sssd-dbus-2.5.1-2.el8 >  A `{U]V yZ])@ͷ>QT`='|*CV1\J@*} )A%#JJxם T[럩mku4gUY`OCǕI=53B_,u*ܒ]-PG[z%3WΗ5bz4NQNp\l#=FxxjṶNMg/wAyMELRl(8ULx#>8|m@>V1bS"!6"fca y59ɯ$h}= wA^8l=N/e,3KeXEYA[U-X;)Yi~ZN_yo"o@t]E,'9jl~b6jAcn1(SHfIͺd m"q!z6='߯\@nI!1u01K1i2mHaaa482b3cdc6104ff1ca6edf417afb189b4febf04928fe65541ec5514375f8ce86a9f2a40b96500c704ab55d1311165a54ed5b95*`{U][!gYbsY*EȂU%ו+AOփ~fQ.i0N.M t]` &q6FS4[~&- " ,# ^rxĩθR+r+=H”NH gA U&2d}yjrfO4 jQk3q3ʘ۠΃?7?6v_RShdmQS[O;sgԨ^Ӑhy ^aRvRSs(!fM y}lnm2$982Λ726sŵTK0Z- 0]gõ7k}B!Y]%;e_P ]D[+nlh|)gқ̿k?H3Q 0Lyv>pBk?k|d   8 #7TZby8 T p  6 l0L4t4 a4( 8 9$:b>b?b@cGcHc@IcxXcYc\c]c^dbfdgFegKfgNlgPtglugvgwjxjPyj)k,k0k6kxCsssd-dbus2.5.12.el8The D-Bus responder of the SSSDProvides the D-Bus responder of the SSSD, called the InfoPipe, that allows the information from the SSSD to be transmitted over the system bus.` paarch64-02.mbox.centos.orgCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxaarch64 if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-ifp.service &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-ifp.service &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-ifp.service &>/dev/null || : fi%&0K- ?AA큤A큤` *` \` \` \` .` 2` *` \`@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh cadesvuk2.5.1-2.el82.5.1-2.el8 org.freedesktop.sssd.infopipe.conf.build-id60668d3bea0362c28ea50d113c1ffada3e230583sssd-ifp.servicesssd_ifporg.freedesktop.sssd.infopipe.servicesssd-dbusCOPYINGsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gz/etc/dbus-1/system.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/60//usr/lib/systemd/system//usr/libexec/sssd//usr/share/dbus-1/system-services//usr/share/licenses//usr/share/licenses/sssd-dbus//usr/share/man/ca/man5//usr/share/man/de/man5//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnuXML 1.0 document, ASCII textdirectoryASCII textELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=60668d3bea0362c28ea50d113c1ffada3e230583, strippedtroff or preprocessor input, UTF-8 Unicode text (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix))R(R$R RRRRR*RR&RRRR"RRRRR'RRRRR RRRRR R#RR R!R R)R%R RRRR.utf-8cd3d46b41f85809ed2350dadfa47de95f9c8db3f8793a36dfddd916534328d60?7zXZ !#,2] b2u Q{LQ >$$[v. 6 `2RfƄ<m{Ey吠۬m H|7',LȳdNKF]$U@a\^Jl&ZU_r^Չk(6Fl1n(Ш ߣ[DMI'[>_T.o!:s肕Hw wtWQ. =D ތ+O?u-܍$*rK\_F|[IeqxP ^JMw[q\DRGq 4[h&{ &j^q4iM=zK)GНS#^Mh׫ v$ύP$A sϙa$;`T$WcߨQŎ.}t5Xa Pl τl| ;g@gޥ' qs>-)8#[V}Vs&Ka46U3'ۏ~eEOm9 u)[qs5D.‹ֈKb㋌_U N?&;"MqсޡTMqB!fIX9PBwtdD,9[cS*M_z3;v8x#[XYhXz>'S]c>"%_yhb)FdU" ¤jU󛁣 @lj8lxֲ0yS<]. V·zBО7ink.S<_h'׉6]%- 2O\jAgﯘ7*zi(ڢ ٸ6LP2Os:x(L,֕,*{+!; vĘxvhQvcW$Q]@XLQ0{/̸ fEp14 Op]ozN>+M դrhi`iqǑ!9rqA(/҃MꃸMƒڟI&+=Ww2R!I<9bsd>Ae*0BYj8ݯ[u?!9Z\,ocG} &~ĺQNNUw\M֮|o2[kΈN@+i \:#b0}]e*A\('4*|o:PMwDZqdpi.^[, pT+߆,Od֢4zy>ɼH [Ar~S'̷>fY0Ľe[Aeop^P eӱ jQxM)I;T7/esΌ'D3Z06]g`Hvlj>\Tw^* >fp4[!oXh`u&o3;}Σ=h22_L!-ﭮUuƬD;Fl\<ɴ[ZAF0s.,Wq@d%E{S"N)f[6@f`.o5gґ`zS[d0l`o 4'sZ Ow^Fx>yQj<ۗlTyX\#xeC .K\ue`8bd3U'D?N?fӊ)|z;.$EqEmݼ~1R!'[ Bݸ>`&ǹXBwTTgu)\85^*0V'N޶TÅCC`$AW;$8 ARQbtT,V<4U!;*Uk fi<5"CHF-} Db}Wdq$ȯ+h`GDW)~^Yǰ_;Ӡԧo%IڜgJcw~ ;ၿ.ߩ I"=ľ@$ `Y~FC}.u Κi.a~UKHN:M F6߸+w5v+*HWoYcュbDd?ۯ'D?^ݤSLS۷[MT:)8sD \iLLƮUVD:*wM ]%/I'V&";덀GςZٯLgotjTYw 7dzbgFgKҏ4@`B6xHI 5~!do*ڭP4'yhwi+B;ov"G>YE 7u` { Eb'}tt iH}^0%blY?=՛#۷ [feO^Xv92hyNYNӺםR]Zzܑ J(fpmz 40@[q_`E;aƅ~mE%о ܠXBmn$ԪǺKxUEq{vQ-( 2): qµ޶QJ( 2ah&ۈ_I9FRCf!ݘSAЎjģGOPhԣiQ{Yq}瘐ʃ]3豻W^+4~^L`̭V^ؾ(U ϯ3Sn[6ᯊxȭ]MZaRpyFbT4>" =$o#IM=h6? nWNA>>[$v)LVZ6[wOL9 c+"ѻ <+Ru[[%߉8E:̚ݒ~f璜D÷қM$\uOOHy5^.6vhKqާSxSN3 ZE`KGBJDvSJA w7[*~hvt=|ġɒеĚtW{>opduƸOA v0eȤfq]og T3DZL4':Κ2{On lfK߼"C >VeA卆y% p2 ˛@̣dq#1>R{BH"jjd Ȕظ1Wr0,|TDTL-?} 6o /2yw{WU6L 4A@PmXiNj ~YebȬ/L/L`ܥQOa)n~8-w! $g^ĜmЁ7@f$Ty5qx" %Q >'~uHzRrkcP)n :c~ >qr,ň>;~y1R1ϣ3ɫ*dz"A܏W>.˻J-'ItT.iS u۪A~{$`R&n1r^ֿj˗/T؇b.ԿٸIl?C`G 1f3,vxʻP}Y/tz&(lű@Ȳ֓>Ǭu3)$;}R.qU|W8eExDQmBzu.1Tjsp.M l,BJd{i#;K_Va(,wV_A[yq㹃IЖDڤRevT*"XlzÓX\MfۇqD k5[R2C&F/^TȬK0Vuk&G šn.H!u|\pG p4cmTWMB7Pllh^U)؂NsO R&o]*yp3BMcd ӗ/V蹞S+ ^({TKzN$̪~<T'g:f{8xC~{%h^Rc9p{0]J6˒5{6(0Kb`Z_hpHvk@)u*]U6_q A%lB-CW=}?ǯ6M8cNF4+Ęk竛!~? BSV+%=Gwc BQk>-HÅ%GC_C_-/,| I:T^p52_k!,Nf=GjPH6x"}޷ܧa曓m qȽf|{됝Jt=[!D &EEpNgPv.5P@/,zR d[XkH6%^BǑ Q F3.ܺgA~Y&1鳁$k}7w#GM^+XEuѮ#|S#ْ"~pj=Hx UEAM{\Lߡ ̶b l/bÕ'l2ؔNLxA?ۚcO4)<,;YѴ꼔\nyi VM/, ,Z؃R0㐠NKo¿d(53Ub,i?bX8>\CHZ\}j&{.G!YdqfJ-YG8]YSFrx3HWVPq%N 6(Y-s:CT蹥 #)`LotF2[K@D.1:aĭ>..beBbǚpY[Aꦟb"4\fF] S4UffE"}kV+vY$[M0= L[ -$l5]Ǽ~g"p@뇒4qKZf;Ai;a<6i8SʮDD!5L[Dу=]{c(EO7ݿ3a#},iF\8qsSOܻ.B1Yev:K!@G|:MEĚ!~e1٘\ilarrfb`̽6(VN~T2L{#whb NŨB JP,m\lR9޼[v@fL[7 zق'"Nغ}Ao{ćpe8{fb㉺)\4j0=aaJnGI JM$Gq;{]{ƐKi2! ѹ5".