freeipa-client-4.1.4-4.fc22$>Z| d|>G?d  D 4:B L$ $  $$  l$  $ $ $$H$$7747()*"+","-"8"9$:Eo>[BcDnGx$H$I$XYZ[\$]|$^ bzdsexf{l}t$u,$v wT$x$ytGCfreeipa-client4.1.44.fc22IPA authentication for use on clientsIPA is an integrated solution to provide centrally managed Identity (machine, user, virtual machines, groups, authentication credentials), Policy (configuration settings, access control information) and Audit (events, logs, analysis thereof). If your network uses IPA for authentication, this package should be installed on every client machine.UR2arm04-builder14.arm.fedoraproject.orgFedora ProjectFedora ProjectGPLv3+Fedora ProjectSystem Environment/Basehttp://www.freeipa.org/linuxarmv7hlif [ $1 -gt 1 ] ; then # Has the client been configured? restore=0 test -f '/var/lib/ipa-client/sysrestore/sysrestore.index' && restore=$(wc -l '/var/lib/ipa-client/sysrestore/sysrestore.index' | awk '{print $1}') if [ -f '/etc/sssd/sssd.conf' -a $restore -ge 2 ]; then if ! grep -E -q '/var/lib/sss/pubconf/krb5.include.d/' /etc/krb5.conf 2>/dev/null ; then echo "includedir /var/lib/sss/pubconf/krb5.include.d/" > /etc/krb5.conf.ipanew cat /etc/krb5.conf >> /etc/krb5.conf.ipanew mv /etc/krb5.conf.ipanew /etc/krb5.conf /sbin/restorecon /etc/krb5.conf fi fi if [ -f '/etc/sysconfig/ntpd' -a $restore -ge 2 ]; then if grep -E -q 'OPTIONS=.*-u ntp:ntp' /etc/sysconfig/ntpd 2>/dev/null; then sed -r '/OPTIONS=/ { s/\s+-u ntp:ntp\s+/ /; s/\s*-u ntp:ntp\s*// }' /etc/sysconfig/ntpd >/etc/sysconfig/ntpd.ipanew mv /etc/sysconfig/ntpd.ipanew /etc/sysconfig/ntpd /sbin/restorecon /etc/sysconfig/ntpd /bin/systemctl condrestart ntpd.service 2>&1 || : fi fi if [ ! -f '/etc/ipa/nssdb/cert8.db' -a $restore -ge 2 ]; then python2 -c 'from ipapython.certdb import create_ipa_nssdb; create_ipa_nssdb()' >/dev/null 2>&1 tempfile=$(mktemp) if certutil -L -d /etc/pki/nssdb -n 'IPA CA' -a >"$tempfile" 2>/var/log/ipaupgrade.log; then certutil -A -d /etc/ipa/nssdb -n 'IPA CA' -t CT,C,C -a -i "$tempfile" >/var/log/ipaupgrade.log 2>&1 elif certutil -L -d /etc/pki/nssdb -n 'External CA cert' -a >"$tempfile" 2>/var/log/ipaupgrade.log; then certutil -A -d /etc/ipa/nssdb -n 'External CA cert' -t C,, -a -i "$tempfile" >/var/log/ipaupgrade.log 2>&1 fi rm -f "$tempfile" fi fiZH33K3535`Fj9pK ^fA큤A큤A큤AAURRCURURU URURT URURT URURU URURURURURURURURURNTlIS#URTlIQ^TlISS#T TlIURUR6aee37bbab7f3a58a804bbbac141a103d5ec66674ef463477c3128b539bfa561b4ca5a5f8eb5032ea3c239e57a8bf39e86667b89758bc51059cc9d71c69f12b9b4ca5a5f8eb5032ea3c239e57a8bf39e86667b89758bc51059cc9d71c69f12b9b4fb0c233a649220a55ebaf8f78679d64bccac234504d4462d6a46b07f18622f3ddd23259bc9b45aafd1bcbed904562e871373ee3b436acc8de6e1274762703e3ddd23259bc9b45aafd1bcbed904562e871373ee3b436acc8de6e1274762703e65ae9d106c2c01d839f4ae1fb60767b1135364d5053133ab7a632cc806cbe259889fe93ec2c8f66b18d9189118ae74a55b45233d622347de8db00c2de1b06b71889fe93ec2c8f66b18d9189118ae74a55b45233d622347de8db00c2de1b06b71c42e8bf9eeb595ea78a972dfa2b52ef5924dd609412fa6a51824b7c9737ebedfc80c650afe6ea35cd2a0c96484b8ce48a45ac3c56c32039ff4946caf2c5daa5ac80c650afe6ea35cd2a0c96484b8ce48a45ac3c56c32039ff4946caf2c5daa5a4f0947b466c6857142a0b0fd5a477bec59f19744426cf4b8766aa01b8a7f812b981835664bb5f1512caa671a2892bf6541144b88eefbfaa9a2189c7d688a1fd2981835664bb5f1512caa671a2892bf6541144b88eefbfaa9a2189c7d688a1fd20288da5de6dc6a2fe632c82efaddc622fc5b3084004e517a3c9b3e61efb87bf80e062d7d4f534a80401de54a70608e6f22295a1c54b47b2ef0c7c771c820195795369608d42e5c8cd1adc33623ba2c4f6fe2243c54c603925faf717b616f9430b9af90725cd9e2ec704759a8e222eb7130a63fc069f2768666e1a6d5314945b51f8ee2061dc29061ae9f67bb177f5996bbf1c9a1a0509a911c237a9b97a270112f26d074455e802d3d73a0bb75f71f506b6236c3108d23e6923f55c332f5a1a78ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903fef71eeccc636521a2dc725fd31ff64cc60789125911551ca262ad498ddd2b7efbc215506be9ab1184fc83a7e997901cf9e63da8500598e5a9d7ef9b588225b2121d0a423cc66facd06fca0d904d135f0b7ef064a7caa99f97bca1f4e10202a4226ac7db51b406f7edf39c15194a18974e21de9d68d693de8f87c70602e789dbd93b060a71caa445e81310ebc9adefd25a3ef31b582dd712e9fdb52db75f051374259ea9396787a9a9cd3ac8819c30786147a59368417bc0d854d1dd07e5ff03499ba67992b575ebaad440be3056897eef062bd5f043faddd3a079d8b4acb7f366ce08b0ef4bd7fc5231c537bd270965e2f622c2111b7f3b512db27b7d5c5de90d1f6ba882f60416f58af4eadefe3a2fccff96ea4dc758ff7342fa3a9ce77963rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootfreeipa-4.1.4-4.fc22.src.rpmfreeipa-clientfreeipa-client(armv7hl-32)@ @@@@@@ @@@@@@@@@@@@@@@@      @ /bin/sh/bin/sh/usr/bin/python2authconfigautofsbind-utilscertmongercyrus-sasl-gssapi(armv7hl-32)freeipa-pythonkrb5-workstationld-linux-armhf.so.3ld-linux-armhf.so.3(GLIBC_2.4)libc.so.6libc.so.6(GLIBC_2.4)libc.so.6(GLIBC_2.8)libcom_err.so.2libcurllibcurl.so.4libgcc_s.so.1libgcc_s.so.1(GCC_3.5)libk5crypto.so.3libk5crypto.so.3(k5crypto_3_MIT)libkrb5.so.3libkrb5.so.3(krb5_3_MIT)liblber-2.4.so.2libldap-2.4.so.2libnfsidmaplibpopt.so.0libpopt.so.0(LIBPOPT_0)libsasl2.so.3libsss_autofslibxmlrpc.so.3libxmlrpc_client.so.3libxmlrpc_util.so.3nfs-utilsnss-toolsntpoddjob-mkhomedirpam_krb5policycoreutilspython(abi)python-backports-ssl_match_hostnamepython-dnspython-krbVpython-ldappython-sssdconfigrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PartialHardlinkSets)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssdwgetxmlrpc-c0.76.84.1.4-4.fc227.21.7-22.71.11.13.0.4-14.6.0-14.0.4-14.0-15.2-11.12.31.27.4ipa-client4.12.0.1# Has the client been configured? restore=0 test -f '/var/lib/ipa-client/sysrestore/sysrestore.index' && restore=$(wc -l '/var/lib/ipa-client/sysrestore/sysrestore.index' | awk '{print $1}') if [ -f '/etc/ssh/sshd_config' -a $restore -ge 2 ]; then if grep -E -q '^(AuthorizedKeysCommand /usr/bin/sss_ssh_authorizedkeys|PubKeyAgent /usr/bin/sss_ssh_authorizedkeys %u)$' /etc/ssh/sshd_config 2>/dev/null; then sed -r ' /^(AuthorizedKeysCommand(User|RunAs)|PubKeyAgentRunAs)[ \t]/ d ' /etc/ssh/sshd_config >/etc/ssh/sshd_config.ipanew if /usr/sbin/sshd -t -f /dev/null -o 'AuthorizedKeysCommand=/usr/bin/sss_ssh_authorizedkeys' -o 'AuthorizedKeysCommandUser=nobody'; then sed -ri ' s/^PubKeyAgent (.