sssd-ad-2.9.2-1.el8 >  H   ;LPe(; U];JeCmȮ'Z4Ngkq}Eՠ۰zݪGU3|ರ inIA`{fc#|\SX5['R3F yfGJ1"(<ɢ+Os q Z>-|{S2g?]{t)0s E\`.Uk>ٙ-'u^2a4_.|rd=2 VӖ'77͙\i"D RpeZwE뫎SuHu,l! $ W\;c;֗^vɀܲA`K/uKUPbvWsċ{c\Š; #gͫB_umB$d //C!Hs~(j߀jY0x\Ya%g8E;fJ 9$,F%BkYciN;2Ik?.۹mny;|502eb4e8f1ed3276c12bb5d72a008233a8d75b6de6c7f303c6844f18535f9303c31bba6ed1ea2409c26fb529b6a74e02689805df0302047c435bb500673065023100ce96220f13f1061b56cdfb9a9e4236790f8ac5ef0cc9a43d9a1d00578268b8461b503db3b0d901dbc5242035d2f5dfc4023032577ad0190f2b29ecaa6bd64c1d03b06c5935213555350cef10a0fa5d7c5a828659101456979c1ffa7da10546d6ce680302047c435bb500673065023100ce96220f13f1061b56cdfb9a9e4236790f8ac5ef0cc9a43d9a1d00578268b8461b503db3b0d901dbc5242035d2f5dfc4023032577ad0190f2b29ecaa6bd64c1d03b06c5935213555350cef10a0fa5d7c5a828659101456979c1ffa7da10546d6ce680302047c435bb500673065023100ce96220f13f1061b56cdfb9a9e4236790f8ac5ef0cc9a43d9a1d00578268b8461b503db3b0d901dbc5242035d2f5dfc4023032577ad0190f2b29ecaa6bd64c1d03b06c5935213555350cef10a0fa5d7c5a828659101456979c1ffa7da10546d6ce680302047c435bb500673065023100ce96220f13f1061b56cdfb9a9e4236790f8ac5ef0cc9a43d9a1d00578268b8461b503db3b0d901dbc5242035d2f5dfc4023032577ad0190f2b29ecaa6bd64c1d03b06c5935213555350cef10a0fa5d7c5a828659101456979c1ffa7da10546d6ce680302047c435bb500673065023079079bbbfc4cacf4aee26e1630e1d5a46baa62d82c2001c53f7e56d1350eee6d1af439d301b4de028a28c2be0c3ce0c3023100b29023a7ba9cd927e715d250476e68147907624ddb15a46167a80653cd2b948a96072914c803b2499df220464ca90bfe0302047c435bb500673065023100ea1eff56b172a0c1c0454def37940422217041ba1d5c3faf2a4201ba38c3747ee32c5b19ba49012f5201d1a65601518d023004b132d7b92376304fdb016e5e05ae1fa5014d4995c517d082cedb959e639793c02763fb936163de584e572734b34f640302047c435bb500673065023100ce96220f13f1061b56cdfb9a9e4236790f8ac5ef0cc9a43d9a1d00578268b8461b503db3b0d901dbc5242035d2f5dfc4023032577ad0190f2b29ecaa6bd64c1d03b06c5935213555350cef10a0fa5d7c5a828659101456979c1ffa7da10546d6ce680302047c435bb500683066023100cac2ea055f5da5809fd28370b1722270ae2498a5209df5b51eacae20d1527dce03cf9c872ba2858319010dc2be29c9da0231009f769864f7bc8ed340df9ea51b7bdfd1568a500278fb1ed27c42a347ea6796d33d1985302e9b9690dd0e36f48f4b53c10302047c435bb500683066023100bd186e102d86529e45684e7b88aabf4bd2e86300ba13111f7b556f35d1134c00cefc0fbd3560a9c2d29f990df48f27a6023100e929878f287bc6dc19415219fd94e30a7d01596b76c0a7e96ff07d5209bbf669e7cc8168f427e8f708fa4781cc9471ae0302047c435bb500673065023100f6f9fe6e0d7ec7205580559e5a53062b25a289f2134f806d95c8275d64c1ed397ba7cddd1c05a85780aca2053abc71890230125c35cbbf7a29b09b842195abb7d4bc1f86981bb64f76c8ecae8a5faeb91d0ae8c1f03c399f7ed42ce0325a11c4fb140302047c435bb500663064023016b43e7a7afc3582356930ed267be5b4d5b8403a5f66790da20e0da025333512ae7d5be04bbfe3fde46bef2757f2b3b102307497a96a4b711dbb98acab3be1ad27f6637e89d0b772670e1c8733a5a6f03599a16312dfc7e19dbb0bf4ba85be14848c0302047c435bb500673065023100b906f1c7e39f53d5649d6d978089202c5f3f89a3886c82e1121984bdc8e911293679c01088449466728c9e2e173da35602306d4691fa464519eb203d49b0cac9e5085dc7c6e25681fc0db8ecf380e6654b8683024ee14ff94acf9a964244f7e32aa6Ȑe(; U]qȡuc-X4#-h]K?8FjVopGvN5l'P_|+)6X`&jl1yNtv fU J@pS\ǂ^9T06 0(%)^*ZI˜ K qbQY\؊O,>3VahU4$H4ފo`yOc 9ˆm'Tr<]y, ׉K(B=ei6@)&C=re_d8u+oɍWf2c?\h|m>o3tRK8$?rȦZMۺ̓HP /ss?jXVD>0 큛h3ޕ_"Fטլf -Ì诮bOw(-LE꯮ Ym~#]#Oh-J2z;t \YholNSe/(l\8VDųv_Ō=;H62 Tѯ2\J>`E?d   2 ,IOX            @ |  4B<B B   ( 8 9:g:G H, I\ XpY|\ ] ^~ b}deflt u v@w x yJDHY\dwCsssd-ad2.9.21.el8The AD back end of the SSSDProvides the Active Directory back end that the SSSD can utilize to fetch identity data from and authenticate against an Active Directory server.dppc64le-01.stream.rdu2.redhat.comCentOSCentOSGPLv3+builder@centos.orgApplications/Systemhttps://github.com/SSSD/sssdlinuxppc64le&'DXK9ND>(QxAAA큤ddddddddddddce435ce8069b92a4d5820562f020538a05d78385cd3c50ee000bd09df1e4c720fae5a75fb458e458e22dd436fa82d6b3be09b52ecd80953a1fa47f0bbb86c9c38ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903ecdf311b22ff296dafe613a584bd02079e00e71f4fd1c6dcde473038e064189b9349e89747056ebf88039f482f915af62b1f8136f1713e51d4f309729f6c2e110a4210108db2f542b8deb9c15d138d58be7fe29db74dd8ab1a66e9095d2010be9a59a330c14b4615c1113cfa17bf702f39f238c5ea6bb36dd4374eea94ed9ff9../../../../usr/libexec/sssd/gpo_child../../../../usr/lib64/sssd/libsss_ad.sorootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.2-1.el8.src.rpmlibsss_ad.so()(64bit)sssd-adsssd-ad(ppc-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @ libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libini_config.so.5()(64bit)libini_config.so.5(INI_CONFIG_1.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.3()(64bit)libndr.so.3(NDR_0.0.1)(64bit)libndr.so.3(NDR_0.0.6)(64bit)libndr.so.3(NDR_1.0.0)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libsasl2.so.3()(64bit)libselinux.so.1()(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsss_cert.so()(64bit)libsss_certmaplibsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)samba-client-libssssd-commonsssd-common-pacsssd-krb5-common2.9.2-1.el82.9.2-1.el83.0.4-14.6.0-14.0-15.2-14.18.6-1.el82.9.2-1.el82.9.2-1.el82.9.2-1.el8sssd1.10.0-8.beta24.14.3d@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) rusvuk2.9.2-1.el82.9.2-1.el8 .build-id0dec4b918833b1c4754acf0b27b8b0fb5dae9d2d7bd0c3e5c36862ea85907a2adce62db4725323libsss_ad.sogpo_childsssd-adCOPYINGsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gz/usr/lib//usr/lib/.build-id//usr/lib/.build-id/0d//usr/lib/.build-id/f2//usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ad//usr/share/man/man5//usr/share/man/ru/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mcpu=power8 -mtune=power8 -funwind-tables -fstack-clash-protectioncpioxz2ppc64le-redhat-linux-gnudirectoryELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=f27bd0c3e5c36862ea85907a2adce62db4725323, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, for GNU/Linux 3.10.0, BuildID[sha1]=0dec4b918833b1c4754acf0b27b8b0fb5dae9d2d, strippedASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)55PRRR7R RRRRR RR4R.R"RRRRR!R0RRR(R/R RR RR1R RRRR#R5R8RR RRRR&R*RR)R6R3RR+R2R-RR( 2HBNz:hָJ+~CQKP>n3uL$`gh>J(?dRB3cnWM$~2uzφW g{zт t{L=^ַ XNykx^)L=}fQS13(+x㢶g7~'w:0yo6-Ӎ9.P&?N"rlſs.n)({Bflr~c([cȷऔ5EqXT_"7֓%KE+nߊ[vbyxp)?QE$kAMC dCbNJ'j_%G$)Q!"K#@q<}jv+@Wo2/Np!qිX>MJ|U],bÜ;iѷR]>ݿ=qsr#B w7{mD4\Ny4XVIs0u Z>G^E_?Fx(򌷚`1ՕbJ)^*_ZUbx(%5>[S" 75rXE2 diaRC߶a O.`%B2ĥ1QrnseY?ؚ!grz.B&^/~OZP %v l {4#;otO5tt}ػ)†|z`N\GJl{X.܂zwUk![ qփ b4F\u[G  td6IjYߔ /ցx&0kP@±G^2gy#8'%bd6jlo5nW::gmFNW⒗+0?e*UOT / ?¥riu{ASs-LI6 'RI )CE֙B:Xϙ-@v{sV{ UX*t kB,av'52:-H( Z8rB"|mn m%\M{ĥ,| "Y9)e Z"CU퓋ܶ۠k IR0:;n'QXpjTjZ/;o$K@_=c[i$5:>TڃH)Mmn:0@qͲyZ![uC]UMqp)'j@!c/ݖ"Aa^6ͱU 06Z^[vP|k-xFW^^^c )9|$hI[zUdB@kg]K˽3*~n'~Löp_kHE=y65Hҗ{~B}lYF NFըG_fU:f;@[I+$;S? |>%a3Tkv7'h$DeW}7 )-_ 2F;^*I xeC  Qj'( [źoG'F盖h35rÞڙM((tC;jB}.6b}.>0?VGJDN=8Hz Lyy÷n|Z'y\%a)4sjtRTŪA%82[@'nAgGxuӰℴ^QaC2ӵº2'^UVz<1"\ wPBHfb hnq݃tkW4bnX:i>:&N:УǸK|E3G'q?O\!u K~ -dzJqJ&[*B _Ohn`vG<`<Ӡ βiTՙ%)=\/lHB b8rͰi:K#%FѪJ5~"ڶV7=9{x{-:G+zm{^>LX|+̲}+n l9ɬe14Dj/WpQzr 3oiDؾN#~\Bl>)<٭@h> §/G}:rvC`}]ǧyvꪸ=Y<~Spg8*ENMQWISe?"we]ERkb:TIn%? `t昞&V=9_VQwG'fciv:"wЂP`ɏ摄ziOL-ك-VߪYoyT63}}쳊ZLQMt01v¸Uie1"gdsV!a}i"15&"h9qn#  JmF+H&[YV܈;OWk \{&q8~Z+)ӄ7XPY< Si/Wr{ yI8Dꡦ5aP6IG%V67c\Wyށ\7vhuLz6Y <6 kit415E}Ln7r-T#7p`W4\"dFkmQ "Mz6ցIr;~Yy6xgL('aeAΟDtso ΓKSc^vK_jC"\\q:T $>)9&6Xkr犢HJ8)Ֆ_>p.u6e cel"mX ))C93[ Z )~ O8%ʠ䤈&$oxacB0eA27x%rjٴN˄'bۊ;5m I NNp\thV:#;Z{+3㽊Dզt΅~\mp8ع(#Ad' JNwXJοI U1e _|SھAqA);w##S%3|!+myqщ*ucM跬xv.v9YrCɨh{}VMrlU',R`?O[_ J,1M6CPs G/i b]hT>5J649%Z`mwե w7@~0nF$tZm 5EItj94<'7jnbRB?jϻ=Knj#؋dJ\np>+n*L pz拐l'_'*%bi՜O{,׺k1.GD1w#A"jp}^# ;ǓɅaqt%v3j1 B ֽa~;ʹ4zZB:r5kNį8I`5[%G֌F{ (η29{=O"&pzR9!yHy3Qf #ݠ4Mj ΧR3"2,dK~T2< j6A3P8hƶI<\6sKLQwM7!%GSNR >]SFuDdx䵸w$FYQ5׷$wW# 2|/rEY.={i^+nsxR$Vz_f`q?]AMn4LHO?=:uF5ݧTJ3J9w VJi|gd@Pڕx7ک DVHo[ #Dyd6L' ?z*ēwQ%ڐ EELJM:rʙӕWkr$6%Mh[6WK\G yYcҝ,89F"CPʉ9?V{8SDͩPxuy'%^i6}RLJH~΁5Z-l1lӶˎ /G6q&٩ָSX9+ C?S8ڟ`<턁>-OYWAv"A$iaWj~:SKu=\у_bF3joH:3c$.!-ǪWgq kXhpK:S+][PcZ"&2$G2eSy4/|a?N!ӣMؙd~オC &m!>v  }z/q.g=TʃW3 2M2[c+i*WQq<3"KzTU tD ΓX%|jew>ξUhx. {He]TIΗ'ldN @3SؒiHwCu3;ϩ[|}:m)X ׏sJ!1ɚ~7WYIczx-.#@wi- ] <@aghNӐx(>PTߠjۍ_[H]ԐtUO9yE^'.\g0h=Z86oy*8t>rq='uUx\7 CR kE7Qd#1DBWfa+~SWPϋ .}C&n.d 3oFZ-W>h پ< vbْj kU;&A|+>TSt-{#f(*hWd a)o{濰J^sZLrR`,G&;sĝǚ%aL'&zǬW ];VU"h A+Չy#簇p$6bϼCԾ%v|F+pI]vG ƢJnTבy36dq}ӧi&}rvD܂ܛuHs5 w3=/UW~n}wp߱qAv XJ OMpbN#ujsI jhH8SO0Es\3khH? >f|P bfes?+g1HX73ƒ$M^r3rPG Pj7Zt,-I,PAyS4 o}!>L!8SDk(Q:JZJ|{!ho`fV$HԚUiev I(ZJ^$;HEl[N>ޢtPVuF_#>5G|pՋh0sI3 N޽]l24s/V@o  |LOC*S`9V%6mVRԢII, 懃a-me/x/9_~"{H^zo%~(]w@UZK-U"\afZb̓-1$=i0&Lgq-/pfe (gt֪ǪnOF0cYlD!g>Mlwګqrnbޛciܚw{э`:h>2aZ] ;hi.Hۮj[Q_&4ۤ'\9]7DBTva]h 3ÃSfو ğbw9Amx>K1enЭ~3r^L2ǯ: N-l/PںYp2v_"cO$O3/쨃i@AzþZ)=# "@ $ऩ`t>[&z8![=u|aR&\zV_,.MJ9]HX×|[4)1Y 2kHbH\w"s;ԯWdѭI!,: H 2F2k1Z4t)7}8G.