sssd-ad-2.5.2-2.el8 >  A a@U]]ƮLk bOw:9 3WQ HͳjuG< x0˟yKviIp΂eka«B7 JMQIg#ۻbQ\ NthC\.9U}jŌ%Œ;DrU?ȏ!aSƑ#,ĔО9:g:o)0e#[{ geǖ6gi/EB6$EöCΩd9Oϲ0&{lC')ѹa"ŗp`oܹիQ$U)h,;NL+Iէ[SfloHyQ:;$J>_2 [Ǝ3]~ ١رKwKC O7J!'=_SN˲Ib^HM]L3H>̥YoG'-W3&E^τH^#9e6ba2f3fa838cfb006e1f8fc945527c79d77af30f419a7d2c0af7bf3821f612d4510eacfa545d5506323fef94d38ca63781ff8ba@U]EUkˤ(H˃5/4ezHCH54šJEgD{Μ5G*NܹI:wnW̬[Kk囘>P/'nXҊ/ HūqGu(._P GKEo\h '%b*6qNIs8AөEBH3򗴗@l[+4%aX`IvZMI6S5Caplx5,EH1/M0 бS'IМ]"VBTEGF?* މ.ib<HY4Zu P,*@SOz"odauU;2Y`9pY㵀3pDL;bTpp[=a.cEQ/5Y[ F^VxĔ( .ˇ .範^wsd^ǩVԌ c.(;UN?|vbpߚs ǤZIO`X>pEo ?od   2 3PV`         |    D  D D $D   ( 8 9P:cGfx Hf If XfYf\g ]g@ ^g bhdiejfjlj tj$ ujT vjwl xm ymHNnnnnnnnnno Csssd-ad2.5.22.el8The AD back end of the SSSDProvides the Active Directory back end that the SSSD can utilize to fetch identity data from and authenticate against an Active Directory server.a6aarch64-02.mbox.centos.orgCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxaarch64&'DK8=OAAAA큤a!a!a!a!a!aaa!`aaab79ea9bf84c3eb7ad17ff57c13eab6a5618531d74283623fd6f701d67772aa89049a9b10f3fc7fe8fb940c13f0d8636f10bb073e1a95df48ef23b741afe75f398ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9031a33d73692b2ba7ed1ef7c2c2ecb44c059f092d23bf5464a7533bc8671272fa93dadf7a75e53c09599f603834565a95390be3daf5aa72b9ca79804fd0c61b5f48b8614a0cdb413a578df1335045bd9393c110e90e0e5f22a9530bc2c80a8dab5../../../../usr/libexec/sssd/gpo_child../../../../usr/lib64/sssd/libsss_ad.sorootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.5.2-2.el8.src.rpmlibsss_ad.so()(64bit)sssd-adsssd-ad(aarch-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @ ld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libglib-2.0.so.0()(64bit)libini_config.so.5()(64bit)libini_config.so.5(INI_CONFIG_1.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.1()(64bit)libndr.so.1(NDR_0.0.1)(64bit)libndr.so.1(NDR_0.0.6)(64bit)libndr.so.1(NDR_1.0.0)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libsasl2.so.3()(64bit)libselinux.so.1()(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsss_cert.so()(64bit)libsss_certmaplibsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)samba-client-libssssd-commonsssd-common-pacsssd-krb5-common2.5.2-2.el82.5.2-2.el83.0.4-14.6.0-14.0-15.2-14.14.5-2.el82.5.2-2.el82.5.2-2.el82.5.2-2.el8sssd1.10.0-8.beta24.14.3a@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) svuk2.5.2-2.el82.5.2-2.el8 .build-id228555563ee7527357d5432d6911814f4d5ec00e4f779a1c603158bf3768192668749c193d91d525libsss_ad.sogpo_childsssd-adCOPYINGsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gz/usr/lib//usr/lib/.build-id//usr/lib/.build-id/22//usr/lib/.build-id/4f//usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ad//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnudirectoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4f779a1c603158bf3768192668749c193d91d525, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=228555563ee7527357d5432d6911814f4d5ec00e, strippedASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)77PRRR:RRRRRRR RR7R1R%RRRRR$R3RRR+R2RRRRR4R#R RR R&R8R RR RR"RR)R-RR,R9R6R R.R5R0RRR>RRR RRR(R7R!R.R5R R R RR"RR'R$R9R6RRR>adclibind-utilssssd-winbind-idmap2.5.2-2.el8utf-8ed781619360ed2c20a0244dd1ce7725840fd96f5fe48b99435a737fbf50fd135?7zXZ !#,] b2u jӫ`(y-oC0lʈÝ4~PAkG;JxfvMǣ7tk _I?PRRQ*.}y'Y:覀唔:TjIK@`ZcJ)dJP=ZL DS0 }@e~ғ랲-&nA$!ಁkVI9!abV%Ka$Bg ~-z"5lћ|L^=Y3uNz t!5*!bDYPq|{_k}9rh[Yy@pa˰g'xӥ* AZbʤp$$v 4f>e]msd-ɼ&EL9z*=Hڏǀ^ k6[N%47Hߥ_I6o:aL4IVGYWa`NLCNEI#:QjUO3&p~ )Y)6fWƗK&V͸·vx s*Ip1F^xЛo>@GԠ.ZNty칊{-9 3?}jIfbҵXV*л'jU4z<wK6ˏ߃">n:ZP z5'N0y*5C0L܄ζC*] s/*i.({,*j!X9Q{E)׭kmn~폿^7[LL8wizE%H3+'^ {m$Pz r*aɣu<:"P~Ŷ H!MfNʿH9 `A n $UA&3V:*pjpS"F U҇)# V=mU ~8AgS_uޅYf @TMaEU咧Ӑ.. IOĪf/g|/6vRPX0Qs8H۸-0#q):¿BݑyQH9L}Au'j_,vKGQI7Վgk33ՑC'@Ǔw6?鏏&O62ޥTTPM?*(:d_gA2> JM7KBH7OnߪAcވ d! T9_E5$5WfڀZ-Si4*qFuUe`p"4WNLnOD w>u &oϱTF5mxv\ T€\>{w" Xv+Ľx2`ס;2\;?&S:3T_mNC:OtjO(:ۦ ڜ$ m*@Ǘ(R2`,viT.TW]w^_y44`߬/9$HϬ&Q7gH)Dݞg\)ZBs>(sVD˭c_vb3us^/'pJ?ΗnJaE20=^b b6~ZWʟ[_ѨktJ1=ea#h˚k74ףSD/E@?Ag[Hajp0ٯ{: :k)OLCWk-S+B*}fIs\o6t]֖PM%A)tN ;f[-LZYah5LwC2ţcDB [{|JPƧZ!lq6SWgVۚ߮R4U?I ^#; J@mSk$S5e8x>׷0fB?2gTx=Rj٘Em5ʮW-K)? [},\)P:/Rx~P[݃#x]Ił|V!&WZh^76&#p6yXk)@UmJ +흰$QL$)Jz}]M[v:Z.4 ZCH -e @z5d}mO>G0IuvusҲ& \DN.ʙb ~%M'!B&4jd_L !SDI$gfM?fWV,Ւr~$:, !coǫziQmn>xqap>hmJI˃W9;(S llIxƨCda505 XSXՖE#m׿B}UPI8t*dNYKQ`)^[m@0qvN OSΨ4ۈ@U,X%g,E+fsRӄʷ PW[ANiJsf$E `xl It"cF9vi#䐁ssXTTOgkk@٪)FolU$@D^Q$ފQMM_Ξ_fr+b@?٫Hi %O *3SR덫װWwۼΊ_u< 8,o#t>i1$=W2sQy{t=DŽ1y*c,%@cx2ʜMƙ~?:Ir^tr~Ч3@ʕ;eu' !\(i qL)!HcN ?cFA!0f3V<%*q_itfPwꥸVs!|\iѩyН=?H hj`r5P'k4iSH}nZ oUR UwEqӥ6ٵP.6}*ЋxS"~X#Ei?*Ipʆ\F; 1xP`(!LD݊rAT䭀lW˩:C(geʬى]fb#F"p(`𲻒|%G]>?z0|gUs }3-!~Ye: J_G ?BVPx,w#Jk8O7.zk|Hܬ͟RgbHrOm~?_ml~K?aC!(rIQ--GӧH$R&$JnD ^G !aܼghl2G_UeK]87`byڜ}d;9fx)llbnc0F5 #!;MKc̵r0Gwx7{N!?5Xx?>̭}o3~xQ;Л,0!eS->ə8jÁ,4~#LtC(>@-{ր5_a\ܦrhKKLErqWC%ΖHށHn.HCa8E@?xskj$jԵzk|vDŶt.?i=.NU; Q~:S="4xD-sg#dbۯuomPϻB0-4wO8(]>`I)[F.j!:ѠĉnfC9(fȬt*&7Md^G,fh'!LIBcEkKYtyYU/HQM(:dG9<ohP xptnDq6jxqg ҺSzTRq>!tb&g,^]^|fJ4ƶaPM)*jRI5C+Zd \Us3ei<:'aJIKwɅ[ *ew2nGpi?ѩ|"2)2w"^Vì$աxHeˈ:L(tM^':1i+_II6P, XoB"*S3A)/T(:m6|(&3aCmz?5I \@ghʄAt߻T=~'D5S'$NG{YPW}8]mԑq$u0U+wKš[= 3}Z-Ư%6kE^TS_< ߴҎOLԿXiMsq ~$'@DりٲAt撅?(gxLDeSF:0;^\F0W)*F`ԣ0еsS320.W%QT wI -B{Ec暓YǑ79o^ jz4nUBcQ**I>RR J ?T%-tȽy=ndeCRjIL:H6z*j{bR$i[6l?;'R "ǐrz4@)֖fգ}I:ˢ5(T$oi}W#MD/LjD&写\`u!*gDB/Ľ]_C;hǡ +< >֣(]0fD܉.jϏ?UeT.D"(6J=`!P5<X}tWGnDz75ٕDf=W uȓ9|YFA0KؤCQD<P3s쿁>ZR֟;>f-% mRKtWJ܄":]ZNB&m*s\gԬMݪY R.Zn TU05 .^L9=SpaCێ'ش؃f-P $E_]-K ^=B^@jfѣp3"պvg`6~6!]ޜwOx5k@f2abR t87zV)gĊp7i/:itZV]Glҙ);Ì-u[^nI<,ND|72qK;UǢs#/@s!a/ *4.^/ue\9jr j_!÷$gCJnB+A(3N>wzv: o)^FpNɁmo!dxQH+V?=N~JBC~CI3rZ%lF%$څǻTjd!1>I D+M !/)6 9Z.bN7cyV;B Y_y>F%T%Ac@2Y?,VДm8;j6}{l&h6A{48tQIQ{<@2U]5UƓ-'s/zu)5Hpd,LZ6_R츯>?* /j%0 gh a`6o9St, T'hZ"c9ʐrQsnR01~@Y!mH{>|!?*L:x?Z b4/!YDt'DMG&7W ȗwp^0o E-TV^dO4A!IX!oW& ,-_wHSaA."~^Noxu0E[>HelP$W`^n04:R&^Zy)&TX P) ު`5 8T5Mx \;,KhUHquIk&ѩϟ#rdu` 1"5\^J;Zv(ڙMYh=?K\Ga9 t.|cz*Xq)/͔_!R;F2|TK,8:zeD HItu,#e'^$:`fpGZ{$$ʝi^GM(,)?gD>W56k7k FW­M6d'|4R 7(gC72^D WH\yޙF(Uu"4 uqZyYaA[:]7bF*^祥*IC}_vjzDmy6AO(A_q¯w5,KW-0>YRM3 )ܯk\hgÛ`:(Iuz^=~MmhŒ3 J֞R Thf~;tGװ3U(bX%yĶ%} p=_,͐mFԚ(z-z`tn΋@)J ^V g-vbw=}ؔIXG[N ~@nTпil%rxv? C,U%|F/V#2;၀?N=/|F!9@kjCwlQ' g*,QSz|mTg)80z &e!֣Λ5b|T_k "Äbm)5G2 F3 Y!vQ;[%7 Z3/TOkGr$dY"YlB{.lN]3@ ![v;HKyZH*zWnÚ{ s-oIWX8d@ H)gBP=FZUIv5|VH{3'}(.<`v}l z}`YnT u}y^0ƴ;è QJ 񻈘0_wpl!N*-~)7o$și* UEIm$xy^Ԙ pK==uҙa{yY>K1BbE^).&JLݼaa_fvTԽiiU| F rO2"t5V.gpj bǡPu;45TmTsHXZvqZ)IrqmIu=)SF BP{9t#0$Ma^ -x*^وv۵e\wĉӘlR3mT[a;. `!=WĤ窌y2ӖQ%&bGx!SƐ+-}hQhz|/ Sx?7vۙJ>ho9n4>dA^;ݪ<֥]˚Lép{<]ȏO [ RM̨V <<[ʦ[*.V#cZV`n}6;:dB `s_LDV]YaYNP%rMCNn!SI,^Zĵ%9:UwVӁ⚤ aEW4Ȥ`Fq>c!ҿ=^Ӯg0kYSoyjA}|aשeV̀8WD_2!ZdSc<PH95ۖ  KhqɑxK=#KFY &&a_͔ǵ-}t&emᶚv8eA^:9ÿZYTOTfv2^5^mmXb˹?ɥW4jl8;R-8(Vl\ArG ϞSѾwmС2G^JB~P!_BtϘ?