sssd-ad-2.9.0-4.el8 >  A    d6RU])TIļ{> fM* є3.^_jFɶM\i%5"FߵO:7J蕔XY͑u$MzRe\?B kZCKU#gqtd5av`w-|׳t[J"w5"7c@MĦܑҖ)z@ Q/3 |mJP#7k2c[^FyoS(hl]:8aya3+fAΐq#LI+h`NۜF~3{@’|;& nͨuH4rUXy^{gZU|CN)+I%6܈73<Fm|3juU%}k?L0WI-ϥI-k@-@1=BeQn&̒DK[;kTLMTD՝ymcf20a637f18265c2e772179583b5176dd18ec5cd25f6480610e361b74ac359450c19ae6b78b94a18123c1cbedd4c69165c1f51600302047c435bb5006630640230652f92f76f3962e7ea6843a255026e55f2ee9019d5effee777f3dba1c438237634b513ca550d7d54c6d2b28beb01e49f023022b294b1bda09a00fca43b18085b4ccd11962028749c048b25932a73efb32ecbfea81304479b2e14d051f2b38a24059a0302047c435bb5006630640230652f92f76f3962e7ea6843a255026e55f2ee9019d5effee777f3dba1c438237634b513ca550d7d54c6d2b28beb01e49f023022b294b1bda09a00fca43b18085b4ccd11962028749c048b25932a73efb32ecbfea81304479b2e14d051f2b38a24059a0302047c435bb5006630640230652f92f76f3962e7ea6843a255026e55f2ee9019d5effee777f3dba1c438237634b513ca550d7d54c6d2b28beb01e49f023022b294b1bda09a00fca43b18085b4ccd11962028749c048b25932a73efb32ecbfea81304479b2e14d051f2b38a24059a0302047c435bb5006630640230652f92f76f3962e7ea6843a255026e55f2ee9019d5effee777f3dba1c438237634b513ca550d7d54c6d2b28beb01e49f023022b294b1bda09a00fca43b18085b4ccd11962028749c048b25932a73efb32ecbfea81304479b2e14d051f2b38a24059a0302047c435bb5006630640230652f92f76f3962e7ea6843a255026e55f2ee9019d5effee777f3dba1c438237634b513ca550d7d54c6d2b28beb01e49f023022b294b1bda09a00fca43b18085b4ccd11962028749c048b25932a73efb32ecbfea81304479b2e14d051f2b38a24059a0302047c435bb500673065023100af26ae18a7f5903e0b1d1b3be2a1a3ec37016d3fd6b099e46404a107e192cb9106e2fb8b7b68fa86658c7ce1a35b41bd02300b7a909a5210dfa4fb2a7da3c06d5cc0a24fd761b14d21a64ded66b07735bee3cd45c1127a4117b24a231b7709bc9a980302047c435bb500663064023005b5a4c8328b21db90c859810cdf573a264737cba4f8fa2e0790781cdd89da93b2f980b5bb6a91dadf49ea1dd732b0bf02304aad057d3890aaf440a5343bff8a198301ba42c98dd458180c9b534f60600e962e06cffb77993fe542b007c79856109d0302047c435bb5006630640230652f92f76f3962e7ea6843a255026e55f2ee9019d5effee777f3dba1c438237634b513ca550d7d54c6d2b28beb01e49f023022b294b1bda09a00fca43b18085b4ccd11962028749c048b25932a73efb32ecbfea81304479b2e14d051f2b38a24059a0302047c435bb500673065023100bb44a8c22b01827cd01e1646ef30cd9985d34526bedd5802866102db96aef8df83af010cbc16dffacc23c077c999271e023069c68e3d3a057af7524ab2ab9646b2b40ce41d7c55482fb7688b7ee86304505fbd0a837938f33dc2a0be95b21e1ee0660302047c435bb500683066023100bb3d1328155d495c3f1da1a9fb145ac8426c679cdf6a4ef1b3402cffebda5326771ed2b8a8d99371409fcf72aaf70e9b023100ce3506ea30bbc09cdc870656689039fbc7598c4bb2756b81029df1b48ac3e6dddf7e561270d7b895bdb60bec362485fa0302047c435bb500663064023002f95ebd0de4e384b6a0eadd96eed033d27ea867e5a922f06976139fa04c26a15e6cd4caffbd00cb17d4572ff6cf4fde02305f628b8cb58d4e1fc78afc75d05410cde95acc1d4632df851496cbc899c4ab70a148b34e2d9e4b473ff5a028b68565bd0302047c435bb500683066023100a0de4a4c8f56cf393faf7dcbbb77bfed6dee314bee034cf7d0c37e73b6332ed3a565e1072cf38471b4438fda6216276e0231008e3c8e61fcd91a97f18fbfa2165305c5a265c401c5de61fddf54c51339adc49431629109e782ee5d1e13e1d57515b5e30302047c435bb5006730650231008f0092e864de898b299a00e4fc96e251e119d12aee3ef68b61b21334eb7d2d462bb431f7dd7becdd9aeb4c810a04ef7202302196bdf32539b45789e978a0095028d3c40987b0222dca666fa3d4019b6e2ffec55ec1e5b15941dd4a8e43ab58e98b47Td6RU]ĂzVy啺1d C#@CϜXu[J`ou`WJ|廅j&! eA=ךc9"bLÃk~k٠Py =qXu˟+Bd.C] xęM6~Jؾ 'vJPE?d   2 ,IOX            P    PBXB )B   ( 8 9:fG H IL X`Yl\ ] ^u btdeflt u v@w x y$JLPadlCsssd-ad2.9.04.el8The AD back end of the SSSDProvides the Active Directory back end that the SSSD can utilize to fetch identity data from and authenticate against an Active Directory server.dwppc64le-02.stream.rdu2.redhat.comqCentOSCentOSGPLv3+builder@centos.orgApplications/Systemhttps://github.com/SSSD/sssdlinuxppc64le'&DXK9N>QCAAAA큤dwdwdwdwdwdwdwdwdTdwdwdwdwd9fce358b83386f8db0fa013664caee681ba1517eb53800368e407006b8c241c314ec222b8cd9b1fcd5cc985ab50bd0c5282d2e40baceb3ea1365fd09ef335d98ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903d6540147836708d93046f0b61437a5f8bd5628e2d13a63c306e614b716e1ceac382d9302b0582000ca295ab81f48ff2cf79551db694bc08af2acc91dbf4605efdd6154a4efa6bff7e91994e5699519129da3d63aa326d5e4828e4b156f6efa9ce96d3beb5e850f1c84245bfcf5c1a8b2e4f84bdc7daaf5bfd48ae144405fae21../../../../usr/lib64/sssd/libsss_ad.so../../../../usr/libexec/sssd/gpo_childrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.0-4.el8.src.rpmlibsss_ad.so()(64bit)sssd-adsssd-ad(ppc-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @ libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libini_config.so.5()(64bit)libini_config.so.5(INI_CONFIG_1.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.3()(64bit)libndr.so.3(NDR_0.0.1)(64bit)libndr.so.3(NDR_0.0.6)(64bit)libndr.so.3(NDR_1.0.0)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libsasl2.so.3()(64bit)libselinux.so.1()(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsss_cert.so()(64bit)libsss_certmaplibsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)samba-client-libssssd-commonsssd-common-pacsssd-krb5-common2.9.0-4.el82.9.0-4.el83.0.4-14.6.0-14.0-15.2-14.18.2-1.el82.9.0-4.el82.9.0-4.el82.9.0-4.el8sssd1.10.0-8.beta24.14.3du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) rusvuk2.9.0-4.el82.9.0-4.el8 .build-idc3d437f3de480371f79633369641c6c0337dfa31f7e18239368ee69b4420f48268bd8a84f8b8ade9libsss_ad.sogpo_childsssd-adCOPYINGsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gz/usr/lib//usr/lib/.build-id//usr/lib/.build-id/c3//usr/lib/.build-id/f7//usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ad//usr/share/man/man5//usr/share/man/ru/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mcpu=power8 -mtune=power8 -funwind-tables -fstack-clash-protectioncpioxz2ppc64le-redhat-linux-gnudirectoryELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=c3d437f3de480371f79633369641c6c0337dfa31, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, for GNU/Linux 3.10.0, BuildID[sha1]=f7e18239368ee69b4420f48268bd8a84f8b8ade9, strippedASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)55PRRR7R RRRRR RR4R.R"RRRRR!R0RRR(R/R RR RR1R RRRR#R5R8RR RRRR&R*RR)R6R3RR+R2R-RRdK̭ڽ`8) a+1kYEny_c/P@*)ɨwrqkjCi[oH7@:3K&S1q= !bChfz%NY,_Mqje ܫ9tN!Wsxwz~4ޣl…`3^/Ht';Jn@:8Gehh?/ :lFMnVAnttNF%KHpޭFI@D9(5&Cly];:i!VIkÄ" +R3$ԚWБ f o}+Zl!`lLxɉbd4Ǘq1/ <4$ }T<]b FY"cJ-B^71kԿz!~3tBCG+=qzSIjͮdrGk)9ULKfc:?m`=A ,e<ϔapu>wPS0^!9"kڬ=E\Thb+W|CbYh]7 b;D!5n?0&줥bc|ǷD/Y~$ s&²H\;OYfNj7pP7.nPqTtv NԌ*;L"yQ~g66 ~V+Liw  }ڟ?ref~М#=2/,}[Bf>Ow G5/,Sw^ONrCY0s]5 q]@~G<~TÀx_u:ЄP۩P ބ=9*T+ s77!?f=XZfYiNX]ɺG&iWֆ /ZCB|-ta"Ub?قBxCQQScEPe6\ZUmckBJYs1&(, A(v<|C\ǜfdy ǓN2swrX}?㝨܍ỳd"**$XꖆP z/ ^p;~pi!PEHv:@ܤAUMAZ?t386s\|rL]I*R =u\NsOD3T+s,MX`ZEY {z1u+>Z1[n_ U/ :{b(FBZCʑuB/tG9?2+67@pm/֏8,ژ-5 ~Sfx+˓zԡOIQ0TB]ٿd\Wp[vC4kpk',Sӷo vqxؕ" 77Q]@Pg=_1IQƐVp˳rPĻjᤱ oh!aܚ 7@3gO.Jwt!( Tk` }Ϯn ŐZR(rW;0K~R`(Rd>ʩFJܐhV'kA . %7>+4Xqm  "xԏS)PdhM^?1|ҁ 'Vl4!c g8bZvQ9!Bt>uSX;GxJhz/ޢh{eXbA o=n#e!|X A` :դuI8qL&#({Kv rQLR !o2I$j[ʾ! 7ZRX.UL٩* ,q]fPKg%ժ%*I yIVp)#P% 6&>"JyءF/`rȰ#F3j1Er80RTDmd-e0Kc)-76qty2+u⳴|呯Hw4d1wf ҭgAk6E!ǫ;% E XNz w<1 F̖_IuL`Z-!1r&]ezj_I&OVYt&{ڵNabm'hOTCvp~Ld@7K 3))<ɗ Y3Bji/d.*Rjɸ NVN_yd1ȧ^'LMwRl,wph#S&xE Z5zpG|b|q]ӌ Xw7t'l R?ӳN Ar = dad%&]u3}dw~IsjzЧ;4YY*)]L5p;X'qca#) l\eMLeﲋDt C! I pA6>.h !aCYClM|Z e_Φfb'1+.G0Dʼ+Ax/҇@@˓,;5M=xlC’/1]S2 ;Rc8zH" xJvo#Iyyg1I9Ñѱ!JՏ ϔAwO{8e.6\rRLT?sR$p8ٜj Nc.jpfhU2X~6[bÖi(P¹ D;۫qr*<}e4ȓZ9,D*]|SR$fWx+P\wT3*zX*$MY pՙ{qd $5(#a_Hnqm:uS&t1sU$ +p)߁f !Uz77'jPݼnΝEmo>O?lRu[*eo8%dZH2is*5- ޹O[0w],<7'M"O#uJ9#c1҉0 5<KpGø(`/"eC |C\Oа9ٝ˾Ҕc!,4k"k i( |5@egѤJ7埠EvRd':;aghTVTYM;=KD^$8ҿ=Oڴ}w`2af6KCh>?g!tfBjsŴcX] 1vٖP J_BlSbk# ?x\)xa~APM^HydPr_*9-ˈH4>ͻ:=;o} 3N}i!*je,Qs vX3*F5ɼ@?Ktt&|/oц'U5M#mD'Wq*(P!4t&g=gmU؛~3BEbYʴ}W<]i3 Ju: Xgηˁ)sU>ecmYn+l27I^'` ֈLwz'CNJnTt6g狮ߦE2 fa@ćB^)!~PT2F:4. D"NG/GA=<@bbbBP92ތc M/CJ*/Ǫ1eft8WxKF3+[ JuU)D5*XzRS|/Y&!V1~z<%^^cW-V`^h>TC؁A LȎ OܠHn_kNvu eo+1ږHOQ4!=3h+_zcL',[#`ᄍXhG+ԃTWuwS?bQIm\/I+Ψ^Pd'Z|CU*2ۭѳdT0TN#zA->_x,HU4 5~&N`5pNBCDm܀[&Iл8}#AJ;/;<8]}[x:;h<;[Eb͹Rpi$#Q\]RR?PlOѵŞ9G@YƮ[%_*XFl[v2 Jl̑#[s8)Օ2J>Ech9SSlQܱ S=Y] YT!١o:BC, S);vwQgns0-?;V'Xl%GEšdNЪ2sFf[VU+Mtq̡[z}-Ѡpy#ث0@^ߎOoLV*r'Ԃ}͜$0g"p)6h%\ ̥LH\"׿R9L  |t.>R. 7'Ƽ+%QgґoFwl"SŸ.`D}T]ʧNs;ɋ ߡ91[[wz)o#\bO3TR=L=u(aMLEwl%>?Y~N$-"a0^k/A'uٞXbȜWua;.P3ϱB!R8oRᵧV;a=:M!ҪKZ<șd2fIn푓qRn8ci>ΊBza1 )1 9:m3K vfaf׹tmKcUU#@UXb|-@Ӷrĝ, nH'MM-3Wb%/ OA* vLCa$q "S^ ;aHqXډg|R9@wa3lH|[MiaX:lǂʽcyu!W&Z!Pg-][:m[+wMAg] ])$Whʝax+cx}?]-Rdfy+7o1wqyuIPؙ2B2Q?od4z?