sssd-dbus-2.5.1-1.el8 >  A `<U]# J_#K3SJ}6+⬝t#W$1n B_=3Uy\6 ( "%QgH*(ʇI^d8S'>n|w^>+R3 5;apbjKdRӱe_?(^FhN8$0} ZT;*Xm#,wqBćp6‡;̬۞hN=z_lz յCinKg4J="Q-FLc G7$Rk'9v.C+èTIzd7>ma$%*I JO&Q2,tleFLOD/9'ZIa ZҐD f7LA`t >KLCTa'd|A6@5Co_w;֢&t.Fq2.\}+r*k~rV#h{(V[Źf),.hkM']͏L8O9a033de0d34daa9afbb48e692f3bc0bfa103eb5ec871bf3808af385b9a060afacca82e77053dfd23d65745fb25d3f8cbf1d0d59e)p`<U]+|#o|vPZ@S< |oUZ{"Bj(2nIq0mmsj}OpBjd?jTd   8 #7TZby8 T p  6 l0L4t4 a4( 8 9 :bN>a?a@aGaHbIbPXbhYbp\b]b^cbddfef#ff&lf(tfDuf|vfwhxi(yi`)jjjjPCsssd-dbus2.5.11.el8The D-Bus responder of the SSSDProvides the D-Bus responder of the SSSD, called the InfoPipe, that allows the information from the SSSD to be transmitted over the system bus.`iaarch64-02.mbox.centos.orgCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxaarch64 if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-ifp.service &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-ifp.service &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-ifp.service &>/dev/null || : fi%&0K. @AA큤A큤`"`U`U`U`&`*`"`U`@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh cadesvuk2.5.1-1.el82.5.1-1.el8 org.freedesktop.sssd.infopipe.conf.build-id1bfb82206b62f3d8a08c4034ed1089cf8bcc92b5sssd-ifp.servicesssd_ifporg.freedesktop.sssd.infopipe.servicesssd-dbusCOPYINGsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gz/etc/dbus-1/system.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/1b//usr/lib/systemd/system//usr/libexec/sssd//usr/share/dbus-1/system-services//usr/share/licenses//usr/share/licenses/sssd-dbus//usr/share/man/ca/man5//usr/share/man/de/man5//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnuXML 1.0 document, ASCII textdirectoryASCII textELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=1bfb82206b62f3d8a08c4034ed1089cf8bcc92b5, strippedtroff or preprocessor input, UTF-8 Unicode text (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix))R(R$R RRRRR*RR&RRRR"RRRRR'RRRRR RRRRR R#RR R!R R)R%R RRRR.utf-8eb3e6d7d16b811057caca66d77382776d8869ff91bb0d88a47a966cedfea1687?7zXZ !#,1] b2u Q{LQs1?0;lE^I#ɒ9`eΛ̞Q|, +\$b^)9eR1wSPJ{]u\.vpFJl&I"3Sz= <()fawao#B HWx<|`n% Æ / ]_cϦ{Y*K> fLG3/N9\5 uOc? {Ju`gk˘Ւ_a,)}GeȘjlG3ܺ%D`qX_H=}BDzDPvce\yB`_so.xx͎Ӓkor8LoF}PB;p]M`Oh AFQ:_/7S:C7zxY$Y4Jh"_JK'CAJ_/]~肣 MNvj6>f0_}PR8QP% 47 )FSsKhͤj!vOOq;tFMqHl[ +!|L.Atamp|RCS VHwkd"}zq` W^`/b[#$\$Y %3bQ$Q两c<\lh/$!CIG<6/D/M],oڗZ6#"7%4!@G_O ̓ tOSt2^ 4LknsT|c^ld8Gt{[sGMsw/2RئS&e]6,.dVV/U}i g ~ Qb8ugdi2CfSKBN|yɛ%RuϚnpҭŭYZ M8XՈ[Zwe"azj$bX aoR"5֨.5o!Ez]Tw{5&kO RY[}Lv{]* g'ﳿFFkw&mz6=K/;·ēe>F#td4rDtb%^GpC/lPL;;_9ૅڕᨼ~>7k~b)AO}>Hրj_%qrY>jm"o/ٵ}2k DJ)4p{KmHWWxQm<HW+c>/ǐ["'V1mD!@Ǎ+X]mV" }+0~A`2_@?Q&+bӘ v&b :e}k ͓'SQjިcPt4e7ElVl`GgTy7U% R JQ`t)!'qc V%ypܺBKjԥ$r#L^LJ/NqB YnV^rF7Qp=M4ף]u;OmpCS L_Ohژbq=v4E$LI!lo]q숂ASRJCS%ZM#;<~r"r\֘cxx5PM# ћ"˻, s`\?|J~p<ܞ^!2MD&z吝ae(5萞+P _#)>?9jt s*$x z;g&C|b?r%iQţCC>L `2Bu18 -tP cܶ 9cg+΢ƀHll2Tly<{_yS@-jWP =H{Ԍ7o&#yDB#|N K~ ?8(p7-t-~%1,5˄Y68ḾuSsE\X^h:dUST Ј7׊^74"eԑ1ኑkT 7[(@ 0dmj/: }C Dg :QIwG%&Xֆ^43_VXdW_1{} e1D!*l&+ S.0qD|>[ eԅϗF 3Pc1B)6{MY0u󛽤t- i&ez®b`<Y쑍1Z#YZڕuo~3~j|pt8:G/4nި%[Q Zl dM /5`hEn}!qlᄐ,V^ rw3*MU,rƳPE.`$E;+qLs7é@z>XO0nUɤW.+LQ+3fh"eXV@'=ieIa%fUr7]IH޷"X)S;$r cmi'uƢ)9Zi <ƚsٙJAm=/7Fix쥞gQ@@ŝ^dl $`p& Ib?&ЧOD @U^]ԫXEl!gh$%do&rs/6]eb=-7w"oՃ!jy@yܿ݊Ae<_w$0=T;bַpžk UscSL1 6㢎{fgSIce<:Yqqv}ƍA^tu'}zn{53̹=Ԏxԋ* ٪{ۅ2(-'iDp 2k]E78bZBYW7XR ,nk,`@Bj߁ܠBaDKZKS5$Ad(;YLEGREPp o2$؃$P\%;ssPp,`l6O4븱HfBf Ap`/T dSLJÐq"[Uְrs'jJw> 4yb?(똯k`mȼ_4\~Z|F_I(7cEޏ ?,mX'׻.uZHHuo #ؘ,i|jG#,y͏;kt`пZp)&ALl@ ,("U&xOEvPQk,ͤ;jZg^3S-n);n`ZF )d$`!avu#'[ΨN&"dA0Xgz(y~YhX)/ >"w(`b:J,1DG; "*)Cini YS uQsHw]L*~8ЪJҁ#Ym&rjS⳰sP(Fz@[U%*mZ@N6P'UDqO3fp߆vxl2E?ˊewmCA㠣T3xe2 X]Xp- 0+=rmXMe.4:Cgɣ1sb'^2 ^BSs^ >8Iuz)f W)`scRP|0׎r#%E.)}W鸓u}a*vw]J7l>_*0(&@jsuT2z;W‚.ŐK^݆ {u+^jz·UHwB>H2)eU6i "b v NU,ճ -t57z! ߕ00CX ?KT H!4{L]e] a>|pw͌i^{efMyQ.tyZ $4QbkifZ hZ8jL5= P` ϽBק 5R@V y ; *FlZđ%,"SvM٣445*RM2j?^=aB^iMWuG9j:*pE'8XK,A MӀZZeN4'CⰇoeB[)Dr^_$W>dڄ*QkGK+ !wհdAH@t^ Mx뀋JܨR҉ 0CV㽨R* _œxT^E5Eyeh—Žң@KΤq~n#SqX᳞^JP5G7EfkeC"l7ɕxn'KXBUC8B<Ԩ 7tӷLg<@ҝ|;}Ywq& C05,gBV(f?Iq.w҇@@AСz:iC{wx5Ǘ#͖a߂"DvH;vnʼnKW#a'ʑk1"1S&z(ͥ !ٵJӦF">}Dܗ@xb{jPZ:?Ou,>= t))=p:PJڟ7" U dDܒ|fdh"RX 30F82%P oDQ Y|k`f"ַ {g=.RYi𛉎9a BC~ =n!Q߷њ"(jt XIS74((׻ѫA3/\>/t  vSx[ꓻM?hתMW$)Sqcr+IgUdURb1( pg`P33 K |͘MyzUqkYZņ#VLphJrFC V@z1 =S)fPHgt_\$YΝQC[w˾{TY'& Zf{mjV5ҨFʥ1="b)ª|$cq5#H'J˭yOr4Bػ:_K꠴Qir’Jg5Dz 1i4,xH^w.5U8ºfu䋆 ׎*k*&Oƍy`G%AAP٩#M-d>)h9<8)zT0E$)WN_snnG]vYK{/xńV%x}I1]mmPQ_#<\īl8Sc`^鉓vX~F8P8D$e];V&L"-ʯ 2l]xC"5*<'B5Lt:zhmq_2N_{VA#’V@fbG+b ޝqxMRU)子:ND%4 )x} k[Df{VhHH)2I⫊l! h\kx[Z]iz͜ŐTHK<_aYt,JMa6U J _8 qog2"sVգr "[>C^pL?]