sssd-dbus-2.5.2-1.el8 >  A `2U]6Dpw̴S;swkkwVqDMU}Kl;jːEPFmkA.c055f4bffcbdd8a1165c7549fb2e8ac98e47581197f3cd16c5a5f4a8b7e5073f1c12774f353c6bcc04fe400bd077b0187739cf3a-`2U]9ZR~_OuYwAwC*er zgIW’97ju?\ܩ"}RT#{tL(?@Wrodè %s$X欤9ဟg |CEJ Kv,۟@rqdERΰ'@LNY,,`q({0#Z`RLw]/A\@Љq/Ot>pBm?md   8 #7TZby 4  N  h    )  \   , `4P4 =4( 8 9:b>eV?e^@efGep He Ie XeYe\f ]fD ^g0 bh_dieifiliti ui vjwlT xl yl)m`mdmjmCsssd-dbus2.5.21.el8The D-Bus responder of the SSSDProvides the D-Bus responder of the SSSD, called the InfoPipe, that allows the information from the SSSD to be transmitted over the system bus.`aarch64-05.mbox.centos.orgCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxaarch64 if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-ifp.service &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-ifp.service &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-ifp.service &>/dev/null || : fi%&8K. ?A큤A큤`D`u`u`H`L`D`u``;`;`<`;`<4601b3592d313effe1a70c44167775b06693dc9b72e7bebc718b6c9e8b094b8f09f028cd5ad8b15e0d13531d362fd4f515952a830f6c821442cb3f901cf292a94c0e50c3586a4d2f811cf4c8797d7a3b345db12c37a4084f68862c321bd00d1ca2631eb70e5cdc8392c97e19924dc9aca4ddcf4b38a44ada079dbfd5f3b5c8738ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903cd6780e8d29b8dd5544622f3246c020c8fb3abcaef759312180e27f103315e0209c3549868a4e0d43a1f670be3ebd03a7f4d840fa1ed4df9c391656db8d814989fe877fedc3b59bb29333910f6aed3e8aa4ca6d8269248930bbe1e69790051fc8ff61ba11f53d12746010e2efa0967c251e0adde9f453978392c717dc090c100e84b412c161f48a352d79decbb5eb960e8c892ebd121841b4c074b66acabf549../../../../usr/libexec/sssd/sssd_ifprootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.5.2-1.el8.src.rpmsssd-dbussssd-dbus(aarch-64) @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libglib-2.0.so.0()(64bit)libifp_iface.so()(64bit)libini_config.so.5()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd3.0.4-14.6.0-14.0-15.2-12.5.2-1.el84.14.3`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh cadesvuk2.5.2-1.el82.5.2-1.el8 org.freedesktop.sssd.infopipe.conf.build-ide879ba527d4f4496f766abdda2fbceb0fe1936sssd-ifp.servicesssd_ifporg.freedesktop.sssd.infopipe.servicesssd-dbusCOPYINGsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gz/etc/dbus-1/system.d//usr/lib//usr/lib/.build-id/14//usr/lib/systemd/system//usr/libexec/sssd//usr/share/dbus-1/system-services//usr/share/licenses//usr/share/licenses/sssd-dbus//usr/share/man/ca/man5//usr/share/man/de/man5//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnuXML 1.0 document, ASCII textdirectoryASCII textELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=14e879ba527d4f4496f766abdda2fbceb0fe1936, strippedtroff or preprocessor input, UTF-8 Unicode text (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix))R(R$R RRRRR*RR&RRRR"RRRRR'RRRRR RRRRR R#RR R!R R)R%R RRRR.utf-89d0ef02237d7d1072553c01ff0d34edca2138f0c52f6f24c2cdf35ac0dc6bdd4?7zXZ !#,Ԝ] b2u Q{LQ wF W%KHYa eCށWz(+E,82A`o$SI*o80OI*Zku2ԈS(U /hx0@"^F:ũO x 1í-^L'Lf6+*'-oMn\t`InFActϑ}Mu}Bm:ܯINY} LO-0s@,hu7Id2q-Mܕg24>גacsľ"dl>,/A%bpҪ?5ƚ֎OWCw%Lfmi"#%wlvL+ʞۚipI0e їVT恩sw:Z|R=s.m N[`ãt,N0**&f`.790 fߙ)-K4X׼w/`)W & Pȟ D4rc,HA *Y6wK7T Kha.P"ַuKMV !7$9;753F 콁MǃR@%_P]W72ytZHfw94WrBO;Z%X V]SZ&VfRbqV8^5S/x0h)bg-N fxx}4C©ܠ{ࠃbkjUBEpGAlGԐn4ֻzO;Wb=RӴا̌A4P -B[yN \6^LyBTnY녀c4#O0,VaÎT6ҺEOAdvh9\י>@#lp Bb+FGc$9! ڟ0tM03.X$ˮ1!6OK /H)~p0rEUj`#z/*]AgCm7R,EcvVy3z)z&84[%[oa_Q-{߾@ْʰרyFOͭ?oȽ2Q1£[P S9HG*iyAdmO-aC8![%#"n/bPl0b..B|/8& K`E\T%?W@< az}z x L[vDDUY\ygkkRsոx$pܣ2Ž@<gdMl_( narH 1ZfNڳB3n"T=s^vgnD DPrWFVxɦF˂NB+}f5L)TGdԦ1CͳztEPYi9hgc]ˇj絛*PݩB.>͕cAQ}Ηje7>dV>=Ԫml d8~mǁt3;IOm(3:K-V.l(m =u^IN@ ^OH§4+JoDR  |\\2pdl׵w_bayP)nzWE1~Y1U?E4' `3 fԖuD[\8XI~ k#9Q.m=;z$Ig[ևʰ^=:qdk+X(X3{uB-[wQ: +^zҔ4:֤~[j|^?p5y>2Q\vZ۬5+D^ k3ħxkgjP Dڡbi`2ץGM$aAf%AIӞclN'R=;ʯ dTUa(}uQ֗s黙2׽^%?8cϝ&&բ+}sVqtSwmWELg\cE<<2*LkbOrvJC|9ݒ^l/b!%حY@} 2X{?ʪird<aaQO y 6uR }Ow # D~9XcDȞHoNH}׮ }U}̃uқՌ)Χ(eU<#jI:8č ;9kfvc39:er~ϖvMfYDWfEc#56@hn˻æZ\6%?oh~ ņ2>'ܡ։FP_&X'U<2&DjqDM7Y m6nOxM6J<ל7u[6 s,{)[\wc|X@aq8>Yb~oʍ:U7EƺDT|C C_O5n9ru9b^yJQy8y^-/u0x+F{c|s䙲mt'h0_l#cUm@S*1~B1cngw2* bղ*>v21̣axڛ!,o jR,:>9nG}P8Kd㞑Kbb_TeK ;S\Z~+l$Pӻ0_?սZ3iݚ [>JI8]g:d ;IZ9!ne4u_p^+@Rń|SKp_?^O?c`3njH=n<^ C {C( 蟃e_}%U9y;3D_l0αx&KE!%pf` ]Z ?wQؘK|5Qa$ZZXn@X(~7UTx_V;jjش ~M~dh۫my3 kj퀱߁ 1HʱC߂$U1Dp\(R[Bo0֓Dz{S|jCԂA㢬+12łp:$^ :+(BNF]?Q<9iN i<<%V 嶺]kE0<(]Θ{b1&t^6-տ("5\m )4Z!BG֏<PV16.9blڛB 6FJ*h7ϨH"h'tC*L.,+|~2e{TL _1>m;`8Lף \&7KyNp`# #$A-NC5ʒcǷ^>aq22^G*W UuT"&Fc=]J54d|8ҐlfN9.Sd^.tر0tj `տH=}l:.)5J\gF+VnLc7ɚ kx SaŞU+0\Fsѓ"U+vEQMadI䜪]"~$)I GU[yrtqYBL,O*m261N)xEu, υzNZFRD+ŽRA\\ ٽك%Jg"CSHxfLqMrMȖdbR~Cg9dex~TIDGC9( 7MQB6v+T+rS,Lo~M jk }09JKqr$i&ӁѽGG(Dlˮ"g*{]ѓOgOn L`{|yTbz.B;_w9AMrl1 3b [s2 *qI~}ߥ94񬿙cN4j_#9 'GKE /Yfp+B"ۂ* l0lvLf9Q*\[GnA[)o/(2&j`;s͍ rJZ? L"qq;BAn[6ա.