ipa-python-compat-4.12.2-1.el9> M Mv ĉJ4!!%joLne)Ip-Bm5 ']g'\releng@rockylinux.org p-Bm5 ']"t}Ve6PRQZKobŋ9`~_FJ,bRqLj[x/8,}r &#?+zxiL۴&{%|^Sp+aDŎ};p@;)?;d ! W IUms|    } <T &('809: B6G7 H74I7HX7PY7`Z7[7\7]7^8b8ud:e:f:l:t:8u:Lv:`:::::Cipa-python-compat4.12.21.el9Compatiblity package for Python libraries used by IPAIPA is an integrated solution to provide centrally managed Identity (users, hosts, services), Authentication (SSO, 2FA), and Authorization (host access control, SELinux user roles, services). The solution provides features for further integration with Linux based clients (SUDO, automount) and integration with Active Directory based infrastructures (Trusts). This is a compatibility package to accommodate ipa-python split into python3-ipalib and ipa-common. Packages still depending on ipa-python should be fixed to depend on python2-ipaclient or ipa-common instead.g'Zpb-67b63646-9cff-4b85-8f07-6543bd5de663-b-i686BRocky Linux 9.5Rocky Enterprise Software FoundationGPL-3.0-or-laterRocky Linux Build System (Peridot) Unspecifiedhttp://www.freeipa.org/linuxnoarch -KA큤A큤g'ȃf}f}g'ȃf}6973ec491c6ab5421b3e5e4812d066eeae13ea7edd814467d6ef0941dca759759b55177234392b4193c554acefd31077eea460ac4497f31b48e28b001a7250fe8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903rootrootrootrootrootrootrootrootrootrootipa-4.12.2-1.el9.src.rpmfreeipa-pythonfreeipa-python-compatipa-pythonipa-python-compat    ipa-commonpython3-ipalibrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsZstd)4.12.2-1.el94.12.2-1.el93.0.4-14.6.0-14.0-15.4.18-1freeipa-python-compat4.16.1.3ff@fffff`S@f_fWf0@f@e@eԔ@eN@eeeie[J@eH@ed d@dr@dcc&@cc@c#@c@cWFlorence Blanc-Renaud - 4.12.2-1Florence Blanc-Renaud - 4.12.0-7Florence Blanc-Renaud - 4.12.0-6Florence Blanc-Renaud - 4.12.0-5Julien Rische - 4.12.0-4Florence Blanc-Renaud - 4.12.0-3Florence Blanc-Renaud - 4.12.0-2Florence Blanc-Renaud - 4.12.0-1Florence Blanc-Renaud - 4.11.0-11Florence Blanc-Renaud - 4.11.0-10Florence Blanc-Renaud - 4.11.0-9Florence Blanc-Renaud - 4.11.0-8Florence Blanc-Renaud - 4.11.0-72024 Florence Blanc-Renaud - 4.11.0-6Florence Blanc-Renaud - 4.11.0-5Florence Blanc-Renaud - 4.11.0-4Florence Blanc-Renaud - 4.11.0-3Florence Blanc-Renaud - 4.11.0-2Florence Blanc-Renaud - 4.11.0-1Florence Blanc-Renaud - 4.10.2-4Florence Blanc-Renaud - 4.10.2-3Florence Blanc-Renaud - 4.10.2-2Florence Blanc-Renaud - 4.10.2-1Florence Blanc-Renaud - 4.10.1-6Florence Blanc-Renaud - 4.10.1-5Florence Blanc-Renaud - 4.10.1-4Alexander Bokovoy - 4.10.1-3Florence Blanc-Renaud - 4.10.1-2Florence Blanc-Renaud - 4.10.1-1Rafael Jeffman - 4.10.0-7- Resolves: RHEL-54546 Covscan issues: Resource Leak - Resolves: RHEL-49602 misleading warning for missing ipa-selinux-nfast package on luna hsm h/w - Resolves: RHEL-40359 With