pnc|^]j>CG(b$PM8Zs<>፪(G7竧tz.^嚀_oH֬Wg9g '\Ύ뉟RC3U#d`+?nj0ֿ 4A!\n̸QS6e:lf;L ~kaFj.2DkX%N fȝ^Mx#0pӹV={ =w=2SBbjRk2Txqۇ=R%r,8"#$@;;nȨŘi󶾇\u}c%hpR"錨K;%-NY 1;e}[cyk+ 4C4d+ \W032@%?:GKyu>ށ͟Niz3ȫ-|lZNoTu~'G?R_[ewF[bKߕlZ]%X <6h·ԭ&,,*塡ӗD_8! p[Ϲ}`eLT';ضw7~}݄Z6Ǚ>Ο+tgZ$+ d Hk?9~L2Փ9Ȉ=R(pCay80^o1R=R9 !oq#߳ `Z:{ձKaAv42?iqm9ijVeZ a ƿiUr$$zÚgĤPS_ڧs ELQb:biTG]^bYhV*H)rDʿ y:lxxEN`RS09͏g/]*v, K9Cs6G0ĺŻS3FX^6OmCʮ(Ro'ͦ>)=#A,'?:u{294 ;.တ ,Aw(1B[J6?4pTtk16.,PuL8֯R: `b4 vΫABMQbtEq};2Bl%>xI?9X>8Nupfx_B8JY032,;0;jAC-,~0nj#h&柛w,%U|˼r#[:<0:Lc ehڴ-'39#$G <~vY4pZv0[Ztoܳ_Brw5I*q}]HD^~&KL^;j1)\ l,SYe.G06l V[#ケoŔC0t-Kq|:쨶Yz-ʛ-fBph !9/8>CrE p~ڧ-PLW_ 7 `ay}<tStBhj%B iL>Fm&E:M$^VF+9Ug.:(U"tF=~a 0.HCkdB>G=+UWgSs}"Nx5WN]ށ?~\ SF'b]SYVߴB&$+I>CϗT䔝\w*1@I. Xmq^, "(bV䇋/jܞ6H3!j(NUadOj1XK@!5g]Uy| Pzb. ֮wMi4%]}Y+Հ\~5ewccbFV{WG PA1~~ӥ(h:6|7zBI/tU'sЛuD!uY]EAlj0nhLfIJ-%d2>]^mC|=1\8&B5S(2cn3xY|D7oNI7FzV,ߜ-RL"5I,(|gĦf%gcEE%U';\#g fVC0{hP[?g!S I;aԙѠUP}`&)p&v! ."26Zl@ h@*)iF=(À^oeD /΃^LhQ ";#pbL5gIǯo5&35x(jl=}BM`nF~kt[]i2]&{ZDr Ȁ^k魯 3!A8Bkß~1uP)k H(:m˜r!+pWա "y'Hp7)TvrW3PE;}r9wLc9a5$y7@#l:ǔnC92>mUL3:'RN~dE+?##T3]35e$ir5# 6G_rΞ[-.TPÖ NE*ǂn#o #PdX9Brm술dOv,f[,e,Q ҉U?®ByPL[NKˮCrO.yi%?M/7JT*dh̢T͵![pokx L[fa-AWσ-r-)<[4{+] S%S[v' F4D=<3d{A%ۊ~i̝Yc\5- 3&DUjGν(5MR4.՘чdbaǡ~]m6n448:0iadHLߍ=W9WpﺗMϋ0sU}.KnGv7;id3(I%0o0<;g!nRJ{XMkBij<6^[Ԣ7y嫮fZX_D&K8ο$܉8E#9*ގ|X񱜕 Jg?Wbb'#qh$̜ALH0z}hqWwp@(AVe~DkIQCC/k/LV͔*Brӟ6ua> WuɐشgJG\hm Chd$>B茷؆wPCà`~XӪΕ ]`{Au);KpEp=-As^qQۦy]oͦXm thReC]X =oLכ[u/eWÁu?#Rgբy~()IP[pf5Xjs rIΑ,::"_ /袧9VOڎoY2vV`v# u&-^[YR {ԗ2lt(+ ͑:P<*zBmIO +'ɕx,B ^K%uukIsf.f/# tx t"4ʿt6y?kv flgEdVnY9%NnV Q-K]\;l9->ᚺ75{ǨWTăFeQ#V6yiySwvŁU`) B2D_纤ɓu)QHg4uL&݈ n>fVYNwH;R9<޿8&1;XH$j1 gES)p]Q 5ϱC9(ٖWVIBĔD4MYFUO~LxK7gaO1mEyV@Pڡ:UwX Y3ҝmmCϢչ U:I]N"/1ÚO?M(Fo;wd zh+oM.!sIO:/ώb4E=3EOyeJs(`qswfE„!Ma]S 0i  -JVP3& /Q>$8q ĊQUȩQPѡ#+򝵼tr#J< !g.퐆~,HiA>t`k[YupZ@YX3g\Vk۔~Q?E{ajuUovi}{uSXD₅ >?mD3=؅]2 Ω_Bq.配 ɜ!`CtȎD[%kF"p8Tcc +*[{!%uRDZZMsh1CE7(.c{bA0v&H~K} 1_}Ei.FMes|%-5'.i 5R]Aʃ|oH!{ؤ7L ϟl umЏa!)1 R$R+?j4Z5QDH,33;O3w*;΍ͪǟ>~b &c "Uк5;`ta0+5v0JYW5ub{.ԯipɏUT^ ?5DoNc}vT[CLjSZI i$aEs{l~#GIJp6Gr1]H ּ0P_;UtDc/b ضJji2TN_aLfj$gSq[{UX&\ o;g.S ⶦP¦ѰDEEzwK; ]<֨7|K^"˥wèfW|?k},M`zp!ga_k\>P*Cs>Dt? /-y?5,'H"133#o"*J*ɸ2rAb;Y=% Vb$^Zm9}0y23ſ /q>gJ֔5D?=~2EMb30LO~M:bà1Jɺ]#Ktr訜M  BL;Tr/5_(/?R=$fضPY@BE?| 8yH&),ur[;*#[|QW_3Oa("ddӺ5{:w1ޤ['F`b } PmUuıc">eD3Pwe Ux[jwCr|4`]N4n ъi PDɘ_/|˖lJcww j{$,Ad,mp((G(h> NwgW] oC{nXoph`?&g+qܘ s sD `k] r[Dr2$)C:q@yN6L. f `|WouRt7ԓb>]ǪdEᲴZfR=P)T+8:Bg"0BS0`%@&OLZ&'0h-/|G9bd!I8g׵ZK RTϏ+)Nl%"C'!nIdG"=R/ !Ì\NweY{KSG,<-iVxG?QG=A%?t UJXI2PQXе"*d_%c*K\YQ<.+հQV8`p |Hgq`GLyG8Hk,Ob.C׬,5RͯQNvHEX=-\*Pd?n gȀl(][5 *]+VoZ^7ߦV34pVdAw"R Q*g5 ŎSL_͝η"(!u†'E_S6O@asF%vؘR;4ZcXh<` &UmGJ}-C[fi-M r&Zf~-C|JPC֛~DH.L]wkwHV+*xGH M|kL,D}w&,aצeb-4Zl.kL_ACG@rY^=H82 TZ`ל_GX`vqq)@ش޲JhVR^OӨ;q@r,LSj> o'fԕi:~[4D?*]ox>m)˱/lSI(ÅBIp—e\i!"E#1zK;? 'KuI&0FU>Œ |a=7=E&#^k̔3[@uD4b??z$ ,vnZΆ!l捭P#ݏt nPb~>E;V>ԝa eTQpFߋ>\u' }kBkR6nEߐ%3d(yA}ʛ|婲^9Y8%˙,tlVS~l$L6~HWrsIc sQVMKȝus3<{{*Gv.^kC|/R> @@:hId " ۞KlZF(>#$Zi0ؤD- a7ɥ[H<}ߊN[A1%0NNRWu;`)z7;5GRMg*׿E懁bbD<K!Lz|:*vKSF(>$b[QK? nܕ䝮1x(zVn$O9G1(d8+˥(S'RCan凣ꉀmBɺ *VK@ N@r臖G 5zG0! H)r">1hO9]wΊQ )FcSRzg Wk"0& G\]ZfD ]tX'Vb}h2>>3?!۝B|:*TpR^zFںN(H}9},Y HgݨJťk2!?NFqB "k"W]cZ6B#X 8#2_ioGm21#/CȤ>u|r)#G^lMvAr=EiTȱB(ETŐ&O}"p631ФN}^ _HW+e "6^EboTdQ'ُ M̩]r}¤r/AM3~nq7r t=t[":=OΛZO_9S/ T5>1fqz]M$Z`FmӜ|W 3,.Nm^x.ΛP-z6 \2@/>R_S#ۄ<&3&_(L$/a5 J`ݝi-CFO/cVGd dg;zU#|}i]~AF ]QrLF8\3$zJa$4; :PoBwG?Yh.]TQ$܋:U^[VyB&/DTLC0 ?} T8mZEJF w3{^ :0RzG2A޳r } B%`Jm\m՜IãB_4+ETȤjn qaqg ESFq1,] PM.K6PV cP0< Jތs0JG85jʣɲN0͒VFogs?G #@vőN_\k`1zMǮe $h{rڂ 9hg!4ᎃ=CH d"[ IwWl/bu͞@<E4o!WExg3MBUd {<>F`.3Uc 3{S2ȥ=v2 ?