libldap-2_4-2-32bit-2.4.46-lp151.10.24.1<>,D`C긋/=„WYIONzD'Xkn$dY⼯<f3 O-}7yxe.eQyr[ ,,∀zG1&# 3Uj?-}9uQcʬuGkPՕ^V(; bn# +N;$E}ls ^hBiK%Gjy2QCԊz8^Hm(E$5al]M= dTͺLc䱨3>obV3jW8: TAJ$?Jd + E| $4 < D T  ,@hxLw(8494: 4>EBEGEHEIEXEYEZF[F\F]F,^F~bFcGFdGeGfGlGuGvHwI0xI@yIPIIIJClibldap-2_4-2-32bit2.4.46lp151.10.24.1OpenLDAP Client LibrariesThis package contains the OpenLDAP client libraries.`Cgoat01x0openSUSE Leap 15.1openSUSEOLDAP-2.8http://bugs.opensuse.orgProductivity/Networking/LDAP/Clientshttp://www.openldap.orglinuxx86_64/sbin/ldconfig`С`C`C`C`Ce52be43e82a177d1180870bba899711d9dbf706a87ba166f46ebfe5fe0e2099aa0784031a9ca6d5a26b339d6ad3c1ba7a6ffe2803bd7e0a3be52e94bfca36b0dliblber-2.4.so.2.10.9libldap_r-2.4.so.2.10.9rootrootrootrootrootrootrootrootopenldap2-2.4.46-lp151.10.24.1.src.rpmliblber-2.4.so.2libldap-2_4-2-32bitlibldap-2_4-2-32bit(x86-32)libldap_r-2.4.so.2openldap2-client-32bit@@@@@@@@@@@@@@@@@@@@@    /bin/shlibc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.1.2)libc.so.6(GLIBC_2.1.3)libc.so.6(GLIBC_2.12)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libcrypto.so.1.1libcrypto.so.1.1(OPENSSL_1_1_0)liblber-2.4.so.2libpthread.so.0libpthread.so.0(GLIBC_2.0)libpthread.so.0(GLIBC_2.1)libpthread.so.0(GLIBC_2.3.2)libresolv.so.2libresolv.so.2(GLIBC_2.2)libsasl2.so.3libssl.so.1.1libssl.so.1.1(OPENSSL_1_1_0)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.1_@_@_/@_FN_?@^^^*@]B@\ڭ\r@[H[@[vZ@Za@Z@ZZ.s@Z@Y*@Y*@Y@Y@YYp@Yf@Y7Y6@X@X7@X$a@XWk@WbW;VVɦVŲ@VŲ@V@V@V@V@Vf@V^@V\:@V@V @U4@T@TuWilliam Brown William Brown William Brown William Brown William Brown William Brown William Brown William Brown William Brown William Brown Peter Varkoly varkoly@suse.comckowalczyk@suse.comckowalczyk@suse.comzsolt.kalmar@suse.comzsolt.kalmar@suse.commichael@stroeder.comfvogt@suse.commichael@stroeder.comrbrown@suse.comjengelh@inai.demrueckert@suse.demichael@stroeder.commichael@stroeder.commichael@stroeder.commichael@stroeder.commichael@stroeder.comhguo@suse.comhguo@suse.comjengelh@inai.dekukuk@suse.comhguo@suse.comhguo@suse.comjengelh@inai.dehguo@suse.comhguo@suse.comhguo@suse.comjengelh@inai.dehguo@suse.comlmuelle@suse.comhguo@suse.commpluskal@suse.commichael@stroeder.comhguo@suse.commichael@stroeder.comhguo@suse.comhguo@suse.comhguo@suse.comhguo@suse.comhguo@suse.comrguenther@suse.comjengelh@inai.de- bsc#1178909 CVE-2020-25709 CVE-2020-25710 - Resolves two issues where openldap would crash due to malformed inputs. * patch: 0209-ITS-9383-remove-assert-in-certificateListValidate.patch * patch: 0210-ITS-9384-remove-assert-in-obsolete-csnNormalize23.patch- bsc#1179503 - fix proxy retry binds to a remote server * patch: 0208-ITS-9400-back-ldap-fix-retry-binds.patch- bsc#1178387 (CVE-2020-25692) - unauthenticated remote denial of service