freeipa-client-4.1.4-4.fc22$>l]Mn=gL9%b>G ?d  D 06= D$ $  $  d$  $ $ $$@$$777X\g(h)q*"+","-"8"9%t:F >BD G$H$I4$XXY`Z|[\$]$^9 bdeflt$u$v4 w$x\$yCCfreeipa-client4.1.44.fc22IPA authentication for use on clientsIPA is an integrated solution to provide centrally managed Identity (machine, user, virtual machines, groups, authentication credentials), Policy (configuration settings, access control information) and Audit (events, logs, analysis thereof). If your network uses IPA for authentication, this package should be installed on every client machine.UQbuildhw-01.phx2.fedoraproject.orgFedora ProjectFedora ProjectGPLv3+Fedora ProjectSystem Environment/Basehttp://www.freeipa.org/linuxx86_64if [ $1 -gt 1 ] ; then # Has the client been configured? restore=0 test -f '/var/lib/ipa-client/sysrestore/sysrestore.index' && restore=$(wc -l '/var/lib/ipa-client/sysrestore/sysrestore.index' | awk '{print $1}') if [ -f '/etc/sssd/sssd.conf' -a $restore -ge 2 ]; then if ! grep -E -q '/var/lib/sss/pubconf/krb5.include.d/' /etc/krb5.conf 2>/dev/null ; then echo "includedir /var/lib/sss/pubconf/krb5.include.d/" > /etc/krb5.conf.ipanew cat /etc/krb5.conf >> /etc/krb5.conf.ipanew mv /etc/krb5.conf.ipanew /etc/krb5.conf /sbin/restorecon /etc/krb5.conf fi fi if [ -f '/etc/sysconfig/ntpd' -a $restore -ge 2 ]; then if grep -E -q 'OPTIONS=.*-u ntp:ntp' /etc/sysconfig/ntpd 2>/dev/null; then sed -r '/OPTIONS=/ { s/\s+-u ntp:ntp\s+/ /; s/\s*-u ntp:ntp\s*// }' /etc/sysconfig/ntpd >/etc/sysconfig/ntpd.ipanew mv /etc/sysconfig/ntpd.ipanew /etc/sysconfig/ntpd /sbin/restorecon /etc/sysconfig/ntpd /bin/systemctl condrestart ntpd.service 2>&1 || : fi fi if [ ! -f '/etc/ipa/nssdb/cert8.db' -a $restore -ge 2 ]; then python2 -c 'from ipapython.certdb import create_ipa_nssdb; create_ipa_nssdb()' >/dev/null 2>&1 tempfile=$(mktemp) if certutil -L -d /etc/pki/nssdb -n 'IPA CA' -a >"$tempfile" 2>/var/log/ipaupgrade.log; then certutil -A -d /etc/ipa/nssdb -n 'IPA CA' -t CT,C,C -a -i "$tempfile" >/var/log/ipaupgrade.log 2>&1 elif certutil -L -d /etc/pki/nssdb -n 'External CA cert' -a >"$tempfile" 2>/var/log/ipaupgrade.log; then certutil -A -d /etc/ipa/nssdb -n 'External CA cert' -t C,, -a -i "$tempfile" >/var/log/ipaupgrade.log 2>&1 fi rm -f "$tempfile" fi fiZH33K3535`Fx|x< K ^fA큤A큤A큤AAUQRCUQUQU UQUQT UQUQT UQUQU UQUQUQUQUQUQUQUQUQNTlIS#UQTlIQ^TlISS#T TlIUQUQ6aee37bbab7f3a58a804bbbac141a103d5ec66674ef463477c3128b539bfa561b4ca5a5f8eb5032ea3c239e57a8bf39e86667b89758bc51059cc9d71c69f12b9b4ca5a5f8eb5032ea3c239e57a8bf39e86667b89758bc51059cc9d71c69f12b9b4fb0c233a649220a55ebaf8f78679d64bccac234504d4462d6a46b07f18622f3ddd23259bc9b45aafd1bcbed904562e871373ee3b436acc8de6e1274762703e3ddd23259bc9b45aafd1bcbed904562e871373ee3b436acc8de6e1274762703e65ae9d106c2c01d839f4ae1fb60767b1135364d5053133ab7a632cc806cbe259889fe93ec2c8f66b18d9189118ae74a55b45233d622347de8db00c2de1b06b71889fe93ec2c8f66b18d9189118ae74a55b45233d622347de8db00c2de1b06b71c42e8bf9eeb595ea78a972dfa2b52ef5924dd609412fa6a51824b7c9737ebedfc80c650afe6ea35cd2a0c96484b8ce48a45ac3c56c32039ff4946caf2c5daa5ac80c650afe6ea35cd2a0c96484b8ce48a45ac3c56c32039ff4946caf2c5daa5a4f0947b466c6857142a0b0fd5a477bec59f19744426cf4b8766aa01b8a7f812b981835664bb5f1512caa671a2892bf6541144b88eefbfaa9a2189c7d688a1fd2981835664bb5f1512caa671a2892bf6541144b88eefbfaa9a2189c7d688a1fd20288da5de6dc6a2fe632c82efaddc622fc5b3084004e517a3c9b3e61efb87bf80e062d7d4f534a80401de54a70608e6f22295a1c54b47b2ef0c7c771c820195795369608d42e5c8cd1adc33623ba2c4f6fe2243c54c603925faf717b616f94300e74b6fb9ff8b847f70f441d9fdcb027e497f935b0cb49e0752ae515167b4e77a998ea426a9fdc4a6a7c8d6fa78175cdfa238ecfa51f151c5709412ba5d1d1cb71ccbc20105d31b8102f4322df60172d3422834cd0b9e0a55107688dba2c327f8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903fef71eeccc636521a2dc725fd31ff64cc60789125911551ca262ad498ddd2b7efbc215506be9ab1184fc83a7e997901cf9e63da8500598e5a9d7ef9b588225b2121d0a423cc66facd06fca0d904d135f0b7ef064a7caa99f97bca1f4e10202a4226ac7db51b406f7edf39c15194a18974e21de9d68d693de8f87c70602e789dbd93b060a71caa445e81310ebc9adefd25a3ef31b582dd712e9fdb52db75f051374259ea9396787a9a9cd3ac8819c30786147a59368417bc0d854d1dd07e5ff03499ba67992b575ebaad440be3056897eef062bd5f043faddd3a079d8b4acb7f366ce08b0ef4bd7fc5231c537bd270965e2f622c2111b7f3b512db27b7d5c5de90d1f6ba882f60416f58af4eadefe3a2fccff96ea4dc758ff7342fa3a9ce77963rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootfreeipa-4.1.4-4.fc22.src.rpmfreeipa-clientfreeipa-client(x86-64)@ @@@@@@@@ @@@@@@@@@@@@@@      @ /bin/sh/bin/sh/usr/bin/python2authconfigautofsbind-utilscertmongercyrus-sasl-gssapi(x86-64)freeipa-pythonkrb5-workstationlibc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcom_err.so.2()(64bit)libcurllibcurl.so.4()(64bit)libk5crypto.so.3()(64bit)libk5crypto.so.3(k5crypto_3_MIT)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libnfsidmaplibpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libsasl2.so.3()(64bit)libsss_autofslibxmlrpc.so.3()(64bit)libxmlrpc_client.so.3()(64bit)libxmlrpc_util.so.3()(64bit)nfs-utilsnss-toolsntpoddjob-mkhomedirpam_krb5policycoreutilspython(abi)python-backports-ssl_match_hostnamepython-dnspython-krbVpython-ldappython-sssdconfigrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PartialHardlinkSets)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssdwgetxmlrpc-c0.76.84.1.4-4.fc227.21.7-22.71.11.13.0.4-14.6.0-14.0.4-14.0-15.2-11.12.31.27.4ipa-client4.12.0.1# Has the client been configured? restore=0 test -f '/var/lib/ipa-client/sysrestore/sysrestore.index' && restore=$(wc -l '/var/lib/ipa-client/sysrestore/sysrestore.index' | awk '{print $1}') if [ -f '/etc/ssh/sshd_config' -a $restore -ge 2 ]; then if grep -E -q '^(AuthorizedKeysCommand /usr/bin/sss_ssh_authorizedkeys|PubKeyAgent /usr/bin/sss_ssh_authorizedkeys %u)$' /etc/ssh/sshd_config 2>/dev/null; then sed -r ' /^(AuthorizedKeysCommand(User|RunAs)|PubKeyAgentRunAs)[ \t]/ d ' /etc/ssh/sshd_config >/etc/ssh/sshd_config.ipanew if /usr/sbin/sshd -t -f /dev/null -o 'AuthorizedKeysCommand=/usr/bin/sss_ssh_authorizedkeys' -o 'AuthorizedKeysCommandUser=nobody'; then sed -ri ' s/^PubKeyAgent (.+) %u$/AuthorizedKeysCommand \1/ s/^AuthorizedKeysCommand .*$/\0\nAuthorizedKeysCommandUser nobody/ ' /etc/ssh/sshd_config.ipanew elif /usr/sbin/sshd -t -f /dev/null -o 'AuthorizedKeysCommand=/usr/bin/sss_ssh_authorizedkeys' -o 'AuthorizedKeysCommandRunAs=nobody'; then sed -ri ' s/^PubKeyAgent (.+) %u$/AuthorizedKeysCommand \1/ s/^AuthorizedKeysCommand .