libldap-2_4-2-32bit-2.4.46-lp150.13.1<>,]/=„f yD0|qds[!OEDWSI?FU~6=eDk%ƺDNbq‡*@&5v`ߛ:z{4|4 G1zGWXhZ9\9Tҫ n@AD iiJ;d8oeyRN)P8 g%tu0` } :b!;e,p8CTPR4 QdO$#OOM+5\M>ABD?B4d ( Bx|   0 8 @ P  (<`pDo(8,9X,: ,>=B=G=H=I=X=Y>Z>0[>4\><]>L^>b>c?fd?e?f@l@u@v@(wAPxA`yApAAAB0Clibldap-2_4-2-32bit2.4.46lp150.13.1OpenLDAP Client LibrariesThis package contains the OpenLDAP client libraries.]build80xLopenSUSE Leap 15.0openSUSEOLDAP-2.8http://bugs.opensuse.orgProductivity/Networking/LDAP/Clientshttp://www.openldap.orglinuxx86_64/sbin/ldconfig\]]]]5be4586b0141c3d825f206b2f9d22e50f5ad274be1a25ea10f4da76e1111a4ad59f7b1ef25a9d7cf1a8a412b1764e7feb52b8cda79866418da2469929df54018liblber-2.4.so.2.10.9libldap_r-2.4.so.2.10.9rootrootrootrootrootrootrootrootopenldap2-2.4.46-lp150.13.1.src.rpmliblber-2.4.so.2libldap-2_4-2-32bitlibldap-2_4-2-32bit(x86-32)libldap_r-2.4.so.2openldap2-client-32bit@@@@@@@@@@@@@@@@@@@@@    /bin/shlibc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.1.2)libc.so.6(GLIBC_2.1.3)libc.so.6(GLIBC_2.12)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libcrypto.so.1.1libcrypto.so.1.1(OPENSSL_1_1_0)liblber-2.4.so.2libpthread.so.0libpthread.so.0(GLIBC_2.0)libpthread.so.0(GLIBC_2.1)libpthread.so.0(GLIBC_2.3.2)libresolv.so.2libresolv.so.2(GLIBC_2.2)libsasl2.so.3libssl.so.1.1libssl.so.1.1(OPENSSL_1_1_0)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.1]B@\ڭ\r@[H[@[vZ@Za@Z@ZZ.s@Z@Y*@Y*@Y@Y@YYp@Yf@Y7Y6@X@X7@X$a@XWk@WbW;VVɦVŲ@VŲ@V@V@V@V@Vf@V^@V\:@V@V @U4@T@TuWilliam Brown William Brown Peter Varkoly varkoly@suse.comckowalczyk@suse.comckowalczyk@suse.comzsolt.kalmar@suse.comzsolt.kalmar@suse.commichael@stroeder.comfvogt@suse.commichael@stroeder.comrbrown@suse.comjengelh@inai.demrueckert@suse.demichael@stroeder.commichael@stroeder.commichael@stroeder.commichael@stroeder.commichael@stroeder.comhguo@suse.comhguo@suse.comjengelh@inai.dekukuk@suse.comhguo@suse.comhguo@suse.comjengelh@inai.dehguo@suse.comhguo@suse.comhguo@suse.comjengelh@inai.dehguo@suse.comlmuelle@suse.comhguo@suse.commpluskal@suse.commichael@stroeder.comhguo@suse.commichael@stroeder.comhguo@suse.comhguo@suse.comhguo@suse.comhguo@suse.comhguo@suse.comrguenther@suse.comjengelh@inai.de- bsc#1143194 (CVE-2019-13565) - ssf memory reuse leads to incorrect authorisation of another connection, granting excess connection rights (ssf). * patch: 0201-ITS-9052-zero-out-sasl_ssf-in-connection_init.patch - bsc#1143273 (CVE-2019-13057) - rootDN of a backend may proxyauth incorrectly to another backend, violating multi-tenant isolation. * patch: 0202-ITS-9038-restrict-rootDN-proxyauthz-to-its-own-DBs.patch * patch: 0203-ITS-9038-Update-test028-to-test-this-is-enforced.patch * patch: 0204-ITS-9038-Another-test028-typo.patch- bsc#1111388 - incorrect post script call causes tmpfiles create not to be run.