// tX8+{Sі0(ɂ!a$!I."sGEBȠfep>FM*E $nQ+;#̯2$q,oǃDht~ "&!<:1 )S:ڪWWHbFR{Juд$:AYو>zZ$\?cږ2ܿ"wP&>[0y&:]]{;]4B@9ȟ g^ug$J$-1̄P.[֎}Te*+7ŴH9a"Cq5,N&?u|o%˸M꣠ŠG_twHl>=-w#37n{*AGGNK_{yJ N6iM$antk9qIlJ`wR*'RMouHQ({Z tJjvV醖x|jInPM惓֋g<R zW~uvLP!.p(E$-F!o(W^WC%MqD%bڄ7N:>A$I7T⁑MH2H*;r`兒{ e U1]A`ߚh33@ZM4X#%_e|$sf˥?Ą+(R- [Njp] iNԏpDVJy H ƥ$댔f{hc.0u?+.x6Fpu;vAs\)_m*^"AFҋ`v,qQP\0^P!o*Kcfh'ZӇ(l%v>l[]_g^y /8XjYdwa,s745F)RMɍS+j#GyB~A۠ݣ(9W،LXD<܍hK,3rf9m)FݫfaR7%i(P#j _-_9Q^%p+>QZXj@ ՎlqL.T,~>"YkCJSIr{ːU>URX]&0iL@s-ˡЈ,7V3D~A}DU8L8mmgˀ/#OgY?' "aYH@AytLN ԖZ G 6i~,g[C16x1KOl k]k1K#k')-.TާZFo`2񏖄;07M q-qL"ވapTvQճ)zc/ ߶aL}˚Ww硽ㇾW}Hg98܍ զS @-{5է(23QaJ7?nQCl^IMVzJsG®bQY}c2˰/17\&TO8vL//A֋W!y1#>PlԲ#0_F^v ='tX>mϭlە^ɱQ:Edu V'u sxhXAt S<|ͻ;LM&\Xm5z kW;d 6g;90V&R<مs2U$_t+LŠߎ*iu|{] u TYIJ0hEh W0aep /)JJBgٽo #84ԷNolr}4aۏٟ2d\^3gA0hL">JL o5Jeű+/UZ T_Iܓc;# 9d5>h7g$Q-nh/:'LZa=BI\=}`ϩz31-.dNbWK,RIeb- s}fޠFݣ ݻDlN'⾸ b:20Mo~>նBHePO- &$1N<8FUz<q&1 uBKCyy]IYD,KԿnbp-1Ŧ<ՐI3*. &}+mc=A3'NQtANkf'Y;bUe|/}=Pin֖@#'\2xoTK]&H~Iވ1lE\#[lK0{ }1Ӳ/-D*5lvj8ݠ).?w9d<6{dSH}q8ģ]lqs~X?pŕi?J,8x]3!W-ɡ[e,ܬ-$ m-c?`:KtYELD]? ~VA7޿[Z J #]ЙҒGDYa]MMMeI֬Qu0{^CDt4;/b$-BWوS?"%.2)j3lBՆ`8@e+w]]|| >`W,?LD7J \uߖIqh*„(HV H<6Y;KB \}d+2kwHvUq^e68>4{˭Jj>.6^ I6S |US0%A"4Y*1peamKșUGb F[vBx{Mß[ l9w,/9Mԇɛ4'w~_΀y1vLt_@خGۥS>gܑRFX#EhjsQ4ΏϊrNOx<!:{g{ Q8_PR:;1Шiaud/m|&PHk1ZٝqN(HG֢h$b3 :8i®Kk4g$fMG< v/4!@>=QN7)r+;e]U Txy^?=?=fGGXjbH;@]PBǺBKo'5%7]>N SO FѲҎ =[ۖ գhq4^Cț{adц^orsb[]ABI =~u Lz; qJ7`RꔇOd;Ռ"nRk) *JaJ^x٧ C멐 \ ia܎Bº/׊F*"nulVJZ+mTԻEK~M ?oI!'܅r:8$;)Go _iَng8Z[ڪLSs82dT{V0UgD^KķX褈 CEjƓ,_3(8ĂYqJz =lP W{nhaJ͚®IZ@YL ] Vui6˒67{`ȫF#ƽ(ˊ ]o(v ad$#ߍИ]k}: 7{pJWM))lԯs)^ w0C~dȓl|94Lx7Buhr%v:bıemn܊멂&fHBpj¯0,e4#Z峙jUbizf^h%`ʟ?N+jkḃLu4wr dVJaGA"LR_t; u cl'Uc@ږf+ s1Hs$Lwج_Hz-T,`E'TMxT9u5s uhK$R0-gczGBT2qVa(D6_hcMӹl|0'Vt.[+HXE)a :5T@tkv\l,$-zJMӪ#[O\ˮKJIV**Α FT\|]\k^`0X3x=MezϺw pm,3Lp7Ք37fj:=t~ Tz ޴Fd}V}JpEG%I¿ G͡4[Z0H lmǻlt! 0^=B_mh "E0];bD%)S ?{\cgSny0z N5%I2s m9IT, R+PX* n@] VknG R4  ^-Ps).POVzL5%X|" *ylv'g'|$=傳GeWN 'ga%Z%6VnaY~32|3i*`Ud SeXC گe["ʙ@@U7|Q @bWŒ~!nQC9jo9uqؗsv ÄP3Qx%9icjQެ I~װ3SM@_\4غ ?-69*Lot \jW8P孈h1K< 9S fP9/3BXM:m67 }8 /Leuas"S5(u*] {ضT#>wMdgjgޥ˫ʳGE؍URKn4Y;6i3u*4),HtuQ9ߋ0#;5讔)s5v>#MZ bSL*6tgQ';H2sC?E橎kbVoDXx\Q^YC.teX:ӵ-m=tk.M9# Dyw[j.xܺWEVNn ;xNpj3%)B'T*DYwK}:U \;;<劂*o!`}u$Inb e4#n0}gI0_d]&ӇfRK{7U5mz,d!CZX8 SWZcmy|[(e!I`0-`jY**fS !s0 Mf;kj$,.̧v {y&/֫}ْ=g_W oj(ۚ9yO;{@OئPF)ƴ/Xy(LVIܹ4ޢ/u`xP ^zsKߛߗf4:f7\%7aYP@>~lGM 7)xگ8 W܏/۫_߀q!AƁN4xjʋ/tGuϺ'=N;}=rl;=jr|)D8ٳ&bYК+VXCJw%ʉ)mϩφ##j`EiGe._1zЬ U%oOVMr6aDqPJͯήnm_ßSq"W#Fk]畿`QK7JJD q-;MNP)wi(FQA=: 搢7=y",'du=įiۿG 0%%Pk-' 'X{6>fGIei|Vu4X !3؏(2PRD ҁ[(BsEkE^&_{p)UB`tku򮊜m2n Fe"^#:_Z/#b+EYwy.Jިjms69v Qj}[:גO/ߺf> evmh*D<#g`7\m?e-yQ)Pxl=3E{Xd- QU-NeNTz8K0V&W-#yo!Д^K*7D g '*qR:$r XOt*=Q#Y,N_gqh&@ mUdy?z>W"nm1 9\~IDHȎ: _>fl*=8M=H:SX\I @=f+m$q}sP&=‘Xg<й@vTihPn RҼ6}aJiW\0`4 UH]d/;B-xyrq:To]8: ӣqjN9Ed^pFQjgO(_֐wlUg5JͰzɗVT %)֫)aoPDSjJƝZ'LsAסoqk= {ܴPZUbwY&l]r!_h<2k‰i,o&QA(ѕŀ!by܊-BiMc2<qJZo6I/#WșP@<PZ,%=8B}R Ҥ<1  v"! VYhA-@PB w FəL*N?'^MQ-0viKzt%@Cx\&@Hh+Z9jy'xiRݙXKlX&LPs!:-Z[w<7nrgv w T攄k($ˏHV/i1@~J%8ŹW3LRsWX`iRJ[Xۥ)ܟ}aR4~<8'5\>Z]-+1Y$}m*C2:o>83`w bk嬶b:[*'({^z =WȎ$S>O]f1U6jўoX; VěNpW ZIڀ';eYfjf>6)f`cr,M}5tGs'¡Þ[$%֥޽6ުO)lfۄI3x8b+e% ρy:G=&(iְl6r.77C~D Von#Kpri<~7: LP\J+m{OE45q \A:A >`U+&cchKUPq_g6OGÆ(1A ֤Z+R)4_h{CUNg{~ġPyUyY ?bNbB-[ښGc,qY2#tȡp{jje_jդ̜lq~c_Qyb`pĔp_!5V-ߺJsn #~ LLOpTMM2Nܓ7@&N8Jk.Tt,"% pKZ=1/uemC'-#D0:-)ww oKQ^ZFp7 N58Δ47jڷvR%fb\ EO9"1{w:4p tPQx:p1֕c ̀HNDͱ,`Fh{)*&$5ob)}3?0+5)m܈iَ1hC Ely^@4+JG#HDO5I >VӞU.y(ٯu19 ;TYKfbO*&^6M-f<4|f:(A0'&aYMH!8N\[iֆAb43ĴA>֎#mtήƃ6Z'M(C*?A %+;Z{ha7ا6\22QV]U{^"]oA;HOK`::2Ϧ8ۚ/J8dfIWkS߰닑 MDEII:eLO70eF΍BZY"SOǬTiŌv#ޮֳ!e{&A2_QV_J_̓ዷ{kyw[\V_0Zu;,[ I[ض;&jE)WwĠXHD0sV }P64afwFcrj2.+W.j <)[\LR$3"K@oj_©W.s]7ҌTe^{F[L>voev,e +x*֞֘UXucֿ)~Z= 5ihIeAشo,vQ/\r/ZxsO9^DkVVJ;Ƚ/R)h{! u϶"o%~q_,` `G%l"TE`cX` ݬ/خ)w@5ܣ4un6"e-u+Dd -ԥz 7j=טP|_\2mvsƊiswōVͅxt&&R?:F_#=M{ݛ uFNT,"ƀ\ϳEb!Mpoǽ+DSXk)ZPd~!n[Exwjc'\Wd#>E+GdvwhѾ.Pq`>mkmʏ@nuާ~z&/eKth070n̜Q]<#m!080$ m$_*{bp\!QM#t ŽaϢO=fՏ/ҎGIol)-0 {']Y}TV{9nO\<ŝh5'Rjx1=4H%aǖoo*!]>,:_Lr85"KR ,}r{BBZh3UgiF>yS!j{v8\XV?oܫ cdٍ=qImk|*D "CV*FB89g]qbrâ3?q8.pA *an-H gcҞmE*#VGSۍ]qНTGt0 o˾GJN[ _ 23_䟾ڨRuxsTQ0o?S"4uP~_ Ă{~N2hުHqXAanm٢w m$l|gd,[ǂaڸoCjH[,zɠ<1`rrR6M@}-q]Y0Ɩ(!uԱ:Dr%d.%K: r+{0?&ݕ8,gNShY"7LjՁNp6l|-և)O vPMKlkGmO cеސH֜j][S.OP8 z`}U.