*$/\0\nAuthorizedKeysCommandRunAs nobody/ ' /etc/ssh/sshd_config.ipanew elif /usr/sbin/sshd -t -f /dev/null -o 'PubKeyAgent=/usr/bin/sss_ssh_authorizedkeys %u' -o 'PubKeyAgentRunAs=nobody'; then sed -ri ' s/^AuthorizedKeysCommand (.+)$/PubKeyAgent \1 %u/ s/^PubKeyAgent .*$/\0\nPubKeyAgentRunAs nobody/ ' /etc/ssh/sshd_config.ipanew fi mv /etc/ssh/sshd_config.ipanew /etc/ssh/sshd_config /sbin/restorecon /etc/ssh/sshd_config chmod 600 /etc/ssh/sshd_config /bin/systemctl condrestart sshd.service 2>&1 || : fi fiopenssh-serverUQ@UPU:UU@TT~TTto@TmT[bTG@TFJT@T T@SGSFSSS|@SNpS5d@RR@RRƦ@R@RRw@RsRNR7R7R q@R6QQ@Q@Q'@Q@QvwQu&@Qm=@QZ@QVQ(@Q@PPPPPx@Px@PnPj@P\VPG>P@@P4P.2@PP @M6@M.@M.@M.@M-M M@L!LfLNLdLLLzLe3La?@LD>@L#HL#HL@K/KՀ@KK@KKs@Kie@K`*KK@K @JJ@J@J@JJB@J{IIIm@I1Iq@IKIFFI9I1.Ih@IIP@H@HXHO@H-w@H HHH@G߮GGgGs@G@G@G@G}G}G}GG@GC@GkGDG<4G)G(n@G3G@GJF@FS@FFuF@Alexander Bokovoy - 4.1.4-4Alexander Bokovoy - 4.1.4-3Petr Vobornik - 4.1.4-2Alexander Bokovoy - 4.1.4-1Petr Vobornik - 4.1.3-3Petr Vobornik - 4.1.3-2Petr Vobornik - 4.1.3-1Alexander Bokovoy - 4.1.2-2Petr Vobornik - 4.1.2-1Simo Sorce - 4.1.1-2Petr Vobornik - 4.1.1-1Petr Vobornik - 4.1.0-2Petr Vobornik - 4.1.0-1Petr Viktorin - 4.0.3-1Petr Viktorin - 4.0.2-1Pádraig Brady - 4.0.1-3Fedora Release Engineering - 4.0.1-2Martin Kosek 4.0.1-1Petr Viktorin 4.0.0-1Fedora Release Engineering - 3.3.5-4Petr Vobornik 3.3.5-3Peter Robinson 3.3.5-2Martin Kosek - 3.3.5-1Martin Kosek - 3.3.4-3Martin Kosek - 3.3.4-2Martin Kosek - 3.3.4-1Martin Kosek - 3.3.3-5Martin Kosek - 3.3.3-4Martin Kosek - 3.3.3-3Martin Kosek - 3.3.3-2Martin Kosek - 3.3.3-1Martin Kosek - 3.3.2-1Petr Viktorin - 3.3.1-1Petr Viktorin - 3.3.1-0Alexander Bokovoy - 3.3.0-2Martin Kosek - 3.3.0-1Fedora Release Engineering - 3.2.2-2Martin Kosek - 3.2.2-1Martin Kosek - 3.2.1-1Rob Crittenden - 3.2.0-2Rob Crittenden - 3.2.0-1Rob Crittenden - 3.2.0-0.4.beta1Rob Crittenden - 3.2.0-0.3.beta1Rob Crittenden - 3.2.0-0.2.beta1Martin Kosek - 3.2.0-0.1.pre1Kevin Fenzi 3.1.2-4Kevin Fenzi - 3.1.2-3Fedora Release Engineering - 3.1.2-2Rob Crittenden - 3.1.2-1Martin Kosek - 3.1.0-2Rob Crittenden - 3.1.0-1Martin Kosek - 3.0.0-3Rob Crittenden - 3.0.0-2Rob Crittenden - 3.0.0-1Rob Crittenden - 3.0.0-0.10Martin Kosek - 3.0.0-0.9Rob Crittenden - 3.0.0-0.8Rob Crittenden - 3.0.0-0.7Rob Crittenden - 3.0.0-0.6Alexander Bokovoy - 3.0.0-0.5Rob Crittenden - 3.0.0-0.4Martin Kosek - 3.0.0-0.3Alexander Bokovoy - 3.0.0-0.2Rob Crittenden - 3.0.0-0.1Rob Crittenden - 2.2.0-1Rob Crittenden - 2.1.90-0.2Rob Crittenden - 2.1.90-0.1Alexander Bokovoy - 2.1.4-5Martin Kosek - 2.1.4-4Alexander Bokovoy - 2.1.4-3Alexander Bokovoy - 2.1.4-2Rob Crittenden - 2.1.4-1Rob Crittenden - 2.1.3-8Alexander Bokovoy - 2.1.3-7Alexander Bokovoy - 2.1.3-6Fedora Release Engineering - 2.1.3-5Alexander Bokovoy - 2.1.3-4Alexander Bokovoy - 2.1.3-3Alexander Bokovoy - 2.1.3-2Alexander Bokovoy - 2.1.3-1Alexander Bokovoy - 2.1.2-1Rob Crittenden - 2.1.0-1Simo Sorce - 2.0.1-2Rob Crittenden - 2.0.1-1Rob Crittenden - 2.0.0-1Rob Crittenden - 2.0.0-0.4.rc2Rob Crittenden - 2.0.0-0.3.rc1Rob Crittenden - 2.0.0-0.1.rc1Fedora Release Engineering - 2.0.0-0.2.beta2Rob Crittenden - 2.0.0-0.1.beta2Rob Crittenden - 2.0.0-0.2.beta.git80e87e7Rob Crittenden - 2.0.0-0.1.beta.git80e87e7Rob Crittenden - 1.99-41Adam Young - 1.99-40Simo Sorce - 1.99-39Simo Sorce - 1.99-38Rob Crittenden - 1.99-37Rob Crittenden - 1.99-36Rob Crittenden - 1.99-35Jr Aquino - 1.99-34Simo Sorce - 1.99-33Rob Crittenden - 1.99-32Rob Crittenden - 1.99-31Rob Crittenden - 1.99-30Rob Crittenden - 1.99-29Rob Crittenden - 1.99-28Rob Crittenden - 1.99-27Rob Crittenden - 1.99-26Rob Crittenden - 1.99-25Adam Young - 1.99-24Rob Crittenden - 1.99-23Rob Crittenden - 1.99-22Rob Crittenden - 1.99-21Rob Crittenden - 1.99-20Rob Crittenden - 1.99-19Jason Gerard DeRose - 1.99-18Jason Gerard DeRose - 1.99-17Jason Gerard DeRose - 1.99-16Rob Crittenden - 1.99-15Jason Gerard DeRose - 1.99-14Rob Crittenden - 1.99-13Rob Crittenden - 1.99-12Rob Crittenden - 1.99-11Rob Crittenden - 1.99-10Rob Crittenden - 1.99-9Jason Gerard DeRose - 1.99-8Rob Crittenden - 1.99-7Rob Crittenden - 1.99-6Rob Crittenden - 1.99-5Rob Crittenden - 1.99-4Rob Crittenden - 1.99-3Rob Crittenden - 1.99-2Rob Crittenden - 1.99-1Tomas Mraz - 1.2.1-3Dan Walsh - 1.2.1-2Simo Sorce - 1.2.1-1Simo Sorce - 1.2.1-0Ignacio Vazquez-Abrams - 1.2.0-4Simo Sorce - 1.2.0-3Simo Sorce - 1.2.0-2Rob Crittenden - 1.2.0-1Simo Sorce - 1.1.0-3Rob Crittenden - 1.1.0-2Rob Crittenden - 1.1.0-1Rob Crittenden - 1.0.0-5Rob Crittenden - 1.0.0-4Rob Crittenden - 1.0.0-3Rob Crittenden - 1.0.0-2Rob Crittenden - 1.0.0-1Rob Crittenden 0.99-12Rob Crittenden 0.99-11Rob Crittenden 0.99-10Rob Crittenden 0.99-9Rob Crittenden 0.99-8Rob Crittenden 0.99-7Rob Crittenden 0.99-6Rob Crittenden 0.99-5Rob Crittenden 0.99-4Rob Crittenden 0.99-3Rob Crittenden 0.99-2Rob Crittenden 0.99-1Rob Crittenden - 0.6.0-2Karl MacMillan - 0.6.0-1Karl MacMillan - 0.5.0-1Rob Crittenden - 0.4.1-2Karl MacMillan - 0.4.1-1Karl MacMillan - 0.4.0-6Rob Crittenden - 0.4.0-5Rob Crittenden - 0.4.0-4Karl MacMillan - 0.4.0-3Karl MacMillan - 0.4.0-2Karl MacMillan - 0.2.0-1Rob Crittenden - 0.1.0-3Rob Crittenden - 0.1.0-2Karl MacMillan - 0.1.0-1- Fix typo in the patch to fix bug #1219834- Fix FreeIPA trusts to AD feature with Samba 4.2 (#1219834)- Replace mod_auth_kerb usage with mod_auth_gssapi- Update to upstream 4.1.4 - see http://www.freeipa.org/page/Releases/4.1.4 - fix CVE-2015-1827 (#1206047) - Require slapi-nis 0.54.2 and newer for CVE-2015-0283 fixes- Timeout ipa-client install if ntp server is unreachable #4842 - Skip time sync during client install when using --no-ntp #4842- Add missing sssd python dependencies - https://bugzilla.redhat.com/show_bug.cgi?id=1197218- Update to upstream 4.1.3 - see http://www.freeipa.org/page/Releases/4.1.3- Fix broken build after Samba ABI change and rename of libpdb to libsamba-passdb - Use python-dateutil15 until we validate python-dateutil 2.x- Update to upstream 4.1.2 - see http://www.freeipa.org/page/Releases/4.1.2 - fix CVE-2014-7850- Patch blokers and feature freze exceptions - Resolves: bz1165674 - Resolves: bz1165856 (CVE-2014-7850) - Fixes DNS install issue that prevents the server from working- Update to upstream 4.1.1 - see http://www.freeipa.org/page/Releases/4.1.1 - fix CVE-2014-7828- fix armv7hl stack oversize build failure - fix https://fedorahosted.org/freeipa/ticket/4660- Update to upstream 4.1.0 - see http://www.freeipa.org/page/Releases/4.1.0- Update to upstream 4.0.3 - see