unreachable AD, ipa trust returns an internal error- Resolves: RHEL-53500 adtrustinstance only prints issues in check_inst() and does not log them - Resolves: RHEL-52306 Unconditionally add MS-PAC to global config - Resolves: RHEL-52300 RFE - Keep the configured value for the "nsslapd-ignore-time-skew" after a "force-sync" - Resolves: RHEL-52222 ipa-replica/server-install with softhsm needs to check permission/ownership of /var/lib/softhsm/tokens to avoid install failure - Resolves: RHEL-51944 Include latest fixes in python3-ipatests packages - Resolves: RHEL-50804 ipa-migrate -Z with invalid cert options fails with 'ValueError: option error' - Resolves: RHEL-49602 misleading warning for missing ipa-selinux-nfast package on luna hsm h/w - Resolves: RHEL-27856 'Unable to log in as uid=admin-replica.testrealm.test,ou=people,o=ipaca' during replica install- Resolves: RHEL-47292 Include latest fixes in python3-ipatests packages - Resolves: RHEL-47146 Syntax error uninstalling the selinux-luna subpackage - Resolves: RHEL-46009 ipa-migrate with -Z option fails with ValueError: option error - Resolves: RHEL-46003 ipa-migrate -V options fails to display version - Resolves: RHEL-45463 ipa-migrate stage-mode is failing with error: Modifying a mapped attribute in a managed entry is not allowed - Resolves: RHEL-40890 ipa-server-install: token_password_file read in kra.install_check after calling hsm_validator in ca.install_check - Resolves: RHEL-40661 Adjust "ipa config-mod --addattr ipaconfigstring=EnforceLDAPOTP" to allow for non OTP users in some cases- Resolves: RHEL-37285 IPA Web UI not showing replication agreement for non-admin users - Resolves: RHEL-42703 PSKC.xml issues with ipa_otptoken_import.py - Resolves: RHEL-41194 ipa-client rpm post script creates always ssh_config.orig even if nothing needs to be changed - Resolves: RHEL-39477 kdc.crt certificate not getting automatically renewed by certmonger in IPA Hidden replica - Resolves: RHEL-46559 Include latest fixes in python3-ipatests packages - Resolves: RHEL-22188 [RFE] Allow IPA SIDgen task to continue if it finds an entity that SID can't be assigned to- Resolves: RHEL-29928 CVE-2024-3183 freeipa: user can obtain a hash of the passwords of all domain users and perform offline brute force - Resolves: RHEL-29691 CVE-2024-2698 freeipa: delegation rules allow a proxy service to impersonate any user to access another target service- Related: RHEL-34809 temporarily revert a commit that depends on newer version of python-jwcrypto- Resolves: RHEL-39950 ipa-client can't be installed because of a missing dependency- Resolves: RHEL-39140 Rebase ipa to the latest 4.12 version for RHEL 9.5 - Resolves: RHEL-34757 The change for preventing deletion of the admin user caused a