}Kt.c*AS.69Olp6I3A?L&ggW"F~؊TTMn%봎y_U\智 2AdigVc6@ʾ!lFfS(1Niy~/ˁ6H',σMB0W}pp,Uooޭ֛Y=@JN2j|# JΈox׃1O[Yʜ$eRW`R9؊Vb-v)4- kf`twpz]fg66)/O8' eG?BwVQoH8CifQ3TqD&Jj3h`.. p6H8A˲5KtP{ODHѳeD{=! ΂/եI8)zZ kNhdѻtI6+5%vΪrp b}oWvɞ"'/]<,@Piy/*D6 XGxxڏηUkӏWikn漃69Zo:\[fDh(PW| :ԳO$A)KBu*2בK, Qv ,*輿%\!mN[Sth 3F%L*ɾTkԁiCp ~dՠsg4I9٩nB{]E8 uO6ـ J;Dq=RV,5@93]=j뇁u2 EyHhJo\(3y#[uɞt.&?sZsF(]t{YRQSghJ`hяoweƴ7Q)[{@BjoXseeLL&{G?20U׀BѨz"<## ([ے[R+!m6O1I+6E cu*SqE(|&YQ6յp_\(cAOT.o{/9r@[a~֞Apj(]2_?%WG/dOvГ˽?>hm=(d72Gy]X4/~@qA#vs֧Y[Y|wޚޙrNX<`^^;3 UT}dU]R@&|蕐 |(z£mpւ)gA_xX&ڡm_er^3 ع_ 㑋:˺h)쐅a&Qc,PrQRY7uѴ+Ur$%q*&. ? ʟc59 ؤ)~CKG14d2 *fx'Ⱥs)@.e<%(QCCtlnXՀ E/3ܲRo;9vtUeAdLجlx@m٩{dS !5nLL)!k>MNO%=܁H*Aަ%CZ]n-#|xݩxuoq8bH HZȇ`5hȑFXaJo}tTg+j$ՒOojçv!alyi*Gր $dd!r b82*N;WџD b&OBE ~=*zu'pįZA/&v&G<% VngWJ1]Q+h>ߤS1SS]l˗$,$4B%4rxX'1Eu\b OL! ~=Ș?6\$an=cd+''V ϼCns_w]AF$#M,>Mw-| #~u~]ӎ.hm0vcF:ivX3wc~a/x>ȍjU[+2=Ŏ<;E,q9$ S#X4a}vFVLqW惷Za5ay=+ `2Vb!dH_t~8 *e6a|cEEYoҏ곸̒𰅮d(Cbe/= ,?4*cI[GOq6 n0 /ƾ\[]R`S3 $`KYij"ɟpd"f_BȡuA.MƳ×>𵷒-IX2ܒ_߇`Jt(Q]t f8~ES%~rw)>Z>eQ9Pp3Vdon]nċ{ >u%׸K o[[2I(5jۧ;, d6ZGg7 r䶕+Mg7a }Dբ:)H3 ,̃Q2so&w?7NFXp@b-  Z36H@Ngń.&U rl"ݪR!o%k30:U J,oʡV3rԯ$ ˪MNo&uZl<>W3ZnéS1Ńrep>>;=5nmf:B4]J?˒ifCDPw+*y݄qǽUVسFRY.b\aFF[t1Zxom<Hّ܊ ,jLC K2v~sq_EGq,-:8<`Z|T.Qx -EK /w#0mx%p8 G@BXȳe'NhQZ6d(fZ屙)ʈ!;tϦy9޸9vBRGb@|esBa,X:of1f;TZX>G6o i[]t:vZ=mۚ{# zcQ%W@D8H G!}R){*^-Cx.N7B?VɴOsSM;|pɉ\.p_s}?+~qQ4p%Y~#a3 cė޻v2(C$~7I:_7xI>&WFu`E TA7xǏ֢szu($#g(c7lDީLz%|><8Eehp׻ 1ӕdp6}U3SEZr6B˗K2Kzp1t!!յ z}rֿ6h?M9"%KA:\I5% "vZ`?y/W}lyyj~\eEu|7kiZej/7!vuW)#ӣO^ۚcĕRl`^lI=`^<#&+,_\w{GAͲ@mhCE?#Tݍ ۯHGh ~: 0:SEEgAR/ggy767WbdOckY.n$܆K{nnX,UF CT% z%n5JI;=4A85]TNBB 's*O_xk{:ޣptOvS,G1WMDڤ³ԖIW~RCo*}&rC T^ h3 LrH~Q wGΜrqePޜ`5FNaXmR) _a-(~SQ]b&$0fLZN@Pp$0uŸ&WaÊ+ U-f\iHcʻ)21zTLgk/;;0N3x}ثq[,@R_kI-dZ [H:ֶ3yP-;1v6ibƞB `af d"$*zm"_۲bsF ӄoꅣt ,Yҙm"iE{$18 }Xݜ̌" LSث}fNh& 볹%t-AJI^,z 7XȾtO2}SfϡǾOf-<;Lɕ)(RF۞ɵ>B,V]JAsFi*6 qUDV{WE4k!3S6uj{KmM]6M-m|-YKV6 r5Dvleʆ5A!3Sa  E%v^վG8Z+iV]iAiTuC&s)hhOKsra&@d[)|hW;!b+a3,-j)mw(>Vv)URϯP 16gvZ|PjwźӉrvɆלh֏B?%88߬j8gjXϸ h}x v}A;[D<raW"8ttpۡV2y诈QclLHEyU,y͉9okDmB̊ܥk mvh@jj7Yֻ.wdӁ:%. V\ ;4οYisj I,B>9:&G2h*_s} 9'o!7j8w͠\E'!N ]DtN*{&p+oQLKVK R:ԩ!N`MtS\^_)6s^jY W~hRC7FMStӿłysQ3!LUv e?u`:SGxS͈;#+;M"9{xj@sq D8f HuՖwvw_ˀ0E*Q:_1B575ql%_I̤)tLe7/NmS|"T wT0ly g[\>DqkM^D0 4tp9Fޖ?:zn7*@zf;BwN>n)p>1v}J."@Z_Ԭ3֏yM%qZuĉ>ܕJ!7QE0<94gLapOPXNh%#S{mJ1mޅ1{JX {[@#ƭ$h}1%1|0R ൐I b!1X?m Ր M'-f| `;*2|2\w#h#zuDDW/ 鶸۞Ҷps&f䱒a)ȡqt퀏x,⨑); " W|cx< m1ŋS8 H;PXݶft5*W+S)v͔`ivr$XQHW*t-gx3!@2&?}&]v9UOmieJLoUSI .>yr"Dྋ`{Ty2#P+岛S߄ UOI,ؕNĭ 1M kѶ_{Rvte>c5bOZ<ًS؟TЩ?{i tr$Ap>DIl= 4Eʯ C2}ʴ(c ק$}5+\c"apY],n ZȮn6 u"4J|Wy)?"VOM@E@;cmbz|MW9|U$v%a^m"1XT$DW^Eȡn\eoDh_ <뱯9MciIU ovJ:4%Fx)!Ye">?͸~[X0r!]0 )kA+L`~v=i’[RݵUK1\E%efz5 #759-`Q*{2 1~__9f0iLĈK֜z}Q:|5\@2QG svB' ^Pj'6[Hdl77yd _0beOzv UiZ,i~ We8-*;-u7ø: ڋU7Pt6TGVw,^kٚgBpV endX $0{k3@Mbv#G9{$\;t!kf NCmY=fz?*X&IC|ij}R7:$["ŷZ߻+rvi% .4!g~1H]4K@$8e_rr45 za3=;4M<)|!b\!w8>y$OBYځ63Y!0GbEoÝje}!;Z??mDIpKri]prS)-U t_ k.')}y7 -ADI?}O~Kp#{@˓)VvdyC[3底:͵KeAp9i×=AͩUYGY67lϛ@eẐ5yPc$;n; \|y?x&_4D!ox6HXʵmwpB~`r‚-~,nBл}˜if9{N noou"=?` r$8,ͽ̾) Lb Ĵ,_&6 qRV95Z?W|*)>5r“|&sdnVΣ25)yOvM ͊=ׯ rl-?1 g"|j%zL;=1Ka,;tL{c){S*h+a~\s)SK:bSdzOq'2&1m_(Nf&Ԩ0 s*ehVi$ adnp݊tv B׎LfެJ` sZQx2B9uH40\߶{^cD[b"#>'JVqR.ό>ZY#HiΗ]&x _ow!nAK ,W=v FQEC3,)lQ>:I40ߺŢ#nZI옯.r.^JF[ׁJ<*t,EVŨ:z0h$TĊ86zVl?]hS @g%UyW3$cRҔUҚO } g^ZcUo*`MgLRQɹ.Wt*Qq~Cc5Q'礤&YJx/\TCRaO,2?Gǹ ^o^+q%?Z)72G Gw;Q״ Mi$<%%)@"dpkZɞEkt| ʔ!Z= 0嗈zj[ly:,*:eh]Ov5ޏob$ycc DVIzh318aQ^?bc]ԮOpz3|M{uIwxc]F\g3pT:zbfrYFP ,*}Wբ7v~ |ʐɧ@m A:NX;x5:t5JUN7|V3CjSs#*+h;%.`AnLhif"2ު+S(͞~j00a6B%d# I2C}u"8}72zgz+z`/L8BW~<:Y@Y 6-Dg"p:/%*ktmGw OdN !򵠺6>9ekNWbC'n\"t2a>:%G:2gZ:vH AЃ4+ b{,H,|d0$%>t16YH*QaʼfS:FE_޿W4i 8jY6QV"Q윌!;wauE5^ ✴D*.F7O T8vOu0(OQA҇2"*^;{HDZt\bGaIu? _PiB삭b~)?b ICF/*%&+txbӔ(m᳷ z(FԆc U6Ÿ}o)jmOȽheTN/c<}QѴ1bXQdlQhk~-×N a ,ʧƍo ]9E6K_0aA0v/ )н4շ&2TRim"hKgwRA%<ѧo<;(g"}z6jk`z>RMKO`c"I~CA~w/x<ފi|NQ0T K]Ћd@Jj#sI#&ɥpXUO)_>cX#̭"^/^t7sqݣHn@(ld޳ƛ?nZm [M4P$GA3Ndh+kMPlioGO2a/;% N&kʙ;dGCL3* W7swPs' o}SIh$P} 'C4r[U'v71/}J !UJ˔! ]]i)mn;uichss<م+$|`T%yc_ c +y#g'OFdtY r)x'^i4y35kư6rIE].-|`L¹r%it_e >D7U7=x6&M(W3ϾlF '+ເEUh9"j Bcq~~тW 3 +A9p (Ye\3%.PXɰ& bb,h+~D(bN)gS _* _똍 5IόBI/v0!g.`v]pP:1ǬBH\̐Է}$+ \k"kv$^N%FJ}z PnF DzݾM49➎)rݪ Vzc0YK'(cvfɓy EV}s\EC B~ţ ^L5&tOO;^[ƺ{e AfG]4 gns$E<@ĩ7%K$6d3\ɼ$9(/SfHfԉ%;11%$GYkAG5#o+E6i%񩡆I O@ϷR8O@< }>D;qPSSUWbBk$oԘc醺q/~T̈́7׌b/Xy$MV˔f\14K򐈸hn~DCͦ5/PN釷t|)g5$mF J=eqz ~&錄VY[fD%C%[+sy[K"ܕ qe%@QsO$vOoLM+#R\r+GJPJWLaj^qDɎazsS:r*C;-=ALDŽucQwEkZyW1c^T>X[g 2E?pL on^ D~rD҃'Twmaֲw@u$cJn7t >Alc pIUdݕEI5=h$3gΫE#  1ʐGvBg$F:qKowX 8)Ytk5E6Y XM *QŸ]e21veZY03P /lPeFSmî M.eB?