freeipa-client-4.1.4-4.fc22$>8 qc|~P>G?d  D 06; D$ $  $  d$  $ $ $$@$$99V9()*"&+"5,"8-"<8"@9$:E>BDG$H,$I$XYZ[\$]$^ bdeflt$uP$v wl$x$yHCfreeipa-client4.1.44.fc22IPA authentication for use on clientsIPA is an integrated solution to provide centrally managed Identity (machine, user, virtual machines, groups, authentication credentials), Policy (configuration settings, access control information) and Audit (events, logs, analysis thereof). If your network uses IPA for authentication, this package should be installed on every client machine.UQbuildvm-13.phx2.fedoraproject.orgFedora ProjectFedora ProjectGPLv3+Fedora ProjectSystem Environment/Basehttp://www.freeipa.org/linuxi686if [ $1 -gt 1 ] ; then # Has the client been configured? restore=0 test -f '/var/lib/ipa-client/sysrestore/sysrestore.index' && restore=$(wc -l '/var/lib/ipa-client/sysrestore/sysrestore.index' | awk '{print $1}') if [ -f '/etc/sssd/sssd.conf' -a $restore -ge 2 ]; then if ! grep -E -q '/var/lib/sss/pubconf/krb5.include.d/' /etc/krb5.conf 2>/dev/null ; then echo "includedir /var/lib/sss/pubconf/krb5.include.d/" > /etc/krb5.conf.ipanew cat /etc/krb5.conf >> /etc/krb5.conf.ipanew mv /etc/krb5.conf.ipanew /etc/krb5.conf /sbin/restorecon /etc/krb5.conf fi fi if [ -f '/etc/sysconfig/ntpd' -a $restore -ge 2 ]; then if grep -E -q 'OPTIONS=.*-u ntp:ntp' /etc/sysconfig/ntpd 2>/dev/null; then sed -r '/OPTIONS=/ { s/\s+-u ntp:ntp\s+/ /; s/\s*-u ntp:ntp\s*// }' /etc/sysconfig/ntpd >/etc/sysconfig/ntpd.ipanew mv /etc/sysconfig/ntpd.ipanew /etc/sysconfig/ntpd /sbin/restorecon /etc/sysconfig/ntpd /bin/systemctl condrestart ntpd.service 2>&1 || : fi fi if [ ! -f '/etc/ipa/nssdb/cert8.db' -a $restore -ge 2 ]; then python2 -c 'from ipapython.certdb import create_ipa_nssdb; create_ipa_nssdb()' >/dev/null 2>&1 tempfile=$(mktemp) if certutil -L -d /etc/pki/nssdb -n 'IPA CA' -a >"$tempfile" 2>/var/log/ipaupgrade.log; then certutil -A -d /etc/ipa/nssdb -n 'IPA CA' -t CT,C,C -a -i "$tempfile" >/var/log/ipaupgrade.log 2>&1 elif certutil -L -d /etc/pki/nssdb -n 'External CA cert' -a >"$tempfile" 2>/var/log/ipaupgrade.log; then certutil -A -d /etc/ipa/nssdb -n 'External CA cert' -t C,, -a -i "$tempfile" >/var/log/ipaupgrade.log 2>&1 fi rm -f "$tempfile" fi fiZH33K3535`Fy9xK ^fA큤A큤A큤AAUQRCUQ~UQ~U UQ~UQ~T UQUQT UQUQU UQUQUQgUQgUQgUQuUQuUQuUQNTlIS#UQTlIQ^TlISS#T TlIUQhUQh6aee37bbab7f3a58a804bbbac141a103d5ec66674ef463477c3128b539bfa561b4ca5a5f8eb5032ea3c239e57a8bf39e86667b89758bc51059cc9d71c69f12b9b4ca5a5f8eb5032ea3c239e57a8bf39e86667b89758bc51059cc9d71c69f12b9b4fb0c233a649220a55ebaf8f78679d64bccac234504d4462d6a46b07f18622f3ddd23259bc9b45aafd1bcbed904562e871373ee3b436acc8de6e1274762703e3ddd23259bc9b45aafd1bcbed904562e871373ee3b436acc8de6e1274762703e65ae9d106c2c01d839f4ae1fb60767b1135364d5053133ab7a632cc806cbe259889fe93ec2c8f66b18d9189118ae74a55b45233d622347de8db00c2de1b06b71889fe93ec2c8f66b18d9189118ae74a55b45233d622347de8db00c2de1b06b71c42e8bf9eeb595ea78a972dfa2b52ef5924dd609412fa6a51824b7c9737ebedfc80c650afe6ea35cd2a0c96484b8ce48a45ac3c56c32039ff4946caf2c5daa5ac80c650afe6ea35cd2a0c96484b8ce48a45ac3c56c32039ff4946caf2c5daa5a4f0947b466c6857142a0b0fd5a477bec59f19744426cf4b8766aa01b8a7f812b981835664bb5f1512caa671a2892bf6541144b88eefbfaa9a2189c7d688a1fd2981835664bb5f1512caa671a2892bf6541144b88eefbfaa9a2189c7d688a1fd20288da5de6dc6a2fe632c82efaddc622fc5b3084004e517a3c9b3e61efb87bf80e062d7d4f534a80401de54a70608e6f22295a1c54b47b2ef0c7c771c820195795369608d42e5c8cd1adc33623ba2c4f6fe2243c54c603925faf717b616f9430fce0b6cd27d58253216bc200d0955e75a85fdd5f0b55e308245d10979c8f9be9fef3fdd0ce25dd811dd7618c7d86c6c9ac9e8722efebe86bb2a1e762e5392cb6780387736b3c599044ab16f013219accf0b48b3e3de10a1f1993a8d8fe323a678ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903fef71eeccc636521a2dc725fd31ff64cc60789125911551ca262ad498ddd2b7efbc215506be9ab1184fc83a7e997901cf9e63da8500598e5a9d7ef9b588225b2121d0a423cc66facd06fca0d904d135f0b7ef064a7caa99f97bca1f4e10202a4226ac7db51b406f7edf39c15194a18974e21de9d68d693de8f87c70602e789dbd93b060a71caa445e81310ebc9adefd25a3ef31b582dd712e9fdb52db75f051374259ea9396787a9a9cd3ac8819c30786147a59368417bc0d854d1dd07e5ff03499ba67992b575ebaad440be3056897eef062bd5f043faddd3a079d8b4acb7f366ce08b0ef4bd7fc5231c537bd270965e2f622c2111b7f3b512db27b7d5c5de90d1f6ba882f60416f58af4eadefe3a2fccff96ea4dc758ff7342fa3a9ce77963rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootfreeipa-4.1.4-4.fc22.src.rpmfreeipa-clientfreeipa-client(x86-32)@ @@@@@@@@@@ @@@@@@@@@@@@@@      @ /bin/sh/bin/sh/usr/bin/python2authconfigautofsbind-utilscertmongercyrus-sasl-gssapi(x86-32)freeipa-pythonkrb5-workstationlibc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.1.3)libc.so.6(GLIBC_2.2)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libc.so.6(GLIBC_2.8)libcom_err.so.2libcurllibcurl.so.4libk5crypto.so.3libk5crypto.so.3(k5crypto_3_MIT)libkrb5.so.3libkrb5.so.3(krb5_3_MIT)liblber-2.4.so.2libldap-2.4.so.2libnfsidmaplibpopt.so.0libpopt.so.0(LIBPOPT_0)libsasl2.so.3libsss_autofslibxmlrpc.so.3libxmlrpc_client.so.3libxmlrpc_util.so.3nfs-utilsnss-toolsntpoddjob-mkhomedirpam_krb5policycoreutilspython(abi)python-backports-ssl_match_hostnamepython-dnspython-krbVpython-ldappython-sssdconfigrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PartialHardlinkSets)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssdwgetxmlrpc-c0.76.84.1.4-4.fc227.21.7-22.71.11.13.0.4-14.6.0-14.0.4-14.0-15.2-11.12.31.27.4ipa-client4.12.0.1# Has the client been configured? restore=0 test -f '/var/lib/ipa-client/sysrestore/sysrestore.index' && restore=$(wc -l '/var/lib/ipa-client/sysrestore/sysrestore.index' | awk '{print $1}') if [ -f '/etc/ssh/sshd_config' -a $restore -ge 2 ]; then if grep -E -q '^(AuthorizedKeysCommand /usr/bin/sss_ssh_authorizedkeys|PubKeyAgent /usr/bin/sss_ssh_authorizedkeys %u)$' /etc/ssh/sshd_config 2>/dev/null; then sed -r ' /^(AuthorizedKeysCommand(User|RunAs)|PubKeyAgentRunAs)[ \t]/ d ' /etc/ssh/sshd_config >/etc/ssh/sshd_config.ipanew if /usr/sbin/sshd -t -f /dev/null -o 'AuthorizedKeysCommand=/usr/bin/sss_ssh_authorizedkeys' -o 'AuthorizedKeysCommandUser=nobody'; then sed -ri ' s/^PubKeyAgent (.+) %u$/AuthorizedKeysCommand \1/ s/^AuthorizedKeysCommand .*$/\0\nAuthorizedKeysCommandUser nobody/ ' /etc/ssh/sshd_config.ipanew elif /usr/sbin/sshd -t -f /dev/null -o 'AuthorizedKeysCommand=/usr/bin/sss_ssh_authorizedkeys' -o 'AuthorizedKeysCommandRunAs=nobody'; then sed -ri ' s/^PubKeyAgent (.