#਴$/U&⴦ *CO 8W9T+8OyɟS:b"'yULjTFR}'cpJfJ~Y찼?DO@M9Вts 5S>z"'sj\E|'fp]=iǟ@dvbn> 3ZVx jL{R ^i3\͗pm_&^EE${@ޜa0.eq.xYý5f:6^<L`+#W3q}R >*mmoN۩^k"V` >#v0o:q^wMC΀[XtKR[Gg,!w+f=WANVg+' M>qeOKޒv0:qR !FwgsRb{ {,8V>}&h"03ۄ&KXaqu.o|gisQqr'vI1wy;t;C&c~)$1ҝ(p_<lSVDrbm{a{ns^'f~IɅ9܄ 1kPй?*;%`2Sg =spHY+>5fLNmP;/ı[* "Kl:H2y~(i:͐7jlX;z[yulK@aY%z+?s[}*!.܃=mEݩFzxa;-6EyN +=J>n9*P @/ Ӓj6;O8nPm G?NQA8U4 Ҁ5mB(Xo94kXR]{gyӘ ,oTj(OFQ}l/%DPE oRP5VtxPX\GirzS4=WW -z=]Kycϥ̆ا+}`/E\@tWE<+ E u# .4Lͳ h] #M1kIV-8Z;}%pLx8=^XlI}ug R LH UZ#HDGHL78$)9x1rV ,m|0D"|mH_lPq hk˅*#w/,!+nD@H$4mJH/hdHb^ j$Xcyo]tSerr T<FHc;S^ O7 w#$VeG $/x? (0zGO^-{ >ůFn-kU$Ѭц N 3oj.Go+WMZ eVHU\EE9JBtT )Ksfx\ѤƬ"ki{|欤@nAЗu?uŲk.恄$C+9DzLgjoIv?Ŋ6 ͋%ut4LR}n~2R7%ۈ"d bLԍÛ O2 5;og9P/dZغ4ARXNaMB-| V[jN䂫d! (}Q}?Q<O#/aNjӕ TN,v*͉[3 M˂e7'ygL",cÂNA /ס,B4rK+9!1e,%N|8ա*0u 㢰U (ǔna3^!:a8R-6Y+AbԺ"f(>; ,Vo{O'釰ʻD7)MCg yJ3t'{PCPZJ1XydJM ցJVlsr0AXG9-&w<>GiJ*nm%k32"dz*bH5F뚩:6&f[){8pH{jC%|tÐr3, )Cz\#F_vf*bdX}M]_2w&\5%ZJPJNrQv.Ƣ:kQ&_^pM9"<׹yq3IUAj00m()`eu5HA2ewV]N%2v~ݑtM`? )KH`qD% %xJ1gCn%)Omlqx<_^SeO-%䓳MzJNYje|9|tρ<32yWr FnE\p;BŜI&4ɤ%ʽ%!Xf_s(ʍk],='ROɡ14pں?3o5K4xm󠙷1,9;,tPڊck{o!F=<?%?Y0%_~F7޳iQbK"/d_vAӳ%yPx}+a/*؇aeG=`I!JL|f@v@VF.}NBI˒խl z41Hi m{5Gtr1,-!mGy);]2GǥH1uKd{=ZwMW1d;-y VMn=#Q`=pY0܎D&qkM6:[$J5U ׯ[B t4v0$[[D㧃38 Ϳtto*+BJ/ASK/ӔBr̰Pa;/&o0+z9+$]>oۃ!#\unԩAIH86? Q"{ЧWg3!sTOjO߳C0k#2'͢SLj50O4ΤTlQ145-c9Q'o WV56 Lt~  >j Rf "$E=).+Ѿxm{CW#Wx8y}SF'VbP}aN4 -s1]n~Cne e@'/LVvG&IOD$l%:80^bqnG8J3@5w;deߐiB‡PIJiî_]$03-9) <8lulUK;No8WMu(_vl&:(`>]+̆8 ջڔ)x~}]?IB}i}Iχ(hmslI)i+ a.0Tv>l , J($Y '|}*ߗ 'a<>rtV rHrvoaHsI[GkD9̜ 6oC~K@'Rm!%-irцwD_Lpe zYwK6._~[-c{2U?u0M_9y%ՀY [HpA/[z !k=HF"=-5Wkz((q'H'@{Z%PbʥcK"cO,S }gUW} r!)(|p(Cc.[mU90o_aP%HH8?CNo:4rZ@D\p 2S܏GHK3:o*~^C}U).bQ9eorkK$KEe =9bBgk$6$p`\'?2F]"euQZ_тL{\=UZR/ \Uœ('."uq(`՗ȥgDRt_("ޠ*;Kw%wn{)cʙ`)htA6ukӨjx⵭r8,Cv j߸$[ aTBtWLsonIS:E>Ptj:YAOף n: 厝Xl!D4*ʦAj OKȳz,`fƗ-~pRǮf!$y::+ .!SC@#Sg Ć~Y<2Y\i(0B":6gEOU!;P# s+G809&\ Byi1H"ҬP`#.Sz+$|ZҞ~I(ٵ1uzKq\²36U7tJ(x7wf`sq@}b0*9djAoNK``< pH1[ 6BNel{:$w9{_ڈGg Y+F¹"SP8 OAgef>Sz]nTO#Y$eX=?&$G .ڦ4(S0b33QX  ,NTGG ?'K}2`NG.MQDFkzaAd~)ԿԽ^è0GMĭOO~/O[Cv9zx"AHܲpXE"5;(uRgBviCݿ@K`PVۍ.[C~垖|ݙ͏3)Rd]fs&718EL qQD31תrZUMHq7.(PZ?HNo>ic.jG%h1'Qa;^ns&3xZR]gHI<.-)m<7-N>K^(ҮSQD1@ej}+ a+EnC ,GD-wnՈɭl o4ZZ5i zU3XP;| ›s+82[sȻ]џfC\Sr ]H|GlaOZ 1,` @{+f餺7Oaw-RGlORAg< GuQaK+{;4̪~Kdq ^vYU5|!~m%b$&$ itc|.kb2nLT3d-> nűO%SWz\?%m>Ͻ@hkK0cɌߒ[8GE}j#nYW8Q-6tjNUZC ڟkN򳋴o(ORoW4iK Bl p:C+JݨQk=&=z<U"^]k(#aؚ]7p<2FMcZ@Txo)|n(ȧBF n#[m:_=m{.K'Y]=Ua *or6vGR%vC| ;3B(4 $쟁R։%3i7DML5C#ׁFo[g.tcL8&KW:(t\2^͹{킛w5x`ZpJ gAf$໲`kELBޫ3LWDqD/AYnL'2,SV']fl\FmlЦ\15dqDp.5̭(ْz%r2OQ HQ'DQaշT~ev+Yx[rHG7;9[3|,St*V Qd|YX!-;_$nuY aq`Q($,=ҵ qQl/~TqfUd;`ɄFۅp"y $m#X_yCIֻT\si WfI7qFhC׻fDJSG(ڝe?L=gBA̔Yt<ǀhl\%+yP׉rGYTq%ί:qr0H1)Pdʺhgy&ų$qNNmr"DxA$50,[IE"%"",I٬v ]x~/CՀ75Qr,tv ]8PCtqɧ7U_R=wM!#BOeꔄH>u:“s3 Zuhlc=ܗԖĝέ±s~v: fnEV7h̓bkeX3zO!.4F.DCPV K~L)wI ɈQ ;Ad 84;OwFYn?vxs=6cu ;Yꉠ3焉„* k LJܦV &Lw9^!Jw.j;LJ&< !䖡aJx<,UF\EZh=^5c{ ٓ=gHe"6tqgᦃ%g* i3W'5TR`&W"_-;Fd{Jήq,VՒ%kr*̐H[k MQ)Q.Ѥlwx.8mE`cj[M z b{1.5̩9&H"ĜoKTBr tᦼ61RwQ.5!&*H' dT{q .6is$hQ*))1Jx}lF꜒B< i\ HG4 oLů R7d[ۊA[@-}=Ug~B7d $=BF va2M Q?GBMD"p02J5 (-hYʪ\*{ RQ<(ʏ<`>SeL|LmhfsDD!7qa~exf]ﵑdrœm6& ,\AbCͮP|O '޲K/J5Cs+S&)xS( 6.5@D&_q;24ȯx.P~0^HiѪ0]u*2b-pzNz62fߺ A9qd-pYq0]-F:mV`ۂU\[ٌy6% mb~A ӹyŔ[[9g6dcHd/:emVQјڄ2r{yrlZ6JYxDp⅄ue eYy[rydXY>9,} u;do6AD8Cwi& fV )U<tCO[tVV,mfn@|\N̵;md|HKMbW5VKo"Y;J-euMNӖodQAwm{qOe«tOXZwx/av9i0d)둩FzA:!ٛ\+?:f>d)CT`s_G{MAYr*\=B 5WΜ"8јA v^dcͰǓvjCH]4ʕN$W{k6ꁡ1u45c ORz C>V3{ oZ zGBTO&bK51_(p "LJypXUb3Γ!n4g6YA5vCװr,K))2K_h)!֩^=WuJ( 2 FI7fjx F3C5'?T:DC4'}mtLY*9@cx>HԼ]/6(ud&9ɦZ L KC~ƧۚhSb[ Jq r;@w0j ?\Ԡ&pͅg @+<؍\) `UZRDBv3iicUé~F A!5LnXlo:tkaX?E#JZO seL2]_@3.TlK{"`Uz (R4ҷ@}\"Mau?i - ؘSuֶofrX&ɞIHe0䝁[Lt>!?z?ٌ@bO1C x+C7Lqs.ZC(c) BK)SS-mF)W7 Ӝ39$iڐw VrEdhn - X eoY$%?&q__WRAm )S+OjC kPn*-}-?h."#M,%(HF:'%'TD>SvkPU4rDPЏĽ`6DԱʐۼi\}/8fM6!"h"*"\Q]Cj;^SeVb uV|AHLKcOPr V9E¶T;;R R|Mrc>D wXozAq'C!4FZ?''<|~ zxe{ay;3J:t X_uo>+E:lp#irv !I] "4zW-|+.Vh8 yx@<`ڌ`c,EC?ZL|6!2mdR:ӷv%(6FTӔ"$I/ySA'- ]L#Jvj2AB1 F_3ۮ> 9|7d.ztHicet@q^d%2nͶ;)k.ɪ'BY2} Ї21]ަ*I>TygO?\Ds%¾'ѹ{F鷊~#!ʾ/r; aF̡{b ê&j|,"]p 1o8T}6S' m;϶ze?^?|8ɇOiIVـԓ,PQ pO)Ӭut ¿.R3#DqM+?tWRp+:lׇͱkcIz' 'ޒϿ-Gzg,Rr֎V,Ջ\*i3Gw3:3ޛH{tl]vt+]өg0g5 aX԰(0S\ʢ?cvbm9j*ԓ|*B 7mwÑ2 t4'+xbVU(1b/'ldAǶkE0`w`tDs ryvͫS 3Im>iRʡm6:\OuJ<&k&L_4 Ęn JL*ξڻ[u;! p!? pKyEEz@BF$pLȓc}2 ݉YA!).RmJo VpHPn,W,􎪶?Yut_8pZ͢p|_Y_ҧ-\G^&aoL˵j]ӠA~.Q_Mi3(>m% Qgҋ/X6xb`V@;*hux@s7̻=/^XĚ-u#K9@)@ֵ/̴\F\"Y.ZVLg.?>N&-"S ک;D 1붅dnΤ~'.x<4~ vzP%f%AN}ь_-@[ 󙔓=)dc\"rT*Yf",>&* -05"*Q˼ s:Hm/=Y Sȏ{Dv"}ReYaj$J"YOFfb ՠW~v a±R}Z6&@ J3Ebd/֎GhS]t޸2do;m" }uԭ-n̵#AoV*JygE_|i+QEhDtކ핚.Y}(3@c%T{ӝeͬmiP6\KS 7KdP)qۧl!T%j5ɅbU|"z [- }30Xb&}v\NTeɌD \tjA!D0v}3tD/¤#9+/ r#OT@U(1` G34̥3#DDT6߱^xe <"EFe{VBig&yثŁvONX81ʴИ&cтy9J$ Ҋ5YTc2yjsG$ 焲\ߓ)]Ju%Ƃ)OV,t9٫;6+],W7h$'S%%DvT|&(U 0]H7N}kn,dW UQ ^$1t땥Ԕ^G6Ҝ ;|ʾy,f.#R_8kBxK7{ #|?m^7M<5eTX .9ٗk{CXӴҦNQcxrz'pjr \~ g>W蓼^[q\AaB B)˶rӛx3$7Xh|ܩ5E>-rޱuE!xNS`用'>U15і9ǮsaHuT3%wgPأR;SGey@)"i\RG BTX$@:`H a8,al NӦu0w߼^V3kq)Y_PK(ش #-X<2nnKb̋͠ 7y;:y~eN^EOtᱜdYVђ)/\0#%6`FoqbLRW JIU/{TP2MxHH?q‹cևQ]ĚY(Rv 豬W$]wFyW;ޚWM*'`'.'CR(.gN8r #,\u30To oWX<@?\.\ipEOANd)}f 8Xt-_gDfܲwm~ ꈪ?1՞PCvL/LC>߳5:1:n_(Ӄb_X "x[W|BgN$;b=2 G p]͝?fY۲|8_xoV=v{l򶍇($nX扥 Oye&Jh [De{"uV(5|},Q 93(gm%Ni,?g#lp&' :"qAo\ziF-N&Koz .u T:O'{_O5IC\yZ+E\ I}_VFs<ЗeŸK4@ ݚI_-4})EH7C}Ԝ^_k}a8KRzˆKWLud5F ͳ;t4!8m+nN6)x/ظuGUURuC jJYJd?NW񤈩 r5=PYHKaJGYOR *~E=ej>'dѭnq4׵,VA HH +Fu9pq퓰?懀}b@Qdه6G-Uppw3E4Թ9uW- {^G38ʀ\t]̰V蜎]Y$m(p6+t" %f5-}7x/pbx JqLl'#K{xm{tL#&eEXhu'%Rճ ['87nC{e;?R5{uEpW M|u -GWHKwr1N GDk{m 1~KdebK7,;:XmH} ;({QV^$O^i~XGr|_Rݞ \(8+EgUfyQ j=AK{9!6h`q~6 KJlD$hmROlE6eBމsJ`%/I^ekn3h iYMYwJxߩ'ZN.uDmb&uBBް4օgԩJ6\(g[,L3gy?`OLVy"}we_|`CaV5Qx69^O1ƹ E>Wf7x 5; 9V"0y?o`[N| =uԳ|DWdn<iMq/@& +uvpL=9_@z_ёU A 5ș=!G[*V 7kx /8LB DEPy%vaOezztN0um®(>iƭBn/ )ȸ Lǰ n޶ͩa.5vv5V6zc÷9͂~y჌DZ%XG<)3!oKcLgތ-+1NCv^owg[( Fi`J R@cgk7K$ п)\؝N\Lh3Q2Cڧ1+TkfN>4̓:+/oCo4vR ?h?rVñلO+Xc N)i,Bs?SdKJu]7);E7 dAFi:WrJwл(%`Ϣ$ڔwL#tZQvE}=rh̊ L%!FND|wic{ȩ @H?l:UA*~޽@!Ԟ0hȓBW}[OEt/Ax6[kR^܄piXwCän^vt4n$CBH%JoLA$ RPy 8p"YbEW艖 1KY=GB8{ơk?;q T[Fի.TSMO x0G^ԚM>B-?+%}Rb˿p!œj'9z#^C#܃q^=E< ]7w]߃ι3c$`@N=)mF `չ#@ɋ J ύJRܚzE-gc&-bܣX$]{yBZ)ԕVA4Ԑ>:!|m/"dl6ST.#VGf`40盖r/,/ 'Gsz]p݁h^*4|t]g)kpogN"e۶A,j-nGX`Nr9+Nݑ.O7*8fab#葤DN&}7܇#ްea d%XhqMNA6Q<028x#4*f+y=HݧyIt_TC_7d^=pI5a,BA^V[i9i}(!ָ|2x;)3@Y=ѐǚKW\ \+š|$ @j\Qy?T6* o[D6cyPfFvdTӡ֪R:f1N2x+= C*f6dD\ʶjttDk.LDpi)_FXl\ NC#ϤGU^:*'DVˆ! >L@|:t},̅lO3 7TNLXAz^F&:i,W,eM vyn/_^,p(A{bm2]I%nUfEG^NZvr>ZZx.,8Ӆ,u]o=ycS\` 5 txA ouiN,i Ve(/Q^nE6Cњ”Xf8q?yn*Z ]vMcwN\Kuqvnb\ln~3`e;.ebšԥ|CC0AEhX_ѣuslM*UL9dcLw'nXB)E.D $dBFԘ$Erjq="&F6 Kgx,Gm:-XI(^jtT`y mlIhXpptf vlv3;Q9^2QNR-R܀lP=8,ʋtbA!<$!8(P] oح8[JAe%)3+U`@ ܀(ڔ >n%myՋxW=/Gwe8X@kHCh7ͷ05{3 %K/JyY U qb "t|kMG>Eڮ"PqUwǙ4@-n;Yb7.BN#,+tD|:)scZ ȗ >Wzf܏Ogر6wg^4LjqG u{a&M"fyٷɒ2/Cgg|N;r p *#BL5mU/Mźm}MۖH\i͓!뤳(0.tĊ+ȚyHڴrӅ)%39,~/r}QPh[-bX OnJ&C a}lN%4͇(#MњxS$%5ܸh!;?