http://www.freeipa.org/page/Releases/4.0.3- Update to upstream 4.0.1 - see http://www.freeipa.org/page/Releases/4.0.2- rebuild for libunistring soname bump- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Update to upstream 4.0.1- Update to upstream 4.0.0 - Remove the server-strict package- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Increase Java stack size for Web UI build on aarch64- Add rhino as dependency to fix FTBFS- Update to upstream 3.3.5- Move ipa-otpd socket directory to /var/run/krb5kdc - Require krb5-server 1.11.5-3 supporting the new directory - ipa_lockout plugin did not work with users's without krbPwdPolicyReference- Fix hardened build- Update to upstream 3.3.4 - Install CA anchor into standard location (#928478) - ipa-client-install part of ipa-server-install fails on reinstall (#1044994) - Remove mod_ssl workaround (RHEL bug #1029046) - Enable syncrepl plugin to support bind-dyndb-ldap 4.0- Build crashed with rhino exception on s390 architectures (#1040576)- Build crashed with rhino exception on PPC architectures (#1040576)- Fix -Werror=format-security errors (#1037070)- ipa-server-install crashed when freeipa-server-trust-ad subpackage was not installed- Update to upstream 3.3.3- Update to upstream 3.3.2- Bring back Fedora-only changes- Update to upstream 3.3.1- Remove freeipa-systemd-upgrade as non-systemd installs are not supported anymore by Fedora project- Update to upstream 3.3.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Update to upstream 3.2.2 - Drop freeipa-server-selinux subpackage - Drop redundant directory /var/cache/ipa/sessions - Do not create /var/lib/ipa/pki-ca/publish, retain reference as ghost - Run ipa-upgradeconfig and server restart in posttrans to avoid inconsistency issues when there are still old parts of software (like entitlements plugin)- Update to upstream 3.2.1- Add OTP patches - Add patch to set KRB5CCNAME for 389-ds-base- Update to upstream 3.2.0 GA - ipa-client-install fails if /etc/ipa does not exist (#961483) - Certificate status is not visible in Service and Host page (#956718) - ipa-client-install removes needed options from ldap.conf (#953991) - Handle socket.gethostbyaddr() exceptions when verifying hostnames (#953957) - Add triggerin scriptlet to support OpenSSH 6.2 (#953617) - Require nss 3.14.3-12.0 to address certutil certificate import errors (#953485) - Require pki-ca 10.0.2-3 to pull in fix for sslget and mixed IPv4/6 environments. (#953464) - ipa-client-install removes 'sss' from /etc/nsswitch.conf (#953453) - ipa-server-install --uninstall doesn't stop dirsrv instances (#953432) - Add requires for openldap-2.4.35-4 to pickup fixed SASL_NOCANON behavior for socket based connections (#960222) - Require libsss_nss_idmap-python - Add Conflicts on nss-pam-ldapd < 0.8.4. The mapping from uniqueMember to member is now done automatically and having it in the config file raises an error. - Add backup and restore tools, directory. - require at least systemd 38 which provides the journal (we no longer need to require syslog.target) - Update Requires on policycoreutils to 2.1.14-37 - Update Requires on selinux-policy to 3.12.1-42 - Update Requires on 389-ds-base to 1.3.1.0 - Remove a Requires for java-atk-wrapper- Remove release from krb5-server in strict sub-package to allow for rebuilds.- Add a Requires for java-atk-wrapper until we can determine which package should be pulling it in, dogtag or tomcat.- Update to upstream 3.2.0 Beta 1- Update to upstream 3.2.0 Prerelease 1 - Use upstream reference spec file as a base for Fedora spec file- Rebuild for broken deps - Fix 389-ds-base strict dep to be 1.3.0.5 and krb5-server 1.11.1- Rebuild for broken deps in rawhide - Fix 389-ds-base strict dep to be 1.3.0.3- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild- Update to upstream 3.1.2 - CVE-2012-4546: Incorrect CRLs publishing - CVE-2012-5484: MITM Attack during Join process - CVE-2013-0199: Cross-Realm Trust key leak - Updated strict dependencies to 389-ds-base = 1.3.0.2 and pki-ca = 10.0.1- Remove redundat Requires versions that are already in Fedora 17 - Replace python-crypto Requires with m2crypto - Add missing Requires(post) for client and server-trust-ad subpackages - Restart httpd service when server-trust-ad subpackage is installed - Bump selinux-policy Requires to pick up PKI/LDAP port labeling fixes- Updated to upstream 3.1.0 GA - Set minimum for sssd to 1.9.2 - Set minimum for pki-ca to 10.0.0-1 - Set minimum for 389-ds-base to 1.3.0 - Set minimum for selinux-policy to 3.11.1-60 - Remove unneeded dogtag package requires- Update Requires on krb5-server to 1.11- Configure CA replication to use TLS instead of SSL- Updated to upstream 3.0.0 GA - Set minimum for samba to 4.0.0-153. - Make sure server-trust-ad subpackage alternates winbind_krb5_locator.so plugin to /dev/null since they cannot be used when trusts are configured - Restrict krb5-server to 1.10. - Update BR for 389-ds-base to 1.3.0 - Add directory /var/lib/ipa/pki-ca/publish for CRL published by pki-ca - Add Requires on zip for generating FF browser extension- Updated to upstream 3.0.0 rc 2 - Include new FF configuration extension - Set minimum Requires of selinux-policy to 3.11.1-33 - Set minimum Requires dogtag to 10.0.0-0.43.b1 - Add new optional strict sub-package to allow users to limit other package upgrades.- Require samba packages instead of obsoleted samba4 packages- Updated to upstream 3.0.0 rc 1 - Update BR for 389-ds-base to 1.2.11.14 - Update BR for krb5 to 1.10 - Update BR for samba4-devel to 4.0.0-139 (rc1) - Add BR for python-polib - Update BR and Requires on sssd to 1.9.0 - Update Requires on policycoreutils to 2.1.12-5 - Update Requires on 389-ds-base to 1.2.11.14 - Update Requires on selinux-policy to 3.11.1-21 - Update Requires on dogtag to 10.0.0-0.33.a1 - Update Requires on certmonger to 0.60 - Update Requires on tomcat to 7.0.29 - Update minimum version of bind to 9.9.1-10.P3 - Update minimum version of bind-dyndb-ldap to 1.1.0-0.16.rc1 - Remove Requires on authconfig from python sub-package- Rebuild against samba4 beta8- Rebuild against samba4 beta7- Adopt to samba4 beta6 (libsecurity -> libsamba-security) - Add dependency to samba4-winbind- Updated to upstream 3.0.0 beta 2- Updated to current upstream state of 3.0.0 beta 2 development- Rebuild against samba4 beta4- Updated to upstream 3.0.0 beta 1- Updated to upstream 2.2.0 GA - Update minimum n-v-r of certmonger to 0.53 - Update minimum n-v-r of slapi-nis