|^N.D/['[h3C= |>(DǏNBbw>)6obogu3?b5bj0e&.,o:`ɣ/͉nVo2 6@ڍCVpЋC"'ݥ療 Ct&Уe&F%>\QVjbGE댖o\_d+MEAc?rjq2cGzO &]IxR@/NPGƴ}@O4,iB+n \8jNIT?,blQ%;ȃKyhn1,[_ ٘$F!DWO*Mo FQ@ͣ(Wb+; {h.NQ5Ϯ >Lh6)C4isǀ-.n5 UL- %ӶF m1\(Oݴ͵bYrM%o÷rD%ZTaWë3d(X|Ai){R%t |bH|Aszde!D9R~dØѨ\|hQ8t`&d$qq9)eSb'\m]Oߍ̛BRQ!wY5e* -Ŵ.)#?{ ^ 4D9ڶv}Ny-ʹUݖ̬'E6_48C ۱ ѩeR6 GJ?Ni-j!BT8wIjު+cJx o!X YW>L۰t(d4_ߋ&VVPwH#2X+B"Dªx zCUUhDGI\X/е^}$^u!f땧G*%$IR C˅@6>/8$آh8>]Nj)m۫uԔvE,*1/I52B$M$L: ,4;gØ*wC?L*"u|µRo'KJtlxFEa{~vHT! Y> ˝A{gȎiC8Hc'zQ򍼍6.^s{TBpN݂7߼UKY/&;䍪Cy]D+\:?櫤z <#I%r >\FnvKt 9Ahd䤋COf&Wŀ 7Ik:㱷ğ@K>>zFJ؇Fޙ b' X"m7N 5nn݊P[#NXACMFQ}vǹI-GHpE{ς sQ cޒ3,"Ъ l6QqOWvRFI+Jx OSvj"gYV8gdWS[z>tHRBUGm`ڸaFԷ|blTP½>XN^GS"6aH`-E?f;3p/ fJFlH܁ws(jV[!;3 Rc>"gNK+Yd6 x)RLk$&/BcV3Dp6v#%(_uX:6MahicJ m(Y,Jh>6g'HJr9zTzMgHjB] 5Tc9D/ݘ Tz]z*1e,Q 3[+4EV^nfOa5yQ8to<1b](S>h|5[OzDia u43뾍PtF?CAGlq7o<M$'nNWBfJ,u]vv?L؂I2d:"0\WhwMKcb-'W!q 1Ol1@\rԠ@,w)cH" 3x;4,Zד2yLFa:iZ*P3Ŵa[\.2۝kgzرϵg^Gw{ U#= jj[/)R:Y?nYjmƵD!BCl)~ j+Ē ؙ'X_~DM ^;5v|R13c,ʌN]*-xkܶ/dw7#17k&dSWJbز6o?:$*|Vs.8%ho0(qw?ڿ?*cp>m;e*]y|Y!cuGW_CUan-J몽P~^pQ?CsϮNyJlmY(A~CZēgΧ2!!VkSA F#2~d!DH]Oi|xUɯ4u1EW`0IgJ@nT{In#Uqx)A"k9 27梴C6) ^x+ M(Q_j@Zx7q3YM=1L|GyV-^NMK3bBw }n$q.<idKd U-s8Ly"&H j0uPEXLh\GN@ћu,Jdǎy}_۞lY҂o`XfئAo &*C*|teZke".WI@X u t*-,]Rn8:zi9*F>feOt49D"Gf7$NO([=Em/59ʹDkNuQ( {n9)+Qwl&`õOz`lC\P.4:L:cd>+e, ?L}n@2?)h;kqsA6_ .BE2^U咜Y\F>H^gQQLVˤ | {~;\y4p3XdĈB@$Alȣע(tюKjD+@"0#4)X^ڻ~ y2-?+^aVی3AAk>~!8Yz\lT%xOjrox!9"%ΰALxOB4,k}\`{ 82$b fN1ƪcF6 CK1K62KRF"dv]"- ^DPZIJʊ, 8/X8wI G|#ͬK KuiZq:gL8T uwͣ1SJxCUz'N{r> TQ @ܽJrI틒x^PiNՑBCWN ]*cE_*ee=N@$AɥgM .k_F+× I*X '~ =E-ӏDvq &.?vt{UYoakɢq'5t3rM|FnnƜ-bK sxl0#榪`&ۏl9ϭ)l('f]jO7@_/Z^<_(cYM.` +Υ箭!#q񌩩a4ID׏]'XDLOUmhZ@MWcP1+#opyIlzʹ3ӥ}'d0JqsK<"!S(CM Iҹҡi{usP4T%SewǷtwHڤGi12g}EF*Td CP +E`>Ƚ > {n[+t?zi0ss5 r/$2E"<i<- GwM%~Т]] ]1hXuN֧kl[-Sp1Qv} zamMKl-Ocq#G3#[ ͝hMp JG_d7?RVV"1O+suC)=e| ̥ H&Pmļ[VJh(+dU0`^=L2YYkĤ9)Xסt ׋&/PvdeMAW,8 +P.1"Gcʃs%O `ÒfǦ 8{8'EKdc>j=t,&WYsRK1݌]?G oED>:Tʒuvm̘B쿣| ~-}~ITk;p#.oҵ̤eGC?4ikIG oТ x r&÷'?\0N)Y/ys KH&=B^'8 ; Y߶1ܓ,"%-pVO -GL%*2RIS SYz*܎_M±7 {ُC4= &ٞٽƙTiRέWRǁ(\@|I-nAa;`Y;r(岥 L;z_ߣ,46kB(FgE9rp-s<a23d8_\E^<`ޯ xLnM'2;MrdA m"ٞb*5d G,%e==M0i 遁p!V.™; ,k&=E"%uB$ ȉ3Ţ|s -A_9/Mi$1FӾhO[RMuD HeƇƫm"43CEu{bMTg \VͧگWk3J%dFGQ q^XƠw4 9LK΀k⻷YpLh|>1)ԭiˑQSARظ }|9hɑ}px4 *2$/ܼZ|BZk== tof\Tأhpg<CДZwYU*2Cg: [Lk,~w{!5ճ$ oZX@WiF'ME5 -{J]j"sb[PgM]^t~GB ?GV$EGj?fQEK@\ g\%C}4H4Ka>;0> PU/yP]^!4иj!Q'vLظ.din P Xml7x.ajC+;&w0@Nq8J7֌kn:s4W*p9̦I,x%<_:|,jмw?=:QN2s妄.Ha%S^9,~8GsJ.9L{31^)L¢E,dw;Sg:&żAt[_<(66vS2{Ix{)Lޚ%)?rANcl( w 7V:Tf}t]Nδ_^K58ͳէc9Žv{ ÐMCYV0^p~i5*DY̝<sތ NvSV6\C'|?@%a<5N[KAKxkrSCsFUyF@͑.git#D`/h aHy-_pA}"ٕZȌkʾ_UiV3IH g1'+EJfv_ZKt3"MOaXF+ͿHUś;]Cjg`vl>QtC=O:!UT?V Q 2 : g8@~~ fXgHΑ\u^I/VH#H햑D؏(ui# 9*ap2~'MT՚Ę/YoJ ܍q`E!^k vF*.©2&2FfdcٯN֪G&;z5ִȐI;3U"a2Px'Do8c@bž7lä}J;IckY }0ҠQD"'r4K,v1BbE4|#31+{T[z>z=9'gW9"BP[Zg5e"и9K:u8K\+ tP 34>hTZD! ^?Ig[K,lpީvغ&CVU|wZEWQTn<|aWzh3-/xK4$_بjd SJstIPܱ4/m[aK=PذRۘH5( _BQ4 P%ᄴ_h:/o=RRlypVg;25 2e@^ge12-_Q֗v&ZmH9*"@ҥAnZtD׶"y{pn\mҧ!;0W0]_54bK%˚6\ܕ378: S0C#7C1C'{J|Qr^oD{xBP,A‚{|ɫQ#5<&ס *[iԤ-QY@BWދt;dݑtY鏤f L8z&4n|WlKqx` ߲u42}YDFT[9TNc_=5fbݖ|Hf Fb =}'6_+N l vǀ9F.X/Ƙ4\7,GiAQy9]'@cډh'<F_:x.`d!ca|~ 8:3Z bBN:f]Ub(:aRAf}] c.ΠI3%(gLhP\pgϣx []c@=#?IC8 f#O5b\*Xdʆ3tpÔ `ՁjZ7ŧi3I'yHrc'ٶթYb*wvwfP,,pH 4WKeZSP<:Vwj'ysw!22VW] ?t5c&ʠDL5y,fV `k&qa/k_A1"a.)1QBB\ 0\>SΙZh{7œz?nZF7ŬհZQ~2@ zvS IT׃-kq2@Ǩ!}>Z{k?moKww!qVE ^-oҭRt*dmH 9l`e9^$%R޷ )U68b&uǎˬ:A#%T_[T:+N^c}=@V%znd=n'FfC8:X&z唛L3;-w^X{S0oFssy\AG;I3&lŰ.#ϭbh|ײS3Ӌŗt1; 8ѠPPE2=d/x&< ъCv;%}8&_=Ѐ)Wox!GWzF4kML㽢&L6@|)tWv9-j 9Wݣ#c!(f$|!3wJ!k)Eu0C}9e Ӵϵp{zVo!w:R?d>OHΦ9 {YA~ )GYjLJK 49%B2M|`xRDypQ |{J }%O-m¤go'^H<ʜa[9M (L@EakBqWۛۺ<2y-44&8б)A[q2B'-ߌ?)p4k䯋fIGU| Uj`*H>R!Ab2͙_۫erSU!00fsvv`nCȋY1Ҏk@na[k=M#1ȥD@ -+nBjٿ+76z nI]/BGCkCA`\&3ZK|RҒ'UO G&V9qi> }9EW9v=Usr##l4O8QE]W|gN1:r.c oo$?`QKԿMf/>du0Yzror6qSU/+y8ܕĻ^yEQtLc4c-7^Jn &#BީO~Z{8_Եb5ҪbAu2__-PX̅ I{*~QE#~3ZlbLPZB#7^:it6t {c i|7Vxn9j>OG"9Nc ł0#oXFkY@.YX&L^Zy7JfU^vgWSQ'W7],3F~`6 9$ʴV@{Ѣh-ո=Fג林S$X/|:Q\9@qN.n L/]gB^g AQd_uM:&#<wdh`J Ej-I@Q *FR-l _AwRZ.fx<R-m""Q {MvSfhMVH`tC8=<"(\ýw_)1yrݯfF^dyJnoOf]҇-ಇmw&sveʐ<;؏":<.8iسdMCs+5Q1:DiG5><*[s8[rVpvDޫ-$iֈ-N|оVqU::#[KT z~r-O޲ BEnEl&o4koA76QA?ZG975h /۲ڵ\@F7+hfIpTq7#8k PgV%Lݫ&U~R$fwQbavYޫ|U蹜V X~Rr"ʯ÷"0 ]4Ot.# ©҅?lߊ&"c.Fgmh@֎RU(⵨ڤ 鐣}Ф :x,}D[ Ыᆃ[|TEy&Cg<{ }MvBJFGM~_,$cTۗ]E8r=f[UdTZ p1IC 4N_+5=Ǣ.*OL$8u:"s +c%,;>,; ZQɞJ•J Cnyp>8S$e_lAa2ڮkd^97/ >NO VꝮ&0ÌionI@D|`B0գ bBNzBF\LYZ2qו6UBtyJyliP!OWX-0J*9֏{û&o.a`(x.Ȗ !e  9CgľẖPCwMUzfukfiM}59_κ瞆x;CvJ5~@tzI!(rLuOZN¤.fF K0<]> {̮}g$Y(]FN=1<{ϡG [c3UGW Im^=K>吜&z+ Vr&QϫB;dr}VD#^M+:`͕`\me<3J/8~e(hDCwGFD:go_kMՋvc (u&#uBgP?x>:"V#Ꞿ>SyJ Οe'/&sԈt`$s+"Z7y WJ)LkO:tR)W,, 4;L4x邾jmm(r|Qw6N6ZYwЛ *&Hk>$c;aǁ_ن^?:hb[g#%v]϶L9S 티2?3E9{A )NaT1l"B)bszw0%µSC/55f`@YQ0fN]$z}bK ts}G p!\{_ZEJ$?YwySvUVkÈ#E`sM):->KПTz%PxB#R+1j:KX2zI`3} Յ/<6f - eV&8Y92j4uGOߨ*H4UB^lQbN ;Qv,A_iπCݣOLΏ{M[bS#cks\'`4懬[J2펜V/!z%+J}ȲFAhXE X!:ju谊.'_@hbAkßW(p8Z,[%  Gb9)`.%Lp<׀dRt@*pR˙zbg@QX kSpɍ"ffۨ]x[ۯN65]UbDF-Fkxj^G[ Um7y~f1s#FcVx>MmnRl=hzʆFEN={]`;GxiM," R`HGރ˪ /_JcL?NDn,bWޱ҆AAY{pо LU:H?]'.W:atw܍"dTEAi_kD*5M6"b28+BZtӯUnZ&u^NވP%RW*2 mV"?}ftbU+kbwgK?hk 6ko6-傲?"Uz)ec`+rGG<׎YEs+VP6F'=u 4xǝr=Z9M `YMWWX.)\ /HE'JoJ=0t%wXW`KZ] >s { 56~]zKcFW05+5.ۡDƲ+loMי]55tE:"r#I`*֓hͥ1"$w1ieUFG唚<9(( .U6>sZq not7t!(\>mT: ˥zf6#G`!\zؠ 2 ڦ}3`-=C(Ufskt谚|F藣jm{t0q~ mXBbC/`0&*N'aa5_Vi B|"̹tX.[A.{va.1"!,wt CjC_*: -HqWos.ޅ1\8^t2W#^ˁXw{I/kVup#.l֓POGQJW (]:dOAFwk*:dTg@XJfO|jWZװ=d\ i@ԝSF̐L%JϦb|# 1xh =zj b>h8կ^7b~;JPV/fk6,c,!aqgK孔\uƈ8S5=fϰ۞>c ]ЋF^pt1g򐥲j}Suz,f9l霤7riBݘKO8;[=v< b[K9(Rn9ixE?nJ; / }^CXtu,d״D٧,~gB , Cd4E$"͹mvprMFp;k9\=~X&9!gZJ4w q,A),tel`JdsNE;orL+9LĨܶ>VtЋ'XB2}T*_{#{@Jl99 @v٥+t|oNj m'@01?$}^׶O)[#v }1#I5ve΁hб>/Vf5 y҂ƴ܄fW*xໂWg*c=3hHy`ʆ*+s~5M%Ѯ]>e}^Кn%ݡ$M_P  OP**ED=Vjud &M*]qކ $2gOY^߉O@_̰ahoR^kUwPJ] ^MzȤ"GKPJ 2E1`QQP4EY^G:ħ"6TN}@IҝS{LǽM[OWrAG̸K0- ޑU#cGF>ܧ6)D^иG;2662A$ꔒKpIsLPg9PYYQ8Ø!hgP 7n.p&6?;42񥗫3} YfmAy3ȷgW#ھ|:r]imI!V5?֏]ewǂ|jyboҚvE5,B3kmF7&L:SiCe¿3ޘ!N;eAkU8<9/[uĂÙ?%xDzxm yX?c`jLLc;nWgSsB<}×'d>upΖiHCcnҏ؟[SqO_2,?BgPiBC#YDZ{x} ?ySX@'腻Fk$0('^ M]݋BYgmT.//| ;+Aff6^#*N\(J?wB|-)w,R]‘e28Ш$E%g Ѕ=I׋=\4dwjG-x5q%(l;޼R;2 b})EK.j86aolP~͈)y*RMQ-PѬ^OJ$xBg@d9"\aכT$K01RڒQ)gA~8n~bqJM1D'@eYm`>!̑E 31~mW%,h1ePjl1K>"I|Vŷ& "msu&AjSڊ[_&0&V.XLMnzOA9 7rN'wE95Ga2o)A0{!{x\ f 'ncIX2Jj6JI'zqC[J eIŎTs|륳&(JJzVbm5z unN ciWyZ!`aL"28oP%δ"11T0h6-K"M\\FcV[ X –1@ׂC5oګ {<FJB[Dyp>l@g.RZݣxH ȷ?kuh&*8/ 17D Ac"\RUbrux%tr>aハWǜ]Oo۶hԐ'?byM ]9JE-dW!^7\UhzzF榫>OYvBk=%Ʊa|t8 LΫ,k-ݢ}l:᭍zvc :PY/q%)eE-=9)"?b" [yLp߸Ipb)?諴C~zqs/UC/f¦ݱ,x$thpSC3p6q:LRaV J~=!U2ch޼#}qn63'87|0 bɑ7]^01C|f'jf!BSh8xKa"dítL:Z\Uck! $V)cM j@tGr704zb,9QNbiIF0S# NwA4Le7UoR ~/6B+ z!XOoq.Itߑ3% ř#゙:oum{s@vl7>=u2FաkdaQqn (cI$KN);á Bh17(0}sVD&u1ϴpc`j*Z)DIAs[I$ j OJ*'| (ދ`;Έ(/ϷNhKhD=og79noǘx_ih[A$xS!AIJ(`2"3 _%!A:E_D}p,#YluR[Dp̊GQR_m? z$+7hyV~Hbd:n@f""U05ܹ mǦ'@5ro0|nJ)gg42K}*SNtw"b2)k ߩqX30X}Hda1Y;~d3a-uEkh$[nB JV'747w@a,Kq8V'8 C@t a rBj]W|5XknѸomFyx4hG';dBM#ߠ }V-vp"U3PVu_9JOc0NrvYK:14uf{l`A T.+4?9!{g;bLd`x`î{krEC2s4<+R>N,`c'q@q7)Eg|IXˊTo MDs&ְ%jWJ k6UAuTՄܶĉ7-IŰN4 R4gEKи2Pv'`j# ?PM0jXPL!?%>X#ŷ.~Uե=v@Yi~t'?*i0dz?f|z51pt 0SlqB,QD~rWB1ЮP"}`m^vmn8CL7tޒ|rȣW)n2@Q6R1j=AgӖc)kt=@'Gz` f=ƫ 33դde-o]ŏ|:Ҝ}oo o/Θ~i[;De3=9)^+^]fE0uQ;obj[IuNDj6jNW Oc.kw!t|}oTXW QQj>"]70[nCIV^gc|~ }۔1'^$0sqEPT^d6W?4weA z}f~%.7!NrYko!GJn*U$Ua CЖZ)LXU5 z K掷Ax[!۠f-%e+mW4;Jq$}B:v)>]VF|%Af1,]`x};s:V,[{ז 5g|VLJw*0j8%a679ЋWf힨/c?CS9N%ϚyXG6]f &|.Y A'\bl^kUҲoLQ6HdI"6YNL~:1o#4PJs)R)i6G'Ng(=l(_Q ` l-1mѕp95'L7 $}F+X}Ыa pg>f+&52f2O"`ۈPz?Oy[Tj+?J<_-29Yћ* uq\@>tV+\d^BJ2\rJyU28}F/U>e թbR?2l~ctT'CU_Gay츄Ӏ/tJ8͹yk9v6_'ncN ۷/)ft]i#ILjG;5a=\ю.NƁkM.fLjN-^&bXhH}#ʹ֡26l^>^.?vt)8:ޥg^âG>(Xe̦YfKJڙ=]|mء^.Ɋ v_!߈t^9_xiú>yПufXd3[˦O~4,dWZQe> ytq0HI*%JueEUBA"~4ٙ&E玒2: ې{Pz(ML⅔=q@QBSWj+rT&:x 6-В jo P?Ar#ݶ0LqH. B:ీXznJwJTK^0 _9sk6E[NZ*WJqQf췎:Xi#o,!yWDHs[y1;V_>Xo}Aa[!NiSѢosDc &-\so8l)v:|WXA:G}v%b){#k[OW+2p ϲv}:xCuħWT8J!*;IHe8WtHP“ěc*T+BFGWޚjBjʆnΒZ" SLv:&&8kLI}z0zp'/i2Yǰd nwD7uǘ}-S~݇ [#wBYȐ}Gf6 ŲH?qo! aJSRKLQJ#k jGASANAYd$Evl!//Nrʛȸ"nivvش ` ' T 9rx / ;g!M dCƞ\ @A7cpӷYӁ#[ڨbP&A*Wa-((/V@Gϻ Bd4fCfٶdx\c;p*F&1wS f$n8A[R>`.~ŵm$l}I ]F*<.+?YJNuӴu|#) @@[*[ӋVSB]<.⚼R+_ TWE@4}7{#l34Cmfaٿߖ]_[C2ZFni,8X̭gCpo?^oR/q֋c sMyk^2OI O '`ݏh&Mw] tT@!:X6kK<0f8"iG!+&+ EvInp@į;5nml g56)+5M=Ӷ *xELS8mo U8}J/k1C o |SI)X18'q[NTEZ OR~}H;1Ε d0J)\.*s.I o=)y&q:;"9e"V>1IFQx}b1lrAq# 7{0-c}=^DztwIigqDxr j2?Ev듌l*atWB m ,*Bʜ=glԕYAB>H8ÀD,B`!o^$VDD[ZUliY1kU!@C-ĆjN_jZ!-XCg |™DjD#E!*x.dF$N*1\^R'<["Jzϥ͞NmIo "\Yz˻d9B&;)br02ke? J#X/k³l@%N[ZVOv#|߭,:󞔞]ՊR̭I7Pz+ FxK;nni]c*gn6ի%5sk. clMswu?bw:P.Xfׂb8\r|u'"9 Rw9^-hu"fPhhۤtn^`"^r>^*QҔB]^}W`JVAA:z{'%[iEk&*}{UWyrI0,UmMѪcePɵo\& -0TxBzt-W~UP41% QBXg\6Q6$%2B,PJY?L$ɾ֚/-$=-觫P%.^0yMB*Uj/3%U8Q[#Y%+KPe!7U\-#PWopӇiq/8W"z;II8l:|c_v.1Rw#ñfrNznQe˼MZDM:u.