sssd-ad-2.5.1-2.el8 >  A `{U]tiߺaήlɦQH4@ 5oGs-4S$[3IJ|0uXSqEXQIs[n0"Œm'\mJ‡N׈R{E_@i\GZG2)S !SֹȌIYLUx}˒JOLxT+fEs2m+2ۓ+ο_D52b{fMߩOq6 A<;پw$XH>*4,Mi'x"CGݻ8UNKʋpA]{2|y@TK`TةF}B7jcA 7DwjE%}jʰ-l%`ߏxum2r D3uK>2-}8X@]RzsSϖK2,12dE-;-LY\ncPOHwuu&bUb|#V+wxRPf4QW)X߯*lCDed}_( lN+$lRfR:V̠mhد*-DWnzUm5aܧsҐ}h%8sa zm>q .J`>pEkx?khd   2 3PV`         o    + b| DD D   ( 8 9$:bGb Hc IcH XcXYcd\c ]c ^dU be<dfhefmffplfrtf uf vfwiH xit yiNjjjjjk kkk"kdCsssd-ad2.5.12.el8The AD back end of the SSSDProvides the Active Directory back end that the SSSD can utilize to fetch identity data from and authenticate against an Active Directory server.` paarch64-02.mbox.centos.orgApplications/Systemhttps://github.com/SSSD/sssdlinuxaarch64'&DK8=OYAAA큤` [` [` [` [` 2` 2` [`@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) svuk2.5.1-2.el82.5.1-2.el8 .build-id9317c3c8b077aa3a338c7b14a2a5213b92b02cfa51d1bcf6240c9f1d76a25d537d652fa281f5b7libsss_ad.sogpo_childsssd-adCOPYINGsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gz/usr/lib//usr/lib/.build-id//usr/lib/.build-id/93//usr/lib/.build-id/c7//usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ad//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnudirectoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=9317c3c8b077aa3a338c7b14a2a5213b92b02cfa, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=c751d1bcf6240c9f1d76a25d537d652fa281f5b7, strippedASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)77PRRR:RRRRRRR RR7R1R%RRRRR$R3RRR+R2RRRRR4R#R RR R&R8R RR RR"RR)R-RR,R9R6R R.R5R0RRR>RRR RRR(R7R!R.R5R R R RR"RR'R$R9R6RRR>adclibind-utilssssd-winbind-idmap2.5.1-2.el8utf-8fdf605b709a742e8fda25631665fc2fc79da773d4b591e6213ff1b8146ab8301?7zXZ !#,f] b2u jӫ`(y,yϑWny>KZLd' XM/]0 7 ^xٽͩy4ѫPD%ߔϘ8?#α)do>/k8` W:ƙ fnd_׻ea_1Za}84UZ'&Y38Gȼn.DKqc4+s UyqI ;Zvl4EGk(^ԼYspMIsvSy흔X /UG[ NO.B;h.afߧ>8ΪdêG ֫+mc7$[gId3y (LO1!j[zkSci]n+qQ։fdB`6/iN)O9Bnk@6OV6 )'Ya= O*}Wh)rɝ Ns)?q#`,Tģ\Iq~tbмECƤ(Ϛy m;z"X܎)CGbB샰PsŠJrqX"Uhӏ֊,ucU |]/F2PĮdy]7[S}'.[JQ9 ?u,D|Ѭ悖`ͷKUfT'3a`7{hRhMT}Ͱ SN?~ە?dq}G|{D8 ιḢVͲ %Ub&`˔1I $i| fV(m=?Z.7u04Rl+]V3dGY]q[5(vmT@: ;H6%4u< !yQQʡBP׾&:XZ| EWk$/PKؓy],Ɇf#i/)Fc\`>4Ľ)"7`2PCSQs  xʞCEOMnxSNM;bY6n(1@.,It+3ݰEqlS{8JdjERvXLRAv'8Hj"Uq+]ܧ -?'~ Qށr[\ cqC/3 |x=Hy}J:K+FF 5\PfѳKa\p3,Rs) f@ڣRBL@WSqP^gZ^vM9Ł($=V5E@|߱ BYOݲMrF iL*Sw )*ݸӚO9 &˷\ry Ǩ`D׾p~P&Fb`ihѣ-AX['4)uAȞt$ټ<0:7 1ױN-;LDVpJ2${*EE WG'l{&TYRPAg' DzQHyG7{ ܘd`{iQ WeepN05' 4V>ٙli%$K"-*@5qV!naU8h&]i0 +}9gBA{~UE-j*N+8DN1Gdffp5)z ^U 1bj68emj7$ʘMa,b |͹TA/כ./~`fdoZ<;|7=VP|1R+1j0Rډ: aCKK>`3#ADisA] =\&lZcrt*vc 9\C&0 6,aUQשJ Z>76 H7bd mmcx nT,x Nl,뼩NsGˢpFh[>@6ϣV26u28X=6II8ޔ`ZcRP^#@+iCy&'2cJUk*A }DȺ3l;}1K9R&em##,k[E_|DO0Pz۱Ʌ[c-îUa&|h涇]Z_s,JecrATtYMk?"i~wr?|&9C>0XƗhà+}6eeDga;M޳K*w7yJD`8 C:fpCA c#]Q!)":.75Cp)giV/%T]ʨI>||Yn'xXqppfZ_kV^WۀUZ,i4Jͭd1pSZ=8í^8^踂Vڱ#HACVbmL"(ƯKdNգI&mɕPp z~6>K2|E'xFa<݈rsIз j}3nClD"K\QJb~1MҢ0[LGYU]+KO bj呩MFf?ZOwKƗh:e,\,D_d Cx+Bw<+yz?= nK?g)2Nx~+;JZ)ֲ٥f 9|և˶8;8Ev2ua!ڌ_HMbb`^Èq\B=1J2V k"8TK2A}lcK~/[Q}ү#&ȑFӉ+{w@>Y:5Ьjtס,zpܦjo!^-m>YypHv?㗐^iM.ihd6F;w} dO[242^eQN :YLpH-VR%.Ƴi QL%KCJQv&č랾]3Rv1^+'@Jͣݾ^ 4+3XZIx4RLnaa};]pwyCF{)u((V idSc [.a=y\ 8Һ:`aі`ӓŶ"tz YL dƑ.6fJ'sƄwNtG  u 9"slp=`rL 4bV3tv4|'Y:7êv]9akkҥr3?]P}>LA-Vd),&-#mDs~c1cG^upFؕ[(<\Njh ܪhvdF)v"<]8y,=@`x בW)!Ҋ]%ntNZ=4TeDreQ LM`FӀhkpαN(-s]0R9LZΖ8e3 ]w(%8b@E9(Y {>_;W/.T][*R#bO&Ĭv4R҃cq^nr ^^;P= h`)A{KrRv52q)UaT"-kQ99q0VVLu&A ZacN2HEPĭU},jd3/7pt—u ">,2jY%b&h30>Sx4 /x [igEVĿ.;x5$dd\,$(x ߲ &,7-ZEa$R':l?:X8 P Sޏq/lyjr5ZRj8 ^ W@괲U)6̔YK~Vo еzGfxyq0NÆ0yYa&Ê_)/sOœ0uV_M'ⴚv'ЯFu31>ր/{Q@Md-Le[e-o:lՒw4͕E3YP9bL;c};`dz)u=Jj t:.6ŤbP`dnNL" (%Sv_n`Be9{-2p-y3^nF1 !ΖϘ^$fkD6<sa4DP2$v|i}n1ĺ.4&t)Æ_JXXhq/&y/Wx@MZ`]ޤM*M(֠YvCRectp [DEԨvUЙ23R&`qҀ@ `YLMhSԒt-Gr'aYI8F!:^nBa\Klo5$,t|OfgsK `hxF*dֶ3G̴LQXߌ%a+#<[<`/;(y xV8rg:^; ~TDXd/-UՂr,@zYwI~(i!}tJuwFru,Lg:>~h8[%WWGWvPnW-[73j Sp:Tb8Xb~C&D2+e6uXy~޹cӌl4I~I| Pq-:h[IQ浬wO. ~z"D?.65ց9{( nOyxl4+Oki`{¿oFgu;q%F+NKKٍPnkФ6xH0Cyó`>",'/qa >>B.,nxUsAFSuv8YV@tP b~*96Gp>`{X78.7ʼ۠YJ0qWZ~(˙[;.LSg;>}%`QA:iOH1Ϩ| rž!g8,\UnFCL90@yG!gNΖ^ķiED !7^0o~b8EhoUdkt阮\Cx& `dm:?uDlge`,oЫ# ΀i"jѰ_C .JqGX|(bE9K3ͱĮ!v..M$+2w*r Br|,?edϙfܸژxL%{gur߳&Y2rc҉`i._E;oE˸ut?.nZqQ"?7#%@PmrRCzN9s ^ N?$vg]|ML讟5_BѥIEa`˾rf~u W)5P@a ;Y܂z@˞^[V+-8cu?(}8SFp fJ|m+i#:ޔ8whs^-v$IE"f5@[Pabo9<0q2uzx#ŝ9#E" WCA 8F#њu&Tv2õNvN+ F,쒘lKwiV57^G${Uh1j2le(- Rp6h_zI6\^lHJ9 6Ruz\2ԴЬc2DطEXx=ObJN[)_bb/2aUs{FOqQI>[˻c |RN&;]o)!$}1v7@OFbJ+!I9t s7躲h)l*^˒X$t#:Wgس*|h4S=XkU8i.f?~RJi+i4 ggU=牬.-h$k@ZM!+|0[3G'ޒz[DOz[ <))H4H#MA>M;*3)XÐS\{|V>n3}\cе(9Bo`'1Q#ݜ/aWqLySu6N% !wv}KoNsp$bOWܞO3K{r"mhͪd>>KV;Qj6koUbIjƠt}b2r߾uRDi<~l2G[ 'JQZ3d٭*U5_40RK(,?'<0ۻ~-y6 +f&j}O=sA\54TD v$,x,_CXDG0˲g1JizXXz,'v M&$l"ǒY y^|A=g.?cDT}VI}Lׅ@eBUOxhx.UguBbޥ*dݕ,$C2kl}(B1t.B6F) ƃ07èHuY> cӻW,i n*@e[PMҮ?rX+tכ6 )#k1ӛ^)mœcZG?)"ӕ^ TV;Qy%4+O!8D U i2-LmНdÔkݘ@~˃t)ͨbm¼`0~& w $_!*cы}$3' #z8\a_ߑbT]h&aOaי&{߀G:CHG=tH!L%v%I.<-Uۖ_{Z33& Ig$#VlUSc(Z}Z!d@rkX` aҨ;x/hW{n^`e=,;7,-@_)3HӉ.a:$V>{Jv»!o$,cnFD1./]H1'J$_ڏzH=Ι+WjV̺rA=U[6>M=N[#f[~A (M0ZDQfv5 @\ekDzQ|-m?O7As'9NS Oc)jR}(cSᶲӯv僎dUt3ˏȱg`Z!7^){v^!&ekPNi ,q=,Ug01s1תO؈iJ5^ɱу5"Iɀ l >5GΠ]d*TyZF[ w6uN4KԊQ`?epX]4C3g Uq|- Fh9ޭ(t|;.uO5'_}5lGc?16%Jٺl} t,^]7V\`P2x(547=j֒ 2e6%ע}=)$68ݎ82A@,S qEWSLs>†3@VN͇s@ WVy,GU@{UIw#uڦeymM^xl-e0ԎkJgI@$gM X]}>8N||jTTh{+WrVos?9ڭ5^|\d|f#zP+}\tas^ {Btnh UlF9e.ĮmA, ءNZ HұnƩ[K*-v0 ?vp y sl^S8GbbUxZ-Odz{bVLܯmgghrcgI Gi . Hle?UdtE|cEZnڵ" G(ٸgLlx֤lW#\}c7%!^@S~U5Q-+a< "@S>*u_>h$V?; az ӄNnq 3fpzcIMRsƃb8taZsev_k1vJՇK3*Gh477`}7leyOZ9떑3{7&@חo>fɏ+U/#x]|O$=3I'vLSbW%o2 Y@wAXi}]{AgɋXT-mFؒHQNwgv^( mP ?`oy5CVnQ 6V)ӡR# D2&8dO{yBý)[GB*.p.? W)9E% Y7.I{v#X P,1?tkʐ1r9 jPʝ/3G`it.G4@mY̓XuP/ aw@yW5݂a@N$K$lR5 ]sz}n{֮'d:u@MrF2ӱa5|jOAiAN/" 蚜@O޸ԅ%(!.o WZp]1Ç?o_ !{ ؒ^tA%&b [Y405!(i+b-zm~A?-Gl-g;!F!FDHpLtYT7 a"2b=8(@LlE ,;%()S?N/o3~ȫ?=pCԱ`h6mFe%`'Qz^7]XdνXBuu*$qꧮw;\Ys'$ 0^x>v[asW_CUڇFS<GXqfB<";}JR -Q ^r$:Tݛ^MiZ=ksߒb7G| $K 4wPQ7]{ IT+Ѳ>7 *`ޗځ6>-C2d`<ÀdVq % rg+WkT2l+aX>y SN,x*;"ؔͥBIv,CO㘖VTkZX<@l'[j+˕d_B1S4yl#PqN]bqܺ/ӸkwG4" YFgCCXT#JӼ<ЧZoC'z8}3_ K^h+ >j+(L$ghWp :z PLoPMR><#O ޳7;_8x*nucǔj}`R$9ҜCJ0=("&1K1q(B_ZD!p)\04j}jҋ'JdPb֗YgC+{||K5x7GWN6̆mI&Wj'r gв2)pfZ({ Ofm6.7_b3Qߪ'R@AD& ҕ0V0EوTA_l7:'wb{q$\Ugp_læ˲nI6_}_+!b:,gd}sR*'<!|W~Gq,EyTwD4 bur!/R"9GPr6쵦9 Vd*q)6[sJhi xv7okћGwqSNiǼԭSQr9杸& U(3&*ME~p|eOnݕRy Jar>rR{tR J(ͱ @=o vp2}駛H/Y4]|5?V6X RLCK*[k?@t|n*o7yL_f)q|@wdٞs]̻ͯz^.תy}KT:T׫vpß*fQhs!9&įd"2[:kWuʦۥ?8Y]m;uqYiŷ?&쭄n#A=uɹfkIR~׊NHؐAUhѠ2ޞlu"Rn5F f"uEh" |/|٦m,R*i߮yLvHVZ{|'J(aIJlI)XԌ=%:$sIZRf~L)rh%o&"V[^O[e`ߖʧ+N'J|bfP.b،'qp'D.dNQpEubq+`5#ɷ6@TٚD0ITQ[4_TWmo-M]6@A9fލ\_U6B $EBitCi8;m^IVca v L3u&x8緋`8hkp$ܐmQ9ږa,-]V.KvWxcNPVvXmEaNX 7 OOQZ3.Qݣ6%ud./Ilb3Rb "hϺs}a/sEV",Bu?1B k jjC?PAH.