ipa-selinux-4.12.2-1.el9> M Mv ĉJ4!!%joLne)Ip-Bm5 ']g'\releng@rockylinux.org p-Bm5 ']>}8ݡA/ iq4cx|JzU ̓(H&4 4w&I4ss=NrQ/š+0-V-\c,#(h^P]<<5$친%mWH!u͔-{Xo [Kdwn5^no$h s.j3HM!]Eͤ( +Dc/ o^8w'^y2SkP%wOs*-B~vVuJ}l!D(ƈÅ &_<)gsOT2vuVaw4ˉJaHHgAc~o5F׿>8 SCf&S`&WP*m kQކ;j*[(x b&Z3%`!f+sŽ>eO7:zI&[bf]|\P,ȗteC C; ߒJ:7l7432b5772876609729d38d282db063a97dcc56aa8747fa7d2e5de6643b9fba42bca3ea3f9c4a46fc72dc0ac8b70cc4d0fdedcb4aiJUC-,-!C>B>A?>1d  2\` !9?FPX \ ` h  4J(89 :=9X>9`@9hG9pH9xI9X9Y9\9]9^9b:d;e;f;l;t;u;v;;======Cipa-selinux4.12.21.el9FreeIPA SELinux policyCustom SELinux policy module for FreeIPAg'Zpb-67b63646-9cff-4b85-8f07-6543bd5de663-b-i686BjRocky Linux 9.5Rocky Enterprise Software FoundationGPL-3.0-or-laterRocky Linux Build System (Peridot) Unspecifiedhttp://www.freeipa.org/linuxnoarch if /usr/sbin/selinuxenabled; then if [ -e /etc/selinux/config ]; then . /etc/selinux/config fi _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ "${SELINUXTYPE}" = "${_policytype}" ]; then [ -f /var/lib/rpm-state/file_contexts.pre ] || cp -f /etc/selinux/${SELINUXTYPE}/contexts/files/file_contexts /var/lib/rpm-state/file_contexts.pre fi fisemodule -d ipa_custodia &> /dev/null || true; if [ -e /etc/selinux/config ]; then . /etc/selinux/config fi _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -s ${_policytype} -X 200 -i /usr/share/selinux/packages/targeted/ipa.pp.bz2 || : /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fiif [ $1 -eq 0 ]; then if [ -e /etc/selinux/config ]; then . /etc/selinux/config fi _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ $1 -eq 0 ]; then if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -X 200 -s ${_policytype} -r ipa &> /dev/null || : /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi fi semodule -e ipa_custodia &> /dev/null || true; fiBjg'rg'ȅd3d5118a19f499af730fcd02e920f076cf99fb5a6490516676dfb7bf877ed007@rootrootrootrootipa-4.12.2-1.el9.src.rpmipa-selinux      /bin/sh/bin/sh/bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-python-utilsrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsZstd)selinux-policyselinux-policy-baseselinux-policy-targetedselinux-policy-targeted3.0.4-14.6.0-14.0-15.4.18-138.1.45-3.el938.1.45-3.el94.16.1.3ff@fffff`S@f_fWf0@f@e@eԔ@eN@eeeie[J@eH@ed d@dr@dcc&@cc@c#@c@cWFlorence Blanc-Renaud - 4.12.2-1Florence Blanc-Renaud - 4.12.0-7Florence Blanc-Renaud - 4.12.0-6Florence Blanc-Renaud - 4.12.0-5Julien Rische - 4.12.0-4Florence Blanc-Renaud - 4.12.0-3Florence Blanc-Renaud - 4.12.0-2Florence Blanc-Renaud - 4.12.0-1Florence Blanc-Renaud - 4.11.0-11Florence Blanc-Renaud - 4.11.0-10Florence Blanc-Renaud - 4.11.0-9Florence Blanc-Renaud - 4.11.0-8Florence Blanc-Renaud - 4.11.0-72024 Florence Blanc-Renaud - 