sssd-ldap-2.4.0-9.el8_4.1 >  A `U]exHnKyzyɭ4~7 1|M"pb[E\<1ߋwݴNM2n?EL4lat)c0zqy"Ḁ˫΃V&:?t,!v-z'F-vRZׅx8RnTw#|7`Yig0% >[]E&38S0X Fɧ2_g^!׍ BKt-,_/遴x\lieKmӀ֮gɤ]+ Xoj ©p Z3BQLY7'7ʤ@bl/HK*sj7]6^U[-VoRG<9Y? +rKp "v8C #VmlS1d%mߗm|Hmq j`Nf77e9f1c1fa65e8057ccc925d89bd3cce47220a154d56eb2dc540e07ad2c31bbb980271de05fc9f7c1635a636966c147d5d4127d_|`U]E5`X~ܛ m^Dҫ,?Q˵CgrRi7CGKBUT&岼Xxa :ι$=L 1r3<n˜Y 6EӕQs1;#dI66^'U䃡aXDRJ@u{ 'turu+s_.X}A΍άʇbX۰FR"ݷp|(j,cqLGYMoB1T[IǃlݑёOׯ;uq{"Q9Nt`J?;4<29Io~r-DiY(Q!(ЕwMc#U|ioq` =ż1Y8+VpF2QhzK\H>p?[x?[hd   : #@FP     8~T// / ( , 1( @8 H9:`GSHTITPXTlYTx\T]T^U bVdWeWfWlWtXuX<vXtwZxZ@yZx([[["[dCsssd-ldap2.4.09.el8_4.1The LDAP back end of the SSSDProvides the LDAP back end that the SSSD can utilize to fetch identity data from and authenticate against an LDAP server.`iaarch64-02.mbox.centos.org?~CentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://pagure.io/SSSD/sssd/linuxaarch64)hKDF\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.4.0-9.1Alexey Tikhonov - 2.4.0-9Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1949170 - pam_sss_gss.so doesn't work with large kerberos tickets [rhel-8.4.0.z] - Resolves: rhbz#1945656 - No gpo found and ad_gpo_implicit_deny set to True still permits user login [rhel-8.4.0.z] - Resolves: rhbz#1945655 - SSSD not detecting subdomain from AD forest (RHEL 8.3) [rhel-8.4.0.z] - Resolves: rhbz#1945654 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-8.4.0.z] - Resolves: rhbz#1942438 - Wrong default debug level of sssd tools [rhel-8.4.0.z]- Resolves: rhbz#1899712 - [sssd] RHEL 8.4 Tier 0 Localization- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) esesfrsvsvukuk2.4.0-9.el8_4.12.4.0-9.el8_4.1 .build-id9cbc148478fd34dc5cfba032ef46fb180c5af9libsss_ldap.sosssd-ldapCOPYINGsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gz/usr/lib//usr/lib/.build-id/6a//usr/lib64/sssd//usr/share/licenses//usr/share/licenses/sssd-ldap//usr/share/man/es/man5//usr/share/man/fr/man5//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnudirectoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=6a9cbc148478fd34dc5cfba032ef46fb180c5af9, strippedASCII texttroff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)(PR$R'RRR RRRRRR RR RR!RRRRRR%R RR RRRRRRRR&R#R RR"RRR+utf-831829910fe6add7d985965e57a4c923448944d7b569621f75220845482fa3b85?7zXZ !#,8] b2u jӫ`(y,xcwqFvׁoPPT{ ^f&.lqbeZabc{$nu;b׷BbU59w[˓tD2,Q7F0Ml=F.GwpE8x%(I.d><@S dk5νWϊzjڔo@mG(ib96yK9e6=qAoH9?aTIYR <)ZK2R15VUlcق!k0,3j#dwa`>[1,D Y&Z?alMQ%Ԥʌyjt{$>DT2lCoˣ](";#roS_k)@ݥ`KXQ2 w%m{iָ}wϭ#ТoX^ UA!Fz2L>~M^lm1XbqBqWjPu~6007Xa>Љ挛<@' Ҙad:a=WѹVR4zc0 dauWG3Î8rx/h.&GǗأ&DQd4_GkSRT1 S3Ԯ,%Q}t5*d >bƆ]k.WM[&e%B{$hju>B(t^iл*_)E98&]2A@|y| 0XzsݜO.Tq5u;M"NI5=rpxydiLO;ᯋ) G|TP#혗=&wv*%O xm8_0[Křoe@px7[gq+( re27U@EnUrH#0#Tm͜XB<1<5h9l^RE# f%_h/`Yν_.Qdj:ܔbY .65, {8]W O?x_Vӯ;U]kMfvp:|JT(zP(@  }֟AͯQҦ8+qBNp`$<1~!c=̴pN> )T-CzA ڣ/z02NX?lWi32QgSrF~Ud^84 3wT^w =c9ZޓZ=/İ]#밴cZ`m(zuH_IIEIJ)E#zSU4a>Ύ}~Ű,w`V^?fRe 8RXU zMg7҆^LEH/q4LTź?'T<}hfHˈmyǿڅk]r哊rk0XW?YT,YpsN-Ǽyڴq@@N(H^!LhxV V\l7fE.̾eŁ^F1y /Q"rn3d%]U];}LB }F+3M[ a!3*~@WIS P YR n;z2DrEs\8D]RsW,j|obې+ }EM8(.gMኮ5|Y,[$os\Y3X?["KGXXf*m 0V_ǙZnaRSdxqBˈT/Ek0_VS?1Ed Bkd]6Xc _r(WLQ!QV#dp^An"1ΰ͉zZ49AQ 2M K+4 >iz_p>$썲*yuxs| Ķ_w9;kqz6MtGw%P^Bdf_]a!I-tw=#ي6HVG̶BË|5}dT RoTM[C^` Hl9z;%Ah r;}> ΉS}%{M@׃_T6Th3M n? h9WKXEsPVG) 0RfD3lE2y)K\Aޯ5|]C/pp ! _M;#G'K] *D @Og ƢM==k.:]ce;/'Es3&7qr!mnb9 h K;o }*Vѳޅ%񶈔AHhylw7-HR`hA*$g \K.Νa٥2 d3^B>=帖ENTc>+8 Bj5+ ד($( P wԊ0R)0m%t{T|trֶD~lr+xPv:F6V  KMjޖnRaՀoHNC*t_3%J686E3ꅟ$߮@ @t~"m~y9߽$SV?ljh1I'^$yW/1r=!pcsL:Crl jxV/Qoa_ҏ3< $6C>ÄRtc-fd/`F%Eu*P<5L7T[QJ[֗Y9gbcݘy: gO҂DLQl@D#4c(7]7u]@!N~%beuqX|dS6%H]DL\{a')=6sv@)<1*R5 n,8T#Cz*/{/]2;P#72'p1y[6kkR9ex5_%ǫ\sW.JzeFKX /Q 1*ӬrYOD5ԑpօtyӬ!u/O71ww$YMa?S40Dҵ=ѷ TEk)nLv~ r'̳!t+w5`O zan\E1-5/Pഷ/D.t2SQE=K{3(YIc`?Y>!fo2$44*RqyaJZ{X;׷^1X5=Wt} 80"90\p3QPH$ym-K`ѸdTJY!5 (#<4%t!@P(`y"p9~_=?ypeUUjsZ,4rJh&0FciVuGeϽXWgNUX.߂gBSKk>P~Y2ϏxX2k@ɝW0ﭹ۵;m 3~WV(qK<&:13B#tf`ZC[nffx5Ԙsk%1:`/{mH(i y\,Yu.7Rb:3{Qj;hVϷ>->r6 ٷ|Lf$efh]>%vLt-Lm/yt77ՂzC#㏊\6v-TžU >Ocr1\bFƊ+nx?jH@P=;1R<Ɩ& OmVңiA<u!DE2w@-.hMYA)P8z b4r7sHCS.So!~=ٞؓ¼L.UQSƜpFoyHh NWBc| =_˸c5˚;3NJ9v/zan#W9for鍕˒T.=B6laHBׁ혍å^2B&p,_L٢7pw8oO]l)sW;蠷Q"=5ҩA¡͎k;7yb1uʯGe+0kZz57)!qb|bw+4x⊟~"lʼnt*/s qJ$&xT^]pO(~LиU›7u#,Ewܰk)Ds?[ CmIp7n M(WZ5c`fSZLE/K!~Qr%ޛtڤ2hGW?Nj&W[^y l`Z+Ml[Q'1[XoR"DHPw&q,(ȀhYjzmZx,E41DJ! wͫ触àwl3<}h&мY+Dμ1^\KʞFf.A .R|Pp..& N^@5m˗q蔭d2[4ji#ُ.O.08SߵFb(ݳu?GP{jezI{fԆ\{p]6"$k/0ۇ2\Bcw}_/$ ϪISeɒ6/R;S a}iO߉89pU@W ~XEHٔHҀqۉ~ )B.=- 2UYJȩt MwDW.9eA]9 BW6LOoKJS{~-OԱ*_,C2#ϗRd3L8TA| ob`Xߵ#)eĄs~ST0}*6un2G-R û]-X8pD9̵*i2t$Xųn][Sf*L S ^q2R]"o&'4_.8KQ1op`V~; ޞ\'[n u_Z‡WMV6I8֐A&z'P xjgXq^f-Z.!Ҋ$/g5]z NYHi󟰾D롊'҃e/$?~H/ :W,eir(ˈW!a0}d"Pُ/lՉ)){nWl97H|0' DAw(n 6V'{ҳY,0y[5\ޠ*8):BӞ#[^ hwrYj0;YxdRoqZ[Pz_,3A* 4k@TqY$ CJfFѡC&nJȻ*;r9I5޶@YA *\3/KIv4,hiHN`%"FI`v٩ėNFkG;&v1[e'y:|WSޝq\v\w4.sB8I0o `W,`IΣفZ ntޘ2ۉPxi i$ PIm[gjlzwdwr6 ߧhfM$B>|p(j[yk DLaHKƒE?tXUgO\kѼѠ2^83 G@좩Qj 8@w 8%~%'KGKAW!sV.}5 {2ɧ}v>] ԺSQANi-(Y=wH UrWhwE_qY=! %rO#-GNVޔ5XF>ǑJ,dbFu: 7FXgU^G$MvZuZdRIafb=xM!c.E<334K*2_Yi4ʖkEǰts.[ *)4-x5ӝ@k ^)";Rß&OSLrޜY%0*|=#|G,#BLI@Y+Om~Z nd~eo 5M9 ~6i7X`ȟ}JK3Wݣw !TFR-`+Nԧ{rh~˟f+DhEw5#Cv!nd hc'Wn ^j#?+LlLl`K{nwySTڜ.Eʪ 6 eTnJנU3e~g͂v{JiT~ME 8ُeJM~td"iEjÑ}o[Ni^΀;OTwzSIH0ia0zȒڰ`IƸ+b)/vF-8gB `炐YT9+9bG5t1DS~(R^@\s>`, 8V=`h츉g .R`\uB4@ӽA 2YdCL7(v@.c6PEKk%9'~j$O Bu7w?