i[H0_Ii_qvH= a2hlI, ORo&}皋KuuuuUu-wjkgj kE2}Σ4|lƗ秴m-'yZ 5fx>?LXcf]2d`y2h^I-:nV5ߒ|t {]q~U{`]@`?{Q2%lg>qd5[r+:OE/Ofּ6HZ5@9pF7;NIEpaƳ~vM{1n&gvK[p]ELVQQi9@PTb08C_:&y7i~}=k6iw-wO7s:ꝧ!$#=N{^44wwY]2[- aj_ø߁._`8ij⺈y5])vx]4!~::<38K8vw}!Jq޷vuxRA]Gg/gz7/mOށ=uo378zYt3n_`_9<.&MZE+.B'l 46'YӍ!16rjM=U$wwN`22˶2i=]v~UO;9EzH 伷Tvh!*nO{Qza+T{xMf9 Y[zC.N QDI)jS9鹶hi|Ai n{OyHN/N`uS;<@?7c⇲ɏMt|dW5K.hlj5LatxO g.B}u#>:*G_}ѻ\睊0!2w(#d^~r mxoZw__/oo,~X/m묽8@8wAG`cZV~k}Ym5^twnEG;q]4Ҵ_i]ǵ wuIoT;Ι's@feVs]aՎ. K<_;`!m^\dZ LsZZ->i.<}he-;}==n~>; OɬZT4M/NEUDGw7'-@DR$ ov]q _#hb]PmlM9SDX.4Cuj`A7 cÂ΢K[H5j n;;$A_pZ 8ߝ܂#iҿϹ+û&Sb01, Gw|xο|y~w~pr%c>,.5ad[DZKvxoyأwx\_grkAn|{}px[/anq;?>=y׸}݄GE`+V7C\!698Jwnۧ__41mqQl~El=_Hѻ]|E}oGpwYX)eXE>Fgxg_Ev@L4>Dm_mUF3ЭuӃwmAN݁=:zwoo~6kfq(.YɭSָ.~G}|]WD(WknMy8h,aeM@a 0]Ku[\4;H#LQ4w5㶷onq\5omɧIgEBSIxt*w4?>=mθ=?76w޵ -v}Zqc> ! 3e:=/38 䓑}iݦUhG#0r/ӼC\6'PG٢wk"HY!hwBD6u"W˚Fvc8N#"Jh.>TecpP^eGb"2`P਴ҳO-A9Q.%?n: 5C0(MO!3ÓK^C)EiLT6zۧzH<43շD6Ͼ1_bF?}Xk|3 j`͎2z37ΕuXJDQ $==-]W)B V칍K^s/==O0-uqW܆{g_;`O|ܛI+^9FKΐnl'g:OY)=z>BNiՒ+-ZoP=.Y鞔ïn(698GB9 Θ?o c=%,5Hsv?N-)Ү?*ȵԀ<{9mZ(vae_`Yoj;Z|篪խwNvIaˢL6dN(QUmbFT^Ie!9?̝"{CC+y@UߓnjA?_@GF%]iEga~%Av"EjJ>k w1 o!]m$k]彻yq%٪ω,i~mtV6p {p !C>'vd`Y_45svPEwWOf=OS*s 5 (INք[̒y['޶͐AK7Ggؼb ~-ͣ C$B(2YTMHOX)ܦw&kVʺq zܧ S((-ݼ8OާC2O|sTſ*.a&V l8,nm+_8~ gM!Ⱦ)ྸI Z'Sh;׿BpހrewdB-^qynKBl=hfr84Pm'2X!Q8-Ņ6Y9x04l|^ksrny&A]{  }9u|zx6^07ޝen:lw/xso:NO_6?'Oؿw5HSt2?p܃O]55g1DHIxkЀ j}_?pۛN-SRq_to@ۀU3#"|`W!^Yt> s_^ܯ{<zE89A?{t̿wiQ@%7do$B]{(/D#5ȱsW5ٷ|BZAQme%auʮԽ-+ݤ2Tǚ*Ș_ɭl8 @|hC1&Ȍ_УC@F~]T/~5i/~_?{?@Ӯ_!"O_h(rp_؃*-1q  Ѝ%O2t /]Y 24o-GsVO4y] _\(CW<:am"8lX;}?&SCI",nSb7hjh DaF N-9~hWJE;3IJEnpIRɚX% V}.nHh및]q'Gʿ)@{Qۋ}pb?AA}ғٷ3mPዷɆ~Z^| |F 8=!@#^9dՁ B2( )E(UBdRˀ"/ȢշW~G}_6MI_@.yrdsbyZiA+8V03[7mhxbuzGN )|D*W=ÏNV'gTѼMOu*@vlT}.Ia #b _?uɋ鿡4TAd'uL LKw l#_=1ŊkUGAz1z-|=tD. )Pz7k:|ryu:/u؏5Ȑ!ůP;'=p "J֍x[^Fa}tb^e:ApZN,T}VϐpevtJ۰˞Uʄ-W>n*3:C'w J|+DЕhr`.B`Eg_ yK!k{vMh›И VSOs‰0М4Ȁj@?6 |'~?NhwMiz:^[xW\?(4  ב9}c]˩K1;x| CD# 1~_X/^yC1O޾xt:>l& `y1챒9r]O;_Okg釓s1*ڧ>/ vԺ|1FZ!>gup~x{q?zOu;=F{{7I.zl|f^[`E{=JܻOGO߿("G?}ꝝk}%֍keݸtZyoW_==kIŏNYv;//m;]5F7Zyq.]8CvaŗǯO>go?/w_=?O۟Ͼ{g?g_|}ν&'gwU&]|Aof_n>yQoi}[˲o~>߯l,s}>=hkgb`ܿY;?:۫W/;o?ƥ1߄n itFy~>s,Uz6O?:Zç7g7F{׿9>>;VƇ WїMqHwioֺ~_6OܯG?߆woo>||>7?v{{_ߝޝ~zٞ}kO>:*[ɺ}=;=~v~㸽 J8zss~=DwmݧՏW}k_ݽp־:J8Z >x{Pkp}~n5/>oiv,ˏzUٕ^~PwuhvjGo?Nr78^~U޹8uοztnnY+MG_:V`U{_vC{mҺ>\{i2}u8o F;mp}۶ٷg:7=K~R?o Wɫs9Lbj|y{{zqry~?}zdݿj}=98o6}r}>z-nO֛76g'ߏD?_NjGgwVSk'ᨯr__{gsXq{y6Vw>pZ_kY~%?6߮?>ߜ~yjO:9 wGwf;7U>gW?5~t: VF~c#tZz[QwM˧sS}ov\wǓ~<;`0K7EջYd_4}<ξޝF«~GchDG7glGqKjÛFcsoO$׃7症ǻGWoݫWo/h|HoS}pca:5Wϋ/gFѨ8<.WQgqp7bwS_|;Qto_OEo“ǀƲyQ~\k֋S`sp7=z{w_O(wd=8x7j?=`僫нts~tQ7ܳ~}gEۅ=}:ۜt_>W-#8]\^Ͽo4{x?ンg_޷]sիs՛(:f_oOByYHn׻_:7im}D;-ºqt}dy헻U*f}8o}(~uK/ɺl `4_/o?ś$//IjgqtP>}?ꌜtH|޺Qh_.{gO sչϯ[DFzhug?ޅǏw;6chͫWwޏ:[C0C{߮"},i}>9{c t#;P;~]J6QગZ'7~D'O%Χ1WZ>o[W_/WW{E{x9_oA}>Kdϳϧw_~>;]ߺGi~)o@7?