|gj#-Z̈́4n?C+/~GVbQҥZpM'uĉ%(T4526RyA;9D kLV)r9tbߘ@;۠l nEn~3 qT22U%\e@ BФ%bȻ'BΣKK2uSi ӮKp*XpV6E8dO~w`dw{r$DiEq@#S{pC?a=[I l?ev[-[}h7Z>({s͓8G4g`i3"/w(djB%S*NlKk5NI6Sl]$ yPdϋ !D]Ґ>xWi;Tjn)Q/R @Ra!=xOM_ z# D+W 32h-@%#;@?o4з3u`H0 W;"ʣC ;6P7RnS~W!JWGͳ>{=ܛkPΪyM41S^xO/tJ6q<;fJfwY BUrqˎ'kADLYԽO]V8G_3%8ZR9vci@Gi|rvȳs~vP^4VL[OKۊHֳ'`PZ<3OAXau'mh4Mff4,+, `;; ;Pp^$=ͤn$jQI7 y%y7M1GYQ?*NscOBҵ H34 ll m̀Z䁭w4^ʚnj2˽5@"b7ˏ`SNIA!~-Ua_~vDu </_0wHf{Q*yk=;䯑S71ځr[˲t=$C(EPj6 \CNQm=Mѕt[;4ŷ[mߺwM]4ϲ^gm}'3 ##vWeՇp,"hW9ssYDϣiqS[ORsL+«~5/ǎ/7܄4}OTBRxxB:9<֓p Y7~Yz j,#q4CwtG'N}cشhjd˶6/'M#* BT{J S;=T9JfUl"rz'a=s,X4*W'݃5]q1:[lӞ_;=v(2pv ]N!CWv, kEBQx!8V%T4kpjvou"#bR=BblwEzupwcEQ Ou{ 3od+d%cy-ح@},q;;N/Np-<dJzKꡋ@cTWB#c95o9Yj GȝH:֘^Pc)H8DrDfpvmq ӓG F@:O6sf(6Η,뜝,y#DD$WJz e 3RL=vufHV" `Nδ $7R_29hAp yN[ 5S+;/A^%3hɴ&)vЕ˚_ɸ6wJ+8/aŊEK=,n*H[Ҥ$:ٌA Ik"QwyB(0"=IQZbUy1`mےϹ4tד{oŬ6B^!KUH")(#i0fR(gZh,9J2ܠU5 %YbSϼSCsK\-J7RG 6H$ƲkN|Ӻ܈^jH@?<7 #FNAԢL#x7͋?!!H y8Y{uJ>%y?`߸ 8V= !&>0H@"*/gdz"\CKI=!}F߳=~SMyjzb.ZXIm85֩69ؔYF{A]f ؠZQ ,n, RL^ur'y?ə ^&N؀tN\3Zgh)_.ˠeƼ9V-y9ՏpiTQپqL<ql*ᢃY9zcz/$ [}|m &ysmo;Vփ ӏw'νrG]Þ }c:Tjo4d6&ZX('LUGf,$ t,Zz)W lH@|5Z~ }{i%53كJjܜ¾dX+/DqYy5?}ђL楮L&8DS<Nό4}k]?zPTnBr;WZ_O yuѾu姆y %Am=E~ 8h6aj1VN)D;_ f] u=}G)Y*ʰ}XRB)cF:7Qg3Lf2Ttww_FwY1~UoA\p?D$㵢N ?jhf:3{wٜxg7[5=pIS2\G8ÿo T;a=&aQ7]pk̇,*?>+-\&4} >YlڝeǾܡgqY#)Ny+wIw58O>:HU*{ەU#vNVFon~J[n<ݭFˏ s0]BXirݫV SI%,w/.ɃOZZdfnӨn"xnĪcNH>pF{;0cvL D( X]}ߒʀ rs}΢F(\*_qE2er@jv<#&@v~r fh^hi$iNrD7^uO2|dEv 60\=5t_"07$@L'[)\0]cpoaVg2 |uC;a=%ʆU6|ה}P[j=ykR?B>?MP!P '>Էx4( sZܼ6ĺͿQE?~r`817\1)gIC&&-@No =Qu''TeWcM%Z|9'rYTVy[ lP*HxI/K G?ǩ"NSל]By׽kt&ֿHga>H.Z"0$svuЗi)H!4w}`>fqi-dp ˌEP7 y"%A[;^j> oi-enɺ: eEDl[CS!LVr:smTs>{etހ.:')KVuҽa6T#3Eq$%ʘrE^&O@2//+ CNi躜PVءG\>9.hng@ɟ.lb?tLHgGؿ3¼Igvmʑ'8Nӥ-xNOWOQfk_5p"NDI! @J_{&n]߅ۡsBQ5?A5)4DaV>0b|uk4T&G9bpK9lA ڳ D =nȮAQZfX#_m[Q~U\&lT g VTtrY_ g& |`5.H7u{U[㥲785(ʗ\961""P}ݒm &ټkVX*@'&߈e{ `1 0?H5jяwrV. ^)[ wąH)&>!gÍ6N,V ^|#gǬ7b5Fz$BOTJ: 4o@:>GV nI %E9LKߕmO|rφdҩrWUn=^- }\%9˜cBZۈl{`{aPk"6Xnlj,H +ROEO3jܬF+:'f=.[la8idv7lZaDP@d%-Y&Y5i:QJ큁yJy T%oV,pW f'Oj13@yb:3Z|,uF1Vﱔ-=hXuoFik$XKPWNL?劇)-Z0t@ɻ2}5`pݤ%r gX@lt7~BdN3 x۩MLZ;#]y]$ =kXxJTP E!|c`Gh[7CH%1:v$gI;[^~q}Mnဉ8{2w*k< hcvW%&E#.4,P9v~X(ƵYIXo:?,ݬnr3y^~Zļ\k G(?ku }5cG AETӢrW3Хw2ppKz 5/U $2|╻@~w6ISF.3C7t_Ee|6ڙ0$_溵< y9+יpwoC ӷKLa0hw$Rņ{+̄/ g+Q&*bU\ڂ"e'$1[ T35'ߟ6ci7eJ(!m椤 nѫT~-  GGEzG__k U-cT[!uMu)MulsXE4+ՔRȲٓPs>y-MOvEd@~o(%12$hTekzACS|$;&ZX0ZZ4Xs)RG}WEֵ &"19AWXdqsV$h\R}NPN5>-^ݛr.C>E1Fn$Bx(^{i8I>y} %~3_1ЯJoc]]%kj;xq]u8CSWc@Z1ϋ&fm'-W4[?|p94.;yq spY3WכM:JKDH)Ez]a[6ɬbPٟ3z5Dr؄RJ-e]مHhQȕ>sXZ.듭_#Zb[?7}t4(XJʏ~a;yfFs D$HR°зH]9M3A=ۑ{\?ҒVqH5-NTlcFN(tM)f&0<5xavt: .P`99F%eV%Гw 3]ҀAWi3Ła%>׌U|JNm* TPvaJָ OORB`,eDžb=yWA+1`F2YΓs1Me& eX4xJR{ \䌬XZ,6A hjĊ+hyEEk#HcRTT%H3-Ҟd\ vFinDS4˪λjހFv5 2x0!*1u.eуAN5)MJz<طANWEl[)t].c>(MX뭃^>Qʝol鍟Kn*y١Mǎ7z)b-Dh:'{w,m@w絃B^Rҍf=qab2k0Fad7U9g8M/j`WFL'vTtJ b[Fya)C \!|,zff67˭6hȐk>&S jq܁WyMpP2$khL57 %fOdQϣqKA=p!&f.$sh=ȶW?5+*fDĶÌ]TJ܏1W' Ns{4p'V 2>gNURdU&5 O)^h&=d_g '0l_3)wP.Y75=S?K /o$}Ŀ)\Du yWLRv^(QPV>h Qeꍝg>>UE\Y #gp#`d_UܹAtvA [ks[!F7n:GxU賩@,&.&@PC ^P|ot}ٝIVp4 V)*aBV +"k~zPYqT5:;u2C8q޿3kNkhS }EF=oV:F>GQj{&<H`Wݭ 9xm Tm 2{9BṾ ECsm W',m㡑J &]g7Hw kًah4{G *Jw¨z 9CXX,?ž ycCed^,3os=Kc)Ny=yzMFfQ*SqB$':q>οd5Xc4sU eJh&5ԶP,OgեT57uz-QI@0 &aC^?ö-{zGk8ih >W֮?^VVz#5yJZ|R+7{惰WcF@|fԽXaKI3W~_(`:js$f7 Ԣt2,1Ϧ/Bۣ$~j]pXLJR4:sË e؎] Qf۲ t敏 ҈41CTڎ*4l*n#z(Bu=ܟ<"5܍ 0ֽzRedbyRSP5fs`4y)8p5b(+J waA]ёθ$&@*f%+gOysS}n#֫iOuPqK;\&i`f͍PqMP"F*2þƸhT&)g[v=qEz*sDM@,J|d{,xY|Vs^8a~Odl"ҿSd82PTLp? Xúd:fg@Iy48~@ZҕtwmZ@'`=-~h)96XbsIa[:'[~;Kr?gk\N sKO:G V^g<psqCvA/T28RR6P #tφB=LR~t % "N({q|(yS' WFA# _U¨[ktҏ2}^_M&T[ϊ(MÇFFi?)doAƞos2bU=ò'ڊp(37aֈ˯$z9 f<[35Ӎ ܍R9lr^n)---QU}{@2fu:jC`m:aLYo{%&X>28@m uxN3ΎQo&xc].Qw>[V{' g7t~]<o]\Xs[jZ{JD7 56:zbOS]=p{ʩVUP8{.ӈlcPR>ڌWoI W~d>!*D^E).)h?[/gg`~F+5 QMu>F陠DԚڙ9u7|12>x̴|'Iw /tQ(~u/:@b wfxˠ\SOFaZ{BW$eǝiҥׁF.!:IhYlnՅ\p2B[r L~R _z%P<di*b265$+U[\ӾF. ڮ/9ĦƤzi-y\"F| VRF0|\x*zxw]~2gygUfV. -F ZÑȗZ:ȫN*rMK#var8prDB$?)ЭGf ;LB(txRpRd_'J4+żitwt;"Jer5|!{e_wv7Ӿ\'(< bR@]Gz\p&;)!p: f_lKeVw}B-Nr-eHfh0ؾIܻ+n@ӡ*0EH(CLS%mX%0'X b)8ު@[6eoƐ$ټ*GW7Kgn0&,+$ޒo~9P>kyR"_EI1tosNHiڂ&F|-Mm f-hv^-0s Cp`(0 x5_r&P Y) n̯$d0\hGyܸl{KM亵D1 ^ᴛt0ꚼ)3uR drBpdWGâ Lzmo f&+@jwI/)iv \] P70%q1L|BW=n[f#Gъ60cYtQ7cbRT fkhv;#i8]>OR 5IǠ 7l{\+X\̌JDC3b$ "HMk0#c(%Ϫ3V;.k 6xk!sM{Oa@)t#)m<h_B !Sy^ j~ǥ>?:<֍UGkf|}+7Xa& &MjVRA=]Y ʐĊcp^ʥ "06\Ds29әJMsSjgBB(qߍ>"x8SR3=aonR_jxEC(פr)GKQ4lT-*ԛ0yI 0,!K:/N+-jtbIS'hSL KC *H˓owcղc}첱ޠv栢G~e=rkn"嬇|)}>tx QCu}fj9c#c _V:ƃ/avQXY`r7.k9:jL9leGae g-3D ujJ5xZm݈LsEhvn7!;hNRJߕK$F.GF^ Ӏk!~ A_$g {Q:in# >.\@O{M'.sRpe9N!p/dQ K7vCee.)ftbp(Nb#ɴXm4cZSIBI3z) !J~p{eB<ȤojCp:7hzuq!t٩*4Eawg*$dWJF<\`pnxhi ȵڪy ƑN${ +_Ogw`1\rd7LF7KNGpiE:l_e"AfAh'0PU0} [$6zA5ry~P oc i 53$S=:UXe`C7;kĭ>ve8ƭ6=t)襗K j-e&yS}z{ MuM9] #"xԑ}ၣ6d͟0 !2B MO$m([{`ro= 3V5{J/u!7iUJ|]x ) ,d~VڟN> n{YU^u4ʼK+r^rU\ MCtQTxS!ZoK!cцX0=R+:R0XD!no?TIc*qFѯMɪ<~)h+ Pݷ_ j$;ruU|f zE }Q{i!S_%g >"&uHKYLY0wsL迤Мa찧DyvGg d%`k#sr)n>Zţ,H]B|P>cZ!tR6*F*x\By;`/WA@˜%u~|{(\_Jx;}V}E.D 2qΡ_| ~'CMoƻ.'bYMޠ-)81MudVI ;x׫8?0"isZ ܳԥ4NeָJhTL j+V>te cT\N؊1+>p j1ZH[5"AeU`J%!tp2J5sFnn3ĉIk ,@>ӹf0n03idHo>}p`w:95aeFE%\I|D+hncEWtcIױȪZYۦn'#@~G67ځߪd` KsyS!cEHIh?D)r vdLgjB9l8_ՇzW~ӳmcѱy[aɾw|˫^NA(rct0u^nQ/./I,0Jyf&~+@e%|ZYXP~ [U@t|x^x-6F_{Hgx3ԂSQ$@H5_l[Lo)ƭ.w6*GΌ7`PES Ϭuv|-T2ۺV׆\ĞaR#t&-`y%F*&f])" :jΣ:fockSpՔ]ECdE3vzВ!x, lOEHg@%KmcЧQSġ6&.jQqx'#S0oƕu597*&}~7kTB,Cx 0KT g/{0?.0[jFP7T¦wP8EQFlV$3QUtDlY%m#HFYhi/ܒ_+"<<:uSd]»)Wyip!~ɘDW͞xі2Bu{jW$.AD &^s5]~Ag`P&s^NN$~ŭdaAą&sń?"],5l38Vɾ”Q^^h z_] . <֬WP*d:xr!N^"})--񯆁.]7: b`QIC9Lz<ԌR`@킠A3 3M_TCFNq s)y/lU_xPO/|jXW7PbB]2d y|uI^^P[)b--wc6XdG˂U1O}=qƪ8L&\/{wlYq$vlߛ&So)aX v_i +0lI(/p!F̆$b<- k=9'kkm5q3*`6=ImjZP"RrgE&dE @.HМD,[@S&=-;̯_r.?-mܡhxB3͙0'*YFȋ]0,&uq]p16gV67x8m7 |xT]j)lVk;HZ1rflI$Ld=& Wd Ps5$a>y+M~Hm9s|iD IWOqA&m ZD QѷFRf]MatdeChq,8ZGgɞfr !x*3KXQ6Nƅ.EUM*>W)>d‚3g{b2'ŁBTm9ݴ@qhRV^y4mK d]n~r .C7?_smj/O#¬-.]>ʥ;aVL'897w\62ktxp7؛8Bޞey"7p7zi8-|X>ry:GuuQp'6gS `*Q<,Ϛ琤^-,b_P8Ԗm9 Ivx h }ضGegYүDž?ڨًhJ͙$:\-6G:|IHk,>_ "/Շ`lq!AY|]-`HLT_1O>=O ut@}].O(NC Gl~MHcmj{CkN~GA\)e.pBG+b6u?&|$K,5`$'W?`anm]x;˅9٦{s+=EֺIs9J9]ZtWM_|(EF 4nGQ=yV~N1vSX\]ҕi,ySz8@Á7J05c.–)ixྲྀiFcZj.Mɡ($ +l^4q{&YD@;aEDCLS`GDXkWmLܢ<0BuQ[fz=F]D;]_8ʮV\-1 e!.ܨNG;tk") 7 8pn;²A|*Wv_aa0`V'0:OKWu/6B-$Jq 8cєiuô`y\3xEy!=99Je|墈PC`]%_u3A p3:ke;j`wU-wZ _J~iN!Z =?}vNWõ~˷: Y1AA4AUJuP-E*a]qt鑆 -^zi-d/8~u%1$%^1PUmt@ItV;Md)`0 UͿ^(t<]p5YVpd~zƊ1=!b`UL ԲDC =oq ;]Dd2PЅ$7Qtvi4j)ƺ<%aEʃ < RuY+1DO,=N4K Щb%4tKyvrM*&\"r&Q+˥[=ެ;䕽x׶vuwo|Ν#7bqsnb/3ɷkC3Ű Evc(d2d<^,c9jn(թ?@ֶج4^B~['cvDR'*sʴ5sf\Kd<|78&d2/eV1 xeJ24u0):Ckuc!Jr%M;!L k398CK ͡?T*ph2z7i8%9fWҹmsiUae`>)\y82-FR'k[D\׺SOZ?Žo̖^ 4_6d]?0Fz,f9l霤}շmAXDk?S˕{Ӥ%6o۬ h.D$mG-iNDuU/[nx)8஺OzQ=?VaH2[h k"Pe<ʗrMr?_ͨ]2}jId/ w`՗%#zu,/4mUÕpV1-組)(&/xf <1rr_}HjzaVGjRq9b쾮5{!ʱ凢xL ]10srJjOPT']kXz&lBN~{,:L9U~\CqM:xi$0v0ivđKĆ޵4s 4Xh<]ިC6]{&R++pGGjIN7zCe#|3ֹ ~ҧ#gk8l>kY[ю;H'n3}yQ2 Ubr8dO3e$)X]y[OWHHO_R^.TnQn!_z'If2I{]Գ=_Gz;4]&<4Nd)==u€P kj+ 6b޺j5F{`yWƂ!o[vEpE7hn1ms7i[p Q8XIzP&\zє]½qei惄 UO4 φ> { W\RhZe1$oiL 75!uvRJRQ`P hG H x9Wڤ~2lB|qJ&̘A+ g1U55XOZ2-e7;eXQB0pA(mh\dme RU݈ ZFo֘bVTQ6d?ی,Jp}C1\(Ʊ9Q_y++DMZ,9Z,%?("RKUU+VCZ?66@HGG6dC'p0RnV" ۩ړ1?ヅAYdBHFֲF& 83l^) w X`v;i0r>7HHBfPP3YF%cE.D sum+1^^i\bP(0M>(q[t݉G^cs3}y8(]hpζL8kZ4SqIPBlAP0m(xD /\r퇈P!^ꨕW=X?]3¥< f'l4uƔ\Kw09KJeU@V r-a@up x#)w7 ;8$k3*v'V3qosx'cHQ',kô`(zN| Ð6R" P,?vtۼ0%ǣHJX E^Foi ] ֌Q'9eܰ嶜WۺJw xup`Jɟ@+ive 0B~3IiRNvQ}Y:P/,WKػGjk7CܨQ۳q.㰽Ę*ē|(x̩s ҹ!1(8xkqONkWFX^615hk!C"JNa.(lBRh1qDS4d"0IIK37/OЪ\!qvx3;P^CMLvZ+fR9du}|z 3DN!bÿl Š˜ 3n|Nv nyZϕ?Q=7I.BqNiS='^Gb̟}7xf4;C* MF'r`CVeTt 5o`? VǟC}tfn` :vbдTpr7eyv㽁)&ݦ8Nc L)|a V@0uC1&$Gj/o:3',hsI_e!/E;zY_0|nC8 1U7v[04}k\S&7 w)A丝f."rpǓf˱쓚nd) 'pp"bL Aj{Ry Qۗ=$Ă$X>'%趼gmxlpU șX~L4 9ǫ1+Xo[Qq0c511I}j,( E 1@+X;%U% eӲyseAz D_Ty4|"SPZT$e0/JzI+eNJcnˎQU|}3YwKM,Av>{}~= )_pQƚ d %ƫoSPrsꔼҵFhw>*I$4ae ĺZ9fN+saHTIA(,1$Ռйg!ZWP5+R5թnn.WiwCT藲(Vxݓ-ds\ n1~d%nZ=#A"UKeې$Kk=eGFpٕ[9Ջ, jj`͏}ӛFr^{ğ#5=EHYܭI9<) LT;J!I2^@=l]zI1̊ƣ|Kpzdx:+lJ澎{->tV%!ztSU:u!r U~| /"`!3%01*E-41M<3dY$:lb(9t}$Q]N R!;,_^N0{n6i]^EewC$2Ѵ O#qW=v&ٽeX쩒5tӰ"v`v݊K&˵p>X˻;gmP e$@7)jA=#Hn/G,`H~'kbڱF4==>әO8@l<UC$质E䬃Aqn\jjwΖ{*o$@(` 4dd FZN@&8eg)ܣɻ a04r" 0) %叝1!l3.DrHMJ^d{Iie@Pf;Y!o@46xrMa?$BrCK'|l[^Kؘh~8mt-dp}ωO{+ G mlE#Stn?E(n١Ҝ=C.XͥlXj.&MjIYZeǭ. =:6a(:û@5u$Y=ً\6GDUFn܆3Eqf]HȵŏOiLwԠrz3H 6(?,V&*X ZYLM] T}ɇr4/O[ԡ1džE>\ >V,?浰Eت呲pٮA lG -ˏѢKMbFaޛ[R<>>7JІ³Y${rJ=dI%[ AXD ִ#k 棠7ޢ{>(='Fš3;DIԘL$x0#YEa_T0TnX&gA7]]H5;à&##;_)Jb =ͶUyBK| ʻ7Iu6/dt* oXD(`$PY{=PQ *!M`n@.?h6YԓKY`@jG-P> B5૪ٛfжr_2zKt_sȥ9%`R,=O=3苓kЕYw9vVG4XFih:y%*egm "CyYmAvZ aJgQOyw*=c,dЬ5<6nX %6(2 Q9@6^E8:O3ѤϝNpv0lo9VbR=W,喾 K>#\K9dXbJC& 0'N7i?߃F~#v>1,ڸ.Q7}s#npҷX$-.#l(#uṄݬ^4ת5N{VB'cWl׋@Qc> X=﹦[rPƳ9oD+t糳zn"#򾏭2@Ys^1 )uBnz?