due to incorrect validation of modrdn equality rules. * patch: 0207-ITS-9370-check-for-equality-rule-on-old_rdn.patch- bsc#1175568 CVE-2020-8027 openldap_update_modules_path.sh has a number of issues in it's design that lead to security issues. This file has been removed, from the package, and the %post execution of the install. The function is replaced by /usr/sbin/slapd-ldif-update-crc and /usr/lib/openldap/fixup-modulepath, through the addition of the source files: * fixup-modulepath.sh * slapd-ldif-update-crc.sh * update-crc.sh- bsc#1174154 - CVE-2020-15719 - This resolves an issue with x509 SAN's falling back to CN validation in violation of rfc6125. * 0206-openldap-tlso-use-openssl-api-to-verify-host.patch- bsc#1172704 - Change DB_CONFIG to root:ldap permissions. - bsc#1172698 (CVE-2020-8023) - local priv esc via start script chown -R on olcdbdirectory path. Remove chown -R on start to resolve.- bsc#1170771 (CVE-2020-12243) - recursive filters may crash server * patch: 0205-bsc-1170771-limit-depth-of-nested-filters.patch- bsc#1158921 libldap-data should be requires, not recommends to help prevent user confusion around configuration ownership.- bsc#1143194 (CVE-2019-13565) - ssf memory reuse leads to incorrect authorisation of another connection, granting excess connection rights (ssf). * patch: 0201-ITS-9052-zero-out-sasl_ssf-in-connection_init.patch - bsc#1143273 (CVE-2019-13057) - rootDN of a backend may proxyauth incorrectly to another backend, violating multi-tenant isolation. * patch: 0202-ITS-9038-restrict-rootDN-proxyauthz-to-its-own-DBs.patch * patch: 0203-ITS-9038-Update-test028-to-test-this-is-enforced.patch * patch: 0204-ITS-9038-Another-test028-typo.patch- bsc#1111388 - incorrect post script call causes tmpfiles create not to be run.- bsc#1114845 - broken shebang line in openldap_update_modules_path.sh - fix the script- Emergency fix: move tmpfiles_create post from the library package to the main package's post script, which ships the tmpfiles.d configuration. Fixes the post script of the library (-p /sbin/ldconfig does not allow more statements in the script). - bsc#1111388 openldap and /var/lib/ldap/DB_CONFIG* (transactional-update) * source: openldap2.conf - Added a patch to let slapd return the uniqueness check filter used before constraint violation to the client. Fixed broken memory handling in affecting error response of slapo-unique ITS#8866 slapo-unique to return filter used in diagnostic message * patch: 0001-ITS-8866-slapo-unique-to-return-filter-used-in-diagn.patch - Don't require systemd explicit, spec file can handle both cases correct and in containers we don't have systemd.