%9iAl[k(`O^ sqjRޠ+kJαjȿv3q畣6ū`k0Es~k"Uȷ#-[K5Gj4S]Uc{{S+VJE(9$ _'b8DtLG]\!zjI=]sb;J>Rfnh pd$bhMVńd]6ҎU0\ӝq&-@Zx0fM^*_6`zih81_LQ%l|+mnq:!ߠ'~s85cNqBtҘ$N怂̵" @VaM[x+-ߊ;VVuj'bvr2  YgEf~:i2Ji,h0 {c~s(_f` 0kvZR{dXz@x^#x~d=]gT4C㤶2w . -+KЭY :1`r_\g~pjxQIz&v׽G#pJۨ8n(^ՏjL2!7En.4IB;fן{zeT͔ߟRьI׿ANW"]u͙g((A N6BŁKܖ.qt8X">/mz Gߵd&c7Mn9M.2 jf -\yȫl=IC(V&Xk1k&[ķ26'l ~cHJbGMO1gQqU_KQMg^u܏8҉9Oyhvrwx.8F2d|s w> "̭닭XC-*su%Bŕa{PĖfXže] ΑgmMVaB ʹgV;-)Ԝ6y'd.o ,n[:oo J7a  X\l'3J?F}Y7ym+Ŝ.C]^Sv>hkTֺs=qTߟc2L"1"Jf1)N,;y7"R2 Z x'SMb͆{ $R+(=CBdRI:_O{hBeDzˀVp)fI#ފ#n|0[k+9J_~ºT8 ݔk:U2x 'y[O<zhהC)H |tE8~|FS"t}⃫lkk -$:#%$ ,J{|KQPVJ H\[ y_zfoǷ3kiX* 2%%+ gni7 -B0j'pݹ2_o,9Gk)7(:2dI \,ZCq<-_ֈs OpOSpLkkyL= ogx"&XprUEOiP1CڨJD} $IM-eФV!\wuBQv19|7y;C&QyJƽMu,I {Ђ/Y,h1Zbkk/ܬF3`_rfxK(\_Ur F"Wi<]Y ŰID'n畯+ :#DIAKqSBf#&L̩܋{=1[]2Y':~\ґ^u݅s7){L…d%@Qu!Ī@y(^JNjf߁ ?Lx tkި,@;`uJ .׬zJgGMVϐw+4@ IYMyAX,՟ر"u_Ɖo&rޑ]>&2.кGֺYdAkJv*Q6iW9Ŧ=]N>wsj xF֞PMŲЎ#M-F&gs;Îl X$><^KWeTaePI]8xލƝq<|kMLm0L`ͥȫ>gT#5m LX?%z!F3br&(Zu#;pI #>ׂ^$k$"SwaaW}Xs`PwM'0z.cL >>%"vDuT*d_m-qv/:o9-߬?kcgmdtXpҒ^Kއ\yCEO`a(#u|doD Ư//]U[ yz yu̎'haelw^V("WmݛW§T9);ުc0'Setb5K\p2zF\'M[`]fS Z$0!b,G[lOzV`!3U B,e(),Aa?~awbT91*ŷ?w.+Bw5~7LTt>!4d/","ucSDSd>I&׉Jq$l>L$nhqs+U1m%*y {jx7QlEfްuOM.. g,t"sI9_O"s_[nDO%>Ȝ S\(K׭OVplձ{> O䏛FЊbqG^2xE5 MwR>5)`]N98D޴l~oC'&5YQ|n^āh궄ڮ}3E8X r%3I6_R܅ :_Ƭ1+{9 j:ݹ L;O\9]9Cv k (~t&id*RxkЅ6IN" +!57z(BM0IKGw1GQ(XBVACq@|jA7`K"$Y,x#Un~葮B.0\6G?\y<`e(v!T6U@H*U%fq:S]DQ0Ea*-F>fBoSh2nVWz$'Nt5mR+@֮f:OJ`CZ|#Pz H-E.wYUɖvBͰin w467Q c¯3+gBܰO=B_V$ M/u `+F2睦 ;fq=*͂9[ s鄷gTgOH'^wP&N Zuk3)ƮyZs}͚dFC~"!ÿ3+?:V#]8';БڂQjS8,h>B]h㞖^cA? >x>hYYZ~Y&zqqn; AF_)p!P|DyBٕA$mKv'b`1 \[gJ={'~ @`BcN<&n<ǾBϜV6\>du%x@ ~{"8zBe4ox6y^U@O+(<KA7N{ b80@VW,A@KzPGKgE ]ګ?۝0H~bVs}:e'$,r`$ eF>` )Sbl襬qlI  9 6+?p(p :^y 2{E*דk T ڭ82/ _Imvu+Zkȶ/[ˡKR ~*TDT!s~cʫߞ DBTĐc }d@rD1R֫X۔꒢Q! ҺG,*a\ěIWB" %Gt5CNTd*HZI]@c 0sZ BabkXA #ȁ\,=h$x%tMRgHS` gY{:XsͽTt,t. 82W0PZj B|VA4~]Gt ĦbGk/u \I# S}sJqnaZOj ;^&ʈ5xj|զa˶ߔec jΙE/S I $H zqonZ^7e') QH]+M~9YbKuV]v>2^$}ќzYx&^T+*e#G•JuU'Bn [~1}Ȳ~W]<蛿RZcԐ&{HcC 7tܻP4 gvmHkj%(KhA1)$!fhA0T\O{^}Oo) L cϚ)qʋd]˭yl "#s\3{[wRAQ=o-c|}"s[8Dretw 3je2 C.A|0Yyj+-t,ٜ{yfv(I6+开u v-+[:D6e/k x \?^pyLQٛ1 %aw]Q@A>p-MNV:{*-8Y? P 175gV6v+y/y>_xOCBEGFضrQtdLݬCP4FOۗ9PpТ`hV2*&CzDZC %$ h]{5b[u34a˛*"zOAe~h_׸j6UjT961s=zU;\"Q/~πY4 g_ZJǞx+:4t"Q[:ۏa ޗ!?˓B@$w Jpܔfi~v3VqY<r.笒)BuStzCKa³V.`.mv˹2^I$&ȦrAy"#+B<:؂&~F=gk݉޽B!mE.]"=}Ɉ2=9x^I賶7gsD!kU&iՕ7CYʇQ3,}:[*ڷfӌ#DZZq ϷD`sLJ`n~t^mvj[pJŽk,֬+RLܒZ)y}ԟ 2G`y֞My )_'8.p zAd#ee"++_/  PB<;FLƨτ וNvYD1H^3 =~o(jR@0|Y dr޷*xI\αxQ !kǸ NtI]\qZp?nk ޲3/DXg'i/]flEwtv qNGl !I #8,fz TMߪ0ʸئ>'/F΢ ˏˣ6FSJl+FDxO?ZlvN+tj)4_5F;n!s>ƫGbxˠyV~0/T~*e^x>܏s7>.rY_1CZ+ԧ$-1ick¶G?z;5}kW"t 4'-k@iQiMo٤/fڶsy=fi EOlIRArlw{!:ޒ"*;g0/y17]88Njz]Xnڕv:W91i41T?ǟ1hny]PEӍr$^uwQ jƺk2,1gY-`8Q4vy[B `?4C>j l'|j#n&B/\k?w n xlG([$(FɌ*W, ͠ζ"ŜM} E6kp'ڎhc2\z|zKT_pP[ywV0R h;ItĄv@xE(֐=S<~:Ow̖Jt @dľRXA,wm@VpHNnJPsM3d'Wn ^ б܅@b,)yR`U5zZThV߲>XQNA|[Za07ޚQ=*ޟ>3A#{uq(a"gG]f F༱|:dbH`? B%{.>[&;|^ٽʍQm 4FevIn^T4Gn)1c]xVeގ3nY3D/K"r~qY1Z `o!r6D!ϩg MJG^c84|HŐpm=$'i bw&KuC! nJVWԶԫ{&Qg9ݯm9N$oo$ЬV7ZLBWe,0ѵLyC_Bf%n}އ6:sbmoK\wr((U+:IȆB7 (Rv=y`Hl YZxC5iIζ:{i? D/Xt+yw `Ι&wy}#k\UxX'$ ұ2R0@H}/=iika2 !I$,wHmX|֤ P>_X9$:](Rñf33yUi{5um^t*iV?) e~W>d>8%mi 0 'cӽs7E+*̜ޚnq _J 4$ PV4\ި ݊矦/ׅܙmk謠z|0z b 6sQ3<TܬmˆT%w$ zy=5k'7)RaR'lVk`IݷS,z?{,=Bi (J(6.vL[YrZ@O(hAX%k"С-9gwa_>57L~;]D2ry:,eUx{*PpBߎW|ʭ1ޣU wQRp]L#p~HrfuvGrXB_=N]5I2C-1%l7F/~u,;a)5B=N/ S+ms, N}b ~?QW޸jH+Nvq4ޅWQP23̃R > iZ}٥n^{xal"*$gȓl>Y| -Z!D6ŽnO[s\SxDLeXDS׼X3?b&CPIebybxq{P94֦n$ZTOХG7Vu&{/:;?)|ћD?*ru07eBh` ; >Ɨ"X*e͞BHIGHuk4OH'ڑc?^=TTkY7!]|D)O2d o\jrΏ-^UBu&x$6f>;Y1WM?k4bPX;+ɪu9K_λY)H%|L槉\oރvā2a`deY^Nm d"#N#MVCtS'Wop ABl\,Y]Y_Zv.lfU|[/QjkmV'o]+ɦOW[o\(ެTǃt|' Cp2/&$!ŵ=/R]\p~ɐq0zPP3㉧V*Px, itq&QqRj3Q}uK,*j@ ߪ;Թ-5doн[z^KdEf\W5.IEʱpw^853!3N蒲_%>B ة2 q[D@S7 =2!3J}ʶH`Cx,70$k:a RB#TXS鬀)IU#0up<ۊ[t 뵍% K;/q1_>~\BX0koaG'Jv,j"B.5Qhɶy-uNIsXHS{Uz,C]ٹW^GԒƆa/yid.TFSziǟ ) I~z5KuVZ#$2cD6cleBYՇ%, '4-+p{$v V/ȠS?*?|BOm1^Hؓ3.h'Ux{NRZ. 9hOy^|e' k&'37nە#&cKP9Jn2P1}U (Ig &hJyG- %~QA;`=$Ԣr${m:6* p60M]?!HvSUDO|BKM* q`C 4b)Aq⏉V“' nk< >jͪo>VStt1*pk}U5 qںt?OJGf3{V -gv쾕o%lS+* AIգ,g%ݴ".^ ճ̬jr#6 #9F=3_my P;!ٚhXBi#n]M'SԻO`wE< [;Ïy︥C–~h,+,\}l~oWKk=8^qA7, 3^q8zx.< \;iuCГzQPtaH&<-;֜8' QZ(WCrYK,*99>2oMe$=݊Eʷc [MSP#@u[ OvD?"֌P!T/h"C2|mJ4C liQm<2x[^UcP״4u":ć.?&3}l2^w a!&*lǑw&/EmX"RQJw͎})rQۢշ%Tհq]zy$F Ko*Y;Wqp!r¿j0طNpbjjmϋiuB0:=[0Pzy^sM "\l>#IF:p߰džhLUŗ1İw* "K=d&V-EDlo}~7O tٯ`۫(H8Fu诚҆VnюY}fBg2oð6 b立;gk\p L$o Ll+Hoͫ*۽{[zW}YQ젰&wV]"T\SNTű3|D]:lCw/sEԭe,Y~uXUQrnirH҃r燸Z|*mr#ϰy}wi] (Rf)X}NH$ uhY H+M4VWl.e248aРM/o xţ-?