|kbk"5W W,6vL$BM{kں:sbX}aI}d+l'*T帱W1+YDfq}fuJ;;|M/Lnw^J#lovUnJ.,ݺ-b.9V fƐcM"v {.M@ 5 `o91"Ksnշ\I5؀-5-+k ȾOW-1_jS ǒ4C'ARhJ K`Wb,^6xJ1dzǧcm&dA , '"ŲBz|&l# !OVehx촢^v#o1-yS.+B0PIͮSZL~{\RRqŇVjʧ7@~ x"[%/u"E&*nōU>SLx^YI* w6Tlx380˯nߡ~ d‹>Y~ K Wl~ea{*}v7-|1k%3M߈ZB-)'bhf jpDߘV@(r31VfyG FzXEm\'z\-0myl|*Gf2X7K@ZAjm_>wa ysLF|,22n7mY f*J GZx\}zx<钺Chb6\XFjy>>l2-*hufny@ $(y{=Eۄ L斮9 -@s%rO΢!Hզ"eb;][ĸ7o2vw|f퀥Ĵ\ב3Okd4IƬ8m 0[e Mdg{~pWs Q%L{G{r' k-UaﴎŔުBk8B)HDW[z A=, v>dB }`K>pۭ1vׁq~wNς?„-FZB &pE@$\xخ{bQ"|<5/1qp~7p!GyU9x_MZu'FU4Z(yJ>Id#iz/]Aƅ׵x]|,Z|- NlVREA׬CSI%W@f%Tu3a]gZpĉNvO*UO7Kz4a:QyW,Okt\b0jśd|[3X].C,ZlKlm&;cR݊w>ٽVr0ti9;,+woL )Zm>$VAZ\CD$9ၕZ7YpG,‰GENuc:C"$fŗ[ƧfZŧoxdO%:mUCr?WuFxWpzQc[jV2 2Hbe h\*M|գlmFXԙ:h]VXMj8%Lo]^Wy?AKұR')j Lf V \ߞ>G>9{ge8 7!XJNN f5E0X)rg0eY!BE7*W'06L ZݧF@dgmw1|W-v>/Ypm⾺y]`L Uc[/-;"7)tEMK jnG/I`D )K!IS53?!DC,YXg$7Nl@#63 %6'$gXj&~KLcO[|Ώ(1ոEA=)_#[v-~W9cGIQS[_mmS% x8[ r<<#mpfA;M4UF bSC%}3'ĩ] FV @^#A|PKbU#SKgCZKf' ]eKkVlᣂSN Dλi٣cv~ͮsy_P؎0z3!inKP0YwHs4ONj)yu kJK:ZQU~nɕk _0xk @mJqYEoiZ=7zPas1S}]kEA[Z@ 70/aI?+WM=1\&˵j8?1b#Y{ ZJ^ܐr.at֓ VC̽\y&5XIuM ea1񄾘Cd&; ttZnE@8)E*˒5Cn˭>"]<Ck!p-l''❡20 x!ֹ`ZYl (hd.V%wvl 6<ɮnNhj@Lb542 !0W޳.+Z`+"ۡ!!ܯz  Q;apbȺ9귻/}+n`6TڵZq|QS1ogA<|5(_?!{2#QnD!=Ӫ06^IBMl= @HƵ4c?/=g/ i'$FFb==X̀X2awJV4z6v1o .Y+ ̋E+v`ݸ& oڲ`uZ5RrTzhl>XEڳڴlK_1!1W 'pESƼ[W+s;Gڼ+}B)lHc?h#-2p@m)~P6jN#l퀝pd5Z Lo]?y , X(/bZo,GƭE,u+8$r90$ M.~_U{82wGҲӁ˘v$e˶{+<;h ӄ!5m3`6rK4>X6vYP} E1/zU( :q3zS#]."CR*/%Á Oq]xWr۾;Wb i~u0OTY= 1<_,z3;蓴߱~A.mR4HDLȣ%;sKv?ӧo^/uȬ,sg"MUfhz2ڂؓ MX7E4=2K9ofV` v{ dV@XE ®A,q wo6W4l%F]o>1B./ AS;ō5iئ`}Y|94@2ʱkb? ; 5V.(+/MjΔ`깲y\Y[1 RߎrvH(ta \!YlCﷶK6+^la2vGrrTy7S8Ӳve51a^64ZɏA]?>L&a+(e)Ǚe$ 7 '[gXh>i24)s{Lv*AB }4s$`B;I0m^ JV^- g_Bp5~#Hpb@Ѿi^- =WaVKb㦱_4e'O"p?s0uWiU&@څmcF$$؆ 2{ވUM6\ A{TY\ZATCYnID_4'߀}6V:|n›jΛU㒖Lɰv 44:RUv^a~rH#NTQ<X9 ˺Gm[ 3L+yI}grHIp9tL~Qf=Vx٩fb!=3D}mGnR S¡=J0sI\N ](hc ;ZÛ/ǬFS4 l4ֹ fF%XxrTTh_꾆:." MeN@vج^TgWe#oM]~Eh[ % `E4Nr7hWt[/x&P-:kܞlT|}a%`*"a r0tHO|f\MOi XpW\ ZsN-جY;Ub-l0NQg|eOn~k#EU5I=iS٫i_%zo;) NzQQ'6p O;?uÌ:H͆0"A5H#{!G|+#O E^Uk>,vBrt%'ڥY츌I ʾCUYycbGlo0:N_61 m2kʡ-h{o7D,(\,U'Q)L(0{ͫ^f: _n de `/?'\8z N.dف̥O5 KP%6'$R0NdTe0 JZol?V! Ro#Rϫٸi2p9BT lAi2GR;p:wP,=7\J N ,@@ &лPɛa}4xYR穿JnGPbIaS3N@Anmfl+Y}ͣ= dJ ~,co~_Lԑ)QNB,;˩,/=|FɧҞ'fXrlJ!̗PBC@kx1 oQ6/wн}t@ϨlCZ,ϡW/_:j~.%̣ {R_XZdǖVy.?с;fY5Q}{?_І'yd|6I@jUR/{+d.0/B(ws5k0 (!!/i3 e'1:' 5u`tFe7ź砂KxWj)^O+ʖ@2 N5=.bT$i61 | &Įc12]5r2`8&qԿԭo|*ol~45;f =sȇ5z&O~@75"`ևLYnz|6d#H*ɋ& רi/%^@p =J)oBL5X-=@G(*lԯ{8| S:@3Ť8 WQXRƷuH'ÓJLCtlWrW3@Qg\)N>{lƠR9c,>]k} -^{c QgZ.C;Iy݋p&4.cB/vk[7s+Ȁ<4.G욄W ҳs]k1P4%E֞xO%@i*7;+  ,#kYy\c仱m"ڡ5ס4u/*X^'ijUFuBq3+߂^Ct*Su%ȱ!ivl7=HvPd4ǟ!T܋<2HLum5F-$ %9m'aE!K`:\A\9,3hЮihZ++aA"퇀]2*5^he_lnfr <tC}^3]QqaEK- YRb\.iBOǦK/I:NGr AB^ޥT ͍:kL"ݎ3*oyS#ҩ8Ʋo:ic@,mnHs2GԘ/-Wj-k^9Ng-Pv!e4B^mܯWir],u(:aa\ Ce0Vf0D1%{@3d:\dJ E)pdI$K$@]̮:*e)W=ss5Q堮7c'1C$_#NX˗x[^/)Yo -0Set͗ hrN_aj  cl5~\ tr~0P =z[SciNεxb:6t۱Oqۮ|qNl?Pܗ肰 jqݩ /[@%4V<-/܅ xaؑ:f` .ݲ/m mʶip:' G偔sAٝ}Lo8'3rl'6bo27atϒ>mB;i7ݨ!MaoO͂w,a;Pzᒵ'  xDf_i*QTj|'Od-)ӣns{"~;-Wq3 kX.5SA8$*elBJo]YV#'.]x(5`*h)i~4:xEY/>`ÁN;v?:h-:j~{ Ƭϐբ6HX FIpb6\ɳGiwkuCpRe&~#O:=!^*-a@!UP9H I YLaw(cEg6zctr Y]R i3|3('3J4,&<o^5gQ8VfJAu@<֗GǜCmoN t|V@ MB .%`/ci5FMD/ =bRH`л}͍Sx6o q_M9fĺ{g`G&r@H1H)Ϝ"(mwtgػ!GSy?N_ƓXv=,!=6md,-b,0+!2'ʹM%MyQ0:_9DGLXb`aq4S,b?, C0?Ncz_@ph]$,U0 BSkvƲKlN0dh2k5FK°,Kc/_S g5 ܑUeuVwc ^fN@ICn9N@'Uo6 _4+Voqe&-=tQG&xt H.uNrgL}؃G%v¶޹w :QO}Bzs@6$?:%K} x- />hҪ+mg9 ƌxyk} J.qtZRԁPIr!l.ٺK,(X>? an#Xpdm*f ٷ&˨zP[y^M;gt9US| gZ~yxpٔP&Lnkx`~|x4sd"殶zvJ K^`&7j؎3K}\Xg@aBlz, pk#ҼÂ\{h΢$?NP? †nM'3ZOA^{ɣJf Rh'5K#i#"׆ƳYf#QZ}ڿDYyO~^}tvJVWiAkҮV o7*@)-20@*5`۞tm>u٢&.E^&D/ -6S:e`Bc {L +2,/cK &>U~TOxyfƵ>3K/JZL/RJWt#Eجݞ9(гN1C4 '_ꁸˁ@Gy!w32cw)toBAQ*)e..6fO OGO![T*%k֤gd T˵$ssj!*3I@#k=NZaA]lusQ$Tbm@]%NgZZoqG5 Ip:bz2b*&߆ѵcXb0WwL AWy #&>4m4CSi߹$SN㍾䍞_͌H(v Q5C2I?lsj!FTa0ĪDCAƈ/#+zd@{m4/)KS_,gSْ&TMsŠPNpG&<ڮs|k٥h#ˮr.HHzQ&1L52rV i!˕}FXWsG;zYl}zCv?fس}衝i/{a6w{E$۰U.r×D n`l\Wv½7zOx+)g]#EĢݘRwhj$b`;_9ópv%q^JU8e"fEZr ;TSlɡovi:}ۑșQz&eblcbV}i{Q|q>5YI .ca_Oq2CiKσ`ƈEZZ8(vqAgʼn$zF DFKx PS%Zm\`&D{tj\ poZ@Xx;?ىq^ 6t-L JZ]&i:j;o|]|_o7H9_44A2"҈P|:C&2϶!pIl8GґO(EsT.F݁PodF,Mݐ<BHب9%>DGrZ*f莂>.SvƋK;9˞l'P \u-@t*u\GVNXzTF ?mQ5b2 8(tҁlE7fxꝙoهilD3nU-KngDʉb6EX&?reD!Qb;Tͮt&K.j0.ћ7>>[A>ܒU`U}V~GVÒlE"EFrS\XOkUl (zjJX" M}'*'۩Ä4ױy-K)$U(F"+,<&Ç),PG YqLHQ;lOBͲK N*Xu& *b*VLJ!Nndΐ,(%Zz\^?(k>%`jsw '.T} &XnYk6q~%iEnuaNl0#Q8xx(vI>̩H<-,K^h'0Sg@ XM@~Ų-On~LtkK=tcI@^n<] FtuL`z;c%| iU1Lm>"`Z-0c&f}6yȂ 5ȑZ_l-m 1mvw1>78䕞HyȖͮ ~Ϩd<~U F!*tͣUʻdI֔ߏ'O4Xc:d_o9snłz;3hb?XSIF5 B|^f.s  ,Pv D8h0P }4_CK jd2L8 `gāU|ip;1 &BA`X(9ز/^~[7l.%K8zUL.zLwtaKĝu٘@hIpY07lTp񛗦M$)>pSіF2l~9kN6΅r,Y'cLT9)Yv ~jF~Gt_ 2#<,q/"'uSꮦ+tOhIEP zw-4K^}T3CɄ8Oj=á7ɐJѲѐ!֊#ۮۄ/U#8OXFWRryϹ,|lf{-Z4(?T%bu4]ZLYfnŠDzіP;u B'ɖp+߷O!3&JxG˸xS[4؛Ii Y9X uE)d0n.,!rg9P iu3jv _/xgg/ﰅ Й'KeĖ^Lԙ8FȝF%d^ Oh*=vAg[-znԩ8@^u*] \om=+2J-͘;wb*Qiv;}%2bK^4?Ą#l`ۨ$/*z j0eW'P5E+;眜ω_>(b -v0SUB>yD̈N];yU|b(.G%:uqݧdB#RD4609GV'ٮ Lrt il 邁7D*5ʂE^{2XL ОguS5qqN*b0962!IW~ `V<'tVI$!<2rwB 3S2PycuKv>5L w;GID@ΦxN3AOm Cxas:B ~'ߩirl_hB/ߝ)--3-gw;G9X-8.^֏1LJ^g4Ny __4GQ 5SD~ on@(T߮('M"d 놴j.+ ~)$iT\ݥi\̿{S;vCH *#0 8:k8xFOKyvM}!!v\,߿F_ F{r}/`pgU D~SvTQS(DF[@wbAm;]+yvِVQ$r|,Ο*37%h>jOvMLQ#bdXL[EBRM aZy*SëI}='JgU~^CZhۅSBaqy1i*aFϳ76Twzgh^!!L^fеCc+EXuj59H8xH"tӻ͌ȧŴ<cNUƱQ`4w&~eo3Y]=6Xf!T7d)^o@wKN[kg0w r4.t 0b^3?T4eeA&v<{ȍvWVRՊ!Sw t.O Srp k=x,!,7R XGajkh!ml1H/sY cW6bFdQ21ˉ0 _ug4E);5Ü1c~ "z`.d n|Nq{UKXy nj̚O n] _JG!"k9K㽂|ߦNeA7[v3$D}ceQM3a1KF9m<4|B'Gv5 [pBfKJY ҿx5ņkt?yx._) `x^,(V  gfE cФ<йh57 ?\l|qXeard9ޗe +z8BLB)x!8͌A,ԛ3lC{b-g%K9Cm}ae&?fzEd?.c/3iE|qqm6=P|+&B~}wt|*zҒŰaU 11[-`e+ekiia+({TdXjsߘz:.T+ ]X{̶=ԕn/;S|jLP> CO)`ubEVx#@rDN5:Bt$18íҹd >=C(k^"CP#+Hz]KyXw }|L| K\KP&2}g$/rR+gpk &FRCUċPݷ_}'+[g)Xj߰&P 1~hss2^seXk{rkLb.3F3*>boLD[o"-!+q6sFc9J[m.0g7ޒg"v/\)jԓ D 8J!c%<(I!ٙF1^i)quV#zm&XDȸ%Jo6WzvX#ÈTp=ʕ* ~Jomi#\(K/,`|}ypeV%@nfKp߉Ke{HbkG 2o2pIQ٧gW]pl$qֻg W$sPr׉3yPx$Ø:Ufg-~#!l2%^E`x,>O@d ݁.s,PbNXvϔzqMq)&W唐X ͂։_ydg=m_+ȜOW3:11omu-AVjZ!q.Wp ۧ?oQO}؇܋:-Q tnŻC@ѯ?OJ2 ׻+;fǰL{T߰8  ~J>+2Աݱ-DHG|n=ȶbIwe&]^r kէzw64y*.f s JeY#)Y۵b"vR:H-&ܟ4 ߦThhJY_z7]&YE :"OZsn:~6$0NG)k(aM!Q,97݊'!-Р Lrv{N45sJJ"ߑrB᮴@^,!ޟQZi}\ N.6̈́7}܁)r\`_ۿez^'>d65r"d|Q#SCv3V\eR j!0F`KAvתrܷ. i:R ζMiiPJK^.\Im`"=u1{IrYqTj7Ga" ڛZDhu`ݡC=nu5od/bae!O1׵1T%m_.? %mn]iHDwR H_h{?뼮.HM5HкƑ~[w ^3QXbP>TkBؘ3e4aztE6Fįwq\V d<S~RRW -kѬQDd4"Ԋx*Y ngQd`!?5˳֚ CIo.y(8 WUeUz &^[}+T; *$hw2@пyo-zE5 BV`_cA{(cR;,El 0>&-VK͎$]fy;|ʯ͔#7SMҝѝGb7}NcTl"ď]%14<ӘNe nDx%-@Cp(9F`׏:>;Р,mtwq l eTVIG 1(·zF"JƒXI:>'uN!Nң]Zȷć%C( ^mL+!Jmad^IYJ VUs.g*T/n~ͽS-CmaLv)S Z} ~r/Dej6`ޝ%).51 P +곗|;J KdB]5Ѳ!ʴ叕el;DKߡ"}߁R) ('dSFH 3YN+sa])P wd]=78!^X5,]2-yYr=l)p*NL)ZbtDmۣk7z \t]]kbldUa4P+J-Z9.WBN;9b/#Kz+VUi݇$-Q-ċY-ErA$z%oW-^kYnXtAͬP Yru1` cyA#j;7DO 7E4S.( ^jyQxW*Z<{$6Cd 5uw@O~&֯idxakaQ 8.<7O8E?BW.TD*Ζ8DP->,E̻'dfԾR &/uPSQ}1SD~BcVpcӚ!IcS58=E7ئ .'QńVM{1Ea9hg~ra+iN4~9LDU2!1G-y -wa(s+- B {'eOӴ%1?d( ~:ȵdp!s5@m֭k\־(h:M4(,$..0nz9\q3 ]@۽8Y(B B_t|5BcUidd 1Ņuxz&Kx;Gρu BvRDr1 ʟxf7Y`%RfA -s)Т߉$OJF=!33 J-[]16Q>˖,'C=Z4sW^M #TuӁfi)O/㡻03 *9A,Kh hs[XYj8r_^ Zk5vk-Yl=k;񰵾R,ؔHfw9ܣ"n媈}yXSgk]2V1/DZJم κ:f\K@9gSpn]-W-U,C=8GUQUw+9gRe>$&FW6dvc񛒹z6W pӤ'y!왖C+O1uWt XjFb,Pr,=*k7( "U:d6V'CCv:K}h.p5u U3/  N e$}o>K* -SIA|/yQ`Ln&i)>-#;*Dwm̆J#:2uڠD'R?5WmKʨ]85fHY V}\oTDcB&QĬ Ġi1M[^LAX0oȤ|0GgP\Y91z7EpVϑ]CР/:u&OKk>,os͓F%S 2#M)zѳMeTYtK' ?l&u_c~}qJLI*7:MrQ)uKbzf*KHOj x =# .T[8 1m̙UB 2! ]Y%BӍ[u@}4>Gv)[ Z0X_ȏD9ǗUqU}',JM*⳯A&i a | :T3&~2@nǶ~IX9ws%ֹ6z8|Bxfc#0t QyW~"ڼDxhx2p7-¢Y:jɹ{š'dդ"Δ  OVu>bgpϩ[7Eϩ36-BLɜѐG #3yJ*#A qԕ\y) H;< }\˜w]W>IFP.? +GuTJAZQC6s%#e. c1(pN<y X4[{O<")Uh%RQHnhxGeKς("҆>*cY5;;258FQ AV=J~&c9crЦjBoR=?1錜؁R| TݯrTi߾gzBĈ0@Zl,M:vK3J}JϗO:=w^xzCYK?'T@@ I~з ) ys,A fL4hDW논Z+fs9pQcm'GR-o^ѿIwu0ٮgn,Ir࣒)PE%8_sDB'K6Ƀlm)O0 4q^\2۔X=ɄZ4P]SGl]IV/p;YC8 V[v)o{,Gnqtς_D!>)d(pQҷ)f]3Lo[6˸\5k<=`R+_p÷U2<E!bi5 .s ^_ 1fQ*5&Mǀ~3wX9‹dزbl; ֵ IjbZ!+4El#?#I`|@GQEHy'OP^=rRFgZCȑ頃k󵈕:zLx> .ZDڝY09 @(\SQ{ 鑁rki8r'4i"3RbĨO5KPCҒ|$]`٬}z\+^qz` ie;B` DJ}8Wcq[출|w\lտO>+Y臒d?c+NX$6aՙ)C u?T.nQ$hr=f!_k~:3tZ;\S/|b$;Kkh8D%~tΊ4fxQ#u3F\*xXv"H.@sNO'PN*ƙw842q+!ǹg#RFt)ѿsO=TwVH% m'! D5A[d鷷0'Y=n~Uz:avZrfbaR]*~"CpFAC H+)bsCPr_YM=vJAT!Z<wMDO9V15o皖7S}XJYo]dR,?;k)㰁?m]Wki;JRKo7vF;3kB{дGL"%PaO.=^ 8HS[$M䗶:a*-K"6x~2 &64Kq%F=dvڥiZYzϫG&ozdt)-+\0^5{5%' DhJy)ysGCx*z=g5qO4,?)0#ܰ hrdqcwkHحlO-$XJa|ysYeԫljc^\Y\.v6 x14%%9-2'Ϥ XNLhn1 D}OlR6(>uwDݳFSJYՈ dɭh ASsΌ\v?n\|2+%@~;J'Y/CfX~ "]L˜qjϋ"t/*$ Fa>Aa5:uZR7^[)/L2X8vsI[\5遝º3>X[s/S9DžIqs jzbo<;e" F?Dy&w" 3h,nF+sHyKY~5PrvK  mvub_n SNvPfqt#iV須P;C G|d 2/LlןtX:Q}U;Pi"q2 IӦf2*ƣRXip䍲 i8>w֣?]Ep۹GA)^%1)`\]9F[粦'2\wŸ|_d,BF$ߊA fv'N&* %Kj%F9ZuG N_3 4-?KNV.C ̬(ChzGiTF8Z4O(CF kh r+\@ f'*ݐ3LgE<& ;0bPC90[0ϕ0qFʥG/ltװa dGdIΎYkkE)Ak蒏 U%65V_}>h#|G-zv/\Gilf6GOxRa^ $GӦ.d;C(ædmLݞ,x AMWM-ḣ>ڛC{;]Q F>IFU:SR?