+) %u$/AuthorizedKeysCommand \1/ s/^AuthorizedKeysCommand .*$/\0\nAuthorizedKeysCommandUser nobody/ ' /etc/ssh/sshd_config.ipanew elif /usr/sbin/sshd -t -f /dev/null -o 'AuthorizedKeysCommand=/usr/bin/sss_ssh_authorizedkeys' -o 'AuthorizedKeysCommandRunAs=nobody'; then sed -ri ' s/^PubKeyAgent (.+) %u$/AuthorizedKeysCommand \1/ s/^AuthorizedKeysCommand .*$/\0\nAuthorizedKeysCommandRunAs nobody/ ' /etc/ssh/sshd_config.ipanew elif /usr/sbin/sshd -t -f /dev/null -o 'PubKeyAgent=/usr/bin/sss_ssh_authorizedkeys %u' -o 'PubKeyAgentRunAs=nobody'; then sed -ri ' s/^AuthorizedKeysCommand (.+)$/PubKeyAgent \1 %u/ s/^PubKeyAgent .*$/\0\nPubKeyAgentRunAs nobody/ ' /etc/ssh/sshd_config.ipanew fi mv /etc/ssh/sshd_config.ipanew /etc/ssh/sshd_config /sbin/restorecon /etc/ssh/sshd_config chmod 600 /etc/ssh/sshd_config /bin/systemctl condrestart sshd.service 2>&1 || : fi fiopenssh-serverUQ@UPU:UU@TT~TTto@TmT[bTG@TFJT@T T@SGSFSSS|@SNpS5d@RR@RRƦ@R@RRw@RsRNR7R7R q@R6QQ@Q@Q'@Q@QvwQu&@Qm=@QZ@QVQ(@Q@PPPPPx@Px@PnPj@P\VPG>P@@P4P.2@PP @M6@M.@M.@M.@M-M M@L!LfLNLdLLLzLe3La?@LD>@L#HL#HL@K/KՀ@KK@KKs@Kie@K`*KK@K @JJ@J@J@JJB@J{IIIm@I1Iq@IKIFFI9I1.Ih@IIP@H@HXHO@H-w@H HHH@G߮GGgGs@G@G@G@G}G}G}GG@GC@GkGDG<4G)G(n@G3G@GJF@FS@FFuF@Alexander Bokovoy - 4.1.4-4Alexander Bokovoy - 4.1.4-3Petr Vobornik - 4.1.4-2Alexander Bokovoy - 4.1.4-1Petr Vobornik - 4.1.3-3Petr Vobornik - 4.1.3-2Petr Vobornik - 4.1.3-1Alexander Bokovoy - 4.1.2-2Petr Vobornik - 4.1.2-1Simo Sorce - 4.1.1-2Petr Vobornik - 4.1.1-1Petr Vobornik - 4.1.0-2Petr Vobornik - 4.1.0-1Petr Viktorin - 4.0.3-1Petr Viktorin - 4.0.2-1Pádraig Brady - 4.0.1-3Fedora Release Engineering - 4.0.1-2Martin Kosek 4.0.1-1Petr Viktorin 4.0.0-1Fedora Release Engineering - 3.3.5-4Petr Vobornik 3.3.5-3Peter Robinson 3.3.5-2Martin Kosek - 3.3.5-1Martin Kosek - 3.3.4-3Martin Kosek - 3.3.4-2Martin Kosek - 3.3.4-1Martin Kosek - 3.3.3-5Martin Kosek - 3.3.3-4Martin Kosek - 3.3.3-3Martin Kosek - 3.3.3-2Martin Kosek - 3.3.3-1Martin Kosek - 3.3.2-1Petr Viktorin - 3.3.1-1Petr Viktorin - 3.3.1-0Alexander Bokovoy - 3.3.0-2Martin Kosek - 3.3.0-1Fedora Release Engineering - 3.2.2-2Martin Kosek - 3.2.2-1Martin Kosek - 3.2.1-1Rob Crittenden - 3.2.0-2Rob Crittenden - 3.2.0-1Rob Crittenden - 3.2.0-0.4.beta1Rob Crittenden - 3.2.0-0.3.beta1Rob Crittenden - 3.2.0-0.2.beta1Martin Kosek - 3.2.0-0.1.pre1Kevin Fenzi 3.1.2-4Kevin Fenzi - 3.1.2-3Fedora Release Engineering - 3.1.2-2Rob Crittenden - 3.1.2-1Martin Kosek - 3.1.0-2Rob Crittenden - 3.1.0-1Martin Kosek - 3.0.0-3Rob Crittenden - 3.0.0-2Rob Crittenden - 3.0.0-1Rob Crittenden - 3.0.0-0.10Martin Kosek - 3.0.0-0.9Rob Crittenden - 3.0.0-0.8Rob Crittenden - 3.0.0-0.7Rob Crittenden - 3.0.0-0.6Alexander Bokovoy - 3.0.0-0.5Rob Crittenden - 3.0.0-0.4Martin Kosek - 3.0.0-0.3Alexander Bokovoy - 3.0.0-0.2Rob Crittenden - 3.0.0-0.1Rob Crittenden - 2.2.0-1Rob Crittenden - 2.1.90-0.2Rob Crittenden - 2.1.90-0.1Alexander Bokovoy - 2.1.4-5Martin Kosek - 2.1.4-4Alexander Bokovoy - 2.1.4-3Alexander Bokovoy - 2.1.4-2Rob Crittenden - 2.1.4-1Rob Crittenden - 2.1.3-8Alexander Bokovoy - 2.1.3-7Alexander Bokovoy - 2.1.3-6Fedora Release Engineering - 2.1.3-5Alexander Bokovoy - 2.1.3-4Alexander Bokovoy - 2.1.3-3Alexander Bokovoy - 2.1.3-2Alexander Bokovoy - 2.1.3-1Alexander Bokovoy - 2.1.2-1Rob Crittenden - 2.1.0-1Simo Sorce - 2.0.1-2Rob Crittenden - 2.0.1-1Rob Crittenden - 2.0.0-1Rob Crittenden - 2.0.0-0.4.rc2Rob Crittenden - 2.0.0-0.3.rc1Rob Crittenden - 2.0.0-0.1.rc1Fedora Release Engineering - 2.0.0-0.2.beta2Rob Crittenden - 2.0.0-0.1.beta2Rob Crittenden - 2.0.0-0.2.beta.git80e87e7Rob Crittenden - 2.0.0-0.1.beta.git80e87e7Rob Crittenden - 1.99-41Adam Young - 1.99-40Simo Sorce - 1.99-39Simo Sorce - 1.99-38Rob Crittenden - 1.99-37Rob Crittenden - 1.99-36Rob Crittenden - 1.99-35Jr Aquino - 1.99-34Simo Sorce - 1.99-33Rob Crittenden - 1.99-32Rob Crittenden - 1.99-31Rob Crittenden - 1.99-30Rob Crittenden - 1.99-29Rob Crittenden - 1.99-28Rob Crittenden - 1.99-27Rob Crittenden - 1.99-26Rob Crittenden - 1.99-25Adam Young - 1.99-24Rob Crittenden - 1.99-23Rob Crittenden - 1.99-22Rob Crittenden - 1.99-21Rob Crittenden - 1.99-20Rob Crittenden - 1.99-19Jason Gerard DeRose - 1.99-18Jason Gerard DeRose - 1.99-17Jason Gerard DeRose - 1.99-16Rob Crittenden - 1.99-15Jason Gerard DeRose - 1.99-14Rob Crittenden - 1.99-13Rob Crittenden - 1.99-12Rob Crittenden - 1.99-11Rob Crittenden - 1.99-10Rob Crittenden - 1.99-9Jason Gerard DeRose - 1.99-8Rob Crittenden - 1.99-7Rob Crittenden - 1.99-6Rob Crittenden - 1.99-5Rob Crittenden - 1.99-4Rob Crittenden - 1.99-3Rob Crittenden - 1.99-2Rob Crittenden - 1.99-1Tomas Mraz - 1.2.1-3Dan Walsh - 1.2.1-2Simo Sorce - 1.2.1-1Simo Sorce - 1.2.1-0Ignacio Vazquez-Abrams - 1.2.0-4Simo Sorce - 1.2.0-3Simo Sorce - 1.2.0-2Rob Crittenden - 1.2.0-1Simo Sorce - 1.1.0-3Rob Crittenden - 1.1.0-2Rob Crittenden - 1.1.0-1Rob Crittenden - 1.0.0-5Rob Crittenden - 1.0.0-4Rob Crittenden - 1.0.0-3Rob Crittenden - 1.0.0-2Rob Crittenden - 1.0.0-1Rob Crittenden 0.99-12Rob Crittenden 0.99-11Rob Crittenden 0.99-10Rob Crittenden 0.99-9Rob Crittenden 0.99-8Rob Crittenden 0.99-7Rob Crittenden 0.99-6Rob Crittenden 0.99-5Rob Crittenden 0.99-4Rob Crittenden 0.99-3Rob Crittenden 0.99-2Rob Crittenden 0.99-1Rob Crittenden - 0.6.0-2Karl MacMillan - 0.6.0-1Karl MacMillan - 0.5.0-1Rob Crittenden - 0.4.1-2Karl MacMillan - 0.4.1-1Karl MacMillan - 0.4.0-6Rob Crittenden - 0.4.0-5Rob Crittenden - 0.4.0-4Karl MacMillan - 0.4.0-3Karl MacMillan - 0.4.0-2Karl MacMillan - 0.2.0-1Rob Crittenden - 0.1.0-3Rob Crittenden - 0.1.0-2Karl MacMillan - 0.1.0-1- Fix typo in the patch to fix bug #1219834- Fix FreeIPA trusts to AD feature with Samba 4.2 (#1219834)- Replace mod_auth_kerb usage with mod_auth_gssapi- Update to upstream 4.1.4 - see http://www.freeipa.org/page/Releases/4.1.4 - fix CVE-2015-1827 (#1206047) - Require slapi-nis 0.54.2 and newer for CVE-2015-0283 fixes- Timeout ipa-client install if ntp server is unreachable #4842 - Skip time sync during client install when using --no-ntp #4842- Add missing sssd python dependencies - https://bugzilla.redhat.com/show_bug.cgi?id=1197218- Update to upstream 4.1.3 - see http://www.freeipa.org/page/Releases/4.1.3- Fix broken build after Samba ABI change and rename of libpdb to libsamba-passdb - Use python-dateutil15 until we validate python-dateutil 2.x- Update to upstream 4.1.2 - see http://www.freeipa.org/page/Releases/4.1.2 - fix CVE-2014-7850- Patch blokers and feature freze exceptions - Resolves: bz1165674 - Resolves: bz1165856 (CVE-2014-7850) - Fixes DNS install issue that prevents the server from working- Update to upstream 4.1.1 - see http://www.freeipa.org/page/Releases/4.1.1 - fix CVE-2014-7828- fix armv7hl stack oversize build failure - fix https://fedorahosted.org/freeipa/ticket/4660- Update to upstream 4.1.0 - see http://www.freeipa.org/page/Releases/4.1.0- Update to upstream 4.0.3 - see http://www.freeipa.org/page/Releases/4.0.3- Update to upstream 4.0.1 - see http://www.freeipa.org/page/Releases/4.0.2- rebuild for libunistring soname bump- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Update to upstream 4.0.1- Update to upstream 4.0.0 - Remove the server-strict package- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Increase Java stack size for Web UI build on aarch64- Add rhino as dependency to fix FTBFS- Update to upstream 3.3.5- Move ipa-otpd socket directory to /var/run/krb5kdc - Require krb5-server 1.11.5-3 supporting the new directory - ipa_lockout plugin did not work with users's without krbPwdPolicyReference- Fix hardened build- Update to upstream 3.3.4 - Install CA anchor into standard location (#928478) - ipa-client-install part of ipa-server-install fails on reinstall (#1044994) - Remove mod_ssl workaround (RHEL bug #1029046) - Enable syncrepl plugin to support bind-dyndb-ldap 4.0- Build crashed with rhino exception on s390 architectures (#1040576)- Build crashed with rhino exception on PPC architectures (#1040576)- Fix -Werror=format-security errors (#1037070)- ipa-server-install crashed when freeipa-server-trust-ad subpackage was not installed- Update to upstream 3.3.3- Update to upstream 3.3.2- Bring back Fedora-only changes- Update to upstream 3.3.1- Remove freeipa-systemd-upgrade as non-systemd installs are not supported anymore by Fedora project- Update to upstream 3.3.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Update to upstream 3.2.2 - Drop freeipa-server-selinux subpackage - Drop redundant directory /var/cache/ipa/sessions - Do not create /var/lib/ipa/pki-ca/publish, retain reference as ghost - Run ipa-upgradeconfig and server restart in posttrans to avoid inconsistency issues when there are still old parts of software (like entitlements plugin)- Update to upstream 3.2.1- Add OTP patches - Add patch to set KRB5CCNAME for 389-ds-base- Update to upstream 3.2.0 GA - ipa-client-install fails if /etc/ipa does not exist (#961483) - Certificate status is not visible in Service and Host page (#956718) - ipa-client-install removes needed options from ldap.conf (#953991) - Handle socket.gethostbyaddr() exceptions when verifying hostnames (#953957) - Add triggerin scriptlet to support OpenSSH 6.2 (#953617) - Require nss 3.14.3-12.0 to address certutil certificate import errors (#953485) - Require pki-ca 10.0.2-3 to pull in fix for sslget and mixed IPv4/6 environments. (#953464) - ipa-client-install removes 'sss' from /etc/nsswitch.conf (#953453) - ipa-server-install --uninstall doesn't stop dirsrv instances (#953432) - Add requires for openldap-2.4.35-4 to pickup fixed SASL_NOCANON behavior for socket based connections (#960222) - Require libsss_nss_idmap-python - Add Conflicts on nss-pam-ldapd < 0.8.4. The mapping from uniqueMember to member is now done automatically and having it in the config file raises an error. - Add backup and restore tools, directory. - require at least systemd 38 which provides the journal (we no longer need to require syslog.target) - Update Requires on policycoreutils to 2.1.14-37 - Update Requires on selinux-policy to 3.12.1-42 - Update Requires on 389-ds-base to 1.3.1.0 - Remove a Requires for java-atk-wrapper- Remove release from krb5-server in strict sub-package to allow for rebuilds.- Add a Requires for java-atk-wrapper until we can determine which package should be pulling it in, dogtag or tomcat.- Update to upstream 3.2.0 Beta 1- Update to upstream 3.2.0 Prerelease 1 - Use upstream reference spec file as a base for Fedora spec file- Rebuild for broken deps - Fix 389-ds-base strict dep to be 1.3.0.5 and krb5-server 1.11.1- Rebuild for broken deps in rawhide - Fix 389-ds-base strict dep to be 1.3.0.3- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild- Update to upstream 3.1.2 - CVE-2012-4546: Incorrect CRLs publishing - CVE-2012-5484: MITM Attack during Join process - CVE-2013-0199: Cross-Realm Trust key leak - Updated strict dependencies to 389-ds-base = 1.3.0.2 and pki-ca = 10.0.1- Remove redundat Requires versions that are already in Fedora 17 - Replace python-crypto Requires with m2crypto - Add missing Requires(post) for client and server-trust-ad subpackages - Restart httpd service when server-trust-ad subpackage is installed - Bump selinux-policy Requires to pick up PKI/LDAP port labeling fixes- Updated to upstream 3.1.0 GA - Set minimum for sssd to 1.9.2 - Set minimum for pki-ca to 10.0.0-1 - Set minimum for 389-ds-base to 1.3.0 - Set minimum for selinux-policy to 3.11.1-60 - Remove unneeded dogtag package requires- Update Requires on krb5-server to 1.11- Configure CA replication to use TLS instead of SSL- Updated to upstream 3.0.0 GA - Set minimum for samba to 4.0.0-153. - Make sure server-trust-ad subpackage alternates winbind_krb5_locator.so plugin to /dev/null since they cannot be used when trusts are configured - Restrict krb5-server to 1.10. - Update BR for 389-ds-base to 1.3.0 - Add directory /var/lib/ipa/pki-ca/publish for CRL published by pki-ca - Add Requires on zip for generating FF browser extension- Updated to upstream 3.0.0 rc 2 - Include new FF configuration extension - Set minimum Requires of selinux-policy to 3.11.1-33 - Set minimum Requires dogtag to 10.0.0-0.43.b1 - Add new optional strict sub-package to allow users to limit other package upgrades.