\ J3ӷe[>nўj| 5n3lYqP xN+gY2 ?C%ѕ.W8(.N1F6/cb{"$3~LCCA?hxϩӐ2ÀӐ7L|t{Y,|ǐX 74M*d:K#&5xs)ĖЕthE 8aȓphBysbt%vRVp[a2 dTNSk+"m&Qi S<W`D |sȷ cԍX-nUGax7醨sEh' ,c^+~7 1)jen_V$)lCNkSDᅿ5![p%8r0rz2Ms;piXZ!!rQO(؄S52綵bIϕD=54Ao 5ދTdQg\Q=b$uVl<D4F%U]~{ZzVɏRV(Cكg~# PʴuYOċ4s#;̹ٳ'GBڌ풢l=ed,͚Ng+5%)"'Wg3Pu*S)x8wN2&P84s͸yֳ%zQ-aW˴7*D⽗8;/Juc`.j$us0##QFE ٍ'1楞\AYm Fo)RZEu+ L޼+y޲@R6gxf./g3rv"^VC9hIyZiL5.u TŬ9*ztr,="[h<7C>W5]MaŅIBʣ4$*dž 3DQZq%FO-aZzszW(f֝40ԂӍ6s^…b];.}|IɦI"C:_Jo Mu翉%MSJDQ#Ɨc1}ϱ{N5I%f6Cikkq c~^GPh]*TRNu!EA,=> o.Trr b N QelJ({`#t1z=Ծp:Ұ7r[[Pӎ2fQ wWSAJiЖTi?ڤ8rtvϗ>џu4P,`X 5jtKP.oj 1\'d~*5➒OA)ox lLOB/ R(8[k@vlQR%u F|vvRUGWA/$U Ak:gq8J\0wYO6<BB#ZWǀ`xarH-V Fqgu?vă<2-]?}V8tr,es`CW!Y,&t ƒz@T;\ůb6&Rg9}4d^C8VKD^Ha/:%Cl͸X/ 3A(tg++[r5(ݵNᱏLQK~Us77Id(,9ep~]'fK|P׿.E!ڬb YqOubivW"4^n9WCs2&-mk'=5|3a:,Vn_zFɗ@`BhT& tνG'%;-c /{#kkHJ s[:.Diak:_E41?{։"?uДUdJ7Ut_ȣ>~3jE\7Ԥ^㐪{qJpUBp=#p9=Z ifuPJ%YU QwiV1\%O(g%٘4.Rv~ -n[Ai}p&Lܣۊ%G5aPxOuzȩ$f4:[7@NC풝^eEԤk{,ĥx҂+{Cc &?&kbcF Slp`ɍa{YRct Z11Qxmè=Ѽ3mWP*s0eOxy,ǣr8g\ (",aif="?O̤FLu)j94aɐk^ 3FIՂ/ DIp d4)J{(Ϊ`.ґ԰}He[jy>)ݫR\'w) vUٲa3&;Zm'rOLĴ}%I#FnJ(0oo /KHUQͽ{2.POhCrge/%Qn__yxjr&񴅑|ԙj7(wV:*XhNRMvΔt+U`>z-ia7 ;cztEw^Hq-|*'╀|EEʎ_Kj30CsRh/Wd곬֬n ?au 9^VjOK#@1Op¶׏SF_/>,.\8G tZ{c%UugPB<1|(GRP˚&kD[)f lBqj$Q/dL6[!fkɢ!Iw emi;37!̥񘣈ˎ23qQ #[1"k \I#$+*s < 9)yȤY/jf]ㄎ*="}r[LRPeK3yl6K87AM(Yt^a䭓z J ]̊|bU0s5Cܸs660)HGJ!?+8XMD]ja,Rs;2r=&N3o( 2y! ," {x #Yq$T?ٮkmc&A~*v dD DKx0hˉ.nnx/_培cqub^Bǀ+L[z;BA9? ^(CK#O\8E>9/0ҋ(-T,iK.FM'+dTիo/ ݂k-(F454d5} Y3.s`~0IfiA ۙ?g$a06 Wz`PքEIغ*"\i(C}?ᘄ|j'B+ejnl+S V;#CϤqRr0 ?AX-275eFou݌B׈*- |O ط?U [zwOK ęW@S_'Y?zE7VemQk1 ΪI43Ž"0;…\IMȆt{s!s_ pϽ>{Rn:Kh41|'=-Y)ibvI}l#Z>4j;Y4}+8,]n*J'f&gg_5 1Eɬ`[>bn~:>4+* Bٳ5!&K'S:ԚJ!"齃;Itr(hJD#_ UoBukiIQ~H@A=T|H龌O<4f=lJ>d Ygb}uqca~c,∶F(X0V% Ίd X8Nl!e<1 62%eՈuv$fZ[;]cÍТd˫LC\J~js$ `֣9#swسP:A *6ye" v΂>Na0^>zt\X|&\g)8h,wHv:.iK&u PƵ@T ßň,Y5j0dd=ŝAFOq,y;(|bz-#ejAtL%jq|k=C!.s $_q?(%몿sTD+! x_PòV܉6`]_ ~H.znbr[ֽMLB:\=@!spތ?v]t!ۻ8H{U7T*zv%W#WөrmOBP&/1n~ 5!˄>ƾoVPLDLR!nRCzİޝ]Cl>L!˻jc`z?nMa XǙ uٔZlHP.LܝN\=Z yIo-Q@KTHTDü)crB%7#:fS[402(\eyK.:,$r"S}q'vw*,dh*+%2VV2zӬ5P\81f a9H#Eoٞ󁭩5>E<=ybr&?$m"," vhiwe{Hr=y DY$ާ<=2 404}YQ6L~-Vi6 0amaW5Ti6BMC2[f%'`ٹ~8F1Ok`"cr! 5hЯ12 L-ŋLE蘸#KvX})aj.JeEkc0͕%#auũfx5\'yrh}6aBH+DiCNҿFI/CFiN"gM bF.k)we@됼YAB+ތ@8ge:Nq pFm+r% Uk!*H}6M0m!BUPDIm+F֜vqQM8i,7HY&C⣻RHXXE<#MCpTh2 |Rs1Өfu5mk0O(~_1X7o aQ;k<_ZIcdWaS~o?*6}\^{3ڡI G .={d{XE(!5vbk0;XYj4mĴg%`S쨄g%ڊ׭|YE@QZcM&c-_)*V!疭U;W)y9)|rwEgtf{uqvSxtϮߗ724׼stPBMӟN&k+ fPo̽3zQw]+S|rw1oWu,w~AD[>e]F (A|+ h"܍`6Q4u` 4q+ꀰ_-Xnv~ϸ(eLA7_\t۔rI5QޕsώY?Zx>hǢ+q[-[ +Y`EN0:KFat{M_yC](MC]ʼP &O]\[oͅOu히͕$ Nv&Dfd䔊Zκ+S|($f7KfC1l3'#Ì {O:7{ /yykh}Vq}%J$$l߁!)ȸt^`  \r9 MM/,U2䈈9p"rA sg1a ; vZD$~' 1 [=yr%Ls[raVT{[m͐Vф'W_ڋ7dm @|LħM $expjv5Ƿ0sP0;F$x^ ȹԶglkڱ.LSXs n#C['Jvl ggAXMR-%ô")qmlU`jb$E.R;ԑH cW]:_;-˜ ebGĈՁ_4zy9 .`$|"~%ꋲﳌ5Km  g䝰ӹO/yŸcvyX>F#$h2~{v-V@u/Lͯk p&iFc9oj9g8 O﹅k\ WcQ ƕQ,z W>p`k@11q-$C]}FK\TK[|Q.!i9m&ޱ#)O"ߘY*q1KSܬ]Eyd4zt M-ɻ=zg|?DK)"1-ek8ԉWW<'-z"lmy'.kÕ}U$,& FF}[>@xo.5γVqy>S;7^cyoVQ؊p :{#SiB{x./t%m91TpɈk$U~YW)6Nz*5$wf7l3v<䔾CMQ.}A2Q#>XCq?,D q`U/CX*fJBW*,L:2i_rV"=RJ8El|U5rxۺw)L1UgrDD#U\q8]AnD08)Oڲ&Ӊ0ώRn<0]m_͏i¹!.Xr'֔V+|f$: J 䭗-/0C2ޮQ)1^=ǹUeq6AicO@u} Y"8Y!%Gm˨ƅIri5Ts-1R&6$NTqƯ-۵z|/֯Y~ z0RhM[8} LKa@Be:ΫG\Ԍ޳pk3Jq;RV*rihKuqe\:""""h,vm;+%X^c;$YQ:[Ͷ |Mh ]02^Cul1p-:P/vqY{[+*ؑ|݋3]<脘" !uKXp[alwNf8?G2.ԇhǤ(q,ݮKgh3vǾBe-lG/5g,a)w}Ȱ ߹=$dU6l/L3<}EI5〮 '~b(#H IOT3Qf!$G8^0nMм{DvLJcy%S+(zj(_97K|4C M>jO(mLlxj~o Bsv; 8*A $aHjQvdC$#*`-33> b饏eLfKxzkC#D C-]ȈL2UfL ZW'΢8ƀI ` NU"$^&Jc BNǙ|h'wYi P1>q2:;8e {2D>d/{-W\ƪ-b Y{qd6|qutc [Y="-(_CIOWՐ05TF( 0X o *돹:G7cĝh^KPH2tLF*mvˆdsw?aш ϣ9 x=9:Ίd-L"acy-0VAh@* }ai_2)1DUZdߵ4ן'˅c_xp c%\ƛKW^痋<_m`gκ>hRPwuZA;,^P~4k@-kLWPHj.Y[d՘seD_r8T! ?#vg./erv eг:wW]JӬGկ1՘WO"#8BBGR5ŭE<;.S9WAF#ĺR%ڊ !hU"TҗٱqNz B1}(˸Om|H6TñZO/B҉*5w &0kq^9?'<0\^G%7iΤw RӨ*-/k __is1rsӻŞH*5q:a1wsNPlvYwE+1 (*!u3R$ܡjNP`V4pPT)ٲ_\c"hȊJG1d;SM31mV"vuR^"¤''6[y|AIMRPKl"F&188 VRj6t.GSLA*V FP\ ;3 bkhJʹSRw')S{ x@CtV! o%mml-X#5O)+&L]cl"[󵮙]?ujnu (K c&TiCd,i$Q7cl8Ќe{(!*cO!jc={/ϴb}m9q#GͬH;ֿ;8oZlg?=a4zBWzgw6A^i]_uz!P+L"$z;3rTqn.RV`uݞR|'b8XeSb?$NZ]&f/q۴"4ǎ"zP;O9$*ġpUuξ-`ޡV(hGΟwNN X{dvaH1,_l CHRFٸ2t'x῿4So{`/(RknQ8qu8zE o)>۟$_socHy/}SQA t]{wq1=r۟FK?~*3jtIY>m q7宷;gcy+M͠1/"H@3[pݔ4:$a'4ųI$HEt y 7e4[r`13B)bz#eho$ij^Ogs}NNd.-wl9!&`rB~g}__Q< 宐ݩk纥J6r~X1ARGcFm~V#{c0WCynzbㆶ~x.M_Hj ɟpn-.MorȄ7ۑK>ՐlKJskOCP dQ%j|/?v_S Hio^@̡ )- C)[wE[F+Qn4{MlJl"g\7fyLHy &bNk{_}ҵ*ad9u-!6#,e4 i <{oۏwRwZ2f$-b ^9)i+?vx=%Q2{V0*Rcݶ;V`f}hben"PhOX 1aR$n>=mb`iB#Bgo3ǿ2 1_~s%$u#V:#[He-`#c7yVZJi]IPTR71#SV\w 9NGN>ȵV 916)QE& :ߝ: (vAc>^uV?U 4-+7WZ!)