ˬSJXՈEx}'GXnUMq̥8zM6 9-GC=dh` g %"83O Xfr g%Q3qG5jO0b=PmaPAK oZU ѶazԀrnmKӃ#)n\J0SpٸK F| fy{=_h7G{H(J Z4J\[9^SIg1o=/ֵǂǥ=o6JO<8eA1o' 3$!StZ#S^H#sjࠠ5tWRҵk?x,!5&3Lr9YGS?u<'ƶW:-HfBiaCcu0h6H@ubYM5N{Ŏ+nRFXx9$޸ \r4\X Ch[ʕUsA՞b3`6 ;FŸ.ʍr^JE GJq>!=@,kPykRiEc8b{QB9ʔ7[m="(R`[`"L?Gv6#KB!Ɣc.Y;n}VzF=xxNN gh%&Unktl6&qHˇDgKxcJ?jI +Q/E^kIyDWd,WJ!eMk&vE;UқO~S߸!bKngҜ 29ǐ 9*EEP@d8];ch]!SQ> R&5٥pΧd*>yc:,{7Id陊;z\I8r4cF3OۻJFp}XX"L^/9=!nWv?o㹇0Mx֠O} ЈI&>P[N&59霮Ry^smc4AXQ&hd1h$~H~Kݰ@=.M7t1BHҷL拐yȾ;AL7 Q+w2GU?%G$7Pd8xƕI/Ap{zb3>Zx%/GˤtWY[@#$]"bT 鈇TS/v_ ].dҮL >gĉ6?bF0 W^zysRM6 fC.SZڗzR`sR5?+$rS3 oS}7g)sݜ;ԭ J\kj11Wcha_>)\f<.sflYuGX)[c5sGSF6ES^ua;M"@mn,MvBv_6jdWq2sA CRKgb5nϣlu-lEa\8F˄Èue\vOa +z`}ʮ<9]]#MKgG8 T ŁJ $΁1B$SIb5Tt;oq ]E`UWq6ʳ[e܋[pC,y/p=Sw)Rs2#aOjnK$%\>)P1RԒ'iR*(Z\OLRV aBdXp$UA\? \ޟm/ # lH?kQ𻅋73|LQvPcKjReDsSv RkDK юe#Xڲnj& &}1{:ki;t([3g'*t|\B z̬mmS`-2(N4HXG)ov_.^SC<‘Q\ 1i}ꡝڢ#\;0f3MA7&+h.nN.MMj$ZYSnz!ZCFɬ(^pzT \lR "d0dв1G/7n/({ٳ ΔܟKUUJpDP\tcǔPⲸQ{ino 4Hxޓ{Ԝǒi1Ĝ~+%uǭwo7]n#*]-F3w=@ gdCݞ膩@3i_21&+v]X e؍='|lzQuoa_8 9[|U2I4D(↞fpGmxyHQԽLih/eڻDOl[v)($i.IÉ4j"Dq;+اT64=p@8ˈk3[;-(Q{?B]Eۢ~TD3{|wԛ67qZm{ch=׬! ELne0,LmB\QRij<_<(H8*Ђ9^Xa&DZG,U$tyx.E-+a$55F]'g6)@G/ˢQ aFހ*ԡN&X_RikOgKU$oBEBi66SuU2S{F*ܭAuϕkĨGy?[|MZ hGetZx$_"VajZR2@[_j;-SeE̟5A' 4 Dl\:uBq;>S(lL8oȏm:b~țہذHܢ%^ɢ$,pƎY:b͒إ;l|VnDuK|8)[t[U/%"5,* ,+ޠ^ܕQ1=[sو(-8B1^8IW @JRNV%6Wp sM`EOd|tMa^fXdu|d lPIe76< k n a;,)OH՞ĤG3e-ؚ Vpm.?(cx\R_i}/)o?ڈU n4JȾg-& TM,ڥ^qӞ|AIQbX_ s#= 53,Gy.Vْ}R5jBmݳsicIOetl3g ˜)z^wڠ sdP% 9WvDy]&^`hmuh4i>hY(H㖽Gf\j&-]I8=ɔc":#yK߸[{nA١N H{HES%] p9{f{MXQяRg 3a MSۛZ e++mna:{J ~C4@+Rx ,g[OAe~ TSx:GKD>ȷT8cCrŠ`֧[Rk7_>́]X>ZGċudHw g&^as:}ADŽqY[)&@BX'sXT$xĶ1z%0^ft %?4>Fy,xVg3`Tnd۵X+cSBrh7(c@ 1D@:"!HޔUjGwZLd@hymy<tI \9رlA,c1ғds̋u ǩ3Ya\|C05ar^# "kX+wYė= *n|V[g]PE1 lIp1G]Ds{UTp SAe Ղ>Hn\93х!&e WX~Fl _2^Y{Ot#ojxMEեwY| LNZ!FrPnEγE+X&ǫ,#d-'Y7sC&ۨ?ne0.xwO.Ed&@WΛ0yz7"BUl)֔L\fD蚽W4<MyF CQOsY{oz%̪-d7m"]IP# O,fJV RgdJ ->~eI7khwZ@Yo8P6qf# r4g-J#Oƛ+]m# kN^oB*8'Fnɹ=w` ;}hjA$_\}$BkJ D%@%U2 LT,pӊߨkY.]Yͅx2}.f!k)6*~ qjiƑ|t\ZZ-a1e:8z?=%I#%zSO3y&rߓY&㾺%il8ްzG̨1A-ރ(3e],#$1`04$"Er<`aط%5m龨&?pi]f@ۆIG "{Cn H gGv8/rO`k*Ξ;Rfz` MqZTIĶT꿷+[cTSz*)feth@<֞rT&lsd$P}.{ִ e)8g'e0;2=]GN4#2txUL.ʕ{ D:5[x(Kؤ널(O_⻭%^CbfK$M ?gW;7PڶKC *K W4b52;IS! DݿvMH# g҃hhQPu{xd{w^_Ц䱋 ME2^.iG W%<;r$:{'NCC0ΰ{P4kkJTK_.5 eƦ^}L~-gkQ'[OjrZ a }Uy:,'mQE A]o#Z{nrF͸#\!. tkbjx[c㾩"րW|8m*__hbהDûQZ~ Dz(UD35!0lP ֑+jXUG($Nwo}T_M+f#CSw]>dRӊ`HW?c6c8y83يdV~ c҅4K>R5~"Kcw%Q|.WtrlTs5LuO񓷞J1zyH -BW46} .'\9^‡Yy_إTM ^gCj of&K%W x:LCKڗxҩtS.>#\- vB (u3 =b}L?X+;M0r oFu NN҆6Qq-}VPEn.8GmwlV`?PR'QPu5^l RF4iY!ԼF,Cv-5TѫܱW{5ob32Fyo*AnhRY k Xv)_qsdjtAcx)|#L 3->IF2ot}NnU8UWlF/B&?XT%|- F2=cӫL8yJ m޹+c2/4 XgD;vSqj:kLhH<~ķ;?_ڏϭ RgN.)t'fθ.*lZLT։4S}ӟV]&f CK!Qo *}>YɈInfN  _^OxQG æCo`=8sz}pnrSsd< xulz}S1 yDŮ+(n*խOpmc5C;Ps)d'Xǜ]|Õc )Lk&|~(3@'X`V'm ବx¼.Syd-PVZaD%F3n4\q&ߌ jtl{Jvqn+hz- sǗg?U:dހ'4І|5'2t%j n5UəE}2z@lA;cxAMhݭ?Ot=dΗ&~A?q?;tn a߉gG;#SN~rZ-l`hٸ2 ^ @,VX%1`ue,)0~ő?A}J֣\%k! A|PA #@^[u =L,kU}6SD.ls diJާ ׻aYgݡX\d[z]Խ~^h&!c5q8CPz0ê ^t@3$8&%nF_*`{LsgVf؋iJ\MD9.p2w*5&G/ G)oB:Qq]#y%xʊK~yh؃7uY} @$Z*B7 U^W:ugKU+;i8$Å7-%hj=$<׊|sandf׿3_ ^0K9 M͟e%O\쯽_[/&K~ܺRѤ h-sT3[?قV  f@b="ؾO%#UDt0:|Ymn,~HI5L`jC>R,5nDhST?Խ) ’9*a+tH}ĢR /Z?`8{UQS{$uܔ{Ge/?I[EQ<|x+_w7$PRTj|<]sR7Ȗj pІt g5`C)YHU~H:q hϲW)WZxX*E ~Â!b"M鯈O8(%Mg(I  ^FJ}{ﻪH0Y7g=ׁi%LF&T8ϢCH*cm=h+,ZQEoY,)QNTw[vz#G j4KJXQ5&cW,Y`+&`qTN~<:p,f,ꃟ5Q)uD:=<|ݓHgU[8YAaؓۿYR~8e:Vd|f?L>=CGAk LR!hC0`n|l+;5x4<ʢ-T1O-5fr.߶<馸י ʟLO\Y3 |З YGt;rP]oK~|c$3rV `i[ [^l p!ܭ~o[7'uӨmV].y@Rb).L2$CY55&.|-xq }Zd}nd7kb61YJ .&[毬4^3IJ8:ʉT>ɧ-O+/0}ܷ 177S=yHIϜ nA(ÍL[PllSLW5oڋVo>iqTLȱ)@_`xkW1̩IdLvAΨBILbjWҙGKL~KƜYF[C瘮W9uz{݁k5UB5o17 G5&+)[wzyLJt[l+& /B9Q]o ~Y |QfƖ>IB!o0 R-|$CSCm/X>.Cx$7CB+ϝ !6Ī5ag%QsL]b c$ ԪժqM:bכ?J;k#c"D3r\g`QʆG&ep NT0+iݢK05^Sb=˒Ƹ]$7*k QMQ;!$b"zYiI 9j߾ZjxUR7\-'6da=j8fKN>"f]਷*q^Z#-sB,M dddc2>P@6V(t#P%/~s(%hбG˔*dm}3_WcCj|.ŷ[oHI/c6`)b'7*[pmՌ_Y@Mվ꺒ݘArG6"5`n}Ftj;Ylna;*ҝa&oo Fxv ][ɫ3ZbcIp0pŞ Wf$7.d[axɁrƲ5,~TL]\5AVAZǸU*jlLpeqi5YZͷa֤D|4dSwAsW(Xt3VٔΝ@gN~Zca:A1z)idj,ҋ&iL;4&/N^cDEE иDHvQ6Z҄`it9]$αA Y 4;RPq,gGmEgWY08}^R:*׽΅Y96PjdV &WFf*㞃DMqzp4E$ 2m~6qMb|CRm r6R}@bkƈBlEAENsh H}Zg0xc5QY:A6RXwmTFtDǸ ^.Fyda4^nN^5J/~~y{n סЛ̖uq@k{uEz1b0BtQCBɠ="0ߘØ}t譈F_t^\TF:YR{q@tmm)Q(HU M!z&7yWR O Sؼ0?V4fd]>'IЭcqpO? "6|" "^+FDiBPy.0xm,s-& ˤW=l"]z!>~La>n*RQYg.K(Vha 3"L'fNh[A8Mر777AfJk_I|SB bY eASKޘ;yU1ѱD^!َGMU6h^[x TZT.wR@82~ɨq0D4tC^DԠT/[LŇ!O\S9Vjs~ kB-hK64ec=vK*>AB}i~F%C蛓EV1 ;F\ ̧9U! jAh@[o 䔤 W'#p%& $"l#Mg>}cRE;\ ]PiP[<"#s#Y0Jǧ le K#hmuC#;{ml6vH-miR&d{ SH)ˆ~՞ KjIb<42TQbILiRb &{rvWzd: ,IIo\Iփ'Uy1޹#脮adDž c!^SH }۬+tFד xC Us /l V-۵B5 ú[ݯ:Q]5@it.y]jV lS6!8dӅ%F!FM =tK$༤܍%׶;𑊾5[j,59DZT }ǿ;O>X6~Y$#D"856m;DJ$Y&[mgO@7nUP>L(Ƴ痄s`1%A*.37>`E T>XL g`mIqq>"~C&Ns::ew[<0WWJC[R-HD Aε+Oͦxv8:NxqWhDV:/ 0e[H\MG=CI r{B*$[EؼJM̘Oӥ~ZSq, hY]R)VoHl2^)6_[z,t69d~7YT nd$$:Kl1ZA-ܳA" +ѻHd#_Td xQVwa>[gXEH'߂)`C49{D(ino58fq‰'[B|)*w𑯬A\Z *?QtUnӐlD2d/^B҄f")!bE5L]G4Y1Wُ.69UlP|RmP`=ڶ&dIit!@3u7j t]or[5,IۗmLrw G徆ҟhG0 =AډWۋMVq <ˬP[ i9`%CЋ0xU0og뭭uǯ$}2LPޑșICuKjMB|!x&6Ԍ)K[`Й̃e>kU4 Pi4bܦRkPG^?)֜YYR8.d)M8wIo?t[YsTS]Ma)I:́86KAù9:ޤ^ by4P{^Xtys e" P/黿ZC,BlaU1:7ˌeyOS]SvqiUb"gNL> i.o0wF \'Leۘf<wLV#=eS%1,[_ˑ7m#j٢po ydJam `;Y bY]rIqf%KTdV?Y-L*˺ͤ15P jvcB]*{ n 0ļCijɆZصېIu{淐 tWy-_k M>69kBh%PZyZ` WdOw(Dt;aEdo>~-o$`XtMH yei, 9'NU ,îP *y )kB0fd $IGm&kQv%dEAR )XJo(;1wS ~ hႸ냍L[aHg߶Mu9^!pBpΐWnq=(W32~BGX\L4蒇,W)֕6qó` `x $`cb:&PloxtJy6CQQHt|6ggi - iR:OmGkSXhj|i@k,a%= (n]MtEh?