- Require samba packages instead of obsoleted samba4 packages- Updated to upstream 3.0.0 rc 1 - Update BR for 389-ds-base to 1.2.11.14 - Update BR for krb5 to 1.10 - Update BR for samba4-devel to 4.0.0-139 (rc1) - Add BR for python-polib - Update BR and Requires on sssd to 1.9.0 - Update Requires on policycoreutils to 2.1.12-5 - Update Requires on 389-ds-base to 1.2.11.14 - Update Requires on selinux-policy to 3.11.1-21 - Update Requires on dogtag to 10.0.0-0.33.a1 - Update Requires on certmonger to 0.60 - Update Requires on tomcat to 7.0.29 - Update minimum version of bind to 9.9.1-10.P3 - Update minimum version of bind-dyndb-ldap to 1.1.0-0.16.rc1 - Remove Requires on authconfig from python sub-package- Rebuild against samba4 beta8- Rebuild against samba4 beta7- Adopt to samba4 beta6 (libsecurity -> libsamba-security) - Add dependency to samba4-winbind- Updated to upstream 3.0.0 beta 2- Updated to current upstream state of 3.0.0 beta 2 development- Rebuild against samba4 beta4- Updated to upstream 3.0.0 beta 1- Updated to upstream 2.2.0 GA - Update minimum n-v-r of certmonger to 0.53 - Update minimum n-v-r of slapi-nis to 0.40 - Add Requires in client to oddjob-mkhomedir and python-krbV - Update minimum selinux-policy to 3.10.0-110- Update to upstream 2.2.0 beta 1 (2.1.90.rc1) - Set minimum n-v-r for pki-ca and pki-silent to 9.0.18. - Add Conflicts on mod_ssl - Update minimum n-v-r of 389-ds-base to 1.2.10.4 - Update minimum n-v-r of sssd to 1.8.0 - Update minimum n-v-r of slapi-nis to 0.38 - Update minimum n-v-r of pki-* to 9.0.18 - Update conflicts on bind-dyndb-ldap to < 1.1.0-0.9.b1 - Update conflicts on bind to < 9.9.0-1 - Drop requires on krb5-server-ldap - Add patch to remove escaping arguments to pkisilent- Update to upstream 2.2.0 alpha 1 (2.1.90.pre1)- Force to use 389-ds 1.2.10-0.8.a7 or above - Improve upgrade script to handle systemd 389-ds change - Fix freeipa to work with python-ldap 2.4.6- Fix ipa-replica-install crashes - Fix ipa-server-install and ipa-dns-install logging - Set minimum version of pki-ca to 9.0.17 to fix sslget problem caused by FEDORA-2011-17400 update (#771357)- Allow Web-based migration to work with tightened SE Linux policy (#769440) - Rebuild slapi plugins against re-enterant version of libldap- Allow longer dirsrv startup with systemd: - IPAdmin class will wait until dirsrv instance is available up to 10 seconds - Helps with restarts during upgrade for ipa-ldap-updater - Fix pylint warnings from F16 and Rawhide- Update to upstream 2.1.4 (CVE-2011-3636)- Update SELinux policy to allow ipa_kpasswd to connect ldap and read /dev/urandom. (#759679)- Fix wrong path in packaging freeipa-systemd-upgrade- Introduce upgrade script to recover existing configuration after systemd migration as user has no means to recover FreeIPA from systemd migration - Upgrade script: - recovers symlinks in Dogtag instance install - recovers systemd configuration for FreeIPA's directory server instances - recovers freeipa.service - migrates directory server and KDC configs to use proper keytabs for systemd services- Rebuilt for glibc bug#747377- clean up spec - Depend on sssd >= 1.6.2 for better user experience- Fix Fedora package changelog after merging systemd changes- Fix postin scriplet for F-15/F-16- 2.1.3- Default to systemd for Fedora 16 and onwards- Update to upstream 2.1.0- Fix bug #702633- Update minimum selinux-policy to 3.9.16-18 - Update minimum pki-ca and pki-selinux to 9.0.7 - Update minimum 389-ds-base to 1.2.8.0-1 - Update to upstream 2.0.1- Update to upstream GA release - Automatically apply updates when the package is upgraded- Update to upstream freeipa-2.0.0.rc2 - Set minimum version of python-nss to 0.11 to make sure IPv6 support is in - Set minimum version of sssd to 1.5.1 - Patch to include SuiteSpotGroup when setting up 389-ds instances - Move a lot of BuildRequires so this will build with ONLY_CLIENT enabled- Set the N-V-R so rc1 is an update to beta2.- Set minimum version of sssd to 1.5.1 - Update to upstream freeipa-2.0.0.rc1 - Move server-only binaries from admintools subpackage to server- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Set min version of 389-ds-base to 1.2.8 - Set min version of mod_nss 1.0.8-10 - Set min version of selinux-policy to 3.9.7-27 - Add dogtag themes to Requires - Update to upstream freeipa-2.0.0.pre2- Remove unnecessary moving of v1 CA serial number file in post script - Add Obsoletes for server-selinxu subpackage - Using git snapshot 442d6ad30ce1156914e6245aa7502499e50ec0da- Prepare spec file for release - Using git snapshot 80e87e75bd6ab56e3e20c49ece55bd4d52f1a503- Re-arrange doc and defattr to clean up rpmlint warnings - Remove conditionals on older releases - Move some man pages into admintools subpackage - Remove some explicit Requires in client that aren't needed - Consistent use of buildroot vs RPM_BUILD_ROOT- Moved directory install/static to install/ui- Remove dependency on nss_ldap/nss-pam-ldapd - The official client is sssd and that's what we use by default.- Remove radius subpackages- Set minimum pki-ca and pki-silent versions to 9.0.0- Drop BuildRequires on mozldap-devel- Add Requires on krb5-pkinit-openssl- Add ipa-host-net-manage script- Add ipa init script- Set minimum level of 389-ds-base to 1.2.7 for enhanced memberof plugin- remove ipa-fix-CVE-2008-3274- Remove duplicate %files entries on share/ipa/static - Add python default encoding shared library- Drop requires on python-configobj (not used any more) - Drop ipa-ldap-updater message, upgrades are done differently now- Drop conflicts on mod_nss - Require nss-pam-ldapd on F-14 or higher instead of nss_ldap (#606847) - Drop a slew of conditionals on older Fedora releases (< 12) - Add a few conditionals against RHEL 6 - Add Requires of nss-tools on ipa-client- Set minimum version of certmonger to 0.26 (to pck up #621670) - Set minimum version of pki-silent to 1.3.4 (adds -key_algorithm) - Set minimum version of pki-ca to 1.3.6 - Set minimum version of sssd to 1.2.1- Add BuildRequires for authconfig- Bump up minimum version of python-nss to pick up nss_is_initialize() API- Removed python-asset based webui- Change Requires from fedora-ds-base to 389-ds-base - Set minimum level of 389-ds-base to 1.2.6 for the replication version plugin.