ipa-client-epn-4.12.2-1.el9_5.4> M Mv ĉJ4!!%joLne)Ip-Bm5 ']g$releng@rockylinux.org p-Bm5 ']"UfIRL? 7_:C*! jTU҇A* a/brp%%+'8:ҧe j[xQ y? @PƐ?ѹ̨i&Ց? :ec|"J;Ϻ}{ʢ<WusX Ag &G H5v"O=l:pe&F`CvPh[h2{H@:V`,drjs R$jmRѬ _Q@6ձN_hGӹyIs wr<3-Rِ-q˪(`IR!5}9A)UE4Bm ަ)b` nV])0`)]NjPH]";UC(E'B>I?>9d " [5F B   "  <  p     @     T  t( 8 9 \:C>8?8@8G8( H8\ I8 X8Y8\8 ]9 ^9 b:d<e< f<l<t<, u<` v<w=< x=p y======Cipa-client-epn4.12.21.el9_5.4Tools to configure Expiring Password Notification in IPAThis package provides a service to collect and send expiring password notifications via email (SMTP).g&pb-c7ed49a9-aa3d-4ffe-9421-af933f90aa82-b-x86-64Rocky Linux 9.5Rocky Enterprise Software FoundationGPL-3.0-or-laterRocky Linux Build System (Peridot) System Environment/Basehttp://www.freeipa.org/linuxx86_64 if [ $1 -eq 1 ] && [ -x "/usr/lib/systemd/systemd-update-helper" ]; then # Initial installation /usr/lib/systemd/systemd-update-helper install-system-units ipa-epn.service || : fi if [ $1 -eq 1 ] && [ -x "/usr/lib/systemd/systemd-update-helper" ]; then # Initial installation /usr/lib/systemd/systemd-update-helper install-system-units ipa-epn.timer || : fi if [ $1 -eq 0 ] && [ -x "/usr/lib/systemd/systemd-update-helper" ]; then # Package removal, not upgrade /usr/lib/systemd/systemd-update-helper remove-system-units ipa-epn.service || : fi if [ $1 -eq 0 ] && [ -x "/usr/lib/systemd/systemd-update-helper" ]; then # Package removal, not upgrade /usr/lib/systemd/systemd-update-helper remove-system-units ipa-epn.timer || : fi j -KTA큀A큤A큤gUf}f}g:g:g:ghf}f}ghf}f}f}06a73f15562686516c984dd9fe61689c5268ff1c5a13e69f8b347afef41b3277655a34c4f7afc8084048deb045c6ff06ae5d6eed4f3491174e890c9302733c6845b2acef21fa8b80c06c1daeedf59e02f279130efdfe5314b848cb7bd2bf5225c3281d4a12837772dd1b5d28f206ceaa7e994ea40e5811b15f14f7113d188f53e881641247f4bd3ee198464a4863ef77075e5ca0a0c7922a4058bb85f6bbe5396973ec491c6ab5421b3e5e4812d066eeae13ea7edd814467d6ef0941dca759759b55177234392b4193c554acefd31077eea460ac4497f31b48e28b001a7250fe8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903bb1a828d4e734320b57e576a3ed45c068d5422e3553e33b129e82d6ba63d52b0de4381a0e13a357440108495b56c58ed640a9f036cae73eb724404954f4a5c62rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootipa-4.12.2-1.el9_5.4.src.rpmconfig(ipa-client-epn)ipa-client-epnipa-client-epn(x86-64) @       /bin/sh/bin/sh/bin/sh/usr/bin/python3config(ipa-client-epn)ipa-clientrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsZstd)systemd-unitssystemd-unitssystemd-unitssystemd-units4.12.2-1.el9_5.44.12.2-1.el9_5.43.0.4-14.6.0-14.0-15.4.18-1246.6-3246.6-3246.6-3246.6-34.16.1.3g/@gaggG