- bsc#1114845 - broken shebang line in openldap_update_modules_path.sh - fix the script- Emergency fix: move tmpfiles_create post from the library package to the main package's post script, which ships the tmpfiles.d configuration. Fixes the post script of the library (-p /sbin/ldconfig does not allow more statements in the script). - bsc#1111388 openldap and /var/lib/ldap/DB_CONFIG* (transactional-update) * source: openldap2.conf - Added a patch to let slapd return the uniqueness check filter used before constraint violation to the client. Fixed broken memory handling in affecting error response of slapo-unique ITS#8866 slapo-unique to return filter used in diagnostic message * patch: 0001-ITS-8866-slapo-unique-to-return-filter-used-in-diagn.patch - Don't require systemd explicit, spec file can handle both cases correct and in containers we don't have systemd.- Fix CVE-2017-17740: when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack * patch: 0017-Fix-segfault-in-nops.patch (bsc#1073313)- Fix slapd segfaults in mdb_env_reader_dest with patch 0016-Clear-shared-key-only-in-close-function.patch (bsc#1089640)- bsc#1085064 Packaging issues have been discovered around the openldap_update_modules_path.sh which has been corrected: - the spec file was wrongly configured, therefore the script has never been called - the script should create the symlinks first, as slapcat is useless on a system which is already affected.- bsc#1085064 Add script "openldap_update_modules_path.sh" which which removes the configuration item olcModulePath in cn=config which is after upgrade from SLE12 to SLE15 holds inappropriate information. If the cn=config is being used on a system, the conflicting items in slapd.conf are ignored, despite of it, the backend DB configuration section has been also commented out in the default slapd.conf. In case of correct cn=config (the olcModulePath has been already removed), the script stops without touching anything.- Upgrade to upstream 2.4.46 release - removed obsolete back-port patches: * 0013-ITS-8692-let-back-sock-generate-increment-line.patch * 0016-ITS-8782-fix-cancel-memleak.patch OpenLDAP 2.4.46 Release (2018/03/22) Fixed libldap connection delete callbacks when TLS fails to start (ITS#8717) Fixed libldap to not reuse tls_session if TLS hostname check fails (ITS#7373) Fixed libldap cross-compiling with OpenSSL 1.1 (ITS#8687) Fixed libldap OpenSSL 1.1.1 compatibility with BIO_method (ITS#8791) Fixed libldap MozNSS CA certificate hash matching (ITS#7374) Fixed libldap MozNSS with PEM certs when also using an NSS cert db (ITS#7389) Fixed libldap MozNSS initialization (ITS#8484) Fixed libldap GnuTLS with GNUTLS_E_AGAIN (ITS#8650) Fixed libldap memory leak with