sssd-dbus-2.4.0-9.el8 >  A `[[U]10K~f*C¾}qxW+;ZwCZ5WAH0&wXҠ^:V`{"(H& GDJkÕ7(7[T(`o0z/LˆPYI%A z?9SWúzYo+U'e< B}NVp%L+KBJ fjQ+{Œ_:EIfvDJ`6B.*tciRiVmf'*Md12d kz`}T`9W:i_ $FcV18SKO$U"D%zN9w9<1JqlaIǓ b:HOAY:'3k a5~1GzQم M3(F p[HTd#[-zeYP&(wvy `M۠\y29V;!ز?V@`.H5486f65b86aa43957c24b6743216b27dbae4fff2eff49383e382447dc6f323a9a8a9c61de66fff7f0d1fb12679caae0346b66390"ԉ`[[U]w OL26?S9u)@})9 ^6l гt|;2"Dw+0T,` f{W(xU}AhmƌZ΂Fq/ 9Mˏᆐ?k!pvݹYU!)Z"'vXȌYQ͸>7xь~ZϘ?+gFgwUp_ ôV4o]nG6 #LdsK=VC˃@\O TOn+F|nda]bkRX0R p|<+l5u=vVhۤؿtE/i ǏdH:Eu`˦3׊'WuYwZj L._iDѴBpB[`?[Pd   8 3PV^u 0  J  d    %  X   ( \|4L4 64( 8 9:a>R?R@SGS HSD ISx XSYS\S ]S ^T bUdW+eW0fW3lW5tWP uW vWwY xZ( yZ\)[[[ [LCsssd-dbus2.4.09.el8The D-Bus responder of the SSSDProvides the D-Bus responder of the SSSD, called the InfoPipe, that allows the information from the SSSD to be transmitted over the system bus.`Z̅aah11.rdu2.centos.org@CentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://pagure.io/SSSD/sssd/linuxaarch64 if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-ifp.service &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-ifp.service &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-ifp.service &>/dev/null || : fi%e%K. @A큤A큤`Z`Z\`Z\`Z`Z`Z`Z\_,`Z`Z`Z`Z`Z4601b3592d313effe1a70c44167775b06693dc9b72e7bebc718b6c9e8b094b8f1018b8062fec54f73a99b3e6621a491cfd79f1d5cf7a27860d6f3d349c32fb316c0b7fc29950beed7802f7ee1059fd3d887486c5c60a57446fd4ede68da8e7d9a2631eb70e5cdc8392c97e19924dc9aca4ddcf4b38a44ada079dbfd5f3b5c8738ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90334dae94764dd95b21b47c7ca459273856ca8a61229bfe3b2d1a792c50019af30af0c71c31974f8afd52bf398a60b933e354801f21b530d819c7f0ca553d2e7160734e0a10a2c703d3a4664724112e6f0d8d01f9cbdf802133f075e2c5d3b8cbdd440ea6e8c9134def5d161baf8d971ff175b0c58e882dc3182b964e8c641110283f60871d95950c3f9b16ae6b927028034d14f4c150bdaff676f63b2c0e97b78../../../../usr/libexec/sssd/sssd_ifprootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.4.0-9.el8.src.rpmsssd-dbussssd-dbus(aarch-64) @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libglib-2.0.so.0()(64bit)libifp_iface.so()(64bit)libini_config.so.5()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre.so.1()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd3.0.4-14.6.0-14.0-15.2-12.4.0-9.el84.14.3`T@`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.4.0-9Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1899712 - [sssd] RHEL 8.4 Tier 0 Localization- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh cadesvuk2.4.0-9.el82.4.0-9.el8 org.freedesktop.sssd.infopipe.conf.build-id82978bb933f70b0cfd0f04a0d1eab2be50e236sssd-ifp.servicesssd_ifporg.freedesktop.sssd.infopipe.servicesssd-dbusCOPYINGsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gz/etc/dbus-1/system.d//usr/lib//usr/lib/.build-id/76//usr/lib/systemd/system//usr/libexec/sssd//usr/share/dbus-1/system-services//usr/share/licenses//usr/share/licenses/sssd-dbus//usr/share/man/ca/man5//usr/share/man/de/man5//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnuXML 1.0 document, ASCII textdirectoryASCII textELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=7682978bb933f70b0cfd0f04a0d1eab2be50e236, strippedtroff or preprocessor input, UTF-8 Unicode text (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix))R(R$R RRRRR*RR&RRRR"RRRRR'RRRRR RRRRR R#RR R!R R)R%R RRRR.utf-8f7b22398eea67779eb253ce78f63fac8d155ea78cec6301ccef87a727da199a1?7zXZ !#,߈] b2u Q{LPٗ 98Kt rɛrk #PbB"KhEOYAy3:pU$?|ut=op'R}azH 8vCy @ (A\xԓ T],`Oh?N-+&\p١"V5Z:)cME\\y64+r,kFH+s]ťӇ58 VTW x-[|  3IcYɣ^Zr`YMm mjm lQxGY+=`ylPa9Taً+kdA Ǡ-f#`_رʵ >G1JrThuhD%ϗfr@]^/7i&ƞoU|J\kȹk%-0 Ǜ7My+47jl'VȼX|3j)wqdC*!gg?(`J8cmov˺MCT85a:L= X;^!wތ8*A[F*xUFjlԛ"D^8tHd[wa_~˩n0Լ P?'52eb64Ĺf!T/rz _ʱ:n.;l>W_D=fzݻ; @8MA~/obUP+l<llghz~>lSs7 7B+!4G)_S(oJuNi7IQI%ﭹoOMr᝝-D[K6ZH Wncu/ 0aBE 4Lԧ߃ ChFdiur6Ngf s1y:2 S$6_%׀f-6 z KP{]w[Z! Іz?0LyʉfPSCBFW'Vշ*JzrHLo)}~`9*06,OW6&7-mę:wڰvG/ݾ#E0k3,Dͼ;~ =7]J>i8k!M ;6?Nm> mxo~? }r4|'jim{9I  r-0$aotKW@^5@#u|VTW(gԭ,s.)Mb@lTg@uT.Ȅ$mm >;W:>P`]S{@+<ȈC>sI)f7O#C.蓆 #v~4%EQ=-P m߼"P|i$%&\QY+摓gz}ӡ `zیqsF|*: uJګ̨9%!lƪkM$!w}g%DD;7eҒAT-Z"n2oz]һosP kYndFt]m0E&-C"(X܎檍?ofzxX;a mDM*p8A[t瑂@{&yBSC>nqҍl ҐERFGs0h( \}0'qr@ǧ-q/cvض~GxQ 6bnU f9a-= xH{Q(hl¸9M ' 2I'g3S?W#Ho5>Oi,>4>!/ /XE% ȎXDŽC+6 RB6sch_^Ϣ1=9:X=}̏5ۃA!rRmn&lɿXJrrNwRcVEƾE Kp#X $oJ,~kG=#*"j{qnAv|J禀:cxtk xwcRSȼ$q̣(z}+Zmֹ.Q+b:GT:r e[ aGԁ`7]o`H3''SVv,F? ȷn28gZ95_g+=LK? %BJO{T~,Z66LH;ES$P S"\G3iy5cEMBgWWm ?XJǵhP~k@&>'lᰖϵU g#yFNi"C|RDr7ن(j\Mc ( $x"+XN|GC8+諍_hEdwtg^&MJXVZw"x'*p* 6 (Z ֧X#S'v9UWxypB؛NhiI_{oăGl2Y{XjcJCtɳC٥k2܇'Q@ڍ>6 :{:h5 @@#F%]*'[Tnz4L? q1J8ePژyKc' ΌS0'![8KIф [_G555֒<ںg;jebBFvN9ČE\5PIcQ&$=I{?R(o~O?Y t? V~@!Cxla{5z ewL8NN>TQ SQfbUy}U֏Z1+EDrVHn('gq輻khBٮv9cU\0T+[1(*bhWc%HCr/ٲphYW`Ep5⑼)(2 -i hmnw#>DyCW:w0b0zCʝ =sxZG4Z): Y9@Jfɸ1kn+xK? jLC&EX"8aZKE@PhEto}SFM-ڡ'}թ%.6@tyì#O3}ynsg„'0 mZ{L6X\ց1>nɱI[d I;AX5 $h{u߫ar`̃>^MΊĊm <ji65vKqP38G=sQH nTbk̓OPsxe_ɭ9Iڵws\La &"tjI@oBF[p]!d7C"6>45V1dqb15i W}l Ri/swjYlu&$VoFgn.\D0TfdlL=\~zĉ9f5G.