sssd-client-2.6.1-2.el8 >  A aBU]CQ͠K5o~٤1*EǐU9K`֤JzHMs5~714skl߮`sp".بeB^i(+\#RZdX@A4O BP8! ;{7V ){SS%qzl-pC8m7*̤MI79lkg>Eo,fz<Ue6'3w*mBK_! H1T/N+}27}. ihyegk,@k42 55ӵ>FJt:8]oEo?g7 9 })ɀb $ܒ6XRZ +MHK.X;`x4>¬R͡做fB62ˠlS >sʽ! YGFi2g#:|{̕$MK_ԖlbXʅ>Ḥ-,mTnaY!h7f#_ F3A7u.-.ʶ+ l 3ؾέ5$mX`[RX9WDP"RYTFIN)tYvӘxDlr'Rf[A8dHt! "ޱT{ѓ|+Z'\nWӛo>$ G؋FmZūImqI KEB+h ,*c >pA|?ld  @ %+3<,, D, , L,  8,  , , ,d,0#T##(L8T9:i>s?s@sGs,Ht,IuD,XuYu\u,]vh,^yb{d}e} f}l}t},,u},v~w,xH,yI &hCsssd-client2.6.12.el8SSSD Client libraries for NSS and PAMProvides the libraries needed by the PAM and NSS stacks to connect to the SSSD service.aЭaarch64-02.mbox.centos.org CentOSCentOSLGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxaarch64/sbin/ldconfig /usr/sbin/alternatives --install /etc/cifs-utils/idmap-plugin cifs-idmap-plugin /usr/lib64/cifs-utils/cifs_idmap_sss.so 20if [ $1 -eq 0 ] ; then /usr/sbin/alternatives --remove cifs-idmap-plugin /usr/lib64/cifs-utils/cifs_idmap_sss.so fi%@)-%2>F @8X0pK = | \ 2 AAAAAAAAAAAA큤akaГaГaГaГaГaГaГaГaГaГaГaГaГaГaГaГalanananananananalalanaГaEaEa^a^a^a^a^a^a^a^a^a^a^a^a^83ba1d289cd09dcfbcd889b05b6459573955c9184b5bf84bbf6271bcec86324584feae0bd7b2b10ec4a3e17181c7bb506252cd95c546b585b018f0f98844e92f93ef20b999dd28fa12f01b134a6af7cad46b39f94122bd6aa03cf8464b31c4d41381b165c62f721b22cd522f1b541bf4dd9c0fb7d6fd69ac1c08fce7190c0265aa7d0a7d240c26640a41e0fe5bfcb08f3f807f82386e3070d511b68f36865e92736127fd647d4c29174f3737726eae34b4466917beedeecc691e5488d718d5b099862b183702a9c9454e289dbcc8e2ba1fc0337258c9f06ec681d02de2b116a844694ceb5523d8209320482c4929cb0ddcd5e4e6db32cf81d7afabf3acf1e5378ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9036c57f43c939054fd4b831f271a14c97a488c38f98cdda5e887c5d396e3b3bc5894ae3c2bd3f5f057d09ccc52094fa1d6d283cc99bea8542e4791c918a1f56f132e63c6fc4ec0aaaeed64cc94a94929eb9009b6de5f3c63cbce141a093246130885bc32e727c11e683d9784761f5c6794ef5a74c2479adde22c4c7e2085a475b0cb81fa99f163128b92ca0f3967f792c29e948f081148ee2f136aa13f117640dfa9d80f9c7a8bfcaf5606cd96831286473d8b359a11a26f93e1ef573f1f56390a954530e1503e88eb7edf1db4e61eeb6f3e3fdef1415a40907998e848a453cdcf49b02f8b7456564acb59d998246f533a5e3e408a5bdc86a383dd32eef7f96d44e0878ebf6eb236c17503f55350eac668aa206d55d07951494030976b0946b269149ba961a850c1cb9272420a01a5368acb8893487ddd3af74d353944da303563c06d6f914505b80402570a9fecfc8979736989814b4ca8aa27964bdd11666ca9cd8afd8e0971c31ec2dd8d6ae8df31d19e6da77689d7096b7789998066d9a673aef93d0e9a0eeca35d0c0549cb71cb13550765658268c510b0ee74736ba3bbedbca35f4fd4d39f962f11c70bcd284be7febf137ffba77481703d9f19b55fc4ec../../../../usr/lib64/libnss_sss.so.2../../../../usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so../../../../usr/lib64/security/pam_sss.so../../../../usr/lib64/security/pam_sss_gss.so../../../../usr/lib64/libsubid_sss.so../../../../usr/lib64/cifs-utils/cifs_idmap_sss.so../../../../usr/lib64/krb5/plugins/authdata/sssd_pac_plugin.so../../../../usr/lib64/krb5/plugins/libkrb5/sssd_krb5_locator_plugin.so@rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.6.1-2.el8.src.rpmlibnss_sss.so.2()(64bit)libnss_sss.so.2(EXPORTED)(64bit)libsubid_sss.so()(64bit)libsubid_sss.so(EXPORTED)(64bit)sssd-clientsssd-client(aarch-64) @@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/sbin/ldconfig/sbin/ldconfig/sbin/ldconfig/usr/sbin/alternatives/usr/sbin/alternativesld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcom_err.so.2()(64bit)libgssapi_krb5.so.2()(64bit)libgssapi_krb5.so.2(gssapi_krb5_2_MIT)(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libpam.so.0()(64bit)libpam.so.0(LIBPAM_1.0)(64bit)libpam.so.0(LIBPAM_EXTENSION_1.0)(64bit)libpam.so.0(LIBPAM_MODUTIL_1.0)(64bit)libpthread.so.0()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_nss_idmaplibsss_nss_idmap.so.0()(64bit)libsss_nss_idmap.so.0(SSS_NSS_IDMAP_0.0.1)(64bit)libsss_nss_idmap.so.0(SSS_NSS_IDMAP_0.5.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)2.6.1-2.el82.6.1-2.el83.0.4-14.6.0-14.0-15.2-14.14.3a@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/sbin/ldconfig  !"#$%&'()*+,esrururusvsvsvukukuk2.6.1-2.el82.6.1-2.el8   cifs-utilsidmap-plugin.build-id13c76f0179a21ffdb993323e69cdd2bcfa21f5c02ab36c7d732203d3556a2817c9b2b9e6c72445833c21bf985608fd3d5663f374076a230a9f68d2d54eba42114938eaee08f15565cf7f657265525e9b5cb2872e7c53146ab9d835c51aec87097b440f3081e9a3da65970c9d0db94b96350843f348d70a1a893721d0c2350fc6c9ea7a6aacefdb252d739bb16198d81b187bb87c15c4e7afa005693789e7cifs-utilscifs_idmap_sss.sosssd_pac_plugin.sosssd_krb5_locator_plugin.solibnss_sss.so.2libsubid_sss.sopam_sss.sopam_sss_gss.sosssdmodulessssd_krb5_localauth_plugin.sosssd-clientCOPYINGCOPYING.LESSERsssd_krb5_locator_plugin.8.gzpam_sss.8.gzpam_sss_gss.8.gzsssd_krb5_locator_plugin.8.gzpam_sss.8.gzpam_sss_gss.8.gzsssd_krb5_locator_plugin.8.gzpam_sss.8.gzpam_sss_gss.8.gzsssd_krb5_locator_plugin.8.gzpam_sss.8.gzpam_sss_gss.8.gzsssd_krb5_locator_plugin.8.gz/etc//etc/cifs-utils//usr/lib//usr/lib/.build-id//usr/lib/.build-id/13//usr/lib/.build-id/2a//usr/lib/.build-id/3c//usr/lib/.build-id/4e//usr/lib/.build-id/5c//usr/lib/.build-id/81//usr/lib/.build-id/b5//usr/lib64//usr/lib64/cifs-utils//usr/lib64/krb5/plugins/authdata//usr/lib64/krb5/plugins/libkrb5//usr/lib64/security//usr/lib64/sssd//usr/lib64/sssd/modules//usr/share/licenses//usr/share/licenses/sssd-client//usr/share/man/es/man8//usr/share/man/man8//usr/share/man/ru/man8//usr/share/man/sv/man8//usr/share/man/uk/man8/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnu  