libldap-2_4-2-32bit-2.4.46-lp150.13.1<>,T]/=„"{IqP~= .>N%̃"1U.nj;j'3+F6ZC5JX-ifML8"|%+V )%:KMg1TXt`US&VL6ە]jҡ/ҭ#P/t ~-9#}Z7SqS?6نbY]`0.TD^Ȗ֩ -%ˆhPŧ8yC2&>/Hb>ABD?B4d ( Bx|   0 8 @ P  (<`pDo(8,9X,: ,>=B=G=H=I=X=Y>Z>0[>4\><]>L^>b>c?fd?e?f@l@u@v@(wAPxA`yApAAAB0Clibldap-2_4-2-32bit2.4.46lp150.13.1OpenLDAP Client LibrariesThis package contains the OpenLDAP client libraries.]build80xLopenSUSE Leap 15.0openSUSEOLDAP-2.8http://bugs.opensuse.orgProductivity/Networking/LDAP/Clientshttp://www.openldap.orglinuxx86_64/sbin/ldconfig\]]]]5be4586b0141c3d825f206b2f9d22e50f5ad274be1a25ea10f4da76e1111a4ad59f7b1ef25a9d7cf1a8a412b1764e7feb52b8cda79866418da2469929df54018liblber-2.4.so.2.10.9libldap_r-2.4.so.2.10.9rootrootrootrootrootrootrootrootopenldap2-2.4.46-lp150.13.1.src.rpmliblber-2.4.so.2libldap-2_4-2-32bitlibldap-2_4-2-32bit(x86-32)libldap_r-2.4.so.2openldap2-client-32bit@@@@@@@@@@@@@@@@@@@@@    /bin/shlibc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.1.2)libc.so.6(GLIBC_2.1.3)libc.so.6(GLIBC_2.12)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libcrypto.so.1.1libcrypto.so.1.1(OPENSSL_1_1_0)liblber-2.4.so.2libpthread.so.0libpthread.so.0(GLIBC_2.0)libpthread.so.0(GLIBC_2.1)libpthread.so.0(GLIBC_2.3.2)libresolv.so.2libresolv.so.2(GLIBC_2.2)libsasl2.so.3libssl.so.1.1libssl.so.1.1(OPENSSL_1_1_0)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.1]B@\ڭ\r@[H[@[vZ@Za@Z@ZZ.s@Z@Y*@Y*@Y@Y@YYp@Yf@Y7Y6@X@X7@X$a@XWk@WbW;VVɦVŲ@VŲ@V@V@V@V@Vf@V^@V\:@V@V @U4@T@TuWilliam Brown William Brown Peter Varkoly varkoly@suse.comckowalczyk@suse.comckowalczyk@suse.comzsolt.kalmar@suse.comzsolt.kalmar@suse.commichael@stroeder.comfvogt@suse.commichael@stroeder.comrbrown@suse.comjengelh@inai.demrueckert@suse.demichael@stroeder.commichael@stroeder.commichael@stroeder.commichael@stroeder.commichael@stroeder.comhguo@suse.comhguo@suse.comjengelh@inai.dekukuk@suse.comhguo@suse.comhguo@suse.comjengelh@inai.dehguo@suse.comhguo@suse.comhguo@suse.comjengelh@inai.dehguo@suse.comlmuelle@suse.comhguo@suse.commpluskal@suse.commichael@stroeder.comhguo@suse.commichael@stroeder.comhguo@suse.comhguo@suse.comhguo@suse.comhguo@suse.comhguo@suse.comrguenther@suse.comjengelh@inai.de- bsc#1143194 (CVE-2019-13565) - ssf memory reuse leads to incorrect authorisation of another connection, granting excess connection rights (ssf). * patch: 0201-ITS-9052-zero-out-sasl_ssf-in-connection_init.patch - bsc#1143273 (CVE-2019-13057) - rootDN of a backend may proxyauth incorrectly to another backend, violating multi-tenant isolation. * patch: 0202-ITS-9038-restrict-rootDN-proxyauthz-to-its-own-DBs.patch * patch: 0203-ITS-9038-Update-test028-to-test-this-is-enforced.patch * patch: 0204-ITS-9038-Another-test028-typo.patch- bsc#1111388 - incorrect post script call causes tmpfiles create not to be run.