sssd-kcm-2.4.0-9.el8_4.1 >  A `U]9<__ b",$aҽ8 `)|Ta5df16085f82e3a2a13867c75c4ecb0268e2c005ed0618f54e01291a9b9cb4190f82ebfb4ce85bd949a37d8e4ae4091f5b31fa0bk`U]XnE 2jAhKh{ 񛱌9-3.c@+8`?os9Ҿ`=jw^ӹJ`5lĵ*]tFk5NNWs(˱s0D%﷼6%^B dv.֎M4og[r譤f3`OtMg-=TUJ@o&1fwQ8m a~[XZ2>C,Ե T-;rm -x{`YM,H>\Akt5RTKϧBgqoZG4)!t,fYXT q̔fӘ*f,QeytPc˸Y#{utHZR mrK=ў'5Ro8fh8rdiO^Phkϫ,{vr>pB_?_d   F +HNVk|   $ r  R8; $;;(%8,9:c>V?V@VGVHWIWLXW`YWp\W]W^X bYdZeZf[l[t[u[Tv[w]x^(y^`M____Csssd-kcm2.4.09.el8_4.1An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.`iaarch64-02.mbox.centos.orgiCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://pagure.io/SSSD/sssd/linuxaarch64 if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi,%GX/ 4AA큤A큤`'`U`U`U`U`'`'`+`+````"`"91b30e576e05441743fcce027767650f498cf10ccca12ce0bafe8505f0e87b6fccd7e89b03f01fdd98dccd0577d20bda8a00016ff9fd59e06d42c569f340c3fcb4e29a574d0d8fb18abdee833929707d2486eab2d2c21cf074496be2e7bf9daf514724a457b0b91cc01937604d309d59c9b126f7aa443432ac6e70597641c72b3b345d932a833425246db804f6179bb6bed06e7723abf6ae04d60ab34e1876b2bc1d859b62e921b6c74b644c448186fe5703dc23e8cf0911c839b4779075dcc22f2f662d812ea46586062ed00e0be873621d5fdb42f82582af3fd8353b2c9a0ed17cf523de4ef43865acc3126813208073a443d217baefcd9472750b365b0dbc91b30e576e05441743fcce027767650f498cf10ccca12ce0bafe8505f0e87b6f../../../../usr/lib64/sssd/libsss_secrets.so../../../../usr/libexec/sssd/sssd_kcmrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.4.0-9.el8_4.1.src.rpmconfig(sssd-kcm)libsss_secrets.so()(64bit)sssd-kcmsssd-kcm(aarch-64) @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shconfig(sssd-kcm)ld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libglib-2.0.so.0()(64bit)libini_config.so.5()(64bit)libjansson.so.4()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre.so.1()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_secrets.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd2.4.0-9.el8_4.13.0.4-14.6.0-14.0-15.2-12.4.0-9.el8_4.14.14.3`@`T@`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.4.0-9.1Alexey Tikhonov - 2.4.0-9Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1949170 - pam_sss_gss.so doesn't work with large kerberos tickets [rhel-8.4.0.z] - Resolves: rhbz#1945656 - No gpo found and ad_gpo_implicit_deny set to True still permits user login [rhel-8.4.0.z] - Resolves: rhbz#1945655 - SSSD not detecting subdomain from AD forest (RHEL 8.3) [rhel-8.4.0.z] - Resolves: rhbz#1945654 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-8.4.0.z] - Resolves: rhbz#1942438 - Wrong default debug level of sssd tools [rhel-8.4.0.z]- Resolves: rhbz#1899712 - [sssd] RHEL 8.4 Tier 0 Localization- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh svuk2.4.0-9.el8_4.12.4.0-9.el8_4.12.4.0-9.el8_4.1 kcm_default_ccache.build-id0b9959d753c54c3c3497b72cb3958cab51e4393c05b13e17783a727407c8ac26975e9c4adc434dsssd-kcm.servicesssd-kcm.socketlibsss_secrets.sosssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/0b//usr/lib/.build-id/47//usr/lib/systemd/system//usr/lib64/sssd//usr/libexec/sssd//usr/share/man/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=0b9959d753c54c3c3497b72cb3958cab51e4393c, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1, for GNU/Linux 3.7.0, BuildID[sha1]=4705b13e17783a727407c8ac26975e9c4adc434d, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)/PRRRR+R'RRRR RR,RRRRRR R R"R R!R.R*RR#R(RRR5R-R)R1RRRRRRR+R RR/RRRR RR0R'R"R#R!R$R%R&RRRR RR,RRRRRR R R R.R*RR(RRR5utf-80f617ab6337c5f3dcabb66e7049aff00583daf6c6923414175f04a54b5bb74a4?7zXZ !#,vs] b2u Q{LQ(cn\˻hթY[^G *\vec9SAʾQ^8oTtD8d50PŠ}J{+PF~CtnAe;CiqSfQXBT\- Reo*5lD#wXm-؀H}Q^ɅLǎV ?+KݺyՀK 0DtTg:xٗ/BS=NW`,jR$֗88*2N ʧe"OGorqF#Aտ.{ocZj%Y|nDO1Qs7AQH]RDƒP " 5푩~5f^ ZӼ*FGBjrWnCz[1W$^rB2= 'xKW+R9v7Uʙma4+QcLqy Q ˩2OJX&mdt =>S"] 46DWFNe1=<}7jnvHvRj99+{*+g!ySamt_y&v݂ ̓30!YVܿؽaAV΢"aT iS=ɢ9wP?u#i$ÎUfPT[ `,~mʫ%08jFv7GCWPcz(LZp-ddP+,N-nڵ+xdEuʶtBfR*[]]{;~! Lt$fJf1j)XKӬrh"Cj ],z; _]#T 1/䥘S!0M)yH0EKK’H#5u.bHoڕѻ/>S5Wh!U<弍 ~oت {"/ 'i}f3L*viY:{}VzLT9L텋.4dvli EubXP/D.~\Yu6U^Ѝ:l! e~BmIZ6WjR#2V/73Z\YElCsB|贵+z65,c! 4 71|j\4E>.C'A.w;/_rTXrIm‚+fvĢqHH R[r@bp vE#b,{&dWyQmYJ$$eI:Hs⤾8rYqGà)H;^fِE ؎r"&:M) T`4i;4}CJeڌ[tyw(m5`kUeKbYs^458[|*73/o渹T41U(In'Bb`}>EhU.2 4jw[2[p"fpj6ML3ksïa* 2xgKG= [KSʠx[3PlO 03c˜@V!Rr?5Qj cS7 czQ*62v@JaĄPS"mr۾4b+8O,9}@Ñ2!ɉ`H6׵N*E۔HWW,&Z׳]$~%IIjǔŝ-{ |^K-yxd}e)z=/Șm`MH1  ս,`*" 3K-H?@ UL7TZW &˶jJ0+8j<퓛6d*Kߘ k 4@z\Jt6aaL0RAOnj<%gǟA)H@21bD=^;WP'̠߳ړNgaʷV=I=j$ps _J76剮MjS"2棳4uZ,x)RWJ!?״Cb% hH=(@Ɲ@ ?ŧ@:ڠF$HKpA =d({d|6޼] !%5P z6;=]/0~;8@ 5 Jv,j7^Oj.|H类5֗3#% Xn!-R([߸J5o%f-+69^=bhd43E嚞S]DS@PZ2ml.8afAO}^\<қNJ~Nlk0Hvi==:^(E7^s᡼2 ]eSk=w7Zdb:%U"{u#x&[!&\1o\A&0&  #mfYdҰۦ9"GC[}*tz,$_c"g1NG_x!y~ABv8aiczbVs!++K N v=E:NU2Uc HFږv.ޖTub9.s=T.*[M+NrЁ#UMVhK{$V4Ĵ[!̢k B'i?^V/ Yl*92Q!]wT GfOKtA'Лo {֋b22M4p ]ZN>./Z4̢ \gp<"ieXy,-u kO+U϶4)EsJL0SIq.at*H|dQKO2zs I[bgOd+bUFI¸d 3'Lmwy^ja;t +(pHt_Ót>䂠OӨ%:Q[GpeEjRC!FnM0q&ud͌}c5kYV xc9B<07U?9ФS ӸC[ J1%&!gǂ\ڷp]7xBYT-@(#M$'\QԸeåFO:Edr5qTD|=O6_pA[JſZXg݅ A21Clc dX RkD$ԋAKm:G8,9N#m,;vlS$7٥&^5Qp[a4{Q.7UbۡVg`Q[k$@:W,-OQy3DCHh𯳹j}+s7ė_E.zn5KP1HmɭFd/3wX 9ѝe.WOwL{=M . }bITcT 0?pm쏯,t49|v0=ɱ-oUҞ!dn#{([FN󅒉;L>L͂{TM(<,'GE<("PZD=-Itk(?qxg^)NuίKȯbYeV./(#!]ꗆ9m;הz0o Z1spI NU+mN\~H9G.~5;hf&1E܎lҪ|X0n WMe  i+U M/I|re(hys j1:ݫz♩+~ҮuHdNĿɇݮI FE KJ\,TU&W~x Dʱb1Tg0%R "-Nš'?/\W] sFCMQL `zp|,B_OX!`KM|8<㱞y!%P (cS}@{OU@LMlKm Q,*,е'?/Unnx^yp\Վ$da8 C{psKY gC,@AG} ts \:dS9N>@۱4y)4'wKGmzܲ A2H͛6RbǔsUh?