directorycannot open `/builddir/build/BUILDROOT/sssd-2.6.1-2.el8.aarch64/etc/cifs-utils/idmap-plugin' (No such file or directory)ELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=81e9a3da65970c9d0db94b96350843f348d70a1a, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b5893721d0c2350fc6c9ea7a6aacefdb252d739b, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b5b16198d81b187bb87c15c4e7afa005693789e7, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=13c76f0179a21ffdb993323e69cdd2bcfa21f5c0, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=5cb2872e7c53146ab9d835c51aec87097b440f30, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3c21bf985608fd3d5663f374076a230a9f68d2d5, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4eba42114938eaee08f15565cf7f657265525e9b, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2ab36c7d732203d3556a2817c9b2b9e6c7244583, strippedASCII texttroff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix) "*4?  RRRRR RRRR RR!RRR R RRR R RR!RR R RR!PPRR R R RR!PPRR R R RR!RRRRR R RR RR!RRRRR R RR R RR!RRR R RRR R RR!utf-828510734a802dc15a981b6858291d782ac432377dfd175168744a9038aa2e094?7zXZ !#,] b2u jӫ`(y-6]ŦQ5A/xك\  E̦PӞU{2pC:)?:DwIhU\13)膾śibDIzB7a(6DS@, %}` 0+0(?}6s ʬ#A*]?)@Grg -y>A1^썝iY~h:8<97Ou|&k%',Va*Zj+'OK~ ONaEr| r>?.?N> nX7m1j5x) Ѱc?x.\2'V;yk&d`=U#Cd;+h5T,Go Y:2N 9'2ŎdTcH3vd00\I5DfUc!iyT|kbcy$N?]Yt@9߯gP{cF/PTVmglgEZt8IRԋX^!;eIA~շtVLbդL,9c=>\j7ʆܫ˳9U!pv_Z+7Yry;cөM 7T'3f|8s\zP)4z7^q30 G j,ŊJn ! Z@rGgFOaIMjaʓ xN-fg:ռsReBW$OFǮ`s;G1uu[m'pk 6s\9_:;YD_aAl.ϝNG)2#@ԁ)>E;mqkrJnЎR ĚD >]"@RN'@g[d䎺 56K:K4)TKl`m&,0W+Vz+U) wi)@k{* uj3Aa :){L l:PvL-[Rߠ=~],|APo 0DM)>;=Zm.aan4TE/M> ȭ__ zͺ ͝J<; CGŬb>F*'ե(_ovP?6f؝Uhƚ5PSHSG PA]&i%IaLURSGb)ʹ+ID?/Z^]{" n0x"K1+0|K)M-tm C0\! !UiK\<)t[ y_ZZG6f)g ` EAd#,ANp&|_0W1-G gR'S;JJ.5f.%>JF#'uJGə~Ϋ+G*.vHwk,@nPѬ EA)~mk[lpG~05T_afx 2xD/d\b]2S=J?bh4~@`Տ )*e/vHzETM];ԁ)7T)5縡9wp[yY"@E&Nzp;/-8C4SIٞx51n%fet[ iLjJ5=?z ,=|l T }mU'?tlΨM`_|2h)jp‘ڂ1v,UѮH$cZvĦLZ%+]^Vk]qe S5<K>(5/!*[d{RAw%lBfE;0aZy_iA^0Dcde! CɼV=2堰Y(Uڇhrpm8%3c@GtjHo&LWzEL{_<'CNݴxJ9y{"Vo]{ <| bqP|7: PָS_g`j41Kj3Hǯ j}R{{b_6IJcxGi8sZ(7uVfOT\P{Apq~.=^lslsKζ xBHgګ?Re婢&~r &įƴU<~gq5K@o&l*o6&Ԏ["*S}j(L18OnY 0xlTڈͧ xF<0}?4Uu~e-t?=ߕZ4B!T236ӏ[$W&jeTLmWFS@PAoǨih"rZ UY!P^pDz&f4!tq| s${Oe2dr 87D @7 '$o'L.QARxb>px ##>̛mg%h5:&P9f謟t&79;ZTpkH߰HG xrWMF:W9B_>ktڰW%KɱJZ=dh} Q_v(XYYZQh7y?^p.w#]CXSf,V=n@(֩;2 )/D|+7 fl%CpܫfEa"E#K7 I)?۩7C&:j _mѧ+EP6*N7sb.MSL08cZuR׮?: |Xv4l,BNfcoaQo$@$yhXrd<ļOp @iUr.^AxkDFk!h{wax 7fmİʘ'h$f3KGsk-|J)uI5Lu3@}V]!2W~9n K(6>  B.1S"af mЯ|D56᛽`wGW, i+5 '"ϩ j:si!u8ą5݆8"4%֏CeJt")9FG6D)7/k(daЮ]BPd(͘6lq>C.$ hQ xi 7^|q__:D7 bڷ9BRm#A^Kl@{ [tQ@}|#xX,}A{7Kδ m!bj B/[Yi0L=(<^ߥ ]&t6) gnJ$EQUB{v~8[9꛴4[~#O:2?d5N%<9ldڨE/D\Ü!~8lCNèKgJ%خ3 -n?%[}qHܙ4TFA!Fš #zԶ8b +I 1=.$zߗj4i#BO^OU~cř>6|VF 8GIEY`k v2whf }j2[&< 1~H#g ɥk8o>9)0:)me6({GD^^,M% 2,j߽b⫩=~"TGOV!ٰGg f!RP|k&vܔ,AdȄzX eXGiȨh`F Uҧh&ba$00 &lj;3mRL@tD(&ofZMhLmY, ՅD+5z9} dC>W!8lhT-2AԬI0˅P1>ÜX# ުj9+LU, WE0I1{r0Y'"L)E΢4bh}2h5%ԠwE\M(ݼ'> HfRS`)I.!CQQǮUuDqm:}dPlPȢa8rD?+d'v^>Lnx( FmȾ!iD7@`+L]KW1-ft=8LF$ $|2x7'synedQu\ا*^,Mme<.f%Y0 `DzS:TRN);yxRgwԕϮD-JymlAKjA\, 5^:?I)S5|n$IóvFmgק|7eJ6L^0t<ϔ㷟.ir#]|;[&iǝυ}?JBKN**dK-q:o:Ц*~_+/xzlnǎVMOeFϣ{F}-B]rL# 2i^J7/Z?.9C +\k廮,AV9hFRfReM{b;~N,<ܮJ/0pcd jNWn^B?KFG_>)v0}deCgL/DpFdmL GX1 QPPhͱ'/kVNֵ%tm/'/M)@;VRW|:sGokܢ;= eyFE|CY튟rx>)~V)h)]tT%c"*y,JNdMA][T4θ9A2OyMp]*ȜmRfB<*5!pyt֗\\0k/];rH~ƯG)80~YQ˃i5OM޿2=!W@>C2X}/Bb1A89+ mUBe"x2 k7 k삙 ?=Y(R )H},❖=I] :5^(.^(6.qд;ax1: bq F $Έ(;:<LG'wx$9xKwpgR*)*KBx:-'-)#% %1T6pPArOcvXhLj?Di!L jrW2.7<6b jhDe}(l~7#Zj4eY!"K£G0)J}ߢIM,,۸ALbH4{%$-NсZKpۧ4PlHCTM*NV n1bqfWR.Ùo4'sx ,P>/w|2RxfA"z6"O|eͼzB"0O!}=9˙:R:q*/e`'=:lf~Q"AV!0fLż)v{-e%0(؇^7h X)eeR"[fWڍ߬i(pjF?͒ӛDIіH+DДn{LyaGah\~M)[|-sruz؍klL ![]MdyiWXB HuqEdYur0XOz0ouquy@K;e}d[&AFM D/BG& SV=DR {"Ote +5I =Vޅh:yoa"#l3L딖A;Gf~ψL#O 5q̂O֝*m^px>\ؽ#J'uDf~R ʬqg(cb#< v;D%IJ=o舐n8Brm'V-xtꢶ%[Y1$IM^k׶jubq*Sԭ=Λjplws $+42Y)a﫰rD#|@LK"bw|{zcƉEZ1_e% o rZJn?6%ND$ 7'-':bvavi.Ύjm$b}.m"y^c;\oܚBVK Wt{4&CF%?Ӊ]!(le2`;ƈdn1A4U wI}O5B;Aͽ2k9jcoC#0;)ySXA02c7XG\HoqZO1 ?<Ժf9Q[ 'M1'=hM9m' hKnޗJyKF5#߁Ν.m 6 \li蒷@(JePL=ɠM!]ZGW' eP^S]8r"lo(DμUo:텺5$̐<->F)vWbmk85iIf0!kO n4w~r]ӢkURJ$Ӈcz/18(Dd|)~ylZ*xUJޯZL&oc2USoV!w9{5@ &H"juNoC1 ;1qoOOfvTYLTl-U9Ub&$6XIhC|7ҕ=ŜSiĵkE_>b?1&e*ɔQ )imL%doԁn$8%g$BƮe|:| 3VIed}qUdd (+ DxT4piKs>Q{Xgau=tK#Wy˛n,^(F%69!q%\Y,nX@$Fл痂2O;L¸XM$a(DG{0H[-ݨ{'_n)\*aWLTE#UK?ԟlnJ"2-d**X)?LrwQ.( [ej=[,ŒuoaǪ[Oۣ%fw}K[yxD\.9;GW8wFwst ,~? =+ݦE mIl|FR0b پ j`]F{`P׳"Jooc#7,r{_H3@|w;|dKv$¬I\ e@np;OX=fCSs fZ𧅻-얫{Hvp2?sc̰g(cxE[hC:陸d|E3_8ՌdgY27޸tc-Š.~^rq-`-uBnh+XkIӮš(\lT+a0ho㛭e[RFnOWq44*v!ӬjXa=Z['~qV>'4ξn`% 5RGWM?;7T(i(_ے6ކ({ظtIЈTԚOyM6t?"]8bK@p˫s"Q3d^=TJǿ!$^t=P,yW{%$^ZJ7'͉hBfu\du⃅/l/%Yd;֥L'Ǽzk2W=`O ߞ!$a \ \|6ڭqT:yH)$ݜANʓY}pf!piz cx#`F?l\s~ N2|d?