From: Gerald Carter Date: Fri, 1 Jun 2001 11:50:38 +0000 (+0000) Subject: syncing up with SAMBA_2_2 X-Git-Tag: samba-4.0.0alpha6~801^2~18058 X-Git-Url: http://git.samba.org/?p=samba.git;a=commitdiff_plain;h=05b2b2cdd4895b6d2a4d345192bfd4fed1e0ec25 syncing up with SAMBA_2_2 (This used to be commit 1bc58c21b15fcdb0a504d051f60e20c4e24441e6) --- diff --git a/docs/Samba-HOWTO-Collection.pdf b/docs/Samba-HOWTO-Collection.pdf index b41513ed06b..251416d1cdd 100644 --- a/docs/Samba-HOWTO-Collection.pdf +++ b/docs/Samba-HOWTO-Collection.pdf @@ -1,6 +1,6 @@ %PDF-1.2 %âãÏÓ -1 0 obj<>endobj +1 0 obj<>endobj 2 0 obj<>endobj 3 0 obj<>endobj 4 0 obj<>endobj @@ -13,7 +13,7 @@ 11 0 obj<>endobj 12 0 obj<>endobj 13 0 obj<>endobj -14 0 obj<>endobj +14 0 obj<>endobj 15 0 obj<>endobj 16 0 obj<>endobj 17 0 obj[14 0 R @@ -23,7 +23,7 @@ 19 0 obj<>endobj 20 0 obj[19 0 R ]endobj -21 0 obj<>endobj +21 0 obj<>endobj 22 0 obj[21 0 R ]endobj 23 0 obj<>endobj @@ -40,23 +40,23 @@ 31 0 obj<>endobj 32 0 obj<>endobj 33 0 obj<>endobj -34 0 obj<>endobj -35 0 obj[31 0 R +34 0 obj<>endobj +35 0 obj<>endobj +36 0 obj[31 0 R 33 0 R -34 0 R +35 0 R ]endobj -36 0 obj<>endobj -37 0 obj<>endobj -38 0 obj<>endobj -39 0 obj<>endobj -40 0 obj<>endobj -41 0 obj<>endobj -42 0 obj<>endobj -43 0 obj<>endobj +37 0 obj<>endobj +38 0 obj<>endobj +39 0 obj<>endobj +40 0 obj<>endobj +41 0 obj<>endobj +42 0 obj<>endobj +43 0 obj<>endobj 44 0 obj<>endobj -45 0 obj<>endobj -46 0 obj<>endobj -47 0 obj<>endobj +45 0 obj<>endobj +46 0 obj<>endobj +47 0 obj<>endobj 48 0 obj[37 0 R 39 0 R 41 0 R @@ -64,311 +64,318 @@ 45 0 R 47 0 R ]endobj -49 0 obj<>endobj -50 0 obj<>endobj +49 0 obj<>endobj +50 0 obj<>endobj 51 0 obj[50 0 R ]endobj -52 0 obj<>endobj -53 0 obj<>endobj -54 0 obj<>endobj -55 0 obj<>endobj +52 0 obj<>endobj +53 0 obj<>endobj +54 0 obj<>endobj +55 0 obj<>endobj 56 0 obj<>endobj -57 0 obj<>endobj -58 0 obj<>endobj -59 0 obj<>endobj -60 0 obj<>endobj -61 0 obj<>endobj -62 0 obj<>endobj -63 0 obj<>endobj -64 0 obj<>endobj -65 0 obj<>endobj -66 0 obj[53 0 R +57 0 obj<>endobj +58 0 obj<>endobj +59 0 obj<>endobj +60 0 obj<>endobj +61 0 obj<>endobj +62 0 obj[53 0 R 55 0 R 57 0 R 59 0 R 61 0 R -63 0 R -65 0 R ]endobj +63 0 obj<>endobj +64 0 obj<>endobj +65 0 obj<>endobj +66 0 obj<>endobj 67 0 obj<>endobj -68 0 obj<>endobj -69 0 obj[68 0 R +68 0 obj<>endobj +69 0 obj[64 0 R +66 0 R +68 0 R ]endobj -70 0 obj<>endobj -71 0 obj<>endobj -72 0 obj<>endobj -73 0 obj<>endobj -74 0 obj<>endobj -75 0 obj<>endobj -76 0 obj[71 0 R -73 0 R -75 0 R +70 0 obj<>endobj +71 0 obj<>endobj +72 0 obj[71 0 R ]endobj -77 0 obj<>endobj -78 0 obj<>endobj -79 0 obj<>endobj -80 0 obj<>endobj -81 0 obj<>endobj -82 0 obj<>endobj -83 0 obj[78 0 R -80 0 R -82 0 R +73 0 obj<>endobj +74 0 obj<>endobj +75 0 obj<>endobj +76 0 obj<>endobj +77 0 obj<>endobj +78 0 obj<>endobj +79 0 obj[74 0 R +76 0 R +78 0 R ]endobj -84 0 obj<>endobj -85 0 obj<>endobj -86 0 obj<>endobj -87 0 obj<>endobj -88 0 obj<>endobj -89 0 obj<>endobj -90 0 obj<>endobj -91 0 obj<>endobj -92 0 obj[85 0 R -87 0 R -89 0 R -91 0 R +80 0 obj<>endobj +81 0 obj<>endobj +82 0 obj<>endobj +83 0 obj<>endobj +84 0 obj<>endobj +85 0 obj<>endobj +86 0 obj[81 0 R +83 0 R +85 0 R ]endobj -93 0 obj<>endobj -94 0 obj<>endobj -95 0 obj<>endobj -96 0 obj<>endobj -97 0 obj[94 0 R -96 0 R +87 0 obj<>endobj +88 0 obj<>endobj +89 0 obj<>endobj +90 0 obj<>endobj +91 0 obj<>endobj +92 0 obj<>endobj +93 0 obj<>endobj +94 0 obj<>endobj +95 0 obj[88 0 R +90 0 R +92 0 R +94 0 R ]endobj -98 0 obj<>endobj -99 0 obj<>endobj -100 0 obj<>endobj -101 0 obj<>endobj -102 0 obj<>endobj -103 0 obj<>endobj -104 0 obj<>endobj -105 0 obj<>endobj -106 0 obj<>endobj -107 0 obj<>endobj -108 0 obj<>endobj -109 0 obj<>endobj -110 0 obj<>endobj -111 0 obj<>endobj -112 0 obj<>endobj -113 0 obj<>endobj -114 0 obj<>endobj -115 0 obj<>endobj -116 0 obj<>endobj -117 0 obj<>endobj -118 0 obj<>endobj -119 0 obj<>endobj -120 0 obj<>endobj -121 0 obj<>endobj -122 0 obj<>endobj -123 0 obj<>endobj -124 0 obj<>endobj -125 0 obj<>endobj -126 0 obj<>endobj -127 0 obj<>endobj -128 0 obj<>endobj -129 0 obj<>endobj -130 0 obj<>endobj -131 0 obj<>endobj -132 0 obj<>endobj -133 0 obj<>endobj -134 0 obj<>endobj -135 0 obj<>endobj -136 0 obj<>endobj -137 0 obj<>endobj -138 0 obj<>endobj -139 0 obj<>endobj -140 0 obj<>endobj -141 0 obj<>endobj -142 0 obj<>endobj -143 0 obj<>endobj -144 0 obj[99 0 R +96 0 obj<>endobj +97 0 obj<>endobj +98 0 obj<>endobj +99 0 obj<>endobj +100 0 obj<>endobj +101 0 obj<>endobj +102 0 obj<>endobj +103 0 obj<>endobj +104 0 obj[97 0 R +99 0 R 101 0 R 103 0 R -105 0 R -107 0 R -109 0 R -111 0 R -113 0 R -115 0 R -117 0 R -119 0 R -121 0 R -123 0 R -125 0 R -127 0 R -129 0 R -131 0 R -133 0 R -135 0 R -137 0 R -139 0 R -141 0 R -143 0 R ]endobj -145 0 obj<>endobj -146 0 obj<>endobj -147 0 obj<>endobj -148 0 obj<>endobj -149 0 obj<>endobj -150 0 obj<>endobj -151 0 obj[146 0 R -148 0 R -150 0 R +105 0 obj<>endobj +106 0 obj<>endobj +107 0 obj<>endobj +108 0 obj<>endobj +109 0 obj<>endobj +110 0 obj<>endobj +111 0 obj<>endobj +112 0 obj<>endobj +113 0 obj<>endobj +114 0 obj<>endobj +115 0 obj<>endobj +116 0 obj<>endobj +117 0 obj<>endobj +118 0 obj<>endobj +119 0 obj<>endobj +120 0 obj<>endobj +121 0 obj<>endobj +122 0 obj<>endobj +123 0 obj<>endobj +124 0 obj<>endobj +125 0 obj<>endobj +126 0 obj<>endobj +127 0 obj<>endobj +128 0 obj<>endobj +129 0 obj<>endobj +130 0 obj<>endobj +131 0 obj<>endobj +132 0 obj<>endobj +133 0 obj<>endobj +134 0 obj<>endobj +135 0 obj<>endobj +136 0 obj<>endobj +137 0 obj<>endobj +138 0 obj<>endobj +139 0 obj<>endobj +140 0 obj<>endobj +141 0 obj<>endobj +142 0 obj<>endobj +143 0 obj<>endobj +144 0 obj<>endobj +145 0 obj[106 0 R +108 0 R +110 0 R +112 0 R +114 0 R +116 0 R +118 0 R +120 0 R +122 0 R +124 0 R +126 0 R +128 0 R +130 0 R +132 0 R +134 0 R +136 0 R +138 0 R +140 0 R +142 0 R +144 0 R ]endobj -152 0 obj<>endobj -153 0 obj<>endobj -154 0 obj[153 0 R +146 0 obj<>endobj +147 0 obj<>endobj +148 0 obj<>endobj +149 0 obj<>endobj +150 0 obj<>endobj +151 0 obj<>endobj +152 0 obj<>endobj +153 0 obj<>endobj +154 0 obj<>endobj +155 0 obj<>endobj +156 0 obj<>endobj +157 0 obj<>endobj +158 0 obj[147 0 R +149 0 R +151 0 R +153 0 R +155 0 R +157 0 R ]endobj -155 0 obj<>endobj -156 0 obj<>endobj -157 0 obj[156 0 R +159 0 obj<>endobj +160 0 obj<>endobj +161 0 obj<>endobj +162 0 obj<>endobj +163 0 obj[160 0 R +162 0 R ]endobj -158 0 obj<>endobj -159 0 obj<>endobj -160 0 obj<>endobj -161 0 obj<>endobj -162 0 obj<>endobj -163 0 obj<>endobj -164 0 obj<>endobj -165 0 obj<>endobj -166 0 obj[159 0 R -161 0 R -163 0 R -165 0 R +164 0 obj<>endobj +165 0 obj<>endobj +166 0 obj[165 0 R ]endobj -167 0 obj<>endobj -168 0 obj<>endobj -169 0 obj<>endobj -170 0 obj<>endobj -171 0 obj<>endobj -172 0 obj<>endobj -173 0 obj<>endobj -174 0 obj<>endobj -175 0 obj<>endobj -176 0 obj<>endobj -177 0 obj[168 0 R +167 0 obj<>endobj +168 0 obj<>endobj +169 0 obj<>endobj +170 0 obj<>endobj +171 0 obj<>endobj +172 0 obj<>endobj +173 0 obj[168 0 R 170 0 R 172 0 R -174 0 R -176 0 R ]endobj -178 0 obj<>endobj -179 0 obj<>endobj -180 0 obj<>endobj -181 0 obj<>endobj -182 0 obj<>endobj -183 0 obj<>endobj -184 0 obj<>endobj -185 0 obj<>endobj -186 0 obj<>endobj -187 0 obj<>endobj -188 0 obj[179 0 R -181 0 R -183 0 R -185 0 R -187 0 R +174 0 obj<>endobj +175 0 obj<>endobj +176 0 obj<>endobj +177 0 obj<>endobj +178 0 obj<>endobj +179 0 obj<>endobj +180 0 obj[175 0 R +177 0 R +179 0 R ]endobj -189 0 obj<>endobj -190 0 obj<>endobj -191 0 obj[190 0 R +181 0 obj<>endobj +182 0 obj<>endobj +183 0 obj<>endobj +184 0 obj<>endobj +185 0 obj<>endobj +186 0 obj<>endobj +187 0 obj<>endobj +188 0 obj<>endobj +189 0 obj<>endobj +190 0 obj<>endobj +191 0 obj<>endobj +192 0 obj<>endobj +193 0 obj<>endobj +194 0 obj<>endobj +195 0 obj<>endobj +196 0 obj<>endobj +197 0 obj[182 0 R +184 0 R +186 0 R +188 0 R +190 0 R +192 0 R +194 0 R +196 0 R ]endobj -192 0 obj<>endobj -193 0 obj<>endobj -194 0 obj<>endobj -195 0 obj<>endobj -196 0 obj<>endobj -197 0 obj<>endobj -198 0 obj<>endobj -199 0 obj<>endobj -200 0 obj<>endobj -201 0 obj<>endobj -202 0 obj<>endobj -203 0 obj<>endobj -204 0 obj[193 0 R -195 0 R -197 0 R -199 0 R -201 0 R -203 0 R +198 0 obj<>endobj +199 0 obj<>endobj +200 0 obj[199 0 R ]endobj -205 0 obj<>endobj -206 0 obj<>endobj -207 0 obj<>endobj -208 0 obj<>endobj -209 0 obj<>endobj -210 0 obj<>endobj -211 0 obj<>endobj -212 0 obj<>endobj -213 0 obj[206 0 R +201 0 obj<>endobj +202 0 obj<>endobj +203 0 obj<>endobj +204 0 obj<>endobj +205 0 obj<>endobj +206 0 obj<>endobj +207 0 obj<>endobj +208 0 obj<>endobj +209 0 obj<>endobj +210 0 obj<>endobj +211 0 obj<>endobj +212 0 obj<>endobj +213 0 obj[202 0 R +204 0 R +206 0 R 208 0 R 210 0 R 212 0 R ]endobj -214 0 obj<>endobj -215 0 obj<>endobj -216 0 obj[215 0 R -]endobj -217 0 obj<>endobj -218 0 obj<>endobj -219 0 obj<>endobj -220 0 obj<>endobj -221 0 obj<>endobj -222 0 obj<>endobj -223 0 obj<>endobj -224 0 obj<>endobj -225 0 obj<>endobj -226 0 obj<>endobj -227 0 obj<>endobj -228 0 obj<>endobj -229 0 obj<>endobj -230 0 obj<>endobj -231 0 obj<>endobj -232 0 obj<>endobj -233 0 obj<>endobj -234 0 obj<>endobj -235 0 obj<>endobj -236 0 obj<>endobj -237 0 obj<>endobj -238 0 obj<>endobj -239 0 obj<>endobj -240 0 obj<>endobj -241 0 obj<>endobj -242 0 obj<>endobj -243 0 obj<>endobj -244 0 obj<>endobj -245 0 obj<>endobj -246 0 obj<>endobj -247 0 obj<>endobj -248 0 obj<>endobj -249 0 obj<>endobj -250 0 obj<>endobj -251 0 obj<>endobj -252 0 obj<>endobj -253 0 obj<>endobj -254 0 obj<>endobj -255 0 obj<>endobj -256 0 obj<>endobj -257 0 obj<>endobj -258 0 obj<>endobj -259 0 obj<>endobj -260 0 obj<>endobj -261 0 obj<>endobj -262 0 obj[217 0 R -218 0 R +214 0 obj<>endobj +215 0 obj<>endobj +216 0 obj<>endobj +217 0 obj<>endobj +218 0 obj<>endobj +219 0 obj<>endobj +220 0 obj<>endobj +221 0 obj<>endobj +222 0 obj[215 0 R +217 0 R 219 0 R -220 0 R 221 0 R -222 0 R -223 0 R -224 0 R -225 0 R -226 0 R -227 0 R -228 0 R +]endobj +223 0 obj<>endobj +224 0 obj<>endobj +225 0 obj[224 0 R +]endobj +226 0 obj<>endobj +227 0 obj<>endobj +228 0 obj<>endobj +229 0 obj<>endobj +230 0 obj<>endobj +231 0 obj<>endobj +232 0 obj[227 0 R 229 0 R -230 0 R 231 0 R -232 0 R -233 0 R +]endobj +233 0 obj<>endobj +234 0 obj<>endobj +235 0 obj<>endobj +236 0 obj<>endobj +237 0 obj<>endobj +238 0 obj<>endobj +239 0 obj<>endobj +240 0 obj<>endobj +241 0 obj<>endobj +242 0 obj<>endobj +243 0 obj<>endobj +244 0 obj<>endobj +245 0 obj<>endobj +246 0 obj<>endobj +247 0 obj<>endobj +248 0 obj<>endobj +249 0 obj<>endobj +250 0 obj<>endobj +251 0 obj<>endobj +252 0 obj<>endobj +253 0 obj<>endobj +254 0 obj<>endobj +255 0 obj<>endobj +256 0 obj<>endobj +257 0 obj<>endobj +258 0 obj<>endobj +259 0 obj<>endobj +260 0 obj<>endobj +261 0 obj<>endobj +262 0 obj<>endobj +263 0 obj<>endobj +264 0 obj<>endobj +265 0 obj<>endobj +266 0 obj<>endobj +267 0 obj<>endobj +268 0 obj<>endobj +269 0 obj<>endobj +270 0 obj<>endobj +271 0 obj<>endobj +272 0 obj<>endobj +273 0 obj<>endobj +274 0 obj<>endobj +275 0 obj<>endobj +276 0 obj<>endobj +277 0 obj<>endobj +278 0 obj[233 0 R 234 0 R 235 0 R 236 0 R @@ -397,51 +404,8 @@ 259 0 R 260 0 R 261 0 R -]endobj -263 0 obj<>endobj -264 0 obj<>endobj -265 0 obj<>endobj -266 0 obj<>endobj -267 0 obj<>endobj -268 0 obj<>endobj -269 0 obj<>endobj -270 0 obj<>endobj -271 0 obj<>endobj -272 0 obj<>endobj -273 0 obj<>endobj -274 0 obj<>endobj -275 0 obj<>endobj -276 0 obj<>endobj -277 0 obj<>endobj -278 0 obj<>endobj -279 0 obj<>endobj -280 0 obj<>endobj -281 0 obj<>endobj -282 0 obj<>endobj -283 0 obj<>endobj -284 0 obj<>endobj -285 0 obj<>endobj -286 0 obj<>endobj -287 0 obj<>endobj -288 0 obj<>endobj -289 0 obj<>endobj -290 0 obj<>endobj -291 0 obj<>endobj -292 0 obj<>endobj -293 0 obj<>endobj -294 0 obj<>endobj -295 0 obj<>endobj -296 0 obj<>endobj -297 0 obj<>endobj -298 0 obj<>endobj -299 0 obj<>endobj -300 0 obj<>endobj -301 0 obj<>endobj -302 0 obj<>endobj -303 0 obj<>endobj -304 0 obj<>endobj -305 0 obj<>endobj -306 0 obj[263 0 R +262 0 R +263 0 R 264 0 R 265 0 R 266 0 R @@ -456,8 +420,51 @@ 275 0 R 276 0 R 277 0 R -278 0 R -279 0 R +]endobj +279 0 obj<>endobj +280 0 obj<>endobj +281 0 obj<>endobj +282 0 obj<>endobj +283 0 obj<>endobj +284 0 obj<>endobj +285 0 obj<>endobj +286 0 obj<>endobj +287 0 obj<>endobj +288 0 obj<>endobj +289 0 obj<>endobj +290 0 obj<>endobj +291 0 obj<>endobj +292 0 obj<>endobj +293 0 obj<>endobj +294 0 obj<>endobj +295 0 obj<>endobj +296 0 obj<>endobj +297 0 obj<>endobj +298 0 obj<>endobj +299 0 obj<>endobj +300 0 obj<>endobj +301 0 obj<>endobj +302 0 obj<>endobj +303 0 obj<>endobj +304 0 obj<>endobj +305 0 obj<>endobj +306 0 obj<>endobj +307 0 obj<>endobj +308 0 obj<>endobj +309 0 obj<>endobj +310 0 obj<>endobj +311 0 obj<>endobj +312 0 obj<>endobj +313 0 obj<>endobj +314 0 obj<>endobj +315 0 obj<>endobj +316 0 obj<>endobj +317 0 obj<>endobj +318 0 obj<>endobj +319 0 obj<>endobj +320 0 obj<>endobj +321 0 obj<>endobj +322 0 obj[279 0 R 280 0 R 281 0 R 282 0 R @@ -484,184 +491,245 @@ 303 0 R 304 0 R 305 0 R -]endobj -307 0 obj<>endobj -308 0 obj<>endobj -309 0 obj[307 0 R +306 0 R +307 0 R 308 0 R +309 0 R +310 0 R +311 0 R +312 0 R +313 0 R +314 0 R +315 0 R +316 0 R +317 0 R +318 0 R +319 0 R +320 0 R +321 0 R ]endobj -310 0 obj<>endobj -311 0 obj<>endobj -312 0 obj<>endobj -313 0 obj<>endobj -314 0 obj<>endobj -315 0 obj<>endobj -316 0 obj<>endobj -317 0 obj<>endobj -318 0 obj<>endobj -319 0 obj<>endobj -320 0 obj<>endobj -321 0 obj<>endobj -322 0 obj<>endobj -323 0 obj<>endobj -324 0 obj<>endobj -325 0 obj<>endobj -326 0 obj<>endobj -327 0 obj<>endobj -328 0 obj<>endobj -329 0 obj<>endobj -330 0 obj<>endobj -331 0 obj<>endobj -332 0 obj<>endobj -333 0 obj<>endobj -334 0 obj<>endobj -335 0 obj<>endobj -336 0 obj<>endobj -337 0 obj<>endobj -338 0 obj<>endobj -339 0 obj<>endobj -340 0 obj<>endobj -341 0 obj<>endobj -342 0 obj<>endobj -343 0 obj<>endobj -344 0 obj<>endobj -345 0 obj<>endobj -346 0 obj<>endobj -347 0 obj<>endobj -348 0 obj<>endobj -349 0 obj<>endobj -350 0 obj<>endobj -351 0 obj<>endobj -352 0 obj<>endobj -353 0 obj<>endobj -354 0 obj<>endobj -355 0 obj<>endobj -356 0 obj<>endobj -357 0 obj<>endobj -358 0 obj<>endobj -359 0 obj<>endobj -360 0 obj<>endobj -361 0 obj<>endobj -362 0 obj<>endobj -363 0 obj<>endobj -364 0 obj<>endobj -365 0 obj<>endobj -366 0 obj<>endobj -367 0 obj<>endobj -368 0 obj<>endobj -369 0 obj<>endobj -370 0 obj<>endobj -371 0 obj<>endobj -372 0 obj<>endobj -373 0 obj<>endobj -374 0 obj<>endobj -375 0 obj<>endobj -376 0 obj<>endobj -377 0 obj<>endobj -378 0 obj<>endobj -379 0 obj<>endobj -380 0 obj<>endobj -381 0 obj<>endobj -382 0 obj<>endobj -383 0 obj<>endobj -384 0 obj<>endobj -385 0 obj<>endobj -386 0 obj<>endobj -387 0 obj<>endobj -388 0 obj<>endobj -389 0 obj<>endobj -390 0 obj<>endobj -391 0 obj<>endobj -392 0 obj<>endobj -393 0 obj<>endobj -394 0 obj<>endobj -395 0 obj<>endobj -396 0 obj<>endobj -397 0 obj<>endobj -398 0 obj<>endobj -399 0 obj<>endobj -400 0 obj<>endobj -401 0 obj<>endobj -402 0 obj<>endobj -403 0 obj<>endobj -404 0 obj<>endobj -405 0 obj<>endobj -406 0 obj<>endobj -407 0 obj<>endobj -408 0 obj<>endobj -409 0 obj<>endobj +324 0 obj<>endobj +325 0 obj<>endobj +326 0 obj<>endobj +327 0 obj<>endobj +328 0 obj<>endobj +329 0 obj<>endobj +330 0 obj<>endobj +331 0 obj<>endobj +332 0 obj<>endobj +333 0 obj<>endobj +334 0 obj[323 0 R +324 0 R +325 0 R +326 0 R +327 0 R +328 0 R +329 0 R +330 0 R +331 0 R +332 0 R +333 0 R +]endobj +335 0 obj<>endobj +336 0 obj<>endobj +337 0 obj<>endobj +338 0 obj<>endobj +339 0 obj<>endobj +340 0 obj<>endobj +341 0 obj<>endobj +342 0 obj<>endobj +343 0 obj<>endobj +344 0 obj<>endobj +345 0 obj<>endobj +346 0 obj<>endobj +347 0 obj<>endobj +348 0 obj<>endobj +349 0 obj<>endobj +350 0 obj<>endobj +351 0 obj<>endobj +352 0 obj<>endobj +353 0 obj<>endobj +354 0 obj<>endobj +355 0 obj<>endobj +356 0 obj<>endobj +357 0 obj<>endobj +358 0 obj<>endobj +359 0 obj<>endobj +360 0 obj<>endobj +361 0 obj<>endobj +362 0 obj<>endobj +363 0 obj<>endobj +364 0 obj<>endobj +365 0 obj<>endobj +366 0 obj<>endobj +367 0 obj<>endobj +368 0 obj<>endobj +369 0 obj<>endobj +370 0 obj<>endobj +371 0 obj<>endobj +372 0 obj<>endobj +373 0 obj<>endobj +374 0 obj<>endobj +375 0 obj<>endobj +376 0 obj<>endobj +377 0 obj<>endobj +378 0 obj<>endobj +379 0 obj<>endobj +380 0 obj<>endobj +381 0 obj<>endobj +382 0 obj<>endobj +383 0 obj<>endobj +384 0 obj<>endobj +385 0 obj<>endobj +386 0 obj<>endobj +387 0 obj<>endobj +388 0 obj<>endobj +389 0 obj<>endobj +390 0 obj<>endobj +391 0 obj<>endobj +392 0 obj<>endobj +393 0 obj<>endobj +394 0 obj<>endobj +395 0 obj<>endobj +396 0 obj<>endobj +397 0 obj<>endobj +398 0 obj<>endobj +399 0 obj<>endobj +400 0 obj<>endobj +401 0 obj<>endobj +402 0 obj<>endobj +403 0 obj<>endobj +404 0 obj<>endobj +405 0 obj<>endobj +406 0 obj<>endobj +407 0 obj<>endobj +408 0 obj<>endobj +409 0 obj<>endobj +410 0 obj<>endobj +411 0 obj<>endobj +412 0 obj<>endobj +413 0 obj<>endobj +414 0 obj<>endobj +415 0 obj<>endobj +416 0 obj<>endobj +417 0 obj<>endobj +418 0 obj<>endobj +419 0 obj<>endobj +420 0 obj<>endobj +421 0 obj<>endobj +422 0 obj<>endobj +423 0 obj<>endobj +424 0 obj<>endobj +425 0 obj<>endobj +426 0 obj<>endobj +427 0 obj<>endobj +428 0 obj<>endobj +429 0 obj<>endobj +430 0 obj<>endobj +431 0 obj<>endobj +432 0 obj<>endobj +433 0 obj<>endobj +434 0 obj<>endobj +435 0 obj<>endobj +436 0 obj<>endobj +437 0 obj<>endobj +438 0 obj<>endobj +439 0 obj<>endobj +440 0 obj<>endobj +441 0 obj<>endobj +442 0 obj<>endobj +443 0 obj<>endobj +444 0 obj<>endobj +445 0 obj<>endobj +446 0 obj<>endobj +447 0 obj<>endobj +448 0 obj<>endobj +449 0 obj<>endobj +450 0 obj<>endobj -410 0 obj<>>>/Annots 17 0 R>>endobj -411 0 obj<>stream -xu’AsÓ0…ïþoz*3­b9®“p"¥80 gŽ²½‰l+H2™ü{VŠ!MÆ;«Õî~ïI?#‰˜‰Y‚i†²‹îóhò¸@#ßp&›¦È+Ä"Žy¥¼^/¿Ü/±2zG¥Ãƒ.‡Žz§\£û7ù.”J®ð¥·³X̹x¬ÉIu~ˇ<ân¸»“œMç3þŸðÏ6§Ä4ÙëÄ+ªt‘…Ög®eaQ¥;A¤r„Hæ"ñyÝXZÿJݶ¬€±¡7øôô-â媢 -Nc­ºB¡z©ú¸šp$e>Ù£ßK½ÞÕÊAµ­`írz«8UÆ°I7(«;rMG6ô -,­2[î½Ó…ïÂ@=aOÆ2[Éa§v¸éð]aIµu´Ø4=ã2R«™³¹|¤|^þõü1’23¤©d¤‰ôŽœ¢kà1‡Ià=ÊjíèŽóÖ­y^K`™A£o~c¶¸®Û¿L‡ƒ°Þ@¡Ívr¹7ø½,2_]\¡+ìՖXèª%e –Xà°¯Xû¥Ï -‘ò¹Æ¬f–‰t þˆùŒå%‹‹[¼#cŽïþBþ‡Q„uÜ&~_¡÷5±)7Õ#Ë×è7ö æ˜endstream -endobj -412 0 obj -468 -endobj -413 0 obj<>>>/Annots 20 0 R>>endobj -414 0 obj<>stream +451 0 obj<>>>/Annots 17 0 R>>endobj +452 0 obj<>stream +xu’OsÚ0ÅïþorJgcÇ@O%ýè$-žéY¶6µ-*Éeøö}¤”d2l¤ÕîþÞ[ýŽ>³ÓUÝÑäÓi‚bÍH>ÍPÔHâ$áNu½Z~»_âÑè­ª>èjìÕà¤kõð¦Ø†TÁ Ÿz;Kâ9“O9…’½?ò±ˆX ww‚Ñl>ãÿ”?£°>¦yœ?<£Êy(}æZ–ÖY¹#D!Né÷0\7ÎíÞN&ûý>¶ÞÀX›ÍäòlHðg©1迺¸BWØɍ¢ÎÇNI«`Ž»Z:o—>ËCƹ&”2 ºÂâIÉ 0jK·x«Œ9¼ûù +cöq›ú¼BïE»o²O,ߣ¿"çRendstream +endobj +453 0 obj +461 +endobj +454 0 obj<>>>/Annots 20 0 R>>endobj +455 0 obj<>stream xV]sÛ6|ׯ¸¦‰:cS¢>,Éov§NóÐf륏 Š¨H€À(šéïޑ´å4êԏeK{»{ þ5JiŠŸ”V3šßPVî·£ÉÆfSÚøæfµ¦mNÓd:Å'Ùø§R5Q{JúÅ):zoCTUEÊæ´Õ!Òãݯ÷w?nÿ”:颫s=O“*Ó[£nhzKµÊ)–šje©Q{º} JÓ~ßlÅ»¶çk(7!z³k£ÎéhbÙI™³QKT¹ÈÔ]´[8œ¢"h©«†ïu¤“k ð=*%Dï þ€!Lé:w€sgßF:Xt[v{Fý„˜ñ[ŠþD\­ciìž*sз]/`÷©—›täã¨û*í¿[®¹f¨wy²¦¿©v^˺Ÿ·#¦_4ïøïã»Ñl³J6´\ඦùf“Lûw=v">“¸\αì\Æ큷õ™ª˜#_«hœ%…ƒg,Ó žhwU½StÔ; &ê+¡é%.¿§1•16·“ÉñxLïHœßóÚmHCXŽ¿´\ÌñºX¯ð:Ã/N/öYN7¢Æ³a§ÞGé-Ý·¦Ê™wöÒ½±Ê›ËVr”³L¸¢ÂxÖ·Ðïö^Õ½8ËAœdcfßözLfÇ°–ì숄/½Î¢ó§„¶¨O¡tm•“j£cj3Œ \òTM|6ZÇ/d`zrö؄¦Â)D]'½=©TŸ4µ¶ ­ªˆ¬Öy`VÌ\«\J}u>ûŠ½sñû/mxÞéõµÌIW`hc1ë=ÜQ‡S‚Ötäá Î ¹†]NGk«v•Æxm¤þ ŠZîëuØjuÐÁÈ\g˜Ë¨E]o„>ØL“‰o!F›ÁëÐ‰P7¦‚Á9%²¢§ãÿ²Åˆ`I¿‹È@P¿ä0IKŒ;K(¹—Ð=Ú((¯óÒÖ Lò@mø&6‡ê «ïü+2#Õ_¯ÓP™!^dæ7'bÁ8FbWb§m02É< #©?×ú¤}àlâXï……«Í¾Œ¶ìwÉhÉyžf‡ÉëwÉ­ré¨ñR ñÏN#z¬ª‡KEћEÞÀ²Q[>½Iì²w´Sفí¢ã œ|-}qhWûx™´žªÂà²å:U¸rÂÇÇvaKélØüïhÝ,äR:OÖyŸ¬³[žYâÛÝԍóQYŒ9îî‹*·ô]ì@a$öº‹£ùZ蘕üÖ]€Š, Ä$v`ÏSî=Èé,DS·•„_Bït”dš=?_°ð†1œi:ŒŠKðDËmljÜoPÏ Ùát…圇l:Iˆ"%’¾æqÝó@¸}}˜Cn5ԄC%mºà•¦agqôƒ%)7yXŸ=¬ä~ÕSÔb=M6xãg§^ÚßGÿeìè•endstream endobj -415 0 obj +456 0 obj 1092 endobj -416 0 obj<>>>>>endobj -417 0 obj<>stream +457 0 obj<>>>>>endobj +458 0 obj<>stream xWÛnÛ8}ÏWÌö¥.Ðȗ؎`Ún[E/Û8Ø šÅ‚’(‰Dº$•Ô¿gH)vÕ¤› Žc çræÌæÛє&øžÒéŒN–”5G/7G¯7G“dµ¢ý‹-ñDŽæëe²¢ùêïOù­•TÀv÷/írµNæí öÁÎÇoÖ4Ó¦@Øåb‘,i“‡ÓÚd£i2OèÂË-œÑ++…—ä+I®I)3ºPek…WFS¡j™<Û|…Ã9M§ÑáñìîF›J"œÀͶ–u¤tð,¿GäÚ4WVfÞØ]ÿ4WÎ[•¶2¡sؔ¥tžv¦EE"g g1¡ãéI2ãèm]ïș`˜ MNJªÌ]i¶ìÎQițR…åx´µ"ó*“@Ö\vƒ“[QecIÔõáñP<ÂΖÀ9MNq¹È¯uœÂuӝiëœR‰zMƒØJ—T«Ž§ÜYtBkÆs ç‹èœº¯/emRQÿӗ Špìþ1~ß{SZÓnéwzõöóÇËOñlš}hü¥BîÞà°l¹ sÚ<–¡!FøÞtύcsÈqW©¬ê`¤è ˆ¥ÑöГtGBt§|…÷D"ËL«‘B$Œ“öVÚ瀘¡“°Bûð¢,Õ¦Dµh$Û§Ú±âI(õ šÈ^Ðê`œÐõèƒ L$5ˆã¤†€ú /D“ @@ -670,22 +738,22 @@ R Dc鳱͒ B?v  oQOréyOP¿ëà 2ê.1 mXy©¬­¦UÛ8p%—£ŠÝ1‹q7‰Õ÷;—äol+r$.:HÍ× Ý |‘sÃÀ0¸°ÆD;Ø@Õ8ù-”„oRPŒ€‰Q¹oÓrT øÀìgƏ˜»¢k]XÝ´î¢Hð”n øájUV” òßZ•ÝÔÃÊø©´òJ„\w7áYÿÆw!@Ž«Â<祌—Íw88Æi`!X Í¡¢/æ(Àª[ÛÓåiÂÿ à&~p%¿xñþå údÍWܑ0lq•„ÝÄÀÇSÇñØÿ¹ÀÏW“dÿpœ±G(֟Gÿ@FË*endstream endobj -418 0 obj +459 0 obj 1451 endobj -419 0 obj<>>>>>endobj -420 0 obj<>stream +460 0 obj<>>>>>endobj +461 0 obj<>stream x•WïOÛHýÎ_1p.U‰'! Ü'ª–;¤+å §ªR¥ÓÆ^' ¶7·»&Éovã$¸ä( ™ ïüØ7oÞLþ=Š©‹ß˜F=ê))Ž>LŽ>MŽºÑxL»‡™áŸ.{јã>рŒ¤ Gñßp÷¦ß†á \á%üoðÓ¹:§x@“ a‡c|Hýû.M’V £8¢{'t&.ðA§ÊeF¤JéÒ(ÑeönòpÔ¹P?íÞ~Z7_&Ÿ~£ÉYé<×K¶\ª<§©¤Te™4²t¤2¢µ®¨²’n®ïIþóžœÆ!댚VN¦d¥yR‰´Tˆ…8b—Ú½!nHjýH±C!€è³iu¤K:µõóL[Ñ×9씥Tf¸PÊ^Ú8Šûç—,"ºÎ¨ÔnÎÉï#7—%‰”ÏG¹É*îG=Î Fö"DŒ÷°Ùä ô¦JÛ¶µ%Õў§·wA« • “¯¥ÁéQ§J6;×UžÒ\:Ôëy~­,¼>É9ƒy^#` ç폞XœÓ[l}I7¶»}u7«=5ü€BɕL*'¦¹ÄÒêæM&'óCïW¡?ÀÁåÚlzß@ß„õîYõp[šÀ“¦kíÑ h␍—ν–¬‹–\“D~ù îǛGQŒÕ~¶žûËÏ.éÖèh*}ԉW 1ð­Ž·G=|Hßô `0îFçø³>§€~ùëè?åÆendstream endobj -421 0 obj +462 0 obj 1365 endobj -422 0 obj<>>>>>endobj -423 0 obj<>stream +463 0 obj<>>>>>endobj +464 0 obj<>stream x­V]OëF}çWL¥V q’‡J÷SºÒ½Ð6iQÕôaco’%ö®ïîÈ¿¿gvíKH€>´ ÀÁö̙3çÌìדõñ= qJç#Êʓ·ó“ÞÇ! 4_áÎh2¦yNý¤ßïÓ<ëÌ mUQòä¤ÎIďN­µ(ÈòI•5™tN::ß"ÜE®Cº\æñmŠ „9xÎ?–ð#}ꦣdD«ëù‡)}ZÑÎÔT;Ïþü}HÎï IJ3ĝó²ä[šÂƒ¥ØQ¡¶xÚPa̖„ç»1=xhªîΓ”³ÈQV…t=wg‡]ç…õuuX€Ë¬ªÇP)z&Ê¥ Ò+AŽ$Ôða~6it>JF4œŒqâÇJZEò/i€ ùý4™<¡ŒšyYÑhJsËÅ8¯ô:Tï6‚sq'T!–àÀh.ÚZeï¤=ª2åÞv~lØ´]ûY¡¤öÔýÜÜ;oã¼eC[ÛɽæüÅYÝÆÔENkéi)2PÀ’YáÎ1Ј4MÚ¾æFÿ¤É™Rú —ªˆÍŒµ2óÅ®‘EÛ0'Ñ „èÊx–Dh/^àwMN™Ð$ @@ -693,11 +761,11 @@ gh)Y39 ±ôYè/B‹5.#;î õ¢ãêlCÂÑÍêf½8=Tl£Õlc äŠô– y' Èj«ü.ê”õÌ2])ø"–eå×Z:S%œ»76G+¸ÐÚ=»’ÕÀQÅÊÀÊ µâö3v‹%E…´ í‡F®5¤i,åÒCX.¡E‡12ñÿ,¤g?5É["ï8¯ý¸‡íyÞª×T^A°Ý?~jÇHfJÈX˄æô1T© Ê5vKøè7¤îF†¢zÜâ”ëh|6¼¸ÄÀxÝgÃô^ÜsƒdÒøl}–­¡7’2‹µV"q{ä_­ßxôU¯ÇVmÕ\‹Ê^¶Ø|W©LEPMÓдué~¨ÃžÞWÂ\»˜ÉלNÐ÷WiŒ»¢€Ib„Ç!þÜtF{ZY}Gñ| ˜#b\´¦zFê ©7âNBnp²+½'ٖá0$èÉê°º•*X+˜ŒÌAtY(RÅMq[£È_ÐßÌ÷û/H©b¸6ËÄòzü#|Òì Šeȅ€—X*¬¼€¯0kÔۀ»+‹‚™üØ$¿«äôR»_™Û½^ÈÓ ñ8@c†t’b¯½n†t8 öqç’ËÆ “#3¬¬)áð÷׳³0öð[éˇðçj~Fü1ݞ1fsöYçzÖKÏHú,I’'jGœ¸“¥©up^®ÜóG®_&åÝt±¸ùtõþúf¶XüÒH÷ûfÓØE|Vȧ´ÀWœ,xÍú‹tïãhŒ¤²Xé˜ÿ†¢òƒ)㨌)ž˜Omë_¯2 Äþ(dPþ‹½“…\ZáåA¶á8‡i hY¯q©Œõ?ìig„™ø¬t&ÍÔŒÆ $qNÜ;0ÎÞ|yû†~µæ.£÷&«Kœ,ŽƒCüV7¾ÖùÏç›á¤Ÿ\â܊sÍ°ÿÛÉ7ã7endstream endobj -424 0 obj +465 0 obj 1189 endobj -425 0 obj<>>>>>endobj -426 0 obj<>stream +466 0 obj<>>>>>endobj +467 0 obj<>stream xWÙnã8|ÏW4ò²`+¶ã\ƒ=à\‰'3öÂX /´DٜP¤G¤âø﷚”r(³‚ŠE²««««é{êãg@§C::¡´Ø»˜ïޜÓ`DóoNÎðQ?é÷û4O;ƒdÐOh±ž&9Í×ʬ]Y󋧅-ÿ8˜Çþ qoxŠý¬5ÖójÚb™#a2Úيœ¥'o‰_>Òþvmi[Z/‰?q´QZ’Íɗ­÷ñ™44!W­VÒùpBfqˆÜАÄJ(CœÍ0úÔ%CÞ<WZ‡M©Ðevk’zåð$áD;sÀÀ µZ{*¥È8(åŒãj2þ<ý2›ÌÿìC üŠnÆ_fƒ·‰R‡q¾J#`_îÂ!…Pš)Ð @@ -710,32 +778,32 @@ i ™¤ÖäïsÂڕ/"GÁG=[+øÁ†–<û¸ÄLë“À?…ønKåw/ßÎdbÈêL–³vð½`³q†°haúÑ@r[Վf$Ï €e̔2™±V…ŠÊ”Y÷¶¥æ Á ÑÂ:®XVpm™A‘!=c·Øë¦â£ÄŠpcŠ:Ûxaޛ¦œŠ5z׊[JÌZÝ ²'´®XÁ»0þš"¯@Í,†)a—.­`Ñèwv÷E¾X¡ÄÒÉò æ˜NXÀ!áz*kÏÑ0¯Q°F»]FòyNA}£AªŸ†¸„jc€@Á˜¢wC¯¿„a€Èm2¤ÓJõ/ºÄI¤œ+³öÆsö›SÀ/:î·ýÆz4äⵕÂrdòÞ0‡œ[Âü5¢g I[v\’Œ(ÃVùu#8˜Ãœ•«O¯–ÖnÄEíÕÓ9êTþ=?ækNps=›Éxh:ꡃU€k*Á¤¡ÊŒ¦`Æê»R;½)hþÚ³›RÁÚT²âⳏ4TrS„ÿªÉè¶ÑÖç—÷‡“{By¹ ›1Õ¿U©¨€ «„n€1 ›ŠwG-y„O¥_ÊJµÏå[ZbO¸VBf?nM+räv¸#ðκéXÙU!–è7µ¾¬VªÃ›³úv089Mø.ð³ñÝŘ-ü;<þ7W(Ž×‹‹{§C|KÈþ×·„ÑY?9Ç7 ,?æ#p›øº÷7¾8ñ5endstream endobj -427 0 obj +468 0 obj 1513 endobj -428 0 obj<>>>>>endobj -429 0 obj<>stream +469 0 obj<>>>>>endobj +470 0 obj<>stream x•W]oÛ6}ϯ¸ðËR Ñl'q҇>8‰‹Kâ,v·Pб‘H•¤âêßï\Rr\µ0‹¼çž{îÕ׃ ñoBçS:™QZ\®ëƒq2¦ÙÅÛä”N/Îñ<Å+)ç׿¾K“SZç¸8;;Kf´ÎÆcZ§‡“d2NNº·J{¥Ÿ(·¦¢wþ&oHÐU©¤ötõfý¦Ni2‰¦Ž§ç0t¸6Ô8‰ƒ5–|!<)GâE¨RlJI/Jཫ6ÇádFä¤}ÁÉàIP£Õ7*ŒóԚ†¶ª,IKƒûÔTµ‚_Hv?¦ãÉI2e·°–ÆÈjkž¬¨ú„Û8¨w·•v^À~$—ZU{¢.†HG =H/xÉm“ze4ž9Òp„rc©2vè;“©¹„º˜¦3àÎP˜sê¥cèVŸV’ó-èÜl2#UMZPŒLTœ CŸ"Z$ÞûO\ë^úàƒ†Kíö#u »ïj6;CÅÿ»ög'“€Ý ög ݘôþÿ¥ÂKòZ)h[(íL%½ªC*PyGޚ†ËŒÄËh(D†b} lßòm[&ïOwvûšo$Q--°¯€Å¦e o/;Î$)Wl¿‘•©±Yoi4 I  š-ŠBaÀ+Ž?X¡Ÿ$G²i=BBé™ ÊAº„‚/:cg̔Q&u Ndҍð˜ÎY¹Z¦*W2ûÁ?l‰`ØÛb³ÕÍÑÔµ±þnjÐ\Ì ö§Ú—‡obǀ^VHðÀ>»È=|ªª.e…¾‚Ñ€­ÓpÒ B =Ž— C’¡‰M*#²ÖìÁ¾;g!c³C@@)¾Hè£FÁ|£…—%@‰vf>wÑ î8TBZÚ4OOíÕÂz•6¥°0µåŽ®Dî4Œ(ŸùÇ]¸4Ä ‹ßtf,Ú $´ñ¿†žTȈûšx0ˆ®–g=èi®W ½Ð®D]qN¦´Q> Êûµ‘Õ|’ZZ@x|Õ1è:™„ ýÑA¨p‘; bqd™”Èî'Hò¨ëR¥ ‡è1üU?ZÞ,¦ß½fA±™ó±†œØ*_|¼©CNB9…CV¢. ˆxò%rWxð°F¶;L˜4¦çtP9øÛµý~¨G$ô°k¸2û¦ xì/ ÌB¾6 ±»&e®æM9,ÚÊ[•z$¿/ä Ӕ¥…Dó3˜òöð .È@Aè\Æ1ÑÖ²Ɛ{ 6ñ|jP¸@«­h÷ºuk,Ü@áY15Çï HÁI…ƒH jf¹ë¾çdOä8MÊ@Q¶´ä܅mþU”9ôp&º@NéLB aŒM%že/œQz(¾Þ£€Õ-ç¤^5[ Iƒ¦†¬ ð„Dª„.[Êd.šì‰T1ºs¼çÐåòsX…¹ç¾Ü\ŘÒ­óž0H›:Š(û.§wÔF•fAôq±xÍ:ò€Û—k áÔ?eÀCž· .c¨J¦\ØpУq–t0,.¥ ZØ ð¨õʄå£l´"ÜI*š¢nÌ1Ô¯Ìè_ü®­z{ r|(}¥Áhjq£çPÊAœÑlçŠ9Æ bË:ˆ)"»Ô™ïç«õçÕoó‡ÅçÛåõb°ê~/ç÷· m(5 8VRDFfú£¥ÊØIßè0>>>>>endobj -432 0 obj<>stream +472 0 obj<>>>>>endobj +473 0 obj<>stream x“_o›0Åßó)Žò”J‹!ä±íÖ©Õ:…½õÅ5—âlf;Yûíw ÍÖE[U!,[Ü?¾¿sø1I‘ð“¢X Ë¡ºÉE9ùxµAºDYó—|͛ ‰H’¥š¥"MD.p#û^›|÷äŒìȟ•œ¸DšŽ‰óEÁ‰³ëÏvF•®krdöÇ,XƒÐn/=¤©0öF?#äâ™#äŽ ÑZ»ƒ CÌôXì§±y‚yš‰Eljû ­À–hˆöݽPÖÔlÐËBm* R·^ÄìÏå„gDže¼.ׯ ~Gž"Ym6C›(…ÀW¾­Ãe#Tw[ ïáÒ;{ßRçKDZë–¤ø©C©##f£Ž…=ô€­ÃݬÕÌ&"üBŽ§û€+&¬Xwe«°6ò ™ÁŸZ :ø»³ô5¬l×uÄZDÝþB~­®†L?FÈñ&¿éFeëíIçÈ7”Šóx°j%g=É®oɳ]ø2Áºç×­²ÕZ¿X/Í ýÌv}åÛíùÍÅ9n}äšød՞g 2ú$Þv>fÍÇ´·]¾\'bÿ­x±Î·É/ŠçûŒendstream endobj -433 0 obj +474 0 obj 451 endobj -434 0 obj<>>>>>endobj -435 0 obj<>stream +475 0 obj<>>>>>endobj +476 0 obj<>stream x•WMoÛ8½çW ri 8ŽíæÃ9-Џìئݍ‹v\hŠ¶¸‘H•¤âúßï’’l¥—EÛ ‘HÎÌ{oÞP?Næ4ß9Ý,èÍ5Éúäíêäâî–3ZmðæúfI«‚fÓÙ OäÙ»R4A9ZLéOa> CÂt¿¢/Âûu}0Ò훠­y½ú÷dFç‹Kœp¦ =ˆz-°ó'¿à s¼á çoæÓ/ZLçSúh‚³E+»#.î.i>Ï+7¼î›%…RQ¡žUe›Z™@v“S[$Èi}Ó¦°;Ï鑴u#‚^WŠš.UÕ§JëR~ҁ´Ï¹ÏߤČݑà½,=‹J"(j=IkŒŠÉzB‘꧐¡ÚÇ켨íĞ„'‡Ù!ÚAr8æY¹i‡×õ4"¶*µ§ÂÊ6VW(/^+O%ráÚ>½ýe)$ª­u@¨&òä#»RpY¾ÅØì üÓG]²´Ök³¥]©xÑÞ¶(ð¢pÔ t¦ôžùÒ¶UAN‰‚“8nÓVÕ~BÊ7Jjÿ-äÙžmy%[d@ÀލP>ýò÷ç‡øîÝçû‡S^Î"ˆÀ|X@„t5¿ÅÏËå ~.ðEl:Ívrº\^EÖÕ.¦ÐëÀ­°¨é20¿%¾WÒuс@À…·µŠ8z]ëJ8†äëýÇïô+¦´Bí‰Y4ÐFCAÐKÚäQõ‚¨¾T ¬U¬g%öÊ÷¦„c‘ þJ@°x ­‰'æ,¢Íšä bõ3ô['à¨Ñڍë0Ç' @@ -747,11 +815,11 @@ dhh +e…0@D4ŒZ‚}ÔC µ“cì: ØM;µ¶Ï‘Ý„Z9ºÍՁßLН#ÞB锂Ç»Jo+˜M¶€Néý9a nÃÐôÈdj2 ‡nƒ; ;bbgûf´Aså¼l‘Ç{–Oq &xœne¯BÛ|*Â5Gßsx¦ñɜxUa<ª-NbÞù˜Júí¾Äde8: ‡œ6‰guvésD‡¼œ̴㖥›Ñ¡!©»¡ÑGáqëû.¦’T™f,d[aôÀÒ¢ô¬Á(4´¶˜1Q8CGV×Yq”y\Ö%özQ{_D×Aÿ mõslN]õIŽcæV¨ö°X.ßpÏuöÊp¼¨fýóù¸~ Œ”ÜÉý°ç]]¤áÖúx¯]ƒà]¼îâ×øxK>#_¯ãÚ8ä†ëóYº€œt€V bKâ“é …€©Ü ùsÀQ^½©´F‚EFO58VI\D¹Ñ<úR'þŽPN—ÈÄ=l¢›’0ŽÖb÷tâh´z—aö1sc`̏ì31JweÂO¶š•ýdTºjcŒ8‡në§jšD/ëíeŽ2í›×X­ñݲËÈ£·BÙòÆ3ô—Nø6˜Åáe^….øEGO¼ó¡£øR(£‡ãùýÅÝrø¶º¼åo«wÿ㠏?xR'䯺Ëålz‹/:œ³äóqkÿëä?=·wendstream endobj -436 0 obj +477 0 obj 1599 endobj -437 0 obj<>>>>>endobj -438 0 obj<>stream +478 0 obj<>>>>>endobj +479 0 obj<>stream x­WÛnÛF}÷W ò°h]]úRعyˆÓF*Œ¢éÊ\Š“»ÌîÒ²þ¾gvI]·Ð"Ž`‹äÎ̙3g¿]Œi„cšOh:£´º¸]_\½¿¦ñ˜Ö9®ÌsZg4JF£­ÓÁñ’|!<>$­Dµä¤}”–´äÏmvŽŒ%獕.ܖ–RX/Ÿ<‘ÉÃ7 žyé¨ÎíŒÍhH_ÏÏh³÷òÕúëň†ãi2AƒB¸Bfô(ʇfÒªGü™[S)ŸÐMé é³äŽQaV{<HÂÊX@/®·B»Jyh†ëã²µôÈúYû¢q¤tj¥pJoEÚXå÷ ón}Ühv½Lt½˜ã÷ þ#Ra^Òøº…iÂüh/0‹2_:dËOI]‹¤¡xØs—­Ôbã`1íᎴÙãÌèäñ@ôzëØgqûXÕÑø匿¾OÀA¸ÊHœ †@ÏvmºLøµë¨ªíÛt‚û¢äñlžð;3kò‘𫛏·7ô«5_Q½m—VØçlñ©a|lðƒ¯x׋Q²Œâ¿äSâoêþuendstream endobj -439 0 obj +480 0 obj 1780 endobj -440 0 obj<>>>>>endobj -441 0 obj<>stream +481 0 obj<>>>>>endobj +482 0 obj<>stream x­WÛn7}÷WÌCˀu—%Ç(Ømp‚VZQ¨]Jb¼KnI®”úñ=ýHZÛuz‘CZ’3gfÎÎþq2¤þ†4ÑxJQzr3?ùi~2è]^ÒþŸ]ã¶M½ M.gø>÷¦d%­øa¦ù‡íýwo°æ+XŸ^âKÖ4:£Þ¸7êÑu¼ڋµtdV¤îJÙ"ó2¦L8·36vgó/'ýwÙ vG3ëd‰Pš¼üê÷{I6že扌¦X¹Ç•6¢ÊFwÖChlc1šÎªÅÚ¯u‡€Çë¹4'RÙ¸ •J$ öi)×ê+‘“v«"ޚG^LÌ؄Žiå³í½0y(³f)–IA"±RÄåNéu…`ï|Ñ©Ý{™hékÿ‹3Úm€9 @ik‚ 9ìÃ6[„†øVÎəp’]âYJ+céþý )§O‘äÒ)-՚b)’g“]ç³Éw x1˜‚C%F TͦCî\ÌF(É1{&¥—Î]º \A®Qšc¶ ¦’,·šÀ%DÀ‹t)ÈÄo½ŠT&¼$欉%‚'dܛÈ$DÊSš;OK^Båq*1æ‘ò,lNiYàôF¸ H»I.ÛÙ\«­P5ø× Sè£ŸkxNŠs¦ ;ÿøáö¡)Ji YFÙQ6Kډ"ø"Zå:ò _t,§j;VifœSl+½UÁ±§(‘ˆ{ÇÜ©£½÷uƒŠä½Ê/΀Œ@ò8ouŸ6Ù?àQdÐÝJ—ÌA u¶Bšš¼r¯öhn(ÅÖT¹~€Ní”ßãÃC¿ã‚•¢œ¹sZKïC+äž àP]¡£ó}^Kf@‚Žt¨/}Ô/™sLšNhŽ¼u¤aZ{?Ä^%Ê£ åŽ‹ÚYú؜í¹Mëø9׌۪ò†—"YK-C¦9ëG\§•5)žڔF›ðþ&:F[ö·Çz¥CúGúsž G¶“?ÕR-¤R*A¬Pƒ•I³ãbE&MY¯Ž!€ù®25¬ó X/ú“Ž3Jô–ú¹³ýÄD"éC±—¢ŸYµCûM(Çy?ðw»¢Zkm®_ÑXHwá<Ïoà>\nïÏùÛ·#/2Æ^ Ôÿ {ÞPôۈÆ$[[‘2ßV&G z¡8÷AêI\™VFÞØ¢G74}%ò×À3¬x¢8ÇÀa˜}¹¸ÿ¡N°Ù¡jÕ:®CçEÓǕïìC$·1y³¼;ܘPwk ‚e~rÀ™´P$m‹+Í­Žœ\`ZtJM]¢Mjb⥗0¶ .Ξ´èz”;Èãó¥ÐòQb.yÿ4HFÉéC¸Eˆó¹0yhzZ×v–S„òR˜¼öBÓuGzÐ|\T\†)Ú¤º‹š³¥‚€­‹pÓ' @@ -777,11 +845,11 @@ c «s(OÿÝeU‰átÖâ­sÌ]uýþæš~¶æ @?š(O! ‚‡g6Ö-7wg£ðJøO_M'³Iý69°=¼Úürò T©wendstream endobj -442 0 obj +483 0 obj 1546 endobj -443 0 obj<>>>>>endobj -444 0 obj<>stream +484 0 obj<>>>>>endobj +485 0 obj<>stream x}W]O;}çWŒª+‘JÉ惐„H÷Z*Ú{IÕJ¥ή“¸ìÚ©í%Í¿¿gìÝMXè ¶Ç3gΜÿ:ÒßCšŽèlBiqrµ8¹^œ ’ÙŒ¿ìÿ è||–Œh<›&S’YI+>E˜i~a{ÿfLÃ!-V°>™Mi‘…õ-ÒÎ׍Ôä7’¶Â¹±­T.I9J­^f$òœJ'­£x:Ú'µ·J:¢Ôh§œWzMfEg#:ývJéFX‘zKèjO™\‰2÷o?OԲ달ã7¸'SW˜#¡÷$ÒT:^a•oN(x)Â?ð;î:é»!€ç·²z-‰¼a—„K•jݾ‘¿E&SUˆN¬•wôÐô.ºtÙ»yx›Ðb#$`…Ž(o->Õ^xe4Ìà '´Ü{ɾmٓÈKÉkÑåS׺¹Æ:©>M’1ã±0„pªSìy@\›C´m<œHMQHÉìám—d¦|p#¤(q*žTngìp.RY­[çA…–;‡\ÑNùMØ#/{âÝý3P¨Coî>ÑçËûû¯Ÿþ}ÿ&.ÖüêÁB钓'éWi¼t@²捱ì‹m.‘:Ci.… 'j`h…-œzZše—˜®X†ÕŠ ÄôÛÓΔyF¹1”«GIóÚÙ ¦ûz£ó-U_°7ó£¾½ö5íÃãÏæß¿Ô6‰~Ì?¾[ôÕ×üÊ,O­JTŽ…œ÷qëÆT€!yþ¶=ãºì|XÑޔ‘s\œÉX|À ”P0 8ÉXdâðª²dvºaŒëƒ…VBƒ&†ÖêIV© 1^q„ )­¼B]a»¨aCL¾ÀI˜AT¢•OÊ åMòv¬)¡þØ}ln‘–»Ö½Í‘WxÐԗÍp ³a© 0F0Å"Žç 7hž܁—fmEAE‰ X¢¢—P9؃xi™¾¦àókÖ³¶áLÈBôJøHÚPEGe›ÐµŽ²ß Y°A¹Ò oë@ ‘µ&hfQ“£¿i/ƒœ‹z³9bMß×¹YŠüH‘ËÐIð*jüCÔ_x´Û Í §XH¼K¥Vî/ä&¡ÏV®¤E<ûn+œœMƒ“e©"®¨Å¿‰‚q_ʵÒAnºL0Îî1¿x œIb̀p° IxBCˆI˜4]­àŠCó*q*-ØDG· ‚€è°ZK ¥Ðy®Ø}B—zo“Åª`k#)ÚÁC',KmÊõ¦ã6»\fè>hW¾Ì¤&‡ÒZ ðƒÙÖýírBã®Óô`¿A]Ëè²¥ ƒÜŽ‹ÎÕººÔêw[°ûÒ§ý¨·—pO3Œ:_`’à¡b@#üÔ3Eÿ悆hQG8'ÀáLa0ðÆî_¶ÜP † Óª:7L.’ál;œàv-‘уº¸:·_ît÷iAtuMîî—?^¿o»‰öS*L‚…EÖjß¿©ñ:üšÔµÍ¤&“(|>ÆÀèÆ- šQÇ @õDz„"¶%S¾ïÐß «\W*Cgªxvy­¨¼e‹Â>:ΕÀX¢`©ëUÏ ”5Á>°5ÅÈÈ¡†2C'®&O^à¾úÇéE‡N²ùŠ‹‘ðx U±·Ô¥ÔrÅ{zœ·• sr(X<Ñk‚&ÀŒ½6˜ 2˃A“™Òó6ŒÈ ÃZ¨¹ßsÇ(­ò{fÔ·íéUæ¨!Íoƒ¤btZ qo õ¨gŠ‡ÑdÚª^~éu›œFLÅV,UÎqÉVÐ֊úÂW¥3~=Ü-* å1>ÂhŒ/!¡|EïˆaB Xù«Á¸ÕñT_ëŒ}¶x ªÞ›Piïp‹[…&Li͘\q(nn_iÐô?~[Ä ŸWóó¸Z©{£^L½s~çÅw3ÿw U7„8üä1Çï·ÍdQ‹ÎÑdñWåÄ°žž{Ñ9¤2LüÃÉ4Òd2KXø;÷—·W—@Çü„Ø à´ÄK$>‡BÜq{o:Âû2ëüwOLj(lŒ¯ô¡Nþ¤§endstream endobj -445 0 obj +486 0 obj 1752 endobj -446 0 obj<>>>/Annots 22 0 R>>endobj -447 0 obj<>stream +487 0 obj<>>>/Annots 22 0 R>>endobj +488 0 obj<>stream xVaoÛ6ýî_qU V,Ùqœ¢ Ð`ÍP`ɺƬû@K´ÍF"5’Šë¿w%;n²CÃywïÞ½»ËߣŒ&øÉè2§éœŠzt³ßâMFË5Næ‹KZ–4I'“ -‹äת¤‡»j„s;cË·ôfù Y´HÞù}#Éàړ¨ZI[i%‰Œ¥­òd¥o­&µ&Nv‘6ìcBãlšæˆ–°uàºó@4ÎçéŒoÝË]€òùß¡h\ P®#Ô\}‘žþÛ£•ãßà4úœ „ ð>…˜(ä\=ÕÂ[ϊÖZ©}¤ÊyceIkP…Sài´gÌßõ;CCXG%ž_RÛS™ß3¶ÔÁ| ”vªª‚í ¶Bod™FãžZ`WúÉ<ÍjOBC©´°û‰PÇàÄè §Uev!Ãr½¢Þ.”oÍNӃ¨Wb€ñBHÛjÇÉZƒÜ‚?W¯‚JІ3ñ(žÆ+£EE$즭Áá¹Fj½Wzs@£E-i·5N²TN(ê%F{Ó"!‡šŠàS¢{ãÁ:×aÇ$2:ˆ5 ;€ŠÚXS7¾+*Vleñp@̯Š²äµ®£‘±‡â¤Èr3!ŽÓ¡­x’üjc¼ï ¬ìávàöüöâGQÀÒùm/ۄPªR:µÑ(9‚£µ!€ ‚|= ®¨U¥diè÷ûO„Bu¸€0Øtî{IWÁӘÆ>¿v4öÍË&…©k p§ê¹å5ºIx¡*èNÓùv@W¼°ŽŸkš‚<Ë "Œú€Ün¨G~Šm‰˜CGÓmLþ`¾Á’‰%“ÂV h#g¥)ÂöàYÊàÇöH—qœtue÷uÆWù/òtÁº>, ^(FØñ ŠäF`amÚϊ|zÁã…Y±ˆ#<›3¬ËœûçðÏØÇ»›ôٚoȎ~Š¹Öf—L°wfÉÿŸ-³Ë2ìz75þmôÌO+endstream endobj -448 0 obj +489 0 obj 1146 endobj -449 0 obj<>>>/Annots 29 0 R>>endobj -450 0 obj<>stream +490 0 obj<>>>/Annots 29 0 R>>endobj +491 0 obj<>stream x¥WÛnÛF}÷W Ї*€D‹º;@ ØIÕä!(Z«ŠªKr%nBrU.)Eß3C.))M‹ à˜ÜÙ¹ž93üë.¤1þ…´œÐtAq~÷´¹ûqs7V+ê•{<Œi2›3š­–øûa…?KM;¾C¨é~Aü~ý@“1mvоX®h“È9Þăש:Tº¤i@o­«L±'EïM\Zgw½1®*MTW:¡µÉô‹ÍÇ»1&3(<Ÿ]¥sªJ­Éô¬òH±Û !ÁöFÓ0˜°ð4zW@]WÆ®‘œQ¶’“%ËmRý…Uj-m¶¤7;·}A‡ÒM¢¼Íµ*Ù‘ÓU* ¢‚šÌîM¬2:}âóÀ…"¡Ä”:®li´¸7Ãiãf•ªŠj§KÇêÒÒ"B(SqUC×!=;QšÙ–k†€Ó¨€³uòÁw¨ÐÕɖŸxE*ËìÉÑ!¤fŸê²Í¥·¬ŽÊd*2™©ÎCr¹µPQ’ƒ›j¯I> LS E*SEÌÓUÐzs ˜&rñTdkqç†pnm•e«*’¡òëOŒšÏçHCN³E¶=ß]<æ¨WÌ/¯ 'Ê¡XHF{¨õ¨Jl\纨ÄIICW. jó3YÜ ãÈßätdÊ û©=!*üçbµÃ£¢ß ó™(Wqj @@ -814,113 +882,118 @@ P ¡ÆèšO¤ïœKØæÆ2va]2›hv,v™ÉM³‚Jðсõœ“ª#,þ® u´&Ÿ%H°GÏ °gå‘ÁD–,áÒ½pE ó¦%›U nd~Ú²Í7~ùoOjâ7[ÎÀMø¨Já”_`ëøåîoL½!rendstream endobj -451 0 obj +492 0 obj 1534 endobj -452 0 obj<>>>>>endobj -453 0 obj<>stream +493 0 obj<>>>>>endobj +494 0 obj<>stream xuT]oÚ0}çWœ·Q©dX€Çv]ß6mÓ^x1¶iÜ;³¢üû'¡ÕPG„ž>÷|\ÿ™ä˜óɱ^`Y@V“ûÝäãã yŽÝ‘+ÅfÂ<›ÏçØÉ飱âtêtDS#–¡«îd$NƾD‡ÚÓKZ†Õ±uþ¡^t®A+l¼…° ! ñST‘Ýìž'sÌE¶"æôWÐ>ÀY<ÃL´,†<mc€Öµ8x×ÝÃp¢×ÄcEÂíÏdŸþ¬=DĞ¿pö{u î¤Ô!û„¡ñ=_f‹„žÈ8ß/°Ÿ¶¥‘%D]kÁó”ñZFç 9T‡öö7@/üÜô †ÔlÜÅ#¼«½‘Ú š -_u0êÖËòe7¡(Kj³Ú¬ù¾àŸ’ǶÈ)ZrìÓf›ÿx¶Ìr>øæ¢ ãÍ_Z>[$ƒ§¿UÔòUa«µJ 4AŽ¥ 0GÔ^Ÿk U®±iÁ:;£¦˜€J(Í­é<‹©ã¹³‘t&:A”éR+ºTMXæÇ;ÕpHjÇ£Sb*J ÃxÑãÎÏ0ð’cngëlƒ‹“ûE±×/¹N˯9ûÜxÏT%ƒJíõ‡@L5z#£éazªÐ“aÖS0`EEC隓"étr­öRýn7œ5ý_+—V™· eãMìP7¾vA‡Ûê·싱e“ƒ¾Çþýá2cg¥8k¸ÖRçÒÔ¬´êʇZûÊp œ%ÎtHCK¾ÎR¥ƒy²Ì©£œæŽ®+sìź}3LÞe2ºw…¸p}ÕbÌöj»e¢ßË6­ìo£¼Xgé¦JR¾ÝH?ï¾Þßá»wÏG<8ÙTtS$ë×ÙP5ʦ׳°Z¯˜…Þœ|•ö³›“¿¦endstream endobj -454 0 obj +495 0 obj 686 endobj -455 0 obj<>>>/Annots 35 0 R>>endobj -456 0 obj<>stream -x•WÛnÛF}÷WL€Q›2%Y—}pœ8ua;n¤"(ª<¬È•µ)Ée¸¤÷ë{f/”,ËM“4).gfϜ93ûí(¦SüiÔ£þ’üèíìèýìè4i{©îñpJ½.ƒñ×>?W’–üîa¥½`u÷rB½Sš-a|8Ó,µïñKÒ¹X‰²– "º«TQ«âž¦MYêª&UÐTä A½¨}=ûzĖ⁳tҏ£luQÑUQW:m’Zé­Pû•½¯{+ïUQ°ƒªWT¯¤5̑gRyì½çސ]RˆZ­%}VEª7†ngT†8s™¬D¡LnHåe&sYÔ2eï§t÷]tk%ˆn¦'Ÿî.hÞQ‘Œ¬ÙéÝǏ×Ó)"—)•ª”ó×¹Vº1´–•ÁV é%ù¸t‘=ß\‹âFm4{n‘e&ò?ö†@K;3lY¤©bDF˦°x‰LÕ0¤×*…áŃ۸ÜÀ³Ó»EJ’¬I¥yÖÁ‘“`:äl©+PE¦EÊP[°ß´ŠÑReÒP­[@'gÝɸ{;ëöNÁ›$SÑPSê‚R™‹"ˆ}u/ŸÏ“Q6òvæ½áÈ¿ Éæw-ô”! -€ø8Œ¼0Ú@Ùó4u,D¤ŸÕ?¢J‘²ó»ÏóׄmÙÕW¹5Ä[ÐYsp¶Fëc¦þ§G£AtFg–9è?Žúþ)£)× Ð;‹–$Ûr˜w*¹„wdsז‘µŠZê¬êº|Óí‚pLCÝT‰ì÷2*\8Ûâ³wü“댁¤Ï!y(» ƒ/ -Ok '›,ëÀÑdEÂдUýN'w©¬Žé}Ñä¿é…™#žc’uEàü¼3•Èìz,ãÁ|Œ‡H& N¢Ø?m¡cáy¬$7Ów· ^Òp¢hA QÿÅܤE”«¤ÒF/ë(Ñy÷1ì-€ÄÄÎ5DN¸Íø`8 ýÞs•x~wþ?€ûøýI4dšï–“4I¤1t¡Yñ2ºVõš^\à !"›pH/¾Êï¸þ_åÃT×kB(~† ÿÖÈFêS•MæÀ•n6F²tA lîYnRQ‹tÖX,M‰z¢–_õ‚!| ø'¤uåGƒW“ëHܛBCÚmýÉ©•ÂmÅᛈÁ\ªû¦²q.‡ûíãóù§Û«Û/^¼p ‚ät‹¶ë\¤#YXÃE"ȬbsÊÿ—ôåTÂl¥Œý6°—>R‹¿eAËJçNˆÂwРj­II%ÚËwhV“ï­ nVø(ä\Ðםõ{NÃjö†D"ۈC+ŽkObجJßwƒÍ‹ôĶ-áHË¢[hD!ŒÙhÈ+Z<þXÁÛsHBð $ô–'½íW½‘ˆñØ¢£ -ô8P®mË^² «RË?ÆBTè¾<}¸\¸¼ö|â;{ž3ìÐc›}HõÂ*×N²Àþ”KÁºË7¨ìbµ)e¢–®É£¶Í³”ømº6 ”t¢lVýÈEóa!mç…Æ'Õp?µ+·åífÚ!¡çR¸ù#•K -êr€{¨0r¼©…‹šoyÙ^L®­G m¼ætàñ‚]ýw.ìñ$öÎcâúZH¶“Ê%è0Ä0\è&KAš|Ú ýñ8ˆ 9 úgÑÈ?ù†ƒi7ïµj›cð·Àœ¤ -Scà²ü0ÈÌå³Íà¡ñÓ&=è&ÄÓv}†˜7†¨vã@ThƒÃ½¨žLa#û±Þ¨{§mH’ù¬s‚^²óg§¤jÖ¥ÐZm½äƓKn<<$¹Ù/X°8GN_~yœP”“›Û¯¶Ѷ"†©y~¼ós汅8oL ÂT¸&^ç1[ -ùÒܕb1DZSÌ3ø²4G?³H¸z$Ðñ6YÛÃYåÎ<ì áA`]1¸¯±úôÀš„Í@­ÌÄ¼$¼â y%ßsoyQoU:AìzVeԜ¯ÛŸÝVFï ˜½‹0ü¹%b®Ó MNô±!“/0K¼¹Vcc†–²¨rY³< ó°J0™ò©ÊhH„Ån_ÚÒ§µÈ £ã«RÔ«W¶ŽEµPu%€ÜNýBn*Yf"ôVE  MKo̪Æ`י;íҏӎ“.]„ýBÝÆT]–ê¬kø@Úõ"h{t÷rN&0¥?w®à°à5ñ'õõûÑ¿Ò+ºáendstream -endobj -457 0 obj -1716 -endobj -458 0 obj<>>>/Annots 48 0 R>>endobj -459 0 obj<>stream -xXmoÛ8þž_1W°.P;–,Ëöú!mÓ½×ԛx±{Ø´D[j%ÑKJq ܏¿g(R’m8'pLSœ7ÎóÌLþ¸ -hŠŸ€!ÍbJÊ«w›«ÛÍÕt²\Rÿ¦÷XL)\-&!EË>Ç1Þ´¤žÅj>›Än'Š&Q»Y؄‚î ‚®?NiE›”ÆP²Iíö”6ɈðÚ7ÒÔ¤¾Ò[:IózóåjJã¦àIûÀV«£‘b[Èï>¢¥HIUÅé»Ou^K*r¨zKU-Ò2¯X—uÝ[°Ù?]«ÉŠâp ·Jš¯&s·(è‘Ãuý1¢ `‡p…§†>m2INòàhIËy'ÔÉé£dÛP…N²3áRxï† Tf+Ê -ð¦(7Ô™R­H…:’uТΟ%Q!ŸeÁÏhI¢šª6üp&°Ù*Â×ÒÊ+R:ÅcØm©¨¥s0§“ÅÁYRR°ˆÙE»ò.bcs ]^HC¸.ª*“ -'DRÚµ—<É«%²­—<\—"X³ÁîYúÐzS/­1åv’¨j÷4š?½¦RTt{ë_=>º#Ú)M¥ -ò -Knà—XD¾ot^í‰lý2çÎ*€…óåY o‚%Rª]uqš/W6å{pp"iùG“kYʪ¶º}t o"î½¼á»Qp¾;Xcw#²ýÙ?ÝõǹKKçÇ¥©‚áS3•Y¥ÈÏb—!5OªÑd¢ÈZK™"/îv6C ó¢ ­_-ªZÚÌæxŒ­Qã`fóldӗp.§}¢=Šr+ ÌÔo8Ñ8û  ¿‚*Usci¯«÷9c‹ïÑMSgJÿ`è^ÕòG‹ðžF|WZg¢¦|ÇÈkû5¯RðÝoœ?Hûs_à»Ãìç\Љ›Ï .¥íɤõ } ŸF¦I2ìEªJ¤–²ÜbÇ= *ŒƒÚé™è8Ök)˜>OP <‹"g€wê>´Rß«ªÖª( :z:(Ԟ¬¬’ÞÇ Gp£Fòéµ }›/Ž]8\•ª©’L6BŸpëŸwȂFù†Õ :*ýu¯Us Y=çZUÇLê˘!“èKš?"IØ0¤Œ­øx<±‘ã&üUZŸ¯bËK¤_Qœ|Ö  ˆœ‘ ]ŸZ³øf–ò£%‡¯¤ÙœÁ×®˜‘6Ñ2º`½.©m¤,ëYD»ú×ÆžÿS5? gZmaö©sC¤©/+C•0 ŽÎ ®±» -Q­{ó†ë’¢i0 »Ã5vÁîóÿƒ|\.=/Łó·ôN¤>ÜQD V‚2»ìƒ0.PfýÂ/Èj›Z/² 2†Sþ÷}ÿâ[´< ”eQ ȟÄW0t28©©PÜLÍ7~dÜZf8€fJY#áSÕ÷%3[ ú—@çOŽäá”Úg¿H¤9Òǝ/¡\AõHqIéàŠ8™æpPڊ”P}¬ -%RV£v”jnm Œa>(›¢Î¨6I‘ƒ(lhô¡“ ”šÔpÔH5ž0ÀDkšmŠÒ’ÔJç¨ÇŒ -8‹“¿ràôsž ÈrL¼Hƶ-…ø -&!Òj Ö*C;&ÔØdÂ|hc]ªˆ¿'Ï3ï½üÖÍ÷ê­j4 [ɽ½ðÎnî)ÈÂ˚94À^ø17ç¤3ÕÑ~צŽÃyKú¿;‰c~y7­)÷¯ÿÿ: [ÆüÙ½þF¯üm¿úþÙ»ûhêÏñßÁÙÕüzµ|áè,¼ùÇúï7ÝéÁQÐýMqÈÄ¿o~[¿(áÓÝú±0T Ñt:}ñôzý¾?|qz­ŽR¯ßÛó}I f „vŒÞš›ÂÑÍfs{¿¹û|ÿ¢‡ÛŸ¹{¸ý@ëۇOwøö‘ãvÖ¢ÛV -:“Fæ[‚½x:A ò rÑ ‡θu’HE$è]8ÌûàWtòèA†]æ†aۀVBڜ?â$p3­˜U™*€ ÝÈÙæ!ô7ÈYߋø†§Qîl}âÌ핐“Æ=¸ &ÇXÃcÆÓ(Ÿ K¤*¥“†~•u]L\w6^ ¬ÒÑS/|¹°!³o~¾™Åä&š™7 -"D¨]9êí;›?‡ém@Âÿ?\„}gҒ†·n¨¶Ì¹zœÙraþٔä97Ђ4Ù<z/Ö ž -'—¡œÍŒ6çÁìÃÒ&p×~îÛ¾Nw»`@ï–xMÍ-ìAÃCU[ñQ90ž!÷Ú© pÁÍ[Y²3òt䧊>4ö“ƒE€I=r°ÀÛÑÜÂ(‰Â‹¶äs~ç<·ms[ڎэi§µ+\'AÖF%¹íÏ­}ƒFª<Qh ç‘Íp{}}r5¯-¢>·ŸF(mZûYxä/´›Úû‹>È;­JˆPo„o‹Šþ½xÎ÷\ùœI¯ÖÜ¢ðwçŠ;J»Ü×vØlmmû3ÌvªÚ ª挼ˆÂþsÁÕig°0&&J,Kó®ØÐP*wy%mC4èû¡W¢´0¸q¸ãY{;Þ®ý¯ jÿ+Ä tu‹“·'o>½»¡µV_˜x>¨¤áÚN°îq{jܽÏā{Ÿh‚#;öè:´ -a!™&ßøp´`&¶` bþœýóÕš4]endstream -endobj -460 0 obj -2035 -endobj -461 0 obj<>>>/Annots 51 0 R>>endobj -462 0 obj<>stream -xµWaoâFýž_1B­šJÁ±.ÒU"—äŽ6!È]%r{ßÙ»®×„ðïûf×vI+tM¼»³oÞ̼ÿ}ß€z-jw)LÎgG—³#ßë÷éé#_á‹O­>:ýÿû¦çu)—´äX„™úÛO¯ÞRСÙÖ»}üÙuŸfáqÇkᗦ²(bµ¢‹<~¹¡¥Îéò16öá8U§¿Î¾^u(œ­f«[dzµ¤XÅE,JÊ#zIYy -kT`ËT¤ AkmŠ_ Qe7%‘Ìi' ­Åƒ$¥«£Y4$Œ‰WJFTh¶”z ħfÐöZ€­Ø•ûHTç°]Ô¶bÃÇb¹µhƹÎd^ÄX––€I¨ˆdŒ'9߃H4[]Y;¾3ÒîlŒ`ÅQåy^ƒ›¢ÐðRÃWSx‚‹öT&#'V‰aIb³ç!¶lû¾Õ핋üV;9•‰ ‹'疹Nlm2K<;R![îRã ]t’€’#|!I¦Y±ó¾V³Õï5)Ã%íôöÌzŸç®»Œ -“Xª„ƒzaSËìL!SCšé:¡¨ñ9V‘ÞÍè±ßmœ”æÁª’2:ˆ=8ßTQ™®rnÕ B,ƒš=Å;B¢êU•DUlÆlR.vÆ&b¨•å`r‹ló¹Ö@ê**Ç¢HŒ&P)‰¤TGñrW:T‘°w»Ù„ërpðþÚØ̋äCJ2® ¼cP6n8-ôã ð´D¶…‰¶›C¦àÙqnOøkuBqAH€L£¢,!kínãò*ÀÑ´D”^¸Äy²¼ÇU¹W½ŽCUR`Í 42B*:ˆ4ꎟ§â—0EV9,Ll;ßQ$—VU6—§VÉkïsæaNlùjþ+ 9²\æï&“a¼ŒVðnq–(W—_+nÇ&]xH€¥{\Uäñ âág®HéäÒđuªÍY‹bŸ`WpW[ÿ«ÜÞœ×ba1°¨ª„­‡B½æ98ËX”5‡J¨]m‚ÃZ"Û .ko™O7ÓædüDϘ{Ї¤ÎA¤v“"66î~íZÎDz’× cƒ:‘ƈÜ"xˆ¹‚ VD¬å2Յ´ÂoË¥s-·ƒäh‹MR”!‘ZÙv³§òuXìö eÏk¿Wè^QÃæccß“Ä€—HîV²A[™$ÍoJo­r½ÉlxmËõ©ýö T¿ì°è²HÛ_÷»i» óöÓ6úé&ËtÎrˆ|‚6éÑUÎ>O,øéšé­â´1Î[d Q3RQ´aq³@#d¢3.rÊ°ű,+ ÝÜ¥ŵLSb)»)´U%ZD‡ürË|Íy%¢sW -Üg}0þÌםÊ-ãD½}CÅÙmЊ™gn38þj[‡w°ÎŽ;ŠË1%àYeòá(èö¼€Ú~.¤Ô -ú^¯ü–ÐÔN6øÊ­gŸï’N[é•TB׌H‘Sv|pêQÞºowtÛŸ»‘ïØÿžR;ðk<‚z¬² ílõ¦”Œ -þ!Â< ]µ€Y¨zÖh ¶¾j£vj³FkÁáÚçÞ¡päÊÂ¥@=é0hRl©é0Ô3ƒë[êÅLPÖ”:Ñ[N*„R>Š4CK@ðךg$<ƒ($‘ílhzXE‹—ÑßtzåÓ[ž$.× &˜Ÿ¬†×þ¢Í¬45ïlßü-(öfH ‰j(‡“†%Sæ[¶q¡S«wóÑ`2¾ÐíôÝüNŏ_0¡rOz7w -ÏC«ß ²¿ý¥´Ñrµx<ߓ< Õru…Ôâ…cp¨–šë‹M‰ƒø§Ü1B.Ñü㘮Qjùïð¢ã#eˆÇÇñ´º¡ð#nh¡ÿß:Óø7½âÁw…²R´ËgqX&beÎæþc´û~E÷³=Šƒ4¿ÇÏøöÃíýý:kZ\¯nŽ¤ ó8ã‘èlîöž;ÝÒÅdøérBƒOƒáõàüú’®n'4û8œÒx2Í.''¯Z/ǯ³yµZåųŠyLüá!1ïïŠâ7WX¶vž¤òûÿž›Xüaq9½ê×Zׅ4vñ^ŠšnÎx¡Ó_ùåB‡˜ Tù^Û©¥¥^˾ç|ï g§×©^‘‚ƒÞñçÑ?ð:©æendstream -endobj -463 0 obj -1656 -endobj -464 0 obj<>>>/Annots 66 0 R>>endobj -465 0 obj<>stream -x•XÛrÛ6}÷WìøI™±)ñ¢[fúà4qëN⸵:éƒ_`²˜„JVܯïÙAQ²=M“  övÎÙEþ> i‚ß!Í#Šg”–'ïV'V'“`± ý£~À˄f‹žÉbŽgáQkZóXÄ1ýÛǗZÒj£g8j•Éò„Véè¶MSmíº-Š'²º¡Íö|[çUC¡¬ÎuM¿ÞÐGeuý–“ ¿Õu®-ÝÜoV_‡ðg>’Ο¡;ãË%… [Ǟ$fö“ -’€.²,¯èZï膭ëÚÒc®¨Ùhú’W™ÙYº^ÑÅͶ8¾L( ݑçÑŽÞ=Q¦×ª-š3ºUå½"³^ó)ª(HB v£jøy¥3Ê+r§!rÚȖ÷Ajªõ¡‘ïdON½oAœÒÚ™®¢‹ÂÒßsÛp yÅ_Oè<Œƒˆ]k6¹í6þu‡îcF¨ÿ¨ŽÁœ»‚IDL»1Ük¸ovd**‘óh†¤ÃïÅW•NDÖ¢ZlKÝš i‡U†«:mMª¢Ï[]uA}ø~7ºÃ/|Š¢ß½ÙfC*+ó -‘Õª8²óAhHìc^èìY½å¨6¦!Sw™|f} ä¼£ôÝæ´Û|>ä³wÍæ².DðÈÞür3¦É¨*i¶ì_ -º=¼–N“n'/ß±:M`r°:x/)šÀÜ`uøŽÕ®Þ±'ßðS¢~ú<¡¤Óéäˆ#RwT"끼s8ù‰ž´´õlÞˑž"#T†1×Ñãî͋é†d£a®ãE7¦ƒ¸¤Dœroœ>„1$á4â uåª@F ë` -ÖǸäU"VUÇdèCòL¾< ÷yG8¦ou¨¡iȒ‰8f\+yéÂ@a™üILMYª*;4ôR^ËÖB/Õ#Âë5åQ-X ÜÝÖæ¡V%mŒùF²ù€‡/ÆSó«}².;:±¬Þ½ÚyZŒu“ŽåËTmÝ®}ÁA?µ…u¬+ð| ŠZA ½ªxk‚– 3¨úIT¬÷Zóe£+H ‹;̵\צDÒ"×8_ËJ¥Jˆ‘Oԗ2­  -"!ŠyÖy4õB‡$õ{xœzÕb“.`O.¹Tk¯¹Þ&ŒK Ž3Ä©¨õVՌG—w·Å§úÕVÀ¸lP ­tȤœaö©Bïòf%T àÊåÁEž;ªîD¿€°s*ºŽtƒ¬ëõ3k:½ÖLïu•ëì”õ¼ÖM[sëê|vù†¡k#^(8õ<=Céx–§ÓS]ºÑKª }ŸEiôw¨»‹ê°ÝœI 39š”r½@¥©i«Æ -a8bŒ úKë2˜wo=!“ÉTšÚ~JYm4¦nhp¢ÜºÌ(><‡Î¢`zth/ÏÃ{tl4Ӆn´/)þ1YX£|µ.Í#;?eV‚p_œ!º0X£â%ë®ë^£â¦ÁÍâ1jtzÉà¾qSݘºÜíùÄL–™i?X#ë$ÔNl‘jkM*úQÆ)nÐ*Ýx˜;™ƒ*S—˜³ž¨Qߐƒ’qòñf¾=;Ýϟ?á‡tyõñþ‚aœ¢Îw‘IÅ•m·b¶C^ªÁ8œÈ?8—ucÊÀ§á(ÈÓґuSí%—pE¦NÝØ8LÜ)¼ã±Îbêôœ2÷®Š’1{k-Áwi¬è;ߑeÉïa”œ)o kýw›/@ -Çç‹â¨m]³ˆïžéÎßދWòåñ$˜ˆ„Žðx]‰Ë¤1ãÉ »â!v¬íŠ -󐧪x)€n²´6蔨Äԝƒ”}m'xFet¯ -U¥Ìpc­ò‚ úq_Z>™锄@r gGgc”ðÓ;Ó̚Rsú­©|#yQÀ!ñ| Q‰¢¹›gâäޞÍ31¦™‹‹£™ñY‹–ˆ¦Dyd(ÇsUéª-¬œÄn áY±CÜK¯zQ8= ôëÍn“ƒ“)Z²ƒKºƒË’ô“ï®Ü`ˆG\bt¥D‰¥è®.=½†pºՎþC›ÂùäH¼“ dº*…–V€"îš|ò ²´‚Jö[l•{)¼Ì3q÷Ïë«¿ˆA‚a«c ‹DOk\Ÿ]ª@ÛK ƵFn2Ü8âÝ(Œ–‚Š¾ã²*o}]Âxr„ƒ¼bpãBĨîq7& ×Mߗ{÷wúžlÎw­æČhÓ4Û·ãqÞe'°¦­S :¨t3öýË¢#4í4üðe×~¶ÈLÚ²¤ˆ—ΧE›r©ãlysà›£Œ/yù}ËQ‰°C ,n“xuó—»yveîÑ×ä:¸BZj“µî«nFYk…¡…º|^ü0À oãñR¿ÃPnåál:Î#¾¢ìG‚Û‹Oï.ÐæÌW8Iï‡ár*ÎÝWçî³÷Çÿýß Éœo…r3 -|(óûÉ¿! !+endstream -endobj -466 0 obj -1898 -endobj -467 0 obj<>>>>>endobj -468 0 obj<>stream -x­WÛrÚH}÷Wô#® 2Ì%/[¹Ùqí&aRyáe 0‰¤Qf$vkÿ}OF2(8©J­]e3êËéÓ§›¯1 ðÓtH£ ÉìâùòâÕòbÍfôðÇnñf@Ãi4¤ñlŠ—ñ`Ž×VцŸÀ!Ì´pýêfNñ˜–XŸÌð"ñçZÊÞ8EqDŸv¢$íè.+¬ÎK÷ûåòóÅÕ͘â¸~®?œâ¹^sÎwI“¦J–Úäd6T“:ÚK®* -cKo©Ü)ځ\a£È¬?œDEoaͽNøl©¼´"E…qº4ö@:‡±Lxûø|+¬¿ûIç‰Ù;z»$‘'4¿¾šÏȇ­,%Vßã_!ä±UŽê¦’;Ì)YY]Hî”üB?úD¬S•Sk4¡õ¸{LIF#‰Ýá6Ô:Î^8ë˜õG×#îM§+x3y¥ƒsRì1½:åjµLéf’6jÙXê×áô_¿û´|î4®^݉­ª´¢¢Ã¨&g*+xďs2aÆ.3ª‚9ÉÞæ+øÏ&Žç4ZE•^MQA–‰TçŠʦä¤ÕEùësVÐíòßˆû5¡­†Å+þF -Ù³“ÉÓº.~Ñu8EN°9WÆUp¬ ÔÛ㱺䉂M8 è„Èý6ãµäÐèkSÍï䇕^„¢4¥ÇR#w~wH1Ù/9”¡Õ™ITJ¹àÊ@Wö -zÎúœ3&’œÌz&h½ÍùŽïz1”Í”çMÊ«[;äÏpÒu9Ú?š1‹6^Ð’ª -ÄÉÓÔ×H"nŠ=*ËÃIXSáí_Ý\7rá²u½Ëԟ7-Ùó†:wm!ÏÞõ¤½ºМÖE¾®—L௠æáa-õaþ«kÅ+ ˆ¶ØóÞê2cíæmðŸÎ{â¬ÍÔFó”nÑ"Œ?µpbPU°ØCÑ ~~¥=g‡ma)ãgÃbö0þx¹1ð5Â^D-ZOécmÿ¡ìõ,?ç#ö8Ú;ç*&WNϒdQoXõ‚µêïo>ôß/^tìüÞãh¨@Z¿3yjñÕ·#kÜÊÍÀéXæÔü¦†~ aÔò¥«›Y`I<™D1MæŽÏÞ<F k>Zz5¿ósýx2Åõþtè×ý}ÍOÇÍ·‚xÎÏbùëâ?©¥-[endstream -endobj -469 0 obj -1439 -endobj -470 0 obj<>>>/Annots 69 0 R>>endobj -471 0 obj<>stream -x­XÙnÛF}÷WÜæIlZ’e-y)œ6NŒ&Ý,À} PŒÈ‘41Éag†–ý÷=wI¦] Š$¶¨!ïrι ó×Ɉ†ø3¢Ù˜.§TÔ'–'7h¹ÆÉt>£eIÃl8Ò²üÒHÒkr[I­Ñ«J֖dSè®qÒȒv[ِª[ÈÆ©fCþÞÛº5ªq–œÖYéh'p+¨%ÙV’”µ´§Ëo'C:]fcx¬¤ÛIؤGa”î,Ù®mµqðUT ->H˜b«œ,\g¤Íˆn´!ù$8†3ºWM©w–èç%©¦¨ºRZTõ(w^Ò»ë÷öü~Vš{Ænoñøôx5ÊæïˆDSîí.®¨UerƒE«tðQ69 æ‰^[|}Ž§Ù„s]P´Õ;àE ~ï¶Â¥„Cð8’hÅètm¥E LÖH^€€- À¸F¶ÖuN’‘¸ÁÐNUU/U®êÎ@¼0+ 6 ök°…ߺ•Æ)àW*Qé é¦z>€Iä4DCH 0ÍNÏõ_*¨Òú†¼çcדlHöÙ:Y#ú²Î<“plâ⢍=Oð}þéË×<¿óäù1ÇºqFWwÒá«ð9Ï}Nyþ±yTF7¬T -VÂß[eÀàþQŠ*às„¨vâÙRg -ø¢²¼´0S -*‘ôþúI#dë-÷°•y¡‚Žž}¡³WHÃ[ ‹È î?ë"7gt'êd¯áªÑ.H÷\Æp< ^A ´ýÒ0Ô¢¢X•…hèYwœx/o_Îjí勌Ù‰Šµ÷”ªë`T–ßG߉=F -hrõX…*u²m¹¸-2ªT­œp\]¸BQÄH£daö-¦§<´–±AÞ±üi¥Ý–£îå~‹Š©èG¨óÅÕÅbÞ3J -'¾V„#,xˆ¹ÑZë2öðqy‚æI“Ùýl2ŸáóÿŒ¤uèµ ¡ø¹×N&ßÝיWæà«Ú˜?’_]GFa+{b@`uœ=±Çãö}>æö=ø„nÇåIõЩEp<á[ðUlE³A¡|°“ º…zѺõ#¾{ŸŸþ¢NÙՐð¥as(x#Y©Òžõ0­÷Qû¡ù„2fZ1º–ÆXQk]UŽ`ÕÖ -·µċ›«Xîãñ(»¢óñ¸ûßlUºJþwFcg£}-˜ý×$¢²&/·•ÏàųL©ÕÖ*l,d Ùð2aý´Œûs¼—ë{†íßÛµïweà Ý M›{ˆçè¨5‡òJC š>c¢·ì ‘²ôí r(1%!ƒk´®T=!)m§Íƒ÷gý}ƒÕ´/›†™'6µÙ˜ÉN`æA°N<¡ò—èÜ|ÑÒù½_øǖìc•åaW „Î«Õ -Ól' TTè R­T¥f+¨ñ ±µ#ìC׉ ¼óãÔÛçA -lt…æn©9gå°ã¶ù׋îq5F›xÙ@RÜ^gÓ)ŸF•ÅŽRì%â³Ùoª„‘+Ìı¶ÕØ{òAäËÅ¡¸ü”µ£ú¯ ª:uè+¯lîÄ²Ä -tâg6ËÍȐõÞ쁯¨”§Ú4XwJ¿6Àý+šY©FRWcÆ߀-•ß?•ç%¨pýò:žœÁzÚQE^žá(ñ1ðõƒòvõaAk>>>/Annots 76 0 R>>endobj -474 0 obj<>stream +496 0 obj<>>>/Annots 36 0 R>>endobj +497 0 obj<>stream +x•WËvÚHÝû+j‘9Ç$†ìœ‡g2c;N '‹qÔ@g$µ¢–ÀÎ×Ï­~ð2™™ÛÇ GwÕ­[÷V?‹©Ÿ˜.ºQZœ½žõ®'”ôi¶ÀÑå˜fõ£~WÒΛ•¨YÓ ¢ûZ•*—4m«J× ©’¦¢˜ J¢$z|9ûfWŠn¥îE%X«3ˆâˆÞ—M­³6m”.ݓŠcÿdrÉϽ–KU–¼ÁF5+jVÒ.ܧZæRyîw3n{Cö‘R4j-é‹*3½1t7£*ÄYÈt%Je +Cª¨rYȲ‘ïÞ§n|á¢[+At;í~ºCÉÈ.;½ÿðáf:¥R2£JUòáeDÀ@®•n ­emŠ!½ —.ó'òÁáQފrÍѶ©Èsù‹É(hYg†”E–)Iä´hK‹—ÈUó„…ôZeXxþä—ììÃôÛ¢$iÞfÒ¼â•QànX:Ôl¡kPe®EÆP[°P߬Š5ÑBåÒP£·€N†½É¸w7ë%̈4WÑP[é’2Yˆ2‹ˆ÷ê]§¾žÝËh "!‡dtéo†bó½-ôŸ«@< £.Lm ¨ìU–9"Ò/ꇨ3”ìêþËÃKBZöé÷…]ˆSÐ9ÙppïfgLhËjŠùÓ§ßÎ.ѐ†–è?Ž.ü·œ¦Ü@o,IvíðЩå» [»ÃUë%uVMS½êõ@8¦¡‰ŒnëTö¥ŒJÎ.û‰ßbr€1ôgHžª.Ãà›ÂÓÚFÂÅ&Ë:p4]‘04mDݼÕé=G*ëszW¶ÅznÏ9É&"pþ¡3•¨ÖõXƃ ø:PL@7šD±ÿ¶ƒn0æRï+Éíôí¨—¶Ü†hZH4ÿba²2*TZk£M”ê¢wû@bbº–h|,Ü؃á€8\$?ëÄ«û÷àÏ ð¸?ÿb˜æû­Å$MSi ½Ñ¬x9Ý(ƒ~MßÜ`BD¶àž“)îØúµS]¯!¡ù‚°ø÷V¶’Пªjs ¨u»tÊÚÉҁ²µg¹ÉD#æÐYc±4è™Z~Ós:@øDðÿBÚn2FCur³•DÁV â\ʒŒ.¸|?D“êrѲĒ˜ë¶¡Í +lh" e¨Ú õÁu‰͚J OÂ/nÀ3¾·ª¶’ÏéXÖì”' äTÏêÝW¥i° åm½¬¯´±V§ëÌ5~€Û.Âmµ¨u±•© ‘hœ+š·Ë£å#ø€ ¼³,z²Ù¾“JnH ¦µ3_#kVîJ”ŽS_Ã/Ž]ÎË;3„ßôù#Æ£‰ß…z<Ž*¶øê2…)-…*Ï·9»A +1¡°ôQº¹†ä$ÚrÊã˘"—QIvý€:¤iÁy6íEÊñ¸28³0ãšäãJÍÕsk‡Q†±`ò¸«Ëƒd`¥L˜íT‘iŸäA:!FÔJ”O´0^ˆ´mpòâ,3Xy ÿl%ŸH€Ým£rõ™@õ@HŒÞ¿½•†ƒÚàE`•çzÃ0ÝNéÏ×X§QiŽP „¢¢qm¯¬d^‘ZГní^™Déñ–E2¤¾ïÛ¯¼ØŒ¼Wwèw½ARGUÛóYã»Óô!žãd-ìXÂÞ߄qN OHàð†ñE„ÙÒ~óÞ°3?kÄ0¿Þu˜úxôŽB;Çõ~ê›îÈ üÕÞßóžÇÈô>ÆãI/îõ‡ÑÕô~“wÿ`øOÉ0‚³Sá3þP­E˜‡Ã›Äã#ÃH±º/Ô²­­²ò&½ë¡Ç4ž$ȹ›LØþ²ü}ñ•Ö&"÷EÖ/¾ž C ‡´V<^".;‘ì€J(^ur4uQK8'l—§Gh*‚X1;Ýx» ,ô_ᡌâo(³U¸çÝí›ó…mVHk)XÝ;/´k5ëªÍ®oÃÀ ¹e:5ÜwÊf¬½]ähD×ÀÔ¿[lƒ“R?-€'²®ͅ3f,KMT c6u¦ñim—ǶáU4ÌÏÏæw4“„Ÿ[ F¶=zø™‡[±ãäQ‰Pó ˕Âq õµg£N€ÂïÌrúüÕaYšK¯ÕTëcVw冽Cëñ´©dªî µGVW¿™; +%*[U,ƒûø°P¶+H&ì÷¨F¿”•K9h@‡Öt€óyè]&ÌåP±dµ€ˆ%¼Õ}NV§·VnƒJqÓێÅè8Ûf^ NÜÙµfá5Ã5ª×µÞõ؍Øûƒï¯¡8—øóS>>>/Annots 48 0 R>>endobj +500 0 obj<>stream +x…XmoÛÈþî_18°D²H½_pœ\ÝhR÷ìâ®8Š¹’˜\Ý.iE@|Ÿ™]¾X‘]DïÛÌ3ÏÌ<«?/"ã/¢EL“9%Å҇‹¿<\ŒGË%uov‹‡1ųQLÓå_çs¼YMLÓdæa$Šù?2„½ð´oØèêfJQDŠi¾œÑC*ãczH;í4í•U…®´uï(+“¼N³rKo¾\\ÝÄaí`o³S(µÙ>6Y®ýŒf÷A·Ï;R°g­y›Tï­N2Ué”T™’Û™:O©4ao!î7VGlú/½˜¬Æ£ÍÀ„ +šN£ExÊéžAƒ3‹ƒ}wj‡C²’J}À‡«Tž«*3¥ÝK…YY¹1¶ÿ“)©ÚeŽ’*·úÑÑԍ…Voàge0C °³o¬š/[ƒUòâào9µõS¶µÞ§6’¡è–Ë7,ÙðÈp²äÆÑ”xHbvj’ºÐe5úFYñIóY<š +Ÿ¦3°Ü_RéVÀAO=™ÅÊØtÔýHÜ#ÞÕ͊¢)Ó 'F`WfÓQ<ŠFôÑjx Nü.dzó›ÝÑsLÃxÁ¾Ý–dlêÁwõ~ol%A¨÷¹QÂM³¡> +!Á_`Q» +Ïï‰)7Ù¶†ÏJf ¸LÍ|O[3>œÞ`‹¬€ÞÓÃ/O°8Ş©§Ù½*ÖêҁQHŒR厜!±”÷'ÌG¦)+ØUVôè³è 1«œ¶OY"IÐ;^X¼>ýš•©98úüཕùÈR&åޚ§,Åpú;H°¸dÄß6Æs0ÿ»£yaÒlslÍѹb=bä/’߁ץ̀U£.St‰¶7ۺδmÀÔ©/%LQ‡¶ç”´­¡gђÑ)*À Ū¶½ Ñ[R7L“vŽÃ\jŒÔ3ç‹Ê`­%^»ðæ§^×ÕÎp÷ül*ýcÏ­8æ`q)“]|ÿWeN=ï\¯Û{X¨<ó%èåžTP8¡Ï‘×Ð \c½¬-¸ƒ¦Ã*JM¡ª….Ö ¸Çò*ˆ Ÿê;Õ6± 5UΝåˆãÑTÐk3Îð”Âq?û]?š²²Øgtõ 7[VÙ^Fw>r\zŽ ¢ÎähÚzO˜P^.¾/”š« „¢þNnà8Ec¿n­A×ÐåSfM))qØiÛ6¬à +Ä/¬,É`(#Í_¥Mˆ¾05&kœ°j͏èÀ9:tèC ßftR£½Ù!û&ñ +5?Ž"©zÈçUx +Ù ÚÄQ|RöZRK8|‹gE°ÀðXÀsh·Kpêg ³­*M›¾Ò?²À=sú̀þ3FW¬â½±l^ÿ7Ö¨7Úƨ\=»µÿ§84¸œz^(éõÞϟèƒɂÎ;áKo´Zâ}–?üCc´‚¸ëÝ4þV µ^­.` Sþ÷m ó?8Š|c uÐy?AèxQ#7ŠºÄu÷IDü°CÞJeèÄlj:áX¶ÖˆFF1 V°ÄÔÛ݈†Ã/´’ºÔ/·M嘫—´?óµ‘üâC£ñùHîÞíÜq‚u^e{(Ï$ÏP(N²NÙd ˜TPo|÷¯üÕ)¨}W¯Sô–¤26CCfÕÝ'yò†“ @É ãä‹v¨Ø\xI+üëì- 8€⭂êïÙ1 +Ìß3 8Xñâ–)ÒÄ'¸ÑTÞÏúôfwEi¬F9´P kÍâFÞÚ-·@é˜bfß ø!s»Ö¡ì¿|•ò«A·§ŒùNñßᯓø·åœ¿‡×{ú¡+…ôm9ÿáåµ·Ÿ§ãföÖ®fW«å+K'ñõßïþvÝ®î-E¹¿Î÷;õŸëßî^ÝáÓíÝ}»AÿpìðËt<¿ºúîîc·ødõ9h{÷QÖ_Ý,ƒ‚ˆðKWDsT%¹”Ý_úpMwÖ|éçðƒ‡üp £ùӇ‹˜q¼öCÃt1Ŗ2-šóZ˜^üNøœ¡endstream +endobj +501 0 obj +2125 +endobj +502 0 obj<>>>/Annots 51 0 R>>endobj +503 0 obj<>stream +xX]oâX}ϯ¨E+5#%&Òó2"²ƒ”& g´šÞ‡‹};mûÒ¾vhö×ï©ûÆéiVQçÃØ·ªN:uÜ_/bêá+¦QŸn†”ä÷ˋëÇ[ŠcZ®)¾¹‹4¼»¥eJ½¨×ëÑ2鎗ËÉl9}žýƒh>ùåÓt>y —Éüãt±ÀÕÅË?.&Ë ¾ß>ä¾ÍÿÅWh8º‹îhp7Âïñû¨O¥¤…‹:ðQû4¼íGó˜Ó‚t™Ê’*MI]–²¨²‰4%A…ÜSZªW÷éA×´ùJÐV›ê’H’ôšª=žÔEª*¥ Cym*ܑ¥T•µü‘sWý! +^¦ÝåV’H]ÕFâ.ût!“Š­ðñ)ùÓÄ+¢Z¥¯GŸ»*’®”ZWá´Ï?Ǻ~L|µW#à\Óîçþpd?</fÞÍ0ƍøàrÄ äþÊÚÞð}7gøý?õ¬¸š\æ+Ë¢fßÚftär;@Ïr9õÞ¦_nèú±ï …œ'¸+UQ!zš«‚ãœÎ°¿Ù3Eº”)SEm(onâhÔóú1¯ý’ŒÊwÏLoxs\Z ðyèymT±ÁnP>wué(Ó ì8’ãÔÕ.&*tl]êÇü¦ŠTï ͖4À´$™‚\DD3ñª6H8LpçőÎtZy­¡ Lú¢1è.Wœòo`e¶º†tÉX* *"³œäJ0,>a°ƒÛ›‹*Ù2U€j(ÅwýT…L[ 2ZR64¦Ñp¼gytíe9@s×NBßS ùbñܲÎ6eCŠ/ZȪâ$¬bZíÉ7L_ €p:'ˆ{š“v‰üÿªXÕŒå÷¡ã™ˆdQÝó@Y²©·‰qKm€ ¡O-\`ŽÜçàùx”¸º V&lƒBä’ö„QrU ½uiöL/óél9™ÓÃ|ú+~ŒOŸÆ÷Oz|žÓòç©]f¨?Œ­¿ÿŸnDO UI ³±Û%يbcÇÙ°ZÐìÓÓ™ +„ÛØ Y¦÷–Ø.¸àä5Ó àCZ|#@åÿŠ’Ç¿ÄlyÝçuì¸m"W•Ìw¶‰ˆ÷ª°›lەz'ˊ•‰.Ž˜ï·*Ù¢LNFÎÉK@0´¢ݶ:!büm$Y–88‡<ŠÛ§×j&_¬Ò*čs5”ˆ¢ÀvÄ®I•Ùeâ S4˜‰æÙ`óåRÌN&j­€jà òågUa*¨L/­LâF­3Y¶rn `ÓoE|ÐV÷ ú3me!“Bï:o|£®™J¾Pg¦;ŒçëI! AVLÙzô J(f¯°%þ¤U{+d½€á±£A¢UÛÉýj¢ƒB$ŽwX4íÍ'&rìÌÀ§QuhUW«Þ P…ýU€ÜEÐA¢ÿÂƜ„-Îq„2c%¬V´-zW﬈²‚†"$§©SZìËV6GH™þ‡7–à­»:¥Õ2Óµo‘ACNœ—îæǍ¼%†JØ¡3ƒ4¤nd‡µÐiì¡owÃÎ剅|#ùˆh¥€»²€ Àtt¨«`½B ;ng&llL µ±ÑÜR?ZK¶sCê²r(ŠÌhE±‚ÉuªÖ_Ðw¢›:Ù¶x¡ñ‡'øÐ=mMºÛòNeÜP¬ô·7ÉÓlK2m-A¢óSâ0·OP + ÙÇÜëË'Ë»úlñۄ­aávh·p|ƒìMüܾxSpÜWV!ّ±ØصÍå쪡¨|=_x¤XBí.µiâ6·ªìÒ䴙çìåZÀñ"»ãqœØshþWa£bŸÓ9 "¯8gQƒ“(¼]ÙW¸®ÉW¼íÚ]^¸ûxÁ̵.\:7`Tj‹ÆÒ÷F¦Áh¿y(Õ¶þÀÝÅÇû£X؜.YTS§Cí¿W90c猱æV‰âp<‚Ûê3kÄfká]ãÇÅÕü僕H$ øœ§g¥¬±Œx!è[ù½°<$~’ÝDµ’ ¾(m¯päœÁŠˆ¾•2×06¸u¼ÊqÝ7Ï怵å7(”!Wk¼l¶b‡¥Êv¾QW΢ ^g9yˆåc‡ç1Hö£ Çï·ÚË,»ú‚ UЦÔõζ׽ÐmŒwÚï¹Å;ϑ¯ ü_üzzÍ_Œ?ޏaDô,×:žEµsfäÊ=uåëþ]w9 Â{o>>>/Annots 62 0 R>>endobj +506 0 obj<>stream +xµXkOãHýί¸B»Ú´DŒí' õJiAÏ°ê–¤§WJúCaWˆgl—×åØ_¿çÖ#q2Aš‘fh5J¥ªîûžs‹ÿžDâ_D£˜ ¥åɧÙÉÍì$ ÆcÚýjž±i0Œ‚„†ã>ÇI ©‘´ä+؅œí/œ?ÿ|IѐfKˆOÆø™ýfioÄÁ  éº®UӒ B4ϒªuù$RKª›¼je£?Ì~99ÿ<¤(²‚úñ‚z÷•¤\뵤v%ZZ M¢Éµ¬([ãæ3¾–”ÉY¨º”UK5ŽH<哠8ˆqߜª¤Ì¨U¤-Y“¿À†LmªB‰ÌXR?à +4/UCQþCw­ ˆ¾j¯ö[^Ღ»M¾±­J¹a;Il~݈ÆêoF‘ë÷o—T*þT¤*Ɏ›4ø°FÛÇN¢dD”Ä—HDIq4FnUÐÔd‚’AˆÍn¼]8$Ië­¥¤E‰0‡ÏŒ1NkW*t$ˆ³YGw]Ò +·öx ¶e`Œ6µpáRèÌÿ…M¦EŽT!²Z¶. ©*KQelÖ®¶Ì'#Ô×ERDí‰}sɔ­ñljZ«4­4’úֆmJ7y»"ÜÏ+݊¢€{ Y™¡Œ–ª(Ԇ³‹TÊWQօ©¤•Ú@¾KÕºÈX»Hao„®dve+7¤K.܈úñºô7âÞÖ_ªÕ³¢þWj”jÿ®eÚÀö~J§Ý` ѧ&(B4$˸V¥È«ó»ÉãÝíä;ÝO?οVùëwšÊÕûq¾-ó ì‹Õ?øîdÄÜÁ1ïÔéë8ñÛ^Ńm@º¶íp[-EÆ)ngñ;q‡Zº¢ùô­Öü ^ C”,,Ê¥¦‡©×à ø34ÄhÅ¿VÃpšŸãÿOÿ9âÁJ¥G´?3—{yXâY_ÍÃ×1†>Ü{g*NÒ|Ÿ‡ûî‹UÝ7v=œI6yÝ檺šÛó‡÷Îîîéúñöç›Gšü<¹ý2ùôå†>ß?ÒìÇÛ)=<ÞÞÍnώJçÖF»_Íý®¯‹ßÕÅâ %þiÛÊtÎ?¼´Xœ¾_™Øü+²2]§©Ôz¹.Š7Æ4ÚZº±Mï°ƒ–h0€píâ“'Ý.ÅƗ—†¡öIvÐ$˼îä†\ËizɅÁÇ€«Xã²ýô*]Šuў9úTË%¸™–ž¨I¯À-šæ4¯L>Î?c´0ÔÝÓåSªj¹¯¤Ç'™¬O½mAœ2æf²O +­ºàHÀ•Ïºccƒ¿ö°çóŽKìº÷™¾åÿcæÍaƒvfçMݚÑ\UHTn,Ä(ԏ‹ØL¸UÉÂÓ°.ñ0sC'Ë0U¦ëTPÑ}-+çÔÍë¢ÇM‡«@çŨeÊÉʼ‚gh1r°gýЁ¾|ÉAFψꢗ20 A˜?lcYœäYÉÊ;ïâCàŽ§îxñÓÌ"NFf…6Hx¨ /PE%%—Û“zgYbü‰÷6»kì^ ¡ÀÊá«Ý5f‰#Ag·»æiƒaw·³Æî`¸wwoêÜM>.Ha&=aòŒHeÛÂÝغøHoÒÎzÛáå؜±èÙÉÒ´Ã;Áń›õö";‚s£Ñ)iqìÊ Lݦ‹F—8ÖÞn16h®6ž2\á¡MçpÖ!;(¶.bW¸Îq îM{]ƒ`¦=ˆ1֙·½ŽDÙùvh4[à àštH%kAbìÂ+Á21£ÉÁ~÷øW®5¿^-½ˆb¦13\ݨçF”´RêW2‡uœÙXΫï$Œ—úM·²tÝgËÃY§QÏe›ž››©¨ڏ»UÔЎ}ŒŸ´DGkô?fÚC|¤wrI€‰hÞ )@·‡¦o+>>>/Annots 69 0 R>>endobj +509 0 obj<>stream +x¥WMsÛ6½ûWìø¤ÌؔHɒœK'_N=“¸n¢LzÈ"! (hGùõ} ÍÚig:–-“°»oß¾]~?Ii‚Ÿ”Mç”W'/W'ã«KJg´ÚàÉ|‰ +š$“É„Vùh–dÉEBEµ$tA·µÒNÖtkjgŸ­¾b÷ŒÒ4ì>ÏØ=ú¬taî-ݬÆŸ³ç=de}'kKÂZ“+á$ ÚãºWnGRä»°PÖ Ñj'­$mêJ”停ø&Éí$mp‡Ì†ÞÝ®ÒçglBçé4ÉØî«?Þã&]]¿{ƒ/éò$ÁQÁ÷ª±ŽDi ÙfïÍòq¹Ñ¹Ü;>‘ïõœ+‚[p1Œƒ^¨є.ëF˸ØvFZT² Óà@¸Sx÷CYØ3(؃u²ê\-Œ´ÝQ-}ð-LJ“© @ïÌÀ²wñŒjjRŽÁîe%=â‹IÉK…;6¡ölžpÊG7q;áZÀ:/žÀëô)•Þž’'†ö.“DNÛDÂ|îw’C-ÍVå¢|,vÝ'@m5`s†*@­ö%`msC8!2 4¢ µ(…ÎaÐÐF¨’ 8– B»ÞÐÁ4äàìµäÜ*6 dM%~kô™j|…ªñ,Ùj€76òfuÂ¥âë…RþïÃۓéâ^\Lð·¢Ùt™,Û«’>†‚‹%3ÍfIŠ‡©ÏÁ±ì±µ’?ˆØGóÐJ½¥ñU=’º©ÁåÒÌÑ^nª +ÕýВÌ[ŠîŽF…:ͅ& Öؐ§€ä¬†6€(³­EEì­Ôìôєà½OX,¹~ ôÈe¶\$Êð[£ø‡j5»œ&ó^Mº®|UXZSZéøäG¤êÁR‡¥)ÇÞߩ»ûéæú/âJºe[I`6uåt³¢ÅQ?«Ÿ¢.PÊW`P{l£Ê¦i2¥ÙEæy1]L’ËöªËÌìb:`‚ÒLxá3§ È"°Øxð’ØEz/×dëª{‚3#Ú9·>«Äš¦Î%Lle¢¥?΀D›îeYò7Â÷«Žº[˜¼a™ñ^t /›ÔðÂÎhEs¨+6G8P«uÃQ«Õ…oeΗØ3^_cPëZI_p=µ‡ÜÔ¦hÂ.¨ÚHᚉƒàE\¼„B¥YÊåðkRM—œ ‡Mpš¤ }fq„§ñàߞàT|d87eن§˜b6HLhC\ +ìùÖ 9!n%ZóyÔå[ÏE^&(È5ª«–ÐåL}Ø?˜[°×Fµ=¹k_^Œ/—]w*j•¤½È¿‰-À +q䭜œ/ WhþÅèK6_´£ð³®ß]ãBhZæÐ-ÏàåÐP_í™êK  =i|õ<)mºP`chw­nr™µh¦ŒK»t€ŒoËèœÜCóæŌÒy=ˆgá€8â<GR:P[Jf‹%4ìהÌf3à>¤d–ЫˆolƯCjoÛÔ>ÁÐҍãLq¥tYz"/Läµ<æóhs³—¼ÑqáÆê§/£N—b $î‡WÞl~ë$â¨è¾2xUÂß#ù—gŒkMv‡™à îêq@'_~ @Ïøö§Úï¹i‰£CÉós!a}xçÓÌЉÜ57ê^ótÇYñ$YŸ[£ñr`œ¹¨¶Škÿ€Fè§HÃ[Ýܾ}|tª gá·F:û@ÀsÈ»Å/!ðCþÀªç|µm°ê1jæ«ï!Uó8µñˆnEq!?<‰Ḯò>ù +Ckljå”ïdþ8E¨±.eѧ֜ÇÎDŽdٚLç L›‹ŒÅý8û}|ñþå ¼×™¯hSôºßËÙ½ó°ë>>>>>endobj +512 0 obj<>stream +xWMoÛ8½çW zr±±b;Žíô²HÓ¦ Úl»݃.´DÛl$Q%);F±ÿ}ߐ”í(Øp순7oތž i€ß!MGt>¡¬ãu<›âu8¸LFd$-ù +žÂÎþçÏn.i8¦ùæ'3¼ÉýóͳÞ89OÆ Íגn+ëDQ§tEׅ’•{=ÿqrv3¦á0Ü¸Ý»Óp¦ª¥6e8mäJ˜\U+rl¨¬ªœÅ‘#‹™·H¤,‰P…Xl„o7H¤u3Ý'®ëÿéº?šû}^ŒÍK¤=À±ÐÚ㑾¦ÚèÊ“ RŠÊ£ñ³‘f÷Œ¹p‚Óff# › ‹Òf fek¾ $­Gö¡ÒÛ +n|âTê\T ®Œ°´•EÁ[çŒIŽó…9q=b¨Ü(¸µžYjç B´¾ïE¹þÖwUÁ +rùc<ǐ:BJ*k…Æ(™´àŽ§Ï4$ëd8ùeH„ŸoQÙF7xØrÙÒ³å"4PøK”ž7Ô9kêìųž´g7ºän¢È¡€¿ٚҞmêZçÃüNf®aaáÑ +¨UÀK_·õ‚41‹u>ÿ ¢}4oèZ„‰B +'©©}‰reàK›Oœkíz;ü‚bñÝP°X†—|ŽàsÖúìóÕ¹ ¯ ]/çO£½µ¶arUt•ç_íÞyæ¤=ðýî¾ÿ××ëNÿÄÏ£a2aT ­Çx“O-¾<²Æ­,9dx×±Ìd( ã\bð¡ƒ@÷¹¦“ _ ?hÀpVCkKK²ÊÀ-ȋ䵄@â„Þ7Ÿm‘hH +¶EWñn5²Pf+#Óµz!ÝVÂ&m„Qº±tàR”~a”²æ¬’‚c8¥ãNS•WrîæX3vžÓ««g;~?CHÌw®º½E£þM›‹a2{E¾7Z»—Õ,¬‚sóóóø õ¢“`žè¹ÅWÑçñąUnݵÞråX €«pvñ\l$Ñ‚Ñ tG.¡¥bƲµ®AyQä¹lUQtR÷e¹À3^¸*mzЧHQüÕ§ÀÝ\‰B¯Ð:źAEä4HChA`¤9œŽëŸÊ¨Ðú†¼çc×¼‹Ø”­Dô+è5úXÄíáh¬·ð}üôù.Mïý…4½nŒ¯uåŒ.î¥Ã¿Âû4õ9¥éûj£Œ®˜©Iy$Á Üo$†£ÇçQlÅÎRc +øbÑ=¯‘ð|͍™ðÀcäùU#yÆzïµ($ªÆðÑÝ'D{5¼Õ°ˆ¤àÿ£Þ"tsJaøä‘VÚî äN=b8?+Ö ŸÚµEK1-3È×N7œy'qßÏjéù‹ŒÙ‰‚É· TSæ¿¿À~ÀÉícyâc ÕaÆ#£B•Ê…á‡OèŠiä,¢Fn$3TÚS*Ûø:Œò¡‚-òýËå„ø7u ØóšUà”e¢¢ÉjáÖÏ¡–ýA£ö r²Ê1~vQÆ/xÖK!š Ò' ŸX哧£$ÇÕ>,7<ÁãøaP„sXc€ +PØã²pJ +Ó,ˆÄ>€ýÊסüÕ h¡ë)šê[šúï7ÜD¡v³¸š 'ÓdH“ËQ˜ø÷Wwo¯Xƒ`Ÿ¡w:k¸fž|¯Ž÷§#¿ûÿ÷ׯ1¾èÅ/ +£[Mÿ<ùY¸~ùendstream +endobj +513 0 obj +1629 +endobj +514 0 obj<>>>/Annots 72 0 R>>endobj +515 0 obj<>stream +x­W]oã6|ϯØæÉbÅr;¹‡Iî+è吞 EU´DÛ¼H¢JÒñåßw–[wô¡8¢HîÎÌήÿ9Ji„Ÿ”fc:ŸR^Ý,ŽÎÞO(Mi±ÂÊôrF‹‚FÉh4¢E>˜‹j)h£­#§iœŒ©OҒÝ66ŽVÚÐýüËÃ-5FÕNÕkj´µjYÊSZn‘ÛHú¼ ¼T²v´SeIÖño#+Y-¥á7N_F4LÏqÁ¢4F>+½Å5Òñ™I»>ž&^¿«I›‚·jZ«gI¢Þ»£‹äXTÒ*qLÙ@×å Õ2—Ö +óBjE/zK´ˆ ‡l­ôÖr‡SêŶÚÖ¹Sº¥r8¨&QvrJ…,¥“!c#×Ê:Üô$_, ku®„“p• šgܘëÚ Uc]Õ|ßÙ{ÔRÒ¡òçÇß>ÝgÙüùâþÞn¤·Øjt9—Âç,{`2þ +'Er Ñdm´.q)ß­rIºöµ ٍޖE/é¥iºi âçÀ¬Ð̶Û(û滐#Q·o²ìñîóçE–ѯ᭴Ml:œ?5Ö§¯‰ÇS®¡–Q­M%J*”ÍK¡*i€ìRCd²P^züR‡üZm¤‘^<¯Ѝ¤\¹Ú–§NAOµÞÑn#œ×VBj}Ñ1v}èXxŒ´NfX¬Àeym¤¹Rµ²‰ú5è5ÍQæ¢,ùUh]x×>ÒªÝj¦8+ N¡ ã4‡²ïÒÀ\*0ôBzÅP£•.ÔJå‚ Ð²pk];w±-Õ™ñ8M.h8¾ ®qoܶ^ÿ½[±Çy£ ¿¾|à'4™¤ð Éå ŸÓ+|D˜óC—Ärzqà’,•.K½ãämµLЊaà@PtŠcðÌ*¸–Ï–5SH]ë ̕7Ç &(¯Y­kTí[`¤›T#€R±Á¶ð„–e€&Ð:n§ÆZòAŸ…o¨³”°ÇÙIؒ·[†³äí^›§3:<×:Wê˜ æÿÛY¥L#Àÿrhà”Î'cļbê¿gpDçée2=àð# ’i¨]#›ËZÀñ¬ïtm×c’+µ6ko~û߅ÞRÒ +t öPf)4ª%Ñ}ÊLoø® +ËõÅBѵ„Øå7ô¬÷”°'µ6O> ñ%-u¼Æ6»Gm4OmÔJ›Il’ŸDñŒž)Öh+þ^¾÷·Äý²0;J åL†{…”™F íۜúKÉfÊ @TWRȕW20zÜȚ+Î眬ç1ôJBðôz/úÝÕL=·NTʊo[¼½ñMb%Ma ñUZÀ¼AË/±2a^7asˆ(xi{@ÿÊWⲓ¶Aó+g xàú» +‰†ÕÈ×÷ë2Ä$J+š  ¯Ö¥ÈŸvÂ@Eh ĺT~fá±,Z Ÿ¶‡}°–cîíá|þ 0t “ޏC÷Wî4ÀC~¨³ .ÄC ‰q{M¹­ÊZÿG±F:‰ølDÇ û>Ú« “WN³A˗Šéq<”q½$U͍Åo‹ƒW6{±,d‰ˆyã|ÝÆȐuwì+_­PžjÉvÍAäå¶hËs_Ô~¬‘èkÌx ó Ü•H8=˜«½¶½<ÃRäc:–X}y˜5<Æh«Ë-7à>¬¾Òâ$Id¸~xä2‰ 3²xږ6èŽÏ|!@s9r¾67ªÁhÅîƒê.$ҕ j?L²ý™ÔÞ»¦Éø.x”î*j¯ÁƯ3Âñ‰ÃDÊc†‰ó)O!¦TQ:'Wíe˜'^ǿìù Y:õÚÒƹæÍٙj£H,„ŸKx- Ðg|ÿëQþŽÒ½DÕü¤<£Ž:µ 4]u tŒ$оVaºl§ƒt:Kø;${߯ïo®éÁè¯2wZòm…Ö×G9 »†aÛ`’œ'“Ä#¹ÛGöÖQä “Ùqø!dœ¶8ÿ~ô/Á˜‚endstream +endobj +516 0 obj +1661 +endobj +517 0 obj<>>>/Annots 79 0 R>>endobj +518 0 obj<>stream x•WMoÛF½ûW Ò H”HYþÒv.`9…æPõ°"W&c’«î’–õïûfwII”}(bÄ&¹œ7oÞ ÿ=‰hŒÇ49£¤<¹žŸŒn/)Ó|…'gç4OiŽÇ¸“_2±®¥¦iHF&Îë-ýJ©*E^~E¹‡¯ç?­¡èÔN¢0†©`F!ý¡ò*¯žHT4›Ó{}“×Yg vN)Š¼øœ_¿«H鬔&áŽc£_p³Vô¦½]րh«*SÓ*×ø_¤)ՙ¤™¬¯ï©¥$µ²÷lì{LÃhâBÞç·8bŸ°ªì;ßn¾Pc8ŸGƽ¨Ä“Ñ%gB¢y–J´µ4d_,E’å•$‘$ª©jØóÌþ¼¯E7‹ôxuÒLÕDmS3™jŠ”º¼\|Ô¦?ò*UñÿPúÙԢνÒ=‡.rðŸyøš=ÌÝ­¶"YËßt^ ½…%ZŠä¹Y·ñ&ªªµ* ©Cï#> A†4¸2¦à\”L¼ û~-ÄQyœ°Õ2" Ç¯ßÿŠŽ‚ªRZZìæ1LâIíìÕùæá¾gn@›,O2ÄÉ(rßŠ¹sh4€)œîY-A¼z)ÐÂÚ÷Ää×÷Âcšš7]ß|y†ãp2öve엧밶™v$ø2µZ°ôݚ @@ -928,13 +1001,13 @@ Y Ás~ºqM‘¨²Äõ§Ã(NK­Tý‹&j‹jÊåZ³Iiø“" 5ÿbäÁÜ3„ÚlÀ¢½¢ï"¶6,ìè$¶Â²aÇS‚ŸVU±¥¶ís.ùúf»SméÕcÏ š’RQ‹¥0=JhtuHw¬+¸Æi’–VMaɿɁ ‘ÜȒPZÍx®™OV=eÚ6Ù~Ÿ°L[­¦ˆÿúþûItz‰¦›\°ø–GÓðÜ_¡xNì[&Œñ ¶‚·“{H)ÚˆI]æ•(@O֑B綐zÕOPí"¸X|<'ç™ÄC@(_sSs_§òEj]JÈf¢RDÓJ‹‹m%ÕÔ,2ü8ñux{é­5υV€UõF™6´”`ŽÌ@¥NÉÙ«­a¦ÖEƒ–`Ë ËB’QPXŠZÄ ¥U’¡‡-c‹â8Kdèû†ž֙VÍSvq«íÌB¢aĵVµJT1àã•#/›TÉ xï ½¯Ænºµ¬oí¢"h@6ìz1 ”¼’J€‘Û7<@Ó\ˤV˜|Ûé&êÛ1Á¾ÑƒwcPƒ¢hPzH•Ò%”eKïw¨1zT(ˆùŽ—b´Öù †*ÛÝîèÜ)ÍÝn/‡¯Œû…RφŠü™ ï6ÞÛ;üØứÊÃýÕ݌fW÷_sîºqd‹9ºm_ >;Ðڕ`ˆŽ^ôï Ê÷µ><:FkV«üø¡¸ÆõQo©Ø«'J†ÖU\îjù*Ê5ª(–êEî`¡®*n^¾_ –;…#ÛÓç=øcöBYò°Â.%˜ªåº Êï‡ëüæšÀ×9ʚCsnvÂjßã²¥}l°jY›°N—‡¡=ºÝÃ}Û} ;F—ÚT0¼Ü&{¡VøŠÔö4Š ÛX¯±óa¹¡;ìm®Ížå–U†;ÂM—aÁ*ÅñÀýn›ô{3·—UW³5µ,Ö£ßåе݂Äpsã–.“ ¨p¯°ì3 †ÖGtv Ù/i2@ðí…×{¬ôS»†íD~¦6¯oHLÒVa9 Çáv¾wk4É4·«§vØ €Ñm×èÿ»àjLß»¦ 3DÙ­påPéY” Õûö{Ä6"€¸<ñix¢³I{ÑáOñ¨÷mÃ2ºP|"`ŽÛêx\÷L°½Kàj·öÞÀ ÕIßÝÞ”M¬3ÐÎÇ}X -þL@ÛrQþ~*ÔRÿ°»Åóþéˆä±f2e}ç^x1Ú@†>ñÿ÷-wzÎHâ0 b»má?Oþsõ<‹endstream +þL@ÛrQþ~*ÔRÿ°»Åóþéˆä±f2e}ç^x1Ú@†>ñÿ÷-wzÎHâ0 bûm„ÿ<ùsÿ<Œendstream endobj -475 0 obj +519 0 obj 1558 endobj -476 0 obj<>>>/Annots 83 0 R>>endobj -477 0 obj<>stream +520 0 obj<>>>/Annots 86 0 R>>endobj +521 0 obj<>stream xW]oÛF|ׯØê¥ja3"­/ȃ?