+) %u$/AuthorizedKeysCommand \1/ s/^AuthorizedKeysCommand .*$/\0\nAuthorizedKeysCommandRunAs nobody/ ' /etc/ssh/sshd_config.ipanew elif /usr/sbin/sshd -t -f /dev/null -o 'PubKeyAgent=/usr/bin/sss_ssh_authorizedkeys %u' -o 'PubKeyAgentRunAs=nobody'; then sed -ri ' s/^AuthorizedKeysCommand (.+)$/PubKeyAgent \1 %u/ s/^PubKeyAgent .*$/\0\nPubKeyAgentRunAs nobody/ ' /etc/ssh/sshd_config.ipanew fi mv /etc/ssh/sshd_config.ipanew /etc/ssh/sshd_config /sbin/restorecon /etc/ssh/sshd_config chmod 600 /etc/ssh/sshd_config /bin/systemctl condrestart sshd.service 2>&1 || : fi fiopenssh-serverUQ@UPU:UU@TT~TTto@TmT[bTG@TFJT@T T@SGSFSSS|@SNpS5d@RR@RRƦ@R@RRw@RsRNR7R7R q@R6QQ@Q@Q'@Q@QvwQu&@Qm=@QZ@QVQ(@Q@PPPPPx@Px@PnPj@P\VPG>P@@P4P.2@PP @M6@M.@M.@M.@M-M M@L!LfLNLdLLLzLe3La?@LD>@L#HL#HL@K/KՀ@KK@KKs@Kie@K`*KK@K @JJ@J@J@JJB@J{IIIm@I1Iq@IKIFFI9I1.Ih@IIP@H@HXHO@H-w@H HHH@G߮GGgGs@G@G@G@G}G}G}GG@GC@GkGDG<4G)G(n@G3G@GJF@FS@FFuF@Alexander Bokovoy - 4.1.4-4Alexander Bokovoy - 4.1.4-3Petr Vobornik - 4.1.4-2Alexander Bokovoy - 4.1.4-1Petr Vobornik - 4.1.3-3Petr Vobornik - 4.1.3-2Petr Vobornik - 4.1.3-1Alexander Bokovoy - 4.1.2-2Petr Vobornik - 4.1.2-1Simo Sorce - 4.1.1-2Petr Vobornik - 4.1.1-1Petr Vobornik - 4.1.0-2Petr Vobornik - 4.1.0-1Petr Viktorin - 4.0.3-1Petr Viktorin - 4.0.2-1Pádraig Brady - 4.0.1-3Fedora Release Engineering - 4.0.1-2Martin Kosek 4.0.1-1Petr Viktorin 4.0.0-1Fedora Release Engineering - 3.3.5-4Petr Vobornik 3.3.5-3Peter Robinson 3.3.5-2Martin Kosek - 3.3.5-1Martin Kosek - 3.3.4-3Martin Kosek - 3.3.4-2Martin Kosek - 3.3.4-1Martin Kosek - 3.3.3-5Martin Kosek - 3.3.3-4Martin Kosek - 3.3.3-3Martin Kosek - 3.3.3-2Martin Kosek - 3.3.3-1Martin Kosek - 3.3.2-1Petr Viktorin - 3.3.1-1Petr Viktorin - 3.3.1-0Alexander Bokovoy - 3.3.0-2Martin Kosek - 3.3.0-1Fedora Release Engineering - 3.2.2-2Martin Kosek - 3.2.2-1Martin Kosek - 3.2.1-1Rob Crittenden - 3.2.0-2Rob Crittenden - 3.2.0-1Rob Crittenden - 3.2.0-0.4.beta1Rob Crittenden - 3.2.0-0.3.beta1Rob Crittenden - 3.2.0-0.2.beta1Martin Kosek - 3.2.0-0.1.pre1Kevin Fenzi 3.1.2-4Kevin Fenzi - 3.1.2-3Fedora Release Engineering - 3.1.2-2Rob Crittenden - 3.1.2-1Martin Kosek - 3.1.0-2Rob Crittenden - 3.1.0-1Martin Kosek - 3.0.0-3Rob Crittenden - 3.0.0-2Rob Crittenden - 3.0.0-1Rob Crittenden - 3.0.0-0.10Martin Kosek - 3.0.0-0.9Rob Crittenden - 3.0.0-0.8Rob Crittenden - 3.0.0-0.7Rob Crittenden - 3.0.0-0.6Alexander Bokovoy - 3.0.0-0.5Rob Crittenden - 3.0.0-0.4Martin Kosek - 3.0.0-0.3Alexander Bokovoy - 3.0.0-0.2Rob Crittenden - 3.0.0-0.1Rob Crittenden - 2.2.0-1Rob Crittenden - 2.1.90-0.2Rob Crittenden - 2.1.90-0.1Alexander Bokovoy - 2.1.4-5Martin Kosek - 2.1.4-4Alexander Bokovoy - 2.1.4-3Alexander Bokovoy - 2.1.4-2Rob Crittenden - 2.1.4-1Rob Crittenden - 2.1.3-8Alexander Bokovoy - 2.1.3-7Alexander Bokovoy - 2.1.3-6Fedora Release Engineering - 2.1.3-5Alexander Bokovoy - 2.1.3-4Alexander Bokovoy - 2.1.3-3Alexander Bokovoy - 2.1.3-2Alexander Bokovoy - 2.1.3-1Alexander Bokovoy - 2.1.2-1Rob Crittenden - 2.1.0-1Simo Sorce - 2.0.1-2Rob Crittenden - 2.0.1-1Rob Crittenden - 2.0.0-1Rob Crittenden - 2.0.0-0.4.rc2Rob Crittenden - 2.0.0-0.3.rc1Rob Crittenden - 2.0.0-0.1.rc1Fedora Release Engineering - 2.0.0-0.2.beta2Rob Crittenden - 2.0.0-0.1.beta2Rob Crittenden - 2.0.0-0.2.beta.git80e87e7Rob Crittenden - 2.0.0-0.1.beta.git80e87e7Rob Crittenden - 1.99-41Adam Young - 1.99-40Simo Sorce - 1.99-39Simo Sorce - 1.99-38Rob Crittenden - 1.99-37Rob Crittenden - 1.99-36Rob Crittenden - 1.99-35Jr Aquino - 1.99-34Simo Sorce - 1.99-33Rob Crittenden - 1.99-32Rob Crittenden - 1.99-31Rob Crittenden - 1.99-30Rob Crittenden - 1.99-29Rob Crittenden - 1.99-28Rob Crittenden - 1.99-27Rob Crittenden - 1.99-26Rob Crittenden - 1.99-25Adam Young - 1.99-24Rob Crittenden - 1.99-23Rob Crittenden - 1.99-22Rob Crittenden - 1.99-21Rob Crittenden - 1.99-20Rob Crittenden - 1.99-19Jason Gerard DeRose - 1.99-18Jason Gerard DeRose - 1.99-17Jason Gerard DeRose - 1.99-16Rob Crittenden - 1.99-15Jason Gerard DeRose - 1.99-14Rob Crittenden - 1.99-13Rob Crittenden - 1.99-12Rob Crittenden - 1.99-11Rob Crittenden - 1.99-10Rob Crittenden - 1.99-9Jason Gerard DeRose - 1.99-8Rob Crittenden - 1.99-7Rob Crittenden - 1.99-6Rob Crittenden - 1.99-5Rob Crittenden - 1.99-4Rob Crittenden - 1.99-3Rob Crittenden - 1.99-2Rob Crittenden - 1.99-1Tomas Mraz - 1.2.1-3Dan Walsh - 1.2.1-2Simo Sorce - 1.2.1-1Simo Sorce - 1.2.1-0Ignacio Vazquez-Abrams - 1.2.0-4Simo Sorce - 1.2.0-3Simo Sorce - 1.2.0-2Rob Crittenden - 1.2.0-1Simo Sorce - 1.1.0-3Rob Crittenden - 1.1.0-2Rob Crittenden - 1.1.0-1Rob Crittenden - 1.0.0-5Rob Crittenden - 1.0.0-4Rob Crittenden - 1.0.0-3Rob Crittenden - 1.0.0-2Rob Crittenden - 1.0.0-1Rob Crittenden 0.99-12Rob Crittenden 0.99-11Rob Crittenden 0.99-10Rob Crittenden 0.99-9Rob Crittenden 0.99-8Rob Crittenden 0.99-7Rob Crittenden 0.99-6Rob Crittenden 0.99-5Rob Crittenden 0.99-4Rob Crittenden 0.99-3Rob Crittenden 0.99-2Rob Crittenden 0.99-1Rob Crittenden - 0.6.0-2Karl MacMillan - 0.6.0-1Karl MacMillan - 0.5.0-1Rob Crittenden - 0.4.1-2Karl MacMillan - 0.4.1-1Karl MacMillan - 0.4.0-6Rob Crittenden - 0.4.0-5Rob Crittenden - 0.4.0-4Karl MacMillan - 0.4.0-3Karl MacMillan - 0.4.0-2Karl MacMillan - 0.2.0-1Rob Crittenden - 0.1.0-3Rob Crittenden - 0.1.0-2Karl MacMillan - 0.1.0-1- Fix typo in the patch to fix bug #1219834- Fix FreeIPA trusts to AD feature with Samba 4.2 (#1219834)- Replace mod_auth_kerb usage with mod_auth_gssapi- Update to upstream 4.1.4 - see http://www.freeipa.org/page/Releases/4.1.4 - fix CVE-2015-1827 (#1206047) - Require slapi-nis 0.54.2 and newer for CVE-2015-0283 fixes- Timeout ipa-client install if ntp server is unreachable #4842 - Skip time sync during client install when using --no-ntp #4842- Add missing sssd python dependencies - https://bugzilla.redhat.com/show_bug.cgi?id=1197218- Update to upstream 4.1.3 - see http://www.freeipa.org/page/Releases/4.1.3- Fix broken build after Samba ABI change and rename of libpdb to libsamba-passdb - Use python-dateutil15 until we validate python-dateutil 2.x- Update to upstream 4.1.2 - see http://www.freeipa.org/page/Releases/4.1.2 - fix CVE-2014-7850- Patch blokers and feature freze exceptions - Resolves: bz1165674 - Resolves: bz1165856 (CVE-2014-7850) - Fixes DNS install issue that prevents the server from working- Update to upstream 4.1.1 - see http://www.freeipa.org/page/Releases/4.1.1 - fix CVE-2014-7828- fix armv7hl stack oversize build failure - fix https://fedorahosted.org/freeipa/ticket/4660- Update to upstream 4.1.0 - see http://www.freeipa.org/page/Releases/4.1.0- Update to upstream 4.0.3 - see http://www.freeipa.org/page/Releases/4.0.3- Update to upstream 4.0.1 - see http://www.freeipa.org/page/Releases/4.0.2- rebuild for libunistring soname bump- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Update to upstream 4.0.1- Update to upstream 4.0.0 - Remove the server-strict package- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Increase Java stack size for Web UI build on aarch64- Add rhino as dependency to fix FTBFS- Update to upstream 3.3.5- Move ipa-otpd socket directory to /var/run/krb5kdc - Require krb5-server 1.11.5-3 supporting the new directory - ipa_lockout plugin did not work with users's without krbPwdPolicyReference- Fix hardened build- Update to upstream 3.3.4 - Install CA anchor into standard location (#928478) - ipa-client-install part of ipa-server-install fails on reinstall (#1044994) - Remove mod_ssl workaround (RHEL bug #1029046) - Enable syncrepl plugin to support bind-dyndb-ldap 4.0- Build crashed with rhino exception on s390 architectures (#1040576)- Build crashed with rhino exception on PPC architectures (#1040576)- Fix -Werror=format-security errors (#1037070)- ipa-server-install crashed when freeipa-server-trust-ad subpackage was not installed- Update to upstream 3.3.3- Update to upstream 3.3.2- Bring back Fedora-only changes- Update to upstream 3.3.1- Remove freeipa-systemd-upgrade as non-systemd installs are not supported anymore by Fedora project- Update to upstream 3.3.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Update to upstream 3.2.2 - Drop freeipa-server-selinux subpackage - Drop redundant directory /var/cache/ipa/sessions - Do not create /var/lib/ipa/pki-ca/publish, retain reference as ghost - Run ipa-upgradeconfig and server restart in posttrans to avoid inconsistency issues when there are still old parts of software (like entitlements plugin)- Update to upstream 3.2.1- Add OTP patches - Add patch to set KRB5CCNAME for 389-ds-base- Update to upstream 3.2.0 GA - ipa-client-install fails if /etc/ipa does not exist (#961483) - Certificate status is not visible in Service and Host page (#956718) - ipa-client-install removes needed options from ldap.conf (#953991) - Handle socket.gethostbyaddr() exceptions when verifying hostnames (#953957) - Add triggerin scriptlet to support OpenSSH 6.2 (#953617) - Require nss 3.14.3-12.0 to address certutil certificate import errors (#953485) - Require pki-ca 10.0.2-3 to pull in fix for sslget and mixed IPv4/6 environments. (#953464) - ipa-client-install removes 'sss' from /etc/nsswitch.conf (#953453) - ipa-server-install --uninstall doesn't stop dirsrv instances (#953432) - Add requires for openldap-2.4.35-4 to pickup fixed SASL_NOCANON behavior for socket based connections (#960222) - Require libsss_nss_idmap-python - Add Conflicts on nss-pam-ldapd < 0.8.4. The mapping from uniqueMember to member is now done automatically and having it in the config file raises an error. - Add backup and restore tools, directory. - require at least systemd 38 which provides the journal (we no longer need to require syslog.target) - Update Requires on policycoreutils to 2.1.14-37 - Update Requires on selinux-policy to 3.12.1-42 - Update Requires on 389-ds-base to 1.3.1.0 - Remove a Requires for java-atk-wrapper- Remove release from krb5-server in strict sub-package to allow for rebuilds.- Add a Requires for java-atk-wrapper until we can determine which package should be pulling it in, dogtag or tomcat.- Update to upstream 3.2.0 Beta 1- Update to upstream 3.2.0 Prerelease 1 - Use upstream reference spec file as a base for Fedora spec file- Rebuild for broken deps - Fix 389-ds-base strict dep to be 1.3.0.5 and krb5-server 1.11.1- Rebuild for broken deps in rawhide - Fix 389-ds-base strict dep to be 1.3.0.3- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild- Update to upstream 3.1.2 - CVE-2012-4546: Incorrect CRLs publishing - CVE-2012-5484: MITM Attack during Join process - CVE-2013-0199: Cross-Realm Trust key leak - Updated strict dependencies to 389-ds-base = 1.3.0.2 and pki-ca = 10.0.1- Remove redundat Requires versions that are already in Fedora 17 - Replace python-crypto Requires with m2crypto - Add missing Requires(post) for client and server-trust-ad subpackages - Restart httpd service when server-trust-ad subpackage is installed - Bump selinux-policy Requires to pick up PKI/LDAP port labeling fixes- Updated to upstream 3.1.0 GA - Set minimum for sssd to 1.9.2 - Set minimum for pki-ca to 10.0.0-1 - Set minimum for 389-ds-base to 1.3.0 - Set minimum for selinux-policy to 3.11.1-60 - Remove unneeded dogtag package requires- Update Requires on krb5-server to 1.11- Configure CA replication to use TLS instead of SSL- Updated to upstream 3.0.0 GA - Set minimum for samba to 4.0.0-153. - Make sure server-trust-ad subpackage alternates winbind_krb5_locator.so plugin to /dev/null since they cannot be used when trusts are configured - Restrict krb5-server to 1.10. - Update BR for 389-ds-base to 1.3.0 - Add directory /var/lib/ipa/pki-ca/publish for CRL published by pki-ca - Add Requires on zip for generating FF browser extension- Updated to upstream 3.0.0 rc 2 - Include new FF configuration extension - Set minimum Requires of selinux-policy to 3.11.1-33 - Set minimum Requires dogtag to 10.0.0-0.43.b1 - Add new optional strict sub-package to allow users to limit other package upgrades.