summaryrefslogtreecommitdiffstats
path: root/docs/htmldocs/using_samba/ch06_02.html
blob: a5b7bf4d5206a513c5c2a8e438b0f36703e81de2 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
<HTML>
<HEAD>
<TITLE>
[Chapter 6] 6.2 Controlling Access to Shares</title><META NAME="DC.title" CONTENT=""><META NAME="DC.creator" CONTENT=""><META NAME="DC.publisher" CONTENT="O'Reilly &amp; Associates, Inc."><META NAME="DC.date" CONTENT="1999-11-05T21:33:37Z"><META NAME="DC.type" CONTENT="Text.Monograph"><META NAME="DC.format" CONTENT="text/html" SCHEME="MIME"><META NAME="DC.source" CONTENT="" SCHEME="ISBN"><META NAME="DC.language" CONTENT="en-US"><META NAME="generator" CONTENT="Jade 1.1/O'Reilly DocBook 3.0 to HTML 4.0"></head>
<BODY BGCOLOR="#FFFFFF" TEXT="#000000" link="#990000" vlink="#0000CC">
<table BORDER="0" CELLPADDING="0" CELLSPACING="0" width="90%">
<tr>
<td width="25%" valign="TOP">
<img hspace=10 vspace=10 src="gifs/samba.s.gif" 
alt="Using Samba" align=left valign=top border=0>
</td>
<td height="105" valign="TOP">
<br>
<H2>Using Samba</H2>
<font size="-1">
Robert Eckstein, David Collier-Brown, Peter Kelly
<br>1st Edition November 1999
<br>1-56592-449-5, Order Number: 4495
<br>416 pages, $34.95
</font>
<p> <a href="http://www.oreilly.com/catalog/samba/">Buy the hardcopy</a>
<p><a href="index.html">Table of Contents</a>
</td>
</tr>
</table>
<hr size=1 noshade>
<!--sample chapter begins -->

<center>
<DIV CLASS="htmlnav">
<TABLE WIDTH="515" BORDER="0" CELLSPACING="0" CELLPADDING="0">
<TR>
<TD ALIGN="LEFT" VALIGN="TOP" WIDTH="172">
<A CLASS="sect1" HREF="ch06_01.html" TITLE="6.1 Users and Groups">
<IMG SRC="gifs/txtpreva.gif" ALT="Previous: 6.1 Users and Groups" BORDER="0"></a></td><TD ALIGN="CENTER" VALIGN="TOP" WIDTH="171">
<B>
<FONT FACE="ARIEL,HELVETICA,HELV,SANSERIF" SIZE="-1">
<A CLASS="chapter" REL="up" HREF="ch06_01.html" TITLE="6. Users, Security, and Domains ">
Chapter 6<br>
Users, Security, and Domains </a></font></b></td><TD ALIGN="RIGHT" VALIGN="TOP" WIDTH="172">
<A CLASS="sect1" HREF="ch06_03.html" TITLE="6.3 Authentication Security">
<IMG SRC="gifs/txtnexta.gif" ALT="Next: 6.3 Authentication Security" BORDER="0"></a></td></tr></table>&nbsp;<hr noshade size=1></center>
</div>
<blockquote>
<div>
<H2 CLASS="sect1">
<A CLASS="title" NAME="ch06-27678">
6.2 Controlling Access to Shares</a></h2><P CLASS="para">Often you will need to restrict the users who can access a specific share for security reasons. This is very easy to do with Samba since it contains a wealth of options for creating practically any security configuration. Let's introduce a few configurations that you might want to use in your own Samba setup.</p><BLOCKQUOTE CLASS="warning">
<P CLASS="para">
<STRONG>
WARNING:</strong> Again, if you are connecting with Windows 98 or NT 4.0 with Service Pack 3 (or above), those clients will send encrypted passwords to the Samba server. If Samba is not configured for this, it will continually refuse the connection. This chapter describes how to set up Samba for encrypted passwords. See the <A CLASS="xref" HREF="ch06_04.html">
Section 6.4, Passwords</a> section.</p></blockquote><P CLASS="para">
We've seen what happens when you specify valid users. However, you are also allowed to specify a list of invalid users&nbsp;- users who should never be allowed access to Samba or its shares. This is done with the <CODE CLASS="literal">
invalid</code> <CODE CLASS="literal">
users</code> option. We hinted at one frequent use of this option earlier: a global default with the <CODE CLASS="literal">
[homes]</code> section to ensure that various system users and superusers cannot be forged for access. For example:</p><PRE CLASS="programlisting">
[global]
	invalid users = root bin daemon adm sync shutdown \
						halt mail news uucp operator gopher
	auto services = dave peter bob

[homes]
	browsable = no
	writeable = yes</pre><P CLASS="para">
The <CODE CLASS="literal">
invalid</code> <CODE CLASS="literal">
users</code> option, like <CODE CLASS="literal">
valid</code> <CODE CLASS="literal">
users</code>, can take group names as well as usernames. In the event that a user or group appears in both lists, the <CODE CLASS="literal">
invalid</code> <CODE CLASS="literal">
users</code> option takes precedence and the user or group will be denied access to the share.</p><P CLASS="para">
At the other end of the spectrum, you can explicitly specify users who will be allowed superuser (root) access to a share with the <CODE CLASS="literal">
admin</code> <CODE CLASS="literal">
users</code> option. An example follows:</p><PRE CLASS="programlisting">
[sales]
		path = /home/sales
		comment = Fiction Corp Sales Data
		writeable = yes
		valid users = tom dick harry
		admin users = mike</pre><P CLASS="para">
This option takes both group names and usernames. In addition, you can specify NIS netgroups by preceding them with an <CODE CLASS="literal">
@</code> as well; if the netgroup is not found, Samba will assume that you are referring to a standard Unix group. </p><P CLASS="para">
Be careful if you assign an entire group administrative privileges to a share. The Samba team highly recommends you avoid using this option, as it essentially gives root access to the specified users or groups for that share.</p><P CLASS="para">
If you wish to force read-only or read-write access to users who access a share, you can do so with the <CODE CLASS="literal">
read</code> <CODE CLASS="literal">
list</code> and <CODE CLASS="literal">
write</code> <CODE CLASS="literal">
list</code> options, respectively. These options can be used on a per-share basis to restrict a writable share or grant write access to specific users in a read-only share, respectively. For example:</p><PRE CLASS="programlisting">
[sales]
		path = /home/sales
		comment = Fiction Corp Sales Data