to 0.40 - Add Requires in client to oddjob-mkhomedir and python-krbV - Update minimum selinux-policy to 3.10.0-110- Update to upstream 2.2.0 beta 1 (2.1.90.rc1) - Set minimum n-v-r for pki-ca and pki-silent to 9.0.18. - Add Conflicts on mod_ssl - Update minimum n-v-r of 389-ds-base to 1.2.10.4 - Update minimum n-v-r of sssd to 1.8.0 - Update minimum n-v-r of slapi-nis to 0.38 - Update minimum n-v-r of pki-* to 9.0.18 - Update conflicts on bind-dyndb-ldap to < 1.1.0-0.9.b1 - Update conflicts on bind to < 9.9.0-1 - Drop requires on krb5-server-ldap - Add patch to remove escaping arguments to pkisilent- Update to upstream 2.2.0 alpha 1 (2.1.90.pre1)- Force to use 389-ds 1.2.10-0.8.a7 or above - Improve upgrade script to handle systemd 389-ds change - Fix freeipa to work with python-ldap 2.4.6- Fix ipa-replica-install crashes - Fix ipa-server-install and ipa-dns-install logging - Set minimum version of pki-ca to 9.0.17 to fix sslget problem caused by FEDORA-2011-17400 update (#771357)- Allow Web-based migration to work with tightened SE Linux policy (#769440) - Rebuild slapi plugins against re-enterant version of libldap- Allow longer dirsrv startup with systemd: - IPAdmin class will wait until dirsrv instance is available up to 10 seconds - Helps with restarts during upgrade for ipa-ldap-updater - Fix pylint warnings from F16 and Rawhide- Update to upstream 2.1.4 (CVE-2011-3636)- Update SELinux policy to allow ipa_kpasswd to connect ldap and read /dev/urandom. (#759679)- Fix wrong path in packaging freeipa-systemd-upgrade- Introduce upgrade script to recover existing configuration after systemd migration as user has no means to recover FreeIPA from systemd migration - Upgrade script: - recovers symlinks in Dogtag instance install - recovers systemd configuration for FreeIPA's directory server instances - recovers freeipa.service - migrates directory server and KDC configs to use proper keytabs for systemd services- Rebuilt for glibc bug#747377- clean up spec - Depend on sssd >= 1.6.2 for better user experience- Fix Fedora package changelog after merging systemd changes- Fix postin scriplet for F-15/F-16- 2.1.3- Default to systemd for Fedora 16 and onwards- Update to upstream 2.1.0- Fix bug #702633- Update minimum selinux-policy to 3.9.16-18 - Update minimum pki-ca and pki-selinux to 9.0.7 - Update minimum 389-ds-base to 1.2.8.0-1 - Update to upstream 2.0.1- Update to upstream GA release - Automatically apply updates when the package is upgraded- Update to upstream freeipa-2.0.0.rc2 - Set minimum version of python-nss to 0.11 to make sure IPv6 support is in - Set minimum version of sssd to 1.5.1 - Patch to include SuiteSpotGroup when setting up 389-ds instances - Move a lot of BuildRequires so this will build with ONLY_CLIENT enabled- Set the N-V-R so rc1 is an update to beta2.- Set minimum version of sssd to 1.5.1 - Update to upstream freeipa-2.0.0.rc1 - Move server-only binaries from admintools subpackage to server- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Set min version of 389-ds-base to 1.2.8 - Set min version of mod_nss 1.0.8-10 - Set min version of selinux-policy to 3.9.7-27 - Add dogtag themes to Requires - Update to upstream freeipa-2.0.0.pre2- Remove unnecessary moving of v1 CA serial number file in post script - Add Obsoletes for server-selinxu subpackage - Using git snapshot 442d6ad30ce1156914e6245aa7502499e50ec0da- Prepare spec file for release - Using git snapshot 80e87e75bd6ab56e3e20c49ece55bd4d52f1a503- Re-arrange doc and defattr to clean up rpmlint warnings - Remove conditionals on older releases - Move some man pages into admintools subpackage - Remove some explicit Requires in client that aren't needed - Consistent use of buildroot vs RPM_BUILD_ROOT- Moved directory install/static to install/ui- Remove dependency on nss_ldap/nss-pam-ldapd - The official client is sssd and that's what we use by default.- Remove radius subpackages- Set minimum pki-ca and pki-silent versions to 9.0.0- Drop BuildRequires on mozldap-devel- Add Requires on krb5-pkinit-openssl- Add ipa-host-net-manage script- Add ipa init script- Set minimum level of 389-ds-base to 1.2.7 for enhanced memberof plugin- remove ipa-fix-CVE-2008-3274- Remove duplicate %files entries on share/ipa/static - Add python default encoding shared library- Drop requires on python-configobj (not used any more) - Drop ipa-ldap-updater message, upgrades are done differently now- Drop conflicts on mod_nss - Require nss-pam-ldapd on F-14 or higher instead of nss_ldap (#606847) - Drop a slew of conditionals on older Fedora releases (< 12) - Add a few conditionals against RHEL 6 - Add Requires of nss-tools on ipa-client- Set minimum version of certmonger to 0.26 (to pck up #621670) - Set minimum version of pki-silent to 1.3.4 (adds -key_algorithm) - Set minimum version of pki-ca to 1.3.6 - Set minimum version of sssd to 1.2.1- Add BuildRequires for authconfig- Bump up minimum version of python-nss to pick up nss_is_initialize() API- Removed python-asset based webui- Change Requires from fedora-ds-base to 389-ds-base - Set minimum level of 389-ds-base to 1.2.6 for the replication version plugin.- Drop Requires of python-krbV on ipa-client- Load ipa_dogtag.pp in post install- Set minimum level of sssd to 1.1.1 to pull in required hbac fixes.- No need to create /var/log/ipa_error.log since we aren't using TurboGears any more.- Fixed share/ipa/wsgi.py so .pyc, .pyo files are included- Added Require mod_wsgi, added share/ipa/wsgi.py- Require python-wehjit >= 0.2.2- Add sssd and certmonger as a Requires on ipa-client- Require python-wehjit >= 0.2.0- Add ipa-rmkeytab tool- Set minimum of python-pyasn1 to 0.0.9a so we have support for the ASN.1 Any type- Remove v1-style /etc/ipa/ipa.conf, replacing with /etc/ipa/default.conf- Add bash completion script and own /etc/bash_completion.d in case it doesn't already exist- Remove ipa_webgui, its functions rolled into ipa_httpd- Removed python-cherrypy from BuildRequires and Requires - Added Requires python-assets, python-wehjit- Added httpd SELinux policy so CRLs can be read- Move ipalib to ipa-python subpackage - Bump minimum version of slapi-nis to 0.15- Set 0.14 as minimum version for slapi-nis- Add Requires: python-nss to ipa-python sub-package- Remove the IPA DNA plugin, use the DS one- Build radius separately - Fix a few minor issues- Replace TurboGears requirement with python-cherrypy- rebuild with new openssl- Fix SELinux code- Fix breakage caused by python-kerberos update to 1.1- New upstream release 1.2.1- Rebuild for Python 2.6- Respin after the tarball has been re-released upstream New hash is 506c9c92dcaf9f227cba5030e999f177- Conditionally restart also dirsrv and httpd when upgrading- Update to upstream version 1.2.0 - Set fedora-ds-base minimum version to 1.1.3 for winsync header - Set the minimum version for SELinux policy - Remove references to Fedora 7- Fix for CVE-2008-3274 - Fix segfault in ipa-kpasswd in case getifaddrs returns a NULL interface - Add fix for bug #453185 - Rebuild against openldap libraries, mozldap ones do not work properly - TurboGears is currently broken in rawhide. Added patch to not build the UI locales and removed them from the ipa-server files section.