cancel operations (ITS#8782) Fixed slapd Eventlog registry key creation on 64-bit Windows (ITS#8705) Fixed slapd to maintain SSF across SASL binds (ITS#8796) Fixed slapd syncrepl deadlock when updating cookie (ITS#8752) Fixed slapd syncrepl callback to always be last in the stack (ITS#8752) Fixed slapd telephoneNumberNormalize when the value is spaces and hyphens (ITS#8778) Fixed slapd CSN queue processing (ITS#8801) Fixed slapd-ldap TLS connection timeout with high latency connections (ITS#8720) Fixed slapd-ldap to ignore unknown schema when omit-unknown-schema is set (ITS#7520) Fixed slapd-mdb with an optimization for long lived read transactions (ITS#8226) Fixed slapd-meta assert when olcDbRewrite is modified (ITS#8404) Fixed slapd-sock with LDAP_MOD_INCREMENT operations (ITS#8692) Fixed slapo-accesslog cleanup to only occur on failed operations (ITS#8752) Fixed slapo-dds entryTTL to actually decrease as per RFC 2589 (ITS#7100) Fixed slapo-syncprov memory leak with delete operations (ITS#8690) Fixed slapo-syncprov to not clear pending operation when checkpointing (ITS#8444) Fixed slapo-syncprov to correctly record contextCSN values in the accesslog (ITS#8100) Fixed slapo-syncprov not to log checkpoints to accesslog db (ITS#8607) Fixed slapo-syncprov to process changes from this SID on REFRESH (ITS#8800) Fixed slapo-syncprov session log parsing to not block other operations (ITS#8486) Build Environment Fixed Windows build with newer MINGW version (ITS#8697) Fixed compiler warnings and removed unused variables (ITS#8578) Contrib Fixed ldapc++ Control structure (ITS#8583) Documentation Delete stub manpage for back-ldbm (ITS#8713) Fixed ldap_bind(3) to mention the LDAP_SASL_SIMPLE mechanism (ITS#8121) Fixed ldap.conf(5) to note SASL_MECH/SASL_REALM are no longer user-only (ITS#8818) Fixed slapd-config(5) typo for olcTLSCipherSuite (ITS#8715) Fixed slapo-syncprov(5) indexing requirements (ITS#5048)- Use %license (boo#1082318)- added 0016-ITS-8782-fix-cancel-memleak.patch- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- Add openldap-r-only.dif so that openldap2's own tools also link against libldap_r rather than libldap. - Make libldap equivalent to libldap_r (like Debian) to avoid crashes in threaded programs which unknowingly get both libraries inserted into their process image. [rh#1370065, boo#996551]- use existing groups instead of inventing new ones- added 0012-ITS8051-sockdnpat.patch- updated 0014-ITS-8714-Send-out-EXTENDED-operation-message-from-back-sock.patch- Added OpenLDAP new feature implementing OpenLDAP ITS#8714 0014-ITS-8714-Send-out-EXTENDED-operation-message-from-back-sock.patch- added overlay trace to package openldap2-contrib- Upgrade to upstream 2.4.45 release - removed obsolete 