ʧ\ă$Gʬa4RsU,YxrpKe)T*Up*gw="F'CNl +D)/b=ZiPqÖހ6l(M* ;0ۇ8 o"r̯{ c>_)}kjӗc6C}\f=sv3]wx\}꜠'AO׬ۇ.7J#g)A/|-}'o(yrr8!TX]k&$uO 3{$qx%ZxV qGdLis{N4~mz种>6TZ,jwIp/8EZsUU$V q{Gf:1q^$XzQ'))Ʌ 2Ǖ7ɳ]|id$|lXj]c-ƍKĬ>5R4F޷rcb,m\ whƿ^؉κFp2A'ijS>/ Qnr{~ G5E3}$bsdfzWIjU|kO]tnV7" |[d>26KM{R2u)2F.”\$lk>4]'*mN0hтx r!-D Dfj9EBg4U gV1R;k)rώP8),!g7ў>RFM27ٺgNL.nde ъ>#NMҎrL_L2z^N vΦNB@2YJ JX s{]wSQZq0=œw6lPa{!l`T|a+ꄓ$Mu">V|Z;>ee񽑴ywAp,5nZE x:x X@ / 7E/I#'>Il?$?SBVC|b#h_0ؒ^`'P*]ϑ˰#@@=kR粹Aos轋Yo+7|7~[|1 mE]$Q<]=V >iHICG(%TZCgtN(9j>{柞?b|Aaa+ͫŷwJ(!+kڠ"8!.h 47ɫr^he GL5_\?g=ZK̆U8g?:FݏODJT0|g`4v57FjOz3/q~-1u.7ͩ΍>u#!Hj_?^?w(&mG;XLBM( j1yO7R`#$P"bh2 "›sK.Ҿv=lFLngyOi 膊U70d ar>b5^{*y&=[7HsCJ>OoT潁e){#WD2ZvɄbT3Cd:7s7Ɵ,S}Xhe.gdF;JItkx2K2i8AXd ![)3aQt숉bR! 0ռrg]置Lp_*^0$ {1jayː[w\kVʰVg aJK`L= W-n5JҺ?7R]𣼾jo& Rg6$بN"Jg( iM ҽ(kk/T9?y>1҆IPKŦyuoE.IJt} tԀR1IG47uO,YySQnT,P$\?|[BȿsLNssacX~]'F(,:rBH!Q"! ]ʚvV(C:*1we*0za ܓo pSjX*((1>`"LV >k0QTi㜝^Zws1ETMϹgݵ{-+qwv[x>m$%׋Y6r6bmܠA/sP;}|p7aRC!dg;0Zf~Y-pٗ"LA4(So Yے:?TC^PGxOzxr)_KNkGTqW"2ؠum2K'ͭ=5S++W⁞f:$ҵb@J:@W( kX5pncf ",{(S~xC(I:B'QGfrٱcJ1{ʁUX~,RXb.# 0cX[_JIzlK^K?^*(Y`j?N˟M1ݻ=qEH-㍆%o"Dvjc-`[ن-Z=Yt<ౖ9/^KdԶr;/SF5oڄ{o.NLbA2]e~z`u|.CFLcΆ1F9#%ڽjbLo bS!5d !,KFBoi:&kqF4qe"y0̇X;<ָj@ u[ƢpS 7o9$&Л7*;jTSFlN5R9Oc޺瑀w宺xhp A41<%wb?ccZJkr"eH 5 (+tE/;O9j-@ij{6=$}nˠr;Uq+ig~Wlt2«03,Z+EhmY:0/oK0ƅK\/c%HL$ Mo}ʔS G|f[m$!O/!AhR! =d&'7l5p!~4c`|ϝn 1tj^ɽrw] ㊕Ue}H^Gce|,@W?tnLmX*Z7ړ3C\` P8$kچC)V_vUCE7nCo[S$g[ivPfd{6V;/ ك&{R^ ]nt+ ecaxC#ADY %o^:kwFF(@ITew0ka L]o )}vIx eGC_HdKvXF;k`\O)݃orn)rDP~&'>A^dVT9- ՝&t<#5riV@]bPK!l9cmg[Tٽ%1*X n}zw(Vv7et3VCUGS7R K3oվ]$*X^P4,JPSj z1hMڟ^)N_Gva/%:ia"N/DM);<Ƀ՟VeL~v:kQrN2B)V7 ݨ" ",lFX0j޺H AW}g4qӨp%qJ2l0j)H2,M›udtʸ],r)3boR`K2 F͋˱7{fH-0cӚy4-bK,3%>HDrz*G\kQ+O~қV}0"@Iq eG!6!ОGL>:В^E]Aȷ_; y!; *KLJ܀Mw (pjh~`>0;م$H.:\/CcHrWIyNzӥ*m> 0%yDæC8|Z?n"?ɇu\w(h1Ij?%w_̥]d LW CgjnE%#/0ٜ8ujUNS QsS&wE^:hڄRلNGZH 3~FK0G\qyHXE !NǥZu[VR<G" @k>Nz`ej}[v*C5#(f'C:%pƁx(іP^2mVg͊/sxP̙_oB*#~Pm.4O)QPfY }cV4 7@,Ǔ*)E{ B9e vCީApƼNƨȥ2n-}lLE۾<Zoh\e޴ eF`C H#8DԽ6h>/DsHvCqGݶbdy'gXTUV@B,r:lNg6t|;Ц cT\ D[xF"Iax 񔤼!y/DUn1)Ȓ}vN:o{\pz:^*߿#Ck "HGTK} *{/:Ǔ_P|ljMF_h;?޸2XB~_}w-S )PyNּlm-nwFQ KEH~TU4or2:i@v!_ѧIy Y 5IwrsK*YP&^e虝ƞ Op[fӊV䛼)1`*T0ҷr-W^~YQ,qrЂ?]:Yۓw ȵu=`1JDH%F|'CFq` Y_bCߝˌI$@v$ g+.> rMhlF/>9ENj_3C1kG_Jk?MR"'IMjČKMEAvLM&t)- >g7$zPfO@9=-U;gbefɄaDojxB7)8uhyCp6: M0S^;CuU.z_}6}d. 4_E\!`M=J>qJ[@BݼPO8SFp uDȖ~wO}c| 8uA`|29c#F: #F>CX ӶfXnu&1\rzwgCO Zq+ƪra@I,j3CԼ@4؉/f3z#kG @0x~d;\&v(njavPHU(ڙS")ĞQَGU"phM3䰺1 y8!z%ʮSaW>{p?\ޙY򧱌KHL;+< @~do(t*tJk u/%:.*P] FN?CGv'", 2+33/CKBdOgycbɣlq˓zF4\^D\sF"@z!Ur?\ٛ43Ϟ@/ MN6䜾g6}L,o@ ڠhun)iL1wxe.+PmTmpm㊍w -'M2x=;i7(› H˚97 BvKWx"p%[5=z(\kX*Tmhu(v#~Ǒ[cgNYX/W[6ZEHf51uz58{ 4'!%|y~;|)ІJeo^ٲt9LFoL'-jjZ X`W+tm7(seZ! ex?9uK![{ rZ0czV湵Xt eDѺ.FiP4?I)AS[nYfk篭 K$viA$:yܦjJ Ĩ}-r*xqbnTkL.]7ǐ\'5MZxi/-W9;c釾Ƅ^+3"H?x k<!|N(U}V~xD.OM:Ȋ8[I5+}Wh5i Piv.<+ Ot&#Ǝ8'vc$`#+SҞ |-5 /rtLX-k47y'U.=MΘ#8O WG.F0flrqJG ZSO)ى]V3CleiT1n:">kD.:PĐM6T|Yrz˒4W)f6A. N4+_]뺲)@0`[i _xIZ yZ7 C Y=`Df'|s$:z xE mBG{oB,*H)dʗVZ(9(&}>5n0}쭔OW<™* C"vΑ'0G|iKvlENv<ߌo%Mzzt*nvM6ly)3%Zj^pQ̲?nQ tZv ؀{alԃT7pƥ6 U5u;rT0EWOtayT_s? 叾]~4!}dIvCѣ>bzZ`JRKM29߃s/jfC~#4өo>-ٿ""́@R/О-(Qa`w@K%DG-`bw_@1^GQ k />P#6NUZ,6]$'P,N}»fBWA@gՇk&htJcn7C/%mYbS>4AZ'+/&C8Ez'su@HIzصuV\L=;vi[oIKV#YaɩPUBzy}t3f͑+ռr mA%u7B DG,Pҡ8M۽:>Ic|ҕ9ÿXA[jMvr j3rvOdﳥXzRq5C ԰EOy[xEy.ZFdV:f;t<ӏɅ}JI>N1\!F̑-!л&顩M.UK=ZO?͎i̊Z"\ J)q3(Yx(pWx=՚A[Bfͫ5zl3g:!9)X,f |" 7\v'a1'tFa˯R(UƗVx̊(ېeǾYpX/4|JaV}UMLĉߑ!E~(̫hkuvl6Io|Fs͉D)2ÁFJiS?x[6X`ʟFr 4d,1)J{=p<2ut瞽;O(w^Vu䤍BR΍bݸ_6?+pcБ:#ƪ܄HjXxhoWw{y 7g"oo J.F#Jkrw:aPOك;t7@U^&C< A ^[oU VCxpVbBf@ $cd*RRKnzZW _SrɆ_e"ȹ}L,3GjՀW `M`L*Ni`+ 烅aF\ݥ>,֤C0B+v3-B`9zC1MT >dú#)4L1nNhn?˃L P:b;o/_rV|~Ys&^dRϽۚv[@7ȁHoufo|[[^osAl^in36K:L#=.;ߖil @䭭}O`?Wr~ k0m%]M\2=]SkǑIB-a%w m~3XY I$a%56PLNNUGH&7%uʥB¥+V*Вl).7mrNCRюN6)66޲Hv}&WWwcLek/'#QC ";~cqIvRyNnZ겅~b)3t8;20z$H@Tf z z~|uNnI;Z V5ä1y4rᛅ '$.aNfIۛXSr^ F-g$VP8 p$WA/bfejU2*'7Ls5!<\ZR2B\9* Wb_/:5)w&la4WVH5~UJ ȞpY*HxFne1;Z^-r)^?ΦKP *L6!(6۩`YHde2)v GsyVKwcd?yn96S)1dp'\~Xz ]?1YCiSRA@EdW. ;WJ!T!R_p'1>% j#"8O0g~h[JrK%Ü ad}# 8$w>Ɯ46.h\@s}|Z 4p3+_փ{wcP@\UT  hRTDS:eE[N}#f!ik Dgi , hEdN_&|ZT;ZI&"j4PvD5˒BZm4˼؍uL^{3IX`6rn1ߕS7ǮIJ a5uœ \ߏwiig[L~UP_݊9AJP3=p1nO6֫yW' ^g׭s'`K ): 0"/4ז/BĜ#iCt1VYf:=:F M]2xہ#SO&V$ئ\qtD@/.%r{SJo;L˂ 7ߧ:-UdS}^@v Tp$ğNE&61-_w>쑽DRl(Ope[WP3jTS3(L$ dx;3.5v(~+٨vFC_zaGH͇Uf#хR#>Ί:ks2N/Cߣ5_ Vu}}~e·>d䀨3򻣁`p=%s媣DpnIP3^嵐sD$e᳾H\Ak]7`h.`Un-*iw~jL2W Pĵ^E O@~\jnk;([YIQ&̓3->s3#gǩՏ6TB[b%q[mfqDm]̾k?Z\[%X5%oר9JY/:f3Z>HNp]И uYc)yff 5rlӅ¶:VyݙnkMg1R\2ݠ.JDea~c !(Cip2L c 7j ܾwfuxJb~(s4:]ⶬos)'8N/"&˷'`+',s{ż=_Tōٕ9=A{̓dž5"3[GxlwR~1ŚJcl.X{GPtDWԍgx . %{x ;qH9Z?kk.&UW4<v_w$Q*7i|`dw0iX30j .wYCA=LK 4u:Rm.UP[dLӐ#Y+RAvOSUYZL%+|ݢ"ݦF[& ۰4쾌z"-ߜOd5, ,f)5gܬgY1:a7Uo@[ާM0K5[.i:9䏭M]nK.u-Į1E͖K;V; s6 }&pF6[z)s5<1JV%"vzG,#?'3vBtzRO("؆_kj+aIJRwFEL5#2WZ*$ƈDAzK\9Ä,ٓv2Q&gp4Hz6 ޴=ݦL.B\}q/u($sMI572U1L<3@X-cx0p@ğX[J1pDUN#cVՓ!uDbytSkT460w7,^U;4zqPjh|g+&=}SB\wDhXUr/b [$gDeM3 *Ʉ֍~J(+ΞXkiY< -Nɽ$Vt;[L5< Cյf4[Kl|)kf[ s1N[C1w+xND1vFF^j_4S, Ib R>|F(;Lax}hgJxKzG`ҁ3ZG3=BOᾅVVWynE+qh s Pm*{O&NTH4iUQ\W^;HFF \zqXER?R G*L\O*#&#96Ir`dű- mq}\&Zҳ <(Sꨘ;<ʻXpEX5VkfI[X:p.-mSv]zS]^C(R!1\U*dO8Zz䁶?2{&~Po #m'n8G4D~k;S>^3(2Ҥz!tVUgF);ѲùbEKwus(3_m NԔ휤hRvWvh]0p(wV在T!#?57SQbH'Ƅ!#wb +Ua>|DW0(4o=I&=fLS#Y PN{be#E)3!G7sK< R]Jީ ǀ$Q"ZM 2yvކl ?o#\qQ*Duf뙽7sBWFC8.i*UKX-sw3`Qp9lun0bA-uB , xDzضZQ֧?Q!3l=#(oPC!