- Fix CVE-2017-17740: when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack * patch: 0017-Fix-segfault-in-nops.patch (bsc#1073313)- Fix slapd segfaults in mdb_env_reader_dest with patch 0016-Clear-shared-key-only-in-close-function.patch (bsc#1089640)- bsc#1085064 Packaging issues have been discovered around the openldap_update_modules_path.sh which has been corrected: - the spec file was wrongly configured, therefore the script has never been called - the script should create the symlinks first, as slapcat is useless on a system which is already affected.- bsc#1085064 Add script "openldap_update_modules_path.sh" which which removes the configuration item olcModulePath in cn=config which is after upgrade from SLE12 to SLE15 holds inappropriate information. If the cn=config is being used on a system, the conflicting items in slapd.conf are ignored, despite of it, the backend DB configuration section has been also commented out in the default slapd.conf. In case of correct cn=config (the olcModulePath has been already removed), the script stops without touching anything.- Upgrade to upstream 2.4.46 release - removed obsolete back-port patches: * 0013-ITS-8692-let-back-sock-generate-increment-line.patch * 0016-ITS-8782-fix-cancel-memleak.patch OpenLDAP 2.4.46 Release (2018/03/22) Fixed libldap connection delete callbacks when TLS fails to start (ITS#8717) Fixed libldap to not reuse tls_session if TLS hostname check fails (ITS#7373) Fixed libldap cross-compiling with OpenSSL 1.1 (ITS#8687) Fixed libldap OpenSSL 1.1.1 compatibility with BIO_method (ITS#8791) Fixed libldap MozNSS CA certificate hash matching (ITS#7374) Fixed libldap MozNSS with PEM certs when also using an NSS cert db (ITS#7389) Fixed libldap MozNSS initialization (ITS#8484) Fixed libldap GnuTLS with GNUTLS_E_AGAIN (ITS#8650) Fixed libldap memory leak with cancel operations (ITS#8782) Fixed slapd Eventlog registry key creation on 64-bit Windows (ITS#8705) Fixed slapd to maintain SSF across SASL binds (ITS#8796) Fixed slapd syncrepl deadlock when updating cookie (ITS#8752) Fixed slapd syncrepl callback to always be last in the stack (ITS#8752) Fixed slapd telephoneNumberNormalize when the value is spaces and hyphens (ITS#8778) Fixed slapd CSN queue processing (ITS#8801) Fixed slapd-ldap TLS connection timeout with high latency connections (ITS#8720) Fixed slapd-ldap to ignore unknown schema when omit-unknown-schema is set (ITS#7520) Fixed slapd-mdb with an optimization for long lived read transactions (ITS#8226) Fixed slapd-meta assert when olcDbRewrite is modified (ITS#8404) Fixed slapd-sock with LDAP_MOD_INCREMENT operations (ITS#8692) Fixed slapo-accesslog cleanup to only occur on failed operations (ITS#8752) Fixed slapo-dds entryTTL to actually decrease as per RFC 2589 (ITS#7100) Fixed slapo-syncprov memory leak with delete operations (ITS#8690) Fixed slapo-syncprov to not clear pending operation when checkpointing (ITS#8444) Fixed slapo-syncprov to correctly record contextCSN values in the accesslog (ITS#8100) Fixed slapo-syncprov not to log checkpoints to accesslog db (ITS#8607) Fixed slapo-syncprov to process changes from this SID on REFRESH (ITS#8800) Fixed slapo-syncprov session log parsing to not block other operations (ITS#8486) Build Environment Fixed Windows build with newer MINGW version (ITS#8697) Fixed compiler warnings and removed unused variables (ITS#8578) Contrib Fixed ldapc++ Control structure (ITS#8583) Documentation Delete stub manpage for back-ldbm (ITS#8713) Fixed ldap_bind(3) to mention the LDAP_SASL_SIMPLE mechanism (ITS#8121) Fixed ldap.conf(5) to note SASL_MECH/SASL_REALM are no longer user-only (ITS#8818) Fixed slapd-config(5) typo for olcTLSCipherSuite (ITS#8715) Fixed slapo-syncprov(5) indexing requirements (ITS#5048)- Use %license (boo#1082318)- added 0016-ITS-8782-fix-cancel-memleak.patch- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- Add openldap-r-only.dif so that openldap2's own tools also link against libldap_r rather than libldap. - Make libldap equivalent to libldap_r (like Debian) to avoid crashes in threaded programs which unknowingly get both libraries inserted into their process image. [rh#1370065, boo#996551]- use existing groups instead of inventing new ones- added 0012-ITS8051-sockdnpat.patch- updated 0014-ITS-8714-Send-out-EXTENDED-operation-message-from-back-sock.patch- Added OpenLDAP new feature implementing OpenLDAP ITS#8714 0014-ITS-8714-Send-out-EXTENDED-operation-message-from-back-sock.patch- added overlay trace to package openldap2-contrib- Upgrade to upstream 2.4.45 release - removed obsolete 0010-Enforce-minimum-DH-size-of-1024.patch and 0012-use-system-wide-cert-dir-by-default.patch - added 0013-ITS-8692-let-back-sock-generate-increment-line.patch for supporting modify increment operations with back-sock - added overlay addpartial to package openldap2-contrib- Remove legacy daemon control that was used to migrate from SLE 11 to 12. (bsc#1038405)- There is no change made about the package itself, this is only copying over some changelog texts from SLE package: - bug#976172 owned by hguo@suse.com: openldap2 - missing /usr/share/doc/packages/openldap2/guide/admin/guide.html - bug#916914 owned by varkoly@suse.com: VUL-0: CVE-2015-1546: openldap2: slapd crash in valueReturnFilter cleanup - [fate#319300](https://fate.suse.com/319300) - [CVE-2015-1545](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1545) - bug#905959 owned by hguo@suse.com: L3-Question: Are multiple "Connection 0" in a Multi Master setup normal ? - [CVE-2015-1546](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1546) - bug#916897 owned by varkoly@suse.com: VUL-0: CVE-2015-1545: openldap2: slapd crashes on search with deref control and empty attr list- Drop binutils requirement; the code using /usr/bin/strings has been dropped in openSUSE:Factory/openldap2 revision 112.