[| u5d IJ"鯘GOB龸x@\¢8~gF][nVB'%l1s@8=ߌ`x2Jz:ˮ.a(%hϤa ,@qcQ% M_kq=QBi| ˶S? a.`)F](Q2:/ 'N}~aapaql Lfhu@i|+:c&%@LP ǘR6> {ԉ`A\Na0/)wnȃB:5۲(]a@_NqoJUHnh&UYaVk-  吷vn|M*U:Ȓsl#cޢ q` Y;3 *?%}e QY#C;c_.fVGD!ZS"'mYfR=> hݳE@zӀe投AF㇌J3^ҫ:Uxn&j(;6Pz f:[T,o-x;2躾yA]MEq~<̲gn1JYoT)nNS/a(3/j06Bד`H${톗n9EW Z> X9GBucAxb{l$r֮g0 r<vz 4}b!S'h͋nj%D-,!67WF!|2 Oۚ : k|);xi"w#τ҂<2KO_ڕp}IyJ(⟃!HEU o&zgt]I d}ߕM *HkYitREvgYL@j٨}y ]2` Y-fr!O@Q 5&"+f'F^}Ê^_T>*Iq2x!V4Gc([!dU[@? ߦJg3G}o~ҕ,/B }Gdm2dI\1\s@SmUޛŤėKRRd%0,V3*LJ@fGzx*uV)$Ds bi(C-Xi84Jyn''xd|xH:kbeZy0ʿ ު 0Eh1' <Dӓz`-2N鋨IrY規õ[\٦O<< 59˜v0,94¸dP1|IؒkX`;4rlfXx0vP~_-⏍o#{#P5bNڭd1l32p8Wjm9P XDCK Z@&XRq<8vs_[nz)ƕYN0ĴKյ_s%j6qJ5 619`ej$4#~@y⯩ 'NJ?jbMæ֋Nb}tay2qd PuyM,ǣ}p Ӎ8Z i$S]0ʽ5YU}IF4zQLRmgci~]H,o [}$] Na )۔?=^x`uue9}zڗ 20MV2,n7~4c_+62n/ᶊ&d2_>#=QWnb?Mh<=ir8A`_#{`IHwc$ewnvܥ?Rᘬjŧpcڎ7deDS {jI#<~]\o ;b"{[.}4FōC,B6K8FkI> <,xMC e~ (::#=ؔF<@r BUÑan<«WHJ9 uzٳP|;UxɄP<_>MNԶV:&{6y*U\%|Fs=\OB9E})jn)`~ J2o5> ۧS!V *DBz5lCSRsP?t,OnȆn Ж~Auw<?m˃3;snk隴`Tx7XpڳHSg\n 61[1,*?U i  .z}IEIi4.'}O@1aW#`5bb.}%a{ R7ߠWg+kS9n9Ƚ{iX}D{4õd26A%1nc#LiV6_nBK2Ylj%N ^ϑ)nwVnȢ>= ZUHxb&mȥS/\Do#T I]vd'$wa0+xy!U-C mNR -uٮ*9$5ymHQO } E6\'.r}+rHsD3K!4{q.8D=c"A;0+?M^  E$%o|XWP٩n_!r@ ɯ.zF7l܀; ܧ+F <=PsK~ʭ?V7Jd_!6]Lhsٚ۔ ,M.#B;^Z&Ў O{?W{ܞY|g7lz ^74'~eA VxS>O5x\Xv}ڑ,@(h9-,곦xxL:v#e 2?}VY_'65ۿ.:ΆϮ_dj!^J'NhgSa,x@ӠJtv&XY+.+ 8;$qDJYU NtM!]A Ǥ,փ붗$1ǜ[X`A=d)2ے5<h&Mb-K0f g?y RhEbGQ? 2HvAl~>Vj3(=Ve^ԁUq* \|M)qfg`W*5vl%{=s>8:͌<3"g(.*&9tG, {#)텂Q2D9d*ݢK'<&PXlVn揫0Ҏ0r}}/r"U#6+,^.}PjX3 *G_da\f2:q+Q:~Ho+zc[% NJKy["?"lcs6@~6{Ti$e-|3N!S)w>(t1Divi~{FwVB]CU 6^f0zpE#O,>~hrb^OF_mMxkwͱgKQM ^!d 󠸽$D`Jq׏nC2"CJGߧU8gRMu0i%[DO8|N }s ANVK/ h 2mż\TXT57] ^Co'f|#"@QbZ $u!'W7ݒSzR ̆hw{fAʼn×4IXx"s@GBOCpy!aٵ1"#cdXIW)utƔ3'C=?g5Lgl*<շgZp1 *1AX^:{AHp'%h#.Fxnt[ )6Wa92D+&&[g9P.pĘN1|[MCn 1z-M##Y=s@E)C9;(})P3ro/f }L/2cL)S)d*P`?WN 9դzI b1P *|C #X6tTw Z}K6DVҥ8Y~SB'G~zR )ԌHfu@IŔ߿/}|Ta@xF؞Jâ"kJ-PA8zS[ 4Bue<E#nFS$Ś[&ɑqP\{X3;i[w{[=&B Y-m+Rr7(`{S)YLJ|FOůDJ轜.Dt^ʼޙ-vTIgU1X>MڵgɦFN:z[U};.rL/q GQCYiwSW,FiQ݆`_v3Y2.| (׷;l,7?LIJwaNɴlqǶJ/"It<rU'P^K׮Biys O\"oSdݲ՚u,7EF|#.$x2s+`6gjk#+XOBzr!}{-(W钙XeQ1t!}yx%EWsRÄyav  0i(Df;hOmaǚTT`@PѿXgDy&?ii2xeDϵCKEf`USyAW9Rط0+KsO,u@mq۴/_Ê_5j6,uVڅ=5g3$p e-TUn?V6+(&2+BҔ:Kj=G\1 /,͆,ꨍz=31_vDo?8wDdsHE8#]=/󭿊 [=g).?Bz!i9ȽXg-FJ{l10MMKWFᤓ2US=}tN fv$GӔfa` GA;OYnj]"j~}"?ǪMdSﯼ3JJ?Qx P(20T9uh޺z BJC o^#:7kJcAb1nTR,VÔ-ߨ>5;`C.3s01YGb9WTJ\3mGa]Pڎa1;֪}CIDkR%9#^ SN :Ǝ._ea?q~.b @AGOTf5 C)?'QKm-i!XQ/!No^7Le*ED֛͓n)4Աp@7ͫ6}vP]w!ԀU&uӂz۽`exe ΒNreoZn<P}hl u$?}tl}IA?칝:i?Wwrꮭ,j)vCqc:DHW~]GX0+>Kpi :M'OXSK](mA=GЙq.H>%{d텟;l7919̻vsiOp"F%Ãs/EK_R̠Ϭ״ˡ%a0qU.';ك*$ӆWvB#FL]fdSmG.lwnw1y،c d#h"_5=-X(B1Y_S.:sxpv5H{TP>)0iRFm pt:,ufKU+}lw"i1V)1 a>)R,N3A`[*di"⯏!LmQb8C&Ur{TJҨ ԞsA>L}F6b, Ȕ!%xV;~}e!v] !:XX.K?XT#/vw evzWTGK5rL RXNޫr}2"t1:D_bS焮xmkpfΖ3 : X$Buc\քlf<87=vؤ1npQrQckjx+Jy4^;\f1v?JrVG ~t9ŭalx[ũ9¼Ca1νu XM~A\l\ojTcʳS[)15|IlXQ"RE+y EݬB*ivMP_~9$(x|Mt(:NCW'Aw% 8a_~jBZtsg<7혽=*JdTv'ig=Æ爍D*Z\IӢ>5һĹA3}59z4<Eh T֕7R`@Rg^0aZ_h$=/Pk{7 pYEǞr!PvόT|WY<̆$t/!+DjdGP+#k+V=/h'*eh;/|_V;n Qؼa;FΊۤ-k>R4ʞh 1g}Y._?\2wyյ4r .5t{Z7`' `$\$1Y|A p# E",v;Z2NM0_n3uFE[P!i-LrN+ފx0 Xal?[`d~ۀQ ]-%;|#iNVI*:>7:ibR6>,7p^pIO #, _ŏwNS%|>3;JT[4'aA'w+2ͩdmt:t<[;)Bـ8nMŘ!/X0"gFI 5HX|f˄~mcp'& cGrl@<]3TLh>]w,H`"A3!E_-:j*1r,NwƊIT"L = Ҟ Ӫ@Ei-XG'oDK.['zYnѦ[Xl'}\|2ʒdcbo?c/N>Sp{-)=3;` =H{ [xmDFIK V{*' b 4r@um1P`΀UHalMM]v:Uʹdfr^nkWZڦݨicpϵvMjXQ0ɅHѐqTg;W$j+?ԇi_ۉ:O`'oJ82J7)qA#3%:xcXR͝w腥PљˆƐeVzẟ6dgAZ昃я+\)&*eoJs7VAYA^b!] DjkӪ2j%iLP>O,TgN*y7~jpiB́9vëdtň-ڪd$M&8\kyлI˷#yo_ \mҟKX28!ا1 O\^F-wL§ nAG&S%c8YWhTQCSF@ /Ԉbb cOPrB*MI܌W~/fdq/"\X[{c뽌ˆ,`ڞb N_~m_d~x+EsTv`O?;o|I5 ^ CE 1qw4ȝ:M繭9{`3%Pƭ)MB%xq_f-jX[g$]]a`;9YBa :te sEe[e=]ػ'L1j 嬒&bFKxȔ)otYל*Ny0ݱQῦ+kGӰcHiiG >@hƵ>6O Fk!>?TV"f1Vyp>s<)Tӌú2MBƲRL% Ϳo~ԴQ2[ 4&v@7-moF0zZ9<oݫ˒+! 0 9nƗjŒaS] O#sc8lSzu&7?["{ȸMo*^R5n M)G B $H1$W-^R67S2MGݟ3 09˘VILzGIPQbeRK=gt!#\ZI2tez_0yswNuTf7ENOCYw޺He!ʁ]i`Zڮx[KX>c2 ~Ӛu/pL>~&) t>*z,!URքh~͟K~w :Wy^|(! ޳XҫU/IR>#p?C2ZthǏSmƩ$-ebOs8ZkF2Y}(`6p=*䊃0S01PI/ry٣1ոzi^oWFh ӥ`$A*6GCYk=pK/"6̈DUWAo!ݔ_5{ҡϕQ ֊: ,gR_%I!e՘%7ze /f `"@ E5nbA oV:wI&L$Eu?MPO}NVM};715Of{ʏrU. 4_AANin9CZyp x^屺΁X-Rfvo"w D.3dW  7Y!2!:|79TlE=u_qq|]=  ryZZۤJZ#Y.sbR(yRD3C\^$1GkނYF`tz>BX]Y< RE_l{wƟ*8nSU$5IBHIJ[<*uO#?2N6[>H; SƕRZmE2QKt=܊%nDL MtY]d#suO=4(Xc{vy*+}YDV5hҚߐWCY26fF:0/׫:&uPO*1d'n>\S,BGH>jC T_%W62 ڹqt4N׈%J njro>bqaeFiX*c.q9;\k<s]:Df$>Pl@-ah. ׇ _M v eX<>,3 fipas fM1$ ٹ`u_D8Ou_ ٜyiCx}]hדk+׃@YsSL?}Jb~SHt('ǒɵO33vM]T6Y{'y7dg0E󃯈_͕&,w}N.(kDÄNm0Z)^#c0ڊbP[9%BܛfA48z"p"w'H5u!ǩ-*I :A ,Ɍ!66]~X"F/񂊳ݪ'Twe헆ت$ v*CZ]Y{u=-_!DledҼA,jVwit0d Ԝ5CAᛈ.7k T5n[ P91y?(^ w€н*¡jJ(epul9#ɫ-C9^-H޼rOwhdg${Q-\lBF[{x"x6՜<^{QV H-/$gz;S&RmQn+Ej/EK W5MςL*zL]JЃKʐ8^:'%S+W^Znw UØaKPZw w6uU?5tWX/Ppw\>r7`n]~UEkWwƵrX諂7_>qO5(ч$~ U<ޑ300T` o*(xA혅};4-[ (XcC]ghBJ8FcS gu@:XҨ,8`."B$p@&u BDe! c:,t.l+n;D,֤1yjcKvAFx1b#?