|52z*pɡ>j.rէv(F[%ʐc:M8+ `0GvPAXO%b W{Pk1\6EC(Noy( {G-ȿ:ĎٚѠ/w~D9w[Z\*yuvЯx#c2ɢkZEaaH2!.T5ի"ŶTE$ Oo~$0{ yLnW9٩x0F1ψJjl1#ooz~[5AۅL$ Sx ,Xbg <(z S{K}.R^ WDtW| OHzU_i<Y`k Z"0` Rx#k.RSw9X{{<}PG2R'\W*3Tڈ#A-o)/UYM U*j- JO卭뎻QZ6W}A.ZNw?cߤETf ^!BӼ  t3$):wf9@'4a#ܼ.tՍ^;32Ŭ!(~I?Cc̠=;L(CޥUƱ Ch)V:$ULQwY){AM\y\- J0yI a7(ʣgՂKZɭp(v%nNΒ2G;&'T$$j#\@OYE(5z)SCQUx]}-Yqr(|#| < 5{>LV A ֱBG[M> j4c˯@뎏1e͎nL=Ifs%K%PeeЩ@\$_Ƕq3:P7[ o믋4 0 ;k}ۨKB41ajWWu ;OH+?VDd4V b\Q" ec.%oe.Xɇޑ2›1ϊXD^۲{kBz@X|Gt_C&7.֍gLHI6U libUX%"WюsRwQ&XEeMP 9kF;4[TX\nwql^BV $KQMf܂2 K7ug%wRI8#hG< 0ͧf 7W}_^H-fgh:9d;m~: Xw6Fv+x出:"1<v7"rnM9ɂ U *c,TDһz Lsq$odI`.q9i>vH$nERka@5C*ֳsvqH3/uqN}N{ݴ$e'xk=tp֕ &!o.9io{%fZmyKLVT(o0Kp0N7uA7yFweeAʹo>ŕ sn~;XV?yĆrX=Ӿ\̈1 Ub#^^M#ZIe<cZ9wyyxvĀJxk*yr+p?kU]+X:d+Mt84JAlVFm6{vgwbkVR ?Z~'da1 6Ϲΰ؜χQUUo IGQv€?*=b"~~ΒIb+,t9vG7iXnFթq8i3+81!#kZmC [z[\yL"_wwBCA@ 6LTl)fcЖѿ%*;٬]2~ʐI84נ3N?!gtXA6b")ʭ J+fCoPy57RVdoYP_ݸN]^ծ@XdmkGhd0iP761toS*lb q5l+nXdNS $4a/*鿍xےx$ؓ hUdڡ%؄%_AĚ_{G^JC 0o\e'L>֟nWUbk;'[S;F zn\֢Nq$ȭ}'S 0-Am}swUOPL\@Ta1&ߩp'fY/9?} @elr]eg0`d>?5&cF~Z:2:+9d<7)0l>-U?r[3{Ϯ/,]TJ~D$~(g$q`=LxR< +g~xHX?S@gN%73fp\a{Bc ɛc02Oh1C&`lLqюjNL'y >e޺g%ҽ1Pְn-JGs.z+^L PA3 aε pa%_T־-jokh{aue6G)J{zeO.M1 mGz M%V$(3}GЌo5g8kz~SWDQi#%Í3^EB/z&7-H4AR~;< 2>DW=TFnJ^a顒 ײRXpiw͓΅& 6M@{)N'*]Dz ?X`pPIJ4$_?5S5 } Y[TZjY6_:@8+uEkUsxeNҔݛxwau ($[wTrΟo2ưVl,,AQ]Sfr ^}cS=Z[o$*LeFq{#mQMN ޕ)i\{0rU҆< [c. i1B-yiFrk|n(2WeBY,"W#13Ψomji%^!!jY[MU2:8MRKy`x'+U]E4D6Y\bx%^qeirsll2Z=G&8T^T)("&8ܿwy1){(B5'|@iOR VV ie;Ȋ"UCAy >zL)Ѥ. E+ \3]L^U _/Q I 1mfSj~lv @T\@F&1:K gQb,)Nh<+IRg/kϬ3?~KQ{9{r+>ݖq?щ! WjшJEF*2G;Կ(o_ewtGۖ["I-S)dur{OF C!I?L%Qbfy:݃}(rj@1m*Kk ;bwE6S^GWN^kv@[A MEB|:/ȻT'$)m$ȭN.k/*_$3B`Oi1R śr_kkTʸ_rhTJxKC"?{+y1 AbdPbŘB[cI YOGhg_ML*!s6 l@z=K%P+!*.2PԑdR!],ϠM*0j_mS6`$[O51%#h Y!axDPaPY)g{zl*aD]I 0"-5>jb8kYֹؼ#[JY8ŀze]$yr9R[T 6S )IJ^fv )ˊ)_74[$~pT[YPF@M%`qf(q拎6mČŨ1#Z t/iUEa\;eN1bvfTVe |D?Wܭy^aQvJ4|Gё{S/X=<~lbRU<;6G>K>E?&ZfM44^X*E im`aqpV컢%ax{&ǒp#. wX>F,OC)*UMI}3$tG;74&ҒP&qn佟Ulv{?Gxu):]h ۄ"xN:0QSEע0 j^>˅UqFihp 0 D+vZ՛ՠaXr|AԮk͖ -Q4scEm nTisz=o Dx)L.d) &"=,/:xs31w2 z$6\u&-+_㻣W11"w85o Yi/1/fWNI*#Nm-k`pه#/(^ -&*LK&|\EIJU)Δhǿpx9xlxgy$>M]7YC I X4pQ1a*Emx_zdINn+υ3(0"'ض=8枯Sɖgsb{ ߭ǐU#FdIa /!U- lu$ Cg<(<vPeҊrr?|$E^r.Y>c5EJ+<]p:b}^c\p0ugiסqt6ʒ_E:4Ѣ75MgbWAH,!a<"@|hoq5Ν*TdRf}"m.ny3 #ͤ,z).ֈC~P V7I8+Ոec ;%L>SdV_w) 9۪,*C2Ͱ6g9/E,̟NH- ׋%hj#y ~]5b|m"e #i_7M߁ڞ}7 j#Ǣ8>zS9SQKKXFD^֧Ӕ!(`! CR:o:;2 fza*Cn:u9 I Xs~!<8KkٙKXGk(bb;R\( yV԰fɟďAWm)?ΉHu.&J&NfՍzovy, ԛy~)[μTJ@ Lq4T 4(n&Ve8"YChIޘ卥SE&)yYvE!:oh,rN+Eg4efU0uCVתD&׆ポ\x7ȁ0%XW#҂5lo!FQ!Bg]T{}YKWz^߂zC0vZ&/؛\D(g{p寬|UGNLp4 oDFcw#sg6'-`ol mZ5hMCƾ6cդH ӅBQ!,@=>֙嬰Lߏh]nBk>DGh }&CW+\q1ېCcXmkf _F.J{6{RjV9?߹N?!v?q VL5و#if+Sg1@9ugQ>6U†y.Uopv ? Nr[OF#+G#d§|C]T5@"+vĶ Dsו[bI2hECSy2c ٭x>S!LSI1OÖiRG:chCf`,GWˡQ;" 83ia}~Gj=!.0'r;!RuTx*}P)[TAYHΊ>IVMұo (Y$wJ&WviWd97$c`lgR6o hϨ5p!ѳ b(%/Li;ˣJ|P7̐X$ #<ȕL=D@WwyyP+"^P| CCZ'<Ŀzq`A(A,Cˢ3ORmPodj˸e^& k!/*g[q‰(sHbON@e|?wбKtxa5~EP&& tOAv"zCw\$ePmw/k=R9dnPHbN$O|GgD:v ݏVMfyd΃ 1Xod=;;o&4&+5R: ߏ"40e|i`V{Fl_o?3 ڠE"mfP2 -NBCͺ\$xh!|AwHX!!p|!P.;̲m(U2vAfwtD/N,sJ{(dizȐT6dAϒ'uy-;6URa 9fzI$>+fwG u%w=(= 3!*zoN~hȞDgʉmK|`e @1J/);.,C^[6*|G ?)PW=7''" Jv 7Ұqލ%?f%SQ}N4!6Ή) ƯFznDHyGe ,5DdT=62oی+WڰFQ+~X6iIm5j/a֨螘V3 WVIa)%5ʵe@tEmʤYr5Y!TLbnF(ѳU)jO nf~ nڢ;5ODXmy=H 1n=ol nԢ+Xo/iSClh¥O +X |;sVXyZ Cj0 3w%ʓidUQ>nKkJ#-s-,j~c+Fh3)\-i\|2 4y0M4M`g#Ns)zJg /n=).:.% D@WQ֮:HSwόO^,I<T}#夲 ua! 8_3t$-o[ڣ 5<$R0[\W*2`iĊu1MpO: MҔ,%"3֣PX&dLz%fiվx8ꕡ׀Q@39F||%20Dж8rM3E1 G ++ۑ^ahG:Fr ¥Oxz-)u rFq .X !U=v:J2J(.Si]ˮ^nMu!szGžiej[Ҹ"'jTHSz@A"ق[Py vGֽgkmj=k5?2+&w׻]kP9'07›]S:?WY}QIMy}>^mc(>>\ 9 rDEkO+Xî 6E_m\!~G5eCwH@_:D1\FPa_!~Tkmmw\0Tx dMNp|ӷgz;qKzY;VWeKIlWJ@ &B`_NJI57޼Ha!}O3g8Jť"Bk / 5b {v_JPg +d,]'itN%1myL_ E>@KC+ǺlW>NE_punUgr}{F-UUV׵n[n~AٙEodCGlQ%s_']:#]MOڜ*4G,2c& eYf g)Kj<'/8cLc݌پ/T<;՞<~0esOhuc\~H'j2%:zR!wyaC:0-T6YS?eUX7]x5YthKJKJE]iV2S](^F}ږء~󩵿?4ZioR0lbQŰr>R|toZE|^V5ՄDa,}]^qpw v 3+fʑ:@3tmZt 6V`?zE;8u "ER3Y0tRmBs&wf^+ +ܑ&6nD`6N jYe1^CxBoB{dVZUXVh9OadlN{x~d 5WD3Ⱦw F'Y?4|cMBՐm&u=#UQW@U:5!&x / U74{heX A=. H+F&Ŏ}zSEa 1vZA6r1b7A2s9`-ecwor~Cr5=I\d"ԩ3Jur/oc ^{2g_C;/a[:i +L[B6:ݝI.J[̂]+ѫz4RĴ,/T0`^l9C+??sF'J6wZ-`e#49B>Կ2f+v7,=s_|Bܤm&tn8Dz]K^RgzCc5wv"UT4g0GL(b) БsQrvDkY&ȡp"au~?<ƚ05uZC>y;?9ݜBeY&[f( -NtΟ=J$7AnoMZtw1zBuAٍ͇R#]$ D.閏_k a]3r>1 ~FlF?f@H|WYGt2 ƻf `:X kw-F٫gIޛR5ANrT:NIp\_l|RU<oKZXd:LR!Z o7,F97zց@e]Hg z/飍Gᴝca0I5@OQc.MSp(+t&).rZGTZ>}"enQ'"6VؘHq9}$An:P% B C3ɽý WJEcÞ?9*5AfTmJD^:#I(k<[WCZނ . H!ў&|ƪ<|&֜gHus87}ML0Enh=f KYk+VPTjcGQ u-WuOGK 9P27!bsDJQ=&+CnNQRd "?J=ݹrC%KY{P]JSN|=YxnvMGGwo;<05<+kx֬FFuЉ1=j7H\bd:\sh+.b/PWTG>]EdۤA<0nLcAB֎`lh$rpFI$$R7v#ㆢO/(Yx2hZ?Y]W[@4Q3 ;M}[V +6 hLy2Gߺg *.`Dry jivYS82|צkxY1 B+zI~50RA" ^W]_(`6El5R0}ysF)7Iq}rs\Ձ-tw@֗>SdX:FzVؾyU&7$ڭ0[Yr5⭨M N|Z`Dmҟ[Gc33&DtEe(&&1?qbNa~kٱ3_6Lu_*BC&D i&ȸ7kMup{/Kib;MQ}d*R۴Y>:2ۧm7)aPv8+U>Q/HyL~zW)KKs$PuQ&d=(dJGH+75J+b*?SIPZc>JTf|BÝCd[S}G e^.{䲝Veߟof-19TSu=6{2gD~Oԟ*I5e'|h2ﯨj8 PK )7B ̸dl^!mdB@GZdbKy-X! lυ;8(+"q-?">wNmҎ1"5N |_Ue. 0xj B*v+v3|%>Ϻ˜Lƾ[PEuBv6iQlr.I(G1Ϟ*aa"'ML)p@ibfsJV&e[?X_ڻ>J_e'o E盅nX(ҿĆ'KSr^A{2vFmyK %93b Ol81jךeTx3|,0DUlܨ[hu-?LJ_^"Sꅵ:X[v6э^*F0W3 {9f= S%7L$;՗tfQ[={o>%9Y|{z49iEPftu^$^΃w",]iAcaL+{K#<88^X=/My`m|y}y o}i*"wzk,yW|[?Os ?|_'NNY.