ipa-selinux-luna-4.12.2-1.el9> M Mv ĉJ4!!%joLne)Ip-Bm5 ']g'\releng@rockylinux.org p-Bm5 ']׳'`N;7@-NlϞVu8Ԇѷ\u9 ȷ˒23+׀5!T_}5E3TQւ_J:@ˮT샌vQ MW̮ɍT+P?'=GFvl}YSqF8 ]˓+/j9Nu>^kr)a0Du6]W=NF -J'aIZ4OA#C r٘8%݄ⷰCQ>ak} mzXn/h2-H!'FU#"Sg^ZMSEBLIĿHbN 9zﭞ:)IގJO|z5)y&-iz,=X6Ue5.ҎS.s61.ۼ yjQ-@{rnuR(yAj#mc][謀U[Cw&S>ׅ҃4Sv uZ6BxZ Nץ Rf`b48da352781d6668f8e38dff0992425d7b402a37a8a5ca2174eeee3473d09850bbc3684e80099bb97d5a0eeb0e094923bea5cfdddAYYȑ AY)>>:?:d  L 9E]cj|     , ` f (89,: >7t@7|G7H7I7X7Y7\7]7^7b8!d9e9f9l9t9u9v999::D:HCipa-selinux-luna4.12.21.el9FreeIPA SELinux policy for Thales Luna HSMsCustom SELinux policy module for Thales Luna HSMsg'Zpb-67b63646-9cff-4b85-8f07-6543bd5de663-b-i686'Rocky Linux 9.5Rocky Enterprise Software FoundationGPL-3.0-or-laterRocky Linux Build System (Peridot) Unspecifiedhttp://www.freeipa.org/linuxnoarch if [ -e /etc/selinux/config ]; then . /etc/selinux/config fi _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -s ${_policytype} -X 200 -i /usr/share/selinux/packages/targeted/ipa-luna.pp.bz2 || : /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fiif [ $1 -eq 0 ]; then if [ -e /etc/selinux/config ]; then . /etc/selinux/config fi _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ $1 -eq 0 ]; then if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -X 200 -s ${_policytype} -r ipa-luna &> /dev/null || : /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi fi fi'g'sg'ȅ777deb2928033401d83a04347be54f072c21e131e318c2ddd7cfd835ab97b8d8@rootrootrootrootipa-4.12.2-1.el9.src.rpmipa-selinux-luna     /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-python-utilsrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsZstd)selinux-policyselinux-policy-baseselinux-policy-targetedselinux-policy-targeted3.0.4-14.6.0-14.0-15.4.18-138.1.45-3.el938.1.45-3.el94.16.1.3ff@fffff`S@f_fWf0@f@e@eԔ@eN@eeeie[J@eH@ed d@dr@dcc&@cc@c#@c@cWFlorence Blanc-Renaud - 4.12.2-1Florence Blanc-Renaud - 4.12.0-7Florence Blanc-Renaud - 4.12.0-6Florence Blanc-Renaud - 4.12.0-5Julien Rische - 4.12.0-4Florence Blanc-Renaud - 4.12.0-3Florence Blanc-Renaud - 4.12.0-2Florence Blanc-Renaud - 4.12.0-1Florence Blanc-Renaud - 4.11.0-11Florence Blanc-Renaud - 4.11.0-10Florence Blanc-Renaud - 4.11.0-9Florence Blanc-Renaud - 4.11.0-8Florence Blanc-Renaud - 4.11.0-72024 Florence Blanc-Renaud - 4.11.0-6Florence Blanc-Renaud - 4.11.0-5Florence Blanc-Renaud - 4.11.0-4Florence Blanc-Renaud - 4.11.0-3Florence Blanc-Renaud - 4.11.0-2Florence Blanc-Renaud - 4.11.0-1Florence Blanc-Renaud - 4.10.2-4Florence Blanc-Renaud - 4.10.2-3Florence Blanc-Renaud - 4.10.2-2Florence Blanc-Renaud - 4.10.2-1Florence Blanc-Renaud - 4.10.1-6Florence Blanc-Renaud - 4.10.1-5Florence Blanc-Renaud - 4.10.1-4Alexander Bokovoy - 4.10.1-3Florence Blanc-Renaud - 4.10.1-2Florence Blanc-Renaud - 4.10.1-1Rafael Jeffman - 4.10.0-7- Resolves: RHEL-54546 Covscan issues: Resource Leak - Resolves: RHEL-49602 misleading warning