sssd-ad-2.9.4-1.el8 >  H  , 0O`dpeQZ U]O@Lj}I0phi`ZeLzjvo@fj9E6QN'o BPٹl&qzO0q&d?$KW"P/[U-ʟ*"[rejI0:E˲UYJA`7$k34pJ5?s_7ES'/|@%(5঒'Q_ _4 McfBn.ۊKYcwniœ-u^/'=1el#a59sk {3d[Q.V+F~0nxʸ~W8,@b|M:bv|H'SN7jH&c#4b--n%:4#J#zL`RPPrJJ,@(Q“80fba9c7a199f0237d16d6cb83cf6a2a51ea31b52618c3323b5f25ca6c3168016fd73b0d439a06294c714cba3e59e0f1b0e9339280302047c435bb500673065023013d4ffcf6156af9e870c94fa7a9a8cbaa94b4439cf22e1a712d14bda12b776088e2665f848b8451872b3e18663cc78b1023100a98ad673841571f1ed96df55ea1e50e078c4f01180a004d8d788d857862eb413726413735866c198a3aa8a6e5de217150302047c435bb500673065023013d4ffcf6156af9e870c94fa7a9a8cbaa94b4439cf22e1a712d14bda12b776088e2665f848b8451872b3e18663cc78b1023100a98ad673841571f1ed96df55ea1e50e078c4f01180a004d8d788d857862eb413726413735866c198a3aa8a6e5de217150302047c435bb500673065023013d4ffcf6156af9e870c94fa7a9a8cbaa94b4439cf22e1a712d14bda12b776088e2665f848b8451872b3e18663cc78b1023100a98ad673841571f1ed96df55ea1e50e078c4f01180a004d8d788d857862eb413726413735866c198a3aa8a6e5de217150302047c435bb50066306402304002245d78604ee65aedc6c9f1ea3d7be2466a1c167d355725a7dfc95de77b7dd4c15d759226fe245a7d4450b1153c2e02301bea8d238ad040967d544984c6e56341fe62de9cad89c73d9472e36164278b35fcf7cc62b57c8f8d531536fae2bfec1b0302047c435bb50067306502310085d6201612bbe5b5e7a2d67ea95134fbda7fe414c0b36e02c71eb8f3fe5fe572a005a637d64db2c6de73e513838a00b30230103a7ae571598779dce1d8c4f04514a3f44073e3ad8aaa4e1f27115a0f19adc1599944ada1c6c82c7c982a4cb98178200302047c435bb500673065023013d4ffcf6156af9e870c94fa7a9a8cbaa94b4439cf22e1a712d14bda12b776088e2665f848b8451872b3e18663cc78b1023100a98ad673841571f1ed96df55ea1e50e078c4f01180a004d8d788d857862eb413726413735866c198a3aa8a6e5de217150302047c435bb50066306402301e1c632c69bc2b3acc8290a4bef5602abfda9a0def7a10712cd98a27ad0a26588b90d5e8ec4139694b816e72688d768402301256a96fbc006757e447f3c1c02daf7da865c47168f75ff2c4a8b66e406772266323bfafcd97cefb75c3ab8b6dfa79810302047c435bb500663064023044880cce4a55ed69410f4315c47b7e83399ac16f753d705babe2cb99ffc6154f580c5bc878b8c1584a86da1b02e705e602306439072c198c10fa35f2ea9cc6daa042df6c355064334ba2e93dbb6b03d7bfb048f569cf19750bc3f6dea8f1a92b04a40302047c435bb500663064023065c6ebd777a00fb0a9376e8a6a61ea292563a964d4073249bb1363fa08247961fddaee990f4921c125e3aa5d2056c36302302632bc482a7f39c3e35bacc38adf8579d07a9a21141c90398320b13786bf536b3b4af3525d2a8f384a35a18875f4d8280302047c435bb500673065023100e3a2bb0b8661f4e380694468a14a6a852140c9cf191a5f705fd23e9ccc8e30c324b80479078cf87a4f0b4e6452f9c729023011d6295fca07f9be426966c80efc5245fb4268b07b9f44faff86d7761d0cc1a3a8de731511fa85a4326478fa830c78df0302047c435bb50066306402305e3b64417267b4854896324cf52c69b6be301320f8fa26f4d44f57b7d6709d8c41dab3494146da47240ff47cddfddad002305c3f93d09b730e7c5804232af66117fbceb84b282fc536b8e9fa98c2806e7894667b4e267af726f819bb74699c0027af@eQZ U]PT2;$UdB hK!,c’+![kлx ,0B%eFتaSWm.=v"Es8ΟX/i33S/Z!R׉~qvh"Rˊ:mo+V0@ĀTM*VY[Eӎltb\sš?;xZcF􉐇R!n/ƱH_iyP s+ūORh.rA%7TŨ}u.SOPYo7_jJ/\4|J 䐲˂V$ c:m|r*, dKJcckb`YS<:խoN+`E?d   2 ,IOX            , c  CC C   ( 8 9:gGD Hp I XY\ ] ^ bdeflt u0 v\w x y0K\`qt|Csssd-ad2.9.41.el8The AD back end of the SSSDProvides the Active Directory back end that the SSSD can utilize to fetch identity data from and authenticate against an Active Directory server.eBppc64le-02.stream.rdu2.redhat.com CentOSCentOSGPLv3+builder@centos.orgApplications/Systemhttps://github.com/SSSD/sssdlinuxppc64le&'D8K:N>oQAA큤e3e3e3eee3e+eeee999cd39a3c238bcf38f2354a2f79e8e56df0585a271c2338d0788de4886f8177cc208a50683ffd2654f8b1b0f40ba009b3e418b8c737708e44baebb1154176898ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90305fe17e80a3d77e671b2392c5305deebf3f88859b494f8c39451065d5d6150fe2ff78fdc5c32896f8681a2ad7d16e721581e2289ce2978ad38a50c5093dd258f26245c7b9735cf7427470e58de26c527c83157f5209ea688c8a0eb0980856fefd97d89b7ad844bc26a4f496ecb1861a49f455fceecee58bfd1d00f7d6671d4e5../../../../usr/libexec/sssd/gpo_child../../../../usr/lib64/sssd/libsss_ad.sorootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.4-1.el8.src.rpmlibsss_ad.so()(64bit)sssd-adsssd-ad(ppc-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @ libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libini_config.so.5()(64bit)libini_config.so.5(INI_CONFIG_1.