4.11.0-6Florence Blanc-Renaud - 4.11.0-5Florence Blanc-Renaud - 4.11.0-4Florence Blanc-Renaud - 4.11.0-3Florence Blanc-Renaud - 4.11.0-2Florence Blanc-Renaud - 4.11.0-1Florence Blanc-Renaud - 4.10.2-4Florence Blanc-Renaud - 4.10.2-3Florence Blanc-Renaud - 4.10.2-2Florence Blanc-Renaud - 4.10.2-1Florence Blanc-Renaud - 4.10.1-6Florence Blanc-Renaud - 4.10.1-5Florence Blanc-Renaud - 4.10.1-4Alexander Bokovoy - 4.10.1-3Florence Blanc-Renaud - 4.10.1-2Florence Blanc-Renaud - 4.10.1-1Rafael Jeffman - 4.10.0-7- Resolves: RHEL-54546 Covscan issues: Resource Leak - Resolves: RHEL-49602 misleading warning for missing ipa-selinux-nfast package on luna hsm h/w - Resolves: RHEL-40359 With unreachable AD, ipa trust returns an internal error- Resolves: RHEL-53500 adtrustinstance only prints issues in check_inst() and does not log them - Resolves: RHEL-52306 Unconditionally add MS-PAC to global config - Resolves: RHEL-52300 RFE - Keep the configured value for the "nsslapd-ignore-time-skew" after a "force-sync" - Resolves: RHEL-52222 ipa-replica/server-install with softhsm needs to check permission/ownership of /var/lib/softhsm/tokens to avoid install failure - Resolves: RHEL-51944 Include latest fixes in python3-ipatests packages - Resolves: RHEL-50804 ipa-migrate -Z with invalid cert options fails with 'ValueError: option error' - Resolves: RHEL-49602 misleading warning for missing ipa-selinux-nfast package on luna hsm h/w - Resolves: RHEL-27856 'Unable to log in as uid=admin-replica.testrealm.test,ou=people,o=ipaca' during replica install- Resolves: RHEL-47292 Include latest fixes in python3-ipatests packages - Resolves: RHEL-47146 Syntax error uninstalling the selinux-luna subpackage - Resolves: RHEL-46009 ipa-migrate with -Z option fails with ValueError: option error - Resolves: RHEL-46003 ipa-migrate -V options fails to display version - Resolves: RHEL-45463 ipa-migrate stage-mode is failing with error: Modifying a mapped attribute in a managed entry is not allowed - Resolves: RHEL-40890 ipa-server-install: token_password_file read in kra.install_check after calling hsm_validator in ca.install_check - Resolves: RHEL-40661 Adjust "ipa config-mod --addattr ipaconfigstring=EnforceLDAPOTP" to allow for non OTP users in some cases- Resolves: RHEL-37285 IPA Web UI not showing replication agreement for non-admin users - Resolves: RHEL-42703 PSKC.xml issues with ipa_otptoken_import.py - Resolves: RHEL-41194 ipa-client rpm post script creates always ssh_config.orig even if nothing needs to be changed - Resolves: RHEL-39477 kdc.crt certificate not getting automatically renewed by certmonger in IPA Hidden replica - Resolves: RHEL-46559 Include latest fixes in python3-ipatests packages - Resolves: RHEL-22188 [RFE] Allow IPA SIDgen task to continue if it finds an entity that SID can't be assigned to- Resolves: RHEL-29928 CVE-2024-3183 freeipa: user can obtain a hash of the passwords of all domain users and perform offline brute force - Resolves: RHEL-29691 CVE-2024-2698 freeipa: delegation rules allow a proxy service to impersonate any user to access another target service- Related: RHEL-34809 temporarily revert a commit that depends on newer version of python-jwcrypto- Resolves: RHEL-39950 ipa-client can't be installed because of a missing dependency- Resolves: RHEL-39140 Rebase ipa to the latest 4.12 version for RHEL 9.5 - Resolves: RHEL-34757 The change for preventing deletion of the admin user caused a regression in disable - Resolves: RHEL-30553 Depend on nfsv4-client-utils or nfs-utils - Resolves: RHEL-29762 IPA sidgen fails to create SID for manually set ID for a new range [rhel-9.5.0] - Resolves: RHEL-26261 Fix replica connection check for use with AD administrator - Resolves: RHEL-18062 ipa ca-show NAME --certificate-out=file creates empty file when NAME does not exist - Resolves: RHEL-12149 traceback in ipaserver/dcerpc.py - Resolves: RHEL-4810 [RFE] FreeIPA-to-FreeIPA migration - Resolves: RHEL-4807 [RFE] Support in IPA for HSM boxes- Resolves: RHEL-33645 - Update samba to version 4.20.0- Resolves: RHEL-23377 Enforce OTP for ldap bind (in some scenarios) - Resolves: RHEL-29745 Unable to re-add broken AD trust - NT_STATUS_INVALID_PARAMETER - Resolves: RHEL-30905 Backport latest test fixes in ipa- Resolves: RHEL-28258 vault fails on non-fips client if server is in FIPS mode - Resolves: RHEL-26154 ipa: freeipa: specially crafted HTTP requests potentially lead to DoS or data exposure- Resolves: RHEL-12143 'ipa vault-add is failing with ipa: ERROR: an internal error has occurred in FIPS mode - Resolves: RHEL-25738 ipa-kdb: Cannot determine if PAC generator is available- Resolves: RHEL-25260 tier-1-upstream-dns-locations failed on RHEL8.8 gating - Resolves: RHEL-25738 ipa-kdb: Cannot determine if PAC generator is available - Resolves: RHEL-25815 Backport latest test fixes in python3-ipatests- Resolves: RHEL-23627 IPA stops working if HTTP/... service principal was created before FreeIPA 4.4.0 and never modified - Resolves: RHEL-23625 sidgen plugin does not ignore staged users - Resolves: RHEL-23621 session cookie can't be read - Resolves: RHEL-22372 Gating-DL1 test failure in test_integration/test_dns_locations.py::TestDNSLocations::()::test_ipa_ca_records - Resolves: RHEL-21809 CA less servers are failing to be added in topology segment for domain suffix - Resolves: RHEL-17996 Memory leak in IdM's KDC- Resolves: RHEL-12589 ipa: Invalid CSRF protection - Resolves: RHEL-19748 ipa hbac-test did not report that it hit an arbitrary search limit - Resolves: RHEL-21059 'DogtagCertsConfigCheck' fails, displaying the error message 'Malformed directive: ca.signing.certnickname=caSigningCert cert-pki-ca' - Resolves: RHEL-21804 ipa client 4.10.2 - Failed to obtain host TGT - Resolves: RHEL-21809 CA less servers are failing to be added in topology segment for domain suffix - Resolves: RHEL-21810 ipa-client-install --automount-location does not work - Resolves: RHEL-21811 Handle change in behavior of pki-server ca-config-show in pki 11.5.0 - Resolves: RHEL-21812 Backport latest test fixes in ipa - Resolves: RHEL-21813 krb5kdc fails to start when pkinit and otp auth type is enabled in ipa - Resolves: RHEL-21815 IPA 389ds plugins need to have better logging and tracing - Resolves: RHEL-21937 Make sure a default NetBIOS name is set if not passed in by ADTrust instance constructor- Resolves: RHEL-16985 Handle samba 4.19 changes in samba.security.dom_sid()- Resolves: RHEL-14428 healthcheck reports nsslapd-accesslog-logbuffering is set to 'off'- Resolves: RHEL-14292 Backport latest test fixes in python3-ipatests - Resolves: RHEL-15443 Server install: failure to install with externally signed CA because of timezone issue - Resolves: RHEL-15444 Minimum length parameter in pwpolicy cannot be removed with empty string - Resolves: RHEL-14842 Upstream xmlrpc tests are failing in RHEL9.4- Resolves: RHEL-11652 Rebase ipa to latest 4.11.x version for RHEL 9.4- Resolves: rhbz#2231847 RHEL 8.8 & 9.2 fails to create AD trust with STIG applied - Resolves: rhbz#2232056 Include latest test fixes in python3-ipatests- Resolves: rhbz#2229712 Delete operation protection for admin user - Resolves: rhbz#2227831 Interrupt request processing in ipadb_fill_info3() if connection to 389ds is lost - Resolves: rhbz#2227784 libipa_otp_lasttoken plugin memory leak - Resolves: rhbz#2224570 Improved error messages are needed when attempting to add a non-existing idp to a user - Resolves: rhbz#2230251 Backport latest test fixes to python3-ipatests- Resolves: rhbz#2192969 Better handling of the command line and web UI cert search and/or list features - Resolves: rhbz#2214933 Uninstalling of the IPA server is encountering a failure during the unconfiguration of the CA (Unconfiguring CA) - Resolves: rhbz#2216114 After updating the RHEL from 8.7 to 8.8, IPA services fails to start - Resolves: rhbz#2216549 Upgrade to 4.9.10-6.0.1 fails: attributes are managed by topology plugin - Resolves: rhbz#2216611 Backport latest test fixes in python3-ipatests - Resolves: rhbz#2216872 User authentication failing on OTP validation using multiple tokens, succeeds with password only- Resolves: rhbz#2196426 [Rebase] Rebase ipa to latest 4.10.x release for RHEL 9.3 - Resolves: rhbz#2192969 Better handling of the command line and web UI cert search and/or list features - Resolves: rhbz#2192625 Better catch of the IPA web UI event "IPA Error 4301:CertificateOperationError", and IPA httpd error CertificateOperationError - Resolves: rhbz#2188567 IPA client Kerberos configuration incompatible with java - Resolves: rhbz#2182683 Tolerate absence of PAC ticket signature depending of domain and servers capabilities [rhel-9] - Resolves: rhbz#2180914 Sequence processing failures for group_add using server context - Resolves: rhbz#2165880 Add RBCD support to IPA - Resolves: rhbz#2160399 get_ranges - [file ipa_sidgen_common.c, line 276]: Failed to convert LDAP entry to range struct- Resolves: rhbz#2169632 Backport latest test fixes in python3-ipatests- Resolves: rhbz#2162656 Passwordless (GSSAPI) SSH not working for subdomain - Resolves: rhbz#2166326 Removing the last DNS type for ipa-ca does not work - Resolves: rhbz#2167473 RFE - Add a warning note about possible performance impact of the Auto Member rebuild task - Resolves: rhbz#2168244 requestsearchtimelimit=0 doesn't seems to be work with ipa-acme-manage pruning command- Resolves: rhbz#2161284 'ERROR Could not remove /tmp/tmpbkw6hawo.ipabkp' can be seen prior to 'ipa-client-install' command was successful - Resolves: rhbz#2164403 ipa-trust-add with --range-type=ipa-ad-trust-posix fails while creating an ID range - Resolves: rhbz#2162677 RFE: Implement support for PKI certificate and request pruning - Resolves: rhbz#2167312 - Backport latest test fixes in python3-ipatests- Rebuild against krb5 1.20.1 ABI - Resolves: rhbz#2155425- Resolves: rhbz#2148887 MemberManager with groups fails - Resolves: rhbz#2150335 idm:client is missing dependency on krb5-pkinit- Resolves: rhbz#2141315 [Rebase] Rebase ipa to latest 4.10.x release for RHEL 9.2 - Resolves: rhbz#2094673 ipa-client-install should just use system wide CA store and do not specify TLS_CACERT in ldap.conf - Resolves: rhbz#2117167 After leapp upgrade on ipa-client ipa-server package installation failed. (`REQ_FULL_WITH_MEMBERS` returns object from wrong domain) - Resolves: rhbz#2127833 Password Policy Grace login limit allows invalid maximum value - Resolves: rhbz#2143224 [RFE] add certificate support to ipa-client instead of one time password - Resolves: rhbz#2144736 vault interoperability with older RHEL systems is broken - Resolves: rhbz#2148258 ipa-client-install does not maintain server affinity during installation - Resolves: rhbz#2148379 Add warning for empty targetattr when creating ACI with RBAC - Resolves: rhbz#2148380 OTP token sync always returns OK even with random