krb5-1.20.1-150500.3.6.1<>,Xep9|  A:F?d  8 .2 HTou|## N# #  # C# $## _#  0# `1$11 (8 797:7>@,B;FZGp#H#I#XY(Z[\#]#^ bcd eflu(#vw`#x#yxzHX\bCkrb51.20.1150500.3.6.1MIT Kerberos5 implementationKerberos V5 is a trusted-third-party network authentication system, which can improve network security by eliminating the insecure practice of clear text passwords.eh04-ch2b-SUSE Linux Enterprise 15SUSE LLC MIThttps://www.suse.com/Unspecifiedhttps://kerberos.org/dist/linuxx86_64RznHXXXHH(8 H 7 qA큤AAAAAAA큤Aeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeefeb99be24124e1c20ada05ee588f75fc800f13286cefd525ce7482b55dbd135d680a6555e3034646f026e9c4fcc63cee0fde9d1c7228aaaeef3ff1c625fc0015babf1d06ea3a76e3b9909faa00e4a0a5c4f0e82447efa6abb3815273d79362a832ede16ea12d43556f40d447a799eba92916d7064ef8b32495f193ca61a77be3b757746aaab1ce04285be8e8c1637da1cf20e0f54fe6f1db8a8390f3388d7822a37f8afec0a584a61ee2dcd062aa64074e7a60762573236b6ad1e0242b249fde621d70edb6aa5644e75193113133f25e04051f19db94a127c470bac4c9fb9a5adc862e860a3c22c1279f12a3f69a0d60b9af2fa37e14f23e1d6066b3c6cc88c69ca08300467c771536024302b90abf8859523d33752fa80ea819484a152dc4bf7468a70a61d8bf1f55c386170b80cf0803cc8ac62a49340f85659d00206e5c629a29cf1b005dc2dea32862af737e2302788c5721ece50a51af7f1f3644dc76483a322dcb2796e133ae8484f07708911064c7906cf4d2af2eca1b57c2577bde6d6d2c55080594b3c97c697d9f1cadc7d9469e322a733ff9d64c1882d1efc6ae65f89e770d165d841019248b8f9d4d7760d1719363b8daf9ebb38760297632e80220055d170bf3f0568266bffcfb845103bd7df2ede9f0cde37bd89d987ccd5b07482c44fc8f43c1cd7bd5cf58675bbff7b1f7171f24945b2fdbb4335fc55c890clibgssapi_krb5.so.2.2libgssapi_krb5.so.2.2libgssrpc.so.4.2libk5crypto.so.3.1libkadm5clnt_mit.so.12.0libkadm5srv_mit.so.12.0libkdb5.so.10.0libkrad.so.0.0libkrb5.so.3.3libkrb5support.so.0.1rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootkrb5-1.20.1-150500.3.6.1.src.rpmconfig(krb5)krb5krb5(x86-64)libgssapi_krb5.so.2()(64bit)libgssapi_krb5.so.2(HIDDEN)(64bit)libgssapi_krb5.so.2(gssapi_krb5_2_MIT)(64bit)libgssrpc.so.4()(64bit)libgssrpc.so.4(HIDDEN)(64bit)libgssrpc.so.4(gssrpc_4_MIT)(64bit)libk5crypto.so.3()(64bit)libk5crypto.so.3(HIDDEN)(64bit)libk5crypto.so.3(k5crypto_3_MIT)(64bit)libkadm5clnt_mit.so.12()(64bit)libkadm5clnt_mit.so.12(HIDDEN)(64bit)libkadm5clnt_mit.so.12(kadm5clnt_mit_12_MIT)(64bit)libkadm5srv_mit.so.12()(64bit)libkadm5srv_mit.so.12(HIDDEN)(64bit)libkadm5srv_mit.so.12(kadm5srv_mit_12_MIT)(64bit)libkdb5.so.10()(64bit)libkdb5.so.10(HIDDEN)(64bit)libkdb5.so.10(kdb5_10_MIT)(64bit)libkrad.so.0()(64bit)libkrad.so.0(HIDDEN)(64bit)libkrad.so.0(krad_0_MIT)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(HIDDEN)(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libkrb5support.so.0()(64bit)libkrb5support.so.0(HIDDEN)(64bit)libkrb5support.so.0(krb5support_0_MIT)(64bit)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfigconfig(krb5)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.15)(64bit)libc.so.6(GLIBC_2.16)(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.25)(64bit)libc.so.6(GLIBC_2.27)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.7)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libcrypto.so.1.1(OPENSSL_1_1_0)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.2.5)(64bit)libgssapi_krb5.so.2()(64bit)libgssapi_krb5.so.2(gssapi_krb5_2_MIT)(64bit)libgssrpc.so.4()(64bit)libgssrpc.so.4(gssrpc_4_MIT)(64bit)libk5crypto.so.3()(64bit)libk5crypto.so.3(k5crypto_3_MIT)(64bit)libkdb5.so.10()(64bit)libkdb5.so.10(kdb5_10_MIT)(64bit)libkeyutils.so.1()(64bit)libkeyutils.so.1(KEYUTILS_0.3)(64bit)libkeyutils.so.1(KEYUTILS_1.0)(64bit)libkeyutils.so.1(KEYUTILS_1.5)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libkrb5support.so.0()(64bit)libkrb5support.so.0(krb5support_0_MIT)(64bit)libresolv.so.2()(64bit)libresolv.so.2(GLIBC_2.2.5)(64bit)libresolv.so.2(GLIBC_2.9)(64bit)libselinux.so.1()(64bit)libselinux.so.1(LIBSELINUX_1.0)(64bit)libssl.so.1.1()(64bit)libssl.so.1.1(OPENSSL_1_1_0)(64bit)libverto.so.1()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)1.20.1-150500.3.6.13.0.4-14.6.0-14.0-15.2-1krb5-mini4.14.3erd.@ci@ch@aD@a,@``e@_/@_^(@]H@\s@\Q[@['ZK@ZmZ@ZNY*@YYY@Y6@X-XCXCX@X6@X@XBX)@W WwWu W1@W!@VbV@VwV@V@Vf@VetVA@V0UlI@Ug@UeU_@UQ@U8T~T@scabrero@suse.descabrero@suse.descabrero@suse.denopower@suse.comscabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.descabrero@suse.dejmcdonough@suse.commcepl@suse.commichael@stroeder.comluizluca@gmail.comrbrown@suse.comhguo@suse.comjengelh@inai.demichael@stroeder.comhguo@suse.comhguo@suse.comhguo@suse.comkukuk@suse.demichael@stroeder.commeissner@suse.commichael@stroeder.combwiedemann@suse.comasn@cryptomilk.orgmichael@stroeder.comchristof.hanke@rzg.mpg.demichael@stroeder.comidonmez@suse.comfcrozat@suse.comhguo@suse.commichael@stroeder.comhguo@suse.comhguo@suse.comhguo@suse.comhguo@suse.comidonmez@suse.commichael@stroeder.commichael@stroeder.comhguo@suse.comhguo@suse.comhguo@suse.comdimstar@opensuse.orgdimstar@opensuse.orgmeissner@suse.commichael@stroeder.comhguo@suse.commichael@stroeder.commlin@suse.com- Fix memory leaks, add patch 0010-Fix-three-memory-leaks.patch * CVE-2024-26458, bsc#1220770 * CVE-2024-26461, bsc#1220771 * CVE-2024-26462, bsc#1220772- Ensure array count consistency in kadm5 RPC; (bsc#1214054); (CVE-2023-36054); - Added patches: * 0009-Ensure-array-count-consistency-in-kadm5-RPC.patch- Update to 1.20.1; (bsc#1205126); (CVE-2022-42898); * Fix integer overflows in PAC parsing [CVE-2022-42898]. * Fix null deref in KDC when decoding invalid NDR. * Fix memory leak in OTP kdcpreauth module. * Fix PKCS11 module path search. - update to 1.20.0: * Added a "disable_pac" realm relation to suppress adding PAC authdata to tickets, for realms which do not need to support S4U requests. * Most credential cache types will use atomic replacement when a cache is reinitialized using kinit or refreshed from the client keytab. * kprop can now propagate databases with a dump size larger than 4GB, if both the client and server are upgraded. * kprop can now work over NATs that change the destination IP address, if the client is upgraded. * Updated the KDB interface. The sign_authdata() method is replaced with the issue_pac() method, allowing KDB modules to add logon info and other buffers to the PAC issued by the KDC. * Host-based initiator names are better supported in the GSS krb5 mechanism. * Replaced AD-SIGNEDPATH authdata with minimal PACs. * To avoid spurious replay errors, password change requests will not be attempted over UDP until the attempt over TCP fails. * PKINIT will sign its CMS messages with SHA-256 instead of SHA-1. * Updated all code using OpenSSL to be compatible with OpenSSL 3. * Reorganized the libk5crypto build system to allow the OpenSSL back-end to pull in material from the builtin back-end depending on the OpenSSL version. * Simplified the PRNG logic to always use the platform PRNG. * Converted the remaining Tcl tests to Python. - update to 1.19.3 (bsc#1189929, CVE-2021-37750): * Fix a denial of service attack against the KDC [CVE-2021-37750]. * Fix KDC null deref on TGS inner body null server * Fix conformance issue in GSSAPI tests - Resolve "Credential cache directory /run/user/0/krb5cc does not exist while opening default credentials cache" by using a kernel keyring instead of a dir cache; (bsc#1109830); - Added hardening to systemd services; (bsc#1181400); - Drop 0009-Fix-KDC-null-deref-on-TGS-inner-body-null-server.patch, fixed in release 1.20.0 - Drop 0010-Fix-integer-overflows-in-PAC-parsing.patch, fixed in release 1.20.1- Fix integer overflows in PAC parsing; (CVE-2022-42898); (bso#15203), (bsc#1205126). - Added patches: * 0010-Fix-integer-overflows-in-PAC-parsing.patch- Update to 1.19.2 * Fix a denial of service attack against the KDC encrypted challenge code; (CVE-2021-36222); * Fix a memory leak when gss_inquire_cred() is called without a credential handle. - Changes from 1.19.1 * Fix a linking issue with Samba. * Better support multiple pkinit_identities values by checking whether certificates can be loaded for each value. - Changes from 1.19 Administrator experience * When a client keytab is present, the GSSAPI krb5 mech will refresh credentials even if the current credentials were acquired manually. * It is now harder to accidentally delete the K/M entry from a KDB. Developer experience * gss_acquire_cred_from() now supports the "password" and "verify" options, allowing credentials to be acquired via password and verified using a keytab key. * When an application accepts a GSS security context, the new GSS_C_CHANNEL_BOUND_FLAG will be set if the initiator and acceptor both provided matching channel bindings. * Added the GSS_KRB5_NT_X509_CERT name type, allowing S4U2Self requests to identify the desired client principal by certificate. * PKINIT certauth modules can now cause the hw-authent flag to be set in issued tickets. * The krb5_init_creds_step() API will now issue the same password expiration warnings as krb5_get_init_creds_password(). Protocol evolution * Added client and KDC support for Microsoft's Resource-Based Constrained Delegation, which allows cross-realm S4U2Proxy requests. A third-party database module is required for KDC support. * kadmin/admin is now the preferred server principal name for kadmin connections, and the host-based form is no longer created by default. The client will still try the host-based form as a fallback. * Added client and server support for Microsoft's KERB_AP_OPTIONS_CBT extension, which causes channel bindings to be required for the initiator if the acceptor provided them. The client will send this option if the client_aware_gss_bindings profile option is set. User experience * kinit will now issue a warning if the des3-cbc-sha1 encryption type is used in the reply. This encryption type will be deprecated and removed in future releases. * Added kvno flags --out-cache, --no-store, and --cached-only (inspired by Heimdal's kgetcred). - Changes from 1.18.3 * Fix a denial of service vulnerability when decoding Kerberos protocol messages; (CVE-2020-28196); (bsc#1178512); * Fix a locking issue with the LMDB KDB module which could cause KDC and kadmind processes to lose access to the database. * Fix an assertion failure when libgssapi_krb5 is repeatedly loaded and unloaded while libkrb5support remains loaded. - Changes from 1.18.2 * Fix a SPNEGO regression where an acceptor using the default credential would improperly filter mechanisms, causing a negotiation failure. * Fix a bug where the KDC would fail to issue tickets if the local krbtgt principal's first key has a single-DES enctype. * Add stub functions to allow old versions of OpenSSL libcrypto to link against libkrb5. * Fix a NegoEx bug where the client name and delegated credential might not be reported. - Changes from 