g-@ff@fffff`S@f_fWf0@f@e@eԔ@eN@eeeie[J@eH@ed d@dr@dcc&@cFlorence Blanc-Renaud - 4.12.2-1.4Florence Blanc-Renaud - 4.12.2-1.3Florence Blanc-Renaud - 4.12.2-1.2Florence Blanc-Renaud - 4.12.2-1.1Florence Blanc-Renaud - 4.12.2-1Florence Blanc-Renaud - 4.12.0-7Florence Blanc-Renaud - 4.12.0-6Florence Blanc-Renaud - 4.12.0-5Julien Rische - 4.12.0-4Florence Blanc-Renaud - 4.12.0-3Florence Blanc-Renaud - 4.12.0-2Florence Blanc-Renaud - 4.12.0-1Florence Blanc-Renaud - 4.11.0-11Florence Blanc-Renaud - 4.11.0-10Florence Blanc-Renaud - 4.11.0-9Florence Blanc-Renaud - 4.11.0-8Florence Blanc-Renaud - 4.11.0-72024 Florence Blanc-Renaud - 4.11.0-6Florence Blanc-Renaud - 4.11.0-5Florence Blanc-Renaud - 4.11.0-4Florence Blanc-Renaud - 4.11.0-3Florence Blanc-Renaud - 4.11.0-2Florence Blanc-Renaud - 4.11.0-1Florence Blanc-Renaud - 4.10.2-4Florence Blanc-Renaud - 4.10.2-3Florence Blanc-Renaud - 4.10.2-2Florence Blanc-Renaud - 4.10.2-1Florence Blanc-Renaud - 4.10.1-6Florence Blanc-Renaud - 4.10.1-5Florence Blanc-Renaud - 4.10.1-4- Resolves: RHEL-76011 kinit with external idp user is failing- Resolves: RHEL-69928 add support for python cryptography 44.0.0 - Resolves: RHEL-70258 Upgrade to ipa-server-4.12.2-1.el9 OTP-based bind to LDAP without enforceldapotp is broken - Resolves: RHEL-70482 ipa-server-upgrade fails after established trust with ad - Resolves: RHEL-67192 CVE-2024-11029 ipa: Administrative user data leaked through systemd journal- Resolves: RHEL-69294 add a tool to quickly detect and fix issues with IPA ID ranges- Resolves: RHEL-66173 Last expired OTP token would be considered as still assigned to the user- Resolves: RHEL-54546 Covscan issues: Resource Leak - Resolves: RHEL-49602 misleading warning for missing ipa-selinux-nfast package on luna hsm h/w - Resolves: RHEL-40359 With unreachable AD, ipa trust returns an internal error- Resolves: RHEL-53500 adtrustinstance only prints issues in check_inst() and does not log them - Resolves: RHEL-52306 Unconditionally add MS-PAC to global config - Resolves: RHEL-52300 RFE - Keep the configured value for the "nsslapd-ignore-time-skew" after a "force-sync" - Resolves: RHEL-52222 ipa-replica/server-install with softhsm needs to check permission/ownership of /var/lib/softhsm/tokens to avoid install failure - Resolves: RHEL-51944 Include latest fixes in python3-ipatests packages - Resolves: RHEL-50804 ipa-migrate -Z with invalid cert options fails with 'ValueError: option error' - Resolves: RHEL-49602 misleading warning for missing ipa-selinux-nfast package on luna hsm h/w - Resolves: RHEL-27856 'Unable to log in as