regression in disable - Resolves: RHEL-30553 Depend on nfsv4-client-utils or nfs-utils - Resolves: RHEL-29762 IPA sidgen fails to create SID for manually set ID for a new range [rhel-9.5.0] - Resolves: RHEL-26261 Fix replica connection check for use with AD administrator - Resolves: RHEL-18062 ipa ca-show NAME --certificate-out=file creates empty file when NAME does not exist - Resolves: RHEL-12149 traceback in ipaserver/dcerpc.py - Resolves: RHEL-4810 [RFE] FreeIPA-to-FreeIPA migration - Resolves: RHEL-4807 [RFE] Support in IPA for HSM boxes- Resolves: RHEL-33645 - Update samba to version 4.20.0- Resolves: RHEL-23377 Enforce OTP for ldap bind (in some scenarios) - Resolves: RHEL-29745 Unable to re-add broken AD trust - NT_STATUS_INVALID_PARAMETER - Resolves: RHEL-30905 Backport latest test fixes in ipa- Resolves: RHEL-28258 vault fails on non-fips client if server is in FIPS mode - Resolves: RHEL-26154 ipa: freeipa: specially crafted HTTP requests potentially lead to DoS or data exposure- Resolves: RHEL-12143 'ipa vault-add is failing with ipa: ERROR: an internal error has occurred in FIPS mode - Resolves: RHEL-25738 ipa-kdb: Cannot determine if PAC generator is available- Resolves: RHEL-25260 tier-1-upstream-dns-locations failed on RHEL8.8 gating - Resolves: RHEL-25738 ipa-kdb: Cannot determine if PAC generator is available - Resolves: RHEL-25815 Backport latest test fixes in python3-ipatests- Resolves: RHEL-23627 IPA stops working if HTTP/... service principal was created before FreeIPA 4.4.0 and never modified - Resolves: RHEL-23625 sidgen plugin does not ignore staged users - Resolves: RHEL-23621 session cookie can't be read - Resolves: RHEL-22372 Gating-DL1 test failure in test_integration/test_dns_locations.py::TestDNSLocations::()::test_ipa_ca_records - Resolves: RHEL-21809 CA less servers are failing to be added in topology segment for domain suffix - Resolves: RHEL-17996 Memory leak in IdM's KDC- Resolves: RHEL-12589 ipa: Invalid CSRF protection - Resolves: RHEL-19748 ipa hbac-test did not report that it hit an arbitrary search limit - Resolves: RHEL-21059 'DogtagCertsConfigCheck' fails, displaying the error message 'Malformed directive: ca.signing.certnickname=caSigningCert cert-pki-ca' - Resolves: RHEL-21804 ipa client 4.10.2 - Failed to obtain host TGT - Resolves: RHEL-21809 CA less servers are failing to be added in topology segment for domain suffix - Resolves: RHEL-21810 ipa-client-install --automount-location does not work - Resolves: RHEL-21811 Handle change in behavior of pki-server ca-config-show in pki 11.5.0 - Resolves: RHEL-21812 Backport latest test fixes in ipa - Resolves: RHEL-21813 krb5kdc fails to start when pkinit and otp auth type is enabled in ipa - Resolves: RHEL-21815 IPA 389ds plugins