for missing ipa-selinux-nfast package on luna hsm h/w - Resolves: RHEL-40359 With unreachable AD, ipa trust returns an internal error- Resolves: RHEL-53500 adtrustinstance only prints issues in check_inst() and does not log them - Resolves: RHEL-52306 Unconditionally add MS-PAC to global config - Resolves: RHEL-52300 RFE - Keep the configured value for the "nsslapd-ignore-time-skew" after a "force-sync" - Resolves: RHEL-52222 ipa-replica/server-install with softhsm needs to check permission/ownership of /var/lib/softhsm/tokens to avoid install failure - Resolves: RHEL-51944 Include latest fixes in python3-ipatests packages - Resolves: RHEL-50804 ipa-migrate -Z with invalid cert options fails with 'ValueError: option error' - Resolves: RHEL-49602 misleading warning for missing ipa-selinux-nfast package on luna hsm h/w - Resolves: RHEL-27856 'Unable to log in as uid=admin-replica.testrealm.test,ou=people,o=ipaca' during replica install- Resolves: RHEL-47292 Include latest fixes in python3-ipatests packages - Resolves: RHEL-47146 Syntax error uninstalling the selinux-luna subpackage - Resolves: RHEL-46009 ipa-migrate with -Z option fails with ValueError: option error - Resolves: RHEL-46003 ipa-migrate -V options fails to display version - Resolves: RHEL-45463 ipa-migrate stage-mode is failing with error: Modifying a mapped attribute in a managed entry is not allowed - Resolves: RHEL-40890 ipa-server-install: token_password_file read in kra.install_check after calling hsm_validator in ca.install_check - Resolves: RHEL-40661 Adjust "ipa config-mod --addattr ipaconfigstring=EnforceLDAPOTP" to allow for non OTP users in some cases- Resolves: RHEL-37285 IPA Web UI not showing replication agreement for non-admin users - Resolves: RHEL-42703 PSKC.xml issues with ipa_otptoken_import.py - Resolves: RHEL-41194 ipa-client rpm post script creates always ssh_config.orig even if nothing needs to be changed - Resolves: RHEL-39477 kdc.crt certificate not getting automatically renewed by certmonger in IPA Hidden replica - Resolves: RHEL-46559 Include latest fixes in python3-ipatests packages - Resolves: RHEL-22188 [RFE] Allow IPA SIDgen task to continue if it finds an entity that SID can't be assigned to- Resolves: RHEL-29928 CVE-2024-3183 freeipa: user can obtain a hash of the passwords of all domain users and perform offline brute force - Resolves: RHEL-29691 CVE-2024-2698 freeipa: delegation rules allow a proxy service to impersonate any user to access another target service- Related: RHEL-34809 temporarily revert a commit that depends on newer version of python-jwcrypto- Resolves: RHEL-39950 ipa-client can't be installed because of a missing dependency- Resolves: RHEL-39140 Rebase ipa to the latest 4.12 version for RHEL 9.5 - Resolves: RHEL-34757 The change for preventing deletion of the admin user caused a regression in disable - Resolves: RHEL-30553 Depend on nfsv4-client-utils or