#x0[T&E3ho\"/l5@ayq4tk&t !"-EOpy uȑ>He{nuP/=ރ~M)W+ ywXS"+)L^9oK̴ ~_6۟ԩW=#z4mW31@zH%YKBY)# dbc+Ut3M;3_J0ͣ=x` ZȾ8v:)G{i}EPjuHFx„^jw&;ĉz#eO(opSŨh꥞ Wɂ'u=H?G3¥",+F22CuVoX bZm>rK׷=a|:ҁrۤN Z"A]}1q3їLKdz/Ӓ637 |9/{W#DCHn,X_؛\ ⪃P g61.ƴwNk(ac ~RN%lуXA]w'ɠAbgjϕ!|IH*? wkl6mhxnԞm`>VXp_qq=ri&A kuR0;Q0QBm19±eC,3Ը`V4ƫX~_'TCĉlc\j ;FԜ0'СDFƛGvSy<?>;-V ]Q*;@<.RM) *NyC,`*ZpyoI 4?`0z-Yk+]P R4p?;p2n96{ҹ<QqX6+Li+^,?6^}!E(nJ9!a8H V=[jFA8T.}#9I:k ےDdY5,7 O5V Zi&W-Kz:4x]GwT@2BCisCGqX֗WyXthŹ:ASm:\kM Q;X%a)ȗH~bDto)ک9n$ד. {OU.c]aωL|f㨗CVi'Xw|=~!i" < bGK\$tf%y 4Z>n:ƍM='ZM}Pi2<\˫ 4YݳZ.ơʯ\MY{s䮣rTH+Pa9m bWϿsiڱM)so$͜qL5mZ&(0 bDuIx\:*V1h0QF2ǤsnMO0Ù6ޣ[[6owP@Q"ܣu$MU7CW?Sl>} A* BP^(cG1z>f!T(a;Ӵ=&Q`-{a wF:M*c(CIO qaUx >&Zit@BJ3fɥ"e*VW6IAش9]k/ZPU>^ +û)öu(GAp|j%8?l7Cueu F?7~Un9 #ڧUV,,Ǩê]~B;r0&yg\^kk'ihߺ%@Ii8F<.eT7` _jn9?'(jz' {WGc'0E(Pic(x?`f]{޳,v='@'/HC{E2u&? o yUZ!"j( 6Un5-VԺQ[x#|)Q ߾ ! [TM`IXDڀ($\'ps柁#jӰtνv뀃!JL'>Shvy QQC-zX=϶Ib 7_3Z˯lk}?."@/&#VatatJr)@nQV)e ޅU v;s9ȁl[yQZѩM(-م?l5W4Դ)(ۏ=}xjUJkpm~thUP'(1SlU(b 88%W%&[>cѫ 3o޻*G'_4;`e,۶f/|Oy7[mUo۶=,yQY y5 DLxE;[\֋ЧgItruKq(v},+jswWhx6-fwLW}$3&r)F80517,kB4=l  l\tKf|ZZnmsObD?s^r.>v)cyRDP Z;'TbZdIt?:[e^*:KÓF_XWnsv+k٧$VH  oOw)&}xq!sjn1i0e&ő˦u1څ(2SV`F0+i oiivxoϗE,pq`Gp+DkQO 12Y#ns*GHքW/&ZϖP(|!Թ{ug/ʪ랩\EL X`( q_֔xXc^!'=ٮ^lhHMk;{糉ᥒG$S]$Z]jp IFpF752 ;m~PJb( ymN@O'V1u=WzFs9wH'@q/jyƤQ HDb._F|?'8J&Yh1XjSj$u'pI07ĐˎgBa8 Be{1tOΜKPZi}uK)>|?Rz /XiimqΚ `j7^syTW|B _YfeÕP3y9Οzb/#2p̑lb-*TlKUG9fLi4zW`{C{ؕNׄ3 Dҋ q_Tt^[mdAW'7q T/W᲍,\Z:Y ohd eu#-,Z)~}kE znsC"`/ӑpSU0ʝƦẀn0q_Ț%Ɇ K,,vmSKnHz.A'Z(k(Q>| ` >-4YovB9⼃1jZe~b[}JӠ𑮼k6:i'.burc.-Z636"հ5JQư,Iv[GC]{˚H 63~]ؚ:|`4: |^>)mAmS p0݋pDqAGy9ν[:!F&+aFBSOhT0^(9yηјS DaDdJy|7*|ն͞v-qknCH9}R'Aw8n31u͎Tr,q[wOkEC%aR_vHߍF`cy5Qpn .IRAu_iI\&,8LlYx')B!}=^罰`0_KY׶CݘI+JzMU׹^ 8AkH9p7G 5ϹTQS<ܦ(:Hk`a0:9?*ۘiX_CÎV 6Oyv#df Ϊ/) 6~؈ S)'w{~ЋC$tʽUos ִN/(xI[*Tc#RZәf3Lc Bk~EGo´;JLʋ(-F|Iywv_mv,c@ENT+poR-@s%n|}p49eR[P @apI?vƪ' b%'a`mN ID1t,I#)>`p>uL iRn3s˭S}l3|;Z@椒b+ɞ҃Ȁ9[nl55dÏEb14uq PB-tZ{PbB{1waOjHgDmӤ -ukvopy }uO`67y4wX{`!o%Ʋj``issɥ^V])Ū1XK{٪F؇_#B9ex҇BRƧng[&;ةq-*L۠ OqՄa视vZ9ȈذDNzXHqneJWڠy4hK 8 _KaO눾e7DM*h%.ǶZ(c]j|/Rl3rkU? 4-=_c4X ?ô<쨸L/u]sKFllM.(Aq~wX"/ Wգ VQ\Qja\EֶL;uZ&@/w!OUac"Gdć b=4gPo #:oKS7 yIyZ +mwjՇW&lZ6$ӟn~މ+Iz34ӝ} jGRAo4ra)Oc؟d~>\XPxmjmupCx*Nv adP+9^^oJdJkF~4>xZ)3 y5aMa7q}][- BYw~`h$g uɔ>xԎ ^1k9Rl lnlZ=$X쩭(*cq2y,#6_v`@GBV2Ҧ!u7IE`R-F+-?UXkkH7(i@nʠJyI6T!\>-$'B`%YjY i7hz'\&y 5w"^9yNVNXFts:cNe)wZ a7cȳTL0,U'J2Kla@Fk/wK$Nʨ֤qKޭxywwJgQίeE y}&,naj')n+2ŪFh2oql ފ 3|cuVR,Nu,Ҋ+BB6:wyXoK<)H qw[ rbQRlE7,#8hO( 54 ܖ% M >XWJW8J^\+ef0:+C)u2 Ƥk[ҝ`$[Q_bX,k!bio8d4rKu"i5Ogop~t9NUP2ՄmY4s;w픴pS&3Sc~28.ҧ}moQ@ ^O*)^!Yz r4DX%n* %M9LoY X{*xT6IǷYMEsP4Li(ÓəFg@b.ƴ֜ͥ+V^J<)s[-J娏N-$?'Ft(~AY_Ѳ%&b;k99˲[+F911hP p%e"&xYZq IPj%΁'f!mͱ4Iӑz-ԗFBz)^v'__nrg#V9kkVBSj jq<&o Pi$]#%;fKJ51RUV9O52O+˥dUMω Y~\-#݅[n'x;ͬў?P5~?;'!۳;@dA );=%hO z7pT)QOڌaۥ%%Υ{vML UX{rp\ W'zŸ..F[ piҫ#kk*Բ:SliRB@ς?Y,@iӠH|SB-*Lm*5?yTu؝[LY@%,mQDmoF븵ss .̀n Uw$06dfc=vN$!?[݊K IYnT X@_n"1J0>Za~*#EX8{瓞:xWetI &B#u&8FW;;c +w^*ˀ ɫQlԨ:+Z4Kv3"̝\bGa[ZQ Ցb "jX[d~r.Lq fC輂@ -!V8c cZȍ93k.D5p@T B_(A<$1 G-kb(dbzf·c_8,|vHEohf6Mn$}ίf Tub?Ur?l67t#JL~Xn&``1s/ϖQ'ppH(v^e3X򅯀%#^<K>4~Aw*yQ@' *}|G7 K%0oxܹC𭤣rF&xۏ.%k?ybխ/\!(h%2RZ>BΈ,n%S.=%x&6W8hhF:2r6q[Ӥ'0kP@nhC9Ci)d.6STOp OO]YbE'=kK}ow"͵+DB_QdlUkmYTawtT`U®QKYG ;0*W'ĢV7 5=^sJJN#_kc;؛ rfJ ]@io~^Stql,ù?Z9Žs3d-4Iq 6hOy)TTh#*s&@b5ahYVWpإFnJ /+hv25R2d/BP@pBut Ւ#sRA#Ejrח [zl4Hm;~Gmm-98^N,ƷBނpGTp~t%1el1ׯG:e-3s@65&dZ 5qR3V] "a{VgԽ`5R Lq*5RV|.0,#B_*ـhR!bijIe_\UE'Ke(T#6UF(KB:C+ CW$QUՓRc,̦JqPek*g7uT]()]zĄR;ד긬-pvُ0nᚄֳ3>*tQYWkЩ;Z c:X 3 }F#m}A\\e㬾o$*d"^6D#jT!cdɹ ^W:k%_Ǭa[Br7S/{/Jf e5YI/"s"Oa1inS'uaI̒=xcػ%[ڒycɽB]cS KlQп@U*ig.3,+rlYeO#L`=n. ė\ VMSa5⠚g3G$]eءW| dLo]؀M`37T)\S˾(99n 㠌xe=ZaҨ|ة̙aJ/;gilj t-! Sk8*g75KArB0` 0A{㼘7 %ur5<_ u~+/j'=P魨JW߻(ׇlܲkW=IsI8S&N<JP*Wx乓<}2ȏx}تmb/|5j/g ]7OHɷnѣgJJOiP{frp%Y8!J'Kě/ӈhu*}Qx{*lOe9sG<m.~ _o" Q¢b~`.X9 .H5WCgg1=[< Ѕ`t'5ETjmY40Zzn/W<po.:%FYk>-J^Ws䃜3L-*A䛐b6:|wU.4[; JBpCd:*+؟!HۣQ:Ɠ, !7ۮOo8p1+BPt)خgϮeI2)suf Huh=%Sx [m~ODuj8y`LH3;P_ɚYnM^:="* UHv'Âv N9/ #\cs)*i:W`^[Ih~'n n#I-;oү-Z&^ Q]kbi8-Pw ]@TzB:vg6I"jQ) 0wɸDzG/,|,l[QRS˟:tΑ✦- $t@雃ߑ_S{ZMk7+D mR>#ı:ǶJl0j)FU& ݜd=N=m Y sWBIbze&[.1UUIM@[}B d*XVTl(c[AG$g~eq_M7+q446}`2җHI8/M&hvfDkշH$fo' 1‹OrYKыTW}\+R Ϛ&CJmbBZ[ϊܰ#v5qgg@w nJ-$] wixiP{-,i)a=mS =LxF&v%_Ɯ}g\Si!^:?85'7p7l 3#h"O+hl^xR %ĵc|6kׯP$?$>8tS{ +Z"ux}oмAEtzeT-4!܍g8`0)tC vOR^m1 '2j4*p䱬dA&o2TZv# /‡@&[TsDPԘOP9-SĽ51҂TlI6+tNͳUv{q6K4?8lT㡖?!ׁ!i/RGjNrފb~ %ߌ*b@&\kŏ? Gj12%Gs vcγ[17&I,I_"\5?%ꚊO6e#tjg/\gXE[o+h˥!˝D]: HP! [N'`\k&*/$ِ'Ť.f6E%Yb ШGKGcJyܒ ilqH"j{Pg@!qY 8mJMm!@0S ,>֟sTh7| c=Pr0{Ww<ɡۥ?)=Vbkޣ/ТhOeH(ZMM#auG3 R-\W9&A]͗1 ۙν9-miX]`Lć a?pqwD D;ѮS@jOOEF'1ѹpi cjo78 aҶ4 طk+ҰS?z*Ӥ\8f+ f?