̘Cpf>B`lmָaCmnИsmo?2m:[u LuPݱoy|[c6 CAZ3L}!:S32Ru,z!SzcjqU$vI9`|*<5`KS./0W;Ӈ'T`)#M,V|n^{jrA9i}vKft; t.3' diV82rW\Fw\l:50*QA;iӹN >Z  oH:|Í cG|O+b2#=`?:`$:Ȳ#2r"4L_1U?SԻl\~<2U2;VgYGXb̤fƐYa.C=8;1h==M_n<+̬w?pZ<|tbElj$tFo|%YB̻uT<IP?~7a0ZMICM{L'BAzXǮŬCgﳑ~\ FMJ^q<]?q ]фN[^nȽ֛dF8>7װ+kTDB2TQ%xyy5~_&rJSRz%%ąp-229}?) /ǭb$cz+AZʭKx|=Jz5HquFjkF#9-Ljj맳~cA}(1r&S5R{E$jy%rbymHeO֐z0CpK9'Rk5K 2 e)lJgC W n6M@T ?"wuOeb4FUXՖS_eADPhS'iL=ؒ}]+" lɛF nٰfrfck4 WN}c 6DVzKp@9|1`I.oaR040W\c\EfC!!ye^lϿ2Sw GENwzu%:8$iW4nweO8JF5 =\F>|t+]dSnF8"6\Ps[\c 8=/WN!VX#jyK 8e-׉%;`i9oq@i|`->=x3ɨp]w{Ѧ8iacf$kxe-q9eDxLqJnkdpahu 呏$ ){kg:m+BsVʷZ-H徐bMpUb9 0'\OcK`-gX- y,0_eÓ(#Jr0K,1RK2?-C2W MzhŖP;>2<)ueaFe9зz|Ձ_)Ta ḣ~VƜ=WAKXLa7!M jb^h9,n aB~Wo  lafӘi?>-QOT̈́B9t*I_w%dܗMq7؏)?Gn_ ݻ{ȝAB/)#:b;$Ҥt K ˞aU"& Т@Н uk]>'2/+'o}#VIA"ɲ9Cz$p>g/~̉YsڴLKxORg {qLIݲkM gsůr#:;%Nω;muZ7, O-q[sh2͓PWtε,]_@sş@r&]ڳ1_O̔QoX yy/5^ƞdgAY_VS|rdPS4t,~tC˕_klg$0[~í]xقnIxi RRxOgifwfd#sK]9Wc5f6PՖd(k6aMO]S[{(D\pϓY'jÑ^QS cGfFġp^ՉŒէfp:͋.t2ܧm|sP)cܢHy{&5A%vާ?C跲(KɏF)l.jla Ma 9Asyǝ1CcBϵ 戚.eEr7B,aG[S%^zݘ-kq:,yBL BGJ<2H'z]9-|pٚgV?a5'&sߣfHO@%9uFXdAs1 n˷3=M>5YJr61m~UL$3,͇"?no3Œ3VOGn49+,<-z2O: Zq OEnXKߗ\> ŏ?pjB+dIUO~/ Hp8oVȲw2>&NUe|Rܲ kzH(^ڶm>59EE3wvfy`k&͞o3w[j ^˾fAe7x3MѤoM?<`V&(CN_nZIPSc/!`R󎖤d}C>N+8&CZW:d~ewk:wǖڴ0ςe& q A"XX#9Uy# kHԾdO!q.@cLI4h]q*[O%}L(QrT~Θ&ɳSS{~KʢfAs'!44y-\ŏ8J?H)XhYE dBBFҐF Wm+?i&Y\=fӏJ|e CD qܪa익+@W2S92hu[IYWhOYØ*s\Z&*&-(;{Ne>jMP>bɟc GώQ:Ifޠ4x}O%t$2ۻ٘GjW:wߖa֡$#{e+pSw*d{>\Ml挌cCO1FBX]zC5|[k $VS ˹%nb ܿw-zw 6[T~ZM&R ̎~$M,&ջ뤒} z5W`>]p"u7Pl&K`ـA %ZV8Fq>M ѓf3wkQ=R= (df`6Hd ia3W!"<ˣ;C.6 ц|wHC[%?/ɑ"W>$0C z 'gisUK/=^g[-H*9Wӹ-~𑖰X?4↫^/cOtˆDsюX*{A&#2s%X,ON|R8Ťߢ^ުrլ- Yz ì]C.! ޳Vw$fi D!f@0G({3~EV* "Ku@Gt+zbZͦ -o7dԖnt r1YsarHcyjXx5$X 8'$ΏVtD 7?Z?)tOo*'@4zYf~=4Fo ;}Q"TtK< K14SArJYtB]R`!.t y;H7FC^M9l5â\nZATkO`1,[կx -Id.R-$$^T.Ox"Qyh;o>Id-\!ˠI8 XS:6)䴔t6VQSFo"HeKRSڜ;@#l`| u]=J})y Y:}I DTߥm-d9Q< 8 [L֨XuQp1VY(J d90W밲4A^*(OSi|s`m9ߥLnc8c^h67D'Xwj*cvs1a`2ۇ_(c(ҏ,*w;St[GyP`JXδFCt\4(hu2gqfZþ5k˰5ǕIa!??]Q67!" ,ȴuUS1ҕV,3AHR@8d5S#+ay}y0~ǼeXzB@4x|)os휱 ݥD,^V;x#6l}Piy^3k?ٹې&Pd3hyxla[((aXdub*\^ݔaiyt_np@>K{zْkj)'DEs4;b.#|8t`}{u߻葤0Jh[,L xvxJmK߭&7d8/36(L@@gT(cbE9osൎeɩxX7se(۶hIQmxD\ b居 WN܀I'A m3%٤I$W>RY&s,x]@Jwϭ8kI0R4F}N3"Z6J*MKYk?)?rTÇׇ;0 w =<6乮 Ny+'_f‹vRfw䮯u>ƗI q5w)Kʩ^Jf].QgKٛN -7z1J#YfKT@#)M;1cb8 :?oQ I J?QzǪ6{X+%IۆLWԐj WSOG%@BEfPe]I@&{yUݑN/&$ ~!%z@'C|(z^nuF^K7a #Ҟ^e" `7L ZCn1 QkG,[%0W_YH&m Ӣs"@FӰE/'גly27*|k0C_\za n6n[xvH9rt$U.c1-q=iA|gm&aP'ɗy)!s? i~䌚EC`X<(@Tgt| FdE{@6itt7NY1F1L&[h| ">ůp೧{s J}B. I /r3,х&7nm (k#-Y ؗgPԼ!>egxkP{K?B|~nGj&GX]P/K=BpQln y&Ž[~'lt0Fj3$Ȯf`^I x*t!]YD^yu %7?g&I\^0ꚾr ;~hPqs(VrUŰJF; w/@JibKY !9Aλx;PAP*pD4 4>Ys-IvZ6,ޱ!\Fo=0‹8?+."VKЉ>e=눚.daLM/>bCn]U\\a#!?ABjpo0ǰWF;Vn;d2\!oǙ5 ?U GX=}`+mZ5.`;ǵG'qׇ5_pK%S K4 Lkk]"Y?PVnĔy/5YH/IצTG@u[꒑3>U$|N-TP=Ն$B&gQ#29@֦࿎~4ژH7 ͺ`۴SeJȌW^wui~M*dnbG^E ڲ޴0ܞܝ,ȔTZ\f#5Wm@=n @"t&.)SNԸjtXywy'RP>y&u9QxP68$]OBhĨ+m1ov@',k5@g1HU%}+'5_cfjmY!jo2d2/=M'o(i)튮*Nʱ1>ۢVR0ٔ%4c!w ;ܴ漴EkM^LtVXҌx8JK&0^h ិNGWTm]#[`4f> *Թ8Ty}2Yq 3?}m$~&~d͒PЪp}#6<tu Oy2<\m $̮etI$hs/)< iF_`b\$dЖ7w-\.Jp1Y{ 2JL1 xJGㇺQSX|92T%$\ER"yP@WœB՞| ˠ u@[c3Z#aI<] yvboUǠL7:sS_Cη 1L`#OyY CCFu\uIrUfs8S |nW *0)2cs%x 5'j gR$Ͳ)8ydtqc~ݸpg׿K܂#\i#0rs-|-1(;G{:W?VQV]s0dԌ&qqR9P;WbxLeF}MU>p(;N}}[T ԓ0>k'W;5*UWbY~ӧYCak\:ۛ %'ojm؍`cq$KI{*_ v3} .'ZbK7Ҟ L_SMu+@?G"aVI* LiDN }6po #HgqXP5dduҕF"mUH}s!ERU0UZ V~W% {rgy}_d!p^r*qpi;UӞh> ]B փ"`' CT@7Yyd?xh,ZrngxCcDlAJUmቇt 2-bk?evzc5٫ϥB=J2ɿ㲼3NaY_ 'im6SNn9[YKVp,Q &$E߾J5o!2c)=2PATal)P=ڣ}g n易cƞ&3 [&lyyQcx (~ԏbO<[x F=txSKED^!9gqv ɒy9c WRIHVӜH:ķq &GV0U+}0)'n}AbMxU9`ĄleGL?2ϵR?}thpAs{1`nG9;Cwy7B{ғwjSٛ"\#l/ױ,w'3f\v薧7Ű ̝WWE'vN ox)3VL3v_)?jog*XoC1Ζ[QNFSX[G*~ДgOtrhw8iٮK om|xEmҼ.lXWnP)-n&\`?4BS0!L P!e w`0"Z '`J[ㅐy,&D|q,RϑM AD֝n?Y#•nxjup &ӡIFF(tu =VǾf'+[]D\mH(V.7,hZ.bgۑ_h-`Ij!|nyǝJ[ w~:ؿBHf?*l [ ,f+܈mj{{µ7WwKUw#D4Pp[Jˌai?.LM?ӧ,H? ע61iÙ{|YQ=4%8jkԖEaxH>ӊe)?I%y]HC48%5z~m2TGO>ʇǫ Lug9V$bW-pKm@ZhW?{ByB@|CJyR08+'zb[kE'}5]q>'bk7.g~]T>:f ,aFO jF~y>t 1 2~^L5s=>?Zi$@TKx @g4;[ecx͞}|pf3P_Qg*ƪQnL,e~a-sd_y2rH2LxPxȑX&@n6ċVM^HiљFA,f/ Z2^ݭ\RgYTJPHvJTl4n WQ$1n.]ǵUwwg4[:#ZYyf#Ps"ٓH`}Nwqw@Ej^X1ۍ,x.]K3/\= 6i㲁ٴ"5!@M _"k ]EحH qK3;fR;tߋ)+xa.5R s@ʔ;'΅lLaC;q-̆EHYLPvKDiSf,f9r-ߞ~VCg'-?(_4e?qR?{0rVi׭ӯL}f<ۖqCSw{xuFvWd'j9.^|;H>}^9$`FYtIO_m<3. mU_ȮQ2 R"q-r95-ETw4Avo&} A¥4Olt mv(KCX\ъD(j5+;`S)' 3Ar"dde؀?1ͤ 5xs8p3 .ehcuxY)\cmBm&Z/$@L5e%qj=U,i`~Jo K)Ut13R$y]!_T`W&3%Iߙ$gP`,[ӛ)NE#[NYڻtԟuu.Gӗ9$q+fѨY/˯nQJ9`H edBR qYn4ٖ= woQF"P(37ҳ _k ϴWMe'\WBCg$a)l8.?OEи!ʼtZs@hma b@n /plýl}OP|!QQ;)=9PW#z#X}Pp˖ R[@l;|\Wluk)lxF( 7VUGq b8-"G*:8v3'EvJj)20aI[!)><ڙ}7 FltabFEazCwH0C'FkGShkX<+C֙b"%:/B3JDTݥSrvg; P\<2xP[Dn?7;vt6q$Mz01R8Z!-ѾуvĖ%&6DwPG3nڪytd[I`  *ؒqʈS[v@kz(7"ٽǏ~i8 K,bNY>65Gv*wb%vJJtfMF83.N5n/*C*ff p8ۇx IL%?ollePG+$RrRR)2De#NG</Q]ޓisMgHvۏTۻޱX3>3t60'.7S5 5l~4^rO$Hl-a8UA?W(?ٖ7A2ع^Egp%p=Y՟)q])Y ZH6|\v*N#T"z+u@ǁNR;񅬰*e'Ҷ9= PuwTЪ+ k]֖\ Gs/$-[vpfi$}IմwCY{30D;m}bC#@&GՇDG7$+<'oCK@ۭZ5-mw&<=K./Ix\*&q_|hkع_6 ]I₞=s0 ߟbaH!S L xeDEݽ0[9n׍كGE$KK.`6Iȅ`2 2JxDٷb uYk<Gl^h8w,1[ďzgڄ,C'wZ77m38 1'uJ &UKxxYgq|l$?rϡCI:2 /ؼ8o1=GP츴0pۏ Ǻ#Ϸ[s-HX@~n,@@墒}IUi\<˺ 8 M\ST ј,6T~fBPIu~=vzl_葸Hh;Ha4 b(F9U0WҺ01rF @VKOt.9T^[@,H6f6kD9KdavFKUG'r7sвz|G˗(P+I E;C4QS}tBh~.Xyf_GNCS`ˑ}-TfvSUXoPm B*(jLmGKZ1,dŗ{Sv"^jj ("7{T[0sFsҲbyVP5nV%&'-bUz{V J4A} $3 a01X>#Sbb˶g@އ%se!3pip15j)}O%nVYR΂KS S k@^:B]W+/#Tm>bԴd0|dKÊȒI[dHlmA4䥕l5Ze0[ @$ޞgBN2Y lU^SX'W_sj=!= @M>b_Zwq'#S ėVLR]qO~ KSTW&b=Ѫ8%;LR $<׮;ʂxQOxLUtkß'cE."