(nKQ 3/{3n7Ees!=tū6)K~59w7'弫ae`U+wެ?H-u'%Ɂo)0Qk hTTN5Cl!e!SНIhEGK ># |GnF׷Z8d|t=BmRɴ tȥk߳ J{z$]^7Ŗ_FE<+%fUH\ytrvH\;v;BoD9 Q8X') 퐜8ۺo)K!,ǁCfH*rRK&+fDp>t6Xf?O+UҤ&!'ppe~XIa@Wջ͏kƍ})KqZT{KAd쟴.n[6cM7\NvXںo&NGh~R!"ڮiSX&'PgyIC)yχ|˴ rtKͳ5wTxCKA_bP,1U 6B~U |M(%R}*Q;5ꟁFWHyc%Y"ZaHq '0 :UH(MW#9w)B,1d5Wws\iA텍Ku~͸Z' !hq=F3ydHB z*KG>.&}yT#=@ng]w4642f\u3::)eP FHg@no( G? ^xh}ccql; tql%.v9ѐm_c: c5Ia wɣ9d?ΞyP?7YatAZN/c6cȆNh&@!ms(k !/]=*ٔnpp 1mrvb*d?$##-uϩqlZwb/MVgPB0f67J$ڹa;I ECq o`H{_K/SK-]3?.(G{0EeL!f5eԎ}D?xWV>Gw*7q$NlYB+%>2v`?$nfϑ0 8B$[3t?K@7&(]qޯiz `LFH&b;rW̥{0Vl00jG?a0ا6dL浄!/ AxDt~h5:3ONqu:y'ƥajbl.cto(8i>0n5,GCM^cH( pbAGofjK35d+J }&TsBdQĵ5s!ϸTw> h|r:k=bdI)l?FA;K)A [r;K2p:a'zߢv90ӆ6]64(x9㳃ե߭~6Wy9רּ  C%U ayG93CٹYi'u(Oۅ(L#& /x:Ok#[TuŅ[l^d\HNH˵!0n?6ꦈcKp0h$V@b\AIx|b7˛i)K1}͞^ZYu~Hh.<Սk!+n2A0]"( XW%{Z=>i^ӏzA/*Ҧ^+x R8mivL0J6v7 Os}GDU4|dD"fcI1{S.hONS_^.j{3P$j^?{sE ؠ݁ 3Gve8W`XrG'&rfup6%Q)7\=Gc,AFd@Ҵ=/0oZNȓYT-!/P+ hP(4ć6(ԻA{x/6: 0}mLfJw#X`s@Y&QT NkW+I9 ON IsJ}4w ζܟf $sQg>ft%LA}C}앲Q?itgDI;kYEeYpĦƆs{Zqc~t8@S{-@ں3oW8ِA}uU*{^nN[?Gy*thRxYvco Í,oHzh^;5# }ΙL|T]XX%.Tt.<)%/N7oiJ,7^B[]N3y<'?q$bQ-?F>,ҞLEB#n2# '%"o]j!9@*QciSk$0؇}*]z/wNoQ j!PVl9izSsS)9P5Q?:&P#`W?GuKL!wy*Ee*;$'2بMjb5A@+ 7$ xmeQr`rƒ,<)HP8qUgA@D=b߉A˽G֓-?$g4 ~,x!09=<9It 9yU:N4uhUҔn$J )YA?x:-q6u]HFh5 쐧YxB "l9ԀeeH+\Sa*{=QHN\ܪBmMCZD`ÜgULΘe4/  [6o(I<&P ;TmWԴʠl!{p ynŠZo݀@$®OEzf2WK1_hl*b:b=s7-7mL]lWFNv"]0~krpzq+*RԲ#@:vm-":[H5;,JBቋΤmyHCD6:{9p\JX׍_͍1mR\7jLs5wUGDƂjm:GypҚMˬ+JKݭr<0*Q : CzAH3btQXf H P{lଥVT3S$=1=fY}K!U7qB V ˇ23q!*(W}ܲFD:N's<-V.97 UֲU@HD1J/eII.@mbprVvx}4 y w]Yf#W ,s&ǯ!{;JKc =Rӂmz# s-aZ8  > BL˖z}bD\/ԵiomwSqa޸!92'V^r^bHT 4'+e\JVjnnRVL>,tə:j:&ѿ/j%ԋ%[k\_hڏ M> HeQ[rt&fq(/g>uu6Vjl,9eݭwĊQrLЀ.k^H4s^p+ZTKƉL9I$}{ hޔHȸWWΒST,od5O8uFG;O? \j "KJӁbè?wW\uh+ӘU$vH-5~oS,ز};2ږI7=l!;j[ V3Tܢ¦CehjIVIDB =4-ޡ,l '-OK.O<vV K$4.$َvF*}e+ cfX&>߁v8feR>|) ]TEycLHX,PA3XZRz E幏69f827&,7 lM3$*؏nk9$?p0f/ECQ)/1 ܮe;zųz %cqqJ ]VydJ*gSKSkS̭U)kΫ=j]'BhaQ21iL@S0uCfV֏DQ9i  ;{6u;f<;xAMvmӫBcN׬T^]94&g{-viFID5[%Q ^εh@`ɠƬ\H$ *!ıf8ws: <K"- !ZN$*V'ӃIA[$v (|%*Eݎ*[ƪ\&%IadWځv2{y@s<߹(+nE#;heh]b|U('v2C6nxPIm]l5kx{ph83}yҧ!0t]pq؅B[l_wE@+ð^ MnBk Q.޾1~Q˹WA-7o[n.n|.BwZ>;L<,tߢ^HNk0 ڲTHUBE&_|4P+,V=f4zknG%[=Isҋm#5h8,cv_X=7&kcވ6eJЀ#@mVq:~O}fcKf+R0S;۝$&}xί:<^EcwsNĨT:xBe;EȜ(n+]͑^4+@^S|N% LQu7͆E( SClUgsD4?פ0mZ .2+_M#g2>"bN!f%:͌T䱱ɞ}NH4q>8|ҫ jV#?qWE^i\n e烙DQ%'ML1QԿ7SD%&y6r)=0rMJ\Pk[-<5#\Ws&L3 E u_Ct˓. V-a'=zWr_!ƼZ|uBPQz1Ш?@oE:<⽑3a;}h ja}kS)& k;5&6o8-D)\bli,SjA7Ai/G>\%Qq+y.diXjz@?Gqu{DHT-`|qqk}= Y9 nopq y7,M՟Oqwz,nz}s-__r5~Sԩ$ZQJw>ŪeӖ?.[p:REnim"vc~JG8zu w+Xl-Ea /Su>rybTm ZyY}xu:3?ť9-)~fei-I+:q M?=-/R pkex$wu{GU>3x[y ).`iYpm)\!p=,^{M%A6PRZYxčIy\Iu(eۅBJrs@\ETqw-)Jkp&dri#d|M)ă lT =r:={OBM/,ɓΰ!hsxn"1pFre8M$ʾ{H/k) . 6ԵOm!{wBxJ( eKY8+Gj Oe>)ǭ|7hE Q<ǼK!KK}znMPi'&P3ZT f; peNwet&PqjȤs#-hd.z1'_3xO)}}M|tXQCҠb70$)+ 3`+RTPT|22KYOihYeR+H;imC#5Z2- Ch6x oto$`\&XF/Bd& <%ũ$ NW‡V>YFŁ㊅"23'LSs{z&/G"T 6饍Sx`=\xנa r[[R"*a}2gL.k`M|Yzc7{_Gx Ī!>FK:PDEw»wNZk }xkC1K7r2ml/<$~Eɧ]J1=X (}6P[UI="%qga,4"(3XcmJUݪɥ?!n@{,!WSel +)&f(yث#ڇO %ZTJ* sT0㧾 ԴoDu G?Aܔ݆5B@L:BOU[y'5oyo(g۵+ڿ[K ^cKm)(+0 JXwFL⭜_4bQD~; b/2'訯 Qcp(GrD}*9`z[JK0@Ęx408rfd #RuX LNA łlWZQ6Vt`旈+uwQnO0_jVPXu#H;.<ݨ}b$xrgSUw5{s^/2PIb(ao/n#̻qD;a˄Zi=?V1 vG'O;Q ). phi]сR_%sS|Jiab௮!kG;dh ^A":.A㼅b:}Y;חΘۥbʹمg6\Wg|PN}\L$Sguɘ}冟jEjx0##%`k &h?uU"GU$q3'e)j4jR* wT˱l}y<#7*!{N\eHڳ0Dtn.s{߳Lbϐ(SN,qZJ#e.>Qf2iۦ 4oS={;)n>Qاp["C}₴xs:?iwئޡ%NoQ#u2&ea(>TmFo?ݲ j\\/|^a^Y< ITJ1J%eJrA00zy(w8WE9gIH U& lG{0|eV6g8H<4~@5Z2Sދ}xq NNTr|1#k:nAI:[\ 'ݿAk~u}2~d)X~A)u M@PΥ~VGYS+΍ %KG*lb _7_;CcY@B.zrGNx1\ܜ{odk6uŰ7CY0L6)\6%@(-db[7bRՄE`sZjПwA[D2Yta5}P#^yS:47"RSq?