ʘDgܥM+w_:7kT:D5q:^֪x9>z/wB'bϿ̿)1$rEe;|,Lt5>0ُ= lzG_USo"oͰ2ڞF;sUuOld˒(MɢK"/$r}g]-/s,SG>FU0{יvrZ9@i^dX 8!Dg)gQ QryRH0dIטCkg_8 (A$>τHWXi,{B <&*U: 8ŒzI(0n) R,[9k ^%8R+q^vQ3aȚm}}2oz:Jg#MxVoMdmVVd:Ι>Jܶa(&m 1~ ]~ {Z(9K9i*A"Km 2hY񳝯j. =~X"aĘT?[I>9.GM1a#Ml4ͥ~ʝ@.ͺlrJ&c; m9DQ$j(F(KQ} z ?:w@nn i]6?h,^7 ohmJd5-iy(b١1@b{=Pj\9385WQ^oסo5$CMڍ]н yoWrRe_/q;;~QS~k*5 ZɞCae~69Rr=\җ 198.' X~ r-0'9ӂP+-?{Q5f[^z06^aH2&C{1WL #IAa ph*M b MgixLT!i[jgT)Uf|h|!6Osԗ2{M[#b?Cỡ}rWbA*Z-O”49t|7HУϸW)HkL#tTn\uV t-.ܦwtbqu OD߃h{)KK.~Qk'<@mbT!id/Rƨ6gl+7&znzHعTHMRwUR#?O fa*L0N*gSͼFYs7o{40}ݸasP.[͆y :#-|q4bM+;ۂz+e#d #ie,z @~PC.@E+Nޟ.N)~nH!ek7ݗʝ^Kij oqQSx>R *cǚy'|ɨ-9M&Gқɉ4@^}OL»#їy>)qXԴ/R|Jp|îh-f;Q14P n.t@b+!T҆gc[ 7=RrI?'g[Z ɈFRUkU![[3CkI4 +?$Y҄Ij<BO/HAj2܊+!'cF)Nk&rPR#]?cwBg.!{GMs9,xe Ta1m3= Z;kBwbJ,}3tۍN0MMZ)BAI!g$fX0\>nLQlOwKg {2+*# zCOvC\ԣTůn8dft02ˀ=Wz1wpP[=JO㙐[гNO]16b"/DI3l EHk楾-1y)ajT0`DLv@vT)u8ޖCYlAI a%jVn~$2Z C dܴ <6V^=CSMe>(}'] ڊ:oӹDH"N\J Qb#(k: iAUwCR0>GȐTh}Ir/qrZW@D((F9wL8~%xFE3iqу3-蟁tsDoѦ^opg"@c, @c"yVIⷨ Y)Ƌ1Ӿɗw#c\n dI-9VS/Wh;HG*[\{ZN̹aV br~OqZ!gMapem]038ܓz}lt! m]>њW&z=:Spn6xX2OHjn@DJyUmP.Bj8.t耆/\s ͪ?MPeCL)5 yBE9޼]CZ*AܦmjS'3}_Mm-# n>8K ) k-'Ułt@pA& Mx8(6״TVO zow3z81Z0 B<1#~Z̭vQ~"N-91/ǘ9*qw{-[%3k!=]:Q$I|"3+2yyeZu6w)v&ƴUB\:.E3Sy2M%WF;.aR h^)RF9aC'\<$n@h҂ vJ |"$myxx&8{xH' }ӪAl˰"Eir1 =QS"B-P{ʛڪQ.uWnݘ<6ڸl1¹_ORRpF[Iy]|[× -S#Euޑ\caH֦5اB(UN-PTK`o%@2ɧzdPZ)@+^Z!>b2&!Xo/>7*V$Jxr%muDrp<<9XViSSeY4)tm[ ~o'L_yd}pF.t۳k!3J{yjU5dF3%umkGN3\:\?)xkM!bf]ջNӽԨmZn_.=4(WEynw dᝣapV0}]**G,Mi!K>ЖbٿUA *?񚆹$t]Mަ]:BA]޲iZeE+s,2A% :uΙ$b{0p x!_ Öu:PI+30BzIQve版}%m 0%PjaNFv* ޛI!oJ9TEX6bECшD\q\គ_OJ -p弹cAS6%oeB<O$w]t4/Kn{AVG_SG"MHbi('tQk,Gz!nu+O;Ը7 O"CNbSWyr:D@3ZB*zH+9A]{Z}I7gS$yw@ýSVti1!.ǒ,xC*hJ Ү'ڶibCwh*# y BQ>ܒ΄ec,c.=u"c[d d>DvL_Vɘ?3<ԋYA34^3y8?r7g!7I?-B?"++z?^Ql?ο]Q辆divw~k.X\T>)8'XL_*̑iڢBB5L9*)H[L垒)4IVkG"RXTa۪]VEnӚ }u Q:I²kdmE-&T>FgB#Q/@iv]';ꊦ,K97ƒ![Vف8E cHv,TWtc_^3A6M!LPlRI#;%2?#ZM<7` `7Eǟ%͌Jꖅ,n :C}7sp5XH X3;J`/ 1Kь*Pr?s(iQ T+[8Z*@nx,Ė=@c"Ihy*9noF ]6[.%^=_OhV͌F'5jVg.?P؜P_]`Si:^\޽dPH_:Dp#¯ 㨦jhΠfh wl;b2lvwc^=6Zd:j@,ॏ`xę H~e ,=CKJ ]{Zkwok\Z?jI 9H^ B׶# 6w aWmr}<$1 dUQυbrS)t o%:x[/p2{C$M^W0çmR] 6sn bS!-t(Շs[{;pECg=o#pR< t]+<;Fu&L۵A’ߨb#L:q4W[Fc6@TЂ+j+ wJSJu=VZk2YqNphnRU(|_׷'&'p덎§~k'LߗC 9%D?Ukd-(ha޷r}am\8BlmP 7'tT'+;>=(ub6p8)=>QajTVd]s'ߚkUWZ^YPzQ+yH']DARSo:6Pw׼^1t%Ϛ6kǛ!|iu؈dCe^AvzBy/dȉi|Vs2?2& Z.et{WMxvU0*Y Oŧ/L"~=@ϱKϢ$nwuȄTkAaO(>R~q-МD>XC @O JlRR"ó:Q3d u:Ds?͎^Ȉ= EUߛrny.0v-u p`k`2I/#TL^7i7 jc vDm RNڙXU Rږkc0OF/Oʃvm +;BBu/1sZ<ha}+ . ^R xR#v({ɓlL*~-(jѓUo5:8=)KN;Z˒> v 1ID]A`j_Qc HғZZJ;f4$dd6AbWF*^~ٻ%4O4n{/45τSLi? Rî~z;`.e7^2"e1e6dxY L)S*l?wKW4mtPV1q {#YP3)DM)pS % G%S!aѳJ4-a쨐x4 vlG=;$1 ԜVGMjɸ"#f5{ר6}[p~ʇWa'\"b[fʀU?*XdxM_wiMل@Øp4~%SwCZ 氣 AimU-IQ [kW|]b/ ѩ,04f"8rrJc( 'CX []\BTo$jpk: hK'Xチ3RVK3&ޔZPLJsg@~qtsS䐷91ӚsVhs/Xu`v>q@\PCvQ_6]\QYϽa?EP|DS2Y|Cb$KO _U3[NtB€Ʒ^W_5m$ъa:sirV /rX`8sI7AWUmZ˙ ,7-`_2X]4KO@<3<ر8{;@IE#kOAS㴔VQ{/YT(J" }Y;v_v%9"mMN@-D9dZI?c7[ Nk>u]n,BN!mBJzovnUj04kh:_ʸje|ǬsI$D 0ZKdG]'PZtNgyCrcr)1&qpK;Ϊx`{3g 4yd*.7SlҾiq!}a=#C:Wo{+̟w +*}rĽ xornɶ6ݧj3K%vK5\Q4=F\K#&̆7UI/L8 tN¯˪zE!E!7=p@Tht'j4!qRU%V`Rҵ[CWĔfrnMmjE\pxbԤpոcii#ΔOi~ʽ!DKWtoIН5zyi;2 uVV{鳺Da&icx|~:Uox檧gݍB||lt^`6^kEʩAItkNw>D`Q\A:[+m[W] =p5 GL =3E`U,'>k#!I<$ß`%"<𶽼z(S|3J)~XhL᩠)UNCKj5ߢTHsnDuؾ+c>q.Ƨ>ԩ㝵f>0JP8fmJElaTe/+'lU!'غ-@絝L#7iK=?`AcEH ^-!n0H%@\wU`Me$ySn҆ YIy^2C5j%u,:$W]75I:( (AX^IXvH,&,ti{߭ba0RS_ u+n'"4?h컛ah~mOMl~Ml"1Ne,m:WUa<Mv9e%Sx­ HqtoEz"5-@Ω<hD ;*-|TJdqC z+i4> 20:_Ѡ5#I~:\h$4l (A4v:?Le.xY(*;;'Qɜ9di HGe'rpg4WjG[_:OK(6PSY4!Ρ=r5!Xs,&K7hGlyRfL;˖yҊ%@wxt #̃ch )ml+je-"`3]Z?+rpd)l¢8Q6o#&C{%TYSStou5{׆6bǎ2fL 0` ));|prkոニ(F> ͥ5f̾}B\eziE  >m6(Ǖ-9"}xw{U;*y;OJ}/dҼ@ ㋝ 7]\m^[Ys`s?&SEzTe˘쉈V% =΋ˡ$ҭE>9LO{.Nj_Ư'ɱ(Ot  ֍\"b-u7Sj{d2 u[3s\^cS1i bWre֚ś?T - _õ$)yn\psFaNJV,W ˿:kj>U_SO1e^%eK^73VjjM;)4r!oeFq% V{]]כė\6I|ߛlb4jorϓa3F)ue|7"<6䯞p\dzN>`&^5Y|n2w >7ani9e5%1ECTIbҴLg=@Wet|Idy,֓@>[(PuDNM׭[ʆVӼBXO=YPnmGFLvFp}'7Oy1lPiFboC/̆2}TOx0 :NAy&J!y.o,[k2šO{- rpOXmO2$T$MAE.v vMsAkO|o;e`vZ~$ۏ1ˡo윦E@$] Jd@t X!s%ӥJ\g>*'WA3w T]YndOaJ>uŞ[H%P 3& Qf3c)O䉺Ƅy, sjj@)n5a76RjWp!O.)sҭXʃ.0<.ȝDw1\B8ZQ+^wIiKE^>kd"V d@5ܴ3ȆbܯUj>=1 !!-ke 7|p%n`tpM %+0*.iC..R=$P*;K<¨GCkq:5 eZ>ݍbuC#u3u6u5[ 7 tz6YR &J;KiI XQ_>󎯭:.gZEfT0.ư`O8DdQ0E K2qnt&re-}1~.6b `"2p"6B#bmҲ:rT7)_ܲ`l&VNpWTpU˄wěFSH\>{cЌ3iN^mFR*6}6-rcnvWR~, ?W09?-Gƛ'  T J0gwJCL"rPaVH/wd0!o\~"bUnS7_I:=6I.)Cْ2HYpix)>18唽y`rqIÆWgfA v;ؠp[X !/w9v(4'x4hza86>D?朕^#\FOKHO_E#i_΁Po[bWӴ~YTK ͔ikǖnZ.i]K eeTZ+HgWHBVx&6u(s3}xڴ7;-'):vlԹEJ~VVO84e;HT3 k*`D^SrIX.Ԇa$e/{*C , ,n;\k) 3Y+a5jK$FPK0A׌pu?+. j KcĖz>tڀH!!oo? ̟;~Ue"uq#yri!bb%fvsCY 8J]=@g:LuvWPahCM9sM|B'70(6Su!+y"Jb6)0L%lԬ 'hGDxsC@!),97j_,Րԍ=:z(Bt'O1r7Z᪑2ޓ?vupT@ !M@_]fRn%uq dvD5ǥðigrT& Qzna:(Шꄞ2fI~= FCJlx (XAe5 xXU7Czi JS"Lr>ĤK{8S]e<w";{pH#; ?A"}GCi̵ۗ)YM7LU,r6ͷCA-}A~SRf`Vp Iuv]!ToD>OL/y|e \܋Pֶ[îN13 I 84eQBc?ֳDacz H$2_i=W ɻ <\q{]JX ׵ưlPy(*cr˷鿸cpAoJHdnG0, bbV]E} ~j՚ *@%X S{c0ZE&n?{ ZC>Qy[*,q3E4-l_9P0oTB뱥 Q[ku!(s|l} $Qd?Fn}yaw_BX⽸N ~P]gqlƳ0GsX XG^0Z 4alDX .LojT_CE0iBh䙵 VwRj n*AbYg_ǩaޮT֝."-S9\SˤYԮNy2C㬂\ڶ9E,4ݦ_-6Np^/{ '~[dBbZpG Ns켧$Y/}UZ;UnԌb)*vpz.#Rη}"3K 8Vlnzo~Swhb0˨i>hJ;i}R4lc˳K2 &JY N%Bҡt6'}I`Btߩ]fvdy X]CЉb8~*xՌd Aסxr~Sξj+f<%+J.R}Gt+&Z ddQ$t?L J5)|wt6UʰRXBhkP=F/&ʛ85!)u"t4pv>,E]xWX|˰~ (mHWqm?KFʘ&d$P%1)3Jr5!