+bY{.KfP .'ہV:o_ WMO WI" z%h#f9}xp .&a 0eA<"y*0$WhG)踒0j}w/aIkt-&6dRʺ$тA wes&}:S|pca`XUTiF d Ҫ.i QFԁ]>Ʊ33smqj@_Hems,_Me68,Mc{o^1~k$+%E}'|m(s4(z͵(6' x0@\Ш+`&,aTXLa\˗kYoFLasOs۱&~*HQהc8x 6M䯦(1z00o* Rcehay"N KHxLL a hv?Xb yg9U@(lO^-CJj)zM=͌sx5{͎N] E˯ˠoy%t"P$O&`D~AVB~[UKު/NEUD7*\^W0R [p5΅NV.\{`ho/gΚ237vW_w"CF^lB-mHZ;k5bMs?x]cߺ…ķ3UpvO ֒Vhĝ.~.]ɒ AMU=5 "MV,ĸ\g^dig[> Ԙ/~H#G:Jg脙hG% :]L'#YpCB}G~旉zO,#iמeH~^)xQ>YSJM`eΗӷ,Ek۪"Uū*k )!Z9jW_|PrH^~MVK^CGݓ/o Ng?z#a ;"!a*rybKjBUc%eB,\[cAuJ( pؗ r(Ծ'Yk(H]ǃf&tJ=P.u4'ONŧ*9tM|ZJ [VփϏc{[mza4z4kN}(cT\((Ӫm3GKx(P,):!I#Ԫ?ӢnM"~– (yI|eZqWS)r87[~h5RŭJ1@X@ 4\xWF@՝Ê^]od CWb@TL=Б@rWtk!/zTOsVd?s6* qdT+;& ɗM4Fۇ!?WX)*|S' yg,ZWц ~3lf^D[~o7>+=0G[@[EOc.V)$CIBHb2gGXh)M8<[x8[ DIL c>0f F ˟q\? ;/ث},b*l@ZLѓb4cKs"|0CIliE)Aݮ>*3qQ7^?kX'|оJn Gyu EyGn^ ;] ޸4I|Q$eiǛeZ:즐Yn(7-3"O@zxi*^'.9 7R0`+/ Y,z_C$@=WRmP-\ML${o"é!<6=dKUN~%{b&1'P{WaQyhE^O QєkO֒I ԏF[Zx>ccxm)7_Ƿ h"!DgS!'v5NL .)H x9h92Gv;R@./#U@r yVOhuFatuvH8m챓F-3f[+փƯn rltO ߉Wz|`LL?C0x)"Ptڄj=jh9-ytU/I&?pҁzS"@Z;qߒʚR1٫q0PBc$s}Obc\dؘ$C# H'\K qowFh)ݕv ô"s S*?]P!Ru$`D"%߈44ڗ(١BuwkxPF<:-N+y `tP9]Oh~=N{|1[{j#~qNӪۨOKZuPzyjnĶ83pɄux( Zba'{؄BN ɛnyl7*|<+"Iyh@(bN'F-[eࡆbj֪ CE @N _<`.Cґ6uej<}X#qOÂ#>abЮ)H9bzw:I  #ItHAIdq׼CV I7gjcs ) ͗A FE-O3##3 Pt霽'*-c@U@9$< . И7X-7Kj*,XѤ̲ A=ǧ{R̯eW`)vN*;JK |砃A1EZM,`LV!ߐf70i ?dZqB%{Y'zA> 0/VZ3{JGJo#S d;k:"=;}ޛ?Mx[rgdRB$H1YU Qv)8ܲlzyk$5MY^5y0+Ni N>kduȆA6TJ&EhO)G89lH,ظW!}i "l@ݼh$>MRpz/R߾3 Å?:w޿LZA_Rc)7+ÒՂGR8JR`i&:.bFIc?.rb~v?I=/y2`kj ܂y(PNbro߈xIp"D,-ވR`oyArSTҭ^+Xƚ:4` `x xVhn{`7UA)Ϛ.j5~ s#N)zLE"D}aN C.~)PMPMO#S-^HmƗh / Kkd3gN{%EW'O'_ҹM@(l#-~yoPJzc*Ӓ)ݢq3d4 ,I0mr r ^ycp'/8r'p)09T!ts"+_/a(Oɋb>M/+eZC[.b?A0DZ54Zj5=!cT6[983rF j2H.sfm弖y409biʻGtd=6ipJRQ810["cgė\hlbus=D]hVnu){ ݪxfp)jrMY*_C{si[UvU\;15b3q~/$?,I4z`$G#LHhc\*= l1InwoRZ)|sVDgw|(A la5BAm>G*vM_$AA9I|qz B' fbNur?ҟת߯#RY[E| mjXl8U:XfsDn]oٶ>FlXyLMiqCS/V%хGg}HTPx2֠dkZb|ƮIB62,R=͘'Led(vEN[U0MDsZ җշHo/ d^YRڊDdYɽNށ4~&svEYhS M Q; HQ|UH fZwF} *YcF£z 7}fٶ,1hU1*|i՜DZI̚L*&wPPi}+ 3]B{kP )J3̊#藏s أ^ĽG`KDa Q"eWj((_N"k˜kDscQ h]!ZӦbUWDaUJKc)!{AˎжyY``1UW~Qk ieΧW LUuDyOҵ%iQ$,)ⵑ-`K*'lT[DÙ1m$qL~ ;$eNj>tJ>_c|LW\URnk[& "{G?s({,ymH4"+$a"n$Z*Rn@祒%2xM] W<?0ց ^oڢ[\tI.$ߣZZ4ꡋ~;rp}QdoTq]d'9@'C#UyxA^>;*NX-9S|zTSS^hw}9Qou0d)Ȝ4?5O*uԭ>i@TrZ.겭7;]9z"fS-!e_q8[qFdT`ldPd^>?MwUY OnYxT mS(Zdkw"k *jKŁhÈ/1ڝNWD; LsohzTZH ;i{HXA"f)A\Hr/}B#ixSe_Z=DW'$=iHp/ P>1IV5+;~眥xycF'W sc-$) ?o>mU[p4_ 0dFmmP:`ՔeI"KoZ5/ؚ"7&&AG캭;3{ozF+z !)"-sOєk%,8~l2Z":%hn;6, 3G~XpfhP*DL(hH6BA ~LZ%efрtF"%,iW~tE`T@e09^=k6oPY(+sN&R=(E%wf, 6ZO{(.iO_-o%-wmR oD#T+]O~xgEsyXרm`ck}g%\]\Uޣ5~?DmkXۏpI$Y3ze3CؾCzeKG˞$>)AX噲ȯO`%c$RUAޝ9d- b5eb2OkWSl kXlCRfy'X82v71]D@s|_\ܩZXU׿J;U{^4n!M|I?g"!x1t+i"5KU=_ŅLlQҔn3fg,~5! A_iB"_ 5=.N6A*M(`L*|{ <aU} 8  wPo*֧ܱ1Ab-Q76-Œ#Ɵ"ÊbY.Px9c%ʫۺX7m7JCV+=[U5L\:4 }Ϯ w͡-=GDci`ܹX&{=~ .ֶxL9/K5ZOO)tujdu.C$W#^52P EޕϦ_Vw@2JzQ_7u>yiLn柋sɔ֞}BywٴA d&%,ZKuGt=woи)XM\Y φYŽ*ѣ|# NNٷqU eyfFrbH*[`oU0p _ትЍ5.RuGTm?NAǻ[$k:}"Ȅ"x]?'(d;!c Cz ^1&HJZ[(>K'/UXO E<fu$߀*[܄izeqi%^xY1.(ǬXPKa6u&,&NQPf8, DD';Wyzxs<}kk2}ed{$7^C'U4ct}V'Yw?z(ywX\7bt:7ӋW[QZ`8V* `Dzw΢qQ?(ʱkl}z,0-S+ܹ|quJ Yc5 UX{nvI邦fYl97벳`ɧtcI?ڏ(|Cee^giadZ}Mx՜ZF ~65J*huٍ6H&:7,myEn)C{.pL(0BM{#Y9'SjHFkQ߯($ {u.5ͅ>Ay,a] =@̻Xгܑr0O,P xpgMQD>UR9䃊,iniɯqJ%% `l@#HTٹM4颣RE*vC7 'RշC+\,A^y5ߊ,jŢ:+Anɔwm'UD]Ut#9'5&Ap8i%?[p_V'0 LD{b9֚RNSIY.- utpL9X0 mozob &IjْRـt0γ]ҨAZc@pJ3;D) }(<[E NQ:Yx]Qon1sba_'?mJ ֯Q41n[Eip=_DEw68iSxtQXޅq>a͈Ud[oT[fAT"y2=Gi/wueׇZLjR͎ gtv;`A뛱e(nژDywl8</)wd(e9Dj^ ߲0UlLB^J"@kN/5=6|e28!O g?Zm k :e7`4SgzmP, %4)'#ӹNv`j}K@Opv-'m  8 H@ )z|8A”v EٓM j3咤(KJa:h %Д(o}OaE" 6(( O .U+n/O}eyWҰxyh0L)%jYMN#(x ĵcϻLS[nGFl8;h= 1%]ؒ~41lMhF="sf2^dŁ`j{pݨB6hn{l%-%QZ}e5Uca>?mGśp8n<O f{(CqgzSAKW@؅k}΃e2}Cj(kdwzi0`FܟLEכmi^o#wӕ>"W쬖+hVr,-ؒj؞\tmTpɋ6yg14Lsjx Ffy#uɺKG#9ỳ V+ kM@)VaNGlV% _ _=A~A?7B _=6dKbCәnff=mɁo[ueIVvZMk?Xi֪"u3O Qm[RD"ti{p9\",sO۾Zxu=G.gfrdo$c+호5P9/ I T` 3/x9QsJ J7I1JJȵbJXN_Ve: nPMvl8P$` f> ܟ3NC}($zCh0/{f/j OZ4nJa 2H!;vxۤ2HBoFuq=3ۘ8PT" tۧ{w#8)G--5*csrgLL3N'w&\Ti1wYT:Tvvsid`鸔TUYX~c"+frUcp 骾XZ],n -%4 ã$`r!D*-z1TC *n`̻dRQ>g,.a;kV+n. b ](\mb[Nk%WH.O\hh,RυHlCu:V<kO02ĿAE@uܘ^w.Jp6=|hEYF `oc `>`e_T- Uf:&i4HVĥ` }"߇C1Z}z5sn?okZn~䊹|xLM{ q.mZh L^bLl Mަf~Z*JێWf'KsC;Q:岓 ң;ֽRh| [A<~qyUȵ8,Yy `۩P[en5:; /LA*z: |rP8 -=/zJ_9J1C1khϗ>-@Vxp}~\dsbwO0V&8馨)aA,mj[٫(;-gCE`qr=z38jk #ul,g(:URs'0i' s8s (Kؒ;(XJ-5e{-Q3RW@bώ}v_OtSKȤhPvmDm$R?[g^if5O:+GǬ->3IR ;k0dVUl^9^! I ǔVR"9Vqo}'3xGaflzr"lgA5Sums[D-ZES:bfK}o֛}Nڀΰ|)w9y[Nм#s29dq%h7ܜ4s,l 3iVYq9DQ] .& a`RȮkh$J`m3"d\qm<@9 ~ MA)yGEd|=iA3SjH"zLͰ վ! &$7' ̿V֑~QD{`iKE{w{](ЯK!IM(h,8׮vfn+.&NآdR5y ũ 'Լ2ew&V=eq7TW_,obEp1Ҵyz8{N|l5(,~]^̯ @n3#yrˠ/-%D"u|y@ҭ2!E-z"F#vNlf$xo 2[8Y!B)9T/%y W48}_ksIh0 RS*u<2<;-Y$`{nQ]Q8 }߬S"vFQ]]y@{Yx{L㯼kf\0a(3aOZWy U?5r}qqτ] q||Y0ä?ANLG7+5VVvݸKՔ 5oi8AΖ;n gDR`tYդWu7\OJ` çxXugӥR'ecSB_6:wb1҉eaWR ك r]([ZR,jZjv(1`=Qђ޸Hizv~߈; @DnM`nhE8m'7pDݒPZ0hShՊNҁ[fCS-9iir> W~T4adrZdRܒMwP@ZI:g׺'.mCwA E1C7YSu7Ś_R5>jj9E_kg]ݱ޽c|(_(0|V~ʬVY7wKJQ $f릓zmW3Kk<?i ީ7IjGC7XJց0|"tTcoF !h+ύ7 64ui-签z NJ/Go-"Hu Jvܚvw/ {,9{ix%˭ѹlem(հaWr+%y*Fc0 Ębdxߟ^6J.gl5vs>SffMMC 7/9 'nq_Ὺ C5ԒyߤS)tp\P㡕6ӜTIXd!41 [I%c+*KgY Z]i8x40FHzo96 Pc 䖽%'ӀH ͏ xD0qw0:xcbQVYֳ8Khz;6WTaةy΄̵‚`c5~Px`[ j0+:~04q?T \]l{asc/|L8u&S-PrZۜΣx]XDžWn\aچ]SSd%$4D!yk&^VlFz%bWOJòc)TCJ秷'^k*e">T"=vEFDiWnٍK•pX .SMo#ɮrW2ڝSBA2?[BC]?зOfuZ{z:Z EG5Y/YP<-5tj=ۢcUq˫7UgW4Or4|Z?|J`r$@%,~ ᎄpn05*KA*u, )૑3_+x1O^A CGś6tE(Ђ g 6dt4̿|/Q)0TUj;DEcKoz£jþC^%!<055j6\mfIgBU@UҳSvE"`?f-? V.Vn#["l,c lSUb 9WO>Cd-~B9OTŮ'֣F$VfԷUmZu[#'NF iuRת:ؿ,p֕bg>z3+-Y%*tӮɿV>b3<| l.eL9 )+~Uc2YsNraH X=F ǷEYkɂAMoS9gs"bZ;ODٙ`yԭq՜/˯QwЃQ8pApxxa.3jJ'uyF5S}T. CXAT>>kM\$跲6.X( nS ogEfTؐ0 YcT`nDkT~ltj?s\s-hj3O'R!CgqeK5I1|)<ΑLCAn=UP׫vm>\dWgyY|jqQQz({}9N ۔D!:^x(^7V=W${(f._X$ ;m`#1i$an-5 p1=TM*!=C+_2@QInV EH;zj$̔n?Vg(g[WбV}N6icOmhwR:(Ñ0;`כ6@}v=jep+\ S[Gu¶F\>i<7֛Y1;`)JH,WzlL/G{+*qgރ2:wU@~kV\/&I3RMe0>݉kvR47* .q7K3"z#rC+#zxG 1jC|YIK֢bڷ\oT38QުzT11ۻh)pgH.Sɇ/-nchZ:i_x IȦhOx_x]ub{pAH@k1E-P*v9 H'_z68ʌ}eטv*seMjtl9f;=~`<~v|3<~]8FC{.@e I*;04.&'x;g^8gb1S miN@CK0wpSPT_UkH\0^PN{*S:*vUVlSM'Cq)wiN&r74-Q UDZXUK\Nc%# uzo}w0s'vm;-|Q,.H -aԟ%X͛uۓGGkqSDͿ.> RE[>%'BX)m0dKu@o;̭XL\p][ n]=ǃ#چ?G[5y_-u cM<8 ,s5J=NoN2'} C/SWUȶtYs*x3V%sW4ћN4cURNv{T|vϮlj#MNs!]H/$G,2Ȭ76L.b ķ+xopmkvF#N/rAtIɒJ*Bj]joW8 WX{y_ȥj^м*{LSw3/ӀDU ˳T(RIܾD. MsGRpe) Eʲ΃!O9~!!߽r%L^R? 8X}52M:ѱ{j?\kMD+z-F7*UijVg\3OfC7%Y6j'*c ^ᠣXu 伓I~ZL]()_U^7saegDZI:$蟯~`CxZ_en^gijЧnp6, qܡf(| 5iFj-_j93+ UnfWx"]_0Z}h$FD `S:eJA}rL] a) %7Ay*l;nG} wQmeězbެ';))z>bб&^ W Fڌ<q6/=͢۹.m},l\KKD80M*cy'ڴ K23a+*Ha\+R]8_?Zt{!