		read only = yes
		write list = tom dick</pre><P CLASS="para">
The <CODE CLASS="literal">
write</code> <CODE CLASS="literal">
list</code> option cannot override Unix permissions. If you've created the share without giving the write-list user write permission on the Unix system, he or she will be denied write access regardless of the setting of <CODE CLASS="literal">
write</code> <CODE CLASS="literal">
list</code>.</p><DIV CLASS="sect2">
<H3 CLASS="sect2">
<A CLASS="title" NAME="ch06-pgfId-968870">
6.2.1 Guest Access</a></h3><P CLASS="para">As mentioned earlier, you can specify users who have guest access to a share. The options that control guest access are easy to work with. The first option, <CODE CLASS="literal">
guest</code> <CODE CLASS="literal">
account</code>, specifies the Unix account that guest users should be assigned when connecting to the Samba server. The default value for this is set during compilation, and is typically <CODE CLASS="literal">
nobody</code>. However, you may want to reset the guest user to <CODE CLASS="literal">
ftp</code> if you have trouble accessing various system services. </p><P CLASS="para">
If you wish to restrict access in a share only to guests&nbsp;- in other words, all clients connect as the guest account when accessing the share&nbsp;- you can use the <CODE CLASS="literal">
guest</code> <CODE CLASS="literal">
only</code> option in conjunction with the <CODE CLASS="literal">
guest ok</code> option, as shown in the following example:</p><PRE CLASS="programlisting">
[sales]
		path = /home/sales
		comment = Fiction Corp Sales Data
		writeable = yes
		guest ok = yes
		guest account = ftp
		guest only = yes</pre><P CLASS="para">
Make sure you specify <CODE CLASS="literal">
yes</code> for both <CODE CLASS="literal">
guest only</code> and <CODE CLASS="literal">
guest ok</code> in this scenario; otherwise, Samba will not use the guest acount that you specify.</p></div><DIV CLASS="sect2">
<H3 CLASS="sect2">
<A CLASS="title" NAME="ch06-pgfId-960007">
6.2.2 Access Control Options</a></h3><P CLASS="para">
<A CLASS="xref" HREF="ch06_02.html#ch06-28077">Table 6.1</a> summarizes the options that you can use to control access to shares. </p><br>
<TABLE CLASS="table" BORDER="1" CELLPADDING="3">
<CAPTION CLASS="table">
<A CLASS="title" NAME="ch06-28077">
Table 6.1: Share-level Access Options </a></caption><THEAD CLASS="thead">
<TR CLASS="row" VALIGN="TOP">
<TH CLASS="entry" ALIGN="LEFT" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Option</p></th><TH CLASS="entry" ALIGN="LEFT" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Parameters</p></th><TH CLASS="entry" ALIGN="LEFT" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Function</p></th><TH CLASS="entry" ALIGN="LEFT" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Default</p></th><TH CLASS="entry" ALIGN="LEFT" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Scope</p></th></tr></thead><TBODY CLASS="tbody">
<TR CLASS="row" VALIGN="TOP">
<TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
<CODE CLASS="literal">
admin users</code></p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
string (list of usernames)</p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Specifies a list of users who can perform operations as root.</p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
None</p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Share</p></td></tr><TR CLASS="row" VALIGN="TOP">
<TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
<CODE CLASS="literal">
valid users</code></p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
string (list of usernames)</p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Specifies a list of users that can connect to a share.</p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
None</p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Share</p></td></tr><TR CLASS="row" VALIGN="TOP">
<TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
<CODE CLASS="literal">
invalid users</code></p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
string (list of usernames)</p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Specifies a list of users that will be denied access to a share.</p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
None</p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Share</p></td></tr><TR CLASS="row" VALIGN="TOP">
<TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
<CODE CLASS="literal">
read list</code></p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
string (list of usernames)</p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Specifies a list of users that have read-only access to a writable share.</p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
None</p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Share</p></td></tr><TR CLASS="row" VALIGN="TOP">
<TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
<CODE CLASS="literal">
write list</code></p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
string (list of usernames)</p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Specifies a list of users that have read-write access to a read-only share.</p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
None</p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Share</p></td></tr><TR CLASS="row" VALIGN="TOP">
<TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
<CODE CLASS="literal">
max connections</code></p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
numerical</p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Indicates the maximum number of connections for a share at a given time.</p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
<CODE CLASS="literal">
0</code></p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Share</p></td></tr><TR CLASS="row" VALIGN="TOP">
<TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
<CODE CLASS="literal">
guest only (only guest)</code></p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
boolean</p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Specifies that this share allows only guest access.</p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
<CODE CLASS="literal">
no</code></p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Share</p></td></tr><TR CLASS="row" VALIGN="TOP">
<TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
<CODE CLASS="literal">
guest account</code></p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
string (name of account)</p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Names the Unix account that will be used for guest access.</p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
<CODE CLASS="literal">
nobody</code></p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Share</p></td></tr></tbody></table><DIV CLASS="sect3">
<H4 CLASS="sect3">
<A CLASS="title" NAME="ch06-pgfId-959222">
6.2.2.1 admin users</a></h4><P CLASS="para">
This option specifies a list of users that perform file operations as if they were <CODE CLASS="literal">
root</code>. This means that they can modify or destroy any other user's work, no matter what the permissions. Any files that they create will have root ownership and will use the default group of the admin user. The <CODE CLASS="literal">
admin</code> <CODE CLASS="literal">
users</code> option is used to allow PC users to act as administrators for particular shares. We urge you to avoid this option. </p></div><DIV CLASS="sect3">
<H4 CLASS="sect3">
<A CLASS="title" NAME="ch06-pgfId-960368">
6.2.2.2 valid users and invalid users</a></h4><P CLASS="para">
These two options let you enumerate the users and groups who are granted or denied access to a particular share. You can enter a list of comma-delimited users, or indicate an NIS or Unix group name by prefixing the name with an at-sign (<CODE CLASS="literal">@</code>). </p><P CLASS="para">
The important rule to remember with these options is that any name or group in the <CODE CLASS="literal">
invalid</code> <CODE CLASS="literal">
users</code> list will <EM CLASS="emphasis">
always</em> be denied access, even if it is included (in any form) in the <CODE CLASS="literal">
valid</code> <CODE CLASS="literal">
users</code> list. By default, neither option has a value associated with it. If both options have no value, any user is allowed to access the share.</p></div><DIV CLASS="sect3">
<H4 CLASS="sect3">
<A CLASS="title" NAME="ch06-pgfId-959243">
6.2.2.3 read list and write list</a></h4><P CLASS="para">
Like the <CODE CLASS="literal">
valid</code> <CODE CLASS="literal">
users</code> <CODE CLASS="literal">
and</code> <CODE CLASS="literal">
invalid</code> <CODE CLASS="literal">
users</code> options, this pair of options specifies which users have read-only access to a writeable share and read-write access to a read-only share, respectively. The value of either options is a list of users. <CODE CLASS="literal">
read</code> <CODE CLASS="literal">
list</code> overrides any other Samba permissions granted&nbsp;- as well as Unix file permissions on the server system&nbsp;- to deny users write access. <CODE CLASS="literal">
write</code> <CODE CLASS="literal">
list</code> overrides other Samba permissions to grant write access, but cannot grant write access if the user lacks write permissions for the file on the Unix system. You can specify NIS or Unix group names by prefixing the name with an at sign (such as <CODE CLASS="literal">
@users</code>). Neither configuration option has a default value associated with it.</p></div><DIV CLASS="sect3">
<H4 CLASS="sect3">
<A CLASS="title" NAME="ch06-pgfId-959253">
6.2.2.4 max connections</a></h4><P CLASS="para">
This option specifies the maximum number of client connections that a share can have at any given time. Any connections that are attempted after the maximum is reached will be rejected. The default value is <CODE CLASS="literal">
0</code>, which means that an unlimited number of connections are allowed. You can override it per share as follows:</p><PRE CLASS="programlisting">
[accounting]
	max connections = 30</pre><P CLASS="para">
This option is useful in the event that you need to limit the number of users who are accessing a licensed program or piece of data concurrently.</p></div><DIV CLASS="sect3">
<H4 CLASS="sect3">
<A CLASS="title" NAME="ch06-pgfId-958842">
6.2.2.5 guest only</a></h4><P CLASS="para">
This share-level option (sometimes called <CODE CLASS="literal">
only</code> <CODE CLASS="literal">
guest</code>) forces a connection to a share to be performed with the user specified by the <CODE CLASS="literal">
guest</code> <CODE CLASS="literal">
account</code> option. The share to which this is applied must explicitly specify <CODE CLASS="literal">
guest</code> <CODE CLASS="literal">
ok</code> <CODE CLASS="literal">
=</code> <CODE CLASS="literal">
yes</code> in order for this option to be recognized by Samba. The default value for this option is <CODE CLASS="literal">
no</code>. </p></div><DIV CLASS="sect3">
<H4 CLASS="sect3">
<A CLASS="title" NAME="ch06-pgfId-960637">
6.2.2.6 guest account</a></h4><P CLASS="para">
This option specifies the name of account to be used for guest access to shares in Samba. The default for this option varies from system to system, but it is often set to <CODE CLASS="literal">
nobody</code>. Some default user accounts have trouble connecting as guest users. If that occurs on your system, the Samba team recommends using the ftp account as the guest user. </p></div></div><DIV CLASS="sect2">
<H3 CLASS="sect2">
<A CLASS="title" NAME="ch06-pgfId-959934">
6.2.3 Username Options</a></h3><P CLASS="para">