`0: HjMĵN5to?a V4{Sple"lie쿒aB kE Mۣ$[Awp .Ķ*! E:x@\{g|in4GFi&<9DXH+q{{I "̯d-Y,7UwpyLJ;32C ɨ!h[6zsCV&Bot_ʨG(WGV ARx y䠸xӷ킮?iPo_R{~|챟oGyj%$P6`h]"d>HME5tA;l<^C2\xOBoˑl:%0びD7.`8-SjGƟ[:z VqpCX_('{?~|VRe%Pf]hn,8 ͩcQTaEPl?nrBաOʗ ;%K}z~|)sl%x;n4S4gp!p&l]Fv]0P:V!S;-zw_f ָ8L aZ qCw$i'3NsH'w~Lw_jIVIogFa5ӧ0N^9W-|ӳ"\'YW 0v lϧ$(Q{GY?<8,,b "]dgJAs3d]RD3޵u_yeU&U;G;/d3FQ`al RU&T֤.݆Y]XNT^ѧ!.ŘޣFw9&+,Vd]fىƀxOTD!?ܘLRX6G=E92tlCr/}!C" _N8SEN7F\)>JKgNX{`F`2:mG6Jg&1O2W;)Q_S[f8 ܭSS8.T̼D-%"p5j@Q%*(jLm>~Ǩ0Ov1ȥ- ևK,*&\&i6A4[7Oa׋n*> u)6Y~tW>VOˠ"Ƥť}Pmtcwx*s0ѓjYToboelie8x= P:;eS$t;l'1~ 0H GB$2yz{%m6H]~kِݑ8!Y N=٦s AA5\1&s ~ Zm9 h\KS:AdbGأ{V(o|6.lt fjc=J>C=aԲKfZ47g*~ui+wltY銢"J W-lh"ƽ<09fV{?8;W4@~ p` skxW(SX#ů]} h_=Ho?xMtZD^2}jM׼Wn+72sP^NgzN'?^At)fʺͩJ %d2p(g+w<|0 J7R>>fe| cPЖԓc"ƚ=u5J<@3l?aXK ^`]ƮUQl.r*Ou;N_#"j$He@WLxȀ|KMm eg?Vp$, r2F,En-E%Qv2μ,S!}:GL8"Ѫym(%1=.Ut |*21rl#t!Z"_kohڗTܠTQ|RqG7w5/h%(Z@CZ&mƾ~Dӭ'J=f9jM1ˏDTx˔1EgY~m׎Н Nku(Q1<Ϥtqஆ04>YmB*7D }+UdPQo;,zh"A&v/(/gk+5(Gwd?ȭk/ = =V"90)̙DSSڊ|"q4dFI}71aV;kq BBw=& Hb$l[y<]Lmf8cO0ՙ +U4YKgȽ< Z1?-(7ސ_Q)Oc{a6/cNhDԾ\~|+)hhѝ5׺7TTvʧ1jؔ@koҽbC}ƨ\Ϊ_7^XTy`'4_y|^ K΄F(o]rgAX8£ S ޗ9.֛h0oai' #X>(;:3(ytOftC\սTVr;R穫7#KK^SfrS؋ˏr`avRG ]y{rP}t mސ)Rbɦd A,¨2/(#9wKL|BL^lp㺄_2M/҄<@6DC^nqF ÷@ӗ,j<<9bOzdIQD,ZmbԘj#bKiNXr~/fM|w :c)hDKtH C"]tWA1ShِQX~P5KΘRASp)Yƈ,K{altb} yDzg I@h{ C"Z$ y(AZoU=tdLCD{8f*(%Y&} GkK:9^ p^׿coVSMP谸g bNj@?}FN/BMr{EqgDq\QlUyDz tvF3 C=d#=$xyaY 26!W{^g'nsjKmEq4 7OtǤOdZU?tE2$l>aҹ 8n  rJ5Xv\W Lϱ{9GoMV2 Z HG*`ŻԌjQ}j!3,וL.-l&)Nq݆9k#]d%5K fQkBKMe2飱Џ>/%cJznϯcgȚ$2:rSG\ȠkdX?P`Ո}/l Eff la,bk]8\7U!ҚC7-|n FA\\9g9Wu0%<⺦KR0|ᘞX=O'd>ATzH G gq5(`<ݴ $-y2$W7[WGG t2$q' hf٦hdJj)~С4mpZ\KY؆ȹ%6Po.%mpBmj=z/Og꼤6p 36r[TNKUۂ r[lBFr>t?򟂳t!ᅚl ͘&nV9KʩPPLߜ"Q.]o QZ3lXaV RBԙf&r#BL_mW n7ow;_3,6Uw{pD\]0, ! xPL>I#$C3+g;9t6e ORPn'@-G={FE qm jh1[ՅJg1=%11бvd|<= G2ѰYu֙=L`nZl]\xb/XtL#uLM̫%4RƴRM&Ww-Q9if][K ח!i;[ι >mfw-Iqr@m"*gϝgݪc}='!,$h$Wwsѝe)c Nlı͆т_V@5rׯ;# % s@ j_T6W:=뛬ԉ-i(Ո8jfx!FsP͏HZ$ӳ5Q{&59pK, ~LۨI ܿ ?Qjgrz+Ua[MfzF(-<@LH+FaY77MKWhO Kt$o_PV8Q[e0oD5swOB+_/wv{a _kӻeO?^'y:qsK^'rMiSX7}dZD(D؟$/Xl#UQWi׌RS S\тCt0yL-)M'zK|!;VAodg[ҟ&rtZS6"Ԑ |92=SVjuRǣdw3K5:5A.EMVVE ܎9nHSW8GpwCQAݥ02EG*)1Ξ&6 /q@)X]SsE&|(w:E;yBd:]}r 4U5*IDY :02Jqfpyi?ft;c{bE1f%uqc<+KN YwgT` nrC=lD1Dr|~>0 m b+ )* #4'X\l  S3!-$ l'1IYtχoH %C$Ku Ĉ+̟b2Y@g :بi08Jqڭ0XF/՜8_HQ#mViG=OE;ޜNdCDŽQҤ+,\(;Գb\HgBh<%ص_KEegR}1YVU"eɛ\\ܪph7~iWl:oS &d87GmA7 E94 1l^Yֲ:):LEk 3MnL(g3?_B 5ڰ$@},N>őN<'8jœ.[to߫4r$ze6wUQ@̻#Әk; tk·z;B0}!@iëO}yo|K96}Z׉86"0N$ʫ&]tkKBkP 5b בAxvd/]qV7pt.:A)#`y\DX+5S} ˌ>_O&+1`wPF^:VCWY"ڏpK_H 'H󖓈Sޓ7Z[Ϸ^;|R( j 9(zxzJ]@rACTmT'4F90X5{،VzTS}B %V^{D k@ٹ(Tn* 2t".[ nj"PfXw=V_>NMSφvSD2</@O&7t9yώ'hd9RN;/w[M~n}1Gb3CI#f;G6V&X,q:k~cM҄gma1('M~c.ʷMN?ߊct'=ש |;ϐA Yo!y*~ cuK$&ko\Jx4 I[ 2m|~9 ة4Zt0Xeh2N2i% Ve+Ar,djJ֕%"moJ3oW\]B| y)`oϛFF4IGEݘH9 (ϽuvWjqjfHAG'>E1Xt0g70z-T&S¯XOZYڞOEALJ}2 7-7Y!4? [3k5a‹$ <3l ClvQVfۆm6 9|%)[9&0ROWq$#^ك3l>f;_3)OrRQ.J@Y"#^ eٗXz>1gtd?_4BK]keoI %3#-2cɈNaK^ YEV^Xht!"tx1lFPy!Q㬀i`$(NG +PD&pI3kː;IB_n5H}*b_ʛLo\ `EmJz̅3?_qL3BO 43Y )4:W˸ k qE7 _nşEN6l[lT*2l /|P PohMo\[M=>'u8 6yw2Y-bUxS4, VXVB,^LП&2eyG?R٧F;+*Hν\,p% Pp{Ha,ӽ}7Z#p;1HvqbHP%.e+uH0ntQk+M9JR+UJh4HGk6IggT*V{{SRh%RuV B#Jm ]x]>mTt`ejq6LQG 8}y;.yn6&(TO' tΌyܾwWw#X")2xb0[@݌tHC7P4"Dž&+7cNp=uɰ" l)Yojo(Cybc9s~-W W1wUPCFT$֞O\TO} <GB̊Tn_G,١=И<3 v[hw%|u,{ёX+:?ނ.(zz2pW =lbטW_k n,s 0ڵ/Ôg͔K7}8B6JMyMPqmBϞ[S պR7q&IW4k&8 -q,:w'A(0@;/}a5U%]V7MUSŋm&^m{ &/bs>D3kg5v~@$FcmĜ=b:Npw' ;Se ^HLLs("C%˜{k®s[` >^1"Ĉ%M E-ijl ׆i}nKTc-(~nz{W#iCw;DePI/XϲK1oXԍĞ'v6Ug Q o TFy hyQW锍S 9VNd۴!qDT^^]QPIWrP1ҹ>w)1?wd&I{jK? ,k爏3c(:QtLۛl!i n>ztCpp-tfq| ٙ9#oǪڀBNw$G>$92G"t}N1 ^OwQHoUg9d~x\%Uc@ G/FOӌ ymW+aނrtc5?CML+nSa,g׻O۠4Z>PEw r5KL7EK[4+ߍD&\_Cߩ8.vІ*ʽ9*{J 썲<U K߃?P7bdEòWsϼ`dkpDž% #%}rȳ֝:WXE yu|dp2l}<u@-rK% 4fK,W<1fVo t=]_-H93,oW3Y+Wע0%\aZu"+E~6Bj^H;˭ާ؟4~EM>g{ V#nq[Ӧ-`j&0%7\i=W ~.XR5 #eVTuwښ;şһ?Zݳw ME1(~pN7o&dmAS8ڟt}6fEe|/(Vm+qʆ~7W"M;C_smR4HI"7%}˧콼 `(иٶq3Qmd5^?V= 5Sbl"B4Go0H,W>uSqH~܀&l48OL|g(M^ⴳ!@ _EL',m. %s;i5 g搀m 'BBڛ sV ECRe:#Ie=fJ'\$,i)c0D_qѣBD,$Zr ٹS}Y8%z]$д$A 3n{i>c0Jש1Kv66?81Ι;#XcLQskBvZn`dT:[%9E5\krng5B9V[K!y ]q^0|؇橾Y+޷sJ"2ysf:vn ݞ'l~&:ږ=S ^aP%NG$ֺW0|04n('v>D&uUjT1k(JDYĽwmre)p{C*"/LZWjwv.xL[>QA BZ~',"87v|pҬ0jwJq3#R[X 588y{.P$G 䰶kl^ _OѺހT|C|JOL pɻ2OpwwX"EQ'-PnH@W& 51.2 }p~:}&ց2;CAt7d轭dYM1cƸH-U%qph5&csA*L @C+O>R4֝< xl Yt!5q̥FC)-+[/$uv,h#w2kcMGf*"]Mh?ta@4ֶB/2{]^mԎsA6:Clp*3T۠G }X A|~ڗķ\ b^c) jmrX .E\Ll$ԋs$i꽲bgǔXU>oj |a.j(& RgpؔvrU Tl۩~f~)`j-RSΨRjo SAK\G݂T>Ljm-#&U|: _&$C(ă4Tl[F>+kZ/6"_`xo Fi7kܨ%+T*GmQUkdua{ "hvnᴡ|w'ڳ9g z8HsSty0>Q{6;cʳ" 4,6b+rlX@g7t5O95[I Af NcP|X*)_zD4t;9\UXb0bx؃ǷmwWy+o) B+a\L8qpco}O`atrZ3Gym:OtKi""]5QKqae)N/2^i eAvi/ࠤR|g/'زҬmPʜ\I8녘+|NCy7?