ӕvkz]+.F 8{nF,H)Y˵˜I|.: x'Y [xtQO?r%+e;iL_} Ŏ_ W bqE7 T7`!e0 .aa)"d+^d ;PwnF!tYI%Û`#`S%2 eͯmX72`{i,ͬLV;t?kt&fRì޿ "2Zٜ0O=bBН{"=[ jѱ5y\kbVtH_ QoL}QMo$LO.47?,Av0嶝]D=;R&jAEG-Dכ}pP`mi>/%($(U:ͻR(0XtUE0S&/f!#3;(x6_%ݷ'~@֯'Ɩ!1CX^I2J*0~gKqq$ǎ=v$K1iN{PG ÿ0zhDϽe-3Cf2mPT_U|k H@ F}M>ÞE9:ϟ/;ȴO^e-=B61zb.I*hM/QL @!7і%pHXn0"phڠĪ|i {Z?NyrŨtф$s Q~}G2QvP-A%yy3W AZ Mj)MNV$ix Yi|o]-1WfLzU}3FU / ϗGM*pj[h,8m c}*{ i 0 CרH]9t;! 5'?8Y-$pGQ G/g#\ TZ)N]VFIKٔhJ5 s f+oBaټx?ۖ`M 6ke v)9~8.Z`:b٬&֬~/ea]R3*I9Q"n↿QWX0 &pՠ(ݲc^eM aFL[7e'שf@Ls *VVxJ}49!X;bh]Ulqo2r@| o<]>19[7 Qήv!}Ŗy>55w$rf@A;矐 y[*Ҡ8R+m*C"r)aZEm E{nH5FNʼ+f]mQ+:VI7_}ó>/?c@ % t3e*#>e(x}z :l[odcgDPO $$ tr / Y{#[#jy a?ȔG{X;Sqi]ξHܩ[5h˪oJ&?9Z(px1O%6:G:N"n)MÎg#< =0Snǫy.E]4"8qu>"ءߌz=ƥ\|&R;=֩ĺТ j$H|?H:ÅܫP2V:d m?U'=(Ze- Ovoͬd.ARʽ^.M6Df&wp.]:$PaA5MSrXMC=}^mh"pY5zhq*~zA"%P,,yb}hoQYdDM׭re" :,,c%=7`6H>Fξ=M_:t~2 .F2gT|:xg n#nQѲcm2 PFyD:m0fzL/5Wû@pbTZ|ۄ!NřxohV=]uLهdՖ+`lxClWV($6)>wa+yQbKL3(6k)Б{DF6O~.ʾeWUub@xÚ􈇷6?r2۳B ~ rٔeN -7/WkHO7 Gcp c9h ѵy P?9ɧP{%;P+M)jP=ɬ:%d}\j.m]4lSU!p=q]{JK wIzd䠗=S&(woBd8"A;krԍfE#s?MI8*vǪ[QIu4M&&?p0y ,W?u}V>ſ1 b@:00b؆¯눢3 q 4p2 S=KiL8!|wطBft%#ANK@dPL_&Ԋ,)ȝivOQԦ5cyƜU4fz˲x5"=4ŋ_v\'f3!*S(T\- I[teMPBM:خ *ƗQfh*?F@I1t( &[da\z`|Iizӫ뵰n,˖ӊBi3 @UMVڐt3Fw3PHp^*, NN,1ފ3?L~}1K@4xZB,[;':Ho԰5y6-%x> q}KBpiţzW%f|Z%zLuc4*pKZwf9?Z<{[o<>s0WS7I.)N*t |h]:ď%(ԑs!;/a"X (;.q7!F?DCBcD͒qH;ߧ63b?Y CRWyV}W'6v:-BgZ;­Ƹngn0O(]{^Lu(꫗) aa_PZK9`Ě`s/.͘ r>D؈`Z㝌NIغlcN)Y &NlQ.g7~)?S+7Vƚ3=AGI70-=I\%fx%Y5c iQg~:^ XE?>#sF#i 7H hٿ٠ CGܿ2 8}<ەx(N$]#^:߷wqsjH!J'#*$ZdြF-vםD&eE ZU.a[fҶc|Vl$yauXfO:ugI,/׿VğT^) SdUk;{zkU !ݯ>:ERK $0H2tDSx.Iƨzf,,v'2!|'}VY$}(gR>ϓ/yv!)_=SK2h Ox?q dO EbhCrȭ\{;(C4!h}L"6NrD ɨM\岒E~}m޴Lvڍ0p_VxKP L6CwKp+_ ࠤqHi%p#LL#|.QNDEA7)oBatZE|ɷ>LTRH66@?3azuY|3.[_NȀ=q2S[/QR)?Stb)}nV۩Gjq x[RhCPi(J-iD^}$=_f,;}IȄ6nnWjDoq yE{ˍ)&A͍4R0"7g=KNT@QƍY)Xsn<] j(A h<'pCO(75xh >Gӧ#ٹ_@M9Hd[ię5!eP* f)„`˚5lɧ~_0]NK*p [/!^-\*7Bq^a|xOW~9 f!YƱ. 4O0Hy-e2ʪQ&Xm:{$`;*XHFJ]N5c3w[vr*X+Z\yZS˯oT#ؕǂ7"'m+9z!u} |u1zkGCl,hn]8ӈr&]m5t, hN䇦sd}61@x&G1ef#eU1*R];>ϊزDT^z꣓g+B"qڤ"Vwֈ}w$+:>^ONhbLC TʬR.,FɤZ`?XvELtmʋ|wEW|k6h][bmBo>V*AsPLowR*AfVۍK-!QJ[Ō)>_6+or6tmH{7d9E!a'7CܒS:!ךh& M^M_sbҊk(f$p߹ Klɔi!Yz.QU@~ %2}*'3EN _ ~ȥ@_FAH*&,2HtӬL-yOu^8B6h>?+B& էܿ{`v=K֖CRy9u-}ǂÝ^KUOOp:^q XqS{/FL$Vºw_uҷ ~$'|TG5!dH]Jцdy -S~q{Q\ςEd58նTR_&mزqLzCLOMFettv!p,Wk oH`Yf(*k%F!6G֕n^ ckSUlOB )/HSJ&Mf#1BQk:2QS_Qܥ:l[FH"ɵa߱od< "1l# ^';jED*|&\U4nm N8.phHoлl5>sQ8#t#ɴ\ |jWHMԝP7++Vל6ŧl(D@/&ܦH(+u) VJ̠( đ??wXm& xqJn ښ1A5āj <9niej2mliD|y_{&6k)a9 rY3'|)E'o8b4v̿ݧƞH,ت3 #|oԑ9{_A=t<sM.OV[NI8; k(S\N4¹w4oQ~1-g+k`{:]WEEw3Q2u4]qdXci8+oxhJt5V7 _D We9X %Lv|RTuu& -YⷝRºψ236֜ ۄ~`>A<;^7N[{E_=1C3"hY߂63aVI^IŰB_N67*)wA_Ιr[]5ΚVk'M`'^D`p JZ(tbgbPA5>t &釤+H*>G +ױY_ze֋G:)}1*[MN6,Y N0ِ ,-vBq蒽*6TYĵ4yEEb<}(:GK{j >T}+W$^Po:wbhD.9d 4ChމٔenZC%IDhnBNd'V$ݳ׵J`yR=sp91;5Y,VDF*M, &R 2~(ulcC>e3s^~+mVS%JM+qיb/X c̡i4VO>=^MGd`xX{&% ZE؉jAFáG߅6pˉ:Q1؈@XUKZ60VZH|S|YE~8ƴ}MB Rp;duc2$.4œz *ig, *6,L\ 'jjg c?Rj !c4Wj/AhŠ"l݃m@ÒiyyYa|@BBÆ4%J!y83SsUs6+/d $DcAi߅v` Ons~M*%q0aᅳ'v>$IK@Pn;q@5+8<)ˠ oVlF>^unIOJm :=ﹲjs38SZ /j+ a<& eA)kpX9JڐlHf$i#ꏴjg "?;zZf~A rJq7wqazsƨ dԞj@ ڄSimDƬ1(aâSfG.$ LH]HuHq"Qb䐫vWvLy.N{'`m>U">4`XRTCoިm,TW1MmӱPʧj0Mǵ;j:Q(Gve&ܠ$ed+N{FV6 `O;3.le+f{]`91w~HR>&{vOXPR0[1 k0H}=|(5fzsiEA|.L>ZAONS<"Oo@X`*?Uz 6*+W'7} ڒĮ>0K:s& P)Rz/4v{W-?gO=(*lڂRON-2 ?lMS.Pg V#( :ޝ_d#vt\ڊ~MYQ+PQJh 8KW~HjnGs.,aeBCŐ;F߮I輻0léQ%%>rxSSK;(tzؓY}ϛb׀D{ T!Tָh. ͜\`, ~'_ O? T?@Oo.ɡ,CQ 0jU{[0q:$b ,@&@gЇի,!z~w # z{ bXik4l"QVKϔon dO)#wJ'Rjđxuꑳvka 5[H٨b8如[9$'OO}}{֒3F2ˆnYP}c`gdj  d$Hp4#x3ݧޥ0 ,I:00$f|*[Zn?=_"}j Ӊ|Б9+? Q3M咯7b wb&ަ2Tw4%d)B+hOP1P͈!{sh С.a\6ĸƌɠw;` NFx^ ieGGlڄmdQGX{Ux) _= 1%Y ' WN5AA9*Z/pWJOԅ~vh{q?\ڼ:۵sβfh02Id]\do*4›RvC\':šzxmI"H{̌v+40788ETjx*yTc0wv& ǹ}Wta>gW!.J ј{1sU!ϓdE8}sUŔ:)CZT] . i T&-^s*c4x\bFg^8E-9'@mqBܨ"DPwM ECCedye7a1U)e,ק FuiVXdJYԧce^0[)P1 Xff_ yAlNWL ԅ ?:|G{+1'OO(Us)ԛ?B5pk# ~<.8D"ƌE_àQ#`CI4`0tM=Tl؛)m/f%'JVH6oHo jt9 ˆX]NQ~p(gXʷۂ45Ysz6T-ϝ;N]2~:}.?m!BW6bX7_s=#mƞߩ(@Mzħf ˄"-B;Mr&{i2 ;zhd$!joE>lɩFRP{Lwrǒu6xkw_l(m?N$6}NM3*>9iN4(]TW`CbKdAcSظ&?M塂t߅NlaÝ]48cKx/Gՙ̆^(`U5( `~6g] 0 ] {9cu k'] @?eTLkG< tX5+#M(4eqG I9&gd܁x0g*=W@%c^?4TmFC:AߛO[8 )5QGUXNeQ'frlULRb mc@gz4#Q=} \67sOC %c_mӡ(Ӯ;^_c*oR2(]zx;9ZmKu0UJE$..bAl+|DKLOY:8Y"a#*d cNp9 g'Qi5fNcqXoԊks VK.K Ë@xpgvIr4Sٛ5F&*v ::`Na?X,[6Z;Cn6kdNιwS׶ Wyq.@9Xba9N%}F9oEpo+@2Z[[ >[g[Ŵ:ٞse= 2WE9YaPbu^buk Oxp=J EY\RY3)bR̄'MSbx4.Rݫl掜]Qz|w;\ǚmrZeb-zuJ9$ Ymz%9]hIY o'YWQ)05Hwa3LŒ"ؑh.CH*Q@8g )/ޘ/iq7%qUI醋dQ2-8ίO$9~ ]p(ZY4:X;\@kvr:A/vofCi ưo&ӎ&0ϯҡi &IWW.ͯt#2V|EFmp1r%;͸ϡ7stdl?g5>zB:%XXqn41Qr %ۤj gJG.XiV%),HTFZ{W2enul|hKt%;$jC A%R}1HsH05`A>_Pկ`/PyP241&F~E]!:{U Sn);1"l]֖t^̗;NHqÁ6ip$4M2 c".`L|yɌ4+NWPƙǐxGȝb` vogz9f MPXXۀ1JSɅeOcB1D<{g&AٸFآFJB>@V{)빛 Dx12J54tT1zӘN~Vù{X>YTMHݵZgdY:)(iX^`E>u: n4[+\1f9 CD(c1>Ӝ?0ȻMpjB?\qk$zurl #aT)[Yc}˂7 RtKZƯR1Wz[*ZTTŎE?ٝ/+?";Љv$I>H&Zt|wKa]s 8ܟ>4f6A­4vAi/q7>kfLn'ar<;gj\i@+=a"F5 fSm\wjL2iʩ{#x`9?^yN#m7&zvN'uI]ϟl&wd}{6r0ŭ̉&2hpMD,WfnwKZiN&V+G$ q b(LDz械,1m/g{n'hN% ]lA=k`m䃫eB^} m YMd3V$$Nۤ]XP7vd3'mlS$b2^^h)"PDU7Oqs!b>ѳMHn @ƔRTSCThécPZu@%@Coĺ{sl-?bAdD)j4kwvM Jqܱ'xw~G0 |eY:s$QbO yk&w藙sT"58hDL3Vs`t:xOwxw<=MpUnц;[w ve1ӊ@˝P3PeOI);75,-&{ 9U :-m]i&XN('4}8Vpibڼr.pTG l-SIoN]̯Du[Xή<߯`{t;p6=RVA=(tzD%U~b]ՊKc&ĕ}1xS¶ViY!6YH12Ҹs)X k6s iWm9dS=)R Q"?4ȈIDLM0m nĄZ܆E/v"Te!