- Drop Requires of python-krbV on ipa-client- Load ipa_dogtag.pp in post install- Set minimum level of sssd to 1.1.1 to pull in required hbac fixes.- No need to create /var/log/ipa_error.log since we aren't using TurboGears any more.- Fixed share/ipa/wsgi.py so .pyc, .pyo files are included- Added Require mod_wsgi, added share/ipa/wsgi.py- Require python-wehjit >= 0.2.2- Add sssd and certmonger as a Requires on ipa-client- Require python-wehjit >= 0.2.0- Add ipa-rmkeytab tool- Set minimum of python-pyasn1 to 0.0.9a so we have support for the ASN.1 Any type- Remove v1-style /etc/ipa/ipa.conf, replacing with /etc/ipa/default.conf- Add bash completion script and own /etc/bash_completion.d in case it doesn't already exist- Remove ipa_webgui, its functions rolled into ipa_httpd- Removed python-cherrypy from BuildRequires and Requires - Added Requires python-assets, python-wehjit- Added httpd SELinux policy so CRLs can be read- Move ipalib to ipa-python subpackage - Bump minimum version of slapi-nis to 0.15- Set 0.14 as minimum version for slapi-nis- Add Requires: python-nss to ipa-python sub-package- Remove the IPA DNA plugin, use the DS one- Build radius separately - Fix a few minor issues- Replace TurboGears requirement with python-cherrypy- rebuild with new openssl- Fix SELinux code- Fix breakage caused by python-kerberos update to 1.1- New upstream release 1.2.1- Rebuild for Python 2.6- Respin after the tarball has been re-released upstream New hash is 506c9c92dcaf9f227cba5030e999f177- Conditionally restart also dirsrv and httpd when upgrading- Update to upstream version 1.2.0 - Set fedora-ds-base minimum version to 1.1.3 for winsync header - Set the minimum version for SELinux policy - Remove references to Fedora 7- Fix for CVE-2008-3274 - Fix segfault in ipa-kpasswd in case getifaddrs returns a NULL interface - Add fix for bug #453185 - Rebuild against openldap libraries, mozldap ones do not work properly - TurboGears is currently broken in rawhide. Added patch to not build the UI locales and removed them from the ipa-server files section.- Add call to /usr/sbin/upgradeconfig to post install- Update to upstream version 1.1.0 - Patch for indexing memberof attribute - Patch for indexing uidnumber and gidnumber - Patch to change DNA default values for replicas - Patch to fix uninitialized variable in ipa-getkeytab- Set fedora-ds-base minimum version to 1.1.0.1-4 and mod_nss minimum version to 1.0.7-4 so we pick up the NSS fixes. - Add selinux-policy-base(post) to Requires (446496)- Add missing entry for /var/cache/ipa/kpasswd (444624) - Added patch to fix permissions problems with the Apache NSS database. - Added patch to fix problem with DNS querying where the query could be returned as the answer. - Fix spec error where patch1 was in the wrong section- Added patch to fix problem reported by ldapmodify- Fix Requires for krb5-server that was missing for Fedora versions > 9 - Remove quotes around test for fedora version to package egg-info- Update to upstream version 1.0.0- Pull upstream changelog 722 - Add Conflicts mod_ssl (435360)- Pull upstream changelog 698 - Fix ownership of /var/log/ipa_error.log during install (435119) - Add pwpolicy command and man page- Pull upstream changelog 678 - Add new subpackage, ipa-server-selinux - Add Requires: authconfig to ipa-python (bz #433747) - Package i18n files- Pull upstream changelog 641 - Require minimum version of krb5-server on F-7 and F-8 - Package some new files- Marked with wrong license. IPA is GPLv2.- Ensure that /etc/ipa exists before moving user-modifiable html files there - Put html files into /etc/ipa/html instead of /etc/ipa- Pull upstream changelog 608 which renamed several files- package the sessions dir /var/cache/ipa/sessions - Pull upstream changelog 597- Updated upstream pull (596) to fix bug in ipa_webgui that was causing the UI to not start.- Included LICENSE and README in all packages for documentation - Move user-modifiable content to /etc/ipa and linked back to /usr/share/ipa/html - Changed some references to /usr to the {_usr} macro and /etc to {_sysconfdir} - Added popt-devel to BuildRequires for Fedora 8 and higher and popt for Fedora 7 - Package the egg-info for Fedora 9 and higher for ipa-python- Added auto* BuildRequires- Unified spec file- Fixed License in specfile - Include files from /usr/lib/python*/site-packages/ipaserver- Version bump for release- Preverse mode on ipa-keytab-util - Version bump for relase and rpm name change- Broke invididual Requires and BuildRequires onto separate lines and reordered them - Added python-tgexpandingformwidget as a dependency - Require at least fedora-ds-base 1.1- Version bump for release- Add dep for freeipa-admintools and acl- Add dependency for python-krbV- Require mod_nss-1.0.7-2 for mod_proxy fixes- Convert to autotools-based build* Fri Sep 7 2007 Karl MacMillan - 0.3.0-1 - Added support for libipa-dna-plugin- Added support for ipa_kpasswd and ipa_pwd_extop- Abstracted client class to work directly or over RPC- Add mod_auth_kerb and cyrus-sasl-gssapi to Requires - Remove references to admin server in ipa-server-setupssl - Generate a client certificate for the XML-RPC server to connect to LDAP with - Create a keytab for Apache - Create an ldif with a test user - Provide a certmap.conf for doing SSL client authentication- Initial rpm version/bin/shipa-client/bin/sh  !"