>Mz;7Oh,?\׻ۧѢh?ڝom'x?k'<տ=}(||j}Szw7a?0;^7w;W?x}*;yuçї>=ŧW?]\FM[q`=OWG'?k>_ٛuqtYJ~`k~}x>{`T]$7?Ƿ(~Y'?nݏ:߾؜|ڏozq2rF/fǧu۸3~%]AE>/jںoN}=n_ܟWǛb;8}x7sӬ*{Hw_z޸zNk^ɾs:-n~G yZ~_aKy{>.vΛO5oO߼I~|8?g糣8~ߩy)z%@=[rn:ʷqBjlżkcB!(#>]PC>Sd2} g6=TڔΗ/%+ ~>@~lzYh7/$ֽ)z+% 54Cϟkbo.6`Z1ulަaHDdzo!lDPbPGۂLV"9.:aZ{eMYGTPjF7SChtFa95u_緽⏯ӽM _bo8 L(п"K_b{U|=ip-=ntdq"٤%'Ut m#-ZJX47xcы>^dG4y/>ϟ{ȑC oe{]'E`\9?a]\8;}+$d\iS#=WWa2>I؄`B-/4=~M߰Ճ-:O>Y>_up̽J{jVK.5x7~y F,>xܡD¹^En˱b1 9SԪ%StA3 !+EJ8ax*JZ~ NZJHqQФ䡏deG2N]C8Zl@Xj)~'|kIv'?mďEHPC,RWoab熑*J.. ۻ \gu~ Ǽ:eu[0p]݅_v]|)p@ 8p/J'a.kSճ4 _@`_.P!=wGD/B6h\Q`_y]#fwvv[ \U^tBz3OΚO2e[{++gzqr% tw/tgz9.(ʂ.ӛsU/P0EE,'?W8Ͻ?8]]pˆqUZZa^aW523ZLcd^Md?/FzMs )`tBZJoK%| ,ͻiٓsU]1s&S*&t 0Q.&$/3!pCl$ۛV3ZDό Nb=*4F-EvN#jr:A<L0< X(# ~OڕQ#!fyʀˡD4Eӎd^Zw}Mr֓*Q|ٳg_? s??zw~d~v{'OƝ5/ϟS-Qٞv~\-'cs?x~?}>ok akG` B1#sk~jW1yxz ~4n_žAH k=\s], ??RcL pc> bw-ouy5zlQvwMx֨U~loNk0K띿*6zօ?M[&fwD $iL0[/Zq z՟`tva9n6^l"o|,OyIwS؎?|] 4L7hzS G17/f*UsZ?t;ncJݚFZLZؽϞ*} o kKv%ESt`h|afxh Hz 8ѵ@`3^^>( |o k7 _C$jF{| "<]8dR2xjPHGSJk`2M&So]ci;U0In<_@Y֠V_N6*7!'4Ca=IV3Mx:`"]-"f3Bhd.Zy7MK" {=.DW"(&Ȇ< 4Mb2Ty\{Wy3/Q dGUtSO$_ct F nK$*Eю̞@{#* b!ԻӋ;?}~wIJFY.zsݟ,63T7Fi:m8ow {0Wy'Z8Fn_׀?od5V{ gitk& |ր!0+ ְ߲S)Zݤ%zl+ ~(n{t[l!b"! ȴ#.taS]Jyiٙ€Pa.:d=d^>e:f P_?/kJ+N[ Y" <EM#Idٖǖmh, Ćmb0:sʈ}@cO~'X3 ,lp)ݣmnd;q24IaeULU4[>L>U;ىk;]>TbS 5lbjB iY1kve9q{ ))=dC)!q)x{ D}^ #ʄځQKaׇl:Ubv-wgrp+f$Qo ġ ']se呧7+x)5a@S@+&-p^iY4h Sر՘0" rܨ0s=Arda^Q!e6O S^KLʛ*4x,*v9cN':,{~3 ҚEKRiEA丩|m?H ITg3zЙȲ7f]#+~ءNZue9J$;eʟ 5A1Z5!mpsrו"7q-JTK^QnGCT- kh-FMEwy:,A\ FvNնI{Gv:_gUաræT~J td*/ȗիLv[t7^Ҷܖў@&ԭ\j8\K}adzfl6NMImKϪ7 ݑV+r^J A/H5Ry1%^7mujM@r7#lu\ 5צ":n2ntR/ϱ́O Qvm'z9"dmFBDk^ngt6_@_2FѸ80 e=4iun>j @#ݻn% 86L׈aajI"GE+} 75#*?;|FL𦩷ZNvVFƀ oh&&0ԃ@b}>T9` ;3z6c5z.L/4x2r\- T% mYk؁iE5Ќ&`"4҈VE$zXYk8[-*7. ]3ݟS{vQ,f#}<0[XK瑋пcr特).|@pʓx ⶛o<|{635q۝x8rd nM ֎B-F>-Q0pqWX'f ʾaX{0gSvdY<Z< ,Dv=<tTRHSG\ ׫|o0CFt ,@I5Ytm꫖cUo!Cijv. tx| pJ;U|AF~V&Jq_i$GRg4|Mp m Kj%|Rqg=+ ]n (ƌr6mgt.Bljƍ Hx2T*:DhOʋBﺛ(` K>GsQT*`qjd=`3 AHCB Hk'Cy SWX -4Uh3-qjS^.{N/z"6?u ԞrWLGɶlX mʌw >a/jX[l[Jv:IrF6KUS͉02s{*)[KlamJ4Yޝ`)q0v RANz` #c",T;>*- &bgE svؑDK<ƻnWfﰸ}gRJ ɽ!xF@c{ bSu'4_rK'y%,Ҁtp!,8YfYtlqߜ;tJ蠩~rAAD :B-yc&bʡ́wt) {F[D'dRyV_m^m{Y-+>&dOYb(!heNzo{ bͅ_ I%dk|ďę&J rx0?*EAAZJJaL$s Q,ĵ&Q1sLi{(sxK8FזxrY0vT!XY! &J"BВud _Y"@=+}o:ӢC2|LIN Njqu9P;L՞:<&>Z.G& h8,NaZ:,:tx('CeWU,pKcа2c-/r-w.KP/iJi#WFo4p7f2n M'f:u(5ݹiܟ B'CS2DQƻ-l'7(`RJ/z3>Bhd@ؠ ϺJҳsU>\_!̈y #8B3t)8npDƅ-1-8t}mR}`a-fB8E4v=%5lHՌ=Rz"]ˈVE Jr?(@Z2κȊv$Hb,6K'Q .+[ž|.1\IQDsR(8+qgrx؛CzG4ȆC艌a4JX I)Lr)RzȚIp9j/K8IV?#';|ȃ@ эY.cʎ8Aygl17netl2LUV@ z2!4aMnyS};i .EJEp <ک 7M&k! c^( sKq@HTILǓ)2].HӴLH u&8Јwsᮉr⽜ ̤Ednq$u)Tj1/b$ ^+ R_Mq?*K)1 U..q%ShS,Kc@7ٛ.b {;K..V˗j%8ټos nIprvʴ/@`\ΧКFI W=f=*L+%n ޷|":r:5p!<4Of;}' :4QR_؛`3 |tbU^E*)iC1QMlKeiiƠQƲ%NWf88%5vBҍ#NCf|HQQ2^zo;I"M팽Ϥx$-L>jRSKG>!P23ECn>X~oUn 5 ^=de0,-ʙ;^4¡Lu6?Aݶ&ʪ;X+H,Bdʼ&qPEU+DUȄ2$j0}ZEZ6}$Am {8KŢ*Vn!