uid=admin-replica.testrealm.test,ou=people,o=ipaca' during replica install- Resolves: RHEL-47292 Include latest fixes in python3-ipatests packages - Resolves: RHEL-47146 Syntax error uninstalling the selinux-luna subpackage - Resolves: RHEL-46009 ipa-migrate with -Z option fails with ValueError: option error - Resolves: RHEL-46003 ipa-migrate -V options fails to display version - Resolves: RHEL-45463 ipa-migrate stage-mode is failing with error: Modifying a mapped attribute in a managed entry is not allowed - Resolves: RHEL-40890 ipa-server-install: token_password_file read in kra.install_check after calling hsm_validator in ca.install_check - Resolves: RHEL-40661 Adjust "ipa config-mod --addattr ipaconfigstring=EnforceLDAPOTP" to allow for non OTP users in some cases- Resolves: RHEL-37285 IPA Web UI not showing replication agreement for non-admin users - Resolves: RHEL-42703 PSKC.xml issues with ipa_otptoken_import.py - Resolves: RHEL-41194 ipa-client rpm post script creates always ssh_config.orig even if nothing needs to be changed - Resolves: RHEL-39477 kdc.crt certificate not getting automatically renewed by certmonger in IPA Hidden replica - Resolves: RHEL-46559 Include latest fixes in python3-ipatests packages - Resolves: RHEL-22188 [RFE] Allow IPA SIDgen task to continue if it finds an entity that SID can't be assigned to- Resolves: RHEL-29928 CVE-2024-3183 freeipa: user can obtain a hash of the passwords of all domain users and perform offline brute force - Resolves: RHEL-29691 CVE-2024-2698 freeipa: delegation rules allow a proxy service to impersonate any user to access another target service- Related: RHEL-34809 temporarily revert a commit that depends on newer version of python-jwcrypto- Resolves: RHEL-39950 ipa-client can't be installed because of a missing dependency- Resolves: RHEL-39140 Rebase ipa to the latest 4.12 version for RHEL 9.5 - Resolves: RHEL-34757 The change for preventing deletion of the admin user caused a regression in disable - Resolves: RHEL-30553 Depend on nfsv4-client-utils or nfs-utils - Resolves: RHEL-29762 IPA sidgen fails to create SID for manually set ID for a new range [rhel-9.5.0] - Resolves: RHEL-26261 Fix replica connection check for use with AD administrator - Resolves: RHEL-18062 ipa ca-show NAME --certificate-out=file creates empty file when NAME does not exist - Resolves: RHEL-12149 traceback in ipaserver/dcerpc.py - Resolves: RHEL-4810 [RFE] FreeIPA-to-FreeIPA migration - Resolves: RHEL-4807 [RFE] Support in IPA for HSM boxes- Resolves: RHEL-33645 - Update samba to version 4.20.0- Resolves: RHEL-23377 Enforce OTP for ldap bind (in some