- Add call to /usr/sbin/upgradeconfig to post install- Update to upstream version 1.1.0 - Patch for indexing memberof attribute - Patch for indexing uidnumber and gidnumber - Patch to change DNA default values for replicas - Patch to fix uninitialized variable in ipa-getkeytab- Set fedora-ds-base minimum version to 1.1.0.1-4 and mod_nss minimum version to 1.0.7-4 so we pick up the NSS fixes. - Add selinux-policy-base(post) to Requires (446496)- Add missing entry for /var/cache/ipa/kpasswd (444624) - Added patch to fix permissions problems with the Apache NSS database. - Added patch to fix problem with DNS querying where the query could be returned as the answer. - Fix spec error where patch1 was in the wrong section- Added patch to fix problem reported by ldapmodify- Fix Requires for krb5-server that was missing for Fedora versions > 9 - Remove quotes around test for fedora version to package egg-info- Update to upstream version 1.0.0- Pull upstream changelog 722 - Add Conflicts mod_ssl (435360)- Pull upstream changelog 698 - Fix ownership of /var/log/ipa_error.log during install (435119) - Add pwpolicy command and man page- Pull upstream changelog 678 - Add new subpackage, ipa-server-selinux - Add Requires: authconfig to ipa-python (bz #433747) - Package i18n files- Pull upstream changelog 641 - Require minimum version of krb5-server on F-7 and F-8 - Package some new files- Marked with wrong license. IPA is GPLv2.- Ensure that /etc/ipa exists before moving user-modifiable html files there - Put html files into /etc/ipa/html instead of /etc/ipa- Pull upstream changelog 608 which renamed several files- package the sessions dir /var/cache/ipa/sessions - Pull upstream changelog 597- Updated upstream pull (596) to fix bug in ipa_webgui that was causing the UI to not start.- Included LICENSE and README in all packages for documentation - Move user-modifiable content to /etc/ipa and linked back to /usr/share/ipa/html - Changed some references to /usr to the {_usr} macro and /etc to {_sysconfdir} - Added popt-devel to BuildRequires for Fedora 8 and higher and popt for Fedora 7 - Package the egg-info for Fedora 9 and higher for ipa-python- Added auto* BuildRequires- Unified spec file- Fixed License in specfile - Include files from /usr/lib/python*/site-packages/ipaserver- Version bump for release- Preverse mode on ipa-keytab-util - Version bump for relase and rpm name change- Broke invididual Requires and BuildRequires onto separate lines and reordered them - Added python-tgexpandingformwidget as a dependency - Require at least fedora-ds-base 1.1- Version bump for release- Add dep for freeipa-admintools and acl- Add dependency for python-krbV- Require mod_nss-1.0.7-2 for mod_proxy fixes- Convert to autotools-based build* Fri Sep 7 2007 Karl MacMillan - 0.3.0-1 - Added support for libipa-dna-plugin- Added support for ipa_kpasswd and ipa_pwd_extop- Abstracted client class to work directly or over RPC- Add mod_auth_kerb and cyrus-sasl-gssapi to Requires - Remove references to admin server in ipa-server-setupssl - Generate a client certificate for the XML-RPC server to connect to LDAP with - Create a keytab for Apache - Create an ldif with a test user - Provide a certmap.conf for doing SSL client authentication- Initial rpm version/bin/shipa-client/bin/sh  !"#$4.1.4-4.fc224.1.4-4.fc224.1.4 ipaclient__init__.py__init__.pyc__init__.pyoipa_certupdate.pyipa_certupdate.pycipa_certupdate.pyoipachangeconf.pyipachangeconf.pycipachangeconf.pyoipadiscovery.pyipadiscovery.pycipadiscovery.pyontpconf.pyntpconf.pycntpconf.pyoipa-certupdateipa-client-automountipa-client-installipa-getkeytabipa-joinipa-rmkeytabfreeipa-clientCOPYINGContributors.txtREADMEipaipa-certupdate.1.gzipa-client-automount.1.gzipa-client-install.1.gzipa-getkeytab.1.gzipa-join.1.gzipa-rmkeytab.1.gzdefault.conf.5.gzipa-clientsysrestore/usr/lib/python2.7/site-packages//usr/lib/python2.7/site-packages/ipaclient//usr/sbin//usr/share/doc//usr/share/doc/freeipa-client//usr/share//usr/share/man/man1//usr/share/man/man5//var/lib//var/lib/ipa-client/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnu  directoryASCII textpython 2.7 byte-compiledPython script, ASCII text executableELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.32, BuildID[sha1]=e2a879c59ed34a3149bd0d5ea7f634e3435fc630, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.32, BuildID[sha1]=66a7f40b24416f2f99c667a8beb0c38009e7b9b4, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.32, BuildID[sha1]=2c820c06e2ec4afc7b693598828f9420f04a4e1f, strippedUTF-8 Unicode texttroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix) #7 R(R(R(R(R(R(R(R(R(R(R(R(R(R(R(RRRRR RRRR RRRRRRRRRR R2RRRRR RR RRRRRRRRR!R RR R2RRRRRR RRRRR R2?7zXZ !PH6[&]"k%{Ht89.bDX#t+.tFײ _4(-t󐼡0xo銠jRSTEGMtg[}$V %nCwq:-3A<_"h <5~6q˹.f>};@m:8Hȍ d4~{hįGaf"ڞaO_o$fd3A?Lh ],F7/al_WZc,A0?QI3 Yn8NCSωIM)"Ǝd>~W]|}C JxvO/"i:~ ""B#'yw Z4s< zZ?-ϥ~ /rK=a=mYlhBwG c3j c^)Wu|x>bSSl\|<ɑzw!))vׁ^X1-ZyفH0pkPV˯Z ,_2gOgxd냖}g<=@>vϨ.*qfqX(oVdUgl&ž+@mo`Tᜫǁio&n۶/YXhQ^N,K@cj YRfDf³`$>r1 ۆ ־sD&&H$ZZ 1.3m@4qno<3!hkR0|UgO`{5jJ৬r}ė16NKiAN =-ZMzHYCc:edɀ%̃ڗA"MH>޺(şZ9(%)p#dK/M 6Uи #R>Pb _Q&RmYg&kۓ7ë.XlEf{Q9L )yjU]e!*^U\+9WXU 9$z_|w\ 3BdH>(y#nB+h:+z 7#rIA5ˊm"zD //UӨA5VAy0Շ37>-zEdfBĐyA,-_s/[GG|=5\Ͳą2$i8Ky)Grz>FW;]"D ni?*㪘̷Fb Aɑ,8-J|I^  2' Ŕҡ.2(DBjd쬪}\]ԒH/$^r_ 8㴝Fq;-5|/_z ;RXGJ*r HpZ:Kv;=).,sy6+wy +PDRLoS2︒Vpcsʿŕ 93wyPw0xICֱąƒ"CHQ˥S*%L{y_ cȤkVi<{rxkO,)ŪL8es\n)'XMzڗ@BV-y rā8akϚU38Dz0/Fn*KMGÖ ^q=P/hzRu (F-ik5tCv?#E]>kJ(3nPXgLep2X Y9wU7e&rnBZdWӴ*eY|ӰvK<ADQX8V:ry-?05jBJvUYkTGs{Bq-a3`BOWT\3!2)=0+&hUiӚ_{lĝAY-p)b M?˝[l թ4m"b"{V- Ji69ћh,;exPcb,~aǩbgQ%Q(.tt5_7t,qSVNjXpy%)]ʽ/7G!|1NJfTMo^tg%,L 7vϳE.|fRNYPlMQj촅ݦp W6lgSIw.t_"SK +?T"vfSy`$9F40kYJe" GKŇңȉIc9ȓ6J`cpVazp^6R!n %dS^2$|z.RuI>%ˡ.