ŖuݳQgA][ߟzj nhv=Ng\.Nnр>_1%F~2}]`^2qCۮ2+0x3ZwsF T'EaM2I2Fz]85>(B"P+˹2`FtEfG+ "Xd~LUTu3|@ TDqRNmJd6,J"]SrB8GuV 4[W±*x}&DnTl]V,+.iS+Zm|쫺FN V=iUVDGv/vΕ|n, Zq7 . 1=j)GLܝhl#EP⭮!,Fp]}AzWٔJ$ LF_F4d5̵YpoA:F|eq{Wk}hnoAlڋZ?SKe5$_le7aqI{ޒ}e~悵B].Z\ ݰp"Z}h PlB9k ,U_؄䝚? ZTX?|: /Wᩣ[j|(×7%ty8S{_`ooC%OQguPHgԞqzU]'22T:˚o)Pr)[c1Kj|NJƑWafV@:j<WQuf~ \]`0}3Zt ( •T qzQ-``}w2Bo*N,sH>q~"s 媇Dp_SWɚjem9 ܋S,ҝQ3}m6ޘK5R_ZE]", 0Nҳ..ÿ$ όcAƘwv~h"ſ?SLPV22V~ʢVD0c1jlm𧀍hKf8CBO \lTjy!oB.A5Apk]K?(r[5Qdvw`"Q@Bkg Oʫuᄓغ ΉH>f=Y;l^F,}sNcOGSήq1j}=ڳ.-hEyuc,iɱ G)2fh U_"Gr[Mql;ZV߆1տi#LVpҠIDcb^Je"hz7S[dj'_4.K%X%E>"M*(MčMi1N@XI2+Ҳ\{0Y[c]0W%09N j04FCH~! -R?a- ; &Ƽ)DSH>%GdYI=5 KW]@#)/%%~p= ǁ0ws%#$g1ŮJi2HRu7[*H$"MaxR%5{)w 1tUf PRxDmim7љ+,No ?9OKM)\V=G{Ic rHw #{5[>sr#J)ź6wp:D2SJd;H|\塵d {v;8N~'~7ޗ['︤,?<\BJ>xهH7nee2~Cc=>"!7u%>Ko*+(l;ѝ O/Zj]*6-tH:nktE+|kwb,$(TXQ>RÎih-l놪Vdzyg 'zӞ @{hlQşhA~)dB,LgZ>6;I2Q% M6-V?$,vJa@{u`"{1}R8+ osbxF#+^J΋4 a}L̩G6<['Λd{թG/"Bp?vyT;5KAlW'PW@"vmrsrǎtơoEsTYP 2f$V?ߜK 0Eu.ɀ1@v| @)x;6"jʩ5&B)`I{iPg ViWvZ#^|$J ~'s}K~ƒ#NDɢz@m/w+Ff(҄(Hzn[[=V2݀_: <[gty#v"N_[@-Z2lH'2Tkrc]-&9*(ηx0yc!y?}/L^Rn '8jcSUvl1ʣkȸʹ`6e?bzЊ~@ޤCUy w,՝2:IozuTp{GQi٣ìu/J_=` Ep@HߝlGߏc?tT >_K#L]cQCקj [̏-G =:9Yl? ^P n$XHIjBxH*b}Q=v"%(^" 9‹ s](dE95._\- -4/m-HȰyR؞j%C[PUÞ'3T* PZ.v-u^pov2黗zĵ 6X&b}W;I >@WjPP%fjl%HT6W7eseQn4y7*vQyln ;pS`Fjya_z|w}z/sHzćfSr=.ej0&cpeB͟ .P@ꤺ9 dO3n+XgNd-@ەcyܖ%7:%2&(s.u\slVD{Lj*bAtbyXٖLjO ӛ0?țkzl:R*lv/&g;Y|μ *s7uߒ_aRlv#Yu6hox4"g22˖X_ Rfw/˥<<%˸ d{=`[}^1ERT&G0gEjb:3E u`s}e*d#Ɉz}D"iZ{GV) 匐J_݃gM Mhp3\l"Vzy[9l>?eܱ/f"T#ݺZCp=]}h^Ruc߃t2|ㆹN K{Yy^\roRLWyc4QrBw];i̴:^ž҂x s~zFuEVgk38Awdt_"sh Ov^%{Y" x-PB@&DCVyN}N T?_g^%ZD 42?ɷ(C_I\9+e/Muz:$rH9)^.nA9 zr . ! g ~. 8ۉ*Nin1.,}ҫ 8]?'6A$[(atifͻ45]רi^XSCboӍ5_q,kiLF=odz$X!kr7ɿ|Eo"~5EWFMtm ޜ5)<:i%z.juOL^Z+ 7:UmIpM X+xn<| Uew #' 6T}c`# 2Qӓ/xl96(V& g0+2E+Nt~D88 T3J6$!:WC1T [80!5~ڞ-WdTY| gd zy6O].'!n9i6KGFyvͿe &"`qY*;dG *LAwLBCr9FS3JwHҥDhD,mdq,1w:Iӡ5Nbqb#ˠ4 ka\[ngl4ɐ -Ɋk*x6s> :w] 3-gwK:ټgnQ~DTQhx6"V2hnD( )Fŭ,.t:s rD9Ap_{YS;)ǴBȳ B1/d܃4=Jt:N#)7h ^K+ {%%"e48=0`i+eoiD< ϊҰԅ:+ @곒qNܞ7wrX扶l٠>'祔4:Q7G|eIVw i z6q3bg0#,Ae{ 5i""}2L zj6C!o09'''@"?fVaE"XeEĿC!v .|9uxg]A] 2Ntӂô}S@) B%(xpFk=oah$|jvi~`]FX[{IR^6m}膐nٖ6E,@hWAydoxU+lwl%W[VxĦQh<%m8ش:ǵs,% 743 +v F,zIӮK~4nwr,LJVKE !Z!}+k liۍZ\,8X26ux(͑et">xֻ.~umXxCF݊AxgBKL-u4mn~E5;;VYws>-G5؆yOB_D==0De;2a.,(]YΏ)XmV8C8ĺzY,.#jS =/9%M4Q ˖Bdv kv-<s.RSZ-"J)# 1Łu1j,\^)ݹ(FPZ̕rzIR!5%it>[&BFQXb[ S%TdOM~P M͗ed$"Ѧl=_p<,Ǫki^%,p2bP/S z*dNSC7g/ER(#'.Be^(wFάLǵorw;(2=V Qb٨~cWg6 "%ESFH5yi& 8jwK|aAmQ =13c29 q/GműqA`IR:)VO6ym= H=YcfY`'HB? q;Ix>ZDg(Z3vYTFgHpYMۡ;V ȷ ř݈<9IXpb:wC7+JA|Tmwڭui;  <;ïPTĸDr]Yz@O$,i P7s?/}}ѕ)^\C b+;=,| )'_',o[&ަ/H1R*žG@C>7l9s &Krw4ДtD1R]W=V~rۼ5)Pnf9 ) j(cVdA"E;Px `!dwyfl]*QLvmbzW%YR\&x3d99yCM$\fz=yKDu: tZ|%j2hYR\{ GeA0 aqrKYX&*\ 8.xL !1T*4db\#ݒxvF_*~oW~ #H Ҙ,1 /P8[3]SW/i?*šaHUot|1wv ?w:<]{{I~EDI&ќS ABoBF䄷po]#NCG܃,oJO *ʱg 0nVIZņއfFhl;bD jLDz 8y$^JD\%* o A@J2=(Q(c#Tv51f\ fƩpo%5z~˵h9ͩh-Y ?i~zR_,5F|T{i i}U4 IX<~22*l狵0~5]"+@o>rbh8EEy4"t\8)sJA)-D_N&U/EIճI| ^3rљUpUL~ $t?(6SHGn5H*Cu3/z4`y,T!sQ8gDž~+I ;ԶK l$Zӆ{/Pڈ2)<'Wz"At Ee;h)ؑ>V(U%0]rpqg_}PY7`VTq8ra:p9 Cc; 0 emm_(mDXxR4Vc~gN懑usO= v-nЦ&iBׁfeJk4 hIW⊀5h$OnZwI̚R( ۺ۾}ܨqێoP3crF8-QȜw36yv6cY!$\HPxS˃78 bD{AdZsoZQɶؿn0ay9Us.CDBvuoe9 A\cW4<-m3 s-{mH${ҠFKG(γY¹YI]n_&z6[B1E9\dI,r+TKJKlC pJXڲ|gՙi;:~W0o$d˞O |jGlG} bZ*?ڨoQFĘE̓@-&NOBZtz[joyZ~)%s`/ӱ ,crQg%=8 avʀ9SvQ+*XM6=hJ`|"X|%v+`Z?VA) WRȋȘ`'[ Q.;-`hFΧtsw#mлO80pZSXR%Bj~ljKt"l\Fe™T'.`U uq!cH=2B𮑆z6!U9qBIF>'זּ6[beBA)=Ck$ͅ1O޳Zkgub5~m(6S{`XKf/O2苁QT?~sR3;,&p;SjzT.Nx>+neK^CwkɁAӘŪ숁X{hO] xsF%**%>AA`YoAPz3Q`{Mz- K4xd+.6UzNǹMy-Au<&OF&I_Lr0tnAaF8 ҲK4O:8U FT k^e_\x$ޮ_T'6K4Ls9>6# PWZZh|!~15q3Ϗo>(O}GY`܇ChؿP(t~WhYVˋ6֠6ҌǯS DC>'sdNkWH~rAkXc,HVʙL$!|CH+fBNdR&&!ůorqu(NVt|.ӳL31؈\9}9Q^'LpCQQ mz:o\sl.ߴl6#,PH9QhTU5H9rBiK-II\zV鐽K%ں. aB7JQYJ#"bbIrw+[\^@ U\*J6K_m9kwc ^[C(PaGd{!t.IxvAt,=RGOaa~O0_'x}Y756|P#2!C$.kD)XNuteEZ tp7o;Y=v'O>yzN9V:K15% }UU4i&qPVrdZ)Y DnJm*Py7Hdso; knO0W".C/%z96$诱UKCȖ^D ^VZ"yL g#:"+9kVq\?m JF<('snx^`cFrp}7CO72h8;F/!_we)Č9x(E8 H]m sW[V lacXݩ9|՝Y7 C10ufɿ7O; nG%z!7߸YJ _ڭ'%S=w bH!$&QEZNV'D=2ͺu*'"=ʭ\=\#]jPT !^., 044 #z?_!Ӑ.iCqNl"'VS1m/F-B'wfkM*ۻ՞-`VL1shkToi]`, pS1ß$C")h2*|[tKs*E'5}7~Wn_΀Yæ疺nVJK^4 -CBe(8\FWz :30DG d;A`[g^ ?f4 gHbyįBw[Rw>s֝5l ݝbO\ԦLrQ r <|ʐ9JqrYۊt޼9[`^ZŨ:p7!G2>-׌(`H?y ,ȕvBj^b1鎗Nn=dZV7w,)eyDIiOMTR n[5#qJ(I;Wpt4<";rYhqmWzu, Zj؅{{F✨X]RDaƀ+vo !纄TfDf>ɻvxNq H -<4*bn?345"D-ܙ1 bǼHaJ;9u K}W]x{0 U~Qk?+,4slM@VβgcGg\A~yܙ*?J8Lp6SS`--_AY?^ ӿ/,Soܔ٦ 872 [M["Kxy `ʚmyYWĻ*s[#y'K[7rwl#;!*1nL:* ܹ.Z FwK|D-DU+ϲAl+{F~dsid>CAgJvHХ?Wko, ,!⍓v<ѾuOA:GCi`KAIZqt[b$BѬr4{9؉(E$|.:"UM0YS62Xq;_=r:!D=y joREG7_~;?f(V2 &pl@m^tL' )0QXY °fzD_ Gr9䫪bfcpEHHsoBJ7=]CuYzbғSX`: MLؼޒvIz@* |*Nn2@՞/Uh 'jI;l{სFW%qFjr?F+u W7VtQpY6 qs5=I U?7Ml Vˏ5ɒG T@+yؑ8! 5V1Uѱq.>/VCjxpP U8n6u3%fU zAnY6+OYڠn:$A>2!Z?g!%HW@j"EV37MMt1b@|<4Jc_Gᢣe[*j?8Ŵ ,״,^Ӧ3T{-R7d1ZZ|/s %薒2_j۬6fk^ q4 A$$'JeďꦴڢE ̃y`ԅ ̇R" k]νRzH+N>OZH@ڈOֿ٢=Ne{D WK/e^# h+Ϝ]HIyPu_Hhu+&es8}S|e~bi 8b̳>R\ar<+JbS"DDK6Bk=@9K_NU7 nH{ؑ Wۀ%KE ?hҍ3>X'mw^/7z(%W2gR~*4id_ncˣoظͬWB#\gt'//6" Gg //m;/=B 46?O 5 '͋7ͦ %~FfDqqȝFD|6E?f_!UBx; I|a5ƊSJ!hȘ+kR$&oW9L(c؃wAb4bH{=pjLӦ|&r z#Qζ➝Vk[9{֚ =9npf|5١4FFKvΥ F MZ@*p Ү+ܤCcp2TZx;muA{ ~Pz3c.@#FQu/MB!P#ӛ3*Hϫes /@&^9W!V?W"C݋:ͩ e´ADi-ȇSmnkq)ҒS%L- )8-kL'yy.