- bsc#1114845 - broken shebang line in openldap_update_modules_path.sh - fix the script- Emergency fix: move tmpfiles_create post from the library package to the main package's post script, which ships the tmpfiles.d configuration. Fixes the post script of the library (-p /sbin/ldconfig does not allow more statements in the script). - bsc#1111388 openldap and /var/lib/ldap/DB_CONFIG* (transactional-update) * source: openldap2.conf - Added a patch to let slapd return the uniqueness check filter used before constraint violation to the client. Fixed broken memory handling in affecting error response of slapo-unique ITS#8866 slapo-unique to return filter used in diagnostic message * patch: 0001-ITS-8866-slapo-unique-to-return-filter-used-in-diagn.patch - Don't require systemd explicit, spec file can handle both cases correct and in containers we don't have systemd.- Fix CVE-2017-17740: when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack * patch: 0017-Fix-segfault-in-nops.patch (bsc#1073313)- Fix slapd segfaults in mdb_env_reader_dest with patch 0016-Clear-shared-key-only-in-close-function.patch (bsc#1089640)- bsc#1085064 Packaging issues have been discovered around the openldap_update_modules_path.sh which has been corrected: - the spec file was wrongly configured, therefore the script has never been called - the script should create the symlinks first, as slapcat is useless on a system which is already affected.- bsc#1085064 Add script "openldap_update_modules_path.sh" which which removes the configuration item olcModulePath in cn=config which is after upgrade from SLE12 to SLE15 holds inappropriate information. If the cn=config is being used on a system, the conflicting items in slapd.conf are ignored, despite of it, the backend DB configuration section has been also commented out in the default slapd.conf. In case of correct cn=config (the olcModulePath has been already removed), the script stops without touching anything.- Upgrade to upstream 2.4.46 release - removed obsolete back-port patches: * 0013-ITS-8692-let-back-sock-generate-increment-line.patch * 0016-ITS-8782-fix-cancel-memleak.patch OpenLDAP 2.4.46 Release (2018/03/22) Fixed libldap connection delete callbacks when TLS fails to start (ITS#8717) Fixed libldap to not reuse tls_session if TLS hostname check fails (ITS#7373) Fixed libldap cross-compiling with OpenSSL 1.1 (ITS#8687) Fixed libldap OpenSSL 1.1.1 compatibility with BIO_method (ITS#8791) Fixed libldap MozNSS CA certificate hash matching (ITS#7374) Fixed libldap MozNSS with PEM certs when also using an NSS cert db (ITS#7389) Fixed libldap MozNSS initialization (ITS#8484) Fixed libldap GnuTLS with GNUTLS_E_AGAIN (ITS#8650) Fixed libldap memory leak with cancel operations (ITS#8782) Fixed slapd Eventlog registry key creation on 64-bit Windows (ITS#8705) Fixed slapd to maintain SSF across SASL binds (ITS#8796) Fixed slapd syncrepl deadlock when updating cookie (ITS#8752) Fixed slapd syncrepl callback to always be last in the stack (ITS#8752) Fixed slapd telephoneNumberNormalize when the value is spaces and hyphens (ITS#8778) Fixed slapd CSN queue processing (ITS#8801) Fixed slapd-ldap TLS connection timeout with high latency connections (ITS#8720) Fixed slapd-ldap to ignore unknown schema when omit-unknown-schema is set (ITS#7520) Fixed slapd-mdb with an optimization for long lived read transactions (ITS#8226) Fixed slapd-meta assert when olcDbRewrite is modified (ITS#8404) Fixed slapd-sock with LDAP_MOD_INCREMENT operations (ITS#8692) Fixed slapo-accesslog cleanup to only occur on failed operations (ITS#8752) Fixed slapo-dds entryTTL to actually decrease as per RFC 2589 (ITS#7100) Fixed slapo-syncprov memory leak with delete operations (ITS#8690) Fixed slapo-syncprov to not clear pending operation when checkpointing (ITS#8444) Fixed slapo-syncprov to correctly record contextCSN values in the accesslog (ITS#8100) Fixed slapo-syncprov not to log checkpoints to accesslog db (ITS#8607) Fixed slapo-syncprov to process changes from this SID on REFRESH (ITS#8800) Fixed slapo-syncprov session log parsing to not block other operations (ITS#8486) Build Environment Fixed Windows build with newer MINGW version (ITS#8697) Fixed compiler warnings and removed unused variables (ITS#8578) Contrib Fixed ldapc++ Control structure (ITS#8583) Documentation Delete stub manpage for back-ldbm (ITS#8713) Fixed ldap_bind(3) to mention the LDAP_SASL_SIMPLE mechanism (ITS#8121) Fixed ldap.conf(5) to note SASL_MECH/SASL_REALM are no longer user-only (ITS#8818) Fixed slapd-config(5) typo for olcTLSCipherSuite (ITS#8715) Fixed slapo-syncprov(5) indexing requirements (ITS#5048)- Use %license (boo#1082318)- added 0016-ITS-8782-fix-cancel-memleak.patch- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- Add openldap-r-only.dif so that openldap2's own tools also link against libldap_r rather than libldap. - Make libldap equivalent to libldap_r (like Debian) to avoid crashes in threaded programs which unknowingly get both libraries inserted into their process image. [rh#1370065, boo#996551]- use existing groups instead of inventing new ones- added 0012-ITS8051-sockdnpat.patch- updated 0014-ITS-8714-Send-out-EXTENDED-operation-message-from-back-sock.patch- Added OpenLDAP new feature implementing OpenLDAP ITS#8714 0014-ITS-8714-Send-out-EXTENDED-operation-message-from-back-sock.patch- added overlay trace to package openldap2-contrib- Upgrade to upstream 2.4.45 release - removed obsolete 0010-Enforce-minimum-DH-size-of-1024.patch and 0012-use-system-wide-cert-dir-by-default.patch - added 0013-ITS-8692-let-back-sock-generate-increment-line.patch for supporting modify increment operations with back-sock - added overlay addpartial to package openldap2-contrib- Remove legacy daemon control that was used to