{b1;@X>y. {TjUSE8(>)z.0k! uhVzMvO>ϴU 1' :3D&{=X6 ZC71Sfo?Yb*gV?HDsjͯE,,jbĭ.4Fq#֨,!+,I}E3ڢ4#RAqzwb^R9ih*PU`K? *"=FHߨ?G/x3;t}=LudnW4ċ{QkN1d3E۴Ir+n*8\ԏewss 5/2}v-^Qf~2a//fCZdLq< 9#L%D8cJsU0_Gua4TN ۚZ 幀mƾ`9=bL'wy}7;PcZ 6.'N*p\)b*jliѼTΊm략T>ہaݵ$t2=[`\"Oi`B!2_6,,AY+jkE7xrO|?v8" H'@f L YjOȯY dO^3eB.k}paB4ȤseqĹ5q!|`krqœs%&[>/|䘵&Iӳ)|>D# 6 ƲHkVV` NB5P $fbƌ5%JoUAAy{hJ!нf,~]?&pR8pDf;׸~qAi3kD%BPdg-.?"paGL1pս$]4KͶ);9Z ͣ UtmM)MҾ&>MeB&Eu2qQ*L!dE:G=0T_ˠ =M?Pt^E+ l`Z]@+㧢,ϚظrSW$(f G߉ FMu(zL:TߨI.vܢ^yا~|\*_t |1\KϪz|KeV5L,+ōD|oV?*3vp>{9U o2z X)p{Qt*@s*֐l NΏb:Vٷ+6'%B!2 J'M M_KND {|9 0Yt_C䦝^"e["%-`.[=0Nh4JPybDŽvYpU~  JªWyFԸu߂^{S=FǧGD <㪍iQ qP9.}^Ht/&$˅H9'xG%?_#κSn֨&\9'[SIOQLMtyޔjr1V#$coݗ  g?yH 2R~&!^uż+cRQ (s>emׄˤzVd2kQRM hh/?cx[Sqwua3_  ni{̂ǿU |>d6G,KwyBb?gCEzH1A Uߙ:>(Ze)J-vu?5&N9D"QWP4){rBblO&|d.&k!M0dG[E^EO~Y%'kg6uދ 6 G]h).CRnHC)>Ci;/ !v$A-]!&D΍M϶.**i%ʖ}脐47Z3Geb"]i.+Ù]j WBπNp&8ﲬ'#[+ We V&^A;XPnMĂƭ_gT7K5ʒg1vvӍyÕ,V (a agiaiŒ5sq?pYu4eٝ(j12' +Y[hVJڐ_pm OLuRٳ v]JJ簟e.f?a%V]be4_sI7bS8;L^$?,v\į; 2;",P`ǗP>IϷ9QUI4e4&LJLqM<@$׆NVTt d(&d'W~<0oPSO 蒼[@CQdEESҷ<ɜSFR>ZS30w\9aa䵑߸$\)rכMX\qV+yڏ|iAJ8x@vvCJ:+gJކ)hxOH{7?>-x5#q88M:Puр2M)ICP<,8- Ԅ3e>Rw 'ɗSi NEY.a3de#-<_#ς!VT+hQ)tau9f\bⅶ#!\"^%й$\86m_ +}$Ivma_ɱG8tDc?T`#%_FӈMr&""Y8C5P]Ǽs6&*b56p;M?G$R7͍d*<-[R[?a(sf0{|_@F+\$: @ΔҸCʇjH]!Po /!WHu:95A{ާո8Í *[ggZ^|eLS!n^D 6jwzAu|$F؛ި!!@uV3hWŇW}vqk}C^Z:sMbMaqxP(/2$56Aoh¸C7O?uni8cNjXj7%((2jpK>Jb>$ʨm-}7j4^&'=7M.8C,5SgT8' A[TM1dbXM>C傴†N.G/B!1 !VG-UNA|C 6 @yIu0Un@U |LO+ ."G/ ZkZ@W6dl+Wھu1yd91w 2pٝv0 }F8|$q?7c9Ggů/5k1 c^h;o%T+`Ʊ0$]!"o5-T8 :zϭ?%)"U%epzn4o\"~ђv_?pFw&G_pZ}\ ga6f MLjxv-|WFwDG@@K=+ZIpxMTC(7$o@@@}; *A~ƾr2TeK0%կEřN~,+ SՕ\%N2l Y TGqXXc.?nyeTf_k&nӁNlvpֳ%iu fQi\ [/NXIζJ p -{ .;2ǁ}Pܟut%\׮qk҂$|lzh+jvOiYhzM)(E[+Ǖ[ N]ުmFAjtG}L;(AXpTy6Bi:UtY7 Ͱ1:aHR@RaM4ĥZ Xrw{*7(gc h<=%"5Jr[2t|7.L"kR~bUE2X{xl){MN73Z3\Ӣ * 7?zFbJBeCF7;<љ18Kb9҇`XHm"d^(X"5{&BTP tO|[xY=gd5[U1')J3lAUPcI`)5xtwZjQ刚.[]4!E4o*pMSi3Էgj1M9LjĮױl#$e#c;^K|~-rLDݨR|CqpAc6肽KsX ,CH FDb9xℚwihzG 30/֤(^_5 z9M%,*qL"<˦`JJ֍&-KmE71>V D#ҎQW,SF) I80vnO)#̋pō8<|_ j!݌9UZ;%ĚGJ)x;;3L mx-ؤ q\/da^I;F qSlKSaM\O%&D¥Fk S3];X :M< {\&s#QO#X(~i$$' Nޤ ehE*HW MEk2"7^2hJ5z~hÿ/*z5UabSg0Tվ I8r3# ^\FDD)jEíؼBw0CO+*!s.v3Beى}!@W$x?f΁.|SƘ|-/ak" ՑL 3íu #eiq]##Uy3#:[-?_ N:6=Zr /u BFI{X(uMOv}=ƪ&d.%7{=F^c@#d^'peF#U* )8tt A:Н`hmc}Ď a9{TFXo'U1MA6qiG4~gY|!*p2Iuo+͹{83R4$@[Hu KROUUڎ < @5 laԦEtFlٖuN1lퟤYUr^Qr.d  3@<n<x9c`-#!Z+ J6xZS-Uyve\"3 az $.zn44R7%74Mc8)ʹ:Iy&&&FHn_F!bQu,83z^=? 9֏H$XB4?#!E׸/b-Xxgr;:\v{.T""!)'Cc-&L;a&,R3cqY)ZGU6.!%*"#V ʪJREAk Y(Jf 2m3f:9w 0W/E䲬A Tug%N:׵7%T0(%֧9rjnL8WQX*{~l:qo 갡hC$G?A>EMe=Eה J`!M2D$̔BliˆƌX{њ7ZoNDqj.;]R/̿-`C׎ o-jkKږit>*^ǯ8 0 =ŧ8@xGZsdcir+w#d`9l8F- _|eZW({pб4ՁaJ?!Кy %aU*lZIkڝc)rRi7Zt_UwQ,7p\oiɁXحsEIDNU'4B~喑fE+y ݇*yjgteuv*ڝU-0OMa \҆º˓\Bs>M5V#.Z[*n(?@U<3X U`Tsf.BÈYf csv{0|%ӓjMC I)K _ 8&"܎inTiUYtagya8+^i,'4ST=D٥K7 "w3#3Z/#SVaiZrU^A6w+ZbOhy]c8AfQSeTZcYYץgvYI 9t&-f:3Co)gw;2[C'86 g:t-NE!cMP]@tc+6핛I<׉26Bl4ޢ//}Ie|z[Mysjb^є|0ĹΊf~D5dgbZԪ,z:|6(ﶴ^_rp79l8 o]^y-:d`l0F,B?+(p1iq/*C"&GZ=RFFP{TFL>6!/̺Z-r"p  UyV Ɓ6\S]mqOզ^0B=@W9mnlUmue7 ZQYվvf!'II!RyQN)BðdP;)Rlp}]#ϼne+J{ mZ44SBNa`*9\ $B~8xC_-UmJfJ|!7x3ZD,b㿫U`'pU3g9TBn\"sE$Wa 1dI{h7gDK#8)}"у7^y-V .Q"2Xeu2QvjA>ye 쨁~%+'G#0M|9cD-PHmSe۾M]v/x0}HU1 4W'`F$V]PMG?@fR|= _`Y55QE5wO}xY%âXhC ]>>\PǓpK5y,\' *s-diFc@"]?׶Pr5}HFD#2'X.":4b5C#E l8paevGRV?V .+#4Q΄{IRGYBnkM8<+"5@ɣ'P ɟr;P9m'Fbz8Rneѿ g7->7aQ&P‚IAN̛lqPthvAzz9tC>'O<p\&>.޲:66L{ܑC<ONF$tE94]^\ziiywd l\1.rJizS_]GH3Je*&5f/9-DsGxYpdE?Y.`T7 Vз̥]҈i1:VDu/f~j.y^*O|x9m#^ԧa4#>_t;\c萭YӝV+uj].