/s/gK&~xF ׳"ShQaYerJhJ_@tE K \+2#JAtnFB`e7 EdGr'&.f@6c,#=`bVO`aR4?/,jA׸VBFŠZQT2i7r=m nJgR / YG̨'mbUQ_߱-l$q<ʫCGi;U+MO|tLk*TCa bQxP6+Cٮ!F.2Z<3P%Kf긚 ^ 9F[gL$9 hrLn2`ҹ?1A–0s&_§XĕFH (.le_]+#~M0KJ lVӘeP^Kϝ MBAfI9qWw?ÿ-I34ϾC4c# 9۰tg7c?Դ`{ YyD.StGB~uLF: o X_#oк2eϟ8,8k f)jYWg `C;uVB-( z~q(A ֮ll[҈DYM AE":a^v n~a>vls%a XtugKWnA$5l8s/]Got{Gnyi}tr|\S%FRT%u 6SSmD]̣=ʒy nOw؄:^)U*q]Ch_1ơrYU8W\u~ªwX?!'8{Ob7[յζEthY'׷A G;EH-OT2RďWEu<]bT<IƩ+[J?$juoW*!J*Xs8\iKIUM@#Uj8Êܼ ˭#-U@vXLGBv{#ۙR@GKiBJX!kwazIDVs'(UIWGԁ[@ S[3R髿>\'=|oleL07R ^s+'S\ㄦ1> H~4l?p'@BS$R8y==dẢ+];޹?Sgy`IM_d1yG8&^Eg\׶R,'.|e1`)T*ɔj`+.SH)j0J69\Z :,D?AEщt|ֲDzQ`̂pd[ ?6YK[<鴯YVa'~g o&= 1M]<n$c zDdVL~#6k(Z 燧_@ӿt^ {C+-a2)tĄV&}:WM'CzlYP[=>D9"״V>Fn^Vc*^9SԨ j܎J~UNwĤ^O usG&lwܓyVrx66YNU]iH[ t! "JLuN$K^Ƞjz|䗪S;#qcll:n>LbJ{zug[U?QDN`˻IdS #qn tr'SQ:n9w+lߔsQ*Im]ܚ^[WqKUuF3).j,[@2ғm37W|81]TsCvߙ%I$8V4X&̦М&^c jj6`jOR?['W{%oc": , y `:H8J/ܡteI; ?x ٌ=+22˙ю'@B4Ϋ)4,4/"4<`sE _T^-5 g3B(iB&1(%ܢfJ1vjؾd0g S)[8vV-/CߗyM~PȱX j5:%3t!C 7d 8ᎩIי]v4Qsw=m:xGL /V? vabq2Kp:t|4(iɗ4ɻs =? `GBPu> k`M\0t8Ү>L;?S]y>t}UAhJtZi9vVv>_r:~ފ X.>Y8w櫃 ewi;|`Qʏ.5'=_aG'P&+^0Ai]ְy^goRQՇrp6/+a)W|Cuau,.t ׭m;8P>}EbDc6vgbq. !xWȿ/*[xݩi$ s4źq͖* e&+.bwʂw/D>,l\KA9\|~L<șe\_V*G}_)Y.*7v FNM}F_յ\^FA M(iS.l-Xdא1= ϟy 7V%.vk*>Ln#> ҢB!z Td+M ;S= bn5m[KG@{e @m@sȪ0\<.N lMjaRrUܩoU8oHCuȤ*w`o u/ky?g>`_նI(bۂĺI؉$ m FyO\ Vzw1Ak(H; EOtѭQ.D2^friұab1R>Q> Ź:#}&w$m>\p@VP&8qmHḠÂAil1g:\ՃtadDoQy"~(Gʷ#v {9 / #0%]`Gfc~̼BL(>vˈzsjBYv؆"H-bxyw+66@1[חT OdƟ&vEwek#O70/6IHJ%@yQx?ɐ.ټkm$WSFU$m}Aѱ.72jM|mJ\Q\9(}?K ?$1Qr{B\b>0w*ו_ qMNa 9xlf|FͣѠ 7>qE["AyEr6>˽VM=j4s`FY~icd /!  F[".Rϊ=L!Zh/q,ӑv:B2B`+/bGTKɿ5ل6N ړٌiDZ,0eb|f*65ƀ%A;b)MS3(:jo7][Fuɀw MF/5T+i>Ңl=,1] 十HP(Ӣ7/5P:4xH"9F!6< hmw֛H ܐp 랟ySL5pf6Z)ƓXУq…I?JY#coI4i EhAjLw/\=r쀩_D~7E*IkP| ;ѭ#fp'7G֟1gDk$;`i…ƁLo<7xΎUy#eVُ1`^62{$ }Re 4 0DUwJA>']Ǎ#Ϲ@Dڱš.j+Ry1M?v󀥫z~Aؤz֙Hǩ]Kj%܇e>aOߜE/-A~ b$ևa ȶ+NpD'+ ))ZFzաHBUrp;}o9ƚx%vD˘ބ o!:!ϲӔi¢;+]oIE5HT"[[ZGt,NGDNs<}2פPc~U, B$T<AhqT]MiIͽL&)]!d(d:y$bk;.P>K#_(C^Y!5!:6`'@lyQ'D8 4c~~951AwѸh ȒBvR `΄P~FV³ 81j\qt +Ą#Qe'ؤZMNJeȫb:μFS1nv2WҌAGv4YpaHnd0i_nUcw ύHmS!3|L-C*8f&H ('E IDR1Sފn`o ^˜c#eJg_ÉBPr>EnMWfV|`<4<]a gޘ9Ԅ!_,r'tK ryG|qHo\xqJ2)"rN*٠(`B9x+Y+6u㒝-JP;Ze1 g ւVmqfeQ<{Pߛڎ"/(|ܿfx:uMB=(o0k=aտJ3٨|n8>ΐ*c #(珩t m|7lƣaZM-LTFv61[^9v\Ev&!\:`Jp<4Q%%ĹKg)rdx3>&o@|'W*NoѬ&KN6J֡"=]QHw{:͚1L9dlNiEzJj 61q@l@Uiq78(i&T?Hֽ ^I &=8">2=by8:4zF4ʨJZX?Z~@anZ \*jkKl~N$tYSյ} H/wYѫ:>g纸 ?u,tB/wJ;LwCڞ/e]%11w4,N#t)CSFa& (' (=6Wŭ!>y'1t?x#p-j6:N~k̽u td$@) Y n:ګ`E|UÓ`W |t /lߑ0kaznР%@+9mt dsz{*VG_lV29\ѸӉ%!n=A,U4Xy^V}lUs-D+<98X5՘D-M=8zb<\̰˱k;E"jSVy073W4+J}2_<_;Sj~%K`#hGC.?b]CD"6Yq/3-5 Eu'! _XIjTޙk][,%aA¹in9<!A[<]"J IưIz3lbXdq$"p-TYz|ݱWs~`K/y)Wzt2Z[f0C qBMz ?h3b,R@3v_tюuu>儩Zc)zJCIJ i5o_>r 둤8kt+`lHҰPČkTd ׬=: .-=sQiBev]AmEvR(OK+b7Gj>;8)%`-]CڮvSL퀲=A6*?S|{ﻯ!Gآ|' Z,$1O(/lHb(L1T37Q={Ka=l3)iٛ6w*n!(a uC4)(l:iʗ91քWMUK)/5ߵKA7%J7\/@yJ{ej]2\  zqc0KFe&!;okF5Px݃Rʀ+0zh \*2*Zw* ju};6YZZ@4GtL~tp@*2?4=]VBpC0G##:|.>%Z"s4P@|s4Jg tvI76Fm'wfToXXɓvK"CC%mE9!Jq-3m ka!s笣ŒAD_f 4kPTq76I= øȤ*SU;]rPP[-zI%M@عu~%ohQ7؂H˳,o׸:W"mIt)"ԫt dZ˾ڈ%e!z% *gCNp\Ճ;0Ƴ9 ,#74]6k,='PVm?B^)Ŷ\M3^u17t;K7w,uhƢ]$ 5K1fe;6Z/`-zJ Fj_e(|Nቧ˘E@ ~iS)cF&hxCOZ2^+weD}k.K4Ua2FB(]:B<1[K5LpcDh :H4?Jr3%Spaqk4a莜;B2֖}cJ B\-ٞi[Ͳ˟4;){  oW9RW G:p]Rd1T]F,} 4ht7e8xL5ꛮ+:$'67GzЦmb1(~-+si+=PkBrEQ[SgEG&ӕk:S^K V-h!)g啑E&ɬw$0 O?n)Ud&(_@|i  =5 ?迯v<ܹkӤ*[\8{R'ވo^bb/.@zhw69 mM.[q;Ցuls*!'Pa|DTx&\MZ`;ZLU^^@4iըħS J AXZˈ7ވVSŠ51gJO֚]hL@[(G#0D~U9U{tӨqfB Z=M^i}\%L(RWv xo[6ʃBCϬ/n ^qA$6F=³Z}VZl C\~(<൝yMb"טsKg%JLBu w0M=k122m[_A |5ßnRWPLX`yTN&2YGѽxn|@Է V0',b D{)c* _5_ ϴ-<^Opi`Aw?ߢ#BS{᭵?,g_F%oJ tb*^rc\^t2"t秪 wO.ڝc/ G5UrS&zwR~M8mN`e҇&U>xb!`II=clkd8TX\S;~+m褹q QtR,cgAML8V7PbJD aN0^ry` *9ZILoԦU5Ԟ`))ί}nBr;_ZQ$,wl~2@q=8 [˸[}L,*yes"I|TX._5"?>扥WM 0o@i9;'}Z%/U \\ޞ> Cs@Kf0}lxŮ zh+Qse1l3(vF$44[6ƴTOar+lKuZTJ햙4U(NeHz] =/ѼYetxWb? ^Tv09^9Ն>/$9Z(içyQTڴ .^3F7r$m őMۮfJV^⽥]VHロ|2NQa 3 +9p+3n=+B3BHDV}kTvx) 踍jv#@p.U50^c7*(96Ҙ4f4CPmn1 "!j]b fdn;ofpXd Y"liW&O3ZGb&Z0]K<ǁwE04YyD%S#*;C=1=ׯRᛆPŒT[Hy4a3z%oi@.aaV / 9Z Ub?B$ļX_3JFDM[!mM2b2 ^^)P%(7`}9)B-"E߁o1ʜ7`!OF>9AZ_5˲wY4@Ȟ/ 1Oe =2pwUJ}ək0T@]g#\ha*h{ ԍw?5t.GC}*+ 6#)TR1N*ȝ#Xq,cQpD9`z/$++\8iX c6q,їM9vR$+"0H<Ӿe(г(~\}R.PO2t}>yIŖO]L{%$ w f Pr*cٟtX;`oP̍]h_Gea_^Q5YdS5M<|7ڋP Y6hVK: s ,?S3'&%n*@DՁFmGP(U %֟)P$Gk$I:/DJ:U}qJo^F+ OU2/h0H~nePmΩFݢ6LB-QN`}\ ?|dʪ0|V+wXU?#Ǿ<;EAJ̖e$qS mdkK33EjL<@D!Z^\r_Cʅl8雲9%`xI'b9diw>*R,<ϑaw)| XAv _F8fH_'+xH$)Hk;G/^U #[V^Uv 7=+Ea+LG[N'T80P|b0yM`Y*h,AOz-l\N҉Y4nsIT?UYbhѭ6Y '{}cuB %Ҕ|cʼ`31n+N lkˆ)9E5},?:̃u^r T@ > goyFl=x!E.P@L )k/{!JQ 0MK=^J8f.րpNo q#d ?q*nbR(YL0X@^(Psc,>3SIGPhcZH@0?HeG8pƓ+9DzeUC} pe 5Ưdǡ+]U~-a-hkАHtSא,ׇ[TJm";9jn:tu4I|V0+@e =שPs 6cPx\jJ2ї$G@ d(5g`ìJQJa 4`*8 -DOmC^@V#K#:S7e?ߑtv:SXEN"tGs}Nz>$,.0*{VρVS7 Hr]nP5'{XeWڱ( Czd$lAA5<:EY97!S"A밈{咲ycO.IkG73$%:9TL䚫 S &*l*zh+$GJ*GI>ea4s" Q\ DO_umNIfIGڎRM=Nty{&7O_6l0W^rv5Wz2bu4tq rRQvJ5ÔrV<ֻ;|noNi(?Iu(ӯH;74@ۖGR|Xyڭ5Gz GR793 c2"/ Ws\g_rlRA1gMFg̒]=:W ;*#Ǹ,3DMRa.K]ٯ@4ghR !4'k9 V1qL'@캱FJ«g$`>lտS{zజ5DF0Tj'p~+z:?@եmj&:Ѥ3lnsr#HLd28xjb=I_;@WauR2*ٳuV(l]Ґz<*gJ޴C8ڋgRXv+k^Z/ȴr Jg7 W1%siݖ BR]k; ToI!17ߋuonHrЫtZ΀_{W_2S]_Xq@P~ߞ؎;e-.z}%c~}a@]gI4=ODǻܹ7Q߇6Q#]җ/<> '؞y7Q;+Q9=gI6@_pjlU^8F[`%0$e0fAʀUGDtbtb:ER~0EoZJңٴ@̐k';vvS(Nc%Dd#SuXvaV<6?W)I$id=xNځ̗H=^G'X_wOLi ;*0W7KH[YƓehJgLj9_dsA>veABξJ=oNKsf'Th[B| @]'P">BukaRk{i6 o6fސ/7q>lrt \5m \&[ 4i[ɂ-*%v (pp?R#$6t9&A ѯ](8cw'ʕ)MK*PDG)e x1xK: Fi [q/D)ΟG>0!3Vpa!XpEҽ)Ryߒi#F5b~#dT3. -tF"灁ez`k+bV悴X] &nfNj3ϞtJm;h #>5) ۥon]i}sÝm8ٗ%&ԇ#MC_ #i/6ʘ lIPyZVu3kLൂm@B.:6cy@n;9f A~\η,HID]NҺ?x 6BfNk"K~ 9UׅVN-s1w+VWg)@3giBMٓ47cq>DɇWe퐱@˂FXڻxS80&~0[>uak9,Ȋha9^{tx~DJ8WYΧ1kxP6Eߖ L_S_Oq $ư '<##j O*i?2{޶8`q|pZ r%AwZkFy!6\054&b}QR6NgC@ b:ҚxLVWR&C͖Wr\ؚG{zPF[?y@]ދ<V?"D&IJEZPB20`oB:D=pd@Y2IA1I Km6H$H*sxU+$}e6i gD ,tNՎ[f!Pg@Z0˪=jó5hiYa h2;;N&F;V팱9F]~gcT_5-&FU #`>lRM ?) mSӶO53HD&TznrA !TGHdVۯ{-6om/0hbp8.x,d,]8JZ|( ) {lMe96Kp|s/)mPHy>՞LTOseŌ.S&դ^+҇eeD&#^5K&HYJS Jp%UNjBDisŚ?ovwH |ڌ {0zf,TcۇJ -J6Ϛ`"+75-Ue*Z봐m [KӨm2g@0ǨTSڄR+|;,w.