- Require samba packages instead of obsoleted samba4 packages- Updated to upstream 3.0.0 rc 1 - Update BR for 389-ds-base to 1.2.11.14 - Update BR for krb5 to 1.10 - Update BR for samba4-devel to 4.0.0-139 (rc1) - Add BR for python-polib - Update BR and Requires on sssd to 1.9.0 - Update Requires on policycoreutils to 2.1.12-5 - Update Requires on 389-ds-base to 1.2.11.14 - Update Requires on selinux-policy to 3.11.1-21 - Update Requires on dogtag to 10.0.0-0.33.a1 - Update Requires on certmonger to 0.60 - Update Requires on tomcat to 7.0.29 - Update minimum version of bind to 9.9.1-10.P3 - Update minimum version of bind-dyndb-ldap to 1.1.0-0.16.rc1 - Remove Requires on authconfig from python sub-package- Rebuild against samba4 beta8- Rebuild against samba4 beta7- Adopt to samba4 beta6 (libsecurity -> libsamba-security) - Add dependency to samba4-winbind- Updated to upstream 3.0.0 beta 2- Updated to current upstream state of 3.0.0 beta 2 development- Rebuild against samba4 beta4- Updated to upstream 3.0.0 beta 1- Updated to upstream 2.2.0 GA - Update minimum n-v-r of certmonger to 0.53 - Update minimum n-v-r of slapi-nis to 0.40 - Add Requires in client to oddjob-mkhomedir and python-krbV - Update minimum selinux-policy to 3.10.0-110- Update to upstream 2.2.0 beta 1 (2.1.90.rc1) - Set minimum n-v-r for pki-ca and pki-silent to 9.0.18. - Add Conflicts on mod_ssl - Update minimum n-v-r of 389-ds-base to 1.2.10.4 - Update minimum n-v-r of sssd to 1.8.0 - Update minimum n-v-r of slapi-nis to 0.38 - Update minimum n-v-r of pki-* to 9.0.18 - Update conflicts on bind-dyndb-ldap to < 1.1.0-0.9.b1 - Update conflicts on bind to < 9.9.0-1 - Drop requires on krb5-server-ldap - Add patch to remove escaping arguments to pkisilent- Update to upstream 2.2.0 alpha 1 (2.1.90.pre1)- Force to use 389-ds 1.2.10-0.8.a7 or above - Improve upgrade script to handle systemd 389-ds change - Fix freeipa to work with python-ldap 2.4.6- Fix ipa-replica-install crashes - Fix ipa-server-install and ipa-dns-install logging - Set minimum version of pki-ca to 9.0.17 to fix sslget problem caused by FEDORA-2011-17400 update (#771357)- Allow Web-based migration to work with tightened SE Linux policy (#769440) - Rebuild slapi plugins against re-enterant version of libldap- Allow longer dirsrv startup with systemd: - IPAdmin class will wait until dirsrv instance is available up to 10 seconds - Helps with restarts during upgrade for ipa-ldap-updater - Fix pylint warnings from F16 and Rawhide- Update to upstream 2.1.4 (CVE-2011-3636)- Update SELinux policy to allow ipa_kpasswd to connect ldap and read /dev/urandom. (#759679)- Fix wrong path in packaging freeipa-systemd-upgrade- Introduce upgrade script to recover existing configuration after systemd migration as user has no means to recover FreeIPA from systemd migration - Upgrade script: - recovers symlinks in Dogtag instance install - recovers systemd configuration for FreeIPA's directory server instances - recovers freeipa.service - migrates directory server and KDC configs to use proper keytabs for systemd services- Rebuilt for glibc bug#747377- clean up spec - Depend on sssd >= 1.6.2 for better user experience- Fix Fedora package changelog after merging systemd changes- Fix postin scriplet for F-15/F-16- 2.1.3- Default to systemd for Fedora 16 and onwards- Update to upstream 2.1.0- Fix bug #702633- Update minimum selinux-policy to 3.9.16-18 - Update minimum pki-ca and pki-selinux to 9.0.7 - Update minimum 389-ds-base to 1.2.8.0-1 - Update to upstream 2.0.1- Update to upstream GA release - Automatically apply updates when the package is upgraded- Update to upstream freeipa-2.0.0.rc2 - Set minimum version of python-nss to 0.11 to make sure IPv6 support is in - Set minimum version of sssd to 1.5.1 - Patch to include SuiteSpotGroup when setting up 389-ds instances - Move a lot of BuildRequires so this will build with ONLY_CLIENT enabled- Set the N-V-R so rc1 is an update to beta2.- Set minimum version of sssd to 1.5.1 - Update to upstream freeipa-2.0.0.rc1 - Move server-only binaries from admintools subpackage to server- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Set min version of 389-ds-base to 1.2.8 - Set min version of mod_nss 1.0.8-10 - Set min version of selinux-policy to 3.9.7-27 - Add dogtag themes to Requires - Update to upstream freeipa-2.0.0.pre2- Remove unnecessary moving of v1 CA serial number file in post script - Add Obsoletes for server-selinxu subpackage - Using git snapshot 442d6ad30ce1156914e6245aa7502499e50ec0da- Prepare spec file for release - Using git snapshot 80e87e75bd6ab56e3e20c49ece55bd4d52f1a503- Re-arrange doc and defattr to clean up rpmlint warnings - Remove conditionals on older releases - Move some man pages into admintools subpackage - Remove some explicit Requires in client that aren't needed - Consistent use of buildroot vs RPM_BUILD_ROOT- Moved directory install/static to install/ui- Remove dependency on nss_ldap/nss-pam-ldapd - The official client is sssd and that's what we use by default.- Remove radius subpackages- Set minimum pki-ca and pki-silent versions to 9.0.0- Drop BuildRequires on mozldap-devel- Add Requires on krb5-pkinit-openssl- Add ipa-host-net-manage script- Add ipa init script- Set minimum level of 389-ds-base to 1.2.7 for enhanced memberof plugin- remove ipa-fix-CVE-2008-3274- Remove duplicate %files entries on share/ipa/static - Add python default encoding shared library- Drop requires on python-configobj (not used any more) - Drop ipa-ldap-updater message, upgrades are done differently now- Drop conflicts on mod_nss - Require nss-pam-ldapd on F-14 or higher instead of nss_ldap (#606847) - Drop a slew of conditionals on older Fedora releases (< 12) - Add a few conditionals against RHEL 6 - Add Requires of nss-tools on ipa-client- Set minimum version of certmonger to 0.26 (to pck up #621670) - Set minimum version of pki-silent to 1.3.4 (adds -key_algorithm) - Set minimum version of pki-ca to 1.3.6 - Set minimum version of sssd to 1.2.1- Add BuildRequires for authconfig- Bump up minimum version of python-nss to pick up nss_is_initialize() API- Removed python-asset based webui- Change Requires from fedora-ds-base to 389-ds-base - Set minimum level of 389-ds-base to 1.2.6 for the replication version plugin.- Drop Requires of python-krbV on ipa-client- Load ipa_dogtag.pp in post install- Set minimum level of sssd to 1.1.1 to pull in required hbac fixes.- No need to create /var/log/ipa_error.log since we aren't using TurboGears any more.