}2PATGxvc'nQCc WU۷V=irD)VY/lv(eyXJ }iH|Gz&-#d}KKeYBjz(ޥpE KK$E tQjYW&{ԘcV$iDZvt H5 =]j?6m#LtJBA.%jLXtwC2]>Y]u813ZZ$~dKh ]0޸xptE084S "նE#'ٵ@@IRuŞ"ƲN94Ȗ!;sҰ2QI[4Cx")w1G`i2e @_[)/| }|y{uN? ;b\5/2Ab,?m$`w&^AEŏ^ 7T)}~\D-s=^cPԟ6+ՆMi8{Xv+d9̉z]B*†;-Ս~wq1b&Q+x@$0I#EҶQ>m_A'/0*hMdnP{}ς~Rj(rkZ~Ҝ{0: 0)ߏUnxԏGb}Lq{L{E4TIJBQT0>tXA4.:v(ݗέsKGF&äp/QPh{ٽа+}`Jd]#O\#$lLv=g},BBή:J*WLhO N_I(Dh62Ngjiv&q]#=Knj݈~W,8ř`vMvH}铤,od2\m$/cD-<¡#ijaneiC-yBo]'IDC&Ƕ66kIMǚ7VAӄ0QbP8MY'f(FvkVaЮ^q&ԍonkʾ.;_W߫\͇7_@ Z&4f8Y3qR/hLPƥΓY gf_4>w.@GD24R.aU2F86.=X MEe_Rˑrf%"8z ՔhJՖe:`X%őek_~2“\D4"xmn'T"M[9󺔜okvU {Ř[nMtp&2Yhdk4L-MqRx5|4|Hi7lQxx&\,\yB[b+93 tVR/@tQf;WYI ,І'bmԬ0rwQa򝚀kZlYF!0~91WyG(̅q8Y 4 R&Sb4yW='Ip[&5mHw1#/r$Ύ:$Dj\Z7W/:;75H%jro-*jmrsD*R X?ϼ/ujqq$ÖwÝi@w݅`FO/N #ѦOInizmU q_%HUtoNW\3{*ޔ~^Ս$dGqQTXgTMdi7+;] 6fOXkUd2﯄18y"U^Ү arL8d]ɂoTo2tQz+=1_?=ЧB_.($uJ !:%0KnBs Y2Rz뮀+Z\Hbڞ݌FWK >FC fe0f"ni1mUb+NhTFs4h;MKe^zc:W$l 2"diI$e!PGQ 7Yܔ,yY|,Ī@ G+ML(Kf@ /d5QZ6`i r]SȑB2q%| m @j2T<ua5;,d!h0JޮN1? 0D?Q?488"&ws69'P躝Lf:C3VЗi|A܈)0sS+ c Cjӧ hyagRѻ/kk sC^ ZP+Z#SS$Œ-mt`4DXwWh'.۞_O^=% "A:WD}~ ?!Ixm໕6O< >$ƍ,h@Q-eȡk=}hd2vX\zK@ycz뿂@t%҅F8wam''Rǁ5y a8e=nU䴿c9張{6\N9 #qRKl-bHpL̡+D˟j:3I(BYׯpͬ 2Mxi=ڎy}Ї%R.1憤Rzzcf7TԜbkL5rD@j`ba70;1nQ1, ]jk+[:r Y;v6jߠbCoG d=_4~vXIWYTS{eyVfG(ٲC.*2ȅo/YExZ5oW;;oh]Oq:Dk={8ivjVOiBSgut&gX X3ѩw֋8+<̑<oI-Вߢguyb*d_- 6iq*ȧIPw}IKY{[,[JJ{Io4旚a\d6i` fşuP٘mrSP;^+U$vGu!͉+T3!63 )%+̿W0> gok_Iǚ,uMzV@ gulNOTC-ps? {\0p>e`'3x v)dqMJ6)=zk%QUEZF1EͯC etJqF{v4N!cM7Gk?AB^YRT`N(ѪoXhVt.)^{{Eu|II:%%!ӹ U\̋ca.Ȁ G/~|3AX'hkNtgMz,@*@p|mgݙx=M$I4Ř"XDhJaga7-fE'{Y,dRC9>>^N3r" (]r%1A i[A>:ꛎ)Z걻7ǓM7+3վUҜ,oY&j)kC~HgEEWbrq/ksz&A v(p)gD Hh}[m[P h4Td/(V̗B޴pyh  n+ H {?pyn6 }aAS @7wO7~>p^=e6GZ%8ATсߍ6!Lw~܁H|!Nj?+a3`ˣ]Y=DpZ`2X͎U?u SJ . N A.ï+"*:u8BZ*x+A՗/I:=KVv&QbHu%3qwH˅~s@*/ch `>`ѽ&i(,Y[>Dԙ_oCܗ5t{ H=VV~42amT␍$ePI"YJe&Xց$e=oIA7z#~хRqQE2Ɓ:2&cfזU~`ʽD8ͭ!T1__ n:D5z 4|G2܋S30Vi@Ѹ/{c;e-d^LJ$f/^^gxyR.!߾F\J]v.Q1u)(0K ~Ӛҋ@JVGG|{rK2 Ȱ;keB=1SR] ͈!@DZh},%D.B'XGk'sP~3ƝK` wLPbط=) 8ؓ/{LR RNGaR] .ζ-021C|b:'/Lڃ'*KC~|K$d謴SZ٪wLHE^V^unBHіp1tXzp0kPT~AEOr$ #hRP7rsnf' o/A>8)KwW@U~ d-6( "uh(YD.vE_F.(J,;lx)ͰH"B ϣ_ ?&1%D|*/ R+$dO7h@Dxo@z,EIhPQD FJ` 2oSG#;k'C DK#lo[6J>u!T#D|qy LYS(fGOc`*{;tZ(rtW)k4\Ef,;ZxPMbN3-n3s6iBId[:׃lzl_La/ _^DahW^dYt2,fmؑKF9f~ A?څj|AZH0Crk3JBr7`'G^-+1_0׈}ih=V2w+;Boh>G' kyBX ;mء.ޝ}7w?WN2Ei`jo=) \2 C%іt0U,`"ʯ k3AɆK(ئE Gi`2Hy+FzpYtta:}O@7l3kO"j9'+`;I>zIptz'Br~_MEވ8#>F%PrHqE46үD50Rk/y-nE5k r칼W( Z_)/8D68w{zx0.fEm6%QACIl{2W> IRnFe^~~"b?@[E#sLE 5EGV: PD"1]yF(Y<%|X[dP4Ne$너z9pġ]isw9NEVHb2qOReq<iyҾC)}XLRA<`MH 'P~Ì-PO&W|A\lB7|~ACӅXe>xɠXa :iuV?[Ӂ,&Ԝ >UwcIC$VP{ַ]Y|bX $dSfVȳ> W : 6s5Y)xQIk%;gZ͕JQzV] {ks>}r/Y2__P_ ԈϚM}%eS |Y+>E2_fglwxu\ќAJƮ)y# re KI P"H i0|M+ C".dp|vaL?5S @Dw?F*[L(f6e&"6I.-o=x^*x4K6yi2#In{5h3>sRt-G)r#EE i?:3ש I#4n?Y~ 'Np_Q p8ϡ!F Xc8_ɇ}8*qS.MKω$f4*V27(P1֯{_S$I9 ?&CkOxdb&Z( 2MrVb#D;ڭw B60Lu-+? LJ=:@XNO-%񕮵3£jwo=#ao / h^1F53Ehq|oW,0:lq@QO>Ŵ \{I7&bg 狿OŮ{Iz9׌'Č㊯A$Gx ;}mS0TzUOGo{f657.|VWVU6{Wp'CA'הH}=8wUH@!ux>(!h󬤏/N<@p FGX^$=nhr=|*jʹ)!nUNU`G˘瀎ځȎ"K65}AJAgs /5M"x~#^;5qtJU SHM>'YhNJbOUޙ4+Uu1.&lkTIOqļi($&QYR=^]ۄ57ңW!g&[wE!tuCRHLZuvl[=þLA8XbAHaP3zwb|{4/mMГ?/! ьyv f$5@JT"6$;] ?;'<6V^)VºKt9/M2'&_U'՛L9 O'4f~(QFy(Mm)󥻿UUu !ӔS{uNߧ@p mbf|*E ^4˹O-j?S1Xjي-:tjNݧ{߼ve(QYxh 8L_ Ɂg;\^:kIFņ_ m}?+NDwLGj!+}S]M._$r\5='CW,QHp(rcXcнsɞb<|tX7&m&x$ 7I_Z'87I&}9WqIv9ˊH)ŃW pGl ?ʫD!VYU9mwI(PSy~É[jo?(t]4[ڳ'h&mfaj]PBل'#Rg% x0P^ƾ1Tq-<s"B[@kb93ju@M5;1Ʀ% α[ßVl,玃f2*v_M0?Y]u#wQŖJyPk=}(1ʁ_L@1";Lx_D P­5/?ݥw pnGh"V"ʆm g;2%Qk>m)䂮I\PFPN.0L̿ƶJRc&\bkJ"NQ6i0GWMqY̐6h=5!GqC.4gQ hut+M ǩRwj$=NLL&>TrhR舾Ai4O}jm$-Oӛee[0 ٛzAC,F v Uc瞰l?JUt] (md@Q'gT b*BR:,,EŻ7h޲l$WAӍ&I*%^t' 4;6ca}= b- rn4 }CR5h!lC V^~ar dj2SҴh}e|Q& wG$&yފڝcW#/v' D&4JdǛ9r̴X)m7fij5k{mOe{ߠk:uJWj׵e @9պ悿 L{tٷ_<&A/絇xҞFr.sr" Lw4G0v )6i눤Oh{aJ_̕9؎Aw\ov͊ {^QiA<ctjM󷕃r(Opl9F].BpG5y`2{BA~듳X񒠏O;o)5DIz;Fۇ?k UçɄZE~At9= . $Q#oyPG>)5/h"p"! zqɤ7xGg!(/W0L<ػ[JiSӅ|!Pyz*!/t#&ɢҐՀBa)Mkd}OR F{QhOa9(dDd_@Fnup>zԐ{vɴ[M#qDz/~gȦzP`eT#D=:BXQ@I:w 'Iɧ,dPrQO RRAm" C.Z#_ar)c ^+(8װ/\~k̥E"J%13 7=qޗ.<; ۝`|ـ7 c"^;执Q &Rer9Li OSq%CRlJGE s@7saCLo66>rFaAS݃kFy;J{Y Hb^ҏ1F;bTG<-W/F&@EE)'Ӿ0.RV#[n3_C<H`T+ i>=/0>€elyhޑx^,] \3h+hQOt>ɗБKkB #5$2TQW̚jhЛk`KiV۞;ʯR.}Н4% AbRT |v Fys7y}l1Aĺ{ F',F9/.2@M^N5Q<~. xDYGPUS> _Y~! Z)”4@;9|bv) + }* +dcKπiӿ3/ت׶icMq%f=2ƅ<8{0&[sRاƔ22&"k f& ևa^Q: v͛@.g:7qGXHȟ$?9r;X8HUv H5gd![M !rW\ڙz:DЩL0d7H* |qFJlR ʴ(ugOKgzݯMe gоOE3&_^FR>5D-z>qt閯|PO= eŠ0>U@T>D8R.'/ =\#רzL"m\xx.\\A‰g(]bOY2w Օ~T:K0̡E_0Kdf|stfa1fzys1\yb G_C&וu?F:cLۃ9ҘaKP?5a~6/qARuxAOiYuRx,ٽvL<H`iYNa!H]:&.9mk\-0nPE'<ϒ#(9ƪyf@J "(NoЄJ ~=:7H|z2qyٰ$"1jWj4 TbR?;ohjDfߢ'ok)5ZgTAJ$3ƾDE?3nSM Rd* .niy1ҷ٣'xMR޷/7 ]O2}sܔmpoDļOIQ+qfKm!b(}_.vꖞ␭']?w%kڳiPHG`bHlX#o7t&iܻ]C[wHsr.Fod|;R*2j TnLަ@ X;+ N`;̙sUWfew;"OȘP h)G d!|84IKCޑV߇d\kQ{k^J'MqDrt&;nn-)M>>b$ o:Jϣ@ ! 3&ԤÀ L*AB}c,چ\*smY9ó^SS&&@$+Fm!=;$Ğ9,UiGrSN-=@;9٤mC+m/`U۪vB3 2(?]j)>x)?7 TC 2(R"F&bԟLrj$M(?Si^0=]kGqzVgiR.xE?~(!\F;n4CLXmu;d\gv9_=H3JEE]۴ioސԐf𨱂hDx{&)!*iHhC/72FC| h@x9cOλ T@(G7$E|ƮG$j8&=pO)#슣IQbdI):=& ,̵;Vb^,S_֘9[\HO=rv]&A4ک@"}O>DzZ9T lkYx?(ۋR kVL߅`c煝ڿKq,U\U~ .~u,4t5PS/JhDHo `u\9G} @چA{~H6l!I?A!&T,KJcQ \!d'* f̡ſ#)zNSlibOPFs_O! ͓yn<)X?WdcMuDgȁ }JA*/36![ VXH\@B X5h-.>>zc/E).1%tu#1)ΓTVD`4[_r5M6ܥW_};Ԕ0(I# ]Nj96ڂ-vvOS;c&b-Ed0< ʶ86-7D%?`bOP>̖LٖE ?BU߾Qt̔u--Q 'X%$>BJ6Rr:сXd'=an96D >3; Rv&w1f,8rNcA-et$3栦榣l7֎_rVȓbw?NHD ܠreyy$2ꢷF֋ 7dx&/YM@NF( wϿ7*Zn"}|?+-IPfu4NGهXA7W#2,MԏCZ M=ONWl.f߮_"g &w bynd/4}@{ odb]qQ~S Pӿĩ\  eވԇ9˒3F ϕGYP+ovblTBwUY#Yw7+yu.Chtg,r&4e*jLNՓi\Тf(uD{l"?.