%_m4ev T[Zd&לiLgg _ rMnǶ>Qfryyo5dqvJ@K^QD55M ]1bX<c*D)=V]*,†5 }3ɂ ;[Bs55P9 *O.U)Bc'$ڡjG'^Al)%VW-޸{oNob)Ԍ+ħ^s[ŢkF_:cohS\bBYdJKs^٤I;fz ifT:F| [ypY>̆A%BOHOGԁ`^^BGqrb.t`pw0X~_H)(X Eg[b,t^2x`NwJ_&1a3UB %2olAZ(c{514פz>|ĔM?Ӓ'FE\@/?wgGx͢Mĥ?$ %3UcGIvbL6wfGTRRU:PDGhYmE`x[ ?x:̜˵5 @O4+,@âH|p y_K}zHHS}f@no Yw>1F=F]YdQ6 jf/ P'# ǸC:8B~}qHaN\JC9[GeDoo;T RT2[$815$.hWYHJ8}ЈSEUiv~+~6uE(%_02=;)ozav|>X=^^kқ~AMͅ8_Sd^kH PaWNl@X[~P[@axǽ]Z'2tD8\m^|y"CF#^LMSW6i2p["UI?8ȥ9Q~>^(j!g!gJ ~-uU&Ve@B_+0@):͹*x(Jҍ^71K%~?kwa#sbyڹ`Xih"b} adu}xg:A- AX졃*a^LJa7<) @-{pa)ulr0X}mv- oJp @D5?֪ eל c4"E[eUul_hRDM&_MXT vqTw!BqΰOo8:X+FC?} cp-byE@g.*?v^AVSrtpso&MiIp } ϠNFzCaPx}W* 煥4Ics}r{W3% ڥsq3#Z0zmjD d!Ė\Su!Z7(AH^y5}@# F=p8#I 93!i3T XS薹ڿ01&s'dP㧤8Ӆ((|6,eY9h(~-yZ&A="޾?Еyi8K_ޥs']MV ]KaXwr()sUkIDk4PUv՟y7(wh&dNΞ?8V)&bCm7"}^j=g$/pO'wm滤7 z(<_i|ء"1C?2{9-fIJੂ'[ dshHmߵVLD*RǁVd4ׄY &<`{6~$$aᱯSHR8ż~B|Z  +oWb</[_߽*M?n4p&ITqe Il(Ù>WSEPf&25)YˆLg+:X/thXuF@ٰxFqY:3f47Y*S3 % ga _%M4rugn`"c' OFfw 05:%e3KHֿ:Jld Z)P-~Ч> ;Jxц㈱T_ֈ+70ב'G|Ğ},Zя$*(%/F>5:eY.HF6Y8$hނ jΥP6'1A\V>W:gLP `1BCDh(q6n~GIWi:\chbۋ! _ Aӊ4\VMXsFOoZ6]x~K5tH)p6ogj<\qi;0"y_<_KO$ֶڱ}<I775 >OA89N,-{Q42D^f9&';cy8Z&І::ݎtWصWV,vv<*.Oy9aJTsԝ g„~Jl&cXT<ߛW 4uBܳ~ZbT[_^spAuWŔNc xv{< תH2 Q#mb)f+tolSxt&<>sdd4۟6Ѱ#E^Ӱ츑vΒA=HZ}/ކ8ZN{6Ip䎥YF~ L3kuRʟǩ"ֿpAx>Lxgk:HyT3hf'z*M ΪWZO(‡ےQ@)OJ(it,ucHG|8O7}/5qs#C[+5G>:'=8OaOSx2*c]7-:iŠfa6-۫{HXU؂ jsfaXDp5!س)j_buu%%΍cbS\c1}u $S s29yq;*/u\܂Ÿt;v$QZeY2?\gI%AD|L2sO oJLaFDaN!Q_ע5sAd 1e2] (+,8%o:/d(|5#yTߎoq`C!7tx&T]枎[%TF;`*(lM/\}BXr9g5*3~*깒|Ů`PԵڰK`XeW֦$qJI8+^OÝ<{ڤdMMam~O#,1i]w㻼?+6~%U[Hc +1/墢HHy]3Hdϐ;`!Y=%2_zGݔ젣zu]C pAs)3Lt=? r?XJam ;_@fȃ.K}`E( 'xOA|\\|lD"hU`k}Ud݁ۢ|(UF6ss&ԙLzӫflqaT4b[%pE/8A_;1;!nYe|؉7u{\z1džXr\i'u6U*0VtKZML>ߖ&v?(DuCnY) ryJUI6pi.]>7{$W _"}Zp=|kGq2\}-#lhzSJ"gC؛Nr2çI(dn`Ҕ]UV>+>ҿiOaWDvG2ρ/nM~Wǩo1KO+-eH|:KᘄJxUFju#%Ȓ.ዅ9[rY~&*,z$D,#E,f\:i0ɓOk+xfMNsWWXe2b01R j :r':FU5{#\G=,|$B|Ƶxh2o;m.HL 90_>g~ߢ,ɫGF +A{]z.p<0c|ѸlzMy4L%e qF7%¨;BV. 8O kPaWM-Ңy7-#g{p_\4 *#PEyXdR0eox,o=Ŧ= H^+~vRe>+(U]5£X^04kO9K۬J;1'HhqmS&z?9ƪR,4eQKT&U9WBrz|Q.%x붴U<_P$3ϝq<-ɨz+^wLy^bWTEB/-3c< /wͽʰ $bR 㒉|πicFOjs@,@ aiv*dqfy8\q_wgS{:u$Jcڷpi։In.zɬ۠ j p~lXKO)(pcb2EPb|uL3:Ȭa 6wR^):3VhRj%ꋽҠ(LC6)6Km umwUqZpG.H}ݿf^'Q>/%A?%4"T նr73$8g7xX 1w.AR_g{vfX$(F,9%8c9n\Ʒ"*L3Up.Rq*"z,(ȍ>(epS:BĪlsrH3-I <1^W#AbT]@Mg^Z(I,x4WϜ?$MNZ& 6CRZMެIXd8 )7i,toMn(ʑ@Y6tWf]5<\7SPZ+,qG33U-']{ PL0U^~?RlәmL&nUO)J,83v=X^yyx):J-WwfMk<@jpNjhD^K qd]Ab[WQ+\Έph3^2@R'Ԍ)*̄vp&xN/ cه;qP)HhEWGՄqRkYK.(4Iweib6y:9|as "5?M"qvLRoBi\[[BCn6cEMu1V㳏&Ph,>tr_vL&BD]J쩺~Jn Ek.؍@7#x;6*ZU@5bǪ귍4ƹ*Z\0.B:N0YX5uxd>x[Bh"7\5m[uEVv]JKcIs{F s9.y րn"@zH6pMGYaZ~I(# Q7cfxf$L't`]rmKI"&+[(^yZ1AFi({EAo;iS2q_[?ֱ<2ncēwmch!XtRᗒ;[D; y}n";tGd?(j Fˋ ]FJwyWS5D nrkȲ[.NfĈ7 {nW) Gv58>mÉ!d(mǐn@s'O!y25u%%Ucb~,HRF)83wdd1{&Jg~: GnEBeVLcg +-KLu DOSQhq&⊪yl)@F_p #t1ahNB$,X–qƉ[G)1ﻄT⸖p^z%);:!6dAпR . S4!ǹ7<OX8nd07TܑF7 u|RmCeg"H 0IT Y/il?5$TA,TZ9`@GdsCjET tUYEc%D[(jvG_}BGr.;/ZE# 0e=(dN<}j鲤Ka5Swy cw4 ~%Aw' @Fk\q k>^Hb9BDGyB`^Ղ Sd,ۡv1zq,t.$, nvG %䦁,YJ4G0aK)&>t*w46  J* 6Rw0l&1~~npk7̄A r (r(юvrH[[9OPg |~+ʼIJ b ʆy>QH!˕C r;2V_D$,<{<sJ>E?Ks)̹r%ԉৰha'g $dףّL >>p߇üRcalW/ Ԡ趯2L-@nhV@T8?av5i(IZQz*x~෸_-HkS;At_a>|a2 `(:Et h8@Q"R`/)KX& ap05cho`QB^O-ǫ"\W'@V&kr`;ZI6og8byʄ&QYS1zݧyLA*i>*^f^p=cP]l)GנFJ#K,ũ}prfQ5\xEg틐~3漦e M~nXGv/ݔCDu{_چIӃlLsTZ?ZW}iu9;R>IjV9 vq-Yaj}$n]R0Ш$As*y߷v3hvɜniN^! l]!?#.tL»*vf s92#,{R$f[x_.;fm0s;o#7#ոG1Ԗ Bd狤~ZPqV2܍ v #>0}=|hH|kL鮆P/7R1o!~alީ48Nn?Jn2߶ʟS >ay} p~ 4_EE '^r9X41yQiq{4 YƯ-҆Iy5WM4϶PPc3G_wWn6̦bd(޵^ֻ;ٰ KfU/jUU0|oPwH* m_] n7uw!+Q 3;WR@"OsLj9/4u,PJ7gm<jSɇO pA*o]bj~qI-h)G=8R%`=㕦īLk Lq"+~kDdf9wPۏk} ޙn i[_28#LLtMIN+c1S *Jt-h%GĖŪ1-<7\ڵT62@iXHHGnT(ƕtq&|HhYC% Ș M|%7X,*`O`Woi718R^QPߦ<sK6!jɗ'$3bǗP [y邔+ .ρGd8Yͮ5i}}aw?R;9`p8uX`w̥#LoCٖ ~= h^SJ05[ei[anGgEO&V(%4M΢<6j|'hL͛t;Z"\m&r%+ԐD슏H>#rhUlQŐG*@dԤ8)ܼJG!R(rZ Bfeb<. u" Ud1JZ,:92m@)pHyz/C[B7*A!ϋ|'<|QAt/4Z,=hU#,BSLd*b__VF,)5mLq@*]#;0fg]5 9bHHu$=g ߊ):+˩܆ڐP9讑nFN[Wb$'֢H* \:@P)%}/ꑝQugT'g~}qcISq(|/D-fl&MITyHҠ><ڤقMN@:6O%+@>+ LiWqC4c=ܕHйPsVpY.6ucfgOmA O,z'*Pܥy1_aV񎹦?_V ;|^m@3Eף1(ؕ- J9leɝD/]m$j-bC|T|2D k\ϐm|B6)2< 8Pfq7A *P-Hu"F8Ò];ߜva0aylbr.+_ߠ`:cќ}^>?NE/H螳iqF'!b7G4"(k l7M*b7tB7I 8.j$>{ºBܳ;7~),m5 w(b󁟍5)sR/Gh}3Qgodnn]"ʖ͸b昞HHԣҤwcD{6\S|A0Sze$H޳y5sC 2~ FCY^EWj7h$ɟ q6,=3b LKFxqӁl@x&( Eޥ'_DF҂o`gdt{Z:^ѴٸĮ>5yPI;u_%&mz%'w%..PH-dp=$ι=+1RYd@PI=7tbkȩ,X0$Vy_TVm9ޅ٪4ETQޤ;^Cn'`[\aiXI@ Nax ׿]o%uw.otLM*;H@= iyS7 v~Z 7Wc1NODjQeBhKL]ICk֒U4M@! A:KRNKP!˕b^Iz73E6 Q4 /tGSk'o$gMqgt{ҵA3'{& 3ߺthK( nsBެg 9F&6?M$1eObKq#Y׉w%P0iدv(w7ls /sDJܘI-mGrE86S=nQ8/kRQXQMǬL(DY̳'H[N8R5LB4|nL&m0lnGm Dw`Mh1f54ԒtaXH IB^GC`7f`45Yô/ O/{eFf;%Vj OTM̭Nl*dHjzgl"ٙka+Όz4޻zƛ>${oh;o)4o'w HhzJ*AIߩѠ(;X1!|&! 1m#^Db$01k;drѹcpdAץ.MxͭᓻGf4u%dB䟛Ф\cv&ƞӵ,Fy_?#swYv2'.9-%VAR8vz}%Dd)H4 Xϸq3"-=wg5#4AAm(%O|G'?NF:|+G<ZB@ek49gc=5~sǒt }Es$*}VPP9ޙ5 X,dc((2Np{cxxA h:(&E[ns{aky/X'$-Bٵգd&2HB23HG NT>0H'f^$H#|X_'ARU?2A1z*Ƞ'$<~IPuG.6ysa`O^BKF(O8QLjl%Z5IM]_&B]G%Md[#"dgϜ9`Zr:2MޙX>Y.Qjqw VvSVR[yt^P Jv{(  #-ᕰĜ٢YLZ#z)C=(&6(VywRSkGlZ."@/XJ `sAڰIh[Gl'ӡY'vwj{@p}"~TXZ[KB,Zl'ނF; :(`m}pE+A[8#EY)LPֆwʣTWS;@ӫtcA*MwِqHK7>yik6 PDY,,)t`;6b3*ȒT"Q)hN,7rVf2%\ӺprH}0mJ[@7`imDZt[/Y(~2y1:yDDŝ, M{?Kg+`EޗCgf/ B~u(΅e#ǾE{@ѭ6/V&;@ 7JLUmHODYxe_fy!CVd, `ַnDe eWWJֽB+jD?/&4Q}TDHbM7jqo܆d$c9&n^BF/&R\|ى>);?@K H?ݣSQ ^w9"l+ *DW$M_n!lH<0{jF}. . ͹BģldR%uhSRU@IFQ8o_xTPR~VJ~U"-rגܾ?# 16)4N\+Svr`Do1,X\k"}izP` &sF(+:O:}Y>P4KpRGb\dW~ NA!ƱH@V)A 'IW#6'`hZ<,r /H;huqaA1Z M&P ڧ7d}WѴO$ގИ/ALܮoW(X#xܧ~Ғo*yBdX%cؿŨS3:1N: K 9pG{ 7>1$A8V/z1X۾S_є<F|#Y3쏖8#?^)S6CzXt Ox=:{b jl(R{k~.=$4CKEia%Q " PWbC 6Wd1rn4xq9bA1} p(`8qL˥Tdzgyɟi6^eh E`[}PڅY& nχd5}k$ z6wpmW41RǦ0J _'|æ߱ AbUE$}Mcv+xTJ T.dLf >͉x˕ӜkH U*wஷATg AӉvhlKHSLk>y]9"qwZ~Gw7DG@1ג>JhQKsKEL84!X mrUH 9CsŅ,3(HФA B3C1"f|Q:G/_+5c6)˶ \TF6]C.U b3`D&.X7~Y)b@D!/01Kk:,0<Խ<^;|ܝn/ \ׁ^ou'#Fāts-o/&>Ʋh w]aIƨʜ9Lm [{#y:u<3QkW2;v {rSD#^9?lWpM=3Z5!ܝ{/;S4tH C\ŭJ)Ivr2,*i xƃwZdZHZp˛. FXF૿F? xp5͐0oNugoKg>:Ƚ7F,<_`PyТN0F:Ujr8j_e{ng[sVXρ~b`2N`Ձqi/`Cf]!; 6H":<-C=[[1)uGfW<-uEg~pAN}zRX"9 j#i"t*WҜ}w1ްfTWΩ8kBLYS^sCe+^.WP;naJﵞSC\іxڴ65꫁RGFm Ov&s7\DF7qME}zIo8j`6Ά bG]"D, | F]ω%[scyO~=VOyZQC#vJ ZEDHLGQr7ڕ? d W; YnCd :HJt+;RIlheu͈9mP~\ ?&WY- b뻨(0_M' Yv,Jd9 ~cGHpHK1˧nG ~r+9CS9x,D Bc@V׸b$?l L([< 9CCciNIj(̃[bfj Ke9V8KD` NT9=&Km6` ("GDGTj0/yJLzkgԠΥ'yTpxRj A^m6<~۪21XԍayY%2ba+ !z[2+ U:D i qAVgYh}'IБVN7􆗝M?hݝuا)@3ƣ=4 >r,M-=e,~FoTn'뺿')}uved}ٲf\,#$>>22UdFr$l3W*Jdž!ooi, 2d:#yѷ12C njJc1U :ئ}ʑj  󮌉 V;nU jEf>igTJCew&I;!ކ^kC -Aְ2W|Q#04>بnw )G]!K,8qET`7bʅD6=~ɋ-LTpH7'6(VjEjhL/׶%VY6pLLwyU|я@(6 Knm j#sUλQi?"ցZwte16-Iܭ<1Y[9m~Ԝ]_Y7x %n0c5Fm^&E?XU[e3<٫2y:b|Υ@}/SlӁQKOܜ,OIwpɥper8RYV)p'8jFuf O=#ݨFӈ2gYdc5&h5̕[ZKWϽdz,7ek.L ͰpRV qJcr]j_tRm82A%nVKN*! >U7ɋ,ڛM?CR+khkJή (Vtj&Ҳ6j)rx;F:M@횤bx[e-$,L(ife<qPt{K@)ǵ=Rv\aWpX9Ћx&:Z^;HК*K:I@V&}$UL CS(#=wx__aiLKH~/Xt1b5 QqwKX Y(߽W@_<Ri#8ԭ.}]+Ϝ\uG/hԱZĖK19 ;-yLKz9֋jCYݔ[)GǾNF'P6)lE&/zzb|.񤹧 +<ƴ-n&%<ωs䱦r⠁*ȍ=-%}-g6(W{,Th2j Sm H3ʜۓ^Y]fJ ާ=ѵ|y 8/ +sLFv Z*,tlC9jxZh)3c9!i>^=5Lɯ.VKL%鉖ņqqUi\v7PbTwU`'3nfQÏ_05]֥w*VV̂ v>]s_HkH2qx'jCxC-bbN=[FԊ>Y*[Ώ/ $єXaxVGxqԠ?2 c:SETfڳ?2UCp0@p"H*=sOm՜ppJA?d:QMwb<ѕy 6lqo' !J>i4 ƪǖt"ȯet&` %HѭFih%};׬ N]5a.txMcruՎ >:^MAGXbml>AUFtf;l~gxjh ]<!