ք*A{,d`]ow\TL,ecYhbzfxUq ;}/7*66b"+>#|q~dlݝU'ȳ %Z;ev=(Ik0zi0K n(mp<ċݯʽ5| u+pF=n9` z=ol٠ýZ9?RR[Dqb(^eo}ISpIWc2)nM#ɣSZ?IsI}XnbvPv+u`T,涨7jSGj4(&#D,$/+x͞D_=>*,+M׆}׽٥9\"|T]QTr.5N}C/=iOǬk=SHoğaw:,XӕT"xi-Tj6O c7i: b:jgKC7uéWهհvʰ%2U{I#}T|Do@~"Mdy-Q7 {Eb_ti]XOL# KOj$?y$$g:XCa蒤4P@Q_=ŀ#jE]9Q-G$nh4T+<ͽ/ċ K/DS\#dHGSfUΞ6Kp @AE J\|BDJ设_q8`a;>ya "IrOj5V^LPBϵXR}0x<β6<d\Hr5YV6YMKJ}DD(hND`xE26_9 $pX|7uEE?"~+epv]ȡ?"s9'4v2SYXyqlE'@S k8$}]U"3gF<&^:7~x `~6K%#kyGc5UͶR7c&W+BbJPa8l5NV 7T#*Q&f9$n0!iP ]yYPťE=(2nIU4NEEw!aSMD-FJp0 Dz9mDcO2E{Jo:gPN)J/o}>KTAVk8=R{*sK&>۞}Rn)dёv.9/EZ0✀K;nP >c".k./<= K'nWP1eʏYwtL~NYz.@vbO $վ:$knSeR&OCcR6 xfA! R7i T9 C:0Y~I ahtH"-tLrcк|1&M]=y0fp#-{svN"UBy1 U Be "[QCwҲpԹO:'Kw⹋~/ᒕL5QV|/ÿSpX geXp.QuќrO SVݢeP.rBZNM,Gys3ҢsNRĥQe$<}$&8ӗ]z%~ /`>C(p_- Rpc~R?Els?w0S e(wtP~ %1/dDM834lbJ}Uz♳oۓJzYsUF$J .Xs$5;4_-L~i%q/|Yb1ќ6|>]%ؕnP)u\CIؿ=KUޥw jNwo5*:%*Y$'g䫏07rZy 6[lPRxd) @5!K i[ %K5o:MUn>fxV$ӞY!e5cɳSunބ8 SJ.c;UmjJƉu\~=X*rp<+9 !'Y{4|"PI=j^6˒QS<?6Ő4'6Zx}i6+$@(bKB;W P01#9?"JzqwWs ~&u(%XX8@ c=ag|w#Gdҵ M7Tg沆twK\^2ar3|UI(@):W'{a/9MЯ m$e^:m76 T` ̌&-RӅU.yx0UqсUB/Lq29Ep3]lsP?:;a6֖ Xߓ0m "#@\eOfJ81z:'z%w9\~_Ub©ƤAzbP#Gq`0jG#H)=p8 VMf䝚yIvݷ&P2tR VMFy#w/݆*[aI9+;_XO_u ) 4?9N,-MkRuޱio* b2”wa{&`ۤ_Jx l+pICNhVb kzc&-hM\^""Tt(ٗ?KwnYrPlf A( I[`G ~?8Al_܄>2/ CR&UdGLZ)Ԕ.QMn\?%;nB:Gͥ.[6[9G";=dg?2 o4,Ԓ* u-3ogȜH^-Oe*\]6΃hqN3Θ#G?_1ݣ3[n[UtWRKALtOƬ pyd׀x_2oE4AɑbZ^!%IrٚY@|U(hѓhtEEh@aF׸< Ƥ!'LBr'2XٹXNZhڢN;7okL~f L Ưd7sߎx[cMu2|/5ς6Gn@`+y`W&H=*ߦ6xo_-%!^sORH_]>"+P\')j n}'A:rI치}BaǠ\p8@*A Xdfdc k4] nN*\I=ilnuL:azhg lJҵ."Wc9T̺<ڪe(S~x|sy xYXr` MA.ᣬ$fZ x\U1eWJY\P;P}cIM[x󔰀Gm.㣚(vE#dMpMi)l~mѰTϹ1K:A(qK(T~0:nA8Cu{=p/RI# jP6n9i)hCfv^@nX.6! ;/r+}۩+@1VAٺ'&R6.:ieTET?K3ƒ(']g|JvfZ1Xi21a}es&؛˩V\Qvd7zF3RA{!$0,~0YaB/ }| X23툧1>0aSӿȗ&\ͅ2(qBA3/lo0ܼ;hCdԐ-M݈4vBHK嬛x69v@W"\`p/$E}ws+qnE[k\C`|CGEw+!:QVzlwVA;;'-g>ցM<6UkZ\E,D3 evb0/oO4$JgSg IږuaEwDCі;)q9w%FUNVӺZ_q"qȕmN*W*P3`FbTnm[! -ֈUBf\qXv\a*Z+ye,sf7Jb`m{Ӓ %SS+Vp}kQ)GsIzJXq_]Q?ܷ!Hˎ'u]"+aK jޣCOҿ^W2<䱈[Sm6 7 *' їKWVYqucZˠ!Cz27AAkCC7hnf?[Wb@M$\%-'Y[2=͙{i뗗O>}w[ZYߤZC{=6j B# F44q//ܠQ6&ĸ{U &dWn > lD !Wb7;gՆF4.2ZSW[I 󟙧vNkHR3쐣Dj8CarY+EFZ bmaї,ŋh(![P w~ JCU4I=EmuG[R6Z*a<jF6 $uHf(3#j%AUXc}tVrz[x¼m\4e=ZH␽EBo N :F0j_HD$n7ʙhտ_ ~0O~1ˈ{\TtudF6H]QJ7o]ўdV9<4c)0ɛx(2%kZJ>E m9;leG+TwI:JrW6pOz[2&OL$s:zq%ެrO_ qwIh^Xx9 & k#k9(-?O" #x"ͽ/[D2  Rߪ[hJ :C43b_S= _bzy]>EBbhKTO V}\<0r`3ȺM dz+yM2w/@t|_"ʁ݇)fC.9S{hC$/㨕w& =-Rl(a|q`O9ɭ'!a8 xSczތď{c;ѹb+8 {}vJ\LȞ9zX`oHɤ;'߼|G$gJ"RYl^Wj T"DH5鸎hֳ'FsVu۲I} rp-iuP4}_`BEY(!mq+4RA YjvqdS$WP ZQa ,k3Bv.>{؄+u>]u0['W&o|\P󍂹5Fr[ie|P,vvRC0 &p[{ 'l03TC@BfzܟY5ۓp1Jq)?TG}/3O-HBz)çGKMF@i5)MP?7yl: a+|>5;_ibjã_ 4{SX+FIM-7 uŭʯ#8 Mkx,l6Sa #?yQ`vsJm[.2db[aԧ'DGV\ݔIf 0Luo'uvJ#GX2}bCnK=Lx3Ƥ)bV-?lNZQ$iFqF68EK.^-W5w'iwZ_5 -2Iܲ_OcGMv]|<ԟ8t.2Y ލ|6woވɻiZUg\l7#Յ5;dWoZHMB^'9h,-_;`yÜ(\3ijzQ-ʁ|n41Â,, ^츎է^2蕥 !ԁ oIC}ؤF M~,pG2ݵ[1ft ~<<ĸVWAn_ J+hBhg= 7KTj?;Хo/:?nLyjq1&u]Ŵ~Xh .Td8N2O"+Ɓ(M쌀Ϗt!W"k.c!t39oEnvG2 -dK( =YAu*XvP=;Փ1"DqkKBu)\i6 3V%'م>QQdAr! Pl>-RQ%9A~ #VWEXnhu β8HU¼kUؼDZJG(M]7p@YeF6oa^GW2v4;AA#ܺ`\h-#:||S=pa~ q@$%F2W%Odj_RJ$y& ZKչ~Љ" @DH粭\R>f`~';8qQ _L!$!Sck; t$3+` B?&B$sN3yHt4wOAvu+ RؑSc“OܧHd*GVmh/ ȷCoҾ?g؛/sO^y.^EsܵOu৮wQ=oHu`Ȑy?7s^EqSYKyz/Xf?`![U/C L )BB{:Z)KJQx7t=U#GB<lH;hv3Y Ej,Q͎ZWf2cQ_"h.N4["]FdUzb(xQ|z3%uN̆|-1F'xuFb3Rwi$lpN2j?6̪ wkJ{sMRz'oˬXOŹ Eɹf.!S!j'w'~Qy2GWDdXl 'EHH{2{ƬXYHsVP>#a⏚} <Ԑ(onB1KO [P澳3vW*&!D\ -/:Km8<YȤT, 9S8;`l2u.RtºcArTrC[kq]37/An'$'3h;W@QiY 3\v&=QĎݿvdh;5߿GTcM=q{vX=PGIGt+FuQ5HBL֊ߡ}ujűP^6 ⸍m`(CIiepoM`>2a8G3e ƂF$Ahg:> P [ * ߢEb)r&KCHP#tY,FݣHꌎGvMH 挮 .Q@QYm"u׆R NuT ,Cj2ދ

cwp> k<qO9q2v}" '[Gֲ֪%Sb7L܁ASJKDQu1IײDu@\0t_1w襯@ƫ<n ݛX#fHٵF"~Y9bpڒ}*&!\ i6l&Q{Qc *-:) fk+"Q=^00jmq}8O [@ʓ| TyBmREU[p*,z\>ob9eAYAވszح?"j[UZ-soUެ<9X6C*mu+z]K&dFf7Mc -ZI$cj&D5sMoh Me="tLI'kuTrNFh8̋ɚ]ODJ"_ ǜS/毻f mĖ6߶O?4gbph!X^mդݸDF< -lUKE뾤Eqelv#ȋxJsO8UO]ZN^TIMX8Ajt)=*K ,D`eqDUUn4[yTAn>gBѩXZ]}QY\ߺu{8 8k b6. Ix4Uԩ4AjX&@$o2UTB#R tSR(Y<$y¬`FrXiԟ9EcahuY&N hTu}^VLX0Q3w9~qOfݰOs)K92kBhI;mxzHVO8GU.x )Z 9ԅXqG-V)y(]H ƩY]ΌZ&/F oA;˶W% B>Q"jg|2i|^]j{o,5pпr\x!oY>F;dw.FA\@-iCrJ4p$CLLr?r>T'0}\~ұEO]J ȫS\pR({ncGS.E`>>cTkVcTInDE֞ԓ:n$io^רU.{BU>yk˷]:FγWM:7M*hկ;Wǒb5lS`uГF 3K%c/ueTܱV6[BzteJ}*ee#93+IjVFU/((L"(t*,ks&SsYZb7wt0k®\J{!Rqg3-ɲ7i~beS(~+w8TA|D&CW+/dU+ٮ)TC]BV!&a*L.n}.AiyT7ޗ\BGi+7wfUez)'bxйhs$q$Q2A]yyPvA3xvL庒Z3 >~m6&SݺnsYt|\w<7tz˭"ILNFm i߫cVU/R>hGD-=>6s՚=1D>lZAfsB}Y[T}O בDjiIXaS |t I(SjOmʦff7$cS je]͜Yk>#]O!CXP!nI.!wER(Mb@ճYBMJ:uz-SdYC/|Bߒ3Wf8&/QEDŽ!]' 2` B=$PyBH=9ecAbҍޭ=K8jbi:3^bZ^E+[qQzmܥ JqVԔ^M1#Un4RL怘]j*9OX46""=Vb}?}%6M.X+7qECyN5wj\vKAxDn{~8ڇa^!6[_uJSisXpYG2!3Z~!>:<rҨY7lޢkxe4cKU^]J+,߰}1̬'\>pR7յQp;}YG>S@ %4sI-Ȕ eIV]wP|/D;3(]*]hOӱ1$HEBEF [b/Rm6G~Wڱ<,K"4Q8-cc[پ7?#nw:#v4DFOO ~Tb ҟJ Ta/tGx|-Zb~ֶ0p ɻܢl¾/lgܚ#uz)epI5pVʰ2Y⩨o U F(˚P %̄G+<sJD RR tTӋ; 82g@i2/}gńAJz.! 0v~54  xmDvGd#ڇJ~`lMtScwI:ple0  QBCc\}OZk 16X9M[]pT%D2ЃF1ޥW.Qnc+RMb_rsuxP,'L 6ٵ{X? Ӝ˗ r1&$'#XM~Fވ1n aaN4Ɓ26$yjjSZ4!.M[:4bNɢ}u& JҎϒS[{lDDJÑm-QC}^Nx0(([iJ)آWONӇ]<Д ?t6 &t?we #j 4 )EdP//,Tm9X5KM7i+ƭg_35+zb`xj\MhgSs G) U Dl U_HӶnCN~b} یf 2}5#i2I]Tq%1{I5Bl0D!GQ;}fʍ1/'f$e Pi uT{Ȥ*r+f!+)uנ%.}(e̬fqUǔIdyN]%jhlV%)E0B4oXiE9Ry$1kdm'ީ`G˖jM7 Hߙ ~'/(^b%@sMA.j4(rѭORU*UR;_[3cy?IuxbaP&}EIxjeBT.dN5a>RI_N+q~gwK[9)s#SEe#_V:ݿWާ5㋞3*m95 M3bS"rHYLz$iZUW;g]\O)>KO D2䲬n տ}iܷKNN&&|4**e#1F,7*"u2CM>G'c 3({s3iXoW p#\ GkO3 J ?, A=JEa]*X A' J·hpΩۭ?