ê"@夵Š húp"OÒÅ$¹;ZÖ¿ïì)Q²‘… H”ÈÝÙÙÙ¹Õ×^LCüÅ4MèbBiÑ»^ôÞ܍)Ži±Â7“Ù” £ápH‹t`eZåvôŽ2]Uþ´øÒûeÑãü]ó»?~íMGQB“ñe4¡‚âÑ$š5W9=„,£C–É·uóÜËgGéF”kIn#©IӍƒ¨ã‹htõ‡Yӛ»¤É½HE[m×F×½ã4‡þÑBP®JIªô þ^çz)ò¬8¥ñ¡&#EöÖÃ=Ðxî3Ÿ' ]dƒN>ºý0çœoîÚ CÚß',²(Køg JQHÒ+ÿ>pO[IÂHú¢U©Êu´giœDSφÈWP'QÜ\5Üq{0‡Îþ¥k*jëHäVÓF<â+a×IÓï†CðiO‚Ká¨qƒì49É25»ÊQ%¬?™ý~'¬tLx öŠì¤m>jp»%¬´¡® ÕV°ªùáóê<¾€`ÑQƒíÒ©T8P =ß÷ úx{ñí{O˜ßÑš† gžmuàwãË®¢ïT)ò|wF"ËèóH @@ -942,300 +1015,464 @@ g ^Ç&¯rÌw)œz’,Pµòà<0[,3. ña÷<Ð0el;¡Oî¡Â™ný‰àÙl Ç£`‹滑cÀg{:@Wä @|<¿”ô6ˆàp,}CE?‡{_ ¢ÂË6:;£íF¡E[x¬bydu*3¦;($‰p Á<×ÛV6M-òR L»eO.$TÊøH¸“:á™–6¢×Ô¤'©ð´¡¥AŸRa…A1Q^ðéýýe‰¥s­˜ Z)¨ûY#ë(´Ã.´±Æ9mÝi×÷†d¤uÂ¸àŒ¡þLHhho†°ÖvÞ>)Íܑ͝Y^mqö´¨Úýà¦!ìt1œàtͦѐ@,‚Ñ*l—X ž‘L“¿GI;bŒâJçV$¼ˆ¡ù3âøääee0åŽ*©«\†sLØG4×ȵ0cõslï­/øG”ºT9/6¨ g”®*¾¢%/“·l¶žÐê&áãZ,‘ØS 0¶Kô»±Xd=‰ÙôTWÒ`Èi õ ÔÐE˜L>.d›µ]%P0BÖ5Ô [¡˜ÿ¥t[)֒*“ÖZ\¦ÐKT|­Ô÷Yú>8—™<,˜ A…³ø` gJg!»U.Ý'ªí !XDtõZôêeôºÄ<•Rf<ƒ«–î—“„sKEzùÜØã~ C`¤½fZ‰:w8k5Ñ#€á°Ž[W•6/FWºë÷<÷‹ßæO±Ÿ€Îl1Õhfe¥»ýdXîÚÞªæòه XÁ¾BÇlü~'OªôŽÒô§ðƒæÔÆ 1ŽõôŠ(È:YÙ7óš{gKÈ7åÙ°Óô„WÉ=œÖÍ+ ‹²ÑÈø¥ëìKn`¶=LCås*+¿*£ë^Š>cÿ!ì˜\±–¦O+£ ÏØBg¢‘U.ؤ—»Êsÿ -8VÖ[È:u§ñŸ@‰Ñƒ’éFUËöi>¿Áò5W©ÑV¯…ŒL4î*­Î%ö±*¯alžÖÆÂf—p§×lÖìñdŠ%{šàGRç×ÒÃÕüúŠ>ý àZ˜Cd„ë’k8O‡ÇÿÑñFø51ÃO38]â·#`ü½÷/ž}uendstream +8VÖ[È:u§ñŸ@‰Ñƒ’éFUËöi>¿Áò5W©ÑV¯…ŒL4î*­Î%ö±*¯alžÖÆÂf—p§×lÖìñdŠ%{šàGRç×ÒÃÕüúŠ>ý àZ˜Cd„ë’k8O‡ÇÿÑñFø51ÃO38]rÁa€ñ÷Þ¿ž‡vendstream endobj -478 0 obj +522 0 obj 1533 endobj -479 0 obj<>>>/Annots 92 0 R>>endobj -480 0 obj<>stream +523 0 obj<>>>/Annots 95 0 R>>endobj +524 0 obj<>stream xW]oÛ6}ϯ¸oóG±üÐ6í`I³ÆEöÐZ¢m¶©ŠTï×ï\’’µÛÃPÔ B‘÷ÜsÏýз³”&ø—ÒjJ³%eåٛÍÙÅûKJç´Ùag¹Æ"§I2™Lh“É,¡Çє%wÀÏV:'k¬…&+³¦VîH¿bY?Éú·Ÿ7_pݜÒ4\w>]áºÑÛ¦®¥vÅqL¹)…êÅúA”[ iõOŽvµ”t4 ¦$:ˆ'¥÷ä eµNRa2QÐ'­^¨UÀ2T˪–€K2† §³dʶÃKÂ9‘ø&~××rBv«”B³‡Â‘Úµ ù(—À™witýáöóg`ÌãFë눂 éyW¸‚ׁ·1ã®%i)sën%‰¡«LM>t€=Lðˆ;/´S…´GëdÝS–­¿Ûœq`}t)åÕÇßϦ“ErIËt™Ì©¤é| ÚÂSA,ˆ"]a³/ ÄúHV•ªЂñ¦M‘ƒ®Ö­¨ŒÒäÒ3Ûý»ai±xe©ÿŒÝõ4I8^C¯÷ÔB¢û^˜žûî¼'çGc¢gO|@ýlš"§JXVBmšýã³çÁT'*Ñ`C;• §Œ†þ¾5ÒB}Q{T:7ÏãÝ&jŒbp¬(%=‹# Û{ïrA¦îN]®ã¡\<¶¤¥r"f‹å,Y"fét®ÂS³ÅrŽÍ~Ìî )¬ÖçoˆYTEÿÜ·˜$³Á}w^6à."ó[øO`±’õ¿ÐN;8¬4~ËÀ(ë9lª³[G[Ví5}º»ù‹…0°ç…3>8K›–ЊM,| Q­lB!é3'’_< y[àAS.Ÿdaª’«É¶:; ¥¤§Xixo<ˆÏ¶qô¬Šo<µ‰8ïî±Æè$žœrÆ¡@mp§ÈŸ„vb/ÙýP7Î r’²/À ôÇ°½«?8ÄrHR ³3½‹ð}¼KJ»†e\*_D†ªíÝîÄë‹$ªÿIÞ!orCÊÅzë©O«ÕPñ,ió ‘Ôˆ²ª¸®w>«äR- /{P•åÝ£éPX¸HŸG*‘ÉØ÷ Ež̇LoA( ¾¡=t´„LF½ÂÐyŽ×q²GB±òªw¸=}ý6J³×‡M–™²Š¯ µpã!+.*cÈÉb—Y´í绖Ëî:îˆ ”æà%åB–ÀÒËwhôSß ¾JYÁïÌ Ô™¯a¦’h!¾, (ëi„hàÎç0î* þÄwrëŒö a’Ì7VŽB^sË÷\ö ¶œsvÊ­ÊjcÍÎ ¬wöAÉ’:c¤uƒK òÎìz)|²ÿMaĀB4…ƒyf}[\@GmË_äы7¾/\äZ‚x×ÒZ~Ö 3.Scï%TǬ™Š9˜>ù îÐxŽ +ïôB'k;ÔÙjáNi®¯°à,BÄj÷y^r ðð_%z3a/¼ÍÞøO9­9(߃ïùÌ©€#`»ýĤ½t,)g›œ{í®í¶ýÎa›ìÀâôòÃÍu¸°P¨"f7 r Màtb‹z¯÷œc’.Kè eÛXߔ¯î` u+`…÷(öòÅI£xFþvk0ÊÅÊ2°îÇ!ö+vž_1)…ᘸߑ¨ªB¡ípÉeB(  ?!âÚ ÇBÛõN^^EÓ³wb/\®¹~ŠôT_Ôbß÷Xó¶"ûª¿ÀbÃøÄÉãä§Ì~Í;I2S)¾²jÄëX£Ü£ÅTEƒȲ*0 1™Ay±VJý¤j£¹ó"«…CÔ9¿<3ÜÆÎv}öâý²÷1;î݇ͻ_ø†ÒÙ*M~ì]c”šOטšxP]S¥NÅu–â¯Óù -¿ý¹ŠnYƒAîä ‡°†zr“5~ŽÀÐg‘o5Y5[ópÒˣ܂˜½ø[é0)FtžS饛—GS¡uÓX7ɶ)àjáéÓ>MgaJœñPسÞ#ܾÄ(~Úë=–´æéú´×{Ĥˆƒþ¥üµÐak'Å NÇÄkÃBð)xwóp¤ôòôQì.èœóÕ«uÃîšæ€{ñ©¶ ±ëèt¹Â8¼šâûµ÷!ûpuûæŠîkóýƒaˆŒŸ0Øêy8uŽýŸÏÞùj`lt4Eqýyöw_Âcendstream +¿ý¹ŠnYƒAîä ‡°†zr“5~ŽÀÐg‘o5Y5[ópÒˣ܂˜½ø[é0)FtžS饛—GS¡uÓX7ɶ)àjáéÓ>MgaJœñPسÞ#ܾÄ(~Úë=–´æéú´×{Ĥˆƒþ¥üµÐak'Å NÇÄkÃBð)xwóp¤ôòôQì.èœóÕ«uÃîšæ€{ñ©¶ ±ëèt¹Â8¼šâûµ÷!ûpuûæŠîkóýƒaˆŒŸ0Øêy8uŽýŸÏÞùj`lt4GqýyöwiÂdendstream endobj -481 0 obj +525 0 obj 1671 endobj -482 0 obj<>>>/Annots 97 0 R>>endobj -483 0 obj<>stream -x­WÛrÛ6}×Wì[‹)YRúæKÓxš*NÍ4}ðL! H° (Eß³àE'I;™ŒM Äîž={öèŸAL#ü‹i–ÐxJ2ܤƒ—¯_Q2¢t…O¦³9¥¢Ñ‘·QzåhÑ»#oéÖ+½®¢G‘/%Q}!Q‘x‘~Œh˜LpÃŃӹp{º³¹Ð¿å5F9>ÅcãˆÃq%üÆ4Š#ºòóÚٺȚsSŠãö\2ãS×µßX÷SE ëýܜš´§.(ÝèŠ2+ë\žð» ió¥.„׶ »¢;±Õâ…-pM_=ÜÝқwÓw$ŠŒü¦-°­*7Y.Ò®¤××õ›>¢–ª.•“Je*£å! [¨¨½(™F ?•«Ú”šJ§­c„2JTŠ‘¥È8®Q€!)J±ÔF{­*>(¤ÀÓG]dvLRšD#:Åþ¬€C'èé5?½ˆ°)Z¡=v§‹5Ѫ.$ã%kOÕÆÖ&£uŸ ­ä†ð`а+'kúlìÚîrgI½L˜QÒhô¥¢¦m²mÛpÍÁt÷)™ÎÚ»žògÃýÒÉŠþöW_ÚK9µºUÚ*C•’µãì4”SÞiµm¢]y&@—Á&i‰BÍ‘MÓAfÚr”ÛËEúÿîlÈ$X:»ÒøÑÒÎèRù½m÷•W9•ÖhÉüúŽË‡ÉTí©pJ¦R+‰ëÞ)«xT -‹-¤©yVÐ?:f};ÏHvœ8¦.(‹wuõ…Î!\‰¢…Øi ôqÌÓ3 «³£#´žiq æ"e‡¸Ž¼7 æb«¥¢-x$ž^| åîø·f¡›¸ë,cr6”ÜjÐûÀð»(Ä?y -›Ü¿«'w !àc%í` £ü ”’ß”[*gÂïoÝi§¤·nÿõš¿5ügÌzh„´Q¨Vø>£^ f^Šr•#—À>цQqXÖ)[{£‹Ž|¼.œ×ÒôbÝõ”v -/rXE@o¥5`È}iÝI*Í@µülwc•Fyeö”éÕ -7bEY¤&ËWN_f 7hÁR)Þa+L¨0¸¦ü¹¨ÊæŠÈë¼O¿£ÊÂ)¸Þý΋F—´Sak¡¦[K‹ò¯ú8ԅùŠªÓq©g%t«€²cN» ¸žîOL˜¦ œâãC ’´›"ì¦C_¨ëöÅ*«³°ËMÅփ1‘­[ ¿˜ ¥Žh¤ƒU8¼ 6¬aéÞÅpapÑÿfSsä_Ò›¥à˜(æßþøu0žñNÆs¬úœ&³«hÖ>zdËž ->à`µ4³ƒm Çãêxœh&À¸_ÑÞÖMvÌrÉ[ èñè -ŠÀ9ÍÏ­éâÃâþ¯¿ïéõÛ·ÑÆçæô\¨ˆÏ]ž‹ ٙäâ3ûœ0˜Bdö5Ø°çê@GVÒ:|puÙÌxÆÞ5¢šk”€É¢µµa(+\æ5›à€.%1,¼šb94 äÑcN³YògG9Å£`>ä<=‰Ç0!‡ŽTù2âZž.®ÀÈ\D%„õX¼ûã~[‰‹–¢ÂÆá^*¨,i!/¡¥³p}ÛáÎc›÷ÜwǑf”Ÿk1ç8„u -_ÍÏxìwÑ-0-rd¹„ÅRbø±Nƒv²:ˆFçڐ³¬Õ¦“Ib˜\ø0„÷|Óå\˜ÈLy¡MúÈ ¯•KsynC.IyEà -¾~ÀعKNììC7´ÚìC_%V¥’RDíÈ¡!fÞÆÆUûp ‡ð>>>/Annots 144 0 R>>endobj -486 0 obj<>stream -x•XK“ÚF¾ï¯èK*¸*$„q¹R~­íCÖ{/)¯ƒ4€l½, ‹7¿>_÷0 ›­bÕÌL?¾î釾]¹4ƟK3&EÙՋ»«×wWc' éðU­@`›ë9>ùá Ïþ,Às¥iÉG° ->û/ì]ÏÉõén öAˆ‡XÖÇt Çsèe‘/“Õ¦Jò™µ¦*[(zUd*ÉyÑTEšêêÉݗ«Ñµٖ×Л×à'–IUª. G¢J+ÃÌm‹ê+?Y–·¯^RR“)ˆ6y¬qF屈,U¥2mðå:Òu­ªGfUg '‚zÑ;Ú&iÊJ*;+]6õÛ«Évvím°ýUÁ!ßö&¤}!z‡ìì6ÐmOö|2Vj¡Ö˜Çý¥£ûA¶AýØ (ðc³úLèû'm¯ù~(^“0±DþþüÈi;þçug5xõ¤òHzÕciàóRÕ5îSŒ$ĵÅãÛ&©t¦sC’¤85u”GMâÚäº>œÉ•!¤íÝ{Úè7âÂϛÑÄÜI+êMY•ÙÝдXy'B'áä¡–¸¬ê$d£Úª6zà}úZ^Rs+e…¹6\n%>ʪX&©®ÿjC;™"sŽ ­–èQwÚMÔ¢%P5ëó€ÞãóÛÍýýNPÞ}a«:×0Qû÷šÖE¦)F„D0M²¢ÝÔ$ÎĈhvËԂ{MΧL×èñLâ)ô`ûDˆ£ÇáQ8Y³ã*y¸PžÞJ}ÝUEoÎ=gµ%.Kõæݶ2ËPó[/]—:J–À“V:×Jº`› {ÓTœ >>جá%qT¥Sô­è_8¸ä&ðj¸püŒ -‡›ÎJﱘrÖ¤SOˆ,¦þIXeÏã! -8Qó–£x{Úê˜EC±¹¹}hÕZÝ{ËöƒYƒ{\|Y ÷¸>\¾C£M]¤„Œjž2Fi²ínkâÎç­t=–èÑdl»»V³ƒ"£Õ"½gyёr/Є¶+Äe™îCT« Ù²D4¾µ½Ê?ÑìåFÅY"Íú¹멍;ñ*çAî|;™Mh{v—Ÿ¤í݅ª‹ÆQ#ö¬%zlCóؽ¸=žÅ䄒2 2ÊM£CÝÉÔ¢Ë}¬+Dƒ@÷²?ú,×ckq?9CZ¢G$&¯#TfY¤`UœOútŒÇSÑÀrË>çnÅ¢G®´mc…¢Gô̊> æCéy–bKx<çöDZ”?f©bIe‘äF&q̾kLBÿaà²S¯Z`ŠåOÞ !6ó¼±ÐNuAÒ¡Zéœ}7³¢Ìɱ6*Ik*rTÁ-g֘“kRÿ® -4~ià›ð”Ïs0ú$§e!΢¥ÐvãäõÍËÿÞÞ½{ã¬Mvn"pš±+jÞg ¹˜ÂUÚ½̚õÝû^ÞÛPw“£˜}²Ÿ"©ñªáÃïlx<t3ïÁoƒæž3£ëŽZœe- ¨ðr'¡3çw:‚Ààãó¿_<§Ûªø‚ïo¢ 7£âAf:tƒ™ƒéxæ ¿_}õãϸvÉQoڸ럫ÿÃêÒéendstream -endobj -487 0 obj -1670 -endobj -488 0 obj<>>>/Annots 151 0 R>>endobj -489 0 obj<>stream -x­XkOãFýί¸RW"H$!œÀ·,”.U¡Û’ªý€TMì ñ®íIgƄüûž;ۉ€îJÕ²!~Ýǹçž{Í?#:Á¿MÆtšPZ|œü8?8L§Ô~è'à¶Ét0¥³é„¿ñ¡%-ù \„™æ·oÎh4¢ù’Í&Ó Í3wà ÍÓÞ|%ÉHý,5•µ±´dq*S¥È+*…±¸²Ðjƒ›ˆpJé ߖJӟy•á<¥E.+KVQ¡Ra½`SGó/'ԝÆpÝ»¾ŸÞ¤!¬þ©Äˏãd®Ç°ûã)íŸ^ 603ô ʅ 1ÎfJª”%µ\".A©*ׅD9ÿ.™°¹BÜKzÒª^#§õ:¯ž©ÝHYQ“ÇýÜ߁«Œ#tàG4G éï?œr‰û,é,Iš£‚\pñ '»(ÿqûW4þس«Ü~´E±¥êẸsÆ/c(å˺à -0ä‚ÌJiKf-RùxtL[Uó©ºÈ`ƒÓÆ\5‡tSz1êßóÅl3¢dÌ*éô„ƒw|ç°¤óñà¢s™…CШC‘•¯F­M°>áÌ£ùшݴö_egð³k˜+à²A ºVJîØìãj2LÞòñ1îz „'Ÿ’cÊ.š®¥M2åbªjIk¡E ªiãú!¯ÐeöåµL4A×¾›f —CªïbhZÂØm!I¤©ª+kJ_pƒû6ïvùðæPpOŸÐyâ;«mêdp: «èÿN¤«¼’4×Üà³àÅAü³Ê+ñʵ°¡H$0ÇъZxÌÚÑ»É5ì0bÔÁX®Øf%,Ò-ƒC놴˜ðÍ=”[>s2†ÎeÌö“rB‡¿cÂÑ-bEjSÁÄb¿F1D,jÑíZ³há„EÆ5ŠY -]w„ÉH”̺Râk Aå¦,늻’%d“Û•{<ÔóJUV«¢p>?É*õÒÜ î¶Œ¨’/´RÀ-w踭$‹¯  %©”åG+5x!S ²FìÖÊèÞ[P3ÎvUZ!ßJA+ÞN·Mêj¿ ¿²ôÄø¡ŽŸ¯¯Ž9óz‰#ֈ è«2 k“–O¹±z‹ò̂~Þë±v6¸G\‰à#ö[€ƒ^ó†kÄXwèQÝ "cDàÄ'=öPG™õlÆ´t£°‡.vw;´,ï=EâDú¤6\¢ãד6¤*X÷ñìÚ$Œô=Cd7 -%Œ,©ŒWÁõ²€ Þt ò®E$ ‰V’ô%ô4ƒFslk/r¨À-× ˜ -#]I[äpÖ  0Q}­Ð_{%zxÚﻢ€F;+œ{ ±‚wÒ.r…ߨÛ÷N|^š<½!Áà"v6´†=Ú¼À¥Äßɍc˜A_å6Xä ûŽt3€ÉŠ¶nxèÕ -¸0ÀÎs»øpÞ¥—¦'X IÐÛµÓöÆK°uCOìÛp×A¯ÁhU’CûUô"™Þޗ0Y§¬¦ƒ€ø¥IKì½YÖ´üF rKCž5ÂجòtÅuÔàáö•gÚí%ò$+ èdvLØoÆÝ~Þä8½ -cQàg+Û¦?‡Ò¦ÃW;Ô5{Ó¾`óMmY­µ, ¼ÈŒíïń@äs—ÓJú%Ëuœ_›:žé×m.}/vÖõÿöø}Ê…4ëöëò“FЮ*1_åFU‡6 æ»•O¶Hî%\ÕÀˆOÖF Œ4J†Ú§fèð è(_¯ÉI’2Tfj½ÞÂ-o™±X{9þRÛ½ Šü+HHÌe´tÁ;ÌÍ~îG¿sûáòåòüäÿG—÷ó;¿N\3ù<ä¼.‡‹¼.EaõZñî³!^ÈÁúÛ¥[QXeK'”éFa¹_÷ù–’J¦PRr#fç×:Ç­Þ /a¯øiXîáŠ/D=o!l:K¬ jÃx]áj;Zr ñ&&»MTRl,™—'ÌT7­Úvè°\+etKN¬S÷ wa×aì„(ðí¶›Q2Œð®ïßC{³»3ú¬Õô>ÞFÒºy/æÈúþöþdŒ? d½ÿñíá ï9øã['ì -ïs¿ü ¬c&Dendstream -endobj -490 0 obj -1755 -endobj -491 0 obj<>>>/Annots 154 0 R>>endobj -492 0 obj<>stream -x•WkoÛ6ýž_qlˆ -Øò#‰|†<š6X»t‰‹b€¿Pm³“D•”âúßï\R’e¥Ýºpl‰ä}sî嗣 ñBó)Î(Ύ®G¯Gãðâ‚öfcšž†S:»˜ãûdŠ#iÅ;ðÇ´X>º;£É„+œ>»˜Ó"qïÇ´ˆƒÅF’•±ÎڊéÅFŠRåkÊD¼Q¹¤ÒT¶$ǺÊKKÊR©I$ •™‘Îù/­Ò‰Ò}-U†Mx§Jæ%oø¬q6èW‹Ï>¤ÆÇ ;úøæhz:E8³ù4¼ Œ¦ç§á¬þ•Ò“ ?Oñ²ë<It&TÒ_º¢­JSÊ¥³D*Ó*‘$èY¤<ÔÆyU»Ð5ƒó³ƒÝßx{yNzî´ v ËM}']ª*+ Ùب¢dûûò¸oØP!ŒÈd)MHt-S½åĉœäW‘©¤{Â!H7ïzcà c`‘‚eòùŸá÷;•W_Éîl)³WîÆtÉåŸÐpzž¹¨_Ç)ú•F•5#©_¤áú%òy”WHëpM”jhiÄkV"…7Ã÷ôKEÞFƒ±![a?à×}NO"‹¡¸áxP¯œÕh tÔpÖ-ÂO (F"ÉÎ2€<ϼ²t…etwI€‡eäüô‰³ð,¤e(ã£Tf ބ^£õŽ4™C¦¬BÁ=7Gé÷\=ùù„/Úç Eâa¼ù„+:idŠº½Ë Ü*iº[¾úفö1»çAQÊ œa¯DQÈ<‘IHwFÊë§[Zˆ°W # ñۚ–~ƒ[Ÿ” v…g^çlDŒ}ÊPm'F)ŸS–G¿ -£×P–™pȗÁ¬%!¢D€(ÿ¶TH³’q™îBzjùä}êÃêÊ«ºK -ʶꤞ7{VŶ5àY&°É)u¸°r_á'8-¤ÓdÄ=Ûn4dÎcÔ冏%µ¢¤9ݧ°‹ÖVh|¼‚ýp/W_ ö•J觗°«asOkG¹4¡cn"’mÄ3‚v˜#CŠ5E;ßn}— Ãð˜h»‘ù¾Mî¡ZkÑ÷Ѻ€&Á }ÔÆJ³—µ‡ÑÊè̹ÐS•V¦+Ç.3>=r°òhi ¬êÅd™ý[,“ÏØTÓe®¢0þìf/ƒB[«"¨4z¨J°®µÒë¯(/ã&N.K%uÙí9§%âê«\•J¤Ý<{ØöšÛy½µ¡ù]eØ!€ø£Ü!Û⁦™Ì"ø ‡„ûÚèª8ñiqƒ Œ[è„ã L2xà'‡!adÏiž\´Ë  ©D -$áæf #®j&­k‰Žs³ùÚÇÉép.x{,ñ-S՚$ú§#å÷ꕉÀ«ÕuŠÐm@!.ÓA–Fw]Yý¾o¼Är u¨6æ¼dC,Ù -5Sè%\’Uªbh…S>?”u㠚ÐÏééΓ­;l#œQ—âHX³Bq3à\glMó("ýŒà¨÷’{L6oî/؎›q܄À]$ÕkWÐv܌ñory½|…sšƒ¾ÑAîÛát[Å1ê¹Âܳ£+.EU@l„1c&Í-ž‚G–•¢fŸwbÉ³Vœ[££/`Ý þ+Š}HÑ«,.?1KTF½l•–7è\'D$PkK#JmŽ^õ`ÍØÊ -WW„‚ÄéœsÕ1æë¯Ã•§û[²8µ„¾H킚«gÌèÓÃãïo>~±þ8³‘bGtTºC(õ ;àXzî™1[+…&Á4ð¶=£šëÅ{p$ªº]úYæøfmt•Cod¶¢1›A|²[(S31T & •hÿtMʼçR]v‹Ñvδøãg'ÊýöõÕ-EFäñ–ãÓàž•"€J7›’oç|õâ&  ÖøžÙG¹á©3¸b‘.ù.Ú¨µÊ!¦µŒ×ÙÄ¢6gõ«ú>Öv”ú1Gj$ëCݹ¾G·f2ªû\}£B!VQ1C$DšD^=جâ`+ˆ…Ž"ÿ…’Ÿ¸Ý; #X'\ì½`9õûy]Ô£Ìd6ç›Þř¿¿<]½¿¾âö3—åVÇ‹U_Ãüòá|Š»tüÀ|†{&.ó¼z:gӘ¹ÿ<ú¯HäÜendstream -endobj -493 0 obj -1834 -endobj -494 0 obj<>>>/Annots 157 0 R>>endobj -495 0 obj<>stream -xXýoÛFýÝÅ (`¥°)ëÒ (Ü$nƒkÒ\­"¸ƒ€bE®¤­É]wiYÿ}ß̒E÷‡ A$.çã͛7³úÏňnðgDó1Mf”?./†Sh¹Á“Ùݜ–Ý$777´L®"ãɺ@*Mµ÷fëoúºSÁí+g·ôÛåŸ7t=ž%S¼PØiúòþØÛ©gƒ—ùÚ…³T¨tg¬fO®¶!!ú¸¡ƒ«IUšjϧÙ{>Ü6!T–á¡®š F“dÌAø´2e ïãé6Á:ì\FÁQZi4µî<·øï]gdlfR>-™@;¡Ø»êIg }°¾FhTæ -e,Œe…±½P8:ò"ü6rIšS-j÷yЕUÁ<ëü@改Ä)PE\HÛP큗­UŽÃMàú@ñY ¼kdbŠ¥®ªtòCBŸÔ“îÅ×$l±À)±XlÞ¥ ¨À_÷ª”ÈëRy¿ÏhcPGÇ(jzTÅZq¹…ìùEå@ >ÚT¼)²²¤3à¯RxÊnñՉ'wT“›p¸BTOL’j ‘®Q« - öœó‰6«ÃÚ8ԖOÒބhyùí%©²ÔV‚t\ÿՀŒN€HQÖ(Ö|þ[Z½Ih‰0a¯öÖH DðÎڅ]Ï÷P‡tØ ¦l„à”c˜Ð£C,¥v%•’TºtU` èhSg½©l@âkä€|ü“GaÏÅG†=¿±"`ã3@m^¢Æ¹a3â§éV郦‰Q@¦Í9¾y"çNBN·±×óΣo¡þ‡åT†nGó䎦wsüŒ¿0¹‰¢´ ä„EizǺr¥Yr €bC}q¹I¹Øü—Ê1zR뮪]YÕŸêtGn#ì0„.Ðn`«Õ,m -l‡,˜ Çßyø͉jýÎ-ÝzãP‘î½”U€¢0Ý<Ó "õãv:ùj´ ˜Ê!©ðÑìW¨Û{B™¦€'ZDAþ…Võ;Ö)öÁ„´C·iÄÿüöÓÅb )œŽɌ -ÝΒyó)§G†ÀNnð° -41òq¿CTª‰6º&`p193Øý\Ðx4N&wÝÏx:]$‹îÓÎg<Žs¨ÝÏMnfɨón÷3žŽ'Ém÷iç3žNægQ1 Ö ¶jK¶WÈ|lyÁµ:–^X×R<8/—Ðáè@¼ÀÁ€Ô³2¹Ì¼Må -údÒÊy· Ò×ÀqšþÌʝæY ™†9«rÊt€ÿ– fÇ~|“‡4©µ«C7,i˜}ˆ -+³û¼UÚ)~œ`*ëq3xÁ/Ù6 ÷7f›”.1œ¦,QCÌ>,Íü}ŒÂsÀUœÃ;Kô‹¨×)´’è_Þ( ~y ]|麝ù¢Ü'Gk$~΀øŠìƒ4/rtVÔrxÁðâʱ‚R(¼f$6 Dpˆ-7nêv\Ÿ{ÆzÔFù>® -bÂõ:€‡ºbÕ©»J½Ý €-³·Ô‹+żÁÔ1)å@0¾ú¼dÓǝ¬‡±WœÄÞ乤Á‹Iœ~€uˆººÖ2$†Jo1q “OØ5DƄ˜=Ír'oz~!feŽ=ÊܟÝ^cú\‰9Ñj’8§ˆ„TÕ©, 6m‡6±=›b´:’`øÐÒ²“/‚i©tÅC»p6Á~Ö\Gü®µ1Ø‹ýóõل>JÑAügmefbb`tÂÞÑwü–¬AÌÒs³ÐÒ·«•8Y­0ˆúE¢ƒ\{Y+›µ±<Ÿ˜Ü¹§v+¨¶x*+f¯®öÆcøì ß*÷.։‹Ån:1d†wB«ðt¹3ØÆìe+]Âw˼–(Gîöжc$‡+½nRlû*}¢ 6'J&Aµz#±wŒb®µnÛùð*•FX#Kâú‘:îþ²OÀM /²¼ _zX‚áq÷}¡ù¦¾œ)ÃJCôêE ’×΂íÓLEqˆ­Ñ‚puRßýzAw/lÞ¥°`è6]Ґg5*­8å¹ÃuD‡±Eìuž# HH)Céâý \`‡P°AØÜ©vݎ]zòظdõúu³A‹¹„¸Ec+tNyh·¦æÍXx¿‡ür€$ºîùÍîO¼a1—y­fnü[WŽîùžÄZŸÿ:ÔŠ¤ 9ÊÃù„üÛi÷’RA3’·Âÿ>ß>F¹”¶•«Ë¶®¸ld9rb8Øà o…¥p&ž<ª# ø…»)rj|üŽÞ½ÿ_­¿Zçr¿ZUÚ?™°Zas‡f»Z5Œé±…‹ÜÄډ““c9lBl6xÈpæj\¦¯ñEÊ×Ìh¬U¶'Ä<&¯(AR[”|#,`/[¾Ü2j¾`…¦`Šféö³gÓäÎ8ùP„Úïïßyû5®»|ٕ»K9&+°Ó3‡ßà˜gÅ¡I±½­ÉÜÁ^á›b}$I립Sã÷ƒd0|‰‘Ç“Ž]ÄK•ÇßnµÇO |h–qd‘IgB½x-~+¯á!zò^†Ù‰Tz¼oÅmñ"WÃ&ˆ|çNØVj½æ‹œL>¹ Š=‰~øp×,X£Ù‹îlÎ[<./÷Ÿ~¼çÅóO¨6½wi͗”ãs_ÏÇøÝ&ü_W¤é|Š»—œßq -¸Füóâ/ñ¤¬endstream -endobj -496 0 obj -2051 -endobj -497 0 obj<>>>/Annots 166 0 R>>endobj -498 0 obj<>stream -x¥WÛnÛF}÷W̛d@¢.–%9/…ãØ­Ûi#åRÀ/+rImLîªÜ¥£í¿÷Ì.)JJš- ¢–œ93sæÌð·“ ñ7¢Ù˜Î¦'¯—'ƒ›)F´Lq2Ïh™Ð0‡´Œ»?™-%†n)“Ž:ï­,é^h‘ɲCB'ÔYÈòyïÇÓåg؛ììõÇÓh‹Ý…Ò±„ÄèŽ#-eBÎЪzzXRmçê i³íÑzß/¹µÜÄuJû³hŽ:!´ÇñtV6ùæ³]èûÅÚÏ×6xý,µ£JnQðDu½ÊRè,´?æõc—q$2UîOâhxäú±;‚ÊeSX»5ebO£Ðô­t]궹Ò*§Bº5¸ˆZµQ¸¥7,«ËóÍç%pî¼M]Êâ˜úY=!ïRš‹Ì7 ¬mUž7“/ø9Šb?]u®”¥âñ ²aæb7xL8'P°,Yñ§ˆ+§Ÿ¯ý Ô©f/0Üb²— e÷ð‘ûÚ -î ìˆÏi › -Òù„Ñϼëaڔ 4/Gì|ïˆâ)ð‡;^˘‰è獄GŽcWæ}‘»~"sé bˆ53 Ϲ&¼º+Wæ qƒØ*MU¬x.?vÁß\ -ëzÌR†À9…¶ç|}†5ÿ{0òxz„ˆkÝa÷Ô¹³âZWŲ¬°Î$ͶñRSJ‘:Y†Ík?j–P/n\,t§ôjWÇÞ㠎²1$×' -Ÿž+ÿ¨M]§µU(ˆ9²µÀj‚µ’·*Ž@ýצÄOÜù¤’\;FZLŽD Ó%¡Nn+xSˆ¸$à$˗ÄÃ'»ÊÛ'÷²axJDhµž‡ÄòÈ\ªúuà<”®äWm¹`™†sK††CûA4"ZÃá3tTe  Î^ùnÛ_±Çº(EA ü¿,H]œ{nõïh0ø]K·Rƒ•ÀË&؟u»gAÅr0ƈќG6—óasñµo>;Z.µƒRó>”¬Wñ&©Š wB;Ôya -R·ÛÛüúÉ ­_·ÛmäøáMdÊlੱ»»Y_ºÐ‹kôó‰kÔÒÏ덈Ÿ¤ãÇ8¶Ù(:£¿q ¶ùK«¿Ø-e3^Ûö÷X«UšB„XTÞ?Ü~â¾à-òlLxóñ»ómÐ츼Ø~'®½° â1/¶—?h'Á p¸RÄ¡©ðéKH»?¶KnÐ)PAº7Z9<Ëâó$"¼¹Âh´ÔAA‚Õ.w/fÍNoxúB)ʝ٫7l_^ªZ¯ÍbýÞExSä¬1ÈÅý—f’¶û7ûÜÌëù4šÎ@»éüÜ󫻸¼} 56Ÿ¡ÌXÉ÷6<~®nïÏÆþmëßl¤º~9_° ã—“¿9'ºZendstream -endobj -499 0 obj -1781 -endobj -500 0 obj<>>>/Annots 177 0 R>>endobj -501 0 obj<>stream -xÕXMsÚH½ûWôR&)#°÷²eCœ¸6N²l*U\i@Ke4sÙß¾¯g„ø0Ù|Ôv+ÛÀhúëõë×|9 ©! :ÔíS”\MNZ×= -CšÌñIÿ|@“˜ÚA»Ý¦IÔÈ¥ÍtN6–ÊD%­”Mh|;&‘¦zUÒ\Š—Y¡ò"º“¶¤™´+)sùšìJE:+–Vš’¦ %*Rñ6‘+mîžN>Ÿ´©vƒÈП=à2èö.Îh•¨(a\Á‚Ç䭊Œ.õÜ֑lá€çÎØÍ£gvsq`ÏU΂‘,K4^¦(»¤Re*Æ9®¹ª[4ÎiׇV nú¤—¹D=gxŒQu`ô±“;À†GTU€ÁÍÄ »!ÐþtÖ%7€¿Bo¬i½ç ¾éšCÜÐDë•„±Ë…Ìí)jɤ°Óqœ&Í賉*DÁ/µÍ—·­0–šhQkQâunNéÈeŠ×œ)‘;eîRŽ?/ã¸}T¾9ÎÁVÀü´ÓTn°ÊŸÕ<2–)Øùúí¨8@ŠRÝq|§o?ÝtۏºkøŽ:WUl{Aÿ¼ @"Ÿ®úUëî¾®&`‚v3 ’²Ù윃‘ëJ^²ET¸Ð`hgÜwª'§M{ÈUZ8PUÇ͗=O^ܾûvòd:¯ÁY·3z&™NŸÏö‰§ÁÀZ郹zf"ޜÀp’izvh´™*§Óƒ›kÉ­ò]0¹ä.fM£×¯Oýtã癒8ÓÞÏjÐ8ÅSðÌ5‰7TG‰Â.A…<ð…ØëMpq *ÙiF×fÕvmXÓ퇟m›•0H¾c˜ƒkêØ „ƒªæž'.Ú´'ïö¿¿«p¸«}Sÿo»z·Lï¢vúæßjí7‘. Ùt§5¨F–YÐÔßÑÄ€ë{žª¦Ên¸\½RZ¢Bˆ@–{˜Dú<½b)3ˆ­0JØÃIʚÇ fµ…êܟ¾$âLåà)t/ɨE²Uq˜%È,óªíµëd;2+äÞ¬g¿WRu±*þXñ|ƒ¶aJ‚Ç)4^Ýq[6$pژNÏŽ.-sAMœ• †Ž7 b)™Aqqeùè”û‰ÅaC¿°ªÜÌ(Ì -5w©eþ8p@å^‹VŠ;^Ÿj惧‡GÀ#ˆãeú¬TÐ&NzúŒ¾˜œ`á ðœ'w?ÛÔÁ…~?¹ —÷“ð9+Ýí~ÒúAЇ÷¯½<©D;îoźÍH!ÿxÿò$Ä4ëR-Ô¦Œ:í,úW)÷—!ð[ØÙ߆^An²Š‹l&¨Ü¬q¶f̂”X[üÚj•|2ÐfáRÉNló¹€>JJà'(Sƹ„¨dpÿR ²×40Ün ‘¼—©.2ÀͲQK 0Zòûµ¨óáyw°pq_ົvB¿ÍR™tE¯Ï0p :öh­q»#Ã.ö.ðȂƒ \ª°'y¯öbÝ삵ÆCI;ýJvÎOF½þE0ð/Ž•HÚGËX"Ù@í8ÒÖÒ­4†wC`f™‚<¸q®FCh{DqsÚo•wµZå*ŠueÐJU¾|h•Ù¬ +V‰ÍÒ¯þHÀߥh/S‹d‘p ú\(ÒLcä'Ø(,Øu9šw£áLLW"ϑi· ӝ”…cyŽAÑ,8Hs—¤¬"ËáÅs¤Ü½¨²¼Å°ë+Í҇ÄÛé̪fJC|ÝËjd ãe –¾1¾’Z@\.ÜbúH˜ÃÖ¼JÉØ1ˆ„ƒ~plÀi´ø  ¸Ç ÒcÊÙuûß3êx=¨ixs=amioßãMôÛ½©yÙÚ?í²†\µ®÷P¾_tä>DòñõL7èÃÿn›¿q/ŽùßíáÔ®ÿ˜[#9=ËÓïC®¾bœNà'ˆfa€ºõWz¥­ÜÆøû'Bh]ƒSÞ»ç¨Dÿü¹ÿ~b|y{uIïŒþÌ+Ù¨¢7ØL3삐šƒŽKÉ?P{oÀ$àNuÛü(²öÇÉßJϔ/endstream -endobj -502 0 obj -1855 -endobj -503 0 obj<>>>/Annots 188 0 R>>endobj -504 0 obj<>stream -xX]sã¸|÷¯˜»L.qŸ?¦üñOgÓå,¹¢Åj‘\Rw¯’›þJÓ¯º¸ŸÓtJë‚7Z¬–´Î×´ÎF÷ëGrÊK*Œ%£siééór­ÌÜ{z·þrx¢-iD…oß_\à3©Uf3…O2S_äòEjÓڋܖw÷Oû;ñÃÅ}֛4Y&+ø¹ÎGϳÅ2½¤År‘Ìh¾Z¯~-lŒîÜÐtÎî\Òb>Kðï V%ôY(­š’~UÎ;¶áâ~џxI“c0úÅl(7ô@¥ôTIÝRaMM¾’T÷Ë5/§ŸxX5»¾‚׫>ôlÓãÕ7Hók7{†­+ ÿRÓÕ)€6=‰:pM /óýcúdțS1¨|ˆã cËã@Æ”i•}%ÓÐÖt– œ§ZY‹ˆ‹& i2½Ú@î7»5ºëºÑS׶Æúxw`Ոwaؾ³î´›{%| ¬§7Wɔ®ç+ÄXOÖáªÇÏo‚þèàž2‹¨2 bÄyý·OTþ¨›Í& ÀN|S2¸'h<¢0G8J%œ·2œ8úJx†ôjÎZ ÝpkÿÎJ‘šÎGû&lŒíؐóVŠº7>p1Àà ^×GE8'ì)¨–ΉRò¦‘Ì/Þ*’¸ÕR8ÜK´/x -£µÙ0Be§r~±‘ŽÞs ¯gÜêØ2œµ ´ Þñú>Û¥u×/Fw—¸óöÛp“ã©*H²_@þ²Vð밖O|‹5y—q¢´Âz•uZX*¤ðg§ý^Õ2¡ÛfKü_ïçÙyÊD/ÁwN‡){[‹‘x{:4„èUŠvÒÉ2uˆH-fm8ÜðÉñ@Ô qa3:ÇgrŠ„÷È´Ò -Ï÷ÜÖyY“‚ÄØ®iøV×@‡ æü&¹Êt:§ÖšT¤z‚‚È4—/@’œÌ"ñaBÈuW§P妠Bi9fä˜>,3m|—TCÿ.5vÕÿaD&oâ-ŠûÒãÇ;r1ûB7òtW7ɂåå¡!‘ç*àÖS½GnL*’Ù¤^€‰yÏû%ˆîþùvG¸õ —ÀYÇi¦Ù«¬’ÙW¬R‡ ‡ü:jòï)“—ÖTFøjñUF`‡ì…NBNÃÃÔ*YŒIøkӔc" ÏYÁÚ>¬q¡ÜäßM%ênÈÆíA0uPR‘¶^"Þ‚œþBô‘…B¾W¾Ö$›ÌäبO}GÏ£ÆL@@p ‚—ÍÚu, ˆ‚‚ÿ?É´;8’7|~w«‹SX½†7†tÞ)ì4ªð[:8¯¹UF«šr*‚õ.Fò5côfávœòœ ÌcUâ -êz¨,1¢q¨Ê^á>êɏF=Í͍ p'ô/cQG!֛Je))ˆ K,«nˆ þJ8h[HùJ´­l Š -š¹‹ÞK¡H‡Y Oãsô"L»¾ɬjT&tBhn v­4à ä<ä rZD©w]ê2«ÒPXìÁ® üÆAØùnDӘmÀ¼‰g£ªÊeÂBjLù­ðÈAgjɛo”Öaí®aóC9æ_Yì  ªKSé=â—K¡AЍòû$X²¥ǝ‘*a9Ãù7¬Hþ£AèxŠ®×3È9Ԉ•µVeå!ƒ™îPÙØ]¯8 -Hèxw×ðhSQs­‚á°øÁú´+!²h‚C`šƒº[ðwv ÀcŽ4pÐÃÁƒ€°Î!h|H -ºÉÆteÅô*9Ôgdƒ—ÿ ±Â“ ÍÜ G!ùQÞ?Ay…óüŽúö¢8W¼Ê*¸¯™qV J?cúfÔ¶PÆ`W°³Um !ÛmĦ¬Ø§§,è¯ÉÝíc@—AÛH ÊGüÿT­î¤Ã±V†žöÂ+¼Yh -=“u\cid‹d-AÄîÐK¢;²hFÐX‚¶ìÌkÑe‚ê¨j°¿•š|;ĨNBk<ˆ¾Zõ© ªC ·b¢yTÁž(E:ÐñMn$²–ÃӆӀ¯…ÆÅëÊTð•rp+óEí§c¸QúaršÌV˜&CòìÍO¦ˆTÜà89효7ëÚ q«‚± Ë úKóG™DÑÛíÆ=BŒ,?–Ôj& óiÓǍ“‰r*ý0@1wú‘r -çxt»á‰9^ ÓÄþXvw£r?qãÁÌ]lJôñ›Á‹Ãò‘éô¨õý…±m:È®£fÌtq¯ ¦SÖ̦¸9à|õÍXƒ”°zîIè7¤‡´(t.è8ýHG˜²m»×gÃ7“°õk‡½'“¡ªâÆÙÉ %W¸PHp %¤'Ð8‚Kїe9>* ?±¶ñb ]¬hyŽYø0{ŸG]£q§@ÔÑpg|Q@ °ÉÄŎС$I1{Ã.|ó2?ú}ŪŸ§‹%fÚ匿î؁÷tûùÃ-=Zó…[µ½aB0A"'qÕ$.ú~c¾ä 9|‘r5íúûÙÿ ×|endstream -endobj -505 0 obj -2019 -endobj -506 0 obj<>>>>>endobj -507 0 obj<>stream -x¥WïOãFýÎ_1ªt=BŽW>Tâ×õh¸#T)Rµ±×x{×·»&¸}ßì:Á1T­TñÄ?vÞ¼yófò}kB{ø›Ðєö)­¶N“­Ÿ~¢É%9î~ćŒöÆ{{{”¤Û‡ã£1ß\\^ÿyvsÜÞ|ûgOÇt¯tf–Ž®:7•PšÎŒö֔ô#ÍDµ;É7}@“Ik I(‰ÏÏw8}.VöâhA¢-@ÚÕBÚ}µª¶]=—F7€F_Ç=écS¿~r¾3d%Úœ¨ÀÄg›ÐÞt3û0¥{ak€Ñ9$ÑWዐq %”ƒœªT),‹jônD`“Ŷ,TZp· Xé%þFÞ¢4ÐæuètLŸÍR2÷F£k£/Dv]§O’J•¢•^uD¯ö©É‚ Qæ*8€jorÛ9-s;ߖ= kFN²'¡Ñ{݅AŠÜ)wZ=ç;ݝ• C•Ð-ÕÒ X¸p86A·BƒÂæCƒŽà+TJÿžKƒ¤ ¥¥Ñx‡„²ÃR^€ž¶Õµðå -lj´!TYMZùÀ®ÐöúžU±¾ÌBC/ 7`8ìb¬ÞA¾™t)|%䃚*¯D©þŠ]¡4بâgæ…ÕÁ¥C©Àq6ò{+,€uÃÄѹ(C³ØFM Oð z¯¼R?)kt…£Æa¾¬Ó%Ø|3ÐH™PO„É湄#AZlï`>Ç4DÍZ-*¼Ásµ4" Ô³T ‹!бÄXÁ«äaLMmô˜.a*"õ#¾õ/ãÅÈêp p#´¾ˆŽ=Åo•hIKˆˆ5üÿá[Ò"bl©ÕžùsÔÈPJI{àZœ¥E·c÷˜¯D -D’7 ƒ|œßԞ±7T5´¶Æ½nÀª´Þ^:Ÿ>;žÏï/¯¯“ùügfüeÅÙÆø²ônd}kŒ7ŸÇ/ûÓùœÛF=t5Zw‹ëEÄ:Ô© -®–p¾n˜«)"‘ÿŒuˆT¦…Ù@ú.ÔDÁ²Ø ÃlÞD}k˜E‹%R¢¿rH®T0`,Q~mU"žbǐM.š‹Å t»7îw;ž“i³Þßz#ZÝjÔgqDë £/€¸C…Öw§Í%ÀʗCŸ3r ê<ÖÈìâìîö2ù£K ø`çà^ÏDCX¡ Cc[Jêї*‹« ¿WC˜9IÈô-¹¿™R$g# ³­á%¥‹ÊÃ<ÒFfJ!:^´Ö`{ž–¿Aªk¬tdoù U­œ,ŸÐy × WÚ Ñ(P [)Çk#åè®Àæ ¢ny„h23ˆºäÜ·H>Ðieæ-Rzí}°ë GM¬tàó÷¥ +·eïk¬m&}CÚk櫼¾úÛ:X¾\ñ -Rl)0™zcÛ=Xƒ'.G®P5ö€yô¦f·áŽÀ"-(|—9øðécg7“Ã#lՇG{ñ Dxz‚ýÊ|Ãáؚ҆çGüÞn||÷hŠŸlÙÿýÉvpt0þˆ_‚8iÊÇ_$[¿oý ¬Î¾Cendstream -endobj -508 0 obj -1625 -endobj -509 0 obj<>>>>>endobj -510 0 obj<>stream -xmU]oâ:}çWÌÓ]*-)Pº}£Wªt ½Û¬V+Uºrî&qÖvÊòïï;|4­(¡`{æ̙3Ç¿{#â5¢Ù˜.¦$ËÞuÚ;ÿ{B£¥+¬L/g”æ4L†Ã!¥²÷ªìŽ~è*7[G‹”ÜÎyUÒskì/ç…צ"áh«Š‚?²8ò|F[6âU‘öŽÌ¶"«ÖÚy»KNã=…ýî,}é i0ºHÆÈß÷á©Ök©kᣢ[S -|<)ÙXíw$Må­isʅ™pŠÂY¿Q;raÃQiÊ0XkXË -–i'-£’åªVxTžV ÊØ#?&1+£-ö™ëF¼GFÂäT03â’6×xšL¸Ät£è;Ø:ÆԎ¤( -•shzš?€åCµs)•sô *±üêåL8Ú8\KÁ_l§6Ñ jBßµ,z»Šòtå•PmMHÜ9þÜ×ꊼ!U¹$ïIý×Ru“˨“ ªp ôw£ ¥€½V¶Ôž¿lµß ÉL@¡ñ”ÃLC \Ò'<úUj­ÜóÙG”>‰2ä•(£ø€?o$" j¼.X8!œDŸó¦¬Cª}3í(ݹ2«…sÛÀj)üjëÖu·¸ùöó1½_.ÿbýºÂÛy.ðwŒÂ}:¯›ìÜ1ÄózÒcËÎ4–*­:O©­5Ýrt&¦­#¡tƒ¾ÓJÈXWKYã!¥ª2ž2EJ8]ì¢@P˜.ëB•¬m®ÕªºØk‹!}§yqäß xOÃb鯭ij÷ù0Ü_¿`0Pó~Ìã݄´ÓÏ`»ã.:(Úñwûño(4“''ºOOöÖ°¢ÁÄ®?ʔª°ßZ%=xÁɕ^CÄyBsßÉZôDÌ£ÿ}m¹¸£G«K‡lÑÝìQXÌîãí 4J÷žÇ3WN[‘í¨(!7ðŒàh±“6à„è ôÎCFŠ®…üÕÔæ¹yÚ§ö¡Ø\ïǧ͏Ž4q°g"mm§D]­; ~ iYBgÒBÔèjpã%…]aÚyÌ÷fú.íá¢Éø ¼rr9Ãÿc¼á3«xa]¶Öh:Kø2Ã]uriA××s´Æ¼ Ã L6,÷0’ yO â±þ4™%t»|˜ß/þ»Y.ÒoËÂ0_*÷mñô×qP&³Ir‰›–~qÁáþßÞÿ͏shendstream -endobj -511 0 obj -915 -endobj -512 0 obj<>>>>>endobj -513 0 obj<>stream +526 0 obj<>>>/Annots 104 0 R>>endobj +527 0 obj<>stream +xWÛnÛF}÷WÌ[e ¢Dêfå͗¨1Ú8N¬4}P¬È•¸ Ée–¤Uý}Ïìr%JNŠ40`“&w.gΜ~½iˆŸf¦ç7ˋÁbNѐ–<™Î®h™Ð0ñŸ¸w›Š²–†¦½Õ;ª5Ýêb£¶‘ô$òµ (ˆHT$.—_ ©q¾÷hT.̞ît.TÁgj£³L~‹ý…xýõG!ÎãÄ4z4ÒȯªT-飉*¶îĘ°=Íøý¹Ñˆa¯Ša]$ãNÀaªŠbû+*3)*I¹ø"©âÈñ\Ôö¬À]¬sتÅ:“´SuÊmŠðNkQ©¸Í-¹X7*“UÒ<«ðWåë€O‘(JP²°ù?"ÉU¡ªÚäUŠªÚi“É"6û²Vº`΀h™Ê +Vëf·o–\ [ +ùêã¯a8 F4™^cÊ)¼Š‚y{—Ñ—tˆÛ9vKYëRÅ(”Íø@'ìµN%ÙôN˜-  Š½çÓ[õ&«Ë6ªhzôšÓ(“³mÖ¢/£ù,}[/®?€¯7-ã=:~UM)M,eŽ­÷E]H \ßæ7µäìý!MÅôGTÎxi”6,3Fº¦eyIEb˜-’È(¥X«LՊ›D“ˆk«?ôY‰Þ—%Q‰S :Ëë(H´ê!íÕ%'"á¡à¦·*p&¾¢8‰â–(À€[ ×±Dè+†¤KÈAK:±œ9æȨª÷šÄic¦·º¨hctÞ9fSXõêþ¶)==NW—¶)|– ôñ¼â8S({eUDUg¾…©U Ǻ©3U0z¨iU˲¢BBÈ*VlŽ¾«®,aË÷–VÇ#π‡ j_>{æÌ9«%æÈ¡¾*‡*3GùB°N@Ê<¨ïž}m¬J[û…fl³LïÀªcèm6,fìÒé%æØ^9´2XÄ­žögÐf¬:IoMg­Øz9åg-,3s„âЦóچãÐ0œ2ù,¡2n ÜZûÿ®Œ¬’ÏÎ[†Å’@^¡Å<5дV2D+SÜ=èÄNlƒ‡åIæ?¶‘¬zF ì1[èŒM´u›ÐÏ"구Ul'‹Õ’”S©3È*DêŒûÉF3,!ýˆ×"ԛ·årÛ=bêRD·N(Ù¸SŒvò dž…¿Ø &h77ÛÃ9.¡ÿv»,ckïBÿyx®1Y|x¡ó¨Xb¿ÀÄ#ò›4ki´“ âóÒwŠG6ûoçü=!䞊ŽŠûèv3°F"[|JùˆŠèö@¦hO/™#K>áù/¶Š·ŸÎ‡AÞZÝ®b7ÆNéÀhãf&f$/cµŽuföëW'”oíYvóîQK àDm6°ˆMيéÃr|ƕÓÙÂÄJQ‚µDÛúÅfZßm›W:çOL•»…—?ŠÛIuß]zºŒ1%헦ÈìZ€À°£Û^„¨G´†ô&nW³ Wíü‚õɵÞýø·úÙr|ö}>žñ÷Š¥B4iµçÃÅ¿L¿ÿendstream +endobj +528 0 obj +1735 +endobj +529 0 obj<>>>/Annots 145 0 R>>endobj +530 0 obj<>stream +x•XÛrÓH}ÏWôËֆ±u³e/Em²,qÕ>ÆòØH!É1þû=Ý#Y²ñBa{,Ít÷9§/ò÷ —üs)ôÈR”^¼š\ü3¹pz£µ/Å ‡</Á(ä×Á¸çQ¡iÎ;pÇl_p{ÿ. ץɜŽBšÌä‡&Ñåk“ÍãŪˆ³UKM**úxûšžM¾^\cn›]º=Ycyíú°†¯^ZU¼-UÑ2Î4UŪ¬HE‘YeUI*›ÑWg|K”Äš¿£Êˆ•™IUœíšð¬‰ko@×Þ°°ÉR#.…ÿΔƙ)h¦+'%•«hIª¤U‰Kyaæq¢ËçTnÊJ§”›$ŽbþBWQ¯×#zkÖúIÏمÒ›™Š2é²TEœl8f§ ±ÌuÏãˆÝVh`3­m㨍8XèDUzÆ·þg3³.é~‚³«µ)¾ &‹t^•pamh' MõžÉ8Å&ÃA&K64-b=Ç;ãÐã[E ],XþY ûý»1¹€nÚ¡E±%{Øó{t˜ñ[Ë.V…I]°±V9Åcá0#4  s‰Q£EM¨­ˆâ’¡U6ÓØÒ`”«B¥ºÂW[ð7|T™N{ ˆÞ >mĵ¦]ö§7þ±ÐÀ…”—ßí*¡I,‡"Ô6|&[UÐF^±W…¾Ö?ò„…¸ç”U\oÈM ®– +ûgúû +Dƒ“È@L ª2˜éú¯£Þ°ãUw«a¸su'u%L¤næ~$âpƒ0k¢”†”<ԌzÑbâù ±E$W +Àm½Ê˗àà¹:žt†ì´äM—»¥zÒP°Î(‰³o@bWKqMEÕJ%[>‘±eTÄ9+[TÌrªSü-g8d¢2Ò?Tš'ºÝ6‡8Š³)'eé/«K‡Æ,r”#o`KÅçEb¦*ùÂ×9…9zè•ð÷‚^©YŒ2ÆðVñ‘eàR0W)¡ õ¢m MCJ½aŒ ],‘êÓØ@ѐ¶8±Ý¸Å”^JÉëßyÖýˏÞ|ØqÃávJ¡ËÙ-‹£nôïj¬?þHn¹åd\f•ÿª3÷7ŸîßÝðÝÛ£¯=QÚ×-˜k0´4«dÆÜ01œ=uEç OLîS…Q €¡Új‚±®:LYJÃ<dq4ÈzÃ~!Ì Jyr<´aÐÅÕB¯ëŒQ,íê´M<Øã7/ô\œð6´ã¶7zG[þÈRÇÞìâŒíQ°Çeîï}D[‹Ú—ÅÃ!wÝVB]&φ{P+¥Ž0[T›mÒÑãeÊc‚ôìí՗²~|¶ÃYàg"_g¼X¬]ÿ›óûÎnðՃΣ蛜›z®Êù4CBµRhßWq¡¹Y“)ž˜vœwFҙ\7€Ö}YñÒ乪E¿6ß?F­¸ƒQ”«<7EÕdhb&Ûѧr"¦$ú´‹Ó®z,¸¸¶®ÖúlÏnÐnñ;åæZš.ÚrYq³Ý™éþîBë¾”81$»8ãnÀtÝ?kµ<é#þþ¸|læJ¬V|÷AŒ­óÜÅÄñ?KZšE‰&DÔE{S]:ãJLï7ª©¦”ÇghNU»a;<ñ!™yÜódq&l‡›ÈÏaϊøéDƒz+¶©Õîh܂m§­ºcç ،Çi°ùÛ¡OBmgr J émݲi ›¬Y?¢òŸfj ž„*Ù]]Ý~x¸ºEðdÈ í3ú¹œüÝYÏÎoQ x « «+‹3¨áA.¬ÓÇqzQ:ã[ö”÷¢3;‹‡{‰Û:s|ƒ6¬€Û))¹²8³›Q§s©¿*‹¾4“~Éϗý$žö|»~ 1®2þÈçÓ^Œí£h[‡Öè5ZM“RËL×àÈmå-ŸODòíÆ-1þ–6aäË*5Ãc,;qlÌza'|r5äùw§òæ.§M’á·)By6bJåóéÐüýös†R<:¡«ôñÒϪځ.²OÒ5•òù´yotÙÓTÖí¤7ªßp¡ß Çv¸|¸yÿê†>æ+ª0ݚhÅ ?ZÿÚ†=>>>/Annots 158 0 R>>endobj +533 0 obj<>stream +x­XMsÛ6½ûWì-ʌ%‹²,ɝéÁ±ã&ÄIuÚNÝDBcP@ҊúëûvP+§—NSÇüÀ~¼}ûv™¯' ñ_BӝO(-O^ÍO^ÏO†ƒÙŒv?Ü.†4™^ F4žMñûh4˜‘Ó´lO ai€ ÿøôÓ Þ˜ÐD^.i6âórQÐg>#ïîÀÅÙí.i¾dÛ|rFóLLižöR§U­©TÕãËù—½ãbÇ{ô# 'Ã!?E +ÞÈt‚ˆKºœá¯‰\<ë>˜âÍ}¿YîtZ[·ý/×SïúìvLIÂiôÅbÄ!̳Þ|¥—âÿ)µÍºÐd—´¶¹©+ª-ér½RUþ·¦ÜP½Âk û¤ñªYæSuǹ“C¡Ø蘍¾6©Û®kÑZUÕƺ¬¢²©jZhÒF- + ˆn­£ÒÂs¦k•YC+»!v›Y8Ë«Ss©îüÎ'\±d?%%£—D®žqM’DâڕíõÝõ§?>Îß~¸¬ê²x¦tâg·i„n +v%ç¸ûÑdžGhùq‹€¥J»'D/©WÍzm]ÌJ( û`MEÊdÞ»I¥B=úÓèZ^øË?‰zT­¸TG³Þs1Ř»1¡\ÒH\#څ³ÎõFáðËuú-7n¥E®MÍ%*lÊÔg!O…|8´!õ£Ç›kúc¡U¥ÛRʑ'årÛÀà®AGzÅnsó€hÒ¦„¡¢H‹&“6y½NP–WµË Sƒë¸ l:Z¼HÐ#@õA¦õ/XAåUEŸU¹P4ÂÝÌꊌ­ÑÌF‚ìsþ{-ZçÁ¡‹Ð•ë5'³@vZj¼›û7¤ô9Da|ΜºHfàvIã ·¦¿Š¬Æ%4hOw~½{û{4tßãV!üŖ¾69B“s®Q&üm]0ñ¸® + kžwìý½JW¹Ñ4w¬ëWÁ‡@ü3†¿r-R‡X°Jøp9ýÝ4‚TŒ¦Òoho±‹!jf5Ø*È¤ˆÙÝðz± ÍØ.( \<Gn`”A›ƒ`¿S'QÓ òPk¿6ƒ›§l w‹LΘ][S;[Á§o>„ɇózKK€ÄføÚé'Le:¾£š]ˆÑšµ¹·Ž±&LEn¡<|±t¶$ú°e<·x„< ³…iª+™Ûþa×'<óÕ²‚è6)ÿ¨ñ—ß0†QT¤e<ëj‚%G— \ƒ*ú^èT¡,”ó\ƒF²Hv|®mUá‰js<¨ï©0¦^a`ÍÀq?áښ´€`ÃQÃ?°ŽÅ˜!«o®O¹Æç8•"! jSa{òÆÒéž*[pè*?ìuR‘#Â#øˆF R1™‰Ìä"t}§Ì{…KÔ!Æ8WJ÷=ƁmöÅ»fØ òvæï·ÀýˈC±o솫tzh£±Pê ¤( +景fëHö¨•Âú‰ã@ Û/Ê×îL×éÙQè$ùWTú¶‘.uZö“ +m^øUp§D?åqÏ1ÚÏÒ°õw<Ów\s´¹®üR¢6åy»~c B‡)ì„û"Á>h/åû 78Ö¨"ÌÐo¡13ôZì7®½—`ð–ùNO±¡Bªñ¬e)nWÐEÔWÑ£ârÂ{Ëݓ* ý¾œ*@C'fBå(2åëÈNɎ.f‘ÌG³ƒ­ÚÏdèÙ»ÂDèu¥Ä£ˤOu?W~ÊTq»>êm°ØIQæ6+óÎÏ9n!YªØí¼íäºÊ'QtÆ;5°•QŠ@:^Û +ôM í÷hßã‹ÍÏŽTÚð‚Œ•ae3èñσȷß°$c^6¿¿$ɨóùÄ«@2ÀÀ¬ƒºH?ðü9NWß'QÂڑ?GËÜaÒà»cÍ­ÜÚyfZð¼_±„@ãßßSF•a‰aÀä^OF}‹\ ½¡°Ë ¬œ„÷"*ñS¾ÞfÐÇÄdK/T&rêÜ Ù84/yÐðÖÆè´l ²aôFd²Sô(s`ª ƒýÂn8Øb}Sü­![Š¢w¹i¾-еY˜Wþ#ì*¾Så[2™L M&¸ÈzŸ¯Þ¿º¢Î~Á¿`ÛûÎâS}ÿr:’Éÿqßc/Å¿Üp £)»û~9ùÓ¢bbendstream +endobj +534 0 obj +1935 +endobj +535 0 obj<>>>/Annots 163 0 R>>endobj +536 0 obj<>stream +xWko·ýî_1u]X¢ÇêmE'q›¢Éí­U´ Ô.e1Ù%Ur׊gøX=œ¶iDðî’3Ù3gÿ8Ëh€͆4šR^Ý,Î^/νùœö?öXv5îi<ŸñßCüXI+¬Ðäjԛ>ù[øí õo±9£Å +~§ó- +ÿ}@‹¼c©¿¤g‹÷gýÛq\Õé7ÎöÝRiü!­( +ê>P³Ý‚ú…|ìë¦,©›Ç}ô¯ùZiù»Vù-*yb–ºuõÙðJ”.~OÛa>õ†¯Ózj䂍bépŠÄ`éb-c鐝¾¬óþF8·-N#º¶;Ú*„_*WSÝÑqĄoõš]Øl¤.dñœ¶F_Ö´‚]¼dá]Œ(ï“ãÖ߅.H¢µéBY™×Æîztk,ɏ¢Ú”l2‹²”]f³Ù]ÂmSх>=#ýÝ!O‚*Õ‰Ó*G×!'ºbDdÈä$dÒ»½¸þx=Lð?‹ ‡aá¾&Gōf:×-.®Oë›`Õe_ÓPàKó(ŸÿSüäBÓÓ;*¤Ë­ÚÔ +Eñ…[!¥\ÍMNª'{t#œ¬PÚ4µ´=RÂÑÿàH,)a¢ÜQÕ3ˆÀ{Ò²^*ã‚{³JÞkãc,ÂßSa*¡t8:¿8÷vN +àöW†q@'ª¥ÐÓ¦äæA«ÿÅÊ +w&‘ç¦Ñuô’ºåÙ…Àÿùݛ_)®Î▚r+EÍ°çȵüX“«å†€œ&| çwÕ24…®Jˆp>9_nt$(ýà o¹=>h³Õ„—µ%ŒZNo +ÈÛ6¶ðiƒ÷XüÂhI‹v؉'ÏÄyßOßzŠϯ€¶Š¦SϔüPÒóížýzϑ“–#ÇWÒ=K¶G½ïÌïŸù“µëmy èÊMUqï’êÖ|ȵ´²í¼DÆ-‰}’…©õJ]ÁÜÉ~û· ½û†|B’ô¸eǟ¿³ãëŒÂÇ"^Þ0ïEK)WÙxÚ¡«çA¾7Jûêæ¥&ŽáOªªd¡€­r÷¤l>‰©lƒaož& ðUÛO(ŒÎõp’½ºîF{f=FVB@UÉzmŠth’4êQ”;ڃýØÐqW%Æ7¾~Qº0[Gïô㫗¢>çwÒ>JKˆP€i僕xµBþ‘q¬T‰Z¡D8”kä)‡(~3M˜¯žø¶ÂjY|á!8…FÙ¬YóI‚"ÀJ£Á~ƒ0ku˜¥{E„ k­áŒ·bš¥7ìÑK®+§0Mþ#|::çh‘¹U¹;çìÏÍÎËú× jfšÊ€:y ÉXµÐVìŽ0ü'®ŽyN+æ,-%Ûs‚#ø$ǎ&ä`8ã·BGŽz³ø”h“£xÌòÑ"\;†S•°ÅñUæ`¸xJç%àˆZ£Ed'Nüß¡Dá|ÍásEãŒy%Džbm =ïIü¬…=²‚úðøl7¦IЁH´=«^ÑeK­¶½‘%†0ŽKpÅt è'Y|‡œ³FúAéæ#¹fo印ˆ?Ul'ÑÐ×ô å~$Ù£Œ?áÔ}K_5‘ØÓ;Ôjo4ÝyÝ1v³$Ú¦IôÍ틒òKӛ½G-bPnH/e” “‘ò4yT©¨ÿ‚¹5†LT5òås½O£e®¶Gæ|F½ÀÇÚOÆIˆ§™C= 1x òªãtÝ}÷ŸŸxu²‰•ž“~Ð9èûÕÊÓÙÞK­“¸9Sh1gr…ÉÏçß]ø4hüƪz‡†Îhç)+þ–˜®ýǼ4+;@ zm­±>õý۔=ÜZ# ½áº²Ý·æåÅ%žƋóà>>>>>endobj +539 0 obj<>stream +xWaoÛ6ýž_q +Ô9v²d݇ iÒlÁÐ4[= ”DÛl$Ñ%©¸þ÷{w¤UmW`-Ð’»{÷޻㇃)ãï”ÎgtrFE}ðj~0¹>¥é”æK~töã9ÍK:Ύi^ŒækMgóJ×d<٦ڑi(ÄÇ+§jj½.)XªÕƒ–º n7Æ·…&<-õ˜L ­už6Ú-uª]Fï,N« _ÌßÓÑô$›!øHñ‘Ž¶&¬mäÈçϞ“jJâ7ÄßO®HIÍfuuŒ8]"(ç™ÒQeišUwZFo] +Oòl»¶UúV"󉽜8™%ílK•y@IR®o–gœ—BzùÐjjMIߥ<ÏRž8lv–r7´ÒÈÍV%þUÊ­Õ#ŸRئFÆg+É]ÙZ™&ßC"ëèðR5 ôÞ¢¥¼ˇ´D½FU~ˆªo7›Ê U8~Y™À@•H4>08^±]ë&‚ÃJ-Ö¦AjEaÛ&dí"vtžýH]ï³³óTx× ~}tò2;ãÒçk°h­6ÝøO°… dø<-­¥º}"&x]-…Ÿb7èZÉÅHg« ' tI¥3zñ­·è× +m\Œ€ìÍÝå3O$ð=MÊø®C¹wÀu됼ƒê–RE×> ¯ö\Sô¼ÖuY)ê\9ÛnžãWT ;#àU­©áT|Ù6¨˜UÁ2Å(W%™R+`É/%Š¬gÔÚ{µÒ@õr­šU´ JRˆñÐokÀ¼éÊëñ (ä îkO¬„Z…ÀžÜÇätn-~rƒ˜\jÅêùº¹µ~ç<®€ø¼Ê®$qa1º„O_¾Z¼` FÜ?a?¬²}úOªgxØ+.ÂH¾- +`±l+øj³SK.£ÝÀYÅ®"A½ÅÓGí<›ÆGDr¶Ô” eý™•& ÇtØ«ñ[EŽé®Ò +†&؃Ǧ1ù¶ + ‹£„× %ª¬Aœ +Ö%áÆÔ±´¸ÚÔ +¶ü±[­óÑ}z½»¹"ó€‰èw²a8™G̐ÉýÛ?ÿõÏ·Ýeø>~ÔIcÄd¦B˜V‚s×(FTõ¦úŒSÌÕ$_Î`i0˜EñÀ½}ä7"Õq0t¿C8m¬84~Âdë„S¬¿…1³sUÌÜÖó×|ç:¹žu{¬Aö²Æù™Mˆß>)’ÝÊژÆ~·\Ȕá鋶mm‹É4%DxH`0Áõ×E  A¿†/9±>ÔÞ-"½ÆØR\*“ÍËáî•Dâõ@»¨@§B~Ô¼ë>.‰ +Rq ’ÅÒ`þ`hEôˆ){ä/«'™³~c¼z‰È°ýzû³,“R$ېœÀUÈþ +CIÔÿ¬I썰¥ò~[Fãê/1ƒxq¥éºZÂ#¤£¼b1 +y‰fy+$Šã§þ?…£6˜Ê,ýû­xPÊâjº²S  ü¬“¶›ÜX4—÷´ž’¬þ¼/J’– °€£ÃO;íÿÃß?#¸íß$æÈÇ·žûÃì°V¹Åò;Ñ¡˜$ÈdY@2OU±ûó5Él´Å´ˆ=qz«bBÈaHÓðœÄ d÷ómÎ[­<®>™sÅqv㖃™¾7òÛ9ºmSšŸä*RH*þop4ßCPs/ 1)7ΕÆÐÿáºÉëÒôæ5£¸á?*¥%hñŠn秓ûÙïñž یa²ôá +7>R9_éê݀+rÍ+g*¿dԝ¾¿¶m}rÑø¢÷a¡¿xƒ±SÁSJ,]+–NlÈ,ãùʳ̔7ðÖ¥ùW~;å1˜Ý ¿ÃŽckHìY`[Û ¨4q⠃¯Ïœ¦´|Ç>à*/i.Êtë]78Øä·,¹+LO¦Ù”Î^žðÖùîâÍ« ºsö=Oï+[´˜ù~¡æôìÏdGÅEÐ%/'Œt§¼àX#© ž“u,«Ý!Ÿrz~ŠKœœ0{É^Ïþ8ø¶+ëendstream +endobj +540 0 obj +1867 +endobj +541 0 obj<>>>/Annots 166 0 R>>endobj +542 0 obj<>stream +xWÛnÛF}÷WÌK¶°¨«uñKá4qk¤qR[AЂ@±"WÒÖ$WÙ]FÖß÷Ì.)QtÍEµä\Μ93ür1¤þi6¢ñ”ÒââõòâíòbÏçtú0œÆººšÆš ®âFñœŒ¤5?2ˆ°süÀýýÛ ‡´\³Ýé|FËÌß0 eIc´!UÒAW†l±Êâ\o®‰vÂÚlÕ߉‚¿Åé5¾ý-ÒTW¥K¢ÑtžüHoÞ_Ó§ûw÷>ßÓۇ‡´†µOVšë—ÿ\ ¨7Ç#8Œ~¨ðãTÿ:âàñ덣µ2ÖÑJ’,m…$œÆ7±Êñm+‰ŸªZÚ+·õú·WuF"æøöõ$QðÂNNIG—°¤,á_©M!òeº”—÷[éA ÔHá$‰’jDZ÷ÙC2MØw%i“IÃÁîµy"aKüìŒFôc:ŠGñà’R]®ÕÆ'‡”Bt£&ÆK'h~ȝÓ:Ø +Çà‡/d ؾt)W)ÎúV+ѵ³V€RX&ÏõÞ^×þ´`F ‘ÔU¨Õê¬A¨/•22k~çúï¤)”‹­>÷҃™1ó*º[3‘h/JÇàYà°éÓ^˜ IMN­T®Üoð!§Aü̵>ҌÀÂï:E]•{eIä!.Pö¶Vyéï›Ýg«™D1-·4øou!iUmÀ–3>èo™ä@«R=¿´ˆ0ÃÓ¥”ã֊“‰yyN~FÁS¿Ðè #S (¿Jc•ëցc\Ô@K¯š,® +“ù Ÿ@ó¨ýÛ ÑjkHËd:ô½xjþi<éñ`èúQç*Ux‚ȍfö¼ÌܾÊï«tb‘ &Z¾@Q^‰h­%UìÐý·<<诪Üx©8zã–ôØ°¸…S¦=ÐÂ, + §´Û +臎¾Ø&n†þ&…ÌP=6ûY•øO÷Kš `1&útµ[]å¾6ÎZ@‡¬¢¿^,ÐǐÚ)T¶ !„wV_åôè%—3¶u"Âz i¿Eà1ZdzÚ&`p1>3ؾ.h4Å㖻ö5N' 荃i_ãÔ¼uÚº.hŒ„†­gÛ×8ã«öië§ãÙYTgsÇƹSÃÖEæ®áת!Z`]CAì¼\¾mŽ3ÍO78ˆH|*÷ÃbmtAïUj´Õkó=ÀQ´;kk‘eŠ9+rʤƒë'Vÿvzš•ÇG?3ÑÄJW®—…!pðçÐ+iýxÓƄ͢d4ÕºÖÌa>;_êfäÀŠ„±®–. x§ó󆌼Ø„â(à÷£4ŒÐÑM|—µÕãà„1vËgÙ5 +Ê¢¿10ù Õ…ªLó*ÃDðƒøäh\‚¼¨ÔŽ;í3†£u^:NÐyAhÑÓâE¡ËXdEvßîá·f¥‰öª,Ý7îéÎMðU–Š +o»Êóá  ¶×ô©“…’tܤ×Iâ]% FW7®@}pë 6ÛJ•<ÒÙmøÑeӜ(·õ°.f¾I6hoFÚš…ë,e?èZõ»²€y0_/À”ë4,gLj~bïI£é&+TÉúÎßAœZó4!{ÉèäwµÁmÑ÷Ș Íôi¿ü߃ò®ôëØà…k׀¸E-s$]3{ñìõA6¸'ÜnÅz‹rýÎ= 1c 8¼9ýò]ÈÛÈQ Ó$qZç6IŒ´OÊ%I‰…±K’š_áÑfºã‚šX[qòní'û|¦4÷R¶ê +{¦+¼¸ôpœ>š® + +ùÀoüR½b¤¶M֞9ìkÃo_LŸ +»8ˆœ*êßJ,ï끼YÀÕ©òyøÈëoû®*Ñ/þ½š§&5$íÁo֜%ƒ·ýL…H· +?{åÃh³!‡Ž+Ok.þԔš×»Ôp<Ħ:ýŽ=Þ¼}Ûã?Pz£ÓŠß2ŽKFo8áöÞläׯÿôŽ3™Mšum<àÀ°¥ÿqñ/à1:,endstream +endobj +543 0 obj +1958 +endobj +544 0 obj<>>>/Annots 173 0 R>>endobj +545 0 obj<>stream +xW]oÛF|÷¯Ø7)€D}Z’ó$©Ü°“6R> +øåH)&ä{w´l´ýï=RE§@Z¶%‘Ú›]þq1¡1~&´œÒlAQqñf{1ºžÓdBۄ?Z¬–´iŒÇcÚFý›„R£«’JgQ&-ÅZõíµùFZI2²ÔÆY²UšJ‹©t.S)¹¤ªŒ…“1Ñ}ßH¿ô_ÃÅûuT â<§D›Û¯cNfÁúŸ3ë½¥«Ç€¶ˆTƒÈ3ë(ÃF„!ÇMŒ.h$]4ò7ÄaF׋&!œ.‚9üEïnõ>ZièN(‘JÓ#¡bêm¤yh}XŠš@Ãe°qˆs?],›S´ñµã9›LEÇÔ4) ”NSX=áz·¥æ˜·?‘ÒûíÚ°_¡_ÁÛl,šw oÎ|~å»ùäOÞNÈ!ùÆÎSóúOm>|Ú¾{¤é¬ÞG¦¸¾³£]-ñzŠ_¤—Ô¥¾¢ ì'Ÿóñ>ÑöÖE° èóN8Ò¨¯AÕóý§“zUËïà2\öæ>êÁôá·ꉬ®L„îBg +vQԍz¤Ÿzùð%â»`&94›©Їë·=ø,0ÖQU@þ>@@컞ÁS³á‹`@ MI¢}æv>¸E(NÃNiDÂÙÐÊ¥ZÇ$Ë–Ë>âᩕ4å½{µ—‚Û*ڑ°sCƒYÌÞhNöÞ6Ï#“bYœ‰Tië8díD7žÙÊûÅ2¬ê {o¥\§€L¥Ñ ²fcïi®Ë‘`u ¡bES¡£eñ 8 °›³+(U|ÙY[/…˜›-Ä `v~3åbZ¥°<ý6žìÌY™'(Óïº:å†^ƤK&¹ƒ˜†PÙ"Œ}Á¿€ÍØRFY’=ўKK½šž\>ÈÃÃ~—¡*¸ÑT +n$Ì A~Tb‚¢˜Êð‰Cõ@‚?ÀÅ×aD*ñöPhª­V8åZ£·µ›Z‘Gãó4B¥è/žü“NŠ÷}ÆËDT¹Ã’ȓ1– ¬¹Ã§°;Llï_ÔKCËð^«S?&UN…t;ÈÕ:aD]P²×ò¯X¢ž†5º¾l–‡>¥QDô3Åú”ä"õY"Ú>ÃԌÊNVu9Îøjz:̔0¼”qûbFc™x‚€L8'P³4ù³ÂÅS ЗD¾6àâ¦+Oz +5÷Ž½Â¼Ö« ï„XXz )Uó²Å‡·.qÈB|óê$ +}(ñ÷úÕ näL>¹Æ2—ƇTSÍWx:²kú8ԏÄ-b«$áu³ü¾çRX7`MçÔ©Ë`LÞWÄö˜ëµŠ«âã©wkÅZUÅÖTØ~âäó{*¶ÜÄIã7µvҝ#yŸcsä¡Y¥wË&õÏ0µž&üõò9ûý‡ª"Mk«¢V p9±ÀnƒÕw2½`zì°½7!³RftÅÍC=àáJ·—€X¶+µÁ³|EjÀ"rGäƒÛàžJƄ8À`àuß <×ì®,ÑF­\Z™ªä³®Ü°¯Ã¿¹#ë~C÷Á‚bôrØáˆi–B€*}雭= °õºRQÐ_äý‡‘Ž®æýl»;=µ÷Mˆ?ʽ°†·4ý©¤ 3mI ÀƒEàÁïïÙ§«q0¡Ù ¡ Ùjqxó½=q6÷cã´ø¼V~lJÅ+T|¶‘Ee\%·Ái ðvéEq\õŽûíœß÷û}àøËe M::¿û°îôák¯N‘så½UÖTbøùÇÈÉl‚T«ËúÉkóúîÍkô³þŠÞÆÃLkÉàï '‹%n.§~Ýÿ‘¥h¾äUÊß>ó#‹Ùoÿۖ‹>>>/Annots 180 0 R>>endobj +548 0 obj<>stream +xÕXÛnÛF}÷WL9EëÉÎKaK¹4RêÐˊ\Y“\f¹²ì¿ï™Ý%%Sê}hÀˆdr®çœ™ñƒ.uð¯K£õ‡g糃·³ƒNÔÁ÷ü£Ë?¾¼?èûÑkž £e4õ¢Óð)¥)¿uün@Ý.͖lhx2¢Yâ,thÞhP!â[i©ÌÕr) -µ¡¯W’ȺVy¿G´Ò¥-(9-$%z“§Z$2¡¥Ñ½œ}oFfnèpemñæøx³ÙDÒ®¤‘"b=~Ú%ÃOGÞ µ{Ãh€ ß!kD¬ò²+ü,IçøŸ¤K]ê¥åðLIW³#º’v£Í-]ê\Y¼KóCq+"Ê¥Ít>Iª$q'T*© ¦\,Ôîö£»ÜžÈ;™êå¨ÌŽ'-TÀùßz¥©4wxHå¥iJ㉫9½œâc«Œˆf+Ùp„wJ…lô’B|0,Ѓ•*JÚ(»rïÃ$gÇIÖYÁ•ðÍ*Ñ»‘2‡»BÞD¨l±¶°‹¼•Œ‹´*¤d‡®P*ÇãKK„O©Êx­×%e:‘ó—>pªCõµ¿š=‘óF¥iáÎÓrñÜkGÏ WîÑÛåRŔ(#c ,Yíª›êX¤è(-ô½«æÂk±+{¦á±\/`QŸKa¤/éÛ=^`0q67FYW G\àLXŽa©R‰–±éãwÃ@œÎ”ô𧋺㭠+v-Ž4Aü×@#`a¹Ñ„Š®§÷œÜ¯ÞK¼´GÑ 8Î{ÃQ¡â.ÿ®fƅGsµOnlåÓÈkÔ¨8Ö@Ïå/­,(‘7Œíp¹fÈøªQ]¤ÉŽþ@w¢þàôˆ6+¯vðà!»¥Ï>CðÞ‡¹÷LÓόï ¡±,KpD¯Ó„u¨TØìKs›·`¯vb8f#|Xú¦×  ^ÔÍ_Àˆƒà^Äý \GD:°Ë÷Ýn?~dOÙ.Àn<Ѓ^£t• ’&¬h¦uŠNB’Ïndn[èeƒ\&Íà„X–>ü3ï5¬O­0–ÚÈÄZ´¸ÄÇ:·F§ôYä2ÅçZïø)s§Pr|{–$5Z1SX_w`ůjIÊìvUýûœ8=ŠSßrv­O¿µ**þ¬Û±3Âê:Õ{”ð?5þKT’u~f;©úˆ¢@§Y_ (ÌÏxl÷^oxÆîÐØBC·ç@I'Y+ä½*-ë¹×ì nôҋé·éìíå—OŸf/æóéd ë÷æs/ óù«è•¥R dšm4نV#*ë[hx3K¦éQÓk! êTÎç ÓµväV R.›\2»…y ÉǏ-?ôø}V'®³” íDV7;¼§:ïXv Ü Á÷aGÙ/ ¢&†ì°ý†*[Ç? rOۏ¶,Æø0(¿“†™ +üÍz†±Q±ÚíSV;B^«ÂxâÃþ¯;HÓÙ³ùI禢WœfÕÿw8}…m"Ö68Íó¸Àvà€ÍÏ`/VSGÖv<ç­0Evs嶕8ë/vB^T1y0äyZ%Rú ~+ ¢€¸F lT¼Cà1ƒÙleÄÓvg¾‘H2•C  –¢;IFݬ¶K]ØøÀ³ÎÝ÷X:ێÈ@L¦d-Â~±ªùtƒ—¢j %Áã+.Žhá„À«ãIC^æ‡ó¹‹Ù餓€Z1Ã~Œ½‰ï +âÍ2ÆÅ]të)o“n‘Aðö”¤}…—Ìj.LjÙð˅v"‚Lünꎅw؆õ) y(ôø ôâ„Y7+ñ +Èu«¨/)KzuhÍ|õ&è²IÝYÒJ¦ÅrÒ×/ýòá׬Tå·å›æF°¿¿âbíQŸN{î<íõO°Çº{×).ÝÓþ£ãôVKÞX§"[(ç±qóíHáÔ,ùÉH¿¼Ö·ò΍y-i%=A™2`Í%H®÷/Ítž¹àpõüЩ΅Ãpï=¹ÍUP™JÔœÆÚZº”ÆðòŠ=|‚ý̃óÉ«9j¬øâq¡ø³D‡ú§¸²3êQ× Øï(À0踛|û·Š?'”·ª("¬ǀâúþ¸ÌmÄeu´²™?EŸêþ³ò> ;S·3DœÃá0òQ6=»>>>/Annots 197 0 R>>endobj +551 0 obj<>stream +x¥XM“Ûƽï¯èœ–J‘à7¹ë‹k%e•=ÈÞdi§\ÙÀ€-€1Òô!¿=¯{~y%«”RI"¾fº_¿~Ý=¿^i„?cZNhº ¤¸z»ºÞÏh<¦UÆw7KZ¥4ŠF£­’Þ]î7¶Yoh¢%m”#•ÖyüLÉxG©ÚߥÇ÷ïúô^mMJoUYڒv&ω^´®Èot»^{³útõ·Õo";јýóÃÕx<Šæ´XN¢*h²œF£ö*§'¶•-Äݛ3+µÖ0À¯{±h½¦m¼¯¾cc®·:ʕ¯m¬#6‘j†N±:ÿVV‘o×֔kÊl w“kÚkÉVÃû¤nüÆÓh³zϓùHÃÃÉxÝÒb~-àÏttÍګ֟sì#¼wŠþGãÊMùâÈ[z÷pÿD¦„-…òøžÛ, žú+~E¶^“¹áù۝‡çN æçŒ `>[Àrx0½=\½êÁl‰÷N=øaEïm¡LéßJó۟™·ó %ñ8Jl1üoþ’äÃÒ§øýMNLF7єSŽœ¸½å ÈÕ«NLgÉcܯɯś§º¦§oÉU:qß}֝LH‡£Â$µu6ƒKp!Õ[Ûª¦ˆ ÇôœÞ/:êMæ4˜px¹¿Û¥–h­‘ :¯(«m!ÉǨ2“s㐴ß3Ž'¡_"¥ÚØ/–öÞÜ"ÿæ7£{°ó¦½úl“ùÍø"ö«®5)þKeSĀÍfôÄÙFµFê”Î̊èƒe¢ŸùÀë6´>­#t¯OIn’B‚ìmSS©a‚óüö`Dƒ.O S×ÈjReʕǯ6óàÞSSU¶–ïéÚûóï¾äiØ¢ÓÝ^ÐŒÉm4¦ùŒ¡SçSB¸j!g gã ¼‡¿6ð¢à´j À^ýðÖ_B¶SÈÝn ¼_®E9>ƒ1=ppkWkÙÑô%8ÀŒ€’嵧Š«ÆÑLÛÆl ¬å"ÁŒ(ÉùZ«¢5_(‰%Gª?dÝ°¨¢B;‡*À‹ØR3Íx­Àõ*×Êá^,â/2›çvÇ­“ò‹%*HHe |ȧ»|§öŒh¡…¾ìŸ,Ðæ°®QwÀï­Í›Òk\öù1 +"nRiá´B9l)¶·ºnéx¸nT­øc6¾ªmÚ$œ0•ª½Iš\ՔiåÎ"¶ž>ð¦Ðݕ{â_­¼õu 2À7 rÍ۝òžeö¾°5à7N´µ¬Ó“C-;O¨\§Ð<….¥í8è¸6!Â$‰ÛÔ8ޑw—÷ÈVºFÃ=·w^ÒLÔMYâÖDM ɍèÄÛ¡ÉSÆ)Vq¾—KD˜öz Éé$$LpE á-3ÊP¾û #3By Ž­Â§(³ôïuŽMòÿ`y|¢² ër“C.ÂÿÜCI*M Öò¾Å­O&ÛƉ€œ +)¼5ŠèÝÏO`z›ùBB&RS!‡O—þ$¼`ã ÙöšÅ ?êŽ «¤Fì +õ‚ˆeµËdè&VƵÑYŸr‹ +ðs[®ûD€žóƒÕ¾ûÆIJ1ܽv¬Ñà º4BÉD{`CRú ¡£8èÉÆ9é2±)–oUÀÑs¯E1QÐlƒÈ%6‡Ù›A83 Π¼ÿ®…¼àó›×ê ø R]R´Â&¥}'•&ó{º~¸.¸2mlnÐ9»k8 +»ÆC²($V?€í8õÑh_X΄6k<ƒêZ‘UºJìEEåÏΓû+#@æÆʼnÊFô/[£ªB´Ñ'2hJAB‘VZÑ/ÖxØ#tpÐ4Éõª*]B 8{ˆ[v*Lø,†.ÙH»–á†aàu²)M¢òˆè£‚äUڂ¤ì[¨{)ÆÅwMì’ÚÄ,©°±â^/¸PˆÝÌkn˜xhÙ<Ùtv¦;Z‘ß¡º`¡'×Á”3¯ËKOœ-4¯.ó/u,P¼Gü……Y¹9ƒ¥±öÑKµÊAǝðI±Rëº/K]¸‚4Ù©:äv)­)òò5âÎyœ:íëÏÕ|!Zþ ¤0덇ô%yƒ¢ÈÛû̞$•‡»‡ÎIŽéº +×.Àf ?âÍ&·ºH@áڅ¢oðÿdèC]B\¸æ´À¤‘ÙÞ `¼I âéRfQ0eÍAç!¼þ òJ>iéê:%x Ž¯äÿsïÔ7(2Ïo¨MêÂ® +{IB=÷3¯V¨ÙϽc·âÆuŒ­++S1åw°ðù û|ÊÖð W­óÞÝ= +¸ŒÙNçà~€ÿ‹sçyt;ÕjÑîa›ZgMImÕVy¯i :›4\eØ^¤‰fAA¸Þ¡·D¯T£A£ ßý®è^ď¹â@¤Öãئû.@md"Z…ôÂ,p.Ym§ªhÓ ¡;Î !ßû—¨a܁!(N8j(5²—ÃSÉvR¦èPýQÒñ¦A©g)³oQؾÖ·µ?¹:¹?¹lXx¦Á_1lCƃءý\Y4Ù`œ8R²¡µ[8)cj;¬ÓÝú-|œ ^UÎädríÚ "*,w ®ñÒVcðXLqð2ÍeBÏç0#\çŽñhq1Í´&Š† +(„(‡sŸ“™í8~oÃÐI’|²ùmCGý8݅ꆻ“A%ôY¯Î¥ü gÓ%æá[œ„a6›Ìop&˜†Ç@sF·Ó³“ˆ~DîèÅÐAƒ¾ +òÏaÊÅÜ^ë×aŒ'|¾ràÇ©‚†I¨Ó½NkB}sRmvԙ–AýÀ> ûÔ f‡G´)@æ&´m°ä85£mÅ0ÍVSBô¹€Þ£Oø"ƒTà{àP MLEÏ@8J³ f‡Ù #É@Bܳp ÂÉ!äx±Ä¼œðqÄñæéîãÛ;z¬í'îåÞ·%Ç`¼ø |5ŸõÑí +[&å3…°¶†“9ý˜-g ¹zL§­ÿ¸úÛß7#endstream +endobj +552 0 obj +2310 +endobj +553 0 obj<>>>>>endobj +554 0 obj<>stream +xW]O9}çW\õeA‚”å£<Áöcûí*ú€´rfœÄÅ3NmOBþýžc{ ºÒªR›&öý8÷Üs¯neÆrr ‡ÇR5[—·[¯?œÉøHn§øåøjÙíïïËmµ}<:É;×(Óʟ®ÞY™:/w¦­Ý*ÈÙãë«÷;·?`䍌Ç4»{'°²}í¢~+ù×£òëöí\µneڙ]EãZ©`>‚4]57•ˆcΛ™i•y÷ùêâÓõ(>F™«eáõÒ¸.Ø5­ïËÞøpt@—¦­lWëZV&ÎåF55¹*F“ÕFEí ¬š pþWse¥Û(¦.›8÷ 7 ]á,½ìm¸y_†½+ß³(~î·¿šj®|-7ø{¡ïwÒ½ÈñˆÀn_HÁTm-JVÎ?̼뢼ý¨ªh×É{PÆZôˆ¸ „¥Õ‘wdâ>~Dr´6Ó©öº­4³ŠLF ©MˆÞLº¨&Pu¸¦R þZák`ÁÛ*‡œc¢*!ï¦Â£`Bµ•UU:ÀŸC*%2taƒÛ}á=ˆ¸ò”vƒTª•‰–™W-ÂR´bÖºt|ÚYà²42˜‘/°×#ŠPHÜ^j?ð~¿}}[~/Ù{ ë5p}bÁó©Ð-ÎGV ì8р&ŠÕ +NSÁåöú£´nu¿3*þJ•Y’›«K©¬!¥К‘g ªB9Ì"}ýŽÅ\‡T9Ö}ˆ)D–9s'Ì]gëAŽÄuÁ€µ$îl€Å3-ÚÔÇç‘\X$Ó®M}¨¬‰p=-žZ©')Ê^MYdÓI°ÙXµ?.¿~¾»ùtý‘;’OQrä¬x m¨w3U{2'Öôs–XªìÀq)ÐùO!t(”×6— @ßê½Ì¾…Wk„ 2£5ª.P Øj¨8Ò¯º™Í¹ÔÅ¡‚I†Á“Þtv*o‘ôˆ¤5dËQ¾B꤫›'¥¢n Ìó¿ž}¸Ë´ +ÃÜïÐÑ$ÔóØ£=kV&ÌáºÇSL¤Š¨º"¡½þ ÜА EeÄKlj™s®…*¹A<^/Н3ëDû‡›äœ— ”N ~Z@X$¡`3PqÉti44³5¡I—3ܪn ¾Š^EăFxdç+kuX…‚-\†Âv¿ ‰“ÔA!v Sßï0åÊk¸ÛýO}Õ¹0›úf‚§àE žÆ•ÖÃjg‰A]M²]¢vCßÐBK $žJYDՈ(š”8œ6AÛ%`,¾¯Ì™¥¾¯W‚ýE¿ÕºqȸàúÜ­651µyŸA¦ýDÀÀô®‚RY¿k|éà¾ÌÈLèdº ÔÈ<‚*×À/%x0˜ÑSgSlc8‰÷sc½ :(:¨(Z#ºÊYÎ*;¥%‚­ÖÁœ +¸¿šs8â+Œ – :bš…ÕlÕ>4@×ÖÚÛ5eÛµ¥}…nWsLl:àÅ ûSáæâŠRP†{„¾æ$/~MòKɄV¡…-´pà4÷Ø´‹œ¤*$‡egZֈr¸Ÿ%½VM)!p"½P­~™‚ce‚y•“Hm}÷¤ã¹=ûüþS_Òꆭ§e3ÿ')c5\ uHC"?‘g’ðpöfWàÑh?É >ŽÞŒ_´-Z4p՚®ßÚ`Åd)ï+璵5/ƒ¸ "XHRK€”iÏS…Xþ?Ø(d€ñèPç×ç)Ƈh”<˜êaÏM±p3äò›ÑŠ…†ƒ^P(ƒ&€·2(@¹u¬',Å dýN† # Iä{?z# g0€Cl}ÚÅو«˜BÏşh¬Ò/F·_X`É¡”œúœCã47¨ˆ²Xz¬0w¡X6—œêlØ) + ±~0–¯èÚÛAÔY»¹Ò,N……”RÈ Ã#[bs€ÀBQ’ý¬©À«¤5 $ ôÅäväQ<¬Ôzæõ÷Û,%vg*Á®ø®mÉ¿Wß`S®T«fø—GÞ¥Ñ^ám ˜~‰C֮ˆͅ6«Y™ u­*«ÁMZÑ^.w¬Aéb0×vñ hN¸ßuk1í¸M »)ڧ⃲H!Á,Ò"ñëriúà†;o­ñ ²x4@‰Ä¯WvQBð”Ë<6¾,ló–FSúéò Ž|ñ·¤Ëo!¤ +ŽN1n¡n!AKF4êAó?¾,Ł3íNz_²4*Ñ¥ì\ Øó|µì<,ÍDEˆxz®¸ÁäºXŸˆ}¿˜‘Qx·¶‹âOÉòtB‡Ô:>>>>>endobj +557 0 obj<>stream +xWÛnÛF}÷WÌC‹º€Dë.Ùh +ØIˆ/•&@œŠ\šŒ©]e—´¢¿ï™YR¤-ê ALîå̙3g†ß†4ÀŸ!ÍG4žQ´9ºX½] ‚Å‚šìޏƒMÓàÔÿ×*JŽäÍpzzx5™’W8l pÃáœtr9¡áV .ž-洊åý€VÑñ…J væa©£4Ó”éÂP‘*ŠŒN²‡Ò†Ef4»Â–ÿßõ(+(s´3¶Hwi–c¿1¼;,(5; +éS¦O?S”gJ´U·lÜï«oGêÇÁ ŽCl{0úŒƒ‹þh†0ð|Å·ûkkÂ8 +]áèþ¸¶¼¥Ãc +ãØ*çÈ$ڕk­Nðeúþw–kU¼ç‹@Ñ÷R¹" U +øYc¬Õ%Øs±¼¹;œÿææê|yýÇ`ð'ÇÈüð±²$÷Ê„C°£Ô§œ¬K2ë +±ß +˜·`R1R«"•=)Ð +.£”˜ù"á²½¾E‡UG)´‘SöIY\òAÚßžÐ$®ïñs÷öÃßo?$` ˆ1+|ý#<éOGÁ¢“Ī’V² ôày3ò5²jº»º@èNåö3øuLŒ¬{†ê\Þ¾þ…\BŒ÷Ç¥1ÉaîÆA ìZ>£ö ʑ+=&ÎÔ§GW„ú™jÊ­*l¦áP¨®¹·ö7ç•Úì"›m¡¦šÏØø߁=çS5õ 0iN…6J ¥X¬p™%•ºSb¯ŒÀúºË§UaŒBu—Í¯U?TT*¦õ^bõuõž'‹ ÷ôZ/(ÎÜkbÍFށO¡±Ëg¯¡£Nʤ¡£V\«T$O¨¼âa8GïT±Ô‰©ëµ®ÉZsÐ`”H‹õÏ9J JD¬òÚÁ2°2æã<¹Bí֚æºËt¤$@œ_Õ§è]òó0ї6E]² 7%ÊyÃþ*§¾³¾\´=ÓÑÕÇ»ãÈâCqó$av.Š3˜Haì¾a¿¦zÚ°ÿߊ[ýL§¨¬£GÄTÅSÅÐ9<ÞXZX—)‹^äޔ"U·UQ–xùñíÄQÈ2÷I”2d}oÃ" èe ~„›m®zÄvæåpŸXßß´ókÛ-DFªÙb¤xDè{âß3>vÿWqCa-àYCaÍjWÀ/–É ùæpª–›>+¨Ê±Š¹kGÀ Ö[Áë›ëËå»àöæ½/ԭɳ(cŸ€Š¥»Q¥ï†lÞA^Šµö®¹U&Œ‹)úÁd1Ç(2Â_fŽ–“ËS¢WóD1žr3o&ŠY°ÐQ^?–­ñáŒË³Ã#‰‰Hn(ý(Ç+ß×b³A/ôþËýr¨ +–XPZù‚Žý˜<7;4Ÿ†Š×ˆ¿Pµ¶ Ä<ÇÎ/ZhaFåŠ-¹Í:@‚’jJð†ìRSæhdkÂ8\c恃â©xf•³VÎ5î‘TÙÌ>ý;›Š¨.¨r¾ËpVjp‰ .¡HÀ‘ï4þL§²IˆôÚêL\%V&riÒ\µ=™×àr+ª—Ý]Ó#Ěø ãç;¯²Èg’‚G½Øì]¯è<Þd:äè‡ÆØD%•üVMH<ʀÂqàNñ^îSLÏ£6;Ý#g:r¦… :݌–…1¹kϵյF›ù©Ÿ:[>BKJÃ'1¼øLÚøÉå€NYט…FS?Ž6©QaNg…ÿ°9Ñ+:‰Ã"<‰;©õÒâCî±C‚l÷À*™Ç¦2úŒiæƒàô‚À:Uì_ÆCž_ù¡8€WnÅls3dklœéÐCVÐ>L“ +\é§ÌÍy“"j)ú°ÏÛös]£Ì%Åíucbvx86æó*Å,D–SHª²ÆÈl¶˜F,>%¸¼ðJ×´UßP–Îñ @&fH¬Ø³qåӀWût5yÈQxùWH¾]ðmP5žùé½1ŠÃø†ï¡ø¸*Œ!<·¢W´W‡/ˆ*…íjEý¬C™ýO.Õ'Øp<†4›ó‡î»;¿º8§[k¾,½i 3ÑÎæXޟÝÿòÖÉ|½Êþñ”…¹ÿuô¾Äendstream +endobj +558 0 obj +1624 +endobj +559 0 obj<>>>>>endobj +560 0 obj<>stream +x­WÛnÛF}÷WL]U‹ÖͲ (œØn 4vkËM èeI.¥)®ºKZQ¿¾gfI]˜ô­¹8 ɝ˙3g†Ÿô©‡ß}ºÐpLÉêäýìäfvҋ&Úÿp <z4 ¢zєp9!§)ã#½¨;»xÿüvDý>Í2¶;ž\Ò,•z4K:³¥¦diM¢Éf«2YRfrMƟñÄVÎë3ªÖTZÚÚ*">¢bûªic«<%Z\k…“•×Žy½VN•úÀÞÛÙç“uûÃhÿ婄™7Ï´1yN1¡Š…NÙ ?2NŒjgUiWª4‰ÊómðoñŠ#_ª"U.¥7´R‰³ÿlIåÞ¶ÜÁ>›K#úËV”¨/¾h aŸ²G²ð–9»âª85N'¥u[Š·8nŠ‘Ç+å’/só¢ß;:¿íєñíSwp² ÁÜ.lA>qf]ҏõ…ŸÏߓ]—ÄÈS‰#vèé+´q¹T¥ôÍñ Ï_µ›Ïïof¿>üüpO~ Xў-hÔ«2¹Šsôj›<ü>½oð”Ð1üÚwA¶”Ï0Áù”DóuõGûê72ÚÂÀ«XÞ̈i‡ŽBòþ¸{ie+ ¾$»§›Ç?n¿ÊNµ³KkÌ?ï@'Ð~Á=ÈÌÿ ‘pG¯+ Ö`Ê´Cd §V¢4 «E'è¤BwI‹·Pú:ë‹pëüö¢–Ïþð"BŒú¡<Œ9Sn‘Sp])_‚±³.+WHüH‘f¦Ñh„ŽM.qݟBâ ø^®4êOÄב^ãE®¢LoX²Và؞B¦ 똘ȷ4(é:€Ì,X‰vC¯±†ÃÄ2k誂x§½Œ1ºqZü2ÞW2# @xêàrRZÊx²/ìÛÒ,˜ÃOj+‚yE×ÐnõÁ¥³yŽ“øßv8.Aü‚½²ž†u01žA•ð°‘ÍNȃlò$¦ 2 + å(7Ö½PŠ, &Lo (ßéxðÛyúåêñ¦å.Ô¹qýg¤×¯îîۇ¹ïŽtùÛ/ +›/¢ÄÜ£ÏDNÑ«r³‚?OßKÏR®_u¾Ab;£«¤¬ØK †Râ‚'%ú¼@ÅMÐmTbÇ™6Rš¦Ú¡®+/ï†òês.5«AÔ΀£\……³ ¤L1»ÖظQ>  Ÿ¤¿A*–ú]¥>Ü­­vD5Õr“Mzfõ¼£2nJä:S¢iˆ\&5°kˍ¥ÃÒI —©É2´ ô*«p˜ûùÛ³šñÌ*E kӖ“jÅ4óé°8ù¥¬ICz3Ò¬ï Ýõ4tz§ò„§$³çû~ŒIZÆ; ñ$\—ÚÉQ¾Õò íNYÇ?A†¡?;ýE(¹Mš¥â ·ßH­trÈ|Q¿Ú内¡³-×ßGtËC–Yš©"²EûAqŽŠÅö‡¦åµ)MXXNwâpJüõ€5 6Jã±ô¡È›|Ôq6L¾Ÿ5~æ ý*çÝfK<ãZ~¿‘Ã9³X–?Íßò»Ýéœñ Ä¶†¥µn‡Ô‹í—F»Däv¦¥ŒÐœº2ÕXŒ°§®¢ß˜<¸ð/lZQÝ +›™|î„Îd]­ÕDåµ= ê¾¶ÌJ@UË3zt'¿Að¤×ÂZBýф¿"e LyyåÙ-ûI{~³Ÿ °£à|_žßNqŒ¿v0¤{ü%°_NÆÑ$D<êe cê®ð¥«‚|¾£']Šâc>>>>>endobj +563 0 obj<>stream +x¥WïoÛ6ýž¿âV h +؊e;¶S`šnY tY׺؆º(h‰²ÙH¢+Ruóßï)JŠÒbÃց%’ÇûñÞ»Ó瓘&øÓrJ³%ÅÉÕúäçõÉ$Z­¨ûSíð0¡éJlñÁ‡pæ K¸–ji¨Ô–öâ 'B„tÁ #¢VÒC˔)™§#Òe~çœb òSÀ¿½¨dDë=ÒWHQlvp»»3Œ#ˆÓØJ%V¦ÜVr=TٚG„Î~ª*™X]Ý}#—]=z¹|ûì×Wz§KzóúyH戎{•ìV(øXˆòÎG…ÚãÚ$¯Sv —3çf %¤œtÖw8À)¢a>Èԇƒ®¬ËuØƈKU–ÉŠ‘ÃU Í…ì6¡‹å$ZBրçח-.f—`ZŸ ‹hM£8bË©>Bʞ74p áàúd¨®ÁÆgœí2 ª”¾Jïw¹ÞŠürŸ0þ8¦ØFL3¼ó`Ítžë#§vsÆʯ‚¹²yòÔß<¡KfqLãé…çHîŠwvO?ÒÿBººGÆ]ûÄÛ7›Ów›Mî7'øåýøÆ|ÏÂsv:¦2uîsoÁúà"Á/¾ùôÆÛl써…x͈b+<97毵þ8H·ñ攍 @ÄU"I± Dmuš$"Ç[O´÷ÌÃ)vû#z™Ñ®‰ T;mbÙ·:Á9f„†¤xûàòEmìGpàVº½ŽÂd2Q}XØ+Ķv¤Øæ`ºÏèE:4‚27ÚʧÍzç³÷ùm’Ót!êÝ%öÒºÊÊÃò¬!V9{ ÛXŠ-VƒN&¢„³ÊQ—Ä  ­lð×(f›3F³•ö(e ÖîÀý¦4÷wqFèæ·5ç£rýƒ¯÷$~Ë ÷Éqþrß FXô·6,-ã®í}‡¥³9W¯_yŽN;Ž¢áüŽâX“1Wtr1ÁgWãG¾š §Gp»X­¬"zëÀ³ÜŽÈҔ©¯ˆÓpû–•r¨æ°yî ñ™£®n ÁÀQæùȵJeт´A~Ñ.Á*/ßñ¡)hž«»Ù^hYÉ]#höÑ=l!‡ÚZ/¢-œ™£ßm*¡‘_ՖŽBÙòÀèAdÄmêÖюŠ0Ôòð¡Ì5-ì[â&VÔI$#èTÐîUðô•×¢(0›ÓÖ)w_ِ¸’Ý ý$ðè¨òœÒÚ*Ì8䋡¡ªÎ„¤Þ¶=—%ÝrŽt¯Y£dÚ.ä®õ Ro÷57Ù[®î(h¯ÒT–›'Ã.Íc…j¶ðé1ÇIv{LÎk‘Œ4l‘‰À*»& Şûº£2°+ -(š|ç´±u– |֙oà<‰5½|*p&¨Ýðƒ‹yÀiÇ2 ½|rwwCؚY£üH™k nä +BûP†;Áu½ÆÕ×éwŸ'ý žÍÚɹœ#@<™bLx(/3'/÷FÙ§1¡Û0êÃ0àç<ÝjtiÏ·#2·0ÐÃQÒíã´õCsYõ/UaYí©$ûºþ'eXÒñ±ÂÓx¯Áu ñ…¦}~½jZ]¼XD1-.›™sæÕ3z]éOh?ô“Njþh‡ªq¼Xbûx9ÅGIzæEþ¾®ÓË#pí†'ó”Þ6ɪô¦ù>yÍâ+ÜG +'i¾äÏ*gq¶äè;¿Ÿü s5S«endstream +endobj +564 0 obj +1501 +endobj +565 0 obj<>>>>>endobj +566 0 obj<>stream +xXïoÛÈýî¿b /rI±äŸ p(’KÚ8n­àZœ‚Ê\I“»¼Ý¥m÷Ç÷Í,—RéÜ¡('±Hî̼yóæQ¿Ìé æt½ ó+*ê“÷˓×?]Ò|NË tusM˒Îfggg´,No]ÔoéÕòn»èn;ýH;õ¨ÉºHÅNº¤§Š4¶:R4½Þ¹Z©t:³t»ÄumiT¹-~å‹#2nW?£éü|¶@èSµvzÆþuy‚<èêê_Ü\ãï~¼¦MÊûM—î9_ÈӇįf7³ÅìbF?[º§@oþEwÞmL¥é^ǶùÀâjvÁ üÌ©*®ÃÓÆø i2–K9œ6¡¸C&|ß:ûðnÉ5^«¨Ë +#Å©ºªÔ>Ðè>*银íh2(yôA‡‡èšÑ„FÈqëUF¤lI£[wΕ£Ñr§mi¼.¢óÐòHÂx*œÚÆ@O¦ªh­©Ö~Ëm1q'yV®PÕ ì#ò2΢87£Ââíjõ”[­šWX­¸@«jÍ„vôo-¢1.Æ¡ŒÝJœÚ/dȗ7ÞÕ¤U±Còÿví ºdj5âF'¤a8ÙVn­ª¯äš(©ª=ØV(Tÿíu`˜ÂÎMù¬¿#]L¸É• m0ÑàáÁ­ÑPÞpüZñƒUE•Ž‘Û†$TÑ\ü¢ìžÜFJíàÉÊÑí:ChÂMB ô =âjÖq °Ñ^ÛB õqC{×¢ss¤íÆùBƒ<-}t÷HK[„ƒ{RJ성Ÿ}zw j‚7¥F%x®¦'o"Î/>pĸù!©šÐOÆg+i÷3p ܊±zB[<çèGTè]EwÊêŠ~Ç¿!<äDUTP»rÆ”žçQÕ•ßËåAŒ“ß@û]yŁ¼S5sî œp²úü· ­Ûù¡_¡Q¿2ÞîI®nZ4–8[¯×Îř¨Û +˜hž>Â'ÿå˜[þ èÇÊÈ48OŸLá]p›HÝõ@¿s½Ó#ýC GlH˜ÐøïnËǬYM?8&ì/!V$´ÐšÈ"̀ÝyS+¿'<…‡ÐÎñ!‰¾/Sâc@&ÁÑ`þÿG$³”.:p—4½\ÌnX^¿Xž¹‡&°^B«måT‰n‹~¼(g–'DvЋË/ÊQít‹Ý‚áËèEÄ«³ÚÉt@ÙXê +ošØkê05Œ©Ï'Þ³Fù¬™IÝ,ÿa¦4Î8H§¾›NVô!(¢èyi:h«¢µÁrݲÞ$N@} +j0=‡á‘}7ItTxÀæÈUä.B»S´Áv8í%{˜sÐɵ{–¥$z÷ kфšN &h2ó÷+5D­JÎé[⠆Ác_™îûF³ sۃª×¬Š 0Ak'á9_+ÈÙò† ì%9|.è €ÉKÆØûã?,ñ(ñ"©-„©mP@ç€Êä±&’vz[•l”Ô²ªŸy¡¤Dz7^"±A…فí)4º0ƒR;Jv·Qq7¹ÐTp]͆wo'ÖÇîïÏLâÝ÷aöɓK;:„ ]ƒ…ʆ4ëJŽ +DN@ ^2È:Á˜¬BÛG’‡ÏJ¦Øm6´:íÊ2gÇšT1ÃS5ö­*§Î"ÈZ¬‡¥·ÓÕ«{Ãijƒ¶ÈˆtKÕÀ’´ÇÀ“wŽ#.ÖlÊތ…¼Ã3¥>hšT+¦XÊËÞ­ïôќöŒé/&ä¡î-øëkêAûžÉÎ@yd«Ÿ4D9×Á³q(äàšÙð [ø1é´,†YŠÉ½×Žpîšy¬”ÝÆK«p W©½wðºý¾}zs9€¯óy̎$Pœ4ÿ¯…žAZx×À0× ´ +Ãt:m)¾›‰ãu÷É $ôü½ +PRHQ¿‚¸´Apò.E¯YA×Ä B¦yNÒ»¨Äi­yN¯föµ é5‡³À€­ß™†¼ÙîmQGˆAäèg.LòǘþY—p0¦î^ Ù²ŠpvñÀ[îD¡,°aƒŸÇ ž ëd ·`Lkpkl­áisàì7äÕUü»Áa–¬~îß`¥ùû~—EL"¦¹›a¿Xº9IÚÒ-ù¤—`ö# øú§›îÅ{~u=›ã;ƒy²v÷ï>½ÇvîÛü®hk¬JÅor ì4Ý>½^ૅò4½¡ó;ÃÆl[/·ÑG8ßòò÷–_Ô£@ÖÐ?;Ãÿ…—1Bð Š|upq}èrâù ‡Á×ÿ8ù Y–‘endstream +endobj +567 0 obj +1902 +endobj +568 0 obj<>>>>>endobj +569 0 obj<>stream +x•WaOãFýίEª +Rb’ ÐO=T ô.-ª0B{/±½¹];¹üû¾ÙµãÄ´z'˜ìÎÌ{oތ¿ ¨ÿédDQvðirp|{JƒMfüht>¦ILý ßïÓ$:T¹-¤ˆIÏ(Õó¹Êç¤r*óX*I/¥•¦KKaíZ›¸K±Î„Ê_)VºDK#­%i#±”MÞzˆ†ËãÁÿ¿ö'Á™2w÷9—±*ùCâ=7"ë’Ècd¡Hárÿ¦asÓpœòM_~»ùûíþ÷ë«û·‡«ë/w7aø¬òX¯m^—ÆȼøK«t†OFÏT*ï•-ÜÅ}êÕ÷ltIk•¦4Ãa¤@8g6]šiCRD yPuɓ(’€èQҕB‘Î ² b‘(K ¹¡ð0U ™n¨Ð4•­aˆ.Ãp]'‹ú99¤Í¡r‘ÉðÀþœb™Ê*ߺ“‚K)2ò{©ŒŒ]¢§ò^n~¨¢†å› 1ðÚ¼úߎ*uìz¾úúx÷ø+gݨçz¨°HŸk…ãï—/ Ò02B„ ¥ˆÄ (÷ÉÝìÃCÐjãô?avÁ—g¤}`”ˆ•RÙR›B䨼d‘²ÑNÊ  +»(ô’L«œ‹Ý «ð[SP&óŒïpÑ®¹)y¢ð0 ÆIÐTD‹rÉIrjN)ÒçÕ +,€o.e,ãðÈSÄýtrŒXõ'M#ŒÜƒ Îé×Ṏ́ÈÙ øs #3½ªyJu$RèÒ ß{:‡4ÇÐÙ hÊ\6ᑗÑç« ÓæPh%Xɵ¡‹$Zß941‡êTwºÔÉe‘hó ¦×ñ\Èýo;t +ã±Dl¥0èDnI¾ŸÛägKÁÓóý֙zzUr­Lv•;íôَ.½ÓTt„ö½æ´¸nW8àtúÖÎcè⌢T¡ï[ÇÏ>Gb‘é‡^©±\ÂS@•’:‰ò“K42j +Ւ˜ê•3vÉ)2Ó¥M‹(÷—‡«GÈ.xp—fm$MAuý£êÑðŒzµï dP.S  •Ú.@ .ünE6`(–Ór΃…R¹Â'½k ՝8ò}OÆ17!Ê£…„emgC«2[B ,¶h—Ù’ÏB`™Îyžø Ýᚹݤ1|½d?°AuY=PÏoQÄÓ žAð8!`»âùÕå€Ñ`|Xä†F6Zd¬¶ŠAëªqU G!恟uÛ{êÈ5¬b§Ú+¸ËµÈ|·Ÿ.üó‚ÞEÅrԕ‚E@Î6€/U´N„sýp±‚7`2¢Jb£qǹ¥x†¬D +9{ò<ü.á›ÉÖ:é`A§çcü<ÄNÏüzq± ÃñYp›jö‹Qp ôD5š9×gm0“™Nƒ>§ØL™Ý)Ä  ×íöÀÕºÖ?ÿq£ãªfѶí›dubÁÊ'(¹b®…[—Ë,‚¦°b½&»”‘š)À]$F—óĹÐ^£. “ÚøN9¾=kv®íªÁ+ƒ_lšz_ÒE”Ò /ÊùÅ#Vzµu;{€(Cüs½Õó ÃDg¼8Tµ8þ[ÅÊFpž|…p ‹ò"|€%O§9Jƒµà*×¼æøò–Ž—c¨0eÈŠá(½yùâ2y%›8]% +kÈì-×ŬR#–³œù›JïLÛ¢€”m"wc«Åÿt¿Sù:A^,(5Í·ó6UóN3£3÷—½d_Ê{XŽ·DA¸ ×psVÄzôðŒ!Vp<1E_²Å0†u#>UËÜemä±Q+ÙqšÃa›è2YXì#(´“\vZ…V¦¥Q–>^õõö,º­ +¬¼—¹§eÛʹ\×±™“NSBí?µó¡L¿ín'+ºY·†Gàm»Ü¼¡ö˜ð„­š™Â1±ªÊy]b¡0 0!Ñ, +­:ßÔê-=®±þù,+5ïîUæ² WãÙÁT/*]ÊJX²³îµQX”—ÒdÊòA×7>>>>>endobj +572 0 obj<>stream +x…WkoÛ8üž_±0P\Ī‰致iï\|¹ØEQœ-Ѷj‰TI*Žÿý͒’jÓkPçaš»;;3»ú~Ò¥¾º4ìQ@q~ò~zòöÓu»4]àÁՐ¦ u¢N§CÓøôN‘[I*Œ^¤™¤$52vÚlÏi<¥ØHᤥ\I %ÒXŠF—ѝ۝hÝE–ÆÂ¥ZÑ­p¢EB%¤q·±ç$,md–áûÙôÛI‡ÚÝ~ÔC§­[i×N­sj¥[ið'Œ£{©ÊpOëÁ襹m!ìô ßÔY™-(µd‘µL(U$ȗ2ž–Všèöf5‚Ž‘Vª–$ŠB +®HÓ\\À€D·“C4¸£¢4…¶’#Æ¥1R¹lK¥Z+½QuœÞ ºàâ¾ê’b€…<<ȓ­u2§Z9£3zJf<ÖÅYg:Ù®8¤ñG+ò9^¥y–†f§VJnÌ2+HWm³×È­Q$™Åå¢stV/‹á²ËÂgk¤;Ö· Ðqå?Ír¡ mu9;«ð¯sðHsœFôÀ€ +ž-Ž“È9ô¾'\wõÛý͘\ipXÔ¡¾ú° ¦#Š•Þ·Ÿ.+.ƒÞíitT^ç°çúé?Ù:ΨÛår4¤6¥¤´Kcî…pŒâmÖÖÎ:ÐD¯ÞL78AO3-ϕ:µF¡ £snS¦7”¥j |6+ÝÉ,_#bWŠ 4atcaå9Íý) qá˜ÕˆkµH—¥ñIq¨öXRkK|bÚJW“î<”“‹5„Ú(ê‰y¾~ +'8:gèS + Tÿ[£¦\8Çù{Yiuö,“›ìðövðŠ(ð5I—Ò˜b¶Ðh¢Š¹lÄcQÂKJ• ˆJ )Œ–¯Üä29odã»Uõ„°^¹3|݀C”*“ÖRËJh4u[zçÃV^"Ul¶ES/…°v£Mbqx+m«£æIþqüáñëÃôî¯qä^ÜìŒ{x H´ +Q_Ö(¥’ñ;J‹H$ °±„AYf<ÝÝ>¥T’©ÇÚÅw¸ˆ.‚ª6)›iƤãÇÓ&UPɞÚð‘8f@ø쑡”–¹ý'¥‰%ÚP`ë`ߤ¡Ë&b|›ï&ÄÊþ䍙ܳÝÈï%¦IBó-óò0#v“8ƒ÷¶|qûH¯q첖°D±ÎÙ^,l%–)¨IbŽì8HM“k_*k}­Þi4ä)PÝ>k>å;ý”—Ö=1ÅàÇ®?p-mÎA^Åï­©ºš'&ÃÁÏB!§'˜³Ôðzq5Äkÿy–†±<ڍåþàÊÄý`DøK4ˆèKª`D^Û?¸†½ÍÁjœBG^Ð,)n,Œ±X°s“-dœ.¶ÞËÔ˜»J†ò›YºæϞŪæ8 ã‚ìo5z`+O_#qT6uÊ÷ĺ̒:T¸žo¬:˜²˜]dzÍ{¢@bÁ &÷ï«¡çý.Ó¨¾çÆ{6å-‹Bã'$öîU7¤s þ§!½a?º:ڔBC†MVÂÏч°3Y”å6R*ú2ºô–ÖpየZVO®noˆøíÞUX0¼ /ðœC/RUh°Tà š÷KT¨Ë6¹ðòø»§[¯?•ݺü#819^{ÔëöŠ»´<v3 þ2×ËâŸCZ+ñ,yzR"3Éé¥.‚A>¦1°H<"…œq™ƽðª²è÷Ph–Ó+ðú(:8…›¢ÌxYòbÃôÄPœáߛñlöù ¨×À5˜ FU^8¿Fùm¼Ú-± š´ø6ïíÀ˜ÙŒùÝDòº×¢tq(€ÁbØ¥þý↖wIÿ™`ǃû3¢Ð}pØ# ùp¾%*ë5Èà²å‹È‹ Èþ*òlVé Ë1 ªèvþ ~QÌîJ À +æ~xf·àuٖ,˜Tе݁Ÿ¢P¾;L k0:Fî6|zKÕC@@*:—ÖACÞ5úûz{wõ´èx+ô|_¡³¼Û'Flæ"^ó:]=Ù`¶]ÁTb¨cMTÒEòåû ñæ:úg +Sª°0âëÙl“*åÀ@ÿÐïíyê§ÐÝ—¡ÖóçT—Ö?^ì—/)+¶ÏFñ£Ë¶V8¿ÒÖý0J«žx%ûª-ïEØÑb<Å€¾Àȁý{h˜ñüUy›Ÿqü+Kž|S+62ÛUU-ðWÕÔë†Q¤Á N'7÷ïo¦úŸJnu\ò”ß/Âáx{ØÃskrܘŸ¥öû2Ý)ëLûéš&Ò9w(òQ‡ç/ÄÚ·9͋álÊßxá]öõ÷Éq4òcendstream +endobj +573 0 obj +1793 +endobj +574 0 obj<>>>>>endobj +575 0 obj<>stream +x¥WïOãFýÎ_1:éZN‚@BH€•øuWÚ#P⪚괱×dÛëÛ]“sÿú¾ÙuÇGÕJՉ#ÄöÎÌ{oތ¿îôéÿú4Ðшâ|ç"Ú9xLý>E)5:S”Ðaïðð¢xw¢<£wÑÜ6lnÛý#{Ž3‹êétLûäÒHø±:—¤¬­¤%§ÉH«³IKå”èe‘i‘¨â‰tJ“ˆJ£S•I»ÇçÒ~ÿ¨7@ô]|?ó¬æ#žv*—‰pˆáD^Ú‘¢…Àá©®Š9‡3++Mïê{#žþø¤1 N™Á{m­bï*à¿ F‰l“0”•…ÿ>øŽGãu ýSˆ5LC +ñ èxØ–H# L¢,e‘¨o´–´QOª2•[hâæ5ý¢ýL‘4¥¾,CO¦/_‹œ´äŠ³*ÁSž•TλEb©-×ã@ò¦":0ð‚á1JÙä?jš—OÇ&wÑ58WuîR•!FNo¶áϤyãÓD]V"Dæõ A^K-Si¸ñŽz}Z²1À<ú/7W¾ZHÆ:/E¡` ý\ØЫ|ò +#ùÍÉ¢A½£pë}<ŸÐ­(Ä‚ çt¬³^[²Š¥šT±L:EÞªØh«S·¿†g)jH&EçBj^9¶(ŽÄnҁŒ gÁYöh*eÓ9¾c $ o‚£á´N؅^†®!¸¨’ DcáÉØHþc·Ý`aðÖäŸ!/dÎ1‘rW§ Ôûµ±™žßz㠃‘ï¥Ýïéã4çœü1Ë8¼% gD¨ÌØؼ=kàªp°˜÷ÙîãÝïî>Ýoùãw=ãòq¸XàeØBÈûå¶ö$x¤Ï¥Ù£{£raê•F½½jämpz‡Š ?Wå÷wÎÞõ|ÓYᇸâébènz0 GaJPÎ%îÑì°Ð½p ?< ž²*W™è…H¡Fg÷h²Ø– /^C§R‘i¨ÑOÐ I]ú"M¹(j*¥†üX»p6Œ­À#I+ aï¡)“îGôð‚Uęað eº'_£Þº-[ÃùrО}iÍæÂsiäwSÝê—µþš ‚† )4*w?³Þ!*‘6F?úz Då0?Ô_aZ«Ìäá3sĨr +*ÆY³] @òk É€ñþT`6\ ™ÃI 9/2SYht¢oÐFŽ/Êè"ÇQA"ë2D4_­ð#%L¥¬1[àžº%oIaÔù#¶5© ‘ã ]¼-a²¡ææ٠ĹWÉ󻁆3ß EìöøÒ¿`Œª]#æm©ÆÂâ½ËôþÊE] +€ŒŸ ø~£ß¥AÄf9óQ±ÌgÎ h¤+¥¨›_üVâäeªÙÑXÅ-äs##ÉÃ[£^NNïjOØøó’Eju‰kÍ Å†ë÷ٖ¿]žÍf7“I4›ýĈ·¶Y^ØèíÔËúAk÷v6  f3nõÔp´2K.¤% âÁæyjŸ‚o3øGÓ~zÎj†(ä?çÚÍTÆ ½•é+y…¥˜íÓÏ´-AxÑ׺‚YÔؓРý•Br™‚ x›a‰òc+ŠØýÏ ›TT$Èíîì+qãz³EYW~Cêd ­Šf¥h£¸GëÉÜ@Ø=ºìý;Çöð4rÓbþ0àš «W +ÖÈôúòÓÃMô{S×ãÁÎÁŒÍÖ¯4ŒA0„U–þ56ŠéÎ[7©$¬Pü\ a¦$!Ó×äþjI@Þ2a˜ ÷&*Áå:‘YHÑò‚²N¶å)~iꔺvÁ¼BGòú²Åv¹•x#Ãr!ášþ›Úk4Ääxã÷¡ÝÅO´2j–.ˆ&ÑõàýIÓj}lî}¼=ø8ÇLÖ_ðž‚IWìës?ܾ?à%3ÙýŸï Ãñ µ?iØç´ðBôÛÎß(ëã´endstream +endobj +576 0 obj +1763 +endobj +577 0 obj<>>>>>endobj +578 0 obj<>stream +xmVkOÛJýž_1ŸÚ “„4¾…Ç•JÂ-¾ª*!]­íI¼ÅÞuwפù÷=»v^¦~ì̙3gÎð«7¢!¾F4Óå”Ò²w÷.þ™ÐhDñ +O¦W3Š3FÃáâ´¿É…#—ó–,;Ò5.4e::‹ö†4O£ ÞïÇ9Ów©2½±´ˆé?ˆ2áD",“(¬&ÃVfli#].•‰[kiÙFçÒR% 2¬NQª•RÙp·FØ϶M=ºŒÆ>µå´6Òm ᕓ+Éæœr]2eÒpê´ÙžÓÚ躢’Ë„ÍeeÏ `ޜ®¨2z% >'¡2P­ºÅ=¼³Ù—g·ÖqI¯ý6oÖ 'µ"Ú¸(üoÀđ×3‹¹xg’Î’Þ¨£šèz ïw sžzOŠLe%b(º×%Ø —]͞£Ûâ@y8Û´-&MuYæLցÎ-úH‹eÜáÓ£ +É2®ÊѪF»n’4½’Æú¬÷ýÀˆ ŒVEØ3b»Ìzٜj:HEQpþ2ËûjçiÊÖғPbø=H ½ÃQ$£•6\á/L§6Qƒˆ$ýвpèô)ʓʱx‰„ĝã¯}É7~XÙ$ïHý—)w“§N0¨Â‚Ò_5CJ{Ŧ”Î_H!qÊñS54<ò’]³}=û¥/¢L9e#>àÏê‘ÕN~XB¸}Îê² +\ë´£tMdˤÖn«¥p7¨­[×Ãâîۏçøq¹ˆÜoˆôK…O¼îç߇(~Æ.ª:¹°âEµ éñÊV׆C«ÖQƒ¿”Æèn}tïm­uÐJ¤M] XJàU(PiG  +‹m#&˪àÒkÛKÌpUì4‡!}§yÍÈðŽ4ËK?ø ÌewÿúKã+»kx㇠i§ßƒíŽ»è hÇoy­…fúÉiÜÀOOrjXÁ4]~”0+¼o¼C‚œ\É5DœE4w¬¥FO8˜`ÖøÏÁז‹z6²pÈÝÝ…Áì>ßßA£ôèüxÂr¥Iю +‹4‡gGó;iNˆ¾@ï°Ó­Hß`ãËsò´Ž· Áõ>p|ÜüvûxMì­+!ðÐvRKµî€Þû5¤u` nH Q9Hn\¡¤ðVXˆ~Ìwfú!îa Óå—k¬ØÉÕ ñŸY5Kûª]Ú£é,ò ûúhq£†Û9Z£¢Ã ,­½ÜÃHzȃæÔ 9֟F×Ý/Ÿæ‹ÿøÛòk曽’¡ÜÓâéÓaP&³It…ÿ°Ž'càÿíýíæÌendstream +endobj +579 0 obj +1017 +endobj +580 0 obj<>>>>>endobj +581 0 obj<>stream x¥WMoÛF½ûW zrP›¶dGrzK‚0Ð8n­ =ä²"—âÖ$—á’bÔ_ß÷v—’B‚ °-Àäî|¼yófôõl&×ø™Ér.7 I«³w«³«û72¿–UŽ7‹å¬2¹N®¯ñ$=_¨¦Ó­,ùT›\gò‡ÝØÚÉZwƒÖµ|6uf'«W«ήår~ çªÎäÓãÃßÒ;Soxjƒ˜´µÎæÝQ,Ò­í7…ˆ’q^2p)cGà)²0™nñFÉ/…-wë¦ü%æ1» ¡ÜрÀnt­mï7«¦ï˜–®·¦µu¥ëÎIn[X*-žw¦Ò‰|ÖÒ´Ú᥄”1¥ó!À™žË к­y Iv…–gU­Õ$(כNó@ƒ¸ZU9AZJÄÙ‘!ÍÎú»È}Ÿ9Ž®K]!®è½wš—|™LÕà¼|azâñ€ò_Oï%Ueé.ä©ì7«ò¶G¨ugÒpÿƒÍúRã Ä$U¥Ežu»5)RL— vì0nâòq%™­ €H[ç7V€Vm£AEæ‘i<„ÜcJ•J S£«Â8iÎK¦]ښ5òfP± ·nç:]]ˆþ֔pÎ:ópÞ×)¡U¥évb:B¿dð^@ªÜlzê!Êøj°í‹·0Pîúü}u†>“׳7ø¼½[âsŽ¿¾Æ¶åöîµgã¡1—É<´D ¤}\´xu?r‰ºÆÇ5貔—Ú`F¡º4O¡¶À53yŽö+›é2¼Õ‘Ò„…ea–7h½É¢!ª@"ÁÓG6;µEOƒ­³g`Dõ…Ë¡¾k¥R™&Π̤}ف×D˜¡}ɺÁJ¨&±/Âq4h۝À^]ë֗‚p-¯\kͬ@¤}7 Â]¦v}ÓV{‚žü(­Ô z±ISÛS`lm;0Dòd=E ]é…t ØӇ˜ñŽ×9íz„i(¹Aè¦ ‚Ò°Õ W£RÓóõ̓|ÈÅ@ƒå­­ “k‚o½Õ-šÖT–±@tRh/ƒ¡=ǝfÂ9àõýG¹ž”šI±Ò‚ëޔ¯T¼×(çÐ/.àu«¿ö†"íñƒÙ¡0Žð ª¥Ô ÃJ×)T¿6ÿÒE½s¯ÇpŒ¥ê›®‘›ã y‘Ÿ>ɼ‘,øÌP|•8i¦rëïz?{ÅjJZ¨zCêÌÿcþr~-Üôi**G'@t k _{Fk2ÿû- Â-2ؾ̢.ì8üaµ¶0±ŸÄ“¢+lï7HňYÖ7å8ñÀÌï$¬Ù7û¾òdU4¤Ã·:* B9Ì "ÄˁŒþª¬ÂPâ¦C`•áŒYz‘Ž°Î@‡½öh„Æ{ÔÕýì‹ÏFá>à¼O½Â Ú}£(-GKF@ŒL>B X0üïÚadøñ䛽Y$‹L¾Ùbš¯¤Ëä; §XÄ­Ržâ$Ü?ã±@¸-¡#ª Ôœ jã!YcD =;ø"Ù^Ûo”š hÀ*ïËr‚T¥«5° -KqÜ`ùXcï,Xð›aÃ;ðƒVî9àÛ;HP,!„×€_u'f2f I>ñ|´1»p}1æÀšì#‚5æA)É8«ž IÇM-ŒFü”žeÌ<9ñH.ã®ÇæÒÖ~ÇñT,W°®vbo˜ôöIaÎGgr¡åÄd4ÇʉùƒæàÓ°û±.ÒÌ¥´ökÇɔñZ‰N RÉá|ám|í5–;`@L¶ÜrÌ@Ü MÓÑ^˜X¶¼XïûbÃý:n©'ÛH¤'D–ˆ¼Ó©B8{ÞÙo…áÜIVŸ_(Œ¸­.E¾œoòq=>?û=#ÄíWþIi°³qgi™È{)ͺUíîË+üèq3Ã\õ«#áã¡9Ž’ÅY¶6F½F}ºS»“¹î|}¯îï_Ôn®Ãw¦ŸøÖèÇXd.QÍÊln—·ãôº¹å,Ìžý@/ÓÁendstream +KqÜ`ùXcï,Xð›aÃ;ðƒVî9àÛ;HP,!„×€_u'f2f I>ñ|´1»p}1æÀšì#‚5æA)É8«ž IÇM-ŒFü”žeÌ<9ñH.ã®ÇæÒÖ~ÇñT,W°®vbo˜ôöIaÎGgr¡åÄd4ÇʉùƒæàÓ°û±.ÒÌ¥´ökÇɔñZ‰N RÉá|ám|í5–;`@L¶ÜrÌ@Ü MÓÑ^˜X¶¼XïûbÃý:n©'ÛH¤'D–ˆ¼Ó©B8{ÞÙo…áÜIVŸ_(Œ¸­.E¾œoòq=>?û=#ÄíWþIi°³qgi™È{)ͺUíîË+üèq3Ã\õ«#áã¡9Ž’ÅY¶6F½F}ºS»“¹î|}¯îï_Ôn®Ãw¦ŸøÖèÇXd.QÍÊln—·ãôº½á,Ìžý@0ÓÁendstream endobj -514 0 obj +582 0 obj 1674 endobj -515 0 obj<>>>>>endobj -516 0 obj<>stream -x…WMsÔ8½çWtqª3_dÂ1ÝZ Y2r‘m-bKF²ÇëýõûZ²Kf,u÷ë÷^·œ­h‰_+Ú­isIIyö~öæÏ-­V´?à›Ë«íSZFËå’öÉ⋓֑ÑT璾Ü}üF¥Hr¥%%¨©q’îöü—%¡Sʬi*"-JéH8>ÙQkš"õ¾Ò¢VGù*Ü柊^￟-ébµ‰Öˆ¾Øó ¾?ÉM«é  +583 0 obj<>>>>>endobj +584 0 obj<>stream +x…WMsÔ8½çWtqª3_dÂq »µ²d(8ä"Û[ĖŒd×ûë÷µd;ŽKf,u÷ë÷^·œ­h‰_+Ú­isIIyöþpöæÏ-­Vt8â›Ë«RZFËå’É⋓֑ÑT璾Ü~üF¥Hr¥%%¨©q’nü—%¡Sʬi*"-JéH8>ÙQkš"õ¾Ò¢V'ù*Ü柊^¾Ÿ-ébµ‰Öˆ¾8ð ¾?ÉM«é¨ ÜDÎà*Q‡û„•„ïdJqÇÑSS -åsát-É£ÔT˜ ŸÕ|NÒiöœ¨mô,°}»øªtjZrÒ9…âQ…˜†^_FÛ>a`Ttdâ£2#W êôÀ!gÜã3RŽb©tÆHøÿ…’fØèjñ$}æcËY¢7Ÿn¯?Þ=>ŽiøÄ£Ñ>G(üÖ2A Âv\ƒªI…iݘ°Ie-mÉ ¹X™*+“»!1‹Ü][Sè9¢´Bר‰§JØZ%M!,¡æ d`´Û\%9Õ¶qüh͈‡•i¥Nd:Çö:M'ƒÌ»ó1ñʚ£J™`$´W#dÀ4<ªd¨&G܎ž÷E“e".$]Ÿœšyk҆9÷¸¸¿¾}|M®CÒ%2ÔžG=*$2!"žº#'©9`J$ªªè³t¡C³°‰¨D¬ -Uw {qDL\DÄù’Ìyè$·F«™C@Ú¹ÖؔIU·Œ‰zٯɬW4`¼hªÃuÀíêA|\ô’ÑîÇ×¾AìÏàôv³ÂÏíÕ?×øƒ(‡`)ïhi°¥lßí¼¬ŸMem¢6“5}Êˆ© ]¬Ù†ÙÔþa¤5› `àûÍá£\%'’ÿ(W3:0…X°ÊªéƒüKêizJôœ„ÝÌ:Ñ*—‡v7Hm8?¹º ž3Í`ÑÈÈVp//î‘Ô,¨H!{ …Û`ÈdPO.EÊD ™rô—Å{äÙÀÓv¼P¯6 “€AX:ӊŽIÀo%ZVÁoF ¹ÞXŽé½7À­`B[´ÿ²òÑç5±Æ|¹ÿÝ[Û ](ޓ*‹¼|+á`’¡[•XãÌ¡îÉ£!,î ‘ï/òòî'a½³Ø[ñåÉIQÂH¼Ɍ†®¿¶÷Î5‘µ¸:UØ撵õÿ -ÛlÂàœ*lÑ_˜`CN_¹Î÷'*Û#pÛ¨ÞéàË0W•ñ€˜çðoA ˆ¤ë7ù°3‹E Fç '€ ó]0S5Ó&„zÛï‹þúô4ƒ¥B–@„ -ÐPjŸàdÀ7ýDî5ìLòÇh&‚ð¼±òG^1Áa¹Ö‚É,àø›_&µdÙø…¡¾{xð€EÏúꄉ¢j4’(Ž9„1ÃshÎrFHäÚðÊ&)'Äê“%Žs.€6±*Æ#¬ `¡ -P“yÚùõv]þ¦óëåUtu²°í¢-{ë3?a¸Å=’²ó}@¿¢Â'x€çf«$PŸ:)¬;'yØ@ÙûlÌ£œ–¥ÌØQX¿÷<ˆ2´메eÌ»#PHebR9<4C[8V?–¶^¿É3ùöáóý‡q*÷†7Ìh0׃ÏÜ( Šè<‹jeáÉ`*fTùçàìj3 ›äBg~”Ùç],¢÷…‡©ØŽy´â¡UÞÛ¯†²§å~RŠjn›ÌÎo² °à-•ø™>»üùE¬_í6ï~1w®zS_a2ñ‹äòÄ®oß_³Û|ç™~c4« KŒÁ¹§.±ÅÏ7Áín Wã{›·| -)ý}öOE×`endstream -endobj -517 0 obj +åsát-ɓÔT˜ ŸÕ|NÒóì9QÛèY`úvñUéÔ´ä¤s +Å£ +1 1$¼¾Œ¶}ÂÀ¨èÈÄ'eG8®ÔéCθ/Æg¤ÅR錑ðÿ %Í° ÐÕâQú̏Ɩ³D¯?Ýì?Þ><ŒiøÄ£Ñ!G(üÖ2A Âv\ƒªI…iݘ°Ie-mÉ ¹X™*+“»!1‹Ü][Sè9¢´Bר‰§JØZ%M!,¡æd`´Û\%9Õ¶qüh͈‡•Gi¥Nd:ÇvŸ¦Š“AæÝù˜xeÍI¥L0 Ú«2à žT2T“#nGO‚»¢É2’öÏN͊¼1iÜ{XÜío^“ët € õçQO +‰Lˆˆ'…îÇIj˜‰ª*ú,]èÐ,l"*«BÕÈ^œq¾$sD:É­Ñê_æv®56eRÕ­ãC¢^vÀkòëÅÕÍ/šêp0A»z½ä_´ûáµoЇ3x½Ý¬ðs{µÃÏ5þ Ê1XÊ;ZAl)Ûw;/ë'SÙE›h„ÍdM_ 2bjCk¶¡ÅD6µéCMÆfø~3Fø(' ĉä?ÊՌL!¬²júh…ÿ’ºAšž='a7³N´Êå¡Ý dÛΏ®îC‚çL3Xc42²UÜˋ»Oœ§ÉR« +Óùûæñ¦··ªÎ â¢&.T‚é"_68À˜¨Qm’˜FרdZX/ýÌJQМ*A:¶O$5 *RÈhá62ԓK‘2ÑB¦ýeñ¹@öð´/Ô« Ã$`V†Î´¢cð[‰–Uð›H®7–£CzïM p+˜Ðí?†¬|ôyM¬1Agöã¿{k´ËÅ{Re‘—o%L2t£kœ9Ö=y4„Ž!òýE^Þ=ð$¬w{`+¾"9)J‰w ™1ÐÐò÷Âö~À¹2²ÖW§ +Û\²¶þ_a›MœS…m#ú lÈé+ÁùþDenûÕ;|æª2°óþ-(‘tý&0vf±Ôèä°a  fªfڄPoû½bÑ_Ÿ>Ï`A©%¡4”Ú'8ÙðM?‘{ ;“<Â1Z‰€ †:a¢¨äŠcŽaÌ𚳜¹6¼r€I GÊ ±úd‰c#Àœ  M¬ŠñëX¨”Çdžv~½]G—¿éüzy]=[Øvі½õ‰ÇŸ0Ü⎠IÙù> ‚_Qá<Às³€U¨O֝“<l ì}6æQNHËRæ ì$¬ß{îE :€õTÊ2æÝ(¤21©š¡-«K[¯ŠßdŽ™|sÿùîÃ8•{Ãf4˜ëÁgn”Eô +žEµ²ðd0³ª|š¡¬,Ž'H¿ì²~“¢I™t6àY +-2ßÚsˆÅçÙByhÏö {·©Œ)p$S°Ïg9.Ÿ™W€ž·)h‡ßÊÀk6c#F#¹³ªäíîÚ￳"?<-iØd®3:6Úïv¯ ŸoÙ9ï†9[m5»S²HÁNA±I±ÔÉ÷/¶_Ìf”½ÁÏ"W­ æú\(ƒ17ð|?q-hÉl‘º)½T‡ÉÍðBß,G¿ÝeâIû™„|1 ±*{lfùˆ˜*oåØ ß3ÿ¦®Œè¶Ïrá7¡PD›4Ã}þÎÁÙÕf6ɅÎü(³O»XDï; +;6:S±ó +hÄC«¼·^ eOË;ý¤ÕÜ6™)œßdA`Á[ +*ñ3}vùӋX¿ÚmÞýbî\õ¦¾ÂdâÉå3ÿ¹ß߼߳Û|ç™~m4« KŒÁ¹§.±ÅÏ7Áín Wã{Û-ŸBJŸýOF×`endstream +endobj +585 0 obj 1683 endobj -518 0 obj<>>>>>endobj -519 0 obj<>stream -x…XÁrÛ6½û+v|rglڒ]ËÉÍqê™캕2é­‘ Ä˜$´ª|}ß.@‰‚Òf2™8Ý}ûöí£¿Lè -&4›Òõ-åÍɇÅÉåã;šÜТÄ7·wø¡ «ìêêŠùÙ,»É¦=«FÓ\Û·*Ç¿›Êçë__qò†&“pòb:ÃɳÅZÿèés2–žçósª)*µò½Õä×Êó'ÔYít‹Ÿ[jT»¥Ïϟþ"Ói«|Õ®Èm×Ëè“'U×fã8ü]L®³)‡ ΗÆ68dZr}¾&åhmœoQ€;ÇÝU *å4Òh ꝶ‡ÈZjB:¦~Ó•Ö4TTÚrvÎô6×.K‚?¢6ýjºZŸ£8çq³ªM«)Ô±1öJRÚ—ǪÂK8\¡m… MITր¨¬j}T²7 ¢PÌk“«šð” •Ñ=µÚs`<2Ž¶¸Î:éiç¹âXîe”ÔbINçÄÑ[ÊMëúwÒó§9Ê«%0&4ãb|¦èãóœ«|üòÔФ1ÎÓیY¸5Ÿ“꺺Êž5+«š†YRµ^ÛR¢#´©Úe….s‰;†y§ë’y˜¥Ÿ s€-©sL¦ WqâXBPf0K¸´²¦ïÀQúÃâkxÀï]fÀ‹i7º9‰i–^Uí@<Åw ;=/¸zÇñŸæ¾<¡é5bpyæ­*P9ú¾¦òÜô ®nûF¦É´¬Ãì|– k-À’Òêji•Ý†˜^9Wíî]-­ sjg2"¹ Qù…íÛ 'ea0œ–†ß1Àm¨¼0ܖººçh[ò¶‡Ãçè¥_›~µæ¤¶´Á°Æyw&±9fìUüfL°ÎVnZo ”ðÚÅBÅ.¡ ¢zg—Ú痭s¢ˆ† ŒO ºxF}aêDTÆÔmÔ+«Hõ­×˜Go’D ƒokc^ûNƌhh Ê´úyB!ã}><’¸•[³YWPH¨e¾¢j¡K¼ßv2xÜ·˜«.ΕAö„ §Åéá- sbDn‘€ÀOatHI» +Uße´ÀÀ$@0°Õ*$í:³6†ä+ÝÚ,j€E‚Y–¥ÂÚ•8£.XÒ=$µàéjÞ;ÆÚb¥ð M!ùÿ \¹÷Ë_G;/*S8ü>èôÊ!òXVÍD19澟›ª®£,×F!MjLу{<àH;ܵã]‚üÜû[„8sžýF>CƒxSâðrè®<¼j´CÇwÆuv|+÷{-ɼآ—äºÞ‚°È_cúC/°×c-ÂW¬}žjŒ ?͹Œ2ˆkÈRÙ·9¯K´¹‚€†ÒµóP¦ÑڒFjfô{Ë F–Ã`‚»}~ûQxΎÅâ/4DáÿŽævÏ¡›ÌW¶6{‘ʇ n 4d‰/¸?l¾z1æs!Hêw°ÅÁ -¡s«uÁ•'ƒÖ…ø ¤€KºÞ§L‰‰z{ÜÏis+°d/"Vt¯: y‡çvÄ<Äô"å“"¼Ö@y•Ç ÖØàf Ë$¦ÍCÔ<´6hËNۃ¸H¯~[œÀÏÒtv›ÝÒÍ݌Æ_¨N™ÚßéÍ4»;2À×½Ôýj¥–ÈûžÓðƒÿx’1ÁÚÏϺ¸áŸƒ]¬¡×Öl€®£—û'84ÞDŒœ0F-· -½¯ãÞN~ÀØê{°Gäu¾nMmVÐL¬"LîF˜A_*ñߝq®âê¨l¹…é-Ë`{Ó FÐlN‚ïŒrH~45a’ Jkõƕ ”Õ¹i:x[ž1èÄøy`Ž, -F‹£ìk±ŠIÈÝt ã½éke©3p‰aæ@Éèc¸3ì{¬UY1Ö°Öb”M AáÌ&‰Ê~× oŠ!¶—6 ¾<ŠVðʲ°odAÐ(ìoâŽJîBRc#DtÌ£kØ@óE·ŸŠÓ 6È-èZ¼l©•,PÑä]ž¨~÷…ôag­›Ý,L·×IZ6xՀ…(›ŠŽrx3½LÝØ݆ûÊðSôLÈ%XIîetT¯÷Œ"¿Ûàí¯ÂKZô ÝÇ`"é!»šwÿBhB³½®åkÕ®„’HНF DÆ¢À~r4œ¥#­sé¹=Øßϒ,ÆID‡}i†­ðŠ,Û;˜{&8>W*;Ÿ À½±  _5²§$rÜ©&+ŽWÑhK¦Yr$ѼHQO¢ƒ³l‡¢4Ú»Â; wôÚÆis¡¹Á÷±Œ‡„NXCò -¼.<° }‹H¡ñևÁe? W7r âDø‰°^Ó4ázóW¡=à³½»hï&·³l‚_ˆ¼ãWÏùýӇ{PÉ|åæ~49Þ¦¢éäSáá‹Ù¿5)~ò[“›Ù –Œ>>>>>endobj +587 0 obj<>stream +x…XÁrÛ6½û+vrrglÚRËÉÍqê™캕2é­‘ Ä˜$´ª~}ß.@‰‚Òf2™8Ý}ûöí£¿ŸMè&4ŸÒÛʛ³Ë³«‡÷4™Ñ²Ä77·ø¡ ëìúúš–ùù<›eӌžT£i¡ík•ãßmåóÍ/Ëo89£É$œ¼œÎqò|¹Ñ?zú‚Œ¥§Åâ‚*GŠJ­|o5ùòü uV;Ýâç–ÕîèËÓç?ÉtÚ*_µkr;çuã2úìIÕµÙ:M—“·Ù”ÆçKc2-¹>ߐr´1η(À]àîªÆ•ri´õNÛ£Cä ­4!S¿ê‚Jk**m9;gz›k—%ÁP›þ[5]­/Pœó¸YÕ¦ÕêØû‚%©Fí†ËcUGá%®Ð¶B†¦$*k@TVµ>)Ù‹Q¨æµÉUMxJÊèŽZí90Ç;\g€ôÀ´ó\q,÷¿2Jê ±$§ âè-å¦u};ééó‚ +åÕ +šq +1>SôéiÁU¾~yjhҍçéMƬ ÜZ,Hu]]åÏΚµUMÃ,©Z¯m©@ÑÀÚVíªB—¹Ä=üÓuɼÌÒO†9À–Ô9&Ӗ«Œ8q,!(³G˜%\Z[Ówà(}añµ<à÷>3àÅ´ݜÄ4+¯ªv žâ» +Нž–\½ãø‹?žï‰Ðô1¸<óZ¨}ߎ +SynzPW·}#ÓdÚÖav¾È…µ`Iiuµ²ÊîBL/Ȝ«v ®–Ö†9 +µ3‘\Ш|ƒBÈöm‹„“2‡Î0NKÃNoƒà6T^ nK]Ýs´yÛCŠásôÒoL¿ÞpR;ÚbXã<„;“Ø3ö*~3&Xg«F +7­·†GJø íb¡âWPPQ½ó+íó«Ö9QÄ CPÆ']<§Œ¾2u"*cê6ê…U¤úÞkÌ£7I¢…Á·µ1/}'cF÷4´…?eZý<¡ñ!IÜÊ­Ùn*($Ô2ßQµPŒ%Þï: <í[ÌU‚Ê {†7śã[æ"Ä(ˆÜ"ŸÂ萒vVª¾Ëh‰I€``«uHÚu:gm ÉW,º ´Yԋ³,K…µ…+q F]°¤{HjÁÓÔ¶¼wŒ-´ÅJášBòÿ¸r–ïF;/*S8ü!èôÊ1òXVÍD19桟۪®£,×F!MjLу{<àH;ܵç]üÜûK„8sžÃF>GƒxSâðjè®<¾j´CÇwÆuvz+÷{-ɼء—äºÞ°È_cúC/°×c-ÂW¬}žjŒ ?͹Œ2ˆkÈRÙ·9¯K´¹‚€†ÒµóP¦ÑڒFjfô[Ë F–Ã`‚û}~ûIxΎÅâ/4DáÿŽævÏ¡›ÌW¶6‘ʇ n4d‰/¸?l¾zƒ1æs!Hêw°ÅÁ +¡s«uÁ•'ƒÖ…ø ¤€KºÞ§L‰‰z{ÚÏis+°ä "Vô&^õ&äžÛóTӋ”OjˆðZåUƒXcƒš%,“˜6{ QóÐÚ -{mâ"½úuy?KÓùMvC³Û9ÿŒ¿P2µ¿ÓÙ4»=1Ào3z®ûõZ­0w=§áÿñ(c*‚u˜=žuqÃ?;»X;C/­Ù]GÏwph&¼‰9aŒZ9o{_‡G½ œü€±Õ?Á‘×ù¦5µYC3±Š0M¸a}©ÄwƹŠ« "°å¦·,ƒíMƒ6!@G°9 ¾7Ê!ùÑԄI6 (mÔ+W‚PVç¦éàmyÆ ãç9²d(!,Ž²¯Å*&!÷@ЁŒ[ô¦¯•¥ÎÀ%†™;%£ŒáÞ°°VldÅXÃZ‹Q6- „3Û$*û]ƒ¼X(†Øv^nØ@.øò(ZÁ+Ë~À¾‘A+ p¸Yˆ;R(¹ ItÐ!0®aÍÝ~*NƒØ · k ð²¥Ö²@E“÷y¢úý҇½µFlv³0Ý^'i!ØàU¢l*:ÊáÍDôR0ucwN*ÃOÑ3!—`%y¸WiÐQA¼Þ×0Šünƒ·¿ +/!hÑs4tŸ‚‰¤û`ìjÞýK¡]ÍöV¸–oT»JV {t<<5‹ûÉÑp–Ž´Î=¦äö`O|?K²'QöI¤=¶Æ+²lï`î™àøT\©ì|&÷>Ä2X4|ÕȞ’Èq§š¬8t^E£-=˜6fɉDó"E=‰ ΰ‹Òhï6 +ï$l@ÜÑk§Í…æßÇ2î:a É+HðºðÀ‚ô,"…Æ[—ý,\ÝÈ%ˆá'ÂzMӄëÍ_„öH€Ïôn£½›Ü̳ ~!òž_=wï@%ó›ûÉäx›Š¦“O]†‡/çSüÖ¤øÉoMfó–Œ<8{ǧ± ~?ûqŸÍQendstream +endobj +588 0 obj 1868 endobj -521 0 obj<>>>>>endobj -522 0 obj<>stream -xWïo9ýÞ¿b¾]*•4IӤܷBTé8âNª„œµ“5õڋ½›4ÿý½±½Ív[¡B‚¬=?Þ¼y3þy2¥ þLi9£‹ÕɛÕÉù»9M§´ÚàËâjI+I“ñd2¡U1r^*?¦U©iÛ(¿…¢JÜ«@BJm·D‚¬Ú“h›RÙF¢ÑÎRP~§qtã<}Óv­­¤òR"ÎHCM)\U25ŽÖêtõãdB¯¦ã‚IgÁo<ãÄßÏß!üì¨Õ÷}2=.}ì2Qådk±ÂÕZIö1°pnôú<¨¢õº9œ-„Ìná‡`Ã6ÞÚhƒÔ‘Ÿîë•Q;a›.qÀãµµMrŒÝ`=…i§u9Ð¥¢ÃOבtE[τf„±rþDªڄ1óÇêe£ÅÅb¼ ùÕÿžá/¢Ø¤*¿¦é¬bEtà `ÃüAªÌ1ˆÖ ãê.™L¸y7ú|{swÚq0 pFoËÆHâ0®p•¿~¸ý‡ö¥.J* -A^Ø­"·aGkåCþÈâÀ#5’ÃÍ!fÀÐ\ý *• ÕS‹n©Ò,ðªi½…C6&èÓÍÛ( ¿á§Ž¹Â8ph¯›§ºˆÈñ ÐՏ†a„3å¬ºÝí.pT[<¨ä´ß{(–âÆ6©éÀéqJô²bÚ;h¸ŒÒ‘1†mxÀÒÀ2®júÅØ^ˆÈ3è GOŽ*fGá*H$Š-ÊÀâò1¨YÖO.uÊY{áp@Eɂƒ(QQ¥5²-ÝK›K'u(ö,ăà0vÑz¼6ãcÕq+ARÀ®XœnÞf¯/Ñn¿nÉÙbŠM¡¿í-¹!oD.‘#zëìFcÊÄ_ØÇ º‚Øì µ «§ÀȲXv|D VXÙ8bŒ¢{±…þÄz‡ • _’‹nÍëíXu‹mMTkqe] Ãž-m Π®õ˜¨5¢/|•*í½‹+­‚`>‘c `EJÕx@:Ù°‹î‘dš¦Xo…ç9# Öy›šTÈÎ._Þ´€cÓZ(™³Â`ç$Vž Ðc¯ñM€%îq¾ÁBË[`d°QÀ:ˆý‰ÅÁäàhÝjLtL‡|Ú±!8dHT®ÅžÇOC‰ÃtèT¢‘«¹ÑS¶kLZìUØÕ -±{sý}õá}½±ö‘Õð§Ñ™©€ O -Ï߁u‹hµ4ÉSõ/»%?ç ïFWw§é[oÇGö58”±8«;Àa|`”B¨lGå'ý§/ž1(QՀº6îý€s‚GÉÜëP2ÕӚ“{AØg¤P&(Š°Nnñ»Sê:ÖmÍH÷Qç‡æˆpGUÂtŽ@X‹rJ’MNg˜ËÂÔ%Vàd¦?¶§“K¼~­Ëi|‹õ§öbLêJ§—I\Ç_Ѓoùɗöï>>>>>endobj -525 0 obj<>stream -x}UMoÛ8¼ûW¼cˆUÛqí䘤 À&È6.º‡^h’’ÙH¤Ê»þ÷;’¯ë.âȆ$ò͛™7ü1šÒSZÎèjA²Ý­Fæ4Òªä[‹ë%­MŠÉdB+yñÕص±ŠL ™¼×6Ö{r±¦ëZSé -Ã[‚A½‚P0$y´ß(´È/‰vš¼þ‘ –3¬{ªÍÚ àe¾…¯t<)z -›a¢J˘óªgÑhzÕ~k$¾w&€5/uªªLÄmB9DûÎ=9•jN -õÝ´Ú€U|ÖZº†ùj7ìš‹E ç××\€^nŸ¨ 8oTôåùñÚj«œq•²—r¼,®éê¦X0Ÿßf‹eÿ|š?ÎpÅóHjDÛC`Ž ºr;XÑçÇOY°\˨@ غˆ÷•†°•ó&n´\³'@‡Ò- aˬôîèd·1 ’åºZQ -Úc§Ê»ÔvÒ­-­÷´ë^Mq_/qáPv!}CSªD|Ïo–9'ßSzY, ºwVÖ)@Ù. -†Q/3õ<æƒC4Ç æ ÉÌð¡ôÿɺ>ì.Ÿt}Ð!é­:áãí]덀®ôd¤wÁ•‘>¿ÜgF €øåv9X•N 7ŠùÉ¡c£®øT«Pïû¼õ¤®rY>W§ÔM~×8‡/#â äŽÆ,x­RV™3Š9 -Él03¨ œð`ˆŒÀ'›(¨1?