sssd-dbus-2.7.2-1.el8 >  A b2U] ]}U/dXGt*dX7m$,pB?d   8 #7TZby 4  N  h       P    @44 4( U8 \9:c>|?|@|G| H| I}, X}@Y}H\}` ]} ^~u bdeflt u$ vXw x y)Csssd-dbus2.7.21.el8The D-Bus responder of the SSSDProvides the D-Bus responder of the SSSD, called the InfoPipe, that allows the information from the SSSD to be transmitted over the system bus.bǼyaarch64-01.mbox.centos.org܁CentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxaarch64 if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-ifp.service &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-ifp.service &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-ifp.service &>/dev/null || : fi%&PK<  3AA큤A큤bǼ/bǼdbǼdbǼdbǼ4bǼ8bǼ/bǼdb=bǼ'bǼ'bǼ'bǼ'4601b3592d313effe1a70c44167775b06693dc9b72e7bebc718b6c9e8b094b8f09f028cd5ad8b15e0d13531d362fd4f515952a830f6c821442cb3f901cf292a9e5df458062df0e792eb497c5dcb08ef091809d838f03aee5a21dcd6d9ca824aaa2631eb70e5cdc8392c97e19924dc9aca4ddcf4b38a44ada079dbfd5f3b5c8738ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903e2a9dc06f99b286b0e0e5402d92f0a94cd949224f0bd5c308ae3e86a97b61cc007afae603fefb2bf3e4f20875dbb5dea27479cc8467e5338680e668bed366cb4f571bcde2cb590bd9c9330163e44ed3f0ebd52bdedc57ab87ce54ace7dfd7645850c10d58686ab592bf40b4bccc26c79b2e63a46aeb90232fa6ebd297cfb8f4c../../../../usr/libexec/sssd/sssd_ifprootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.7.2-1.el8.src.rpmsssd-dbussssd-dbus(aarch-64) @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libifp_iface.so()(64bit)libini_config.so.5()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd3.0.4-14.6.0-14.0-15.2-12.7.2-1.el84.14.3ba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh rusvuk2.7.2-1.el82.7.2-1.el8 org.freedesktop.sssd.infopipe.conf.build-idd40cb686c87dc833421218b61bcb007c2edcbb6dsssd-ifp.servicesssd_ifporg.freedesktop.sssd.infopipe.servicesssd-dbusCOPYINGsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gz/etc/dbus-1/system.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/d4//usr/lib/systemd/system//usr/libexec/sssd//usr/share/dbus-1/system-services//usr/share/licenses//usr/share/licenses/sssd-dbus//usr/share/man/man5//usr/share/man/ru/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnuXML 1.0 document, ASCII textdirectoryASCII textELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=d40cb686c87dc833421218b61bcb007c2edcbb6d, strippedtroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text (gzip compressed data, max compression, from Unix))R'R#R RRRRR)RR%RRRR!RRRRR&RRRRR RRRRR R"RRR R R(R$R R*RRR.utf-8f884c2b39a3d5f6dc35f4b8ce6e6bfe51d8710c250340260d3f1890e8c4a418c?7zXZ !#,Ԋ] b2u Q{LT/~$ ;QznmAaܪW߬;KvK]"N^<5!wn{]q_sFQR +kl^j%^m|pe~*~g{-=dag??5H1"~2PRQlN&4Zy39A kCcl=RAb5%Pj|@ㄨr?rf0`->S?8TzW ïydmUizk$v m[ -DѾ 3'ٲ}d;Ј:&+B||E6)#\]>Qm`QWf3C:Xa$XSkE?B|)&&9Gj:yEݡu)PO:J /Njv~vK@,k tn`@L|w7|nfH61K_ tpi/^ X]Q46/WV{1R^QV-5 MSޖ) &5FIZj#Dg0"# 4uJ3;},p:qPI4Njw̟љO:6Npܤ58+})+J':٣+r9Ϩ]@NQ \vRBٲuu<9w7^6&CNQeW_I^Jwgo^ߴQ6AP ȏTNn-:0Pc/[ X P],u4P1V*j: T{pK =LD G`TV眑*#$%HsL?U@◾_b>MG?=h%\ы̺]Q#<ܪeBIO׿$/W%YSVvf SZy,Ѵ/J| Y2XT-W ½SU*\`Y#,D!T]EudLJO^vmHvnIQ_Pn>o>6߫n.M|})rҌ^ N0|XJ Ewۃ"F?qҔC|.$K+&62;hHR G>Qm3<\Eײ<,DIo*S\CWp5S#J-X/WR,3`&)h@HIn"rT1ߘƮR [,ozxf?)f7E02B!{vf2͋Bog_&oɥJ9{<2@#RfM/}T oH,pIJUmMs֨('n՝=uV!ح cET~ 8Y \Ͷȋ ҭ[ :_Xl@#_ M)2CШieŨEiE[Y.HS*,C:r0:눥nXgQca7 QKOh}Y_jG vn _ȬW5HSݞvҡ_DT6_(sjU{鸞]m fؼzz4mVRMKXSsn\iaqK<㻰&S5B譿檂ٛPVVRH6u0`D/^),Ǔ6HoH/|d}瓒!VܨTCMj ʓvB ߋzD:ՠL*<\HgX3uQYaM5!<XD?ŗ0լP+>v:+i"UB.YL o DkYYP 5$$dNga@^y'Ɖ0:(]euMڳ wFOpoS=FuqJmY5oEiFE5;f}7XT>d}#2o0F'vOC*lGEQPȵUDCFܭ' 0Ej*2"kq| }wqM!8WI`EWHwVvT=IJVݞM&E~4E 0`n z^@k}+S~8HzdәsTKsy@32h-d?0Ko%JdQW%蘒Ǒ0{[cMa~±ݯ7X}>d Ϧ#6s^AC:B&ϗ:y:h)iWK\hz8S:U9piqUH.GƙQlT2$/MϕJ4S]-G%S"5j&aj$ wS*t"<)GX'T$!tZ咫JNRZtgz/A&e_OD8 KcIa߯29G#6 C#,@ԉǦIM^DI?wP[tUp5t;RzV3:zg[{ب)hu:gT2!&M|BM,~Gnؑ#5IAR4tG15)ݼP3^fQk†Ia#1*E9玿4CXFG%|"-'/i+F1FbHĥNDK\vQAђܓbyOl{ijwn[ R፲?&]slqC#c&&oV6y(>{0sA:Z= `JpL~d'㯛gW[֬yh`$3k9js I>䧹*jjԄbAY(*?ꧻt3\1Ol7,qM-?mK:C5Q|KۨzPiK4fe=,[?H:[J,ZF<í%]g:s6qex&"7_ϻSMp$GiOE2@,`ajSj2pwՎ oh<`c1B({~"`b-ӎTŕFdC^m$&"Sw @kC<\AjiOfbE/:5MwI XH'={{K3RO_*Yk̵4Qw zx DU!'YzugM8jA fvυ瞊t-Kܠj@|r)q-y2433:+(ײ f͘}!*Hs1<2߂F҆`.̡(;hG]94mi8^yV`${y^cD4–ȴajJSoƩ#?N-a N0Wk]׮97pIH= gנDܡ_cO 8 )ʠaD/r;f.66 K|º ^6eb6րw%? tll+5Ŀ'b˱dEaOaˉ1Dvdg"KE=lQE )By]?t߭ Wcv JhfN,k(jM#CJdR:-=ᑭstI4GK@zݛeX@NX4ɑ1 +2[QxޖHV[Ep@sP4|Ha,4)T\[.kHRWU=xEVF\ey|u~-Z?U 8wkţJS D޺IZO߻Q*s kmX1r4bQ̳غhL X2 ڥ80f U?L{w IV  9X?mzMW_HNA\7DSGG[ NgpwJayMVmN+7;Y[lE  YP=UKq׃ un*?HJ`}v!G>$j,>o.4 k;(]YN CX'z '¿oAlU)YKG5ШQì^dE+6NA+z eʾz71i;C{+R%etƍJD̯mhFIspXU:MWohqLsfU"k%26sXBMCj 0~۹t7+Zq*/+Kݭ^n6/SO1>!B{s]}R{(۴o*?Tw UWHLkU) :%$"p8hTvOX0򴺮3DIKYR,Ca}|C ̺Ĩi0Amk+&2c$*NZDrOBuAS g^ I= KUNlɲ5c J|λ֋I^j `D0]X.j5 MvB+*՛#˰~RQ\5+4w,/ AP!