&/NuӸ0Y441kQ-tH?9 .7N7VFYQߋ%H6NImVn K\}8keql jUh vi\q޸!$ϟ+YW<6FcrWEq]'S ZQk~o(*v{q*JthH(onGI7g$ SZI3 i챘&FXJ"B:<Ş.{NtyJ,q6LBYK409ŭ(P<7hR,n ]A[;6qq˟i7/ćj_FJ_ėk&{vw\"Z 4 M.b7+L+R/o,K¯G1m"jfw|D 1LHO,`_"{3ӄø5j ~1|8e@~F֮.ᑰʬ[ms|xO#{k0e?תnGɄ=3|o,j׋)m/i'༼yJHn5TN] M#0˒r&au0> )d?x(k^wmw#jZhrl7.+{ՙV ]ΒHfy ;({<=m[.ޞH}_* XA&0UU9HI| ,hdӂ}N[ oON;79I'ɖqB߼^1}z%T3j5ge&'_Mٮ;߄yi3׷Cahѥ9!EA5P ӻ~DqQ۶x6#NԱ :eȗj! 3/4[D4@ Lcifk-9cMj|E%Fn /!1u7l?䣁,]Ew6#(5N/˙22 'YstƤHcx`RVM8?Nbz5JN|"R[r,TamM]ԡd[X}dׇӧPP<XH6'a6YMW -jsˢY(_iu~1=j5 #iw篕qftvbORqƢfT(min%ۗ4^Z .]!6hjS]䙵 pSVLkhO- 6 3%p#˔t 8P#?S<58xK֚x_yҐ>qoUȃE>JdWG'VjC^%IW3af}he!ovIe3ˁeI&-6 ] Os+:~oG- (l؝cZV{DqY5EApTq_hn'ѾV/!0#Ks4£[Ɲ[MWȮC>EYxUl r5skjDՍ&T m'^'nfVۉW W>~AX< A\*L-o׆Oh˹n߇+(<r>s;3hn8I̲͘8z4\bYڿ`R (V49LW`KlD%po'29L0Z, k>._;ݠ4}0al}?_rlo#l[Ba1U;F}SdzJ{{m4<-yrL Ȃ  ҸcDzz1BV8!3r(aZT#6!-V9z'I ][Gcs*.G!>PIwi*]̹^HNHrgݶnV2ƠI-t&ZU`V> =1捖t4 C%/ʥ$IAxYɓ&=ڙ?b*}WCH*z5)rfFiWKfQ9XwaZ; 횞^P_1~_0)w'*Ⱦ~S߳rb&dLvє=2_4P`⦍ՄKS-߃z*aDle,˰,};b~^QU1L>޷Q1 kYNK|O> S,B6wDž$ }Shv6k97=)P6BCJք)33;b*-t8h갬Md߸A*K}`Mq1atpǍ014HFh0c9+^М)x lH> LgUMuS+d|Gi> d#bO4Žt_(1dրY8@O-wJfhJl&2+M`kk;sEz)f}Ehsx 5/Th^|g}2پF.rke ECWܓen3mACn*0,>e@X*_ Veۂ~Bӫ)f%i VO~, lB h?3$GϖSXԭcU 0$ʴbz{]圆kpߕmM襎*Wϟbٱ?|&!s1e䴠%qTT˓u3-;Dn s%g( ]1EQ32L> xهdJit%]mkXU>yA$@`d6ߧ1$&Oiԟ"0Xv +%-o@x}AOV>v i94.m̧9VQ#?" YO=hӠ&g_Þ{!<0^CԌ0{s?t]4~xBpBidY݂yVA-6AzL6O: <Խ(i'^:\0jL8&v!0 eMTnucN 8iF]vfbL7O9rOdeHEڃu;ZmYk`l/!6ذ^/0ҢfmJ^%,YWQ~H\c/)~Hd:\9H{~5hK01cUܝ-K؁|_Du̔2+ Zdb5>p)Lc- w Y?AB B$!]}5>pi`)hXzR6MdDQAj e/l>^ERMy%p8 OMŞ7*$9DkL2DQ'&<E""`w?]A%n=RAL0&g:4YRqÔE*t2V&r]h_{HJbC9: I&5JdgADxf[㔣5Aǥ "{T Iip#Gb,fPَtk8/y` ݆G{;tL[\" etro#`&ɯzXU!5#W"Z~=m5WS'̀LJL3Hߝ҇F^o3Sh?JIogawiא:0+qzƪCpBNhg ӄ ZEui#GeԆ,;O+t;J'&Ya@O|I^4 w+cܝdA +ѸpG`~ jO0{8QN]4Nr֢C:B.WaKc] 8KIn&ٍcW1  [RqɼJj9ȐBy_6LO⮮:kOWנՊĆb=Ӑeh E Z,2Az._@v/T힥@$GEٷ^/C>{ggsJNB`:QC"5cEx ր4q`fqCԺé 0G) )Ī1)psaйN'~A*C߯s_Ba2_d8("oK+Y$iƉx;[LN=@t1Mj(9"ihaTq{gtjc?9pio{Q(v6PhaF6 |H6#+Ñ ]N9&e2(Rz>|&ؕ$8tލ,\Q8+'Gs$ncPWgdAW5sNnM@\2ę3)̛VP[%s~#b5i3ZEyȃ eq'>r篔Ta %Gٝ_qHIA&&"v z -Qd:iZS=Hɤ6xSܷw P0 ݉0u1,`x\_Dskd.u溛t!Mj0^S郎p1p2%Kp1ᰞҮTM"oE"UtQ70QyB2pjؤZfr/[M9BUhzDUm|$\Lϳ5t8ξ(TX$%b! &@\:]*yek1/Ł'7vĪȉPjQ݁S2!7Aݺ-W1U@xC::Pw qD 4LYU='{J7gZ0pDzU8N=+ O.f9c"DR,W f7]*E[~3 F1\r^Ό5 ITv"RK?ÑHJҹ_,k06k||dƵ}R {0A)rtTL!iM@,X !x Rq5eWX@bT=p%6+됙zN8)W>2E_N&ƌK'Mnά^ OȷOiL#:~g/xٺ׍I\~d`§7~: "==|p4 G (*&c`XiEf;9t>=(18znk/7FӹNЊs<̐5HWL;TBi$]YYRUTZT|"Tꎈt,8pž~ҌxEuM|7;l|:E)o!m^sVpm\8K}i0:գ;o%:ft4 qFMTU- >7!7cd~SI~i+U FtWTGO ƣZ2SBGԭnEp@,!nABɓ&HIhp:D[Ape%Vܠ ysԊke` R*,85!yWB˛;1:!2RziX:vd1dE;& O%õWB|ŀ˚hMm\CkDAMjw5J+ƣ}'_]npU! I{Q/rw'|gݘ%n0/'w(%'b^M@ujʠLcef&y]"nX% tSD@4!3XpJ x~jM> 2W&21GlmU jPo]n YgZv$ (:0?U\@Rocx\;{^!#1}T<WR) /\$d.bYP#}RSƯZQSZKx'=?X錇Ujh, @Jn*MW`.Ih1`k/ШW$ ' aIGX~ކG#LK.>j:dﳽe 6gDb~&GD{Ah @'ԡ{EOǦ)5Et Xη ـg 5 G|;ڣ*Ȭx˄K?m'#*a΢-=Y1hk_yG ՝|O()==<mhߜx>wN43ݵR"oRs D9Mh UT +:y= 2}b4[^h`^'`xfB=n.~K<ҴL8 ?]u~$h!(an\+# оٞz-}`ɭ㇒jqc1za>}hޡV "sN@G-@<:£mS$Q~>&YR5¾c*׉IYDuV3h9WPbƁ"95I0oX{&u[Y#gUCIudḏh0k24KaCr_$oo)U';^ Waz#qb )+.c$iW^&D|H#ͮ`ߕ.'HҀQȇ>~Ts⧰D5S188A 2 DY[+ٛ5YP bߙ>]nV+#\\ͮM.Iǔ 8ec+rAӈL E22fO,:an"3\\u}eyHLMbFٿR$CShW&(]YwDJ>!a*L8Nc\?q}T|b907 >_rQ_iD#Xqʝ o6dt_ek湷uR}ԛ7{,#cٺHx,ljʔ\o 8݌:<cC5P!_R6_ A2 j/*qKtw2͘{{lLUP{!.oOA 7.dǨQR%}Wļ]&b7?xQEcŒ.qm>3n}z_4=g; u2T5!XЈ3s@5P9U {2v}]c C`ۀ)mW>WtLTJ;UL Ĩ۠ WˬqɁ):&lѡjcg٦³Q[ӸrYo%ew3buVw Ĉ5rlt! YGq?@ѩ—7I)Ycm Ɗ5j*iFuDğLQ3se1:1zrd0B0ҀɃnxǸGpa*V"-Ijvn]Ak JL$ş[(ɫĻD^O!pȯ3N`] * .~ng{g>vyԶJ< IzLeK:AP,&#ϳ„tX)2$9d@XPR"M "xgjB&NiJ]AIQZv94A~K: 'n:#5q~zzj.ګd mqS+ymc!ͪ-:Re0C?aʈ1} ?O"]c'>FlIR&$T[%(J1UyQgڅ)rVrKk&J;87B}SƹhP %R@a/w>uQX%bC}`d#O%ӄs .K4ßޖn nhdZe8~4hs)](.#QG)#Yz4p~No14r%֬~G4Grqg X$ w>+N±?F=%zS ~fHJMY1}`VȖP\[wU6"`'x|N ^x$GHVXUC@n{̆;*2'rZf5A+5 a@bM#k0_ 2MEC-Z 2DfOE2zשfU@a6!Ÿ^ujOm+\v?*\'$-JP/G4 2 @q?n)~J!V8,Qq5Et42nWsy؇$HV|Q yDYU|qX{J/񉟛"V #3}Ҏm$HH.XwLA1/lAUi57k@,DLtɎvNg&9rn@ U[2 |/ZRH]AI$bXH{ƪuW}Rl_ ';]-f #3:܃q{rNS)зTuER:IKd,y)7[<5P{` E3"Dǭv7}`I SJ  D飴eTfC,WdJkJڗ>ƕǸBnOoavxN "56"h3a&F+9tbYI EqNEHrSvqb* ȧY o-nETELa?HGxyl0q -|;z'#aŞ<1zeK3n7i'8!z~>Sd>rKn_%D6WKOeZo#' 7C=wZCzq;Z:=w9QJw ՚ЄĹy w5ͣX&6@zWj'954rp=4Ʋkh"mjܤpw SyJξTQw~BS(@AŭG21SdYu@GTk.zi})R7╋x %6zЅ%]큥{Dco?҆Mi]zE[7^2K-(L,'l 7kJJLpŮ:H+j엷r_OUgTq7]V h`d)V_~FtJ^/uMnEV|„.,gB B"M4V*_Knw,wı;ݘB|%감 =-_TE%^{Iyt fͧ rXM,\Ntۥ}j^iШnX=m9sq'<<R|8]t9)i™mg@I*wD _\ۙ- 4.E6Q<(-8A;;NDWڥS#MU|ÀH6ӱn3je鎥>V[kW!vx,uq#?RɊ4/~Qi9(k84`9W@HHa p]r!z$=iHy9*gFFc9'6]>WvڷFT}ߣI+Bl qaỸ=E[  v˴O2s[P1qUcj2';#&ϵՎnt7B ]<@ĖptGoe@:G^+ ]A?XvhYbl4QK$ KnsjA=#tcXg%ClAG!5!*4x{P;t|j WQĂ:Z`BSh{gS2 =-Ėh[%t?p@}㋜gMQou$fCF˼i0}1꾆[6",f&%whtz ;{뱭6e>Y"nI9#u7Hd>\4}@-0T?Zc{:J ο*ٚb)hY_xtWF6=|Ax4mH@,{P7!Ysk:Uyg &4Ǒ^{tqSG Juc2t`.7z,!rL0])M?/sKP=_hR4^}N1zf 1JčRB66G kw3&ԥnyԵco5waγ/Zߦ;n_ 7o֓kAȹﴦHݵ̥ $|t&E%F%8XsliUdH÷!1*f`:ݑvJ3rsl"Zḅ6cDз9S N}~  X,'g+6  vcaOAsҸ|69EWV om&(9aq l۬~ ϖp! gWÀ_{\ĿDsTЕ%p➕c ?/]YɝCZl- :uPn\(KXe$V&uo, C氇 z0Tdrpqj]3zLBaSp6]$bɏf4ÞJj.i@ZTo>yiL9}uߺM tͻάl41L v|(vqאɃ y.(w̱H#kUZ(Yܤz1bWaH ܤ!Ɵ`%Fԭ[Mu" Ͱщ]sQ :3hk;,dg9;84)` E=] gm)d:`c*zס8g"LS-fǜ#UDD,o rlLт$1:5zByxȅ]Mg^d?"@[?EM[>ڰ-/!mT6y~ !H+aOG%f? S ,SZ=IW2 ^LUCFbUǰjs6"d\f," |Q)/\$񴗝ys:넏8{łacHL"/?ztU[8>KeT 1+ fꏫ'ڣOPO.B~J-Is;dj\Ib+&\fS݅CC)߬>-FĤ$C](SX0A2.ׂ oK ' E@ {'Ôq)<<p>F6g7ZF.bw@./]-#vc MnO pB:}mǬȶZGTe4-m wJ`;S?O"+c?bҮvN͕V X &y5Cl,+'p. [q{u8TPwO8HT%4֪o$$%p(돂 bHhad et_RqeF 5.VF=L*y o 1FGdZ˛n|=0i{:: K &ܝnNȃP^MlUHfWPmEͮWO`)\ޝF;/jXT2~`z)$ DIbQ*:ˈg] >ul p$nv1WZ9~p*[P-i.)0$%'u pkq`OX#(>Q20瓧ZbJݻ{aX$]T@jHh)c5P知" >ۀ6V?zMB+yEMBltH4M&R\Wd=ڦ׵1>Rw0<>!3;x'B\8auV)#1ZH,wYB7ϕnHXXc ЈK ~CT2w@R>g~_xFtʰ >H~))%M + FƳloyeյO/?{ r-kX% ˅ 1\9 yՋiBrp1qFyqU;}șCÇ2͈(]}X)?^J2;wJcFuP `kЭwG&= C:M_bVli"~E$8Zwz#&Ռyp6Ik %\ʺ毮XEB- k^_-M& \]-pMX&4^n&}:I<| foϚ!3` }8%BNrҀ>4J> =.l[ q "AbOJVەEA^M&y=;Vm-ԛQCua-}P 85 JBpS6NQ.2Eb5TnЃ E(*^>rOՕJ9 >Xs|qy;0n:e>s醈7 0y Kn*$'ډ*d}FIc'Wx(w}"7 >JQ*^%lBh#MXQZ-19䠓`Hq&+T1|dkͣ⾻MpFD#ARӧoGQ$ 8%(|Q2s\u,HĘ9D X$̓qZW^?[x3{{+x/a!xU lPޛH-IƳtG0ٸO{WA4Fࠄ.#䗈X<D{}/n/z[>}۽H1m,dJ!P??fWQ^YãCr_4gX8WARo|Kz ͪ#yfx`.supIJ(a{A7(2l3VGaH{*_l+g00y _tOƅ6JX);wMWŚ,=YurPxIvQDqj9Of{`~0t|=ka@ V|Dzd b-Xoju>PjLf$l)%"ȑS .Kz|fp7>8( _GTĵ{<+цU5hϙ2R;z+E{#m0n&R墔R^Ok>XVWl޴3QM&W[ wG/뵬6MD|B<[Wa/`C<#:ckVdB9]ʯZt:0LljQ%W]pQq ĎRũ8'7}`r5 (sȤ,|Tnw/ݜ6P&Rx]:!K:.[dTp\ eX//E!ؑŬ8O (\F>9nq k{|l.,iACgFgaN#|7 P kpd;h81!m 5I[qn*pQw2f 6Wd tQ="N.nz=@'tz1"kD{Ѭ; ģE¾Z`R{~8{.ug Jda67ò2:l:Lh;"= oAi6ڶ" o 3hxxTirHC™?tFkM5IJikA.)~A҆(jiٟEaTr+~ ٻT0 QDxKMy4Tɞ݅k:>|guXf{Ԟ9Ӌߪ uvVEqΨlEFDȜZ8% +,P[ѥ-WT.C4kirW̮!R؄TaV*c$ C? O5S vWH䜥 c4+Դ%˕SјTWұ1)t=mZ]MJ։*黾өqV;ʛU$t|w|翭6d-l?kOfRӟ`jW~FU2M]JZX?TO,KnG=>WFFDeyf$if&r,7(ׄa$,bnFwc]fA,utgbnI^~I 2:hpwPpDRm9r4`g>髻I}4E,ގx?"Y(2ٔi*gLࢼj͑8aSҊe/qјh\H$K<(_Y;`}RbxMFFdC(b[ 7&5 fS30ǰ˳c4*@-Q4wrp\.PE9ftLTxWw1(80Yw`R;"Px{?47B~ =ؤ:k%˕wactL8QK TiwpV lQg2: 5]P@+6'j͇鉜U7CՋ#㖾bN1U插UKsJ>hI& X*{;,QĵYpw!MwN Ĭi+l`ʉ F$Oεট\Ĩu} x}>'?N! 2'vYuk([yneǐXГHG(˸SpAȟƒPK&F -Re|\OsP8DF/ YynFD"ez2T;U(F)A1]/wTO+޳$1\B6 Lb..