`Pxv™Z͌w 'z?Vt"*d,'k;f., X1S~XzLԃY0)ـ$Lw} 1+%PV)FQ$кgVjEĤo)n58J3M]=|Q3Sr)Թ p Kv/=AjHKÜTW"=feEtc^'p!Z@cӑsEZ2|1}{}1 ,^? ""4L/VЕ14{&oƂÎŃm- 8.@#m;vJ`LI2齳sYSUQ h w{`<F$sV! ={1s1Ԑ}^@T {ܫ o2噪#U%vn^3?jAlJnCWQRmenM2 @ns{"oVRGq<]J%$Y(4KH:ݘl?.[T`<]bNa1x=J48%q4t wK+L )E!Oh&E<(;fȩ.;Lw?ymtݳ+GR hCɚ3:ȚoW.>iTP[W۝\ nۤ{~wnB7KL +M.0 jkr(ߝQBM@puELG%TVxAodHdϛ*yl#%laH qFG dc3nI4&<]OE~e3|``TDJ*:Zi6?Q/eT4URDK%iԨPQ9ވBܰ<>c4&wy 2Ei~DzorFp(wjؙUsYucq+ Xj^y`Iͬ_`;5wr5 Yq[Y'uLzN Hy{&_KǾ~A1*FE< ^EԘÂ[8!8EfzD5|CR\,CfFfk/Au.sBDrrX_6աǎ'@xsɒqSz oh4v-l(}=KYu?Db̾{?DMRnDXEKҼh"/(C~2I)QwvXa'B}ud$c\qρuWVH%c9enD987znw@~C2MJQQ2_]&C5 %vetӝJJfb  ɮzw_պϴguPB7,iSHcYqU{@gNƈ DʸݼDl.^ci>?CA(Cr |t[6g8X>Rs̽sqÙb#f 3@#B ,.f +XPBȰ4SL.{bq-87Md\!ߢHe1n/.Lt+ia3E॔@ގDN:bɶbP_Cl}>yf[91kH\JLSA>u$I`D\I9!gSa^򊃚)LJXŊ[%$0gt@5$ƛJHS_++V;~w+lPDd{13F#M/S;)z w%7Nr&|LQ$^Yhh`M/dsA->> G-u81*rM TM,eh1">2`pAa'zU nF2}$N{j!V2s:1!S~#Ӣɹ\ 1 CHD5%w켵Ɖ>Ѷ1unTsd"|(a"Ē6U?hS4P-2/C֑(b5_%LE傼q>8qA'jtE} 1+AѰvd&< lr {e7ڭ ǖEf#O8۩ռX%a=(oE?zj>0TU$ɂTz|7Slq"zqzuhx= +%o3~+bW fi?wr1F96.G9dsgŞ􉢢ZR%-G Pfʎ>!mH: 35SGإ^ÒC[Q'΂1-'JLjHMqg Q< sQn6?O 9'3IG|&,O._ c-pHޟK({ ԧjp+G쫛`1 9{c?jO*9)r5 .(_ͨd9M[GL hnr~.7ؓUfyڌdU;XhS_HkKj:@PG߰)Rω٭ޠd m<3;-M1 a:̂n- |TBJ(jƄVĸFXaG1Wbr:#%QԌ*vHm)+`GnVrKDU6iXu 640t_]r|H\Z j먕PX/q\;b%pWޭ~loy.j!a\+W= hk~Xݠ$[ /vӇfb p&ˌS1g.W0T#f?M  z Ѯ,Bm^- l6a 'rMxgoEZܡPefq6B*##AOw-ox@ƤMI@LIF{rg?Nbվ`L]f3Aqf!uߎ '&T5g 1d*v2zb5rYgEMs>.'d؋QqAys f[(?{i!v'zKVch/4 2FZ))66Rid`cExw%28B)N YM> t;.,J @;v~32 !#ERS{bjIgupDna=+"klOSGB]1d-vi q`Rw[>\]!ETtK@Op[CAh&ٔ䢜(R(UFrx)`ZltPnYP*fi#߾drZtƯ R(FHBzQIdd~dU¶1\U#}HS1ʠXԧx PdKMR:-W$kiQ,ۧ,?e_xq+Qχfc&{Dz(xe mn!!6,V}!@R -!Tfq97N^;ؒϻ%_PU-;2MK6v4o O#s%醍~I%7MсWbq\\VY$B9F)kF>_#COq< ֬GsLI/}Q-3#.O#/LBq l3)? k54QPfls4nRLz6^@a{&n4G!GgNn-aPGy#7ӑ4dP^=}[=8!<AƏEJN|nh{Fa+fM>RyMXI~&4X! s^Ly+>l78 ?ؿYc3 gY XiIL92d0 I>($1tGFɆ3fuR6۸'\Yź>';2t$oT]bY:agbY܁SE:}͔TE^{ZwaFJK~MZ@"d{W<'vxӗfpKZ0%J ~۽>#̂1>Bu .+桬@g(?zlc$?(vF%|{3V갥(O]D,65%j]W#hdvZ 4cQh`^#K!8U=> +C_@n&*蚪Em|rsVP,TB0^e_/C_Ol(*ޠm0DHX9۔Y7ډu̔( "R04a`yĆY/~%%(lk9z]ƴzrXEܢ^;l|X(VƆ˲1,6R7NjKb|aCYm j?cl/XLݪp\-2K@GL(sҊKY%g"C|9e͠/Nؽ?ƚ$ƽleќ jR\*qOWͅ7+M!Z^7-(NŧAقњ— >Whcpr"|oPݶ-4Se~}R\n9nntzV%e5 sV~Jl_)Ϛ&-<(mbc{_o aR}uAGVu:Of2Κ~>Hlobg]h2t2=w"˛FXhHaMMGZƙGe??x{즟z"Ao:8;EE6DieH3y'E/d2 .kzqi(N]9gGwGbVZw U%gVCpuޕs$ƝsШU׃7RQ&i"HO2;/ qB;AAwT5ٱs25Wg dOV*P.@R֘"! Uԑq6cdVE.Y.xC@&&DO&^ g^̷%ZMV|)#X'1[AN|yZ.)j+eI1ⵅb4qYɴ4; ZШ7mkcUV1+Du$V^#Ym+/]`xO;j'&e~)B ,$Gޔ]ޯ?.~b p.պ9we' ـTPIG,)>YWe ݉wE0f զ_@}ZMm0c wM@X! A3P>&_9[|Mo)Wt ՞xG SnMxRR߾"eع_H([g_VA;MIj:.| Jf .S7yM+.ZjNq&+2+~q3 n @z2ic绫*"վ D A+7_+q blqɻruS?Z F7J.CYg D sk idȒave Ce)wMV AovTT6Ks/q 'qPbW:'l,wK_ceA4F7qlbYĽVT$<$=U"\G7z!BEEqߤ0\-1ay, `O8I%%=%y&|rTMB&?K7+@'fy/6jܚqh¢DoA*"ȲjE1Cp]BY]tⰺ8N@UDD"{9,2bȦ@`ܱٖLlycb)m\^):gЊ*?vg(^ mo^ᯁVP+ú?pKoPޝ iѓH/ U[6qxMèOB 3Gfě#= Ó-jZ}Ac7F ۰^Fڻv NCAJwqTsp[[]9X` {vxЈr>85PMu>eH`V vm;|ͯU/{{|~ᘐ F;U;ߜ@s?$6NS7PlUrf}ց'|1<Ǫx>C(340r(Oh@:%$sŔ#$دԩbךvj٢K`yZO>v|W;pH@˶+F )mƯ |Boj8JjwLXK~lKB~ReqQPC ppuI\o+q ԥ PpSK8W$pd4X^]*wwF3]J #mk61i)Ήb1 O)6i~L]&4h IV =F:y[LqPh8a}BGzm$rmDO&*}[dF|q|iDСnsgQ9'v8d?[KJM?׃_GVΛN@7? &P u)Tm=tdڄWk u5sdaNmb=5+AB)Ū/L^70Ho3%_>(縣03JO:g}> b{k| X_ǻb/"(903*2μ7gt>)$_Pa^BOۚꦙl2RjLPFR4TQGC9Oܲ۵7~} \QlϷW&vD@"z?#d 2{?hpN#tPUfx!k0rRŢ@,eRj%?<\RJl,2"f3߼i~0 a7㸚EIi\xAJ)x`15t8"yBGd[~Zd#eڳèm^p Y.w{NFeU-O?0C-/lL.0>h~*sH٣G09Hk1{Szhl]',;H5٬Z;]n@|;~4QF\|k*,$9O̶wҩjƘ ܵ g_a#_񪠥"cEyx '\}Z5fA~ÎҽEBM UD%( ;y6jsOm&Ȱh{^9Mݙz_iPA˄P&?ʆf"hҍr Fw6=8ڹ*NE nWqnžʰ^.2jO _UU#7 9VM CX+sa $K,RN]|{f`y b8n﫠O+j^y,4^x( .cug"u<.Jp}ԱWd\᧏3| h@n$-*Z 綤3Q'$mD*W@5!dh:H&>賖c"-/ ƛnf!r*)?_C#A[^-JC◫7Q1nglћ~#HӐhPKue*r ^03 oa_}۰'۝UD3O'Ww ϔn)Io%b'I5pP^:#I>|$w$KPcO3A٩vp{BO6D%vy(8" /oer =q* [ӹhGfWu[%(z~vLkt߈7g$.1B ÞD)o,ҋhLv#elgx]sW"c_"Ȳ~OQi`Ăt헰I]o pt,V13 6I[LX'si.g?|!2نdT_4>n'r %$O(ڠӀ vZ,/!g|lG!D5ݡhjք$Ze[ ȯ8\K#,hJ X"Q|wȰoL.~eP%)\q6zc%%Ll!#60GDunC!Xwg>HK%_:xQR|+rYC+l(W0pkdnj^ba:H(UgH%ihFWyq^hZE}ݱƖr/.j>Yd!i`tTM` a%0ROymڛC\k\sA=^G%AV|D+9wF 1\sI7Х`ODdY9; 8N\eg <rݰUۛ c~Ho}Ⱥ\Fٝm bq{:vrVR d^iJs34&r(IpCxQ"ZݢWZjPCi x$e)tjٙpj6t Hv8U^3׆T:є9i8yǬcK F~/l"D|wB]xAM_Cj\{mΨo"K$H/d#^.!/t 4]XL Q'c5eh30t;+HQ(ʽl*]x8cOACb`u7"h#dyGkN>ߤO]rNO#~W D@4wԹSEP5qJr'x| {yBE'0 zj0[̏aԼ#햞' Vgk[4 J&(PV.}3ע) n.PYu-7ȁT3鼭'w'X,*4.'RARw~yR=H֌C OIqrPQꦪA,V$7JjTDH/"}hv<2F>e?"KݝgiWEZqX/*rYǠf_yEcxgȾwTR$Z:7ckqU@@3;;+vh!xXCNс9W`$B@GjxjYTTW < a/pC47dkTwY2v|dh+)aAX0ͩ"sѭb`E~_ưehbn;7) *yGWD4'ÕͨZ%UbR5M8r^|b=&VH3$$pgEMj.DӿI-+ y1xn7^2.\̞} hߘ}\h5_Kx(^ tHN8xRQb܍0dqC0~.&Nh/|Ժ?#QҵTGG:|;"9CucJ΂O!.fPkKk`Ô%6WjrAՃ5{*a y;Y.7PJ lc}#[{Ʀ _+j4-D>9`taX$!1\v"A+,IcKۇ#i˶3$V\tepXx &eOT>@Bw:睇%N wv}YEY^LS9*$`2÷OkGe3.6GCc?