<A CLASS="xref" HREF="ch06_02.html#ch06-82964">Table 6.2</a> shows two additional options that Samba can use to correct for incompatibilities in usernames between Windows and Unix. </p><br>
<TABLE CLASS="table" BORDER="1" CELLPADDING="3">
<CAPTION CLASS="table">
<A CLASS="title" NAME="ch06-82964">
Table 6.2: Username Options </a></caption><THEAD CLASS="thead">
<TR CLASS="row" VALIGN="TOP">
<TH CLASS="entry" ALIGN="LEFT" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Option</p></th><TH CLASS="entry" ALIGN="LEFT" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Parameters</p></th><TH CLASS="entry" ALIGN="LEFT" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Function</p></th><TH CLASS="entry" ALIGN="LEFT" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Default</p></th><TH CLASS="entry" ALIGN="LEFT" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Scope</p></th></tr></thead><TBODY CLASS="tbody">
<TR CLASS="row" VALIGN="TOP">
<TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
<CODE CLASS="literal">
username map</code></p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
string (fully-qualified pathname)</p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Sets the name of the username mapping file.</p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
None</p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Global</p></td></tr><TR CLASS="row" VALIGN="TOP">
<TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
<CODE CLASS="literal">
username level</code></p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
numerical</p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Indicates the number of capital letters to use when trying to match a username.</p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
<CODE CLASS="literal">
0</code></p></td><TD CLASS="entry" ROWSPAN="1" COLSPAN="1">
<P CLASS="para">
Global</p></td></tr></tbody></table><DIV CLASS="sect3">
<H4 CLASS="sect3">
<A CLASS="title" NAME="ch06-pgfId-959982">
6.2.3.1 username map</a></h4><P CLASS="para">Client usernames on an SMB network can be relatively large (up to 255 characters), while usernames on a Unix network often cannot be larger than eight characters. This means that an individual user may have one username on a client and another (shorter) one on the Samba server. You can get past this issue by<I CLASS="firstterm">
 mapping</i> a free-form client username to a Unix username of eight or fewer characters. It is placed in a standard text file, using a format that we'll describe shortly. You can then specify the pathname to Samba with the global <CODE CLASS="literal">
username</code> <CODE CLASS="literal">
map</code> option. Be sure to restrict access to this file; make the root user the file's owner and deny write access to others. Otherwise, an untrusted user who can access the file can easily map their client username to the root user of the Samba server.</p><P CLASS="para">
You can specify this option as follows:</p><PRE CLASS="programlisting">
[global]
	username map = /etc/samba/usermap.txt</pre><P CLASS="para">
Each of the entries in the username map file should be listed as follows: the Unix username, followed by an equal sign (<CODE CLASS="literal">=</code>), followed by one or more whitespace-separated SMB client usernames. Note that unless instructed otherwise, (i.e., a guest connection), Samba will expect both the client and the server user to have the same password. You can also map NT groups to one or more specific Unix groups using the <CODE CLASS="literal">
@</code> sign. Here are some examples:</p><PRE CLASS="programlisting">
jarwin = JosephArwin
manderso = MarkAnderson
users = @account</pre><P CLASS="para">
Also, you can use the asterisk to specify a wildcard that matches any free-form client username as an entry in the username map file:</p><PRE CLASS="programlisting">
nobody = *</pre><P CLASS="para">
Comments in the file can be specified as lines beginning with (<CODE CLASS="literal">#</code>) and (<CODE CLASS="literal">;</code>).</p><P CLASS="para">
Note that you can also use this file to redirect one Unix user to another user. Be careful if you do so because Samba and your client may not notify the user that the mapping has been made and Samba may be expecting a different password. </p></div><DIV CLASS="sect3">
<H4 CLASS="sect3">
<A CLASS="title" NAME="ch06-pgfId-959994">
6.2.3.2 username level</a></h4><P CLASS="para">SMB clients (such as Windows) will often send usernames in SMB connection requests entirely in capital letters; in other words, client usernames are not necessarily case sensitive. On a Unix server, however, usernames <EM CLASS="emphasis">
are</em> case sensitive: the user <CODE CLASS="literal">
ANDY</code> is different from the user <CODE CLASS="literal">
andy</code>. By default, Samba attacks this problem by doing the following:</p><OL CLASS="orderedlist">
<LI CLASS="listitem">
<P CLASS="para">
<A CLASS="listitem" NAME="ch06-pgfId-959996">
</a>Checking for a user account with the exact name sent by the client</p></li><LI CLASS="listitem">
<P CLASS="para">
<A CLASS="listitem" NAME="ch06-pgfId-969146">
</a>Testing the username in all lowercase letters</p></li><LI CLASS="listitem">
<P CLASS="para">
<A CLASS="listitem" NAME="ch06-pgfId-969147">
</a>Testing the username in lowercase letters with only the first letter capitalized</p></li></ol><P CLASS="para">
If you wish to have Samba attempt more combinations of uppercase and lowercase letters, you can use the <CODE CLASS="literal">
username</code> <CODE CLASS="literal">
level</code> global configuration option. This option takes an integer value that specifies how many letters in the username should be capitalized when attempting to connect to a share. You can specify this options as follows:</p><PRE CLASS="programlisting">
[global]