=b4˻ЎS['RZG3Z'L[WbG!B:k4PKK]&"]} 0]E@DxWvj }G)? w kE-u¨ls>sRyScj&IRK)V5tu^,<4 wYdBgRAL%Uk Y:rQX(62Zk]Z\aP uK`G6 Jyqͤd*L7J n?X-*]Zą^Ϧ Ex*ǀ?_}Sz?oIToC(SyL܌߀[a(VY|\`ě}PK*mUYYOOJ.;E W$6l#n-7aS,ۜAK6>sgC`$Rw;PxE5ys[Hq@vٍilUתz,Fh -*;=$undsP{XD@("A0fJf w pnS)Z!v?j+?v)!]hF_BT6-1@>6|oEtT҈f 319w~N+R;$˃͎%X àQ'y_߅oE͎yu?W1TP\k#fºVhl{@W ;^k< fZRЧ8i߄׻3Camԯ1-!o08FpoR*q/2g秪4%s` V0 CB[!ZOgjT&DF"G\9M(YX.Vu}%v]rސuc;_oOR:H$,Y*Eְ\`]p&_@%(ltfoA$vL?R!чh3|/W q"k 9ukQM S)4'G$rw;Cųz:,? GwMePAV]N=|6PX5 Nږ1<޵m+0u82j樔bPl 5//Yę|9žF(y}ocd%nS- gj[SndӳDe5 BUM"EUCO2椛u\s4uVxB w'Dsu t QYa2կOk8-t|y&@8'nxSF2e_ۃNb($k1#CoNiҙGښ6P\@h׈%oh-KP?‡Byg@a9zsg[ ? 8Q # |غH\Uܑi> ^G6r4gSmMlrQ0:ؽ"l,F-Ct90\>$!˴Tx5ŖI;K|fjLm^*L%3L,w`vTMdFutHTƩ Wb)7,WS ɼꁶPky癣 "d.5jB~4޶wi(*N 976u''ǿt֔YVXS[BAC)$a-[Ƒub 6B@Yt<TaW é^؞%󡂦9 n/Bo\4ߣ&ѱQjEl6練#/=b_ZhS0^r>F1x=bY+>Ul-C07s#2<R%aOzi L=x芓 $Gg/vmNiOBKC ~7eKX]3˔E@d~LrwT3(󏞵ƹH!kVY3}j5pNnrl'-9ZIZ9Um[^øL-P Ϙ5mC8| rW/1σ>{4pwqK2=bXU/]  Hw%G +Y*M⎪ge.#•Ë\4W!Oh?2(_=5.]ZMB-uEZh`SqMN J[Esx a`!,.=ylEƯ0p!P0tW3+,C=GyH(BZ7nFON”?Q)2mm\υR !HFJ#fT9\~+D?Lhު4WQ [^C,L_n0&Po\ѩ4/N!?TfLy$G۾//;k7ͳq\vw H.*$Ĺi*e:nM@RKB$ ->C0-:WOx'8o ; NΖ3B2gzc @"ڄ{'0ǵɣ+)j:Jy[2s!Ci{xE0Mf4m2ksBQ:_e`wA3J Ǭ6>2%`To؈t`EYᩣk=2wASkDއp?oO:[?QZϒ*YM7޿Ou0mM+sbp tyኵvwgrTM T(dLCA]@=nYlN&~nԔk1G@뫹 ZGY b}Qgݳ7/PɘWI<О)~dbiŔgu'"5! 읠l{l'xg_av<3d جu4,/C^f~M97&L k&:Cep5UG}6xEZtH]B4CHC螆#>Fndt=U- !~9*/Cu3 dDQr<ݍ=.־H"~*1;K> :8)pm?ejʾ`&a$J]DLŚue<[pYo!mU—61oWfL].+ZfDd#[לs:%9evy:Х=cV n2$~G=|' ERμ]W4_EI BHuG$hֶX TnuwDJ%XU`ea/ 6lmE뤆 fPmbQIV[ܠdz)6i?r%>eN-*ESSjngYIq]Jb#lbh[ZVR5+×1Kxp{/ > 3Re0ߜm zyv[AObdži82uWK'8 YiC!gjF|(8XZḳ'Œ WoW8GU4GK4YB&HhӉ[ NKuUmb^?0*i`_LsqX 鮡YR#,?+D7xp\e9R'-A5q=NQj$ zW8.+ 6󭴒v`%9蛚8jc4IN:(rv,t ~ɰX?T {s Gh?Ju&_dg&pSMj`)xjgkCLMOSiD"yœzCM0lk *Tq8E^tW^M٥)joLHW<#C! C:F=21)Gz&*h$D'[;u$_Ra#m#azXe^=rf` YP,(qY=/[eNf1k b$;&O2x T~yD?~r[=6auf”~}$q+ f {dOq]C0WW"VAa՗R?吝Cȭ;0qc>UR0 @ L<٧ASO8ѢRGLINAɅo^&AjWvy+opB(BD_ vös9jx<)qϟ _Ɔ83V8~VbIJMdzja"pٍ %>ST+M@߇x3A`,W&,GM`.[@`/#krSJКÞi,Ψ}Xfs}Lk{$i̅p]̂U ]Hs1lYCO2'o@X^Fc oŹqpP_b(ʌ@:a鑝7m#[I 8:=~յjN'61dj 7F.LInJiD|XXcZŧxW|Ur,^:Yir6N""g D;勾!q_y QC1SQU1Ts hG\=a@eЊv:>&e[w~GvO }oy$%ŵ%ԒѸb")pD$?bw` *cTCsQYT\ҟ)spc@ T֦LɐpAuA̧S t5G&w%( XS臿'SS4#(Rpb "5\&];[88*AKrqnew!O>Ɏ"cO'YZ.ʛƆ1KaꠏKՠZ}Av;jQ.`P<>vuŸ#9F])md `#,">`.Tn|YupW.;wwGۭvfZ8 5׭NRNxQd;! Zsp+>Lp؃?ք[pU k(.LM`myM`rv$O2&y{oW[mΫ|=Zq"6%Z( eX|= ,_DW? -1nbrJ}j:47m0-3@~3@13\n1yt_5*ݳ[Gy[ʰ\6Ω@Al F0QڥaF";`r޽ ׈)|hGy7O-vc>;9퐧0e帩s+c+!\;+0B~'_dHa`p6P)9Cw3~#УB;x@3ey ʹ}H>)T~- %;ȋ8mIX-\W%y/ w4[A$/617A2;Q$p &U<~BԠaހ2x%;If_U&r9=wnK XK˴,7S4C66p#Hi]F ,1m9(#l6Í!\^/MI4S*PD\H:f@=Of /nr_r!n t0v ~=DY];g HNmNbvvȟ|ve:TLZVLz/YG'pGmyw⾪Ƞ:Ņ8=΀opEw<\_F]CȮ5E='O/:T : k0 ߃LBb==vur˲q_Ie.YG|$%75({)m@&A"7|\/,7a"gt+f$2S7a,_05plJDt <0 pa`Hsa0@oiWuŬQK=d-ʮ6D.%S/ܑ35@} T. ќ<Kc=@ƩcD fyi|ce v!}OTH@GȔ͓6OV1Ӑ{6xK8oCAI,0)楩j>/U *}AzܡkJ3PMaM螞(:RyiJc!%}s]3:|xhNacnZ$E5 5S}SdzNtYn\]gZa?K-vՁq;O\1z)Cj'"tI@e_ #ۼ$}&ˆ:=@.}˩tt,ΙM}|m1S4sߤoZұ,^Boȉ=uEYe:b;fϡvЀߗh4x;fH9&@mM+o! "9,HE|#9JZLbf .@9{LXï:63P]{\SDLM Z aەhvB_ #~lz`^@@5D\:7㳖Fe9ŏpV г}DJv:wVRvDeF,c!|QDBbh2܆P4hp?Ak{ǁg1;Ni<}7PvEcT6(lpW8.[ 5#y}굷O л-E$ِNܤXsLcjP֮0J `L:k{^*[vC܃f1.pckpm\+Q/:$uܫyT=r6$$GeGu"Xqd$ eeK2!HlZ#ʠv VD_ލi0_J1u\I5^Ggd#ՙe0!Q--4Ak 50!IsߣL߮_0*3Ii\,!בk=2zj gnVAaVE{PxZGh<` <HH.\cr覘g\?3yOR8 PI$&ktuP2q@y kƖ.\c\E ǭ5S3oj+in/"mN0-/1GKb?x9nkuD ͩ~|egL% mQWή$<螲t3-&A<̦_s!bJRSV"k a"fo4ar?嬘=BB5sEW1lq1?tS6:j­!<)]-R: *ɎdSI[vғ dVP3a}D_5` }r2Cp٘%aya灵^F {<WpVM2fBM"іBj\S.^w^E5rX n Y6Pj aNzWD8ՙIaRtZ nn84=pj+jT(=gߓT/{= >)Ԙ$-!7Uŧ#')5eyk49 ۏfܰr%5tS؉N@W/@aϧ :T^cG/XF00L3`;I9D R_a#Mv 랛&!-WFO߃TG0``)K޿_V̨2kd@/ouBy:,r 9_e2K.GQ]?mUJaHk5vr˞4r֔fS ؓbVqG?PD$[^{4WWR.T (;Adgϛ# M8|z[(釿ԎeXNxcQE՟nʧR:y[{}$&PB絠($Ѵ ?C1kDUjֻVms)JM0 DaJ^O/HDR UFxؾߝz U%õ[j!9M2=6qQ,^6 ; SG,fžK 1Bx}@agXxU9Pmx^#lInڌu;eݬ7G9nUjK=%s t&sS$"י $罬UdKscNK4Q=4`cvK0ʥM8k Pp_Vu]p~^`!1Y:E$ZPy $OwIPsӷ/O-CigT}Joʹ 5޵`mCĻV2M +U13]b𰤱r<=aiSwB:yIj!=ϡROViRAld)r{'Y =$J9)Jf "Z} 75ErsS˺LGAf:/ţ%tdnvꖤaˆnk0',NN9J@Vuj=x޻u S*OA%r{ 5#sfE7L*gZȈӬHDE9QMgy+vS+Mn渪Vv z~~ $cjq8+?FPlJTT@&+D~ =D #0F U n1مXyIυHhтqn29 ` Vn?59t+nq,w蛾T~Ur0rSdzfy&mb8Muh{q-M.Sx(QRoPѣ7p;bߠlhEX7:vji2p:FRmF#3.0ZR$gF;P?^Mp FezBjE0Z\E~4B{_`FvO|#9ؿxΙ+6lJ'r~;]㔛s f)pTgߴk"?lH8OGeqV?8^=z!q=A-KCg/`{_WNiTUBnJU]y%pw@,0}{DBDv!J1j} mNcG>Sދt\I9\/3fsHc;H6g!ZrvGteoj 0#!`5k8g{r2n4T`#hOǃSK0{ d˚d}}C&=Շ~+x9Uaiӝwo/7,5J<(D )-bqs$QäULjoe$Y)h55ƒt,]L0(oʖN0WNXG֕·.촤4v90M/jڋ >3 =59%a+#[Ἱ,9UYB$9`:[lżȷD@SPl-RY<ϟl^kCsFak<) VZrP9̫K|LY#ԍGӉÔI6Lz8ƨ0IjІ!UXoT)@κYɾ }ݳU3uwnzog2giyOsbrЂ vn@N[-de+qĕ8ux psYx>c[~rPDă8k4n%}Y:!pV7|Hֿ׈.oL8 ,x 8p1=O&NmsU yA-'=pgABV[&NEv|yG\jt\O^~OT`h}O ;#i_ ͢ɹVc&1%=Y6=or8 9(QOjrQfc̗E;&(QmC Pe Įm9łRSBlL6߻P 9Y haCG|H+^HφXMnWrn8NZ-φZS ˼N"R0هGەJe ÝOEHcs@&D sSA*l5eזomH72Z CRǞj7eY9 CJlqp=퍒 )ѩi)f灴j.Ѱ0HR4-*̊/(O&APb;qk >z#9ذge@ 4$I5J ~AlN; 2-F8f fh8B,} v֯2n{ )R/c6vgބh3\6׍IskT~])Ӟj6e$&%? u @ڪ$@6>05xyC9AW(Z7p0a^ci(;Q?{p`9Cl4:+_ʇN@+B7R,aZ\ja H0NTs1I^ 'bã"t+C/9D"σ 蟶e 6jʏ)ݱ.\7 gcˑw3a 4qBS@k{w.l|[f>޸6<Ӓ|@RJ&z`ʳ?zʩ7fɰ_=0")*y-Y;f---iȂzmzمyA|r )[4̹.xQ-;ɀO-*$la"5US9&Ճ'agi|I++$ Вuv[st#VUFh[mrEhE'"H-dR|3!Z/*Ice;A}SCm2X38 5Ea>Wwo!\m0^mchØ }]uBRhL,HXx[(3H}le@DuA(j&w6*~A`kҀԄ#5&X;ȍq}5Rb4gf\3"0r|V.)h)~WhWn69A=?w%M|;{?0+3,}+_gDpؿ9hBvZ;쏌xZWG[EbaNT7ϟ^Z2QbCM֍5Dha9J`23o>4+=vDI_L3=J@g + nG :F?G~ gsâ3H8RKfm7+1Jdw~{I(M<޳c #`^`9 C[D(:%GCG oo9= fϞR3Tݹ%-4̹d+,;w : 7G*kk;0T]8Xm!ۧIHQuܯyn0BC_BSR\MJc[VkF-<3m)_J{_?iQx8h WX\m4B`CCl ͅ5p/p4Ӫo9X]g){i/"v)pKaq Ic2/D{gP4| ;HG X x?Ug _1LAC/)i5@Bw{!o~&x΄ (Ud^?zFɦ{4YF?19r8捯d&GUBg°DP3q_+\z;EB:Ю"tM;[;ko~PC2 ASczrÍń`f/½a٬Gb8WtS duȂ{ZOfsװ:$Ⱦld8'D/τ&(A 2v ෩:K&C ϐ4ELBZzńz2 $42C0|#m& J)(#*S%bJr7}K!.EK>8-ܽu;L<_hN9x G"a!!FCnH;PqnDJmqY4?|>6Sr! frpuFNT aU% Ǘ~m-) HJs+VJ񱋰(Ogq%0=f߻6 27?ePuH۠tJQ":Sv]gWXBmNvq J cpu' aILF7u{]iL8#8)\)H#VfchgAd\kᎮHA{WR6DȂ1it;n%t~G(ߋxco2 w>ET@MKr3*F!6zՐe PH%?ly6s5"]5$cC .ШW60gUe+ 'AAy|#\ٹgOc&z ~KMXֱY[mCØ葠Az`R$tMRLє 87A]-PSj7ўcMSV3CH'zH\KەϮ9YxM_udBQ;eh.#\|wJ.$O݂"!EKbk6P:ә2:|ʴ-χ jsn1\h,Ӯ#Wݼrbe3(ܺt9EZ[/;]hF?3{Za@.xfk֍v̦C[7O>< rdLf\==hxvd@JBLgn"r)꿌(j2;UT\Ƣ"eiOLp`":X&rp87ٚtvB,#d6-b0J =vqn rCɓ` \3}WT 2dB wEiTΔ#O3Ԛef@?*ZBj+4,0@,Bsc.7$y`, *g-O5Ej~kV~d^UUV 4@WYgx*IQs#'Axo5b7T}Ж {$1N!\@!  w1=bfEYklGC;׳1m8x ;Q HvK?7q%g_>`A/ؔpSpcyrt%xV%2C:QOscJ39W:Irn9.ߘ.`yMɗ)ܠƞ?Z *_#53Ag?[(`q%PE$ۢqe_أxk1R8ЃՏ|+p}Jp$]͐0WbE+kA1|묲oyǮOťо>c?V|ϼN!oPRE)Ɵx;PVk7g3I'pCsަ`w7l<p<8ml3/Y5|ΊEjϔl н|2LZ h%7Ƣi;Μ-0<%ѵkG79!@<6r7L SKf~Mݐ1fM5V8"҉^wX}-. [roP;\0%qj4E .T~D`NgtL+ꌤD||Lq, cr/qm2ϷJ1 ƹ`;Mк"!<781mSM~aLoONW@Sv;Ѥ̝~|](:;Sw>ܦLJKt{eS0T#^Oq^>UPW; xJZP4&TKҕ&-;\"mbFOy4f n|bREAyJaKk-\|E$T4M˫Ywh@FA ?@buA=b@oAgyIu<,1"/Dw>gFNI3y# 7t2αw`H/5olr}ғM4T5Cr@uŦڙ_A1aTE=,DRa8AWrɯ z_ƿKo5FeYڒjoJp+p fGѳ/#q!;p;LKOV._SNw)b|?i YE!]LUR]VNJs* ߄04h0i@iS[JDjZ)R˱=qc&ĶgKe{qdMgff)'̇TGr$>-OSļ 99&8.ya~|94 O v|OZdV-`c'%9ΔS M9油J^av*D;omp[ VVptPf@IuspP73R\fGPīGVl,>inSȳ<~iw8--<؊a*_e7_a){5U Ob 3g3l:/ b%"2Ӽ)w̕+k7j TĻ/)>_cDN%":3kJ|փpjBl+f=<Baq4ԨgI!vuÑT#j;:&,®} 66s-RT. n8GP@A]@o^˜92{' kqq1B?( e88N߄]gTxnJ_ȈAB5  IfӲ~!mXSGO4x-3d ѐSF ; 9ń!m^MtۈIVk\[.'iėdlvhsaCX:.V_!NYUiR?>qI/=8uj 6hٝ9z1XsMY`5,6 ?tONF+Yy)C}L7|Ot4ZGzłdf5FvLM`l|{ ؙE #F4T% ol$ &Xf!1l4:~R`=7µٜfqN#] MC j{&z77{sm_Ů-ىU7S\ 8RkAmW$Hby¤jZ " aq%.b4F~==qPx[K pwS+}lĜɀ+̀ԮBLijvr=~Zs;Ϳ%xTl& gTEYyN[p+pQv F:\/Į^՛@~—/U1!N2z YQ;]!RE5>Ebw;$'=j,X6RPs->XAe5g[WG^ /P]:uSz]P\Ѹs` ()Ɩ4۰:r9%,xqT?nm %ӽLQ|`I#1ms@IyL ֹa`% TϨ?v&QB?ck&V$8D9!%ػ\߁gТ'$V3(eCO&^ #=+bfbЀӉi48Pi_9!}.$M?y+k(2E΢ʣHaS)o#aLgd7'wln^/b *=ip]M1WD{k-XIyNǻ ?˼m\uA@C/p{i t,h-D2z)E{ *M6K5{pjh`1[c?/iI/U0݂HsjU,e1ĩ偞֓f,¾ءgnb^_|=إ1#VnfH13_|2H>nȦ; 0I#lI][K݇(і&r} ip)\C6c)'L!kWwFbK+db/+u8]S/d}4f=W?IՑH;rNJ~ cN1v2lDCp0$M;E8 )øA/]0G`H23}>sjR16=U|':M)`kr%f!/f^A(foTpE֣bC£Dh9~iSo&72ִ6/:_w^B61ag^Wja΢Ԑ4jTo҈?~^TXt,#R`/!}'vupv\*X.V $Q_m34]5=Mf۽rf*Rl+Ա`EՂO}nr$vm/ҝ4t#'"e]MbW/[N6[U?YX눇ͷ[Z PE7O؅7O5ln\jۮ?*KpnԾJ%WYIzE\`&*쾟_^%з]RVfDw }M1U2u.SLGU˹}r޲̪פw;hzsؒtpV'r*JuTDV'%0i?²yN 9Fi-4ǒH3o=og2L]3!Xd|M~)kҍ*(C6K*ɱ[tW Xu/}YοAT@GF+^_Y[uj'[CN{?hkFDg^4E@xuŀVH̙^Q8ZaFÀoR󹩩z]I r.'1yWnxB]>* pu{j{d;@ز{'XM$>C}pKkKn#AD aO J{)yp$:[eQh^N`1Pb؄ u0ޙޞez &-ד$tBm+4L: p#n[5⾇miFrY]_:N@6n30s3qH˙Ad]cp.+U5woR޲⫵)z$爧mZ@P'nnUr7ykjga'&NJrkḰ)=Ur= _܏>ś0PBW!7glL@kF /;~5y`S8q+"}x @ˬB H P7M?XH |~!7lZmU;A;ҫf+l#Us-@< K<6ISna{&oؔq1NB쨩ÇLqW xP僟 VI\gፊa9^\QkO׃G矵d8"\-JÁpV*YowϡIϋSůCLAot~BF(`Tob7m4Mu&XSZ4>seZa·$5#ɖX$zO&<ܡb\]`KU8fm6 v_q]^MylS ?`&)|tUXΆ;/v_I XV m tktX<هcy"q(>|xdtj3  o ]NFd9W=_:N[K{ x %_J)9>)e AKH􇞼㓄3e1 %Q՗AeȀ`.܆x,F'f$}Y[TA'JF4- s,C7=L4R}>u{*؀pvVp{ҘbOh2Y㝸 i$H=@=NLM)+Kefn OgMF0I@xͲ;Gƶ;ߴ*q,C_KmLЫ;olpptm<Ľ+씍ycz?`0͜[}N>/-_Zh>BVoژj43%f7)[m4}f9Gt@Ҳ5>.vAaqO8Yp n$Am`ە zF#?m>Ӧ5lˇ7]t1j^C͚*3jf'Hf_uf[ILJ@ Y}1T-}lYH|Ջ֔\eX+bg:n@%&ui2'@mKsM`b1}'rbV+8dgumr=V׾g6LLxrnoY3m _7ƣ"A/z8eڱ<=na ᜑ: hU<`K5f^+mR.MN+` Dh*NL˱:t>J(PX},u^$w@F%uvr% aT֢p^M,g #j[pXʉC¤xVwr~!R  v|}$8Yawͯ׼!guG|ljؘ{)3b6窙ժM2!