[fȅ{<*o h{lVIH"c1Ŗ肴+5U!Mj)G㙣i%Pڞ*\Wp'Li>]K{cd^>IMc(❬3R?جBʐ1楴=]} 8XBtNy_:_ O8x紀J|=7;QΡ.+7tjU%M.Fj˗G`=l/EsrWtL!#5}+mj2"~D2VxgN iyWe uppBe9OCSl'9 ݉S(N!TQZ a+/OُC03 gӲm{/cm+|1'o!ȰAیS#3s_ŕt_ZHKr MGʓhŷOI RC}&_m\~D:[ '~p)ؔo/>"X)>ʌ<'7l2~8֖ {3}-uln#>0yAbĝ22KE]x C,H϶+^|L΍ 7 żLKimM{uOc< hz} W2mgQv IMR}sWz!⬡%(4'Ƿ`SLR̬wB2 AmzHmuC:˜wC@tȾT<}^ )VrQB(c7{<.2/cY<n#(y| gO(]QV`_4/aF8G䡃Zxt`}q0M'}b&kg{wl RoFLj91hdzM ($3Esx' _˳+];<^B=:i*I@]ٚ' *QYN@u}AJnz>6( )*Pn)k$_ /S<ưe "dKVWd?hUDQ{OW ]{}&(6(<@I ʂ˲!yd)h*Ll%u<eQ R@Ӝ҈\DROSHϘ17 3/SE`\KΎb-/>b/8<^>\1 ;D (I9RkOD^.EcSfC^Zd0AIUT51UK/P60Tji Å̔%C^.}lYx}HIjE=23%Aك!J&d:7pO:oogheCa|'%h칋514l?Zk1R|zT/ hQ :6DNݔf <ӎ laާly5Dw,4fP:]*@~V.)en:̌ 4ڢ{s37iuI3!F 'Uy2ĬRxWGlo@e\NO x7Y6\(ժ]G&eSP|> n vKvd 3(0|Q軽gAe qX <+j7p4} ۋT&>4\4"]8: mSHI[gr 4mtaaov7򮭦m=/B ]p\[})rŠ ll/K)P *H N/1élaOh K(ݨ%wS|ϸH'-ָ aX Rͤ\p?ך7WLn5kԣ>AhcLLC,q 8$ ]4qC?rOjk +@aY{*432e,CEJj{xF>oo&JMG w=.JOȊnУ^fޟʩ/Pot4x0^wvi_E.cIr(;~{׃` (cɳJ>eOw47D?3BQ"<.kVB&)@FQыq q(s2>C&T]P"VpbD2!֢{DU,xS^Xr3ˢmislLҵi/6.j >R 4-C?WW ~^4ؖ׳ʓrb Sy Eh|r|E`HKlU,_녂 VB`Ƽ?-yAF\MJ089qa / Tm{*,|Fv/9 MKB2mNQrS*iiPAcRb #"Xؚ~! F -ͬIC;فx2&DJӟfIi{t 8= rSg]<O>1ѕce/QH]ޏi.d2p`P2hlT-ِs0A^; pg2u8{n#¼l9XV "xIkbj|XG*&G@2aq D|Ltbߤq@oIupm+y-[õ!Kh[R!Kt(ƓO1i% W^4 Gnʝ#ee}~8e o5[Ɋö4E$./XuDM}In\t@?ϬMaI iK CJrZj WJ6OIb*dӬ#9;j`+o.ేfѤK9b5@xAg}<3wbH·ؾmO+k.~3>[K.EtJe~+鷫P5r5}7"5Rǐ㒬@C#kIj4ke6ۛ,;=<JOЅ5fNwJFN'Z_oN g/)E"˥ƀ@`]JT/5lqn#w*LHKuv0;d²JڐDbErdlU K&5wC2]2?lVpݠ}L،mM- (/F;F$7[pP 愙;Kn5sMbO:xle0W*oZu -$Cl넦x9WQg)ZM1z\?B1[ U7JXӃ_V4]jXmQտdLUQG!T zˡSfb0hvdCW_`šb&=VZzYu֔ZG7xǙLpeķ}痮 V}^u[N[̢ \?W0ި%%LXys4!7$V2w(<0F0Qܼ+5K +\a䐍I iS"R4%Sr~^qVԴg5$!i}Sw b'"a5^hkŊ%M1ZyJ"K8m(:򡈌1b=E$ {Y&\;}V$4}@IzSB+ {J)`b}k: *"L9sc0:e|`f_Otm)2 _rK\i503Xʾ)3/{7A;  ]l07GPLzjx斒 \ iN1\<=LGyIcnZ:.ekFNwŷدI?a HНH f 0Z YS6;.Ei+Lsz`nl0s97yS_e_h@ճ-ꐢvGSG.6e ش6w<؋J4Tyx6nb[mj P׬S&,IHƱyh 4d G$z(8πqZ=JG[ "ǧǽکNxzI$6KЋXN2#i\nQA{h!A˾o#-"*+=3, Я7(WV]MIZ_sh/a([+vQB,I;tJna@E䛏>S'-,\F,q!̨rpr (>2&&w#a uS_kN)aizP))x Z4l>@5Ax DS^fL6 oȴ-L'`Y`uy 0>=ŸRQ|iu7J9aʞwp*K;OydH \wJll_ذGbJyu3fvp(7c/Ǹr棨m9llUmhoR3K`Urϥ-w:ooDR)Ќ3o{RyI|#769ﶖFϧ?UhN2(i^EYy|Wv,iQ.nT땣ﲔnNhS-r\CFD!z](3r!P<wK?+ :͂[e/6Ny@!ʀH5?0?\'< CѕI"6VS򵆉/)7EKj?ou;\M]Xߝc`{g*,DGf& wƇ+Yh6謣K4α4$yPIJ@WtXTŮmɷ+4=AB$#I<5fM`o?$6cQOŪh ҷ;l^-\!ԯREڥ?R'ڕ B[gF4٨K?EWr :_;1.ɳAll>}nV/>MsΜ!ύǥ?*Ƞ4@nٸJ/tJ(F!MhhRP'p xc һ 0(xP{Ґ+*f):35w}y@O%żvEW7&zO^ x"HBN?*t7P>G%H*3O>·xvY_nz[{$XEihR:W[~]Gn8ųr,3u`P?ni2Ќt^Pfщ A%"88Lac&}R'1^/*"fQ1 |/9vԒ֨DҒt>5A_ֳȈo_@ƭ~LxN|LtaOSȡ DOW.\=ABDӫ4pEHvڊr}oEnC])(?=nb#ehRꆇJ:oC^fK { ňIa͇AjhQߎIb9y>W)4Zb(fbjIL%-y&RBC.UJn,۷m1HzF?r^0;))9~@AUx"ʒL->RVϽRPAє`ɥM1(MoNu.o1{ DB'5 a+ty|l'u͔ЋYq1%*fp0ehԩҖH¥:/H][U%nmn*&CPs_j.r3SŮ'x'q0[AR'Q2 aR<, ./۹ + ciCƱ od4w ".^?Ne_RA;ՉCBL,JpGeӒxx?޲xKik7-a`j'Ԕu~pڬ 9M P@mڤ;P/׉U卨~j v7|T\%\0x\$ )o!}'^<:~ MH/.[x8d Y>H!q*?tT$C{ܱ6xdž>|,Ս=5 X4q kwKAuMFI/%bWH7%qKA3D[Z~i-`2j̷aީTɆ*gAWS /p_wzᴇ<b4%|e¿16ؔ,! odnX,6 u׭CakwI1SNH\z˕x$4k$X.+VYD\ܷ=n/H(uP$OB||ԼUh(PN&MmiHlUF .ʹeaLLlf]XDF !kf'ȑ6RJ铘w\ T5l` %,s}gq0mIBrvqOƙ1@lcYcGᐼ(i׸zT[S隥9!Lc?f~҅̔KJlOk&eBE;nE@#G9 M-&N"B }t*:%U u.*QɈ&P  gJ;hK^ܽjB HR'k0nz $C+iLR`'`^+;ښw-5 оV#i.8| =gRӱT\%Ыjp<@q蔒y+YVD{]Uc-lr 3FǛc0)J5#BFD#EdFͥu?lI?^GY+2g&wu@SZDƵSjy*"e򩽽RO$ DL$wYF Dߖ|֟L)^Hik >.14 i-po,/]$_ʔLDad/%(Ae +;Ʈ9"'>ӻVs)𬳽23< &44FϢ'œIYkX8 +K\k?:#81Zqv.{q}uoK,Oέr*Jrmz8f7OڦDC"x# Q "θ7.<Y޲arpa~s֞|#ZAK(É9'ހ_>n^ϲ8 \wJCnXlmGr2D߲ZK >G Xcl] G;1Kq)J3;x3} ebJ'⭥wj>xK)vm@۴@' w>mHoJThBS #Z|0swщ' 'W[,W[ݙnmQgdV{Lh eV!`4(ny+E'E%xZ# ǝ#-9jZqM}j;#WH2K޴'~$ p*RV!"蘁FG7PjxW{5z坜M!ʷ<]؈2=* ţ ):y A4aygˏf_wh-Ϧv|vml>Ъi\|N܈\o3^X6L fXۖъFRz,}Q=K(fj4<6fnKN_& %ݔҨ PaVYNUk)g94w* >X^tB'{I|w*T(TQ͊fgrN5ΏOf-3A7][TM4$@hdA1[78BJ-;]bT&V|ENQZdzũے&M[=PvӪD4칡G[ʄR B(%ήSdSMrZp'ݿ`td[.cc̯gcJBR,l=4ox= !Ɗ!nxb : z9AtįHa pNQ>$& H1bɚCsY ܔ*I S|~_أْd+ά=9xtWW^an^I`%8eTVslRdlE G+ݕb4^6+g071Wkݯ)a s4CsY{쾽"2G]JS057ĉ}lTjwBB)^s`qvksgXlDEt@{ dѥ\Tpk@ 6=O>FcJ?lHM`Mky K 7~s~'ٸjޠ ḿP"Q,n⬉Ҁ$w=SrkzTTzi^ϙ C~Tq[;TǤ: VmV/xvz˼ڧe P"6F8Vv՗ y( ;&FU@ Dt1=mL5$h2M\ھJ#=6G1:!5pa38x$hAz͌UnO|pIczhX "\GgyEi¦v=p"Lڅm #Oi*way=l~ImK[.Kpb >}Τz+v ݐANnI;t$\,ߴ 8:>QeT05X}5k D*_&rqҟ_ۛE8N\pƱع|+c鈘Nia*E njqOt߶P?T䩤pSyۓG /kG?`.G.ԵRE 6Bzw@a(z$ i"SO{I8;Oաw4e .И-]ѵ‰\NTG`R\]q+[ Pww.@3 +8AtU+'SBRJ7ϝxyhɐ?MAg ޸m܋3(ZI{9B)MvH¿V~Fqef#ƴ\ɧk@ J J)׿wi{WF<SH'z = ߖoF#FΌ^@P:L|%צZ&UfVGmg-!pn ECajJ\bf9b.(vGU7&ܖWxʹ( {2b:nJzz$'3#Vm&lfq;+'0j& l]uO%Y_#u_}&Ֆ]tm`H*0ӛR:t&a*eA㯎.tp2w~~;6#u\Э΢<̈́шoЙqerOg5c`mk^1ǟ2cmGdHHuby3ϗ}P:ejGRûϖ_/[IN]ySi"- ZVNcx:jLXvsK:l#uia L\"B!#s7UsC_ ;S KC=7gm=;;~B$+ho7ђ9pc^,$\5S+5:(E۟Bǧb/fv ceq?