+|[c䢧QG:;t\ 4Hn$!*v3MO]򘍲+q6?[8fWE3:;Ł'=Qpv.@xgE5QkJ@x"z= ZNRUԠb 9w]2 5M `0.$*_u'A߱/:̖8 $TT}LL};BJdz>:w W.ljbެS8\ 5CȮxx? ¼HʏVh^Cgy /v'-Nri PK\ vM-Ntz+(@=С͔1I3V 1C2M'BpSsL,51"$n<@y-* Á0 IWl-oCi(E홖4${"U}6sulp | >Y$Swqyl-}#C vcXaS9`Iͳ635;%kjUHbq"1 >`.rTCep,ͅUqiRf0NvaW*MdhAiqNJ}D1µ&}O31 _t0i$"s*6Fuf||$2VvJ6#VP FZ%%km/lH>;X"fNۗ[$}/S? Bc#8'c{NLv$d -o\@>=Gb xY0$5 ſu*Czĭ8o'Qb[]3敡ВV/YZ9NYv,q?+ 3YOyun!)b&_|՞Bd's\W8,Oۻ7۝&+lghsSVb"=`E$⇶鍥SEYȽcSiXug2[1H=`#:#.aV<'*6bF~{aH q})7rw[vϓ:xx"J";g6;L5–ʏu*-:$xll]'b ELD$OxK% &ثs_=oEP"M/}%*<9g^H4/4ӠrifUAYw%+,nꈸG5||EBP~NNjVHTmrAD/}fҵ^h7$xME~&ߗc  >@EI %9񵖿_(ڥ RqY1o)7Pв^ mTAul.h-Axl w\ExAŏpG҂䩇 3&8[令+^5.=fznWXaW*@>ou3rq_+=J-FzRϯ;[x<*4=LA/bFѷ~$FìijH2o4p^\Ð=d5$巻| e3G IuXto0{T{z.? m 'yܚz(: +R2^TQL:~Se"o\``ըCE:qZ`Ab7˖señZS-C[l @y#՚!zk0Ŕ:ޏ*l_Z09S1c +"x&5W1HMx`yMffa&ҧ*@աo֩b9 q#VE#7rTĐIjkg<[z:/8 7?I ʌT /fEvabIo=t&ʆГAa;)E@~?]Mb{e2dYS\K"5]B]ՂO=2HBySC GƤQ.!9;PhdAscnoi8/d{urږβ4Q3Ū=zԫQM_",/64Jh.UkX uHj!M{^`QkKW eUʲUU*v&Q'[v弗 $A^=kQ4e^ h#1VgM?}aJܟF`рw+kX`o'F7)shedɸapt*Ȓ9 >3 .D~"P,t0[寖MC5*ə,Wpt%GםԹjpM.D2!eӑQR7o_J!y&P4uO X BT{ ɗ DHBglIUy~!1%l-<ѫCo@vdr6t7l9  qe.n\@N,Dew%| Geo0e%C% IuYW% x`pzP Hl8.'F݁*ou>0h:L>-[5>rDƱ$ߟ`(7I;tjgѹvVnwZ"S-t{Q&Iyҏz=aT[B׹6w0&|FtjBsE"pꮖqh؊~2̻pHfd6P ( !ȼۨaV"tK;q4"PSGB ]_AɡDikc>xT@FG?DzG%)uߢxH>r8Sp6\ >yi8u:W9 7G 3fsU܋qTr3܉bXFp}; B5l }:.J %xA@vʻb(K:Q8!(?U߀vr'))8'GrGc?DOSEr g2llc,*+?rZg&֒Xw /"u cl2%-Bp!#_B \;p?%/2&cޞ.p#A} ~ 5!%҈iʹ[QMQYcX*$,끊&C#;fGm;Wnih RO}\PH$>ˁ{m\-#]-}m QoVx<96 Zc2 Dr:p lS[WOoH'RPr֦N쓰Srr=vν2Os_@Ĉ+XӀ>;8dgӆ wqD/BG\9gP"XI"mC 5`%S%q'VO5ݐdgWzfշUyj6拓3g> =1b4iq}˛iB aF3)aJ+$:8jK:\䣃HG4riA7+ؕ}?)r +#Y %9Lr)պUoG/SFũY q̓kw3xʴ*}u }t9f0SA*0g'pٚ>{1io_]ɯ8_޾OOaW'~ΐsǃdu j'BѣA'؀Q IGXN9d7G=9"]W䍗`G zrA]:!Sajz,Ƙ aaY)./}ZݪH:/ڤƵ.wBlѰ { ѩ&k1C˼*A gZ1M 6T$ZyWKh{kU[^ 5ׂ١Sғhl5E޼9i(qg;fs' rK/;B\(c|91ɵB bmXn_g, HD{ --MtTg)g5u@IE6~j>%_g6.T%<_u8 ob]5-3RhSש(քAC[̀jv}>yS+TDu7aoMfmf_' 1hPM#!ͯPlBLO. hd>Z2ߤ7c",ՉjΖOo}T_ZJMHV6:r^_ nxha1Wh@7%gl^ԔN Sv؂n"JlVYPo=HFS1u J<@6T|>yP} Cf\//pnX.yZ &k sQLiFN ޫ63IWz`ThCQ]OʁxS;؉zηBu꒵r߳ ܡtz1H{}\Lbk#+{z"]h ng_e!Z6\I̪AdjJN\=]PŅ@~-Keʂl$ li+y,iX=>.A_ sԍ!o8AInڋI)9F6tm9[qضA.oiCa,l.12ej8ߢ'77c QkKtV{[㐏9D6O>#=bܺ#>"ToqD~d:AE ]K4ށ>Ik27b׍wGY<~>tFAY'ݵW Xje2mDp%3-s%ъ\9yX3Rg&)oLzGug\a9r0GDؔsu"mU6;IwW6\ALtO$rؑ@Z2Yf;p2],% 6Hfϟk-K*φ,%,/0 @`oP rBD s$7v+kp'@Gv\x6?#)IaָԌTas)5K5-Xu+PQʼnޞ^eڰ9cqKv̔ g*g ԯօ}g0wQټu.|5OJuxWK$Qn]\r)1тj4^WqI>6LZN]mo&/Ӟ3C ī)@mt쁛;inf^)jYD>GH(͇c8vE% HPld%d < P>1r)w~gד]&9& fRbᯚzR9jD iF )EJ)zFƂS'(Q.xZa\_*H#5%N,rd4;if|*u]@}&= ۉ.yCW"u߯VC Pʊ$SDTs} 5וQ]Kd^bqGJÙ"("0:~i/(:0hl\vH# !~C#@AγYgkR| F< BtM`F5q.)$.t3oOr?M2H2[2!Iǘ]iiXWJnx?>lm?XL].،v*e j6f:kuLK:,zbJlNnmz;ն#& #ӂf\Y4zeWϜȐ}  ]*Gu+ jr5)-fD:D?ִG F>rED*CH x0yd8lPbw9tE? :7S)XFtg*!.;M^hU ԭ.gtwjm ^ E[;䍨*|5PsȋnL ]W+/v)cKgx/Jbȕ0y;+CZHZ*%YO:ESE>YJ_u@',6p"IZښ4?)O[񌙏Bi-!N73ZM|5&0B@!u#T\#ȡp{%:·&j,0R򂤾j]3>)m]ݯ ם FhkC&1gL4j*hy|ae78% B`tÔ7j>np>kaǛ0^iipD`˖ⓦ%bFM6],"X:$6b.ښ%IƼz>ɀ/|V#1XJSJ{s%k9̬OP7*}lnlּ':mTݍ}}aM\`|aެPRD+lU+\,Qayqvj2 qM}Fg.@oc~cb't{iZֻqq&׷w/ nXuk_(+H@'Xc]%6ށ{+7JAw`K֡2gK<@:' ݲMoĸfBA*ei#i,7=G9Lsx_"ժpS^jX(o6vm )|wp 7^嘞 )|K+/*I$*vܠy4_LX+gcS [acvb`߲cQxX) ڲbA^M_5DA .t GiH /k:d0nY+XA9q-/g:!!Tԁ0.~^B6ntjĠ4e?n_dSݚP; g|'ujrCN mA-FՏo=6K#O75HHa_FzW%_K͈ un(e?!c}ʇx qE9hX.a8>sOM7VX/c"Ģv1mg4WcC[1udM&>"V9Xv֓>#z+\ѝո]>q_&?IIE|3<SY=,,;u[!Iy5@X/\0nk ZO!=T>a'D6ier0yFZ3l]\zyfG2Hq3&pح] I  (zhEs66+~ xrZ Љ2ml+~w v|"f@"m0'U/Vp119S9ZQ Х3 8챚Rpר2w`C.Nj.R@]t`UH4Ђ\Re}?Вkbrn:I..R~Ap}ӷЛOu3؆LR_>($ `SߚG+FΖ%VI"ZrB7I̍ȴmIr1LK u&Oa$,0&)Q\hЭ=c['?l\@gi@,X/?e bWLC*[WCDrh p_慶ucAE_XcQJ8Y zoQ!<0LG0Bfʩ7t^d>ΣT4w dbб=> ;'c;ZeJ@d ́x7MýDZQ\ZļHG8ɑQh^ ƒ«*faT4]&x)E|X3VsrJ*jsIB;DV]+Le>O:c]{X[YʩcA?= ?H$T,4@]]%USS8icƌWY8:m""f$WwcCD%P= Toq ?՜If.Fzpv9żh9/zS4%+V?z vcHɰ6' b/* n8bG((C_wd͆Al]+Wm㨷T#-<4k?Č3gP=RǰazޛluzYO0oH*jP lL5IGK$?BzF (ty}'-08t6 8 / DO..?O{[,뗅ǣ Т֋3xrR)MٽX]][J_Yb ҟ3Tu`ˬD>sМ>cO 2Ƽ1׎\-e&T\mn# ]}ԜwץJeCD٤"k7}_(U'47)z &+W PW?K!A6q;43r'y?Eجr|Hf |MS;sg0Ƞ/0aҠPdAU6eY`X)7X\^YTز4)9ʲN}vfKm;Hyz(AODfׯ>o5MGo,]NYf ;1AMJ2#9jc]Q4u7dfW Q*k%]O=`fGEx(=u5- "|_s,%/HbקDc%F8RvνpBLmzd{^SOsq(blƇ.j@9wzG"7Fv;>=Ůp/w L|SfQP,x.Y \9$wʀ~Dd)~B xO̵i(VP:?)m|TG%S\ ߥ۷2~Q+i8~'38zu(ZTSyGxpX9Ji}2B%Ў03) tF''=Rfts0ݠF(^y؃°~{ P`6s"1}u]5K#E xrpS|{¦kxS$W?$60@D)C0C9ctĂڗvUq*rGTɀB8 _GU}537*ay>[ 4]D+ZјFPk Fڡ?F'FAzDr"#` ϏR6?')*`JsQ'ܷX=-f*sBk$vJw Yћ?D˵wYp |H{JS6Op2BPꙁ}]U0lKf샨/TFgm~n'?{xYVWΡy-ѧjGQ̑TxkD^C¦ΗW nmStd{Ɵs9ԎR9\(9GgngBd]a8WQɋF d7DQvd3_=aqzRtLeDjS:7{0H_E-<#ǠOIz,n`E<2W_wG&Rev;6%+'X|;@K t EHE۪ED@选ښqd0` !9ٌvQm:Q< z=Q4;y4lϊ=]]ޞ$ҕt#m?v-553P1ÍAG>vn7L<\fCCVk[h'vs#)ߑh.eY/Sùj#xɋڅ/Q"!2|^jD?χ\o/lCz\ 839Vd͏:{эL#<6lr_i\i ڒ$ 1F. goli "*>@_TValtXL'%J5.n_$#i/X-?ӞV;P c`Dtp3WoVzb1or! f́"Ѵ4}+K4m8Q8g7W?os0abO?cuXrŇWٰE.uQbͿLXB7c넫P - G''_C c)Mo *Բ#XR0{0V׺ YZ1p!YU9"`ZUru:#g篐(Z,s"ЏoJz JPPIKµNs&mSY-$-H{>I6eBYOD4QXtHǷwy 9}"zDHId-M#R5P"*JuƀjZGWGha{'R Rƛrk9?Jb]7޽eQkAбo0y]V25j~f[p#Ţ^LsB0b; /p-]:/h^:]5>+Ch~6G9/ymi^"$\$Rx_*w^]}(}Azdؚ?z9U%S_jtH$.