- Remove superfluous insserv PreReq.- Introduce patch 0012-use-system-wide-cert-dir-by-default.patch to let OpenLDAP read system wide certificate directory by default and avoid hiding the error if user specified CA location cannot be read (bsc#1009470).- Add more details in the comments of slapd.conf concerning file permission and StartTLS capability.- Test for user/group existence before trying to add them. Summary spello update.- Move schema files into tarball addonschema.tar.gz: ldapns.ldif ldapns.schema rfc2307bis.ldif rfc2307bis.schema yast.ldif yast.schema - Package previously missing schema files in LDIF format: amavisd-new.ldif dhcp.ldif dlz.ldif dnszone.ldif samba3.ldif sudo.ldif suse-mailserver.ldif (bsc#984691) - Fix a minor issue in schema2ldif script that led to missing attribute in the generated LDIF.- Enable build flag LDAP_USE_NON_BLOCKING_TLS to fix bsc#978408.- Move ldap.conf into libldap-data package, per convention.- Move ldap.conf out of shlib package again, they are not allowed there for obvious reasons (conflict with future package).- Build password strength enforcer as an implementation of ppolicy password checker, introducing: ppolicy-check-password-1.2.tar.gz ppolicy-check-password.Makefile ppolicy-check-password.conf ppolicy-check-password.5 0200-Fix-incorrect-calculation-of-consecutive-number-of-c.patch (Implements fate#319461)- Remove redundant -n openldap2- package name prefix.- Remove openldap2-client.spec and openldap2-client.changes openldap2.spec now builds client utilities and libraries. Thus pre_checkin.sh is removed. - Move ldap.conf and its manual page from openldap2-client package to libldap-2_4-2 package, which is more appropriate. - Use RPM_OPT_FLAGS in build flags. - Macros dealing with old/unsupported distributions are removed. - Remove 0002-slapd.conf.dif and install improved slapd.conf from new source file slapd.conf. - Install slapd.conf.olctemplate to assist in preparing slapd.d for OLC. - Be explicit in sysconfig that by default openldap will use static file configuration. - Add the following schemas in LDIF format: * rfc2307bis.ldif * ldapns.ldif * yast.ldif - Other minor clean-ups in the spec file.