>ej#ghMc)J#RTEtAȈ)/{l{b[ltJ:dj"PE'q"4xhr|%>'`: 5 5XÆPaXPYҁRLD0PouG( \SȀ03vYKqZnwf_|јaBBH]F(LdL`Bx".KkMF|P.![crxCx|xCm*\ P$VEd#V7a3ZI*xLL *}9,d۶ {h-<ўPNauİsP&I[v0zDGyWCv9BvZmTz=*љBFQ:/9?7̦dCG!( g Z2-_ FGwDCa-"^YTG1@kr{O ?D @Ê89r.1B;b/<2D:&q_W-ˉMᜳ߫6J3i{>w@_U|@ҡ-lm vrW7 l9WQ0Lπ~Ŀ5eش >cؼd22M5R+PO7;V.-Q;Q C:&ݝ!q^˒Y̴Altdžw Np 01k[4@ +1=I݈߿Z.A3ьZ%9pvm(2X*nkCO3$|܇Z^+)q vmLyBP1SNrM59ޯPT"SN>[_W1 cGdc PkezY_`n6ULl<yVJ֔Xi +/oֿϷʃ'!Ab #8Tfo-ep:ެ5h*xJ7^$}.pXZG 0! {kN#@})ن\ }3vmmεnŃ"*nP`!/3kSny^~i>ʘ:>`Nװ)ҹvJB QX<rՕܪVh4>:,p3 =Q !1h?&8Go(|ڎ,Qb"n( n\];5A̲\ 1Rl5 990&0~'>Hp{1>"lߤ(!/ȉbЀҼD(yϸpQw#sM~-7-+S0?l;ޟw䕀_]1uXPВjk[WSQ7w9Fy( u2i:演#E&ů aB ^CPQhM<&闙;YQǮ-&)7ĺ}3T?ӫYÕB5ʜΗ@[$S4s{I "};9Mi ޸y6%\^MYH+cl݇B)BV%aT >G`ַe̬;bђe5vOG20RCbSP]ʬ_.Yw m1(PXXעPLoG6|IT':~{`&ÞSr }:8Q,pv^+?x-[U9gIBo<@`\WDFZLnX{lfgre"^3cFtr6nu3Ps].rj5 j|.>UG-Q+wک5U%:LZ93}S"౟P` G؁U"xf-O8{^n3s}TDw-/Ֆo[|ִ`u_P/"ǿ9}VRjbW(eـ~m(v\^ 7K ab,&l8'P.#?/ju o}~M 툤 #c̰\fz#:Yp ‹x#-c,.M~6#Oxx BT ٰٝ q -L.\{rɺ4iH[m,7sSdX8ig.$%jFki'C~ݐ(@1ҿv =s,I!D~nzi4?y#<"߾;=q4ʉ6t:.>~F?ֳ3܏A, Π3ZV!Fpjr{@vz< yкpJTC [hAWR(6,-S qr) =a' N`ҺW B ) 9꬟.Xݮ+˳)dx_⺶D~|i U_g7\_瞘!)U"&I/lqH]!P`Wp[p5Lݼ~kO(+{:.#>Zgw[,>|k4 mi8 ۲[*[ skBvԅL \'eR'2k,p'ǯBO]/HLM3<`R7 by,},|7} ynrTc }܏_Kզ/Qֆ .(FX=T_I=Pkoq"=U^ѫw (D-9bߩKؑqfF cГ('Rh,T] IşqPe<7JT{}IAYw}0A(uT^q1e-1S,As('I1Y{CKQ"5oU7S=TJP6N="ҀHD"~ReɣHІκ\/%$%.|H<7!9P6t6#yQ(yS>QAN}\#}l6rOE!X,s+||qI!fS$ ~>ǰ*WVx~ycW^<Qh2;\!\ӤT6n.v:Ք4Fԅ%-eE,fV/{o#?`a_z#:z(8Ҿ~kJGsDjFzk遲UgS]_Jcy%K@(~Ǎ3L_ә@8%,#Gͦ$Fӱ]lXɐoS9Q5hj aޖ8jm~}[fZlcVsx9HyNBv. !-6v=$ɬ77#>eabOmˁ(Èk0=CND[eui>@a|+Q_wRٚ"XϔE7/^wgrYBaբێ6%?">T 7u1b Kk{~i!@d9[Θ'7~V,Ѓtw'Kd <74MX” |=\( (PuL8 v me ;E FvnAeYFfg{kb Em_qU~~Ij .Zى a5:=LFd.Ixp(G:8gJ c+[,əGQ|05ajJcC9|L%n ώ|m5*Tč'R@yᐻim^iR"{Zm?-`; 0̱_ 7PWi\oDАHWfFHod 3l^ώp5uDOЮHY @Uzd "w 5y cP v0HGԋe-FTCK菐zˋJdl-Xg\*%3,s gW(? zع:~!-HOˀc}GY' ?+ak(]g7E9{:f DKn#Ѷ,f\mjB5rxmQDtEcڟ`ȆlmީyF# J] D\V|->`_94:w{5wg͏aD.m;iwU8ie!`j )5@pX.z a|ar&/ϫ*&X OloU()(v~*ّfBBPHFBNl\d+>%L/DrE(Gu,n/\|.J錺I:=5>ImO5>/3_om *x 9~Q6lOYN<(ltf ׆g*MpF3$Qݹ9\ ~'J@Bw צ>="Q8wJƉv'WK[4,l0Vc)PB8yw%>Qɉַ˞LDuE_"Qp u>6m.NT52SY e⣨>?Pl1v:Ғgm 7 ly aMq؈z΂֘[C*Ҧ64r kڮFnWkv"ٖ0mrrXC/mwv711)sZ㙿]^Fdi{̍JYm˿X@FR`^j"-/xF&g1c9N:5ɮ.+ s/LdsY(Yɢs_N Iwˬw݄g vw{<%Kz a~lgΝb n%uWqЯ 8UHR(/mO2ZO9_NWnDžhJll}prqwzy7v([fu h )inYF'JW&ɋ9矰;;ڏ u?3GOtҗKR>uU?g^IL&96 t`6zލJ-%nc &H8UW0Td:,rVp`'mJ& U~~ԈAŶn[J (D\Nѕ)ONq|ܲLߢg єLQ nvӠykC!vcLI+X4x#+{c_Ļ y`oxO@MCwcri)֣ p"MT44u9!Nw*ķ B@S~VUN$zBi½3zpFel8waxin}[T_2-5p7zNn Zq$u)j{Ӻ|&=N`xq/GZP=DrZALeU#ӯ#L1@N)sq)Դ4~ n \Zs@%}4ɽϷfg 1$ȑ98/&xBEAzKـS7Uܙ'+5FȒX͑U,Nm \*I> TX]Ò(XJ9 #R~3JN tTzRy%%ijZyOU=>|Y$T-Qt1ڬy'27qVbBܜԐcSf֭\;k#_voIinOZmيr C<,LDstܛ');# do)GaòC}HD,%W4<^0w4dkm k]B,d^p7@H”óH >xz\&u"@q9÷m; Ʌe`g3|7lKL)zzЯAqo5q` D !:s80F6硛$BťB?bdn/rnvV:yQOy,e)#T}% <&"_K!直⿩ghM.#X+TNˎd[u_Z8B̈́2ջBu%~JWs1I)?e`X..$ cxtâf5Gh CxsT[$K~lG \ `uC/6Lǚ؜jLxΛ  UckDJGHNpP ?ঊ09+G&.j7(T2e]k}er`GMς6FSRz sg=/ L ("O*ly?kAV_@ B'K=tO%mZeEF*sz6 _SzyQ`:éM(4'g,2̼bz=#7_"&<ДuSe SY9YRw>H9ZBՔcYZ>Xqꏨo xw0% VۗŀyzAٿQy"'|- AÑb.:wIm[װ'< yfX]P3;zsIV0ǧ ̒Kֳ<\.'ML;zW@oG'JPsămRnG`]{*"  J F]":hY՜fO{M\Sl1L(@o2dS"?v+C`z$JSgj/R+-nֲЖ-ALطxG, X7ד&CIA@dazDngp/y 6q>'oJ#kԀ1EJJl`gcUOK5D[tZzBw a+M]8@t RϧL{-RY=I؆ԳDbl`~M/fC +S|.uڨD.IЦF_U/_/g+U)R~y@? $LJ[gE`* f$3A@wdxShOvAwEc2nMQrzC"܆c#eif&٩i4GUc,wmrt0!~}|e$OfJ]s/OW]mmҎATcfvBRXfF`!bjLg2æޮ!]N :k^u%͋"9FF=F 'yuŻ kHeVV'&ʫv`qk0-ʱenbS=F$Pxpc|kq[R(Rc+}3 V2ǀW2o <}u;7D1 xGoEJcI"@ im a)^¤43SE1bPH2=6㊣UmaꉆϹS@Ikk-yPpÖg[Qό"WtLZ&uLZ豍yy-Jx5}6 a>6tHoRJ"GC&Ք"ᬟ JLg嘧-g(2kFXCA>$y~I*3پa [Be+R#[4S$3Q=1@J18HV+#2o5E+:JT7,vGSARٙh l..^X(. q _P9UhB:';"? ".~>& @8B4?³"I>|<bm.0:"Vwոl7>#;PX5Dgn\9 _WGФLlSm %l*vM] mK@ P X$n FKl )+50M4MV@PRaU-0ZXSH%h/Y^+L6LDZdjg p`Q欫{+BeˀB%4~3i}Lmsf(WE xF /0 ѫ "a?_.I\]JSΈ8P7,]@Fl{C " # x&Q/SHssiNݬΗ B*Ek4[_kP&e}Olϛ0 A44cx̏U\=TEmD%~® ~<9:78X"s/=x2FV!8e< :Fuy׀\5{-",(SqԾFK ={g]t)G+X3XN7x4ǵEWRS2$09&y5>3A8>5OAqVhsTO8C:lGqؼp}ީ@5 l,NԖN+vA" ]FUه]_yo#ͣ2WEJU`l%"J{!k~N~#7緐:Ipbrw&o.iĽΓtpi 'I77L*\pDCX!|zI(YlV.u1+lӼoN1MpVmM, @{JO [ Ƙ}UƲU?9Nn1dR-ft[3xЖ<!ʾ\0EVNzFr X{EuF*-cK(Nax="ׯܣ lGU^C`q"2'؟ࡸY"e1jyqa$ JTn$dóhΒ9p#T5`!]!%fva U,i,eכ¯f$ H˟uG#)8"GH Zy"L̫T(v&m&S"CeB?#`zcYk$:*wIjl macՒw\w׾߻r`52[A'@Vʐb YÆSX+ CU_<#+^0bi@FȾ1nyU a|2N^^)t 55ۚD 8$M* ۓ~[X΄s8}tQ2if)ό4v97M7E3#IV '"z#:>Ժ\>u2_C$*I#xAȺy i E&6 7O^ $nu-gdqs~@;VbӋ:C/d62}M|˄a`,25|18sݬA;Äh"RBk^`z8 %e6PoN!m_4  w)5hJ4'lC3Ԯ_ vO%5*R).Bw@AŋΚq%V/6l:1'j~I 4Fz0+80qGPso;ZUʥzpcH\!3X.7xdbjt#FnFsbmqaJӹ=--\itP_XHoJFc II<0kIѝi(8GHebyu(:\pC7fJMušx UE'1A]q)'4"g 30j¨m~]{B:S>y}ۇnpmǕP, *RMɇ1JQa^1gpXQUjȊni0 }Ou#Tц͆q~a onYhb e~~tg00&`u HE;$0ێkB3ShH"C=^SBB3 h`VanWMuJ~cQ`75v^W,{L0$DK`;UB*_#"tllS[0fH?