migrate from SLE 11 to 12. (bsc#1038405)- There is no change made about the package itself, this is only copying over some changelog texts from SLE package: - bug#976172 owned by hguo@suse.com: openldap2 - missing /usr/share/doc/packages/openldap2/guide/admin/guide.html - bug#916914 owned by varkoly@suse.com: VUL-0: CVE-2015-1546: openldap2: slapd crash in valueReturnFilter cleanup - [fate#319300](https://fate.suse.com/319300) - [CVE-2015-1545](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1545) - bug#905959 owned by hguo@suse.com: L3-Question: Are multiple "Connection 0" in a Multi Master setup normal ? - [CVE-2015-1546](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1546) - bug#916897 owned by varkoly@suse.com: VUL-0: CVE-2015-1545: openldap2: slapd crashes on search with deref control and empty attr list- Drop binutils requirement; the code using /usr/bin/strings has been dropped in openSUSE:Factory/openldap2 revision 112.- Remove superfluous insserv PreReq.- Introduce patch 0012-use-system-wide-cert-dir-by-default.patch to let OpenLDAP read system wide certificate directory by default and avoid hiding the error if user specified CA location cannot be read (bsc#1009470).- Add more details in the comments of slapd.conf concerning file permission and StartTLS capability.- Test for user/group existence before trying to add them. Summary spello update.- Move schema files into tarball addonschema.tar.gz: ldapns.ldif ldapns.schema rfc2307bis.ldif rfc2307bis.schema yast.ldif yast.schema - Package previously missing schema files in LDIF format: amavisd-new.ldif dhcp.ldif dlz.ldif dnszone.ldif samba3.ldif sudo.ldif suse-mailserver.ldif (bsc#984691) - Fix a minor issue in schema2ldif script that led to missing attribute in the generated LDIF.- Enable build flag LDAP_USE_NON_BLOCKING_TLS to fix bsc#978408.- Move ldap.conf into libldap-data package, per convention.- Move ldap.conf out of shlib package again, they are not allowed there for obvious reasons (conflict with future package).- Build password strength enforcer as an implementation of ppolicy password checker, introducing: ppolicy-check-password-1.2.tar.gz ppolicy-check-password.Makefile ppolicy-check-password.conf ppolicy-check-password.5 0200-Fix-incorrect-calculation-of-consecutive-number-of-c.patch (Implements fate#319461)- Remove redundant -n openldap2- package name prefix.- Remove openldap2-client.spec and openldap2-client.changes openldap2.spec now builds client utilities and libraries. Thus pre_checkin.sh is removed. - Move ldap.conf and its manual page from openldap2-client package to libldap-2_4-2 package, which is more appropriate. - Use RPM_OPT_FLAGS in build flags. - Macros dealing with old/unsupported distributions are removed. - Remove 0002-slapd.conf.dif and install improved slapd.conf from new source file slapd.conf. - Install slapd.conf.olctemplate to assist in preparing slapd.d for OLC. - Be explicit in sysconfig that by default openldap will use static file configuration. - Add the following schemas in LDIF format: * rfc2307bis.ldif * ldapns.ldif * yast.ldif - Other minor clean-ups in the spec file.