-ZNn*Y<! ]w{A5 )~NHYm#Xb溗ṢFmZ?kuf`D/r+UR|>q!N9. 07ﻲ~|HTE跏X  T^p W̆v3P2Wp+o񨶪L4i J,#$ULtԞTUe=]+<؉boHbҳlQiG|V'Yٰ 'AlhY$(4Z'*\e-0Q ꎂjˠfk$wFG:THUg8<i(霅ɂzcSAp!KsB '];dRhm$If<`g{V"H#=HW\PIʽ}>7mI,PkI!N9mG.{pf/w/|{o?KDR;j]3QGf &ykÆ)GO T]Vaq<r73J}Pz0.cPlZs2^@SHW_3cmkw4 tm4ڟ]#:^ sK>!BXI0XU +O\P2Q+?jEQMK{R"j]^/awȽ^kfwծ4Pql W@{^'pXFl1QD.n;z2jh"¬+j{!BbiqP؏ӄҜDWRUs-)"WF횈((3[NQJO7 0jH_p :9 l.PM.W%9_չ^d;n+qK9+[E\xm@N-wEF(s71).5'hnlI0ku9Ə;vÛ*n vqwsu=ܵ'8QEqP8nnnt; 2!2/X#NڮHr%IX;,76]LKI-'t)4qO1@5*!z-~GW+5AoqcD74"C`L&-s 2yں.l&*#zoEoR}lT |yDłqHs#;CTGr-ܡ?nikY3 AMQezs#*PoLw u {t >zLE*lӥ>K1`XUT{p͙#xش _p=+%x\bP\/E q K3u5(򭵿BEwidk hс84wg;K04ej."&ݲ"q䤯CIai5atwSTn=8<{N rx;d>2)&Y\ yyH[ѯ+OFx~)0D*:u=fzb=rQ.Fx5]g212o<3E`d梅WP}_S%j"ov_.) f)"}N0~؂%e46lw)wɪ!sh(̖:%yQEl;۝1bpDr&EI( )vgU=L@sj'#v~;y,^u.YAzՆR.;' 9-r}kfe=l5L(L<.> ͐0ј\FRO}8huMaxϑL]T`m A?v\R#b.NC #Ld XSl-7cJ)'! US^srDqGW%Z>CqSMI:4% gMvi1 fRXgi [CNHZ&r*^ /bӸC^_b|2јMxw"o2owGc X7I`lM^zO 2-ҽ5 [ ZX5!i|`~j ELYv[TҐ!dd:00麇,+?;~C"=+ח!a{T1g8tL^{F+ &0E6 *k#xN4o|.TƠr lFq+~ѯ)̚eΫؠBq;'NJM g)k:uC{[Ic^D3:,9ӓ3̩8 뫁X -yV5K}yM.# |BziM5 cz<h{HbJoӞn.˶E b )aЀ$usԄuo1yK[;f֙,^|ZG2ٚp.ADh7 E~&F٠X2d9nkW"BY"L=5OaKؗSX=0⥀~vHηY/ &`b_Tf"0k~E$<0"[ 3N=G3$Vf?# b @i?cǟ . vċr`X2dgW"ϭ'w01w0- ' i~<~{HpN k`~at\*7M"fmb EWlj!";k*%FlH.ɮ}*}mcأ?ֶ2{/O!!{qI q KgP1Hyp߲L(yv-=q}y{Լ-E`\dizzy9jQ% afOC'7 "wgkR8K"Ì异ZM 0 Iu;4q^Qgj #]ᅟ&\#ܬC=j&U8L4S6*2\iߏ$.>?~ۦX*hA =ZQׁgJr>OK_ZU!(\F*㠍;O;fc]Zi.HԵ*ޭpBp%jz_5K0I{ͩzb"˦ѩ|&"@ m '6Y5PvXȏjv:g,bӦ'3-@>JsG5Ⱥ_}a^+~(eF~S:%ikTD/zU{81fZQb{KECAlmOۼ geŢ%H,G.3Myp a\iʖ0m!#%by?өR\I/AAni~tWٯ)+ҍSaRSp  ,$+nlhp=Uzв1e%2, ᮭU1r$wN2zP$3??nZ;hk GO; ]Q #"|Vjp/Z0@|fJ`#dIok _%ul%%{BaXmC?şMħlC)J]ό-gR-*I{)䢤Ć0D+5K8ORӸW8ԧA@B&)v:ΙG"3AԸm r%4 TSoL/*%WǴ*@cYYkfCOP)|W3a E̘%M)P{ ?K:/xʗO0Wŗ@ZO94CgW@ ԃC2'~P_^Ƣ 3V_σkV'Z:3/H39+xҚUc:X!q#H@Pw/lqG{ķ#[~:}U+e=HDj=p=bft %DV:hh3#(yK,`c[Naj@‘uR |vxSv+We@33E~͟vJ jhtu5P9(̻@BNN%4L-hx _@G0J%Do x#E})Lgq ;op|V鮵,>* xoBd<;vQw^50ސeUʟ!9;VC#|HL O ~ƺ0<rpן|=??Q8r2B{Yw;TM*Vks51dJrFs3=6Y274'5Le;6&WiJnwAxfPӷI ]* SnE#j=ZZ aeZ=e]@uKq.SDRp:Lx~< ѯIE\zbʎO1wʙܣP;xH6eǍEqZVUe"OrD:-SD`OMzcu$.bMMgB/_W7C':@}P%6<1lNRZN3AJ{.ɀ0!m0Ln/̺1φ=p!q@=l0m"`-^{DvP*i4OE*=#o1/=f?J;tzyPRs>dv5`Qf}ucuy_.0(䜬'=iy0U[^k8PG(#<9_$\1y'igI@wI b|],NbLzUÜʔ][ӳuʰ_CDu u_yRK/V+iZ%|wQ6v8pӖx #CJlg[{2N~ M Lw?&ϑ33TlҊ5/9"]U?P{J)4cE2ɾs19{E9_9Ü2$#0@mJ﷭Qioh]0hgL+OV'nofؼSJI?WR*A N["9J}s8 x3,U }D2vq[B! N23ľbX|s&9ɫRHɁ.:$4s\aZڔ&/lmTDίYa;QF A{8 v鷪\ T@tX孹H2{;}ĝlmJxث~Ki<2c"P'C&m\sX`"R=gPEUbZA-~Q梐]<#;<+[$jTlc"s-lP0E>@cvVI8JQcڡmqn?#Z5i̋A]wDtrNi9%1HK{4 KߖV/@o Nc{vʰ΂"ESaT݁XtYʔu̜|@kC=QI|MAl5xlkE[9qJJٍʚ 07vȝ TUg.sk;S~j.+ppZxz`C76]RI}b@U[/ys}pBiq8wp1,Bw4y';0'#ʚ pI [K`F1CٮjҊfe5ꡱ fERwtE㬪y޷/b)񟿓٩_{H>$;CزF y8JgGQf J6R6Tg[A}LSmC_ٍ߯x`qIxDu4r7Tv\g^9olifnnw-tI8Q_*3 Үw͕*fYKy=~n\m1I,4}l \\ ]8\l]}ܭC1J$=9R[мY?zgZH)ޞΜw_Ѳ!dP&ɱPR6%OoJ{*<M'~U`ׯ̚aRdafd@ jEa'i:#r)ڛQǀ G+FzRgMO_L*;fH÷))av`=+ޢ9c@im N{ǔꉦ7=/1Qj1+IÃ[6JSf"4HF쓓9T+E* ?Y CzG٣-֏ X'A:5^ uE$J '¿?~3Ms5̒_Nn%-YlPx}FkU價[юO`=ÏvF1ôg_ݾmh:. V# -V0v⦌_׹n0'Czʹͱ-߶F3g #DP1/t, KQ&r#No>{R>SMeJG\r)  @!|5UZ)oFg_:WNuCU+[D?&8vt'|JU%Lt?P0ElsrPJ3᠒aVVq9t #2`#q^ Q_i˗If['P;hKTVLZCIdaP+4Ѹ5{,{r=ֽ y^P;͔0?Y} YuG>Meax\F\Nyߝ{Nz3{[~H.Zn쭌X(膂2u;o`H{Y"D]<MyA<&6:RmfMVD+zNJ/Ro#@;AdbMͤ|2u[ܓW%x%`?j.Q&Q95|XV 1p47 :H&D\ &+%b*?b/XP#. \%>GުAq?#\ t?g:jʁQ<}A: r3>Uv5ȁnէ´*ڴ9l3Nǽ3B'5g܎"s?Rg$TLc)lS&Kr9E6cwQ4dMj0DzBzڰfQ UPi'0=<^I\&=SlAzԺ#LLy6Qmn* BIoNz {䗋qc{js@w[1.c"OpQ#ޡH=d*M+VSW u D즬=/R> ^$][i>b ̇ tGsv5? NlkhT+|zotkt~)߾q7,f"*sJ :΋Q2¦8sRӇ1Ek 'Ջt%[# za:mOݗ%\R}\MÍ(,qؔJ>Z\鈆EE^_(VM=GD"H38v FIo$|-qc_uh)ERlg.&}Dh?僘npb4$5+G/_-UASD)m ݺLp}GTj׾#V&ӎw3֓ZId >U1λf[j HB`w)~JP#)ɿ39 f#8EVodѢ#:4 E `dww 3jU a$Xg;/R50^F g-o fhE}Tj<(P TIJ=Oc ED.ސ&4EEq B#{29 %$~}NFYJicC/EMdMKozhƪ yѫ}9ݾ!=Olo |@fmadG}fT[O޺RǞ/]:f1,4mG:_/AHTտ'U:5$l0?]&9灰k7A' 8P*+3eZɲ;"vjSh4KJfys٪v;NLU _ZsE|\ / fɰRc\Z!ly- TCCa0bUIV?08PdYg0 'n},2MV(R6M61X9hħUs AoKMhǤr1lA^5Yc}~ miAytM\-'}H@\S~Бj(6&{ ]>jrhtV]dSI$3DŽJҽNW6QusYҀU(OйPҟ"UaVD}{2Ab]mώRMQs [zv-83.!I#,ja?04Xl8ų v,_Cgy1A`@$=K`: 4^ OAќTob͖ EݔigM͜=4 St2CYqdGAMPRj з.=(c-,Q5n.H$m[w&wPjV`Gfi(?[2KD}MP4BxL {aɮ$輦=zVmٰai#%E\z#1Jy!b@7-X\mSsGrUVK\"Jڜy]6YMKGxK؛xZLCJ_: pi>D4E1y찤n'(Pg>h5=+PÐqC&8e#?'r]b1"):-nk%#n*̘>p"\#_vz?6^>x!iskbίu5  lr?(Ueiw++n:pJgu6S,Mg= )9mhs,gRЅXH ܝXw/l~$P_g)} ͞JNFtvշ"50i-YXDg*+ҽsoAsH yO$<^抱R) n31f b={'2CQs)> a)8$*51 Rhg8.#gx'>rZR$ Rd<DW廧G%/)6TW!aoi"%*6!\R|a^@L\g4%$C#ZzWyeFM$osBE\0cIԼq7_LIe C"&G-@8"r(" w!Uݘ ꔞA`H LKN* k㘢:nqyO'M#g$¨O[|+<īh4AƝ:֬}駔hĨjdY#H`:J q1>2,K!|*&c9Z}Y=k߳jPs;Smvƶ(ùs!xӅ"ULPSn:A+nZl \chоC $$L W"W5Qs*1H>pPݸ"GRw\8V]pFK$_4YsC(8_U 'I.sG Xb@u, [ EH!diξ4tfgDuiaqaQrs26[(tRuROaM^(g:eE~fSq\2baw6k3ώ'Fwj4\ƟVklqΣCNoa͆uFbd{p32z e v  : :ҲѐM{t)4ؙz4 z8)NAŇ1GR:X7l0eLTJ<ۇezYax<0BDc`#3EOfmW' ]nCIQuc RR@dtҔN gP+LeȰp &E`X&Ӵ`h0pDzXkT3鞋J- e#{V =Ool]F5²{1rxlxe|B5 >:\?qJ_HKժ3|,\ =tA.Z(48ehN} Ϥ^|m+$Vjx/IR903979|;+g]G}59M .B!"`O`N,3w:Z"鰐[I9mdN#B۩BfZnx ?5#:%?:W>Ħu#Ql$0؉D1&B߰n`Ro/Tu%Eww'k3y lմ]Џ`0o[N?N/s i)|@@sT;{!&Xۛ,^zL˅Kj jEpRAyuXYXCzB+ojM0DJ_/>@ ǟK\Y-,`E,XEHiiێs7n5i$t7n8= ޔUrte<,c;ڈ|\j>ky7l'mʀt[1os ,3W-xi4p*9EcBm ^ʆ%yx<naywXBq%R;-c"62h엋p>H+B]ڧa`?J<&XH>DD7Lҩ~3Zuȳ8bWnEK<\ghj KR*[k3; ޻1k?/>%IUpt Q4}` Q1,|GJg hhi*pǙ-C`ϓ ]E70{8Z4*H2u~ɉC+mϜ! =$A:< M~T15FS rДPH~%_vrO)ɍ'*qq9ߌQ+ʹiL @(ԙ4`4sx|n 2-'WW=/nj3bz#Y%t(3t`a{@0x<?