-gqV Q>IESNE.ilEg}y;K_e(w0^L*\ŝ~T,9;&As"l*}*o.P5ibz];$)ؑ qOڏlyr}.4l8)=_" V׸W)xrKoFԦ_v-1"Pw)58S*jX]VU-ܮIХ5oo6($(4s4DbR]Q6w>5-dAbQ>*HߕY dۋ иڍbeAGp6Uegfkv?ܯ.4.~0ʑ4%,RAW5<:i"5DmCjx .FfIpbד؝EX]4;d{DkA2XE,Gwbx7RGd~ ƖW[ Q{"5II7+M0zf:GؕZcY[ ^ơ2"oC,i KqT T|yUxdy; B\.Wę,wCߔ6rg/pLyZ#aϼi)/ik7YO{Vw|%|sssjDɲpt.}CylU74!^rXX2yDI͊:$ܖ&72UlV凫c *J48,j(%欀vj oc3jm jsӴY;LbYÉKgFmP>ָ?MsaQ,)fƵCMZźq^Ԃr';XuKQ ѕ 0_hC^:g۱  5#ZʃBkcx5aMlʻoQ=[6^: Ϫ酸ƨ#Hg"g n׭F "[%:1VV.U{)ТXphRw27Gc`%'6{~ I.gW*^wxQл@{u:splOa̮mP\WдJ: [uaM>fE @4.}Sشq/jO:zC"q"Krk:!ׇIpKkEi VeW0rZ~{۟ c+e3:'f[c㢂is1K*#F^{N:`yjG,T:J~wĂד_shdOf ̸fubX9'շ?5A7S>眕h &+WCYܢX!IO:ISGW=a#?n$26ZSJ#JV](-cȜX] UV~(sU tMv }7у4rSŒ@d|(e4`"r;:35ѥ%@E˰o}M&n&,FۦO[v YyR8u#sw Dħ]"B:vG}a9:~)ߞ!l+CY,M_o,`V euygbi7j| +ڭ*xϔ9PA|y.e{~7KvY'~ 7mjHe*iȮQ2Υb^JfJ$[q:#p u)ao0ΧVK4~<̤ $ɫRBWwV02wY?a%هdKEsU,x('K|?rEg E&a7%>W1Ü#JFGy]l\r-[!Ub`_t Ѻ)%p<3%dqU-Y\7wƂ}^֎E$wbɧ X-s$hJ:RY-pNΖ>뙮8MMJ)2jF#b'ǖgL΃MO[wkspqぎl 1HJO՛:al^ ECclX S6s?'IГ0h:{,V7r2}(;D s-R&g*@ΒIO|`LP Z>]ľJNwno-mh|_=uD`d MPFvb*ƷMFv]S:"4n(1DzK)Gl`uc]IS[ d@_6~j Im}yI9m)A|M"!OZ }L%T C9Uv,pbzD%hsk$8SS)ޛGe"Dɍ9wr^cOɯةocݾ'UMmcȡ.G\&əOlP?`RL~\A+%90|E8Ӹ.A`7;\Lvx{DRr d~@f)zf>ᔚk*ӈiZEl,J3޵(y[߀jEsV{QSZkӣȑtp$r>IXKe@TMV򧚬Eo84ֈ.*(y"Y^m՝a ؍2a=.ܛ|s=c,[J.d Ts|w]KSUf4)SG׃Ocq9+W#ht dS '#+?)X&Iie|DJ:PJcqQqF߰bm֘U" Q[l\&ުɻeLt`a+!rfaaVa8BziHT@WZbR+Oڷ3 . #;(S)ʀ)y((Je;@2J}ߍ-C`O=rA 7'b1UQGCu:EV8RW@E!bQ>quQ>d]0k@kƤF(+L$HL2Nc.zt+BrsZ"\lqL[/' ,gGDZL0MՀu%} !z[THr;iݪwWum=ިxx(&ɼCRKFY! ]ʞ8g\꼤$lя{Xoλ{dzj!oZC:tZvlf~Cظg V r̐vzs=H*8mmd y2̢m t10WAw֥T>FҼ #(UGGֺqݭk <Gt`B"-lS4h`Jrw.ϡ.0WhE Mˈ&\JF76blN"&]$sLŠ/?&NK,ΛΠo ZmAZ K]*-yI )7cv&N,FN5 0/ay" 7qf c[Â>\̬j5nǹ@Эګtr:peÀ鉹Jh?G$mʽk ?*&GbI}e;B# 7V BsG XDGf`i}8 {fM5l_@iód1<%uy z@DJ^ UTpw'.E *.0u֖,u{f>j7,yj'_Ri/^(Q`©-lM}*gU$ٌM\ᆲ4l\ś81Ei^>3ؽfCF%FDO ?_rQSP6C J89 fhbH `~x^щc(xNdVl-;=+7CȼB ܅>iT,0BSnj-_l^F)]|kPWuaH/U5UJV«=? :A!N`!a{_q_?9z4ZI\;j |vp#2ǫﷲ>@Z;;Od=7K_M&Y PbN5u?Z+]5uv\ TjI&tå<} n<)`S~ʾE ZU 74ӳ@+`KA>g R)2&,i0cMPn*4_ ҉ Xs[JH7N!V婾$Vx9Q(A;U.BP#<gm&>$f`#e4 ̇Yǟ 3 P$pA{TpwMV_cǐF=tQe]^g qE Di}v|;J`-4 gs6\k %ADM:b\WSFL}< gg?z V"{̢wgGB@9dd:ʯr*%"b ]{$#'Dg9bc T8mLèPNtK[Gθ.<֎ڙaːћsM`+i zM6["f5d31rUqCH=DKV t\h3&¹ 1e-fLIL5 nd! [헚 Dg9q?W爞L|L~K4/o̧-y_i^ŒBuJ6I_h7 3Y.$LmąaF7]gj-g7ER } esW:Udn3]+(#&f09kwdk@}M/?ȂWe*EeF (X(U_h"%MFc-uVUi OIj~=(kbVo4jp Q2}cNXӊ;RKwj<6I^4c'M|D'@Ktwh9{t2 eN*g6õF墜o6 "tqp-Z: VNH匮 %RFve԰[8co+dk2VRس<0V4Vdb&2a, xB@1c ,V9K@ ZchV|~ڄ6c޼* f{Ǯ)u2#و1a3Uk -M_8@|i=o9DѰOAhI k.wl20^|tgOiHߐegN]ޠAKQLxCvçM{oƋԶQ2_bݘ KS! v2+_Q{ۂED:VunOLX+?ښ ƞh#q >ND[i8Q6Qӏt,QA%U2~ŵ3˚Pȶb6v5{R>ZA6q4/ kWۧ: b Q Ii뒈ckgnv L޼uWboػ3N$mhI%PJӺRwRELKr+v9jJGvm^q`nǟ̘eLf y5L7+:$/ZXlrx3?@ۯ=!AZJwz_|"j }Z?un\]?x 5.7%*Safc9FS,86\}VnBcZn0GzkeEp#$gJ‹ Hʢi:A:@H~K7635/R**q +=D8hZ?G^[FѬie2RAGhrA|J@Ҫ-y* ug~=gJUZ]o39Bb~aw"~21Dgk\ZU R?U]0H#{Mc\X`f' B1?`9G6v-*žoӲ1+op#Yi{Ho7v=%g)T`nco% w&pcC-OE n:b_`#YAdR;qcbzliM(-ȧw׵՞3 O RX|_[Õ$r_9_M}#JŬ~0BԹjs`\Jl~5sXR>-4T dјCv\@#A1SUz1^9.r<9R:hH‘2}̢ٝQq Xխ J3q+ſo2?OyRtV38# r 9LJ Mac5PxτWk:W28& / V6ա L%AmYc7jFw, OqPޛϿgj7XkR}PRax@ Wۙ}ҕ]7҆O0=A} /`P}\312XH3GRpedwʉ-66;z)sar.R!Jf @(j.~jqXk5 C:L1:Y @ IQAJ0;9, 8|腓$]aŸO瞇e%-'9%*NEP&f :;#Z>r#nOwנ[axo$PD'Ew;gG :5q2!j}DF[G]OnXؼ{ӥ7s&-3E:~@[Dʼ0kb*=7cWYڜ js/2(PYSYˋՋb bz՝!qe`Q9qvTG˔ ׆IB!O"o#3`xNΏͲۣV:D 1nȨ1Z=aveކ<g|5qI3zј wXqjH!,[ ,p?EpΙ#ތ.6Fh@ح!@H1U]LP"pM}6dCC٘B =}Yɶco׹`=S`%mU ,BieV:9b D`fԞN9_F8v$9U$+? C;X)i̍VVLo#WI2d7]qZ!m0w\?|J0$􃏏*GҢc1np/]vRuPZR MZa5GHq90W*4N3v OIg mΈ$eql'#-kl AVJK^Mq]VhO)EI;_MOԿG1:ꏣ 9o}{22S>~<xNE̿Pk3:(/F$vrJ|*%h$ЋN!x +.!+ t-T}d[qsN&ӄ3^mpPs(;NJ,)`bRE'oߨe柟%siӿYCDTkKc[v.Ǻ'$Ŕ\+y*e$>6@ѿaeKq)nG~6x*gR4O<,[8S`_0m&Pdu 7NMo 9>^҈$QB~7v<;3e ?! O]/NqW 6Yx/B$508T eVs=1: KGu{"ǫ#d32]ǨEWQ+O>/3Ł^>PcރCh f@)hXӋVU0(z3w@YSLAE{7ѫD= N@F-sv@hb o%}ўߑVXTC#R?Er؀${gӐzbI0$k+h1<2ܯ`|O㰈 UǗ1Mڟ!-k2XO*]=]k.G!˞v65\ֿby2kUTݑkk=3Iο.D=[fn&\]>e|S5 etd[f3djVTq/n<7-7`vDsUG@kE ɕ4^M}/<8+U 7ep%gްbs?4qI3 Lǯ> _ #P4]Cr+mqgMl~F9lPa(Ʋv'k-8G'^VYj9.'Y#q= ܯcgng2/>?܅54CdrƒK1顨I>getď5^ˉ51?bksdZhC<_4Y4FE,%3pF~5 tUkX7.^/8ԬEIzߦ~Ouki>L3yD P6Ŏ z6\bfQgT>W5gLm0jH{swW%V-1Wk.L/"Ae //K#{ U0o؊4*ɍ"1Cx-mۄi+*+Ć LP]w΢CBisx:_(҂W׫7V]P󋇐 k$梈?Bx@k'ԝܹʖHg3NCn}P,h# #u(I&vXy 2q\0 {*F VN۬2x(x{E,l(PC3N)OlҖD)$Q~_$+M A EDIIeH!fk&Z.qqN~/깝#P":ٰ?ˬ3˽kl@JW3󭹂09>59vDi?GEx@TlY(*v>v>M`67[w,"ڵ'άzA3k*JVѿ ԧ^Yu9K}a0ѡ[ke(N,ctG8r}ʜօ1| ^kwO|)O6!IҋYc`$ub'MtG.MXxP~q(0q[B)X*-UԿMP.,$emu3R@z}Tn:0B+WVC}4r'Ozq =m%H.cYN,E ǵA/b@w~ A5_h$m5 `ӣe̼#Ca;ʛM¼uMϣ,LTag=` v7B+ Tߒϴ!~/PuH&[kB,Ǽ:wzn'd:A,mۼd8aVmˇ UI/ 1ij+)Z!P}2 ʡ%ב?DD Q090+//GPs)cq>d~t2n U ۵RE!`7tSpFMdI H?D(l|z m㸙\ {jc 9gԀRi63?#5# clˍ: _z]z4+ #~?~[I*h*%ZDڞA[aXLރ8R/IJJxވ[VWÄG)'p9JB.)w<-0xSjXiS vFo H c79nWKxҟ=j/zS`DSO42]kφM ?ۦWY-wwEP|\VN1k:!IKύ  9ooǽf<9y nxfݠL _ټI/̈)1-1Xns/o!VڅJ3fɍ(.D g}گ>X.cwKB#ԖDFf' ./%MLw~ܱxkUn§t؀>x&{hFCrs0 %Tvf9%=#LKlƫh g V>Wg%I /`;/b#jD+mm)z0w2EzĠGeti"04+ CjqAV~v#;Fm طĦ]9~t1HØDNᖔ$ ExT 3v:rx828/$]GR@zWȂN,u6bi%ϞQ]CWcBO8sވE%ZH/6t9KDY4E?7bJLmL8Tqv9G}F'O[Z^ Zdw#yģ޲t;ܐ8 XscЍ%yCVYz$P''#4 @7p74X\ĔhY02ϣɰ-O_@03)¢P8d@+:06}w_$MS :Kqr{ͦT.n.dݳ"# N>i̼4 H4rz՝ml=\V;Z!=9Bds( OҜUU/Y&ߒY  m;oS˙?ΒA А)G$%q2Oks#eS|SII$=" .;3 auZ_01z߷I)pM0ᗻVV:i*1{Z\ȃ?Rf Ns ]R9jӰ@DZө)W<ɪK{Z4R8 [~ CUw>~;/mGvH%G~e5LhKdTT)@vfg(~WRegzusx\Vg^;[MǘHZN&x2W_춼JوS t@y` ( Hzq_b?wϸ _^;e:NB+;H*)^B3݂9T5sSAv{DMfDw1V˚̤Ҭaq&XPoxY<,ՅB% 5\.> 4.dxE$Yn՞ku=Vu\}0>Ud Ìd*)Aƥ--&^ĖWѫMq,3!|tODH6·s6䠉f|5iSVGz3{n웊ϕzUrF/UP{ɎPo̦kPر+l3yW﯀˝'- YZ