*#p;`} 5 Z T\b6.^߭#5iEGk6}EڀkĤ664 ;{ىJJ^koiWDWzmI "Y JR &;weqhʚ lT0ѷi8Z 3ip1Ôյ8a:٘d$.@I4#YDm aRp+_xQ(T$-X\-uM4ꗁ OkǝѸ}Y2f9 Qx$b~m6:Kyv[Z! pgڛӽf_L}@/ Q z;v$[U$OWaa\xvo پE2kgdO~0V "SUwtC(SF- Ee{&OaP8UMD^6+3v&&6AސMSV.ʄEΣzzPyx;=u#D ߧgd d[&fCˈ+<C0߼;zLQ ܡ I;F J@>iS#usŀ74Jk΋),~y:LZ}Oۏړ,PV38 " _mG9g2Y箪+y}h;XKmj4O D%k1BfqHLeVD 0'UK|sӂ fґy}~,!"\fR*V@5׊d(ޖtN%I)a¬,D^4J7-'TM}k] -"jՅye֭- Ry.c4 (]#8Vg }(Myٻs5Nך΃_>`YIn&XhN>z`ՊQ'8ᗭ%kE)E7-GFGۉ`[x"Q H^:癞7Q_"X%OOXKOrA{:h-&ZԘyN1۠ȴ&J}_"<6+ ¹_Ƿ$dHtakt&ݶp;uY4-4i;2Zl>?ColU- 4''q7|N!OCJM1 ߣPFJd8x%0!8a),2M+bZ+N,xkJ_m{NA5o7^+CZ=dQf1]}.0s {rJX\,)!D?~q?° odBjǀW_ Z&-a?ԧ^;ұQ2yP_?.՘M Dy&.Ridsh*Dn >/Gwp,-RzUO2KiS7 ?t Gkk"9(Q `6o= XLfl,ۤB`;3td{aU|XurR{B״_<~B`pҽΠ g-4p{n¡xW3R1I;t3 {[K7%QƏ?ua$~=ʎ&Oﻡo07ij伆E܃g`N7 35zhb/t62WJU3>5W' JMrCr J4zV n B,/|#Jӳ ŅMSH.>:r[~r4(94I %t@K@6QS%Bb0}nϳ8XULz-rd T̄CtV \P(I0_^:}+oe ?u׻O[|ݕR q&WXa>uARB۰Ҹф `G˱6ՋC??ӄB+;J(l>Tr]xYyE$KZKqku."Ehx䝵DGR,gF=K@Zώ!UxC(x&lFsTX!Tit AP c\Ե`(;éI I}-j7P]"Hqޱ@%"6Xt׉Hx~*A6mlGF5&uf!ߚr yc^}Rs2ag3>`;Xl%Q2nBh5> NJK#F'֑@mdi,0qvߕwPoY`rYx.D𴁖URfe`kd}#> f FYhg#c*rR{ ?udQ'tW\ѓ#b: LE^ AT<8Ti`nOavxOURCl#3BArS v5P|y`#5H?cU #MZIVTnC=q-kT  6|Y=PNHF\p0evՂ1}ZHxm0Jjj?80%F%TFd;q)0ȡݳUt sIͩg൚ot5¥Urλ&P~5ƒA /$MK1 h"Gӈʽس-\(Uoܓij蒀=P~*ISӅՖM o7˙>3 qcũô'K>#EXXӮN`Gq/~P$xqhL[b[$[lVEC/tPY mf]=IE^%u^QCxC)ϫ /?WtWq9S({$UMI{(ndϰo.Ϩ {)h^״&[L3 謻 4OFVID;RADP~?zOa;^Ric.* W\kaؾntR-Cyt͟].Sil]ufhRU%,:sԅ/dY 4ȈKx˕g)eg5WJm,B_VT5lgS@\G*!b Cc&&Un_0`Vn#lm],k Ɩ (Y\)kʈS{LnRK7j~yi-2 0K S*j|i6UA#cPiDfj jcIV/Ա>'WkI6.LVڲٗz|aWAf>‚lrb(͗Sk1rΓ༌ VKRz{E$'jh뫨иxN tp9 Jll<ȷ+%$BA8)@MD^v2ĕSH #%-XmOߐ~ܢsH[xrV|'0 +sF8+9:Z-5L]|,d"`Yŧ>D`:Kr>pjc0$\$ʒzd*s.!v}7#Z_x٣ \%zT5%QƢ=ԇ`n419AEj6w:Xi$}=)5EnOGbީ kWm`h)V"vE 05Ż#ȨvЌlģHb gg0`YT°<~?_NxBT\:ϋ8hvtNڼ,^7lu&$eJg^2>.C@䈪)`0.dp9Mߖ]cl!U|0F&mKkoR~?H M-2EEltl?pgx@M"+cJ:b)>dWAWnd\TWʈ x&!3ǚ߂j]S`R3H|J(DMʹnD>Xd+(ŏ's:09L(8^퇼ojU۸|p3\œdž=oNR!`xyQ]g=":] Z1KFA!9 #`F*3Pۯ, O%2 Bvzc\b۲FrH w+o-ol,X/eH·S~%גuPo9]G^#X,9-xev 't:u4Re|H)s  &E[I𖆳&RKhJR yjzŹ*;pbmT9qt$6Y"E%LnY"Cm+kR$s_K}מ0qB z+̜[CqqXgĪh_wv^upKHLRzi'(z{lJ,y-^;JS\z^r1teo dPH !_~@uU,EgQ6#lVzaO]f1ZG-*YKϗ4Ixk) ! +~8 DC $1XQ/ێ{UZ 7K|B9Y&v36H!D9zYBv^ 4H~  )cz#JvL@[%=7"H Tg/&kf:jMHpJ>Edd%S(9OUrEuv|Ʊ\\UL;e]29oS1g\e!_45TF Vj[ S$4\jVtN+[ 06 A(I(X+Q, zem/DPBR|"3Ѐs!kq<-{hj!pW&FD#. YҊ.zIavl /D ]Xba 2tqHi85PIrdM9ֆyD"y}GeGj7ɉv)>mC|/}nIØۻy[efo.7gƋ#a1+ޫ_ToM[ܨyd׸e;t'>G-j另vTݙc?38NUc_3`bwcX u;[Eh4 j ʴ$̫3|ht ʸٱIhk*Er2譤ͻ3f^ī7W\ êPv9i9znﳗhYRQydAp7Bl}|<9v9悘ڞ U~(JiSFGUt]C݂7)E@w"/aKMQ7׀}N_|;]=]χz. n{ИM ӅEٱ=6/iHL+- 'b9H){,NC\Dյx=>$fGj 1.BwH@ a}%RN8/ l3ya-;;mKs#K*2Fȫs9(=YXO_OEsA鿈,V~/1q W`ks-u-_<6P'wks0}PF*|(SN^Du+@7ב}9`|#",O)Pxl"nf0N/]3}8iZ.Ab]3'-Zι~™E\/:oZTw;$ s6UfC;٫IhB, znfI9Oru¥Fnvk~zIusT5%hIZldM@CLΡ|;5[f&[]m"$]_Bg89UPiJp"2ڵD%(/lB1wHfJl#Q~ƼӟO &̐?bu K"29V' yomm_xQ!7EFuYR<,KOZFݗ@Ku,bYdqf!g 8y>F},C9<f}]6ky_*6Z=/@2.7է'af)g%ٙX?y3s^c0;`!_ShF"4Sk^4r^IjQ9ZΘB;86ӥnHinm^ws"h@|q%U|գ#CA+q2r|7ZLtn2:Q2x59 :c+EdT.?NJƬܾ u<*d: 6DWRŵlƛRޤ_(T(w *8!v8 58_Xq-FٰW#!ꅟYOE>7$g;qVag&ƠF/`!QP} IU3- I~dHʧ=U WŜxI<\1 A"24ULPhJ"iȶts؂Crhc┏ʲ%GAtwJa>d3:َy<9yCg8mXQ`bYHX=b:D&EɃ=/G&r{[,jPNc?|J.zPd~ N˖VC7 XZ! 2dx@]0RЅVydfT|M'5vLSY\b6-ˇPf:[LroVS9^m;SD逸+(aE2ĺ)^v=C3`3{h~C]p:5`~wpԀzjTJET ݥ;ݦ2͇O$"MP5%gd 0c`ee'uŸT:7Os:3ww e , j`b;T2ADKڢU7}'7ɡJ0W>bwo~awXMQbHz{p\ص-%6aW'Q! #-Up(3۞ =; 1$3 2IieDN̍SkT<q yC./Q?rC`9mhiK)E>[F5 Hs\ebRgϯrm^6Yiγao"._ $8Jۚ7lLfi.Vg;ve;GրPVʎ:w¾[ʥ]{("BGgT -;VY@QˑjCb?:PiDY7߄PQ'_I_,~<TP%nyD_w d&YJY4,s v-ym29ܟunhYk7 NnqxyC$ /Ky@I?-;Q(CH{\J1"S9wgW=S|>F2;zq/>pZ0~^[.R) 227M ;^W['wsu-θl_z079nLRMS)V$|1WVY{Ҋ:фhO%1Ʒ"~ӷW,o|uZ8\*'q/.;ll75}$Z}XfL>K?T!)li#aשB20,$\oxc zs)lŠIkjܿ@ʺko+3ͯ1N ʙ4%ܨ,~xfxOo79?Bew|g%r]b %^SUάIa),/_HlO~MTߒh%r::т|\Ҳ4עXmc:/{TA2{W^)1Ô2(3lp  w0]akaaD[HNk̫r HVOz~iݗ}9  6s;/ݜyα(W%EY6JLkXv)1HC,nxDu$.q@iՅxk//1aLpnM9, Gig֋.+$"m %W̦1ow6O)(s R )4F #隯y1ܯ.A5c_+EVƅ [CW)ޥf:#4'5_Y_@y y s-f`pv,i^)b_]pOu,)_Ag2Ѓ\V 'WA l翎߻`Hg$t`җw:*\4-`ů@N,+YX&2y@rטm@OR v#8Fr:?f IVCȏ; k2,Zٯۃ3,;]Dc-ma˜n /r֢*"RkIN3 7[.k < 0 ^!0jh~ب[fͅ:G\Aa&r=M9(./ ^IJf@ dL;F;6E.r,F{ujӀ1s|R 2Ǯts;~1XDh4!ހXiHȯ'4D\G(-2^u1C *yFn&vZ]@e&fzSOLX<굱5/#Y%IKg*eYxxJ4x/yjNPzggdDQG}h+^FV0/1C>̓,F>i$TWSkcgb@\Cבxn'ш%/u<[f IE/=o|71^9Puf>B e<*+Whqb"\=ByAevkOಷݻSK0)!CZD?i/`>8HUdUY`OV}A9pV'Ԕ^9( b3'ׅ+홬 ppYRz]\{8E@U>6sگZ#綹8U]nv+զΉ*}<uJLV0T7QP]Y6)Uwd7%5T[Cb_6%t$z@C^gϞCݪM_kTYrqխT*jD̺\  cB^4g/Ƃ@-$Y"s͡=u"AI({c~IpR`A:6+Avp{o?)>%kZ-+oFZgeH\hXU4z1*h0sh(׊x3$ݪ`S2JoDjӰA ؤ/#z8VF L=Lj L+*-OjI4ګJ+5TVHiw)G[!~dR*4~Lol)YfbMdG_ǥd";e)1 Wtl yV p+0 l-Cr3Xd9̥Tto(L9գ`*& aGjk=Ӂh%{勮c5Q#FT RHV|o]#ixܛB5`kza8<-j?rl~(ѷ;P^;E5]m\Gs^vq]9Vxqfo?{g穒t $57mٓ ';Ald-#4au&#^46)siՀ@.qX/_u\]e0Jx 9l^,J@%m⩍XO<& aѮ⮺ `,.uΊ?m {J sPgB 3Z!N$ Tq2F9t #{P\֮<86KEHZ!K\;ܩ/q?$ȪS2,93d'.bʏ{akeat6լzDɸ?6 g5U-I1,Γf_XÏGon7{{[Pŷ,>BLK!ѧl"C@TdZ\v϶H).u-\"-4 (QAbßn6E*s7, s"}׈zK. 6ܕ2 QH!OU~?zO6Pw~ TAiwTa䫵rIn'Y= %ޥb8%x { L~Hjҭ7bF0iCא2c7A .owH) u@k?ebXBn?ߚ =ž|_WA_t\_rt'bE Á2q~]>o&[52)_>ZH~]yD:<&14 %yIezx5' V)bF}v|א7E7*jB`>7]eYYU`WFmWĖS>nYǻNmG͆L տDڤ9pNCƐU}@rMW,O&Cs-¡"; Z^Z3^Cܔ.$wzNemasuZC5b o7{J5pcћ0huН3mMi,! #Vݛ)4MyEj-{M¥bE3 ,76c?U~Ae}si;8h7kMZ+Eq|ـd8.?Gg\9DtA2j)Og_k;ndo"xf`2ަLgR9@F8)ARs‰+Nh ei{9=6^UJ͉xg{Gd=+!O8,u$wrxHNh6*{3 vh$oikܯp0 x-pÀ0Z#TƲu5*B`2)-o Vͨ.&8<@Jz*0-՞~aZeKx̅XY.(,/1>ս_(M"k T Yf 2Dx[M^&زe|%He/G dyؠjnQX+llr1_S[RɘBCQP؆|1nJ`#n1VELDG h/|'f.nmBKOukg誸" 8i k>g_4rm|7q9?,IBYR9ְEv  Qoӎ4|Na'X}2f84ѽK["\a|PO.