sssd-ipa-1.13.3-60.el6>t  DH`p[*= FahLF`" 9Ӱ B L0W-mկIB:L(Sv"/78E1щmn pՉUg0+ג (:>:<Ȟ,w'vCDJ!ԐIigbhb{FP%6pGIqٛ=9Qܐyĥ6hZwΙKujsCpDKLWqy 0 3CPO'ombd;}+|2_<6[a <ؤA~(凄igi(H1_9 +;|#0tw_IU>n2; mIbpVk<#"m<cDz!{*1+Wx(HjQG̥Wu#cǑ~YB;{W+N:djɗsbہ:vaAV&p9Wy 7Vb?2l2 ]R^S6ĿƢE _/e$i1^Jl1cEi)ʊ}!QTlrvBu):uG f)U&רK$q5M[5 7)Q!xp<+OTMsPhJsxU[hBn! 7Sở{@\Vݠ*r넨Hsap/𛢾G'n7i !T,Mvy@pw|_ @S|>5?d   6  <BLh v     /RpGG G   ( 8 9:gxGHIX Y,\L]h^bOdeflCsssd-ipa1.13.360.el6The IPA back end of the SSSDProvides the IPA back end that the SSSD can utilize to fetch identity data from and authenticate against an IPA server.[)&/x86-01.bsys.centos.orgO CentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_64PKA큤A[)&[)&[)&&Vpn[)%[)%[)%7684e3cb55714e67f3d6ff7c4e6ae8227ed7395ffeb086369a808505530a33f666f3d065ae5ef18ebc6963b3dbc715809d2f85c1aa6ab62bc459c181ffee70f18ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9032eb2849613fd8f4c5db80671144b186907b06959c120911c2b3e1e6bf80e0a0db353c3eb0238c9a324e92c7c63f270a5e04da55d2f6b326ed3aba9708f35f4a3rootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.13.3-60.el6.src.rpmlibsss_ipa.so()(64bit)sssd-ipasssd-ipa(x86-64)   @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ sssd-commonsssd-krb5-commonlibipa_hbac(x86-64)bind-utilssssd-common-pacrpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)libbasicobjects.so.0()(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.5()(64bit)libipa_hbac.so.0()(64bit)libipa_hbac.so.0(IPA_HBAC_0.0.1)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr.so.0()(64bit)libndr.so.0(NDR_0.0.1)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.0()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsemanage.so.1(LIBSEMANAGE_1.0)(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rtld(GNU_HASH)rpmlib(PayloadIsXz)1.13.3-60.el61.13.3-60.el61.13.3-60.el61.13.3-60.el64.6.0-14.0-13.0.4-15.2-1sssd1.10.0-8.beta24.8.0ZH@ZH@Z2gYyX6@X6@XS@XOXJXGXF@X@X6@X6@X-X!@X!@X&X X X WWWW@W@W_@W_@WWW@W@W@W@Wi,@WYZ@WPWPV@VJVJVV@VՄ@VՄ@V@V&@V=@V=@V@V@V@VvV%@V%@V%@VVVVVpVii@V\:@VXEVV@VV@VV@VMV2 @Vf@Vf@Vf@UAUUuUn@UmUjUcUcUUUUUJ@UB@UB@U@U?v@U>$U8U.RU.RU-@U-@U-@U-@UF@UF@UUUUUU U U U@U@U@U@T9TTTTTTT@T@T~T~Tk4Tk4T$TTT@SvSvSvS%@S0S<@S<@S<@SSSSSSS/S/S;@SFS@S@S@S@S@S@Si@S@SSS!@SsZSpSNpS 4@S 4@RRRRRRfhRD!R1R%@R @R @RR|R|R|R|R|RRRRRRRRRRRRR@R@R@R@R@R@R@R@R@R@Q@Q@QQ*@Q?@QQvwQkQIQ5@Q0@Q']Q @PPPP@P@P@P-P@P@P@PDPDPDPDP[PPPPP@P@P@P@PPPPPPPP @P @P @P @P @P @Pf@PPPPP @P @P @P @P@P@P@PPPPPPPP@P@P@PpPpPpP@P@P@P@P@P@P@PP@PP@P@P@P@P@PPXPP{P{P{Pz@PqnPl(PaP`K@P#@Oĺ@O"O"OOO@OO~O@OOO@O@Ou@Ou@Oc+@O]@OYOOdON@OLOLOLOLOLO;@O5O1@ObN@NNNN@NNNj@NN$@N$@NN@N@Nx@Nm@Ng\N[@NTN?N:N:N:NNN|@M{@M{@Mߒ@M@M۝M۝M@MM@M@M3@MM>M>M@MM@M@Mx@MM=M=MwkMwkMv@MtMtMc@Mc@MbSM_MQ0@MJMGMA^@MA^@MA^@M.@M9L!L@L@L@L@LNLNL@L@LA@L@Lk@LYV@LRLI@L7@L(L_LLGKj@KK@KK@KK[K@KK~}@K]KY@KO@KKK/c@K+nK"4@KJJ@JJJkJJ@JJp9JlE@J?r@J0J,@IcIcIzI)@I)@I)@IV@IV@I@I@III@Fabiano Fidêncio - 1.13.3-60Fabiano Fidêncio - 1.13.3-59Fabiano Fidêncio - 1.13.3-58Jakub Hrozek - 1.13.3-57Lukas Slebodnik - 1.13.3-56Lukas Slebodnik - 1.13.3-55Jakub Hrozek - 1.13.3-54Jakub Hrozek - 1.13.3-53Jakub Hrozek - 1.13.3-52Jakub Hrozek - 1.13.3-51Jakub Hrozek - 1.13.3-50Jakub Hrozek - 1.13.3-49Jakub Hrozek - 1.13.3-48Jakub Hrozek - 1.13.3-47Jakub Hrozek - 1.13.3-46Jakub Hrozek - 1.13.3-45Jakub Hrozek - 1.13.3-44Jakub Hrozek - 1.13.3-43Jakub Hrozek - 1.13.3-42Jakub Hrozek - 1.13.3-41Jakub Hrozek - 1.13.3-40Jakub Hrozek - 1.13.3-39Jakub Hrozek - 1.13.3-38Jakub Hrozek - 1.13.3-37Jakub Hrozek - 1.13.3-36Jakub Hrozek - 1.13.3-35Jakub Hrozek - 1.13.3-34Jakub Hrozek - 1.13.3-33Jakub Hrozek - 1.13.3-32Jakub Hrozek - 1.13.3-31Jakub Hrozek - 1.13.3-30Jakub Hrozek - 1.13.3-29Jakub Hrozek - 1.13.3-28Jakub Hrozek - 1.13.3-27Jakub Hrozek - 1.13.3-26Jakub Hrozek - 1.13.3-25Jakub Hrozek - 1.13.3-24Jakub Hrozek - 1.13.3-23Jakub Hrozek - 1.13.3-22Jakub Hrozek - 1.13.3-21Jakub Hrozek - 1.13.3-20Jakub Hrozek - 1.13.3-19Jakub Hrozek - 1.13.3-18Jakub Hrozek - 1.13.3-17Jakub Hrozek - 1.13.3-16Jakub Hrozek - 1.13.3-15Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-13Jakub Hrozek - 1.13.3-12Jakub Hrozek - 1.13.3-11Jakub Hrozek - 1.13.3-10Jakub Hrozek - 1.13.3-9Jakub Hrozek - 1.13.3-8Jakub Hrozek - 1.13.3-7Jakub Hrozek - 1.13.3-6Jakub Hrozek - 1.13.3-5Jakub Hrozek - 1.13.3-4Jakub Hrozek - 1.13.3-3Jakub Hrozek - 1.13.3-2Jakub Hrozek - 1.13.3-1Jakub Hrozek - 1.13.2-7Jakub Hrozek - 1.13.2-6Jakub Hrozek - 1.13.2-5Jakub Hrozek - 1.13.2-4Jakub Hrozek - 1.13.2-3Jakub Hrozek - 1.13.2-2Jakub Hrozek - 1.13.2-1Jakub Hrozek - 1.13.1-1Jakub Hrozek - 1.12.4-51Jakub Hrozek - 1.12.4-50Jakub Hrozek - 1.12.4-49Jakub Hrozek - 1.12.4-48Jakub Hrozek - 1.12.4-47Jakub Hrozek - 1.12.4-46Jakub Hrozek - 1.12.4-45Jakub Hrozek - 1.12.4-44Jakub Hrozek - 1.12.4-43Jakub Hrozek - 1.12.4-42Jakub Hrozek - 1.12.4-41Jakub Hrozek - 1.12.4-40Jakub Hrozek - 1.12.4-39Jakub Hrozek - 1.12.4-38Jakub Hrozek - 1.12.4-37Jakub Hrozek - 1.12.4-36Jakub Hrozek - 1.12.4-35Jakub Hrozek - 1.12.4-34Jakub Hrozek - 1.12.4-33Jakub Hrozek - 1.12.4-32Jakub Hrozek - 1.12.4-31Jakub Hrozek - 1.12.4-30Jakub Hrozek - 1.12.4-29Jakub Hrozek - 1.12.4-28Jakub Hrozek - 1.12.4-27Jakub Hrozek - 1.12.4-26Jakub Hrozek - 1.12.4-25Jakub Hrozek - 1.12.4-24Jakub Hrozek - 1.12.4-23Jakub Hrozek - 1.12.4-22Jakub Hrozek - 1.12.4-21Jakub Hrozek - 1.12.4-20Jakub Hrozek - 1.12.4-19Jakub Hrozek - 1.12.4-18Jakub Hrozek - 1.12.4-17Jakub Hrozek - 1.12.4-16Jakub Hrozek - 1.12.4-15Jakub Hrozek - 1.12.4-14Jakub Hrozek - 1.12.4-13Jakub Hrozek - 1.12.4-12Jakub Hrozek - 1.12.4-11Jakub Hrozek - 1.12.4-10Jakub Hrozek - 1.12.4-9Jakub Hrozek - 1.12.4-8Jakub Hrozek - 1.12.4-7Jakub Hrozek - 1.12.4-6Jakub Hrozek - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Jakub Hrozek - 1.12.4-2Jakub Hrozek - 1.12.4-1Jakub Hrozek - 1.11.6-33Jakub Hrozek - 1.11.6-32Jakub Hrozek - 1.11.6-31Jakub Hrozek - 1.11.6-30Jakub Hrozek - 1.11.6-29Jakub Hrozek - 1.11.6-28Jakub Hrozek - 1.11.6-27Jakub Hrozek - 1.11.6-26Jakub Hrozek - 1.11.6-25Jakub Hrozek - 1.11.6-24Jakub Hrozek - 1.11.6-23Jakub Hrozek - 1.11.6-22Jakub Hrozek - 1.11.6-21Jakub Hrozek - 1.11.6-20Jakub Hrozek - 1.11.6-19Jakub Hrozek - 1.11.6-18Jakub Hrozek - 1.11.6-17Jakub Hrozek - 1.11.6-16Jakub Hrozek - 1.11.6-15Jakub Hrozek - 1.11.6-14Jakub Hrozek - 1.11.6-13Jakub Hrozek - 1.11.6-12Jakub Hrozek - 1.11.6-11Jakub Hrozek - 1.11.6-10Jakub Hrozek - 1.11.6-9Jakub Hrozek - 1.11.6-8Jakub Hrozek - 1.11.6-7Jakub Hrozek - 1.11.6-6Jakub Hrozek - 1.11.6-5Jakub Hrozek - 1.11.6-4Jakub Hrozek - 1.11.6-3Jakub Hrozek - 1.11.6-2Jakub Hrozek - 1.11.6-1Jakub Hrozek - 1.11.5.1-4Jakub Hrozek - 1.11.5.1-3Jakub Hrozek - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Jakub Hrozek - 1.9.2-134Jakub Hrozek - 1.9.2-133Jakub Hrozek - 1.9.2-132Jakub Hrozek - 1.9.2-131Jakub Hrozek - 1.9.2-130Jakub Hrozek - 1.9.2-129Jakub Hrozek - 1.9.2-128Jakub Hrozek - 1.9.2-127Jakub Hrozek - 1.9.2-126Jakub Hrozek - 1.9.2-125Jakub Hrozek - 1.9.2-124Jakub Hrozek - 1.9.2-123Jakub Hrozek - 1.9.2-122Jakub Hrozek - 1.9.2-121Jakub Hrozek - 1.9.2-120Jakub Hrozek - 1.9.2-119Jakub Hrozek - 1.9.2-118Jakub Hrozek - 1.9.2-117Jakub Hrozek - 1.9.2-116Jakub Hrozek - 1.9.2-115Jakub Hrozek - 1.9.2-114Jakub Hrozek - 1.9.2-113Jakub Hrozek - 1.9.2-112Jakub Hrozek - 1.9.2-111Jakub Hrozek - 1.9.2-110Jakub Hrozek - 1.9.2-109Jakub Hrozek - 1.9.2-108Jakub Hrozek - 1.9.2-107Jakub Hrozek - 1.9.2-106Jakub Hrozek - 1.9.2-105Jakub Hrozek - 1.9.2-104Jakub Hrozek - 1.9.2-103Jakub Hrozek - 1.9.2-102Jakub Hrozek - 1.9.2-101Jakub Hrozek - 1.9.2-100Jakub Hrozek - 1.9.2-99Jakub Hrozek - 1.9.2-98Jakub Hrozek - 1.9.2-97Jakub Hrozek - 1.9.2-96Jakub Hrozek - 1.9.2-95Jakub Hrozek - 1.9.2-94Jakub Hrozek - 1.9.2-93Jakub Hrozek - 1.9.2-92Jakub Hrozek - 1.9.2-91Jakub Hrozek - 1.9.2-90Jakub Hrozek - 1.9.2-89Jakub Hrozek - 1.9.2-88Jakub Hrozek - 1.9.2-87Jakub Hrozek - 1.9.2-86Jakub Hrozek - 1.9.2-85Jakub Hrozek - 1.9.2-84Jakub Hrozek - 1.9.2-83Jakub Hrozek - 1.9.2-82Jakub Hrozek - 1.9.2-81Jakub Hrozek - 1.9.2-80Jakub Hrozek - 1.9.2-79Jakub Hrozek - 1.9.2-78Jakub Hrozek - 1.9.2-77Jakub Hrozek - 1.9.2-76Jakub Hrozek - 1.9.2-75Jakub Hrozek - 1.9.2-74Jakub Hrozek - 1.9.2-73Jakub Hrozek - 1.9.2-72Jakub Hrozek - 1.9.2-71Jakub Hrozek - 1.9.2-70Jakub Hrozek - 1.9.2-69Jakub Hrozek - 1.9.2-68Jakub Hrozek - 1.9.2-67Jakub Hrozek - 1.9.2-66Jakub Hrozek - 1.9.2-65Jakub Hrozek - 1.9.2-64Jakub Hrozek - 1.9.2-63Jakub Hrozek - 1.9.2-62Jakub Hrozek - 1.9.2-61Jakub Hrozek - 1.9.2-60Jakub Hrozek - 1.9.2-59Jakub Hrozek - 1.9.2-58Jakub Hrozek - 1.9.2-57Jakub Hrozek - 1.9.2-56Jakub Hrozek - 1.9.2-55Jakub Hrozek - 1.9.2-54Jakub Hrozek - 1.9.2-53Jakub Hrozek - 1.9.2-52Jakub Hrozek - 1.9.2-51Jakub Hrozek - 1.9.2-50Jakub Hrozek - 1.9.2-49Jakub Hrozek - 1.9.2-48Jakub Hrozek - 1.9.2-47Jakub Hrozek - 1.9.2-46Jakub Hrozek - 1.9.2-45Jakub Hrozek - 1.9.2-44Jakub Hrozek - 1.9.2-43Jakub Hrozek - 1.9.2-42Jakub Hrozek - 1.9.2-41Jakub Hrozek - 1.9.2-40Jakub Hrozek - 1.9.2-39Jakub Hrozek - 1.9.2-38Jakub Hrozek - 1.9.2-37Jakub Hrozek - 1.9.2-36Jakub Hrozek - 1.9.2-35Jakub Hrozek - 1.9.2-34Jakub Hrozek - 1.9.2-33Jakub Hrozek - 1.9.2-32Jakub Hrozek - 1.9.2-31Jakub Hrozek - 1.9.2-30Jakub Hrozek - 1.9.2-29Jakub Hrozek - 1.9.2-28Jakub Hrozek - 1.9.2-27Jakub Hrozek - 1.9.2-26Jakub Hrozek - 1.9.2-25Jakub Hrozek - 1.9.2-24Jakub Hrozek - 1.9.2-23Jakub Hrozek - 1.9.2-22Jakub Hrozek - 1.9.2-21Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-19Jakub Hrozek - 1.9.2-18Jakub Hrozek - 1.9.2-17Jakub Hrozek - 1.9.2-16Jakub Hrozek - 1.9.2-15Jakub Hrozek - 1.9.2-14Jakub Hrozek - 1.9.2-13Jakub Hrozek - 1.9.2-12Jakub Hrozek - 1.9.2-11Jakub Hrozek - 1.9.2-10Jakub Hrozek - 1.9.2-9Jakub Hrozek - 1.9.2-8Jakub Hrozek - 1.9.2-7Jakub Hrozek - 1.9.2-6Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-3Jakub Hrozek - 1.9.0-2Jakub Hrozek - 1.9.0-1.rc1Jakub Hrozek - 1.8.0-33Stephen Gallagher - 1.8.0-32Stephen Gallagher - 1.8.0-31Stephen Gallagher - 1.8.0-30Stephen Gallagher - 1.8.0-29Stephen Gallagher - 1.8.0-28Stephen Gallagher - 1.8.0-27Stephen Gallagher - 1.8.0-26Stephen Gallagher - 1.8.0-25Stephen Gallagher - 1.8.0-24Stephen Gallagher - 1.8.0-23Stephen Gallagher - 1.8.0-22Stephen Gallagher - 1.8.0-21Stephen Gallagher - 1.8.0-20Stephen Gallagher - 1.8.0-18Stephen Gallagher - 1.8.0-17Stephen Gallagher - 1.8.0-15Stephen Gallagher - 1.8.0-12Stephen Gallagher - 1.8.0-11Stephen Gallagher - 1.8.0-10Stephen Gallagher - 1.8.0-9Stephen Gallagher - 1.8.0-8Stephen Gallagher - 1.8.0-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5Stephen Gallagher - 1.8.0-4.beta3Stephen Gallagher - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-2.beta2Stephen Gallagher - 1.5.1-68Stephen Gallagher - 1.5.1-67Stephen Gallagher - 1.5.1-66Stephen Gallagher - 1.5.1-65Stephen Gallagher - 1.5.1-64Stephen Gallagher - 1.5.1-63Stephen Gallagher - 1.5.1-62Stephen Gallagher - 1.5.1-61Stephen Gallagher - 1.5.1-60Stephen Gallagher - 1.5.1-59Stephen Gallagher - 1.5.1-58Stephen Gallagher - 1.5.1-57Stephen Gallagher - 1.5.1-56Stephen Gallagher - 1.5.1-55Stephen Gallagher - 1.5.1-53Stephen Gallagher - 1.5.1-52Stephen Gallagher - 1.5.1-51Stephen Gallagher - 1.5.1-50Stephen Gallagher - 1.5.1-49Stephen Gallagher - 1.5.1-48Stephen Gallagher - 1.5.1-47Stephen Gallagher - 1.5.1-46Stephen Gallagher - 1.5.1-45Stephen Gallagher - 1.5.1-44Stephen Gallagher - 1.5.1-43Stephen Gallagher - 1.5.1-42Stephen Gallagher - 1.5.1-41Stephen Gallagher - 1.5.1-40Stephen Gallagher - 1.5.1-39Stephen Gallagher - 1.5.1-38Stephen Gallagher - 1.5.1-37Stephen Gallagher - 1.5.1-36Stephen Gallagher - 1.5.1-35Stephen Gallagher - 1.5.1-34Stephen Gallagher - 1.5.1-33Stephen Gallagher - 1.5.1-32Stephen Gallagher - 1.5.1-31Stephen Gallagher - 1.5.1-30Stephen Gallagher - 1.5.1-29Stephen Gallagher - 1.5.1-28Stephen Gallagher - 1.5.1-27Stephen Gallagher - 1.5.1-26Stephen Gallagher - 1.5.1-25Stephen Gallagher - 1.5.1-24Stephen Gallagher - 1.5.1-23Stephen Gallagher - 1.5.1-21Stephen Gallagher - 1.5.1-20Stephen Gallagher - 1.5.1-17Stephen Gallagher - 1.5.1-16Stephen Gallagher - 1.5.1-15Stephen Gallagher - 1.5.1-14Stephen Gallagher - 1.5.1-13Stephen Gallagher - 1.5.1-12Stephen Gallagher - 1.5.1-11Stephen Gallagher - 1.5.1-10Stephen Gallagher - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Stephen Gallagher - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.2.1-28.4Stephen Gallagher - 1.2.1-36Stephen Gallagher - 1.2.1-35Stephen Gallagher - 1.2.1-28.3Stephen Gallagher - 1.2.1-34Stephen Gallagher - 1.2.1-28.2Stephen Gallagher - 1.2.1-33Stephen Gallagher - 1.2.1-28.1Stephen Gallagher - 1.2.1-32Stephen Gallagher - 1.2.1-29Stephen Gallagher - 1.2.1-28Stephen Gallagher - 1.2.1-27Stephen Gallagher - 1.2.1-26Stephen Gallagher - 1.2.1-23Stephen Gallagher - 1.2.1-21Stephen Gallagher - 1.2.1-20Stephen Gallagher - 1.2.1-19Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-14Stephen Gallagher - 1.2.0-13Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11.1Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Related: rhbz#1442703 - Smart Cards: Certificate in the ID View - Related: rhbz# 1401546 - Please back-port fast failover from sssd 1.14 on RHEL 7 into sssd 1.13 on RHEL 6- Resolves: rhbz#1326007 - Memory cache corruption when rsync and/or tar to copy owner and group info from LDAP - Resolves: rhbz#1442703 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1507435 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-6.10] - Resolves: rhbz#1487040 - sssd does not evaluate AD UPN suffixes which results in failed user logins- Resolves: rhbz#1421057 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1487040 - sssd does not evaluate AD UPN suffixes which results ini failed user logins - Resolves: rhbz#1487944 - ABRT crash - /usr/libexec/sssd/sssd_nss - Resolves: rhbz#1489485 - sssd is not pulling groups in a trusted domain, with the Global scope- Resolves: rhbz#1438360 - The originalMemberOf attribute disappears from the cache, causing intermittent HBAC issues- Resolves: rhbz#1404697 - SSSD does not skip GPO if no gpcFunctionalityVersion present - Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory- Resolves: rhbz#1415785 - ldap_child does not remove temporary files when it's killed with SIGTERM- Apply several more smartcard-related patches. - Related: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard- Resolves: rhbz#1400643 - sssd prevents sudo from getting data from LDAP- Resolves: rhbz#1393592 - SSH-CERT: always initialize cert_verify_opts- Revert the ding-libs requirement - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Related: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Require the matching version of ding-libs - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Fix a coverity warning - Related: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Resolves: rhbz#1324428 - [RFE] Discover forest's root SID even if subdomains_provider = none- Resolves: rhbz#1367802 - using overides causes segfault in libldb- Resolves: rhbz#1329378 - pam_sss set KRB5CCNAME with sudo logins- Resolves: rhbz#1382603 - autofs map resolution doesn't work offline- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1321884 - IPA sudo: support the externalUser attribute- Resolves: rhbz#1299994 - ssh client checks only the first certificate on a smartcard when the card has multiple certs - Resolves: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard - Resolves: rhbz#1372681 - ssh with Smartcards - skip invalid certificates- Resolves: rhbz#1329648 - Protocol error with IPA on RHEL-6 - Resolves: rhbz#1329647 - IPA view: view name not stored properly with default FreeIPA installation- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1327272 - local overrides: issues with sub-domain users and mixed case names- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Resolves: rhbz#1377782 - sssd is looking at a server in the GC of a subdomain, not the root domain.