- Use optflags when building- Upgrade to upstream 2.4.44 release with accumulated bug fixes. - Specify source with FTP URL - Removed obsolete 0012-openldap-re24-its8336.patch- Relabel patch 0011-Enforce-minimum-DH-size-of-1024.patch into 0010-Enforce-minimum-DH-size-of-1024.patch- Upgrade to upstream 2.4.43 release with accumulated bug fixes. - Still build on SLES12 - Loadable backend and overlay modules are now installed into arch-specific path %{_libdir}/openldap - All backends and overlays as modules for smaller memory footprint on memory constrained systems - Added extra package for back-sock - Consequent use of %{_rundir} everywhere - Rely on upstream ./configure script instead of any other macro foo - Dropped linking with libwrap - Dropped 0004-libldap-use-gethostbyname_r.dif because this work-around for nss_ldap is obsolete - New sub-package openldap2-contrib with selected contrib/ overlays - Replaced addonschema.tar.gz with separate schema sources - Updated ldapns.schema from recent slapo-nssov source tree - Added symbolic link to slapd executable in /usr/sbin/ - Added more complex example configuration file /etc/openldap/slapd.conf.example - Set OPENLDAP_START_LDAPI="yes" in /etc/sysconfig/openldap - Set OPENLDAP_REGISTER_SLP="no" in /etc/sysconfig/openldap - Added patch for OpenLDAP ITS#7796 to avoid excessive "not index" logging: 0011-openldap-re24-its7796.patch - Replaced openldap-rc.tgz with single source files - Added soft dependency (Recommends) to cyrus-sasl - Added soft dependency (Recommends) to cyrus-sasl-devel to openldap2-devel - Added patch for OpenLDAP ITS#8336 (assert in liblmdb): 0012-openldap-re24-its8336.patch - Remove obsolete patch 0001-build-adjustments.dif- Introduce patch 0010-Revert-Revert-ITS-8240-remove-obsolete-assert.patch to fix CVE-2015-6908. (bsc#945582) - Introduce patch 0011-Enforce-minimum-DH-size-of-1024.patch to address weak DH size vulnerability (bsc#937766)- Introduce patch 0009-Fix-ldap-host-lookup-ipv6.patch to fix an issue with unresponsive LDAP host lookups in IPv6 environment. (bsc#955210)- Remove OpenLDAP 2.3 code and patches from build source. Compatibility libraries for OpenLDAP 2.3 are built in package: compat-libldap-2_3-0 Removed source files: openldap-2.3.37-liblber-length-decoding.dif openldap-2.3.37-libldap-ntlm.diff openldap-2.3.37-libldap-ssl.dif openldap-2.3.37-libldap-sasl-max-buff-size.dif openldap-2.3.37-libldap-tls_chkhost-its6239.dif openldap-2.3.37-libldap-gethostbyname_r.dif openldap-2.3.37-libldap-suid.diff openldap-2.3.37.dif openldap-2.3.37-libldap-ld_defconn-ldap_free_connection.dif openldap-2.3.37-libldap-ldapi_url.dif openldap-2.3.37.tgz openldap-2.3.37-libldap-utf8-ADcanonical.dif README.update check-build.sh- Upgrade to upstream 2.4.42 release with accumulated bug fixes.