%=h !M+oJJ:==бḶE_t`Lۢ\q9S{Dˍ欄A\mJÕKl a43Ll6ʼ $ǚ¯4Jk;ʁAf*E6l1Q q~B #Ȋ"̓tn@%I-}9x:}=ũۙd{? bDCƙ(()ʼnWnLiU(|D|x85 ]xiPӷRMnB=^T6'5&w=,W[@e!>Ł0 7t <1=,áifS2~.GR@s ł15hi{C܍ MmugnЕAMix?B;?$Yت{<5GP͹mFv_Řy&gϐB+8?{| '@ez1(6EUGLuMmoski/Aѩ5tJ!h!p|~1pbg4eۋ6[SGQP މ.YNBӽ79Wg6S#FM9XTPJs=O c{E؄ US@ Vť[u.m^wBNV."P4XZ$yQ>xWy>˭8NW>(<&y5 3Pn-54= dg]JSʎ{`O_SI5; S}Cl fRzUw ~#c.nZVVMŗKt 4'$)ђFVä-HlːrVh%zNR~< :OgVIdX_>enɃK0p ŭX +=%KK0 wqP~"$~"Ȣ}UjQuV&vzg @cJ*Έ ?vLaMf¡B^ tEz< 폕R ό|<2P?bu8kHpilqz7 C,b4]}h (v֛sȃ/{(Wbw{f6 PD(e)bKśf|2Wc5Fǭ؎e#l19:wŒ^㎰%6 1 h{-z* -]W L^C_\+quֺML"*0D^jv]nD}i y}!LzOnbC}uLBE1O`e8FeMf* 'լ#I$+uxg]*!SzF%KIt_<_*7qxOϸqUvPʤ#\pǪ|\~jEM7);?z( C~b <$6Z^C;8Z.:CWob9%/ QtFLr#psI2N[S~ J ;wN1 ;[i./ݧnK\t]Z$ ZOyNqXB`3WwŌ>5p*EѫR:K//yGyܭb3[ {gCUX:^E5\*y~H?Y)zb GUwp@I],ɀA#N{@ά|R+ľ{4 9p/oq]QJu!#a(ֺtOs4R5#-/ANωdTO}5=wndRwo3kXxtgT/G9CFnmC dJexQՙlB:{8q'Q7hqk=}wF?uMBu?H2Ly ±KtjEj6:qgK>eS9k=d4Н؁W-TNODW GRBBz1;ѽGԯhWhAAiǁ%q(]? Yŵ?9d؇/T u3I"߀Ω7W6y@KJ.-z 챀܆l$ Itҭs~7MlD~:%FWybfjҗZ==Ea$i7ӭҊt;{3W %U z^D'Pn/+QHŁڎ20]l˯T1D+WT0r%EBD*?S ^ww?U2:sPUu*ӈJQ`eY橸 x9Y R5<K>qt}py6!pZ2 (Sΰ?e3sTvخdN-CpKLP.C.3SN*ܝ? .A_ЖbE{x%>`fp's4ͽPۿHzW!|\Z)Qș~ fZ? 6&@&0ө"߱F3Jb/|264W[tf%h3-ߐJXsO^@|—jGfe.lܔ.^p^"DmED},Zx"6;R,VL0nJ=+R< RwoX,zkK X(s$w-䁛_6LNw_B2[E N5CRdcc k{~Sy<ױ6ڲK_"LU,"rC%M\}Ǽ>bhZ Y'jxiwgR<~jӶ+ۓOpȃk$>YuvIv U]: -(QIg "2D^0; Fr "S%ljUVq~Iom,e-YWnB}W~Ǟ^`^ZĐp("R&lFk/h#WO-eSrJ3,S:3A`XElxV:@vE߬U\*X 5E[Ww?^ٛ m[vAhjI}] E;V+5AMr A&ZyF$:Vt ,}ޕ.LA;7p؞{gYܘzз1K85nq9"/, ~e&mZ[PD@CwX R)](jD_Dbz " :LԒW:ܽr} [:7:1jSb#_]C3d e{.-m0 ֵdC CT_q PbP矑<# "؊&3/.0$-}U96z'yEX.i"ekBի_q2rzGKfOwBb*?2_^m*42vYr'%^PyRXhv+,6\N]Q(L,Jl9\At(\ƼܩW_2XOդ^q5K3fnI,6@ pɐV~oK3 >vg1_[mxBeKY0KmT+>cxF5{ ( [iI/{-^RRů1WΔy4 {8Ά%]YYI8taۡ_ m⯹Ls[Z-.h\t7ডA[}bg *b%YSS$"49#F!*Өjm+6/1e}Ź>}Ke= G@Uv0pLĒo*Y* E L^`6VrUsioV嗢rJ U?lE6NaHX[>f;R'I,d5x] 誊khYX/|M!t1X'y*:ٗb%zݍ^qƺ֝-0\$HMrE>dwyN1dGrkV-p݁DݘC xp2ʫ[!v,Z'%#& ]YN&&T 9foSz L46Yf]ŭIycq}bm̾)KCQIo{Cup_fI~T&בmn@i1ߺT렬s*0F3vI97eoح^X>bS/xn-X F,窤ބ]-jGȘ?=_AVpšڠTt,Cn3"i]Ab)(Sw[l"`>.q,Wyt LDkY3=q67Jp AG`WKi{x~/zƿJ9C *^*+;J7 ISN*{N,R<\Ę{̕*ijzS;89Guierkm'O3\i<CgC`,"{k+X,+ﳳmܷMj-ԉ㕫fLJQ*7"i*LPTl)CMTj'ţOD_#`XM\ i4?b#iKjBJ`95.)i.:8Z}/4i%4 ^'G2UNlܵy,;:W>X^DRTrS's> K1}у֩r6fzQ/M ǿ? ɲsN.ʢjQiu RS| UP_[ 4Q ˸)בZ5FaW帠xceM;nj VJҞVК1*:zr Hu^џ7EY33Q?.u|ǥ[*38A8Zq(jA|GRdybHL(}QilPp~[{eu!~HU5:v@llG2Pv-] Bb9덫#" 0, Gk ȿhU':%rX|5<"6 XiF)n2ъ;YF0{RMQ̣_.HU@RTA;#y&$=D}`zCe1P2U?nXhJL6;eH2ԓGb ZxpiY9~(2g.>^R:F`X3ce)&ڶ@Awt2,1dU z e μP}Z~dTFLIZ%9 =E!*S0ԏ]Es} /ॼ-nt7`nTd|Q Ȭ9B[#Ҡ]c4ݒL;pxlp  q!35;v{ Sī,>(vJ{[@~'iٜe. H_FoxMg>lbk '2>HM*`-Ʋ_7ܣCgy9{E|Nf"'sYK=nťAu1MT+[wftaKq\,9/ۃ@v 76jWqcG`PgWzk{6X588_nXr/я=Iެrr=VBóe]%a]bRnI9sMG؍Vm.k_j' XoUtH]*lwn+mcc9 id%1%V#1~A?O Jգa[iۭ*!L7 :6f#A!:PCuRSb@ME5`4:F8!?a0S0Y_ LKlHX~0%CIgjd_N1|QwĿm1ԯ G?ZU4T}#``(.znծ3?xuo69L,y؜* F=3""Lǜxw7Jrh2-l†' SQoq7-hMRQq ̨e'&W piA6/6?j% 5(J,L`xjX%A-o+ 1"24J1Zh n1s.d ܄LnRqb m S\3+Bv4/>~N bKT .tsD'nѠݒ|?u0{߀15<6k:2MW;V~FaN;\1y5 :а>Ο1G0+56Q5CU`ݮiN3~4q9?Bu7,tF:solj'90!#:*KN߬2kLfbɻ,uߗxSx;p,oK_׶;,*gnyM Rv!w^o!DuOdD[jQ{e~oyrn~]B#5~@h`C)jF b-r-@e -lρ5~Sn\ǗjCrH\nG^Eߢ v1ܦ@'@oޏ*yZYQLFgyWw,!yѵfe Audf^tnWy|.3~pvZu\֕nع04dpc- r'3Izim-0 LcU`8)xMA234Ri\Dq~P^(7 ZQ>Eğ~(ҊrnQK3B#TiCbՖƩ?wAuD^if5=/3!"q FP׵R ծ^jkn76}]8^A:RFn tdy wAi>U^M GtF4/T+bi-wY{VTy%U 1ւccmr?>b9OzXp۬N0WfU |YPn9zjtVK'!Ce*n}jRP`)~M $H9D ވ^}OWLbV;älBsغw5x+_ @:q;p$nٵ֧X 0 *mܩor #1go-:~uX('D#r{H/9@ǻIEؽ8lIطS^Քעd%2{> ݥ.s>b)g?7!JbBw}%P ߙh Ia`]dH "Hz.`%7 ұú I?K,䔦W&p*?P " 8 zޔ`򞑰drK[ԟ3 b>&~d-ѩtۤdǛ5-{ChcӁ ߢ@8#[9?ɨ)$i\Nh+M$- WY? n8c%S` i@e*B1,Z4F+swDPΨ%yu&V^dH0Gg8*kTU:W%M.[;>ϩUMXwE,2ri1\ZCk V)Q߼cmc@p1%9ڞUeV?,J}Xtn -@Vᨪѣ"ӰEܫ}3 `\D1ۆ@`:,P-]Ԫ"rڵİo刹ɮ9-Ez 6GcrFb08ՇK%CArfD#?rrN e(ބJk3 <6}RxW xY%+#Re[0:R8v@Q.6V0Qr(_{G@{C7+=; ` a!rj5pb]@Va$ܙ8~Kh!ӄg$n0fݢf#dt g5${;H@XVge粢!Nˤ¯}2;kf6L t̊Rb;#!* l:՛1>Dbټ0 *_*U:"|xLѩ2yYa}# Lfq"cP2h(Fi3/6ݪD߭& {m*9}ȱWUaMx4=PZ_I37ߜqضέ D|%(LVh-,<7WC*̵qX4}b>-t :pQ\ 2C,] CM:QrZw6mי MJ"hĬpFS䔓PE<}Ac/ˁ1.^mKHw\CQq/9|3("&FH9 I6mV1Ֆb՗g"5u7^ehVLfBhI5*{[`2:~DbiK*Tȑ,F.d%:?U+]/輲s"bG<|42 ci[,P:e^%e-}3d5H܅D -oF_(Ŭ1qE"v;sy@qh G }x#]pV鱉V-ֆ`BΪa[]-&m}Q[f3˦݉tm IՏdD:@V&nky`:)OgK% mvXFGMyoH7O?{*U~JfT<1=n 7ɦY5We6@!d+\_dͶ́ME_ i+ 6xX;Di$$(q hcNY圏tJ']KD= qA8զ6F BL["qTdB:+[s*5ƣJаjQ-z9̹֢ͤŤ9$Jy967 ݲMS0t$uS{cճ!ªArD[BikF q Yxdv͏ClR 4e%Uޓ%{tr@@$7z ; ž`dيd4Àk`(ke~>+PNfBsRǢj.}p! z&4k63K~]Q-Mm*1(ϵ>cWEPh+xq- wȲ\"8%嶧$?!`mOW>f@z%cl* eVRڊM)L q}z#k7Q$Su*#^TxYHfk<lBZ*XR8e"DbpP>U$ݦ-WkSBHP_ `fl~9c9XQzY|UBr骫:xU N< &`(4sc?ȱziߧJ+IdDD .)vA23dg.EOm' y^vHRTMI"NIxs*Y1q^*0 #߱6IY]^Tb{$#u唩#}vNԚS*14ƿ2Ћ>Qx7z}mQ B 2*! >XI1 +ZE\zuH]e4@`՗:he 5&^@z d@k~U.kF^X%SnQU.)C&3gO.Y񣏿Ql28=Yw=ƹesv m%jdH(&TS| zPGvmd T|Cnpk&_ &=1?Zd*m qX*] t?WSlZl݌JLkkZA| S۶>@yZՋdžMCU獾^' ΓCVF$d%wQ(}3i_'ڭ}AdW2v4SWe)7'#`2'p_[>+IX[f/ #wnMH=#_ߛFLH@F R vG^HߧϠQhGy8| @D9vVcݰ49se0hg7~\< F%ޓubF.a\YxN6Jvrɳŷ2u ԗ/pdEwt4[ج8DtQ~iG oN6J:`Vn>rM]:ؼtesёMZlAIтc}RZ $?Fzi+I6Y7_j-NV#yOjn3|~Fb'-;n՚ `1W&ޒ8Xc)z=.4KrLacǩj WfP _у}ĘJ4a9OD'c(JpCb)I?