+>Uw>Nlh}qӴΆ[h~r$~앉k9wL~."=P ֊N9 glƪ-:tuXՔ<* ݤحszT.+p_N2$`M ɶCjU1Nv~7yGe-Op鵗s&e؀ u#s7%*'2\?"LA:R(1Y { 1a.jE.ZGcBwSjM[k#80?45:eso.:4IxC~5VG\hγs-]%Q:W tqp1[' hT~r2 U#:g<Uw犝leO$fvT@QT91~uY.-:ZA#)߁"lHWtHoL)pt:,QBi{7z:^:^1I1$p 4VŞu#&a1DMX@S 64vޯ>lfXVl0Q+wvϿ,%1]fcS$AwEP(@&qNRzِ;c(XL=+B*"i VHZISqhfI7v`$ 0w<5xj 7 _l)^[J+@cZ=01$ɠ?EDPsj7.g_Ox:{OOBzb '`ڐ:+Y aA[Eű_~SG iU}cKBH]lMIZRxbxE?R/!וּX }~Yl_ʀF!8Aj{wQMMFqI-TEo!eNRG4F.GG(@} L)sbR4uMK0 {:ZU]D-gѧ:y7X08.ER)W"(`QPYS u }-|р:  X| 'ɀ[h\_J{D8'29~oy` ,CD`PivׂŻgɠA3eķ  3EݢJ4)\J}LU7㘑{mV.g{E eClɷ#$no+˙̬O=|DTA شVՐ9Oe"wq$9N8 ƣF"T*S?q nImOoj:A)ĝz1HogI^kE\= #^Qم%{jnՎMw',+1$Ymq5s@ lG4YinfV2_)蹀D4u |b)`K{6 YWWeDHu}%T\8ы \[]=B/r0=0.](grrbX'CRjuSo '%bYav8s/o4ԿubI/UL 5 ksY7]q3+EX[֐cZw"CxQ*0u3y({1KqৡT?rI]1jR/׫pB*YTcwQ9f~A$P,Ǎ9t?)!İR2$&A;0hL)|TI 09 vH5c&VPn]2;;,'m- ''JlWMQ%W"BVyKFܤE@h.C&dӜchɮWs=ӬIJ'H[z}c ^"TE午m3 O[^;3\SWQ~f {`'ܛFKW/ޗd`܅&2b uw~;U,oj;Ctm̈́.̔nG?L0¾~ٴ) v.'Ky0ȑވCI8ne(`wV<@pWWuF0* 2oH/iiT:3aп٥ր/;S @gjZ3~hm`-?_pű#$v|[8v1Qam?TH ^| OUAAj[u5BP$&Έ喎К M*iޡc@:r-JzUԌ3НܢM`#fÂHA,sA&{\{uL=m'; >CwxVpDdhFRKw4{p.(o@˧Bwn5'iyX` յ3tB`3a0if@:FcƺLt'c O@q iCU?o$VÎ ĭD~p, )3 uF)7{HjH@Z- 62=)Jfx%MxtYS("q"vbj4h$LUeݥT$QPkmZjl8 / %kZ ('qGBKv)D?%!pZ7,ޜ1vMLǸ<8laBz55bHxo3԰yNڷ4"OW#JcL# GSJh}H c*{ױbLv1 Gix_!'e8Iژ^>zzz+Z~QirU%%#o1u9 tm:z˿˾Gl< S LBv+hD>7. ߷ hgbd4W9%9{v̏z3JZη@V!71BoYFVSHetA/55˃?85y ~lތd;V?] Zݟ*6@sgB?B@rӵyFAx@Εs|%Hw֘?@]c+b˲ƉI{"%wuZ7h2yGk0.$Tc$@',NC]Ã(%, ˴y Pf CDY۲XrcPI<<#/b&mV{,nWKw 0U%\ׁtJm{tSY{H2 oͣ|H֮Q.Kho[z(Mdiaڙ4ݬҖ_C |Ɛ_lk$T^+7.[m|v弉r{c"2Im&o#٧3r!3NN_Vəꌵl,KohG!'FH4Vy+kMeB۾59998޹1":X W}1f;b8FQy9I8hvwC?Fj lq8jL*=&m׾Ė/&"߂h i#E hjTX%Z:Ј(:Lɴ5r!ʹed%kdskQm^]C%<"8 MMX2x`jHu,4ReȈ@ɝv7' Ԣ|7=cCe nYN]-̔FyhVRk7!6z2bTv&';%+Cb~<,<9 CT]9G5d<~;0WbI0vw`yYÌƿYc{|)L}h"WhBuj +Jh4[4!s b1`^ь̗X7zZ-dхa4bӐ'\| I;2GƥFضЮwB^E"~.`!ſ~6FF%R\KӅɗF?*@B*JdNF= .0b}J%/qV RrV8Co?CKk5R0 :;ZȯbEEfZ66UkMnzθ֬BK,}X΁BTV낖v@&}Ƹ4qehiIɨ]9`zw}T{kC(uaֵYg)b_z*ȳ9:]dUh2)q19e0* *Sm"/jTNxW Wydf]5l%6nNlT2Nq3R+a:1_M}`$\56[xe ^ `$=/8jO?'At%KAD00IHQsi4 ٷPGg- 1 uD1u~_xaJlV mbp:} '_ 8*R=.zY MD)iecZ4ՙO@֯e.OyA[x=8k|=d9m cGtbLw@A#^O'ԃލ㢞@hM`Z7=A0lܬZ_]̧\ XEu{P WH|E&$DF~ҾyS6j~1۪ik}8 ;+;c!MEsjVP{rd̸ 1rHm7{>v4/b,DԒZ]E.Pobupf-{*"c`v[M޸@ WpPÒ?})S~0c>*F]W[=ǧj@x\>q;sAƞ"b*biHV3+3^ [69JH96;^j. n[}nXϘO ^ v#6`52eJufkŔ7f&6@4xRyB:_\!&31gXZvVL'r.DZX ekm4qq+*5,JO(KJ_VZ5+Jf0=61KDE4PV%HZrw  $?{H/(wOõ3v)<VYx_&9;iUDw`2+MIfK1]o^Y1)6ty3tk&ӪbqG$ ;r_d5'xgdB}OCqc6ymGD0GU_8dIBG͏ww4ĺ m3~w\0oc=X^I ǽcm猞|A^W3 U>Y `"":1O"3e;f1`=.u1}ej/׿֥DPA>??B0)ld|p B %n"(= alu/8ƚ)ؕ-ڶ3Kp8#;a[Ѥ܅BTG߫7;}[\_m1"R :le˨;I}ٯRqXFt3&܄Whs`\J6C7 )~BlnҀp -`xȥƣJ rjCJ<ÛCT:̍O)9ɁDh8X[YݑkG5h1sdJ&yrxGMNSWE;X?f[M`6x\9MX]# J7ou/bMJʩ _dy]LzkRtT1Ol>U8<8[64ęjeλ c(i-D` Q-?ԏAߜ:p*@pW-CyeLDJ80X1`ۏ j)Si]qˌt38MsH!i>Xzz @?t@R,eP\&XD.K<[x 'F!-%ZnןXa3V|[j%B$n'Gp"^M;.=5]?4,\"î=_^/̡'B Ĝh~'PY-cFvuiJg5).?#зO= #m̋ "'׹NB3+)sѧVr  ލxV&a_#QO'qL{l*OrY:j&v1KZ*iFV9hB/?>I`a|f W&mpSfafITE'!/L{vvk DwltIb:TQ jzqpPv850U! Kf?ͨzVgDdkxsK~ WMYZ,DxM@3U|%|+N9tn6FxW{soFvy?&VFZ'Sűv^:%/?RX I;Hw G*dW[]QS0m,AR{Y> /Z`EJqxo䖡PB]\ҍ~KM#QRn_ܻGB :(0gw0[Czً ?t*uOA6@QJqoq92Ĕ ezv@/ҳ丼GM+=W‰60] P|v"qH 8{M@~b8?%SvFU @p_7sa3UA^K}东UUNbOK)0HcQA ьvKUg@0 Q?UfsYa1 ŔAX7IcAu?Yphw׸̺;*gCr 騢Y0e&C7KXdXl2-Cq(:˺ 3^f%E>8g)j/oSbjINHZ0s7bk7b@<<3khIK[-M{H'jtrbG5PmChΗ$fZs&8S؎Y&ER%,ƲDxM +石Y!xpnyz^VmzOB[)B+HBRܘJ?> ~P)(ќgQ`i3%l^x"T1VYb*ulF-9Ur4>]̦FV󁘧yDBw na,vB!^ED7q*G굌'J@M)w>bANh0_AJ߶k_cx8L# =fb|Nq %jHI"TFk8愯dF0H݁#z J[{l)k8a 4 V;[~\췶%fk8E1n ,O 2;tOPm`cOa ½;]`PC7(FX~2\BZ\sl۽fYŀ9|wK(36NJ2%9W%ŀfEGfp۝$$;[pvc`W+]6 MwpRxI,9~rsZF/o,7.~vQu1ФY^Um|PFRh+D m/-}ކP^52WI*]Fط}5fv+?VJ6h0q)5ARsbjOMRάJY/Y}mɄLIH:g(nd313s]9I̺^ Uִ0yĎ~rԽȵ $9zT̸$ʎ$+e49nriX)jc6] \J@U;)8p3j=اpC X5;0Vnca UfyIpMtotqb;:=z'nDaY7zwU}g!d5)Hh"@xP+MlJ=,$C۲%c1Ɔ@e 7VxI⑑4;ڶS8Bq`2{~8^bW&6ThV~<+PUix\-0h.BU'1^ w-= XqvPɤ &Eb,L֕C POEq0|*rfK %r2 y!!}o,pP5o Uq\r:ّS;Mvk-ws:L3xȱZ9W&liM҇ !{] (o Ip$#ݡJ@|f)IǪv̠Iy'.ҵN6i QU&>4g&r3QBk[2eLQlh}ẁmP?p17߫$nP"z#"m8B@EYK0菬EөvUW[T2.Z,)?p 5&W`tRGaP~2q+,5/Uyh{K:',DJވ'ӋցWk- oab%D^ӉuL@DU%AjxdPoBd~e!Fuϗ-\n zb#= =0LJߖB@5YPUH8(|V-)[yanh攕 ~o14x|ep$:wSck`@;>n,T}rZr`:deB0 g8՟1k-|\O:uf@T7^>{ȅCo$7g=e| Fz DxSʶF(% Dh$L'T:8ʯǘFz n?5Y+70k7 sM > hqPuG_N3NtƵ@ߢ,E-Z 0g^p`,]Q8Z^ ރdvE*+g^WBk։U`Q*Gms؀" 'WTcW̜K^!Dw!ޖQFyp&鰁X$1VDP`v|Αj@̦ vPmXINNPXo-5}cmƼkE cϒʻNulu聍qz Bu~{䀔[D(,֪/guOgQ&܌zr3,2ȝ} Hj}r3Ղʄ=HPD0J/"捆T*~& so7{+jJU-A}yfBkos$.+%p:"wl84pk2k חe9] -fO6衣L{V謙9hd c6k]\PުU PTNkL{2H>1T[e-Nt2qgjֽ?c߉餧Z6/.Lk4nK[fu'qn"Ə?PZ'Mйrkxͱ&e ''T癑>XF۷0W"Mv 2P9pln06K9;B'Pfxa~M%cZ9,f?w9g!T==.YP, v4T-<L\\t}gK" uG`:Q jxB+_RN4FֱlY0ӽ;d%R5)`R5s,қ"~ȣ x`xGN"o7nq=%'Ar#D::NQlw"޼LXkSw'*Ͻ^uRȚMɾ  "7D\FፌL`HESAMwwVQYFY)`hH / Hxu(a3.Bm/l( ` E@q2"ˮ1s&#-N~$>`X=Ֆ7AZ ooDhH2U&>$0v^(5RD\gbij;iD5xuͪGѓbtyph3$́ILnj~|htacиCe`UFsMYXI;zz}xdn3/9y21RȘkCS фLw g֘N0}o63{.+j5pă @魼2Lz=+Htہ3̎&Vl`팾h9D EWJgl$+CIJ2AH+Pᨑ𔙻@bP  ܙX(Fn"{tE:_|}n$+LZj-+4az"rA!{Κ 'DQoLq՚cWbaUQ* KV#69y KR[Wr3 c" +81&#{'-W8, U흥߱wa 0 ӏ~Gi'GPJG\BWvZ9.Y콝` @Ű;m!;̄Y7tZ٨C$(GP9z͐%f/u'Y3 "2S!JJ>뎲:]bL?P<H{WΡ}5*z%%.c#n2 LKZf9 ^M|# 09;#r`Vx`e6+0KD]#~>$}Uy-86|q6tLj0ʑ:\)Јȟd)ԳSb+PEJ$U9 C!|1 % a#hs=M[5C*x0< 'nGGOנ:˾\j O18~1Wrr9;mE L.780J/K4z,%x(?\EH:5KJ]XU Yzeo[MrI' .'n# ?</T57:y)Db ;6jۍCNulliϮM{WADw[^xbޕgR)& n=m1n&Aw˺_ej<S5 =YfP_'̲8 3"Y~x]N QmAUħГ Ѐx iA 6桸XdLՕESq%e[X^W C@}P!A͝%"f ?z%$Wvb%˨r@~w5B{#NR&qn!N9>J:" WEwIw*nNn)baHO_|G;ݠt 3c.b:׳\0#-]V>4QvΣ1<',zyltvvbvJeFHA#C,sj")[(K<Q^o<\&Cu"8 Y||jfUPy\n m}/f*໐AeX) 6Ǹ7!