}5Tw,7";)7lՌ](g+ e÷cmI- x}6u[DIEO)7잙+7" PsGklP%ff8Ȭ Nk0%Ml s 2J,Z!0  ]qΈ@,eRߕ0 "!]mXoS:6YLڥe~bfT-jr!j|aHUi$oWBh3~֜~B4x~$FVΚȱڽ9Vҕ䀆 ʂ|FZvUKBDmFBUBDb^3[]l8z0wnuy4n{6&*- oȂ`KΔG_O Yhpa$S#4YP(GyI z+@ ׅӰ8E F'LW /IՂ-[g?Ykr.eƎ:NoSLcð0t /GHzC*,t;,V2`,I׬$lЂ:2KmnW9i,$-)5> FeIS+  zdbrlDgdI&E0yu}B8>|CMa0bFiiCP o]knZ} *(VU]Woi0W,6[)LjewPzH WXe` /W<&B8~*] 8Tq&S{0߸Sr=[ \aO}́O uzj QCL%8Zs0!B7LJ;R"6G WD!ρLB⤲,ذ0뚣ofgZK.רe vk*_eB7.gjZ.4GbNnxuy7ù&|+dXiɁ]<ѭl qKWq?m8S9!v bֈɓ 8u_Y r,`=T˞f+ yH"&/ bIkAu(v}PÆJ,S#E>1&|-/ }!tvSin?8I"Ӵ{ ٞ_}`KgD˽1Pd,aٿ pi&{1PR:Ne6oޝAYOBa ECEs$~@ͳ쵍0se_$\ğ##Tm&.ſoI!nL!ps Dlr<*/&"ԙkbxSs;WPY\ 9xw~$;) __ x ܤPXК*~`Jw[xq+lTf͑N,ST'"ks@palf=,{a -:#|n!hE*\i+GbrS,{-\Q(? a6թTXv 쁆(ktMb?\h=!H35Zpl!|66Тᐽ;M8\[cт ~s/XPԮb8 }7t0s#Uc_ >"Q5'" ٽm'YxVP)璬C]rAXN' Vk~+f!#͏犙_~I?eR4 *m[J.{tཤ: hCQ]U:O5Fg%4U6OY#rl({()g&߲-~aZC ꇥShzF^ܾ885CЬ3A9`@!\PvfCVt<8oRȃA^&RcaXcS3.{IC'ky\ۀ愣2D$KCsj/?;jm>F0ܳu#$h~k=`H&/Fjdgˆ8{LM4ц>f1:/LQ'Tx)n:H8Fo+/G-Q(ʹQ9 >蛔5'm4c}qAxzM:f@,} o%;9$ (_ mR4yDRIhU̾䡟@%jt\H~)b9pYZB<腃T 0aϹjŲ=( yέaN[+lbfϫ ᚇyw2 H S'~_v$08i-PBm~jԾt/9A$x"+WL%Aô9tcK 8HI7kV URJ_6>R>XX^y{˖EYB 5srdA6"-gʈ~|O?t2Ֆ,7Oo9uسu RCY}GMHԌ#:>l4 qQ_~L垃ߌw&B4*lwb $%C|+ׂ6ȕWd?귆B|!%nZ9l"$UGzX˄bGgRP@ڽhQJ _y U Gd]TŢQȐĜgcemo,TԠS7e+xzٖ9Qy~@R,s%R5Qỉ< KJ7÷MғANizha餝88tet( q{;Eu0Ӻx Ee*kT)$ֵ,*,;&"LBg|*e`$3x(0&&xI2@rL %)`@g5()` )Z@&9PGo* xSǸ5>V@J+96Ê~|SMS-<>`fo "J38 ` ڀz'ٞ; J0d\s5g$+EM:Az)ܑI@Q@SR_w$sTD){*9ʷ>{ BT1%nQ"Bhs.v :@ZdҘ TQL Bv9nP7E-Rգ)v4XܬM3hxfKx0.–\/2K\X p!M n*ovd|s\g꼕;fncڄf!_B귭\h@@Ś!-G^o.Ʊ4vT¡u*fރO(3"mPAl&z<~t]W~3yKD R(N/uݒ[񦫣QHl\m1mkm+JXc}s=jM >0"p^r/+,cTᕴ\}v((~RX sCNev9 1 R! 1mz^Ƅn) C;x V bo,N? .&$BWakgzȾ5e*ґ1P{΁`Ƶ0*ڍ*\J,{B6q0L7|DZ>\DoռZ ,äyiAGOGmFR?lKh_?d i`R-85`PXJ:AA] ztX˂o؋f= %DLW(MD/Q?TZ5- ¥ȒI#(ŒCod;eS&-67JT8x@NWO3@Ln>o% sE.Rrf 3fr9Eq̅Gx^`)bHv'Ȑvƻcocu߻; x qxհa >%4[gfH/?B\繕y %yD<9p84lF *_ǽF82}˟\ߍgs"|yqu=q`?6d) ~mAk+z|FƱҰuI]qq P$?U J VOb|-ҽ{_ V"a JxLմEcw7>qF$?/#U/0 B|.){-i6C}6+PdA8rKr mC41I$WS϶n Mhf^1}^,N4~X9M%:3A:41)pוy8F< M%:u`Ji̡UK /o"0g(vij "~#1 Gé},U'DtzHemKʾѾ`).s&!Xʚ$Ȭ HRiXʇPP+ ɧt(4X|*1ǛF̐{ 낭JW ΃X/b>;"m-ZV)2 [( !46^v0{ e7:i#5ln&BUACR/#wă¶&v‚Vd”A+̋UY &>t$fX_fɥFe.º7> 9v\^|rQi02S[:9S2?xs/vQs=+sWRic7=՘Y`v++͢zA-Ɓ7!\!qoD܄lp>pT>%F2C"ܠcZΪRDp1ݕW A4{k]dt^mrg+ [gkiWwxTc ?AM7$+gd}[-!MkD]j )V]ǻ19m<pHT͉zh6n Nr e3C6R WDN(+W'}Y avQeP}u4l/z [9KXwӋ{ݸٰ_4ᇲQBIRɉȖL:MD(f3ߚ`i\h~bUUwhYdlFjȤTj9wOβQ݃3tlsqg~gv|vȠ^4* ;jvvsjOx%Ơh ']a#L~"gs3M?q>k_ǙZod3kaH(Z [ iZh cRj%*_^C) MhmR> "4s+?3J]O}^E jBcdyoP=myt 93F gg$e fݰzUYUa}=H(_WU:ˁ85zEǍ>kqfCGqk*=mO4S|POh6w~>3(eiÛlM8ꗾ{ 5q+Zβ/*1şz=(3ijQvv fJN-5{hT¦oyq$<^:s2Dfts}~mɼdR ?)y>| s.`I7t$ * l#y!:;U9ĨO溟_|b@GM$婺D%wg 'c7 mqلDY=TOQ6n!G6/N֌?;5~Y #[Z 3&ϓLSd7jfa/lSW!@ v#VxoP!ÁOqɫUI ?kgJ aBiSD(1텤pDi}kJ9%YAVwjxF"k_` c?s1:!ܙ(YJ.>*d`BT]ITV􍚺~XW@ƏAqi)H>{n e=035fU5hyj~V[׹m&M%GK bA2 D'؍‘hm?Xg*IGpKkS`q_وuAF#ub\QFeuh \  ,h|Tz^Dh[8'i\G5HX-6ϕ{\XQ6280)\^YƩyx-ҟLB|lo38>7ȀIGݽsaSR*,Z/ %m(eL*az cQ@_F0 3jV_ϋ VUA> wʖ`6bpebVSѯ17fafv\C+klSMKW'SAkڂ =vM/_w[Fb1u =$P=cs(Wq8B"֪ezH&\)_uttgr:#gN)7,:n&w(ŦD@#B΅(zAJu!= M/H_/x;?t}AdG&[peA'35;^tQUqu-h4iM1g:-1uDisɫ%|!bv= ?,y&8YGǃۈ_>Fw=tϗD|̇@lC|( /VtT:vsWAa{䲄--uLP[t%EhA@||ZG Rn XOu)Io`ߙU iS cMЃQ ՘z'pqG8qKjq`D9WYB{LgZȢ] VFySț$G_ɾ! j Z@D:^{5ǯ,i1) -|xX$,X :HϝM8ׁC%ط6 HW kEU $T>tcZH^:^ \ѷ7%£C|v?GרwKo2Cj|![ۥڲ.OV" 2`Q m߅H\#cp M # } D]+ bݫxS_V^SL-c^&׋@;QVdi ;|uV3 M2ǂrZfNA]%4o; %~0QiGQ_nU0ffD|"n"X%tsy9.1Zeש F },7*ceu.AZP˔$Ar%lwFj o02o Ix~zcXxώubcz >COOy)psg'4vQE-!]9uɇr@ P1rd P@aCJM"#/[pd {ؐC%5⎔IF|p[r/ tV:V0# I#hS I-#@2s<:պ羦s#lBC:K5ʒϯTd:eR}MT#N mxZһ#n-Umy~‰iۆ\;ɇ`CpЋx%H5o5QBOFX+7Z|<'8zKmJ/L% ;X A׷cl ?1=M.+; FX؃qԉ A޾W 8_.?!q[ŢVQ^{a@(齕m>pM87M|IDr;ZWzn/g:f-AT3p[3ԒV4@Su©5dqb374u 'iAb`CZ'5*Khe9-0MlޜٚitS:Oh[[pKګ VA&*>3ֈ5) `en#@riKTQ Kϯq9UGW|h2ro b]HOJѐuyD.R#u LT,m=EE)j#( C=K+RWNx Vi.wa*oSv vOr :im./*kly͡GN؆*e焉ĚI5m(IWQa]TN .'hYvܵoznc>f3_76KsyoP/ij`ǨIHWƎ@x?ضo:WhvǼH5yvLUٜ[K/αm@@kiטEqr9J=/1TM7bSR|'j~c;ZD.} B M:6:\m&ab%v *lbheT`Β0P:R2{>0^?Y$U)_yI,Yr,ގ"KnZm*bXX>An1lj>NBs♬KG^.7&~ TP{W+T!^a1b(Ze= &m73O xͻ5Nr߁/$MqnѪS>L՘z&e2Ssk'(!N]l-c%QTSj^mt2rq =Rr'LUIq<Z36MimV)‹[9O skd>w) =a!˔Ă6zb0Ǵbp _4d$C)kOmJ^C$U=rq{ "t&bmᔷ4 "?VXxZyvXp oc ((͆EXB~}(+!>,l\80.Gq`gMܵ;5C+W}Os %I8'(tS L~l&Nb74|P72B"]] d@`y8xpCx19iLA--qz0JP,z$*8tOY EN7?9F}.(~@ejX N&PK2:zUސLR:  mS _XC¾rDAOn *Ր;R~#0Sق!?_['4#N8=TKnR#JvD\m]Hz$aROI 8Q6G&YU١bʠF&vy*wȐaꃂj4="QiLfG#'>щZؔΙQ9D̹U~-J9\ݺ/:4<)3Ȳs{zo/q4x`Kgd[{gLb AH6q5,&nM2N43ڍީ\ le񺂧2BT+?z'I}}#l5:Z~A@G=|3&Ŝ0]V1, g *:=lYQ9}N uu?+Z#{¢o$~UD0º6UjDb$!Qݯ!o|?\>GN{tFԕë[uJl#2ʟV-Mmcg/h` bh7dIA7 PnxjJ%q>hpFݛPCR@}tόH?Mr MrP[$̭jN )\&34 n+özzb6i]խio l.5wYcW^\],;i&Zv{[s6%۟{/8\>g4N' UC[~6LtOWt LYrj,:+K* ;ܑ+Nr5󤛩q]W,z8z (3[珳,?vqJf-wW'4,sNO-WpBx C?%^?dގx"Y{m˻s82z䏚g76&g\V+1ӬSD֖B}/q:zގ)_sꩩO9wW8 ~q ~*Mt[n׈jLZ"P?{V1 y6:z{"f^-"A cgpj-#g"9!AʤcxZq*.mSTβtDVK- hIG 9;{WZqD_&qLSP1_jPt1Bݔ,$C! Y5]j撺A+#ܪ^xW $0 iFnOvfpWL^E"f(ǭFUW:J6um.)$7y[^T$LY& zu!;zI(A`xوBGTm? (5s&k Añ bN~*I$vGΥPQ1&tYc\Nq$ 5(hQRwuH5^Au, u@I帝~}0rbK2so:ӆ0kdΕSfEiw Xۦ'T걀OI.pgmЈBܝ^X[:zX hDkJ z^B61,lI+y3 zxs;>2xpn.Qa[&q߽skWX<#ku2+iWd2cE2: VѓJ]wb3es9v)BpnVYlިKgCl1K kl@8*'Mle lO㸀td{osUթI>͠'!3:W) ~ǖ)_'bՓyCxɯIjAFp ;c:jzg$n(uT'Jg\mgڂ`w ~+~]M9̅O#TVՄcʥ_dO"A#]II|Rz5qdǐ"zfn@k`:Y?=8*uKHrӤ>q88Nw_B/VFpǶ1 ǵOEmo18 ?({>qҟ¸5mv[%/ j6΀y^9 Ev9&]fsgG.hVhؚ=?nc󱦊68e!=\G| D}MDuFFz`A"03&wSӜR%*F[{Q@W\>7h;{v˪@bΈΟ"B=vn~:s.̚4M=H'pDlJRam5:Vb+g)h*5`ZS!U!|cҐȲ#QyQ:j |(+ĪA,*M֌w}>tDX@Q%4v>l TyVy LA!Cs5Ha[}pu$\ mMVix%ڄ^!I`{ z S\ wsv}SQG#m.=d1  7CvKIFjsdO'{0FݡR.Y488V\]=kL8*e@A%7f $tm;4C bU>cŅi$+Z!5hYx@aVs %"[J-Bm]k]`"K Ml~bS}KQ7$_rp:碱ǥG=i;ƀ" #z/dHhKIx=̪Ez"ui!ҳJ_Yp; U䭂9OC^WH{k7ݔyz<7O;R* U{2l05jSRLZqĤ& LK! l5Xi`f3AJM,6*kS0I> ʚzzc /tȺj4 C ކcTCq.g($C&&- gT)V9iSJ y0L<;0Y C ;崅nytYHʇr,1|M k @8{!c߿c>:Apz%dQ ^@ wջ#^ cб*/S QFyUeh5` dpwmb5kEtX]i1uL/R~^<nzQA>Z{h.mw*-PHX}1 !q25܀Y#;nITgcy5n]rLIq\L<[ "$ .ammRf]-l',u9yrFX OAR,wTS"Nq.R1,Q6Gi$p@c>CdO)SaB HrN&=$ ?!^6 _c )?#^ (7*&{ 5" --ԊՂ@D%m (Y=@8".@ I2,zw8t4g u\;!w]FoLnHZdOƿR,{q9XZ%+~Z޿- svt%PI_zf9tanF*}-Fʴl ;jBt9!:GeWQI1"cCoMJ[ UK2UYĢkB٨,UpdZjkk8"iNIY.z6о>Q@;Wd ʕQME+"`AjKloR R>ŒZB@"Q~vx/QȏTYI81ajx@O_T͜>e?ÿa>Ax8-rso++ s4#i2*)M*x2lĚTŸ,nk y7%΢!\Rssc= ݷ}h:QwwȮ">cZljY J=@۽v_ͱJ4Z!Y a,6=jQen&KkZ#r6OC?89jYIOH~z:h{n3˛(.ӛ2>Db NQ`_Dz Ctfz!sUVY+Bma<q+G3QaݘScN잨5F;tAB|a琐’C/0] Ӕ]1E03gJ#U^ Θ4; -IxXbk*?5--V)?k\@D]87RgK'gX?I#}Ud'1ӻ Ump>~Ȩ̈BdeG&uEL/H 5u%:±%[]VP5_c&/0V4g0 H&-f9J6uنQՏAGw*Y17[P_҇ ʒS|B h!-bnv­+d_~t2ڛ "]z06 L]BzZPܤ>߹(/; z+2Ե&pYS0~;A|:M!93]9_F֝U=6ޤj3 Ck^ioؑƂn)~5]$ؐd<}=ffl/:}c}+ۇz[?2)㨸Pȭc^]u`" 8rˊs۾kicY<&rAǕ)?d*v="6 U"+ʬk0'*^K* t7:@'5/l{lvW$aqң1`|~ ɟ2L|?~N3 hYclYڼ Oe1CyRcJU.