Å6M> (MF6rW m-| 0GLEp\obSG Twub" XY|+sYUD!_WVB`KT k1Q$wpXy%ٖ3>oӧbа[3{DxR OنUe$Ҫ.s1X(TQ8[I\( O7 eucMl'4>E\Cq.v J5~;+l}HVS~ Sn_dr<{gzjmChUK s#S ݜ‚ Tr>eꉥ䮟I׏yxM$F6-oN;SyA}ʺC~ӯ(!\ʐW lTdA çK%Joؓϐ;B!@D }v/1O"¥ϢJzs\ |F!L$}F#n&|iV7B[J<ԅ0@Ə~Dz?-Qzr|n Ҟ ҔՄN$)[[{碊)X'qWBg'@Qn/dMl񛼺o?\&GqY.0A]{&|ֹ*hţ[hG< A=8]uQpNHe2 <ƣΛF@6 /*:|\(0~ $6ό RE=&>"֢>cS>N8 ;Mr@)!|1BsOgUcl_g(sBpb2<'םh<˜L(x=o䅵FkǢ]} X{Zl_gW-^c^4;2Sٍk7 5reQoUցenFd(᪴Ub0+kFh#O>1ПAm$$A_ R&94JoX.[S.H/)~3ckMJxv5///$6$݊5dW2fqy̐D|lȄ/6Zr#Ϭ5v(fC.uKPs}TFbe+R^'֯`b('eW#J>Xbرeײ[E;C@qxgY~TZ|[X (@لIr^,ݲcy֡S3Yj~tD]X4vm >x;(ۺ|;ͧQ|aRSK1z/JдG #XQ ,&DƳ&f9@#Ar%?6 4YPP{ک3uxDg("!%ǧmX8LSMr9m.ϩ,6™<#qjP0: SC{֭]b.pi^;Zhv Nkoaa  Y Ja?x2n껭<؀ ] ~YC{C%shg"t k}Yn[pҝaJ<~;@uIs=Z]06g2{"*wc <>>r+* ^;Zp8y5^xHcd*9us#wm|Ͻ5 n8*ןh-Ŕ܅ N.KɉDđsM\%EolTD%sެ'QUC A:5>!9t9>>r ۗgnݸQLIi ԌpJdHz\ko 1<. Ge`k x7oiU/7Pzj1EbGfUʅ[{jxm)OA|0qmt4rK Z2ܦP#s.HtF 4;Vd+.8ٿ10=gC^rωB~"@Ο$.5L 0K.K>2^'=6IdrӪ[JH p)8c")E7*]T>$ ~B鱐=YêINgn^& y gN s0QbCZ*LY! jӨFK~Z`]m -I[{TtPx $ɴm1o|qP=v{NdS6|ݧ=?լ.+iHhhyq-zm@Rtg+l25LM Tjl:H dYP[PaӇblAY>%eA"\=H%R$})#ol2’Q'̒+#πTb$XY+iT6-S샰eFk'-VμVx Wm,ܚZntohÇHeʋ'=N-Yy!<ıJgT [h/M1S7Z<#\9)Ě8 VNڂ{BuB"wb*6$Ϫb:5EXc1]Չ53YQK!u)ITw}6d?R-EkͣӤX ݈;>/M"4͓C]Fs_N8͂§B^t||L4d9 R&K-'vbUx(бBb6c~s۵ɜH;'GC j\p%ŒC%0KIrK(;.oʹ'.0i"˚N_fNFvUu15r-ShfOX/dCɋ`X߃Bi:ǡWr|Ԧ!Tq5|>ELHSS! $'&af#ڟqЂ_O&sFMhQ[d7Bz-}n/ ,X),nJJQkJ*vF'8xk9%SM-?EgqJ5#S+#"4ھiHt>L[bu(n 2A3)iH Ŋ`Ƙ'T]f頱REzkհN6C vh>4J`m. Ԁ,QuIxwHiIfR ώQ5"0K_KXu9rnzPLsrx,;x9ۑy'jCdXi+!'`V,rG)Ϭ"^Ce/%*:Zh኱>ѯ:d7KE4L1 ( Ri\ӯ >Ō~ӕ;$#xwZ#+A&+UF'Obb/ť,KFƁZZӯ d(8zb圫iQoKI?;sjn/r~ª*~ՓGZk:#1Gq i-XYjCnSE[e+WELÜC"f1-ƦiJ5 AL裥mޡ$oYjKYYfx2 ЅR8Y"7KQ;@*خۓOy=vaZTX mK @\6hc< 5U2`J-D˕C/HXi-}7>0h4n\CDkv/†8)sAq/UYЙ"q^F|9kok%- u a\V%Ualp |C槐k(N­F r՞r0/K' zԓ{?zJcۍCT (Kp#кȫel tGggj:!7}- Eф9fiJ`io$5Y: ^08lCV=ؑ $-p-+kᣢ YVY≛ 4Ws;2Oq7g;Nf6(͞oO{R&oLWH v~bH;7\k ʘqܺQēŁGoulyЊm6BɝۜW)~rqPp_],A!+.y;uvGi>ʞdG*t[ZCK 񣁵7t}SEyT;5~/{PVaCG*n UJb?p'̥aCłu^ ,Y^D>`C.*,j%Is{MK Rި )[4g^35&ǧ}`%LE?cB ¶,81 Pu -$tLY!Ѓfue+7< HBW孆`ɶO:bˀ;4I)[0{Z#U$ЖzP*rUv\5uF_/@nn@˞s_G!oa`!s^Tm(zVFOP})GkBRZYM y>Z $ pSăZA0edk4;فهxHYHIUӤlV~FM5 RVko?LTUKgi?wn  t*lVw J6-Vd [S"zjBZ5M-g2M I)o OdXLŠJZ{mg) 7 I rZ=Y=! (({i,%RI8 Fs]"πЏh[4`G8o폐:h<|&Λ+^_y:" }'D{x7$/QJ:BgXbKVSacW:^}['jpm@I=K?8r7ihі\BtQ>Eh mݨ_LD ?ްs˺ >DluϷs=2{#=*jpヒ{sFl%oH̖ Tf{xC{*X+t $+J]ؽ!!+6fI[lG \+unp @٠^*¸͔@=tyѠ@ +8ʹQy*Y/&a'3_ewp!WFR0UX<,Eu|~أb@UCe21;rmsMHԤmMmL=ǢKRHd:A+Pq# ׼N$+^ߔzX)?FqZ|&#o v! *(^\13GߓR:&bY_ $Ha2܀PqɛR 쮳E#7Á9aTlN/:f(HE]%^I]~h4O5-P5Zr*U F+}c|yÞ6 -}iA[ZZ_om{P X'BB=r b cT$`T;vifua5xN@=G1M_0_n_Z !LLc AIU\ vq C %C@w.<9)5c`Q泑_c )hQ&dRl__(G? gSY5|M/z1JyMU"ػĠ;yAA*8c`MCTQظ/T…_~=uy)k 4˫>}ڄȒl]\[ C,reŽ̇1?֍ya8C(Xcj=5E<лgxKNc(d]an_+#geT0 2BD7Amɑ 3>LdzdT񎪂b=inļfAB4M~Xjf§m?|aaD7548tZp஋U[J( *%k@fH(p3NC/j: }|;73114#Ҭ h3P:HE4eטvZmw՛5t<įo[ZW"@әfXOjiޤrj u3'tlv'TPE@6uZ[: (n8?2)-j$SJfa2ޙ3 #/>RYR\ Q vaRJh|8J t ^%䓒b٬:~ʾ4m-AhKNB5_~P*Pe~bu59g@5__XeU,fmьFTmLwz#UHo?5q#ipG%[.sC~M"Dk}klL%I;y@7X 06nrxGҖNk}q P?4\)-8cnv{nc%YWu>Խjn;??m/-0ڜ O:̨@ {{X̄PwJT6 |+g>9sbE4H*d]ھdM/P^~{WrMr5qd`\'p6Ӽt.9EMxC h<$ )K(XV*Zߟ-k+eO?taw4 WSKxIgo4LFA 1Nn؇;.JFL|ɑx*AuSU.Yؒ_τu.%[Er/(,2%~^ KoF^5\CZXJ?K]pŻc;4u_J4# [n4xg]L҃p-ḩsl7b>`O`i#%nPwz-|_|V/bEӸ Ct"'#kZօĶ!#w~OJ:æ\L1"j1u9t !f=E}P iX}#E~^N82B$)?a]8ܦ&.1mL kI*N0I˾(dL Շ,ǥ(׎Q. O<7;+t;zkS5?_,ؗZ(f*?YoYu8L!WHzhsԡbZ!Uu)Pjv9zy1|54Zz#v0a_ъ$BnX(XSXc[%(>UZSx]d !. PO}rM'Ln\׫W@Gg @oCb<4v n ەVMZ5vjr~ qK0Jp3)9+-NOf|!ώwܡLueAm|Dބjn>Mi~|`dNhj޸S #}(MFb׍?q5e`$eWl۹l{AV n_m!ZcQGC@N, Z ȱWxo3;GCw A OT-|)l4W= 0]D?n6mmyvώ8.w8c;Tc;PS3O f᎖GwL#ZvH[[Ϻ;O.-jtWM峳Ol 5'QrOV#a9 ugIL;4{E0ɻ)P0~ƛfN]r3d'4oMwe.'