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.3()(64bit)libndr.so.3(NDR_0.0.1)(64bit)libndr.so.3(NDR_0.0.6)(64bit)libndr.so.3(NDR_1.0.0)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libsasl2.so.3()(64bit)libselinux.so.1()(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsss_cert.so()(64bit)libsss_certmaplibsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.15.0)(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)samba-client-libssssd-commonsssd-common-pacsssd-krb5-common2.9.4-1.el82.9.4-1.el83.0.4-14.6.0-14.0-15.2-14.19.4-2.el82.9.4-1.el82.9.4-1.el82.9.4-1.el8sssd1.10.0-8.beta24.14.3e{@eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.4-1Alexey Tikhonov - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-1680 - auto_private_groups does not create cache in IPA server SSSD cache - Resolves: RHEL-10092 - logfile rotation for sssd_kcm not working properly, sssd_kcm never receives a 'kill -HUP' - Resolves: RHEL-17495 - New sssd.conf seems not to be backwards compatible (wrt SmartCard auth of local users using 'files provider') - Resolves: RHEL-18431 - Excessive logging to sssd_nss and sssd_be in multi-domain AD forest - Resolves: RHEL-5033 - Incorrect IdM product name in man sssd.conf - Resolves: RHEL-15368 - SSSD GPO lacks group resolution on hosts [rhel-8] - Resolves: RHEL-10721 - very bad performance when requesting service tickets - Resolves: RHEL-19011 - Invalid handling groups from child domain - Resolves: RHEL-19949 - latest sssd breaks logging in via XDMCP for LDAP/Kerberos users [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) rusvuk2.9.4-1.el82.9.4-1.el8 .build-idacee5f21b1f13b3fa787748a885b4a9afe7449f58754300b1a4b45da6b9222342bc90cb58d06libsss_ad.sogpo_childsssd-adCOPYINGsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gz/usr/lib//usr/lib/.build-id/61//usr/lib/.build-id/d3//usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ad//usr/share/man/man5//usr/share/man/ru/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mcpu=power8 -mtune=power8 -funwind-tables -fstack-clash-protectioncpioxz2ppc64le-redhat-linux-gnudirectoryELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=d3f58754300b1a4b45da6b9222342bc90cb58d06, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, for GNU/Linux 3.10.0, BuildID[sha1]=61acee5f21b1f13b3fa787748a885b4a9afe7449, strippedASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)66PRRR7R8R RRRRR RR4R.R"RRRRR!R0RRR(R/R RR RR1R RRRR#R5R9RR RRRR&R*RR)R6R3RR+R2R-RR=R R RRR%R4RR+R2RRR RRRR$R!R6R3RR=adclibind-utilssssd-winbind-idmap2.9.4-1.el8utf-8c7ec39b2b3fe29a486eef5637f0d6e86a36584c83c4158371b39b744f92f5d83?7zXZ !#,] b2u jӫ`(y//c:ma̝g-|E6_p:?D\1 B>'f-)?DoHw9'M&O%$N+f}aN >Ƨ솽I0Sm/g}F3Qg=i#F@bxf NS70A#eY7{k)E!HKO6ĆJƙJi u=A 46 Cmշ?p}$L5n\\Yha/I>RLhi103,JBl"wuBiIҿº#7bnLHZ~*J⊢/X[DfY4w';F0zVG5c/|lϬff&6_ lEgP kaq 6  93 H)Xt4{8qY˿1Rp1IaG3Piҁwl%Sٱ sWAM7tʡB\rTbeD,m =ȬpڂeZJ~ʡ>=,6,{88u5N?L!^qk$_!m & {9; EzEa! p(nUz2̊rjP0 u>p(nl+I bC,zyvwC[39Ջ:|۩SxC==>4>- om-% lm6[<3p砶մJRwN~ A(~.ӏ6< gS6E:eA ,\M$Ucě $(ɘ0yjyUb]L Fٷ[彞㭠 Q!ۦvO!|J^s5a'`n7 &_S^-k`#f^zÅ#cX}+=^HĺenzC{EZ/Z΄KrIwed *'3g?= ZNX] o8 :6&E^SE.(5U2Jh1 O!U <~ǃ #Gy]4MƜM9EdUq(D24{(T(۷9֪ϑ$&'nco^_w䫽 Iah;PV^CdU.4M#jB?0Oƫ}"U_ _>'ϭ{S@xr}G+Aǿ>{3O;4ENkw(T{%YV۾g0iPYگ˯n9O;DuکUdYJG` SdfxW1NTqH:r;I0$d[(e(i% ."*x1[UL/ZtBܸ7;7bbᓚB?O:U6?id 8q}/}Hòh$Ȃev s0#Hn&NghUY:[$/">BAzRN~I<*9jpp~F#$kjQdf%Ѕ\ Mm V*.hȁ(4O8Æ*Ā` *o1" k^KC!c+ް̼]nIK9z/=I A' {r;za?bwF_lA@hqOx¯)$xBͫ  ]˔&LESeP9ὰ Ff!Rr]ʹF׷?&V'6p h1=?~b5mL>3va>B32Z^H7}NUrF]D y];.l І@p5J:ǍH0"mKPNR(8FE :d6TfJ?z{UCFT``Ƃ9*F< Is^!ZBr%dYtM^Ls+ %&.H)|5g͇ɇ'; NWluȠx%Y]/6:rPi}˨*1ǁLRb"6N- wDzI,3:c__u*?IH"1odp]6hleDZ]ri~̜י|DljsϔezCd&ԫ2k}Dc0\\QZ5PF;<fϟkaO|+DQk^q*\Q*6sF>D)V9Lj_YH[qTyhH'_/#̿UiՊqK-La lfO* 43EYUFJm(cWduBxunaT&qz`gEc XeJ~ 3=N=͜V2 ]4=O" ʶL3ŧIiMrL@ -&e!VJp2&hFA!O/Xgd"_WBg~S=_SBXðt"9[mJdT`w|vdڨ0.a[um抨j\8Fǀ MJHۓKhϏ.6(0NF۔-)Cm3V3dh y:Ge稿c)`@gn7c3[]'{R#j]O~!FŎx7८[M!@Ij =~jV#jYK=Yq@`0L`s8Kw0g]olE.)q\ڡGbLҵ-#mgv3M1r5=:ʳ\gF9$zJC8\xPӚeEQLuʞOzwI,'um;^on^8K} n^*y졄^)RO aRIZd#L(eŲQ f;w~)>0-.[ó:):WEOh5'Ltv!]a"ħVmɭ 4l*L4#usęn4x݁řc\ Yc6Q4: 2ɢ>jEm<&gFn7&LC#0_afovt͇0MG૱i֠-ve[͎>:zz'Mz*2x7dbP`eT(|1pW1>N^y!1+e-I+-%5\ E&-^ ǻ^X5 LTbo=Z!Sgka/uG] CƗxOPg՚P1լ\[9jl-"s'cPߜ}Tr +/]w-L Ė\wu R?S&߱8dLɇɔGuWobkXU|Z2슴A1PP{!0s93b4XPMj)LA q=wL{;PUpX X3* U9zc$ aonLuA< M\~OY;`RAiJW-neOҷw4s_7cz=!9C~RKs|qC2['uݧ '',ŭc ԝEV r'&Itr)d@FELxE8,Z;R+hteZnmɮJ-xAg8 D\WG9xnj>rd0:pG&K]20ʻhsB>ݱxnivVd O\h(HH.i4QChK7؊hY P0֩x^!첆ߦ<{LƦɄ? ~j)s,^Wg-v09C4ypcfõ^ u@?GR̬$er`e?N>̝V:mSĩ/jDbK/f%ɮ#-f\s+F9y(F;ko1sikuRǢmidϥ]IFXCuљwD[ZHԌ%d( 0D9ѨtVѬ0KѼW5qRInC0"lιn$봠W4~oJL.A E xY%YfIYthLP ˧֦^"WYxʋj\1\'SJԋIx`b2f0R^9@e&(^6"h(rql ,+YXg }sXS̈́ɵ[ NI`mUzHeV@a]z?J(+FVՈ} ir˯M7+\_Ӯ5CgEIRifC@m '&sUD̺4 ٹFaܬT#0Tq@hTKZ~݊3f3 %-|(nP-Vpb,.}FW{bQLLdѱ 5 )W \, ?ZQN! BRy!w["lpF~!