Ѧ6T|'+B2W[dg\;'{|.I}<畏R/{mΓK9mc%?߳W Wؒ kRGYhmF< 4CqtGBO_1?5U'!@RN٪HVm:VRrkWw0C9Q2K%}n]< CFU+IF\i]~܍r=*yi@yIJR0?k73$?0:#&r9뵧jtXKւۃ™sox*} iM:U]9J B.SPO@{}c%_Fbܞ9>85#5,sqN2oMm~>t&7Y}rB A s7*GHO1l^:IzfEI ZM]o$^;.&z#aCi442RY/b1C%jbQNLRec:lM @ I _`] 꼠}X9;@;!~{HԤdA^* bdMo{8|>iJ4#u*%|#e%'Rg^tIveb| B+ vȎ+Kt/FV[E9/8poG"D{2qd'f'gRK;ѐKprNc"  +sa}Qf ꕓ5ξ߄ݏ*!"'P. 6Y#yz_:AI3)kZ%> ە T! }e]m,C, z$ߥܔß%4.Qk~s^Cb2Vޅ[ɰ(vUu\ӵTՀ`+ǂM~p?:n*/I{)^\>h5W;}85e$̆yE=SL YH`C5C LѹnC/f~9nXmPN >rANdu(YS$[^$ ZR"M׿L0tY{%`$]w)yNF%C[0Ac$Q=?lU޼kxv&v؎N\뙁mQlz0Տc8p?W,@IpE}]TD< b):H:dL^:"` ]Q9XSnn/he+%r: ݩ yеCalG"wrމI@8XIE)ҁ;dmE7a! 24} W9=!MqK5wakCGtIӗ/OZlԆX݈;3KԳLDez/EL3O&CXcBMW`fcjeHSV&;AJgk?sil'뚒lCQ.'^{bVZvIqڪ뵕֞=\R2LA:Uٌ^Iܲ] p_BG ׺# "~{?`$RnX4NKaA>U+1HY/HrpEeaU<+Lu5AI?2םGUhфCxjƃ>4Zx>0=ȝ&: q'\Ɍ!#ZVf3# Zw)KNw4/>(HeJ::@'w}n?OaatfIL[\vahVaCU0HE5HQn3n)i ~djk-4Ţ7exQ9(6eddhá}` JHc<cHt}C$i66ELq{2;x=sڪдz?tW˝[(ؘеNSMy[KfC^:hBYEs[YO%;Q,H$Z[ zs=5YRK,q˨ϵSA~ﻒpgHrsP 7MVmi̩]+hȒX.>źʶիQkrv%sjqXj +hP[fH>h-8Zu8#zGՐmDjݡ4kju0w{Yo?^C5SR HE+J޷$]Sw=ɲF_ e*DΔHf0 odO 'J `kI4ŽAVyW$aiqhÚ0Wu7/}L:^p껫]4O:b.JR&~dʝNf;Y-՚c"̠W)Â%*WRDĆH2;nrKM ͯHsRЋ߸W{Ab b83Z_oASBt vj 1[ RZY4y&AgJbbcW0"hA}}hkRxSe_۬oU#QrcfI,] #׫P(|%Xvt$rI҄ԯZpp9mϾkJQT T ZDǂw. >bB Z?iԱlAcdKxU+Kф/'[C}gӝCnW_uE;.9#DbF﹃,Ϲ $yi\= D/=2>ACoQ a+Q×p#=ԁpR= 55\8gMnQ&c钘^*H䭷J#۾*)r.qmBG Ĭ8̫~Lͦsᅱ79e?Gbm֫6VvxTzfۮBpy+T'gWʉ˓ƞmj |'ȹCZjq%f[zɟeҥ7ЪBQ&RɎ:N@p5GCB/&O`GzX̬+2)BJںWw e:J] nlyY ǔggISO9IEPVKjRHud/dUYdc 1h/ȗnk0r ,=AYvf\n6=Ha'sqbxY!cݗZL e[yGP48hRfʽ4* ,"Ћl`-乸EGNPݤ_plJ6Q͗(iLOZ\f0 ]$F> Ie5\NX qG!8Kh[kƓgUm9]9Ōw[G1j3b2!.+M^_WW>E\N gGѮtX`f9~%M#dV.>J*$Vz&.O#ء\d|%^GxB>-2uS=/j4m-3>n`{`6܌\S)1x"2~nrʯLoZf!2o,xT:~RNjMځr%|. rr`#HX7Md`ƒԩgYg9SvRKB[Ty(E];r+ӱVۘ|P}9yw5chv2Ao9cYfP"mnnDE-,JK,PX;)\Y2aPOeF vWH!.Osv:$O,Uo~;AOȾ{uy:69uf(-zH詂y@gbii_,g'I)@% DWpdZ6F78eAӰf*wV~|vuhv`ak $']Pobt1VfÒx7ԅΆI tA=`gr0ؘr%"mǴᕳ|M&,XYܟ-U`gF^:^6 > 4ji/6Kt[1\^%rH0kM6k&ɩx6g̚|I*0u2E)7Nx~+; n9<;zh]2ӹJqB6Lъ;Ԯ5HbI!/R[|68&!U<:|is|(}K'1! P5=:h iz|P̑x%Li~$O藕AIDUѓd0);l_\;R~ քӬ(a+/2W97Lf8&݁vU_aǖLchVh/E[yH=ޢ\)I /?`M U@fv`iEpM[=vc m<'.Lw=XJcH6l*w)!/%vd}UWGZO72A:9:26؞л`L۔Nkxh<(dWVhO@o!kiM<$^gR}R@ُB?9f@HEPbo\B'Mj> RaaϤq8HY8>*֏Tu&نLϝGI\WŤ0]_â?äip&ĝ%ձ1C l|=j?Ζ}I~jl%*W4.Y~ waQ=#Up q> V{ī2G"Q 9vAEr ?#٪o O,Η;`$.ݫeԲmleߋGHYr? jѷeFAq`;I 4b42܌I+۟[Po%;r]2ԜBH@qi~EIφu-xQ y^|)0NOn5ଯ8a۽FB^l3E˵ O7惢OOhPTڱ Jz.+K7 B EB [޻Y2s|21;)D3)#A5+*R 陈lKF]6wCZtm }:J*bࡴоiuxO% AHjP3w44:ģ$Umt3!@q|2:x/$/!$?t74{%79*@[ mȄQ@U߿3NSP{V|8J<{fʱr#'t=!qgJ~5<ME~RnayCĊ/zUkg9pRj#i ›i9%psC픝F0W ݇j1`7h?Hcalpx]vϲ^D~P?iç^Pd` B# 9hfA *Y8W@E wq] eE7lF\W|0gVR%TÍ){/c\ $p9q!=!BL} Vh͡| ljj$B2\OL#Um)" %3JeZ'e_Oy=zJҴ&h9A#{ܼ":-#OW,+ ?bz;0rYfs ZLO>9c7el{t 9j#Gc^a!u-$8 .YDY۸4ΰ&{ vF':65 -"5DvCLQpNSó:;3'3^"7|R+3f0^!.SJ\g^ sz\Iuܺǹ9}9 /n@ݖmҍ?\$sY 5T77w*4t&Iy*X4fmy a90 %* "b[.njN_drE\ >Źt܁ FNW.ɩ%4/fc(_ W=GW6Dצ ɖ Yu$q"3H[fi1x!Q2 {GuB"ԟ#Ba6$ZaC5C-i4 <♼!A_zDM˃_wU+|rΡC% *^W= _3 +Q)fPK$xx \U#wQ|NWE`:YwG 3N"=ral^AV7{:WcNw G$q|7: Fȉ6WVmjT+o-+^2 |Io.i9'ؾU nL/9E f.P[Dx;wrR#tBuZrꥤ5Vc>Z%=qIxq,di8=@MԧIƆ_ufQH{yi@lnPGaU4x))v7+y-Q'sՁ" cQJ~D\)62Mtq!/)$#N+<0g2oA؜'.0m9TVT2ܥȨHy5Iwud6FC.$͒/C[1 >\؞ĕs]- x@dz-|QӄLtxВn0r4B5QBQdH[&Ɖ>_c rIX@%4EY*@Yednoxnpnd"㾗y$<&Iz|:JwOOXH (C$yX:5&rݎac u0H3q7P#ˌp4zpYp yDm}wmgK6坊`wJfj:V vҼ*IERJ _&T>g#hvOAFWuAp76 qS4L%C 2sI&&hSEr)O2iГ%Ypk " Ui(PaB-XAػw͠." ) eL ~tq~GqwIzDĕzUMMw6sEn-9!69ޒ֧W} r]ٚ}.Vg .U9ʩ&ON}?:q~O#=k7.*N gmQZGdn]S,|mz_o ^%s$ۍ,mD~e1EzqL4;­O *HAit>=jt|ӥ0#;O\pn Nb'xP**8q==NP6@qwómxMȅpx/] R㩕>^-Z"1 $ϼ:cOJq5 P·t5[HBz'ϔ5d=cZ]uӘ|M!mSWE'Sp*pME!v5g[RM蝱cz;š\Lɣ6__DKmꋵ8R4o]"lH=#,&c;~Ú4l> )eT|Fd2BQn6%žYaҎ:0!pd]`s;QxطSQq=f9CaEXzvN[V`(_|bZ( k1Tx^)jc;t^'܉ׅ.:'e:/gpTmG7eh>k+FJ@X<|化Ý"[^ { E-k"M|yN \^izBU؝а fh$!}EFzȮI8;ӭӯqc"ۮ#x]d,K!u\;}[z:}2  =2*53}B&ψVH* f;l:*cJb@t8yj!u3RfNvQ>k $F.,.H`ZTtι[+ 6ڭtpEqӢ[mv/*l}?V67(_z.bnpB;SJ ,(L6?Ƣc,z| gF]9 bxS[y63`&sB#U7ZŒTbV:wÈEN"[5aTY_ܠ%ruG<&(tdxDd]Зʊ1h†{ZJW4 c*ن JRȮAKҐh@yyv;&*L_ifk~Xڕއ[- sCjcv[f;.yA ۜYfemf#0+UIf@I-fN{ jVpE.yrEi_䃛i O~~SGp Ly4AR4qv>7s,qQA.S%zK[Lj:CrAb_U,9^vZo#.d=A]AUcwY1[ =肇_Xs+7>vut3]CJ5i.xqd]-""C ' 9F!a:Bć9(Y-46268#,rlw?ꃈ7ɧ"2||[:w-DW1_WGUa{0l%˽;%v󉄐0c o_.pwoԇ;#$ai[YۛC͞HnYrGyݾw߸hD=̤'4lQnq+t%i:j.Mmxd3ZID_CcZcx6)9cK"{z[jB96ݯBʶpҪw2y`@Jh8%PRFtCN~T#+srFrZX9:Dm.F~ibVviVe++-/FCwbOUMm!%[}Z |k`rR[Ng*lA,P<N"u%},qߴH=" Ïd]uTšdak|u6yz8nL_Y[c$$nK%`,*v}&Δ GG}`OA;GuP+-@nY?@MO~֏@ 5fKuc `ۧOt{S qũjW+ՏT 1tb}Oe^ՅUy˰3&. (݄W2Bë;fMB{Eae`wM\藦|sS *SPϧ_)) l_zdyS0Z};[_>S1יsnz#"ʀ2y7./CxTaHG)*9Ȕ>:|_cE*؎`5O=A'Gq-">LOFs=DdoNJ/]I Fd}DC; ⧍Ԯ,K}.6W2fŊ0@ bwf{Fj sOG:->Ք|w%.]xUu_ޝ9%Fjk " H{-O|&/B51>o'GT4+1ġ^WeKzqrijAOv##?c#_|NyV7u~$,Srō0<;('Sgۛp]&\%J1{/eHעHA+LXm@#?ԛ#/R+`۞֟|@i`'w\ 9ճ۸O]ΡH+,5i2_I;Bzɗ~ŋ0 pm)䣓EӇ,ԫ͢6$k/y,U aAZZ20DJ+aW)ΪYpojrjIJy W"qPMɦKlh]6|ګIqMj"ܹ-Ь9 ¿ _8o!^<$Dw`ϝo'!ܜo&9q= u#wfk[miD+^:t 1&'s q |{r ܘZUD$\eVO3Y/=Me+&J8|62ҫz|P yvM!GpgUKW؎r)'ʷ4:f>eVzm:?E}eT5PG|<`Pz SX],W 'wbTȬX!I)kef6)`Kb: ˘ T{!g8aԥT]R%(h53 UPjb3AxL 

eo|BzncCTfntt6r)1UZ H⌝*ȱr\sz(ܾi~O3"9P1VqіL(s!V[ZnnM 7샀zk9KԢ#&ΎjZM2[虭뚹ٹٳw[(G@PHG_*CrTCzϖwe^r94B|3WD}.WFWRGsANOnD~q3q$XN܍ioQf8ѓ $. Ai_y.e?(Gdozf@ۉGl$p0YҿZ^ԇK)CjI\$@o_e70$oU%$9o6FD_My:DWZԏKkT${α/RB ^vyQVuI/<"羯@icyjM:/QX5 tmzLw'.=J≮ۯ@U\9: x/CKZ+?7ZQ5}[(qiGLslfu`kլlXpѡ5,ƾ__M`8ӴH['DD]coz%PD:|lM"ZNYƺϕ$vŮeJU[Ü2$ְhћt:gZk:Tة5{P.q8g8i0dwHjtmk\'v]EQ!wdϒ33 pCS_IS\˕c0!Nm;/ h2>r2(0ǙԲx)ƞ]p,%4C֔w;e %wy)}fm.aӒ9\~*FM3%a?!S@\ky&Pwh5|ȁѩ0;M JW2oWcp{Sё^S4Ұut7~ $'x!qtBr- =z 7ddwHzE+Y͑>ƆYgFĻVtt5e?fsڿki ySJ؆0PsX3ҩ.r#{P/wz@UIl-zN %6o~I$G%/Dϑ̣-0M(I`z:fw1kS|A^#2vvs5gl16C=*5㚟/bbwpDVFIn(v`r甸Kp06n8P-WcpyqbyGpK‹p"Vog660-lKTR:f'h4:^3ʇ2f\]`z#?Q,\yl*^|,(.z1n,ƹs>T= INFP >}p2`*uN'&j篁-P]9+4`SW\ bPn (@ gL % %Ru#/_(Bmn%+2)RRΤJ[(Б̙B_'^w"c&!zhͰ&(\1{spO2>Dx{oޙ)r|yU d&A,J{ҙ‰L4lY\LAn(';|BB44;nD CYh H6c?ߢVOB_ZNu?b}*~uK" ?{rw95ߵTKCzR˕+MdkW5&<LHĶ#X<86S* $ĠncbC@*@7!x,XPԿK=~D EJ"LoOn @|˧5~ճݘrd@Me2U &??KNxgN' Ew{(wx"#.1wTCk4+qA3 (m*]ҩZډח"DYUp1ff&E{30 Ț(~򳪸u^@=IazI6x56&lRʐͿbWgr֧tYS]0=R61mޭHNGo W ܱr7>?SATF`Ia2TC$צ%lCy>`yɬȒ@A&rv#3Rvf1dn9Vߴ#iV:O]MAX.C9}?9oJ6N>"_^<+[CEEGI wy}CAe@tpЩirĔ\ASdNL5;܁lHeA FےSCw%c;\+uF97[@P\/RL3  ƅKV6噩up'K%aD},=RX͇Ïi."uKNWDhU΢޾"?L`uߊ6fۿ5ò9դ͡S9kv.m8ezΉ{2LHIFGCn *>X& 4CuҪUn#Jle%+P]xCnqyX"|. q(ʨIb}cD%U. 5&4_\55,9>[N';$j'}elT@Z/AJ9VJ>\y֫iUsCAp!bh,&E<+'%njy JaUFsΤm<@u&MXl!kx~N}1A; i+?'sNdo OhbYlQd ۿ3k2&ym+|hŸʈWР(:$@Ki]eUd;j4ȿc2w(ӱ:zTkop 3=j `s}/4jdeoqN^rf ᯙ*q!t {dІ;+.2v)l]M&p2zQUo:bg+|{xբM^ M׋m!1Ka޳DoIJJӸ6>phoSh q_nj*0)QF#uƵ=I` ~4CJ{僀,} qwmu^@_aݛy8^b(ѦRʌdiqsR{W.H}E#nd r&1Q4 8e'VXA3d.`]_ *Zf Ʃm݃hKQPQcs CS݂@vwD嘙8}w_a-u`*uH@Eu9Mku1jYEptM( IOmg#` ZĚS7C4ʚN?̫X0qbp 'թjwC!K o?-FJ&/$H)ݸqV jU\zz1w =4e`YȕJ0(. 6 Sѿ7ڴe0q`>U!i4ÆtPN{sݹkdXD2\IB!dGqSf' )uΔH$dB_Qogxw&{R3D𤳢e@H]od`(@:z`yxZ9KCKU#΀tm<37{'`v oLcr/ oi!H`LRqMŨc&oz1*D`=i ]\i;'gg6@A;'?,<QʝD3vc}CeK݋iv:laP #6lRD7&zs[}z~20` ޵1muh.#lNS {OP:ƴr4o@^n)q!x]Ʋ!Y i89tybV(ì _v/oIhNOC9HMѼ 5خG+RT4>S >Zt|ov7EX$l*`t5d~k4W!