nfs-utils - Resolves: RHEL-29762 IPA sidgen fails to create SID for manually set ID for a new range [rhel-9.5.0] - Resolves: RHEL-26261 Fix replica connection check for use with AD administrator - Resolves: RHEL-18062 ipa ca-show NAME --certificate-out=file creates empty file when NAME does not exist - Resolves: RHEL-12149 traceback in ipaserver/dcerpc.py - Resolves: RHEL-4810 [RFE] FreeIPA-to-FreeIPA migration - Resolves: RHEL-4807 [RFE] Support in IPA for HSM boxes- Resolves: RHEL-33645 - Update samba to version 4.20.0- Resolves: RHEL-23377 Enforce OTP for ldap bind (in some scenarios) - Resolves: RHEL-29745 Unable to re-add broken AD trust - NT_STATUS_INVALID_PARAMETER - Resolves: RHEL-30905 Backport latest test fixes in ipa- Resolves: RHEL-28258 vault fails on non-fips client if server is in FIPS mode - Resolves: RHEL-26154 ipa: freeipa: specially crafted HTTP requests potentially lead to DoS or data exposure- Resolves: RHEL-12143 'ipa vault-add is failing with ipa: ERROR: an internal error has occurred in FIPS mode - Resolves: RHEL-25738 ipa-kdb: Cannot determine if PAC generator is available- Resolves: RHEL-25260 tier-1-upstream-dns-locations failed on RHEL8.8 gating - Resolves: RHEL-25738 ipa-kdb: Cannot determine if PAC generator is available - Resolves: RHEL-25815 Backport latest test fixes in python3-ipatests- Resolves: RHEL-23627 IPA stops working if HTTP/... service principal was created before FreeIPA 4.4.0 and never modified - Resolves: RHEL-23625 sidgen plugin does not ignore staged users - Resolves: RHEL-23621 session cookie can't be read - Resolves: RHEL-22372 Gating-DL1 test failure in test_integration/test_dns_locations.py::TestDNSLocations::()::test_ipa_ca_records - Resolves: RHEL-21809 CA less servers are failing to be added in topology segment for domain suffix - Resolves: RHEL-17996 Memory leak in IdM's KDC- Resolves: RHEL-12589 ipa: Invalid CSRF protection - Resolves: RHEL-19748 ipa hbac-test did not report that it hit an arbitrary search limit - Resolves: RHEL-21059 'DogtagCertsConfigCheck' fails, displaying the error message 'Malformed directive: ca.signing.certnickname=caSigningCert cert-pki-ca' - Resolves: RHEL-21804 ipa client 4.10.2 - Failed to obtain host TGT - Resolves: RHEL-21809 CA less servers are failing to be added in topology segment for domain suffix - Resolves: RHEL-21810 ipa-client-install --automount-location does not work - Resolves: RHEL-21811 Handle change in behavior of pki-server ca-config-show in pki 11.5.0 - Resolves: RHEL-21812 Backport latest test fixes in ipa - Resolves: RHEL-21813 krb5kdc fails to start when pkinit and otp auth type is enabled in ipa - Resolves: RHEL-21815 IPA 389ds plugins need to have better logging and tracing - Resolves: RHEL-21937 Make sure a default NetBIOS name is set if not passed in by ADTrust instance constructor- Resolves: RHEL-16985 Handle samba 4.19 changes in samba.security.dom_sid()- Resolves: RHEL-14428 healthcheck reports nsslapd-accesslog-logbuffering is set to 'off'- Resolves: RHEL-14292 Backport latest test fixes in python3-ipatests - Resolves: RHEL-15443 Server install: failure to install with externally signed CA because of timezone issue - Resolves: RHEL-15444 Minimum length parameter in pwpolicy cannot be removed with empty string - Resolves: RHEL-14842 Upstream xmlrpc tests are failing in RHEL9.4- Resolves: RHEL-11652 Rebase ipa to latest 4.11.x version for RHEL 9.4- Resolves: rhbz#2231847 RHEL 8.8 & 9.2 fails to create AD trust with STIG applied - Resolves: rhbz#2232056 Include latest test fixes in python3-ipatests- Resolves: rhbz#2229712 Delete operation protection for admin user - Resolves: rhbz#2227831 Interrupt request processing in ipadb_fill_info3() if connection to 389ds is lost - Resolves: rhbz#2227784 libipa_otp_lasttoken plugin memory leak - Resolves: rhbz#2224570 Improved error messages are needed when attempting to add a non-existing idp to a user - Resolves: rhbz#2230251 Backport latest test fixes to python3-ipatests- Resolves: rhbz#2192969 Better handling of the command line and web UI cert search and/or list features - Resolves: rhbz#2214933 Uninstalling of the IPA server is encountering a failure during the unconfiguration of the CA (Unconfiguring CA) - Resolves: rhbz#2216114 After updating the RHEL from 8.7 to 8.8, IPA services fails to start - Resolves: rhbz#2216549 Upgrade to 4.9.10-6.0.1 fails: attributes are managed by topology plugin - Resolves: rhbz#2216611 Backport latest test fixes in python3-ipatests - Resolves: rhbz#2216872 User authentication failing on OTP validation using multiple tokens, succeeds with password only- Resolves: rhbz#2196426 [Rebase] Rebase ipa to latest 4.10.x release for RHEL 9.3 - Resolves: rhbz#2192969 Better handling of the command line and web UI cert search and/or list features - Resolves: rhbz#2192625 Better catch of the IPA web UI event "IPA Error 4301:CertificateOperationError", and IPA httpd error CertificateOperationError - Resolves: rhbz#2188567 IPA client Kerberos configuration incompatible with java - Resolves: rhbz#2182683 Tolerate absence of PAC ticket signature depending of domain and servers capabilities [rhel-9] - Resolves: rhbz#2180914 Sequence processing failures for group_add using server context - Resolves: rhbz#2165880 Add RBCD support to IPA - Resolves: rhbz#2160399 get_ranges - [file ipa_sidgen_common.c, line 276]: Failed to convert LDAP entry to range struct- Resolves: rhbz#2169632 Backport latest test fixes in python3-ipatests- Resolves: rhbz#2162656 Passwordless (GSSAPI) SSH not working for subdomain - Resolves: rhbz#2166326 Removing the last DNS type for ipa-ca does not work - Resolves: rhbz#2167473 RFE - Add a warning note about possible performance impact of the Auto Member rebuild task - Resolves: rhbz#2168244 requestsearchtimelimit=0 doesn't seems to be