õiÓ9cx‘ VÍþ­`|½Èóé ‚÷œÈ×}|O˂OiœÁG‡ñëíÓÝ-½x÷]ËHŸœL Ž›Ì -ï>îV»egL1_ÎQ˜7½¸ºîý=ú1x’Tendstream -endobj -526 0 obj +589 0 obj<>>>>>endobj +590 0 obj<>stream +xWïo9ýÞ¿b¾]*•4 iRî[¡ªtq'UBÎÚɚzíÅÞMÈolo³ÙV脐 kϏ7oތœMi‚?SZÎè傊êìõêìò휦SZmðeq½¤•¤Éx2™Ðª9/•Ӫԁ´m”߈BQ%T !¥¶["AVíI´M©l£ Ñhg)(¿Ó8ºqž¾j»ÖVÒNù)$Œ¡¦ ®*ˆGku¾ú~6¡ӗã‚IgÁo<ãÄß/ß"üì¨Õ·}2=.}ì2Qådk±ÂÕZIö1°piôú2¨¢õº9\-„Ìná‡`Ã6ÞÚhƒÔ‘Ÿîë•Q;a›.qÀãµµMrŒÝ`Â´Ó‚ºè³RÑáǛ¿Hº¢­€gB3ÂX9ÿ"Õm˜ƒùcu†²Ñâåb¼ ùõÿžá/¢Ø¤*¿¢éÝÝޟw ܃ÑÛ²1’8Œ+\å/ïïþ¡}©‹’JBv«ÈmØÑZù?r…8ðHäpsˆ™04W?ˆJ%ÏÚf3ðøx9åÆt×0óri ôÝ­94Ð]Ðr±s¨Z>Æ^)6Ž1&b|ž³ÕDm»m=2¢ð·t„…dËäX¤êÀM¨¹}ىxz*—®;¥Ÿ¸ˆ"h + ¨Ø¯)W@Ãn4Âùoà¢WõÈDˆ +gvˆ˜•#ÜhP6]©‹”Å Û#Qø´U?›”ÒÙx‡ÖäŸc…™#ŠbÁjï +R]¶Må  ì{àµÃx¯¡T¥#+Øb¶âÿƒ¼ú™G)‹ §Œ!n°€&©U¹yc4£qĀ¤5MH%F쉕•ù¡–T_Tó.š³;‘k•Ê€ +܏\S÷s×=ƒ•  NÖ×ÄHö˜óìÈÉDAÝíÅ¡/9óùŠýkəOg1áãhaɹÓ§˜<½E‰œ9Äþ<Ê"sƒ”Š¨ á**„¥­²ÊCA­q‘ðò#Üd¹wsm J®–- ©Ù;ÿ€ŽûR³„¡¼æ«]G±@=á=K¡(<0ô’0ôØîgˆwP?Zeá(é …6Ò­½>°JW‰'í•'ŒA¥Ñö_NõÔ¢[ª4 ¼jZoᐍ úxû& +BÂoø©c®0Úë¦Ä©.¢r|Âtõ£aáL`9«nw»ËÕÏ*9í·ÄŠ¥¸±„Mj:pzœ½¬˜ö.£tdŒa°4°Œ«ŸµFý.blÏDät£' Ç ³£p$Åe`ñaÙÔ,ë'—º e¬=s8 ¢dÁA”¨(‡R‚ ‰ٖî¥Í¥“:{âAp»h=^€ñ±ê8wLPˆ‚• )`W,N7o³WWh·_·äl1ŦÐßö–ܐw@"—Èƽqv£1eâ/ìã™]AlvÚ†ÕS`dY,;>"« ¬l1FуØBb½ÃÊ…/ÉE·æõv¬ºÅ¶&ªµ¸Œ².ÐaO–¶gЏ×zL ÔaÑg¾J•öÞŕVA0ƒÈ1P°¢¥‹j< lØEwƒH2MS¬·Âóœk<€MM*dg—/oZÀ±i-”ÌYa°s+Oè±×ø&À÷8ß`¡å-02بŸÀ:ˆý‰ÅÁäàhÝjLtL‡|Ú±!8dHT®Åžǧ¡Äa:t*ÑÈÆÕÜè)Û5&-ö*ìjƒØ½¾ù¶zÿ.ŽƒÞXûÀêøÓèÌTÀ…“Âów`Ý"ZF-MòTý«nÉÏ9ÈûÑõýyúÖÛñ‘} åE,Îêp¥*ÛQù¤¿âÔàÅ3%ªP÷Ïƽð/b®@ð(™{J¦zZócrÏ{〉ÂEÖ©Ñ-þqNBǺ¢­é>êü°À|¹Àî¨*C˜Î±kQÎBÉA²Éé sY˜ºÄ +œÌôÇötr…÷Á¯5b9o±þÔ^ŒéO]éô2‰ëø3zð5?ùÒþÇ (gŽ7?ö=<Z÷.ÄøN ü†L+ük«1´9Lˆ7+#ȋ18Ø9Ëð{bÊufÑt±Oñ¶}ÅWä,}ôî;4”nûï,¾õ"~±œá,Gÿóa4_Îñ¢Š7æ 6þûì?±£÷ãendstream +endobj +591 0 obj +1743 +endobj +592 0 obj<>>>>>endobj +593 0 obj<>stream +x}UMoÛ8¼ûW¼cˆUÛq­ä˜¤ À&È6.º‡^h’’ÙH¤Ê»þ÷;’œ¬›.âȆ$ò͛™7ü1™Ó s*t±"ÙNn֓wKšÏi]ñ­ÕeIkE³b6›ÑZž}5vc¬"H&﵍́œÅEì„iĦÑT9O·šþ26ý$×i/¢±5…Cˆº='ÑÄ­Kõ–:çc èÈáuÿúæëï“MçÅÕÏúu„×$µÂpÁ΅`P¯ ; I¾ÙoZäÇçD{M^ÿHËÖ-5fã…ð*߈Â×:ž=…Í0Q¥cÌyÕ£h5=k¿3ß{@€š§&Õu&â:¡œF¢}g‰œJ'…†î +ZoÁ*>-]Ë|µŽvm‹Å"Ðãós.@O×Tƒ„#7júòxÿí´U·‚¸Ê‡;9H9-‹Kº¸*VÌç·ÅªžRóãéÇ®x¾I­è:`ÌDWnkú|ÿ) –kˆ[ñ¾Ò¶vÞÄm‹–öèPº$ìc™µ“ޝWНì·ôQ²\W+JA{¬ñT{—º^ú µ¥Íö½ ºç²ðEÊT•‘©‰0žƒØÒí°ï¯õÞvåâ—‡NƆÉôž¨ œ ò-»ÅˆY s·½œ<ÎûÔEàR¥Côî Õ»Ü/VÅòÿ¸µ¹=NЏ­fÅÛìRN÷ŒGñ„Æ¢!¥K6G‚öο„ØãdW3ÿ¦=À3h#ٟÐ2nÅ‘Ò ³tÌãüÆY™w[Çõwö)¸I¦QLé $UÞµ\ò$fõHah#†V+ãL€ñˆã(3û-²ˆ7ÖJòfì²é›‰{GÏ¢Ý" ¾•[ù +Ž¸\²ðà>‘Á5; ܆Ñ:ïv&#…›ûH³Zê8;ªd3m¢1ñNœÍêµ<£}Ý ­¯ý.w#7Gîþ\OºôñbŽëò²ÄuBՇôÍa¨ +ñ½¼*sN¾¦tY”Ý:+› l㨃—‡zóQ‚1šãó†dføPzLÈÿdÝvç¿Oº!èôVð‚ñö®óF@Wz0Ò»àªHŸŸn‰3#ÐV@ürû¬J¯ƒ†E‹üäбQ×|ªÀÕ¨×}^zRW¹¬Æ+ÈSê'¿oœÃ—‰ÀñrGc¼V)«ÌŜ…d6˜ÔNx0DFà“ÍNԚŸú´éœ1<‡HP«áFÿR0¾Aäåü +ÁûžÈ—C|ÏWeÁ§4Îà7‡ñóõÃÍ5=y÷]ËHŸœL-Ž›Ì +ï>íWMûegï˜bY.Q˜7=[– ¿'ÿ1y’Tendstream +endobj +594 0 obj 1010 endobj -527 0 obj<>>>/Annots 191 0 R>>endobj -528 0 obj<>stream -x•XÁnÛF½û+91€MK²"Ù½9†Ý(’4v›|Y‘+sr—]’Võ÷}3Ë¥(ÚAQ0D‘œ™7óæͬþ>™Ó sZ/èbEYuòññäüîŠ3zÜâÎj}I9ÍÒÙ ßdÉM¡êV{ºLé÷O÷Òí+Ó4ÆYúhچ”ÍéÛ½ÍÝ®¡Oïÿ:™ÑÙb Éu–馡g[ïJúÕ4mð»9ž`wgótÁ_¦ó”þ0zgì³Í -eŸùBÜփۆº†¿n ‡DÎ:oÚ}ïz¾J@’UºçÞߒæóÞßbÍw?é+6TµQ´Hg钼.µj4™Fn©)a™¶ÎÓ70²Ï¬4Ú{ë‹æG'«Zó¢‡pð¡m§Dœó‹€3ÄE÷¿N/@,p+—›í^Üv6׾ܿ…= ^!ZÆáZö¯ZüCÐ1`|̔×Û®$ëpÏQæªÚ;TN“øˆY#·•kIrᚖB>`ÁwÖr Ξr„1¿=Ž¦5eIn£÷p‹O\Ž­)5* ¥æL"<ÕÛ%•WƂ ^µÈj¦,'J`Ý>ž0ë„z4çO_>Y¬g隖W—¨jE‹«u:ï¯Jz`îÎpy%%?pöÞöÞBU™¢jãP2×[Օ-½¨²Ó>ÕÊ«J3Ñ'B»ªèbq‘~9_ãîêj2†uŒÄ?ÓùÝ¢gaÄ4 ›,ò”•Ôtuí|+ ÌHjÄL$sB…jh£µ%éÓ%æ×ÎïÐâÂø³àl ßV•ì€Ço%­ï¦OR¾Vʚº+Áu¸s¨v#]Óy‹8po³™—–ë¨ÕòrÎ¸åÐp´ -%a¹dA8Tó2]¤ô‹Û1¥]„fہ\MÒƒc1’Ž¿Cj@cnß%‡&0¼Ôg¸Ì¾Óδ…pěç¢XÇí½éږÁ…0ÇÁÜÜxÂ{֑Èn¼`[=m•Ü³0”ÐÐ ¯þþé|k‹”¾(“²Ò¶£ÚÕÍYWŸrpˆ†=ò½hÕ4ùâ’Þ=Ѷ„ IG´Q;D]q‰Q<¢=²dl<‹uµ‡×™Ü4×cÝ>e«H‹]a²‚Ÿ7 ?fW͊™€–E¨ÇoÊ­|Ú!ªOµà@c¡ÂxUŠ}\—Äí'©±Ù¡ó‘›~‘Á®VÑOÇõ`ýÂôîáöë·_Ÿž„JOɯ¬Nlçéý$öÑKi ª`3ñ$šâeÆ0uûñþóƒX48è%Êù¢}”›ÁÇócª`j.ۚ|¤ñ[£VRȕ•ÍmùêøÌM“yS‡•¶åA&_±£ògÆØg0Œ ðx‹á—÷[õ$¦ŸooŒ­a)êë¶zÕ4;çsÊÔ›÷Óû#•Ië¦tÂiÌý„F@:ž‡:„æ - p$îxß;ìfÉëlÜÅ0‹u•»1Ä׬äí½*Ž÷C“ºJ/¨Tèׁí¨¨ïnÁ™½³zBÒd -{%„­$ê»¦ÏowxTÆ ëR#iH  ‹¥”[G\¨ 2!¨ðš×7ºÜÒS"›KŠ  / ˜Ñ V]*¬)qz° ðé¤T8µú FøÅ€¥ŽFz9ˆ?\K¯ÅŸ&ÂFvÀQö„™L-ÎŽÇ +„êdk‘–…ÏáÀÉFÐÆ)„“N?_1u1Ty ›0v@&ôé´zQ¦TÞyrô‡ú wNvý1Ï{J×8ÆñÊ -°µçºl|▁ŠÍ²ªÃ9OÍýïÃ$´X<ÛÏ¢ÐÑ}z1ˇôöÛr`` -·_™ƒ°IÙ8™˜˜BËó»Ë~ -]ñ‰õæýž@?ú a¹æ©†_(òä⊡áÈöÛÉ¿ŒJ#þendstream -endobj -529 0 obj -1802 -endobj -530 0 obj<>>>>>endobj -531 0 obj<>stream -x•XÁnÛ8½ç+ºD\Åv\'ÝË"I“EmÚm¼ír¡%*f#‰Z’Žã~ý¾!%[’Û‹…Òä̛7oóïфÆø7¡³)Î)-.G'73šLh‘ce~~F‹ŒÆÉx<¦E/VÒHR–DEw JWzSQªËRT¹•p´QEAmžðÉ­è^”KA؞‘( -½!Ak+MX¼ÈJU)ëŒpÚPmÔ3¾,å«Å·£1½žœ&SܧºªdêdFä4gN“q2#œõŒã„%£µãõt%ªG‰`$!8iìJÕ¤s¢\Ғ®h©˜ B§¢@7÷aik,I›ÁíF–ÚI*õºâü~ìj¢È´Lh±& ˳P…X’#ª…q|3‡Â‡žÜÌ`ã{™jÙü¶…;fH­L×F¹-aݳ¥ ~rQoý‰R”[º( -e‘§È7tR”£N8¹Ñ¥_.…ªš=¹«É*'>øzq„*ÓütžÌiv~†Ï@˜Pí<â-Mf )ÆÓä¼G‹ód–Ð%7ªzô`2@™2¨šF -µ4¥²VéÊڌQä)Œy…è”Éh¹vÙË=loZØ¢Oû“¢þQqó̈́® -•>q 8gZZüdi]£è™…~^°ºZ0;˜|áâNàžÂÒßw·ÿfµµebõN„hèǙdÊօ؂=ÀžÏȵ)鷐@›c1£FtýùËõç‡ß*ñ{l*QʇWƒ¬;_úê[3œ9m  ‘jÀ½“îòöã½?y@ŸÐV£† »ã8žŸæCåw'y B³¯4«ÓÒèÌP`Æ<…< "ïeý“;kjTíЂᚫLVNå[þÌH7Vú³òkÜÊ0ˆéë+€‘+Ydme} -µ°‚–Q&œX -‹*øŽé`š ôhLåH¤Ùu]kã~•^»Â -ÙËoœ‹ÂzJî%9æ¬yÚ±ÄÑ¥%Pð‚ íáÜ¡&û‚uhÖêjt éÜêJHï¸ÞíÜpI÷œݬ!÷WºrFÑ–‚è¶PÀ¶×™ÊsèXå|mL#Ò>€V?”´#²šnqU&¹äˆ‚Ü”Qè\2(ª€€íÛ/Wƺ®Ü¾=EËýZîNß¼…$v§ ËÝ$¡¾º£Hýº2=vÚf(.À¡]Sœ<½®O@,Ð Ü­yf€š>±T#m­ªŒy)²hDÉä ¦>þ"ñp$&(E]C|–ÛFøUåç¨[)I²þ̖‹«÷&3£{lŽGt¼Á×ñË1-•³íaþ làÝD®Cä|h§6<' ywÖºú³=…^ú!M®€ð¨Ü2¹_‚x„~g×ÁÖÙsV–~(÷®nö@–C|th½gvqtÔ¬wVpèÄà”ú‘ǝÆlgaL -FÇcýﻲ¿¿« þ›Ì \ˆ¡ï¥&§nڐµA¹z‘wP`¤vTõ1ù¼‡ ~Át¨¶aëþ,˜%ÓÕ±cº@nٗÁ%"?¦ 5LaÃl£•mQãÀöƒBŒ‚Ï;.”p°5Ê¡Qƒ¼´W¬Á5Ì„¸¶k?,…}Vv§€µ‘¹z Å{x:äAÑ=Ê»Ai*­=ˆ´ñÀ£(ÏÍ!ėkxjv*+nbLMf×½à«t/FﲙïLfá=¨Jׅh˜í硯%;ÏóhÊ3Šð;ÝÂVš †ucà£þ…/ñT@Ž¤ÔÐt…<–ÿט4…@‰ñº[ôKÔi¥h!ž$}lûh,QÂAÜà%ÑC¼Y)Ш¢”¢ò. ò”|xå#2’§.:‘9Øäæ'Àn|·ÚÀv%ž[#2õƒŽ£ÑA ™ûÞÿaÌmpžHÈÀ§zm,—FO Gl-´~BÑñƒ ïÒè5 ¢âµn‘ú Yf¤ÃkÃ?iÕ lcj¬09€4‡ÀÏ1®Ï#t— †Ý89e§ÿë8‡‡ØþÈpšÐ»Ãÿ´÷å¥VÕvS°Ý‹iÎƵöb‹JXYä£0kÛïv¾ýÃîFŒÖ -[dÔôr°™}žtÉýùëeÀ+ë¶Eû†üiNˆ+…à'hgŽÉ‘²yâ -Ûo6E^Øñz{4À¢‹Rí<DC,Ñ©aàãÂ=M~ížA'7çQÌϒ þVÀ^ -ϗû‹—ôÉèoGôN§k6›Êë°ýõÙRÈâÿ÷vœÍðöô_œù4¼[ÿ:ú¶±7endstream -endobj -532 0 obj +595 0 obj<>>>/Annots 200 0 R>>endobj +596 0 obj<>stream +x•XÁnÛH½û+ +91€MK²"É{s {ÖÀ ÉƞÉ|i‘-³7d7§IZ£¿ßWÕlŠ¢, Q$«êU½zU­¿Îæ4ÃßœÖ ºZQV}~:»¼¿¦ÅŒžv¸³Zoè)§Y:›á›,¹-TÝjO›”þøòðoú¦}ešÆ8KŸMې²9ýx°¹Û7ôåéãÓÎft±XÂFr“eºièÖÙÖ»’~7MÛðìnŽ'ØÝÅÕ<]ðÛtžÒŸFï}£Y¡ì _ˆÛzpÛP×ð×m¡á¨ÑYçM{è]ÏW)Hr£J÷Òû[Ò|Þû[¬ùî½'cÅÆ£ª¶Šé,]’×¥V&ÓÈ-µ5%,ÓÎyúaFö™•F[`obÑü¨ñdUk^õ>´-─s~p†¸hëþæ×éˆnår³;ˆÛÎæڗ‡÷°§1Á+DË8\ËþU‹:Œ™òzוdî9Ê\U{‡Êi1kävr-I.\ÓRÈ,øÎZŽÁÙsŽ0æ·ÇÑ´¦,Émõnñ‰Ë±3¥¦c¥`¡ÔœI„§z»¤òÊX0Á«Y͔åD ¬»§3fPæüéûog‹õ,]ÓòzƒªV´¸^§óþª¤Gæî —×Rò#glï-T•)ª¶Åá s½S]ÙÒ«*;áS­¼ª4q"”±«Š®W駑ãñ5î®®‡ cX§Hü ]Þ/zFLÓ°É"OYIMW×η’ðÁŒ¤FÌD2'T¨†¶Z[’^Ñ9íPb~íò-.Œ¿ÎúíTÙèðÈÑøqúVÒúnúÔ95àk¥¬©»\‡€;Çj7Ò5·ˆ÷¶‡˜éQqi¹þ„Z-7ëtÆ-‡†£]T ( Ë% ±š›t‘Ò?ݞi,í"4;Øäj +þ‹‘tü=Rsû.á8´00á¥¾Àeö“ö¦-„#Þ¼-À:nïm׶ ~,´€9ææÆë >°ŽDvãÛêi«äž…¡„€^xõ/·à[[¤ô£@ñ˜”•¶Õ®n.ºúœƒC4ì‘ï@«¾ É7ïôÖ艶%MB8¢ˆÚ!êŠK48ˆâ¥è‰%cëY¤¨«å1ë|¥Ê¾‘GËbJ¬Z眏©±rŠüìY +°Š,t­U[hƒ bÍ0F:غšÙä‚.„#E¿¼hšÒ­äE҂ÈÅ:Zûà:B@pÝhnqÿ¡fÍùÔô·ã9åIòæQºérà +þæA֓IÈ_÷Vû¦0õäá·)SÏ_¸‰´`™b"jÐ bkïA¤ +ãU½hºAýÕéÔ£dEñ-RÄâ_è2GåÂh ´G'qœ£j¨ºÖʓ ÃÎð9¼Î 䦹ëö9ÓXEZì “ü¼ù1»rîTÌ´,B=}SnåÓQ}ª íÆ« +Tìãâi+Œ/Af €á4À”„Ü=oRa/vÍX¸T9/›XT$´^lM¥1ÿ‚gËqŠåAƒƒ^¢œ¯ÚG¹Ìq<¿0&¡ +֨沭É×H¿5jå!…\YÙܦ‘Ÿ þ…ÏÜ4™7uXi[ždrð;*fŒ}Ãȏw~y¿UObúíîÉØ–¢¾Na«WM³w>§\Aͱy?>>>>>endobj +599 0 obj<>stream +x•XÁrÛ6½û+vx13£Ð’¬Èv/Û±;î$N«I¾@$h¡& €,«_ß·)‘T’™Nf2²»oß¾}ð?Gã߄Φt:§´<ºZÜÎh2¡EŽ•ùù-2'ãñ˜i¼XI#IYÝ/(]éME©.KQeäVÂÑFm´yÆ'·¢Q.a{F¢(ô†­­4añ2+U¥¬3ÂiCµQ/ø²x’oéíä4™âö8ÕU%S'3"§q@8sšŒ“á¬',­¯§+Q=I# ÁIcWª&媐–tEKÀ:²¸}K[ëdIÚ n7²ÔNR©×‡à÷cWE† eB‹0aX^„*IJQ-Œã›9>ôävÞ?È´PËæ·-Ü1Cjeº6Êm ëF˜-m𓓈z;ìw”¢ÜÒeQ(‹¬8E¾) ³¢uÂɍ.ýr)TÕìÉ]MV9™ðÁ7‹#T™æ§ódN³ó3|„jç4™5¤O“ó-ΓYB_•Ü¨êɃÉeÊ j)ÔҔÊZ¥+ph3F‘§L0æ¢S&£åÚ9d,÷°½ka‹>ïOŠúGÅÍ7º.Tú́àœiiið“¥u¢gJú xÅèjÁ`ì`Fð…ˆ;{ +sHÞßý˜Õ֖‰ÕK8!¢¡g’)[b ö{>#צ¤_BmrŒÅŒÑÃ͗¯7_}«<Æ4²©D)ß ²î|é›oÍpæ´,4Dª÷^º«»Oþä}B[‚îŽãx~p˜•cÜä +;Òü­NK£3C;ðò0ˆ¼—õQµC T„k®2Y9•où3#Ý XpèÏȯqW(à ¦ßn®F®d‘µ•õ)ÔÂZZF™pb),ªà;¦ƒý]hr4<pУA2•#‘d×u­ûN6Vzí ++d/¿q. +ë)¹—䘳jHäiÇD—–@Á 2´‡s‡šì Ö¡Y««Ñ ¤s«+9 U¼ãz·sÃ%Ý;p~t»†Ü_ëÊ]DCX¢ÛBÛ^Cd*Ï¡c•óµ1HûZýPҎÈjº;ÆU™ä’# +Np#PPF¡sÉ ¨¶o¿\ëºrwzqŠ–û¹Ü¾»€$v§ ËÝ$¡[¾º£Hýº2=vÚf(.À¡]Sœ<½®O@,Ð Ü­yf€š>±T#m­ªŒy)²hDÉä+¦>þ$ñp$&(E]C|–ÛFøUåç¨[)I²þ̖Ëë&3£{lŽGt¼Á×ñë1-•³íaþ làÝD®Cä|h§6<' ywÖºú³=O…^ú!M®€ðw¨Ü2¹_‚x„~g×ÁÖÙsV–~(÷®nö@–C|th½gvqtÔ¬wVpèÄà”ú‘ǝÆlgaL +FÇcýݯ»²¿¿« þ›Ì \ˆ¡ï¥&§nڐµA¹z‘wP`¤vTõ1ù¼‡ ~Ét¨¶aëþ,˜%ÓÕ±cº@nٗÁ%"?¦ 5LaÃl£•mQãÀöƒBŒ‚Ï;.”p°5Ê¡Qƒ¼´W¬Á5Ì„¸¶k?,…}Vv§€µ‘¹z Å{x:äAÑÊ»A—i*­=ˆ´ñÀ£(ÏÍ!ÄWkxjv*+nbLMf×½à«t/FﲙïLfá=¨Jׅh˜í硯%;ÏóhÊ3Šð+ÝÁVš †ucà£þ…/ñT@Ž¤ÔÐt…<–ÿט4…@‰ñº_ôKÔi¥h!ž%}jûh,QÂAÜà%Ñc¼Y)Ш¢”¢ò. ò”||ã#2’§.:‘9Øäæ'Àn|·ÚÀv%^Z#2õƒŽ£OÑA ™ûÞÿaÌmpžHÈÀ§zm,—FO Gl-´~FÑñƒ ¥Ñ#jDÅkÝ"'ôQ³ÌH‡×†Ò0ªØÆÕXariŸc\Ÿ'è/A »prÊNÿçp2±ý3à4¡÷;‡ÿyïËJ­ªí¦`»Ӝy¸Ýã‹lx}p ´ÙvÆ ˆ ðëÔ&H³Ÿæ¼ÌèvV ž{€ ãÃÔñ›ƒ}jíÅ•°²ÈG0`Ö¶ÿÞ7ì|;û‡Ý­¶È¨éå`3û<é’ûË·ʀWÖm‹ö ùÜW +ÀOÐÎ'’¯"eóÄZ¶ßlŠ¼,°ãõöh€E)¤0Úy*ˆ†X¢SÃÀDž{šüÚ <ƒNnÏ£:™Ÿ%ü­€½ž/—¯.é³ÑcÑ{®Ù`nr(oÃö·gSüI!‹ÿßÛqv6ÃÛÓqvÁ§áÝúÇÑ· 7endstream +endobj +600 0 obj 1789 endobj -533 0 obj<>>>>>endobj -534 0 obj<>stream -x•WÁrÛ6½û+vtRfÙRIéÍ©›i&MÜ6ê´_ ”“¦õ÷}»€$ -r:ÓñØֈÀâí¾·ËïSºÆϔ3z3§¬ºx¿º¸úpCÓ)­ -<™/´Êézr}}M«l¼Újò:³uŽ-قrãtÖZ·£F»Êxolíi«<ՖœV%UZÕ¦Þ™šZìÿëËÇN÷֕9)ÄtºqÚëºõ¯Vß.®éõôÍdcÞÇ_]}x±idê­v¦Õù(<ÚßDo·ªEð¦Ô”vPoÚ-ðñƒzÛJ <‰ fóÉ ƒøªªµ"¿«Æ¯=§ãõ~9¢KPXG_V´ÞÒj;'5@YTÍ_ßþüÛKÅHÒ®l®±Œ Z÷!…C Y.,òð[å4…ÀŠ6OZrøeui>{ƒDn– |žák‹@ø;š"C&üíòÝd~BùròvBŸmnŠ³(UDj/ò~Êø›±|ÆÉnfúÅí„P!oªTñÇl«ê ËȍoJµKêU•UÚMR¿µ}¾aQVšìq(À<(éþÓ)î1­»¶µõ„~µ½~ÒGµ¸ºTšÊ´ª™Gj:¯øÑ9ai…=/µE8\•Þ&ÀLÝj§²EÄ(úµQ.¼åD•ò¬Ÿš†AïÝÝE•ÚÖ9B)Œƒað©À’ܪG]C±¼ ËlW·©Ê?¥QNU(cßÍö}WCŒYI¾këÚ´r¬B‡'0±’q<æh/c>¨–ÞDºjdogéÐÚ§¦Ò›²¤B™2ɉ{™Û*œx ut›eÚ{ºÓµGÄÇG“¨ðPmB‡°Tc—¯ ´Â80p(ÏÂÉZt9·;êËJ<;)?÷  !p ÐM\Ä{¬Ϧš‰î|›6ìÙ {Án$«C÷Eì&ÅÂø®rãl5tÐb¦bí ‘Qnr¥ŸQêV§úðjB+övï˜ùÎvˆS“­Ë]‚ª‚Å7] k•ú€<—¯6ÎvÍU0ù£¢½Ôh‚ swsZ6žŒöè€zCsÐþ÷VO½.Súaà>Ì=ÇìÀ/âäÞ9Å õ‚òÕ`¡¯Ø‡ÆC#0a—$é\H”^ábóRñ'dS8[ ˆ=ËÌ£UÁþìV¼¹¦žÿp.)»÷ŸR¦¢Y1¾<=—4JH¬¨iJȟÍt„yg„:ÉRor=!4?XNÈDôdp1¤AR“: þ1ˆüáXZ91t€üÏÒ:˪(Õö‰ËYû §ó•Z[\oA¤0»Òöž±‹õå§WñZeòý ·—­3(†7nŽ;‡yÎ*©’s£*2[5¶F’©Šn}˜p¢Aú FÎ{äF—4êGÒ£ç­M‹Ç7ä`&€=d±A懃|Þw /‘Fwº„a#šøŽA?x|—ñÀƒxÂv¤—”ÙÔÖá‰h ‰L !9Î:ÚáúK3ü›CÁ¦[¶Ç¡°Y nvÎ9‹¼œ3®†Õý”¸xPUnhÞ‚ª1B%äºP]‰{(‚–ÛW>>>>>endobj +602 0 obj<>stream +x•WÁrÛ6½û+vtRfÙRlIéÍ©›i&MÜ6ê´_ ”¦õ÷}»€$ +r:ÓñØֈÀâí¾·ËïSºÆϔ3z3§¬ºx·º¸zCÓ)­ +<™/´Êézr}}M«l¼Újò:³uŽ-قrãtÖZ·£F»Êxolíi«<ՖœV%UZÕ¦Þ™šZìÿëó‡N÷֕9)ÄtºqÚëºõ¯V_/®éõôÍdcÞÇ_]½¿ØÆ42õV;Óê|íaO¢·[Õ"øŽ +SjÊ ;¨7íxÈøA½í%žD³ùä†A|QÕZ‘ßÕ@ã×žÓñz¿Q‡%(¬£Ï+Zïiµ“ ,ªæ¯ï~þí¥b$iW6×XÆ P­ûÂ!„,yø­ršB`E›'-9ü²ºƒ4Ÿ½A"7Ë>Ïð‹µE ü-M‘!~»|;™ŸP¾œÜNè“ÍM±c¥ŠHíEÞOy3–Ï8ÙÍL¿¸*äMՀ*þ˜mU½ácY¹ñM©vI£ªr£J»I귶ϗ",ÊJ“}Û +0JzøxŠ{Lë®mm=¡_m¯Ÿ´»äãQ-®.•¦2­jE摚Îk~tEXZcaÏKmW¥· 0S·Ú©,D1J†¾Em”Ë#¯G9Q¥ü7ÖNŽOMÉ ÷î¾ Jmë ‹¡ÆÁ0øT`InÕ7]C±¼ ËlW·©Ê?¥QNU(cßÍö}WCŒYI¾këÚ´r¬B‡'0±’q<æh/c>¨–ÞDºjdogéÐÚ§¦Ò›²¤B™2ɉ{™Û*œx ut—eÚ{º×µGÄÇG“¨ðPmB‡°Tc—¯ ´Â80p(ÏÂÉZt9·;êËJ<;)?÷  !p ÐM\Ä{¬Ϧš‰î|›6ìÙ {Án$«C÷Eì&ÅÂø®rãl5tÐb¦bí ‘Qnr¥ŸQêV§úøjB+övï˜ùÎvˆS“­Ë]‚ª‚Å7] k•ú€<—¯6ÎvÍU0ù£¢½Ôh‚ swsZ6žŒöè€zCsÐþ÷VO½.Súaà>Ì=ÇìÀ/âäÞ9Å õ‚òÕ`¡¯Ø‡ÇC#0a—$é\H”_ábóRñ'dS8[ ˆ=ËÌ£UÁþìV¼¹¦žÿp.)»S¦¢Y1¾<=—4JH¬¨iJȟÍt„yg„:ÉRor=!4?XNÈDôdp1¤AR“: þ1ˆüáXZ91t€üÏÒ:˪(Õö‰ËYû §ó•Z[\oA¤0»Òöž±‹õå§WñZeßäûn/[gP oÜ*4wóœU S%çFUd¶jl$SÝù0áDƒôAœ÷ȍ.iԏ¤ÿFÏ#Z› nÈÁL{.ÈbƒÌ'ø¼ï2^:#îu ÃF4ñ=ƒ~ðø.ãñ„íH .)³©­ÃÑ(™@Brœu´Ãõ—fø7‡‚M·lC5`³Üìœsy9g:\ « ú;(qñ ªÜнUc„J(Èu¡º÷P-·® x^.S ¯>L¢l™‘8"ÛqÏ^δ÷ +FŪ¾ÜÕÙV³Z€=éŸãG–ިÔPý {çš3YKtxÛŸ^88ŸÆȧÞO*éñ筟ºð[–{Ð2÷ÆIÝÅ¢›34Ô"EQ;Šö·5›m‰_¹FŽ;yD‘~PBn¯³ª„»òÎíD)\™cH¤ÂWNhP~äá¶8#h…á&öÐ׸e·¦9;óÈ>ßO–0œ³ºŸæ¡:âŒ=]ÎðÆòß3öôf)/Çתåd…gB±0™Ãë‹LƒD‡Mœà8WæîÏ<ÈÝ'#ÒqθåØÐ;Da;^ûA8X€Eýaà¶ÄJtÌ`^>>>/Annots 204 0 R>>endobj -537 0 obj<>stream +604 0 obj<>>>/Annots 213 0 R>>endobj +605 0 obj<>stream x¥XMÛ6½ï¯ä²°«•ü½zHФŠ4mãc.\™^3+‰Ž$¯×ùõ}3¤$Jv¢E€$’Èá|¼yóèoW Åø“ÐbL“9¥ùÕÛÕÕÝû1% ­6ø2_.hµ¦8Šã˜VéhcËTÓڔ:­my¤J§ûÒÔGÊíZ¿^}Åæi»ùv<¦Ø>úT`“¢}¥KJ3“>UäÖÎüÚÑ«O¿½êoQmIívّê­&Úé27UelQÑg•?(ÊÕ®’oæY½¦àÍl0¦ÛdÙ >þî±´ûÝÝÁ–Ùš¨¼;ܽP]š]¦J}CªX³É‚&Ë(ÝêôIŽH·ªxÔëÞ!È‚¢Áfõ¨LQÕ²öÁÔ[#S°ïVWœ>É!%ü¿¿~½Jæði>aÏrZŽÛ‡Œ>s øÉT¼îRÏYðö‚ 9%ñ2š{[Íöþyå#u5õ'­•TՓd®5"¦¶#Ú©RåºÖeDoŠ#IÌõVÕD]jdÎåK^)¼(l-9A]®“k¤©2Ug†xQ¦75}+N¶…S™-€Ù£]¾4Dâ,µ`{WUº¨Ê²ã }×¥uÎùݼ¸KƨÃï«žð¢Ó‰V5 *Ԝ‹k7MÐÚÑ8ãóԈٽéÒ¯ìfjë½nÀéæÈÑJB9'õÖVüwwJgç9jp1^Σ{šÍ¦Q XM¯Ä?5ÀÀã¬×Ð6miô˽ijé¸^mðÀ!£vìG…ÂÓ³Êö€}EòŠƒÎÃqþ|~r~‹)i„0çûþ¥’wW IYká"*Ù×]iŸc¥[g¼ETjóªÍƒÉ˜»¦ÞzNG1(‹[±ChË;>Û´Q©ß‡ðÁ4¥]ïS½ŽhÎáú6TwRd¤ÙyQ[Ð!¨&[À sˍË}¿[8¾x±Xø9ó³j>‹!”©ü랺ÊÇL3!™ÿ®_j·0cÓ¦uCgÕõ˜N"¨.ÄAx~NSÁcߛ¶Š§8@(dè+¹ÉÓô«0@ÓåRà.ÃÆ=´1O—÷½ˆ›)ÕòE܆ð@n§Ü–Ú²ÔÕÎòÜðLã[å<Í ÏI,gH<ƒÍ í\Æ>ëgI¦²g¥ŽƒZêþܦ0Ñ 2ȂQê€lŠGøë@€×–¬¶Ì–ÙA[þ@„׶¸n`ëÚrŠ ¶dÂB g䞺Æ÷øÂöÿQsV0JÃ3áÁâ>š„Ïr<‹ÁWÔ€Ü7ôßՈfó©³t’@cHhžë¨Ol§ÌÖ›”ÌymHlÂÝ®îÿ#±9ÿ Kh!¨°´u'ýÓ§;f»86ÆÊ+¢ÿ-yv³Ÿá¶´ã¤Í`‡k…6W[{\• 4öÏ9û—í «rU­ƒPÎd¦K-=Q¢ÚgDK~L;}ñÄo)iÏ$CĨ[Ûæ4”Ïîâ2´6Hpçÿ™ [ ê/û?ðìT  9tàbƒªTv¢ÑZ&xÓɖ^£C_°ùM;~ðwÌ+¯Št!îѕ»õ(ȵun "S¸SŠ7Ìd2]gW[ðÏS“UC‚¨j¾pŠ|ä¾å»*kë–Z)"8'r­2 \óòh÷¾ ÏNíw|‹awÀØ-çVþÔ͞¯¾–…m&·.ÇîžNN¼@€pΔ"VÁNÅzP‘ÑFËW—ÕUq]{I§p}DçÔ&Ýgªô—*H)ÑB¢nø—MNÃƲÈfw:ü³oÈÎ]¸)™$¸焑º—‡FTœÚøÄÿä‘LÆØ -Ž*ˆÍ—ÑìËké°ËÃZh¸)ŒËrµÓ©Ù˜”Yœ~â$u}‚QÑÀ°c+¾~þ,2€Ôs´†…ƒUMÞÃ_i~`òÜæ^oüîýÒ§)™/p·›ßO¨Ñç7ß¾¡?JûÁÑ/6Ý縁˴b—p›çÅ·‹1~BZ–Ñ,¢râJ²Ð/ÝÑÌ+Þ>]L!eëtÌ/Pß?¯þJhœwendstream +Ž*ˆÍ—ÑìËké°ËÃZh¸)ŒËrµÓ©Ù˜”Yœ~â$u}‚QÑÀ°c+¾~þ,2€Ôs´†…ƒUMÞÃ_i~`òÜæ^oüîýÒ§)™/p·›ßO¨Ñç7ß¾¡?JûÁÑ/6Ý縁˴b—p›çÅ·‹1~BZ–Ñ,¢râJ²Ð/ÝÑÌ+Þ>]L!eë,á¨ïŸWJiœwendstream endobj -538 0 obj +606 0 obj 1656 endobj -539 0 obj<>>>>>endobj -540 0 obj<>stream +607 0 obj<>>>>>endobj +608 0 obj<>stream x­•MSÛ0†ïù;œÂ qãHÚôc¦Óii3큋"+X`K©$“É¿ï»ò®n.1’vß}ö]é÷$¥9þRZ-èü’d5¹Î&o>-)M)Ûbår½¢,§y2ŸÏ)“Ó+O¹òÒéÊÏHºÕFÐ"™'K …¢p¢RA9OïN³G[ôÁf‹KìÊò©tJE•ðO¼gNýÊÖ:©¨[·¹­çÚ)¬;¼~x°¥=?,¨Ï´WNQíUŽ*|P"'»Wk/kÏ{ ìNXËÇlt±\& Z®Wøâ ±¶ »·”¢Ffw‘2”!½u²Jè³!ƒ¶†ö:1©ÂäÂå-Ï­.‰À¹(»ÛióÐ}éÎlÁݙ6=ÀOÞVª+äÃÍí ÆFO÷S_˂„§´ '²¦<œÜŸ‚A°QÈÝ·Ï¿h§\¥½‡BÏÁ±ž„²Bû¶é9ÊGêJ ìAã@ -C´n’ÖlK-¾Â^)ÓpíƒRÔâU g-šò•¬¢\‹Ò>h;4ÊÎ!6‡¸qD¬–P{¢sލQ´|Dû(ØvOõŽð©»J© c)²ˆœ„”Ê{"Ø3f³{£é€–%u1z¬‘*˜Žäò|ôŽL_úˆbƒ¡j$tg,ÔƒR¶z[6Ex ¨ð!3Vn–Zž#1yh…±Ü2NM=ÀŸ«§Ãíe41øpMí²æA5نv!øH”% boåUùŒMC†µ‡‘yq¤Íwhª<# =ùØÀ7Ÿ.ÚKdJ'7_NøèËPO9ç[AÈ'þÍ*{ÎýEÁÎ:‡™WòKƒe#á^d…ÿ¿e­' ‡uD_u"™ÉŒ‚¡„qžöÌ?ž÷!Ú ¾EóþE×(¸?m&”º™D ±Å]C“ÀÐÿškž°ˆ˜W =äcÅah;4ÊÎ!6‡¸qD¬–P{¢sލQ´|Dû(ØvOõŽð©»J© c)²ˆœ„”Ê{"Ø3f³{£é€–%u1z¬‘*˜Žäò|ôŽL_úˆbƒ¡j$tg,ÔƒR¶z[6Ex ¨ð!3Vn–Zž#1yh…±Ü2NM=ÀŸ«§Ãíe41øpMí²æA5نv!øH”% boåUùŒMC†µ‡‘yq¤Íwhª<# =ùØÀ7Ÿ.ÚKdJ'7_NøèËPO9ç[AÈ'þÍ*{ÎýEÁÎ:‡™WòKƒe#á^d…ÿ¿e­' ‡uD_u"™ÉŒ‚¡„qžöÌ?ž÷!Ú ¾EóþE×(¸?m&”º™D ±Å]C“ÀÐÿškž°ˆ˜W =äcÅa>>>/Annots 213 0 R>>endobj -543 0 obj<>stream -x¥W]oâF}ϯ¸â%‰6'•VU%]Ô|íB»­ÄËØÀ{†‡å¥¿½çŽmHP»«¶‰DbÏםsÏ=çòõh@}ühÑðœÒòèjvt3;êã1í?̘ ‚ˆâñÿÇq“‘´àÄ6»Lo/(êÓlÝÏGcše~oғë•X;iè" ÇiD×E.•£Ÿg§³/G¼t×K{C>q–\ƒ€n/?ZžÑ§Þ;ÕoñþƒÞP*M(Õj‘/+Äõ8 #ú,̚®µR2u¤ ½z“°$(õ‡7›ÎŽôd©SQ&â'ðp´÷ð%?ý|!":E€¢¤x4Æßú© )CÞÆ4Ô·8 ßpI¥Fˆ©.ׅt’„²àá4¹Unék%­ËµòwJ$ÑBW*#¼ðqî`ö±ëZ9·~†©0º6¹²Aõ"U„RV›Ðòe ÐV®,ÞnãóÆÛ Ñ9R ®„ÍSQÛ.muEJÊ YG®²fßñ0§×.š­$Ýæ_*£'“#³M‚ç'Ǔ«{z’ÒÏOý]ÂÛ´©7ô>§óè|Ô ¶òXo0¬™0»~ -'OÄ»)°HIG¶Z¯µqÿkW„Ýyîjò8%ý‚lÔçt(39?â<¼¹ºùuò/éEc¾Ãg¢¬¦¹ZK”On¬#·AêõR⍡MîV~,V’^K#O'»µN–ÌAI!Ôsûœ‘ßօÈ2”+¿˜©ßä³E®ªE@“E]´â(Œٖ)ÖúàdÖ¥¤ruÖQ[,‚Í°ßt@Ôæ™#kðïR…€q‡ƒs;SY #5·£ ífƒ‘N¾p6Áw¦õU§ÒUëf™4‡ô¼Ì²Åïfè(í(“65y„ÚSj<íè„èøÉh§S]Øã€hƚÁ±âb–áW—®UMÇו1¬®m>p¬ªS‚ÙÂùµÝƒ³wé@­ÕR’ªÊDš:ô\¥ r;Z]¢pq„x*c¯a;%®‘jvoE dò{%+ -l~b! -M® -ÇP¡¡? W²Õ"ä5Q¯~V&YFP%J .CrðÂHkñ¤ý!ö0…õq–8d¢óà×ÞåÖuºlv-Ó|­‰>O¦M|,­>_âÃ>fºpþøìO·×0B Ê\éB/·óS¶ãI¬«TŠm#®š2½Q…¸‡¢j ¸×Ê^99첺dð“¿ôýðš…|‘{œ?/æŒûÚ¤LÖ eEðD$ ‹¯®Úê(º`ɪ}ž ®µù×ΝsðÚÖÙ¢£™ñ8r56¦(lNF1:‹úDî,î?ß:wäa κÇó?t °Hä÷:†wïÕì<Ú·7¹Âhé량º‚‘€»­‡p½ÔÉBÍCmÀF8ø, 5ήdQtIf 9é‚;Šù0±6.a´vþnûæ Ë lD›-W¿_铛`&­¡Õ¹ï«ðã,œuÞö邶Üú¬nèà'ê¿·ìIü¶+8´ÉÌÀƒ™ÈÙ{¶Èg8jçnýîì—,kçî9ÞC>>>/Annots 222 0 R>>endobj +611 0 obj<>stream +x¥W]oâF}ϯ¸â%‰6ÈJ«*‰’.j¾v¡ÝVâelà=㝇奿½çŽmHP»«¶‰DbÏםsÏ=çòõh@}ühÑðœ’âèj~t3?ê“ í?Ì +˜ ‚ˆF“1þ‚IK^Al³ûÀôðö‚¢>͗Øý|<¡yêÇñ&9¹^‹ÒIC=Î"ºÎ3©}xü<<9⥃Q½´7äçéÉE0èöò£å}ê ±Sýï?è %Bє­–ÙªB\³0¢Ï”t­•’‰#mèÕÛ K‚x³éà<àHO–˜:E,~âG{¿_òÓÏGÑ"¢³q( +'ø[?å4cHÂÛ õ-ÎÆÃ7\R¡b¢‹2—N’Pv<œ&·Î,}­¤u™VþN±$ZêJ¥„>ÎÌ>`}BkçÊwa˜£ó`“)T/"Pyøg.eµ -_&܍`íŠüí6>o¼MÐÀ#µ€áJØ,y¾íÒVW¤¤L ‘uäZ!kö¯szí¢ùZÒm–ó¥Rz22Û$xqr<½º§')ÍñâÔß%¼Mzc@ïsºˆÎÇÍ`‹ õÚ óë§púD¼›‹”td«²ÔÆý¯]vçAº«éãŒô ²QŸÓ¡Ôdüˆóðæêæ×é¿<¦MøŸ©²˜fj,Q>™±ŽÜ©×+‰7†6™[û±XXIº”F8žNvk,˜‚â\¨çö 8#¿•¹È2”)¿˜©ßä³E®ªy@Óe]´æȍé–b)ÖúàdÚ¥¸ruÖQ[,‚Í°ßt@Ôæ™#kðïR…€q‡ƒs;3™£#5·£ ífƒ‘Ž¿p6ÁwfõUgÒUe³óTšCz^¦i‹âw3t”v”J›˜,Bí)5ž¨_*d!FæÛvT+$éð*©Nª¼GF´ +hæ„qD÷OóYpóûM—å$yæ =þòê¡ jdéîòiÖñGÖSyn‡Ë‚õ귇›¹§ãão7ŸvtBtüd´Ó‰Îíq@4gÍàXq1Ëð+ÈË ×ª¦ãëÊV×68VÕ)ÁláüÚîÁÙ»‹t Öj%IUE,Mz¦¹Î-.P¸8 B<ȱװ×H5»·"2ù½Æ’•¶8±…&WŠc(×ÐÐ+Ùjòš¨K†Ÿ•‰DšÔ@‰B‚ː¼0ÒZ¸… Ï&XP4ŠÈ?5ξïsZîcÂø¥wd|EEï* q kO´!»¿|Ð…ÍéÑx„΢>‘; „ûOç·ÎÝyā³îñü],ù½ŽáãÝ{u;öíM¦0Zøúg¢®a$ànë!\/u²PóP°Î> H³k™ç]’)HÎEºäŽb±L¬…K­¿Û¾9H3ÑfËÕïWúäƘI%´:ó}U£~œ…³îbÂÛ>]pÃ6€[ŸÕ-üDý÷–=)ßv‡6™x09{Ïù G àÜm ßý’¦íÜ=Ç{ˆgèIK *½-·028-z—¹Õ](ˆ:v»:VI^¥¨ò‡›¨Þµigb™†øÿ¸Z­¶́oXOåˆQ ƒþ0¸ I„[¢.F £h«&CÀ¾¿goŸ½>Ì{„àoX¸/”$E ú")«8Ô6 +@ô¡J3ëëc_{-÷O<£ÐžçMùŽ‡üÅQy+`“]SÎÍæ>æ|'¡(›þôlØóñè/?Ñ"endstream +endobj +612 0 obj 1594 endobj -545 0 obj<>>>/Annots 216 0 R>>endobj -546 0 obj<>stream -x­V]oã6|÷¯XäÉ8´åø+A.Erg÷rHsil\PôŠ‚–(›WJTE*®_úÛ;Kɉíàފ †l’³³³³Ký݊¨‡¿ˆÆ}:Qœµn­î윢-R¬Œ&xH¨'z½-âö¹ˆÄ™ ëR‘_+|Ê|K–I;W)G›µÊé˼ۧom^|V¥Ó6ÿöŽ°ƒ*§’Žä»Å÷VN£‘˜ @;6Zåþ'þµ;PÕáOûc^}bÌ­­(±$é~º ¯·Ó'²%ã1:™iÃdz(uî‰>@zTÎVe¬è¦´§Ê“å–æ2[JÂW&Gnm7T‚ƒO-Î5$L?=þ܊†gbL£þHô(ƒN}p®¿š³bÐ)}Õi±F²±Ì‰–ŠRý²^nÁ½>^SZڌ‚‡±Êµií}qÑíƲ´FltîDõ,Enºÿ¥ªM×1ù.0ÅÚgæ%pgA´€,u¸6†yè<6U¢’pڟ‰>««s3Ò£†M±È¦µF‚n=Iã,…$P7ŠmU@jì¨Ë^”viTæ:ä*¤†Ú¥biu¾"cñ£Få2kÌqÝ.¿«ØfJJ¹ZAª —õɖF¢~óµBäm(÷~EP². 'ç(Î`2F©úøhzìéápôÆÓAŸàøë–VÊ#¸‚$¥†&ø}“+ڀ'F)Ì\^;×ýȺ3]:ß¡¸Tò¹5'Kcç÷‹_ÿ@VÒsƒp“œb{"¡+êøÁ[6¯aĚºº±çÞ<`©Ë"ŠéõŸ¡Ž²Êyr¾ñƒS…,A ¥³¡½‚Qrf,ô®·l©W:—þqÄk¬Nè¶Üz8aõfù¿vŒÙôØTs[çUZSÅc¦}Û`Ö÷‹ø)K"5¥©žwˆd’0Ý ‘Ë–"¶yZ­”»ºC'Öõwh™,è=«Ôõ_çÌ®vV­7ìQûä%š…Ùñ>"W¨X§ºnîCÌö:Ä‚¸%¸³ ¿66g©Ž -ڈv¡× ‹1˜lͶ’—˜{[¯è=]î‰b_‰ËD=k4£]uH‰•¸ úô@wü}0¼ÃÉ»ëùôñót!WŽBþ†ùÌo-ŸŒf¼æ9Q“€ódQ@§ lÎ꼩~Lhs³m”Ým‚aö’yu^q/‡NSö‹ô0XáÙ/ÝËûk #UƒñIƾ‚¿·‡˜*¦Û²Îï5=…c> &¾^ṓ¹5ä³Ô¦éã/µsœ‚?GpC¶CWW@åAL¤ _!NgèñM’$<†BÄ×¾ÌGVëP*å)¶YkŒf`¿@åow®ÞS®ž«ÝÙ¤é’h4MιSç׿Ü\㮵<¼é£« ÷·ô¸é÷:o>÷ñ֐üo ´÷ž00êþ`ÈAqüÚúۙ¹Èendstream -endobj -547 0 obj -1109 -endobj -548 0 obj<>>>/Annots 262 0 R>>endobj -549 0 obj<>stream +613 0 obj<>>>/Annots 225 0 R>>endobj +614 0 obj<>stream +x­V]oÛ6}÷¯¸È“ 8ôGü‘i†´uÖYšÅBƒaZ¢,v”¨ŠT<¿ì·ï\JNlg}‚²EÞ{î¹ç\ò{gHü i6¢“)Åyç]Ôé_ŸÑpLQŠ7ÓS<$4ƒÁ€¢¸{&†âDÐU¥Èg +Ÿ²ØåGÒÎÕÊÑ:S}^ôGôµË/ŸTå´-¾¾!¬ Ú©„¤#ù&úÖÐñp*N‘ ­ +ÿÿÚ¿Ópؤ?Íøí#ÇÜؚK’îæ}¹™?’­8¡£kmLB÷•.<Ñû”³u+zWÙµSÕQ +K ™/%á+ƒ#—Ù5Õ¥àäó¨Ãµ†‚iÈO?w†“1£éh*”ƒ§07ß -˜1ð€¾ðe(6–ÑRQªÿFÕË °—ÒÇ¥•Í)0°Ÿ«ZQ—2ïËó~?–•5b­ 'ê') +ÓÿÇ(U¯ûŽÁ÷Sd>7ûQvŽ"ˆ"ÐÒ¤[kc‡.bS'* {Àý‰1»º0#=zØ6‹lÚp$èƓ4ÎR(}£ØÖ%¨ÆŠ¦íee—Få®G®FièmY)¦V+2ØjT!óVÙíò›Š="CLI%W+Pøá¶>Úê¯ÒHôo‘)Aކvï6P&›ÆÑäô ÍŸÎЪþ4=Ôôd2}¥é± PôuC+åQTB’Jƒü¾.Œ• ­ˆ £â *o”ë~$Ýk]9ߣ¸R ô¹Œ ¥1¨ó÷û‡›»èÃ×?P•ôlÎ`’c,O$xEßÛrÃâo󵈘S×xkî,‚‡ì2‰b~õg聣¼vžœoõàT)+ÀBël°WJ¡€Œ‰ÞzËVz¥ i ç¼‰Õ n+¬‡"Ro_¿Ò×1‹Ëknã¼Êƒå0à,3ݛ6£¾‹¶ä§La <Ô¶¦QxÑ#’IÂpE._ŠØi°Z%sVuŽ¬m£å²¤·ÌRÿzô2g¶^ØJµY°DÝ£çl0 £ãuD®T±Nucîý˜ÝDêàĖ`íW~meÎT4´%3¬‚×@‹1˜lçí²-“˜;K/é-]ìr_Š‹D=i˜‹£]öH‰•8'úxO·þLn±óöj1ø4Äþ›ƒ”¿a>óÄË䓂Ќ×<'Pž,KðèƒÌ™WÝOƒma6-³›ÀMÌN1/Ê 4îÔÐk{Ãz‘+=+ãÙ½¼¾ tÀj>ÉØ×Ð÷fCÅt[ֈ…ý;¦§°Í‡ÁħÓKxv2[C>ImZn”ãôy8‚[°=Ò8ºBT4Atˆøâ#Äé¼<>I’„ÇPÈøÒÃçùÈlã=˜JyŠ­3ÑŒØÏ¡ê·[Uï0·7WOFÿ5WO[ §3Á÷\vî ‹«_Þ]áL¶<ä郍ëç¼ô¸0œÿ¼ë¸ÙöÿÝ.hç>1žq$0¬îdÌIqTüÚùbÁàendstream +endobj +615 0 obj +1116 +endobj +616 0 obj<>>>/Annots 232 0 R>>endobj +617 0 obj<>stream +xWQoÛ6~ϯ8ä¥)ÐȖìÄIž¶uK[ h·Æm0 /4EÙ¬%R#)kþ÷ûŽ’lÅéТhmYGÞÝwßwwýç,¥)þ¤´ÈhvM²:ûmy6¹¿¥lJËo®7´ÌišL§øE^¼Þˆ:(Gé4¡·—éW)•÷ô ª• o'I›«—ËogSºÌæ8±Ó‚^yàßøö?ò헳4Éø=®Kzg‚³y#ƒ¶¦3Sšö¦Ù‚ ;7ÚS®vª´µÊI†ðՐ2;í¬1•2!!ú½·qž¯8úzñÚÙ8 ú¢œ‡+mÖô°÷AU__R°}àé¬ í\n”ÜjsŽ³¢ô–¶Æ¶pé‰Î¥­*Îq̨vœ<œÇH_xÚ §mã£÷•×y’ˆx¥HDìð9q+Œ5ûÊ6¦;ÙxŽ2lÒõÁu1 +Aè²!l‹ìê“ðm,ϸn±x”ò·Ooβ›«$¥«y–L©¢yv“,ú§’¸úS<ΞÔ|ÉçV6 +á» ÊæºÐx!Ùâyp¢ÏIŠ©=Ä­ébB}7™xfNbݺû6‘;ŸlBU>K!&ƒƒø¤«Y†òÌoøΩ8EÅÀ݁]óۛ„Ùwd/h–%±=kƒ¥ƒ{ö7¹Ƹ%0¯„Üh£Ž¶ä¸0‚êfUjYîûJêUÙÑ ñÔÖë`ݞ +ëú× WDi¤΃¦NÄ|!‰wµ[±Vþ¡ä²lr&@ ö9¿7¬Ï雐ãªY'„@‚ÀßÐZ„ ]´bïÙÃ^O!‚W^ÉD¤}¬ÐÑ÷Æú0¢Ígó£=~mȺǺï­ZýÒÛ& +£SÅ3¤øüý…¨;|ê èññ‘VζȆ`n–%ِÑ]%­ à/ãq’­6¹Þé¼%“çŽÂJՐ¡Žâǝ¥µ[fug²ÓÜBˆà;V›-»¶ÃuDÿôþˆì¨Ò‡¼¹»¿íCP*Wâ^®üJ…V¡Å ³õí…§Á…»¾N®i–Þâߊ²”;m÷tú,›âåX ŸÑ&9¯ÏŸÞÓÝOëV®õåJVn_Ý'­g¬ÛÙô6¹ùn³ÅÓ ¢j¡ÛàéG$Š`v³‰3kŽ™$ˆŒujŽ»H–º‘Ck½ ˜BU#7hvÐÓÇْ,«†_¡…Ÿð(·Ôê°ù>wƬŒÅ6ÚEÃèC NÁkTõV©š¯©¨©ƒÍ˜Î1>ñ̄ñ|¯ȀS¦Ú©BaÔåT©°±9·‚^ºˆIp·‡YŠ>öè[ã^HáYƒÂØ+*;˲dFéíÅ#äŸÝӁYé-ÿ8fÖÒb„´¦´"Á•H +>üQi^Qm5† vƒÛAk?Ãɶm¹G5eL&¦Ãàxx‘Ä<Ùj{d/¦omËíc­b„/ B³í°-P(]„–áÌ#bNo>|¦7¾çEM¤ß‰¾¾Ä2ðÁ¢„aÓu ÆÜ ûÑÐîû!@k'ꍖ@»tÇK¢h±v}Š+v´ZÊKâ툎bë +TªšÀÔÂE'iùò‰-ñ¨Ç™Áa$F”Ð †à¹V8[Q?³Ÿâ<440!n{¨õšÇOϵ(·~Tœ·1Žµ°Ü­ã` ª}éÒ©EUëî6ï±}0s!«¯`ÉéÎ$m½gŽGòÇQ9æVÒ_®ÈÂÀ_[½f öC‘|\ +;1øf…FšXÇÓâI •É@ýÌ&#ªh‚•úråö6 '¦¼H Ñô6¼á¼œ‚Íë$ït¼aÌ8©c«"ô[áöIìїX’±cîžñxX#>5Ý|èKþÔM•™1¹¿ê÷l>9ÌÎ.sº«»UáÏ¿–¥;nö΢U`ÊéØ '÷7ý-—œ÷lF˜~þ ±Çõd/æ8“ººâÑwþ:ûPnì©endstream +endobj +618 0 obj +1480 +endobj +619 0 obj<>>>>>endobj +620 0 obj<>stream +xTMsÚ0½ó+Þääì؆@Ê©äkré$-žæ’™ŒeìԖˆ$Ãðﻒ€í¡ÃKë·û>֟ƒ )ý2Lr ÇàÝà¶\=Že(*w4¾™ (‘&iš¢àÑk-$ f~lUJi0¬˜1¥KØíJà²ø ”l‡ñµ '{Ü(ñ%)â|œŒ?úÑKØZ€«®c²ô×1 A=Ëhʯ¯wˆtqx“À—˜®ŒÐk¡§ôüÕ°nÁ¥—Ó+zÔJY†?=$>¡¨ƒMÓ¶àZ0+ˆUÙhÁ­Ò[pÖ¶¢ „%-kd#—~f´TmìîÒ¨^sG¤x‹šD$¾èéavïzSÃl˜äŽ–eË%a: Í$¯ß.ø)À{­…´-5VôϬ”, ¬òPÃ$E)Ö¢U«ŽŠ`µ &ü˜ÎÝÏùV(ÒVÃÍ@L$já(PûŽÙS êä{ãb}*WçM)ª@ž(@²ŽÚc†¶!TuÆ2P;Tšý•ê KÛqqÿ‡Ð¥iIVž­w ±€ilhäB¢äY->{ç™H:z'ö䤺­`&¸C3{±¹ê[’A TRœÊQ©¶U'Î.—çA<üÿƒkÌgßngïù{þ¯T…Ò­)£ýªm˜s[¡šôi‚t»ðù¼ñšÉ%ÙÝEÏý/¨´ê(嶯Ÿ‰Ä>Ä~zØÃ}fGç +¸U~IÆ.ÐN~UºÝ¡Œ_BxnöK;̒ ù$ Å^¼hõA+†{Å{ff›àlœ'TOrÿ ¸«Ùʒ Yšàéùµxƌsa ænÕq¼t놁Â&£ä&|C®Çîà¡|üŒÍ€¡endstream +endobj +621 0 obj +642 +endobj +622 0 obj<>>>/Annots 278 0 R>>endobj +623 0 obj<>stream x͜]oDZ†ïõ+æ"Àq€x½³³3»{n}؉KVB:@‹¹”6æî2Ë¥lýû¼U]=ýV5#8"°9œ~ötUWWÌüëIÛLñoÛ,fM74»'ÏΟ|÷ê™M›ó«¦íW“¶óæü²™N¦Süöâ›óõ»ëMs¸jžö§Íþtûûó>ùþü‰ÐRM+?ýõOò›f˜¯ðß]3o'+»¸nÎäï„òÇ÷Íw?ôMÛÊ_†®Ç£¿úüÃúæ´96öÇ·kúYd§ÛÑN²š»f±˜ ¾févPÿùðK–“b×,W“ÞËÓí ?²š»¦Í&3/O÷ƒüåþö´¾¾Î –2ŸMbe½¿ ¤aèc#4Î7·§A¢\¦Ÿt¡©@@œ=}õ쩘±[»ÄÊßLáŸÖ<§Ä+»~²„Wö½´¾^˜W~÷ÃÜ|b@á¥sÃvB^TÄً˜dìH8;mnr &O±º,—âÅL°Û‘0ý߬' lØÎãÃØýøëf]ü€T`tÓÉÜW"c#äôa“«Á*0Ð}5øArÈØ­÷#ƒT`àуa262nÖï7‚fóÇt§â±Þ±ÐŸ‡Ñ±ôÂKÜiÖá&Gµv2+AIÝÉôÉô¬OîTjw2B²=ŒYÕ!¸“éÅf0# Ïî¶×—Ûýûє¤„)çƒÄædt±K‘ Œe'Ö1¬@d<Ûî×Çmò¸àüñLöïÓꐍ^?´ÒÛ¼?tÁLŸlÇúä¡ö#$ã1!1+Â,øƒéÛéR$d8§È@"˜ÄXÉ£VŒ0ÖeÃR\Á1¶blw7‡ãi½§«hÅ©úø@€7CŹEĖÁ£PûG¯Ìœ7õ«aѼ)]oêW3½7ͽ7e½ZÞé՛jBåM™ ¦wcÆ:tޛ²¾MÀðü¸YŸÊPC:˜ãsï)1[HF/ùŸ«IÆFÆíîÝãH…ܧ]U +‡ýÕöýÝq}ÚÆÁõ u ¸¸«Q.iWÛëÍD}sñЃߌó§^rvD½ G\Æ Ö74urV'7 úÚ MŸ<†õFô\ÐÔ-:: Ïrz¹KyI#î׉û1!C=âÓánœ¹°ˆa.ýÀ!ŒêÉoF÷# Ë‘ÌC¬€‡ˆ»ŒIö>Ÿsõ°ñËöô!#XÄ|k`z@sÂâf}܉?a 0{ȐêvX•¤¿× rÚÅ´Jõ‡à¶¦ONÆú䶡v\#$?cBbV„>¸®éۙÆ=$d8;­'ÎÍH ÇÁ$]€9†®@?I%¼‚ =#¨ˆŸeÞA2ñà&?’ @@ -1250,158 +1487,157 @@ qvq B<¥&ólÿhÕ5–œ,µ¸^§ñ¥1c‰¶$ÍÈ»!Ÿ5¤ÕŝIfȪ>•)3É:r ‡HîQ!ö‡ý·›”ËlJNDz˜UOxzšˆÏvcÉUZ&•­ú³k;åÞ([úcz‘.Š!g8ñ“Š²Î£Ñ3ë’ˆ:½ÝŽ„óò¶ià8&0x‚ݏ‹Ôæ*­NR€°ÿ;ó ÌŽ$9ß+QñA÷ËÈöٟ‚U4_°1o¦d,õÄT¦¬x¤f7}jAÖ§Û¡²Š¬å˜˜ásVÉ …,[»G1vEz~ØáE7=pŠô5 Óº·HfØ~tAÆâ;èO>Éz¼¨ ¿T˜é“1*¦à¼J:x7²D¼oÌ»ëq7¾6É0gDGcB.n~Ä:éeC¬G.)´J" tcÝWÄ DÄíݍ¼›4Žž¤”0+뺞c"'ÍƑ Œë-,–YŸ,Í:T.QÕPüåVKÚ|øY2D™X«鼇W?ä,×o¯~d–®U8–®~ÔJ¥Õí¬.3:«Xöd½]UâÏwPtâÉÚ֊4Jº_QÆ):KÄåu{÷V "¼Ú^·‡«âA¤Mù<ˆ«bðŠôGÛww§2èKö–Õ`áÔ_¨•¨X?Ðë%,dåRW!+PAÎ>ݞ6ãánƒ%¸3?—¨0§ãfܟd Ø­GÄqÄ­ tøD8²*8ŒQ+„†“1¥ùô¨Ö³•¶+IŽ^Œ}ˆÖPf8èâÓž|¤`m¤´û”¸¹ È&_/ÓJJîäû–Ü}6¿øìÐRØAÕ³ê8za‡59zíiŸ0=›!JLд¾fèY,Ž}™ÇØ]úlKÜ£Íçr$Ëù™»j¸L£#•oq´Ëßř¤¡Ø‘Œí”uK¤ÍjœYZØEöÂtÛ«ãæ*ÉFõ ® -vßCÎÂL2‰Å$\üÂ3ʚ- G@iƒÜˆà3R!N! G†ð YøÓ5[¼ûhóçÖm°· :š.F?¢€Ô"iöuÇÑ7Ÿ\fRZÔu( X5â¿|Q74V»ÆÈ-KfCÞJïҍw^.±žÐ<¦O{-š§B<çŽ%,ð_°C㠋ŒÁZ:Ԝ{ª>XKãïÑhœDè8<‰¾Ã»!úz9ïÿ’Rb‰,I9NFGÐßoäÄÇïþ¡c½lù|í11´mgGÄd lõ¢ „2Óñ«ÎÒ¶ÅõRÛA;:‚ÝŽŒ0í#4¬,j8ŠÝ”G¼v,k$Nûðãdrä\Æ9«ÀÀáàP•\ 2¾ÿ5¼¨CRlFD°s•±¤žÊÃGø R›w Ó0‡WÆÆ5ëV/Èfµ/”‰S2¶éeŸýŒvß#âXK2@?⠙ë)4oR³çJÀ%àÓ\‰Œôúëõñý8)Hïá'ꀃËÀ0¬gìïvïÊl›eâIò¾¯ˆq=„–kIjåZ`<@cMöŸ\[-)dðœf—Ëeî°äH {ÆQ=cȒ‡A 8‚ÝŽŒ§—ü!’¡ÝÑñ`<®†Ý×›ñ#n,ÛÍ0#rÈÈ}w\¼!)@XNDâè@V ‚>n‹C“ - ¬ W9†ˆ >êI*¸F.ä÷Ža"/'\~#,+ÁÁ{„jÌAü"Rʉ –€ÃØ¡Arˆxúæ­Î›dYûKŽž­ÛÅd@20u3ý¹D>œkõóeËRt‘聙YÃòt3\~½MÓÀƘ{. ݍwTf”@Ü¦wz#F€¹ëè­E'Î*çù) [A°X©ƒ¦_'yô6DPOFèÏņX)ib¼4G6±®û³8݌ò¸“`꡺mXžxQŽ½wÉ ÇÞE:1¢|‘!v;R·ëۍ¾Û‡¥§¯›[zKàs\zºP†`ý¹XCŸµð©›˜°›ËÔøÖ,T^ð;=E‚vÄÒ+>Hút7ê·Å E!fõ_–0ê³1õ=,õ=ÊÈ[Æàê§ÖíaÃǜN.¦ècX«¶¯Mœf7¬Ö¸ô÷Oš2¦|“•± -Ô×!Æ¥¢‚A` ¼‡ÆˆtÛ#ÒÔ`ŒlE„QgÂä $T‰tÛÞ¬/~Îߏ|èo‘õ¼Ý°@6æRús±›~”Ä/`/ÝgR&ÇÒÞ”ÉÕp€ÂYQ ÅqtÞËÓÝxÂ0÷€±Ñ‹K”ÓÒ¥†z—þ«|¢±˜Â[B÷Ý-5П‹%p”É»Ž³Óš\[Žåj‰ --ajÛu”Ãö×/þ}û"°ûŽi¥Én\»Ié• -ͼdôKf^¥¡ë§d¬IÛ7¤õ'ý&42{ý&´¤m⺌îߜÉG„¼¦ôO| yq¸¸ÛáÝwm SãTqß|»ÐãFßlåWøBõ_žüN¨“endstream -endobj -550 0 obj -4978 -endobj -551 0 obj<>>>/Annots 306 0 R>>endobj -552 0 obj<>stream -x͜[7…ßý+úi‘»Šº[­Ë‹…clj¾Åž¬÷!ÀBÖhf:ÑÅ+iâäßï)²Hžª'ã$õ4Ï'v±X$‹lýï^]ñ¯®fMÕN«Õöޗg÷¾x´¨šquvQÕÝbTWÓÙ¤:;¯Æ£ñ]}v¶|³YWû‹êÁ~wZïNÇÏÏ~¸÷ÕÙ=)JUµ|zùõ½v:WÓÉÿßV]7jôbS½’/r‚ÃeõÅ£IU×òըʹÃ×Ñ÷NF“Q¥ßE°mU›ü=ŠŽ÷àiyXžúý.QXLݎZ[CTã´Ïr@ÞÎF'\5.ûmFˆÙXì ¦¢T‡xµÜ¾Yf©ÀXLF Lj6ýœ¤Ú¢õ§¾­ëÅ, ûJh¨šQ3úYµi`|iðÏFwõ_3.žZMñ…S¸å¤–š† 5ù:uB8oÓ¢{ძåÛÓú Gr¸xãYzÛCºâÈE²­å"ùqü‹×׫ëCú%Ղ„ð€ñà‘ô¾Çü#éYÀ$¸!Û$ð„óývٗþDB``± Ø9y³ðBˆùLÑ :ùƒØA*qæà‹†¡¶ç€ðúj™ Á†ûðFè}_‰=‚[Îà³,ºÄÂBRO¹ZoÞ¦0-ž”dÑҕ#ð-ñÑàIF'aÆ<¸™ðŒÇ¹¤a*ÙKОp¹Î&e3™[†b=#¬î?½7ÂƧxÁ¶Â.ȧârÞKâœDa7Æô¶g|÷òI ØiI"Xsrx$WBï{ÜÂÌ"Õ3Žý¶ß,Ãú­YÀw>u\°á¢M›ma18AnT6£Ãµ -¶t|›”UI`ìmÕU¤)@ï[ÄÓe¿¡ .ËÁ^‰k‘ -Xʓþw·‘¸íÆZãw»jÍnÑ“î,ˆ0ãéïÒJ>.U@Î.ÁC¹Êôu8z¢e0¢y“ÈÎþðcÌñÉ9‡?0V»ieÿ-yz¸ ie~γ-iïéJÐÐ̈èêÈÓ~uØ÷eu£z¡Ñ6 Jl_—ëíþTv9Hˆ¶Y´˜äXŒð¡ÕúœwÒI+3·a…´€'=Xn6±•?Qt­YËâ!µf¸ Ö”sãtd[Ú² ³±­T'!¬·áÙr›OØkD,Äûð -GOúUf°L:—,™ D x -N®®>v)ôƒÅ͒Ö슴c™“¥¦Ô8öfWÿÒeXÖVBã†0&#ô¾‡¼Ø\_^†Ä8&RLŽ($' (ð¤û×ÈÂîNýÊÉ'@ìè`\¯Z xÜSÌÅRV\ã'¶5¸_ÐãEiÙŽ¤Òeè ÖN¬ ÇØ0¤sÓzÛ30ç46‰à×°ØÌ"ærí´ôb ÈÚu -xÆ×8gQòओî%‹@ó$ ì)æy‰€ÀÓÖ!´€GÜßlöљÄ5±éçe©“¶f“« #½öÌxA¾€<ÖpR¶¹bc+ïeL*Cˆ·Œ—ëãõ&w$“Ɣ䫁Äûȃ°§)öÞí:‡PÛ:»Né,r.È®Shv6*V “»(E°U÷f€Þ÷ˆÇ»ã ®Q¤ ç jËJxãîF*0Ð{ÑQ¸> ëéôN¨‘4BŸ¸¡\›`O)¯º›pAmÒyOwÛQ -"§4Œ<¶ˆ<Á&Ç)<{˜á Ú'9 M=ýW?:Ó ”WÝM¸ Óà]?@S¦RRQ"Ƒ5Dã ðŽÕy¬˜’øÓY'í˒¦ÁËq9%/Ô8œ–×!¬ ݔN¬À5¬BæeÑ')á¤Çj “¡bZ%úJp¾‘Dh*$ÑÑTŒÐûñb}ØöGiª<ò‘$䣘”àõe_ ± „ødj}¢TÀC88‘ -“°pÖÁVd.POxýؼ0Á:P°0r5A(”Q& SK飀yÇÁÖǜigò¸X/`:ÁFMüÓ 6aŠõ+qa­LB{NÙDüÈ-ÄÖìoËël9/´æåÙ¥v]œ@qú]”„Dì.”ƒË€ðï~ýŽ2䤃£Áà­LÑû¾ìg$‡—CÉ‘¨ž±Â›—T–ŠÓË®¨)ۃ¸³LüUò”¢\y›{rñ:Rƒ…#ˆ+lœ„÷,³Á:P’v • +vßCÎÂL2‰Å$\üÂ3ʚ- G@iƒÜˆà3R!N! G†ð YøÓ5[¼ûhóçÖm°· :š.F?¢€Ô"iöuÇÑ7Ÿ\fRZÔu( X5â¿|Q74V»ÆÈ-KfCÞJïҍw^.±žÐ<¦O{-š§B<çŽ%,ð_°C㠋ŒÁZ:Ԝ{ª>XKãïÑhœDè8<‰¾Ã»!úz9ïÿ’Rb‰,I9NFGÐßoäÄÇïþ¡c½lù|í1±u;ëmgGÄd Le ”™Ž_u–¶-®—ÚÎzØÑìvd„ié¤aeQÃQì~¤¼8âí°cYë$!0p +ØGkf“É‘suçH¬‡ƒCUrÈøþ×ð¢I°qÁÎUÆ +D`x*K á3HmށNÃ^׬[½ o˜Õ¾P&NÉئ—}ô3Ø}ˆc-É`ýHˆƒd®§Ð¼I͞+—€Os%2Òë¯×Ç÷㤠½‡ŸT¨:,𞱿۽+³m–‰'É{ø¾"ÆõZ®% <¨•ohy€ð5Ùpmµ¤­ÛÒé¸\ž.È`Ï8Ê£gŒYò#èG°Û‘ñô’¿1D2´;:Œ§D«†Ý×›ñ#n,ÛÍ0#rÈÈ}w\¼!)@XNDâè@V ‚>n‹C“ + ¬ W9†ˆ >êI*¸F.ä÷Ža"/'\~#,+ÁÁ{„jÌAü"Rʉ –€ÃØ¡Arˆxúæ­Î›dYûKŽžÞw1 LÝL.ž‹s­~¾,Ã`YŠ.=03kXžnF€Ëï±·iØsÏ¥¤»àŽÊŒè‘ÛôNoÄ0w½µèÄYå<0?…a++u°Âãë$­Û®CPOFèÏņX)ib¼4G6±®û³8݌ò¸“`꡺mXžxQŽ½wÉ ÇÞE:1¢|‘!v;R·ëۍ¾Û‡¥§¯›[zKàs\zºP†`ý¹XCŸµð©›˜°›ËÔøÖ,T^ð;=E‚vÄÒ+>Hút7ê·Å E!fõ_–0ê³1õ=,õ=ÊÈ[Æàê'o +øï˜ÓéÏÅ} kÕöµ‰Óì†ÕׂþþISF Ôo’ 2Vƒú:ĸTT0l÷Бn{DšŒ‘­ˆ0êàL˜|„*‘n{›õÅÏùû‘ý-"²ž·ÈÆ\J.vӏ’øì¥ûLÊäX›`‚2¹®P8+ +´8ŽÎ{yºOæ06zÑ‚c‰rZºÔÁ°‘BïÒ•O4SxKè¾»¥ús±Ž2yב`rZ“k˱\-Q¢%Lm»ŽrxÀþzâÅ¿o_vߑ#­t"yÍëa·#)½R¡™—ì~ÉÌ«4ôoý4ÓSX“¶oHëOúMhdöúMhIÛÄuÝ¿9“7xMéŸø@óâpq·Ã»ïÚ:§Æ©â¾ùv¡Ç¾Ùʯð…ê¿<ù7xYendstream +endobj +624 0 obj +4982 +endobj +625 0 obj<>>>/Annots 322 0 R>>endobj +626 0 obj<>stream +x͜[Ç…ßõ+yœ‡Ðœ/‚@–lG%+Ò:Î[@q¹»có¢\Ëþ÷9Õ]Ý}ªf}‘œ]ÛŒNŸ=ÕÕÕ՗áÕÕÿêjÞTí¬Zï}rñèãϖU3­.®ªº_Nêj6懲Ëj:™Nñéú£‹Õ›í¦:\UOûóf>ýéâ›GŸ^<’¡TUË_¯>ÔÎ&ÓjÖ-ñÿ]Õ÷“F/¶Õkù"'8^WÖUu-_ÚÌz|}o7é&•~ÁvU=mò÷(:Þw€çÃõquûDa!0u;im Q`Tó!ËIy;ŸtN ¸j\»Œ ó©Ø;LD©ñzµ{³Ê R±ì&KLj6›|Ÿ¤Ú¡õg¾­ëÅ, Yx€p€fÒL¾—6­—“<ñâò£É½ý×L‹§V³¦Á7s… 5ùǟõê„pÞ¦E)öÂ'7«·çÍ1ŽäpñƳô¶‡ôő‹dW-ËEòãø‰×Ÿ6ëÛãpþ!Ղ„ð€éè‘ô¾Çü5éY@ܐm’ +xÂåa·J"!00‡XP으Y x !HÄb.~d½|à¶CJœyê[%a=%ùb^xϾXœ¼iÔ+c´œ.ER´ Ù-96ÖSc¿ì'uqªj•´”’3&Åà8"üã0ì‡ýuò ҉Oµ“ÞRâýeU¼4 4¡¸ +!^\¤:°H* G©#ÄSë—$§ª½E”<¼Î7¹.$ƒW՝„jS—X`1¾É:‰“sñM¦h‘2ÄÉúâ¤ñÈ~)ƒzd¼PÄÝ/¥ƒZ?l¬&=:åå–‚›¸é˜`ìE*ñžÞ0ô¾¯Åj™ÛDâC5Ù Õ3¾ö—‡w§Ì!%8syËÑžƒ4Í’‰I‚d!ZÀC¢C‡T«]à  <5-¦~і4.^,|0j¨z.ÑͨC0êþë›<´‘bW-–Òx¥_®·í×¹ÑH î³@Ÿ5r½oåç›` m/NÌH,âÍæLIËÄçâÅ¢\ 9ßP0%ËÐu B X„OX(C£1[%[LNXýØ©€ÕŸ6Çï6Ç¿‰?5KXð>½·éÔm1½À¤C"†fyñB‡³¼>؎£Ø]Y^b…,Ï°B–7†ÌJ4.éç¡ùCÅR Œ·ås®ÄßïRÜ Mê ÐÛPÒóèçjŒº•60O ÷=3¼«áúö¸Iõ`)ÜpŽ¬Ã‚RO2AuâÌ2¦™ê¤ž‚A0ׄTٓÙ& ë«ÔWÕ*MÝHlbD*0B¤J°•è»ÉÂê /ÃnuÌAŽ•à`2æ9Šö›ç°pWµ]‡ù¬} %{ŒÌ䏇ívs”¾ƒùgóA]´é͈ѵ0hJÂEî{”Êö¨¦3ŸÊöJª‘!þ3*#ÄËãæ¸ùïípÎÅwI ¯ëdˆ5¬„÷õyµY]"1–gCÀ{±·LÜ_ÎÄí‘L.ÔĒ›µ5nr@AÊRBRAT_#E°d@4ìñÉjýíõñp»¿s ~˜§¸§ú?]:ãÔsÊX§^8ÓøŒEÕu]Kgdy4¤PI3(–Âá°&3(°U9ß—% ³édîÔÍêm¨%„Ú…D~S-`6®° á ½ Qß@”k!.ªH4¸·¿™™Ðƒ©ç"÷‹pAM¬ÇVtæW{Õ#‚¹XÛ~DxrÜ`e‘&ÏE«c‘cŒ‚}Ež¯Ö7þ4? ¥ù[IdϹ8ޞÎibŒ”²Li*“ +xÊãõýLãe‘Ô„É ?Ub{ÍÆXÆLB”© +àOpk¬ÖtöM<çÉvëdVbÀDôµQ´çT%µbM/ƒ.[%ð êç¬]ÝÚ0뱟êÈô¾¡¸™sŸé° #©2¼¬¯âEé3]ȶìX‚(GÁQ1Ïê,BïK¢Çç«ýíj»Íy+Áé$y7UI!™[lµpA®0—ÖåV”ðY ‰+ÈXÑ1Bï{ˆ ¬WÀWXN*àA¾I Îl&ÞÍõIhÏ1-È:ñƒ9bKQ°§¤Ì‡¤¡[á¸:‰íA(ÛV¬wj¼‰SÏ ˆÃ*0ú"Ž­‡b=ãjûÃıtu/6ÍÂ¥™´»&¸]¸ OœIk=‘vVäf”`gEò[£y7"<9ìvÅÒ$”ýAY¢ñFˆ—Ç6Hwyax ìÎJ*àŸ††MVé:"›#ðŒOÇÃ1,ÂÕî1ÿº+ƒwM‰åѼ܅ jJìê؆¤Å“Аª»FÒé_ÿp:oò.+‰`¼S„Þ·UxyØëaSš‘tâ aHáǸê\=¸ I!M(c¼©EBºjWÃvW~e…âÞR軚Ÿµi×4ìOuHIsf/¨±4í3ëyÎbC©{%xüp¡z½í _߬r&K"X‘œzß#ˆ{yÖeÑÐ’ +xÊÍfû6Eqñ¡$‹¾®ôaRYӊ.ü!©ÀèCp1Ñžñ,ׂ4 ÌdqÜ>Šð„ëM6)«À˜Ëڇe(Ö3ÂbîÃ{#ü±6DӅ¬5zO¸ D̳ çl²pþ¨ú¥ÌN;Ö+Ñì̘d°Ö¶áÔ Ñû¢3ãܐ$¦“Hm0‰ì9W‡âפ! cW%a=Ãos‘RÙµµ-à9Ëï?~þiHTåHѽ䀤Eþ”°FSòÕpAN–`íà‚} ì1U‚ŒÐûz’Ö{쁢8F$Ø¢—4‘aaŒUèÙþ„ls-G“NÉNAjiY̲,-àköbs~w8~›8¬sKÇA€=å‹Ã5jÚSBõ=´hkV‹[,!I¦Ì/J¶HÄì°(ÙÍ9!¶¡A(ÔC~¢ 3,ÙÀ¤ Çú‰6L¬&r²,Åûš½Æþ!-'±mØJ°2œTÀsnóÅ" °ÍÜ;„R=âÕaµãªR–LĝlU´€ç|…MÀä“,¤•$ß@Px2ë’ µ쓭Y+lÑ9/äx ?~,sàDRˎªX*×ûðôË珟½øϓ/_\¼úò‹Éùû2<䇆‡¯ÀXE É'Smd8·µI@«wÁŸupLxÐ.üL©€¥”;, YëÊ´;¨² ށ…f÷,©€…¸A•u `ˆuí“ +Xʳ’z!òúf‰g³ê°ö.AÁü}´K™MèS˜’çë6\¨_ñεTËÖ஝ë(Ç,Zö™ +ì\!”´ 6žeYÈè•è+ñÕ~¸Úä8$“$IRLÑûG Ô¬³î™¥¤ƒ£ï6›}æÆ=S›„ößUH ¶ÎÜS%´çPg!½¤Z¦*‰ê4«dUìpè+ì-©€g|õâÙ¿“M¤?%\Ëàζ©€‡Üžhd`t9Eiª’ x -Þc•ì†È©[ÅzFé‡,×A’&ðˆÊ¿~ÂZ°cŒXiH -÷¤ó~¹Ù_Æ3O’ûà՝í<ÒÄy®/RïÂmìpŒmÛa’:L͍:t¯÷‰Á$dzYðѼ¿ @ûõå' bG›[¹Þ·òŸÐYóÀ‚~–4 „´—©¿ô3)`rÌ,#H:Հ‰jÞX(UÖp¶&J¶#INØ5 , ¼,O -t)lF,œ^ X½9¥Î* r^ÚéÚDõÑv¬mvƘpc›(DÇåús§7´Ibà¬z!3ÖCö9_U“͊µ;‚¢Ah8ïëÕi_^b­ti™Y’Â=‰Æíà"ÓîÞE&æ`\è!« Õ‰ÔA'þ¥8C™Æ‘oÊ\Ôô¶g<¢°N"4BHÞ„Þ÷ˆ²v C2GÜbH¾}ÿù …³kKÇ@ëpAv /$p»–Ñ>N ò‚/ ˽/^ϐ‡Ï$©ø¸˜É€ۓ†öýÎs:³bì*¨pAfm¬=𞺋\ª–|†L–ÇÐåÈé÷¿ð<Ÿ„0h8Çi0‰l+bB‰Äåe¹fZÀ"(p‘¼¯™?JbZÀ0l‘R–ì[Ž°´Ðõîz\›˜#§’ÛÌ9­xA‡÷3 -—ðKú¸`Ñ´YË)$Δ„ýŒ - -ƒJt_óƒ$CCbÃãFx:} lâAk+ր0êÈ)ïΗ‡|¦¥ðlcVjª¢l²óRÒɼT–‹†’Àž²’÷óTŸ…À„“?£dÙ.?¦õË°ÒCŸ[Šë¨qS©Þ.ØóE“Ç¡å·ž¼¶Þ‹}<õ -Ÿ‹ïbÚcwèpæՆ/Gßbup܁þ½~›8Áÿ˜£d_‘¡Ó&Bp/C€Ë*2ðØ$Neäè+p³»*%:•¡D®§Üà« ÚVŒP¨Gp oŠH¼Tæ÷†o{Âòt:ôo®Éۋ~ŠuðÂbâm©¶Ë·o10…y£üZÖoœ7NZ!ÅÑ«¦ñÀgH1†ÏꤜÇ2َ 7¥ÅrØ ŠdOXo—œ¸Š‘£™ÇÏZ‹Hóâ篚Ôõ‹1]¿©'¤òx×Ëã[¯‰@* 0ÄY„ÞöŒož¿>{D~âç76ÈM9ßShbÎï"8äSøœ[ã}ú­ÃΆüÎUi ™*'%ñû7þdª?ºÿm8šþ)Ö3ï1¯üÙÚΘ±„Ïj,†'þ(§Ø¥X&LÃUŽÄžœò.ãK¼é”“+ -qÓð¶ Éã]/ç·õŠzŸÇkI¤W¢”WõŠB\\ҒFo{ùjð{,E Ì\~CÑ`:„÷ç¯¾È}•$¢8#‡Wtø)"Ñ^/ùĉdÎ^ƒ$‚Þöl®ì°ŠOžt€ €WA±Ræä$¯E[kêm¯¯Ø¤’q@öôMæx›ÁØ$‘ùŽ,+X¯·=a’,@ -ȱ· ©·½¼ü’ I G]^¾(½Aoôùë‹rLùìÓ+ÐËWá· -2£ÈÀ˜ËIkS…xÛ3.J+’o -aIeQo{@˜V„—OÈÿ¾¸oƒ¦^嬖|.A ±a0v¹•‡ >«<ÀUÇÁòÈóß?:Ibë•è.è$yF^þž “0!D ‚ÎÀÜÕbÐQ} F‰¾ÜÙH„þŽë°ÝG­¨·=¡MžJ -ȱ뎣,@/ÿþ³Ý¾D¬¢’ˆ#¿0cñ¶GhØûþó¿æª): ÀU%Þö¹HÎzaOžFo{6Nr%H2’ØfdBd Ù ¤)zÛzÛ¨ç ôÈ{`’+o{=~®5™‘4` Ç=ADzǞ¢‘Ø#ÁËÔ Þö{ޗ‘ç0ôױçðc×X‡ àß< ~¤5üø~ùÕý§_Þ¯pdü#îW×[œ”Í'¾Úº«þ6 '”?ë{]8|{ïÿbŽ^}endstream -endobj -553 0 obj -5199 -endobj -554 0 obj<>>>/Annots 309 0 R>>endobj -555 0 obj<>stream -x–M““@†ïüŠ>f;aøædeÕU–ḗ˜,k`Sþ{»™šÆ*ÝTm%á}ŸéžámòÓÓàãKC@˜À¾ö -oý˜CàCqçJC’FPÀW¾ßîWÅîÛ¹s„צ¹”Í¥»+^¼·…G‚^šÞ}}煉ò!‰rü_CªØ}8Ö†öëÇ´¦¥±š$ÆåغX‹ -¸Õ®†,Péœm/ ¦-;sÔ ýTÖf¯ ÿ幜܄ˆ ¡­ê{uí9`ìšßC ܃„XË"œ@ •12˜ ™¿`X`T]w-»Âl5ž}ºhÅ -äö\6‚›*šï†ħí:̄ˆ8’gê¨ñ´b[Ê]ÈÈ÷œƯ²í*Ó<ݍµ0g ¡Ÿ,Ú±ÁjÜSîAB«p¾!N ×®< Ep""­°TØM50 2• €HÀXs ?ÍXðïÏŽ…WԀ,ã•ú÷_»lÛ¹ÆXî07ú.X4P’-¦C$¦ƒ#d©"áÁN‡ã½¹ ­3ÍMçÏ îº¬â`÷!¥½ç„A &ÂäABÑ0¬@Nåed02â~HÍ5& ?Ú -G;2“)YLóaFq`É9´Fk,†iFô÷ó ã Œ¹5g³ƒÁ­J}y¾ƒ@‚n¦ý^5§¡ îDNFªY_ƒ@ràhÆ®¸ C¢# -:ï -Ùb>ù¸‰rš*r°ûuÈ:lÒº>jýôüߨ±0ÚÔMÏâþ]ÿ,Îܳø^§9Îâ,Ä,c’·›øܚ—r7f­1î» PÊo¨<Žû”~BVUU¹PñþÙÕÍendstream -endobj -556 0 obj -661 -endobj -557 0 obj<>endobj -558 0 obj<>endobj -559 0 obj<>endobj -560 0 obj<>endobj -561 0 obj<>endobj -562 0 obj<>endobj -563 0 obj<>endobj -564 0 obj<>endobj -565 0 obj<>endobj -566 0 obj<>endobj -567 0 obj<>endobj -568 0 obj<>endobj -569 0 obj<>endobj -570 0 obj<>endobj -571 0 obj<>endobj -572 0 obj<>endobj -573 0 obj<>endobj -574 0 obj<>endobj -575 0 obj<>endobj -576 0 obj<>endobj -577 0 obj<>endobj -578 0 obj<>endobj -579 0 obj<>endobj -580 0 obj<>endobj -581 0 obj<>endobj -582 0 obj<>endobj -583 0 obj<>endobj -584 0 obj<>endobj -585 0 obj<>endobj -586 0 obj<>endobj -587 0 obj<>endobj -588 0 obj<>endobj -589 0 obj<>endobj -590 0 obj<>endobj -591 0 obj<>endobj -592 0 obj<>endobj -593 0 obj<>endobj -594 0 obj<>endobj -595 0 obj<>endobj -596 0 obj<>endobj -597 0 obj<>endobj -598 0 obj<>endobj -599 0 obj<>endobj -600 0 obj<>endobj -601 0 obj<>endobj -602 0 obj<>endobj -603 0 obj<>endobj -604 0 obj<>endobj -605 0 obj<>endobj -606 0 obj<>endobj -607 0 obj<>endobj -608 0 obj<>endobj -609 0 obj<>endobj -610 0 obj<>endobj -611 0 obj<>endobj -612 0 obj<>endobj -613 0 obj<>endobj -614 0 obj<>endobj -615 0 obj<>endobj -616 0 obj<>endobj -617 0 obj<>endobj -618 0 obj<>endobj -619 0 obj<>endobj -620 0 obj<>endobj -621 0 obj<>endobj -622 0 obj<>endobj -623 0 obj<>endobj -624 0 obj<>endobj -625 0 obj<>endobj -626 0 obj<>endobj -627 0 obj<>endobj -628 0 obj<>endobj -629 0 obj<>endobj -630 0 obj<>endobj -631 0 obj<>endobj -632 0 obj<>endobj -633 0 obj<>endobj -634 0 obj<>endobj -635 0 obj<>endobj -636 0 obj<>endobj -637 0 obj<>endobj -638 0 obj<>endobj -639 0 obj<>endobj -640 0 obj<>endobj -641 0 obj<>endobj -642 0 obj<>endobj -643 0 obj<>endobj -644 0 obj<>endobj -645 0 obj<>endobj -646 0 obj<>endobj -647 0 obj<>endobj -648 0 obj<>endobj -649 0 obj<>1<>4<>]>>>>endobj +,ûg­B®ña§C:sT© ©°.ŋÜuhã¹ÅüÊætئqÑ]I8?‹Ø.Lp¿A&·ZŸÃ³ô÷“7ýÈ<ý—}ì,ÕÊn²T¸ÐçÃþq‹„À&]˜p;û¨^öE 4c â™4¸Œ¹®éw¶ƒì̃„­¤á‚Ì#ïHÐë ó‰ÛAnUV%ⅱÓ:’¾Æigô$þúˆô€ØR§f™LÙ[0-à(ȱ¾.u½iöþƒØ/sß/åZb*)͵NxÚe'i‹Ò•cö¯lèag‚ÞöŒ‹Õ‘ÖIHcbñy C–ˆ£j åK¯’›Ýà êç­8.љ™sƒÈ&YFÈUãE±kƒÕ ›\`ü· éÃ1L£W¢'ð™6YÄN9é=Ó+­2=AG‹âæEˆ–Á :µ˜Dq0GŽ­#§BÃÖq-[=½ Ô"˜ø!k´ E°EÊ\½Ažëãát¸*s’„amÃuQöˆôj³;Љ+w›e Œ0BëÍ%Ÿ;$­dmã +Å#Òl/?ht­‰mÁ¼ªÑ„ j͙?å-ý« ±±µ”RCÐ۞ñbµËHHûcNÒbˆNàë}xãºÃ:SXLØ+4˜T`ÄÁû뛝c×~ҙ…¦‹â2¨Gó… j’~ܽʰNØÇ aNè}‹x¹½½¾¯LŠ!ðž¤¶Ó &°œÇ·ØÆ؟‡µ]q$yìèb\§Ä·°çÈÁÒ¦’dÁþ\+à rЛpA­€×Äü€ŽYcz¢•€Ù#">â탠H„&À@>·ˆ®Gšv±¬B÷ FŒÏqv2¯É±”04O¢F”gOóðG" ð:|’¡Ôâñv{ˆ®$n‰C÷²›ÿ#=¶3+pr&,Ÿ<Šä Xø'!e›?6¶p¼)E¸P‚ÞöŒW›Óí6w$“Æ”}jÑûò$œJç‚ÓBíììŠ×óì&\]ñ› óI±jÌÞT/;¢poè}Ep ¸6B‘ÖEãԖ•ðÆݍT` ÷"Êq}Ö3Ì +¿8:¦AÜP®M°`žgÜòjjž0cÆÝàÍ]?ãvç ¢6Àd^ʀØ&#ÄÃn8‡ y÷ÿ¶'Ø]H°æ‘¦Í3îxQ\¶^øAÖ)åHRKðÅBO`©<Çàë-Ö°ûo–IÇ3eJ#g¿órp¼Ð'ãåà8ËçU‰»–ƒ+,ÞVXChÏ\–ƒ“¯ŸÍõ"Y9ÞöÇy­‘Dkåx™©‚Þ÷ˆ—›ãn8IS呏´ a!¯í+ieÜ£>Ê`–I`)¦Nåz'R! [À¶" i?Oøú™y½”u `b”]k‚wPh5™$`š•Z*ºÙòޜò!'–a kN­5j*àŸf´ùR”à¨_‰ keÚs¾NñEš÷=͜†@s~PÞòÉC`¼Ð +˜Ÿ©;̑OÄØ¡$,Á®áBIzÛþ5lÞÑê8éàh|á­LÑûžÂ~F"qxIG "Q=c÷H¯©*,§—]¤lâ~Ì2ñWY£´åzÈÛܓ‹×‘,œ8B\aã$¼g™ýց‚mK×P©€§ð±XRÉNˆʲ5ÑžQú!‹ÄõCä‡I<¢ò/ë²$ì#V’Â=érXm×a¸ÇÓ{$öí¡ú°âcôzÛüâ`Ôàô®¼÷dŠô€òVIbwƒ‹óè}ø60èoIFØÜ0 éoRÀCäŒB† ¸vBª)×C¼3°T:­,gÚÚ(ۃhÄ$x¥)%Q=¢üÔiÐÅ°1.fZÀÌ;i¬“Ð!oGJ*à)§›Õq#©ZsŸY¼ëø®’‘† ê¥8ÛÂ[^¤ˆ>®êÝY­·­þÎ1Cñç©jf(Õ2Œ÷aŽ„–Èe`i&$¨EÞí7ÇÓÍð6¤ÅÀ`}ÈÍ â¥k L%óác™6.r:Î€—sìüaѵ†ê£ÝX[cD¸³=¢¦cŠr}=îh‘ÄÀ9ôAf$¬‡ÐIOIH‘ã1¡<âr8nÖçCy휵ҝe6jI +÷$Ãuæôû[ÝR¾ +¨áÐ'eò¢Qø»tK´ƒ]2Opû*GHì*–‡£à3 +éE뇕?ÖÇ»¾eúFeœxQùΞñë?´æĖr>Bþ.æ\ø³¡bN·M¡òø~ëƒ=G„§#W ï &J˜,1E¹¾"c³~ø©À_iPkÍY<ÌÂJø»Xô¶ø9¦T,«ø‰)!©:â¼kùÃÕœß!<?ž†_î"Šr=ÆD©"—U5Cˆ·=BT‘@¡ «·½~ŸŠR“ì›jÄÛã‚úÚ}_½yE­”†ðwiûއ%·º§Ò¸yÀZü7“­Gi6rֈ×DÂNF¢„•¦(×bÌoœ Ú-¼9iôòkVMs'*ñBÎôqÄY9–‹÷—«c>*H2´8¶yåwj`N5¡Þ¶ ›[¤–á5|(ÒÂËÃ9c'óðëLˆLKØ­Nå¼}‘`҆ž›±>Þ¶úêíêˆm[´gd þ5)—uH¬¾ä¬)ü]/yúœÉ­©ª8º«ñPxýÊëÔ)'xs”ìAc·L„øB¯ÑØÎendstream +endobj +627 0 obj +5013 +endobj +628 0 obj<>>>/Annots 334 0 R>>endobj +629 0 obj<>stream +x͙ÍoÛFÅïþ+öè­ÌoJ§Âqë&‡ÂM-4_Iv”Zb*ÉqûßçÍ~o†6äÐ4Qœ÷Ópgçq¹üû$wþr×®lÜr{òr~rv9sEææ·.¯g“Ü5måæ+—M² ß.Oç‹w÷k×ݺ‹nw\ó'¿ÌO$ÀG¹\>ýñ«|ãšj†ÿ·®Ê'³xpï®åwLüþΝ]Ö.Ï嗡«ñcô«ïë½‹?F¸­« ˧ b6Ijl][O¦:³pÚ¨¯®‹$'ÅÖåY;)µ>œ7ú‹û +!XF[F 0WWoçW2¸À£4_N¾Ë¿ºŒ…()r)cˆBԓ"Ä"Ÿ]V±¤˜_ ‚§ªª˜_CQñÖMåú6’"Û.Ïßø XT@Çy¶ +f¤ŠbÒ`¤šR®ÏÄë“ñ)JœäY/ã3Œ‰0B-b!ž¶ŒWÝcšu¤‘‰[OZMˆç-a¹Ø%‹€È 1¾Œ`¯{idæ·2!X²ÛÝnîöëžDZ¦…ô"Õr}–su}Öw2‹¶p½™­J +°·‹ýǔË©¦âFœG +°èn½ì=•à4™ø’âD´åt½-²ˆ©x¯FDªE8Öm]™7¶Èxb`yLXº³Ò‰¤›H•F•5 À:LuS€%,=‚D@T¥-L¢Ž=4 ´èFs1À–ÊíYÌ´±—,æv(-«p;-¼AòìH–q½Ø¾[ü$v]VÃç<ÒøZ¡ê}ʐOåNZŸ*z'F ÁS˜N#ŸŠ€è(LÌaìS ,…‘:bXŸJ„à5Š #Âs>•HÁ§I|jÄᎌ6ÑO"PGîI–ÁòVü…!1`)S;°„r*·{EÐáæt× >G:1©JšJQBÀˆýòæÅ}B$Fc¡"6¡0B)¿c(e.fŠŀ%Ÿ}*,¤jÅl$pŸ€ôãË*0°ü6Š#Ù‰€h½mª4BÀQLþI£Ê*0f~é®;b°]‘JìÊ[žb„€CÙUóŒ]i³ªg êUá`0«zÖâ¤5«R›U" ‹Z§ެƌóaBYTµXB(Bÿíå¹û}ß}½þŸ»åÃ/ÉÏeo©q?¶òÊuuºÙlâçÍÉgG@+endstream +endobj +630 0 obj +1798 +endobj +631 0 obj<>endobj +632 0 obj<>endobj +633 0 obj<>endobj +634 0 obj<>endobj +635 0 obj<>endobj +636 0 obj<>endobj +637 0 obj<>endobj +638 0 obj<>endobj +639 0 obj<>endobj +640 0 obj<>endobj +641 0 obj<>endobj +642 0 obj<>endobj +643 0 obj<>endobj +644 0 obj<>endobj +645 0 obj<>endobj +646 0 obj<>endobj +647 0 obj<>endobj +648 0 obj<>endobj +649 0 obj<>endobj +650 0 obj<>endobj +651 0 obj<>endobj +652 0 obj<>endobj +653 0 obj<>endobj +654 0 obj<>endobj +655 0 obj<>endobj +656 0 obj<>endobj +657 0 obj<>endobj +658 0 obj<>endobj +659 0 obj<>endobj +660 0 obj<>endobj +661 0 obj<>endobj +662 0 obj<>endobj +663 0 obj<>endobj +664 0 obj<>endobj +665 0 obj<>endobj +666 0 obj<>endobj +667 0 obj<>endobj +668 0 obj<>endobj +669 0 obj<>endobj +670 0 obj<>endobj +671 0 obj<>endobj +672 0 obj<>endobj +673 0 obj<>endobj +674 0 obj<>endobj +675 0 obj<>endobj +676 0 obj<>endobj +677 0 obj<>endobj +678 0 obj<>endobj +679 0 obj<>endobj +680 0 obj<>endobj +681 0 obj<>endobj +682 0 obj<>endobj +683 0 obj<>endobj +684 0 obj<>endobj +685 0 obj<>endobj +686 0 obj<>endobj +687 0 obj<>endobj +688 0 obj<>endobj +689 0 obj<>endobj +690 0 obj<>endobj +691 0 obj<>endobj +692 0 obj<>endobj +693 0 obj<>endobj +694 0 obj<>endobj +695 0 obj<>endobj +696 0 obj<>endobj +697 0 obj<>endobj +698 0 obj<>endobj +699 0 obj<>endobj +700 0 obj<>endobj +701 0 obj<>endobj +702 0 obj<>endobj +703 0 obj<>endobj +704 0 obj<>endobj +705 0 obj<>endobj +706 0 obj<>endobj +707 0 obj<>endobj +708 0 obj<>endobj +709 0 obj<>endobj +710 0 obj<>endobj +711 0 obj<>endobj +712 0 obj<>endobj +713 0 obj<>endobj +714 0 obj<>endobj +715 0 obj<>endobj +716 0 obj<>endobj +717 0 obj<>endobj +718 0 obj<>endobj +719 0 obj<>endobj +720 0 obj<>endobj +721 0 obj<>endobj +722 0 obj<>endobj +723 0 obj<>endobj +724 0 obj<>endobj +725 0 obj<>endobj +726 0 obj<>endobj +727 0 obj<>endobj +728 0 obj<>endobj +729 0 obj<>endobj +730 0 obj<>endobj +731 0 obj<>endobj +732 0 obj<>1<>4<>]>>>>endobj xref -0 650 +0 733 0000000000 65535 f 0000000015 00000 n 0000000244 00000 n @@ -1437,623 +1673,706 @@ xref 0000003817 00000 n 0000003874 00000 n 0000003959 00000 n -0000004064 00000 n -0000004102 00000 n -0000004143 00000 n -0000004227 00000 n -0000004269 00000 n -0000004354 00000 n -0000004393 00000 n -0000004478 00000 n -0000004520 00000 n -0000004605 00000 n -0000004647 00000 n -0000004732 00000 n -0000004776 00000 n -0000004861 00000 n -0000004920 00000 n -0000004967 00000 n -0000005052 00000 n -0000005076 00000 n -0000005128 00000 n -0000005213 00000 n -0000005262 00000 n -0000005347 00000 n -0000005396 00000 n -0000005480 00000 n -0000005532 00000 n -0000005617 00000 n -0000005665 00000 n -0000005750 00000 n -0000005798 00000 n -0000005882 00000 n -0000005945 00000 n -0000006030 00000 n -0000006096 00000 n -0000006159 00000 n -0000006242 00000 n -0000006266 00000 n -0000006313 00000 n -0000006398 00000 n +0000004052 00000 n +0000004136 00000 n +0000004174 00000 n +0000004279 00000 n +0000004320 00000 n +0000004404 00000 n +0000004446 00000 n +0000004531 00000 n +0000004570 00000 n +0000004655 00000 n +0000004697 00000 n +0000004782 00000 n +0000004824 00000 n +0000004909 00000 n +0000004968 00000 n +0000005012 00000 n +0000005097 00000 n +0000005121 00000 n +0000005168 00000 n +0000005253 00000 n +0000005305 00000 n +0000005390 00000 n +0000005439 00000 n +0000005524 00000 n +0000005573 00000 n +0000005657 00000 n +0000005709 00000 n +0000005793 00000 n +0000005845 00000 n +0000005893 00000 n +0000005978 00000 n +0000006026 00000 n +0000006110 00000 n +0000006173 00000 n +0000006258 00000 n +0000006296 00000 n +0000006359 00000 n 0000006444 00000 n -0000006528 00000 n -0000006568 00000 n -0000006651 00000 n -0000006689 00000 n +0000006468 00000 n +0000006515 00000 n +0000006600 00000 n +0000006646 00000 n 0000006730 00000 n -0000006815 00000 n -0000006863 00000 n -0000006948 00000 n -0000006994 00000 n -0000007079 00000 n -0000007117 00000 n -0000007169 00000 n -0000007254 00000 n -0000007297 00000 n -0000007382 00000 n -0000007438 00000 n -0000007523 00000 n -0000007618 00000 n -0000007702 00000 n -0000007747 00000 n -0000007795 00000 n -0000007880 00000 n -0000007926 00000 n -0000008010 00000 n -0000008041 00000 n -0000008087 00000 n -0000008172 00000 n -0000008219 00000 n -0000008304 00000 n -0000008348 00000 n -0000008434 00000 n -0000008476 00000 n -0000008562 00000 n -0000008602 00000 n -0000008688 00000 n -0000008736 00000 n -0000008822 00000 n -0000008867 00000 n -0000008953 00000 n -0000008997 00000 n -0000009083 00000 n -0000009134 00000 n -0000009220 00000 n -0000009269 00000 n -0000009355 00000 n -0000009400 00000 n -0000009486 00000 n -0000009528 00000 n -0000009614 00000 n -0000009657 00000 n -0000009743 00000 n -0000009785 00000 n -0000009871 00000 n -0000009915 00000 n -0000010001 00000 n -0000010038 00000 n -0000010124 00000 n -0000010166 00000 n -0000010252 00000 n -0000010294 00000 n -0000010380 00000 n -0000010417 00000 n -0000010503 00000 n -0000010545 00000 n -0000010631 00000 n -0000010674 00000 n -0000010760 00000 n -0000010806 00000 n -0000010892 00000 n -0000010939 00000 n -0000011024 00000 n -0000011225 00000 n -0000011274 00000 n -0000011361 00000 n -0000011410 00000 n -0000011496 00000 n -0000011545 00000 n -0000011632 00000 n -0000011674 00000 n -0000011720 00000 n -0000011807 00000 n -0000011833 00000 n -0000011948 00000 n -0000012035 00000 n -0000012061 00000 n -0000012143 00000 n -0000012230 00000 n -0000012315 00000 n -0000012402 00000 n -0000012457 00000 n -0000012544 00000 n -0000012600 00000 n -0000012687 00000 n -0000012737 00000 n -0000012785 00000 n -0000012872 00000 n +0000006770 00000 n +0000006853 00000 n +0000006891 00000 n +0000006932 00000 n +0000007017 00000 n +0000007065 00000 n +0000007150 00000 n +0000007196 00000 n +0000007281 00000 n +0000007319 00000 n +0000007371 00000 n +0000007456 00000 n +0000007499 00000 n +0000007584 00000 n +0000007640 00000 n +0000007725 00000 n +0000007820 00000 n +0000007904 00000 n +0000007949 00000 n +0000007995 00000 n +0000008080 00000 n +0000008126 00000 n +0000008211 00000 n +0000008260 00000 n +0000008346 00000 n +0000008393 00000 n +0000008480 00000 n +0000008528 00000 n +0000008575 00000 n +0000008662 00000 n +0000008709 00000 n +0000008794 00000 n +0000008838 00000 n +0000008924 00000 n +0000008966 00000 n +0000009052 00000 n +0000009092 00000 n +0000009178 00000 n +0000009226 00000 n +0000009312 00000 n +0000009357 00000 n +0000009443 00000 n +0000009487 00000 n +0000009573 00000 n +0000009624 00000 n +0000009710 00000 n +0000009759 00000 n +0000009845 00000 n +0000009890 00000 n +0000009976 00000 n +0000010018 00000 n +0000010104 00000 n +0000010147 00000 n +0000010233 00000 n +0000010275 00000 n +0000010361 00000 n +0000010405 00000 n +0000010491 00000 n +0000010528 00000 n +0000010614 00000 n +0000010656 00000 n +0000010742 00000 n +0000010784 00000 n +0000010870 00000 n +0000010907 00000 n +0000010991 00000 n +0000011033 00000 n +0000011117 00000 n +0000011295 00000 n +0000011338 00000 n +0000011424 00000 n +0000011470 00000 n +0000011556 00000 n +0000011603 00000 n +0000011690 00000 n +0000011739 00000 n +0000011826 00000 n +0000011875 00000 n +0000011961 00000 n +0000012010 00000 n +0000012097 00000 n +0000012163 00000 n +0000012211 00000 n +0000012297 00000 n +0000012343 00000 n +0000012430 00000 n +0000012464 00000 n +0000012579 00000 n +0000012666 00000 n +0000012692 00000 n +0000012774 00000 n +0000012861 00000 n 0000012946 00000 n 0000013033 00000 n -0000013101 00000 n -0000013187 00000 n -0000013241 00000 n -0000013326 00000 n -0000013394 00000 n -0000013479 00000 n -0000013537 00000 n -0000013611 00000 n -0000013698 00000 n -0000013746 00000 n -0000013833 00000 n -0000013890 00000 n -0000013977 00000 n -0000014032 00000 n -0000014118 00000 n -0000014199 00000 n -0000014286 00000 n -0000014344 00000 n -0000014389 00000 n -0000014476 00000 n -0000014502 00000 n -0000014547 00000 n -0000014633 00000 n -0000014676 00000 n -0000014763 00000 n -0000014813 00000 n -0000014900 00000 n -0000014950 00000 n -0000015035 00000 n -0000015083 00000 n -0000015170 00000 n -0000015217 00000 n -0000015303 00000 n -0000015369 00000 n -0000015448 00000 n -0000015535 00000 n -0000015617 00000 n -0000015703 00000 n -0000015778 00000 n -0000015865 00000 n -0000015938 00000 n -0000016025 00000 n -0000016075 00000 n -0000016153 00000 n -0000016240 00000 n -0000016266 00000 n -0000016371 00000 n -0000016477 00000 n -0000016583 00000 n -0000016689 00000 n -0000016795 00000 n -0000016901 00000 n -0000017007 00000 n -0000017113 00000 n -0000017219 00000 n -0000017325 00000 n -0000017431 00000 n -0000017537 00000 n -0000017643 00000 n -0000017749 00000 n -0000017855 00000 n -0000017961 00000 n -0000018067 00000 n -0000018173 00000 n -0000018279 00000 n -0000018385 00000 n -0000018490 00000 n -0000018596 00000 n -0000018702 00000 n -0000018808 00000 n -0000018914 00000 n -0000019020 00000 n -0000019126 00000 n -0000019232 00000 n -0000019338 00000 n -0000019443 00000 n -0000019549 00000 n -0000019655 00000 n -0000019760 00000 n -0000019866 00000 n -0000019972 00000 n -0000020078 00000 n -0000020184 00000 n -0000020290 00000 n -0000020396 00000 n -0000020502 00000 n -0000020608 00000 n -0000020714 00000 n -0000020819 00000 n -0000020923 00000 n -0000021027 00000 n -0000021405 00000 n -0000021511 00000 n -0000021616 00000 n -0000021722 00000 n -0000021828 00000 n -0000021934 00000 n +0000013088 00000 n +0000013173 00000 n +0000013215 00000 n +0000013271 00000 n +0000013358 00000 n +0000013406 00000 n +0000013493 00000 n +0000013567 00000 n +0000013652 00000 n +0000013694 00000 n +0000013762 00000 n +0000013849 00000 n +0000013903 00000 n +0000013990 00000 n +0000014058 00000 n +0000014145 00000 n +0000014219 00000 n +0000014306 00000 n +0000014354 00000 n +0000014441 00000 n +0000014498 00000 n +0000014585 00000 n +0000014640 00000 n +0000014727 00000 n +0000014808 00000 n +0000014895 00000 n +0000014977 00000 n +0000015022 00000 n +0000015109 00000 n +0000015135 00000 n +0000015180 00000 n +0000015266 00000 n +0000015309 00000 n +0000015396 00000 n +0000015446 00000 n +0000015533 00000 n +0000015583 00000 n +0000015668 00000 n +0000015716 00000 n +0000015803 00000 n +0000015850 00000 n +0000015936 00000 n +0000016002 00000 n +0000016081 00000 n +0000016168 00000 n +0000016250 00000 n +0000016336 00000 n +0000016411 00000 n +0000016498 00000 n +0000016571 00000 n +0000016658 00000 n +0000016708 00000 n +0000016786 00000 n +0000016873 00000 n +0000016899 00000 n +0000016962 00000 n +0000017049 00000 n +0000017112 00000 n +0000017199 00000 n +0000017253 00000 n +0000017340 00000 n +0000017382 00000 n +0000017487 00000 n +0000017593 00000 n +0000017699 00000 n +0000017805 00000 n +0000017911 00000 n +0000018017 00000 n +0000018123 00000 n +0000018229 00000 n +0000018335 00000 n +0000018441 00000 n +0000018547 00000 n +0000018653 00000 n +0000018759 00000 n +0000018865 00000 n +0000018971 00000 n +0000019077 00000 n +0000019183 00000 n +0000019289 00000 n +0000019395 00000 n +0000019501 00000 n +0000019606 00000 n +0000019712 00000 n +0000019818 00000 n +0000019924 00000 n +0000020030 00000 n +0000020136 00000 n +0000020242 00000 n +0000020348 00000 n +0000020454 00000 n +0000020559 00000 n +0000020665 00000 n +0000020771 00000 n +0000020876 00000 n +0000020982 00000 n +0000021088 00000 n +0000021194 00000 n +0000021300 00000 n +0000021406 00000 n +0000021512 00000 n +0000021618 00000 n +0000021724 00000 n +0000021830 00000 n +0000021935 00000 n 0000022039 00000 n -0000022145 00000 n -0000022251 00000 n -0000022357 00000 n -0000022463 00000 n -0000022569 00000 n -0000022675 00000 n -0000022781 00000 n -0000022887 00000 n -0000022993 00000 n -0000023098 00000 n -0000023204 00000 n -0000023310 00000 n -0000023416 00000 n -0000023522 00000 n -0000023628 00000 n -0000023734 00000 n -0000023840 00000 n -0000023946 00000 n -0000024052 00000 n -0000024158 00000 n -0000024264 00000 n -0000024370 00000 n -0000024476 00000 n -0000024581 00000 n -0000024687 00000 n -0000024793 00000 n -0000024899 00000 n -0000025005 00000 n -0000025111 00000 n -0000025217 00000 n -0000025323 00000 n -0000025429 00000 n -0000025535 00000 n -0000025640 00000 n -0000025745 00000 n -0000025849 00000 n -0000025953 00000 n -0000026315 00000 n -0000026421 00000 n -0000026527 00000 n -0000026561 00000 n -0000026595 00000 n -0000026629 00000 n -0000028196 00000 n -0000028245 00000 n -0000028294 00000 n -0000028343 00000 n -0000028392 00000 n -0000028441 00000 n -0000028490 00000 n -0000028539 00000 n -0000028588 00000 n -0000028637 00000 n -0000028686 00000 n -0000028735 00000 n -0000028784 00000 n -0000028833 00000 n -0000028882 00000 n -0000028931 00000 n -0000028980 00000 n -0000029029 00000 n -0000029078 00000 n -0000029127 00000 n -0000029176 00000 n -0000029225 00000 n -0000029274 00000 n -0000029323 00000 n -0000029372 00000 n -0000029421 00000 n -0000029470 00000 n -0000029519 00000 n -0000029568 00000 n -0000029617 00000 n -0000029666 00000 n -0000029715 00000 n -0000029764 00000 n -0000029813 00000 n -0000029862 00000 n -0000029911 00000 n -0000029960 00000 n -0000030009 00000 n -0000030058 00000 n -0000030107 00000 n -0000030156 00000 n -0000030205 00000 n -0000030254 00000 n -0000030303 00000 n -0000030352 00000 n -0000030401 00000 n -0000030450 00000 n -0000030499 00000 n -0000030548 00000 n -0000030597 00000 n -0000030646 00000 n -0000030695 00000 n -0000030744 00000 n -0000030793 00000 n -0000030842 00000 n -0000030891 00000 n -0000030940 00000 n -0000030989 00000 n -0000031038 00000 n -0000031087 00000 n -0000031136 00000 n -0000031185 00000 n -0000031234 00000 n -0000031283 00000 n -0000031332 00000 n -0000031381 00000 n -0000031430 00000 n -0000031479 00000 n -0000031528 00000 n -0000031577 00000 n -0000031626 00000 n -0000031675 00000 n -0000031724 00000 n -0000031773 00000 n -0000031822 00000 n -0000031871 00000 n -0000031920 00000 n -0000031969 00000 n -0000032018 00000 n -0000032067 00000 n -0000032116 00000 n -0000032165 00000 n -0000032214 00000 n -0000032263 00000 n -0000032312 00000 n -0000032361 00000 n -0000032410 00000 n -0000032459 00000 n -0000032508 00000 n -0000032557 00000 n -0000032606 00000 n -0000032655 00000 n -0000032704 00000 n -0000032753 00000 n -0000032802 00000 n -0000032851 00000 n -0000032900 00000 n -0000033361 00000 n -0000033508 00000 n -0000034047 00000 n -0000034068 00000 n -0000034242 00000 n -0000035405 00000 n -0000035427 00000 n -0000035578 00000 n -0000037100 00000 n -0000037122 00000 n -0000037282 00000 n -0000038718 00000 n -0000038740 00000 n -0000038918 00000 n -0000040178 00000 n -0000040200 00000 n -0000040342 00000 n -0000041926 00000 n -0000041948 00000 n -0000042081 00000 n -0000043818 00000 n -0000043840 00000 n -0000043973 00000 n -0000044495 00000 n -0000044516 00000 n -0000044658 00000 n -0000046328 00000 n -0000046350 00000 n -0000046511 00000 n -0000048362 00000 n -0000048384 00000 n -0000048572 00000 n -0000050189 00000 n -0000050211 00000 n -0000050390 00000 n -0000052213 00000 n -0000052235 00000 n -0000052409 00000 n -0000053626 00000 n -0000053648 00000 n -0000053822 00000 n -0000055427 00000 n -0000055449 00000 n -0000055592 00000 n -0000056349 00000 n -0000056370 00000 n -0000056554 00000 n -0000058341 00000 n -0000058363 00000 n -0000058537 00000 n -0000060643 00000 n -0000060665 00000 n -0000060840 00000 n -0000062567 00000 n -0000062589 00000 n -0000062773 00000 n -0000064742 00000 n -0000064764 00000 n -0000064934 00000 n -0000066444 00000 n -0000066466 00000 n -0000066650 00000 n -0000068561 00000 n -0000068583 00000 n -0000068766 00000 n -0000070395 00000 n -0000070417 00000 n -0000070591 00000 n -0000072195 00000 n -0000072217 00000 n -0000072391 00000 n -0000074133 00000 n -0000074155 00000 n -0000074321 00000 n -0000075900 00000 n -0000075922 00000 n -0000076098 00000 n -0000077839 00000 n -0000077861 00000 n -0000078046 00000 n -0000079872 00000 n -0000079894 00000 n -0000080069 00000 n -0000081974 00000 n -0000081996 00000 n -0000082171 00000 n -0000084293 00000 n -0000084315 00000 n -0000084491 00000 n -0000086343 00000 n -0000086365 00000 n -0000086541 00000 n -0000088467 00000 n -0000088489 00000 n -0000088665 00000 n -0000090755 00000 n -0000090777 00000 n -0000090928 00000 n -0000092624 00000 n -0000092646 00000 n -0000092769 00000 n -0000093755 00000 n -0000093776 00000 n -0000093928 00000 n -0000095673 00000 n -0000095695 00000 n -0000095837 00000 n -0000097591 00000 n -0000097613 00000 n -0000097764 00000 n -0000099703 00000 n -0000099725 00000 n -0000099876 00000 n -0000101691 00000 n -0000101713 00000 n -0000101856 00000 n -0000102937 00000 n -0000102959 00000 n -0000103143 00000 n -0000105016 00000 n -0000105038 00000 n -0000105207 00000 n -0000107067 00000 n -0000107089 00000 n -0000107249 00000 n -0000108934 00000 n -0000108956 00000 n -0000109130 00000 n -0000110857 00000 n -0000110879 00000 n -0000111030 00000 n -0000111954 00000 n -0000111975 00000 n -0000112142 00000 n -0000113807 00000 n -0000113829 00000 n -0000113986 00000 n -0000115166 00000 n -0000115188 00000 n -0000115345 00000 n -0000120394 00000 n -0000120416 00000 n -0000120573 00000 n -0000125843 00000 n -0000125865 00000 n -0000126013 00000 n -0000126745 00000 n -0000126766 00000 n -0000126822 00000 n -0000126927 00000 n -0000127105 00000 n -0000127224 00000 n -0000127359 00000 n -0000127495 00000 n -0000127643 00000 n -0000127793 00000 n -0000127933 00000 n -0000128074 00000 n -0000128227 00000 n -0000128389 00000 n -0000128538 00000 n -0000128726 00000 n -0000128859 00000 n -0000128987 00000 n -0000129105 00000 n -0000129241 00000 n -0000129383 00000 n -0000129499 00000 n -0000129625 00000 n -0000129741 00000 n -0000129935 00000 n -0000130040 00000 n -0000130163 00000 n -0000130299 00000 n -0000130435 00000 n -0000130580 00000 n -0000130704 00000 n -0000130831 00000 n -0000130973 00000 n -0000131178 00000 n -0000131283 00000 n -0000131383 00000 n -0000131563 00000 n -0000131668 00000 n -0000131787 00000 n -0000131912 00000 n -0000132057 00000 n -0000132199 00000 n -0000132349 00000 n -0000132480 00000 n -0000132606 00000 n -0000132731 00000 n -0000132871 00000 n -0000132998 00000 n -0000133129 00000 n -0000133261 00000 n -0000133439 00000 n -0000133567 00000 n -0000133703 00000 n -0000133838 00000 n -0000134045 00000 n -0000134148 00000 n -0000134293 00000 n -0000134465 00000 n -0000134597 00000 n -0000134731 00000 n -0000134864 00000 n -0000134988 00000 n -0000135109 00000 n -0000135256 00000 n -0000135460 00000 n -0000135561 00000 n -0000135679 00000 n -0000135806 00000 n -0000135925 00000 n -0000136048 00000 n -0000136188 00000 n -0000136315 00000 n -0000136455 00000 n -0000136591 00000 n -0000136713 00000 n -0000136849 00000 n -0000136966 00000 n -0000137069 00000 n -0000137273 00000 n -0000137434 00000 n -0000137582 00000 n -0000137710 00000 n -0000137853 00000 n -0000137977 00000 n -0000138106 00000 n -0000138251 00000 n -0000138416 00000 n -0000138568 00000 n -0000138719 00000 n -0000138816 00000 n -0000139000 00000 n -0000139189 00000 n -0000139371 00000 n -0000139529 00000 n +0000022143 00000 n +0000022521 00000 n +0000022627 00000 n +0000022732 00000 n +0000022838 00000 n +0000022944 00000 n +0000023050 00000 n +0000023155 00000 n +0000023261 00000 n +0000023367 00000 n +0000023473 00000 n +0000023579 00000 n +0000023685 00000 n +0000023791 00000 n +0000023897 00000 n +0000024003 00000 n +0000024109 00000 n +0000024215 00000 n +0000024321 00000 n +0000024427 00000 n +0000024533 00000 n +0000024638 00000 n +0000024744 00000 n +0000024850 00000 n +0000024956 00000 n +0000025062 00000 n +0000025168 00000 n +0000025274 00000 n +0000025380 00000 n +0000025486 00000 n +0000025592 00000 n +0000025698 00000 n +0000025804 00000 n +0000025910 00000 n +0000026016 00000 n +0000026121 00000 n +0000026227 00000 n +0000026333 00000 n +0000026439 00000 n +0000026545 00000 n +0000026651 00000 n +0000026757 00000 n +0000026863 00000 n +0000026968 00000 n +0000027072 00000 n +0000027434 00000 n +0000027539 00000 n +0000027645 00000 n +0000027751 00000 n +0000027857 00000 n +0000027963 00000 n +0000028069 00000 n +0000028174 00000 n +0000028280 00000 n +0000028386 00000 n +0000028492 00000 n +0000028598 00000 n +0000028704 00000 n +0000028738 00000 n +0000028772 00000 n +0000030594 00000 n +0000030643 00000 n +0000030692 00000 n +0000030741 00000 n +0000030790 00000 n +0000030839 00000 n +0000030888 00000 n +0000030937 00000 n +0000030986 00000 n +0000031035 00000 n +0000031084 00000 n +0000031133 00000 n +0000031182 00000 n +0000031231 00000 n +0000031280 00000 n +0000031329 00000 n +0000031378 00000 n +0000031427 00000 n +0000031476 00000 n +0000031525 00000 n +0000031574 00000 n +0000031623 00000 n +0000031672 00000 n +0000031721 00000 n +0000031770 00000 n +0000031819 00000 n +0000031868 00000 n +0000031917 00000 n +0000031966 00000 n +0000032015 00000 n +0000032064 00000 n +0000032113 00000 n +0000032162 00000 n +0000032211 00000 n +0000032260 00000 n +0000032309 00000 n +0000032358 00000 n +0000032407 00000 n +0000032456 00000 n +0000032505 00000 n +0000032554 00000 n +0000032603 00000 n +0000032652 00000 n +0000032701 00000 n +0000032750 00000 n +0000032799 00000 n +0000032848 00000 n +0000032897 00000 n +0000032946 00000 n +0000032995 00000 n +0000033044 00000 n +0000033093 00000 n +0000033142 00000 n +0000033191 00000 n +0000033240 00000 n +0000033289 00000 n +0000033338 00000 n +0000033387 00000 n +0000033436 00000 n +0000033485 00000 n +0000033534 00000 n +0000033583 00000 n +0000033632 00000 n +0000033681 00000 n +0000033730 00000 n +0000033779 00000 n +0000033828 00000 n +0000033877 00000 n +0000033926 00000 n +0000033975 00000 n +0000034024 00000 n +0000034073 00000 n +0000034122 00000 n +0000034171 00000 n +0000034220 00000 n +0000034269 00000 n +0000034318 00000 n +0000034367 00000 n +0000034416 00000 n +0000034465 00000 n +0000034514 00000 n +0000034563 00000 n +0000034612 00000 n +0000034661 00000 n +0000034710 00000 n +0000034759 00000 n +0000034808 00000 n +0000034857 00000 n +0000034906 00000 n +0000034955 00000 n +0000035004 00000 n +0000035053 00000 n +0000035102 00000 n +0000035151 00000 n +0000035200 00000 n +0000035249 00000 n +0000035298 00000 n +0000035347 00000 n +0000035396 00000 n +0000035445 00000 n +0000035494 00000 n +0000035543 00000 n +0000035592 00000 n +0000035641 00000 n +0000035690 00000 n +0000035739 00000 n +0000035788 00000 n +0000035837 00000 n +0000035886 00000 n +0000035935 00000 n +0000035984 00000 n +0000036033 00000 n +0000036082 00000 n +0000036631 00000 n +0000036778 00000 n +0000037310 00000 n +0000037331 00000 n +0000037505 00000 n +0000038668 00000 n +0000038690 00000 n +0000038841 00000 n +0000040363 00000 n +0000040385 00000 n +0000040545 00000 n +0000041981 00000 n +0000042003 00000 n +0000042181 00000 n +0000043441 00000 n +0000043463 00000 n +0000043605 00000 n +0000045189 00000 n +0000045211 00000 n +0000045344 00000 n +0000047081 00000 n +0000047103 00000 n +0000047236 00000 n +0000047758 00000 n +0000047779 00000 n +0000047921 00000 n +0000049591 00000 n +0000049613 00000 n +0000049774 00000 n +0000051625 00000 n +0000051647 00000 n +0000051835 00000 n +0000053452 00000 n +0000053474 00000 n +0000053653 00000 n +0000055476 00000 n +0000055498 00000 n +0000055672 00000 n +0000056889 00000 n +0000056911 00000 n +0000057085 00000 n +0000058690 00000 n +0000058712 00000 n +0000058855 00000 n +0000059612 00000 n +0000059633 00000 n +0000059817 00000 n +0000061642 00000 n +0000061664 00000 n +0000061838 00000 n +0000064034 00000 n +0000064056 00000 n +0000064249 00000 n +0000066192 00000 n +0000066214 00000 n +0000066398 00000 n +0000068297 00000 n +0000068319 00000 n +0000068503 00000 n +0000070174 00000 n +0000070196 00000 n +0000070357 00000 n +0000072057 00000 n +0000072079 00000 n +0000072271 00000 n +0000074003 00000 n +0000074025 00000 n +0000074208 00000 n +0000075837 00000 n +0000075859 00000 n +0000076033 00000 n +0000077637 00000 n +0000077659 00000 n +0000077833 00000 n +0000079575 00000 n +0000079597 00000 n +0000079782 00000 n +0000081588 00000 n +0000081610 00000 n +0000081776 00000 n +0000083479 00000 n +0000083501 00000 n +0000083677 00000 n +0000085683 00000 n +0000085705 00000 n +0000085899 00000 n +0000087736 00000 n +0000087758 00000 n +0000087927 00000 n +0000089865 00000 n +0000089887 00000 n +0000090081 00000 n +0000092110 00000 n +0000092132 00000 n +0000092308 00000 n +0000094113 00000 n +0000094135 00000 n +0000094301 00000 n +0000096167 00000 n +0000096189 00000 n +0000096355 00000 n +0000098736 00000 n +0000098758 00000 n +0000098900 00000 n +0000100824 00000 n +0000100846 00000 n +0000100988 00000 n +0000102683 00000 n +0000102705 00000 n +0000102865 00000 n +0000104889 00000 n +0000104911 00000 n +0000105062 00000 n +0000106634 00000 n +0000106656 00000 n +0000106798 00000 n +0000108771 00000 n +0000108793 00000 n +0000108944 00000 n +0000110873 00000 n +0000110895 00000 n +0000111037 00000 n +0000112901 00000 n +0000112923 00000 n +0000113083 00000 n +0000114917 00000 n +0000114939 00000 n +0000115062 00000 n +0000116150 00000 n +0000116172 00000 n +0000116324 00000 n +0000118069 00000 n +0000118091 00000 n +0000118233 00000 n +0000119987 00000 n +0000120009 00000 n +0000120160 00000 n +0000122099 00000 n +0000122121 00000 n +0000122272 00000 n +0000124086 00000 n +0000124108 00000 n +0000124251 00000 n +0000125332 00000 n +0000125354 00000 n +0000125538 00000 n +0000127413 00000 n +0000127435 00000 n +0000127604 00000 n +0000129464 00000 n +0000129486 00000 n +0000129646 00000 n +0000131331 00000 n +0000131353 00000 n +0000131527 00000 n +0000133254 00000 n +0000133276 00000 n +0000133427 00000 n +0000134351 00000 n +0000134372 00000 n +0000134539 00000 n +0000136204 00000 n +0000136226 00000 n +0000136383 00000 n +0000137570 00000 n +0000137592 00000 n +0000137749 00000 n +0000139300 00000 n +0000139322 00000 n +0000139472 00000 n +0000140185 00000 n +0000140206 00000 n +0000140363 00000 n +0000145416 00000 n +0000145438 00000 n +0000145595 00000 n +0000150679 00000 n +0000150701 00000 n +0000150858 00000 n +0000152727 00000 n +0000152749 00000 n +0000152805 00000 n +0000152910 00000 n +0000153088 00000 n +0000153207 00000 n +0000153342 00000 n +0000153478 00000 n +0000153626 00000 n +0000153776 00000 n +0000153916 00000 n +0000154057 00000 n +0000154210 00000 n +0000154372 00000 n +0000154521 00000 n +0000154709 00000 n +0000154842 00000 n +0000154970 00000 n +0000155088 00000 n +0000155224 00000 n +0000155366 00000 n +0000155482 00000 n +0000155608 00000 n +0000155724 00000 n +0000155918 00000 n +0000156023 00000 n +0000156146 00000 n +0000156282 00000 n +0000156418 00000 n +0000156563 00000 n +0000156687 00000 n +0000156814 00000 n +0000156956 00000 n +0000157161 00000 n +0000157266 00000 n +0000157366 00000 n +0000157546 00000 n +0000157651 00000 n +0000157770 00000 n +0000157895 00000 n +0000158040 00000 n +0000158182 00000 n +0000158332 00000 n +0000158463 00000 n +0000158589 00000 n +0000158714 00000 n +0000158854 00000 n +0000158981 00000 n +0000159112 00000 n +0000159243 00000 n +0000159421 00000 n +0000159549 00000 n +0000159685 00000 n +0000159820 00000 n +0000160026 00000 n +0000160139 00000 n +0000160255 00000 n +0000160400 00000 n +0000160572 00000 n +0000160720 00000 n +0000160872 00000 n +0000161004 00000 n +0000161138 00000 n +0000161271 00000 n +0000161409 00000 n +0000161559 00000 n +0000161727 00000 n +0000161874 00000 n +0000162078 00000 n +0000162179 00000 n +0000162297 00000 n +0000162424 00000 n +0000162543 00000 n +0000162666 00000 n +0000162806 00000 n +0000162933 00000 n +0000163073 00000 n +0000163209 00000 n +0000163331 00000 n +0000163467 00000 n +0000163584 00000 n +0000163687 00000 n +0000163891 00000 n +0000164052 00000 n +0000164200 00000 n +0000164328 00000 n +0000164471 00000 n +0000164595 00000 n +0000164724 00000 n +0000164869 00000 n +0000165034 00000 n +0000165186 00000 n +0000165350 00000 n +0000165447 00000 n +0000165631 00000 n +0000165820 00000 n +0000166002 00000 n +0000166160 00000 n +0000166334 00000 n +0000166440 00000 n +0000166570 00000 n +0000166696 00000 n +0000166806 00000 n trailer -<<4c0cb111c71223d1abdea98e47b3a13f>]>> +<<379319e715cf855d9f261ba14b5e3b6b>]>> startxref -139743 +167020 %%EOF diff --git a/docs/docbook/Makefile.in b/docs/docbook/Makefile.in index e3694896f24..0c043d77e36 100644 --- a/docs/docbook/Makefile.in +++ b/docs/docbook/Makefile.in @@ -36,7 +36,8 @@ MANPAGES=$(MANDIR)/findsmb.1 $(MANDIR)/smbclient.1 \ $(MANDIR)/smbpasswd.5 $(MANDIR)/testparm.1 $(MANDIR)/samba.7 \ $(MANDIR)/smbpasswd.8 $(MANDIR)/testprns.1 \ $(MANDIR)/smb.conf.5 $(MANDIR)/wbinfo.1 \ - $(MANDIR)/smbcacls.1 $(MANDIR)/smbsh.1 $(MANDIR)/winbindd.8 + $(MANDIR)/smbcacls.1 $(MANDIR)/smbsh.1 $(MANDIR)/winbindd.8 \ + $(MANDIR)/make_unicodemap.1 SGMLMANSRC=manpages/findsmb.1.sgml manpages/smbclient.1.sgml \ manpages/smbspool.8.sgml manpages/lmhosts.5.sgml \ @@ -50,12 +51,14 @@ SGMLMANSRC=manpages/findsmb.1.sgml manpages/smbclient.1.sgml \ manpages/smbpasswd.8.sgml manpages/testprns.1.sgml \ manpages/smb.conf.5.sgml \ manpages/wbinfo.1.sgml manpages/smbcacls.1.sgml \ - manpages/smbsh.1.sgml manpages/winbindd.8.sgml + manpages/smbsh.1.sgml manpages/winbindd.8.sgml \ + manpages/make_unicodemap.1.sgml HOWTOSRC=projdoc/DOMAIN_MEMBER.sgml projdoc/NT_Security.sgml \ projdoc/msdfs_setup.sgml projdoc/printer_driver2.sgml \ projdoc/UNIX_INSTALL.sgml projdoc/winbind.sgml projdoc/OS2-Client-HOWTO.sgml \ - projdoc/Samba-PDC-HOWTO.sgml projdoc/ENCRYPTION.sgml + projdoc/Samba-PDC-HOWTO.sgml projdoc/ENCRYPTION.sgml \ + projdoc/CVS-Access.sgml FAQSRC=faq/samba-pdc-faq.sgml @@ -71,7 +74,7 @@ man: $(MANPAGES) FAQ: $(FAQSRC) @echo Building SAMBA PDC FAQ... @(for i in $?; do \ - htmlfile=`basename $$i | sed "s/\.sgml/\.html/g"`; \ + htmlfile=`echo $$i | sed 's,.*/,,' | sed "s/\.sgml/\.html/g"`; \ echo "Making $$htmlfile"; \ $(JADE) -t sgml -V nochunks -d $(SGML_SHARE)/dsssl/docbook/html/docbook.dsl \ -f /tmp/jade.log $$i > ../htmldocs/$$htmlfile; \ @@ -82,13 +85,13 @@ FAQ: $(FAQSRC) HOWTO: $(HOWTOSRC) @echo Building HOWTO pages... @(for i in $?; do \ - htmlfile=`basename $$i | sed "s/\.sgml/\.html/g"`; \ + htmlfile=`echo $$i | sed 's,.*/,,' | sed "s/\.sgml/\.html/g"`; \ echo "Making $$htmlfile"; \ - cat $$i | $(PERL) scripts/make-article.pl > /tmp/`basename $$i`; \ + cat $$i | $(PERL) scripts/make-article.pl > /tmp/`echo $$i | sed 's,.*/,,'`; \ $(JADE) -t sgml -V nochunks -d $(SGML_SHARE)/dsssl/docbook/html/docbook.dsl \ - -f /tmp/jade.log /tmp/`basename $$i` > ../htmldocs/$$htmlfile; \ + -f /tmp/jade.log /tmp/`echo $$i | sed 's,.*/,,'` > ../htmldocs/$$htmlfile; \ cat /tmp/jade.log | grep -v DTDDECL; \ - /bin/rm -f /tmp/jade.log /tmp/`basename $$i`; \ + /bin/rm -f /tmp/jade.log /tmp/`echo $$i | sed 's,.*/,,'`; \ done) @@ -102,7 +105,6 @@ proj-doc: @(cd projdoc; $(JADE) -t sgml -i html -V nochunks -d ../stylesheets/ldp.dsl\#html samba-doc.sgml > ../samba-doc.html) @(cd scripts; ./ldp_print ../samba-doc.html) @mv -f samba-doc.pdf ../Samba-HOWTO-Collection.pdf - #@$(HTMLDOC) -f ../Samba-HOWTO-Collection.pdf samba-doc.html @/bin/mv -f samba-doc.html ../htmldocs/Samba-HOWTO-Collection.html @@ -113,7 +115,7 @@ proj-doc: man-html-all: $(SGMLMANSRC) @echo Building HTML formatted man pages... @(for i in $?; do \ - htmlfile=`basename $$i | sed "s/\.sgml/\.html/g"`; \ + htmlfile=`echo $$i | sed 's,.*/,,' | sed "s/\.sgml/\.html/g"`; \ echo "Making $$htmlfile"; \ $(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html -f /tmp/jade.log $$i > ../htmldocs/$$htmlfile; \ cat /tmp/jade.log | grep -v DTDDECL; \ @@ -124,7 +126,7 @@ man-html-all: $(SGMLMANSRC) man-all: $(SGMLMANSRC) @echo Building man pages... @(for i in $?; do \ - manfile=`basename $$i | sed "s/\.sgml//g"`; \ + manfile=`echo $$i | sed 's,.*/,,' | sed "s/\.sgml//g"`; \ echo "Making $$manfile"; \ $(ONSGMLS) -f /tmp/docbook2x.log $$i | $(SGMLSPL) \ $(SGML_SHARE)/docbook2X/docbook2man-spec.pl; \ @@ -143,210 +145,218 @@ man-all: $(SGMLMANSRC) $(MANDIR)/findsmb.1: manpages/findsmb.1.sgml @echo "Making $@" @$(ONSGMLS) $< | $(SGMLSPL) $(SGML_SHARE)/docbook2X/docbook2man-spec.pl - @cat `basename $@` | $(PERL) scripts/strip-links.pl > $@ - @/bin/rm -f `basename $@` + @cat `echo $@ | sed 's,.*/,,'` | $(PERL) scripts/strip-links.pl > $@ + @/bin/rm -f `echo $@ | sed 's,.*/,,'` @echo "Making HTML version of $@" - @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`basename $< | sed "s/\.sgml/\.html/g"` + @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`echo $< | sed 's,.*/,,'| sed "s/\.sgml/\.html/g"` $(MANDIR)/smbclient.1: manpages/smbclient.1.sgml @echo "Making $@" @$(ONSGMLS) $< | $(SGMLSPL) $(SGML_SHARE)/docbook2X/docbook2man-spec.pl - @cat `basename $@` | $(PERL) scripts/strip-links.pl > $@ - @/bin/rm -f `basename $@` + @cat `echo $@ | sed 's,.*/,,'` | $(PERL) scripts/strip-links.pl > $@ + @/bin/rm -f `echo $@ | sed 's,.*/,,'` @echo "Making HTML version of $@" - @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`basename $< | sed "s/\.sgml/\.html/g"` + @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`echo $< | sed 's,.*/,,'| sed "s/\.sgml/\.html/g"` $(MANDIR)/smbspool.8: manpages/smbspool.8.sgml @echo "Making $@" @$(ONSGMLS) $< | $(SGMLSPL) $(SGML_SHARE)/docbook2X/docbook2man-spec.pl - @cat `basename $@` | $(PERL) scripts/strip-links.pl > $@ - @/bin/rm -f `basename $@` + @cat `echo $@ | sed 's,.*/,,'` | $(PERL) scripts/strip-links.pl > $@ + @/bin/rm -f `echo $@ | sed 's,.*/,,'` @echo "Making HTML version of $@" - @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`basename $< | sed "s/\.sgml/\.html/g"` + @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`echo $< | sed 's,.*/,,'| sed "s/\.sgml/\.html/g"` $(MANDIR)/lmhosts.5: manpages/lmhosts.5.sgml @echo "Making $@" @$(ONSGMLS) $< | $(SGMLSPL) $(SGML_SHARE)/docbook2X/docbook2man-spec.pl - @cat `basename $@` | $(PERL) scripts/strip-links.pl > $@ - @/bin/rm -f `basename $@` + @cat `echo $@ | sed 's,.*/,,'` | $(PERL) scripts/strip-links.pl > $@ + @/bin/rm -f `echo $@ | sed 's,.*/,,'` @echo "Making HTML version of $@" - @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`basename $< | sed "s/\.sgml/\.html/g"` + @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`echo $< | sed 's,.*/,,'| sed "s/\.sgml/\.html/g"` $(MANDIR)/smbcontrol.1: manpages/smbcontrol.1.sgml @echo "Making $@" @$(ONSGMLS) $< | $(SGMLSPL) $(SGML_SHARE)/docbook2X/docbook2man-spec.pl - @cat `basename $@` | $(PERL) scripts/strip-links.pl > $@ - @/bin/rm -f `basename $@` + @cat `echo $@ | sed 's,.*/,,'` | $(PERL) scripts/strip-links.pl > $@ + @/bin/rm -f `echo $@ | sed 's,.*/,,'` @echo "Making HTML version of $@" - @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`basename $< | sed "s/\.sgml/\.html/g"` + @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`echo $< | sed 's,.*/,,'| sed "s/\.sgml/\.html/g"` $(MANDIR)/smbstatus.1: manpages/smbstatus.1.sgml @echo "Making $@" @$(ONSGMLS) $< | $(SGMLSPL) $(SGML_SHARE)/docbook2X/docbook2man-spec.pl - @cat `basename $@` | $(PERL) scripts/strip-links.pl > $@ - @/bin/rm -f `basename $@` + @cat `echo $@ | sed 's,.*/,,'` | $(PERL) scripts/strip-links.pl > $@ + @/bin/rm -f `echo $@ | sed 's,.*/,,'` @echo "Making HTML version of $@" - @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`basename $< | sed "s/\.sgml/\.html/g"` + @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`echo $< | sed 's,.*/,,'| sed "s/\.sgml/\.html/g"` $(MANDIR)/make_smbcodepage.1: manpages/make_smbcodepage.1.sgml @echo "Making $@" @$(ONSGMLS) $< | $(SGMLSPL) $(SGML_SHARE)/docbook2X/docbook2man-spec.pl - @cat `basename $@` | $(PERL) scripts/strip-links.pl > $@ - @/bin/rm -f `basename $@` + @cat `echo $@ | sed 's,.*/,,'` | $(PERL) scripts/strip-links.pl > $@ + @/bin/rm -f `echo $@ | sed 's,.*/,,'` @echo "Making HTML version of $@" - @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`basename $< | sed "s/\.sgml/\.html/g"` + @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`echo $< | sed 's,.*/,,'| sed "s/\.sgml/\.html/g"` + +$(MANDIR)/make_unicodemap.1: manpages/make_unicodemap.1.sgml + @echo "Making $@" + @$(ONSGMLS) $< | $(SGMLSPL) $(SGML_SHARE)/docbook2X/docbook2man-spec.pl + @cat `echo $@ | sed 's,.*/,,'` | $(PERL) scripts/strip-links.pl > $@ + @/bin/rm -f `echo $@ | sed 's,.*/,,'` + @echo "Making HTML version of $@" + @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`echo $< | sed 's,.*/,,'| sed "s/\.sgml/\.html/g"` $(MANDIR)/smbd.8: manpages/smbd.8.sgml @echo "Making $@" @$(ONSGMLS) $< | $(SGMLSPL) $(SGML_SHARE)/docbook2X/docbook2man-spec.pl - @cat `basename $@` | $(PERL) scripts/strip-links.pl > $@ - @/bin/rm -f `basename $@` + @cat `echo $@ | sed 's,.*/,,'` | $(PERL) scripts/strip-links.pl > $@ + @/bin/rm -f `echo $@ | sed 's,.*/,,'` @echo "Making HTML version of $@" - @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`basename $< | sed "s/\.sgml/\.html/g"` + @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`echo $< | sed 's,.*/,,'| sed "s/\.sgml/\.html/g"` $(MANDIR)/smbtar.1: manpages/smbtar.1.sgml @echo "Making $@" @$(ONSGMLS) $< | $(SGMLSPL) $(SGML_SHARE)/docbook2X/docbook2man-spec.pl - @cat `basename $@` | $(PERL) scripts/strip-links.pl > $@ - @/bin/rm -f `basename $@` + @cat `echo $@ | sed 's,.*/,,'` | $(PERL) scripts/strip-links.pl > $@ + @/bin/rm -f `echo $@ | sed 's,.*/,,'` @echo "Making HTML version of $@" - @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`basename $< | sed "s/\.sgml/\.html/g"` + @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`echo $< | sed 's,.*/,,'| sed "s/\.sgml/\.html/g"` $(MANDIR)/nmbd.8: manpages/nmbd.8.sgml @echo "Making $@" @$(ONSGMLS) $< | $(SGMLSPL) $(SGML_SHARE)/docbook2X/docbook2man-spec.pl - @cat `basename $@` | $(PERL) scripts/strip-links.pl > $@ - @/bin/rm -f `basename $@` + @cat `echo $@ | sed 's,.*/,,'` | $(PERL) scripts/strip-links.pl > $@ + @/bin/rm -f `echo $@ | sed 's,.*/,,'` @echo "Making HTML version of $@" - @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`basename $< | sed "s/\.sgml/\.html/g"` + @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`echo $< | sed 's,.*/,,'| sed "s/\.sgml/\.html/g"` $(MANDIR)/smbmnt.8: manpages/smbmnt.8.sgml @echo "Making $@" @$(ONSGMLS) $< | $(SGMLSPL) $(SGML_SHARE)/docbook2X/docbook2man-spec.pl - @cat `basename $@` | $(PERL) scripts/strip-links.pl > $@ - @/bin/rm -f `basename $@` + @cat `echo $@ | sed 's,.*/,,'` | $(PERL) scripts/strip-links.pl > $@ + @/bin/rm -f `echo $@ | sed 's,.*/,,'` @echo "Making HTML version of $@" - @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`basename $< | sed "s/\.sgml/\.html/g"` + @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`echo $< | sed 's,.*/,,'| sed "s/\.sgml/\.html/g"` $(MANDIR)/smbumount.8: manpages/smbumount.8.sgml @echo "Making $@" @$(ONSGMLS) $< | $(SGMLSPL) $(SGML_SHARE)/docbook2X/docbook2man-spec.pl - @cat `basename $@` | $(PERL) scripts/strip-links.pl > $@ - @/bin/rm -f `basename $@` + @cat `echo $@ | sed 's,.*/,,'` | $(PERL) scripts/strip-links.pl > $@ + @/bin/rm -f `echo $@ | sed 's,.*/,,'` @echo "Making HTML version of $@" - @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`basename $< | sed "s/\.sgml/\.html/g"` + @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`echo $< | sed 's,.*/,,'| sed "s/\.sgml/\.html/g"` $(MANDIR)/nmblookup.1: manpages/nmblookup.1.sgml @echo "Making $@" @$(ONSGMLS) $< | $(SGMLSPL) $(SGML_SHARE)/docbook2X/docbook2man-spec.pl - @cat `basename $@` | $(PERL) scripts/strip-links.pl > $@ - @/bin/rm -f `basename $@` + @cat `echo $@ | sed 's,.*/,,'` | $(PERL) scripts/strip-links.pl > $@ + @/bin/rm -f `echo $@ | sed 's,.*/,,'` @echo "Making HTML version of $@" - @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`basename $< | sed "s/\.sgml/\.html/g"` + @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`echo $< | sed 's,.*/,,'| sed "s/\.sgml/\.html/g"` $(MANDIR)/smbmount.8: manpages/smbmount.8.sgml @echo "Making $@" @$(ONSGMLS) $< | $(SGMLSPL) $(SGML_SHARE)/docbook2X/docbook2man-spec.pl - @cat `basename $@` | $(PERL) scripts/strip-links.pl > $@ - @/bin/rm -f `basename $@` + @cat `echo $@ | sed 's,.*/,,'` | $(PERL) scripts/strip-links.pl > $@ + @/bin/rm -f `echo $@ | sed 's,.*/,,'` @echo "Making HTML version of $@" - @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`basename $< | sed "s/\.sgml/\.html/g"` + @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`echo $< | sed 's,.*/,,'| sed "s/\.sgml/\.html/g"` $(MANDIR)/swat.8: manpages/swat.8.sgml @echo "Making $@" @$(ONSGMLS) $< | $(SGMLSPL) $(SGML_SHARE)/docbook2X/docbook2man-spec.pl - @cat `basename $@` | $(PERL) scripts/strip-links.pl > $@ - @/bin/rm -f `basename $@` + @cat `echo $@ | sed 's,.*/,,'` | $(PERL) scripts/strip-links.pl > $@ + @/bin/rm -f `echo $@ | sed 's,.*/,,'` @echo "Making HTML version of $@" - @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`basename $< | sed "s/\.sgml/\.html/g"` + @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`echo $< | sed 's,.*/,,'| sed "s/\.sgml/\.html/g"` $(MANDIR)/rpcclient.1: manpages/rpcclient.1.sgml @echo "Making $@" @$(ONSGMLS) $< | $(SGMLSPL) $(SGML_SHARE)/docbook2X/docbook2man-spec.pl - @cat `basename $@` | $(PERL) scripts/strip-links.pl > $@ - @/bin/rm -f `basename $@` + @cat `echo $@ | sed 's,.*/,,'` | $(PERL) scripts/strip-links.pl > $@ + @/bin/rm -f `echo $@ | sed 's,.*/,,'` @echo "Making HTML version of $@" - @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`basename $< | sed "s/\.sgml/\.html/g"` + @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`echo $< | sed 's,.*/,,'| sed "s/\.sgml/\.html/g"` $(MANDIR)/smbpasswd.5: manpages/smbpasswd.5.sgml @echo "Making $@" @$(ONSGMLS) $< | $(SGMLSPL) $(SGML_SHARE)/docbook2X/docbook2man-spec.pl - @cat `basename $@` | $(PERL) scripts/strip-links.pl > $@ - @/bin/rm -f `basename $@` + @cat `echo $@ | sed 's,.*/,,'` | $(PERL) scripts/strip-links.pl > $@ + @/bin/rm -f `echo $@ | sed 's,.*/,,'` @echo "Making HTML version of $@" - @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`basename $< | sed "s/\.sgml/\.html/g"` + @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`echo $< | sed 's,.*/,,'| sed "s/\.sgml/\.html/g"` $(MANDIR)/testparm.1: manpages/testparm.1.sgml @echo "Making $@" @$(ONSGMLS) $< | $(SGMLSPL) $(SGML_SHARE)/docbook2X/docbook2man-spec.pl - @cat `basename $@` | $(PERL) scripts/strip-links.pl > $@ - @/bin/rm -f `basename $@` + @cat `echo $@ | sed 's,.*/,,'` | $(PERL) scripts/strip-links.pl > $@ + @/bin/rm -f `echo $@ | sed 's,.*/,,'` @echo "Making HTML version of $@" - @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`basename $< | sed "s/\.sgml/\.html/g"` + @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`echo $< | sed 's,.*/,,'| sed "s/\.sgml/\.html/g"` $(MANDIR)/samba.7: manpages/samba.7.sgml @echo "Making $@" @$(ONSGMLS) $< | $(SGMLSPL) $(SGML_SHARE)/docbook2X/docbook2man-spec.pl - @cat `basename $@` | $(PERL) scripts/strip-links.pl > $@ - @/bin/rm -f `basename $@` + @cat `echo $@ | sed 's,.*/,,'` | $(PERL) scripts/strip-links.pl > $@ + @/bin/rm -f `echo $@ | sed 's,.*/,,'` @echo "Making HTML version of $@" - @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`basename $< | sed "s/\.sgml/\.html/g"` + @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`echo $< | sed 's,.*/,,'| sed "s/\.sgml/\.html/g"` $(MANDIR)/smbpasswd.8: manpages/smbpasswd.8.sgml @echo "Making $@" @$(ONSGMLS) $< | $(SGMLSPL) $(SGML_SHARE)/docbook2X/docbook2man-spec.pl - @cat `basename $@` | $(PERL) scripts/strip-links.pl > $@ - @/bin/rm -f `basename $@` + @cat `echo $@ | sed 's,.*/,,'` | $(PERL) scripts/strip-links.pl > $@ + @/bin/rm -f `echo $@ | sed 's,.*/,,'` @echo "Making HTML version of $@" - @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`basename $< | sed "s/\.sgml/\.html/g"` + @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`echo $< | sed 's,.*/,,'| sed "s/\.sgml/\.html/g"` $(MANDIR)/testprns.1: manpages/testprns.1.sgml @echo "Making $@" @$(ONSGMLS) $< | $(SGMLSPL) $(SGML_SHARE)/docbook2X/docbook2man-spec.pl - @cat `basename $@` | $(PERL) scripts/strip-links.pl > $@ - @/bin/rm -f `basename $@` + @cat `echo $@ | sed 's,.*/,,'` | $(PERL) scripts/strip-links.pl > $@ + @/bin/rm -f `echo $@ | sed 's,.*/,,'` @echo "Making HTML version of $@" - @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`basename $< | sed "s/\.sgml/\.html/g"` + @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`echo $< | sed 's,.*/,,'| sed "s/\.sgml/\.html/g"` $(MANDIR)/smb.conf.5: manpages/smb.conf.5.sgml @echo "Making $@" @$(ONSGMLS) $< | $(SGMLSPL) $(SGML_SHARE)/docbook2X/docbook2man-spec.pl - @cat `basename $@` | $(PERL) scripts/strip-links.pl > $@ - @/bin/rm -f `basename $@` + @cat `echo $@ | sed 's,.*/,,'` | $(PERL) scripts/strip-links.pl > $@ + @/bin/rm -f `echo $@ | sed 's,.*/,,'` @echo "Making HTML version of $@" - @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`basename $< | sed "s/\.sgml/\.html/g"` + @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`echo $< | sed 's,.*/,,'| sed "s/\.sgml/\.html/g"` $(MANDIR)/wbinfo.1: manpages/wbinfo.1.sgml @echo "Making $@" @$(ONSGMLS) $< | $(SGMLSPL) $(SGML_SHARE)/docbook2X/docbook2man-spec.pl - @cat `basename $@` | $(PERL) scripts/strip-links.pl > $@ - @/bin/rm -f `basename $@` + @cat `echo $@ | sed 's,.*/,,'` | $(PERL) scripts/strip-links.pl > $@ + @/bin/rm -f `echo $@ | sed 's,.*/,,'` @echo "Making HTML version of $@" - @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`basename $< | sed "s/\.sgml/\.html/g"` + @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`echo $< | sed 's,.*/,,'| sed "s/\.sgml/\.html/g"` $(MANDIR)/smbcacls.1: manpages/smbcacls.1.sgml @echo "Making $@" @$(ONSGMLS) $< | $(SGMLSPL) $(SGML_SHARE)/docbook2X/docbook2man-spec.pl - @cat `basename $@` | $(PERL) scripts/strip-links.pl > $@ - @/bin/rm -f `basename $@` + @cat `echo $@ | sed 's,.*/,,'` | $(PERL) scripts/strip-links.pl > $@ + @/bin/rm -f `echo $@ | sed 's,.*/,,'` @echo "Making HTML version of $@" - @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`basename $< | sed "s/\.sgml/\.html/g"` + @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`echo $< | sed 's,.*/,,'| sed "s/\.sgml/\.html/g"` $(MANDIR)/smbsh.1 : manpages/smbsh.1.sgml @echo "Making $@" @$(ONSGMLS) $< | $(SGMLSPL) $(SGML_SHARE)/docbook2X/docbook2man-spec.pl - @cat `basename $@` | $(PERL) scripts/strip-links.pl > $@ - @/bin/rm -f `basename $@` + @cat `echo $@ | sed 's,.*/,,'` | $(PERL) scripts/strip-links.pl > $@ + @/bin/rm -f `echo $@ | sed 's,.*/,,'` @echo "Making HTML version of $@" - @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`basename $< | sed "s/\.sgml/\.html/g"` + @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`echo $< | sed 's,.*/,,'| sed "s/\.sgml/\.html/g"` $(MANDIR)/winbindd.8: manpages/winbindd.8.sgml @echo "Making $@" @$(ONSGMLS) $< | $(SGMLSPL) $(SGML_SHARE)/docbook2X/docbook2man-spec.pl - @cat `basename $@` | $(PERL) scripts/strip-links.pl > $@ - @/bin/rm -f `basename $@` + @cat `echo $@ | sed 's,.*/,,'` | $(PERL) scripts/strip-links.pl > $@ + @/bin/rm -f `echo $@ | sed 's,.*/,,'` @echo "Making HTML version of $@" - @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`basename $< | sed "s/\.sgml/\.html/g"` + @$(JADE) -t sgml -i html -V nochunks -d ./stylesheets/ldp.dsl\#html $< > $(HTMLDIR)/`echo $< | sed 's,.*/,,'| sed "s/\.sgml/\.html/g"` ## Clean Rule diff --git a/docs/docbook/manpages/make_smbcodepage.1.sgml b/docs/docbook/manpages/make_smbcodepage.1.sgml index 8a58b8614dd..a36f9b968c1 100644 --- a/docs/docbook/manpages/make_smbcodepage.1.sgml +++ b/docs/docbook/manpages/make_smbcodepage.1.sgml @@ -1,5 +1,5 @@ - + make_smbcodepage @@ -56,11 +56,11 @@ inputfile - This is the input file to process. In t - he 'c' case this will be a text + This is the input file to process. In + the c case this will be a text codepage definition file such as the ones found in the Samba source/codepages directory. In - the 'd' case this will be the + the d case this will be the binary format codepage definition file normally found in the lib/codepages directory in the Samba install directory path. diff --git a/docs/docbook/manpages/make_unicodemap.1.sgml b/docs/docbook/manpages/make_unicodemap.1.sgml new file mode 100644 index 00000000000..50a5446d60b --- /dev/null +++ b/docs/docbook/manpages/make_unicodemap.1.sgml @@ -0,0 +1,172 @@ + + + + + make_unicodemap + 1 + + + + + make_unicodemap + construct a unicode map file for Samba + + + + + make_unicodemap + codepage + inputfile + outputfile + + + + + + + DESCRIPTION + + + This tool is part of the Samba + suite. + + + + make_unicodemap compiles text unicode map + files into binary unicodef map files for use with the + internationalization features of Samba 2.2. + + + + + + + OPTIONS + + + + codepage + This is the codepage or UNIX character + set we are processing (a number, e.g. 850). + + + + + inputfile + This is the input file to process. This is a + text unicode map file such as the ones found in the Samba + source/codepages directory. + + + + + outputfile + This is the binary output file to produce. + + + + + + + + Samba Unicode Map Files + + + A text Samba unicode map file is a description that tells Samba + how to map characters from a specified DOS code page or UNIX character + set to 16 bit unicode. + + + A binary Samba unicode map file is a binary representation + of the same information, including a value that specifies what + codepage or UNIX character set this file is describing. + + + + + Files + + CP<codepage>.TXT + + + These are the input (text) unicode map files provided + in the Samba source/codepages + directory. + + + + A text unicode map file consists of multiple lines + containing two fields. These fields are : + + + + character - which is + the (hex) character mapped on this line. + + + unicode - which + is the (hex) 16 bit unicode character that the character + will map to. + + + + + unicode_map.<codepage> - These are + the output (binary) unicode map files produced and placed in + the Samba destination lib/codepage + directory. + + + + + + Installation + + + The location of the server and its support files is a matter + for individual system administrators. The following are thus + suggestions only. + + + + It is recommended that the make_unicodemap + program be installed under the + $prefix/samba hierarchy, + in a directory readable by all, writeable only by root. The + program itself should be executable by all. The program + should NOT be setuid or setgid! + + + + + VERSION + + This man page is correct for version 2.2 of + the Samba suite. + + + + SEE ALSO + smbd(8), + smb.conf(5) + + + + + AUTHOR + + The original Samba software and related utilities + were created by Andrew Tridgell. Samba is now developed + by the Samba Team as an Open Source project similar + to the way the Linux kernel is developed. + + The original Samba man pages were written by Karl Auer. + The man page sources were converted to YODL format (another + excellent piece of Open Source software, available at + + ftp://ftp.icce.rug.nl/pub/unix/) and updated for the Samba 2.0 + release by Jeremy Allison. The conversion to DocBook for + Samba 2.2 was done by Gerald Carter + + + diff --git a/docs/docbook/manpages/nmbd.8.sgml b/docs/docbook/manpages/nmbd.8.sgml index 5194b1072b0..8db2749bfa5 100644 --- a/docs/docbook/manpages/nmbd.8.sgml +++ b/docs/docbook/manpages/nmbd.8.sgml @@ -37,7 +37,7 @@ nmbd is a server that understands and can reply to NetBIOS over IP name service requests, like - those produced by SMBD/CIFS clients such as Windows 95/98/ME, + those produced by SMB/CIFS clients such as Windows 95/98/ME, Windows NT, Windows 2000, and LanManager clients. It also participates in the browsing protocols which make up the Windows "Network Neighborhood" view. diff --git a/docs/docbook/manpages/rpcclient.1.sgml b/docs/docbook/manpages/rpcclient.1.sgml index c02f935d823..0d45a5dc203 100644 --- a/docs/docbook/manpages/rpcclient.1.sgml +++ b/docs/docbook/manpages/rpcclient.1.sgml @@ -107,8 +107,9 @@ -l logbasename - File name for log/debug files. .client will be - appended. The log file is never removed by the client. + File name for log/debug files. The extension + '.client' will be appended. The log file is never removed + by the client. @@ -161,9 +162,8 @@ -W domain Set the SMB domain of the username. This - overrides the default domain which is the domain of the - server specified with the -S option. - If the domain specified is the same as the server's NetBIOS name, + overrides the default domain which is the domain defined in + smb.conf. If the domain specified is the same as the server's NetBIOS name, it causes the client to log on using the server's local SAM (as opposed to the Domain SAM). @@ -179,8 +179,15 @@ LSARPC lsaquery - lookupsids - lookupnames + + lookupsids - Resolve a list + of SIDs to usernames. + + + lookupnames - Resolve s list + of usernames to SIDs. + + enumtrusts @@ -193,6 +200,10 @@ querygroup queryusergroups querygroupmem + queryaliasmem + querydispinfo + querydominfo + enumdomgroups @@ -244,6 +255,12 @@ + deldriver - Delete the + specified printer driver for all architectures. This + does not delete the actual driver files from the server, + only the entry from the server's list of drivers. + + enumdata - Enumerate all printer setting data stored on the server. On Windows NT clients, these values are stored in the registry, while Samba servers diff --git a/docs/docbook/manpages/smb.conf.5.sgml b/docs/docbook/manpages/smb.conf.5.sgml index e5357d24f3b..70b4cc1c8ee 100644 --- a/docs/docbook/manpages/smb.conf.5.sgml +++ b/docs/docbook/manpages/smb.conf.5.sgml @@ -325,7 +325,7 @@ Many of the strings that are settable in the config file can take substitutions. For example the option "path = - /tmp/%U" would be interpreted as "path = + /tmp/%u" would be interpreted as "path = /tmp/john" if the user connected with the username john. These substitutions are mostly noted in the descriptions below, @@ -586,8 +586,9 @@ each parameter for details. Note that some are synonyms. + add printer command + add share command add user script - addprinter command allow trusted domains announce as announce version @@ -595,6 +596,7 @@ bind interfaces only browse list change notify timeout + change share command character set client code page code page directory @@ -608,15 +610,13 @@ debuglevel default default service + delete printer command + delete share command delete user script - deleteprinter command dfree command dns proxy domain admin group - domain admin users - domain groups domain guest group - domain guest users domain logons domain master encrypt passwords @@ -670,9 +670,11 @@ nt pipe support nt smb support null passwords + obey pam restrictions oplock break wait time os level os2 driver map + pam password change panic action passwd chat passwd chat debug @@ -881,6 +883,119 @@ + + + add printer command (G) + With the introduction of MS-RPC based printing + support for Windows NT/2000 clients in Samba 2.2, The MS Add + Printer Wizard (APW) icon is now also available in the + "Printers..." folder displayed a share listing. The APW + allows for printers to be add remotely to a Samba or Windows + NT/2000 print server. + + For a Samba host this means that the printer must be + physically added to underlying printing system. The add + printer command defines a script to be run which + will perform the necessary operations for adding the printer + to the print system and to add the appropriate service definition + to the smb.conf file in order that it can be + shared by smbd(8) + . + + The add printer command is + automatically invoked with the following parameter (in + order: + + + printer name + share name + port name + driver name + location + Windows 9x driver location + + + + All parameters are filled in from the PRINTER_INFO_2 structure sent + by the Windows NT/2000 client with one exception. The "Windows 9x + driver location" parameter is included for backwards compatibility + only. The remaining fields in the structure are generated from answers + to the APW questions. + + Once the add printer command has + been executed, smbd will reparse the + smb.conf to determine if the share defined by the APW + exists. If the sharename is still invalid, then smbd + will return an ACCESS_DENIED error to the client. + + See also + delete printer command, printing, + show add + printer wizard + + Default: none + Example: addprinter command = /usr/bin/addprinter + + + + + + + + add share command (G) + Samba 2.2.0 introduced the ability to dynamically + add and delete shares via the Windows NT 4.0 Server Manager. The + add share command is used to define an + external program or script which will add a new service definition + to smb.conf. In order to successfully + execute the add share command, smbd + requires that the administrator be connected using a root account (i.e. + uid == 0). + + + + When executed, smbd will automatically invoke the + add share command with four parameters. + + + + configFile - the location + of the global smb.conf file. + + + shareName - the name of the new + share. + + + pathName - path to an **existing** + directory on disk. + + + comment - comment string to associate + with the new share. + + + + + This parameter is only used for add file shares. To add printer shares, + see the add printer + command. + + + + See also change share + command, delete share + command. + + + Default: none + Example: add share command = /usr/local/bin/addshare + + + + + add user script (G) This is the full pathname to a script that will @@ -934,63 +1049,6 @@ - - addprinter command (G) - With the introduction of MS-RPC based printing - support for Windows NT/2000 clients in Samba 2.2, The MS Add - Printer Wizard (APW) icon is now also available in the - "Printers..." folder displayed a share listing. The APW - allows for printers to be add remotely to a Samba or Windows - NT/2000 print server. - - For a Samba host this means that the printer must be - physically added to underlying printing system. The - addprinter command defines a script to be run which - will perform the necessary operations for adding the printer - to the print system and to add the appropriate service definition - to the smb.conf file in order that it can be - shared by smbd(8) - . - - The addprinter command is - automatically invoked with the following parameter (in - order: - - - printer name - share name - port name - driver name - location - Windows 9x driver location - - - - All parameters are filled in from the PRINTER_INFO_2 structure sent - by the Windows NT/2000 client with one exception. The "Windows 9x - driver location" parameter is included for backwards compatibility - only. The remaining fields in the structure are generated from answers - to the APW questions. - - Once the addprinter command has - been executed, smbd will reparse the - smb.conf to determine if the share defined by the APW - exists. If the sharename is still invalid, then smbd - will return an ACCESS_DENIED error to the client. - - See also - deleteprinter command, printing, - show add - printer wizard - - Default: none - Example: addprinter command = /usr/bin/addprinter - - - - - admin users (S) This is a list of users who will be granted @@ -1264,7 +1322,60 @@ Would change the scan time to every 5 minutes. + + + + change share command (G) + Samba 2.2.0 introduced the ability to dynamically + add and delete shares via the Windows NT 4.0 Server Manager. The + change share command is used to define an + external program or script which will modify an existing service definition + in smb.conf. In order to successfully + execute the change share command, smbd + requires that the administrator be connected using a root account (i.e. + uid == 0). + + + When executed, smbd will automatically invoke the + change share command with four parameters. + + + + configFile - the location + of the global smb.conf file. + + + shareName - the name of the new + share. + + + pathName - path to an **existing** + directory on disk. + + + comment - comment string to associate + with the new share. + + + + + This parameter is only used modify existing file shares definitions. To modify + printer shares, use the "Printers..." folder as seen when browsing the Samba host. + + + + See also add share + command, delete + share command. + + + Default: none + Example: change share command = /usr/local/bin/addshare + + + + character set (G) @@ -1545,6 +1656,11 @@ mode bits on created directories. See also the inherit permissions parameter. + Note that this parameter does not apply to permissions + set by Windows NT/2000 ACL editors. If the administrator wishes to enforce + a mask on access control lists also, they need to set the security mask. + Default: create mask = 0744 Example: create mask = 0775 @@ -1648,15 +1764,9 @@ debuglevel (G) - The value of the parameter (an integer) allows - the debug level (logging level) to be specified in the - smb.conf file. This is to give greater - flexibility in the configuration of the system. - - The default will be the debug level specified on - the command line or level zero if none was specified. - - Example: debug level = 3 + Synonym for + log level. + @@ -1720,6 +1830,48 @@ + + delete printer command (G) + With the introduction of MS-RPC based printer + support for Windows NT/2000 clients in Samba 2.2, it is now + possible to delete printer at run time by issuing the + DeletePrinter() RPC call. + + For a Samba host this means that the printer must be + physically deleted from underlying printing system. The + deleteprinter command defines a script to be run which + will perform the necessary operations for removing the printer + from the print system and from smb.conf. + + + The delete printer command is + automatically called with only one parameter: + "printer name". + + + Once the delete printer command has + been executed, smbd will reparse the + smb.conf to associated printer no longer exists. + If the sharename is still valid, then smbd + will return an ACCESS_DENIED error to the client. + + See also + add printer command, printing, + show add + printer wizard + + Default: none + Example: deleteprinter command = /usr/bin/removeprinter + + + + + + + + + delete readonly (S) This parameter allows readonly files to be deleted. @@ -1733,6 +1885,53 @@ + + + delete share command (G) + Samba 2.2.0 introduced the ability to dynamically + add and delete shares via the Windows NT 4.0 Server Manager. The + delete share command is used to define an + external program or script which will remove an existing service + definition from smb.conf. In order to successfully + execute the delete share command, smbd + requires that the administrator be connected using a root account (i.e. + uid == 0). + + + + When executed, smbd will automatically invoke the + delete share command with two parameters. + + + + configFile - the location + of the global smb.conf file. + + + shareName - the name of + the existing service. + + + + + This parameter is only used to remove file shares. To delete printer shares, + see the delete printer + command. + + + + See also delete share + command, change + share. + + + Default: none + Example: delete share command = /usr/local/bin/delshare + + + + + @@ -1797,46 +1996,6 @@ - - deleteprinter command (G) - With the introduction of MS-RPC based printer - support for Windows NT/2000 clients in Samba 2.2, it is now - possible to delete printer at run time by issuing the - DeletePrinter() RPC call. - - For a Samba host this means that the printer must be - physically deleted from underlying printing system. The - deleteprinter command defines a script to be run which - will perform the necessary operations for removing the printer - from the print system and from smb.conf. - - - The deleteprinter command is - automatically called with only one parameter: - "printer name". - - - Once the deleteprinter command has - been executed, smbd will reparse the - smb.conf to associated printer no longer exists. - If the sharename is still valid, then smbd - will return an ACCESS_DENIED error to the client. - - See also - addprinter command, printing, - show add - printer wizard - - Default: none - Example: deleteprinter command = /usr/bin/removeprinter - - - - - - - delete veto files (S) @@ -1962,6 +2121,11 @@ parameter. This parameter is set to 000 by default (i.e. no extra mode bits are added). + Note that this parameter does not apply to permissions + set by Windows NT/2000 ACL editors. If the administrator wishes to enforce + a mask on access control lists also, they need to set the directory security mask. + See the force directory mode parameter to cause particular mode bits to always be set on created directories. @@ -2002,17 +2166,15 @@ mask may be treated as a set of bits the user is not allowed to change. - If not set explicitly this parameter is set to the same - value as the directory - mask parameter. To allow a user to - modify all the user/group/world permissions on a directory, set - this parameter to 0777. + If not set explicitly this parameter is set to 0777 + meaning a user is allowed to modify all the user/group/world + permissions on a directory. Note that users who can access the Samba server through other means can easily bypass this restriction, so it is primarily useful for standalone "appliance" systems. - Administrators of most normal systems will probably want to set - it to 0777. + Administrators of most normal systems will probably want to leave + it as the default of 0777. See also the force directory security mode, force security mode parameters. - Default: directory security mask = <same as - directory mask> - Example: directory security mask = 0777 + Default: directory security mask = 0777 + Example: directory security mask = 0700 @@ -2054,67 +2215,47 @@ domain admin group (G) - This is an EXPERIMENTAL parameter - that is part of the unfinished Samba NT Domain Controller Code. It may - be removed in a later release. To work with the latest code builds - that may have more support for Samba NT Domain Controller functionality - please subscribe to the mailing list samba-ntdom available by - visiting the web page at - http://lists.samba.org/. - - - - - domain admin users (G) - This is an EXPERIMENTAL parameter - that is part of the unfinished Samba NT Domain Controller Code. It may - be removed in a later release. To work with the latest code builds - that may have more support for Samba NT Domain Controller functionality - please subscribe to the mailing list samba-ntdom available by - visiting the web page at - http://lists.samba.org/. + This parameter is intended as a temporary solution + to enable users to be a member of the "Domain Admins" group when + a Samba host is acting as a PDC. A complete solution will be provided + by a system for mapping Windows NT/2000 groups onto UNIX groups. + Please note that this parameter has a somewhat confusing name. It + accepts a list of usernames and of group names in standard + smb.conf notation. + + + See also domain + guest group, domain + logons + + + Default: no domain administrators + Example: domain admin group = root @wheel + - - domain groups (G) - This is an EXPERIMENTAL parameter - that is part of the unfinished Samba NT Domain Controller Code. It may - be removed in a later release. To work with the latest code builds - that may have more support for Samba NT Domain Controller functionality - please subscribe to the mailing list samba-ntdom available by - visiting the web page at - http://lists.samba.org/. - - domain guest group (G) - This is an EXPERIMENTAL parameter - that is part of the unfinished Samba NT Domain Controller Code. It may - be removed in a later release. To work with the latest code builds - that may have more support for Samba NT Domain Controller functionality - please subscribe to the mailing list samba-ntdom available by - visiting the web page at - http://lists.samba.org/. - - - - - domain guest users (G) - This is an EXPERIMENTAL parameter - that is part of the unfinished Samba NT Domain Controller Code. It may - be removed in a later release. To work with the latest code builds - that may have more support for Samba NT Domain Controller functionality - please subscribe to the mailing list samba-ntdom available by - visiting the web page at - http://lists.samba.org/. + This parameter is intended as a temporary solution + to enable users to be a member of the "Domain Guests" group when + a Samba host is acting as a PDC. A