} EՇ:}dV4A˔d3_aUcajyA!;򵱇YMBkTeY~o":]LؙBbw_] ?@}-F+*ԢАp49ܫ%}*CCQ}M]슭Ja\b|ʧkMྊY8"{J.~ ku&wyV7`|pT;wyXzV A+paFAA^/IieeYW3Tiu ͐Roa`,cYV7Tu8T<ܽSٰhO .qK#)ҙur[sȊ@{4rH*}fĬܨFd=4'N #|E7M :6*"-ޙ?^urXX"kN 0=J$ .0jRf0J6@,thHPAH[XƜbΉuNힱICTfI4XT(~5J*H a[ :@97Shk;s.K\_-KnmhsY1kdFH}EwI yb}P1wPFҭ߻lh/҂X6;?to0a6'ܨ[k۔Y 9x-g D8 `YQE|`8xkP:q|`  1^Cx<.m7ϻ'^ۣR񊥾Pʑr}g<ո< INjv(u*ͼpطVA+" y^!۱:mmʵW8`JSadX`bɡ뵭wC=4E H_ɕ~Z-Jd zHL>Hz'_?<ʡ3U[KfKټ z&MAv^{ughG,,?CATEE8 >ouI.ݘ+4_&SwnIƆO>/slx~*t|WhIK1j~٬_߰'MxGW,4+3DZ92C_0py*¯\UaVW+NyQt 'D*}# u+ q-Hx _K 2EOМgx5}PⳝS`TDW_n' 4fI0۠>}@ɻ)cLF&_( $Р>2UHa_+49_j)J;RjJ:֩ ^pNP tz1J(b >SQi;Sj )'I-mN>7X . è4;XfeNلg÷pTT 8# jgVjB* Qb̂B u8Hm#KO!YoIo׆1+fȟK O1}bqi J;cWgWJ08aW~%iϑwak)Oˍ= ) )(|A~cޘXcRľ}i nBNշ{? ‰|ӤɷIw|4`ƮR&>0#v.x1K"^x%ZuynB_ ?qo+R;dlGR%RS8ƥɁXq9M#+{䜂[~Bۆ' -~7>}\gURu7sm^t@rMRpk둜:EwNPh  J  W1p0HA aIBR0Ym >.]|hTm !wT87cGO@:cmjp/+£=7kFB Nt"?qv@F#neN 4j83"7 R.ъW~uA(K$wd֠oV{r z85]}Z[q-!y_~5m,rb.7CDfXsƘֽ)T hxKA& -Z{!!EK=T/m*m|K콶jZVT)ҏ@Vo=ٻ@aJXjCUN{ Hl DRSE./D@g>'AÿĮeR!f3QRV'Ff~/#Nb YdrL ʌ1<#?&SW~2M4.PK/%%`b̩don+0c8ξV` ˋ%3$*ydͩF*2]AZÞ=_p>db'b?3쒍0擠^Nއe輰vXGjONd>Pװ4 )3_߆d~ݴvTFt-uDu;W6~U2 SKOXHӟpߵkd0"<bd12҄YUZj^ʝ܌777ZİPCz>E/gs֛ c΄')Yw'wI vQpEytb񘎣FV` I`zy)cPW4(&)OvHր_jehY$k{j l.7J= 0t}^\qA^]"w^2Jbp)V-CYqE)Z㭳}~m7P&3 "aS 0@۟S?` &h1B0F,@ ^}T@YjNFઝ<)E/٢]rykJctZk^@W6bnڋyPbt5 z?W  ]w-6 #b+txs0StNltt)v2;0H% D˦$  a\u~^`aA37eƜ|8هXl^Nʱ;24Wrt8JʴWVLmV#vX-;i3 &;l ٥Y[ (09"4uEM!/R[~6ҡC!a'@q?pkZM?S!v!ʧyg+ RKuh9n*]..I:7$fĆF)Մ){J; ˖s>qHYʦ̬&XmL(|`>\j3,l נ8swM= M{JoY~:G#++p0h,G/D&,8[fuN4H <_8sA /F2"`b$/(X6nyF"KD>>ZNVUط2|䨨l }~ PsE1k?h"){QmBVV 0r!G˙{s߉<: wx[Gt9_WWho\H{Í:םtDmc.0eX-='d0t݌o@}GvD{2@Uol1r8Tp 3+Twt{@VfYDӕb Lv>$R?&+4p$XJJtۼ-x lV iuHtaq$X|yRUn>aIŦmP]vo<`Ư`:aF)_V*˚V34|dS:uE٨!Zr{4C`TL܏¹q͋\*.aE_6s{07UHB-s49wR%nuYIhXAZ޷N%R\.Pc ԉ+eLOʉ<lmԨhX?PJB Z{X\bna暰C<,s樑n:ݕZbu?_0mN]Z-hmtFCzzT%3e7d4B̮QlDxc< @vMM팴 sn n4*##{g@aKw,aBW,7=]N.İL:}_88AX9jO!hp:eh,7j^7>@hIGжOC诐&~IJ5YYHUn5j-6H[0 ,i#ho(iI`J t/ X8-sNP⸓ ~f ) G9Fb%PPy.cW8a*g2\}*{&>Nm2ȥeGbr r~pN%u  aePj󦥐1:%k{_tV@%!S̪lTcZ ֖5)PnݫXY%OO#zy/X|/ОעKT|hqs6RGAFT1p"_$wi>Xim_0/­n/Vف1b6{$x^Hv>sʉy:={:U-^x9s7F;Mi|owrp8,DW P`a{:NDo؂b\qل 2vy$@e}(NI XEM)8 y/R(e26'*wd0?uAG7/Q)jBu]xW41,1Hm[6B0/ vFɻu_ *|Q asju0:o-Ahl>rIF ޽/rR4ZǍS$O.ktbW4O\lS=:#84v+gTlv"w;h ]4 JAxDPXo] OG'*t fP{ED{ik/ [ yŅz'"F\8 40m twpR Tݟ`s}(e,G<[esHj)C@C?>) )Oc7jm=] &~2"jszV5ƌz5Rhźk EuF@eP`,m7&:RҾbA4v_)UP051#FN}΋P8Oycaј76Xo9TG "fqe`@0FYCU~I"Cuv^cVs`Q8%D8$cɕ/:2#6bҌN(_>a> hؑuAsns,bl|С|ɝkbOi[9& S#F_ȂR(+ Eưq:r`aV6un@. Q.cij`!O'me4nX}[SMȒ܁R%;=V!:[ kk:y:VQ麥=ZIR^1a9.G|9lRk൲pB-mqk#|I<0`i4yқNɳV)$e1W9!1Y!Oozw=iB`DXϭI_ٺψxhbh< qm0rɠIL<ѝ|Dv QJ͚\cOpmI/dα (n#&X,H}e/WѱtC⒦e_C />9hlc.ys^gz ~ޑYf/%5# ED= Yߖ#7% YQ!1]KJ&t8 e΅'D8!Oh]oU'(v!1:e=8,C65(2CbyomuR2@DіT֔uZmwRÏoEJFnCV@Z]8;wObq n^6eM-c3.kڙ fK*^ U{ډ3Bh +VY1=~zsۉN \8EцOԐQV/6zCH㦺 h1H7Q}*9D^: *s'05~9;C9Mb3z_4}ie 5xԠ%@ u/cy (j}d hK#YʉQ&*'C%oY3D2kM]?f.*zScDe">n{9,q҈ UT1'HS }9FB) ~cGn2 FN|庙%{`XT9Z &:RzVR)Hĩ~yYz%L. $6[ؔ"'"7hRx*t`3z'1.\QoJi4"Z4)rNXtnh XkP؏Hukobgcٱdjtg: ;z=\S`mm¹:Rjy$bG6 ZpFn3w@OVp [7ȅE苖<sZ̍9 Fwl <*9v QҼƂa3ewfm%r]wΘJ)d/z+.9 yޚĐ)`8/h+VW%)oZaqhtԧ5u:I )/_ vJܧ^A::_u_$>pJ+<ڴ |@WPŒ&w}{m$5 /Vܿ.( %g=w5QwoIZiΧfM%=# >;],cĩU2#5GJh?RmOF ɺ'\ LU\?9-S-.xyI";f@r-P%=6OOkzj '6M5:7ƅQ[)D{n>dEԹ) ]UFCvvJ@77hDUyj! /r/8'y>CfC$.S#8]5+4:Ni>9}OF\"]X~'O1\Fik)k'o=A12ƹ{Z ., 6; o70P]UaFOjQ _Z\{V t| ӧ/wpDv78X}U99+?Ģ/ߨ3a2XrNy Xy:~vw)o&~6=72oŠTh$o=fR>gr܁!a׼e3D"et)d8T#Gַ9up~QWJkZXmɸQ`aRPtɡrHGcfXd&˪ 2^AP47Vp`0`1U,,!3_)6u'@|? lg.&cC&NȤ4W ׽J{RW>mx"!: g4[9 2@NO@)/$ ^i>> CJ]ȬdߙqW>ꇂuHoi T+=nf)QIQ+pV@mU.kZK256º}@FR&X bC:I4V0tW2PVU 3FD W}?|E8{{{g$L#>\e<ʖz_^C8al7gb0󆙫/Űds >+@Y=)O"?s/w+j5kGG`Gy{KiT<$ "}wiJ`U`YCkx. UԋԶ,vo62\!:@5on|;o4E/&6y/--Ŕ-%^dnSLj像>_ETeԞ:~:|0*yZgyS'Dga[~=+WiG<&i.lzY )_\4/S+xo@JM%NήZ"9 կĩ+BQc5=q#`1i6OoJ{o7}*JSV_d ܷ;3ś W9OB?U`7@1s}_Ux6:_5G@@ECK[{z܋ӏzhuHW2-_ 92䏛?G杦HKO?"n$(M2#zė iFC Ff6}J/xcFE@"]x5PuuI5<ҙ4K>T`VQNd܆[ғ 2}4/s{IS3ޚG7QE PFOX 򶨶+Sx* +5Dz ]׹sӦ T,cy˭0έ_Qw!,yl𹒆FfX n}DcLb^*oIqK'^RS3S3-|ӍF!$ 78!ҭ eTc$dȣ!-HyXjf {5u׫ Yy.<Ӄ 0ܗntZyXnkE_旎&T+߭&syA-;6GA@C(3BO!xy$,=vvj;tt$үP穐p D6'}|kC^}M L]@k[2ieŜX=@4ijp _c'N@:qE-a+n^cuQ$b=# `Ms!Qy՟uozTaE_£E5U߯N:ㄎW@HIfIll[ܭ+lPCeBk,.-j崲_A{ݚr^סu`CGjyڹ'gК#|zϓҋ^łIXLA] OWjC-:O¯AE@֤n062+|D51y Ra;Fh;Fk3$8I`nNQG.}dcC2l'[~K' )O;%#EyC"7)C }(?O%`5#Q`%z z\R{,5.^?[KjO8JԕЄd4d "ˇXPs2,F4 Lkڮ!l`? #˒-Nҩe'T;fÇs^gX1\Zz6sOM8<\Xv^9zc$xZSxoJhMC61n B3t%̌ T`)#ZǷ( %h ;;w vXz;4X8gI 6Y@3D&z: ,"UQ p94cދezHNz媂u",!  ~n @-q=ƀ͖J-\SNO?Qcߨ˚Jy.XI4X2+WE(/r^UóGE꧓ ;ʹq`/"O(ʨ3m-fdw]&W4~99<} 5k}|^@u,[+Eu,~CsU钍˶ꘞ2driï췌®epq|1Vy>'л;,<#,hxsVs:?fATf5sرOxAw[y 嬢(8H<`r]};y8 Nz.r8Xpwkڼ/{T w4b-_YR8YnIY("5K93x6_x_t%朚T\( oI*> Noo&j(zpꬦU>0\.AVM"8kųSӧXXz0JU,v)#lXKqVKgQ6=BBҀB`o$E1;r2R.' C6(NgsJ}qo뻦vd-Kըj InнѦ6&V))%7Y4*9O`R;8XDAuh:C F-\gƶ=hU1ͣ$:k3y.x\G pAPvxmujZ> 0 hiIm8Z !pa}YzO?2UQ]"&~bYNG2l4kq|Ǹ|y4+ Yyb2x!};x`|mh8qJ+KlJd|iŊ0=(n $75sMB{lYC;a!;Uo 9dצb[o@_J}OwZ|u6";GqR F2+Oz,.2 $2'_2O_ow@I@pq=ԦWbُK$~)(9RX&{׮PE<4j]K`qihNl'f6hۛgIeF#Ad3R^{wq{js3iob'֨- ϫN.Ți-uVtSӒ 5|Ok9[saڢO,k蜀@d*c/H Z'FqA |m-ORsk`Zj[IZfA_xaMCYi /MItk_ŸxpZM|\*L)cZe&u &f2_uX9Cϋ=Kv9g=xW@nZhs`IA≨HR(-CNe,Psˊ {pú7.SiOnTwP>JG(k 7UGS2Q1d&\?Il%f٠͒11Urd͞ػ8B!qǺש1 KN+KxzwL$ސ[hUeZ]ۄ|k<&8_" L5͕B.xy}dɌˀʋY_Hoө5AZ;weMvؖԹ4 G9 [.08A[ʽCc(d7-/iVɸy<^3 {ok_0W2δppr e;>C)HZg"ŗ+[%T%%a NKEC8c9en0G[>Qq'B*Þo8Q{KS/vN(QeP̳3LMس)#<`vkrb3g?