	username level = 3</pre><P CLASS="para">
In this case, Samba will then attempt all permutations of usernames it can compute having three capital letters. The larger the number, the more computations Samba will have to perform to match the username and the longer the authentication will take. </p></div></div></div></blockquote>
<div>
<center>
<hr noshade size=1><TABLE WIDTH="515" BORDER="0" CELLSPACING="0" CELLPADDING="0">
<TR>
<TD ALIGN="LEFT" VALIGN="TOP" WIDTH="172">
<A CLASS="sect1" HREF="ch06_01.html" TITLE="6.1 Users and Groups">
<IMG SRC="gifs/txtpreva.gif" ALT="Previous: 6.1 Users and Groups" BORDER="0"></a></td><TD ALIGN="CENTER" VALIGN="TOP" WIDTH="171">
<A CLASS="book" HREF="index.html" TITLE="">
<IMG SRC="gifs/txthome.gif" ALT="" BORDER="0"></a></td><TD ALIGN="RIGHT" VALIGN="TOP" WIDTH="172">
<A CLASS="sect1" HREF="ch06_03.html" TITLE="6.3 Authentication Security">
<IMG SRC="gifs/txtnexta.gif" ALT="Next: 6.3 Authentication Security" BORDER="0"></a></td></tr><TR>
<TD ALIGN="LEFT" VALIGN="TOP" WIDTH="172">
6.1 Users and Groups</td><TD ALIGN="CENTER" VALIGN="TOP" WIDTH="171">
<A CLASS="index" HREF="inx.html" TITLE="Book Index">
<IMG SRC="gifs/index.gif" ALT="Book Index" BORDER="0"></a></td><TD ALIGN="RIGHT" VALIGN="TOP" WIDTH="172">
6.3 Authentication Security</td></tr></table><hr noshade size=1></center>
</div>

<!-- End of sample chapter -->
<CENTER>
<FONT SIZE="1" FACE="Verdana, Arial, Helvetica">
<A HREF="http://www.oreilly.com/">
<B>O'Reilly Home</B></A> <B> | </B>
<A HREF="http://www.oreilly.com/sales/bookstores">
<B>O'Reilly Bookstores</B></A> <B> | </B>
<A HREF="http://www.oreilly.com/order_new/">
<B>How to Order</B></A> <B> | </B>
<A HREF="http://www.oreilly.com/oreilly/contact.html">
<B>O'Reilly Contacts<BR></B></A>
<A HREF="http://www.oreilly.com/international/">
<B>International</B></A> <B> | </B>
<A HREF="http://www.oreilly.com/oreilly/about.html">
<B>About O'Reilly</B></A> <B> | </B>
<A HREF="http://www.oreilly.com/affiliates.html">
<B>Affiliated Companies</B></A><p>
<EM>&copy; 1999, O'Reilly &amp; Associates, Inc.</EM>
</FONT>
</CENTER>
</BODY>
</html>
_\FDDndziDyRDj NOHkzorIDԥt+%^μ#!glb# { C[ejM=ﵱ<3 S^Ji7>z-e1%Iimjܟmeېl#' x(} zzKe>T5>~󲑏ˬ`)ֺ~T5AnhHcQTrWn'Mƥ@'1ʍKnW2&e b# b6}{8*O$҉Z( >Z[qu"?,mo:H3~`/쌭^EF`B8]n4sƬ}EDjA<]f6ˈ9&/"Zq/_7PT=Ma$T_zgK>) _BR򉥔ANY?_B6!4۩^Ý t'3VG('#hhL5Q)_ZvRWTۗm⁦Mt#ݑm~YDSR20oe>XW,UB+ʌ)zGmGƖ;5$Q:~􀙱wAXc6=.\0}s.!ܘ㺖?Wj0NQK ^@ma U'3=!x8VAaf֝  u}w{(812oV>XF0j` s.fvDN9oW ߇DEiQv4nSwJޘM~Gw.Y]yEeTa8"Ңr US>f=G-dbJ$<Ɛžc0BN%dk c,?i0'GV=nСNS[{ ˇd͆p8$82$6񪿲ߨ:b)K-Z-lCZ!|:w?c4(@.92cqre&q&#G`7 *`*€>Ŋb 'ũu51GVw277 ,~d ;6mNkgj j:jy+yR֎<ݢmː RJxY& Q|o!'#:SIONQ(g3{{)vLQS;+k&@%^$`P\0\BC#M(8ZKH83|2I^f͔=rJh T<ۗLcf=ѠRDp8F7?k2b0P޹! Qf,si\u|L 4?H<8?i8O=&H +Or> 3 U)B4z >N6"]G`FO EK[r*&]%j2|4oл4$bЁ龿$zUOdnvY.K»c;&bE oLEv Ўo=RY傐UfkI a% qKZic0Z+.xF~iYtڱ V2/4W؜/5"*˙f # K :mnĮՠۼAGՌ]z5]E8|*â8&ٛ](JmȌn!U,-U{=G=|xJD %^>?:%=|nIu_05Jz7x}xmx2NՍZ،\?5/5s.T+>G-M܊IaKN@F/p`YUpEXdG`joNw- L[.qK3sL}[Ƹg-vԐ*KB>:r,|=8:C*= ,*uʶM S\d7" 5H(DFё>s}ڲi܇?1:|8d}ia. uҏXL촷6&#!"$4dljw-LKw>Kn1%p6iC惜E̚F Bsi,>vϻi:khĐ,n,]^+o4 q9:I5mܬsot֎R ݢ:@ t5Vj1g6H {7O"Cj,H,1 Ő1Y+~iX"t+6B5S,_ y/-j=12H `MtBKw7@Y Y\y'eǺF1* \^aiEeJdW?ԭRzlo׏ECVZUax%5kITD=,SLxNFW*؝-, ]j/=ˤmb"cӫ^ 9Yxo uOU$]Wds"ʕi4pa#y1呶+]xhC "ϵ57sYX_ yy8  $Ǣl :&U8 ؄Q8>Z՛}=1Xj- ?U Wؒ d:8hM4{E!zJ+c*i[Ib_߳0X,m0kcN&6:mvBH@FmFҳdg_ݍiJ o݆æweșS;7TRCx2;)SŞiqGwE/O2ڠV`72E n? q"+XSbG[\6O;,vofa_ D+3!gd͆V6k>e_6) Mw[bYI\}} '8bY-y2@&R, {']N*78@(F^ 74lRCep43cBB+B+ Pn֔nFu7n;6xƓiH2n"ݶl(63d&i9ڥ֗l˜#@1NtUd<rYV䬲qP"cx̮n@4[oo` sB'1ط͗~ Z0Jf~ :T7MB:TlQ{7T9 @ u>.r ,uY!5\c뺰fŀ*wlTGv_Bi0\.H&q1* gIzJ?pUr GJGr Ӆ X;F n;yϥt1j.;aG@ba%_ƶ櫦d&X#tc> U7(g7K(B'8Tj˪\,܄qz1zr$:~U13?xdC`0ofFriƺ#P3m*1 =!HDf Id44+{rg}[ ܍5׫rA"M^b++}~FQKr~m_;140IWmA^_*!e|T+lxi^4Xf^j+Ț[SgF9]i%`N2`Nt5jR܊ J 9``̛O9[n1\]FiִKkIu׮gyZ{ ض%Z.Jb^ׯ-NvBgv :wC09ʂTŁv>m4gq̆zD+Ez|#,yCZ~B8J[i݀G$т "sQo1$OE6sz^<ҭ  7&Pē"0/ V!A(B:ȁ\zCh6Yw) j"G|g1mOuZj!wRx !k<~BC5!b28dg_?C&XY| ?I4]g,V_i#PEH.A<zp^3.,Sfe '>b#&|ߩhT_)HS ]PϚ v#2^ ͖Vdɐ._ݜ""QP2vk#sH@l]vXחk$n?q>`@S͝K lC[ m\ĄZ~a[x[˨Q]S~8k%-; }c4_1ٓC."#vZ{­nA!/?rMY>*do=%/[aGAmeHQi. \*iY 6B!AɎjQKB~1h2>ډiXtbDTS |tʪejL@5ɣQ!ԆOe(ဉuH !URdHa4u!M[Y!k ! G# Wa=KmdVjˉS_ҫr"ʜMBSX/'Oh\B鼆CztOfZJ9f/TXl10*ujzkB Z1?),rr@27{3pŷw53-e!LЇ`f:_wgHN Qd=8)1s Ix^bye/ם-/tkՑkwd:@%`u#mkRI4F(%i)7.N&L+ SV6]t}<cuc}טת걍U;bP3 jIaRo,KUq= ǥS]An]*)RaF}疬 #3ՏȀU)Wo ېU 4V [/XaWg⌬DvHJB PBɤ# Aom6X+>R/=bLg-Tw;ibrmsKT2"Z*^xKF~rmQ4.-ğEi456S`/ #"4.>ќub z(ʵш8U#ٛx`p5ϧq!Je v~ʧl!7(QV\"tPԈm4<ߦYn`!@;F_o U<W9/G Rba7%T)Ҋ8]Bq{B֋JC~@mU[1!D[!4d wLe!4Ld/z(|UA$3tpU1o3+VWm3+e ڠR/ZtꐮWFih;6' ]i[kj3kO L'҃`S,sup/ֶqJbFrIݍyQQ1f^ Zgrch~,=9߻QO,#a]۱Ä@FXL4WTd$l,J =9` %LH vecGW/B.dU </fJKgK+3AE3CC3D; rYi0dzn-Pn&0tj;ğl*x`?B9.c/Rq!;`|Yy0^ ւS?ҨWkkg?GeXbdm Yhe&2]FgGo:&JCteǧg.3&j"\Li0RbYxޤ>09ʻ1XϰF^RxNK)v+%Xf2OmFLQ#<)CVm IDY'Z6od;j2FD jX(bjWX=JJ6HIݏt qܾ΄60}vAtDXJ۲Tu@nęB_9ɣ|Z$fx=|^8%֤@0A3Ȩ*Uzh% O°p~Èq;Ň36\t|Itjg cc  *RZ~\Uo d 0(XM9,X.U5jnsVL|}b q3٬OoqwqckLWN6m PҎ*r3G|5tA!j~37th5יsO Nc^f(<7FUFSLC*3d ƳQ/Pa;p ?ɤj'~w$_x;ҵT{Hp"G?d~-cngk&Ka qisVOQM꤇%팯Цys/RF@ao8W u9d~r44ĚʃՑd)2 ~jV7*u!$%VV!F1īO@6jO SIF'06g_U4<[X(rTG&&!PnHo0ec #J$5ZG"7١A1[Ʌ^S1ŔP+o(kxduubpE=EڟA~B]NOz'Ă[֕Zg|:C-I mҚ{_{%]r0+/'e#nUQ$ ?SZ6mE&by6g7n%oe]@1ZP[ȁ=O>I@[jǟHQP>f=y+/Ůj}InRsx=$lT[/G B5(HbHRUk4I5 ƣͫ1cP'Ojۄ5n i! XJ-io6 fֽ.~Y1D&V OUJ9ߡ}pN?I5Bj &^6 ѻxLMM,`gAhSvnT*rL mExqwal[*I}Ld4FSyco&4bݸpGp&K^v,=F#oh{oU}o,xlhwN V %*Jkڎ*^6L9r2 dUdSIy;uD@v-)W&buУ^Zf2 QAB9DQ @ ^K8#2ɽC8>gKz*?u,^~ܟ70>kbJ$>R&Qcm*3Lv=G+E3~Pw-*3\ayMv }FnESa$ %t'k)sk:}ѶiBمn!N "LǑt׋n]+["=%Qg)3;@A:S6Q>7p3p[e7s^6誨g2PdAgW06x&fpGg^%C>IYY3⺩H 퇓pV`oI}` 7xa.\f0Roךqj%VS+nਁYQ0sne22\e#_1vmH)"Ykh)L"fF|:W+ 0\m '<3n $"N][ӣd4Kc赴O[b(. sZ7XVDzźt)8WuF.nfWtFr9w-2qcx^9w0WA,l `j fpڒ삢Df@gKN$XSٮTbbp/#.k9OLƮwlY|5,h)|J3f Lvӌ}0Z)23OlȒ'PÉ۾ .TW#Hi#zk-_8?%СUzڑ5fְp9Fe; +S?:|iI/W`gy|xqVk75i oiI``MNkO^ ?,Uy#1Ou+pCr:Ce,זPGm7PqspQ۾&ӟP%{H?6STY vׂ/-b X̲ff@'Œf [;"Ӹ,\s@H \Re$z?+~K["'uMO)iy ،o2C"PqʪWhj0ؾ@܍tQTd`I c3D?+פ.