- Resolves: rhbz#1365218 - SSSD does not fail over to next GC- Resolves: rhbz#1367435 - Intermittent sssd auth failures- Resolves: rhbz#1369079 - sssd runs out of available child slots and starts queuing requests in proxy mode- Resolves: rhbz#1338619 - segmentation fault in sssd after upgrade to sssd-1.13.3-22.el6.x86_64 when upgrading cache- Resolves: rhbz#1324107 - GPO: Access denied after blocking connection to AD.- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1340927 - sssd-common requires libnfsidmap- Resolves: rhbz#1340176 - The AD keytab renewal task leaks a file descriptor- Resolves: rhbz#1335400 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1336453 - sssd_be doesn't terminate forked child process if adcli is not installed- Resolves: rhbz#1312062 - sssd does not pass LDAP rules to sudo- Resolves: rhbz#1313940 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo- Actually apply patches from previous build - Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1209600 - Getting ERROR (getpwnam() failed): Broken pipe with 1.11.6- Backport of a more minimal dependency patch to avoid changes to AD provider behaviour - Related: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1308939 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user- Require a newer selinux-policy to avoid issues when prompting for SC PIN - Related: rhbz#1299066 - smartcard login does not prompt for pin when ocsp checking is enabled (default config)- Resolves: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1259687 - sssd_nss memory usage keeps growing on sssd-1.12.4-47.el6.x86_64 (RHEL6.7) when trying to retrieve non-existing netgroups- Update sssd-ldap man page for the recent ID mapping changes - Related: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1295883 - refresh_expired_interval stops sss_cache from working- Resolves: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1298253 - Screen lock prompts for smartcard user password and not smartcard pin when logged in using smartcard pin- Resolves: rhbz#1292458 - sssd_be AD segfaults on missing A record- Resolves: rhbz#1262981 - sssd dereference processing failed : Input/output error- Resolves: rhbz#1290761 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs- Resolves: rhbz#1244957 - [RFE] SUDO: Support the IPA schema- Resolves: rhbz#1298634 - Cannot retrieve users after upgrade from 1.12 to 1.13- Resolves: rhbz#1287807 - SRV lookup for KDC servers doesn't work- Resolves: rhbz#1273802 - ad_site parameter does not work- Fix memory leak in the NFS plugin - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Resolves: rhbz#1296620 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1283898 - MAN: Clarify that subdomains always use service discovery- Rebase to 1.13.3 - Remove setuid bit from proxy_child, RHEL-6 doesn't support running SSSD as a non-privileged user - Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Don't own files as the SSSD user - Resolves: rhbz#1289482 - warning: user sssd does not exist - using root- Resolves: rhbz#1279971 - groups get deleted from the cache- The p11_child doesn't have to run privileged anymore, remove the setuid bit - Related: rhbz#1270027 - [RFE] Support for smart cards- Resolves: rhbz#1266108 - Check next certificate on smart card if first is not valid - Also enable OCSP checks- Resolves: rhbz#1285852 - sssd: [sysdb_add_user] (0x0400): Error: 17 (File exists)- Silence compilation warnings and Coverity issues - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Squash in packaging review changes by lslebodn@redhat.com- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - The rebase also resolves the following bugzillas: - Resolves: rhbz#1270029 - [RFE] Add a way to lookup users based on CAC identity certificates - Resolves: rhbz#1270027 - [RFE] Support for smart cards - Resolves: rhbz#1269422 - [FEAT] UID and GID mapping on individual clients - Resolves: rhbz#1269421 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#1265429 - If the site discovery fails, ad-site option is not taken into account. - Resolves: rhbz#1254193 - Fix for cyclic dependencies between sssd-{krb5,}-common - Resolves: rhbz#1247997 - [IPA/IdM] sudoOrder not honored as expected - Resolves: rhbz#1237142 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1232632 - Kerberos-based providers other than krb5 do not queue requests - Resolves: rhbz#1227804 - Group members are not turned into ghost entries when the user is purged from the SSSD cache - Resolves: rhbz#1227685 - sssd with ldap backend throws error domain log - Resolves: rhbz#1221365 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1196204 - sssd cache holding gid values for nss, but not the alpha group name representation - Resolves: rhbz#1194039 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD- Resolves: rhbz#1266404 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1264524 - SSSD POSIX attribute check is too strict- Resolves: rhbz#1255285 - cleanup_groups should sanitize dn of groups- Resolves: rhbz#1251349 - sysdb sudo search doesn't escape special characters- Resolves: rhbz#1232738 - Cache is not updated after user is deleted from ldap server- Resolves: rhbz#1227860 - Provide a way to disable the cleanup task - Resolves: rhbz#1227863 - ignore_group_members doesn't work for subdomains- Resolves: rhbz#1226834 - id lookup for non-root domain users doesn't return all groups on first attempt- Resolves: rhbz#1225614 - IPA enumeration provider crashes- Resolves: rhbz#1212610 - sssd ad groups work intermittently- Resolves: rhbz#1215765 - sssd nss responder gets wrong number of secondary groups- Resolves: rhbz#1221358 - SSSD doesn't work with ID mapping and disabled subdomains- Resolves: rhbz#1219844 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust- Resolves: rhbz#1216094 - /usr/libexec/sssd/selinux_child crashes and gets avc denial when ssh- Include several upstream fixes related to ID views - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1213947 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1217328 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set- Resolves: rhbz#1212387 - sssd_be segfault id_provider = ad src/providers/ad/ad_gpo.c:843- Resolves: rhbz#1213940 - Overridde with --login fails trusted adusers group membership resolution- Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used- Resolves: rhbz#1213716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1212017 - Sudo responder does not respect filter_users and filter_groups- Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only- Related: rhbz#1211728 - Only set the selinux context if the context differs from the local one- Package the localauth plugin - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1207720 - id lookup resolves "Domain Local" group and errors appear in domain log- BuildRequire the proper libkrb5 version for correct localauth plugin build - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1194367 - sssd_be dumping core- Resolves: rhbz#1206121 - ldap_access_order=ppolicy: Explicitly mention in manpage that unsupported time specification will lead to sssd denying access- Resolves: rhbz#1205382 - Properly handle AD's binary objectGUID- Resolves: rhbz#1205716 - Installing sssd-common-1.12.4-18.el6 might install with wrong user account (root)- Fix a typo in DEBUG message - Related: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Handle TTL=0 in SRV queries correctly - Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Cherry-pick unit test changes from upstream to allow cherry-picking sssd-1-12 patches - Remove unused LDAP provider code to avoid static analyser warnings - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1206092 - sssd crashes intermittently in GPO code- Resolves: rhbz#1202728 - sssd-ad requires samba3, but ipa-server-trust-ad requires samba4- Resolves: rhbz#1203630 - SSSD doesn't own the GPO cache directory- Fix warning in SELinux code - Handle setups with empty default and no SELinux maps - Related: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u - Resolves: rhbz#1202305 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605 - Resolves: rhbz#1201847 - SSSD downloads too much information when fetching information about groups- Fix PAM responder initgroups cache for subdomain users - Log extop failures better - Related: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Fix internal error codes broken when fixing rhbz#1036745 - Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Resolves: rhbz#1200093 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything- Fix Coverity warning in ldap_child - Add better debugging - Related: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1098147 - [RFE] Implement background refresh for users, groups or other cache objects- Resolves: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Initialize a pointer in ldap_child to NULL - Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Relax the ldb requirement - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query - Rebuild against latest krb5, add a versioned BuildRequires - Resolves: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Do not mark the selinux_child helper as setuid, we don't support rootless SSSD in 6.7 - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1168347 - Rebase sssd to 1.12.x - The rebase resolves the following RHEL bugzillas - Resolves: rhbz#1172865 - sssd.conf(5) man page gives bad advice about domains parameter - Resolves: rhbz#1172494 - PAC: krb5_pac_verify failures should not be fatal (backport fix from upstream) - Resolves: rhbz#1171782 - [RFE]: SSSD should preserve case for user uid field - Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1168377 - [RFE] User's home directories and shells are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1168363 - [RFE] Add domains= option to pam_sss - Resolves: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution - Resolves: rhbz#1161564 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1148582 - inconsistent group information when multiple ad domain sections are configured in sssd - Resolves: rhbz#1140909 - sssd.conf man page missing subdomains_provider ad support - Resolves: rhbz#1139878 - SSSD connection terminated after failing anonymous bind to IBM Tivoli Directory Server - Resolves: rhbz#1135838 - Man sssd-ldap shows parameter ldap_purge_cache_timeout with "Default: 10800 (12 hours)" - Resolves: rhbz#1135432 - Dereference code errors out when dereferencing entries protected by ACIs - Resolves: rhbz#1134942 - sssd does not recognize Windows server 2012 R2's LDAP as AD - Resolves: rhbz#1123291 - automount segfaults in sss_nss_check_header - Resolves: rhbz#1088402 - [RFE] Allow login through SSSD using multiple attributes- Resolves: rhbz#1154042 - RHEL6.6 sssd (1.11) doesn't return all group memberships against an IPA server- Resolves: rhbz#1160713 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1141814 - Password expiration policies are not being enforced by SSSD- Resolves: rhbz#1139044 - RHEL6.6 ipa user private group not found- Resolves: rhbz#1103487 - CVE-2014-0249 - sssd: incorrect expansion of group membership when encountering a non-POSIX group- Resolves: rhbz#1125187 - simple_allow_groups does not lookup groups from other AD domains- Resolves: rhbz#1127270 - sssd connect to ipa-server is long- Resolves: rhbz#1130017 - Saving group membership fails if provider is AD, POSIX attributes are used and primary group contains the user as a member- Resolves: rhbz#1111528 - Expired shadow policy user(shadowLastChange=0) is not prompted for password change- Resolves: rhbz#1132361 - use-after-free in dyndns code- Resolves: rhbz#1099290: RFE: Be able to configure sssd to honor openldap account lock to restrict access via ssh key- Use the correct sudo iterator - Related: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Add notes about offline mode to sssd.conf - Related: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1127278 - Auth fails when space in username is replaced with character set by override_default_whitespace- Resolves: rhbz#1127757 - sssd can't retrieve sudo rules when using the "default_domain_suffix" option- Resolves: rhbz#1127265 - Problems with tokengroups and ldap_group_search_base- Resolves: rhbz#1126636 - RHEL6.6 sssd not running after upgrade- Resolves: rhbz#1128612 - IFP: FQDN lookups are broken- Resolves: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Resolves: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1122873 - Failover does not always happen from SRV to hostname resolution(via /etc/hosts) - Remove spurious systemctl call on %postun- Resolves: rhbz#1111317 - [RFE] Add option for sssd to replace space with specified character in LDAP group- Resolves: rhbz#1109188 - dereferencing control failure against openldap server- Resolves: rhbz#1084532 - sssd_sudo process segfaults- Resolves: rhbz#1122158 - ad: group membership is empty when id mapping is off and tokengroups are enabled- Resolves: rhbz#1118541 - Floating point exception using ldap- Resolves: rhbz#1042922 - [RFE] Add fallback to sudoRunAs when sudoRunAsUser is not defined and no ldap_sudorule_runasuser mapping has been defined in SSSD- Resolves: rhbz#1120508 - tokengroups do not work with id_provider=ldap- Fix potential NULL dereference in IFP code - Related: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- BuildRequire the latest libini_config - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- Resolves: rhbz#1104145 - public key validator is too strict and does not allow newlines anywhere in the public key string, not even at the end- Rebase to 1.11.6 - Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Rebuild against new ding-libs - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Backport the InfoPipe patches needed for Sat6 integration - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: #1085412 - SSSD Crashes when storage experiences high latency- Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6Resolves: #1036168 - sssd can't retrieve auto.master when using the "default_domain_suffix"- Resolves: #1065534 - SSSD pam module accepts usernames with leading spaces- Resolves: #1038098 - sssd_nss grows memory footprint when netgroups are requested- Allow combination of proxy id backend and LDAP auth backend - Resolves: #1025813 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Inherit UID limits for subdomains - Resolves: #1020905 - Creating system accounts on a IdM client takes up to 10 minutes when AD trust is configured in the IdM.