- Upgrade to upstream 2.4.41 release with accumulcated bug fixes and stability improvements. * Add patch 0008-In-monitor-backend-do-not-return-Connection0-entries.patch * Remove already applied patch 0008-ITS-7723-fix-reference-counting.patch * Remove already applied patch 0009-gcc5.patch (Implements fate#319301)- Add 0009-gcc5.patch to pass -P to the preprocessor in configure checks for Berkeley DB version- binutils is required for "strings" utility invocation in %pre [bnc#904028] - Remove SLE10 definitions/bin/shopenldap2-client-32bit2.4.46-lp150.13.12.4.46-lp150.13.12.4.46 2.4.46liblber-2.4.so.2liblber-2.4.so.2.10.9libldap_r-2.4.so.2libldap_r-2.4.so.2.10.9/usr/lib/-fomit-frame-pointer -fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Maintenance:11079/openSUSE_Leap_15.0_Update/06491bedb2a11a89cd58f1ace579126b-openldap2.openSUSE_Leap_15.0_Updatedrpmxz5x86_64-suse-linuxELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=9f234e8817ad6e7138dd8e792a40cfcaa7a0866c, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=6d0015bf631b3e704fe38bd6784ebd1e4284daa1, strippedPRRR RRRPRRR RRRRRRRRRRR R RRRR R Rutf-8ff132ee8d72828505cf04a79f977fdd350dcf27c378753c25334fc3c1b00b739?7zXZ !t/mS]"k%۫ïnagA]?f=)\+/% UuMj#o7/=21@,'tjnq%A`k #U֖|ơd&f/ 3\vEJ+ʃiWHƵξH$>M,G%^&UI&Cw R! i©ql)'W2Su5rs?D[!BX%FFo =cY9N:P؏y|ZGysko[zI?7S%9CO`0 ;Tkwd"| rc* fh,[Fu5QYg}\3 ;]8{(B}'kx/ G$f_Uo8*6:aB+%Mr̬)5 r^SO1&i<l! [1οrdED/-GjqVH GW5(e.k@݋TAݾO1$۬N%KXm Y%7#Ct2.vjl9cX cw+|bI`u/Fyx)#JOݕDtv L[X'sXavqZ1 >4k3GKE `^E8,%FJfђ´|J&QLr:.I/լ]5H #( ]xG5Ɲ0Ë^zJʷyNW7q"+L & 8)]M^?x"GY|,+ 7@pY $O( Shkt5]*whA=mSM:myMI{_rE3y8OhNɌ|#e-֜"/6 '%ˢ"[*QKeVr MZdI  f;isYؿb"&H|k/p#R{q~v9y࿓ 6GE#*d%eWdI d?/Іv /҉^z6ó0@4Q GS!8ӅE|eC_;_Zgsho.;-,D)Ifq!^m tF.kqP(;\YGð{G^>x1# цu¤Vx+Dٴ~)V @Im3J{㦢l˝% cYSi͒Z #pMK3:*ܸw o%G\5!A1ʚEWn) KIѴu;p_qX)˂S\f^iFc>Zz=+9qB m3q@*IӼ~jm[3Ve\+νdB~0 $.JOt K(3ߞW HסQ/Js]Ud4BN꒻i7- >!TϐO:Ӆŀu:LuB/dD]m=M) nx#oh=}|4(`IE"JiAq~2@/<7͊tc:xClh؀nj(wmNRxJG^0W.m?`xcm=ʵA=3oBk0g}?4g4+~%`Q9QV+UHUR]5srKe4|_;ZA@K}S˦;[?w&~#*ͺiռMFANSuPDX'`Q$F(;2>eUTj 9BPFT\yƒ7=EQ%s'%KBufMD;CJxβ^C(Q A!..\c#' "6cil@xqSdu]3yjg+rғOb F^약R4XiFPh>n+!Ƞvuvx8<&WHX"%`Yv0e_q޾QbuC`~{mC3Ɗ Fj&oT SjO"iѮ9R};ܸσKĝu&$NRp|Rh/2Be#Q$crKDs9q"{>G+()5CjB<2n,[G^+adFSCyqJ32DհB8TPC5w9V Z*~m@Ɨ?_OӎVSVp{YFas P|"f'jhK CL cAJ!񝃧7LB̈W"qTyBNP))<]9w(NMUb$eխo_Frn#@!gBr>$W'ΝPùAƭ9n$3$gANֻC='Nv|\=<AQa5K X8e:.[::Ayތ6W[V'¡)Oy_!EݩnO@ ~tyhb~JQ`};?8So fr@mN o/x< L )ap9 ES^g53SnA]Yp9qG'T ¼]l iGt0ite> KyBE:Wcio_j BeuӐ @º>UDp,H4q* |AYN@Gnaqi fEmokn ك9B@ޓ͍-}&Jk`(8)ZTךhm{ƽ3$;jTl`LG 6\Gެb@bP |ڷv^9 =kX r)IX^鍖Яbo U?:1A i]S\.۴B\ơ~Ly>GXįU_C%:Tn̞Üts&3owzO۰OU ^2 iSRok2Z !nXeYx0EV$%h1+lļxW_A?O&iF%T7MnL]AHtOv*aʭ]cO)a`paD6eύ5qFq[e~ 6n-!