*˕`S;'V7 L(rH͸u9IZ٩?KUNZOPowȤ@IwcMs֬&۪ߡ|i3xQ}J`@ z"Fj3Hmbg.?ȾH+A3MX$GƳQ81;[wk<J$g͜gօAO r1䄘K^+lG"r3O῞3~ޞQ)(ȝ" ͙sei~zSJ9vFWXUipk#!,ɥj6o.YVڸӚQMD #)ri-kkJ*22Way=(Nq`Ĝ(=KQD|+.^o1сhzQB}J74}Fq&S.e'&V׵ԍ*(DZGv Kr;\ܵ.vgpI|~'b^!uA-F܊i ?K_良'eAh/pB51O|g5N6は>;.)K֑swvVkksѸu|,^P#EhZl;J'VȠnQA+ !*S~Q?K Fj٢3RK;[%u] c'}`A%\~T/JQ_-J_<Τ}$\" CFB1|/8࠲%bzAJیVK yH-tFcLJ13_$/PRi7V"ri#?,߰U:Z+^9 L07dd^IZڄ1ZjԦR~d'p)pyzqDo28Kb_w^c+=u3p2 }e_wsӝlQ86 gWCKؑYH ,ZF_'.&@1hBM_\EP inE*L6~~+!:G,%AXdЀkPc4ZPɘ֞c6J"6Xpޛ>ly;PAf y25 L2o֚u_Q٠[s"jKX3+'fa7Nv]C;<|"F]ϣeZ֕:^MhDWFg=1tc3SNvΥ>69ET^Al+t'~sk. *!e BܧL q#C,@;<Rs~Jm-^Rk̋4B#MhoFEnb:@+w\Ma|$/,\F}B.۫?3{ >h.M >469XX-џs&@MHSE(Xk/̽!`9Oj͙!+_eē=}1Y%\;V:2ˤrIGW r&0<#Q-ӝɏ!4-w :H~@24{bv܏9mAoC, @Ko.zڥ#ω{E;=\3d<5 )H l v{VYEhHc2Ӯ靸R?SxnA覮$MoC Te\rW JЉ4@oĕTxHTluP†)МBx.Ny iMߺhqE [<47#mS7CQL"yHH20) $UAT^x"t [ft(3r޼\eR4HB0@L xƟƴEp[_VqŧP*ݫzM3p%{u[sm'wF M,an:p5m_+8=]uU${N*"T%+Lת1xW7AMkTj|!b<2KO_lhMgIkt>7ȚK'O TïySn%_P3 *ЌvD0ꯄ;LG)-c_bk4:/0uۖ>_!ZdϾJca~;m]%> s% ֊L[CX k>N} nefr]1Bmˎl0{Էsù$퉔9777'#7.KŔn=4Ipb0К:uuI(%>ޤRP~Лj@d* ~ܙʳkv0J7WTDP}VZ_.$f;T'$&-P5i7^/VgI-mRzm-l~ƜFq2:I&֯}Smdv5hےek *B[5 }hmR[GIt6;Yuܐ^JGV랩+~ {rBh_1{ :iDg|!,a7ױ7(G8GV6)#+"ʊ1ޥj%&X6l:du/RZBNǸlqRqTJڎSnHU. 7z0C2"v0Dl,-,GX6Pe?Dnڷ9M3* kN=bV'"} QדѲ?&LV]nl|μgބ[]5 pHF@wKKF$/s٧Gu^𜃔bk@+ya(E*b"{yCnb? nb^>6: .gVXlϴvˆN)gyI_l"4z0(S*-Õg7s,pΔTeVBRG\YȞ0ň%\@ }0symү\)N9K9O)m0%@j> ӫ\!?gmЛ@SVm@5x*9mQLAވiecgk3*L*?-H:c~Q1G563q|w+ 4sv`0sD9hlŶ.".ԏi>Q>40#|@N\4W/?ތ+ڀ]n JO}fgm2(ꎘ"?KUr+pyg=o24]/Uu}/Lg\$.,[`t꺅m$P}%^Tg=b +X=68zhF?{;Z9}D#Oœ=^楁_wW,&%Vvx59⣝XV^,|i H?4Jy x: %uNLt:E ~)+g1nmSDҮo_3w<]m*f[KAYc4j.?=W̫g+U P/ӔpWolnViN:PYQtrȥt<Ʊgں1H߬M"|9wV^ d+{w{U)g*PBzC+ob7ktI T@1 X&v. o"%Q.s8(l mo+g,*R\LG 8k-=bkھMyRwG$HђL)&P_T,cS_ so}'s+@gȊBPuGZ}C8\cuNq`یHHOC.y#*3GC?MԘ|^/")3~ˤ>Ig#CuplTN l!Z#ܳp*]T3 P} Cz+@vt~|=)"*N}q2rGXKDf"!gioQnu-S;MJ5[ڿq.:$8A80d іk0yCh_^T99f=[ g%aE/-q!{ ĭ@q%;Gy>YLv_]S:O}1`*܋FoEs{2LP= "1=ˠaFU]~!Tn-(~ƕjD'*r!weںpvƨ ]s%] A?Vf2 zL%G\DZ>< upZG[ ]u'u";q]-9S[Q ڜ)c^^|niB~C-6nH|U[-h9F䕵b}O-)d5Oa6{ŋrԌ*:hVڥn̛cqX3`Y?j̷xY-)¶ 1[C&X/H-p' s0,څU_ڤ~guΑ ,=Sri8VI=י`cQ"YvAX;U6Y0bp/xф,0B B.}>yEi<&Jy7{}u}YV*])]L qФ H4Ÿ4=vL"y&Ҁ!rT;!rZsKOKNW4z,eZqJ+H)~F6FN+C1.5-ddxzC+jyvsTUx'eښ|}YxIݫ{l!&IW0kq>Xk 'Tm _4Q)_rݬ\̎dCa)AA+(r_Pg"(McjO9\St! Fܤ: k ݈9+cTTj ݫD,v4KWK.•wZiGxޫS9ٺ'$" NQiyx~.6[ lڵtd~"QugȎH5 ;pIBeCK}+_Y2pfSgİ!!7c;3 4wGK(IF@lp3Cq< #|?z̐b|P'ep3@3/>Puf+n39rD6Z&{wd)ڏ`Mg]_b MzkÄUȄ|ѿJH ,6u!+wYbKڱgnls: avofb<@t5Gù'۬ Uvv_p 6'R5uyAn.ZRWymVPHkŷCϡV342r'I+߱]7;P#WrZ@1ĴzKIl#_ܪx]la~'› 8_^Uq.N&<S[>Oɫl/%y迚&I_QTNjWaÜj PQ#K~{ .𓀻,HS; 2puz5#sW1<砲 P_)7sė! Ob" oH͆.( EJ6vkE'BivrIVSesʢGaJ==I7k Ļ,/O! sD⺈<+}^N~"2 u@2Ʋ-YE/ó~- S1tnXsY p)Ug ŧU-j py\9)_v[W̲?Y5lfOMRrc&l  ;}*,(bX6Va^V.>=["C= >$z3Աdtˮfc;91^x )9NYs5%T(/ϹbH]SQK,p*!wPIܵkG@xK[W&dyZsfXö@C{D3j=8JfTvA"-D33ÓʾˏB_XlGf"GYsPM0%}f9ޤ 4P0׻eɲ".0V u&!=G@*K Y'PZGkinb ?@Dhؕa63=kK˖.w XI@ +5YEŵ:(nHwmY&"~$v,S{:@kgZ<:`w*hWj읐 iЩl ڌ&ui _73ډ2f 0[ vk+;1Miy/*p+OVqK#̀Tu?'!>_dH45`Q7?<4~R%(0MGt4ʐς3f;wD=bѢa]:0&/`Or ݇9Ǭ@( ^h937ײ`}H&\Jǐ$[y PAWoi-p7+O̲Ṳ`pE)Ko-JT1Ϻ%p!zv mӟ RB9P358 vx:onj+OrՉ4kGh=X01 |AaT 0@aqGXH1P0QBf'f,p iřWbPm%2tYQv簐l7ö^!ʈ+*Z%~)18䨛ǪQYMNa&j>Gff> ddBoeS]u~͇h,b|OM0+>C.0OpJJ`M{u2KžOw]E4WAԓ&~'`}DxbYͷ2Gy x4/kaYeinO$m eAAƸ(h>@ﺪ␷[:P!)TļXV[ьgQM(\|B9$7sk,`$tLNY"eM[,VYƢIbN^|$mջJU!9v-PN$+V}rڏo*!.g%=dO!9M% j[WAEGHIL_pҨ9u_4p^~m̉QOQ^5_cԂNԪ Kڎ'&zp QX™lZԟ}F*>_ԤxΙ)@Q@C[jsk̷εiuS]ImWBmF]%B˺&hv/T=DԼ͛c>址'ޞ-w謃Z)_ c=iYfS[,˶t4]ߊY' ޏGKAD_d?g` \,[ѳv9؅U dǐq}asQ'U3Aq͠pls31 m6z݊։Z` -$@-Z?l.unjl-uBN  jE2KjJ!T Q"J#Qg4>-*; iKO( Iު}woRpY>ECꘄ)x:>Sԯe[yC+ȇ\y )V25%v׹J݁=#G}f Q~Jy81`6%ۿ/m:mC.'he×Zs:9హꂛSݹ|7/T/蛱2 a:Ï>#&-cݣ曗[>Uc+8Xv}"^^eI=+N%-hB׊\VZڐL4Sb8j[VKe}oiY3?,wu3/.]| 1rJGrObbόI2VDҞڜ _Wo=^* GM?bw|AZ<7ɀ|K!хQAa&d >eӋBda>Awf ('YvW'P'r߅8Y!UUJ CJ)c 62r6|$ՐbsK^5'/cˑ!>3,S>UJKG]VM )J8g :0]Ck9 C*n2vU~<0Vp*,"E_-vE,Mk죡tu)C1:\f8{Y,=W_c;jP`|QfWaxauE8_DO}߯O5=k%yI`ň~;9((iU xnQ|D;m 0K%TJ;D}{۱Ѳ9 qo3x 6كŎ}cIeg)C,ةfd֓HLAC͆f4.rjl;í2.4>YB,`w &ES.66rPX8n"L֯%ڮ;YnOegZJ׬&c }"]M #OYj+ݩpRou;hº@\K P8ەTVP߂%,Ԑ Ɇ`ɡRf=OLBlccqwkф'Um)"T46a\QX罃5J>& }(C?|6WYk[4 l%/S潰}" &B9 V'sI1_zG4[Be!>[|OmLlYL׻9ח&U,DLkrpUDוU g0*o }9qĄYi𔗇|ȚePMlE&Dw_wʚLug Ӎ ck'"jLROcg!$17.v2O`mJRuN;(H"B.Gb7Sͫ]nRbZ!R[E[Sؒ@`j} a(7WQUEkg[U9qT!ЗuД5ȉ$>P"0CJIMy{2N?;lk MwWiU)Z`p.#~lp M> Wn'S(Y8=\  ZiF->V#H˩С롷 SQz}\u@egAqLv$L1:!. |^wU+n*D!dw.Cap3\e81c{XHH5(.>Ì ?`!e3lv>KM$g!`>wD,LbP|WEh5oN[n5M) R!ny&j!\;h-r3iK+ռ;^Pk ^*.`2,;`F](96pVzz3U"tOPkbIxtF!/ce*PljeޥYp\ 餢.kI/I\tC!A("h9V[L:p$`,4K\;E e;>"mЊ;CXJma401]_M#f rTCYɖQd;OF:xnغ5_D ̃SAERHL@&^2 Vl>^ BsZ͊DB?X2 8/w0f@P;ݍO-8( i>$dύ#Ч@3:fn3e-ɥIW۫>vyJ!I98$m3\Wd;g̣:;OkdTw3ۥ|2Dg±<|Չhʧ!P ׶)cB\x5ɑtǣYA"bo #B8w; F\2;1 -%Ц' az.aUQ9c=,.lk ?DNT%?.@"/ۺua3`e=OOxQL_8 /VV{g'ݾZ=$xåmQ<{t߻L<He)r9{>!