Պ@k2xf-O/,[LàϦ^+XK/t\+5+B|5??NT 1a I/r,(2( o(ʼnap NolTjF,"A) =3yaڛAEP{7nDOw1t_Jp YM0dt:'MBNQKy73jeV1:BBnkŎ.Ev}#|{ϛZK ^ilaD_ne) FnϺeAې(\5Dio;=I}\0 Ea5bIAB620E'aU9[!eӴoAsNM&LHn5O/@G-7չ_ BBa+;'kI͡&t~݃uofj^7Mza)RK|kvEQ1CN*NY\k,R2|SS2 Y!E6ɮ HRwtƂoּ *Zsf'PG o3C% /,Q& ;%/xF=xTDs6uq~ѯPt9-# $ԙkUN/ A1<#5KAg6ox >fŽ:խ1y7գe܀my0$JR0<00 *ke{Xns9E80TTyNcۡ#Ѣ 3c4DѰ \=oB\ڸsᴔ<Ӊ*{Bj r{~Nj @Vy1a卋VM/+zM(NP?uXu&bϖbtJ0EtJ}GqT_C W9̗)ճ,%&c; *mh5!Y_`= z`tz,IzQ(G(ooYa_oɿ <ΉIÓ1=~o㒜#Xxy[` ô\v8?f OvJeдv w88_MІOG@kYv߱{ʭr^|Nwwm%z25/!tA_gG*LG^kQc[a7b4X6tT閺B93{ 1^,G k~0h3 `^muy@,3*Jh?<'-%dwCSc~$[ z\ϭX,d8B?էos]i?6,vvo?Jl4(B.$MMmaV\,0vy=,YD#T6B[&_8[hRpj>`oow, \ 7aM:ܮ<)Bj /d/QvHJ¨͑p:x9D u#\@fxXuPX2h8&Cy@tc7/ijh%sWESG\あ(s9B*p*;'ix,7C;U)c L#>eo2v2tfP/Jd]C;ҩ YV(z-P:ʥ ) Ͼ/maŁ ݓ;\8p P] /8bE aFfZW="x'$N} FomC;;`KF߼H[zp +ROv=JnRFG{̊ N(We06kVgH)AK8.UIr ̉5X2Wa70"󄀴һvۊe~6Hd uľN+xDP $S&Rd1=> >n#4Q?\tZ t$-%R-]οNJK5;y.?jcoj?`YP"Yfut4ӆF˵Сw/rBY4M`~P]QPqRI!;qܲ80B-.:|U]:];Z&|[}pO,90؆˽hvFɯP/ }ڳH`C㡺k2O%]>{-+P]$@V՗W+)Dt`lY5lpeviԎbztR?X7/ړҒ_O@~o~ vw܏4P>ro`T,bK#woh;AY¸%FƇ;QUr4&kVΝP$8jI\US㘘tJ䲋hvwQlK5HFSd:vJUajmv9Wֈ̜+F4#|._0ް] -^cFpTy+?s`QbJXΆ>-<)RA)]F"#@9WÃf(5bS-ь1y|z8ʋ5M{꽕1ȑ4pv3wG[e%W$li6+ X:4 Iro!Iwk|'3f~4v= C X{N$_63QUG T(N30]/VU6z\.9~'SIP!&y7S\-k'O aʘO|Eg֧؝ /0 l {MґUz1bdR.o^a1$vەMg $2.J#S2:wګ$]ut0k$g+Alz%z B`#_"i!#DI;T?șN!9<-o7z1 zuoxʟ"6z o*;,#x*G5U_GUU{ӈ*>,1X2wsead?AdjP,ݏ#=~qR`o[w 7Es%z=\8q3>Nrd>qdъ s? ux&E{@4_:2|=imu[O(C{h6>%^-1f9&[MA"]\$at{m1;/=d/:aļYh8Ϛ&W_>hxtF:R¤`jmOu VSb|hw+)>׬7\Wnkn8e\G?~Eu8 8 Q|csFA T4 V+$v1362'f6ud8uO"=KUU1^FҤYJc^@<_c P3s-ܟMRR~BaD>kT?JqW'wm6:.)8R  qJRH@9f~)FGLnnyA!b_g1v$4O?}@l}P̷1%t+tJ>Sz@$<ݝQ)U&T]I- <"f~* {1@!r)sKJJ%wm[594m'7Y{ ٯtp $KvnÄu-zϐ6x.LAOۯ./ 7%F~6@c CMrdSUxU~7Tj皕 *g0 kJm?dn71npt&gF&Fźt<S~nqHuq#Iэ|=3wIW>螲6o-|y(%69{[ b<{-B{*~:~ r{HKαҥ0eu/X-?RXb:Mo Gf̭T G`wAt~38m&ٺFWe"ƥ;suq^߂ v_v>&Z}L8 L(OQHhh,]s#;N{x J LJZQw=c,q2!兝TRM)ͽҹuPRq$zp Bp>~t fow)#'=rUpcK4;ŏ!N)wHB|ʹ>,0-'ֱp$i}܉ $U,dH `- .ݐU$y Tzꁰf0D9CSxm[x&r@=aX&s - 3s.sێ1 訡O `2xMZ_FY+E)~SNyR$cڬ*ntL2}|زQh~Lu+ɹՇYqrpU`tz3 W5=QR!]tD1FEԒE~v2k&Fi[v% 7,gq({:m.35̗"`.}bp}5N`zR]C}C5gU046"\Aݫ#DoRb]!f@(sX]Aʻ+AqH[WCg("m~jC@|YLbKXܞ=h*lL.(dq(qNNG'Umzc Ԍll58iB%$d*~1%?nc0`}jIIU^rOzmo.-Fril*(>-ur'n&Ԛfژoh:Ul>Q܈"LK1G.YHl~_~*#c(<` z0>BNha; @F`3:Ӳ Bpa>Ճ="@_drΙ:}pE`msa!tczNM*m~uk\zQ ^T0y*/&%{қjCy,F(m =/R CM h aS7*O7p^nY52[s0-%ay%Jd~U =dC5 e 80 :ٕkZEeCW([;i sHqw PjDbJiBAW!F n.ű( w G X*ayՂ1"rc[#闄ًvϺc|Yݚzq* ^h?`J{%weIov!{PU:1ʞ'ԕz':.=|ƲF t\@Oˢ+ \@%scme%u+K"=}ePqtFPY.:+C2xϭ?q46'2 Lo!Y+NF8k6v~EU>KJ_h.SRaҍՐ=lT3=ו,,E1jfOVnb@T@0xn@# M9 dM1 VC!vLϦœ퉣+4'+ ˆ"+}ZMW'^ubk-d :Tls`\1C%)wp([qRCCN ".ch\RҶNENAHھ1jgAxܨp9@c8XfP5/}%;ſRwUmH5ԂdϭՀك%rԘuSFkkm;YM6=sW74g\n-EkmMvnBqdh)lî\ՊCx$1SgC=E0-$_0.@_nd?@w"JRp0Ó7GxBMRC'dYgC_铘͓[#ה%&O(#d1'Xm7h"0IUkSt 1|ap6> ZfE3'fr^ t?Zvy(ʖ{ Fw(oDu$]QcibC]GV9rN:/h}_ft:][ShrGzf*cգ\ԁ@v;ER1fbmR/x}olC~CxbK#ߋ|qdF:RetoXk<+yvukj,PM5% \,]w {EM CT $T'Y]u )c(gϧZZyzxɣ:~k<PoݿcQ7|gI JD̑UvlX~I-Cc{++*qZ|@֌xK7Xlj3%(PQ}BM6'C%|p'_"!"B$ ~ٽ>GԢwnݰ9?9sS }{S+UJ?x ^8w!ڟ[[RGziY[VIe5э-;32z;D|gKȶ)&a~g;?tBurFM^AѳcNN1@ 9H6+ Deyu!Gb &3-ǽSCaD6Rx2qWIsr1l^ƓBa{&HZ|`/@u'gUGH̥w֛YnFԮf&Ysnfڠ+MA3ff,?hEZ_ZP57R&Tvȸڧ$~p[Z ͤ%oUT] ?NQ{7="\ hIA rK;{j^))=r`8iI7>oGKx|dh?b*ݜԑ:jk A0N\ +ɻ)+uo!(CFWMm<6bгܕ0ᒞdwNN ;h-|޵.5֩PQ"3)L{QP^C7P{du3cD3`1)7R9u!Tqy%n.BT8}vTh(κ|S%DFg ߄+  H)4hYNtUOdO@>#tޞg*{A2el%[sL27:/qt;U$bpܶ4X,pًp suqGADT*%b.Yʛ| ikD{ݏ5O"F' aX"zIz/˹]SWk*KԆF=&("뙞oeIk:H^'8/e?ޙn,p3a>::Aɡ׀+zݯL`U7C9Kko.P~NNFA jU.7d,j= 㺥aӥvٚO Lm hr]sl(ambcFc͢E>~#dBB)/`u]#? vd^c-.v#"yۮԃl׀j+O+tj?Zv#8QxKK=QfOC>'=Tr=+=$Dܒ ZEH_SfEUm.#" UN/fp T"/DF?2rΈG $/! 0"|ַW)l4b#? zTɲ(#)0[0?hGS}#XVRTTF=YZq)8aPeLvU1PRL1!. mXt-ܞtq㼨`Lԣs Q w`ڑX& PPM[1JٯY,VmyBkG ЃwH#?uX -TGur}gxtY\ A_n 7./ 3b}{Q.D2$B|[;tעmܬqX9$l{Q 0%fr\ʯ _sid#Ҭ'SsS?@Rl_^X3sD>cP$1xOHv Y~ X3V]bOtfO< z-I؋}]m 1B tV ;GjvyZ npNPF/)`}*Ws6ϺVcn;LlxS\N|{!)iËܟ98XLwB*@~h8d(G+ӥ#֔$X%i:WɄ'O*fI`x{"j넝ƘOh3"XB6Uf0u 5aF~FCc 4wєW@HMr1k#}*B$sc˪^pe:6xK HI)3MwUzq6Bm# T I̽TS;aЏgl '3& p,`Y@1uPܥMBdM"9^hWn&;#F1BG6SFOܛgqqh{+A2ƘdQl$?Y}ӳC~uu ob!ľ"cw5Xz`5{(FBfYP1r`GI=`:dT^^ȱ}dlE<M):1EpK:kzV7؈HdA0e_(o>fLs!] :?O_A4^?"l7UH3B\!o1ms +m1^Ƽ:Typn*H:Ɂ WGj,NJjJ@,pFz auf'{.Ճ:$29.u7:~2k*etRo%YR3o̯sylU,W uaj2U*KP~l2I1tj %Krq-eb=c4z1|2LIGިw;2P~ 0J.b?a~;i0j4|$EFjQBV/N {a6tI B1Ϸ2ip06*JZ'@l'Ҵ$^]tͷp6ۍxS޶#2y|%@RLfS$ }z|0C="{,S2J e 6 &c U5*-q{dUj,cIKE /ZQ7-O#?IZWrϪNdT?;5(XL(CځJ&#p gC&̜eL=8+#֏nx='L=#HX~>iz|H-i38" /b4W>vW Ho)mEdDͱ493k{qh wWb2me,1u~nFH bdF{k%[wTf)0nS]1洛fǞrm<g?q]s[0d 8qRmLX-i۞ j-,l=Ce㼇3"U`Ab/j" Yў˜w-b&*꒨ߘrz ֓M})-)AˑZNذOtEYA ]aqAT]5yd?ڱL)6V͏A֣!f~D߾B^LE; MJlz9^C0yU8xΟB^..soyRT̴$,{;hކ&@mnbg˦iۉ[ς(sl(𣲵T;(J\TԶ"‡:C!V(nGHv0 汉H۽꥞}]yB{"qoSLL-g#Rs4Sd>ˌ$++{zbY\I,m{,Esn‚jrA/BHȋ)G 50U) 87|j"iW%;)=*:Aڏ^3@/V$|f V$\'GϾNaL&>"QCkC0:ll1ت"fz]*]6o{8fD2r2j96ndʕ37 ׀`ʞ*7y¢[? p)`i=hӷZj5EpAvh G=82c8'[gU,•1t6Y-DMR:'.^J:W,X$8Cd}f(tU_Od91JQxnW%̏%_|QVY ')3KģR j9 XVˈ 0O<6+IVF6& >^8}NT.4, 'pX1$gfQ*]sL}DaKREa$%)WKHuTDι.YWE+)a ar Vf*lWd0pmkq Hߞ#,9b7^"ضT;[5Ӿmhυ)!=f( vwEGiJJgqz:n{tA (n껁ƭyB]bs>Xϔx}X `_o k g*kh[|(B$DŜB%ͺ۴IND q`^R4Ņ"|W!g_?