(OWu>ݑb0(zJgL//Hth13j4DF,bd6J%p4C;z{%l:bFWzն$G&pGa552 ek@Jirѻr/Pj‰|ImU\T|q B}ex͎uUY2=԰VsH.wvnJJ ~߯9Mlҁ!q2%*r3 5LkDjHjTY;O~C_? FZ;: Ha,b_j/4gs^aq`d .Tbv9ZOMKǺ{ld?f6zk5*,╛dX_u!NR8N=jOgΫ,pE mgcwD2u= g /k+V !-ݼtJ ŗ [b$ VB\"T56S b|'h 8kZծpYNk+ oa JB %5@U"ǖWL`i[ Dv<\>QS7o` 4j`Qphcz=wbI*U@  HT &|kp0:kR0#\+E{ba6RHlUkW>9N)V̖d As۠ˋ@L,Jduhz[;ᶔ f[LCaXM<O;vvǔ8oLUrGWFKe ނ`P}9QƗ{2@$RaFM4)VU"ظڈ#ud o"j|[^UdEsź@BAHr\w޺>"UP\Tg'=c|z,CU/,w*($ǞT~O:J :B䛀"Fū&b')QA{,h u8j6_+ׇ׾JMuLD<ˏCvoDݪr2Co#m64dTUAUptċOBXSR1 aQ$_uP<׋b}Z^mDniUmCoIwo WOA}v!,vqoVfa1Y.;6e4);eJA(0ĝ+ʀ(2ubЃa#m 6gc].(--+5boW?y?޾ XEI39 PǞ4dHN6fx 3ɦvj>VbB_bqr >dEʭߴn,hbhfUJ*zD}6ՖžS&n!&=>z/G1toMv:D}?%2/UHlN9N`ȲJR=9"RX_@Jʞ]@ ,u'ۨ٧iY'KQEY!ynf#8bř=0\?%|W59]"tdćQF ! >Qk_D7HRAoKo, X@dRk npuVid4(0)ԁ # ~l:}y.6˟R"p͢=x8DՎ-rPefdYI"?"([/ O=-J#XuM,_οp753d(,`:>^߁H:1#5|iLً"OR[#H=%O'*9_svJ &((`HޫͶ6[Vs-K{KP}IGd|R =&8IcϨ-'G8AmYBd#fSNA⺱|naA)@3 yȼ3`[Als. )sH 9:Ge붓IvѬʜ? ~b YJBO}Nu;,HkB/7W2ܮ5KHI,>LN7\*%Hߚ^N r 8 Dvd@^zB:]O? 6o2Ro}\VތiU%jj&Üi4ھŵr,1e=WοLw:'G2^`}6BIJF0pnmS\ۺҖ?B"5deLBKZUtٲqbgvSm/:dVKܛ7/!7~xr7TbRD-M.^Jq]l>Uc"OjI*퀶w ,>wyiFP0BJS1e-` [/}("hXMUg24iҰD+j-`C{:_:+HD:{3WLnJf2ޞ974;ww(K 0QH[2c+]Z"Ll9J@kvCB>?_'@k爘-coAW(A;je[8i1ܐO$ւ_>V*~Lg" cS+5,0$6Eo@_}z%ZT~< q*t6]YzM|4i=k;G F8am f]P@@BQADȸUY뽋 Sw8RXˆq\tiv6*rTR?~~K^fG^yxS):!D Y+.~Ѿ{t+s&Ε;ǥ¾>DRA7^,:>ko_w:=A'?B} ?ϭ P:$EJ|Iݥdo8\ˢ9+mؐX |٥U eV*cgK̞ Rh,Űu_*'OCrH_61b8h a}?49h]Ƴq;f 4-l50+tLp$z٣? z@ezK/?BCp}Έ]aH< 퇟%\9L< i:cNHטּ׼IѨᄔ%D J6pLF4,NcӄIoI;K/l@!vm-ol+UK] T"#gl9CLjg#{p-f󩘠qfRMO)nNM ҿf;wBH@g-2{v?Kw̠ 3c'h!AmR$CV < MO $$Ϋ 3q^9TֆXʛ&j"I2kE*{Z2|g텲3a򪾠[/W]4E U۰+9v1/^ǁ7mb]GBAD%oR{o';<5cF^QcZg\DuFa#M7sBhQ$;b^LJ!>E 4U< 8aH#X5ųWН:ֿhbl=^i'IcO=YeZtn!q9P$~A yH;z,8~D,=P;sAG ݹ"8|*ܢ?&1HÉ^d } <$=:Zp&5G^k%A2}>'SFU5KF3US 24*)7zQ"K"}62Z{- U3+E ݃^W"_T?>M)j5js nJX T鐺zӔ$gXij"D1Q[;)q>.jNKIyS_G,D "5t7e^a$M >%[`jw[ jFݩG95@w,R ?=:|9[~!>aPq\@CS{†0[3kcaz͒3RT '̞ƞ}.Qq/ QϏ9GxoX@!xb?nXth\?Wݿq2{uIs!&u3ٲإu3,3r-?#v *\u,a*ԕV?QA=b3h ;7k4 x ՙmaZmhumw,nsbĄ) N8lPe:VU~A(-[2j@>kZ,v͛SƊ6ae !g7W6~24LC~Kn"`*H&ou砖 UpǜVEȴف؎\ fZQ ~dȻ;' Pqocs]YC{1+EX1dbV||EN̺"lZrI s1ML-ioHr=i߭+ͿSI9P_SӽbV1*e٧L]>=OTVo#98F/Pwx+d,RvkVU?8f$i|6oNNS@T@|&C5j7c bdܻ{XEcKI~ąɚTт~Avm4*ҫLeE, .ގZl/8tҧK 'gq >A*g#,u\i^1Xobbp-6 %bDm Fբ"\2䅜(Y(;~*$Mr pD .v76 ٚB,(vrQ?<5 Sޏ&`u9y F?ks^Ywd~4[JvSs>eVZ)c!.mlB!̘XbVWroNWh'A&{Ŋ+Os*w(^C(Y»7<;|J5LPj$C*}\Q%~ۛfEʯL nQձ`Je{Baod DPZ&jWQ#zć&'2{Ֆ*$?L^D{Vcs^EMug-t><. Zi32jNl}4rJW?Z3"rF䱊BѨ.2u9p)ҠdY fDi˒qk@<5=懑I1A6u.c&pov 4<~S :HlsA\ӕd/F!qw|]dֆBh)Fvcf{.uf/O5(Vd(=ĿPj;Zػ2g ~c:xkEi 9WBayG#LUbBs+a?<k.~~(,Mcf.xX^x{1{Jۑu53{<`EvR=U Ta8;רΑ_ 鍣/ȅuuQlnW]B aՙ$}o\ܟ z edphiB],>TWHCLIV-3_ +.o;ɒM#v{OF&TY;,^Pm~+N\1'GbqY\j2LĞS`ǁM>BNa8믞I-BDC`b QR?riOS\7GGnlpOB+x.FT,10Կ[t5 &m-[4HVC[ yԕ%3|LoA0 &Nym]kvK 5ո[ |^KʡŁE&?grV_l󪗔Xb!:V|X0;4c/󹨮 j"WFHg%,yL8Ū{\4n\'.( ߸!N0]y[9+BRZB0aՠ`SQuGUBK\gBW`.Ʀ$<%2IQx^\p.nµ=ZltΟQg4MO8wCH:te$`>fKM½7SHE5L&wrA=)A?nYM-C[@yw3e`"Wf-b\~0@nN9c!g?iN +Z}"ffOJv$G&Ǟ$tg2f@k%oxǼ peۡ8PFWUv[S1,FM&2o+t;O}4 W|]GL,z{KA-s0 4BqF~ck6?v*?