need to have better logging and tracing - Resolves: RHEL-21937 Make sure a default NetBIOS name is set if not passed in by ADTrust instance constructor- Resolves: RHEL-16985 Handle samba 4.19 changes in samba.security.dom_sid()- Resolves: RHEL-14428 healthcheck reports nsslapd-accesslog-logbuffering is set to 'off'- Resolves: RHEL-14292 Backport latest test fixes in python3-ipatests - Resolves: RHEL-15443 Server install: failure to install with externally signed CA because of timezone issue - Resolves: RHEL-15444 Minimum length parameter in pwpolicy cannot be removed with empty string - Resolves: RHEL-14842 Upstream xmlrpc tests are failing in RHEL9.4- Resolves: RHEL-11652 Rebase ipa to latest 4.11.x version for RHEL 9.4- Resolves: rhbz#2231847 RHEL 8.8 & 9.2 fails to create AD trust with STIG applied - Resolves: rhbz#2232056 Include latest test fixes in python3-ipatests- Resolves: rhbz#2229712 Delete operation protection for admin user - Resolves: rhbz#2227831 Interrupt request processing in ipadb_fill_info3() if connection to 389ds is lost - Resolves: rhbz#2227784 libipa_otp_lasttoken plugin memory leak - Resolves: rhbz#2224570 Improved error messages are needed when attempting to add a non-existing idp to a user - Resolves: rhbz#2230251 Backport latest test fixes to python3-ipatests- Resolves: rhbz#2192969 Better handling of the command line and web UI cert search and/or list features - Resolves: rhbz#2214933 Uninstalling of the IPA server is encountering a failure during the unconfiguration of the CA (Unconfiguring CA) - Resolves: rhbz#2216114 After updating the RHEL from 8.7 to 8.8, IPA services fails to start - Resolves: rhbz#2216549 Upgrade to 4.9.10-6.0.1 fails: attributes are managed by topology plugin - Resolves: rhbz#2216611 Backport latest test fixes in python3-ipatests - Resolves: rhbz#2216872 User authentication failing on OTP validation using multiple tokens, succeeds with password only- Resolves: rhbz#2196426 [Rebase] Rebase ipa to latest 4.10.x release for RHEL 9.3 - Resolves: rhbz#2192969 Better handling of the command line and web UI cert search and/or list features - Resolves: rhbz#2192625 Better catch of the IPA web UI event "IPA Error 4301:CertificateOperationError", and IPA httpd error CertificateOperationError - Resolves: rhbz#2188567 IPA client Kerberos configuration incompatible with java - Resolves: rhbz#2182683 Tolerate absence of PAC ticket signature depending of domain and servers capabilities [rhel-9] - Resolves: rhbz#2180914 Sequence processing failures for group_add using server context - Resolves: rhbz#2165880 Add RBCD support to IPA - Resolves: rhbz#2160399 get_ranges - [file ipa_sidgen_common.c, line 276]: Failed to convert LDAP entry to range struct- Resolves: rhbz#2169632 Backport