#Hw k5wj*P}9);\ujҍ> it%0YIg\:CG[JIWICQI Zx EGk&I:')Yh^rj?O䮃Ȍ}%L,[.]c@F&\d@̅ZfM;tR豺 ,s-oOI:0J+VGd)6=Y*q\gO3U!j:.GAc%Az.qHPԉNX\u4=>Na%mW;9_4ݖ:r!iNYی E[dciXl<x _BʬeSb#+V 6 H/O;=]^D +Ω,2@$%ƥENDkif,-mtq02dǨ.֐%$&NxjfA(*x@hl3ݔB"t""W#Ӑ l!ĕZB_#kRd E3n <:]cwmPﯟu ՙj ʃ`p3-6#1>99 Pp6(-:B ëG\~cwd," [قXk;y C2ٰ12_3ě+ .e5=u;5 n"k\ erCŝ@HxȤT\pDl/Y EPK@˩7.>-ryDlg@ɂoRrp_K;]^#?AZ߷s:gظZ!Ev1O@vgŌG@~p%qK.ԺZ\ ez31HȶT`axˌM^gtȃ±$"}34KH YfTSi4*nu,GoP*0A<`'Xdm#C} %]RAILgsb&c> /@3^bTFHDeõJH:u^>RR0H8g5fpҤPujJn)~Pm4VCxzgTR,q`$E|8O6é?55 j71oM r VL ImC6zy~ /ozI/2X *7ʂSxFMY#qf1ヌ/"/oj IDĤ$Ӆ5JL3Sf^sf@tk߶F J_U;議Q#Yt:B)[$:@O?s Bh ZwxlF5e:/xs˫QoG!aF~3ӓQ)żl$A*aI?C0 ͐՝V~@ ۶"@K#3ؕưM# 10[ 7YPWW6܃=1 cp~ \T'TCdzH7Qo^_JP/I&}SnPւ抈7(YL@ZgaT,Bnk2E㟝eb#~Pj/i 鬯8wHxQ؆c}RTeWõDNj"Bң:ͨaL1c.@ d.P vٌq'Nx`>zdy2R`3 n:wmJuEO~_ǟX4-QzX!| +`Y4u,,jI~u6ިӻ ?~,\/c9TʌYPI!vOEǴ+nkz̺\ q ;xqCmS=hlnr"#=3?*M&ePI2-KX_֋HˢKP=?hSڏf."D@@}ܐ}@d0,+;Kܭ*W+TJ \\IqQ?9x`DK#`7: L'F^3Viu}GG54n$Gߞ-h 1#T'c0CЦI_O/}~:Q𕠠PP'_zuFT!*WGuO{K47CkLiјZNkldQͯo1.O\W}P~zMw1Ns7&axS0k{6m*U0Jq*^k!͵Gլֿ@P5|d[/sLKtuZzU}ðO2\jrJ}ڤ,XU%Je=YnH1q2cm$Gi_V Le"L2-}DyR \?*]^ǀwMI''R2=@E/9N!V1Wa]PG}B籵d oHwSvh fRɿ|{['#ʇuIA'6D .RIf8kD}( GO&Zų)uWnl$*؈ D [ t3c9}S XwF,J4'\xtgY4y lڔ!n鼂lӇ(a,>n-5Dej22PVHZ[9$C؋Q,8aޛb:X/Ň!r+o5:R֘*d ѠJA|ˣDM}#`A >ߨC**zȎ\GwɎFs`?kW獐"٢PVhdşEYG,3eȆ(NVM)'CiBط;t `; =p=׉u.pi󚏕 ;sAy{!1*j дEl뻯 go Do"M#Jb.6FVùj[@./͒;B8aCL yuCCO3߿}qY6(^4YQLn`ߋ-i[H;e4 ę2 WhvITEjUi&*qq"|K}oy>(M9\ԶX*o&x< ds%cs¼~]jJ& oJ^~- Bi1= \Ds%[23&FcM޽O Nwm b-|"~{* _\{\8/0L Фxy' gWkPZʔ}&e׍Ѯ0H)eeʙ_Vp~ t;Tu|\]YT*)%Eon ' bJ-J.*3 A ]q[K  S2;"d[7Hfp;Cgρd_\!`iHcVP'??+l]M, ISE%3-(TƯ"ÝKD1'HEBC}P“aZ7.Pc|vY0,=DisU " _r!-!{'kfgV<MMtM)E)Χ"7m~^r!;Z93j|h9 =* lI ;:zRø )c)O75c爐2[kGI)vizpT {'dXL^(۷5idU9y!cIͥ<Q!3價z olefTc *~lEmq" ʊIH ^B>SqN Vݖg (ݭpHjΤȻ ?g54sg@+5w4ʶy[^6D'PI|B|MX} "Ҙ_NIwV[t͏ 翏k: oS4%JDx\"I X}w|sfUJ~P1]pJ=(4qq;>z`]!&)!> |22s ŴGa!&_^H}Y6 BJ Z8K.H@#zڙW+'S݋5ګJV@]u Q`AR] P#]Il~%dl40}D0@I#1sDo=,zV+P 繐5vL2m _ <eq`Ñ%$N:Q4CN>YJ54~D!VSY@;P06!RE a Ka&zrxӬh~xHo4L~ؿ%u$f~>z]7]"J\pʵ^oF*1?'LJl{Hħ2 bH\9R(^OFg3N)M'?gFr>K,9İ:PDL $ # I|6@Isu|3Ct!X {HF[=S}дV |TԸUn@-z+d>*aĚJ5BIo#\}Sf(g/RrѐlCzCk҉- Q Eځ4:W"l ˜@܈j\V@#ՙJ FH}E#%Y|_}e: lE3 ;)#H,=høb&B9e qM᳌{cNo' p&xazX|I$QLKe@>g 66?55S5nlZEw@K/0FoNnf{\UhJ0ƪ-;oZ,q fyBҨ}جu4f 0i@W%e $)Ԥo2phij۽~!UyT~&Ͱ Y#9zz&7*/VD~ʦ 1[d1g4/P2PG2}v?.IxրxKr T?"Bi$$D x-X؟뷟gIaXT7P'~].Y E2˥&vyf$UG-M 1 QaU:/B5خPE!h ud\`a Im%>SXIUjϚGZ-×/.q8Z4)pLj>4gm3KICCmo7a\~z$/SJ9^;H&isSo$'eЧRDt' ni *SSh#~?I'e{V]#hPP*4(vLp Bϧ#7 Ԗ`%<0f[.#yE?{̰ߐf&c L52))#Zs4`E-—+u;FgHOMya' F_VzHBKh ȭv,Q7܆nS]5(=44B+Z~`rLdnr'#nM%oڤL)0avQ0dkfNw8!gdn+"Mq[bTh4^r>CW⧆+SAWя a yq3 D`1L?#!Tx܋**.P?lJ;5U!/aϲi=Nj˓ĸQ!ypD<|~wąO&%I#w,`y&9SlJ1lGIJoo!niMK$C]EηqM2&U8jk vM < D?G t)*IJ+Ϣc_iTv]<>`K$s/x[ö́(/@vwՐ8U- ӑ85B(2tL{t%Ҳ݇]Thf^Nn"̬%5Q,J}1~^5vZK8lS<ޘ(tVTLׇԷ##_A)]nqKh;[-TJDDF~([Q<f[9esZ](]V9=vP795gʄJmU$E`CC[&8H_ 6WxWgvX.@勰6z܁1 v!m8zgf[1%XR6 a~ViEn|5Ng߆ d)ܳm߈!PjX 45%.^^iB!nɻ] 3`;V0ZںxSiiˋouUZt]<WHt^a4knES(wj($4dyx*4-KzXiE 1Ϭqmn qEΊnL @hpd'ƛnF7Z<({i87=ˉP1 A =3ƺPp (&ɭXS :}"e &H_W#Ɔ<aĨsWIv\_ e'x]줱E +Zs_jbJћEZ|DU3PT4g$_>]+gX Uۦ?UO 3n#5KZ0k\N ʞF/NJ\!&acx=;w@BH4U(m~eQ+C~C Xw~$$} mv2!URyFq`|ؽ| a \/)g ZX 6;^/C`n8dzJ07יB6jA%1>܀Z"]RKwŷ}AʡCZ<JP#P3dSY br@J#͓*EEJάDc0Xe0Fސ Dg"r!9h^Zv.C,Т<⋢*9dO%-Pvn_qf\\z+lկWC >Oi 5eUL~$#9!"u D@ʋch:.MΫ zysK (UT,v9&TKl/>+-4Xz&B"1EȲJ@fGcuO 5ڝhB&=-qOK}D`eQȠDL n^>;)T? y0RC84_4a rewwGd5AJ'ASSsh?+e&8GJG+m^=Ĺ*;:ҤM(vPϧuYYs0SQͥ마q-)yKꭱُN X\O+y4ϊ7HHS;؀ʒzչ%EwS5vd&cTYf0>% ¾1OEc#@׿J76J_W/~0oM#. O1Z wbp^Zn7)RsDÓ])kUѐ[3dj(6ٞ{+ELB"*qޗ1@ݥ9\ш-\H_UQ{v+`Fh$y9}(xNP7~F׮ ZE;}h 7V *|!\bLrq9*Er? C x-luP]ۧW,oc趥_ĸ/%h)폌)BI'ILenM[=62+bR:@.=T 8{@u8ِ!Ύs\i[@ %ɲ/ ]nQeۢ_ I ˟0vn$ yj<ҫ*fGbPs=^@@ޅS D48ʋsu5;cnGM'JnJqA[)MP0sp;)q{#SZRi԰i[rd_][}f5ipwK VKq{ WSV:ݚh{S-X;YU(zb" oa韏?|',f=d.Z[+|vwMIqk*E~8*PRhD!>^J!xͭ7ت82ܩT![2(⍘y%aJK@duOXޮ X1WGi˘VЏ¦V5{&U$Ac^wލ*^sI߾Uߥ^hm^E={XAΠ,@ԧdy7)W1\*`?Tl;~Jcl| dϾc')8'$ 1\ih+)ꥥ&s,B/C|"B|m JKeeG ors|nxy^n.<;DhU kB. Hu®6yoD>RlG~9.1t#Ix x p@/:'MiTxk4ggPLA\0YI9 NH9l"j&ӣBfEhrs -ȗrFD&,/sh=%89!}34^~l"O6a^m^ⅾy ;YGvCtE OcFˆC<$':v|pOWHr.ղio Yx!i FZҜoV6]Smjmv3\f!.oy Za⎹@N2lV,fMHARӊ1rHD#@W}3b5vڔOo zYus=ՙ`ҷ8m{C²xd>8Wּb% ]_;2^qT`tKɆ˝F"6 lf#ސc4oi?ys&OSq*Xk(Ts I  _IJӂX(FY'1~u:Bg34 @X^7I͜nt^0qDT>d oAzn RQ0AC[,`)F=, drVo^YgzT@j֎?QFhǞFF/"ș ;BmM4g''J~=*w2'2|LzLsK B^u"0=Ĝ&\ٽb>y%TR1E^]_DgO vdNk Tp=3WS Nݩsk: J(wX݋C Ջ $x>Y3|iRq]bO=,1*1PbT`q]hAL1ps7Ŵ._kdujgtmM*{XiAsny8Mq.ѭ3Z 5@OYL'स6q->Iχh% !Ie<zj8G  ჿ®-Gάg! 0G[]ݑ˷ʖw N0UeU=H4s>3~pvõ vܲpNN˧5f"h3w71.X2.aۯW[+"{|WYST xT@&`[IQPza@ =Boq4X7tHs:26F/:3kt|ɪ-}k ^WDBS(i.I}7K"LDj{,f!rMZnU(y+&o"f2Wɭ-ں? ]m׎( UڤCe/=VL0( v5!:c 5L 137Ѽ[NO{]=[LЄnK[ohᰇZdK5 9yO :C@zDMd.sZvj<ꪀ#7YeyBt=uoy1rX_`8m7M= xKڱ"8T阏Ԑ tK0$:&]F *c+$ۃNh"u9M7+xtclƖaX\jOJ8}!7#kR)krx%e`yn^!BM03&9#^q8@b_bs8CR7PnXAMvP{2tێ<f º:=Łn}WLl9a2y*k7q%sTGՃhlkD2vE"~W#lk~PX n0|:VwwZ |\ P* i+CZ,Ѽ68ta}פ*puMl{v`(?'"ˁWO[{\X5< V ID'ƧNSԵS~Xm-VWWV?L-Tj&N# jR" ,`9`HZМ. @Qo$Q7^W]1##A ؖl@h$EEBopQbǷJh1@B+,@HFs`0RzBg*At8~yosث. ?ਮMW$0Ie.o1;7dkv?mZ[tsuun|5}S؈޵;:fzg1?V,g.Lp)f<NjfxOsaք;µRu ul[V'PU]3 *P ?uB]G]gVn/h4=gCG xHB%PRm~^/tNl:r8A@(&jUmwxOӁp6pNK=آPme6ZXeX*. S(xd*`\zXịdF+ jTAxRk1ZGd=]0ZAy]ecU43A sSj[!%'@2L:jTk&`fIDθmVNlb凼KQѥچg񐂎o8#Sq@Dgv D^UT0vJlchbQwc$R ;I*Q$5"XLBW&ԕH^hS_eVan=82$\ ;.G=dJgEW?aC׍ܣ,/.Zp1*g<ޚmYX9~HUoNI{=oEծqWC[v?z yTS *"oPm?5)31 Z<?`PY6n)U̯ˤàͰ'Y1# v-^IAi^ f/ukSߟϪbۑ Rd=O-TvDK֌e,72K 98XR̐eP9EI#+EjF1䣓mߡ#q;GLV_}6!^֑;-̬-WfQ^|bUvT:n %vcyJtf?