scenarios) - Resolves: RHEL-29745 Unable to re-add broken AD trust - NT_STATUS_INVALID_PARAMETER - Resolves: RHEL-30905 Backport latest test fixes in ipa- Resolves: RHEL-28258 vault fails on non-fips client if server is in FIPS mode - Resolves: RHEL-26154 ipa: freeipa: specially crafted HTTP requests potentially lead to DoS or data exposure- Resolves: RHEL-12143 'ipa vault-add is failing with ipa: ERROR: an internal error has occurred in FIPS mode - Resolves: RHEL-25738 ipa-kdb: Cannot determine if PAC generator is available- Resolves: RHEL-25260 tier-1-upstream-dns-locations failed on RHEL8.8 gating - Resolves: RHEL-25738 ipa-kdb: Cannot determine if PAC generator is available - Resolves: RHEL-25815 Backport latest test fixes in python3-ipatests- Resolves: RHEL-23627 IPA stops working if HTTP/... service principal was created before FreeIPA 4.4.0 and never modified - Resolves: RHEL-23625 sidgen plugin does not ignore staged users - Resolves: RHEL-23621 session cookie can't be read - Resolves: RHEL-22372 Gating-DL1 test failure in test_integration/test_dns_locations.py::TestDNSLocations::()::test_ipa_ca_records - Resolves: RHEL-21809 CA less servers are failing to be added in topology segment for domain suffix - Resolves: RHEL-17996 Memory leak in IdM's KDC- Resolves: RHEL-12589 ipa: Invalid CSRF protection - Resolves: RHEL-19748 ipa hbac-test did not report that it hit an arbitrary search limit - Resolves: RHEL-21059 'DogtagCertsConfigCheck' fails, displaying the error message 'Malformed directive: ca.signing.certnickname=caSigningCert cert-pki-ca' - Resolves: RHEL-21804 ipa client 4.10.2 - Failed to obtain host TGT - Resolves: RHEL-21809 CA less servers are failing to be added in topology segment for domain suffix - Resolves: RHEL-21810 ipa-client-install --automount-location does not work - Resolves: RHEL-21811 Handle change in behavior of pki-server ca-config-show in pki 11.5.0 - Resolves: RHEL-21812 Backport latest test fixes in ipa - Resolves: RHEL-21813 krb5kdc fails to start when pkinit and otp auth type is enabled in ipa - Resolves: RHEL-21815 IPA 389ds plugins need to have better logging and tracing - Resolves: RHEL-21937 Make sure a default NetBIOS name is set if not passed in by ADTrust instance constructor- Resolves: RHEL-16985 Handle samba 4.19 changes in samba.security.dom_sid()- Resolves: RHEL-14428 healthcheck reports nsslapd-accesslog-logbuffering is set to 'off'- Resolves: RHEL-14292 Backport latest test fixes in python3-ipatests - Resolves: RHEL-15443 Server install: failure to install with externally signed CA because of timezone issue - Resolves: RHEL-15444 