~E&F )&W_] A?yWF[o+bґ5AG 9*Ix 52$~<>%$*l d*f 2\(&'$hj&/sO?O-7#W =4 Vs-ަEԐEO#z`0ɆU1nSJW1%(Ib<#o? r+^97dpX-ji؟?=the, SKf!f+O*c9n?U' ֍v!w%t=/oce=ݵ< X: (OL *,lP2Nc@"cf\FIj; ;/v>lњ!ㆎ%?!RnDUY1m QuZ֩*Uy-О Cq21xknhg0fIA:ࠪcGO8'߯0X̃AŹ ZOXcBXKź"  uP!)xGW3םIvk4 %Hp!Hw`/E+({h͌R2Gc}tE|akmijyjȚOZ%'U*xUżi.3/519`yCZ7Tl'ÀqT4waLp9mEAԋ@r.ɫgq`8@4;;?4MԶ<π vz|nޝ,p 0|c?kTInXQe"€CFA<2ugcoKQcӫb/c` 涣pfEf~V ѳfg9a#_v%VUUң'pܨbV00]^Vp夹720Zhe).YlKj./2T᛻)f6G|jx:Mό{+pPJ|j//+roʾ96?pG@E`^RJ7yU d;zPCCcY$=Uҥ1W/ '3/ #d[Vf@B ^hSnaH-ΏkgVQGnlcd.Af |8*3w6W{{TQq> V9z}v e2oX,?rɮ!ML rR'P*G@}fW `ˈ4|X>/)6 κXpc[r.}{ۏhwߌ͹9<" Jg8nGJ̟;27jw@|JaO5~͒t]l`8L+?F\al>Y相ҍy{kd$%mm}Z+xTq. ,MA+#>Iʎ c$<}++7mDJxr&Bh*U<:4(qV9dls)BGO_%V4f.){,AH+memuPâjυZf-2h?}:9Q"}30V{=hXލgn`b ؛ U>}lRz-u &_zJtQMĈ8 ͓zY2}w-oޤVOp$\rE{D*)3JKږZUѽP&K)PI^G^TN.yLjLǪbo|9B4dDui/I;F; -uCq MCj#-Ksc@_9y"=q5w8a݌H^%:}jFᏞaJՌoR;D}#{-M+ъ*i6h#e?9^弊%G4!%\Rf7``jfPy"mI9=Y7$a0Nj wW'x<ƳfuwGJļ[nN/?N{QUkϋ8` (  R*a`%(1hlXQ%i]SN;qJGdzz?)_B E^ Az5PlY##ƃ`!9lō֕[5M *AhCQ7Sӥ8BIU-BPY ]|LK0PmunKA\'U]rCًL,jƀ-# ,76$W|!.% Rw[7t\EfFp1Y]LGW2 w]8s㾫!S)rٙT1lԣ"'1u.OcƋ\!XH$_<)c]} VQ_eβV2& -c8qbdZzU:Rn?fw~ٷK/.a`v6֖Q ֖ZR1a w܀9y2F"<;c$NI6 efRf'Ëd=&gܯ)_V}rǶ(~ $>GصFbXC:i.c nMPiR#WzbiդF#y_Mb6Q/'[i԰ptϖH}e1ou9Spf;b GSSk۟#RZNf7<}F&6ցDSk7y ٕɽoi%<\mz. bNG 8}|sQ-B&kfRt].79-)4v]G[7& I? c;,+>++d[B x ܐJ"'}ŅU.}"k%E*AI#y BGPHr]mX伂p?(rf)jE30-#KҎ7q|q ş9Ľ Nx5'g AÎb Hv<<& x!Kj\sJAW@dMJGܽ̿]GUhRz1-/G~7 h88-kA(?]:b6qKE[Ou8v'E;h+eJTбTJ7GSKLdEyMǐ]E.&tZ&= |/Eֹ0 r+1Ŷn~a2H\Y69R}*-3]BAF}Xc]?,4C܅yd?mjZ"@j7JaU Wz8J CӮdfeZVSb_U.*#9^gcjwa7Ѩo|bozvX[W<ҋiSht ~t#OK_/-[>Ha"Ѵ >2[Iad4[௙XrMD .JAsnU> j&ijC"YU cX ^>*$.~Ew/= %%Ca_/cCP^h=6?Iϸ:?SYP&1n/A}JnҎfbM91A{Dȯ9kGɃԞ^PPv&E ]4PśvT[ yKn~g(M}-vHFXT>| &wmI[+pmc@YsQJ-鎗4Qb)1NT3ӢMo3OB_;,;DkxU yuwBG<m :xixcY E<0ZWB\,ּX%ž`/8^d3~2a "s~K2A1 k78`ԽPO7"0fWwv)5\Fؽ=̬W}WP PV!"3xDlr z,5^\*(Et P3N+bNZŤHaQ2'Ym& N ?.9>~W.xKH n ,?m+$; 4wmݶ?qN.`4 x[*.3luO gll:YbH6po.ֵ`z dwJ/cQ azPio00qe~ueΔed(EC#ğrYEqdd:s;خ<9].R%3,_²dOP[[gh笥%/ g\}m0أX Ț)ۤ^ pS]UvR!2 @f51?EԆ|2A~&QPs:5Vo.#Ԯi[u "6hԆɖm i K۾*j>FL 2'/nZ]|LɆIeZaz3jiG#|y8w oJ_Iwd*-u0 ZnU]+ݺA8龩%X޼%ꥉ N3N[#ib'Իrb@1Ɩn>K@4VUnVgXa 1#A`w"0irܭS/!ߘ󳻚rڔGf{z5/$S5f@jEwc^ePx}H Նv0CY|܆0G}/'Qlw^N]u<661ڷ5Tz޴FiiقxE &ސhΡg_DYǘV\sNrSf c΅_mmVxet[h2(j{z-ߝc|%ȸ׳NnCV>܏mGŁ]WJ[/Жˆpz}iY({"Tqmt62^orT27u \^H5%%dQ܆[2,TD C tbM8NSa-b?cc V#r%}$Qh?yѩ#H̳R(uvÞgG chy$M󑧕쵱+1xtۏ{Bz*SL M;lxÄ Wf/->P^Rܒٹ[kDFT;a H>dl31 ,iK3*>=/y ܆e2u#' 9@:Xc;KR(AAs@ _ӔYq ]qut2hlЪIpTn__ZjɈ'DAY`wvm#S&Q*#ZBfVzdh#7q#$ofZ};e{ޮJVnZ[0L9|dqV i??!4!"71 v x~nu6Aؗ톐(Dľi<2q1aОמaC+!F#u([D /JkjMo;R0^cJgm>4 77(]ꧣJ]%[x ÉVEPdR3ZE*8TaM@tP)5;IzƼM睻ӪߋO޳8Y>yau7}VoQ{*w6YLxL۷J'U3a!vFOr!4(0?ǘ@}A-.ilC)>ˉ< `&=&B x^Dl*I^Cl4qңn#sN; LQʼ)o6~ !F%"&ְs"8Y38=bOv;yXG3صfX5ԻDg,AS-E9 ]n L G=7ϖ a{vzS44V'dUc_F;g6<3oBᗙ;NvM?0?Jp'O|ITfIGfRW'g)69hTa:1ĿTznmvhFf>bu u1as ;$B'}JL?oKΞhHbs g:;k~ 2+nљ\5Q, ֫UwUW|$u`($Wq( 9LݣR4]0q 2ʤiD=wyr῜#F e˨I/;o)rk_(xT{q◾*G> pDlF}=4GZ]2qS8v*Orj-!T◝pE\lnh5[dj_8~RlVi3N(QM&/7?y։#?NUtOElȺ_%ӟ@G2/$D1u$)]-E+M}J^ߑ2xܩ7Wgϧ<(S'C謂\byZWNcdW>8]q"lJ1;a }WVwxsӋb 1,JL]EƤf{Z>4W\OK{xE` LN}?day $OEI'[îԲ௄eˎlisLHE F*i7+!hb]BthlXBޯ,afaL-!`tt 6@DC4d[V) ,a;+uQ+vڲC.E͎aF~< EUI4iߜqe4oItX Mq8g <~^QӠ1+2dz8ɶ*mBHRR1}@M%JxP&aLVxI5[0Ezp:Yb*̀]DD,d[Zn#ri}#ta&=-JW y >% D2xqD$Ps(Tצu:mZg %:053/Me6އngm$~4ˈ2¿2H'*.N2nġh'2)2Mʇ*ɓ/qw_EK|,䶋^%lN..ec~ %cny?f`=z3yysqj- cecJa)_-3_WGtxc@KZvդͿ$ُ펕nt:1CJe-@7ߏ,W^I 1MA(ݴ !<Ğ09J+0Kb*1=M/C;${qɭpyKdMw Ʈk 4D3ߍא F&>M/5jM#հŷBd؞ߤ&: Fٗj(̸J`O\ g ]%.Hw3 k&ԙ3ck zM3;k~)V*e&?﹒`,rhKd?G=fRzGAKm15;3CE`S$Qz.LH(1>Z"5g3X"FzK7ydg,8I(Aqm4F`oZOy~ |S#zK]@$ϭi3AI֛^O=Z@N-`yQ[19dz i}k *NWb]KC:[gYf Rx" `_˱}Jj~)5g s1O؊fsKuЭtQSI]'9NYh)qm*$30}S4 W{q$*bi[4 :dNSFQ},58ja(>Leu\$&8:R>5 ҄J-bXggX[GLBl^ Arو"Bݬ W /`u%%6qRӞ[_Ǩ &躸]R6%e8_Tr|S5lnC ~/Q7[14Pshk8o#UE%1eCkHUDK6ֹIbXqq;&]JǗ;r-ؽR8ypH_=Hs.Œ1g[k =q([n l *ؖts;NL&Βhb0MwDxC>eYXaX? BWR1$O8Ί+QV\\gU$+qϫ xxEJq-~=T0p#U ~;G>g C^r$pF؞]Ebw6󊢘'-6k55[{=VPjPLdj (`$$c7)Q^zECjϷt%@ GRiH^@ BJ. 4:jϡ,Zߋ~"jn6?=,1 Z͉SnP tAB$ Y H3BJE1  xڹ/{ mR٥"!EZ{P$Xݿ`gޓKD{i8'+yJnz5NI3h!-RVGW SC )jT5yQuNh? Z.76pZ_x\$_DoR,#yux|$̪ݩIyo'mp q;vv Us5<,Zԑ ] t}kTxЋnYJDKD;ǔӫoy^ZH Kq—vރυ[,Ъxz}C]㤴"HRV2YG* rw_C^9i"Yd:z *(u3it $zezAT x jEĬ[~Y$2v/)ciG7[6x]}rN2Hlgw\ \|Y݇2ltmVSyjc\{{3r#y#c\gycj V}K.6O~O|)54c= .u3>&#`&=ψ:@lU u⻧cT{oҩ"DkrwPX:#Jڣ]'CsdD89(|_F%`%KTU-.Wl#%sJ~D)1z:hBCKgLg"8<j z =dJ<|Q ߎyZDTQ.ٚ 9 au5N*ͦ<&tV%(*",ʕ2ff&5M0&oqdp=;>i s0)zR"J`dZH;qlx@), >&K Efw_F0B4RE 6V'ZdD|q(Z'nQk@WKJ~] .4[q=^?e!˜[ B|Bӽ?A%LJ-唜9&qN(X\f+ PN=R D0[VCyI_1܃nKqW wQ"5<sy5oB(擌NI)G ) gI2ad*1 ˯ rCx'~K| &bn  gI+uA&h6K"|)*F>\@TL[.jȧ"@|J)o4, V+o@cpz-b#Yw :X)ӓ!