numbers - Resolves: rhbz#2148381 Deprecated feature idnssoaserial in IdM appears when creating reverse dns zones - Resolves: rhbz#2148382 Introduction of URI records for kerberos breaks location functionality- Resolves: rhbz#2124547 Attempt to log in as "root" user with admin's password in Web UI does not properly fail - Resolves: rhbz#2137555 Attempt to log in as "root" user with admin's password in Web UI does not properly fail [rhel-9.1.0.z]/bin/sh/bin/sh/bin/sh4.12.2-1.el9ipa.pp.bz2ipa/usr/share/selinux/packages/targeted//var/lib/selinux/targeted/active/modules/200/-O2 -flto=auto -ffat-lto-objects -fexceptions -g -grecord-gcc-switches -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -fstack-protector-strong -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m32 -march=i686 -mtune=generic -msse2 -mfpmath=sse -mstackrealign -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpiozstd19i686-redhat-linux-gnu if [ -e /etc/selinux/config ]; then . /etc/selinux/config fi _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then if [ -f /var/lib/rpm-state/file_contexts.pre ]; then /usr/sbin/fixfiles -C /var/lib/rpm-state/file_contexts.pre restore &> /dev/null rm -f /var/lib/rpm-state/file_contexts.pre fi fi # with_selinux/bin/shutf-83d01105be0126ec047e23bed248e1a1fc6d779035a4171030c991000e018ace8af8ffe52adf187b5049c1c4f7239213cb4054f5a675573555a0fefbef641eaa1?(/h}071081a416727c872426a031./usr/share/selinux/packages/targeted/ipa.pp.bz2BZh91AY&SY{ ^sK;8ռ N<ֳkk251GΛ02N7q#0c7vx1+_] `|ov}ͧYN`5j׀ ܰ*v2c&!H Mb5(JJAhwNEURhh5!$ A42=&FlL=OMC'4SO44hM0 lTѠ411@ 1UB!jJE h4T ș A4CJhLOJc(bdz#54LFM h ѣh 450FL 04'UhɐcA0Md 4@Ѡ i4224ih#@`00C"Q?hMbz{J23(H5=mCM@@i=Mh ihdF=*(4L )CC&S##&A24dhd2C@ L@0A4#&}o9el%$ǑUAl $R-hS#B>Pȸ_)er.wd&ԣ/2@@1x1a[t3@L!8!*=d&L$CJOWͩXncHh7z/z0c9ֹfg- ]4^tI,e%Ajn$@hf&Lf4P3Qm 脢)"D A0p̩&uJR--+RնSJ$!:WBJ葜HPmAE(#p! l9[ʯ1FM,4:؅ؖ訸ϵ?CIbZw']FOU)+-/1k5~o_8鰝lYkli_{myMoNj9<_3Δ)*z=.S'UW+;=*rûޱ-|guwxn6m x~G'syܞB:U}[WجUwaZ<>/7/ wEjM#zJ/=Ո}R9PtmsskmWN UBX6?X(Hb#%*mHHĀ1`$F)~͛}א]ww a[v/ġh0*op!(B t WPj((E;:U?$% Hڱ֙o?ܿj Fa"!Qc2"+hex+ZnϣރNuqB}~ h8omanXߧ[xtNnZ׋|0%L (  Wy>[ A*]*jjr//rY׿vsxcw@[]n<1b>>6:?]__vn.t:; +)IK{[[&YomonavvzIDGQDE/O3:ĥ!:ufEQj1[l4FG=eU)NbH?sutNRͅ%+&T6Lb\왳jJ{Y~Sxf|$R ͪEhΑut :V _["D"즨}fJ4jT#jHFA)۷ ~eoكXbllU(Ȉgͷ ٢Ի9޻n;:t -"*UWwKMXQrо;WV/! ïk-3vzN$Ivσ7k<ݛg|-V%j@[އM e K2͈;D79 1M~Ȳ*N;K˚^~'e+޺ߞKՎ$ +͍7hRUc&Qps#:Ͽ:r^͋Iu}u(r\Yڮ;:^4DuKe|5׮.&4v?`jPDjCI$c|5]G=#ݎo~zFW OKχ5l -,a?*ofC6[@(6l6xϻ6 Kv=53no:Lӷ2h͌n^qew]nOlWrP~K;=ݔ>Mwu>w%WV\>abO_efh)Uq_&sSV5J}4SwwjNJ4أMzZ/[PA{I}TX ~YbĞFrSS/x)F_ rE2*Q!p(dp%voyo' $2N"b)QN9 2HH  .c>iVOeGD(Vn)S6q)QOrf&):m>w{7u<<.nǖgQmrhZ-Eׇuww؆q][x֏Y[杺3Ex3ϗ}ؿ3[^zʜVzZ5:`ӧZ9v-i qǟW޾ t_Ӎ}GNf޵ըMUdzm㯥i8;מC7x}gD.9_cٷ{yo-u˯ۓI먾fכ<=zڜs=Ƴ:5Ǒ~-=:ϴ4r廧=bi =`smng1]7z`zvzvm,u* xspsM쇗/N\={zۻn<<9َݼ;w=o>Fxտˎ=wmjͻ9{Q]]QBp | 3;:M5ٯu<ƣs[7uܶ)žt3T,lcI#yD/Mgk%&ȍMB狢7yUvbiD%Rֶַw;w6p*$DJ b(t7MWwv!