Minimum length parameter in pwpolicy cannot be removed with empty string - Resolves: RHEL-14842 Upstream xmlrpc tests are failing in RHEL9.4- Resolves: RHEL-11652 Rebase ipa to latest 4.11.x version for RHEL 9.4- Resolves: rhbz#2231847 RHEL 8.8 & 9.2 fails to create AD trust with STIG applied - Resolves: rhbz#2232056 Include latest test fixes in python3-ipatests- Resolves: rhbz#2229712 Delete operation protection for admin user - Resolves: rhbz#2227831 Interrupt request processing in ipadb_fill_info3() if connection to 389ds is lost - Resolves: rhbz#2227784 libipa_otp_lasttoken plugin memory leak - Resolves: rhbz#2224570 Improved error messages are needed when attempting to add a non-existing idp to a user - Resolves: rhbz#2230251 Backport latest test fixes to python3-ipatests- Resolves: rhbz#2192969 Better handling of the command line and web UI cert search and/or list features - Resolves: rhbz#2214933 Uninstalling of the IPA server is encountering a failure during the unconfiguration of the CA (Unconfiguring CA) - Resolves: rhbz#2216114 After updating the RHEL from 8.7 to 8.8, IPA services fails to start - Resolves: rhbz#2216549 Upgrade to 4.9.10-6.0.1 fails: attributes are managed by topology plugin - Resolves: rhbz#2216611 Backport latest test fixes in python3-ipatests - Resolves: rhbz#2216872 User authentication failing on OTP validation using multiple tokens, succeeds with password only- Resolves: rhbz#2196426 [Rebase] Rebase ipa to latest 4.10.x release for RHEL 9.3 - Resolves: rhbz#2192969 Better handling of the command line and web UI cert search and/or list features - Resolves: rhbz#2192625 Better catch of the IPA web UI event "IPA Error 4301:CertificateOperationError", and IPA httpd error CertificateOperationError - Resolves: rhbz#2188567 IPA client Kerberos configuration incompatible with java - Resolves: rhbz#2182683 Tolerate absence of PAC ticket signature depending of domain and servers capabilities [rhel-9] - Resolves: rhbz#2180914 Sequence processing failures for group_add using server context - Resolves: rhbz#2165880 Add RBCD support to IPA - Resolves: rhbz#2160399 get_ranges - [file ipa_sidgen_common.c, line 276]: Failed to convert LDAP entry to range struct- Resolves: rhbz#2169632 Backport latest test fixes in python3-ipatests- Resolves: rhbz#2162656 Passwordless (GSSAPI) SSH not working for subdomain - Resolves: rhbz#2166326 Removing the last DNS type for ipa-ca does not work - Resolves: rhbz#2167473 RFE - Add a warning note about possible performance impact of the Auto Member rebuild task - Resolves: rhbz#2168244 requestsearchtimelimit=0 doesn't seems