ԇ\00 z^mi+]BBKfT\+HVKý!{by!Ke*4ft. C:.uhp+;ф5Yyh\N 4 doh|Hݏ &A*[=k5To4# [˞ tPcu4󓵹=r ߅2 QuGT9//9Y 9zWI Gs(ڗ)x$3MHMY[&GCh{ kӍxa q_vkkz$]>Ŷb׎ɢ\H4jG7MWf!zx~3sa->:PQ23n*Pz{N;*#7.4e9R^="To v/+"D {֯B(+ *E^ⳳ&2Q)\ToͰ}.N+(|+Ȯ (r:7ri=x.|u,*Nނߦ!v3WJ~q@o6;u)uB԰IYx =J)f0M=AU^hwU) g*D{5DC~F ۈ24 ^ȊX0v,CӼX?/ b"j{w;Td隑YyڱxuX LeeT8 ~fMo;!`qfi.՟Z*Mrwi^J'w'u×/FBVD4}perZe`l:xN*&I$ػqpvZYly9[,J.&^a7MuRĀHvx?!/ߋ'5E,r%ވ,4cła/y_!TD5QK]$"qVFqY YJZ#g\-1 34i}^W>6pb0or+ 57oD%t9`ٵEG j 9G>#l7j$#~˱MH!J5r7Q5x)t[5w5g7b)7$@>Ȃla9Ag;7TDćT]"ͬ+:LJBa ]aUE4+*5f-Q(K '+݇Gvu8:v!?YeZ {˝cS5 q_̈;y YȌ ^nFV=20ubW]y1t=VhVxZmMLբޏwh ;vOv0Xq^`!lt2"焯PJy^={# FuAX/G8Wm=Fsl(] ucͦvinO~j' L|\1)vy`O}!n)hH$anWjfL˟!" rT jHd.a28_jA kL|)ޅVPepMkJO}>҆WV'("͎ ܦ51;A+խzѯ-@&$lpFU3PYIZ6ӟ.s`xbiMgSxnXUloԯm+Ap@xduP}JnB"Š튣F3{T4k~u.Yg?0 mmɄNVZ_)eQo!I;m؏^]/Q0# R]E``7YuQ Zϔ-XϊJܶuY;1Eq%-r圲c&tɛ:9(db=Bc"㕷Hem9Զt;y=$dm.V.Ub4~R/sۭ(WГ/Rp[op gG9x._ =uZWq%nև1iqyᘧnpHezjS:(;O<,{Ṉ)BG&;6Դ'zJsIf]8N_Ҥ<1 lTO[3hmK0jD\oN!_*|+LFڈrFE@,# cy$H=9:Yg8XʧgvNrgIA/h0瓵qf.`11 ByG~VyD!eehMV.-OQwR("6xMA@8g}X@4ƗDS(Oa1Jԝ 9lBΟʴW41sZg~(woAC$ ϝk{AOA_˕[yOGsfI4jF>-I܋^`@A6tqS F:Sd.`Fg~eԿE7l*3KLm>† pF(anHzsdQ1BRnh I"T.lY:=C&"L4 @N=#_WW)FCТ6qo>qqBMxqzpYSlA+wX`)/_Nԛ'~bT)ͣhd@ j\@6d{',/dz/V*e@/+& ^_lv!CM[*7ZÍ@ȚSĢJ\Gu]j ;pz\$S*qN :zL \ o:h2ѩ2cV'-I,KA9;!mlN/<$.GRsY^QR1hQqAe!Emh~=:!f %xšRĸNՎuRvdz 4yBXȄ ]ʺ0dϞ B_L(KCAߚ\@we& m̤3 M#Wn(X5]ﱀQ1Y}fN7=7 +%+b `̺'EHR 0:2V'_<$-47W5lD22<lHEz=qjL~ 0؅Z_Æ496@0 "]n 7*Bj|ZX64ofKnz%љTU{pt N?\ցtܭPÍ,<$ '~_O7s (kkj1 O*pNkC(sM$5bj!^|YZ}f)cHVJ]7`AlQ|/R컠UTjGOI/PƬszw]{5(W[?aX/>:5t\a[%hV`Th=|`*,7Xמ 1r*ӗ*@*~u~rzGNpΧ_OYtXSDJ21R]̾/PV>fzUZ޿ѷ EWѸ c԰+׍f#'ugC97a E# DFŷ3V(lVt?XSLiL7[!lD8[' pBe 9-^u)ڑ74҄n~G&*8\@ʫ CZࢇt.+l37}ߧ$fKўCpkª*hۭ9a5KJO{O~؝_Ul |GOeZI:ϣd:mQl6Ⴥp=VU~j;H؂*HɀX+t=RCen$qo::B?7oͳb5.?_ی"!ؿ^8#qsK `T (kDG ɣx&&5W +X'KҔ7::'H.G;0>g8^_.q.s nK3.傟WPVk W$\i3ݔ9Ka. +NЈJ\4V`+ews"U۪7 u]iZ&zX8O4- :af3ں۶yְؒsk)̷8R,>>o XC8umn %pOI\Wάkeuly+ZZ4*قP.q٬}9)Ɓ7ͨs:.֠RT.5egUsU"M;uRbٜ5 e4f}UBw˃u]=VN[[̭宇TDHqxp]=cI#,͎FdPϲ\J#g7Q9*m'jCrl9_ۑ4u-zVWfO 8%\x,֞4f9b&Qҷ+}y Fj5'ۋ%~}p`8ĐOCH!2ANj|J1WMHPR$60Vh#o v|Wfo| 67@OHCRp-G_!ұM*\i{Dq& |ܳ΃O_[ 8Z j9:~ үqA:CAIX1LF8J@:X 殥s:xVrD w|P̛)ī!A'| z"9qW*U6=d$VQXڕۤ@s8mՕPo b#X@[JLP?*gl{0"ؿy $㹍Q&9?Dh9@}cuwǮbq~#ɟc)?ה,XZ+lJɠ7(d3{OǢhvBn*X$TLK|= O2+8$@3w~uN@9;xM}n=Xl}<&*MD*0Z[$hm$u\x$،,H< yΛdqbXco\V[y h*gY: yu>8I/ ]#L}iXs.Zd_&2Y{e$H`ԌOGEOBLKP9u2)s=S$y|=P-,;5xTfo$ ^B$wsLSN^3y=B)[r}V9ꤻm6?So1JR&#liXְΖJ§zNw9T v:3Op{!YI[4)$cӞUFc4LGH򷲴A7LR1|49b֖ ؔVp:܋h]4OKQFi4{Z6dzqxey|>hL|Yv&L%+P}R-:jMEU'd+ن֯:|t1 T! jL^N?sNo J(u u@PV)`XYআ hl[Ȇ,O:@q R-]# N?SfIٿE_]UJv]0BY`[KgYP{?' è"|ebƕXby'`[~e]þ?̍?H)гN '32v]('x>!v<׮+AĆعdA5mg}TMEgx-6[[4Vd5˵1m'%^b@'3Ui4Ѿsk[<[8!dQ |VAPif^{W1)135>,ˏ'f8? gb+##aTOcYZCßhH#gS\sbCX$kպnEJs5 uPPK%YNF@x8D*q8 _Id,4Hz9m9I85fWazHM+1R))Pn-xЂXi]$)ZY3&\+WZW=}B< V?afj~/899 N4<W/ AHI|u@9L'pewF1ʻ8d.{}JɵiNƒB_dij޳aKtmu*JPn+(~#}G-Fm)}4ט*!\nv攬 E@Tj.r9ԅqOdB.\W+fdU \t!s)DW0n x:gς5wST8fir&l X}8lH䭹F\ m/pnZM>gbi@c"0GLdP 3ϽqN"19t'^3MO%/\#:Ac|Ȣ]ְ E8,Y~t `'*&;pٳ/Nf%tnd[aN Im\|k8$&_GxG)PV=&,T"[+6Cjj1q4JqW^ZP &+W,xmeDԪ_JG2yTE(\y3FHGZ"G6N؊ea/GO1Q!cW*(VN Ǖ(%|/0Z/B K%ɜ{Y'1@(A=*ϾQPC?1}. 7Rk{Nzڭ¸GRK[o<re0kHÕ)z1BC _rUɇl| N#bZ͟Grr #E*k7Jzs XY% t M; 152CS_%WtR"mAŨjgLOxnФV}t~=wAQ&SεA >Գ" ÅemU 6L|&&a xn ` vm`*=ndg&̀s|+ߒ434i#.*0ycd.n'Cbw&2S_dDζTiK8͝uͬc&Z/1hpFBr[ $ih 7潏UOphƶcH);:wr]M$ʒFPci)9vZ@r 7׭}th%>lt&-'M?'.zpsQ8 > 'mZRgGMhޠ vg?wA$KNzaWq"|%@ Ҡi1&64[GQppέjMm;!~%+==WOH̘t6"v! $r~"4p@ԿXpePhJ:䂼Эo?:W7Q qmoэDϏ|΅/-9HouL_У!T1݋;&p#`dr) 4F`3:[Ԙ]X `Ә_qƀqώʈXn.dBf" %Fxr[ '=P$WekxH@f2w|=_k-AMK@ym MAs^F~t ~yhqS@ #tLE~kы`P.{x믦1-c~)&[83ڰqohnP]"6ݦAĽgNA(8 `YL*7 DR;y/\m_,dcsjk Y݁Տ\{ƟDjWb;9\>w~/ĮTDz7f*w45 6Ɖ$6vW EU6]?V* fmII $:Q5Z8,%/4~~sMxa 볡Z~dHk7ivi1/BT+U٪Oyc#>D!R-3G\ȹ.]=[LXc݊NNYz:ŏo V:_QB4!ڇ"MURAwyI)=q6k(*C\xd4g30z ,(C9b G#fmm^/}A_;NlL&,W wXz;OՐ#!|gk.JPPBkD.xh4W8`];ҖvO| pxG8<u\A_AiKN03 ię <q$9d42 4:Ȫ־$}Ҿ7'`a O,!2 bvKR* 3Q}<`mY-k&֯ .*`K J==\dtLj<ɑ-х v 9dhVDPS裬S;\`xf'kC 6~]3o$lSZT+nx3J;;2G*Z U;E)[0fs`0[?\I@mCxas 9, <DAMjkk(<%:AZ_)I" ae6SgAfC!";⛃yV\zUFFD &čPv0p{2J%XF@kN:yt jb'.Ţ I40#cOqK(hG*n7LxP*. 84|*Rٝ=xJXʏ Vv/Ad/Sz+ ƅ"r*S`2E5ߔ#k=R`U{yݡo )ykߦՈlEsK#*K͖}$/a;)c3YC܇3F*$N`C!#x4Ĉ]lcN|wњ OkM*Iɵ a& JW{ d3Ld9 mGdeNQ }$9^mY^r&X~8tǾھ޵Z醃t42.:am5TGe#]& &jaFߟB CذJZ̃E8% B1Q&&VcQ_Rb`SIĺJ/~O}N!?,YB;YQS!Msx?.FqQM]( LT{jaV23X!'|2E%x5/(Ra. ,TVK} 7Ѻ%8GkSή- ^k٫PNRfCd|vۆ/2/r+O8v!tvwQ0E2Ȣ)4^x܎L)ʺ:\}_seSN^s&ǿg7mvv+ڶt&׸0%RQ '+2B"D7iuJ|n5UI ٰ!W|D ˋ77]e9J_ս""ũpٍz-K]aVDIFϚMȒ؇f1~#r0̳n-7.#MSfg_Y fAl6j3] ~~.T8+k?dFw Cj ?łaُ|`l{K|iȔi:<BT!^ Wt8iU8w_| FS~\֕&HnvAy+۩iӧƞ<h_'h~-kBБ]&C>6 B{ũ *\W_`ǣŲnWHN;?ι;5E2~a,ߡ= qDTTĄmQii|9^gF6kc#]159WMLyʔ\7 nx b 2:2wWdKb`uje;o`,F=/KٟasZ囌c{'8Uk:*䐴֌7g˖}Ϫ8b0^ڍ8 ĥm9ʻkԫO-cg'{mţ%k(|=GF$lkEH<GhA51)9T)/FJ8d wzL% ȼ4}g64O .m.5 LA[IB ʡ؜s05%Nu~RaJ((|3$% W#bY{|sUdCFZ5x_nA{bRgPj<{u?B| ?Xz{:ۚETgsjX5`M$; e13FA0i$^Rc 4pvUJpy ;ݿ"eTWtS!ǹ]FѤ8z( !-< ~ !3%bEń o9>)t+$6P=m)WcJQr2(Ө>sP sn?3`63C?i9TMKbE(GV@>QsrE aGL{nza-t4Q4Z4 e8E=ZߚbKߩ ; "$L«7'6$,5 €މjLcƲHU)B9@)zA`R#AqXSI |<oJ곷%X4y [Q9W;[ycs:#&bNҢ_|TIJKXB*Ӈs{5}nI݊sɉ qkdnܩm3~%W摿uͳ}4Ib"̖+سAc5Ntdfl0RJ47~6?$jpdnkk ?'#xgBlrgTRrsRJ*4%k^!dž\WL{Yh Ypjssw=>z1h?uԮӜa ")jVdYй#z Y<Ҽx1'\3 %?7Ij\ne≬!F~bxDƕB;I~:x>I;s.p?i)]@ϫ1d3=^~-۬ga#i\8wLsl-y t_WĹgwv(V]2f&KQg8>Cl`9SƐQ7 &m6]k6gK.ݝ0/0) *@O,W/?.t>u2HɁIL/C1~:戬B>(;+@AO ҅3T!t7Ή2fhgI O:Q#e NIA>5Fpv,9)\n[U(s#kl1ϩXM7e8_U< ̧0F8s_4Al)}`95 Ӗ}l!H߬)xƪ$ ""E5TcRθmVNa ϥk=ko @uT>g])έ/o7;MWHGdsw#>swَzN!IT; 5yR]~+"|K 3W,P'Q,dmnN)Gj̆zb͗'n=Q0UŎPiH?ϥ/o2#g3B/ʢ%s?ĻG&"z}82eKw4H& )P.O-;se[ Bw~ŎO+ %4+GkB,7d WjP*6١1d)'NSɐHs=ϲlPV{"o]dkR:)ϫz0o}"b=Zb '# zGPm'(o9UŻL-) GoO֯bXX#c{)Q:5Y3lO9.u"4퓛lsOLN81sD(-8 wvmd\kaW^7xl}0Ǿ!C2+rF,"7rEzyj%˿[d$Oc aŬ6HLD$r e|?_p?^kaN}Yr"jbM#? xIz"CAKSQmoj{^go$ B`/XA(/,x\@mLk(wFKx텚dk36cuH󯣦NGNR:H1KrQTwnGl ╨en?ӄ6sJ*R֭~ۢ_nƕDٱHF15Ԫ"v:2B>A2iW3l)3%C4{xY7úuXd+eJjr;MjHh(s,IoB˟c T4>|d0W0z~ľTGscU vf7X2: S;|&.1d1ig# #Qf:$S\%txl6FшCt%%>״fzlXgH+'zߺ{"/kE< \xQ0RT<$f 6ݍ* $Q@01=V^s$-u fMˣm|jIh2q0sZZ9,RyR>VY{)GumbHue$o<ɕob%N% vTcQƥԂN!TZ%tWODȜBYO7#&:}7I?]DJ)]1 ܏R3i`hhPs+u$geY5{fy"uN@Cxt1$Fy ',iLa2A$*qC>ݻː̈́ +gl[|-L>cpw Q6g_#0]$I#Uctk"u@-7=%|?5gYM>ynq{])2Cʎreg2H(?Y_v\CEy=Ge(O JsӪKcn Ӣ6Q!ch ՁƷr,-VGFfO.*Qt0-x`v?;._Ag_'g_U\>^/X%DZ-1 u 3. qPT^ga.X0?;9-6iF hkq|N@gMc잹Db|fr#Áӛ$Y:w%|]ئP7[XM6矷>_35^]% bB!K6OF&K+z$Ss_)Bʓ[鉸==S}Ғ ^ek 0M+*QkȀUS7 z!$RywNSjS7)+jxn}BtsH Tpʿn$V P "*PR4h*,`c we? OVlId\Me,sլz#>D]؁\ iljF>򖏣ji77e@B'G?=&XZhÖ-z#x4KU'٫^N!bN){L%s6gu 9 ưUtoҩR?p `S:5^S >Kj쪢\{&r,OwcMG@ztF!&.7AkNHQ K6GFLa&4é}wŵӒ;.!ؗTUP⩢dXgd.۳ޭ_ɫ\4V[ң 5nV`.+^)Dd`%oQ.FQ6DHyĆ=7mj8PLφF6ලKSMyY`A}ด<uNZ6tSyYi.$ڀqu$OBOyP> =_ފ)(;$(;`Q}{_ץIziNC8%/.IWBh3D'TيzTy=jI  źEYSYAm2C~xvlw+R#N!tU‡ЕJ:5UD4g]<z?ru4g2[0!ڋZ1PjsJ&RF{q o_iSZ&2CT#p 9q.)n3EuW [=qX@}/"d->¨m[Q~,@zV F捈|?6 .KeNT NR*"9ɿ_*Qp܊(SXupEY1yXf_dn~:JܠxqWYhDwA1RHt >݆1WM龜Z*GCؔqw2^Q>9AءPF{ͯoQZJK3w<4uа2Ql#I&6 @i,%Z+Efkz* N;͡vmE1M:1I~HnKk5Meh[<$!Y~Z3>*e[ 6&Ya~ܻ׋s@DOlCLgcdPiN1mKFp\Vi0(_ dGRj0P?T~kA%/`'4<&<;wʠۧΚrf΄ ezv.