1.18.1 * Fix a crash when qualifying short hostnames when the system has no primary DNS domain. * Fix a regression when an application imports "service@" as a GSS host-based name for its acceptor credential handle. * Fix KDC enforcement of auth indicators when they are modified by the KDB module. * Fix removal of require_auth string attributes when the LDAP KDB module is used. * Fix a compile error when building with musl libc on Linux. * Fix a compile error when building with gcc 4.x. * Change the KDC constrained delegation precedence order for consistency with Windows KDCs. - Changes from 1.18 Administrator experience: * Remove support for single-DES encryption types. * Change the replay cache format to be more efficient and robust. Replay cache filenames using the new format end with ".rcache2" by default. * setuid programs will automatically ignore environment variables that normally affect krb5 API functions, even if the caller does not use krb5_init_secure_context(). * Add an "enforce_ok_as_delegate" krb5.conf relation to disable credential forwarding during GSSAPI authentication unless the KDC sets the ok-as-delegate bit in the service ticket. * Use the permitted_enctypes krb5.conf setting as the default value for default_tkt_enctypes and default_tgs_enctypes. Developer experience: * Implement krb5_cc_remove_cred() for all credential cache types. * Add the krb5_pac_get_client_info() API to get the client account name from a PAC. Protocol evolution: * Add KDC support for S4U2Self requests where the user is identified by X.509 certificate. (Requires support for certificate lookup from a third-party KDB module.) * Remove support for an old ("draft 9") variant of PKINIT. * Add support for Microsoft NegoEx. (Requires one or more third-party GSS modules implementing NegoEx mechanisms.) User experience: * Add support for "dns_canonicalize_hostname=fallback", causing host-based principal names to be tried first without DNS canonicalization, and again with DNS canonicalization if the un-canonicalized server is not found. * Expand single-component hostnames in host-based principal names when DNS canonicalization is not used, adding the system's first DNS search path as a suffix. Add a "qualify_shortname" krb5.conf relation to override this suffix or disable expansion. * Honor the transited-policy-checked ticket flag on application servers, eliminating the requirement to configure capaths on servers in some scenarios. Code quality: * The libkrb5 serialization code (used to export and import krb5 GSS security contexts) has been simplified and made type-safe. * The libkrb5 code for creating KRB-PRIV, KRB-SAFE, and KRB-CRED messages has been revised to conform to current coding practices. * The test suite has been modified to work with macOS System Integrity Protection enabled. * The test suite incorporates soft-pkcs11 so that PKINIT PKCS11 support can always be tested. - Changes from 1.17.1 * Fix a bug preventing "addprinc -randkey -kvno" from working in kadmin. * Fix a bug preventing time skew correction from working when a KCM credential cache is used. - Changes from 1.17: Administrator experience: * A new Kerberos database module using the Lightning Memory-Mapped Database library (LMDB) has been added. The LMDB KDB module should be more performant and more robust than the DB2 module, and may become the default module for new databases in a future release. * "kdb5_util dump" will no longer dump policy entries when specific principal names are requested. Developer experience: * The new krb5_get_etype_info() API can be used to retrieve enctype, salt, and string-to-key parameters from the KDC for a client principal. * The new GSS_KRB5_NT_ENTERPRISE_NAME name type allows enterprise principal names to be used with GSS-API functions. * KDC and kadmind modules which call com_err() will now write to the log file in a format more consistent with other log messages. * Programs which use large numbers of memory credential caches should perform better. Protocol evolution: * The SPAKE pre-authentication mechanism is now supported. This mechanism protects against password dictionary attacks without requiring any additional infrastructure such as certificates. SPAKE is enabled by default on clients, but must be manually enabled on the KDC for this release. * PKINIT freshness tokens are now supported. Freshness tokens can protect against scenarios where an attacker uses temporary access to a smart card to generate authentication requests for the future. * Password change operations now prefer TCP over UDP, to avoid spurious error messages about replays when a response packet is dropped. * The KDC now supports cross-realm S4U2Self requests when used with a third-party KDB module such as Samba's. The client code for cross-realm S4U2Self requests is also now more robust (CVE-2018-20217). User experience: * The new ktutil addent -f flag can be used to fetch salt information from the KDC for password-based keys. * The new kdestroy -p option can be used to destroy a credential cache within a collection by client principal name. * The Kerberos man page has been restored, and documents the environment variables that affect programs using the Kerberos library. Code quality: * Python test scripts now use Python 3. * Python test scripts now display markers in verbose output, making it easier to find where a failure occurred within the scripts. * The Windows build system has been simplified and updated to work with more recent versions of Visual Studio. A large volume of unused Windows-specific code has been removed. Visual Studio 2013 or later is now required. - Replace old $RPM_* shell vars - Removal of SuSEfirewall2 service since SuSEfirewall2 has been replaced by firewalld - Remove cruft to support distributions older than SLE 12 - Use macros where applicable - Switch to pkgconfig style dependencies - Use %_tmpfilesdir instead of the wrong %_libexecdir/tmpfiles.d notation: libexecdir is likely changing away from /usr/lib to /usr/libexec - Build with full Cyrus SASL support. Negotiating SASL credentials with an EXTERNAL bind mechanism requires interaction. Kerberos provides its own interaction function that skips all interaction, thus preventing the mechanism from working. - Removed patches: * 0007-krb5-1.12-ksu-path.patch * 0010-Add-recursion-limit-for-ASN.1-indefinite-lengths.patch * 0011-Fix-KDC-null-deref-on-bad-encrypted-challenge.patch - Renamed patches: * 0001-krb5-1.12-pam.patch => 0001-ksu-pam-integration.patch * 0003-krb5-1.12-buildconf.patch => 0003-Adjust-build-configuration.patch * 0008-krb5-1.12-selinux-label.patch => 0007-SELinux-integration.patch * 0009-krb5-1.9-debuginfo.patch => 0008-krb5-1.9-debuginfo.patch * 0012-Fix-KDC-null-deref-on-TGS-inner-body-null-server.patch => 0009-Fix-KDC-null-deref-on-TGS-inner-body-null-server.patch- Fix KDC null pointer dereference via a FAST inner body that lacks a server field; (CVE-2021-37750); (bsc#1189929); - Added patches: * 0012-Fix-KDC-null-deref-on-TGS-inner-body-null-server.patch- Fix KDC null deref on bad encrypted challenge; (CVE-2021-36222); (bsc#1188571); - Added patches: * 0011-Fix-KDC-null-deref-on-bad-encrypted-challenge.patch- Use /run instead of /var/run for daemon PID files; (bsc#1185163);- Add recursion limit for ASN.1 indefinite lengths; (CVE-2020-28196); (bsc#1178512); - Added patches: * 0010-Add-recursion-limit-for-ASN.1-indefinite-lengths.patch- Fix prefix reported by krb5-config, libraries and headers are not installed under /usr/lib/mit prefix. (bsc#1174079)- Update logrotate script, call systemd to reload the services instead of init-scripts. (boo#1169357)- Integrate pam_keyinit pam module, ksu-pam.d; (bsc#1081947); (bsc#1144047);- Move LDAP schema files from /usr/share/doc/packages/krb5 to /usr/share/kerberos/ldap; (bsc#1134217);- Upgrade to 1.16.3 * Fix a regression in the MEMORY credential cache type which could cause client programs to crash. * MEMORY credential caches will not be listed in the global collection, with the exception of the default credential cache if it is of type MEMORY. * Remove an incorrect assertion in the KDC which could be used to cause a crash [CVE-2018-20217]. * Fix bugs with concurrent use of MEMORY ccache handles. * Fix a KDC crash when falling back between multiple OTP tokens configured for a principal entry. * Fix memory bugs when gss_add_cred() is used to create a new credential, and fix a bug where it ignores the desired_name. * Fix the behavior of gss_inquire_cred_by_mech() when the credential does not contain an element of the requested mechanism. * Make cross-realm S4U2Self requests work on the client when no default_realm is configured. * Add a kerberos(7) man page containing documentation of the environment variables that affect Kerberos programs. - Use systemd-tmpfiles to create files under /var/lib/kerberos, required by transactional updates; (bsc#1100126); - Rename patches: * krb5-1.12-pam.patch => 0001-krb5-1.12-pam.patch * krb5-1.9-manpaths.dif => 0002-krb5-1.9-manpaths.patch * krb5-1.12-buildconf.patch => 0003-krb5-1.12-buildconf.patch * krb5-1.6.3-gssapi_improve_errormessages.dif to 0004-krb5-1.6.3-gssapi_improve_errormessages.patch * krb5-1.6.3-ktutil-manpage.dif => 0005-krb5-1.6.3-ktutil-manpage.patch * krb5-1.12-api.patch => 0006-krb5-1.12-api.patch * krb5-1.12-ksu-path.patch => 0007-krb5-1.12-ksu-path.patch * krb5-1.12-selinux-label.patch => 0008-krb5-1.12-selinux-label.patch * krb5-1.9-debuginfo.patch => 0009-krb5-1.9-debuginfo.patch- Upgrade to 1.16.1 * kdc client cert matching on client principal entry * Allow ktutil addent command to ignore key version and use non-default salt string. * add kpropd pidfile support * enable "encrypted_challenge_indicator" realm option on tickets obtained using FAST encrypted challenge pre-authentication. * dates through 2106 accepted * KDC support for trivially renewable tickets * stop caching referral and alternate cross-realm TGTs to prevent duplicate credential cache entries- BSC#1021402 move %{_libdir}/krb5/plugins/tls/k5tls.so to krb5 package so it is avaiable for krb5-client as well.- Upgrade to 1.15.3 * Fix flaws in LDAP DN checking, including a null dereference KDC crash which could be triggered by kadmin clients with administrative privileges [CVE-2018-5729, CVE-2018-5730]. * Fix a KDC PKINIT memory leak. * Fix a small KDC memory leak on transited or authdata errors when processing TGS requests. * Fix a null dereference when the KDC sends a large TGS reply. * Fix "kdestroy -A" with the KCM credential cache type. * Fix the handling of capaths "." values. * Fix handling of repeated subsection specifications in profile files (such as when multiple included files specify relations in the same subsection).