$ާLi~"%J[@ݑKb7. κ8t{<}w ih8d9{@? ccYK;wJO)AlOqkQ`g\*xvwJ+i/M2Z'G,E #Vex8nU.?d-oJ궟90QB?@ޙc{֩F^ó%HoIjOǦ;Ռd \:+˥ =Uv)+H7xuqvf%J7/j`-#S>+i<@"U8) P谏խ>%θZAESa}Ӽ[zF9)'o/Y1L)_r#ڡKϏ<\J xqK CϟE4 |q).p?.Q|j76ԁ[|.x(*w@a,<<["x!|/- @Et .L8%w^HY̳OG7=2y N޲#&؆5eɲcmc^TFosm8߶3-spޔw})T5RF x "6 kQuX\ٴ4S8R'/h%Ebʣ+(7>4Ru,/Vѝ!xδKFC?aZMfO( NqU۝ZJ'l⡼#6V.LT^ "hEfĭђ>̧P轡L9+{$$K89 r_jeYz\3G[(B܇@t{̀fy@49Ad%H\r鸂CiZZMT(C{/6=+2btc'Ss3YOLhR3_".sf8{sSJs 3ra4S}.woW_ VWϸ(UKcWWއ{Ca@$B,|鑁SYSjCw&$uEtgCcӅo8vl͘!ԍL{kEO ߖ0-dw+S+: CObe+߀*̵Faf!H>2qpOP8F Z5͑W JAQ1 pܛRF=}Ƽ*DbD*?bN? o =16Y|[](\QVW]ũ-i䤰OoX^S -k? Ù7'ZuZ@ > ^>WwC)?[5I S+3y`WI w [Q 1%KM ,gtܠ ƅ`5oF9;QҐ`'6R!p": Rf@96Ft8VGM$m?vzo 0ag*mWqxBd_h VMx"ޔ޹;*-KS bۃR\ƠRjg"2O C?.WKd)6^lQ$ b8 R6ŋI<2u93T{o|YPsV& l:xy$>J!9|fdy }Ю v2~<#_! K+ -FPc !erhi`I/ј9[~8Fp[dzSRj4J;UnMF3{ 1 j.u](08c`gѲeER hħxNx:{&jusfנ=l42hY _R!GաĹs3$>v/>ֽKe kx!CLaw YjF xuQ, o4+GVrpH%O| /'a.+z qéuwmzC!qI[f&qNƾ '%p}x{-/0Ϛ=;pC@^*,xrxuAj+UXcKe -?q_BHd/t8Z&TbXbr0G+H:}փA25_]gƤ9 m' Y =ÂH^G|8@LUu\~ز=+t Dչ< s.s4k֢(*1TǷvA>#Qy.sx(.xQ"{+Zį_ӊjKysg2x*Eoō|D(Q6F)v$&l>=d*0n4Џ 9$ܩr;2+佟v%"yԬJ)r?~uz΃vӴ1tINhF*Y9 i ׆ L^p m_P jݻrhsR/r;RZ򖖺FC~X yU$_9>ZzjG< (h>qU2d+C['o73ĘZTH,DhSdbxvVtPKn9|75D"~ԂGniTT(sNx|Kzq[R0<ʖ4Či` 6A'Ǭ/n{ JTl%ϣ=bԧWwVߡ'm[G֝ (wiO% q}O2\27DBPa z ;6M[Cf墴bJה j$T,M82ԄcjPz;9D}C.b'p2#UUej 3_RT&bJ:V$z mŮYܦ)TiW-7/ۯ \=iƒE/ FǚlPp(e#HSKKjGJ<ߏ]r/,sEf:"4#Дڄl@%ڨ:7߰|%L)r75D  t[?MlRF%a\kʜ CKkuACjN^ze ueiY@8ٲo'Y$:X/r:Q6# ^.{jx+J$]ɢ!|38&cR;R:BIZEr2/6v\vȮ|QNPlb^gʧ঍cVC%28 5}(25[*t& #q 8vb"  ebw oIva[,!U֞Z/9tT"<%h,Πw-]0nmcFo2Jɬ-=@d3cjdh YSxH~݋KIXkD@-M{6f]}'v%n߀ z[ԾWI*&ΧWtw'N{D \}9]tQBҜ הvͼeXUeOc^;Qemzm%_ %5f_1ŲiX9N uN5fm{EAȧ0CU uB_\q DAњ=E458a;ۇxN2c 5$m_+-!nSjyu4o#?"v[[?Wθ"iJ|:T-+meS.iUꂉYQk*.FHN.hX2`I)SŽZ!Ws33`E0ƴ .IA@tFձa7gc`ʑ]bz?Jn+&^ J- L13m:Ȯ(*OkvH=aQZgSyjw{>s.rlZCt{q;ZVDwI@dyK(VRkϣz ǭ2fzDXh5.TՎ :SEMId\vQ/au<S8 fY6u;K |{'ʗL TJZ ]KhcAO֣V7~ Q-ݣ\=c&D{>Jo BjvE@L!d!$*"32q'܁kXny"䁘2$hS]7on]s 80]`F0vHv5bc.N,ѭ-jLCA*bEJPX}Z4T_pAo{$53$9^a`X~Fˈ|oj6wrO}3_ao9{ʱɬB`/ueW܉G6e[ܥnwP{ + 3ʲm]'K@-az  q \b"+3s(guC>&^dyCC|4`:oC!}ـ=Y۲}HMeA &Ew,փ+<4rڞa5.e=mV3R+dz~&[ɓ;bǤ .WN0gK>{el mbxmF;s7jE +GQGt_pFQՒFIu>?j`K}{z$yJ2 A8EkKdR7b:`g/M`$>RG@+ i~<,PY!$EM Ў-N^D<:Bʀ{]Ù~GdSIp/"CZ$C C,h؄*XbkSn%e<:B[#`4`5UBtF;;hA_@AÄ\,2րt_X1@ ; u,T N=(͉FEDW@?jzFx{c20dhVmM--f?٭kS| ٧GbTFώaĬSۻ2U(`Al~`LƒÎZ<ݛ>uƈv a%ʤ;=f>s0I 0=*)rtjD'پ% X4YKk`@X*ih6_YP6>(⁷'#IqyC_ZS҂2e"^ihͿqr}~rYCY,l´Nzipwzм0;XTlG_dlf2y0)(>upe ܅~idAʹ;Y?rb63*E!# YRLdL1pZQ$>Nm"a8Ҵe|=H<>Wfj9nM\{czy]WEKЈff=sLYl aWx+/:0)튤X/H=ꭊ~~<.L1Ӊ0/<{ ܵQ·J!8k&|~9PYL희e9Gt\8\W_W^ ?>/D/:v|eRyI1O~nφVx>$sA kf y AL //VUr &0mZw ]u՛hۋhҰxdPVOJq.ƖVD8H5RO">>/6mI*\EBjŋ\b4iFҗ8kT8'$VP?j/(4h, NOǑ/Q'egѩۅbK#6 1Rb]>R`vGkM\# H"g4mcNnI󴇱y4η}6eA%2,OhgvuI@IlJ?eKSepm}1#ڀ[BU^O~]  T(|QT6[[;^fMy|2T/X${}>܊d+Ep5y-&>#2.]/oax76_T+;쾺wIaދ#ۺLcm&pV]T .9/Ydj Fj1m@%)?#?U Ne઩7|R]J %)rkoV>b_bжyx](҉*!~8O&9[ge! dQHE_Q{o~0_&g)k~ hʊ=mm!WfvcPk.fr@'Ѯ'?ݷެ7Gk`{u pl*@bbJS>LL9#nEwe\1W@~[oJNRѮla6&fd%*|xSໜؗ  _7@Z-W*xHʟ'":։{B9GN"=S5"yME"h9[=Uv {w[]iVӥ&+!av$SL]ne UXuqQx@ ܕlZh v$a5?2A R:+$]ZVHL@/%iC_ƾ373s 9bϡyMbƠiEGzW}^TޅP; Aaأ`"*! ꀟEʞ"R{V(+9S9x$9Lg3)_hЊ*oU~7݀ BE6jI&pt~&v6 Qh گu^,cW'<&QjiB"t xPۼxj >f¢37f9Rm0 [SO!1֦kX/D-^f#yz'mcTָWsi ?X$BHYr : Wy r Y>^jq0b@>nN!-WRmv{өkD=e- <=52f8dm\ A^k7jGPI.E)֧m0;$T6 K(4JuTx&SkDO#,MRccSm }$+PFmRW!Lj<ͫbvm81t9XGa>)h]Ye>Qcny['B15jk-pW }JXX>}c~cR]{-K=ӶTZB/Ir2f5T l"Tu crҼBkxW R؏odw +-ڕͥ1U#rV3p$ be8.JB\ | 3gdTeP`'~8qk(5y GT.`7ځ9v>Cw#Q νpJ{c4XjO7raQxAsÍ_=RU\C$ЈHD'4\M#^l 0D&@ar xj}Rq.S}~&X˲&T=FHDb;1rCD$+huF[! zR MQt1̌BpFjiеZ)5RR5'C[dea(pLSibt4@ܼyRjYZTt5Vѹ9; 3 [~̜IwE+dY%9\4.!K`#X./2yOBm148GWv㔖^esN]8*Uf&Fץs :::9Pa;T[㙲CP\mBԕ0l4mJKUTk:<|WahԿƴp t03R"KM,a| zDiJ}e[Xk3s#NZDA(](>K9^A<溌 60*0h䨶/ aEgnYb[$X/Ùkaw&_6bXRw ydXO$%ቫ21-:+)24=J \_yNb5iӓ|{V)+VoY=V1Ҥ23?iE y+|D*u٦sv_ `2",jH6Zp3p̆_0KT咈%GtISN;t(W˫$':hE>>C{ 윿ΈTb{}=zLk2Q[5޲" _C!r̭]NHR4|Sx:8-{x$<ʥo1ݻfr` !"`M8t'Q ^h@ٗvf"rճ7^Ĉt^Oq=(kٺS_#EMpuA$OWY{zg5Z@Zm 3f)QfXGT_Y&hqb@~NxMjq)׈Ylp3cZVkGN{ASiNܶvcP;d/3J1ʹUJӊVƟ]b'9Ֆ!%>UrL3޸h4AdFCe,oӴvS:Z w#t'HQD͈CQ3c"i$ypum mnf!?VrUKR)՜E JmdҵW L8% |c#!HDu\&ӧ@VdnYC}̺w)N< ؂!1I̾`co3ۨd3P6#jK%0H@6tv@Ι3B=b{:F2$0G]'r䙶VkhuMO]6q60ͽ~E/w\Bv\QAhn9KMqZxxL8 ńT+җaMql-ݫS~'X$es(D_*I =2C M'qUCSBBu5mJ 0WF0hقxۉS:s!)R`yLH"?͂3XDv;? Ȟq}þ[ K@(83w|Q葎R)}>c>:Z<#%?Ӷ:`d܌A1 ~O@򵯠.ceFO"Ҷu-X3"p+sjV`;N+HVe?\˹TƮdl榛*i4:H( i}ֱ)\i9m5M]& \OT9BR~Hpr(AERR1XHmpO5 3 I7 RW0»i:<)$G+dr8k,[LRf)[Cx4Yюɉ΅CIĴ54 0K.̅Gj~,8ȏ&R*yBNZyvڸg@2hXEl(e|Ci Q *<)#r5#yJcCש~> feO &jN %|S[eZam fLITv[NbƗ1f]Y:4^㐥:&XD5|9w87޺rC.MH-? c=hUT2*V2g$+bi_s9XNtEg&%CD?3#O*v !*}SJnz:%9w#cj/ap8oKY86MV9[H'_ÿJǝc Ur 5ZhTEI:kQ[8{(ԥY4D*iPMt 5dً{?cf9.RdSIkJMTC ;< ̆ޓ!pօ!bq@!>:ߒfۀZWbٯCHXܬևq|J&F q3CHDd<@s7ӿJYnV,;oDy QmQ_BnNt)\7jI .Ma"X`74AEMFy"ChboV4D֛#}%iٛ6Kg_Nuod1XŃdE!0sJc( *:hEU[4 4gMoe t"Qgx}FnO\ q#$`"CߪGy^mܸo*~@GUFA +Z r$䦞ԉOjK?X >K!!Txp2*( ̎ ްzz"6r  XhyzEF@guu2ER&oƝf,XPI:;) F ZUgsd[v4eԲ#= +Hs뭱?WX&xndEe+oF*<ڔ㇎Iv_fcN̲`$ո#}x`)F3;UP-5.dR 4KXIRc;_Oy?pmEV"&?E-[>`5K4,ɣ9vg}+#JD+MfO9%q#}рx:n~'٬fIuh Ak5]؞dL?.Vȼ/ {>e-gzd]?!_2fÞ2ډS'з@ 8Rs$-swvk]}4of@yh:$ RTZCA $B4[l/N't}"b8o/qQ:['rm&D@ΰHܯ]>sػk}^$v 5x-BcAo=ޟx:|ùxdz$( u1Na} qf8M&hڻ{@$M!#cwR6y(%ECM[0W=ΉS5c,wម+ "KA|=uMcOpRgY|.iPa;9K~4)᭾i88AL{P.n/cy >Jᗁ]tDMd1*{c֮Q|ςRQ4&7ȟBERy~=Ķnx:y7C1[@`EM2"J`~PI&.Aw氩$ֺ3ɑֆaᱰ7O%1}P Ot2F)aC5HӭGr` ip:IMejae sO(B S/]jkLK[S3}@ c ɠHg0Mhe ùèĪ3%}ΎBOsoaGj rS8q#l(顐vMll:E(@%tԵP.D) T/H+@ckT66D(d #I,]⪳o0Jx*^ êCx^1庋O0 z-|b$(LuEASy0&0eejTМ-F}[._x=xKEHM^} ǻeU`(\/4%u]rzDM99U#I >3+eƘڍRHa+NҒ2]35b:FZM>]$V6I%W[ɡjSE+E!G7lle$$i $v8? X%gjů]Q3,| 05pO[ï#@bNm8Q؅A4aP`=(Qv.F#W^_Dor|{le4j`FU GF~#2I:rGˬ8l<7--#lmXmDWN,h@dO\eZBR.P,N:=]>bxSB}ՅԦQEuD_E@t4Y-T(h:akder_8,zJ=\[JdSHcCs憥͝&Mf?,T>HnmD-Ȯ3HItwΠwdzcJ{</Y}`y$75` c=d}ZՐ IW" [G2'Λ`d\$A$$+?\B Ne-:)Ww7|i~Q;f]B1mHJ) |T{8)< r.u޻Rp$=ps ELQ04Bre./z=-[0 i,fWjv%'Նi*}OQ*RKe7ɪ s>(=wx:.>ULGpz+=|a|O@0S_n4ǧo0'*ɩ|\n)]NB9juP cgҽ\D$p54nV/ ia<gi0I8~fS/Í6WQ ejb>2pfa;F(/|ɸ3N Qzsū=!E޸jb^|nCME[71 % Qc>>kOʞaZwk/684W9XShȐׄt&eA(;S&˒c i9) bg_i $,, S>n!/~I yЇmrJ~&຤2շj dם;>h$0] {T!*әkvlvb`&<f* +6P.FCbVqBz ]L[g4dӴ3j-YŮY;E^ս{wf Kח[־&/9 .W;k.2jT>C̀0]-)t[F@ۀ[PZz8Cɶ*<\,!BȶpZ&!x6(bx2dE89LwV -VQwHrǣh淜`Z{y/k ٜQTMk_C;^J1Q<#/W})6/쐴l$ޙniCbXfvm+kJ0ko)Ũc+EPtӱ.U+[}+3 ,򲔍_nwz߀9hwd>{H~G@֖m}u Q;wSģ>c7EiE.{/6+: 'L @ΌYe~#W v pW4(v6@H@̯7Oivh1̅g9dU!;@;\񽓪Z"ي0 f^Cm@_J^hS˲JuJvUXvX6Mfay4-9#*)cħ{Y«i/&DH a+K G9(q^򀛏y7qמs*f'"iq3 *]Sɹ 6xnK =3̺}CZ 0ОuC&5mObϤ8ZW8 h+@[5vCMld As]]鉚 /P 909H4 Od]6{ qEV,U5 p0JP- F.[g#!yRy06/d ~[#_C_56?U"k[.vonGVo2VOg|;ΰ'<4-i.$ZlnSW~1َSj]{@4 I,8ʳGG2 oL\mq}V 5Cev&T|.|,7$/lNG",1`TswNMy2^U\kj$̜/>x6L\]dUĎb3v_r׮[TC8(z pf׸Qs [vD#+SIR*.OÑ9;"8ˌ hZ"ѧ>¡#C([%!-2Ȯ!nd HA/>\:Q#Qra/{7w')X䤌tKJap-XX܁wW;ɟ/@}ə\oŕcOҒ~ 4jzQ*H 7 Xv+NjǪռuA<R X}p`Euo!o&Dv0R r4"';J'ApSOf>ΑCY^4wzoVFj WuuTU콦W;`m[sL}V6AbUM!"