˿`VHzNT j;mjT~G0SKU}1)gYÉ'hyOJBd PE) P+&2:ln{i? TtD`v#j;7bҹ?0!H>GU-&bϮܮ#tB@KbQ'=/PĮpp>_TbCN2@C>*j+ғ`o_S 2'Jv]1a\W <u=gy'AEU!_-&"[[ S쯍q-9 _J)]|? %ۧ1oR|4 R/9WgIDETkhcC!Ev䝶 2<1= FWU*R2B!/B64*H_AR*$2ZB;$ ܱuh'a7>*;*uڰ~zAs~% Z'6xќ4֐UIh燐[m &Lm9:!h |_^Pң&h @Sγϐ=k`8:3l*6 )-dzkM`WUTYk-(Ȑ\5tqfN~b%2V|h !*j˝ƣS*LMEqDOk?}<=U $Y9\Ʋ?{R|6ݐEd,2zNEjQLl_Jŗi=0VWGqe-/ oHb$:ۭ\Vw$^{wK{|h!3gԳ &)Rt|X'CnSI4m;̰h6BLr[w%[$WߕGfSҋA~x$-%a0H?Qok+qvg]fM :`zid<-@Q42Uhz5:4ĀjA&F7zXHo<0Kw=]7"'mbzW}R֒Lq0x6hިjђ=TI! Kw[G&K5Ds-iuVVH/7vGƖ`y)PF +w"-E-:9@mm&HAO&7-*@7E Mߊ exy8rC!@ wRli"J{5tX9pV|vY9K\ҪEnsHhm[W3s0q,ӷͲ ᬑi) rE diؐc"o|pB[vvWzF2lX_MLshOɽ_QR.xu3R8{Aj0#SL5/-T]ԄdA]$Z&xnڲ?oÇu_ALq~Z.u0q:XTxr)ejrV%a5F)HDC?I(57f>?t)V%&!VP=░&sA8u~r R9O|V7-}Vy?_x*4y3"W+/u2#cMX_1-RRvsf_aI+gV&6?|<:#X,# }X͕?m]kMZC!L \t$nZO_Q=2uQ>?'!AaN<4ڧķ7lևVj4utﵘۺkq}5DDw!fof=HVX1YLӠK-VsIFz¢.:F_"uM-cpcvƇ\je95)Ƽ$k󹴍+DG"רx %i>W e'xkJ 6-]0/gy.Q>x3+Zsuh}xOP@UMfZ6 m:{k609(45խ'FݦBYմsTg>tNOJ*WBh|: <5{sG\VAiTQÑ0&8 X8iC bq YY)c5!J9;h3ZPRfY@RI1qf+I oTˈf`ZZKp^% c8dMGuS#j_38cF qsAfJ1k7h`3[9QA,gc`.N?+#8Cd%hxZS_ؗ1Aw\[;};ir0ΥKXA8F+jLT =X\M:kbcL縺 [A#B6V.]N۲p<;2Iv?Sw0oV#d{)AѸsدT!&m[a9uv@M%`2-kSUidpd.48H{~Oƽah)k3=tDdV:)BBH(-Jy !["ΓU3WgcL½8NR !ׯk¼Re.URO<\+\<@fGT֟1Vz웬hG ,S*Vonm"*`U%G/Vnjx@sVzN-Q=R9H@߮-`Nji4^0 p>< 3n*ALE\B>|+F(Z Ox/z#$ECmD3/QCJ ,(_"3|m= uXL'9BNTxJW7/} DX(UπŲm8ݖB?vҚ{xitĎC򈁮]W+J%ɂZ.p[#,{73ObE=2~9aUJ;<,zr%r^w"C4E8UT贇CώM:v~CEaNܹ$oe& j|h'Xsxyqۍ4Je\\[;Zo#0ž}B:<(ԎFz^Ng 5ǾѸ::6syzEP.; gݍQErA-W;紐jRߐX־QFK\#:/3(rh}2% JW]@Pd}6Xހg8,u}SV]ڛ/4!Ih/G6ƆQTʰX< %6dE*LTn\m5b=EYkpftC-Aۡ!)Q`tO!fo۽z?Kshwq4BS`۪ܭ̠gKwɺ1=\_&e#W`oC\x r!cGk-1nU+ˉcvݜaB ,Q\QmA ++?f@lT IvuZnJ-sͲ9 Gt*7U7=vg<o~.՚=+WJ9%0#oEٶjʂ#T 䴯[bBU74RQwc"P93Ho3'U6dlrtHm}ê+Ѣ7t뿍bK`}Du;`(5'gߦ=[= "`=2ΧO8<>j#]e$-B98랶..LL X)n MbMގ%Rs<@Ѥp#v%wA6#Z!jY]) m9QH&/2tG-]D*cZ(=?aZa_oe}S05}yq6zauBZI\~SQEdHtp:C<)<C/n>El:F /[C8^@ܔ 1cl#x\qFOCvڑIT#;mqw=`EwCr%S/ rS?u( F ?%%,(pk[ T ˛kZı ȝwiys봰e°k\ R'UyFĘ@o1fsP y}As"t#\>Z(ý:)m|w(T .alyyTʭ[f?|yӄ8vѪ*4bpI=a%H+iUEL_BtO*6x/FR-JFRa\ 5'U?Df@Rw/rCSd%UYe Ϫ(`(nZrOEߍ@&1$Y&ޛsDpwrz*I?%KX4`mCeK'QbaQ.$ACL~Og . $% X-Osy| c*10neN4:[ퟄ ;@:sV[\Bri#.gNi ;0Ade0כs+wgƙX41r6$`.Ͷ^̝~*Ow>[=V6]j9NRx~ Y&i9RY1agG.8l5%0aȖ8й=t!ѻI; /% )39Cǵa2Йd_y,<ٕ/jꥊe>ex# b() !_P"ȣ mγD~׻0JirɥSd'.yL  & |,4KiFk{r_ XיJ]-:j펏mrtU)2Jy QȎ N=}ɕ} *ɂr SJV7Zy&'ۙS2I)c 8%nO,oεIn:_AoDʐˍ`Rtr^lԞ2g@qj d-b`y6Q ;p^S2zTzHoWf$S%l|m5ҹ, V2/Bɍ0BU<]#1$u<(-,h9I,tr6ռ D1J7кvYc:ױ~LO<i 20,7Զ_dx!~|3|i"Q$@1kX]1r(ʣ8gCyhdDKd-SSV)b)f(|u!Oh.ŠZ mYגxWw1gt?|\'&bV=bA51&:MK,CN=ލgKؾMa)'/(UR՛ﲺflCc/zLIV'4ጡ[̘ UÀ?iacɡz(տeh4fؐbz_zmHal5kcz$t1ck~Q3S<eUUEz/ ـxւsN[߳ݠ)Whh1 479Mɡ; U~U]n#-CZ+τ}=Wvpl[e?Ҏ}c0\s 6½>u d'5gUQVvr1l빙x q)r85,)ҵ5MTia{LdPNt1nCb& 92\3mԟ֛6v qGrIٲ:'g1~wUF.ٴU[U,r;'CϔbFTFi2JƊPh+Zn'\,@Nh8K2{5}$]\4e} *AܐQ.i@W,:1VGԋaX)hSUn s) &~G0.z6a)OBVx ?b HJ=5c+z&#{ />VexDgU/N53dRBv f{9:o"|sL#GU020Wp7(ϊq \^~}Csr-0Wt$sї kPuXKXeb]m[GCk/]#Q*ןΕ÷%bxA j3}hy[V罰Am'9wYdɒ6)'gUnd]n1Pܟ[۶`oܓMEѢ>E! P,4ڭ50 ޒ246u6$O]nHYh[FErdx. =U@N]xPHEU?z+UZg0fQju /_Szid :Qom*X2 @ (jp %ltNi!-'Fő!1x1]{|*pYPKNH_IeoTŐ_K=pShgE1B ی( 9XJ1fKrnx6>xgՂcŝ{ 0uVBo+b`lWbp @sF@o {J//TD~AlS*e }ZHV{"Y sAPvzIYG$TmY{%-+plר3c`KrD->۞n,%(!Ư@%YQ{sU]zHޱPz%W*n}kmf _΃ŕ, 3ouH2q'A砊'MAItzy}NyJkx+_{xݱEC'rxoc&!?m}y̴ɣMZXKr\]mr-edVE5KR(3 ՠg?J xݵIerD=CP`Sm|m ;WӮ^4񿒂2ɨ30 Zx;P5j-DŽ{,n&^Lke$~I e`6^t`XJ5C5GPXy}[X> mY  Q?ʄGv^TpV6a>6 (rc p   $Gg)҆=l5}"^ly1e y=+ 0nSsޕ$ ,]Wv%tus مz}/&cN4{hDH"4 ,\V~wsEDw2ZDP:$2  ;o3]iUKN4=':\M~X#NA "?)1la#ԥ]]рL58W>A>>g?nig0.@ Ԟq@bހYir,(m9fZv}#HaDAA04 ;N_2tcL3#@či_H!h RWL?z/&8%1e>hx`ߖ pd.%#"kzF:%4w'-i 94 : بkMV 7H?o)DF>9m5 ^G$ɝY"م$bMS2PS0dק|I _J(`<áaRe~̖LRFpO3F6k $  <W_ͦڒ|8"JҰm[VI$>0[d>94_'^QbH;*|2`t>p wQn^GaFj`V~#Tݬe FHr,t '%C,&AOpAKBRB2Q/n0;u.!ܚ`\V 'jkטa!(ZQA:l2 F|$cb4ϛJ2Sɘ*𻁂&6uOX;M+̸p@vR%bT9$;aґ’c)z%3r|Uvd_n.Ra")Fm+cnB.{amsS+YGl ť$m U(oM Bj[@/XݓT*0 bJ28g=l"O"*x?@Y==QH [DmJEZl gvşJ_U_~{c+ Q;3di!fKkIfܴ֬Ċ%ls{>MMYp%Uwܑ= 4G-GV{JJ,{eQ:q o*wA#:7R L;66ZcߊMޓgO2j9f/_#o94pB i)e)kTæ7AXUJq`P6@&NE6Bu,lP!m;<f9>KhGD@{=-#]AP}`AgfS.?NтDծP~Cz7WKncŔY8X.p~Y֮~{1>b`pSH>a/O)oJ6*M(O݉tizrB.Q5;@-X>eOp{nf[}%B͎=SjE J9x+xMVrܝgn nYdT5E8`ϰ1"uW G ;hnptpa[RM@0xz ׽kw{&XmnQTRUӛO,[,u 'jc(KX xN]!dSs<)Xɕ硫*5߁tiZ=˜`cUGrlڙG` A͍h l'Wov(D5~k茾3Lv, @>lmAtnr:e|[Pӌ Hb5ya?O a3B',^nbn g}PqA2J 7tȴ*POKRpG2-#-9- 6+eKS^ZAcrqY !41E4Pa2gM*|ԎoXdfw]FRn ]WK-ѿ?n%a.aK `0U bB193^ѕ`=W{VwDIHS?&Et d=afY0-oNm6mdYF(Wn:| ܾj jNc{UXTK-j&QpU)0 tmSG꩑xx`lb ڹF_a/G4Sg/^i¶,Cxj~zdlU9LpY`>ߌ٠d"f~Z_+joM+A9fC#G;Cap&c0ފH %Jy^6ԙ yFS$ / Ff< 4.C'$uNnTHc">Eh9SAn_&`a+Vy~VmT' K7%1c3Z2, x*~b=59 f0[5W~Ds&Z?xݔY1E@d[p 4 kE-JCZ3j˅֊^7 ;` ֧zQCGT 7"MF IMKSטAA EZ5E@:)&)_y3axQvXNEa>=,{7gP\aL8Ꟃtq^ @tu{N1!'9ڇ3"MsKO DBUȄiši%>bpp(;vcH-boy8#p-ۘ 903Dy2ߍxO1sv\ 1?ڭwzkZ8Mgy;p XRࡡ)f;c:FYUtvĕv49{ވJ 6گEec쿈~:OgT!Sл_* !&aC`m1yuyi2ۊ"}=ކX8\Wu'%}r V%MFsX:@5Sk^b-"vA\[`P9ΖU $.2@4YiӒm91nV޳4C+a] ȳ_^f&x9$7n&1&~#e ;aiFh<e+wݾL3iZ"ͮw,yC}Ĕԥc?.}3T]Pܻ7y]Xl 5| f{dڮ˟O%[jI*HzdW Q.'ւ\6c*IFѝn獊}k0?6_?q5Ϭm SFI!bdn/`ʯ*BыΔs@[@u-m MiCEp' zp%`3wgu iԚ3tN *D8$?#.he xvMe*~{ E=Di25xC'-_:䍩MvUs]wlB _i϶{'VXz 4]8S{H8l4""ˇq5fȃ̟xf1EYDvDj50͔-奄AmPRBkhO>@QI0tP9*Gԧ1#s^D@w㾗ѽ1 Ά576 ^l&Ҕ3gdkfY8ֶ^oڮ/ |GxCn*>Swl:WVgϺ.o O\o̾=2@]x^y'Y3{I#cmC\nOښ k:a,@,~gj/`nfr >L57+\C +cOmxBx[2T?45+{VN~ vG%zc&Xv0OsǏ#oDgL!PеHkHO8A*(dĦfDSj9>?Zy 1VYLTFe#18zň >N$jU} b*=aI.,JT0bYmb*h{sz9UP|F:L?IV3}y<|Zgo8|'nÊ H evy4 dd) 6A ъ-@M>ba`]Lhrk9E,}QBܗ*1hӳi4,^F/\6t۱7A:[ XKjFڍ=OuOyt fSQk_Cϰ&=v3뉄e nڸa{,ypQ)nc'ѓ^z 0\T%ZX̭I4FO1]ha0ٶʦ{M.n#a)g4j窠}0lx=BDbj UT\BIE6ɬgYW% ձLx!ݻ/P\ʸ`Q CbnV;OllN=]fG|7XIr֡pYaȩY|~*H:C$ D+Uh&^138r"Zpi] 42Pᜤ`Lx.iր4d\ l: A`ăV ړt)3o -* W%|7l-x؞]I /" X}wW!yTD\֐P"Jxj~륜^Խr O*h=H>W682v 0ڰhMxal.UAuH8B2YX0Q)Ij%^zcaUOPgؘ%XK4ʡm_ߢ!}=ZMvOP)uC6BCF; g rwkmL:RI*.Nb 4f5TFtQ :׹;!U6soyL=RB>cu`%Bɇz 팲&}H3ym_O̐9|AQE.Q/0gAÌ*\GhTz* J"Lxi̖t_LBHT-ЗLSpHyfTY2"/ZLчO3 PH³I#f@cdO/I+I't*nWy4w"/n(3nYv64u6pVp]w7-b8⏌ȰdZJMص%1qќl:W4uI+JEYyҕ!ĦШ ;5Q2,8r@f:k%qЈKly耩cXOcs1-Vosa6^r% 5 jҶc9Eg:$J+O6+2xݾF.FBOajd(Ha?=4t& ]ՙ-NJwZL%ҮFl""zCIDK&f8Bs`,i)xuڬ/QBA7&q gluhz 5'i NDb*!