}؃OЭC$!6iUy26f(њa(vG"k}HпSM:XIԷ ٧iW\|7qm~ t$yna"ڛ;6!e'Pߨ<`Xc.3&|5}JWzCq Cx%^!V_6pxvmGBL_>+mk R&)jh@UPC0N&?ÖWKYmLlQO`x.Zk s 3MׇT3u:ښyA,a͒Uo2 0|K%M~,JcUUD@f}M Owg!jaN14Ȳ 9ԓ|R`8%br-(R3=@sǰ%YkKyJP1QP[8 ^2*ͤX\b ~ fCԊS0ǻ&BOnby~|ptt:`2"Ee\ꊷT:ҢeXމTh[Za1yJ&Cv\Dmj,2;!=юg EDZ_%*z cٛ,6 rRD],R+"W1)5Ѷ- Lon: t'+%5vl̇8ڔGyEdNutqIޡP6r07P{^`y92~]T価7]RyJݵ<~+K8L[Ja&|s2t-3#^_PE?:pIQ7cWgo=\DÐ5zH༥sжA(DXMڢcX/$fuT#(e6SBġB4:p`>앎_lbswޑp\YTdM'D/E I+צ`~maa3d<4E?` 0!Avh,&bCώ $:O `n f aNb%ސقݿ3-őo͸e9 !]vi3rd)JcykV%t}ЛKNyh4xt~0Xn hƝ*7ȼ M)o+ UT{|-|}/3pQ?2tV0x*>kL+#mArYL T2!?6۬d\ W]$G< ӷT>07AB1:R`783tpEײLJ`E=aǏ!aD|2'05 <9iJX=7}Sh|a(u?aWƲ^2ͩ9mmW JOoh̺6"O7HR$ ^'ŗ B6JJ: MnpᩰG#؁4gw!g&T BHyJe9n8,,zc49$N@ vA,}<\oDgJqAff OqeKdt  VMSD{&4: =n9qrďCkpsEi:|=, +(A,A{fU܉X"lڈ5C_;n=h̄a0+a.Շ^.c#t/N\N':)Ȯ r*!ҹ 9oAyțMIBa A`D nT)t5򶎾L|1l]TYG*yy:dgj%Onb%,F|OR]vY^CEhx>YXKOtgti+i*lMW݄h!QY ;$n56`8^A&YߐBi2`rMslJw!L,{Ȝ=YY'YZ#ɀ:N?EhX{Ov;P3Ⱥ!.Tgݯah6T+X.EBZ^J,]'n҄LOk'R6:w'Ҟ5Q.0bׂ|1?|"һk%;-wPޚ欄>_lssϑ?+⫝md| OW Nx+d6,Ii,^=<.Hn6NT-44Dv܏ۢJ.Qb_lo a{զ!fxfIpCʪ8-R7a24 "psAeN9)d>X[tbyko!Ns;oXlw`3<`bXy|(~JWminx]~4yo5s{e)cהrDXMQr I# 9s.T־21*rTŹ#Nז:_OJĊkCENҧiCUg/[z5<[He`ó탍N6ل`Ÿ |cb±w*"pk\:x̕.)p?k(z@$Ef,SZ }2ﳙ7'>S?/hS ʾ br`~]ݘdU5coVj~vr̅5/Iަݑ $&̥=-[ޣ+$l^ʼnmo_[թ{p z)+cRvi;+&reI|8ʃ W _=IlU\w&"cхƬaY rv2mU}Y|ڲʡ!qFbw.wZ66OlOFG7n0|(,rj@ 8#JC}&oE:)"jئYc ↆrx1HíI, Sr/?uhiSAmw{J#l+]#"*Hf.rA(n~pkwżdA\QZ#;!qrKV@ލuj. f>n|PL0?jJiK6@_D]O'uva?̓ a88jgg `IX% (FZžbr!XX\JgCD&JaD,#4J"v_7&B@bhvu]"%EbWjE rio M _ Mk[(Hy@mT OEo)W=d,t,6ǂq̑LIQwJ?QK$Z/۱Q Fif%AeFc8Pn=a~} Q1(IPΕ]1/`)yf(%}:fE? ۄ YnKy*#I]qX_۶WECƬrF~{ϕ#z켗#4T&[Z}>.0d!@v94 Ut;̘ǔ5 w1c.#?eՆi8M:{gL7 Ġzqk2Tͤ|r. *R[5AVҬ Vy{Wb8 ^EGX)WY*MG}f(IZ&adxӎA}:6mSے';=!ѨlVh=)=25zѤ]ܡ3Pc& z MvPGH /nˏ̎l3j-at]D?`QK?i"@7mJH8{E4E~̏PZPuB&WY^IS?4w\ ns#si43 ɜSnN(.Xժ%{V$EY?.עf,Bw(5P8ݚq_-oD j@0]vcS}ϫ%) JhB(E͍`5ox-ԋ?({T<$˳pĥe,V@Kd$yXS5ۄ 1 k@VLA-i\ctX>V3 !9tEQ*i%ּ8|Z'4BgZ$zּvGvP:';s^\Qr#+תLyjvAf7}HAָ8 $>^3FI_K\+qc0Af+מ*lgڐ@~ dPBŻwHD@1v(,pf6Yiݺ= T~:G8_^qdv1]B\gkka9Nc>Քyke iiR~62OWŻX!Z#ws" Ye[.#ȸ%eHت-v\a[3LὔWh$lԖIo1EocKpd}1=圡z|RSE#un%gnʨ%'GU!B5G~@:.骯uVE1EL%Λ-v$sUtWYm*N0^qV]@}&"N/#ρ@6vI'\BA-m F9(=XuYH ]u {[ka 2XᅤՒp qfDW!,v62EB[)'y $U+U,:U`ݖsLrjWr5%W)fBLUі+*~ n4ظ?@ L3~Ȁ/<~lklM]3 SRLOLG\銀~ץ}vu;ZE>c7Ӄ1%;/v=Kt']qV[tr]OSMo &)?yف#x%[*æ?lt+6 эc'VWU*= }K5@|ryBd`!Z/Azۆ@}o":[ oIP%`K fJ:+$gC`.Tw?fC^_]W4sS{H64+y*Uf_ieDos { }3S3Dj$ ǙC5mVr-Kvo&Bci|"~;>6d9뀆'Y_PvXNEyBIHC%N3G$@ݭӅ ]ZN恧*`~rw2{#RgVI% Y<e; 5ϙHMӻ"v[ ȔH)PwRۼ1j?ƃN?Ėh[bp+[+~e&~_́-(6(C=}|o F[h=%%7Q{viIfÁ}l[>N@!7'58W-9\fSfz2+7ޞRP -_vjc˷j=dOs߷ע+Rhsij؝wABb*bҙKɓjrql^+?Y23]!rzPj<} 2s2N͘a=O,vͽ~W1H|uyOڊhNXUֵj(2㝧.Xg$GgmG\Z9T* [v,;/8lWzFfbGNr>c++[{\XST;F`! b{KИφH![Vk\"'}o'iVؓbhDV]S0(Wfהm7kk` |6dk ~iXL(R+ EVHuK~5M WT; -qϽYΌ^g^ee $[T)tq5 S!_ZAL^."eW1n^ݢ8 2cT8z I_蜃<&HA5A̗ZJ ɘ3qOoM͉j>} Xgރ(WwExWe҄1/J"@xTOѣ͐ uQ]@7(m pzHBrtC.ٮ9GbH7PwQBJM9$Xrר_ J]*2~|Ժ"py69rU"_{tX K!5bۨ T0D3(̤7ѹMH4zmmk ogA0Lkb,?>$q`GC\Y驀2|uY9< Vi[/oK,I֨[eN+2yJqgp7|0Qzͼ ޫ4L_PlNB:QDKg6A]EWXէ.EG&2?@ܛ \:U*,v'5hmUp'XU3> uUDy*էA-O\k3yu%+zLo18f/wTȉ e=~6N5L %w)+_/&K-R iR_OS ~I~BX+_Cά'*7x%pzr#W.Lۑ< daަ"ퟠ5>7VHlUq*d)&pʣ,_pf}gq/?>}[Ɯ@Lv̸҈Rkqקw Tqk8wIۚX iL%9a?b^\7w*JG*ƌ00XAYu-/5mc1Q2y m(f`dse]-b3޳8ǽ!ڪ3Gՙ3bxS갡vf8=|A7˟{$ՍP<\ם>M:4)`G`2$(SWlT{ċbB`} F#$fJıpΣf6u#ߗ/a6;PcA$$hwng 2MP~w >-Gze$svD k 3s+<2J`UflUnNU'<H +1֝UcR`|a,qсHE gn' Rzm 4-LMO R2~dt|Win:n"*|(sܷ+D tOeqQ>.zj,_ *sJcԃ Sw>n,D*.BK3;: H?_=éhu1_H4H 5GMԊ_B6քW!>8h.W&x y|=bcst,ꁳG _h([J]5ۂ`)>>>u< ¸ MmLg9R_j0W2 Zx.&Y+ym0m ?~SI5F7]V#d3Jc ~+ILi/r{E ]w{Ok5m{o;% @o2kI5*Hnvx m*]u!<&9||0>!h\(8UZŻc_q쏏+= &e HL>;pKXVnN|sU[mMX™zS>b6шD@]A;B[וe7őb8<g# <6.3}9Fz;ipE zV{vށ;v"\ `fl^CLkW\k6yMmZ_ttvǮT(guPI.= mѭ̲怘a\D~2+t38vXpYLr' ZYQ a gzĩ@wѡ'6< 8oK?$+} &{zNR2רn4oٙNly]=swV+tAqxaYd]B Zbo߯(H/*  jL'[} Af +\ևf@X話l3Uݲ w4HN݀>ۉLZ ٠V_őKy$#U(g3rBCƫƭr<\#&mW=e3+C,(dmȓT"sFPa_+)kި)$2B܍c ީu6Fϑ.n#BS]P"FV&8s\=5~ox9ؙ,^C s4Ƕ~*&O^R"|Q>l2e.wKD8<g_ybgn왱;d|()sG5Te%@jÏLB8HBr3K)FkS&))Ww^ޓ`A+F#[@1 rm8v:/yP*4 9FUYkc樹;E7ma/Ui"]hx8ajG',? pv5%8пxC$_PU9Cэsv*L4^SV%^koLJ6fE l<DՌ#W.kOFs#}06n8(Ψ-,n]|]+%&۱3En㫨j/hS%5Հ,﹮qzr=*B2u=Bn`@Hd:3JHPϴKHj5oAN#=愩,Sw-m6,#7i5 pyZ ^o@:I~ Q^}%8?mj}߳'aޥҫ(<)ה+֕/>1u4k)[<霡S%OyO/;A J]^ 2CFzIy> #D#'b^ qS4XOa`+peiPoӠgBΆђBr>Z&F@EayXX q-&y2r_ )QB{c|(e-$=[c^[T 3 Gm!HurEgs̝_=!.3+\A'KIN*?r#]!Qt.2zfx>H@KГt}_&|JSi8XÉ,K *ͭ:,:$u4*0Į{y"lK w6#4x ]ן+^1]D Pp$D#/z aߚB%"Iòpqgտ`$؅Z_5]+O YM2),Ik_&䒶3 Xe8B@,ZcG*T - ء;ceNF W//yʧQ̛\; siLb8zoh !߷ͺ˧l .PòME?fP[c]/cNh76.479]縘HF`X:D^iͧ"+Ud`r }_F%YT֚{n?)X&.{G!Ene<67^WZq$`>+00; xo󼁢g|5 ?68Vb_?YÖ}1/Bw`m$[LV!&v_Э܀JDWbtv;0#ھf$gt@ A[U֊L%?bݻCߛ d%5Fws!CXJkp*k <:|n70*6:i7S.N`,rXJDQ+2NEjˇ`Sv#JN Zm\;5u(l5ta8GmAű*NPFjӘP4fMMCf@U+CzhOC/lx?|v)zxmqF2l)wpԯiqSl%OHډ#`Yn$W5:V 9"΄scYGOХ mF 7օ>%8Zf/s-[,O!H~qR,k`*Lm=ۀҁ^"U Xs==D8~Ty?DΏZrҧLrc蘵bvg\۱CcӓEщuDO9ǃ]ƕ{,PO(dzɕ30Jc:BŒ*71e.ƹE*pQP~Ƚjq!F/ض֡h)~[6bBޛaD?"G J5~C'=r4d$xXKZx|3(!2Mla\<$ڡ[, GMYVQr;.G{Ås:1>#h|vE鄵^\zuM[E"ecmfa- @iR3Om2 ֨;eSeLˆ4lK^uXIpXݤs!csND"xSd-or~OlE(f(qkc)Nȴw `3J,h8./`oaϒgsr]K|^% u%x_ Pk4xt @OĉaP?rS //( ƬM #3ykWET[zq'E;țskBf˛7_>=t0d+mPZ{,(jr☙J.m@dHj(6guD>p?7J +ۗf8FD Aq:Aƫ%0Q EqMo&ҘҎ/bYQYOќ[IGڈ:M,w#%)2䚓'!eV?sv))7c|ݢ|wͺ5R?ewQY5S ۟O_Tb~,vvh}gQlYܖ-hn|T|1p Ԝv@?ٝæ 0>'AyIHޞ kJ{3lfP߭Msq帻Jg#FBwCgK%JMimmO}i Dsi" ,8T_pCkcMUbJ}Շ1o/~l{}Q*3x4]i:h_XLx/187Yw4EwE!sk ^]T{SI8Ok=tj';d@Va.[D!AǠ1.49_ϱEPxQ k\v/KsG88p`$Ē@D@aw[`:n}T!Ozq$`U%I051!GA >.m\{<`8ҠX9L:?Y~qtD=';)ƶ圣I@@}. y\‰n \GE_6b O^ 2&+gJλ."Kq,Z|L/XI֬Ei>&y *7IR#ཊ͹ji[!7Vy바uDxnP ]}V\i'RXIp"Pc8p$^C/9SBٵSW㶕e1 2Ry29WYiVik|wJ*ㅀ|-I;GK8|9][ ~ym%L`קs8lHq닽&p]*Nݎh)js?ޘ'B؜i7pq /yTftТ4fHMZֹIaʤ6Ơ't;d!