%}hob0 QCԗJ>cx Q emXUI|DvO>7{7{Cy-\{r΂ZPGRYV咲A|d /2_ƈM 7O~ܿ`Vsrl6v~Ķ08f,Va3E[d*30E9Eb0%:Vߖ m$ms %6HMk4..3f\Wř1"SW5 [ڸE:K(-i&ӉĠwun0#q49[3dUGr(kiMjT+brX:Mp_H4_r.ADZc24&n_:zh3d )3v:!4t)?NvH]%Dai$g^ Qw 6NL+ &-TS3;pZ=%g~U 'J~4|퓁9%G#5/un{wJ_hR;(eV@n|ې3[ zA\7'qI*IǍS֔wў\ :B4J}L7;1Z65*2&!ϼ"ȵGWޢl*\G/PG 1ڊHAB3)b0W"hav\Q}B9| $DU B% !AgU FgRMnڪP:7`MUvTJ&CA%-.h z-w=(C suGJW8.6APhskЛb+PVg&Y>W:t) &ykmtLK˦[E~oT) \ 4*y<6D0 l$HZ(Trp 4"0Zɨwm_Svie Рd 8AtKXwnliW=T#S%L sȋ(x=2xx|pA4ʼY͕\MG%/9(ʈb”wd}3N:'Γߓ1gi{KpA#[j ,loHnøv q {A1[bɉ.Kc.+BjW!5Q,t9.|S _hҏtsf:A5"ӌFggU`|]PBZK+R/wƞl Rc17˽I'OʂO$$N7y׫,U 3'urIM"̤q͠:qH+}@c:Ћcid]z")P1UjQ> 78.`JAɋv:_rULʁ?쇔h*dچf)e 6~6._yv a$G]/whR`i\ѭ[TV,@Eubۙ`]k *#@J{BG}b!Q\>7oJfunF{p*OyV%Yn C,VĘTY!C1N#Ҵl\}aU(vKջA8u"v5%·t뒊Pv6՝E :x݀ Pa PHWGc[3_xK$1S]3瀧~Ů}cP:YVd%!|10&]w i\= $ oɇY̦&+Vrc~/u7FAf 0\.E,(z[iWE)sEh֊S0$ {(խ{7/)jљ{mjԴr]{ )%CUut>aMë`rݱ5C}[TΓl+Hle[]ے wSTG4v* !/i`Gkz̰!#`,>j'Jpܭ5h>)UO,$;> "S z>n[RPN##8$ $\`H^_##Y@{$r^ѻeM?)[ֻ;fx_RkAHQ-L!s j/ ,-߽sUr+yƨ׉q 22HMQ]^L=U5VX.3u>sBL L{J| }Ox%uxjS[D{Đ{P瀕0l_A'+`@Δnbعx8z頡aIx#(L?t>+l,wЀLp1U 1nS6_v*Mθ =Q~LΪfkcUʕJ~xX\"F^O/n)HG.IkDP:c1{5+\ dWa@&]Yp"HHO [{هn;W\Sr$߲siL+U7Ol^XT xm K_QP-"0lk,e 5v@ghim%El° w|8aMs}=d/{v+xe;'i0/f5CR]. }UNþʫ]U].[yzdhЕ֋lcp>w#ImmعZEE ;1}qg%"#>PԴ}QZ\s5>t XN IVۊMT\67dmݮ%K_1O=V}lBl7֥2G902TCѩ^Ab:SLLxDUcn:~q/F(;Wh4io5c ΜB6PA"bvWjl~u-BClš=& G$*8*M1m a #٘zbDM~fPx*xANRxV , Wz]\:Q2UPjyÓU ,A%%}?)))pU8|p~R7]!,(.2w= i935LӉ .xsd O+MT) \Tq+5m_li:vh QalS^6}Ձ8BPaC/F^Ε5lb'/Eh.](,04Bؔ6 qbi]#[ +̣B3W:.'.˺'(I*yQů9:k"6WǴ%ݧz/%uJLK)yu-Dȋ WQF 1t;#<5ߵ16?g \j e j +=i#Zp.tWkh[JSS@rbȳݬ-d^yj8 юJ\jrS W","鋏 ]ރ'nX(ETCGSUì(L\e˿l=~ch֪օjM-Xݙ"&ΡyFҵR)=]Lu9@|C 2Ve&$ `aEhat\ -OSjd~2}\3lxxnryt1JqVp4*\7L/$1On HV %KYj6H#| Y @'ǂTGmr`nĦ|&4ymt&v8J!F5TV2=[nQj_霐Nˡ*8xg" NO U7R#Bp<*Œ iQ. !f0tHLY:VATڔ| s@ʝ0Q6@/1m @.tLszIk:̊3$r/[eBAΣ ʭχ),( Bik #,]f8wb8nR1Up~oݒʆD:8ZcfOPkfR ^BE{ 3t_xo Oztr(2R|5Ng"jope Y3-X3yw#0]arԌ;w@Ũ5؉.'d\(s*"Ͼ)ra$_oHO&w{*-y'NLC>mK"Y4x 3dS 9S|[qub"XJ - ePD= ;mU5=o$ [;]ԔAVR6<,SPiWhjmnW`*UZ>0iyȟZ1 뷍ۈfQ?Fʈf%]:abjPFܬB@b+B QH6 nAI S9-Br`Jj!Uե-Nsȩb tMs9 w"rqB*/B+!|X< Hm5/L 4Ү0N+b P+B u[ݔ_BRltC<-EP$9Iʍa5M JbJzry,mQR=ԝf1b Kڭ<;#(_ CӯmI;+J>UrVkq76g"j'XY\ɥ:oZ #3.MyqMOLfQW͖!@2|͝t #Lzo921rTs {πI %Q_|^>0 GyWMNR/p|Ú`k*a#uKtD4[Uhtyyi%JSO Q*3~ZO'# `6ul=K@po摉d G+9bl94;ٱ34O}JHz v \+d.O6!S"]wFWd۸(C$Θ!|#l&j]k- 7Z "h8 78̽ Ɲzr,@5CXpϦun?C%fb0sʜ&~YXTqĊ N%Vb֤DQ|kɢaeMGDD_U)GzTFR)T"ͅǥ`>˃'Q3gw@KZhC罠ҰjMRK*}Hdi6q)UE:s;cZC*"'>0*Lf⹖ťZ_/lAIiLθ _dVqvU#. $=\DF©9QYl~!Gx "<`$BL'L̆v;Z3'Dj@7H!`*z~d9֧\ZT#]T1n,+qJvHުqinnљ:Dfc¹Z'XQל*H? )σsw:Y?#ѯ_^eʻYeA J0hxw2;&_M$/l#J.s ET!*a:N*Ei1YDalܡ~ |bu( Rwbj^9ZIBSڪVjTͯue|}S2#9y$/2R gT&iy>Ն2fkr[Ű vKD o@2 AzafeOp !؍r=vSMyςOLINujT&36>BAVyxh؟ 僒)' K"3WzOEѴc?X[O&i{BJ} HBq^H5 IΡ\HT\/CK8~dt Iʼ\mz Q _[|ءCID^$axV'SWR$$Wj&}‹i2̻~I5oDȆ( /kem"ĖU#uu>XpU+.%5LG^TKYͫgQ @^cr]7k9J:`{#) -Dapp9)_nqH5߆N[Qe 0m[ׅ:.t iWVZb<+*_) /?!y;kd[oasY pTnQ1υ!$ֻU=9P ѶPU҆+=`.FZQ(]K\ 7Cr-h\Èn knsMp2F%M @y>lR aGtB4~H0 2[0!%I҄\Us{Bm{(c} 'Da32{}qFv 'aD{Z>Ue3Y"Q0fx} _*ڀzK ZTxшR~yQMF;SWs`ę&K#EsNz*:?Y;!)".z^1Ue9'@;Syz8t܌<hRv%ܪ 똳ô]4Bw"@L:ض,GmWQ-e]ٲ Z`W BY4?u7;|5@DqTc@gA)r3hfZ14гe.$FYb+*^ WӮ(87lT RNb4>v!W@ӂvPEew.7n &\̴-tйɀDIE*9o P0J5_*f1&"3YBګ6'NOd'Լ|(SE̓'w'Ĺa:?Lz6}e>JQL <߷>v.@uK GW)uC>0PzAmEJP 잪VQ)2, lrgO5oMI|ط?ۄ"5 uK % pvG&Ux+8䅷 ||X~G6Lj@XtȮ*pt-%1%n$Lk@1 kѲ^BT_C6耼 tӠҟs Q5r~Hԏj%r rBb]ƢF3dI%s >]gi1Dl9 qK?KR]ۄZW頭qƂ0+ eg큣] ó`зP% |нV<BGZA×԰߉k.y?Pp$W#_b-qxTXC7𸘷j?rʋ/ĥ@cr530@ƵB%`ΈqcS d~E1ʩ T'f]p'@&@vΣ#ԘQRa)Q92K7_N>r~΂gݓ}UU:W;I8 pi)(PGhWxYfD h2qBC4סƽE3$ gK-NT( Iw~Ac=S֊+W .&͹#]xțWg@zw@;mW/7ؗgȏ `Z/LGapXb ZwLd[Yo{OȌ7a=(9O|X: e"@R!@>F 3\%ӒG 帎#:jvt/P{eya1]JDD^ Y魎YxIXGɓFɪR1҆DʞQ4q\(tCWq6 U v\SAMIT}kY%ƍwzEK#; a$/XƌT!]VnL&h'B(cWijNUnܰWDa$/7<"^Hnwus| Ȱ}^vPwC(a|SPc ۲QiK`6a zS fJnj :,(UHw _m_6mii޲m_kt`9FDGo"%nw JkzW.('pQ:_Fp9xXXgʹ?H ~ͭ˗}~GwݎB0?! ^4$g+K&yUxBTU0|U~Zi$dgVOfDZjmFWy} Gx0= ND U^o_z(I't H7sJgnrs{&is+8rbѲ\ CV3{ !N7޿Nb+!I4s jzႷsKVSF sx'N* FDCop*35J܀)uh>|J/`^E/W*_Lı[K3ObcRK8-i댾f:m$sfp/+vF҅B ֑\F nv70k7c9kR! $w~K)0ꅰ硪M*5'R;*J8}0YfjwݪP/J$!IY65;y6^{ W+Oo [Yc wPãhҷ< U b,OT_7?ЭJ!Xek.T{4P_=i y" Oh{)Bc: p#{j̵IDtr@cD:cL$z W `:" tw藠 ^>^#K>Im nHSQB]HQZlsSM"dnjE)f\HgZ]} ؟*HKvIy]&'dL2+ 5<;UD/EHuP ESnA^w,tڄN$.=@7 S<)X}tabT\,q7a(օoa=Z$0%.WI2C޴p_Fr6h=;JPJֲgPO-^]Ie6F٫"giz/ۡ-TԎp`޹%9UU*ZȫW[ȵi.2vMEBD j{|\,wfNs!^>,y+HAfɒA/A]|Ov|a/=JqiKe4ίؤ:ڊT; Oj#/uK;ѷYMw#=y$3x()AHvy#EO8EZO6dh 0ѵ*2r˰t5iqzCCEb@i,)x]̈́OF*I E+|W7)`PH&)XƤUZ2x͉Ij,ﻔ-ʝ*+&'q4(}|VH_7Mu-`ƤX5%y]5RWϿy(~!rvv#Tm iϮ|KO_!>?:? 4Q+&KGm~["mU]%NG\hӵݭX\}7O@ 1HP귛C'vkr G*),-Ac;~t5NśTsG͟]&U{"0VH)oVw qO.B h(Zg`'PkPݝ 'FC]}qk\bԆ}v:7wZA,`|F0- h~椼\>.gmV^ WqMճzYg*b`;=%f*ՇU4qZRnP$Z 5H6 Ju -h7r31<Ѹsxh=G~XVw [B<)EMGs.)W̽)Ӷf}gM q0|,7zD qyƵ:/V&)`]/L[.5J/Qۭaa&mAEbaX JHRfK~!{9niVDzdA|hĪrZ4q2MpP;\p" BưT:?m΋Y4.{FpXh;ɻц@f'i%סkOmViO@z0=ҳեTجe Tj̈d'4W۔ډZ(GYjViv/ \d8UV [zuNo2hJy8D1ѳE 0;YؕtԒ#} +D; s-'KBZ.߆ME%-k z7N9q)8Y./80u=<#*OdlvWpZēV-&-ףt:t(/W"wO)M}ڱE^%g훨7coJ:lHp[e}1Cܲ5HӘJkDtWmϥ;ɤ>6g; y)ސ|b<%1Wx~tpQ?8(YEQ'?Z"v=ƣ0j%{jT$XZIL;$}}#g)=jaQacGj|!l|%vmSԶR(ki94 |{iN;m1֏oՍsomI -fl\Y 綬h*.^]CM`%Vj.g{s 󝈳_JpT/*DOPF?ihjt5yBc'r[gܮKm D5h""7t,BQVg ع #Nڛv`h+S;~@Y8h^S&޺OàKk*d/{楢 !i[GҜ_خ_xպ"7@ \pXS )f7Pipk-ڊ9/:sٱsKa73,k<WoK0 Sf;;o:`% 4z"'k σ0S6_pr;#%wBhDylk&=Cy3K{wh6?Ѫ`Y>= b${/IRbnb ܫ2t椶r rr:52x̦}meԿ8-0&1`:/r)c` X}x,Ahz`6Ā*H@`Xqi Ꞙq^ƃtF1N[~b. ӤqOyׯ7_>[Q&S:_OFdM[Wcϓ_MG}c=+ShCϟBq*A^FxX9զʵ/vБA)}Dp݄qTE#Iըa#U1ą|\ $r23!~$-U쀹6Ҧ$&h+{8S͕^_;m(?^{z-̔y*Y]bҗtft c2іB,Ef,v]F@eonS' W=LxF>7 )8|8e0j*jUesWw dgk6?TuGN}\63%U^0b,g4J*'(tT:7?s,VɝғL&j'1\Owwa^U#r]p[r qC\F B|L Ffnʎ ^~8B QU2gm:t'$[K}b‰"'M[O/r#k'utL_R]XWD-憩2nNS+w&D5DaMGY ~gĚNuz^0( 4URޏ(v"ҟӇhqq$lWMEEtx]/htWwzPd÷dR'i 'X:DnH==S\?t'ԓ'L}@`gȾv- 8gmw<`8'2B,Ra` 7 Iͮ:Gk(3G+a ⁤/Т^tfZǴ~ɩQIIx TE-DՇaoȓ/4}$R Cn3T]5dw`_EQOڭ]=eߏW<ɃkASw lT).U8Bؘ5~}xپ6DS E!2.bH¼ Va#Խ,1@4`TvAdpnl,o]śŒ^S=;xnVdሲq7=[NHӭ+.!/3bUo;KD;c l>2|skƄa숉]N2{-*_݀}QpN>dGo]ڣMlj>[Y,(8CF~g$ n>Π fGKB NbMUx|O:`\vImM%/Mݾxץ ۸H <e+Ֆ^@ܙα4PxKE.%6ާ"p-EU Ҡ[*y'=<%es̔JG״YEOC Bq 'z#xun)R%].~眣m*/5Ȍ/vM;]ټ^gIs7x8FZH5xQlwI}qwl.%kxx)8CMvGzeFYrg`.\QЕa(e `0 >7n3'=3z'y7V9p=C)( EgA۞r3!ﺘD~1(*xpZVڈݰ.cںN³> nlLw`<ҏ*ä(DײGɎo9,[T]p ӱ-= Guʹ N<6XލjSZܹCF5.*1c2/hT"=f# adxԼ:$ڊ܈g/lw 2pLj;- [vBGJVRad+)N2 1[5p{:?YiAԨG}a0ER"+eLFZÑCƻ{Vcsv=k-bmi|޽k]$3oUXByW<.Vuq%gfdD}W<8[} (N>Yd70T|랻`TɺjlfkA3UՆ+PuT~V7&P}\|lҎȞhP"bSJqo̕w *YMi%k6!&L֞vwRM5!uA0GS X&,Qgo ESq"n|Jٺ,U֨Uf\~nU 蚙qDw"6upbU|#"}*V6 3`-lY JE*qpQlLMd RO@ 7cxV/À>Ž=Z-`¸AC?yЫ$O\p֐!@n "j]g[8އ E-p]EmšMJi߇>h Y& ,HNEoI] a7Gk -yA"D3pyl_hD>eM/ȘvM?#H)'KU$OWyB[P){ fz^;BSz҂䮯tCcmz m?(Tn!EC!PYVF zsgq3S% d>F=zCAH l"$i;zZH˱۵\c 򎏸ha"]׈Qʽu}W5MwU`Sa 23*`j\d^'.L8 Y(4R?A"&̞"GAץc3eAȔJ ynzjn&qJLZJ,rlr)=S`Y#%iAI Bw/}8WTF"xqOsb?H*zE f@rlPR^\[/.Hފ I~kFju@Z.Kھi+0*#qY/q&{ς5O\(_{Uų?ع!x}FRSGDLEJJ<\?;$\1*%Hv˾XbUkU_:'m]2$'v>:p71_VeKfc"uHQiNJQ/Xy5# Smwf$ rSJ0x5?ըk+l{x1Kty&Ӟ@cz a)Hm.`Bx*}ZF 17Sg<ܠNh#ƝP3}ʙ2/{_ޑ`0&e4G.^U=s[:3kI;i5˩R`L:d#QQ"ՏFR*-#XUeYDg];-?")8_pCmT;K3.3UHQP>A|.K,03ʌeTҞYł!X¦UTl[_]6)|HQ}w߭Yw=91ȡWpyWMf+V-efNjYC Ȍժ3%HߎnK* [-~W,/0k7%0ȃ*!>Cdjz0s[Ϻ TYy?Tur 5ѮAX|W25G|#W}`PM ε}va|5 L ׉uכ t_*$Mǰ.Nώ0_ﵯxrq!a/S¢*_G{b,҄C8DNRI%7m^=+c_`^aWqh{5T 昷ZqUI s"|۴$ic5Ei\9]o˲;*'x~xup5GfW'{6Z5ǀzSN R5MD(sag!,׷N_U $+jjO?\Fή1 l/?wqf]dnrتĬDh|ڱq ~T}ΕEiy|>d(-+SlkT."s:1dſ\bk+ҵUKj4b5UHK݈?aBJ yyCqd] vRl}9 O؈Q:_ݝ~@u-&$@p1KfZP?Ã`B}*׵ū%h(6QҘco2Dő|Eoΰ;<< 7up!T$TC|#]ׁ+//[:كCk$`c5}y L>F`EdHC1 E/H|/26+cfLE >}%ċ3;I&w2Wka-@0բ3 [!n&y|IKw)wfI504!׶ReWݷg3?孮lMNW޹TRw(bRk~|!y#/P3HO2/k~I)=W+:c$[Ai}ϲώN..:w>M+Lʞ%dU`sQj9`;*81#X?'")< >L5:4Hlt"%SojuE-y~BXZdfO$lȍW65굃4g9O4:(> Gȃh,$ ܃Bfׇ F?ا06mVE\5-T kdvI@!QQ}}ݎ45S~7#"|Խ(A%B@P#_ٶ ueC&8~SZgilwJ,`sO.0m3թ~'eډh.pםdᨡ [Ԙa2h=+!e*d!sx7+2ӕ5뵘.锴u@ȐBc:4I}m&UG\"䎝jEq٫r≐gFAX=b fJa8vq!IU ZY}jت$8I킫st+X ;yi5dթ 'B"ëuӳg*xMƆŪDeG-VqP"80s󄒥¾%>ΛnRzyO$`Y^Z+'#F(H@E'ɬonظc6 ǩdIQ=k3cAVݭRLyLDRA2_q'ȢCTkSJbׂƒdMV ,#GlV䮐+BςȬJ{E`ct&l 3_\9 i'memq+맾/F`@e?pIٷ]_e؆pDO(h+5"[䓖ma8_}(ݿ`ؾ%hMNc(fVjsW1 Mڡܵ%{ڧA A-Xb;%ZEi5;'l^r;UrS,ёg>EnOދ2ۉ+W0}L<\s&K/5r9Ә"c]L@O(,'S>톘ꞑ3@2Ա N-t~G. nQ/04؀JHI2՝|) X.wn!\ZڠB7nI rE[&LeB1b߄, 'ʋC_Z836/[C U/{"_Llc;CmJ)G@zmWi TQA1wi&L§مq^;eQI#2tJ75f_=]v hyԲ&@`5x6d^RGd֯lD \j@*' Q4NJ0#bnV) Y#ջb p ¿m7,<*o"IzC"۪.!& #(<T ӿ nG~8ee ä6Dڋuf9J/uRP`m5<|eҩ a ~^{Mo޼("S@"y,T΄2/KV:­PcZMr4=z{obY,6ƬXٯGMZGub:.l6݉5W2;u@pY#oDK˫vBoj8⅛ϙwˆGZ1=qa.n4_GF.rd1 6K!qD|` 4 B|2VLE_2 НH By]? 琾N7P~lhal(QTC4%Mu7p/_WY)}4#ʳd?07wy_ -~H YN0|"#qsnR{^EiOL-z=p}Lі<_0fyfV<Ψ6bjW2?cihm?u[t;tx>HM+Ϣp! װpv}.?o>F~0ۥκ,"K'ړ\4 vӀj? > ' +/g9HFF1eR6<`SU P;Qw#m"tImn4'˫p$ژē=Q>ͳBpEhQ˵l#=%'c:KrM"]d͌&@+s>aΧNFoY3yBxzdx]Nͳ|G/؛sWi $QѓKP 9V,0/9%% ^ήvbqϔl@"hj r;GOtu؅E=JDޚz괯z;zIl ,2Bo3Kf?J-5.@`{HS 2 ;Kj!{Kϫȟ6^Zۂ $ E2SDW;jG9?ݨnTFdz"89kI &Ek}v-Wk%̊eb^s%gA%NW[ҙܹ !80Gd2֑`hy-·] ;N5#"vͯ3|PvyD5S:8{Y1[j.  `r-FD\Bڕۅj``ijlA%y}BkrD0nM ֢lfGLEjMvo M=mRDŖgW#?(@}Oy|{`s4P;OK8!NhWQH}"=_g,S?FA h~v _X#4NAZupy&G:ar w#+ Oh5sҠ3dCq-ʓGcwiG< _wRqϭ? %l x)HOd5s[Y=ȑNk_]'1{O$SϢKI~*5Ss_?ERӮ_fh;12KoOI# +``ԑ5؅rfAa9%[jE;dLzeՌYUmޚԤQ &".* #8ǩ ;LVb!KyEhM^Nؚ1zoXyhdiG3ܯYYmIm &W4>XK|>a"g%$jɡ 0Oh{LSןYb1ukln5s$}H A21Iu :ݘD'J#7-1#~I >H&_.mXo{όI#saB Rտĺ/x(IMϯ$PNk.i~./Mv*d~}m @4.