|(~"{n` ۧj;SaQ懙2PJhl]b8vsLWxւ ?nE*y ]`'mqΊsiȰ_nCo E90Ht0J”kHrKB^4C׿9p<=*4LV/z8P`r+P7w2OY*>eWe+O=⡹cjZV8:tT>BdsI+F_D |MO> /Ԋ(PIljV :r]&s $7$T4klB&ʳwoBIYF7Czc;AJ9 1b2S'_;W@t߰w IOUe擱Xn1 !c[9}>2}j-L4n5n- 9D͏7.0 CR 㒭Mp9v~4py=ߜ$^(G~hW ޭK`;2`kmx9B5zb5wcr]`BF9W& ^ D(q0Bvod# 6iב|F}ҐyU(m&kh{F㵟!Wp!ב;ݨ\֯Q01w 4Et~Ww9he'&ޘcX|@Á'J7,7Aǰ]S}ObA]Y$ 9GbF?iQ!0d8AQ-QcLhު'3oU <3psjDt>JO4"{7Ă`^v%&f|Ѧ߷K(LSz@|@Hpڟ3\%QpltZ Q;uMutx^+ަgR8m#C)Vb߼zԏZM 9,3,ۙ&rO.~Ay+[{\[x׵dSu!I٢LTIM+yQ)4'KZboN]d}ۅi_?Ct(t߷ktj5@sY!B ;BIԏB56pP. C/::zw.C0vy ^cWm7Z ]yu 9Zp CmǕqg̼4.rP1 *c? ID#e@#?5 'l6HT $%c|p,0p=.o{QfVJsw HwW[y!$! I8סr"TbL3 -7D\(y</MRyf̸+9t՟1NgCdۭ&(w[  K7'HrDZ˷Q95ryuwgY58@3f̨n8@Eߟkx[73P}8"Y7JH9ڄmG$6tLVe#}(u>t)O-S N)PЗhsI^Zq@Kf}RD[(Qo5;;U{6U+Y1sG4EbG[7v.j!FAT&-QMVd=VHiYmݒ8ERԏd#w3izf, eS&0ma 3,,-͜/ py$2e D~~i3}USFXHa- 6Ҳ{S {]pCLqwTa~_F4N/>HY^F$|˒~WjUu2#weC+mZFgBv%ǯ Mo#VWsy0ZL!hQT>8ʏnf&]:&% 2^~d*E pk^~\/ ! mSBr:YAAv:ggByxL$kcYOVr DOp?/Ž \NSXȁȥdg,+iu`+7ٴrs]\<#>$m0u$mAԼVCR˿مʼndajێ>b_H/(r>R;p64*n8ᑜvrN`災%֩=Va%Ζx_E o)[\O5}R q䵕^H ’Liz8Mf]/?|ʅ}ܟfHOp?|% Oy$kxr 4  ]uj\/|<"rg ]fa$5[-MGE*bP`TQE6rT]M;zUuqfS2Ưc $. /`Xt'?f&GR(.o*ZD!g)mI/&(`P۝{|.^}gl4)BЂO5d~A*-E}n Í)D.]XU)צŽd\2rП75[jUETaJJf6 %S[X$i95P> b$}{߀5{ɵްծ 7a':7N~jLnq#تH{Ayj2C?_kA.B~rxQezf5EA&3A#LcCLEI|3w ]V(a矁l*_!eL{PiDE@m*qBl‰)B7?$Ě>0[mmkc"t ]U/׎-_=ÆjɫR&vǙ~h3bi$ˇ_ E[m/LZ)(9jA'hn@)(Hns`KÜPP8/AQ^V.? }ʍpe7h& 2߶<>Z")Q,5vSyӠ:=W=Z|n#P j@cryLn8f&Үv$m'[Ίsߩո>m?oQ`P櫆7^">dl7oYj -Ȣr%QHgnl7E7vx]vcqdػV߿Gy?LW˱-ev03;b?魣Kpr}iz̢xX(M#kBfċpT'-ƅ`HiYK[a7ikAqipb\x Ď% %Sی|עt[='[5|^սA^bR*G{ʦۧ6`z)!78͛_Z֍NQ==݈ϤXԯ-$=9w|c꙾B:6&$XYb#qTqkHB 63b/B g=KUṷ-lS}G62ψ@G̉f6F>#}݊|4bgM40`jNsmZRl@}ﳵJe`[E#i<!58Ս´b pj}G1\D:eaTacsWb9ނeᾒX?(4õ|C Y>`M;wxĝI\45$vğ=017xv\HZn( ^ 9ZAaS‚m^]"r y!ߎĭwUӵ)9=z׺~D}wzF_iNj7)99yb)C:B/YsE*~m 8Z":csD"4+Qk|nZ/m L;J @Zb\b[0Sr?['lB5W,Yԇ5J'9ܔ{ *02O n)/GS#/Pm+9Rwt#h\W(ChAgvs_D&ݶMٕ-VO|@rС2tQ%*[-~}k4 [ۦؤyW{3!2pX>*3(RCbXq.D>MTW;;1 ]6r"S >n#S-> >],%{gv%\|2/6=cRTꦑox&:ؓmt"H݇ %ƥx! z?]Dd2k2#0T-MweU"zYvPm;pXa&  mk5or‹ФB =C?C4B[-P5-REIDɩF? K`sÕtJY"P:OR}RJ^sJ1mǤs,v@0YM@ =S:,FWnFߔTv4ywN<%i'.C 0hluR) :ruAjCHJ[۾D1R]1v*Ԍ 󖻚 zA3${uDq=ЉBcAns҇ē3fЊP~onGdYj$}x)VvvPɠ՛<lSd@[ĔVJF_,A?l]Lla/5Wr1ަ>þ?߄k(!-o^чixM8퓮I\\Mbo߇wߦL"5Y.oJ^ vF`|h .c4 ,Ox?"$hct݋uĿ8Ka *ӂFv ń81: g xAix[^P |a^;1ek N KJ鷃+jMм@)öZq<rX4s(f0ÞqWS1XJ8&\"K/4 ,$ACsRvR0D 7V]d=i}yޒ4r֛gr"lPyn*M04Exv.dXGll2^NvvAৰG?QW>}pvrʍXSY~ s2v:=c-~#uSnrz?f\7UtDZ.c6j w/# aG<. VFS)[Oxpӓo"P!}t@ C<&3oDox;Z&< I/FT“}L(T0&TJ-k@~4?NKhͿ$~ J~"E%\4{T?[I%r5؜(gl1mgi"d_7jLf q<k1.n-Ŀzl7ءCJTķU Fte6Hp '7D!h"  !{C@E]ohlڑ-Nz]q:z!9i:9DS$̑p ZM}í;8`OТPBIfK`.\ CUUnh)P;L]n 6ckx_7prjIVAzgjB?CDL`J8Xߌ: 7;G'_\!Ԗf0`ϸ2 .vpgroI,=焩MtOprXr*@P,h}|6WH"8?1u Th4`fPGnNcjx/8S2b+9 GЃbcRKq= 83L)Ac7؛}2 ?LNK#bAKu0Or5=}C*54I3{gR… Q zev,En}WKq~X#r2KЛ?u;¥=逇-UޥZWkgbRő1D5͢b~yxv/n>ݛe&(.r&%f?T|}9xn%3)1=8\UYZ68[8;-x\RF{ReЎK"1&1fCѴ$!#fylohZkxd{$Gzh %:0"纾/(mIw_U`R`u%2Ǘ ixxθ"4Dͻ^Bk~cz@d "Y!y0lKicBCݯe栀{ߎ?P=(Y3R%oC` _Nj]ɯ璁;:+3kwc(:+# N6 Q,kw~OMzFylΛ[P(dɼHnҷէ` m-Jc1fJpXj^j+,Wv@P0+@s:4Ia\Yi;jw찶+QjѨߊ9qw-=3k/]<uDHI^TdͿ^.NgH3-Dd0ObZ^f܀+wk̠{'6뤫YitnPWa&M5Ό ivv0<-O`%Lz /' -bx[=$z( bd%-.4 y(.W ޲;JVQOA2Fh~MNH$` ~mjxu䟨K8b-S[Ƣ܀ pc|QRd`#mC2 =zU:Z&F1vRgJb!ypTl(wRCژWOe.HjW C;kԑk^9Y!yf؄U{ /{JP [1:A~ֱ&|i) MC3ሙ~-䃖Kh\b+%F)5,Tr X Sܞy0_@i5,NNDbalgNz/n-=z oL.b8Sg:VrNTRw#҇(ދOOe2B~t!WSNa3T鸫D{Z O\1W:[QLcPDN,2M|Lv N$^5 @1fgR} |ΘW ?Y\UMsA i Y 0ľcFp;߲#pFgW ]GL a-S#N _hlUB>ԓTN 2cYex"۽V Ϟfb ѝZ^wT89^ 괪5IPuGAEMNF\t^]!ؙ%e]\+yQ)h(|3.v'?GX4{LTřo8\ SƣO:9n8V/ hK˻\DH`'1lckp PN{\:AvFq%arpkbu^\_#I4"@dw`sr-ѽ'ZB_0_C DCM jA^ٿ<vV8[nH7Ӂ+H9v4nxjd%; ƂU0RIL)Wm+%#(c Eq7UD|SJe zK 1G?ZjҹKq4RCĊVNcI]Y>C᠎rGS(8Fn< 5z  kQ qЀ.'0_w#%Jt|?4Y]{5n`!7H(2/ԠvG#~cJx'dzזэCDM@oy W5q@[I3{;`B4WSug萈H Az@WU k;|iI7˄a4 ˵WC:] 6؍L!J dT[Jd`~}NؽhU/s]:6ZEḶJۮ 0_bT=†0)!$ & [>$~#4[bF(k3=>e)E\Tfu\; "gz]7Zaï/zBg56Q\ ?(1 in-͓L͟RLw7)1SG$g#|`*+ FW=?4,&sYN)lU QF=Ghַm%Ps"5-7%>jX443.8w2o>j;"z2k?f4unB> lZC.:m6\\H}9H?/KҞ0ڈΛk'`13GH.YgQ'P=#vyDȌ y@ |%y bM!m(&Uϑٽ,o\*WsE9%zq{[:Qg/Z~&ŋ,3哐YouDP?RgE9ptag2m@g9i~ ܶkS^*F({dCNȻIӳw=zZ("ͽXØ-;nqfKnK2-##BGIgm Vvv4&^8\yG;֝WU#vkVz$5d DSW7qav }t{sGof X e֖(_?45.7!Fݚ<|-TG#ۣ+iX0|-*5SLbͻW~]Uegn+ӖOjo 1O- D_V5Heߍ5o EoʨoTy0mcRRr=;M 4q{2yE1"'SDc@AzfpaŔ"Cv4Fp5wS]pBaz_F)]$(Jt*&6='H2=-|<rʭdѠm IBr.?-NA<@k]p=Go%*{ūY992-ĥU'(ԩ`j/yUS_T\ي(N2Ck9jhb2P!/W֍KyP}UF Ǧ<-Ax8>9 zxJE [XrM\e@@FshIՒ#}svZKJ1EF#1< O΍j bIoXGupkˣ>:CCi$kE-{͘DћgMzI,У)#\e/hq蓮n|:&Z7*/ໞl ؟׬H6 4dC6uLp~]b)MէoE/(˿b@{! :dwT5)#p m 7:arT4` ݗB͜!H;maf%/Y'6]z ŕ bw|l)gM8hd IםUl!"TOp2Cm]kq th5Gr잎(2GM6Əeo6\|&D C;Xľ.ap)E Ԕ ձM+2 ^U~.|DO=+gs0650ب7JA)՟FfD~Wqc 9ħ%#EX}8gWDe|̸R2ʀH.l(0t**I069q.vɘrb9k6v~b0PGx!xX]6:niIмK":"q͂T֗|8q`o8l8!)Y\zrhyqcwSlj[ft~6ׄ !t MH=A2ϙVK[aiu^G;'~aIi~ D/8@]G-C7S/DQyx ӊGW 9F>&S܏7Χރy;"b|Njp0#3 DA]N53Oá7^ ?`TûbL5cT}'%<ҸII"&Y$>f'Fqz7bM.; M@Lv@z@ѫ8sKPe~=a( W^=I-ݏ= VyV)-Ծ˩/(/,Ȥj92&űy݌`P ̌𬳌&ZvvW%x5& ]Ro]1W͗Y3ٰ*zrTFԝ'-1UN3wA\7>,jZZ?lCFB++ شG %f_b9sAl?3Q޸.;Cb0.xZ kq}ƹBYqQuR?2# GY83t#L&P:P#A>9[VK!l(Qa!MEp@J`(2 }f{YIm7S٧^r3lZ1IrZ+ v5"d*0 ݵH!^"j|H 0 7;`U쳰Wu/U~=mrz;t .(kH2|R MǕb /'s(YiMu[>ڀ/}|YsB;W[SCV]!:8& it/Hdkck;R6"2w|/E+UIf9O-]vg9K)O( ,0L,mw`vJyNr]D#,.5#VSu sFˣ%"+!M̙:{>9>t(°ܕ@;Ɔp^zsZ5^\hba[#^S~_dޕ;RɳK)K C!W PVo(Rt[ $=9WĞ秀) hz,@P \}{lQJjd~X׋ԛAHM[¾_&ۦbF{zRNGƌߝD2rpV>,|2^~|O=ܵ`&b3LW] O("EfBX\y TAۘZw*(? =4)'_9Mk+R>j߱Y]8ʾ<̮R5#afY֋DՍ/^5%`%FKU@]m'\YBђmyDb;p.#]] C3|O&ua>땪S] 0rS߸Ќs2i!珀ٌPLT(}[HD]xrd!!^H}YKAIN߱i M l$ͭtE ]5IK4d:AX7D!}Gr/h4hRxZc$8GT% pGhmk|>\:qLu)vz-P-fJD*pYNb)zs!/e 5RGL҉l8c" 'vC:9XR1'ΐ}7#m? vKC  aWL,L\~ttqܧNHꯙj1zU'XKiϣ{6̃y:E.zIq)y-pb(Uf0NEVS\'xr;KL3kmVՙeT3eΓyXnkYO2^F#NEEo?Ű޼,^1V&{WFHOaqlf@RZک@Ifs.Hxѻ|/ntk0j4P@Y&s:$NMLN)nIK.wÅXB Sd׻;<ʡAZ7{QM?dtG02*:_'Aɪx+rKnp2~ 2ߊ|?j\@BU$ǭ'эYddnvʮWJ=DKfOwg=ZCQUn><9B2oҶ8@fhKݱ5! Лd"15K$],=I ƛ(L{.\Q]d9pkf_jkl+B5;{w1o*zh~GdY@ p//Ybz-7 \oVb\akp:.{Vn15l5އN|S#,U~Ki)tL$0XJ8s< H>$$"GvzoCۦQB0;O݈(-p ]s~z+?luȾ lW\ (3e]?쨈vaҿH΄+ XvL6׀C=!ijQ uQ.XXK[;'De.;bS%ȱf괝 r[® I(;nF H8ʛO>-Us8=Q8RWk^/A5}v@>̪HU#WT͙,t==y6cw_w!)4MN'O^A&4_J俖6R#ܞ6+^NP1Nߒ&φŽCkJMm{E_BY*4#/m&b(݆Ik&sp[i%QO4PfaKuw2ziv6 oﱻg:yHP?Oo%8Ah+=s.RD5"|f{ }VE؂Ynl\ZQ[$(h"VIačSbL6J̎^/ͦ*,Wdc1$x= &)-Y/J rQ 3 B@RQ.쪤`d0gJjOu6̛fXLlGyv>輥A@_{@V!̈́X2jK=XEHA޶ATƌ,0{xaf{4ךšLlN6jRw!o xB%)2_W5?0h0U h{+ֆ9`# 8b[W6ۂ™1|5*oeg3&tjk@H2KuĎh6dDP }ԢڷZhývbLJ6G-ĆbrF Ww*ezkguv\ X$1xSHAgI6߆^X_fB9S=PbMq1rpYM+`k t*0 4zw-f~ڞ٥g]3Y)waAcM_%GePMŦ4UG%#F'IԨ L3nK $룱RDϬ+6Erm;io^c>dkildnbAq`>_5:?_މNixB![Ϋ`6Do$ڌmy se#v(߲m(,))- 1/.!zi9^^NA[ Wyml.%AJ} 6_܍6KEk;n)ck+F7Ǭ)a)Px5&905q c|-gOO؄(gG+CVq͎$ &&*f6Qx͟ԿIOIQdP\G_8/ct׭$]3.X<8ϰeKc8hjUڽ#`3 ck%'tSԠ4zZO8^uaD[ 3ݷh|]yip .Z9_Meؔ c; h2`_jm(WlJ4 -oc|x?jvjjk-Xvf+,,/X':0,W(-JU%H~0ϻNÉM}zeau֭ro+eIBkV+NARMj``Ƒ͜ $P`m'cHtp4(;|2 _g1 8 ǬW ⨡BT\k`Ãs\g$Un+9d<%;ܷSAn7`qԓI$؀-ھLjz|>}J^]˸Bnz}/]ŀ 87.i@ANjDȥfG^l'oe$e1vc\<ˤ.)"GN' y ݐɷ׳nc.F;K  .