$Tjchús|rt2jX`#V,#[&jFO$Pq)F>|mHPK=Gdd 01TpГfX)azdzaϖp@Vv2V'LLeűfvɡu 'ET@p쟵+T8t[)!Dr/%rƏz] tB;J/ti8VooGXT[;<.hW<^6HgNLж@ `-J=qebX4Xh*; í'"Zf@盛 .54kQmp^TCT1WҠaRyl(A`vlFbm^+l)o1 35§N@4A+Qj{05uFfT&y?vν o2M$ևZxe%,^Z" gpc8Qg}%Uq 8S{*In1v/{lg6Qյ^r>5WO2O4TT^/yۃM=X.[(,ǂ@(o:-,sOUxuϩ\c#`h ]Fu}z8/AIe*s^ҵkZxv?QL f29ǔ~ôڀKY\~s  5s=o=,oF@S8}A qiE=噁l=czbJس4˴kj'{B@';:3o='VՉRe,/&ׯ$ǩ:A'Oʽ bgG]T>~v0O6IiI{7QFz䛽(jO kVN~:& HE.)469X(nv8o˦ㅰյS<'Sea&/ %CՠrR<|m+G-5œ[nA~07)BPـ:^iVy|FJz?o4ZjQEAM.d~_ך/՞\@j䚑*ؒ_L{xas#W=QI|=~6Fy/p,v éQwIYLci]6D_~t,4 ݿQ}p Ce꺽O6#pGKW@ }d?_8ׁO:+Kf29 ` bH< V,%&fŘ#֝\H@p©W^ mԫQ{MR+ZR^`!ކ;H0!&XV~YLI|$i5Ǒ$I]t)/ț)`֊1+j!J4)S6~[S[7=1H}yyh= ޡ୺Acr9׳]~>/}Lly/X&B7X9/sf*kЏ063wt<8l ^ťCnG b\SzKT`2ھϾ?lp"YVypfXE1C' @F|x6S8.<&qG&.צ@:PjaJ)lԿ9i\VH)RsE1@t-?fd Z i#6٧(G.!A's+WxJ`:.ĕS1NFXZ qxsiSU>ض"= S_OdK 9H/>Ⱦ9W}#=mJX(rZ,m܂i ^$  6lNˎy@N|䵀9x麛X_#I$kE_~c.L??6oϰ@C3_@bE~Q$Rye"lu@ H6NaR=ƨ`gY1+TDS=W0jzD!"_s5Y~icS쓡A%J_ifBG]qm *tܕIi䢠{e3%F1y6_?I!TPcю$ȰF52>χGt2ψbQ[)XRM͆S€4 aXg6櫅G4-_t7E, [~'w)<8%R!LQ&]2c̅.`;1K(t`l/?;',Qn/2PSXч 񩡣<ڪ}Stki.O9/`w@uw9^P$҂9nv[5n|$)HKg  ЪCQZ󄽣>11]8 6{]Q8{UQ3F.]]`E>d< TzչNLSvj=:fg)T&*&OS"5Yy;D gA7&OŃ\- +K|M/bhѲ,k;E>29EZ( D+8;Iq*1t + ܃xβa ?%H,j-b(ވYӊg}乪W"ACre&0Q|ڠ ]B 4ې44‹3j%cO~B=9dj֕]pEXAf^(ps[ ^`H<{rz0iia-hy.om|W5' vlO/N, Μv;4h,3Kw#yzc:ynI?Oim׆ EDr+S)(sN:|z?v3 S (gB)*.oB6q2KZaF'S4Cx}23i>'(-1sN4T\tlԐ?^UיN$7[% $B)V ޙ;'\lb!RqaVhr#\6ni3d́bd53rVżjy<^ ,9'"ƭ+ ET3xc7VVA#:qoiGydM{-W;z^ӨJ Tn=?쿷ʌȉEbw7]ˋi$Q D(1Cxvֲ(lQ}VIQg‰${R9CpjT]{_L?X0YLԇ{ë>=*I?_ej_MzpӑYYσG: ]Cp8hjd ι8 7¼# 2X]v(iwx]:ʏ^N-`3N)Κ ?.bE!rJ9k+d p—fCy`Whm@s_o'֨xɹquԨ_=ޯ9k/\NoaJNs]^@*ºlS6G$=iUKPI~ZVBR |@>n_Տ4ŵ3+ZM9dp$F8 +jU"A ^k{Y?CVr~-^I<Lu )$bWspo%W蔓ڲC W p_/ൔ}C| Y`mx)P%`Dz@f< zBz_)JAWKH~4#-ʴ"#P&o ((2["U SU/|);"K};~iU]N$gIta'vLƽu Y #0S1pޘbNXqnk ^ DO#j X^iLjp%!?7Kb{׸q*q*ϨcvSY4Q-~8jDK*&<WQG̳|V*hH#vk9Q]%^rKPR3mAKl؜ :2#%\^*Z|_[V.%BMޅn^'Wy%eCq<0꩖;h5o 1#.FY N/RCjibD@7¦Ry+ ٻ{}|RS0.9?Lv7ғLDCt m^28w\lzN=$3n&^k5x +nh9{Ygh??9Bϧ.bO#Ƕ&cS3udһ<(K[v,6鳸a/Wh\\y;5Z^4Т}>mbx7AjYLFNy&7:UX/: ұ2& ^k٪3JzW%I]ɖB?,a:J0O"N%`vVB =sM=h0INMߨ.yK.-5"?|ҥ?DS,(qj˩ÙcFD6ɏ$+ڇ@2d߷# .`[D";0ث:K̇(*S_ߙ;xao Oҩ߫$4v ufZ'q=n~i` K7+| w+\ea AM8Kc]j׃'].}|\+Hx*P}[Vv֏qt5t]zu@źkj1k @ծGnZ(=W6Ne>hfqMغ~ĸ*[+xv /{ҶB_k_Ŏjh^Ri[}?j|ŒSowok{*B0Wk&tFO 8jcs$hՋߓ]I܂OzD1f+ 7X5\yl#|Ewf&g_`ѭ@W4Rg)䷫Qh(E&EwI=͚?8Ƚ6*'§$qqQĆvK Tɮm{it]YQFNw Ltg|n 4H!}` klʼn6BZR&+0oLEW/ j wMOnc6mJxuZE dlw+Op[' 3, `eYO*uS܌PэOne$Vhjdw_W I{Z|'U؇s|XM 60A Oj :<8ʛw8 .[ & rW[Ufʴz @ k:63k`ӷR4Ё 7`]E˕5asD~H*H SǤUCvg ǃAS0˴-u(: CA{V*hdj_̧r I2}xla/^|7Af{xT( *D`KTߑ?>YCȮ"y1 Hol B\e+]/Sn|% lrLsE]{}vl bu?B7ED)]+Klmc3̈́j,4C kQ,C tS: ʻ.. D`w ᡼SX {i2Zpc¢h4pu_X8z^@Mx]#m|)rJE[^9h+5;xwXsQ q 9FIɇǻ>[tpO"c)xMuto4HAh/n;%%:GFÒ"e\ /_cٕNrcUkK )zyO^&PadQt zy`88ًX.KOJzN7:5y1quï aCKs@pߖ^Bp oJ_u[hR2FA\%{-c5A+݋˒$˄dݵLiગorF+ ڨM M>uƩ-)~)b IQ jew~J1B&`;5_|{\~9Kvd@U(Sσ` 4Gs B˺e^a6xJh AB/S4UTO b ʾKB|. 6e܁bY 5_䕖.b8n1èJc_P%+ZAr >W-7a\壶'½dOwY؊jT#`β7D[ I [:$8MntVLPM$bH."-wr.˭j?D9:#`)o k9;m0eY[)gK^('f}SLF-GT،PٹaS~ Sng 0_,Lġã"-Ҁj9,wQlB'MRd!Jrd0[SЉD/7OAańv$V>j=<RB0q S$WaQƭC+dtӰ@sSM+rSxNf]d{wI++EЂ/`bC-Ӆ-`"/dAKn Q˼7xȟ*)/6iJpV2^w1|$S6/ -z~0@_{t{42IBt8Yc). aMgݭreK{ aPhޔW ;-ʈwLpMxPE}\u)`bٷNqqAe] yy>KBP+{).Qni'qb}!j/ڒ*&ZV 멨8R2$K)7uC6@ >PlGGK1 (BC}ёu\tX/; Ny Dh*-M*4w"<*?B_DžUMAu dU:e KOm@#aaueb{ sVF$#UfbB#g$x"nGL|QJn=ōm`F:EN@a}߳ ) F"EBz7^Z|)f?ιEG<9*sE &pd=:Yv BpW E;!?0$J /L% _jAatƹ5]Q`}cRΞQۿ. WT#꺻a?b$yIi ?[&wyZ)P?4jrc-d#@JٚϤ4]/O3` ¬XjÅTtTFq Vft)b5Lr~g6hwV_3+3:;n\=yRn~&do.nl4ޕqye&t}zܿX+~lAS@<$Fb>Mv|fV9I\tr{=ۃXAg'ۺc-bjG㈸_Yi(ڃ uyuOs>kܐ:?b4F<7=T^֊ķCe3IFS QQVQ\x>Rɰ]T:k=ZTYrwT} ۛ@ 2tiv|z@OEp[lg"4T7sAa/t Z-":,{i:@RE;Ч -To<0퇌܋wm!HZq7.3Pkg#ӃWK!>kiŬ&g]^FBup64C$sK`Ð${QwW}/$ѸlJ'Ì26t!\ [vB^Fz46oMLŀi 68(k1V?|Y80v)}𘇞9\s~F?3AYa'3L-E}tنYϹ%>ē똸gQh,!$̍+<5Eqoֹ#Cc;~$?,0iiՌF3sոD5*b`W^ߢ_['5V,8Қ4v'\"~ḱ)$ e9F \&M1~@جLDȺ>'蹭 t_O+T~5Lf~,np^惎k̽/tL9=!!t0lf}R9bK H?tϨy dSQWǎG|@4v>8߀Ac+ʢ}~d-fEF6FD|m>b4@:W7({&Վ@qH²WUtT{}8gz/ CvU{90*0@tOQ MB o^py['z[͇ITos}ԒV)]c,̓-͔@vPjUFϊ''O 4Q !`NqSӶ6ֹ-NV 9l,μ/k} zEKL mh\#-{JE0%Z@Ejs댯mvO%G H pه.9@S%Nt ~qHɀ6% M ~3ܠ *W ImuI)]_[{NFSS7_R<ԢYc#2ҕY5IE>lAX-.oDNQHC*̉ 2*R}qK"*<'\m ytsר_ZOrnU(˶6(iYEHY+SĭG%otC#?nKZzERkwxQ r-!d$im[E~k,z 3HUW/kUrL_ r.bkKteW%zw}??BM8RRśm.=-DP7j'9SkNh)sC8ڑ8 Hj,mz lg_m2Oj; (TO4k6?fTo+@6dsO픐1&-snG:hj9mpq]4^8>vy@Tb8P>OV˙RWOm6ff:9 ^w, hD8٥a]4zv̈́1ruzOijm8s;djX:ZvCVmf}j&Ϣct|o1qF  {3 \.{ 8 bA*HMAinF-ܘ&#J(dtYY,{x9-{/RW,s:GNnreˠ}mޜ5ۍӢ\ `йDEHI8(æEtևw7GDy|×Y*+yG<1Bdݲ`6y; },=MOr tB<}yF\L m4]B%y^9* PeB3qjz {XЖݳf-߶:  C/PP\a`%;Z/L:&$9m" &1C邳E62'}'II`*znظ47Es( ?