_,1ua8:{%\p v>O Ǹ: X䃚,=/%-5oV"E)zWNݙJd{(\ā m2E4|8p0Y z;U <$h@8:َmEڢYXn)5X5ߓ p@NۿfOҨ 'w/1=_^m[oFAqWIONuna vD4)fS3}iD@߾UmS*xiUNEsѯ==QˍIg#ބcݎKȍq-@ki=ٵWu%Z_1:<+RmcY :1X B 7wDFu\Qj m|{(=(o/N7ZsO L+P$/:{%Xg3Wz5Fغ0[B;Af0T@9:p"8]n_71GPi\^oڱ=0:J`w@͟bVbhzF;HѤlRU[n؏JnĞ7xȾj0I/BWi~naMrK3[>[g"Ѷ.v0HL%e K?=~ST+;{q3ڜF 0JHG~^jxn=67/!xk7DŽtM1UEyv'9ك!jˡ+lc߿1<}Ē0u6jh6e2]䮗Bԟsx3!uȎڝ̏sVz H1^I];^JAҤTdK+gVߌ| Y((M|IAaDcHJ]:XHf~sh_V8M\p p 'u72aI$M8ҏ1yzlf\1j ·~{")vƘ%z<3ixWqm-=g!7F m뿯 p?Kmÿ@A rǬP02dSǤ`wAX@; |jzdL&<;x ^$sZ NWʽBg6rÊZc 8RAp8\{PQd96=RbdJ\v򰍜gk4bWk1aklYlr]\TfNIqjA YBp-e`+?6P38{w5_~bs;8K]ӺPꭈs(ሎ΋i2YcnLaCaX)<[Vs}-?iehYNWb̄ʈY?6]n"-n_ɉlӈdq2u@di˛-jړek߮ % 뤯GԊI+f 9I' :;2HW\Sц$!Y|[vît-YPS g@n2è!|@eP(xoyUCB̯S4oqVt S4|ҩ,}X8UYE ?xO"Utjʮy2rF E2yO1z,?fWƜl"NM&dQjY>Th=iH 26d=E>,\>g_EǨ \U2$+/+fNzR1N-.  ݦ2X=sdj;I|S4逋`XS_˩Tٕ#?b. в곆}ZDY5RٱIOXV'쥝u4[@ Trf8Q1\Ib =eg2G,Bё ?́t-ݡ0*~x? F0 \V<6Mic8/3;=5S$x afg;+igjLGk (.wuTE-@dLDRKPG;%#%?ti/_W8/B]靊4.T o!&DhTKWa/;2G .:h6fՒ@WSlo *{yF72 T*)|]T9"Q&x+= Oy짼O}IIihhmGrSK̈́lAvN,fx}J:ぴ0+^ltL9 quYTKP3aX)٦ %ۉxnm;-l[d'ARFk4W Fz}3R܊`9{N`Vn#w,yk8M_I˙,m|u">F̳el u6o׷߼wv[rS 8ed8mp< 0a= ջj~Zd{%aM~h]BPX›T\TTQUSpZ**70b'C."hC %`y\af YUt<@i%KDu!/0&տ\y8~ V{Ex01NsӌXuYgGP7فiXT FlfD5^z[VR<%%zLCJ=G\$= ,%o85Kl#,Բ')e8f6fvPg??sZXR1wq1LH5p'5Vg-FI8ΪF&cB8sa*)gDKP UPB4W}5ۀHݳY"k ŗv܀k``6@ tn)?)FS" :G}{VQf}i *{\OL6%7}/VtI%ƙ#$)4܇#8p䛮lzTC2_ΰeJn2=`D:˱!S*ӄxkZpC5}3jzou\ݱP@ّ S-]i, `iOC1:-(|@5@ތ{yV:y6?Uϱ*Hanz?X_baMQ]LD{'ה< T8zVԮ5E}kA>gܬPNu]cep\x^iR˂đ%RmTgc 1#)ù4ITO&(hޡX%lxS` ;<*/@*Q+#uj4 ipLh8݁d9U8傷މ<8F16ܵ3:> sVE]V!LQ]Q7_>m zDEɝ z[^_G%2<:Χb*{+HSSoZ#) kO͎\tMQW37`鉵¥vӤM&i o$n!峬wg%!<!RNm,wR8hQ%p ˉ?ꆟ䂆4,'ҹV |CԈqQB Ll.qK V A&a: !S:b6qe(l}mӦHpqVJ_I%7}ů1}@gVNd̩Ӡϗfz&3N 3G]I;&>`YʂY Cah14 ,׃! }ҹS}SbPws!#q`YƔW]"8-aY45.]Rj*N綴oz&KD\ E0agőڹJ/O9Nt<M k,?3GE^0hĈqR 6"{#uT-M_+M<ߎ"@y /sg9,Pb^~K/_6k߂Ϛj(G3;N u:WcH}mZw e,@xd? veО6_E ϻ2UQ:[eтÍ BcW3aߢ@0V눹d pwv1e{ @qȠBͬ7 U,bm /#zpdC)N"ċ|0 TyQvZqàYL+3Lc[{9Z^wu?G+D4kB!TJIGZ/O(-$SMX^? 1_H.EaB9nr\uK[)m H}F/A&Ç2vS 5_fhBkBr{2q1qE_b6O["r6pcvc;Jҟ9qʹsC*+Jcg !4}ů\st&!VvOڄ#S.!(xU*+D$]AQT cUtNlg \'Lv(RbXr'-PXd+e O}8c~V9K7l ˩h-`)w6} ͊׬h7?HB~$3= Nt!jSUv~!փPNnL9ߩ?,spH|@6—L{}P1'BrVT9#!a( BO!xo~I`?:s m4C~~dx40fvS]hyDB:LRN~AKC,ba,Gj~J1g]h \ħۑ]t Jth$ݧ.c"EOth7jp폷"kDjR̎m7Lw?$',̇Ȅ2 /AWB%y*lRMՂtMmV[HlMϺ:qt=4XJY/'p0(qzb?l=R2S4P{.u8gFd  jl례;L/GՍ};ԡtZE'&wR8Y;VC5iB~i9n{U\VSvc+2$h0 `ne*͌OE։NwqVp/^jYoKrW?MaF~Ɇf_YmqX鄁 Fs !+QV=Z0?].$'OHui-I&=_FB2JrʺLu /1 πtt3!x%H_@Tr%E:|}$*/L?Br !z K?D6ЄnK/cEbRm2$[8*k)C*N'\jZ~eUw9eB)-lfv1 ;Mx۝Xf<@:clr{Jr)Yve~Fӧq2Ά~NjAb3]̓Ad]r\|LV uqQXK]3Bjh[,ǜ!H3Јj_ΈPM(f=tJRj¬n1}H L|V?2|#xAjj9hA[h@a̼ |r}GC/-QGhhͳzdjjܫ(Z~Aй$M9pyC5;i 0Ƕt覾1ĘgNy璺S߆$e;Į `Pre | .a8 kOF=Mq\llOU'ckɃT7筲DU˜ģU2/@p'|2T'c &,jb%baܻx6ҷ$pB~ |*>|pآZgDHBá% ~m=E+~ :&Ns@ڵY=R"w?Gt"H ҡZS -4xnIW}7m?$j~c\sF(f F:6-6~دv;gk>Za3V9٢xS-mKtC0S%B2/i~n.&)rc|ے}V$xAΓ/IEu]R|n:.w+k88/%!d!u¦mhado;LgeXdJh_ en)2čș\O{670ܕMRy[~ħhsݢh'-TIHngQ*J=W#^!s'bL{BH ;`FTmYtj坾`~E2ٳ|Y VN#o~G>>xd*"JZSW<-Mʏ ܏Qgoښ y3R]\{5E,-(&my/qK'U2{jy0f&fd#tNx ߳ዷ(yh7X΅2ϊ"Qa w6MՌ_7m$ QcŬV'|2 g;)0yoCYhB$*ʆ8t/mVT4l[,7M]`9gl<"rWr\=?QJ e-tI_4V먾fRnbOnEDxEJ6,*<<)n\Qm3Wbu ) XSUOБ ~qs#QsDZGl В"S8h0Gz_TI-D@"@kђU"/"m= &\7eKvɕ/,%D|,6)vαPBl(Ew7(Kz%KBYrօIt'y“ZzCyFSY#=OWm!(Q 5Omq^w_Oss*Uf,Wv~x:/U`"Q vf *Ŏ} DuگW8x!NN(D''4ҙXzA g)1!i2L#д0*xFsTM\ә蓆={ӷсўz7ӪY9$\xҡuw^~b?F3dX%~( 0:a3N= 3[H-&d(pBeπGsP+XvYw|VhKm!Sr8䶞%<~Uok-:QRIZ- aͼw&=+5t4F77PyOmc*Nj^uqa~8O1Fw[OӬbca8d,k+ߙI)D4\w_mL'3GkߏpbL~FB5}q8'r]Wl#RKK'69E)|͇XbfX/6xa#CTᵶs8]&)]0K(,*a9}0+-4a*x?.9ynteg1ޅL+B% bG%*1.Hicgqo ^*Ґq([}4X!>hv85.J䜆uQ D}_v H)'H6M hh`𿘇MouyrC! JziFWcnc&/*!