work with ipa-acme-manage pruning command- Resolves: rhbz#2161284 'ERROR Could not remove /tmp/tmpbkw6hawo.ipabkp' can be seen prior to 'ipa-client-install' command was successful - Resolves: rhbz#2164403 ipa-trust-add with --range-type=ipa-ad-trust-posix fails while creating an ID range - Resolves: rhbz#2162677 RFE: Implement support for PKI certificate and request pruning - Resolves: rhbz#2167312 - Backport latest test fixes in python3-ipatests- Rebuild against krb5 1.20.1 ABI - Resolves: rhbz#2155425- Resolves: rhbz#2148887 MemberManager with groups fails - Resolves: rhbz#2150335 idm:client is missing dependency on krb5-pkinit- Resolves: rhbz#2141315 [Rebase] Rebase ipa to latest 4.10.x release for RHEL 9.2 - Resolves: rhbz#2094673 ipa-client-install should just use system wide CA store and do not specify TLS_CACERT in ldap.conf - Resolves: rhbz#2117167 After leapp upgrade on ipa-client ipa-server package installation failed. (`REQ_FULL_WITH_MEMBERS` returns object from wrong domain) - Resolves: rhbz#2127833 Password Policy Grace login limit allows invalid maximum value - Resolves: rhbz#2143224 [RFE] add certificate support to ipa-client instead of one time password - Resolves: rhbz#2144736 vault interoperability with older RHEL systems is broken - Resolves: rhbz#2148258 ipa-client-install does not maintain server affinity during installation - Resolves: rhbz#2148379 Add warning for empty targetattr when creating ACI with RBAC - Resolves: rhbz#2148380 OTP token sync always returns OK even with random numbers - Resolves: rhbz#2148381 Deprecated feature idnssoaserial in IdM appears when creating reverse dns zones - Resolves: rhbz#2148382 Introduction of URI records for kerberos breaks location functionality- Resolves: rhbz#2124547 Attempt to log in as "root" user with admin's password in Web UI does not properly fail - Resolves: rhbz#2137555 Attempt to log in as "root" user with admin's password in Web UI does not properly fail [rhel-9.1.0.z]/bin/sh/bin/sh4.12.2-1.el9ipa-luna.pp.bz2ipa-luna/usr/share/selinux/packages/targeted//var/lib/selinux/targeted/active/modules/200/-O2 -flto=auto -ffat-lto-objects -fexceptions -g -grecord-gcc-switches -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -fstack-protector-strong -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m32 -march=i686 -mtune=generic -msse2 -mfpmath=sse -mstackrealign -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpiozstd19i686-redhat-linux-gnuutf-80cd351b3869ebc1eeaae7bd0e3ac164ed2c0593310ff3efad14bd319fea66c149abf3ad65b9830ba811d514f7c8f132d8ada08ae08a31e251ae670e32862a3ae? (/h2R071081a4016727c87327dd036./usr/share/selinux/packages/targeted/ipa-luna.pp.bz2BZh91AY&SYM^ Y7B>{a@8h:@B%M@=@OTѐMd 2z25A M4F44bcSCLѐ=A5JEQ4f2bQ@~JQ*22hMh i 442 Q6CL 4 hѦ6F='E< z4zbfh 4$D&j0#шhd4 z O*OĂ7J`ؐ66lz֢HΠJ%yfm T7ϝzwxDŽAw iqkiruqF5qȊ:8#<T_Tomeϼ|⾯K+yEuz~gw{ y(\QtB!Y#bBLgv !  !4؝w.c7=5!n 6o|6 s o5v(UW9+[kR#vtٷLS< T i$| #,DmS4ѵC@x0_Ъ+hY\`_5}D r,3wm ȲΜf1p2^  +>=@A s4Y|.8HvMh;4QsOTWaP3ތ,fՏ |˚v;ځ7P9Ί׫ B *h*M Tn&Tɪx\Q2 UKQ(IAS'L*ڥB w%(`ئ81sn=B,TQ,3 v(c/.Y`t2" 6h.n>O|o h ʚC*ɏʛr嶋K ύ:>Z0Xw77b!Bmْd37& m!7am6MjA׮'ˁ|Ɇ+SkI`ȋlC`҆! lCb؆6"b6" L2a d&0ɆLDDE2cʝ#+N:` R9`S!>#| @f!ώ(P}p >ǻ^ O cJPhmp(k8wSzS|3ei6+1 a>X1Xo3/FYp=k/?F5<`YX!HӸ7@q mC2 aH @evpg]x  (ZI%pb8z0~~3fx9fzv-yyeJcҺ93yq;I6:=us(sC)!qۨy} C)"݀P99 /]Fek׻w8I$$2I`I d̡ 4@`%LH }J b%(Oyz{>Gz޳33>ͣdѪs2TQǏ:spDDI8jtb4tҜ5U7Z}_*5 0`U^D%EJ(DTDg#o3_P8&j mnnc`mNz$Jis5;z{W75X*^SY9أ^^iN7p؞*n'eݶЧvb@$m)[H 3 UrݘlթJZ9UyɪI:ē Vۺ̳um$=ȪHi'[57ț8>n̎eHUf$Q)$A`fffe^2x=օZv`wmL7[m@xLrfbBdUVb@ @ ffb@1 rj̙̗{wഌI$Zay253Ls1[ ^6mz .[9dnD2̼R=:alūשwχ##wu,X,mL8$z*ٛ&rB@z#Ix0_iDJ9J3V(,_, 07P[iME΢P smmh:.WWN!aJ2Zo=a֥fRJ%(QRh%)J)%9sͳh댼q$C v#w4 5u(~qW忈ヘ%ccT5\s1Z0tpا^`I% 6X$_\B_`YS)\Oϕl$4 >t:}FL)˻~t ^tv`f@hUo6V f)Qտ }W`o:Yzyj]`I޹QX.cy:5n "#З6n:9)$crJP⒕M Sab@Rıjtݙ<[.'5Nb&3q6ZQ 3 "U3-Ty'qVnKXPχn|Y l:qKbc[wD?ԭ(@@ɀ@AxD%P%_;jąɍ)AMg .7 "@=7S$V ӡΣB`(! 6Ch|N@,RHאL%M-0JY5SL:w5b#V Hm"[3-A$sZ0 :!G=$71rfIhmL5>P*m0LJ!2C637G*Md3\CV36 rYhcPD:$Х h~PHpCpoK!(p`jq0"a-CDw0l=^6Mf,ď>`f.|Pb] x.eq!Ǖ } RM $c95EAq1= ,8"- $V9Ф"th0B9IZ PH1KP҆R hTDw ioMPҰ-;t(Ml8jϠ`.#}\"vX`ZNY8:K,~5Mܩ+|z~>R>h\wr0Aj  gWhe·ڕN`znVN% 7hg_^ړů7֛U\:icy= I.FQ^:1Թ2;k'FNR( |%Jlrt߁|1`:1(p}(R@:fxHp0Ja$ @iqԀ/ZH = h=vJN4x8K^2:AM)B @.ʜ"JD P{i7`/@td{UY#ۥ`;L]35٬n&ho}ᾏo>co̮^u:v;yTU[cyޕ ,ږHZ_}RW%9w("{wIk#ꉸy'ȴr"NyϷ3;i?#Ȟ&ML"<`iDr')m6 6`qm&5؀[ⷣšHIbLO{{T~y'ZbF')SzTyD :w^k6oOaP8vrmWq"EE8I#y~%ް{>Gޝ;ýG;ө.y _{ޝIwf#Nm{و6NXw6&d^)݊S|ݮ.bcS̭Qt2y9w]QBԣq4ξ^.8pz+9TySݘT:jr]ڇMٜZX蔇GͶa:!$FhCǽ YPb|UPy1S{$"<9D#&Ah@~G&`'HMX{{Yg'Gyn*6{XMy\ׯ6nȖٻQ%@l9U'Up)s6bsЖfgȾ'9̮8ꋣ&f-AGmwzyAp֐GX3P! -ay0PݽV 1B0o7ijlo83ѮgDɗ~ˉnmf2LW ˭okZc&LFjܬ[\49 LTS]%ȩtW>fl%TtB55&6WI.˓.beUfajĸ PDmz\ w/=2Rƺ{5(a'iqd>2B CL!Jn¤QCɅV*A9cS =$s13rț i.勔f37am=L~ru~:ӶzaN}ԩNnuc]7eqsxƻ<<+׏]*ehÁ]ō 4r2su+|6E7o!wq`@@`q^M W.m!!vb`CT)IUgǾZ]gscmI#FԕŤxE+F%hS@@0(cJq P$wd,ś|٠ gD4 # 5F f7 8S@9A $dU g*`|&a ݧu;d*ͺA  *((& f{>$ֱZԛTإmD&d3ʖe#2r1`,0Q~ݍ!,PA I&i[=_Tʨ8by @1R 1c; DK``If!CYŚYICd )-j8* „`g !'Zמ2\p J\e,lln3q,SGx/̀1( 1s:&y>`1u&L"d.ʔ:1 ,HӒ:%>0%G QDxgK< r|g]JWbأݸldBo5%*3zD7ޒB!#ePJZ06J0LD@a4Ww[Xr,ݠsC>c. 8qk E`7]Hb0C8IQ ZQ MkPةR #BpꚀm/r◑Dbq+)Ĺ1+C0ѥH\IugFXM1Д( =҅aFe@D݈@ Kx17Sǖ>IVU6 wt zw(gSyZ.MPQ$Vf#ƆR "v@ ع+㈝|?μa i$ːKi"Bf"%*« ȩL"alC  `SSTTPh\(=t ~G&x+F/c&40Up] \=cb^ŁPf/8`N@ 'at[U L5h{bդl` e2Uڏ&l 6н7հ H `/zz[uX;a%0Rɺ-Y&[m7Moj)Dtt%ׁ@(3t8nFLwVOc$CM16($̕C=s@R^9C!} 3!OlX*Sݚp5R@4@x݄}!=x)El I2 b"c.!8:a߮i$^X{B0Z1ZlY^`3vԠ뉡׌FDS$Z.)1x 81`(ŐY©AJ7zjZ*.M}x:,IjP jB$Js|ݳ3r淭26m61 -hBT4 Px0J%bX~dKՙ8wmnT82&%l@G IIB :I'v}Vx;`BMNTs& $#y@)]bY D "@`($Biz% APC,7b@Q'E,E5Ab$8 &Qؔ f9,T̀|%@ Tf"*Ձ J<@.FRIENBJrT0"+(!)! QxճLTk#5ryӮpVU&S2I,A!K(m&KZYPBz8' ,@ `m6bn20԰V4tC#R "<,GW6&QvmdI}K@G^hI08a04 `$-+4 @yI(8ƒi ԙryb7 @UfQc@͍LGT9jHhm 3B57UvBrla.Uy@ܘ?g+6.w4'C\uo ;=9 id %"0 !;P I֨R9_l$ C2HxF:(07DD 0# Fb}ÒdJK HHJu vI,a8>]0ö :$dfd812eDTPBP?P BhAܑN$WbTRAILER!!!w(@${f Ib,)߂J9,l8D)JpbSW-ZP0PCJTbA22#pphrOLe=醡i2:fju0{5xHZ KKk 46}!6Ƭ*"`"e?bzME;t{`gCףaDA(DbcD <Cq