to be work with ipa-acme-manage pruning command- Resolves: rhbz#2161284 'ERROR Could not remove /tmp/tmpbkw6hawo.ipabkp' can be seen prior to 'ipa-client-install' command was successful - Resolves: rhbz#2164403 ipa-trust-add with --range-type=ipa-ad-trust-posix fails while creating an ID range - Resolves: rhbz#2162677 RFE: Implement support for PKI certificate and request pruning - Resolves: rhbz#2167312 - Backport latest test fixes in python3-ipatests/bin/sh/bin/sh/bin/sh 4.12.2-1.el9_5.44.12.2-1.el9_5.44.12.2-1.el9_5.4 epnepn.confexpire_msg.templateipa-epn.serviceipa-epn.timeripa-epnipa-client-epnContributors.txtREADME.mdipa-client-epnCOPYINGipa-epn.1.gzepn.conf.5.gz/etc/ipa//etc/ipa/epn//usr/lib/systemd/system//usr/sbin//usr/share/doc//usr/share/doc/ipa-client-epn//usr/share/licenses//usr/share/licenses/ipa-client-epn//usr/share/man/man1//usr/share/man/man5/-O2 -flto=auto -ffat-lto-objects -fexceptions -g -grecord-gcc-switches -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -fstack-protector-strong -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -march=x86-64-v2 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpiozstd19x86_64-redhat-linux-gnudirectoryASCII textPython script, ASCII text executableUTF-8 Unicode texttroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)Rutf-8e03ddfc7f793a4becec4d005c1292e1b827cc25ebf4fcbfc984a0a78a9e96580cdb09a5374bed44cd71b50d1c83dc416ac2e68f6faa223468f3322123c79b908?(/h# A0Lk5Fܻr'rUm5)3䖍䞏qT5X:?6<"k rG%9>,p0%P#SrɛM L:}<6m]Mc_)uN.[ ̆̇aw"%, 'ڂ$\@QP`TP$\[.tT*M+MpeO580a&8(  zy]Ljm ]e 6bD' ۂ2Q^g Ib'd ,FxβF#߁S>(~EJ(HɃHY;Cl.vA&['/z^Pӈ_U p9k Bݶnܞ@ WN`?n.Ii:j X|aZu Umھg[oI .9<#)Rv eMHva-O\'xY+Zuhdۊw')Hlt ZFH _,(ۂߓӨ]R`,c6xӱڰ $ k%~yĿm"6ZM@ޙ8A&&0ނpKA~;}E\&)iOy90TCNzO+=4*zdk\c|(iZN'CI_Rj=|`VMRlbu`䵆#`j(jgE\ȥMw&Zwi{]Ð"5Y",wDι5ծS Mg TvBĠޛ_뽖/ iƀ R1>*rE1纮1T;rbTwS՝OdrvI3S$SVzR Lܑ!nOPEvQN0ww%t d9}`^M$L0`H,*$L (` (L\uD|>`zx\Npn2)&C&5  GSd%5r`*Q`htt^6p<*M% Cr9 >J jk+&2>{\VBM6iz,EgM2.LREdl<.Dv,I!CF"X;&( S@q0X.$".`ʅ-O[IA44 P=?.Z 6 .?k/aۥl~rr~w^W2a<ξ &=:̅{Ĕ=y󥒽UON;QCЊL#, o].5or 9ڷNj  ]oRk`wD^TaVMf0QƧ>(mxJ7Yi u,Y߸9έ0j4 @tn" ýapLZ}}ڻrN]IY]_ts>h0kV-EZ} V(#q}k"ڜݤnӊ4}=I)PTr5s^)u-I-yh[_I(7d_$me䵒Ž6J7εu|zݒPOD$i62 ttBG5 /o{C+ES 9`w? 8<`dHFzaKn5ukv |hO!K+ l!pSKobuk<5J>ru\&T\ ~d0**:ɩԮߔO k2drq{&~#bm%8z9eGWmof]v\N=l.R!r}#[1^$>΋ bc"]Q_L98pt{n/@@l yX̽&u #7]icVXj/f{ƌɍ~-Dk =z[Ug;qCnqO!8ʵOwx]۪bգ`-&۔D$BEAd›DseOcfiЭ ~)9Eɞ3\InBp0˦C6yX[:fy&n,ǐMN<bk}Qc#LmcG\?>_%Rger"$<,yJXDDpd+&3^N(2d?k={Q%3g%yD!iK(ݏo,+JV__LF 2 |22怜F=쬓(gzB%zf⅜` il<4҂h4<4r"L=PP%rE!m 0SSog ub֡NbJ}bC sp`2dd qh8d&ҚjfFs@ H<0QNCKah@ Sv$ kA=a#+\{eC즭,Vdj͸i-_GFrҀt:p&`lso(p*w6i@zp,.QPNJs w&j:D!nPD5Sƕ~f<Ŧ8q=L_6 ?Wf—% 3cpNr S, (D%"mq0c8ĭ5W qQ( wNŚjH',E)?av TP:L*CӮb|u ]3U6Ho7Pac(9@<6XXhOe6q@E~;"|-e F/^!