- Use optflags when building- Upgrade to upstream 2.4.44 release with accumulated bug fixes. - Specify source with FTP URL - Removed obsolete 0012-openldap-re24-its8336.patch- Relabel patch 0011-Enforce-minimum-DH-size-of-1024.patch into 0010-Enforce-minimum-DH-size-of-1024.patch- Upgrade to upstream 2.4.43 release with accumulated bug fixes. - Still build on SLES12 - Loadable backend and overlay modules are now installed into arch-specific path %{_libdir}/openldap - All backends and overlays as modules for smaller memory footprint on memory constrained systems - Added extra package for back-sock - Consequent use of %{_rundir} everywhere - Rely on upstream ./configure script instead of any other macro foo - Dropped linking with libwrap - Dropped 0004-libldap-use-gethostbyname_r.dif because this work-around for nss_ldap is obsolete - New sub-package openldap2-contrib with selected contrib/ overlays - Replaced addonschema.tar.gz with separate schema sources - Updated ldapns.schema from recent slapo-nssov source tree - Added symbolic link to slapd executable in /usr/sbin/ - Added more complex example configuration file /etc/openldap/slapd.conf.example - Set OPENLDAP_START_LDAPI="yes" in /etc/sysconfig/openldap - Set OPENLDAP_REGISTER_SLP="no" in /etc/sysconfig/openldap - Added patch for OpenLDAP ITS#7796 to avoid excessive "not index" logging: 0011-openldap-re24-its7796.patch - Replaced openldap-rc.tgz with single source files - Added soft dependency (Recommends) to cyrus-sasl - Added soft dependency (Recommends) to cyrus-sasl-devel to openldap2-devel - Added patch for OpenLDAP ITS#8336 (assert in liblmdb): 0012-openldap-re24-its8336.patch - Remove obsolete patch 0001-build-adjustments.dif- Introduce patch 0010-Revert-Revert-ITS-8240-remove-obsolete-assert.patch to fix CVE-2015-6908. (bsc#945582) - Introduce patch 0011-Enforce-minimum-DH-size-of-1024.patch to address weak DH size vulnerability (bsc#937766)- Introduce patch 0009-Fix-ldap-host-lookup-ipv6.patch to fix an issue with unresponsive LDAP host lookups in IPv6 environment. (bsc#955210)- Remove OpenLDAP 2.3 code and patches from build source. Compatibility libraries for OpenLDAP 2.3 are built in package: compat-libldap-2_3-0 Removed source files: openldap-2.3.37-liblber-length-decoding.dif openldap-2.3.37-libldap-ntlm.diff openldap-2.3.37-libldap-ssl.dif openldap-2.3.37-libldap-sasl-max-buff-size.dif openldap-2.3.37-libldap-tls_chkhost-its6239.dif openldap-2.3.37-libldap-gethostbyname_r.dif openldap-2.3.37-libldap-suid.diff openldap-2.3.37.dif openldap-2.3.37-libldap-ld_defconn-ldap_free_connection.dif openldap-2.3.37-libldap-ldapi_url.dif openldap-2.3.37.tgz openldap-2.3.37-libldap-utf8-ADcanonical.dif README.update check-build.sh- Upgrade to upstream 2.4.42 release with accumulated bug fixes.