#v|<eӋZ8?TX X;rIu4qAqB/| |8*m0Ր/6«6HlCUK4\mc(؞m Uj6G/'x9\ޙw+',-nKvwZ6ŲrK 4E9)1w6?rUƊHBE<"C$Olū, _J"q|&J@%ޅfC<.?j`GplSW5t?xa=&kw)X^5ܞH|B4dx4A8=ue*nci)jˁCP"S7LӢlsra'&ⲗ6XM4P+sŖ+&j>)F⧄8*~0 Pg!MWWBy1t1{J%p>FDxhl: 7݄A]_Y;A+L@K\ pGՀETZd'P+fK  Z~bx'>kW\2sK *ęY$ETLE6BDNb6btة٧%`Y0YPFފ|O1"A964uN!-5O!S>Yx+uhwϳ½ܬSr:7W e4m(m\՚̪$MZO/*oD'F&avsa$ 7Vc#t]Pn.sM\X,d"8 aEV"x6^0Qm(g<؇Z&"i2{$,NX(DCv+Of" C5A[|pG^ln~>5~*2%~PV{yD5ڛ̌t^,D3'ܺ|Tݢ@Jw.Gͳ7HLܫQO+by&Rn?agyP51ۋy}ە};%"ޛֻMn޿A#}10l%*6B06.P2gz.\GQ^\'$VՁ]x9 2(LU!#~"H'5 W6`oy 2 .rĊFLϵe'MS[=6,-7蕬)}"&(@-Zð p5tڵ|! PJ^Gc*K2sI>MU`f4PٟhꀶzIRdFi J"SCXzbƇARMa-JfZv/{+'ӡ~{$6ԦQhbNIU+~|>aNq*ٽI$@ Mv1x&șFj҈Kj6H@J ^eگn~;a_6YBNɕ Ha ҌbdE8]F .YG ~jt鄰j`!IuLPC%H#D߱sߒrL*inIńUSTc߀QiX簾˾_H%BXtyܡ`|$5C]Ps}tۿCd@1uQ;|3IbB YjijV9#8A[Mf  a*ry=f!W *\;qҞ4m x7*ލk(j0>) QN\?b!rd]kV?lq!gp 9m,Xz蛫p?  PӒ6hW;ʗL5+"6yYTx[d&hc< -$&YTT$({:vtsDOU)8@*s2{e>v :IT 4-ff hYP^ivi.8l8s2)r,#]!Qneי-EٽZ*fbɥ nșO[1&o7r@mŨ |wG^陼2bN1 ;\LN ͱ)b4UTp5 5sDC} X9 / 4QbyɌ- u@E Ire+>`-[׭R[iP+( E^QY4;]krGW |&UE8 'wUp$2 IWY;+H9\[P{ Ng1=^qSiDWcXQ`I ekǁGыǀ??DZxqj-pckıe(0ɬ+qHuaﭔ4cWl_| +V|Zܒ RfKTꛌ֯]% O-+L +)M .2 J!5f6i5-7ߒoTDVb\MBIͻX94F6CHcOu uco#yGΝoiyTYMʹX)hk|;nt "YM+a +iɢ+ZsPZP2\mcoy]jzP!@.ѕ|i M3vmթTRoB\BYAISΠZc\ F nZEbHI6r &^pg3E>).{:Gu-%=.HHUc{VZw4ƗM{ ZoG8~SV5 тRW@RscCL8TS*>õ7}ZC긾Hs#.PS[zW qtlHʾD j^RcA,&M'HCNs`@@H;@;b@L14_Ďit1V6Ql:⎷|OsPOLЇXDk۬jV=LU>JZ\S0)sEئ۝3: Tߋ$$S#j =tҩ%@c,8ɡo k\0S}bsadcQZrm=-: M#^Q‰;XC1s׷AaSU2kU!hk|ލ|8U=*d?4+riB M_5WVzQq}\T84N,޳ɐ?>!S6Y&pZr*AqъIjA,_!I6Rπ K'm<݀20Խ:+gN ^ M Uaٯk~24;|UVF-X=`75cR47Nf㟷0߇oO ijṌౖ(ȲR#ޙ#[[4߯ >A¨2TV F`[e"Wx~ !ۥ@ Dqӹ~ 'g:dSE "k#–Ⴖy‡&IO!ueo{ WR̀ ϓYp]췇ZW<2ukNt4*ɨP:Ql w)koiw_h2>;쀅hΚ-| 틟%j EHV r6V>6ֵYk)iV z6l:s:.>  XcSHd 'W%M^b tVUsBpRJƥJ ѥEcj:4RK|?Yi:z'74}~*o)st=E"Ɠ fTn%J.*PS$;ty]"ǥ'~7Vg8.m0t;zED Hz줂ب/~J~S-CupKeLKXÃbyZRV>pJljtJaS|8~T0{d'NZM cKrhjbt=p[O"Na4wҁ|-- '-ZrPwBsL9q *KOAFJN?9V.)G&pf t[X"zg9e^Kb6À*Mf^WDL0:0H, 4D" st=[ArSkiE^ s h0fΦ** K=kGJiɀ`ۏ'x!#7\ΛO[]zA5T_@/c⒡PwBM)pB!+}LkChjCt8W3KO};9 7ua0&ˮ|[@{_9L f+TNY@LBJFvXZr0yTF"@4TUa`Wm\Ϳu3.zF$β6x> LJ::'4s!u:GqƆK,Q #U'rO8/FrO<^]ml PBkAMK_ۊ3 ⬇l} ZpCmu$w~~x2'K/dlNjF]iI2n1 Ptr[:$&B C.Yy51ΔU|Hr ṾV<34f &nA+ۣ>:,qeK٧VyXf3.v;1F{}诅HȦ1bqb- Wz1k;ԪO?.}ĜDmVA+jTksq T5B^ʧdeR\d:!|qXJ\YqG(/¨SQ$#%;P:i6 :6c:I7)? 1V)a vxڬҁԮwDSԖIrT8tU8q'0`9 >}\%ovFο,+ " Ac% uݪSt/f='D:v ?;}W&WnJܿS$AvWޅ,!BJSE\qAhk#9}KMU|3ꥻ5{# gsS = ©( :<꼢W2't|gCvB[ޖ]vKZ OY+͆(Н9̲`|Fny[ruL:i_nwWnI@8ל} w"ĥӮᕈ8=f/%eӘƫ 31:iQt㟏Ys@ 0TJ[6w %k'Lk*%Ǵ~*KS%c#MHyÐw˜Y7/2 ma!Arg!mӓ1 4̍u [n9hLh-J|q_*nڊ޲xkp~#dM;83a, ܇Gkʙ  0l6UMqCS%lY#DfQ{K"Z*Tb&"Аe}^ "mH }gt6ʾ؊^b65־t\g~B9_};(>\nzOoasa*K ~.|vU +z؜"l+xDu؟hIA/ۃ{PhC ncKswƭoye?@)n07I`M!Xa%NV'ysrqU_=yԠq_z[xR(5a&WW޽>`xZV9d:#&Z\(1m#>^دr'jpB! 'x}?$-$Y*wMZb{`je[N7pr ? mB\Er8`F]+r ^ {4?OU|H(w/Jg+Q|uM>6!=$Q2d ԰ё[=0M؀펂ԧ{x^+wU +RS^$*N$CY'o^X=|s\aM~% x;W1f)&%y$嗍ȋ,TOCm,A oT/LCa4BGu7K {ou %ΌM?PnGVGnj,!(m(Q*s9<s|C_Ob3T:+^ mĭw`T*i`|lKAQ=a⚭~d>Ileciz1ԭnx{nd0DWׅ6ZZ@ujf.sLճqM-C}jX鮻HhtA9gJJ}1&@cɝs_g٥b GW"a-K,>En=P%+)L{&xB;KD2TEQp20@Vϊ'j!CpBqrP&sILŠ'+~!Z?KΝ8_a/<ު&wsI\A=E0lݚb&i'(Ԫcb1fatæzޘg!ƨ~w?.ySj"3OS5 }lOoC oe- -IkVr*e˃@DZ8,t/XxƩ"Emdr7rZ>RI-q$\e|P2Qü=fPЭQM2Iw< 0TPB&AZ`a! |N8Kkӹ뇡%)҆g ,UO`CM#Ğ ~dH~.#H)`3S9vh(֌]˗ \>uqA \MIC vɺ B08mG?V'~AҨƍxE*eޑ֡͂l@թ.mWe3_@WBPQ>Y~Nv 1.u,rQ8"T[+ԑnִdSYX[\}i \2|Bmx 7( $݄dFhqxVCYq]/a&SC4;Մ(ϹgY^ѱl# )@6 ?z}7o+`Dr1)rJah-gi{/كMɐ"m=}|)K*=+˳Uo%}/yBX6[6y)E&:::^"mBGs֦ ɨ5o,>`vT'G܊Vܼ, [NDfޫ>-Q3ZH׍Fq_ICW u hXNS_.5B*aS E$dٔ;^g0x՟7 _5GYwQқ4y iYHxXfx|5; AJ'eDLկlpnk;n:N(n^aI/|/h Zd)s4s?~,_lFu}05W=moZş1xch&^U9J1^E菽#T6/k4J#R &]Ɉ'۠[DJ*naU%KH+FC8e'Of-Qfk*5E'ȇTfO+ي}dfE:HbH5' g_L _&JN@ n>\+>ҷFQU8j릋OxUfX!3"kzh b%T+Q%==tK}KJ\6UL1wi8!>E<&LU-/d/>:|:tȘZ^dgmC G07S l*5${E1]p:eYxGQ,N]5;Ncq bԓ0/.K-tM8WSr- 6nc 9FߕvCOZ"Q$@vcLш̲F昚F|> X{"(r|d6oV|U|ykh+ 7_wEh% +HLs;c~q64?vQq-i W#| y)!\HH|QC-Q3^6is"Fw iL@P'tǝn\cK /Sn;=֥bJn(jGNbjѐ4lsb:dE1 Rj!􉖐]~8H")@Rn(%2T)=ɑa3bdR΄ Z|*o5Mʈy9p$:Ad ,ftuqnUEf%_::e)pZLKýMQAِ; q&("F˒0\\-Ɋu? yvmLMS(B^KY  ;/}X G9%s|Wu֢A>&3q9H|tz]*?Yjt|ҝQw /ufXP鵣n]=e0˔ 8"6M&/dȴ#}+#H š:FbӠ $'J,5_v׸i/VQeezbc(#-P>,H\c#XEV GVY6_7)<gq-H72ǞVxI_Ix((ЋԔ_:F5e:\^%Sи\f3x.)Pk)O'1VE!'CVT_#dikE^DڸSxMo<`V=/V[Nњ(:Ӂw1uG][ Uݽp{ F>˸7,k(ASLpY+v]qUV(Ht=lJ%h! pc̛ƶgLsZ 5a~ r0}H/7h3'Yp(9ްGJg8\}{ka~MRgKaA)/#o~BP d *2gQQQsn>P̧MJSuΛq}omaM/v@rgn%=Δ ޛ׀?KE4yE=ֺLnm9ho^3ES S-a2oc.hcz9A+a%@ЃD$ pgxGKc~1$ƅ.-D6,A'$(l I>ᦡz:⁛w -k[)znF\^niE%R܎ҴJ Z?==n gM?!*ӘaϷfOToZkI')S?uSg69ȓu!4yrm;W28%W6ߠoaMIgG^c,JH<5@n]Ƶ3jL a2ne11bAw&3Y Uex5pntwgc,eAkxL6}CM:Ro[JY,SE75pjTH$y)[ǟp41O1 "[$=pXVz ݸM:O8k[ |S$rR<o`}<'gl[<bP#$# /+e"!D+BLiCH٨HQUNJ/BDzfA^;fI q* 2Hlx>N$4U=PHf!]ʴ$-\S,r&&u#r G_qB]Jϥ!gi'U!-=_L)>rOdE1KGgݞ fg%ߎ[}Y&׳Pb惪"j|5< ꕌsH7I*6jmt`J {LNѓ-2`dKro?^\߿vqfI~iYss'Iɳ݉a qźq!wm)Tnm{eRAq$\l>@聇-/PF֕"{#S]^+J°M$F׮.>Ώ]-s"4>_\ [z6Ҥi0 WrCZw5pWaxf~^4ƁlP! l)[g!b;qCaF*]GM~JUQ(|Δ'a7fչ M,ҾG T-`p]JhE#)0;C%3c(;R.q 3h:;ʕ(2%+wīfXTH5} 77hą-~}{2aƖ`H'ZH#-:ɴ2Ҧ3崮'Ym-LtD=`Si=:P3w!nU(}uS}&%U`٧0Χ2XŁ.eC+m׆TkNN@rD~{W2Q͹J k/vaD'm"mOB~[l]p{WUS,: 2 n"?yrA@J$VNJRf׆&K D$e!GP˔jk`=0<:(4`“@ǹu5M&&<[J>^#fͻwׄLkc|Uv >m/h[P)xGH\{,nmcJo¨lmAXSqBT")>K֡,MZe.mKZ?K dyxci,U⇄ n qSgA_SAOnȮiB#˞={#xuޓ\XP< Ji}?J{Lv DPڀ;ը9%lʹ9CIıa;55'E>t0T䣲׮o~]*ۈJkS̩ZU[D,z9,MH|ً|ƾDu|]'>vlvLjmB>FGk@ydo% ;6S<]B3Sp}yNWl&1Gs,ġb9 [gհ_&6hXyy!e֡$3Kk PVf"c>Z|j\B\Y=TXAC*T~ەH ʹцDZH5))(_j0XGnVNG,Yvr7K:MAsf0δK{XnZ0ۙRMt0"\xLzrV.NP. ڨY~V,L'pkd5b&> 5/ Mc~v,ʔ\uQ2 VT| c&,\09. m0r,<6)qN),QGvLJZ6ëǡj.^&JThxp~RYDYPǣ~s?K~a}9Z ظ -01‘z㔓gO #صEEm'[dQ駮eVWEzt⫌^QtOC+NM?/k"v N/WdJr/#̲18;/eSrp1 ,AحP 2e.)A9gZ5o9>oKhl{;B "`.֡h*&YyI;22h'0A97/`Lb=XnxAmTH2xM'WǎRJۼvЛR^]T 2|VvuSwPj*uYn:w e1&n5^I7]/2:7$0)H«|L4wbHp+tNVnh{mgxn6#;0vXPeCkRY2+eJkz^3hGN~, BpMi3h4B1rq !8e > ^8; ZÖn%$S> {fR`")h:Mt/?:g\תsO9\c `Hk1 y*qUX"4H-HTY ˌS#Avg9LCKUOONDbW,0{WK!)pM+;E(hKeRu۫bӕ2Kb5MtW1y/zU_B5)+W# D>("S[NnB`>kBGl-]ebM8Z0p cWs*U>"P#G֓;bi)%u?'439r,B .EQfWJ"9SgD->%g/[JݴyQRn[z;qigNkFl{xՍzpn :WtoIkv!ߖ'jdCNܨ:4ײCp!tVPơ[=F˃;X>QgC[؈@<B^Uu'PX:mΤ4 m0cEʱ6an,It!#r$ 2SMQsn+dTNg߈XI&Ug: %eT7y+v1=A#%Z/ 'O<8fL^;븖dQ˲,GPt#QIk{dz$1E&nǩ IN c-#З3G}NTUN_q#Lhd* d]m¦3gu8L(.렺ȢKܕHw2]ya0 `{?8}whn. 28 crJFp,n1 rݡ߶ϊ?i{_6­d&C!Uwnr{cJkOǽ_m:傡WѲʉ6' A\*KgX3bP0ʚ#qX$üH ,7i Dz-r7`E lK GϬcɊ^D__x wWMk}EτF. Rzγ8]H}"ӽnqs#E{vlSR/0YOv:EM%7T{8E8mB"-5b_mޠj3^ "5'2cG&@~LxΐEs{{=>8`57a11lxD5wP$еl' @F]v ;Kt_Y]WW?~[~P ǩyCKΪ Q;' ŭAa)E3dnVi {o;6l5Լx0ӖblAs @Q!Z;DH+o^pB*$B0@_ J5ToK+H16],"+ %IJ%I"tsp?.67ءSk~ <'~=ͩn;Wb |O#wYؼ%GQ2_t~inP42Li23]"-KM1,?=(ksͻ@H}g@P N<]6FR[<E!̘ҥiHL-4r?hYl8 V6hJ޵ vS6 HХ UӀI|5PbhvGy|}:WqK-+JAg^LHu C]Y*7cklp㙛Jr SD!0H%yMPa vfcU/z53jP/]".hLf l6AG;Oz D<[~ ڶ^Mx+2)'鶸E8]Xp转S '=Z\uR]?dt(3*9 q)ċ"wK>!Sax[$HJvjygc䛽;r=IjGK*[Ӌ<T&Ԓ!^dh[G3k, le79+xY1UUѲJTS)7 ahqd#7@꿋Λ}݈5q7Th8`iLW_f)jfXlF,XI4:u$jc4jD2 h /voFԋ$JJOKf=<LPi{~=)@򖣲 ˔Ԑ>7ei))vtE3 o]!Kfe޻\5;חeIw'9@3&`1gC &xw0z88z/0 pF?jpCJd؎ 2wM3%7kŅ] ell44_;I<,?#ܵ܅@opZ,jpJJ]B!UVs OhvW[ 2*&-W)9R!ǵyDv/\={kGޯ ;c`ɷ] x㤤ȴ }Kf}\։[h U8)=-"XI$zǤ^: /b0nStZz_4g)#2Yѣww'_WaXG 2R`~*' V#>AYr-aCj[jkNo5c3 [RU=Ѓb$%N v/xs\KF4tI:E^R鑂8*TW 8h'W4_4L{զzn^ OR| K9⦅5JUyKө]y{}'TN@:{_x}:Ün"wW 캱7NlEkC,ogWyb_s<6I!Q^# {aa% q $D.?eސU0eE鿩f5Y~voJJv 6#xjhOE͟9Q[! C`m ҢP|v}`d`U_* -/[.;zHrpxcLeS׊,l1Dbf%{rk5MCix$r 9C^[N(4M ' <]sIVZl]~cGd;J@AunSoۿn~%*ҋW\FNؔ% wk~n腬3Pp m:SP*M7;1#;q\_oNJ`^côSi.7(x{t^%kW.taB̬&~g<|zQj r![_U[% ^C44':PW4p)(AR$oH;=g{֯~PT'L@uKKI?/::t}-1At:㱀߬0ڇ9 2YJP, ЄuZ&Nq,\I"66[,GL-6GGpL_R eNV2D~DF3P\<)8"o q\kFYf?N*.e{}=)6.L4162>#= F"Q P/v.fz \`Z؏i( '*OH; djHw:1jC|X]{:Eh,EڗEvAVr6q uRsR.>eщ" Ǽ% $K?K*@!e߆|śzBM{ ] VϞT̫+(cM֋U_Q&"#UYT#mɄ01hXu0,xȞPxVp7? +]WGi:$ q weY]= y 5 @NUF"PcAAÍ$F ,MzoGTvIo r7o,'B=m? |ݖ,SbmLAT6RF$Ih1鸞{ pIXgҿ;qN?0 y6!~ƞ90ZG[; <`O$#_u>1M{;ZqYۓ" 8)7<܋xo;k_,r|]%c61w%r!;"F(h glBuH-y u#0cZt fHhi=j{|GfRqݼ!`y),BlYoؾ }ćO,n-ơ=h-ZD(/dn7SA]'C21sdGL"V*6 kvS#'wcCUo@qrԇ ωr=(F"sn.2d>7!)+i}m ']co^;(&+Tc^2@\ɧM_ǝX9ưPEG@KwqMSbs ɶ9ʱZߓx~UOwNbbY 87o= k {'iNĞ: ~}=:|mt%ZZOi'U\9߀o^-5bK{UV=АU&ŏoVKWY{%$[ۚ.f\QlRZ(/9:ϲS+d81!c1LK <їGHy5*8ae؊;Uձ qa"LhrN<5d=-(>Һݤ1RM&r9 gߺ6|;-=9i@ ǍX(+gнÍpW ^| #-i?AE-+y3.%Z1t<9sDM-/N%Cl*ӧ~CX+ox2E$1{ x8f +H"N0[h>MS4-> ϧX?%&B`^>JU) j..SfMYIԐ]JU0a JrZlED-V$el8d"l㙺|r4G4}d4~y3scCF!L^t1`mœfDn-Hbctt=?Mz58#dn$;+sa|;bjKJ ؑ-JڎZӲ%XNmȬn&qvK@)8[+AܒMf:+<'g^|yŢ` "VzU,zp;<.=C}4['&_hUsκ2Ʈ֑Zpp8N]SΔ*9h*Tוu.Qs"|kk$`Ƭ)RăGpE۽fzќȤq#8+\=hN{#Hz"8h98߀kL&V%mgh" ln*W1 ɺ,# bgzT\-Pmmz#@xb<= =ű߅bi9kY#A7#ҩt n&̿;iɀFO@^o2JدNʎFݷԮgQ)LEFO};@)L@O;[jb~2 bW9G߶7hc;?j?N8K諸oA} !>w,bD)S #Y% 9h'zfpf9UEBnYn ipMXyk/Kwz/a^k4ayNP)^xyoqhxVub|GI31KcxٜL>Gk+CАkL؈X3sc:[mb}܍H Ja|77){T,ZUy\_'-Y&$m2v>K˴eὅ>:{ 4 &[?f-X.xpjӒ$?ŤhB߻ #^b&`;!!u"8{[ҴtbI 3k`dQOOZ9EYp6B^Yq)0$e;ZIo~͈(hNqna2I'.EM\>oRj?&D=Od|A# ,+0i|*KY캋NfP1< сOAGn9ޙ=fk:^AIk^r}+(s!$`,$ء 2׊t@5?atqO{7κ*KN*Qj+HSۯW49Mv*e$.ؼO==b)j1u)_oڧp˲k+еQ| S pLN7%Gq~ħ^GU꙰XHmNX8&5 OI&@04Еa]@ƹsvE tJ]bG9:ZÆ+ӵs[ yIb٤?إpXD¸i)7,^EVvy0H[1|LsQNq{ӲlG%Q,2b!),N(SCf / r,E&fDvа$O-İ#˞gɞYne#|\L-:|=QRԾq2c8k[O2Yb/iĨQ `aQZnՓo)TُtHxmyvlm \9Y@6q;ɜI` )prJŃޕh{7dV.