- Added support for /etc/krb5.conf.d/ for configuration snippets- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- Remove build dependency doxygen, python-Cheetah, python-Sphinx, python-libxml2, python-lxml, most of which are python 2 programs. Consequently remove -doc subpackage. Users are encouraged to use online documentation. (bsc#1066461)- Update package descriptions.- Upgrade to 1.15.2 * Fix a KDC denial of service vulnerability caused by unset status strings [CVE-2017-11368] * Preserve GSS contexts on init/accept failure [CVE-2017-11462] * Fix kadm5 setkey operation with LDAP KDB module * Use a ten-second timeout after successful connection for HTTPS KDC requests, as we do for TCP requests * Fix client null dereference when KDC offers encrypted challenge without FAST * Ignore dotfiles when processing profile includedir directive * Improve documentation- Set "rdns" and "dns_canonicalize_hostname" to false in krb5.conf in order to improve client security in handling service principle names. (bsc#1054028)- Prevent kadmind.service startup failure caused by absence of LDAP service. (bsc#903543)- There is no change made about the package itself, this is only copying over some changelog texts from SLE package: - bug#918595 owned by varkoly@suse.com: VUL-0: CVE-2014-5355 krb5: denial of service in krb5_read_message - bug#912002 owned by varkoly@suse.com: VUL-0 CVE-2014-5352, CVE-2014-9421, CVE-2014-9422, CVE-2014-9423: krb5: Vulnerabilities in kadmind, libgssrpc, gss_process_context_token - bug#910458 owned by varkoly@suse.com: VUL-1 CVE-2014-5354: krb5: NULL pointer dereference when using keyless entries - bug#928978 owned by varkoly@suse.com: VUL-0 CVE-2015-2694: krb5: issues in OTP and PKINIT kdcpreauth modules leading to requires_preauth bypass - bug#910457 owned by varkoly@suse.com: VUL-1 CVE-2014-5353: krb5: NULL pointer dereference when using a ticket policy name as a password policy name - bug#991088 owned by hguo@suse.com: VUL-1 CVE-2016-3120: krb5: S4U2Self KDC crash when anon is restricted - bug#992853 owned by hguo@suse.com: krb5: bogus prerequires - [fate#320326](https://fate.suse.com/320326) - bug#982313 owned by pgajdos@suse.com: Doxygen unable to resolve reference from \cite- Remove wrong PreRequires from krb5- use HTTPS project and source URLs- use source urls. - krb5.keyring: Added Greg Hudson- removed obsolete krb5-1.15-fix_kdb_free_principal_e_data.patch - Upgrade to 1.15.1 * Allow KDB modules to determine how the e_data field of principal fields is freed * Fix udp_preference_limit when the KDC location is configured with SRV records * Fix KDC and kadmind startup on some IPv4-only systems * Fix the processing of PKINIT certificate matching rules which have two components and no explicit relation * Improve documentation- remove useless environment.pickle to make build-compare happy- Introduce patch krb5-1.15-fix_kdb_free_principal_e_data.patch to fix freeing of e_data in the kdb principal- Upgrade to 1.15 - obsoleted Patch7 (krb5-1.7-doublelog.patch) fixed in 1.12.2 - obsoleted patch to src/util/gss-kernel-lib/Makefile.in since file is not available in upstream source anymore - obsoleted Patch15 (krb5-fix_interposer.patch) fixed in 1.15 - Upgrade from 1.14.4 to 1.15 - major changes: Administrator experience: * Add support to kadmin for remote extraction of current keys without changing them (requires a special kadmin permission that is excluded from the wildcard permission), with the exception of highly protected keys. * Add a lockdown_keys principal attribute to prevent retrieval of the principal's keys (old or new) via the kadmin protocol. In newly created databases, this attribute is set on the krbtgt and kadmin principals. * Restore recursive dump capability for DB2 back end, so sites can more easily recover from database corruption resulting from power failure events. * Add DNS auto-discovery of KDC and kpasswd servers from URI records, in addition to SRV records. URI records can convey TCP and UDP servers and master KDC status in a single DNS lookup, and can also point to HTTPS proxy servers. * Add support for password history to the LDAP back end. * Add support for principal renaming to the LDAP back end. * Use the getrandom system call on supported Linux kernels to avoid blocking problems when getting entropy from the operating system. * In the PKINIT client, use the correct DigestInfo encoding for PKCS [#1] signatures, so that some especially strict smart cards will work. Code quality: * Clean up numerous compilation warnings. * Remove various infrequently built modules, including some preauth modules that were not built by default. Developer experience: * Add support for building with OpenSSL 1.1. * Use SHA-256 instead of MD5 for (non-cryptographic) hashing of authenticators in the replay cache. This helps sites that must build with FIPS 140 conformant libraries that lack MD5. Protocol evolution: * Add support for the AES-SHA2 enctypes, which allows sites to conform to Suite B crypto requirements. - Upgrade from 1.14.3 to 1.14.4 - major changes: * Fix some rare btree data corruption bugs * Fix numerous minor memory leaks * Improve portability (Linux-ppc64el, FreeBSD) * Improve some error messages * Improve documentation- add pam configuration file required for ksu just use a copy of "su" one from Tumbleweed- Upgrade from 1.14.2 to 1.14.3: * Improve some error messages * Improve documentation * Allow a principal with nonexistent policy to bypass the minimum password lifetime check, consistent with other aspects of nonexistent policies * Fix a rare KDC denial of service vulnerability when anonymous client principals are restricted to obtaining TGTs only [CVE-2016-3120]- Remove comments breaking post scripts.- Do no use systemd_requires macros in main package, it adds unneeded dependencies which pulls systemd into minimal chroot. - Only call %insserv_prereq when building for pre-systemd distributions. - Optimise some %post/%postun when only /sbin/ldconfig is called.- Remove source file ccapi/common/win/OldCC/autolock.hxx that is not needed and does not carry an acceptable license. (bsc#968111)- removed obsolete patches: * 0107-Fix-LDAP-null-deref-on-empty-arg-CVE-2016-3119.patch * krb5-mechglue_inqure_attrs.patch - Upgrade from 1.14.1 to 1.14.2: * Fix a moderate-severity vulnerability in the LDAP KDC back end that could be exploited by a privileged kadmin user [CVE-2016-3119] * Improve documentation * Fix some interactions with GSSAPI interposer mechanisms- Upgrade from 1.14 to 1.14.1: * Remove expired patches: 0104-Verify-decoded-kadmin-C-strings-CVE-2015-8629.patch 0105-Fix-leaks-in-kadmin-server-stubs-CVE-2015-8631.patch 0106-Check-for-null-kadm5-policy-name-CVE-2015-8630.patch krbdev.mit.edu-8301.patch * Replace source archives: krb5-1.14.tar.gz -> krb5-1.14.1.tar.gz krb5-1.14.tar.gz.asc -> krb5-1.14.1.tar.gz.asc * Adjust line numbers in: krb5-fix_interposer.patch- Introduce patch 0107-Fix-LDAP-null-deref-on-empty-arg-CVE-2016-3119.patch to fix CVE-2016-3119 (bsc#971942)- Remove krb5-mini pieces from spec file. Hence remove pre_checkin.sh - Remove expired macros and other minor clean-ups in spec file.- Fix CVE-2015-8629: krb5: xdr_nullstring() doesn't check for terminating null character with patch 0104-Verify-decoded-kadmin-C-strings-CVE-2015-8629.patch (bsc#963968) - Fix CVE-2015-8631: krb5: Memory leak caused by supplying a null principal name in request with patch 0105-Fix-leaks-in-kadmin-server-stubs-CVE-2015-8631.patch (bsc#963975) - Fix CVE-2015-8630: krb5: krb5 doesn't check for null policy when KADM5_POLICY is set in the mask with patch 0106-Check-for-null-kadm5-policy-name-CVE-2015-8630.patch (bsc#963964)- Add two patches from Fedora, fixing two crashes: * krb5-fix_interposer.patch * krb5-mechglue_inqure_attrs.patch- Update to 1.14 - dropped krb5-kvno-230379.patch - added krbdev.mit.edu-8301.patch fixing wrong function call Major changes in 1.14 (2015-11-20) Administrator experience: * Add a new kdb5_util tabdump command to provide reporting-friendly tabular dump formats (tab-separated or CSV) for the KDC database. Unlike the normal dump format, each output table has a fixed number of fields. Some tables include human-readable forms of data that are opaque in ordinary dump files. This format is also suitable for importing into relational databases for complex queries. * Add support to kadmin and kadmin.local for specifying a single command line following any global options, where the command arguments are split by the shell--for example, "kadmin getprinc principalname". Commands issued this way do not prompt for confirmation or display warning messages, and exit with non-zero status if the operation fails. * Accept the same principal flag names in kadmin as we do for the default_principal_flags kdc.conf variable, and vice versa. Also accept flag specifiers in the form that kadmin prints, as well as hexadecimal numbers. * Remove the triple-DES and RC4 encryption types from the default value of supported_enctypes, which determines the default key and salt types for new password-derived keys. By default, keys will only created only for AES128 and AES256. This mitigates some types of password guessing attacks. * Add support for directory names in the KRB5_CONFIG and KRB5_KDC_PROFILE environment variables. * Add support for authentication indicators, which are ticket annotations to indicate the strength of the initial authentication. Add support for the "require_auth" string attribute, which can be set on server principal entries to require an indicator when authenticating to the server. * Add support for key version numbers larger than 255 in keytab files, and for version numbers up to 65535 in KDC databases. * Transmit only one ETYPE-INFO and/or ETYPE-INFO2 entry from the KDC during pre-authentication, corresponding to the client's most preferred encryption type. * Add support for server name identification (SNI) when proxying KDC requests over HTTPS. * Add support for the err_fmt profile parameter, which can be used to generate custom-formatted error messages. Code quality: * Fix memory aliasing issues in SPNEGO and IAKERB mechanisms that could cause server crashes. [CVE-2015-2695] [CVE-2015-2696] [CVE-2015-2698] * Fix build_principal memory bug that could cause a KDC crash. [CVE-2015-2697] Developer experience: * Change gss_acquire_cred_with_password() to acquire credentials into a private memory credential cache. Applications can use gss_store_cred() to make the resulting credentials visible to other processes. * Change gss_acquire_cred() and SPNEGO not to acquire credentials for IAKERB or for non-standard variants of the krb5 mechanism OID unless explicitly requested. (SPNEGO will still accept the Microsoft variant of the krb5 