_VNCKі5q 8 jlPy_גٟ%>Z񏹢Nd[.F(l-e_Cckܛj\M; enKP@rG\$ ĸ ;mކ=ʌ·ʢ:F=6tb |,+Z:}xJnz:?(M1$ d@P "`<\0x /U odW>{kđNeib7+vImgؠ.}; 3-]/` POdu# Pae A[0~&m(K5>ڨ6\qoz1~BL{mUWkFzBq?ig=7 'oEn?Ne;H*dFJW2ȗERU1Qi+m`y1GܤsƁ sQ;@o(Gw{y/U8Z7,q8z4.O`f;Bk-943k~&,uRqg-Ұ,:EP ># ?Γ۸WE=Z~'_U]ul@ܖV^XK3RвḬ$) rl [,/|/Q753&aI)@ ';jZEYɯJi)ղ&%W[6[?rNML9r^)=0 fnuy^2X-ݢV͑$EC\csO7E'f3voj\@jaYN 9>m:fl uh@=&ڪ2Ar8YV]:hlCr7x,:yf&9{^O#tZ[5%eon?qsYBcӀ =T]󮮙=_[ me{_,$13Űf[I4eK$nz;phev&YzGW$SQC| eEJӡϞgR5fy+@ RMz԰QeV+s$-=|#t=/sy@'ˬ 4yNr#J04E?Ӹ "^Fk^cvX rX+c$21a+tyӐKqg7^sP 4ҟH<%mՒO!Of&,!}ho|v9sɣW .kW&武t= )U'@RI-iM Ųf7'+)}G Zmf$ k5^ [oN\Mq-"7Yuə')$|MN,=@^1tHj0 KVTR@nb2 omb{Tk_J=AG`銥3e]}r nԋP;r9r 58r~oXZ)ZIЭ XA@spvoD']%UhZ7ir4 ,-tl󣘉qSCE:5ԉ3 xGjcd<]G9ؘj/FY0kAwI$'4dIBUY-%z/%R31Pvuv!eto70h>N7-/CV(ÓP^i\m@B:B!0f'[R,lVu* WPgv2l>{s:Nce_!+15>A63*$ִ?7ޱ:]Ш;/ˋpr` w椺]]BQO 4DIcX ҇ZGOlLJ ںmXޜ}$ 'bfSc/ØMpV[xstʱ_bF,7b,1#T'44DASFE緮#㈚[MpXl(,N9s,>cpSpRk]8CpPQ5RgۼA{JFzP->wR#@+TP'8ֹ i;t(LBpW)uèɝc@8/_335/7"o-_VX YÐq,a(nj &sm4Y\cD`g\nqD49R\\a7@8ߦV g:Γ" ,ߵT;PKH R dp{&lzpn>;?AkHV3s:`ջmW'Tᢘ>Cww<հ>ob < Xg;-tϐ-5Brӿ7cLA]WNNNkę4wY/]O,A1*kXK\jh3,*WyP+E>tߍ\*G*mݧ:m)_h`#Ar8^VKA{Xϋ:(I:cit :hé8Fg|%-ҫI +uec'7Qٵcrl$51 In|EĢ;~vĕǣ:R[E6FbmU=)⒜Sbpj׮6~+y,O"̬|٤ypsѧĵ~$LSў(VqjӮ:zΕ:~`%SUL(u$5"C#6\rDxDz" -j5A`,*jm_٧Bld}߫v'L5Ycy/0JSz-6-w; %d!Z1%ReQ=JdP5{JRb+7eߩVӑ1Hz5% *[f:mghu]PM428j3P՘+>? rT _a`}fe:qč:=@Zuܡ|d)-gFx:쟌!!X8%chuqM$ICg WW`8%|MɞgekϊH8()߿Ws_C3kޡ;HW j3zHA" &w<6YutܑE BJsc6d}? %?7tAWNlO,Z7ڄYꌉzFD,*3F Ɠ9V:3Cخ?z҅Ǎ}֟ A]$ =7yF+bAF"x. §/ꄯlG2[p9A$VΓa/]'*tCbV)#'Gt(˂絛O.Rޡ %;T:)XX˷fXNXNYtD*Ɵ! /2]lvWaՀRP"/LF; ;$_a8CCAmEY\J>C5QE!u{v䣲xHC˟TU=x"[͔#%h6E7]re,Eٓ/cU&OY˖7S~&f5#n|B'YAz~v>L{ߗbָb3 i]S4?@VL+Dt-'>>'֦nz]x\zy̋/DBHKL ߧD!7%j%r u2>aBDXvx ZׂPаcɞB;\R}+jU ]jw/$lfj`T/!DLTuAO @ $eT\o5|xNzL +2H(\uaÉ~ T^EzST7om`OpI ]׼ֹNw2T7E[yhWLV9y~#&z|c t(es J$7"m>8Q2ig|ݕJ`1dHtUW"tDLGQ (yqg޺,^Fe<$y2j6߄c~?[?$8ZnksE\kf#: #KRJy|5,6D8]O='1{wIQYWyƚwӼBȵ)8]* 2R@'ZRjDdW1&XU704g#)Th /\#:O3oQq$cDa 0.>BQ4N|E y"6LdCf_6GXM mp 7,W:>@]y=gġ|a$@#ܺ{c,gw `蛌oAlW}Ѭ.ʴyMzq@3ݰ0QşqW k4^]6Ld'>/]lqz4/Ȓ͕mN.o+'ȮX/'"mkN8ӄ 㔂s]ofٖ҅Lj?֙k||{˘M\-W~Q[Wz&yϣ1dwºO0F8CiJUiP#6>_Z%'m:(K HdriѢ>i>i1ЌIm FiVu-/ p95[C@YZ+\ y£E\^t5.N%GɳXUykЎ- ͒ZZ6}ZA G|)* "bՄ8v]":BL5vB`=qk +jY_ da0#c@u#8K$mkrfCS,A֔}:Ie:̾"xqwUcVcGK (_L6= _!VʎRbeQߙy?G5瀮4!g-0lƤs )%tFt#O7g̸gG>ܦ/4X=Ca}YQ1lNCV{!=M]s%*)f"꽌c*@Dd:اQd &EJPO}hA?hOܚ) hHi"=fxel\XI.n?Z8c0UnbS:߷]7'xݑ5:bRX/:1Si}]ND:?\̟#bf KG ߐ|$e}ܭjhˊ*qm ;M8aF}!Tgf퓣Tm&<898li$Sf=f^mWq%gn"٤P3J5EaƸ M34̀CI:rv~e` Kbzʚ-dH+q,f5,rA PwFźN@ٿu/_L$*`3]=POE9)dl.ˊ{P3[ cOWА&P'Eݨip jiy=NA:2/k pnz7]`$r)̦ͧ$M.&nib˜H`eh]rAür,xvBbCW#m[ҍ% hh> y7ż:6 .ͫTèlU9yoȶ7?oۺRi뾖g-iA=#+|?!adr{eC(bYͫw~0P֡ҟ+"4n;qwgPŏT&hoJlmׯohlkztsYy$\*ՐŠPWY9Y/QA qtD"3dg`Abypj<2!&Y4s/Ip!aǦLqk [xˌ *K5Rގ \4W0-ʹuKxb[}ȧDI,ɛ}%L_D .uBpp+EM@NJҜ!GCe=>&̼ލk7Ưb̴H-Lxf'(UӘߍ"]4J-IIJBLy]q6 mc c]+-v]nXT,@97K=tę).?;qtƧkOH v>Yk: W#Q<B"ճӬK%,%H zhR(J`-q1Yʆ `K3e*XǬ~8u_[l9oe|e8kVjs+qVyV4WsIWij|l0J[ u@C~EԮ12QD.n0ٟG)>oVy0:Ǥ"䴂A >!쌬ÒDXKIҷHJ_ؿF= )飃/E ؖTUH ũ3)ZqP0_yocbUdz0o}̂$'Cu olEQ,D1#cu CG8BECOb³j#ALxF[KBI ~fa|y&YPoU/Z@v WbuL1&YtD5@GAHE] Z} #b )a%Ȱn,KTiVƧ1{6>wDcs_L@f.bK[k"*3V881>iv䥈#TEyf YYD2g@GmM&{ܳnIotzsBW&E @M6|?'~ۣf ^t*QJV{t<^$x+EwrF;FDZ҄ޛQv}+6 }6[\:RC}mB6N#ݠdDYoX[h#% N᫗w0eIxGkJ5P[MP$j"4`%?S4$J4L l< T1ێ2X]ڧL!dDuC!{n$B72숄%P2Kr,K$.g/n$(^(nٕD'Y@[L;9{wNK(܈i)^%=ݯңo;QmFG͹wfV3peTܰ19u pr)lXw/5ZX0cvKK+4̯ 'VCkKVVڋ D*hJo.|ޘ a+6J˨Om#cm YU1kA5Ftp]NuS^TU æV2 lvP])=2\U(ݗmH(p< s(e$I-s[eC5l`د*fԛW)PbT e1n@dXLI b871QU)TZywtxC8UI,gn o(Pn=|s?2tK׈ \Glh:*Wi6_KF냟^Qpu$NuH*ܾ0Uv3'?W %2s jd>ֺ&*}''@KMeboӅ+X>}|0ծ6Rltr}i=3;iQ%QhRiN>7Gt D4\.x΍sKF-""'no)Qo Ǫ6V֨ur9](d E{(r{L&VDO!HoQi5S lJ[u%o;Af~Ǝ9W8\A(`O)Ľg8/v[k+eyFfQ!ڈ8sO`9Ts.ޅ˂dܠqdI|l>iR(BV^wo!nO AM| <. +3P|#] Vrm%H >hp+%Q&,V z[WkD~N}?`ja/"GB%2F0pZ;eF"ܧMڗQԁaCe x1bDt*v}!:%΀`p2; )4kSsLmt6Qسn\Ύ IaIxuCo\T v c`V N60z&rp)-Au8]w 0sjQZw0aZh7wmkte'{;kٯ%>, i2AhݤYFDԌ-»ղw`xj:Jp<Q0BѸ"Ҵ߮ 997Qހ&8yȿ8Ǣ'Rt}v-^l;YGc:J\ݑic'E/( rTgOd&.YNwWM[!. IKjhFBv,6Ԧl6DV\e(miOw08fty(ΪSWM09ї~Q"Ya|{Tpn[ = Eؒd.)B(ٽh梺K>ҝg{:쑮lCŔ:2oE!]3JW 'd_kH2+z.oD8 졋%P S/ l| jZqraG^Gi UL[k¬2kwA4rt3{|,Ґ""#X=xVdanyC t7Xb\ {ӨrMm_|218GfϡTB`"-gߑ|&VEJ(e ^ڒ5KzYMqxQӧD?Y oQŗ <IEPZ_M8OSNuV-DТp~A,EЂ'D<`/Ċ(N4T~}qpZ?ŒitРXRk#?kk&Ǿ}=Ugs1Bՙ̥GEyEX`&Az6KklYdYqݭjy-97ʾ>k 50T~)~1ڻF 6G8܄+OK;Qr_{޲j!Ru Dj_*o-_p˅30lj}J]S IR"2q?Z#h.0g Buewx8?Eg- TPwaPVC¸^^fx… )~&ĦmF_][$^4L; כo<H{E6$t+=Nx&+ > alX* p[\^>'ή0dbl_S9.U:WhP&ԕ_j T>sLTq Ŭ^;M>2J rz~d5ʩѥڰI ID_f) 4O~yqa!\O ahnG^% 5WҮd aEjYHvb%ryH8VKE#[‰|7JV4q"zs'sȶc7p.K[O1-vɩR"/GQM}0Iѻ9_}NevNɦ}&zc-l >F3Z}BZ'5 ktֶKdo* *'ބVtЉ--5W6sE͗*#)21ˆ-K+hNC* :7PúbZyrXEsUne[Jo)iυ&>3! ICwpsHiġ%Jf_Z1EjiNHg_O|2x֝+:mO}=bÊ}9!WM|=Wr4j.eh|ReEEwbTȨcCh5 ?QZC&8uÛ6IlH=E+L.EH{ɘrX:X 0$}dSS7{fyC3{Dǔs("#8 @@}v uYd| "r O;h ʴ Mz)7L,@}(:nLBqd1"xoyGSVw/ؗC::X(t=:ȿ9;u?