}zE:40`ZvReL QX wEaU3Y[%Y5bSM74PG6 g:1ff pb_tvqEJ˧ h+~8/@{d-y>s/hȟ^(c(1`{gnM]OrR9U^ZdZ}H}->ho=Qu T/t 4/|ԱkÔa$eU:ktY@6Oz Vݮ*G4P*|phQ|jL0MdeU[7>|Ȯ.WxV <_TXbꝞqeDl19%0u(VH?8 }^ߤ &+n3PSBxꄾװNeBP7yEǑV5/GAXsDQ̢.{"z'/1~pHHDaB_nԉtTD9b"*EcJ ވ5.5,'}X?ɠ^ߴ]ν4FZj.F8:F~F %BomZ׈+#lvoY&uK[R]FF Nm/e |e맾(a dI| k7*;"G8{M:~ 7[#NǙfCW]e֔ Ud+-]R4YtLAD"AOmOu bj*0.za4cJyz䒗荆%tMte;cY Kn fO8xGUԇ'@U[-^hkQ9Ӎ yIa-*Ϧ}gˑȋeׂ-Ƶu/*{JutbeҼ:T)4`,Hʖ>)zЋoC`ل G鶼,u!(R*zr|Mt*=-_Icœ$}9ݑ$ccsSsl*dbQP,S9~n*g(\sP`pcS'ԞHRqzx-e0&ݧp: NxӺpAPo~z/s sXShٱ팷3QeAXon@ ?P!3)$89 eȨ# ht 稪 ɠ5zn]ӷVܘ@a %߂ 1wJ2Xy>P.:m®Y~|7Ѷ E:~&Gu%M\'‰k %o߬洹8$,]oRk*$FFITDw)*w21Nq i^F.36|䜞T_"LXȝJsExeSGŻe9+g4"C1̪ GH6zS2?&mT>{(CI^V:StKȚKΝ5? &r(Fi&yCegRq 1t˨v`y,[CP,6pc`ٔzP|c] /5w.#|X< vIڑq Ap9li[nb8"9r ˓>xbQ?.-2KԬ;$L(+.2h/>WR:6:'=C$T1Fӏm<ͱf6hߏR_RʱMBn3C~E Ω٩QomFQi%LFXg*॑rRE~oܽ2gNhO#nm ڼHTƽ|>A4~>rϛ8vb/&pSϽ_j~CY˼D'9Hz8V-\^|[Zxm$hUx7O*iU1}p(0F% @j}:}N/t1PA$3gf51d $T]v;8͵B$:0!qךּ-VՉ>jvx~DEg9;|H1>f bXC 3YХr|^>u bJz^{Co,7y>)&4WxΛiݾ E2+su zm vYoL޾ :M_w!4AR~xfdǯ[K*8gkNx\Y Ik]AzeK!L;!p5E |Х©8:0&vRqìU r !Wbg<‹ABcs_B2qarOslO:fgwx p-봩^ײ4p];E꼱O ksI+坞FpN i8 [[- t]y.Y(L(ޚmVJ ۚϻ[372RPbkg:/s6Ĺ<=ߜ'DZ-A0k:o wWdfŹZz&,ri2M9w(K$ߢ^6>D? crgÓ6mbn ]$0jUh_~}sImh٭mןtQ",dl1%7^*ӛhoS$5;k-[0oũ6ն6+(F1sܷv&mw鎞hL""ڊ%$?h}ǯu)ΐUᘮh&mWіhj.Kgy܉|ef1:HR6uQCNl z(e #h&412V^Yʧd#Jpuӻ~Ix U[uWN_UdlAزBuAփh"o#tx1-̢i-{BIYR>@ıSٌ 4hUn ƒ'Uw5"b(ތD&:4%C`0C !T5(<0)|E0@׿o EM3u(y( 5a=eٵFzySڻXEQ$JnKj:dM֐Q=Q?@0vN2S zED0T2@i!"*[Th * &e4|PIçstEgHY+M,ߑ]n! C/(Z;iejʎfўu[FΠs-P:gPyT'rzFNW;ɷ~]]V1=?mLWkj^HI3hJyðP6+:fz:qg-vlc'­5[AŇ04cYFYD.3?UrɦFȡm}Q'l`%oU_UR:m8㠹 Qήެ)/<<8x6]C{I}vG'cTh$zta csـj8?v5ȉ\M8u0M66*dw/OV.l>KoTUSY4k-+&L2ifkV_NlۧdJNET<3WlZCA;U~qY{|3g*tv` VUr.UWd2 AIwoʞs6(e|{dF}-@oٌ lU'P}bh*qÙ?/8Ք6YJ7{9 Vqk IWt/V:QO/ԩl|Z߃apV\ ,L5Rv*%7H։n{ u^Ò FiB@f `P$t:2VS^Ayz ^޳y-=w@`8$2>)ZcZUtD%·gn1K1L88sw {ªb_vnWkLY'WP,} QYf#Ak=]ܿ N^s 8ήY:P m&|x,/s Nit$I0?W+|&=X)uD7Mtw3 {o3J^3(ȸ!Ixꬼ9;'ϹF>; V)uGP^'PdOMqEC~W` AB@;EQ6m%|my2%# = a>OP5emO6{0h#YN u?OnB3C: 4\E ʅ=`4~D9ή{X+{Y Y 'f="a$Cۃv~+ }a2rn݃?h-f9E6QQqfT'ڻnw0隆 mc^H,g>,cf'9;Z34-!g agxG "CϊmM:ɟXPR7!f- ,>!DgSThào*",@_Ӯ/</ڷZzR@$:т5MNxW2; #Mz?o= D46wK 3Cc=E>8pqmR^jPzथ޸u<}Q2c@B~"` .$͘=?זfYyr>!_mpLNRd|^d<;Ȳ;vg(68iD8Y+[MIE_D͙Ueff2K )lMIypU#0hL"8_e}bc@# hUFUZ qs>J>,ѫ3nݸW! ,վ;sUTu u/T{@pt\dKFc\S!0gW[h-xk0 5^9 hؘ:QR!њʅ,~'1M.Qf#=a[/&""vW8Y-+4Y$vg;_*D#J\T^a$f\?_ 6z]єӞ5s䉣-BdvHv\JAәQ07N(\X}Kk:U/4Fb J`O=;\XB4lՀ#SoKpw#¨0  Q/ _`6f3IS\Ф$;МNYZMTe}\+ eb /!j'6JhJ3fC߶4 _(z `n2ؘvCC,@C Ȅ@h{?޴ 76zevOQ<58*E\ǻ 䟠&a99zr?qFaD,LuK~Dtʭ7ww&)O%K(d `8@Tl9S6P]4b_q!xɤuGfv:c3 uB!s"@9q'J*'TLq~QQļ5+%di_̣ntjRen>_F/ Hc$V^OfH?tm{OʤRfp"tU34Lbo%`~D dȗ,&ʼ'Q$B*tO*1 Hbe>{j13!Mо |=^8{Il"$!OƤirT)irv[T0.k8SLȴIQ,@e@ߊXAI?vks0(Ljc9seʽߓfCr ^SƝԥwpx‡yI_QVq!cWV s{ԻpK_L}Da xqTP&bVk~KnpTdԕq{ aG_|kKehU/ HZ^ږ R<Vu*{Î~Mȼ+xbX^8ozKq"+ %{R#/YNg %g ,6\*#K#{yf+-+kiSTs'U\PV[O wLP,IDѰ\:YV[4`G5>s'ln=;;,_.bȕK7 G}g~>FapsA"eAd G=OF %*>6+ok`75ZT:b5;95{mJLvmVw%©g-Jw{3n72}.M7vEK4dgl< Ѵ!= vBtɦhG'J` ۩vo.@[] ~#FlV_v]9Fͪ;3Z.T^(˴8^q3,f\8TlW(Ux \g0+ؠK`%iy~V"۞czYi tY188}@*z|r2T6矢OEt 'y1U+T@&gYEL5d> Ι!.}EY*'0J4qVp|: #ԋ$M^X!3&CLD.}a%oN`k*KC/9D.I> r7;KKZR*ϏB60$?U; 03LeɧKWFYӜv.\ <4q>Eg 0ݤ%Bé>]eDU6Tکܒ8:3cI Zir/jk VXԺBh&̭ۛ 1!Y]Ya|A<޳, pҹԸN?lAC}-s(2 ;:xþv.SC{uKކIɘ#/Dι"}]lG8wS 'կYh י6Xذ у2m) f{Et{ ggK!3o x !1#ߒ^caOY_S^e`P{ RQTW>>_eSFr_8دp-hv"7'2W"ܞYp܀,a@P/@,P, u(A}x9B$+siOܰvW\m18xe 48\. b:%0][x"tw=ȟF ?$}(xzJa1TL/U'$ GfKh[0weO,[}+63{eVs|c@P7&XSݣ<܃-2'.o$~,#KHq` ~N%'te ,vO+׈2g`-OfQ-.1-reM_\jmX0)x%˳PPMA"QVN786v-;J] d(ҠYtiyRll&Ub#FTR9xG3~.A(,(VEo<[XO$zZ٘({$Ǟvd>z5)'(%qI11CaԊb-`@׆D_8!uo݉d~_UlߒRܭY2VC*x5f)5/ꉲnH&4s f"yMa{$ 70t"1=iDhD|u$./e-\yJЛ؝~ @g؈l1#*RC1oyˁeX0 6n^F`!dB|,J2 m"Sٻ6}N$/L/x zY*  A"~ :>unbikPkz\ cGXhVdsճ˨pҾt(F*$# c ~fY~|Um<3Stqn7 6٬6. @`j2enDa1BXVDZ-[tDWTnU>YP+^% 2e/}4OΆvQƴ& fiK /b@o©"ZI;̈ObD4S1ASe8JxiF},.SSkjhn?n8eNhdUN5et[{&rsMbmv9A[ ]yoir~6-Ȃ(l|tzhI$O*]ŸezƳM,_a"=F?ZMxhXOc-ȞH㊧{ Sj d+njjcSV[?+}In*Ce'`Etd+]j `uO"hlʁk EcmԒfZ; IEa#$+NmXY%:]Xg?̷uDtN/)Nh)u|1a1+f}:uL7z -OX&]zVN+MTQ.K(CzhچY;x劳$=o[j_C< _-[8AVv+ ((-~~YFZ>y_xq\ رD#aZkZ\ͪ@dzT9GVrHR u. 6I6`5X:I?GW01g*ZKi%bD&x 7Be"xOj-P^"fH߷Rg:) β| N<%sCAJܠH"BS.Hsu @\.Mč}483泖/0l*X+r/qq1!vɏ)=`5E0gSgLoZֽ;Jduc:KKҝ{O)[ ru6|#-w?Jj2z#LF |>O c=ɩ38\(ւQ$lPӤP"IRQqET|;uj`>[V'Eaj Pya݂Vs^XNf8!A H)ʒe8 ٴ|t!]qq갴߷#ɣf\+YR 0dH.pxzހ@<ʺw%=Sy^U"xF 7iy5"2ln:|%h4d]o^fp7ɧլqK,O2!!Bgb1pSb2DJ+{'FRXR.軮,@GlZ[ܯ>Uǐ$\gё`󨂃RK3٫޳)}OſU:-EBZ~Ҕҿ:|!-ӔeLH4awC**W ;ɥ䑚RԖ/ fX,Ln*zjANz b6м[%pǸ-oZ{рKt$ct!wH$xκsDwP(KYz}Y7]P-.\c1W"&'r ϔYsBYx+hCkXN@]=RUHވT|W)~d62P١9) 9w<'pO{ST@ϸf'bsN"٘C X]qe!ʇ`T^-^Ž2M[2ZLѡ NSZǨh|2B?iDk&x"c`;E0|s8fej1g}D}wN%ӊN0h}y) B@E:`[Ek{gsc,,@ rI,i-{Wׇ˝LjwbٓCx"k0|B/'in%΃< -XkN4xmGNa0O=dPoښ3[pxdE-)/T71<)EKwkrHٮCM"1觪*#L1ITS[h'PNyY 8ڥ#ꆍpXrszYa+(p7-oyuS`&.( /t9ǿ UoHįŬĢ/TF!EN Wr ta:ܷUg@%YuULHϜ)c(ꝭMF hWGމ" [N蕘E}߽"QlSf@i.I,]z+݌ AECy5h{/U 3+4tP,) )j.y؇6.]ɉWŸ.d~QJԩ6?6H=sdRpVjȀܷfcɨl.E݅ђ10JrlO%L=De8u{ ZP9T.7uV9HlA6z\t9X2vܳ-, FCgR=lW,'R`ň>FB ;sJ`&=hЋڏgiKVp0Y|,okd4VS#r?lm @m5KYאYWo1*[ștEݱl~ƶߥ?S34 )DƷp!LJؼoLv/h)ʠag}J3!s(,Ku gis3z'쵥9ֳT]0 ! _PG4gna#KQiE6cKA3L`:4FRopI5RMN-Oj6!jFܚ3.;ted r!<qM+Vn/{Vk~g7 ZtMuDz]Y8HGd&x}UYAN>H2VR^DY{<"՟u|(2q[SƀՏiމDI.l<wDfJ bŘZ˪FLb:[$`[1^ψȍHNxd}v[U\\J#w4RDY]IUFG - ŁAysq١_ǧE!n.ύkCWdɻJMA+mȮ- ud7eQ(cY1NM.oK !~s<-! }L$3]*J?D[rZ.{kYXyvsɉؾzf m7Fs9˨xV!ň`+_ ?