mechanism OID during negotiation.) * Change gss_accept_sec_context() not to accept tokens for IAKERB or for non-standard variants of the krb5 mechanism OID unless an acceptor credential is acquired for those mechanisms. * Change gss_acquire_cred() to immediately resolve credentials if the time_rec parameter is not NULL, so that a correct expiration time can be returned. Normally credential resolution is delayed until the target name is known. * Add krb5_prepend_error_message() and krb5_wrap_error_message() APIs, which can be used by plugin modules or applications to add prefixes to existing detailed error messages. * Add krb5_c_prfplus() and krb5_c_derive_prfplus() APIs, which implement the RFC 6113 PRF+ operation and key derivation using PRF+. * Add support for pre-authentication mechanisms which use multiple round trips, using the the KDC_ERR_MORE_PREAUTH_DATA_REQUIRED error code. Add get_cookie() and set_cookie() callbacks to the kdcpreauth interface; these callbacks can be used to save marshalled state information in an encrypted cookie for the next request. * Add a client_key() callback to the kdcpreauth interface to retrieve the chosen client key, corresponding to the ETYPE-INFO2 entry sent by the KDC. * Add an add_auth_indicator() callback to the kdcpreauth interface, allowing pre-authentication modules to assert authentication indicators. * Add support for the GSS_KRB5_CRED_NO_CI_FLAGS_X cred option to suppress sending the confidentiality and integrity flags in GSS initiator tokens unless they are requested by the caller. These flags control the negotiated SASL security layer for the Microsoft GSS-SPNEGO SASL mechanism. * Make the FILE credential cache implementation less prone to corruption issues in multi-threaded programs, especially on platforms with support for open file description locks. Performance: * On slave KDCs, poll the master KDC immediately after processing a full resync, and do not require two full resyncs after the master KDC's log file is reset. User experience: * Make gss_accept_sec_context() accept tickets near their expiration but within clock skew tolerances, rather than rejecting them immediately after the server's view of the ticket expiration time.- Update to 1.13.3 - removed patches for security fixes now in upstream source: 0100-Fix-build_principal-memory-bug-CVE-2015-2697.patch 0101-Fix-IAKERB-context-aliasing-bugs-CVE-2015-2696.patch 0102-Fix-SPNEGO-context-aliasing-bugs-CVE-2015-2695.patch 0103-Fix-IAKERB-context-export-import-CVE-2015-2698.patch Major changes in 1.13.3 (2015-12-04) This is a bug fix release. The krb5-1.13 release series is in maintenance, and for new deployments, installers should prefer the krb5-1.14 release series or later. * Fix memory aliasing issues in SPNEGO and IAKERB mechanisms that could cause server crashes. [CVE-2015-2695] [CVE-2015-2696] [CVE-2015-2698] * Fix build_principal memory bug that could cause a KDC crash. [CVE-2015-2697] * Allow an iprop slave to receive full resyncs from KDCs running krb5-1.10 or earlier.- Apply patch 0103-Fix-IAKERB-context-export-import-CVE-2015-2698.patch to fix a memory corruption regression introduced by resolution of CVE-2015-2698. bsc#954204- Make kadmin.local man page available without having to install krb5-client. bsc#948011 - Apply patch 0100-Fix-build_principal-memory-bug-CVE-2015-2697.patch to fix build_principal memory bug [CVE-2015-2697] bsc#952190 - Apply patch 0101-Fix-IAKERB-context-aliasing-bugs-CVE-2015-2696.patch to fix IAKERB context aliasing bugs [CVE-2015-2696] bsc#952189 - Apply patch 0102-Fix-SPNEGO-context-aliasing-bugs-CVE-2015-2695.patch to fix SPNEGO context aliasing bugs [CVE-2015-2695] bsc#952188- Let server depend on libev (module of libverto). This was the preferred implementation before the seperation of libverto from krb.- Drop libverto and libverto-libev Requires from the -server package: those package names don't exist and the shared libs are pulled in automatically.- Unconditionally buildrequire libverto-devel: krb5-mini also depends on it.- pre_checkin.sh aligned changes between krb5/krb5-mini - added krb5.keyring- update to krb5 1.13.2 - DES transition ============== The Data Encryption Standard (DES) is widely recognized as weak. The krb5-1.7 release contains measures to encourage sites to migrate away - From using single-DES cryptosystems. Among these is a configuration variable that enables "weak" enctypes, which defaults to "false" beginning with krb5-1.8. Major changes in 1.13.2 (2015-05-08) This is a bug fix release. * Fix a minor vulnerability in krb5_read_message, which is primarily used in the BSD-derived kcmd suite of applications. [CVE-2014-5355] * Fix a bypass of requires_preauth in KDCs that have PKINIT enabled. [CVE-2015-2694] * Fix some issues with the LDAP KDC database back end. * Fix an iteration-related memory leak in the DB2 KDC database back end. * Fix issues with some less-used kadm5.acl functionality. * Improve documentation.- Use externally built libverto- update to krb5 1.13.1 Major changes in 1.13.1 (2015-02-11) This is a bug fix release. * Fix multiple vulnerabilities in the LDAP KDC back end. [CVE-2014-5354] [CVE-2014-5353] * Fix multiple kadmind vulnerabilities, some of which are based in the gssrpc library. [CVE-2014-5352 CVE-2014-5352 CVE-2014-9421 CVE-2014-9422 CVE-2014-9423]- Update to krb5 1.13 * Add support for accessing KDCs via an HTTPS proxy server using the MS-KKDCP protocol. * Add support for hierarchical incremental propagation, where slaves can act as intermediates between an upstream master and other downstream slaves. * Add support for configuring GSS mechanisms using /etc/gss/mech.d/*.conf files in addition to /etc/gss/mech. * Add support to the LDAP KDB module for binding to the LDAP server using SASL. * The KDC listens for TCP connections by default. * Fix a minor key disclosure vulnerability where using the "keepold" option to the kadmin randkey operation could return the old keys. [CVE-2014-5351] * Add client support for the Kerberos Cache Manager protocol. If the host is running a Heimdal kcm daemon, caches served by the daemon can be accessed with the KCM: cache type. * When built on OS X 10.7 and higher, use "KCM:" as the default cache type, unless overridden by command-line options or krb5-config values. * Add support for doing unlocked database dumps for the DB2 KDC back end, which would allow the KDC and kadmind to continue accessing the database during lengthy database dumps. - Removed patches, useless or upstreamed * krb5-1.9-kprop-mktemp.patch * krb5-1.10-ksu-access.patch * krb5-1.12-doxygen.patch * bnc#897874-CVE-2014-5351.diff * krb5-1.13-work-around-replay-cache-creation-race.patch * krb5-1.10-kpasswd_tcp.patch - Refreshed patches * krb5-1.12-pam.patch * krb5-1.12-selinux-label.patch * krb5-1.7-doublelog.patch/sbin/ldconfig/sbin/ldconfigkrb5-plugin-preauth-pkinit-nssh04-ch2b 1711121296  !"#deen1.20.1-150500.3.6.11.20.1-150500.3.6.11.20.1-150500.3.6.1 krb5.confkrb5.conf.dkrb5.cshkrb5.shkrb5pluginskdblibkrb5preauthtlsk5tls.solibgssapi_krb5.solibgssapi_krb5.so.2libgssapi_krb5.so.2.2libgssrpc.so.4libgssrpc.so.4.2libk5crypto.so.3libk5crypto.so.3.1libkadm5clnt_mit.so.12libkadm5clnt_mit.so.12.0libkadm5srv_mit.so.12libkadm5srv_mit.so.12.0libkdb5.so.10libkdb5.so.10.0libkrad.so.0libkrad.so.0.0libkrb5.so.3libkrb5.so.3.3libkrb5support.so.0libkrb5support.so.0.1krb5READMEmit-krb5.momit-krb5.mokrb5/etc//etc/profile.d//usr/lib64//usr/lib64/krb5//usr/lib64/krb5/plugins//usr/lib64/krb5/plugins/tls//usr/share/doc/packages//usr/share/doc/packages/krb5//usr/share/locale/de/LC_MESSAGES//usr/share/locale/en_US/LC_MESSAGES//var/log/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:33037/SUSE_SLE-15-SP5_Update/67984ff1f79d5e3962f556a4ce4ec8d3-krb5.SUSE_SLE-15-SP5_Updatedrpmxz5x86_64-suse-linux     ASCII textdirectoryELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d0e8852c6b9e6b6becf25d85333f2c6416f6cc96, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=98b6a7ce8855212ce3203f180ffb1c63bc03feb0, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e846cf77041716c3612114b1eeac65c6c8d6a4ce, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f77d8766010ffb0c0887f2a2b3c713f57419da38, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=f0b2cb1ce92103110b585def4d3a1198bd0e7d81, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=1bcb4975bbe13e7e01b4d8bf863a4bd2fc134b7d, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=6795dbfcd3cd06a531353830919076a99c153a6e, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=89ad7ede1e0f4bcce4fc9cc3667f60d9b69bd1c9, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=7a256b70d28123b09eb673e19aea7d5a88e498ca, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4ec2b67becefaed045edb6d2f52f329e20335c6d, strippedUTF-8 Unicode text !,8Pj}  R"R$R R RRR+RR!R#R*RRPPPRR$R R R RRR RR RR"R!RRR#RPPPRRRR RR RRP P P R$RR R RRR#RRPP P RRR$R R RRRR RRR R"RRRR!RR#RRPPPRRRR$R R RRRR RRR R"RRRRR!RR#RRPPPRRR"R$R RRR RR RR!RRR#RPPPRR RR R RR"R!RR,RPPPR&R'RR$RR RR RRRR RRR R RRR#RR%RPPPRR)R R RRR RRR R(RRU7Į&utf-8e195063447b78dda10d83456e5800c1f5e339e77339df9c5512d0e77f4e19050?7zXZ !t/+]"k%nyv^tn(V bK3]#Kbš&g-9S??b`bnm]YD8QJ&)i-ˆO\``Y%/> ^<_k =XPzf!G~J~V0{ʉUvwjh{5<_ 8m3|Mԉ#ZڥZrs9o;-zNT'r{.K*߮_[3g%>HW?9?@8e`>sEϹ?)ȵljFLf:Fs=^jKf[U3* -[LMeR:8S:mG}f%-59vAp>E0mu@~sٮ.;X/ 3~),y\daHDO[2%I EM|gsSv.V! Ŭ>!s=21Nk.PneLa#:~::0f$ b/W#m"1RDd]R0z9f9={-h*\p]3l%e7NY cz%4AҶL=4 .{IzuBNt;>Wc-iTɟ,&-c:M0~I˙k[$xC@ m:u+x^SqW`JĐP{^t><|>wRSxԗ7 N`I**:ݹjoi*gQLs?hBCt8U(G1kƌznXMє-Ȭ:2Dc#ɕb E z*&j ysapq?;:,|bD+rj9N1s~j>EP@x<ߤ.7L^Cm("mo~)$?2##1*jXg!(" .S o-мjզJ1`HTk(,eI]y "0}ˮfŰؑ]ȅ`D!iJI wl `ע'JeJ|/ݢV]<-^&Jct#?&ԕFxw:u skڸ}%FF+R p<;;n[w(m淦 SӛQzu|"s9[NǯO:&7m Ȗm7SOR{>dCliY2= RC3.X@YA[14,S1byhghl JrJ]kW(={geD#hmrnUjވΉ6ޱoE!1"c紻(,8b L7cM*#0OR BLl|&BDG0 J\c/ BpZ;'75ܣ,Ӓqn52rJmW7(> a@3 M5a$,x_ٳ GdacQVjwHqir}%JM^s3Fm22Z~}HչpyI i!0 sGnuH;%,Xv/>+za`q^7> lQ?YHtǓpD/~9ox8R%VrT YeA3܇reh) &BcIt߻2; JVQɽUrR[=8M%S'׷"6W~H[-8"j' h+Kl^u `>!qo+TEWʣ ˸ɻzIӎYAN$A ' y0bcQZjo)YV=?4``h@G =WW=Z$w@\0)ᓴ}#zqb\O§ڴ 8])wW!6-[1jXzk ]uƨ(cdR׀E$^JrVhes$-ߡ_7B¥s5ӟC9*3^udsGWP~vUUٍ5e#i/j37S:U<~n.i2+FYE'& o觢d6MZ A³AvSߪtZ1Ia:~wֹ4{uS?Q-79w" Qvp r tO-CX]+$?!}տAR0$hCcH)@/0M04?dmfw%SID_/ @32,o=7HS9~X&iˀ$+ogRoAY/ Tm~A,Ղ5}Hn_Y(K Rωkbx`mF~5wjfn2xW xcBLubCq6`Yq"VUD",=bhb@(A . xjiOR(ѷΚfa kkb$},r~iVW VsUVZ$M8 63°br aCmH/kI?<'EG7Xf/> C}M/'5!t=AFF Zh ,;s&<:_?GQhv[aw q׫_^ӫ\Je cEēŒoclܶjD8[VqND]\ ƕ$A ou3+fVsȿ47LsBHNkVqugi k^d 1v˚FA08ud `pbDFk]q,!&TL#!/ o˰ηM-yV^ގ8 cUEskZ+µ5X0P0hl%U5(jQ鱨u!^CA*![ ]Σܪ0)XY\6M;VXYv=9TQG(rJG6bb.$`P݋u {͏|嚸3lzЭ4<,dZ)<׏K>lnAR.t.R9",VB^Z"Ohbfej0^D^°""eq^U=LEg"YgL9}5|y@tOy 1583(0YnV|Q]*(yÁ\J+wΓP`,9ar icJ$Y\9 *6r[7D[;>5~rt~"B 5Lbs4~#sSK*[̓qhN %$|UHt@ IFALs`3c/&ujsewͯk@||&eGj݌5 4uNMM wl۵E T'lFP0LYA8co:~W+$8R hއJ8| c^pqHfOʡIwhRQ _7̝ #8CNN\luyC9z/@f~:SAt@{1p7V)[O,lQ 8sx!6$=;t3-Q?