+ѯ J{8ʇAyQס󞢋lž"=E5sf/V x_:{ѡsj祡LT;^̴f52y &[0x)! [ poZ #uݭ#͐FR|[9yRVaݮŀ]eSLb>}@/]B ,'qI1=:&hѢ)p9bMU5`S3B{=ۧ#S/ KD>'U%~2gAk*AKgi'lQ[]Hs4Phq[mTscxWw) B@)}M) (nseL$xtmMtn+AtZRı{l|IVnfպFn#vzzy˖)n2`u'ԐL7-Q RN26`~{rxJ*1*^2ʻ@p8f0ĊH 'y N"H 3Up B73iYdې' \?Ý[fJ}ǃ7x~ \g$!V7Zg+߅']<7(Ix\6b|)V_VOqg (`T%&~?x2t 44YMY'!P W퇄y@%b2crͶ6Y/>'}sߢ*K:;(W|sҐZlC>6,ߴ (:'"jҤ~|Bȝ0 wH'7b;`5gNnK*hJW;@K\Zc[v4iTOXKA*~3xJH}MZY#ilc&T(o^aa $4&;?-eg5Q%K/Q|uuՅEFf™iW~fPG^%ATO-m%9Hw`%xm<|gWqd%;A K͝~ku\VbjWl[ 0qAn)5(RJRc5Qu)G}o^ZGaJXpՖ$B/0y52H, **L$~{\[[d!2N)^!x]DE[tZ)'e,FAYkt~M7=ҋei$͂*x2lfC6mt;rA⭴›03au|obCwlE?2z` ,ʓ }?Ha+֙nJTh 3ЏUP@$OIwn ܳc}!MFN[c:x'^qnb>v1&;rK8CBL+:aSJ꼤`G3#虊> i>{zNi?*ib%B8Aq[%/ (@t h!%DwЈBpA FR`Dd0%$#m ?b`6rnACgf76@XzY8Unn_N?#;$W|{繢UX YQSO3Kݺ$W*;B7ě^^_ͅo'vE 5c]!?Lp ds~-~UM4n؇dtVim4}=0aWiVo{mՔIuRH3D$Q9mXYUSm`h(,q-jՈz2GUtpc0N4{=P?&Pb4\~(&ѢG'ttD  ,aif=d,}%mw@6W=s2(/H$Ҧ[rpC8eN[HXsJ`g1t<G(~ -Co * yh-< ZrF]#R 䁦^8ӓٽ<\@u8结2'fd|ח Wgb2SjVPEh{(!wM|v3*$!6mpi.|vy[wmO#t-RئڲQX=!d-cSw hv(Sf.M4jXgm X^mL#h2S.x7 f|!0{|/,#b *~']`2݁J5/q ǑxV޸brJ4]1MIxO|:BQ hvրg Ԋ ? GM⢠\ ƅ=H͘!W+b_@Ǡ7bݞ :YUxJzi FlkV3վL3dkTr>715ߝ 4`;"'Үj Z%rˎm)]B\YyKI41)diח]! "^i.Jy6;`"| 2M$5`ʪs64d;nsP# p]#1w`UsĦ Lty9A&G0s7{Aq=IY )!! (Rfh~/x tq r9@|u7BXVGzF)T6`L0QCt#c?1tp.1cP.pdIwI=2=cC$|+AF=#M(]Vb2kO6؞ݨ-j3ŸO"e1Pe0& HTx57{R{kE4.{tض]خP)ݺ4i'0ĸ0f_ mYn? }RvF{1rT-֤]U8\[9b9x(vϗ3-· HxH,]˖3NAZmJg[BT>Shj@HLgkϠм6 葻7`iR?x@[ȓa.zXyeGi .<X ?qrU?(Н?~3k;vQby|֦qԑ$ l rCdބ??)!i?GtNuy/oB''n+pPsQ3fdcxOuaBbv0DGFxEŬGS8,x7 aMq^q9@=h\҈hE=_Vͷ,O2ģG.OC 7q우&zG\`yNn65(&UAY? CʂVzsP)GglZol H0-VcZMFBLYt_ a6#Ηk:Wx?(w4_)z#VDY_F@;rsJ!EH5n$H芦U9d#F.PİK]F<2'du9->`xro<P c;آU?U? H( }{]BSژnxp+B]]*JQeuec*]ZyB Jh̏ǀ:+V٠V@?M-bWr~z774΀_OĉH6`!x~Ĭ-~ߑ}ܳ &4B:6˲'̦0`PIvīƊٶ׭gXÝ*w$7. B!?!G"xtrjcuW1NZ:,WS:h< ] z#YC_;S0W7nK>hz hoT2(uz\ǯ/e tz"tB"փ⽜<ճ*_y2ī ЏWI%l_m`\am2NWo!=7tA?&D]s(h.Se3.K ʭK>p)dd7u.X70h>U a<͡iȝnu#124;'.hqԞ{3voW]zSW%iQepZ[@@1#»]uL*JJzoF7#U2ps|ZhLɋk,ԭW=I8’J\0L]fWd@5mΤ)BuOGMVy4r$矠:kf4,8 LCLJ۶r&J&2n!\.GZ=k̜aSS܅#M;vG#J(J;ڈh9]։7oV+Y~ n!x]jE eN}3g3gG֬at>m4s%s2Ʉc2lW9T+М:-j7~rGK r=$(X~5*-Ѣ>AkQӶD1alB EZ1j\\TgWw%T.n$5sb@=$%N>~85^I䀣/A?+Ы9 >)^8;Z` F:Y)W&nlgD1nyI^TB@?-" C! |rzU`_rnRţtM?O S=̚Pb99K#k:m'Dc1Gioh.EyloyqApc/2$qXJH{.֍ fHi׻=D\O;0/{?suqqQz,wvF9~F0;ʎCָIu;}ϚXusI]-N.ts uL!`51;3~{| BLj-!sqIf_gsEwv{әjkkaqi8^)J ;T9wKp;p0hO b ^PcC d=ElE{Ņ UJ+'F=96S!e\jBcYgP!\&!5UE~JpU C]բA죤]͐a^OI}`b>ԩzNкL |In &MD>m~/Om.Gh@n|Q(͘3O*^.*z 8^ ǝwg]r&+8uqp%ٕA/z %tث(V&US3&(>RF]Ool~U<6Ba`xDQ Uٲ![dK/ Ԍ٣Ea9M$IK{b6,'kʸyӛWB-;G*Eҕ e>u^^p]H`p"J IќB3c폪,*^MhnEtƖ`B"[yXXآftAEA>Aa$ګ`d<Vۯwm֨c"KOS;nos/`z=hVY: cr'xidt볮ギWraTyW|f>rymLBn&]kA4X0seI|Y楲TYq H:M:!U:=;q':T1Ux])aNA}a^:ۓ0.JdEz4Lo͐G\VǺVqϹmjpzEsKc7TT?U-?o{ B pCcb8ߊ"csW2Iw :7!,ocJAW-032;j8! G=YCnLK~)4BU#*ݯX Xf%4|φJN.jgxݷr=5ׅ_&oꮲ\Z#5o #!Nb8 ?Z`M+d܃4IF{ޕԲ7hk&2 -Ծhػ<аoAAX|sZ۰^_ڕViB l9b_N9g>=-D?+%N ZXwtm ^sb`[ DZ-7 *z2biǃ 'wxE"ZѷoKY2\ kWQ{{z̲(TP_3|szj_a K(,n]Bni,m$%^M Ϩe\PCgxHU5>S#)Se46XUwW('_2k$0|l"I}Fjt9%$RX;^CO#^ oK*7P xS#ݬVu $x)]JiK {̑vpgf<߸Q%s+@2YR'>TVeʵPf9@z[GEmm稘B+13INvm!cMe;|1y/eS^.Bhh=ķXN01YGwN43I ;9M%by=QLi R^0MGi  '_vHfÊ-jGH¾y%Se3n^Q"IXf>"1B@"rڱ_jBI.f1=?r!kiyXY("gOr%sfn=-ZpYM 7+!W˄Ҧ[Cn@Bbt,SxjRsp,7G|PJιI-_G+v7u6E7x:۽p?W'uo̟2#N>tVοnVd| &(䦶ܴGvS&bN gpfL3|m|F%'Nm:r\8&*59;W^OcTIX-4٭ g<$<Lg{ʈ cvuяCI~U eĤF`@kxe}+l/_mN/ 3bs,MO.?߬Ҏ'h@qaľ %[ɜ{i"`U%@z%3p1o fΘ Pۢ`c9 q5)$gb?`9,b@DEg1)\&aBrR lZ0ek_3+VBSL(¯*w2Ye*/N!~:ꁑ %7ӆO\71{T3{!k%8)Ń gD &TLAwۓ8u帗 =.|($hÐVd;Hpd6W Z^SY!流9:C{A(fU v=sf},csۙ%_;w@M,]:͊k$*HVZ*ߗ Fy!i?; alVBka#/LGIEQ<5۳iG ^ y(76%(0[sC99n$À928߬߃:^պXzCKTLcHP$^+ĵaҹ!_햚Mdq Af_D?[6NEBQHA;}?ʹ(hi5-Fodà"@[ˆ7pJT{|&-f|-贯:$&mIrZhr4Xnw ۼথ&\GY<) ":-j,e-J-, ,Q׳gsyދq_ |11P@ |,C~j+_Zc(ER/*TdJT(˸ O A>&=1ZO4ڽhmMK+w%}gkQ2#[n=bA !4{ qAb΁2ްɓh㧚PZ~vF|c“ʀ0s6XqINvt,K0 fkX+/1ڂoҷ1Qى#hG A2c3e^O-q^ӾTe2 /HoJb/0*J3 #Q2OG WElsm{MӼt?]YG1B TjdRĀmQ 㸁6'JccڀT-gݟTq<`(Cqe~<2O2<̛Ʌu/]24p@\Zv eY:HQl6R$]su DG!>oDz8BWXGb̗WR0d.{Bx3dEZZ3s)[NG^eXR7.[w孶] 0c!gEYz@.tA 2O9 'x$g+j[~XNl4;k_gVQpxp&>_+C3tZRj1g3k5kn6,%9K5vgLxλ@E#{V8<'lMr6J㳋8d7c$iEl?lcC(<{/ c@0-c1n>nha7a0gA?#?͆bD?y$.8Pw7чYl`aMDӢԩ #Ё򆒱+ho @)SD Va1"D:7,hhVϟ } jG\5b]N l eQx1hH'F' /끺?`mr#z+du@K.1^hmji,xL~xV:e[HM.%gш/K1pݗRĬFl#Ox6|Qgrzr%~D'/&Q|{|"FYEKv\"ȒR 栋%K[ُIBݎ2^'[L}$J[GhD@rFAy2oK~| dڵa.j7iqUEmiPk^z=5Yv|랺%b:l5SP"whaQ qF;[O3$#xTCbKOʀOm}ՕKR} :<8v810,yA*[J,4\sp\uD@M(N5_=kDIl ȫ<[:ExdJc_CƖj8lI*%jp탂LFOEjE)*x֏`7lǓr_+P(rҭ[ٮ]ʹYf=Dz7țe KcRM|2ڿƝU Fz+>C~)Cl[x9M)Na#K%jہ =o .uZ=#8΢k*EK+>/9{Hƾ"m<-l?En!O A-Iju8'ΊX]l Sw8MVΒ5} 9KVV$PDD;ƙn[Q,c)'[R~$)ZA3w0%氁fPm!8_> NW3y֬_B1#y[`>no:aTMwaI`K-ϖu/՗7WЪ+z"uaW\K^J,qM)tr%WD atfٷNSo}Y-{g%6{^}PGRAcyqTq[^Hx)q˾igCuOo@wZ $_'T2d/CQ.8\`+6/Ɂޕ\4ぼm,"`ްG' 0NOOoTa&S [ȧx H3ud8d7[$㠗ͻHAG5DljY>ζ&uGGZzm32HLFק=J3-"# #b{@4>d%{|s6(ۓN0_TSS#*\ YD;`U0gb9=h}H3+l:#JSξNׇrD_nܸ+L!