&`4fhKoψp/6j< ;L~VH 4*Ak) d2M]! ` Q8LR']A1dneE_oBAZ,6]Gq{n oȊ=WV*=AENylB!3ƼtnKcxQV5c[IݜHS(pN}ۘVe坿,A+T-n!C3Su_#O ϫ&v2 0M`fs%҃^duhϹ/L&vB/;5~a.6لIhC(ms;;!u+h!pwjkG1IhR}~P((2 D YpjDeZX \maQЁ~AA5CS3;ET}90LP:>;E-&JGm`[ITlsQkHBs8bxef m/wG*s.ec䎼mMCO p!ٗ Z60\T,0ȸd]wB7d~hfp! /V&ī-p9aȳ8EZadþ \49 '$Pcc&+'JW9AkU ^GIn/`߂n/4+Þ7{A"/ɞLtc>!)EHKHzyYS2.Qxobs=q_`G7ti e*8'.)N%=O#MK %~Tch, ASUB-[AC"\^Uk/;|ɾ7.қ)?$ILP![ 7`z~קŶ8 1LXJl $iq-zǚPpmaRO[g [PtRmD6fU+ifq"%x&x,23-k(|)9 9Ժ%$;Yr7{AGB:k.zy܉Z G#dʔ)prNjЛ;dYkˉ ܞM M [(ShAF3<_7mP(j֩P@ E6#YWPg'|(hsX79f0$Q&&:{tye"2ZDGz kndȺ&*gȑ] $ -$QLo6>ᡋ1 A.NY@HʏA*Sxk_:1kPBud֦ ]2|IRƪ~(eYK,u?);KFPa{56;7 Mt<`AܶWyf.d1gvk<1\ oMl{e(rk^I({75Ѩ +Y9hphh4;,I Eu8&[?fyo"qp @t]V:tg뻣 ޼Ek)UHT mjXƢDFWf7rkB/w=e4Qj.#VaXtO ~] ¹TfeRyH^bE&'R W=nʪPlA$PL«,jxQ2e(i S,dwń&P|ƬUKY;7B7']xIs@CP~zm d[tEIڔ.7WXeDGJLԮ)IEk)ˋ5s<,qq`!J϶ Rl L_̰/z4uO| bߨRHjAS( BZbͷ4ٳGe^/*gq<!WR1riWd\,\aB$/(jb[G+Ju+G㪩Tg8NT) OC+9@nTX6Zx7U=;0@wNωM%9*kd_(jv#b( ([ S tmn7DJ)L pVq F՟(! B7bg:CN]y oaJ @hVg%MQ-VM`8s_c*'r+e\z,~Vu  %;A pl ֘(e*TLѭޙOWL`*yIU1M6dŚcG=f1+gH/b-KfGt~=N7+2 {f<"o~S삝B'Yct9:kr' w*H{סm 3P$n>rwOۣ>+KW uݱQ-Dś)$J5- "p;NI Np;$+7Qx|~\Ew~7zt}Nt}TV*Ҍr_:훳kL{VF;|SʭOmモzAjlUGGƨ u"۪v.=D[&J_vX/fwb0RM-ADźᢖ8Ϡ%nnFS}Wzƹck lL@q$ -'P/򐿼 MXM0k>s`ZS  %+;:+Ty P(5x5fǮ#mkvbZ/(3m멬*ܫ`E $9Ξ.qUHINH?ґ8x^5dЗJ;h5>$"*1H\c7e\~ӧH&]l[\#CΙ4̻)z".:2Fͩ IhF3ŋw =JI5C6!|/v6s!Tǂ,tU]s>ww+z\\E}AiзY1.WI޻iac@Db.tg]8xɴ2>& {y|hשp]sZbbSqsĔ+6\ #Tj=͓L E#WbvyVVk@9c1¬~ Ei`A$h8Nsh1M#:H*K:-8-mY2'dA seGU.[k;cm pۇ;$@LZ߇舎@L85w6!#hoiI6.WuYz{KCde_%WN0[ r/D *ye0Qw)m?/AW, ;@GZkD$!oa{)Arxm!<&=%?x=x,z=19$yԋż$Ppkoў)UIvew=d͉N1SFvn>Z4'.-Kv9¤1 -g2#2ٴL$gx\p]GSoV& 0x{H9# wz("\ɿ}$CuK( G7~Ŝ#V':ZUld0i VN/2)_.!NLle hp5 ӝgT\>+i72݇Pƛ>EG7?R^dO-5cd˧gy"CVm#~*O-5'mp] c[F՟ Mf1Gcv a>c-x6&vOp# #(VRZaϊa+Ĝϻ8/l> r5ԁ=y 領5+A~vvLzkU`+p831[1Bvo&Sbl O AK8x.$~癇goXQio n8gkT {zb1 ~c҅.z^߻&-OFA,j>l (brK"p`]ra]!ZXoӤ rP.nw5LkFFq.q0Y<;o@P`~4qxo#brB-PVkyuҢMwzޅqJϫW՝{q*f*pxT)XS} w*}#PN-mdH ;]"6{cqSvP"CmA9%z&"aEQ@^$ȍFy ړ@, MRoNVr7߼&z#4Ev]*Q<EB%3.uY.Gsa5Olt9^-.;A^UJdnE:8@dyfG]xK E7 ?Z)# eVHn"Ͳ݊PmVJs@MѫREYEoF PF{ ]kh6.ƀ1dR ϠIRTwR5"Cޯ_f z6oa>T4fbyJuJY=O]D#`$f+x=qka1M.6wgKr2(J,wcH,x Σ ^m/(@XF2MM ax3 )ѫY +6IjXyjy a?x&M6K"BsR2u=Il(P_!3(h*(ǟn٨X! o V=PRlWᄀሗŸ`O 24u2V='{ٹ4%uզQE`HA`_?ȊA@5 Sci](vI%"_V4 xF*E }.dKNSsmqM$E\ɡYY(6'Z#s5KXTNj+#gZ"Q ]jS@{܋4Moo5zt8 Ae^lȄD02N#_nI^9ޛrL̘>'0`{L;(+7$,6x ?#w0,X~/|Q.}"6I,BݪxUުށȄvX~yTuVN@#ɯmid{{zn5)w3ˉ"7 |` ш axas߅0nS_ T/(Sw}P3B PԞu"LG{{XmR;# rOZTOȌs)))2  pzB)6ܺkQלlvp4P@Ŧo-+w /Y-9xш'^A~l`KdeJdzPGTi~  iz~l!z L{E9ڌxsu3uPu-vv8/Q} c#dh]x̅2[,]-6G+QsG:q[[wù("7ڹ(:83Ȭ߉5*m[!]sRAkq7cxRi?T.XtCpquf-%ݏfz,vrQb"z <]v&e?QnP|}0 R#+u,XsSk}ۓHcx|Ӷ<0҄N~h6E0FEHX)%7EqG>S Aapjm! /c:)]uꜥP3F.ۈ Os_'ѿd6*:MoD V %@j╒Cej΀9Gl+2M 7^e-tnK[QgGA NZ >-@?^mY^Y+gE Dl^ /oP zP;X)%^EDޏQ O->~jj] bMO9%$#IY䈒&^9-~kXjveܖu6FA>տ|-q ;)*WyK3T1ጇXGI--w~{j Fouژ iN?w iqPo87u>m(,z^ѸWHAr!к?{#g/Kxf .o@oIo48[Xt8Q QʹUWIyc=.$Va3iFZXlbvx5ᕞ(iU#>ǀ_|w&XIC[IC٣b8kW,/5#1c)CVCOBYڞUе.V@ܶ1ؕU=<>׊9 D`bR;pqXx]>U=_x#QڳI>*mU(EU_1%hڬ@;3ȏﮥW3|Asld5X+Ѕ]ua[[ԖL }I.>i&tdX8zD(23ԩUn)ہw)y>uT{Ј>S/ڔ\]_ySзnE_|X},e<[H"܀t3DQC=bu L%+( XEeġo(^$zo;4L837x%"eZfՇ8HQ{i?t߰0% L BmZM5{g{MO>›rƩJX ݅z޳+2;xƹ)9Ni'!|%Q1.(B<T5[|7GC4*L_3rzlUyO)$[Q-Ko}z&2&*S=iLZy0)#yG*s>v>? ×dǍT9]8=lsymFȅ 1{O!M%悵K1d}}P' ) e⏛^i_^o'bc3F &9 x80/,$Oov?nqbW;5X6t|(,jCވA9o\=]KĦ*WDS#WAJ- i>_ɑ!hdt=19<_9tmԏwvbUl^Tsybģ@Sp5UC:ݣ#νPLl3c5? hʬv~~Z߳9u4 tNM"&p hQLehNpilEBmk/vX+ S ͞;9ixQ]ng@juoh-_g 'VmP]"À%LUaB1g :]*}0ނa|.j"Nb3LoR 4:<ҸvM?~% =56N75`,\=/aaJS(5S9)]%Q_xE=Ϯ:Nsu61՜f_quVs\o ]5m63A{3@R4@Jlu}v@IA=D-#F @_h;7.mt׬RMoe"lj#?0/n=]L)+ŶvDC?ʟD:~Dr4/RK?4+>qѷVB8 vƭ$C?A^-+}+t3]ACsjF5#;bg| 'NnI1kQז5w4}hrkg1 BJrIns ̿*9RS qs⸴⃠ȗX2L@3OMtƍ@4w5H{ d E(®{bL+uuaHQn)Σ+,&N[|{FŒuL W'[D S>v&9'>!