$Q%d$]eB6gv4JThl; Bnu*|%Gz4>l(qDY~A_'$U5}D;~I}G#3THl&2Fm[>'O{?o.=Ą dc-{y/:ٗ=OIp* {6jjbׅ>^AV 1؍wxfZNML )SJYKE*0,܄Ѭ"]UǴ^ȫd+qF 䩏38k@+eJ@X*L 5#>i}igCZ]DըYc $ Y<<"={ig3Q9 RZ? f;ATy8!iH&L!jM@ ï1";lrWP$:&aDW R3HzСDYldx WGėI^dd1phYk0@R'b陋1h}v g:mvRDҮ3pXXN7a6.VNf!kFefq\ \mBw+z`KkQTW1RQ?[Lƻ9|s@]޸}KȮSxSˡndo9C9B }^uָisXƓ{Ǔ)Jr3[!{-s./olA=+LL:np׬C^(RG * LY޷rU8(h6(nG8[c ௢PAg8iή1X_?NnG~ `@߈ BKucW!51 t`'/=d9裮yE8T-p9hz`V]E@` 0*l}ڴ@B[5cWS_UXe^byiC:r[IBP[ LNaM}JœMY}k-7.PEOGNN32l6D꟫/}Gq~ زLDo#9-3P [StEO[t&z*Oɞ=%F&J H$d\b4KsO.=2:(ݠUã<ըONOfw2s)s;CGAiu`4٭jjV t(;g ZSKI`r<`@o*:ƩР+JS[:>v!>+H3s.>3a?< Glo~pϬX) zj|jN5{~+=UU/ߨOQYyr=4:ִgAs_΋ÞᎯ""BEˌbpk[vIN-h7QTUU[Ρ?2>KճSRW8aR@by1QοGKΠRPdB5[\RlD 6RKXF7aU"H` өB9p=>A dklD 󑘋yX a g^V/|Z@ 9F#7f ?;~ebyJ?\S uZ"|ˤų3[/(_h-N!݇Ԛ %Śeg\GJHf\ҚǕE&4՞#DrtZ"0Nا~к.H_5z a{;?= \{:fQP 8QA+{D)=R ZXφ:aw HTZ ޅqk³ht'fV?X\ƉZf U` P YE3‡I~`~ŋX10\Mqڢft{<]#.1D"{mA}3 .kbBD@@W>KaUwڣ.#6 u| (=t!Rx1 ZDr<]<뷲1ɘ )Y2t*>%i+NrB./-n at]lye,(SÃ_ywI Qu羍?OS~Tؼz.nrFщӇr,7:pGE1851\UxaqD-Ȉ0  )zvL&˓Z .)Q\0QU6,/r^q?B~F,΄NPY6u[3F3 ]`]13ABtbDfJVЍӽ3F[cmU;R8)3ybƜa.{O$7lmj~%U29{0} n)y m_MJ$nmi-V{9),$Eey8#oK!T4 > 4{(vY7 T7Hy,a{hgHLXE5yWAT?lRΞ xfʻӻ$66m=pη(?!uS+3eaIfi=& ԍDlk^Fy6hZgJZwR71ͣbhv)f ,;~r6/!ZxiĘ TJh!:؊i'!KX5:0j% C B~[Jؾ|۔y ;'. ig3Zh;0W&8Ye>@Pdmsv-|r3p8FP2<+s(8'{p tB8As[=W~ĐƿWl4Ժ@lSҒe ~WZ,(D9Y CPsMͪp֐ tfSTXka2!_htk2Q.}FWW7zJI 2RvgщJ*Dd5@m&W.=&wi_uj"rΰ1'r.*c 2 FAl|}XV䆾*y'tv֭V0uw9*zqv[(Qmh:CiP'l}Tn>t}0iOx&%5)ARH)z~'ƒXvH/(A.(YjcCM9}G>w !”$2FY\]DIߨ&CH\!sc+FcF;4Kvvm6|o !t=j=7.@L̪"Z ߲"!Pi&&k~X(S0y[!)@nu"?pcT2 /Frw*ĶH$l)JvNo|a}!$uk }u͘<XA'_eaZXArk`u9_X i٧i[qdM廘BS S[{&^3\Q%]M?{oj*/2^TxށMIe(ps"!V0sh.Gޚ:J biKw;r |<[q&܁& m2_o8!)}rT^X?;t *$OZ$ak MBXi[F^ŝK?Pe8*_UXL/'Bryol" O1>X$l.n:K7:#lK+~ T#9["r_tHtcDXO6shh1ˎ0O7wł!vٵxNR8^]hrIl*U @A2Nv:c5ՇpQ5Ԭ-l+u.D ooׄ*POg#߆px3|> }ং{@TPY\, ai]I50T. f S0mȰ?¾95Jz%`I+tNM+FO:)>f:Btv=;/Tޚ#uC KG +vŬi^N .( u.o8Z;ȿq0&uHe.21Sb/#jiGFGXE! g.aZuZI;K?gEcZ;MU,ÔiQ`9IsSHg7ۣN'J1Up՗#Qw{UPӮ&v7:sZ?D;N~6o66Y=8MSӪ??}I܄\ؚtctG=k f #,'Hʛ#,"^D6`]IP]^Js}gS1K!5H@>7%0v!Zti zf#E0VmɆK0g]nslA1(”"yXX.p?RM#7<!+!PM'q*]Dt1k΅z=.ŭ%/͚ȸp]v+ mq3~oN띊:gXk.ܟlx3 w"JEڪ @7 KCQc%ݝbdKCvbq0:B\Eƻ !y^eE}knKwh]\^О. 5B-a6)K2Q3 %U#cIO臢@ЬUćR s&)'apqV@:AhL|70?4C?b:@K1!(4SpI S"'7XQq4@`ךef]!l B2ZQ3㉦\ʀ_ɀ'V(NJ|\.|S`X|{% ?3ZZp}ʗ\2Y ٸajD!Vy>i:> =dd_tPJ]SJtolAg߲P/CbU%]i* Y!T'M<fRU\M]1SWdzVbBƿbD')2Ġ$ }+6ob! & )bFq sI_솑1;vy#ڜJ(C2\z@>q`%^XX--đdW%!Zjj ,ӧdbܝox b}=@EsN AovWQbNXtYtjSKDC*S߮ux#r fJLucb.dQ{3t6Ez#;:};=6wCո8#NVEB@|;yIz,;zx!Y'RDq i7>ƵۙD`)QrD,1*˔' P/(vN$"m?QñPa̎7q^-xQs I=AB ԴvYB򱌲EU']6Iwz?c=B[Yˋ-JaKۄ\H8f|g6 Nm=~[Q" FLo@Ţ,=1c"Fm~vGգu$^+ QÅZ@cƟ7ۗ>N$vSGo*V {| 6Dq%|YA a[k^Yn}ڽ099璶G6J3)Je.U"\B d#qSx*r&|O߲~Xs%*9Ƨ`t҇ɾ`HR\0&С?~^⣣XCYkƾ3E4zazfxQ2/e/wz%qJb;˜3s}]7cDr2XG) |Lv nGD>&< L&YU($öە@8ACxmlB1l^kVTeQNjGmE~[ :p۳!Y3gt&L\t#ڽ Nx~gW֥omr tzi4S6vd,rHLpm)[Wn״m9DHn\/u*LؙIAIHꕉ7a(wzLKF~3}pHP` tKN6-{)dHm6,%yKPOZ.SᡊЕh$qxBsƇmo h)Y;szS)[}. 6J7urRb*ٱHe^dusO_&Y& =X;+G2a1nl ծ0BWP"?#.T OkFA$3E󍢾4\jpYߠDRҔN.i ~ VjWf^e~\vH;;ehޱƛet?56c ʲx3Mu3Xn.(0AB937v}7Ӭ\iyxRϑ_%j* F2<}[d1$Rty{KT;e!@6D\F?M͇HF{_2oEdCn`*_=O1bDmyfA['OˌTao (*N&dL9GGNFYlӐ ("ਖ>؊@n_23_CfIFm郿lKwtUlv^,lW6z3ȄG9׀DέZ6b斶b:uo& vca]/]ߨD+¥Q Qi=fv"YyUOax }q BԬ*Y,'q$3T4B+"ƾ@`{ H$hF(S>^e:e[9FNa0I6G9^`i?,}SτVRAXGo};~K"Q;ssbF33ӂiC]ŵok]]=HBAN6)AGtKKΑqclu}It6,fR#"CX[&"r CykG8y~SS7_P)F.,vܮQa,+#ɑ.Y؄e6:?(WՔ) V!kE[$1-M=K6Ww>i>byۊK3Q׽BCEF֖uo~yt#Cc}Cnsحf:8ʚ?3莦=X~ޕ ,[Xt7aոRD&rn_φd!zdh_;0 $Y^/{SddIbEZ5GYȤZl-0Hzُj_mUou p;\;$ 9Nb#h@hi"?u*qj `n.8]j2(щnu1i[)JCA,^L5JHb^w_S{ ϟi+43n{_88x_&GISm泬  W(~yYhU[hD8ڰ4D>6$#D Aq<Z/2*3(l<ʭ4~aߐ[J;RY >NfY(ZLqiÃ(Ev{ŸHQPfgs0t`% ,|='Q~&8fiy\9Ǻ6-ZeBv"/ zdOوSKfJ&7Lsp#]TRN/wB3[41]9!pcm?*!Lߪ^nLeN`JzKW("l boF35<%9܄])mib>QaSǭ 2-{u SSL@ɹL$3oIcwTʨx 0k.7eZyci"{U~Z(#Drr;o;\BS0 \ҖKweDy􎴹0!Rx^"(!0eE<qU1b9 k@&T7@=o86KO8I+-_`GIFöe! yV( UYG#EY"4hwv@'0DT\pi&f\\*7}IxxM-@^W[Ɗc Z> 6Ɂ{%p&22{8^Pncrnu&[HE^JoXS YeƿL ~ +"҈7|bS%"z 88Eʞ>[{a0XE(|Ong,IЄ'3AEb Rj< AxG|!V&fv[_X~F!*[BT11,36 *WYũ终y{ x`BNIf>91qc;)+NY.JڦЧ\ Af2 [? /7:NΞ ko yl6R.U$p*9Q^M]AHrTݰjt oN0{ >7)BSJ<=nw6[CWj Dە\kѠ2y8g!')u2p;kbǰѤ4gk4LJczZޡLbȠI#;B|MƻiuC9vCzL((ﴒZɓ )]/ȞOFdvFE=nA;i.9  gGvXu3RU+; 8~k%%#j0Nu'c#m GW@]W-{7)eѰ>vW[QP6npCϒ'NkA(U%fǃbOn ~Š2yQgxֱe,hx:_ߍΎ/i)I:{Z7"^؎6`eAgyPz*~nj.S0"ZK|]-ibud_LB}wX] DC0ץ7W.wjVcHw\Ƹ!朰͉:5o9kHs t@m>Z dW'1B3fi‹s=mlXfn:;Ws+DZf+bV=[1~'+̥ Bic > Pn{-cFIj6L#⸾6/UZ W:tr6n]4Bnr8l95Gn@EYR/2}4(>L%|\n"jO<#?@aMi;eGKEU!%MSyno3R:dيL@bˆ!A`sCT:pJd?W ;֫7WZw1V_٘Xg84{4T )7I%U^%Z"iMf*'Fxp]p/8X Sx^Vn+@<Ͻ"rϫ=-ݻ[,bdƂ5rduH@=(!*25"lɢ`2Qk_:r$i,e4P3>CKDm[*S-Um} u??)x~׺<kXKl=* S(fAA~<Tşč9؞.3 n\po3eFSݪ;-h\9hi(Zo%ftge~ʸOzLd%9!-ri>?؃#8=O9Uq6O:N1Z;QF*_Xo"]K|kscPÏy#YL; +0mA@\%݉\1UU=cf4Æ%c/V6:/ t#LkbOWQGyT%RѶ}.nx2 Pn EBItը]nd4+cn8AgZHY\k޶g8E|s~ZgK:hvTh'`PKYl`G/-uhg#9 ΑGנrS>hv!GX^duijT5@Y$^~Crfm4}v Lb%!.9쳮y 7l hkmDV}_8khIUea)sj'-BcM Ǹ#r Hu^M/%Ljlه,K |n mp5i? }/|~GI8+~B ^<6=})I碨 k ܯQ%U\]IA8"/9 "j|aӺ=~az{Y'ƧWy1OZLnH8%wH,d^?ﵓ&RmRQboTs/ʞGai{ul.hyXǣ`D\0:34ƕ]KI[%ϛHU@HxemeN/6fউYfN1O!X8[7F9Qi%6bSdʪrfx_eC=-_/@:wO!5:?.琤2k"|iB ĥ 0fHe^Մ *WJ9N%9aDKP;q֑3hߋ= yta]f U'&]᧣TV2[MCãVN)|XgM_Sa{itYzi'tUQ^4ga4WspYR@R˧ffvܔ i2)^S)X4Qg(F=nw钪B/rJN!TʫF#HXa 'flD̏IXzipӥٰ)ڴW48s*_x|k[)ؠmGJadkk C:^qCdoNLV~ݶt$a]K*Ӻa!U4V/)<^΃uvv3g- 5~ <3 =~3qAK_ Α_8z hF=}qB%_kn;~leC1CT]%1{%SGdQo1ІZh ,߉+iz+pS4Ng/ZYcΖ>>c$sv$Rt6@1y?e] PC_6ے00?\njnep$Ԩ:660W"I%Kh{2F;n5fuBv$je1<*+~=Zf̅zl&$nzU#w4: 6aĤ$cxx8``|iq^^_8=.pG[uhE7?n{X{h ;~ ́\21ԱcY-2ؑZW4U4*TI]Pz֪'{hl hDKK@N41:){MeEPzBӿPǺ|-4~3mE"q=YC)pL&i 2"QK1AN®:TRx_¼,m5 "^O^gs (V7O~ Wnl/ -7LNm-K eQ⣾N@F3QISլgE'@|x꫷1;K2:aɭPjV3U)9ϹΊn9 7GE?w $!]4<|~NGƑ_ySڊqW)͸S6'_ HB9D ^4".d*0w M 1;3md#K#z oBtKÉ;vԖ1e-MS+%7NN죈nɵ-bv+K^貦5j~TMKG3E/![fmKըiAu;ZdEZƊEJ?x c*i'y! u+LϿPd8ՄNcKxքc ބ:6O$jWA[ҳ) =7 䲧[:S=";|YEsf*޵T:8l^.b(s &l, E=f6o ":Đ)B/R Ln&.yTI.?|:WS rϻ!s4a~3б84w8*t [dRN@gUFfN#ً7t3RHx;Ŭ7ָ']}LjkQ'zF,}̰QĮ^r,n=I v8ZkW[~|qxYo>+Po*{K#L/kx}ַ%^[{1#p ф}`ɐZBC r^Au = h oMǻP/#:zؔ8pb1HJv޸n5f,ɚE]G:!DIΉo3 cBÄuώTg/땮7 W6 vQ7y܂"3.uX,`*,Af"]um5[*ny+A,0JsIn.ӸA*!>!![,>|aċn&!981,oqgDcYc0#hGCH~|4%}%B?Mp|.\aLTw/Gm#M0:PH4^ղKxP^XB>=w:qk| %wR,1& V{"R;+-8 ˜Tmz2@jU'F!qo}Ӳf]2=%-՟qt i 5j݊ٳaR/f{(Q*O? _uw ȎG}OʋRAɥ_鍑*Ə&g8 R:%.JھM"ě!sX8 >@?W} Z"v/]"6j3 -dQ7E'@Ue|2^9n@zݕzV"ɽm_H1Oa)NTr 4mγw봸fYԵ[AnJd˵K.2)f)`XSj?c7`HW4%S.j6`&[zVR Щu.d\=&1\xTɘ6"(tbhn^r2rW]ldFD&.[clx ^`X߿z. כMe$Xf1vFj\EN$웳RqƗ o\nY[j gPsvaAC5& =[/6λF^$:l4ٗd`Nzٸ|U|nIm5-o39=YE>B얽f'-PxM}+^B _ty-|KS&AxkwMϥ+3r XHǹq%gh*QRj"f1˺uGJh$)/qDʌ/ n\,Xw:p:*1C R:70@쀻h~dȮ/}_ۏʨY%ۋi eDz wn GIh0`?cG%'c@ 0(k Eݹqzas 3U[(,[C2T[܋ܱq \m}Ni=w?X(m3G:mFY!# gih\zqp",/6y:`w3Y9yaBU:ֶ%=Xu3$3AM zh&Q;!yF`ɩix{?,c&`LsWZ^fW $u* þ{u;oM-[vBnFܰr}4< @WhE7\.6Va=}a ijS䩄HA?iu/Yk&b Pq6p,؇KeAZp0Aim7+yqI!@Ǜb-^D:GP=o[ ]n|5d9c&FĢrEF]  Q*$s.4QJHyqiM}.`SGH;K* 8}39q ^o Q"U?=QQ[˭Nl/:Ͱ ]aҟo& ہ? =qˏOVVCIM0ۡ& ܡҠ-=R  šd/RǎW~vY6pNldY ,1EyccU_&&1]Q}`i&ʤsgekӠ(9< rh5^y3Dd\5e+i=s#@)eo|OFhI,'ߣx[E!۶7|m$OTiğN003~IQ؜^xH-i|܂'[.?T}wa ="7M~#Dz$F#V^QaߞzM^ :S.O9:4G/I ,¬P|gsӎ͔lUb@9v`we%U9ԁ znT!CCtQpx6K7'I$>2fһciGݷoh7#Vp`4ܕRm_B[XYlQ6npfbVSurJ&:؍#JŽ=2OwO<2J,Đt OՋz\# ǥ7rK82#9zc{_ h;D#V_$Loyݶ4ܟAY\7 ޢ\iwziteGX—cJ5wд$Kͯ0{,FQ!ąTUQ֠(N\+?Z4cC`nQ 2ˍkkfXn!7SOpz :{+{Q8( o >&43릘s(2S wH!5ЃNhۗ*e4Fh+:'@Mqjpm3= }Pqp%{fl@xP[0Zaf=\g))˹J^U^OwtH6ȥW?^b\7 5gNf18 @ߔ.@ p=^DA6d6vԂ /Ppq3裞t_Uy׎Iqonlw`^@PpعmJʐq)ɖ-[5dӊGkk)_l_ vHܚ?j4VeG #nQ/ֈ/p!Z^鋹6vFΎUC`tIS73p٤:lw㪺}VL%rcZ+@U@Map ^='AAUanⓁjBs&o8<<2zxdMJij٣D ~_DKڙ#rj v"Ke!eI-B3\zYMm>TăFz% HׯhHְQg HC Y*TK=!uZ܍Px=Y<کf'*ۣQAhtn+hm3]Hlc@r`W@H7fВoSۚ;R0OaSaߺ PqIƥ8Zo)<+tSIv?u=y9FZŕVUgRRTvu*S, ewǓLٮ| 6SIʼ/}WEfA4͊>R!~&Mڻ!<=noaт Ls`oJhvQRyJdkn! OiƗ?2V>;rD ҿ5'dp| #u%菮8^ɥ4bcY<ƉnbƹFe`\"P~T9IV?lPG-rW e\Fx忱X-ӏ |ΟE)EWWȦBғȬE=Q*]-_Si<9lg.qڶ0=ejԺGޘ-kVl&91qA%xeOk+g Ub@P+z&?TAjv>M*zqO-/y2c5rKI f0QʟR [5LAgL"4M(Vf/wJ3y6ܤ^ R2X`< WMj\R+,QlI *xw 2I_}T|h0c|>ts6LH^'. c-ߌ9-IAx6Ae0ڎ :Lkj' .g0&wR]>e O9Iн@76W`{/-X?a9\0ފmmP 7<]LԛlCo,Ja>G6;q`M΍UY;jl.!,&xb%PR.lB\^lI5,*2ƻف1,jH~ΰVRBj_FeuPPR/րBф,ɟm|)7esQ_0i c%ޡBLMwqk%&:@j8Dͯ8,OFI&w6jj_¶.H{NZ)(BΨ=s蓸S2 ^c&HI')N{gkRt8Ablrg`Pm (F~AZnXRU?R+Ǫ4q|d}Z0ẽЀ1$>;Wvx*dJ6uw!0?ͩ1ިˏ?sv` dt23z b.@ ( ̃5Q7ǀЮO:FF>O RG2'~}/ԉ5BN~{} +#(ZIKH^|G0pKDcTeDI>頕hIͣU/I묄n.[: AyGG{GU!$6E7+2dj+Z8_>aw۔>Bm /#C?K+ye&%aJu-<ؑ6zh0/%2R3b N(j@/*x-YK*XZ÷Bt#ێuq񑤵_:$|,-/GdAݿgh']ThbڑZ(Ѵ_W1<Ɵ%ڭIii$Y!Ŷoh2wU5;W;f<]Il__P |Hp@ qp= aXwLYKM xNJ&Pj{|'dD!!`Vܓ\~ьjԵwA>.9|)wqޘӝzzGB.XƕcԞd-ۃe}+4!Q]ͭ. ),;8aI~[+~*a|R^ѡ;1iW|T\3e=jUo" f*qafF:يm3+ٱn }h3\# 6c MQU£爖K:dCK{! _{N$$sي^S2X: Z z#%u{Ѭ1+8$B"2xx` lrk8g2\MgZuQ1,&[fCe3u~X=5ېG@RA2ڢT0p>hqdP*kgbf`y6BSٖ['+Gn}gXl+N k$y$<]6 jb@q_.ZI' ( ˘wNwC`^VP]{]^G-R}х\>d-c Q .ʯ vWf JwL%|3P"R1mE,bDR1}j}g6ϴӏ]gΫIJ_v+%=pa(Fŗe@M2T͐־R?kzCB<&gS\ N %'_:|/ A!SnF5KN>I]XC֮C(_z>>xD[ tmt;NEAu򷔬^[spv2,M3OUȄ]mP:rBHboFml%bPD bc0.~-Эj'zɵq`_iWէ3w"_[ 3͸<!1O_Rj"v۽S?tƫ,$EԊlQ 0]CAK@z5MImL|#FeqJqڮsfq.,Լ; R2c!հ$:3NJ:c0UشVps"Vpϐn˟8ak0aW|c2+(OdDyʯO1Q6xV}M2Vr)2'g:7%gm}ǰ1؈!p+=[kmy_UEl]2n>G 6嗔j{{lCJҼFLj.),V>$.SX\%LRoznQONt}B&j2]W/sԶݔF89;U˛gxE=URyo$f?ɹ_^OêyjY7zdgy+O`F}cx0$] |֮iE*h9[N@. G>BEV3&f!hF%֧RV/ bɭPo1P<5hKt#Urb[y8_y񃼭vz>c ,ngZ(1̝F$Jig3} ( k>#jqIX!"VG$4Hl;*3,ԅ9lnme(bؕ 5fFS |A$J| u#Lies}0=aZTIƍ ;{v)-R}1PFJXisϰՂbE>1L5S Wͷ1 *%]iB宠ڰ&}DK= آ%.D.Ejg9~biiK}yX`gztLn)=5͌6EGNJJ%# ݹ)f2ap$3ˆ-s@qt8$(x ~4?_cL1/}BK"bKTrQJ,ȚmXMjUyة1m!QGj(>cBO^Gn55yOSQvdc KkU^6ML$g]ю*h8o IԹcXܫqEU41z4T {_?=?=6Ut=U ņBMۖUZgY {9|4fJV-z.@P"=4h"E7i^qYiʱz0pǛpifۮ য়ޤҢ1xߛ{9v ڔF|ڧl %IjYT^BXÝPo=v HOQNQx 9q[b\rp~$LN'B?}Hmi7u(m M^dQ|JsN&1EtP$u5^`v6: vSJk3ۆtxv{L^`<dkBg}ZL?06bժ}C>ڳG⠘f_s7E6KRZ8Q.Xd^R+a@3ON`JqF5%[XP/v q #jڧ+!UU韵'xv:I&5\鳑lyɱ/;;mB6f_Yנ=UPGۑ .*Q+ihuŢ`(S#jk-uPHִ@M^9ve!~F'7]#e%[łg8A6h1_UO:ʶ.T*GԌ;ZYX l}o1H FŞLV Wr|wÜM-1Z`+ `OUF#̬Dc:F 8Igeß+6.CجFԟۘ6iG`HmzxyK_Ӊ/r'(/po"9}z81: gqa\ .#Vp%Wf\s[.+V0DaS^+PӪ|P!H-vI֭gRV^@6i{w5DRǧNͷ%׮IjnHT>Īk-T,&}능xuSYM+\u;?9մہ‹=Hzl-.'yu]ZD'КZSͼ`HW͡UASSӭ آؕxY7[7!a}7+FOԽfԔu.ְ͹8+Sabיv!]NW33=X=p؋?|E[f0bZug%~$ѩ8ߧ4P8< A?ݘb s?GJ8FZԜ/?*W^ןÈۀ𫪵(ȟ8#wŕ@.Md"!њ `Wpc4<$xwJ o2x%yIE!_9d-yԜE-K=r0$jRӦyo. E{NXĵ[7C{4/*?`M- Pj%Cjse<ʺy_?uUI4nDqA^D~)j3t{ǎ ->MV> vc'T"Zu 8[]w ڥ\7XvbhH=1GZ0<4\AsDŽ wC[HryBM֕>'$db QM\B\h+͌ƀ[<=[w=KXy?{N텎n{p*(1\.g$,V4uM\H!`)b#e`ܸ[;GԙRNUVa.fz| Q&i[<1(bE}bq0(/m;>8LGR,ka>7QN8zؓD5xRt{|MRޡ $yncC!wY e&rkK|et7c41J~M}*D_86&$yHFHh]+d`]ţ9nKɘ>Ar媵yJdo1J_h[XYt6GskJﻧn<34g 6n/M~ dX;Ȏ 5x#$h kqzױS31 UE9|xL(hp7W1r.C[1c~6prա(Ec:tuAMֱ=42Vu"/#pB|桉<M0mBAd;}hze/~.l}IK c%9uCG4ֺ%W**J\᫘4oX`FlpTYL6YŚ*]fǚ1?i#E1BM>\JF}SBS\bxme2b$C=q] _wn(LJ305YozU#ʎ^clfDtӁiZo8۾u3K;.k{z O]muHxG2tA$ӭg<+_܇EDĸb{4%SVEF J/H08OAAk  e \N\ F*-iA ܷA`l@+:ԋsN?)H דEGw}pY/s氚Np<%xj)sFx )((S;_#l^-J:_B0Xu8ઊ>8ڂ[:ɥO5<\M:鮯- pTȢX~{;o?5EA*FLR(@$ԏT&E*_}ܿ zx,2p~^}㤚4}-0ygKŐ]Tqp^tP(%`m_(rjY$vgys O #./[í]e0:tFJny?^pi׻+6b?*,Ňm*\?AìiS>qAU0(a?L {uD.ÜObȑ2WBGT 9t`pu ސu~}B )bIzg>^7szyh7Xr4lZŒ5կRc 4cShkf d-˭7qjG$U , OM4[C(!bz+NZ-Sߓ6bV"j *s#"g/#܎b\z ƋF͘e9!T5뤊zfW`?^#߮Kj^`~3`fQwX_@;Wc1wMromʽ* {r߻3Kkt QkK.DЈ;՜/chW̧&jD% RSix^cB>D1V&s{|PPݫ(:6%Ur8hZT4 2 C"c+Q~+ \ ̌z`+o?knec{HwJ6T{L }k4$g-z9&QAm-38a0/cfS0Ɍ8qH \U3An%yBHJyxB< DW{=1wB 7DH<#R6K!HXOD\ST&3lIhG7^+DWk΅zDk\?Ry'^!w&ܦg=Lp/Ж$ =O` Z^#L|kk}0Hq5,}1y&9[{$ \l.A|aEX!Y{dqz'M膣Jz/X!o@':J!s 6'q ϸ"P /HEQڡ?)Bvo?Vέ<т[/jd'x&\BVq5;P@zg֨xФnEYXβ E,, 885NERuCB)^Qe]VJ[ܭ :2*#r':'F,mBA W> K6)wZY5r_Xg~nYW}t3)APO#~E-~Mоx;9D/`YH{U8tҟmUOT8W'WΟ])2y' E+#]'TGRxC>ir5wԝ~ 6qsY!6paӠA `s{ȉS^Xˀ'&an0Lp::=_ @/5_S0lv~C~PUBҁ-|FSIN>] Y9, Œ_Ɍ,OUcIUNi[/L9~*!oZBǞ}֗2aq@Zu^fH{eNMOK'O8-9Kc7gh?K"Mjs9=[]6V)v:1Љ9Ϝʩ]Q){:Ǎ g n]٢,4M){mYF>| IKbUU# .