偰i0H>V'90,$LWszǷfPB!-`*16ԂmɡMQ\3?iS2ږӐNŤ!hLu3m2nVC(*8TVfW?t~l&vR1 ^Moj9v5eg1Ck$i_zU<|{2! s{5$GP7zk j ۳KߜXl-iWɄFUՌe a rQOvӚ5I(ExCCβ"d$AEDЊ+&5떾~ߡ` w5R%Lߛ.jgV/s8dJ {}c/^qcSNE[7l;£Ь{53R™Gwm؇֠1P@ēapcPkVjsXm?{¯<礈v/ŪЊ??lx`&_vL u/Ӛ6`?~tyD{ѹe1KPQ)wǟp~ dɤ!Q1Y;axjҐ< &3 [0^fyo>ְ[R0X&pSwKF%OpKr#"`"Fg0eOBw L&.r3_sYd Y jRU/lV?Ĝ{ضr)D"0t O5cRv@gBQaȡ!]6.|J嗤1Tf0Rs%B!Ss{/[IDٯGp*XEP լx?UW0Wse=Xlj^ d ֡bay̙@4hf~A H^B13vk/7 Kyz(.-" ~k[ppL #5}k:]lA^"M;Uy 4elN2?YD*JZÚaTGzݚ~Q~?oH&>MD;&!iŽzUZX.d;J ށ*9BQLH(-L`p%Oc{M*wV+%;aI".^ny"T7qޒ-h`W 势w|  ]2ܐlZq_0hpΪ?=f/PpBfjÅn޻֬ CqڱW=uEą`l$Q5hDC4jwLU=YNTӊ*XK 8 gw.mY4sQ̨& KKz4EgA_y@DqqKh!CO1z4U T`{3P.@^[xh^pZԠ]J}`\غV X,KZ-%ӺÐ(Z'_zLwn}QdvtG';?bO-.2ˍr^l8D4@˜ҥI]zD4_#53*۰jLd"%-2*KjsnE&W`,yJXO#?$[Um<~+P in^"]bվP~/%\2dkݜW0_e285iU6_>(R*]K=hs%8bݹFibN0iyFb$G1PP6#C>+/ă $6qBȢ,u9p{x!!gF>(pN4_5"rݠg,aDGH` N=fA|6bjA9\bi G]AW[ֆD( *%x[%S^?/?g%[ NlV^vERȆ .U}.E֣OlOp(%%2+5ؾQQ_{@YvW)n'1+GQ,ԔnLmXcw 㚩@-d+_hgvZr%PO|*cLCVke)-xhALDQDz@\= &!oaŊT<TUuhgU} E,> NW}H0us#qfnR1e3[+2=Ғvg,q(t]54pE64rg:}޺)~8 &d"UdTq{#oSѬ!pfFLɱN>@ ˏ9 e ~\iTr¾c}i (4jIKy*([.ab:7g5J,P $$n6Wiԥ',J6YNoJ*.:3vw-c2)0IV0 3߹qræPkDe {C&&E~^ m ~Dg\4sYDcw O>Rnmܽ.g\↭QfS4V}{=]m3Fza>|#\%C[ ~otSZ }R,0|KfcA=!v>1L.)??-QY=c'XGe(l*{V`X2m[Eq:>jV%ISMb Հ}cQ8Sڀ)OUծΉf4oM̤MAa}6gVߍʐ< ^f#q'_}%y⨒ *oՇt "f.S]`c25{UR_6G xtE0&VҍsIm=oZօ<`S ߋo'#66Յ#&JIPm"8{LkL$E+aQ|fC^"(}KFAMWb撧ECDKiD5nKF㌇ЄB-zv` 1 bc,P56)9wc.oCǀ0v6[cw$R\l%e%hR%dɯ2K5t} Q͞e)+\/ndRfMΰmhxjZƃ0]4{dX!av(sf7iTTp(|*х1on({e} tR2&xa8e^Śfj(4eds0acъuf`=N;e"1M8K\ae3M,8=W턺#2VfD}5+bzr[ 5C\Z5iI)MR(n9mU(Y=I;S$Y X4DflqPb "}兼(2RxYt Vw)7QlgQmrG0̞2>79-Zʉc"r_aq%7E.'EDiȯ$HrGa:˾d[v⛗Sr{ک2+`qƋ&p_-^`i Dbd̒q>Rܶ-oR+|9 5fZ5KA+$~ni΁iMjK͇ik,ϡL5>q,e8Nj66-Y|IJ,O=XQR=l~r˂c]sr3&48e@^r'BȊx/}Qq}ׅ%2r( qb3Ƶ\&'ƸiEf"M ʿG$U3jW#4KAn컠r'7A`gDWz1xgcI>aU˝8ض3tOVȜhɨZ㪝LN̵q{[#I%a<)3>}sm⩄LCb;ͩp8aYIJ%/cge~ɨH)8b-J≧c"xnngoߖXO=h[*VGuI ! /,7ؚϛ{seQ}mx S[+G^L!`ƿ"2|JT1ţ\(oM{+ֈQ&k'#fn3TW DLsRn[sԓRuhu S D)y-h(}C]AU}^{a峜X7S^v'L*yS8Nd5gaU`rxkM2(wm z m)An- Yus(T"\e(4\] rӚwi^!bYqc#yьI%XqHYobDZqה5aPxj:u7h}vdPXTLBn8)_Į:F&3=f_ЎİS'Zx<_6剔H%yſm{iV}/-H L{AS.ŷ%#nysIG3:9~Ea}IDp5Xd3fM7Zfm:DGSmr`{Mu/'ճ$~fSfrw7/;܅*q0"^ ;6$uelq9#xL|gIuUSP)f}]r -I._eԬ(.yM=yEe#8{+\&!9PwʧzG} ';P({r .TJn:$ =b0µrdt&%!S-?cJ??R3>y%fIW_*[(1v0{PQEϛ1 3 m8FJM?CůEoѹYlʴ8Zp ɈKm;?G,n:6nd1B]`br"bB(bN=xw/yVm f.rq5]q5Lov].bA&PpݡΤYAH)z@qy2 8k>6a˼|"O"Ep^7i\"pbI $%uM3=*53BEܨl vՍ{7D5҈Vl;t.`W6Rcu qSMIx£>#ncť(*ݟ°RWn·% =j4Θ|PUKQZ5 YI/Kbs+ ]@j'tGC3Qa~_ױ@JE&L||&k~#_Ux$Z|9ˇzi-(5y@DHUu| _9Z"pG'$Z>ܴN<`/X=l<:($N!Qhnx`f*޻$,AӒC؃穖<=h$՞ѵ`q ׽aL{ `q22k)G5CuUWWItok/ qFQ[ae%le wu0~"^ []ڃ`?[&+50{SX1'Oz􎰣+L $3s41/n1wmf)P<#(zA$~Gd64koM G-an' #Aq$Ց[w:Y`HP)łxw ˯h/lœNܘ/vbS.+/3[#r`Y3i'e$~[R [Mǀyr+alv.`B4Sv7nƒ`tf>ol}vk#dS4Q#' b7"AS!;Li"Xf]^ipaz@}}I\+ZhFz>cnv 5RBl)'Խ(A8Keƻ{(5vğO0T+ʹ+IX6Y\ tAǸtg0DJR4z[]G<t =kKtݍAPNN!8/\sb0W#y[t,nSPRJ.ce5hŗ8P;Duɽ@'fm:0wb}ޓa,0;e3 =7XW+;QG=x:aAWE_=2D\md]{BuOxgb(/a"Pi@Yugƨ)g' h?"Zb?^ly3VcʌoYt6Cv>+Pq^e?S biATfN?T MfHKߨ63X[]RU%Q3V9\_Nɜ$yCX=JF!x7oD)$*m^|;ͮ̄LC)HHB,8, zr/{xvS>gqxQ/4wy0ܑ9/8Nv<0hO1Uuq"rPl}mDόq ښ,硖kIݯAK`2x{v4&!K\h>ā6ۡ "3#rom|#O|'! eiBH=Ntf3xr≻=\>o5('bHLs)tuSʹz~> L:8 $.lC QEYdbD}LҝCG2!hmCeX/(y54Q?Z7kl\D:+ˆBB&l2~253=DȄI/̡,3@޺g|]0Q,y4!#&qIc`ТXbؔ3d. 7sh)hFCfmOfx\ŊxZlfOI³4ĩjaQP=\rwz}\5Xiz+8ez"S+?<aH|}7 )@Ъ_l$|=:މw AD;"yاzcwDߥQJBIŽx)x#T9D kWw<қxI Ŧsy?W`T&V~>^󜺳Aޑ٘#:5!l Md&C9|)dX`#P=:H]0¼*~{>QG\` }1(K%N)LL74 \2uwSS${ E`?G6:&UC' * ۤ9AC ر#[,)L,6GĕkbYX4BCNnBM,,,McMAϨF|mN,nQCsx2T&fիlho*&ql!4vlAm}ŭ~ ! )l:?H @ǜ\ߋSYT@gP7.݋mj@+!vں:fgFz\rs˶s!TiI#`<]9 MD4k?ͻn.Ǭf=G~(,6"hWn`+s`utCM;} OGN/6< ȷ8Hwm//"{wЁSy($b&M3`@ھ`}d __&\}<=s>+0D:d&:9HNvl iw+.{2b4o9(0cQaw|G$ 8!K/nNmXo[)ԕuWID5s ##q7W-ɼ.:9N[ G+7~?~ҷ?4yqH~Ó,#hN]z%~!wuȵQY BmӴ ?ˊoNK{NJ8^2x3 Eݙ$f 1.!u78}0a6+xӛnh H5 _;8B3h{Y;򛖛4^A5g{ROT:M.=* $7LTA!}c3@>gkRK,oO%}.>Y$D%P;v1h}=jK\?ܻPo 7a|(k+ 75Rc/à;m0꿷е)Lf:\5x1cu᥈UOkJg eMx@\Jnk}`ɧ5ۿ#RJ} Yp-EҔ!E'mXYU_r4VSZD=G|=S 0\aMxK)3L濪B,;)aXKdhQcm sSX]n,goԥ ]/c=Z3`K  =kyidB&Euaׯd/oJ-s}*g)X[q:5NmR_ \U5u50,Nʂ3r_,R3xm?k驪BeeX]o<\3&+o\ÅP;+ %kdA12(u(:֥/לhOۺU: qk(UXt}eǔu3\НۖWz>9 l5GَǕ8|4LX{{]+gmڕnwJFeLžo_ږ9[1^>IJ[/BјNƏOox*嫍3ALF? j~" (W m+fzVbֹx"&(^J%.'hpHoCw eҜuܘ?]6sHO4y Jù@^$;z! s_vZJLH~^pVtJ:#Ln@o!5["KweGNSSd( ^Ӟ3q\( : "siʂ|e$"ATkr="_s l^ [5pQ};oBP6;Z.ٰa.w/$8h+mf 8+gyP{''rcg$ylW0Ea8MQBY:5w֩g ѶANZ}yfkVjHسBZ#$(1t`hH *'/Æ\$y >r:s+k# 'A=QeT]2nʟpiX5A=pn|n }䗓91GF;ɓiNst&yFYl^"\ݩspƻc;A2ý^z<%W@u囸WYx- p(eJH]]y/ V )Ɨ~NJ GܸFc䙣2-b&xGVFiG.8J!ڗd4ЇCo}gd99LDS9eh(C%&w `@ZU *Z55rE!vp hF,UZӝz˫9ï,X|}?[͔~ Q hM$;-2HPsca=ީ_43$˖}\Q$\!WPӅn qRHjhAʚおIݸz3T.