% u|7\x,oLI'RH(HqԢ4)v-uYݩI$DϬ]$>JrPrJ;(GP0U hD) BNW3McDeu,#T{8BN"~v)K =݆)ke-eRjKZK@Yvc\6hrfeV#T)i_Z"*QZ JXL%ϝk0&Kb㊙6 ]NX|10)I>p]*<!}lS`|}}خWpJOT{^봺4+X1Ww'~$BH~xʼ_FWp Irg#h9JGBڄU(vݕg9g1I! ‹\/!5pNXc[%joxE)c>;yAY6bٛiUR&V>D} +='rhQ|~ܡMd[3sVO YJ5.v(.T6uE$&_;=ɆPLPjn5:+D 9?i=' zw-OErw0z,=SAģSؿ~.Q WT֭ b]+.$Wz˞ [nmMш( h(GQEjԝZsw{= o!%5|@o\I8+%B$b#j٩%ڻq:"$a HêdLwṲ?CD'a49t{;aMn޷?4[x` 7LoMe*+rS[ "\hЙLd}ߔ+A l!]*c)75Fi&2(\cVgXz&pqRGQGY#^=Xy?胑) w9-ěP=9H9޹+hxE |lF%I?Agv"vs=cYl5„\|~*N .9&j fFZuF.؇ⓄVqĐu Z8Lqxګ'$p)r)H&ޝ ΅{8 caN2X9spNKy~{>r@wqoi `wxX]=Q+KYVô ixvpj$V.V뱢}R4$!B1lki6<ͣB*Jf$EL!3p7g"J, !U5EԺk 5J&`5(=_5Az=M߇'ա[E,a{?.C0I_zFpk'x [U !5sR_8jp%/hVA{Pʋ+[bTnA^45qe\cieB:zª`콰E{ali.DA=t}Qumsk%Ũ*왋#eJD0 Vq|VHpYʯR0}m!P?!m3y3ӳ ؋YG=m:* {eoYB+ԉ6c(j&* #Br2=$EnM,N+`)8<̼>+4sz&i(>ՓA2lE#ǒz3T &Jҝi(*BCZ&=fݚ^ jG٧ B([*j~V&+nLR tKQ{.I]:LLǭ $(#;pyV%C?^.Z`Pd ՎK;7â&QJ oC xTA2XV n: /64}6Y.E>K$lKerfPȳf7n xr [ (^O/$ HA?}泒-;VWϢbYM43>b =/ |{k%u~@yl.R1}jrtT-㲛ͳr3cVa {fMJ$=:eAXfUxM nY),8ih z_(/PE -;q ҟAی eI'xU,e;H2 R] th`M!`XYȎ'k& -,Ro]0 t[ĭʨ>GĤi [`Gpmi") d=cWR&`!0{ms9*F:TDm+lc _xT P>Od3c d,6F|鈔S9*]+DTeD1|,nn+̼=~cRq-]<ʟnIR 3 Oi%Fo Bm?ic -pJpf8B}RlѫvbG[gȊhܧT˄]Lojo WXZA!Y?=!!) ?ɜ`Ƚvށ4mv]rhNDd0!u $[ׯ:@m 1sS i%2/[]qM&`Ϣ8Tb<"Epl᷾׹>cв[ji!O;gnIJ)+nzZd4Ni=S@pjΠ|\S9ޝP2n#fO_aa`C/I@FSZ J }2HK퉭.ص,0 DqĈ14wNF ΖeiR`kk+",XB [4~ Rf78&W~yPvs="5w9L.KIҠW@ # {猣 \ ] ٶ%79b1aiӰ:*0,5b I:nhqp&9]s/H&QSkʉPOP>#X@_&7ɉ F% +tD^pf m.8_*{> Gxv }It#AKO[e N&}4z=Y@H4u$Hi ?MZu仰_m|!˭L697JJ=Q `Mt$8[O  Pt e RDJ]1{r81%j9H{ɺ uvL`a&ѓ,qqğC^b9F3s\K_oh4 zJ2,/ܚ' )(x,gro7߃x, &OW<|x<ݥ# br J(铰f>o\0bDӦz:Oګ@Kco۴tFW$s& ɭq&JZ y 2wER@ sYa~oۯ,ődZƘmXQ}˓CDӱCaEҾrtT0ˀ%)WXPZ+ûxtshQgH+;;,k^ q#N};0*@0пv{CJloz:Ea#1j'5:c34&g^4Z[f>m3L YcńY`*=Q<+^qsT/nX6Y؇p`>C.RNYp##qz$%_W쀄IEk.}~F~NJP뱤UӒ W^NZ8ܱdm9Tݒbw}x~_aI3d|u/>Cv"KwY(5: ;hB؎j-SnjdE;*Gk j>^f嵾Zqя m%?/Dj1\vzpfWw,Ys*FUGsՂ~m8_m%ŗڟZEFpbeŃJ RZkpb_̝]l&8&(ay񛟓:&_?z6\"j֠tCu v.;~55㌉F? y-u2F.7b1sLs MנFZ+K-ۡlBOUC!nӰk>v= daV7-M}2pn}kؐܔ*!yߡ73/X >Zr=i5:XÐEGS.>+3 /#=͔=jS/{sALK 15 C 'cs!b{cR'jW>/se" LK*?Shx1Sb`\ x yga|<зO-*%"g ZYVz2_.A0H{a7XS"CTm'k?mPћG-WYw(r #{F|zXMNyK( ]W5$-۟G(uôQ}$rN?wT\J q/;%Zw$@\ 0iF+QXCR"mg\F3 f|Et^:wvkv y MmiW bs)Y}_= Sޫbt4aON%Rm>߲m*FO&X폳 (Vtj5ݸ$A?(g"7 x71qoC?Z2q 0XaLsC2vZ ֑hq_%.k+i y'HIu&OL9w `%QΊp;9 *]:× \|`e8(<zo97{] ~YRC; $&%w旐оz: 'KY\L8@NTQK!T-:Do^7&1Ƞ嶻7Psڀ=/%+ _%GSe i3EDq/ex.t8+YOgќEkvv \JKg`ORUZ9|w7T#ܘeSfuTYn:p%*,$.<(B #5 ?{_,) o\+TW. kcy?Sn?gdFU{0P e፥i1e_Ϊj܀:csAHPK{wɅbP92kcxχّN: < 6:xYirWgq"ny`⺻ʄ]ڲcN;D$?2tD.ghv#m.iQQvHӡ(;u>'"Bu!HawM %nV3(?qMu:g (cR3^.%Hd)D¥qʝv|x Be9AxfvJi?]O3R˙slSuP%qb7zC.ygQdLi񴖛oU>e?JpPs(%'*B@ƪ/ .~YSxXИk%¦ָq4L4|8u#pKy}E3q YzՖSEHD|sT"}DoZqk\V^ƣΙM%mW[q]?¹3dS>`ԦpЖ4s$IҨ.ǡoq 6(H KZ+,mPl*OF )̾.s9LkCb4  ](+As{B+Xz:av G\y8bBL $Ey9NBV3dR; ]jaC -ODXAۼ* @ 798KOo_+hE[1O9,_V/ !˕"X^ ~@ڜ]K3+~&+PدL"=(= H=#>B?r%z-DU7+09^$ :$䵥rOOTxKGBPޥS4ܘk ?q8T ɪ^Cg%cMRa\=!A!.>X.VP7ַR@L>XXh98zT tC! H7H9㤯SVV-nѻU{R,OL#}yzxkԳᛪf;slq6 _?6ETf$0z5HLe Xm `NC\ >fUR[olҐO}!LѶ\Դɔ +Iv QT\ :2l\15TݺdD8I77jF =}/f-or?1cL%Y^&6<뮊 ;Ӑ|.Pr˱/JIH@6rq?`)xr$C<"ufH{U"S+! Ĩâ[3 /a ӮvU-m;e ._꒎ԉ^:)'2ElOQRq nBͩ0ρ0a SwpH. 3E`\jӧhoJеf.fq߷mZe |'Rd^  IJTڠ"xZyԹ7SKwvHSЮ -KD,'M(j`Qf`:FY0v@8 7a{r֎xv*nIE'RRǗ y =g_~uZ ;vf J.$8`EK;?vjk 6<y',0hnGp"L0BZJ++-4ךOʓsl<2Ŝeqgzy 0`#z8' )1,P~(iy&jJ$4p#L onIv;Ex^Vs5GBmiV(ZWǭų16o eW_XZ؎!S{J.QՐt2-fW/T)cIvݛ+~"6\W!Q1AQӌ/bĈ *52w:Fk|GN5AL X8-_ US#$#V}ZmhV#ߎɡ0Ns\Od8"j%bf43;#>Yz wGr rYx&y8[)м}dC'7[Y&_"!gi|oZ/B/s=b +gr0hyDx^*hJx`yt;}Wne}z [߀xT~MmːsP,izL_d8|xuH¢҃BiLOR_>T‰c Mؽ{٨'Qֳ@D vAr!93 c/r#yAN4m(%99JtC^k\8 v !S:+(]͎9P>KUy%MvA&XhD}|2mւ?@Bj~JW$PxLDkV2 Q].%*Fw-6GE'.? %|mL#.Y0:/$,ziE 9c֨ن+ce-VZb¤]9+ŝi97@ 'ktzy7PU⓫u W63;(ÐQU0J#E3 ؀+˱\)\L\GV=@$F#Dy7B_s @|7RUp MF%x2>J%>KpČOI57ÇzP?:KiMʴI[$`QZfF(^8-A@{T#>d>,[T*ਜ਼scA\I=qsY*u^WhPK<*%YӸ_,zUuז ZkUbŇ-`:m ӴȈKjɸԢAW̄ʪao6-^I?M}mC5Ψ|MnC@'05^%J>gP3Ǫn޻2='1Kh_cVyY?hJ8*_J1! zTR ~ǿZ寱:Sgb{ H7k0HM\YěP}~1MG/;.k7ZT| ԁWJ/!㵧ҬMRCXPOa:dzδo%YAp/9ߔмBBXӀ:(o 2Xy?F.MYR'(';_c.hԠq<| ~߲'?X.xtY|+}1W _WygҧHU)7 -_M0J]SfX*o),F<,eaYձXVYy{&ωG~ڞ7;Spg8q)~߱a;``UhqG4hsuD0ٸX^;yLۨ۰]ݺE{UtV "ّQb#|ͩE9K%<vPf!_ʺ':N׈wdخx4l堋-0e%N'82mxUFHɱԽ&"_i0g~W=%GE/1|(♭Q?^oȖƝSxV/\1JCTA`"βn؀J|#$< {IfJms\XE>Йb=rs (8XYgDp=1=REpe'׏yk\+NF>ݵaY' VpXݲ3!->3ЩA|Fa<}%,n?p"w681D nь>ӖLaxj' Bx̪4n/;Xo,q?ݐefbeXXwS)\SIM [0B@EUwEjɧlq"vZ]016)PoV&8{ *ey+wv% Zۺ: Aɓ;LA%bkDrFW/d4`.\0Nb1p5B7zr] *4i1P8y.~sWyfYgBs}yVSO$j>Rոn~,D)z5ԾW< e&ȎYVXY Yv1MaR% wr._meJ *):Sg\,Roe2SWb;zsNCG^" Bi(NL>iz#ӼWlu,b ze@8>_h)8VQEe-ruLA34rC -PQ)X 'ʀst!!?UzC@.1hfH^AJt4VP\hѵSU ,m̮-ܮ'50EW өRcWfjGq h덂CZoQ K/72<@Ě]XbM҉N= ?hė f[iq16eϱett;f28vyޖTxШh0nDYhɋ o8S鞈o-?Y.ٜ*="Cd\5 5Aہ@sne{TH>̄ˁ'ZNmc;~,4U/Q`56೫OUw}i"U{AC3/X#}{=xKsP]ޘ Z(Z[{[F0y9bV4|#pfaEoer 8|lз[OIO;R>IL5Yaҧ@s41'?p%]&HZu q4De}ml~.J*DH'1z^.h]1bnqk[DysY܁C6rfg*\ ~ZGc\({gq%bpX:BpӒӘWhQ =N ®L<]ZHnZ@%NϹx%"ʼn/ĽneBf,m+L.-YpXP4|AȯVr=EጺJknYsX<<9 ߅CM> 5~Mt} v8V9,aUހ5Zr]+AIƎ]TF՚}SɱYY(XVǴ?TG'TEb)83Cl%7H3jŞxm U2MqelMnRͯ{Hp,]`q2hB'[DdbIħ C vsU ]x'$b6܇h^!M[#dݣKkJf67{'.XPӱ=g`tјO ЧN}8DFcykgJYx{῎_mzPo][kӂb V6.;nܧEu2(JRUAZF]dE,k+qbA[]e (ԇ4_~ ?R <&eeiw29pyOk,:UsXQY:=Ե,|4'YjKo)R}ˋ4i4<0L[( FƍQ3XXcQ'{bkN/S]0R,+I 6(o2MkC@?͇h!DEmB5!Γfb9$npV |yyn~Lò>?y*Rv)X^,w2q$vȪ]c1sfJv$,`F;1E"w ,xA̓6ni}6&tM< ;n ;y PbR<"4Jī_1O&|YդR> @|5 = +T rW;YvˆfNj;B3ARvMb ӱu2c0&l#(erPPgb׏RaVXe9fWH; Ba- Y:6D.VXk'||cT]cF^qxyrpޗ]d]iiH;6\z 9DE]@pvڃA~po9"(H׋ZϞܭjU $p OcIP5(܍V|)DEympCy߱=SӧÜEy0cc/6A.E r&^J2$x?UK$i 헱{@ЗH/eG._)mG\a|c8mSZ^ Ck`uwnm\%ә@"~,X^k\i-Jcy't︽6nыD2$vǵsNynLh﹂}%?CuEg yGF 7jS<. ]xukĔZG'Ejۮ]6l:&< yùoP]uza_.]̴9[I0Q6Bݡq‡%1/hvƱ&ڧ,)|0Ƌ65{(YA'>sS_whӴ+xCnikWǚ/MARBp:|%S!sA4!ߘ w)^GēZU]Akqx9#t7ān}Z`ҵe@O0SC!