}TX0ɔVdD+ogY@R&EGM2?s[a״S4\`Bj%Nl$&miOE$vSI$"09$TXQOC300)=J2?ߛ Tb`@Wn: eAl`a+yPu*ꗗ09) qoԄo/?=k{ev?$ݻ qegI3 =F؟Op~J/ +=˓MPBۗKRoca;/ݾYy{ &=1f=rgv*V/&:B=\+/XZ5(ADց֛ή[.rŚUW}V"E߲.Pe*%p (q7.huiv|0U—7Ɵh @AoF`Э&Y6 q<-GGX(ե[afZ]7U+/-@j-8RAK7LuF_;ޯfKbW1X)SpFR_Z \D:E.Kwn}ٌ:y2しKCP.GԀ(Lj+,. lWqBsuYK3r K{UbV5D~\sq7Y9gK#r(]^/vː!a.(YOA]3;bn7#m~bSMڲ0{~{1إD"D֋j(t*NC/ڻyCm [1jA[,~$@q76>:,(Ato2e>| +IAd\5ǐ*cͤY Ռvz'#m?vndy7֏vBHV.3w*]@ޑDDZ?_J<"$%ç Ι:צNg+r$LJye a/ Sv)gVcJR`4?n^gu YWD=Eŭ .A3A՟t宛ܻU4<`+PuI΢m&/qq?ZiD!`;[|&M^Waź1(ny: D(2XN"RVIVH-c5*׫^(Ri'Қ|G5o}-õi6]b x?ҁt!AQK%TR똊[jCL! ~LڱL?ԜVbG(熈iR('䲿qmXDв3r4_hz`@*fM [oxVQ9ꆕ#BO?/%%9{D)1p, @f %PXcՎ~8R]րۉꛘ7?9r"TN1VzW|x $E]] 9{ [y巔vnj[s,"UW3D8ObVю^Hu_d6Ȝuzn.v{MpnQ_@rC&> ~b#\q\ZdLiuzGax*1>_نrPI FCDvvNvira$b^!ԆYlb;D#n;/jRԹ[9ld6ޮND?౟_Qgg&tb>n]od>o_G,36x6ޗb6 T~MP+T s{Wp G# ^ZPDO$c0y \ r;ѕYS-~,[t` ~$yȼYpoR٬o`c_ތ 9 WȺKD7vh@G~Ɋ4E $kJ}r9{vsJL0"TI_rAQ/ykйG^H.F̝0qW~/M $O3r"v\ﻖ GGdfhT2>r!ڧ0p8d5]pa Ʌa4XhmŽ/ 27ȹ"YH35OhΞaBsli$$FNov~"OYnd\\ٴ)-쉁5%~~lpHJ.K`_UL<4~Ͷg(FCTVj`x(8!xKwyg>..뭮;ҏ{L^ʹĐy-BhpPOJ<\9 J;{iGFElV0sLZIg&V;`!M\ Nb6͜4[d`V.]ſK\6 rFUeDz[_PNG\]AZ$=8o/aQR]Χfm$L{I {WlMoq8+a9g4`R/}NDK٩b6])%%sxp¥Hi'swґqӎ axcvk/fh!U瘠 k+wL=s__oT" Sݤ_rhQ2 bv' RDg`G;hpj&lZ(ph䏷&^LOm QXk(]^N N0&ښ&->LnN8]/&M98>5yA+ߚx{>lwA̵uT۩1WCS1r0O/'K!l8KͫyE[$'XT2hfcPm4i1?{Wor|Q4\n(_׃Z;(0gXS l+x1QXkbQq ndN0ac*ݶDU֡ ٦h<|5󄉚}_ߋ~ "a^vX4'kI &K#~w_7](4'C_m|@M癜as ;8Ϫm9OՃBfCGK`vhL_YOK],nb5 Hb %ڄp&εw6zuw/⵵-Î,LFŦl7:KC$1!f623/g`%dYzrM.}6[ïpܯgqA1P>(L>P_fMVk^j*!#JMԸV#DqiFp^kZ 8¢ 1ĺ\/WR-V|e{JC0aP=fK'MFGOĭc F/gdF?7"m,ZWK p@@_v-z>nʨ}f ;ns1O{4nK 3t#u@󞽮Gܝ>~Ħ2Gj&w;3#<4+.]zd[r WҦ<81| K| u)pqՐ](^V襃n7ymoUp{< $VRb(j=NԖyTهSpFz % b$'!ϒūZ_:րF~>K HNS&.gbcʧxb6(N±y]jz:&*2 F.*j vt L?<̚]ѓ-Y*(Yc *i!(*j(\ yNX.$"%u]8~T QqCv {8ZPekE)[jq0$hw` A>l># 4;?i+{ES& ~*mX^7QA|fu;Ts4cwJ<"7 x0vrǓ:/<^Zކ P\iW/|ǾBwڡVkLAzq,,1KH w<$5%O(S,Ư> dݖ=T,Z0l1lzXiDNrH5,S.3f۬r0kcD# gnn\"hXktaUfmPcx&檏BY0\sTNU9WvofZSD[ e7%jZ6qeIDr⚰"[Pip8(sf-OGհ B$\(~瀿$B"=,ur}q ;ߍ.54&_x?_Ž|",Ҵ>VRA SC92`F wAE\d?N,ͬP;QY(i ;F x'3S;Yh)E3564(?#C`2-7^S++:cUwh b{,(X,4`FM;f]!$}{Ka"6KI\ШhQ71"$D;-ik۸UYi-3y>- s=}!ucXaBuL^PSh؄pۊ/$t_U0_#i 2e q2)۟A6rtu*RA{yH~G44Mx;'r4+ͼkȍu9A^ZBkW 8VWnəqxįl"6T;_\ژmer}V`rPzQF3/&{;kR*qBCbeGzK_|Wch_Kye/:_Dֺz,7Mu)Êi#CNL]V=hAWW; KTa/Eht9,:-XDe5-ZwR}ex/PjA"Ȳ;,*N WںO~?a_=OZc)D"^KjA^E. }6wUDbˏ3?ޘYQp~k/LW/=+r`{?XyQ\j_/8*b$& 6jy7mY+zqxhYiyk L\F<%EIvJ1efk6 v oSD(Dkx`Y%V4!!LvV#c"m@~E`{JW"n/ &"Οڑ&W&Z6—[u zh!SKk܆;mF+W絑.ꊭ= =H D 5FME{^*T8E }<ӌrQg!C}D]l_Q lVO(wL2Ef8j60j-[#/h; GW/2cZ4-u}(4!QHIGWuF\ sx^4};Dsן=yDl`4[H'eFߴ.Ռ"/Z. <*w0(ԏ]Bl mV~koUT,~Ti͛o Zle63#Mh!i}8Pgg*OOx U_p+w;F 8G[DdJ18$)ğ־Xl}Gl÷3J*Ă2C_0edDWw>mNАe2(RLM]/<ɓ診RFR'qA,jt@uAo(B#;N LvshZ,`-+HT*s`f,U]%RρX[_KdBeؚV9r]rٰfBiI!ݬ&m)Pfyxuel~ILftPk"QՇ•uX/Aџ~Ctέ#.H$ޥ廿>&ڞPr}p^؊;%&uŚ;O/-4jJu%>ưXy? ,½\9va!mHhG(H#F{^ 8n8U~Y2mq_ܔɃ~ՌV߿} |3{$f@שas{d.1 MrGزMZfO(TPn#Df+aJ '>1O V(5MKlz$u1$l>WUK~oۈy^ =3`0#Ro2V~͖`'xGs#*Tm迻߃t GfV ?om(W&w%ЯA"ÒpۣVp")}{QE2 {wc(GQn{x4:dΪ-r>P4"m!!;lW2Aqs8ξ .l(X|Fh !㭓,Bc5XqaߊO9(mtfR^G1DlD**%ktu=-]'b5Ir,Hu^F Gn`cP-ygY@R$D2Z0>&A!v8.͡ exfD @Ľ՞SO}[$ia57uȱfe@aXc27Q#mu⨀_suCQPW}\(~`Ӳ')}BG;HfR-@ )~fs(TAX?L}[qBN-tsqdU4W@{jW.- bnUSCIzQr L 3;Bj}ֳ6Mk/-|=P E>x{TҸaH3d9F,anfDcfLLdWFwV9 \%ZH\P:,R-\:B"'<&~QM3)Ld{UGLT A% .{b{Pl}_!u.Eg0Z'U 6s}%=e#Tr}O%cIzo0?j[ϭN{gw.sZ܁&2H& 'tu [cJMdp69==q"ȳav1iK:#/w#ZicǃGY˄$,։Wl:E/]I~ PO}fW1fn2.)xyQfuVL"s  r73ȻgX >$ E2N@M1L.,8&Tׁk Mfj́є3Уx)Z;6ʷQ:j%j{t4?2+aV{D-6 sPXOQ#IC::njRKO/>Xqfl2Q~yw 䮋YlRTΎ䋷(\`x@I˴59_7knDs eW2m;EYe[/oEEf{Ă:e)Sk*,`FL&?d駻欩ݭpmc[? zC?6A=b, $kq FpF؉XVC>o,򼦝qz4Fl38x*yF+FIH,RZqwn 3b86 wMj1L435F!]kB毲b K( x憛Zó]h&SX1'O`}Z>5R$z쉼\rPQI5,zAl9Tu B1Y ϤlM6P2U|BQ$-)C4ԇ*9-u0()L=pW>3EqBǴp2BO-.T3VϔML?Si'(5A}I"8uq5?*7Rۋ{`-v zekgQ5NvK_e#1?Pi?  WG]a nmS|,mXŁmgN)M~}yH92%'HR&֙' n%s(_^4itIeHM>!c"g(MRE3֢7Fi!"DK _%8{*3 Z29*8`+jJ^?2GB 7$&"p bx1Wgv^yO 5<*Kq2j6| "ʥrcT5*~yYW,'лg{)dܨҨ9&^VSaUj̈́ Xg֑q>%EdpmGx u)b 7p$>]pU7: :/=+C-[<9(a() s۽yphC G'{eszGv*rnDl4'kUAWv~뤐+!JRO'[$Ei X~nďǞ][_a,Y՚J=-ky*zS[8{s#m1wgdo&nŲ>ARN*bD (5eJ@7HO "qԥJp ޕhxXыBgֆ_8)[@ܹٗ=rdS>٧!+uׁ=TxCB ӳ"|W%7O*;QG˚ @t\zGL?1d.fUeأ7i=Qɽ&M(O0Zw5coFq]Bf9 pԶ|Y tЁ$Cd% :/H#VQ-ug})Upj\Eibm{tQ뚷 1>T:>V kPYt,qZTfۂF#Cs gf?ubw9Fu^iNl:.(\G9z̬?`=\Lrk L Da کEFqG bîpӘ >zAcDjSJxutT.P] OQ V90ehC8.Ad\>lwG{ ΐa\\v9 eD!TN}}t;j/t:N gn?rAC)(KM}@|͝FeNy.nV4.SuKvnK,[\- VT*d 6'E?wGV..ϭ1eM0 #뒽#W0 Moi$z*ѮFH#"R<##1!|AEӟ~hjW9;*ˑ6PNy{* w-hPQ^/IqB?sF ÝN^6tfKz$֪UfBٜh/d\N ;5{AB)=Orr~}X!USyPdWi6Kk4-F&O]I!?H8?B -< ;1oU+X8~#ÃS5FcS}HifjH*h‚LvSxPke@B9PcL|=@.肉jd=l6mxr$PٝCD.(/734"atn.”nwhAmƄ>}rvMqp )pK` '!M\! K8Ȟ7932TjP`$f=QVe~839N5|z^}e))CGw~"#A[sZ"Wev^)GT_&XmӴkI}/GaՙcU RE4 4IY<&9__<p(k`XPԤ[T;pR[zTҿRIBuFn=u@+k><<>ۺ?k wXgl><E~:zS^0jgm06k[ =hp1рu=<+7$ -b*ja_ Ž\>G]g22J1[3C`85m%ӉWǼo>Tg\ XUV׹%ZffI][fM i?6Sq|G,iS/9VJT"M%l{ 7/2J?h]zd6n 5e^ :·n:8Uk)GoSW&g_U{ޕUE8icxep=ҸK C/I:P~ Mɒ9f<{Ysח}W,a*l=2nRXw@mdu0Z}u 5<!'H>Dn2bq-< m3~y彾^`DZC-2cLҴ_SRT.0?Kq- >/rr @hf\x3l&hI ̚{gvj=Ad؊UF9Td=jDd.w+xE6z6㺷UZ43kx.DŽp`Zc9rN;EF6PD0r^D.!g3pd@S֘R`[v,+ z'hƖ҅K+pM'.:SNw>kD;E6&@ I[T9v)Ȁ;ٳzQ P_t!YqA뜮@؆˫EŒEdfgqic Sۼ1!Mtث sj_MW29Q~Q:72뎟=d&YgWV?C]G)ctlm}3c>ב,DS>L_M;Ot :S; :[Uolfʛ't%窱H dO:Cm \m;B9ac LWKVRH߸a\0f$ablr<)߶‘X9f[5dyD&˨2@ao!aU@E0y'|= ^fy).P;o ‡Iv<|d؃ d$ q;>,11BHoVXiF,DCQF8= !INLh'GJsKٰftC{ט*"ƘX@#1:";֙e aXT񌂀><2DT5&?@j .xO(p~j~cweX *03JmL@-qWC$gK]jnz@Za=M ba5V.g{^E۱JpdEx'Z!jd?; c]֡Õ2 dOs@Y;eͭCMHP|%;Hn3Wȗ-FVb.P f{'m',WC%ReqQ,gzn{=<hca㌨lwI,nWD`0t㹨ijY(D+;y+I>GAc$?c*|Y"pB^:hOk3Ѱv)$LE'dx,*!ݒ >,9qg$u5珂m&,fVG 4eف`+t+ŜM$k~MK `͍f|=*8M:P"O4Y2jxA|턦0#2q ̕[ MCw]pljlĝ{H`9x74b$ -OeJ4| h К:w7O$zs }Ïmz*u/)WAS]/HhBWnb\{&@l8P5MIAQ09v#k׫iWޖԬ /;`yA:F!>8K\++h[a*9O![jٳC `)$Z20O]ebŴ~!rnH[90H]b+E#o !wW (I#-)M-(6J 7_uя.cwhTT9ՠa91{M{.noU>^.@_<_OұR:ZmCܕ:D_P+:O9,vզ]$u/챋cO4Y w[qWVM>b9nJQBec{]zZΚWO>y܌(Nf-oHQog.KG! %۶|g7Q~v!"kG=G=1LD9Ǭ/+NrإoB-)Q ;"v>_e-f^MP)|1Q.QWZ|&⎕1݈JM\ l kf4SܰO}f9m%!8^΃d'2S<>Sl |6߆sap w*tCՇIiчG4WcLy(^zqm$nv3#pt :y1m])qF4p€0.t An[tkS J> :Ci7-+NqU>6g4j:y"~{9V{Bm3bAs) bȹeXj5^vX;MKSR=C`/ ܔ5$]})G2X:x8/HLJ@T2/w,Gw󹨰3s0)x'iɸp[0Qc:jvhToPg6YMWq: ~$pC{Mu3Ϊ[ROPC tAv3;4`-p4-*M b@uȞPJY% .⌘]8$&!Pˮ>o$}>RPuw4\{wѾझ5=LH)?HNLQ=89#dAUOljbYǗs(16[8{6zzM8TecMJ*=度Ln(QWZ]B>s$&G(6V)ܮѰLj u$.,>/p$`cg v.qilZ4]AFK0OzPT%,XTd+*Z*0Ph{0N܀º_-|#3 cfGD:WbeFĢ!~Yb6d]' %ح} qP'|b(rQţ5(?;|H|oFm)RZ>M˞T )ODpiU^_L7a `kщQZ٭zqݼ#g!]$tŋ1[ >eRP 6!J቉fN$"ḆZ][n ~s\cvj}zW XFi=7jtB7{>'GO yĤNΗX`ӕʍ{VJ9KX5&w%KFK|N2 -p;&2:4 Jm"I)]x}aM"гk*O n2bJ"P$޳oE|-~5xJ{hcAIKHc~N5t.! |QAm&3(]Uk_]LƻTD=Gq&Nxc61ݽJbt=Ԕhg|-)E\ql& ?@LF_'A<q)ێLghCTIGR"DUw+Pu2HI,2\/"j{U|\u)LW;,Wj`6!8pѺHCLpN2G0'RuyuWPRxeyaw-4y{ne%Ǵ3͘J"F|(+;XC{zֆ(}hQ]AaK=., S9,X4 0f$玏C. q`-DKMkKq[ؐ-X۶)`3RJLN"_f(H O<$mw.NP}>.d9|L'=$<bMj̪$n}<5ev MSIx|?8LC2Or̨`PlD !U)ep㵀I%n.v1#tE)da.sMP9|w8knQL_[x8msS %aZQ\cM94;uiP0 ސ6I?T^/ D+k #X0ǺΤ9zf)GbFkjHb'}Etzڢ{o>y{`2/!1ܿVpU1 0FqE>Lj\3<}_0fDAbP4_=7kIȬQ"iR(Ɍpx)oMVw^r^C嶡 n9=6 ji7~ЍNf=-zQ{{Tey,{  tR3l!HA+.5`Ro<6*H׫iސٽe}Y*{R|GU>/cXڷsPM/}@w\ k <1(# T!gul$F׸,t2@IRLo ٯk0~G"S SoX$\ 2_\ SHc6  Nkްx`hI#N M{*t5^D'GD?FÃ4< / |~z^|=1b̄TCcܟfXnOgą: Ϙ;+?