Ɔ8v  5F+[x;`36q╛,p椰@HYѺqEZ@g4ݒ UZSa^#CH:=_^ &ZknzC dV$IZ\r|2rZ`}Y3.%&L0 OO!q9vͅi ^cS>$ >Ӹٯintά'$+(j_髙c D, L{0-fO) y) !f6/y OQ<,5j7MV%K$՜DvdCJmN8pI~;0&^/vGoU1-AρMr*ΣdGE5:xCM6lJ4s twrl{ cT |}t2 x Pq O$ 5}o>yX3%'PcXh"s/1E-N証|")?,7pj͸Kݎ!xM3MnG-NR^dq^Cĥ8J^Kw¦{QO,*J }NlBbߖM=;Hu/Bov8sU1{n6&{()MY GBpXVs_ͭy(8Br,`5H jAEʾhK}'pјW# uסC\$Ϋ`y}+M#,Z0H{mFs.IP>[ |FLr,EFikl@[]nQ${Yɲ^1[G|.δg|0=N,54䱛L'ۉ]U up9g)= P^f< ވbOa<>FJkfwv7v&v%D,U) UWZ^Y(A9X[`*F? 6XF=Iks>&i*6+D.c/r&lv#~{b1`!/! tV I~Lk1yH\?3;;@e~mqϥ'_؁2#,9g LA#GC.0cBsd:&UrZQԩ~6?[|Ն]pH3m-`|> րH1m,!dtɘe2C<*S͜Km .ecGm/}Uz QSQ++#0"otHuN~[*ԫIÚ"`4Cht"&F< ;!GGq9C^Cr.lFMY;ெEbaHptx+ڔ jO?>^2&N/O-7kV{)kci&v;) He,zBMlBAb#E̸'-`ۑ S,=蔎:?F=ֶ V[`@5vhUt3PESi65OFń#Wvˡ鲱m<t]&QjWoP W59JBjʶ¥,-e5]dؚߺ,͈RRRU*XgrQj2Ҝ9z޷N3LMv9\Lk?>+[;\DP 8WFtT,NRJ^x {T̕ F⿝)'iן(<9a1yEk{Z:8?`P ]Ri}ř`?*K_DqQ^ ]H}.+%ziBqdS!γIU$zV)2/Ѯz><-"EO1' z92;_ zTkcb]Li@慊W6YH,f>J*.":(>}qD?aU`k$Ӷ%mF~žp*mGD[l7:zLZ#ʚҬR'qf/N_HS9Q %j&~>\𣯭K-QJܻ |Oۗѷvc ,T_zz<ġ#֌/rb}'$페P>"\H8n4s#NyDȴΣ92zs6Gmf6)\Z=g1_t]4Llk.ΌT^nY r"?aEgF9h *MboEHBo~Xtb’Z昬9TawF◼XsٜNO`v2AǨwTcJi e-MT9:[4;5 NZ6̡ap[ejT,`_FkN>Ѫo>UߚzJYmg!NLe4a]b}jH?Nu$xg i~PsIKS&:m>,Z5uyR6T'[[ICX3 j?vE >rȦ0𲦉CN.noגGN^XWQD %UwJ:%0 H?ȮIs)DUtd x11 ̕q_l=d6i瀜[L+)$"h v!NI Xsr0;, ۻJ'x/+,ל]sEeos))FڒX8ad#=& γ)yx Baǿ_XflԪoOMDD8i,%7[&׮7}pw): i]ø2[{釄+MRuA23sQ6^gK=`[(ݍ*25. >5EAJ[ԏVo@ބRnekɺgT/A)+먒OBe+RN6RfF+ѭ"*!XHlrF!2HZv̱Ȝnn#fćsm%tI/xE <ځzLN yDh+7קuz^Q'DsOU8v\ۣ9yEKBwCZȩ. ׯ96+J8`n_^a24)h0s.2_lM.K߱cHO u L>2oGd_*ȯ_F0UfJoN' $zF*." D >2׀܋´@oۣf8 XRd<'e{G?b16ӳ*=ʟYTM5 PA.d6zcW0$`?|g[h^BokZ2kVq |4+כ knYISa@ZvC;o/=Kz z -^(ьwhT˓SX>=^eb3ZeT&f_ WR}^_gc=6bj:;KfE"3ʴi􎵋fB!\bJFWj_ $]+ZO- lw98댨j򢁺aμ;FRP5 }2YO,錉W.J̜Zx)[|p^DxFƺ|z l;P@e> !né~sׅo kzQԅSR$]C@53dF;y-EzC ƋNmi./WGII>J~T}Cq>ѽ60"B*:d.GBMJ^2&,:|^M^L)G\0XE#2y4cupiRK%}A6\Ί ӽ Wi$hd {oޝjl3W+ZZzviF+P>E0ɩ"AW$Zgk%o7;"/PWK&.ep{XA U?Ɨg G}W,[4mTRL 5n(})vQh"}l.m rв0"L$-i6.zk\yZ,qTxɦGtfk?CFT&,ADZymtG |bDc6=pfV: K >gBku#GOζ`;М3dU-gok"L'Q L.wIzrFдnP ɴIf1ۇ;Ɓ{k %hO&LH8wϒ "Xghb]Qf@6&$`3 ǣi4~m>%㗐j f?КnWn pq{:~JSntFfRvĬ^gOnw+[ ^V,̈rdUuÌM>vzY唕uEHוzC%hah8D4,,.|QFaq>=(5 ?mYdMĬ«QƷ <;xʠIhj[֔ڎyky(u3%tkS/@zvO2d<~o nQK4yt1lZZ φ&e{t5=p"XT8$&\?9AOoVtҞpVg.-plZTx}Ge=XE G ]X0|{u'ATZ"tT1i򾧰a[NjWt\Ԋɠh]0YOgn!L POlxl 8(3=A.|pqMQm>#n֩-rSeKHʾ,GK=NגσykS~pkq*S9ږ1bVNVWJ5Rzu˨u F.#DxzFMvCUwqieXgI显|mb+8)UBhd4-v$_N4=`槣rl{W6y)7S T!ݎiq6:yW#+S2|S]<" u*N,HH?q5H~;I:| w`nގق(11v6JW #SQ-r݈٤:?0@eCaZ"ؚǓ0 i:eS;_Df*Fz0%%t5 ?KA16nDzޡ|ۼ3GrJ=%΅2Y(^h7vy3BQ$P* ޯ _&2gFCtpz.$ٴXM$i3T\@*PFi0V!\*Az'cN%Cn̩۵/(9$L gC47$$hTRy٢G둌@`?/ _!H€[JBqYKsƯt6G'k< SbP{{ °4%{e$G<=z ŶHm:;ryßέFprjLFK529ʏ+"vDU60m%u4 / ;ԉJ{%}W}!^۾KqmfgvXA-8AT5B!]ѹ#%A|x8^dn> maH{4!eGO2mJe%6T+5ɨ.;q`+36&21PџvN)FBcR~"˥%5r쉬q}w t#Cz++{jTTսm8f;diS.Դdw@5fAb!JCrtȗKOc6VHKX^I]Z N_*hJ pB|V]M*P&KUԭ5杗Dd0g˞pth1H}iH5u` yBg3s-A]BC6w{VLgSκ8].M{}HzIߎu֓jڐFcQߝv?x8 ,k#ZQy'9Ay➂Hcep_A-j7֤!2- .҉-؍'% ;?MWT;_tS?;\x2½a~&")VPW¡'6[xKt^LQ[,UM .{\l4ZN@A|f:(ji珏\ $4)zJ\̨>X2+ZgSKᬭA1;c9yov;#;-6ug\"@Ow\"nuos2V%Hm4s.vJ}Dt t= Ͼ/i40DH}#YBQ1M˳J?-1v<>A!VŪF#I1K)nɐBmM222FT #xRVvqQϖ K|*QS 2{7뒠p,iʾdO' Q=ٿC7-rpLRYLP݂8^#_ƟgD6rE#Nsy&-R; OVIUa^Ϗ.I!" p Zag6e9Q ^.-?lM;&JBͯ%A*# \@dWp)4ķ-٢S53gm=:dXT>0oe"ٶ+7:aw8pGD=UbA]!D \n`v@ ?X]_Q*ؤ>}k; X>DǦ;ΞD jecx^vHe !qOGκH_"Д pK]rR)[nq,4l=]uwџFd X3 ƈeW_:f7ӵ;뵱FI#8R O֑ri'/}*4-c>9hH ?ɁJp}s*3Yڰ5RfŔQa $5MۀUsvd05M,Z>xb *}-ySY>lHm-2P7At7͆Պdꬎշ C3CToO`vsP/d۪bAhꈙсRmwKό׀Afňߌ]x`HJU;(c = $!ѢX'9.[5딂O7I?w~Ǟ5 |Uxʪv \ļ*GKn 0+i߈[}\}D/·;eO.8%mA=kx*u܂ҧr㾧j-q, 0:m\ͫC`}ry:|\ڔt̞?d֘S\M3V @W1Q*i۴ѲKraFz\KR~-=}%AzOLY-khRlBmdV ?^=K bY=p(Dz(Dr{تTPjAL-Wh$ZVz_ Gor1)^9vH$em^̄4n<bߓMǴk89af}-gic:\#Xd)I,KrK"Z\MX'DFhQ$kXҾғ [ړfpU^T~Bm^WH!b/dxwjc6&0dj9|An'~Zz])+KZ68*s0D0֗ c1Z8Y7;Zc$^|˟eplG[LepT tƯm@F5QUYt;m&?#˵pR@Ioݴ4,)@b,0>O2OIS^fK\h6.z m*}?h"@,X2B] um:zCl'Oni8#_1r8=IFςu+,Y;Uq*[%S~u؉s^2kȗh?Ilcim"t p;7(%cT^{֍/PRұ8\rdLN@}EO=Iܰ-RD-ɲ-{8FAEFQMp4I%Oxz6W buhWhGq\Rn t|_Ll!|5ӳr,q-g]JNվX-ܣf/@BL+XR fNMR*+Grw\^ϯr% $!^81XN.'r[ +h4Uk ̈w24<r7!TδUGYv.IxiW6Jt3W'(9L%lw jT_uXz`ޭDm{ط`<@ J!l{ `3C21SAw1PeEϳ`/{ZhX 6Oh$P"/ʜJpo%:hAs2i>DYuq[Y^u[/5Jq6++zYYuV%e1$V# F^g-|@L) E3}72hV>nޚʨA)FaQ} =t1iqVQPݰ&N\enjg2,]z;"X[/~4'ĥܙJcw9y#ro2فruBY555=5kttR(.p@hj]t[M5`fdV2{|a6GX-9Ԛ7OpرجPx76(&^U6=Xa̠4O}F!6Pd*LwlDIwz3qXDVC\V m(- 1956yZޑ4 8N4+G[-E;Bs)^zT2yLl,Z~uTu"ݠ[so`̉'k`{ Ny0 xZr(y6 6ODʑCNSҘGJ{՘ `E~q"**![)AIQBIԊ\jP+|Y_27[ߑpB>  ctF0QQQYnݾZ!>G ~}klQ56pڡHgO!5b7<9nHuhI_Kmweu\W[IB`;~ꕃ9}ȽeRГy ?Q\N8o`7 *z ҄PE|ֽ z]yH74-,)G+2pOeȃGay# fJIa7tnjE-Yv@Th_0EaFM0 ^f| W]xNGkE "I z'Xڼ" q"'* =|s^ǘuIYm#!l8>kefvu{u"Ā)i)-󫧼{VqЍYZ J[ v?Ҳ123wÿ٣&Ӥمa.w1H?~>R-m3co(_SoLhSmF·2q%J^JR~ڰR;ܓӕ(frSgB=i ƕ>UeUL򬉑A2dV&Q ӦDs]"mކWk,qL⠷Zx.>'Pys3xM:xfbE3) TσųQU S0pRvCuk vZYEylc"3ۼ/G4'^JCawzfOTV]ŧ75ĥ񤡝(%g* g*D=2cgZMA<3=)ܥPf%}I;#O,Zf|Zـ#0/wP'*KJG2}P*C4PfdeY|% }k=JƏO+N ?6vG!AK)1HQHY/:LIXd 0ॖdz^J'YϮ3q#d% $^`{?'@Cԯ#rHmqYw#%Sircӂ:,q?3?r֌LNV\7wq3d.7/™D1)fdDp`KQ8 00lnq \"I`ǝXR ڴYoKI0Fo( eg&h2mԶXp-D@d%@KN2D u9;o _;G0hJk0ɷ)G5Pdn5"cP;gw.]5; DZMUWD$$a~7C϶D^':4 1kF63bp;mѺɆ.EuHE_Ԛ ,N Z c j0;;:2~SWQ(NʩF t?kYyWI k@hT*Wf&i6IA(}M\";t86Q:+WU!7V":om4=R%<Vc\c qw)_NjwZ7 $d$Hlij!`~ݜ~qM$kv㽫s\WԢ5ȃ ()#nEkTI+&FϤo'X^Lx[,w:1yGUwcp3ekkýc2oR0Se-FnCz/RV8[#Ŕ2YceyKt%a˧k'@ҵ;V@`QO==~HX+aRT`Р8bȀ{uO)o`r_uуU1͖=@gY5ko/, lp[ 7W" $F{Or'uOn:5 ӡoGI&*h1P֨5MD&5'om 'S4רp5aٓv6=z%(f4[5دJ1GNEVάyam׶71h1ڼ|BUo ;}>"/jtCMBXt] Wv/(w1}5Ko`z?T%8߃$Z'5:ɋZ#I`R I$%jӀn6>&CyA[f!:#ዬGp@l,pe[-i I]lR6AI#aQ&_]rà*GHy̩&BFxE)`w_$i0%PIҐ." [z-/bc.D.$7b(35DuWnQĦ`@c^!B ؓ<>Z}6q$n?'INU^ =9iUQmCswGf,Ι)]z"j4k-ƎF{ljL厵B3hݦ9VL1֩؁xkk{K8]YU [Ffh^LP[ةC/9R tȚ3N`lCtYE~TD,+NOG-҇QNY4b,QͶݵK6콈k'c1˟ ,<ͯ>Zr!A/I`>2BmŵpJWJtEfʕ93MT:U'x\[GąќԎ0X}$y"+iW w+<:es6>!_,!_^)-7gY7㬹3eO̘w:/q/baJ}W^McSơ?4(?ӊҏ`Óoًkvr߻t#2lH`yf0c;`݈1LT}cOj_C){[|ZQ/u{4mUE_9Jٙ45sɬ,D< rNu}_D$(%v2N`.o.n*OޝJ*Էp :a㟮"|?0;WPpbŮZ?<4ļOɎ-TXx8 T+MD.׌<] tЄe/)z &]ʋavfbw@ѷ#vy| ~TD+T+Q4 J+:E/0Wg7=[3GxNO,#]LZh[Rc›Ԁt8M| u*5GTs rAS:<[o5n;8 |g18lsI}+1U,ӧ y H]y^+Ib=,&7bV YZUcm^D_D5t W FhQ51&xoW`yɔXW܊ 1$I{Pt e+ :ƫl^ p+F8ײߝ΀g=qvHiWV Q..=s vۑTi؊4$P3rwɽZ(e"X׹qs\KXFsMkFߪ14Ig>&Y(xjT>=Ord6󻩤HXc}`@~!qݕlω)+;r}9@ep+GCfN'e}rhd[?9;RwsCO_K&KlwTFϹĒwGC'\C V8 fqHTXݥԏ8HGg%Ksn%-ZB~~VyUHt:uӔo)z Qԃp k蘥^S-4QA ڥߩxogt\ #T"K@v1DPrP*&ITK~ÝK*+֡ ^1%~c2.0sϭ_Go6jl3 }gw'HG@qoH fb)@S\C<8^/Z]Ħ/S" zoA)c. &߆NjZf?1u:N!OGf#r?1WtHVvG3Nx̱eDtikŒDa v&`0"O,_^WtZ}7YuD2,q7nmZIp RT:C;:p:GI/֥8d!;:o9[QRI,;o+&"b",=GRWA+j\}5SZo,Ipt'| }`v:mx+ C^*lHYs{51- R*p4H!,;7]X0s,ɔYdcZ4[+[!9BFTgX͟~L,<(0+*PRtشT6X~&S+Wr@:b@s%' \$ 3~obsq7h @K)PlaGƦ<<Ӗ֞4eڵMxZ%8]}zG+Q&=' coZI{wD\gXT zY6Y3y[cޱl)hq+Kԣw#>X[If;ō, XK~g[^X1YXmoju!kyO.iVE̠ri{|֖_2ܬ~;vhZI}KT:_+?VUftmpEp&YP]#xvS@`4𲣋K_S*n*Czhg*{hxTn]jwTT}ϾbàtO|LK#,:J:7Ō(x Ϸ<3bLmU=VFK /61_8_:*%iP+KIns \:,i1nW#lyҐEԥ]d?>v8JΦ=KweRJT(v$6\2w]cxp+S%-bS~S {SNz6l-l;ӥkdN\)~)󼝛jCZSMSS/>MyѮiV&c򎛡c0d 91AM&r{UpXxz cm4YE=]Q4\"ISu^ ="@J&J=,SM#h⟕NhVΤHDO,2H˗A\a:ζ}unuҝ!5g7y lS,Յ!pƦX/knCEj)ꭺFx~srM% iWaꪶu!,'DP& k:]k;/C7C_Y57baW:nQȘ%oTLivrgʾW_yM  N?Mn4_"\u /I^vӿz$YKpT?:'-29V~<m  ,vvD58;<{<|6$urrPL"u*Z+a­Ra#țБ;,8m&-_"&x{`8_F+^4:z{}S&yC_iKj2w6 +ܓE F8ƪrEТf㩏2NR>|79.BPʬ`8! S^VNܜS\jPH;[œT DK3xNk;b[,2 7!D4+io4Oq-IY bWP1ih6,C3@vtg2|jqT"Vec,נ-3N Җ3Dr,.Xu2X9:*O(}EJP.-7jM_Lx.lCB-K'%ij \  f5Zh?ig\jjaJx= Z a~)hsj\/ZfV4=5n#!7c(33Yhs9`}4n)ADX%gŽ8~]ĔpkXrTG+HVDxg 4Jcf7T$)zm̫[vN]1cU06)\Ӆ]oػ ̺5 Cfwtc:Z1n&ݩ6 :G'"J;&Mݬ]Er`~ kkn3gHnW4od2aU)̚QhGG+2daCiLtND/Yl m&oZmFD!wTE>_(CTQ,tIx{vEs LX0<BMj}> -u'8l^&Ъקs I}X&ܙjقfn +)2_DZp2Fmҿ,fLwV2a{Row͒xO< A~{ jQ<ˢ2W88SvG-9h|#=c:ܱ#(-0ktI\SY}^z/L)bM~`)jR1Z@(U$>彾WS^O{Z' W/ Gh,vd&bừS#/!])sBk!j^ 6r"Ϣ ܭ5G\ISM%dD ר-EK!PZ#쑲:is#_ ^3 `QY,y v92.on۷I}Td".Wo(o2=S֩0qvpbY࿘t wrlyO +4yF䞪J|tM!eR6@˘wq )z1+ d ɏ\`V+(OIVІ3q%:ƔY56>Hf7r"2|ќAL(/&ؤC! vI7 E ?4V:lFѴ>}F2iU {U-^i o8/#ݩTd-!`VqzԔ0k Zle8bk*QuS!!}eI'ԫC5g=1<LbݮUy!r:JA-Txu'eZd i*69gtu9~:ٖEA]JK1}qE7wf,im:8r+$ӫKՔ]$QPa5/;B>yZk/Ut>yr*C F}l^xdJ! q(a%Y)U w'Gp"lyp2E<{iv,2{XS2VPfkR`X<=H wx͖q6qyIfd/rH%źލ|#SŦcnP˴_GL0?ILE[d I? 5;e-[W4(͝'n1U#wC2a^-4F/,i},WeK}Ofpp};Kv+5E 1N.2q"Uj#H]#0j$]y/p:q13e!r웮@x~+e䟀6/pxCD9f׶mӎ/ed1Lɗ /{!P~woG5Z~ &Cl-+~=͡әۅPxNo}N";Uxw?15s]ʊĈq*YMh-ꐓtR/~:qPPEzop/*8 \l#5>m4q\Mrh^)f,>Wvt㢥&'~-LtK<u8;#ۮ\5u˞+Fʓ:Y^6A.x|CTY ہx܂|VSaɜ1ߨeP)bvPڋIO2iGB#sE0hX0zcmN5輻7ahg QK$SBa$jAA4PW'z8*[@)!()Yi mNy%ڃi@<#jFZXv*-?ͲEqU\]Oi)دPi/ɵȜ §#.8M @·p"s@j`@ƄfOea: b4ÈPr֍U)w '-cvT+f*a-qHlT9$mH|Qod3b܎QI aL(![Jl'v0!hu,kM( }*imac1,A6 {^P91`ywMsÀ^ٷZֿ(K7&*$'?_V'c?e *n>s- s%5:;$`Re*Yq&*gAZz_ܧ-f{7<1˳{ލ/8a"4˽, hESk5/5p!,;U;hQD?Ի6%a[5ܝ^мusُؓMp"9"fr%WiXdy[vj4@΅'/Z 1jBAD5%?-9,)B# G_ !$V[t3Gjcz Tqc+h't*;f2,FSOh`Tp`n+UiRV=/P3MUwƒo6kW+Մ_PA2GZ50#&lf<,LSC?  vµmiϤ˧ݽc;?[/ZF:Y ͊35)f+b)DzKV3?rh]bꚥMquB]}\$V)fFUCg4/|\Oei13~9R:w Ywܑ~C * fW I&:[0Z.*!e8Ֆªs]zt#푥G WqyR B9k3B"CCm-p&I.4B'?k V" {99CֹP}o%׬+uiuXհ|xŵZURݻ9[V|AәA ΆW޻Ty2|w^f3V:߹Hwcw篭UnNJ2zN1SS0tG~4ʆ\C=c,%~LMarkp 4($cgMpn| G3] @N[Et+z[Xlk<):3sЎ1vH7٭NTR@8xbq/|/MǨ+]7#vUbvf }J1n Bj\JdIv jD EzpFQ%/Lh? 0UD"18 0nw91-{ i]0(=Uiz;Qȋ&89޺hQJz/Cè$x`n;T+M/ | /^t-D` fžRB-jf%(x18[v-*Rו%wVvoM ɥ tد)VsRr/w&MyV(iY!V/޲  Ӊ$тzxй5:DPCۿS\sy}K*eb}Sq6QdU'=Z']y|tL0*S1yq ej_>ԛըhc:X2=КT(q,fxO5}Ms6w8 iP`{|q[PI꺘e%$~$ӆ ;IcAzeET3B2H#LDjU@ `yC.Dm虫]4YLPBYH6|EEym!9jr=t&+N~bUζGk;kj!nAV`Ws7%3GD|I<{lDvn~eDz&V6w  OMa\G?