~4G# JuyC۩F Yh<{E "{Jao,6>2]O`'!ع&RDI-no qR:=ٸXpt47j]`nTY^+^[l:Ja P5wۣѝaYE4Űv9$̠㒢uJD98[@2M#uWg.j3vTi \@]H?궡"ܼbJg+(>=o.2yw (I-4Fl0)UxR*9Z$A#,eQyi}#+3Zt7m>mA%1k#A`av` /vFTXS rR! Ѐz=uəμd P#%9\;{t3 `1hA"K6HW 3TJ8D` wuhb"{-8Iؙ_1mW-T_5`5zc_Ol=(uM-^yu|YRGʍ9skHF`ieFee+qo A3}Y & /X0l<)(|*4t oTĒ+n0FŗU{"9ƺ0xigj)BVً98f95 τc8=bMD WD!M(2Nj8i쨴d^Vr"ǤJTQ{%Q$E6_HPz$jl_(_V&"s ?(~{F,^+ ) DzIGG8c7$ ;#\3JdW2>#AYD?lxeb[@8Y=pbO-p"u;0߆1H[78Luv/J{ cS7&apM#\ `]x7v6%JGf.5[~1D;3xL|b63kq@W-.CюIGNAWfeةtcV<Գ*[K$^ۄyHHjOkۉ\4I63f^|b- eݟϷ.!YnM;EQ'&*e@C*)Y {%xve /*C _5r_~':˝COY"</^z"FEZk/MŁ!rJP&+\Ir(%rg^BNHymQw|+獆_ܩWYm:lxD (pYqux^߰&l06ފ;H4JDBT36{kVw$דNw~G[RT.\/䨳~ײa\δ͛Qh3[% _4uH50`&T^AۼW_k-WN@~3H/sؼwVу}< K)B:$xOKxX| u;{D)N lG&-ê@ګxyq 2Reu.؅QHG"ȨHYfeylc*79 H3bF"KYvG3RI{G#LXVM#}Sc;z58\5K{&}qAdjrv(!>#K+ȟ43AGcrxVƤ|: NoW6x5MM_Qlt)GUv2`N`Qp*m+WPwZ,%9)7Z̧ۡtjSk–D:BDU1;=Z!fLՌ=M_I$Mp`hY˞mz4Lؔ"ũz tAg}yۨoOK_vZQJzzm8h0[t ~),wL7!P!zM>w,J"ph4.~31 S ʒ7=_ͳF㵽$9^)>LJevtTL: j9kF[y7aw k>.8Os($GUKjgR=FgAS$Fo9 ߶x3H1ɑ5ØAMZga*| hm*ȑ42Xܱ>_;ڧGdD# QgnM1^7 j"'ū#[q k2ٕ:"pZ[l.m^n1ߘj +k'G|,Ip>mwRkB`dz2{ʉǃW.cxB=&uWLP"z`gJG|M]ِ@ ,"xkFoN &IDVuA7DOr$eUAэ ;  bsƨO}s A2?ҙ.ߞ3ʳ/[1Y\Srʝ7mB*w&RRy8L8ȸ3*ʾrc[l Z O<IJ_bH,Y&qjASea\ߺDCܧ *f]JH,IaT$6àLnSV?fJKKl2 u%Ǎ@ȁ{h9W~}.ԼA-Ic?|MW3n`ϼSX I0ִtT~`3 (1+35uC>OYV>i9g!T"yvc6h Y \1q%jխh\:?=T3~{ȩⱹ$+N+NMyDPl)Mc=aF^Fe1C9moHȺ?Iܢ'qg l^#lb]&=S0vgj~Rg▏ ^>iT۵?p"4ؚ](G[y&1]DjJ_bϕ+-߫y7A|{RqH 'Tzz&Gν.~ylɰP;uhiQ/Ρb!*HbbX Ϳ90RUҘgJl&-B$!Iy:{MnmfI"%mJ`}'$N)ҝ;a  9`RBES~yI2\QTb<ϋecuLRHyUKt E]ϷK/[~\) \۟tŖK)m z! =%,wgSEC0!]is]S R BY nE}M UgɥUm"uPeps͡b\=PD23>A9ߔ"`Azq%VFj{j,qxPnWǽ(>[T$z-iOY\YAg@loӘ>"?0 !$Rz3+ҡp[)k+IhaWSt2*HvwQXc4^|ȅ`6!R[sgYT}c 4>K!ؓ. i YP+c?a$5ܙx{L,op:MXUjpYKfu&9~ zfc?*z7I崭la qGYr]ꥬh#v&Lߌu'Bgy}džQgl5$eɒ[nrIv ew NXJ~ i+28?JCI8-T8,[u6խ <"_:&џ$eJ⦗$Æę`![d+e كol+Ҋ edfk`O 5!NPfDH;h?uv2|vlꑴK(\YJ^sK#~{j4V:] .#)7D!ѿ팑;NOA)@3-@PYz*% ;fq?ݵ58W۷\Zhl01Y^CIXz6f5\KU6SIKB"l0;} " '[8>9߹~[v"XI⺑8GtͺpEս;cv+a8A7$^z1ֽ~<-yȤ Z~3缋e/F;v yf}ؽ>ҩ*VClZ{$5F~aq'9BsP|v-l?Zt.pm)rmM!i9@c6|A^y@nOg''آļg( 5[´/qePфFJw'8F!zb!]҄t( &1I5QX،'Ɗڡ}T72"lkL,M}VM @BUtsy U*!I0cpB$fūᦓUŞx[wB6 cUAhgPM;)*cHrȵmW'm 8 5*{.l/thQ!ݕ]{$V"w9~B߆aR~4{r/&u"T=$|g0qG{?@qT#{=Kd ƇNcDV;|~G,nz3P,*D `bd6W,>πi-y>P;sJ8E4mxAJS,|s=a?B1z,A.\+Zu']aQH8} Ov)HErR ́[fƔ#7=߯;"ANU*cbFWsvJopF~V!F唵岱3$Gcq⧗sYb`7kp ^(.9 WN(-aiy< Nk9y+/2 &1e쳻m%lIn*cɚqzOçM]M :-swV,#JW}R"%J_+kl2uiR7[R_+sH_+Jꞇ <.M<+VXC.MuNRTX\QjeN+qev\K.fPY:zҴ|xx}+DĠQd\^MB(R}ؗ3ӛ&%} &N4q̢zIK@t)D>fMi4/ X.x,=B|@NK!\Mq첪y̘by9"aeps $Xۍ@֌(鿢cő]Ռ?l=Pwm2r/;.tι# ; ձj`Ij~T]p$;è_̇ *šu]INˡz3WV}UzqWn3Ll!"Co )c(&kc˸ 

؋6>웉8T24عbC3r.IHWtZ \:?a)]rY^yڝ&n-i&.c#.;:+{i`옇fr}$H,e j+) SJl<*D^]0n(>Tsu4+ոINLS)f8/R7`eUo6h߾(Xr)$it YhNv&E?֘b 5 PC E* b!V3[Chb4' ^ڴC͝ *닧Mk4yuL{nߤ{APӌE mkf_գ#sZ( -^)oX)Sh[>Xp|yy B[+əKF+qbtYؽ&1΢³7a|1և9x#2*<$N_jp}"`{<`6U(WWJnzu).2CC]pS-2!I_xz5 WfӇ5 a !Nn!;t?њHfJ6.7Ma?W@hR4 ^.F-4ёC7W~_GjnƤ~|@B,82:<9,Tڍ+au{Lp< :S.ZN'%Š@xM],x&' W_]5%Wol XQx 5@`PrQ~BAz*ח;b'ҫ&brEb:˽ڪ-!oTGlbbu+'$"1qe<t`A[ %tBYBP-)5y xA%l='3us_Fc%VκuR߰5nC{ȅ#?';gҪ'Y KW>"Om]@!s]x +$=KEiqKCW( ~).t #M|sv Q~< .@$sH Kx݊2o@Y13W_e U@*[`j]+4Ad8sOU\C^8O&Cd+%Zg#:w>٦$/l߯Q P>RuQJ'~u| ͫE߶@ }zvƄdō&yedϽtgxJ)6; ŀ[ O(8Sqc)"BẰ~xi =W}U5=yE8T.o]ͦ*oق|owUƙXlg_${q r};1\fb[2ӿY͋*]Cs3"EF&M,Bk!%󾠌OE jL!J-Us*'ޑ;퍿f(|3} 45wy /< F>#O0ZacGYt*@S^M4{%^A=>cp j%gFt,n();gJ8ķ4ODY8C>[=⦌+ @Z^ BZ$v{y8ΙbݞNBKfiwH]5gP vŦl毩v EE !7ԗ멝u %Jo&;ehxR\dfawԺ RK9يK4?/mh[ӁCAUe!yE2Wgc1î~p[JKK-~Ge1iæ͂_0AP-zEzn6&ѽpM_lZiyqMizDߴ~&Ru3f(oΡkHЊn543nɟ7VXyJ4QO; 'pWؖ%vݰزg{t<~8HXKC1XGkQn>#J&3s#dJjd:H~]*䔡#r.bfI I sx궯dZ}z $}Ӱ*]Ao2=:VcDML cF6Ԅ_+٥N)SP00ƢH:ׇּYo=nRb\[=:=X9(O拮*_ʜ:jcBiICi3_cS#(rFE'2wcҕ[(ɡtATz jWSGPڐ7Ѕ&}63TiUM9FE-dmC1KhOw*"!=Xg. y_|(Tqry1.2$yM io+P\.u?]@>q8Yec.ٙ:`|!U`*Bϐ{P[ta2Wݍy2B@3|Kg'OpeGܷx:*B,=!^/X޶z`-8_0?_:oV̢d#ZBJyEp6m5T\UKֶFsɆO:(RZ_̅RKą k=zr0% TKr [Fڻ +pպ3QLͼdS2C#I &R%k5&U}YPR6\vwS'0oP{yT$4F{ 9:R1FoF; 8O5o{EޯWqw\қڠNFIu  E ?9g)Zo?xW3k*)|Arן(Ga<;RxϵTWO@!2QiBbb ٕ4`G r#O}防mAjqwrbxF4%(p) :hA'6+NW 2x93jHl‚TV6`XH~9W͜ɢqsx[{ڗ{M4ZSO ,oĒ](?~ԇn3($ab=^,ǴSUuU%J u$I-vw!:-(*Up7շ/HqCmiiۖ=2ク!(>DjəМ5N@2a:k$ʐFWJG.H7qXK  uA{ 2+hȔ{iF;Ń~Ud?X6Ԝy!Psg_k3Jn9GMO^o4]$n\{|_0b_[ɰk>B- ث{xlz@񋠴2z;FYCd\D]CIKw(!MbK =2r;vf)(^<;gf a$k*'1!#( )TAZ;RW4 EaE"9Ihx#7ņTCE9Q|i\^6؍zOcZE<)]6}9n= ٝL0|O-g3UsU<⥩s.)UH9& |8b6 gx8@.;!Ԁh }J9鮊qLܿ`jm7 cܩPZo#%&݁d(khy  @rt!K7`j|0U6x1j%6^8 92vx5t󹓦-6W"6֭tU΀'_~b.bZ:H X:u xoM)3 B34w2%Bװ,KzCw%k:ĉc97#Fܮy|B؆GX}8*4Uo0$o=/xF7]tlíJ;$O(KoQS{m<`6o$hRh &d|*a9JnBVbFw4MːΚu/٘<)voK8Th 4BҜ}G^DVȶKo;5 |n+w~^漏v.$f;nzg5ihf"cP9 (i0U`xXjx*cv.>Nн^$U[Ϛ 6N, у(p۱:o1hE 5m^T6NF@,lcR!: 9\E\JIGW\ |:/k$*N1.Ro&b^wkApi$8Aar)?-ClI9Q-K‰fvkԃ暼:^Oa0@}rjnFĥ:^F:Ɓ3՞20c:'@\|:av|Iܐk$ ookM.ZR\6j&;I&2!N׷xYK@"FgsʍqW="q&nO+g*4qj:6VQxwi2gal*xO{L| (idl!́gzXQ`d:'Vu$aZPgn6;OC~|G VOJ)Q1gܬͺ8fmrf5Hv@vQ,ҿsܪFG>i` 1ӟ}O?{l-yNM{Hx1r7K~^|[XUs֗J\1yrE1kvj%.V_{ !+hT˃E6G Ch+eNU1H <^YIuX"8='S1{΅DZ`"O~{Ay wg7lQF9H@,;a XߙUAERei.BCHhXa-+Ww*'ϒ\Sxd.;;s:)b E@㲆r`2kh3a1#7GM>~( atzx]lqa&;O%s9 ܯv<6?\v;h`F.i]TDU_ʒ"_<-k~-wߐm k3ܥVS'0fa_ @$ۑ'W7N#$"**\c.:"X@)V(`y~D7,I /^ GF og=SJ]J|#ĽiQWΑ`ck8Kihh잫Hidݿlՙk;]oSNι?>'uD/*JFmKf;8m'32کc} $:ȴ]{ͧ^_宺j[Z'ݍL`( Hxd•溾eη7f] T:nD+J Lz8OmO1W%:cyH2:͛\H],wsX? (k݊t1UfaLHOvdž}"%8yHFRi޿ɻV n^$=v p"h ]qZhuq r'B.{lMkb'!nM?{kMSˈշU&8%6k5PAK-'fAdXj&7tkjw˰ݫ9ԷbPw76KL+d&Z2B1vu, Lu.,$ L rPaF#]A_I0z.۷32+TK|O^pKەr,&Ly[cm f\tm )uЄu$8լnjw}(:ʔkB) )_䆬Sh/!"ђy#i`ʌ%4LxSo|$ eCly&ک.'Zb x~@bI.mfYý8*wJ/?Q( 1iWa605GTO]3BNx#mpL=lu) [^mfڒY7da%$D?rW!G:O5 453׹! *[3M&*PRQƛHjׁx qH-HmO}nn>M*$]*RK5bV?67KGn_r=1@tɠ{~. 1e&akKv> FeL j;(_]7\Aj}-m>5M'>?wlGKR7k?$ed$XFV7X HpؐǠpo xCտNiH4 W˔R:G_%'w{?dxs1 p vJwԂ@>!u 4o S~#HaF#,u^4ؾc+pMI3]/SxZM«fV5t?*Rx]8B^ӡџTƁ&}vfp L\<8]GV ܇T@:QA eMw%k_O(xlbR\#~>VV 'PU&յ1T.ДN֬>:7%l:.;9o8zƉ`M'T13$6șqՖ j`G]d?ixe{TmJK6q|  Z0`q+1@vu^2\:pzb0 czB4u}ZsBm-Bo[J' ^cj df+~lc fto_xn JCOR:M*@^6Jd\ZVkKsZ.lbC.ڊQbAD"o'M)*} gtoA#pȤ3Ū'] B){k:uەTD zSX m}*4/]TaehmF4-_$95<'X=)YD$,U*@2{$ᘀ^^Z-?!VqKǿ_ؕj , "epƬM Y>>U~<=XoH,(˘sAM!5s$*o ?e ‡4f^D rG>Taǀ5ɋvmtx+ @Uڽ3glvR=fh~ud'R&NW&kNJ?݁vV%+kƐi_}qa C18Gfx9i*ta x儱S-}/ r7MoHGXf&E]S{8(˓b0l:e ,ybs"V$j /Б,4n?:j5tκt5_`'5{)]ȿo\^uQU: ]Sj8Wsvj6!T/hyr*4qE3iІl6K40xRǁ Y*ɔS(U=q!#Ayk07l]t̏#+XM}3p7utP*z[#w1Ў@UL̏&wf~s96[#@}n#MgUgpWz($((̺2DܾFr-\\OóDpG!Lg^Agt쑔%[')X vvw4D_pL0gv\ wUj[qN,ֲfG3Ւ>Xr; RAQ MdadU-C% )!Ih 1kFKC4_?U,ByZ[7W \w2ZKrٚ* f_U+ >):u6Z{9Wšqb1|^^s/ۆ1)m`q~|ɽK6ҽf2dU}$1>\rn~çRAu ɉC\n89`VNuC}~IWfX6EW:k>~>]Mb oveF-'Gg˼vS֑Yc;fCK3x&YPo8CB \-iҜS@ZDS/4=3Yu=dF3=I۸ @B;~3` *[c1Х䞝♙3OHX ԏ΃t΀R0w.JSoTj`G/cX z|FfU8q[^WkW߬J-fMӧ4 goXvO o['㩋XR +s͵1, e4AVzFn;SKoƻ<#{sLћgڥ-)_NQ"7H pz . FA)%pqаck={& ~'%E ǣOibX+l^y}A;ђ #8&Z%my&hS|cswGqCui۠B!gi^!`AqtOU$º~\Kq\Afa-%@YS_&f sﬖF^7:@O@G3wzυCR.Sq)b>Sv.q6_~RDйQI=ʓJjFPCM'sL[iɲuֿ sҡ>CD,`(OT+vo&5bcs#c?S%-םMeIU_*c*]o>WE)Rgi%juya7QI z^Zv ?)Um(a [z^e#?aedڒg+}›o#_!MR(S[ϑjD_ˑ,m7 Yi܃j*7Ls푖V&ӜGHM܎339BB)|YT;oWyTۧ`#x|hN+QuZt)Aymp3C?nύns+g| ΅C^?d9E<=Cr|z3U-[ŅǨu]d|c_p.||ϻLb͍Ne)[e Kfŷ2#T~6I2C^jO{>G`盒{$?v6hBsg<}{(AOp_:F3FT-Ķe T➃S8[EtMAGxk?EP7?O>' RxR= 0hFMW6L%ڊ6XJ1ޅ5)Ѫ`V_*>80 2) Pd):kzF U/f!(ُ/:~2Dbqq )$hY5,fL]dЅb@0&B[dJ j,EJ 1f*^kX0HA 0x|/=,@ .ၞE7%[t_;"D@J ZN!!XJ/bJ2s7ʀRˡb0X *1/:1{E~-764|*zLe8*3 Uy9],U/C@^v?,F6U0red>(ly_gj 3;5~>>nt{/Eq̺V(`QJ+/=&Y&-.PfjL߃uX[A^! kJ6㮙YE =@P=D=đ'K1sX$7o4fDߊ'݅xVG(6i>^Oz¤[޺iӝO`5dIC:57<T.=r/}#js.3RGQsU@XΒ2' 8 uӋk[:A[jB !Ymj1_;q^.m mG킣2; kC~\j3kuݮtHvb^?! 3{:kO5#6>{A,G;5r,R[8|ŊmTLf5}؄hT7Q\u_Ne}w%zxC8`+?C".ؓIWLsfRu➭h^JSobE=t7C6Ȼn߼t܏*f+%tGT8,F"+5A5qET:^)զ.̺xȋr0ތ"1jǬM^c1]Eڐ]ԠrcSua1`GtHsl2Y[-Gp0'Ϊ<ڱ- Sešjw ϯZӶJ/pړVܘ^a!ǜZkÎq V$;K뤌|0bZ7}vGaL49!hcK3E3Guw 7ӓ9;zT2jsaS,=Cg`B|^3-V4NLRx52<ɞrJKkv]wyD蟙 >vM`鯍c>7-zƆOaw#-Eq ʌyϢ"ngs(a-^7}([m,ȋi_8&EsTOh޼sEW:_I!*@SnĂOWFk7JaI+3]H<~3 cn;71k~Q0VCp5X^Y4kaC6I@:‚g_ϠE ߑ|%I N6tYlz\~-c~斓)֝ >ߑ߮Iv=f `A3aX*ɞwWFMX=zx)'"vCs±W^I6;zې@U(ai?˽#+v"/Z}1)p0B41Ju7'a.Xпu hM?~1bم;zxހٯW:)< j>LMxTΤ@$DК!9?N h+PSɨW(p .I9F 8ZnvQ[*s*J%Ϫݗt+yrqQPRl+`ڌG(tuJ43/W.ƽg#Ҷ'v_G*.q!X"' _PC ]k,%U R)ZS}ZpM ݪ S $o˗$1օlOTTr{Wԯ8i0RԘ~=8ޖ鉦_x}cI~%r6u@Puju!vV8[i `D$u4;<ZҦbyXdj"ݰÌ(2ZIgdPXC zCwoTʖ pqqG^vb;rλ4 yMp `y @%]y}6@0Ͻˉ-Cf "JwN=Z‡'x#6lx* !VI#O5 ћ~ 5;RceftU_Z[ xKE׸#0Gᨊ!  {C~}|jKRV+h@GV5\"SW6n"o&~/Fc ~ 3*zcWк'̜W0=jn4P}֊n7.P'BN5V[#d1U4ȼ_)3R)DX KVMQE" yfM\P9LE1_>9f#XEdޭ\ !Ej:2.J 3W-8ڿu[ *F TŤ lBiCN%wX@m:|1hk)k*C:q+(!TLIl_rJzc۟ u06"H9,WH0[HdDPċ A( v g}”z]* DzجjswcKPd̤)`!iT\{ܭ>V=xd ʓ1bC2@o%zyFvݡxb"+()P) ūH;쯠#'~xP5}=:ɔ=e#'SV&8؜CTX\ag514gݿp0{]YO& RUkiV_q˳n*P6{EhmA|;"Ae5;pu$= b#u傋+~ףΡ'gݾAľӌI˹|qh.lze=wõ ak)$rEu}C_c_KPd 1ږ#Ǩ5f"Yp2"d vs=V՛3d>s j {Cj Grcv 9愾l3)b!Ǝv ҭ >4֫2 k L ,_{O ]ē@=udb/% ",jK*?MQ\n\!t6̕yUH!` ɯ!P^qkqRAk&q%ƫ@kgF1*s3:ECˉԈ$+;0VЬ?9=W KkOZ7c O}aqd!{uN9]:x8PhyPS)@^lD.AmɪA%FHO?hλq.voV&sV"T~]Tn@~ S]GȜU6bt? 7ESKu\n(T(t&p_gۘ^Tpm#|@> kxN1g8{Kֽ:x%LS%zVqvhT\_>wS>Hj)$7s/8Ӆ=!"