>=~DGa裼` nӢ)N,Tƥ|TT=8a/~WzQ5 Oae7GGz}꙱8tOTT{TF_O/̨䆀W2k[ "ML[hRěfifN!J~"Rx?d8 28r-)(z +5:.]*{2r|}}*y65ZQܞ#7\kʼIۏ @OܿdXmbzEq ~%oj?;J\-.eTȃJEKh_}-%49V^zgyslP|\EH7,z4຦:es_p"4xXZ+Tą;G~,Gtp I|W]Vh3sx9[ۘbiI,q/FVpaR.{ڡR]˞~wDZE&qs/ц ,>w ^ۥl;KȝyT -"kǎݎJHdfNąV4L:1ҭ&VAmptpEElL,|>'+| N`,EEqC>H2.֠r Ibe<e”suLũ@d!j+X4j%l*"{̂ *(Ba[(\#!nvDUoO"ŰHTjRSѥU$KfF{Vӓ&ja'PS*-7i)!{봼SY,-9K kR&VJTp?j~@h b_{ xY^A8XOr-͟sUL6 5AC?'MW>>ς~M~m-a0|۹,*(#%UsS@+Ӯ9@oL\osu~'nw Xbtx1ccC( ~Ճ+ u>sbP<˥9X7798NjG<3gghBp(Q(fwxKD8I<%x[0~ b-F%sK,f0ƺhTqk9GԱ-\a⃱]JhME f!v$hgSGCM"p T:鎢:fɣ=/'GqD }"T/؜F*-6"$+}.1,y"˭zN{DL )_Fɡ4mmL|H%cMCa8 )YKm)#|ktP*[)72m)2^2Jmh:R2WfMKz=BMM#&hnOkr )ڟ.+L,'@vyUD{E9 b]db{&}SBMlRG?h_ +'ğ?ÒEdq1 &y`^?=m:g']7 C$m82]2< Ub9YJIDYpG"s΍0k8~.LӚe ~mvȱ)G,4`-R̚)@JuKͺ8 s8kv(c9TԌaNֹi,JAqT8HlX>CsTtyQ{E茎U1"Q]piR_ZI6wr{l" svLxMt< )hR0(A`y/y8[z[܉,Iѐ ԠeRaKQ;8\9u9X/۝'*L$gyћ؋>Վ+8X:k"QK8hiEJ̥LGz4\P> Gc'~-,+ZQNoܾ:} c+ 2Gğ)f,XH-"͌p-Y$}4‘F5HJ{.:t  ICk @[tڏ~O#2T\B\ٵG@w/*ywwxU$Mxɱ9kzHWN֢]HAא"^KO7kBǐ/.zB ЇhЊcD Ј`ϑ-\}ɩdSEdUoJ&O‘g@ZlNN+ƤI@[&BqxCѝ$)`h Y(q|)!̕أ.zLH5 l bbhC8;dY/葮_iǃ 30۠KP{;ݑ|}eQru{ Y1+1@>l$tE2|O{7Vz@I._{Al@mN-tˀl?_PwOx&ş~X_A1#0?pKțǀɍ-iSPD E`k95lCCp aZe>%/gx;)yiF]ȋݣH ؇gZPj|JeOydh06Rs*`)ZrѵY`vӺ#O?s2*ﻏS'΁PPV֯!"h.&A0# iƆ{H B V*(;yH2U#D䣲 2ጳ:ޤѯQCJtǥ&A;@OX7\b}EZC  CRdjzA~+j調}wنs?}Uۭo[{G^kG(|#tܝLPp h2 t/F,.Fuh-ß1 $ ,3!j"O=s(FPH:9{YN~ 2̕鬙4bKy"hF FF1`F Drq Jge-L: PV3=DufIRJGiEf)ӥ!8vf325 AOZY|#<)v+3/SQpŒ̳ʗė!ĊXXh]Ey.:ugÜS`2.x]>BSP{]/r?!ڳp<W`p[603\i<\t7ų))[A)П 6Jab AN?y]xDŒuԼu5*o,K;6YBd^} ;SF/tnW U56^F8hdhۉt5Vi71`lUqsډ4& oR\'꽊xگǣbDt0%&We9~X"/y]%Y.7pt\#=of@Eo0707010000000b000081a400000000000000000000000161117fe800003db8000000000000000000000000000000000000002500000000./usr/share/man/sv/man5/sssd-ad.5.gz[rFϧV%DԗL]mҎֲ"9L)UhAA7f W (Yhjw=so7?uoXu:h_ff1{"_6ZT"Ƭt(<NwDcoT2ih^:} \ m\)Z'rFa Np硞&{!I;:N&;ul)HsHJLB0ͳe2ĵ~Ƒn'sW~_wox?E:]*J3#'Q[M>=LQ!'y5drf?;o$e6Gku47( >}|zC$'{8 Ul_Q <6z"-'\%ukDhߊ=aHEfF,eFHvu(?u.īˋQb$`4?}ǚf?i9H㶅D/t;nj Jsf|8x8jTH(pFG(gQgL\x qk<{Ig_^@@djR*9`TD(ſ>;}9x_ZQEO8Nf4sq-#?$`x2YZH:'87A7UiI)#FYJH?cj øKL/ANzPX>5 fx]eD vD4z3vEv2مLd|8?m:J,J򫗚r jTZEf1x R9h "۠9z,߉Pq5;SQD!> 9j,OBs,Wy,XfO,J,ntrC9> ˛eOp-e4@8+g'0ZbjYjV4i>GaKPi(P%4JOiX) ؉|.`86Q +3#Z.:Q@kE#>q W6Zuw<&#gDKD'Ig̦Z}U}[[Y|6DcO6B7 Is P!9Qh"ڗ&(#ZW!UȈ宋^w;6S2j}paRtZ')tk#g~5PjBX/ʙ |%b*K 8հQ)ظHkG_q.' &.4Dj%MT8Lq[ͺg=7 rƃgȃD:Ad zOҔ72MphD*IUēX˵\Dp=~Dm>B.VWóUɢI<2J(u$u ]IL@-HE(abUDTSOtgQP"ovJFۊTQ!|l gČ,f1=- y" @ʱ*`w鞘s[{ݫq mUb6"̰4B$T2'01iY E'%1{V:%#cuDusW0 W&[B,=4o//^ˠ;:vG>P{نtS5ۆ~nuS\D-G%X|SH2r ,H=Fd#3TepI0xne$2vPɝN+c3.%"Tb8e *N9]M$`艇n]oZ5Bܬ,=Mַ/yyvZ`cK^ߧKja<-517nX0JbbEiάb69|B5V(LR^(B\Uٛ"$6LE8LF\P˕;~AM!h f-'پZΘpr>t c6c|"_+(0P68™| :|$nP.Ei(|u,CE֊%=?f*bG7?ZYtǷO&sCΨц ,4 EիDmKjg?,֡>C"NKII STJQ"'Prjc14I BXƴOU]Z c=)EWLy\IR,7oⲂ~r6/j[s`U\rͺՀ\SGFڨN]j[#r}Î#߹s-$g޻^i\őOi9!US.%ܙD_kD)$Mc%ظɬ0ZސRx?pKO$uL3L y96ciO"_=j|"0b ۯGoN2 ʖK􂛍]U ")u(PS/=8 [V;;b8xφtt*R+&mQhF8C8$S1t,WC/.]L&U%\dnH;@\). YYsY#r|[Lxjh4Mr,`@Dj!Lݭkwʷ*T"]qP +mUychuž뫷As}wy}FőK9b)&fʢ&\"^DP[V8 JKBTskJ [&",;XpCC9aٮ;8,WrZ☼ق됂AKbt87) S];3!0Fzn/P26We0nU`;4RSꄈ˳O9pgyro{FvaomU3,6,)J9Tz%(QPq!iҘ霐=b",1e5>b/5 thYAq.Y ‰{@D9+!6lCnL.cv˟&q~^nH,FßKZa4_utt8oN}Ȝ3g&r߃iv!t|F0Z.%V}mH-ȡ`#2b\|q(vHn3̏c~k>0)7|}K1ÅN-rًiBKԋi"| ~[pNE&<=b9]>T S,,vW( bl\dk-I :T/(ؿT2Uҡ2DԢl1N,yWe>чHY=kYuͥyֹ6{8m#^6溪؄jBX#/&obDۋ= ب&OU{KSo EISkΕlmnwʽm8*Q=poMR_WLmiBf:@; \]۶ ZP!o`;_{:fM)v^&).I^VPsgw[(߷B2Ef`I*:BU:S*"7Rݩ;{nv f, qjc[֛Se%kA~RFsO#J&aHf1ԯafg]p/>~sT3LlJOZgWnOs0Y/[dteHF+VGӛNM ~ހKa iWgfeigx ,7rֆݼS*rPyw/"x@XPJnG]ۨs: 1 UY0:RI^'ԂH箛h-vWNPx/,I8XN5V-Mur-.,ZKqGVJrL(xkX_Ya Rmd@,H,H th`$|,ĝ>/G;i;0 2W;/jlw&5 X"3ZN5c<9|AZS8.G~&" F]M܋ 7'-|Z8gwhU}4))NR<pH@K0.-VyN<'.A*jѱeuE=L Cso}l"ٹ޵2" %ͺHi35Qe\ҙd ƲDGzhDh8H =Os,穕uN Cq=^RD4>S A:)9؇DEy;6V+~^D:ܙ40$@bu5}) <F XsFIlh4pK<] 8' W?yrF&}UIOh3S^Nt2E>,*"t}X/tP`/ z8b`'] fȖ耽n {p^&K1-7ˆ^d,W,CלWR(O҇C>tK z 2TYn#zeGTBSn\ڒjQSθ+3ASϩXjYҋ.ѳq|nG&ּr|^Y)yɀ'-*,w gq9<$5b ;#Vq}7}U{)V4 ѹQ].^9dͳzEraqwn;𐅌뇠1eA6䏾Pf;̷3Pͅ쑻Mv-ށ?cL XwFk]nJ(z˞#r쌧\ȒJ=;T J0I 8O0y_ls@)H7[; ~_ωwNLj('_*VyVnpZ.{ʣ^ܽJr-ɻ(MC)d>YxCþA$Z}]o.:WeK|e|&3O9MY}ӚɧȺdh gŦtKڶ8tp~6n˱o@$>ҭ2iNd \7zb_g~1W0t)rޯ1xYq]z2nnWߎY|̷C'47܅b8V^,7g_ kX.2]h1U"="#"p$e p勫&A$8,5!蓴Yeh gł n7+YpGC,|P?`7s_xI_kk͏iX=%OA"qu !ݲ }g26"^"f 0I\n-Ȗ)'E hu~O^ԃίBsL ;q&Y}۾8"Z;i.4Ş9GLut$EoOhFoɿ53nFR}ɐ(tzB"3"3cDr !3b)O) r$J8Ks߸6 Y8=aZ |hMSjp^3]PXU#z"M!j4G\TdY6vP;P7̶;͢Q"~w$BwgU6[e>7A1FژDӚw@\M  9(BBaH}w0ȖY>E-BHDip[b1@ChΖ^$4DnDwpi,Ixz^f6%H;j^LވwL/).!{[(* AXLQ5i[S+1c dIc[nGMЂiNBiCس:(o[̐fs2fl|`Td^ˎ 铭Ͼ܊>~rɧfY`sV , 0v0/OOfakn&.MקR84W\6I%ZD h==>Q{SRUQ6L!׀b #/cCŝ>}5 .%w7K}y(SU4 y礸yb ^ٔ3 uF# 3IlڙLjǵj o *F.@=[u!hoÿF_Go{8f`w9x%͢oNDǃQ-W9hbqqÑN+TeblQ ?O${5͝W)42 v?YV3>a^F2g2+iޞz5O1.g6-uT7Fz}fhPt0KUpc;*@U8}iVʔ<&GbEg(J+H"6|uƌ'ṖqbqmIXQ T4[p)bS3=TWTuEA>6AeVi.37rw&RH9RRl1  9,Ns>u -X7< 6+lriQ?Z8r(O&>CL( }*bn36o`5*GZLE-PSnF,z*$ibRl* _#xj@WL3JbTĹ[k޴(te?((~$c9C5_`WA?T0bxε֒Q{ Y4ǣ4 8%ZPR%a#WILM v%TjEi="Z=L딣n^+(W['RA,Edcѡ%188\}.Ƅ##djP i"eIi8r?48g ӭ.O3ʏQbZ%Y;: #3Mb]!s^JpX;BNS*Vqp^ۋ?c居 魍:.mP$ Eζ7eޕ阆pyn3 >STb#ڞ^ȯp@j`&Ŝd-Ze_*?i) &tؐ## #閵z@"}ы^ :qН cMo6WP! Udp*+.Lzu-PnLkAWIhf"y%͞OS.XEx[oyMq(H e:!ls^$#.Zy; ڶzϳR΅Xukw8"JcRNrϱ١vFDeeʚ.dI;y }6 q5ɶA тnHZDD(h *o“מ4~?<ܕ9/ͦ0ॐɽ6g~/nJAIsLiC,!zrCu^-„t|MrK2uX7Π}6JZjϪ޺/MuN/90q8Cߣk #7Q>#ka˻R8+}64cϦB*M|0 hK~W|&]:g=rAoDxR:2#6j݉ca;YEC븴Z8UݮR|3>.vI~N}ѠBk5c1}{ jBü(Ϯwh[U]Ħq}E=k3z(eK1ZӡZH)yD#%FĀ+T+;]e@fLIKawHeݐI%=?9K|ٺ6JV(|%݆54pfKlaM#+VaWwSϵ$qe,0x5 ת~ >P5;x";sf{80 !NzUpZuzaWwq, }LaLƣI[ItGHF!7A.*q8Z6L@w$WW*ہ$`^SλUvu3nH!8/&֘B/o8 fwdC~"XA/DE#Ie+Hv7(-:VłF9Ws81QzW]0zQ$*4-N$xA͔f8xE\EUs܇rIQԲЋ#& )xR=2ry-U: d7i.7d2j.Q6Tc>R-dWθ9tnTS.VT s( Z̒Y勥Z3aƻޫU^W2CSYG/\ %L*wWڟ"$kGPt*Ik5ʼnJNᶠYF+V TۤTWӣxus2m.hP?M,&2|t'i߃8]@oQDf*>ML5=mgac7 bw f[0/q1c=CpUʹegz/mīZ7p[᭭)T]qKQc>s#qXOiC3GYJˑUtoł#b3]8lfvC+@Шu<V{ڄH΃m!kx>-$;Q<މΦ#_6<R^G"M7KK &J[፫rfw;o|sAeZoH/iKP{_s Qt5˜q5l 3'')B5ĵ64$C{1`Aӑ#I B)A0b^ez-Es2"yH*umpf&P~U{{MommPR`/ӡi`qXlXZHwXM6YBe%o.vX2j]l'Bfs)|.g.VCf7(lHcW&b(~1Q:vq%ڜD Q7ԗB}$ 8%{yU.q6nN6c8V4:`޳  EPEzǬ ȒXY6t݀86S4&'*mzь 8sjlNZˡ!.\jf3;y_ BBebS7 z-'}y{})Γg_vl=~z}q.H6ʙMrk`K(4OM,*>OATk_gɭ&2X"eLa},; > }%%VBC. `N ToH4Kki72^XlI{EĬHnA:a&H>>Q7,ꂚ ~bVFc[gc:Nmƶse_xt/QfFIʃk> &^dT=|3Mu!ˁvmVsA2h@߽ F3kVPH,T~il,8ZfȁTsβj=L~j4+;e$ c 7]eaz0iM~tXiktu̷^ ڛl/v=  'H<߱K^y#4#IE,P8 oH*L.11"<O'6٧=pf{&ϳ^&wDWB\% 윥ZY~Lp]܀}nyɚح!tɎ|w.&m(3"K.oD]gVhnH6QC/nV*` l JHelgE!\'3)EV[Gu0 TL좼@[,HXL@6j@s[m-˩ݞ)us~#We:}4iReuw puqx.xpPF4E9+j ڐ$W`-nPV~*2EB}AR7Ym &@!KsD+o9Cu-bL7R_UKK'aή?pbvfIA!rPĒ=h>6#^ G/`6ֵQ]dInSdxEf*yk=Wɂ8ٞ؝p5^qaTkZPs 7Xt22wY0]bY!x#>]tI! /h(m~,:G `/Ž^7x`W iUjJqr*6Y6%gLg,NݵW" %Z 9E79&JbiFdUvc5$*-'7# {4)d߼$?67Lbq|FJA&«b܊ZGV&*@PeM;Mhino^>z=$M<߈cmD4/x3.ounuu@3p-h`z8gxVe|Oy|''Z*j- M@‹?>KBxQ>Ҵ0?49ZtqͯKF!oi2IWy/LC:U^6Wz#muJC|J.[6Bfdۅ[ѥ.?48ze]ϫ盛Y} Iěhx= )*G_'*ݛ~owo. qhH =0̪$bʢ*5E9͆tW;;O}W+pSFDV0707010000000c000081a400000000000000000000000161117fe800004f17000000000000000000000000000000000000002500000000./usr/share/man/uk/man5/sssd-ad.5.gz}{S\ו|S $C/^;(jdIx&SE5&ݍc’*xdqfn*u Aotzg $IЏ_koSQoH MUZx4j6bY&z~}}WԲmd}QRkzBmZi.