/ +s0ɅqW,g$[V0վs\uq==)V{ 4&me(1sIhv8A(IZ1 x{U)Hq&Tskl8ѼF++,~DJȯ0Q _H%}jҵJibK3ns+F\!!e"mV~%&\o3O^fIjZSjtVrM=)^e1^d}F4#o+!6Yi`.shVLbm'm{^mˊJԡG-|OOL} w6MtTk6lL?j ޷I~J~ dDgj. {,p5&8,ǏBWsa_E_zJ8e r+# [zMeN#cZ.-ABBcO(r #YY&q1JT ) ZӆaHdoLKP<ĮDJڰ]l(?NXTpJt?Cz7u]>|{/=4dԔPWe-Jk/&t$%j5>m1"]oznSn-Csk(2&ҝ2v.gduE:;iL)c;{a5 @m'*YGj`V1V@I_X]M+3Ғxnü,ݗJ1T,Z>ѬeE9MaUaD^ag=u=0h`*@X,l8O*. %$HvI"~oTIa st@x4U}Yq|"n-Ñp%)I__uqv<ףbb`#U5 ;T W*+^ LE(]_$ ,ܪbҏvGN& WLEP")S.~[ ɟ}@LQؑbRW\!LaQGlML{ œ&\~%RpyU -ӡ۰N>4[aKGqRṃT=ZVl LRHoX&٬~QY*>s6̲~qLneQx,C@$.4v6`dg-f$c+BT%Od-{ky\a(L p$sLN ahT 8(;i71? {5KlM۳M%)1M~11xD}Hx +ԙ8tLƒHjAd\khU[f@lj=rDބBd5kb=V>[~&2bfmUZHV? s] ] &؄*6NH.N 3.JS+Ӎ`]3,McKT[;NpL}HBIS t)A\๥}3h?`?$Az]Ѩ4e/9 @)r#AL*XGE.zp=(-Ȥ⊰e? \ac(3.I`)L"JY\df:ngp0'9##v4Lc׬,DzH8sH q̡ĵRwX|XPaѿrJW͍Em#%lhdL2nABrC =1 '(8>)b$"ߎE9q>59b.1R~&"#a, azr 3H=[BFCV4%yC,lrѰ1vi2Fi;8Xi a0*'e *V#¢ub0 *NF$.D: (SEAeUr'*ST Z"4 8AUT T\]A:?AU(X^b6N5-9 ẹY.sԪxUTΪ4 MIҙm[ [ Fj=#;`])b EPR ;.0D (Fb?ZK_Y>T2m\}izZn|6t4uǩ^Yt'jYi;ρL26 1~3|@WG X8! ܭ&e~8y!׌J§a] {ixSg%Mb1Ef/}_]02C[0N:[Ӵ#4pg.|{+R?j q ˜ME$i퐭H("tvUXK*c #wQZbxG]{Q+P*Q\_Z{QUjr ->mh\!t|Y")I͗ܬ"Zٰ#i|l`j՚"Et$C)-nNilE,`q%5S ئ*Jp_fU9GSޜ S`O>e/WۜM/QvV8b,".k i dGSEv)h,H7,5&32.,:d ]aB).&yr>DF~ WQlUM2'5q>  (y}m~U8*EQt.rS.Z$%6zyuyfO,~ vnYX=]>NlˮK!FvX`C}:'a MeÈ_IݶATv 1Ƙm[YP6mXkaw6,!AlZ|h[>%Fxq=,?m$UFřVٞY,#DDԅ-YTZ2UgIznO|`D/)ZNR "y- UʱQc)0Wy\g  ͟;b gx 4fBՙfkR@VžҺd@A%T^bQ}1l/:B>HEe:Jߒ󴅎T9hhI"Ge'v<#kFks8pZQDŽ hmޖQٸxF`ͤ߱#o0vf`KYlʸJaCTVXFyV;bE{*,f-&gYn:8ʼp´pUgR!,t7l'Ez)0plNZ:^Ȩ( ^ ~³$NTB_?|z4)Nw.[k̃FG! UrHSLT{IfZxzQbm0]#gqn7z!9-ڐ@Y.hję(&- ɔ ݿJ-OġٜEeo],(?67^?vȪ,+f\OGQPȍM{/Pœ_w Pn=[#w ]اX2$ }mCOgZ 2 :^Yi;6+AhwCw~#ߓJ¡VUE{HJYvM Iaۙ'I F>4I֋3 14xeӅ7KpިI`"^b,"m^5I\] ԣ`J;s xyQG sR+l@/i&8 2%5oPEk(l,2UfeE^(smָǶkQK~L^x%LnNE艌^m.Ň$dPt{Yq>R\LTdiLˠ7zXS;7)Cn͒QkUe4˞mDF3 z ^y G%ewdJLe$ K M/kuia;KRzMwZ@2kֲW-n9L$"o=ᘶ93 W!Sm H5Xkbkfuf&{r( U',ml7 dtqL6 |յ(X fzl}2qɇNtaHbV+ =;xVlE (Ap|Ywˌa%&GnlI=45#ܚE2VO׳E{w&iIc؀gX,a{!CRijUL \1gvxwoR0MA5~}ǩ#46tχ4"͜dfPV&q\%ptCĀӍ5X-f"w_W|ձRIUwUˑ;c2Kk_A0QUb&XIcM.7" 1USV̂v,QQ bo;$U}Bm> byuڐ S3TA%wCY 7 VdK̠c)+&*hq S[U] 2/43fbCgeF)_$L|751H=4~Z,vH)Ԩ-kaR3DRo`e2+QowDK@Cv&Aồ􉻇Py̲Nc!UҐ, sp|G>]1 eg!-Q_- P.Xx %{#}YM^35߇rhJGxq|5nML(;yJVp*߀E hgA⑫ m&$Mn `] EFԨ)<#I^k\8'n*ÓC0u|uAQU꘤:l{Y|us4 Hfd$ _/r&YzcuUzh46Tc| #rGl!2뗹>%2VDэL<]s媞Ck ޚz j;ʹ4x/F,L{Ŵfǵ&_R<yR#Fb* `THhH)gHaE@ϊv-&(jp7V`-/ ܄.k3}adzL,MCXW5jŝY0wƅޗ>[L̓toĝ_arR- p=wJ9!DZn견8՝$%L [2]Ǝeu=}5"*KՔ(꼹 +rtъ7!\5>R r-q)QYˊxZJyíǁ}11v+}#w969l(G&a-E]@J =㍟%(lͰ;݊,K˺ ŊJځy 1r$e {D0DˡeQSj1̽E(Vk.o.UPfY0_-7w&gR AA ϲjEQ3C4uĽ`kb! AS;iVsֆJt)Cɹb;Lsaߺ ?Ċv9LJSQҐK87?Bh_eoaK`0̜;XCk6߆2*'Hz|̈́퍳=VB[;X9Q뵢 %@O1Ud 6Ԩ꼵޸;ͅC5&HXVX2d`2w1g HC4HZ9,*=~Hg1#6:vr3w i>8kgϒ4IWŰ57:Zv#<] K1!dfpx-BfxXW]jⳈj-Ied13SF*`%rHӖ@m. F`REUM*+sLGjY% +,U4EO T"]8q>( mnIM4Ô OD&tP(G$._'cdת7zc?