ۜ?Jw##`j1 SkMn6s:_.~+ N5x́0R) $DWXjePB6;G%WoU6089bSdΟÈH*u޵<&x8:/Kl.EcђV:,uɐN i ͒߬L871M5fB Nn.~u;R gޱG{Iurqp}3J ! LFnOnD"U-ʅ=ͷR)@ $'ɾt!>HIEMClbưKjG'ڐx)]o CXIڊL#'(ƯXzLӀwOw_Q9H~|ḱK,"0X ^i,$<j_ܸ|it3pfסs|y8/׏C7UQ@\i]9H:u:ѹzzS)/H"#޵ӿ6DQu"R)Y*b5aOyF6~)ItMRF9PoF ]$ *g̵\ښChbu<>wEqjNUOp=fGFi(ͱr~0rZ1K o2 Ö@>;qB ^bě^l%Ojg76­ ?˥rF4!J7w89Y@t}󂈱{ً֨sI3"AZQl{Vs; aP߀v9]:%+50 `Y/Lq#ϩp9Ha¾R׳xVUhږbD |5k9 Rt[AIMg4}#p p奩DFoV(Oէ@5}0I*EOF 8,Z:(4E/G%w2==ՄdX{Q`_,/ʻC6 Ey KA}ɯwzzv? V}c1!OəTLqב& -/vHtJ,:,Lpx)6l1) 9xxwOOxf>FPT5;Pݜ2j G+ǃtŞlWH3hH`)RGDZ[&CqZSJ"0mA:RvXoA!_tT8S@Oh(vBabU49t9Vd8)cZJ܅eDao֕#NvIepnG]ݚHǰ% >y 0I~\)V =M`GS6dWcey gdu}R½$]XȎzUF3OYv^qYiR洒ŏVy0Y N9?mb`.":D=4m#ZĻ5}اO*)GۼxHzIwf9 G0P uw0TRA.A5*\oQS0mzv/Ojv{yi}CcZU ofj%cyAu(, 3E|Rwq:/p xGpFxO5ez~uJ]ِd=_n$o Ԓf^-IfKS>Pf;ScR={:Fm(m敭ˑhd̋51O1)2ٱY5(/(Gj^,,m#T[ek]!CW$X#$Tqыj*v2]<'y)ɚrFjy]RZ$*zq8̰4@dTh=#I"C'c SbRnr 6[;]vaw!|9})ԗL\~rmSy@Zi=5f`xw}IXֲ\k/ ypBh~ j%}5&lMV4#F[C~ *z@nc:o+TR/(-F/R;z~0f^6Z9ў> ̡ܼ{_SG)]UeHQ"*A3^I[*Ԗ52:.!ؚpt!ٔ/b`K"<,˳\m>EO}W (w$RR\iV3HŒ\J|"A'P8t`019)Wl* 6h^PLzBw1z݀Hs ']߉F=W0yͦp"b~wjTmqFo p4x*JҗHX.~ۂg({Ftzpeݐ_~֢BZ~oj~=ଚ48/$!]jQ Iø*g)+Cش@^Y5Z w\C_JX^S)>[y_]PSj]WNIϻ5-ѓZۆTX g=4?"zLYVdW:1tT(qs_c61D1 tk,#*wJ}8s⚒2r~GPZc.cqKIz!$ q5HvT00Π= ԖZQ-O^!MvNrV6c/[/:7#zcrd$ ys!ޥb&ʗ@]i$}/sy:l ⑱ʨ_̰."OS1Yykym1Yۏz<9moRʥC'3(k=F)074q!b@` 7n}" dͬOWcN{9Eڱ_F'ݪ؝8Z?JVCdISeao mEOyIf ?^5CN"q5ŵb 4CaHlj|(;V@Xm%JaJG9HFnkUpc^uxeR/+MNRDOO-W-gZ9t`AmL_ȡYrfA$ kz=>R ^PNeа]!2"P{o|,Dh7vp0 B/ZɂVu螼OȞ #=@g;ҥu F y1(gcI ]cbʻ/oװVk9.oh =;?襴g?0xvXxV肉raGc[{yҢy)ZO5D~Swb䓕84̢< pj6B4OA+Pςiǥ X6=N,# i(eԹfTI58#37Q$PjsceKA٘ȉfyܨ<=F͛ux2h. Vk<"f'`'ej *nl61֤z1F۴GxEXdrTA-[ݻ;WH3NSY'Cfܐ\+EaX W?aE(W4EJ09|2)4Q[m</㒰o~XGċ%IXnQ9Wi1cZT/KGXH),+x įaoI8}2_%] 1iмߗGZDD 6F=` \}G+?HĬt_C0!A5TL[ }DkArfIJN12^a[AV-p?E0 dWkbҊ(9 Yr,n .%l-+t y`:D +DZ/ I;(1h7]k109,1ǎd,x G!VM~XA4Ռ$Y|+tWSRϔI'N)ZR E^?[2bt$FبX#8 'wx!<O@Qғ>ѡ6>7<#Z9}nRl2"wCg['<=lji~߄TNH cF<$6fD裐2 xExJ8WgKRع-FD/lFZ+ōk˗<z*Gŏʧ!wlgLd ) ^*F+әGidڞq:mGC"=RD 3vA¡d;[8[q6Uhܜ \. 2(Hvd*]7(4RjOvJե#S7aۋ"Wu _:~(#ѽ|rhr+, u%3H^'^X9%G:gG8{Gb6۹]V@t p3J߷ ̕I]p5)Š΄.ȽΦepae€DE:."8vT?Pw*t&2 UE_,KѨw/{Z089]c\K><8sU!bp vvU0DVRrU ̵ [jŽkvg@o r{)hձ2F"E^JGnI9%# g#ti' S ";~cFeqԶA4T@(s㠬Q3I 2_3oJS`>>T9+)My}@iu<"VdpBɎ+~5}o][Uxz4,Qnv3n׿ psH밵:= \gHYjH B\kY Sd8dGanDj2.{Ko;JhP1~OLٺ# K=8KS'0yi1,U5/3PHH@uņ6hKBG]H¥'ٟ V[ۛL|`#`ujln 62J#o27xacA2n2`xӴuơ!c8Čaa(uzG6eU>]'r`VOֱyx17hxZJCE/=?VXe w{Đ|/4&"6NQB ?8l:6r y{H/DyNl\"qxKK۳,S @EL]ù+fJf{Kx3OD ,0\?p mH/XZE'&Ll(*,O9dY+}{p<66 ?Azw_ۭ$r-ʐQAK[ǻe* _)QWvDvW&F>W^+pjkW9{sڤ9i0βp^T;%= HYf2V@]j`ȸ?O@s"k+Gvϰ<9q!} K1 ߐvkSU]7WS"y(cӽ0-i'"t:E &6ncyn@ FAYSAk W?^'Xa`4sp|Qt(]/]x{A;DDkuȬV  n_0ސ*W|ܢ50y3$4!ڂu;&NjQ=Ny )-SNBZ|V#2L ixQrōQ $l0KTD3ݱ'2R̶Yڐh94Gns-. f*&,BpsS:`H(HnLZ^A<:COͶYv> k ͯ!ߓ:RްP?=xv6 /}靦SO 9k}gq9/hF>q)ٽ W~Z-EB޸P'Kqz[§Hy^p+eS_D ௦t8PW;ud^Ȅ\ ޠ~븺:9%p}nq@k \(;S!?JX36=O61[A) mmj⚫$}x0W2D@!k%:UQHCfa>-BqBd3Hy?* S?|-D /q9Jvk0_IJ0: 3Ձ:cV:=8qw xg ]̛nWжN <ҝB9yvBYC$:DŽ¨evl$'~T<dMK>]?x;CKF'ۉbZ٩H7|̺M>Ͽ87p܂EL ZjnGčwgR ;|;RUǬLlZ5i^˘eyY36-a6Z]oP}R+O۲t,7A"iUS@@'Ce-C!wb%^6<1øʈ̟L[x(НQ\=m>)a2s>^}: E[mACC5VbVsJ2W`]Kz犌F2Axʴ\WqVP=OXn ~"I|My)i9.`%XuW@4@".: {$ܽD[3~0ze,X`kG{x3U>)z# 2~ z(͇ ]{HS^]Rns靉MaI9󀽥Olʕ9sfC.nD[SY"~99Z R/,XdJ; J.E`|C4{ci2YD[cA%פyfբ">r&Ja:RSW֖őee܈0Mh5chzlVl<2s5{,l˸ bwMpXhwOq/-I},XNHJaTf!t}ZcmJ&x()6"p$< &oC tRK4$ono]cUFY$ut_2vIALm ]e[E, P`i)BVI%y}c:ʯHxUb*cVt 9{^*!t. + .k[qz L"|^bgGiɀQ;܊4U_t2myZ[Si̩AQCag較 8c\wɆQX#w!IҘ?zO[:]4A+A@=H.g7Њጠ/ ;FU3zPFKھt ,%N]hV꯹M-ܒ'F}vk:SR-QGi510PcqU/K DiׅDzӦK6ICڊajUfZe߃5[GdVM_3ޣw6w;k֢vUw^r#\: Hn u|nG[F1 |3*/\cҦe~=gKevEU)58ي55d7EecBfoVd ,sTwzv M֒opye Fc;+[Sf =~D='}vkQ8|Nk{Ͼ.Om ܶb0U'?k(B0}dD|k:Bı4W迂OӣvDccj$DRz*I s* h`M4aҹfx%dB&|QlAt:(tmnD2u-/g϶*xb<ܺM@gTpX4E"RI(`K9E' ?7hMOr $:)o4` Bd'smrDVjk}aj:wR5,-4a` Y[iqP!\"8sTD$Ek[GB@T{+u+4{9E lBuLJߣN_>zM}boNt}BNR/tS1TۀQpkr"zY,R50.VINvSdO_HF`8C:\Ğ[θT ױr.w35|ģukߢqo9qeB;2;e}IitYkKpP H/Gb 66CB2xRo$o_0 ӺT-s j o2ֻZU\GgxHÆQ8 HBי԰B΄NÊN{6[Sg;$UM?$Hb(2ѶܷH)(KϟB]함@0njNZ1l| I>>ϻZj 8#ĀW9 V;2U22teRrgž8ph ic~Ʀċ rfJQ խY.^ĕBÐk &F7+0 UL⬻^qvP<|cdz+$+bE w !@F~cY3B2UOFd٧!yb1O?k#Ϊ"d> z _eӑ^C ڜd6 aغb)9'dބkq#iMѼ7 ^8eѳs@gxhl57ꖝ EҬmvgd/^D VHsȩ-D|ORgPhGZQXcJu rsN-&:8aqk?O#ٔ f$Eo+-Xh|cȸAIgU'gltbing Tܴ[Pլ懡[&Q&@$ \Tr)p(Db*isbkR愔J>lSȠyAP>HUUpQҪavG`EXGܒ_'2%@7dwEt#q1{+D1ezO }b+M-w1;Hwǿ`;Wu*4U%9M Uvʽ˛şY"$yBq}5JJFw@8 שx/s,=] $g~?Aj@SB0XmFEK_6wR(8@",30ˊdĢ[I*{*a[X?/'֞4{^O F_|=VYM^>O"d@,fFA"B!\\Ga%2\O(k_#&`p.l!U\re/)9'(:*FDȄf"/ ԇ{<. {p>zzwm*b}79;L#I1z2x*!xlIZ';,?$ŐsyѵPM gwǷ# ?{FA? Q0`/g2ь[\հ}&.<@j) M&^\(q1Y,$J[#'mFN-5Ң~ (׿{_* )M챜Ti{bu<$b !.\+bv@ ~$,:Dz:ugf{1> 7 hSV4NqM[?0tرsWrb(RGXA JjbC|:;1b2TfFϗ =sL$/:~+ RMN /}Jtfs>Kj%A蛅e[Hژf{w=x x%K ; ga" 5L.z PtYP?h,oIП(D؈$s9Ԑ,hRB\֞"}5}sp5Ӣ"݀tx)2*UGKYnRGo 3וDJ>촣'%sW'+#c {pYA|)~8 P0`.F =6^_ ̃q?U^vr`vI# SO!f*@=Iƻ# 5G&7p֚p2;$-HNӷ`s잫:-M^>kgmeoJS%wШ\Ȇ8ᒦӭkjaA_߼CoA/˻>r 9b- Zt*1 oo/&-$\.1yafy֦ṛ]O* vgtuxsh$yČj/NDA ²q 3 r,\&e>zZz,Jps%3ũ5тl!