0010-Enforce-minimum-DH-size-of-1024.patch and 0012-use-system-wide-cert-dir-by-default.patch - added 0013-ITS-8692-let-back-sock-generate-increment-line.patch for supporting modify increment operations with back-sock - added overlay addpartial to package openldap2-contrib- Remove legacy daemon control that was used to migrate from SLE 11 to 12. (bsc#1038405)- There is no change made about the package itself, this is only copying over some changelog texts from SLE package: - bug#976172 owned by hguo@suse.com: openldap2 - missing /usr/share/doc/packages/openldap2/guide/admin/guide.html - bug#916914 owned by varkoly@suse.com: VUL-0: CVE-2015-1546: openldap2: slapd crash in valueReturnFilter cleanup - [fate#319300](https://fate.suse.com/319300) - [CVE-2015-1545](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1545) - bug#905959 owned by hguo@suse.com: L3-Question: Are multiple "Connection 0" in a Multi Master setup normal ? - [CVE-2015-1546](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1546) - bug#916897 owned by varkoly@suse.com: VUL-0: CVE-2015-1545: openldap2: slapd crashes on search with deref control and empty attr list- Drop binutils requirement; the code using /usr/bin/strings has been dropped in openSUSE:Factory/openldap2 revision 112.- Remove superfluous insserv PreReq.- Introduce patch 0012-use-system-wide-cert-dir-by-default.patch to let OpenLDAP read system wide certificate directory by default and avoid hiding the error if user specified CA location cannot be read (bsc#1009470).- Add more details in the comments of slapd.conf concerning file permission and StartTLS capability.- Test for user/group existence before trying to add them. Summary spello update.- Move schema files into tarball addonschema.tar.gz: ldapns.ldif ldapns.schema rfc2307bis.ldif rfc2307bis.schema yast.ldif yast.schema - Package previously missing schema files in LDIF format: amavisd-new.ldif dhcp.ldif dlz.ldif dnszone.ldif samba3.ldif sudo.ldif suse-mailserver.ldif (bsc#984691) - Fix a minor issue in schema2ldif script that led to missing attribute in the generated LDIF.- Enable build flag LDAP_USE_NON_BLOCKING_TLS to fix bsc#978408.- Move ldap.conf into libldap-data package, per convention.- Move ldap.conf out of shlib package again, they are not allowed there for obvious reasons (conflict with future package).- Build password strength enforcer as an implementation of ppolicy password checker, introducing: ppolicy-check-password-1.2.tar.gz ppolicy-check-password.Makefile ppolicy-check-password.conf ppolicy-check-password.5 0200-Fix-incorrect-calculation-of-consecutive-number-of-c.patch (Implements fate#319461)- Remove redundant -n openldap2- package name prefix.