latest test fixes in python3-ipatests- Resolves: rhbz#2162656 Passwordless (GSSAPI) SSH not working for subdomain - Resolves: rhbz#2166326 Removing the last DNS type for ipa-ca does not work - Resolves: rhbz#2167473 RFE - Add a warning note about possible performance impact of the Auto Member rebuild task - Resolves: rhbz#2168244 requestsearchtimelimit=0 doesn't seems to be work with ipa-acme-manage pruning command- Resolves: rhbz#2161284 'ERROR Could not remove /tmp/tmpbkw6hawo.ipabkp' can be seen prior to 'ipa-client-install' command was successful - Resolves: rhbz#2164403 ipa-trust-add with --range-type=ipa-ad-trust-posix fails while creating an ID range - Resolves: rhbz#2162677 RFE: Implement support for PKI certificate and request pruning - Resolves: rhbz#2167312 - Backport latest test fixes in python3-ipatests- Rebuild against krb5 1.20.1 ABI - Resolves: rhbz#2155425- Resolves: rhbz#2148887 MemberManager with groups fails - Resolves: rhbz#2150335 idm:client is missing dependency on krb5-pkinit- Resolves: rhbz#2141315 [Rebase] Rebase ipa to latest 4.10.x release for RHEL 9.2 - Resolves: rhbz#2094673 ipa-client-install should just use system wide CA store and do not specify TLS_CACERT in ldap.conf - Resolves: rhbz#2117167 After leapp upgrade on ipa-client ipa-server package installation failed. (`REQ_FULL_WITH_MEMBERS` returns object from wrong domain) - Resolves: rhbz#2127833 Password Policy Grace login limit allows invalid maximum value - Resolves: rhbz#2143224 [RFE] add certificate support to ipa-client instead of one time password - Resolves: rhbz#2144736 vault interoperability with older RHEL systems is broken - Resolves: rhbz#2148258 ipa-client-install does not maintain server affinity during installation - Resolves: rhbz#2148379 Add warning for empty targetattr when creating ACI with RBAC - Resolves: rhbz#2148380 OTP token sync always returns OK even with random numbers - Resolves: rhbz#2148381 Deprecated feature idnssoaserial in IdM appears when creating reverse dns zones - Resolves: rhbz#2148382 Introduction of URI records for kerberos breaks location functionality- Resolves: rhbz#2124547 Attempt to log in as "root" user with admin's password in Web UI does not properly fail - Resolves: rhbz#2137555 Attempt to log in as "root" user with admin's password in Web UI does not properly fail [rhel-9.1.0.z]freeipa-pythonfreeipa-python-compatipa-python4.12.24.12.24.12.2-1.el94.12.2-1.el94.2.914.12.24.2.91ipa-python-compatContributors.txtREADME.mdipa-python-compatCOPYING/usr/share/doc//usr/share/doc/ipa-python-compat//usr/share/licenses//usr/share/licenses/ipa-python-compat/-O2 -flto=auto -ffat-lto-objects -fexceptions -g -grecord-gcc-switches -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -fstack-protector-strong -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m32 -march=i686 -mtune=generic -msse2 -mfpmath=sse -mstackrealign -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpiozstd19i686-redhat-linux-gnudirectoryUTF-8 Unicode textASCII textutf-87370e8cb99bce974f7ad0c2865b62363174db439247dc09359a7424fada6535a7eb0329d3051377aad563a443f702ea5976ce3d9ac227ba72af8c7ae7161084e?