Ƨ "q N@7# :hVܯ T/n6m,Ё1!@hGYAJpz$up")k˶14~.($Fs:§Ѹ~? P?8 vQX Z@su╥zd9תkqB)֡* cE(,{c\>ޝǢ+k:%5i4R7R۟Zq,@0`9ܗNPRr8VuֱD̄;Ec T H:XATΐ^Φ$_}Np Ӆq;/L1#6ŝp%&|wVׁy`vÆ%f>e0t%ӆW6՞=EMżQ(qvP;q~>pi"ɨ]ԣIat ^~~\I"Iݪ zlT\]DNN_Z޼硔$h:7ꑵhk 5 X8~knE29enkyIx7ȍ060#3=9JYu5Qd'F~A6JaBh-d.~ b!{-}}Ȯ9OF_͏r\cQ}Du7mH 2ըcBl^׆Ӳ.>mJzۑ &Jo'^[Cr` sS3~'Q-Y&W3KR]U# '֌?izc7rM#ʩb׼C(2kJ&x":I`oj!-[g˩Hp&? $}8;%TFt#F hlJ<54f/iƑ"RWOBRY8}zhO7(?V5Dҷ\6lv͗hyKer9r o%y&'VyKGcԭ8\0aץ_Kx'yQX:+# -\*)V?CFD;B#Iu'EMGJ$kLB_$nkgF/?d&j@pDuO*?Arr.Ćhe\X9/ D7%,n8?ʅ0-'GNTAaP@htqDx ^#2 ~kQ7cb1C ޲$D_#yKVPx=oABwBC\ˍI<`@X9&gHT[>ei毮LӾ~{['AXE}8\Ĕ~ECWl'E300G6689ڠ7a|#f=l,86^F&auɋ yW;X ]LIN{U@N-:@a;ޕ!Fˆ16>?K@pb~:FUKw pPwGsQW(<VbCylMەGI[G!I^2.ELxj k9o \qgVN$Ǹ7_3 ΝZJM^_!K2_K\'pvEOYdsnS^-ʼn?0K.w9mT\ͻ3u)H0{B;෱^ەO3. )zBBN9$GջJ&anu@S7fڛcx ^̇ۗY29H'Rwj2ҤG&gQ3r(R%L;mTj4N10]x$ݭ7Hu~I!SV.,H&câN2=S#wfbC|w<~~`j\ܽQ+Ve(1׷_Ɓ>sG|? ~QptzXl 漢Q F-*gC$B.xɞ.9ecA/fPTWP/W0;"i%?WH`8E#O4܃9w鑀||}KJkt s*hK/4{€fJܖ,SމegkQE->( CL5jj} ޽}?3: ';Jh7^R([=el ,ڏ܎C%tÓH3"~B`&儮0%я+6(O?1jW -Ftү`B0"S&Z4O-Dg/>U[=9o`Q+b@m_ |!O_׳&ΐc}N0mrjPx98Hsw)b%kPr= r\b\upM>y  =^ X9ɐsI熁u+w\KVN 3N-kW 3zi}~m* C+8 P"ljRBn\bf@rf)tjVUqFBb,nj?XKz+3](_ sP9̊?׳%K ࢐X3v?PC[2 4ߴCl3g[uu+uxs Bênh ڈ[l]6-F>R5Yo nq^ %\i7ݿyT#(B]R3iD/H:VwMNb͊r rwJc^R-|Z <?D)pɜh?r ό;q˛wZFp4`9I;! 8kYԗgT~ß6Ig2Lu4c lwA VԪ.6:(Yʚ(߻oO42llғs^%a&f.7]X@jnDsj>nVO#d.D䇀[,anﮧ4~Ϸo~J_e Oߓۓ5 Qaſ'Utldl#jVxcJ٭ +Fa.AE ̖%]piIL][m>2 -9u=զ"= ho"}.ñp$%MW]-ojc!:{ S$+6k͂~Eɬ4ÁY"lTcw !a]o\hj ڊ1'8WEFdZo7̮کaO=+m2? /5?'lt`]w}`:]<<埛3XNSnZ`jN=Ŋ5qw]XӒL~Br#~`c~@hYIرq`p8J6 t fksM(,ѳ m"h|E-$U6q qA#^ߐnޖt[#O>=;s <$Zl/ڞȝO| ڳG}~>&s48j*)LZH7;<@dNUlX`k4? TghF{ ->`EʻlS_?;Uf5czVinS8zA:3#fPF,ۍ!0Ʀi@|k}]+NЯGi[2$tUAm ͯ2bMWB֟&_[T xM; lH(ڈ8 3yg#~eAxfI[%eZ+rnǿKf/Kk2eMqH*όBm 颗YCjX VB`!ڶy#*Q^yA`Jg4Zp6aפX;ʞ8i5v~t}k՛NsBLLCR6 NyPKv4<ܫ6PCD s" %vWAAuAN1b[:=dEn u(j:V32EȊ3E9w9e;1fiޯ.zVTgYaYcd{ߵ9aVJNs 7_Q:m?|Gpbq?Nk*m[+(%V3\3>#ᚳ7LCNUԍVRXLL_f87vXzvwZ0yGkԓSoj]^ɭA%M}/?}n?a m\rjٲ!0fؙWZͦU;va>pפ*>a5Zi'wh8Jq|N}.;1ɽG-ŖV ˤ%)zyQ}4wcq^7bZtZ:m@cw?@\92"Iv_Wʺ<++:,lahO˶tw >Pbi }0Sh/-6$BX'䃪sH޿5z|-#j;dZ,(FU6ڮLPU5ND4#ħB'IE`( ߏ0-ladxxPԄ]ZN4FThN3Y`yrLIZerh4Ǻ w{Sݢv3hj0\/ПeT]尬Q 8~ohPG{~d=$bf=6HK,t3? ߭]MV \gTrpy!6C^ ׆NV+!hj}_{=Ry:W 0{9$qLW" ݚ o@w]V04+/Jm ❬,?BhLJAʰqw ;π|Eז&KkWESBU" o"1x:ru8mMXs 4`O4š `jUjMRGpF:%]Zl@ y 3ьQ>x3c{ 2ʔ},g ,Fb~x1GI AK{˱2DzqaTϻ߫2x|Op+TJ{"%U c D7=BsXzØPHpcs+ b!'%  3͗DC=uϔ,|*'ia/ybv'zevu< $O(paW`J2i5)M3W7E4jo8&@Hz uRzh=#=R.) Ǜ&3(ZwfLSQsq<¤\cWy70WG{#i%w5"X氮4iEYsV~I&"æ[nk`^BW_zjPfB^~#"<h!.z|pv>"~vKN `[qȱz'Kb72 M ԧ@9żRa9B_ѣ#W0QgyAjj{_)kc#a(b8)ONPQs5A#/+lN$@)2 Cp UoɦBӗ dጧ!k`e ~m/$cC/(26FOP8&#c&f R1c#z@=9#<N(ߦyx@=G_ Ch~CP7JC*J;\O9, {lIx׀+V1I7Kr# za4=CR~N?K\q'R 3J"Vx>Xcr׃4d$ru+mO4fkIq%'ůL9V, mlA;V1*ن1qB?7PK`Š:VȳLn`cD<]'Uٻ [;M'}C)TCJM17Qc6=pOyfar4F4ɹ͏lCO_(<gOx_ E>TttX,}b@3oLD@@vTw-bg}'ǿ8t&p~`:q,š%krPƁu_,{V 2%=_= $?Sܹ_f)/]bTKP 5 BO*Ic;z cwl~6/4d8@ ޿3S3ԕ56IL*, IbE ~tXދLvg'=-kc-)eؾfR;N}ۑxt2#-M$i%!Fc_,K߉fb%V,>dbo*PZfyP|pW=UOǑ(K޸k|b͚̦*wZV582gҁt,I I2"击6Ul5oǹ49^&<:пp)6fG1'rR$W%ˊ}$<><}&<(z0_16$U%`1Fؓ=Yr|.n+dD%,1 +pu 3LV/ɡ6 ROZUުpB~6S1!:byS<|\=6>ﻮ_%/܊ZÄ[qo \ $Y3Q2`)Znx;u}┽R%Zlܮ !(JL@<{HuM?_s!kWۜ~#6$0*2e@WF¯/Zk^U=Xp>씍r0^'p(ع:J fP +"^ֳPL1G=ƈMh'wW5wJ4;7j`KSnxd7R\lV8("`pDO7ecʃh[7>XCۥP7Gi- 6mjje76-3(~0w02ɼ5+)b\^RQNǷG$ Z^iJ(\C|5JNȌ;sښyV[>4u.G;9)$Iܓb2vhѮj@,[yOώ "L*JZ(J0T' Q]/V&PJFC/6g_ܘ2ug%Γ AO™NQ@kJ5mw|R$¦=J/_+ڡ"E"D"elqwB%"F샲,\m[ʹq$:#>Ezًs +T5{N&$? nlv ls)tk!jF^'gYbӀJ uQZƙ<U%iqR<N#5A ڀ^> ߨE41zóƾiX$*c0QkdQh^wgp rZTiI|?p 9p,ΫMUMjC  hX0 ܴri!@vTs.>*6GއU*=3-f8QWƄ} ZsF'ӖCOD:s$pN0Ô2]9hUzrN@ԕw޵xBϠW.2{d5fH I~!R?ؽ8mY:hbLum3+-Osh| @&9 #)LxZ5VQG2f0@ID.P.wJW%_;AGV<ɋ9'pnuDyOM`AIy4>iYgҟCw3CUUD!6ɕ&nU\膥[@zCqkSi#G2=:i#66Bgedz70jT ?_ƶo=2~u3}"4ɟ􄑧Ow?1I,=X:TmT!M4pF ;/xi6CS] zF=vё&!m ?G$ J"58_wvEȣVesWJTxpW4,RV /./xOpN As4lE$lU$[dREMTwkD֗oL\| 6 FM14 @?3&L b>2OqhZl낌V WUNI687]-jik6ddC,"Jv8MP$-PVWecCu ^o\Jqqbe޹mQ4\{0]PjD.x( cP.]UKiS}G`k`ڸɵ6 ,uӮ=njAO22E jwJ#ɎHZ4OBݲ]̌P_JgHUgoFLJ$k>_}05ۨ筟<1+,Y8. GF` efv"bp7D7Ăr#&KRlA)IhP] D@-wSC7(_nyoYg=:}7.Z)y 3.:w{h)r$\v P;+SDۛCj(+ B3n@|^l8\| Vt6 7gV3mFF[+Q$Q+::'3&nK'D;Ў,擪=Gֱȉ'͊8S-I&0\|B#[&|'&g2>ocO ԅ*M?ʇ>FPq͢Sq<:wxDK$qVC@c XK-t*JmF͞CX3:U;M<;GI5NEUmLÅ+7f#y4Ls|9"1țX 7r~0!x,ē,ShF&^.}pDK!gmHz;"]UkaP סb!hq>eCum ( *g)]E;v\Y&en5t?2ۘ4'Gϻg,_r^_ P)/ccl0(|]-V'\"Ƒ/W- 'g)Fie=莞r" 9*f -8yM,``yu[ɤ+$'b M.MŁN<+N\g1S*W߀ꚯޯvsC!P{OGFu2nP3Z9&W4̱ZNn F$}uN^Res5t Cb1L͌y^h}pmxUoL ʬݣ׉w.&5WCl6!9OB*C(X&= p5x}Z˺^xWC)"1EE'-@1OUg7n@fD UцXit+JȒnz[u%Х"3aJmgw<; BQLܿ3H O (l6' Y]iOZ@罎a Y#45}H_@;X䩃S+@VӁɈOsCG`gfxGP VФfĻނ7$wfȟT\_lXOVb! itɫaN$zƕJVTt)N69L3]{Q vQ!ZoXG*! qX!KHn(abN.UZ$ڸ|YP?TIq}[-t=lVq*UȬ8ryUm O]DW@E[ &8J|+ Hˁ#G~? h~]$ i j@ +NƀH{3Lt|Fr &$0ٕjcݽD_U W iW9ٛJ*]6;JQuN1Jth^ }ꯍ׫|ڊ40nk{1WҵͰ0AI-E!?]