>ߍҤq>C}1͟ըV4yLc{7@`S%aH-dH(%h<;}r$Q)  wXɒ*}m/a\J4y^;К+Ɠ\+5⟈!/>O`>MDð$KU.F.mCf{_-@s60LUe>p2C %z3[QeTf\9SŁScʒci`Cg,Ar񶊗UuH4GB *{oj~~İ>~uO[vv $"YL|Xtj&Y4&/pv,I:xw6XӢɘ?0kx3+w+^ȒBs3:N瘴J\m@>hGi|i㸌k\2=+҉ ȇ|]l)IN Sn@ي:_vqhy(@TR,C[~#Pyn+MPRtg}M`?3Ge #|]:J7#x&G|$[o/7(`ik~5ж^yԑ]zu{K* B7xqvbhjz~5c}9+D'Pֽٰ}%|jZbĒlZh`|e=~.#YVA3v'+BV$ML2굀68|d_VUb$IT ]iRF fZgv_ R;ÅcY[7&NAĞHARUT sJnp?QFw!`/ͪ86ï: y){fɋm41Ejby5 i'vՅd$\@AsS7˽kǴ` $An<b4ZҌ֌bG%!۪;$8C -dWX |I )xq&cL s}45gd(9/(NVo0'.;B28 ISۅY_:Á,*8/Xрۓa.Mӱ_`Io.hGg=H?iVA ;po,[b[h lҩWStyc5kH~'@ k7lY(MPsD c~_J&d\7?uņiK b F |]fajQc(22s$tyJ^B_VLw_Cc&jSe:қxWCBq>\Ț5o樮m,O"j4>R5paPep* %{=ۨF:aIJӃ0M,1:dM0"$Q\3N>`gmpw$DFߏ#7u)\זW0x̼ng8_ʔ`TQ/1u#&x <6$^S P~Vo019@OX{jv<5ȇאOx\HTC~šyˇ!.kb~kw։߼B{5Dk+Ո>7a1)dw=3:3rY#'c0սn!3]Q $aOk01sI%yw!Uӻ[>* }K+J-fOծWo֓R9N彽'̆2K6Lsbbb>,'d)Jsݣ= H mj|~[L&G&S#G\pـK,Xj+YgFߟ% &a§q4(JK w_f _Ve!"<>< >/Rj';UTGtݗh=yX cC!O1 Sҫ^g0k= i1OKNajx~86X)zZNnS*~eF?~ qurtZl'^eؘaą'EǒV" \GP1@ `/Rn'ia&*Y9d7Ғ˛sz2^xgFWNF$7wTtw$( Cg*cvœڗ]*6L++;4ԝ@Mgf}g7Ud@fC)ӢAst\tPCW~F7# ։؁[ a? Bdx6ՑK\2)G9-P~vE Þ7[U&$<*ž?:ֳ6_9RFYyV_ ҪȵGpթK$dc2\,Ng֐OFoMx+Y\.V<Aemx[baIc@\ $5ZW<(wOJJ2 RIw.C|HGtu|EH; N7υd8ʨtjT $A̞2>nrrrAKC&2U4[#{0hB6\qi*1.q"ٟ즧5 9zt3taH-ֱ4%b(Rŭ\QAsԀYĊ jȶ]{f:)$:Y_zՇ)\| kpQb9X>{'K>}dku%u(|A{!7$#iF,% LTƴ~vxF[Ux́y(8U\:.lUDd7riXEĖ o㕤f-6/3iKOq ="_%(nYfnV# ap>upR? 5>H HK8 n"sټ5v\nmrʟt hʞV=+0F{[*?k_vˀvhIAձ:sH6J@o2j /EW@A"즅OwIs+ zK~|ބ#d/M^SAFc^*p* d74kqf6лUW^1#-կRӷMfU[RA7~&Ѳ#BM}Vkβ#zKr/S ٨s nKGewQa8PŔsv|ʎK|EO7ޣSK7 F=xu R 'iR*1%/` byO:1V] rzEDmg: AfZHf94AHf%!x ֨{b<_ 'hDzF̥J[VXk3Fn&D6 %&Cϕn/̩F)5aؑq k*9Gk*"ܼ[;PKҳ}vujtydcyK1qW 9uQ-$u[]|GFn \R*ǭoD \!:'Dņd3YiT~LʕapvF<3)/>$J /t_OSǠ֍9d$#-(No}0EȦ\?8f3,mQQb:}eXy\0ӟ8؅]l*@h.c,pK-+B쬂7N?L}_䝦/0DZNB ,%Bo +D؃ffo0 :Y.nK:ׂFdZi[ɮv/ML sk`-vsGrWS@ ݡ|Bw 0W(v_S8zTs)0].ɢ@'B\ڋE8+JnD WibhhXl@+_Nr-|z @rͺַ՟-3ͻu(G¢:B(׵9r!a`G2C_ fm`jLE4pTϪtdra? cx%*C~S8ڠ?n+25{CCrj}VY?ۯŎQ4"7hcGқ,+rR qq;ƏE$ʖli8n? cGzc@]XpEA%)Mdaa.9U:1BR2luk.9_n 7m>98d$Ո"A]Ǝ8^Q ux62pWv$rLXLJʛ>|%d7iuyUՅՕ??kM\Rl6&r=8{ty5fQiY ʹ\gpg%ؕg$toM_سllD(Ts_i1%0V,{3.oHGmݧ\vnr6ݾ!>٠Ywǽ?guUF(tΐ~G0WVJd廌/e ʞ>IEei|M.!x *5\m4veTHYCox~a6BS/YHFg0tE<2tvP' $B=q7"l_ie_#6Rl 7#*u QW 'S`֠?vnnٷȈ0,jܸ.LJP7h- zS"J6 [HKӣJzjC7׋wb"͡2Di$ch5 N>;2z[L\J0L'B- 곏乌R52rzlKj7p|\@o n n@,,@rti?!ݮ}oUuPtM':(uYn{ sA,GQyE\ 8h7_,TIjsLNMQvK|vcf^qZ]r_ ` R^ւAq` w~P[o$Enc;1Ӄ6/lmS6V]ZPY \p$k-]iG6[06G21+~[iZR@o_uFz bnަZ2a#n T'm]$CnD5= -vמ ؕ^P2S&G",)} ˆ0Q:JWHWb4Ҫ/2)x!3uE>]R[D}%'+ g6|3 (,h}8z36j~TgđmpXIH6n2錹3P`"C=&M-T'B;9gC;Gq;|-7c^RqpkTԼD4;Z{XTOHƶLj` z(׺%gTY )0BzI6XN`#QYXwA7O fZͦ<1W=\0h hYo}CXf ϯ su`wQg7mFxax|6$NSb uw1y;^CPap-sƄoEt`Ϗ/҈P+[%`:[h"kl|89a].g,Kc8 yz8x&pfw*6j;o `hPF O\dF@J*Z!󶪍JĔx|~x 'ƳKUh4\*Z]\gUqQ 0vhxd+ɏ ~^D^K_Z$ߨ6uB%-}wҎ^MG576C!1MWU ѱ<2^RI<`41m ;OGq)⿳3p !^ Y<3`k߻8Wh] K[pףK w3W7i C~?;gmay7a}3=J,'KKeۯhW+uL ϣsM'Z4;*q= V=eɇ)QK'<4$TDW9I%PP1)?z2aFm?wC<v}u D<(crIJ]^L!^!A;1 <,Y7fO~XK&i6!@p: m ٭Ƥ#`f059)*+IKoaOg{,^}j[ań(a#\N,g g?=1#{hQ2EEI"f-OaUj]؄F.YiAL8m[FaV ?]O{X*8K*x0cۨzȄQ}Ip(yy.drk Jغ9-?o#eH4_taUʓPm f 75aC[)KQ~h|{X0ms︈kPk|4M*sۻeaz* vE1 F ЁҢεي=Ogt"h(iږǪ/hRT҉Er buTsr:6vyy@.fgiE/Q?wyQƤ&ze5(%_-. 1hĶ`)dLJ?88HMSi4[}B(R HKNK]TLO|)[-4 '-Z{asDssKUve&wZXj4 rB eA%`-:hK.nP9ߗXFB]bbn=S\#,oɥ Ox j@sVJ7vP('cz] gp=zO|fVQǂPjQA;R_jWZ3R ,St0VmZ+ѻK JYZW$͓fgtn㇧vpe]s^( 1 ȑ8p #V<{!,\&. [E ރ~pԫӍ?L5uwp}oŠKm7o)SAϭ.p^f 鄋 [; n8 OxGkA8Tw}`tGv,"b CP,A8%d?\/+c?Z4mSjͼE;05P=lM8!b\oz:.᫦XZZJk]+@L9}{l3Z81cXbq1?Yb7sZI{Jo8i-73p57lSF< :ŵQ5!$BcbR72JldY):`%7$F8ǗO}l>%h~bP8p[`XtnTԓ4mcϭn @#b0, o"a*pLMpr}A$yd%CN鮌x{?p>6r' &F 7Q:G${F􌱫.OCʴ,'#W](6~Amp By`HZ|qM;OջEm+jop֠΃i՛޸cj8RP%ф t{ ]EpPCtc0U)$ ;VlH9HLj_ĺAڤ䦰sU&>*Eyik[;_'땜V)bU)7&{ ^|];M.vGRc,-L< O(L;FlQ>?퐚sqI 8cc.ef6xoX ŞaVi<6 )`@XLRRaד$$,;{msGt0U`?!ctSxФIELbIY@=ңm/B=C j8B5oNPıgqv֏͓$}v˨b>\cRu:VZz9" ΂ٜHXϥMQ Mh6(;o2w!Mg耙#tǝP[*KzeSxTh#Yaz7fo7V:MAe܆֠YHO| +rH&'iaIq"#/hɔ;(C]!6^҆cmzeh3n[ vr$n6gx6H޽?bYvQ?ZydJوie 5_b~~@?BݲjA(թm`,;u6/H9ǙҹvU6&[: ~w]|R2bz*π_d]Z$FV87{K&i2N48V4ɥ $ P]"I.K>HwPR6aX0wa߫M,r) fZұ/1a;aDyby+~úڹ  gij'{Կ! CZxRTz.G!d,Z!SKя{Z*t{>Ӣ0{jknx`eDP05pgA}R:{E嶠bֳ.=d),4g%AO/#=m?.-`|oDbc SO0F!;ց*"M6Z0}C TInta.rA`dٔ5Ћi.ֈ\t Ey(: >HFJ장A~q 6@5Wrפ)gSW= gUs;/qieӢz-t xuQ9l7VBNge҅?xF"ME,|M[+*1:t"\5nXtk~6baaB\o__6yuQt[[2ӭ:g~D?S|Ҹ9iB6]UΗӨ!Zr{2d?^@<'_a2^uψ3&NqxLkjތa["' %)&K~o𲁾R/Z0wp9#ofP݉~tS°ެUD5\Ex&p?HXSÜ v/+H6䂆zZB_a)lP#-mx|~;$n|&[f; kPF|7a:^} O5ehֺxݥqp/͞Es'i :0A iػ>+C\Ƨ_'xv>X>2f (+T)LN?{pL٠~pWfok{a)[uT==q%h(K50FSSX :`&(܋0I $̘.0m* u0{EtAi4S;44 GSڮas/ 9Sf!mb|Ll+|`ܡP:ы$-*H駅E>HF1-۹.Պgwr?g;+AY 9Z-'emݨ 93,%p#OE "KfsȯAPfi26s. ~.}\:TJnG/j^*oH NG^ LA,,k뽶;۹e"-YʐUEw@h2ڱom׈Ԃwu~'@mSYAcyĮ2\HẙŽk<ÁM:/n(姊q1se!|{;z#WMƯT`⾡&;n3 T<ܸ2m>V(jOnJߠ(5J>a=bҪMtWT'$KQ.Lqw%Ϡ 3ZS9\I&ޗ̊|<.igG cE]S* 'JjNw{?r+˩uV sxX^U:!@\@%o["ޭX06vHHBɃ Hx2ӒveExWㆠmnY|}2: QɭZx ^$W\ema5[js;s ھAG1dê[kj`Q)AEc ;帰nJ4M5Tr4 12dsyD&J0JhىAV@!A7_2˰eEtPoOb4+Ԃm|i`!NI>OCBq\Wj%Nԣār WÅH . `75_Ip¾ԩ2Y_sL#xaΎ%ۏnGscn+IasRMck N$[:)Iڌ\N=Y AyEd{ $9*X{D/3ô.I!}"=1Ӊ"Q,cc5պ QSe@|E!m.Z/v샡v}!Ke@DSFo[_Ô<Ȕip31]#h/;h ?T6>hu`s+.5}3W !^Cq2!'Ӌkm޽EFpkhի (bJqb_.CQ#ePT2wwvU}@oLۮhĽkuY#1<^RwZ];UZT5Ns$/IܡuAͨҌ{Yۉ\+B+q/ CddHŧz )Xq4Y}cl^Hϲ(4-ۣ0Ϸ~wQ45Hr*WgE]aG>sU {LHqgY VgsA}*"oB]f/T|q|aY7M `wrCNbGk0$1YztPOfWDHJv>5\MH!.Z;+oD#M6{ fRǵ>Pݾ$ߒ = u?@ P@B΂ϱZI@]DS =5{W $iCdm8}^۱?[Ż ä~)Y/񅋰rs=h\0h?)TPϙ,,W5x4Qy֔8DHp?Q֟0-Z~fԴ;5˴8osvϋ=XRUMhCOiW|x&QE_Y[#8 o?qdUx9 k 6(})'!3*GŻ=綾Iv}3C/VGNDWq(%URi)UT+8gt#SJ-u>j m 1_t;}4,<}[Li[ҠNn+o 0IÙ$ҳJ yȜW  xI&&[S (F h5!}))*~~?[=g& 2EoǞfQX\T6]uMʄ:㭐$VprP 1j>MTf.:0˨7 :h m>mӍP1>~{~Kak.2@<Ӊ`}g°1aE;PhU:>S<"S8`b 2絻G-RXMCϻ.XUyPe9<'#fێx?v}Ͻިr@bH/U<$R@ nnUeA[ִ,[Ξsm6 ղo`_`5 )^6"W{U(+Xbx47<{B~,4:=9X.ӗɖR&N;>0nw{Z{=UK;4a&0șu r4 |Z{FW,kUKgx⩵RJZTN*TRJ\ZݝTb#W^ Cqg wPu9BЃqT8dEtz3RH(:}'/SZK[Mu0 Sw7d[խ1֫{ 8;F>i $܊KW2dw|3~W#Wiб <IIF/n(F6oaaK*~驓rB"vR00 }Iisk<ۋcUz~4.VP ^a3TXG(1V|I6Ͼ$\lC0pt8ʩ"np޵j s ŕW^ L n|&ɠtdxJpѸ^ {7ГCK1g\TlWo-%SXK)لVb-oa&^'ĥJ8e`3/ˋ}ZIpTi\| <+6r딞~Ӗ%B-4+Ek|(+R^)@0mY3ss{S?hoNy~ sIrl:=KY~hUw򍒐#݋S[J-wޏѠ䦯lSpg}<EIkJpQXc]J z.F VꪒL쑰m69oTuA}~Xh*)uו*-݁[⢦UhsqU\yo8̼{F&F[xG>IH<،n<.ZGsɏ #KG1qqNMRWz4˵N>7M 7{@qH]cem@޳FO>~k:$Wv:DVݮ[(k14GQvD<ZG0>O{8yǧwPo_v*[&TH6[^C/S'R!98^ylq*S0]Xlp" ~YbTՀGDpHıIc^b,\.][3+~m.,bj0ſwuԓwΫ#XӓqZ>sds`rίqrVwU@wNˎ = c7[1{Zޢ:O!RYu"ֹelZghgYJ:J(p1)O[l!=:( 94IdS_A{.i4ϯY*u$hwwOss}JOCZ?zWhU3_-ToW{%hbQ}_[5#1T Nƃq}"a7=1=`;]y}lg3$e1^M'7Ac`S3,~5#52Ȕ4.Ϩ LfN8QM}f{a9A3H=27@//>=RߕR2*[ccCO:&㵳_ƻ]w[]\g3f?>M@dto$ OIa PȐgqA ZG* =^~s]¥Ԇ])|0OjRi-4܀~m{yͬ1X`iJ1h;P+Mlea>"+*!13pavJLk4CF&[R'7E $ vl "CÆ,ͯӊ kK='#QƶkV1 Z FH0R|VMpA~A)fnF :ϢL.lK 5FI-'eIJԢ&SIUmh+wZOu8\6=aU Q|OsGFnq!G=Sr!Pds (r[K575=+f(;>ٛ'c8r7yuanXm,jr-1aa\jxo{6 ӜVLI]˾jt=SM2l/7)=;>e>۟oʺLml1֒DvM„ ȏ?-9`>{*|L_c y5}?5,?OkaB  JO>ˢ QϪ2(&$cUʖT1_z=NpؘJ|n7zgۣ/&aeTd3 Y+X jJWY]#My.NhԠzkMjzJ9نme4<}p? Lt?&[TIr?SOXw3ջ^rFRMOn5G_aQ3T^ ?gɉyAڼ=wg~;:<gF "0F, D @"=f_@ZZ$%ߢp8=z =ˈ꩒,D@I'm/Q 'vDO>(OQnf$+L;qGoj{qc5 g6>qt,`L&D"߯Fi" Ti>82|w;a9 \' Zc"4fZY7F V0QfaT!(ЄGJBf#ٴ_WYI-ȧo:N/2W'sH$J=<cl`JE?ҀqsnY ;{4W8&9=QB V$:?݆ϚGD?2"5 >QV=Av[&A#,!>C?%(7􇇎u9wCou8A@EO|mRyF?4rjSM3[iż;?+M5,LRFuIaZxz33Oq v4 9Cjtz~L8 A u8Yʵ*;}4gPi֧ pk(pe\Sr`e]3m}wY0P-jbY;&[^[(E0`,=)ԂyALml\-wcOajyi#G} 2QI__YE%s:! ZRg`,D dydyj/T1|ilL{jw FG H@FTuH/,Mf:eWϼϡs!E3/ir<f8|=c"ܠ|Rq?l!yPm4*wM{QOo[rf`.I0F`Tmy#J/]o#3@o(ܹ>qvwSj7kz]}=VҸv?'C‡BȂwtRC&ߣ̪!1ŃyDϸ D&4'XPGFH6#w+EH WOc T5@= d̋~hpjW9İσRh|%Oũ燔*=Ytr  Y`<#nr@ 1BqD;kԐf} Envh"2H xs*A%GiAVyI{sx~4}C~9(EMWGB⛫&pSK9F/;GŮS.myi~Y>2S&y%bdfB*' 1KQ;%MzP =.7I"4R4J޷}V8)iHwX4֙P8ϱHhYY݅vtrD4fD禀EBd<}:U+G-b;NR ,yb@6)3K8b?Q߸Bdc06AF w(CGXVѹzS(6L[lQ9o9k<_k;gc,>*}> !By80QG8`pTH:9cn5m7?EPy.%U!MP68e0Lrxƭ5wiu>{/%Br 3WG1fi=g;h٩~}OI!:έYY0Rtҥ;zj 8''՝2k//F0}drsQp6nΪmV5xX JDlC/fC*=|| ԛ:7wUGčy:oJ3J(ےCD1O8 \kkAPB^r>s3H~#S_M7sn-On-k\i̖-(l9KeX{7N qwf<֢5#@{;$p̿o1Ywo}fd>P JR|f-<_SuUٛ:9qy]ۻkK8u@ۛjrk3gr`Ӥs{dVYz$N[zlD>K*#mðV6{z01/yU+ 8)F*:[#VV)ߪy[oo/B+ubQῧ刀m塵{EØeBEUJD<[8/HDmLh~,!l R{u}]IW뫂ońtǮ#M\XCI\o p $NK!(mZUekV~FV&?Z_ӺoSߧUY@ϣ|6J\EXMeb!yϾ.y"u+;!PQi*b)fˬ+;HhxчS $ h"qb+?S Iegi}Pfgbe F!cMPd\ i\J(oVN*͏֫ꘟ0$YQ=:FwA!l(gd޹cDm6|~DL{߂hlVv [۹רeeA2+c6QNNf"ce%Z̨e+@.sMeakd&)c`ķ&.CJ wqCZn<U{m1Y>&M){H_9ӅH&3Vx/Lj4Q\!imw0UW/ueqΞ >PEp-My3 e]'s,,6px<[AqwP(:'G]Lq`ͥ^vOH^KKvʣs>dS' 54:Z6Ʋ-pB!6CY 9(lڪV㨂M&vY_}yeF{fq+{.}oJEb[ Q k!J"̅ Kxz+1lw$rڍVBڠ|nXܼ0 8/ͻˮP:l=fԝ>s(|q(W)$ߩ۠^E %9tiLj+CVg1{Qz bTPd g:"sʼlM8fBZ_dz7WNFQUGcP=K(7 S؆Y^ɭut؝'Zuz>*C"XfL[R⮾G[k Z2 (;L FץWr g=Ys1ࠛA:AR8b[k`{ؗtƁ >!10?ƺOOPHTu2_ ;y{ GFAz4YDMRm#Y.92m)85[&>Yi:%Gu SJ©NSk8kt8u)Y"4]VֹBTR2MZǻjWW&!2r\0vdH=ߵ`OQT͵m7y/סT]=P2p1i,XxSI4&նh[<9 DKKUJPQoiEU( mGt GPTHtR@FB` i)sqQL}/o:Uޱ2#ث_磮]o7O'\VZ6MK08+Y4ip\6cx' Zc)ia 3G$u\-)+ ,ˮvPp {j$@ ݠ ɒc>eJ^GSM/zyLIV;۸KO86 ba&YG GȤaӘl6a\6 GΛ2M3Yra>[WBe{V>T3-̪Mr(+{L˥EQyllkudyϻ?# jmHO ۠W2Sh皇d٥mC0zzD5p\/f3x|~6z~;+HuHuwmv|>oizdff@́3fD2wիF \ur=C[v\>8@.522* zK,j@sfBs-}BC'$,[{ϨuJiF| (#elW+eqܮS/e2yH|_1'Rg3&eGc1gp9w;p}?g1ݞ##LBt\R:%ŀ 5W%3sSPZͥ_IG1ӈd%!?p(Q.! *K=gsw;2Y^;9s=htbZfjWju <^īF ^SsWN`ht:Ct:Ct:nC#j=v=VcM^~w+i4ZMJJw{euw=h3{=t:C"" V^NWȵ}{wmnt}k|<ĒR_,_߲ၕxy-m7R&00E2 L%D`탊_@؏ꦫ8<Ӯ wf/o_3/ I iMbsi$.w,$IGޮU[qV[mkJ1I~~cql߬H=Javbv#?}֋\X.߷ɾ_y/{Di8qv6y%/5/uVƙ5INIޮ}i_Ag7%7~T7G=5-yS=͵$Es-$Me7'Z&.(U VwSХo죥7}i 9i:q2pҸ] rϥ9,E=Gj۽K7fXaA]t Ap*]=ûWvheAg&S03ɼ`/>/G:=g>sx6s}ܡ&`zʮGh[vLxϛs}y7|wh̥$\Y͉tsgxǷȠwJO|'\ |2X/plcq4v dO@]2 L7,E+'o>XBO`NɷFrZ%̱5}9:pJBƗ"2ݭ-"t+ϵ`$FW:D3 Cʂ/eu`Jd)`:/뻓^} qXkջѣ똤gNVΒEU*K>r:'i##56|0`cK.Z:_7P(d>,-ʡ6laP#|dUi4$mŵ.jSh5v Mu5T&\^Kt։53WSn("dʀ (Ϻ\ \_T!pfiRЫYr-M (2f68.EeS]^TիVZV%*Yo9CO T<2*O05Y40>h VWPSQPQNUӻuSTQR*dTo voP̂-{s_cv'pZ%*R_şT7OytXH +j~Y40"4I9i\9mk{ⓏQ0zr@ Z!mrK5Էc[^Ź_ F UT4o^FF7db1[Xwjsjم O_jL5#طE7ttt`֞Xw(=>#VXiecWCxE2uD$-~Rt?% oK"aclzT8$AgY4b)E'χӠvծy8k]P~͠X|ʾ}ܵLF/ HYc-nc-ax{|5&&cp.uQcJ@k TsZF @X/aQ b'd.k#  9$0}Qŕ]Luaˡ4/+a_KXwU "HbeWs`,;/ fmT$ڷ#õ-u3ܢ-ܿ?C?O>枎^ R yڜ w8sOn믾y<#R0.WA_*Ny<[Om,VIfSd0RY!ȚQBj#y;Fvcj=G]}7wvwv)YgbvJ#( LnυHm\b^r"u.]U?ziՐQƂlT30|,iȶ72-@bGa WРe)&!SjUB+Ę;`dFᶗź{ KWi/h( c,id<uq>;TwM%_qKZ] &a?9h_9Z5 M $r4>jcdoV SQǠhsu\Ysy9# ĝC-Ӯ:k5}ggN(h AnL~|KG( _Oe>rI fBw<64ndEDK8!=ΣDwy_~VڈA`t3:!61ShXrV*߬Aأ)X.y0 B-{CB@k҃&O>i"&4~e{cq4 8)&NH`T*JNݖTHK-i0ݐT,Dg:SC$nl󴊨qӡ_8ѤΓ0l61'foiuEc+ `LGy'WS8/"%״j' &Կ^u7K>ɦ?Wq&5q\XUu[HdU:wffn=FT&rqBk4q%ٸ/?͔qIOCOnvXzJ'&wE#h` لDVzEjo {+=?Lozn |V.(2`6 T: A?$ vJ _YT(75e W# W-:[O{"~0}75:ZҦ#O,?1hXɇaU nV%fR' ާR|ǽӥDvrܼ' 4%@0VyV+bғHʕٕfIb%}S2nd[_ fTH$9Ŭw7<:pӝ_>nE-}̷PrJHnVyuPĉy|;Z< gS 裶^wVr/Z[r}7>yCUNÔOSj# Cy%~c}lb]RbkuAQ[#9*heU|<0rO?#ܚᕊmy9+4<Ѩf 6po><8&UHjֽ[4~b"%ʸnfN'7L鐍0RN6( A`/A QAk'4y:ѫϧ "q4n)}ב'gt33CUځT/Ξuj2NYJ2slFџmj&UE r,k$XX.Pɀ@ Fp׎&' +wfT'AE8:<=bl<Ʒ#1RRj :(h`bOChdtR'{ $e&_ZEŽ*#>/3S\I RGgz/-5f΢Jw2y\q2p XL@6ߖUy^qfHLpEqwi7de3zVǙn<_}>"VDshGjz]t[ tB 1(D<^5ULzm %V޵Su>LZnه8هX[g;kAdtNO+0"3ezH1U ! 2@PbxT{}*){t?>0! HG#5$zlzW#̂B( ܰ?;Vj}$>>bMr:JqNS~0{N#gMߨ$vude&,}ـeqϯڹm } vA|/)61눳ͬ]@ :߁E?l笾4}&JrJ=uҕ@h̋g ?W.S@ae,$WKtLC:$q‰u.%l?QgdG|G\D xD~4>k|uMe䶩V1 OW59IaPl=:+(Ҩn#OY1ߙle] :Ifz@ƙ$Fi̶0s|X8iX_ x 6av":,8FdH,rGz .>" (7:ǰ꽹PHI#ŵEp5-= _ʯ:a/7<-_4iid9jԦPxۖxb-)x_@a=YPamQj䔉e4Y.2kgBA1T0T% }v|NjzwY=L+12꼣li}3% 7G]MPDD!GE->o.Y lMjB/ B'zBT~|zʤ?^ikY!TtyRSᴹN۫஥~ݩWᵼjYsřHE,ѥo›-kP`NM0u`}VD+E2|[)gBݝ lzMˆכTY 3I(3iǏ)ɥ=Wi7i,0eyK=(Vn|rԩT)J1A&.1n)nhjA vG>$3.