- Do not crash when LDAP disconnects while a search is still in progress - Resolves: #1019979 - sssd_be segfault when authenticating against active directory- More upstream fixes to prevent memcache crashes - Related: #997406 - sssd_nss core dumps under load- Resolves: #1002929 - sssd_be segfaults if IPA dynamic DNS update times out- Make IPA SELinux provider aware of subdomain users - A better version of already committed patch - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Resolves: #997406 - sssd_nss core dumps under load - Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #1002161 - large number of sudo rules results in error - Unable to create response: Invalid argument- Silence restorecon on clean install - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Make IPA SELinux provider aware of subdomain users - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Print password complexity hint when password change fails with constraint violation - Related: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #948830 - sssd do too many disk writes causing delay in "getent netgroup allmachines-netgroup" nested netgroups.- Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- Resolves: #963235 - sssd_be crashing with nested ldap groups- Apply a forgotten dependency for patch #254 - Related: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality - Add two fixes for better handling of faulty SRV processing - Related: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router. - Remove enumerate=true from example in man page - Related: #988381 - clarify the disadvantages of enumeration in sssd.conf- Resolves: #914433 - sssd pam write_selinux_login_file creating the temp file for SELinux data failed- Resolves: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality- Resolves: #918394 - sssd etas 99% CPU and runs out of file descriptors when clearing cache- Resolves: #924113 - man sssd-sudo has wrong title- Resolves: #924397 - document what does access_provider=ad do- Use permissive control when adding ghost users - Resolves: #928797 - cyclic group memberships may not work depending on order of operations- Set correct state of SRV servers on resolving error - Resolves: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router.- Resolves: #954323 - SSSD doesn't display warning for last grace login.- Format patch to configure sysv script differently - RHEL-6 patch(1) apparently doesn't like the output of git format-patch -M -C and doesn't properly copy files on renames - Resolves: #971435 - Enhance sssd init script so that it would source a configuration.- Resolves: #973345 - SSSD service randomly dies- Resolves: #971435 - Enhance sssd init script so that it would source a configuration- Resolves: #961356 - SUDO is not working for users from trusted AD domain- Resolves: #970519 - [RFE] Add support for suppressing group members- Resolves: #976273 - [RFE] Add a new override_homedir expansion for the "original value"- Resolves: #978966 - sudoHost mismatch response is incorrect sometimes- Clarify the min_id/max_id limits further - Resolves: #978994 - SSSD filter out ldap user/group if uid/gid is zero- Resolves: #979046 - sssd_be goes to 99% CPU and causes significant login delays when client is under load- Resolves: #986379 - sss_cache -N/-n should invalidate the hash table in sssd_nss- Resolves: #988525 - sssd fails instead of skipping when a sudo ldap filter returns entries with multiple CNs- Mention that enumeration should be discouraged - Resolves: #988381 - clarify the disadvantages of enumeration in sssd.conf- Call restorecon on memcache files to force the right context on upgrades - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Resolves: #987479 - libsss_sudo should depend on sudo package with sssd support- Resolves: #951086 - sssd_pam segfaults if sssd_be is stuck- Resolves: #967636 - SSSD frequently fails to return automount maps from LDAP- Resolves: #953165 - Enabling enumeration causes sssd_be process to utilize 100% of the CPU- Resolves: #906398 - sssd_be crashes sometimes- Resolves: #950874: Simple access control always denies uppercased users in case insensitive domain- Resolves: #921454: Resolve local group members in LDAP groups- Resolves: rhbz#911299 - sssd: simple access provider flaw prevents intended ACL use when client to an AD provider- Fix pwd_expiration_warning=0 - Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#872827 - Serious performance regression in sssd- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#903078 - TOCTOU race conditions by copying and removing directory trees- Resolves: rhbz#903078 - Out-of-bounds read flaws in autofs and ssh services responders- Resolves: rhbz#902716 - Rule mismatch isn't noticed before smart refresh on ppc64 and s390x- Resolves: rhbz#896476 - SSSD should warn when pam_pwd_expiration_warning value is higher than passwordWarning LDAP attribute.- Resolves: rhbz#902436 - possible segfault when backend callback is removed- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894302 - sssd fails to update to changes on autofs maps- Resolves: rhbz894381 - memory cache is not updated after user is deleted from ldb cache- Resolves: rhbz895615 - ipa-client-automount: autofs failed in s390x and ppc64 platform- Resolves: rhbz#894997 - sssd_be crashes looking up members with groups outside the nesting limit- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894428 - wrong filter for autofs maps in sss_cache- Resolves: rhbz#894738 - Failover to ldap_chpass_backup_uri doesn't work- Resolves: rhbz#887961 - AD provider: getgrgid removes nested group memberships- Resolves: rhbz#878583 - IPA Trust does not show secondary groups for AD Users for commands like id and getent- Resolves: rhbz#874579 - sssd caching not working as expected for selinux usermap contexts- Resolves: rhbz#892197 - Incorrect principal searched for in keytab- Resolves: rhbz#891356 - Smart refresh doesn't notice "defaults" addition with OpenLDAP- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#886848 - user id lookup fails for case sensitive users using proxy provider- Resolves: rhbz#890520 - Failover to krb5_backup_kpasswd doesn't work- Resolves: rhbz#874618 - sss_cache: fqdn not accepted- Resolves: rhbz#889182 - crash in memory cache- Resolves: rhbz#889168 - krb5 ticket renewal does not read the renewable tickets from cache- Resolves: rhbz#886091 - Disallow root SSH public key authentication - Add default section to switch statement (Related: rhbz#884666)- Resolves: rhbz#886038 - sssd components seem to mishandle sighup- Resolves: rhbz#888800 - Memory leak in new memcache initgr cleanup function- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#885078 - sssd_nss crashes during enumeration if the enumeration is taking too long- Related: rhbz#875851 - sysdb upgrade failed converting db to 0.11 - Include more debugging during the sysdb upgrade- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#870045 - always reread the master map from LDAP - Resolves: rhbz#876531 - sss_cache does not work for automount maps- Resolves: rhbz#884666 - sudo: if first full refresh fails, schedule another first full refresh- Resolves: rhbz#880956 - Primary server status is not always reset after failover to backup server happened - Silence a compilation warning in the memberof plugin (Related: rhbz#877974) - Do not steal resolv result on error (Related: rhbz#882076)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider- Resolves: rhbz#884600 - ldap_chpass_uri failover fails on using same hostname- Resolves: rhbz#858345 - pam_sss(crond:account): Request to sssd failed. Timer expired- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#880176 - memberUid required for primary groups to match sudo rule- Resolves: rhbz#885105 - sudo denies access with disabled ldap_sudo_use_host_filter- Resolves: rhbz#883408 - Option ldap_sudo_include_regexp named incorrectly- Resolves: rhbz#880546 - krb5_kpasswd failover doesn't work - Fix the error handler in sss_mc_create_file (Related: #789507)- Resolves: rhbz#882221 - Offline sudo denies access with expired entry_cache_timeout - Fix several bugs found by Coverity and clang: - Check the return value of diff_gid_lists (Related: #869071) - Move misplaced sysdb assignment (Related: #827606) - Remove dead assignment (Related: #827606) - Fix copy-n-paste error in the memberof plugin (Related: #877974)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider - Link sss_ssh_authorizedkeys and sss_ssh_knowhostsproxy with the client libraries (Related: #870060) - Move sss_ssh_knownhosts documentation to the correct section (Related: #870060)- Resolves: rhbz#884480 - user is not removed from group membership during initgroups - Fix incorrect synchronization in mmap cache (Related: #789507)- Resolves: rhbz#883336 - sssd crashes during start if id_provider is not mentioned- Resolves: rhbz#882290 - arithmetic bug in the SSSD causes netgroup midpoint refresh to be always set to 10 seconds- Resolves: rhbz#877974 - updating top-level group does not reflect ghost members correctly - Resolves: rhbz#880159 - delete operation is not implemented for ghost users- Resolves: rhbz#881773 - mmap cache needs update after db changes- Resolves: rhbz#875677 - password expiry warning message doesn't appear during auth - Fix potential NULL dereference when skipping built-in AD groups (Related: rhbz#874616) - Add missing parameter to DEBUG message (Related: rhbz#829742)- Resolves: rhbz#882076 - SSSD crashes when c-ares returns success but an empty hostent during the DNS update - Do not version libsss_sudo, it's not supposed to be linked against, but dlopened (Related: rhbz#761573)- Resolves: rhbz#880140 - sssd hangs at startup with broken configurations- Resolves: rhbz#878420 - SIGSEGV in IPA provider when ldap_sasl_authid is not set- Resolves: rhbz#874616 - Silence the DEBUG messages when ID mapping code skips a built-in group- Resolves: rhbz#824244 - sssd does not warn into sssd.log for broken configurations- Resolves: rhbz#874673 - user id lookup fails using proxy provider - Fix a possibly uninitialized variable in the LDAP provider - Related: rhbz#877130- Resolves: rhbz#878262 - ipa password auth failing for user principal name when shorter than IPA Realm name - Resolves: rhbz#871843 - Nested groups are not retrieved appropriately from cache- Resolves: rhbz#870238 - IPA client cannot change AD Trusted User password- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#861075 - SSSD_NSS failure to gracefully restart after sbus failure- Resolves: rhbz#877354 - ldap_connection_expire_timeout doesn't expire ldap connections- Related: rhbz#877126 - Bump the release tag- Resolves: rhbz#877126 - subdomains code does not save the proper user/group name- Resolves: rhbz#877130 - LDAP provider fails to save empty groups - Related: rhbz#869466 - check the return value of waitpid()- Resolves: rhbz#870039 - sss_cache says 'Wrong DB version'- Resolves: rhbz#875740 - "defaults" entry ignored- Resolves: rhbz#875738 - offline authentication failure always returns System Error- Resolves: rhbz#875851 - sysdb upgrade failed converting db to 0.11- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#871160 - sudo failing for ad trusted user in IPA environment- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#869678 - sssd not granting access for AD trusted user in HBAC rule- Resolves: rhbz#872180 - subdomains: Invalid sub-domain request type - Related: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running- Resolves: rhbz#873988 - Man page issue to list 'force_timeout' as an option for the [sssd] section- Resolves: rhbz#873032 - Move sss_cache to the main subpackage- Resolves: rhbz#873032 - Move sss_cache to the main subpackage - Resolves: rhbz#829740 - Init script reports complete before sssd is actually working - Resolves: rhbz#869466 - SSSD starts multiple processes due to syntax error in ldap_uri - Resolves: rhbz#870505 - sss_cache: Multiple domains not handled properly - Resolves: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running - Resolves: rhbz#872110 - User appears twice on looking up a nested group- Resolves: rhbz#871576 - sssd does not resolve group names from AD - Resolves: rhbz#872324 - pam: fd leak when writing the selinux login file in the pam responder - Resolves: rhbz#871424 - authconfig chokes on sssd.conf with chpass_provider directive- Do not send SIGKILL to service right after sending SIGTERM - Resolves: #771975 - Fix the initial sudo smart refresh - Resolves: #869013 - Implement password authentication for users from trusted domains - Resolves: #869071 - LDAP child crashed with a wrong keytab - Resolves: #869150 - The sssd_nss process grows the memory consumption over time - Resolves: #869443- BuildRequire selinux-policy so that selinux login support is built in - Resolves: #867932- Do not segfault if namingContexts contain no values or multiple values - Resolves: rhbz#866542- Fix the "ca" translation of the sssd-simple manual page - Related: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- New upstream release 1.9.2- Rebase to 1.9.1- Require the latest libldb- Rebase to 1.9.0 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- Rebase to 1.9.0 RC1 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4 - Bump the selinux-policy version number to pull in required fixes- Resolves: rhbz#840089 - Update the shadowLastChange attribute with days since the Epoch, not seconds- Fix protocol break for services map - Related: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#824616 - sssd_nss crashes when configured with use_fully_qualified_names = true- Resolves: rhbz#824062 - sssd_be crashed with SIGSEGV in _tevent_schedule_immediate()- Resolves: rhbz#822236 - SSSD netgroups do not honor entry_cache_nowait_percentage- Resolves: rhbz#820759 - AVC denial seen on sssd upgrade during ipa-client upgrade - Resolves: rhbz#821044 - sss_groupadd no longer detects duplicate GID numbers- Resolves: rhbz#818642 - Auth fails for user with non-default attribute names - Resolves: rhbz#819063 - sssd fails to provide partial data till paged search returns "Size Limit Exceeded" - Resolves: rhbz#820585 - Group enumeration fails in proxy provider- Resolves: rhbz#816616 - group members are now lowercased in case insensitive domains- Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Resolves: rhbz#805924 - SSSD should attempt to get the RootDSE after binding - Resolves: rhbz#814237 - sdap_check_aliases must not error when detects the same user - Resolves: rhbz#812281 - autofs client: map name length used as key length - Related: rhbz#784870 - SSSD fails during autodetection of search bases for new LDAP features - Related: rhbz#814269 - sssd-1.5.1-66.el6_2.3.x86_64 freezes- Fix typo in patch for SSH umask - Related: rhbz#808107 - Coverity revealed memory management defects- Resolves: rhbz#808458 - Authconfig crashes when sets krb realm - Resolves: rhbz#808597 - sssd_nss crashes on request when no back end is running - Resolves: rhbz#808107 - Coverity revealed memory management defects- Related: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false- Resolves: rhbz#804057 - Initial service lookups having name with uppercase alphabets doesn't work - Resolves: rhbz#804065 - Service lookup using case-sensitive protocol names doesn't work when case_sensitive=false - Resolves: rhbz#805281 - sssd: Uses the wrong key when there a multiple realms in a single keytab - Resolves: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false - Resolves: rhbz#805918 - Wrong resolv_status might cause crash when name resolution times out - Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Related: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Resolves: rhbz#801719 - "Error looking up public keys" while ssh to replica using IP address - Resolves: rhbz#803659 - Service lookup shows case sensitive names twice with case_sensitive=false - Resolves: rhbz#803842 - Unable to bind to LDAP server when minssf set - Resolves: rhbz#805034 - accessing an undefined variable might cause crash - Resolves: rhbz#805108 - sss_ssh_knownhostproxy infinite loop hangs SSH login- Update translations - Resolves: rhbz#802372 - Pick up latest translation files for SSSD - Resolves: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Related: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies- Resolves: rhbz#801407 - sssd_nss gets hung processing identical search requests - Resolves: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies - Resolves: rhbz#795562 - Infinite loop checking Kerberos credentials - Resolves: rhbz#798317 - sssd crashes when ipa_hbac_support_srchost is set to true - Resolves: rhbz#799039 - --debug option for sss_debuglevel doesn't work - Resolves: rhbz#799915 - Unable to lookup netgroups with case_sensitive=false - Resolves: rhbz#799929 - Raise limits for max num of files sssd_nss/sssd_pam can use - Resolves: rhbz#799971 - sssd_be crashes on shutdown - Resolves: rhbz#801533 - sssd_be crashes when resolving non-trivial nested group structure - Resolves: rhbz#801368 - Group lookups doesn't return members with proxy provider configured - Resolves: rhbz#801377 - getent returns non-existing netgroup name, when sssd is configured as proxy provider- Do not auto-upgrade debug levels - Tool still available for manual use - Reverts: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#798881 - Install-time warnings - Resolves: rhbz#798774 - IPA provider should assume that ipa_domain is also the dns_discovery_domain - Resolves: rhbz#798655 - Password logins failing due to a process with high UID- Fix explicit requires to use openldap instead of openldap-libs - Related: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64- Fix multilib-clean issue due to upgrade script - Remove old copy from the spec file - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Fix typo in the patch - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Use a patch and install the script to python_sitelib - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Resolves: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#785871 - wrong build dependency on nscd - Resolves: rhbz#785873 - IPA host search base cannot be set - Resolves: rhbz#791208 - Entries lacking a POSIX username value break group lookups - Resolves: rhbz#796307 - Simple Paged Search control needs to be used more sparingly - Resolves: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64 - Resolves: rhbz#787035 - ipa - sssd slow response with thousands of user entries - Resolves: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#772297 - Fails to update if all nisNetgroupTriple or memberNisNetgroup entries are deleted from a netgroup - Resolves: rhbz#783138 - Backend occasionally goes offline under heavy load - Resolves: rhbz#797975 - sssd_be: The requested target is not configured is logged at each login - Resolves: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Resolves: rhbz#761570 - [RFE] support looking up autofs maps via SSSD - Resolves: rhbz#788979 - sssd crashes during initgroups against a user belonging to nested rfc2307bis group- Handle filtering python Provides in a safer way - Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3 - Resolves: rhbz#786553 - sssd on ppc64 doesn't pull cyrus-sasl-gssapi.ppc as a dependancy - Resolves: rhbz#785909 - --debug-timestamps=1 is not passed to providers - Resolves: rhbz#785908 - ldap_*_search_base doesn't fully limit the group and netgroup search base correctly - Resolves: rhbz#785907 - [RFE] Add support to request canonicalization on krb AS requests - Resolves: rhbz#785905 - [RFE] DEBUG timestamps should offer higher precision - Resolves: rhbz#785904 - [RFE] SSSD should have --version option - Resolves: rhbz#785902 - Errors with empty loginShell and proxy provider - Resolves: rhbz#785898 - Enable midway cache refresh by default - Resolves: rhbz#785888 - sssd returns empty netgroup at a second request for a non-existing netgroup - Resolves: rhbz#785884 - Honour TTL when resolving host names - Resolves: rhbz#785883 - check DNS records before updates - Resolves: rhbz#785881 - List the keytab to pick the princiapl to use instead of guessing - Resolves: rhbz#785880 - debug_level in sssd.conf overrides command-line - Resolves: rhbz#785879 - sss_obfuscate/python config parser modifies config file too much - Resolves: rhbz#785877 - on reconnect we need to detect that a ipa/ds server has been reinitialized - Resolves: rhbz#785741 - sssd.api.conf and sssd.api.d should not be in /etc - Resolves: rhbz#773660 - Kerberos errors should go to syslog - Resolves: rhbz#772163 - Iterator loop reuse cases a tight loop in the native IPA netgroups code - Resolves: rhbz#771706 - sssd_be crashes during auth when there exists UTF source host group in an hbacrule - Resolves: rhbz#771702 - sssd_pam crashes during change password operation against a IPA server - Resolves: rhbz#771361 - case_sensitive function not working as intended for ldap - Resolves: rhbz#768935 - Crash when applying settings - Resolves: rhbz#766941 - The full dyndns update message should be logged into debug logs - Resolves: rhbz#766930 - [RFE] Add a new option to override home directory value - Resolves: rhbz#766913 - [RFE] Add option to select validate and FAST keytab principal name - Resolves: rhbz#766907 - Use [...] for IPv6 addresses in kdc info files - Resolves: rhbz#766904 - [RFE] Create a command line tool to change the debug levels on the fly - Resolves: rhbz#766876 - [RFE] Make HBAC srchost processing optional - Resolves: rhbz#766141 - [RFE] SSSD should support FreeIPA's internal netgroup representation - Resolves: rhbz#761582 - [RFE] Add ldap_sasl_minssf option - Resolves: rhbz#759186 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#755506 - [RFE] Add host-based (pam_host_attr) access control - Resolves: rhbz#753876 - [RFE] Add support for the services map - Resolves: rhbz#746181 - "getgrgid call returned more than one result" after group name change in MSAD - Resolves: rhbz#744197 - [RFE] close LDAP connection to the server when idle for some (configurable) time - Resolves: rhbz#742510 - [RFE] Separate Cache Timeouts for SSSD - Related: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#742052 - id -G group resolution takes extremely long - Resolves: rhbz#739312 - [RFE] sssd does not set shadowLastChange - Resolves: rhbz#736150 - [RFE] SSSD should support multiple search bases - Resolves: rhbz#735827 - [RFE] Ability to set a domain as case sensitive or insensitive - Resolves: rhbz#735405 - [RFE] Option to disable warnings for unknown users - Resolves: rhbz#728212 - [RFE] sssd does not handle when paging control disabled for openldap - Resolves: rhbz#726467 - SSSD takes 30+ seconds to login - Resolves: rhbz#721289 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 during auth when password for the user is not set- Resolves: rhbz#773655 - Race-condition bug in LDAP auth provider- Resolves: rhbz#753842 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758157 - LDAP failover not working if server refuses connections- Related: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#749822 - SSSD may go into infinite loop during RFC2307bis initgroups when groups appear in multiple nesting levels- Resolves: rhbz#749256 - SELinux errors with SSSD Downgrade- Resolves: rhbz#748924 - RHEL6.1/sssd_pam segmentation fault- Resolves: rhbz#748412 - Memory leaks during the initgroups() operation- Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742288 - RFC2307bis initgroups calls are slow - Resolves: rhbz#746654 - SSSD backend gets killed on slow systems - Related: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts Fixes a crash introduced by the earlier patch. - Related: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names Fixes for internationalization- Related: rhbz#742278 - Rework the example config- Resolves: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts - Resolves: rhbz#745966 - sssd_pam segfaults on sssd restart - Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742278 - Rework the example config - Resolves: rhbz#746037 - Only access sssd_nss internal hash table if it was initialized - Resolves: rhbz#742526 - SSSD's man pages are missing information - Resolves: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#738621 - Lookup fails for non-primary usernames with multi-valued uid - Resolves: rhbz#738629 - Group lookups doesn't return it's member for sometime when the member has multi-valued uid - Resolves: rhbz#742295 - Use an explicit base 10 when converting uidNumber to integer - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names- Resolves: rhbz#741751 - HBAC rule evaluation does not properly handle host groups - Resolves: rhbz#740501 - SSSD not functional after "self" reboot - Resolves: rhbz#742539 - HBAC: Hostname comparisons should be case-insensitive- Resolves: rhbz#728343 - SSSD taking 5 minutes to log in - Resolves: rhbz#739850 - Coverity defects newly introduced in rhel 6.2- Resolves: rhbz#737157 - "System error" appears in log during change password operation of a user in openldap server with ppolicy enabled - Resolves: rhbz#737172 - "Unknown (private extension) error(21853), (null)" messages are logged during change password operation of a user in openldap server with ppolicy enabled- Resolves: rhbz#736314 - sssd crashes during auth while there exists multiple external hosts along with managed host - Resolves: rhbz#732974 - [RFE] Have SSSD cache properly with krb5_validate = True and SElinux enabled- Resolves: rhbz#732010 - LDAP+GSSAPI needs explicit Kerberos realm - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names - Resolves: rhbz#733409 - Improve password policy error message - Resolves: rhbz#733663 - Authentication fails when there exists an empty hbacsvcgroup - Resolves: rhbz#732935 - Add LDAP provider option to set LDAP_OPT_X_SASL_NOCANON - Resolves: rhbz#734101 - sssd blocks login of ipa-users- Related: rhbz#728353 - Resolve RPMDiff errors in SSSD- Resolves: rhbz#728961 - Provide a mechanism for vetoing the use of certain shells- Related: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID- Related: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Related: rhbz#718250 - Remove DENY rules from the HBAC access provider - Fixes an issue on big endian platforms- Resolves: rhbz#700828 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 (SIGSEGV) when ldap_uri is misconfigured - Resolves: rhbz#726438 - sssd doesn't honor ldap supportedControls - Resolves: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Resolves: rhbz#718250 - Remove DENY rules from the HBAC access provider - Resolves: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID - Resolves: rhbz#726475 - sssd_pam leaks file descriptors - Resolves: rhbz#725868 - Explicitly ignore groups with gidNumber = 0- Related: rhbz#721052 - sssd does not handle kerberos server IP change - Use ares_search instead of ares_query to honor - search entries in /etc/resolv.conf- Resolves: rhbz#711416 - During the change password operation the ccache is - not replaced by a new one if the old one isn't - active anymore - Resolves: rhbz#715609 - Certificate validation fails with message - "Connection error: TLS: hostname does not match CN - in peer certificate" - Resolves: rhbz#719089 - IPA dynamic DNS update mangles AAAA records - Resolves: rhbz#721052 - sssd does not handle kerberos server IP change - Honor TTL values when resolving hostnames- Resolves: rhbz#713961 - libsss_ldap segfault at login against OpenLDAP - Resolves: rhbz#713438 - sssd shuts down if inotify crashes- Resolves: rhbz#709081 - sssd.$arch should require sssd-client.$arch- Resolves: rhbz#709342 - Typo in negative cache notification for initgroups() - Resolves: rhbz#708009 - "renew_all_tgts" and "renew_handlers" messages are - being logged multiple times when the provider comes - back online - Resolves: rhbz#707997 - The IPA provider does not work with IPv6 - Resolves: rhbz#677327 - [RFE] Support overriding attribute value - Resolves: rhbz#692090 - SSSD is not populating nested groups in - Active Directory- Resolves: rhbz#707627 - Include valid "ldap_uri" formats in sssd-ldap man - page- Resolves: rhbz#707513 - Unable to authenticate users when username - contains "\0"- Resolves: rhbz#698723 - kpasswd fails when using sssd and - kadmin server != kdc server- Resolves: rhbz#707282 - latest sssd fails if ldap_default_authtok_type is - not mentioned - Resolves: rhbz#692404 - rfc2307bis groups are being enumerated even when the - gidNumber is out of the range of min_id,max_id. - Resolves: rhbz#699530 - Users with a local group as their primary GID are - denied access by the simple access provider - Resolves: rhbz#700172 - RFE: SSSD should support paged LDAP lookups - Resolves: rhbz#705434 - IPA provider fails initgroups() if user is not a - member of any group - Resolves: rhbz#703624 - SSSD's async resolver only tries the first - nameserver in /etc/resolv.conf- Resolves: rhbz#701700 - sssd client libraries use select() but should use - poll() instead- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix segfault in TGT renewal- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix typo causing build breakage- Resolves: rhbz#693818 - Automatic TGT renewal overwrites cached password- Resolves: rhbz#696972 - Filters not honoured against fully-qualified users- Resolves: rhbz#694146 - SSSD consumes GBs of RAM, possible memory leak- Related: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694444 - Unable to resolve SRV record when called with - _srv_, in ldap_uri - Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#692472 - Process /usr/libexec/sssd/sssd_be was killed by - signal 11 (SIGSEGV) - Fix is to not attempt to resolve nameless servers- Resolves: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Resolves: rhbz#690866 - Groups with a zero-length memberuid attribute can - cause SSSD to stop caching and responding to - requests- Resolves: rhbz#690131 - Traceback messages seen while interrupting - sss_obfuscate using ctrl+d - Resolves: rhbz#690421 - [abrt] sssd-1.2.1-28.el6_0.4: _talloc_free: Process - /usr/libexec/sssd/sssd_be was killed by signal 11 - (SIGSEGV)- Related: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683158 - SSSD breaks on RDNs with a comma in them - Resolves: rhbz#689886 - group memberships are not populated correctly during - IPA provider initgroups - Resolves: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683860 - Skip users and groups that have incomplete contents - Resolves: rhbz#688491 - authconfig fails when access_provider is set as krb5 - in sssd.conf- Resolves: rhbz#683255 - sudo/ldap lookup via sssd gets stuck for 5min - waiting on netgroup - Resolves: rhbz#683431 - sssd consumes 100% CPU - Related: rhbz#680440 - sssd does not handle kerberos server IP change- Related: rhbz#680440 - sssd does not handle kerberos server IP change - SSSD was staying with the old server if it was still online- Resolves: rhbz#682850 - IPA provider should use realm instead of ipa_domain - for base DN- Resolves: rhbz#682340 - sssd-be segmentation fault - ipa-client on - ipa-server - Resolves: rhbz#680440 - sssd does not handle kerberos server IP change - Resolves: rhbz#680442 - Dynamic DNS update fails if multiple servers are - given in ipa_server config option - Resolves: rhbz#680932 - Do not delete sysdb memberOf if there is no memberOf - attribute on the server - Resolves: rhbz#682807 - sssd_nss core dumps with certain lookups- Related: rhbz#678614 - SSSD needs to look at IPA's compat tree for netgroups - Related: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option- Resolves: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option - Resolves: rhbz#677318 - Does not read renewable ccache at startup- Resolves: rhbz#678593 - User information not updated on login for secondary - domains - Resolves: rhbz#678777 - IPA provider does not update removed group - memberships on initgroups- Resolves: rhbz#677588 - sssd crashes at the next tgt renewals it tries - Resolves: rhbz#678410 - name service caches names, so id command shows - recently deleted users - Resolves: rhbz#678614 - SSSD needs to look at IPA's compat tree for - netgroups- Resolves: rhbz#670511 - SSSD and sftp-only jailed users with pubkey login - Resolves: rhbz#675284 - "no matching rule" message logged on all successful - requests - Resolves: rhbz#676911 - SSSD attempts to use START_TLS over LDAPS for - authentication- Resolves: rhbz#674164 - sss_obfuscate fails if there's no domain named - "default" - Resolves: rhbz#674515 - -p option always uses empty string to obfuscate - password - Resolves: rhbz#674141 - Traceback call messages displayed while - "sss_obfuscate" command is executed as a non-root - user- Resolves: rhbz#674172 - Group members are not sanitized in nested group - processing - Put translated tool manpages into the sssd-tools subpackage- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Also add the updated ding-libs to the BuildRequires- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Explicitly require updated ding-libs- Resolves: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options - Assorted bugfixes- Add noverify to sssd.conf - Resolves: rhbz#627165 - TPS VerifyTest failure- Related: rhbz#644072 - Rebase SSSD to 1.5 - New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Resolves: rhbz#660592 - SSSD shutdown sometimes hangs - Resolves: rhbz#660585 - getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#659401 - SSSD shutdown sometimes hangs- Resolves: rhbz#645449 - 'getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#658374 - sssd stops on upgrade- Resolves: rhbz#658158 - sssd stops on upgrade- Resolves: rhbz#649312 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#649286 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#637070 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#642412 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#633487 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib- Resolves: rhbz#629949 - sssd stops on upgrade- Resolves: rhbz#625122 - GNOME Lock Screen unocks without a password- Resolves: rhbz#621307 - Password changes are broken on LDAP- Resolves: rhbz#617623 - SSSD suffers from serious performance issues on - initgroups calls- Resolves: rhbz#607233 - SSSD users cannot log in through GDM - - Real issue was that long-running services - - do not reconnect if sssd is restarted- Resolves: rhbz#591715 - sssd should emit warnings if there are problems with - /etc/krb5.keytab file- Resolves: rhbz#606836 - libcollection needs an soname bump before RHEL 6 - final - Resolves: rhbz#608661 - SASL with OpenLDAP server fails - Resolves: rhbz#608688 - SSSD doesn't properly request RootDSE attributes- New upstream bugfix release 1.2.1 - Resolves: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs. - Resolves: rhbz#603041 - Remove unnecessary option krb5_changepw_principal - Resolves: rhbz#604704 - authconfig should provide error with no trace back - if disabling sssd when sssd is not enabled - Resolves: rhbz#591873 - Connecting to the network after an offline kerberos - auth logs continuous error messages to sssd_ldap.log - Resolves: rhbz#596295 - Authentication fails for user from the second domain - when the same user name is filtered out from the - first domain - Related: rhbz#598559 - Update translation files for SSSD before RHEL 6 - final- Resolves: rhbz#593696 - Empty list of simple_allow_users causes sssd service - to fail while restart - Resolves: rhbz#600352 - Wrapping the value for "ldap_access_filter" in - parentheses causes ldap_search_ext to fail - Resolves: rhbz#600468 - Segfault in krb5_child - Related: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs.- Resolves: rhbz#598670 - Ccache file of a user is removed too early - Resolves: rhbz#599057 - Incomplete comparison of a service name in - IPA access provider - Resolves: rhbz#598496 - Failure with IPA access provider - Resolves: rhbz#599027 - Makefile typo causes SSSD not to use the - kernel keyring- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP - Resolves: rhbz#584001 - Rebase sssd to 1.2 - Resolves: rhbz#584017 - Unconfiguring sssd leaves KDC locator file - Resolves: rhbz#587384 - authconfig fails if krb5_kpasswd in sssd.conf - Resolves: rhbz#587743 - Need to replicate pam_ldap's pam_filter in sssd.conf - Resolves: rhbz#590134 - sssd: auth_provider = proxy regression - Resolves: rhbz#591131 - Kerberos provider needs to rewrite kdcinfo file when - going online - Resolves: rhbz#591136 - Change SSSD ipa BE to handle new structure of the - HBAC rule- Improve DEBUG logs for STARTTLS failures- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)uk1.13.3-60.el61.13.3-60.el6libsss_ipa.soselinux_childsssd-ipa-1.13.3COPYINGsssd-ipa.5.gzsssd-ipa.5.gzkeytabs/usr/lib64/sssd//usr/libexec/sssd//usr/share/doc//usr/share/doc/sssd-ipa-1.13.3//usr/share/man/man5//usr/share/man/uk/man5//var/lib/sss/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m64 -mtune=genericcpioxz2x86_64-redhat-linux-gnu?7zXZ !PH6] b2u y-iSqal7jN)L5 f 4u"Z<]A6hAxS$;#OP},76z {32YǓQ$9,Keb:k~Y E?Jʡ?c2l6T&G֝O[;qvܪ0l%`TWgC<,fwTNO`F)Ny?da aLmblĞpS^g2֋ qْ+7͊Td~ϽbxB[)&AOR -=!YU>)oa+RT X.୉Q&?$ugƜ/eY֊b,rIIύ۹В;i kh WtT?Sj䢕n:#xZ.TCPRx~||*;jBcwkGc { ݳA w_CciF?c7\4( X+b۽CCIT9JבcO0Oeݘ׸v`|)8*p=Eeʥpe(#Unwf]ٟ^he}h|I'!!:AZWOYdf%=oO#.ccڿEm1:х:۫wQ;ؚY轵1c؞ 2߹A%۴ 'I+[Kc, }Kt0B|#`KfS:J?k`LjtU5fhZ-ǕtN.p {p!\kCGEMD~ȫ)&wғ Ih‰O;%vDT3Բ31ܟTړl f{6{Vw>re2Bѧ$g˷>GN/?(8&*qdAF0rxv7$bd~CxF< mWDG<c!ozZG+$q! Fq3=`'}#pdjg,o"U4@D*:T3~Gq 6aMU gW2% <+ :f2燄 AT\l~t|]k_2}\<䃍@t(]L淪ɺ)F|Fag4 n`nn$@6&8wϯadXG@nrʖWf,,F6s` |,y't~0 +w\Ƌ4N'k?ݩɂUϤzAnε9j3U S=`~ùG,S_!6T _Me5;=POl ȫE4z~o8#h%⿭_3ڈ"[Wrq^zbݽ]KgXUzG5).\r~b^hy|߈*$p$of wl{Cy JӇ+-EDV4CKrzTA$#awmP6m++ʲ80pEV-5T[ap Zy83lÎWRBl'=&%LYS ew@2@BNvkqXA=AnH6 mhAu -|Ye~K^WA SsOI+-bnQ$D?A@1bX*eDf6ǔ@6G%Ige Tuى䖿򭊭d7fU'R,ߴ7*_\[aQ`ݫZMiB* P˜I +X^7GOu>ۘ +:ch-Uij6b &?8pעfF#pr%6GT!; ,?C>n4^u5$۪uEY%caS煫uϴK6\{ +8·|_b :8EjwM d }&lvvO @55t_o`Ѩo:8rbTF Geap tR1Y^,{Q&M4%5DyR#v1zZGOOB--ܷF/7PBkEVX־wSNP~pѦ)Z,e(e:>Ir'L;u9̢gF]7m)ZKHwD6Bf[ D y(cFVW z`/BF_FyJEP>@Bfi^8T?1RX;fK,Οɘ}@˄*aQJ/| ֻ@0yRyE>S]Y1Y9/fl(ohK<||<&&ATY2ֆ>O3%|]]725 Q$D1N~lpȝǦB)UGzU{{QBƯ+g,/90: d';)~7x9R-$״pdm>3϶Wn*I "W})m{flFH XhL3skiG LV7eŘ1-aM=LE`@uLNҽRق:ZBx>рB' Q+e`"+ H\5l Ubjy|*0o,`u9a뵱6ܸ/nc+rS]_^ww"*}gm 2x+Uh 's?d4o j%[5)檑mcHRxITUG8'#;IC^Ss:%] w3/+Z ]HnY۝nUTb:ޝINqrR.g ]Iը֢Pk3Ԫņgnq}7_d'ډjq̡{CB0 k1łԥo$ʀ;ތo{zc&"ZiZ,a2`wKx pZ-2" %'C^NEy\yAt=vMtumrmM'u* {6,EwQQ1pX"#ͥ1-9'*,Z⨟Y`C > 8Dp:l;;1IfBδbmizު/MAժKu UnwAo>vt`R ( 24dD|7^ =xo3&&]ս^>[[2EFK{7gc%bs(u0-˚s"lj:,g9{#g6 !'-Zl%V'(%E9M!7˖V;9ShBD yEoH\]___Nろ CG8y@umP|[ɗTvofXXHȎW XD_4pw %I|5?_F'D _]}DVD*,|po!BH);>Kܫ>:U4 ZV$?P1j3ctFS{gV8?9Gm^% 0( hĽsY6 wC8J|9l &rU&9V9 7AX{>R3e5zp”OB哲&MOV]-#(i軡n"%+OG4&Alm](; q*|UMX9}%aVԥdwCdyYźՒvy0T΋?1eܡ]'o,]_NtTۙr%vյ]2.krUUyTY-~A %Hzg9<*6ůĬ!PϿN$ {C/TvqN4<8f/<== (iT㔺*(Ng{>eC@@*OKa6q%1fa[Rm^f ">U!fbddt<8eIhɖiS" 0 BN ,8["<mȷ\tjef%Ò֡M⓻d!SM^C n}{^*Qh_&7O')IS*d6GH^j%{ZOZ))-[NwuL, dvi1{EgmHwhY\U}H%ND,~ G0|1/-ii~*QH: ܖBzAi-W)(NOc}DkI ;swB|XQ +@P$,>/N'} n$ 9aק/46So|xt-$MV16{k^nO4ہe*YI~ t'E/oQb3LG%"F^V++^ט ^'za@5c2!l :J]FgS>ien9/!u 뀿ukt=Ng:dZ=jw;S  3d7K:.){{/vp@d}YC -+b.'G6+竈?KVuf)!eS A?(Ң2~?hLoqK8b&`$\Ͷ.v)|(\CTuQzBDC;>S/0"ph@d4Ĝr:] +LG<zw!kͽoko|`*ѾMbof՛8bDOKfDΑĕ縊o.pF. bdk%t~AX!J EcVC"u$u,mƭ#F'mVͺ'\km>P/ȣ?^=Klg]⧃ lwH5+G߲ZgorRkd )kH b^G-Hoi\K|I)O +*.p/5B9zp/CjV y[0 #NӰ;s$Fu'PMl0HTάyܯ켾1nMyҦK$Kr<>!>mBˍyt\8n).z\="6ѳϲSP+"=v11f1Dw X>T ')V0nfA mM HD?Vu5&Czj3UI p?v DaN;wS,qs>?uD1EQ!n i1C&Ԡ<)Ϲ/}q6`˥B̰vH۽"|g e}x͘d8\ff>R7xņSM5jvKs"f/ 7#V!xͶ"ANfK[K@G!XDH]ٖL`L4mnjYξ5 ybJ]ǀ ׬Ƭ3w+'P . !+XVO4$gBPS1aW"3rl׭[uUr;$[/F"֭ H͎<>,rL z@' :ϣ77khbz@r7%|n{:wj&QMv'#K\.  GP\&`d)9X_Sݫl \0 yۓ7|wJ7;@+..e׌N+]u? Zq$h:.0j};qU>qœmJ4NN[)2o>2_wda<70r @Qș29';'SJ^-ƛ!V9ՉVP=gN#wo!)-aﻤ-nk߸Na ހA,qdIN`J Ս"UUS"7Pԯ0΅^4 ?jIb(/jEM}zL滋l:Ԥn&%2uT-Ҡ[F\` >e΃cpqH`v@8rk9/:rY^wOEl6"8 0]1ѴwbRo"E iaÓ7QB'WO֠jNr,uXh EtA dmXdT#r7KA,VG% SEMLٝh̷"j Y8>+N<nJ԰cupꞼY0Z+M 4d(;pZRaߕ?=_A/NU,d(|S%5E3kXo%k~'t2%F:]I$ N28qjEqP`b1Dc]`I]j5EI uD˲=zyni!m y<}{ wٲg~SA؄ȧoIL=l2g uQG:Dg>]uWG{> N=ίHiyY縸 lȗu "1C+s$ Pfw̭^^X8z;8)1g%BC4GI$n*6vXЊ(":؁f}zPhso|j(i@_J, r4M ؁k{nJ l?-Ё4E+{c"凪oBQZ[yD 'WсD ZNz@U^|fʗEmk s4mqF^[Ğypї/F07vMM9Q9L C;>aӬG;Z馘-:\zn׉ۣg9e"Jg?m)+0IXs$j0+1R"Ϊ.͏:nv0;PC|L ͆'i]&3lY܆SR1mlxԁR˕:գJ5X tpv&Vgms5!d$kE0+z, Ek\nU*.^@l›ə=]y֛˨/?1SFQ,gDϚdE a?\(VIf?M6d? XkHڻ/QT9f덄g&'OHg4a &D7:q]+18ԛsFi3}=Fslם kly<~Wc!-P@i5G͓ŶbSh/%oVV DGdzӎ^pn*.=1$j8"Yj6O0~:DO$ dh8b U7^5sVˮW*Bu~j1Cq6(X4Qk$PI;K/H"עRC^Wd%^&$.ѐmKIr*e1F_eV=}c@t_KTJRaŻs uYd{>8^c?f,a {)r3GvWGFQ((g0{ka03M3>(mn,Hk'CuQb 1RM: T8R"߇bR)akɲ(jnyIo|f7L :3'uBا)1)b}v1^_}bLW],L _9nhzR4%t.|hrij zF:8׻zFib~>FUlmaq|(Zjap;tA~E^ /6=MQ/q7G\Hb'4o)oojOi^hZ!I?y@JoSf7 k[t+V5k85 :?5i?\]Seqrg^k7jiNCkmE۟&js(dA4X?9,P;r y.rCSaÿrݬr+E1S v.KL<v a]{qVr!ҞuHGZҜE|jԬPx=F_ɊI}AґM73]Pi͹b*b1Lfx{zw$>g|I 4a\r6,Q,4?vT=oˉ~.B-ATr(~ 7:YO)_@:P΢p7K`G qhX=QÕlI7˶+A+5ؠ.)(^4 -?S˫,-pg( ?ϗ!YlH-h7| (6Vk뉃E2lPYte|9 @]5zj˭-oQ+71O_KC`_ʬ͉>)iscrrpsv cR\-vIKmcW3-*rUހvF MB+M$]4 j&O/xSxH%nw…;@2}O=0&ChVf{5y}(%v .@n#73'_ZS3Ayv^^*c(6y!sĶg[Re:5ojZf?]ADBS:jnr%l9[)4o*PfgAE="BیzKM%K]^|= tO j_%X ˠ.I%^Dc|-CyKs|HUkÌ#*\Mbp-?v˟`}ǷZl8YK2:`,T5Js\FEu#b|e6ЫZFO_yD\nШ"S-%G~Z!%R4:N<"_/r?qA8.qn˥JU|,H)^! s`׫>7-UWA39WiV-' *U؎LTFX,*@` A\bw#B$D˅E\kuy:XxLыx>9X]*j<7%7u' nпup @xm$wg>{➙WU[u;D (j 5bĈOdަWϦsjEgD @&ҮYoŔNHڞs[ۗa DqL}엺S*WR , Lk1%LMnYymZIE+Lu ށoV ݅fEiEh!|1NA6N\XqS`i/BV~yP3 ϴw6'=F ٣mmnA]|M;|5g;N/Ѥ" +Qr4[a" `{ؤs^49F;^f^(P<#dcE'vMK^FKۏo]3DG_^wKؽj{$ k`dt\F-d>|B= qUc=r}oe5rȷ:O%:L~@>ғlob!<>Wvm~v0!/2 C9XsAќ7ONa sJ)/&,fQF hb"o8#pUH%Qy0$@N,KB>l C{ 3)TjSY);nk1t"7d4Q## uaAVj^w}_Ӽ9ńeu/0ʌvk "(w1oDU<$C`gj]#gHf7!-"`B(;uGEDi%ǍD\uO`9\b̨A3ﱯ0|IJ>-)|e}Zӷ-rbd@<Ӫ&OݳV9Ar x$T vty"gNxgQanWTsyn5 &_wȍK:I;-4z )- 1Ŀ0KJ3@IŃ-N#CB r(7_(!1&#I=L<!w`ZRbԄ;H<2-Cg?lRζgdB1`VNIsdʣ֬@}4F2Q =;w W=s~з<EfѿUG=?&(~ؤe)N\OMx L#󖛚${"eWO!el[1]14j[A)>|acF`KȄKKu+W>R\Kx.liuQH3okՃN5/!-x}/7Vc#Ald2X e ;lVF}neּ=kAhW"R)G7v';D)=uvin.B=/w䦏%Ay=pJ`lǨL+8Y1H]/7KeptE`OxZ |䘬K6j;qt7G$.ªX'zEX6u S۽vÅv'i~jq2љ΢'N)K t=e$3ve~ss 9i)WW 8gQ#dnOx65"&IR|(Q'R׽Ps![!ZNH BK^ܴ墍@vs5S/F/ΏcX_dd _Jz.)gc`uWр \зL7oҪ0v:E\t4ᄲ O0^an6Od!Bd ZLQktmZCe»hVtHݭ2h Z>gGvh uc0S҆@9}A=kП#B>uo_p_,zvL_DX#f3-d>4 O(WYAM(KXZ> wD펹E2=]=Ω.GHH%=#JF<ۧ fj3(3ABou0`$'Nggi-/F& Ĺj ^Y ʽKq|C} d1l=2>i 2YgUN[aT$BD!t_h n A*\ksiZ}amYyh o٦޶B'L^&q"Dk7MEDXEaw^I/}p7Nح#JNd>9uSksIwxS#2Z\riAL-Ϫ$yD3-i *8;/\+$@{և,~I~Bb-Kmh*KuoBnskJQta䙝^h~\f'_-xdbVԮ+x hoab6̨DJaU4 otV`gM.v8fLHH^=#WBi]?S9PŤA,&=njPL z@c$Ld ڋc'L%: n瀗r[-!m!U;T?AS %:g3O']9a7_}DND=@m/#4H/m9"%n~e8 SuvҪNY{oyIcfnE{K`+2sX!Ԇzx1*WsŁ$sD1wJiR4-X&ۇ\7ؚF 0'.$$.>̓?uI"*,'TsL_-(z{#:.evALyǹNϨ!x2LgaIT%jǰDEy Z>M*:ĝ?qZ `3ҷ3:9cE1{!} > H];Jcgc`> M̃#ʌH8%pL+)dP/хʠwi!Rտ1E 7IqּTv W-&O??ɆEf߀`'|6V Da`)_qHrK}N9@DH.sFpm=R7 >-MDbwi2T. T dm[Q *'ȝwZCJȂti%I 3M;OZ,3eW>P}pP߻|De]nL?%ߐe*܉Kj|pngyƉT^:e}/ 肨zlE$$K7#@̴/ors?^ِs$H Zzk_ޮg8p{D,3C#'РkK6R7{[%P3gֺVx7sA.`iBjhYN_ZRC F~ )j 7V). ]8Z-?Wxum:TC6U\w >yG  yp @ 6ꗯrX'A-CcL7D^۬d63pm,f!1jr!˴J8?OOQK bg^6)u__86ˆxHxb99=ڝ9y#Ȕ8Ne/*ȐXX d%>1ȩ׆/[͇_@U cHAAL{Zl SA:@u 4Dw)g WwH:lsi gOtEg v1?=Ď+ J^t+V9(0hҳ]1nc(cJ ٚۻX-@W۲ZvU_*ͻGWe@&RQPUJB.݊Z&[}_SϋlZ0n_= س>ZO5ٮ҂|XB8 q? q3)q%6_+ r싑W4-/7Bq- TA9P&٦ʒ|RS<= qo6^@϶] C!Nߨ|'nr1lۛX+jir(x邼kwkV6ᩲ&QǓ7d1TpBȚE|Eܲbr9 k-+ObAeO, < ?E:f̆aZYQ"{{i,J֛fV֪^e Тqs(Ar|;$:dfpW飇<3p!_v8lhe勅VT3E%1 ݺ7)_ sm`h9iUI#cN7J2U}FxO{3=^>^#un3=C(-_3sF@A6d>J6xY qQi˺3,z LX{b)Qik]OҩgH2'))pR"9 D ʺcrP+'" B;*<Գ])Q/P8e]99dr$gm[9 avfET#Γ}D-K*[y޷ IS%(dHR՗ɼG!ޔ LU_p9jN+A\1wߖsh/ztՅ8./ق+P&BgR'|[T^V,9(/hEet' `|@$KROe%tְiky$cbT^%Qjk3 ނ _ C1B֫^ H8g ;_o2{T\-svdJ9R$+LPÙ^[ZW=䯍$ጞ@ek"$ou"&6l9\ H3N֚܏qGK'ϗִ/ϔ:ͰQVG-~\5,)O`ٗ.LJ켬ަ"R/uZ3:>{"D"1(7HMw/csj2ۖ@M$/xZRN#]1/˂鈫VR,_LD| Eiy2GH O1ɕ"IuE̡q^f3)C8A%Wx?2 W|@N6}"!0-߳'u 8ÍD|WIUɕ+Bښ`zU팺qˀnNʥԯ"D6,wό+B=Vũ7R,{r(6d'F-&W"V6̺;?$bXQǚ6/$q\~0Szzj&¼`Ԁ#1[~ o)erLXz |5M*K0])r 4ޙOѭlifRпw~ҏR\*+RvgH;of P He;P^.OUMFr)-óIop\@°Pz#LG n8SkK3[!ȻtM pNNOTydʣt&#4{>իtMe'4ǟœTTSȗs>Ei#3EP`yeԲu0,jU ||U-wd45洇D$~[[^ 7g׮cHyLK,w|o2|j _T=gUO2C'>x iEnoO٩yϚ/^EC[{*,u0A9# ʕm Q1B3sr:(ʞm=E-wZ|Pڥ[UIUw6ʟX#Z3yǺ̅MnY U'(@lɰ{+etrВ`y3Syړdj3—Yb8L;IYݽ+S=<Gn'&y `@hE!N~*3:14{2<2K $>\}(Xthk J [^kԒ5+BVT@"|ODŽdŷzzZ\/0nS *@"Use*|f)ۅ#aUUR:VCWxXDn3zӳY42L~x_7a^p W(a)0^N\:k Z4XkW WbOX3  -':l&&` ݤWMeN"7 M:*O:㿘+٘VY&x=?IFX+YdSA*ՐCqeK9ǤJz_/C'G:3o8Z'qOWO7=/muy>پ$ln"e *%IõrZD|m'$w/~edb$m=%z6I_İsR6;ʼn1V]'OT2BMPNPcmpNzLmi6dn7X*4ս#b~tMKTG3cܷ[Ok;,^wSkd<+ɢž_[&;'ȻVm1KPyٌx9Dq(ja>cٌ:s ÚPn*V\v'4ńEsqݬټ7$Y)%R> ]ʄL0vL7z븾ݤfݲ(S$pqn4ēɲ6 Y|S_܃~KDHGaL9wW\\S =  @-w @0 Ъ]"Qsu""*?!鈬ŭ! :߷\#Sn SV-oI |vt ["s{ŭ\aSʟV'G{ k?`4$kGmxDlsuINIchG8O86j2ϝ-Bm\gM=i {tZB.Ny@`=(V:&@JS 4g譅aj[4IZ/gBq,MSO &!r^:K![oKEi•70;ƕqD4d$@;]BTQ&"zj OvMij`,I>@%G&rKV1p+NNܪ| I$\ f#kmCLF>DW1|>:]Q}|Pz %d7%'>aYeh{@Ӗ/uճ}\dJ}51IsbCH^}U@CdM,K5;Q׿!wIGP*B_v!P&OK3naNרM^WѡRDû.7 Ysq2oҩ fg25ژEir@!Fu0so۪#N0#VZݼ_sZtW& z@0" x@2M);;,N&K:]Yw1iy*Cscqiu@[ 3 Қ0IZՠ䓶,!@")"f$ }W,@Q'xv?͌`EcV<huuFs[10}9C.qE/;e@Qdj,DÞԂ "O7 \ȧ 'j\RLd I4,CAmĞJe[>oʪASw9 /?~_mlLFiWTf0_@$1[E+ hkNm~[dX}yAy[5`OY$<ړ`+hT v2 ʔ]c,d#îzX P ,l/k'-\o,1 U`nF 1}/aӝA/ʷ%ݼw X=@d(EGE}z~$߁6 &iQ$(Uf:-m*Q 7b.7+6τ%sƁ5EcZ[z1U Y'[C;ꬒ:gq=Ȟ{njVNKr ռ%Ӝү}Soy25;Ϊj&] )B1R XfBV.)A<aEIIzʅP X,FRh 8gA6S0W%?Cd=v_ ; JPs?C*]䈕4Si  .xBn.wAʸv"JŴj _},C=>op-F)AB%Nj{?`h^ o&BNi"䴔dLb&4ۙ7t#`1]X&ak^yoX7$tZRd;åܔt{{sV8vY7St53+1|u<{ʉ-Sel͂D5ܡVّ5mA)zأMNJ^YiPPz!4KkPZYfl`3梶S<έ t>vrꗂNb ROM~54+MhCW/KfH+4zQϓ&3&&2k(VG8 Ȅnse1<),iIX4Oe֯3FIg,El'7Bp1¢3D2XInIv9ک|u˗@tGhc҄PhmJ=X c,}phc皪UBɴ'VC4Cpl|I`KӷdsC'|6z2n0n8E&4<{[66Ur\bv6$,A!B볂& ƈiacL D |.- at&Rs៝2t8$R-QA2uOP~3)Mt DZ", 'iG^҄f,E$.p1:#ɖ 1jJ0l~cg}Z˪և&&u7?U}H%M HMN3o/`MmFFC-^>F<(HnF_K#Ab4< a:RtcyB)d٩3}++:]m| ~2ᡙrlG; Т#KR b)}iRpx $OQ J#P[3u>Yn0$jC F8=]/tk$)9o܋gN49ٲW%d45"9IZFnL|ϿUcEa9Lߑ`vq=t&"4bIC]Ac}%簩r["4I:KI}`»GIO%kJ#Ul> )E}]!EC#˻ .?aT~dN!m͇)>+^Ðݐmڒ_bI'̘j"`,ov4f h4r;Z e%(i$T aj7 <þ --Kܠ`vӌ*SԘ"'[$5^dFH.F3\}ڲ_{ZyVuxDPf< %YW%񜲻 LglH=cuiW ;#|*~2d旡qc.#U2:וuTN4 ?cgXhƃέ$SC9T.-:F"^% ;ɳ1{Y7%au& viertn"n';Er}AQ+H$nA2bz0q>_ݎ设d. JՍ"hǯZ'ɀ| 㗺􍙞Hy2&߮<_S6N9Vbsoo>z6µ)ȵ)x|O&#SԮ|W)$[7w{/zcdnQ&vIfC@ [ HQ:\^ sEmv[( %XHV?hMd x9eJP"TsO Q==,*[#7_ӱ!i<Q-5Q0C<{,paF=Bحو7b/qM~zOdi{1ug^gBVq!訩eUӪ4Ѱ##zCТ&Sm-1"beߗA+in]z!x/qȪdQM4}S&G;lX.h*Z,%?F2~(gZ=9}\}kQ4l-aNqhgxbJw>qjCD%|=˴M41CER@aÏEIm U=L+lRm2Mla|oA^?'{|2Nshg$BGZ^H?r\{<d~t}aCMj4Aᣗ uTY![wu˧K3Ŭ*ھM;^]ôQh=)=~l#`swS>GbcZ1.LeSQ%wVk8/0+ШB5j3ƃƫ8Dz\TK̀Πjz} u91/>"D\U-=rC*#As (߬<+5Ri+鸽ZӦB(/7*INxgj ov/ QP&MB>jM_i`QInlewv Mv <xg(MC?R#C*$Vtlhwct~ K*@5H# jQO@˯es Дh8!hM-D52?kf-z/a_@ 8 `ӑno/& ᐗ .jEb4Yη]$LXߦXIQU+ h B +V@/tu7kJ *tԿAZ\C~jvSD.AAZ?