$CQCͫ~M ̧Ə[9/=aX2KÊ*CE$A' +D̄.&^sTwwԽd;V% eTP]SEb` gOҮ8'Y<*v"yYq:^Ez̥wL Glz暥\%7r "`cvGn┮3$(FaĻwj,%4ȽpHn)h00U*yzF/ő{jG_?IyL`oUv s1Akä).Bⲁ4,l:U:DXFVsqzфTQ^M.5LXb 63.nmlݮؔswd=X,N<&ʓLbjUqcSYgQΦ(̢T-n ƪͦ! G!BTkCSE;VpdQ֏AV[Pq]lIJ:0*ftW'KZj3Ǎ$6T( 3Aw K[4&HH֘Y"i2!:|:-os@&]%ΝB-?BLe瘵p~؂9>IebFRN> fxjFBtWέG\4hGh ~Hu6<>20, *G%!Vgzd𰥿Hz!6VtP̫F'b "utWDՃq l2'V/KO(#:Ox:~2%f8R80E9kYC57yXi#!̖_8S A8IПF`%` D!Odj;Hǭ'fЮIK`b6-H\AsC@eaj_Vm'VrƁL'a`GJQH^ʛR~U뺬=2t0f>JX4lK5X4Ì"u%KLj9,P{%5Bjwz 1fxGܪԱ0m̠`T.m*郸3tu6nF S(Hx.W斂;:3P0+Zl+G>D^)cGxh!9<:#7c+̼ųPP/)9Jm! !HbC`8= 7]1cqGD{ÅH@3T2z#91{AOq: r瞹eR0]x wj9MdW&{hnHՑ_i ;7f%hw 6:in{Q|&D, F4f$\ L鵄 UzǺ1f 0FZaJ,Dj8Ij.s$h gֹY G[z07 ok$HK;EI@b1#}_^MMD6?cݨm6`ݼ.Ƚޗu]. `:Ѳ"P*_>35$O/VmIh8Rc.9+kTsጪM\H^ PI6N*cكMx߲9ñA̓ 8^礕Fv3$tgq)8&'JӨ*GAw'2Ӽ {p#KM85=NMb ~Zb*ZwK>K#ƼB6.F~ ;.1v3sr5 "WOȝVէbĂ7Ta2%>O ֧`GR Հn`q^U hZf 'Y!ľ;7L; RdDQé*q oڑ/” b!: !jD+(Q2n# jY͕ rmKctL;)u٫ 'ZTtLR *L2<]&L?6,V_īn+RFT)bALe҇jypY*;/jYFn|Bq :7T+8 (Y5FX1Wީ`=BFJӘν .6¿PtLZz?6q\\1uh*D;\Ri;ҟG:C1.aiL xW0iȒIC 2=o.m;H`7' MraJ8d:F  ^|8SrԌ=  a ȄCC+'EJj^3'kI/ }w V҅zOFo$u=^p=@_ݦ)Puo;PjxXq9J>jƒm_@f_u??p=/S ,1/(<$ZB$Un cb8d-{۽J`9q`EwzF~-@ġ,([̷Ug0U7Yy$͗m#r4|i8T=Qc|Lvj \}1utUҳTȪ7*F7&ŀn]Hjy9Dou6l Ow8Tt╃#˺ĄS)-ڦ >\^>j!GżA[TB}i( zzS؜޸#[XC  HhbHà6Qڶ٘| !g߭r6 ucX+^^zl_G.ǬUNڍ뒬X:XlY9Hِ WNn14:Jhz|B h$ |M]bNdFe7!*lQjRb~P| #1$'ŽyWhb,M v#s ։,6oR[kC)U]oxu$@]gBv&J//I-wZ&m3tvեz6klEȸ u/UWT.J.H6;3PQ%Q*= 6_sQ ɣ^ Rn=%O"a[ѹt,O#,єߦ U(_X{LMw5v#E_êLOzøz#Nۥ~_/a퓶Ȣ9 >(4Ajz{jl%9'smqҒ#'^M>uG2Ɗm>|3LU0t[@vLA61Qnm|qPuݹّ̽\2%@4!sj,'".3C'uƜ3DB{WqYM³Gid₋ *ך;US%\D N@]V B;@)A:KCؿmjLb[QwN bL3ThdA՚׸N|#%A.vQWG[6Xsef=b3~ T!dgwx~?De$84vP{l-PQJTU+T37D~}& V kmBwVvb3 REbሞNu$ vu:cGl\##@WI.Ҝ?pPPKxI6{g<w 9E_נ`^\jCؓ&@\뺭c(Q2]zkuL h4(ʲDS*9o, h+[i:or_ QybrkRg:%R;?uWJɖ4'I他fuog4l+Ƭ H;> J.32 .P)r*rWEIRgN >Ai$&u#%"tCMQmb]6C3.KDyl 8# S u)>S 0v|R*DaMT ŸBưr8&>K%;R{hgňjF)`I@^0$k[%_,X6^c+Ni/jD=t:zQ$5u ,\[pf#i2ٳl{Y/2w68 %lm$JȺ֘]6+QyCj^SHYI! VFp.izǭ9f'[4ΫWk-:r hE+HlHbZ*{4^U IY"kng7ui!#٬w~"pߖ' Onvbri7f4FvZխ݇yZn Nzp+^% !/(fF7hVE^&Ιѭ}[-#f@vplxG#)4RI*j!P-v}q>T ̯ФFiO& )sڇBK.kUE\Ȯ~&-V/vԱ{k]h`3FC?:j@Mׯkb@𺌾? f*OߥnWukk {Y$02]HL k`*T;,`U؁{_E͸js0z~/=A4ѷԿqc iH )a,/7=r[R*xniu XÑK`.bFA~fcp9@ .PM\w|B#2 $?B$Q x"(F<6dh|sV@``}fL?J X{}I.eﱔݛP5{$ChRAu>2јkhNkI+! 2pf^(sR/%G}WHD4Y7V6.W|,J%?5EBA" $GeH>̀Mx9d_rI]Կ[uu\l0M<;ezX=ӳc ׋u-j3ͪ<+mۗUG;o㕟 >[LH`N Dx3Q j|+ X16ɦ9 2 P4U(K,,RZz׬ˠf! %dk!Ō%JpIgwϪ993lt>8)DxH>":E {ulH&cvUVUu"E*E}VK)>?_יi+Ru+`К#$6D=~;tٷ 8F 篍o^^%R*<ߖ ϧ7$08O\UD"c)#k3#Ѩ -Uu(8m#(''Q95"<Ɋg÷// 49z⥕ü;t1,eH˺ I9ƒ'^Н>Rzỳ)"6 id< Xix !#!gt*?stadm5mLEpXzyMsQIjcGCR"Exޞ}6wwH 2'4C/]ZGg:L>v XT0"4΂N`)9?-.cߔ&sp7ɾj>m?ΌC7*EC wxXMg5qoc]5HPBبFVvfvlFOhQfc8o362|e!ڗ_㠳Vڒ=Jϥ9''j.*-!nE066J-'g*ԁC>Q{nҺ.LE).0Qszs;Nb< &艪U2j;3+bF:L,jR4Q ,yNev)o`ۚ:m籍39OK X0PU>4!@u%NꐪP_'8@|mǶ.*lŜEө7=YZ-0soV;RsBD*J4:C؅ߑ>\{PF+ki,E?}ikEBjVlQWOii'r?׈l@Hv&RF@jvS%mM.=7*o\ Qt[cʏ )imc}y] e!y|Ј(pƌ1XVZOi]k0Ftp~ 2=e"/^+볶:tJt.5<2$ CZ$دe[~FYN0FE^≡ AX CV6}އowS;87eynhb> CMU`eNo B蓱cu ms,]_&mϺ)Z/63w9֤5*։c5W"lC!rvZ_|يݶGNyPqr/oJXUCCXCZҨҩX*%9礂bp Mh+N{^{}mw @)?귭AuRy} _-mo)XZ)OgMapza5?N}mq1=|ر3fy`t<]dyw<nk US{<"D{S' R `PDd"8\ƞ "CZ-B<;?zCiP+3>{ܩ01Gh֋A OhF؎)b繣ӛ_{f7wū[j_խ reLzͷ;<Ԑeo9{5XqMs`r8a 2w)X"馌?B+Ƞ}[#9?v>Qvr(E }:o)I!(vK)"3:|ilC<Rz Ynd*uu`kq6՝f{ҹ7kf.NQlOhW$'*֕Fgb s}"zr+pbz5 XxL {Q"t'esPAw[tkcCfu`JxIIb(lཷJrNQ%6y)9KO69>gdɻ(@O>V)+W W1iTLr_^jro'{,@ px_EE»Q 0 ʁn-6Mo /;q!]YԗimB$< U_/]w(j W+DǘEjEZh8B%¶,ni*.C *c .}sdAߴCq2N cAW?D8Nvr 6x)0}V8ޔ`]\' G(2 6 , J{#~xdKe(B$lZ𥥷;;KWX9؞_^ PW=Dߌ[WFMI Y;J@е.2[zke G)cJd&֫1(CyNZc+HFAGVp/DO'5 Jޤ?> 9=;vq_ }~̭P?F61l=e'͹_p0BE]^{LI%#+X_ ؕSK65)M g0&ʺ=ҋ4+XE͜^7;QgRyf/F[xw>N)_zѕaiGRpadb8چ)@ƫMMn޷ ⌙E ap?z FZ}^: 9yTû1b漢ʘc- *x\7Pu֖kKqa, Ѻ2DEA'7bq4NB~_~] 6HQ6&g=ޚ,ZN-9ʡxygOѰ@5fׄZb x_#QizmG-BQ%e(y4)Mϳq2|}9J:bEM^~i2XF8prXYC:j\H!̓HQx)~t^óucsAV)uI\EIq!ǰ w2v}=[ 0y&T5CK!IIsFNmOJ1va/Pbo68">ʍ/Բpw}Ȁ؁uVSAg\^jfMۋ~rOtF`A9F5HtḯodYVdQ-jSyiA-~>~Bi@;+6<#a?#FF3XYLSom+@Gں(PbeJ޷]}8PpBR+q>U4s1tM Le bHۍKOzV@uS*M7ib. [wA+P:򢠾"~,V{fi+ݧ%X y:tXEJZ?äqxbwV,d1Z/vZf:x_N/%jG͉ofATtMWef3[סa"zuRƶ YnQ,X7%ت2j|AD;$vs>tjSQJh憙njBD(w~(%s( HR݉Y"ɖuuMs0{OP0*@{Dej/?.umȞI=&aluP̟r#i/H,A"h19P p ~(C^MŐ2.a+}o3xkjGWm}Il 4Ec>d֦vqaZJ`}[Տ #]~ ?3btrQUxuuQF|G=!#[S1`?pNȝ2'kdE)x~>wW Q.?w3o@w2 y-0 i$zVX¯% wVrI#EU#4b ׻`F $E3'zAm&[HnN YA|DF̈́EyW|`Wh߿R쎀sm'}+hˎ4IA4(7]:a2΅&!f1=:Shh.WU,ied( @7Gd&D %E(gM RsGƽNqG#RjuO{06#dbڰ uf&P0R-˕`ze{$%~PސKWc~lŒ>K8E"xzg`J!MEಟF*!)I#+xgLu86+y%eVKH،o|7"v#ԇl%A~u5<=޴D-|wHU0@K0]̓ teyr8CC!._nk*ڪŕ2\r/s @Zڮo2_-޷][y]'[̠ V;9"ڏT,~A,rn垄hmJOivS9e|XTdw@׃r0B> eAՊ*Owwyd>s2n+e711xgn.