$Pq췜|%].Ty$SA1X蹃ë-&e9Ru'+ʧ؝O(v<=qMڔ!:V_H=nׅ6By0EC7Lʺ𩧗.lt4ܸ0X\׎mpq=ۮ>N2H%Maٺ(=>bMs#ܳHhW߃C2y,Ar R@T )8H63~lP8.WohwAr['x=Ë-@~ ~unVϼ!zCZB|KyU ٵuB HȸLw=7,]1jBB^osG@$`mN4, bU˅FXI\dAvdUzh,m4vѠ0|]=hhwwDHO2 4sӭNC ڭ…<ٵnmX̾AN2$3VIr]OTK0*qGVll53 D݃ԛ5Fn{XNTC*)3}$:`9T\VHYQKMP UWo4eœWڜ냔+չqW2cP'4ߛ=/VӒ3kR`Mo=b3; mٿG)DVT,/CP*LVR ^zlԂR-7U.^2ɔ?+-!rެcgKMpŷZ#0&D*Jnn`fsլTlRt.2OPдfsY*VR!GcX+R- KB6q< n8Ǫ u湘u٭ >,MP42)Qy/ )DGQ]^R[WJ\k3=Db I^965(w;8BȓLO<݀'gw,N23wZ^*vO ^O6B8f"bVi{DX+T@2#y="voT3U1׎!ق3%w &f/JGB!e_/f^U5H' =;Rŧ%+u~pgc |zN48S,Ul"ԉ32b/椡?VHG:Ž~ttൿ#hUXR 13憘Tz7x9n4UlOs0rٍoɋZ;O' 7!{ |MH˞%;x~dMtp[rB(Q JC4oa6(ʷGwGڼ䵅]S$Z:Q  QP[.pBRG9N@gS2!ΆgpDZFfze~ڠV#ɛ'ۢ>2*qq4, p?d\9Pu8o<D UP#ބѮj[ >r bF۩9J!QL2#܊&mn%8Xʅ-a'`_ъyO>,-%yHG/ڸo, %9 "+*ZP9x|/z'X9,SC$4X`1ll^I*qPFL2EO?M+$CwGJt5[4ʠö-+Ybl&H98B=gE`eB0O! eF~M]MԴTxWP>RCqlXqANG(L"'D&=(-hwuI5^j2|hm'6P2Z1k7I#+ =3Etr\A \Sĺ9VjSopꄤٺk(oP `Lq,pkW ˕e t?w6v֊3w+6D[wF%C (D2A0>r7'aX8Ai0cF/ɲF3x_f:Ş=k>iJjN;rH 0Y5K\Zgφ_Hj| "/b5U)h,Be\"P| fNOr^p?8ʔuHRL^6OFw>ze3u/ߒ=PvȄ-SI1:*U74FCRS6ώybRК(ٱ:W?X c4~?*q$|}mp %;ȼЅu0 & 9)h6RD\VzsshFuְf2 DJ4L)r\XN^Wx;O }sJҙ,-)ÙcFe yOA_wB:*94z)VnڄOxRkCDE˅=W!UȔi)*K^9\r Ȱdpp2QjK3zNmK`G~bVD?Sg]n2j1h9x w@4c 2, ^X2DA| $g|Azミq.̺5=߱, .\B&z.PKJIxXC (2gp@{Me2K+Z'B0w0&X,;DHc2T)7LaɓBnbܳk_GrSE9: 5) O(YP]+axUW;oF6v#z]1ARù HU7%_IvJ߃C^IgEɋo+EvmL^ɄnwcU`sh7 _du:X j6,ri6l?S$mV̐C^Ojkf׃QuRh#qNܧ p\ljjb"[n aM0C*.39 hGn'WuMm^<X]9ۗp*A DMGGֱdjܵ6I~|f8uKT~H'm %IzOEĞԿtb"P@~8l|)1eUDǿ~9ۨ .$+`b 9ݚ֥<@*|ki/-h8X/rY`o'[ll׵>]zH`c]`1hVtLHZ= k!wI OXL. MA4'7ٜ4*h\ ~!G} 0HJNtd-y@:c:04 M rN)p,b4@cG6,epm–eICR֢yQ|2uFskmH:lQfEZᐋ?R'=\']-L껈fDYGy ľdȌS{ l쏝aߢNI/0ǹE\O9XVt^Nf=׶>DyBqiWXaRtxR"Ļ#S04bUU>+4 gQpu̝:'IH ;i_Yɔ@3z1Xi@R 6ؕ:Cg,؆NV ]M{0i{^Cc>eL}ݱ iwpLzKZ^; UƒTp)+J 뿹 Q XE>HJaAZi%2;ߑ I:kMߴU ʮP N> ;6oG3O{U]dH:ñQ5t}̹Gba=m4.jTN5 Y *bCi5_N/r LWNҴ<;ms^qV2}5eA&hoz'$7{U/VTtVnUF_wO',q#Zcb -:Wfx{;C7GjيL\UxfbIǛX=qZp& ?ݶ86p֫ =Nflݏ*6-ā0-`?;ҀND䀠b$%;q6^\U !b)xv#SedqJJ+>ڱo@9eo|1tKŅ16J5f{X03Wl\&Ow[f p?B|ரX=3Z l;a 62?Ηw N p\X\CgB4pER€udFH%rxɣ Y z* b(9-Eƭ0!rW}ֲS(>mcmuh$=.͙+W'T9wIZ$a.ȝP޾ ;@*8C';t7EXy_E=2)UVO 1^9=4Շ6jC^.N0<僝i*)L>F|%#4}1V;D@*Fك~xN|贶U\MR~^&f]Alma6uЩ0WaMS79/>m#̆HKuC`l] w;H]Sa(e J׺Y VYs]Ne)]v#(ظ9-iœ樂Q/y];LBj wQ*_^@h(׌m @܌mc\To8OxT@ @̍8]軗 imO+2DX%_ n\G('J{]'H6Ȋ9d Aa}L.skpSG'c,i䜻]Z`m7\ro9+8a&ʔXݝV~㷛/؊ׯ U\qG}}YFїk+"0ݻ+ -dd#̨wVl@`.l2mz]ou%LBjك ;J"@yO_J1nZ}CLih aVym}ڝz$ܰT=XN$OmGQok]S;-_QpNzǵ1Fˡ٫5k hu&y;5=ZnpS crdFF:Cd8Yd嬯ܙ "KV$4du+Wz>K&'BuGIpm[JMyTSu9auAF5'36Gh/vd&v+j:<3 n; ).`rbmG$8c;,2_"4? {9kh-Qy+J( Uvg0@&@ElkzqǍͫч] . :8lpƸe{(S!ulN&[D+ q-9P/@1um22` \:zJ ۦh}qgP.n2DwmK;!dԼlyhUcMxR 5 lcJih] ;Z o,uS՗#݂.ݢ -]Ɔ0H[TuO4N*!_Ue13O3=@Q 4y6\kōΩBȎ ˩;!Dw1!IP[Hۘ%VI ˔SϦ~b6(4;.P=QV'$)x~ [ĚoK;1-6Q2!5RV.RnSA`N딐VEbwJ G0Fl HI``hbh>:of_QMGj{{njbMU^HK dpԞ' LmBA]dN?P¿nIv2sY/! ?2.=Fφw`,O.-rr Bf~$ .7:E]P0iLZ~%}N7tof0Gl\Ԧ _ci$0adV2G؍׿M@DLp-+Wܞ] 8vG"51oz5WZiY;d2i忩g<SvB=Gbl0*v;-d\FmJeb"S7nӭ!@QɕOH"UY]GBĻ=@vAӃ Eo)=Nyؾ*DIwT8ty?Lr|-TR"߰P4{;_]~I-I 9mqcw?1W`ȣY1W,;L9[ukI.7yPȰ<]0߈؉q6`d#\֋.CF/Ri'OUHA6;_RaN'4D eku1ȋ NjZjDUd#9frRw=Y V-vDln>SAٲ{`hu|\=L*\N"~Ej])al9~#? ׋=o10/&x+70#+I7%#t\|c yL$F_mfd=eo`LZf9,r:U@<" EN=r dA>|2B~_02^fT{!>w׬[-bT҃6:* O@0,2{Jϫ3M^e]/4bNRM ڵEpMn!1&( Duç㣉}%]BX p[`Sю \p;luUAs_dNEt7Dg&d`DzQ q_歿e"y5P׷#9+Ҏ*Y&#vjQ^L\{ޮ[ʗW 8Ը/N5KXn)g$z}ͮ#ѷDQ=0 2 n!>.ܺ{ɝ:+1oKnvh)%>|1ע0s>vAOwЩ3ORa.& m;hs:^r;}G6*h?xj3wpL1$f7En&(fc-uq(tOWىo,0ƴ^Uu NY3[+r$B-#SJCNvOR*)FS*g6u#37Jp"8ܰ| k6ܘEV4#3 R#=rrHOav^ r]svߒl3ҊMx>,EZ "g4&lEyxQDClM: |]Zp &O7h. +@*Gz8F;=rr"/F:Is @/bLL':9_G~aZs[9X4l*'1;[ybJP (hHfy*wrT%Eil>qdHu G"0 rY~I:2XS$2P\77y" =$3y "[!M6*Gogbo8HCQ(dWm؇ |rxSIb~}UHwXob>` R ^J,JUU\ 1ls}t<4Hmps[#YC|\wWR)5e1&P z.ق[^Y7o@\TNL/CH;!5["mWV^N-1Tϐ*7_7aoRH;m]2>D.Pqx1XdR|Ol47q2e]*'w!Gt2E2R{*I,i܂=G890E.]HoHc9[[Gn?`@CDRk)ƍ[RCe/սڽC*k-<ٛ99*ST җ'!ũJ~D>/%M훙wvޮdr׺fݶAub2Zf㩵I-h1^5;sipƴR @4k'R@{vۡDSR\b!x {4J# Jj۱!*w#V'9Ճx#, c8XƨjA:39b+L@jq_4pFN_JPĈ to:xNLHJ?p5vGpC@TfRsIuKܢb"3թsZjђhCC[T7]`i|e pc%BaNd}(!w൰Tf,&Eݠ=`U"ۦeQnIt0 hI&λ/u!.%Юzؗw|O:/3 {|f#yCE1q+Ù_{p7=.446$[2֯Mln%^ /ﵢ[~u])10 kדZaBU:KŻ"ŽUG螥=;(ݶ%߄bBaUb\w~FGB\>7%5噤TSP4(%87|ai^I{[=U=/AM#l~ X׷+B V >nK禚ٴ)KTS؏{y}(l; U>dI^8<δh//HhM XިwJ4kZx>N>r}KnTY'|`s=bٕFw!#R(7ɚL(|]C{w^Yr3sv Ie<~[d<>zμ ܫ(NJ0Z(5ܡy)ke :X xZxKȴ! 70բ A`>_-.?кqpG#'fY&Λ2?$˓TSq >Ta{wK}$iD OđrZ7oʌfPޞ.[ei%yQ*vJ-Ce,z(l6M=S0]wPjFK+dۇ"4i}P|ЅblBEQ=8p~!{LMF|? &Kp#qB53Dć4Gt~>;߻ < Os w O^E.FsІCQօTvi9*2N_1Tzs`Xm,Gjh{DDD 80ζۃuԫ~wNgt$]w-YS- y 1u}z~[~r4}G$%pk"a\/tHjF1@c3z*o`R<`̕YLz^dѹu*0QD熡xѲs|¹{]MѦػ9ZPN}H=ZR70]E^][k+~7ŹkYID'f\4|Z!8o- p:F"t;ב!Eωly)B븁 HkЩ ~^ԝ͙tZCP'uqA* ?4r9x piҌDYz;v k M-/ppI*ɚt"& F@oJEIC!Cu1 -п̺A= if8?E;U9 0i{Hl+αFXaievE_1AdU*)zE5L7QEOa4xH=ƀkUagې"4~^gM-0[{mSPÞt$o;Q3iu^NmϞlco:/N.k`Ӓme0{d *\C ϼ-B,X(-C $s{˭ I=>Q6$,n64L:~g6잏F#p#Kor{&S"i|J- n|+yK(T: o YDϫ/]wnEe7ВL萯/z_˩lCr~?~+*5T&?d_[7Wձ<*ɢdzHbIVD-v zC}D{+_/a6'RVnkdX# ܦűiqQo7# V2)NB4C;i.'FV7/ΧJ׃b@g'ʔqƹh(ێgAX*2b8hkK[aէQ|ʚ #I.l]J5^RV MO*Qhe Սc+jC:ȬԦpN΢<5$#G{"Rn!g6D8T^l{[N/=è0>&֎$p:ElZnh`Q9|40|cǝy&r-\^eW27`| a>ga)+JAohA{V4 _xsM,ij6LȻ5+Ib$c$< |fR+T' |--uGbN\鎄A >^‰VR=*tF9 in^f`w\]dHދBWccagat֥Jws3s7] AE 쵽I @l aO###.*X$ gYJ0"͙J+. @ײ-zMP%#wzwƏ;}^"np @613mYQrǖLy%Q8iwa8Y@.z>UEm2E8/Or@5~ϖ#S['om>A|@' 0?: 3_c)$~s4{35u2h,&Ϊ u0Die)TBMОQvUFڋ2a8ֱTꢳ| =Co{$x—(d򪒲&GE5`AD^ԃ|SOWX2v6f\pr?2$ JU)C8$laj%1 ۪QZ |wX| JĄHM{S?-\IȌE<ե}ou-ěXX`Q8 Vi3 i(lƾL\~:Η5#Fvں GL\jIGLGFGYe7E0ҔV4bG# GKD\=!ib^\De{k>&~MV9sX_3:]Iω^=$,׊tv9z\ϞsθM  ?fc>0+ ,Ҹ^*2R"jccPx:QTOp"3jBShYj)?VnA(kZmTPpnK@MͤdF׳@[T18,I(v?M!cK0 H,4sD.DGAcOw "91  1\v>=Ih4\%ja9'P=kTAɴsy{YXmڀ.~;w0@4FWx,{Me[.&1?bXT?@)&)` WRf!G6;?ya_g  jq)hU*];.g`*BC\.1Ѐ{gBO4g-?IhOGsTj3is!Bv\L3!g AJ&.}Bv`*S^`B za2j|'5W._߂K7]5-;C<4t13~3zh&:37bvy0 pzk!Ckߢ( AIw-`H'I3o挔|#kD| |O9\xީ؋rʛZ{? Ʋq+ǛtTrLTDOѠa\A"*qwrs10]KU3R,QpjXǶmHl RjL$z9ur&.I2 v"R*!"IFaAj:}Ǩy[ƩOV1V`N)Rwd>zX<!="Gj>H!%9AOD_$'ĝD{`gP@ cT6*N}(7.&Hd̀̈́~*TDDZK/t8*w|<@fFZ WPAI\qkoHi*~&.K_h;'$E c'/EU,,RX l˄ƙ +0pT"=M_ _ y'r)"`McW 9WCċ~߯K׳hG!})vm/O4xbiMfNUu^"$L=j~{wca!88iQmeZ7Wl zTC(ao7R␶U#vT^dG͔Q}PqЫĢq%A8(p6 Ā7~>~sөoE5k#8f2sc^\sj-궈cxwHTsC?ikT6 '/e'*:tD[͒\kgM35So_T]UۂQ96\nݏ_%K3WءhS*p% 59+i%9Zs?|siknWq[[w @f8ѵKIx纯*%G Γ=CYE^uc/Xd%MLſb >|ŲFeRoԶ$Yt[[j)|Q!b9FZ aHe[^Ae!i\ >2|fHz6Na_#)(]䪏!u/!?~~9nUwXԑoF:" ^=TzYX~ a]:+^,f{9\\U"ZVdѨ2&rrE-{'-~[R`6zm;|O1IvS- odllTl ҩԴKu s Q2gy:]KC+(#O׋w&SIJ5D_8?e=Q$J(/zn5c}s%fi |U]>X÷JKK b%Bl# ^68/q\aDP7O,7oH% I{h{)"C Ec_ FXvBIxڤIgA4ht W l"PbX0ZԽT3# 8:l`a⚹\' , btPV('W< Neל%V㔡7>N[Փ a뢉!zُ6BߚMyiy"@G2.Uٍ.E-[3BA+5rg5;Jng,"6=tb%”cX6վ8܋l/r (*c5 kq&iqXJ jZI?E[8ЊŃ'z K%z6$ ھ9`K8Ž= )JTIј@5%㎸ÎVTחKfJжM[8\*51bgK%+9uOvl+Cqi!?nV4^ǪD : JSYCfȋ+H?BK(K4z A5 h *2H?}dat7*F#etNtfX;hM<0auOoc9p fˤh~ڵ',i&+U&}8 ?_ In i~ma{ 〺*88o 8x~!RBv ܠ!@9xOȑ4H"FijMmFn\m y` b7rA' gAՁVJ%'EfQLazߣA~{bC$I^8<<8N?BRoKuUc'}b!o?3wT=2<&RKƁ4_ '߽yFIar(3gǯپt$qphxJ_Ņ 3`,ҝ)6K!gUIcJ$Wl#E1g._: s϶ YZ