# J ~KQ`i6 1kJIE?᳄Bo޸V.Al#b3Įu'g }UJ,gC "Kv\1? 7gk+͇l9).*Tr1f;eg} wv\Ֆe6&xn̠Щ\F( %mXwDぇRD Tn XONAsth:"IcN39d,G.6c0n3cҗ- EGPJϖ| IXQsik3:b'}뎍35ZӀ썴a4l bee_^n;Z0I5UoP;V-u/Q.Ř%W޵\-LcE!ך*lj;09RR/Gp{;:D `NFrLk^#K򘺋!#4. }ϻj3ȭ@X+ ͊[]h8y8=Gp_ |P*jv '7&^_UǯKg]n16vvjb@,Ǧ+`^@q榰 7.CAuNॗ|A1hDꘖj}"0x*7#d黀D& G>/a)458pBЯE@Z8 u"0~?xELW2!oBk-;)xӃ+>k9{A#PWRW%R]:iRȰHCiӹ*{AdLӃ7F(˟FBo2= e|ԘPK3ąM";s` gFumٔoK^*~kw'/Tq-{: sDa[!ՙTjTw:˸87T+ '!`{l.O1&AoTg`icQ^ɢYw%vgR !2PI?xL7>C.٣+"ZcC{QaQޡX~0,50:6pSI, {ڃ?LGhʙ3ʰF5ezK7Vcx"\<;%Ë".|+F nF>"ȶ&G\ J#x~t:!HLGKc0fH,&;ϻp͌caA\^A2T yNboO/ZH} ne.[pa*  H &FeicZ*ApD5v?Ȱ_dE_vy &X}E};TT~2* aw+u6"e/F߆%4wV_ȶsS 1} 'aRvF@4W>׊'nTkf29SW\LI!;W,yT]X:[16 (*rftUO0nF2vxLӮ:*"1YTi-UiX{G+rc].`8Gp9LUolb[mbl s|\̉dR kUuKlщމ/hĬ^J7e=oPѠ Vj{žG!ôĊ rdgfY#:Zg'G2R;wIנKp+b7{h6NvgY'xބ$$WT mFKb*a|l 1N(߄PH77-ix$e‘o)8UұT"t%ÐJ* } B;zo^5T!ċy iQ ]~״ |WrV(^XGR!OȚѡl_uc\;37u.m!yoAB}Dp2g1Q³ e7?K \s $HSÒ]gx&Lpw&o鶴A)VWqtb+>Cv.ĉp ‰rgL_ N*lr(k:WVv"LSކ%`Rj{>ړ0* o˝1Ffdk!_1)KěTK|NthX1w@8ꍰ^O'*M%LS2ɾo)A _Fg<{--(!mPRiW< xݳL 2,gZԮK,{َY=M]kGCf2_6W('f6FPk2MX 9d(CKIN,z`%o}<1y<ΤCJHrcZŶ"##|5YUh1|!͘ Dp MM2;Kށ3)]$c  4I$=x!ץ[RR_,&;Zu;8ZsXwp3K}Nk'A={0:5n+:cUޗzjY ekB\43X48)acAu:aF=ecB!d |(E5\Yy S/D@:N\s@J Yڼzf[ۛ :Xq%Z! ɥfLՋnb0}tb[o*UeRͦrW$dI(7~\l{0.2X8PS|pWwC8J)ǻtܘ5!W ƷXFsYLT*uy'RTKQ0uz x+E"V-+n|5cA3?u3=5'=:sUF!0P- (`2*():&7bSC2=6)^:/Dxq}02w{?Xf/XQx ]: ?lVz/S6'ݜ\,9t##J([%5ugq x/zET/o3#%Q֝߶7 I;?NfPOwXkYz`4B6*a*c*归uOE:ZCרNTB"„MsxѰ¬QG\}0!-~k{a ~'UJNS}LYhB 2*8'+h8I+і>y51^մՂ?i4u1*^pon[ ?@ZbLÝmpIPxE&{>n˵x!C{\R%gI͸ں6%_Fo;8|Z:+uZkؙV=ϝzw%p?4>ZW ::V.!G&jΘAnFf9GǬ;]la[zؿtL< \4pY Yq~Y*vp/oޛ-}%? I[N2k(U)=w  )pN -cZ -v ΤՖI0uӤ7L1Y!^' ȗz:q!_YjQH/ThtƸw&_moGmF li-;V &Lq0 V!#3x-l;^#r~n;o$װCG4,z4h0D/;zEQAۙԐH l yFІ@BȣSiPͷPNN Op?*^-B}W~!QN_A`Pm]˸ԩk,oI@ ڋ kMfCO;BwB?~p>İyQ槑%ʗ]I*)ԙK" 3c5 `SA;;d*D$&"YkdZx(}سWa la w4Κ5y{`$7ج I1"v4N ˎn^{:!H}R5+ \bΌePmla+߬#;-{~Xq܌#N| [rNDUk)ŵGW7ۚE1`9 w'!#]EdR>wHK(IRC8<s*!mj<[2Iqtx|cs.2v[{}`([PND;K _mt̚ Ӝ{/ >qXGlbPxA~#.P}S56]9BC**-6x~!{ʅm *dq);֋|ض#YenIg$0͚bTz}A.b#" RqPn9 ' #\P" 7PAL]ZMM@)IƤӰ^!E =(ĦБ k{hq:``:ƙ^߃X*[ AK,+MK S<լ/6j'9y2b!fn.ƥ 麮. Ky| o&y|:Et\a.)TpGc1A3|~J5dCm-Hc5k1G{ ұJyxOnZ*5ǻ2ee=X! YH|mIcbX/Tk3玮`)ت[vy^[6P^>дu V.臝+-¹vxֻ] O)T+?*R<>Q\ Ҹ7H 3%[_C1Muu),zڰH_iW5q}Cf]"ş4faCS,VY* Vő);IAnYpҧL53NヸYr:}gϮ1Wd{g9aS]Wķ2qp(јAaYMYV#uq~~L8wA N2z8>lĮd:"9w0 ρI|'ED{+0q3^>e,ٚ\=֣$^a_ĨI@1Jw3f; K`2BQa1垤zdEp \BH)FC UI7`{Ss"Hh r U`To>%=tŞ|u/Y`g†^pg Gi :6V s >~6P1Ϣa!vYa$6 HJd}1ZqK4q 4wxjB nc7w1޹oNӑQ wf ٩ P1a.MAh|O>>~$!F|&'Ճ-*}E(-S2,l;Y3H)mS :ItJqh ~, M;`pR^Sor_&y|4 .E:14mUAE,鱨\Wi/\r~Pë+<6:+ćD\xvt7QX@GxѮ=5`/gb0svZk t8Mp3{{dexAO]Z)"Eԝ$^չf%× CNz>Y (OpXXϔW^aP&m$"9Q㾴s@UeYcX{5ۄLR-`Ϗl[{k(J8J[96pA[4um bKő݇ ZK>Zwq^y?-tgs -~rú+ Qavu^66Iȅ~ - R#H a)_M|cuO`B9:^x *s5&)HuK({ V'}Hi>Mlldߦ_6rV, K.D:NTyM$tX0S޺ZG&Sg\p&xKb`W1\f5f.@>Tޝ燖/hX s׉% Nsa)%I6G</i>mW1LSW"+IkRSj[B qw0zܹwFY%P;7URA.dI+[f ZhuE[QN?o[t_JLq!W=Z S媏f4^J?//MIlePԪE^ Xi7Nk ,w@(l~8>z'qҿGfi'0ʛwX7g}.f3zمN9z^I\qD_ 3`RԛQV)GPhѤAl4uG$rhΎswt'Œ ptI^T Brw7R]Q&}s5F-"mo3N7S 'k՞eOYB?}|]7ܸ0Zf5"3nՁԫu/#eبf?|2gDwV^I@΍3XrD[8+2@(~c<NJ|1UKÔ\[nz )i2R8ϴ=}FWC*ڔiA@[)qc%:Nh\+FOZ9KD7fڥB3)~B٣ArI+< -'Kcx{Gafi M2*nX`F>-M5MY21= *wJ ,D^ ci^,EzX~qَ򥒎\8o]16p}MPQW[@EtqOyۓ-򔶾2bkKԤv㙷hψ |0_+ni`dKPwI.%R6$-lГh+zp}oW2,{Ɔxvh.Ph.CzDQ@S1H$zEVQv Pi|s40hC]7vu`UOe|1#f\J)b ʿHEQd]4mцWv1`VyF .n{INk?_V-I PY,KM?d`޴3;X ne"ك%>w7 ^CH$p]L19+Pk;+ jO wdc2)=hiy{xVϔ R7u6S{ggc}J HiGRg:{v5"!W%~9bAg쟂1{X}BnEd0V=/J޷,Xye] x>ewmSP9^Rkإ7g\Nb9\R%Sd3Ǵad}5fQ|JjoTb. v}=ؙs *-ip*Yz gAP@rA=;HL^tg #4ITͶSɚW,a zKNE-(IMJշ]p Yg_ҏb`&r咟:I)Tʋh [ݕ VoRmuJS)F1x_`=gypOLR1Ǣi\ ?ŶbVEJ%Q$/~/X8MGߨrAq$Ƙkpb]%ڕi̒? ~>A H=a`dve.[q o鋞cVocRX=9?WO8b='⧍A?*tG;L}ڟf-#f|Ud6"zKT(7D/3r݁y;!yd"`c@}Zn˜M2:dA<{F=C9^QJQۄƅ9m~2:UtN0@N4S(I-"4$yfG^BinAbŽħb4j_Tk.Xރ YqP<̕3iBj@@b@2q(^Ih<ف* ۸ny"R|Ĺx4koFo5A^`zch>Ct<܈xw2߮()Ut#GBFRm֞bdx Ƭ XXKb_@"i=48׀4x6q_~21&vk/R>wbűS'"I\$c.ƌJNaMJ>dS~Kka]Bn?t 6ӜTɲa8./ /q'sYED+/P4j>?+HaMwJF@zrpcه6[Iwg\i[i:[E3>k "&tW2՟U\h]#f5 3·0uJS`4]19?n_Yn`GK1U rYh]?'Gubf\TEqߑ4NzC~Rź-(vbv ǸaO3bBb37!Zܩ +jJYjDsֶ7ò~ ?4iGSaKG  ' :qOOkO73I7<ZFÚ]6)qg`G?}Hvr}L&^8\h&rXD]ھ5AS/&b! 1{軫8$uw]-oG-1"TemD/GeAu-ګr1eIrꐞXRaDNpO;З}=/BvQJz|i=xZx żY #F+vԔ?V_2RJ J#*dIVz G#/Q_CoJ{}QplS˱1u8#z ۤ\38b=i7&i* 5's>f6h4șgx"T%A[KHfȼ_ ?9*<̤]X'N[X%W)y+i/ˑ^IRdh|BsA]]`D(kŋ=h!o7&J悜kf.x(@VT(# VEDu 0MVHE!;9Ne;!bߟ{xUc)([%Mt晭jIFw*TkS!_OyplV^O_;إz$m\rR8,HUIG!Yc28 ^_~,<9dVl%}[,,44(5"K2b'M=#&u:1a x3 1ӗʂS1%@v\ i=]䗭?^8ī1{+IԣզZ\ ~Ex^T\g^Vkqd{ Q!O0;dDRW 7J&ISGet~x7\ /}It-ݟ6g/|×QcD|kVEcGD @h*\mǘ g}6uOcZS =5.4e|uE26J 2 % Hc GvUL?akCnܙAۓN"BKgov/TL"$s{#ï UaqGDu>2qׄ$LBP76X["OTA5EkhF⮸q=>\bPE{U;c[ʾ9sI_KCę/Ŏ-)ы}+\#jh=9#ԗYAņès"4q(|~pUwӉj3=ZzT$߾at;?ʈ/: j(XZR |}AfPRS2+ԟsp其%9@]P=xwcCΜˇ1+ƈi_Ӊ<kw\({w9d!vĝ;TXzui9A>=OIX \LIj\֊!| tM";W|9++I)M/灉Myʼ>#Ӷ},u(|ZTDSς~̖1V9ClL-9KۙSۼ{Pmyo :@pZffd[|,#g|rm`n}R76̟gvٹUsgЇ-DrzQ͞R EJ5yK6Mw1Ɇzk&QW"דhEа\˗:@Šxd\ۖDT͛A^U2j+T"!W_p3}fex+Dw>J(A|V ^Pylˏ1gU 9>YWtxw`x;HK#j2w(E ;~i̔C3}^֯UMP'7=%GwXzE#N.sԎݼhgM @ǎѠ)wK۸0 T)҄h?}$+mMkkT7/흍9zC?sĹTMv)=AB;xe7"uUUJxwE8hOr1})\li\;6ɨs[_פYmUEg:7SV).{=',$ԍ{h(EbhN<_k۾._ix3J6֩w;QAUTz!}( ]IXB i c1DJ~PŇ`qGe&5-r 1W?\pRѓ\xnن]"*Re@BR#鍻s2+0S!ҼL_r֠3D_bSMF_ ȟU;,cQˤ,0Ud$mFޘC/==>]Bɥ9im;yʁ!d']{\.