{\1ɢ$`W^h.Jp:>@$IS[9n.p% B=i˂‚f*SUz"`+60رZpk,j 5bpg1@Rp#̆{cHmy1nYZe@j~2a_L͕][Wϓ[1P̝w<O_W S}w9I"ѣ/1Ku=jleE<-uZ>f7NbC; !)pkpR[ǼkRK>ppݖƻOz+8/5DJVu[KlHGq΀Z>e\+0# g;PRO7 Klx[SWa7|1!o aQ"!Mf&F E4CO&J{| ꏊ d\Ba>8Qt<ߺ<pW`3-U7X3f$(I@=M>|U_N̮RsMt*r[SReD%+q]W2,Dw ùpm[,߽dc>E!O4ՐS24IGi=765 gv셵'hB$S Tî01X*CrXwM N!XYZb d#*BQXI?˯뿱LaJ3CJv~4=aH*0h>/K;_U:;X|2 iCEmд$eE1+^cڎbd}fXIR)#3.`J7u]jf" :|:@&le4//u N5gfuR|\bHکUI%\.m vͬݢ^މQ4Pud”p߰ۿ[|=L;NǪp=E̶J8=)*^;Eg=,cў145X@nP]վwRƬrپ-qV!.c tV+&m`AW|DaߎwA -hPīlxwUT{=Uօ|y'inH 8h@{ٚ2?7a\΂4LnTI Ά8= ,C#BVTfOgu2"S% .ɟC(kT!DET: I;B&$F68/Xۍr=`[:p5o[]PpIv`2[5dڃ^9m&'{(F>]?|e==2EEOUU^_T:IGh@99=u\t;箶ӻB!ɱ?N3ORө6GCZ5RֆZ̐5T@k'aCXS?eSd2DϕbvU\ij!+k7ӛ UD {odCi͏,4^ڙWWGPCƞ_ ޺~@C%qY W !XӮ0`ɶ* sg-~`JĖ:r7,h<;SWBbEqe L`BPAЩ^NG29I\7̐qN߬3H&  VA۝C+|ƒeYǁ;oXIe|cG V7@-MrU5/*{{O Hv ޚ{oh`{;+6SD^NfN' m抇 .c% 8[(0Q6Vx*13x X<9 imۿ$uɮ3}i*r4^@RkƓ~CˈC,,薦k%51M)PׯɴE`ԥjC)%#Xe& 7BH\;7[DdO.#+B:e/\3{x~E%_*vF=r(Ll!_U Z]Q._ P tP*]XA.JW`7j)-$gGe$uJe_&2ihvB8o2+@x--mrD&%,T2t/7a HX,6mg;JD>*-iV^sAuĜD@BdWVfƴ.#2#  v)B6'Bޓ8NX{aiO+=fQ&eԶJل3k TF)P'kMfof`- !Y{=: TpU]O|:ߥi/,YѺ\ti]ܳSـ &_7Y)$U'*_#K=~⫭˪,A;noq:L~plr5M_u|Ԝbw6=5R|R|O $g m1($`b[6$;_^;ڊۦbuɦW@x}w2m3\@d紓-w}6KP*^yW)ͦVk&_nƒ;N,#W P a9ukURX dx/\% RedGUrœo?\Y&/ٺѴ1"C/D6Ǣ[%t^rE(O#*|-fu:jr2M) Y`%|S;?"h~3a?AO`PW>TզqQre47 i42`yQ@; Q(P kL 4\t=*fKle IJ /R[ٝ#J]U+g(⬓Mn晳P;5>8ߵf H/t^W}q`ћد8Y ( }K|(`?LKKvX [ l,vVDVMٕ?,&5kJ 2ǧhd?X3ܮia5LMOTvfO|R[C=ίFy Fh=ܒjx4йjtٳ\ȎMFi<!5jA~xVDw-okXt,97bVXZki}֓:#{3:Sȕ@zKv~FjmVz>] ߙ@6vjrСs_}?4,qu]-x'( !5]&Ubuo0^ L ΩYUιz#sD97vOA*_NI!4l05x_10ES? q\m_hbۍs)` W}?@w``c޴a*p k\A:'C*M@^1"R'.pV,MWfIT??v8:[J0r7:nxezHl`R%%:\1?PQ{9h Ζ^97z1 GJ CFU'+B[v]v5\\$WN.J6tU[YI/\A>+ǁeS3<3w`_AktBk + ln}Qaj(lwt:eiy)(9tu,+ʷ~lF\m/lMITeQޡ#)v,bdw_Ljط&N+ҎD~k!Md.c fuTNgqEN(.kvS;@ 9B߼Ib"f@уfhW2z c=n6TJ#f0tnJ)e.ݓI4NaY>Pli *u`@Wwr+>ZRg~MZ=T|C:O%WyP֎\c'# HEؚsW7ȟ5`-* N)SBfeL=a{"a_긃xg X:˃?S߉^bɖ3 !=\T`dw@ Ail/? &yUSGiL{? DدVLq,==gO:H`.No ids4)/@ k3EK 0ڪR?V]WT b&I~͉MZi^}sPE{Ry4ke%U<'3^7r6#'S;F3cI5|DvL՚?_ :Р$`:(qaoXH4wpb5N\Su8 B5XiZ4ϖ׹, * +]{}r?A>\@ 纄v Rc9]97cm g3./0g@*K2=- ۞8@e_mC|5ר%zгM^̘'zjaQ %5Yu\Ti:I m"<<GLP%4 w6w?r"ވBAcˊĎuU 6d_C'/ݿ0~mMȘ"M` 9L,;[(_>-kHɁ+¡NU"ړ;+G[ %c:<`#wlU{JEar!1m/HXN@`>"SW7#׏D1832|-/l.Q5!UP؞0U[MGuNQĐt73bW 2@b'u25L nweK5)R> 5}MFaDBPE@]8ᶱf.Mu%$H zYJ : uw "25B=t_ X1MB1_r勶|!n_}u"c( mیsm.+s%R?OɳUˠ4i>\ B@T]X;XHI@CrS10{=U VϋJ{@Ylh3&xjC5K2@f[3OJRb\D;U \I:OMYг6'н'ksNcWzyD"kUXk7]5`>N#ei֚o5x%|_reZ+ |Jhv˵ynͽfRq,</Oz Q?BoIYU|dX,C誅c/@ؗ ?+T`` 41Lf4v}[pɦ~\<(,NEEȗ6O_׻xk޸b&Oט9]\oy|Ⅹ-19E54=1&W>$zgG0,׀!miwdzD2jsƠVD^|~jpc!'0ycĺ)È|٘;Q36(,xs \ ;ħ@:aD3VIcm3?EB噩*E-x׳)@p۟ŷ[urS,(2{Q)޸O=O*d"C@`@9 Nxnu5B$\KOy3sFI1 /2\(a8 @NO/aYQqbʰk [ƆJ:iu]VT)Pi9Խsل4I&8{a{Pݣ`>qR9|i{]3?3]k=m0jjs5IGW,C o%yivbc!`:Jims>PU~=p. K Qhq;'7bfI]&Ankv4G9Xб.IF[uWGq0uf/,!nӺVULrC\ފ۵{šqq\~Qc5onh zǰWY8,I8e鸲}3Q܄d{YeLdƪ_hUr/r(F:4+7Z}1/g5uR4˂!@STޝA5~y,=v1O=>2K&m8׷O"n+Q`h&$pzPBZԑV~'wU-FJ]b+Њ#t>󣨣UwpG/SJ#Ht%  ,frT2Sq I)swD<).&\&v`M'#=ߖEQ3GcRЀ~J61Ϻ+P]),E&AGvȗWvv9S>L2Ic]բۿ9eS3+2: $hN $ސJua߃-KG7G!Q<&V rh)XSGrB4뻨~/K \~vά{.E~D b|E&K=ؚZ)Umð$ n-&ΠDc8@Iw>̪kޕyW6V\Fa>a>-]|2226HLz?^4 EfkO-<t,=^ӴIxuqT:MeͭgwC] 9%b1FUځ,DyN5aWV =F,B%N.ױS- ; )/JI`J7=eJQ=ߓ3M‚O%OHt֪u !p3]h}( Zc9EǺF +3@%Fr!r ["C!l\UQv㛉]m˕/!d*Ґ\BkHdze+1TyE)= U›*w6gbpxcx]U ޭg9bDGxz8x]F'?f%^7Pأ/m6+Y3:ڒ%= rDp^rJ27< '|({i#,-)W G Գz4wwo9f&+!We SUxUi3})d_D}QT{tMf%CɟP[:O㍉+܏z i6@v}Ӆ\NLl*+{͉2O?I;K* Wq'IƋUTDoFg)YhyU'WX R*rCaiKE_Y7^iZRuuwAePI nFҙf!KҦmhM}*lp(eKTOxq55A < ̈;%N{.V!s;NWȄ+Pd`HMN <4#t_&0vbM|AXHH_'B~E+.*xzГZ#=]($JOs&g5VKV s*}` C_Pr펇ceͯ\Z{ yE(69HZ J>͎=do5=mino w|}kn1'YQc`HfE!˰0IE$} bng1&a-GWQ7P!=?d`܍WvVqA1zVruL+uqQ= tvk8OZS {KJ6wj#4y+yK$b›[g:r)(Š-A䉮ErL[/|-2MVqQ"#v¶\щ𸘩)Q]̐68Bug@Da_Vk#5S0(J5oa WqtXIneT0X$CWs螈!r} sZ.{Pj;v :3~EΈgv}ZDH8|3e 'A)otO]wJBM=^XA܁ 2Pd+n#3@V8(Z)D6 }DY㥘zJh/`5~}MSSr gzʒϰ3Ʋ86Ac{lW= _Pp]Dê*XotI,.n2u zl"! yq%S8H~SY!{R`64 ]ޙdmض=<Mt$.}݃ܟLv*:aӯiW@SV_"Q,YR\>i?ЮЮLowjxR }@DǙn+\xnEO͆+ `Y c5s_:$,QBYTĝe,)JCwz!jV?Gw>! [CnTz 3>N:4pw=IPxTI(K!m@Q5p"fYײD?'Dg} ڧ͗$*6l<@S=1B|MҤ&qB6iI5N=Iߵ!7rƨSc|B)u_kb!ƾ׵ ,QdU&7[? M)Z>@$utWxz5GѾAw]>ŷٴr4d^S(}!xtzgNZf uM-1T(,=?8{fPUzJ8!"/ ųX`MQ.͹ISTZϯҏ.bႸ2$Spf QVRȀNFvH]f0LF()~Lԁ\ gP/?.!ZLČpr5Nq$dR1%_}YHUk(U51=ߙfV/-SR(ý`ߩ6+MoSdIv8Bhf<bUkk/Fb;({`4cw  Ip{:\&p|H~BA1>,UC9<5E5knr &_yVICkF\(܀+CP8nQI>} bW[RS0yeہ6fܓEKq"Ro͏lr ,"/*$=[Hi2e6/{UA%/A[b4fD"Ӱ4bI\rJo%?n0v_HJ3sዛL ylpgd39Mm(ZTPy*3 6C ;7(0ϻ:ܒCcDCn1\'oPE&#G4"̇~7"5gviJފTShEDBK?I+/(k@m͙_gX<ڈSLd$iq%r L0x bu7_ϐT?KCYHwՅhٛAz'.2U*Fơq!I\sW/'mb{VH)·lvP Z-q\?BiPB[u,&C7yũu۸KTU7Nh4! .P1 L}MqXp5o*bv^(w醜gr|;Ʀ+Uֈ=cQ__ E|cJ[ANϓ=c~VNi)﨓5acEk0ɶM zvYt] 0z>Dc|'_dF\ 0.G έm˪ܩvg/JI=Kn%"K +;d٩/CL~!Qxp`5nSs+ 6>oe9rLU^bhTyETCOp|=H ܑ^VN{+-z$?FfA`erGJ'K׽n8kV =L]S*[4HZl؁?JJ۫,6 [AQcK#6UNbRb4vt_bw 4ғw^sCgQN^ݧS1ݨ++1cfN7ܫƩ u1D_ /(w %] [A?q;~(f^Y{|||gY~E*$=ʦ׺s<"toq>2>;# .K"&Xt kc9qՃr8Coy؎33׼L烼yYXFes'=1gM2p^qΐv7pP˵Q&1*wcL"nqӛbƧ_u~_,V{/qM9<Ax2 @lFݤgVd))ҩ2IDPcsxOt.kkE2ǹ1(\,摟[Ҵ}aKvVIYf-X~I UaU(dO0x 4$?i%m)*742kOZV$8c_xKX%*8®>+al蚐>VSݒNLٟW~ VMtx%s\nxje^L|*4 n }.50K=8>&"rVpepJZ!!y'USJG\PH(@v~ycPT |bNeUOB4dPKr+kfkl-!1Y|#jrܡ!EG&jj34Qp\=aCyE5,T z?qhJzIi܉;GN f\{NgIPX_jui|{V;m5oA]uFckUrq̣yĘ9AoMo@u-oT[^`ٶL!2^i'bCg%x굞l@ke>A/OhDUW[Ga_2 uX -.iwʋg (NHjFX6ougx'5"I:hALړF|IZ@ <5J/i.vȭ5:y"F\21F\OZ 5 g쒾 #YNYOgI%<:KXЦ*Ī=\ޥ9G5P8 |;xKYgT(0WDiC|֔SwI}{щNA(ͩYy p x?eomWW溿ͼn2{IB#{xѐYrj<?,G)*an8V>zC %ԑ>P.y>y-N c".tnۉ7QH;4mvA1R >jAtK{,d<"U#雥`3w\I w=@!yQ??fJaSpmpt#x' ܞrHX+UV[`|h+_z9_[`-5!mJ.Ќ_{A0TsS>%!/ جխM6!.ҧ|cǥ / a~HI,?!rյ<5ʝQ\\MEa{{; =+X+g?#t74`[ 1 4Bw:czn;\#0BFK9t#Z옟:I嘚MN FqP禬2Ncth>tky1 Wd\<ȅstq) iݹ#bOf`HPp)t.kY{L~Tbi~s S@c(}@&'+6gOO3Ё!1BH{EUY5.>_⏧<4SV<^d86 2#ZM ; %߅;0$eT } ׿сq27jl^ Hö ډ_׋70=T~߲h0CD8A_" x)(4&X0r\o!# #q~8Dt)Dă\Kʭo ˚JXG±rS ӈ"+.MyAs~kpY* SUጎY>V]6Wi/nuQ".ίkSn@T%ZCz bO?]q;"5^ۨ/[Q S\.瓾4@lu0,q K\V7nWz lDQ bCD9>d<몁=f49:)6]1g`Up]ދDXV)uT; OZӗ/M7^N"C><*N|S؎7螪Z+Zu t+yK~0pvLO f]fl'm)T?ԫzwB2ٟw.&IINU ~yrTQKG {˒$yvY{{Mq#K(qk\+{"!nhhi1S8KL. lf? k.8(ҪGu)|!x? }q(#WDj$i B<)̃T{]v=! &>N 3$):O`.IȎQpde߫3@¤Z@v 6hp' _tq{;3AA=K|Ŧ2k.1])B+T[ A[bl0SX1Z:B_CyXa4nf829 { Wa'-}iv%hq}OyX;J4h?Xod4x}Ҧr U ]}sk1_v`D J_GP/$0@eBaUt6ߖ*j9* LM rCvIؠŧ~$cr4a,pvs;[^֌|"?M(fTGH%}# G"G]ù)-g⠮C.Af%=r)h:$y 0GiH6J}C=ݘB0ߔx[>rXRK b:lh\b"և'l$-Kjա\(v\?cYIc饁Ě,QǝK%ުbx#^;mph"yǕ?&{ ?