complete solution will be provided + by a system for mapping Windows NT/2000 groups onto UNIX groups. + Please note that this parameter has a somewhat confusing name. It + accepts a list of usernames and of group names in standard + smb.conf notation. + + + See also domain + admin group, domain + logons + + + Default: no domain guests + Example: domain guest group = nobody @guest + @@ -2431,6 +2572,12 @@ mode after the mask set in the create mask parameter is applied. + Note that by default this parameter does not apply to permissions + set by Windows NT/2000 ACL editors. If the administrator wishes to enforce + this mask on access control lists also, they need to set the restrict acl with + mask to true. + See also the parameter create mask for details on masking mode bits on files. @@ -2459,6 +2606,12 @@ mask in the parameter directory mask is applied. + Note that by default this parameter does not apply to permissions + set by Windows NT/2000 ACL editors. If the administrator wishes to enforce + this mask on access control lists also, they need to set the restrict acl with + mask to true. + See also the parameter directory mask for details on masking mode bits on created directories. @@ -2490,17 +2643,15 @@ mask may be treated as a set of bits that, when modifying security on a directory, the user has always set to be 'on'. - If not set explicitly this parameter is set to the same - value as the force - directory mode parameter. To allow - a user to modify all the user/group/world permissions on a - directory without restrictions, set this parameter to 000. + If not set explicitly this parameter is 000, which + allows a user to modify all the user/group/world permissions on a + directory without restrictions. Note that users who can access the Samba server through other means can easily bypass this restriction, so it is primarily useful for standalone "appliance" systems. - Administrators of most normal systems will probably want to set - it to 0000. + Administrators of most normal systems will probably want to leave + it set as 0000. See also the directory security mask, @@ -2508,9 +2659,8 @@ force security mode parameters. - Default: force directory security mode = <same as - force directory mode> - Example: force directory security mode = 0 + Default: force directory security mode = 0 + Example: force directory security mode = 700 @@ -2568,17 +2718,15 @@ mask may be treated as a set of bits that, when modifying security on a file, the user has always set to be 'on'. - If not set explicitly this parameter is set to the same - value as the force - create mode parameter. To allow a user to - modify all the user/group/world permissions on a file, with no - restrictions set this parameter to 000. + If not set explicitly this parameter is set to 0, + and allows a user to modify all the user/group/world permissions on a file, + with no restrictions. Note that users who can access the Samba server through other means can easily bypass this restriction, so it is primarily useful for standalone "appliance" systems. - Administrators of most normal systems will probably want to set - it to 0000. + Administrators of most normal systems will probably want to leave + this set to 0000. See also the force directory security mode, @@ -2586,9 +2734,8 @@ mask, security mask parameters. - Default: force security mode = <same as force - create mode> - Example: force security mode = 0 + Default: force security mode = 0 + Example: force security mode = 700 @@ -3340,9 +3487,15 @@ log level (G) - Synonym for - debug level. - + The value of the parameter (an integer) allows + the debug level (logging level) to be specified in the + smb.conf file. This is to give greater + flexibility in the configuration of the system. + + The default will be the log level specified on + the command line or level zero if none was specified. + + Example: log level = 3 @@ -4580,6 +4733,28 @@ + + + obey pam restrictions (G) + When Samba 2.2 is configure to enable PAM support + (i.e. --with-pam), this parameter will control whether or not Samba + should obey PAM's account and session management directives. The + default behavior is to use PAM for clear text authentication only + and to ignore any account or session management. Note that Samba + always ignores PAM for authentication in the case of encrypt passwords = yes + . The reason is that PAM modules cannot support the challenge/response + authentication mechanism needed in the presence of SMB password encryption. + + + Default: obey pam restrictions = no + + + + + + + only user (S) This is a boolean option that controls whether @@ -4608,24 +4783,6 @@ - - - ole locking compatibility (G) - This parameter allows an administrator to turn - off the byte range lock manipulation that is done within Samba to - give compatibility for OLE applications. Windows OLE applications - use byte range locking as a form of inter-process communication, by - locking ranges of bytes around the 2^32 region of a file range. This - can cause certain UNIX lock managers to crash or otherwise cause - problems. Setting this parameter to no means you - trust your UNIX lock manager to handle such cases correctly. - - Default: ole locking compatibility = yes - - - - - only guest (S) A synonym for @@ -4755,6 +4912,21 @@ + + pam password change (G) + With the addition of better PAM support in Samba 2.2, + this parameter, it is possible to use PAM's password change control + flag for Samba. If enabled, then PAM will be used for password + changes when requested by an SMB client, and the passwd chat must be + be changed to work with the pam prompts. + + + Default: pam password change = no + + + + panic action (G) @@ -4810,10 +4982,21 @@ password cleartext. In this case the old password cleartext is set to "" (the empty string). + Also, if the pam + password change parameter is set to true, then the + chat sequence should consist of three elements. The first element should + match the pam prompt for the old password, the second element should match + the pam prompt for the first request for the new password, and the final + element should match the pam prompt for the second request for the new password. + These matches are done case insentively. Under most conditions this change + is done as root so the prompt for the old password will never be matched. + + See also unix password sync, - passwd program and - passwd chat debug. + passwd program , + passwd chat debug and + pam password change. Default: passwd chat = *new*password* %n\n *new*password* %n\n *changed* @@ -5798,6 +5981,35 @@ + + restrict acl with mask (S) + This is a boolean parameter. If set to false (default), then + Creation of files with access control lists (ACLS) and modification of ACLs + using the Windows NT/2000 ACL editor will be applied directly to the file + or directory. + + If set to True, then all requests to set an ACL on a file will have the + parameters create mask, + force create mode + applied before setting the ACL, and all requests to set an ACL on a directory will + have the parameters directory + mask, force + directory mode applied before setting the ACL. + + + See also create mask, + force create mode, + directory mask, + force directory mode + + + Default: restrict acl with mask = no + + + + + + restrict anonymous (G) This is a boolean parameter. If it is true, then @@ -6176,17 +6388,15 @@ mask may be treated as a set of bits the user is not allowed to change. - If not set explicitly this parameter is set to the same - value as the create mask - parameter. To allow a user to modify all the - user/group/world permissions on a file, set this parameter to - 0777. + If not set explicitly this parameter is 0777, allowing + a user to modify all the user/group/world permissions on a file. + Note that users who can access the Samba server through other means can easily bypass this restriction, so it is primarily useful for standalone "appliance" systems. Administrators of most normal systems will - probably want to set it to 0777. + probably want to leave it set to 0777. See also the force directory security mode, @@ -6194,9 +6404,8 @@ security mask, force security mode parameters. - Default: security mask = <same as create mask> - - Example: security mask = 0777 + Default: security mask = 0777 + Example: security mask = 0770 diff --git a/docs/docbook/manpages/smbcontrol.1.sgml b/docs/docbook/manpages/smbcontrol.1.sgml index 44418ea85fe..8e529d8b712 100644 --- a/docs/docbook/manpages/smbcontrol.1.sgml +++ b/docs/docbook/manpages/smbcontrol.1.sgml @@ -1,5 +1,5 @@ - + smbcontrol diff --git a/docs/docbook/manpages/smbspool.8.sgml b/docs/docbook/manpages/smbspool.8.sgml index b847aadd059..5b409bb9de9 100644 --- a/docs/docbook/manpages/smbspool.8.sgml +++ b/docs/docbook/manpages/smbspool.8.sgml @@ -1,5 +1,5 @@ - + smbspool @@ -8,7 +8,7 @@ - nmblookup + smbspool send print file to an SMB printer diff --git a/docs/docbook/manpages/smbstatus.1.sgml b/docs/docbook/manpages/smbstatus.1.sgml index 6f2361d0215..c2f638b88ef 100644 --- a/docs/docbook/manpages/smbstatus.1.sgml +++ b/docs/docbook/manpages/smbstatus.1.sgml @@ -1,5 +1,5 @@ - + smbstatus diff --git a/docs/docbook/projdoc/CVS-Access.sgml b/docs/docbook/projdoc/CVS-Access.sgml new file mode 100644 index 00000000000..aea146b66a1 --- /dev/null +++ b/docs/docbook/projdoc/CVS-Access.sgml @@ -0,0 +1,157 @@ + + + + + + + Samba Team + + + + + (22 May 2001) + + +HOWTO Access Samba source code via CVS + + +Introduction + + +Samba is developed in an open environnment. Developers use CVS +(Concurrent Versioning System) to "checkin" (also known as +"commit") new source code. Samba's various CVS branches can +be accessed via anonymouns CVS using the instructions +detailed in this chapter. + + + +This document is a modified version of the instructions found at +http://samba.org/samba/cvs.html + + + + + + +CVS Access to samba.org + + +The machine samba.org runs a publicly accessible CVS +repository for access to the source code of several packages, +including samba, rsync and jitterbug. There are two main ways of +accessing the CVS server on this host. + + + +Access via CVSweb + + +You can access the source code via your +favourite WWW browser. This allows you to access the contents of +individual files in the repository and also to look at the revision +history and commit logs of individual files. You can also ask for a diff +listing between any two versions on the repository. + + + +Use the URL : http://samba.org/cgi-bin/cvsweb + + + + +Access via cvs + + +You can also access the source code via a +normal cvs client. This gives you much more control over you can +do with the repository and allows you to checkout whole source trees +and keep them uptodate via normal cvs commands. This is the +preferred method of access if you are a developer and not +just a casual browser. + + + +To download the latest cvs source code, point your +browser at the URL : http://www.cyclic.com/. +and click on the 'How to get cvs' link. CVS is free software under +the GNU GPL (as is Samba). Note that there are several graphical CVS clients +which provide a graphical interface to the sometimes mundane CVS commands. +Links to theses clients are also available from http://www.cyclic.com. + + + +To gain access via anonymous cvs use the following steps. +For this example it is assumed that you want a copy of the +samba source code. For the other source code repositories +on this system just substitute the correct package name + + + + + + Install a recent copy of cvs. All you really need is a + copy of the cvs client binary. + + + + + + + Run the command + + + + cvs -d :pserver:cvs@samba.org:/cvsroot login + + + + When it asks you for a password type cvs. + + + + + + + Run the command + + + + cvs -d :pserver:cvs@samba.org:/cvsroot co samba + + + + This will create a directory called samba containing the + latest samba source code (i.e. the HEAD tagged cvs branch). This + currently corresponds to the 3.0 development tree. + + + + CVS branches other HEAD can be obtained by using the -r + and defining a tag name. A list of branch tag names can be found on the + "Development" page of the samba web site. A common request is to obtain the + latest 2.2 release code. This could be done by using the following command. + + + + cvs -d :pserver:cvs@samba.org:/cvsroot co -r SAMBA_2_2 samba + + + + + + Whenever you want to merge in the latest code changes use + the following command from within the samba directory: + + + + cvs update -d -P + + + + + + + + diff --git a/docs/docbook/projdoc/Samba-PDC-HOWTO.sgml b/docs/docbook/projdoc/Samba-PDC-HOWTO.sgml index 699ba54a09b..0b86bcba634 100644 --- a/docs/docbook/projdoc/Samba-PDC-HOWTO.sgml +++ b/docs/docbook/projdoc/Samba-PDC-HOWTO.sgml @@ -8,15 +8,44 @@ VA Linux Systems/Samba Team
jerry@samba.org
+ DavidBannon + + Samba Team +
dbannon@samba.org
+
+ - (15 Apr 2001) + (26 Apr 2001) -How to Configure Samba 2.2.x as a Primary Domain Controller +How to Configure Samba 2.2 as a Primary Domain Controller + + +Prerequisite Reading + + +Before you continue readingin this chapter, please make sure +that you are comfortable with configuring basic files services +in smb.conf and how to enable and administrate password +encryption in Samba. Theses two topics are covered in the +smb.conf(5) +manpage and the Encryption chapter +of this HOWTO Collection. + + + + + + + - - -DOMAIN_CONTROL.txt : Windows NT Domain Control & Samba - +Domain Control for Windows 9x/ME + -This appendix was originally authored by John H Terpstra of the Samba Team -and is included here for posterity. +The following section contains much of the original +DOMAIN.txt file previously included with Samba. Much of +the material is based on what went into the book Special +Edition, Using Samba. (Richard Sharpe) + + +A domain and a workgroup are exactly the same thing in terms of network +browsing. The difference is that a distributable authentication +database is associated with a domain, for secure login access to a +network. Also, different access rights can be granted to users if they +successfully authenticate against a domain logon server (NT server and +other systems based on NT server support this, as does at least Samba TNG now). + -NOTE : -The term "Domain Controller" and those related to it refer to one specific -method of authentication that can underly an SMB domain. Domain Controllers -prior to Windows NT Server 3.1 were sold by various companies and based on -private extensions to the LAN Manager 2.1 protocol. Windows NT introduced +The SMB client logging on to a domain has an expectation that every other +server in the domain should accept the same authentication information. +Network browsing functionality of domains and workgroups is +identical and is explained in BROWSING.txt. It should be noted, that browsing +is total orthogonal to logon support. + + + +Issues related to the single-logon network model are discussed in this +document. Samba supports domain logons, network logon scripts, and user +profiles for MS Windows for workgroups and MS Windows 9X clients. + + + + +When an SMB client in a domain wishes to logon it broadcast requests for a +logon server. The first one to reply gets the job, and validates its +password using whatever mechanism the Samba administrator has installed. +It is possible (but very stupid) to create a domain where the user +database is not shared between servers, ie they are effectively workgroup +servers advertising themselves as participating in a domain. This +demonstrates how authentication is quite different from but closely +involved with domains. + + + +Another thing commonly associated with single-logon domains is remote +administration over the SMB protocol. Again, there is no reason why this +cannot be implemented with an underlying username database which is +different from the Windows NT SAM. Support for the Remote Administration +Protocol is planned for a future release of Samba. + + + +Network logon support as discussed in this section is aimed at Window for +Workgroups, and Windows 9X clients. + + + +Support for profiles is confirmed as working for Win95, NT 4.0 and NT 3.51. +It is possible to specify: the profile location; script file to be loaded +on login; the user's home directory; and for NT a kick-off time could also +now easily be supported. However, there are some differences between Win9X +profile support and WinNT profile support. These are discussed below. + + + +With NT Workstations, all this does not require the use or intervention of +an NT 4.0 or NT 3.51 server: Samba can now replace the logon services +provided by an NT server, to a limited and experimental degree (for example, +running "User Manager for Domains" will not provide you with access to +a domain created by a Samba Server). + + + +With Win95, the help of an NT server can be enlisted, both for profile storage +and for user authentication. For details on user authentication, see +security_level.txt. For details on profile storage, see below. + + + +Using these features you can make your clients verify their logon via +the Samba server; make clients run a batch file when they logon to +the network and download their preferences, desktop and start menu. + + + +Before launching into the configuration instructions, it is worthwhile looking +at how a Win9X client performs a logon: + + + + + + The client broadcasts (to the IP broadcast address of the subnet it is in) + a NetLogon request. This is sent to the NetBIOS address DOMAIN<00> at the + NetBIOS layer. The client chooses the first response it receives, which + contains the NetBIOS name of the logon server to use in the format of + \\SERVER. + + + + + + The client then connects to that server, logs on (does an SMBsessetupX) and + then connects to the IPC$ share (using an SMBtconX). + + + + + + The client then does a NetWkstaUserLogon request, which retrieves the name + of the user's logon script. + + + + + + The client then connects to the NetLogon share and searches for this + and if it is found and can be read, is retrieved and executed by the client. + After this, the client disconnects from the NetLogon share. + + + + + + The client then sends a NetUserGetInfo request to the server, to retrieve + the user's home share, which is used to search for profiles. Since the + response to the NetUserGetInfo request does not contain much more + the user's home share, profiles for Win9X clients MUST reside in the user + home directory. + + + + + + The client then connects to the user's home share and searches for the + user's profile. As it turns out, you can specify the users home share as + a sharename and path. For example, \\server\fred\.profile. + If the profiles are found, they are implemented. + + + + + + The client then disconnects from the user's home share, and reconnects to + the NetLogon share and looks for CONFIG.POL, the policies file. If this is + found, it is read and implemented. + + + + + + +Configuration Instructions: Network Logons + + +To use domain logons and profiles you need to do the following: + + + + + + + Create a share called [netlogon] in your smb.conf. This share should + be readable by all users, and probably should not be writeable. This + share will hold your network logon scripts, and the CONFIG.POL file + (Note: for details on the CONFIG.POL file, how to use it, what it is, + refer to the Microsoft Windows NT Administration documentation. + The format of these files is not known, so you will need to use + Microsoft tools). + + + + For example I have used: + + + +[netlogon] + path = /data/dos/netlogon + writeable = no + guest ok = no + + + + Note that it is important that this share is not writeable by ordinary + users, in a secure environment: ordinary users should not be allowed + to modify or add files that another user's computer would then download + when they log in. + + + + + + + + in the [global] section of smb.conf set the following: + + + +domain logons = yes +logon script = %U.bat + + + + The choice of batch file is, of course, up to you. The above would + give each user a separate batch file as the %U will be changed to + their username automatically. The other standard % macros may also be + used. You can make the batch files come from a subdirectory by using + something like: + + + +logon script = scripts\%U.bat + + + + + + create the batch files to be run when the user logs in. If the batch + file doesn't exist then no batch file will be run. + + + + In the batch files you need to be careful to use DOS style cr/lf line + endings. If you don't then DOS may get confused. I suggest you use a + DOS editor to remotely edit the files if you don't know how to produce + DOS style files under unix. + + + + + + + Use smbclient with the -U option for some users to make sure that + the \\server\NETLOGON share is available, the batch files are + visible and they are readable by the users. + + + + + + you will probabaly find that your clients automatically mount the + \\SERVER\NETLOGON share as drive z: while logging in. You can put + some useful programs there to execute from the batch files. + + + + + +security mode and master browsers + + +There are a few comments to make in order to tie up some +loose ends. There has been much debate over the issue of whether +or not it is ok to configure Samba as a Domain Controller in security +modes other than USER. The only security mode +which will not work due to technical reasons is SHARE +mode security. DOMAIN and SERVER +mode security is really just a variation on SMB user level security. + + + +Actually, this issue is also closer tied to the debate on whether +or not Samba must be the domain master browser for its workgroup +when operating as a DC. While it may technically be possible +to configure a server as such (after all, browsing and domain logons +are two distinctly different functions), it is not a good idea to +so. You should remember that the DC must register the DOMAIN#1b netbios +name. This is the name used by Windows clients to locate the DC. +Windows clients do not distinguish between the DC and the DMB. +For this reason, it is very wise to configure the Samba DC as the DMB. + + + +Now back to the issue of configuring a Samba DC to use a mode other +than "security = user". If a Samba host is configured to use +another SMB server or DC in order to validate user connection +requests, then it is a fact that some other machine on the network +(the "password server") knows more about user than the Samba host. +99% of the time, this other host is a domain controller. Now +in order to operate in domain mode security, the "workgroup" parameter +must be set to the name of the Windows NT domain (which already +has a domain controller, right?) + + + +Therefore configuring a Samba box as a DC for a domain that +already by definition has a PDC is asking for trouble. +Therefore, you should always configure the Samba DC to be the DMB +for its domain. + + + + + + + +Configuration Instructions: Setting up Roaming User Profiles + + + +NOTE! Roaming profiles support is different +for Win9X and WinNT. + + + + +Before discussing how to configure roaming profiles, it is useful to see how +Win9X and WinNT clients implement these features. + + + +Win9X clients send a NetUserGetInfo request to the server to get the user's +profiles location. However, the response does not have room for a separate +profiles location field, only the users home share. This means that Win9X +profiles are restricted to being in the user's home directory. + + + + +WinNT clients send a NetSAMLogon RPC request, which contains many fields, +including a separate field for the location of the user's profiles. +This means that support for profiles is different for Win9X and WinNT. + + + + + +Windows NT Configuration + + +To support WinNT clients, inn the [global] section of smb.conf set the +following (for example): + + + +logon path = \\profileserver\profileshare\profilepath\%U\moreprofilepath + + + +The default for this option is \\%N\%U\profile, namely +\\sambaserver\username\profile. The \\N%\%U service is created +automatically by the [homes] service. +If you are using a samba server for the profiles, you _must_ make the +share specified in the logon path browseable. + + + + +[lkcl 26aug96 - we have discovered a problem where Windows clients can +maintain a connection to the [homes] share in between logins. The +[homes] share must NOT therefore be used in a profile path.] + + + + + + + +Windows 9X Configuration + + +To support Win9X clients, you must use the "logon home" parameter. Samba has +now been fixed so that "net use/home" now works as well, and it, too, relies +on the "logon home" parameter. + + + +By using the logon home parameter, you are restricted to putting Win9X +profiles in the user's home directory. But wait! There is a trick you +can use. If you set the following in the [global] section of your +smb.conf file: + + + +logon home = \\%L\%U\.profiles + + + +then your Win9X clients will dutifully put their clients in a subdirectory +of your home directory called .profiles (thus making them hidden). + + + +Not only that, but 'net use/home' will also work, because of a feature in +Win9X. It removes any directory stuff off the end of the home directory area +and only uses the server and share portion. That is, it looks like you +specified \\%L\%U for "logon home". + + + + + + + +Win9X and WinNT Configuration + + +You can support profiles for both Win9X and WinNT clients by setting both the +"logon home" and "logon path" parameters. For example: + + + +logon home = \\%L\%U\.profiles +logon path = \\%L\profiles\%U + + + + +I have not checked what 'net use /home' does on NT when "logon home" is +set as above. + + + + + + + +Windows 9X Profile Setup + + +When a user first logs in on Windows 9X, the file user.DAT is created, +as are folders "Start Menu", "Desktop", "Programs" and "Nethood". +These directories and their contents will be merged with the local +versions stored in c:\windows\profiles\username on subsequent logins, +taking the most recent from each. You will need to use the [global] +options "preserve case = yes", "short case preserve = yes" and +"case sensitive = no" in order to maintain capital letters in shortcuts +in any of the profile folders. + + + + +The user.DAT file contains all the user's preferences. If you wish to +enforce a set of preferences, rename their user.DAT file to user.MAN, +and deny them write access to this file. + + + + + + On the Windows 95 machine, go to Control Panel | Passwords and + select the User Profiles tab. Select the required level of + roaming preferences. Press OK, but do _not_ allow the computer + to reboot. + + + + + + + On the Windows 95 machine, go to Control Panel | Network | + Client for Microsoft Networks | Preferences. Select 'Log on to + NT Domain'. Then, ensure that the Primary Logon is 'Client for + Microsoft Networks'. Press OK, and this time allow the computer + to reboot. + + + + + + +Under Windows 95, Profiles are downloaded from the Primary Logon. +If you have the Primary Logon as 'Client for Novell Networks', then +the profiles and logon script will be downloaded from your Novell +Server. If you have the Primary Logon as 'Windows Logon', then the +profiles will be loaded from the local machine - a bit against the +concept of roaming profiles, if you ask me. + + + +You will now find that the Microsoft Networks Login box contains +[user, password, domain] instead of just [user, password]. Type in +the samba server's domain name (or any other domain known to exist, +but bear in mind that the user will be authenticated against this +domain and profiles downloaded from it, if that domain logon server +supports it), user name and user's password. + + + +Once the user has been successfully validated, the Windows 95 machine +will inform you that 'The user has not logged on before' and asks you +if you wish to save the user's preferences? Select 'yes'. + + + +Once the Windows 95 client comes up with the desktop, you should be able +to examine the contents of the directory specified in the "logon path" +on the samba server and verify that the "Desktop", "Start Menu", +"Programs" and "Nethood" folders have been created. + + + +These folders will be cached locally on the client, and updated when +the user logs off (if you haven't made them read-only by then :-). +You will find that if the user creates further folders or short-cuts, +that the client will merge the profile contents downloaded with the +contents of the profile directory already on the local client, taking +the newest folders and short-cuts from each set. + + + +If you have made the folders / files read-only on the samba server, +then you will get errors from the w95 machine on logon and logout, as +it attempts to merge the local and the remote profile. Basically, if +you have any errors reported by the w95 machine, check the unix file +permissions and ownership rights on the profile directory contents, +on the samba server. + + + +If you have problems creating user profiles, you can reset the user's +local desktop cache, as shown below. When this user then next logs in, +they will be told that they are logging in "for the first time". + + + + + + instead of logging in under the [user, password, domain] dialog, + press escape. + + + + + + run the regedit.exe program, and look in: + + + + HKEY_LOCAL_MACHINE\Windows\CurrentVersion\ProfileList + + + + you will find an entry, for each user, of ProfilePath. Note the + contents of this key (likely to be c:\windows\profiles\username), + then delete the key ProfilePath for the required user. + + + + [Exit the registry editor]. + + + + + + WARNING - before deleting the contents of the + directory listed in + the ProfilePath (this is likely to be c:\windows\profiles\username), + ask them if they have any important files stored on their desktop + or in their start menu. delete the contents of the directory + ProfilePath (making a backup if any of the files are needed). + + + + This will have the effect of removing the local (read-only hidden + system file) user.DAT in their profile directory, as well as the + local "desktop", "nethood", "start menu" and "programs" folders. + + + + + + search for the user's .PWL password-cacheing file in the c:\windows + directory, and delete it. + + + + + + + log off the windows 95 client. + + + + + + check the contents of the profile path (see "logon path" described + above), and delete the user.DAT or user.MAN file for the user, + making a backup if required. + + + + + + +If all else fails, increase samba's debug log levels to between 3 and 10, +and / or run a packet trace program such as tcpdump or netmon.exe, and +look for any error reports. + + + +If you have access to an NT server, then first set up roaming profiles +and / or netlogons on the NT server. Make a packet trace, or examine +the example packet traces provided with NT server, and see what the +differences are with the equivalent samba trace. + + + + + + +Windows NT Workstation 4.0 + + +When a user first logs in to a Windows NT Workstation, the profile +NTuser.DAT is created. The profile location can be now specified +through the "logon path" parameter. + + + + +[lkcl 10aug97 - i tried setting the path to +\\samba-server\homes\profile, and discovered that this fails because +a background process maintains the connection to the [homes] share +which does _not_ close down in between user logins. you have to +have \\samba-server\%L\profile, where user is the username created +from the [homes] share]. + + + + +There is a parameter that is now available for use with NT Profiles: +"logon drive". This should be set to "h:" or any other drive, and +should be used in conjunction with the new "logon home" parameter. + + + +The entry for the NT 4.0 profile is a _directory_ not a file. The NT +help on profiles mentions that a directory is also created with a .PDS +extension. The user, while logging in, must have write permission to +create the full profile path (and the folder with the .PDS extension) +[lkcl 10aug97 - i found that the creation of the .PDS directory failed, +and had to create these manually for each user, with a shell script. +also, i presume, but have not tested, that the full profile path must +be browseable just as it is for w95, due to the manner in which they +attempt to create the full profile path: test existence of each path +component; create path component]. + + + +In the profile directory, NT creates more folders than 95. It creates +"Application Data" and others, as well as "Desktop", "Nethood", +"Start Menu" and "Programs". The profile itself is stored in a file +NTuser.DAT. Nothing appears to be stored in the .PDS directory, and +its purpose is currently unknown. + + + +You can use the System Control Panel to copy a local profile onto +a samba server (see NT Help on profiles: it is also capable of firing +up the correct location in the System Control Panel for you). The +NT Help file also mentions that renaming NTuser.DAT to NTuser.MAN +turns a profile into a mandatory one. + + + + +[lkcl 10aug97 - i notice that NT Workstation tells me that it is +downloading a profile from a slow link. whether this is actually the +case, or whether there is some configuration issue, as yet unknown, +that makes NT Workstation _think_ that the link is a slow one is a +matter to be resolved]. + + + +[lkcl 20aug97 - after samba digest correspondance, one user found, and +another confirmed, that profiles cannot be loaded from a samba server +unless "security = user" and "encrypt passwords = yes" (see the file +ENCRYPTION.txt) or "security = server" and "password server = ip.address. +of.yourNTserver" are used. either of these options will allow the NT +workstation to access the samba server using LAN manager encrypted +passwords, without the user intervention normally required by NT +workstation for clear-text passwords]. + + + +[lkcl 25aug97 - more comments received about NT profiles: the case of +the profile _matters_. the file _must_ be called NTuser.DAT or, for +a mandatory profile, NTuser.MAN]. + + + + + + + +Windows NT Server + + +There is nothing to stop you specifying any path that you like for the +location of users' profiles. Therefore, you could specify that the +profile be stored on a samba server, or any other SMB server, as long as +that SMB server supports encrypted passwords. + + + + + + +Sharing Profiles between W95 and NT Workstation 4.0 + + +Potentially outdated or incorrect material follows + +I think this is all bogus, but have not deleted it. (Richard Sharpe) + + + + +The default logon path is \\%N\U%. NT Workstation will attempt to create +a directory "\\samba-server\username.PDS" if you specify the logon path +as "\\samba-server\username" with the NT User Manager. Therefore, you +will need to specify (for example) "\\samba-server\username\profile". +NT 4.0 will attempt to create "\\samba-server\username\profile.PDS", which +is more likely to succeed. + + + +If you then want to share the same Start Menu / Desktop with W95, you will +need to specify "logon path = \\samba-server\username\profile" [lkcl 10aug97 +this has its drawbacks: i created a shortcut to telnet.exe, which attempts +to run from the c:\winnt\system32 directory. this directory is obviously +unlikely to exist on a Win95-only host]. + + + + +If you have this set up correctly, you will find separate user.DAT and +NTuser.DAT files in the same profile directory. + + + + +[lkcl 25aug97 - there are some issues to resolve with downloading of +NT profiles, probably to do with time/date stamps. i have found that +NTuser.DAT is never updated on the workstation after the first time that +it is copied to the local workstation profile directory. this is in +contrast to w95, where it _does_ transfer / update profiles correctly]. + + + + + + + + + + + + + +DOMAIN_CONTROL.txt : Windows NT Domain Control & Samba + + + + Possibly Outdated Material + + + This appendix was originally authored by John H Terpstra of + the Samba Team and is included here for posterity. + + + + + +NOTE : +The term "Domain Controller" and those related to it refer to one specific +method of authentication that can underly an SMB domain. Domain Controllers +prior to Windows NT Server 3.1 were sold by various companies and based on +private extensions to the LAN Manager 2.1 protocol. Windows NT introduced Microsoft-specific ways of distributing the user authentication database. See DOMAIN.txt for examples of how Samba can participate in or create SMB domains based on shared authentication database schemes other than the @@ -858,13 +1773,8 @@ Windows NT SAM. Windows NT Server can be installed as either a plain file and print server (WORKGROUP workstation or server) or as a server that participates in Domain Control (DOMAIN member, Primary Domain controller or Backup Domain controller). - - - The same is true for OS/2 Warp Server, Digital Pathworks and other similar products, all of which can participate in Domain Control along with Windows NT. -However only those servers which have licensed Windows NT code in them can be -a primary Domain Controller (eg Windows NT Server, Advanced Server for Unix.) diff --git a/docs/docbook/projdoc/printer_driver2.sgml b/docs/docbook/projdoc/printer_driver2.sgml index 7f0aebc45f8..51471ae6900 100644 --- a/docs/docbook/projdoc/printer_driver2.sgml +++ b/docs/docbook/projdoc/printer_driver2.sgml @@ -13,7 +13,7 @@ - (20 Apr 2001) + (3 May 2001) Printing Support in Samba 2.2.x @@ -55,17 +55,42 @@ SPOOLSS support includes: information
+ +There has been some initial confusion about what all this means +and whether or not it is a requirement for printer drivers to be +installed on a Samba host in order to support printing from Windows +clients. A bug existed in Samba 2.2.0 which made Windows NT/2000 clients +require that the Samba server possess a valid driver for the printer. +This is fixed in Samba 2.2.1 and once again, Windows NT/2000 clients +can use the local APW for installing drivers to be used with a Samba +served printer. This is the same behavior exhibited by Windows 9x clients. +As a side note, Samba does not use these drivers in any way to process +spooled files. They are utilized entirely by the clients. + + + +The following MS KB article, may be of some help if you are dealing with +Windows 2000 clients: How to Add Printers with No User +Interaction in Windows 2000 + + + +http://support.microsoft.com/support/kb/articles/Q189/1/05.ASP + + Configuration + +[print$] vs. [printer$] + -WARNING!!! Previous versions of Samba -recommended using a share named [printer$]. This name was taken from the -printer$ service created by Windows 9x clients when a -printer was shared. Windows 9x printer servers always have +Previous versions of Samba recommended using a share named [printer$]. +This name was taken from the printer$ service created by Windows 9x +clients when a printer was shared. Windows 9x printer servers always have a printer$ service which provides read-only access via no password in order to support printer driver downloads. @@ -81,13 +106,13 @@ the client. -These parameters, including printer driver +These parameters, including printer driver file parameter, are being depreciated and should not be used in new installations. For more information on this change, -you should refer to the Migration section -of this document. +you should refer to the Migration section +of this document. - + Creating [print$] @@ -112,18 +137,22 @@ appropriate values for your site): guest ok = yes browseable = yes read only = yes + ; since this share is configured as read only, then we need + ; a 'write list'. Check the file system permissions to make + ; sure this account can copy files to the share. If this + ; is setup to a non-root account, then it should also exist + ; as a 'printer admin' write list = ntadmin The write list is used to allow administrative level user accounts to have write access in order to update files -on the share. See the -smb.conf(5) man page for more information on -configuring file shares. +on the share. See the smb.conf(5) +man page for more information on configuring file shares. -The requirement for -guest ok = yes depends upon how your +The requirement for guest +ok = yes depends upon how your site is configured. If users will be guaranteed to have an account on the Samba host, then this is a non-issue. @@ -165,27 +194,33 @@ for each architecture you wish to support. - ATTENTION! REQUIRED PERMISSIONS +ATTENTION! REQUIRED PERMISSIONS - In order to currently add a new driver to you Samba host, - one of two conditions must hold true: + +In order to currently add a new driver to you Samba host, +one of two conditions must hold true: + - - The account used to connect to the Samba host - must have a uid of 0 (i.e. a root account) + + The account used to connect to the Samba host + must have a uid of 0 (i.e. a root account) - The account used to connect to the Samba host - must be a member of the printer - admin list. - - - Of course, the connected account must still possess access - to add files to the subdirectories beneath [print$]. + The account used to connect to the Samba host + must be a member of the printer + admin list. + + + +Of course, the connected account must still possess access +to add files to the subdirectories beneath [print$]. Remember +that all file shares are set to 'read only' by default. + -Once you have created the required [print$] service and + +Once you have created the required [print$] service and associated subdirectories, simply log onto the Samba server using a root (or printer admin) account from a Windows NT 4.0 client. Navigate to the "Printers" folder @@ -198,9 +233,27 @@ that matches the printer shares defined on your Samba host. Setting Drivers for Existing Printers The initial listing of printers in the Samba host's -Printers folder will have no printer driver assigned to them. -The way assign a driver to a printer is to view the Properties -of the printer and either +Printers folder will have no real printer driver assigned +to them. By default, in Samba 2.2.0 this driver name was set to +NO PRINTER DRIVER AVAILABLE FOR THIS PRINTER. +Later versions changed this to a NULL string to allow the use +tof the local Add Printer Wizard on NT/2000 clients. +Attempting to view the printer properties for a printer +which has this default driver assigned will result in +the error message: + + +Device settings cannot be displayed. The driver +for the specified printer is not installed, only spooler +properties will be displayed. Do you want to install the +driver now? + + + +Click "No" in the error dialog and you will be presented with +the printer properties window. The way assign a driver to a +printer is to either + Use the "New Driver..." button to install @@ -271,7 +324,7 @@ Domain=[NARNIA] OS=[Unix] Server=[Samba 2.2.0-alpha3] description:[POGO\\POGO\hp-print,NO DRIVER AVAILABLE FOR THIS PRINTER,] comment:[] -$ rpcclient pogo -U root%bleaK.er \ +$ rpcclient pogo -U root%secret \ > -c "setdriver hp-print \"HP LaserJet 4000 Series PS\"" Domain=[NARNIA] OS=[Unix] Server=[Samba 2.2.0-alpha3] Successfully set hp-print to driver HP LaserJet 4000 Series PS. @@ -292,7 +345,7 @@ Add Printer Wizard icon. The APW will be show only if The connected user is able to successfully execute an OpenPrinterEx(\\server) with administrative - priviledges (i.e. root or printer admin. + priviledges (i.e. root or printer admin). show @@ -302,8 +355,8 @@ Add Printer Wizard icon. The APW will be show only if In order to be able to use the APW to successfully add a printer to a Samba -server, the addprinter -command must have a defined value. The program +server, the add +printer command must have a defined value. The program hook must successfully add the printer to the system (i.e. /etc/printcap or appropriate files) and smb.conf if necessary. @@ -312,16 +365,16 @@ hook must successfully add the printer to the system (i.e. When using the APW from a client, if the named printer share does not exist, smbd will execute the add printer -program and reparse to the smb.conf +command and reparse to the smb.conf to attempt to locate the new printer share. If the share is still not defined, an error of "Access Denied" is returned to the client. Note that the -add printer program is executed undet the context +add printer program is executed under the context of the connected user, not necessarily a root account. -There is a complementing deleteprinter -command for removing entries from the "Printers..." +There is a complementing delete +printer command for removing entries from the "Printers..." folder. @@ -473,7 +526,7 @@ foreach (supported architecture for a given driver) will reveal that Windows NT always uses the NT driver - name. The is ok as Windows NT always requires that at least + name. This is ok as Windows NT always requires that at least the Windows NT version of the printer driver is present. However, Samba does not have the requirement internally. Therefore, how can you use the NT driver name if is has not @@ -489,67 +542,167 @@ foreach (supported architecture for a given driver) - <anchor id="MIGRATION">Migration to from Samba 2.0.x to - 2.2.x - - Given that printer driver management has changed - (we hope improved :) ) in 2.2.0 over prior releases, - migration from an existing setup to 2.2.0 can follow - several paths. +<anchor id="MIGRATION">Migration to from Samba 2.0.x to 2.2.x + + +Given that printer driver management has changed (we hope improved) in +2.2 over prior releases, migration from an existing setup to 2.2 can +follow several paths. + + + +Windows clients have a tendency to remember things for quite a while. +For example, if a Windows NT client has attached to a Samba 2.0 server, +it will remember the server as a LanMan printer server. Upgrading +the Samba host to 2.2 makes support for MSRPC printing possible, but +the NT client will still remember the previous setting. + + + +In order to give an NT client printing "amesia" (only necessary if you +want to use the newer MSRPC printing functionality in Samba), delete +the registry keys associated with the print server contained in +[HKLM\SYSTEM\CurrentControlSet\Control\Print]. The +spooler service on the client should be stopped prior to doing this: + + + +C:\WINNT\ > net stop spooler + + + +All the normal disclaimers about editing the registry go +here. Be careful, and know what you are doing. + + + +The spooler service should be restarted after you have finished +removing the appropriate registry entries by replacing the +stop command above with start. + + + +Windows 9x clients will continue to use LanMan printing calls +with a 2.2 Samba server so there is no need to perform any of these +modifications on non-NT clients. + - - Achtung! - The following smb.conf parameters are considered to be - depreciated and will be removed soon. Do not use them - in new installations + +Achtung! + + +The following smb.conf parameters are considered to be depreciated and will +be removed soon. Do not use them in new installations + - - printer driver file (G) - + + printer driver file (G) + - printer driver (S) - + printer driver (S) + - printer driver location (S) - - - + printer driver location (S) + + + - Here are the possible scenarios for supporting migration: + +Here are the possible scenarios for supporting migration: + - - If you do not desire the new Windows NT - print driver support, nothing needs to be done. - All existing parameters work the same. - - If you want to take advantage of NT printer - driver support but do not want to migrate the - 9x drivers to the new setup, the leave the existing - printers.def file. When smbd attempts to locate a - 9x driver for the printer in the TDB and fails it - will drop down to using the printers.def (and all - associated parameters). The make_printerdef - tool will also remain for backwards compatibility but will - be moved to the "this tool is the old way of doing it" - pile. - - If you install a Windows 9x driver for a printer - on your Samba host (in the printing TDB), this information will - take precedence and the three old printing parameters - will be ignored (including print driver location). - - If you want to migrate an existing printers.def - file into the new setup, the current only - solution is to use the Windows NT APW to install the NT drivers - and the 9x drivers. This can be scripted using smbclient - and rpcclient. See the - Imprints installation client at http://imprints.sourceforge.net/ - for an example. - - + + If you do not desire the new Windows NT + print driver support, nothing needs to be done. + All existing parameters work the same. + + If you want to take advantage of NT printer + driver support but do not want to migrate the + 9x drivers to the new setup, the leave the existing + printers.def file. When smbd attempts to locate a + 9x driver for the printer in the TDB and fails it + will drop down to using the printers.def (and all + associated parameters). The make_printerdef + tool will also remain for backwards compatibility but will + be moved to the "this tool is the old way of doing it" + pile. + + If you install a Windows 9x driver for a printer + on your Samba host (in the printing TDB), this information will + take precedence and the three old printing parameters + will be ignored (including print driver location). + + If you want to migrate an existing printers.def + file into the new setup, the current only solution is to use the Windows + NT APW to install the NT drivers and the 9x drivers. This can be scripted + using smbclient and rpcclient. See the + Imprints installation client at http://imprints.sourceforge.net/ + for an example. + + + + + diff --git a/docs/docbook/projdoc/samba-doc.sgml b/docs/docbook/projdoc/samba-doc.sgml index b055477db74..fa58399bf1e 100644 --- a/docs/docbook/projdoc/samba-doc.sgml +++ b/docs/docbook/projdoc/samba-doc.sgml @@ -8,6 +8,7 @@ + ]> @@ -26,10 +27,10 @@ Abstract -This book is a collection of HOWTOs added to Samba documentation over the year. +This book is a collection of HOWTOs added to Samba documentation over the years. I try to ensure that all are current, but sometimes the is a larger job -than one person can maintain. You can always find the later version of this -PDF file at http://www.samba.org/ +than one person can maintain. The most recent version of this document +can be found at http://www.samba.org/ on the "Documentation" page. Please send updates to jerry@samba.org. @@ -49,5 +50,6 @@ Cheers, jerry &WINBIND; &NT-Security; &OS2-Client; +&CVS-Access; diff --git a/docs/htmldocs/CVS-Access.html b/docs/htmldocs/CVS-Access.html new file mode 100644 index 00000000000..ea47cede040 --- /dev/null +++ b/docs/htmldocs/CVS-Access.html @@ -0,0 +1,193 @@ +HOWTO Access Samba source code via CVS