- Fixed share/ipa/wsgi.py so .pyc, .pyo files are included- Added Require mod_wsgi, added share/ipa/wsgi.py- Require python-wehjit >= 0.2.2- Add sssd and certmonger as a Requires on ipa-client- Require python-wehjit >= 0.2.0- Add ipa-rmkeytab tool- Set minimum of python-pyasn1 to 0.0.9a so we have support for the ASN.1 Any type- Remove v1-style /etc/ipa/ipa.conf, replacing with /etc/ipa/default.conf- Add bash completion script and own /etc/bash_completion.d in case it doesn't already exist- Remove ipa_webgui, its functions rolled into ipa_httpd- Removed python-cherrypy from BuildRequires and Requires - Added Requires python-assets, python-wehjit- Added httpd SELinux policy so CRLs can be read- Move ipalib to ipa-python subpackage - Bump minimum version of slapi-nis to 0.15- Set 0.14 as minimum version for slapi-nis- Add Requires: python-nss to ipa-python sub-package- Remove the IPA DNA plugin, use the DS one- Build radius separately - Fix a few minor issues- Replace TurboGears requirement with python-cherrypy- rebuild with new openssl- Fix SELinux code- Fix breakage caused by python-kerberos update to 1.1- New upstream release 1.2.1- Rebuild for Python 2.6- Respin after the tarball has been re-released upstream New hash is 506c9c92dcaf9f227cba5030e999f177- Conditionally restart also dirsrv and httpd when upgrading- Update to upstream version 1.2.0 - Set fedora-ds-base minimum version to 1.1.3 for winsync header - Set the minimum version for SELinux policy - Remove references to Fedora 7- Fix for CVE-2008-3274 - Fix segfault in ipa-kpasswd in case getifaddrs returns a NULL interface - Add fix for bug #453185 - Rebuild against openldap libraries, mozldap ones do not work properly - TurboGears is currently broken in rawhide. Added patch to not build the UI locales and removed them from the ipa-server files section.- Add call to /usr/sbin/upgradeconfig to post install- Update to upstream version 1.1.0 - Patch for indexing memberof attribute - Patch for indexing uidnumber and gidnumber - Patch to change DNA default values for replicas - Patch to fix uninitialized variable in ipa-getkeytab- Set fedora-ds-base minimum version to 1.1.0.1-4 and mod_nss minimum version to 1.0.7-4 so we pick up the NSS fixes. - Add selinux-policy-base(post) to Requires (446496)- Add missing entry for /var/cache/ipa/kpasswd (444624) - Added patch to fix permissions problems with the Apache NSS database. - Added patch to fix problem with DNS querying where the query could be returned as the answer. - Fix spec error where patch1 was in the wrong section- Added patch to fix problem reported by ldapmodify- Fix Requires for krb5-server that was missing for Fedora versions > 9 - Remove quotes around test for fedora version to package egg-info- Update to upstream version 1.0.0- Pull upstream changelog 722 - Add Conflicts mod_ssl (435360)- Pull upstream changelog 698 - Fix ownership of /var/log/ipa_error.log during install (435119) - Add pwpolicy command and man page- Pull upstream changelog 678 - Add new subpackage, ipa-server-selinux - Add Requires: authconfig to ipa-python (bz #433747) - Package i18n files- Pull upstream changelog 641 - Require minimum version of krb5-server on F-7 and F-8 - Package some new files- Marked with wrong license. IPA is GPLv2.- Ensure that /etc/ipa exists before moving user-modifiable html files there - Put html files into /etc/ipa/html instead of /etc/ipa- Pull upstream changelog 608 which renamed several files- package the sessions dir /var/cache/ipa/sessions - Pull upstream changelog 597- Updated upstream pull (596) to fix bug in ipa_webgui that was causing the UI to not start.- Included LICENSE and README in all packages for documentation - Move user-modifiable content to /etc/ipa and linked back to /usr/share/ipa/html - Changed some references to /usr to the {_usr} macro and /etc to {_sysconfdir} - Added popt-devel to BuildRequires for Fedora 8 and higher and popt for Fedora 7 - Package the egg-info for Fedora 9 and higher for ipa-python- Added auto* BuildRequires- Unified spec file- Fixed License in specfile - Include files from /usr/lib/python*/site-packages/ipaserver- Version bump for release- Preverse mode on ipa-keytab-util - Version bump for relase and rpm name change- Broke invididual Requires and BuildRequires onto separate lines and reordered them - Added python-tgexpandingformwidget as a dependency - Require at least fedora-ds-base 1.1- Version bump for release- Add dep for freeipa-admintools and acl- Add dependency for python-krbV- Require mod_nss-1.0.7-2 for mod_proxy fixes- Convert to autotools-based build* Fri Sep 7 2007 Karl MacMillan - 0.3.0-1 - Added support for libipa-dna-plugin- Added support for ipa_kpasswd and ipa_pwd_extop- Abstracted client class to work directly or over RPC- Add mod_auth_kerb and cyrus-sasl-gssapi to Requires - Remove references to admin server in ipa-server-setupssl - Generate a client certificate for the XML-RPC server to connect to LDAP with - Create a keytab for Apache - Create an ldif with a test user - Provide a certmap.conf for doing SSL client authentication- Initial rpm version/bin/shipa-client/bin/sh  !"#$4.1.4-4.fc224.1.4-4.fc224.1.4 ipaclient__init__.py__init__.pyc__init__.pyoipa_certupdate.pyipa_certupdate.pycipa_certupdate.pyoipachangeconf.pyipachangeconf.pycipachangeconf.pyoipadiscovery.pyipadiscovery.pycipadiscovery.pyontpconf.pyntpconf.pycntpconf.pyoipa-certupdateipa-client-automountipa-client-installipa-getkeytabipa-joinipa-rmkeytabfreeipa-clientCOPYINGContributors.txtREADMEipaipa-certupdate.1.gzipa-client-automount.1.gzipa-client-install.1.gzipa-getkeytab.1.gzipa-join.1.gzipa-rmkeytab.1.gzdefault.conf.5.gzipa-clientsysrestore/usr/lib/python2.7/site-packages//usr/lib/python2.7/site-packages/ipaclient//usr/sbin//usr/share/doc//usr/share/doc/freeipa-client//usr/share//usr/share/man/man1//usr/share/man/man5//var/lib//var/lib/ipa-client/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m32 -march=i686 -mtune=atom -fasynchronous-unwind-tablesdrpmxz2i686-redhat-linux-gnu  directoryASCII textpython 2.7 byte-compiledPython script, ASCII text executableELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux.so.2, for GNU/Linux 2.6.32, BuildID[sha1]=d67d98a1695ff78002880e88c092624e74f317e2, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux.so.2, for GNU/Linux 2.6.32, BuildID[sha1]=886e6bdbb8876622fc389aa11e6dcf5368d970da, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux.so.2, for GNU/Linux 2.6.32, BuildID[sha1]=eb517a2882e4ec3fc12e380f62f6f6282a15e242, strippedUTF-8 Unicode texttroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix) $; R*R*R*R*R*R*R*R*R*R*R*R*R*R*R*RRRRRRR RRRRR RRRRRRRR R4RRR RRRRRR R RRRRRRRR!R#R"RR R4RRRRR RR RRRRR R4?7zXZ !PH6I2]"k%{Ht89.bDX#t+.tFײ _4(-t󐼡0xo銠jRSR/R/biǩ^ ټ铽Hy[u 65bxw` ) 8yS,^YN8$ʞ@Ym!D r06M{x& 5m_iEN2 Jdo2FH84z Q8D G \ڄ!h>3|HHZ2 L|1y Yw`XSƌ+Ҝb? 9hfx27A )LZBbw{$.ӑ'k=scc4;ad Nb!