=s*>x;D v{Ƹ%Ci)[U:pu7G}:sJvݞ0uYz?0uTDs<[K@R_ܷ]c1y(Y:^aJzHo*vNFopa-^).F~A(3Xa.>"J,u—R8֬7pb;o#vmIJ"(m*b4r)/u'80=&! ZDd'u@b{13(Kf@61dHʉg 8,uAaxrQil1.1Jǟ}sXX)ׅG${4hnCctINNC'=JmSYRZpnʽ@(vA@6Dbi\Jq%)USF&!vp=@DiC oW=6^NĐ bUhƪ N. R;ƅJgn t.&sz'UeLj 2N0.j+*qNO"e;=":/B*Y#f`&'fX q\<ƚ"}cVɬtXv)xlTwXP? BsϺwYws] dދT14(x׼tk8kM4ovڗHqS bq|- DFi/o |fYK"?l@`'Zb$*.@S3wҮɛb;7+!5m-$bt4 W6 )\׸>rArW 1xndvqjRة ٢xk"FU¯j AkL9b چ@~гdY"K<-7-:~'K .w52k[N3 Ȣ1ʘ x6ds(Ջ Pư4C_sDiU< 4_Z(HzQl#9z58NJ**`wγ5]3"Sb|fP@щM&h}w(#uJ0?_譁 $9s}BT|xtNCa#9VЪ!,IȈ[rVk*zRy$~H$1IGJ# c:G"x!ƭ6tPA,@с$Љ*b J 5zm4xR8V U1zy2z|yt<^]QEEoܳ}uHP{;!KA߆ EH?xj~H UU o4O~&ȡ=%,T+]ޕk/whM= ]_ 3qx;/"7\KdD#q5/ jG*Xն_Ew=Ce5{cvb ?_/*F)viŷ6ÙEStj c4.h !a f^CUl?p5(~H׭wy]UJ0Dbv6n$l3L5; {MCI NJCQk"fKWf黶\M+J88uk?x}npU`%\Ƃϯc=ˑ%8z?u IIzE7fML?L]4XLw P- kfG@Cszd$j:ә\#%|E;y$2wV9 GePͬq2w"iP5ej=TO ׈ԏ(}G>U:PllHf(l-̱6c Q=rW)ġvᨃ!I'ÆsSJ孪ӆ$>&k֡ w L6s]E~b4OДɎdSJ1t{'^ƲW|hyK#2QBV5+^wWڂh0W.UdIsnoc|*HhH/mщ[a'W1:'ȾgQ6o;$cg׈DEtJƨb>kV\{A_hP2 jhѢz\Fq3ǁ >d [5ۆuKJZg4ȧA[xm4ВK4<X9?@\!!SeܐPh ȊFy7x&ޭcnK8ߛJ]THr4"T1IDN1pͿV+ݻOkg#y[^K^PDG&4&BAPЎrm\_GlZ 5,tD3#۝,xo\0f7R1X@D~&P:Q<*٩SHN>k[O"] e7DV&DB [^bOI鱶Uz%{KZޣ?5ϰu I>*ި`E1AƖw@1.%Ŋ!l6P@,rtLt+psu7RT8aGTNE57|O; TI9 , CB%F-d$T.p`zFlDv .1YS?IɀQo!kl݁NH|tay%,|D$ڄ0訪E zߖ&ྪvR(1 |ـA^Ź`=Sń}yT% `veMg!$p濷O'lA3Gř?Hpv,hC,F# [,Ro.NTVR.>^盧{AGZ`AU~Hd>$,sV 䭛x&gG'^L&IϜ6UiKŢʨ6(ǥCgI'buCM^S >!䋓hHoJ4ňc)ZhY}o+ii)*VLA%o /7vi-WѶX3u~*0Kܞkbr]L&Râ%C5nU3ƿp|T&ᣑA^Uz)8`ԗ*}b+xX*X6=HziQè(TU=4Td /(k(*5;!oP7=STwA%k8;k1.ŔB,ofq>=jWrAN&7ȍs$,ݹzJy8evO(oxM:&wk*s| HZ! ǾFa"z͒d)_E,;QE!pB__BHmqiAL-(jU* UF|dRA_ ɽMR穜?v/YLV5}q K'ϢOȈ8q2U9FdӦ4O;UɳvѰ='%{: ) P:)3+;=.%$s1^drCRؑvK4eQ[oha.-Z&܇,;UOlp*w±! 5qjl%zq`ؓ0_YFUDxRoJZT<7=SB0g%6:.oBgVVʷ('?{ܵ(S7e|kY5vkʳ*LKfEG jW cwO"/2ߚ.9J1*eLP$j3>bvL/OKY .*D,H"H?a$sTȳ,އM׬6`Z+ota9qLT <ԖnSR6bڈ#gokopr)3N5?ղ않N'nl5U7RTy7>t:KF܏hd}>`ԕG p1C;w FMfX[h`t6̟eҫ2 0c^J mTvM~X,dyUrGw:y{I|=[_}F(PVm&:lZW3qgJn#O'ɵqWl0ȞŢpCO){wY+K:,Y)q@=WVpĨ֛XEpBuS x^]{cy׆c~TP_+`Y%/voTH@յERx4Sŕ}1V@5)RXg[ '̯jk`xաλiLO{z[ E١rvୄEZ=NYv N# ia$*^FdYsp)۾ 8"Cuִkݵq>Yоk'*Յ*$ӖD6Aw~z%@Nnh; ܃+:@F50Չ 0#rDZ:k"H3)ҭ6+ ~  9a|XKoejT%O`4^7\^M:xHdt4r4UE)]3=/eBbSuP yr }sR34C/4!Ӣc_-xfm>_B.I^Ayy_?9#_ƫ AeM6)#4}`.E h=LD^$KvCU}Wsb5=*+v(N͗̋,,XW.)f{Ai)M g߁p1 h/[X0OK*p]K;{(E6:RӤ+|.dk:] 3< !"Bœ]C'X2GKӆ!猝F2f lLb\^ASZQ̳Jĸ6'eV3RQF/:€(vëVyk [@r2 )GYŖU[?ŵos4p#5e:$Yle81z&bH0'_/?G,(3).A.Q\H;#Ł|"%d:"V>vCTX)X/ٓo6!~ۡzH_˧W5:.Ӎ_VL6Dxa"umӣEt. r`}NLsǼaHgzg]Kmh 50.VoRprKoFTU]o{ھu=> ;SF K¼ 0j+y !V1K‡|@o{jiHi5$'Z7De'm3Um<"AY*d'WB:?Cۄ;=_ ]0_GFt'2gNƒpW~Au7`"g{.Π]d| Yޚ]+bkM|D]!C (]y[)%]b*.gXq5n˿@ ($':2ݝ ]ة&F2_)_bxzR y/^8s>PnJtf둥i6nl)68E8iP, 4,aITƨ(wKqn m=LNryvTHMpe,l͉ưӤ2Hp쇷:'pʬ0\<ɲIR阼:TyUB◚r8 C C>JVP7 ꨲ9!aLncf߀C Y,~-MYkuÌ=J WPfAgC*L7]rqH%O w N!N|ieR 5dұNZ`\)ޭ&7IIPgoR:7ӣɴp[ADUpJԄÒ*wd\,#ύ!z!O_elp3;eWdBT)j=/7+˖dkykF *ߖp`}@! ";/1u ך}@T3|;o@kSˍ-8f:w4egU^עv0IV8>xUeUlp$R|rMF Od'`gs,*WB.p[~]t 4$K23TIiZƩQLym=lR" \ruVy}rl1ȃXН8Bќ\8"5 DL8K #'2n5h*!( 2c>?u)kC݇2[8VLj2?8}qcl4v-Q^3ΈLo<\FO:Soy=c8-[Pj:Magi{vVk#wNJز<StGIطQȴx"~-fp:jgwwa&M?wHݪ w^T-:7ewMAEn>[]/9YRnB@|] -3Lv<i '3[-BKI6N'/߸!N2R!?U`Xp?unZGY-U7E+gG}3<^BشU]iVy_Qm!Ty bͶiΤc*Vg1`%aؗV˿M) Mcn#uHNҾDB.XSy"d!NC$;WN^76FN-Qʱ،U+.jv=[NPgYj G^h$ݢa o <=Cv ^f2.$,c85pwQ.A샭(`Ś56" Yi:.d|:x߽m`J%NB;{q)mwzr{ Za?p`]2ԃ:V.BU?rݡSi{pzpm30AX2s?i\4w)Q^0Ogؿ6p-f/kʼTmTpHn qTS37P( RP`I@(.z΅ ǜ5{Z4a( \4ȰhW^(@d:7:PviY*?q_Uol]͍L'jF>خ@ wSeVBo ]Z+K7eY&ktcKI˧\=OD7O*04ˢҿg#N>ܶnh,MӨRQÉBmsɡEUnM|ŔW(lT 9@mZ])zNs,P Ex(/V6Zw#V6. q"QsRXCc fxi6zB!{:%@pWӏtAu9Acdޅϋ`@QKqŖg쬀v "+p GJ6a նVLJݿ}.I?]M~/AuSx[)ms"ݸS!cBqU+{},3o&b~q @F(%qoA(9xAU էc.ҏ6J7gH F8"&A^ٸP]pӐdE&gB'*2R־I3\Cm) 7ʥO/URuW2P{˜+p$,p/5[n|(:FRD ӌ/DƅX\ Y\M mQ\A(h,i,~2I{tD`)NGפsj|.||Wۙ,Vi ŢC?RF`G~Zs YP=2㿖7{,\>߇Z_vBpuS;J?$=2w&1!o3!@3?AʥaUõ1Yلϼ4v.=~8\DbTEӃa?Py{>n\,yجyϮ*o`Lmӕ X<[6$=#EZTgWsR"uBZ r4e=*Q} &" 菓Ry>~7GaNH,oF$SP! 5{^jYf`*N hcfkphIt⛣dj|6 ֜&ƗOK'R\.5JN3Brw@7S-3LzP׃\5}cVl??)s#f[L}xNuHrp؏+ޯId@IONtDV7Q14as" brg1Djhs M!]ֳBVYUz~3#m y9P s\e>9%Y`~A^e;7,@`L~Ӎũ8uES m(ûqi =Wr=!SGS }3BJj_V7Ú'=)dxe #aU^ c7"(w67EomZ{ s$E0)`L Ѳ~T?>7XDfҸgFs.#(t(7N[DlBط1*N#婫+KN%W̑qXeP]nMVr~b* Ʊʊ6MN%55Y5Co@gΕ_ɚ3u:lD "Wǩ[ej!_%҈ijZKK̆KϠ LV 8ܓ/U&c(IwJ%vCr%GGtDj)*sNzQ+gԶQߘZ7ґ)w!uA+ [޷H\ d>ޗfu&;0H҄dyj6 އ;3^_Hk^G7(0/5Ny"S7}/:<[ I5bwX-pe ~& շmܸʞ |TFR`4Wodwz@#v=O6<9EMє.M+qdicǭJ?"4K*Z{n1i^dз9*S!ixkTy<q}̦}}_a+E=2n! N ǞT dQJQܴ 1R6r\É_Zv񻻚^T: >E̮Pjbbkl1;;2Mٞ Y(R]%@)\E$+ϖA,3,_1Lo;^ci?: EEm2^i!&hd?Q\GivPnhq\7Ss=;kDA|wISMy(ؼ>A@~rjiB[~:ⵠ'GCNK h5@p&Uc \F`Oepѧgf6%z,[-pK[ Nf-lSsm"uK̠a)pKYv+~0AI͡@̀֡@;Czd=2&#NKw%;߃-M@m_0B?2xv>'Ƴ]2;CN:O P!~r}F6EY[e#7}޻nØ`xq;U| *d/W)1YDeOkKӮ/2fRq]eZ0@NIԩW8Z=A7BG}]'o󣓓?j2;LaHHEj0Oѹ̺.