(/hZӀ$E6 8}9kD*ޚSڲҖ[#hǧ'NTbD751.HiBN H1Jil Bks$CsuN"I騽M5 ʍ*G]b/2lӣ!,ջek*C悫Vk6] Ds@5 ̊z45Oq~:WvUr$ʴ|7wn:yyVAK;%VsrʜzIGS%oOJ;9-~A*Gjq ]座+"zvH?սEQK 'h9"Qbzށɞۊ{V.e{ijA0N,Cum6=Pض6[WҦ6Unk[bo2zTGv0,<r!]n`%u&t%[PNVKTӑv 10ur#ePj![k $<(B⍚!e U=hqgTlؐ"`VVՌ=ˢ UT,,2luPH5pȠCguYu'#6I;QrOR_p-&;}mK^wo+}E॒kƹfN[ʌG @us\bX[@'HVm~T4 ?h2d~xC%A)dbjA XzhWuq:թ%'.H&y;lq `<'Ž#AIĝu<PA MOm'jb.A 6=twr״-A,<rr:QVUN=R)"#Np)j- %!Im5[VM3TqtzWɹ;)_JJQt:%Qk4Mk8Y7_T$5-(JPPKˉ:Hrɝ+bHve]m@M_&vomT[vN qx`{2~fn^Kw6XL#g/o"? q]*u ^~D=H{;QY5`\<)k?+f6d (9mAd2Bkfƭl8et^jevqn)ʼnUҶlr)>RV xwQV @g?wPRΞ /n1 V_[ɨOOZJ?k_Ld;9%L)FA['rU^󕺿4cj}be,\n Y#xDUEァ," (7A\si4oQ|\tu1BZ1'-t)Aeo ܑKYFZgpԖx&eN%O e䱌m(oՑi\['&t5Dnж ԍ%/*\ݚZyX_ V(A$0A;u)eNlן)%nJ2!ޕsicDgı+;'?Oծ)@AIGѪwY]K I ?g[uf*mNr(UWW**g橍 ]1Yq`qsOĠႥ9\\?+gTN{?lգm s[\G}^;֍*c:z!'Q{&J D"&U>A*Sb}An&ZfPt)7x3qq:OdV#^qmUqn:'#8Đq$_c/` J fpxXF`#DDcGl``^[ *|#=)PKoZUEլrokRZg=l kHXnpH[Kgev\xpfpo,zh<ATvN} T<.Ҏb=tZt?RƯS<} +F""JoEIiJY˅  /q~K64@zGtJy7?*R!h ҁB8op**., aCި\N"4)tP 0<8Q >4{Iad DD$mpu#nŰ'C祥kY%AOlRD.Q;uu4` d` b\[0#k"\B3/0n9EӓD .KD`ȪKۓd_Ӗ9C>YI,n7 (#h`͉$މ[ NM9Ud^ 1A(٦ZQCF)dAX7@0^xRQ 7+c N찱4Cc>9o#ܽpz:%O&/ ? uOZR293bʟc{,uUzL[/.A:j\u:d}}dID*-2wC"$ \6]|Ʃ YK2L {~+/3Asc= [607;a?.}߯O˹s &Io `/5BOd*2jX3%TI*2vī L :*OȮ|0“rn2j_)b r. r86D!gpSYž;-Uc5TnG~,GRqBI#*n&T)f h8=~/)qi`8gy 1BS^A0ȗ<x+$##/֝Sg D:9y87R5pCjtL8T:tF.vGSԦcihg8F=M4RxY:Fa-QŢhX O[۰`>6P/E*畃CJh޸( ]JaJahkl$1/NǭJD:`~:WUM>Ъ!ϋ"?8 a\3{yJ ͪ,(($G's 7OtxWt@7wl$< J]aMsZQv-vaNQf>Rߘ[Y?>w%,ȩy o9sdH{4αW~OHЬXyK#y\ɫ =EǢI Mw, SY U.HlzrQ+fJo(*aV)x{o]DWϞ혖-V1R7át8^l;ҵXLCX<ϐy{qh̬Q̠h! ǵ{4엌|zѫDшC)G4@ڒ? 6EO^;ϑA[jsF9S0})17Qr,+mSe(q)6]@/=;Mfͣ8Je^n{nb$?tݧG7QI=C:OXg̓#',㊴"9TZNCHfn7r V|JH|D_h)!zsBPfR]ayl%yBqYg=@Wuccq 3.L)+Sќ^k L=J=F,M~]:XԷRfAloxebu>E>|u唯*cR43غu%>7HS[*P)WuhK. 3}=bޏ Syll)؄?xdi>a.5'"$;@82{rjUؤ,!GBꑯhc*[/:'@%"J C8 uR27lkV@Ǐ FA$&x&XV\xCyN`%wjV~å¡KiԾAwx0EVaGN7a209j*§ D;˜R7T$#%/'oSg! -4+Fq޵ kIP?b y²=!p])vɔbv2sĊ(* 'g Cal6rb3+(g>}Cdu~JE ÌGm4EZ!5j "x0$[nVJjlkJ¨J 2mRlyFEQv YϿq'~Dra5[dx+8L&hJ=1VL= UmH'ǛI=p.**X+KCw٦H2#ߠ}-%Z|o®÷\1 S6qSj#9?v#X)^,BeyKpNqEF*8`ýQXl J?^Τoׁ4`I:Ѱu]:OJ);f޵X@$O*Gx*䓱~&$z/kjBYB5 zZOGEIY2 Qj=0uӪAΤK'D0,cP`C *ٯ|QڤKyltv*ZCUVIyUB7O %kl_!ˠr̚ZZſ-ZXC}%F@`j,>)I/xա]OJ ^xQ iY 4=A+wz0+u5{rga2J?yUɓQIaߎr;% oE'qOd