=zj 8ue%6hCH o0B8X0*yp(]I.jwCs*!Kk\@"_Z J'Vl"?@>tUdYY!$se#0:EsØQiC/l0}?UG B-d⌜wZ? -ri mp{lV,?dqTu.E$WK%j V!uq=38KD7Lvh;Et9忤PY454W. JS&ibSqmı-0T+~o%@/иgJgL`{Ǟ#sx{1@E]jY6lֳ9_4%9+rm_+KE#WtKuUV* 1$^D0, Y&cSČ,Q ]ٍ MnMtQH`XiOHFNpwȉ[$NPP?NW,b,q ^ J ~<3p% >6r d|ABȋƄUZ 5\KٵCvix!3$4[F;F^ޜ)>G@ 6(yXWʄZޖ`]g58 WMbh&U@*:C)fجTUM %{rM`ׅT5܊!5]8-f{cD8SN–!h")›@-# 8[h65cWPI@|E;bـÖZCljaptnh=T)noOA=BĤF+*GQy;xgߌ:0M nGۓz20_F-EÑN ;},^ Rq6{2mCnFk@x]9vl; I*-˜HbcW,Hv ũTݡۃCjj= '8̍%pY'<5~L$u+,Eh]s꫔/w .6{ xATyJԃ9b w=ݡ7U4]±_p*4~Tᩂh%UgU[ZanBHI XayG(5 %}2\i8zi80_|ݫca%Ѳs/1SǸ ~Q34 C9Tm(W{`Z@ `s0EtGC n6?G"Y'qN0TI¶G?*( <%cmNbl&>.Kń5'踟bCت Ϧ$g#\+[s,CMn g43嶔VZ!P<{|熲e!Fox80u~ cU> H\krI60`z(/[Ik='< /1ʄNhs4>yix_4Y]F:"aV_<5)[QrXR\S\X=FX'jL+%{ Ұ^N;ZP&*g-w dwD/J)k3M?S(C ؅n bQ)01@ɘ7/)'yrIZf@W~vc7~Z()A.5~[!iw @SR6Ѿ#/I@VL߶Arax:Q%eoh੣g(h=;JJ7́^F5S zq|[]0Ft _ R0ڞvy KJ]lVL4ʢ[յ$5<^+!: P#b&aF)Cf.vYɈ1| =N sh_FÌӕ:FӇ۰&n``A3D^>v&lJϨH4r> d:պ̆> J^b\ PsH+%=ᲹM;vᇤiчƻ69B[$MoF:qk * ~.u׏+X6g]jNmhxR1[+L^Z{M422ޕ3$@gcӔroIEi;-c˱?%n`xyi Tf MIm[8."֌K i,-n`X~EO'_@ SL?hzDc?.'ޠ?g:;u<dpE&wOƪ[(8N_P0,booJ˾zj?Q>*t(N/_u(UhZml Sd(aKO-8_*w# =(g~#nf K]"[ү8vt/4B$9H+%#cZ-@˃XՊҦ[P|fjc?Pni͵G|"# }cN}K B1}uZ^55Ѝ8a{"8?lta-?FOh/X,*qX <{y-24eLwʕ8ŊyYI\ &be#uթ m PA|Sλ_ ?.A! ?6*5񑉄mYƕiӎ ;os=zK?]ĩ'ύT.&س 1*6д1Bv$-+ŋC 1}nmS4Η.bT9#Ng膘eJ[f3uh"a~HPH{k );ؿYl8Ž WdqT(o0m~ bx ɹt% yO"4E̱UJ2yy'QbDnC|`$!8.n0wf^>MF &tlda6PtY^}S nnN ٫Zٓi>ުoDEra|qs3A˹J&|ha( 8J^Ƃ_ wiHy94sXWRgK` 5\7)aZVT@61woP_@;+p a,}%V]@1"'nOnq4m9"|/ ]hAS`IvJLgk3 y"tҵ5ˊ[>DcZ׹(O2~;.ov DZC sMptu4 3ie3*Aӓy_I! k1Kws9Ș\ z߾WqLnڤ5ajG)1x\Lf#/Tx.,f¡qΌu'E-@d$%>HwaװF Qw^.yvvl,-41_|sÙ(3U%Y}M:'w$O (8f0r02#0/`ϴ4~as݉sJn~ʬ/05N''~$9D(hu)܅M+:;VErAKH~UK͹!,h:BUfA;LVaeJptAֆ^Q! DK<(5e_pMl-yqw8lg]_UH<S_3HaL$MT(+e<* ;E8$ZxZ`#t.ޅC/R3)8Rl>~¯W̖#B瑇B̊NC]RKPFjw'7|%0֘J$% z[DR]v*vx ^GK0MI~NtcTңFB$Fa @!\N=86 ` -]gQoM@RrhAL :e:\:+#3fxK<>aEd`2) ֔-1`$Diǜo[n GҤ_>"t qUxNz1+ gio rKc7I/҂P؞>mTzpEf ]ER"BP3`6̓I!-3( }l! H lq p;9u8#n7g03p-Jvh 6%hq]q+lX:RlZU1DqNC'5M,>I-oIjbCJ|&(=FȗJ<`?'/XbAJҋrҸ\E:bb[i$ɻ{ 첃OJ 8S-1O@pKxQi5aAB~cG^d7UŝgGғKge^]vSք:zqnVܴҿwh\vBc:-Di6KB ByhMl2Ό_r)8N!.{D{;rTwko 8L>]ց1,-)k9GN LlW7&Mru*t1b#lXr:ߤ^n~gXկf8^B( atC$|_Ea:+܅ҍMmD?㰼JAY[ط- 7kxmsYAxe̖uJQl3GooQ[Cs΢rG%UR 8W-˪|q]J]ۢM/Z{?Շ|DkGNI"0K-Q)U(]ZG;!xAD'(/˿ZOcx)W;37pWgcL6j Ez"g+-.C$&h_j$$d|f$͖ayiqm✽?Xé<ְsHWi`,~e >M+|F8Ɩa@:ٍͭ%Kޥpr8o6 hx(dHn݄= ɛ,6 "8*yһ0ʸyp[RiF&l g| mp/+ulF\Z|33:]Zq-Ա<:Cw?8qƆbɷbCO=|;J.BYoWj|t|FԒ.#̈́+yz[DQhxR# oldy*-| 1_fGѴq!w[ aLsRǻDܧ݋IC8&7h=5ʊf}Yu:¤C85m**a4~XY\nMP2W)K)}ƮPU2f sH->$&(-߀Jʍw )BEE>X)  ]٭j5+U:cd^9-C| 7nM|&=;]7Z@%덽" Q~ԙ4|&D)mr3JȲϱ(5}a|Q 缎pfM%8a:+랢 dXj{|"N_PhsJ{8ZA,3̺x$U@p#qWBCZ!8>f')I{Nރ'~܋o եt{.~9(m@YmN"!"1E3<e+y_W,Ӑ@p0\]_a|w>[qM=D=\yiPj N?U]o}^iIgD-XT~Y:(e?Uy@-}p5n/+'_ФͲk<z%tK o\q!J?ڲ~HhsM(zH:Yjh Ж{,͡9 >Ж;@Gh}=ӟ6iOJ'5l|A!ui!|v\_4e.aEDwSŮ-'N& Ite*A4S)i9G.Pis.'N⧚̷l͘L/X1L m]ks}Rae}mO ݇!"h|\Fk`Ae˷rդ*PLWr3% 1DŽA $^;a[sΖ^/V HSm憴ZUdX?Xb ӨK ?F.сZ%?K o dޔa|.ϨܙsC%P0>qٲDrLs56Y,b;z3w0\/T7t_o>܆d2Dg'H2J̀B[{Eaz )x2 GsEhIe*s3iPؗ~7nKTYmT=}PB=YCZC+dš&a4vn)o=%|ڰRol:Gp%t~,O:i@*?O}o ,[Xs e6'H#x?#ZujYPV=3ɏ*wSs~g7Q4 5(O :;ɛb: ˦XsH_ ) 斿 Pmxi]ȪZf1LPV:Rl;И0pR|R+3L" Opc6mUtϤu3;T)J䒻#3#B¾:\ ʌhѕeCC sOZ(6,7±WrZAen®ڪ&/*'QF^ hqȑ܄n]ccV d)(cͫ,6i΂Rf2]Z͇3!^9F%:#QêQ A: ?kjdMuȓjĽsw]Om6.uus6Q?ofLmV+uP@e%KCEFHg .D.aZފ!HR#⽱p?+xxI?OMs.Id^B5`='$kC nD@ n,sB#?k!c~AS"\y+|-V]PVM9Q@ Cafnì0GۉA%;vQwSQ uXA!A' Z\ SX+'wm7L Gx~@JwT% 5Xwvrф H 0*,+Շ _E?|4D+?Rmb@Bh0-md, nhVtmǥrQL~p: /w-KS5%&r-SﭚKT=M=~c7~r$ާ: ZONSBEB5{qx7.^fdI/>c .UtE6bGT`/)KpL{zsaE?|s(f-^&L}5a=E5nM2b_:l@*sihvӵһ.zru,bcՄO8hAA Wi2 NS=`X~}R?jd&K8'cLpԀl ŝz?SAwõ뺽,5+?CѪ64_e"W\VLY[+5wa3 @5!,dlUQաRYŹ=ZD~ʔrׅۘ?`^/uiY /qJX6xᬉv&|ß̑v4n(z3THݮ,laIwS+cc1c+icc቎o.BjE5)5ZG]>gY.U(=.@w`g)"4QEf*f+T{EV$mJ󋛓k T*-=n8oy$(uMXzrӇԮ> eYRgmˊwEԸfVZj|J͖.GG&ݔ#vm~P 0Fbc2,(K@ZQ$XD զGrO̿!=޸PoSKBGg5gxE+1S8|2Ex"[gy@.n)ugD\Dmǁiv22Kܢa+0x BJac9`8{c/>!M!ۓ "%LGEE : tn—X*['.ɰ/=eHB%t'82AW°xHFB=P%0#onɕYEAQֆq~ Ҫ lѠ_ K[VR^9 Z$'rѥhc9 ZTOOM\ pK3YK,>Gӓ=1:#dM* O*:)MP3#=h 7;6^ZANB%O_<+B\cf:0xs.g*E{c+O}w|Ԥc0Y R1L3 ~x'R0II%V]-EnTO(K*UYLTWlx:mR RbΜB"Wؓ-HeWD YOl:&w)d|?s4kCoeI®(;DDWi @XS. чS.*|wT=OI/˄[xB}`E &%kw2WjɊf<)I0.2k+5YƟepl .^NCd \NJJ0ݑj^?Жs gh[Bt .m'fډ_*-ErLZUwRԗϿeܚѐ"~6 ӬuW겎O*ՖO>bU0Ŕi+SI/xa8Mۉ8nxTd_V\vw=)⒬fD.@{# X[ ct*^#4t4q{WZ5up]s_]\nFrЃ.͸͏ q:7x]3z qg/2tߨ[;g6*ҋOk~T1ituR2C0n3eE 8qZ9j_װL|: VϾOC|75%E \vZ|M/ ~c^ڿ*Ŭ*aOO.ՑDgnb(f!eB-"; BF)Nx`l:BZJz3*o{B7nʔhy E C'~hwAN[jw8twC?NeAPl`-t$,D mVD¼F嚗-H̘U+gb5X-Ūaޕ}=xr2*M)DcjnDӴˠJ&?4<ӿ.yf [@B OvzMv+` B6ؘP2mq2Cj8I?~s7Oi &!i'#^ 6Hq Y2 5 -1 ] }$3BTU|K,4R+⼋~}N nR :afA m1iʒizzJ?aYzb2qmzLn\מO+WU* ПѹeItS«E1S͞VN 3@˜b[#Ѐ {jG ;/ 5wP=%p>y}G|n9hAoҼ SɬtKJW<*i+[ b/ V;PA苅{0[fM!Л~~#ƑrD @ hĺVTɯFQ w٩'e<:/k^AH>Zi,pT#tH*M,!wÈi(OR 1IJxhDZfxe-&TRo}ؓ;G,W'SlV "4} }QXp~=H-zEsf:tmĤL155)1nƼ틮CnXgs?eBaB`(JzxʴZ1~VM}Yc.8ˉ$S+[Q.31>AsFkRoq L )Vl\ȅNcʉi%Oj)ݲvEP>c2dAYzHV9QrJpquӿ~r-aߺPL.HA֥p'vFnɥ; {4N%b|_L%`B^Nhij)[dž$v`n:S tca|$h"{lY4IG@nOYCߊ:i3bI꒎8/ \"Z5ף{a܀&/-. U $ȣ(}Yco16 7%Ӄ`㴷eKvpA _w;CYTC״ćh`+S4Rυ5:"?+[[k9s6G|TglE?Α[zQMARgL&G\(asZ^Cm+pobM*4BgUR,T=527ĨPwk *rߖ"ul+p ɚlPvQ 3.0@{ɄIf0urf5ZTj7 T2ϵ){9J/ 3x5U.N4 Qz [9;ˠǀzi-/d-\>|ܸ2((&ӎefr=xO㤇Xz/y)ޚs.B:hYUeMUu1T)Aw3Wg,:63@SSOuz%XL>cye '.;Q%ͅ=[h SuurFxl)w7W9Ҁ;>ʷijDZmTx]ky]&P.H7b٢lv'4YdɈuvM2{IIJm;FQ9=ELgU+!Wn!!𧕟L8 a9eWL״ϗK9m)!1B-Q ZV a56Q,X~܇2;n.z#WTJeB렉Jh՝v4A|m>$%1qaW ϤѮIZE@b _:$.O**!Y_]¦`h(t\N#ٽl騕6ͬD|V\*g8&%1> 'Zc5mR6Xa|TZjNMKGrhAC SKz/Q U"!Lȳ$>(=#4 o_j* [Ѷ YZ