¨N u%>G@hD)H;8=/)ü*eG"ۣI_/0iƞV9{w!(S|XϽ 뙤2 5ULE8eFb#p}<;*ˌu;&<_m>^byY>*XT oΘ2`_V%RT}bߓDAZnE$"$DkpjR -uYNњ^rR3~ߣf`X2x$@0]H/'$nkq_s' OUxLBzU'í()zTtɈРn[ I[]~?=iEbb@ Ǩ ǙͼvƷ$_x|U%cNVI^ˆi,omX(TЮ2%ݵNQ8}ons\)ΪF~@68R[yY&e"_J 1= ݱ@!4^  kҝK Us=EA5ήz+#A<xwcǥʒUct2pW*;~]f\XC%Ǖ)9.&ɍi3.AY U4S3?Df EBQ.L Qixl6"u l"UCvdž=3R8>6ڑu"_Q$4 R }; T+ isHkWMvڔi;Y.2 RI!AR7nE0 p ѢI.tPVϋ`*sx9܄OU" /@8Hn%hPVYW6-=r_掿͋kn $ǗkI˸%& 2;Ci6: B" {Ժ@(TؽVp@dt 8]0#6G*OM\턇%׍lj (\=#{f]yu;&G6(Z2\8Rں2c;;x1[C{3+[jG~P6.Z s7?L;|꧈Y49};⫋[_px.'T {OBQno4#=ͺ.c#]+!y~nc`:LH:Za.LXW T3JuP^% f]vx#.~S^E9Uze$kܒ\tCQHC&|\LJȆ+gN4kh SJ}SEfM[+{OeRZNΰs>#/ye ,lշ“ R cō ݚt9n:ϣ}p|}G *E:=bY(p'@̐o"ym/31lA'ȃ Fiy7ӌ2c Ƌ"I@އ8w1WQ0] E8+\P2e 0'y,71{&g). tQ^0*p.DE*@6+)JHS}SnX87LdȽ #-\tnF}%qG;8=ax<%X&YZq&DsoIeЈ}׏pk-a-u]ړ]:p_oNIFCbGb'[_Ă!dyӱY䰾6EpY|h;5hyq~-OV&h-b`e땙`z (7PY<=ȒQ6K]2xvlB пeEn\i;,a"oBbC;0$[ {"v$'yNFAg&j}鐟{*آoyڛkY=JEFwi5/Xr i.yتi@YxjJOa[m?ZE?L|r(z& _xVI:ƽ<6bp*:e N)v+ȶzLɦ۹>ʅf 0:hF,_> )i𢜋!&aM-ccZ0j(zkfyɇnd\1V^Q!njmw wy|)UC-%i㪌4z_0Ag_'͕1;ě"W+ H !=mGglY7Z5̨X:rല:Vm@$gobX ! +Ӓ@}{T [`0CCs;nO-Ob4b^=sP^w2bPE.c7ZI} G \*H~VW|%}8Ism+bf^s̍ R4[4z^ǰW u71'iPj>\%E۩>߇ Zw 6rLĸ#tG۱tl ;nޑVE_-ܤXty;}i~T//*I[:0Nƙ @ؓO C""NwgtA oZy5,vЍdDR̈́ ׆ ߯Npr{ AQ0dE}R{fJ<;Kʴ= Hep/Z/Kie8T5.8"mVlr`z`]SwZk÷Awwhe+AKL9UHN^uh;-, Dԩ%ht{>u8e}qZW52oD=.4ǣ>=_uO $5gML2;صKD{CYa +%ikVhr4w`OWJ:]mf8!c! 9=ޢd)> E(l֬kk U\R֐^Oq 5)'X5UDM8 3ȕlTAN#  PIQɺcx%Hv?7A䪢}r|yBb걒vz/1 Pdvļ!c|ދk P;~13t(< t YM HE)YuzrD1 ~#g2`oԇ~ܟ@ (.C>>qR Bb$Za:7|ZJ ~'h[gѺ vP'XLJ mC:5%,uufgD0#&M6Oe#Zrm!mz^Uv' 4'KBam3aff.9+[CyZeI~bb&z+㑷eruuG!hH]$7@mVX/&=3l|Sav3;h'4R$ɽ#Ip:IzUA@ đS^?@sivpyy.nuV`.zx.{]iy :n]l Pחe `JU]#Vc~nM;qYas0K5 Q*W'+1TᑴμBx+S} F7JhD=w" / (J*Hes>Kna DZXKj,9{x~/SSd4Z`x; \7؉7r[\k\`$ι^qPt]^B8o:e=Q`~W*Q!4Cu _r#QԀTB:ݛQ=odz(?VT3 N5(Ȼx-ItRG@} &=Wx)&IA)NhV^(0ZlFB H/v#S0p59TeM[pKJ'A #tCTfm c%KXTD7X(96w/Mׄ@j4R~ t}~cosH,\`h׍qPt+Wv#7RܱյӠrQfWʅ"xEɂkr+ܢĭI]*@<|| =C/Q()\?f&6(+>Ca*y0gImJ+  j#{ 3DvKmOQݓC{Pҕ6'2ÇM 5H`4ERg+Z?B&yxxsÉ?bOW1){\Tet%[W   ٖ~F#956Vdӫ`(!L0O+,l.z\FcF O~J@a&=Hj%iCY\xvܵ1B U7s+ 0<:T[庱TImRHQ +A/xD/s m1zXY!^$ΠYa/BzZɢ@@7K,SMмe: #jԒs_K{Dr%Mqv Y1%NL m4Λno#dASJ}8bT0CuC9Wj$j%SR܂Ԓt Zo18g-&ħ1R,6S q1=|4J^I m@~Xar[d*^SOClotL[:iѽUiq7f?>sݬy8G0< dfa!1E~m|<"l_Ws,SNO<{S=AA)ԗ_ao&3»Y- 5$|ܠiypSf k'VXHO!>'Oh|;2}}{- m`f'Cs;>[j[Z7j߰Ήhn2T@bG= B;|om#dx<|A1gFuVyyD~ep?*QXxWD ` ,["an!x7pwZ EW_@I,ՌSw!Q-<d8c{ŷyxl[r'/BE.{ {>av_V>$+P(¢R}w'f}(M{z CQMg9Hmxne.c;NlYqγkѤq Jஊ)SS|{I%?tB(F"/lz}33Vm=yvu;&ot{&+qWov6g3"} ̓-)Zi}2/l1xΠdø\Jw?2l{hNr \vjM3Q`ngaU/L-zI=e4h;!-3.%8<e#CaUVTƕAiyп6霿{|JMT}4h޴.lpf?L-="R ޑϭ~[pPSo=SϽ=Ȥz]ie݊>aK9G- -IkfW`/{ ]}ȫ:Rj6㸫.Թ[(V;ɋO"eOcߟțT#BGe!_sxn6A3='׃[hUQVv=݃fڟ:4/RPbumÖ}c+|2txūah>0kǙF͋.z`F\PARfwEl.K YRJusLB1tKW`2ٴ`sJ< yZ\KKr'1-뻜[<49 Uo&y!( ilȏ4_ FNk~yJ/}A=޷9"T()Jh.Mi.@38LɚCnK 3f*:;b;'Ji";$ BJ`2$7VǪdž0I[rDOkHב+ T={gOZ1 2?~u<;i/LUw@Pa5,t _Yh64{(,5').*a2GPMݙnoM~̈N\du!a/E`= atԲ]=2noj@LDoN (:]zaYLÂ~L?cNGYҗDR'yŵ YQSpA:#%]Y2\aJ_Sno+yө~D}Wm×KL?EKHlwS8MdQDD7X]A ؔr;ANߠ#YE:1ƣ ^L xtrpH'd.,%NJ$|D[c>x3xm0j]!+%fus9ϫ XsxSUj.Mb~y~P*ԁ|)!'PҫRࡴQ^=Y!fﶾčwJ!uC^*pRBunP0 B^'CJpI\\er`ʦ?Zf]}@!X8 P>nƬ7:s1ѭF7jtO@(ωuX4Opv#2oZ-؀'Aj˿g8yyBB %/^@ \Up)7ٷ|1MHr.T4i)pc\Oq,$X_=f퐺^ 02=|;%sN p3aTrOa J[ĂT_71b5 t|7ڌNe ndH;clZ/"_S쏜@ŏG&6]&10[B]b3W#SNP 9`;}϶ϟ'$&nzM^qjK%Z$Du FeCηr>PFTAvZ50gW*0%֧M/K]-/ؙ,Ⱗ)ЋADvXtb݌p۲i[Iƃ@ ?y*`ݫH2)Pg%6؂~"0b-6M)4X>ur4BS1WbTS?ez:*{S 4.('M0pZrʯW$=NBm0W敪m6U+c3 ZWJ|VblkH-<4$da5'Zȓ%}$bj.vsE- dVX HØ3 dP9,[ݼӓvJ CDQ[>{xs=wf!#s/Eq'=xm 0B=[ p9Zn4g7g]=^ߝ@h5R5`} ah,o N\ys Y !Ό b"9RHZ,$'\߼6#l0 DS@zMFK,ƀmNS1F*T"8'ǖ?)wioE.Wt 3‰)4bM3慲L }Ngi"i]•LN$P %ɗ;cuE~,s1>6({AEb'9&;Pu +=tSFJ3ANgcXƑm]hw[CPcu&Yjj44c!7zqo3&;c е%#{ڈI*Kķ]I~eaL>6Կ80u;uΆĚ\?k$@ ߓw GT5S@qN5slAZ O/(/N*}!& _/lR!;f-ԎRmτ>w=s:|O ,t5ݖ`*;"^MPVBڮj91P[ܛet2TutYc?lKx89#d]:78_2RN쐛,Ftƅ+FJ! ywQnd.H:&%yԀI5iAFݸ-b|Ӹ@T7Kwh@mG- bbPIe95%Kji*'t>ߟQ08yOX`|! a9zGb }o#E,kdt)FS jTQr{<Tsq6" {/]4=3AK,c-FNU&ܤP gŜe$p\RH O/u ,$^AvhE3=%1mcF"׷.A2x5#& wkMKDaKK̖]F@v#9JU?|&#"s"\Z(#J(zG~^ar Q-t`a׀*'%-(XO/:~ }y*hPj4_MP$KbާF(;S-G6f;4wꐧerxYs,hd#9ccv?Pgi' +_95̭SZ, ن@W-v~ov`)FՀEvVGrjE${ˌTT@Ml#Hgsmge + (]a/,T t{קU%`Ƌd}8ΌW$|n< &z[jwc@&V[ 4-swܱD)ĦC@aXvk훒yT }2(QWX<+*hȄ쮁ؘțFQ> iMP42(N1R/:Ln㠿 gC$[B"^ ъˆ0u@M&}^g4`SW)E>Wb{fLxτ9SuKxטyrxڏi/;M=8M˲*L::Yߨ!=T.ۯįfWQ'OKb| Qi$*Mî8*B! py4Z0m>`41^#[ieՉ;sbK\ GWN|zun2п T4d<;nʹ~iݔr>k;|c4 vRRi`VDSJRAuzڶV jV)ߛg5S-uq|@X2ĜExʾ]Y5APxn3iۿR鮑~аh$!*o;dSIڐ=y]"GL}=Q_f6.cXx/Q#xӫ{ r&MQh 1 \}|5,u.x|y DUĢnw\VԸ $9.VT ) aLS3aa9_3̻i҃i|%[G$U2+0!_W_͉T D12U/!s+nL?wρ1GS Ӛ>ƧMz ҃QՃ&qtf<ܒ]ȡY!Jv;m$~cXۗwm(Ya!M&y7ܲM*P f&RCP*hmPmXBzAs\([$ǹ|з٪Uk>Ŀpbz;J0j`t(cZ6KK (Vv/ic|_4f "N.2 {$4hJ,:es}+ 5A?B!OsH7s'U3,7׵T~g0l:`5wqHJEa wjeNpSbi~ͬzuY !J$y2 )8C7h0ŸaЪUt,(OyȟFwFě) ;wN\Y JspIMhĩ YLV$!Zg,Bq!*;58#"J8z}C5W-)|փ :,,Ei)Qa!OE^ \L/Nc}u[>/7s'*9˚wﯦ ː_v>w(>ĀdBmeCj6%w|p($Uw ۤ꠾޺͒ eٔ4[&]"fM?IXBߊQsW'H+?݅삷ЃM<Gј 7~#-/Ts;<Ǵ&ajeMeu[*KE`ڎ E͗P~YE,3 gQOvcmlyns G>]m†B)_}]~}&v0zޢdM8oxvlE`!~ԃV3;ZD}[;!7^UH<rB *М4;9_./g ^kj~|qhʕ;K(E+Ȯ3Ml, k &S<eU ԉ6AfS-r[xE9art;*DGbx[A2-&GџYT*qޚǽ"~c#qK/xAzǩUN&%ƪb]/O~dЭ.voQD ϋ O61T8p(%]F}+>dM޹ {#,< vti(OcS(N9fe9R\'kR';Y{~^kLFD߮#w2vaD*"eik1jje&]Q/Ӯ> :\Dpc%ݤa[[!/K*_D #hǘp!ÄԹZ z f爔QweuR臖4 MeN:@t ]$,]aHo/Fs3( MB:%r xHSw5SˍrHeR28H]ȠS#&zU*ez9tPE*rg k"64Ⴥn%]#5zں4Z- ps1}?B.`Mٷv*1RƾѦ)D#y,xbP'Tdu ]B >.7$Th%Y$T65I`"yy 1#(?__@D>N{E{w2Ɠ+VAnuMRA:F xM6n6Pw U1OPRh{ƞN}e%'l\e읲+`U5V/$~b# &C$̕܈?i jz8|ih)p]y-̑euJ[-(?o]{G1)h?? rm BI0C^7 _(pY\E5[BOo#-6H|FhJc* uBD9j@VҖCm /ʡns\S7&ӧ_!sbV;AsM<_T{6z$+D"P?29.pt`e0۷"of0~x 8GL?qlhh9YBL̞>~S ϡEc vM *3Z)$jzemS-ThhDHsc|<\je-YscdoWf(-/7wm!Bj?IwnQQ~l@yGqv嘡S=\}9|0)=W:=x[OC+Y 4U맷> ?ҎK_ ?G3?8em71tޡPpIR0hH|'im@ȁ4hK͡<G+Oڳc, 7Beg25U?ps+x/E£fط¥Y'r80VNSk!Z+Cy闎L"7Rۜ,|.VaisYݯ>S_8k֨<[ވj+VES=ua(0;WK?`Hܣzq. _J3d$~iӒzr2V5( %.;x2mn&=m6LӚlqc)&4=j5~?p'JGD$$7bNJiJ7p&7cp2ZT0clW` nt ws|PͷJoyWhVzFxv;9䪋?\_QHZQyX:_6b k %+<|l)}'#mz2><X!{h7h W8w3 vq,kWv3nMkGZ[c;CVa>cޑqs FNoꄔneƖn>zvNڊ^8u1 4EV/7߾%uEVd)(׶ĩ_96ңhzjq/ȖU5 ?4OТ{7%  >NʰAa_;`5?K-SLJ*Cf@;+PUvDZ[/N$풀&J7, kxk7mB@k'N~2 ~>G=\Y##y>,"[6t@:2u;4Uup8"5 `|T@F+(tG362%*íi aY2?+&Ki h> GM6]z LIʄS"ĨZ!YaGZ%E6rvWiA{7?οtF.  )$!ްOOSRL*"D GkCB.|Q ș=.jRӝKPѝjqR7rb+UŪlC^)i[ 2mBd6Xn= :%I>$CHn! mFaMcPnO&'y5Ou4R1!`fg.'D|ōS"gߊeQf':mHP#u$`ۭ=U%ߖyO+89Ary.cV­Lևo=PݢޯĿ -~\q$cwZ8Wrm9a Ɩy F<0\ڈ6C uJ{F ]lͶ)zRFƪ]IYL 6+e.B;Lr1۾w( 4vG3ZQ9P&S#o:" b`h(#<e!NnFCja*xi^Qi=[a6f$($D\XpOd6^WN}0o7ܼ!ÈaGɴhjWliaީ5`ηO޾іaG,I ̼fZ.1-NOt]WĚwNMBz|9_g O=D?'#lzM eVEex9vvVު5( |w|7D9ßMN#Ex&-TI_%Y&qa9fQ$&K&;@sG $"|A^;+RjEa3q&Hg"-Rddz-E|{uA}#QP t^L|m|E!]V}JrK{ S-\y(8~e#/#μsӉG \)kC<+gaePhܴX㉪T9/ \zU2y/q7̀dg֣QUN:E(<$h&GL n|ޱHe:a]7y֐ݏ^sM>s;VR.Jމ`'2mqj(UܯbXf#D0/A?c3U IIXv? G'=¡3.k\t?~>Ѡ0)ZnU65gE>IB\~:ꪜ<..L2mPYXSAdrAΠ3/7&^OA_ Fr엢 2?nՌªV~v5)2 䪗/d E *W."*fp/d^ gBBua4[B>[yL/</d+/Uhopp~l hE6i;}i6?,ǭP>XV1ou?1v%&VO%/|XOB^8hӷ)KEFڮ|cƌ#&qyHXúYHƩJbw* p T(kaڈO!*?< yFFy Gg84f [Pni~$ۯ;أ]6'ԂpY-]=E%`d (u*/K]W gLN?=;;ހcAV;S(Y;"U*r1N/o5˭GiFd'ĉԫ'q6B搢:Cn^볧}+ &zw@wF%z" Id 1O.)$1Qny1tg7DeymՔw1z1KdL $c8kpTrRsJeO}d8}\|-y.BiJԪѝTyݱv ă&v:߽@腬el]c:jSB\:L1\~Q\y#FbuHE6 eF0W; N gIg̨y$M 54FKX>tS06t!?6Yg!qK}5 Y਽[`n^ɌQ?) qe≯zup끰 ڍP AwW0SOဦѮ>f3ci CLqBAi؝_ 7/4j$oIz9J"P:Gk]IS"zDin a'6jFjҒsu:+͑=GGl8 Vk,Ө)T`ɉɎZ'yL;w~+9-Ra9RŸ/m|c1v< զ4MVh!7. hC|bV-J㣧rvϋb ?։H >0\I@{i9%NB}z5!~<pV:Ju?1a<0`{U?o@n5E*tn)uGŖ3L$I1'Dk:>c."im\~#6 _%T/SG6e{ܲ`/p݁OXsB* B>5K8 aC^Lܪp4`ō׭!Ĉ>pkc>h"V5UGI Jiw̼, lHm`PZ\.m|ĘdjR#\ _O֘|E ̛k3B ϊ"&@\M ?T2ٜ'V"=L~2c̎y<t n }H_lu@f>h^e2G tUyWo'N:y%nP!x]{Gdf7\J} 0a} | dm+ӝJHzjF~{ipZEDpチz'PX;+ -82ch,EFŕ`-ktk% =ۺ9R!noh݊}n]D"Ƶ{BoDI}ͲS%l5`xt0S1 !y>N3bvIyLKs9Z/{C_*Jg{Y.J#|깼Ļ` 7`B.DiVqF _?״੷~E8)#p,+6da6.E!_ NX}rvaWDĒD7uhSIk$J 9Dc:+ARJ)>̘R׻:/xJ~' ?(@*]2Hv3*ot 3ȀDcu%l3 z_\eZĒA81qqG.w4p3  DvMsym戾٤;M86hF0ZI-I竫?BѓÂЎ'B'Y3p*23ry3yP,qfm4,bLbp6gIKeIzѴҮ7wuz?+!-m=(Яg 2@#撄rs zE਴;Iazoj]f #񕚋 BN",5{{cx@zؿh[r p4n \x}+I2@dPU}.Nox"A>CgdSs7K-\}4vۭFZH-3E.YQA״@siَ9͘ @O_~)NJ]$F|qi2s:BCPSGfa 8jl`:dȆQ-nE䟗HYb D@Gyc203qҮ׋fd|WNc LE:IJ$y%I/9 ^@J AZr}ŔC3nR]tX.ϼYt܆Uĕ!l%u"{ln-[g(b[.Byp b̓[S.ȫ}קVSb$QU?J* (eKVsy*Htj7uἿzb7%>){@z{+]׵kvn|2#:jԖO8vVuN'!tŜKZT űq q>f1OORoIOLoz~Z})K{RH!ۨǘOS7T!2BʝVq>@B'$a5UVKmLjs@7B S-C&bXI=q8:}> nƏx1v@itlB}m[(Jg !xZC_Ʀ}n~ EӅV)/nekB+hO|G1#}@BV03ll"a}/~ӫ`:s)fqJ0]P*mY̾ABrTU@m#4tBo=mڕT%QaWMPx/ ) 8W k&+ȁ ¾!l4EӾm.]גhUDNT|q)#k>2Qq־kG+;>^gUGʝTD?(G++`c^ֈ6żaN~_ k' ID1RvkO@_h6 T7ve?=a8G^siudؗvsN YdӲ_I.JBG3_,YgٲQ*cAHG _\$YPX+D"`Қ&!eO*@  UH+:ӶXl@.>^yj-x~'f%}1= apԙ5}dB 5LOK92XJ B0irl1Rq"`\)h1`N87]Z oh@A}ܾHF8 R7>)W2I2i2@N뽩ҷ} !li9VY}2>< "SS: iCƸ;x4 }(^Y'Vg2Ϛ'rzVM + c zm-5YHnQ03ZᤓTi EUQS*@:l1jy#BtK‘Y;Q-|+#FgIp'!<5SʫzHUG*· 8yCx7]buI }ߢǨ<1/UEio"GB$H\6P/n 8F1(6# "n.{fᴆ_v[ MCkDoyQ.]