TQs(i~W9Jv4TPz!lRNv*ߤ{QBڪRLJ%<Ϲa׼0`Fb4ķxk'Mj)?˨^V9щZumHg&%qG{V,Xp@k7d> W&&X ˓ezQ kpC8 wX{B8a őB6)2>wBVpY_c"ώ9 ׃ȅՏ B:B kDp^eDčWWE라 sS]pw-r;PȪqx* Z"KgR<0oxx5o=Chu0Dw"nb ˃6MjW% OX %̬d&y`$Y ͱQLüB}$b৕~xĄ )LMM/O"ݗߺ;*ԌYw'x,Fd(6%~:?:=p88dJ!zs J콘kīf\jW3\G=^F]rV ˳zPx l\ wg3|"E6Iv٩Y&=Ӗ&ekHvyHyᑊh7#9'۷bPE]71 H 3%mbm4;%\&< s83/ }=4FxE_Wb|7=!Pߐwqv&&"%a^ē %ũ9H L5>1޸Vwdd2:¢Tp.w2;rH./v'-,//`:ODwޚz[Ty;3۬cmR^z'(F/bLxN.E[AFj2/׶(Ŧ_P,⅌4喋.4XXv]Pp(|\{Kvm޿tʇ]J^ 88]I֦rA1(PXRhlL/!./nju֍&5XǸ7i5yf-2L,M qT{ <í-$iݠ#u[sUѩ[£vL`` n)BaPB2ߛp'W`fѴ!j/e^ w+Z]LQe< ^bFwI[~3C 90nм$2s6M`j 'd[\-ElI?>M;%NS**Un܀΀(g_JƨɅ:B%iu0Z 3;ն7&x`G d_[rRpj^#c$0фz#O|ʊy͇mu7ۏTZhu&[8c a wB2$/zٸA?!['հ a%0Jw?%N2kosÐ%t?C-A'AN,=+됈 bHxj,p xIH nxZ$tnDJpYN4>/ o/w}*=5 [vވk}+ Xʹ9>fD´.sC (zjAO̟ƈJz!s$ ea:u=wVgl۠-y(k(Z58^ҟn=Y1şGhKTL:G:\ѝGv([@|b9rqiǏd"B"ﰈOLH 0-f5ʿB\!dhɞ(Q z**tC}^tuCåչdJTM77{tws Bux}Bg3w4+7!r'^ۓn2wάHˬpVA~[ɫ@4Z{!%n Gyw呐Pr`yZEL;kfߙ̊i߲"_ ҍ:-7py4AIMEY -`4*BA[hf3&E}3'<jg_,13j@@t:`d"ga}ﻼ={ΝS=eu궎îزe8Pٻ͂[~(}JW|eҮ#YW~qYk^)XFWZx:chzvj~7H{WH/#~ٞ;Jw:E9CTT)ʟM#ӥsZn:kUAI-p^- 1fͦI=K~(*ӿe}טq@ڌ@-pZecQdɰL*do3Utvn:VGqt[11Wu)[#_Z[f_-#"X߹=ˌ; Z߼MRN` Jpl /H :N @![+9B*me&pBǴ,1 Η-f߶̽ z?ŮQ9E G"zRDME4;I/b"'Lx4׈4āԴ5Ɠ I4lCRcp ^4UE/Yb2@v.Gx\=},f_w[&x gѸ+ZM TClB!2(ϛ&$=4 Nvk)(}R?6*- ZwKmzX0WTɛѶhb0̶EBNKS6g($x+W7Qv0r,jynGKw}I4|ɑoK@A4n 2bgmj`PT|Sa+&4jN-IdCv^UM e>&z) ryK "Gfnlljp% {Q涊L3#K)n-ḯ=3Ocd;αFG7*3-m`q:iY:3Ihe6_ 3^H2p\MQ?ЏDzpй-]粛Ii r'g/.}A*@揭٦y Ht(l<9kU,/p9VEc.){_š (nǣ&N<5aXҔߧ\c.JXh<\}:ۻ]YUvC&i}F('[#k`b ِY4L_X1'ҟsm\<l`v,Boʊ{OQyc̈蔸IR ٕ;ϗ(3yIcqo;}- ƒE>-2;]IIZ!zj'ЮH9zF*[y^0Ϥ؇i&6?:Ղ<x-5|ic$VLlRZfoa 2'1q&c`)Ïn[m'pf Ƨb*§X* o#Pvi^_أd6KVyvgm aFl$uG_"}@u|So/FM<QFѽ^+C9)y8L0n9tuX.,ʄP? .46~gR.5%qz>,OxTTVz~Q?Tޮ\V,T k|X^M GxM_Ƞ=UxnrV8T@\ %0ލqLNgX)5:ij%J#Pu/Յڝ8hɲF 3 i *"!7ŁӥsQmNi}5Ir>_J*!1N<$dn-ImmSYXՃ!l$ެ @L;AB·2b] TVȐ80hJSqi^M}q&}I0FASudRpne@ȟbWƉnh!oS3& Rf\urHTݦ*Tڟ?|n_< vZwxV{EMBxbRua55Ws)+H/a *|ٝv`viF?~ hSF%D# lSoCݫvQHFz:6s{_,#5jdrauh>('5:1RsCy+[u~$a!BB梟U;!kڢuXMs "arߤ͘% CܚQ./F$!5R*+OM|~&/w<}h1Ȕ@Xu% }(%\aNHB8VqIDs ?p+> m"S/đTlC /Qؙ ^R0_Mtq`ekVEon[>Y#ڳܵymzJKK >Zi}0Ư48`!-G"<۠4@uߚ&y}3Zw*h[⪭ΞP-3bJ*&v;" @ la?J b ז'K^T֔Θ& 6 ƖS,V2jƸ˼uPX4)ŽP`vAwfc'%QR"40z=־o7zBc WAfR-} p!GLaEo^0[ʌ{uBi*_V0wm= ?ɲ$xvxa#9Bۺq$Lhc6tGa- ܂"AB0P*)W8lׁ;) RWӇK꽁 ;>v)ZZ!vȄHO2-f;8Yj=kTW> ]T|zwryVV>$JCr5m[_q`j[X_N@Rp9e59G{=6buȋ*Z!uL#b q2eS!0zI=@C!.%j`Hn#Y\wˠgpOxHΪҝ,RYhnDj:d;B`3MtS8G<9]z-9TUcHt0g/D贊Μ<押b̋WŽQe*qޚlB<:`{9MJ`Ss~Ŋm2I¬AJTM1,X,xTJWIiRJ&,jnVh '6Ctl?GD)4m[|C᜵[BQĂz01#.ZY 0 R#E:?16(mbIbrT{CtO"xAovIٓ} NhVǥRچ>dSN*6K]IǸP=ϼtER "tG^ xb[)ײ#&SBEd4+ ԯ9R`nOPL%=Ùe4ʍooz!cA]yuu(E)u*z\ 8T ۳Еp8_%۽yl|na^0yns$ad-9A,҅\ʧ%Օ㖚0X1GI&9WC!|ҕD-(^nGqw+1,Z}pp~DСcH`lDU~X9Љq9MͻNH=$5,Nd~{64"/`Q~6s[ˀ~3D( !{`&7oo6 B6.el.2R?].BPWgȬDK:sZ0^nhf @wUwZe ?Hf?t'"Bа+^ OtU:#a 8 et_ҲkI_v $,:J7a&mMRn[p$ś#oqz@BR'3V}mY&jIr~ iKuCkOLA_-GeY7DGM +hŚG/ X3Y ?Mۆfp5Y"vcgS&Wxҕ޷qJH:X/*=`gRy:i~פKjpP7gqp~.Dix~h,z%MK{ٙyT"+|J%2l+,'6^t[Ia5[pr cnhґiոq0Sa:[& ~\B h .S- <@PFӓF!d};7GzR @/NVcRW‹Ĺj~Bm/ª6z|TNyn},%ܙrjK?>Fn!QsIρƏ>%!7v-d_blI2]c!qZ5WINby6̹a ʼn!B;S@ԌR[EK6XXPӐFN1ݽ~m9Ž;0K;fۄ'+@Pn]64/4`R}w82ig98DC vJ bz h2]\6g Ī`lPw$И^͍Hݠx!L ʧܒrթ]8