âxCXHYĹZֶ)DO D6<@'`XŊZ 0nL~dhWy6,,Livc/&I暺^}o Bİ`֨Ji[ǹvX?nōtNbR= ;ZM,%uz^^{=\AK&C]hkpbCv|$r7O"nMu3('4 _0Z:_6^ c'zwTP!  5Ơہ[lʱ;[jgSǗ(m1m 5|IV?dEh% m쒰[r͒;P$9E9y_T5D$"ӫ, ᪝ʐ0ԙ9ol: U@!%]VN: ˞4540R ‡7JPJr?\JTEU tl CŞ$0L;w=+xm񲏎a2X{zݩRrxv^[i^4<+@͖j/;0Tx|(*rzjkCt;;JJ퇊@8zEݒB , f@`r*Rorl5lƮijLc>RX(04͏":oir+Gx,)"n`=lHBx?+hVyJWBAYAȊa4= l ^%Fs *{.h~[I)Q&.;P%/*&ngUXfgUnzׂ|X}'[*O87 [7vIs )xR4C&ц&vی\w)d Ϗ\_|΂pʑC4D؎ W 0dE˵+U֐> FQ;K曬7ǔ!H)&Aڔȥ0W˶lE/g/Qp@! or:agPzMtq!8f{y P{Q`k 7V`a?طF=n:%ЎCHl ,ִ-,"c".~j"^؍閗ei鶼_OZ4X͊;;<` ̓)NOoaYqER*Y,"lթOٔbF-0Xo㮃6٠ U|e-L-^m9h`Oikk#vIx:9dƟYM|L5 5I K $(lyLv 1U4(0Xn?+[%Ȱ?D㹴pc(xRʗD.p4; M=OAoV˗S, =)0Zvsk YL͍"Of183?r*3 WH˝oOz1\vXb{V|3,Kg_ӥɻӹgU G 'WDNrC.cf|-WNZU7;mht9"oaty6C$ 4Kj$T594oewi9-5%_|HDI┇~@%z{*t3K}9mn'BI&Q-M@-556l\ 7d1ɰˤ4ed8qBnDUfLJ73bfrv0 I^eŚFYۿMZ~|{Ȕ$%POKYJD$XBO?Yhb)`Rey!d3ꭱ k*Jwrl(Q'#Y Y% #!2u"CƾÂ'&;;x.0{^uZtұ hpֺi'9jpA_WBJl/vz,ZZ-و"y(ӿN>'12}@pe({"y&u`ĭ К$M@¢GXCRWe`Q {A ,_­@uS.DEMrԸLnsnP:7z0tR$[Y?NzAK;k^%;ELJ&[ٵHC")$V- _۲&O#k\ DCT]r1{.U»֭VaMuifRy|LTy=g:#uk`y{ht{xϺY#VxbEWGq6K!"Hչ`WRqO9Dvf_/o~jF8tBCLAM0Xue2UJ.抪ȷ h[-h@%둨 c9ozB_"d_I *5y-MSc}KFI+9I[Nj>k{Fla>⇆'Uǃq+͓ۛQR ۛA2z4,J S!MyXI&!y*DhI;5.d/Ew^X, whL|E!5AT=R3aoKPh'؟uܸ iHF+@/KHǒL. {7l.(1ϡrlN'%qq8p8BH9 p}ˍG嚊Rn{=_-l~SEݥOQKjYu;}5 jل\M8ȣpu L^~6Gl;@!CFW` | kibyb2KU{diYGm31{Da X(885ɰVW$q|ڥK8kؔWmQʛB3{KnK-j`]e*? ~ fO*%VU8* }GD@Bid\ǯpm$TjR2ef#_ >ou_ ݴ촯2p^l3qs붐@x 욒*J|\ҘWJsYچQ;Oۢq@0vvaL,SK-==Phj[lu0-L'8nŀ$웞0AYJ_IQ>WJ$]+y~Y响Yl(@+ !tm3EP{(KmyE"]˓xаvl<踰Gԁ# }NMR_DTdLqH. R0Klzi4S(m(r|K48O74{iuTNodi6$Q<;:X?gq.;\x"@¦G2͆ɼ%X9b]HIkx;ɬgjAV4DqI {yeg򼭙kQ*yLJ]xZܬ"ZٰӨ d"^n>~8~{y~!|Na/E@- He1OVu\ &ي3: Cw8~ w_pKJ&NYٹ>\.0o&1 r+|ӿE:L؊574ڞEk4l W T=cyPUɃq-S-)ݧ!)t=teWdk;5 lUL8WY3ZLsm j =&1/[zuoHzbW %v+ Lt_&Cqq&˓"!e9 QNgo(j]8 U[(`R]QKĊ/VT8rڋ&)bpMwt9&kB.~pK[A10 7*^yeߚx(7ߢ9؀&_ؒǏ O%JyvKMת ڹ ԩr;(TI&_s,1ĥ1 .7FI SzךH 0rv}W,|@7S]tZ}g.'9_D!`t" 1gZ$IEu <pMq4{-d}0 k@1 6$N*?;WJ$1^B*Lt/3E;Uᡦ<% C"TJg6@>LUM:\zYPxK.ǥ␨%آ&>TA)#H yH bt|}|tM&>&5IƢ)1րZ7<:j9r=6ktuˠLfLZhW\TF0+_8W!ܕJS'6b8 6Uxr3`C4(^TFa:@$u$;f;Zt7yНi]"_L~VSb*q']w>z?ACpVD[$櫬gQaqZa5ݲYZ-zNqGHAMikmfo >VCXUPvgoũHxķ?09(5V;2f&X.tYl y0ݞT羢Wv )A~v3olbh^E֝,ŽxJ!ŻMi|4}%"4Ѻ6~ًuݞwzIsV z:L Lg<͸5 _clH$] |M!n=hi: S- M˴*y2<5d,=wA4?cʘLrҌ:}%܊{rZXL` QfPDq@7AFpI';m3kH` nu޴7XYFބXHtBk̒N7`O2Q,?U ,6YZ,.[OF̤gzn8()kָO*Gp6E1kT87?4=<$ŕ^ha=vLoŦ2A&ޭSp>+yط@->sWP _djBg[=J!'^+`L"%ErX@ra?R\RW f敶V{58f`ZJ>8 wÇrok*dU}c R*:r\o{9eRakeO`yGLEdP Hi0l:*mx7}ՈHX%) IDeENV#M\ϐx VZ?Ie 4eo"ĭUUPL`(4*Wd5$pk!<Ô=;ȔxN$|訐)O ?44 aʪ•ih_iP&摥^<=<e`&1;NN!=;}K?҉64aHL!W#ôH^M+[&&u:r Ee<#|p!fcQ T8;e5*BC5^L˩&DfX921IԉT\Yu,XvT>Jܫm #ujI/{2xA\v=~ Xy"7J#mBX%PD4f_ǖ{*.$|zޔ׳V?j=jW`׶L`>O?Unpc@IG 8RJ7DE5S{VU,0 p2Pb' lP gO**6wsl[DfӁ`Q[^;?).$Gn FC1[ߞV%RN>4~ u22tn8\O|4,s;z>XSgq2(bb wXS& EY@Id$C 0* Qͺ?m#Ɵ^ZHQBQKq*[Ӎf+.RUcbZfhmU U|Sv3+~dAہ OmV3h&i(/{C ڳ)~C &i϶,=s>%Ӟ,v̆1