^hJ8y#:_2lPf5i"@uϴ;t#8g;oE"r U;8sB"tfü]1bs&&7'8\aEJTu6}A<#Tu?7”E8)/l oL + v$' UkJxos΅n\)[Тӱadބ_]X(CkZwj!-6Oؤ0XuV̝"ڮ|“*HfnT72В=gdHS0G>e_ e!i-qqYRs L gX؞n$[(: 9% / [>mkF+IM52Z-lW֠ٙP^WtK~isC_sotQkܑz:\c]ݗ inx%q6ߦz5X(!/]w(bޘ)QT`ɽ )Bͪ| ,M49Z;%'Δ!Hc7 C.dHXAE@& (uV5%[l]j?Q4|Di_ߺ-x6~K|>ȳ !" I<3ʇk*{1x=jdLҍʥZR9gK#u.7_TJyaa4j&翞! GwK ~9kPMW'Ŵ9J+UhjY|n].ec}6Y?ZX F2 Kwl_buh*Z]R]jtWϨBom`(56 rWN^{Ô 9NtSv Iy/f(A=O#X0M8Pg4;fdKQb݂;U椇MB_ :b S20h@ڸtQ  D/"5I)Ek1X'.dsҲW+CKU`ud_PI꟟7K@‘anmh] xE BJVwr_elbw֓k1ﻪ\ ƝR }Jĩ$M7Y2e) Кac\sw̸>n;[jwTAT((="jx"\!p.2g^͟5(uYׇmY<_4 œ]4;|_8l/~$}`s0K!#mWVF3$DnXdFIv)7[bfCy4-y @I~+m)зWS("a9]l䰴q,j+ixA (j;# iQd,AVA;U4GQQ/dh4ydɚ90sOv`MAP, +StG;2|kﮑUču a\ㇾ6HzxbKx7}aЦi[ hH2 åH 2 %*(FՀ) #d \^,I F}E&M!#Hkk;h4\Jh_0]Fwj9%\_Zy.%F΅Jki6ck-U,x}?6RЬ_`@㉲R,`Q}]j) 'Iv%8}KnL M0_pF8^H.n) \$Ҕ{_ئ<&סcX'M|X|ٞ&Uȡj$ºtpTZ0;:?FOqaOLc/},)+D?B,kOzzt1/[E?Ӌ$(BսZɫ5Oc /5 õ*:f Ptn+TEO'wշ*gG:7=-~˃iNL$‡ b G%Q-duk"lݮj=fl$Di9:hJ+1[ l\@,RMGo!Ox֙= x-|YxV/oTAfG?NgRs97䝤טtFmpF;96/T׸ül oΣ'q򳜙z=h}RUaJ|@u"+zRoz]nxc?Q p1A!nxW3<$_F.9!(dLa:^NK T w\-b"biZh/W[!_/'ĩ3/sX#sE^`475 , ݽ5J@ aSA;x™cD8%mϰ !$O-1m2|zRn`DrY}ɦ e Xj5@Qj\b 5fݓ2lhoh3gd1zA1[TﰃS}kAMPɊYܔ GV"Z5%$2N% `F~BFZkm(#R5]QB~ )^>7$/%l:e'4Yӷ>>:`6:'+:`k4JL5'nv1 Q c#a)dQOE 계u>;/@]ww74Ƃ(0xH6I>M/AU1˃R:eh>@Jbgpgf|vʡbEo;E}hXj;<`XLbe B-Yt_cGH< g3kq/a %sLuqp%-$QGeëd9 .V 5O{//9i(He|5d4;ZNpS">ƸrL"8NfwZaZe*~3*6. j&C9( ЄOԞ=ECI9AvzNjQkv&¥XtV+ ;.QEh:lj0h=uL&˘{>ɎW/9ՕL*sm~"3ud]rbޤjU:JDC=&r9BN23o@|k̎%E`@@8_HXQX(udb8R֥AJPݺ˛g !E Æt\ah߿"1~'Pw []lSRN A1iZ./+nQ}޶7R-V-]/n~ep]J<׫oa!{/AXl ]Ȣgڹ=Sa,OkCl(BS܉3Zi(9mP=ϱA-Ε&ob> YȻϬN("IwL~TQz9luOWµ}<f Q[9@ocYJ'&uY#QN&4#'~؊pH9j|>gqΙ"^h[oP%0R1֩w=$~K :zs#kV r<@l" }J GSPoB&_;j⪳_tΘ%9ۦgH>dT j?8YyB7:t'gۤl(sPpU˧>4{}Y*p0s9|Kb)7DN&ﳘ8lPl{r `_8Tp#,!\YUCpCLծܽ.q?%K: -MTCtGQ>H&c Y+X3MI7ӹGxv Įnߢ IN-u'[6G14ib}(dp@^6:TDB\ܰp1Ŷ᣷d^Y2Mi'VpnI>@ir)gMM߭Ũ*<9e #ħ:a%]fN~tN9n@KaUx]h=VQ%7twcz##fb( b<_~vyy·3Vg 595AO?W~]dրeoB۞s5igE*,#9u*$f'<>Ƀ?{"ߏ1c}SW!є9 A:dh'TFrƧ&l  ,4_ԄE67X4O :Xi&\1_#C8܂ oMYJ]Б3nԛYm{;qJ`&A)L׳Le*<.4<_;Z]p?HOUz%,35 (bfB?4D;rR :E+J_2uef;t$+i5#b.__㉂ -_= ($>NgZ [a/r|7R 8 'evYOI|O^}dj>rGF6\P7w*p7]y,.18n{Cl?c+NJ:vO53k-!P6#x_ީ]׆turRrc-0Q \N{t fSŖ*c ܷh #8JĢlWzn%V'^:Fh""݌tI'1,k;˹,O)mj6got ҇7~98\Nf9u`-tyUÿ8 ^[]1"~Di2#~D}<*wTʁT&-Ȣj\U G`SRXֵo>qVČI1ic>A襕~n BE<35+BZ%۵P&t˸vyF,1'k,aaUqxD^ m AbHQʬz00n?N$UxtE򚽯[Scza>okC>/ ٪ zxd hj$YyjI6ڸfHkbTCy3ńVU7&bsM1ZUHUv<_@ W'u9q=CqWm״8pc郞 vŔax΋5\<2hX 0.sӛͨȀ6l,[?֗ڔ퐾0w+N7ԻU~*/<=N}?"sZƘxcI L%I\w@V^cfa?TIC"Nȥby"z];]/0{) @}'Xd׺RQS"͞^얷pr]ob~pGՆxzM3MX4ܐrs3O{`"8`i{,QE@7-f4qUBIűVXrߐ胥bQ^3u(EWYpp+@]!up U^/a- 7 rX_Zc_|#,렛ɥ{J)} Ԯ њC,}G*NdARcD8=2 1B7ij\&H Hrf?ãɣ]i);li&-z1?!6UtVR̋5&JbJ(]]Vnζ%{U?Uݪ5σ0JHnfS=Ǣ\Lы=P ֬VfȕIyhgCOE5|i[,~Fiu]m&j~ߺS.ݧ D}J(`b.tfLE#lEi6b[ݬ]UlXIhA6I93T#NAt{>V.nb/cU1*o9ij= *8Z扡&;UiwZF-r~2rg9^q#[) x笑mCVMUG'zeE\甚iRXص+ac53ڍOOO]ç U]`*[ rok- ^ A hsAjʕaYDc+Av(뙓?p8{F9BWhlA2/fi`΅SZ?P>{eD՚ 'N(p&SбusSFb2yYte [*>h癕q*aU}珞=)V杊% ?U-`0kᆨIA0eY%Ps{`^]LP3j&P.۟;xG^ɕa6^snPokrUՍO:|ndHznnV'x<Z53kޅ9a#[H.pG2}?E 2A i8AL:W:Z)tb: fDNi'v.ѕJiiE7+&=uA0/ ꣈]K" ) l!a) ^TQ|¼_XR^1QMxg+>M]'zuxf$7*.%pFW߅ac{Px'Q8+}{S#ZOiֈTN s|;=9cPWO%^ow8з AHNELyr4Kun"~D.5,{zN I"N[&awˁR]-:;Uǝq}歇sTҙŗ=N Z~vm h6sϤA|=X I= پrkk$OOJ&Qoc|Y?fv &E[."hRL@Y,8"]m7F=mD/LKO-4_e8POY:gP#H$sX. `,hrs}xGr01mN6[ 10wW5i[/4gLYs(GQd[ @>$>jCon 0&Izv4<gnԟXFoNf'0jbN>8Ux*vXe˝fe\e*p7 V~^hUx258s1t ȒW;\?XFН ēQaq.{~V[~-Cy]ܲ5{^blCxfw^)nIGGGN65C3dDA65 '_fb%9bOE QB0bAWX =.)HDcP s{U Ff&AxM\&ԅ!Cgg.^ZYn;+R릴bWW<YŁ*N$ Mgj˾"\[Z㋲\Od؆q_ʹ!Jф.qz;r*IeClT9)AŰgrk 菍/w$xi0JC / DP,'JHqp+az'T]:aaV8Vz6z{ta}""0\bRhx6 Ŀ M೒߲F{E}J`hkbBODgF1#iL Q_,[Nu OMuKf|2,6u!hl{ aL 0 w;: f}sX󯱺R k &Wz4F VHބG-+SvU6=sI_&:ө6o\$l@ᨍBh)Dٔͫi8fCg +ܰOgN/UZ B8_c|lvBB׮U 7+'vZCr#耩ѽ-hFYfz{@DL:;f|G\R#a#Ps *poyȁbH(G|`A^e=<`m^ .~yF luSXxUUGIMˉZݢ B{ 8a6BzWSO6 1,-!IʕI~`fw➜#p Չs]Nppү _)ߠxjg-1n4r7Q,i\/S>+`v^d>_Hƍ.קLC{'D7`n8jqāRS1Q*X>n&"6>)Jݚ PS 0 a{L'E;֙D ΡmX]"t]$s"JߌӼOvnύ~/,vhմS\ aE1t}(\Ia"Y,x1X7ս%v#ײ"ʀS,;HN4)q,sg B ['"ؔڊAk=chuW٩5V, _oG ``PLn(W ~_aE*U;'*z[w#)|z]r 繥gK? ܲ_kn_ig[S=.΂pؘ8L]PeDGj$ sZ.0$Ȗ܅MM}61'{[ ;5c3ʏh@J+>A){%wI +yB;%ܞL˲.A6c4F>UnA|?e')yVKm#g'9lF՞V֠8D өl,ǛJH{lʮ4 ^hEË:y%$\gk{3X8i/1V3#.QMir>֊Zﵩmb56D[iTjwtcK<˰#:@46!&(dC9 Rݑ2p¨@bĆ,Đ!G_XO##WҾKT1,%Gi=,PDFy"DL~qPpfgMvp@r mFXTR5ދ`(XRc [`7p +r%<k{qbB3ׂ5[,zU#- zF]ir8h8DGzW41|k[X?"z2g2T =Tod3Y ]IN~[t CI?fr:xuUĠ'2F|D :}T"ߪ=(DoVo÷! Y 4NI# q*2WϤ-No#^ c lb;R*?rڰlHWsL %!'Q#ɐ`[{7Igx$zXOaAD>"$MV4*La*KƸ[ r'jT-0'5S `#J0_?J3qH_.\Cٮ@hD A0̂Ayaxz#SkncTu"Ŝ8D:z\^3*]#3]X y]" ^}\[kCy~+&5 B)w/#=\~B/eP0bu{}nAx'+쫉,E:bq m_i툞ʍ0/iЙ*?qF{:61HZMI V3j[&``oBٷSr): J4L"iG.3);C;048ƆD3_XGW.A7XG&X9$}1r|0Ԁ$I{D$=eCj,q3tAǷ>EQ墛|#6?Us!mU!Owl9S,l!