/{؃5\/`ZNQo`ZT0oSϺbx R4&E\BKA"ni8OSfO:|F?]+;@(]7\ҧmUxt*{1 wL6YӴ 9:"@P\3]EҬzŲ! : !XUMAկMNq \ _%lՆY53*l7졡oqN~x7-] N@KήKRX6ыK'~x7VlԜqvɀք? fcb~u%\z)/[EUqİIe7@ NуUd#KMBM~-k?2Np$- 0«9oG Ϭ1 +dN`Ej79HO SӦL=xEc+6)cwb59?OVx/O b+\8d15Y؜w_fW; 'S h"jՒ|RV(Č< R%A+@|*4 @ ݺNcK#?GԏQhPtAreg ^ԋε0"SUF @i'% Qdg/ 5 jm:oi>a/'k_"ӽޑAJ F6Kg*0qncw#gJx|%c7`eEu&iU(2*) $|_~FKk?zտE9~3k>nĚ]_`LoSX[94+t)ko,uD0ԪVۈ2 v v'ԼknqXdY+0[Y;$u tl /(qG&uS.aO )Ւ3^"&4VmO{kN!/T1ÖSE->&;@X\ķn Sz]}"w`Q5>$#muiK.Q8Wq 8ĆsԞ#Q2CGD|[ ]6j|)>>ZNu놖@"BG9\i:ހv{dA裴)pvz65pB YLQ` Frutu4`|#B)I4MyLob<V wG~;LPX+3Y |HN[`<X}L4 9&*xy: C\DN4^ѠXqn7J[D!}geJILcCeôMof\AWI o:7 u4ܘTG+qN03Q-cM^R.Dإ3İU}1?Xr/!bev\zCP:a|em_KbD+R8qMe/uat}J2ޠv0$,pށ,x|:0;zmd8<YuD.w8˞V'5 38"hٌm;7$M%1X(Qmb gJW)-Բ0~!KάA%CU ?s&5Nbر]. P@VFE{Zc%0-uތЋ].)w;ܾ{PCQGI]u1u4o"ϵz*/A$7Ml>)\PG +E@kWs 4Y[`I"żMόA&s|ǣ2guָt`a^3einOm ٺQ/I# SS;$6ǟuzއ$NS-̛w+ާ܂b|_dm E#~j^^G$p/Y^|C0{$zf ED M}G5 q,[r*%2'mڂiͧF?}nO_=UAUx #n\Mj\-ZIF-Y2· D-=Ecy]qA i 3HGkٌܥdW2y 1?q|J `X8IlޕmcPDAdl8E6'ޚ\ޝDnl#ħ/WGRaQK;aGy2in8Wfcĵ5V]7/hc= QR-Wq/*3# VAg9FNsyR :q ]^f;ł8VIB^|U6#ϡ_S6j1PZd :5K f~][-TC:~t^"u/ݷiX };I+԰HBs}-F 3|z Ϧ[l;)ڛ.akw)*vGW% _ب=J {//ǴS6F0I" Ss^bnU"Yb 0hR/^~wgWXQI ЃW\N~%PtZi3*YJfv\"_aM>.}#{nmVWS]U[LI҆U!|)}#l-2}E[%oO2C#6r;zMV(*qIQdۄ8QQL#}㿐҉hC+N7%L.#L8CSrawd;T;}ۓ ⊡_ ?oY;K]xnӣ Oqg>6YpYz-3fS:4xb4c5l6 6g&iŒyܦƣ2d营cuc3rHyzDǑ4$??3n-i#H_{XVJxOA`5;3sFPg J`93)] 9ӮXM0 xI,'AZVJ3uZ<-L`_-)KcWx:O,bЌ㯒}:Ƶ%%F SV@1NK/#5jmbRRJ-y~xDEӏjU]OhlukaNR3#>c%1B| Fqu鍂;ծE1H{}H:xAGTd+Ϻk;V=goQ}jFq <ijhj 0ɭk@N9 hE[ph?AF>3}%3kmN0GU1e,x~HyXԾZEqrQ[4Sڅ|h, i[=XQifC`˜J"C4_"FK[~m摒$O[%\Dtΰi5tz7tpLkdS f]0z?Vbv,Y NDG%xCĚV MCM@Ib0_?B2PY6B_T껥6ELa\!Tٺ41Pt&~Q S)mg|Q8ėP$br>I y,~tꠖP.oO=_6?z;(W @Pxoݽly &*v h3l ʙ- vf:g+j OR1'\[^n }]U/~:q}A16ÒOh{ۛKD𸰲oaIgD7li s=Jy8ե'ʬ/1DIxg;qG"OFco+ $6{ljOP.nLx8ӭ luy7*x*g+0R.`"Zь\qvKACg86|ywm@8Ϛk"y嶓!/Y{u{B"3&L i˱Qt#0n*yR-A=m>udA+B|:g#i8 FcTYGS6 xfRuuXG=ˤʜG }j`w0]z&2vj\DŇn`QWa.ԃ9X҅SE;"8׵rU(P?Yjng.Ω "c '\晎ls) usY 2Š0NW9YrR̃Ut\$gi͵&klTRά'\4|i|<mlA$T[ `/^߼f" ,=`j=as*Ư?a ))iWEi*;Iȥl !ߵax6ˠ;Hw: ʁ6a=Hl=@k4 v5 }<6 =DrLT%e!zc^|%:K؅fF> >܅woXĚf](0הgpFmYbtaɫRA; Kk= peE}=;tu'jc(9twz6,)zf23YA}bLbP% RY$AZ ?*( Cza< `ĥu`wjA=(ai"q\9P0c#_ra'aU JֲB۟{+uÅaߔB&Կ­oR4\H+ޅm(CC.SBZ2^-^Й ]X8fR 5|K=$(NC1.W+Д"4z B@x.mA Ҩ/u'+ ?ݡx: aLIݑ詴FϜ%O.~)bC@%1Ż:2O8>e'O4yo %`!m<@Sv,$% 50W,ݒX\RA= NqTvo0O=y(RrM4Pl 8 z31^PHL!Qd/g_\s8i]ZYԨ JU/-Y{V\N}1eoFK;Ά,t=ق<N4}sY̦ BRPO2b_s5r"N-lj,t?B 1^'dFg~h ֥@w"cb{+iG^)BlMjC}W9u#^_MkR"(+' G)MbR5PZ0x\)ط!_ Fdıy" cnR1t=2V#D{vNй  .v#F:)$MW*Mh f9xBs4V4?']k΂Z g)^ s`A nJ"~9ixe2n?>|E!'z"m} ˷vS;Mdn%y<vKp`]{ޑ4G0{um _ f"5i\ͱfb=~Wp GE\̙=6=F~d@yZw;XNmܧO%Bg dB Pĸ÷53i`c.i @O OP`Nvd!(Z%mm* pSN-DlzY/4yÐ}ӉZ%zgx0úJ%oɔ@VIy\`яaߐ8]M'fXP~nmf<1֮v, ӹ %t%*m\Y4XXJԚ9ߗeFeӤ+'Y-{K "牻v?ytCYv}~Qq1a>(k L4uA(c(M۝^; }wX`|tU`DI{"@i^),IS@x?Qw\?cD-=Ms@vF'BP||0S{!-k<$bjh_kozl!dQy kZ\];g*) P(bXNrg}*r#Ki+\ c5`9v:`KǧE b!KpU&Mz'$R*` 3gh3טּ.xr?QMkƟrZ EtTzD7H#9N5fOI^Ew[4bad?TK\FKpe F1Pj~j *H4+ߔ"SP{4cpyrVA.=cG!!LJ@K*u(YZ[B(l>ٲU<li*x!B wg%bG(92bѷo>f[4SkEzٿCZknI_~wsl[sye[L/./%`%y,NX&ؚ,6*faboeo]Ø{hkU2x֌sq^t^ _/Ma8@2vs;+bcFxm*m屆 z+I|01:x\õM-uKN# U]߬,v} J:J~MW(Լ~0t6;'0w雽6t._w]K8gH:Ciᵎ<.܃?s&M7v8!դS٠[fLMP7>0&oD$n ެ#7V9yVUv/ZM$]8͍?{uHG,wav:|$ts|P %J\}'\V~C۷hJՀ,$"m\d$cA4E &Bx9rLmN'߼ki->5"5ύVkT~} F5y!X)Ey--]7I2{<)l.Ag6{ ,lPZ2R5Fc9\4cA> &oZX\LXsL{I( (~ [LPq K.t4wZ|c["Aq/AVxV#MЫy&| ef SqA{EBßz[{-s\ 0[d!FFke6$ rz"-tZvdy9k*HWRc5JVWE"?hZ">ɩG 8L{V;v섽!|r?UUw,#MB ;}i^%KW(,P^邝]hHrx%@ŝ"9ZjJ/y+;!$~]iS3Ok|tSK.ɱ9V>u{Pn ̄>-w:/{Du?g t@b@|"zفy߂ UmwbT\v\o4] *msb?o]i@ibSOeVғwLd^Ē`u-JnuRϯ0GOg OIch97p~2o˪I]]D|f"?GbuOT *94㸧̉/^1 Ҩ) ~/;+NV[t2f%16Hsgpv%Tg:/SK/L/;xޖMz=#NG-Q*[dى-Қ:?ZPa d.5aҒn)Wݗe ΄jlYpB߆!P80CH{3 Fj+-&1i`<~T(jk]CKiLyTz= @ uWRKg!+ R}!ㆧ"׻s-YZC$u 4~g6xB:8MyR~/^R140Iv`ClYUvXz]e/혺+Z1Q|WrZhυ5N2PIh]x]S$*| :`Y:!Pҗi&^D'5-]HbutYԓH]n?sK._^õ; EmmSaqANNpOj0mwLMx>-;$|6J<<( (Hs0ֱOlDmaiޟȍ-vwD/(^oLjZί47?&/#heZM!4فUɐ%p}G<)"i'f;l7I'PD͓Sj`?{A 'cGBBo;TrLDLz2-u44H,t&EdEU<#O#S-A dALxvRjXQylꮦ-^|qrZs͓ 9 R8<3Î<8|j8CjkP1x S#̡-~gDGf0+m1DN6SQA/#έ>;_*cx,_r7Mt i+`WJ4m6:3PJ*Rxί0d|KGmbӵ&fͱytYek&X BpˋǴkku==2{;4GzR8 5; 3s߼+[*Qrk*jf'x+$(Ҕ5u, Le="OOmQ(Ju+LDDêFw}g^`)\HyVL֔ɹ&]HF6R@)îC?Op NxM^z].H~)pBg)V2=T3橊xQZ{Ӯܗ(cH0!8'vYDxԂ1<>J$S&7C9. uaP/Ԣȶ I ; ybmwסU0Tlv#Pz#2%% 62%`5]/j<@f$<@PKP]q puBvy~j휲w_"=1ղWt.3TŨzbŌ_uoQCF%)Nc\_Q4T[OMo2Lc(qp]Zg]Ìê!ٺڍۧI'{9"r޼MNDK sJ*6R1x>.RV}8fwU9'+zjsGp«hNNp+Z"9 ;l? n΃ނʓSG"{ ~: ?5XR ' ֌z 300n<f8*Cr֞&>> _U^fYަΚ1!>HD~&{(OG@ g3cxPRX\@nTK'xbd N;e^nLO)82{簇#F+EwD?SZvJ>De68/oElhy_wh(+fRvvW5xwEP6[mqדѲgT FF\t}Mp[+/B{+Qr# ך lYJE;>LŐjO&T ߏ ^mz2lV`@mGjw"FlVX_^OF Vˈ+ !Ds;MRaYo+idB`Z#Fk"z}}:MR~/Av1|"GUFK?u#o`&Iߖ)@⌡ȐO T/txhA YKv1;1^Bfe6 ~e0F B_b"ʏ : شf0KqQpYگb>"U5Jzmjs?zQ3|Dxe°a/ߎ%GO%F[]ձg:6hUS.^ihv^@u%Pp@+'\ipTP}l؛ZC耮Nk+_H6& Z [=#bfM g#gSHShG$ +=:.