ϸkVl6^\ ^ IX  jC _L)GSm@hNwCZz<+AP|m uF);\ Qx1hyNϭ,wkU$G˂co9 p)H/U4|f4u`bEWt}6!zrL|6 #a'#ʡ3 x 0$S|` Cͅ 3Vl9%SGDpۼTZRs81*u-zIz#oj#+乻E8߭6Ee'2a+/pHwZaȨI?&ciD27a#ei{|.PV:X&Nꄧn~Y WA׎7-c9Aqiww`7+N3R-"QRJ0xq w;"|^ Y=W#NL_ZahkAT@3B.zV)vGV [sM/ZO\1k]z:YOS|;Q EP1_mң32^1|'ȘzF_vMbI8<[1ݖ ޠy쀆ٷ>C?j kuO(d/Jؕ \}#kp\l)5b)Cdé\`G?kK5 `2m^*_[OQ򠐇cN ,Zbp`-H?1SZ} ΃plj>"l¤ZuZfΈmo]57R^~'..Kr?c1`ΠTkKIHS-OÒ4ϗ5/p&3 I%Ž^cOm d+?汄] {u2;/uM:{R^nŹ5R/!-dB/Td͊Axɻ*|}ɇ%MJc(z.ԫ|uʧ̀Т:70Ow,Uڟ(zF o25;w>n?rn}ЗzVH{u4g+y j& xڟCsǼ C<zt.LZ'Q˪ g=w(Y}TPԗ֚>X%ޭl#*)bJ 8[ڀe5'BYMz!F%RdTY$kʫfQ0p]q 齖_ê$dP)EM G_f>+kspA ]lj1T,I7 sVND];!/}Kn\ۚud `ŭ ՞]aQQ%=0}>~hf􊤊xuC}0{i9DoFȘ=G(_l$=.Bbq&U)z㬳n2ؼ֩2kmG2>:%uַz"fS1ߢur _ ;i>5@4l-&LwMe jFDuֱL)&::hAt"ޱvt T\2b|keS|NZ L;%ҳtVdJ$~_~XAtUR&8N^U?Э\ a8޹xFHXB5[[Zt6b/i&K<]t 5c kG ZK9WHjUF3m8 FR{=qbNWp}{p 7Ha%tp EMB"hz} C.ض.2\ >_p4MvRK`dD^aǻakNS/ Y尹]Q̞ပLn 5a6]O _s%l ;" %E0n 1ѷTZ߀QV)b`oWsh7ALn](V 8hIG6 h<-+}qa' TUW8 CՐ| +V.R@qqD,A M7\:Rzp_>hJbЌ7#D.qLsO4龟vޟB_0gXIIG:QشejE"J8DqѫO9d~&Rz$@d_u_Vg4\ Xǯq܆a/R^'RHL^Z4Kʇ%mv,G}EEʇ~&HglhB7ćoPF4-^w43yz!TAxis^k^pq$eO4p a0@U5~kkf8<˱54i}fASPs;`9Ur]^CO"5b wy[kX ABӌb^fO`F^͹I"!(1ٿA|_<.B;GeWcy59YʹUyD|ZeaDk!0}nRZΉ, /DDtQu)v*jc;/j*vnqmiqx=w@ϐ 3%7 ± ^l=}JB^'"gVt^[>'+Adr*ԞVM`q*d?ٷ֞"HQ$UeFIDͪG+Bٚ_:ZQ~s>(02tB+ Iw&q&.LbwF\#U_IJgn]k䁪gJ ?46pD#>"dd$9`;IANK˩&/V1,RW,TH%XO[v|aO$h ӌ_rR;Lnr=^ *Nd $T`$\ÿ#\:P@^[]I bRS8E`'wRr(FhB|Ra.J .NyFq.E"\ݝ>- I ݁rw8x¸BE0j$=oK\ԑ6@BXA|u@cBv[160$h5a?6J%m7C # } zsnBpPblw]$E5njI1FN5E}<^7G/A0`Wƙ}#<-9l,3î <ucH)8# i$JQgb&Bqgq=+!0Wb`N|y%08,9Db$^aXcA*loynB M~$1g]H Vp&: 4{"2[7劲!wJN;%k4{dO\GtIkm nZCWV I,AU6I7 >Fkɢ,1Ys$"@yI}891Ъ]_}M 0n ŝ\4 kWOϿ`$VT3 RaȧD@ ks M{u\RRܚi- O[DS3֏c~S4ڮ[ŜZ7d^|Zo]rPTTf gIp&0=&׭>%uMY7rj"'ZedF" /2WCV>3ޘvFvO_$.ݑg>feOdaY3$Yo-Sk=' Dt7e2Tq8O[MKnlZEtK# :O^ ѹw;/O"Rai>wd; з>'{aD'؎xQ7pv}ݳ] Dl/ꌎpQi Od2w&_ 987;!w ÿNgNT9j9ȫ%}bRpb@*ivqh+?rzU{ys17oK3`xp_\e$GyR@]Y [Kh| B='Q'Mx'%f7Tf#U=1[ɰ#.8w+S#31o#m Txz8,h#/Έ}]Op/h(۴ss2oIMn^U7^(KzE| uk b: Q 8y|}PǺhFY0MXK3PS%FBI/ɴzpmއ6x *"Onzyح߽g靆'+GK֔fIiɒ3bj<=3|`Ef(WE@ŹIWՑ2cDof<#~[[3եBk?吻9 5scYU'?k׺,,K g8ٌ0%,{0J)!7`mmDmJbJgm;< U:U鷏IO3uf|[Gb sUiб}F̋y{]^pm`MXgӾ4% F _Wj8wg3aT@4$z؋_/ubT!9IdV^37%+hy^ݏu;%!6<YU&nKٱ}gmѠTQ{ALk @>[Oh:Jݱ >@ Y5ہXѧ 1Rް%@7/ & \]#qlX_7Δps ϰ6-.Y͑CE=K7WY-'ȾM5Gge&Q:!L(~Tc<$7OB %c)+?(#^(y{Om 3 ۣcAɅ[11SyS](gQqP/u hw[Yc;noy'jPe>rR_  [RzZ3:3Rc3Wr({ &Kz [shb;P-|59޺L,,y$hngː!pC8}X[ "O/ k{1t>3lzS^ %cTC1r"9$Z\:I{Cԕs ͗*tՓioKttw67p -k)xrZt({i1Oys N:[ho77ō;>=?{̄g[1\<1;+'23,pMHk+^\֦(#L'|< ,DȨpJ?$uLS~πJq;$j\ ‡'oS-;;u}ťJCطDS/?BX:1v$:d|q1+WU0%g|¿Lqw2[V+Wإy6hh?Mp~W3֎S7&1X?2op"kT+#\~y4(&Vj?>&k3YާIOl1n|s]ǵREoAK?/^>r.8f3L9B3ʌr~qL2/CIغ}L+ͭUk-B W'pi^jua}߮,:IXJ bYj;{"uTO0#d\3 ܦ`BL8pZ31 W-bVy1Eo U1`&nA_Jsb&+sL=s1kRtְH9X;P? T7:cW>d1OɀxR93 ]lxJa.m|?C8`ro"ux?gEL+$|x9J qܝ!ܗmy ndYڄި9BwUGj C:64Қ`qcjd0O[O`/x7cW@pд $KָJ8LFwTő7^OiPmq~*KHbی#F[4ʌ, dnH'9tD=`[D"z>5#%E֥L*V diEJYD?oEXZ58Ny*B/yć1_ËJze}K9 "2tBFpBwIp$)+{_}* $IP2OxjjgiDQJk%0?U+qj}2^5r@RK 3AݿU m*a&eᳫL kFLʗIfwrO#7 GCX `_h[kk"&{>޳9_2F!3&eTm-S 4̾i2N8N ˻F2'|')%+% !dRd bb3 !TȽ"#zͼѠ'YY;4_@)sѭb`sSrjM_ G|Nl5\'Ge ux>yUjGᡪy m*=_96 L>zrg:WnEL'iݎχt :ѭiniŻ}%r^΋qqܝ,sԊ:T %@SM#A+xC=~GӤܧ- %USukalCyɏ!vܬch=fUɭq$,_/73EO/Al,*|M:⹗!!ev8F+e Nas_85y0b&AH&DXؒXX|,פ6ScR(Y{(c\ m_c0etjޏIg`b+lsFR@wgBI!(9d%&9}Ch\M-!=kJHHhq;ʚEE` po>F#SUdA3}Im"V^ټ$1zj%((àNo8ElMA#8Sg (oi k4S2;DҿzF5kTEjuXgx+S_A5N3,<9Vo&]c0)jF?KΝ (Z16wG:<%0`@"4⧅Pnmmmm%w]SLi~2, R&>L֥&=OQ%OKT!*RߟXzgR$6bbI+2 1 ~$)aQ`7DVׁ\݄*lJL|G8SN}9:*^> Ƞ|*9m_t~Ku|q!H7X W,QAqقƎYpcuI:] GɝsvEѺ]+jOIWO!/#݋R5o1Qgzp\= _?2:.SmwYDR<F1 }\[幨5"eOXۉQaI:"WrsKn-Jr&Uctp;?x-_U?WCD]pI#oBrV+$qUD* H*%;0^DqGՄHv3I`~ޜhK|A =# >F<ꨯ½Y/A0ЗiluT#,KU" )%!ZJمW򞎺F3:{9acu5fL*>T廌cQBr[=BY=dDʹ3fc=O X JYB99y"af6a` 'ʁz3:bW\i{Sêibqe3VjL~r=BڻJl&(8O? +rSBh7S} hg fKRk/4.Q'<$翧g>?:403ĸXFamY+#0%Gf׬! w̽Vk| >&O9cf]Zձ@ t!Q:暍 fiJaz_?w*|HY@+*"Qe&Js2C_ZVSdg6 ]tfb@l3IgD9`0(Hac#c^5åKѣz^`(@]*#D R`W@=((=*1b*gLr5PsjD[1lG) $޳yT-#~7 2ˋyG'Nwpgn 1e\Ԥe+f!c풀b8t|O0pvJ{Iw>wD߿QDi0ߩ^ڀo\cyZVED6b)nݓ+\Uc?o%H&Q"RU;#*/te퇛WlH>ӂuJL1"cuܭ]=##BAL]B/,=Ѹ9\G'zu[vGf`˭X&t wdCm0RkixZGV~\m 22 i-(YG' 72zGGnsfrЀk5/ZK+ko^'4]8/b-ɏtڜQ|k=/A3j<0`ӞK^2VG>Kl:V!uY{;sjXaSP+'C{@Zs"֓]⁨~C2%oA}[zr" :_t5"~ԟ>}۔h] )jEju1͇v ~9sO\chof+BG#lCdB3U_%GT?!s =:R}~jL]Ku藼um'JfI֭חm"'s&}YCVsz*E=OH"xj&0œ%_:Ⱦ JcԼkkk1)<^Ό0͘]ޔIs;3=Y`7RtTѻNs,{\ qp"Q4B= NOfkm,ˈˬJSnH“t}Ə͞h0 1V@$37 `h#FA6L֧vTE)h${ r|^|ᷪ*B^%a7/.W? <$jxxj*7īl>g% o{> !L@=X31 9 U@3˨4|O~Aj*G]tUt j~݃(1B~{Ta0lwjPh.PҳoGt* tIJDY{գUb+N>f',Ѿb!ރ\RAnC|l\%K<} ~#]53|=SdCup,YVz~1偅ho@SM.A;cPg{]넹DA#,&]0/)F2<ŀ4vYu))6yT# 169.S4'Y;N( [h9{fzc7ه;GrFtЌ6@lC wՅ 9]|wFo]+QEuӂ`֝Ir~U3KTnڽБ SC.WLjʩzT({%5^Z;W- e˙ZQU'lM;NvZ"WCkT״Az6Fi'̤dXS4GzkXMf26`Y+/S: {LxDPԆ ں2I3`PfQXZLO „r"H0C;b4PH 2\? .L/$ѪG3!~.ٛHrfn=eaщ7PWI^<ó;df£'sȀPP ~^!=yh u<(izaI/6`~AlDT%M;&N$mbzN,Ns6 O%$mW2@dK1,Hb"i;>' m A`r4ƞ/({>2k+$3Ycᯣgr@F-H&+1Ӛ&x,%/@Xcs|&*^CVSq-6#r]dB"rvQc,Xp#l'j/D:,^̿81h3Nh@w#1%:y,n5bȗ{PRhrPIZ@`.!R_QlԌl ;dBi[1>tk׾ys&dA'r+ ֺg6)VxƒIi$`<@ڟ5/Nv4.&J=ED/)rfmfJ*gmgpNܮ(uDNEёFzeBfPʀ {{Eʖ9HO8 !nzUïR~O2$ȉ6R@ !X_;m.;cJ皲n>- 3XR4[RkOTS|l/[߯|?}9ƶ$wAg+ڏOYSE͙C]v X\%A0лiɐۛv+8A=)>jcK ٍýNva6 U a8|!rH_M *_ ;ُnSXސъoS(&B|!q)Hm\ $C5o̭<=+H-|+0|0^t6,>gRFǖ+(LC$`A9][Au(A}GA̰SMƭH OͬlEp闵>N*R a;2KbDzʈ:rԙ|2v]$,Ug_sA蠠;Yi:|ӕP""ۢ0yiPSX궗3f;-o"*ģD#q_98T:ޤo{+j.9",7BZ 1(PRgD?AH;;#\D^bkePM&3nSXJ qz;T*\g:V&:V-0F kv@!3qssJd ${xѿ'dnZ 'yp<8JK0[J|sV ~{3!V0)؍>\ q;q̕XF!Zd>D\f1oCtbLIN%cA,tZ_]EO>%u #w#**L8պ+%޳\<Gg-Z)q)7\3 %2"Yugyqo$f!U^Ҿr>$7(6s[kBaRRX "5!4#h_TJ=2|,$b aQ< z9ب0=/b11͝wm$  tGA*Qv'G!R~7nC#yAroy,d!ς|xuRO(UɃ\]jg=Kj#a}D& :;j5ÆBYKMNlw4TtnUՄc:"d#ˀ:/hgf651St U`fN/Xt *+]K*Ig9Ǫ22R,tOmͽ;BE9\;tHѺޜ d4VGrug1*$q1yf 5痍`͌>?-.b-z/V|Y:dz[sh^o`톌Rɤ 6t'J[Rm 2#@YJE^D[GP"G}_sf w#gi1~B0S^n^Rb;$TgJt/QGSJS0{A ʃnpLaz1E7P=xDŽxb3'ȕgŋH/8,ſ VV죺q=VGU <{ЃvVP<`e@ 4ilhM [eZN")|^1 h=(@i+Z/W">,NnLbI3S/3=g%< ^6)JdgLcF">`JE6-vHr!Bd@laex5Qߚ]M"Lr lq/LlyF.ۧ!.魏fgl/4lPSckuq&gMfڲ Ip+`φ%Wp2.v3Q9 Q@5yoս S56M_sHMR);697[_XlTL*ɨ/")f`6t@B\j\J-m0C^r=rߖ߾cFFb3B ~"bCpǃ1뚍$U\z5Ya*$8 q=Vf$}2"saŠamƛO|# fps8o?7hYzE9> f) H2w`q6Q.UͥI"W-:w3g;C65SƄs tihA=V$|l?j;h 7wW*4 3vtmirj̛*?J,;)${p:=r7k ,Z :F+"T\.]-(׌@xé-?3ߣdYbXc>E$Mi# O|`Y|2K2XX~T9=>Cw)DV[dX35Ӈ'lO\ Ffq䬢pt(9*H-Ey2t?J A1[P´] TX-Kh WSt .yBqJ: ÑglDW4Em*<9GݾE/ K$FͶlz jE#H'fudlXK|=/@:!;kI +MHRYDiUCѠN]&嗋6u}t"훑cAZs^5[0wbqާ ̌ʺ:p0`wqOy}Af#<{l cũ XSoIF\U 0*v+}ւԶCKL׼Yoh4vlݧNGZUN|;J 4^^Ig ND$w=ioWGdPyrNbeõIxOl+lbI>pO>]CSE>  (%yagd믗e@z!HXlXm,s_æ3]>s# `)0K&K|nlpeY?L,So Rxx>VsiRpB5]vLet*h^E;Ь߲J eQi$Խ;Y`UuI{/dQZm f% &m< } $i9ֱ J9T4Vtט)(})6٧KS}RqG(t? R /D?