/+sr 0h@h>Gld-MwfNz6ҎӓU ૰f?#Zu1% 2x?&^+; ?+@>nWv)86' H3B@NR?':Ys, ߣ^pWwe^][kK),]مU42q-W^zooQ[ZiҌc$8pۮ nqIڤFzĹwSWX UY7nɰ,ZX+H]z_yY?~%p_ʃ7J!*-Hea{|.*fK=0Ɵ&+ًE }<6^D2o[sW0҉=R;WZ lt]˹kdږW_!y>4oP.ErxLaK-hELIaD*)Ay(Io|A5R1;!S+H(pN@f~t`PVaWԒN 19V7Ku&o;/R 0঄֚CuɊ #&#̤* "˔|WVWHR|l'~bYVm32}fR(yT`9POU] ?xH p} HY^X _"9),2vu@0-sD PO/Dă!ӻ~Ż8:86CJP"']i|&!Ye#12#h/{`-Cl=:%w+yV]a:$sFE4Umwhд;lhAù[?RhFF++#GP ;H4x8eeO糺y"x4_i[HX_r榙Y5˶!`vQXG  hwR>rG, ѥE#lȳS 3̺P C6=xJT[sIL(cqSa*yAyo^YEask/Oͤ`0&0bN-+Ytaunn+mJzςڍߊvXX#5',ܗt$dMD6fJi-f! ܳ/l5 K9s烸?\t Uj3NDf*q4nEh02DQCE%~/=TD[C[AHam[IzoAп~NV~'wWI,1z&iXtsͬP5*+礭'|TMRAt KJ>r SA%G{hh&Ijzj ^qHiQ7҈!,~ń-s GV8-{KfAj’\@1@o3c]}T\uvs sFjm=/eZe.[^dc2 %xW(m z+G[¬'k'pmG(FM53>E PlPNס$tD\P %?@@0ƍlHTFWʖ;C*Ȭ7T#LZ5gɪ]pֵ"/D'vQwIV,4W0sIUsL^s L Z> D;{Af0ETz x zp~mTՌDr '}owWR ǹC`}WF_՟wы]6(l߯׹ ; 㦲Q)oe3d 2eL$ >&JtLpX4x:clrkN?u}3֩Zc,@)`^XRRf92kpF` n`0)M$@oLCӹ#2YV|\ Jͣ_˅ùUSPQ 1cO!>6;~~!d#?ի'I+d"cptT^h'E閬Q[mۺK(Tyo9S.#+n [OfEk}6 h%U-D EjF;L12+ B2UjS-J:LԃT3D& S&yR; l0*mc@W`8v97jةM-x9).ԡcre,,}Snf6bPc@nG)*SSmHJ/ÕM b W)]6dE 8rm`%g[qBEPh6)ZEUBw!&JFB4r,:ȩ;>=Z1KPV=qZwȬZR_: .F ]ChfRHapځ@Z"9 `YrTkEe*:HU7dw ^U#ȐmR:Ƹ,KT}Bc;~\UU-g Oskq\ghr* wS.d>.\j򸏠N.hejGR¨5}'O#0L:De0ڄI{|Y˷^ Lx8G%k~=!~ LN?# ^D[ykw(6M(e%fRcdQ5!L>¾4`9R5`$i}I@6($!LW&\/(ftE(/]7_E* WU=QJW+"I ?鐾Ё;ՎWy_)7KքJ=E1HPyUG*--٠D4#bc"nv/uߕLwMM#5cMcӬu(YL6x{A3%eѸw@=|8@iw^ &Ŵ_ e qr3[7 9罀}(K'NE:C@V.VV =&%^[#W,.@+K `YğB*$=;9,-vTz4cG؃ ]g61]y+-Pnj^T>|[tˁX`{=i舡fT@).*6pۯBa2LWZ}{D9[H+D~>aLTS7<`#GB4pl(_AZ7 ɡiyr_Aho 2½Z']nF;]wheJ&i4EY?dLڢ@tAj&R({Y~ )Hjwxe}*N_Eh \ϳհh >c2>gA'5,ʝ)9Vo(Ҳ+X-E(+ W1[TTzS#w76jHchYfчQN>OQhʒR}٩IClqޘ^"7\1v>fHE8pmb[./YvypQn d}8hfu̦$vBv3Rퟍ [P~[uӐHЅP-jY5ݩO;(F3I?Ir c 3`.9H(p3vIM5Nl %EsIob2̓W:=*f` 7YpS%<.GDG0I u|}}čn  /,uWQZF( =RWYb0}`"re6t52RP*؊$kl*i/fˁi/Ġa4#z)rPm'eّsntȅWq@28Z|u66H)K$ )Ppbb P00ly1.(;HI2<ʝ}( 0.9"ji$(ۣCXb#~mRgavHBY;vO=Ib]wT&C~cVܤKa3-~jB]UNƹF  $o 9U+]ҁY?I?q"&7 .6kep~sSDƵ0h`A$SQ ȖwJCg| V^c}v" >I5jrĜp+ڛݰ~/b )|f%FQ:v5@xWmϧj'4u؉Mކq_m) dZzPY R8V*<TuzݻDJ Q:RcrZviO ĺПrĩ8q02M=r? %sґ 2jwL}rI<QJVF)>[BV0/T)&~6h~+jUU5{ΐ̤.(wUђqwJmTn6+s9q:3Qw s2YJPx#!8Haq`:Y2j&a-} c*CB9Fib6b7~îVS-/Ϻ,Ɓv]~Fx`OeG (VxMH6=%gO6oZZX1(}u6 kH_,vқijxLnYaY K n3v[޾K|WsNb.vc e7]E3f?Ra+csUg i.ngOkkqN1(~ˎ+;r^go1O~i0q^*ᦝB!GT"D$BAxl3I \g<_-(TU K $Q!` Exb-?LsP㡌s-S|I<_æ,ufV}::c KAT*ܱdc"oMURv<9OsbGnUߢн$mC*qBL7c(G2@3aЉ%'GP0ϫ4k $u#G`Y%ʁuK)jUgeB/btft^;JU`BkX r>Vo[6Ap= ??I^4O3t ~yܨ$3 ׫xUCշ O[_,\ګxІd Ds=ړ6V*-ogj?؀)#<'Q+z0zD\X\ T E<+qJ|) :e &",g`C]e0hƳ8؍B57~ȃмBjӑ#wǀy mEF *^l?7 ,{`7]t 9=blye1w.ڛNF!6 M68i,UstOqU&* Es4x7+{V|w? X 4)ޕGSq'GnwFK[z)ؑfp֫ےL?vX^؜kO6붸[Qz Q=gKMo9SqCAƚz)Y\]Ti ز0><\hP?,ƖʭcE[0Ծ7/bneC` 0c9eVp ~!Dz8OJ}Jky1ń03bK܀)i&]3 K68nH+;e,hQє9 Ȩui>zʙ+DVmMwS[TCND膘gꛉ'!p"@)42;\%m[ߖ<*&.V:I Ucci<&a \_'-s26G)!ez[~UB#؈ eYpvma-'%rPKlh/xmae l{}9dR]t g_4VZ^sb1SΚuֿvĹ:b-wi2 |/%-/ZÚ3) k@oO' hY_6j6#@Qll졎o[IJ.υ_l9&8ǸVK!eºO.?PiZ` N14E| l1J 0\d5_;<>Jѩk"f.u>t)/UXgN;fVu x'$;al{4bW}mB >.iȴzmR`]խ [&<4+:?ב;A?H.T…oYi=2d=Ij{~ۧ[cMm H61V|cRruΟ+suƌBdR F)C NLYNj*%GWAk @wN6֧|^R6qxoNTL!h rP<ⶻVM3tWڽ'2Fi> ¹"+NLQ=Ԝu#j %z,tSf[ GG9\_A~{ZH!5i^Qo?i158PljA:{_1q`2>ʠClB  |U'~nt\BR 41h ma=zifTP\zTޅŠcs[>$qN@g x:pH/&^.ؚi\$Q .6$j-1 ։HiqBQ-NfR϶eʧxW!Ό2KREn=8 $N"u:8Nj5!/Je*.15iWy+9O)1櫚êwB1 ıϽ '?:ŋ %۩Y_a!_Vm 3Uw`i(7.G%6= oA:z}! uH#? p}ţ}-?ο#⛍嶸F5Cr*XbJFÝͤjW4 58cc⣇䗐e|횾4/OvpUL=8ץ=9Z:UϕI"FEf| Q篲+Q"+N~svɔ0늯lN?5OTW̔}KC1=a|K_Bؽ8U NUTc4V#jtZ(olȥvu x-ko%C܋Hh 8AIF6~ʯ OGfpla:FP8+o%#͞Alt (UB˯#ژْt|u %MnWKۅFs&Tp{%dQ3dS ךno^l%?ꑬNba#e_m,`Aent^] 8u.G=bkԉs HwlmwaT-cP8;f4]q"#^xѤY8maP.6QhB߸N`si Q~]kbF=3sCkǶw\m6;[ ۜ6)bL1B%:LVFSuKg(a #͇b%L2 %8kOIPZ Ufud4#DE6LR[LW|hn'&snp|tt +0NY,Jh?XrKūNw] 17)[9I6uYk Mҽ?e.H]^!rATu&8*2Ʉ!b=I)B328z!u 6r" /a=}<`1SU/9 ꨠ><?Gr8^i5!fg#9#Lz$ |C'{rlo!+oaDۈ ӊ p/ ӥL1$ 3`Sd;@9-=,bϷpky۬f Lfí'YZ-=_$`8l0c08E+z8Jc].5sg9Xm'R-(*8Q,'?kiURonp=4+i-Vf%"DZ :Оu~ۆ;Z8 D#AǴu7aW z0 ݅ BW: WFL%%I4nH:JT1鷢y|ʬ1WI3N ƈ}K*<k = YtT'" dU-)5x+i @4"(nGU1sk(q> J.x|{K ._;e1V=Kt#+ (\I";b=ۂ۽BC^'ͳ>bNӑc$sE8.";d4LC=u=NGF'5J2gAȯcG<~w;ߋlJW_xLBm-q̕^&W{<6-)ûnLU?#o$x[M;0 v&( "/𢴉O/7ҔmR Ay!c\-UM=L9o|F^ώtfa#d)bn \ُ¼A )To^vaa*{jJcAsWW"A۠j+uضr _pVJ:\> X]o)Xl)dԹ&tu+'IؗIOo˚ll%6|Z > ]@ &k=;8c]AK=m|tWdic+TUwr)R`ƿY^{A:yb b%=Pcw7BM }ȚƁz+Vubj>.0nX)1L\*MajN=R͍'Md!fyS) <'SH['sh~ȿ-s/E?whG UZɰ<6hBmcD3ۙ3'aHFERx\~ #=WGW ZO=T5:Hn rء]y3^=PȌ[ +j֑7j0lN%޺o\a EzOAii"9(E@F+럆X nИzrp ֈqg iw[ݗ?AO0쳛\j\8bPuKiYn7ۆMlЛ'!!7ie{0\65R"xZn-^`Q8x-(s"h36{ʍ4D:Nse[xo{Q9^!ګE%f۴KY8S9FE!Yos:\[!*qW! j:.UzjTA{.."G:3:Ro?sK!j:-LQ=Xxob=>ҏ KgFx4h}VK=s4Gg߿E筬H0mltJq;C|&D9thj's]Y7D4rl6!+x8{|}€x(*8> 0X򢣁Ԫ2A,Mk/8ʑkQ.sĖW\ɱ{g" zjN 3Np@@1֙nDAnwK: ?/07G-}Hc%]g1O=R0tK.#+ScoAQިvIVs+",3*FLԩeNP5!t,F7{AK蓆͗.z2eZHA>?