<[fH.tHJ<ΔyXl\W槷Qu!ł4.p_;KZ3s*^q.. c3qw9S ؙj )lZZȑG5 Ѭ8VPd"iy[+ (6ogF_,4ڧK? ?!X7 Z؏D*P0bRc^ Q!`BO_~s թa ~ dE!|MknCɶLW Bd{:ۛje*uN(AmrxLg#<\a ܢn []c<#@#d lg#2GߞrX:άIJfS嶚0)9=‹Bg|t͟t`ӃĀK]{ϰ4!$58}]fnX /L]v˛ NyWjf~D' m$6Ơ@P߄m Z3j,9M,T't &M4&"-G^,Gwx$Aۡm 8ZZ\-,A$QfWa,VXi;]G$ŹizƁi!O5qQ&]9<=H 7>K J<(U> wSMtYi6a auUJmRpBgwI=ݯ|# lVd;dGq[U+MI?cYoYM !D`;v8Dq:#{qJGaFE אnf\v&kw@Ljn/=89 2+SFjԜZ_/4{Qyp4 X|DhIE<XB|P?ʮ?^ufHV9Ʀ%\{5Y4,a[=r[Jүb-1We(Q a2S)f*16PN:7#@.)J܃ Qy;oDE! ևst}\I؀@5"2as do ᔮ=ܭ?f/}gyДucZz8Z{d]Ztr0xIP2ɭ|MBkZQl'{Z␀ȑ{d&9[>DA80 E!֙Bu5O~YE[-^OY"${W,WBكᷤ0x4U艷•\$LibSϞ)fRIiX=2je|mF LDSw1s!&MI9e}] wBB4+Ah{j;%yṱC]׽YX}]Fѷ_`/3IpRE xq s`*I&X}"|i0`ο%WaAw7GS˻^E|`x!T4ˤUB6zqGGscFLтE3fTKD@=JJx@>sE\mSC..4; W)>X&k%ʜ`U}rbJ#QD朹Lx{T9GfYB@2XCsmQZRםOEpJSIrϨ_lt j{j"ҩ-d Lo9Sr`tFB9ڞ䍦uRk-|7!CQPr?DsڙMAlJZLjs7ž"c+P$-rN-#vVQeۧRxz3G_j fR' ى}4?? 5*LЬ;j7vctLFs5/$o&/ПV7Z.VUbN)-Jy mf5p߷,7}|]0lrd6UXV&;%y&RSp3ÌeP=áG8YʒF5*Ml>UUɛ]BHexeP>XSsei7Ȱ4'Zߠ(E7N;ݗcAdVRyw->Y:`Mt0L-$:k' 2;* u*_\֣-isO?QȗJc㎱"\J!>(<4U n4=+d<ŧ{k)ċfZM[ y5=F1f4߮J"swWyշ|Q=i8hU"QTb)O\s/4t3h\ uE<&ͶU$(ZD XIЗ#[b[F6QǍ*&4B-sV_HHNlVYH! y,FzxM7[λE7)gN;_<31 64?ndXSlnh~yZApj}`'! y]b [%RbKR'ᄦ^COYYp2Hb?}#Fu%g'_KoߛSNT ckkL_eecnU.%<(u z!^\SfŦ}\B{0WVg+\f+eB62\dÎځ=(DYF{FJoa1Sz67*mkxg4}tic3v:\FlCvWǺJcK?Bw;D ^\}ռ#>UJ pm..cP'?25tARh|Cy0g1h {Njv/4xet^.A #+%|7|+EUE͈+>pddl4xKA\Ldё%+[D@X.?ThƑQ1_=M.*nZwZvI->ox $-*Z4Dɍ\{ØL9u1W`)u'üd'P^`iԦN|ͯ/8`5\$:WOV䪼wC^Wƻ?4+3+ZhUMC~a0§K-, {X~3V78 FO{:* 1VӍha}OP7OLnNp-amo:kpo\lJlэ{X"'h OXyw 0eZ`V%l?ͦWǷpozhȿ-HDF^ xz(Z'6meŴ0d:v0qܩlAJЪ.f<%"ԙz־6KA#]MegW=S~>b70a9ol+:+OT:YI84ELVgMgґH O޴pMsoA2Nko5+nakc)Zt螲COkIWJ*F.to3Y#̞Igߊ8J&wzq70q{} 4 Z,39z䭪9)M閆ܾɄ|b@M*>oԓ7Qr.UcIf,7 4zM!̤hy40f[kwZC} 51h'~W,8<[OT*zp{"׊>dM%j2oafݙNݡCݨq}4BT67gS&Z'뿓O 8)?"ƊnUu myW+yGYHg%8f[ׅYXl;X&3a6TѕN&y`AK^Jp%na{3~ze :sFmHxEw#ق 6K-J x7]?.Eڎn'Mi gULTݦ:!\<LQ1wS"96_Ɗ/t[cFA?r82Ʈ?QiôXnLЃ`~kU_E$%v#4ec\}"-;"  3gvM{*t#-œPveinY޶/ -\"u.܈4TR' WNyΙYAj Y*K v|kƻR'oՙ/ kr QQ|j '=LGwEP *JXNkzAx3=|yԻt%g6\^bkAڇzLrS՗)7I7K+ g%]R)9l6(%烙.*桦 S5gvH#< Fso= UaI&L VθKD%.l+.1 ^2p5@"3)gC,S2vE~xq+ToZe=GWj ͞rh<4za1#Z%U Ӿ~v@f =Q5ͷ%v?e4% pexrdj"/ɄhQ%0f,B0 [h.}TR ^3нEh~E.TOoH$Ix, FAd #UXM,VJ18<̋@(fx3^!IqV,{aqBR̟jD ͫ_ qpep̘ wG^1x~\gU-ݜc[bu46wIo6dfػ_4Ʊ36mvC z\<_{>ف~g 7K,CNQc@L5dM!g@U,ӥDǪ s*XsTcrX4#*nv%Wp\0:#5WBsY_'CsdCŸxEEiv$ө9(sND~*B2 S{u'ڣM^x7PvɕĹ6C &zU= M(!k*m)DG vuօH{0pa&sVz[® )uaD?Z@giq $L.9xQrk7@5{^Igmӎ zOdsJn}ɌdWx^\`aEq; 0ed|C>BC#Z*5T:q-u}P( @6_HR\nj6**&:%{PȼLX?E:u"h1qL+ѫ{󋖅u,fHsKqe]\Z;-hdr.:je=m Wp3.87("k }=N6ƶVCf}`z=;E}{ 1SkˇRLl.O$A`pA2?t8ÈDbtE b?\G뤓vacbضҒ*\4uBha_T'KeA>0 }W`͗.(Jh-A uIi7% E.uNgAn7=8yRKQu^$'·MpciԌ_^&r"<4V<`"QAހDdPm o(N.l(PD#Ser%l+HoM'ODis<!E,%rXcXV@EĮjœc@_~ʘOɨd2zv̷YT6}+%K0H%p V}_fq D6{>nd?SnOd6*@ȆW{Ɇө?+ H:u67 -m&^Zrɱ&s }ZFEê;K;5 1R^Ux ڍ"U(LאLZ{) }j)&ďoܷ0 菿VyUy^ kDF;YRY19 =}#nc<6a} N!oaL(jTӒ2'5y'6;S%[\v^7)ui_y 0thD2 J&Y&gM bo &f7̐gpG( zm;N=ߠdwq,EVe#b ؃1ʧ& tKanG _zw#4Z5_ҘQ,5 ;VK37B0}H)I+1$,ThI4~@pH,}W(/ C>6$gjntcAjfrN]YX9HW2Qt&+u i o$8Zx/dL0O(){8mFI#^p9rfqחZ? ۡr)H!Etc#cľ#b($ 6ɃCvf}dy7}`qAn&=ckZs@F#YdbkȰI[bD_ !Y**Ę=r.y8w9*hbBITaGJR̩)d%Prz&o,ڿJJ3[Ljr(~AH Vt&)؟1?ڥc{\`7Ţzq05Rxَ F: O Dޞ :圇7~}^D#\ uؤdTNǻ9*K!ŵbd7 1o :|Фu+gI"8߲(xѹrW=NewAhQĔc0DݗK-yhR&*K!uXF$X9~FWӸstڰ{ Kܿ(qϯc|fwmA-65@MxcBFUްdcD@M(_aӴgj^fj [Q3Z1-~y[Zk[&$tMU GIZw*C{Qm"FVy8pCMl6 p$ T}TBR CGoVY]~\R4({Z%51֒N81^b1榯o_s0`tI \S2 lNJN/oīh o(z+ nΛÕ0n_qË?1$\W]M+c} LctbL7Dһ7τrØKug@N$7F^/3ⅳj{Z6I87f"V9(^YcX RS8o8rlYY@ HFwX{1@ۛs[S,`% թ-pF7@ĕX޾LYy0P~^+z/-<*h1KۖV}؏ uoK0Up 56H~l' ?.Jvw7),zH(gq ACWㆩ_PTR1 ŲKgvZn jz;W +ĊڑGr)GONm[7-m[O:CHED|2Iٗ.Pg$7;vܜφlJ|!oUƕaRn=1jSI̓ixoڃ%%8z2-ɬӓɜMxQk]+v}]PZ&5%.|}ǣrLfh4Dr't(7 ] u 틗5~S%@\7PN6@zsq%Pe03h0`MT$Tw *>F<2KJߞo7 (GP7(j+džvQɣ-PqQztww0 m{q\2Y~9{*󴸫x*rr˽P=ہ\ (3ሹ)f~!_:&]4iŎwp tl]Ù\ap ["3e[7B%/=}FK2Vx<]i.]:S)j~&0>C/oR\[t=aoC47n9G/NK"hNqG΂֯"@&M&с2>V0JVE n(@(0'/̰{JA3V _$kr {ƶ[P8hN0`ǰ`-QmG~la )9} L$"@@)f2Ik'>)Xn5I;sv`A{ 6^,Div y͈E¢8s>vdQm$ӄb+%Ғz~/iIR!VĭzMrx, HfYUߠήG!x.c{)jk\,4v<ͦ:4[Po\G: í(G5<aT2m*[USZϲU!l, >tʶ(FUb{+xTWx>$;S;<ӹkZo$&/}(8S\<$~W [Qժn|@!ԦR§ 8܍i"}ϚPXNS:V-?/DS͞FĔc8 J/ l5r3/Y:TێmOHŠ[?Jy9%IYDMX $AP:ġ57H-SwyQhb|6Âf $Ąv`9S R^Ķ*~ߢvkjC,(P8ėn~2?Nayjf90qb»^MC7BRKj q奆d6itenNr(Awk@bEB?r׼Ֆ 0 ^xLd%o+o ϪY J *-F)D?zQx:z,r/gU)Zs' "C>i>b&L&3L-:o4LVknMAS{H2q9TFNQۮjA1(kм5?qEFò=T>aMexQ&%6rDI7Z [lTIK!;z}?3T|1($aP%K62Oz߬sji8 [C}yݨ4!*if7̯d˫2c68Bi"ª({z\JdU/FQ _1Vڥ#8hV t\#>x-6zvY;Q,FMTo/%ƈ,C!דd*kiBYNր7#=[9x?%ob'߇{v='Lj1(R~wֹ@NCş/mao7w"לV's~JQ c,W54fT'2B;w8\٣f#Xc_-fiSXd(& 6& 0')~R\tա؄(KoKq$gp67-TojR&A6åF*BQ`vGI\0Eʑ @rW؁7Viy.6;0Uj-vpҚFȵ4NҗH$QPK,Ȇ/.]4Sl}tĿ&zG(%´T=pSe$;[zL/ldxyMb>2JM/ďyX;sv~5:2n LDp^B*Je.@]$oiIW9'0/VJ}ĚFZtEdM$ԻjOX3'T 5̥`H U0LU>ːF3sKP ծ9zjNN>r+Un| 6̰ͪLkɬr& eE뾷LkIOsBIL=lm1EmJ>p$?⒎>jJlyC`oǍWd{UId|,3c8Ɗz'(Hk\QJ2:DqT_xA-R$pŠ5*_ax̤HUx@v]3{Nc#;PGx-eM\9=&??0)W4@gFef#E^f*Rᅯ7g-52xDݵ>egKowBctn R]?ʨ9۰I;pk@y*Ҹ#OOuv߱Xli ya6k SوD oC 0u>34%Q&kXfB<t/%4{O [:ǡzQisE1Eo u&^~% zJ Cҕd%&[қdFؖndѱŦn{F\>Bv* d+>25OȢ* $S/-;qLkfOfysr>X&D}L"ܾޅ gu!$%Z//C+r{׶(Su8(ش5j")[Du%2t.+۠d!WYŨ²Ze+xW,[a%BC-UW]d\q.0%w,4MHUaO+eS#Ǐ.T2l,^[]hU&5|ؙdଭ Qctꂙ&э)Eg?"tL*yހ1q¦$ t]eX=ݦ/`.nQDYOfr}w5>$=z tq2|?P Ko6oށ^)mFn6|fYԖ/ҹUz)@Ye<{]þ0vI{N!Qoԗ5oéUv $̬+@X;:H _ժ1p-ܟoe@FoIu|X.L*`V.XF :~&u ^h0Ja"i즆d V3 B˕V֢l;_Vf{ W3ʨZuW'#7㳉_G_Sc=8w 1cώ-}M"(s{JCKCI5X*6Nv aM{Km.#tXNZΘAHHRK_{xaܠ`O3GO)d9nQ|^/a#z JTYYZ*BTxOuGdINagw VʗU^16C2 %.0 4*ŀfF:E58@pj^Lg4aKZq$ڦle>A*m ZqN+q-za .2m TSOoqxKCm ݓd|y6z:? 2F EJe~J/GbyEл:wotۇsWRR a#c(!0Rh6<8;=%V9V 2`(`o=ͥw5zU {thMR|.(N}.nP(7۾;bH7O0N ݼh^]@.PHӂsM>Н: 'V #N!'B)igFI.+߲׾d{!ۚgPWdGt1k69su[G p-ӤDRs֢\STT[6}bR|D!Te3$[986p/UBޏ@g9 j^"qj5G, ̞̹Pw49Dv yhJ5(1QE_nbGcmqs9^x+DȚ;D6iD_%ݱI(_<_:eoba:^'ok+ ̶VlÆ)_8NW:lƴ]6ი}kBʃ$&%m6Rn9++#*%Y5֬=~V.1< yVG`BR"jk4͙ͩlyF'̗K7~aǝxUGOy1Dh(nqCIB 'ekH2&-k!z'kW?3qұJl>%2M~|c 6w @J`g[_eIQ}fN0k;ߔ+(}YPÂИ)%Q=7E, ; kqܮ!!Oez&WK)i~WۊK4>/ًr!WW٨=I@9d@-9iX1:wGOs=U+k׷ 1b jI՞`M?otM\t p},[Aᨳ7,4R  >ggUSʫ@Z z[J$~tTSB/iNٌ*.9} T=T{5X /}FouxB Ve_+.cq=o+}ƺ< ڵWbz%#\,k0˱#=$(p*>{Ő\5 Xǣ!7+R̆q-2@ ߻0 l'9 FP肌ަh&9ٳ0>]5EoEXs/c;uA R4E@Y4Zvuz lNfS z ZٳR095Іl1s|YLщrBz6.0'x?#d*ӣ̊BDNGgN{C;?h|x_a 7M_^Lɕ$~Xt/㏉pa 5#H̛*x j }n(\zTv?Զ*~rH.elgvY2 ijpK!M1*VCm<2=/]4dF68P#Z/PAD#@4+ uZ+Yk!Pcw,!&sG^?3 p8@#4-w<%ӟ J[&Ee遅 S4y|_DžE{:DII6_AO~,&SR^q}Xzp3q%|uǃ"L$Yέlbk t]5~â7r-XΟ-C9Ur ִ+sD 'q`?b0j!޷a dٛdg>ޗj@HDNT@ݽ]$Y,Ȝ=,w!hUrōA\[(onQ{"'[fn§Se vx}6B[gn<~˃GUg6&K1,R,&Rb@d%B,L&< .E'%_<ٕBé{[o;>?ԗI.NJE5N|rƽvkCo#8[p(c :7eg]7\L~-$g3 ?z :zaR+N)\4ˈ3~0{/u| Л 24-JNzF4|_s.GpKx 6P%_z{ևkцGN7GP)M!a1Nܿ  < $8>?Cv@Ak*.#.4pG5 *YmY~xDtOsVJJ-a9&{hEiװ,$Ĥ0"ZʂD2JEõj |]axg1"ߛSDw?3WUǰFǠaeY;UHGҖ@JԈPT$`1f&ݼg&~t 2Xi5,Gؠ~'9ҹn oŨ@eѝ@ԌMnjQN`8tעࢁ6l/\a8*~E_`c- d扺Gq%BS:lp~*YCʘFK@uLcj"ZMrFxK6=J s!Է"6z x>?uډ~ivRj1,A+I[?> Vnec4 }hD~aK4ͅS0vd4 OLsN53ؗX <Z!>;<Coj<e&g7qOTסczwX#RZĺ=N8\?I~ǻwQ7~-@Ðu5]Fs}NHN ?S|bK!p;qDg ؓʑŧZ26Z"_mt=b4+YIK2R2B'~5$D+k}RH!3}P]>[¸9Ws.o-vǻk!W! SpڻYP ,".}#3ׂWg{Y\C/Ί{N-!T]M oty,9x>{lW-I vNAhπ.[L=ߕOi nDPqP#2$l?GU'e f1|׸\ j+ym:(虒y#xa٬\3E&vs<ۚfx ܤx ׫݋@C4IpJ9f)wzorkiƄx.$©ͅ ҵ4}kcizKm@yV)iUo7N$ާeQM<( f2p~ ͨ0>5s%3rRJm&X4AwK,-._P}󮹨 YlSGV7&qp1J $fG}ZG?K'"ϯO= AEborWy>"d[tKU0 &c= Z/?̹ʯ˺3"#vbhA%L2:s5 ļzgEh}"l/Q"ɥן(,m~"t7rUf1o.<:=PA9&3ob APO$ǐF6EG#\H/y6]h<Kڲf`~3_*I'_~ A' L6%ùv 86p!XX:v=ԟPF8M#= 3&qp63iq8G/Sy6ϗ"xT܂d Y2?S97ǖKdt 1RBS"MVHRNuzy0e'kJpTn|ϭzV O+[~6ԣ9Gk0D.e&DCJ@Fugc:W2ƨ>A|x9Y2"^>Cl E:G.mi .U섁 AG `$迍OtKy 4a]rJֶJW*{8B)0G]V;D15hHQD.!Nk]v9'n>xo^˥;Ь7W^;5!SzC  {{oVYXT}tѠ_>re*L'S/4K2(\kgYl#x cEU")2F#?+<㝑-Ү_D#<ɓ\avQ3 wd:t#4鬵imVb,\X]Wr>%.,X:l)E5{ ~ TxMb)aN;=8?%, ϯHlSyszjS+>}ϟtV$ mUR!.i^փY`GB { <WgQśf6'9ؾ0L; ,FgdgR9 _I"0Bna:?tA Ƌ)"χf+ ˆI$1Ž&B'upF?zLk'nv6nc ?E8\iT?Q]WP *c ^m\9~YEf ʀc}|\hK յD8cB;#=p&W|ė]7N j[ܰh{ )XEuVU8k5 $8)X8DjsgZȼd܉$JMɽ"~n $%d'٤:7B#F}9!'>!=[ )JWRDrmJvӞxHe,aέh--h.:2_ڍj8LdJ0$a}\>e- *eR[\$J!TA`M_[kZd[ HݧizpZ `jvevM:LwXһ#e]\Tf}*HLɾ O;vSrKsd b@4l9 15rT7sG >Vۈ$d~p\0Y;*w27mPԃs7* IBRFfv\f=M4OXupV >H`+eP *,[(ޥkCwf)4qqB1JpxAӴrI#.fj_N}x8$wb^ԋ'kfd4kEvSޭ&UVV,@k=vb*.F$r+qLeDdXNna0XHRIl:ts<=x+uQ>Hc=&ٗ*vw;(%q"ɭ})Ԯ`\XYijV~3@$zeJ[fM4}_џ|yz%+ZV30; hz"8cC-Iv .^7@>43Thy(3 V}ӓ(eY e+}A$/mmLn/I8jHY׉uꔼi־W"}>hZ<بs/!^;%B {2g6UdsS'V5 zW5‰]Dvb畴)4ۗz[o WTAX);?d,G[2\ &C[[]9c tSC5˂ú@gaRbxV c/+XL3BI\wqBhw;gy3sD:T֖p[HG3GSƏ ǚ+{a@GqBYڮE 0$$? 9í>l j>[/ MճJШ wJyGy&@ɈR7vd+a4οPW@U;_20fsKr \hb/ɩ/Kз4O#ӏ\!4JֲpN'Vd-~Ka`%}k&`jކc5J8]6+I/u;xWo˾ozbkѸ6-'fMRdiZRjP?]xQ0^qvaԇ'ia*f2YOGPkM*fB0s&%UXhR4^L[-FS.NHuD,|7.C{uIf%D\Ӹ]Yod/N\$B9{oLm@jY4) |kN<:."I4`{a v;N*%dt`^0u=Bt1Bt$:U7]nI)"jB׭2ȣ@]hg]f *4.T0ux4=Ίyb+?\.Ba<ނԝ~Ǩ<%¶!&pC//is}4 X*=Z8. t ey# ņ!eƃەJ:K;p4(_Cj7g<|cqyͲ>\3Q,xT ViIMZ0YIOZ!1'Ҵ6rCI7EJD l<35&O> Lm:mO\Pl۹'Sh<';͓`t)yN(ɜ}(q;z-<7trpdb;/6E ݹ|1U!zZm4־(L M~v>NHB+siI eQgnU xkk j fL.I*H؏|s!5LJKS=1|`{ mHۣ#ՀT@?(Ggl\ϪM}6'̀.Ag1 X[gFq|q jd~/c+ ߥ)B)8:zV9B^{8@YX[}f}}21q~^p.O44Xrw-N,6 뉣XR )d$^8>m/q^(:lϨ6;c1cd 9Yj?--Bg$MO1ϥPK윿|1ɯAkYC"^M}es""ޮU)^ۺ3{PYFVD˵-8n )2A'g~9#"",E3HLɯJfr(Xۘ| U}`g}ES2:O)^cPW ؽ`uɗG+2a|i|k=)gKĵ~+VI< &>d1%@2xYjXi-$(лX\CLakģ3E|n*8$&35j ˚hSS8@LyoB&t9/0+kV(Vn"Liu=cauHfe!{^ yiHC߶WYVu:Ot ]caQ; kHk̬jQ Hٮ4t֠ޡ9vA?aA3︢{?Sޯ_1؍DvChtBm|؏;WŰ|qv'E (*H_BVqX:O}#™nP1]/0k 61X©KXy4n3wm'kO2B1yoFW 1.V;.c`fR28L~@&>Ł(1?%'fZb0@b=Qy(;hp0I„K5{{{ Dpc._= 73qsU~u6p Y"eUm1F)X1hhcnNf*YRM5Ic 8T ^8'*/ٷ*DxcB.=ϷIayʀnUZ_gq1t/H0 *4 I:cp;.3&Uz2,K#qyZȾKF &dV9 pSrH+ٯ?ʁ[TsK+{W\~C}:+*4*gVr;O#D ᇸCTLuOM@PS?ߔ =Z6g%3UhV&Y=Ecy^8$xuth7GEHN=W% (pWz(kudFWX'm:EiBjnќI%Z|[5fZwbaоGXT)Thp$abOy;( # 昢Gʭm*Vcc p>H Sچol "p,$ȆsqG1ƶnk1oV9Xj٥A1?>0݄i%fCF*<nOnaxPk`ڰcwvc[!< ;N|!!U~F(,t[KFZ`vPm迃Xd#VӦklL˂{YS-YMF)],=',"JfS`#7 g\'"LDU[\=bRWnEZHXŧ /Ku3:;HZc 6Ed Ip03qpِ¶ҡVTpw}Gt+h(ֳk0urܽ۴iga188a! ϋ:mA1Yd'&Tlw͍ѯ@]s'?7\db l(+-: ww! ,{YZCE0,4m/TMx+C\Bby+A $C}aG>u*o!TY U2 Tz}RXR0yXXX74k"$NHJ73 < ^31PʭK)euP2Qq^`K+6=c-Y<zzvP V 됈 %q1&Bъζ'?nɭ43tBn/(+1BfJa71 4! y;=Ii=j,'%G7__;ηB d= Q$.y!@%@AwZq*# `-02/J;},u5+'UcJC(R9>hXmqtJYμ&Kͧۀz%aiG>t45qE> ՉhdL͇Oeft>8(p8iIvgFYrhM=Qm9woF#db= PѶ3o@Q泶/+IuLؠ(ٳeqLFdɺ]̍ I"< ~T}䯂veF' VZ'Чl$=v6ڦ sOa;pv_rث(j|a%왞>OިD쫧-50A!QE8- Ɔ7m̜$4`}(_{ؕ5`Kr{y9ҁZ zX4%e<,gS^or?CZ{?q@>Bꆗ{1beZ@|RCMv9nRdvv_.t <af#vXd47o aۺJD,%P0-I41,0ƒ2x§n1|&;P`BfKr(/%pz4Nk^|HPAmjERRV  Z3}2jttx"SPGfBKVɡ*pD}əbM /<'c^M@bp5jeЎSie^T4b KvKQj)aj1cJKqǀ2iyB):}ќM1PS32㴴|8`FJ{XH>pEwgi+Ipx\|'X53$ƮW-ͼ Կ 3tJWF9L^;a 1k49z=<ĵhyc?20؟A χ'_IECb+)$ko&+jU<7Yu|.W|EԩԘJfp) $n`>ۺ]~dcEӅ+X$ymhՉ2r @*WzxdN:WtxPqߠ1JjOW{ü*pD$­ˎŤjKCUǥ']`Q&IYck2x=}OaIV㜎?6kin#CTM:uq)0 &;gV .ĸNTvً<#WG@f~Z*խ(8Z@〳?D s.v$9jz4A4K HN ؚ F*@0QVMt攇3[8BM"/EܘMp++01;Wc+|@}fߙQylˏ`*JxWkf2WB5Y aY>5 Db[q„E:S߬d91kxeT4`/Z)YǝJJHj ^y_recQPp&Fkjk~B`(&ii.c{:rVi|ޔq wCI?[ `䕴-OLy/ m"jӽY-`H=yӹ۷-*+Lp}[GN-"aJJ'.[?G I>QtkO|bW9[AJPp4V}}˖q dЈ~BDTe%;,i&6 )aO őb=g_ئ$rL,1+Y䴛I;d@4Pق+[o.\U/R-@xDҺ( z$0|o`f^ߍKXŠYNK~?^-[FX:zMsC%Vc==v@b&u-V| }_[?Y|{eY$f\Hj>7pAoGȝ^WL3)X4җMό +kX,K\c:0_GC+f1딂K+U15aŢ9ogʀӆm>F%LQq^ yM5u֑cƲpF>Lk6yrӗ}Nd~`{_EYE3|z'-nIaSS Mlv!'!ΖbwB4}{=fZ ϧ﫴&V7,mjDE`]"t(ScT6h;icYͰyg`PB<`|F&pb ΪZ^mtO/ζ&W;Ut[6c*-0p'j/4[$d_(-Bda(֝fS t-yt 9_)KA(`=}Y둩ABD\4Ln7m^iB-HumiG=Jnr,ϲkGWLZ)~xz.X3{܍I1. wl.vԆ(B@'=zE](~ωV%eOZk /Pև!W1rd(j,:Eufx5_dmvmxߠo.ΏǟJ!eK*|i6XϮz~8BҜq-hHבijpiRDB)jmw_&57Xý"̀zei' "wY6͵W\a i8|yVXPN'e6"ƳͿZP|4˧Ɵ6V!hf嶙<&S QS*gC P=!`v+'Cf E$ihҴJDU m]DY#)jgη9K .~xi/]~{6)o2˯^Y PŘ*i9uS_lרi";քK0ƿ A6fΙH(+IGvm~|p|jFx?:#dMM^A%5-eѽK4~ޣAt+r0"?q1d 5a*Q ݊%SCW$ ^gWʈnjbZ>(Oy+̨}D1G|@1C灍=JQ\̯>Z&>(?O ٱh}OZڨءj  ,5љ!fYfp#)n(20j5C^e;~<ߘYznj"Dt۬n%+~ҵ>*o!q&Yԕș3!?{\m,O l0|$n.̲j!uUT; dQ S54MzS2`5jN>,HLa1"ܒ|Bn ؝Gީ*9I[.,݉'Dqԏhm*7{Ot&hι33iJiLQ@GS9da?t8|Y~-n]lL&Vk\SDlzHK¤t ban]v$#@V 6چs.P7$䕁CH2< 9"_eG4B)rHX"`̈́PZH^Ug^hPؖ  ѕz[ Ƹ).maG] -^/6Ʃj;,aGk9iQsIG_k+z$V1 `"l›L/Edm&Uյ6mz#?8"6Jp=ΐ7Fv=Ef F֢qIVrB|Kfiw|,,c~:v-Y{9\ف[2-:#Se1.Vy6Uʶ%V ̙_W%: ĭߗ #6M?K`a4.;HgN"':2MNclsjKˀVX9*k <&+ 3 szDW!ĆqK/n_~!֤`<ha[Ejl| H\grkwHܪBL u $+g#:D6;G*PcSxz׺J)xΠ6{sO7am8I0-0(䊻bKJFmmRpP'3&v:Lp[ȁ/5o(y*8?7P2 ۉiMbz%"/XR/aIJaAC showw/W= ~勺DQ$qCWN7c%WCc?TAȸ-jКjY&t#嫤)ԜoDhy|I^BoЦ&EW0TsIڵfiPZaOi~wLMdْ?x't7ۺ#j7*_$XiG_gD] M (O htegvI{6{׏C%]ܩy;۵Ո Em_peP(k(Lkxsp`Ϣ^Ys>J!䖮=ߊ*Ǫ$!l߷X8bQԊ>_nSҸZ۪׼}'ݨkCm).A|9wUӳ]ZӥDpÅOVȔ&R^veEu}w1nkvT-`c2mhQخV>_Tb]M{w[ڠB3ӊtTy7ɗ*ޒ;_R̃"T:VP'9v^:?dC TKzR]e2-ZDxNA?v+`?ˡ-{@, c`XӦ]cnkԚ\SM\DhrDiB).1H( pƨD@TgGT/$ ^ ~)v3Ω)Q( !"K8~1P!E6YkYX?.rwi?4#qgG";E}KHZ2٦bxɎ$N@1 x`)B8hea. Q@ԜLe@уNotasa!! p?3;9\WOjP $9$m~ ByۃTZ{e x Uz;#EEalcZ+I6}.MDjp2=7J$bsVXqf&*U2F!{/e6'Z o# n*Z|Wi/b 5C=tCU1ŕG G'G2Wrx댬@H h}!l_ Y"C<(+g7SաǦFVàO,&vx$u05n13Xkm.ȱOIubLj?M.PY߆/#[Ot#"d p Q oYgItC.C 'I)ǕJ_&9Yz6M(bJhpEd6"1K>P-^sX'5эUF^l+BBUAm3J?Y9dYW݃*aJfސ)¢׹p49aBޡKNKT'[ؖCC>Qh_[<J/Dq?![^¦Y"WQAu12,~vd8~{dNA2Vj:gKZ`0rygsNpw! e%t4]A>&w vɧ"#/v4df[۲20C)?:2XZf9? ă1mnȆi$t%IuJc{Ԍ=W?I8zcEi MM:K +LyeJY(Ϝ*uFvNGk>3k5 W9ʀ#t{bX\u .`I[6r+ 4? 0 j<`Ƶ8ҿ$>nppZdDl$3B DWsrݛyH5N*/>vŅL˳J-횀ˏcsRanOWIQ.K4Zu4ֹc-T[xLVN & {KGoK( W@XXG2:J\M+XJ֧{ԦA `2-y- (ȳW*ytq!.H,jsS.8)sܸxtr(-+DѿEpI*ff_qg7=~ۼQ: 2/ BpTPmO;q-H jXE"qQKyyOlɘ_y&!,2{FW-:+7M\黵 |. .,]mZ0gIb8Í{c5Z(4U|mXJE[Y7Kcnc f ћ^Q`L)ڎWeNwѹgvGS) To[<ntM0e3=A\|i>̶]!ꦰDeo#>䧮1*Z^!{V6y@v0([6=T`TM[X@*d~+;4Ѵ{mqPVĹa1}jH:¹u'ɾ u|2UǛ a j MvD3` G_'5hG1X9sA|(o24['~>ƼJgW \9(EgKnGO>/NV8Œz| $ sM~OYiwaR.9ha\$Խq4TpON5+g5zA|Z G@/1m!C[? )NfS7VW֞ItVJ&ƪ+<̒~qJ}ʐ`wʟΔ؍'nW%[Nu7F;M`pZ%;0 Z^<IB:<H˨6eRVă|+c7R#uq5wS_ۙ mP &T15PUk~Wt%0q6P>0+h˳B&d×8-!tzn`!@Dzu?k78CY ;=Cl@3S;ݔJF jmOw4烮8ENŽ X,@<H%Iȸ\hGAVÑ1ϫMX}y)h0Ví? YC[s? @9zXx@D`H@6pz|-0foaHcIcLryA /k@=˜!zFP(fSnY e=a3wYB~F"jxR&.Lnu(25_9K6I=L>MӳZ3Nt:x ,^w;]׼չ lff0i 1+/Pw5ZAu kϗB|'+ J7$qO(⤙󖥣-Cq$^*[NF.̤i{ Sښr53^5~%'.|^ uU/޶G.a;rٿ$`UkɔA신pgX.(Ϭ6d.Gc>+f51yK yI Rt_n nn rc {h6H˲=X3L߬P/@޷~gNL4Q~fLIgjlgtlAp@ir%FQl;py*Ie)kb.$6uwަip p#ET*.22 EAJ `'"[_Ec pdNs .d?#.6[)RR;!NW3e2eA') Xa~LYςgZAG(&2P+F lݶ[bpV.nחjȞĎ` /5']  ]2!wSG8(vT@m){`$zćm s};.EzGcf ȯ O d\Hǂ4@Qv}Kã[Җ*V#{`@BnSݤN [4)81+%RQ*谛Yt<"):eG-#<#d4 2]%4nqǏ*kG/GXp2zvn͘`vi'$vp<74} Zy9ԯ$"+*H-3O x VUDFR>L9s+M y?Z,Mok5-Oiu23Ex6EFAk徶GoFBot5OȠk4UAIc~Ju8]Q=Flj`l%?so3<̒5, 7J'4C;v(>3~'a`\w4nbBwXE5u #6\`%Qq rwk=PĒ-⩋_)/ȫJƎN ] 'iLzZD#tZC+BL?z^5Nk>37Z huRu82M3~ 5rT>q$QƖt67JIED]ssAhur:J6rbg`s8 ӻt]{T7% T;,pq˪^Jdr? mr<S>38eגUr/f$ 9qoY㜾أOܹ3!s2ssC#lYp*U@OcGGKNV`O6cetwy\M4Ƈ>K$}ؾ`H*J;0kJd=*μs aO &C F/FV=vG(=jv;P*]: BGX.PԌ2$4 wSwT_>/E}*jW'Âz1;φZ6>S7hQҥҩxO9A68 9{Ƽ)>)b6ҶU*`-&:Z E%=bZ-S pKū˭-"''JIރ^HrO: qw=Fо3y@1qi(XY}Asʉ^y*_ЗǗe5mp#~ îpQLJ;SPi!޺'R܏m@ojn:(Mj  `k@d5'fU*$U;H2)6J-EHaW{dɣ# EBhcfao{%OՎa>KYhqR-[r=J9(+(6]6inj>UT(CJo?_5].>6ΩeҞ}J@uDg3Ig%g:mg,{SkT,ckc'Zl<8^7VT|\2J,T\=}%mJ=m"y;c !`֯3s.g}.{/\!'['$:oy_ rm)(wS֏ F64 rqѭĵ=/^UG1tB=}M捶[DTүn$ fKBy=M@EiC7;Dtc~k`B8HCS! W%|كg gB-`*9fiB~1+]3P\%ŏ!9]jMU{yXr;K( }|NRcL8fuOt" ԃH2*arFBQ$rpI2 apoΐ# T Y0B44FdNO^t烂fgyÑrb=ɳL7D s vuv(<+IXK r?]úmV0?iz)) y_wlYi6x1Cr S~˩"ɛyPRٳ\v/ 3v)Ja 8@PE ^ ȵ5q:UmAf-ΈT^>5A$6 .3(PŭA։%KЏm.Qt0Y@2 gF{P-8@1#s%@1?uNm}ɓPƱ9徾MHg,p9>k1S ` ?~`Ј[(_{vqu*UU hurnY#mC-H֬r<'͓%iPEw/6_KZ8".:qxDT8uM snWDR߇{9{I]ޱxht8R_#G9O ޝ|X0J>GVp5~=r.)VaY$|EpO`fP]y3_P`8U~~Q/ Bt@Dzd&rCYٰX5n. l.,jA*chE3Mcދf,|k{.WXqڹ?H\!EKuRyhQu0MGp F'7yJA:ڣӻ=K{pە+ΎLhR6LTϳwnQ!g^&,o67 ԕLٚ KCtΉd\ʁ9L@8TX$.HBYP|ByA2E>#JǺ|jEUsoP-ƽ7 HјuȄ=qШQ#DtnA!((6 Kp_4G(028U0+ ܦl };>F`԰*=hl g-:XaCZaƁE*(z[dȄ%}Zޏ{IJ7.V}eKnXy'?nCbA+R9^hLsaclРø>Z.M<&h ] _bzt=$A#AFIa+FQcqߘD\Amﵰ#B8?cX^DPTS HxԂGRD9}\n.X֕;2ӤV:>ēp}調"ξJ1f;2g~eKVD>Ǐ/&"B&jiqiyѯb#=+] ·UgH~l w QَqOeXsj;@uPܲS銸-LKm "=ߦA~85J n;t05rU π>R0Hm F~Ci\{?|ǯTb3˞BOcC$J_u(.+l$xxzʑEu_&']({N7u%VЖ},I+Q7dh-])L\r s4jqb L{aҋ\o\#wם-wB$MWX_fK2Aǽq-b3@iRYkmxz $V K[~×fK,2'RDYe(d(F2ͳ-{% stӥ\a6@C6<4"4zM@{xYӵs]btЉEtR$7n3`S@ d1ݳ8tCٵJq,lDӌ^TL-k13d]+/6Bܒg JYê[uJ,Ǘm:Rꩈ> Bԇ&HH,`뷂j8=! a >PUjZj!o7J,Kak~A'x 8ϟymBw/?A;Úҳ^._,^`e<+ؔaW٣(baGAU,̵CJ $}Ӡd./Μ*L߷U8県 D4n9[:ƉC@Md`/e3wD޾l 9eJI d-6G0 萄m[E[\zФw?p$5XT.0"|%Jd;w|]iBDư]gA2 `HQi:S<4>^Ijl.KJ_T@+PZO"pS?Y9 #k}9U?1|C]IOL~8ۂҽO7u+oEnfr-quq* o#}84Ϗ7 1tw[;c$疯tBl.%,G"6iJja%Ծqd]ךm)`ž[S.tWnCN5/#0#J6H*y}gh.G&Ws`7 EZ/qkw=<`( 4qfDg_T@gg$qՓp&'MHKⲟmև^G*&BnF(gnI>M|G*[@L?ߵF91IA3WQcp_0m <ס yU.tdrX( M/P;{4aN xr4B669NACJZV,{Ic@<[2YxXcNy\B lHP_˺>RCۻso7;QW!fnhQ002%wE'h痼qž1-nNyH\X]xyJu^ٝVwq 7OzcPÓMҹK O(4QFpJ[L|Xo 3U{J+$NH@Wsõ0D,qɝyFl+:%[fqC0vkH/4pYT&rڞ_薶MQu.