- 2wJsEL2-*w-n\|('b.C[-iw%7]5#DH*C#C }Yȣ2n&{ńU-6/{*mЏ䝸"Wم:"ZcՑcԍG2 [/9Fmb`+8΀vOPВtlѬ iR|_[1oLސ?0?XW1jyEh. S5kK-nmZ@u M6rR2, Z Hg 53D,4:#qQ?..|&[ ϰPs[>yi5%)d4ty8~#hՙlQj,6bϑF|k:e RJh!6T^#D Ćh!Ӏ˭Z 犓VO)ڦ$//SxO1^5[<&\ HtZx~zM.^nHG]~#)Gh^5SUKq:%-䛢q"PeHAzIÓ*&e!.$H-' [ߡ˕V[Ah7cyVZB^?.k/ؕY+|8oA=u7)j5l?_3`z/)2;և#d ޫ'eX\V=9$*QHR6Br8d'96@N6IQ_-JƇ=2Lxh4YH7-E?0$6rɜ ȉ͞uSdǽh09z 걻f3.{0K"಻n|Fg 15Rb2xyEI/`g-۪ǀ5LN&C�W6>TG?Ln ؄N7ofʄ[T[s]P =/SU|CZi߉w,(l&m an>6/1Hy#%glY^F02x榹jI_cWĨ*fzށ>uh'ΙnJ8,Xݼτ:lƑӌh&G䲔: IibY Wɳ͕a+c1w(lWgI*` ؈_fEـVpI5Y@: t(@nB<]gq;\O֮djt:7DQ8Bnؼ<(xYI5&c>LRuX`3b2ð/C#9&ME~4WkL$7*,S.YaBb):-42̌Z)E<^U4Z+.5Nd#7Ƽ/k' 闀y+[Z8LY2s5`jdZzo׹9[pJwp{94¥s?o/Ą+ CYY6Ӳd"u)\ȗ.UЫVmL|w=' ݵ}j p88teO ֏tNϱ\_S /ڡDA|+?jyQOc=ץ)0Yh,dnn;)S?%A@ԁZ/h A; K2|7͵V,Ќ rVBkKKx'-|H\y7 w/Seşo8eX41@@ȑDLfдS{r'oKՀlOnCT wSJy/h,*@t.w8&F31xe:(x7S*sap4OhB!ҫ r~0s=8۽.k;@^9JV_9; KpGj/TzG H{$PaXzu~wMF\F {p!«l\lN2WHT5  zX3 !>r 4hRi 6QJ PF3 M *֬3$Fe w iląwGX[dv >v,d)ڋ!U26b`N@Mä%cЄŧaWmuYԔ`dnz`9"?'&{uGReRw,(Ӳ?&dS,F+ܠ~<ܯzcec\0X9}ޭy8 N3rC#s,,ߝU<_yY]'̵6K=],AȰ`6ɖl}gUR:3?+I%T?մ-}1H7xJmO׫}umƴDu=:sp>a&!_6D1LrdH-y.e!a^<|q @&#- VIJ -)i<_{٘Bv%WޜNԛp-wfw1 Pcx g0Ϭ١:P1Ev ?(X B1')*gi9GhQhX ,@G<>%t.csȳ(ID xw tS>uObgNuor25_NZH ?E%,MMB~´ h'& ]o!:լ51sexk^YDsa^:5ɠAq(mߘH9-W6zw6-sD5<8nD;&~iswAe !7sĭΕ.ؿIxOqjdKNͅ"Ȇz$IrDŴ,ppt!/@J&&*V,&&:ozrwDiFLEaO"ŲBANi`;lg-r|ql, siK$F8jn P]OvQe5 8Tڛ͘K@WGk{sS[:s([SY |Z$9g7[A{Ȏ8SHu SoAn-}Iܼ3GCh"3zŦ"R %}IotgWmv{ItA7˜Ε#iԑ 0Z]?Yde<_K/e`eGr>;N{]6e,Yb{wT I_#C?݌%FS@[R $C"|q;AJL[Įi+j$\⿡]J5wNe۰t.+lf-:1 `nHDs?jP""K[6x1z^j?d|N>U[yΖ+FotY>~`H_ΗI$MY,S&/ޛK 2`y=y( x&WHM?@_3ٌD&B=niiIr_wSreBt~5Hl(߉|_LPF Kŧ.E&r0&)".%)YD|⦈u3o?/sxgY^F*NqKnkEn|[YE_6љ$)J2UcAq% kܯE ;8 s="krBƆMzdH֧L9q1}ېadC]'l]xŤMGaEEW|kMێFP.%@(x(nj0VW2qv\"glxR%=ggq> /3Cz#`=i\h>ӡ:-[ۖ;ZQBSNX:?:/ #k{+R77yRZ=fUŊk1qzHٹ,̶?ًNCֵ0)gZ>2цgDĠt QxmJ]-11V軆jxEk2Q4:7U/B"bOS vXuth+:dR`љTw4E]UχVM*;X3RqeBIH l:o:eKdP43/.t%":.jD[!+C*I ^K߷3#_bI""7`1}E~/MjMxMEϛ1jgL);]FbH׿&5h^A 1e[1 zJEӼbRMY+֎H`kP^neΕ 3 Z51巍O&?\u98 as𴣒 Bmtwx_;'ЩHv;@~bt周ȖulBTՌy!,,'5~?g@e9]Ma%oen%՝~v~KGm"@nԉt. <>pό'_Zn#F3AF};!u|(6|_ '҃@k6fz؏r`70[Nq} g Wfֶ:QJi0b:Q@]`:ZWI+` hq.Qp}{䖦~ +Gےpn f7Eh$GΔaKJV%r!vW.釦1:P= %͛`ܻ>7.tS=BA8ߞz(G@;+"Yǰ羾I'Ηk}PBk`%xh8 i;}B2"mS sͣW ݌`h-= ,\: ilFCX>f U,;|!?u&{, ܙUIE&|84?ap]Mtm̭'䚰uz:CȸQvI^ϱ`2~W#kq5cK,[U]@Ө]GItotC甼DU?f+cd>!PYsѱq6r cu% `3AS<% [M_-kgݧM v>N8 qA{'h%Ӡ߇]fvOy pf5b},$R ,,SJC{ssTS#"1B&69g>kŖ-hIf.M|NFOȅZx H({)1X_aM"AuZ2ѩ<^#Srpg>?Ffz3Bpµ#Ep@;pw A=>p1Vh 7l qz(ک0G F (f`]gݝ L&(2X@.7eo뻲T@;zf8 3Wdإw\`8t&_*:-|.aRӽ90_8|*A"]>f҅\ݗӰj֕ۺd̫$+M7ڶ~EQ^AթFYN jYC^~9<Mf%?kanoeUB>:me# f_xs:;U'Hqj Fd*rQj *{YYee%L00~!GMpr) nrnzqmx-jV\QreV?.JGڹnWj%XDLIbF)pxT Vk~ajфU-pY T0#;+Oj֋NBO4cz4N3 ͨ+)ԂJգ,_g = wʚC0^l^0 7N3z:/IkfZjoy)T_>w["=fH!QD@- g# )+#'QZh:fC${kwJ|AXL BMH6h'E`ّ/Jf4/8֖%ҘMϺa:y@wЧ7GTy\Kɑ'u qe|R lh0{a= $2q Py1(*/{;}a#,Ƚ/bQۊi؝ EW]Քz`}(9y.%r"51ʦeGpaKzcbTbR~>';Ll R@!s) *OWa79F1NYՅG{x&j^!JSpv8f&ތD '{?>TN@PAC$8 <nHLmǨҭ??\cwӝ$ak4pa,AW Z1d䔛62S!~?ӡ4m:^=nr?5c^hq7;Z喝^+׹w~GTb $Ic0ohJjqG{ A46lT5G"cAjTd Ϙ0B#&/_ z_ otE!Bxĕ#vHe9S p?4)D 6j=WK0@z,4jOB { yЛR\@p޹E+wKIRr`}ԓ>EAe #raE7ڱٓ"?qȌZl̛ȕ`m^A_mgb |6}V(`eY? ~Nf_+|tksĉz?2nWZJFZQ2*i^Lj_1Pן5<6}>M9G+D'F+8?F(_MfM&PXh =NleIpl{L>T{܎$V&ͤ#k㫰*Շ)4!mFDamP~uK;ǭɫt;l^cd9emRPֈTUlI'@Di`ey8].Cc\m1q3#۹_<'xݣfg}\Xz+Ys"Ġ>&P|ĵ=&r#_oOSi@J!^5~y.0~zhCKX)^<'/pcF]YO qD!j5Ѽ«&vP@գftjuy8 q[Z頽(Z@4@ \,5iXY~a:yyvJR-D2,~Jʱ(7nJ`h>+,k2WB[;f>5sw>2ȩSdk{qsN]Y5͙(LNq>vo`#%Y/tpx*/rn8@O;@f47i whxAJ~!ON. 25 !6\3pT'uiI DB+S)~2'x >'?8"pI*JBYQ p{M~Gv}֐kIuuTH#ғ|\PZ;0@/!r!k .sV`~?z$t “'}MF:Rѐ:IL7Ơ7#xռ<-Hoq%=\@uxq`uǜO|m|d_u/\p PS :R8n!5s)A;$].8㼌8g丬a xԜ-;G=`  ӂC=RRu(l CdשdHH܇H6[HOzć|k1V=Q?0>5F4,%IQ:OGU(P]12p#Q=_!BDJ: ,u]v1c*sgu)砃-{i$'6%"\*gNz1#sbFu9<RЈ '$w1O,xKn`~I|6{&"YыГK$0<-EsEi5awHhi-S Ă)MaRsЬLY[*B_uU:sO&<j 7 ϼn@)yYe)uoa<3 _:k-{ݙcYاzJ6>%a ܻi%]~8oLT 3ޙfF|ttj;rwĤʆ4n`u&yN@dv`"QCKƂt$QJ>uoDJy(*B"2B+3 N 1^V*~d4r 'H)W˾:B86gTkZg%1H q"Ԟ%Qivn}b$p9! )]; sDeXZe 4TETԱVʱ~I;x LlM(0bF}Rʟ`HkbIC}ŀ Փve"q cfK}rpp?3P U&Oh eT;xL^dP `9_@7D;d(zt>660kōv:JȰkQҭrXg$*`flꪣX8bo=hc˻ͣ\U)[tGc G}~p^ }qv%xbGz A*/g右IǮOL/,D{0oS06 MXVk ;]nۡh|+8,TJ7~BqEy[N k{A5>e+Ǭ$ƨly` V-^ p!c~ϛdun+o)"0Aٛ=~Q-F!XoG/Ұ,vb/B56'RA#P T|piDm{Mj{,Nkplݓ98?z&+5\efn?٤D W!7 Yued0R౑*rfnie Nߦk;烐|ypuKQ~!9ܯ".Ij;#dS "M . .ZnhB$׬d@t;'$ۂ,I (9Jep.pfHT1l"BT8V0̡_j .t3TH}5@XKv=.n 6=GP +Oq0U,U(+{[it0 RT-1}oU )Є5#=S׿9/`Yϯ'L 6DhqLf44nA}16|z9q2?=H]#YMs":گ-P%?Qn*%7:6GGq^G)pd{In\ `aU۩ѭ~+qQpP9$nAOq\F#]Ұ/{]:G'oH%egSwCyvH2̦x ]_RHiyuH_}_ $9{}\y2H[FnnJL+Tp@kBK`:ERk`YWز kKii[Wݔ@wQ$pqn(+},M~D X73!&)J`>XG?w</>wETu0D _ ϋj9[^Di{6k^cUCi{2;W87y伝/ /wØTɯ4'G"*=zP]\=; EM7("%1Lږʌ)`)-Ӫ7%@ʄKrYLx?Kz3ͱXB a2l++~4؃y&R7H3!Vٕ3YLy.gxrȋ f.L{\Jluޱ1QIU9- I@{q5/πKuݷ%]+BHFcդL*?U󅽞 !/y PM/}&﫟)u^sSmj0~n])Rh/A];#(/DaKNgΙdC o gG,{ 0`FD1㩌;϶_vjⵁʁ} Se.r3qP@J m/\tŝژ&lTҮ @l5 tKP[҉:XUdM;9| ഛf{ AQZkɅ@!Y HMwLFC0wFY