#$4.1.4-4.fc224.1.4-4.fc224.1.4 ipaclient__init__.py__init__.pyc__init__.pyoipa_certupdate.pyipa_certupdate.pycipa_certupdate.pyoipachangeconf.pyipachangeconf.pycipachangeconf.pyoipadiscovery.pyipadiscovery.pycipadiscovery.pyontpconf.pyntpconf.pycntpconf.pyoipa-certupdateipa-client-automountipa-client-installipa-getkeytabipa-joinipa-rmkeytabfreeipa-clientCOPYINGContributors.txtREADMEipaipa-certupdate.1.gzipa-client-automount.1.gzipa-client-install.1.gzipa-getkeytab.1.gzipa-join.1.gzipa-rmkeytab.1.gzdefault.conf.5.gzipa-clientsysrestore/usr/lib/python2.7/site-packages//usr/lib/python2.7/site-packages/ipaclient//usr/sbin//usr/share/doc//usr/share/doc/freeipa-client//usr/share//usr/share/man/man1//usr/share/man/man5//var/lib//var/lib/ipa-client/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -march=armv7-a -mfpu=vfpv3-d16 -mfloat-abi=harddrpmxz2armv7hl-redhat-linux-gnueabi  directoryASCII textpython 2.7 byte-compiledPython script, ASCII text executableELF 32-bit LSB shared object, ARM, EABI5 version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-armhf.so.3, for GNU/Linux 2.6.32, BuildID[sha1]=d13e88b3023e8145130d000f6ff7a1d5e9f15266, strippedELF 32-bit LSB shared object, ARM, EABI5 version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-armhf.so.3, for GNU/Linux 2.6.32, BuildID[sha1]=08109bd43dfe60ca2047183b757a259c4ecd9355, strippedELF 32-bit LSB shared object, ARM, EABI5 version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-armhf.so.3, for GNU/Linux 2.6.32, BuildID[sha1]=993a7280b67a900e5039a6d8e83666754c709079, strippedUTF-8 Unicode texttroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix) $9R(R(R(R(R(R(R(R(R(R(R(R(R(R(R(RRRR RRRRR RRRRRRRRRR R R2RRR RR RRRRRRRRRR!R RRR R R2R RRRR RRRRRRR R R2?7zXZ !PH6ER]"k%{Ht89.bDX#t+.tFײ _4(-t󐼡0xo銠jRSU BlW5H]ǕC*OTi2zxfϭ frOI:%g5iJϱ]$(aIz/QK$.`dWdvVX S7*07')D3]U-$BYygC*%^T2j5HVhIK?n*3.i%Tj\]&Έ[)>2畣QX:d" E8n^L*MhLOb!ςEO]z;!tNQӎuA=j X$Լ~jì O|ZFok%_]n=1W"LC &=Iǃ$>a64so)̜:z'oތvFkE.x%4(lK--s݀=ey2Rbz;"ˋ1եRn+e8wǸsč5㦽V IZ;V%4m e /?z!i?^899ߙfx.]Uj2\FoJ!B3 1zR pwɔ(8K͆0bjizoץ6|x-(UI6O}6\4lgRzr;d0k.F{&=u&T[NIǷNywi F}L5R0W] #(= mIDqiA ; ⧯N Nlz%+ww`Q.C/f8̬Y:Dg Y6Ƴ8*+AgR" ߲C{ mqyw-T: T q4$8o-R]Bi4gN4NARb^ORD ?⯠OU]՞,hu waeAY}A͝Nd 2JϽ $X8OD]=R鳄>ZCefECɇs% @0tEݷ(e5Z}`*jQ.v'EJ!`e]nE+q4]6ݐ*ih\.1'Ij[^-!HЙa8T*Nr$_GO0^VLVW}$jQto;-2oO&r9;I)"9EG0LĬ%1<h..icv4/ry oNyrh8W$oޟoinv\7DK'5=}5`c\2d## C2%󚎘0vB!lC[ۈjKxUwx4 }Z8L`dNcO섭zW1ui+1,4lN`jX)7b|Q1?$Jڊtų4Zʫ%Яzom}}NH=:oEĴD'2kk3P o.-mKe΅"aGV75JLEl4,R`7SD _BJKpފӸ86jS*< O޹~):5~JYb?z|[r * '@~Ufrd3`sV*{UŽcpWx7jفH6߇E]GR#`E?:G},Kk^ԋ \lt\(THPu!G̮??mDTN<c!/=Aí?njL/zSq͇njDQqTY#{iu4#׹NubVSdtaw<*wDKyӊ־Cˁ採Xrݹl5+]$@= Ew/EP}uQ\xHsj1wzZ<6rH^(n~LRh&JJԮyou+5n~qUƜSI3 mQ[Z2:QcPjvGm-]ye! $Ң!}sٝ 3tgUɵ=YD5jn"4:abV$Pj4WIt'rWsIV,)Y;3<-ůx *SԋSGCэ%?E-idТ3C|(vOpW+8 ϶z|D"X(x֒,XʷƄ[56j襂1̒:x遠LH4TBS ԐaZhm+DM9 KC'RCL#|d閤u 6H))f^ٸtLg2BԿx<DVmE8D]r'啤m<;b-K8uZ!wgtؐ<ԼTZcZ3ϊ)bq#-+РLK1g&MK\GCrEnsos= 0e8BQnR<[뀅Urcɢ6:b.O f&+: Х%qό5 yeخSZI~G,SZ/Uή>PεXzXcb ׼YW9à;9X/Ν |8?~i&l ?LAдCQGqgo* GW{L ՇXyĸH|bՃf?\B֗ACƱ=k:asIr,*ɔJ-b,ob=.tyԒ˯TlPlGqGH?t^˝%Y$AԔzbn_VՖG+|hJdշIzhU#>~G˖zQ;Lq R6Y8:#z.`\D[wg0PH*l:\#VT2q6H1쉷bݕV0eÒ+;y~٫$Ɖ@SӨW= zEkcz-B"}!Z6pQyf{ O5}ڞ=(1%!V~7xW{|0(m2$\֍ZZqPŹgK},q A{!Ȁ K)WX1wK](B yܤwLv(1"@txb۝8*pCmOW\)(ﮚֆ,ƤYBbIB!<<=D)ݭ1!p-[h[us_ +sV)5s'f %_K76د7 gT}Ǥ*QͦJ6Y.քW}sHѰFĚ( 7-kV%n=v r 'p+ln*o4FXAvo4ʦN$wV~g7t5]өG'2twI;SڛE9[^j[oy>]Ki9Ma "СaH_.&l9LQؖ娜S桓 xs]*׿R"[}ħc6iaon#|Rv4欑"oSkB$>s-GMsv~~FLPDS2bF St&$K~2Pҷj^,ZCnWe;jh<˜-ퟮduQ `^6␣~^ӧH e^jizӴE ّhqo|} 8q+z=kLbalk_[qUb_?앵7bhO (j~9x+=[6A[Iaa.ܿuK2]of)オ1:7{zl- 7PW 0~@`0:RK;:s|Mˎyv=!Xd}'p|[h¸o(XqkO݉Em^2b l]Ox$)9?o1yG#MhYJP _ќw1CP/)C#dXg(=#\ n@+EWNpS TȈL |;VpP=LnWpaG4h݁  W/.R>tCXLeSнрꛩduR\j@jK!^QxQޜp\`^,"- FxUs\X;R0p3z"R%'aF+Bǥ^dQ?%N~UӱJHYDzF8̝RSLݣEt;z,K r@-`x/LepŨK o[rXSL^Y`;,رPޓH|M]ob  2{Lqyp`AI:^d.>2Y]֗~XEPt]$ſ& ~1+! :,䋝fw`G:ۚ $i_&|b%5L(nڨ 3HQV"B>"/UB*3燀 9}d+*{9 aesCclޢY*RX<$cix@1f;1>@r:#OvdA> +S^gUiBB6g3cU vNMظ]v}Y)3vݨS35̈́7!]UtLQtf)=֙T{ny_p(\w!kߏOE4Zsnz#*\I>$iwњ`r}[^<86(K( mZ>&d6Xo])5d8HiI K6S^TM,\wpE\'MuP}"!h˘ %i,k\=0^|*ܸݳ¨LSti&Ae 9L)+{_#5i BĈWP{xٜYuB _0HU]?Fr\a (&+ϵVHpx';hyVp 6ѡx8?8 TͮP >9\=ha )H -#s cpƲ]qjUHE2IܛAfzJD4ͯs|Jn8c?ⰂPw"S g) ixdeO,8p~w\Kn[voW3ǃYٴƮ//N/Ѧ?U(B<ihi guÃ[|.t<ʞg,K+TnW"(KNf`kKXnh7X>Q՟n,ŽyH8W#fkV2 -x#TvHJ}zf"36S^GZ# gOerBwul|H)o?טb_)!Z.yM?댎Bjsz&1??g> n(LK|).b"nqe}%kq &;h?~Q"A])QwsQ8 JشO#8|{>2OUuO_}%vI:޴ 4b0Pco}%GF1VҎ7`R*VdFϞZ x}UyFn !$uj'Т=mñgf0_ cF% %sʭ!P&oO.iHq%m=@-+1QwL+Vn~d $ <]3a0zKu%^׬.Ⱦ m]̨dzKh!h=G:p!]0J:EHJevö@YfA.3"Fk+_.gcK3t6W.8Ɍ{4 x׵P8f7VqQܲ_װݳH:IF]jq)W_BcuՖL2Ġm\xBifX6v[7@f6[?Ad+hRmqϫRitq3g[U{]G'mn&(oq!Q-_#M*4]T\ZVi?)O-pf%H8 h{=g@LmG4!heZPDĕ! -(&#r@=~OQm2IijrHW @zpa3t'}J2U8RυCi OS+۔(kH'_ C)ȟ5"$s싸oL{\t}`<@I",#2N.&A KH# .=ꗪ뽴:TאiP dojnT%7U -?&$Q#qkY}Y̆cmBLZgޖ+l$MD;a+[15`QBVtNE)XpC1 6Y1`:Pvń:v $VReNK'crP)V]C)q?ӻ y],v[!8h՜N5NKgaqtt)o}CژR7[d\ÐaE҇b+^`8D䬮!.`)}/)&>Xx%~|9eQ3W#Ltq_}\"z٠cFV#hʼnG!UiyaNk[IC/9~5Yu!-DHYWfȁ9Qv2=RI&W{&+^l$ti1aE OwѦ0%:x]mkɈɭ bur%xa=d4=Mx^S@&PeNIwpāvm~rh+K\RX6.jzPus8U}4*Ŕdhb/N¡h*az\p|u@˞NTړ ]UEU9L?T#zC Nq'?U!Q{Hk,;l=?`m*ЄEYɦJb0}6E-M$uDr?@6{-H9{R K-l&%|xE2u':7Jʰ_(C75L6bh(u ]iжüxk4 Ӗ>k"vKXVxаYh ~J ~5)R^\kP qL-V~sNs-j!fj @)Fv#rEQ,7[vVhxhW0yP)IARK-p0zy5Cƿmƽo%$tQe Җ>߀0DUȏeϬ󧣈ϔu-YލT?'Z["ߡNpϊ!ܗ3rU=P",J˞ϐe_L.Glbۥ>شr=}ŪH"+F< x T*+8#z9“P@렡Nrk,ΐv|yx53@B!CL ݨƄ]/y=G.̜\Am4q8''Bq%\1 )\;F{mJ>X#ߘ xJٛˇBXNH7POS`ھNkVy-^ge-QV ]UWL\<Ş)BeDՉG,4;* D?@&'eN. 5yyo?"P1JݢW>L SlR_b$Kri0<8Pn EDLO9(Ɋ=eyGT1G]y"Byo9{.N0Z`Fb D nt*Q~@P~K77^zx(\$rB {2c IES\^Kdl H*i i>I LLqYKhR>lo_98l 5aԱۥWCմM`0"h۲ڕFɸ:&y6qZlb݉}Y=iz^fi57*FB#QԞl>bKBs]%;lCxx\::w8C (WObpA*!%]0DxSӀYXC%~{PքGQѷcvL[dw{߫3/D0zkO!y/iTz#;,C2lEbIS,pvˡ_+y~w;{wԑY;.Ӄ 'sVD@0K82"cp}_hҝԾT${7̯Jʈ%*h];o;`TzyyЂA':h :.PDorKӵ[E:8E% 2"\FرyMdf'Kٓ1Yd6Nu~av{^v΄ԋY\`(/Q@pXtEd3 ԊSE^\e4f4bznHs+E1Ir *J6_Oh uU?$.!:Mhۖ!!d Ֆ/Da/`j;@G `ýxs' Z4`e8}lG-[^ Nw^u.|YRMܾW 3[]cP;37/h;:ǗC$Ņ@4(,ᶕtQ/;(szP C"."oE1$p`Ld8e-_Wg׭0X3)L=ïsF5bڤܝh?ȃIk>3qͪ#iKuiGN,|4F"usz o3BP E,fxjW_R_;4x%6cq\J);+ud&p\&_-4Qb r#9u[zWbrM Qhy89$_ k8L*e %t& 2 E]9*ںjӶёdٸǓj]AZ\%⛋1,AL7أ$?z+7M罜h "$F5\wV % &DUr ē WWJ:f>*"9^L`[(Oҏ"&VtAwP[3nM!