>iBt'AS*lϟ䕛s{W%+FK hs U[qNY :t}OV>&+ĶZE٠j>b]6Kd`}DsOn^@wl! Aj87,HlpN硓1;T >reulAo=x>l3,+T<ZIK:24r|`ڿE*M6W϶oU*`YcpqW&(u!i/=q$F8rCZ񛘤w-M$EY7E]M*w]5V&h>'Ag[>[rP:i,foc< 7}FؒyͼH:`ьC `j7ʗ~ߺ(f.Lz68j+-62X4?4j\m0F ``SCÚ]sRg7xnQ:Ref-W+/?͢>jN+3_;#Mk嶰etDZcdzR;kї&"g b,UhFr(q?a˙V 脆~U<<`ho|)٬''Ϋ- 8\)S{f3FUO6Du,.̊];~!IDT+ti:O05z0*|y\aдFx"j-qlI \WCW@f(k J u2~}e[auiJ2'|5=D Dg+ʞ7I3Oj[~b+ź9a`$WՅmQ捷]?5SL+]`: nYPTc`E}2>(PùT(ZW?]!Ih(JƐ+@]z P(^}7E(1|}[ eE6<@aj@?i̵b%#V\uZW,B硔!DҔȔ;)(NMȪb;2|#G~|U"h9S_Y 칚i{ g%r' f] 8GdyEAhۉk9WzgV@=%ꔲҢ7߻h>ŦJդq1;xd:gJ%A$ZD]E8 {:$}P !nI4&j'&i wv; s L=&iD^b$m.w].uбZ3Q}HCnrl~>c3/hGX=K2د>h VӁ]S&A3-y. `dԯ nS?%mx1\VuO,rKb-8@EwRr[ wtzĺ vȮ;8,X(IS/C(d`oo2މ҉X/[- ΐ"6&;M:I H7~{4PVZ"_U+v:Z K𤗦;z zP d{F&o_rM-#j@0t]"dgrOo]).a_)t3oo[32sC?H+ZYxԦ^ QLx#YBWANj{@Fi2z4 l_~ SLZhk+K.ͪlQc}1gOW,2sb( mhE xLiٗ bƢг3pf!=|(I<ʨ/y3F_>Flr< k}d`G +NtNSx–ܨ=4!@w cjRJ}Vdᑎ)|ZXcC%2rVb6Ǥ>4*g:'5KQE[ `bҺy:_唱͇ǙV)~o9JY ;~4&_rF1(өK`f#V&: q\1ƛ?hxz!G|ώ+dGeYv2BgYNCQ6|tEs)6v0f[3Q׈7x-{6\{Ajջ1]u$jVcYF<*!:0Wش؆}tQ&79s:Gp9^hUB;1AyJ#u `h4$•%k!Cp{0  [e Q *k%zY?C1pItL$R8rڃN~%ߴa!4 }{AoJlͿ0 {}?-7fys•ĿZ4(Fݐ!^I5FmoYHJ'y $)skv53ܜ{LΫoD]Kq@cWn{ZZq;"vDk7)7HE(4Ǖ&iCչS9dhep+ڟ(6vIRdןppCz#!ZsFcbU#lr2vԧ Y(P/\+l?$_ =WIj ^wBF8E Z'y4 b4WrFHG(0QaGJxҹ{?Fm0n=+п&R˦ M\>H?X߉g`-UAr%%K (pB?lbs+WqxE.\ѥܗ`~7^bgƓ. 2VU!zulHEFmyX>?F٦,!PErcBt'p>f<{n@D0nϙ\`uSs3KX+H]N*,I|xY?R`=##H)KvЍ^Xmk;C@}q8`ϕ%["zy hLK'dye{Nc pD) OHI/#ZZVy[Col50Pnyvmh702&$(oCvwŚC6#hXK'M?FVdv*8!X썅h~@|6]\v&matf61jĔ 8eXoމ˲ECϻ2ơv_\YDP+1|z!/YQGzu&w`ANV728c ]l$n[$<J爎<Ļ0,!(' 2OYy0+ @ B_Sy?ع>=n8 12r#gMgI*VUI'hwj$!z3f'73@`2~Y'.}~:*֔u4CS@HʭD-J̳oIhgo`d rg|b/ V~0U85߾%PȒa@C}L3H⓽R+wќu*=e'.s(Iy(}{b 4[uSJoy0 0#^0ֹGy~úΉq@È\BLM9ުkb+&nFg*Jx[tز3]k#ɫ.yIV"ㅬ! ֬;4RcϬ]#z;+ ؼUTy܊+{~{QBS^/!Ht23;H@5&L|`(5rHu}ꃉ>_6@G?GF}0,%2C9g=qv0ikh,$[\aNؕ@P08f9"$T\*GUHYy*f&7"x$?g.FXnWŠa>KSJ9ጸ YNeD`Q߉x>N_+%826bv `gR*?f99fD#u꒝Uu=zj~`vTD{_!2Ex1!#b}L``<1D?g"BCo2{tbe!aQ?vBI|h46Xe) íub3|.d:hzQF<Ӡ}u5>OB@;-N#xQf1k۫_f3@s쮠Pc V[\o;)4 ^/JBmy)>wտ_ۚ*ǩEF<6}Rjsv{6߬iJuuE~*^a(eKv/*v\Z^$)S]ԥl)\lNįTǖzHhkL^3u 3k7G;|M˪t`#T>~ <$aQʋ{A}CG<̑fn!ҐNaʕ#纸5*7y~ݢ}TT~ԋ:WkUUmd -ϨGj~zfxOEvӴ ]ռvUX߹t2s)RIjd%$ >H[ɲ5*Hv,4`N#ShLY ڎm(|DWP\#X4Xat:8ꖶu"_h XC0]DaO@&wAQN7x|!vʬ-xׄ%_e3X$ձ#e% ['\T Qg4ؓ,C1؜ J|s0n1 IB>26W ÓknSqB=GͷzC5jNjTرnXzXQPk5~iS \MqRk8cK`]Π+=,by Ř)9q:P@LQ"*?%J߽B3jDw򌙢K꿕-#Tbu3P?/ԂC+9s5L%l̙C>n1+'Avw- ;'UQ7Ƿj(PR.RMScX%aqb0Awwȳ>26'GoYn3ߖI^ a%MZ. |%Z @+Z==Ü#hG~M?PȷXPܧ~2$ls(Z_KڏEgSd]qa"O6> d. ÏJ?(JzB^G. 9~ֱ?1u)TY!n.? B }#bJ #o{o:"_A\QәeU-idBjs==GHr}mHmOvYO\ *1 jȶȈs|${uL2Aыw^FQXSUKU:+ ɤ(EvO6 qdAkwnah2{杪mXf;r/F8bS%^=g#ggV"lYV"MH/O <'>@FH@{n?& i/KL KЭ*v 5xHBN-#_q^PrR649乧.*([?҅3mqۨL?]!{("4,ή!Rlh\F1 h?[)qV'>.+p2iʁ' 5E$l8@bC>QIRِA?4#ly-߅2F)jkr5̛A\*h EO. 1-m순oɦ-їM^&6<ҒaJ[?lKl;fA\BG=I Wq\a:G^CCK I1`>Y`Iž.OJ `_*,9wZ{'4>-BH`Una̒44g;_ph%S(8 lC.G_^M2{ ?..X 4&k~s zGkÐׅe x~6.Hzl8VyVЎ=ey+ xBT4p-J̞]GrA* 3 ;!}.y.L ~[`5wɴ0҈2 )k5"-G/%ع$nn)|r9fIr( [#}ݧ=p'7ٔHO^'6CQ`Ъq@ᖼ#tp)OZZ~g./0 n.3l!rV3H;2xei\GDZ'!8B\ =J.(>1şs&>7٣'Gs6Npf˂ߣ8qrY! e*g MC!1l1;l 68 6=1!p#Owrr1;,ff9BGS$sWkzUkeJ6Kq&UV*O3[O}}OQۗW>`\HI8cV*,(]JQ!SNBmp_e(tC,'IO$nE s3ܝ/RPΘ^PZ@-W60A}ukK~-1͑X- U+"D}2[]T` zŀ$.pU/ٹh| qd3;P2W;e-/5YŌլ[ P>wcG4<.a.y=}X]AYt P/C*÷pCLxᛯ [ ti_L&>n];`꘶eCdVTv퓢ail'ci@K Orvu4$%Qz? aAHlrf\2*kߑCĤnA/M8%tFLgpSHL,` z}$t+}nיM+>ipy^G(Q.n*ۅ MZri(x_f~8K 6C8Gi ;~ɵoINu]-tc0ۦ#%`p!xD1 IdgQ\;Bk-h{yz}Y.`+Y *}ndƙ bЎf wd̥'!%_:-mw.!Džm# yo\WKFskkZ%\QNY~Yw]-z-IR8 we X'Yݕ@}?E 31Q4yKΗ[9sWh/+INjbXY (p\6'dBT\Z E-vc!D ;Z4DÀN]OY uʲt7ws<; lU 2Uo.9,@ʿXb:*]$ѿWDxUWR*l:I&_31sөG Uof7}A3FPxyͽE $/vq"=FvIi*/8m2ylPY_Z>!Яʮ"6P&t!DL-w/PxadQw m# "II8HQTx HMYŠ4P.LcQxv%t~ }c>ۧH`ZDN;9,BE:I -_tY9 #r:kK'W(?"&IRqӚ l@qP׾H)X r&r{0+]$UGC1'9e i~m.㵔ջ# 7Vxy(X~'/Ӆ/&o+BT#q݆f 4!ض08p*޼#yZZu +;] ~IoD;3 ph_+?̲{N7iM H5˂}hJWq4V~ho~A8u<3̐{.7{ RCe174(0SSpjq `Dt59XOWK_PSG..w[֕ѐ Pn/!&CsC񻟻981]g )Tc9syT֩8=sF. e8lnVt氲+Qg^j1qgʈThy|< W:S2739׾p"T| Y3->3h]jp? %U>Pfzg?4!sV@iϹ߂hmdP(@VatV%0"qD>pw-n%PF xhP26 cŘZtc?+*Y͉yA4G<:OYX"ASYrSvՌQiYnݹLNTQˑ닷*PZ1= \ X@]EWI{u_]m̢oAkKyP  ~Yh |c,nڞ|:e DrM^DhWOヌ^i-Ƿ(E>2*Tuې/+^4xZgf:.h@t410evQ壣Pԣ-v=ܓĽVbώwGP m3ŐPc;=7[~%&q{`+kcKU}U)U촏;A[bSGlQF~sC)k Qi565q W):j.t:%c?ʧ %=o0N&X-{LcxeާvkO;ƭg?Mqz 7#HV> `+'y&MkL|`﫠v;!N)3(>JQ`Ȏ0ۿ "$.m IRtxoe$áp.|je:h?ߢUPgM"Yٌ(4F#%Z٧:PH%R*P3 c:q.".xw~4<wU3+Iicvn${t0\&%IjA8FΏlI aesʯXTR%sCY~**SyɊ{F!9ĊU낙A=9?d.h=ngU  bt;5Jv5 RH A>(`OfS`48Y\2rsna6mUOKS@d)uv?xG Xc{KHw#r`#+5BJέ~Dt KJ8P ``o\|țXE aReQjT)ȸ`z0$'5V~ܰuoSⰳWPE3pQB༩uR̕7F? >mdjމĢ 4E Cyg@t*ok-edQx`|1}-ל TB1tO;nIk1SibWd C]=ӓ9 $U(ڡ⛲[आAeeDqDA:IQ&LH8=՛LVe]+e?4_Dlq!4e>[AALܗfps;i;+=h =?EYuL(^NbױSc'3%~yHz;}. NNJ=>}qs^2֡}mTQgSF8B梲nuWWz:FE&!S< 1뎖Yc~Gz}SѱuN}R ]W>U i;f缉Wz%-5ɝ\\ 8^}cFwm%CM ]{'#9Ȍy{BQHs2&2sMjՕo]I_ߤzZocT5 g3<"86͝N.H[qyE$%ʌܲHI%Zv# ̙v7,M?.lm8R􁌪#\&GY&:(mԏs `7׺M̷x7z;P|D}?9W5;ߏt;T´D1!ȳ.j %eIBљKrDޒ,0\"*^㼉M,Ӭ686lI wD1J 9`: >!9Eٙ0%k6WCпt+?I?eGgϢ'@N(ai ǫ`syKx)&ҊgtZ@) #+d5Rq cc2,^rڹc#|>7=q}/:pt?Txĕvk ~#O(^)`6U؈=9} ^7^& LOlg{% S ~yNچC#<+TFLIgſUF؏Re]XAWgHZh੤m`d$gJe 9xtפbQ]u3 ?B̻? K㥰j'`c[xwԖ(C"ZFDW-/+.Uwϊrs)Tq塢.7eJ ?.u4UU#uFApQA"FLf* >)L<+V"O5|E`qN-t_3Չ(#:${O*=+a|tEzc\yAN_X ˺S 6tj4 . i ]ۗCh#&ju, =q˹WnE<֊W2fob|M(G~ t騮w|MǴ3绶*_j v%y1e6UH2 :AdێoШt4Z9G9v PoIv,:i1+Y (76zB^>VSc*28ں16 偭jY,aPشRsp#rtR&YzShG;J@= +mHOi;ʝc;;CW?zN'`±Mepa9w|6un :,e[\^FBc97Qh. >plȔ03F 6엇B;;M5/I/ bLrS"@|r];+zrO ^yآt.mz|9IP r !Ro_sA /%l<]Wt΍{hŰ&ip/^lfj05vٜ|7| rt[}bB% %tǯiŚ pM-"*mPhG7s$OMdC˒yUw Q+n0` (i?I%QgªV> 7\xCbjk[%lYF Ҷn÷ד@rXJno$!w/NZ"uu;4ǽI\xF.%3Ov@mxzmm^ /y?V`Eh]iCx$)D4B2!9昸]m]]W̿ٸ '+bimxm@ijbI}- ژ_#W4}mVy5kz XEƣWL&H&ȗ]'vν:յbh@E@-fW*nWz &M ,\Pe|$`J]ڛ!ќuK6źE&@k dW^gcn?X ?aHZE~G7e~Z 7'B7[ɠM#gNPnӢjk0M#_+:ɅW̱X>c(O  hN/&!N`nK,=ݽ)ԟxU_7 8 Uppc Q& E #K){T;%eW ~tA}~fE%E_)S@V8UĚ̌fw9 \DSFE?eZbAgQC0U\QF;?ΩjpOWMf_bƕ9}; ]2,bs;^qe뇅4@ob>a]^'k6mßdTZh9ɂ}x:N ,Kh]@"A0V'+sC>[ʪ9OҠ;vQm]ơ.̧X΀%=(Tk1Q Ϥ*Q^ G"Vߴtk0c,U@ v8y j.gM`pG NIW{<p6XrE^7D"t,\Y|jU\/Gn(yf>%wV*SuC+v㨆-U#i[."J{I- rVVa)-ʎI W8ی|U7ruy~c'c 9$ZW {V^pX> E8OX\D(-nA=ŏQPN8 c s@|I;41EHsz6y/qũTh)cce^LS0'yKzUp'OQΙKԀl1cΖ2)R\W,UuE莘\듍Ԥ(Qo|T Fс\M- G]g.3󉧫"q͌B+PbD`i(YA^@A+aBU8e fDžBYh!\),'vBFUpQZ />ZT9($!ܨ+!OpsB @"ad ;xŬp*;IإI(Byu՛ 9խ1B L-Ɲz7S6hf B@]Ua+Y)"+ 1u'L[ۚ)Ms@ceDFW>%،pEb1ڻӦ$gT5yVbYuDP~ b9򠺸𺯽)HU7lЊjAXh"|6,y2Z~Z|ZlַR5k7S;qr Iy } e!Ђ*.[`Iqۜ*KoXِ7,Ye /vs^kA`ػ GAE 5u ,^0ު.~8k"=}iv@*e06dMF fӽ&е p,YI{;AIƑ]F'3<;r[?7]gc?]=rToB d>52$>TqZim€{ DheOG}LwV4f!w?BU`>qIkpUҨ& <7u[ @zG2[ˣqT`(k5u )S;L7VWYObVg2A|X7An n=aU #®a-T/)&Qv#˥}N úZEb)}zN?E.M7ؿ!NukI$pTӫUj\%@1ue*:I$]&6Z(ldPV`OKK(יQ ZFxu=(B` <)^,O7ٻ[7E p$ P+\UxGשS_P $-zk}bƕE^n!cM5| /X^rKj)Xj3P P/yYa& A~ " '\2툶 =n0$: :D 凅.)/#4o%i),w V ! ZRWzh<ͩhn?WT*+}'TdE"m (k 4&EBS_ %#|f+`ppd}ku]grTxw;̭'aKulekƉiI&AG"`N)0OCeJ9V*wO?š7Ȍ^u!ǴB^-LԳT[^xd⮋'#!Z$gCT->Rҙ170T%  L>+|^ t<ӽE rM2V*6σ03}2qрэfgmpV-xd@ {*CI uZk@ŀB4#4̌ah'oc.-0淍O,%K'ON =-e@9k k'Qf1 O<мvR;D/ R¸j4EW>Ù2#ye 8'RDb]9&4 VWaSԤdaR[&K3l#2B_%V{Т[KR X89oc^f~FG3LsJђ5d}rF^y:OπEA>'/!w!ʕtlgq[Rmè6Q4U8ٙgϗLһ}SmXVvFKV ;YQG!BFMrW:+~ wh^|WԵYSPlYQ] l7/˽:p!I!x9ƋK5fl FߧaAU |:Qi`QVfXZ*_OCRˏ6ID1[EA'ܥr=NMSߒGO'_@q~LQo3<2|.T픭#h1á) zHglyR\i^khl߽6fǺѼL9^NֿHm 4(]cmYR+vQO<#缺7 p~.Z}UI(2ں`iH'3ifv Nؒȗ+cQg>038ve&Fk*;봷9_i@NS>ٟ,A7`z_1'i0* lTiz ʎl6WˮNAp+JՍ?l[iM|xi7|$x=0S8w!-qH,RĦC:z+ș )ܭ5{[y(@OͿ.0#;[K \7Vi1P׽e8д { 0k[09Gw*l=ErnER,t}vvS|bl* %Zc(fOIC8aB s0p\9Zg꜐cO\X#*t@?Ta!S6MNr'y`Y> Fmнcw*LǷ]ûb|3WӕS N|IߢE 8Jl)o8jX/\=,+{}N=;iքy6FH  tcHmv)o֐g˦I.#H"av7~0Dk>}e++:CJƣzf&[ &jʝxbK5xyέ[a*Ȥ٢əP}SK0e#6L˵ 0@J;߹N~b7" EUѼ I\#-ʬpòi 'tZxi:'T$AS2m! Ftc{mU-p|?ql0@\Pl]ui|i}"i3g`כ&Ge zItMYU }"Fccwj q 7l"# }UTh!6:l#D[ë~OD%Ce<9Tg ̷oXƴXZ-9H(?Oe2meBmVT:T!Ji&V.Ct70J6D7 ]OA Lքc&p:rq("Z;z}%'R,RjScᗂ00|q4g E¹e(TRJv(Rb7BP|=ת}Ҡg%m1hMܩ #q] ԯ{%!ѭQ/[*):5KPٻ`ָセWRk6E_BQ'eW$`'Q+8>gGK4/YJ?ӱLQS&?BBrE( J{BϠB~f7y/;oH8x8An- ա6KĎc3ˡH0j<'w4̖+wӄޢ_e #/fS1&@Ere;6k 55T1n#H$.ФV&!U>0B 䦚,RuMV!JwӦn3E(IH뾸* gDB(UJv^]w— Q~\mS(r8%phvS7.ȿyђm]y3AAr6| \5[WxTcȀ] l~2l 3#KQ5j䇢ؑ w0$$;14sxI"ANxik^ 9-|Ǒ Es<<$VO`ǐ܋O!<4Cggx"P.(jZ45NQ]q>":Ԓmr6_g t^FQ74iu"!ȎUФ'&T\2ʆ,l߆aq.P#+/<ezzFԎ;޻@,KE.~@@Uㅚ[|rlбu^?Z?"1eU' I,_C;j2+05aoC$Z;>9*m9(z : qdc8)]Ɔ?10ɻ] ]5ݠy f$TT'x8m~jM54qV"'?fũ& \*9VI/oڛirjz~< M&{VO04%="V+,qC%M{rT5H&)M#Ab&E1KrEHgdQmy:'6) j\e@ˇyKb4]礝 x*'/z8_(u~E_Ͷ ^du;P X0ະ.>ϼQ -e=L -(ٚ@'Ǥ:rQ4nCLBgUq1幱pڐ?uL8d~|IL>"#'eZ](͜H1 8}K:iAYzY_H!g`Hf^iBQg.2S&=Af& {+(M^d| > 3uh܃a؞M[8Fϭ# N`/Y2um 8MqwECA=0f JA'?=Nu{dNDe Ҕ|fi/uL/I߳=-.+ #Jo`T!2^bPӕ3rǜ^A h UΛ6ApK)z癙hz 3m\4cgm*8d+M%:d^[83RsR*2!Ra6/KL :ʋ#$s#y;V z;&ǴF>fƽݳ㫤ҭp&±2i%0ȉ8 N{}q %Y5-_<[?' Gpx"-ѽJ~P"2Q1d~q'gԚgzRGl KҘrrcU[U?0? 7 Խ"=K_GHh 1FaUs͡1eUͶ}/?Nu;K`e@/<-)Fғ2mB?9|fd[cOV @ˇ!Pv0^J_ѩ:UwE͍n~ߑMQRWw/YF M?*7OZo'ԇDq&;~4|n7p(N9}iFk2hM i `P`0|.x+&Mg>/[hh](lsB)\6AB:_n9Mlɇ3Xe@OfgT)6hD'߿\o8ng?n9G(^38:A0F`&Zx٨~{8 ?",睄I)DGy: w%H  ׳{s,C3dv؀}b"QBvbz[0hY|f /7EF8TP{a)'P0 g8?,}A9p%BdGؙ%޸|wy;Fޑ^f9tiYYۣP⸛-\x7Cks , o6`/F/+^= Ys!fe8v"[YakVrh5`СUjMDe`$9wi #y<.S}8Tg=LZ#]%o-״$4YE!-jݡ,x pfmWyn4>ےVuoB{5Ycۇ GޠT3w}ͦTnJ#`1͆{Gl`GXp7NE"."26$l < jo竂Bx;v;[*KcXY|1e|iƞ]z+f'|L+wM\c hcn*Wo ZEl7 m5+_J@ܩ6?c_*uJ^E\ޛX4FLҥj%>d*<ɽoy@ G0'ɨ:J Vʭvc6㾪rgvtw/A7eUy7Jјjn4 oX7bHTP[à/DO9IJ+.6)U[\WY {$a;,S1g ǛnHrܻ$}lbgW\}! Dֳ3On2)3O)`)zgm9 (z)@(6!SY3 5c\C%^0AQWš,!E4s'$pU8As\ <7̰ѻA=]d@Z{HZnT_9C>n\+5nh|f7y4h@E{%Ahqck@ -PЎs~LNck6WD`qT (ÿc{mM0DtHWh;|v-Wqd׼&J: \ſuʷx01 9_ uVĦ]4@j>2t TRVrK p:VαխP2=:lhh~@7Fa)~,I&O_?u$w4W foC^mԘ=9Uu~#3R ]9z?|gUz"FT':l?GyMoYdw#sРqZ0&#`|QkHp ׺_sB(u'e}8I8?oUV3u2'GI R-#[QXp ,Vߠ@CzS]+睈u_SޙPo'O禪6eߌAoSz|=8ոZ6<-Yr]y턼Ԇgũ P{e,ߦqXSr蕞ic- =u ȉzCO b'(>\_~6Gz&,q wvSa'^tCw>3m~)vj/ps\dC ĆX6 !K{,rjs cC \OV *Ų@JLf&% $mJLU9#~0zU4CӦRj31]C4U52]Y#9ʎٖiN]7Xp]]A}bAeIs ^!HqYS{Vt˱OxzC72E1!KIf)hG2` *UkC^=QIB'5̧-1b-@)^lEUӡSG8QccW Ejp(  ~VHv]rŰA^ Q5ʸ˺I=#cKpQV܄s 훲~֟拏.B-v4iF Zx91^*Fv ;CCJtǠx4ZwSئZ6hzH/kv)6_; ȝEROc٘y̑}@C8jKbC}hTEN=X?1ٔdaidvL FA! l &PMv'CgJt{Y +ଫ.4r(7it.Ok[hyl V!c1" r򢠥V9.mF2}˞f0,A(BѧjVɈ6t76o|A\N&о(=mZOa^+iIYv s{l%""Y WSIuU):j|$=RjzͻCCzW}^-@uV>!4sq^I|Zw1vKޡ'Ox*?L%A%āP-vpi-MϽ}Ul07d[J +x &X>_ڹej*ErQ20=w2H; pϢt۩G`\ `~>MD/׋ܯ;js9DNev*tp>>PTtЏn8?蠤Cޝpnͣ3Q8 R%{fyb-u\'t;/ 9 zկ5&MXH.1< !=9Lw:rdۡUoTl9xzac_`9XS cY6.G=ܣܑ =~[ @pTD+m R\XisQ}~=Qe !5ٵQ>vb vt|dVT`'&YR~\µzCˌ5ug/cb D4So0i_hHOM(P5LM'$wsdůFQuwٳcO:`i#c`{SU"e:v- ulkb_'YZ>~~U6,b7iD˦S1u!c`*8d;'꿂O}"8=cudYKHR6ô_U_}d "F10XX ᯨia*Uz8;IEeֽ``c٫o)Sr< Q}o;rpUj! #Fx);.Ϋ,=(=ԡ—RB<6^ty9i c9&-?\TӷL h\mɾ67?Ii[ иz㴉}bc׻zEj/Vy ; JdU\5(0k>NOkoat;,(t0nR Ggkuw]p˵U$x@N@koFKDsrON(fcRb%(Ią(%>qWpNcXۇ8 gF[w_(kJ.e.Ze[:„“6_|V'_׆tc*c (UN1|tm%J0=nu 4]<)"IAi(:'$}\bͳ+C\Ϥ_Dz-X}Cy]0J+R#]lRR8r_ɯOFƑN8.]M 8-uȪ(`}~xm/z `딧IdGN-Ŷ{EBұS"]m$8^)9JFИKư^tӔX7o%EeVXD/d` v_0οY{% C`Gt ڰӐԕCǰIO}T沼>۵c>TN]{\+c=ռ[MrSʒ0ґ+w(܁# pI_\7f.qy^ ˵)ːFw8Dx'Łpa` ЀȞ3V`c *|E+Rmy_a(v =osJ˜ APLj(;y+_U\kqS͔ƻ[/JL!⦾}Q^PڦH2ᷞkAx7,lIҵ8 ۗ*ێ:ZLAT2ZrOZLnҭ:٘Yh|mu2>·5]WfZMo4qʧc{<#~/E+Xz:'/ba+"yqx3JjET!SOv.WSdONe3ʑ9hT*Y?`Wg@wuk ߗNH0,pW) j˷W.T+7щś}؊?׬-z-bCښ}-bOTcxӶpKիc;+ZJk3H-y ҾJ8jof(QL0|&LeeÅQiRXg}"?) jޢcHL7\SyR&kFu6Tvg*XD}7]u>;Vݼj{aFIӠڂ^rϏ IQ_$g'@NM]M M1B4Ù ΜGp뛰5Uƿ4:6藨 YZ6Ke,t_{ju#!|3)_6s] tהuO4@[4OeA NgK7cXoA1TWbZ%i6_$6̊S*AqJ?Ut/CP=y#N ,[/'>GpwИV:u*Um}!Pڰ~*v1t)%e.rˊrؖ=oK?$脞B?M)K)VI*hn4hcͽ7_-X'9._J繬p+Ft/܃ uH\T2: mj`+mX+1.DPLa[-1qdaɦL±0$ rg P*dbT=9'M*wVO!M;iv-C묦շãq#Ji>~,)L6S{XMp%&'63mFW |tep]}t_"Z٢Dk3pĖ@[WYVvk\ѿ j!w¸Y(8z.379 Sz~P:YL̯hAo$tnv1Jn9?Ep7C3f, +]p$f)۝G [ʉmjE$t1ac}E+J RF3ـArE1s[~kn(xb$43EhH:^3Lї8:!2<:6%T@*;' {P ;SˍB0^gBc=|{ koYsm/`v?\P]DoVY#`U_ʓ=οes$6rY+&޽"ā|&%!H $yמ6vAnKdh1ſ֯:1:Ael)={``&\S{g,8D}#~|V\r*/PSʀ-$MONM&uoQSw^A,…\jTA+^"o a a8J0} 9;DS#SVhh04}czhө~_Gsڲul9E "щְ^iT( &" 0bg 9ᗨcx2k%Pޭq4-L$nM ?" #43v=ʻn1&1N6R$+㺳)o\*кj t!5R+!&ޡt,} mʼii_Oؼ !" X$Z @7?dgfy#Ov(E/b+P+얃U;^%lN{^'T!be6w93V/U[`\K@(- T1!*G√ATB SdL[`_&q*t.Z$[c EL ڡ$zav.W= K z&TF[Wȸ@4v QKN~⷗⻹fAQnf{)Φ(*-3x՞LyN9뗐 /1Ɠ~aD#4|$ߝ\({oX7gey̋.V37DIy킑!>^t\= ؃ǒ&p0-ft#fFNiCYr,LaB@+3${ڀ{wᆎ}'o:%N4JjνٖÓkЙ-nG(AmVeU 9PWQ/~5 ^g}r9Kh}=ϋ+pfV'd6~ ` 25QힱH ;qFߎpy]&3[u9v+BHE4Ek*yBBж^u~4ɣj4D8s Y?q ƫBil+V:`ճ{8%I`,fўC) L uYqN`nw clfi\ k JKH~S1`ߎ.V5P?jLn4vخL_yYGah5* (gsT-a۸޳֑G؇&D顳E6p$_?n2sJ/&$c/7Z|C8EGclJG5+4F-ӵh[rp",]T#XڝSlw9쌸N(@#xZ8Tr-ے xU.0UN-8]r6 u <:wt>lHR4=Rf_i5vRߌlXo~50Tؒ=sT4|;eOoA(,4c  "?Ɗ|MpT*AZSIkpe0dE{9[ڎg,W+P23e {|9Յn{N9)AWb0D50 Aph"ĝ 6Ė y8Fg,+ZߖeHqhF ohSa:Qy#n**N|iX":pG$2p X+}@\I0 zͮ$&/)*ke0}^e 1Rǡ|"e7,gԻF'  qNLiQԁ 3@aRozumb)<(a EI+րA Siď2xNOs-]tNEa<{+ &@bT'84'έn$1Ġ Gˇi0yn8Pgfv[ WVn9IPiߪ[1yGOFx eiAoczKv$(tbfM{1T^ uu(r& #}qCGQ |\jڌct[4REGQlg ߮kmᔭ _R}Unt2E})O/@ MچWsԺ:Zq& _{]%Hw9Pߓlό)QH}䳾,fem̌xnߢ)ݯ'ڈf-!rJ >Fxdlqno); m27xٗt%ƾ.IƟZFL:mJZO0$xrî5+WazV̅4ffl(Y,pLl6F{vK~O):3${KJ=qSt‹o LFG<<9]]/j$ v $?]-ԺxKM8@Zh¶K9h~rd$rhocڒ%r(fv?k۳ +R xMla[7yNgÂ?=US ؝XJV"(I.5$돘>z  aR?wWp(D Z ztd6e F b@j^@S:e4,iCM$M2=sF7K ,|Mw^{𠶘_mRW#ZR"@{w::Өn9D}vuё8p/$+ XxiC\y5A8{oq%^%GzOD Ex-iCuiL轫;)Ћ;T7VgøtޙScjH̐* R.Oq5/~l#B]/P.'#E2ΉIӔi.Syv 8w`!#˱sYqᛞ=~2(Y*_i]'Jf,&:lx+6딆v%e\VKI[LpNHZ:߱`S͓,[,pD>{}Vϼc{|G1ng|ir<3~gG Bz@uFԽ>Ui!]R|\&~ui[`>d"]Pq{ kSap=l@.;Ds=;WK2Yd>jNY::ʝ?`ͽюjk&+W-ME-1|{u @QmBS*+dK_;FĀLn'|Mo>|/Zb^MRM: VEC(NQ[M.w$d zeI 궈kv.9TE0LX+;8DqJU4g;UH7[+Zp :٪]X,m@ ):!ݾKC?8ZoZ֨qGs(ջ7,.iGt,.DDI^۳6N+ZtKVG1ɓ'"4nj]NHVhF7Go-{=` /n+Km$%ur>%ʣټ!-6T@A(0|Mb`ѥ3~*nS›R,"a!#0CFU7VHUA!Ant <1%`#+ǤIB"-bIB2.df=Nm߫c(MBtߗMqboO[I"B:M4[={dD-t&)n*,Zcnp0`5\O.N7[G$ [Vfp:yMDJlIkQz>pQ|{/ w377gOD>!++63̭|(09^9v ;Sۨ_<}idxa@g'j_Y%1zmyE/`R=Z0 (.U/njd- sdXEr9[ui |o?E ;OXtQP*@pm5m"4 eY4h Nv#vB8/ ԿULz'83R9Z*oO?G~ )N1 [I t0}t`i^ &p8Hgu)ҕ= mb62aOۢd{3/7MAzWr\Sg;r][(|O*xCށ8GgS4^`jeKm.n ű' H@KmU[$8N-5-1&f]?? FPm\Y&}!BץZ/~R6iڈL;c&  hThaKt)P;[j~2q{!>'rdm&bl:#l_N 0gT,982)9x@Eh%-bz7I `>q[uv7 `OPOo[d5?ܱEdOYTb (y[C׬ZZ>(/D (<1f2k3fV(`xP2zMzvsG| ȍFC3zo[k] "w>Fz勱rD%Mfah,jcԒ`No]ZKX`bMG (T\U¥51ۖ|,>*< )3yl6^|ݗR91ثX)}Ue</Bfףua!Uv۬mc!jQ'dg#=#P(KX4յM\Zй}ǯs K!Mb&;gvEqET]Y>:; kay&ΓHXKOfR$%ym*!:ji- oe܏B+fEQ.&aYATSj&NqbSf͗ǩ}\G+.<..S*Vcx]NmV:[9ќM.$Q+[XB V;=ޒ,Ym7o Ф²64]v|6$i xբhqu Џ 5KZ 'o~H4N&;%X8H$Xs A9Hf2.gS)R7GT^w!-tfVcǷVsRE:9aLK@ %ǫQ`!8g+9s^kt黂ΠSWj5Pɫ.Z)\] ]1)iOO$#Q`ؖ N-W Z"p`޴~+0}2l;>0CFXfubQXI&SL 95 @HI3y8}p:PyR+B@R-5:]6C$e&#"cB(:#LQQ{1TKVب~3c [VsG|$)$eQ\yf*벛m|B7⅃4A1{ɼy"xK'L~—u]߅*+^Cg tWe4:`yj,Z{zy V-1׺*p0B!V=-,z1,U!71hun9ο$m7I6_*_\yi1e]yOG}m`< < i^;4i_pс{9̩vi f6"̚\IOn Al%/әѤIaSlGz ),gR^#̽a[V(|Ք˰yg>S{g.ykmsq^vÍ{R ) [DSRkdo Sʱ U0Mg]W OE *3źXx- ɴu5 3H>v:~HP/#H O/q8]ޮ=rЗbj jbtK^Yo+5&Xat/RÂdnCu8>MQLeRiU%Rz%Esz.QZ{ ` \e2gB@#uNCMmh"LqkE$Fx7H.MmV&*h௽R&/AG9yW;ߚ?Bmzldr@;4kF3۪ (DDp N@9zL'[[${QE:9~/8Jĸ ;n̶RIHߔسV20li$7&4 2Q[xpY1$::.)r/Pt(ݽmCjxȱ4`ydFNO!a3vSfҪ>z\`q[j&sJeUU0m25t뫇) |{tĉ0bzYNߑꨍymS 9KcFx{T/{ t0TD2U k,YW`Zc_r)vAɴ ́c}†@u TtWNa#U\[jY $k/{}Łd3]􅘨CBlÏ H\9ru)c2NR j^\Ϣ8h,䌅Rfz r/.>JL5h\=ӃBRxw:_z"~ mS{_G!k E8?0^?%$arKbS>Q[q=t'̳}Y-`s=WSg61=i\C%NԢɢ/p=g*E{yZ:w.S'-0[d:~4/~_>p=0#p#;]gk+pI ǕJ ۙXJ:w{qr?&qo贋g;KYhgVp&fhe߰+~R% ޽%!(BT'fܬWWr}q"ݙU?DV3.QH^?5;JL(~L1Y傅\vlRNƛT::YmkO3z BE yxs; 7.!ab`aq3[7vNaSZ[PAvͯ+=8`ǻQk@++Pk<.!?:FE@_[jڑ(# sħXQoVCx3; ;"yJӝV9KDTg*Vmazϼrtrz*[%PN>ic7!7w#B&#ʌCr8ceVNLa85evߜ"ܣ|l,`)NOK -6%dw{yo {iN-"ni>L&Sk )ڄɆ9dXL`e{Qrnf6?XLrm`9} z.J&`,9cOKC\VS+_g)p"i'OmGjXղLc`8× WhfjRfBU}w Z 7 =LEMv"*~@Rm1$ FTY,+@Uߐ.J|荷8,-h7Ҍ '}<(4Y4]izkX7X.Hұ608=a"\oLwϵązbDsP0ž"3.bAhL-wZ Fs/|Ӄ!*,v6zjb03ңaoNΧO}dJ-מ978O(V9a.[{nh?-`PA z~/CbX,RdTMƲ89lmKrI.xi" W)s88[1<=۩軄U_L;}xGq N!Ou]cj ew,vNO+Ѐc{"?NG V>gM'OMXshE\z)byhnw@͑)o˽6tx4F[n$ ktnɰ. z wxB4Iy~4tH}.~,s7!h2~("FLC7Wޒno)">6ϝOo:rtU+0/au`_yo/@+tWxxh,%L׀ҏ3A5nC 6hd܉}*)?ІbEuUT _rZU]1\M׸Bp!ȥWNIwEd ӕ)/Y34-^i'pk(ߕ ѳV0-^]sx恳p~c[ ƊB|FCƹ>p;@̀]jc_ߗ疾ȁhR?mwG,{-^Tqyv p+/z&BkӛѨoH%Z=~ _#2jhݱdcqXg mt%}Us =bZԍ^_R8VOe?FhEag7j_}XɗA{%bMν'Cqe \$X}֬ygR E«X=*R DMwn)?;[ۢv>b &SD6o?dY0.n.Z8#_ c0-aj[0f) ~b2xَHV|HYUPt8tÖQ[vlk?ׂ6@Y b4p[5μkГ 挈 { qRK8vNW!*댽,}nEi+r/IߘQeݹ}Г[+]LKce15[_3x2@zb Q 2;,QSDZ rma$}yH,?\^m2ޜ.UmD%05QjCЁ3r )q,;B#&3$ }8:ȪRلwDE榏O}y׬3y_'UQ̰Q~0Z6S/O*Еeդ[<1ͺ7.}V#[2 EↆOP͉' viŔp{+p7!c暍D HN3Vza5\ѱE3wtyo+ofx/z0ѻno)UJ aE ֌lUzQ. |^PH "?Stx7@)Fң3Ȓmfo&cRM10~VhvEMyv5%QGx%S9w [܅=M;{xS{4+oGs<.`튕$Y^q-/O躳)9MOBa]XwEЈ];~Omw~H7AдQ@~A )FW 2Qdkr [ $s& T?0r}!흔W4Ԝ0J`o#8\}P_h;{Յ;Bґ|xA3"ޔU^XpAg K\ĥLaKkڐVD񇿫]oѻ>ST00苿'=K~?c¿-W;s$lٿg554[GK^а!\w#*-U4Be>k`{?b+n!`p2n$" -k'<%[v̕vpL:֯g\yfA0ui>P䦟6fL7V')++s1(dZ+|OQw =?"d|m*C8C#J٩y'.ᫎd}F&_ky YA(F;x` Y,MAhNl.Jo" Y 3RhS7vH֔\;tmD-@!+tP.H -\FFT\u;Wfـ&*X5r2` =~/x7s5͕ϒtlEQK/Sr?nVtj*ʉ_3u8ہI{ !]