*0 4I"@.a)\US#UwG2զ\]00eLg2:s#9D!9wCF^!3(퇧,SZΈdBCnSE] Ӿa݈+9eD шtQڞ{1 :c!75_\ > ˤ/[蠜 uSر{/*Řq @v!v^l Bt P v|#> 'b1Y@OِВz`AYЃe=q0؛@msg@mkx#99dZ:Um\'M6OL ꙷ7R֢ĮKNjٱE5?zf:Uq?8,-?c3Œ)0c\ɗ7w 'nm5m:b:O8 /^K n^cW*;S v DMC?ԋ\=%]F#Jd 6vAUlKlN }^Չ Ӑ,Rk򉵺\Խ9 %FWw(?i+'T󷌓Ah,40jK3[)5뇝upmZ[KTe0U_xڲ6X YL"Q6*Q"*4`eyU5+s (<mXJ^E7}!%q!aJc@[z*]lz7} ^4CO(rؒ ʙFܰ+bF'2g4V~G&W`Bɟr$l-F?N慛P8lj-9[nc' Ќ0FoBɒ_?|qtќV?Q3"&@THEXuaDN/HrܘAɮ\3V+|Ciƿ/ y)z՟ cuicA`!s'Q\dS*ǿTWЭEQ4K u"6˷ݰ1؁Oa\p|d޻ Q,H'zϫV0VRk)DX|`ڠ ҰE5}:]ǯ쇪`66GQʱ.sNJ t,ꝶ@ھ%ōWYum2bY7zQ@2䠟C4@p{?)[%J7 bY$Ss 0ؙ'a>ps!1}øLQlUӛ#( JO kW}3p)}q_xWmcY}3E[ѕaәf&k|֙6+o?ĈyMS9!m9i*kۗ;qxM?QL}’I'Eb+jb/ڞ-J;Ta]\Zf%ilyI6\\C?Qiʾ)?+2)eՅ@] uyjlҽY8P{jtvxuL'WE+ p 4 )Ԥ%ETv&༥u˧Sg_+6S´=yA"uH~#`[};ּP)oJ~fATwGxrn`UpM (!"$*%pAPᘽYN#W~({4º  k=1Bi#poMWކQ7֓Y@Ds~cEL*8ͳTd] +[H"]Y(2cCa/$Bl{ o:zmYHp74:&$w٧;p]ᆬ6dȭr{kl1smE&= _ 67[ѫ!K}&27Y?SU={dl<Ϗ9f l b m4륃 ؕ:-T[5<] ˁӌ퓕CWڻ_ NYI #0@5;a5Ыm!G~5%U]1|2+DsOjdܟs1)HEQW5s7\GDHߒcݬ?/}s :$H&{ dGH1Q%_ K]jĴH3W҇v /~gsmANava:ӴuMDHe4}o3S1d}}Q`4p"p&}C.D5&?"&zDgKI6DחeR¼k]\A{!0p,hڙgR;Hw 54Gp]{39kj%6ΊB{ȡ}ǫ3:*Q$̩nwe^S>uqd8Fnk?&|BѨ7Ǯľ+JMK9 7&\o ex]R85(uNqg)5coL#jH _rlJsP0<<hy _fm0Za4RӊPeVUWmmrǕyw?y߁Q}RGdjfTҺ$Mfsm-U,4Ռ1WagyClIАfp0/ UB"!u!dԔO1|p%38#r*5 7^ 'YHt^"NҲ6%1_=ZȞҪ@BΆ$ms݃P2YK_yi@ umBiv:N~ϲR ?3x[b׻-:\B\xVOM9ݲP skm 31xif(ya1U*08ڐϧM{yTjMH;gKyH5g`/n29Ժ M,L7GW %_J_?XiQ@ET4J}G:e]1[NZIo w&΅%]٧8]5o0>X 5&zCX>(\)z2/|o7xp"))~ m'*#Q\% $K4$+h{>+ev?#3*XjGnTYe +a-D27f DyP1N:ewo$;=cWfajD t5y `5KmU(m7 l8tPD *2s!Zj5z+"WuUjt~ *CjǠ'H `MWF;!s05 $hJoVpYjʩбS()}:mV,mȂJ K8Dp^;'DjN媿1^dfSao̮Ӿg{#Uz[&3kQL,}B VP %Q$ܨt:m:ؓF8.>5+6Jlz}[.3{X@o1GE3u, {Lg­&>IS꧱r^fG/-ˢo*YNB1#xW`"NOn8w:›"Uqߔy= 29`GBW%]'4G7k!`_(z;gqulc6Ʉu (h2hm}8yn=˧4<:'sj:wdx$ WL}x. x"Q f 2蚖pLlyYpt6GbN T_ak9g\=oF9Zx:Ei9r Łc5Z0?9F!r7&/.4*ہsjABW5uMRqKI.E @"-/pY2Hسc:bؐ2Qx&3*p[{n-`q43`OoRvk÷ɍ 9IM`lcg+O4h0zcj7UյGY{4wa KN3JO.,4vVa`16Hqp8+0_OKA\b $IƑOg\0!VYm7;Aq[Vl.KDdk2Cy*ڬ6W\uhzA 4ߑowk:yOijȍ0Ph;)1}׵J<;U8}ߖTjIT~)˱kZ͕<~AR8l7>Zܣ,b!{V)#R671/y8NE#K=`q2RqBh&f\YPGRxgZ2YCSٸ"֢hLsV0xhL1F]^F|Ol<ё$d: ˶dZuZsT* 4\xZlP/5O@,ByN(#'0^ E;MJCETfz 06&? ">k ܱ2<&:G&򆻿] 5؜+3 DHd+Χ6\O3mU(O)I_)kCoyb@hW\m@O|ODeeёB+@tW]U|g{DAQzyT}^.%r-T:@^jvmUݎhzjK)5f2V 28W;`sl5w}HrMzjQH=pCr'3i`Yֲ MoY hJWB$7]$|3 XGf"+E΄o%1JY6nVƥj4^:+`p_E &W6G87l2mlb;*4 B!WqIa@FKW.Z#_tFvu4Pv{ _>?#p$;> @HdSah:Ds?KKP1́`c\^Rp4Kp:pN  ;l']K>+gD+H{FrmED_Ґ<ՉCâ)W;<"kkIyz>*\CMP,.v4V?MSNT-AO;'SxCU~$v/`cg=@$<j3yזb2L[9Mژ#QԈYb9sٵJM {y~07@dA >L{(/TuQ+~;+>r) (d#nZgO%S8!KS >o9F:סpG$`Cujp{m 3-My.QdҀu3 $`2ډRnQdXLF=hPxЍ4cO\<ANzfVJӑ&,PwV6Ǭq+? v|"z}? l:^=Z[DF 2njTXp_u3-Oa.T"85# ذT~Y#?$1DMr'?ЄB)?P w;)j *;W xKh#w:֯&2P3>NUR/.HO gel&nLySCh@a@ſIy>=ʪ_ Y2IF?bbT;-UpaFqn ye`8ԟ>J.=JiQ588ouwrqk܌"zGFJa`4l38B<:_mOٸh-rbp8S+ z2TY̆ꀓ[Nx<4UHy|I|y5Q WQ N.T4Bmt$ p\ <=Rndop9 b$Ph^\{m0a~5gFvTSG"<ݟ41YrVF;Evb8#0@G%a +Jo:|sL3'+,B3]]E]7'4[{YL#J#-Bu Zt6̀=[Mv*xdL3ʰzΚA64( ;Xx?ݚ@$0a-;R⮂pQs׈ˎ՛ _qtksuJ"o_[*FPNKY4yOƆIDǞj/sP&OQtknH]p֭A5bRSgrN+7;΃U8$ʐ1YXj*F=fu7e?}9};Rt8 6"mwRsh}lg[UR _̛f.WwN֢Q ` Zf6r.ĭsR¹)؅iNԹt$n,o x'XYGTٟCUotB;OOE_+Zb9N *!1#3 䞀FI.%Ԣ9alPNvyEXX `_rk#j1*2vݕsOzz~]8,(0ʘ}wl~sqw%fo9dG27 MuջddWNjCC ŒfrBI7{8*j#L[ëd1EW; "3b=S$І?ڈA84_UI80L}PE*ՅD+n3Ut96s'2 Bwn`E:K]Se.x 2TL[F[ kC )ӏ_S$%' 5n1qKQ'@,qUIƽ2-nk@*bֺ{i ^uӃԐ& KyI^uLSq^χMHP]hCCyU@5^TNw`;;XfCzz6;8ŕDc\WyY]YmJw"V wt/&&jP?5,7155̬25TtB[v{xnogr=z1ςTtl " {/Z+:F Z$R8})٦X5U6ml.:@Xͫ%LY'{&X\]2`";Y b$!6&hV8;'Q`%;I3:huM\ǟw&Ri2s\v f6oǎGމ@d(e6[ xj}L]W3)aW -ejWkt׌UU~a ޻2a#RɌ$2rD.eyHe_Tt ]'܁K>*p o0!5PPLcDCrIگ%nBֺlU_mA׶( ̆JVYZ WK&ҵ n;fL1^q8A}{0SmNȃ13@ZT4zqxUr:Qkp1r;HWh#x?5}x۪|KKckVT(,UzfoM@4=d}% ;QnK''$y с\v'V MgF1lڍy_9a E,5w?`&̩g<}D3,7D!@c ^7P*TI š|6tSjEyww&!&dWdvZFD2W46q<ї[v8[cbȹ*Sqvl?ν|e.+4у[g,Y^( aYBl/dab@>r].B VF#߫V"ignc;ҟ[prҿn%cOzǧQ#zF&_貮{ B \ne\=MCfʜDqY8'r9) /a.]+>2!"޾o i*GoGE utS׾LEl}dXEsAm(wn% 3bqk)ElV~CLoM½NhƱS3)_ʈד/=1b.y$ή>쭪KeļxL J;d0x)SR?4p>ـ5O@M~Y]\ YQ R*INMBms!"#T \2s|:oFj햢K!X닌vs|o6ҩ}L-x("OpQ"Ϟw8Xd‰q|ryU?tAK7H$C0 1`H.zia%q_ 2qLF~?!X6 W]):-dټ}QLgBkNE(@6,֨ cp$-0-x[~O2!pdC);nޱNknD in0_m[ om;≩f>AU1Cǟ,{,&QR rK͏GX3@| .jݼ@K /UxΈ{51_ȣO"]9RHDb|CB8IH:_1p_~U] pESI}O(1uC2 :~C* " ٙ3(/ۢ !Fe[90sw頒q]y;8n%"ȠW_ɤ B\_Ƭ@41UWEA{tp=Nkh1{56m׆baV hڣƒi')f~ͳ#JrOo;A[Ba>rBE+(CJ;e@)IMw&o~[ cC+CR\ c7눹/ yG`q|Wuת_)ֈA0D% n6DaZnS"3F7`. #)Tas\V}Đ[N駦"7J _ k|6Ax3ʲk=JGX'QCo(Z," 326:SPb͐b~b>]͡C137VaU'4 %Z]Uw@>3&Fe6*괸,t]Ber: wÃCPXU>tsaT)BywIbv'<YM-n<9ڜqy6,)e}[qKFsЉ]h D,.XeVX@UI;;/xE>VsV)G+WU373U`,>7[/ySY^ZȲ =RQ7g`=!