ˣaI=k7*vĒwu'p|=~d2!4g=w߱Qß Ցc[S__@h-Ca#">_#kk-WCksUQCepp>%è4Imm򕝔.F4J$s`u|>c/2/qpW[XnN Hص%Mi$SKsL`S+A>FS̜K6NY26r[ʡ3Q4xb!3Z?(cf#uC۪I89֒r w!)fr d8ۄ@t+H hzsH`T" #wr9!o=b?DY_tT|ݴ\zS,rcg  )-͖b4.w %֮p$ikw_%{4 fiw`lpq7QKb/d듻8ƇU,t=ex `̿Ou}e-At}];-Pi #?툄z(Q )\lBmX=%KRju\Gد!nZJׇn״=wŦTP,=ry_y76GHz0-m6Z;ne5|qȉwFP4ˌ>ґhITdҚ"btߵvFjHC wV2;7}+x4lw@k㴧Sa G[KX Aw^+2Eoy$-l":]IBUMp+>@=wwkBJ$0rKZE&9ƆaTNbf0<@H{>y[EDJ4o-ґY+EVϚaL 3 7o`ELOr)H.dIH$D4er:nI`oG֟NJ#<߿Ycg_x`A9bWdתᝊ1oS|> ڬM 0U%w&. C7҂ MG*fGdQ:ϟ<$-Ϩ..Y@[k] qJ-*ªDBE@vwG^hz>:Lp]H4k^ Ĉ6:F|%o`؄ s(ȳ^]39BZU}򵮱BgYxV'qo#1x:QxPdϕZF`uY-"zQ2N1j윿=_~ 1 LC|҂Et!F+DA^"ciPERay/LX㘟Ooq gzv)@T=i m0UU)=Tjdj|)IL7/l_pܳG22n=R1mzP 6`.y0UO>I\K>P}lM,r"> }E26|j{6jFI˰s r'%Ȼ [TA:u\c)y_Tw/;!qxptrE=u KWDTI[a;W4ahV,$f Ou_a]*7+?xQPAWp-Y~.5TKzGVj Ds IF"DhUǣ&ON-g=#aø03[A6Y3\ø>|@}/Z HR>48ȥֺ8g_@CFha_~Z1u!A7pH65`0YEV%BA>Oӥ4z]Di|w< |zf3XƭFJHwZrKvL 8Vn!K~Nb7~Qʢ ghkd *0KꇎOq2G։@)NIIcW6Z:H #FjKAhQ֢FZ6Q>z-$l:DJi69O.ր^&r-TU@f7(.GOBH!?zVz,_ .vboͪB~]r5bU!xn M$Ѽܨ{0} 3 cNK3lfi יZe!ldU'x]hZM# p]_{ jX*T/ h=z; F#RH$18ҶcXGe< ѲAerc& B})\Jr}ͅ =n}R-h!tc{V^?1wH,p P'U਒q 'VN8gDtTynm3r6"ӆYX3x;XxBwυCF1ޝ'3Pc>h5.0OI2ESv*m͟TLGig(6ܬiŹD## @Hd m9gE`IR2ԅ zٚ!|IVI =)?m|e6-:nyS'D;HIȨרSYR:yMr1ͩBҋUpQiㅹ|6Ɠ@ĵ)1.nkVa!\]0ދo[p%^3^/1)&螼g3%sd ʱ ʕ"x9ZAmesL[^zǐ?_af˻^Лnj G̒x`BKf3 fqIrr׸(qaX2lY#ѣ~a.ʼY~N}JW,{ڔI=Ϣ=4ZB;#)viBV#X]=Od2r)8??r~w#gAglnp'eWis%6\\N<đPo0fCD3嵴n΄k=W҈i0WsЗ! ϙh(qnlsܼ(JZ0}U5.vVIhɸѮ'Kd [ 'mT$@w' 5;dF l/-suF5,"p?asz :"/ljMYz\8ڵǙ:^ѭ]4Lm'0G"MrwF :C !Z ]mjÛ _[ ~9s7W a>> DםDe,k;b"V=ŬKc5|_XmNZB7Ļgn6] ~_P|I)^rBÈz `&~iټC/gG&C蹁h4є=$kn&-MXJMZrn"g"MS*ptNT`Ndd7xZM7r$M隄ć>jqCa鸏H$XuZXI΍coqz0ݚJ(P\HlsJLVKwgR﹣/mN\r6P+1A?mX뵌{,0e-']YP\ Ű5iUp3nL|ZBiY 9871]jxEIJ CjxJ yV)E-<[9kFzKDȅF!ht!<M%z큷Y7MG EU8u [P%$PGjzk&MDP؄mq}OWqcF d hPLKɼ |Й=x:CgYYd{- lY6h/kbrMc\ф4_|M^rHvj ]cyHVwׂgQ^Kޔ-NU(ZR>JcJ,s-qgzڏfoűi7SQZ-ȃC >pDSbԖ G!͂π Trp8Ѿ.It̃cPDw9Jim[5>ܹS5٨T]g4P%|1B!7$qpt 7/0q({I>~#ǿ⛯GWL#Q+6&ZdXiqqEx貲3$dpLqc*x?bP`cB0j kIEyqʅQ4]1;;4$xl|YB⎆Vj5GW'Cb50RAv.ӓ{{SF5eMH!,(zahGU*7_ Ke՛6N@Εp:Hjgԕ32Ch@!A\y+&FQ&,qudOACIe@W^ fFb.t g]UP#~~푕kš~8\%uQWsy[RSt;ێ ЉHAKdfqrE-s(C]Ug`t8A0L =B۝ 2E(Yf<.sϐYDifS'޺J_rm팿Z1'XQq g!^[8#;qe$<o V . XE tU_]h)A+ =`5CB~80 ns˸\ܾOO˧»[MW)ъ &=x5DŒbB(˗OŨ^9cﬤS #ԨN8Ti=OJ}[˱\{\ёSxd3<_.ڨ-N=4ĭJ]ɾ.9(PIym r_?N$.myS lYihM%3Y3cbnTl^kmKRhi:w ȒnTS=y#9L?f=?ܹoQ8}eO@|r[u%o]К2|ߐ y6" vHIX7B3°G3$. 2?` sM`~H{ !| :Rw& 3 ].Li0Tn po#٪[ t*.o|9K{YrIjE4P-$@v_%` ?tfdKô%ӲGl[4i$ DE,&܎pQ1&D`6zȧ5 DxfKNOZ9U,??UjM=PllY`&r^cC=j#y)\ep~;Dmy#hGmṕUr6A |Q@Ȱ\:Uq ;zt.מʰ1Q Ai8` e@DSѺDyFV'!\jjU@Ϗ*gv"47kXj!y"pq1,\w(x 'Cxt\@6SfE?zH1"S2-WD|؝ޤy'reQu0zg-B+Y-H(<0IF]<%:8BbwXەR6%eVr#;0 ȣQfq侸_iYdhJjv,ǍbaK]8 j=G@o\"߇w28-e%X*8ಚMrA+]nՔ͍qH}|MA VK@;'ǃ ~PlkO4'N}EWR- #8Z~4eN69/b4vhӱ$2QmBΈL@OT|2bĽm"~!s# Ǭoh2+$4CuH&¾7j;sl7+9疁u8SMº}^ˍ?Z _q@~N4XoHndtis~~2Ǎ%M̻/)cf0C1X:S%+Ay]ÞJ$2A?G1}c5a3 DZIɀmA$7 \nB{lE [`~B0bTMyz\/6S&!m9<7ƅ6@bƑkG!El[JɇH~<''e/M"Q(MWv2Ց| ;#k \_]xn!nf5dgCL;b+Ln8$R Zܧ6noL[|K(^WE*R pIy{*J{brf2/LkwjIq\w<$0Xg76V+O9[a䗘sO>1lM|(;\>ՇXM<p#o)C7r~y:pRV9UZb{Gף QG!6/CI nb赐M!*) 8uǪз*~(X:8-/r 'džrP eQ/f8.,oKYځ_)ՓHdYW +V) (,R q9* (%-'ƅN=WB[gòv^_<|?GZV\R?yXWX*\^F01)YY"#R찈RZcP私tۀ-oIR'ݱ=j!Z)&?fQυ&3cZRL_SB/ԼlwnO oG2)GM s,iRzZF6Ց$ݮ{dغn𝢖_g7P}vzRlYźo7Y*`')ˏׯC{OuXQO/,lS\1&~oճ {3cLy%; Q ; VB#Wٓs=Q +Keb?9Ac,k+Tz ceTaB6g|艇,ǼA [U( }r  3I?#E!I5:nۊ_fWrA$]`a`IG@6ah0[<Kf <uʥ$M3VTI]v l%X ϊM}*|>{0ճ֦\l>LFQŴM &CA UQ[}J_V%<'ǖt:Fwz$̀10Z5fni!%t58jKm)إ`^Ɂ\։DvzS"=&|t:ZʄUW s/˨#s"E/q,H f`sL4?:&Gܻ]P~ s,Y^ATF(scbБ>T}2'+meczBto*Tcs*O؟m3\mI$E[(\ۦ,/C(Oʢv6L{$[jOcZ#i*Oj~.# 2P$s'JdR~`rKaLʙZZҬ ]kgmSY>j]pY$2IT&ۏ0C!!)8Y9+ 19xX :G 4+@4B红pIԢ8pUf!/+`$޼ /3mq7]/ipV0]}F,J ƚCAtv` H#&1EX;5D\;(wT0%Io:!áUeQQnVsl%059t@^l6"'(JҾ$}f>G>֢? 85Qx!dgGe]^!xDe?w_\|:4j¼Ex P L©t["5?Ppj^(@PL:x73dpAW'Vd^3 rW!idEP'=Nz!'d3W^ƍ$Ǝ~yHim=x}%'d !!x#۵a2I^NayMhEdv7_ Aq2=0#F{g?.׃[[Lmt.\v1ގw. PkQt./FGBYLn-Xn6IDI*p cW# ERTun7c-NC=9c_ ;&^ 2߮ôK|x,c'#&(7Z=Iq0Qk1A~2C97]BiL1D">"NG<.'31>6U& 1. aGȹ@+"}0qEMYJ(i“VN&˄@#'=e^kJK2nhfх? ~vAwEDj;ek;ш lD}*9>o&kb.+2,Tb }^j 'RKuKjSW7DxV[0A%!fFw|  Yj5k gLӄ` W gY999pڢ62NF/,öVW0JmO>N C?]E=tmKi8H \fu + @ozFr#D]ʊVG_$á=N=?jS2}{ o-K +ձb/##>rx#)0בӤr0>YUFl%G]byMۅ={< (BÔWs9 9[R15 o_MHs:wF[14I>\(33˚U[=Љ2 ]^$r]h-#$-Td!:I;&%.S,'MI FCb3J_JpX3ؔkב!{țDbJCUwNS"{ u:'I#B\[U;&/j*ic2јm}#$A|A^Ҷ۸m&fmگ,r-_b/^>S2M_JjM^&wKOeKmx')tS;BRpVc%U<L.^ RkOݢFDo]C1UtC}ڒ4ۋQ;,UMciKpK'cIzQ>NiVwGkSmDF0 OD@yss3$I|x^56vێa՘.{"Rx$S ?6_6>)d"Z@1iSF^!^+߾Ob ^pb׳𦹂xĖ׋~±pe3HF@H AXm)-~=a tSyh0ļzXƧn?AVI ,WE#Q]/ΰ[ڂt➡/O^ol5C]53$ۃx.!M< T&ӌWWbx 0*4%86h1@{ g9>s hPQyiY q8Wbp w~okvQ}%B%+< zP&0Pـ,]eBLRFf/3?|z>w2)Yg{( #= a~rC0nSMr Zi,?A9ƒ$EUH]*2wB?Q7>E&vr8,Gi o+zwabl] 58;vcƩy<'C5;qozĨs}A8ӵIYgV.A$X1\gy1;K܆C+5y{Z1jQqc)T%gvJ{9JoPhE V&M<-a~UiqyM^nĹ$RgH'$N#qвuQ׭d‰ʧș]\ &%`|ӏxƑlԟW/;pkxgIcSQ~dW}Pp:#0R\m|1BX7`l-~/ ,u-rxo[,Amӂq[F'5Zž!:X8u 7B4w9^/an $ rTm3=J4Vܽ;Dy7~H9 &N2`ð<ӼW/ɴs+2bYI;q=eUM`7~cxK֩>20 9M+T;gT8opk͙PrHvoYVϘf擏Pe)g>L3nUJtRKdBL`8-m7hm7<pۓ<-PWm(vXn4HJ*pDĻӂwHr:fj z-t >#V2 eS&r7> uUi|-UAC^ZbkFpLjO{=[ Ḇ'-* dA+Dn f*x[3h])q"dd w杀-E`$'LOwwm p!6f(YE:(SI)!do-jD~UHC3ebrB⚱|G-1&y+kXHDKjŬyi4VNs`Zh#t;rMF\k>Dy ib#Y93,I²wƐ_CH-e;dSs,5dǴ^=Ihu&TmM¼bޭMEeJ܋$C ajQ|9u`2IdhgjaXZd?b8ieظ'1־*.h;x74Oڄ:zsU\f|otZ/DQ5Sc] ˧p"UK;K;,s:Õ}rͣB Gٺo⠷?K QԬ pOOAAfk"bmJCܽ`I1 7\lb`/PltY1~IZ"pp/1z>XF*>8䰿c"Vpw >it0A{Xv1j>$Jt\қ6s8+ 7r~9Zfѣck$GQ\6!Xa#l$!n#u1A.e!.