'L-5Rz@&6B4~rN0V:YSX5jjĞCUG T1N@1hHؾiog]x9v΀Kp̂ -#lT_hN9‡&>`&+LfGd<ј?q^\.(Eׯ 0쓜ZUZ+ 8^8Lv1TXl62<)eq,)fH_$;iwĮGdSՎ.F%RJRkac5ӯϗ.BVƤAXkvX8YvZC*Fƺ&_)OsӾսy *bR:JAwz aY,7:DyU$IiT}2:}i!(!P_!9Oc `栤B'spۢ[X?C,o,e}1~jg4`=w^!jޡQ<wփeޏeE^3c|![N+?bp[ _鶼^OA4-!V߀Nv"7Ǭ依R&%*q_,։*qUl!/UsV HAGоkHx gNG| AN׬w6KF|yV mϒ,Ox6[$y +Q;)9qH=N8Eὃi9oK̍ LKhD/M+溨=0`/c(ᠯ8op `&^V%ZIvz+,H=ι W ȕBg[gQʌ2>_ګCM3^[m'2U( Zs()IRU«8 7/LoNP5uϫE;ʹ bLѥEC=VjxLP]U]Fa Yh0M~*(}8~=9dUib ,E"H2&k1r>VEzW IYa5ޙnM6\;`n0Dln-V_6e-בkM$4;rGo.T:)=bw$[e9ׂJ`!((E@Mt*Ay|imM$ ahHG_.IW`ѯaJ6a?y+tm.ܬi caHb„ٷ/D&n|?/ZQ™c8~m|QDStJ'ZRehW[Av>a rXr vck;g7Nnw~Qv w> jh ՏB='Y %(;;i58REZ!*5)w)CfSP? eZs|30}+9Ua*?X1q'(/}UOOqgVx*392!7uAD\fO{bW <b)ŭ Oe +/(l8;'RJ߃cuQQ.Y4JXu[CK:7MJ:(#;QdYtW!Zs2egZϚl+n0C=u`Ʈ%QBNDaaZLlw_j-~ݺ=+AOfkH6)l&Ѭ;b#;ftq}n% ~#mcDw=YrKCè #W\{U?o唹!"4-0-ed6< أ OeخB'F.Z*̴*rВVwѓ*O"t,eBAr_lQ7vS~ഔ)Dco;wgbd&}~Z$(V)7|*$w#HunՂ=ޓ}J1LDzC>n"-:{GK GD V]w */W`I"9FA ը|R@nr tDlrԗ>_/#%Wb9[)pFʰAoVrc{.pER&fݼ;L0cmϊ/ȊXJnlfԌTP#c^~.^牙޻ʌ5R-]ig>5J0?ST dr %C<]vnP2{?W7*#~RLS.:)WHgNKNU8EfҴFќǓqaNYfNptfװk05'תh -d us-`4Uzf$5oٝ\H\ L]ZtJG~ӑvw4_BlW0IZӈMX|7E!)ckjP6AkK¥1(M/L;3BvុNK*4GցJc":?@p/4Q"/l'1/qR 6%;_IgX0'gذj=]c_0%._0D5)gُӽdNl%֭ɍ\"y=Z(CSR%3mV.{X*R7 wgHCj74M\Ka 5f/6[8be9v; z Ugt,S<E2ޑ[f)%*Ð*( k*g=EOPaM)NQaY6]vOU&?ʺ)!(OyVO]s.Y_y|'UEF#zwTSR*q{mIL 5tե(u͏PZRK&X]Dr~V rd5a%gR25IѦׅ]WẂAʵ Ewi^=e_eEiz* Gz $HY\ ;%*dlAÒ-?UR棚 ;S%"MZ~S<d(ě^NN'[f9va+6AR4N 4ףbRg=ߚΉF~_P'?|89*5j$|7@dL9ɿoWD 9cP GAeTFs "Y5~/nT&x&mb`>]]vm,fS@9/NeS 5drfILXf#fF;LXN?" [}#ZґD[W X&bupsK>>:R#KKgn{Jȉ_+C/sLV3H8K ?[OTK퐮͹C^$ii@LQYa}˨sYRW1)*_/Q6qnp Lfx^vnBMc11L 2n<eZsnD5bO\`KNl#J(-&cn n06 K,o0I=l@D02xZM S4]nْ:!qz\2uk$7FƕR"dynUvQsp,(CV`cx$ƩkAc.1dQI-64JXǘT$%WVIA%q[ݨURT~m|FRY쀧l>Aܹ\8Wcs\%Dó׮ |^^#HEheC>ju`}Zã^{ˮjS LJ&v`:Ar0K4s][bb6䧵U7TF{]Zh,$/Fs/*$,D=MXQYTS|%&9ml,ܔF<;V?%ǀYaJR\ܸ%\>LM6 $Cԟ1h=gIwtѩU K?:#}w1=Z+@yu4zv6ݷ &DۿQxq Rq4^]nR9$-3廞 _=O(@+8 ͈}Tڜ`9coߥ'OtZn1j1nє:W.T(q7Z4WrZ'K*fck +=hiI Sȹ |ˬ<3 dbQ66˧a⩔3|~b=!8U 3Ӑ+'\w]3\9_EG *Gzgoc8#Ӯc}W,A7$Sdݞ@++@>lr( Ys]7G7S>ZjyT!QZx7yL#xĭwGXcseyqjoC\܎UJm%=V0绂=  spD6`,zj"h}`EbGw8S&#C$1SoRfж{,>;5rwFl܎۔&i Ձ 6Q`"1l:*NA<ܒh4pnw~Й 1ca8 )ձ 8$0.sJ1`6z)rmJ2iyJ|oWOk sw^ qOԎ)JCk49':qkXe|{jgT.XtCt7(x! ~1]zRQ+0j:Q-JULsE mUؗ_.ZI3:)#]l&pMIi!˲A9"!P3A [+82#W;~ٵW›[Q#+jSo|ۣ5! 9ȱڰBi8>@N;n}L=k-y? )ӕ[RD$<4 O# P*d Gfl-ГA2B7@?o7m(՗ꉇ>-*#rQ<]?W =@mIH^[e_9wEQ b잃GʐS,ۖS`|&)'SHC@绀c7B-TxMG=zgD|pJ;pݻYʩ9 X:+Gl=KzLk0-7E@=qh|;-m=\{fn@Vo:}/:hމH-#-Q3$mCN=YMo9ξ(V@5P-:7Ʉ??=3q ,lP5u>i5_̚Gc3yz X'~W#jWfwb/Y*]۪dWՌk *%Dq.T UTDL>d DhMdة`3X_oOLdB>9w\ޣV^HH-jS+Uy tX,)q4zWHBxNA "vpUWRue6wVZE*ª UCTt|% 4|diVWgIc\4ܺ> ~#%2l&O"d­llhF'F[> wnjwC G,/cAR4q>xk=fhIe |QN;cIUМTx]Kcr$)W*Wun3ŨmU8x9D!= t/B}poIɤU*3(igJw{^PZYKs.^:V i!m[\7/@>T.O'TW8ͫUzca1-rЖE|p*Ҙ*M%}d\8U[N+3Ij>xX;`"ݺT("b)r1 :5sNջ Ɣs0G dwSP?aρΑs`2}Ԟ$KSYFd;2l&tp5 `ͺ2 -/* q\He(/mc6vXSŴ :7G(6=`R^"*P2 OQ֐bcO'(gkm|"&ƂD"1-6BX&^WWD`Q);Yoirυlk/;ʦZYO()gvgNzG(y&`|~6CK=Wnj[^pT7]+*W>+Y_ɭew,\ĵ1C5i{09"9 PLUD 1 ogUC@U8WҶ^u嬜sfwm KL="5,S+ jȂ{Z_׶g/T 6ʓ!fF.5 `\5S_H-mJ .V"$4"p7=(G|=oo". 1aLK,Q1v~SNhy).ыOҖ>h$w %O$XL3Lg8` L6?43RQ!||oAY&Ng^:ɨECu$r긛+d݇*Iuª&IGmX1)=mt&F=-B U!RU5_*&}Ei ~zD/VUݰ|-WiS[u3";x*Bxahq32QA"Ҁ; E uZu maGİDJрSqr8PL ,l`|K;`934LA;gI&w\cY8|ߏwNJ@La_*RY!y˨dإQ2 u@vڞ!CkԪa0P:aXNΏ`Ɉoex=GxC R̷͚ AlGN){Q­ |d'RI$`l@#x89óemřG;%>5Z`Za#ThjVOJ=MN%Wwڥ)cfP- UB/KmTUL·V!~hsZS ":ǿVJKHucBnc mo %Sex'D&~ $cJA{+܍Z9T)r*RY )$fM")ϟԴ3YР?a0l_nXw3# IlRi\! !<%5n-w_JqDw2qR+|t+©^/L9XۈW>q¨%@@Vd~dߥ6ޮ^_W+PS5."^p0}d?&@uMQ qz7)?{Yij~}Q+WbmM/گ5'gVLJGD/0 D>!j4VO>u x7TU٤s(}cS'!73mV a u(Go;ǃ!IWM^ﮋR_5Bga:}R;~t{qw#ݠěfn`>:QT\#j<M;ӁF7zZrS*bM?ay)sϱ/\ E@+{)v[ʪ@ RSfK+s35&֩pN wܦp9G\IDpzpA8iکv N{ڹ'9ei4]({Su׳k3Y^Ht)kB:_5hpn{zXW=y<%>3`.m VfҮDՂǣg`[Jf6uBE#%N^ "lamӧ^}Y3R.2ijO<@S*+qLtyNC [T4O6xO8Uvu4f ` mJQsگ/%K^|޵?G+%F$ JOIҹh hY $ eĪ%s V rǡqo!NcRy-|=<={'H R07e&JE(O'\O" s ̤ vn9w7a+UamClGa߳H)Z│5E=#zѮt'fr\=K JR- dܣ6h9 l "Ua$-r^4g63 0RѬjOCw8Y+/cr=_h y#m s$~I{^=8G}-*NO@շ+Iqپ]"(>e/bNx 놟}ŝ Q6Tpmh&! b5tb!N!4w?J糔#Ü`r /:%],\` l /'b^B>Gui؀u)k0SYq =)NM5gr@g.IZℨ\bJsPsܬ3T M#=anJFs%/g#&,$Ǵq,t]f/ dgYh?|$AIw-z @u?yH_F:4C0X@#Ty-:o.j6&?v)EŸv52pK[QWB7T$@ЩؠUyaV ن;ŒĩCk}V&|*6B?<}k |yfa  14En2t0Y3DHD#UI"!@'rl Zy038t;J1R@z ==O-؊ѫ/T] ]liס DOd%FncF/|ջ"Op+"$GcOvE4un=chn@ภƵ0ydłx44Л/ÄpE ō)/b=${S_v^~B4*k2[{U~޻i-͊jȧ45DD9K03]W{@vp,Uzp(B"Tm| ͬ"Mpk1=g剽Y]Mm>*lʍOz,h4np%^XaS81ũEgwmΌ4VnEc+ȭluvZid @;^,IP֒|H͈UtO*7vfZ.̡ $_mNa?La3(G8p,| YJ*RmѰ))@pEr)WI:݃1()=S^8̍JgL֊qt&p!њn`*l2|_ _XoKY#GZ]yy"O_G*҉c,CwM>H=xm נUVy!XMvT%AWv^W)z#)Z0'|wTe'ǎRoVKEnw8_IYS t]I.9GgȿS8Jl9XX5BTA5D ɱ^p.]ߛ-[T f[|$D"jզԓ$Ť,8zo'zFF=zoLɊc@Y wrY/LF|Jo\P?[8 IcMrUY?+ؖX\۱P^|ظ &#+JҙQএfĄԲ`|40n0ѦtYGI2#p\YViQWF4DNa7jgc&r-ǩehZ%UèE#@kǃ=-R6fB;:sls}K?p.E.;L"a-Vugj. g!!`sWze?r⡈u/KNvY;}yHsM2aw_>JXHeP < ə0hpR;qG MDodFhmz u(D}Mi틱xZzL1KW.GVVR۱%جHxZ]m-V3rC6};n'A) ďP^[Nk]?F,ԤD^Ɲe َ:\yqFwa[clG@EY%RкATK oV=;ZڹeR *. h,mYtx- ki|UdbaZnLO LMCicwym_h48$;UGp/Z~^ gc`ѳZßdžƨw(CD*iƺ~QA(M`86$J~Պ:I3ֻq4ol00{{*!m,n*%EH \7zE&]c&P#3*\WQ7!^l)EIeƷ9bą]k@P8m?)zӫ|Q?uR*"e)ReKO- moTc z JБҋ BYR p]o@ U8Qm6vx,A*ϹC:!z_?z~PN1%V.]X=ǝu _~[$Z/tĬil!;*$bciukSxgx e^uu%L.%!OVܴL7DHGpog)U802a !]Xl G p&J #R5:fRA2YI-(pPVWtvD,p>N'DKrmE_*<#`~^;\. XV7R Nc"50,eRLY}Z0x)z8/ǏBoٮJ @LH=]a:*Q 鏦d12fNL0ģz x}$%9BQxYB6AЧ0]ӟ'ڳϟG.LIȟeǔT n|u߯$ƿsOXDf/k&YH盽U֛żP {iQozBhO6ɇ b݃A+wg Pڈid#Қ DoHwkAFVV\ JYaM8 Ť)Bd e]ĊHx&Hjᓫs"nd4ǵ_u,@m F-* ҂cVo?Boף i<l'[Y酣Bĺj[h͂ucOO*X.з;N]O7za~ĭ>^ 0 I 8hSQSB& ]*,;K lyLl#oc\ЋlVJC)DnEjBD){ X%$(F!9]8 p[*+APQ*ȍ W~vdj'iF?B"gukw,az\a01S{ 6Gp+^Xld^PݮʋޤM|5Q~e(U T} 8oOA*JoJ0B8 ﴬ[>E2U) !}^s3RF}%@W@RI̖9| lܷy9avrrZֶK?`Sa"*B7"plTD庯{q-/&7nK"q?U.)#ϿSZG%U Hsn;ܫi|8z".r2.(-dCyKff1I]M Rʗ6Ɯp1$E(Ҿ(zꖞ[{U㛠 /LJy MJӻ c&a-t U-=IFo(e/>#W4k:& |}>fn1Ɣg}FL:^WN(,4^If Wk[< PJl*ϐeҵ*prN5_<a;^CM R2Nl5nXNy sk#dZc#MAcѠN4dCRvdjLGA&\.>>nד2rp|s&a sfu6npmsXfDTn >~%KmtE=|ej%p֬+&f|OX"+85@ALؒ,zBFM[k=r=,T`\y Y+Q F>W>oǜJ%̿qOӍbZGČ?DyE5A2EH vҥ?dgx$;x&Q.kw՜fr' 1٪WC4qjF7UXCE)}uSGjq=Y Wv>U!BlW:GdE;=N QP ZD^9$Yo2]4=&Eio{DOixqDގa'^~nW|?f [w)h[dok-,W4ұ]z[=Vo00"}y?\k*+Ā6Y{c I^ua'Vh3OG&aMˊi QĢKв'91~-W_dJW4 B$xem-F|V`B Huh:(*펬JGpf!ΗhB 쮙2?Ċ*1kfcY JmKy_31k8HI ]%Gǒ_4Fp:7t('2& :CY i'8 \FGB&şT=oaKNKFh<%D0"'-`a8Ձ\-!˻`9Z9:ި&U{-vL~UVeE{>J'iɡTpE ht"xX |xiի})vktxv?| OuDz3.4NEb:5+pKw[J}wkt';gձqHEѴ(=8)قJɥ!˱b\sCȂd )~Iߔwۢ; Eb/v zeX,ۄM}ف ) *Z\S=E3 iyJm;Gl%ϭ,䄱SSJO%)pw?831xBE}p eB1z^2Ȍ&P @pi}r;tn ރ@WH> F[@LxrO6HR(%,}.KUGro'UZG# 7gf ]ޓ)] ,g#ԌWgvo qbSb*̉㹈4Wdӥe/?J?[*J#z*4<}?k禤q$ ˜D 4K8y.4.u62w Ee6u^h4SNXۺ5+)UL|H;l!yTzL:k3c`M;p5p}ґ("D3b 0H"S\|hDnaW˅Fd>̂0.zM}*4\Q\~?