- Remove openldap2-client.spec and openldap2-client.changes openldap2.spec now builds client utilities and libraries. Thus pre_checkin.sh is removed. - Move ldap.conf and its manual page from openldap2-client package to libldap-2_4-2 package, which is more appropriate. - Use RPM_OPT_FLAGS in build flags. - Macros dealing with old/unsupported distributions are removed. - Remove 0002-slapd.conf.dif and install improved slapd.conf from new source file slapd.conf. - Install slapd.conf.olctemplate to assist in preparing slapd.d for OLC. - Be explicit in sysconfig that by default openldap will use static file configuration. - Add the following schemas in LDIF format: * rfc2307bis.ldif * ldapns.ldif * yast.ldif - Other minor clean-ups in the spec file.- Use optflags when building- Upgrade to upstream 2.4.44 release with accumulated bug fixes. - Specify source with FTP URL - Removed obsolete 0012-openldap-re24-its8336.patch- Relabel patch 0011-Enforce-minimum-DH-size-of-1024.patch into 0010-Enforce-minimum-DH-size-of-1024.patch- Upgrade to upstream 2.4.43 release with accumulated bug fixes. - Still build on SLES12 - Loadable backend and overlay modules are now installed into arch-specific path %{_libdir}/openldap - All backends and overlays as modules for smaller memory footprint on memory constrained systems - Added extra package for back-sock - Consequent use of %{_rundir} everywhere - Rely on upstream ./configure script instead of any other macro foo - Dropped linking with libwrap - Dropped 0004-libldap-use-gethostbyname_r.dif because this work-around for nss_ldap is obsolete - New sub-package openldap2-contrib with selected contrib/ overlays - Replaced addonschema.tar.gz with separate schema sources - Updated ldapns.schema from recent slapo-nssov source tree - Added symbolic link to slapd executable in /usr/sbin/ - Added more complex example configuration file /etc/openldap/slapd.conf.example - Set OPENLDAP_START_LDAPI="yes" in /etc/sysconfig/openldap - Set OPENLDAP_REGISTER_SLP="no" in /etc/sysconfig/openldap - Added patch for OpenLDAP ITS#7796 to avoid excessive "not index" logging: 0011-openldap-re24-its7796.patch - Replaced openldap-rc.tgz with single source files - Added soft dependency (Recommends) to cyrus-sasl - Added soft dependency (Recommends) to cyrus-sasl-devel to openldap2-devel - Added patch for OpenLDAP ITS#8336 (assert in liblmdb): 0012-openldap-re24-its8336.patch - Remove obsolete patch 0001-build-adjustments.dif- Introduce patch 0010-Revert-Revert-ITS-8240-remove-obsolete-assert.patch to fix CVE-2015-6908. (bsc#945582) - Introduce patch 0011-Enforce-minimum-DH-size-of-1024.patch to address weak DH size vulnerability (bsc#937766)- Introduce patch 0009-Fix-ldap-host-lookup-ipv6.patch to fix an issue with unresponsive LDAP host lookups in IPv6 