Introduction

Samba is developed in an open environnment. Developers use CVS +(Concurrent Versioning System) to "checkin" (also known as +"commit") new source code. Samba's various CVS branches can +be accessed via anonymouns CVS using the instructions +detailed in this chapter.

This document is a modified version of the instructions found at +http://samba.org/samba/cvs.html


CVS Access to samba.org

The machine samba.org runs a publicly accessible CVS +repository for access to the source code of several packages, +including samba, rsync and jitterbug. There are two main ways of +accessing the CVS server on this host.


Access via CVSweb

You can access the source code via your +favourite WWW browser. This allows you to access the contents of +individual files in the repository and also to look at the revision +history and commit logs of individual files. You can also ask for a diff +listing between any two versions on the repository.

Use the URL : http://samba.org/cgi-bin/cvsweb


Access via cvs

You can also access the source code via a +normal cvs client. This gives you much more control over you can +do with the repository and allows you to checkout whole source trees +and keep them uptodate via normal cvs commands. This is the +preferred method of access if you are a developer and not +just a casual browser.

To download the latest cvs source code, point your +browser at the URL : http://www.cyclic.com/. +and click on the 'How to get cvs' link. CVS is free software under +the GNU GPL (as is Samba). Note that there are several graphical CVS clients +which provide a graphical interface to the sometimes mundane CVS commands. +Links to theses clients are also available from http://www.cyclic.com.

To gain access via anonymous cvs use the following steps. +For this example it is assumed that you want a copy of the +samba source code. For the other source code repositories +on this system just substitute the correct package name

  1. Install a recent copy of cvs. All you really need is a + copy of the cvs client binary. +

  2. Run the command +

    cvs -d :pserver:cvs@samba.org:/cvsroot login +

    When it asks you for a password type cvs. +

  3. Run the command +

    cvs -d :pserver:cvs@samba.org:/cvsroot co samba +

    This will create a directory called samba containing the + latest samba source code (i.e. the HEAD tagged cvs branch). This + currently corresponds to the 3.0 development tree. +

    CVS branches other HEAD can be obtained by using the -r + and defining a tag name. A list of branch tag names can be found on the + "Development" page of the samba web site. A common request is to obtain the + latest 2.2 release code. This could be done by using the following command. +

    cvs -d :pserver:cvs@samba.org:/cvsroot co -r SAMBA_2_2 samba +

  4. Whenever you want to merge in the latest code changes use + the following command from within the samba directory: +

    cvs update -d -P +

\ No newline at end of file diff --git a/docs/htmldocs/Samba-HOWTO-Collection.html b/docs/htmldocs/Samba-HOWTO-Collection.html index 85ef2feb705..acfb1a7a3c1 100644 --- a/docs/htmldocs/Samba-HOWTO-Collection.html +++ b/docs/htmldocs/Samba-HOWTO-Collection.html @@ -38,10 +38,10 @@ NAME="AEN9" >Abstract

This book is a collection of HOWTOs added to Samba documentation over the year. +>This book is a collection of HOWTOs added to Samba documentation over the years. I try to ensure that all are current, but sometimes the is a larger job -than one person can maintain. You can always find the later version of this -PDF file at http://www.samba.org/

4.2. Configuration
4.2.1. Creating [print$]
4.2.2. Setting Drivers for Existing Printers
4.2.3. Support a large number of printers
4.2.4. Adding New Printers via the Windows NT APW
4.2.5. Samba and Printer Ports
4.3. The Imprints Toolset
4.3.1. What is Imprints?
4.3.2. Creating Printer Driver Packages
4.3.3. The Imprints server
4.3.4. The Installation Client
4.4. Migration to from Samba 2.0.x to - 2.2.xMigration to from Samba 2.0.x to 2.2.x
5. security = domain in Samba 2.x
5.1. Joining an NT Domain with Samba 2.2
5.2. Samba and Windows 2000 Domains
5.3. Why is this better than security = server?
6. How to Configure Samba 2.2.x as a Primary Domain ControllerHow to Configure Samba 2.2 as a Primary Domain Controller
6.1. BackgroundPrerequisite Reading
6.2. Configuring the Samba Domain ControllerBackground
6.3. Configuring the Samba Domain Controller
6.4. Creating Machine Trust Accounts and Joining Clients to the Domain
6.4. Common Problems and Errors6.4.1. Manually creating machine trust accounts
6.4.2. Creating machine trust accounts "on the fly"
6.5. System Policies and ProfilesCommon Problems and Errors
6.6. System Policies and Profiles
6.7. What other help can I get ?
6.8. Domain Control for Windows 9x/ME
6.8.1. Configuration Instructions: Network Logons
6.8.2. Configuration Instructions: Setting up Roaming User Profiles
6.6.1. URLs and similar6.8.2.1. Windows NT Configuration
6.8.2.2. Windows 9X Configuration
6.8.2.3. Win9X and WinNT Configuration
6.8.2.4. Windows 9X Profile Setup
6.8.2.5. Windows NT Workstation 4.0
6.8.2.6. Windows NT Server
6.6.2. Mailing Lists6.8.2.7. Sharing Profiles between W95 and NT Workstation 4.0
6.7. 6.9. DOMAIN_CONTROL.txt : Windows NT Domain Control & Samba
7. Unifed Logons between Windows NT and UNIX using Winbind
7.1. Abstract
7.2. Introduction
7.3. What Winbind Provides
7.3.1. Target Uses
7.4. How Winbind Works
7.4.1. Microsoft Remote Procedure Calls
7.4.2. Name Service Switch
7.4.3. Pluggable Authentication Modules
7.4.4. User and Group ID Allocation
7.4.5. Result Caching
7.5. Installation and Configuration
7.6. Limitations
7.7. Conclusion
8. UNIX Permission Bits and WIndows NT Access Control Lists
8.1. Viewing and changing UNIX permissions using the NT security dialogs
8.2. How to view file security on a Samba share
8.3. Viewing file ownership
8.4. Viewing file or directory permissions
8.4.1. File Permissions
8.4.2. Directory Permissions
8.5. Modifying file or directory permissions
8.6. Interaction with the standard Samba create mask parameters
8.7. Interaction with the standard Samba file attribute mapping
9. OS2 Client HOWTO
9.1. FAQs
9.1.1. How can I configure OS/2 Warp Connect or OS/2 Warp 4 as a client for Samba?
9.1.2. How can I configure OS/2 Warp 3 (not Connect), OS/2 1.2, 1.3 or 2.x for Samba?
9.1.3. Are there any other issues when OS/2 (any version) is used as a client?
9.1.4. How do I get printer driver download working for OS/2 clients?
10. HOWTO Access Samba source code via CVS
10.1. Introduction
10.2. CVS Access to samba.org
10.2.1. Access via CVSweb
10.2.2. Access via cvs

There has been some initial confusion about what all this means +and whether or not it is a requirement for printer drivers to be +installed on a Samba host in order to support printing from Windows +clients. A bug existed in Samba 2.2.0 which made Windows NT/2000 clients +require that the Samba server possess a valid driver for the printer. +This is fixed in Samba 2.2.1 and once again, Windows NT/2000 clients +can use the local APW for installing drivers to be used with a Samba +served printer. This is the same behavior exhibited by Windows 9x clients. +As a side note, Samba does not use these drivers in any way to process +spooled files. They are utilized entirely by the clients.