- Upgrade to upstream 2.4.41 release with accumulcated bug fixes and stability improvements. * Add patch 0008-In-monitor-backend-do-not-return-Connection0-entries.patch * Remove already applied patch 0008-ITS-7723-fix-reference-counting.patch * Remove already applied patch 0009-gcc5.patch (Implements fate#319301)- Add 0009-gcc5.patch to pass -P to the preprocessor in configure checks for Berkeley DB version- binutils is required for "strings" utility invocation in %pre [bnc#904028] - Remove SLE10 definitions/bin/shopenldap2-client-32bit2.4.46-lp151.10.24.12.4.46-lp151.10.24.12.4.46 2.4.46liblber-2.4.so.2liblber-2.4.so.2.10.9libldap_r-2.4.so.2libldap_r-2.4.so.2.10.9/usr/lib/-fomit-frame-pointer -fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Maintenance:15533/openSUSE_Leap_15.1_Update/eeb7863dd08c1646d5d31765333a924d-openldap2.openSUSE_Leap_15.1_Updatedrpmxz5x86_64-suse-linuxELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=29d86ca08aa171c18da258213dbeedeb6b7077a8, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=1749efc9e3a075075482aa02578c439cde3a0f02, strippedPRRR RRRPRRR RRRRRRRRRRR R RRRR R Rutf-84a45e6a2ef4c0254d3604543261bd00b5f85587955852366e0225aff761e6d86?7zXZ !t/VA]"k%fkïnagA]?f=)R񐳎xH򷨯xGȬPpzK2U ʉk\ɯMdC+JSkwh!X73k->u/@4iNjf1//>eU0';A;kb_X|&NŤ=fکCݒ+5xݍ;}p13wN%k✮ WBCԍ"F4UugI&Aj5B&0a݊EIZe)DLH O/w&~x'5V |9KɎwUW{5B8 /W~omwZZ=[Ğ>eM2H r޽uPXDIfSC[g&49 ;@+A ՘SGkØ7S=Qh&/BTU!hl2wQîkծk1M*ESt b5_P:_ˋ;g/l܈;Sځv/A`F&a$X!>n}x ۙ@cj/,h\kppɍ5^V;rXဣerJ^!R*灣s4c͵# U xm!Z0,Ɛ}(zd]f6L /yte:@OEP@,k,y2 ժjOn!Q{Y&П*6iLR ?x$XNR >Ari1Vva[m2~ULB.﹊.OyH˭*&"Kxrln}€ݛYod|^ZQZ79(rLt`USjmS~L@Ѭ39:L|UG*OgY DGG+uK".k~Q u aPXbVDpٳ M lsPJڒyªz^+%Dn4KՈ>`Roi xˀ%#_ݱUh3L~|5wP~"I0-dDLTxG1 [-Rh#grTF/ qeDr?>7lhl+Ȅ~2>)4Q#j6%tMn"2c!Θ˥<:AM -ίz@!w&pES|TK<}*.\^׵0ҾzbzqQ*}>*bW>GUu yme d.=},|~A$<˅ iR"^t-mF 2h. ݹcq+u1b,,d12&`@T\WFX ・~_k=9F/s\| <(-tp @Q@(l1ye!BG 0Qvg-ij"R 3g:j$ ٚ+L:o1ٚ=;MѶ;A20_E b̄}:y6f-vUI62`qzRg(iˬB5]2ևȢ"J1 ; C(,Eq9y[vݕ fq7T^WB@īJF<@ ]5Hs8\QwB}JKrԃŒcHrޣAHܱ7փjd", V1_}3e>Z5DwN#옽ڹ)Mx4"|`,>R:&C s#rPspkVA=3D7Kr˹u "ŰlQkmw,lgǏX5TT$Q룿 u$UV>JyS~~Pq+4mXG~7&bH3#/q}AhڿʽG|@\ 2ݚ|JAuHG>䩸8ܠTMVO+\QE/49ff^:d22E8.Cȏ.;Hh~$4ڰ?`}U."LºI|>ĵƲu*03QΠsnT<:v')5!vGU}] n/tVa 5K&iT10ުgϝ/p)aZd9eE7Ls9,QRG]TΖd!!77wS|c1ݯ^G[?dg7#Xs¡Gh4SG+Rby adhh" OΔņqQ޽5٦f(EʘHpA9FΚAK剐Ҩvi.^d4o%3h[C`|9sLf%(*2nEZ)i#@x*x7sIBӉ0:)d*:aC nPx`to^ R:y4F5t۷Fp?S 7~4~ ~P1e%9߁153:|z Fu>UKi|cЭ@Ԣ[kQv-su󷶶*IS3IUffꭩ+X2%XxypL+A`o8ω3ڽ.sHb/ÎhSңu׮5*$0{#!`<쇹:egʦ-͙K?7/}@&1*PrpY| uZjkh n_Mx~cXꤞn+׶Л}oHcPMigNjyVA %]5h'Fg&XqҔs'8k3n.=^iyT$ScO{7͜]lt l2ʹ®R8552 m`9`{(\xxlM DR?s՛mۀo%N}e.(bם쟿ی7}yNo#)Am[q37 ,),ˋ P Q^isCmHTf%^1;\M@lWOUojo7\ ŃYxn @'3 F! 1D-cy%̶x BY|cݣd [^udj 6.=ǥR.̵|s頨rOq.˫Y/lR?z78r^s*3*3d&\y) :Zז{~:V{Ɲj%j~v/ul*gS!x?ncCybd_|rGoiy@R@sz kb+ .!dKF0l > I1ig+fTfNᘁ5}c%H[斢 ?itq!}3Y,vAWwƶ$ҵ-Ly?Z{::bI0Ni;Ĕٻ]\ ;7GyFc㊳gl%b#-*P08WFTTݡ|Vp/͈kIO e$Hé^BxSQ`8$T%7Oƛu=(nH_qT8[9+U8l\E{ᓞY+P'"Qm7(E8@!$׊Gqmkvh}2*4[% ٘XOμ %1pCQ1b1h *ʺ ZCteB-Tl|H /(7JeV܍53M|կK1umL*}M܄!\;q9 ϭE-yU5lX ۮL##/\sCO?P ¼,%tI>7EYzwپly&s r+a!\tm`2qEU;܈^&ÂmjL ϫ=g@f4vU~mlf)j MO="F,no%X},V^"RnZGѿ<d[샌}'-ZB5wZeoE&^e0BISIIаɳm.