environment. (bsc#955210)- Remove OpenLDAP 2.3 code and patches from build source. Compatibility libraries for OpenLDAP 2.3 are built in package: compat-libldap-2_3-0 Removed source files: openldap-2.3.37-liblber-length-decoding.dif openldap-2.3.37-libldap-ntlm.diff openldap-2.3.37-libldap-ssl.dif openldap-2.3.37-libldap-sasl-max-buff-size.dif openldap-2.3.37-libldap-tls_chkhost-its6239.dif openldap-2.3.37-libldap-gethostbyname_r.dif openldap-2.3.37-libldap-suid.diff openldap-2.3.37.dif openldap-2.3.37-libldap-ld_defconn-ldap_free_connection.dif openldap-2.3.37-libldap-ldapi_url.dif openldap-2.3.37.tgz openldap-2.3.37-libldap-utf8-ADcanonical.dif README.update check-build.sh- Upgrade to upstream 2.4.42 release with accumulated bug fixes.- Upgrade to upstream 2.4.41 release with accumulcated bug fixes and stability improvements. * Add patch 0008-In-monitor-backend-do-not-return-Connection0-entries.patch * Remove already applied patch 0008-ITS-7723-fix-reference-counting.patch * Remove already applied patch 0009-gcc5.patch (Implements fate#319301)- Add 0009-gcc5.patch to pass -P to the preprocessor in configure checks for Berkeley DB version- binutils is required for "strings" utility invocation in %pre [bnc#904028] - Remove SLE10 definitions/bin/shopenldap2-client-32bit2.4.46-lp150.13.12.4.46-lp150.13.12.4.46 2.4.46liblber-2.4.so.2liblber-2.4.so.2.10.9libldap_r-2.4.so.2libldap_r-2.4.so.2.10.9/usr/lib/-fomit-frame-pointer -fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Maintenance:11079/openSUSE_Leap_15.0_Update/06491bedb2a11a89cd58f1ace579126b-openldap2.openSUSE_Leap_15.0_Updatedrpmxz5x86_64-suse-linuxELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=9f234e8817ad6e7138dd8e792a40cfcaa7a0866c, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=6d0015bf631b3e704fe38bd6784ebd1e4284daa1, strippedPRRR RRRPRRR RRRRRRRRRRR R RRRR R Rutf-8ff132ee8d72828505cf04a79f977fdd350dcf27c378753c25334fc3c1b00b739?7zXZ !t/mS]"k%fkïnagA]?f=)\P{ ھu21lM.ׅT9v;\ݯ4}@;vIBgJ E*| cGXN EA#89͝m$2)d!` m?.d&htˉ!Y&< ?zF^N.G{TŹxީ` Ζm\u3iiG/맄l~dt:캨۲OhLF%(WTipgDLVy`5T/OQWMB?U=ultF5ezrn,rn"U2؅^m&_{.>:O Jlѻ+,B3[cdN=lU[226Tn\r"-,kKݚ(dauC {+'0#꒞i`EnL7j-{7ue];RHL)ǕGa#@rBN{{`( K Y+)]ٮG!Efk&5tϏz Z ̗pys6#ϜyLr LWc1^b;3HV!@-X; D-Y}S\gq "sVoaN;š&jvɥ-͙(砍 9>& gP*DP)pV7QJCf(V/OV24-hȜϴ|K֝q8vr O cc&gX.imESƦ:&8@ -X1` $Z)ƌ)nrf\H&HD=1牏J7[|Yн [x C7[}\~ʛ/zַeAC ,q~3;q bTbhi$U-Mjt1m bxVsqe3 L91ДtOM&W`^*a@c\Yu5N2~R7fS kqp!jmrǟs p&(b ')+IᎧGT{)3q |Q^٬TVGA)> >+к4tL!-YL4,CtQV=ǯ,(ߜ6= Mi9%W^]} ;߸9<"t] 14<\檃_{ 1 ?Q( Tb}a懤B%$=M8Fxp o_"*<05 jf->^}aQY ~|Z[5{m: [k _4e[pP(G\ cy\b֌OܐW kX\4n;Q4wC Vu62S-Rs0r 5eI#~vqQ( S-%9<)Eҧwϔr`[@isDw4=-JF"]xݶ ޔAQuCY-)' !\ؖGu"\el\܎M9@kH~ T'Cv4,YR7cyI{2R0%hhͷd?k(읟ITW+˄"0Aˇ&ԡMԐO ViIϞcRAmngSNdJ>fV./fF`5_[: gi =Saur=x[_|B5rWi8{Bda/)ixO{:l,C{ߣS_ cV>@;!.f~0/[ps}lnJM3VqE'/bgG~C!