_{$Vۃ+}E=j[y v &P ٽ}IzDL/۸=m,zoj4x$Ӝvmy2Iur#wY 4A&Va1`&H%M'~A///Ǘנ<r{\lʊQiBdm9˸͌wE,c7FE`" ԅAK^ eJ.oHiU7a4oDvNvru< 2jH $6bEmUԜF `QI1] Ji62S_^^8{E]I@O¶sl`ZJ߹!,`t׏ \a8j=$ $.n %玁N0jJdUtBf+&]Lɝ3۱0zI* \zϔ,p(73cȩKn`cEϤSo&H~$[xl3Jl(؝|[b6V (46 a-UȣU!̹RZ9tP_}h 29<(R2~v@ǩې/q6iN)CS!D#auBεdg-ڴ8u0 hpIPnM+ؼ1ڏv)hJĨa^Xn{ED P(/`Ki@xtp72ȤmݻK>1cu1LI.X7e5"qcעD&2s$j:)oH4--o0;_gS6gɇwß,g5Q!X)61`3 _+$Q($ fi%&iQdVY$Hf0cd󉏳6cv?[OҐqje,=6ʑ7<@Ǡ.氡,F1ȚŊ-l}l!̨{pD ecyJWDIaF;b3;hk3X$I˜f5 v5̓"9Ɵ1Ť>jz/eJtI/3aЫ^97'y/0[s֕aUP2z>lifժ`"> 5*O@[8T}Ֆf(xoZCi3hƄ}@X Ȣƿ7 =vIc1)2-ށ|ߣsp,Q{nYJ࠭U`͂Vs /n/iе\L68J@fHM T b7$\=]c{5(Q9 ʇ-01sjjq r䎏VUrs(4uV 3,pGO3ق:B|Ba/Uv;/L30̞R_mo݁iSqϣMkP}Xݠ#egf)OT멶v;Zdrlhӂ|$~G4Tp] t^A4kzgh .MOғp)԰m,KDܻ䃔G"3pS +#W3֥n3mw iVV)r6x<"q3(X(Z!%bL f%ra{:F,i{="[֓n WhfఽDdsG[j$Ћ,nmG|m ݨ:t(=MHxK V>[(y3 떫owD^a "Xj璼 mΝMVLj*Qqh*vcѪx+.*6@Ey? #L]* |@ oխF*I2VlVz(ZTLt.xG,GZ63βmm/Ae!F uldSNl>/=$&l` in' ӥ%+Ǯ5gSq6 Mz }T 5;AlI:?J2pZ* iO -%uE 5M=''n|/Π`)4?Iq}JZ̬ϯZV%y(e; c[ޏQeBs0 9!F;ߔ8қw&Ac7eBU͹NQ8m`bDŤg3;/ n*=ohR/b+Ռ9g|8ͥz7{b |s b`&y5,h(/+5h w\υ*N+Q:Rfé$YOZ&&$@obӾ0rڥK*v櫣 \.+>F`erS=<"q(@Y{)@1\w@}yB|R O`CpN%#I~,Ej|_"VY8||&l_kg'tq;5b^ GE5X 1'Bڌ2ڶAX3Em3rWH5cPa: l0Dn 󄦎6ʩq){2'=/28ɥ=R1}I7Slo?fNJ.T ɑ y'TC|"BLK9'?]o:M3P@ .r- W(J5>P~\e&?#20)X҆iCY Sw͡1;U{ڸbDm!:Rz'OE;W]j7Ld7ݽ`HX+zL42z%bE"e}' Z?TwjxU$:s+0mV2 Dft^aL(r bA @@a詒-c{s&gH ߓ0j@GM)t6+@]%UھTCAW1^P&uŎnZ/ Bk9/ ,5(2"RsTW KǠʠ-S8m bBmA=Ȳ~;bx]h-{!ϗMp |^CkbK=y?BjnDݱx"ퟵ~_D;݌[{3|N>Y8|X!ѣ%@ܡ{dQz{\XM}(WbzI'M6g@u' PI~&JT -Z_q':%iw֎I'{~U)Ow*a#~kA ~hNoTQ}_Nm#T& DhjT eI7F^hOωDa`$[5Wjl3<%XR[,ק H[U <&2(֍!'K9?Xt6hdc9VDXDMbdKbBK4 RK^q6VG-8ã~dUO% 3WXIy$b4Zyh 3B磥\sp4f$kUcwzZ6+98{~KKU G+,ls09"zOo+iq$u9s`deKp4P3`o)+Ot~ ʨeAO /PbxIxhM|-i1J5ɞ.mrpYXAt9hY/c5Mj7ߣ~[{z9ôc|vko1{Iqi Q|4濉oe'x{]ˬs,4MMSy` ۇ_y,C{!"c∲|;oN6b҂:BG1)wq$pT{[Yf.dJj ¥R&+GT17bgQrˇw%f6گ=ү X6K&W~{-QiS:].85B+evrΗ`4*s&xC(;涿 =c0u6O9,7_[aW[9kUa8bQx =f?b c|{?[{Prx#NR'ջȣlے]W._^)j; fZ.vMV_TNlc2`/ZgS`x;$h|%+gU:4Z.#QUOXA2\l͎a 嘱a?Eb`Đ!R#ke@N?6.<(d#+U~GECW٤5/24ޫwPp^WTx/Ƶp&{/kkY/^6AR7M)Izku9j;h'Ln^yd@2G󱂨`TfO[]㲈M2*_L?xde'\ոoSBEbQb :-F ֚Eq묅IDu\-FYt`8@t<&xhQE^V\ |]^: < ?yczdA޴ISa¡13Qjl ׇ{g~o?13[^M|!X✊>?+at?aג}gy mzK :H4oIk>ف+N-1`n]GY/+,##"WZ߀ DH:QLkTZ e.*g ] xw8ru {9ֆ4Z4H!]7ӍVͨ( j{?2~zX^ؔ%N_|%$⚞fz-!MM(x]>:;]]7ϵ ]H:VRm:RΓx#ى leS.y,ȥ Qmƣ]&2ZC47V.]3hmwD8۪秃\@d,`Ezdgmҁ)\6p#φ.= J ;T =˻#%] |ƐCFc og!R&w(iq̻x \ \ՠZC-H3"WEw`%aH1Z8߇:y`ezW+$- 0ylC+)Qe &2T68\e}5!D* 0E0+!&3 ԇgq<&pALW:8r!&E!\|IhiO-C·=K03WLLEv,xE@ZrH01oKŻsA-Ң >Ԋ D${t\] iVr: |kIc B`2E8r~Ə6mW.5FU [d_U`]KێZ%F}F~́%-SAFxI`^ ev<+Rv_T T%ajjykJnEBDF{eƗgf5"Bl- 30^)!{\RdlU? 2r[A&#Ɵ ?O@(r mX!&_$v@\d(l j\ܗ#\gk o/*rHC;GpGO'(uf!MzK=~OœZ{⩉ Kzl=5T8a}<)"V5mOA$n:  bc #jQ",E,hYzZ >oԚAbJ,xQb #V&$Oٲ`@XN/mۻ;G4ϳKVvR}\P+ i.*E|-Љ$.5XM}r5Bɬoi3˲$ 4eMn)03Y~|Ի]@%jeMej>;b(ZKxnHD-ۑ{< \_-M,azZ0YJлÑW %{z_a%hhKXE;PHі4a:9[RQf&7@h7ux]-D]\t(śj-K@yN 8_[sr{>l$'T_ѝ~"W*y,ΌYϺ_afu}?D"ƓAcኄ=RXNi\`̕E@_wC1i^; V6)`ځaiy}BpLJd=5j#3(f}E,G1ZsPr`?sOge\CZ 7ܵ vӟ{z[Vê+̸݅`.s?R+6CbE*dL5WHGV@uJ?i}?:N/֠-?M[˃R1 %r6'&֤ K[!utjOG%-r1q1޽oZ8`f$;q+jPG62vdw{Zq!whjbDm6|C(Dh^H1LR6gK6Cu"aWUQ!9i . {E * #A61>UASpj~G,ɠ~C  7) ׈!%REС;zz&q/FoՑu+눹V|=ל+u? .-za jq9S1ʨ[ u,Zg2f(nds54IO5D,*ݷ,+K`5/(tqлIÈyRNZ5 +n֠V3j5*;S02>IהJ#1|;xIpsO+_@-܍em`#pp2A|yeϙ gƔ_|E[d/[ҘeL ŇntɔyJ!p_l^eSI7h$ʬ(d?hx[j\JVH z"O `% *9{8Qs1H{ j"_1ȥ9ƺuy#GKڎ 88N`P;of80i5` 0(ȹ/֔kοZ5D s/ H*i9ib&5]-y/^Ƀ!'Z(z :!cUQ"-i'~5JU[(-K@ŏaqeG + 9.2]D~wNr:# =Z9*f剝0&| zciy݄8!<\&h6!r}')9۹I6XA g?*UcĶX(Lȫ.jc̀e-u^U8|83Ьs[.XM7c psņ]GPMV@;[3U=Ya8CZՏ`9&ɼZkg=p!FBXơ.h+u\ ?rTi̚5vR$3fr;c)8%5|j\&4-t)!ds \V6jHH4iCmIag;?uWT,:Cyv;Lύc#Tk.nX_h!7@ MVjUP[sYr0K<$H2_KmPtr U;Qǭeʩ?o'Q}alH/-J7ܴ*˭Am%͘nxI">'iXGR`Ӵ:;ʼs*Jwi it %2JR}卣*FB250Sx=ً ¬9oB'.eC)qȗ^g q,|M*GI K1DX{EX/K kR;7Z>[.D4yĠjڦCLY_J/c`ܝ+m /?uk 8+ fUOX=͛^jMH:Ri&<&;w215s|f8|N۰CV&0J-8a}=RVNF/7 XoD.t`b/-C87z>H;`^Md;vr릉zX.s4?a> ut$G=2ihȞ?{([<* -BgB_nN倜CQi=*RA4.\Ρz .)Z,Ze.t|ESr\mX"Sͭiu3$8t?VJ< 9ѓ{iU:}-o)2#} #MW3eVH$971S%X(Kс~meNsO myM(>e@弖DY`sK9-rkط}h!?}0BI]ˮR ӗ;ma/dYW@/1T-&ڒ׸Ucϋ5dY 0%p8 RvL˽ Lįҳ6$eRB[>UdY!mvԒZpy`3`vGuݯs;E&s(]#5قzڥ5,PQ:N45Xbp6Fg2.O&FH٘/K",Dy#Gpl_5 AQLfSM3t`Cs)ʄ6TF's`/^p&]Sv'Mw=I Tfd 4\63.z^aeARAVUoAݙq+Xsp//oto5+Y.V>}cן 7jIcZ|m 3W-OE5Ƽ,|!T :1f6WMpbU+Yd|8ŗ1] @:ǵm=88^="dzF)3QVx2=sl8 A:<5$y )2`6N3OK T6GF;m)IYC+ҒhNs)H@|)X.}vwRI@FzӶd凅^icIH# | }BُKumX`TMč[{EIU[f{Zces6ȁ81c7Ħ^ʻ^I %:rEɍut/\=V^qu2L$K?=Q(C>u}?qLlXcmG~ ]><~l`F cG:Np:"ož*0x57X`Z=&SJQ=9f갎fGK$="m-CFxb7ni>V:DԖM*I&HyΈuג ]-~=:ֲjEz.(yVͽP*=So|tG f,]٣F@zWa"3Rpќ~7&驖o$W^stBG;n} #iĵO~I:Zܑ q$[҇ 6Fh C@mQ7S?P]Ux/=t<jv6uE_F0nӢdn&шS=CCPqz04X, m);;5w[s9ky-ih#ͭ畼qPgFRxFQ8Pp}U|4RP=A9<ƑwjR"eWS R6 C>k|!