}&8guoGھOgP[:hxlܚR}5ܶzRf:O uo!:V0ND pHˬu#r\JJhdž[M$rw^ x/+0r_|x:-iI?l! 7dKVE yPz|4׿kK7ibZ˂?lWw\?ydxʹ?1Sv>M5Wʋ?9o홯'=,! {6Z\)~i0Ã}N}Qicȿ1nF?$Ȣ h➌.rp@TJi#-A)ᛕҬx̪>ط׽LrP2ut`ʑŏZǍɨlĂHWp e -z;jhdfH1 w;'DD[AA(a0?H68,LG 3w7huÓjuK5n.H'N;ib*x7xЈgԎK:S[`Ɨ15Hg7h}t`W)j[h RVT)Ik8XT:1 |QnCSĪN/R^Ҁ=k  A9M{1X  ȥWUg/e&3*x|2s[Mtfu+sRW"7ީHt*ϤسVN䎣o_vOu ]a»6BLC=JP [ Zbk)%S#`p1|h,ƉL)-reHV3!e`cBKO[p7^gsD;fm'qjeԛ8˼^Gxyyy}Y*TV[1QupBQ,<3 Q#DӮ('&Fjix waikRVIBLQHr,w)HUKՇ t6=R-?L_:ߛ۹bf||?F*efRzi_= +9c, sUE?[CH).11g}0G׀R"?j@]lՕ_Cӽc9=G{}T0klR&i IxW߈-FaD{Eh,Jxk0 O$vΝ\ase o+vzpI.c/?%AAΰ](`auWS;L-'cRml||<|;=Vt"Qmm_Wg;}(.Zڼޣڌ<9Bˎ]DeӹzZ+M<;#HIba{EUzhK/ A`vtT;>`}4D<\CwMF ǚg{ &+*DqpKRA}R̥XݘN"'|iY~/Um?B"P !5~DŲل,PY ɯhD-OegΚ2}-4 lz^1/@B,i~G Y|g@>>oD׹<ο#Y0 D- T(1=>B%py;yMm?׫U:bᱛ$ "#o 1Hn8w#m bMaݶXu]a;K=S 8l @!X@H. (xE^xVJX׎ht\NbOMYQt^bO`XH=Cn?3&+9zԞÕ5 #|;͡ae_Ľg(Εho\8#2'h*21]qG"~4 KUV ?OJh])|I^kUDvXuc ,T,k )bV fah­t>41oꮶqE?Rz/~}mx9q+Q5&s㺙i|AtX>ZqM.OVQ~Ec0 k>HfD{bNeh9_Jx:?r/<eFW"O<s;u$f6+Y[jJBx,=R B?qi\oH]{\Ouz4tx% &4fv` XLn]\]//=k]`9>pB^@pG?HBsOI#K\ɯ`3Cg#41 /ąw'JxWFV3WF1{3_uc7syTd[ V٦Nʯ(GҼO#f5efBtJGP]h3_HLY=`nGm 8kd~}DOP1.f*X5M"'bc &tڌ#rQ*' nGg1rXL,r)An fݲDj(.a_r¿&@xl/?8}`8C,;gڙ%VKBT`& ~9mBJޓ|5d-]6>/D|ft'+<:.|D(n~50*\e`k_6h>3ܒ҆+ɋ[)jl͠j“筌'gD;AK1y)B!ל-/$7ma rysG&x1|s7Zyڔ=ɡ ~y4f[: tmPOFp5b{\2QR-'`\Z,-a<2svOUpOPBDKoc *9US$Je¢dl.4nu @ާdUY kq@WӓWqLȨkbS&bұ،d&>&W y賠ǥDcGxY#Ѭ@(f+EYc# Oݦe Ǎ)esJδ[4'M!eJaC$gHL"=\Kǩp| * V m'n8ڐfD#$:,}%{IrqR%@(2hq\"ɕhw!xYO0W,9tyfˣ^ȂWCHld7^Ov[[-6 eH, yJ ޷\۹U<ˠ瞅OQD׾i>Įj!Q 9@Ӱ#5=v/wj +6$Ijx3;Ex g`o#9;!tKjG Vڲ53 '}O3HyLsaӍJSkxkwC|}z yy!XZ5,"$_P}6Ӂ?mNcxð׿3ER8dV xm^ "aG{!t{u=pMڣ%K1?(7I1(%;-$Vz3_qmֻn(cfD)ilkf-%"D>[$-+(Q;$*0Hh+ܾwJֱ<9Њs<Dž{kt)l`iG.}p(dBs-btDoy'DVj9b&찡]M \p,^FNmKf$_g݉h'PT^l4\\ $_EIJOwH'ǔפIgRd{4UʤP[ưӁ^V=A;]bRC?N{X!ۓ>#p&%S*6h`;!8MnΫȐCB׌/DZn*s/Fnx5I9baQ1:<ß۲96o9`lqFHS@|I2m 'K aΖߍY_æH,QqVC|VCHI\bo"x3ټ[|wa L`g# F9ؘ&Kɺe ZY4Q˪ޢrRƑ^a ,Hul~rvM],i/0P3vH g8C ZCh9c )䰍- ,;I`OVHV%paL (oa$s?pغK@h HH"z+Ǹ3dǁ.9Cz|8ܗYLx5>R:b&tp^\J),w' cyDз=tZޅ{@GQKzG7#o"@^50BA,3Ҁ߬yNWgoov+̓->쓘<4yy^qsrҢ;]YY?!m+l_wa|o-@H>ټm];.2{,ۓY3YOKO٤Tpbơ2H6nĊxH8Wc.@5 z\29fk_*|n|}oB\BezOĂ@am&#Ur)3k4qMkN3gќ,gO -QCۋ)6)+u^v"CĞQIhpIF`7W#hOt- 4?!@MT3&H*khnSEc؛0;5-׫/*i*_NBHKㄒZׯ#CS&])|&Ț~ݱYwSR'č7aCvRZi7 \Rܼdg 1*dJh8 |;O$lڄ "hh*+kFRtF- R|4HRի\!EvDz7<*K'ҥp!äP3 P5A}s!KWd7i3}M&Nٗ0ʓ.H,R)R"##Ra]uOz/ ޭ}KQh#36+sd W݄. G3NY:u6]t'd*&,NTJCd9TVYy<=P+5i-\֜掶#ADN֬.z["qbS 0;!F(OP1JTjYC [o,[o? #Rgq* uD5s.$间B:}UMY:vxtSnmȑ3 󱡷XbӪ*Mr9 ,cLbw_ڴU!@$?$ bg))QxP@h UfBJ0xk{o4AyzԼ.g}]%y]p]  {\W2_xd`/E{XMzCH|y2Я?Pm!*{/YƝ;4YOڧzH&%H/ڽàvFz@x |CeGn5򲨃P]icc;]Nd'`Ӊoߪө@ _ݒnC~DMBGYR;0E`# '{4uF:?>oI5;<,^J .|?FLsxRBWׇ?umhpIl n#PZsTg R"?&0bU (';ܘ>g΀9oĊpQvO 3(y%^əQՋ՚M͹\g+qLfTxr8ۍkhf>)I,>uo;4Z*827BòaO C+{3>AֺG$KLm5! )8>@}1WM.~` e9`ҡ==ZܶJ{~Ҹ9Py\񭋅 (M^Lvyv{ଊThJ=*QP e2]),Lj7TgA{*S¸o>PiZsk:<0=?[}<<ZݢPlJum _vOnՠ?g_+:V~I=BI ],P.uubV{9˟U 9m1y Q?ҁJ:sLA@vf&+uRk>F 'u 1q!H+hlYG8Yo!&Y=2.2!-Z-ce=!2z<煩oaK3/6 \AZp@:8r+#9[F_Qtgks[O[__A+lrL]CGgM=Zo$e=$7ѾA|^ yI꜂?&d}|(=` cTUⵌ+46ji Jd0(Vq)pJԴ3wv/Cg#1nB׏-UCأ*rƧh HnqSZ#d[8KOM}u1(sPv0Sn,ueY[bjLB;yC'ˌk*P~&{5u:fG܊B(ˁ"&ɊwN8vZ]*[ ;vګǎuK©Q{(kcOr"O5ײ=5l7҇-1*-<,a <Ӓ)1 `xhC=ddc^}R zqw򠈗??* 5Ma[ U`;${Z G4x%cXom$;{ǩb sDWs3`hy9g|O cMl\}@já6jl ^@3~܃73O5x@|pFAXY>N~8b.~5uH,2[QgH7MN' _$uF\~{}Ҵ٭;N7ӂ7X9[ ֆcmA'됄~v;j}+mnmA* ]DiI _Βb*u&V14 k9ZS,D [apYU-yXbL3 \SK7ǬOI%T;6c̎{}ıTa?=`,I1,$Pz^.\8s犳[@YQw3\eO&s];wA$҈N8NοPLm. ăNb|* wk(W$fj=}gOE6')WKB=9^s=(46}2S4,Gwe}L{ xv*-'w^yP S ; 9'c+\ A3PV<b9^MڙMIFZJ l9?_Ƙ2$͖9=7)c3})8Dd8 7; Ve=)FsjtXiL5 !T<QQl"KjdަXɍj+!Z[Q"MDWZƊZR!uvL+q]{LP~uqjggpd^gչ|R+e&I#^i!*IDny>rvK}`WʨᗣŞ_zA_sd\_t` /f< Zσ/ =̡1auRU73/Om`^h6Hذh(|+~X=< téGHDw5sTqE(^i%G.V4;!}'>B)^\ՊƼLŖn;QJ|㟞cCo(0.W@դ\@ŨB 0hfԨ ?,=7uGkX!_2UdW5Tl`nC'[Zݼ[qIs!Y#eʇ!u5díapg͓*CM h_#+wİd$aʸgdiD1Yv:ҩ_ad uaJ\͏֓Hjj͒b\ƯЋ-r_? &/*k5'B-rdkN Ta 颟f /%_\ƶ̎-=Q}/S FAk۠uѮغ_"< 0l˝]Ytc|D͕K.J-O bȂ9r5^CopQ`JCģZ%'M!~DZ.kR70dž}nƅd'.xFݓEHHn hUz(߼W 7ÿ!x8P(o+N VW̓M{h3~y1i(u@x`6Bii (<#s`K/C3IaӋ, HP $.&ם&?(G1_xyQ|8O7LuGPFcj8T ҳly=J Js8)j+k3wvᵏ+hu[Og_&@4*o(]P햎C˥G#c3WO's|yE6?B8[v}!h5lWD Z^Ctyȁ  VvAO]3x[0m_rno{.CsN8 :73.RQf'^Bf{ ё,EKoHNO/wZԣd '));YKlXqY>^~GEܮA^)S,*P}oQ4xV||\JD$ܴ\Z{Xo5 4wQdLckR1@-qTB6VAW_ cramqcwT9O-5sq;f=+%ס]D h%¸g2 f@No>Asm{VЃԉd?RA_f>;R9 ԑ&K#WSG}xe%?wv]I0Zⷕ*ѯnӽ+YQ{2u1bn@zr,Ô룋ýGowPp 'k]̬zf▢@}aq'/j~}B18T4FCZS>3kI03JlԦWۖʢ8H!L&?ؑ4njøZ6Ilu?jZѨ8mNj}~izjl$`bO&Q#lKH됭XIdfm1g0tp sC7SZMx?b;`0L]"BP1,J4:emdWI l38w#`H"@mm?wNIZ=h}Nd1d?u -@H+MeoCqnRFo.\b"[Q `$xۨ Mp8fcbWhpX2zz+iɋīM.Iz.ӧ%{s 0A;gFtܰ=3t}8V׀N rhꂋt"Dޜhŝ"|  \ t4s2yg!Vczkoe9ΕUhe}ۋ3FQv+r^5x#{xEڱnfx=!U# Hlmt9j8CiTeVN~=;HsE9V}Ȳ^Mئo z_PK鑍#*EcsqlbJ7, ,OËѹB-H>/(Gה2wCGJNjAZsX,܏녭/pSfXɝ b!I<gm: K53ʭgi͍(MJҍ5+d0uKHJgH8zI(ޭrl9S*5o9`0M03lJ^Y'̥H8jf]5"†k ֺp+`[؊r袦(yQۜzN |TW&ΣܡQ?|61GRvkn>dNoM'yK񤍼c,]:^G\48ІPtQj~٪hS3dz3g*eq!mǓ_FWeE&D9#U=ոym8x/\r wo:eRpg ţ(%ܙ/ܾ'$8k'Y^J6G. J|Lc -9H wXk<ݠ,)|!ѿ ~S>T3+ͺ\R\B`-\ntC wZeIPX0h ..fsA5S͞E9p_Qs}i(ׄcihi]z!fG.I[݁3d!piL~IR{ YGop,9l Mw$0q*uxXzyt_TGjGyC7a O GYNFSwwrE3&R7wfD#[LGd3${fJ[a!A,DzjAYdL0~;D)nӛ.wDƮWV6%ƨ48W8 KX"|gA'@7kijyHG'r\R:U 9dN&> !F0zWgeIѸ4cOϤj[& ~P, s7]Y5{2`2ʏW畅WαL7cRbI~~OKBrONNt":&m5ȕ͸po[cr[!X5=ɺz5,>]zvgҎ Gu٠ :j)/XI_B>E{Gw})-%ukĹ^Ґiylո]P өzz\‰P^^>OJm}e:p,&%zc@:!uP[9_ӴX+mzxpCl7zUnlLյ` MVXznj*cU"eYkq$Ef/ډ}B#qQq7y hD潝ОP zMI!!mLÇyQP`Q2.a{}kbĘ5έI^*CH5S@&\ˢ$3j}1݂Qj~m .k_f]\`؛bhUH ^cRo J]ͿV^ ͂= 2`\ws YR:8]O<k.roݡ,yV T ەXP96>@RZ0X;}yCb&tԜm|IPBIVzS1+ŋғo?۝A#Q:2샂oLʃ$F?fWoq|8TcvvљWMEb0 S^$m4oӊ H;t WA$ H|B$Kם%BStʡ>1n2eP*EQ"R(f"' Jz]1iYT)ѫҰ(>6 1TE+^X|АX'؝YUKaN׵@oX5_^x!3/ T im[%Ž aA 0E6סo-OS#9[os?rp]]0IY*2<ȷWyDQ) ߂@.x[s@|=s|sO;OY u6hIg2DԄ^۟HTXWGfMJ_!:j`Y`<,R aҽtTÈP+Q\(gG4D+D*&w*s$bWۛlHٮ 1>P̯  nEZKXrVwR =Vx<N:$>Ÿ$`=?/MD3'{ٱ2f:,.k`h%oHexaOtٙ1Yܢ6ޘfINU[QNv/`.)% Q$T'T/e3~# h{hNRa43>Gב{P&M`ydh}>xʡc7GsgGI )Es"Aͭ߬&Xb{4sw\LJuvV @am;UE_}?h[]Ƕu}owͣ;\\[)A^O sl)SMl !c+k0P퐁a!ЖՒ|!FQx޻{w^ȅu̫/MrTVtɡS]! "~{*sD>Smx敮>Z=\}=Q7 iR`TL;z.6-irwZʀSN3Q\YԖm )MmW^[BR9M(νD{l28ז0{0/\uq'-|`OE:IY bNKvuRm+T)UZ }HZS..Yg*B4w#^FHFͭ.[i"S`EvڋKRHuMp`vz N,Em"%D2fl#^/:C/QN|toȇջ>BL>M5ޓDfoI+Ƴ)VA\8YXsW4t'UKaQ\tl} d "($Ähtk3V%V3֒SP樂<)I3{:Sm&P*3X2@6e %`:\a8p=I\d6e2J{,+gH 棐~- L'Ր;EkV&-IlT<8E=ʻ ˉ?~/@Hr=9q&(f! oOfqwryEA1ÙҧmԂ! Pl(g `Gm.vkQV O*JœN§Np@QF/ "6b, t$gEK gQDOhHL(OI8@G/<IM9n1=v0Y)IOH)[tY0ljIRwS#2KOnNm6zfP4}G/ UqMO6EA5j wy>3|[PIk</g0ķb:䮵䘫^N Vtnk ڬ[ñ׽{(ڎ2\ɍug`2hQiBETXoqGUte^@0o/4Au0>[b ==(r=#Xxq$CnT>^FL< \8AșN穌6_NbM8 _PYI*~3 y 8)`m3֫E{>b8͠  5Dt~M݂iK>_we5٣DU"{,E }E0q~ \6o#':@8 -2o (t7Ơr/AB(Zgk1tZT%+V,9GGtEJIGn }؁\=n+(BtSWB !{MVzLe{flQ>m ]`vwuG3ei K9SySo{.swm(:ԃJXeڇTJbsO)!>ʉ nv;^`vq,҅YQPjz'^ԂЉըgi9ma ,vrj<fp#º}o'Z#bwFs*tp~14cڛURA-v .(h =jl- G9P[ ®Gx9}DYcG)l&ְEGtQv3ݙ9 c9y"ޢ\'w1Z#.Mi-c:`4Ǻ$#~hcfi唓|AX?f_e1H \c;ˬMR%Wĕ/:mL?&sG<9!uf9t]R,{p,Im7k$Yނ 'PXOѐI+?\Mpj1$bkL@] Ds!A*ZzkS'C0h ?AB(Zut}$$w~mЌbEtԬ-}Z'{81*:rGru9>3$>IfQp0lnJ zs ;ʼVr3œ^;|7 |8)GWIF| ljN¤ibr/g 򟻒ؐXgC/[3._s _O8X_發7-jRd7j-jDjKL"4+lgbZKE xuRekX|A`үlSLNo6]&1ֿQ{GAh#^nD_Sw`4u9@fhr_@if B"sGX)$*hA zN~=stwNMXX֫ܳUIH/1qXWEwd CE):Tfqoi.[Pf(D%.Lk4 v,``]4u"A$TJ:D c%:"ܯY>A7OWn8:TՀ[u?/FCnC*^ gI)GOa,r:A,tSz ;4`z?D$F kcXb l =I@Vm[sh._V]ʧ&~cȈF^M>r__U;uoY?s6uRh +yT\K[ }bDzw! i)eO5Xg+9`?-9~%W+~,1 ^ C[KK3]9H=QK5fe֦CN",߆(3<lJe0fS?Y 8P.wg(< 'yt FnS6w> jY$.4Pz#V KmȲJ'9UI}F#y7q1 <}\,qWQb%wv^ui, 6s\%Q=1JELfŒҎp `l%e4I~i{ӽ0_uswzŒ|~fphox 2!Gb%G^]wCUX1t'>i{#€ksh [ $u|f6ij )=6Vv*EF-WfDvfqbv,q_:,K (Ɣu^k)s>2'6x D _$ګzA2at;2h] t7HyRBjYGNZ /2vFK.̡j<7삐 V8ӑHλS;ꋳo]խ Y )=ʉ"]kӤf#zUQnwR;}r(u#.%G޽m,﵀#g"[<vץò$m•xׅ{̱U>_ݣDo AאyUl84`8g2R2hTG5R9c$a_)o7 NI7_:|~Ӓ TK j 2}iB{wM"_MDi{4D{[O(ӝwз!fkyP!b%zG <~䐟E;1?NbPc]% @@QJt|Fl#SQ10I0 _\aɇOԿTm&{firu[f/N?hZQ%wygbRsnt:VU6_Ȯ^ӞMJ llj[`d.^S`}ڃ1]~s4zĴ p[O{٦i{;s;9Bl:)6QÖ?WtMZv i5R` ]a0jG?E[T^AΣg='Kf0JE*L_ ..~VnJ0'poLסWVD0{|2WA[>9whau#da_;ؒM,n\`}GשTшE)'pcuBq`j뙱_K B@eyތ>J&UE%d80n͕O)KkUuĩb[wڡXoe=1W^rIy? Ŧ)_:ֶuEQ-?}]ylv";?y!_gTQX%V0{0}wC0Pv?kdz\?E|db\1TFRbVd_%EXԲL^Zeu5L_Ʊsu*˶z uU1΋H<\;쾊ՙ7Z "@U^G{2 $ 261$|k>1r5 <+/т_*6Ghoc8 ,7){T197C|쐅&fXL o2hɻ(# 4cr3ύ 06섹&+I \a]GbcX`3>:Rc^+{8 &u$\33 Dzae%Kz? u~9sܴ#7ˑu(i djO_F9E$!n÷.D1;Kr]dOHu gĤ~S^9i& Z. &6i\R·ʮ3@8hX,ǼqobW ً"38a3 'DS9n'cP~1,/hR,cƆt v?:T(=D\= k7bd!uެ 49cȕ{nr!#CO]?yiܤ7@=Vd~CyE Rۺ]#7{8X{$K]zEEqtт2mV?kC+!R"W' qR40g,T{ W9先w|Y+k^:w-%yW}yA,^֛̫Xn+j/p<>H@# 6N6MmwEeE DpN/m4Xs͛TS Q2AP+hBBXDP◺FRO*"=9&.4N 1ĿncU$"U7U#"/$s :Q JM8 d&bH,JS\D.u .'A5e1 <|p˜)GC'͈' ו/4-}<1`VU=ʢSj-H44!;_ % җP+=~ߊ HTؠG (~" '],_y9{pon"d;tFn'*Z!0W~&[m2tR( W+R^W /9~oцm£7W-@~*{s4#/WQz@K?:7zU,c(;CX:DX9YpYpJBKV#xm._!$9 ιNS:;0:AyUTv%leCZ1rQ7DU.~Mn428Q=)El`|>>W;QC0 dhP=<+\%Pޒe6stwʥdjBUG< 8aq$}*=En=5hQENfbo/9%;g`uBEV ˓Vۂ/+-A}ns[Louus5ILNwP;%ߢ.Ӷ߃M Xk9kJQz3e}̕=z˶enh}VtǽI&-1}si{5Z_.43s;X"c4E4o9on߫c Jm^\璪}8=Ls1WGިք9 *Yb1Dz!*-2Tu<wJ>?\a}ѳWAa'eluS7,(RA)8.h҈y\^H~-g(dpBDhFdTƟ,}6wQEXXW-jhH& ZZS :^ rԀ,·~aŮca~0?