͊D#3qt+)usN[4+)G 7e`]4WL9>:kyS LUY%kNTZ !^F;bצ|-؅Dي%:\ 1!@YXgdTCe.x(7\"aWr_?0}4[xkt ;.@3vz8TB얒^TɵX:'|#qh篲#griiQʊncЁ m:9n!j[iXD_@(2LTN:>dߑm(|MqR41ylI #~v(9ޑ{e_ ݩ\%G/4ZI:3{!4 $/ME}ްt#e jPj d<~nA32µ "M5>'nV/Gg4NA=i !MjEA iي{/"2;8}ݹ[L*zTa$yL66Κhy읪sz6ULR Ia^}9]SDWJ\UM^܊R0X<#s QvϽ?^=wBD;M^YJAt:RBi\!0(L,f/N vkc W~Oh{*Duзc?9{ l.q oqWMKmj? @-+yGPRP4@{h)(;@ |edÄ}$*a61n$jqb/3/U(q:^.ҰUva7Y*Yݙ096[s-"W3Z?Q؞dR>]p=Wut]\z^p$MfTwHJ3e1֞7~ϙ:'-\GB|wڴ˜/J|=_&*IoRmOx)1LdjiiZw+x:n{[yVȡ_F.L3InC0h!_n„Vqd%i'$UL+3E i Hb7oެ(&M=NK.@?jy!mw }ըC [\MJ 6g"ȄI|ls,9pafТ*@j [ՕIv}P*$qX*n$TKG/j".YK>g9~Ts/JwѲQlK`t,Q^(Ӯ`ߤ7̰~ۦöa A EzAs4.AIr MJЭ\l дQ2(qS6 \I; DmVf6 H5] +~\=O(gW]էڬd_Ri'aKfl hrQ_,&QI7OO v9;j 8#*sFm)+CQ0jIjD# ^՘SS y6,)"^8)L|\L]ѽkƹJ;(hﳆ_1ם}\ߠ'3 %-PWS{+Z@jK=a^Ӄ9[4XD121C]ݲ ߚ&9k54YA=CW֪ٗ T 7El6CJP=Gc L:K2]OR鄿⎣־ۙ6梟Tc?7BR:: ϧdc񛡴K*ĠDH\tɗQ >Gt{ڻ=CI!.y)SX/ nWV0yu8pr}qW"NJ(~Fbq0(6r;HزG-F) Jc vn!DM9ugIv*$/k #rzrZXjM 73^jt7B+8t3}'Mpe fQp:YXc43."~/]122ܸD݀(# ku¹7L{6V1^9UG0UkVHv]bwM\-.f1U?h(/7M x]/YI` -y#-X֍,e%J%NU Xg+=գ\#"׏"Q4{dZYG˸dT:A]aMz 6Bp1.iQ '2pgPplKZ(+ J\3DXuF-jtsCխl:b]}`zvtNZ8jp Q]s ѻ ž ϐ )bCǯxxF՜M@N VzOa>qѢ!ffPa< G'];ѣ|@ ^P^=%qr'IjM.S(l}-:Q~CT F TC,dJMF%lX3"z.-*vs^Ft)9ꊩ[U +}n>eػ1SJrΩRJ<)\&#W,@hb!ޜ2-&l1za>. ºP㶎0cHnܨ=}}2&(ǜ4k{6"/q6ЍRmQ˥ =9Iy Pl G:7!y) f(@x 4j5;CkׂHJbQlmw7)CCXL{fg*To=# ρԫ㈎N/PZH AQiaosL >jYte+ R$FqHKC}XNGم9RgWFG։{0F#JzsAE0m?{i ;Ь K @!;_M#`uf{NVlA$q(#@@&X2kQhI1"FFkJ) 1lLKǘ}O?/ݮr ZoF4U4L7VshrqlqYT^A׳V>V<=FkE+36wG@%/ $7z$O4x[o&݂/ B º$tfX6tcnv\fHr63)5q8(o1H-Msbp%s .j*6 -h_.^|}As[B? U.Rv S| 'ziQ8-t(z옢%|l97g_QΕ ŭ#aؼDˋar]7sV(?ӼwZ=RLYӢPx#E{eG@0(m]mҵUB-]xŢX}ڶݳ4-9MZ*<)O~R,vY˧q/OuV1aV)ļbH>M܇(-gس}17 Ē XS5Z_ V$ SGA"{5:ݪQ7zB6n +DtC_M0)b.c٥ G@Wķy 4+bpY0(ė#JfkYO2pF*7b^=зZWW .8~mQYFiz|3UZȢ7-M\pK&JOpIGn~FuAե(&:z/OA*mmF'@rdz_e{':ć7g~ȟbnߡ RQ?]pDg\jky0u[sR3~7@ T;x4tz,o~$~,/*Q/=~dw*A`H٤X&U3#&"5tc?iX [60q27*FzaCv%O7giBC.nM9xl۝v~|`ѱSUy^bdOW(1w&ԑNj/<׹:GCq -N_0,m#nBw|or [SE-'k+ɸIAܙّU瞶L6^:Q(_v 2( `'e|ztJWH?j9#N fh9Fa_Rxhɠ٧>C.SsCY0cHq]"&n!ntZ[1_v@%{{^϶hc&vV'uuNx+e k~|fUYtgfllE3B CڒO1SQ+|!=ygYAkϩIfDrvډ0Hu UoGSi3H fO;SllbSR; <{SS֟"L– SL=:M -e\lh49T*=; 0 odX,n^}f Ύ7ėÉڈ0@FC/'~Ɓ6NCRpK˘ƶ{"6 tˬ"١3n`dۨT".u5aDw^7G]jSѡ8׎{>?E~-.X^,o'o} >`1LI AN(H]"?W܁ʆ?$/5S oqupO7<9jV1<L<"]REYb\|&m:4[-@SLXjʘ`?"Pn;bqˈa;.`A`7έش떙Hd2qѼ?`~㬅ݿSQ*w_N _݈{?ri. =NN;䋋 ^7"?qX ]ԪZH,׶%De zUEJĬ<6hm.=O ܍ӟ&# %'D7;FkeYP+V{C55[* a~A$`Ty%:Xx=g K#kX<${i$h`ۥ'Bs֫' >.؅Z-9nNr 9==x3Ē==8+9$Y 2ՋKYHJ']޴Cs`h>Ly95#\?"EK?DB4F 0m ?uS9/s17 ߑQkh()PiVO-g_Ǩuc PEv(sRAŷ@"6RG6`4Jc吰?5fQ%|.o!7y̌O0{9W&tB" xWd,}Z<)vx܀n+?&,)ڗVqz LqWw֙t r aj= o&,ݞm)l"f筬 nۘ W'7&Fd3ODѯPjfv`"aN_YS$BcC)3ӟUs*AdyAfa@e{!pc.\%[;jU|> o&`ˋ b0F׷8瘘SYal&xu~b7̉ٺMtK쌦|0QLUPEjt'rԴ֏ϫiN [LJhAoJ~RZ"gӓ"HeO2z<%:{U,(8H)6NEC9Eʷ_F'GaٟD8.'}^'ߖ>m&9~b*kG-mM\жc(|_9e# ry/2%ьT)`dJq)b s 1YˠMg v.HsO<`3, A(>!vg4nxFn@" <3-A`M@PE-e/N'DI~w`-pS/C OKކJ9j?*Ƈ7BoM'}.