#牯\+_Uo)SʮT^9v֕'8trRm(; n;u>ّB׬{ |b9wǕJ zd]Iĭy ;@ͨbXٙj#dh-8qʑ3 [dLy2ә<Xd'Y"w!o"r>~O$bt}iVGRaۙ@\Ts<uiܷ3.C'Y^٣*7'`Gm%&qJ3yl5/7GoAON<]8O ` uޘu Q ӈf/2#`:UT֫t}wCς5DøeF+$?UT0>uK~qj&@\|3<}d|DIZyh:)gO*oay`E:E8\2oϯ`af7 XSCE<= Bi~omm.=VMR]ӟEįTN{˛Bob瓴2;vX)u*2Idgب,pzf܀H6-z~ߒQ[e %a"g-{Vq&G L ,6x.rԻSqkUɶ.g: q2I$С@k2 %ddž𡩎jY|<{J)틮(I9NN]|i?(ߪ\Zn{ۿndS>s,^\4z}wNơ/Cqc䆸? W">ZYGn0k W]]&vA~b&1;/1M L9F 3ֲDXeRIA:.'=˭m*N/Hb*XRKw[@ ^z57IwY8Dlc3z$D kSs3f1uͣ(ib% k*4QD o |Qw. (3M%cl7˕7CRz6K/K'AM3efG4NO*O6Вs)cXn+qr/Tr$ʔc&W<oIMSeTr~&* s6 ̭RZ  {Tԙ%tl8z`FY9VSDsmb4e=癚 n'MU MV)Nrʧ[M:Mcހ\*9ەVa+#_6PŤ3 Rٖq-k̳ n! <k*ܔ!SW`RR)mGH{l*|2D0/ɭLTXe]gEP]ϳTyhc?`cCv 8;jNm{Q:']:j][዁MU14gf|HYbr{͊7}͑[ιe8tP^S$%u?ݚ8^%|=FjM*?V+ggy }pb u(_kMĦRyNN `A8d~l~ q-s06Pdmq}CHD_9 JoO,M:R0p۠MEA$2[`Aus ܺ hUr?Jc܇U9=yKRnYkUD(I8$Pbg!|;y2,IǶJlg6ߤQZ&j^Bئ4̼<M@L(W]Z)>+:u9w72K8Dj@ ˀH}?xJTX")CVޑu7haa,Omek2AGL_ut}8fDV^sY%e|8liʦdk]ԁP#bN oLt%@I0/V=>ܭ=+xGBD tа^][NO(~.>:.i֠clؓ&PP(Bj4u \ehrH}WS͹#L*']PGS*47C;=PEM tHN!+홄cͺg]1lJ!HE?͙ LuVMDZfQzŌSA+>¾1"rg|Rp&n gFUΚ*(=㘌4% n* ")B>;t S U(>Xhtnb ,x45== GX|[Ƀ.Ecgcr]Vef+Y˦pÈ} ͵Az-P+SlR 'i֧gl~zb(p6Gu W1Fuf' ԂI) az OҦH reYm EM9L\Q{#Nn{᭭,q|R7'&F92>IX9X-hj8vSy?IJeVZRFxЧ3Ǹ%t[poP!B]DuhE> @WF6&I."mE{% +F>eOZuhcWjh?2$CK^W &Z+M՟ 7&GJn#H2FnYOuO)TX zSlhJĹlf5xK rKzf*8 S`\MPJϡ·/*_F Pt E?b h_ld  ڽƔy'k?ESN`mQ!*l,0_?ʊE5:sSJT 5NV[/opHb v<&4.d=_}KZRW|4''T2U&CxS\ֹOڧag7~H6zhTRmh._\}4CN{a=>,iO$ӇY5Sszr |&ؖcV: hſxR'20/iWhLT9sMD kq*ũ hu H6ە @2"ptRy` К6`==~vU-hR?u#t5\iKrY(z`u{ ) ;+Nx3b-b3jjůWY >Z`?O{Ec:ؙ(Z,bS?뤋08ޜ!J+|<aH_swƜ:n◦,T%V>w6-w:մʒ7Y:q /=ZڒcsU] qau2ܚ>k_T#E #F~#cay"2[+=LWZ,;;Lpq>cn_Ưdwn햬p42̙)pft [|@HsH?03sN|,PɓVÂ_ y8*RoI 3h㮹1|/vu!7ECDeDXWs@;)WARb{}F'ڼkJ_\$vD"cɦh3HD;8ztsCd YYP?=P tΔT>0ŻYU;h@e7rcF 9K8j鮻 [ :5>.W8. eg҉f3nמ 6uMTV_1 h_baK%wmKW!x7r$c'OFEƎSᆹ4f2 3q.A疁LOr8y V CL%!8'.6i" 6IUWhNbۡdF=p~DJ/$~W,dP7b J6[r9Cª٤m]κÞ*T'21O |cОwK=ԣFEED:_9Zo`txl )*#r+/7?Ai 4:ݽڬmY0 Ğ1tI Z_x LMc>LeYbXgQ1 R3ver|&2|pQ{p^uQRITb%v,(Ƈ4,&*J_}] i OUh~"K}"9д?5O &|2O`lT!0MfȊhHPdzwU;QR<Ԡ˽ɽ-m 1^zo gJfK !m5g((PP* ^ǵ:Tޣ̄}4 6WNkr x xPWXBy[F}O҈>"ν9{=Ho:[2?͋,ZfEnALYpNGiܣ{9dH[ccxȇƱ?~o2n{RIi_H*vVc ^4Q˚?M;H&zx?P,jV gthx~QV70 ^aigTq4MsaaOV@n婂hu@̛Ny7.肪ޗs"MeKK)*Qʢ%+`h"ph2Nvңl2x/#~)~ Đ[`,ޕbPc1yB`CJ~,&cWS̈́K?-E 2'kEE8 >D՞25?8d:HXT5Y鄊x)!@wuMQ>'k1};}4d-gҵB"\$rCn-0ZkG/Y!N75@!vzHţF&h [Iw&Vvwx, d)RB_mǬ%獐 x<'ëC5P?ڏT[>?&CR sQ-+8SD[!!Q!Z~l=FDW b?LYWHlMBe t82fzv+myRZZ͕[]^Tyl6n& zº˿K":;Kͯҝ6RFd/j<ɼe,.[耮f%Tr*eY7&spi$wt gIFO9 P3lXh<2p|sݝ;?mಒ؃n!{ |h?-Yf`yKUTfq0b}eC)s:պe[gW>Li>*/`m7cKR%8a`04.hzK4Xo:2ըൌfa}Go虿>'yql(Kg)&WM潁%naOxMs Fnȟ1A5:6>f6kթRGOTnr1$үRْLBQ_yX*Ik]qټc//7xvO1Fme[]Dh)*M'Ap2o飪T۔3o'v$NLtG;Ľ:NYd a/.2nUz ^&8<Hװ^F %gfiH'(d`$x40QKai6[+O!zM) X&t{#~=5ʅEAH:D3~vXHwﯲwȈOIߨc-JEz hݼ3 ~SOD56TEx0+sBzFlk1'?gSp=2* ̇Q`ϋ)xs?ly'UL~2]YvEᣭ7vQmmf(v2ilE _#QlƆ1V @}\Ld3ZƷXAuGdj,!~\O\sH'.w~N * .p>Xb'% ]0$N6;?nF9{KF7 yp@5e%I[fa|#k^PA,MDf18qV4c˱)#, ؒ兘?aO \ã?F|ĝcl;hKi̸4<]vwaG d`E"UjCQ;] @{MkŅ yV.UPXV1-6'vA+0Tt16Z5:<')n:9C;P #(Vw]U,ZI~性}Qe{2pȼ}΂τ^~%fW:EEаDMj/ Vdԁ#ck 8aII2EU4Ϣr/J!gyLlR s$ߛoFF~ zH3+KI?ҐZK%X-"#l9H_N^0xtWȮ֨(3sni-I' Ykz :7ۅVض:ii>B15tW}$MvnHĄ ~ObrU,7$d.UXVY%?/]y^/6L_L=d!ǍWΖ oW0K Gi[4վs8Ey:cVjvʚZ$=^ޅ&!vFxRz,r8ٟG w W O[,у!M߹txtOAWZԤ&+(oAkpU\ɉBD G(GoI1+d"mfМ l>^1%#W'Ɨ(4s|ڌ%L4V2h*hד%yov-S}r02!jԕ`>Z]MAg u7/uxUYr?4F̼[=wm ZƔ =04mՀ%A4GFf# Ag+L7TӖT_,p]I]kK* 2Gd] ׀ f)$I?jĎtA0 $c9*R}Kj"q]H iC2:EHf#+l-(dO ܙfHd ˚j_u55'Ag) G$ōKVP1 (@!!ړ8Ȼq[;ty g0mN&jC.ϼ?ts iIhܵG8UTtZ.zRjU~̌D_펅zovbE[{> u{tPakǑ]0DD`eA{@(Os t%V "5: -aA%?dGh2-hƂgVkl@=͋K0N#5۠Q^*:p'Q@ 6 a Q(6_)OzT~#A4)Z15  lCP &ۉ#6Ʈ >ұ鼓QUEV/-*ǫ&~9Ƭ ;uȲt"DɯQCPSLʝKP|؇pn0U*n9!clo-0)A=Bs~y9;Jc6;XQH'_b2z V!QFnY%$-?*fDž]n4ɭ9cMؠ}co\uTȄ_B@^ePV^H6E%S"C|5|ԹW8Q@`]wwG9Bh)cf*w|VAAŲCIjlK_hv ,i5` T3(H^jGR6 M:X,]?2Ai0=iybJ}7D:N/Kj;E 6aKa)~):ƛ^f&n_~nі3 >F*txLbom#JdNBlKOBlOcJӣb K694A5B =ou}=nL)U@D &rަZ/ۓm• beV֥%sdJ ^\gxL٬ɮ}?&mM(KyyŜs|z?IqdpWԍQ< ~0\ d8;Kn<{Gyy'G]hoM;g2υU%C3č}(W%{ /U!\g?Zh6MJ7QwY" Xk)r(FA;|<!wcaZGd6BV@*̛[ y2N#$`c%r!TExvGPpt#Qá7@Q]w0mgN ͵I8wfX0 NGR/ǀO}A0SG/@"c0`/ZLІ QkCTd,\Kc  'O"Ebqθ)~@Y[v7:rw|0 k'Sf)Y Y.a@8ᚬzHt1i$c4je9fU _%7ڣzV \ǦڧU&5řI[L1ծY=es8Y)&-)^M7,9cVtϜfTQTԯe\('7#|Agi?}@gütI FFgC,u$;@=).=؏BTLXgK`5o0N2ΜQ۬ ~"S@ ?F JX9\aPPT@}_Ɖs;4y+g5m1GV-v!MM>]{3loemmM?JkbS 9l bnzo;^QXs[YFBON}'ֱjoQGK,hg25;ڢF7(?U+c2/L,ªb H_?cW @YS :@Z bwT(XNTbSg: g=U-[~Q󠊌%#LAA)*?ׂ @ Mm(|]eY5Ɵ+o7y}DD3fz} L%ZS]s -KV-SUXKV)N+ 1hm~LY ͓^1G8^;('x6!E}1A@ϧ4WRvxݤnAcPLf%biƙ.umȗE[׃l sdnY'D"=SFX-jn`gMx~U z'L Wh5~y+.{s Ԫm4A2¡ܥA,rH5B&@dy׈ 7W2 7mkqʵBtmYn0D$6sV_)屷vP՜ڗ( Lx)UQ h) 25/V4[y>ܣt6UDm<F:#jWᙒMo"}`O:5};w>*7/Zq@|]8rU %ڂM`*_=fuwM[V$H"IܒkǮ|a~e+)`,{d04%EHFX^47\~]𷛉ilX$;Rԏ\:ao[gs$}"AIݼEQl߾ Pl ƅXr 37iԦ2-sfot/)/uaOB*31C[d@,rZ@|]:7 |Todŕ+ny(+ѐD+7|]򜪃z Xho~# _ z*\U0 lʐ?M f$! ЙSުyAL[go{y1^쉇q:R$ҟ3C9y++6"w"O5T"0 rGVeۀVlz:mƊꅷoZDy'Pbgx7驗3:m:s!؂j$re?XA^F6CN'tw¬zjI|:1,'% Ji<[M賌ȋ|Զb9؞d; V" >=4Z;1bzĥ,ȏyzEG* ^q|Fh+'|z`Iy'Z-)[)kVN'Iu];lȨVby@$wg G.>fe+XW}α&QX;rRc"(wNÎQ:AЧK z;zs!B<nobJw%̏ rBZFfxwP[1e1zlzlI-,~IJeS ?>,s9O ~a UO~/5iժ$qh9^ٔL7A) z|}ѓ;`+΅C!FZ =j2~q;2 MqZ{."ڈ۞z"T/ IJ;;f|5/2[:zޖBRB8*ML@n#؅5-ʿ[mvkU`>iWE-`J\ePKt[pgn=Ȇi Uⱗ>((wY}N@X%2IR:s%Cwtri|z@\XB}prѿc@D ;կH|ѵ}]ݶOd1.MKK H‘@}#[Rt&Yt]Ǫ #@F7WCA >#[ؖ;Ex9{̃<xU cMt*)cs++!8ZO֛N5y5N)#I­Xn,Q`H'_ :>a_U$^};}67l3^c1#7~ oB($:hFE7XJe&OTO)Fi׉G,pH扷Lӎ [W[*ہSt*"n©ҒuQ  vQo|=Us/-P;j]YˆA3b`.'`ǡD馂#x辎%o9c] /{1+6s Tj^i#T>E,m&i7/~Bۃ?g0ާbk9 K YS.qh6ǩObm)5E˜bb5&Fb4 r ]m `RX!I F^l4~=2(6:)4;Fdl!GNx.@sZQ&`j~h=,lAfBja" k"XBOd3rT]{DLĩh)JINXvDݚ3\~s65ͳbEyo:dtXVՆg}0QZE; Շ/"E*>٥`K.CP4݀HٛRº'Žw4i/AjӇUSklϸbn$'q]P镚A}xj yڣm 2AuJt(Vfk[1 kBWeK2iFaק=L ּm5ч#kX};4ZDW5D KgVA 0 %bW[,x`Nqs/Ј4rH9yXYm1`^T.;0=h,q92IzN&/GmK~¾Ჺ\l0Vj E9=&vfW{Q  X^C) ٣.,;ޤ+Tă<)Bsr}G~׶Rxx{-U5}MѤEfٚ2C*2fb/cMf+>w1 H4tSnŝ=;sSx^BGP#5F:ލij⁎ 02R'B/|dr^@HD5\gFhuLk[b%иDt(M*WLEIɝD4!{I^9N8vӎYS/ysJЮb_zK'.{huH.<lu(KJ,(}_bF tפ@9zAHdc]`{,M)u` .fr^Jw?J*?qqWuK3PBŏڅ3=L6cN7u P^/nx7)JگJ&s '9_=7!qaf=$%ѐ%qz,ZdYi]M+ ¨ø7\t(̷|i_ '|3geӑWAwda܈`)3}=z6I}&[ZR"DΟc%lڝfp.HaduɹwllכBy>EP:z/,zl*(qmn#ΖY-U7x6dCѴ+xz-F}1i M@1B; RcN^I.(-/ Oag %:Ǿ26c" Nf 9DTxִ 5+pEep4H[;ypY˗^O-w!݆?NotIe+3]^IPvDkKCe_2EnwHݙ&cD>+!osf`-rcهk&0rh-Y}%iZ@;AyV]R?BgNC =;Ƶqt h je#G3T5^]֘V TO r9jtW.>t.B`pt`X I;t*%?@x{ c"1S#~B(&+%\_9]eÛ"g%-#Ǧ~&~liYD}C~DoHݛa@?Ffsx|;h, qfjw&n"F.3OB\Ї牗x~>`b!WcXʅ:u"^d;KoJ#tgq+TN-*E$3h,2k|啃[;'e,]#~%+ Fэdn]Dm=GNfyNvG ]o̵IT~ J(hJR$.$D@&CC 'k~b3D&a]ē;݆Vϲ3X1Ui9 WICxH|()n3hG zN=J`k}r³ON)? r8gHRd.$[Yw`XIy%ƀ0a@W4I]ܚ+5Cz:ʳ[~6>԰b! 2}Oj4/xԌKHn 4cpb\{V%QXVW}pz?$Pt?nG2'G X,\"3$pl -0p-Ֆ$ "{%qJ0XrBq33KG=J q pZKH:E$[ P]MYAC6pe\<̎{~Y{aG h]-U.bi{6+dZ+4PSt~\2wv#T&o36z6`#h*TtDO'+Hfɀ;ċW'}۟T¾&SR' 08z*mG7/h# 'ZW"M_| G ?1P j% z30<;3 }6‹RSo׏/W ɵ?XTy/2Հf4kI]rgڤgqS!kˤ\E)9޼7|rT~ٱNf+ag|B mwv[oձW]vk&ɟ"4@Em ?ѵ!bLDcrURTB! ^udBv7>G5L~dzKiƊGy"i,f_r&SWD, ߧBSb5T[=rho$]ƏCMšJtf.