~nr{fW]b1/Qqi PcLCˏ}En(yBrxUh~oG+)E)xGڲ/Η. jP B p6ՒԹ!^IB3!h<' LQ@yϖ9i\.(-kCxCtFm(d3$%/+%ޫ] LbTdqa잷`5O9'nl9,VOw-oI-[޾{։g?s^- Xk`SdZq(#I+gΑP< uhWgt,N(%Ζ28wwo+Xթy| bg3&WQ/2ѷo2! 'e[b锜آ%7>+C֮+,њOCsႜiiJ՚-~nڟW28͹nzov"9t1I0VGXRBXӜx_1n9RGZ(z;Eu&LQͨfNۯP`_IC,we[SAXgIqHɌޚmF224y7km^;mv.Z-vE}/ǤɆ.;,m}PT(T_5F '0JQFl.w2,pq͔d3LWt@yfd ggYɂ*E>mxl`A͍s\>qj2nOͿY9Ibifkט3F(;K̼8 䲃;!8{ЬW^jV`I6JC\Q滃]3d4? %+S_L |r;\E=EoQ'SnH8Aų[SDPGb(h%(SǾ Z|&>>uliS^8kp5pFvW$}PHXԮ*&.\b_.8+g㛜i0e=x^ <C`34E(5W3p/{0 2ڹ8G VzO!: 6W֭wyGaEt @A{(="ڵ6MqDq&3^"5H/ gH(Я&+fFs`M PY .h{S5Or2)vRqdC ΄wȀg=WCv`Pq{ykqN*^~9r1lީTTc;yNƲ^T?s__)ڿ6 #S =Dfq>yNKu~ÜwJ[EySҌiۢ=PwN)1RJj,xxϼ3W64֨зbޏ@u[:E}mTNaxswJSD skԯ+]`Xesƿo z']63._oȪT'ͧh"%u*uBrF*:Y k:2doɚ8C2S6Jҋfv!o ,VR6 'Zc J6ml!T(8r\6|FNǃK0I3|yc6z/WwNut5e, l (Dfv&2(T4D<:#TAD#,/⾼v.±TRz&Ȭ9Ds0]GR~.QRܵZT Ԝ<{"ikǠ_x PZ@j |֟ 6}s}M66=$wOnu=ÓeU {(t/Z/ kev@wz8u/t !a;IvFLc4 ~*=~aYi 7s(idmX7S~@6;_z G%0/ 1Utlhu|8M.--O9•W8jZ K$w&]U߼5idܗm)'5v%' i>)& ;r^7g1c &,,*15A^1}-W%ǫ$rkߎx݌L@1uVV^Ϸ}z=0uҲ`VELn,+@%B/iP{9mSM7ǛBv% U*\</Ir{$$({;xr:#8F&djVTDZ}yR~h!mٌs\FRE{@ɺ;*DzKv8T X}h^o>`a%|˸? 7>g[VH?7"'3Xso-EaB swa*af钊w+" l`<;W|їp{8#}Kt\]0Q%ޏ8 {/yӜC1N y]]1#\ +g#H-kc9tC &=@L@RD# z`#A833X҇?m`fQqD=S\-.t>4#S\aMT2}1nNTµ}XW^e nRԸ)@׺m U=ٛ@tq?\ G6 ͐~ *NQ*]ިVu>%td'3<""~բgá#ip)m' M4& +yCEҭZR!uM&RCe%&Duzqo ƒ׷rA=cp fw0s[%nk )\!ᖮfN꧳|8qlΌ'aG11YϧKVg%nAO&/:?c-/EX1VRzLM:ބC+846!Kֹ^񺰕/IZܢ8 OF@SHCǂ]o5^ldZ!I^Q[&;1r.JVPhq [Lu&[P &U58F%INB-j%bs.0|sH(I(J,d7N6LVR6 wfU۵OꤿD,UQR${,jh`bJ1>gUqN ʻq< 1KܷcK®N]!Q-p!4v`G4?|'JѩDBo3OlUd;?* +;H1fuƔSIV4]Խ.YqՉVwk[_ҖK ?'S"ofKɼXVߺ_:NFGI*K0Qƭ>hX $)?fK\[#9-*& ?c2BV#[=d/AWJWA:{xA> 3U 22#u2RŘXeuG&Au5)G%C^h|DH_GѤx̤[d$m l5cHచ9$d|\=V!?-@m)l4wj)ו *{(5t7_@.ⅰgoxq@%F 2TokJ$PZm{7v~wD1aĹ(dPƟd@E;Hr-"l%=jS#mhw!U;O8W3WX@JKݚ^~U]4NW3`f73h,(׏S!\첈9,cv3{HkNَ[P,VoN׀rd1~OhFҵJQ1 akLMwK8˂i=ZP*M,8c﷫LVve OHYgR5wm]u!֊XѨR#N|)j96[? Hic*|kE=DK݇hLac%FR\/ ><׋r_D$YvPgVϽMDa$'p4`K_w"Ir=jI3Һ'-{PR>>< {k.&gYt&?A"Փw^,#%"DZU Bq̂C*;ˢFNOtw]5 6./XmP89z x`5*m:tMv]Y Թ)av[l;fk,#+oCܛOurDI'!6lb >1)R/-xv;=wv!FOf07%gˊ 쏷K=r Il!Ze;UzUQ_ 559;|IuIbEhXC8 BgvWmz0`hΝ:zA5bWD׶?x0ylb l2e`[xqCz^wobbgPxNkIM[kB"% JZ1@LD `17T'&$3MKxF_}f*=-_F?eBHwe%6?W~.mЪH{PWB[SP)'CNA'ݚŒ0ljiZ:=7e?0"殃ӈuaF֠ -mt3 M9j! tC嬪I'dP\aB$MW g82Cm!cηY[& IxjUA2?MɍZw7$ELK|@z[N!=ܓEX'a0?A"fRy''  `qjMp#=N^Fw !`*E>W_FS9 IFk\U A2S(7 ' I(٧+,O„"?IL@M]K4քg+&23.}g0CE8pd*{|_GF&r |/iβZyݝ/8[&. 9?i_狴-51Bn,CQF/a+p-bVtC<$Zɺl /~>0aNR/}Z7TZȈ*׫ˠq[iFiٲC\]: {$U' ]%r<ƀc|;recU> P*5b>B~ wF@tKq11Z'yӧRU}[4I!2hC9Dw`3$gUH|@! BAXk<[eQ)MH~n}QL6Cqe)\h-/^/f:RGWm[;d\1!-έog~Xnn=jnm$nI1T`Fm^XB+XFHE(rQ E`ER#/]IjIPSH[Khh^i3n+Ou]I EP _:Kq-Rץ|+>s[2iRIUllY,웷9$+yܙJ菉M] W tNYqm-1œTt5^lWt(f wYWBG3c嘿ge'm Q|WC$i @HD;ĄM |]/"d1n0iJwceLIdM 9N>crE!b!&c7W4fAؚNY+]J:333i4 (1'wS:~ou(K'GzWuN*Dݠ@hc\4M S1*p/ vHUfO07E.H+^5@>'>&>v)jay=n/PZP{pMeoMPg-HvҘ2-C*iy4Zw@WHC ``4EK .#ʈe\L>gdWg:B|(G^f`$ 5m6Cpsx3k䬚vi17苊GX\i\d4ΐۯQCt , ͞D:z_p;W3"ގ(^#jՖ3c7?F]N)[3cK)ODeA>6Ơ"Ӵ,)M;(!J9mzzâ}0* $q3]sv@LP1=D3?,y,~>Bj4RIܚ/9oJ|: ?B5_H˧I. YZ