-nk_ɛQ Z\V @76\TqqA@=6?O":kͬA.S4`0FNyfE$g q~?AX fb\I>Ȇ0CNPL(yl@#R. `Cchdچ v}UN e.sqs|ń9?3LIOYNb4{oǂ/&mk3w&ZG؏xZ?Y86aUoo@ø!O)؅әR'j>di"_Y0 ޽Ӹj_I.lhpvR]N~m /3ɶ+niYW{yᡰq e,B/O' DioH+9:eN=kWrOiUB"%_}Lc PulV4'2{o6FlFIʞ̀az`¤JZ#QY;4!A$8{HQS9Rބ'3oqJaV'8zHp uѻRҜO;#ծIF5f s bm@qi}䮩\#H~9'ELЍ2fnz%7q@)ZNFlnF:_( o\ '}qP%9 *HrztlDH~ txx@k&+1I{40]Bop:ć>d, !G#s:>ΘAOpU]8 ծ " a&S.3KxntʘtIe<  *+Zb[F#b gy]^5yG ݅SE&D >: W[׎u  @RO$44%Jh: 0*p 0Qs~%N ȶw%#\H/X 8YXcp@aFԺ+"X9jLfӢś>NZ^6l'~JzTPX-eaC"z 1AhTARI8ޚ=h!H=|av/ۡtC@dvs2*SBN2hg%fd7h4AAhd )+@%WJ$.WLd2-.x` 7z[9?\f *#?Ox/:<4A>,UU#(ԗA4f֐^]Z*B^ǣtݦyV[N d?ʷ|~d25(府OSyo/%M֞6׹4c]HqcuN PǃH1>U8B :'XP+odT'iCB*jmrh<;䘗YPn\Q$ZղUOa<$-g&D:1 `өҟXF_t# 䈭PARz@f&KLF;ܳeKf"A] I+#.1VO2=8g^3*y~(VE` \ۯ,lJIJs&m qtGz:%7wxS$e]*޾?5mQ%mK3@G)#;mKڭcI gg^n=jb~HҜey*7WM 2pS_ ^XT)dbv%N9NtkxcKCrb}cpߨB~(י:^}SeѼBܳUfVAxQ錔,iM" Z|'>r4/4Yb1{:'mk~Waq^8ؓyt^,(0yZ;j,|wpl q U'( Bi143BNvZ2<%N*^NڨSokPA?|2:ȟ@]HND$C)`}<=\a򼀭@'T`m tMp[l@\][KT8ҡwiõsS$F o 繐A߰$YJ.#s9..Wfewo!xg'6l|"*z5Th=<#Gxm7%Eg ۮ ḓxY'AdG(X3/[ZׄEyr!{segy׎gZ&V쯣kj-a]8y7wmsbDߺ[,DFt0KeZsKCgèX4zA+Rsǵހ}gZu|P ? DZhf2$$,'1E5ߥ1 ,ݩ.ޒMiw3)|.uM|ރA@H8ڣS%!r1NwS2ר_kzf7:66>&:g/;mK}հZ_cLPeo;yُBs`aݐSȱTX2M# & V l߲eO ;t!p~`?]2oc%y1Nwd- '!3|cW6Z:M)ge"mQ혭tiNb|hޖ~Boepkg_&%Cu*S!*g}-\ܓcØ~57-lJh7 BwiuE-65=̒!Ktu[5c$Ҹvxm=c>~̊1:ҽ;rYbkxW^2c p$nHv|cCdh0ka]8ݡWx[ca~1_f84.c/do50V(s=ZA,mfJ+3lzyϊ/q&X?iZW e]- ]Gw%9&і)AIxгnOIWaTMyLȃ]6WPP|Nzs!wd?"hQBE1ı?7d#ģu{ cf yvE a xoVVt }oov_z#Хǖ ެqV-uKޭ$h0X$Ia.XUV Z)a>sغ$緭8dk&h )r v's&ԬC1e\fK ?T!O a%OiKhYXګ b"S3k8b^A4uDnOv6s9fϫ9Sm%BI,cDP!/J,yԤQG G+ˡNU_$*XY:KPGj{Z&MkKѤ!y;^u|K Ƨ)0#hE_hzxd#)6@tW`YF07qNnJ +\ZyH.o%qtvIl`G3\ [ 'id϶ E0U-صR 3`N] үU (4-EdBk*rV3b,:s[{S=z6R=%AB8CwG#E]1k;E}kiZdŮ{{ݧyO v \%P",7R=v;'`Evh:Xߎ>a,/NZx/x)('[UBASǴ,uÛiU\C{GW&C3qG!NeaCE:|Ȕ;nIb Ua~9hȣ* &` {(XDtjfcw~8}Mn8%-:P>>7)E]AuUw}p}~]O?D)qr/| f_"aqz@P!H\9kT+(ϑfx7tnq˦Y,i܈8L^{):W 6 ~ ;cޢ"F^!QQs´P$y{I `pasnťmƮh-S睐Ia" ٥eSV~eYc⿀j89d{gdEu58N!#c=Ma{Ȁ,O%m!.ن&j(0N6@ʋ8c%yKҟ2tJ8KLg=glR0!* 6T3mݬ/)b[V(Y'y(*e',W-(rG4(:2 <")74/ئN}͵Mq^kg1/4a)k>dQ%WbK# ԇt8 .h*Cē- dY[%Tי\7rwؕBbŗBjԊ[OG(6jKTB{}ZW%Ed]qE鞅:޹?W] Rx֦uuBք`InuKIpߞeDx2]&V?9xK$&,(4L!A83*>IZ,n2%-;+486ͺR%(]9"9~?֪?8|<k%)>kX:7Cx wwz#$V9D=` ȾP/;`2V(Vr_O%uی8LcYx1;k􂺣T oUD튵WHu|m0kxL)5?b#'sTIɀadjV8tkM987943y ^l1g&c$Kʙ-wr nIyF]<7/0 ]ZW>CT]vccęm4 L)IR3p:g3r /~R.O?;7W8*E 4g[8,&~T*' -;st]vD@tJQ\6@𓺦!G "CnEzF4/tǩn:mbE,2bWU5֣QhACM>$^oJsD);Lɔ*/-e1o_$Eec%Wј,HX -uU2hyTĔJdp:l0UAF Fl'D$D vh_m[;XE㦏WIJvSéK:纥dH=0 덜#}aWK֪~r(Ƈ߹ݧBˤUxǿA,VAzݝ_ѼAZ'3ç6zaIOKZb5Jݒ{a0y*oᧁ-72gRhEYZ&cDБFE.V0+& hq ˅QB[3Wz^,+$quo.zPӸDD+Ppˁw5WLA}gA}QˣӌB/RtAf߽v j`S!K=B?͛oL)|z)sE?6ly= s#t̮Snי}b%'3?<x(^GZlYU=`|]%<DžU)3+QԀ~ƇB$Dܵ#nfnaVmKYO8jʢP,.<tv^'u4lI FL;ЧcL4r>C`zǙCpVYD`,k22:k(U=lQg|Wi|曥r_c/ZUcPm^vt(F%?9J*#YZKs2*Dژvc2&]V9ˑweF!=y/^3.E&IߴJu&~\%RǚT:NBh jPz6IX&Gٴ9cgm(ȅĿvgp'lEP>4LMLIaQe_y%&?d=K=]l_h'Lc~ /ș;Bc3/G/A\M%EANxI%`3/2rRu=Gf; Gwf~k0 $h= rQL;coF|2hzli =0>y8SI8"D'֝ 1<k]~o緅&lԜETYF%~רX9 KH|O[1 hXby kCW-|?R},^H nn%PD瀴ξTbHݗ 75)l߹o& foCG 9&@&t瑉ʢ|$\B̨رgM6pӁ_9_^wڂ1< vS?ywu2(T?=)MQހou ֢ ^6lƭȨJYXY:mg1o4pw+t^(_P?Y76mUP1x:9F UdV ӎ&CY- v8Z=Z%2j}Wϴskq,LHy_ `905@3JwTLu#t3Ŭ+hBe uQK 鋤+WFD`=SAO>/3~qGHNo߾Z ,:}`hA*YE$~Yz,̋$N( j*R@// 3"mSKticZADJC? fY""TzVn\PH9]|>*d}YCAT:ÐD@.壇B3{;ؠ?:8q?23+nIDjŠq̿hWP]|<4x' y6SҶJ GLD͝4_^כKXyު !ou;(/\6_=*Q%?Tn:FvKJ/R+_0=KF-Ť}CG2LRpL ѯ #F"mZ%VEoxKkPڿc_&w1I}l晝]1Q!%D XT4@m#[qʼnH7oS +=н=j3z D|TM +~ϑV]}>f?,cxKI Wkr\+(Jne?2~ϖL<_xs 6}^/ݦ gWf':tu-P#!*d+v'k7,.wA"+mš]|Od#æ$\(zrSL8b$[H\2x&;v ܻs|OW+i5+M̻V WFk )%Y#G$sSRh k8\OS RE|Pr ~zũwФ]ʘv!0pX~Ǣ]r\Xq-SSxՅ˧}ήjxkLf٢,E9 37Vp|sI[cr!J JbmWl,jh~zIݪ$dܳդuCK:_L6#Ivk쀧mkO Է&y>.~ \χg_ZbFZ^n4Oкt0s{ !e*c˛&:sK fkW* Eù Ĭ$DzirUVa* ,,s7b7_z3[ѫ"#ǫ<8 )(6O:b;<ˈyBת/㿛N1}:9'Iaʔ8ՙ&!CzaUgɎ /sRN)]a+e,)M}p&3D:DzKbSi>7NcZdJ."p5M%~nweZ\C uXi2gj3r0sB׃|]Re˘T5,ub,iUwQTV]GVR5x'W1R5 \ πg\=w+ tq T,C_u׾LZuiZgk\mdbBBw 2kNp WW/}3l蓾xF7V|.186q(E]&l<V*ޯh Ίz~ͫFbNX^_KW)[k?вm0a|P4\) VI?>%5buУy[M!Mfo{AȠ}KhS spZcwZJˉE^mw]I\q3}>CFӤe4Ѷ`Ҳ9 KKwjKȥ],GAvuڀ(uۤ"7b'h6s%͏2qpyk&yȕ 8d4ky1+y,3Pr5:D_2 x2?bN}L}y@z)/꿙.Y!2HyVҒ&fבCO:Ь/ΞdR7\K(%=.9EO{WX&KFb1nN? Hޯ=Zg̸Yx]vtfaSYFkbJ[~  ˯v+|M=,[%Ncﲬsٴڏ+\9Jf"H~_ؕ|qVkU_4YfMdZN͚:~I¬Js=ES_ _ r;sR7{"GT,%(VO;CWnylH"6 "đ"س2ސ`"w`8x= `4i1.WwWĸZ&r*xmq7grڂ"6w i%3'G/Y F˾25Ι:2ա%\8kNO DZ3[CoA|]OG5ӝ́*w yG hTZF8DLs\ {œ FD `h P% |F7~cBsO|mCZ^>V4 iIQ[lwJ룳3uty$(9Os _EWt('9/s !N@byJLP+`t$Yu)}!&tyTS8.,UR#y-rCfu v!;քy`B?[@gU8x?ۨVQ$QN@=1J:}<"-H1>8`. '1=pb&k\#lfԟ=6fX rJj,>.IR_sk*G"R8 e5OǑl/4K7i/(]ccխkREJKTRǗB }n9 vXK #q)~hX潂)&Kek6Ĥ$R*v^lMjֻ~DtMeA Փp&F9zË߀|5 IڐQwqm!~{K. w[R>>h%Qヨ2R!YLN&2 R8G _9MLa[4@&5#ުQY˱4ɥDZm֠s0$OZz uaz䥣Х,gVz=a{6 HFX8!Rז` ?|@J9q[63qQwX! 3ؕ@?&?/yD ?".f٩7{o0$.Nxԭ$C fCu>]=k8YJ(A)t{݋z,T ˰Á+Bَf i8[2$O/Zz۫YA$J턂@Ij<^7$YX>~hW26+SLӔ^ŭ+0 Ssϰ[}IU?RdiF21lR)*u{.Q 胭 ~`E5!Ƹ4`%ƓHy g.0`şvq\Eba'N>NkLJPU -Yn{`~Ƽ砜 ZbZ0Xp$mD|+PAFKR]gL_ئvoȳ98|׮PcJnX7  >蔿kpil\; rz^ ~i,?dcŃ PԮ $rkBV݇ˑ My%)t6TH;7%ȑ>?4 NQd-iv Ug#O1+FW=0Q+kavA$i=<1)yx??P(ۏQh=ʴ܂z|z"Td턹!u+{|BX(c2X򈖸%Ȧ|?\kdUumHy;w2⯩ kEpk5\{n A'e?ɐ;@ rv<}|r g׭',EF<@v <~H5aqʪakVHS(SW E~۠!J٧ {mtqV T -JJ7/ךm0iVr7&F8<)2e"@gaixOQ+Zp7 ږpX`\ J`r  >wiaZu!)_W"}7jo?{#z}vy0кrc>3-ߧ%)R;D8v9 ޑ1 %v6JaOO'&+sZL؈Eݨj[%Hb 5_" h 6XMt~lQ3v.50seDq5ƥbp4 ^O k:A)!q%j$3TQ=s.hJtWQX A03XpS5yc  7Qyl6ejg %y!fuOgh,^93,Dj< ḬoV}I܅Aa;]-F^wP!"³ bL's9>ٸWf[^h⛄`%nQ)g-)/^2% CԆJ('Af@űk'1n?EK.Q^*ZJ׋=irh3ڸ ̣2Kޚnr@:Quߕ9cg$:qC30+ ՜$p&b;wGa/Y@Zmz u piNLvԺ"%qN vL߹"Myw*r~%7] p'Hw>԰ULJO_75׍M!jHe(D:A"i8M,+ 5&b>a#đ'D(/t cO կR @>Y{f!_8}ʜj:FXl:a0ʈ9逧U2_w0=M! SޅF(Sbx{$ʓ:S"h qvVV5senQ;4)KN隂AVL<뢖M&WbJB >k 5-M`v-{|0fi($oTܴ`_$gmWܭ|? B {MF jRG?6ĐWwAǰKx\c8l! o9>~˫T늓hw_g wAsDEH=8dXHWS4l:t~: THjrvi-ʛ=niI3(L[/$Zaqq~]EZбLYc[owj 6C;ݝ$9E0n  "ɑ^OK%z0]t;/fMNa` .jxC3t*٬mJCJMDijx} b.V)3((7QZi$ `W0W-7{e-Z?nV8VPQߣ^%V_+r]a6Ǹ;:w)cbǰ |<]Tb3n\ 6j] }W?vY 3.՞i"ƻa|lF3oW#Ar~qlAƛg| 7u@E&԰'Nh~5O*=n%iCښn }W5 &UuX\iU % Vѻ/t fe/b{y^KA ظEa>tf4%}Z*.圛N~S@.)[$(w$0Jʷ65ǀ6 n4:k#د+Jݷ%FBzY*5! _ :ZY=7Mf|(e̯< ! XЖ+65, G;(ۅLHWG .78 LǔSA78Hncf7ʡyџr#|T{!ͮ1'B:Qz~GFlDfV~X[?Ẽ@H =y(C[macM=M SFб嵮[|MNud-aj}Сu_ Q2}fD>)l o2qf? &93TV #MAWy*"<#$n;3C疗dM#39v(Vq :(4Y iMӹ& N>[Pc&I#+[t΂}cqޣOuas G.{*;䙭A ̿2c*sk()P=Gh: bW_pψ݀Z,R-D&:n>C8~{:n=5u.>_ls k1gv`0!QU:U/,ȭ2EV?-rxOİ"բQx]z$qHuDST`@jzGm|֊?