/#ϮgʌUy`;TR+) 3u7|xo?9NEw(PI-8,N,}/8'7l.O/x|܆]QaiJz%Nx>&EuBq"zgb-S::@\þAQ:aY kecP}1OmоBպX.H ϟ(i۞5Ke%䟫5r*a[iy2œT4K:lʙa@!.UZS[+ |Oh%`+tle?Lq%#J cKe^s_6Ўqg wZۄ ,4-ڌTy1w [ѧ[vKSEi[ Gg=&XA; t(Et4)NwD pLS"E .߉]ō` &Uznpu?r ѝ/5bLZ0/Oqg K@UBVT"I>[?K3ErIʈۤ"+_`Q̠_"=[u2Zpݷ3؆8$Lņtund 6|J;[@V C_ԝCW#Mk/:Ir-"):9qtqӝ?/ qA( y=s0;_'P);u`DGs 5cQEHם"_'rh%g47rUf))0$xbg#qeq7uӣ9r*rpnAs~Fm>XQ0CNEtSMj=^ ?p Um f=BM[^T%RG1/\0xd7SS#;BS̑H 6dLo";A_58Khl 2;Ҳ:AQ98F2QsH03aL_o}I+؆ $K@/+\0.1=h&t:%`݈u>ad 1J6J_*y;7w^ @z5GFJnfěIoD+ˆ۟Vkrz lׁ-ڗ5R`%^е/âɖONO[*#X).)Ғ{o*H[^|&B.2dJޛ> 㨿G=(3&m;$hXgZK;y62x{^y9 őVp #'.Ud=Ix'-PeRZa}gEhuC{]BXH&!iX<< - {Om{&J15#aO YOze)Pd gk$SFZwŒ)Hص|F܀g1:xK59Y/;߀{UK`t)+*:&{Z*)!MטNP>'9Wj^?%ПކHژ!Jy b \޿$4\ tE> tP[HttOD^lϔ]#8Kh3rR(: bTC1qݞySe_3*/wjP*\f*(¤m QwAE>аd{}>G5hiSNS(`+KREVUeCҀIi㚩|[΍fw5|BXf[}|*Ϋu[^A5ĭg#*mJ&<إg6R @ٵ: gBтmxϵqӨr Po+ЖHrڕ^,v{dC2 qn+kG1*^l>mܹ4m2^`i8BٙS&$*o6`{y)ic5.`~6c0UnW{1qV `nkgͼ;un)=#ʎ#9@"lʓ"rA}hbv9Ž>aÕE!W?, "-MhB|1]g1YZR${4>}2Eh"JqXbD[pnP`g{t7m`K҉0s,ыFXՓx5;ʪ@rB)buzXN5VH^ 2Myt'7 Z\WVe}bͻ9Ō9Ν2&S=@ Ɯ t`4\xvpK%x!-cn^*VWQț{.8!{|wr@|Kq A ڳ07{%% xʒXLZy(^aD.8/Ph: z~F3+ix\QIr$ZBFoozh+YvѫzxF=E ,{Dz֠Wf\gr&xJEo. z Z'eM6c3}F?I*';;0}H|r߼agQ!έ}ʙ?Qߜ2ɍ_CޛNk___r ws8kqܴ;G}*'n3_ cd+)H ga-LB}G+{9o]>B#[Y%6w` %$൚J 1(F!@6뀘v<`70+WN4I)4vc\SMj淕; oA {֯f sQ i1TmkhMkB*PI#j=KOY^M{t}]ۉY>v H&"_՘~z}'H@2L?ks F]) ֔RDq<%&~-㭐* yW m0o,#&|{r'6FP$4Vx,:V!;|ITKiwt~oל4<]r5B(F{Nou;/ǃ#ɽ erx?I]qҘeeBcVz%Ȯ~2zo3nv7^{yy^ A)V!А]fgqT wrzf)ZxҡfuvWzgPh &x!bjwRnbwW:lO_woM\P.h29;7EObLE;4|Za>$qgF@x-gCP";3px~O:\+ n'+38elLQ{R,8A0lF \ GrXUȊ,ig ]rӴZt$(E#!,Ps{/Lwt)4C>wE$z[8U?#Gf<I h66[DZXGXߋџzu+[ 5qr(FWXh2ZXk 7'6kIg2iI^v9pVY 1oE/YQSv >;ڔVhvцྏ.x_߆bE,Mԁ=yz>9M3saLռܨ&0n@% J'YcjU!:ym܉hk+l tJ SdP.aϻ^Twm mԾr'E%8*(P '*~ۀIN]wjd7b9Rr*CznP  ;)Yat]1Z[O& 5MwFĄ}8}peV 6E̞ Q3!X +uL!| ս塗8,(3[sWX{ &=`u8eG~3WDQ衛RQ"'`>1+Sw?[i`ټ&s>B1wҳ=m=-Ԭ6_kwJ!ae;93mՕsfxօ FfK#K,snCMH (h=~Ұ-lUu)KwVLEY]C* h iz؍:cVYUCd;`DM' `t@%xX~a7FA9^NC~g\DHAR\=/ .C9 @4k˱ygUpTA7 )5Ko h-+`! x*6ǑlŞ| Hƨ8za~ ޟ{!uIW?co/ j=r^gsY_2 8y{?+Xu[9ewR+r9FNF 2"vp5qi ߩ%$;_o0>s!E%$m_)W#MoMCj3EXnԶ5/ C+BHoF,joo|eVE `a^uPt{V\}6|g(Xk>6Gw)ߜRn$U5{>^;jPC;I{(G%N^9G-xա1 ~ӯvl{ }}\}MKBj#.rATG9.sj D#\;go sw iHiybm3.vwatSdC^1x,[^=omi Aa(TK^8bI]C9с]vT`8$ăTx-0ecZ+ŪXIkrT؝%&bg-*oqϾN0A1"w@z\7sMvT$#h VBUX[rp5S:ruY\2d^lhVwcd8WB7z˅ʼI8Ý]&L Ěn^jytJ[&', KI~eiimvsQ@h>i|Ϳb J6jE{.0>Ks^]TEKOi($ 9+ -/u繁n3?80O(s9d: H~/bD^Y j*O)5@l$[?RAn'3RHl 8`)<sul"mh9ܭ:GnFI-OFR\CUS&XQX?5NKJIZN#N{|%KJnvo%٫$!\3_=2%e rWهyF=ڙƏA\X.oӼoŦTudy@H3g4cԸV]lX 9K-rPR@WnF3ɢX L:OXeΝ[Y靄.Z~ϙ-d % \3J ԧEp3[Zmyh W3 WDz@_9mUxp0Ihو@nl)9jOћ8oXeOI&0S~TMVÿyH]9v@c;w)⺦BOX2P-]C&וZfiS1("F J0H2E|U{ ojWpBUc.rReƒAOeP+n%Ad;xKw ;ԃ87*P_ l.oy%D2C1gԃ}(~Nxt/@gBH3@E큹;C&Mw(-PMJ0d*d~,"^~ޤQJ:L6[ R1htN_Ng{ u,kɠq8]'A P*"iRJ}>(m+zpwA\4]uRʺ VA߷:c.څ<Und4:uك:FT$م2PVYpX:.^XOȞ (P/T"#s5.$kqo_`_tZ9_۠8^7 j\&AS(P9&x QcT>)ܑs\"4&d5|qv,1>=+F^6a[Q˔qX*4:o*Ѓg+iN4*(َ.D hJpW5tNsIG*biUǰ-`v}:;lڏw.wΔ_gYVA .m @Lv6&)U<;/O Q EZ%,Ҫ}K!en7<j#KD ߮\loK3DW6F.a$lqG\ږ19'`KqnVdsI3 BՋld2LDT"3ltz͝A[O ~>'1؅WWJvZzt9Ui\(:4(|]Nv&d?;gsSWLYm {-X삹@=G),:06xֳe0 LetF}GZFb5:OL3-Y"w>}GBS?^؞ 2AR:_~*ޅ+6B+THW?طq(Mi* coE>٧~HN)zVQڊG(t4X$ a]gMwY}HX콿m g*#rhAs;Ɨ`fEK?ymZ {'i/PjQĨ!dGN2xSehE[?8? 'JkAOSl*`nٱPє1ɪpm. F+R#xcɣ椝m<qk j5_&pp?-u]0I|iN$/Xt]sKo?j!(_j{1 cWnzq!_9}LR آ8:;1ܔL snc .x:lW݉*ax_2J+OW]p=\ض ' -;XAlDLur͍K3D[,j&Y=ğ6XD 6L^x m+/ˆ L6/|nSV!A}86qw`P)ystK5*)Px3}9 nM)Zxιtty ©W5lWA Yسiğ"g!ElТ)w[ 3:j|R*GI{F_>QI48i=/L;wlgMwmȕo/y? ȝN,'# zMڈ{slmK\Š~z\k)O#/3b~@cbe"- vD `y)OgA3S- Pu06.ʑaO$ YזއL{-O Ia(dM-q{!B1k7Ǽe#Ux61P%ZSc@Hx} %7UZHh@Qa#1kˉaW2L}siJDY#CNocC@)]FƃUZ_bAhrVyD-Ґ}w8,[I8n%RsсV&$&=ҲMxiΖ SQLErfHfMzXUw }%(EQl~$-""pU7}GRrɤM;SppIXd,dm5  #A.™=Z l#>'aTVɆ9g,43+eօx+ 1rؠW Kmou{"4goJlb`3Gb3)2"a*B~4)f3 \yd4"A:{PQTN!Q Oz҆0(W$K_٨&$7Ք.W#m6y]M6!zjc?x L x1Yd=G.b'4ʗ{UTcqvW l͆aBD8%JqM]#*Mn`|o|l> ρ^VG{|S N Bk'-_*#kѲ(Bb.16d2+U4QD~{'#ѵ.G]M[D'W@\K;̈́3(uڞ駏=52qDӠJDk5$2GeL@4}L5Bt tb̏oV&'{>&30:ԋ tê~*2k_usцMRidV\ה ;/#.e7= g1T$݉*sv~>4W U!b'JZ$CE&4+.UwBgJbt+:E#]LGӎzxh3a㕙> MwҼSą!z%G& 0;Qvc CK`Lv ID0zt*N".YUuz#2T+ƈ:oD WpOQ?E*C?g|G`LMUhjT 9L)9ևm}gNlO P${'y65'D_Ƥ7OK)) V@G__UșcϠ"Q8r^vE+hx!jg4CM3t/ 8U4|J`zbxy,&a(D\NUFW> SW/2^d3"C) aep>Q3Rd-hF0D2)]-)EBdHokV1мM##ʠ]A0ok |73ڿB2fhR W6;%ǥ>_6pG%,'7 ^R3gTkF&^onV@SM(g+[|M@Ki~"x9/tл!Pǒ3:hg*bŐKh} [)9znUa XF|j+a},];ya4M-6AѠBbGتDo#vZ[,-Fn?cl`9aan/r3p~ytRo!PԛkOUV4]-k…/ƅŻ^UL¿o9Ό8iBT>o.DPXLXx0ĢNFOqIǿ9:ퟃtk](6MXu"0BlD\Q3SZy7@68oMbP2-f:i1?,MQh8{2qeﯞ'O"P瘄W9*%Ҹ DZARGI ajSH 8˲\ 0hp;/cqYާYơ3d/EN'rÄ`2àQbx?iIĘYe.!lˎ:/gXdE'6f'{ x^(č,;VY9 =^TG8BҾNώu  j'^tƦ+Ue̷ٞ(<&@* U#kΐA{lF *#JG\n$vx_IZѫOBkYs=.p++#|#S)4Ϙ=z2&l5zᡱ&pH6dC;X R:7>vs9F _D!m|E\Hw鬸34g s?-}ܫv5uRމg a< ju}5Ae|yhgca!~_HQQ육Z6 5z~";lp6s1zоm2b j[2,^oV`U^t\K"xsvwރ" -zn-)frteyEք5A5xS%[Z"/ UW/r%`͉>4'~rej:H_m5PtWȎH ÍS+OE7fK}z1E7SES_ͻ3g_u{j᤼?TE;{ZayV,u<"S#\/y[B'SDD9k=N/) 1侎_:K1`QU-زvT̄lyjޝPu$KJuaD'❄qrcbv_vs"?{eaV 5 I.>5-+˼E8 ~-aqODI©s5Q?J.I}deY>b3SQP}'so#b&^g%E|09Nw4@6^!HlQ6Z޸~e c'MKuy[c%LX>ۜ!?~7`1+ޑNWYsSș\*-U/ F4XjeOfac=Bs[\ceᾯbjf)u.bQl9zc4a}RJSiEwBYj՛@By|؂HsHlU4„g8gmyUvLaw]}1}5Fh>9w9Ղ' :Wb1RPC{]n,,`E'ݛٯVa(|ɪfrU5lk1:P)7UC0ӲWhI{/Ln|X {V(*ȩ1.Bǟ,FZXw/νBd Ѭn#!"$eVk7c ~B]<损c!L QX r0w,mLUExvp# ~J J =Ќ#19Qw[sø")踩Ţ*}X{<ƣصyoIwA%&s89}:~X܀o7OhECMqjbNj)YL^v\;/ɷsG,/Lqk! 20tT1,Ӫ]JD[v&E[9" _ܥ n뢕hx "x|# gCsi^=hcԁb?쿺hK0P5l R,mb2MK$|Nnw23x˚\ Asp_ ܬyhrZ_Ę 8W>a?@ 6}VlȌdSSNu7rT #l$Zx6N;(@cdW|VxO 1hppFDF Ai+$HȜ-4,iⓅBzOLk.,~̝OK9@-<;:9XYh&O$f@r0#+nCiӹ $hJe&Sz@6YB-!{h9$d%m?-n\'.a&6{3Z[bҿthTk߾wSޤ2;GԚc%s\g_uk8-ԖVyEhQJx;F. Ib&/WЊ:߱Le4mZ2UENg̱lCg?4:$#7­(E i+?~'3P2nll~jܽWݡ;6ȀFKLJ EYYdYcEqx3&omen)/FF띚v>vJ0NPC; όvmj;%kGc71$YLU2Y K o hS'; T L:Kp՟Ǽh.w%w^/gmF%J0?WH +53tpg[!)%gHqrw+\%I0Txכͺ(5J9$PdqysSXW)Z6H){fep?\wŨOLAX(:ㄵ n3}ij(NB&Ϋ AF9]T+I+p-N[*aLޅ!#lYYK{]Ix)nh8G (%>YSarK kW7P~7Da~ tA( 6VpT gg"!`^+{ǫH8O-LPܹ +9ّTI֚0ɋkw$_mȟ+_[z@/Lu?$*"xK9Bejn$O501}w~Rp$iͽtʛNPb?7kӁXÙ^x܄"@ Gt)@"~>NQ5u4@Ol5fb:H4):ӢPJ#o Bg}g񇴜JJ,%͸t0 wjLYtacyL$3pkcB-|O,I_7ڔ!^d;pSKp]uC+b+3^7PR? |fT%ն8 UCɋ04m nJ?9nѳ ZJ N_b't?i^X >Y@@D&M#W)i(o{;˩݇M$$ xE"bgb<:csth}X&҇QoC\`JOy(;`\@~ a '&u:K0LM,dyB~L\ۈ0dL@ W+l`+`K,JZlr-GιC[}><} G.i%iعӰk'xZ:1mCݫ}%#r\ 4  \'WY@e&0I=gБA1 6?ʅ5|VbaE kYγձgxU!gT#D (ThKќM6 eg{6rB|%T%Mvi̝3]}1>mKlQi.\T_ij?xE#vs_3g)oP,Yʺ*O\?sh.ۚ3ˍ@}jF>%!G*D8*3+x{?cV #%YYuXg\@F#CM0jq6%l ^cE0!gJ}aWuC 3ͮCp))akl * ^Fǧ=!!%ˤ B4(J/Wx?Є] \GGb4&Xm *ɺNA=8{B 9e =D 7as[rC)ڄs&%ICbc(ˋĵo.Q=zW4F\GkP(DY<2q& !I=W~S\+G(2mqQn|4sc\<*9{sR/k\v抒6axlꮡAW*$`!bh-.6M2˄5k`x.!Z]*jBP⺤(so&GcE BO,:;ʷx' ƣ+*c>1L,M m{ k1\0l cY_ fRYha5AAI IKuZ2@uX=eL0_|G<)/KOH~vb m]b4RuȂݱѿ1fQI.| `٥uA"Eb/Ye,-ehGNϬl{ {ρqöm3آ4?