$"֍U;|^i"Q:[5 C (7 Bd[Ab?7QOWG j}նbX/ yej 1&n"!F ƣSR!Y m(©GE WtL+E!ѫHǔxaBK/= 6!X6+\]#O0齕{L8H^J_9 7[MNytÞH貄2^b8̹/G9Pv]@p Qv;}ʆ$S~t饜U@uVqxc,OSLLB0 ; @Іv p0w"H`C@+VŜ+2#qfl=1נoWWjдEb w2_I_Y~25E\ڤA߼qۨ1+`|۵- A㤥`ՃP$jzh!nxku5RZߊP,[Dg*9 H+@=,Aa^y!Ef~e'U!8/ۏ)8̨" h a'ZuqH]n^qa+9ԏ9R3~rV&*<jWCQ;ݜt]xԺNzAMrU,]>C\ܮFI.#1IcPᛜSMJc\)=J #C8 3}@í8Hft%Ŭr)2ԋgSYe!^%ԙ;뤮e!#o|D\|Ik%{s{G<ŇaUQ&1cM(XƯK^ `hsYU<}~#դ]dQqD X,3އ^<%aA۷iGQ.VvD]FLA-\)F:`}q5ޜ-R aÕةJg Pt&7XǛڽ/|]=QhbRCpGDXvbф  |^@o"'W{ϡ0eP*QܭlZ1 u1ߎ`m~QLŬ2EЭb>j֗ k?CȇoV&[;|Hl U eorg))PxYo7AW5\`8𮤵C+Ŧ -x:ES.Azs-784 >!y uލ@`Td`LgWHrmcuN_L;WgpEnS+C$,C<B&f.ԍNyw;`JłlwA\ZZB"Mӧ Han=&2 Nx۞)afg|ҜdpHog]or m I[BQKژ#!(:-Uܹ[Q0?v֎wz*ժSX6*zhkSD}S ] ]*AQI5z3kCK5Vz|hRr_"cIL'pGǏ<Wܩ]Zg^wh g|jd<a ;SFé -2~wHRyEtq-rwAA(/Zeb/{'j`I*WpIBEh<Ȇ6+5Ys%oG؇CfE烟!Βn~+őA?<&=i衐W.IVUȆR۱;n}9猋^3J:nK< V f,[O>w^!PXPg\&xk]~50i$E,[ϴd٧fI^t t*`A][S\/é@\1yGo/2Xu} 4wy/~z4}IA^w$Y\qNXz+wVհ'un 揬c=IѻUIX,`vcs%E'XJ6"s|F%QބUd@G'&"T<'PS!Z򬿝*(JmxT(i8<i:0 @Zb]Ҩ9RPeIO{k̵:݆"שHu;{o,}׺ 9,Gޑr]LWn, S?q`℗fk96Ѡϣtn2Ͳ~lJ r ϳfb_sAQr;äꙺ/0qϼcVxUƹoGޯ" WNsdI&cŽ&D'q[6` ᑴPW*Qt",$ZYN5ipPF[n!)g#*\D>f:Fdz(ZHSrV~ai%9vP`TQ1W*~|sv $L*^+g|^ 'Vww9*g3%831F|oxO0xؾ8As8%19fn?QjOcVIv0LzNZ;"9~?}Q,HD%;,z7|G9J{ju\Z|K02q`)9Ц7+Ht@J'>ȣbL@GȷP*.6u,}*)#H#tz߇2tߊ#r0Œ0CٿDa` x4ru֮H`#ʀC?CMVj=Tqn M nR& tѺWe\<핢jy*|yȈZ BCo']>9ػmU0 [mS;A>덀!_*H$dFejAoS;4 r$Ttxi7LnwG=sUbvBvx+~Tܟ"x Pl3o%$0njwNʆ"#TsUWe~<-@omJCd$$hitk"=t?Ibg\e-8:./ ̜5 c'q5EV?]7tm% RgZ䒫 19 6'nO}uxcF@+ӳl|Oco&De2gr$3Ku0 P"dpߗ?ǻ\! C2q sCr<h kldiٿ;ZZ`j^Zdp wH0fV!'j /꛲ZX煇~uIe;joooE/f7UnUT#ouuI9ilpmZ_Dj䴗ZNe=bK wjnr#f} GQYѿf4| oL h|:8|< p.곔ĽK≸pt=KGv%U4 }g+bPwVS;A񆤒c’b]˛49@D'yqU4=I?"1rG'l]iq³b>,RSEII\ӉwS|ȸvz|羳SA_ L󮑌'gD,DtR>QI*<>Zknk@V?ȺcNUFY<%AvI@ՐR|HʡshJgoL5vЪϲPS>1b|F))̰sY "D=Rڈw@QI!;B;b;h{ `@K\c]87N6&")`ڒcn}L{EO&#x"׳#7RѿuJTd~L[€ٹGUfÁq{Wluo ԀnG_ |"&p;1ʞO;ɰr5;7!F_!JZ"]dWĪZLܽxFLk3,L"6Otv3o`}BS&s/d$iI}C4IDGrK-*_&s_<9rOCpB,L>Jk֘~Z8zfS$ Tbt\һVe +zrr!W'ת[7c8Y;d%Lu8A8Mad9l<%8}zȦOOe0Ai ې5,m4`ф76|=;6>ʀa~iK%SwgSb}.܊= LPѣU$_' r0j(fGZεWP`ga0>F&jܡl5_ÐugNG%2_Ynֳ2HKGgyv-X"nRsU^/%0S HEu'NWLelŠ꘻uѣNTCTuX,ɋl9BB/Yr `|ݦ Ȧ wS]ZK_z3VP K;N4eP#T)(CoPm5j]Dն^3&u]Hd:# E`ˏ=aY;If)Rr_YW?_d86K]® Rx6·bzQQݝ~^tvAZV9xX43 k;7џyGq)kL#9r70p(ٻy-B0Gz}IYwj85OEQW3ILQr:hE*4ge='` Z[ Q%Y̮:"ta1#~ 5$ƌ D# ^:wu1~td r[аd2U=ƖrjHpϜ+ʠUoG2Ұq Sʯh9]u#9T-!!{8Xi{10sƳ%U˛5 vePwڟv%Iq UD $W\]b{12ȉ~Kn\O~cs?7l" Yk a٢tGG27n?ZY+RUYrsRUr7!(O(,"M#'@ mGRRuArK5<9NL N@_Ⱦq$^pԏ{(ko"',wlB+-s˳|:gʨy8>ĕu`aBIجo$YP5}ʦ]-%  'sA9KO͏ WM۶əW*OJЄB2=7,\8:'!\yJT m}QGi|sy֧,53dIPJ<:ᔝ{4 C9.4鉕Ga2Dj>ZE)Qf_o=ñ9d~BN7Fo͉`KfR /e ֽj ?jeAgQ%?ADl:Eh8C݄TA܂򐰝0 fOB! S[pNҖ[6~@LsI5)Q;aZ}28vN<|C=cb;T%mGQ<n, !Nj'h&d?!MFKAƖ$9c)Tڶ Oȭ%Hc3E pmpb cóɿmX+[kdohyvBU ry|xx݉[j Nw~y-~ȶbX~$utBjtJjoS .سql=m1Y_iS y¨ J\o^ə@nn5޺Pg#MRm j(92m<)@8C>Ղp:GNӞjdFFMwdض|܋A a]3apw,m=_q'< >k;^Q\ ])]UҔ?yv^ rTА6[R"Db`Ǘ]R%b[t:^⥺X&qj (-:`d/ Mn9n~9l58Ɗg/a\(wtK+XZ jg< >1-v&1ikjw Lյƍ