-؈C⬄ڗi1_RGkA,E@Wo[h9rȵCP˒5dgf4?o*ZL !o$O2ҎMCւ>d8#1svƐ~Bumj; _AFVJQȳ!(Z# t56]{_YO (Moq:iJ34#S\3uŻCu7f=`vᦶ*B1ށz+gqv&m^}Lxko&۪!T2Ǐ}m{g*]#Y٭/.dIL¥òvl٬]bMʿA˪ؿ~`=v+ķō= 71?je\6*@?FS8?MCLj{&rwmc [V[9j󾼞=a[y/AX˜&F#̄9$ $ˆg]vĤm!blb_CTޞ|Y˖u ͛PGXmLSi` 6Qk HU}b`c .Adr լeRұQm5Ô?OcSУsGG) S7EK0]!f/ eWs6]`)[8;gՎy+bԨҒP#HTp)[{;=}x(G|9P75e$ V?diCQrjP_Gͽ;nb jHI@gѾ ߚ|~ʌzC&>x/9Q<(.}f+L#dqID=3dTA741[p A2Hߏ Dw[&1|~w=aP5#ؽ،LrS|[dK:b~< Yژ0S>Bw5ptӺң3> 1yohOx>Lg40G tt2ױvYʡe0\H|pnđ;EaLL r #,{BA wg밯lհn*"z+JawV2ַuYٰϾ&fck7DZ!YV!ckNݗn.9}!?ceK۸o i'/YCUgoL"gbsa\:y]t#(`3V8 !CJ6 3mZju5=XoTDEF♀+ˆ0vQ\uvS00әP?' A5m!L!<h!˖/^jZm8t/-6+"[;N¦\ظɨt- Ucȏ38ߝ&3$<6x,^G;ʀ1#=J0G&SKr! uє$ITzD*SY65fui+B~qBPlC7E}@Z ŋ%v.j_SRjR10)mt=&D=E2yܗo>9PVJ .ppT@ 5yrn'fǕUiԙx\^GO4 /^3>Yp8i-:\l o])tn))P_s$|{]mV/EV<x@94##Z1a~:5(n>dhiu9 (C|[3[Vw z$bD:ٶ|?c剏5 4Iлtlw#'Y1r3C6=߹J-J6 _9,n8_@j\>q"e+ѳӷoHyyXxK~uicx'eel(0v~1̊DdNd?@x K%D]*Ę 4Z6E@8JXl ijՑ*2 Vo4] wvǺ`k<׼%C]1c˞kmWiߚfw<4-"zQНSd뽙'z cR5<}=*?h`>>h; }'&n%y#ibJ{B;(*'eў3>A+" zLE#˶d؂n,ʱ;-=dFt)>n[2ڐZ磆[* PR^>EBޭ3E+=.𳦗.{u kO+3t.~r$WW:ӄX*uzD-畞HG;Nvf{dtOU@xq:٭gV>740`o13#FjK`eD o#s05Zа KӠQ]P<0~ZL +! h-0e&e5# lЅEV*xEMp?y]ˡ:R @6gxاP>ϑJ(p RåV.џ;%pٷL:!j-An0k Lφkj&*rKi |g2&=SU:Ke ShZÍJ=_辗꟨Ǿ}%"5&%xYzů1Iϟ2a!Xj) 74}LHw#-4X_ɤG_߁VK~eAquhT%$|UPzm;XR_2r|oޠww"wӠV58yf٧Lh( ̓Ry#M^ԋz^*i]ٔQgOp2+Cq Ά빽37<_VTXouгVy_RY^]󪂐mqO/Sᝅ"47(7DS3@D[qҪo90{00&Vidu :Դic҇DE7}as,M9gQ/':jGOG*9- `>^zq^FÓo5}SuaTgd"FtL/h]D\~MntA2v2c)/?E o6zJGewyv񳁀er=Ԗy% cYg^@& AQ AgntY6g柡Gt4`#HdǠ wbg$Mw6}ouC"8ktD̛@~Gj6][}é(h_rtYt*1#L.on)v@WP䗜u Cbr@_+k*|Gs K\\YrL&beAM{]lz%=%HNNF9{=`H Jb:<%[3,WR S"f%r5RcX[ u,&1k]8vJeϓfNw?P&Zxՙ/-;KYiĘ@7W2Kyhfow,su N  D"`?yFfO0vHYC;]IN*@!BV~ l6?~{u7$ЩRc~WݖM5lB@6Xg):.a.ڪ&$_c֍ۓrX  ^bM ~BJfWG?DdSJ8JD+6MŸW[b BCDUW' qE8vNLK:)cC^j h odV)N[*tMz&SL͏R< 1KWGcl;fm[9J멫ם'Jq(pmo"ɭǜ7(ɸWm<4.ѹB_U}m4 m$㪻4:xclBJ\|fѝ> +C*&>orutWuֈ2d'J8U{%(&a6 M yQ}:*7FӒkB"ôˇďb]z!͑iy 6<׃86v )1ev$(⓼T~A䓙[sp@cq %@O$;{P*ݹlmg4psYSz*aD[`"f]>(5\6e3Ydfj8KŸMm gy( />c U4椖y_7S„ל~Dn{3ڑ=F&&:I'EĆQ VWQJg5qv{GԽ9s?sŒpn}1++bKhqcF#@US|vPVn;t^ı mV KiMN𐪟lX}` !voX61iLlq`tʗyCp,}SECCR:A,Jb]n?fPZ/Nkȁl?3Q#D϶N-L"7tf2u,[le#Ԉ 2c^W7btXC 75H./đ$6/ҿV9J>)oH{chciĤMs9@<xq#3]m{qP:62˘9Uaߤ lSC~& UZqIg}[@'LF5qtySFvnS,EBx g :^3e=8sN XQ4I,*-\0\qCׁiTWkb k K:j\St|z? te(h.5bmUJmYdXp(8ON28>忚Op5n§_-gA*Z@뒁>NVX=1Ła Dv{[!ɠ>m`(=FMsn(70g:io]aSmrP\ELF0s Dx<[G=& ^l&AO[42bo#~`j' j}RLjICU|e g@^\hu:]`_X=rG,{ )~) *?ԩ ;&[f0o@1Zs m 9Ͻ@)AC}u8$r$@FapI^>k2\sϐ#Ŕͭ5_ؿ =CܨEjCY H~Y V˱.@A`2gK,5Mrϻ\XgLlI3><$1m@ChѫeJf*fAYXpFy^hSc ~X# 5sm9פ2QȒz: ^t]pO\c/sT ZH"uS{QSg[w mhnc&X~VF$S.[F^}POf|-dt25[259s7 }ZQF9Uny]4%r XXa \9ز*,nK ;f [`ԵC)6v:` ę䥸l&Aj D, ?v$g/Ck!F>V̠&% lqV%H\H5ota: h!~/_y"AURx/::g59(y+, p}yq!eYb 9uN[, r6o⍠gU>Jz4_D~/ݖ=&'Fu AKq _hV<E4N@$ㅡ֡ nKA}ĀbQJ;%nE9WUkpְ$m?Q{6@{\\^ ċH>Ÿ y 0rA&[ձZIDC^Ʊΐ2Y7qvBpE7Y"S]Y$h:<';khBSo_<U3#"PP:of9hK#' rg\5I(Ytě:G l PqX>&FXYBt@uA8m%\؀x48!9'xk][o4 .}rXN$easx#BXHj퀀J!Ib~u;4y=uK6F P3fİLӶF>LAR>,Mׅ {A{L'6'kofqbYcJ~FG 3,0]voDSO3SPT3wU^Ӱ"r(u |"vDjRv]P{z f~Mi>}'@vsk٥B<ӧr %t(1 w'?Np_U}'wJ6\\I2 VZoy{jJ[/0+K }{JAؠ"-vm</Vr;m׺r@^ܲuM!*?Ww1[T3ىq|Xg3Fc!/rR=T} )u>/QjRĝmrb#d+TܵSP}as K8b6]_ )u{c=v5pȳ1},.6 56lj}s v- W1hyÁ B0 "S;y8)ZV迄UOxJ"U--Mm5kF^Ӌ81Y n=R_wY 89>q-m([?>97c,2Mㅘ~jH44&$yA<l̻Vࢱ6 om;5k6n'Z(D a܎+.i 㛻Z+'oH}pɄUB1\"S&2R)`T$77H_F̨ժj;/HxbugdUo70'WD.2 }Q'wtmYmW*F'Cٲ)M8vd㟝'H6>ҁ(NLȸgC9ۅF m?xU*^c8S(jgAZj b'uR:J[N3`(|%_:%jl+xɽqY?>rFi2`ż55nc__P+nll|T=lNDŽ?]wy*Qړ#:{]dmFTiqU!;1k6ɣbx..k]5J f$J\ ) b+/(G|)_KD%Yk5Wl(RHqlbX% ` -Ci#~ŕNozw6t#/sߑJ:婵C† ,q4Gf۟JL3d*rPjsBf9u DrPB$tvt"6roc%!7{T4qZYA)|!TU.㵏4"xS C,1 &hJw8zLc! lR8e=nU#(ѵ8|3}!