b"&OCg[:%Y,җ_cѯbMث~=1AUxf$=2~82I`votَ[aRYnxV7kK\d#Jc[}>ufN:N2kL1FؐnC-q:iϙ\_Y\ۚ!LڭY5&! #C,k|ͩ9(y>#D` a7a]d.UЕ*j @07ӛ٩lbJs^/c$z* PnZnV"p^.]eأ7ed\s‚+g:=!E=>r}4HJzhO`[H哼~Z4eP+L,O04 tc s g(% !yY] hHڝ1uW_d%!a<\h;fT('0i\ ? %ʰb6v,SV γ0 e$/I XMN|_T 9CB6QZɾj=t jۜ\}Y8Dr46U *-R>wVͼtTL<\q"ٻL*z1)Π/A\Q,W۠զjLJ3~:}~ 9}=+ag $+]c3wvM(Y'DN~ $G|W TJ``sʼT&j&Y]POI׃qg44%2UR|JUaV"#Z 1/vjÂs;۳E:7~,V=ԨEviqkl"Uc_i(uBD`Q)l(-[n+ip4Z []Qʴ!.߰%L&GbvTu(*"aJӼ5=lsװ-TA{ThLf1< 0?*xEѵj J)#`ʇ)Wfkfuf&VaԙھVYЩ >~ w2Y+X*Fjb `  o CJ6+fƷ2;smJ ]z"N) 묏ʶɯ$&_DJasR0R9ģ|yhӌU2H4=oDR_AUlAKi6Z;kEԞe^_a7*8CMΗ35>e yC|Q9뽶ͱFYU gjBavX*T=X\;;,ACH?Q&B_RAH2gdboIAф<?j TJK7)_ ʓvV>KVI=qxF(ڑuHcˢŢH#)b.wȍ@_BGȕ5|?4fCU [%:5mͥfATd(+WqыȋqQ-Z5IS siia;̞ P6SDZl+oH-̅m٠PXhzESdT0M%K|ˬ dco-BYH%Fw/3F2c bưS%ن{0Nr7;efya(Ej|lT&:z݇rmoeG'jwduPwb3ci?`E@_?utw08RP"O]yD dJ&*?gMZ+a9k8[UWYmv>\D#s$/Exj ݒRk[SpؔXʎ8\ ~pm_̮zednY &^*GR0daGpOUtKsM͆XJҕcnb]U! gb+0u@l54 #k[Ubi_JDĉh11Vc_Ŧgةjcz9W5՞ȯ1>GL8e(SRKb+F5sX)ԫ|~g~Mi_Z0h ZN:yOǕ[}]n T3 Gq+,8Ge'!/s -uK*#p/TSvr*_ҕDVF\JEV/CTQOK;C&H˱v;':]?'k}cXfuOϕ:T5L$gGY!0WܖP|u#4Lڵ rn*G1qj ŀc>,@6p}d7֮zY+w% j@؅BƅהiYW&Ud #.uof|& LKbT&XȅE',UNĜuu9R%xlB,:n<qL, xĄAv:'\]+Vbؕ$Wެh!dNA%,DHdGU#t: E ɚw؀ Uɠ*F5['aW:UE+o"(.N̯@Ha%wMMqw-ydO('}Qm.LS,'.I,,Tj*7VF`aTS? c1j}0cRʬ#=ϐ|[1CJbZE&LC"TYM$/V5LM浒ĒJL"ŔX+LPySf@R<ۙ,YM U8Y6-faG >/lޚ"A\h pÜr*bPOdAi&!9nf,BPFLk˓KSЅ9 }ĝx9\wyԨFc;0˴R(UxS?_n]{5H &i4igihG{O[SxQJ% %;TQ;vmvVţR΁а%떂[4I{Zt Þ,J~1`FWI;#19RQ0%[~[W@33Ǟ@8]V_vSvQ7.<'Ruv;rl3TE\EUPe* =a]VM+G(T"'TF(몁PSE*/1ԗŠ n';CxXaB)Y5D-i/GMcPPSylT؃ld6zjAbI Q{}e+(s~ pFahyNv+yg.[9}ҧORc2NF:&هZ|_r ,&~HG04CI!^gnZ:ˎ/pg3iwq{:vDNw+w] +/ nV0KIIz}&!=7;b(|0!P<~TK"̞T,-<# >UP& ʜة!Eޚm=D8/ذRʍ\֪Ij9&6Q:UlY{2Ϭud"Ÿl왃ɁL({4j՞I`:R ."+1PGްp=RU FA6 jl)5u!$H>a@Bf *AM VZ4IR(Wn@E8r[DΉ p]f֕)CkXHiO:,'ˢhG`fO ]lo|Lm:ypFvNنߨw Dx%{횻2btIP+q'=Vﴌt𔸴(X8`4-6QzmުZ,{N;Cz8Zq mXW0}>Caax}zB ??''.x޼W/"rJ L7쎰Z> $^:/I:fSN+_4=b+sWhɺ7^$r'-dᕾ%Gm˾*6TxˑtE`t؟O!IP>~Pq~"(B\Bk shbN*pvG^q yfYO$QOBrьOHumKs4kMOOc HIC8XE`glnS`! 3ʶYk`Iy5b2rc4~0S\$6^ G/V$BKKO(u6|gRa]e4tT.q}L29M=~2 !#h ׾~_ҏQL|v2IXz'q|EQz|G^'GTZI{$hB=z _/R`Z/4Ijb-]U: SOC\=6 4<\`se B6f`H%lR&&^6kh3hNe6(NQ9GYgZگz ׼1gQnveGL16MdCѲͼ_ݸ/<@h='u eЗ84FI& 2]+(3=d'~ZbgSYy*Ñ Ρ0X1 j:9Rب@x˧}+OlA^?];y?