The following MS KB article, may be of some help if you are dealing with +Windows 2000 clients: How to Add Printers with No User +Interaction in Windows 2000

http://support.microsoft.com/support/kb/articles/Q189/1/05.ASP


4.2. Configuration

WARNING!!! Previous versions of Samba -recommended using a share named [printer$]. This name was taken from the -printer$ service created by Windows 9x clients when a -printer was shared. Windows 9x printer servers always have +>

[print$] vs. [printer$]

Previous versions of Samba recommended using a share named [printer$]. +This name was taken from the printer$ service created by Windows 9x +clients when a printer was shared. Windows 9x printer servers always have a printer$ service which provides read-only access via no password in order to support printer driver downloads.

These parameters, including printer driver +>printer driver file parameter, are being depreciated and should not be used in new installations. For more information on this change, you should refer to the Migration section of this document.

Migration section +of this document.


4.2.1. Creating [print$]

smb.conf(5) man page for more information on -configuring file shares.

smb.conf(5) +man page for more information on configuring file shares.

The requirement for guest ok = yesguest +ok = yes depends upon how your site is configured. If users will be guaranteed to have @@ -2538,26 +2682,26 @@ ALIGN="CENTER" ALIGN="LEFT" >

In order to currently add a new driver to you Samba host, - one of two conditions must hold true:

  • The account used to connect to the Samba host - must have a uid of 0 (i.e. a root account)

  • The account used to connect to the Samba host - must be a member of the printer - admin list.

Of course, the connected account must still possess access - to add files to the subdirectories beneath [print$].


4.2.2. Setting Drivers for Existing Printers

The initial listing of printers in the Samba host's -Printers folder will have no printer driver assigned to them. -The way assign a driver to a printer is to view the Properties -of the printer and either

NO PRINTER DRIVER AVAILABLE FOR THIS PRINTER. +Later versions changed this to a NULL string to allow the use +tof the local Add Printer Wizard on NT/2000 clients. +Attempting to view the printer properties for a printer +which has this default driver assigned will result in +the error message:

Device settings cannot be displayed. The driver +for the specified printer is not installed, only spooler +properties will be displayed. Do you want to install the +driver now?

Click "No" in the error dialog and you will be presented with +the printer properties window. The way assign a driver to a +printer is to either


    4.2.3. Support a large number of printers

    $ rpcclient pogo -U root%bleaK.er \ +>rpcclient pogo -U root%secret \ >


    4.2.4. Adding New Printers via the Windows NT APW

    printer admin. +>).

  • addprinter -commandadd +printer command must have a defined value. The program @@ -2789,7 +2952,7 @@ CLASS="COMMAND" CLASS="PARAMETER" >add printer -program and reparse to the add printer program is executed undet the context +> is executed under the context of the connected user, not necessarily a root account.

    There is a complementing deleteprinter -commanddelete +printer command for removing entries from the "Printers..." @@ -2823,7 +2986,7 @@ CLASS="SECT2" >


    4.2.5. Samba and Printer Ports


    4.3. The Imprints Toolset


    4.3.1. What is Imprints?


    4.3.2. Creating Printer Driver Packages


    4.3.3. The Imprints server


    4.3.4. The Installation Client

    will reveal that Windows NT always uses the NT driver - name. The is ok as Windows NT always requires that at least + name. This is ok as Windows NT always requires that at least the Windows NT version of the printer driver is present. However, Samba does not have the requirement internally. Therefore, how can you use the NT driver name if is has not @@ -3049,18 +3212,60 @@ CLASS="SECT1" >


    4.4. Migration to from Samba 2.0.x to - 2.2.xMigration to from Samba 2.0.x to 2.2.x

    Given that printer driver management has changed - (we hope improved :) ) in 2.2.0 over prior releases, - migration from an existing setup to 2.2.0 can follow - several paths.

    Given that printer driver management has changed (we hope improved) in +2.2 over prior releases, migration from an existing setup to 2.2 can +follow several paths.

    Windows clients have a tendency to remember things for quite a while. +For example, if a Windows NT client has attached to a Samba 2.0 server, +it will remember the server as a LanMan printer server. Upgrading +the Samba host to 2.2 makes support for MSRPC printing possible, but +the NT client will still remember the previous setting.

    In order to give an NT client printing "amesia" (only necessary if you +want to use the newer MSRPC printing functionality in Samba), delete +the registry keys associated with the print server contained in +[HKLM\SYSTEM\CurrentControlSet\Control\Print]. The +spooler service on the client should be stopped prior to doing this:

    C:\WINNT\ > net stop spooler

    All the normal disclaimers about editing the registry go +here. Be careful, and know what you are doing.

    The spooler service should be restarted after you have finished +removing the appropriate registry entries by replacing the +stop command above with start.

    Windows 9x clients will continue to use LanMan printing calls +with a 2.2 Samba server so there is no need to perform any of these +modifications on non-NT clients.

    The following smb.conf parameters are considered to be - depreciated and will be removed soon. Do not use them - in new installations

    The following smb.conf parameters are considered to be depreciated and will +be removed soon. Do not use them in new installations

      printer driver file (G) -

    • printer driver (S) -

    • printer driver location (S) -

  • If you do not desire the new Windows NT - print driver support, nothing needs to be done. - All existing parameters work the same.

  • If you want to take advantage of NT printer - driver support but do not want to migrate the - 9x drivers to the new setup, the leave the existing - printers.def file. When smbd attempts to locate a - 9x driver for the printer in the TDB and fails it - will drop down to using the printers.def (and all - associated parameters). The make_printerdef - tool will also remain for backwards compatibility but will - be moved to the "this tool is the old way of doing it" - pile.

  • If you install a Windows 9x driver for a printer - on your Samba host (in the printing TDB), this information will - take precedence and the three old printing parameters - will be ignored (including print driver location).

  • printers.def - file into the new setup, the current only - solution is to use the Windows NT APW to install the NT drivers - and the 9x drivers. This can be scripted using smbclient - and and rpcclient. See the - Imprints installation client at http://imprints.sourceforge.net/ - for an example. -


Chapter 5. security = domain in Samba 2.x

5.1. Joining an NT Domain with Samba 2.2


5.2. Samba and Windows 2000 Domains


5.3. Why is this better than security = server?


Chapter 6. How to Configure Samba 2.2.x as a Primary Domain ControllerChapter 6. How to Configure Samba 2.2 as a Primary Domain Controller

6.1. Background6.1. Prerequisite Reading

Before you continue readingin this chapter, please make sure +that you are comfortable with configuring basic files services +in smb.conf and how to enable and administrate password +encryption in Samba. Theses two topics are covered in the +smb.conf(5) +manpage and the Encryption chapter +of this HOWTO Collection.


6.2. Background

Note: Author's Note : This document -is a combination of David Bannon's Samba 2.2 PDC HOWTO -and the Samba NT Domain FAQ. Both documents are superceeded by this one.

This document is a combination +of David Bannon's Samba 2.2 PDC HOWTO and the Samba NT Domain FAQ. +Both documents are superceeded by this one.

Version of Samba prior to release 2.2 had marginal capabilities to -act as a Windows NT 4.0 Primary Domain Controller (PDC). The following -functionality should work in 2.2.0:

UNIX_INSTALL.html, please make sure +that your server is configured correctly before proceeding. Another good +resource in the smb.conf(5) man +page. The following functionality should work in 2.2:

  • domain logons for Windows NT 4.0/2000 clients

    domain logons for Windows NT 4.0/2000 clients. +

  • placing a Windows 9x client in user level security

    placing a Windows 9x client in user level security +

  • retrieving a list of users and groups from a Samba PDC to - Windows 9x/NT/2000 clients

    retrieving a list of users and groups from a Samba PDC to + Windows 9x/NT/2000 clients +

  • roving user profiles

    roving (roaming) user profiles +

  • Windows NT 4.0 style system policies

    Windows NT 4.0 style system policies +

Windows 2000 Service Pack 2 Clients

Samba 2.2.1 is required for PDC functionality when using Windows 2000 + SP2 clients. +

The following pieces of functionality are not included in the 2.2 release:

  • Windows NT 4 domain trusts

    Windows NT 4 domain trusts +

  • Sam replication with Windows NT 4.0 Domain Controllers - (i.e. a Samba PDC and a Windows NT BDC or vice versa)

    SAM replication with Windows NT 4.0 Domain Controllers + (i.e. a Samba PDC and a Windows NT BDC or vice versa) +

  • Adding users via the User Manager for Domains

    Adding users via the User Manager for Domains +

  • Acting as a Windows 2000 Domain Controller (i.e. Kerberos - and Active Directory)

    Acting as a Windows 2000 Domain Controller (i.e. Kerberos and + Active Directory) +

Beginning with Samba 2.2.0, we are proud to announce official -support for Windows NT 4.0 style domain logons from Windows NT -4.0 and Windows 2000 (including SP1) clients. This article -outlines the steps necessary for configuring Samba as a PDC. -Note that it is necessary to have a working Samba server -prior to implementing the PDC functionality. If you have not -followed the steps outlined in UNIX_INSTALL.html, please make sure that your server -is configured correctly before proceeding. Another good -resource in the smb.conf(5) man -page.

Implementing a Samba PDC can basically be divided into 2 broad steps.

  • Configuring the Samba Domain Controller +> Configuring the Samba PDC

  • Creating machine trust accounts - and joining clients to the domain

    Creating machine trust accounts and joining clients + to the domain +


  • 6.2. Configuring the Samba Domain Controller6.3. Configuring the Samba Domain Controller

    The first step in creating a working Samba PDC is to @@ -3768,7 +4040,7 @@ TARGET="_top" > = \\homeserver\%u ; specify a generic logon script for all users - ; this is a relative path to the [netlogon] share + ; this is a relative **DOS** path to the [netlogon] share

    There are a couple of points to emphasize in the above -configuration.

    There are a couple of points to emphasize in the above configuration.

    As Samba 2.2 does not offer a complete implementation of group mapping between Windows NT groups and UNIX groups (this is really quite complicated to explain in a short space), you should refer to the domain admin users


    6.3. Creating Machine Trust Accounts and Joining Clients +NAME="AEN870" +>6.4. Creating Machine Trust Accounts and Joining Clients to the Domain

    First you must understand what a machine trust account is and what -it is used for.

    A machine trust account is a user account owned by a computer. +>A machine trust account is a samba user account owned by a computer. The account password acts as the shared secret for secure -communication with the Domain Controller. Hence the reason that -a Windows 9x host is never a true member of a domain because -it does not posses a machine trust account and thus has no shared -secret with the DC.

    On a Windows NT PDC, these machine trust account passwords are stored -in the registry. A Samba PDC stores these accounts in he same location +in the registry. A Samba PDC stores these accounts in the same location as user LanMan and NT password hashes (currently smbpasswd). -However, machine trust accounts only possess the NT password hash.

    Because Samba requires machine accounts to possess a UNIX uid from +which an Windows NT SID can be generated, all of these accounts +must have an entry in /etc/passwd and smbpasswd. +Future releases will alleviate the need to create +/etc/passwd entries.

    There are two means of creating machine trust accounts.

    • Manual creation before joining the client - to the domain. In this case, the password is set to a known - value -- the lower case of the machine's netbios name.

      Manual creation before joining the client to the domain. In this case, + the password is set to a known value -- the lower case of the + machine's netbios name. +

    • Creation of the account at the time of - joining the domain. In this case, the session key of the - administrative account used to join the client to the domain acts - as an encryption key for setting the password to a random value.

      Creation of the account at the time of joining the domain. In + this case, the session key of the administrative account used to join + the client to the domain acts as an encryption key for setting the + password to a random value (This is the recommended method). +


    6.4.1. Manually creating machine trust accounts

    Because Samba requires machine accounts to possess a UNIX uid from -which an Windows NT SID can be generated, all of these accounts -will have an entry in /etc/passwd and smbpasswd. -Future releases will alleviate the need to create -/etc/passwd entries.

    The The first step in creating a machine trust account by hand is to +create an entry for the machine in /etc/passwd. This can be done +using vipw or any 'add userr' command which is normally +used to create new UNIX accounts. The following is an example for a Linux +based Samba server:

    root# /usr/sbin/useradd -g 100 -d /dev/null -c machine_nickname -m -s /bin/false machine_name$

    The /etc/passwd entry will list the machine name @@ -3949,23 +4255,43 @@ WIDTH="100%" >

    doppy$:x:505:501:NTMachine:/dev/null:/bin/false
    doppy$:x:505:501:machine_nickname:/dev/null:/bin/false

    If you are manually creating the machine accounts, it is necessary -to add the /etc/passwd (or NIS passwd -map) entry prior to adding the smbpasswd -entry. The following command will create a new machine account -ready for use.

    Above, machine_nickname can be any descriptive name for the +pc i.e. BasementComputer. The machine_name absolutely must be +the netbios name of the pc to be added to the domain. The "$" must append the netbios +name of the pc or samba will not recognize this as a machine account

    Now that the UNIX account has been created, the next step is to create +the smbpasswd entry for the machine containing the well known initial +trust account password. This can be done using the smbpasswd(8) command +as shown here:

    machine_name is the machine's netbios -name.

    If you manually create a machine account, immediately join -the client to the domain. An open account like this -can allow intruders to gain access to user account information -in your domain.

    The second way of creating machine trust accounts is to add -them on the fly at the time the client is joined to the domain. -You will need to include a value for the -

    Join the client to the domain immediately

    Manually creating a machine trust account using this method is the + equivalent of creating a machine account on a Windows NT PDC using + the "Server Manager". From the time at which the account is created + to the time which th client joins the domain and changes the password, + your domain is vulnerable to an intruder joining your domain using a + a machine with the same netbios name. A PDC inherently trusts + members of the domain and will serve out a large degree of user + information to such clients. You have been warned! +


    6.4.2. Creating machine trust accounts "on the fly"

    The second, and most recommended way of creating machine trust accounts +is to create them as needed at the time the client is joined to +the domain. You will need to include a value for the add user script -parameter. Below is an example I use on a RedHat 6.2 Linux system.

    In Samba 2.2.0, In Samba 2.2.1, only the root account can be used to create -machine accounts on the fly like this. Therefore, it is required -to create an entry in smbpasswd for root. -The password . The password +SHOULD be set to s different -password that the associated be set to s different password that the +associated /etc/passwd -entry for security reasons.

    entry for security reasons.


    6.4. Common Problems and Errors6.5. Common Problems and Errors

    I cannot include a '$' in a machine name.

    • I cannot include a '$' in a machine name. +

      A 'machine name' in (typically) A 'machine name' in (typically) /etc/passwd -of the machine name with a '$' appended. FreeBSD (and other BSD -systems ?) won't create a user with a '$' in their name.

      The problem is only in the program used to make the entry, once -made, it works perfectly. So create a user without the '$' and -use The problem is only in the program used to make the entry, once + made, it works perfectly. So create a user without the '$' and + use vipw to edit the entry, adding the '$'. Or create -the whole entry with vipw if you like, make sure you use a -unique uid !

    • I get told "You already have a connection to the Domain...." -when creating a machine account.

      This happens if you try to create a machine account from the -machine itself and use a user name that does not work (for whatever -reason) and then try another (possibly valid) user name. -Exit out of the network applet to close the initial connection -and try again.

      +

      Further, if the machine is a already a 'member of a workgroup' that -is the same name as the domain you are joining (bad idea) you will -get this message. Change the workgroup name to something else, it -does not matter what, reboot, and try again.

      This happens if you try to create a machine account from the + machine itself and already have a connection (e.g. mapped drive) + to a share (or IPC$) on the Samba PDC. The following command + will remove all network drive connections: +

      I get told "Cannot join domain, the credentials supplied -conflict with an existing set.."

      C:\WINNT\> net use * /d +

      This is the same basic problem as mentioned above, "You already -have a connection..."

      Further, if the machine is a already a 'member of a workgroup' that + is the same name as the domain you are joining (bad idea) you will + get this message. Change the workgroup name to something else, it + does not matter what, reboot, and try again. +

    • "The system can not log you on (C000019B)...."

      The system can not log you on (C000019B).... +

      I joined the domain successfully but after upgrading -to a newer version of the Samba code I get the message, "The system -can not log you on (C000019B), Please try a gain or consult your -system administrator" when attempting to logon.

      This occurs when the domain SID stored in - This occurs when the domain SID stored in + private/WORKGROUP.SID is -changed. For example, you remove the file and smbd automatically -creates a new one. Or you are swapping back and forth between -versions 2.0.7, TNG and the HEAD branch code (not recommended). The -only way to correct the problem is to restore the original domain -SID or remove the domain client from the domain and rejoin.

    • "The machine account for this computer either does not -exist or is not accessible."

      The machine account for this computer either does not + exist or is not accessible. +

      When I try to join the domain I get the message "The machine account -for this computer either does not exist or is not accessible". Whats -wrong ?

      When I try to join the domain I get the message "The machine account + for this computer either does not exist or is not accessible". Whats + wrong? +

      This problem is caused by the PDC not having a suitable machine account. -If you are using the add user script = This problem is caused by the PDC not having a suitable machine account. + If you are using the add user script method to create -accounts then this would indicate that it has not worked. Ensure the domain -admin user system is working.

      Alternatively if you are creating account entries manually then they -have not been created correctly. Make sure that you have the entry -correct for the machine account in smbpasswd file on the Samba PDC. -If you added the account using an editor rather than using the smbpasswd -utility, make sure that the account name is the machine netbios name -with a '$' appended to it ( ie. computer_name$ ). There must be an entry -in both /etc/passwd and the smbpasswd file. Some people have reported -that inconsistent subnet masks between the Samba server and the NT -client have caused this problem. Make sure that these are consistent -for both client and server.

      Alternatively if you are creating account entries manually then they + have not been created correctly. Make sure that you have the entry + correct for the machine account in smbpasswd file on the Samba PDC. + If you added the account using an editor rather than using the smbpasswd + utility, make sure that the account name is the machine netbios name + with a '$' appended to it ( ie. computer_name$ ). There must be an entry + in both /etc/passwd and the smbpasswd file. Some people have reported + that inconsistent subnet masks between the Samba server and the NT + client have caused this problem. Make sure that these are consistent + for both client and server. +

    • When I attempt to login to a Samba Domain from a NT4/W2K workstation, + I get a message about my account being disabled. +

      This problem is caused by a PAM related bug in Samba 2.2.0. This bug is + fixed in 2.2.1. Other symptoms could be unaccessible shares on + NT/W2K member servers in the domain or the following error in your smbd.log: + passdb/pampass.c:pam_account(268) PAM: UNKNOWN ERROR for User: %user% +

      At first be ensure to enable the useraccounts with smbpasswd -e + %user%, this is normaly done, when you create an account. +

      In order to work around this problem in 2.2.0, configure the + account control flag in + /etc/pam.d/samba file as follows: +

      	account required        pam_permit.so
      +	

      If you want to remain backward compatibility to samba 2.0.x use + pam_permit.so, it's also possible to use + pam_pwdb.so. There are some bugs if you try to + use pam_unix.so, if you need this, be ensure to use + the most recent version of this file. +


    6.5. System Policies and Profiles6.6. System Policies and Profiles

    Much of the information necessary to implement System Policies and @@ -4159,92 +4611,107 @@ Profiles and Policies in Windows NT 4.0

    Here are some additional details:

    What about Windows NT Policy Editor ?

    • What about Windows NT Policy Editor ? +

      To create or edit To create or edit ntconfig.pol you must use -the NT Server Policy Editor, poledit.exe which -is included with NT Server but not NT Workstation. -There is a Policy Editor on a NTws -but it is not suitable for creating Domain Policies. -Further, although the Windows 95 -Policy Editor can be installed on an NT Workstation/Server, it will not -work with NT policies because the registry key that are set by the policy templates. -However, the files from the NT Server will run happily enough on an NTws. -You need poledit.exe, common.adm and winnt.adm. It is convenient -to put the two *.adm files in c:\winnt\inf which is where -the binary will look for them unless told otherwise. Note also that that -directory is 'hidden'.

      The Windows NT policy editor is also included with the -Service Pack 3 (and later) for Windows NT 4.0. Extract the files using - The Windows NT policy editor is also included with the Service Pack 3 (and + later) for Windows NT 4.0. Extract the files using servicepackname /x, ie thats , + ie thats Nt4sp6ai.exe -/x for service pack 6a. The policy editor, Nt4sp6ai.exe /x for service pack 6a. The policy editor, + poledit.exe and the -associated template files (*.adm) should -be extracted as well. It is also possible to downloaded the policy template -files for Office97 and get a copy of the policy editor. Another possible -location is with the Zero Administration Kit available for download from Microsoft.

      and the associated template files (*.adm) should + be extracted as well. It is also possible to downloaded the policy template + files for Office97 and get a copy of the policy editor. Another possible + location is with the Zero Administration Kit available for download from Microsoft. +

    • Can Win95 do Policies ?

      +

      Install the group policy handler for Win9x to pick up group -policies. Look on the Win98 CD in Install the group policy handler for Win9x to pick up group + policies. Look on the Win98 CD in \tools\reskit\netadmin\poledit. -Install group policies on a Win9x client by double-clicking -grouppol.inf. Log off and on again a couple of -times and see if Win98 picks up group policies. Unfortunately this needs -to be done on every Win9x machine that uses group policies....

      If group policies don't work one reports suggests getting the updated -(read: working) grouppol.dll for Windows 9x. The group list is grabbed -from /etc/group.

      If group policies don't work one reports suggests getting the updated + (read: working) grouppol.dll for Windows 9x. The group list is grabbed + from /etc/group. +

    • How do I get 'User Manager' and 'Server Manager'

      +

      Since I don't need to buy an NT Server CD now, how do I get -the 'User Manager for Domains', the 'Server Manager' ?

      Since I don't need to buy an NT Server CD now, how do I get + the 'User Manager for Domains', the 'Server Manager' ? +

      Microsoft distributes a version of -these tools called nexus for installation on Windows 95 systems. The -tools set includes

      Microsoft distributes a version of these tools called nexus for + installation on Windows 95 systems. The tools set includes +

        Click here to download the archived file Click here to download the archived file ftp://ftp.microsoft.com/Softlib/MSLFILES/NEXUS.EXE

        +

        The Windows NT 4.0 version of the 'User Manager for -Domains' and 'Server Manager' are available from Microsoft via ftp -from The Windows NT 4.0 version of the 'User Manager for + Domains' and 'Server Manager' are available from Microsoft via ftp + from ftp://ftp.microsoft.com/Softlib/MSLFILES/SRVTOOLS.EXE

        +


      6.6. What other help can I get ?6.7. What other help can I get ?

      There are many sources of information available in the form @@ -4290,10 +4761,15 @@ of mailing lists, RFC's and documentation. The docs that come with the samba distribution contain very good explanations of general SMB topics such as browsing.

      What are some diagnostics tools I can use to debug the domain logon -process and where can I find them?

      • What are some diagnostics tools I can use to debug the domain logon + process and where can I find them? +

        One of the best diagnostic tools for debugging problems is Samba itself. You can use the -d option for both smbd and nmbd to specifiy what @@ -4335,7 +4811,7 @@ CLASS="COMMAND" >

      An SMB enabled version of tcpdump is available from - http://www.tcpdup.org/

    • How do I install 'Network Monitor' on an NT Workstation -or a Windows 9x box?

      +

      Installing netmon on an NT workstation requires a couple of steps. The following are for installing Netmon V4.00.349, which comes @@ -4457,14 +4936,11 @@ CLASS="FILENAME" information on how to do this. Copy the files from a working Netmon installation.

    • The following is a list if helpful URLs and other links: +


    • 6.6.2. Mailing Lists

      How do I get help from the mailing lists ?

      • How do I get help from the mailing lists ? +

        There are a number of Samba related mailing lists. Go to There are a number of Samba related mailing lists. Go to http://samba.org, click on your nearest mirror -and then click on Support and then click on Samba related mailing lists.

        Samba related mailing lists. +

        For questions relating to Samba TNG go to - For questions relating to Samba TNG go to + http://www.samba-tng.org/ -It has been requested that you don't post questions about Samba-TNG to the -main stream Samba lists.

        If you post a message to one of the lists please observe the following guide lines :

        If you post a message to one of the lists please observe the following guide lines : +

        • In addition to the version, if you obtained Samba via - CVS mention the date when you last checked it out.

          In addition to the version, if you obtained Samba via + CVS mention the date when you last checked it out.

        • Try and make your question clear and brief, lots of long, + convoluted questions get deleted before they are completely read ! + Don't post html encoded messages (if you can select colour or font + size its html).

        • If you run one of those nifty 'I'm on holidays' things when + you are away, make sure its configured to not answer mailing lists. +

        • Don't cross post. Work out which is the best list to post to + and see what happens, ie don't post to both samba-ntdom and samba-technical. + Many people active on the lists subscribe to more + than one list and get annoyed to see the same message two or more times. + Often someone will see a message and thinking it would be better dealt + with on another, will forward it on for you.

        • You might include partial + log files written at a debug level set to as much as 20. + Please don't send the entire log but enough to give the context of the + error messages.

        • (Possibly) If you have a complete netmon trace ( from the opening of + the pipe to the error ) you can send the *.CAP file as well.

        • Please think carefully before attaching a document to an email. + Consider pasting the relevant parts into the body of the message. The samba + mailing lists go to a huge number of people, do they all need a copy of your + smb.conf in their attach directory ?

      • How do I get off the mailing lists ? +

        To have your name removed from a samba mailing list, go to the + same place you went to to get on it. Go to http://lists.samba.org, + click on your nearest mirror and then click on Support and + then click on Samba related mailing lists. Or perhaps see + here +

        Please don't post messages to the list asking to be removed, you will just + be referred to the above address (unless that process failed in some way...) +


      6.8. Domain Control for Windows 9x/ME

      Note: The following section contains much of the original +DOMAIN.txt file previously included with Samba. Much of +the material is based on what went into the book Special +Edition, Using Samba. (Richard Sharpe)

      A domain and a workgroup are exactly the same thing in terms of network +browsing. The difference is that a distributable authentication +database is associated with a domain, for secure login access to a +network. Also, different access rights can be granted to users if they +successfully authenticate against a domain logon server (NT server and +other systems based on NT server support this, as does at least Samba TNG now).

      The SMB client logging on to a domain has an expectation that every other +server in the domain should accept the same authentication information. +Network browsing functionality of domains and workgroups is +identical and is explained in BROWSING.txt. It should be noted, that browsing +is total orthogonal to logon support.

      Issues related to the single-logon network model are discussed in this +document. Samba supports domain logons, network logon scripts, and user +profiles for MS Windows for workgroups and MS Windows 9X clients.

      When an SMB client in a domain wishes to logon it broadcast requests for a +logon server. The first one to reply gets the job, and validates its +password using whatever mechanism the Samba administrator has installed. +It is possible (but very stupid) to create a domain where the user +database is not shared between servers, ie they are effectively workgroup +servers advertising themselves as participating in a domain. This +demonstrates how authentication is quite different from but closely +involved with domains.

      Another thing commonly associated with single-logon domains is remote +administration over the SMB protocol. Again, there is no reason why this +cannot be implemented with an underlying username database which is +different from the Windows NT SAM. Support for the Remote Administration +Protocol is planned for a future release of Samba.

      Network logon support as discussed in this section is aimed at Window for +Workgroups, and Windows 9X clients.

      Support for profiles is confirmed as working for Win95, NT 4.0 and NT 3.51. +It is possible to specify: the profile location; script file to be loaded +on login; the user's home directory; and for NT a kick-off time could also +now easily be supported. However, there are some differences between Win9X +profile support and WinNT profile support. These are discussed below.

      With NT Workstations, all this does not require the use or intervention of +an NT 4.0 or NT 3.51 server: Samba can now replace the logon services +provided by an NT server, to a limited and experimental degree (for example, +running "User Manager for Domains" will not provide you with access to +a domain created by a Samba Server).

      With Win95, the help of an NT server can be enlisted, both for profile storage +and for user authentication. For details on user authentication, see +security_level.txt. For details on profile storage, see below.

      Using these features you can make your clients verify their logon via +the Samba server; make clients run a batch file when they logon to +the network and download their preferences, desktop and start menu.

      Before launching into the configuration instructions, it is worthwhile looking +at how a Win9X client performs a logon:

      1. The client broadcasts (to the IP broadcast address of the subnet it is in) + a NetLogon request. This is sent to the NetBIOS address DOMAIN<00> at the + NetBIOS layer. The client chooses the first response it receives, which + contains the NetBIOS name of the logon server to use in the format of + \\SERVER. +

      2. The client then connects to that server, logs on (does an SMBsessetupX) and + then connects to the IPC$ share (using an SMBtconX). +

      3. The client then does a NetWkstaUserLogon request, which retrieves the name + of the user's logon script. +

      4. The client then connects to the NetLogon share and searches for this + and if it is found and can be read, is retrieved and executed by the client. + After this, the client disconnects from the NetLogon share. +

      5. The client then sends a NetUserGetInfo request to the server, to retrieve + the user's home share, which is used to search for profiles. Since the + response to the NetUserGetInfo request does not contain much more + the user's home share, profiles for Win9X clients MUST reside in the user + home directory. +

      6. The client then connects to the user's home share and searches for the + user's profile. As it turns out, you can specify the users home share as + a sharename and path. For example, \\server\fred\.profile. + If the profiles are found, they are implemented. +

      7. The client then disconnects from the user's home share, and reconnects to + the NetLogon share and looks for CONFIG.POL, the policies file. If this is + found, it is read and implemented. +


      6.8.1. Configuration Instructions: Network Logons

      To use domain logons and profiles you need to do the following:

      1. Create a share called [netlogon] in your smb.conf. This share should + be readable by all users, and probably should not be writeable. This + share will hold your network logon scripts, and the CONFIG.POL file + (Note: for details on the CONFIG.POL file, how to use it, what it is, + refer to the Microsoft Windows NT Administration documentation. + The format of these files is not known, so you will need to use + Microsoft tools). +

        For example I have used: +

        [netlogon]
        +     path = /data/dos/netlogon
        +     writeable = no
        +     guest ok = no

        Note that it is important that this share is not writeable by ordinary + users, in a secure environment: ordinary users should not be allowed + to modify or add files that another user's computer would then download + when they log in. +

      2. in the [global] section of smb.conf set the following: +

        domain logons = yes
        +logon script = %U.bat
        +	

        The choice of batch file is, of course, up to you. The above would + give each user a separate batch file as the %U will be changed to + their username automatically. The other standard % macros may also be + used. You can make the batch files come from a subdirectory by using + something like: +

        logon script = scripts\%U.bat
        +	

      3. create the batch files to be run when the user logs in. If the batch + file doesn't exist then no batch file will be run. +

        In the batch files you need to be careful to use DOS style cr/lf line + endings. If you don't then DOS may get confused. I suggest you use a + DOS editor to remotely edit the files if you don't know how to produce + DOS style files under unix. +

      4. Use smbclient with the -U option for some users to make sure that + the \\server\NETLOGON share is available, the batch files are + visible and they are readable by the users. +

      5. you will probabaly find that your clients automatically mount the + \\SERVER\NETLOGON share as drive z: while logging in. You can put + some useful programs there to execute from the batch files. +

      security mode and master browsers

      There are a few comments to make in order to tie up some +loose ends. There has been much debate over the issue of whether +or not it is ok to configure Samba as a Domain Controller in security +modes other than USER. The only security mode +which will not work due to technical reasons is SHARE +mode security. DOMAIN and SERVER +mode security is really just a variation on SMB user level security.

      Actually, this issue is also closer tied to the debate on whether +or not Samba must be the domain master browser for its workgroup +when operating as a DC. While it may technically be possible +to configure a server as such (after all, browsing and domain logons +are two distinctly different functions), it is not a good idea to +so. You should remember that the DC must register the DOMAIN#1b netbios +name. This is the name used by Windows clients to locate the DC. +Windows clients do not distinguish between the DC and the DMB. +For this reason, it is very wise to configure the Samba DC as the DMB.

      Now back to the issue of configuring a Samba DC to use a mode other +than "security = user". If a Samba host is configured to use +another SMB server or DC in order to validate user connection +requests, then it is a fact that some other machine on the network +(the "password server") knows more about user than the Samba host. +99% of the time, this other host is a domain controller. Now +in order to operate in domain mode security, the "workgroup" parameter +must be set to the name of the Windows NT domain (which already +has a domain controller, right?)

      Therefore configuring a Samba box as a DC for a domain that +already by definition has a PDC is asking for trouble. +Therefore, you should always configure the Samba DC to be the DMB +for its domain.


      6.8.2. Configuration Instructions: Setting up Roaming User Profiles

      Warning

      NOTE! Roaming profiles support is different +for Win9X and WinNT.

      Before discussing how to configure roaming profiles, it is useful to see how +Win9X and WinNT clients implement these features.

      Win9X clients send a NetUserGetInfo request to the server to get the user's +profiles location. However, the response does not have room for a separate +profiles location field, only the users home share. This means that Win9X +profiles are restricted to being in the user's home directory.

      WinNT clients send a NetSAMLogon RPC request, which contains many fields, +including a separate field for the location of the user's profiles. +This means that support for profiles is different for Win9X and WinNT.


      6.8.2.1. Windows NT Configuration

      To support WinNT clients, inn the [global] section of smb.conf set the +following (for example):

      logon path = \\profileserver\profileshare\profilepath\%U\moreprofilepath

      The default for this option is \\%N\%U\profile, namely +\\sambaserver\username\profile. The \\N%\%U service is created +automatically by the [homes] service. +If you are using a samba server for the profiles, you _must_ make the +share specified in the logon path browseable.

      Note: [lkcl 26aug96 - we have discovered a problem where Windows clients can +maintain a connection to the [homes] share in between logins. The +[homes] share must NOT therefore be used in a profile path.]


      6.8.2.2. Windows 9X Configuration

      To support Win9X clients, you must use the "logon home" parameter. Samba has +now been fixed so that "net use/home" now works as well, and it, too, relies +on the "logon home" parameter.

      By using the logon home parameter, you are restricted to putting Win9X +profiles in the user's home directory. But wait! There is a trick you +can use. If you set the following in the [global] section of your +smb.conf file:

      logon home = \\%L\%U\.profiles

      then your Win9X clients will dutifully put their clients in a subdirectory +of your home directory called .profiles (thus making them hidden).

      Not only that, but 'net use/home' will also work, because of a feature in +Win9X. It removes any directory stuff off the end of the home directory area +and only uses the server and share portion. That is, it looks like you +specified \\%L\%U for "logon home".


      6.8.2.3. Win9X and WinNT Configuration

      You can support profiles for both Win9X and WinNT clients by setting both the +"logon home" and "logon path" parameters. For example:

      logon home = \\%L\%U\.profiles
      +logon path = \\%L\profiles\%U

      Note: I have not checked what 'net use /home' does on NT when "logon home" is +set as above.


      6.8.2.4. Windows 9X Profile Setup

      When a user first logs in on Windows 9X, the file user.DAT is created, +as are folders "Start Menu", "Desktop", "Programs" and "Nethood". +These directories and their contents will be merged with the local +versions stored in c:\windows\profiles\username on subsequent logins, +taking the most recent from each. You will need to use the [global] +options "preserve case = yes", "short case preserve = yes" and +"case sensitive = no" in order to maintain capital letters in shortcuts +in any of the profile folders.

      The user.DAT file contains all the user's preferences. If you wish to +enforce a set of preferences, rename their user.DAT file to user.MAN, +and deny them write access to this file.

      1. On the Windows 95 machine, go to Control Panel | Passwords and + select the User Profiles tab. Select the required level of + roaming preferences. Press OK, but do _not_ allow the computer + to reboot. +

      2. On the Windows 95 machine, go to Control Panel | Network | + Client for Microsoft Networks | Preferences. Select 'Log on to + NT Domain'. Then, ensure that the Primary Logon is 'Client for + Microsoft Networks'. Press OK, and this time allow the computer + to reboot. +

      Under Windows 95, Profiles are downloaded from the Primary Logon. +If you have the Primary Logon as 'Client for Novell Networks', then +the profiles and logon script will be downloaded from your Novell +Server. If you have the Primary Logon as 'Windows Logon', then the +profiles will be loaded from the local machine - a bit against the +concept of roaming profiles, if you ask me.

      You will now find that the Microsoft Networks Login box contains +[user, password, domain] instead of just [user, password]. Type in +the samba server's domain name (or any other domain known to exist, +but bear in mind that the user will be authenticated against this +domain and profiles downloaded from it, if that domain logon server +supports it), user name and user's password.

      Once the user has been successfully validated, the Windows 95 machine +will inform you that 'The user has not logged on before' and asks you +if you wish to save the user's preferences? Select 'yes'.

      Once the Windows 95 client comes up with the desktop, you should be able +to examine the contents of the directory specified in the "logon path" +on the samba server and verify that the "Desktop", "Start Menu", +"Programs" and "Nethood" folders have been created.

      These folders will be cached locally on the client, and updated when +the user logs off (if you haven't made them read-only by then :-). +You will find that if the user creates further folders or short-cuts, +that the client will merge the profile contents downloaded with the +contents of the profile directory already on the local client, taking +the newest folders and short-cuts from each set.

      If you have made the folders / files read-only on the samba server, +then you will get errors from the w95 machine on logon and logout, as +it attempts to merge the local and the remote profile. Basically, if +you have any errors reported by the w95 machine, check the unix file +permissions and ownership rights on the profile directory contents, +on the samba server.

      If you have problems creating user profiles, you can reset the user's +local desktop cache, as shown below. When this user then next logs in, +they will be told that they are logging in "for the first time".

      1. Try and make your question clear and brief, lots of long, - convoluted questions get deleted before they are completely read ! - Don't post html encoded messages (if you can select colour or font - size its html).

        instead of logging in under the [user, password, domain] dialog, + press escape. +

      2. If you run one of those nifty 'I'm on holidays' things when - you are away, make sure its configured to not answer mailing lists. -

        run the regedit.exe program, and look in: +

        HKEY_LOCAL_MACHINE\Windows\CurrentVersion\ProfileList +

        you will find an entry, for each user, of ProfilePath. Note the + contents of this key (likely to be c:\windows\profiles\username), + then delete the key ProfilePath for the required user. +

        [Exit the registry editor]. +

      3. Don't cross post. Work out which is the best list to post to - and see what happens, ie don't post to both samba-ntdom and samba-technical. - Many people active on the lists subscribe to more - than one list and get annoyed to see the same message two or more times. - Often someone will see a message and thinking it would be better dealt - with on another, will forward it on for you.

        WARNING - before deleting the contents of the + directory listed in + the ProfilePath (this is likely to be c:\windows\profiles\username), + ask them if they have any important files stored on their desktop + or in their start menu. delete the contents of the directory + ProfilePath (making a backup if any of the files are needed). +

        This will have the effect of removing the local (read-only hidden + system file) user.DAT in their profile directory, as well as the + local "desktop", "nethood", "start menu" and "programs" folders. +

      4. You might include partial - log files written at a debug level set to as much as 20. - Please don't send the entire log but enough to give the context of the - error messages.

        search for the user's .PWL password-cacheing file in the c:\windows + directory, and delete it. +

      5. (Possibly) If you have a complete netmon trace ( from the opening of - the pipe to the error ) you can send the *.CAP file as well.

        log off the windows 95 client. +

      6. Please think carefully before attaching a document to an email. - Consider pasting the relevant parts into the body of the message. The samba - mailing lists go to a huge number of people, do they all need a copy of your - smb.conf in their attach directory ?

        check the contents of the profile path (see "logon path" described + above), and delete the user.DAT or user.MAN file for the user, + making a backup if required. +

      How do I get off the mailing lists ?

      If all else fails, increase samba's debug log levels to between 3 and 10, +and / or run a packet trace program such as tcpdump or netmon.exe, and +look for any error reports.

      If you have access to an NT server, then first set up roaming profiles +and / or netlogons on the NT server. Make a packet trace, or examine +the example packet traces provided with NT server, and see what the +differences are with the equivalent samba trace.


      6.8.2.5. Windows NT Workstation 4.0

      When a user first logs in to a Windows NT Workstation, the profile +NTuser.DAT is created. The profile location can be now specified +through the "logon path" parameter.

      Note: [lkcl 10aug97 - i tried setting the path to +\\samba-server\homes\profile, and discovered that this fails because +a background process maintains the connection to the [homes] share +which does _not_ close down in between user logins. you have to +have \\samba-server\%L\profile, where user is the username created +from the [homes] share].

      There is a parameter that is now available for use with NT Profiles: +"logon drive". This should be set to "h:" or any other drive, and +should be used in conjunction with the new "logon home" parameter.

      The entry for the NT 4.0 profile is a _directory_ not a file. The NT +help on profiles mentions that a directory is also created with a .PDS +extension. The user, while logging in, must have write permission to +create the full profile path (and the folder with the .PDS extension) +[lkcl 10aug97 - i found that the creation of the .PDS directory failed, +and had to create these manually for each user, with a shell script. +also, i presume, but have not tested, that the full profile path must +be browseable just as it is for w95, due to the manner in which they +attempt to create the full profile path: test existence of each path +component; create path component].

      In the profile directory, NT creates more folders than 95. It creates +"Application Data" and others, as well as "Desktop", "Nethood", +"Start Menu" and "Programs". The profile itself is stored in a file +NTuser.DAT. Nothing appears to be stored in the .PDS directory, and +its purpose is currently unknown.

      You can use the System Control Panel to copy a local profile onto +a samba server (see NT Help on profiles: it is also capable of firing +up the correct location in the System Control Panel for you). The +NT Help file also mentions that renaming NTuser.DAT to NTuser.MAN +turns a profile into a mandatory one.

      Note: [lkcl 10aug97 - i notice that NT Workstation tells me that it is +downloading a profile from a slow link. whether this is actually the +case, or whether there is some configuration issue, as yet unknown, +that makes NT Workstation _think_ that the link is a slow one is a +matter to be resolved].

      [lkcl 20aug97 - after samba digest correspondance, one user found, and +another confirmed, that profiles cannot be loaded from a samba server +unless "security = user" and "encrypt passwords = yes" (see the file +ENCRYPTION.txt) or "security = server" and "password server = ip.address. +of.yourNTserver" are used. either of these options will allow the NT +workstation to access the samba server using LAN manager encrypted +passwords, without the user intervention normally required by NT +workstation for clear-text passwords].

      [lkcl 25aug97 - more comments received about NT profiles: the case of +the profile _matters_. the file _must_ be called NTuser.DAT or, for +a mandatory profile, NTuser.MAN].


      6.8.2.6. Windows NT Server

      There is nothing to stop you specifying any path that you like for the +location of users' profiles. Therefore, you could specify that the +profile be stored on a samba server, or any other SMB server, as long as +that SMB server supports encrypted passwords.


      6.8.2.7. Sharing Profiles between W95 and NT Workstation 4.0

      To have your name removed from a samba mailing list, go to the - same place you went to to get on it. Go to http://lists.samba.org, click - on your nearest mirror and then click on Support and - then click on Samba related mailing lists. Or perhaps see - here

      Potentially outdated or incorrect material follows

      Please don't post messages to the list asking to be removed, you will just - be referred to the above address (unless that process failed in some way...) -

      I think this is all bogus, but have not deleted it. (Richard Sharpe)

      The default logon path is \\%N\U%. NT Workstation will attempt to create +a directory "\\samba-server\username.PDS" if you specify the logon path +as "\\samba-server\username" with the NT User Manager. Therefore, you +will need to specify (for example) "\\samba-server\username\profile". +NT 4.0 will attempt to create "\\samba-server\username\profile.PDS", which +is more likely to succeed.

      If you then want to share the same Start Menu / Desktop with W95, you will +need to specify "logon path = \\samba-server\username\profile" [lkcl 10aug97 +this has its drawbacks: i created a shortcut to telnet.exe, which attempts +to run from the c:\winnt\system32 directory. this directory is obviously +unlikely to exist on a Win95-only host].

      If you have this set up correctly, you will find separate user.DAT and +NTuser.DAT files in the same profile directory.

      Note: [lkcl 25aug97 - there are some issues to resolve with downloading of +NT profiles, probably to do with time/date stamps. i have found that +NTuser.DAT is never updated on the workstation after the first time that +it is copied to the local workstation profile directory. this is in +contrast to w95, where it _does_ transfer / update profiles correctly].


      6.7. DOMAIN_CONTROL.txt : Windows NT Domain Control & Samba6.9. DOMAIN_CONTROL.txt : Windows NT Domain Control & Samba

      Possibly Outdated Material

      This appendix was originally authored by John H Terpstra of the Samba Team -and is included here for posterity.

      This appendix was originally authored by John H Terpstra of + the Samba Team and is included here for posterity. +

      NOTE :

      Windows NT Server can be installed as either a plain file and print server (WORKGROUP workstation or server) or as a server that participates in Domain -Control (DOMAIN member, Primary Domain controller or Backup Domain controller).

      The same is true for OS/2 Warp Server, Digital Pathworks and other similar -products, all of which can participate in Domain Control along with Windows NT. -However only those servers which have licensed Windows NT code in them can be -a primary Domain Controller (eg Windows NT Server, Advanced Server for Unix.)

      To many people these terms can be confusing, so let's try to clear the air.


      Chapter 7. Unifed Logons between Windows NT and UNIX using Winbind

      7.1. Abstract


      7.2. Introduction


      7.3. What Winbind Provides


      7.3.1. Target Uses


      7.4. How Winbind Works


      7.4.1. Microsoft Remote Procedure Calls


      7.4.2. Name Service Switch


      7.4.3. Pluggable Authentication Modules


      7.4.4. User and Group ID Allocation


      7.4.5. Result Caching


      7.5. Installation and Configuration


      7.6. Limitations


      7.7. Conclusion


      Chapter 8. UNIX Permission Bits and WIndows NT Access Control Lists


      Chapter 10. HOWTO Access Samba source code via CVS

      10.1. Introduction

      Samba is developed in an open environnment. Developers use CVS +(Concurrent Versioning System) to "checkin" (also known as +"commit") new source code. Samba's various CVS branches can +be accessed via anonymouns CVS using the instructions +detailed in this chapter.

      This document is a modified version of the instructions found at +http://samba.org/samba/cvs.html


      10.2. CVS Access to samba.org

      The machine samba.org runs a publicly accessible CVS +repository for access to the source code of several packages, +including samba, rsync and jitterbug. There are two main ways of +accessing the CVS server on this host.


      10.2.1. Access via CVSweb

      You can access the source code via your +favourite WWW browser. This allows you to access the contents of +individual files in the repository and also to look at the revision +history and commit logs of individual files. You can also ask for a diff +listing between any two versions on the repository.

      Use the URL : http://samba.org/cgi-bin/cvsweb


      10.2.2. Access via cvs

      You can also access the source code via a +normal cvs client. This gives you much more control over you can +do with the repository and allows you to checkout whole source trees +and keep them uptodate via normal cvs commands. This is the +preferred method of access if you are a developer and not +just a casual browser.

      To download the latest cvs source code, point your +browser at the URL : http://www.cyclic.com/. +and click on the 'How to get cvs' link. CVS is free software under +the GNU GPL (as is Samba). Note that there are several graphical CVS clients +which provide a graphical interface to the sometimes mundane CVS commands. +Links to theses clients are also available from http://www.cyclic.com.

      To gain access via anonymous cvs use the following steps. +For this example it is assumed that you want a copy of the +samba source code. For the other source code repositories +on this system just substitute the correct package name

      1. Install a recent copy of cvs. All you really need is a + copy of the cvs client binary. +

      2. Run the command +

        cvs -d :pserver:cvs@samba.org:/cvsroot login +

        When it asks you for a password type cvs. +

      3. Run the command +

        cvs -d :pserver:cvs@samba.org:/cvsroot co samba +

        This will create a directory called samba containing the + latest samba source code (i.e. the HEAD tagged cvs branch). This + currently corresponds to the 3.0 development tree. +

        CVS branches other HEAD can be obtained by using the -r + and defining a tag name. A list of branch tag names can be found on the + "Development" page of the samba web site. A common request is to obtain the + latest 2.2 release code. This could be done by using the following command. +

        cvs -d :pserver:cvs@samba.org:/cvsroot co -r SAMBA_2_2 samba +

      4. Whenever you want to merge in the latest code changes use + the following command from within the samba directory: +

        cvs update -d -P +

      How to Configure Samba 2.2.x as a Primary Domain ControllerHow to Configure Samba 2.2 as a Primary Domain ControllerHow to Configure Samba 2.2.x as a Primary Domain ControllerHow to Configure Samba 2.2 as a Primary Domain Controller
      Prerequisite Reading

      Before you continue readingin this chapter, please make sure +that you are comfortable with configuring basic files services +in smb.conf and how to enable and administrate password +encryption in Samba. Theses two topics are covered in the +smb.conf(5) +manpage and the Encryption chapter +of this HOWTO Collection.


      Background

      Note: Author's Note : This document -is a combination of David Bannon's Samba 2.2 PDC HOWTO -and the Samba NT Domain FAQ. Both documents are superceeded by this one.

      This document is a combination +of David Bannon's Samba 2.2 PDC HOWTO and the Samba NT Domain FAQ. +Both documents are superceeded by this one.

      Version of Samba prior to release 2.2 had marginal capabilities to -act as a Windows NT 4.0 Primary Domain Controller (PDC). The following -functionality should work in 2.2.0:

      UNIX_INSTALL.html, please make sure +that your server is configured correctly before proceeding. Another good +resource in the smb.conf(5) man +page. The following functionality should work in 2.2:

      • domain logons for Windows NT 4.0/2000 clients

        domain logons for Windows NT 4.0/2000 clients. +

      • placing a Windows 9x client in user level security

        placing a Windows 9x client in user level security +

      • retrieving a list of users and groups from a Samba PDC to - Windows 9x/NT/2000 clients

        retrieving a list of users and groups from a Samba PDC to + Windows 9x/NT/2000 clients +

      • roving user profiles

        roving (roaming) user profiles +

      • Windows NT 4.0 style system policies

        Windows NT 4.0 style system policies +

      Windows 2000 Service Pack 2 Clients

      Samba 2.2.1 is required for PDC functionality when using Windows 2000 + SP2 clients. +

      The following pieces of functionality are not included in the 2.2 release:

      • Windows NT 4 domain trusts

        Windows NT 4 domain trusts +

      • Sam replication with Windows NT 4.0 Domain Controllers - (i.e. a Samba PDC and a Windows NT BDC or vice versa)

        SAM replication with Windows NT 4.0 Domain Controllers + (i.e. a Samba PDC and a Windows NT BDC or vice versa) +

      • Adding users via the User Manager for Domains

        Adding users via the User Manager for Domains +

      • Acting as a Windows 2000 Domain Controller (i.e. Kerberos - and Active Directory)

        Acting as a Windows 2000 Domain Controller (i.e. Kerberos and + Active Directory) +

      Beginning with Samba 2.2.0, we are proud to announce official -support for Windows NT 4.0 style domain logons from Windows NT -4.0 and Windows 2000 (including SP1) clients. This article -outlines the steps necessary for configuring Samba as a PDC. -Note that it is necessary to have a working Samba server -prior to implementing the PDC functionality. If you have not -followed the steps outlined in UNIX_INSTALL.html, please make sure that your server -is configured correctly before proceeding. Another good -resource in the smb.conf(5) man -page.

      Implementing a Samba PDC can basically be divided into 2 broad steps.

    • Configuring the Samba Domain Controller +> Configuring the Samba PDC

    • Creating machine trust accounts - and joining clients to the domain

      Creating machine trust accounts and joining clients + to the domain +


    • Configuring the Samba Domain Controller

      = \\homeserver\%u ; specify a generic logon script for all users - ; this is a relative path to the [netlogon] share + ; this is a relative **DOS** path to the [netlogon] share = 0700

      There are a couple of points to emphasize in the above -configuration.

      There are a couple of points to emphasize in the above configuration.

      As Samba 2.2 does not offer a complete implementation of group mapping between Windows NT groups and UNIX groups (this is really quite complicated to explain in a short space), you should refer to the domain admin users


      Creating Machine Trust Accounts and Joining Clients to the Domain

      First you must understand what a machine trust account is and what -it is used for.

      A machine trust account is a user account owned by a computer. +>A machine trust account is a samba user account owned by a computer. The account password acts as the shared secret for secure -communication with the Domain Controller. Hence the reason that -a Windows 9x host is never a true member of a domain because -it does not posses a machine trust account and thus has no shared -secret with the DC.

      On a Windows NT PDC, these machine trust account passwords are stored -in the registry. A Samba PDC stores these accounts in he same location +in the registry. A Samba PDC stores these accounts in the same location as user LanMan and NT password hashes (currently smbpasswd). -However, machine trust accounts only possess the NT password hash.

      Because Samba requires machine accounts to possess a UNIX uid from +which an Windows NT SID can be generated, all of these accounts +must have an entry in /etc/passwd and smbpasswd. +Future releases will alleviate the need to create +/etc/passwd entries.

      There are two means of creating machine trust accounts.

      • Manual creation before joining the client - to the domain. In this case, the password is set to a known - value -- the lower case of the machine's netbios name.

        Manual creation before joining the client to the domain. In this case, + the password is set to a known value -- the lower case of the + machine's netbios name. +

      • Creation of the account at the time of - joining the domain. In this case, the session key of the - administrative account used to join the client to the domain acts - as an encryption key for setting the password to a random value.

        Creation of the account at the time of joining the domain. In + this case, the session key of the administrative account used to join + the client to the domain acts as an encryption key for setting the + password to a random value (This is the recommended method). +


      Manually creating machine trust accounts

      Because Samba requires machine accounts to possess a UNIX uid from -which an Windows NT SID can be generated, all of these accounts -will have an entry in /etc/passwd and smbpasswd. -Future releases will alleviate the need to create -/etc/passwd entries.

      The first step in creating a machine trust account by hand is to +create an entry for the machine in /etc/passwd. This can be done +using vipw or any 'add userr' command which is normally +used to create new UNIX accounts. The following is an example for a Linux +based Samba server:

      root# /usr/sbin/useradd -g 100 -d /dev/null -c machine_nickname -m -s /bin/false machine_name$

      The

      doppy$:x:505:501:NTMachine:/dev/null:/bin/false
      doppy$:x:505:501:machine_nickname:/dev/null:/bin/false

      If you are manually creating the machine accounts, it is necessary -to add the /etc/passwd (or NIS passwd -map) entry prior to adding the smbpasswd -entry. The following command will create a new machine account -ready for use.

      Above, machine_nickname can be any descriptive name for the +pc i.e. BasementComputer. The machine_name absolutely must be +the netbios name of the pc to be added to the domain. The "$" must append the netbios +name of the pc or samba will not recognize this as a machine account

      Now that the UNIX account has been created, the next step is to create +the smbpasswd entry for the machine containing the well known initial +trust account password. This can be done using the smbpasswd(8) command +as shown here:

      machine_name is the machine's netbios -name.

      If you manually create a machine account, immediately join -the client to the domain. An open account like this -can allow intruders to gain access to user account information -in your domain.

      The second way of creating machine trust accounts is to add -them on the fly at the time the client is joined to the domain. -You will need to include a value for the -

      Join the client to the domain immediately

      Manually creating a machine trust account using this method is the + equivalent of creating a machine account on a Windows NT PDC using + the "Server Manager". From the time at which the account is created + to the time which th client joins the domain and changes the password, + your domain is vulnerable to an intruder joining your domain using a + a machine with the same netbios name. A PDC inherently trusts + members of the domain and will serve out a large degree of user + information to such clients. You have been warned! +


      Creating machine trust accounts "on the fly"

      The second, and most recommended way of creating machine trust accounts +is to create them as needed at the time the client is joined to +the domain. You will need to include a value for the add user script -parameter. Below is an example I use on a RedHat 6.2 Linux system.

      add user script = /usr/sbin/useradd -d /dev/null -g 100 -s /bin/false -M %u 

      In Samba 2.2.0, In Samba 2.2.1, only the root account can be used to create -machine accounts on the fly like this. Therefore, it is required -to create an entry in smbpasswd for root. -The password . The password +SHOULD be set to s different -password that the associated be set to s different password that the +associated /etc/passwd -entry for security reasons.

      entry for security reasons.


      Common Problems and Errors

      • I cannot include a '$' in a machine name.

        +

        A 'machine name' in (typically) A 'machine name' in (typically) /etc/passwd -of the machine name with a '$' appended. FreeBSD (and other BSD -systems ?) won't create a user with a '$' in their name.

        The problem is only in the program used to make the entry, once -made, it works perfectly. So create a user without the '$' and -use The problem is only in the program used to make the entry, once + made, it works perfectly. So create a user without the '$' and + use vipw to edit the entry, adding the '$'. Or create -the whole entry with vipw if you like, make sure you use a -unique uid !

      • I get told "You already have a connection to the Domain...." -when creating a machine account.

        This happens if you try to create a machine account from the -machine itself and use a user name that does not work (for whatever -reason) and then try another (possibly valid) user name. -Exit out of the network applet to close the initial connection -and try again.

        +

        Further, if the machine is a already a 'member of a workgroup' that -is the same name as the domain you are joining (bad idea) you will -get this message. Change the workgroup name to something else, it -does not matter what, reboot, and try again.

        This happens if you try to create a machine account from the + machine itself and already have a connection (e.g. mapped drive) + to a share (or IPC$) on the Samba PDC. The following command + will remove all network drive connections: +

        I get told "Cannot join domain, the credentials supplied -conflict with an existing set.."

        C:\WINNT\> net use * /d +

        This is the same basic problem as mentioned above, "You already -have a connection..."

        Further, if the machine is a already a 'member of a workgroup' that + is the same name as the domain you are joining (bad idea) you will + get this message. Change the workgroup name to something else, it + does not matter what, reboot, and try again. +

      • "The system can not log you on (C000019B)...."

        The system can not log you on (C000019B).... +

        I joined the domain successfully but after upgrading -to a newer version of the Samba code I get the message, "The system -can not log you on (C000019B), Please try a gain or consult your -system administrator" when attempting to logon.

        This occurs when the domain SID stored in - This occurs when the domain SID stored in + private/WORKGROUP.SID is -changed. For example, you remove the file and smbd automatically -creates a new one. Or you are swapping back and forth between -versions 2.0.7, TNG and the HEAD branch code (not recommended). The -only way to correct the problem is to restore the original domain -SID or remove the domain client from the domain and rejoin.

      • The machine account for this computer either does not + exist or is not accessible. +

        When I try to join the domain I get the message "The machine account + for this computer either does not exist or is not accessible". Whats + wrong? +

        This problem is caused by the PDC not having a suitable machine account. + If you are using the add user script method to create + accounts then this would indicate that it has not worked. Ensure the domain + admin user system is working. +

        Alternatively if you are creating account entries manually then they + have not been created correctly. Make sure that you have the entry + correct for the machine account in smbpasswd file on the Samba PDC. + If you added the account using an editor rather than using the smbpasswd + utility, make sure that the account name is the machine netbios name + with a '$' appended to it ( ie. computer_name$ ). There must be an entry + in both /etc/passwd and the smbpasswd file. Some people have reported + that inconsistent subnet masks between the Samba server and the NT + client have caused this problem. Make sure that these are consistent + for both client and server. +

      • "The machine account for this computer either does not -exist or is not accessible."

        When I attempt to login to a Samba Domain from a NT4/W2K workstation, + I get a message about my account being disabled. +

        When I try to join the domain I get the message "The machine account -for this computer either does not exist or is not accessible". Whats -wrong ?

        This problem is caused by a PAM related bug in Samba 2.2.0. This bug is + fixed in 2.2.1. Other symptoms could be unaccessible shares on + NT/W2K member servers in the domain or the following error in your smbd.log: + passdb/pampass.c:pam_account(268) PAM: UNKNOWN ERROR for User: %user% +

        This problem is caused by the PDC not having a suitable machine account. -If you are using the At first be ensure to enable the useraccounts with add user script = method to create -accounts then this would indicate that it has not worked. Ensure the domain -admin user system is working.

        Alternatively if you are creating account entries manually then they -have not been created correctly. Make sure that you have the entry -correct for the machine account in smbpasswd file on the Samba PDC. -If you added the account using an editor rather than using the smbpasswd -utility, make sure that the account name is the machine netbios name -with a '$' appended to it ( ie. computer_name$ ). There must be an entry -in both /etc/passwd and the smbpasswd file. Some people have reported -that inconsistent subnet masks between the Samba server and the NT -client have caused this problem. Make sure that these are consistent -for both client and server.

        smbpasswd -e + %user%, this is normaly done, when you create an account. +

        In order to work around this problem in 2.2.0, configure the + account control flag in + /etc/pam.d/samba file as follows: +

        	account required        pam_permit.so
        +	

        If you want to remain backward compatibility to samba 2.0.x use + pam_permit.so, it's also possible to use + pam_pwdb.so. There are some bugs if you try to + use pam_unix.so, if you need this, be ensure to use + the most recent version of this file. +


      System Policies and Profiles

      Here are some additional details:

      • What about Windows NT Policy Editor ?

        +

        To create or edit To create or edit ntconfig.pol you must use -the NT Server Policy Editor, poledit.exe which -is included with NT Server but not NT Workstation. -There is a Policy Editor on a NTws -but it is not suitable for creating Domain Policies. -Further, although the Windows 95 -Policy Editor can be installed on an NT Workstation/Server, it will not -work with NT policies because the registry key that are set by the policy templates. -However, the files from the NT Server will run happily enough on an NTws. -You need poledit.exe, common.adm and winnt.adm. It is convenient -to put the two *.adm files in c:\winnt\inf which is where -the binary will look for them unless told otherwise. Note also that that -directory is 'hidden'.

        The Windows NT policy editor is also included with the -Service Pack 3 (and later) for Windows NT 4.0. Extract the files using - The Windows NT policy editor is also included with the Service Pack 3 (and + later) for Windows NT 4.0. Extract the files using servicepackname /x, ie thats , + ie thats Nt4sp6ai.exe -/x for service pack 6a. The policy editor, Nt4sp6ai.exe /x for service pack 6a. The policy editor, + poledit.exe and the -associated template files (*.adm) should -be extracted as well. It is also possible to downloaded the policy template -files for Office97 and get a copy of the policy editor. Another possible -location is with the Zero Administration Kit available for download from Microsoft.

        and the associated template files (*.adm) should + be extracted as well. It is also possible to downloaded the policy template + files for Office97 and get a copy of the policy editor. Another possible + location is with the Zero Administration Kit available for download from Microsoft. +

      • Can Win95 do Policies ?

        +

        Install the group policy handler for Win9x to pick up group -policies. Look on the Win98 CD in Install the group policy handler for Win9x to pick up group + policies. Look on the Win98 CD in \tools\reskit\netadmin\poledit. -Install group policies on a Win9x client by double-clicking -grouppol.inf. Log off and on again a couple of -times and see if Win98 picks up group policies. Unfortunately this needs -to be done on every Win9x machine that uses group policies....

        If group policies don't work one reports suggests getting the updated -(read: working) grouppol.dll for Windows 9x. The group list is grabbed -from /etc/group.

        If group policies don't work one reports suggests getting the updated + (read: working) grouppol.dll for Windows 9x. The group list is grabbed + from /etc/group. +

      • How do I get 'User Manager' and 'Server Manager'

        +

        Since I don't need to buy an NT Server CD now, how do I get -the 'User Manager for Domains', the 'Server Manager' ?

        Since I don't need to buy an NT Server CD now, how do I get + the 'User Manager for Domains', the 'Server Manager' ? +

        Microsoft distributes a version of -these tools called nexus for installation on Windows 95 systems. The -tools set includes

        Microsoft distributes a version of these tools called nexus for + installation on Windows 95 systems. The tools set includes +

          Click here to download the archived file Click here to download the archived file ftp://ftp.microsoft.com/Softlib/MSLFILES/NEXUS.EXE

          +

          The Windows NT 4.0 version of the 'User Manager for -Domains' and 'Server Manager' are available from Microsoft via ftp -from The Windows NT 4.0 version of the 'User Manager for + Domains' and 'Server Manager' are available from Microsoft via ftp + from ftp://ftp.microsoft.com/Softlib/MSLFILES/SRVTOOLS.EXE

          +


        What other help can I get ?

        • What are some diagnostics tools I can use to debug the domain logon -process and where can I find them?

          +

          One of the best diagnostic tools for debugging problems is Samba itself. You can use the -d option for both smbd and nmbd to specifiy what @@ -812,7 +1075,7 @@ CLASS="COMMAND" >

        An SMB enabled version of tcpdump is available from - http://www.tcpdup.org/

      • How do I install 'Network Monitor' on an NT Workstation -or a Windows 9x box?

        +

        Installing netmon on an NT workstation requires a couple of steps. The following are for installing Netmon V4.00.349, which comes @@ -935,14 +1201,11 @@ CLASS="FILENAME" information on how to do this. Copy the files from a working Netmon installation.

      • The following is a list if helpful URLs and other links: +


      • Mailing Lists

        • How do I get help from the mailing lists ?

          +

          There are a number of Samba related mailing lists. Go to There are a number of Samba related mailing lists. Go to http://samba.org, click on your nearest mirror -and then click on Support and then click on Samba related mailing lists.

          Samba related mailing lists
          . +

          For questions relating to Samba TNG go to - For questions relating to Samba TNG go to + http://www.samba-tng.org/ -It has been requested that you don't post questions about Samba-TNG to the -main stream Samba lists.

          If you post a message to one of the lists please observe the following guide lines :

          If you post a message to one of the lists please observe the following guide lines : +

          • How do I get off the mailing lists ?

            +

            To have your name removed from a samba mailing list, go to the - same place you went to to get on it. Go to http://lists.samba.org, click - on your nearest mirror and then click on , + click on your nearest mirror and then click on Support and - then click on Samba related mailing lists. Or perhaps see - here

            +

            Please don't post messages to the list asking to be removed, you will just - be referred to the above address (unless that process failed in some way...) -


          Domain Control for Windows 9x/ME

          Note: The following section contains much of the original +DOMAIN.txt file previously included with Samba. Much of +the material is based on what went into the book Special +Edition, Using Samba. (Richard Sharpe)

          A domain and a workgroup are exactly the same thing in terms of network +browsing. The difference is that a distributable authentication +database is associated with a domain, for secure login access to a +network. Also, different access rights can be granted to users if they +successfully authenticate against a domain logon server (NT server and +other systems based on NT server support this, as does at least Samba TNG now).

          The SMB client logging on to a domain has an expectation that every other +server in the domain should accept the same authentication information. +Network browsing functionality of domains and workgroups is +identical and is explained in BROWSING.txt. It should be noted, that browsing +is total orthogonal to logon support.

          Issues related to the single-logon network model are discussed in this +document. Samba supports domain logons, network logon scripts, and user +profiles for MS Windows for workgroups and MS Windows 9X clients.

          When an SMB client in a domain wishes to logon it broadcast requests for a +logon server. The first one to reply gets the job, and validates its +password using whatever mechanism the Samba administrator has installed. +It is possible (but very stupid) to create a domain where the user +database is not shared between servers, ie they are effectively workgroup +servers advertising themselves as participating in a domain. This +demonstrates how authentication is quite different from but closely +involved with domains.

          Another thing commonly associated with single-logon domains is remote +administration over the SMB protocol. Again, there is no reason why this +cannot be implemented with an underlying username database which is +different from the Windows NT SAM. Support for the Remote Administration +Protocol is planned for a future release of Samba.

          Network logon support as discussed in this section is aimed at Window for +Workgroups, and Windows 9X clients.

          Support for profiles is confirmed as working for Win95, NT 4.0 and NT 3.51. +It is possible to specify: the profile location; script file to be loaded +on login; the user's home directory; and for NT a kick-off time could also +now easily be supported. However, there are some differences between Win9X +profile support and WinNT profile support. These are discussed below.

          With NT Workstations, all this does not require the use or intervention of +an NT 4.0 or NT 3.51 server: Samba can now replace the logon services +provided by an NT server, to a limited and experimental degree (for example, +running "User Manager for Domains" will not provide you with access to +a domain created by a Samba Server).

          With Win95, the help of an NT server can be enlisted, both for profile storage +and for user authentication. For details on user authentication, see +security_level.txt. For details on profile storage, see below.

          Using these features you can make your clients verify their logon via +the Samba server; make clients run a batch file when they logon to +the network and download their preferences, desktop and start menu.

          Before launching into the configuration instructions, it is worthwhile looking +at how a Win9X client performs a logon:

          1. The client broadcasts (to the IP broadcast address of the subnet it is in) + a NetLogon request. This is sent to the NetBIOS address DOMAIN<00> at the + NetBIOS layer. The client chooses the first response it receives, which + contains the NetBIOS name of the logon server to use in the format of + \\SERVER. +

          2. The client then connects to that server, logs on (does an SMBsessetupX) and + then connects to the IPC$ share (using an SMBtconX). +

          3. The client then does a NetWkstaUserLogon request, which retrieves the name + of the user's logon script. +

          4. The client then connects to the NetLogon share and searches for this + and if it is found and can be read, is retrieved and executed by the client. + After this, the client disconnects from the NetLogon share. +

          5. The client then sends a NetUserGetInfo request to the server, to retrieve + the user's home share, which is used to search for profiles. Since the + response to the NetUserGetInfo request does not contain much more + the user's home share, profiles for Win9X clients MUST reside in the user + home directory. +

          6. The client then connects to the user's home share and searches for the + user's profile. As it turns out, you can specify the users home share as + a sharename and path. For example, \\server\fred\.profile. + If the profiles are found, they are implemented. +

          7. The client then disconnects from the user's home share, and reconnects to + the NetLogon share and looks for CONFIG.POL, the policies file. If this is + found, it is read and implemented. +


          Configuration Instructions: Network Logons

          To use domain logons and profiles you need to do the following:

          1. Create a share called [netlogon] in your smb.conf. This share should + be readable by all users, and probably should not be writeable. This + share will hold your network logon scripts, and the CONFIG.POL file + (Note: for details on the CONFIG.POL file, how to use it, what it is, + refer to the Microsoft Windows NT Administration documentation. + The format of these files is not known, so you will need to use + Microsoft tools). +

            For example I have used: +

            [netlogon]
            +     path = /data/dos/netlogon
            +     writeable = no
            +     guest ok = no

            Note that it is important that this share is not writeable by ordinary + users, in a secure environment: ordinary users should not be allowed + to modify or add files that another user's computer would then download + when they log in. +

          2. in the [global] section of smb.conf set the following: +

            domain logons = yes
            +logon script = %U.bat
            +	

            The choice of batch file is, of course, up to you. The above would + give each user a separate batch file as the %U will be changed to + their username automatically. The other standard % macros may also be + used. You can make the batch files come from a subdirectory by using + something like: +

            logon script = scripts\%U.bat
            +	

          3. create the batch files to be run when the user logs in. If the batch + file doesn't exist then no batch file will be run. +

            In the batch files you need to be careful to use DOS style cr/lf line + endings. If you don't then DOS may get confused. I suggest you use a + DOS editor to remotely edit the files if you don't know how to produce + DOS style files under unix. +

          4. Use smbclient with the -U option for some users to make sure that + the \\server\NETLOGON share is available, the batch files are + visible and they are readable by the users. +

          5. you will probabaly find that your clients automatically mount the + \\SERVER\NETLOGON share as drive z: while logging in. You can put + some useful programs there to execute from the batch files. +

          security mode and master browsers

          There are a few comments to make in order to tie up some +loose ends. There has been much debate over the issue of whether +or not it is ok to configure Samba as a Domain Controller in security +modes other than USER. The only security mode +which will not work due to technical reasons is SHARE +mode security. DOMAIN and SERVER +mode security is really just a variation on SMB user level security.

          Actually, this issue is also closer tied to the debate on whether +or not Samba must be the domain master browser for its workgroup +when operating as a DC. While it may technically be possible +to configure a server as such (after all, browsing and domain logons +are two distinctly different functions), it is not a good idea to +so. You should remember that the DC must register the DOMAIN#1b netbios +name. This is the name used by Windows clients to locate the DC. +Windows clients do not distinguish between the DC and the DMB. +For this reason, it is very wise to configure the Samba DC as the DMB.

          Now back to the issue of configuring a Samba DC to use a mode other +than "security = user". If a Samba host is configured to use +another SMB server or DC in order to validate user connection +requests, then it is a fact that some other machine on the network +(the "password server") knows more about user than the Samba host. +99% of the time, this other host is a domain controller. Now +in order to operate in domain mode security, the "workgroup" parameter +must be set to the name of the Windows NT domain (which already +has a domain controller, right?)

          Therefore configuring a Samba box as a DC for a domain that +already by definition has a PDC is asking for trouble. +Therefore, you should always configure the Samba DC to be the DMB +for its domain.


          Configuration Instructions: Setting up Roaming User Profiles

          Warning

          NOTE! Roaming profiles support is different +for Win9X and WinNT.

          Before discussing how to configure roaming profiles, it is useful to see how +Win9X and WinNT clients implement these features.

          Win9X clients send a NetUserGetInfo request to the server to get the user's +profiles location. However, the response does not have room for a separate +profiles location field, only the users home share. This means that Win9X +profiles are restricted to being in the user's home directory.

          WinNT clients send a NetSAMLogon RPC request, which contains many fields, +including a separate field for the location of the user's profiles. +This means that support for profiles is different for Win9X and WinNT.


          Windows NT Configuration

          To support WinNT clients, inn the [global] section of smb.conf set the +following (for example):

          logon path = \\profileserver\profileshare\profilepath\%U\moreprofilepath

          The default for this option is \\%N\%U\profile, namely +\\sambaserver\username\profile. The \\N%\%U service is created +automatically by the [homes] service. +If you are using a samba server for the profiles, you _must_ make the +share specified in the logon path browseable.

          Note: [lkcl 26aug96 - we have discovered a problem where Windows clients can +maintain a connection to the [homes] share in between logins. The +[homes] share must NOT therefore be used in a profile path.]


          Windows 9X Configuration

          To support Win9X clients, you must use the "logon home" parameter. Samba has +now been fixed so that "net use/home" now works as well, and it, too, relies +on the "logon home" parameter.

          By using the logon home parameter, you are restricted to putting Win9X +profiles in the user's home directory. But wait! There is a trick you +can use. If you set the following in the [global] section of your +smb.conf file:

          logon home = \\%L\%U\.profiles

          then your Win9X clients will dutifully put their clients in a subdirectory +of your home directory called .profiles (thus making them hidden).

          Not only that, but 'net use/home' will also work, because of a feature in +Win9X. It removes any directory stuff off the end of the home directory area +and only uses the server and share portion. That is, it looks like you +specified \\%L\%U for "logon home".


          Win9X and WinNT Configuration

          You can support profiles for both Win9X and WinNT clients by setting both the +"logon home" and "logon path" parameters. For example:

          logon home = \\%L\%U\.profiles
          +logon path = \\%L\profiles\%U

          Note: I have not checked what 'net use /home' does on NT when "logon home" is +set as above.


          Windows 9X Profile Setup

          When a user first logs in on Windows 9X, the file user.DAT is created, +as are folders "Start Menu", "Desktop", "Programs" and "Nethood". +These directories and their contents will be merged with the local +versions stored in c:\windows\profiles\username on subsequent logins, +taking the most recent from each. You will need to use the [global] +options "preserve case = yes", "short case preserve = yes" and +"case sensitive = no" in order to maintain capital letters in shortcuts +in any of the profile folders.

          The user.DAT file contains all the user's preferences. If you wish to +enforce a set of preferences, rename their user.DAT file to user.MAN, +and deny them write access to this file.

          1. On the Windows 95 machine, go to Control Panel | Passwords and + select the User Profiles tab. Select the required level of + roaming preferences. Press OK, but do _not_ allow the computer + to reboot. +

          2. On the Windows 95 machine, go to Control Panel | Network | + Client for Microsoft Networks | Preferences. Select 'Log on to + NT Domain'. Then, ensure that the Primary Logon is 'Client for + Microsoft Networks'. Press OK, and this time allow the computer + to reboot. +

          Under Windows 95, Profiles are downloaded from the Primary Logon. +If you have the Primary Logon as 'Client for Novell Networks', then +the profiles and logon script will be downloaded from your Novell +Server. If you have the Primary Logon as 'Windows Logon', then the +profiles will be loaded from the local machine - a bit against the +concept of roaming profiles, if you ask me.

          You will now find that the Microsoft Networks Login box contains +[user, password, domain] instead of just [user, password]. Type in +the samba server's domain name (or any other domain known to exist, +but bear in mind that the user will be authenticated against this +domain and profiles downloaded from it, if that domain logon server +supports it), user name and user's password.

          Once the user has been successfully validated, the Windows 95 machine +will inform you that 'The user has not logged on before' and asks you +if you wish to save the user's preferences? Select 'yes'.

          Once the Windows 95 client comes up with the desktop, you should be able +to examine the contents of the directory specified in the "logon path" +on the samba server and verify that the "Desktop", "Start Menu", +"Programs" and "Nethood" folders have been created.

          These folders will be cached locally on the client, and updated when +the user logs off (if you haven't made them read-only by then :-). +You will find that if the user creates further folders or short-cuts, +that the client will merge the profile contents downloaded with the +contents of the profile directory already on the local client, taking +the newest folders and short-cuts from each set.

          If you have made the folders / files read-only on the samba server, +then you will get errors from the w95 machine on logon and logout, as +it attempts to merge the local and the remote profile. Basically, if +you have any errors reported by the w95 machine, check the unix file +permissions and ownership rights on the profile directory contents, +on the samba server.

          If you have problems creating user profiles, you can reset the user's +local desktop cache, as shown below. When this user then next logs in, +they will be told that they are logging in "for the first time".

          1. instead of logging in under the [user, password, domain] dialog, + press escape. +

          2. run the regedit.exe program, and look in: +

            HKEY_LOCAL_MACHINE\Windows\CurrentVersion\ProfileList +

            you will find an entry, for each user, of ProfilePath. Note the + contents of this key (likely to be c:\windows\profiles\username), + then delete the key ProfilePath for the required user. +

            [Exit the registry editor]. +

          3. WARNING - before deleting the contents of the + directory listed in + the ProfilePath (this is likely to be c:\windows\profiles\username), + ask them if they have any important files stored on their desktop + or in their start menu. delete the contents of the directory + ProfilePath (making a backup if any of the files are needed). +

            This will have the effect of removing the local (read-only hidden + system file) user.DAT in their profile directory, as well as the + local "desktop", "nethood", "start menu" and "programs" folders. +

          4. search for the user's .PWL password-cacheing file in the c:\windows + directory, and delete it. +

          5. log off the windows 95 client. +

          6. check the contents of the profile path (see "logon path" described + above), and delete the user.DAT or user.MAN file for the user, + making a backup if required. +

          If all else fails, increase samba's debug log levels to between 3 and 10, +and / or run a packet trace program such as tcpdump or netmon.exe, and +look for any error reports.

          If you have access to an NT server, then first set up roaming profiles +and / or netlogons on the NT server. Make a packet trace, or examine +the example packet traces provided with NT server, and see what the +differences are with the equivalent samba trace.


          Windows NT Workstation 4.0

          When a user first logs in to a Windows NT Workstation, the profile +NTuser.DAT is created. The profile location can be now specified +through the "logon path" parameter.

          Note: [lkcl 10aug97 - i tried setting the path to +\\samba-server\homes\profile, and discovered that this fails because +a background process maintains the connection to the [homes] share +which does _not_ close down in between user logins. you have to +have \\samba-server\%L\profile, where user is the username created +from the [homes] share].

          There is a parameter that is now available for use with NT Profiles: +"logon drive". This should be set to "h:" or any other drive, and +should be used in conjunction with the new "logon home" parameter.

          The entry for the NT 4.0 profile is a _directory_ not a file. The NT +help on profiles mentions that a directory is also created with a .PDS +extension. The user, while logging in, must have write permission to +create the full profile path (and the folder with the .PDS extension) +[lkcl 10aug97 - i found that the creation of the .PDS directory failed, +and had to create these manually for each user, with a shell script. +also, i presume, but have not tested, that the full profile path must +be browseable just as it is for w95, due to the manner in which they +attempt to create the full profile path: test existence of each path +component; create path component].

          In the profile directory, NT creates more folders than 95. It creates +"Application Data" and others, as well as "Desktop", "Nethood", +"Start Menu" and "Programs". The profile itself is stored in a file +NTuser.DAT. Nothing appears to be stored in the .PDS directory, and +its purpose is currently unknown.

          You can use the System Control Panel to copy a local profile onto +a samba server (see NT Help on profiles: it is also capable of firing +up the correct location in the System Control Panel for you). The +NT Help file also mentions that renaming NTuser.DAT to NTuser.MAN +turns a profile into a mandatory one.

          Note: [lkcl 10aug97 - i notice that NT Workstation tells me that it is +downloading a profile from a slow link. whether this is actually the +case, or whether there is some configuration issue, as yet unknown, +that makes NT Workstation _think_ that the link is a slow one is a +matter to be resolved].

          [lkcl 20aug97 - after samba digest correspondance, one user found, and +another confirmed, that profiles cannot be loaded from a samba server +unless "security = user" and "encrypt passwords = yes" (see the file +ENCRYPTION.txt) or "security = server" and "password server = ip.address. +of.yourNTserver" are used. either of these options will allow the NT +workstation to access the samba server using LAN manager encrypted +passwords, without the user intervention normally required by NT +workstation for clear-text passwords].

          [lkcl 25aug97 - more comments received about NT profiles: the case of +the profile _matters_. the file _must_ be called NTuser.DAT or, for +a mandatory profile, NTuser.MAN].


          Windows NT Server

          There is nothing to stop you specifying any path that you like for the +location of users' profiles. Therefore, you could specify that the +profile be stored on a samba server, or any other SMB server, as long as +that SMB server supports encrypted passwords.


          Sharing Profiles between W95 and NT Workstation 4.0

          Potentially outdated or incorrect material follows

          I think this is all bogus, but have not deleted it. (Richard Sharpe)

          The default logon path is \\%N\U%. NT Workstation will attempt to create +a directory "\\samba-server\username.PDS" if you specify the logon path +as "\\samba-server\username" with the NT User Manager. Therefore, you +will need to specify (for example) "\\samba-server\username\profile". +NT 4.0 will attempt to create "\\samba-server\username\profile.PDS", which +is more likely to succeed.

          If you then want to share the same Start Menu / Desktop with W95, you will +need to specify "logon path = \\samba-server\username\profile" [lkcl 10aug97 +this has its drawbacks: i created a shortcut to telnet.exe, which attempts +to run from the c:\winnt\system32 directory. this directory is obviously +unlikely to exist on a Win95-only host].

          If you have this set up correctly, you will find separate user.DAT and +NTuser.DAT files in the same profile directory.

          Note: [lkcl 25aug97 - there are some issues to resolve with downloading of +NT profiles, probably to do with time/date stamps. i have found that +NTuser.DAT is never updated on the workstation after the first time that +it is copied to the local workstation profile directory. this is in +contrast to w95, where it _does_ transfer / update profiles correctly].


          DOMAIN_CONTROL.txt : Windows NT Domain Control & Samba

          This appendix was originally authored by John H Terpstra of the Samba Team -and is included here for posterity.

          Possibly Outdated Material

          This appendix was originally authored by John H Terpstra of + the Samba Team and is included here for posterity. +

          Windows NT Server can be installed as either a plain file and print server (WORKGROUP workstation or server) or as a server that participates in Domain -Control (DOMAIN member, Primary Domain controller or Backup Domain controller).

          The same is true for OS/2 Warp Server, Digital Pathworks and other similar -products, all of which can participate in Domain Control along with Windows NT. -However only those servers which have licensed Windows NT code in them can be -a primary Domain Controller (eg Windows NT Server, Advanced Server for Unix.)

          To many people these terms can be confusing, so let's try to clear the air.

          make_smbcodepage

          inputfile

          This is the input file to process. In t - he 'This is the input file to process. In + the c' case this will be a text +> case this will be a text codepage definition file such as the ones found in the Samba source/codepages directory. In - the 'd' case this will be the +> case this will be the binary format codepage definition file normally found in the make_unicodemap

          make_unicodemap

          Name

          make_unicodemap -- construct a unicode map file for Samba

          Synopsis

          make_unicodemap {codepage} {inputfile} {outputfile}

          DESCRIPTION

          This tool is part of the Samba + suite. +

          make_unicodemap compiles text unicode map + files into binary unicodef map files for use with the + internationalization features of Samba 2.2. +

          OPTIONS

          codepage

          This is the codepage or UNIX character + set we are processing (a number, e.g. 850). +

          inputfile

          This is the input file to process. This is a + text unicode map file such as the ones found in the Samba + source/codepages directory. +

          outputfile

          This is the binary output file to produce. +

          Samba Unicode Map Files

          A text Samba unicode map file is a description that tells Samba + how to map characters from a specified DOS code page or UNIX character + set to 16 bit unicode. +

          A binary Samba unicode map file is a binary representation + of the same information, including a value that specifies what + codepage or UNIX character set this file is describing. +

          Files

          CP<codepage>.TXT

          These are the input (text) unicode map files provided + in the Samba source/codepages + directory. +

          A text unicode map file consists of multiple lines + containing two fields. These fields are : +

          • character - which is + the (hex) character mapped on this line. +

          • unicode - which + is the (hex) 16 bit unicode character that the character + will map to. +

          unicode_map.<codepage> - These are + the output (binary) unicode map files produced and placed in + the Samba destination lib/codepage + directory. +

          Installation

          The location of the server and its support files is a matter + for individual system administrators. The following are thus + suggestions only. +

          It is recommended that the make_unicodemap + program be installed under the + $prefix/samba hierarchy, + in a directory readable by all, writeable only by root. The + program itself should be executable by all. The program + should NOT be setuid or setgid! +

          VERSION

          This man page is correct for version 2.2 of + the Samba suite.

          SEE ALSO

          smbd(8), + smb.conf(5) +

          AUTHOR

          The original Samba software and related utilities + were created by Andrew Tridgell. Samba is now developed + by the Samba Team as an Open Source project similar + to the way the Linux kernel is developed.

          The original Samba man pages were written by Karl Auer. + The man page sources were converted to YODL format (another + excellent piece of Open Source software, available at + ftp://ftp.icce.rug.nl/pub/unix/) and updated for the Samba 2.0 + release by Jeremy Allison. The conversion to DocBook for + Samba 2.2 was done by Gerald Carter

          \ No newline at end of file diff --git a/docs/htmldocs/printer_driver2.html b/docs/htmldocs/printer_driver2.html index ac845b84334..c44d9c5bf81 100644 --- a/docs/htmldocs/printer_driver2.html +++ b/docs/htmldocs/printer_driver2.html @@ -83,23 +83,61 @@ TARGET="_top" information

          There has been some initial confusion about what all this means +and whether or not it is a requirement for printer drivers to be +installed on a Samba host in order to support printing from Windows +clients. A bug existed in Samba 2.2.0 which made Windows NT/2000 clients +require that the Samba server possess a valid driver for the printer. +This is fixed in Samba 2.2.1 and once again, Windows NT/2000 clients +can use the local APW for installing drivers to be used with a Samba +served printer. This is the same behavior exhibited by Windows 9x clients. +As a side note, Samba does not use these drivers in any way to process +spooled files. They are utilized entirely by the clients.