Τ4)z{p0(+PCH*?Rq,²dѶ"ɉ`uT|HHn}q'{Hsg,$YSɩR6,DnqqK PIoE̡{E};`fɃܬ #H`.S9>!cb7 J :ݣ*@o-z3)9:xf2;*x~bdȯwd([A7xmBwi8Hrps`94[7"פ{ F꽰MEL>,\]{yPYnjkGƍ?ifٳk.R!_;,!`7X"#v9ρ"k_GMD_f\LAIŧ_([mZ_{ؘ+;iޜ5FVa0ŧ\Tp<׬~-`9 xQoSM=Wd!4۫|"H{ WBsuvQ13 'Mg1Ebϴ\5?TJxOɚ!T{}9iFm\Ʋ;Aew"a L@ u>;uQstQRQ CB053K)I=Dp7(TLC +,|M.XsyN'b^3}+@{4"(óE Rj7hqDmSs +`|4?N%` g%Zġ)̢ f0y\G+rQqv ⶣ^TG?FvxY JK2 6'ձfbݗgZd/OB8E͵jA yj5Vw!si?gK~PIw2!I"Q AYɚnHfI7t+Pwwx/E~B foo}UM=MEc (^Q,@tuiġ0{YgwȾ%']k3,Yj;>ݘ5B|FSj'%IhL(搭hnHnq wֹ4eFھjHsR9)A ^c sz=KP%vL[ӵF[ h4ߺ809Xt9Q?:*5V~laMq`x 8ߙDJ(*˜w,EE/FH  E)v} sv}F/X!k/s3=eKu*5xjB7m?y2L;lD\`)H#\ 2Zϗ)sa7ք %rsH8xm\h0=Q7XikKbT`FʯTVs1QPBfV)xן_?W`d'J ߕI Po|K!@b*ܘc"U2W휓*4ٶ3b.Id Hzb_w,L %Е+ o# Q[oh+VP8)Q;狏}Dfh0*[0܊ A@h!0|;OL ==WU[yXxԸI\EŒOaz户Bv* 0 eg*,-vz]I\'%1~&;P؍P)K)@KfG?m N7l •nxHMм\xVv,?H'*Ǯ*i UI~-nD#>HFb-qD,sR8J[1q0>?P)۴>}_#⨜ 9W9f1|tgtegjk{V_?&$YC *\ ~ ږ_Cj1#oHjrAC)'Eʄ?B|q0G2ZX Uo?}LՌJ;R('hd} Rq$:qnKB.-ykvv;&lEBgY!L#T] ]:3.FWcAϗ1GMzz΁RrFIi9"D:Q(TrT~>޷eӎGέA^ =+|O)K-] W0.X=dk`Zɗ} MG.|8}9$A^MŜͥ4KߪH 5OwW9\|&7+;2)HՖݣWƎdg֗ՋuoRnAw`{ ӭKBtU%*= Kz;@2dBOt!~˵i5_~|HbJ엧ae퐭̩$)",4ezr~n$cV(`k;A7TV7ܝhP*v@ Lɜ0{6. ݲt<4G=fqH$D4o^lYhi>oW)7a"cK(ɺ-[E 5d;sT-ԐQ{fm<{WGV"MN92[ a{NUf>CW 39[ #_wܹH@~L%L3HRzZ~c1gMp=_+[*Y5B?h+؞mmh0EWj`e$5xY!@&h7rg?AD7oHw"_: z}tE"`i1f'n{}16Q, VU\@-]8F8PuT/b׳LX 'o-hK?l龦^*~9dp͐*hZ+D12S# q F:8P\"?uBD &F:_ݘ|jADbt7H}'5#V)t~{!F}kd46X; QwStb9wn3 L_ ~ Ԍ5kY'5ELdxJ|&2;?S]o++ue>H ߨ3Uvq:ULGj6C:e8ZemL:LKJ${QCGH}3n[Eͬ`A SsV ]+ЀXXq `᫓!iM}u|/dM׽jX\3+tg܏蝷lQ>bOJS#kE->Mߡ7Ea.q`w 1D OAr. 5M\FFblrnqip9fL+_X~QЈ2itc1&}UO̰ʘ'wԄ4Ji srԧA 4]inoFuRt;WT 5jIn9ء D?[ˀa'+2uy%$3۫iY9짶79O!s .ž3ny3}=hQUMGmL &qj7O"˒ 4tm چ[;ϳÄ ABjžGt>y#`zg_hd7<20nnzn#NYNw&P$BD"}3m 2BXRؚ67@8`SZ( 9kFÃћU @R|.su_~pAUapiqw)ƉI]*2,yGW$ٖLZ94|1`Χ0nAm#F, DEKL 5c :gP"h,roCN:Xi6ի[cF5Yfg O'<8sŀDeIMHppƪb$)ΖDyM*UW8y8~Zձ%ΞKݓP]b+`'!+kSRj |r:d!&hȐoP+{PI"aNƎ xDNOFȧ>P %d7Ԍw[Rȏ熪zAB944! -Ω,ߩ?:2q͍>!CËp,g uH\zQ͐.(h~#nnofq,bQNqIz]Ud!ZÜ.QCViIT,]cl|leH+ 痨媺4`Z[HKAY8Ƣ>Hy sNOSRW}L8y~J8*+RM#ɜloP ͼeOc8I\LiHdd]ʼn6@cn'q "(l|&NihP7]('˻wrq>,jW⎵Z'eo4 I.WWZTsOb#z_+ЅK]lحqoY9΀D"Tʟ>~DG߭SrjB= ;&^eDž[Z^{PJߖ]Q#M$ 5*w19&z9iKw>HsD'$jjBNQ"J&܊#_RyA9X #Q)=sBBjPY^ $Ŷ$\t)0V Y)oְi>.H@)Taڐ*U ~OO *&NoLn>}FVd37;c%Dd >~}/WF -e_A]y7zlɉ\&/~5}@lGh|khM:$#h_ -w| Zql mC #΀dڛ%Jgc fY?)<m ۰XnQ6v 2]:saHX-.~^ؐs; xoPe#T\h`U4Ck,yxmPUf$D[aXpI8RÏi #X#qmNd[SBh +e,$B$mD1nM bwN202^qigӢr{_(vpBϣI#eB9H7RJ8?a,9ULƦ]sTL]3YUD+?kOمV2G[zNx'r pQUD[U^7b5XRS5@4y1 q{IfFŔn1/,7cSـ߻_dl5˯Ya\4g3{v>Dnv Mec%O\q\[{́ |unZ ׸T? ,':`sz6m9okmM;KTQ3O!ELR#Rk**?kjږoD[,9#B#Po;^ s$[ѣb1^qN'`!\`Ѱ6ݜv 듖\474Imo_ґ&ԁ.䟘s'2Dr?ΟPXT)io 5A5s*Kbe.i ρBqxI9榰:j-籟 PdpAr)Vq..:%Q;3) mmg){N}37asvMOfDΝnߤO{)%੃1ZƝre&p @ 5/rt1Xu%*Zy09+.uv;=)'x+#Fo!,{%KZw^cZ&I=F)Er \-eJ@~ѻjVVĶW/D^7Y Y2y/r][ﭐo8($zctu>ڪN0M9>ekYm*6Km`0r^t5'{Kϸ`ZȄR5RMo {>(o>8v'URюf܏ڑqOh0*~1w0Z,+J4d~ LEv Iwl86вm8PR~+ /#t=i62۫R=z)Rz+N/'faKQYQj6,B0F.tD\a^b M.u`&<` 3WKkbN7>IKv$}w F|2楐Mu ƽg*ޘ徶|44ƪQAe{9ѐv{>Vbf| N-MkS[#jݔ.FV\0r)uRpn3o&^H2 8]En7@`5AQZ"Ek䄖%Z s[tLGab{U"óxkvN$0<9[o=vEj&02`_c!#KJ5>wnҚ)B:@/='vbK@vox!4rNZȼ ^K8I3ӜNh *UF)Ǫ0&l9tMcF"@>3Z{r`~XHTh9?%[-l1?[l0+f0- Y-J1`o`8L?Aм76UH޴Ɩoǡ1 $6^~&TZ18Zb՞OsD}}N4Ao*ƮU<]H)V0.f=>!F)W9%ΐwr(Kt3onJCh2DU̫ԏTxx2 R{Uld΄:7Or9OdVGSA=jf߹|#&~R ĨZđɊ>61C,dKzYig_0 bX+|)\s7`ͻbu먮+"?|9+W(iVRy9JR\G'nNYS?ߖ + [V ^X'Gt'$m۸h]*%wG]UBR:vfqуz8}4 7 4ط9607$qn_#wy' ߘҷᶌlWc/Sh >"75遢A(h ˒jGԓRn\M|/ǢSN.y%ƉB,f8)zg$9CPyfw u[ȯ-EhXL?#Nppu=73EN~yf~Kj(([9lhp`%4ͯpнcN FWَ>#p33Uߠ+HƓvʢAW7$js#"u,9ޝy;iu{&xd:4{b3}u yFrc*"z5KK@pBL3HhOOga(x'Yβdq%@ ǟU{WBkD`TU#X1]@'#r {۔"gȀ?ŵ5_4h vf+CsAw? vd`t}SUU0v)%$=0̳/ ɘyk7(VG.WUvw)=TU@Lۦ޺+o:"J^ Z?N[@XCs2rHGřjGi]*/#9*Z Jq>S%9 +BͿK7]vs+NH&-Q&JQŜk䦶agr~şl6!+qE}`,l =mOtD_0 jjbCR:с^e j bw%"iduq\)3ѝ?$ SÿN5yącV (BoB!b Hm<#`px-_U/ƒ;?uD$4 'nPTU:29ևh v+æ (^kV8,g3?7'\+)]`Mot9vTN,z/`}̚XIE?0&;#n'Hq+5K*.b2"V /@/i)#=s}S!滲-F:ݷ3n0p'ma1#F,'F /!2+ւrfs&x0E1փ/[ -Caf{n묱Y-vzB=IzPS7\#T%6. g"$f{#L[D_Ox$D KpCY"k2;tr3`FVJ2Ccp6.;!O61(cC `?d{M&#PXh+3hFl^jze#¹7_Wʗ>_up6"+Y+h?\iҕw2qr8uoҼEesoPyyШVfT'a&$S!bkxc\\$N6dSpdќ0Qq \3 I@i=!bt0aD؜ uQ)_64{;˳&n=O38 o":]WN~+ 99)Œ^iZ[p>Aߒ9CNJv[gPM~Ј\wOd,YŦKC$'5e͏#͢ߣQcM+챰+d_j `%u]6b <: '';]lqj\[$ׇ];18;pZ\z 9E:oտ5/:8oʓ& % ?,vTS# rS<1A$uo4b^X4'`>7:RJߵ&-4kz"U'zʍ"T;5s Q"-({@,H`|c:o%P I FؙoEmt3`B2vꦢB&U=\$ ^rP ;$piYGz ހ6<0<OEFB9l(r`yEv$k ^a[ťQ=ob|gwYvK&)F@ G"+1`16̲dSFZkEIy#dMpvM}2`b/P;騽.\+L26oUUaT"I`$|-7 0)1_3:PO4_ѩo"g/5yoNjQbM;Gk,/G̹ C*㱽$?uL@&5i2$L@)H*$j»/๟#^Jj"h%F|#D ş7:*`VQ ZOҟwgC%F1}L$4dՀ(?¡FXŲzܜ]vQЉd0y 0.[o5D11 |l'v=.dF@7/,6_ NG z49jjh!~2BU/^5Íb8mL{iEb-WD1zx冮k PzaC(S~hۮN|7BS0tf ]),VœqBj7J4|3?,1!xJw\s%_H_jZk[TƎq]Vo đ@Z $ičS3fCa",-`@3db+ӿL5냎+#<n_ nX|OT\6{-Uh\T7 /vy?淡^t̼+#ƳBB54K8!6ª/K~.J6O@Q)ӆI zS#P#_5lU:]FCgԦ9@tJmzs~U&2t[3 [˷'t#;Qq 9}fED[6=Di+R)'Gp Np]9W?#|1q9.J?Y}3P/a)K='T<{+}6b9ԀF% hE; 8)bD)ي O zp޹U64e:&L CMЊT4fdG;CSt9 o'u< ?gt?Z*o9casM0jQ (=46I)S2w`Xy̨4Qѝ̤NQldjӫw? U%nFG Zw;') JpdS 3Tb?:L6l O99a8kA={h>I؅4舘Ի_I eCjYe\ӒBJ/&Koj|<^I#e|2-229Ec]|R猙 OHpBuU> Pmѩ)]Z?