/zkUJ"$6kKݣ` 'Yh!U2|2.5?A0Lgcrx 1z"=O,ROSx]NA h'lӨJ#h <`[ )"OXMa2e/P(L-C Y:Yioe:2:bCf~C5vXQ]ab(d!KYtM5P1Ib5lZtF8b|i\2Z5]=cީ 4 ,e;$ؤh'~'g/"͙R̮}٧fU>vw$锝<^ Kpu7xٿu z>Ao+NMMTJܩ,VvQP_@M!K{_%YW3ƭ̸pl'Q{bdN@©-Ŀs'~Sfci.풟 E5&Қ0&&EA7u =TC@Jgy\'@VNOj1d.Ve6K>cw<˧u,>\T 'ȬOM=!s"pQǧA,>i_~'Z0@U>J|2$/>RJʵ&]M6mG(9o,"&E<{f,\I3 w431eW [3% C";f6qBq U ̃xتdą 6^EPr/#֍ٛ@ł$5X祾 9 Ez󩚖bʾJT"mȽX\I$=g7z̅fgo>>+Tԑt[MS!Kr@^-ČoR/ֶuuG%'O}ʹdg=|~+aaң>, @ ߪmu<50v·^,WVE&-x.cڗ4$  Iu0 6n|8s/=ւ(6=am)>,xy@Y#]σz⪌C0+0=z~*(,0csuGyWGiU mA\4, *f-U*>4@HUC _ﺒq,1v@;מXG`3g] 3Eh*Ңn\wj%hnmm':8B\60c z&9bA>;ɹ~.`?Q n>K`p]:jq^h]v8]xO86ZJL76p3Y3OE3(݆6t#nH_bȊ Q@\Dcs)o4&16^Jr,[ wu)# h۝'(?MB!g{-jJ C:wX%̩, !] GDԏ[r\&b6dzrg +#ˌY e AmH*y A#אQ:Ci 0P(\)֐[ua8` U݆V!p^b7ew!dO?`)B4NL\N9>Z_V3mWPRSzB%csW*,CrHl .ggyW^Xh*:h!F3v6BIpd{p3bdP~!V|)=o`n/l'?Bzuyl+Œ˵[,SϵQg )FO(Fܐ,!r&e S}bV+LqO,G4-}AlQ+FA1Z|ag#(_DKQDaXE-ͻd^'8k"C&3&~HTZ'w2~D 9]B'ay&L1XQ? \{LLjʙx3~huFKXߏŹBms=ZeKA HGXt^ |.&q)cm+gFdViKLc-G^s,"]6^.Kݵ0uY2<`pe٬0! /*޽pB8E69b=fi][$mQJ2EN~^G :0t][+;F7#]EeE:y\G]򴒃8%Kf*?TbeRh;NS!vՕmZaJCװ!4uu:(lޔ#1sfD]"$MRAtB$/'fcq(W쏵 r{),KszO@ R M>G,6修iL+g}c[Rb?/t]g6I5&6(>QMD{ksdcƿZ #ȲyEsᇵ!I8iPbGTw`܋Y Ť"41M*Iǜ1ÇIE\$qs+1ʯf~AF!eE8&)ZS_)ts.+O߾s5iTlcd}TM0XQDA\bVkk{ ;ëvW|M6[Lah61VUE&r&!yS U>T𡩄C7 ӹKsYƈF9 WšVqČ|' F!~n^r7' 4/Li0RK>w Zml@+ R+\fTt/# Io{n/Y[d 1p9 b܌?+y4k;0%eYJacQ/ *>W7uܴSqFӼ Ф$ϙbv!@ A^Gr"DuWJc6.P2BZ+ /)yU{?<{$U8d`(v Lʸ"ځuoa xG/o|$X$bͳƦg& .?WYu-h췥n& }s(tT׿ =,yR^,LwlxJ)[{ݱV&-@< (B,Oj'Q6*ϒQٸⴵ(v'i/#W;aԊyCizt9ZSN~|o>-gwmt"JG7M@vF?K+-0707010000000d000081a40000000000000000000000016477168400005143000000000000000000000000000000000000002500000000./usr/share/man/uk/man5/sssd-ad.5.gz}ysǕܕ ؍(@-1L @4 @[nI "$͡@D8M @_6ߑ/ $ Ye;⦅NZ}CooҪƣQ,vk_\vN}xnW7hrrr<Vk9:۞oJ6ToyOOCh5km|(-TމZF}nN/GN /6GFFNj8GCf4;E U"KO q+*svVR?G+l5./-ĵbR ~n*sBԊSգj<׊J-תzع ѫ/L0MNMLMF83n7ΞcMF[;XVXbwM܎̓X04bs/_vZ]K+xC_v%P1^ \WpG3PkjRv.ū#u5^Wډ}s&_P/GfOFyࣃĽ*Twu烫,4WanG4 0˺_tR'p ;~ڽѽ,9({ziCzmwGpK}A֩G"ݝBtpMz=mg\aMwpz밫MYx^AY&q!CPS|ST+` ݧIRë V~: xE=6p 'hhj:nΦ:ի M0Q%_&NEC36u|@':[x0_Ё!Wno @q u:6wi$'%Г@c,=V0$sEs}ɥDHZ=a{ɬ^v}Se~ėݾ(I_8&@f$! ^N7Q sߎ(lº;,^D2֚-خÉeJAӤX@.񭐑`\\"+xgF~1{G-S$ۍqn^%o:m-ȊX̹^%Ӈ DL0I[aˑ4:^Rn0;lK:k̹6t u߅%ރ[F0ꈅĿֱE$#2 9%g{ٰtE1HH tBs Qk: : { Z$0y,:WBJ!5ە}tϻ?77@R)9w/z3{C*kJ:8z2*^7v>2` [dvAafl I^v>EVmO{ȭ* {d 37Zz^/~H W 9t՜fw*r GGj _*ͦJټNM]R.;@[E9ۖx9,5\EZ[ų'iN>4$qȌZmu}_#n|O0Be' n'aI>*mO,M'&e_t7Q8oၐZ~MoHV4\8yWK8^]l˜}Cͥ\Tuohb2zohjs}dgA/*j3}Csgu5$'^z}z<\$TӶ4Ph _ïvqXwM%_R5;hjNzSAcª >ʧwO:V{N8Q &^m_#bE׸T7h"mτWGo?hCWR*>p]aX=:lMqp'jv<3[mo)[3Wٻrh)6&xoMd9xjoM??%.ϙN@7fVΘmʵ^6 Ҋ괊*\Q!/ZJmeW`kD~g<^=R?2m ȾꥇȯJE=)}lPV*2P 9ٲ{ !C^Ij-ߴ<ŀAk+};(z[e!"`P+ypC }~YԿX Bg6.*eEby\_,VjQmjg, :x$˘dİOǨڤI /}Ht`'>Us/בzZH4''T~ť0aяפft?Ĩck!G;6C0h_J;v;DT.WY6p qs'E g{\C`5Ihmx,*Ӄx(rh>񷓺yn.bP͈w+jTqTGz GVZ47xkk͸UjrY7sf :ۜ_M6NRo7O.âwRmōn6I5hZWmDVQmZC'؂QaٸZ'YzXճ!xV { ;ɖZ>{iù %}uEǴqx#ڜ}QqeݹmR2^65.~nDAm]X=2j IgJ͸nc~Xzį׌4GUT(Zz Pڑ(plE[OXHHem1ZP)lkpͪO`3]AqLM^-tQ] }4W(O(HO2 zrTZtK h;cm+A|.a]Қ?~~XyM$n;k6=E~$`ov{NsN|--aLYd{a&Ӿ#*B̝ԓzU+*qn~rmD> e܍ZD-Y3Q457LTJ\#;- 8lqey;Zfځ14#I鏫,Icx<[P_d7fW΋[ͣq݇.eS_eˎYHoۘ<H"1Gkv^m4W&~AZ?oXFlSfZrPE_9Fv(uϡXiIFqkv.2?TD[NಉP0:9q֌hByR? [`FH ".62"VZq#&Gt8z9FOYR^z~D}3g^ԟ_<r7f$73Yt٩9J>HXȍZaAep1^^.^.+f~yQo/5 )T_&vjũ\;uc '1{4_U#j}lY=ՄYE<X/Rj9t༯siZ W\J$^x4aJ+Y'/p,Ep0ʒ!K NE}uY/u:>[n֟H }?dm8cIAZ-VWb>?#gڿzg(LR">j-3jP CE覔iGbNAV-q9.0vl!B7,B[SFpxjb|N)dv,\h/b/O?9 A=LEI" fntzɂ3S25=r5,ڇ^ZzWpE&D{,,=>Dv(ȠB<}?"v󛾛a3roNp~LDX cY9|ߞ~C lk{$ &܋o4@Ŷ'b2M}SCd`:k\Zݔ|5Tv+3V7slRDL8= _ۗUW*eΔFX\rV)=q_'a^IaZzt=-&'~H[di''~/;gbM]!{rzӧ???۰/:6vQ:V #Q b򏏼*/#nJ5Sl3#/DQBJ3 39X&ְɕBaZ0q//HA-^XHuS3مI8FإcωSDmL:HM.Xݓp2Y,]fa[sq@ g*18~:8Ogǟtq ͥhdйK|(:5tߟ= ~Iɐ]Ѯ-׳V |6h!8S33gg.M\tvbH<--U/G)TVJG"b[Ĝx~fWNN,a.|o\kaE9z73}B\(#Ô $ER`/iwe DzǮF)\*my0nJMòӜWt LYGNQv*YX8p;+hQ$Ҍ2 [K*߁ǨǵzTJ|$|`0j` &G&t͌d~AʓM( Hn_ Γ>i׌7!"w8$>rZj(;RNw ȤyI0"}>,ōEA)MtK{Y):y@QXW_(Pd#0=sĨi|_1HL6kk]reC37kқ͈5 6m&KZw55JS~DNڵ;'uHKPtH찕C3Ge1h]+AfQ;g"sK*rl9U?b!A3ťˣO, :nWpBhnچ)F25|uO*[G|c'6odV:F#8d` 9 7+ =m`O}M]5ly+nXGV0@`]ӝlRFx=HE:/#~  220*r\7\|_! AwbD8A ۽)PjェASO/(lfћgŒU]gJJxvp\Ň oF3T#wUdsU{ _uM$b,:df^,2 Bgc^dT 80dk*a\/gs*19eBR!U Fks\0P\<WºIpZ2"2w-n(潏Lu޿bZwվZs+gglhO Ǭu][ׅK44ς(P&lU}WfԄC}S\ES@ԿjF7K% 9 "8?TQYWS<_wF܌k!zї@N:{ЗxTϵz0sTN!Y(\u\04 Nt)$N~!f $y1iqU^Ej nj= x~nty-ƍއT[$Ju?mp=Ӝ:qOm~`ֳԓR*B"(~}CF"¦ Y&E(X53hhpZKT7UYX?€uE]L]4dMNapB> ;[PMSOn&lX ^ DC~Ў(;i@$b R&}M"j;3SBL '>7"̀"H^)q#{8bE^ΘFULڀOP֊E/eS\{0UD`ƚ>+tn|6Q_hW$de W# =.%,K繿 R GnOPN-/+ҕhDa0jRJ"p;(R0x,1av?K(3+?LpҪNǮ٘{ C?a@^svR^7Mne=p|uX;"Ƀ,}zAA826upL *Um0y6v iFڂ ( h&x# +EqOXF l${c` D|TQex[)C><m3a1h N3!?&twdڄ;)ᜑ82*QMIO}z0cI۶jkܠnX3TDEFtFúX[uT\Lwz+VJ1> x(nܹ(@oXR_~NOMy7kfbKM.Jignn֎V\G8Hp}c;aˋӃs|Xj(9',w1 \,6Zqvy=r,w61jVi]>aHӍxފYazw'Ӷ3 -Dm 5=j3;Y1{߱m=Ln7n TۜT ' -' tAȡI2W9^o-(.:2BɂۭR4IE3> BGAl3瀵z`;<)Ko/UZY&J-n)[gvK.Ж$lcA24!o<T;צ>E=>}'];[,X=Ahh$-{&+Xs!u,´|dvJrtBӪ3nu̵~FVbڂg1 `7>fS\-fYViᙍamW`C3}fH]aq9fq><.纮 PPF#2:x3nڏ!At4 p 06n<[.|M2JHn2dPr&M: kO=a 6'-l ` D4-~g ߋ b`9!̍ B,SU'̉}mz)XȠYw[r*ֻJ~#(ZL[[!K26s^'kx%*6Qm=̼AAcٺ,̟OʼPi y%mʹ`T d\xqj #mzJkzq$1>Q+0f+^,Ody?V%ezGəg߉vWղLz{dEԼVN[c+py|1q]t7d9Eq]$aS^ϸpc‘֘ev\Oϐ[Ku;MCy( ~#ٻɪӛlb>t+{8cÕp_S-=dO0En}qwXkG̵aN9pmP#se1T;TPX9rE ds?x~tĺ WǒyLG -<t8r 6I%ٻX|^T*BMv5rܼ3]U=ʱEeb^Pw4}He.d/Dwv c,S)Qp-7v2 q-~X/j-bUDFyӛETcbeNqOe`mxOj.. msnIm>b!|J( Ful "iB /e@ݎhΦ)Q}V͛zmjCg< jCx19wM-麴{X{+V+xE#$+ߕxGFF_<3z>µZ߅| &)l^rJ¶E%ڝzĶx$ ڽ.dž ~j65R9: `sEvCmBF3ً+mG]e3jwvig(U"dmOrK'Z-Ox>ַշ84ɰ(lsh1~4Srh 7ZkjK-KpW=wLCݬfKCCJ(H 5P8qA.nr{x~3٪g;qEKC:3֠ixG65:_CU/|+O!J ǭۍ3j_J\r7V53L55u^fs7EΞm3i]%i wZ;Iӵz#}ʧ ܅Y!.#( 8ծ+dUPQb$y{~ad$m?ؕaBx8.P|z/|@\UZL~ 1Er:jeY7m)MMUsۯQѺzX)Q{~zQ;7 5)9 7F\ |;l}hc^I nWf:Im5_f#t7u\XJa|8n28ogJ8Bm a7lV׏AS:]8gNgkk0.'@&aT)ܙhX/.$3VB́3jxw11N1V45߄b):FLHd"xI2OzϴJKG^\Z'-1dԫDD&zθ $mh3|͞> If8S5^1ܚ!No ׭ ^.\ѝum95imY7c&#[YVo6P;as%Q*R.ȁc^s-l0[:\bM/|Gy a8VW"q5ndROFΫ{ EuA-߂0&:/CcM7?`JNDrms wSU'5Q_G$w:r=V XgU' IgOqxiI"rbzhP\OfG<7n/uU9G#:QHRw(s2ZTyB4=rtQ*KjtMPOwY1$HufnT#Dȱ ԅFXu꺉Z|vnFLX9 bٞmԑ>9MWq*^[hkcs&`u >iJkD ?D/GbO*8П?:yt!8< 1~@x*e`QEPQ+fsF"APmT%`׺Q,)ԱƸM[:uXAZjNNcfϏŒ%E#gd*/or$Zc!!E$e\b)s2Rvy87\5qhpPaX1Fq'&Phu>N1lP'4Өm9mn ־1`f`/Q>1 @@ 6~DqZVh-[|׃t.t{<H\-$ Εg);IdDc- $XN: MC?'Ԉ %QCZ=H'88 ;W@ 'Qu]`C9ڳpxMPs#B47/_go}I{O1;*H&pkŪ˲),He9swRV OBB>!D.Jp"/iӟ+垁?bXf&P)l xEll,+%xrRg2:_Mrf#7zXwe88R~\2&|!v4# D6K bQͪx e jl/3TT{шc}|f@ =4b]Df1=)Xm#ێ[4Rc$x*ec\y"'.q'J,4WΘ >{(;.U2X`\=.NB\S"!DqGx!31ڔTTˎӄ']97DI̴B\bv M1[c4\k_7[W nٱo` Xڗwta?oNGr:å G,OKo'݀eǤed$|jg棩ċ@.un+j@ W&x#vD0E7Ġ w% WOS!\3MU~8Kf彈t C!oSZG2G:Hֽb(ƶRNKFI>W2&Aj MTCAcoG!?7)U<)+5>pVl ӖY-xmA-Hl2Pm}b𦮇< yԷ$q:E9Mݏȃp0Ω;yd:#[՞/ʐm] [ +X{YĪqq{(D)S`^ܢrꋱ+zRn& 0MMFsH5=Eh"HRIp'pqKQ} !e ,)AJ7omRL>#X|=)¬$#h6b%XUGkIƭ /{7Oq5!?Ju!zx%I@I{׎b7=7w$X\n&&!Z˔r}ݤxbd͘%N1Dh;)/qh +DDI"~)s1 8'TR77$:' D3 "1UT攉::#[Gp/\7kPz&% x0cXr%T;9iWȖׯS}gO+>< }; ,NʂF?/8J5j#IX-i5u(c3B3`hS`(j ~i#Y& uE4l=́@<(/L44=w$Pox|U23"ud-pc .4u rG%q͘ch+/0A3_gE(.%rRL$p#\H^ƴ7BWOt+pF{K|Tw: QQVHnRIqH^ 2V<߃fW4B'>gOh4Ljl !8%=*BrOX$N7X1!khM4jtK]fT:eQ$ a8zRRsdPAvX-檉lp^Hj%pz&cBU/d' ¸eNu,u&¨dUg-oIѻ:g9ڂsho_*zKfkV`  tۜR,ʾ6{Fdk?vkf9h2~(b#glk1k r%>|'Klj##2ѩβW<ua-ikH';ϕuheϪNtRrB޺\6SRh,HoF_Y"?qá';@$nu_:x(ͩӣeU9ph .c %}EeD;qAgZŸni# &hA(Wm%yIoe^neN0Q`9؆ _6<]xrddf /nnrSz3NC5Ln+u3c9X4ɉ88cӅ9 +󶥫h\5DUWs,SV ֌TT)$.SHƜ6Jkc9^U<kx+$;I1pZo-z XV#+3Ćro[S]fiReܙ LQ7x99#K6ҧګנ)3u ]?[VիOlZL;x]Ih92 ?w~BƿtF[JTR.̂BaN4a2W-Asu-Očwf~GMGf>awwC飫V|oq(u_~V郤'[S=nN=HAsHYBc+r7&m{6.bgή^#}%\D[N©oP"fR~ Ը2SyLKI;T1ixg{`d6˭ퟡa&U:lrOiGG! [$#i>_ a0jhd;z< NnzIC+G,qAOVF^t\DWd!LXT,AeC@<6Z͊/ki+.KlAmf':^e\ZL%W}O(8:JSedƩ{!S ھZ &/ 4uK8"Nt -ūű|5:Knr(Om'Eʩ d?>6)_`w,[np2'+/]0!2z.QF/{OHgp M'R2!2c>@"7Skp"Oh+!(0D1JKMg&eS#Y{׮/gz6^ZB=xnCk!p{毁n! y?گ!؂75 wEʁir:L=rbfso8Kv"O|%WCB|nb[ ‚DXP¨lTM+ +| 5|3tűݔ[Nųd{ӂZŦY<ڄQ~l>n=x&܉ X_fʓy߶s #UpC=MnzGQ춪K> 4T^C 唊SH?蹽j1n=d+Sθ Ym]| O8ާI*ZK,';pRGMXkm,XzCސDJ+zqi3Ics嶀;NZ#"MǶvk}4wp 7Cq`:+cym7SKhUuPkQ=4N'yYJIIroէ&ύ'УKVKmD?)$10ibW,NLBV[ )sގ4QH5nX8m\3a)(T!#<7#$MN;'k(Zi(9d@@ٞQE1Q=}ݴ\8avIF!6*Toꛗ%$DI@f?UKrj Eo7( bl9ӡ{zM}KVähC7r*D3+(AePiKkҫ r E<}=r]{6 V<ϗ>Kl:#%1 Ruw׃ϹKmd͜м9΁$=esqI&"KO3 Yw9 `69TC2H]7`Cx =1W(z< +vT2N*#=^:+=ceGĮJ:: 3+wf֋5+%$b6@>NJx ܰA'/#?S<@E;STc5R"ҋeݑb4o {~ MwEFCu{q[3']a;iFTtn!?a\7,Ŗ}]um YnKge*7`~jfv#&K@Ujx#[5yr/ݹ~~ϟ>KӃy~O?>}rEBjYc+cWQ8 x8B{]j(C b Q{bW$9kv5:  ^^f#ϣم~kJJCm@2?c? Gݐpyǻ'4kYQ.cX;#;Nl s?1DI`b9b9+-FPa KiM(8P0:wsP;A[U#u^!e H\dF▒t$iIdBMEzX#&Iݹ ;p|/ԡU0 7 O^:1ّtMBϞw)墽,t7L+9F6m 'SziLq!BǚVqj,'KꚠזS8YkrdpV7/PJW{,*A<YLKJ>x7ϝ:w3W?t?&ƟhCnE ٖgKez[W\\x@N LCN-j۔Zwl%9IA;fK#.o =f\$UZzKϾW),5TqTMR1b_̅D݆uHRZeҐ Bx"xC4r4ظ BDN]%"s[ Z HH.3hJ*F/r >ҎPgX.h.)W(6Wͻp cl{W7sfЌcf`3z j{R\fv| t 4H]2XT\T_axR ]Լvs.7[bK& i("]I0@;G龉Jt[hKvJ}c<ũ$e&NpM}S)oޘ| KXRLe䱉,6˵jFqyT:u^*69=07070100000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000b00000000TRAILER!!!\ܽ 1aj񤧝 nֱ4 YZ