@0\8˓.>ZHQ3Ҟ빣=,7 4 >GAu™,b34m[k6M*/@`to*7m`۴(q ۺ㝨ā +qa^+LOob{K=Gz/l"k }֝o&P~HDtT#kR ĥ#Mt~cUSGLAc(E[bϱKCׄ4 o:n(K 8DDn1l4X=\6"Y.ׅഡ@u<{TC,^Ojg˂cQz_\c i G2MŽZUhgD{8B<ѷqp^'&f0 ^u} qg 6 OjDTNd - GQFb'6jr>T{k!%P3!6=_!nE4Gzmv~%4(9󪢛OY..~^}sb x&T'< cSc[ !(rIEZ1Ч$ =(c%7g(qIٺp{UvpFٻKS@UJ1 S*txq+PTg<2afW6v}"5뱨()gA|2|Mӱ=H#vȝW\d{G3sw].gGe\uӲg[ Ym͂$ jwEĚIzb+F(hC@?L 8p =K=j ,Ifd',இ 8 ' ߀+8F' v֫򚆐/N]#ȫ3j"1dSL zgE_Ei29D:2 +i\\ț$~&'KohO5tF]"MS֋b*v\nz0c+o,AI&n^OA<}c.?tW̫R6Hs 9nx1gfăW 1%eHTu0&c PDNn-\1u3!"o<fkʖ,&(x,NyZxQ5|xXxnor-4+|׋As`N Mjqyv6e[GƖP>&V4xnf "E@20wzN11D|/6lZuZ]G'8ھŦ+Us%ݼV"הΘ&/9F>Vѯ'ts 1ĄXssA%FGBXdvLV-%j:Ѯ,4F(gn>KQGܩ#(QqBB]. P[tGwč b8 5A839TGMR ;٩jxsWO(}qJI_z| GUWt[+Qq> 8o&x)g8WJ( AbL*gv4ەI.7۳^@X6t j os'Яe;=Ј2V4y\%X", rԭM0ne3/x! I>?e[PI`0te"Ex-GT5bO/,GA-Dhaa93;-pp&oҍ+7S-A%`GVT/m;pX >W,D~@bh}_Evn R*SKNneM?W3$4|;z08s|Mf9h҆"J cGr-^`/i/cWt{k+"'*[F+y#e({w?Ƣ;,8jةf;Bږ:A5[ #*d<o-(M*AsXĘ70=Qt ʂ*@' WV)7NTR+OՃօa'ZJIϫےRgk # 'P`דOtIߪ2 "JXgꅟykyT_ʊ[~::kݻj/Sbr8xU jY @2(|Ks6CMʴgrwxd_`@UPfм|=)r\_2 dDZ AC/xE~%;ydT]1Kw\``G7`_+J&,(.Z e*Ή]yktHsг^ANUw;vrZ>V`(;qIӧ A~UصyhyEc qt)$aׁQJ0w0w.l yGF&az Zt;ky@5j=U_͈􊯋k؊xS"~'|\>Ψˑ)s6VYIa`Q̝@sJ$ϔQr0p`UiU*ӕQ Bw l?yL 4 0װdTgY-З Ng16%(^Yud.uVJ&+'q%vR*jв:K >2ٜ£4_a@5`—R #2") Gћv\NZ_ ./9&mrp*G &*O,]yϫ5t;L"W1!`"}#G(:@B)\ rNrt}bYMi6ɿҠ6)NˆԚagiH_^md/n~{Jj9U>+t%|KЂbYݰ# %v?` /w0n̍WCGyi1yZnF$SQFrq#iNEFgd>AO3 j oU>WG3Ob⩷SۏWL|zQ[6!M(2O+PPlXdU@h57 @( @ZRPlpy͹P#;Rad*"@tv#8eerFMA#=}0g{;E*.d{db-P})#vnL_ ֊.jxГ7FT7'C o]zd./G(!p?@4 TqxxDd@Tj<6ӲMPv';9hC'Nc@iaR]fMY$+^kmx7ͣ8uu/DA+m5/K\,;P%"E^sru]7%ck"Gd,61e!sNE_&kq[QTC:{aڲ`b^ujb| 7>[eۮ<$z`^1Q. 2eB;@I?K5촤X;)k1|ɜnd]S$2JEY2eש$jv߻TDP" YCk&A֚tC0@Ppd2‚LR6UFPX澔@O77l BH+t$ex6}4XٽosM5$vQG[e>j:lC9pG10kR$h3azloǃ`,+_ҩ \=$ r ɛrOveFҿjʞ)zS(ZAO-k9&ݛ$~2-Lp  IU9[ҝjJh.;6noHb[lJ0њqa? .bxfjC%2$q\0\˕1zZ%gk6R9; %վqq*IPC ;,DCZ#IGV!MXm<@qeA^]S[SeU|苲Ng𸥊bKq "Ň?2 I" xhN4)9DƆ6d[\zTck3L嚁f/%`VoXӅ5I?RxȭMLRHIK6Z|oOjk+  Oj`9LWvbߢ xAA0NllC` dvXBUG|Onaҙ+6g((E[DI4ɒ\*Em}6KH+l=ieDu7,bj$ $ua>gIVP Î@H8#Jd1л&p->LEOܼ_5?Ct5S&6BBclٖ (ZIYTb1㬦S5ERNz>E⧕]<( #_bJ]7K1et51#ѼȼXɽC%?gH Y knuPH!<5Zh߱+2t~>72g@0(V*7F[Xp^2z$ҤuHaQW%PP+t#KŪB<P,ӆ@ 5DEʨP6Yp=`5= q=eQU{63r2,& .vچrP4.Oja1j)S*|&,rjÌXI6?噙Bmk%F6Txc_rLUft@/ɢ`ݥ;Cxi,tWV&ӔD%͝}neyhxTQz.Eyv燴 & )?z!h1#r{ӵ5߾&pfXߘϗWF l[M˕A/2=ף^N#9F_?]TcSaYJŠ܊B5'Q-H=6!)+\7 0S&%8LV H]LoΆO2lٱ9!ٙ/OIq$~!"MH+a)L#``}kUꈏ'6Q,Nb%W] JHŸuwx+]51;Eōw#& 5 TȠLZtV(m,ao buw© qC P-`,(h^L@YIxz#a>̷5 (_96]Aa`!RcW0Cl"9}mRQ- 21ú]wKHɯbzĭ_ iN cX,%2<'9>Z `h辡l4MH(D1a,9'EMBR!&) ERD?K\jI.on*I";0@dz[&Vb{QE4e׃x?cĻ$$R'aNWS[dtz/ۇ,]|}N]C5YL/W8zBǸR6bT0D$IR(,vnuKRMV20飔33c2ż_mt%1)pmׯ-/+O1ˆ Amՙ7Ȱ-3?CLÈ6!