*"ĉhhCa|nuKjՋ+UЍ*쓀 Erbp#T%'M>/wϿ!s|FC}pL ,%+:VqEb6Ү5.:53X{} ->]r~)^S F+%:2cй2ݐ]4f[g}- wsc $\R+tGM{) FNKtQZY nrEHϪN*(氋Yo3Bbwo Vͧ×ϐ/Fw>[TȾl~7RJby"r#@be zwj=ŞTn7"u9 mMe8uRu=u*YK_m'<1H:9r8>:M L^;h֓;WEvRz 'ioRbiw{_ F5~sZJv0t4$帒4T9/'2up1:cwӣ!7p\JgIx?3;$PTnc&0GyܴDA&U+c8VG6ޝATuVE,5f9E)))s=Pwg Hl=J}ʮͿ̑T,nxx^[ެ@l1庑$aE7fh9f9<*J}Waf>L3|Ǭ3J`}zbkwBG_)ήL:,J&ڿg77D΋܀(N_JdoHijWIJJMU tإG5"aA .kiaUxv)a_^i*=p͖ +}n|4\D0t~vePM̈́sZmIT3D4, ` Akw4HREsk)?Ow;̒YY"1cm4ﵢ+ŲMPEoh~ª+QY?sxp.i\lR D=/$e8K.ۇ/rAxVAfaK$Z4wrXhnXaRv' 6g5NW/6t̀ مH%h41y[lȄIg^+bܔ,o dZFMy-1C@=׬oi nqœIZps2r1ܬe2BE"`Y<ԸF @R SS^Ȕ!(LyfڄuF֡0ZMڴ0hMY m"j`XB#kN*^ۓ%r4d[q1ԊH#j0JѯKF&ӦPF1Tp`;Pe ;sC._S9K dn"tӶ#_Q@_QcJUwAN`~atޜ?' VME㓯s*`~M=?\{[Pa~;tr>FfUm\[ ~lAT6-'g&z eMH&GpœLj+4yG;[_Cy[d[ H>=;w%IdeDd;@_[Pt՟A [kG?-s|뷒)ƟŤL̹AHX+ 8dz5`2mպd-8v$L:~q V(c'@ dyi"F1µve "PTuGw~x~r=S\)gs}j i'ԇTVsmm|$ѐu,z(NË,@(xdI⣷JےH{kɜ}CEt/#g<> N@|\ sN.F/M' T1]Pz`up붸181"_9L c^`WoS`($cT@T3X.^{AUq?:k O^^` 8j5N/eP f`ëB3 .(fjgV$i"rsHjBԃ6 Q|DmcLW&2ylils^=`T9.pLW*E ^ ʈa?]}NuТ]x [;1Öpܟ؉U)f q` !}°ԡbfFsG ORDSϝa>:q(GRdY&@23l0\L}uK)x~Zs*f>Íx]$B+t%}t:f;<:p9IrȢ%;djЈ>:_iCx rWP ?%BzĥCDK:X2أT}.ӂmuNTcTZeRl!6\|}y/쟹﷑e.زu*vzxȚsF6I6mC4`cyvz6COBkxSi @a~5fSB/E|ibx/M`$KFBdz1yk7Dxӄj1>DDgx)uDwuJ+6yX4B"|{ݩ.XZlHE+DМ(#4`\"^Zu0>'N[zLJwpOp,I7L5S K+|k;GC^uvUDe&0Sǘ޿O6A;hDIndW@ySq֍ٓ$ݬN3/\bk=_2OL$ȚZ,-h) `^HŴ*ar#g@|96{Z,Vʑ3$2qBsVɝ~4RZT7T(1K 1iUKY4k3D.&͝qul]zX`&f|Ws47jנ| jTAү>BELca(zUTU: p`[4B<w' (ro5Xbq 5.L oOl$q˽>(h>Xp+쵀A~FBϼ_+*&Eo4zrQ?{bͥ/PHc.|i';؉«^)|\nN4|wT-QC⺬׮y\0zX*^ 8Aִ &I>V3`L^B&SĻЖo];q#=tz>"m$(e KAz]wuӻel5p8Q'D3ZE: *3! 0m8rdZG Y%y~ o*[V W ȘNoS|Q;w֞H˹E-sZf+v_wE6h&T7^=s4xl[h d):@^8DP6pS6/kyǘ3 Mɫ$t{1!AoN xwl:+k,ŤXEvm,V=` 6uXݙԁǙY<94RA d 4b%\θŔ8 R4gK~L?0fJ!-=dx obЀU]hG|Gd;zC׏T_LV=K-$>NU?''GJFdJxv A؈:/ݿuQ%@{"rNܝ6vO2x0ca_v,gi휿#U,3:@S˷ "N":ԝSB3JrŏFF'Qn8NP7Kv$y?L@]Y5/?j\b$ȢJ#x=6E_d*LWpk=aq){R(lJu H|1C{/sc#Zz :m6M_Rۃ nYOQ 6UV .lQaX]!S6ІPv5ހ[.k[X-IWw%l]S\alf]q/j]4L\lD @&+`\>qӰ-^z= -\%(!E||OqwQI-(?FaD^ {h/K.FwO^F_X,A%^Y2o&#|Avef‹9``tS8&yxÆ{@c3n fU-H3~\ O:JoDQff;Ё2bX iFa^Ν%q*2J]YfL\< iOK$N(Euf|7 Mq9n\A+2t+x?8XQӚހE<\F!P`cۜg0r-!!SRfO3l,-۲_`Kx{74Uď(\B9%0Ucv DgZW{9({*4;'H ΂RTDZ0l92-X'V;N'>."I0?[ZU sAR)1gWtIw2!VR4 -73ag,hʝ7evvc /]xȵx˙LSy}sg-XFFnN R$L%H*-5e8"0n3i x߸;Ыwkrj"oQׯS˔*ߑt+p ]kڲW9.SeEdV!r\eEyiDw2ԗ-sY`O-ffL@#M1d5ZyM.$CVo sB+Hh#:hB +u ;)sD_AUQ~\ urAD|Av8jv Ե ݗkiq'%‡(OӅ~[BlYۢ">ySe}gu&dyl\N|gPCݢm3dE!ЌPZ/{ё'M3iU="VLN~-~v+rIJX) M<ީ08unoB p*#Df_J{]j Kԕ aqk]ǵ4#l`f+;@rhl: ,pOzx]œɘ >XRq8;e<<wZ ڸ$/spPo 8Rۛ(*`L03fXxA&oεV/UmcUWwė,QDMx2F$g # 3_$v$ڇAtW/t=wJ=,t?:Sa.r|޹f1ɴ]׊6r Df ~"{OܱKzNf/$,.d&ʱvc0:0A٥G-!t*& `S!8EF~qL8"ߥ11n:ήs&5X3! y 1i!laFF*/I.*&[Iޅ)@R=>Kҩ_wFk;v1}g U%7m+T5 5 ޏn%v=1ӥ}p=Y)p&1ʼI\FSs:9oydS Gb{HYə6r`{a+GH`:;a2J/1),-,D?qlϭ]mV UQ+(vٺ _.vl֛8qt hLW-n+1/~ATIB!F,jaڙnJnm;wTڣ.J;tj:\ ب yt+A6ڠ"@Evmw҃`|24,EY]ʐ.mSu\Cظw*Y AG2:Łax8OB0aeƯ%%RY |8}VnȕDd"]kKFa؊Ȉ}УpΦ$ j="ȭB2WhgBk̚nxLjh6X$TFpeQEtò*NV뿏kVT{ȥ.k' .v7R Z]|^9m{EA\4FU.6SN4XTtY&dd>9Zd>,`0">2RpˀkqL }3%wSNn![a']~Ե ~?Rw|;Y挗Fl] n(`ˤ ' tzX.l^M^GsTP ЖjPx-TTEg[FM,+67 Vz>P"_^w0837R׍7|gZgQ*M0RmoaWԤgcoy> \nQ򺎗Aʎx|80 ; R-N(l-&HBqy>\Q# D;91KNneN}~uWw^B C׵чEFpQշ,v%vik~Lխp !^?r3* 7Kh#)HG{dl&C1ZK4C|7ƚ.́ɇ}_D|]+(]!nO')`FUT[Rd3'ɘFb ]ӫXEY5"K KdJGK[(ª#) N~X?~6>pN1rWtf2TUnd_>9`cݷu,_ʎY+L|e n͸e3L'L4tl1]j25Tn^[2YȅmVx B!9c19zڸnY{(Xϲ^툖kܼYA߅ p`Aɸ'fСeLATP(*nٸL-R) #0h+0h&ܐ?6utzyipD_2AT5 [kQ ZF0(ޱOVTnJ#͸֑[Ɲ8a&ײ᮪. ¡P~ !x\?WB귑O`Ց<,4luqMWܢQprUJzG[:~ ^SHzf{DN:W`ЎN6T4ێ+$5e zX'qEoYt'a*g ŗlf=`BU) %kJuWW|wM;HHeJS_yw7>r=\ 7¡ݎ Qp;N@P ;ܔn:q+ƍu,f LJ>isZ7&7ҳb ;`|13ql z6zl8Ec'CGi.SeS%+M_Sh˧3}[r?c%&ɒao׺U01`kcL6r@V)^YY:u򜋫fv6f8j.Wƽ$?ItC8&)0:f'0-\ TmK ,Z,(s^#Bs*]{# `b3~. ()(۱!7B3Ɖ/]vCO# -ɆvE`up~lZhfKACi?6 8 QVaB#F{@g x\nSm65f9.-kqg>=?.}Dך߉1s6 \[F|^R!ҵ n{̒9CcYr3{ ePS,eZ,U`䚅zE{,CxiK4Z4AwWzw n:% " 'hQU" d"!˼C$;^i}+ ?1!سn ! C^`=1_!/d'iK07 fEEђ -ٰo<D;@ϨjZ]O0ܓHU M|RNq^3>@`B[͍oiJI>&&VY"~N[2f0P)VTRHLF|`OJb !^92.e '_69aF jHħbvY_374e 齣I9c:{,pKvkʨi rd eToEϊk Px?7O7?3v"fa i: -G#څșg3t\yyEdupIAy%{ ٷqU,i\FVʟ7:Q'Qi¡IzKCvG(F"w*O`}1˭ڂwʚDLYeZ|LP9+t-Yg xSZ5!FށTeԛcMCp;(i>~rj}Q Tv 9^ok|hј{>N Q5l63xɴ&SQC|KBiQfrYЅc89hD(fBVs&[*-Mؑ-[(\#\S4Vj@6D3| e7Au>՛ȶ0vC>D;A(/yhD{jϽ6/.jV+g5$Vלg`y4| \ia]%H<][ ؀%fK^6~1 ۍlu~ '0ERrDDؤjf<$ k *a1઎L="3=u@V W.S"k^qܦ^ʲGg0B[7M@w͕̩N*ZXR1~5K>OA1@!m;[?p!:"/$Z8 voԅvaE/I6_OBOlJ0bsIG}Cl% Cncx8 3o),B ؟H>>b ^9O(ZF9k\tߧx ׇuʲ[7 (߄6!eR-òy"q+Yaf$oa-)3mdc8V.6"X nE )x נ91wOm[WuT7;+*/)hU{1?6:ҘeÄ$/)h;LeRkaBV9k #6⭌w4#]KuDY4c4acSe9#Ϯ#hH]p3^&:Z(1KkEUx~7c#~oU2"?J~Y2#@0 eG(iy;‡܇6tDi 5N5g+-dm DKMȭsePksq )!,-Y <.1Gs;ꪴ-0kވgH`HZ$'ͰeWf'*-I!@x~Ѽp̹ Ͽ\,k9Ӎ2: z&(ڊֻ}xm*=&}Q mĴg]2CMIJkz= 9<jZk͑ I>݌ J芘|}{NSTj}6Cx=V2N^1ßo~-l*%Ɲ!>47 ے"cs̡ot"X_9rG\[VXpŽwt#aۚ]y-TWZb< Tk{r2mjR@EKX)uXE?)D ֺ+2qۊQI׺>>N`[Jj]F/H٠GY