̲6R%VlsPh_zv-/"j6Q^˷pO [3̖N9DjnH܃>{)c0d&&י~ cט·> ƪ57ks7^2+2Q.D1Ah bE^A4K ];w6f!Kq*E Xy/gw7m߄Gl00 o;g^fte ,??Qɛ{򯂯ƟyBZu+m#RԽaȼ $WQ.ǴL03;n5))|Y3o~1 =R"YpF8`d/kK2V{@.LS(-EFRan߆Q{DOiy3_BdJ`w !$)['EUHi3Y5g *<^LphEB^ ԐCsi2  c*ɺyn.?H_Q]G" Un8Ԩ:"T8fRHGQI䵷l\j\Tv)>K@C9jBԌ)-D&(͎?R̐Mn+afs#gS_A@̯/OR6^)ln-ږȻh{q5~9% oCUҬ*t4D(#KKK`f^'`+x|#OM{fYduV&Oplq2pPL(CzRzNSe@B-"s6}S )%{[! 3箜TlK|k>ι) qԜdKW4$LP jժ1T }xu8-EH i5y5_7㊪\ZH:n8btN#; ӛeW/Ї&oԻ+xȰցn5/<8vZЙ*\;X휤) h}=d=f{r\t `-IGEi4OLcF*ؚsp * 'GaQh)vd\Jק0V|)OqWͅ[Zo4Dh*A/?#dRK 4J`"#;k{BK ua&ش:Vgi/4QMϳ%A(]Ҧ ^r1>ۋQ+8`'SH<|ɁUj3<`QKdZX'CS61fue]33=ŒF'|FVbWۛGx.1J5*gSRn"ID(r HP5P3`'(5 ^I&wIKwo}?鄟3RHG\$88\(FϨ2BtP.YC$3{tȅ#> Vs!Y@V V3vu]dsoa&Q2+@6;$Ѳ_}_O%rshEL8i?4rj9, +/xl0^(QvJՐ6qjl$]5^*ar _<:IL|-EBTp+dWݪr J]9;u_F箷 ΜnvmF/Už9' ߀Fr~+EXcQ#HE}Mn|ڎ^ Ȉ2E;^P^zŷ!m}{'Kqwd%r7ΩJ.w0 c[VA#jiwPVnq HȻufQb>w_[ڎc.Z(OλjXcyղ͕, ^$^P&eA=m"PjoK1ֵPfZƯlgQʮ3&%A١} ICYypNUQJص) QME[/i;5~ S]D7d6{QdEFP,߱S[L&jRK3E3[/ pUxO㰽 L q* (eBwļ _;R5p夅N/]ZջSm(!'ㄿ+n2X]܃B2`u_u~`kMQ.솋ܚ6ʛWDhN[o54nRFꝊULAMBu4:0R%ݡ[ QKV1 zanlhߚuS5뱙?4lFDu[1ALF)WA[ 0E{Ōf?VYD~dsFqA;V8sX ޡq=kw;Cml1;Y>(.Tu:̞kE$GѼ춁C&ODՄgdX6OTG^Ld|f=hRug6+@zR;>3긯ۋV@GֶC"ܵIiky8sF`dU(R]e:෋Dtk&Fc3Wd[)>3m]T *en>֠ιRcQ[4C9/q Q~MEJO@NxͿ'98:{X-p/o˔u;ʝm䂖K`>1SLAʑ6SYVr=15ni&<-;N^u)~n(~DwcAhD7S{04"7u׏=gԪul0ipBz]*w6ո APZ}{8RC5(X)_4Y5Ldh;Y**m*cvVtI7/Kf ,k-沝ĵG@v~ |ĈAgqRjhc&N^ES{N ͒ww ~,dW^ja)K?|k,J0zGݕK<$-: BA\8Ka.-k3')И@צGxzW4t& ^CwO y?9 M& ˟HqC4lN`BJ7*my!r^Sb8'.ČW2:3B]0P̂DD7[>#Nco7sSQ#(@lȱTxr?Ĝ8y'լv> t^C8.f\l#S*~yQ<R #4w/0NeWi};,M͐|k+:Q}uCδx)0$ kP˵!cVfW~v#]7=D3𘷔dxpnㅦy%o0aRC[P"wX5Հ K_0j[D'"rʾQԭYWn,OLj09j %a*q8(ƙ "o !4Ia$ަۮɮl!]S & cf1sDI6/pb8`[f$\\*?uS=Y?l sv|7hř[F"P(Z 1y-j.]4&9 nFz]4Iͅ]H'%RԢ@F;d`>?]ցXY1vhv`;YE ?%co1 xhu7pikRю-]"XsLÃVL'n$Olū`ʒ!yXݖ]rٳ4⊺)0i+xCa%E VP7݆s#10N&`=6`}ʸ_5h !Wr} J>ş T{.V>뇻xJ:=;ޗ"-l)H_8ҰIo>FfJ,|O{ځoz4N‰J48?ybi0uߧ^m"z5Ng!@$RS> Vߒ'3nM,a#f*@ddcV#^fYtx;fJ,]5_jtZFBWȾDt䫗:kNW+y/-d3{@;Hmx^$TD,uGrϋ[X%"eq~rEJ[ɜnÈ^a\$H'K8{ *Z~JXw-8^[|Yd q6[*C-\NV :,\6^~k“d@dWʏ8庆A' ʮŏLGNOX2)o\F֥p͡y!Hȕ FKg Zvt'pe(`T +I[.d53th%L2PrEB*Gy:=+VQ̇:IQ2z-Qf(o\Xc XB9ܨ3Φ}&neAMj?Ӥ'>BĈ3d5 .p˗yO@#1aZEH׾uQ$= Oҷ)ЫLlyAqAt˜:Hy $b!F :g"Q 1ƅ AMޅB:UfBְi]_#3W3ksSW wrv46BNh4Ie_n`3& w< ͫw4XS~`˶?O4w Pjzt -X^ ˜ 7)ooo`1v9㻛>+^A5SܮL?g^ H,QB1-;@"Sc%WyJrAVRSbF1`ٴ/ Eqy]pab;}Q5jD9B(ބIwp2w!YYiRjC sњ6 @> %LdB+lEO_ph̓e$dKS#z6w@M@$(1IoIl?N\G[ E^cvqXz*A/Rߞ'/u(s±ǢȂ0 {L߂~.wm;VwOG37KRԈ+{fڿo+d 9ă_nRZ|  WN`LW%CatxI_}.RBD6=WiЯ?#.8V.D[;'wM{3u$6TYA;˹(&{Wo9<5I+'XT7\TO0yquFz|$[@De֞A)"a du1)V5(8=n͑0AT JKDvmAXtu$[CmsW@Gp]$$-лwV[1!VqY$A.,lh\"v[Л={,/Jfe{Ǥbo1#6 , l4)q) {;8܀g^udCd_AX@*טEuMn#wh&CN`9oi9w^A%.۸Q2 /,&JH~96x~*o7Q b/ܫފg/D͆GaXxZ_ l:E]KO lVOA sct=6Nȁ//FW'i/U{F XylV} 3G2ťػcg 9)c}Z_]Zʷɳq\;_v 48Lϫ>d$(U•{UrKo4/{cNJ$3Ca~g.U?B-?% ߻|[G \OIGRIu\e+x%X 'ro^ɘ5Pq0 9] q a'€BVG'%vsL+Kؒ% Q!9Kp3UT5˙کEʭDj>mo& %攷CA_P1m_ BGOWάK:kuULU1/yƏ4:f;`iFEnG)x\%D@W -y]tIװ v Mإ5iVQ^#%PoDJ!F*,GџTݗa¢|vdn$]#cĂj3#Zqqm{+A95!J5qhdޙ66[w!ٲ땕ޑuO2y/R2WstX)sǸ:4}6:0֞J;lYBI'F|wSrIu5tAAG`"0vq5M>s*+[ND".BDq7 tl٩a9s4TR֒q@i4KeMA3%QW4E~bǪbLސ;a) !&Ĩ O @#;chhMVϹK4 "A J\|X`h[y׮il$_S9ݾirLy8n[U#aeDH-yFnk afr-נgD;J٧M5 Sk3e$F05`\'?xP+apH&ג6Lʧm%򅊈Gx3Ñrs`6C=1v77Fy/ŅJ4贇֊\E.j*zIu-W~|Ailw!3h7 dHIdy(Dȼ,X#!ư1k"(1y²-<2Z+ Vo*p7BT{ۚ&A Tœ|(~ K .I\0d^ʟJ\Uq-||iBcEy.Vs=v a* 6i |]M%,'̎7E:\o(>x-M `Y8k4̪&j ؁MķMEGx!wZ~+%2C#q\ye}.7voO8.zC&孴~~9Ku#S Q=8wis4$%d(PS+M-4b*+\](yq#w^Ar˟U,k΋ѻo5 U2f2WgW=^F,;HW"o- ]m;F{q0uSB4_@inYYR/D גy!I۶~+h8i ,tgCܨ`ve6{Q$!my+%ՒhD3=V<.j\a'ݧ5,_^D"IEhҔ<0o0 *.vT8TN ˒kLH/|P Pf\*$Ve6A*`bD=Yf=$D?/moc%yv_H'\3Rb$+~y.@‘Z) 8p#4Ə /sGڨ%ԝw/^J6AA9Pn98aMqCTУ+!/[ߑ6/[w Kh D:翵W9sm'[z6#WgK+,WԍA+T[BLT`eŴ>b!#$tU /u g>4!!j)]]BUk<uDcmpqX!q1Y]:kBdRS{v4s^Mb7oEH`!/D1 /;©3/ Ѱ}?ݏHeDH^ +4{u؛]l +Ů3\ؚ@{~ i NK~B /?r$Luȅ/4W?e/{Ŝkx8xU+VH 08{@9 δJ0ZfhW* cGLcJhhIzMGGex1!Gፗ07Q8NYӪVװ:#2 ?|`6Mzk4?obުݯLjIH"~@)ȅ <cC Q^[YgF`UkL'Xԝͥ{* 4*fX2i |1?H퉨}2B:cE*MƑNhQwd)pXjny4RKj͙-{^%*DH"IJOj&]s;EW± +26?s\^N*8C'| -Wv&0 V~Vq# 㐯bd[`J3Fm=]x^ M Z][ <}{ L bOtXL V5ΗHdWJ}IN 5>@"z0?ȳk"roVD [cnro±ÍsJg}# nT (Elj#iڈdT`xA®ԤZ؇PXdmj;$& y#l_Xj_.,{UiJ^ }ƙ ]$N+xF+A{vb=*d \AD_н_"Pr>A"{X@Ӳ9w,聬R-DBR6R[\Of9S(Ep[;_pފ(qM2gtg26k̤#:K 8#,T] 慚ͤf DϳCIY52(M+,i8;tg圀(z'(;{)$Xn:Ԍēx'Ãq`{j}˨o?qnM"J6%.FU9#(SWkD+7`U+Jhn=j e.pLNa+6ymd<=7H$ǰAK@+8)ɤv@';%Gix$gWF9\.N3olBQ2㑗Tٳ|L@'_ э|(Zv:s RhC&Ӎ-M ih |MkU׈"sb6G7H_FjNp O?q)0%xs~f({VyLEG:2>!Mjt1VIt2`E׳= MONL>;t~ZJ_y2 w߁\AsZlՑ ! c/waӭ=18-W ^d.3W>wڍ g>?$9@.VCή,n=_UgNA]ozc A,F7*Lƺ0VhC+i7wt)w p$tY0j:x DMju6kBNH5Bd]c(l0c?XoİnOU_+tOcaD[F铙fUg'@LF4`+\R4 -h1bx91bWU؞jW-Scz+uZ0+j"n@o:PVl'*EX+(ʙƄZ++fi moRcj1~OdY"5/,! )hI>GEFHgUK oh ~6z HeX>ts֊⋧lW+"-[rMG*Z[R]6W*+c6O?09ªZJՔk !gT_mij\LM#PK?Hcyު|kVC:Eq沶]y4xoMƬnկd߼-3=YilC$ jCAU+EcL83'&Ȳtn( 4Yy^rmLi"C.Qo}F;eCc^aˠ9ErqTvR'EZȳT[)N9)5p*Isi~@bن3< G+PLX}h6Mg*#;+c<§暷Fz[i'w"cǔbϒ5v٠.fzjJ=&xPRYLWX2xXd¦F Z.Bs0Tu1pW[х?.t,$e/wCldcM 焆+B+CAFͤXMd'duׁb6|O~r/Z*!ZemхsQ!m}ᭀnPUй;jD2Iܬvi., -iI5$z!