*1em$PPk"6ڜADqwKJt7"`fKVz5*9ۿ ڒԸp |,)Go-Ž3|qMM]Ůd|D*tdTmP 83{)o$BV* XdV0I=R7d?n`kP 8mݕVB1iZ$*xPDŽH( q,:(~9?i82>{I%Aa -x@+J ̮yrPb@o޸`W5]D)At rۻ A_U*Fk%*FRx;>o1ūvA,m~14FA<3rWK0)E]D\K{\;{vAM(yYU]m>&Q‹E?{1q& 5fad7KAzL]>GxQ#Aljk  ʲn|5<1ro7hOWf4 2dM6ݳ*rX @B,K@HxE8Վ)30$DĖ† y~v?l&̎)$<@vJTrߧz9fTS0(@Xǐ*j2 Z7Is@"Q209&(ŃAK;bw_GGwAˁfXQ[-l<s9)y 0(VIYu[d׺4(~BIuo~oH*/p5 a,c]g@I@#t1 rVx55$1s":Ajmч[[߿ۊ켽cnrX_+i8w|"cDb@>Ap¯{_3U m}kR޵$d(4)dF`fJ8<7&Z;of/OPrP^\QPfRj_5E|F'Ş ==_IRird:i)Й\F Fpak0Vc FGT $ Utvrcoy̌ײv,fm=) O`]*NRyKu1cd,Fҹ_&T V;v5ilQ}F~[S:6 k\T ^i ޤNp)7 Wr#Sb) 7_k,.d/j)g $1iQ xkyM coX?=N/GӣK2?gJtq=)~Z#>W9%VtJ:.AxS[Hv( NЊ$e/΅3pċB9Կu'573x]P :חjЃo3Tj?fe;4Pxo??ʓg[{(mg2г8*bi>";ZBbqqMsWӨ:·|jƸ+pn[z- VF}V]3607q( )ڄ?n/7޴-4q{I{l jW6D'Q,FX ZdËK 0p}՗'GZ&dS}M *·&LMGKlwu2x.`MX9}~.'4$% : zU,[&LU|Ph= MF׀v5/a;pMwbKK[8}A=VɲnؒV'6{M< >lr"GR!yVS5% >"S(탾>FRw-(nϑr5Ee^IGN '_Cf2,fR1븅NdW7 5|֟%.NM* @Aq D>US|U/|=سL tw96(S"qQh= p]S9Nn/DM Eߓs'S0{""8!EAmu$tkP{9 ^2{AVXct2aJ9:T p,l6 V=fALKak@-[FއVJ`Na"ň'bX$ 5)Ҋ*%JZ=Iٰ6o8zr)ˎɽuZ`)BΏ},%TuxrqA۵fTD+%tG5b ? 4=,/ \'9*&bj J^fpPzZx|u+ngAyFC ST\t]wZf) iW7& nj׷Dsx cqK_:[!mZ?RrK\U 1lRܜKVpyTV.:PP1p^pF r#3DэLI4 ?!_ 8Q(r M;% "ԋ$Ri< ?Uqz 9%tB3c]4*85Y {Brؖu.%DZ&"S;saIFѳ)!I8bq*tGQ3шC^N~ã8">P]ޗ_clw#AcqR<VSBM=ir'="&ctXPrͶp &rZ&t!0 fj J`K>5td(-ܔ@ /nZK%6H)04nommydz`:3G&"1Ԭb{z 70))ѷ_Hu|\dÙ~}zFDz{3L'kv*pn5fΏn {PlͶvR=YqCmtNQӚsӤJc{D*I^v8%26tOiV 4AeArn4|ڲ,(4͒*t\A˄deMjN|ac\!ӄȾOk08Md$WJ|qiFrY RHipP 3,fMIc>^}x$q%=F:X褡 :lGr'K*.!o M\ڣj=+ hZ 6w]}euYG6П/k;O'NgO?/ fwEF%McQ)E( "0WH׀Sd[!P8J\02 3%2a?`A wOV(8g4yVh{#N`HpPSúk4jZn  z\ЃSDnba I#p($ֽ֬bFi' ?|nQtcr(cأJt 4% -[V`X6?ɽ a"'uBLwQh;YQak79yzKЎ:2JRLI>+vdy]U-/ v"3 \'/OUif`'Jx43 sƎD)"Dj Dw#f νb9&^Z&>C-@8O`8(T"R8r)4ؿ9h{%ftԼTɊATvryt .//~&|t'8)%۸~] O6KH<,A>j\ώMU4 !XBq ~R~1K "f[|GbI''k$ =,|D5 ÇPoc>E60`~詭x>Z n%#nUGe%JɅ|\t8|@" uEL7R>;е5`4@1blT^.ZI#Z*kMG}D)Z-gf ^ |k`T 4@A1{sy>$hÇRYa΃)Ziyygw}.ui~`(p=E Y8yHmQ0vhpJ(0Np%E rY_4QMiY Ĕ\YkOW0 ɼ.Alҝu~:+JnQCj/_U[KG+ⴛʉK06TժyDzBwڄ7f)^E?rdQpp1R`"o ɲe?,i®_tR8]rs:{C\7v o0707010000000a000081a400000000000000000000000160e00d2100003db8000000000000000000000000000000000000002500000000./usr/share/man/sv/man5/sssd-ad.5.gz[rFϧV%Dԗ$]mҎֲ"9L)UhAA7f W (Yhjw=so7?uoXu:h_ff1{"_6ZT"Ƭt(<NwDcoT2ih^:} \ m\)Z'rFa Np硞&{!I;:~ztz|zy'\:giFӹXZ%&J!sTk2 sZ? HrpxB79+}bïg|÷<ʟDO͢D .X(̭&qG(ΐ<ԇD29Lw~zma̦hfY:An-ux|||{,I#%a(-/C[gW~TCjeDf2c$|)HIv5W$gl&w76,bOtA?RKQ"$o@ďwݳ bԿ; A_鱦"/OZĸma;52ы254ݎ۱Z_og/. Z=$J!Q DEa2 Y+(ע2.t{Dq^(`W5!PF7x")Z1˓@|?U- =VSq9[lP΃&%f\K, /Y ~GjQ0T(T SZ<~Jvb6 MLfHrBnNDZvȕ V]7,sY2ђ'If-f*)V_UD}cj$ͧ͡`!܂%`fNcYSp%XX6VYユ D 0B.znO.o2kd\|2m1IA<*ڈ$B=">DZ֋8r_.yi~5|>{!N5lTt +6n"`:WrIb QaNq̳wpGWfHen$S?ũD"dCʳk 0BqS&*!yIN^c~yW]JE|q̧(x]~*Is]BW({P .RʆeXfQUS9Yț]Qb9U5d"aD7$[™91+qLOiwKCdBt6rr2X]'ֲ^jܦB[-́3,9  LxLZl-eILE43DNhHqxU?† Vk'u|dKO%ˋgo2./Qpm}3Tl;da-Aw3bG7P; ,WUD"*SOSMVv0AC|}*..eb8u/ցh$hxrX˘:8Vrν`_PS$B>HvIָ{ģ{3X!o:X'rWJ# zj; p${B_!|8DKQq rPi|cO⏙ M:zhh݆omP3|!?) BQ*QA:;:eRO'u(P+ȤRRk}TH-e M+1!dUzXf~J>$n}`;G相\tX'W$ܪie3j?Ma*o nHj6SgwZŝCJ(հF*¬|WԬ,rC xz[Bmra/mr\t]t^QqRXEn>;3ȢW㖕N*R!Z2eBFV;a9P%4yE~NnsN; \dk8&s:`5]$ u sW{[g~ 9G [Ns4; G"Ԕ:!vN0)1~<}[??;zȷʶYw[w*(8sڐ4iLtNs1]X@ ԚrFvHĸ{r,tp=b ڕ[!Gcq &vOjO8W?g/z7C% t _0 ƺ}::y7>PGld3AabBp:`>[#uqtwi-Ta ~>X6PJ}p1L\lrtfZ[DZ~`Y|Rq^>ʾI?j9Q4y!%Ń4fiE?8i"A yocy*|)[;_n1w~d{e.2m`R5_ЊK*`_*j*_c{QE]QWd"ujQiU6^'<+2A~iv5ӬwЕ0gڈ!(oygK+'a\>Ս*י%-` ڲQ'*a`숄ʩzAŁH:^bG!ærp mIy=<q{zSqhU"mj"eF@A4mr7"B5cF{9~xj &6z%'ó+A7ç9Yg^NĬԭ2NtM:{2$#yj+at^?uc6+NyAv.a5osW۫SWpRYG nmɱ/@Gȵ_V'Yڹ."/S@ (M&o%0\ha3ITv 9nkn^[Ep9lG_ANrmjʣg֫Xnw,-\{G'њsQ{^>~SE-)qMxyVejb{~z~ZWxG&E ꂛDwVe[|F4[ *>HIL'e)y?Y8$%Hni<']AϊPSnXƲ:qed΅v'i*[h!z,_42pFʂ835蟏_yTἺt^Q3k-_SѐRJy.0Py?;f4RVw@N)7>ut\z}omfT2sbLK2 mcl"#tm4v"4_w Ch9j J:'!roJ/)d"Sth)pK |}d h{h?a/p"]k [f~ :ښ~[wYW[$64C %v_T͟<9#B>X$')Q'GN: jW܃ wU>re,S]S@0=1Ю3 L?d{g}<ɔ e{3{ݔO(1݌'wְ|Xb{{k[rAvi澪/0&E(-1jL}^3{y==TsRvUt^=O/faD/AVLp+kN+)T! }DmCt =M,JZ]o2C\eh*)W.HmI){g\qT ,m,Eَ8|}7n#W|zmbk_N TqG/< d@CD[;ʳrҊUJ ͑Z aowAؾ۪+I}Kܨ.UY]uݰ xBCPĘ2P$SJ[`p[]拂?k47+4=VU:՗%VUt">ïCƱ}*Kߪ=$pa=f-rv{7`|Oҿt:7*'z=# w`=ZᏰ֔ %7͸}پ߉='H4?}}NVNn= 7^eq[eh؅/7qWG_a(3ۙL(gB&G1&TÆ;#g޵.m%~ keψd9vSZRlmdI%ҞR*%$@ZW'B^/udǛs?}D;'CQ&w|5zEdv¯XIWwjEr|T&󬾎iMSdG2bDkn%Nmuc8??jA|X~bVVYZekw^q=Yak/3a+l_{H9Xm<.]jUj7+oGC,{P>GۡsxY}1^ ywQYp5,k.И*er8 2 8UHAD ˇiF|]lIڬ2bfio, ~(X]o/bwr5mqȵGZ`A_vےǧ `:ډ`z愐nYɾ3Q/nS .wd4Ec'/cA^W9|&8>mEҝJ^b#&:Xr~ "]ӷY'H4ߚuΙb7#XdHk:^ mlp= !AoЙ1"9IWɧC9_mx%P9eo\Lωb0WJEx>ZϦ ]f58Pg.q(ŪMy=&Nw#.E*ju ,R}nizv|q}ffh(BA;c*-f2S؊E^ HO#mL i;C.&S\ !m!g0$Ⱦ@\dK,Rc$48 @-_1ẅ!4gˌ t|L Z ;[]4kLC<=/uu3D$J5Q_&oĊ;&Dyː-{y e,  -_ ˆ˘1Ȥ1-h&h4'R!iYSI_Fη- fH9Y36>\0*2^/re~g_nE?S,[09|nn+QxֆDr`؍x;pŗ'lj0t|5I}SI\sDey+.-^4H਽f)*(k@11!W_>H ػ Cvo|TPJl|Y@5Y%Ib*]/ ((&Z( IvH;Y2Cizu>TDnJySh̓^hձJB^CzG8d42eʉ?2kz8˟&bTȜOOm]qT_f,Ւ `يw4uEYFT:Dv1. :6O=UeW*3twi0G[ ,ψ;/֕KJF+wb4E<3$^}>FZYM^E )*QxsR\<1K/lʙ $Im6 LcĈBs_5L ?O W# qa4{g㷇{_hp}`;؏f7oӨ|4\eH*21('\e Խ΁Ϋ~WДaTZ,?A0/d#|4oO 3 e#=>3 F\(rVT:pxoإ*hpձY*e}4+eJ#tX%XLLL{b>t]cF( C8|N_fA$vuX,Ӎ(Y_v *-`a H+*fǺܠtRDF]͠O2+@JUu |b)uB$ts{)z) VGK9XƺsϖIt\gr\AI6^4AsT-J@9'N!pH&>1I7d܎y-"n u )҂ 7UDj=[Qm41)6U/lu`F ^\j f+%1OuVܭtoUeW?1ft!/ acRT*HmѸd۠ThA7Nt$-T"jQ4]I]7[VkOnhʜfSsRL_W?7`xȠkRG=9wRlcZ q_ȶX5Abh0β?BsᒀcZgRò]X2UE(o{,5-;Kɲ:]u:`M"tk)uZI|;٨0ǀe&~!FNO/79JLL]r0>WZɄKnE. xX7AВeA8kߘc2!zkT"C6lY,%oK,TGKꥑ>X<=v*ޚ*XZ Xc?p ! 3`}a1?i] ~HNӮ௵@o%C}+(yfU:8P> *T-baP:CaBb:tM>&9[H։%,kgP>U-5gdo]&I'8ѵR`ՇJi`nDV)Ef̕>]Q1gS![nP~G%H+`.y P i<)`LZiĉ1br|Ѱjǡu\ wZIqnWAy>[c;$?'A>hPv|s >bXaLgIwS˭.abӸr]"ĵ=[AβxsPkڔ̼Jߑ}#b$7FpA8]]4nM{d`aB"89B2 fqB%;2nHؤwZjTFI<&DTO#~( nҖ#Gg~}N{bU~N}^wܔ~e#}H~˔1cR gR &^RKDߏ{A3oݍ<_xխ[rqi+,njDt';@ X#eOgwg0Njz>K9 2tL.VԛqrUε73:vt$=Wse=>L }H`D*Şlld%+pCfnÚFw8\`% pL6&VŰZh|82Z_^klrTܚup<9i3 =Eed EE`'Z*RSP8i-Ί:0c׫nV>ă[0& Ѥ$Pk#K$  w| F{8yS-IRTo k+UN@JHZ~f0/)`_N*:V7DK PKkWr7߆EqE]H _;!?\G\ɤɲj|$uRtGbAA ٘(=\Q(i@'ܴ\AOT `g.·(|"3r&3߰V-LZY!ت fڲm6U-ޛ~Vє} [t渥D98 l'Y衙#m,*rOb1͙.sm6] h:m _[vmP$gx; znnlA ~)Siy pS%beR\{ m} Tױ:廸ҼLڙBÓU΋`\I@Lb[rHDIƁl ɔ]|12Kl\9qyi$[ں6Li8Y h=w&]SB6(Qd4Wa|8jZ6Ԃ}-xn;soDS÷ cH;_J\.6y}!>3W!3BÈH6$ +1č?(TmN" qq>N]N]*8D7M}1L+V[Z`lنj "(ߢpXkcVdIjn@]Tl)gǓMut_6hN95{6X'u.S{H3҄Hɗޓ`s;'.TFinq.&@񨜐BHd&d1cǝ=U;~*1.aEuޯ$g_=tRovON^IxϗZꢩ4IØ4ǫc фDެ0FB'g{-숐Xr1a@x8aH(ӘSFSZ}-ֿğGl%bWITYr Fab᭾azjW "%k lR[197FmԒf=W_1,`5ܝ]̼V/j!21)zZ,zď[u;{{B9So`  S7c):H-Gg x|Dܿ%K[ĈWN4:**0lNJ<A" GgEuՌy ^U%(4+1%QS#"1xZ.V5߾w_^g4.fBڙƁx^cvo#X\przK0u8QIl|CԹa\ .̠HD 'v/?/..Ӵ35O5VhYf{uR4X p a Ɩe22COdZid٬ }#\ި5ύ;l{}1,]:P.+b 08"WlYH=ݩ!˜ț7-rE|ȅtvg%9xu+Xؘnj8kx1[MyT}B''YA\:V0z~\LV2 \l9A&wbf2.wDN#y|f5&8[Hٛ$@CFf0TUSJ̽CvxxM~n e h.4ꅐ҈Q)'Kk.qFt( =GW1‘,LfbETgn<,)ۂob`B>2(Sz$QV;V:-iȸy_b)kmMPyAE佰@b-f50jpC}|TYp?'