}hN:;˙u NzO|CIMdFy(;2@ɥBv F Frb }tLu"Ls:ϟN{RjTOj]ޞf2W_⮿QdsG;}T]~ |VV8/JdYT#cPGD;R:?Lպ]}!uBX9f \Nơ`P/cޏ7'ϔ@zz.Gٴa.4_ jt$Sj=-P5 ndeL e\ӯnT3@Yi]ZXF2 [ {_kW;ƴ~?I;;7_orol5?X:j(gǑ-jI#j}@v%XOHLWBnJ^u"?EFpXT,a~qhv5QgDY2_VchߡNǔZϸȷP"%a.y46[S!;H6tffs)ĸi[){\W;v /*1Q6f{*/_?K,_ǯ|'JTBiF'Zbn'O ]H"IDt,(йpՇ$<(TO/[x.6?sAn^LUedL1AH5TƵ ("lH W*q|m0N#^i1Eje.YEOo#Bxd>yѕm֐뤨1j/w%3,RԀ80}еVhxһV#`\.qH| e>]JޅjGzC_<, ?aʚ{v[8 h/Rf-llm p'1BWDQI<Mr &m*UA_D}WսrbLǸe~q-OmwHmTnnb¢HĦ^*H6D)-9<U3cPԚA.(A!) rU=WkmG{mP0 95MStnrH'B1Y&5q/;g[M6;AYJ[=dur ؈jz:\ggҼ0^wG e2?uFC!w7݃*44Q`!# /d4ho S`^qEa $BT|.:?u_jcWו*ꂘL",Yf\SUlZ;XXozmLX6&\ɭ.Ny7uUf-1Yi;c^cJ*_~i)bVrY"fӚwIQZh,rM"e\.IoކJ^{e*iJGzRKi9 C)d9js-}-TQM5^r $Ϙ'~mG\\M(-+"ӫb+ıoUI,DW7Јm%C}l4WUTW,TWA],E\&ex8C9iG>:wbUh> _aǑnrkjeZ-|Kks5mHQаx~n$ ƺc}ҷ$w|[6zjoE9gEs_/*.Aa&}JMf',uTgK6c_;oVg^}(eq4XyXdQ1.uUjSeM:Mz8̶ըmqz- ;v;vUogKuLkRu'T8o,'YVWS&0s$bF8X.㳎d,NZp5GlࢀW*`G"1 *(2K2`;4ꎴGw 2Ⱜ,-s>o̗fM?;ܰ&Qf:Q tw.P{#%NG81±i u>;}6 [_,Q|3ufSIVCi0t5q{?W;ٿmJe[hʅŅu[Bꁿ  !)gɏy\`˕4|צm9I O_d#L^3'r_}Ǽ樈m0@#s n^}ރ+DoovJu. W$VkWNs?TM3SJ+XMv:n^z˹sTݶJ9. o/>IjqƩ1%%.£=+X;.%jPªBg"a/8 ~"VINc*u|cBS#A㦼Ź2qx klw;,D˙mw^ xk(D=54y\oO:A^ }K0ɚ=Ƨ^2mzzkH!~<';G5N]Q(dm+!{x~J(^3]&q]u[33ZժzO=QXihﰷOD jч:>^p`~X:;QR(^C"^@?8&_ CVY,:S~fh`V/J@̋ɥ4$@ݲw=6 !X}'Wv{|l}}4ty3`Pь &.H"gE~w~`﵌\RCŠfF"aJeWS !*>(X+b]Vpo .+;mLӻ_UY b+EU""0敂+#Qb$PQ9fO_ۮ믲ye﻽8ύt0:_{ۧ>U =zǸ)%OR-ͩ NDZ&+UI@7):"W63zsgUDRāּfzD@4 9%6+qqQ /7nm*JMxWvIDe~vb| o9*Ď=PeК FUR˃j GFZj7U}Agͳ8M%Q02lQV ^om\ Tg=3Zi]C&^̰ҠᱲY mTH`,+VTǾɠ6m.dyнhUAȝs9%)00Ζ7*SU\̸WN3¥f/;9Yx@xC|$P0BˡN_Τ)8=Nr5,q^.r(vldc5%A`023%T,  L$ÈyM­ؒ%ic=%KDף5xhQ]TI\W}~Sa f宩*|lOFMkFw@d]>>Ha}/|o}=,߽wF(!O/;:$K8W ѰފHPāaBwZfwktH+֝A/ ;01Qfkh XǙy3ޡ,S BBCP?|t2:f o Ya+k)'FBH3Hglm<KP d$Y:JOCQ.M!<ݶcFʀc^DӇ`*ѾBjf3t!dc-1Ds~nC?nXRWY׼.{sT574A15XLO &h$LbN,٢`d W*kI7 @#!]45NU ?öNh`Nٗ??Q>vau*JTSf{bm:;40" ^T)x,*i@> ~N;BO^^6WtfRϻ#2 .qd֩k:HUT%pJ[d mYWuEC2;ye+<7EeU0Rp¦WKe3(^*&V[VT1SyR+8}* Q"*Ćvo Ly<>Ngs̴z?oI5SMz*} h;fx]xaiv5nVSI}ߑWGbv.s>1OUr2.;òo`~f~ֻ/W%E?J}g3;ƴǠԯ712fF><84˓&E?23/mh}{}HYVuٵ8a+`cڋw}nYgwuKuEߴwe8Lj,9k{w8W(/fwrttmKKf\muj 9%\?FO7[$!N'G)n_g{9xx}wk;wrխV=ŹgCMW}TM86\y|1kS{L6 vsSguIe{%80󽆏TxeyFt5VE}cHFYˡƿᵉtOwyȳ$" gR/bmo3{Sѣ?]4:8I9R/D2r.[ztXr>=[{U?CɁ e#`%opq{ AAf AR;Rkpqn(X f 2߹cr$sAY D"r$tzmZ?U _Ix2Jr vϽܝ@tcAfpMg‚ C(?)d9[3:Ah(4^u!.>i'Nh`HHAH4};Gm[:"o 5 "#1P5ٍLfiRxe(aQ;_?KV(PO"6ZLwIܬ?Hˆ**#0 tvNWciB8  ̡WVݷ_^rc;p/;]2r(+ $ sshI$*5꫽qFDm ex078-!eΰ?[&+ (͡x1`dNAmI%X1CIqo=Ot eD°-^%HB(7Vd;?Llɐ%^f ֙i)4!g,Hȧ̐w ℍ1}%<;AMxNHV_2ɋf(bM&7~/T;vc;-n;ѝ:lT(kjJ]U 8OehC z (}*٪O!FP^uGާly}lp21ﲱN/G"YmM$-)Ĵ %P~  <9Ő-%:6>jeiezrKf㹍궝5?ڧ‹x(K04R #2PˆqҴH'}'f*C#,3ER'3`jzeD/AceeOɨbf m8F$\}E}?>iKʨMH]`40`wQ|廲Vp {/̬`1E A{^OTϺ{[mCa*8 m"&ģޗy{4%VZDvL_Q?vTVp]x]g΍T`̼Xc%!(be#f w2_KIOGi*ei']¡g v`s D͓ MvK=]l*7S̋S K߾^򽅆YX<3[;1JP5zlѠH|B@/`Z@\hSsI(]tDrf;,|erD)l'EHT^B Oe|3Ts F=>g9$!ԿN]޴w?F#/uv]ibJd={~7}OQ}6IKŊ6(6gU|KA _0PO/oZy y'qI_P|0Ժ/+\~l ) {/6`%̌߻Bc>o*3$V|gt2pU5q.T;<^ j6n=y\kmmZ Ӿ7gws ֛Pn"RsȡN 5y5Vz5>2-7f^+X\̣ԃp#q엉&ŋ6 GS ? 01{$]i7&znC6yN]o)H#㿺? ʩI@S* qu\nE0D~}{Mt'UN%}kK}nOKꚼVd%! *}Rӽfmp,GWzA$DdF[[C ^~_`?wb,Ik6662Ҷ3elfԛ9!MIx =O)}'d(;5. \?ߦjAp˺,UmE=\*%luAVay@,I\y.'\8,RBx8x.&;ԧƧHֿۤ{w s+u!$X!9^#n>I'MlHLnyڼALMl! UQpcNsڳg!B-[[ofZ6v>V[]Q{ z ٿR=W㞚t_>+7pkS]Qk<!A?S=-MT}]:+IŷWn޵ڻuvon,poo~)K8Ge j?sGt* 6XC5_ċ;!OW)Ñv+Z"Rw"TENH#h$6Fh8ŮƼþwOv)f"ıc'c#) M/{9G=#<byȩ\RySYjHJ!cX .=no<geXA*Af:a$VVdX1Nu5.}UyqgB0 [7uaWdL5Gx $Ku6JF?&oB[`g3-qƿ9+Nkx=Guzn5Őm7]y{oqM|s,vp-<('bտZ(EAB;]w vx'U*## q͵^0޳fg:qfQ(]Ȃ>,w e[@"RtM_dZ,Ԯt7ge:g-kX4eɈ*w!%pجx1(%/~c9CR#WaA~{V?w4.vi*Gd"dHf*Ak SN14] pmSc :u5s >?o1}UdF.*R\3Z@7I˖N98wU%x.֢YdmqD=1pUn?.eƆ,@~B7 ;1-TNd o+g^z԰(jȯ|),JnH wJ$20;d [vc H򨾭wfc Z42 C7qJoG8%V:ư4&;=[uBxZYJT}}w ZC2RK" 41?V&JYwAoY{.hD3 <XJQ T$Y5S LT}jhoΠ#!owZo: kU =-k޿^V.N]%BM6 (B0TJɽC>BRֆj~4ϒH7幮 !,y (:%3n,}N3->/߾Vsyzcd?Pu4ND@{7s>ݯNP ]Q_U|WZҷC꜎R,܄Goܧjsl9RLBEav)~WNu^yaz+0׾qWWX'?qw_c'eh!w|%qV87#y7L8R !)ObM`v? }Dz{o2(]<'&hn>?dtxYU>9s*UyڋFƊ8H50"X`h3 BP\yĪ rSA򪪹nYVd)~ m6[o5X Qt)DҺbѲpC <mIcјn:ig#IΤgU6ߟ!^E4AkhXYWG/s9K?YJ+ޥhʔ} J]YwT_+|* owņcoY^HK7[Onl-P[@blx_<![ph8b14x4?H3CON8(iKw?-iNmqQbS^w k+DXxOoV:'{ f~SA.l.ZC~t AA*A#J tq1(Kf/AE6(CæHp>삣|m|0AC 0D_5C! F v` g rv֎CT⹇5d桀?k~,{mtmgT2 h~=\xzi{Ӥu0mX`vev}w:U2xj6|=Ob<NR$$h\8v""Tu֕j9ܨ49l,cS(˛CKl|mo\]c?tjqpao"oKͪ¿aWo LXeQot`201ZGiQji;M\;fظg6yZ~+Pc%^ab5\T|@[o1F:\D,^୞q5|_!XH3*-@}0\n_&S_aWRփNܛ-0_3^~rEl ?j&TդzԈ3)#Tؚl%s^d4N||`ĠBF9hnS2ER6V*;ϫ\ˆr;ΰ5zs|e^MW!O`hC^, T`t*wUe6l2֋ >)4VwVho͋ l~u/pd=NUUBQihhbffJ!dg4`w[|j4 njZ)iy‡N?wzՅiѝ<{\J6;B@i#&*:@)T$1CiB=] T^Pap{Iaf4$8l JXP0*U|>>gh?30`TkSױ$(1@߽)^NS?x |Ž4w=֥sCplj.A,67W%UAJCH0czD>Gz*0 +а110.7n2EqXKi+)1kCAP Ǯ IVQW22)䄍xX$*/߰% W]{9{=9ʫLKm8x݅soWCB=9miµx CWrǪto촟{sSe-dj06ﺨY&aC%ԭu1Œm)MoJŭc^O{֪)АtRÙ..4G^ s3%KW)P1J Ԁ" NZ0tHSb+ez<o wTfY}/S!-_!~hD^nzٷ`Q8zhn$/ ff %jXv:bɖsKRR/ v3k.҅M+M2{/gIb{@Q|I,ܦF &7$q9Y.ug|+LŘ^n.2J[v z^87%kmB,_8x/H;}K[!h`dY!Nθ"f^-REwO ((|,biYf^WX-6(Ӊ0Үqe_WdQ2LiuYwN#yJ~r/m,_K8dߣQ lO;z@w +L-O}=liUץ_G8uigU0R~eW,$тѵq!}J[PY5aƏَi5txlleFb>75mڦeVGUm'WQ,'dc.S䥰^jskJG]8  Wi5ĴL2M<_o|~|Ǹuc=7ɴ^쵭RÚX??,ĂHU1m~/9c%S#N8jBnK~ֹox ~597}v2m޷Ee=}1dLA*Phɬer ?}eU.+ >4(,ߤ#3b>;n.F2q*]~ -/jy}e 2*#Js0*O+ea>0 Z#P(Z D_U9>|O]pBb"*͑Pyaz~U34FjէMIg+ǯD Gw#>b *W/QP1>pcC;`6Up8_ s:6MrKQqOShv:+厷d+ndªF>Rת ;N֕oa7N&v?#7ZnYTXXXUW[[[d|La'O[sL*\ndҢ=Pj;I*$j@̊Yv]@ֶɷ wko/,/,//,nn..>Ƿ/PW.1@*1G5:^w2`r-]ɫQ[vE:jv'} &А':ť^bwDc݇oH{FSTB2efفX`2U`iB]H״l TiYDތ9,a A]0CPHޞebzở?Sb;^._zGبz敤Yhea8IU`r1,$=˧r6kq9 *Inޫ3=+5Kϑ:ɕv=vq· ڼ3MN]?,&u|ON}2 i^ȉ $@{/#7״M\֠U;ۘY@UZ&tKB\s+Xm.!)iPK$5=f (TqZ B] =K+)!꟭4Għ%WSȫu[~T¦88;1ym0[ՅۨV/kS7kS;wY3jo꼞6]qYkݥ:rw1cg#E k}ÌƼJs ԇDžd7|_ z6i&fkX]FwͳuV+]ݠ<{;dr핏.Of^^rw{dp<iv9OdF'nlh8 OWl̴N˅o<4cn#%[w>TV}tItHwWh^bmOj\/Փ^һؤD(ɘP@RM/&y 3+K f4kߓacʯfs3v:?TV#d]W]f^= *e jCkZ smNK_G9DFJy'"XęS@"'n <^RGjτ`snB?tt9N+]ʫ,չO@6#?@f7[e>gy< :=)#{ݶwj6Jw02Q<ژu("LBM։Nb9GHoǑޏmWq4 J"m"%2ŻYYk}K+QF(1VQk~Hs{1z18$}_0 }fi)-ɰ/lm7g9]s{84[u-)#=.2f.2O6}r YcM"qm* uˇf^H\.ycg ӈ߱-1ó|_~>Ȝa7mp*fc?Y<$2)*IXL"\&] fn͵ @0m5d#eێn3.l75/.]B# 6u|zNWm(|&sh'H@A@}(:pUmf:"VPc2({ʾq&kw=Vt% NSq{wM%U#8IXF/o# q6ŵ3Wq8I?8_n܃K(MYrAOv3@T`$e]b""rԷȱ:!%f"ܼ2v3L 3:]5l5%/ ( ?=Nt)fA,/ӄИ- ʱ7ÛS [K)Rn]8RM yQHq(3H&.Mr W.e2fDA+'y2xQLUh8PYe6ht 3 #-(*5[Q(أh)L˥\d쿯 VeX6%gz }0;z/ap!})t{ 'ih)'c-XPjii9'o;05{\'L˜Yqz ;r0Fs;F)A!jrca+P[YAXhR 0|_[ Nf%;x0" bU )I.ғ@JLUR+2M0uRpgQ)]RM6T*F1.a&G ڰ &X,Q )HS"8s(@O} ;Cb??GٰGSQ 'W0-̢fKJ4Sݰ.cMCU=*HX_}zJ{y*lbh,Ac ȉs" Dלr`n9 ayj_9)[Sq3NxM4 E4*lT-uVdYU tã%\5 G(bi6D}7n}y;  ^$ a4#gO=/Y_k\,sD:TPhc_) AQTAz~4Z+u#Z##ǥ֎]x$P6uhzhj%ȴB4^wgv#s ^_ ,.Ӫ ]C?6>A Ymhh© cN[$Y*ikI$q)1jbZ?@ c|×M@ p͕n1RR*2_6GwLQ.bP""f;[b\SXH`6BEjеGjTO('Qn6󕹟fhU5{& oY.,>ǮUy,hhau@-L_^Y"\#YM5;a "~=)\)GjJ c{#'&NIF)L3][kG2$z,WP"E䡌$Mne=&U(C#mc3LHؚ~$e+~ pJiULsͶ gQ1%X 2$7'<ޕmRj\]|_ϥ!,<і%I]<)plJlUL%7YDZԔ,`1~}iLUl07Rx_.2Zh_-ZuRFF & 1ZFi7ijBl N5:@ _}XC%pmsXW'J=X5hZ!v˚'Eq;11} A|bG6ήp {~' [o[T[~ 1P}9pFA~I-UR1N ZҸZ=\iW [*JzdοVYwoT.`|Ӈ.sHӧI?|RsKY2'\=mi| 92:vSfH0"E0UWBn?;'~у%004R|z189ǟ\hjMF>#<>ч [UuL]zuX̢ a H*w7u#t3 G{e3~퍥A*>d﫪ҏ$ ~p1=M /ڒĊj[%KUd47 DGaNȘJ28edp=?3UF?SP>sj)ManS;[6uR˙)D~6 {r00=b z4|4v.L$hθvh722WILT;^PZ:,+c,sAG[W9j.gU!Z}}nMލl Eߥ<)|2|| >L&*,r>ܫm) O}*VF]HehL[rTxŊZ)4]&C7*mԕ#s >+ :^d[} F _UJðproN vJx{՝u֩+.`d5~1)'e;=4CeEԑX|T~uMfm ٠#aEP MP_{n5; [,y"eFZI}[i5HRڙn%FM]H'WM{ktM'Yă8\_yoes2n}'%ǜҲs% V3CZ)Xxk#ߟԝV8 Wsybg~ wNf6lF1e7vJax[*\H4$A{Pa`Xz<\Q vJ}Y篔m8H*UIJ >m>z{ 5ۦtwiM|){%sz[}D̞V{ VU z̢fʦڨVJQժϿڮm gt6038}LOJOvZ~׬7uJDﰷ>ySCp`U-/ <>s,gfWs8ٮYl;I (0 'F9JRW+^m $#4gF,|o9ˮQ/4Pcn/fNߺQ[Gt> SѿUx66~Q QGA`!yqVa?/_h؀0Ʊ8 ]R-<Yrkf2meXYkWa\sEh4ݞxr4_OމhSF@"*Sz6K;CkYOCB(A4fWvj ZIt`QI),. X9~[=iuZlOp"ݭ>rKiRgkd52(_DUGyg[+9 LߗQԑ^-ϊ}b"-cfgl{)>ܥٻt es/1U 8&[T{]P`q!W*+mlzA0{h&r]%]{glkv1/(fQ+|m'zw16< CWn-LfRvMI=F~n]C/Օn76%|:+t-I [";!R!X>3q#|*LCu,hUbUFN c-NyZW< >ɿ_aPʉMɡD5گCj9.^D*RO4r@T%._<;/5~s&OJkrA`X'?Vޏ ֪(^YeaE^=n_:.V(0kJC:Ũ˔x_Lx62ʣ<~@nFG\}ҙovjl0sxbV@NŐKOclUe~c^-LzM/3_5{ID X4+ Z 9 +z.Kց,9vMVi2t NC\7/2 TU+׳? ͨQ)]zGtPHjzOyW;˕D* X "nV{/_;Gt+ _p.w|ΪRȠsE\ٟV]z*0cmrBm.d 37=+5ڢe]5gzT7v:cE),Qov+_yoo'׳Wm$1r&5M! g} 8"S|s)&q*mHf36Z".D"!;D/H|S߼ wxL| `W8>*LÕSBGZ&WzoZ /{w?s91IJYG\ݢCޛ/]D|2,#`Zv܂ ̟Kfv00$}v*wc^})pO#^/d0-Æ]MU9!T4CU`563UAP,>Pkk\1~\_6I|' BM7s8"H[%oT,Rs<Mic4;y3'i DW+ҽL . @J L³jBR *1ͻwRar9:~vU~kV̨:<7KG~4#!W2v~tuY2̣2!IBQKD$Df4A!j_C{'|F'G~w(*ᰝÙ?ʼP۟һ:^!tagƩHjTBaÂ'VRuPs`BO)Psh"34PNK99=7<wKqE C (ffJkeMfaҕkf!%33Ok&=%gmSMW{RXd,K `R\?_]6*tE[OYb3q}jg:Y楘1D'"jx 2Cg}g: Fpߌsm;:*T-F.U$hŚ 1Tj<"搔  oBAe6bί!Ђp#hAR}ks4|Un9LQ&A/ t߹~>hd#0DlF^){>'}.}HndUB| bBT%s&}>/+</~|(ٔg_@(;ulm{ODiÙw1HzE?C𹉱4M9udg߭݌Qӆ6qŷ;}kNQLEj' F2PF-FJjaCY I:3xJ_j0APwX_`*(^ϋ $B" .NFBK/AWVHcp.um" +-xۘ}L$|}.~N6ޗ""% Yd15viڕRc"@H#- n7!~_`>'p7/ t0XeW@: H|!M.yb2C(I^0{s ap'/^FyLQL0͎u3X-JyC*N@K{BVHR "`'~ ݩ֝^*PϪ^y7mQ Ս}]7g'2LpS qJ$UA*d-( ?B7闗)[yOLlua~UZ]kѠ[K{*\^jjt0Mbo]6?/Kn2j!paJ ԩ_g]swtjnͩha S~{Z{xuU,dpg]g]뚺,W-^vOmʩ#O& N(>vG,NL gS^G9ݐU2! q[Y}x+_:(9gymʕ1<>.\/ON{xNΓ~6ܑjɓJ(}|Uv^Eug5* ԕM.u񯫯^Y/IyIY99O=MZv^#mD;j3uSzU,hjսG>mg\N{=c%@ Il]Bj#ː PEQ!^vEH=5M2v{XI,[іns仆f"APTZ:fK05Bi,,2ߓ}Lx8T:ܴk'\9J((xW?-}r>1UOTB:{j9-1"17k3h 0x~ò^x*ұ*2Z}q/) *k0nOK_lNJg ېAO:Km>dumO"W ?P`z}8]+x4P[|ay&2(hѲzEWwtPF?5p;痟so]!5LbPMSXQa-f,zTU4hUSρdj}|EcfifX%Ј/?,u v kLE uEW?Ga}DG(ci\yE;VQQ5?+ hjGϯ?v ]6l <(uuEthg04nܤVuq[e򵱆b-rEB]t]I@1 ѵO-R-/gd 70ueZ 4Q> jY nyLW 7{4W .1&ΥNwKXDD NCI}*poƧr+*b|^feBlLfk1"^E`FNjj/_[Yj^&q)>_&uٙ2 -DO6>`HK"c¾>oм~NϹozPsUnRRz+ ء֪vPLJQ/<#p6{F;?|?2~_%†,.EN}m#;R6E/\lsFmdo+})y9BOc++]jNsczN f(,i`H;agCgoj 3(O`lQ$*>kk> ^=8ݽų#m4ylo ;~&H憒YA9\:|D"(ypƎ@;2tR*!wyNUf%Ax AQ4 ;f nbdVoqaƄn}=vR3Xb]D ynNp$M:[8rQ:2uISfڔx=-S"v`Z \vZ#/90۴JhJiBJJq4iy9Gif"0Qd0Qʯ e^.ԵD';3g3QP_'*JV1Ka8YΕё͸zJ4P`Y`5t]}i1jt\ìg((ݭ(fZgwreP5RCU% &c"dJ-.0`b.l3@,) @']u)$QEDa#IA$?PDB(LQݏ͐AWOcky_;pup0ɃXDHxOR*8\M3dk}/]vGbhnZ3-{ UlK6%sucvzetqݣeL~۝CWcj,䢊 g|eUT.oyXIL)HNR)q$$~-~TQ./DuZ4Q m4BW~/ۭv|gz4Q$"IC6Q:TGUӖYx0 lvc@Jԓ$(DwĻʾ D0fd8BLAFCUKÞcD ɓRj|~RzD;;}. F )`cZ,xmaF #u# #ntM8#[DQBe6jRŔ3+#"`B~RgNpx0W`Ja+1ڃ͛YeXd:ˑǗ n1c{>Tb5ht9}YPyپZSw\۫h.x2EBgHZ ̗4c@-8* Y-P/ eH)9+|qDh@h"Jܔ:  JR_NxwL& %PP@Sg3BO";`Zy2Í}\ )dYdXXf _c~;6=IFe. |EⲇYki0>φ>r9P[n3$ JL2bDKL&W!}lQe$/;kvOϾ "Nk{b8wVArZh)dΌi*vD@^ΓXaG!ԙ@8G K8MWp5*gRY*p0?_UP!bZT%KaG9^[Dsױ} _>&ab{ToM^oEk^eu>/\f'_i?Z k$PQh޵NāO.Yer$N]piel\#b7)}qm?܊]܈x˞(Q{z<9bሕ"|tTMiBԲQudG+<\ka4 H;Svf9(S#]ˡ lTi=Y1ߙ5$l`,bx%iIM-Qjk!&7.Pɂ 5Q"X< 7vf V|*u>%;pF ,32f wma-l#l*MBѸDm7]%ѱ.We _{ ΂ ,jh)bs`o gx9Kh9bƄ)!x2aR++aR]Y+!3lHAu$d脦Z$ܘq ;qPT]i0Ud6W '&+8nߞy;G rpiSuȍB TVWX8331Ka+Aj( xXּ Ȋ/]$`t{Hah3 $ͭD 1i^JCE4=c  O{h۵0H)-[NwTMPԺR,+Z\`BLص@̘]F_ZԃfF~f6] n> "ӜDh;"(ph'X a O:me62Sg*TLEV5wҕ# HnEIbΉGt; |b'q03wڎW,oJ3_11`b͋,/a'2( fVA .mWiDny^I[N g48^5e(sxmEUEJwGS'{}rD=.JD9ߴiCۊZ" /z<,ϗ .&# J"0`/VLCfB.,ߏs+ r '3 ?g^jJf15tQih=g9Ayq{O?u7u6#mlSԱ,4C@2 qq+9p>No*Ko!٘>ߕ;W7cWpn=ffC!lIo )`2:#Sɭ-?l0mmO-} P4.amk 6{jj> ̙|[tn&Q2g@$f:pݣFCߢgƉ5Op6+ F>2O&H0#lrKYު%ڭP{}?y]9RX2рT.^d}>qm!{:Y>ӽ7 +ScZ4Eb04ZUs[ߚr:qUDTNfZX_#Da*jH=U^kRO+}cJwq&Al{qϟhDƧyRޢDySD* `mAv۹~ӗSKTg2*  Wg dTk;"Ejߕ(ra ԯ蚅AŋcV/Ow ic %`A6a dЃ#O=jhvx2 =>lHC>K{|Av/dpխႄ H!sU B8w9X'e؁f뇿!D֕M:i͗2ovg֩= ^xk^2/}w>\wgGbYf6>ma{< w8 <ِǮ2Xu J\Ć/N1h-c@B3E$QFd8萡5"I3-Zub9 UB5`GRU2]" <R` sl]S0 | 4Fo +CQRK&KeЦ ?|ͮZtP- <GpPllƹ)P%B*+.A5'N-wWAj:s9ʖo❲`4g}K-Y w-ێ/.A_exb7G mN8%C`3k3l0ݎc)KyʾWS]FWcY_:a?XRb]~K Z r`$O<VVfƼ}<6ZfBQE>G}TeR::E\}Z:uB$DǾ*6m~?w]ˢd4xK_EZЗ5fAץ*-(=MZ"n%@Λ7cԾc(FoeaiZsuzg)Rq84=0cEmmS_٦>A4љv(7.Ϻ2 pn _9ֲ9X|= .s;{0DA;6gh{Xi8n0hE -HTSϱ?,`[Z w`Z}shേD_'sǣXCYxfIS&q(H_ P(Ϛ]ျK?j7NC@qHɔ?9ؚՔ!~//6meslfJg/S.^``G׃a5lڮCFGF0mZ6: HD2 NH +Iل5wcIg1&u_?NΚYCE odƢn.7[n_WwtothՋ'+&Nϲ $Fop_msm]:ݱ0[*!