*ĒIV^qy͕,YerXV#KI^VnmwZsQ @Uo AU*<n`F+yE~?]qYd~ Ĩ sgV+><[{{}K]N˩]NWrrsɹGGM3/~~~z.ξAî}0А+~_bX1+EEEF0k#-gj^Z^^gU#Jk)ghZQQPϴشhҕ*VZ ` @nҢ! JBk+e5Mj~/×#^l,y] hIB^ QL6Z-Y!.x-YL@^dWKuݙ9y[xt˶wy ()&<6F!"H*PyW(xE0mbY#ie\66 U$QJ  x^RRE6 <yl`1 c(nwfoc7ifb M1I&b c歒ӵi4)Ǐmbf&clHFy; @ @ e*b@1 rqbɻlD:$ZN".˶bux&0>f7Yj6NHhg9U#13v9 +Qu5%\u>ڵ7o|O`a:dk,?a?F [Ek ҸS=]iUc r YF5MƄ ]KckX0HS$2<ޤqح0ҭi4444 lRVidQZ"+) HLLDwR!U5B%2JIDpL  XTMe$42D6DB Z$(B`Ęi %J ?!$,nA?R(=H"弞ViUt-(H́5q\ݦ,peG3u q@b=KJ()^RլշwK>辳p`:`x ],B!(#H(XLAAb}x,?$zFݵDr9Uu+tք(BA@D;1N88UPA UªyW980q΀|! P%& X8@^ J( X(6 $/DF7^w\{{~+۬Dgէ›b?c*~#4Ϸ}zS^ 77?NK;=7s\k_Q<5:ݹ*i^_sS |ʺF-c٧V=4Rb->Oo[D)}=37|L< 5q1VKIF]dLrne~ڍj#Z{U;obnLrPy9ݬk9֭U뽬͝o|Mnr>5 T9'| u{N2c+qEt]g&&sͳҹ\}ڍw7 5ܽʠ.-ss䪳!vwչ [^_.扔ź*1WV[܆$n9 .k7Vm5cTdFVstS7"fE0&ȗ{[2rMȧ7[VBȞc[qb:v+ &jywJvXkZ_(0`n/V{4BiD'$LB^5#nKw/b^66 L\\..2}%1z*ҁv˿y`Eco.ld^YkנC* "aETǼh[tix}¼N|TV̘v퐛Rǀm'~k@/WFkocvmcJUA% "%@ IQO!!I"zt7! -;?xOzM <Q-mEw<^M<%0 P"18KZf`h "H 4VƑ$ S@Vg4,Y-r=?^N7'. _Юvf{GO=0˪W&jjDZHbŒlZP_R?[@kRlh-*m?鷅]gt.`Ѩ˖ϡ:5՚}dhT˲*,]#(xh;dwP[5滖iF5w#cMZu_B 1r4=|`UE$+AE)a`1#'nq% (+R.u &dQpKtlWlv%0ƋgI@Hs`@s{>K!5]# >NGյ+/%a!bOUTMLIϷ."@=PAGPr; B"pQӞiЊ*(qAE7i/R($%խDQ b$dA->؛p/ &.-0ĤE:T&b#Fl4bjZ*ŽiI,֍i&IKdpnd[5&֭z?CSZi6t?D&RԘ!eb)'y$cLFRdžYzL#*5r=>$M#r c8%#u]̀;#}}u᤮顜o]G+I'N-}/jɱ3On{uOd=|^+*G!sM"4wr7P}}a'atXb^h"03[f6/npa`jκ"xTM~/ q^}hc!taٹ=LC-{ufvmb.&{vۉ]<>gGV"E=4Y1n#W{w\5 0e-,W 03un[Np{v$V''lnbn2fs^JۭSo|ʚ>G/y'Ȥr".kWo֢5t=zmQm&`iDr7%m6 6`qm&5˜YrZH)ZLGz:y{%Y?㞨IܻN$˚!q˩<09 P8kǛtrҞDqq 83{Wodzýb5 W{ӽ:[;#Pw}ԗzqNXwF'Nm{ƣ#q|zu$uj1ޣQSU6{j̲qmZx|%4pr}zyuǪ\{b\ίMs]51ҋӋsʫIоUG 祚ޜN*.,Uha%g&m6}n:G3XƝkzxr^'I|5zQ::;bWcsj'^s}Kߤ=zC:H4M 7<-I%b7ȸ`VŚ3 hHTU^ik}wI17 Ie۹RrLh* kz-C,}&k)% ~ H=;Q-:"`tf 8XsvZ,(tږ^>'= 籰?lVZF/722E δDt@ p@ t˿j3E, $V,f4!cե)e̝ Ġ0nG f8~6]vM6]UE NujT3 [>U_mO!>3IWr>)xEvNzk6*i'3'ɇXrO[wm K"7ÌuN_0'@[  <ʢ[߾Gc;4|9\m愕yΒݪD:TP^B $n7'ޝQ7tI@$tvkÔxL;[{@BT IDE;4}5-f4{& /q9i9$n9$Av|ȵZm-L |GmU6-F>=&,f7uv+Yg[rªHCp'Lj{4GPѻA~ֈRbi94&S& Vdp3}D8O,szbMzǔN99V~ u3/46co)&}VӪ_ j{sT`rؽHGnu^>7t oіrq{t 9*X47 QBp `mء`Rψ DQ }No%Ƅ.aW2SYqf1镗l3v64AYK%URQ q]4ͫ"T40q)idM2z Ie|1,VÎ',<` I6 D,)[$ A|c ;ɱ'*ocb=;5~BH?i {!x+"Vubb1 A1+qB.'fKLs(.tR}g; ouV博||-(Y,"iN/U3%aQG^ D=}0{qj3pwԝC*>Qޡb9fkc [掕lhhc8|LDH>-D$XrZz7 c9;+\aEj]iH هM,jMr{ٳd[ 'Uv<H/\4vhc=OP7D>~ӣ@d΄GhH>cPq(]GM2/*Mj5=y }83FUh|p|7vu1ttmNMi}~}y9H6 C )MtB!yh^YcvL SW^a3q3CG'7 7&DŽp`d:[_f Lrي,ieEtj>;c֔aϷqSIst0D |nQ"5O Hzv)KFa\Ff̘zPmf_a2b3VԔ[t%%،22]caδmv[[-b]mnշ&u뮽da%7tВp#vnީQ#b 89 ۛw8`^juIgfJG@O:@hB*c=EջlMNlIgU=Mvmkmr\;P6X#ulRHxwzA܋go1Ɋb5RY ޸PD*%դg^IJ +ސV/Q XNajHۊݬTE0>\Ari#-. dkp_1fP s((m8-Z!3crw*S).ư65 7&ڞNӏ 7sY3"B5F1zc<Cd"!BF01T1"fNtXlךK')ةM|Ӣb`F:2;vj!]u'}xn%bcuWWh(Je3*[mȐr<͌,O6ǑxQf#sԢ j.-3#v::4>៉3ܲ'ڱuش