ˢ%!4צ5Z T`3^$4b,(x ~iEێRt3TP{6Mcf'-^N? Ryhn>q8=f޴{&fdJxwS Ha<ClN!1hR8bS6ȨĚ} @*nl[1|i,VgߨLM2"aCY^JRin"54I 0zUy6zefb`7-FA삇azTi<$ZE6$lw'1iDش'veP 7f: a+ rSKEI򐂀e45/h*|*w5[Q5@ ۿH!6Q1x uզH|֋,ok}ӿ58fUGƧa ĪVjU!Lt?ervvYCfξ^ ַ:"}4$Ʀ8wsZ "1l%_W{>BR9HQk͒fkJ̀V~8HѪӘ`eh/AzC{@Su\)ŤicRLǐ r6h@KIϣrA>Dwgg#<.۩( !ߵ6I,|/u*6n{q.#DQrlF09NÙ:\Uw=OlW;T^sq8KխW+ Z͛a>.񔤙57{W8B0K{tY&s;qyЮF)U!5_6LoX»m4> x::!Ew t;eldնf"Lq8gL3 SpdGb6e" uw+NPjׯTd chu>2[8רrg~/ٶ$5ọ//`=(s2ߢ#M1YWles/cC˲փe];d@%=BK7W.;x[lW5xM$5Ug{w]Xe&JOuRƄ~(HQA[5 ߷eHsf"KPb׳b&}PpuvLҸq l} ëB&(H{lv;.vOUӭs2&d;D̿/ِȀ!ذKm"Iɕ-Vd,P(8:[[ ,KDZ @LR(i/ucݎٞuSqZ\xaZ$1f䢫~mvh@ɅU@x}ST<`Qq>XphZhΎU#rQ>!9!0prQ;&La~}VH0lp@&c044\|gd-~(d U8(esd8@eLۢw'XRqˉMuzx.״oGuAJ@פ= Ȓ(Aϳ>N(SUK˓KAO[v7W_@su(>8N& 8`m`;c"C'ny")tij=k YJ8*RȻݰEu&!$ 1A.B2fQ#u~0! Un0[o%M]Z'>u G g6૩ɹUʭmOYnv||o']<6|SQ,1=8ϓ 'k: rN5FvݟV3Di1}Osldl_]өqgN[51oi:*zfԝ`FnsnEP2Y5?}up^@4^C3xHM.tboO'N`ٳ]FWEjo;-9;67z_aIcSZ d-oC A|kz4nqaз*ׄqAoۓs50  W/PWCphLN r^wb0'T=T:PVSD:QKǪ9i+dAG2<>5{B=ȿDr9*T*vf@$  \qqkb6o`'/߬yhPd'޺ܫ:2Nrj_v!^Sq]7͌FA Y2Rv.Yl T'evfL%[|uxb[#=+|!%/q֮-^8qtpҪQwFM6g'[BA|'4=s<ň @+Lh}Σj+2g*Y(I^.n5YPcV ^=A. !_5)@?i_@zx/@[ mEi '^ezRB1'NwU%{LJkZ߆Nxuв WU/N&g>M*,tdy+wʾm8~S;z@ & QAIĂL[myi[*҃&ub _f{hZ{''J [ د/s<jsA~G5Ua=qsv$/D, P}#b}X *WLNj!Yt 8'9R՝y[y;L//@ܗ7,0z+?K|( }u:Uv*dyagq%(~|k֦Cذem~U7h+KJ;-od}Nڙ4h3zA q =zH3, g~#>r1x 7lʤg"r:}>*'W $f+Q3BoSE\OjY,Sc:rm8f|&\K.ES7rAM 9eP=\,#e~suFH Ŷ&%p\x,%dyC}LsJ ҸX,jY{I mlPvYӆe3A5 xI +?VtDn +eOiXz"0B3؆C͊E7)f{?nO }(Wj.ѹZղ!%qR w'IjMI[Xgբ E@XmV]]9nGd(7yCo g}sRẎcКNj%= `E Մdk2Ȣwaˎbh3U?WiwNdm#M{|0|-Ό'lg)yf7K``1ʻ]B}P[{AM\qWTvx6bic$礏# H~ Г_ eyZ7#A&ʹ՝mPE ~ܽ)!"O`qvNbVȟD7,Vi'v w/"ødiN%W`?x<nc@Z<}vYGY0p⟸˽M')q6Ԧp,^rhr4L G"&螾YL8_H_um{Nu " UOfŻَ{qO=g4+Aw* ^V?ˮI[DqamzfŖ/NZ2`e0LvVѳ?xݺ Ƙ&yf0mӭ|eU]IkdFضVH`58VIdfaMߨNoI\+cr.n-?ٖGJ ^"Pt+cOc%''U⡋ rwPKşY~:Sup@hA]SL-K@W;. J&5jJZ3 IX!C-#+wX z&ұѐ28;bxjS?!o9΂OwiǞStD\^LS'$FZ*+tB Dv. /fkaE~-BqƤ"  zY{͸>=*ZE](Sb(In}P{ Tj_krt-,\?uǟk)$@$TwR?Sr@_R;Oz6ts@yGjTcGnT0#a@],OA7G!Q83(m"7L[$G]ڧv |Z5K2 _!wf4:(0qaFoԵњrXNXe0|)0$0zO@EW蝋i-BߓU$9dUdV İkj2PSi PE*h/F-6VoH*:sִ Ymk/NFd#/@fH&ԿVCv&\[?^Iʋ{gڊzoCKFH(1O&tY̥uR99[ ܧ JZFm?>Q˻Jv vz[PWّv$U<.B2@5?|zpD*]7'ouY4 V-˕w~`,UofKz卍!˓h2zh<DccETXj WP̔ay;ɓDeM1JS|uׂPQXQ!1=!]w;3](?Pr}flf2D ]O:M\ÚLkAф7c1]8@LRܮ-#Є",GNL21iq+1kV*P2s k_t oij,n# φևX']V  #Nqv<f1at҇$H>=F[.«]Dgm\]&6md 42nQ]-6o1jC:h])SltH+;2򡗑Ne7%5 ;="9AqOְ$x##`GM;yܕQZsOV.n()[o?߆?ABsbo-4d`_uoGܠ[>4ڳ'1juB Hz"%lY@RB+b+94Ү~|+ wU` 1.im @S!( @aV8W我/jRAlU6 {o|lkQ5E74\"?|M |I. K,v.}A5đ^gE8\*N GxLhjE>~bkÃJ+/Iz0 z@r.%i0pz<]%L*30P36o)i`Q)JwVՠ[&3lu"a,Ⱥp2cro.|AdN]փq*m%T Uͽg >Շh\ALXe0kߤ`>y8@+i\L"_̊CLT2MiL\<%e{]12=ڨ jț*f:;e: ٘ f8]"3{^Xբ&{Mj2k-UHMӻQ% )b;&{Q4}9`k"W)^K^l~XkTm{z~ԗFg.Ƞ Rap>#?1T:յj}99 ڟ߱Qp=2{-ޘXshXD_.(cl.y/WP8\" 6r>]?Idۈ̗=oTR:.A8RRd @[͠cScJAZ2T|c'{3syu&`OTC(P8 ΁G#6.2q-D(F+dĢV'I?\8eM>bj#qt4_<WGueYi`ϙ#FAxOmB={_O2Z bU3JLC B;*O oIP?InHs Ȩq eCp0SkKn|2+Fbi۹JE:ݍ3 IkB"E <Ԡ#*E?B'Gc<&'mSy5;BOEv+*r5߿ Ϊg0dZOjJe:<" $^ v@ūhۑK ^mvJK$.V9S9YCaVg6.dlUaj ĐN9Y Ӯsjrp{.N=C^NӐ†4pB6 f$+o+14ꀞ3gxejD!3v;z򚏮>h?9҅_y>W Ϯw>Cy%rs^ɑ( yɈ&Yne&V*`&#' lVkmk>aԤͬ_k԰;ۤOj %~pM"ڸ t|3`UC(yj@0~p0;39e ~n @W~0hr|I$d:Oep~'z=I7G#MS!A = ZP)ƽvSٰJolX=EY?ǿ˞TP~$U.؅6z\Ҕ?xF-F2 M&*(Jz#Ǘ''k!\]b- f!9odO쿚 r-còJ KȣU:ߝtOZ$"GwFYQБ#w!5D q&-yq )P\НLQ8O"jzdv`cdICcm52n9BCo#M7&v \0&ULM_T5MЂcmZ3Y"(ZXߑYSvvt+{APh|F/Q9|  X)eqw: ֵ49qAV 5rIX ?nܶPr|'H4Yga| ǟ )GB:oLoS @.PͤK Ԝ^]۲ lgۍP| AҳL7<[KF@:7(`Ƞ(_6.= 4yN#sH{~W aZ9+7;UnAS* ` Vx,ԫbRuxK%SWXSh1 Y'> ir3ƸCUs|.WhEhx[ ք!zXe\eh#b0L,7nYN㹄XZc>͍ 4skՐًA.j+IɨT^#'e HH?+eY#O]v$@ORmg15( #M`v΃ϦM ĕq^bRq|%^#ZUAiFy=-*d8IHŽHQ$tmkh]Q K]^^-C=}])Q_¥Z^p2p|T)p.mѪv}s94P-KoXH<%gξLȓ[e/*,lf؟< /o7`/Y&m7)ʍN)jy$*pw|mpdoEW_̖_2@}DJ)dUEG"s?YZ@65oE-Xf:\MڦJ^*N*c.,R.\x''ZG)yWY 0z̈ܦ{ըͤ_;[SZH_m)_BӦ„5krZ 7*#|޺6]Ԡ'Kv7)o|xn apC8vU9<ґ5uqy8'̕dQ&_nm μlbg; &c)3GՐ Y :˯1L :uq9|sMcs3u:IZؠfhLQi+!҈Qr\RK`Obވ۸:E\ɖF%ȃ:JMtlf8eicR)"7vk=&Wf 09zpSbT0LVw%%;<&%ⷴ--4 g"YPKT5zZPE&Ez>E}f9OQ宜ɢ/)Jt_( RG/uw QfSۍR9^|gyw$;=o[beV2VFqYU5|Ҟ-,4$Tg YcXq)Ӟ>:5Dȯ&"Wf3>Ԝ,Ne=ٞ( tq*6'A:#R]iz' @z~g cथØj_@#1=7J%Ǟ q,v;̊f.^ P~KC>tS+TKQ F/QB)~aPg@SX\AО&y<i'Qf0/߈r=0Mߓ!8=$g7}.\,j"|sI h˺<]?Ay(sOh4RAIenl HxUe6jƨ"9>ɿЏ=q'*f%Ӊ+}6)B5%00МPH sٹ_ЃaCD;)`<ئj s~f\at1FH/(# ~]"=ttG*u6Usè0rBL5foϝ(3~9#8o/:ۃ=&z =3&ī~- yɺma#0Z 8_jpboieJ>wJf֎=T=9,/1Cvp%)fTQxZ%9h )BT[tp{ksw[h}gŅO2],d<2aw{M'o*̭#Fl3ذ NY&K^Em-r,XmRb{yQ'!K.b,єͿ9䃋)uudだC`ҰL[jŠ" ɥt USmg\WA i[)LVKÓQ`}WDJ5^8fkcC(GN\M&niW  ]=W,DcV+[q xCdGoyYCN9*y ~zl /^JN53ͺWkF%Tr\Ɛ%n]E"s1E ](0/V(גi8޻mCV/ 3☚-Pg|n|ұ&[>qz[q0bm$6@)H{Fj}V+K0VxȪ ا8̆z"YM+ eBķw6bLGPؚW5QsYtY>[Is0tpEPv25Rz"뜦ƪJ8֍v_c~M1{{bf#L4)t^[-;U:Nf[;HI<]6kCI4kLyW-iP^- \3$˹{ݼ1yhLm^pwWc(TϿ ,ZI/IGH!u|iLE b5kF}p| 5ljX9L5էۛl'Ռԟo7 -Άܒ) ,1̍&W , R?˕ޅ YZ?^kuAHrʧzQ"Hy( !xr.EG RS_w@ȼ2/,PRd'-m*\I~_/@T`K>8wC3!rֿq2Y֐ L\#?pZuJU}Ho`bLE}P扮~q3}/Ї`2 cvN닧X|#vd-%'؈)Ѵp|m; pf=*,tPRwX>b'̌\op%ľ/,٩T TOF9CruT.̿šY0p{WTzDW?ֲbT=,2"}4Z5+嘙-[/S)=.,^$3n=DpHZhZ$[`nwGJ_tm/Ax9n NhјhUEs2L 6c@R Rs/y5I_; Bɇ/cU~c»x[r|P6O&oбX M:7@U,YUp 1gqhJc'ɲʮMW 'R?קn&cbN@/sPYO)P,_$SF$tت:%EKd{`Uj7ej əSt%WQPHA#m H)K4Oݍz=z`]I~G&1<t,K=j847eε_{-XwV6 -H5+vʹqoD `m/:dҤ&;4Pi;)9:kk@4$D{ 5Lf)04o}8}G'7I#v@ɛ4TpگܝB,E)8[-$R ydBpRCb,Tis x ꡹޼ C*N|)6ڻ{<3~?M I V#שkK.5;p\-M81z`d8d a1RE4PRnC7&MZ?}"\ޒu- eH UJq2>GЅI^t丞v/lˁIx_t^pO>_;=x}-fgiCO)LvSxyѧ{).IYڵsR?g&0꼆k9"dS\qW.?fsht7oWm \"6tҐ" X{=H%.4&̹O)V?wd +k-B*QOy,qxJ*2p:0v] .`iMŝڊ[-zqaE`F\-:UaJ\Z/2A︧@w?mńRJ>-z<~[RE_z3D'jΆg[LqpNත-@B1?UQIqw^mQ /& Pv ݞY>kGյk ,U- `Byk IC9L4rףYU-XF| U:gzW20J3}BmFUbKmLОL]H)U/]10z_z9Xɾ%ޣ |.׽cAڃW(r.NVf)lAc(ܦ1Uqȁ]fי ⊿c|, /Ѱy;m9D}uNP;es2Dh T9٥č }q~JV[<>deMieկ]L$ ">r>7Ō6*dVHt$R^ZPO} Q/|"`Yѧ4^*0_Y)Ec(Jjraz"8#P/؞$g=Ȏi)BuᔛNoC!jK)3w[`cUp|S+{I[: zE¸ҷNATc{^187.:Mi\Q$9slLD`rSLo1y?H0@PׅRhqu5Qh9m/ ZA&ӹu'OXh;ff,{!=T6}`Ȝ18CG%5 %hwzJ/f<ضDHxtV28H!I" gqp[oM!9A-n@WM^8kVjte !˺cTY-kG jV5'WgiΦXߥF݂xhP!*1Hu4zb7̻qP1~+3߶1SUu 6oH =ķQ J2-6B i9+琬f}A;ʷ{g7_$HTRoJ;#=.uQlsU2Ր!B ΟSLp ү9B|}(@BM PF}'v|-VXƖj@0o$\x>I$h*Ls65,su<[ZlT>U'YᆴQ_wV;RE[q''9YC1dՌd9_6J1HJ|yT Hr ]:yv\<3&x 9 3q7[wzmZ|gx6^V^oKM|ɻ K `g څHa~j]fuH4IIw#_pN>GBߡ?,CfLvIrBc9%|} E7Z?(`+Ȝ'!a++?d4KɞP7 :#q t/A^/3+^ ))xkХcؚho>< C5殝ћNEyiKQB IffM\No6dWLm 8n4{)gKu`?y:\i@k$Q`+ /@#Pd]\qTaGJ͠}^/?{&J7L<#Ɵ(8oxE-qId~ ,ӀmgRzfRZm֥X_wx5*-3p^߯JnDrHܗisV:N嘧xARDHXlL!vq\*VZ}G+$`~K;!!'BQ3yM+wzǻ1Bǿf13H’|js'zt!wx8gjY%B&8/lz+K/3 bz|":i-,XW0>f:lvO+ '}d:QO-;u1JEQ"Kk0PC-W(5uSM6*O<qFߔD`s͇",}ַ}icM`1ja#$QK!nIrwrL upu0bvj i#\(uK^IgcyՂf>q;҃ZLC;K7fSTHtOJbdT.u_t|W`> NqHpIrK}~8&*34[ @ -W-;v k?TD)vUjŶLO…F)(`Hr f7fF\۸Isϡ񋷖7M~H?!Q2"H?Nz'.ݫ9[) "C ÛBi-k&NL&7RXɚ}/sJ eBXs2WMmhF pf%b7Ќ([rByXOd )y O:zHlgЌ-q؏- H׽a+ye-<>d,2>:AuEDw;7RӺf$\~wLAH$~۞ߐ9] *FEym,o\Mzܜ<)>?p?PF˹̿O:lB<*R A.#{XtKk;:7' žp;ma+i$| Z]vwE[DrROԭ~Cb T͹&tK.a.ۡV8%SH2?IXi(Fz|7ę*hN_eZUE\x:pŊ\0a:@ݔ3*u7ds:VG(l>YbHљH=كN`m+o xB  vTdl 0f+/xI>XPIE{banGU=%k2e8䋖xħf]ѦTax'Z4૶ uPK(wtK GX["zisG哠ov`DAF|+S$9w6tʠ4EELNVf&'OZNu&|zUK9f=:İs:*м)‰m7`) K(o WW&`!e{ 0#hFkA5 a/̶XZ:@Im5s Yv,t*C".Le3hODӒSt]r.͟hx u}!q^6V⌦G)Z`!<5Z#ySGÆ3'v@h@fdEze#kg(]B MmC6KIyܨ(#l *~ՠ5*υk7Fp +W8Pߏ=H 1:Ԓs5+ :ģIՕpfIHy{RWerɌ.F$#x` 96YD&Ͷ!4)*q6 d2o A]-J Zz+G3} *-, '%%d_JGlo!Cn I:2[} z4ZjFZuGӏZn "gocPd qY:!@ Sq~A mt"W!@Pa R>ݏ~lX#Ik G^0_ UPRj2/`=لh7 heч mٙoN'X!d">)C7:WΝF|R H]g9 4?nd[J >XTĂSmR89; &̄+4S= Hܿ{IM$b} E X"dxĨF o Ԟz1TO1r_S) p^wg[f20dJX!z^:8@d ۪W|AYV)\VB6m|ZzS1f"N]29Ͻ<e4VYHD VBI?٥/ )vD4΍7g5Pjlʔ{?;nE\_F+l|&(aZ9 T(+5ܰ܏%`3Uɸ r 7&!7܀g|%t.L=?Я}ҕh0+䱋Zd]"X̫T:_d}j@S_OGĬX2ed_? a1?t-U= Pt.y,ۙ;#iߵv4FlZ[;/)qEu>iyj1e!lp7TAoY3GW9HZL = )&[@pBB '@+ӻ@O,7'bFtwvA ggSrX3_ʖE3?>ex{t耐bħ0D>nDqvf2Yj}AުʼM?!i8}pcwVJ9pjyQ LWM t!( 7Nx&lP_\- cXş|35#kĂM|^a'3bd.xOA%GBع]ϙr1O5<GV9ltZSMÙު5*p*mYL-za h\P=[ߠಷV sK qrqaNF9z|l},jh1aD){7_B{3ua[GLWNб| _tN6z3_hWtߒޒ4&RDwˡtf=&NO,: _">ms͸%LKؕfO1ͧf^)DLC 1OZ:]!JuiS! QUaP{]/(}~_C8 XG[2Y,BHma5׊'[JYWYORSuh{9ex i<