콡SmvSAi~c>A)^؝o42o5^Nk^ QqςP8v%#R=_R0կ\vhoBRά¼ 1Za }=::c%5nW=SWb`oq\@ y6-z.lc %6\C_m $8Ձq6Dwh⚊.^\- az:ɁM^?MG`{WxD3- l"e*?ImqQslS?ǁ||Tڏ=?xlӎ@ʀBCvM25[ȳ;p)ʣZxc/Q$oԐu[Y)R6t%vnFwgCT ,1ނGfBUUHH^*S;?w/ye?"JLDJ+g[lIXE)Nb٢{*5Zs N}8 w⍄eFj$Mu}rSR)P)΍ۍ)eάShP7[f;g VROS%;¼EE=v O7fpOub]YO)A-β2YXi,rJgGmD#nwR w&8x :  gtZ<eRF ;i3"T)mfu:bD3Vs>7*6hW{NWvڴ-g&]ҵǝH˼u?wʲc. :"8+ ^Fۉ|ea6 (OBlpt[𒡾\'(MԺnh!)56L$J/TzэY\]|l=dnq% dܥ}nKb2mMqHr&M '/]x Έ(26G̑}MO?A?>u8U#\@]'Zڲ ))|B"mW'4A\Q4A^QNZP y/I{|o˻ c,3Cdinv5WLUhX=.J(<{7lM4J /VgvUj+ !'Y3x6CyG\jzmULJ}KG`-5"S92&<[);v/aTiYrK`fqnpxG<@OH I dtk8Tpxy4VeJpI _[? *1-P ϹI_ִzd`R.UC؂_qĶ eld2Ol /WM4Hn7"ަ=sGluKHtq6x%18+1Rmoܳրt/?f?S`5ƈ1&ݸWhzf-޽7TZ&Wjw$2$D~ZT;8Ta(Ln=DTLy&3̣0AAqm,Ml:ǒH)n 1m^h}CuH r{ Xʜ?U8' jƔdtLn"Q7;R;1PZ"-ڣ)\n/BNRTm܋J|Sz;Lz Cz 8J$`vT6/sz]~P '9RbzW zs-#BqS_+ @Hw* 'oU:#O$*|޷-s\sCwA6#^yK&InO`!Í?j1GH!Tszm0wg6#]7@g0ˆ]o10ݙ*Z'aXϱ6[4$hZ۰ˠ+ idov"JӬ)Mn`01+A;k {NsA)!CGUEO Od_{LLA{|i}zڶU'kXR5= mJ'rp3ulgwjJǫ]5"\78 eH\nmx%d(߹? ՊauAEB'ڪ6*Ly[DBZS,"Gx{rjԭ aTakaqaySM-ϙ)\6LY3^ ^k5T_8fQ.s?^/ _q"nn%yI;+],bSP}Ў[ھ7 #Dd[84&u|斳%U<a3|яch]:pߝ1Jyɋ(\y, . Pn ~+;1Aht&_|cT|JU~,{{Pr"/i/Z}^ Op2p7] J|oa@ĕPu7.$}/Uk-b; ]4ԢEC#$#=7 km\eQ収oL8 i#w81Kk@l01MPDYw4ZwlъK|]1-<^IpdY&Y 5 )2wt@ `F?4t :q3(b=eâa52 IUz`ӱQhL! fҹM4buQSyec0fEɕˬ/^%\ty-1?«Ί LM(G@sX^ n'Z]FҀ).^AiJ!9;foZ2[nQq k[JCO\SЕQq[b(y HX,-"dP!=~#%'ux%w7%UcNB8C⸍Ez$G }u4馢r0T%i^QlO%a$uE54L|(*JR'0LŶzrYRV { i6sv17Pcܲ=\op!`A[{S]Uas:0i/GSb9GRNdBe!-)̪tˢWӴfSH&2i*)`7BHٖiOmX<I2D3:M۩@kJ Txd(V2/.5ߥiLVEȁC$rO|}k!'+xCh29 s 3_р>vɒ/h{ROTVERK큐TVH ;5/ ;ܡ X*2N4tsja%T Fg0=a?S% aiGl!tXt]yx2c}鞫 _5ms]r*bT!L˜šUwj7W^X眡T+z6;-M/T沄Ş?Ȃ$J',a2XѶRkf^AgL5νlP0PX{nuB0Dع "n:vQӾ^goS6WUJL7 9(HMrC"hKVVIV̀Y +va p q &H* W)#mF_qSGEl[0*@UhhSbQèSrvQ8[~_Z m 4mxG/V(3~utj1$qHLz6*׶n*5r|7 LsQъF|g "U]L.u#GNê;Dga^| sa=ȹ):=0!*l:+Lm(QDO O+BЊ')xPG,;?K6N>?["ѳ3+&RQd{[WJw}f%.yI &X>w>I;(7EsB鸟ceD =;;6Mػgk`"Ϊ" 2~c>9??gńp_x\:ӧR!@+29SYp$l$=ʝ||1Mx+$H!\|왳_>gt² kŗ;cg>`K>KN=%/ejN& N  ,#f^V}־:x+i]:W4`i0~<MJWϭ$ƋG*G>Ts ^kBލCpw5WDh+t<{cW%V}")OIp-bdhm0m5R>ViN0 :S2%d9ĺ#zo|&R]$v9%_癿b,8*ֲgH'GiW05&QGȰJ&VRQd[ @z h+ؼjBƬ:\9?VsdyxlRW#9oݙ [{vq"0,*轉zł ~QAPgBIX,/A,BUU3Ím.BHP(w艋k4sU:w !kE^^ ݇_O)t.E린Fjהn-y" \)(˿>)85p(TŢ-1{ZSOP,7?5㹝`>wj4q=lH*+3ʹ@ \vΚ. n>LWaD[f쪽hy3rlqaX~ ̳mJ/d%u0 #g9t% h뙮o ;Q?n>˱Ȧ$uհA^t T*C'e䞡/'j"{$(c36CuA!?8Dۯa7L%UBL kTCLJ8A( fX!?qD"s6AG^C*!gdZ߳q"V=uJ86LK"کR+_ϑ`ҸzF9iXCz#;Uxujˠմ?}I[ȸ &d4HV^(WY״#i 1ӌ( 1jE' OԕosgT{F!v)5͛_S< /a[ַP5rQqb7\_:}*$| e7ieBlx]!p¨P;oKwB4XN <DŽ)5@ȡFd. %yv:{[SJF=Bp1@2oCDi E"Шb >p)w&7UB4LH{#l%S@J|Ztd"'tU_1élEYO 6Hٴ1`)ԁ;]̓CUlTR(>Ҏq [u9Mrk쏰o=z^la]0]ɃKVr ˙!:Ocȥ_{ցA %q\ M"oFv̑ϼwb+dxZ0^/^pf )Wm? H"9B8c,RE3^_fu9+%! &Dk g M˥U!lV8A X’'Q>=ț -C>pSʁ\K aiIs$TtdsI,HTtunJ`UH>7bxT${Ll@5X$| nҕSEJ|(8bCO]V_M&EA׭#>ƻQLRmH8Ps_E=nx p. hءǂk^*`~Nٰcx킚9j?a5L[}j0ĕCDK5#w3JEŵ9pVX.#;wu xtI_GU7LHhqKv>VV ʁ>ǶB@Dè }6!ڵe)eDjR&!Κ]x7˃+W[N,K Z%H6Z6~23P7PuAͥ:y|y 5y->aiB\Y!T> NSj@y˼ l?d;ѥCr`lױLb?{b`#ﯰؾӎb6&7Q*7v8 e(XX~]^eJ|#ޅg­=8eJ0$ \ XZ%mHh=S1VcV={[kk?RI$ 3y!MG7}zO> V b1CƄߗ8NyVQ'N$ H<sqV|h^DWp"ڪ1w Dm:Ō;oQ3K|bOb$SOzVUj޸6oJ)wwD1!ƒUH \88v((QP;ȡb*+ X/t5$W{CCYm-q$Ŗ@21-c2̀- ڤ bgjaz5َp޻d8>r2?2@IcpvtGuEI͉tSx3 m8BI=;?c4>Sr|&mS4TQv%UUINdz_|avP\T ys{n+S -hz!_I0FVz)&`+ oA{ȿ{0נ )r8E /oSS2}ߌ(',RhRK.2>P Tw,fgл-n;@A[:Iێ% \/śeg_%qH6kkRgPOyB#,kI>$WwcEƴKN(*~T[k\ubW;wйP<:̉vm*wُtx,̃#;o] t_{#z[Vu"(;(< ޽"mIDuR<7r(/ZѻEYy(g@;2iVm-f˿*|.̺gWA<>>Q+7> 2jL嚚#X1ig^="mC !񤝄@F 'd5ҭ]%)rx:NJ_ |:͜ydzǿĵܟ3e-Wc4rX{< \xܮK'ʒR[E\թlH<>YW y!/CZ&tCnEGz!?:Iy<:=&1L _Qd+9ւ p Izk6H~^BLpZQ,(m1mCWA9㘄_wnX8d6u73R 9SpKsF(7pQ8 _yy+f![WN>=px'½D󮚲rc. (uv]۬ ޤJ IGx_dI99Ho6dD UX( Xݝh@4SjO9 &Sڌ "d!gwi|mə6d!aD|<Ɂ~1Lѧ7qbOS9HbXPC⃾j;BXzO bBH4y*jzJzGL? Wö&Dj_ԺTV$3GSRȮb}I4_ܟa)WX8gZ YU^ M;Uc}+\&8KcoyT8BGkƨζ`zRakؔL SkR8gmoGAw#8@ѭDb0Մn/`+ޒ}R`jvթhQǬ~MpC5=:[ζw.z!yd63U{ 'ݛ{j 3ZKh4ha:'˔>gfìjtFIK~ M0{ԓ+:z4vV"[W2cQ7f=Ag)oo]XsVxV|O lsXwWUk1ť'9HJHP+HM9wjNXI^♳F՗Pዽm_ _ʊ.\ Z!2p)=?sgTo3eK dzvLϟDsyui,}&ۏ7#Fl4 f|a13-%JkUHȰBS`+4V}fE<(:5%]g߫Hfx\bWcdkL,\U, Ҟo&ʎM#{ys,aC?W(O d="C§l)DC ((h:Od YHt QԥaߟbEMTp >:dB`1 hkACjP}I1tOlJGEdkR̫ҨbL9}=Wzb'q^FeFPzʾD|e'v ڽ?۰'!gۮ\w Xքp*8Ht{, #tr|vJ@<߁ Z5P2L4\w1w$ӆYuq<KxzCYiz0914ƮF'Vfëwwye1rSUg8hHMkkyk; PmL~D?EOvaPs;T/.mfff}Z˜lE)/F c5-Q(6`wG7ٳiSMV#DY\,=ب`֚,`Z"&mGZިxVBj3c;e^7]Qr>՟&tf PbbLt7oU@-Zjo=eg_{#`ʬh5 s[R+晞?. sL (3HL8MU0Qx#f_˂ ~1Ļ,n?iIM\nŤgcuvQc:l+^lȉ3̏F9?orIUau;.I $dIz[^v^>L Ѷtp@v <9gze"݉>c{1T80EⵟD;tA`-.~/ zwZBII0{C!):8YJcTAfvY"4f$K>3#3P;Blm`0c`= |GNyỽ%HQcniI yşb,ŠXn>h)6lP[cŨE˩ה,>e`u~{.Gk `DG U ̛SH*h(މI}%Q!mu;A4`ŝ܎$g|*y ~pkB%^|g1(RVVMooݗ\*{OZ큿<:e/o ~|7,/3W =p~_@{үݱ`0VLJ6; اPᬘ%5Fk|Ep=xj>|˻jDkN}v5m82'Z8wi ̵He2M'"kO{MƸD XT)9~y b1_r+E @]VBK..jlMjX(Γ^ y&o`Ur1%(gHuqۛ"zeqU1 6{ܾwfRvT rō:*2$r(;uOl 75@9| k`*X)-GrCɉ56M{$uSHgU:+< &_AyK\%4*stǴ+yz Uo\ކ8H X' %(F+VեeC3%;bP)1sCg?:636"ByC8=xχ~O|Veڅtʼntk☕*6e$G#/"6G&7;Fȟr&WfԲ`5uu٬22_x3~4G $6K?']/DR x8g~Yb X}bwrV.Zˢ4\G N( (H4'ήo!#5N9Ns\]?iBjv|v0^c/+:DŽl-$UpΘ7xʰƸ}1ECxB;6v`w]B[#üLa VD u:^8:DwnFTaޠW}RKrv-[qL;f*d*=tA,|NHa3<s%k}ejZYewM;xvҺ:bUq|=qՃc#ϑ`di[o<q^ @;C*!Ͱ*ߢa6N2)aFj`_I;ݠ6<%mЎ{Uٲ/IOxY0RXJƓt|hԜ(Oȏgc\# _6ox9{# p7N̈́pĞE}[XGYhWI?ɏ tkoGo5h͍17QTUǏfTm8{%!#Ay+pBTR|Q\K@6ӡRwE!KM^ '~ڑg wГ6hin.Cg^ ͫF75rt+O]0<'b^|ޟ.(Y2e,`ҖжLoV/P&wnCaTzWDmhA)&aHZ-5#8,%Cu#*xQDmwk]>FSB^.6 +mM]rL d]?] YHem{n̆wWvo48SRqRBx&$R±ѷE _mar133K)H Dc"ɞ+1vtOgrkᶮ˒>U0H,MyW5EP=[:vh"$`,'+J͜1=k+ltz]IE̐4$? nV4zk{XTy. o>]ib#~W H(F{հj~m wQT k)I*tdLTn y⹞*0'YswL@s_͉|%?{_T|Q^ vcS;p]慇pE}&@[ǗFQ# 1~אe!6NsFWc0Q/GB)\M'pjik`Ch~wIXzW"M5΃9g&i`G C H!zybLt^N#MB{PB [ Ynڞn0Ilq*Y28$QH'_]RB)\&l_JAoɀ s舡cCˉOw#(zvRvjzH#p(֪@WoVŇ[NZJa5>0)b)N}]+^U;$/Q YƜN9dI Ũ_^u-ZKҁa$~)<47D2F"A|X^CάOO?R sX[/TV+dbEZ8$$~P*ቅ\} LVWMN=U o5z.*`x# Ӿs햴H's+h}A St*Vk9N0E^nJnWeW`99Fbue;z~왉oښ ] *RQpINH! +'LPboNgV{:ƫigm C'{d°``7s . 6*^ש}MSؿr[ƚ@ٺg>f9۴6`k]<+9x+Qr#gOW AYBmoيsVAM7fIZB𿷕<dč7 L˰ 5.ZPas(WZ;_VqgW˒8&Z5gCǵP2|E(b_t;?H7K8&Frb*o6O-fYʮ`ɟ9ro^7Qw$@cвPZ7g]vU'o/Qq1 oc#&!m:/_3@len/y&70gJw2jo:`! b _&=9QrƆl峩ÍHYqC%<"^|bPx}LueyN~mA>WSqY5ɧ'ԯ{k>6D?``;sf\j7g.J;"+,%1RWYօüR-ϫ'ٛ ]( 葃"dLA&z{(|be\Sjr R A-Z x@33b|u B[^BG(ar0pް}g)iQ0)+$h.{3YeD.yb޴HiXElзPi{3: -^Ⴐb1@hmr.OFþ~yRP= HWRd"!_ؤ;-D., 2ǘ;Jvnp`+ʳCF&}hts fgtߤi&u֔a:I ^$5{8Hwr6#TLFLcBʸs)4x%kc=JmHc~k>o)dy@V\ VY' Fve&⶷"Ǻ1UfţG Yu{2'Ag-r ?V\^1VB?+E#avk8RQY Ͻ5<*raZ6pd%h@WA;vhd av:#(ίUmH)B?>{ w쥫swOb0l<Ҝfn!AG14$./s͠uDTu՝eG ٺIʨV9ϩ"zzP)ɺܡa7mV]"~O9+I:k$N!֟lu_.Pny5b *W]Ǣ",ZkZ!FԠ`xǹQKIQ@H+Qq6*.[@>ʓҖ?!+D5Țw %EoTzdC@="3dTlhxXjb{mk9"8Eк˟_6g _m`B:ޛ~e(Vtw{L~Jl;cwn GI@\K.fD#]\!ULhyWûNK@W3 t"_By>FmZ{Eݲtq~p0ruD -9.Z7+<}9_^XsˋjQ:P/s_zk BC#3D2^*η%r Bߋ|#OL%=\ћɼ)#ð&:U]eWeq߳,62"͆ 0v5u:pVNEjDmO9G'Sú|.4]`)$t^ܦ^S3r!}j30K_@#~bBeI vrޞ-AS̡3 ߋ8n,7Jy3s6#l2d%K7:nd΅ ~Nft; tЄX_ٵ0D5p>`uuj0B>l^ VQ"mzzY)(/%;cr،Fl<[2Ao"󩴍h~NMS3{N_9z~ҧ)>@rqXO* IP֟Zk3IWgHcA4 ʲ^ V߱1 !eC3O9!