          The following MS KB article, may be of some help if you are dealing with +Windows 2000 clients: How to Add Printers with No User +Interaction in Windows 2000

          http://support.microsoft.com/support/kb/articles/Q189/1/05.ASP


          Configuration

          WARNING!!! Previous versions of Samba -recommended using a share named [printer$]. This name was taken from the -printer$ service created by Windows 9x clients when a -printer was shared. Windows 9x printer servers always have +>

          [print$] vs. [printer$]

          Previous versions of Samba recommended using a share named [printer$]. +This name was taken from the printer$ service created by Windows 9x +clients when a printer was shared. Windows 9x printer servers always have a printer$ service which provides read-only access via no password in order to support printer driver downloads.

          These parameters, including printer driver +>printer driver file parameter, are being depreciated and should not be used in new installations. For more information on this change, you should refer to the Migration section of this document.

          Migration section +of this document.


          Creating [print$]

          smb.conf(5) man page for more information on -configuring file shares.

          smb.conf(5) +man page for more information on configuring file shares.

          The requirement for guest ok = yesguest +ok = yes depends upon how your site is configured. If users will be guaranteed to have @@ -257,26 +306,26 @@ ALIGN="CENTER" ALIGN="LEFT" >

          In order to currently add a new driver to you Samba host, - one of two conditions must hold true:

          • The account used to connect to the Samba host - must have a uid of 0 (i.e. a root account)

          • The account used to connect to the Samba host - must be a member of the printer - admin list.

          Of course, the connected account must still possess access - to add files to the subdirectories beneath [print$].


          Setting Drivers for Existing Printers

          The initial listing of printers in the Samba host's -Printers folder will have no printer driver assigned to them. -The way assign a driver to a printer is to view the Properties -of the printer and either

          NO PRINTER DRIVER AVAILABLE FOR THIS PRINTER
          . +Later versions changed this to a NULL string to allow the use +tof the local Add Printer Wizard on NT/2000 clients. +Attempting to view the printer properties for a printer +which has this default driver assigned will result in +the error message:

          Device settings cannot be displayed. The driver +for the specified printer is not installed, only spooler +properties will be displayed. Do you want to install the +driver now?

          Click "No" in the error dialog and you will be presented with +the printer properties window. The way assign a driver to a +printer is to either


            Support a large number of printers

            $ rpcclient pogo -U root%bleaK.er \ +>rpcclient pogo -U root%secret \ >


            Adding New Printers via the Windows NT APW

            printer admin. +>).

          • addprinter -commandadd +printer command must have a defined value. The program @@ -499,7 +569,7 @@ CLASS="COMMAND" CLASS="PARAMETER" >add printer -program and reparse to the add printer program is executed undet the context +> is executed under the context of the connected user, not necessarily a root account.

            There is a complementing deleteprinter -commanddelete +printer command for removing entries from the "Printers..." @@ -533,7 +603,7 @@ CLASS="SECT2" >


            Samba and Printer Ports


            The Imprints Toolset


            What is Imprints?


            Creating Printer Driver Packages


            The Imprints server


            The Installation Client

            will reveal that Windows NT always uses the NT driver - name. The is ok as Windows NT always requires that at least + name. This is ok as Windows NT always requires that at least the Windows NT version of the printer driver is present. However, Samba does not have the requirement internally. Therefore, how can you use the NT driver name if is has not @@ -751,18 +821,61 @@ CLASS="SECT1" >


            Migration to from Samba 2.0.x to - 2.2.xMigration to from Samba 2.0.x to 2.2.x

            Given that printer driver management has changed - (we hope improved :) ) in 2.2.0 over prior releases, - migration from an existing setup to 2.2.0 can follow - several paths.

            Given that printer driver management has changed (we hope improved) in +2.2 over prior releases, migration from an existing setup to 2.2 can +follow several paths.

            Windows clients have a tendency to remember things for quite a while. +For example, if a Windows NT client has attached to a Samba 2.0 server, +it will remember the server as a LanMan printer server. Upgrading +the Samba host to 2.2 makes support for MSRPC printing possible, but +the NT client will still remember the previous setting.

            In order to give an NT client printing "amesia" (only necessary if you +want to use the newer MSRPC printing functionality in Samba), delete +the registry keys associated with the print server contained in +[HKLM\SYSTEM\CurrentControlSet\Control\Print]. The +spooler service on the client should be stopped prior to doing this:

            C:\WINNT\ > net stop spooler

            All the normal disclaimers about editing the registry go +here. Be careful, and know what you are doing.

            The spooler service should be restarted after you have finished +removing the appropriate registry entries by replacing the +stop command above with start.

            Windows 9x clients will continue to use LanMan printing calls +with a 2.2 Samba server so there is no need to perform any of these +modifications on non-NT clients.

            The following smb.conf parameters are considered to be - depreciated and will be removed soon. Do not use them - in new installations

            The following smb.conf parameters are considered to be depreciated and will +be removed soon. Do not use them in new installations

              printer driver file (G) -

            • printer driver (S) -

            • printer driver location (S) -

          • If you do not desire the new Windows NT - print driver support, nothing needs to be done. - All existing parameters work the same.

          • If you want to take advantage of NT printer - driver support but do not want to migrate the - 9x drivers to the new setup, the leave the existing - printers.def file. When smbd attempts to locate a - 9x driver for the printer in the TDB and fails it - will drop down to using the printers.def (and all - associated parameters). The make_printerdef - tool will also remain for backwards compatibility but will - be moved to the "this tool is the old way of doing it" - pile.

          • If you install a Windows 9x driver for a printer - on your Samba host (in the printing TDB), this information will - take precedence and the three old printing parameters - will be ignored (including print driver location).

          • printers.def - file into the new setup, the current only - solution is to use the Windows NT APW to install the NT drivers - and the 9x drivers. This can be scripted using smbclient - and and rpcclient. See the - Imprints installation client at http://imprints.sourceforge.net/ - for an example. -

          -l logbasename

          File name for log/debug files. .client will be - appended. The log file is never removed by the client. +>File name for log/debug files. The extension + '.client' will be appended. The log file is never removed + by the client.

          Set the SMB domain of the username. This - overrides the default domain which is the domain of the - server specified with the -S option. - If the domain specified is the same as the server's NetBIOS name, + overrides the default domain which is the domain defined in + smb.conf. If the domain specified is the same as the server's NetBIOS name, it causes the client to log on using the server's local SAM (as opposed to the Domain SAM).

          COMMANDS

          lookupsids

          - Resolve a list + of SIDs to usernames. +

        • lookupnames

          - Resolve s list + of usernames to SIDs. +

        • querygroupmem

        • queryaliasmem

        • querydispinfo

        • querydominfo

        • enumdomgroups

        • deldriver - Delete the + specified printer driver for all architectures. This + does not delete the actual driver files from the server, + only the entry from the server's list of drivers. +

        • enumdata - Enumerate all printer setting data stored on the server. On Windows NT clients, @@ -603,7 +641,7 @@ CLASS="COMMAND" >

          BUGS

          VERSION

          AUTHOR

        • add user scriptadd printer command

        • add share command

        • addprinter commandadd user script

        • change share command

        • delete user script

        • deleteprinter commanddelete printer command

        • dfree commanddelete share command

        • dns proxydelete user script

        • domain admin groupdfree command

        • domain admin usersdns proxy

        • domain groupsdomain admin group

        • domain guest users

        • obey pam restrictions

        • pam password change

        • COMPLETE LIST OF SERVICE PARAMETERS

          EXPLANATION OF EACH PARAMETER

          add user script (G)

          This is the full pathname to a script that will - be run AS ROOT by smbd(8) - under special circumstances described below.

          Normally, a Samba server requires that UNIX users are - created for all users accessing files on this server. For sites - that use Windows NT account databases as their primary user database - creating these users and keeping the user list in sync with the - Windows NT PDC is an onerous task. This option allows smbd to create the required UNIX users - ON DEMAND when a user accesses the Samba server.

          In order to use this option, smbd - must be set to security=server or security=domain and add user script - must be set to a full pathname for a script that will create a UNIX - user given one argument of %u, which expands into - the UNIX user name to create.

          When the Windows user attempts to access the Samba server, - at login (session setup in the SMB protocol) time, smbd contacts the password server and - attempts to authenticate the given user with the given password. If the - authentication succeeds then smbd - attempts to find a UNIX user in the UNIX password database to map the - Windows user into. If this lookup fails, and add user script - is set then smbd will - call the specified script AS ROOT, expanding - any %u argument to be the user name to create.

          If this script successfully creates the user then smbd - will continue on as though the UNIX user - already existed. In this way, UNIX users are dynamically created to - match existing Windows NT accounts.

          See also security, password server, - delete user - script.

          Default: add user script = <empty string> -

          Example: add user script = /usr/local/samba/bin/add_user - %u

          addprinter command (G)
          add printer command (G)

          With the introduction of MS-RPC based printing @@ -4348,7 +4227,8 @@ NAME="ADDPRINTERCOMMAND" physically added to underlying printing system. The addprinter commandadd + printer command defines a script to be run which will perform the necessary operations for adding the printer @@ -4370,7 +4250,7 @@ CLASS="COMMAND" >The addprinter commandadd printer command is automatically invoked with the following parameter (in @@ -4444,7 +4324,7 @@ CLASS="PARAMETER" >Once the addprinter commandadd printer command has been executed, deleteprinter command delete printer command,

          admin users (S)
          add share command (G)

          This is a list of users who will be granted - administrative privileges on the share. This means that they - will do all file operations as the super-user (root).

          You should use this option very carefully, as any user in - this list will be able to do anything they like on the share, - irrespective of file permissions.

          Default: no admin users

          Example: Samba 2.2.0 introduced the ability to dynamically + add and delete shares via the Windows NT 4.0 Server Manager. The + add share command is used to define an + external program or script which will add a new service definition + to smb.conf. In order to successfully + execute the add share command, admin users = jason

          smbd + requires that the administrator be connected using a root account (i.e. + uid == 0). +

          When executed, smbd will automatically invoke the + add share command with four parameters. +

          • configFile - the location + of the global smb.conf file. +

          • shareName - the name of the new + share. +

          • pathName - path to an **existing** + directory on disk. +

          • comment - comment string to associate + with the new share. +

          This parameter is only used for add file shares. To add printer shares, + see the add printer + command. +

          See also change share + command, delete share + command. +

          Default: none

          Example: add share command = /usr/local/bin/addshare

          add user script (G)

          This is the full pathname to a script that will + be run AS ROOT by smbd(8) + under special circumstances described below.

          Normally, a Samba server requires that UNIX users are + created for all users accessing files on this server. For sites + that use Windows NT account databases as their primary user database + creating these users and keeping the user list in sync with the + Windows NT PDC is an onerous task. This option allows smbd to create the required UNIX users + ON DEMAND when a user accesses the Samba server.

          In order to use this option, smbd + must be set to security=server or security=domain and add user script + must be set to a full pathname for a script that will create a UNIX + user given one argument of %u, which expands into + the UNIX user name to create.

          When the Windows user attempts to access the Samba server, + at login (session setup in the SMB protocol) time, smbd contacts the password server and + attempts to authenticate the given user with the given password. If the + authentication succeeds then smbd + attempts to find a UNIX user in the UNIX password database to map the + Windows user into. If this lookup fails, and add user script + is set then smbd will + call the specified script AS ROOT, expanding + any %u argument to be the user name to create.

          If this script successfully creates the user then smbd + will continue on as though the UNIX user + already existed. In this way, UNIX users are dynamically created to + match existing Windows NT accounts.

          See also security, password server, + delete user + script.

          Default: add user script = <empty string> +

          Example: add user script = /usr/local/samba/bin/add_user + %u

          admin users (S)

          This is a list of users who will be granted + administrative privileges on the share. This means that they + will do all file operations as the super-user (root).

          You should use this option very carefully, as any user in + this list will be able to do anything they like on the share, + irrespective of file permissions.

          Default: no admin users

          Example: admin users = jason

          change share command (G)

          Samba 2.2.0 introduced the ability to dynamically + add and delete shares via the Windows NT 4.0 Server Manager. The + change share command is used to define an + external program or script which will modify an existing service definition + in smb.conf. In order to successfully + execute the change share command, smbd + requires that the administrator be connected using a root account (i.e. + uid == 0). +

          When executed, smbd will automatically invoke the + change share command with four parameters. +

          • configFile - the location + of the global smb.conf file. +

          • shareName - the name of the new + share. +

          • pathName - path to an **existing** + directory on disk. +

          • comment - comment string to associate + with the new share. +

          This parameter is only used modify existing file shares definitions. To modify + printer shares, use the "Printers..." folder as seen when browsing the Samba host. +

          See also add share + command, delete + share command. +

          Default: none

          Example: change share command = /usr/local/bin/addshare

          character set (G)
          parameter.

          Note that this parameter does not apply to permissions + set by Windows NT/2000 ACL editors. If the administrator wishes to enforce + a mask on access control lists also, they need to set the security mask.

          Default: create mask = 0744debuglevel (G)

          The value of the parameter (an integer) allows - the debug level (logging level) to be specified in the - smb.conf file. This is to give greater - flexibility in the configuration of the system.

          The default will be the debug level specified on - the command line or level zero if none was specified.

          Example: debug level = 3

          Synonym for log level.

          delete printer command (G)

          With the introduction of MS-RPC based printer + support for Windows NT/2000 clients in Samba 2.2, it is now + possible to delete printer at run time by issuing the + DeletePrinter() RPC call.

          For a Samba host this means that the printer must be + physically deleted from underlying printing system. The deleteprinter command defines a script to be run which + will perform the necessary operations for removing the printer + from the print system and from smb.conf. +

          The delete printer command is + automatically called with only one parameter: "printer name".

          Once the delete printer command has + been executed, smbd will reparse the smb.conf to associated printer no longer exists. + If the sharename is still valid, then smbd + will return an ACCESS_DENIED error to the client.

          See also add printer command, printing, + show add + printer wizard

          Default: none

          Example: deleteprinter command = /usr/bin/removeprinter +

          delete readonly (S)
          delete share command (G)

          Samba 2.2.0 introduced the ability to dynamically + add and delete shares via the Windows NT 4.0 Server Manager. The + delete share command is used to define an + external program or script which will remove an existing service + definition from smb.conf. In order to successfully + execute the delete share command, smbd + requires that the administrator be connected using a root account (i.e. + uid == 0). +

          When executed, smbd will automatically invoke the + delete share command with two parameters. +

          • configFile - the location + of the global smb.conf file. +

          • shareName - the name of + the existing service. +

          This parameter is only used to remove file shares. To delete printer shares, + see the delete printer + command. +

          See also delete share + command, change + share. +

          Default: none

          Example: delete share command = /usr/local/bin/delshare

          delete user script (G)
          deleteprinter command (G)

          With the introduction of MS-RPC based printer - support for Windows NT/2000 clients in Samba 2.2, it is now - possible to delete printer at run time by issuing the - DeletePrinter() RPC call.

          For a Samba host this means that the printer must be - physically deleted from underlying printing system. The deleteprinter command defines a script to be run which - will perform the necessary operations for removing the printer - from the print system and from smb.conf. -

          The deleteprinter command is - automatically called with only one parameter: "printer name".

          Once the deleteprinter command has - been executed, smbd will reparse the smb.conf to associated printer no longer exists. - If the sharename is still valid, then smbd - will return an ACCESS_DENIED error to the client.

          See also addprinter command, printing, - show add - printer wizard

          Default: none

          Example: deleteprinter command = /usr/bin/removeprinter -

          delete veto files (S)
          parameter. This parameter is set to 000 by default (i.e. no extra mode bits are added).

          Note that this parameter does not apply to permissions + set by Windows NT/2000 ACL editors. If the administrator wishes to enforce + a mask on access control lists also, they need to set the directory security mask.

          See the

          If not set explicitly this parameter is set to the same - value as the directory - mask parameter. To allow a user to - modify all the user/group/world permissions on a directory, set - this parameter to 0777.

          If not set explicitly this parameter is set to 0777 + meaning a user is allowed to modify all the user/group/world + permissions on a directory.

          Note that users who can access the Samba server through other means can easily bypass this restriction, so it is primarily useful for standalone "appliance" systems. - Administrators of most normal systems will probably want to set - it to 0777.

          See also the

          Default: directory security mask = <same as - directory mask>directory security mask = 0777

          Example: directory security mask = 0777directory security mask = 0700

          domain admin group (G)

          This is an EXPERIMENTAL parameter - that is part of the unfinished Samba NT Domain Controller Code. It may - be removed in a later release. To work with the latest code builds - that may have more support for Samba NT Domain Controller functionality - please subscribe to the mailing list samba-ntdom available by - visiting the web page at http://lists.samba.org/.

          domain admin users (G)
          This parameter is intended as a temporary solution + to enable users to be a member of the "Domain Admins" group when + a Samba host is acting as a PDC. A complete solution will be provided + by a system for mapping Windows NT/2000 groups onto UNIX groups. + Please note that this parameter has a somewhat confusing name. It + accepts a list of usernames and of group names in standard + smb.conf notation. +

          This is an EXPERIMENTAL parameter - that is part of the unfinished Samba NT Domain Controller Code. It may - be removed in a later release. To work with the latest code builds - that may have more support for Samba NT Domain Controller functionality - please subscribe to the mailing list samba-ntdom available by - visiting the web page at http://lists.samba.org/.

          See also domain + guest groupdomain groups (G)
          , domain + logons +

          This is an EXPERIMENTAL parameter - that is part of the unfinished Samba NT Domain Controller Code. It may - be removed in a later release. To work with the latest code builds - that may have more support for Samba NT Domain Controller functionality - please subscribe to the mailing list samba-ntdom available by - visiting the web page at http://lists.samba.org/.

          Default: no domain administrators

          Example: domain admin group = root @wheel

          domain guest group (G)

          This is an EXPERIMENTAL parameter - that is part of the unfinished Samba NT Domain Controller Code. It may - be removed in a later release. To work with the latest code builds - that may have more support for Samba NT Domain Controller functionality - please subscribe to the mailing list samba-ntdom available by - visiting the web page at http://lists.samba.org/.

          This parameter is intended as a temporary solution + to enable users to be a member of the "Domain Guests" group when + a Samba host is acting as a PDC. A complete solution will be provided + by a system for mapping Windows NT/2000 groups onto UNIX groups. + Please note that this parameter has a somewhat confusing name. It + accepts a list of usernames and of group names in standard + smb.conf notation. +

          See also domain + admin groupdomain guest users (G)

          , domain + logons +

          This is an EXPERIMENTAL parameter - that is part of the unfinished Samba NT Domain Controller Code. It may - be removed in a later release. To work with the latest code builds - that may have more support for Samba NT Domain Controller functionality - please subscribe to the mailing list samba-ntdom available by - visiting the web page at http://lists.samba.org/.

          Default: no domain guests

          Example: domain guest group = nobody @guest

          parameter is applied.

          Note that by default this parameter does not apply to permissions + set by Windows NT/2000 ACL editors. If the administrator wishes to enforce + this mask on access control lists also, they need to set the restrict acl with + mask to true.

          See also the parameter is applied.

          Note that by default this parameter does not apply to permissions + set by Windows NT/2000 ACL editors. If the administrator wishes to enforce + this mask on access control lists also, they need to set the restrict acl with + mask to true.

          See also the parameter

          If not set explicitly this parameter is set to the same - value as the force - directory mode parameter. To allow - a user to modify all the user/group/world permissions on a - directory without restrictions, set this parameter to 000.

          If not set explicitly this parameter is 000, which + allows a user to modify all the user/group/world permissions on a + directory without restrictions.

          Note that users who can access the Samba server through other means can easily bypass this restriction, so it is primarily useful for standalone "appliance" systems. - Administrators of most normal systems will probably want to set - it to 0000.

          See also the

          Default: force directory security mode = <same as - force directory mode>force directory security mode = 0

          Example: force directory security mode = 0force directory security mode = 700

          If not set explicitly this parameter is set to the same - value as the force - create mode parameter. To allow a user to - modify all the user/group/world permissions on a file, with no - restrictions set this parameter to 000.

          If not set explicitly this parameter is set to 0, + and allows a user to modify all the user/group/world permissions on a file, + with no restrictions.

          Note that users who can access the Samba server through other means can easily bypass this restriction, so it is primarily useful for standalone "appliance" systems. - Administrators of most normal systems will probably want to set - it to 0000.

          See also the

          Default: force security mode = <same as force - create mode>force security mode = 0

          Example: force security mode = 0force security mode = 700

          log level (G)

          Synonym for debug level.

          The value of the parameter (an integer) allows + the debug level (logging level) to be specified in the + smb.conf file. This is to give greater + flexibility in the configuration of the system.

          The default will be the log level specified on + the command line or level zero if none was specified.

          Example: log level = 3

          obey pam restrictions (G)

          When Samba 2.2 is configure to enable PAM support + (i.e. --with-pam), this parameter will control whether or not Samba + should obey PAM's account and session management directives. The + default behavior is to use PAM for clear text authentication only + and to ignore any account or session management. Note that Samba + always ignores PAM for authentication in the case of encrypt passwords = yes + . The reason is that PAM modules cannot support the challenge/response + authentication mechanism needed in the presence of SMB password encryption. +

          Default: obey pam restrictions = no

          only user (S)
          ole locking compatibility (G)

          This parameter allows an administrator to turn - off the byte range lock manipulation that is done within Samba to - give compatibility for OLE applications. Windows OLE applications - use byte range locking as a form of inter-process communication, by - locking ranges of bytes around the 2^32 region of a file range. This - can cause certain UNIX lock managers to crash or otherwise cause - problems. Setting this parameter to no means you - trust your UNIX lock manager to handle such cases correctly.

          Default: ole locking compatibility = yes

          only guest (S)
          pam password change (G)

          With the addition of better PAM support in Samba 2.2, + this parameter, it is possible to use PAM's password change control + flag for Samba. If enabled, then PAM will be used for password + changes when requested by an SMB client, and the passwd chat must be + be changed to work with the pam prompts. +

          Default: pam password change = no

          panic action (G)

          Also, if the pam + password change parameter is set to true, then the + chat sequence should consist of three elements. The first element should + match the pam prompt for the old password, the second element should match + the pam prompt for the first request for the new password, and the final + element should match the pam prompt for the second request for the new password. + These matches are done case insentively. Under most conditions this change + is done as root so the prompt for the old password will never be matched. +

          See also passwd program and , passwd chat debug and pam password change.

          Default:

          restrict acl with mask (S)

          This is a boolean parameter. If set to false (default), then + Creation of files with access control lists (ACLS) and modification of ACLs + using the Windows NT/2000 ACL editor will be applied directly to the file + or directory.

          If set to True, then all requests to set an ACL on a file will have the + parameters create mask, + force create mode + applied before setting the ACL, and all requests to set an ACL on a directory will + have the parameters directory + mask, force + directory mode applied before setting the ACL. +

          See also create mask, + force create mode, + directory mask, + force directory mode +

          Default: restrict acl with mask = no

          restrict anonymous (G)

          If not set explicitly this parameter is set to the same - value as the create mask - parameter. To allow a user to modify all the - user/group/world permissions on a file, set this parameter to - 0777.

          If not set explicitly this parameter is 0777, allowing + a user to modify all the user/group/world permissions on a file. +

          Note

          See also the

          Default: security mask = <same as create mask> - security mask = 0777

          Example: security mask = 0777security mask = 0770

          WARNINGS

          VERSION

          SEE ALSO

          AUTHOR

          smbcontrol

          smbspool

          Name

          nmblookup -- send print file to an SMB printer
          smbspool -- send print file to an SMB printer

          smbstatus

          nmblookupswat [-s <smb config file>] [-a]

          .\" Please send any bug reports, improvements, comments, patches, .\" etc. to Steve Cheng . -.TH "MAKE_SMBCODEPAGE" "1" "24 April 2001" "" "" +.TH "MAKE_SMBCODEPAGE" "1" "01 June 2001" "" "" .SH NAME make_smbcodepage \- construct a codepage file for Samba .SH SYNOPSIS @@ -29,11 +29,11 @@ This is the codepage we are processing (a number, e.g. 850). .TP \fBinputfile\fR -This is the input file to process. In t -he '\fIc\fR' case this will be a text +This is the input file to process. In +the \fIc\fR case this will be a text codepage definition file such as the ones found in the Samba \fIsource/codepages\fR directory. In -the '\fId\fR' case this will be the +the \fId\fR case this will be the binary format codepage definition file normally found in the \fIlib/codepages\fR directory in the Samba install directory path. diff --git a/docs/manpages/make_unicodemap.1 b/docs/manpages/make_unicodemap.1 index 6ecd538cbec..805bc2d6c78 100644 --- a/docs/manpages/make_unicodemap.1 +++ b/docs/manpages/make_unicodemap.1 @@ -1,100 +1,97 @@ -.TH MAKE_UNICODEMAP 1 "24 Mar 2001" "make_unicodemap 2.2.0-alpha3" -.PP -.SH "NAME" -make_unicodemap \- Construct a unicode map file for Samba -.PP -.SH "SYNOPSIS" -.PP -\fBmake_unicodemap\fP codepage inputfile outputfile -.PP -.SH "DESCRIPTION" -.PP -This program is part of the \fBSamba\fP suite\&. -.PP -\fBmake_unicodemap\fP compiles text unicode map files into binary unicode -map files for use with the internationalization features of Samba 2\&.0 -.PP -.SH "OPTIONS" -.PP -.IP -.IP "codepage" -This is the codepage or UNIX character set we are processing (a number, e\&.g\&. 850)\&. -.IP -.IP "inputfile" -This is the input file to process\&. This is a text unicode map file -such as the ones found in the Samba \fIsource/codepages\fP directory\&. -.IP -.IP "outputfile" -This is the binary output file to produce\&. -.IP -.PP -.SH "Samba Unicode Map Files" -.PP -A text Samba unicode map file is a description that tells -Samba how to map characters from a specified DOS code page or UNIX character -set to 16 bit unicode\&. -.PP -A binary Samba unicode map file is a binary representation of -the same information, including a value that specifies what codepage -or UNIX character set this file is describing\&. -.PP -.SH "FILES" -.PP -\fBCP\&.TXT\fP -.PP -These are the input (text) unicode map files provided in the Samba -\fIsource/codepages\fP directory\&. -.PP -A text unicode map file consists of multiple lines -containing two fields\&. These fields are : -.PP -.IP -.IP o -\fBcharacter\fP: which is the (hex) character mapped on this -line\&. -.IP -.IP o -\fBunicode\fP: which is the (hex) 16 bit unicode character that the -character will map to\&. -.IP -.PP -\fBunicode_map\&.\fP These are the output (binary) unicode map files -produced and placed in the Samba destination \fIlib/codepage\fP -directory\&. -.PP -.SH "INSTALLATION" -.PP -The location of the server and its support files is a matter for -individual system administrators\&. The following are thus suggestions -only\&. -.PP -It is recommended that the \fBmake_unicodemap\fP program be installed -under the \fI/usr/local/samba\fP hierarchy, in a directory readable by -all, writeable only by root\&. The program itself should be executable -by all\&. The program should NOT be setuid or setgid! -.PP -.SH "VERSION" -.PP -This man page is correct for version 2\&.0 of the Samba suite\&. -.PP -.SH "SEE ALSO" -.PP -\fBsmb\&.conf(5)\fP, \fBsmbd (8)\fP -.PP -.SH "AUTHOR" -.PP -The original Samba software and related utilities were created by -Andrew Tridgell samba@samba\&.org\&. Samba is now developed -by the Samba Team as an Open Source project similar to the way the -Linux kernel is developed\&. -.PP -The original Samba man pages were written by Karl Auer\&. The man page -sources were converted to YODL format (another excellent piece of Open -Source software, available at -\fBftp://ftp\&.icce\&.rug\&.nl/pub/unix/\fP) -and updated for the Samba2\&.0 release by Jeremy Allison\&. -samba@samba\&.org\&. -.PP -See \fBsamba (7)\fP to find out how to get a full -list of contributors and details on how to submit bug reports, -comments etc\&. +.\" This manpage has been automatically generated by docbook2man-spec +.\" from a DocBook document. docbook2man-spec can be found at: +.\" +.\" Please send any bug reports, improvements, comments, patches, +.\" etc. to Steve Cheng . +.TH "MAKE_UNICODEMAP" "1" "01 June 2001" "" "" +.SH NAME +make_unicodemap \- construct a unicode map file for Samba +.SH SYNOPSIS +.sp +\fBmake_unicodemap\fR \fBcodepage\fR \fBinputfile\fR \fBoutputfile\fR +.SH "DESCRIPTION" +.PP +This tool is part of the Sambasuite. +.PP +\fBmake_unicodemap\fR compiles text unicode map +files into binary unicodef map files for use with the +internationalization features of Samba 2.2. +.SH "OPTIONS" +.TP +\fBcodepage\fR +This is the codepage or UNIX character +set we are processing (a number, e.g. 850). +.TP +\fBinputfile\fR +This is the input file to process. This is a +text unicode map file such as the ones found in the Samba +\fIsource/codepages\fR directory. +.TP +\fBoutputfile\fR +This is the binary output file to produce. +.SH "SAMBA UNICODE MAP FILES" +.PP +A text Samba unicode map file is a description that tells Samba +how to map characters from a specified DOS code page or UNIX character +set to 16 bit unicode. +.PP +A binary Samba unicode map file is a binary representation +of the same information, including a value that specifies what +codepage or UNIX character set this file is describing. +.SH "FILES" +.PP +\fICP.TXT\fR +.PP +These are the input (text) unicode map files provided +in the Samba \fIsource/codepages\fR +directory. +.PP +A text unicode map file consists of multiple lines +containing two fields. These fields are : +.TP 0.2i +\(bu +\fIcharacter\fR - which is +the (hex) character mapped on this line. +.TP 0.2i +\(bu +\fIunicode\fR - which +is the (hex) 16 bit unicode character that the character +will map to. +.PP +\fIunicode_map.\fR - These are +the output (binary) unicode map files produced and placed in +the Samba destination \fIlib/codepage\fR +directory. +.PP +.SH "INSTALLATION" +.PP +The location of the server and its support files is a matter +for individual system administrators. The following are thus +suggestions only. +.PP +It is recommended that the \fBmake_unicodemap\fR +program be installed under the +\fI$prefix/samba\fR hierarchy, +in a directory readable by all, writeable only by root. The +program itself should be executable by all. The program +should NOT be setuid or setgid! +.SH "VERSION" +.PP +This man page is correct for version 2.2 of +the Samba suite. +.SH "SEE ALSO" +.PP +\fBsmbd(8)\fR, +smb.conf(5).SH "AUTHOR" +.PP +The original Samba software and related utilities +were created by Andrew Tridgell. Samba is now developed +by the Samba Team as an Open Source project similar +to the way the Linux kernel is developed. +.PP +The original Samba man pages were written by Karl Auer. +The man page sources were converted to YODL format (another +excellent piece of Open Source software, available at +ftp://ftp.icce.rug.nl/pub/unix/ ) and updated for the Samba 2.0 +release by Jeremy Allison. The conversion to DocBook for +Samba 2.2 was done by Gerald Carter diff --git a/docs/manpages/rpcclient.1 b/docs/manpages/rpcclient.1 index f45ebdee509..d046ec37091 100644 --- a/docs/manpages/rpcclient.1 +++ b/docs/manpages/rpcclient.1 @@ -3,7 +3,7 @@ .\" .\" Please send any bug reports, improvements, comments, patches, .\" etc. to Steve Cheng . -.TH "RPCCLIENT" "1" "24 April 2001" "" "" +.TH "RPCCLIENT" "1" "01 June 2001" "" "" .SH NAME rpcclient \- tool for executing client side MS-RPC functions .SH SYNOPSIS @@ -56,8 +56,9 @@ planning on submitting a bug report to the Samba team (see BUGS.txt). Print a summary of command line options. .TP \fB-l logbasename\fR -File name for log/debug files. .client will be -appended. The log file is never removed by the client. +File name for log/debug files. The extension +\&'.client' will be appended. The log file is never removed +by the client. .TP \fB-N\fR instruct \fBrpcclient\fR not to ask @@ -93,9 +94,8 @@ it in directly. .TP \fB-W domain\fR Set the SMB domain of the username. This -overrides the default domain which is the domain of the -server specified with the \fI-S\fR option. -If the domain specified is the same as the server's NetBIOS name, +overrides the default domain which is the domain defined in +smb.conf. If the domain specified is the same as the server's NetBIOS name, it causes the client to log on using the server's local SAM (as opposed to the Domain SAM). .SH "COMMANDS" @@ -106,10 +106,12 @@ opposed to the Domain SAM). \fBlsaquery\fR .TP 0.2i \(bu -\fBlookupsids\fR +\fBlookupsids\fR - Resolve a list +of SIDs to usernames. .TP 0.2i \(bu -\fBlookupnames\fR +\fBlookupnames\fR - Resolve s list +of usernames to SIDs. .TP 0.2i \(bu \fBenumtrusts\fR @@ -130,6 +132,18 @@ opposed to the Domain SAM). .TP 0.2i \(bu \fBquerygroupmem\fR +.TP 0.2i +\(bu +\fBqueryaliasmem\fR +.TP 0.2i +\(bu +\fBquerydispinfo\fR +.TP 0.2i +\(bu +\fBquerydominfo\fR +.TP 0.2i +\(bu +\fBenumdomgroups\fR .PP .PP .PP @@ -180,6 +194,12 @@ and the \fIport\fRmust be a valid port name (see \fBenumports\fR. .TP 0.2i \(bu +\fBdeldriver\fR - Delete the +specified printer driver for all architectures. This +does not delete the actual driver files from the server, +only the entry from the server's list of drivers. +.TP 0.2i +\(bu \fBenumdata\fR - Enumerate all printer setting data stored on the server. On Windows NT clients, these values are stored in the registry, while Samba servers diff --git a/docs/manpages/smb.conf.5 b/docs/manpages/smb.conf.5 index 56c04c035cb..efd36946abc 100644 --- a/docs/manpages/smb.conf.5 +++ b/docs/manpages/smb.conf.5 @@ -3,7 +3,7 @@ .\" .\" Please send any bug reports, improvements, comments, patches, .\" etc. to Steve Cheng . -.TH "SMB.CONF" "5" "24 April 2001" "" "" +.TH "SMB.CONF" "5" "01 June 2001" "" "" .SH NAME smb.conf \- The configuration file for the Samba suite .SH "SYNOPSIS" @@ -503,10 +503,13 @@ Here is a list of all global parameters. See the section of each parameter for details. Note that some are synonyms. .TP 0.2i \(bu -\fIadd user script\fR +\fIadd printer command\fR +.TP 0.2i +\(bu +\fIadd share command\fR .TP 0.2i \(bu -\fIaddprinter command\fR +\fIadd user script\fR .TP 0.2i \(bu \fIallow trusted domains\fR @@ -530,6 +533,9 @@ each parameter for details. Note that some are synonyms. \fIchange notify timeout\fR .TP 0.2i \(bu +\fIchange share command\fR +.TP 0.2i +\(bu \fIcharacter set\fR .TP 0.2i \(bu @@ -569,10 +575,13 @@ each parameter for details. Note that some are synonyms. \fIdefault service\fR .TP 0.2i \(bu -\fIdelete user script\fR +\fIdelete printer command\fR +.TP 0.2i +\(bu +\fIdelete share command\fR .TP 0.2i \(bu -\fIdeleteprinter command\fR +\fIdelete user script\fR .TP 0.2i \(bu \fIdfree command\fR @@ -584,18 +593,9 @@ each parameter for details. Note that some are synonyms. \fIdomain admin group\fR .TP 0.2i \(bu -\fIdomain admin users\fR -.TP 0.2i -\(bu -\fIdomain groups\fR -.TP 0.2i -\(bu \fIdomain guest group\fR .TP 0.2i \(bu -\fIdomain guest users\fR -.TP 0.2i -\(bu \fIdomain logons\fR .TP 0.2i \(bu @@ -755,6 +755,9 @@ each parameter for details. Note that some are synonyms. \fInull passwords\fR .TP 0.2i \(bu +\fIobey pam restrictions\fR +.TP 0.2i +\(bu \fIoplock break wait time\fR .TP 0.2i \(bu @@ -764,6 +767,9 @@ each parameter for details. Note that some are synonyms. \fIos2 driver map\fR .TP 0.2i \(bu +\fIpam password change\fR +.TP 0.2i +\(bu \fIpanic action\fR .TP 0.2i \(bu @@ -1332,48 +1338,7 @@ each parameter for details. Note that some are synonyms. \fIwriteable\fR .SH "EXPLANATION OF EACH PARAMETER" .TP -\fBadd user script (G)\fR -This is the full pathname to a script that will -be run \fBAS ROOT\fR by smbd(8) -under special circumstances described below. - -Normally, a Samba server requires that UNIX users are -created for all users accessing files on this server. For sites -that use Windows NT account databases as their primary user database -creating these users and keeping the user list in sync with the -Windows NT PDC is an onerous task. This option allows smbdto create the required UNIX users -\fBON DEMAND\fR when a user accesses the Samba server. - -In order to use this option, smbdmust be set to \fIsecurity=server\fR or \fI security=domain\fR and \fIadd user script\fR -must be set to a full pathname for a script that will create a UNIX -user given one argument of \fI%u\fR, which expands into -the UNIX user name to create. - -When the Windows user attempts to access the Samba server, -at login (session setup in the SMB protocol) time, smbdcontacts the \fIpassword server\fR and -attempts to authenticate the given user with the given password. If the -authentication succeeds then \fBsmbd\fR -attempts to find a UNIX user in the UNIX password database to map the -Windows user into. If this lookup fails, and \fIadd user script -\fRis set then \fBsmbd\fR will -call the specified script \fBAS ROOT\fR, expanding -any \fI%u\fR argument to be the user name to create. - -If this script successfully creates the user then \fBsmbd -\fRwill continue on as though the UNIX user -already existed. In this way, UNIX users are dynamically created to -match existing Windows NT accounts. - -See also \fI security\fR, \fIpassword server\fR, -\fIdelete user -script\fR. - -Default: \fBadd user script = -\fR -Example: \fBadd user script = /usr/local/samba/bin/add_user -%u\fR -.TP -\fBaddprinter command (G)\fR +\fBadd printer command (G)\fR With the introduction of MS-RPC based printing support for Windows NT/2000 clients in Samba 2.2, The MS Add Printer Wizard (APW) icon is now also available in the @@ -1382,14 +1347,15 @@ allows for printers to be add remotely to a Samba or Windows NT/2000 print server. For a Samba host this means that the printer must be -physically added to underlying printing system. The \fI addprinter command\fR defines a script to be run which +physically added to underlying printing system. The \fIadd +printer command\fR defines a script to be run which will perform the necessary operations for adding the printer to the print system and to add the appropriate service definition to the \fIsmb.conf\fR file in order that it can be shared by \fBsmbd(8)\fR . -The \fIaddprinter command\fR is +The \fIadd printer command\fR is automatically invoked with the following parameter (in order: .RS @@ -1420,13 +1386,13 @@ only. The remaining fields in the structure are generated from answers to the APW questions. .PP .PP -Once the \fIaddprinter command\fR has +Once the \fIadd printer command\fR has been executed, \fBsmbd\fR will reparse the \fI smb.conf\fR to determine if the share defined by the APW exists. If the sharename is still invalid, then \fBsmbd \fRwill return an ACCESS_DENIED error to the client. .PP .PP -See also \fI deleteprinter command\fR, \fIprinting\fR, +See also \fI delete printer command\fR, \fIprinting\fR, \fIshow add printer wizard\fR .PP @@ -1437,6 +1403,94 @@ Default: \fBnone\fR Example: \fBaddprinter command = /usr/bin/addprinter \fR.PP .TP +\fBadd share command (G)\fR +Samba 2.2.0 introduced the ability to dynamically +add and delete shares via the Windows NT 4.0 Server Manager. The +\fIadd share command\fR is used to define an +external program or script which will add a new service definition +to \fIsmb.conf\fR. In order to successfully +execute the \fIadd share command\fR, \fBsmbd\fR +requires that the administrator be connected using a root account (i.e. +uid == 0). + +When executed, \fBsmbd\fR will automatically invoke the +\fIadd share command\fR with four parameters. +.RS +.TP 0.2i +\(bu +\fIconfigFile\fR - the location +of the global \fIsmb.conf\fR file. +.TP 0.2i +\(bu +\fIshareName\fR - the name of the new +share. +.TP 0.2i +\(bu +\fIpathName\fR - path to an **existing** +directory on disk. +.TP 0.2i +\(bu +\fIcomment\fR - comment string to associate +with the new share. +.RE +.PP +This parameter is only used for add file shares. To add printer shares, +see the \fIadd printer +command\fR. +.PP +.PP +See also \fIchange share +command\fR, \fIdelete share +command\fR. +.PP +.PP +Default: \fBnone\fR +.PP +.PP +Example: \fBadd share command = /usr/local/bin/addshare\fR +.PP +.TP +\fBadd user script (G)\fR +This is the full pathname to a script that will +be run \fBAS ROOT\fR by smbd(8) +under special circumstances described below. + +Normally, a Samba server requires that UNIX users are +created for all users accessing files on this server. For sites +that use Windows NT account databases as their primary user database +creating these users and keeping the user list in sync with the +Windows NT PDC is an onerous task. This option allows smbdto create the required UNIX users +\fBON DEMAND\fR when a user accesses the Samba server. + +In order to use this option, smbdmust be set to \fIsecurity=server\fR or \fI security=domain\fR and \fIadd user script\fR +must be set to a full pathname for a script that will create a UNIX +user given one argument of \fI%u\fR, which expands into +the UNIX user name to create. + +When the Windows user attempts to access the Samba server, +at login (session setup in the SMB protocol) time, smbdcontacts the \fIpassword server\fR and +attempts to authenticate the given user with the given password. If the +authentication succeeds then \fBsmbd\fR +attempts to find a UNIX user in the UNIX password database to map the +Windows user into. If this lookup fails, and \fIadd user script +\fRis set then \fBsmbd\fR will +call the specified script \fBAS ROOT\fR, expanding +any \fI%u\fR argument to be the user name to create. + +If this script successfully creates the user then \fBsmbd +\fRwill continue on as though the UNIX user +already existed. In this way, UNIX users are dynamically created to +match existing Windows NT accounts. + +See also \fI security\fR, \fIpassword server\fR, +\fIdelete user +script\fR. + +Default: \fBadd user script = +\fR +Example: \fBadd user script = /usr/local/samba/bin/add_user +%u\fR +.TP \fBadmin users (S)\fR This is a list of users who will be granted administrative privileges on the share. This means that they @@ -1621,6 +1675,52 @@ Example: \fBchange notify timeout = 300\fR Would change the scan time to every 5 minutes. .TP +\fBchange share command (G)\fR +Samba 2.2.0 introduced the ability to dynamically +add and delete shares via the Windows NT 4.0 Server Manager. The +\fIchange share command\fR is used to define an +external program or script which will modify an existing service definition +in \fIsmb.conf\fR. In order to successfully +execute the \fIchange share command\fR, \fBsmbd\fR +requires that the administrator be connected using a root account (i.e. +uid == 0). + +When executed, \fBsmbd\fR will automatically invoke the +\fIchange share command\fR with four parameters. +.RS +.TP 0.2i +\(bu +\fIconfigFile\fR - the location +of the global \fIsmb.conf\fR file. +.TP 0.2i +\(bu +\fIshareName\fR - the name of the new +share. +.TP 0.2i +\(bu +\fIpathName\fR - path to an **existing** +directory on disk. +.TP 0.2i +\(bu +\fIcomment\fR - comment string to associate +with the new share. +.RE +.PP +This parameter is only used modify existing file shares definitions. To modify +printer shares, use the "Printers..." folder as seen when browsing the Samba host. +.PP +.PP +See also \fIadd share +command\fR, \fIdelete +share command\fR. +.PP +.PP +Default: \fBnone\fR +.PP +.PP +Example: \fBchange share command = /usr/local/bin/addshare\fR +.PP +.TP \fBcharacter set (G)\fR This allows a smbd to map incoming filenames from a DOS Code page (see the client @@ -1898,6 +1998,10 @@ create mode\fR parameter for forcing particular mode bits to be set on created files. See also the \fIdirectory mode"\fR parameter for masking mode bits on created directories. See also the \fIinherit permissions\fR parameter. +Note that this parameter does not apply to permissions +set by Windows NT/2000 ACL editors. If the administrator wishes to enforce +a mask on access control lists also, they need to set the \fIsecurity mask\fR. + Default: \fBcreate mask = 0744\fR Example: \fBcreate mask = 0775\fR @@ -1970,15 +2074,7 @@ effect. Default: \fBdebug uid = no\fR .TP \fBdebuglevel (G)\fR -The value of the parameter (an integer) allows -the debug level (logging level) to be specified in the -\fIsmb.conf\fR file. This is to give greater -flexibility in the configuration of the system. - -The default will be the debug level specified on -the command line or level zero if none was specified. - -Example: \fBdebug level = 3\fR +Synonym for \fI log level\fR. .TP \fBdefault (G)\fR A synonym for \fI default service\fR. @@ -2022,6 +2118,33 @@ Example: .sp .fi .TP +\fBdelete printer command (G)\fR +With the introduction of MS-RPC based printer +support for Windows NT/2000 clients in Samba 2.2, it is now +possible to delete printer at run time by issuing the +DeletePrinter() RPC call. + +For a Samba host this means that the printer must be +physically deleted from underlying printing system. The \fI deleteprinter command\fR defines a script to be run which +will perform the necessary operations for removing the printer +from the print system and from \fIsmb.conf\fR. + +The \fIdelete printer command\fR is +automatically called with only one parameter: \fI "printer name"\fR. + +Once the \fIdelete printer command\fR has +been executed, \fBsmbd\fR will reparse the \fI smb.conf\fR to associated printer no longer exists. +If the sharename is still valid, then \fBsmbd +\fRwill return an ACCESS_DENIED error to the client. + +See also \fI add printer command\fR, \fIprinting\fR, +\fIshow add +printer wizard\fR + +Default: \fBnone\fR + +Example: \fBdeleteprinter command = /usr/bin/removeprinter +\fR.TP \fBdelete readonly (S)\fR This parameter allows readonly files to be deleted. This is not normal DOS semantics, but is allowed by UNIX. @@ -2032,6 +2155,45 @@ permissions, and DOS semantics prevent deletion of a read only file. Default: \fBdelete readonly = no\fR .TP +\fBdelete share command (G)\fR +Samba 2.2.0 introduced the ability to dynamically +add and delete shares via the Windows NT 4.0 Server Manager. The +\fIdelete share command\fR is used to define an +external program or script which will remove an existing service +definition from \fIsmb.conf\fR. In order to successfully +execute the \fIdelete share command\fR, \fBsmbd\fR +requires that the administrator be connected using a root account (i.e. +uid == 0). + +When executed, \fBsmbd\fR will automatically invoke the +\fIdelete share command\fR with two parameters. +.RS +.TP 0.2i +\(bu +\fIconfigFile\fR - the location +of the global \fIsmb.conf\fR file. +.TP 0.2i +\(bu +\fIshareName\fR - the name of +the existing service. +.RE +.PP +This parameter is only used to remove file shares. To delete printer shares, +see the \fIdelete printer +command\fR. +.PP +.PP +See also \fIdelete share +command\fR, \fIchange +share\fR. +.PP +.PP +Default: \fBnone\fR +.PP +.PP +Example: \fBdelete share command = /usr/local/bin/delshare\fR +.PP +.TP \fBdelete user script (G)\fR This is the full pathname to a script that will be run \fBAS ROOT\fR by \fBsmbd(8)\fRunder special circumstances @@ -2085,33 +2247,6 @@ Default: \fBdelete user script = Example: \fBdelete user script = /usr/local/samba/bin/del_user %u\fR .TP -\fBdeleteprinter command (G)\fR -With the introduction of MS-RPC based printer -support for Windows NT/2000 clients in Samba 2.2, it is now -possible to delete printer at run time by issuing the -DeletePrinter() RPC call. - -For a Samba host this means that the printer must be -physically deleted from underlying printing system. The \fI deleteprinter command\fR defines a script to be run which -will perform the necessary operations for removing the printer -from the print system and from \fIsmb.conf\fR. - -The \fIdeleteprinter command\fR is -automatically called with only one parameter: \fI "printer name"\fR. - -Once the \fIdeleteprinter command\fR has -been executed, \fBsmbd\fR will reparse the \fI smb.conf\fR to associated printer no longer exists. -If the sharename is still valid, then \fBsmbd -\fRwill return an ACCESS_DENIED error to the client. - -See also \fI addprinter command\fR, \fIprinting\fR, -\fIshow add -printer wizard\fR - -Default: \fBnone\fR - -Example: \fBdeleteprinter command = /usr/bin/removeprinter -\fR.TP \fBdelete veto files (S)\fR This option is used when Samba is attempting to delete a directory that contains one or more vetoed directories @@ -2220,6 +2355,10 @@ created from this parameter with the value of the \fIforce directory mode \fRparameter. This parameter is set to 000 by default (i.e. no extra mode bits are added). +Note that this parameter does not apply to permissions +set by Windows NT/2000 ACL editors. If the administrator wishes to enforce +a mask on access control lists also, they need to set the \fIdirectory security mask\fR. + See the \fIforce directory mode\fR parameter to cause particular mode bits to always be set on created directories. @@ -2250,26 +2389,23 @@ this mask from being modified. Essentially, zero bits in this mask may be treated as a set of bits the user is not allowed to change. -If not set explicitly this parameter is set to the same -value as the \fIdirectory -mask\fR parameter. To allow a user to -modify all the user/group/world permissions on a directory, set -this parameter to 0777. +If not set explicitly this parameter is set to 0777 +meaning a user is allowed to modify all the user/group/world +permissions on a directory. \fBNote\fR that users who can access the Samba server through other means can easily bypass this restriction, so it is primarily useful for standalone "appliance" systems. -Administrators of most normal systems will probably want to set -it to 0777. +Administrators of most normal systems will probably want to leave +it as the default of 0777. See also the \fI force directory security mode\fR, \fIsecurity mask\fR, \fIforce security mode \fRparameters. -Default: \fBdirectory security mask = \fR +Default: \fBdirectory security mask = 0777\fR -Example: \fBdirectory security mask = 0777\fR +Example: \fBdirectory security mask = 0700\fR .TP \fBdns proxy (G)\fR Specifies that nmbd(8)when acting as a WINS server and finding that a NetBIOS name has not @@ -2290,44 +2426,38 @@ See also the parameter \fI wins support\fR. Default: \fBdns proxy = yes\fR .TP \fBdomain admin group (G)\fR -This is an \fBEXPERIMENTAL\fR parameter -that is part of the unfinished Samba NT Domain Controller Code. It may -be removed in a later release. To work with the latest code builds -that may have more support for Samba NT Domain Controller functionality -please subscribe to the mailing list samba-ntdom available by -visiting the web page at http://lists.samba.org/ . -.TP -\fBdomain admin users (G)\fR -This is an \fBEXPERIMENTAL\fR parameter -that is part of the unfinished Samba NT Domain Controller Code. It may -be removed in a later release. To work with the latest code builds -that may have more support for Samba NT Domain Controller functionality -please subscribe to the mailing list samba-ntdom available by -visiting the web page at http://lists.samba.org/ . -.TP -\fBdomain groups (G)\fR -This is an \fBEXPERIMENTAL\fR parameter -that is part of the unfinished Samba NT Domain Controller Code. It may -be removed in a later release. To work with the latest code builds -that may have more support for Samba NT Domain Controller functionality -please subscribe to the mailing list samba-ntdom available by -visiting the web page at http://lists.samba.org/ . +This parameter is intended as a temporary solution +to enable users to be a member of the "Domain Admins" group when +a Samba host is acting as a PDC. A complete solution will be provided +by a system for mapping Windows NT/2000 groups onto UNIX groups. +Please note that this parameter has a somewhat confusing name. It +accepts a list of usernames and of group names in standard +\fIsmb.conf\fR notation. + +See also \fIdomain +guest group\fR, \fIdomain +logons\fR + +Default: \fBno domain administrators\fR + +Example: \fBdomain admin group = root @wheel\fR .TP \fBdomain guest group (G)\fR -This is an \fBEXPERIMENTAL\fR parameter -that is part of the unfinished Samba NT Domain Controller Code. It may -be removed in a later release. To work with the latest code builds -that may have more support for Samba NT Domain Controller functionality -please subscribe to the mailing list samba-ntdom available by -visiting the web page at http://lists.samba.org/ . -.TP -\fBdomain guest users (G)\fR -This is an \fBEXPERIMENTAL\fR parameter -that is part of the unfinished Samba NT Domain Controller Code. It may -be removed in a later release. To work with the latest code builds -that may have more support for Samba NT Domain Controller functionality -please subscribe to the mailing list samba-ntdom available by -visiting the web page at http://lists.samba.org/ . +This parameter is intended as a temporary solution +to enable users to be a member of the "Domain Guests" group when +a Samba host is acting as a PDC. A complete solution will be provided +by a system for mapping Windows NT/2000 groups onto UNIX groups. +Please note that this parameter has a somewhat confusing name. It +accepts a list of usernames and of group names in standard +\fIsmb.conf\fR notation. + +See also \fIdomain +admin group\fR, \fIdomain +logons\fR + +Default: \fBno domain guests\fR + +Example: \fBdomain guest group = nobody @guest\fR .TP \fBdomain logons (G)\fR If set to true, the Samba server will serve @@ -2574,6 +2704,11 @@ permissions changed. The default for this parameter is (in octal) mode after the mask set in the \fIcreate mask\fR parameter is applied. +Note that by default this parameter does not apply to permissions +set by Windows NT/2000 ACL editors. If the administrator wishes to enforce +this mask on access control lists also, they need to set the \fIrestrict acl with +mask\fR to true. + See also the parameter \fIcreate mask\fR for details on masking mode bits on files. @@ -2598,6 +2733,11 @@ bits to a created directory. This operation is done after the mode mask in the parameter \fIdirectory mask\fR is applied. +Note that by default this parameter does not apply to permissions +set by Windows NT/2000 ACL editors. If the administrator wishes to enforce +this mask on access control lists also, they need to set the \fIrestrict acl with +mask\fR to true. + See also the parameter \fI directory mask\fR for details on masking mode bits on created directories. @@ -2622,26 +2762,23 @@ the user may have modified to be on. Essentially, one bits in this mask may be treated as a set of bits that, when modifying security on a directory, the user has always set to be 'on'. -If not set explicitly this parameter is set to the same -value as the \fIforce -directory mode\fR parameter. To allow -a user to modify all the user/group/world permissions on a -directory without restrictions, set this parameter to 000. +If not set explicitly this parameter is 000, which +allows a user to modify all the user/group/world permissions on a +directory without restrictions. \fBNote\fR that users who can access the Samba server through other means can easily bypass this restriction, so it is primarily useful for standalone "appliance" systems. -Administrators of most normal systems will probably want to set -it to 0000. +Administrators of most normal systems will probably want to leave +it set as 0000. See also the \fI directory security mask\fR, \fIsecurity mask\fR, \fIforce security mode \fRparameters. -Default: \fBforce directory security mode = \fR +Default: \fBforce directory security mode = 0\fR -Example: \fBforce directory security mode = 0\fR +Example: \fBforce directory security mode = 700\fR .TP \fBforce group (S)\fR This specifies a UNIX group name that will be @@ -2689,26 +2826,23 @@ the user may have modified to be on. Essentially, one bits in this mask may be treated as a set of bits that, when modifying security on a file, the user has always set to be 'on'. -If not set explicitly this parameter is set to the same -value as the \fIforce -create mode\fR parameter. To allow a user to -modify all the user/group/world permissions on a file, with no -restrictions set this parameter to 000. +If not set explicitly this parameter is set to 0, +and allows a user to modify all the user/group/world permissions on a file, +with no restrictions. \fBNote\fR that users who can access the Samba server through other means can easily bypass this restriction, so it is primarily useful for standalone "appliance" systems. -Administrators of most normal systems will probably want to set -it to 0000. +Administrators of most normal systems will probably want to leave +this set to 0000. See also the \fI force directory security mode\fR, \fIdirectory security mask\fR, \fI security mask\fR parameters. -Default: \fBforce security mode = \fR +Default: \fBforce security mode = 0\fR -Example: \fBforce security mode = 0\fR +Example: \fBforce security mode = 700\fR .TP \fBforce user (S)\fR This specifies a UNIX user name that will be @@ -3287,7 +3421,15 @@ you to have separate log files for each user or machine. Example: \fBlog file = /usr/local/samba/var/log.%m \fR.TP \fBlog level (G)\fR -Synonym for \fI debug level\fR. +The value of the parameter (an integer) allows +the debug level (logging level) to be specified in the +\fIsmb.conf\fR file. This is to give greater +flexibility in the configuration of the system. + +The default will be the log level specified on +the command line or level zero if none was specified. + +Example: \fBlog level = 3\fR .TP \fBlogon drive (G)\fR This parameter specifies the local path to @@ -4295,6 +4437,18 @@ See also smbpasswd (5). Default: \fBnull passwords = no\fR .TP +\fBobey pam restrictions (G)\fR +When Samba 2.2 is configure to enable PAM support +(i.e. --with-pam), this parameter will control whether or not Samba +should obey PAM's account and session management directives. The +default behavior is to use PAM for clear text authentication only +and to ignore any account or session management. Note that Samba +always ignores PAM for authentication in the case of \fIencrypt passwords = yes\fR +\&. The reason is that PAM modules cannot support the challenge/response +authentication mechanism needed in the presence of SMB password encryption. + +Default: \fBobey pam restrictions = no\fR +.TP \fBonly user (S)\fR This is a boolean option that controls whether connections with usernames not in the \fIuser\fR @@ -4317,18 +4471,6 @@ parameter. Default: \fBonly user = no\fR .TP -\fBole locking compatibility (G)\fR -This parameter allows an administrator to turn -off the byte range lock manipulation that is done within Samba to -give compatibility for OLE applications. Windows OLE applications -use byte range locking as a form of inter-process communication, by -locking ranges of bytes around the 2^32 region of a file range. This -can cause certain UNIX lock managers to crash or otherwise cause -problems. Setting this parameter to no means you -trust your UNIX lock manager to handle such cases correctly. - -Default: \fBole locking compatibility = yes\fR -.TP \fBonly guest (S)\fR A synonym for \fI guest only\fR. .TP @@ -4423,6 +4565,15 @@ containing in the Samba documentation. Default: \fBos2 driver map = \fR.TP +\fBpam password change (G)\fR +With the addition of better PAM support in Samba 2.2, +this parameter, it is possible to use PAM's password change control +flag for Samba. If enabled, then PAM will be used for password +changes when requested by an SMB client, and the \fIpasswd chat\fR must be +be changed to work with the pam prompts. + +Default: \fBpam password change = no\fR +.TP \fBpanic action (G)\fR This is a Samba developer option that allows a system command to be called when either smbd(8)crashes. This is usually used to draw attention to the fact that @@ -4468,8 +4619,17 @@ in the smbpasswd file is being changed, without access to the old password cleartext. In this case the old password cleartext is set to "" (the empty string). +Also, if the \fIpam +password change\fR parameter is set to true, then the +chat sequence should consist of three elements. The first element should +match the pam prompt for the old password, the second element should match +the pam prompt for the first request for the new password, and the final +element should match the pam prompt for the second request for the new password. +These matches are done case insentively. Under most conditions this change +is done as root so the prompt for the old password will never be matched. + See also \fIunix password -sync\fR, \fI passwd program\fR and \fIpasswd chat debug\fR. +sync\fR, \fI passwd program\fR , \fIpasswd chat debug\fR and \fIpam password change\fR. Default: \fBpasswd chat = *new*password* %n\\n *new*password* %n\\n *changed*\fR @@ -5230,6 +5390,27 @@ is in fact the browse master on it's segment. Default: \fBremote browse sync = \fR.TP +\fBrestrict acl with mask (S)\fR +This is a boolean parameter. If set to false (default), then +Creation of files with access control lists (ACLS) and modification of ACLs +using the Windows NT/2000 ACL editor will be applied directly to the file +or directory. + +If set to True, then all requests to set an ACL on a file will have the +parameters \fIcreate mask\fR, +\fIforce create mode\fR +applied before setting the ACL, and all requests to set an ACL on a directory will +have the parameters \fIdirectory +mask\fR, \fIforce +directory mode\fR applied before setting the ACL. + +See also \fIcreate mask\fR, +\fIforce create mode\fR, +\fIdirectory mask\fR, +\fIforce directory mode\fR + +Default: \fBrestrict acl with mask = no\fR +.TP \fBrestrict anonymous (G)\fR This is a boolean parameter. If it is true, then anonymous access to the server will be restricted, namely in the @@ -5562,25 +5743,22 @@ this mask from being modified. Essentially, zero bits in this mask may be treated as a set of bits the user is not allowed to change. -If not set explicitly this parameter is set to the same -value as the \fIcreate mask -\fRparameter. To allow a user to modify all the -user/group/world permissions on a file, set this parameter to -0777. +If not set explicitly this parameter is 0777, allowing +a user to modify all the user/group/world permissions on a file. \fBNote\fR that users who can access the Samba server through other means can easily bypass this restriction, so it is primarily useful for standalone "appliance" systems. Administrators of most normal systems will -probably want to set it to 0777. +probably want to leave it set to 0777. See also the \fIforce directory security mode\fR, \fIdirectory security mask\fR, \fIforce security mode\fR parameters. -Default: \fBsecurity mask = -\fR -Example: \fBsecurity mask = 0777\fR +Default: \fBsecurity mask = 0777\fR + +Example: \fBsecurity mask = 0770\fR .TP \fBserver string (G)\fR This controls what string will show up in the diff --git a/docs/manpages/smbcontrol.1 b/docs/manpages/smbcontrol.1 index 20e08dd8325..0c894aa959e 100644 --- a/docs/manpages/smbcontrol.1 +++ b/docs/manpages/smbcontrol.1 @@ -3,7 +3,7 @@ .\" .\" Please send any bug reports, improvements, comments, patches, .\" etc. to Steve Cheng . -.TH "SMBCONTROL" "1" "24 April 2001" "" "" +.TH "SMBCONTROL" "1" "01 June 2001" "" "" .SH NAME smbcontrol \- send messages to smbd or nmbd processes .SH SYNOPSIS diff --git a/docs/manpages/smbspool.8 b/docs/manpages/smbspool.8 index 6bdfeb6adbf..e30755c4b2e 100644 --- a/docs/manpages/smbspool.8 +++ b/docs/manpages/smbspool.8 @@ -3,9 +3,9 @@ .\" .\" Please send any bug reports, improvements, comments, patches, .\" etc. to Steve Cheng . -.TH "SMBSPOOL" "8" "24 April 2001" "" "" +.TH "SMBSPOOL" "8" "01 June 2001" "" "" .SH NAME -nmblookup \- send print file to an SMB printer +smbspool \- send print file to an SMB printer .SH SYNOPSIS .sp \fBsmbspool\fR [ \fBjob\fR ] [ \fBuser\fR ] [ \fBtitle\fR ] [ \fBcopies\fR ] [ \fBoptions\fR ] [ \fBfilename\fR ] diff --git a/docs/manpages/smbstatus.1 b/docs/manpages/smbstatus.1 index 21ece4b02a5..d2e3c97e796 100644 --- a/docs/manpages/smbstatus.1 +++ b/docs/manpages/smbstatus.1 @@ -3,7 +3,7 @@ .\" .\" Please send any bug reports, improvements, comments, patches, .\" etc. to Steve Cheng . -.TH "SMBSTATUS" "1" "24 April 2001" "" "" +.TH "SMBSTATUS" "1" "01 June 2001" "" "" .SH NAME smbstatus \- report on current Samba connections .SH SYNOPSIS diff --git a/docs/manpages/swat.8 b/docs/manpages/swat.8 index 4ec6bfba5da..b53e0574307 100644 --- a/docs/manpages/swat.8 +++ b/docs/manpages/swat.8 @@ -3,12 +3,12 @@ .\" .\" Please send any bug reports, improvements, comments, patches, .\" etc. to Steve Cheng . -.TH "SWAT" "8" "24 April 2001" "" "" +.TH "SWAT" "8" "01 June 2001" "" "" .SH NAME swat \- Samba Web Administration Tool .SH SYNOPSIS .sp -\fBnmblookup\fR [ \fB-s \fR ] [ \fB-a\fR ] +\fBswat\fR [ \fB-s \fR ] [ \fB-a\fR ] .SH "DESCRIPTION" .PP This tool is part of the Sambasuite. diff --git a/docs/textdocs/CVS_ACCESS.txt b/docs/textdocs/CVS_ACCESS.txt deleted file mode 100644 index c854d3fe33e..00000000000 --- a/docs/textdocs/CVS_ACCESS.txt +++ /dev/null @@ -1,124 +0,0 @@ -!== -!== CVS_ACCESS.txt for Samba release 2.0.4 18 May 1999 -!== -Contributor: Modified from the Web pages by Jeremy Allison. -Date: 23 Dec 1997 -Status: Current - -How to get access to Samba source code via cvs. -=============================================== - -CVS Access to samba.org ------------------------------- - -The machine samba.org runs a publicly accessible CVS -repository for access to the source code of several packages, -including samba, rsync and jitterbug. This document describes -how to get anonymous read-only access to this source code. - -Access via cvsweb ------------------ - -You can access the source code via your favourite WWW browser. -This allows you to access the contents of individual files in -the repository and also to look at the revision history and -commit logs of individual files. You can also ask for a diff -listing between any two versions on the repository. - -Use the URL : http://samba.org/cgi-bin/cvsweb - -Access via cvs --------------- - -You can also access the source code via a normal cvs client. -This gives you much more control over you can do with the -repository and allows you to checkout whole source trees -and keep them uptodate via normal cvs commands. This is the -preferred method of access if you are a developer and not -just a casual browser. - -To download the latest cvs source code, point your -browser at the URL : - -http://www.cyclic.com/ - -and click on the 'How to get cvs' link. CVS is free -software under the GNU GPL (as is Samba). - -To gain access via anonymous cvs use the following steps. -For this example it is assumed that you want a copy of the -samba source code. For the other source code repositories -on this system just substitute the correct package name - -1. Install a recent copy of cvs. All you really need is a - copy of the cvs client binary. - -2. Run the command - - cvs -d :pserver:cvs@samba.org:/cvsroot login - -When it asks you for a password type 'cvs' (not including -the quotes). - -3. Run the command - - cvs -d :pserver:cvs@samba.org:/cvsroot co samba - -This will create a directory called samba containing the -latest samba source code. This currently corresponds to the -1.9.18alpha development tree. - -4. Whenever you want to merge in the latest code changes use -the following command from within the samba directory: - - cvs update -d -P - -NOTE: If you instead want the latest source code for the -1.9.17 stable tree then replace step 4 with the command: - - cvs -d :pserver:cvs@samba.org:/cvsroot co -r BRANCH_1_9_17 samba - -Access to the NT DOMAIN Controller code ---------------------------------------- - -The Samba PDC code is being separately developed on a -branch named BRANCH_NTDOM. To gain access to the latest -source code (this changes daily) do the following: - -1). Log onto cvs - - cvs -d :pserver:cvs@samba.org:/cvsroot login - -When it asks you for a password type 'cvs' (not including -the quotes). - -2). Check out the BRANCH_NTDOM by typing : - - cvs -d :pserver:cvs@samba.org:/cvsroot co -r BRANCH_NTDOM samba - -This will create a directory called samba containing the -latest snapshot of the domain controller code. - -3). To keep this code up to date after it has been -changed in the cvs repository, cd into the samba -directory you created above and type : - - cvs update -d -P - -How it's done. --------------- - -If you are interested in how anonymous cvs access is set up and -want to set it up on your own system then you might like to checkout -the pserver source code using the the command : - - cvs -d :pserver:cvs@samba.org:/cvsroot co pserver - -You really have to know what you are doing to do this. Please don't -email samba-bugs with basic cvs or unix security questions. - -Reporting problems. -------------------- - -If you have any problems with this system please email -samba-bugs@samba.org. diff --git a/docs/textdocs/DOMAIN.txt b/docs/textdocs/DOMAIN.txt deleted file mode 100644 index d16f3aa55dc..00000000000 --- a/docs/textdocs/DOMAIN.txt +++ /dev/null @@ -1,381 +0,0 @@ -!== -!== DOMAIN.txt for Samba release 2.0.4 18 May 1999 -!== -Contributor: Samba Team -Updated: December 4, 1998 (John H Terpstra) - -Subject: Network Logons and Roaming (Roving) Profiles -=========================================================================== - -A domain and a workgroup are exactly the same thing in terms of network -browsing. The difference is that a distributable authentication -database is associated with a domain, for secure login access to a -network. Also, different access rights can be granted to users if they -successfully authenticate against a domain logon server (samba does not -support this, but NT server and other systems based on NT server do). - -As of samba-2.0.0 this is now a work in progress that is expected to -mature rapidly. Since this document pre-dates samba-2.0.0 it should be -read from the perspective of it's origins but the reader should understand -that the following details may NOT be up to date with current development. - -The SMB client logging on to a domain has an expectation that every other -server in the domain should accept the same authentication information. -However the network browsing functionality of domains and workgroups is -identical and is explained in BROWSING.txt. - -Issues related to the single-logon network model are discussed in this -document. Samba supports domain logons, network logon scripts, and user -profiles for MS Windows for workgroups and MS Windows 9X clients. - -Work is underway to support domain logon for MS Windows NT clients - this -is mostly working but will undergo much change as the the behaviour of the -new code matures and becomes easier to manage. - -Support is also not complete. Samba does not yet support the sharing -of the Windows NT-style SAM database with other systems. However this is -only one way of having a shared user database: exactly the same effect can -be achieved by having all servers in a domain share a distributed NIS or -Kerberos authentication database. - -When an SMB client in a domain wishes to logon it broadcast requests for a -logon server. The first one to reply gets the job, and validates its -password using whatever mechanism the Samba administrator has installed. -It is possible (but very stupid) to create a domain where the user -database is not shared between servers, ie they are effectively workgroup -servers advertising themselves as participating in a domain. This -demonstrates how authentication is quite different from but closely -involved with domains. - -Another thing commonly associated with single-logon domains is remote -administration over the SMB protocol. Again, there is no reason why this -cannot be implemented with an underlying username database which is -different from the Windows NT SAM. Support for the Remote Administration -Protocol is planned for a future release of Samba. - -The domain support works for WfWg, and Win95 clients and NT 4.0 and 3.51. -Domain support is currently at an early experimental stage for NT 4.0 and -NT 3.51. Support for Windows OS/2 clients is still being worked on and is -still experimental. - -Support for profiles is confirmed as working for Win95, NT 4.0 and NT 3.51. -It is possible to specify: the profile location; script file to be loaded -on login; the user's home directory; and for NT a kick-off time could also -now easily be supported. - -With NT Workstations, all this does not require the use or intervention of -an NT 4.0 or NT 3.51 server: Samba can now replace the logon services -provided by an NT server, to a limited and experimental degree (for example, -running "User Manager for Domains" will not provide you with access to -a domain created by a Samba Server). - -With Win95, the help of an NT server can be enlisted, both for profile storage -and for user authentication. For details on user authentication, see -security_level.txt. For details on profile storage, see below. - - -Using these features you can make your clients verify their logon via -the Samba server; make clients run a batch file when they logon to -the network and download their preferences, desktop and start menu. - - -Configuration Instructions: Network Logons -============================================== - -To use domain logons and profiles you need to do the following: - - -1) Setup nmbd and smbd by configuring smb.conf so that Samba is - acting as the master browser. See _INSTALL.txt and BROWSING.txt - for details. - -2) Setup a WINS server (see NetBIOS.txt) and configure all your clients - to use that WINS service. - -3) Create a share called [netlogon] in your smb.conf. This share should - be readable by all users, and probably should not be writeable. This - share will hold your network logon scripts, and the CONFIG.POL file - (Note: for details on the CONFIG.POL file, how to use it, what it is, - refer to the Microsoft Windows NT Administration documentation. - The format of these files is not known, so you will need to use - Microsoft tools). - -For example I have used: - - [netlogon] - path = /data/dos/netlogon - writeable = no - guest ok = no - -Note that it is important that this share is not writeable by ordinary -users, in a secure environment: ordinary users should not be allowed -to modify or add files that another user's computer would then download -when they log in. - -4) in the [global] section of smb.conf set the following: - - domain logons = yes - logon script = %U.bat - -The choice of batch file is, of course, up to you. The above would -give each user a separate batch file as the %U will be changed to -their username automatically. The other standard % macros may also be -used. You can make the batch files come from a subdirectory by using -something like: - - logon script = scripts\%U.bat - -5) create the batch files to be run when the user logs in. If the batch - file doesn't exist then no batch file will be run. - -In the batch files you need to be careful to use DOS style cr/lf line -endings. If you don't then DOS may get confused. I suggest you use a -DOS editor to remotely edit the files if you don't know how to produce -DOS style files under unix. - -6) Use smbclient with the -U option for some users to make sure that - the \\server\NETLOGON share is available, the batch files are - visible and they are readable by the users. - -7) you will probabaly find that your clients automatically mount the - \\SERVER\NETLOGON share as drive z: while logging in. You can put - some useful programs there to execute from the batch files. - -NOTE: You must be using "security = user" or "security = server" for -domain logons to work correctly. Share level security won't work -correctly. - - - -Configuration Instructions: Setting up Roaming User Profiles -================================================================ - -In the [global] section of smb.conf set the following (for example): - - logon path = \\profileserver\profileshare\profilepath\%U\moreprofilepath - -The default for this option is \\%N\%U\profile, namely -\\sambaserver\username\profile. The \\N%\%U service is created -automatically by the [homes] service. - -If you are using a samba server for the profiles, you _must_ make the -share specified in the logon path browseable. Windows 95 appears to -check that it can see the share and any subdirectories within that share -specified by the logon path option, rather than just connecting straight -away. It also attempts to create the components of the full path for -you. If the creation of any component fails, or if it cannot see any -component of the path, the profile creation / reading fails. - -[lkcl 26aug96 - we have discovered a problem where Windows clients can -maintain a connection to the [homes] share in between logins. The -[homes] share must NOT therefore be used in a profile path.] - - -Windows 95 ----------- - -When a user first logs in on Windows 95, the file user.DAT is created, -as are folders "Start Menu", "Desktop", "Programs" and "Nethood". -These directories and their contents will be merged with the local -versions stored in c:\windows\profiles\username on subsequent logins, -taking the most recent from each. You will need to use the [global] -options "preserve case = yes", "short case preserve = yes" and -"case sensitive = no" in order to maintain capital letters in shortcuts -in any of the profile folders. - -The user.DAT file contains all the user's preferences. If you wish to -enforce a set of preferences, rename their user.DAT file to user.MAN, -and deny them write access to this file. - -2) On the Windows 95 machine, go to Control Panel | Passwords and - select the User Profiles tab. Select the required level of - roaming preferences. Press OK, but do _not_ allow the computer - to reboot. - -3) On the Windows 95 machine, go to Control Panel | Network | - Client for Microsoft Networks | Preferences. Select 'Log on to - NT Domain'. Then, ensure that the Primary Logon is 'Client for - Microsoft Networks'. Press OK, and this time allow the computer - to reboot. - -Under Windows 95, Profiles are downloaded from the Primary Logon. -If you have the Primary Logon as 'Client for Novell Networks', then -the profiles and logon script will be downloaded from your Novell -Server. If you have the Primary Logon as 'Windows Logon', then the -profiles will be loaded from the local machine - a bit against the -concept of roaming profiles, if you ask me. - -You will now find that the Microsoft Networks Login box contains -[user, password, domain] instead of just [user, password]. Type in -the samba server's domain name (or any other domain known to exist, -but bear in mind that the user will be authenticated against this -domain and profiles downloaded from it, if that domain logon server -supports it), user name and user's password. - -Once the user has been successfully validated, the Windows 95 machine -will inform you that 'The user has not logged on before' and asks you -if you wish to save the user's preferences? Select 'yes'. - -Once the Windows 95 client comes up with the desktop, you should be able -to examine the contents of the directory specified in the "logon path" -on the samba server and verify that the "Desktop", "Start Menu", -"Programs" and "Nethood" folders have been created. - -These folders will be cached locally on the client, and updated when -the user logs off (if you haven't made them read-only by then :-). -You will find that if the user creates further folders or short-cuts, -that the client will merge the profile contents downloaded with the -contents of the profile directory already on the local client, taking -the newest folders and short-cuts from each set. - -If you have made the folders / files read-only on the samba server, -then you will get errors from the w95 machine on logon and logout, as -it attempts to merge the local and the remote profile. Basically, if -you have any errors reported by the w95 machine, check the unix file -permissions and ownership rights on the profile directory contents, -on the samba server. - - -If you have problems creating user profiles, you can reset the user's -local desktop cache, as shown below. When this user then next logs in, -they will be told that they are logging in "for the first time". - - -1) instead of logging in under the [user, password, domain] dialog], - press escape. - -2) run the regedit.exe program, and look in: - - HKEY_LOCAL_MACHINE\Windows\CurrentVersion\ProfileList - - you will find an entry, for each user, of ProfilePath. Note the - contents of this key (likely to be c:\windows\profiles\username), - then delete the key ProfilePath for the required user. - - [Exit the registry editor]. - -3) WARNING - before deleting the contents of the directory listed in - the ProfilePath (this is likely to be c:\windows\profiles\username), - ask them if they have any important files stored on their desktop - or in their start menu. delete the contents of the directory - ProfilePath (making a backup if any of the files are needed). - - This will have the effect of removing the local (read-only hidden - system file) user.DAT in their profile directory, as well as the - local "desktop", "nethood", "start menu" and "programs" folders. - -4) search for the user's .PWL password-cacheing file in the c:\windows - directory, and delete it. - -5) log off the windows 95 client. - -6) check the contents of the profile path (see "logon path" described - above), and delete the user.DAT or user.MAN file for the user, - making a backup if required. - - -If all else fails, increase samba's debug log levels to between 3 and 10, -and / or run a packet trace program such as tcpdump or netmon.exe, and -look for any error reports. - -If you have access to an NT server, then first set up roaming profiles -and / or netlogons on the NT server. Make a packet trace, or examine -the example packet traces provided with NT server, and see what the -differences are with the equivalent samba trace. - - -Windows NT Workstation 4.0 --------------------------- - -When a user first logs in to a Windows NT Workstation, the profile -NTuser.DAT is created. The profile location can be now specified -through the "logon path" parameter, in exactly the same way as it -can for Win95. [lkcl 10aug97 - i tried setting the path to -\\samba-server\homes\profile, and discovered that this fails because -a background process maintains the connection to the [homes] share -which does _not_ close down in between user logins. you have to -have \\samba-server\%L\profile, where user is the username created -from the [homes] share]. - -There is a parameter that is now available for use with NT Profiles: -"logon drive". This should be set to "h:" or any other drive, and -should be used in conjunction with the new "logon home" parameter. - -The entry for the NT 4.0 profile is a _directory_ not a file. The NT -help on profiles mentions that a directory is also created with a .PDS -extension. The user, while logging in, must have write permission to -create the full profile path (and the folder with the .PDS extension) -[lkcl 10aug97 - i found that the creation of the .PDS directory failed, -and had to create these manually for each user, with a shell script. -also, i presume, but have not tested, that the full profile path must -be browseable just as it is for w95, due to the manner in which they -attempt to create the full profile path: test existence of each path -component; create path component]. - -In the profile directory, NT creates more folders than 95. It creates -"Application Data" and others, as well as "Desktop", "Nethood", -"Start Menu" and "Programs". The profile itself is stored in a file -NTuser.DAT. Nothing appears to be stored in the .PDS directory, and -its purpose is currently unknown. - -You can use the System Control Panel to copy a local profile onto -a samba server (see NT Help on profiles: it is also capable of firing -up the correct location in the System Control Panel for you). The -NT Help file also mentions that renaming NTuser.DAT to NTuser.MAN -turns a profile into a mandatory one. - -[lkcl 10aug97 - i notice that NT Workstation tells me that it is -downloading a profile from a slow link. whether this is actually the -case, or whether there is some configuration issue, as yet unknown, -that makes NT Workstation _think_ that the link is a slow one is a -matter to be resolved]. - -[lkcl 20aug97 - after samba digest correspondance, one user found, and -another confirmed, that profiles cannot be loaded from a samba server -unless "security = user" and "encrypt passwords = yes" (see the file -ENCRYPTION.txt) or "security = server" and "password server = ip.address. -of.yourNTserver" are used. either of these options will allow the NT -workstation to access the samba server using LAN manager encrypted -passwords, without the user intervention normally required by NT -workstation for clear-text passwords]. - -[lkcl 25aug97 - more comments received about NT profiles: the case of -the profile _matters_. the file _must_ be called NTuser.DAT or, for -a mandatory profile, NTuser.MAN]. - - -Windows NT Server ------------------ - -There is nothing to stop you specifying any path that you like for the -location of users' profiles. Therefore, you could specify that the -profile be stored on a samba server, or any other SMB server, as long as -that SMB server supports encrypted passwords. - - - -Sharing Profiles between W95 and NT Workstation 4.0 ---------------------------------------------------- - -The default logon path is \\%N\U%. NT Workstation will attempt to create -a directory "\\samba-server\username.PDS" if you specify the logon path -as "\\samba-server\username" with the NT User Manager. Therefore, you -will need to specify (for example) "\\samba-server\username\profile". -NT 4.0 will attempt to create "\\samba-server\username\profile.PDS", which -is more likely to succeed. - -If you then want to share the same Start Menu / Desktop with W95, you will -need to specify "logon path = \\samba-server\username\profile" [lkcl 10aug97 -this has its drawbacks: i created a shortcut to telnet.exe, which attempts -to run from the c:\winnt\system32 directory. this directory is obviously -unlikely to exist on a Win95-only host]. - -If you have this set up correctly, you will find separate user.DAT and -NTuser.DAT files in the same profile directory. - -[lkcl 25aug97 - there are some issues to resolve with downloading of -NT profiles, probably to do with time/date stamps. i have found that -NTuser.DAT is never updated on the workstation after the first time that -it is copied to the local workstation profile directory. this is in -contrast to w95, where it _does_ transfer / update profiles correctly]. - diff --git a/docs/textdocs/MIRRORS.txt b/docs/textdocs/MIRRORS.txt deleted file mode 100755 index a133f261c53..00000000000 --- a/docs/textdocs/MIRRORS.txt +++ /dev/null @@ -1,6 +0,0 @@ -!== -!== MIRRORS.txt for Samba release 2.0.4 18 May 1999 -!== - -For a list of web and ftp mirrors please see -http://samba.org/samba/ diff --git a/docs/textdocs/outdated/NTDOMAIN.txt b/docs/textdocs/outdated/NTDOMAIN.txt new file mode 100644 index 00000000000..8408acb979a --- /dev/null +++ b/docs/textdocs/outdated/NTDOMAIN.txt @@ -0,0 +1,51 @@ +!== +!== NTDOMAIN.txt for Samba release 2.0.4 18 May 1999 +!== +Contributor: Luke Kenneth Casson Leighton (samba-bugs@samba.org) + Copyright (C) 1997 Luke Kenneth Casson Leighton +Created: October 20, 1997 +Updated: February 25, 1999 (Jerry Carter) + +Subject: NT Domain Logons +=========================================================================== + +As of 1.9.18alpha1, Samba supports logins for NT 3.51 and 4.0 Workstations, +without the need, use or intervention of NT Server. This document describes +how to set this up. Over the continued development of the 1.9.18alpha +series, this process (and therefore this document) should become simpler. + +One useful thing to do is to get this version of Samba up and running +with Win95 profiles, as you would for the current stable version of +Samba (currently at 1.9.17p4), and is fully documented. You will need +to set up encrypted passwords. Even if you don't have any Win95 machines, +using your Samba Server to store the profile for one of your NT Workstation +users is a good test that you have 1.9.18alpha1 correctly configured *prior* +to attempting NT Domain Logons. + +The support is still experimental, so should be used at your own risk. + +NT is not as robust as you might have been led to believe: during the +development of the Domain Logon Support, one person reported having to +reinstall NT from scratch: their workstation had become totally unuseable. + +[further reports on ntsec@iss.net by independent administrators showing + similar symptoms lead us to believe that the SAM database file may be + corruptible. this _is_ recoverable (or, at least the machine is accessible), + by deleting the SAM file, under which circumstances all user account details + are lost, but at least the Administrator can log in with a blank password. + this is *not* possible except if the NT system is installed in a FAT + partition.] + +This *has* been reported to the NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM digest. + +========================================================================== +Please note that Samba 2.0 does not **officially** support domain logons +for Windows NT clients. Of course, domain logon support for Windows 9x +clients is complete and official. These are two different issues. + +Samba's capability to act as a Primary Domain Controller for Windows NT +domains is not advertised as it is not completed yet. For more information +regarding how to obtain the latest development (HEAD branch) source code +and what features are available, please refer to the NT Domain FAQ on-line +at the Samba web site under the documentation page. + diff --git a/docs/textdocs/outdated/PROJECTS b/docs/textdocs/outdated/PROJECTS new file mode 100644 index 00000000000..3008bea430d --- /dev/null +++ b/docs/textdocs/outdated/PROJECTS @@ -0,0 +1,88 @@ + Samba Projects Directory + ======================== + + +>>>>> NOTE: THIS FILE IS NOW VERY OUT OF DATE <<<<< + + +This is a list of who's working on what in Samba. It's not guaranteed +to be uptodate or accurate but I hope it will help us getting +coordinated. + +If you are working on something to do with Samba and you aren't here +then please let me know! Also, if you are listed below and you have +any corrections or updates then please let me know. + +Email contact: +samba-bugs@samba.org + +======================================================================== +Documentation and FAQ + +Docs and FAQ files for the Samba suite of software. + +Contact samba-bugs@samba.org with the diffs. These are urgently +required. + +The FAQ is being added to on an ad hoc basis, see the web pages for info. + +Mark Preston was working on a set of formatted docs for Samba. Is this +still happening? Contact mpreston@sghms.ac.uk + +Status last updated 2nd October 1996 +======================================================================== + +======================================================================== +Netbeui support + +This aimed to produce patches so that Samba can be used with clients +that do not have TCP/IP. It will try to remain as portable as possible. +Contact Brian.Onn@Canada.Sun.COM (Brian Onn) Unfortunately it died, and +although a lot of people have expressed interest nobody has come forward +to do it. The Novell port (see Samba web pages) includes NetBEUI +functionality in a proprietrary library which should still be helpful as +we have the interfaces. Alan Cox (a.cox@li.org) has the information +required to write the state machine if someone is going to do the work. + +Status last updated 2nd October 1996 +======================================================================== + +======================================================================== +Smbfs + +A mountable smb filesystem for Linux using the userfs userspace filesystem + +Contact lendecke@namu01.gwdg.de (Volker Lendecke) + +This works really well, and is measurably more efficient than commercial +client software. It is now part of the Linux kernel. Long filename support +is in use. + +Status last updated June 1997 +======================================================================== + +======================================================================== +Admin Tool + +Aims to produce a nice smb.conf editor and other useful tools for +administering a Samba system. + +Contact: Steve Brown (steve@unicorn.dungeon.com) + +In the design phase. + +Status last updated 4th September 1994 +======================================================================== + + +======================================================================== +Lanman Client. + +Contact: john@amanda.xs4all.nl (John Stewart) + +Aims to produce a reliable LANMAN Client implementation for LINUX, +and possibly other variations of UNIX. Project ably started by +Tor Lillqvist; tml@hemuli.tte.vtt.fi + +Status last updated 17th January 1995 +========================================================================