qf`⑵~Oc<' ]_ eǍf^o^`ٚ@)=.'45c<]n~鳕yt1U%0A" 5f*b 0 %|*yS% b]tH3w1k~ ԮmfYn!/o(SXξ6>̀=\\&DW4v [.gxVAesZQ옗+ܽ eoؚ'>lHǀz**F.B)bOy!a*ޠaaّGԻt(^${atM-iE=bAby77XJG;.$9R8%qNw|]cm#^aF[ $'rx1Ţ"_xom J4i[s7+Uy|ň Mkv!S[+}M[L8ӛUy Yf ]$l~!ѝ8}#VG mWߦg"1fw,/=kJ8LK$νaDa]78©oCS \}cF9z񎸬LPexNV~񢠚V\PeၛyVɬzjt/0%O$<~x&iWEV$;[ԛa {^'ԗs D:8}_OҤߩ~b,iO78BZºhdSiH%C:deN%|q)ђSF~Dq('٪.o=W0u va)[UE 8YczWC3@a,71E/V.qMڄ D-JMg5H!@J4cM*reRzJE]d̺mpuf(}| .3nK"!OTI '4}L7V1^R۱M\@=rYsFt1CԍH~O td2gHk8!? %?鴃OcmҘ$3ARz8dlY> mIYA晰q$$Y`'p t'X+x*,-МFƮCE&AvKÛB=O";uOe{1uz/^nV49I_ uI׮0`= :ZrDMn!G 1+&D(M7û뫋T_h8THzɓ@^݂O|#h>p{zRTs6ξ`wq鵓AeKEdƼ3Զɭ9tKL##n@vθj{.hi6dtJh [*j줻)qM~)?DLLp׉ɦOΩH24TQPpI7H&]M;4Pf,=[YaT$;z-6@5S&5}dFJ"3;vHP˨qĎ#!S凱 Le'*'jR Se"\ -X?yT~qY(`lSZ\cӗB!hLos#)+EI7qyzZϐwû%J+Z9~"  }1?ȝC/Zw)_㨫4e+` ݟ{ dO\3K3e0 0B^!o'gw41(􎹦,+C i ".bc@>5-'I LON~վ gVnT5ic85xYf!)Q2ܹA_|U_4 LS]mR,=y^jRQgΜgc]bI U4m,(ުBX 虻.<.kr̸0 Q\BpJsT`hy'8A#8`O;-r[t%W_4Xrr%|BNi.Qƻ @@8e>b5R2tT6vlujxZݕّDk<) ^6msv3Y5tR+fVpN юij'7b`AqCR2~(:ݚ-tGSه.KMs Si h}k|C z4e H1zGq֚˭r6ET,lpJ&VYvk(& ܢ=*q!26 ZgF!<,xyY8Oņ>o%Cf)*qSTSsْYQr!8C2@ HP J^r7sC7QAw,m1JLN<7Vn@K xM)kq"tk0Gk8Ҁ00u@6 /܂-%ߥPeϧ n=f`>!;& I lY&{4s K4[!i0i~ΏPi fc{9B҂ͯ\w4(Ը50%?l,M Z-tBغ۲T% Fݱt{m`&;>Z/E#DmR#$e dFo@R] Pz[XC=`*Hw`,y%T S9`.#}jdZ;Vl.bZ^Kbt5F[U`q#æ-u(!F5F0EuhʼnY8>i}5$6%Qs\kD VN:Ht9\{KFr5 S#cievY>~o(>&b>ñ=v49(\pSUhLnj#%*UTh=CF;@gsJܵh l'd4LkzS͡[\bmn˺FjJ+ aO VIZS86J On['G fNѭ@aÎ:ryJ+T/VHqBXYR9Ϲ|ʖ$si1Ew/?E٣ӪQcm?k(ZhY^k׍4uޝ_t,Bn]$=㔍L; _dF0&~l2E{Lct LUG7K`DʳͮG8gX& .ڒʢ9w':E.0 ,5`V8\u<z7:Fi| ?v+(Dnة<1W"ތ=?Y"mw[Ћ'zX 즯m3 ew)-@AvtIR(WvUz׭5˝)衚,sDW:I ȶE-Esz;`:t7d_i`ߓ\KwzhMʅ]ޥ=^؊;YWOz &4@]dZ|FX̢":>8no볟-}Kh$ԅϞwQ*r?ӬoUׁ3 9 |Dyni Ê.~Qq"RVM% 'hD;( BƏKB9{Dڰ[Sv~ 1RDǣN}x  p&xNZQ_=6pIL=<Hj֮q6^V]]w9<LaתT'P'o]&E:%0( R츼Lqx@@ @ *R~psZPN3PW-:5Pc&x@*ےϕxjApx1}YÐ9n~/O!ڤidFq9&%h'8EWu`s(tlB]f@Y6q+OO|v,gc8IwkhpP6kN%]274#8hovVN0+1*>ly%z9tATh(UrD.p;F@ckX"ѣu[P_c1'q_HDHb.Ke+ 3Xb9%?T,8SteVpO2à[Z.-Dn9e=F 7mNNa0 1jptE@<'PˠZK9 RPŰü!HZ>`{ymmkeZ w~(ҺSFm[`f=nBy٫9FH FƆ˗x>n97'|ś#M911H4|R.߬{|$qo9zgQlr;WCgL j+/gU'i,4jHn]Υ"E.u1Usl*Z18sn4X[D>GEj`@M"?5ʱ8W)rύűbQ4%|~*"ߐK~+M@8t3R[q'^oTqWiv#GF87㑐>h=mST 6jZ#!R,C GliBeEnwݔ: AFC x}+ߙΞKV0b yeF-/!@ (onpUw6f[iT[稷P`ѡxR?OT&oY3ӖpWYp^>rSuUG OwfArAy.4EcQmf?+_]iHm`4ܚR%wYpX\^jb@Jx.j-HM}a+!Ck ;wu Ͽ61nj$[a!Oĝ^wpwC:+!QO1V0 lU2 O<єF\W8.ȉMU#o2CqL߾ yȎ{_d1*q޼,*ЫmHB:J#hH-hJHcl*5#[~.$gG]BkS)kl'Ӣp) ^y_+ZZ;=CNsG3!+‘'Jx/ 3`p~skpĆ0sw Y TP;0 OI.1DFz?ϑSc;tr'&(͑\h0BPk JF%Ug>Ti?a8T#=3+9n/QIPu**(…Qjͦշkg9'%['898cfQ5Cы\a2K]˝qG WV=Ǥ Ufd5Z:lMMxJliKډF0a{!NӋLɻiwʏň] mpQ/M*-'  !".NPAfZ4}v! rw,] cp6Cj8mG>e'![n}H#z" +@d70I!%fJ.|ۺ)R-GXU@2WZGx i:?bn%^ZLBpBNZyRv̶ sK+E=C.č2BK<S|3ܽԸW`ZWjx}_q?ojӀ _ #X}kYbhjyc!wW}Z[%l!AK{zFFmMa062e2(JݲTB4$=Gk~$ O} Ψ磧GDtƍ.zm穏jz &#BѮÁRuMb3v"Fks_dfg T=~D6RMdϴN#R sK9 uDAMg!=4/ al%3^ܞM5I 0ǁuNŕbày̲sKP3L]]~i'o{YQ :`١ t'E ˨(G& i G*qCE^Gd4=ŌԶcG{z ImKI3;M@efTH/6A>ZhE] l>,FMQ`%FÆG`3} 16[.EĐ& $ՙgsuZׁql+qz:ͩUv hRYͳ"]y.:+ժr<Š9EGڨ;' ^u;7ܑ,|ؕpEV t#j0USgR;yiň1 'C^ppcN_|x %rGZ7Y,ٲpM!CbXהrK0/贰m#Oy8[ݟK|[ \V!+k[FwPhP2zw{\˯I|RN#G]C!L:nf]JXcn%aal=7FM?3J:n 䵐2/`D>I/4{m;k>DƑO\YF: ~2:jWFes20q1eϯ3!(k06)*|q(["lh^h~O"|KK7Zdmqh9YI[⇅ÚѨgQ6I]=6A;!(êh9wГ&ꊊ2.oA֫M:STiD~P.`g\ F8hobmPr Ŋ! p`D $q4C1`n椇b{.:/lnӀق3z3^%H)i^8m7dC)s$e b Tkb èJG4_h;87K bkӤI8Y!OSP zK0SZVܚi0̅w\oZ\irܣ#23Cp ,9RاMpu>/I^b \X T;IA}sdVetߎSl "j@2Y vg!Nmͨ,ͅvH ڷ. Ռ?cycCBsOtռw ^h(ЯE]8kF#F&d^=zK強¸lO *@cϦy_}L~WeURb%X>42HҜo^"I_hiu8-(:Jzp85WEO“t#V*MM;ŗ}Cx9&? k|:0ХUS5LC6&x \E2MvvxˍfMH:%sk:Ӗcbcs2#rG'T0rb{)AչTj-x!,ն ,+-71Gsl&"Co?Уd̕VzzQWfy?{K(§]Z/llrEms3d51-\=g;?KW 9N \\|#i x̵!ַF3ëNt"Sr"Ʊ]—=VX`tOTOT1. ])t}D^>YϢFW-kNmW@Xw%7F$2<DP(3ɸ_A"Iʻu%)}>*O97n< Q'-W+!u3 ;f!^ful[e+Foo .WXԏeNM{!Fo#2X!;.%IpXyj1ki ?2NL{%VyaZP~'~=gh*9CRcx+yrM B9s9NhU08aPQ(.kX8Q 7';Lee7~lB3@}DsxxdfbDҦpl h_vzgl\S}&LBTQ& Uդ2VgfmrrL$h#1uOC-:XBx&?x ZC<rtj3ѡWO2rJo]vJ@=q'犪h3o3O͍-Qvlp- :Y)OH`Jj͢B7JCWOuW≫__'6&6)jpdm @01NN،уgSX1_4fFRߴpNqb/,V[C|ӎؔ:A_&եBu{kRDGb 3rhaADk4:1qW) <»XfkkKf徤N$FK:хj5\@VŸh=;?Ck~O gA q}i 4\Efdq$N̶0J{GQkjJ2y拥\"FˁSh#w>g&>> ? 96t_ Doa b9YJ0_Dw:>CR~E,.zSS8ZԳaJ]_( &%sT&l WL%A4P%pAFq]I_oُL{W0_y?0\D+]ffu1st#/(5K{~bZC%kI1T|-?KjDT4&MgjL o-~Dh#=/2viNN7n=drcҶDڋYZ (9S8lJ}&w5rnyЍeKt]ҟ+n`ߡecšRvSm`U_F^y~rW_'ePp1\vm4YO) Z\3a[@/TM 9aN=IH隽| a>sfSb1&uX bSXU%J)8A\X*fυ/ɶF# |.}.MK.п6jUΓfAպ"A/뒗Ӷlk ^<zOv| .DqK Bkd; vjK.h3 O HڠbU0(t5{[fyuH7|$zrѤ/Wx!SnH fLjN)>)WdUJaN:\MMuqk# '%E%7?ze©^Q+q+PB$)ΜM&7x;m)(-SsxdSیr%uHl)g]^OhoDK aֈ=Ûp=]^"z'ƣ!tƔy\yAwqKJb'䄺/㹙l|7T&|i`d)sA[$WD㮳n*<1wdct $eE:SԮqRƚPC)p~ bWMv+: VL |ܠNEQk+cs1Q^eOk#/鲁#T8 r $7̉M_qH]oacݸ3uL$ڿ$PWֻt`ct ])Zjn_\"Jc!+>po7 ;7{CK1y[աJ{"&8"3v7Cpk~ǩQQŃ7_V&3^bI%2y9,6rKӰ~r[,-0,35EUUn`?ٚ*@[ e A3/c3̀DgP6QN¶Lih:]n$,d+,"X2Epw)U&9)qv0,ZiTլQR<_qJddbu>)NSnL?41ѭK5z}sn@0Dbfo MF'egJk'cR EI5XuqE<W9WWOTo ?7XfgVf[t`osPZ!#Ď57;Czj]Ղn~I\߆B*B lө/jK;+Ԛ4-K<C#v7|l9yjHzpQY%SHOEch"X*V}riuuGcSXZZSΧ8D~WcbӐSᢱ"Nc(+l@Tje{ODm*? 'X0YٙVZ{*= ylƑ]WO^Ỗ2X]=o.L ;8s& }IL\:@xAI)HC5^Lg,??2C31P'z6| P̩; LB*7|DSbfE]m+:Fq=XϤBP!ն _"w9 0^9< z RZlbf#|Y6R -o՟DW=GaGvvܬ]o 4YHxVet:lVc * A* /{v\k\: ru iFI^w"R ڶTwɬddfտmB&ᔻxO7Չ ep]n>=KJl|z z k G8.9)V$FD$lZ%&7Y"Lsd_5A=EEP-&]./MA^x H_M6bX?IC6őn9a2Ո?\'1^\,i@@D_f ߜKtQ'v ՗I+H`⬍2%> r=%?ܡ8Ŝ ڛvthBz/6}:&t Eʕ0ĭ3~1Y aJ|VHBvcaL)-=IlfU0Wx)g* M\ ʋJ>O Ø'2g5zwîz9]|uR, 8 aGX=D`U(zuQd#mQiTsMMՐVN.ֵ}bPP” %L˿tgf~ Pp$*䮬fuxwmݍ@i~ ݑtOf7&ڠz UѬdb[_ۚXmrzL@L~I** @\u}:??K8'STd$r' Rx-l ra}ON_vsYd݅D M],1un\Jn35!}JI+nd.Cs#QCF?z5Gr?~C?*I^H@yu>Rϥ^+6ՀZC!@6j {zx2G.X;xˑ:f,MK;0ӳ1F$UQgQ\+ g$N|d}ؕ.Y:龜@\ %U].AP7IM~2r:!*1+d8*6^} Q8U}Nmdۅ.S,{kd}_f@QP' i)&۵-Es'4# Yy <8qyY|։]fD x㘠ީ$/+Ӂ.J@.vPLji#n{ʋnoPZp.[o5U9d~wcP 6skrϱN{<yGcG,?^V Q >dRn WDl^ivq'C[΅?u.- ̟ 4s%/ ]qBi #^{?̃Z?KTJ5;L5ps:DHlԎY86v :6h/ǎ{2CY}@yK?KnE"{Ƞ_m@t -"*(g"/A=(YAz\Q .3~.qP"5&iOyvVΨ[ ܢ8ok_z#ںW "S&F@_PJ$VƜ'/~o)a-]\')6L;ʨ^A`j"٦G_U+C|a#yOjv#AR f0ԍC=H/Bj-R hMc + _ŚiA[|9Mh ժX ն&qgWѭ́,MuՎl#}a8;.&wR7$")atN"{#FPsHt6"Z務 xSp;VL7P޻,)M #t"g5p};z4Y[ʄ]C>[kj4jm(/r!3H"GJ^N%vw?H#)nu7a hdG0(2{ޣ{řVr@rsuIlW]u3jP/=VdzH%\PE=]O ɜ nmZt[)R7A=]u0ӗ.A#e t#νl)KtGU9]vBhI`y%d_j 9Q6(FUKi JRً@vf$s*|#2F&nFR>LYDuOy$\ˇjO3+wH[ ZktvF=k(X]!j Gv_#SK5Sw_~aaq u@%mss;"DV\%n~IꩅZ^</ŻfFckk%  1,WD$)\\ ?~əe+`Eae(XrS:7QnzSB:MȯoycET84  YY C \Ub,!"BQr2_ mќ|T io;qY3-,mZ[ETnvcl_\NNqo/_4}iWIzuo8(zmT:"M4hAP+~{=d5G} %$Jf[:VP]n(lׇz! oK–Ÿׅ uD?-AwToS=kkXOV7o+Rz[{Ƣ9D! `Vx[xTI!Q֦;aaW7<- uMu5ߑ#3~^fD9AZ,=$8?-WÌEeއHX8 #yr%5L]ac^ZkMM:Eczd/6?T&T^/⡹eI";6MH }YD{}[EH>O';oY%`O@1KʩWn}radD .H?Y xwo%% ț+̯hG>2@K3^K E@ A%!` J=$Go%hl7; D a͇vUA!&I-[Xjw/?0K]+ S0pT{yY͇vhpYl ~y*r!2 :+!˖fT nJ˸aNEezr2% b)q7a dy\GyP 3U# fDȖE,zwqV ^>0w7xkpɼC7 -)2#$書ioٗEdeU*ЂB'ˏ¹cӄ_V2ILny jJfM0gi, Mzn1PS>Pp{AL'y3yjMgʴhd&Mis^OqQ'p?YcUsԗr W͎ܸ*0w>O= {c)l c4"8^/Ea8[#V<>HZ(=O7@siutɻɞ9?(+b;o.\;%@&3BeBf!;AcO$03/n77IQ EIFkmk`OԽlA6~BaT} Vy2)9go u}ƒbGJō@{EdȩGtt-ڷr0Ѽ:'䒆:K7ׅDLKs§K;~CqX/<ZiC'nŢ1|4[Êrx=2B,vU.i>9{ҨɵOC´9ZjcX} LB#MܽO;rZ[ۗeuy~ sy 9Zt17=^MT(iDK4=Fga%I}oTo f?={F-k5r@ՕU)2J'ɋUmky&^gdGin~̾Gv,;F/DGs8 op~QRK61 U-7#=hKms;솤ɱՀ1sAO| =2i›FxN?TTUC(az#H DUtkKvoycY)MZA~OC Zf^}W3s`~[qA+0՝B1|eGOggxDBH =LML~wpr]G-K0N}H#ڝQb鞬? 0O5Vr%΅՜vm'4* =HBأLJ(M7ߖ76dS젏g,mI1sg#*HVCNmuu H% Vc/\^udR¦##KVQ$\R*ÊWRnM6]4),HˏB'iY赒;XrN~Hn:js=F1vX3F(ڬ9o A"_5񘏙]sObYUe鳹HfuģDtѦ۔ގ=2wY,ԂС-w$EpZߪ \ z\2QS=Yz0~tyB:7O6ว(uz }xRߟbZ>@ik2!t}w ntܛR^{59IfķGWc< ;8wsÄճ)߹uC`&w^w ׂAhb|>'^!Hԩ-褓1nDOt~R8B`Ąɬ&TN>;5!/eds *w'nms w!@;#UԈ"3gt7kt"/KɦhqFΦ#+fyK^Gd;gsO:裂icإt_RL[YO( ]D豫͋ԻW<PUyKW6x_J+ǘdG[l{f?&A=bF)!CqV7^ۭWnc|r(L|zo_D8}5'\#`.#ۋ@u( 1(QARxyyb䵟嬟N3BI/%"&hj.;ׯz%L5Mr?x BMl0ܯVz t7w{>2 b` >x$ތ~+L+;y9Y |dDr* N|cyQG9z,ۼj@o^Z͏7aO/97G XNb1v0~dsC<1 =pbxށ ݪr+B1-z6-dKZdd9-:\vyalLy>gc-fG-И.h v,pH8H06j@jr, NRzٌE05>=FyTj/G@<^C92%Mr7wwPA]uY;t %PZ\ }pY(@0"OI枉eed̩ZLF[n-lGHKFkx˦<1Qq9N u,W!LkhX?L˹ {og?zb^0-M@R>3eYtxG~aV2>&fj~N4)A|XSP{x* 9Q &hD${A ܎Zf*`ZQZ{?,0M?.3C[@iYIc=S Jٙ PȣYQB{:9-Z৳QWES1LKxsьnA3CJ$YeOhS, KDC/9ೕҚ[d<"\CDʰnf~7Sݼ߶@֦O,o+m(_$*ģ։{|VejB,dX$ _^TxثNl2rW3EJw[?i;4>vֻ-kyeAy jk_Wv$ZEK]Q: *V{}ݍUtߢ̕CH$o3q#>sWy"~<ҝ٥W5]?sUivR8L@C@A/B׸Ln!:6Rbvl_8q,\d"AXjғ*\a6R'\2 V!fZ q=" u2+~$bS@JK]bLݒ]}J O`17j h+-I/%s@ b`DƓl  4D)?L;cܙwq~?㇙VĽ>- c(+"tGݼ$6QH<<-O~@{&w{3Ru/VvK"9ndu8cdAχ?jf~RH5 `X/ijf 9(@B<8x$4e7I$/s=A_ TR;GރPڅ{tXmB3 h*-2ω y~ ]5~JXUcƴb"Iy r08܌-_c?Ml ( zUwҲdAG =N/hRǗ1fmfe4PF,>xTs${mPz-NMLk =Fo_+4mY,lLu%@ډm?x+G Ǵlanc/bĥlwv>H̞eGQG@Nyݸ<0Q NGIϠm_d/g 0b/4W>%8ܛhh癀M, .O+dR eZ>V,J<ƴDB^jhU]ԅn OM&#%TK` {IBxj`rodwL?`SG4 4_:лjR Ο*e9Gj.# ȷNVj9"e?U\s&хۆ>{XV O=>@nXO!,f0.&6(BWOPK/O^ ͕;гZWC`6-G:OTVAJkt/$tpϢr($ĎqwO P};0tHHn ?ޟF^V詵AxaحD|uK7B f7X HAHI iWneҺ狄IMH}׾hJƝsS6Mĩ-{w'LBpkΖ(B6?`"L6'zYD"~%.NX1ی#ч5jPG_@Z9]Zԗ9 {[r#0sXetϼwtMm 5ņV 0zA{EF^(!ӛAg=))ǚRgo<=kcU(D\Yt@J+xE Kf$k;lE]B+U@9j}>~yèP,࠹>vأ35e5s.<~R"䥞1ˌV^*N9 GCdk?G ıSN3Na]$j@'\aM)UG<@囵_D#/fG/{A`t<)cG+;WO2,u`+NqT8(ؾ~ш]-k f"-R-$rL49NQm迻.(yqn{IwI?7iWq.M[::2Xd_+8}Nf%9jWЩ8Fiǡw$"_? x(@Y RubaigU l8|7* W NrBEv1aONv%2t$`V"Hۃ0[y6Ty1re#=I k5BWW4[pǩ) F !tϫ^Җ̰z:ھ` .qVybH!8!D/!A_$kALX2`x,clؙ$~Ȼ/0 (-\Cf~MB~٥uZT@4bLփ2@dh01OwڵՉ2:D#B',GY\~6?: FZ  HS555sP=7GdHp<{xϐ4 g ϢK-C-ˑ0O?b4a-^J9Ej)'%UNLA<ԛ3sTGT-GPbBT=Fi ̢ ^eY;oƄɻJ4 ܤzBۦkVf>]ox卟Awmŗ6xs; : ;u[R 6'r>/SQv%Up)88 /ϫ2vWH K*">s!I hn[ (ōgL!wĪo" @].&Pk[CybiExi(H+G ;|q Lw3>`oMxUNUzyYc,P3\9R%egMQ@fC̓8`v7,%3wPɤ^7C6S+jah#ZIDŧzHn|#,CJVF:ctNŇKi)ժqt1_.kZX!ۙ^G'Ϫ >c~JaaaCz7$V]} l̚Dj)\ f7Hd C$6\v50೷"lc2|S G皥k?it3xձp#xmE2&I+ӓ>883RBٻ 5"._2?_IOH穧{=>g \8: c՝#$3a0)4[1 oql`|{ĸuoh x=Ui Em9 #Ve1DN0@ґT+r5iמ7Bi]&~پuc(xA. 3CI=is1g Q'׆lB5"nLye(ƑzE4İU[%IZ$ZEnt02 >7L\0j18{Ef;e߁Q YbvHGoͨiE[뻾Cr&$~ΪobdtI~GݞU8N4tׂwʼnR͞ M!vwk`ঃ/% ؒ<ЙKϑeDVn85`^=iq=aMѤt.ni 9 Goێ<@__2Հ2?y噰͕狲[D=h/=k8}Eq Bq`Y{C[2Wd>6:5LVG3 ) NKσlQfHD3ANžD: 1Rr s?aٍJvXbV7vB `QDpk[Psp hU.z⍻c䤴3+t ,2?$ ;_! 8yϯ- 0q@xaַ`47HG%)p'(>ɐmH a'Qsat>[E4$ϏBR5 'MN,_ kq61,+ZK;ay A$ et)'BW)k5(2EYȸmwF#7K2p[}aɽ/$;C~pݼ?&[ZvŰ }i*RBH MWa?l[b]EF5p&w ^G_ aEbtB%?}!Vb%|w>i$s?Gvt2cWJۀ_'c}%.X}* ׮pK͊gҬ.y^eSE{ {r  ~lx {Kzu bx|G !7kr,Dz苯1}򗩦⎂hhX {`K5{  &Z%y\Ev/U Ք<&2|Z*΃17@yTƘOUVP}ub{@:;V > %6, 0"Ck{]p N$><{!Q͖rH.[|*["D y~<:&[ nA]+D!?%ǺUO_'߃]$J:C 0 N}%G<<ץ3qƠOW#7݈ۢ3fz> Q"бw1Y%7b|JEVO6nĂm-P kxGLnSQ-JJ9zvPvވ~ Ğj30V3;R{OcصdxqrM_AҔwe XbQAvVn'b;XL$e bP.k!u/֏\Ԡ'1Mi1j<{{ !3/k?w2[}!8s3te(#CdkO3K8YMXc'{ )TMBp=Dq^XRHg]16/ di?^Og(!1ibB KIQN2fW!