%pʤ^ e7%'dfuegzRP=Ci z}1 U3W %T̓,Y{BU1~ mlX~=Uuh瓞֣[&94UVd"%{oPZt>v%@Qw'ԏR͕YNLWI@K&wLӂH>:SY|jR81 Tf[빞K=,PA7kی%b0Wm;`Jh-c#5h`o;4Bo~zEWLl {C#27Ts(~+_xtkmr;U[nBSݳ/}͍r9aDHd.EmY'G֫Gx 5x syD}тUñ}`8 ^nxYWTie;c-׌i8ei=ζagaGo;kسfa-S3nc0ަ1p$ϗcIAU/0c Um:=/_>Y;Jk?d=S^=eygwŲJT-ڨc‹V~hS^|@qmY3"ц̄]JǼgYs A7fDgfjf뢮9u )2V]*G~ xceҨ{ ,U 60p##ד%t@:zDY!wu}/%HfV}_AdaW%i4fuk< ~8h h!$;2vpSrdu6B/tkn/Qd 睘SApMVisa%p Ʉ)0Cf%ֺKĩ+.6*5F*.P :կ} [Ig!pkN[EYǡ'$ocirުjo CsYQqV9GRl=UP?!L2\Ы+kNⰊDm㟲|Ufg{Qxuc8BL&4ɰ 9=ʴxnqYI[233ᖒT`mb$G%``5*/zEIH{lDПyuͤU+ppwXU FB">Jb4b]|M͔`)!&(jc_EHv/b˷-Y|>u!%8 M vx@7*3Qn?wo76!fs#-,O_êkxFM~wgU*}/Qؽ:xɆJ\ S  Svaھύ6LHN^P r v?6C3+-4.Xd;4VC] 73f*U#ѾOu IF$bUWxKWt F>-O4>hm;ܢ/;g8#f82ws^L:ŲƁW;;jˤR ^qڹGM:D KVOm0ܗQZwZ# qÂ=O9vt8Jqㄯ \%/ewTEfn7d`9VPT}rlO+%bb7Cɱe!Xb3 Rr` B4nX@HpVr,?WcEuK: t.;7S:_"!C-r曹`# NY8b#{^FN鏇c%Y'W| A<9LP}oD&͂6?Uj)<8@ɫFWRTA#ikg^]ʩ);0\{S>;/80L~!5!2M}a7FNi|YOiWet-XЏ=ޣ:mٸ)b]AA?Bi( _4&5%Dx? h;T0N+e#W$0T/Vp7XH3V%- USZ>*yp o~J*6owl+㽹M[hbBˠ /̻[asa'x6 $ Iklon*BsFzcmY4cFr1kCVэ!UwⲞʿbK҇N :-ୌbZmQ˚Fx{eZ FJ "CՀ#hᏥ~\Ycܪt_:xfI=fx3PD(m'c-O#_ߘ$ctM?x$}`vuqQV~&$4[l6k)g Ag9V>vw> Z;L@C{ - $ovEy(&:j̬D+JF5F +5*ew?xVVz=ajlcsqԲ?{x/4ej(Chִ}a@y[KkQ9}4#DZT~GOc0pm91t 'mE]xvf#)udߓs%Y4׮f~,XYcGBߤ{tHc9˚yuӕ)oə<.wρ[~guWr ͥ?=4Dm%ZÖރDz=VM$<1eSPG99m/Z,.Z`F륧ȑ"8=Y VP\&ۦ1tWɻ /H ZzqvUqѼO^<"N>s0ܕJ01&SVUDA@0lz?׀EsWdx+k@n4o&y2w'u+*`K*,CYr 4K]_'Q_5v_kG(AOϡn?`rd% g3?hRCNFYH ҂8jFoHSr6ܨGj _de,%CM}iyw=Jnrcۿ *20O(OLfV@c)1dP `;ȇ.irqAN.3^IJ I :Vkc=:-ߗ΁_ls ]ubn)>s=z3/_;+u:̣MGZK g#[5ɪ"=ӔΔm "n3n(sB 5aG;/[,cz5hr<4&f|d߹R hz0 X $E]{PWd]HW75ŊA$96pJ9fZFl aodСAhyԾ`/?%5CPPi::GSݟ@=2H<ʒ2:iK?K~@knYK WߣdXK!%Za5z$ R3]&OMyyŜcġi廦ҷ|E!NgՑ0蟟)l0F.\o\>%[ UR$nhǥϗSsz.m%ʜ2SPɋUg(7Ns^ ]60kA{Nh_]ogoޠ1-eӘ@XᏁ*Ɇi=ལ=?2 7*(|sξW5mH(p[V[yR=,, HॱݚN @71qEE7+[5'>'H&8s VYG,ƆĮ+xGVE`vE-)z|kR٠np0, =p46cL GʼnMڈ»"U&p\_Ϗ~: yt%cNJI%@&s=]MJڎcgTnnfqow) : T K^ߝM}"KZ"1;tv607 _nU ,<#v:B{<,q˯p}gLy )qRt=R0Dp_IדY9'8 '5Pn[mJ[7^3Lɱ|U~f;q1{<,91wO;3LSp߱dCߏquRJbBgшCuc?}ҋzQrl\48[ua.u؋1Ӻ [ ^lurV!mmXvBN'y_OyL~>![=67<ǚ|\#-yl x赆ҼoذŮyxV}8Hۍt<~kqGH_~jʢ~1A Y 2zhOGvC׆2t_)7;toͪܦ&d]yA+sIVڀmjض:Q aDk:`N%}~E{xfr֙.H QrH2nc=] _~5ϴs{p=m3B+?PXdbحT&וk:G?SkrrOO  S?Ǝ$SL| و+6"J1=렽}X8ȍ {Px5\dW'%Y@NxMnQOpiL%`x8k< =+g$eU+KBpo 1W9O+2rl"' ok/ژ#O:%}rpur'@A\Rj UQK S<;@w#@Sȑ\pA*9p^#bw,(䵠w3@3Mhn)3g>8%7fƽV1-N\ྐྵ@-lK6Af+d+$Kȋx5F#B#?bټC#ވDzbcK Qȸz\BA O|X/1>B$g9k-ݹ\ٺiS:S'HnpFT33$hDh)E(6;bdf{'M q0}d<Ӡ+I4gԆS}~qS>B!^:Hh&(G+.E^D\^Y̘Ҁcq,?B7}-VдPuq-o-Ow.H4M42fc+vC0/ɂuc ~'4A5?`bv-|GE.OH(G ~mEŋ0+TfݛWlC6CJeQ?\nn$mrp 7IT^J#tV:ɕ?-"0#r+z܈Bp/`;u Wa[g0ՎIa3t8q3Z:%Xx&1nE=0}LCL%Z1@5}a=?ϤM*®qp*͡vX]G>(vm+KtK˻x5ytڠIW|PQbmpN!\BwiJmײB4KZ(.n!t$g093]/ 3WoOflJ QE@?烜sSWeN#Svk48J !LwRw3pD,u^JrpK.pmN<1ΒD{yhV)-Ԍb[adЭ/j=.}agOqq]=Dpߛfgil?|37ԇd-_.qoރiD٠P%^zzyamNP#& b.ں PTֵn;fu{N.x{WS:C?ՙdl5i_?"BS_U3I(]#!|y)a(+lWǻJp ez3K Gd JŠ vû%͆@3dHQؼ^Q.5wXsN%oM2o˰e3}:b&c*u( 2<'e #F{""{e>I#8}"з ^џ+XcȭT6|M5{%)L0n3Gy`PdT l4ȝᅕDʓ_m͙ C1s(NXS,p;QiSJ2$I}ۂY{r&F?FM0Q&VD6K?b%vfը9IA:akno}]u쟼.VJM'EF ܎8x D+l:1Tw|ʕFЊWp,kBvd> ?Y&YiBq%#т u׆lƹTġ"W +6Vs +ml%+4BtD0Scea#뚚-?03d2FlY]'NSf#;n\FkGļ(j=$Fv",D fܗ2*^l^_DDօ7A@-qlh]6@S-ٷ~\8j" T.AVU:Fq4fuzdY%Z]emTZizu!ȥ>Nd]E0tu3F|FtHx57ZEQX=V"y@pk[JmTvdfX9(h_A\ uJPKiqRt4ős˫36Qݼ.-KxNn 7cC(ip$ՁOXRcrݧ-6F R[#kxje氍8ՔI4KZshox]D"$3A+gytɧ.Hl]_M7e˦0˘.Dދ(>>o3N1~;/Wu99A[/nZ/!E{|5koqK5bq8Go*EW6ŀ^KxiƩOU9gpo,cqbá^1Щ` d?!&.7T>†`_Gv:o?$3CDi2KUt~JuMaU:biǥؼ7հB[Q3 u]%(£&$Ozkf2R(|R~/N䮌u;0`ѝk9\>}/֡xv@BQ9B1J6QjL8A"[KK'a)mU _QUr*E(*^#lʓǞ{f0Ǒ&7AO=q[Ǯ" fIR6u}#l\#*ih4ef;>WǺe8ʻ'IO@sY=5 >dUlLeԱ CaAH6E4u<@GUcTxpG]!O $ Qc1 F@.g{7livUMQ=smj`a}Q}Z[͜Y*O:QCOM@fL^Gc)ROAZdž7Qv(db cٳ @#|_٠X (Ɏex,mX՜T 狝TPǜ&O 0QY\<9E,:I$RoǼKh5o8qNo߉8#;+q|X`XY2+Q$}a`zp/]hQyXgsl4쒉t?D¥XX+ţx>e7[zI9X*ﯫвg*~aDQ .!Uc?䫜$M &:xlEڷacAVq8vguZŰ~oW.񈀠R ͟W!B=y|!z͜G!_h?)fESPrALXɄ3RpZZH6NI8_ºWYwMV 95n3iGja=op樨V?]ů7%CCz(-}2$(iqB]LOlR#:wqEsjא$idolP7v5*$q"TӺ6gZ,Vԝ&";dNxLǖp<@? 76|F7,VIܹj@[mBq|BUS*7(ySHJɖ- 24/Wu"?ZfYWU{ 3M rwհE >7h斤2 TSz^ nK_"wZHfCMp2i6G)A^S|VdگyNKPrrAdYѨC d .ysb!GbuyMHL2|=CjIΜJH0~cx$,?;=wj.']cq&޹JN.Td,2XYEqA$D-zVk8Vd%:Pgj|(SBD/aS\уČc%<, A#n־!$(*QU7\$Ґ-#,~mJ*@mcJlHͺ^ŮXW 9(Tlxp Mq̸/V'60C%NJ IwbʦgHEɏDWQXbLvD4$z<%䚔=Є_#U$sԗ={oߐEDG͢ %A'%N7v*p=swF030oQrߣ6 n@PyT$ҚيU3cTG\ *)\:l9,$ltLkFO{f9vI& չPaM?!\gd4C3 kEs2#uF>+Kf濈OE!}ҁ`s?$kgI$g.JӳF՚IH?əjN'ZW1(J=)d  ї$Mk&d>Jx׷O!b"4'OFXAtDJ=Xt0e6^1.! 9i r?)~]$o8wqS&;Fb'65ؙﭧ-GADZ]fIʀՍNW^~H!w59s%u.K0œ40k:ď~+5 $1<;kLLҌKDY\Ĉ8J{zC' S'.S}WJcA,(cI6k$㝆5f <8pgQk2;Tx3x{rAk9똾-f)-#3/݃qm`8w6DXvg=u\jl'Y> hۢd3'}WM?B9\2iFޡ'e6(y eL ^P;hmq[Ny 3>ZI/P#ꏞO o(,Ózޙ5CJ92s; : ۣKmc{`ޟ&XwGn;F#fZq$UXuOW {ڕ =j)] {Q$ՇIgJJuErnbm ~IVt =d0rCXby]ɬK-ꯂ)ƫJp![(o*WM&M[!'XM28ǢZQP@U@H`U ۧXY'ѻcc#xx(;PV׳DmY 1e (3+h^I~b-Zft.ihW|j).9P̯XK?^x;T`QEW\A9w8lNw`k9{jDoF \YlW"lY?isԶIU5W݇Ioy̙")Rdž4Rd!ڴU`PfTD6z06 ?7/t(a9 YZ