+X]8 (eI2zO(@FQʣ@3F%΀m_aިv-eCi:5˛$0D_!o} g 71#w|f̐eτ0,0&+B09"VS:D` K,iU˧4aC93or.ņVyu;/ۊ6 |@-8V|DLZkk)Kh6'fMᡙŕ8ClE'ks!:ݘr6dDHԋVDV\#sYWb+%fk4zqMmIZB1) Ȍ hɪUvB\`M!τ2ۮ@VæH:/{p-x up) SP0 7Wj_[>sZ#j)'Jk/R#q^e&oKHXERt~XW8J{1l%f.0Dnu3I^C%D#0IspuD3J赙kv(}?FΆ9D2^6u 8ݼmXX=$/aAld{dZr̖s wzDf )Bt^ -Gp tnש!]I(N[AnyS0B{(uhw+ń"Z퍊sC[K k,Y%nQOAZ^؟=weթZU1[47XikᄽgR709fB*8bYjOq/>eOp5ߒ 4G %P\}^>7dl|E|4>G-1~p=,"!92yĝ$o/ u+hHlp͊mV8Mޢlg9@+ {J RREyBlʋ&J>I>m>{(AC_`0fa>LK"f" PeH qM SGXcՇl5s=:mK,B՗& Ȥn•6 TQh;ָ*pQk]jfL24;dS:$# .wr~j#9|1S{~1s  >F`L~uTY)-g#/>]qRVPX S\@Ǒns{P/aXsVLmxfiN NY} golNY i ,6ͬf)&dQ^p#VI-;Y!ӭ.PUJWDP ;6n^:Mgw f}OHAOXk L%ñ/ߠb&\C\%QҫXR `AaFOO ¬QrXexBw/Cf>JF+EcLfM/_lܤG3$*ZfQt>s7pCg{4tq~)5II8p,M}秙|70VwHjh ;/-۞zcs]ԬK#dyR^I,2t^Ťw  ntѣ'5'^ՊY-^LDב@ y( ED'KP߀@"E ef %{t}3asZ7.A$&ا,rTϱ. J\g¨Ťc|4fHpâP-B̶aFE^Xv4o>R@3<;| D. !a.M;=r9xQ=jFeT[ NKt#4C:*C4-4 d䡢ɺWi|8K\GΡ7Owm.}4ϙ} d2TSwu7̻7I7PVi0rb"ZC1o|yr}-c=|(G=4߉c r!NTk0E1#^|l=V1|5fWey"lCoi& ZgPS6@ڶy^jPxv'$:xd68Ujdߣ/2DqEqG4/IEzK]u vC2@o&%nMN{x߼y : ڦA &,`$RX9^5xӫË)f(w澕8ЧȬfҒ~k<U+'Vdk6mۀҥm).1@4 D_k+a/wC9wą.(g2"V#}}}WRmO'FɱW|CqY ά8 lL " )*dSXCv:VǸ)G&Q^;` I ]=GO=gDK]zmCd}zr**^d+\[OuԬ!>QfpWkY\(?eUU(W/v;[,iTfZm͏AZB%;+nEP>|0EG22̿ad_x$ZEc*asvFq\eVS7,[ [|VN ;BMl]zOy@m`HKUܚ$1/Sly()ԩ Qkm(V!'&k q\DIGd" 2s4?7ZPN85xZBAWؤa0|RKPKvO_abW#" aKO=izh9I<^y m8!>3-j˩&N<<(|q8yݡ8YKÇp᚟P;l^sh$,!wZ] ِ.#O{4pɻ6Gt u ץ \RspUu8(/sGW-Kp^j*/%h`9L~3Y7wYG(иsTnl]+J !6IkQRu}>6@tB#9׺k4pJ!3!rl&bt92 9+ĦA0"WHA=l(arŵT Kke] Uj"JZ`˲QVO쯝u;:NH\1T;5 zk&F'x_"rp$TVj&" $eٿpHWzY]WrЛÐg#~!< a(SZy:C4\T&KݱQ惟.WKrcnFnpuac;ćz/{4JCr֝/e8ꐧnjy⥍VjacK?0WlLրOtc?X8HVqτ{2( qY`Ysed[>1bs,p H:<^=l"ڐ+2at}ңq.~r:isXCڢ2`*e:9DT*;!F*&N7KJfcc*N6:nS b^&hя2x5)%/iqx?P/o{p$ٰXLEwܫKt@heVBkc+y[tFʊnNK:\Ns3 dӌ{';UBFn|rwCv5 sƂΣ礚=#I&ApszٽFfc8WInSltq*M◜҅)Q޵ ~2qSӟЩ Qߢk?b6ɏ:s F[6ArlR_.C5P=U'LDţ=Sɪ~g}& 9Nnd.$T 7$fM>[0i3=E.8ֳ;us71 B4^s;MD2XA=PÙߢ\o#eaZ‹J*1{PG$>[B[lfʙ @{02Z261z$ N/ӹLOfTܺ[ )Qӓ7a,3]鄘جGșFc!s01^8-=f'Ve$+:k|,(VKMy)#6|E$ v7Ex[g PN[ݮ$4rA@k=mՇg<@h1%(@~f(|jfR'qz|["|_ C:R UNN5tdU!ܘ@Xkh5x21 `Nٹ^K3ZyI=Sm8Օ%߱V5KX\|,?8!BJ{av#-_!x~!tWhyGr |с0uɋ=VnMj#[g=̙EJǎwܢ!p؟4s\R@Vj^QUi}S!}E"p]L|[`'Evhu..kϺzDV[g= ASMyabMk0և|/"MRpkx\!l*;/3`0tWnYj6VLmՄϧE8z(Lgv ,4y=R;#2kSz-LsB1_zj1}[F,tQ 1e\]"I߹?hQr&;gp_c"g)*g!rZ:(oI+7Mђ45c8d]`9e 4>Z$W "&#%}Ǟ5j05f9m7[Dp8ft6QTQ~2kP bHYs'ugs^Σ$0:KW^uk57l&U@{P|٨ cccA.սĒONmڽ!tqVYnx WFLҠchg8ѻ^xF f o1=I)x)&*yLBhB wUZK&Π;}^,i5*XAYMF)5 e}1QxA0*Y7j?Ԃ\(B!b}t1 !84neWm?{TĂESP@"ě -RUi[gQ*Y8SnxJd6ˢ  s:ANo|[>-z])$jOՑk?5%$:z 1[Dz% iԳ^j@Hv/4AIQ4_qZunS`|~q9гc!EZ@H]jwl2Ʊb8}EP Fl,V~o`Z(0.p23xA@L,W9e/<-nGMG9R+Q`%ڦh?Lyp^I0 3Lw 2mw[r&oM{exXoh`ӡ tCM-]e yFY*xZ"k`C .p0n*߻|A50!N,;*QA0WÙ|c0L(=]<3y[Fq$ȃ  )CEI')ΆgU S# ;hGh͂c8BVom$w]S>ɈE쎱*:O6 ~fXkVJs߀Dt&[[T,xy/  PF Pkpiz(!TZ>ahVi+/hQij+_ߐ6/2}O|4wĂ1Дn?\k9h?'(/mP!\G d@3pu޳Gޣ*K^Ըs}(#i]A Ѭ[.lY>Eҟ.R4`*@r ZGsKsɹ,2^$yAͩPɤ~g 1AJGj~~ϡKCI *"Z184q}Sǝp_4JYS7fAKR[k-ƏPMRot fɋrȒӫ'՚+!ϥSGՁ._yO*eq~ވP ΄LBF NZl<0X᤭ߡOL&‚vb]tU8ҨA8AQ,~y/W . R밻yɣvH)I(bv|$nN 7LO+dm\Qldr[CV4G'-+U$ӛO h0ǝ8pr߄ijgw.1&vDD7X' 񞉦 d`B_3f;o6tB=#HuYQ(4?\/֯:U g@f T n'  J" ,_`.7 "l-1XRc'ru+Sͅv''X-\ )/:ƀc @r 3:ywx]:05$y[2**\  d}6 u\ۍU9r~E6|-*:1תvT)88H :0살ɖ{L<]mHs1xz.M#IvFC߰ v/I1p6*Nj6eAZ̏!J LƬ 3'lL D@ 5t%Μdl}h}[Lu!!uYr2%}5½fK̛wHV<<< J/}a`Bb("Hew.R6W;U`90ZO7򌤳qnPH#~*v?'7zDveVya@~jm$: $ ⧖h 6[[r7"rocSB^d6 oa !-~lKh{ADH*Ҽ_Ji2*WEz \[\ʕ(<䐭jAK?"<~ ha^y0]&jN#zs$( h/Q 2ZЋNƘGP Pylœr`6$a%<۴VlpB|Z'Ӷ)f*2e7:NoR9k:ږLY>ao8,ߌEfԫPwnЊJ2^nPl) r-¡hZf|l8K?LJ |^%&1{2csmԆv֬xu^|/畚bKwd GӍ܄f&f+U`amH.ԣhNvyfD5-HTjyWҜO= [x9,x03/8ZJ:qe1o 9j%w%SP~.Ix|jjI߱ZޝC )A_!W߬1W7:L32#n6F߉Ubצf޴a%9j`\f(F^ӵ}c,gK&B-&8X^e"@KCmwb8\r/^@Աc@(@)|;6[gC &*p8>V\ȅ Pʢm( 2qX y \b)8g~Q j48w󒄞9AOx%=kdڶٻ#'#z em5vT'xikdMd+7GBK6Jn1H/ o"PE9+*;Ӵv^ ZN( "Qb׏'0(2Oj0 o0.̊!6z库/~e#-WȰ(i n3H@j(EYޮ y#*CS $E5bk> j`L1uytKsCB1C;C)6eEl; 39[˛c(O2p\N''Ö)ڵO%o*Cػk]a['$ 99/ 3^%\[e3q 6ħˤ1H Aov/q𕂪]Zv G!v)E"W&p93!uNYRXغ iH] jN<6LXqp|`1Z}+lLwCO+*4O6BaBJCLIeQn:돷fC9"Y}J(%Ӗ(=r"w/A?1ugl# 2_EǐEp4x8JWxu\#A_ {TTZ{B  >MOwT7 Ms3iDj0K2':D7𹱲q*PNqE,p|a$~8tEeuzڔ@{c~k:Wk 2 uSmvYZܻ"ߦx7(YukߨV{5+QKjo`:HXPZ? bL8"Z4/ڱE}8(a#.?9ד m}'D`Ȅ 2ԏ?ĕșH e 4Y[E[0i."WLL@V9t;ZsPsZ"؆RO|0eh{#< cS@V\JJB+x&@NaIzׅ,)i۷qe`JL;qv{YlKZAhtͱX̠|qCv<|SoȷyY/f-$jOL t/+OamVSW}4گ5ʚ.],.q$AI PU= AF L05WɆ'^ < BNUT78;mS#RCA\UN[_ 4u`2:3 ,-^m[~t,ePQ?;Z?8'Jfi=qĻUC^Z[Q+|ކ5B!E\/c{}{4{7LGh71S~L*VY;"Ӯ#!^jbiS*%Xfb0c5cv|1ݳW$xwe&9D[ (2S՚;AGj Ftc_JLQ*!<ˊmߚÿ6 "Кjfc+?w/#,WA!TO䧕g˳4w}w _ۛtN05%j;'hB.]C437|N(|@П BY{/c#7%؝M*=NxT hS"Ps2WvO6 T5`X~c6i"*Ґm$H/JhkR޲$.pXȆsg=} JiJrugji1.!L9i1Z nI1̀(%%WFH&6=KtdCf@x_J F048 C AƬ?!;Jg% çgTXCӭ7 Ft3}~vM& |M2P8+ո ʌ#aV*;X'thNBpmO^;[6:k}1!u w N"!)"{qF)88-=:/JehR)5;v}(lEVdhOutyW8pSUW1ܙr:; hXW!$DM).mw|H+ÕX 5vΗU7_pM6w*Y Wxa+]&_5yRC)ߤ-e#VXKT".-NJU-m΃핲SÌF~BcgZ /vL#^[\..nz$կ:'GɅZ1XӮ`SmZ>zg@kG,#F&3xaUԳdmIaqV#;D.b> =RCg-M\IL{1<ݚ7B a{Զ l1yvɨMEdcœ6CMҐX%JmjǴļ;yW>V-ۅC9q`riFF?%'І>9@/9exz|[-0dߩפ$% { "yQP/N[sñ}^Pq鏣ʐ>o\x*t fL"Xe5O'טqbGgr3VJO$d:430 J'qcҜ}od ILzfʏĶjZٮ\[3w|cB9 ,#1{!;]Z̡[CO=N|3T/'7>95N5=p[F$xfgJD'l}cE@\%ؖ]atGrpiu K_L^Slޫ=7@ Y?MXZs4ZbzKq=#)|1l i(|;#RӝPczZ LN&%H&Qz~;q,g^EEw Ks N%?MyU}. G#d(^#)΋ ʶr'Am 2Ʀ%,) BZOK/1!Lw Ȭh۔sӰcfkC~ a>NpV @Zl71&*HHaH-ɭ-R`[^ u}З;x\> 9eڹ}V!nޢTL= iz";^X4`gG]B5eHe'zlmW-bfǗq-ސUjo{C:B4-A`QB8CxfzuQW9tS#y:@Ʉ PmB8ye8vfY9m*9wݓxG[e[oHhRPX?A[J( ,n+{DGz97bߣ#dOh1=iUE 'iz!%x*>n@dc7n,K#6GkV@!AG>;"K#otH>w:ﴯ,Lh17j-J9q$LE[A/GE4|}u&1AqنeklDV[ {U>UqpJoD^Ywۯt{~x9. Ϯy&~ L\s%b</ J8"SOG)*Kh:[1YwnP=oUFR{WW*LJ! ƈ}b9wS]@셗 4MA#n^zãVXv{;ؽ5l)G&G(P NV \,v/j*lB$ڸJjb y;*k?ؑ36bVۘ0c$fnY%M¬Tz/kqk9MG$04w 'sgNf@*)E=嚉g)Y['ڗ sn&@8$^&pVs H@WKLLո9@l?47iI =J²D(}C0b ֹjKG Huo~V ! Sd\߾tAs2 Da,ۡ=pNx3֮-? YZ