\GeߏDAgՎdvrEcOWG҂I6zV23ZZ\Vڞy]xIfN,> SW++/,@e5]EqKle MʙE Vi/Lf5Im;q'톖sT)G.1, Y$<]V$..xec d2؊Mhnm"L [WU_ʴY;LgU,fױ .FQ /Y"Go.(l3&$)[ r}Hx˅D&xAKwtw:=̇ <.& ra]OWŀ_ΐYA#I{Mevh#Q %EO:L sFԂR9#aUF|pUQKI֋3 ]! >dЛggMjy}qڿt4hKU)ly%漭<=sia}]7ig$q(ιXOn:x'=oV:YqtUU H(@W/KN;:4A[WUbVB\d[jjŗ_d-dolQ|1^LUl)zAfDja-]. ruƭ^3&ocB@1:{ 2-K3@G#Q0-S&g(\wTx@T(̢VRWէyA;^XdUbmlM!-F_*$[Ѷy3[jef6^=Ξs䐉>(/0m_y598s~8 6Ym0%  qܫYxb헏/$9%qO/c4"X{^8E2)$Q2',36OSOߎ'Fw4RC@*>JU@9,3m!JG;,(};-fJtU-unp_¯X4EWJɦJ(XX . #./^|]B)rED=sڬԅ}NIZ[HCLYTliE$6YLt& Te]S8tLSB73aK& ,o@:(ɭhbk7 k4ɭE-lc4ii{>mV0 r.4p+N=ZF/{Q`HK'ڳNczі@cEhM4{ Ab 2dHV,&` Zxsf^h q11j6zQ0Ӽ/u"vc<Lfr3+k3g'WG/_͸L}^MePbߤ2^a֠хr~$EDLK:J>Je3V( ЬFũeO0Hpy kHѬ| Ift-#&<> 7˳;l[,$E::G5dѷ-3,fy+̝^=ŀ>Nƍ%|n7hh8LgiIaMu+eٶK B뱌t]ϪpZ Zko&❩K*rZ["7=D2i-2 l\M?n1[ oeágylOrp[;*Jg'5}(~meQ*Bѥjꢓqo*` vL,t/ss]xS|$Yv]NYƏ0lr).cqI#4wq}ֲWIT4d[̫'%<8_U1 ×^+_&.jIʙ( r{"GDjV$%?)kVt7Ѱ|i Ec+ň5m[g"ZPU1THWhu4 :<%S}9崖ɥB'OxTē W) .b'Q.@/KU,NLmX]{*R;/\`i/(p& `n;Yt´'*B ϟ^OKS!m!oiCסseBKN8=./" |> FLl BMQ;*k`2ٚԪ& 婶Y}2ZetjdKexfbLa'="p{1d6_`T'أC\/fbS*rvU@ AbW,`(qGɶ:HIuVDQ/I:BT[#ʫ$PQz7g1`{F#T" [$$~J}PgFChˣʼ OSXfٺoq;lDT%%Bsˁ˴2Z3nXH~ߩz2H̳ )v Û5[%T5//RCo݋$NXҪ ` F"Fos<67ؚS`NUU;ө6ſ:\`+B^UgU^G}%n|\> Qu$_ *Aby7 &Qx14(J2_:i9I^ߙgx -:gSB )v\7[MVa:׸ۢm[[.W\g~R4/tO ,V_EuPw*4|m<(5(bdk?r/qx^+g=q_KW.w9GQMSdބͼIM.V:7qѡUHOK9ao~i'M%+_1࣡Bݕ39E·%- Vnp /#J{6_exLOˋH EJƩ3N!k>L"~Me/x+ѸU1îʼz+QW7QP{@u% @㒕qsacƷNSLgX,7P y!Dblbo =]+v :-F> }Tn> 9P<j zuunrNͮ{LumM9{ul|ߺ4fV<ź&ۃzbPduZjTwPɲ$6liɦڛSG܉yöo)xA?5Na5 u0Plm$?9h +{UP+ӚP+?XRIr|it;,ؾvj^DI1w; 7I;WpQ%ޮ^TcB&5d4<$heilOti6}X(fʁZb|O7裳m&%,$t_&NY.]P$5-:uՆXΏh>- od  DO E'CGG8Lo&q՟4Izf M dUl iJlQ՞bhMRg=ΐ.R yXܪ@#@'M0ȀIٱy0L>C}5"zŖ#s{nBJ.TDƎX$QY$xV䳂GB#@hy!Sc{ Hc!ftjȜaˮ3C2j+*kTvvsq>.^| l J}kR:- Ɖ˅ϚrRNZ0%N߿i~ZF* s4_dV~rC>>Vź2HQF}~n V'fXMc)~%Y *f{gW=羧4Vp]n>13\^$ 7zhw+WEˠeM== \"`ZEйd,gޏl;{@$LI:m1kO^Y꼡`8/u1g5Ө[Qsv}K[?.d;e|\uᒨ$}N?w9S > NE;xdap)%*_YfWym0FaSfbxYoKAЁUXL'X = Ot-3d4)t*M }&-νJ_eZ|]>^=g2=َrwpd!e8 /aE?Aym" YTW'E vLb9mMV,:k%diW#3eer/b¬VB_鼋^>ٺŋ}xiƻ hJz\סVL zJ]x{; iu β}r v/jK3:31FAH\CruVwcVj}ZK}]f0RbA*58B(Lv1wup1%]q2WGEV/{^ bй$ZNít){TUA剀_: q܆m6_$qI"ۂJĐ;v7;MaQСb%D_4596>DSu 0 s'^}&+'j_kɀуDZY_,AO='G#"֟}r#%&~vđ 縒YMcyWo=_Z4èO~_9N\q؃\[;eJSVZ`Yk/S| Practical security for cloud applications with aws sts and IAM permissions – Coolsculpting Dubai