[Ť4YZ ӝ\إfbI;H%]79LNI+3 TH3(I};-A>\ūH; w=Cow`dyV:R9>^9CUG U_b8'w鹇Ϡ+v? D?ތDG57C¶~U+]5pmC}#~Q#)3Q{n> 69eZ5qdxdQ({!MNߓNI#Q=-3`2bÐ ƯjMLP]^-mi֠2e[a W=u {e[z3/#吩Y X7Πm4Csi Ջl LμB hߴG)U$Ku*E]vd?ox_(/!PXSme <4y_  Q@R8}ZU-z4Y $Iמ8}LUDG`7b/ZuϢ>H?t΄8cq3y.ETۊ`` mfp1; D% iZ*np2a7 ׏3ĊFC3֡t?[Cz_=>ͳgôz0D4QaTu6`FK<ƣwY88Kw< k# -n=MU%λBB4ifS)\S@!;h\&GYvK|҇'dƤ2z"uɿ^uKldҩ ZQ&0v4C^{Ȱډr;;Sc@H9ځKGpWHLG ȳTD\ ~Je=`:)o ltEsݬV*,s^y)T~|ϕT?qʊv PvuknL>:>+vά,{R>(#pZ ĝh3qIPGwS-8VD8e`+ GHvݯ@C{]*DGDR fd&s8n.9)Q, BNE5)^i~nG2ȍƷO(|0R:P70 ~ؼCJ&dDi~Xέ6K5!7AB=b1B)E<ڿRTR WG1C^x_)X]NsZ}DQB~Ъ'S(r=Da$[ w0 (9kW,'ʨAH LJc;nbχwiE85V"4i uy"%LL T~5nOP{VUUWq]XVݏl{0K#~^ :8n 5M{rl&OUgNK&yEp連ڬ$hM$zk>U.#_ Gmc kh;Z\gL`K\'*J GV>hcPM_0 4U` r0Ƃ+[W/\c4UǞ$]hjwb&G^UW^Һ"2.ϧfsH )rtGB#'y4s|&pWJq!uIE2  xy1wkx2ֵL;E9p_?O(9AR)HlrI(8mhďٰIx7rVOVM]5@0-H1I+g-X <6 h4$QӬR Գ4IYU>q2̀Svj254]O"uZHe80H=ם$>jr8=sOQ3' 4{%ܮ"#꒶B/A^44?g+ ה"E(,N7&DET%ѕؖU'ޒe`(rzI2V1ڂݯ P.{XzͱOd~|}超I.] oiHr P*= vM_Mz#f}VkIg(#1Hd)+̢UK{mL_TH-NKb(Lt QdnSq4jp Z+FIkRVn!6ܻ&fS{HlkSAB2'Q܂ejYf-a_8C14,Pzys,^O@vt6?/K9h bXErGcPj& 喉M҄$JPjv jQ,96/_3^: )* _ 0LXM䗫m8GifI?\L#t-)FimD ~%~F }i[@IW+map5Sss52l:1lOp%fZwIE 97^ج腑ԫIjճ?tnys`N˽+MwD qy|%98Y[]tevWu:y:=jb"wNhnvtWK60iē:h}/cÄΞCEwy-~7 $&"uNudu7\[z: 4f [ƞ?|ܯ}YYZ|'NU=JQfg"2I_b."q-滿`,+yT0mV+RSE A,򧟕@L!e$>]NGL5n؈VoQZh}6 W7EKs\Ov{ӣfϽ(/aIiEa:''N%s$g&2gȄ1;\"0A^'(VqV)4a8Us;=G᳝,JkCN& ĸFׯXtfox,W>髺 yl[I:]~G{ P#Hͪ+X|p&F7 $ʧ{B:7C0`מ' & *sBX-P/=g܀`&.AӓhJN ve \NՐiyruاe:-l>5|Eb@y(3nӯ$dojê!(ƀ557 S6gJd[\k!D?W?UsCuC@ڸ޶LS;L{?qQR ߘ2fV{g_#ip2E7(voRXFjʐkuVd1l{^%&Q {F7i*CS33ma_WF*?A|k POsu99'K*~r'Qr1 :HgrKp&]]UsT+. ">뽧7JzcCp};nΆvQ TcDk!t[8Vy]wl4옦*%+Mpr S3[ Y!E0NCe?/-D2 o~M^\UCm|Y7 4m㆘Yy67ZXMHya>.[f":Ū1vak=uĘAdEa2Fo|t#ڽg^1̯Qرl#u-DL5\g0m)1# O^W>wrfZ"Ͼ,.8B!? M8gz= t~,Anju]ʟju _P/M?QlfX2nHX>]D.?| qt儂wʹxo]ah{HP}Nfd w)Q}r{ڜL_([:mc.퀠vŤp #8 ubyOi*dxXgqK3m5Ѓ}̿Si}F} Q ՙ9bcb(ɇ3Y&.ar-bԲ\,`X!/ߘySڐEW !b@Ey,CYקʼn y_f<ŬvGW/b TBZKXh@]Jܢ.ӭO;[hң^]џB+Df^ZM.z]kr| B- G{ olm.G\Ȕm3jѬ4a'[y:^qe8q[^-g6udM"AL{ʸDWp:q˚$l5iX磵,=[<@3gaJj!'e'yF!VpmB>'g"T 8a}7TH#YIIl6۞;ԞD&|8}>9C`x,, XJM'Vo\ 3E"UssyWPJźOGG+LkpkMi_` c*M_25~2[ٓAܮ)8+Z`Zӱ W~yB?Vc[#ҷuDĒm{Rd#-W!R4K6@S^d_Vy:ujsFeAQ+k1M߆e{6 V>З( pAsݾj.%=;Rdc݉ $_-+T$챡N04tOV)fX:A6}hUK3G2-ELGj+gODMbr uecΙA?[5tF"qY*Ks/ͯ{e vh~d@}5QGy^\>qs/7<kT{+zrcՕRyX3\~dd3: <sh;~0 gYT*]ae9$逧(o@(W>18oPfGZݐ}!#r"~ƒT臡"܏TrAq Υ˳uPr~»W5m8س+BA|<Dv\p cn .q>1*C\d􎍩*eƵULTc 'E`qFl]|FM[ C"rqs Hj9xȣ;Eҏf䝺m.ymF(pFlb##aGP3^fD3e↦gCg H_<iM?@nv< A}eCGx\H4ͯ|>Y40W$lߕ-L5ũاVڹ i_r hjjRhOcl4Yz\+:L-zk嗾Ql(ϛETh?x~إ.UxmV}yÄr A…'~fq]<<(AIӼUKBT` $&J0a_P6{JJ%mdӧqҐPS=l{pLgo #j!-/͂{uԩnvQ^ R#qP[5H96/w7  *xsG,|39g  AtזBn & W?>l sTGR.T+fE>@+؊m=1nP#9}7/ gP4X-QE-"-KǨ 8>M XBB9z\^&ą>CPC,a%A(z5jnRk12M6dž_Z;CZè>)**I9P9`=~ 1LMѽȷx1q~np{XEV{Kąm*SϛJ HJPA{0?n L$ٮDg$A_ZjJR|$G捍/Q0*{nf9-Y! ,aC1A$7L 4[ȷ0; c&O쬢k=FN Zfd@ 5YѰ\[pPF} << KD0p=Qpb=KI+I5 HCf'[VXT\~)BA3@,%Z G}'roa:8#QZn)'X̮͐]5=]mao9cx XvzDK .@MѲ$e8)/,<%OVP+f/12h0Ԁ͚W mM;- 2UeKqYa>p=3 ^:窙*D6j1W|OSfPZh Q_wZμrԁ^SX%8RoIzmQg^L JcVlOG+5n7ÞYѝ [Ǎ,ɉ\'ְR KT L N간a=>FҽvR>I9duoG%&gL*dd$@gq8u-k,mHA`޵}? h} (}&>ԜZ rZ5T:ң{c٣`ٹ?IPw%Xf}ӖZQވ}zr,\m; jo?<50h4DeU܇]26'O֍(¹cny[gBu~L(OeDQ$?ubswQFyp6,1aS|TtDS4b:>5di՘ s -;WIԨG;t>i홤ȏߝ۷~6Q DEvЇE | y9y]g xmmN/i< j1 x$7nmKa[2œO6Ӆlx n1IT0gA9YNMe ݗ?b|1.J=m]hOP9;f*>MY/6U!`);A=g1ln%^dGZo;ܭvyx6hwuk,f(r^F ` ?e\RW ,b⪑ⓡp6RQpW Z0!3=<EHroڎJq 3POjE'**)]Ni[mgQK" P=![e?M$ dt-N|ZjCi Fzf)cIi5EϝzC>^6O f{9Ǚ$ G6 pݘL#@؆H.MUKPu^׶' C + Y &;^>FS>,o=pyj`Y<ɱgeo4VyWwpTZ9C S+صr5 '?#u B9B;Њ +f☽>*ks|w!, \>k gĵR Q26鱽FfVzDIQ*1  r[~N;l3|Ln3@b SBvd7 #ۖØ %%+'*Dg)uqQ4HZ)]gs ሡ@߄hiٿCIL_%=ڈh+ܹǽ` (dNnOj Q\Mf>gHZJ+bޡJ%~hݵ\񆞫.b>oܛ,J/R 23`qOh;]0,ct|#!xzQG ^fҐE䈒]6'=yJ؃Rzo%X6r>|M:ĨAl)cuT3,Ơލ ~AZt'> qrXd(J[GA$} 9Rm6%qsǹྦྷȸJ{65\7(>k`+18m2W$H%).B˰K{uZE,-}X3I.Pz7931]RЩ\hUM{5k(B{(l:DoA/ǎz6YL#3~3 o=)2zL9@1b w>F46RYT;x"Yf,|4ZMYL㐘ԣ 鈃-F&iZgK a*@n ~:w4v &ޞU|O"(#ǩCi#æ;:BuL c2FYQ%%?c_!Ve#̣Q,a*VW" z2n}x@22!Z=tz# W-eW}Aaz뙳HcHVK˸5/(|6;Ȼ/wq1i{f6I^9 fYqVĬ]YU:f߿k9<#Jxwݶo϶3yT#x9v8Vc=PЀI >\2gИU9NjaWv > ;d#Sf(2+$iSakSF6(xBݾ?a{wBy8tPc2o5O*vЧ6"ք#L4[m2ZU _;nevږDV-fu!_Q|z (\I2q@k:( tƞf #z C\@ǵ_;LoFumKy) `[XWYY7V!/(v=qП -tS" &A6y.X1U&r<>ObcC [ܠh43Dmnݾݔ a+),L?E"{ベXgb]Ϋ3rMv'E4 F?YL[v =(RMS,NOFզ%b5Dld2Q-0D'\`k!AdY5[v!b1[c^%Lx3>[WBPEi82¬>8{l[#am68pB[ Z98a$^ b@ jhS8wsq' Rƪ$M-Uv$$g[?]c'&+]M/D|; ?}sؐ>{Ҕ*eǨ9sVh P˼"&cVWpUNя-b0eE-%KU%|^\>#v*bUzKx~m钹&zlEmizZ]*[~(F:Fj++wA&|4n[fX PDYK.:qjRtFbN i8xT L+.]D+巻FHAfH fJ(Rz0~ 3$+ȺKSduc ZNpPȵبs:ŋ n T}pz)˃&6jGM\s2J6t!aڷ Ѣ%K/~lI9CןqY{ 013\Ղ/6-Wwj+>|a..WP Q*,HgU{cʀb# IMO`00~IM_MZ4Gꪑ\,jfI30y1z?{zV٣+~I&M)`^y<u8_L'|9GbDTԒNnĖqNÜߝޞ7Sm@t EӼE|=gD&8 \{rp} 6Ƅt(z4SE Y-4wNE)ysHK ?U"{p6lD?ְp <hp* % 2-} D6UZrdw0dy/ԷvWU2 㭍=:8E>G֥'BWtNh('ţIof{%'{Gلwi\0Ӿ|iMA@QFD/gg(6Ά/ ^%3q [[yJK@?vK$LhxSJ>Ԉ8^GE(jd0CbZK3 #R^b<"^]`ۛ ٞOJ2~:d8vӤUP{\J16PRH\bޥש.YJF}>Rxj9>T!/jh9YlCEqu-F8J=+*7<-7ߠECBϦ.V1pyK}JaLoQTkQznf2{F=tP'*1(h۱': Fuv?:gs-G洣ͅ^OkӮLDHƄͮB'taZ]9AUMb ]%뒤qw8 \gWq03:!{HdT9Y*h= Or!ڲe؄e #1^!(ZO1Lg\V~ܾafJ^rе ƫ+s6͠>ZU.q /x ϥJ6ߵ |ko"ڔ\!]~oѷmgg >,X 8{ }QKF(7Q}!%{/t1" Nd]儏BF"paTݻSܸg"ذ<@E ^GKcA<8IQFmdIlӑxg^zb#3jg0i`w*պgtTچѦw.;;؉|K_6!ttS+ dQʃJ'SI޶_ *EQR_t&eklZ QaGZ<07 |˓[Ҹc %;j.$jł>W`~(*bH`N0Cjڑ%J ':`5>吧64)%<|QCn"T|R;}fM=[XV.9r@rAWJk* '8Vu t%V*?F^H]9wDhX%b9;YMWPT]YaME#جg L$>+J²ޞJ+25mH'Wdۯ|=A^ (:vVPA).\8K: >E5S.oSX&q6ԳUP3y(~`>zC#KQ5H+׵ORdHԉ^_u(pЪ\gDi* iP80`T?8q?joh"m*5$:3 ~:3b cW5pҗ1|Xw 7kofP4>ī6~㐑4Nd/iʌ6-\zX49GT'lA"K^N&_kҐ4[S~)k?+4M؈ɛt.x}M`5%ƴJŸ9go6SK8Q:y~1>@ϕY'O ✐!k\1*ڱdG/TӜZL_2\MWuQ B'^͒ަZ:rop=N_MB뙳B!*Mv^+9_R۾#mz(MN*Z8iG!2mK 9 YN5:1x? YS$UQZ6q<[,V0XkCyK0{;|k˩@pu6(}5)J}ؑĒ'/FœH!oؔ\㧉d)& 37m\Ywٯp8Yvf)o1h'dr>}U<ܑ6ah!70W5dT$RZfu O X iy }Y%!)%0?^%o!$}f4'fgf 1tЧ@E1i!蕶RoM"b/ߩ=SM`L/o)"Z{M)ӈ3L1I.'9@.ъYJkwz?u$%kq6b@ER'Z¤=.d\äc$f]E\Ώe>'WC8] 6!t`sDSQ3R"eq3ᝮIOݿŦ$> j%*@<후%[B'>O)W1Ǐg',TF{yV^n+*A'&:σpOKt+e+ؒ;"U sbD:#ט/1?g8.džHQ !w٩/{;>~q>֋יP%2OWn+mqώc$\hݤN;=/HdpΠ2y]&l)h} C #?f~ϧ';1h! ?A,7:cXaGRUY|A-uL(Mq"Xl\۫p,ꕲGhqlsqL5#kaC8e r9_͒j_M@0/kA\%Bl 񴵀˩M9ĬIJ,ζ%9#v#ڇ䗖nfVqtƲ-h2UlIk %a~/*SJⳣ԰"[K "]sM~Wo6V0 P*7֌I=86 7&}gVt,RaI"*Bӂ)JJQ!ل^K$8 g 0_AiHE[.:齮,E)R:]lawu1ج~`+ρ/q{>^A3XtRQ1ѣTw.PRKB UQi0j LR