&3"]נxVoZK`4?P&D8է:[T/91{9j*ۜg ;DBgS$w/{ϴ,̳Ib>f^P`U7dyP娎* YfW: YWݨ]\ U'b;IadwK)eQ`r(l KE/qep :u+#H X5?ڍ #pE,=)4xY@s} T111pQ}V?uL[絛"!1]KNRWIqF 4'>ʳu.I4Yx}N:ύ.H7(}tӸ CeOց DxD22oˏJ%0D@憸 ' =E!c6p|C4I<W0g,L;2Ͱ3/se QP EGTu3u>yy8Oْt E4 CPEB \q甗{Ky7% t,-h9PlR4 Z_?&{BoLVЉ Vz.(0:- |/l^<\("mK xGKXe@ 5)!R&i:TLp'iHJ*7#Ϛjm]"\:!G[3`J'FXY@)ʦ[ g>YLX͹0:~(eFJPrB{ͯNDKDtuԴx `n#ޥ\4ʈܶcAAOGDʺ vn"-͔Ď5-yRxu+vE%U 3 fjp8m%_qUaR<{R,ru_*1&R桞:I54M0%P/9K:CNgp-zQQZ tm0%ͨAVjLuV$̳m?Óhg8s>v"bWq"$_}V9pm$FkxDTWAj\nTNa5#ž"jk󗭽~t8#$~:,)|i=#>z0gNP>)/N½e&E"ADfFuf >UT@ٕ,BӞto+OciL}|aUFf)] V!\]ϴ'a`ŇDdH !㻦SV오NK:HZk K!<Ȯ(-p͔q3BB;fqlN^|0A9vGhnQEYvP:/Q5pQtZb@D!}窂 n:O7w>=a s[6B'BBl3'Ož+G`/7v`/E4RFq+WQ+yH-QT/iV@ӤAsO~+GOi^,BN:,?=TQ?jo6҉FwL 3msc4ⓄPy}4я6 Ζ]n>7=YbN*Eo=a|![(-R֣m=-«A౒'՛2q<>$@n%yabou^>l]A}Xb_Uxex`3pCJakGuQS[SbrNLR.om0EnigL0$gEK-Z1}2?xmb%OE޹!J^.u %TM xLmf?g*-ryp,׋o8zoZ@S-S$l9ȃ3#{ L7 vDFfxU]a8OZ"yo&9XǶ3oB%b&wSU͔y%*|η{Z=8 R)-얳EN)#nE*%;xTn?|m|?N{-vt\aK\IG/Q|H1KW-|[K*n$Slbp.GBpi?L*21);ѡص%x^r!sN/L .ĝ`&h] ^S:|׽jcfMs/wz kڙ_&O ?mM6Nq1C 3KNSn<]:CuQўz7k&YG s~ ^QU.E,^LVU[U2ԣ&2=5'QKM#ۧXb%ec7iq2ɁI67#ZRh˹6+a~2Q+l`0G>f1Y@  rj/w]ag%fՕyt(.6S ^dsòTH ^T6 cm%О\7L㻃R,OI dv,q<1bhjڟQ0u%$Ģ<&%[QtFtNS_qS3RNiV0g\l{|>P PTq%ώ`㔶= J!L,wV3mTɓu=,U<[>4lhGn?^b@ğ< DǴYKAJJ%n;ޕI-M^Xy&y^N>Jctl/^ZaNPlX͌r)̏J<{x%@SM]bU3~ͥG\zڸP*ݎ!FsR>4f9^3XNfhaυx/*G4\ò:up g׶^BH5uGQ벐e`冴 ɠ#~ J +4H=i Z2 n9.F~P/[UV`Ekh90~ UtC) EtN ?Гgnnʖ=u`-J'k7~>% Imz!`./6S"JW7d|>sR&p  }[ML"U+yHzD Me #Qy arEM% mq T#fvB({Ϊ?\.l՞ Iв/K7&z˞ P 3CW>{֗F,;&kj1 jq@W Ξ%I"kgI,BĄkqgR]8&蕭rֳmF!ӠE;UAMxֺ%ӠLqiW,XV%,T5r &@Ra{f|t_ _g"߬8vv?xB5kwzޚ|JYC J)? ɰJbbfxsTz-P8>]<'8&*nOu t2sGUW@0 g.9;u%imKMw<òdꅖ_uިo4d鼎]BF'Ǯg7Yi1u:3+\cfg O~ثT-~wgpc'.gn(z!$Purh&KP2b H]nPi뼥Sǂ=_Ľaw:3:1r`f?̣Ymt!j)ܾAv>ϫy&LکRyg4#T ^!`;¡)Y>m9-H0{_qtDȽ~ tT~D]U+HZ[@<˭޽$nͣJ|rBi|]S8'k~[Г к]_Cf[Ƞ!H6V HL!J;~ 4d L/bZt}:`5ZlZ{ slvsn,$Z;@h[/(c҉ b迨lS$eBR'n >@}wU,+ڭ!,=;"sDO' P<=v9H:I&{;zo2-0ci4]Y>- y3g4Bw2GpR|q*5{[{ߦwlt\ Yqxۂ)S<rC͍^mc]Ky=O.b+U¹Dx+\]38_G<[qJ?U[/rbA]aJk VugIoCQic5:V`T,0%`ٍͯN#ak(18K9&R:LO : RQ^I Y91B1k V+G-rmX:Qa+gJAdeշJ] o|L[h;e阈B nP`MLyuXvՏ=1'|f J)߯,!)Yc0f=G̫ڔ"4d+T{,1/4,6q>Hk+ͦjWmQۺGX_,x@xݽdMC6 :0VgjBaOyrl]<,X_ơ0ͣ\w=]A#6{R͵c[ ޕTLjjo<#R4hloC96j\_=&GIhcRp&.+I^[ESۍ}YQYƤ|U$̄yTQPD},X"nSgyx9hl9lSL Wv@I)B:y#4%x̨3,Y5uK-@{K65"^E `-y<_"&”zE 3" ( zU0vHe/Z\*k8|©)8r]m2ۅpFQ\JAx Zyb`3 ;]:/&+>*e/ L`HxB,?)>p#,< kbn9yk9,7T奦9&^.M3ڌ:WwS+F+L:{v^M5 "ŭ(JD?Bhy1  =(owS'Qs}tASQkhCO_})M*oг 0ѯ7𼉯ZOynX҄{CR_o6WW Z2eЃ7/q `"@3$? oxW=+},^o.P;߮h ޥѺE#%̎ȟU#ჸ<ӝ%MW7iZ⣝?wOfY2QP1{%Gg𘬒|'Xu7;*Fn!rmOPZ3*-f 6z#kłf8`mmۦ戫V@v@gф?(-ĸv\⎅\,̌I'Q)uojL=)a[eb>Ѳ9Iv ]Ua GN'}_f4b72 WcRDh_ju*r4S`N|4GiWĻ< (if>H "Նw Hi>F$@oe~ʍPN0-c@1 UʺBW|pXGx:'ۀV 7'_\@! ),DTعm܈ N`4Kt3n8s\pVvMe+l.8I KGC2c +UE=Rжc5akZ҂qUS1i..߆N"= ݗAP@ /xt+^4n{48Mq974herK)F`Yݰ_29~p] %q&Op I9ZRikitvXEzQSj Ye,J@Yvb$ X-rZlѢd\RMM(%r`˓} 6S4uEjWg'G^q^66ȂҔ עd'#; #D 6= ܓoCn`ř{6`.JRue-Y󙏋N1S&XXR.<%rҝg&!KDZH5Jd$um [K'[5/@TEOג1/iro6gi\n^h ՖϼO~{>:DWSԝ\+!*Ewt!"&_J, H{}rʜ#طSNYƁWRmyK?0ؕ#yV{:;\*s)j|p㡦G_: U3 H哎Rt;>"_m"d.Bʧbш6 Ar6/4}>=qKi+s&]gkl6 %czW85$i1؋ V_ڒCTD^B ~ [<Ӿ=@6Ɏ(v÷rĈ#)p%E ^GRFveA{Vu&ϜXXsw;n4 rȹF q!5Uwhaw)mxBP&_[7RpIL +dj:Zz u2>8yz~}^B,L$ ɗlX\;H/J~C;8iM%P\5Ss ==+)ӍK:V^ u:(x7ۗy*819Q=j:~ʊ:,I=K,> Q G`6aYJ~fc5i4:w gXV16gi*qF^~L E~6o CܘTԅm~ /7;..! #4j)rGY0" %# [jBJ~ljėZvWU~أl>J31?<;-#ld nQԻ1,qU]‚FʭّPOj}iWRk!DFo=ׅG9ZRoDYNM7uH-$Q s2(ν]/#􊵀ax»mk@kU{/*x{Gf4!0SD3 s x^XDm!2MbtZO#>|iϱWUAu>1$IoR^d }N =d/ř3(֧taxO6n}/qOX}SF<MJ/V=!|eI`21۠$c[솳Iٲ:],Q`v_YL]-[EӹLr\9J2ګD| n̛0"lI)8]6&Tz> ?` ӬMqJv۹E몴o/E/"iE x>,dH.t<y1c,0Ω7ʋC^J'˜˴WNy~:sUimKvdž wKǻ?şNGZ{T9肌sx~`֩hV9Q.y fau=Z'h nԳ0ϫy:0R;e>.'R-j|+t]h*ߦ%.(fl