ܤ+5rߺJ4/UyԸ #=^CN!&nz%Cִey>dc=ώW'!!X01W7;qӯza|u: ڱ;g%HQr8AjsJpXMLA[@& HW)ef[1LF]3O(F>v*Mɿ* &WIm@&z>c*[T@*ws軳 cy=ǜ:1\B0̭>a*Ae*ԨFWnDQ5q˥YEa[.kA.a~:, 66^-Ъi4$!a⇥MG :7ɭ"I~oQv]_ͲxӹoTPVwz-#8 ?40C1{ AW恢(E=&Kb?`5Mvz`‚>`$aƢ+=2lL4+Zr38CInO8bwtd5 [q4ŬcAdk?%\h!-%cXYiA)$"7XiG OHScr_eKf P_c)øC~=89}.Ⱦ/?; \A&M;`qe沵j:hOC_)hdYw >9sci?_ru/_xvcy6Gf;J]4!$4Я~_I \[2\g5W'ԠsDosPR(*;]B6?K{e?,V}R fkYh*}v-*R'r}jQyjLԘΝT&˅d M[DW䱾U!K[d|'2a(q>l^E[C3[H*%|#Ԣk\Z >R1tZʓ1ւi=} [ǼOs3f某=Wo"ORNwbE/| 9 b#@qUʁ('OE%B* RRc1'[ww8eP{>I|{qoZ.ְ֡ly5(ٝalYo . =4_YLlҸ Dc[O<7Wot֠:Qۙ {7!N[Ь[4cJH׫mJqYڪ)$ā`qKgpZmnv&bVRSzF;v2<$Y\񶿣&U4`.i` ^.BM^)-VTEe݁#V!'& MSpGp7d0 9j@wx}2 #w_ɞIJs@:PQ7q\%/BQJ]d5$Ŧz 7u~sKN)8.X:|wDDZ$6xAVA{g縋zO Gуtk͒`,z=|~tU/c ֓D7/4kS\#igKq`/I$z"sO% n 9ҺKE96#PSpČ;'93HБt^*; gc7_".yp9N;&5N͹doK<پ)f1Vu3S u1ZAك$v.!FM |yZ G)&^h W7Ѩ=>sXjjrHu?_ԧw0O껳8'7ljx~`<Ȝ}jp?cW>-v6oMw͸JU@]y))+dax9G~l-b;& _ޢ.Dwr%CÍJ'kFy!5Ȍ%5߆# WKA{# +8+MPV5U72ҫν/F5EŜ^FVP&?iչspN6E=`LcSPKN'8£eRBҚsR5Aٰ0i| tp!4kMGe@9qL'!)0߬ X*lı_Uy,bpIL/;bm)s4og,x1JeՑT dLxwU)ė)S% C$?rkraa^R0(1d)GC)K'M h;a3o&WF] r\$R;Ta/}Q_/0LCz \ȋT 1EW9R73>)"0b@~:0͑iB0j0! L(e4l`@#[ q_ǘ_m;<k gD{W^PV&`00IV^%5Tg@ 'AQ% /)V6}sݞaj>Ggck /o%2À*Y?0i;c93H2Ţ}Vh'}I_eƹ *B\Ğ#;ɒif%Z dһPI]ĽF>#JI˝ؾ]}Bjs]d`.uPMBnēPM[(Lo(1“~^>"C.-OI k5PH4W rn;J QXŌ/hahl@c ~+2}|sN5TͥFh%O3%vR:þd Ei!{ɕ'5Sgm-etLmP~S!SCXzw6v"_C|AOA;` [ Cr,l%q!aM T󶊮s3Pcewe`?P {<\!nyQC(}3MV%ˎF'60)ڛ][zFv1NN뛻ƴi]%pۅ!CA 6M$awcAC;+/qԣ.d 13pSeRjU&<{U3ÈeMdg0ی("*iK6VCpDo!C[6rYQCwAr,M alݞ R1R5i5,Kp+BͶ#IwT=YI34;sm _^^io\3iTa..ܑZz!Q}p_U V6nfVp3r 7ai\dLա qu6)~gkSQp"<@aUOeGhwA}hƽTa$hgDGWNNmysj@y7Q&|@{AL{[8/Y\ :V!Fd"Mj$ h6myOZP{.(N9=@R3F~D ? 67rhi|/; S^扔TO42^Á}"->-=Hꊟ7tkaE݀KVu5YcI6=ʪVuGuM\tN_Wb~[.EɉK@# ĨM(%;]H6ko=)a+MM-py,i -Ku3虖5pM4)3 gozimb8kiLG6*Y󹬜|3TXOqXQ $w76|U JH-;BK7v~.CƲՍ5 9m, z[bQ ͽƪJR I@},V!q.R>O` zVw'V1p4eYe `ů_-8$QosJhRJy{¿] Yv MU*5 Xh86&1<(sɺ%x?kvE$u/3<0T::DL)U9vE~J?DM 7̋ WE+7>oA{ϐF jǕoE6[{vQSkGd8\HX~CF U!fkesVR֋yLhJ<=w!sEGhb$!F>mb.t rJcUOOOD7Neb*Q@"15q`0DW.=ye 7C0| {҄nӰBi+/+|"}"B|V؅9k+MsS݃k$ɫ;ýDk[QhN54-.yu+#rk٥*hLi2Ht8JyEgDZ .3$ogW$x'B>I%t許ǀn_H-KF 0'*0ǍD?ҡp@5J.鋤aQRozr1vdCȁwqqo~ 9]C;_jRF{g^$mĖsWBC^{Cߵz6D-)n$s+(1ML!:xJk\|_X4qrkcLs9]m,BI)kޓl*ι(r`iP(A9<ɔ ,c8R8 -/X?;XXxr|Ra֫{rB6\:g8?w=qLx\˜rrH ?4LaHqH# J%0ze|2Q5-a E}:DkŞry@F Kg>7ݓy=v&{#\:ql׿#߼ѫy42\!tkީ '}Z*ԩ‹ lZc/ZTHDgY!0&tcs%_I=]Et>K3GWMbQ: *q X8T1Ĝ­,&c9_}YSŅ>}:Ͻ%ȡBj=êyup%6)I{!=9Udܟq4eCbz`\h( dCը]) S@`v$tބ=Fs\J0KIQ*Q{LtUCOLAujXa3dFp)kΫer˺(aÖMHye4\P_`+y;8AH5*/ARPl3;U1bЭVa CZT")␺ y|{^~ Hq+.]N\ɻ")> 9iaz'u5z})i~Tr!-^N&-;!ow51)y\mkk <s?OC@#gsi Z}a﫾F6Ώ}uui}olΛžG@j? 8qx*Ī0 q]nL ]9d"߳F onc+9?#TҶCpr6O Mpgb`6`D|x,\)).~L0(UWsAA7ov$σnOes,֖`TbDj$nKZa#af=oF|wlx kbHJ[E*E8Z 6&GƦv' 9bػ'4ۖ 0Xw5;UCVu}>]䄕1l',{|*|'Y#@b>Xv&5M͓0U_,P7̓Sݪb r/}`uo6\cvVibG 媦Uyn:eiٔ.?<$@h:,`~̎ʑqk1?(-L4-?řcT)՞43^ 1Ж#{PKG 6fC u).&[,/^pL,A<= )!zm%S#~/d@5"hWP"; HxN5c]s}(זʍvXo܃rN YZ