=q#X)mu@hBsT*~=-D MU"֑NB/CCc$њ[`S h^zr8 Օ ;wAgbv#o Dfc=_ 6{`T@xaK`<웻M؎4aOu7)V'AZ>3]_lj`dL[tw(GL1%BT.zoX̨.WWWJjs(:/@s=?k2R7bfarML)%!R\ZKVHc#;X:8S6WG3m؈:U(!Z;BDœFdƕl*B1CRSC7[d4q ^% <)C^wi߼BTö&H]Pc7#e"Fs NOU} c|;g *>Mz}کUg2~OgVi߸$fZFAԻuqXXޑ.ZBQNCdSgmU6x1o1ؠU\>kQTf䓴@·82p{PyBi ҊO/ 0bZޝq&O>;|KͫFa^U tfݖ[#WAtl?tH=**L9:qգ U` G F99l(Q{/:f42[Kzplg@g";5@J:Wu :XTh lN^>ӞQKN{.uۋu Ag]8:s8ݭ#ٱ -䡋ˊuZF= 4*y7e[YFXKiȉ*yQ&ÑsA F?\OQ%+NpE1 d2fXD;ѪjUR>c_La\=Atw:cIwY@QJ oeʏ.0zu+Wf$|vοdHk@*g3-P-х7K$ |ʧѯL\?rÎFm=KHH~imBp;Xe14pfLi~=li0_'7Fur؈L3@T% {@>vV2PSچr C\6>sǙ}f#%W,h/xX6xrfv=g+t@!H2B#v 06_'ܭE90wfZ _rD~i؟dCд;~ÃBHO/n-y˿HaXOM|\_30@΢Wkkp*fDCAr RJ.rvU@$ˡ_'z |3M4@3pNygUtRHR G;}}mʒ0χ3;Kd2^qw?a2t( y(4dž\Vp;L%EX E*<kx4[oU!]W3D:Ѷh@솘 rc? )B'dKd6 SD}U:qTgIʆܠ9I?=KyAREϷėBI`B9MxVİc*uVZ$ŸR "u;-/Ϲ:s@z l{%lŽ Eʕ+$ɣ2#!".B-hXCmGZ`e,w0E,_ >dz*UnMg94Uqe89)\#J]`u&Ɏ@b!ix qld{p<| 8ɓ_d<6wds|zl4~6k< -=iR7`!5ΨBR"@NDVxH7P )^i:3u5u:tAUh"q G33~d@rMq΃,y}o4 vָfd~w![dp8biyP~ L*|+[8SsHBZ$2Ⴗl6>2F<-r̮xl%LmZWt멂Pt#NK"Rzx5Aj.hTҴ1,xquQ;)jÃͣH֌iwx:F ۘ{Sa@w%%1{Y3zۿZéKzY' `^*Kw|r|mҬiYTܡ#\TgNK~֞!jMj.m`rTLÞv5)Ia^@,?Rgє1%{_ j.st.;N=jڶ].a`ɵYph8:%oQrBh9ɱEC9.*Qq͚cO[!qSS}AfڽC+tR. 6W4Iix.f5DyqCRFFx/o%HxSK1FC @  ~/Ho}~B`f%quU T!?T6B=t>}, ׭A}Se }ՠ,s|w';x* O+հ8$7=Zɦ tcJ'_}st́Bi`(7b-z>fLZfJWS#nr@yk:^$bwR g8`8%he XΔo{{W` B!>X?ҦgXmvYn"M(41f S%Tjaɿ87<>1] ISq(fjE@0X=8es%xNw4=KZɳ1XĄ;\f%. ~[&JVnVH\l^ס_PPo];VxVT?A涳^MEYQ3yPd.nGʖlpq5&8j 9fFc'b6)W`/2+ϼ$^ R 9m]?u{n?сLuH4z.#`yE)yj^p-uD2w})xؠ?AAa^Ȕrbk}#ڸ&.^쌿CMC8򖜃*ҩw[eҔиÞ-bt(D[[)1RM!\ %l~0hTn ~5Y(fC;LLbǣ:.zwg!UIl}p8\LǫfEy/*z}~X"6a ޶q%OӖ8F<%]BZ̑9& e;*½ĎSQnf4,b{b͜uu,Ú4fBB xpӖ4.&ASUҀ f/T\+=^(9uԄ;^D ɁuSDL6ǣkYir{3(7J7a;vp(7!kRAp)KZQ8vhpR]a/Hv+$<b' ~k.d0{ZDڕr_b*M8" d75 P4{*`zu-إ)-Gɦy5zdmFklYxfX#Hilԛ Ս[fr|Јԅ]Y⛋M\n5ЃS fCCshd$qVpIlZM-SP MFŵK޳l !E3QL1ZB;#l`޼L")*cvm]aК!mh+<6w[ޕ\8* zх3=s8٫n3u^& lG[XOuiB\b#m+G421- קeNJhq=V{fh%L)_{kS~紖o/bHbdh6-q^dQ y kaQ]ӌ,RvFjP\]l$^B#Qe}l8]LR6FADR|4r؝iɯVNzZ+SdQHbe4q9h.碲TԈE(b($۹:Be(2o [XxHr%E773M$A}83u&gQ,f[`լз8d9B(L,8=|9Q\'x$x!x=B.|0?vdژѝD0Mpvq*t9i XsA+|amI$J2yUeV=`y~;6!|LrcFWц}2^FnSmMɛkX1 /"(C7hP ,VjL6ƼRy!UM/Nygkc¡!`\ӈ>2,,W% pXW+?BdPsz'z*~ꜧgn[t,&neQim[FTO<,k 5+=p97Ņq$Ooo1/f_01\ u|ؒh&A:xi6v$hMŵ|pawꮱlt%! `%/{|"st+;q ƈzD^ܹޮ>",0ʹ풡-=/Zi&(@Ńjsn!X/|x 8GaGp7詤[&oUMh %th V" l@n]Dҡw0 3䝜];ۺ剺< .D`J#۸Gz{^J ~N{.LpSmrDisr ooAf#NRzcm)a!b bXD*v.пYԲF-]luMW0`Kaw囇ʑX9+2g,`ZQ^rzoY-q.;S;Jzv-⛇H= #PoO'(|q,d%vԧ˵;_z.w_eOҙ|Ecˢ=w;=@I+hqݞ,~g+",21{[UrNh_@?'/'C`5d]>mj:zYQH9g8ItϴTۏ`Ӛ_dRQmT g[ ^`[sc2}}*l'T[x1Q+qU^ig,HSrjb\*x!D.-[P=}ZW+λNϗGIbuj2-c2Nrku $sCyZ>@[ϮRTTS2ErWI1-n WW@mqty nA`F$tǫ C1w\ȅA>)l<+܀Hsd.D/$]d1R(m8ߖ#d@#: MwZNmҾ$Vi6 m{LqzbP.~s2 I?Ke?=6nZO\ƌر[Lb"<{Ɖ.[754nj3'//CJ O}*WLܭ1ChWPN=#ˤal?c'}=4u_\LmTw WEjɉhZsdpjֳpݜ`Rj`Poe_U A˰4N揟V2f|~'oҫ_cfOBsu,c;Ŧ82A 5ta(maӂ5oږ*oaMrV:j u\H"cqwLfPMwZM?adCjA=n pQO ٳ!L Wa?8FFXRşcw(L\iG==rɬndQTBoh] F76 TZ@L& ,D"NUUȜGN4>יi5Y⥆)=RԬ4LAD2l3{m4涩eqqmD`ԉs. ܱr E{~f8{K֚< Q}}"B; BI.fQMmaq-*"=q3|AQ"v_\Jm+8h̟a|*Mn%6_QpD6?ba){4 ]{-0IVY\qe.6yFjmQ0 3K(֠ Lq~$WezEtVb/;㜂pJ LCF$N2PSnˆPTb+,m_bZ{&?ұ(*]L{4Ɵm 06#keA!Q d 4 BHw \UNI+q5ݎF%BNZm_/ 9E YsقπvBl=UN\Z"g LWht-<.w}fUigXx$~ySLNaL,; 8T0#pi7N4hJc%E}q@y[9qV:=NTޜgX.oR&"*Cj:IR}-^Si1/P3 zkϖJ_C#)eX wp쩪َCA N"kٶ PĖ <#YwZW{A*!cb{4RV^XLdqX M>3">hYVT:waH+#$ɎDVnϥHP@vQԽPK:Pִ+7zOd,E^/l:b60:u9|I=]rah- Jg〪j5r JKN%Yv`o.QqBJs P$R}ˁmTjA岣e-\.}*TbڸBŇߑdo݃ ?~B;- mW.Ҥ<@:H)B\nH R-6KQȳeZ=LO7!KHL?g^*!mOj<ܽLE[ e\X{w (]akPԉF\ 7xH Hu(9H^gjEW10[D';>B65Ԩ r Ϣ,+Oz/0T<ܐG1Roצs**ۏY[t)q'z֦^XP٫IM.]AJv >z<sW[ >Q@~yy@ Q CE3x^ōs@<|tj}ʤFv4oEyM|.F'&}T}YDq(vq4C"e@T9&s!vH-^xi沙Am[ F0rGdMӧ$*Jq/in0\0qhςD0WЩȺ oߛ rq^g:Wԁ異Q22#Iu@G)x]Ŷexif+7hTcE%Έ$DtV96.8[1wk(IwqPI|O #DIp! E +L5BQFjpPu32oāi+m{Ep}a.:gJӾ`Qge# [>SY34[$pY|C"^Azڒ֦9b L⇍-!ɝ#^R7Q60@Wtd>:h@@^V@DOdO% DLƷaЍ/ ܰqlbfH񴯻wTaqB[flz,+=7Md{5Bov؁ ?B E3Qvkmw)&d,2] *c4Ռ ) tU06bP~W}~_A yߺYixS@-'1 MYikOWQf)sCI?f2@$OH 7XrDAEo9Ws\797eY C\,:zK*:%?$N㠝{K3$[@ T2P졕ˠaj18Q!mS0yK'!Bqby&fekjQrm^iBiiW]slL#$VFUX8 KGQFX4ohߩ/\ w<)#Z*GpRtr[h`q+uF'˹h7Aނ`/͕ 15UjIC+q/VOϵ?`ǾeR^xֺ3c,/TK7 ]QMl%/TVQ,a("~n|׎q9t/Pu*r]o.=h&,kڸc>bG%( Ml}?S$S%qM3#BQo#/_yz#:;BR kH&|9mV9aU`Ms_0;M{?pQY;R?ϲV myHFLttߞdJ4?*9!NN85LL)c`Z r.8A^q'PC ,4J1&&@J"K4CbיIQ+81 2AD[<_TصF"^pį~edR:SΓv!e*' cbKH30klpx؊Fg.˜T•ٵ݈7#.bEbs!W4I#TA2)mYm4ZQ](0m 4>Pm>[mSM8KỹTCoh1Hr<-KMro`=yV*܃ 3.QdhQI3K6GRB|Ch٣?< Xjd5glr<'nͦ(Q3a^KY 7Ex a&c /;o@_Ohʈѫo6m7"QT;CLܦ|:O4GD9w?]Hkƕ,ii3rvG¢ vUBM[Cw}51סg2 D*v(ӫؒZcUGNf lB?xnU#6Aʈޗ1bPnT#K ̗B#S>{i,gO!Kp,tK4J4_U -e**`3b'=\rGad፸6D|A^fmc77ε(FfβwIU,VЇ^,ES#c2,]C]$2h7H/FFc-&NDJrJD $ W5z!3ٟ HaBQ*7!MseZ|e6FEdbUԢ#PTIarm#7xx5~DAUB2e~wGuXłϾ,$Ww}/Pm FwVؑ" Xa2}/D4`i.ܞ]LpduQ\z#P "-Y *n(W㚢 )hV$5(*jk0N$v{mVlhl +JqA\".3' !b\Mc#]$B)&{1G%uJ/djAT4j11S㓈?MdEW+79]P;-UCyxm-[km8QD"P!3,ۛBX_v$iLNDYT!wڠ__3.BJN>bB8cķ?2zO׌턋#gC눓IF$M@Sb,DB5VRt?ե{*If[rZ{bmlt՚4Iw jp@w\Eoע0+vIoC$@*;€A6!7d AFv_K{Bq )OP}M]k/btG4*-߆!5 ̆Z[TN X~@ Z78d )1jxÀ lI0~[WUG_{ɒ̮nt}i u`4V k۽pa:Q߭X 2)8ӅlqLW59~ "1Pv4=!3`\ Ϳ&Cw]ϑ;FSMyFAdǑ`5aDOd yJk?"7gB? BH/gPB! MX Ku!|~Ưgb!{DB4粩E`/Js;K*@ p5\ 5Ӗ i!(&b LZ!!7l$4Ӱ`CuɗN<+!oYKNce$.8ϵR*1^ۦ.^Xc0:|q*{J,ںdA~ގT#3 2t#r&f>zl>pɱ*[.VSa]ѓhCD v=\{<2\މkZq9wQCp-勿AP\O*@R|-=\"$&׷1PTٕ=Пrt)vu-?A;c@癒DfITSݜYQtFK7uXQ"כkZ;yۖ2\^u HHib KfLf[;T~f9w-~ԞDD"@^бiSV,G1&K|M6 c޳Zo9Шprqgi:4Z΃yFǮ'VL?$ݯ _,Sjq, zFDo|RRsv9q]MdlFe͂(*K&Gw] BCv$=]5S_Ґ&ZfY-&EAaVE+&ulVEfFr8Bi)pH۸(7FFY`?y]^*Vϕ'ZeL'Q3qa6v90 \Y@T5oT.Nsͻ9hv2QlTW5z 5 \Lin˗1_{c&u:[UꜵqԷ~J4# HzaMρy¦G=O z7pW0+UVm3.֏Lr\P:QC,\Ѡ+w0Da)Nf0?'S&x:p[-.qEͺΗSb|7lA聢>ĠfT ۫hҳg!j$gR@}c1DfE!`U @ԑ? iUȢyArV2STإIT {>m! [MbƊ#w"CFn#ȉw5t yڰRW@yh2MKk^$9%_]j5|PˆQ }º/i(cXv< WϮk>w{`cr&Fz V; bԹ:@.sE;~ UAK ;cx:窶Q(D>OE Qޑ Ru׏Y̯ r`H(yMbCMB7#PZ'jwÄbBTwW~ ># BURAUF3힬m3k% mue*\(1.q\c;2qM2M2 g WY[cչDH0rDD| -FVTb[|jBTA_C&=+*TD/%f7-"+c Ήxjx#-8kUb锲-a :V5V>Lvx3 ?dbFbtB*t[וePRxOW%q ꜉R$.V'f.Žߺ뗏2 Oܵt2Vh.֭G= Xs/:máfNDMc1jWzp9rҞ;@zO̩>ǖe-Tߚ3KۍZ}tm96PJlS9y' n CQJ|C'4'"trvDoC;iT\~/B1ڄ5.,8U,+ڰ+8P#:ȺSw}r:|#{!:.xHڸJ7/[Z|P' ~箴? )YfNa!KlS'~ .n TAA&)7|䇚Nb|䖡~؄F&2 [P񈗡u t TfgcvW>)pNBvtZn 14(޵}8 ~nyad9!DZ}\jޕ el e^'uMV-E>/IKvӅ$RcZYoCU$ b:tM{sM8~*HCeUXN1S4:WGVBD^3.+EBg %G-/vuȌPk[+ruͭٷ;X0UB#^`#q3&lYp4 ƀ1ؖ~ DкP&-;V 6Zl-2Hy"(jSeR8\I "E_+|e.l,-H,p(z|j ge&9/vDJGK>C#@i풨n\r=ùPY8q[qCL)P&@AsdM8@rPoCs`%:PfJSrTE2U7=*y!K`ښR74 =Q\}>@}FYcW}k9Mc,dx舩<"IsoJ4Qp[141*"2eldGMhko9ٛk5Ftu|KCrb["KƲDC8m k!LgTniM)v7So"VEn_^V=BM']C$:=s??]?$ZSK%\˃^Yh<_\?xL蛇!"pp)gv3'8raQQΣ@JpV8diZ1T#E:Q?fcC cdd{@!&WݍLZ!wј/'Aٝ.8W@[DA+g7yVwz È''C NU54 +^蘿ziDܘLs@ sɋ8H̕}wXld*ȫPgp]5&A,tlnܦS_$SYirGu( +'^|*z?1ʁ͇8T 8B_F`d?XʱQ=螤Ոo'Mkyڼ.H!fjY{[3ÿu 7.+Jy!T[1zK;+ f(D <ԡ5S؍RY,F%(*krio\g|}9mmH^TMr\XNuqDh4Z2(j̽j |-^ϴĿށ8Q"/i C1\k%jfEcF> ϿmX9ce 4hR/d7 3lˡg~єM qxBa`@zh:ɂap&()%F7E%BzgLMs2nsJ2^"ꥡ/|?uE1ԹRN^Wݯ,wPUfcL uMG&F,kqvzVQ úPaQ, [&y V3:%;vk: lo^9RݟGJ#72Ee(1>Ja{r(={*Se>v.tK[ma* O_|LMeX'ϭI)a+J ͜iZh gQx# _׷!7[pݧiVLӍ|f]>p:AjUt-eG}`@vf5*V8%N.-\,>B !F>;0TX,)6c6 tzW2Y,D}ITI;|/ѥcNajB(٫?6tX!-Ɖ?<Y)FʀC8,=EdDnI%&"xwAÁoU%++]O7't>\=|p΀fq< <{rT3" +sLpVFY#[z!Dm7ž{k/ۋҙS ֣L{YGy'mSffHzrRz0^!^{9ڝ@ShJ(]ژƊ2p`C;*[kt+V *|{&d$9zK NkI( әVSp"dUռ,̾<~oeZܕfkTpr o`WsnIEwp!tn[ݹEem@,mHSmb E߀9hr, ־rڻjZ|DؑG*q D>}+"iΠx~Q{.f B >'众wVEb"6?lU)ma-U`d^ =(gr)u9a&fF-K3U*7uԺm8K'\fg0B.㾆JuڈVYG{#! QD$.}^1vNhkt,~I{ŖÕ,x~ŹAlNN5QM^Bus7ðn9GUTp |~7 5u ϛv,?Qj~,---f۶Dkh3ڦTYtAOgju# S6^+ێFWٶ^>E}y>RלW.`D@CzAt8).5%ѩSHx'dFI$cT[$ 3^C8TofwW`^NrE/=ZG I<?#zR B\*;Y"AG5y 8u@W\qVa\abc@v.b37$ar= GGڠ614 .Ib=)P8\@p7B82戥 bQMzI 8^(Mj6'N3;Y2U>Ţ.8\1RjM, <CYE"9bIGa2Ӌ n݄tɱBǟb/$iCܦj43hۨu^Ot~ȑPLW>]Rjr*4AԾ8Q#pk%![/V1Ler]`d7n.[o휝M~,Đf>}O;  `=(vnMΞJqwb&۷S D3f֪F+4¼! b5:ojY~[30fC91'Tt2.>RSx!{PS=Ugjc_vy붠WCz0gMɠfT$J4[P%APT7[tUȘZ;\o < XxW ,MZfR%^O ҿW8-@녒 j/a,X \YTg'aֿϣn^v:+ 㶟/J|, 6AJq2xoy婒1 3dD "Qr⼏r*~Cy+n2MG#U"ckwetL0d@_DI9dprQA6\pMg[7`NpRV.k+1vFIx/@aOs8 0x *aP1>)?q xy5M'[%*B7}& /{xGLXq`C4\h?{ txbFP5%w+0O@ʛ.oޭUrkQXYO<;S.٪5e * M4I̩(Nύ%tj֔+W%rfjwOFœERgjf&Lbv&c{s9 q+U<|lq96ï &L)%/s!`ʩ0eDਾ|Knq:GRH3θ$Fc|:iv!Z|.nf>ל!"9@@r ywn&0ј(Dn'{DF󋪡\gY?lpEPuRy uے>' :i!~TN F,,ާ5S؟7]:2Za<1KB 1ts8+˯"fUᓅSA+ CbM֍̟2miiˆJaš>ڀgVo )eGQr<U<)D $;nĸ R+aK=o~ؒ̽XkT iJ)_bȷMHT*uHl$Dm]_pY^eұ8PN L4y}l1[tEip⊹ɕ2[2[B"VxJ9}o %}2퐝2fRhc_rۦvd2h/-L>,}8M>[rVB麱o'zHvY/JC~ {{Dt tliD@sKKSJ.*>2WYA,될ϰ`{@Qv(!މ+pI9@SP0gH1x$rt;n8e% ;^m$b9 $3'7u0tf\PEʠIYmBq]12[f*v'2$`5 ̢BxgK﬿F/svCb҉]yr(H&PSTS WN"IRMS!,wm;CX鋀-V]ijs,JH#ߟm01-sq-yCh[_|:|).*cyYۻV an_k0X,U^{iaԱz)3>B}.šzBj$-oXA1aջdh*Obf_Oo&vls9 MKUQH"VH)|.SGk09 }3 d=`CnTMZ|a'`݋Y@^A)˜aeɴ[,SS+J1oU-ipSFkʽ}j2.+0 C\^6f%,A&|H-xk3$CnD(8)[!T9K_bh4\|ʫ4_@dŕT9}_1oȠw%;1ᠣK-,wlq>nGaK6wVlq)" ]'EpYQGUA֑[ g8έ`?L{ `8@ Kh,'eRL8>:A|uG9ox}ٮH!| 1BQ|׮D8{Ɲ`-gSa(n| ]^m|!؄3afyxvǨCF͝Jតu+-UIvԮ%kϨW#CΞsoR]r_M} <,J2S8ĊyZ"RG}q.Pkя%6V=-nڣίIXߓ=^UtEY UraK"T{mFrQmy!, hC{uz.Y٥JPhT縳-.aL Cu W!yeFBA謢; `NaaQHYn;N8qb,R;N ; w6vd* "d* esq{+ b̀9SӘѝ ?T3!AK5dSb}2L#C;"䈄+ndY6 GI !4 1L2kcRdmC5~P~Wdn禯qGl>$0uzZF*f77'bYХVZVhy3x 0člHEI wAh.rrؠJ2A q @Ⱦm % g5,2m!&tUQUrvf& *4Q3O9e[BmTIe*?E .ʝl\@9|6O :HsR;ϳn6G P3-TfUy(ߢ$:T+ϵ%{jNk ~W qy-UtW:Εq{^E+/M2—\`G+eڲ퐕/+-IBvK2Lwl h)ݓ͙/dH7,ThJSH cV>aAv{A Bk_^J(p}R5fbWkIgh"kk=-{+YOu5XTUR?/D޼L9N Ū;XNjRa<Ô6Z LGu*Nló'™gSDFܖկ$I1UHimSĬ #`/=]rsÑoPpmReځdlx̲աr4~vLIC0I3%z?Ϥ:}/ s G;\ (H-< k DVc 抂dQ({ݮ8 jJcO B7[bԥXh}Ύ|Jd -p?ũ5\4M>^Jy[L|Ò @'6y¦ʝ #=^޹T)T  gŜE^ŦXOpd`(tІ""^jiUev^PCP*5lKzi38Ek"P"o5Z,N%_0yTvopxksNr)B&8V4u5d!۟2*O7493_D,hoCN# 2W:a[YMK5C~0tWZ@:oЯSK05s :F%.Ԝ |¼4ÃXKpHl24s +Kceq| ú>UǨ(I!2KD }I׳?P@SsseԪ\C=X0]NcLgp'eLdnf)s #"lTIQ5Ճ& kH9[]HAZkifƀ|`$}hvge 7o1| <:6Cz'Fi6;;DK?O Y0|TfZA"W{;; a z 1&VW_x-(^]]@Cʧ7"ۆ"bA8 ٜqNNˣPRf_)ZD ϢJܽx[H;^~DT%O A;~d]>.wzLxը:^, 2Hj%&pR(#(TV'O)+_gY5A? ~pܳLT5eXƙMU$PTz[׃Fxd);9*qy"#ހ|Xs &qfX_w}T/`_.*KDT--/a#e:ʆhANe0 DZ Ϣ#ɪ12VWz!+J\{{Z4V2FJ4l;$>dDSt{&ac:<Fk1nWHo[xk1*$֞y2Ԅue_GU\Y1vU7:=+¤gsWM#nC8kߗq.!A;x֣݅}kyR>{+BSes;OιtC^ӄ{9c|ڑt =W37fqɃ574B g՞Cͥdӹ?3.`L=n1qQ&q[_đxamc~z*kp~A luǔ}z( 6 )hO־. E#Xس^}~4050+;@*EVΤɳ~C݇KE=P˟ stGlDZFmDt%c2g4 w" -2>n!O:V0{ƠyT:}MomgRXrOjc/zW "Kܼ=)ޅҡtrMo]!h6)QX!C[a9sogei;;8Ab/`ΔLCwobI X;4l+dmZFP F6Dr>n | S¡&U{"| 9`MpCNs;Bn{} Ë-'A?R]"- MGY{Dң&( P$Hh| N>V1RڏS~Û>&&7ͫI/cxAPe2EI(/#8!gg4SmxJ͔4?P\ :BL;qnk\(×̉ϙw4 m2q0gc!JAZ)>p9MThZKR<*]^3j Ln:UKcc-a6'A5\>*,^av>BftTj :v-[=c,b Rқf9X[j@96fpLlUI>P} wS5gQTR:u~0MզH:ثXf<4o\nnSY[1$1Y&4 ,2,S6-X+kB5/m@ĥ8~ Sd'r D JC]]3cf|ᛈLxwxdZaM? KOܥ|_w{j9R7k5|j p'mAblD7ΰG/v$g\g;AJ[\G .hMֵ ?E?Bg=.,zvns>6Ft>?[UJҔLuн^Cfq~ L~cX>}nT_05 kc41sMٮ=4>GVK ϰ,)98oMvEN&=VcXr Mˊ {RV|(yGr"C-i(|F[jiV2%'r#gM]A>t3:v&xEet\)0c~8.E◞]wj~? M.lZUrNluv-T'Kjz>f놀y+E}LUo eLHP;ꗦeJ>vY8e^Êr Q:nwVh>;Qms( ֎O~=xQ|f fi?`@nm^c>*-Wf/rV1x|/@-x @ã ee?mUhF0">%JiF_Nd@gp]Il:Η{Ł9 u䵸W i6c\ [RС^܆,£^yZ(7 ~ [`X{} H^ na4d_xL0C-_%&hb{7Ga\AqDP\d X~oE0%-O) J,a\&WpE5d@*5YTwsJ`BwEXwLb~ )杭5ITOKI؃Jnuk{|+NdOE'(n=z}pt8G+Jֹ܊rWAA"N򳀧?y@HH srn®0p@͏fg?oDiS杅8j"WYdwrBpy1K߾K} Ēzu%bp/1^|'|E+jQ咓cI#. 'I{W!ϰW7Sn;$~6 k ټ6!TXi}, ,~+RDw@)δ- ^/1^N4;>Pԉ! J3~! C9t?3t$ʨnTcs'i 9#]X<ROSmY2?Q/9GK}UEc\v770} >(VltppxS,=3O҆JO n^$3M2܅PJQPڠgCX6xskE%; |sX/F_^U̗^kLoumJ.v2VUM"v=Ok{ O$ Y ꬒUUMDHdnLڑ[weVkS?JK Nxx2)#x{Bh .ܺ 0pI͓t{yh[0*Dz蒳q{z\aX NDyA>l +7)9j3֚ W:yg\"px`|vaʠi+" i2s1h^0bg=%:5Ĺ<7~̒.n0͖79{gEmd5dZ.zMHS[T>FON:u;𓝟<;gς#Tt)%qʷRx/u?)Dw*Ȭ Of"hĘ豓r+4y^CxM+7 cNmtN쬁M^- K mh53~pHI 5Kói`]BGo9x b-tj 흡SB89 o1yi\7#IQ08I&0b.V0 :׫UF T?#Oc yO(kfza!5u)v$.%,\- 7Ԅk0e[Fyk( uXw`3D<' Y1V^ϾLlpc~48>t]ͅYqb\fNcCU*[48*!ѹv&y8Em7U41TOcrjrh4 i cT SJlJE6V&o"Z8}c^PFu5֨ Z H;'U6ֱT/?\}n'K_\Zmq(ԭ([n^(C4ss@fzaTEor0߮2Ua@s9ExcP'YdK*{;_>bѦXm|!%&H(87t:hvh_f&mFw,'+!W0黳V}R-5x8R+Vzt{`;e 1 9Qtt-OI 6Nճb^uC3Q#'OƠJaeq 2E{ᢼEYLCI+YsJ|ϲ#җ)+!i]lkOFfICKen,qʏwj,'2-䮙 J~قlf~tjT9[R+`:k1me!˅v=M3[]i_mChD$}pշoPTR]wE#D5! UDa߽CYxvr02*<!CI7 O_ IXc8F :Pf!Tu%$,FJ_Íg`83[R%ORͳl$rGfnc+ܘŪQ Oog\'âsK'Xk b|L)B;<kJbQܧ/]^v\?P!ivV'$ާ/:L [ՙ] gLpL;,$1DWL W5-.N "qZ3!;7cȕgCMBn+!_ z|\~"BZjcMƆyx `ﴯŇPMIf]^Yz T 8j:r`5q"p>8qaA`gn'29u7*[x3|Kį| ׹E/ )˟ҩ3Nh0K[r }ϜYǰ?zx?jGIӗ:tvEBgڤde&EL?ֆM1n\@~c%Dz@Վ;h *gBv-~;U2w9qԙJwN K¹v/V7F<>6@AS:'EV hX QIe%[HO1:NIL_fY OEٯws _0Bz 8ɄZ17Cd:aV{OU}Or6Zg^ ~V>/_v"!Gղ.s8SsK3 㣲7I~ W.IvN*6ٌAtvd Mըd8nqphޅB j嗀9Lz?1T/{ 5xA@JU_,jucf%7B?*`O/E~:=)T΄}K2jFҐ}DhkBt?0Qߝ)=EPsILp|BxgdĎlkiUz'=t g |һ=]ئhv?׆A/uA9lĮ][7z ,]z;Rh{rg)b96z5^)'K^)\%QRe/Ƈ"*Ms93%pv@^Q ? }RJNȻ2o&ᴼpW 0SL@J5#0aEt&5w^7eA0WPԁ#JquM=kpS3 tWF@즍㩯Tqq1k$z]z{s'RUD/k"M,)'vL06%)_rXd@55X[`uYh+|Xwq_uAhtRhޝվ%f(Hyw m,/l ]{i>~jUi58_!N7VeB3zvge”_'.S2uqNב˨h{G8 ?gɼ?ÓVpuTj " tt Տd$ͫk _zd-[+mB}y6aA6{#&JCaw6MB\E w, s嬔s4NpP%P:U-Qm"I5j*!_0S(6+;@'/–@PF܉옧 0qE,Ty~TH>={nNJM̠[w40К |LDqG^os@4uAtGkOY>5A1x "X^;*_WI .5AeV݋I+/F)<+ v?DQN4#`qJNoOQrx߿o*=)H9LN䋋G i I x_2#s96t뙷K)Hڄ#egt?C''KMn PC' ({ZkdfC_ e^^2Qg)Ɗ@|gcK@صu*گ.& D-5woԚ#$?cIV@O'bαp"ZhQ7SM膋DZCi  #0_sԓ|j1EKܯk0)p~E2=&w(jɗAb0)M"_VD Θl%kbSVJ|PpեG=!Euyˮ.LHYjf 3Bm'˧9wliፆ;rA2\?3ZE?^ :x+(-?f?G MP܏T RuPijq)E+*W}E &֤ +dqOZ'Sg?-,Jbw^@-bqB1@UZe8|П8PF> gh&E&GB pU6VR'9M&) bnϮ4fmF ۢydH_ -D QM*Ew@*\H/R٥x]-,/;i;ZNnWQףwizs7/ -5>O>rZح޹Bu.J\OE9Ym&&Q[?jiZI/F-$;2ªXNp?B С,&lx s@hR#4ՠz RCBʤӞr>+Fxb+i?Nj*B_wNn ]B$4FKK[zwڕI!fqf|l?pm\+y쀓4cMpJXVm2:3;꾫3OJlq3g3QxDH:sYl'nLq #ع68&w\#.Pc* 7ˈ;ִx2vvU&;$kӉ ܈H65)rULLF}_О5AnS[߭qp2=G9 mmGӊzuKmO`!a,}.sgI\&_^7D-zAdY梢feXAͮt\ENYZ=_Ţ41q'q2w]h ] ט2m_ݭ,ג~VUl(Ż߁]x8 JibEܶR'#ȃι[X,xDֆ{P:ȗ_~R,KK|jߜEJp(9k}E*hSC=ͳÇXrXaTKr[WF8[7OfB:+؋ޮMx>3 DS9g%ʣ&/qI 5]@|AWEY1Z۾/(ԩ J1w4n!!)O >CD)z[I5-ѿ_WO2ڱD׮Ux"W3@T?'KRM܈Ƴ5Q~פ 邂=`r`\B> JmõIK@IPJeH@bfֲNo؄.G/hሧ:K0j{ JᄴSQ8f"&G]Ir8KV,AES@veyqC$>,i 4+9'wdxE.ُm׶ )rK}mAz窱~Sj$~_kWQ55I?I aPOG{z'*]iRPF|APciw[0GN)V0`xԦUD664erL!,a4>*c$ݳ6]n !CU6N{دM8FkPl$@FFf'$8ˍ;OAHtnm~SYqDc,`RF҄..~C sYlXY0/GXr/.IbwkqQg/j{RXs 4v)Llw!B4Tu㈥qYMF?]ݍEuDv9UUl M񧭔] ?D1EHWݬ4MA;H&2*,[nK5,% MZv8;Ƽ6@|CSԙ&,v{?3p=l|1R/k>&y.AsCrӦ'5#&8ic`9 ]SEReC@2l?ny0I`m4K]X]\|wA{`@oD5pi#,]cC$p}$3B䲲Ͼ(G`Kѿs:)HJFńI5~<&PFkRp+QYCjt bϪ({JƀQ/`t@rXybUMJffgNyi@ VÔa)5 0LK-#g=NIA4a7F( ᰙ=d#CUz^'[.U+L LqRIvP b+bgsRZWq4qIa"OW}`w[չtBo/^5.3NYcT#gd UQ"/[UC˞(0z7{lNxYބ:?PP!}*iMu̺KfLϦ5u oWUfR3{; HimgiS&B d)}>djx?+=,Fd ˆA$Kt‡6=(WwfE淦G콐Ed#-RIEL 6"FFz3Vn1n96W5v'H|%cLdY>/=Ѻ$4y< i=}fgm[Zm'77|?:$%t+ `Ȗ)ki5(ы~/*mD>?sj%ܗb@vH}Pdc~NGzzLODktIFθ'ƹ@׃mJZZ̎W'7T]הJ]W^ŝ:1t& oٶh^Vӯ؎tMZ!\-YazL~BCh&Y^̎Ƙ#{cJnJ6Q~<<Nh<9n:>[ >+Agn}cp=PvIpcL4BFcBٿWg1`UcO$G`J\?KRn/~JK;˸'l@@vD&e"]_ Z;>, 6jh/XwK3Epy6︽P! zGDO$. R]Hs̙^lDQ|\NmxiC6?̂d">❐.;t}CQvoAgkfw}jaW3Oن +{/sB-i] '`~j9O##g\G{ D3I ]nrw,7et͇aPRH}A"1<<.G"4E Tt[uȝRl K!EFf[0 &ʢy-X6L ٧pws:DRlм)mhMmB 'mC:ln" Ǣە&KWc ~QmI7xExj订쯕`^bM=A_qcR:Lb?2F*6`ϞY)MSj]1"OW!t1e_s6\F&cB/ywDm⥣66%xpޘ ܤ&\% {.@թr0/t&G  Nîp x>Tpf(w><7>>|(` \w!A_̴.ëSPf׽mOҤlcb>XЫM⥐ꇽ뷸K3{вX$|̌X,HMo#YwJ)2lW OН#\ay,Vk ܈e6Z$Kͨglr1ƫBh]@9aK8Mv5~ 3nD%zݜg+U ) 3+ڏUZ C5զFU>Ư|2X"LLll !c^ܭ ΥT&CM~L_VTUs怐o&A?y7k]ڿXp3 u7x~9Q$U) 6ܓ2oBt tCRrH[}1zp!% <wBZ& dUbB2+= "dNmW;~tE_'dJu˧60A'<ug#y-za+sK$n+w|5f]+(r:f`N| VOiv*u}8?zTnls K2κRi>(A% ;Bd̛\[49@ 9'S<)ŠI6ׁrN  "6JTPeekkɼ&B E *ļ'p#NQd<3>-ЁM㜀{Q5kԲ7xBnBƗ.@4/6V`s3~tfZ]R-5JhݙTZ?m iV$ y!exxIitS#2I2@:uj US$_{)IEPL<&,%3tvlX J`Lh,J,4%Q++O>;UJSg^<@vCw){O#({׈\h6E#9ִ~K_M.g䀜iO'n Pcٌ"="l:eh/E@zgni7 aOu<\ۡ<7~k *:4jDW(c1\ᅪp7ۚ"ndHiS? %xJF?E{*<1ֈp7E§5Bߧ!U]IR%I  rdMR'ʳD @70kʴ:)‡n=!bvH ʦeMF~!̋~`^kW#c."s-D.H7>O6O,* o#OEv.SૼU pa]vïKl6ٚn~+!zqs:~ҭ7ʊj/~ЄHďO=\RhTT9Om_7{t'{uDIFer&z®6ٖ^' g~(~LK}H)=dfOͦ"=ih,H(ذ0.#b)Y @ҁtj-}B.jQ>"H"vl<9k+rpzUTq)w`S~HQjgd;:u\^EĄlG +|՛V4Ffga 9P$cf-Ê@ we\ S<2V>F}Jƞţpi6#xu') ARD*( \5@[#u'wo@M'SyѭZ;Gkq#d=Qs2m8 T0fN; D8 ̢6}jY/bW.AF 8C4eXy> ׎%aGw߈n+\ .`quZHScC_kmTXI؅ )Fvhs̪ 䏄"g|W^vY*UU4h~[\:"Yyj,H闒gR_|_ W hD-Ah@L[xu]0LRy 5b k&+xC?x~+4&6oj%3ln&w֘L_˛:%EO=lL#vL)՞JJ]\3!H) .ˆgɢUBښ"/sj 8o%x6)c׹Data'B6C{XBz~?^P{s۾hF2}pzF4,% f#Sshk)ZN)NRnփ9w_Q1ΞU1WD5+j M>n<ʾΫ"U!P.m8Yt2S)JrCb3J\Yz#Fb Y^tY_Z(ؙ;/VD2.gBR[t4\TB 6g%%A#3YF}ޖR>_U_)34Cɜ$ƛd. V|9XRgæ;ie;ov0E9JP Toqf\9[p86CxXt.H@x'rM¡OHE jb[+'K|m_3):#w%?gMY J;|lDuU,K(X3abb;=CJhjh7.Djd;9Z_8B/]Ț)z#~uNĝr~f?U #;l7 q`0Ii'xˍ6ā(#b}9q( xv|u ɤ~`ٸ Pm=MJvh_g\ipw1q%9hIX D¹Y՘;p.Vqxuu΋@((6e  & 4;oQM=B3zbKɟ \n3{ȄCv 5),vAlb 8 {2AIOz\ K7X0.JqnQ6۝$e#bՌs;-4 h} 0y)4~x;jҚ\ T6<%YrVIU3i ` Fj'00 龏 V,wBՉs- 5;e*{yalɤ?Ͳ[X<#X_ K˅[ABZΡQ8mFۥ"d$H3 LG ]ɇeøz)x &!>ÃL1U%RC5ʟng\펏8\F g\<8$q"szT< g_#8/\jCd\2iV)t]~QEJE3Yo PY o(mSk0r}%Ǭ!b`" s[ ƴq !}EW~^l;OMaHАυtAn@((ma;J<5i*uXӝ)a-Hi"(9dU6D~Hkc揦RuÑ+1~m#~Hચ[!V(gHkEv%G:gFȭ5J5gKEX: Ӧs9 ؖʪ{^窯 8(W. !@} YZ