?!"{roeD#!9KٝdDSYqڶ΢s+R/q#܄-( Ƈ{M)p8=Tv.@8ؕWc["m:=Rx_9T^^yCGk)(p0u8fph T]Hu}m<2+!$E\WR|$RX+x# s{p r>H`"%?Ő^ 268rM͈ q=$X b>~֜.d: YBҪ?}*Z,˟,Yrs%)Zsn:PUD9K`}% ABMt[rkmJb:l^AZݥZ1qWSzrC԰TXx' 5Nl͢(WA[[q[9؊^4K[`"* wx|AܬJ63y\*lfQI,y?m<=ytγz;Oll?yBooo=e>8|[B~&tC50%bxA٧&ķ I/dzVhQM_o,gu&>r+!KFb7~54fQD`t,W] }^OW ֽ"bV$urW0N ${mE|__tuAMec?i1ۋ+K11{6c9TE2ίI yiE(y3Kz_$A5[ ^Y/}`i2>bt:@az^}Fu6 _Ma빠Xi 4UVc#ř5+M|[J$p*?4 6 D-3@`9|gY5&R?M5PnR2G~ױg0= LVz?Y5d[AEwu bajcuz $֌%$"Wxi`eAطG$g&S YǧS ?8TJY/HS;"Xbs+!.yےVvTF?&8~ @.n>dBdGM;g}gFSD%7".3+ff쌍MPA}7$R!7}Oj0%2糢E_{۔Ce"ՌOA-݊ jV\L&vQ^ -$C,&uj| 5-b6Tucnϔ]+2߾g4CS]Ї:TeG݆|HYҠ U`)fج6 Q~%ӹ vסPJ rץ֥Cec|O gy1;3XX_v{@ BTbɎFoO<~ý㗻<vt4JRۃDIōC0BڨshѤJ7)Z"3+dAlOefNJ8 05-OT(ӹMe_,dɻ{悬sYG.H1qHUPa&XpEg%pq!pF Wi\s|W%c4J_&y!DժK/+=g6:r>b%R-!k[hv׭RU=tﲮ͋\ $oM4ɞVC /M78YLJ~fU1FeQ{KޢڜfC̫㝝ϾSyV0707010000000b000081a400000000000000000000000160e00d2200004f59000000000000000000000000000000000000002500000000./usr/share/man/uk/man5/sssd-ad.5.gz}isǕw  $sW 0' ]]ݒ8A")G(HYK݇c1n@/4;2eVVw$Mw?;Fr4-%xZ7OG/vzw'=[=m}`3Fjj5ǎ5v39Zώp7ZҌ[0TZ~9̹huIJwZHpjR<.%c [j/8yĉqW&명n:{B>uz{OVD֮6_E50,kKxI=;S[ex9u$:rJ9B#8$J˵$J$jԛx\)Dix3gG#_h/GKB97xO7!ңK6~7wc˭jR`g'Uӥ'grF.EGKi4oF&BKziҊJbܮzZNQ*B%4Z*k#GkgnbFq D}W=$7ʵ^\9ʁ /̞0NNDo>䠦Q3GF6FsQsEVԵ([Svz;{w"qsF4Yl)<ͤ!0dW?Qҥ@Jo*8ڻx*«~]ajk8SVhއ{բصl׀6DjXs54̧)xdkW~t4'>V+ـ|/Q;h:QڅZгw-wXXmU} {9-̍QW>} 4޿>}>,:C~b;sR/wSHpFzo݁!BIQӯݕ{3)@PI7[N^fC9]upaIf0q~(o;AK2PBJHX Y`ʵ&(>ݻm YCHw>pnDla=".ј/: cCh+ cv֌ $Qk< f]}5p k2P&#e1R]Fs%C|s3} tV>W~~h77¤`C9}!N5"Jqxe"dHF`4mcl ɣ^qU_L5sա2kp.)0L TEo\᪂b+rZ|Y\J%8cb1IS|d>. K|/VPZNBpd>@);>KX~ A̽kEgŕ<  %.VlF~Fcu}ޟ#njx'x^?>%Q?q3QI3G><]jED漅B/Jy5 (q;,Titq/ ,C4p 58;؄1GŨős:r8Dv^!t5n4ʵ荸&#ob }] kaE,g\ Å@F1mKS `5IK!o'ΰ`b嶷"|]:JN:Y p B z'4+}?& 5Rhv'DMHL.#mt"O| %ɑnu<%-]]<$-MÃmGrT B TK pOY}pSj ?kYz Gڮí0M5=JK S+d~L[HnŞJX8uW蓻$ۏ!.pu]'b >f5K\^rnjܷ2"\]qE NKRFgË`?ouzVY`w5 ſ& H3cA?#GJpX |I85}VR=u7ՀK£j\ íw8cA}7Kj\Ejw1dA.xCtjDRLXO3 d^Dr=w R8^GMHg'nQCǀWl|͈:UZh׶]7Hqޑ‡AAvwQ00օً3|3ؐ& {&5}jM 纰5H !h[~Վ1Yc*0J}5UĦgtV%J[/J.M9?mڭv!E;HfAk4M.D٭YGO䬙wU2ƈa$ :H@~MB.$uI(hEfCLMKd #CFiQ[}t%S0oln8󇂾ί;r_Orpr?\?_i(Cփ\(ۤN|Hv) :xrm@ y Ydl5 Dc:F1\ClO|n&xn- qcSĘY\x]p7ܭllq83D] ({0"25Ȋ |\we̵"cZG7)>&4|<93H`Eapw2Cpfbʑ=lV5C`>Op*=6\HbvzZZǚSZsY_/y"Ng=ҟFce|f6gҤmఁ5d.$o9H ^e#86g{uBhB(`ʮc<NjCwYۡ۸z }kH8MJ@I<&{`>zkBqDL#_)6PF4t0 )kl LLo̞4gl\-Dq"CݎY/ĕWKc.J&X4F)nޘ-^>쟬 `#lR۶DQiωSxm:lMb2wMtغ̃B8zK 0qL+ sx4d#^9a'^B[Ӊ?+#$mDGKщ'$. u rz'&G eHfϾɩK/1/rFJ&ؘKJx3a3( *"Pn_?333fb\tMFǺIRv4S/vB(G^1P"%ǒ_rjEX)bM䲖&o#LtJ?NC\^@dޜp,eaB S WuE[D< Vw1JIm,kKcR1 Dɫ3悰 sȄL7d2jЋ4[6;Hy2#iF lbonPłU@ѕdtZS!O M #á4JRNɮdN\ke؜kJE1f#`?x,|=TF2#Pki\k{QbpVz&y+yPG$E0R;M=KZu15S~DKNڵ&U-;OhH찖CG1h]+Bܔ袈vB 3Ϝ]lUꘈ]o2dWmHuP -|+yq) L#U^8!T7Lj}k<  }HN;Je`s2doWs Tl kۢƤ1x3|%bmcvb2(̿! t U0&0rH'B$QaBNP6Qn͗ڕatZ?oC\H&!NPD3eO;?sT5ߠX"WXݑXj.*3: =:2: \8Zβ^jf2߮5 R]J^;Z G[7'x/g\@ 2wa)jpCJ,ypB<2xuP&WߴN7#\7tkw%]`d8krTMƚ)UKnn_aZOԓs4m@9n 1̀&)^Ma2@1deq1mB~䀛OK\ Gƅ<^>%BR40 ]jX&;LआWګ0p,);"l-xLm?gQB =[!dRSF7#AmNT+<)ץZ^ g+.Y2̖cE]ab#G|f䲁MvP+܈ 3[ ?2auϨܦ.~>7g)6\5uTn73|Ke3|pTu ا*t&mqWXW\Lplۆ\S1c\<|8hHT|5h 1ljtk!GarZ t/7 ( +~<@&v5ӻIp n@ 3)6eEEG(^^n Pza.Vì].˥@@ ZύVpzR/7ʭ~*J-i)]s%$Ym$stF{JG=PF?D\uI;[c*.$4bEX鶶 =uU:P 4*֫6Xl֫l>Z uUfeϵwc;P:4+F%h&.U\~cX5HV?/\k):Yq!4ðS4Æsv~Pgby<КivkiG ]_B{x9w"0s]-(6뵿o}P-@a v6g5u ? ڿ]JWѰ+[8\.*Zruy,<OWDk4 gdLU;]178MZ.e6Z^\7Z _U.&u:ghJ_Y{G:۽+ƽ>e[uoXW'p]mr־ 97']ږq IDk6ELgպy#:IPC#̍&q=[FPui،}+_T xElpW╗^8hċ\1In+) nb1; [DP^i dojYorvk 9$R.i2_)ōtX{j{'I˦ʮ|gŇoV q%z=n<҉WL8M흅D/|iƌE;ATS#i`]| Cd OPކ]f>:N~LΜ;䥳Zҏg.]8]:ڋ4#%BTԽb5p '8F1K{ikc#]Tpx-ҺZrJ8R 4Qϻ4ϓ[]T.^VwV],u3u z__NjoFo {q.k bK*oz=SRo/U<9oU/cݶW 2C PђB:x8a[\VB+'R ՟qoϭK/ @.XElc~\$LFSZE|ClDDK+vyjA )R9O&DV7)[.IPnjḩ?+R-e]cX {Z kѰQd"uxlg/͍c$rx$nf27[IA #ǧ7XzV_cagHASؿXZ61'~cdW~Ƀ1) :I'pzӼ_4 )?Řܟ. dԃQ6tΜN9;hX׾m-oXQiMz:hfp;" }D*%ͅS .P/Cpժ5Ξ|y Nפ,.7hK5$ݦfd6&ftRWOE x]&LÎAKAQ>xhۏ Ky s%029]4w((蜛Dgm}D$O5ЦUnKDŽO_5D[}87TMmArۧSm0a'595q6Z @80يt 4:iޕ`*#_Bn-i?'|o&JQ^&X7sĽ %Rbc6f2'MlNT-7rH'.i}&}6Kv aCSI{o FA2 ;S:(Hmu6ٳM)^c1ߍ^p6Ui24()Ag +wKDx[Yw7qxnXXۙoj<~b`7bﶽV4;߄:JLeLC5R0JـM_lW<c-0/ }VG}.yC%N<͡kQQ3eJU^5Ԛ[Zvv\)h H`-hcc)E Bm Qo귌]F3D4$cp< NrmWXD#+jDBHZbgZG*"psA{L9 0Pb@F}"gp\)F [L ~J۱YF ^pZZ@4$~G 5@B)UGM̋-nl2YdV]C "go7hw\tش(OV0eS]fd9Jf$)WJq\2,2t /)6Hi]T(({^zEj^u2KxoGki-n*!!1YlKra2*bpc`F(06~mBQ!oܶm#Jb6Ҭ!1cU?'oV$XAأCher&Uh#: (ÞqaLX^,# }pO:&V|(tz-My I˿&XkRRRc2*i!Zr%֓1L!%WWIJxMbss/C^qrf8-]+Y)/e}kC O^xdn ǥ:.侀̦#;ivb#CI"f:FD\CPli-$PEU=W4׈D;\zRB(HsR% D.&m4džQH 1LI5V@v=E% 7R=4el4@ =y8WT,ifָD΁ϣsŒJyoPaCD/{83p!Kjt$ml=B+58 Bh3&TAzWYE;]fX9ʞbZ *lСD5\iikǹ69dErH8nuܩcכ'8P} ?0l+ uҖ3uE;@bb '4{&o>ޗiU6}fym.&Ķ<2XA]5?.G]9`hze!.^J`ɋxXߩ 8 ]^7<րxiZ/ >x"}V 7IPLKQ[6yqEi}lIJ8T$+)EUl"Rvp$h]Q)xi<0ۿH[[O2=^`I!+U {H 6Fo}$`s2lƈ.1@i#n`0>#outjۢ$A&*ۺ$G"Z5E4o"br)*kS8FN5w 1c(Gd辎ϭV+Rs׷ AX"|H >x5W0{}Kt\e-ߠ*k}xÑBvn) r̈۲3ԛb[V WE ec9mPIC'7O< \HLF!Gf6Ru,z3x:tcws4"˴>)TfJӉhK O*GWEUDA6A?-h .fjBж,xP}L{lh'jtXx)83-Xtv,ĶofiFQ}~TIFqT.FB$piNSvEw{ u>|#\,^NHE2c$7w<:\0N 9B&ΖG#P0Jq&0Ve qv2yٻ,Y|i&QTf(C~Ց{l4tP+A&"cʁV D_'>c-JEvYe, '2WJ G`enДƊWbTHa׺$+Rl9̕ukCڥNxrBֺ\T6s/ZYJ8s^4EL*dN0:&93l=K11as$\fVp&K& ۭ5 x&J}wt6[{vKb6~DZ;.y)Im3&KN[hM"S)Dڜk/=lJ :Z8/hX?h[Li06یB9SEre]@/kl 2cU52g9cp.BB fr)i.I3Uϋf; (_ZR$ϤL G-PmH5-Wo4Q5AY#JP2n.%Mh-5%T@kBvYR'C|+#_)HV{c%,JXgbL(:mTU?"]+'4&Q0pd*hADjXQ~6̧wԚ zʺ):H-AݽU޿ۢ^]q(}n װY&gUƩi@m"T1"%~4CS(Hzرa\y2D\l1!&0{NOŧJW: AjlXe1EUȞƿrXHZ荲+Bl難EuEgKBT)4mp9Fpoڶ[%֍1}eNuUX%0VcC5Sx=:+'l zp>ӕ\7r9I/7#ރ?>UV}_Wl*NyCgte !Rz:l]Yk۠HW5СiZ8֮FC홾ldbN%Wk]NH3`-bM:5@Vn:1vLpoI.A_3]㧿BvJ8MD0MHiL VTjY>C)۾RNC,7S) %t)W)&LB{ۧ Rv],RI>)أxK߼YY͌n#Usr*E07 (.ÑfL-k5/[GKʢuȥ9_bY~ß<{QSճn랔䘹`TɲIBJ$[EST_3 GP-p7䉹q@cbZ#gJd 2gw(O3[+'?ZxasLXsC u:a"z[xtzU37**+r27@Xwn>[Ӳlw2q`a;Xv2Gw[Hrݕdس5  M([Ewe _-L]`̷mbbZiz_#5 jۅ>EHbb:؟u"<=϶F3E^H1V! 'قVEW DA}P]u#bp0]l% 39>zSt`G @O'=ͬM~E~cj՗Xkw@1ǼRؠ$[-+\Vȳ&MM{t+ v1p!lCQ0!nuP'&pVYqJ-(/ODNȎH#=$Ô"N]=2 dR}3mJC[(քkJ׏I|<[hmO q]ky=NjE2zTW\[JھuquJ^mm ]1kOաV947%k*n h+ +AZ\ 5j1{G:g\TlKzmw)mTpjRT+qN\2*bZ)9Cp6K[6BJp+ʵ9k6A ␳ׇ-KGakak{h#iZY0e#6}cS\f"Vi 7nR:*~j3$ 9(f(vMhuR. &{N8S*Pn4 Ę*z.nVr&$=p?'!<9s­$fdi"I:P0Z91\TWL$1WHr٢^P-\[}×Քo_.7?[iBL) }C[]߻u7{5G'ޡO-Ԋy.['=t9 Q_4cOd+YY2t E]vT,LхY`9^5Qqɤq/Jen{1@~H,Q^ImF%!KS) ȉ~4ۣ*tZ@K@9!ȺBv8uɏ, e䶍 MЧ Ѭxi&Ыwֆ5Ep$bdIe]\\\RkI(|cm87Ņn;W>z]Dֲ`[W)`C.ft+1 slpW)1x ס@yf\U5{ ٟ& hvҚ/D/LSNͫ9-x>u,T 7mSE {|oX/utD]p7$j}ddm&5G&A>կ] Bu\#mZب=aשV\~fZ a,u<\-lۼ HsE!x2 P`D8 o;M=鳳D}frt#7)iko=7{2B_[5riI6 Ik Kbb -0ύkHrIdb .⻜wq۶ \@-h%CoG:iHT^`;Νyg\($MFy8Tߌm\wSo+ WӐ^_oF4\Tc(:9erA F!"S5۲j ɢ\UlC?܉BNd!"Nƃ- 94a ՛2?nү~MC݊=37#Y-L~> Xwdl,xa2\mMr>+NrMw(Zڨ)ea>pcNL uob]hѐ["9tՌ1R?'NNQԿ1p@q(^g =hp30RaDǏQWg'fgjuT