Practical security for cloud applications with aws sts and IAM permissions

Practical security for cloud applications with aws sts and IAM permissions

In the realm of cloud computing, security is paramount. As organizations increasingly migrate their applications and data to platforms like Amazon Web Services (AWS), robust identity and access management (IAM) becomes critical. Central to AWS's security model is the Security Token Service, often referred to as aws sts. This service enables you to request temporary, limited-privilege credentials for AWS resources. Understanding how to leverage AWS STS is fundamental for building secure and scalable cloud applications.

The core principle behind AWS STS is to avoid embedding long-term access keys directly into your applications or distributing them to end-users. Instead, applications can assume roles, granting them temporary credentials with just the necessary permissions to perform specific tasks. This significantly reduces the risk of credential compromise and improves the overall security posture. It’s a key component in enacting the principle of least privilege, limiting access to only what’s required, when it’s required. This method prevents situations where compromised credentials could grant widespread, unauthorized access to sensitive cloud resources.

Understanding STS and its Core Components

AWS Security Token Service acts as a trusted intermediary, allowing entities to request temporary credentials without directly possessing long-term access keys. The key components involved include principals, roles, and policies. Principals define the identity requesting the credentials – this could be an IAM user, another AWS account, or an external identity provider. Roles define the permissions granted to the principal, specifying what actions they are authorized to perform. Policies, written in JSON, define those permissions in detail, dictating precisely which AWS services and resources a principal can access. This layered approach ensures granular control over access to sensitive resources. Effectively, it's a system that decouples the identity of the requestor from the permissions granted, providing a flexible and secure way to manage access.