=쬟4EhFZ}3 Me1ckSKѹݜ=i4;Qbr/>BOԄ yvX+N7/)ba&4,<XE5*4&9Cfdؗ6)D%7+lWN>ˏs68M;m[19xzA (ۃ眻zL,zt67K Lt/U7O=pզK@L+#Sht3Hwl6.F%9gOB k+"ҵk${ZpVm_"GX)wŝ>z"Sim4~kv$e ]):fXWdm|e[HC#5pж6X-#$Ec3<"aށǠA-՚Q,MFJC }F66 ،"狪/Y8As+OVhB7Mf=׻:̲:@N^&K<@nBqM7UOhRFꖺOf5|?E(Wts&XpPPDDvs̠wJTz`[|'a[ı]ʜ\($+c5`H?lԼxS5w(-wfׁNR.]DP1O09B+& ]m&TH Ey\6l~xhTm Ӯ/YAmf_eZsz2BkLЉgԓY+ L7Z}u$M#q);!Y^l5ŝ 7&xLT'ĿOcFSpFMh|bʮp\Mr;:Yn~¥|K%:%~nBTWFj1qoY{ d=3 6')@R_E1@{sMw|Y57ʤ ah K:"|,~* RΊ#ʎ`q04½ꕸZ}/mPl"Bh Rrkq({q.u@WqA:y@_,kXfmEB4nJ[svC^RQR9'́z" S I=-8^+mx wKᱪo73ֻ"iQ0l$5TL_{TMzw}@dG]Z耻4 !L Ű6UB渉f^LF ͽ։﮹נog{"رY/_3,ϏXXH,0b@sv@$~~4\$!r2/}̟V>܁L卙q*]!#R+vP/V"_+hF_?KD n.$j8H0|]u<8t6Gĩ- ,n-~=Ꝯ>R1A|M(+p~3YoưQ.j8Rgrfax9w1Pj p&zWc}D/oSyʐ<ս> pNt>%;R@|Mzi1ժܣX5:U~Qx??2"5wvz=of)mgseb1x ~4^!3 kM+WkzcE]S/7%uDNei]G2BV;Av&tHGH5bnbWԒ68l+=܃}~54GWȖzvl'M[tq4g2d=7Ar`67ldy/i-| "^LDgl|Gn0~N"i6N5Rii0˄v¾7NdF)`ߨ 1cLU:3{ju6*OtMHfr9=uIZu ~Ac j͔;h VA(\-.T/n{޼hz0"EDZ [M`o3y5M@H#/혳q4 G@FI%tpi?(\k ^+[uAzv=*̎5V:+Άfv S5EaMUSg5_4ʷU=Ξ䥷c![InCz`ZҎd` jk3(KU̺Tm~hm=DN4mҨ7V9VmwSUIW?|vS73sz5m/vx-ƯL3cjt\+ d@\7|'p>>'kt.ޡ./5p\PqrPpGLX|MKAjPZOͮ\x6 )^ OEw+DɪlĞ\&-[?oo߬G\y?&Lmü>,'h3)2;GLitJXFH Xz9xX;3i9Zx͡K?y^;!$G{߈_bQ`)`hf܋S^%m2;g0l4Iyi4W?fd),g]|ySaìN?{ZYvDCp#U WPS"pɌf;çe:.Cm$a<;'1Ɇh󁄻A&=+hUi*<(Eq]&dƠhٽ?]5!vjGǃނ ,EPz3R໊ .Wn#+[?̺Fq,gm5&OtyM]β!~uANZ oz_|w=mCQ'I7B 8.@hLLoN0riXոTqJQLuϹjgEHi:Ši (cv2l7n uUW +mkw:a! f }#V.\(%~읪% rc-w6^f҄ȑ 1׋De]0ҋlAuj%]jY<&iġ$;'41"61C(ne|7dy!. _W iw9Y> %Ğ$"BʋRaG~Φae[HLI⟥];&opFNxmҟu;Hȵ)L:Ꮂ|8,B=Dkj7f]<Jf$Y<~PF@ 6;%"sA |&uqшaWׄ`[>)zGZyb)UI$eC7ٵ$â+N^]:(6?N.x$M)G\~Σ#JJ1&گ?uM1b]%V_v9B 0m1tAOc ks\8#[Qe+ZIbLx`6aA u<Tm5e ؅Y^4Q\BZ%G&/vnWܤ1ieۆD/tݘ&45gЛNvW>YVӒ c^6vѻ3*MXD FxhzY.Ecg>mV–[5/9g A^ Dƫُ~&A?>~ tQSgjVW\2<xS}pߡi`=+_]M >he)߀MS:KK9A"ε9<â_]?YBT驝|/5/ZfǛ,-K%a8qiQޟ|`4و~9@6A}uAfp] pk[鷪\þ}pW;#߽HVQԅBІCnW!('Ze}չUmjTI7Q eD%1ұT*%nW\|{b@r|~1l5H LݍJ9]Ƣ (BsGɸkE* hlY{YWߡkW>rI6+>ѝQa9`zI׳/!_Wgaz/8MpZ C"?$R28 U1񜊱hhH&t#xg@W-oE769QI b Ǎ6{6mG>whB=$n=lմ")sRrO}ɲ^{XAXoa:A{VǴ<.&uH,wTQ t z(18ɭ+i9űE/.MssD_`T4*fVhxn?}=jr)tos*kjdL)[z;6dʒ1")yRi(ygR;FW5GlMƒ˿B=ayz6ON(jSnfXQxy{)N飬9{2{s/>VLTd:Y- ƶ&7gӅaȶ,ȟ괨 =@Y/}.1+P309wS|l]D-h"|'*K >C`?9^LMdŻ0()`부{NA$G6Q"7+]Ι$hJ_:PœApruW(y=˕2OK+myG~#9 .gN隗P4~Nb) ݡk^V, Yӂ}JпuT!b(, km`خMo2Vn?Kn$jFi;:v|'·bֆJ9i\:qEforo*oWu}M+l.᜸8Hoو U4T2mK>d{+b:3:3CY5=i%:u#k[}m2U7ED?+FfSPe)  wqDdg=#Rt7}{9]3guPЖ2yS#k k ;AfKsJb^։/,pp D'ud ZV:$D>~^ĻGL)U6ԍlNvm2 L(UD`ʽ3Ga|yRv@韐5Vv]%i6@(B բh%JL^TLyzGB mav?\r{֔[B1U}]\En(%ƾ3z_7U{s}9)&PfԔN½9b4DK"©xӣ!č\֩;ա'xNg4cPw3; U$j{G[@ Q^qkNK@tFCP[ 9;vP͔E-Gb!qٻẅg}mQEy8ޙb'`K#\$#b(gcqbėyl H[ijK"Y]OKWxBjr`J! O%y9$0ҹ3ً_P!_nt#S9֟X$V &do m~O"i;'WQLqݗhPK3x hfp/DQYKnj[r_/_F'>NgOp+) ld$IݓܳDZ (PCm!gn>(_YXNqAT.%*ev-meM7V`f|l/eo/igo l1q*iÂB*[ipHϘyp6[8ځG)$F5K]W>rG3B Tgf56it7txcbo7l( ?tБGKO1\88, @شrG4)<A9Zb-ԍ);^c`c.Gj xQJMY0!l0g7LEc_\j%KZh]E߽SIT >\'*}Wl@MnAʍcqU@9o4]S?ʭS岍ۍwpp74 BhkN5qNgΩ>86ֱתdKn4Ǒ[Az-|!rF#hzySnR1Ȁe-ɓ$_lIz̭6o'h%Q R(7% x ##:ӎb0#Z{Ǵ|Qb7bSrXU}OTz`Q;oӁ t;?6wp|qj+w:)]>oQ|$c=!q]x2=uZ&݄1nԣ£O^.<тP'_|HPo~*K/G3],Ii CtҺ^%8e`C/GZA8oQeC[i/XJ,VdQ Kƍw2ڵҗs'4)U"v"yԾj{֌A6NPR^%=v5YYc["P8N{)r.%uiQn+=RכbF޾lɋpP G! *MOQT_TU-}HJ~ xBBH +H=Qrm1aUݹ1FwD\ - "~T*N` JKJOB2Piӆ`?mid1[pirS)v!ȹb($%*IN]VZ|L5:NMφXA3fr>TCwHWьoAۻ:ő.3Nq˻&y˖00=xꊇoĬz{Zrq?#@1B1JhTxjH(@--۟mC]*eO,]!P<}CaPA0Guyѓ(IJ* Dc-&AVEݷ>L(j|Y \Q_*0:.tyg@k\[zn\!)__|gW*7[^a1iG[) i8+DI%v"A uZW+3ǼÜ o,R^(ea :H|J4i>_']rm1 GfRF%=P\9Nǽ4 `—-kK8lKS3.j 1X/DŽ7X ja=&S0 P{P%$g5G׹U<x{ Y0|SaSTwF {rpYE@Ӛ^}ueS[+Ez"#մ/m_aw*k 8z/Qe ;t6ܚz`(W">jVC o܉)X(轧^0< &Mm  X5 .`6M[yX7}Vhw~sl{k61Zᫌ-ZQu+Z+,]cU}Rfd* sRXdÒ![+0Ў T".Ӱ9d.o,<>6E91bߏƻAbs Tg5&1@cCoͦp Gˣ"kM{򜋰*=$D>qIxw4"}wEuɎآe g:Fbga95')J<-vDr/V݄AY[wE5_Tp?z^G4Y9&$*j/iۙ}wrw]ye `+8 8G3uI>.tՊ9$~>nY#X]N4Ѫ+szLo%Hj@d,nP -͵.1\p"]R}[%]VܥnHsQMƴラ(D V쎍PV98eT \D&t%ΔπM{"O7"oDvQHKA^Pߒ2bCV?4QQʙeDɼ|kҠ]ޒ_Ui ^Q0xퟭ8℘c.Ԅ+IP"{7X%E?ceSXyF_c-xDښX$  f"8Wi͡9 eՁû%[I@.u ؼ8RW"3"X7nxˍ`OCO,"= -?;YG[:)L]igY:6Q}=$?1,;Cg[cSsl'lփd~@_TN/ hQa17^Zտʹ:OY10B `*ċ][%"w-6: 5J'@u"Ladn Al*i!'6K L[uHn?A(rH;GVRrNډh3Jfnֿyin&pZR` mM*)dc͐Ighq2΋qG| 92VH _s=auF<@̹=$|6H;I^朜'N_~WV2S[O)r4೔[)UẸgOb*`l<ٷ}>XD&6E죁̺m:FꕙZ;T^ş'w&ئ?$0Ga6!5^쮥(F+fe82뻈f51W0%@g>x HeC*tHX 5l@58ZIevQ |Nu'fRuFz v]nNkXH ۱! sjH7^H%lF|$@I8; gKwDRTD{IJ.Xsz{5;WO|_v(ۃ4;nxhт8Wؘ IؿB0.?Rx$l(~ \ml2< Ie(wFKDlj?lo*R~}˝P}p}OjvX> k]ʔ2@*j _ 'VZ#l>R &=r~1'HL\T~mo /Lo.3N@[# 2ѡk m*goPn۹T-taآElN!2dn)M{uir# &*e2Y} 5T|l"i =XYfO0Z1¶8|9=$Zo*ttS:;;)27dmt%i]0*ŧg2κc8|M^Ԁ|"%Xf$ IW}CXYQ@to|X@M2 xA"8knÓq0-}uvn'z-ƺ"431f lpd 2tS3q52bx!]^@8fZH BHI3cx3s7;mx*y\t"X U-U.c"j ~+<fibz?}6{C?]+qoӑ}MPl=lzGp~?XlAfs_186=S=`؎ɠwȈFE;XG6 Ֆi= )i+\~X01-knc4U-NWCIW4$OWԤ?ER@eF}݂Dn:oݨ甍mDNV'[kZq;Q$ci W=h$S)˚?'5xӗ28?M;&![N%`p;(lqUnwxZut,g-N'[IFE*+&d #۫VSm X#4nTYC.˥+2I%f"zGm~CEWqnYlalVBks<|zscB0@{ǁ\)JJUy!K\%mTp)X,WUce2r!f0^$CȂI$RϕU"\PxiߢB!Sl3[۵=wyoHL6]n,S ՎBݫ9K.N>'fyB#| ˟V. pS,+٪8ْychaPP@-ڇ)dsg"x)'3,3K գB!1vCaN~}~W䕁sn-]Ffݏx@q P.&NlYG/7miMXGjk+r,dR> }i2&|5)݉(^ ŭ72'+N!hU;{^SShjqq(}!-Wa[F߅Ye f9҉]S9 T_ x3qt6MnӀDLdJ`#ͤ jЭ]xJ.Q̥-h|8 LF$CE9th< (՝JUocHaN@ٲd5&dkڂY<<=NpRO_d~`mxy$)fiip`Fo=Z7?)\5((K(hn4Rs0ORxhHldf| LMB?PXg}z7v%+n?gR书_ )lbVŇYA+yRWm (|xߦ1鱬DRcBiWP +ufAW@)*YX-`C\mVB"2b_C@Daw}]Ιr}Jg;0}}Il h>i:7"rKJ~KQF2pZP1䯬e?3tZ\Ǔ~U\oB>!'aܥ&H`.dX'cQHog?uHرϓsͳddI@Xy'͒Zlp; P-`̢Zjnfʰ` JAf B*/vKochx{'>6٣K?נr`Rj<d`pϯo]?$}DzۀĚlC6Q*}chm4nbc\YfӳfDŽLÄq8;x ^ۦY?t=d%pAaOBYLvJS(b8Ð8:<-ux鬚N|?U--YHb$ b(v=T8ܧOS+C5g\Vnj!7aPV˪Zlw0-9za~:lyį-i FPV7$2UG݀M D1X|膸nXB8gRv:jOʛ JjNтz]Pvb0ko%A0PTTL @C(v/e9AVmƸmm CC1 'S /VT߰)525EZPWUZ-J쇝#7p/NIcpQ6ld6<@RPɲ.nj"3?pHZV[?CWb[zgF,"$:q Ȅ88wDn2#1G}؇UIǚ=dn-6"@7q_Cȃhښ4^v骹)mEmnIكRv&rL$JB8K9 34=MgA4~(/1BzM9 ˎZbA>eWOd![1ZۤT5-yY];:sߚԉV1nuGNt%A62 wUbԼooPTHXqJ7s\-Qx[(NIs1܇# ;چX6%FeNIMl|Je5#x#9[D 3}󘦷ʶѩ5jg F& ~ @Y,ڋA(NǑP&0t;(B*?4DQy\/U$~Uﱄe77M+&(~xN=&kNa -\-Cx`wSnk&Sv+_L  v= w>ݾsPN*F]׿RluDMóڵO+1!lpIἄ'2B#("mѓ=u. TwWNVlBn=^"_ldE%1UL8}qD},ձuݏ,bU^jDaԛiإN3l{dcÇNYQp/FJ*ƻoEB"/"KD"ئ#K+S/1NKM{˧#ZG>;򔽪*C}BDUpdx$cAþJvr&Dnz6~)sh?4myT 84&(0/"k!04]WW$7'T'4ղ j2'B';6-~D63)PNu8[OF.͇|jv(hˀ%B]R 9}Z?q M'lyʆ9Ռ)0R82Zjam)$F^'>@·/ ![koPM Ibt6cwj4|(!yP#u'Em)\gRdTC",EZNz_kLs:Qz5 P`oՃ0]0G,;TDQzÿ7EuaiC9g61UuS0ҭHrWۋѠ-&4%c  *00Gt`R:$, gLNsqg0iX/{K澺0NUg+fKpTZW&=1aq鹒|)Ƿu{6jGe,Eд1mUS `;;̌[lfMf@Y#2@IØaKu6Ϳ|kiyhUǜ :cנV1-rE2ґϯlZj/_ DECg,HIUl̪SuPgjyYXUВO$IKaҵiFN;w+@'>7"8S6_U ҥSXF_ wZ}4:k 2~0TYyEF}=3+of_iZ)plޖ%] "@ x־mlFW(,?ݾ/HQ)HdG_QWDofVaίNYaA-I!aSN*+ydxyGOxW|y+Ŧ*xGIHa+P& &lSA=$ϥ f<R0Y V`M+n5Y":$6˭z:כ÷Nz͸(H<,T{}UB!n^+G9,@6) P'p?˹dBr {|YfʤWllrTi4bFgrwptI@X`a%X:?5R:"9|A`yMtؔeD@3Q?<|`~zT}xYzšjgIX@C.Ābؠ\Q#UC# K YZ