\NxQ34:-:TDIY%W3c5XIuXqx0hkGO6z׿pnZ0Ȫ92[L#ء4Ʉ GBK4xi+ՇDŽV7*3hYe cHݪ8HT-!Tb!-JbdJWqKy [ſ9~m;.SGUC=vCuCk4k=󴗺f{E3]IPA}<2GRCOA^eMP43-1dh9PY?ȃA@|rnė(`]ޏ<xdu\۠ 8Ǜ3$g 1xX딸pQq z^LhξjJ-PD4]3ur3aX*5 ߷xF uܮ8=v\ܴuH:o})@M oMg^F9Y6԰2?ns:OҸVI5뒦EXZw#lTN'Z;vj9pJ(JdGpE(׸-bx9p6i pl3G.*eӂa[D޽Y/&QYEt%._C$mG>H|LOQ ;D"-}D~ˌx_5ҸpHgu}L^zr f@Xڥ-W[ѿ%Cʨ f_/_o3}[\q]^oct}H~<&a[A7^),h3Owc۠TpL}_@W/蠀U$U ،H zEs}2;#ى:0ֶp?:utG追\>SyZA9کr>_i.]V۳\EmNegn5OYB!x8tgs8ݫ!+wOa R۹ؐ镳'}N~GrG'yKZ r*$O)7|NYs v8$IҼf MQԜھb9$>aw]ϤQBs'y@pQd(6UЕ{7 x) ̢'Nϟ=ᴹ7:xy=+jړebnm3u6uӗޓ?.Ĥ)|wS"A.D)5Hz_`M 4tMBZKEy7i$~L{ <پW*)SxC_WkVo>#TE>췮49Hz3zE7赊]F,(i zGtXIB/DjH<[~D/e|A`3~cR0pG83"0]kᜫ)ՑT$h3v^w d2VV`0Z3M7E04OG߂P؂TQ3ƽםh_y TH*%Po~/S0oԸcev۾AWbqA)\xZJ+d,k z"ƻ?OR[#,6@z6T M9 yYe8SƼSІ`7*ߎrR@5}YZ 8;tt0?Qg8a_+;.s(P.D~`ճv¸{ OSzb@G>*w;㏋78Q {3bjI.[ZS1q7}4]P) !!!i J(iP>XCR,rtfAS ~DAkN3#F;O}yZ_!Q;? )0ܘ* a',#|NY4&a**שfCcpd{w)#oa䍤 P!G>oy CxwصwڊĈa: ƯEArE"q3bPkTV$ 6OlGjvX:-K{M%·)Sys6B }"vl>22Sޅ p8L!B~Xɛ# Nj+,cRn )3IS RXTI#oҿŰwQ{Xk w9117!yw6ä8ʊO&sS º)0)#H*FvP,Ւm;%oVcmcuYx"5qT J#qK6kb2{x.B~#砺f @>>$q6Gm̕_?_ݻwvjCv-FWKfcC^yZ9`SP z,S?ӳsb[$)UcUϽ"|4htn5``ܒG+3"~ɝy4F@ .$hxιVtWЁĮ}DfruIwc.әuq3 TO4olnΚs-)e fBoզͮz56H_$ؤEO)[]t\| Lߺx6{<b?gAWPq`n}ӷU-i)5ù]QjV0On:>~w!>X&TqvIdfCugg8= ^}:nS@ETڭ >.t+ch&OW2վfIiqaКs0c-;nS]Y]}E)%1Isq)cK87EyDǕ0g;wC2ůmHT"HٛpK)nw8wCp[Q_dՉ۾4PM(?6us=un++i2'ӲXބq?4 bH()f3$J i%頔T^F*3K )hw AF$dEme_W~Πмe_D, t{I~{7ᰏGɵWx>n֞9Oz./~̡6Ù F"/!\65@眻SARQ RT{ڳ\8,-{ۀpmcZm#?WXuWQyVxϣS}NlgXv hkf*S6FP[s-%8 7QG۠oQDY O8sw0X(dȠd^SjQ^1߮HⷅF^.l:]ΤEQ|=vF`|n/.s0iy.zE^)c<+QGφo 2 gQq-Y01d'h2onn7 [u,)(dAh49IX} XNfI%|ġp*>fsЧX=|!s?{;wdkf=|!gېy^%he.lܛr$ Ks3#ZG7X;_᜞ۏ\e^B9MZN<{6 9ܑa m2KzO)l tK-Lr(LAVXe2V07Uf:f~T rzjk AD!8=9~*u`snm|S]nUpu8˔ja)uMw~sep#\ 2 _֞=p$?󣴷K HI3}HF&.a>}>d5@{ݫ!;"Y g7j3Ja+(K4.wĨW5PJ6N%^5fIcByRf{fx6U :2ܜ|c2(Dݛ<.\C1u1(jL<]NnfAcRg^7~jP41cih%rfҒfxK<)䣧oiV26lqh چR_RA".ʐ4bVnq{hM&W+"WgN.s4i؋Gam-lPQg{2,e^lpRPĒIy;][X[ki0%s'jMN[Ѓm'\MAC$gDZS<^T!P0+n dghOl%$7O(lߒl,ը{ rs@J4n2 BZ6/̠㘻j$ßX<>_OynϟW\?:nK I7G*5I@*cLIA&tM!*ᅥHM}+1ӕsrOf\Py$V#.P ',/N3´"Dp S#=Ԍ\1ui,Ozd_q]ڙ~%Ih*_N މ/X=q 6,L芜pvڪF쟧ԮIb=fb*BфEʛ!򰭝8UBھK #N|Tc`(AbBꣳ&8l HebꄎKGjz"lVF~d,`J̗\bO_3,Hp;.@wukSRlbx:|-:bSSw'&`;ɽ1#MU;)R9 gkiC}2BP|VNu^ ۫z[Z_j _MqļV GAhomwKʋpA.se؝cMC$fXO^c⣾2X-w17?_dczsniIonh|ΏY7԰rՙ6 HZƾ'd ԭ6.2I0< H-%'0HQY.Tew ]U֛( Y܎ kOuœdF{3U*`\BhF̝ L7.or߽{ЈۆNo{YJ<^eyeG]m9X[.1E9=̛[UC&ԟn #t+ưV>߲հ_@DY;RB>^؋g/gT9rNd! #)0?5WE ӻ-7>1ZzIv*0}E$v5E+X.%cß-c3lZC`qahl#`3;! `?RyX}ԟal|}^ ;M8{!AtkO8;ʃu# 6E;pș%8MWoESYe ;;u۠xzE;&xq@H0h^MxNO>C:Qm9 ?iG◨ ;^~<"V(à,kxJkE[ vi7{N)U {eꔯML藍',6zM?DCWZՌe5ȷodjc?ǍצNmIБ%JP bym ($P30.0F!πeFRuYvgqS itl$@ҪRUoL O.؏]=-siyt ,查5Zfne(!e} =r]}{ҁeX[ 3AlJ8צ"Oi(j~$u!ݬ*q#$uXy|jH\!m2qie5HpmKQ4~$'iXԋl8i+$}DYUG[*4&H,ibDiECqh#^Ĺ&nI '@os%[ 0z0l%Na؀']4zQX=v9mXN;[_''*rwhw*Bm:UKV}lN)lrȯ0STEM1*oLr8h#zٲϿ. :% /3N55dח,W4Oy)j%M,F`#a8\i<#لV^0y* <)G(rmY^3x~hx" ،*.DQ~m|Qd AcAWq3'9 VՃYħ̊)ϰ$y#a^[Á47(maZ\~xjPK1gYg0&,f ,W"Ls;. 7PƁU&}J9(֑"̋xs;hy"5-6 pM`Y*^Ѐ# |dCh7,|{"yog;Ŧ@ >$>^ *&v簰jH$:i}kByz%G͎fKz5iȮjJ-o4 X ?wA,L:t 4 7_]|]`ҡ(Ȫke\hePn WA>y$(oeh;B M%% 0 &5x:͖nqg y%~<8}lֻ@6\N qIHU ]V ˄+yu/nOLPCxj5HNFHyBJ,ʺCtGxBfk#[& uر;, &#'-7æ\^{މbvNx|?v1%"~;2l7N>rx-g0+uwvŨZyj/̀ yPT"xCTw+ )g0r9 ۝W!NǤF7C.2~= XϬj oR&ek>biQ*[3h)L(_ej >$W_ThB!čt.zY=5=L:`3B%D'JYټ؁;4*&"GOВAS3U$2 ! 'ߕp{qtI V'>"D|iQ!':RtRD`} `NZ}Q^P&4\,sfHۮ-nGli}S0Wi_F5@ EfIP}1esc쎘N$%yl\w}e=9k _E P=qw~ߝ.U1I.w/ץu4p`XGi!?ZM(?;.9/(ID'̉V褺i zx%FWUnw1\'?P+{+2n9*Z1yFV`'W9tv/Eu=X-='JdhQ!>Dd(6JPBI<0@ S0[ωfӆD FL:;WT&Yt\Rl!J,!4Wx#׮+Vb GbEqs X ({/_p^*24̈́@pld+} ;$shx=m g%҇g4IK3?&Af!lط#"-nv\"E#zج@ƴF8+ 2.&)70Qo` _&ț^brھoyb01|V돔lU@+օՆ)1>ϟQ݄x\cL)^=DMz/G)cw0j,ƅFIâ.+k4!W1^ TO}X燥hkAxCv:mje1pU5/#$78u x>nd3t㫡ZMg6μeQ[PޭYP/D9QJzǚ^e|ޥdZ'g8.5FT R2nk'sj^V{\« B5s0 X &0 M Da%dm^s)7ŖT,ljр%E͒UzPf%-aލ_2YC`,R α(%øH,'Lo& x"J.aj#vNJr myY o|B۸?]z["00L37K2,Ens^3)BaOla. ZyN!y43 K Im%m O-J (h dוqXILT}iDBwO`3b6`IP ϊTquG QSŝ\= [>.ء2 3s wHO1 /ʝ`7 /Q %cflֶШqp{Ly,!MIs'f. x´ָ1>&UFO:us%P0 ++v l˜'3a`Uvv2O&G,8Pkn(~]>Z75F6!g)7\/2&}>#7X-S7`a1'#9*9WtQq) wL ԈeN"(lbCUX֡8v3)% Rx {E0bZصoUeGYv`v=|ХIGG]kjV x'Xv}NGE6K Qk/vkeҷU4ďsX} |7a~ `HOFJ*Q#o(ZpϋvZ c]j(Y*oP p6tRa\BG/*vNo>Z+ _g77KU0)ߏ: >u?nϸ,tl8U͊q]kW94%fi B];si%oW EꥩٳF&A[*Yj. kbi[fycXX؆$:Ď3,M#0/B#^kūRN  (4P}Xqeq憅(\_'EouX1sOedod++A拤(RP_W ٫CPf<yX}]+V9(RP"ce[v-0]@߇S=C@|;w ,<9>ТDغP`F*)tpa,(z*2ݯ'`O 5zoZt5'Au{조EwvOp-jb?Hb ,ɛ.Y*tgm $|%$8f:!NZK|@%hiwjY Ri#g'^Dڞjs泘xA8+GD6nb$tj sM 4<C JTh2THbl/wvۤ >1> Sl Ư[L\. o`J _JL0,OrrhK PX'(,ƤP]'_YO屡rI(%\>NϮ1.Y ra p";~ަ  Z Օ?hç߀TJm|`Q{t0>TdԢUFR t>"T zc !r=[[o_F_ 4$k>7U>@JcH6w;6]^|H\?vּ㑺YyQpñ%ټi a`]zNe YZ