}CSoDCӃc㧢S;S8c>D\Gb-lZi]幹c<>P9kC^|:VshʻBk:<ߨͩ#șCqʹGӵh܌~뾡Jd_d3nEx\mEsbժqrYµVlU굾ڂޯ\F2_ϵbcR굁b969vrڕS.OEScS&.D?9a&խTW E^8P#HPڰsV/o>\7cգa<^46=97=*,xzn E稷LaD`_) ?:EܫV ?β܀{S71(^p'j ?+eku~Ϻ7K>NYOvv6 ˣ0<|2?R>bqh"u@jʰ0EvaMz lE[m\@+jP58ECpT{p7qsvԇ`'j *q_I1vh։il}/M:bՌi?Px߽AɯON]$#)Q1P֥KS o!R:B-4;9ǍٸQo$+C-V1g+٪ye}ɧz &dęH}h]:9p1\6<X}F|.H7!ڢcs&/LrR5<fot~ oxSm14W=М\J毸:e7['m|Gc" kF@xjDpCWqΟ"۳_Xw0#՟;8Zu4QP)0TK߰E152RK$>bz^:'Ә=O-S$ۍƸE7[ydEX,P\xÅA"&`$᭰ܿHmb/@ 7LB`h5\;Z:j o?%;F0ꈅmĿֱD$"2 p3Ύp6tΡ(iီQhCc!`YжEGmk2P'#eѹJ| T ٮMWsC|Du 1RtV>W^ƯRsXAumYɍBs`G?BO;\EkT{3`3 Ef6jr}!iܫܪ5pUkrkp>0H V^XEg\᪂a3rRn7^)HK?Q;_)é)Kb`C-z(g۲V9f!$cc_s.EHsoo;JIjyӁ‰ևf9.wQqO]5a/ >9P} F(l55 %,)G>dV. ]<2}QïIJ&W&/2tIPKxfPso2բ MkPm"R6Xm}oh<}]=q^_psմ]9*ZoW6Is \ y;qܦ]]x!fץT6qZ^`TИ^XQFm Eq/"N@_mۏi)2?&QR&H5>fX f>P;+ّoy<%+]<$}Hv#c=*7qwR,.S5/i7o=e󅮾ZµV=mTvѪňhxsc=vM78;y]YIcKTsKۓn$ RUK7K绚vUeq>?G<ЏH63XjSh UvZ]E/6G@p]*4 8Û/C~TO#bE׸E*6>Dڞ n?: {{JѸz[]#㔶ZiRD_@_/kwscLLXԢ~5ŻH}z6ЙH6QII1a;͈ORa.Kz*) GjZg { -b 2> ekFr6gFh҂@OMhA:þp> Z7^i>>_ ^{ߑߺ^xeRӝu>cw?EchtO۸OM L{o/r4dH"ړ%}mY0~@˨RBFS6EL7:R!?Z>֋Ud35tn*v#[0{\u.d;uB} L,@ޯDb5GK^qqJB/˚`YJhKӌƍB~-Y^Wz^H#l[cD4xn6S@Mz@^aO*DWF kADr =:VZ~4 wŨR wgҺ?_>6Dam%i2DWhKa!JթI揺aF+1%c(rG)L-{h'n:KziCyQ/tp{NPbN|--am;ڠLô s=UclՊq{zъoq7n,݊[i,knP:ts#GoqWh mbȲ^ևwg>rfLY7݊+wY2lSW7 fiHW9t(N"Gye{`P,k|l2 QVK̹Lj2M>-pn.0%FG01!\; ix6-DciP07+4BҬVD 6܍_u|G[FFJ ?0t\G/i53FߧO=EA9Q*#p֘܄dkn( /c1?j޶ڨ- ]mU9heD ВAmة.# {%mI !18'om9Töo<E|:è qE-}Ӌ.oOϽ7'!rjmj$ɧCPqvnB 􏦛gytg'zzv-&cdA܂b+4B9*|L)BA8?`-1 Vo xb+u՞SeX{HSI #A§eDWA:1RPirTX6HC4tw#7Ԓnȗ".ÿٸqeRbyRk˯7KB | -caq&txџ؅_yu~5s,i¬Ke zwt#88\,7[qOҊsO3 勀K^@RR2߈dP ⤺ZWǎ9ɞR^O޹ok L~C&Oց38W+!dd(׫b5z*V.I:F=eO6ѵd,WFD1P4۵\Ẽ =)@| Jrvߞ~Clk$ &ĊL􀌋mOĤ? 6/;{Od`:kp\Zݑ|5Tv^3V7lRbDL8= _ۗU%edDX\rV)yz|v$\61"-:"8v[{z¹c`zV-,$20'OO<{FsoÁibF1@6=y! _GBrqN)Jyld]'p=wV~Ћ79qi+Nӄ`c WHHް(&ŇI@CTmKƨ ŋCg5#l]j{)uFxNd"jcaGj^vb >{c,0qL+sn{4#^%fGxvYӑ?.# x5Egq<r5)+uz;vf/O G*ef&.ąW^R/scKKkc֫ҵggؠ$V;5&\{ *Lo4>k-q0k'"yn3:L@RKn.SG+*ȐJwke-1MF֭%*Q 8 qMGɔ9peaҙJ ǩkI"(pdV~x,|FeGjM@1ZdӘ-{Y54s;mѺ!Iތr֣k&Kfw75S~DN;uHKZPtHlC.3Ge1hnV MG@gο.Tku@`]T캅Tpw.>(d}i ajTȄx!>lF=ڄ[A2ݎ㐁$Sld>2qW @ixDI4gJ2|;6g$&QC9xYU0&mdz*҉<ŶiSlP|Ǐ4TQi͔ڵ:- aL}+$ @hq?[qw3TSi @ F+m2=h^'p/0> 7AތgFa;nXE` E&:,},׋ C;L}M%,bl*: iJ)TA&opA/qp.SB\+W`+~!*sRk }n3{jKP9Vkͭexg=$ZֵunL.A ? C+VVqt^QMKXpp5AN}SV뿙l,WziTp^!g\?4RJt71OUL^F܌kGZK9(A_bk50[Syx6kPN?#}$/l@P"|?'2Idz<_7Z#.ϳ] Mm%#ڍ.˸с4pғjKrZ)7v߸.m7S'->zz2JVA#l5vlXר2,@AI]NݝI[7s G\"b\_n)~ lR) NGTarcҪCm  @CheNy#:}DlA*ҤoȢ76XDmq"@F<%Tpsy# -"M[p1ґEz -ʈr!,BZ+n *-NquͣT!Tb[\gWݞkZ{E-De~f\I&VA +",\M".D"c컔Z ,&H H$זWܞY.G5@( aԤD.i%wQ:!8`Xb60APgVOQ^.,䱛6枽Oק\.RMM[s_Hg壏x[B"(GN)?j( \kfӰM/PLV@DVf "$⾰ ؍H>3 ^Sqp V'!]=lVGb"gB~B7M.%f+vS9#82*QIO}z0cI۶jkܠnhX3r*ԈtؒyΠK.^QcJ)ARƝkܽTfϊ!UԔq#Fm.+IB9avIM ?c n.3cˋӃs|Xj(9o =XlJœx;hy{'f$\cHӍxފ[azw'Ӷs -lMNi#7ú~ t `t'7v]6MfkӞfwJd7;94I7EXF(Y|U_&ɼhOr3~_\(7xVlDZ'z靥J+D-e+.veڒ5x r6H&#DѾёbԧ3HGQ2uC¶s$<.w1 VO,uG{=AvJ3*\^RD!kV m"Ogfϭ1ZZ Zj $8Mqqee[61^ IZc/qӿFRm<"C$GT7u]?<-]jӴ 5ͨ0U}6tcD`f,(5B4>h'8؜(o<)Bb~:_.%aglq|;^l{hYTǎ`n-J-pT4sEr_wEME,dl-9zYr]%(ZL'[[!K26s^'kx%*6Qm=̼AAcٺ,ܟOʼPi y%mʹ`T r:0'<G:;HbT;}"O5[byzpYQKj~_Rw깜y]h\={U-\qښiW/t*iky 8o54 ',h^@=$lʋ 7`L8R5ڶ;r|nǠi(oe:#X&C(IwO>6\Y=MVm #^|>gV6,)nm5vd,&|v <'_Ҙ{lgP3ϏcYwwX2`?Þ';n'Pw& ${UտJ-PS}֚EfqfLnޙ.zEZE۪ju \ X"Q5Jc1/om>$R 2q "[MU;]1ty]ө(g;grX/Gj-bUDFyӛETcbeNqOe`mxOj. msiIm>b!|J( Ful "iB /e@}ќMS*72/:Ն"x2 jbr8۸FQui;X{7V+xE#$+ߕxs##/Ϝp-2>I [KN@y bx<h^X_rtc>3~)Et egul&M6!Y^3ً+m~C+;ų/X:Hjl~Z!۟#u~>YD;~o ƞϷ[T_Hq? $;۸۔.O!*)17lH |LGB9fMy<4ӼP>_Dl.ۚFGϱ WL^Z}z4W>wշ84ɰ(lsh1Sr< }%nru58vrHlܨ7N'I_ #*:t٪D/cLHTPx*]|V5ٯWBBLFn7xZh#jS$[ecxM}8HūӃ:W(Ih˓ פm7%׵ >]Dl]Mla%&lDjO1&ףm֭TNߏI?N+uw"Yg? } !Xe\hdzV_i't^ǝv4ƅK =t' &= `G8Jhk}tV>*[wվ굹< oZjfjj+o9=fZ!i wZ;Iӵz#}ʧ ܅Y!.#( 8ծ+dUPQb$y{}qd$m?ؕaBx8.P|z/\'.q߇r`zEALaQu\>&"ZC)EMm[esSS)poV5BJTGR/pm7%'u`2leWaXtuF1ŋ ѻ53-f8$GtX;FNNr``w2Hj2`sºW rŁS* :?o[vc(Xj֩dzؙo)iI>ӥS={tv16㢝gP8`$ 2 3;s őQR܅$yQ^H3vfZO"&Ƣ:^ޱWj#W&P],PLj LyBB5Q0I7WoVi6z +>Vk%漗zNj猻p *I܆67 F2ƙܾ\I~˭pݺ  [)ݙQvS֖u3Nm2ee6a &pkv[Si C=r$WyA>`}f%٤LfN]Fݰ˛Jve8t o'[e*'\srp4S+Ihu;;/T$TJ෮^\6*ReX.iwBY"K$&Xtqm$ݍ 9!G}faztvV#Dm^Nc,qn9 J4 ?왷A 'G\~ЁzU_" vE!El6g(By`0[ %\i/7Np88k;R@Pju r1,- 26FtJg˭р~J8 ?WPԧTzn(\`y&u>w[o^KS)OF&qXAY`!6ﶨ͉ 8J dB,yMMWˎAb&-ѳۜUON*\SW?u ȍ-V+yE}@_jTԏKⓣa7@C8@j/լ'РGJEX]<1+j艎,631v'4Z#SZkTcGA-Uvf } "&9-\1E+2<ƕco^I7̅xLjPF}c}X;舝~d lG  8הI@%qIrǜlq/1{'cG97DI^̴`vM1h[+c4\k_7[W nąKobFUڗ;NM_#t{`ܰ8 _J{cȊWgwn2xcNH3sh*',"n+DZ[#.Bw ^vD_ eLͭ0`4‚]ɂT&0uSgtެqN@QHk3/#*|! Z^*J,)'BK@|m.'4\ Dގ$ ntm9yG#RbR(@L$0!s2Y<5ZdaYn @M y+oIh+7*5^r ISR=n׎\oU=_!OL@mO;)B< _w?Qc#|n-]*ՇvKqn]qA/(O]h$^CTC~"IÑ_@-Ei 2GW,;\8vYe: >(+ T:*;#3cHN1ۈ bTXu|ZV%ut;8&[<ք0ë|& |N$3es" Fg%%nznp I X\n&&!Z}ݡPs2fw`"ZkI@ApO6u^{$C?pwGkJAU<TR77œ:bćEb|5TQR4bnYNtn*7wi}Ï ^0w_M +|9񘋳aľ2OvRd]Ӓ-ߤr kU|x#0Ԓ%;' -&s|I|r&Qf< m}ˇN ̀XQX{\P4*=Pv.Ph70Ph_d= h4- Pox|U3"udۭc .4ey rAl1!q6fL71.Ό=R{?g.,S> W1 B$\$BnTyT+$ȎH78@doYyMQbA+zB;>g9h4LN j!8%=bM!r_gX`^7/!khM4jtK]TeQ#$K9zRRQpdPAvX-*1lp^HpV&cBU/3$'ˬUCu)u&¨dQR g٭Iѻ g9ڂsi_z35[*LmNeCeߘRG=#VGHN5V;@H5 4w NG'xX‡lk1 㾥K r-||D&RyBm6Z]z{nBCښ4^-b?tlRܯ$;c<]I]92 ?v~JuuF[JUQPL*BaN[2ל-Asu#Očwf~GM堹f>VawJrC飋@|VL>HJIOvzZnN=HAsJYBoLSmC]&%ZDIʜ] GBZD(&SHߠ^E`/(0Fqe$v7L C8W@mZXێB:L^Fd<}q(:i(+om͉q'h~5ڶ픿dy\ )& Vp9L+WY₈,4%踈L/5t%DBRXɩrYTkzymZs!5_,,W\Wn0+uN4ʸ^Y겙¨:5Ppt͕BÌSIBj)4ۼ$Xp%NuMZ&ЋWcC%'~Zt楗XcLh>A>":WNފW$A)vdau4Yy %p2 ~ivz8}Vh:IHE%9ZBp7wB[ AňQTzl\j: xTWnκܻJlܠYϛ_Kkݶ|vCS1s("x#d9n5|#Owp 7C}f`:+cy]wRKhUuPkS{h6{O3YJIIrԧ&/'УKVK]D{)$ʼnT Q+4+A'q|d m~QoRω(7ZGy6Htװ{Ȉ.G(I~Gcںq hE (>`-EYm}d( Q$~\Cv;a።̀!v''u:toYOjQZ~4mFN=z _ًĞw[&gQ!& 9߇rC\8p0B,jCW=3=9xS 6puDfgW{;D 3l$;dlxa \b)Q0Cf %dyU,YWrnɐswtN6=EqbXy rgw[hA=K.g>Z (}ӉU&uҚ0趰x_8+6}e] AIz/d`'A8`үro7'2 X)VgكDDZ*˾H{@[eT}]m ׉q LBNQIћ"9S}]?O&ݰwͨU} ~6 NH8wN$Fk"ϚSl9ⰁN`!%<۰,3#^YqRmʩ/D'xdHop#|<0F'"i"ʕ UZXl5Z~KR<8W-G˳ym7Ԍ~z_H"-@!:$ckbvv\m{SJz;錭qF0Gg}A汕WFDzj]m: 꽎<8 r?3)ڱĪX XDH-N_ aE6*z:ZB5IJ`WNou"Đ%viF,0һ/T2|T#^=|~K|.U+Kv?GIO?`  ܣi"#^N@j}er6yнa*ŵrCnKmi {o͊'~+5* -I3|b]qzACj9q1f_MvmhTc{6eg;0['G\+崬P*4j0k ~ 0u[)*W&OOǡ]a߻ݺ`9:xcN؛'a3/~NBIc#W\%wE}oT,Lҥi!XnnWBԜ2hq:=oj0~,Q^%YmFM!3KS ȉ>y;]TB;u3R=I-'Ohj aL%;\p# &O˺Q Ѭzi&Ы3wU8`X%#ɿkKx ns8?Pm;[>j4ZPl  sbXoT';7@]'gLsn52FNvv)E\S';YiЎ_]T[Ӄi2ĩP;HGRC EnJ:y-{{#s[LVZ}Nt:#,H>Yd[2<"Usk#˽@mSY'q0^e:'gVG Y4;O=)5CE6(Z8`㱕ndM:JsE7F:>\j(NЧKo[.EcoMqe?Q-xL\qkco6qalD-7UWߺxie2B_w[7zi)뽧 R[d/pXW\\ƸۂI$0ns nm;=FNR4! ێؼ { oU3Kr Hty_*f{TLW,sy){g}N}TĵVC}=4H?n2xF.:6er+p:maNd{TMC*C?z@S!'ːI ֐}C'Ae6Qxyoj L!M!$mamz{AQ{KMt~~ϭy/V*C)nbZ3#qӟcxRXL~ pl ,x0&yӌiS'obYX吨38¾^D ѺCa]+L_H 'bR?Μy)Uo  G:Qeé81Cқ<ϝD5bP5|M ?+''āj/CApfEjeT,Uq3r=`zmP\Jm_+dzݸQ[n- 87f;WM6|f<_j.`Ofes\~'u%DnSy VN/՗1pR =vs5[bKZ0m n}xww;x4/-ZKr#P><999>l6s}CoD._0yoTtzTtoNOMu:mw7;'v8\9mwFIw?u7׺݃nqw;+7עվ\ RstxxY -VJz>*rsZm׆K3gΞ}bs齾 }Y?07070100000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000b00000000TRAILER!!!/p/g-J!.oeSq_"N X8  YZ