$NF4jUFT?'';zۧ$Y9$G;=h A+G-hVkc``taO TsNZ~؟ '/w csN$ޅAa$0ޒ)P0!iYG⥪w{Dۭrh1~SWTko3t:nR|?k2_yԣ#.3Q{fu.i;l v^İڶTڎ)ԞI+Hrc o=PE}+H^S O Xm|U]gMD=bec|1m43]%58{H5Г$8Xry(:S Uz{`ʾ< tǷf<}xpsZUҤ0@"EA ȸ;OutڏP.L+%Gy'u;4mGY3|Ꭻo\,ᓾFP/#XvZT# \p=Fi_ NZA1vO?3s#R_.;Cvc^^i] ayY#'Cb[ʡa:s1H抡%I^FgTL},(x:صRp9+s])RKtqR Os)?faFŞIvAA*Ma$BE9m/z ixj,pck̺͛ȷsgƺ00y"sЀT4-| 6i R$ v3Mo_ns!} cF B ,x9}Sjeu܀BȨ +N _k_2ly AmI!VȈTvcOb` =T%.a^?CL)|ٶ.pUjYcKm4ewG+ā vUpj 怎dE[kؚ[LK`גQM_vMc#*v31^"-LPt_ Ca\B_W* l |Od+՚P~k}yNES01E WE<a=MLJ\&Vv^+~w2c0IFRjPkԿ]-VC-?h`yo% ɩjQ\h0{=}Tn|ER_~1WTw'jW57n)f'5tk;k`$2" Uϩt_]xs{ Y3E&}C"M*䏋{\Շ1 x^=1 tX&jVJMe:n!_'+Mn9/`wl<^JeN9b8I2 Q8mm cRkqqlmDp*icA?p㉠ăL{ _ݒYnV)3d !&*ɏypDJF,\GHeBO#vYvs}gFx6]AVSIʁ~vn8 ?o%] 0EC_Bh " 2ހA*_Ç՗S2}8D{r0 y:twL-_fbI(e ^R/Z!\QcrtBf+$]l3vUg}ia,䐗cO#N=jb➝Kxڻ.H%fV"I6--^Cjqd*.umVv$?V? jxj,ewz&;3LYE3<Јkh=.G"?t"9q$]5 ~ރh7<[n$ uǻQHc48ȧF-LШʂMRN1w `-hctȁ>p{ n9j5WnsfQWяl %`^A;c⟉F- ,H}nRꦂԭ66DT qaF|uc'CuJ$M" =%?r{dz$x"=@^k+ œ/8J±is 7ţi@B#<'Й%~<[ȕVJˬkqAfrz]ETe=@騟x9fdJ:QNf)RG^je+֯!NuӆBPXG,'h 5 oªetA ^,E_Z{CtjOٔFʅ{s*  եK.[nhi*X j4\4K4AIy(߂%ƪ4M{Uǜd׷byꐄ1\{m?Z!HJ8J>|YՃj`6Jߓ7렓.HDM-&x輳Epӧp0v\fo{@:V>Hw%-ΖP`(Cc'}ֿx>A|97 (n dK*,<$<"^ZMEۭ"ؙNzLMt]mnbu DefwWµ & P،qu;v&}k W<1:-N8R$0<֙w{n< A}پF$SLiOl_ZkBBB1ipP abc^o^ֺD/J ?uOکRL߀/4#e 5K:$Y =v "dUJޟc'6;lӏzFڤ` $UiN{39X티pC0Oϗ'IOM7JB`9vVEƶ, 1:me:O**o} w`T9W0gO_ېx~9q䇦,M=f0醾h?=C:2EpWKՏX,BY]<{yOcʻ۹0\/DwFzA7T~ťv}I l|y2f$C: i'6]{`  i??<2srmrWsil νKҩiwʩX>!Ә >ڒ]N3p{VilH&l8S3K);+?&DH UOARCn,m5Z2c llFK~U6Ō ;ا-~%"k#Ҭd~~8M\:!TL'eSLywdFsu|SCyMRk Ip$ೕ#î7N^0wmgd/SH*/ lpG7K6Nt+Q[.Ä+C pDmZ,xoCݓc׵stF N :WTD(|~ ƘO$Pţ4 zJkq&0~Yfjkޒ|y ە/hD0-LKuCi8j8Dƈ6!jIfƟ~1v(/|d9C|DȾר,;RJ3H ɽx/B{``®ɠ^7("3(Byj$B{HQ>f:jM[v3kV{ɊbKhÖ}&0p%K3!:KJS@-3CEU,Gl~E7MN+Ң{<:V2D$;S NM U#{LM臅o񠃼(V xVKWSLMvHBRfh~Mn9$&ku8)Jcod镇*nW`E&> Q#Np\OE ~-glш;J\3b%%f$9%tc=q=*lCBK2h^5!?hZX63MyTi~TorZiCA@C+e}cz*q`§80,7f(V 05ST#'mϪRT) F *h@=5;O\ +3*y⼿y+{!sۊTqкP m\}!ejciELCw: Xmtb>Lmb(&&P3t# ZFp n?5^KGJK(RV,5x@hf/ "gd6R=E|B&.;SZb+<{fDn9F>ݝC͗]xAL =3I_cҖ \E3i4 ̤?WZTDo>'R\\֗@r>xt`*}Q؆6N7{ʿ7:\dYV+/?ٹ,%j {Y45F*:ȉvsMNA3>E'FسW$e1H g{Jp(ٯ@y+I(! w|z+sS- "e h̖?ߑ& >0NӐWöNc N[QrR ;ן Ƭ}$̬К*P*2jJ>A,GxKt޾x~9x`fD IB>.*>X2Jx3r5yunj>`,@$~RMZ"O8K@";'v:K##1Na:X0d0kmxay/&[E.WIu>_jO &d!Aiwzrej2hyc̝FS^'O? xaFmB˼wDcM,}Z>9L33aLX)DlPy6GTZ}sJv gAKJ #ܘRߦHHQ>V_-,o(XE.x)CoMR,j3XE"=K9^yqoϭ$AR]g&/%i.>\`O-:lR9T!*c#sBipМU%wds3:)Ək1,u5 D~83K2:Y иUg+yj_ۀo!ӄN{Ah~{>,+tSZ64ٞ;ka,pPwHn%(P TIp[TA* +vgID̼ĩV :Hq"csI#ݜiv/i9t;6%3ð?0tRX_SګeEϞfl=I-u6?SDE=*+dj3xI)~tż!V[h١^ؕ4ŏ-ZD#L Pǖ&Mz2a{8ͳ' ᏸ%wT;Fc;!PQ$yKt}1E鰌SVN Ya65֫kف|+9(b݈qsGsKbto;NJ\\DTKtdIa<wmH/1qyA|ܯET9+?z\}` 2O3˧- “Y\U>zBbִ / Zi?{AW!:,mz4~| {'Lz2ɚM zfA;[dngu9Ims\/dB#/.B+!Ć#]Ļ9y\iFrԒ[c6O#M(ʉ ]Ѐ.W[V-J(8~TO})KחX#ØQ_gɌUC|n< nov=H&y09l鱣4vh,\(#)־L ZJ FEXv*{$.xz6M¥EY{yK\[Gy 'Zxu.8vkxw 48x61XZ\;x4WH udǾD)gջlY5y I*tNvIxhVG?A*;iRң≮)Og3ri2r~(!œ&BbZYjXRNljM^j,Lol@{oBz -\u.̀5d0?j@$I2(I,-7-x3*rj? C2-@ӑם>a£ x^)f =L)sV@q]6.k?=c;Y`m)1 ` ry`< 7s9i%ˡ_#{yXB2`ulðMvDE:p}-ABъa(N+,aFg1mȑ*?(~Z v0*ig2˅HEd Iiui(<4gxC~jN.(z@;q'N`´RU(_m% `s,%om3N`A|V $p0/mO2i iV_!Hߩ0:?/#N)zy>a7ِVʏ{)K~^-^ f&jcyd"%j˝jG_u俑I| /c9P*$Q*-yl\ d ʔ+-`s"(,ǐ>F ]pR0]}֩ (N'C_y$Nتp.jǙsjk0{vIpA@Wps"5L/Buz C~dej'UTH9 b]D[`{mpUi\{gG<1Wq⊟++*o2,=bǪ(p{7C.Kh^z8 i&.f&|n<ӽM]~_q&6@DqWH;j/2TƱd2$m;\/nH]\"wAv{#DJj*@Oy-%~6T9YS`AZS`NIS_Ԍ֯xKm>3 a!ʵ߷vo뚉;(s r{暭l0v4f@]/n),Him=D[~/B v$CeuӶU>-"x@\ܰRb+YG"MEԳGw/b oGlXB qm{Vе.rby/'ZƎW2mżU+x⸉X@seȊ{'1k;JšKMo)79gdl5~T.`)5Uu2T$STϞ[-TMįǵK\fH(Œ呾~k ``ㄈ]+91^L2.@[R!mL P.X.rc_/Z'bAUYvC(J!)h<kg ۙ ӳy"W(vxꀎqx)=u二6+Xrz5pq|r f_Yh>d]}U]W :3f3h cJ!OPM7Rhh\|ѩՎVQ/˅̚j ~䇪3JSRF+fڅ>1 fNY 1MԨ?\|)HpAb2E#̦rw2JAh]r>$~n>ѭ9]@g ǴW!~u GrG f>IDH$ (p=˾Ey 'GvMׯ9k{kAt`뱢@P)"wJ>kKE{%~Ae92y? `Rq}5MP/Z(`^s(\qP=$ta~aOf`4\1 ]b_e 涫=2d92-rfOw\5ZXJN 5}{-~sѱ*m83a \%* oڪDVPGN)B, A.MfaqLacMa}OΥuH.k)à.f$ÆvAv73ZKOO(bi5?iKeT=iB(5Ҥty X}¨iC64LoK2 FRAK(K_Nacϗh~tF3x#-}JIJ@m>P7p|:$P-~F5 /Vq+V?0^Vd?oi2-[nO)5`rk 퐄g޴4搱Z\ֺ1?F0 _@E,Y٭q (\ڙ;f45WNpNJ"RYKwkFxJMEnh/RNbs]u s 9Z:D>[dܹ|U'&F%z~Ű'szհ::@?vF+s7£,) 3VS)(GJT 7O4oB6ͥ@== F*u )0„GX/yqU j#oyβNy]|"~XUf'3'VGHTf OJ zͬC-qg6! >$H&_51]r4q?8 aD06vwrAz ;^;?\ qEzr .ջ@)tv|Q +`;O/̍atO'7ԥu*h,hLa46D$Z5H(=y >Tt=!1er>sY{*iҶ2P7Re(L K'cpeV#X47nj#[Td Iݒ?ۣm0z+=߈Q[!Ke$0I$9rJoȖLEfp{)g3'Wƥtw^;_/MwE@wVwZa&tqK9_i.R ?Y.\|7A6(Awݪh}Ar/t!FI|eE(eeLj3Ri/<8౾GJnxSoeIK+y;~B./!Q]Fh @vkLO+O*=Nc#lq|brݿ1*ݙ>f`ne"{S|7քRŃ4!0!\=(zѮ&#nБlX8PF$B*KCsofE- 0 $3 e̵&4Ch2k&~b`VI? /YP)7/Q H/n9 E%:9~)KQŸ֡@t`N-[ELh,E;F6<Ql ~C2XN|j4VS/X3@<*Y YZ