` >92CEo߁*X/|0ʙ⾑W]^\!Q׺&FaB]WSvrw֙'\z]s\|Qb2:UY'xL/H}Mt[vPej1_GAdH.<myS*({3̵C3foצhtWI=yتlS< ~Ӄ޿Wϥq_ވ~zMY1[G[Ew%[S'sLypJoV{,y|]c=<ߌRwUQ@4EOD \ 2纉P~2&R2R άdru_ՙp|iayO⩲Z=H_3I369xOj7n<7CMuPCr7EgJUB!%mlTWAmQj#_pc:~|هѱB?q|J֛k*p9$wo}w!V7N_th${!Z|j_qlwp.l fNtjlK\)WHC o˫_.19]oS4x1TQ6igWSkT((Рjzwb"*OZn#Չmk qZ4;4^)+?6j$7xgHrAH ᅢW D=ln?Ô]B2A lr. ">^O7%J͐ AKD%G4"E":Uˆc9i¤Nwf{I^|1\T6m=1aC];z߭ K}VyW%J\F<ځ~z;<> MdTlS0P V~F3DHL#OU)MF3g>#A%]bCBa`,QiC#"7}C5ӲKxLwғk|G@GL ӢQɖԯ,=^}%r0?Dm{pK]%k}Km8xxL~&O-e&c/%#/֞?%W^,"+?mޗa?{V=A>y֕l'imHj z`[C"+glRQbY;(Ѹ7Cگ:Ѷ<r*O5W,;l#>s+UR 0=8b!<Ȼ8M@]%n@i3x8!I0U̫ۨVKA ""aYlPT/hGi$o{*8:@//OuLܲCSLB~3nE:?#. IPax\|6@AzW{;uPUS: NrDͨ܍VBk]):ebXDbj%lNty_:3^ S`_eIVLI;zv0E]rɑ,dVX. JCykGEأ&;F^$~We鳢!0EkzkԆwdNc2@m PŨ)\?~:کOs̑/粶-jGpH3ewX=,6L痂}CCgxqP^!ZAF⬐6&̐)],2z8wҬT@hVa{@l._0pIT`Po:㷞ZJ+إ];W( da>!F7j,2yY@w8=ܮF{#3ՙ T>lS9"YB yE5ƅ5QH%%Uߨ䞩eq|VSRM#T`[q҅Z1XN|/\;Pj|$>ѡV;W9w:Cc0_1_ n *ѝp;f%u.Xb9)9Q"u`~D>;gIx J>}/ +_ 1’VM3E^\\T}iC1/4^i<_+Rݟ8{)Oĸ_d'-m qNsMJ#/Ղl Th}xKn &38k{]T,zS [[&`VC X_gmHb̹z6+\%Χj{D^u]^4rC\jqE2L]ev!J -Ϟ#4%2BqȪLSD:rtdszX;h3L5RskZ,w+é8_䨦9ǣxO7xzҐo #4~EZ2;x"r+ }gtԓ2zϱ@ajC 36w_c7}|lr+OC ;TUa݆Wp iRͩ0I]8xFzY=[tsҏξr!ڝs]"~Y8\rjy$ <ʤ*_eWHmcou?*X @+FAQ0Ս\NtfVX>(+nv=a{6)Y,-Nc_.wMboդJ|;عv8;gNDXlu 5Q׶ֹs]|1qCuwk UwQ+|^ܕ^ ސEfJ ȱԫ{(h?R@2NBIk NOfsD~-7Қs}l 4P\ |Fdy wa/9 4eXGu$*|pJ֩ .OF zԞ/MaPXU!RK2W)[7& yfe8؃P+؉' cTec2=jǪ7$7eho*( |s VƏ}خ !¯`Npp R:b[(ɔ{}dWH<^$&D<{SMFo$J4Fa[ߧa#'Ɖ!s!žYDȍ ӆ5ħfCw&ΝTBmezK',22O.M"UF1 #m+&a?lڏOܝGkB sU+" ;s'ޕVc@K{T v:gBH w5Gܡ͚x0aQx Xu9^4['vM䑱8t7[otxF]?4" _8d#OW 2e.K8Jvl/(Eܩ׈Nt-6.ڥ74ejU5j2r"_#bm뾥ؠtl/&/΁*U\*e'eudqTJIwp}x$h٦V,V2-Bt$d~uZ0 ȁO/[+֬:" UPKq-Hou9s]=20ҭD_ C]!Q¬YI},?9dw/`_ ̭N̛ k.)"bNQ ȴṏYk), Qd5ifW!1^9iwe%Z٬"!@mBfA_Zpq|~SV].T 3wTB$+ );;\>}K("tGxWtK6;dz`sqmi U`_W]q:@I,Jx%mR˯A?t;/k<c./h2EpQyj/+ ~ ypc,EB| (ަF/2XR/aa膂}"L 8:1+QY.0!SAL`3R7( r gj92wO;}T~йEqErJ(h[^ώF!Ԏr bMo5Lh3\H GYYAgV|dI+?PTG8WjBQ͂U]ZWpYInZxbO"Sj7^C/Іv>eey&Ll^Rzwt=)/N$(B>WuUIJ8{\cl=!H9+iΓ06jצH6!(wuP?IF Sc,_4vU_2!up~fuGſLOB֌@o[I2n`K v?@&@=Y}qy:iSuw8٢:<3L^n"XQjSJ'kvs}=vEM("LYx:oTC+q[7C]g.y|ka2dR,UrHEE@>ʈK.c2VLx7W`.]&y ܺwҍrPB!!o-yQXX'4.cN9.t*Saa(5Ɉ̿AReKD7)F|gitcc _3N GD'f)Э疄%k9Б|ui۲y|!RFL9Swuo5ͺu|nE$/ȗ%$k7a71Gw ; JVCM98OR.c,L5!ϒaJ, As*w?Kf$lexwki5b_)V1ڜ/AVCFTtiV\)Ƈ%`\N()Oq X&E HX#f+pOF,Q*hGbd;*uK Ȩǎ!+Z'8̽0)U:)fAÖ,{.];i{چt4iܧ!{hѲpz6.¥pr3e34DDj"eBSa riog.8&c(n+.+$m pWh(͵?ƄٵMI3ip|tP-E4bj_'[9mgK,rǒ=Jx2/&q\6s@f[I[W)!]!f@&`Xr&$ YS]G3»*'Jt_TqNJ S JVhpLל+C).HyN &B@Go6Sd9{ء\" # ?0Qrb(2TA! R~xFBɇKk9#@&Jo4$o%g04EB0y11q,Wpj/+,Dٜ%% }vZIʘ򦺰g)H ʥ[rm< jLeqYUb]J\-UqQ|Ձ)%(Yes`e3_n~ qZ I& 2ϛۍ6ENة_K97Spcd'~N7/weo:8s뺏N_{8\D& MS9}@Blv_m/?|V-]HDEW楖p]Y"o'`،}u He4_i|H~,6wPP8([6=zXtX.p{]zN.A mejnQWK%Bp las v& 6F'in7w)H kX 56ӇA"PbSe; rX |q\tFfNL^h7 ?w]8O h`Pہt%$5 8H Y0@~#&Ąc >!Ȥ|MϠ$"P+''wXH)&#L"̔׏IZ~ۂrKglbyR\fI ZEE λ;ST9,\KO)*P9HmDZ蜼m +Rÿ,ĤZ:[J4HbqPph B@H6j D@[B*74SwGgt`Ҹc؜_N/r2O腚)C(EU69sYZ B-7@r?ie?v1FzRb (Za!NAMxkdVkB=KZbA[DBq4#9iMEgҥkz0;z.,Ilr6W;VI 9*JSF,T Wŗ_au˜g^iCҲb|Emrk,C`O?9/i[&D!fe|+J/r/:y-NbKfmo3sx89^^AO1:R^H <7hVDfRbz4-?(L׬)Z0k.J*?c.j*f+7Pb!,KZj&8 fTAgl<4Ӗ<w2uM$)73#U}S4H+) pPMqbV* ܕ< Lv=E;J]4!mSPISH@l#y Au?=3"nL Q] [#9­ E7LsSIwwN;`Sy48T{ϲ=.׏|aA>C|XT?@>WL3ھͣ*( ]= 6<ᧂ5l'hйMcf/T_xtpYPFIig\.`fzg:bHV&u&q&S? CN<<։-%8< gͬ`왣%@X Fp&͋^18/C7/:Nf >1m ٖAVߣb|Slqcdh8L 96Z30qrK]L)ǀE93߃,^XNfGggGAEW^NׅAjDJf%w3^D *b[ѺV'&aPí.twW꺾XF2`2E[J}uL̲YG1mY dy&E:cXP3{^1=FW(cUd6CEV[p0UN 0bFkE ~Fƙ!{?Pfbu }kyɸ? 88Xb+s:?eJdžvۏ$Wf#GFe$cA3ɟm61! F`LA4՛Ɍ)S+H7"PC'X'ݾeCE1`ضt5E$  ;oO>k'WcKCbͨYـ@0/T#a(z/]v/D3ֵ4{v˸Ò*l~/!~%gBU~T:1IIbR5۱2 ᄼpuw9gs&k7t_q([gi(n]ݺD I^8˹X8M۝rv,a႞)Q]~zQ :^7%ŵ[U|KM˜*e*$v@=n}ʍv.FLOf t1#*h9Sa#Ǵe#^Y5ZQׯZk5cts!XyRFcYz,!N O_yn^8:ιdhF1K0jзN /CE8)5[`W~srJ{* 񍲊m)nN V"u<ΚVݸM\|p=Z={|ܷ?Imz|^1B+ *3Zx: /HtUthD@eGڠ,uK5/?ˏj/"+nVS2g,D-,XQVZh\]C,`!_dti6''wEo8Σ 7`/WY@<8rT6(fu!כ+h ^$;O6*uMeTzu@EEtGVkq[q[פf-ҶdV!5O?KV!v5Z:uox[聢梻Laio1 0ro)ȷ &=4n gM.ԛf'X2eAjП>WF0_gb꿷'׺3Vn)#A3E%ܒ T=6-˛lj he2̃:2E E \Ky8X'n"%IXvl0VoX~U;iY̥vzDVk$hI1$MS04Y@"΢QM̍i#e>aTV. B]bfH1V0#92Iu:"N9 !mn?k[ :zJ1Q~qXjJgF,Jek!E*$>*sP9hzu ŷ$l}~ &6l(V IW%jN7狋|,woLxhڲr ț3\Ex[zZYQf\YqER3}$N$e_Hǫ(i |T/̕k= I BetQ\+D]Kpaeq8 !${N߈WdJw483 l_b8^>m $lY!1!fϠogݣ#O.;%OX;ڗWDž!L휁<;inKp./U48.nzma/~>5'%MmiD'Lu24dPS+\ `"R=< O) 6%0L c)FgrJ<>{S]Opd#mRc߳[\&5Es +3M0M\JiCgl 1䚨@~ϋ J[q" 8)jҚ?!Dn$B9O3vMY;~L% c\3pR'DVJccѵZEEbkcBp$lM+gRVʢv[srBMviS\H$ PL[2{b~DBjr*yn7/=~ e"[H͐`TcPRO6ͳsG 9r mN0 |}VQ/{Xc+.;T4kBتa7ut>Jc!y1&b)T,^x>i8XQ6GǦEFo= [ԓ[a8 박E2N*U8*t :;6 E.bs$!j9F{l-xOB! m73AVLػm xw[_F G7_dX?5 ӿ`Q^rpL_ϟ\1Qa)M)\$I&G.^+`ԕyyq}rHEΟmWx&q_ߧJU  lgRdw?HdNkdT]7gΊb-Y"h^1@7m ;f>o㥏@Q/1bhmURSns~F%vj:9-Ryʙ(u{!^ C\r5I^g.L[mpa!Lb[gmr$=PrǾRԆ iRCփ0n_T!HדɽeQ#4AրxÕ|8Lfp>u(zŁFe߉w[t749Vp0{?)JBr?̅Pz1Nev]\3hr3;{@'πxh."zDZg4[ګɗ V. ؘ:YC8i'ψ'P#U R ıUEY# 4@*jӻtdɟ*o+Q\upŘPd0SZެ""6w|hzn\N*Y.}]Y]:C9a|:FvvڂiPEa'!24R,7⑞anf;8`B,~"D~n qWr%Ձoq*mcIp h_Sq*9 /!Ij=9 /Fb0A>tm`0<,a* Z 1 %C tB)Հ38:v[+xY%a.IՎ;J HgI^p@{ 3 9[6Y{(uHWEO"'όQ.ݴ8`s4Ig|@Ym[$"3Tz[[$HI (OǰM#HچmЯKΏ+MxA9p@T[ExٮGs&őt*y:jrv-0`{  Z藝 Je.cB,ƞg*$gw9B8}˜A]XCѩ2O-AHxYsXsfJLTypξ9|p=-EH|5ngU@ Р `v>kZ-[f*WB 9X,f10.?'>~COkj`U`QڠiƫcS9k,l5-\jMex%qK)v,ҹCd?Mdg}]퍂P/9YtoW)tz928Ve/r)'ˮ6f2(xOv =$qֹ_@ix 4)R7l-BHq,)߷94Gu\fͺ"P/&RZzx9QCdvzB`4K ZЀ( m}7H}E6`rn(ESF4G>)F!&f`b( dWq%XbdUe;0B:¡#ujiaOpjHTUu.J_V!U>8^c9jU!Y>=o;J?}vwc7׬ZhQ7y^v*oSW w~Ur^+%e/Ȧ5=dM7P7{W押aCdSJ(k@N<3hc;!tҜRAOORfE"-.cN`C[T7بp)xB5G/T⿇Kd\>DdLi-ݲU0Ťy}MK<+J8RN0;6|ܐ^oV3aIUfLsb@rzjiv?^lEG-U[U)xcj=j`limHYp.Y|@63eLn#R{9FZ*)ͯsPaMA#_)i/JoФHt9\+F/\ls~mYrj#mwH"TvGN@,5n6Uñ~KEjܰa!?MhZhĚI\{7A)pDu3*:y{1P i\ҍ^Vv7!$h!d)nYdO7?ܺD[`2jx N11GV #b#`$~0hCmH@|?_7 ğb[)ԁF9e12ZFY+t}Z-;`RvJ&DlzC'THvJa~ rI@_dnF+AKy!`鈘,tsUjLH\IžBi$t*\ɾhCMdǣ3:q?YoZuU@PtO} ]])x\|h,{oTu+#*H*껛ҤYih! Vgr1 xzOk9 #*}ޢ,6NOVuA@RLȋ@C_ ;+;Trx6M3)MI[@ێW8 {|wn7ʩPQ #7·*ah$+.MKp=Ы+K^SVМ*jj26;䉮C nI W`ZS*phTNI  s?g0 QGSMhwL_:ԑ?.3LЦ_wb)'250ED:<Ӽy0^%Ml,Fzؤ- ~:ߕz0Y#Ba3h⛴8p@ =jgՄQVxJ"^}7HSܜV79C[кn컿EGo-g$a99ljQ`>j1o'h?Ny{$ڥcniT8_=ϲJ g[rʩS&(ZO"/NbCIUi޼ FO90D^߳KâΤM00kt/,C~F%[\7: 5rN|̖ HNiUep28uWf# QuH1$T|GΩ2CMS9@7uP LJ=$-@%Dfeo%vHgrD;$DbBG"07$FAn5% #?_IZQˤpK@ˡ?+US7~R z" scF_9Az,`CVˀkNPK/q݌FKKm1'2tw aC3NG8ו O/ӳ_@YHGC`kʏeg8o;9*0C}\qZ_%焵&7Q!c;R-VOGvHg39d!/giNds~/TNW*Șƿ|?a.B$[z>4//XgIpe醧}wOޜ _rw:o%3r$kz\tBZ!OXUIׂ҅"7~MgGQ;$ޜFc7g̐O%\QX%-E͢yA)bvLHJ-[@EgI3nH@IM8C] t]bz^p{Z8:LًAF ɻZ~a,Y)%0.܃nPn!8xY|rs1=}097=S>L cչcUu<ęb]BP\__0o><+? 3!Kqp NQ!yye MG8<ӶL LvB?/ 0 A^TÌoG1}+Iv:ܧog:@xϐ]B4# #w>#>n-]kQ4[ʛE/`!D=q?Id4bxz3K|SdĿ"üU0"%iEtM6 0 /|:'L6L;r2p˙?A+?ԐFWQ稈rj Y4PW7b`_H2Id4Ak뒅|9ћ/9<$uƝd 8:6^\2̃ W_~ل(1-[ܸ(@:yTO{O޴ }lNe(biD_H&q5lFZL"vVhݢ8 B7ާ_RJ07 nQbb+l*bOk3k!YpC2x9D |<|&yV9n衣\07Y1W)Z'jru+۶$RU p8 q7͹97_u:Xya],V30j) {`gᘩLDFB3:aTj ZQSe-R&3i]zǣ0fċ$9Im|ھ!]+U?EQ_Մ.9 HG؋̱:>7l|?rz?OADѣĖ>i>Es/^؞ G F i#;wnЂ/Ŋ <`eZ4VƲ}/nM£j^QVwk0O߭oNF '`#y)Y|SH=`'ľLytZ[6e롑Eα"Ѳ|^ B]h!n,"W1l)&tݾ4,eǣaCuZi[|9ˌ^9> Osm=*n{HZ|9NbccW̭q27p۹1D P3̫75=lN׻shq`2 2diyM2e Ⱥ]E M0g@ԊS(`tOt0:WIlPxہM^JFY>ݶU! =~buY~u}҇4 ›(0ɋ@Nc|a]Qqow|j}OEaz=?9$RϏEЯ׺=H9I k*d>L:rS#U dg sKֲ jꪥw*3G<~HF[WGQZz-ȹZj`W{hcW-U^hFj\;).Bmo8t8'v_i;BIR1:\%oѤ5 Y@>אZ_`|S)-χ3:vE\\^ҎPHF#NAښ>uĄ'eݹٌi(Q{>fʪO=/"$G`(;ᝐٞMd ;%؀x$?Ȯvp01aM"ʩ q4oZP˜ # HJuf/aVow!zP@}wF-UFf1ϐJ|AiYǙ9 e;Ī޲at-lL`kWF]#efl+^pW}cuĝ!p5%ej:>OuuY]|-+<à9DfEU|,{y,ɢv__cprU(d\ #3$7NYeJE7QT'CJ +|dTs!ެ4aG?1>h FNtszaH Z*)%4ȿ^?=R3MXVqg|Mud stadh6;/]:2ϳLiJ9Z@J 77^^zߋL?k`U߱egׁMh.v?]if'[>IOpFJ3^!ߺGM%3dt^ͧ|_Oa+9]V&>oW!Hti[q "6^J "Q>퉨kyoLmҳg*ez9PHV |:]F&UKІG\4lg",<^Fώ SʘǤKЊ ~^Xc4j+m&JI<=p0|'Bc İ &N@}M؅w#vt@seHmJﲇUAKKk(Lw)/Ɫ"y *m )o'ǀ6$\|HO3?Yϙ(r?0UY{Z-<-Q :{|+1:)Xx8v"sPQi\հy:ţ_÷"mV݊ O-I=%R{H/wA9CbPpLEyH]oo+c= aupnK$7IQ #~Nݶus#Xϻ^Rb:Z>>L.8b%LՁ"w>Aꛈ=j>2>T,k2p#R>-Hyd<]qw=k& RDSrV&A7܉Lww!Ǫb' ƀ6U" '64D aH*\dH#|iȋYQrLc־h|$cGi~a".Sjs;ky2޼trxnG5:wD0lfD=l^BѼp<IY|+ߏoi|u;)χޡ<40:;2 63|j<\v0` 'Z(787c0Po#? e YOU rlU.o@\&g󡊈=?"<[V̄f~ڨl0ͧ S*19Ѻ4Z@tM%|8U"nxW>s{>%zaFMY{^ç ˑo:fYtR7 8Kݧlv2~җ-@/`}U/-YįJқD Ib#$J 㐍즄൝n7Vxg惼 KjFo1p8>eԮGꙙE %W@̩`B̊A2$Hk7pCÉK0Yk$㨫̢A -1ɾ%%4[07S1pf"̏MUn;sSW {68*x1V$΋;ӭ; dfAi~#(obF~I䓼^ ~!  7򕶘Ói$ja*$̽WRH{kZѡay-R)3 x\9G᜽R6_ ORZi)CL:纩 [2 q4lc]8QU@]I;5ec%ڥh`}*re[dIC/NHm-p»ޢMY{Lq0ؼmYV~Vw6B>r7ˆb ט/!L)VvZ<ٹfG$*"R%qnGTDLoĞQF?ώ~s̾~oJႎ{OY!N"zkJ;*Q]msfrao8 &z>i}w c4Evbt׆bTٞE VoSDԋw"Gsʓ#kxX&KhQ2<ٹłgx#`Tx>_NƗ¬&wf>2A @+M7Vͧ^vGRJ'v$s/1Ƞ1QW\/t2y5WL(6*IVƹIz} sF}`_3f.஗Ÿ5:3۔YAO βBTk{Jc7(l.[=D/AcASapBr4B DBPx%bE ך;3]wc̘F^\;ݡCH%vc-aqda-ȋ2JAڶ1dvVm^hIhoQh4XFGM #T0 @+D7B >R8 n٬POڂa=RU6]vLXGkZ/ 5ے>P_T-&r^}? 2]?gz6:!~MgBB:e<ĩ~ QEjo)yL?œNs{0 9|S@p'L?U̬{CnS:Ⴧb^݂~"*~KKSPѰGjkkrQ9W,eɜmOZ- )#,Nf'#KO'QZ Wz^˓-vOV6Z0!SFve}!,K-zS@3noWs'7&oI4ʣ}0aK%Dó'ZXZ /7f=W@)x:MX\w|dH|t~d#%( aTݫ '7ڥ& S9xzK+x e4"+^uʈ` kE)0 h#x{^^NfFy1.iJZOH|P8AD8L|@2-,>D[Uye62܅'WkۨzK,\BtJ]Yc.vupȶ]EZ,xZm4}iGo #CNu+61݁W3P?;AL{F>W5^9p %Ph}$eu"heQtLx8<ļI%)A8@vK:O 6@sK3@dWrtl'K..%WD~\zg0C0LHӴG:i$/Ⱥ;YvnIn)ɲ("Rֶ^X,;_RQ:YDeG%-v:mΓhF=^`ϫ58RO,Ho㡈arQ=:k$'8[e9tپ2KCP(E>gxS݈#nXGᥤFrgېYT?a^Ӯ>8@aZeIBGVtaEJwcv\tc8$ȋX[myiaVf!2GծAH@\i Zj5 ]p:Io fMmKFQ K]3#}=,p蹙r91d c>.<\3}?u/۾$T}P8Յ2ۛ3|tj;byn3bjVI[RSť .~L3(S' T6 &'d|Eh>bkL>2,vkI4cR]dPOJ^oTx/L,ݫ~YlWT>OnL1 _iYʬbSn'gDFVwu7_seA^Ǥ` Ϧ(iY4_8d= ,Bw}!Ğ:`p{9i'N\y-u$Y"F@Z%.2<Bs-zqe C2iه-¦vd=Cf[Y@g[ tuK/bm^ν T}Y(xW5h-,:=h&yX#[AZKkq!EQ$ :I.Kc/|21bg#2@ fӨq~U } 1SKG:B$N P8S`ꯕ SoyUǩE֨q~7[o!H䞏'x?UPܘ't5 [-=&独xر(gT$=S ]-kxn( 4Be+' 5?{gJ]fB])%bxFw y\--^j?L㪮=ٝ}_8H.'1.{Xeq8i$潜yzN*"`Q g(:kTs'LC&0w1yCy +K Hǭ螹4D+Y|( o,RImJ ;5:*Dr}!3},YfP($&H"Zo ޘ q? >Y,RΩ9{qUb6ɬgΎIILFZU36ݡ :j Q֕H,)IwLz3 ijuQ%P*n+SQn m>ԳX5q;Ce:gr'HGs$y*;q>6yV_H4.Ns>VEC>]†O12Pp t5dM}o>=*Ʋ`R(}qr783G4HcPE)s ~^!ңCV S(<EP[Kv")kH}%B Kx*к!Is gBTfٳ00hY /CNC "` YC5 K:mS =JX;7DFꧢJiDj'.PY^操e@3WL5QlDA<6fb(2_̮+ x;J$&K37t&ﹿϺ=hnkV4H p4w<GZ1n.KcQ3^zQXi+h;gܥ&1~|2^&j%D ljpPY_r.2n"qo!#TM v!o}$c]lOp2|xUxNQV!R͑Y P"yD[̘wNau\vL8AK0k3#&åz<][++Ga|ZH*~@I2(J2ȮCIyF8k;S]Ԗ4UFCގI?]Iê/F'zlϑDʞҷIԾ~8[˒?\iF 4xpѳ3;Ĺ,^v q 6,P-\Wd◯;"rbJm  5\$Hs;lF`{}Y|nEt͚`^';V q$$<= Vx-.O$u/|& nd(ΛU2 ^aPI\٢lm0k0B*;:@6UyHuEau[댣6"eP/5;v+\t}? u26frZ. d*]zi |WO5]PfMRTŇok$2zaJǢKb ր67D%UrEv†u/7ƾp8:]ęp?T! )ygzGWU:|'Skof*l 5-Tjx Z!gc!~z:$;d\X =>ޛ`2UgɅ͖ ] @vNh *{V*/J2H*v2TK?&9ϲG00x'XUeyu\0ݘ༢+Dޑ]DeZ!J~*x|ʴQ'l%[Lh[gcjIEex2Sc{~t|=RꚏF4itx!DΗh~"k/k2'v2j?Y}FuS+E&a`|s=jPT> ]D*祛LF5Ay\š&zB ʒ5LPSƑ {lK3P0B HZ8b)PGbFM:W Y춃 elvݜIJ_yƬI ŽEy%;֡{DҔ s`Z0ʠܑ7q0oA#dH}]hy_4>M,1QDŽD?/sҼč;t#DfjF[`&D~1{T)̑&C6$ޅX?l\Z#i|7 zu zyTgc"Չ.Yڼd|Qa(":X\dR ޠ/UԸcdkO2[|k[pHKWuHoN>m3O)~b%ׅgF7aw/$Fئ|Gj(A(.=TvL'<`A$H5pQG.:f~-Nc(M_4SWGȰCĖm{΍ BJ~܇3g!2\YAыzJN&tI5sdXV-TbF$]C/yhiP4^VFaK.pᓢ9 4t5< zgAh4D!ZW46[БAXT)LY R1d}*0UM8+[WW u^ -gBE7q/HzO{4n#\ݟfu -~WrV!j2Ruۗ| BtdeTۂE' Zrm+ԏZC)I Ge(?Wk"6fc z#H =U{ N]Bv(.a&!JqRgo^V֯Whr"dՄ(VS5]c]5(Gr8&Ud %."ZwO&?Ac8X\Mnhro{ q|c%iE7wY0욾P}T#gS"Fgzv`sP8=dXD"!}Vw7c| 89)xnyZ!j*1.h6I6 -"-$rJdxp*j2_YjRCS뾧T_2X ex&*,.~Jz6Y-"͉}ƞ4=.(3eƆ6Zs9=$²(Fy%ާ?K( UP H&HN=A|9MHZ=;Ru⡹7vt)!]4[@dR͌`S̥ZDwŻ$vLyZ @H+j@Mdj^.dBj +`z\CM)R,'*v˺k1.#gGy.N6 %}4⯠}m;d`/&s8y`VS}*6\A7$U`~Nk 5]@)Fgxfg4>D:W^Ô_jޗ!"gEN?Jji-RnJ1zEɫ<WZf,7[Zέvz;)v_KBwgEǤ<MC+6=c?BTpRyAqE1Jh!Hă3ʂ~*K9\sj .ih"o3TW+2iT3%%nl$j=[#7ʐ>}G<ZnHy4b!aInEF+gr6>q;1Gxfp $lb.=1tNaFhՠ#\u.D5|*]9GMUa)# Cv  S=Srfz;zE`$"uRi a#O_ LrHr("_鉑%Mem`.hVi!L>/NdjLe p`Ci83Z˪,Iۭ"$պ l.!)z|k 1Ao1۪ȿu0%AN'VBǬ(_T;##G$L3;urŏIČG@Na FdgB{"`W{8x> } (VT!ik$]<`r E/9"X#lO8j`,19r GƠS}15zѹ'Ec9Rzy6.?*> ㉴v_