|XqK.͹ESӯ zw%airNQ_XӇqqٹmŷ*A)Vgg$0'oAmp"沠iX!\gxXN*cd ne!FB@;OAH$=ꧼ 8 l} -- ]Ie mE6^UE)վ>k K%3|G%wQ'44jv,^_r&Xc`pk ma|wlX;31O}&]e8@D!K77&΋mm!ߍGt11}Ͳ ~cI“opfBPxʂh&g'b+<e͡3y[aX$fx[ w8 ǝc;[↉RyL2DOSƌ1au2GC?/a[hGt2s(ݴf lAol!6ە,?.L7[2ka>rQ"e GBD>[쉀}6̈́2;tөiyU.JنC$iGXņ`ܛ7h:Qjf.${O8E7Ѿ Ʌq(C߅h=Sŝzhy¯f"g άh\4Fk4JФ?ǧNlA dZL{oN{+( -/Pbۇ6ZX@!`z;jbԄnŤjuhrss3GT_*AnN`&H ܽsfVL0Hۧ(P[S_EFnlbv$"`ZN}HzSBlt _"S!%!.CKb[KCu.~ԷPb&񉦹,p)ٌsC:dt$luUDK,m-L(@ҫV] ]i}7PCւ*ua3Z['>Y0>pLpR4+; Eƌ d,][ʰ_e7.DvefDJ$h|'[~8&"]P?$H܃[Ufhf@r^5]ꔫCBqeK -V•=ORCiMQBz0őGU\`.D4!=KDF~h5umyXCDߘ^k=1?~lh޲MDѰ,j9)$nGՍك3 W UޅWrr(073x`w*&ͮ)r4gU ~ [1(;U"kI0BfI=#H>h 9OT) G';EVrG]DH6 !So.wd Y(> w:=~SJ, ,!Wfm;U_/\C|6&3l5A)UQ]e }Ź Zʜ}'JM\_%zODL?&MDeLO֤r!ݡLBU L~C0-'=EY2jV?G& ,*#kh#Q=Me\Y#N#Bh U+"0xDǚ͟6 . JeI1>;j us瞢"a;Ӎл9iL(q"f]쳕gƳpb&;$37Y EPsuhQV*jt0$!;w,+7 C u>o7|`MX{0"wOcbGp+ ԝB\!QM[9VkEr;Xxf @pJz>JS h)SyOx}>d56(Qp˘2KI'_|h*A芿 v>yϢRce9"z:}'P9|#4.VcL.Ai\IG6+&}rpͅ 7|W4,HI?>,rlvpdž'4 ={$ Ns+;uHyPx_ZNd6Evk| yw ØZˎ}س[?A?TFnU 9.BYt 7w(s 1"#PD^\$&s+/~EN'zdzvaF](g:iºyƿtҧ1u‰dLs5yy EV JNLҡ.p߿\M`_࣌*m`"`g(oBJOb[Z%1c"qO+lEDz3!tˮ]7:*?cp0g,K5-?Jg@tᡙVD[7܌b#ob-, hօ[,M(FPmCGCJ-BV~En|x7(,CׅC 53sc I0D}%uŬZw_sQOvm}x.xX @EoPw*{ TՎ՛ _g$;֚iV#Fw4'?`Dvra: fV~іbEVS5?J@{ ?Ao-:";ŋ Ê2/JT۟o_^(p%]/\xhVFu:~ONMէ0~3/{ëP3um%&h7Ɵ&#|ReP^2؋ұg =L `^r4yrվ)S]n2e #|u .tMD(,D(`Nq=ج]f\0\SNʢe$O8NA}zq9pr6ͮv#c$~!&!]'s `9-Uild`@J.$2-P ͼI^_6j}]. {dֈ7A+e,bQA_ߪnN$ُ t\[3"5[Ib]^Tjau*zSqJDLLy_46Y|]UrgC쿌R-t6fl!U׊ n1@jW]tTSe\MU,?x{C~#cmI)o.Rq7AO=ބ*r:r4GMk+|;Ӷ)MY *%\dGOYƺ;8Psh'}QZ^}N73DC O:fgذꪻHkZH mʦ~{ '&)F!b"=l0͊K3_qd,NqL,z' oS6 U0@~ʾM q5bA#eaus.r 8nWa^XA&qduBB[EFGϦcF>5ֻH5;X _%&H<UHBt u,o<;iߣgl60E;cɌ;vQPT2Qz&;3VM~ߝ^v aOwn\>;\5}Up 볐*(SI1NW1펭n5ZoԵbϹ8ܯ濒ƦhHy`ڏڲUF g`eMv('S J*.:'7/7-GjKD_o=y`3{Zڮ[ܫe!w5b*)w7PQ!X YǞȔA3/6;#-aѠi=#GKO xP()>>XH6v<[+?mf1\n"AYڧ|el>ZAt(6Sp;[n_hù c k17}Wf2M^9vŏ^WI qyl8Mk7$bI4{@D݉eҐY;M|)s 6{]g;E>*|NZF#!߃8oalҷS8g- XhRT'n=tU8k2۩Vտw@%m %WpJ.)){^]yT6uvJߕ7;Ӊ|0O0 $H=c@ur"]w?5R͍)u!An3u(oNA ߷ wE]T/-VƏx:z^~-V #KȻ;nkJ)ft.OV@Q')ܩo@xiH% T +ڃu +ZWMrqjW/Pe+a\xe*|1H#jUa(T;6^UQDL/#f,iLӸ2]!F#yDŽ߭ԳTV;<4M@dg-]N,[/ވix)^; -`a ,%sG ؽ yt^+n,5!h8Pa _ۮ|qr2^/^9 O\1Ag7OW@˺٢ɬ|t+m'Qk]r{tШ|q#1zTЃޮ]$osJ{v+ffoz^UdXTR%TB'YT(nG/Ww-)tBբI@  Ef\'lPh(E-q>jEp'DIu$3}AIi~vM@C>8y3,ar@Nj& a#s zma$TYqX/nۉo~LlU5*xcpI' AޭoZE75)GIJT]tP{\Qs8W*C7(0C33 E\e߃q [Vpt7˲p \dSWJV@Mᐦ `ǖKMm9_S!Y _^)Ԫ!qþq`j Lv9*NCx3/z7+82bU}DU*_o@Kok(x!9^윖F eme7+X#{Qis3Tv 9((6ԳPL`#B[վ<:~w<gʜ3 Őb"÷M VbW_3}"=2^h3EVxұ6 {` =g̙J>O$J+X:~cV@qIjt1ʊM= O 9}Mۣ6-,Ae H{x^ R;rJ[ _BӡJo!_rx(9JϹհ~:PXpCdNak. PVs5XxJ n'^*>᜔rmTn*oP2ȵg{lT |6hEcK{*hQb- LVf^a$jASzQix* U_su qlݯ [(ưJ&1DZLMn8Q&^rDbGF[N̽Hvk2SF+Ô+,R+^0HȆ=gHw]۩Pj0 -hO:} r Dh}u7#_{'/?o=O}`t,FVz^yM.6xcN2uE 5J˲Y7)O&L&M {@`*d{; =8i;_{8$*ZƎQtf*2ޅ&RR)$>]@opq`JnkOJxaF,&*Ycl>))ٗL ^ KBK y9댃 (ku>)6oo.W6mrI$q<D¦alO[$.G-ԅ }[?1eۙFs&ծ̨AȗNػu+'̪ul-58MUP!'B?(VuMQɓx:eqAn^'O;eUTA*]?[U394ڂ!fIhڎˎ#c% u{{Fb.bi_ah3^?SSJ l+/| \Pؚ!Oݜ]~ ^d 'WׇJtf}O`Q.4WGس&⃰ *#\iDŽs-I9+0I%Al;%$2 5){.%aeNNjxCȶ!"|K}*1ɬ?pic+\+&c7|7SyѦxpY' B!B.߄ݻMrˎ_W*vW|.Tks:&7G^@m ]PF⮳O6^ y ?~;G(ѯѰC3!f 9KZ3%ÇW|I[54;F2-Mw[ Ekpxʕ ͵i\@:a?̿+:C+os'"g)E\y4vI\h`aךfcu>/ $=aq&>=2EYƹlRX2?cżvM/)W [D5g^@zG?DMsꮋT=݄lL[ֆkzHU_UQ4Pn `0f~G{9qM'r4a;J#evYrkc_HRpҏjqE֨0>M8ŸXyev MYh3L[ gUԙ';Tx;=%"NzT*֦A/Pej}t[p#|xðE~OV4޲W{\__5`6:C۾31)Q얀n hm:$״tNfL{c,Ӧ:_z4"Rf/}9gMWPrw#AI$-<aިODs35|sM{,f1K+̖#m5i>L IyP]tyPc}O5(ьne=$ ^Iv X?O)ֻwԶ#4]r&Ac@539.4Pxm TΙؓ S6d`æ?(7DGe[ߥh""1?a>Ly7}@KTWT5͟։l!-B/{ 0ЛNg8 &6z}񵺖]'\oE",mW:%˯!* k` oz)4S"7i~ylB"b+j|0(1K؞绉>:)HnR+WvZpL<h#EfDHx-ܯ_6<;hwi''xLe>,wɘ ;l;A~9bZȑ;Q` Ur9b&ݘ\CĦZ7h\$}{X#fLL9|]Lgab_%/7}t(gyy f oNƃg}`Y>Ճ,HSm Nu9NWRN\^016LGN0`SǏ!2Ѷ ޒ)t޸Fݝio﬊@my(C?P0NTeAo m=-9H@&ºkY|R64<%8+UdW&/6߫a]!8h Q˲!K9~ \@mؤ/"T݉2 vQI-!-=gkG$гFa/Ț]L"8nk*k*. ? |x|(w|(B\(UVB% $+ i, 5э՜>712|fУ!js#*VĀF_?~qCť?# nٖyϏr4M*k%@}.Y:[`}`/Y~[@s*m@ `Ga?$ Yv:V{0BX}fQ? S\kc>߶X2>Nfn)3Ph)-bC0涯ګwmU n.&|] uCq"U dbSE WpoVz iRneZK桕32ًvWߪ ߵz)NB?3W2 Qc8Qy=ꈈԩS&H`pX”gZ qbd'w͌a=E-;6w57s49t#YCH4ї\Q'7kHicR*"$SRbџ?g }^kNRMgz+s lBxvXY /:VGoZDV,lIƸ I*I8H?,UY(WQow=Ta.Ta:}lu^=D*,v7y4Ű՚:hKEbčd=`Ʊ-ߨesC9H:4E몠d)w3yk'V"t`_Lm]"ߍE.=ۿq 8*M33LP5/_"Spv*ZP; xrHb #EcE]/B-ӻr: z&0FZS sB~uw+6 hD3ͼn'%7Rʴ2=%<>+-qN] eYiOJ@0&!xO7.bbu6s82^Hߠ&N419 pT2dELv Ib*c>P&|hw0+/8gXdB*&*Ԉ%k%A8*uW*Dؤ~EþeQs M!'Y_ k1}zqTBѹR3^{E@v6W4 lPq ǰK6YUПX@//m 7NkvSSZއ7G Iu7I保$oKDQGJ'h+3 단M& |g]ЕZڳQH]m!JMGh#:}YzJQl`)r9̊4WŢO h WN3oZ!:rj\aNmIQαnĻ*+ڡ'pjoȮ2T쪵&:cAF?<8{E.ٿ$Qc-j\G&M./?Q~p 4<⋈G]TSXQ>R.qQW^h5CVUTηZfaôoc'\0IS}z: f.d8;eZoՑ ;F FVQn(Afx3j?D8 rQ*VdLA8}5 [JiʫE`{c%HѣM4*(zG^!y[+>dnx  V_߫BFY Fwj+Z‘D'#aKcSlws96] 2Ob#B!vL^(_:vJk8ꗦK;sġ#v=@POqipdZH`.q("S:!:Z/U . bmĝ,(姩?B%5YN wha /涺<*hH;1*KAUnR(:>(DKBN]b&Tq =00 o5iZ̔7PoK&QJ߇Y(4ot<fJeMf]Pjp%Sw@8-XR1d)DSk??UDo?HJThK`hH;ֈs~p7AHK! f;^@ݫCN!!m;Z5xIVpY. Z<]Lnh`iK-'[IPyߣFU?YSEu1| Mu6GX3d,4,H$9ď!g=Ӎ3ԮضW^ftoj]{5dDa:ʦ+: Ԥx|c̯X"#aZ/ITM|+QC#(m_ b G 1]N^us5TiP%fm?SKLUZ*J\ɉm~։%g>H|КK(.% d½=Eu{V #όQqo;#5jg% }&.Sk{eziRJNj GQY/:.TS:nRЍȅf)u(MY_[QmfX'tU\T K*P^,<)&зM?H1&8xx 92+!n o{O?=B Y#Ƹ\&ш0wy%8X{%od|lͦSCp&}%wiZԚ~\7ۺ39{LA3`qccBqE YCZEd%d =^ F|cd G\}@:K@uZmmÀ'!4۟HOW'gndIA