\#N RW gfL^RHkt<-=ٓ"&2}Ǫ0BJ~۟-l(NH|ʼ6>w(T'0>)S&jv@HDE[l(c/I˝6'Y@/Q ,}6԰s!#MUI5sayDj%Z/ vB'9:QH/҂`}`msMDr n  .Sᕸ4T!(WĮ:О ~(&0V)ֆCd[]PmE^<:w28,ZN ~omp=&k3ݧ[\ai%qv-BE" W_T:G? ֣f0::O `y!`$lelPz]֭@}W+`'J9O:qKb^p`-УkJbg<,O _Qt2#[I*3Y.u/1] 0᠉ROi ?16F{㚿b`TIA&%6A`kto7,ѣgMK S"T@֥ڧ lHUe(.aK$S~8p s¨?~q>[;vxX$]ZWy~Sf ck΍=U uu,珁,!ym(M?P/Aɪ2)S.$bfr8Mueu pdg{JQWs@#I]0RuZQhYUBj#!4~}9m ZQ%LZt,jz8T+=T=#^S?rM!b pgW6с9'pW]Ustz0; u€> 6kwBw#jR7 =:WWb#v.ef+2Σ)<0,W cOjf(1@0RFj6W5̵ojԽm8tٕ;?z91DHCK+ 4#$4cDM,e WI"^§CvCڄ ҼD ]đFʑ/Eʵ/lZ+91]Ad}Hyoίz 9!۠%\}"*mG)vˮRQiJy7 cO⑉۪.+HmLa"D!@kEMN $uo"K.mH$ ֘C87e]yspyR4I  )- d6H$%2I4A49<1&d?;ӬL6idV$>d4t,ORcxP@}~"*!z M+AwuHQ ӿh`ZCq3$:HhbA2ˬ9 Կ`lOT00#yER.c<+PB,AtBVcq@9y 5%;ݍHj85X4>& WH[+] zCګbFk%p9׿f^|/dۨS6R)X2SFyF9qNF li[̡)jrsݹ`Q>ZcOH1(^&ͤO5m+"2n5mܼ&MlRvȺnJH DS), IFCHHASADVIIISdwll eawsopimbsolutecivilurATNews at bhit ettsafmsteos "cofu<'sbriefa.>o>:Alsoncronicapepl,art e:>SOLUTELY;`sw'.el;c'Typ Of mbea GUI"boxgeeoy)"F ngsaray,Lesseread,philosophy/why--lgpc54211.gzXmo8_1}hlw87uZ%a9uQe*I.3d˹ݷ Pyy2K#DNHJ!U,NG׺:zy]]B^M(`!/*K#2HIV'n'FuFK'I9yZ,'Y8B)gN|f,P=F)0i+$RIE`gk7>VHᄃr Y8ֹb8v`6AZi_>u{Nx>R¨.~y6wD^W(!NGwn⒠U81o2 ڝ61yvjoq:?Y|ds|;r2d~Dcrs3_%HfA'` q"@tw 05S 2t&dE?W}S\v[my+ QC*.}VwIP[@3HwboolZk-[" #Q(Kvoʤ :CoXy6SRI-W\1 VCGdեDp2)]|G @DM|B؊#kꝷOZ,?M *uԌ2Uf_9 䗼hC+^H%vR|<*1zGm'TȵeqvmCHVYNv51:[El!#hq,iM@/P[ol>ڿ¶]C&:a@&DnaM\0oKQ88TW !i3/` q򠍈C7MUܱ+ޱt ~T2grmr%<:U fz&Vj77whTJݴn~;Zbz/AzzDVH`Z]YHWk4r%`ODޏiTFk{$&oT/ܔ=G"iʟue@ڼjrjH1<_$ 1/jxq9<{M;Ju:?/~O!vxCW^A7tY7?βҪp_ ·W'[9,酷Wx0e^|R‰9iŇB sj+-t@":OۚUgG@I(1K/[P.o\ِ_L.GOfg4פ14-;itμ+gqeem)^oU= C);lש^2Qi8;h~@dqߧSzs.O5l{h ;/[Oq/ߍKL؉{N&MsZFxKY&1=ZZ_9 6]-:d1b35.5WkoF_q~htG "rCIijlƈJ!g虡UsJ` X gqeO#*R%eƒ,u"]j9|eJPr֬(VXjSQ-VyV< CgaRA+JK~#K[82YxcZZӬZ*H$ qF\ 6,2z@Rңc8 cg³LɌaqM;/`jJJS« ϭsZI̪|@ r>wKMh>MwA7$e#Ke Y} x~<&^bA9=͗ќfb-|!YJ/Tv!)mģDaUY RDn: ]8a`6(;Cˋvu>)ΦQ ]YDiiڤyyl7 dzIt5\3GU5 x6j~VA80/<ݎ.Upk&x$"1ZWyT.At޹ɹ*7jϖt-ۏYӛOsURq!!MaPV84Z3 X{SvH/(zO/G5FZi~d!qʣX"bGWjC D\O+-jQiԻ G+VZ 4;FCޟ"Wi+N8t3/:'H]>96r"Z"ea{h$QOi` jr`McGm7#P 0g L{XTh;`PtWi' V9K[~圇Ιټ*gk|Gh>m],`f:<;sC ~M! pޒzeH}dihOUS_i@,Ӫ&xD\1P(J#k]sihˬ]+|yVBС4R(e@@rF 7 li*ĹID1GKc= 2D˟epӐe@ae$hﭦ=0Ïat&\a&=l>mW` ZR Njoۂǰ ,{ҾO(!&#/_6 h>ҵ"ro'6'̚"b?ڢdڐS˿׫BZ3Dc*V(6^K O3t%.w~y @aIvONJ|լQSu <_ nx]5yaϛ\~^ci(V{͉g+jIiasx$4s.1vnĸyhR*sz=`VJTɦ38u(GØȍHNam4&E@]ߑ"e^źӞJN ~u4nY 3VaE1J~sY=1go7茗NQ݇킒F \xh 8w/EM(w ґ []cs2a^~ӮDU+8};:B#oQ_q7!4ćUIk‰gJ pѡ2i}$!Za!3= Ǝjwtߎ9(gvىCWlcN܎DDNaIW/ Rʑ(>ar4̎-gtAF4m^Q9-sa6FJ06s۫)D*,:7GEؾ-Ox.f _E2k/y}Ppb&1[VcKUÖŢs-Yd-Wfg%MiRZ2C-p(si-("Ey鑐K`ؒ ߕ-p[ͤ8ѻy\Gzbt730L64M &3C핣7. &9yECJ>:Mq=!rb4LXN pc_ Vձxx!lҶC@3TA樼b Uv4xF$D>QmA(xBY5B8n$UKF !-e\pM1< `@~=$T*<NU6]`$a4;` TĮt67?/m$,.L O"`3?t/4bl ޔK3 CTXHȈrӢ>"<TEx