Utilizing AssumeRole for Temporary Credentials

The AssumeRole operation is the most commonly used action within AWS STS. It allows an entity to assume a role, obtaining temporary credentials associated with that role. This is particularly useful for cross-account access – allowing resources in one AWS account to access resources in another account without sharing long-term access keys. Consider a scenario where an application running in Account A needs to access an S3 bucket in Account B. Instead of providing Account A’s users with access keys for Account B, you can create a role in Account B granting access to the S3 bucket, and then allow Account A to assume that role. This isolates the access, and the credentials are automatically revoked after a set period, minimizing security risks. Configuration involves carefully crafting IAM policies that define the permitted actions and resources.

Operation Description Use Case
AssumeRole Allows an entity to assume a role and obtain temporary credentials. Cross-account access, granting temporary permissions.
GetFederationToken Generates temporary credentials for federated users. Integrating with existing identity providers (e.g., Active Directory).
AssumeRoleWithWebIdentity Allows web applications to obtain temporary credentials based on a web identity provider. Granting access to users authenticated through providers like Google or Facebook.

Choosing the right STS operation is crucial for a secure and functional architecture. Each offers a unique way to manage access to AWS resources, depending on the specific use case and identity source.

Federated Access with AWS STS

Federated access allows users authenticated by an external identity provider (IdP) – such as Active Directory, SAML providers, or OpenID Connect providers – to access AWS resources without needing an AWS IAM user account. AWS STS plays a central role in this process. When a user authenticates with the IdP, the IdP provides a token or assertion. This token is then exchanged for temporary AWS credentials using the GetFederationToken operation. This eliminates the need to create and manage individual IAM users for all external users, simplifying administration and enhancing security. The advantage of federation is that it leverages existing identity infrastructure, reducing the administrative overhead of managing user identities within AWS.

Configuring Trust Relationships for Federation

To enable federation, you need to establish a trust relationship between your AWS account and the identity provider. This is done by defining an IAM role with a trust policy that specifies the allowed IdP. The trust policy outlines which entities are permitted to assume the role. For example, if you're integrating with Active Directory Federation Services (AD FS), the trust policy will specify the AD FS metadata document URL. The policy will also define the attributes that must be present in the SAML assertion to successfully assume the role. Proper configuration of the trust relationship is vital; any misconfiguration can lead to access denial or, worse, unauthorized access to AWS resources. Regularly reviewing and updating the trust relationships is also a best practice.

  • Establish a clear trust relationship based on your IdP.
  • Define appropriate permissions via IAM policies attached to the federated role.
  • Regularly audit trust relationships for security vulnerabilities.
  • Ensure proper attribute mapping between the IdP and AWS roles.

Federated access proves to be particularly powerful in enterprise environments where centralized identity management is already in place. It streamlines user access to AWS resources while maintaining existing security protocols.

Implementing Cross-Account Access Control

Cross-account access is a common requirement in complex cloud environments. For instance, a central security team might manage IAM roles and policies in a dedicated security account, and grant access to resources in other accounts. AWS STS, and specifically the AssumeRole operation, simplifies this process. Instead of sharing long-term access keys across accounts, you can create a role in the target account that grants the necessary permissions. An IAM user or role in the source account then assumes this role, obtaining temporary credentials. This method offers greater security and control. It minimizes the blast radius of potential security breaches and allows for centralized policy management. The ability to revoke access quickly through role modifications further enhances security.

Best Practices for Secure Cross-Account Access

Several best practices should be followed when implementing cross-account access. First, always use the principle of least privilege – grant only the minimum permissions necessary for the task. Second, use descriptive role names that clearly indicate the purpose of the role. Third, regularly review and audit cross-account access configurations to ensure they remain appropriate. Fourth, implement multi-factor authentication (MFA) for users assuming roles, adding an extra layer of security. Fifth, utilize AWS CloudTrail to log all STS operations, providing a detailed audit trail of access events. These practices collectively reduce the risk of unauthorized access and enhance the overall security posture.

  1. Employ the Principle of Least Privilege.
  2. Utilize Descriptive Role Names.
  3. Regularly Review and Audit Configurations.
  4. Implement Multi-Factor Authentication.
  5. Leverage AWS CloudTrail for Auditing.

Secure cross-account access is a cornerstone of robust cloud security, allowing for collaboration and resource sharing while maintaining a strong security posture.

Advanced STS Use Cases and Considerations

Beyond the common scenarios of federation and cross-account access, AWS STS can be leveraged in several more advanced use cases. One example is enabling temporary access for applications that require elevated privileges for specific operations. Instead of running the entire application with root privileges, you can use STS to obtain temporary credentials with the necessary permissions only when needed. Another use case is facilitating secure access for CI/CD pipelines. These pipelines often need to deploy applications and manage infrastructure, and AWS STS can provide a secure way to grant them the required permissions without embedding long-term credentials in the code. Considerations regarding session duration and policy complexity are important when planning these advanced implementations. Appropriately configuring session duration and balancing granularity with manageability within IAM policies are key challenges.

Extending Security with STS and Application Tier Integration

Directly integrating STS principles into application tiers provides a powerful layer of security beyond just resource access. Imagine a microservices architecture where individual services need to communicate with each other. Instead of relying on API keys or shared secrets, each service can assume a role granting it permission to interact with other services. This approach minimizes the risk of lateral movement if one service is compromised. Furthermore, consider integrating STS with serverless functions (AWS Lambda). Functions can assume roles to access databases or other resources, avoiding the need to store credentials within the function code. This reinforces the “ephemeral” nature of serverless computing and improves security. The key is to move credential management as close to the point of use as possible, and STS facilitates that objective.

The ongoing evolution of cloud security demands a continuous assessment of access management practices. Moving forward, expect to see tighter integration between AWS STS and other AWS security services, such as AWS IAM Access Analyzer, which can help identify and remediate overly permissive IAM policies. Proactive monitoring, automated policy enforcement, and a robust understanding of STS capabilities will be critical for organizations looking to build truly secure cloud applications.


Comments

Leave a Reply

Your email address will not be published. Required fields are marked *