χk:&uwh!Vm-,b.fJ*UcԊQ`>?6ncd_zHΖ#T`}R"k2Gd: bAAn[KWUߕZM%i9@!^ƛ&Go&p%R'$RJ*5g2j]~UCwh O^(,o|6~У! F,uSw8(5EhoG=/X#ĉmL/J[:C Pms bI]Sdd3: '#%/ANff2MnbgĎ0YYʍ~0k=n$ 7B&[o9 cMrg@4.-΃pǤ]B̷A_zh/IC!̤ 7}3fmy~WR"Ñ"!- piIBkoϾ.p@n@R2X28;Ϋ圎V*䎶Y;֧l4eX]PHn 3V%٤^ϣ&LuFfQc3?;Mϗ_X\.]p >ӆY4m>p/d0qySm(+ :|.t{bpp#%?/s; Crz(kdZ\O. ]^͠G*+)._uXꗔKf0HTxC˧u*$܇r|u7'#C=WrK_Y?S?Z13=O<}M Mn>Yy}&$8H}2HO J}T#BAgNR-[U p5^\cAjݶ[ w[7/uQz&)WpF@&(9}J9Isn}Y!@=Ԏ~X2=`rV.ѾYPUUn{>]\K!)<~O@$vއb??J߶\o^ԚՉ~w$#}2]XI/ Syy9#"˷*"]&O#>"p[LD/Mn Z5ie:(raHV1-)",'{F\2pÁD0@_EJxGb? wC̭HoH7)G W]~tK9AhA ާ3!BFJ$R*U8ڙCV.Ѥ &%vt;!F}sT &pM\!%<֩u~ZeXlbbj;`6 *U6{>1Tu'}j˩!86%{l @!G]]d7I ZQ`Uy`eƄBȌD"ڡ ^}9Dɫg[ U8rh7m,֚zL4{ϱ j C*w0c @s;.]8y*dTI(_#y=Uʃcs;iP'+k8jA-iyCgLb \,qO~܌`jw0e,[mR/- ~Q ߡԅ-O2(!sv>!,)b OT,)w D#hh-rĺ6j8f5ݑgY+nRԠJ[Rk0x%G.+|nVf[$JyQօ:soÙ,JqqƐ#@M:A4dl110#^ˎ& 'TgIzHlICBB.R #*%fT~Q*53^hS6X0@pa* kHPzRݓĈOi }F|Rk5D2sȅFHu9}vǭ,E;'SFM'-zL)" kziﮦ&7FDd^[-vfeIoؗ2PwPkk[ckY}G _Mߞ14 Hf%{:*t @9eCܱXuݮcщ| îD\L PdU=!eXJ ;}BV#N-(gr(w~1 h>9@ .d&qk({"R=6,6d^Un]Z͡ ~U/zsmd4&zoyHOgϓ$nώ#{ryު?Ԋ@nN8JoӁ52c O KxLMìI5֓la)5d d$;7-FJ ;9pB) UT<ӊPѕXNG5^^V6,`ug$vIae;aT(o˺?t4YZzϑ$3]>RIw~_^7Cӷ]>kL'\ MO}b4 +voC|dTYV3~"810F&`,.ζ@C?QQ*'q#ڥ~, ӽO*=X(:~H*ʽQNk;Fzc!$ }ne+J˜qUxH{v=-.(bHt ) *@WJk;yh: DϴlUW%{Q̗Uhp;E0Ja)ķz'_' `qМc6!w첻?ǀ;Y5T&3?a<MP9w#`]=Y:(?a5qسhxuWPa0D)*Ow0?ΞuPbr/88@q0E5:]Q֨ThK(e`֢7k̀C^w쏚̀77!gRi:-/p(3|9J 0 )P"GdW[pe#D9BKh9?}b~29Q: Pxwx)ؙ ߇o$f9z;yGi+ٯ'SWhDp@1M&7'* XBca'0pWz”eSC8Vs>6dAhtZx0\Y_9?iH { qD2 tr$J#uqLw)݁qIg[2N$'wk@Mu&+nSZHKW/5-IOgNDʩ2ٮB4mY~ v0a+ h0]g^-']^^g0YJ#h__M'f0ZǍp|95_z[ 9 Wp'KWP0N_cE#T6/l _l{$,v)Lq\q:RyC]Kp-PMTFyn_NM2T4PҔ-GR@ X#iW{ `#?M]y:DOd_?dnf$P(O0kٺJycjcCEE0ME"BUSo;Ħi|FKm!Kg+n2wIAw+|VBF|ġAάLW KVua#{gtXDU%4V=9reW"4fn{ÂO d2o97,e&s""]hOD!=Mu[Dk"%v:Yb:!z z#Ow#B./Aey>)IHl{ro_}Ѡa+oSq &bpP6R cƪ,*:*DF/4#{ PZ=M9#⎩S#O释+D+@Uhrot~WiA 4d6mNpYW۞TZJm8MH54 GUpBcbE> MBW"%T/idm%@knN+;heO5uwyvNwBN)2PWuwЦ3Te ]>P#6=Ԟ^ NOW=_v^ôQihpGf;A*\aG+(noIJaTȺ.|\tS l".Wads/iH*x@!` y9C}3HW.H`v.%6{׎AJm:9}]̇ɰPcNݠeC9}mJ.EZ,pYsBP3'ȳrtGÎ2Tξ4ekZEvo [v_:e׏,@wE2W=ʮe:5DҌ}"6#<Cxzp(|] *KBUpNuC-*+=)$6jLXja/ɛD]2K9rT(UOB]})OLUA*Bl pݗ_Dj'beܗR:P!(h$v⌦-jhNef7 cwOцE5{lSfGEzh]iArEsJFKM gHJ|=B,V@lJX`1~;}MZ*SǮ$iozxg_0bYjģth9;&%qM@Av ddL~+u-.i95݆01!߁;V'K=_ڔp&^hww2mT8tOGAǖk7٘؛N5q]"TW h RYHWwE*/m(uF8ѸJ5Ƙcl[e|e\eq!Ʈ(?uD^Fq8 !ўVºξ褭W0JM'z8k,IR:l:S܎:4CN qVXc-ŶnxtED(},{󈽳W@w3r~΄] ~Uh&X|WjxpM;(cGjhY;Lp _ 4Y)M[;\sp3 !`Y蟓r_xG 턿!Yh(9%xq(Ljk5i$4:D;Ri펯+zZ5nn365q1ƅ}(VmLy7㞘ʵiu_wmѿ>BY7SP]n {ӼbBjMD칔7槾3˿j5WT|IvTDZ`ͧ ӜRY>(vyM+eL߽S1_gu =*F쯾8AXNSښJ(rl z^P"t&۩]PRDTBP(RQ, p^86*J_6{ZO2 :IE4 |H P(e`Iw"u]E.77z3I[OAv2=*FS#|36 ſd!'mlPh A ,sWTEd,c>lc: 0d(# iILKNP␌kgvw0{QA$B͌SbOտK pk'0CSG&ESxU`O]U2 N{IP% %vHߡqNJIBNopC.IvH(̸6mNq/b9r\Gġrz/ECE>/țz:G4]E@8{XSG{<~)"rJQG:k{5+` I{EY(ϿxJN_>A4\/< X!Fhuv: ԑ\@UpDMALS 0BBsh`i)Ye(;me;z n_$ە1:fP.!Vp4?S#^4jqy$J:%?c&u㙷,INk- }itV*:ބ)&-ɵF7H4 ,hZ;b>Xګ eb9(ʇH3Hh쨝[( YٮԁXDWFUǫdኹ>uב q&u_ޕ5>^.B=#3l~5W7ZZ%G S~Ɛ~a<1鬕]<+AU)` !j1CnRiA߉vA<6CUO3fb'~D;{pFW7wPiGKȲ8)29Umz ACQEN+De9o. o;ܺTX#)U{jHk-~Ba==^m`\85MtttDy[An~nwvç ia'"og'f3`3ݞ.^Qն*O3G_Ql'a:S iBcPKzRj>i繖iFYS*e@6(X+̞X$+&.V&"^QGb-܈E7XfzTnSO%C0Y1jEvb$t @/mMXK 2,tA8@۾A)V7uKn\x(+(68:mCv)󔾽;_呟R l7"-WS1۠[y9N'o|\)Fg$3bKD3'Ӵ8)OE{B*Jsɔȳ.*w&-j믺H[_LkL{z3Ч뮵ĵل-ml-CA0̑GO{$LvT/I0uQzδ0#!`߈ӸT#oR%z<Z(i1ܐISDIϡ2lNN-i6z= iA$tV Sffв"l}T;xTvv["+0th´ʴlx96·<~`zX^Vheo x~Zmq؎3?G/DS_\0lҀeR7S2>JNkqPkfG do`b-/Q5!'rqZ@F^;xn<XHmĖ#1 "Mf"i/0F\'tmOO~TM4q:ּUsd~Yj3%#k([74S}y~j'!rp@xQh<k t c2:~bu({/xϕir?%Bc{xc65bFv) DO]qkT9#G#FӡeY *4,.Jܱ6<*j{Fb n vaJ/CġC@+`A8~O $ uX Uk L, ]ӿ)تˡs:p[ru;'u~H\:pc 7.fq| hTWJu -珩⢸#w;b(D<9_U2u F}/~|]n mc:`GhBe4}6Gгp.M9x+v`^qߨZq&{٠}:iEz1*<&W!pjqo J"j !T@hc&"S{{U;5Ş`Fq=CT؊YT`qmO7.Fz1Y~=@e㻸'"ջ}TX$~DQybHRعR36ύSM~MئH(d+,x]JbB@,ˁҘ9ԐVγ0 +mk)8'NqWI4`9fBWM6RA؄lEԱ]@⼕`g 8%m9,y2&loLUS{ɕ7%dzl82xRBDm<Ͳ˼%RVB$rzG*`SGf|񾠒"ҠsOx4Z]kBaבg΃g$+°U%֤8N9kl\J42COjwp` Ig)utm‡2 w@QKw?0م `"/'ED0(| pdlvIH+ƲK֢)Fe)0 Y6) I_sn++t >xsq8^_(%ZpIv3)|Eȵ3i/z^X .'`3V]3S= ~):C\:9v0y.{ܔvkcs~{e:"ۤ%,{wwQ8}r}qSaqZI3 ݬN8f5*p(Zfܴ*X=pE3jL)ĚvM#i fHlU8玾m/ҪPY@'omPnIa.0U#2^E7$ uw`-yg#uVmZE|^E41|C] s>ܻ3q\uJcEɛTuX>X"d/~ ?&@Gx xD$@4ɡ$+I$B3LNsBu}Pzvsx$_nwssNgg3].AB՛"T.X( 6"a:qL`=kƭ6 nn1m329F `GjǙCSAΏQʝ}G8Xa={<%|~lX] pvύqx3M1_XΧ׏cڍ{-:cJrd<gn?( ZҔS'R.{A kmҒ5h}H-Z#=^K3FE!jwHw N返mI1yyYՃ*څm#*Q.,#@AAt$GQY)c},`JQ,+!Tt\|a1Ctm#fzFkGqr}rsCsynXx;oJVQ)#i;ҏղb^T{*43kmBD'!-@;U\8`{{-`¤/<{y7EnX.ڶHv>ʿm>TxK۰~ 옚"PoyՅHVVgmIPT m_}cNc-wkyd 9SQ0{.NM\ 3(Wexox,M :Fæ&üXٹqm.k;, `1^Fig+A }̨!z-f H5rׇ]hIYYv/+6<%#v=e@YP""Z}(9bnUP@2'h !3J'v 7_iDV0(E-0uҴ66j|tGv#ӽ?zҌSfwbCvY>͖7#b~gJ?/507l _d6LVjr+%Y9qF:'xv?ИA1߬ډ']5?J8n":ɱ0i;##"o$>ZĐs+=bZWnRu 8ލ+Hռ~$O2;yuJ(V,BF!];|&O6˓@M6Lc 6@WS&u~M|цIt ?kC(S 35΃+T4 AJ8:b*3o>j@(φ stm[Th /zheaDKOe]v O>lO&3PedIv JA>"&ڑ:y?dTD8_59J0&uA"%,ǥ/*`V*HdZ:Q@5q:v 6˒/ԆC@('`- PHO^=',r6>S,kjNE)#i`n wj19}H_p!e| `K( GxJ3uA!Euܿ E?V 0ze"70aPQ@\0D'Ujsju& )'.YC065=ɽFࣹ̹:qP7. B{0!G/jK:Zik6px5DX_ʋ*`YҷRifqL PX;3hȠO1Bhާ.{|_!*Ϋ3!qȃ+WsV{j%?xjsGC`.zU!w'y^|)Kfv kdu\z)>8;I@5uq_a3o7=bQ#Lq0 w]ha^mdaN-yS̊N. 4$!

)~/B/*x֮ߤ +zh6[@=ʸw4ZiXk&uLKU$={d^=}bҜ| {Va>b3##Lfp+JKcǛ:еs5Ccd-~ ޜ况Y?D#ĺgâjïٜ:PP-K3~ş (tr)L 𤆘7)O~>q3Rd^ {w! rI cZ "ɣ@%w`+%VRD| l}zS̋{f& *doY`4.hN)CPAxtp0l""$p˻H@Qt$I8j e(GGd(ݵ֛hUI]Xt˳HI ME>pl V 0R'sky }iȢ}(!;K8y P7 +Bb9?"* DA +Lks >OWmqLt'K6rNkw_m;%5<_S4't?4Rfb?SֹV!l> ƶ;7+Mc mhّ[2h(i/&SIr-LbcF%l :V =jDP' #V4Z,c޹ ,gJZpS|L?c-@98m5=Qh:{ƖcB':㸣 sECcǔ{t[l=0T1d&3ip7dOc⨩N]h_jw@A{U׽^\]F~:BiCPr /\m- aI -^Ӫ+4lkE^cCH,̘e`TwNSI{_[8vOIc6pA=x.4˹7K(!|w~%S_Uij+~nyDOu]-rqYڋk5L{ۀ+&m@'vScڱ1 F:Z8 mi{<]=EbEӎUtDgi$PBxuo}Ԛ  UOT56#Ѿ W]Ƙ❖+Yʦ{ -g0+јE>X2:<@] =sk@ODVHoxtU=%B`6o>YnxKV(O-w停qR,Gߔ} S㨱n֐iM/-̧gVQQV񒞃g8Ҥ8}xjT}ChOb =-6 I~w2FPCU*V!s&uĒ(cqHM Ubˑb9NԎ$w"+e(%M_.vqRPMֳī Fmû7Jvo>j OtDPepu x>L4>"+j ,'҅Ӱo3pGsZw]u]àa$>4hY+WdPAң#agCQکh//- tl DWxA6/)W]Ia N'N3+UpA-[z UVPc˷*S/8nӾѭ[6 J偨`Ss0qǔq.2!qwLv59:'|̹ fֆZo:,¼䣔D b5s uT=A%+.Fhh+k #lƓX034I~KqrH3w jLݙ`ՅrS^YsOʈƷ MǫVĝvKx(þ.dr"AH] |1/u7"'A\ƚRGLf}no'=oo\e{)Za^ҚQ-Yʩؤ-(^n%~(q0Zm`#K衒[jd > WmUGq#݊8fl"<9]a~t6ttҡ}h?Z&bӕ-€4Q:N{Qo“ ~̩CvƤ0Ke] I;CŞI\B+`3B%=o4>]Rϫ_B-T*8]`![!~q@3w0*Kz ʪM׊c˰dʎ9}WM%<桾qz-Dx$*0W='rb2OY/)yeyػ*^rv`GGg͆^?\%+u-#ƼʏyhS WHb!d?Л\ ?oBJ9>vVel7Kf Z?<~&* ]0m5LY{Dɲ`v#ސ>)^!hq%\c  IK$X@g4Lr[iyLdzKϷI\=)&?j 2-`)uQ _]@_Ⱦ%!Whiȷ0#:^{ ;Ww<'x/Zayh tC&924hm%hO4p9PXiH 4WBAngև;mo<@~Rb BV<؇L}~uRK@~6˱TrQDuf3v;4 fb a߭_`q!{8 v>E}ZAK|YŁll~%4'h"%7J|5iʹ>IaK-b eRJPS8JC|Rן:plal̵ε{""/qjU.N>& H->%#u2(ق|1<  ~`:ľKB貽.^$C1nӶChN Wk .v#M3I$2&RT+$v6PGxbcx#a-УQ}fO;A0ͱ6~ ftj6ڽfAM>o,<NJeBGY LfmN-{(풛 &y I?B:Mqh>0LQ~[v Es@D;)?šqKZ$|GU۞Y=E'gu|XaZO@2Mt n wQ,eo#lw/&FP5`iD?_0Mǿ'okDܘgp\V2|cL*lӂu9IXgӿ&1qu#s |NAhz