@x&[MAh؝<hȝAZ6-mw`<|0 &{.YRO3(6>v0y, _~u>-Wn3 vV-(:`τeQGH,FԙۯI=zὫkzoԯ \ -S>zxvνA4VT t.vNBA+mh$es-e۲-kU'l LiDg~}535m{*s [AN V="*w[S/T!Cɬ$Y.MGjZɴW xݵyEkq^1:(uN9syBMYhKoeKh:J|]/2Z8ȨJiP29Y?|wk)$c6x#˂I;FN)+Uͧdxp#s!؋8^D*[LbpaIF}:F{MG/*n~ !.q(ا9?<$7E&I'Ř wG3Td48$X`%h$ѣ#TNEC-) 0#&Cwf Qf6f;9p{߶Ǡ._Mi@s6O${uT7 Y)ѷ:ͭ@v' YJw v vO]<B鱧I&)%#,`$9C1}ÕGA"{#t>G:V3*`Ox}(&%FvX=w!Wg^tn<ͧMc /'"‚ ni=@bwDZKۧM)2!m v_(;EI;хrb}i C T_^Tm "V嚧,pa$ANȫ6bU/ؚx0tFg "WmEd:CPT9n9gQV CfJyqh{E~#&<݄2B}Y꧸=4*qE5Ř?jp⠩.4ޏ@c)g#"=kIuCS/!YzzQɴcs|@ZֲGǰR#)NH-ACܫFϨ;xў3] =5{Oqrou>C9.㊵nَr{6oYM l3q"yIo?N]DT>,%"lW!rz]m!yqtT)D\ڤm2HZhV>*!Kd!ol6~C||/6mLx7,3ҽG]*7GWGI;)sg8pR5/a"V0!}\H`~xh9pi*91xPӺŢ Yvq!@1ѩ+k|Ffr,R:|,\uJbġ߰>;iKvq>2 e00f3{# mO<k%b{gH L+b@?m"//,WB<_[2,2GPb`Tg ёq&o[͸V|=X$\p $r77 egLYKXSrGQCq-0% Iw&NCuP"Dtg䖯-I zTlC&{,( .1芵Mlxuy主S+P&X-`JJȄ+"ObtqSF tjLʐ|?7/fcAFM.-BE{)7A^gw{;>lvzG^OX~{pk|ttݦ7)'A߿:]nS+72DѫcL(HM )%W˓9Sb 2S^/eixqGOv &4`pV>Kʥ0Y RJ/!g|Jpty˕XD\hlYQY4)z%QP6zǕ At rQ23 *In:Q-Ōq͕$m=7-2e Fn Y<,`21ѨLҗEfkګBnZ8iAihҤLzɻHiSzܠM9N"u;߫v%1U,z aU8ܪ=}l*ok2vn0m&e|ZX 7܍ BG]E- Y Oc3}՟ «HW&(O0®$>kڂgX5 5Ϣx8p(,Ty^quԊHY~6.ΓUqA; GIObUV2v7b#irC|D,]2|*͡0Q_>+(웋;;Iy27wr+Ʀ@nݿZx*@d^rv(h-ߵ͊(m4<~X/0707010000000c000081a400000000000000000000000164fee79000005178000000000000000000000000000000000000002500000000./usr/share/man/uk/man5/sssd-ad.5.gz}ysǕIQ݁DZb"4 C(t5$lH РG,Ϭ'bb o|U] e;μFt]KƣVU+剕b9u1j_%$iZxhGSU9ɑH=i/\V+SNWZ{]5ѽ^ᇽNIoW-e=Re;jjqJkJ^;__U[ s/D/Ud^?G gGQt.֓XJFUkը^?'gG#[YhTj\i4Fώg'![# |?n%B1?`'cGZ cccΌ{5jGJ+#IRc=VҎ*|RkGRnW JՒhbRF}`+vuZw/DW#%h)n.TQ^:40Wڱn[.E_4}t45=19=y~|z̔՗&:hf8}᪺G{~on?nތ&mEѹj3)+6wy U﷽ore[<+.8e^Unu  I]PZsR/^|ona<^4q^=;03,xf~r𕡙z 㨷Lԗ(A~|QoWWBMuYo~>9Ls~[S}Ln0(^j 3?m(ekuz~ozz7 OU z6m{>C"3͹<2l"9nd[t*y7ikAVb *A|_>\$`)&L ;a~!9 Լp$a[J6Y`εfX(>=c )i CX:Ij;8@7"d9*9 gCx+bIt,<%sklv I`EYt#_Bjk3_=\_~܊zSWJ~J)_?w~`fwo9\GumYɍBs`G?BO;\EkT.{3`3 Ef6jJc!Y+^i7[ZªMɵBv@EEAp $qZ+V/KE\7 x'|Vf^)hԀh6'r LXSW(w@E-7J\c$+Uh\% CI/M. áHu>G3<3029802/#`j}!z5i\k%o`d p{&4f\Å@C5mGsE` iK!o'>iu;tYu(UvܾV;dX94f/S@>^DRy&5Rd~]&QgR&H5>eX f>R;#ّoy<%+]<$MŷGzTBo X]]j^nPo߄{ ]}}7"km.*C;hՂbD491y&|V͛8;xCogMqS-eoO(qy16[mn㧗bw5}^_/Rӏb.p.dy70YK3*vWexn ܷ2$\}G<ЏH6#3XjSh UvZ]E?@48.IsY:M R?*봫.aDr0;W_AJm>Jx^ǂn# GGsӓ-m1q܉>_Vwޙkg9[tjwff5|zfޙ̴~|Zl!]y72}s52Ѧ:9=[AnHrՉs,Fƾa?g:RY9ck)z"+H+r*D:pM]komp*1ޗ}m}z{H1vm, !z+5L(|AYE(wC8d5.G0G]x'~Ӯ m L22)^o%r̓7@Ƀ[j߂%>苣͢>ٸP1qJlWѠ]jg>, :x$˘dİOǨڤI$/}Șt`'?Us?7zJ}zluh*?RkA3bO1I!|ox Ҏ1(uVt@} ~R~).Fl|w~;,ةDIp~[!ʍxf,͸T"@D5x8 *lF_բBLn>mY R{ڊaRo%R!*V^TC7K lj|5M|ڜz{qGyn v=|Zt/xvZ;iF6a'_Tkm3fun*pVjp/$jjT =:7LEW,e`1hsiGYۯϕ wQ+ˌz}jԊk ]AnDImEX=7S2n igbWrVTD?]YWFulo6.h'T2Jn7\d --am0RfU[̰pJ$ܰSLPbDfK;۲rT7xbB_+M5jJ xHQgkZ9Q*N}M{vc46 >®}Ai͟F|?S?~y<& k5۞8CNz='M'k0&,vI&ewDZzh^W+FRݸHLޒ EcYs˄J)aH;.ىhaK[ A36`[Q^֡g*>rfȌ0uW8L)- 9n7eӶuMC$j4#hCk;@5gDZhd J9]=w[pj]ƒ7Jȕf$GOQtMOpr=w|b[*h } Jsa &Ki`/cC3"(JkNϒ}1Ljp0ɳXEvMi x-H%}1 w)*[v2 @zdF@2?ڨ|pu̍"oZ;7> A~2>3JPE?J7Ar鿅ulZ3f ؐ +Ʒ"0.ZxCIs=vӐ5 xk~kp>jH,'+ɔ`Ѡ3u g2ӬcH9b6o9Dx$`k@IIA NL^ؕ r|=1^tս}{.>o 㤀 )~q|/px 0|r$MMDsߢ_~zy4o65hz$ <,Q9SpL_͸fh0H)G FҴV:'xwQA=0Js(y|lQ]K7Q6E(l"T{5`bθvx5=ڰ :^LO乿)XfEcn`ohDyhm+-D8t#|z9OYV^yqL}ԙg_ԟߟxj7f$73Yt٩9N>Hh.[eAcp&ikhC0>zF>8qv~9Z2̭Xi0uQ=,%ƕjUjl,J)X&vz|B;}c '5?x4_W j}lY=ӄYE<Xz Rj9t༯ izW\J&^x[n6J }?dm8cIA|֘kq;5\x,ZWX IJ^'Sm1eF-)}9eݔ2(Ti>Ȫ%3.եfMDhe[9Xpkۈs_OmT> > kB-1]tc1ɬ\4ߝp`n6nN,8?93é/Ssx+g\H\?|a}FlԞ͉~ Wd @rq2Ge,+ǹD1P4۵݄~s:-8dSf-6(1w}`[S%܀U0^r.=iB4ۼzB"Cq]권㬑^md#r'bQTؾR/s4rxA[eg~H%iY4bD"r[L"O*Hq mQpV=Hw 繁S3ggϜVoÁGX%B*pNj{Ld]'p}wV~\W?2mĠH Hް|4G|D: jqwjE.L.=˔J#<'O1밋#3I/{[J6`bwO&gtcoOUsǫAOՃy«&Y؋?[Q?xgHji-GçF.\C3dW@.&%CvE\ϞwZ-eנ}RlfoNϞϜ]nר.̩5 ᾇx5/.5^ fQtBs6̨6 C|R:0{; "뷂d1![m0I姾^I`g{(mbڞak;_ItX>D1ߐI#^JdB62a&҉<Ŷ~i3lP|Ǐ4TQmVբ:- aOM}+$ @hf\0|ts%)yD<PfJV,Y|FD:{GY) U (P|)f$=C5 P%L6W@u[L2,ƢM?0lv #PA t>EFݡCf1HU r6WP.)R%`n9e+qzN q!e+~!*sRkm躱>LZ+u.qX5qv&dpjY7Ex]AC,Buzj Dxnp| _ZQ LsXppRMCCjg+^W/$WY@ex5׀L@9RKCH :?p*u=uYn&Z9} G]KS1G8;ruy[/ #ӨD>Am6O >ωLc٨ٕz3+XUQz 6ӀFwaPJ}8IEH Yo\3-f}K=*"G^g0k+"l۰Qe8Y];Vo@DNuեʍ " hWWEC'cCՈ^ Y6%tf!6)@4툊[e@" i7dћH,9"@F<%Tpsy# -"M[К1ҕE -sRVȩGMLM's[?᜹g&m۪:pqaZcc V SUE:r;`2oyr=Y>V.|@Pݸs7P [6*؝0nSרeŖ" \('D`99vOqI], W Is焞Z77$t9?8Q[u^m_=aHdN[azw'׶s -T?:09kx{gFwxcnۅ`$nv9 NZNqʃCdxs^T\taewۍh̋V!;$'+"s}k Z@@ z`;;qIQ~w3QI[>K]r$mxn kldQ|y/htd؅6i,A԰ܐ<1O>A]̂F ўgr5GRgrciyZ,6Y˱BoVhsGgkU0⟐˿h+oR,Rϩzᕪ6Dej[0Ïgges_?+B=.5ӂ31+_ׁ9Ay8ֱmޭgODufz_m<jLs9\ .zZVx֞mW/t*iky θo5, ,gh^@=$lʋ7`L9ҳR5ڎ;r|nǰi(o>{?]uz[4Mluه.PueD}l"+3z)F-7.+v}cV6)nm5vd,&|v <'_Ҙ{ngP3ϏU`YwwX:Þ';n'Pw& ${K+Kb@Ro"B[.wfKpVbѶ*qZ7㣴GC@91rTwRD F5pL܇HsnbvsNa9]Et*55*>3FYfa3'ǵruF"V)iKDl7;YM%p<&Vj?Q`f8;#7`J;b`\"&LNߜ@r[4݈lR!gռזy1Щ6tY?R+Ls1K";Z;()^Ů+/866ٱh>\Sg!0Ia+Sve+ T #%wyM?6l3A-]ԹMPvf?vkl8;Bo;B7_ `rfxPǙ8ֱhlFƉsFl>Z(J+dV[E)J%=*sFtĕ+?2F1עv 13/~ Dħμg?a" qNs)#$k`S||A%6io.I ѳD׮߰Y(ԹvLM`C~7&\~ifxʥo\O%N"9R*d5o.uoX ܴ`tNltApz3Am4j}+. uT7^mu+٥oƾ)#.-éN_N "FiY}q~MWwUk`δu6Z0jFܛ5vQ&c^v M[pպF~_K6Kn)astouT z" J,DFF~=krɱq-etڢC]sz@s]r;xA7U_B~hFD\M2HZ]Vj/ vz4AU]UIh^- _}mMޭ}^F] ;폑o{~>Y7Wv\ j{hnnc[?/{޸şI$;۸ی.O!*)17%lH |GB9fMy<4ӼP>_Tl.ۚFGϱ W.O]Z}z4W>wշ84ɰ(lsh1~4Srh 7YkjK-KpWp5yIY.ir7PP@0j8qp#9]݆ fI]/֒Q:y\JRh W[WPBaU,?J׮\W-ժPM:Zȵ:*Ii!!@y<{0561Ji:"Z+A,T5i[*Mo7=u m㬄p-vרA[k -Zu3zn6%8yE[um"6#ztǤO &&JiKL<^aU5G.o5vBA9Dor CW |@Zi`"l vod67Gg SiꪒI_M] SMO_\|y #GgLZ@I4jtݦm6t@pH)wau 9{+ YTIўmg^j&O0v%eikK4Ԯء a89b}]ALaQu\>&"ZC)EMm[esSS)poV5DJTWR/qe7 ʰq_]a%59j,*EՓ6sڧf2LZx/gqHwf>浝(P)Fe&]e6Gz[ȅu ɇ&qy}T@*t~޶vc(Xj֩zؙo)iI>ӥS={tv16㢝1Aߏ^snHi@љ̝9X(HAo)B<(ae/ [;fQ'uWcѿds/ثh+ӓM.ocĄDl!r PG($lt@ϛo4l|\xsOL~ENj猻p *I†67 d3_5í}on~vn]x ႄ̨k͙qHk˺[lg69߲ϲx&pk^֮Us ]'.L W{Dk^*?[VU#/7`Hf:ʫ[aCf.6J5"C3[#`>q[2i C 9yA>\KcI;̜a7 PVx[זN?x[o>p>޾pξ_r2e?8/Ftf%)푼Pkcj^`kmzW_\*R Kpѕf^.ǵRMU׽zY_b ;AwqIxݨpG cS146:u3ŋH~Ӧz' =DslkeVG@XhҼ8A[~i6_ǟ9&`[>OsyI)j4 ?*VA )Gۡ#+R[)Ujf(B|ehH[AEU vm(ϒBۻ>HXLP4n& $P,Y2Y4ˑO.wF.ie8>:]T[KZ/2?)C٫i*h~sC~>9"m¶{W6`wb*Q4yÝ1Ju} kK8jq |܎)XӦ薰j fcJ(uqSd `7HGZfݲw=Hg>}BfGcլAe@|ev9pmh$S&RKnV! ǒuiy$xl.8Fd'/1D%_i/"cw&X\^ZqRO2Dֵ *iư2'ԛ ?G6 rnE'Wzw~Iw_1;*H&pkŪ),He9swRV OBB6!!D.Jp"/i+e1j3ZR6<"6vW<5s\&_;f#7z/UѻpdS~`YU?.U>1k[d)VO,>B++j/I\[:gV!y}N+nf 2Oid^iq&rb9:o;`TKEODV3 yr #;@jX6i lq= }j_um'.)`Y_ޓ~6 )5cql20~ _KFY +^݀ded|jgċ@.un+j@ W&x#vD0E7Ġ w%WOS!\3MU~8+Vt C!o[ZG2ۥJ]Ҡu0̲ҽq?hx [S儦 U!0U鱿# ][NP*JSiBGzcLiLD<6OM$tZ܃>Pl1xS7C" qx[ FufGTAJԝU.UF Z;hS.9C scWTڧ6L4`"F`k*zD{t/p_ 6j㖢hC-$=\8vYT Sڕnb|Nx{RYIFјmĄJy̫ :P/y:[_nq-b kBB Jx| >'*0f:ǪFg%%nf~rp I=艎"ML.#2V)z}ɿ t"qa7c;Zd Mrxٳ'p٦\;\P6O.:,gRPIܜxPΜr*͠n&Rخ_3jxTQS&輏nno&7wi} ^Ǡ0w_M K|9a~ǾrKvrz]Ӓ-ߤ kU|xÑyvf s 4Y^@q9j $>v F"OӰ8[kCSdQvxυf JP-@(=F.UL(; =hfzxPh_du0iiz,{Irl)p@eZgD:2Ȗ[A]p)Si29ݴՏ8J16V'^`sg:32>i_m}Q8}>K,崥`iFioVNjl.p~?Q ;" ܤpivd0FyͮhNz}Vh2$Y-BpKzu4 NH཈8n3c^bCКLY0g薺t'ˢ7 IAXs *i)ȠZ-TٚjJ$9\H TeT.X 9եԙ`& UT5fIXA FP@V`N h Zɢ.c|Ue̎.@~Y݃9T8dmsJ1(f:Br FFtɠK4tR>|o0$ȵzl,'2_jӏ̏ԛ p G":^d<҅X# {_cw b#="Wi|}}o8qH yJrCNH Z#Y 9C#|dSHu2p&PY0EK4NVO?LU&D%}vHoi5j%MNmWJ[I0G( rtDj(9 FϳMR׾(u+#%87LαdU 'ЂSccc6sOnpc9ssӛ֛qBq`wk]9ȯI&&'%HPavNNPbSW,CۖvqYrPUTFp UQ{N|J^>/hXrTr_LY1huiX3R3sHʺL"sƢ(nxUX_2g-$iQÁznڶ%` X5̰ʽkM9 vt=*cfIq6qg*0uPDUi1|HX~<v%1W0)5mePJB: ^: 9ӄɘ^s"D"q׍ v<7rܙ5暥ZMM.JyrZ~Wý}}yҖlMк9 B;\1m+ϴA u#h=%t~>k"*pN?]6(kƕcZJء}T`O{St_Y]nm };0ֿ(š`w:zdXٱE2qj%`j[FSQpruKfl\p3Z09HSl%v7þe -s"K7e^ttF t2+%"3#J.rx; np-COٸt (^v7? u)w+ʥI^0mF?b1:yPEhFr6ܞk[H uCy~agTvB c[&yS9["@NGǡ]Ν`@l cٕ<N䩯|_p‚6WlbKPX+ S5]ui?ao{9RǩxnoZ]+@ؖ3KG@ѳ}sa4Տǭ;@a\yR=W`a=p {(4ՑƈwEoɸtAST5ۺ\N9./rGb@upP&[teȚ]o*_L~±NNRJ_b>'0O -ut49۾7 Iҭ6> 8@8)0Wn Xc9Bi>*dxj?Dqq7N '2zC~ <<&\jaZ2׆~;VeY=5#{g6:D W9kԅs)(f㒃U&'@7|3w !D * inat2 SVB>hp¹!o2(7ZGy6Htװ]{Ȉ/QxutЊP5\}xݶGk2 v lO¨(>}nZ-K`ui$Hi}JL[scϒOE$S3%95ᢷ[A o]e 1ӌнe>EiQX9"V8-T|opVg/j({mo` Fk{_6Dr8㥿!bZ}}OU&^w M^_EBؒMJuN]k.`rLF(0r`j.6F)~IެZ՗X޷dcVqtA2lȔ*>(`]ic(t &Q؆=f'Á{e)I)<Ƕ[)xa*E7ӂED+ fSQ\n7c[ ?í帜 ~y#˭ǧ.IM"p<[\_Hf#' SW!jAg#9:/Dƛ'9˓K4c8)=RCuD.K^4ȁ9(uWٰ+xX!_,훬4H=-B^V>2.6s~TC,:VbƭK&.N?E΀b/f o3PGdis A{jP"!y`3.EW9neUF:PC7z0ylVf{ʎ]ttfpf֏$b6@>NJx ܰA'/#?S<@E{STc5R"eݑb4o {} MoMCuq[3]a;iFTtn!?i\7,Ŗ}]7um YnKge*`~jfv+S&K@Ujxc[5yr/ݹ}jeBjYc+c_Q8 x8WB]j(Cb Q{bW9kv=:7 ^^fcяSCم~kJJCm@2?c? Gݐpyǻ/4kUQ.cX;#;Nl s?1Di`bb%WjmFP)a KiM)8P0psP;A[W#mu^!e HBdFgҡt$`w2QƔ斊:DUJot]xh d,b[ԫ )_U}.ԣb5F=R?AFuaTJD+zZEsIjrN*Q72~^Zj9)i6^r3[RCn^-^'qy1+*<1Cw:M BA3 7U8l:`*D)U*@P*{TEԆP8[d(* z(qevzi#,-8P|{rl@n"'/.Ț~j{i1Aטvz3%[SŇS6_bwVvk`Jr*akh8ao=tyQ.Y1V:D^wY2\iXAEw}ot7r'懨eR8qV'C|9.{k~mdY28N3ܾraө&ϢSQ]$cStjaL -! t7P~ndqϷFuamH $X,ͪl7Z<}gnX)^P*-|>1nM<?Sm{Mrgg>xiE)+EE'fr31 ҒOxB׹OTseQP+bDsO`nd&*􃳖~iZݸ=OX'ܲ RguѶ ݊svTD\XH|ӟAjܲu""ǀ+?5\oе71"q߼y~bd護&.!8/>1}'iWG.Y$UާبS-{H-{<~yn^55r-Ztr-g 9pv/fLkݳM$}m/T9sYP,=󉷮\<@2lW$MBRr9iˋqŁ2D݆uFrۡUЪ Bx*xK409/`&6`"w#s;Z HH2pʇ?!#td@9k_1J,o4l pY^IoPc~ɟs+vKzՊ,-s{{fv8FRmP M_g[`qZɵW$9BcY kturʗz=V[Q7\ 2P]!&[ܳɟ~`z+^.EPoFC!2DN,xyngYӅR*p .ֈ/os0.f^zm8nչv~9wUEZ]|~FkH\QV\~)N_$s+ 佤ј_iA{$‚g1dh.Vu[El8lJ*&W[HHDn)U)yy45msN0\H2D 51}LLTb]!Rm»QLug]<}S#/@&]̮z"])g8=JYVc zhR^i_WﷆI#UVvh\Fzԕtl:SyԐd4oM OzHRJ!U䱩,*jjչfܼ:Z.>}K/ĭpJ^07070100000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000b00000000TRAILER!!!\֍;D 7K'0.cw7 ć m YZ