-lWZT6p`O4#sgJ p27|v.:?‰U D2'{j]4E騗&1?3~L9NRƃϼ1-G"~2L={Ӡr޹@ iք(Ko'rLE v OV\BcNqu,L*s'!MACje$MIdx's#<ՒzxR$ +K}=X^o￙&1}5RvJ?XΙkяULj@x%j/٬I1Y5!耆E/!.'0(AtŤ3̇Ƅ$&R!qo9SnlşV6D ?%zn )E|U##/MM7 & x]{WŃx.K6Ytn[=)-d3u1l YՠπXCB^ReC_jLAT*r絘hX(Z1gg ]F}e ƌŶa蜐Fk\OYgɏ %W9s"7AAT~%rw'd qic?^2궳t~ӟJ)Ч{=\օR8r(\N[o{V41d` Lס.I4tn̉YcγQP'LVLOXxȥdC= gFHkN5l^k:Z_P@O1UA3F\`b@戗݈/;ynR&[\ۂG7ӹi9~ O\]+9HSٯ'=oaFkنT7iІ8nA~O7PK:ΞkF(/*.w˨R ~ bVC/ۑj}aV2&飀uI bfr7UIF; A 0"(5k\$-!L4z R~^Ǝn[yG -{m.ܼ>[b@(xK}.?O~KԬbP ,), sĞ_ß?z:vZ?uJҽhip RYQy/AYpe(lVUU+ɂ\=Q7pe_pN?2@Od˩V*d]J:'CN#u#.1لn)돎rv` dwUoMmPf q Zk2lbBSiXIg_kp"\f,vP.96xV|xu';^BP8;Rs|D.?HNFC/y|G>l4oE`}iv|":6GI:72RdyX*48^Nt7k}iFFꐼ!k#Z\ͳ[.7zE | '_NٍMIkD&[gXْim.Y&&MgpO%E#.oBB Ξ [+ԧW8ِX9Py/DSiBP3x ' 0 e tLX&b NJ*'Fe1UzA+(MwezBHg< !FyS-XY<^BWpO: Uc?k{vUy$UEde2[m  o;:`qG5zL;,8 d@>uKp³?&B}'d< 71ި=Ei^`jL|45Ȕdx)o*DuedD-,̕ ezgyXvs &ہ߾?Mٸ!wŘ{oRlc / /K3s^( |N?c#I?a-IјS)x<^ ,hxf}R18kCsbK;^F4u4k֐¦Alad[ 9UǨ7қОRCPP>i0G_T8`"LURU`z]p ϵ<fJ'ݰ le7Pٷ%(xn b5w!B*$ zt1p}á(s %') e, ADiatD]by J ax<{e})gk눛͖֢Og Aoݿm'qϟBɱ6ml*]c1Yo3ߦX!]2r:u*BՕ̪@1h%NյB샽jw1SQٙ 0r-2/ g&9SfqTxW.Fٽ#6/2Rdwho:[ULMӿgELʿJYQ'ɹAoPxdl@6dǫR^94xl0}UɡP^c>C@쿱hT#d{4QYJrL 8^S0Sc$ī?,,ۅ#9l'Wɒ2+;4$P;6PdPp?֛7-͜f*~ -pNՌ77 ԙ7r}'b=[\=;{JjzΎJ#wSrƃ[.2piT\F.Ţۥ 3mu-j{v"yQL#m9`N gP_Ʉ*HeP,EaNLIPlbCX,?|4ҏ{m+;%Kt2i?ߝl8nzC4-(? NIHn)(h_?/vgQmJipqK[:MC&jG+Yx.4& /~ڠhV8\Rb #Et 'SyXcWX{VxGq[,b) ^-8 ުNK8=L;m| i D9=ts24J(Y.˾+Ayȁ E_[$I fR;3*QgI G,6 hQ%K#4˳-^1t؊HcEږTx= 󵚀 T {BkV؃O׎[Ъkr:7>I9y_F&;@ϓ+[n xsi/gq~;?ǩsKﰻQ˰|1䕥!* NoӆNBh :n-KϻycxD ) ^a'h3}k heCn<_8Unfwc+λQq/`͗=10NnF.I82#G[qf@kdmǪZNHG`u rh"‘* Bꦋ mµcs`5p$iylBz0Yt_(ljP@MVH3]$a ;p+*z&%wQ=:hfj7\dPEY4SڦM(iKTu ,lX ̲#fDFfg}?&QYf[fD:~LF*Ym %V&p27U NY}Ԫ/v$},]dy{#kVLpZ$ChՖIY<!եV2/kԫօx_\DqNנus^تz#O}Hz|aܦEfT~z|EĔ}J:qot0vCQE(wpk.K\rX F A UTi-+n55]*WqH\12q$ۆ̅NK3% {5 ǜyv<(ڋ1*e)M=,c2R'>2#SKk8S2{K'_%,gu ƵW( ֪x2J73DzGNC/eAOzllq[a[2W8 "m&u"|D:o9if nN8'&6{%ϞHh7d$]Rj}& qҰJ\VJi!F#(P bMHM! eFHrR|@݅]qF5.:YyoÙ Kǘk)XBN4/ųNd򡆍 62E:StkLJ\8)F'0/NFTLYܿ34 ["C)ͣʚQ콚J6#\l* ]ҙiM4^V_vVYVX0$Af[2,caʆ@>0$4WDa_ F0Č`L{W4,|J}ȓCuK7 RJ0Apd 7o( ?b 8%9+J7(`zulDǤ\ş[Yohf]क़Ȑl0d=ªpʮ'\a֠=IΊei ?`oN!ۆ_5BP&uI") }O 2Tň{Nw~M'3H [;3W4%׭읃3qLkƻҞ^*U+ U=zB,$Ȉt ͂C*a*?d6Țϳ|/%l99f8G24NMƎ#f+Ζ~Ѩ)nURbu']k G)vjS#TmEjES&wT*aN7=u3uqb:Tg'jشYY`lƾjX3!ur L6 Y2vWY޵Uˎ?&eZtPR@aħ ! nxH@lX(Smyd'LQ9sU2;]5DŽ{27k ]P%5lFbE4,&6LlK(O^Q,b6:8tmcrM\:&б9sQo̦^EBj)ϖ nluns7Po5*!'/-kp|_6}{> 3Ml+;ևzU9 TIąH2ߔ.zk/mސBkf!J|h}tLDN/:2^/j> Y 㢟X͋:poMg-`:ss͊r3exG"pEұZdޠr◩UPs< ]~ԶMઽ"/Xzw^hg8.Ɵ@9;jݝSt|ݠV1ҿfJ۬})'dFIyD ӈŹ5 }M Zp/6CpN㚌a%QNAuDM; $]Q])jQ)L 3&_SGS*0%hC2bG <ص`nT͉*"*5$ sw> "̌Vi ?v$_إ&5L}~fUB(RlLk傴GF|_R+UD0jYY ;KY*RdFnҊE?FJZܮ!lvi:5XDӘzyb^jp7CiP5m#$wCXJ6h#t'X6> tS`@uC\|w,.@tj>;`6Vc܅s[2R]J˨a1C,Hd7V6lMˢ6 _U5ĉ( c=j4Mp̟x$ll@Kxٶ"*xǑV%O77);ڈE-^4[XC(]Ԯڲ 5P.o? rҹUԌH7\BEڔE=^4ulm $Un1z7}PB.j+=O^v@ť̰AVfFw>߈sA-u ȭh2|ڢxZZq&<[c!m4@Ġr}jcd vkD>G,R3@GbV@9 pdxV=IמX9RPnmÞA }x{\\\ ›93v^ ;c 3[zH/b -L<(/#B $#nѵzyqD0Az'%g4϶øz;~o ?L,#myYXQ9Oc WIs. ρ->2g";FG!C#@@IN3rD\bDb'lQ|4?no$}Է,Is8&ROR¦&e*O'sQnJ'53O¶CX%.ksIs ̹GgAh1ZDNy+)ců"Y$Z:Q֧+w񖭿꫅W\ R { RN<޶\}2{K|Α- ͛ϯf _9/ь?/`\.26P9Z`Qb4 N yAm‡g4ϏeS̏[73]rOS}g9*C+PUCaȧD*ѷoӼNG6 ǚH{OT@“Fnut!n C/ V': ƪEo_sΌAj ܜɟ>gVA~Y!m*&/h;[\mʫ&_WΨ SOYHh;άe/Rg`mNFh4j#-5 K}vI<=D#NClx+(q>:o)Ng~uO_qȕ]c6ق#vۏ#1KҡPHzXФNW_矣gMUE/HPVK$M{:F?РREqRQ7aH! t\ um@fO|r@F*6#x<&Jؓ,B W^^Tʆ'T5gztp㥬.rE+5^Ppۓ1I.*uLw|[i-9 jLy_i1$5kEjl8nv;0v0thJ˶ʤ,oOs'ʶ+J=hV~Vs~X0G#Ч6^H}9^G( A€;.:Hc>|+XZE_Uum@ZU>y\,|xe 0)[VKrv8/rôpw'{TT .nm rY:-oBʄXQ>'dg#Rּ9>ʷr-4@UN|oPN]t&kq_ii}`H! 2UWBؑ޺`9]*$X<`֛[_R0JDޗ~KxMULOoNGo;XVN؜ýFS`b…ͧr$%P.UKxN@tc;C&{.Qr/+0\%.s9s8oN \aBXynGa]vN kIE,q3NjPE\VpMB%a}5'3s˓ayIH0|1, a-pA JJ^wq@SI{9Ci v[I`TjRYGO5I<^2Rܷ|ٺSD̎<Ag*M`cMSppŮh6VoN,TĬ{t4=қ^P<`Lh}s߾`'A̓844Z"{:iDN&}4A+$nϤqGG ᠝KlsM /+FWn<02ل&<>c6SQ&d>[I*qUAR*JlR{ηyؓerʗA 򶘎ٕ,yt-Y!h}k( $)A^ )bsRPͅ}u,"6LEK~_۵qšGoţ: ZSY# ; ;Wo"d/|9L-`CLE˪ZLas[#!S=|ޔ୹.~0 秴LeՑ|Vx,u0cC< sGDw2|$ ~xU@mn{f"1ΜH!uREUfo"yZ{{ 8ʕJD)ݳsB|VdN0{ɪ{4ltl_ ndXL.?o|!@ڻ/:vpI tp \ ˼ydlТ]?7lCƽ}Pm{ 8N !/\^)޹"\ޛ ":`;N`\>G⿄kFwKc­4hEK|V%[J-!%q *d"# ER5X>7-OQ_+PGguYSZ2 Ѓ(H \w(ll'L*^].KNL<,bFYp4%|Pn*j 9eHvJ\gTz3eAѢ8:ni^vuH\٢7 shhd-V-@U=S0ܓV5jC<¶!T'/ݚ~r*Vhk7Gvx$uDՊ_1 lrڞK)Z:b5 HEYYSye)'=IhLI?>"&ϧq \uJ4)_W8jLMkګAZG}$E8q"P )39|rvp 3Fy[[9S IR{z7E]E7/Y9{ ^Pg"F!Mm 4 A"FЭ:Y[YRkHJH} c7''My}7PG%eeXE#yB|m'^(Ʉ`E$\׷ߢƦnpiGQT(koOi4DJi[S*RsGpåIfǡe3LK S^)NԱO>*#"E28POA{@IP\)6w"V E%4ן*hdx3N*彻3&Uol>v׵I`zK^'vGz\ 9s }"EE%:9oex4:դ:ȺeC N:\x+p=!^"C57_Ln=1kGI[Nxb  4 4ykX)lrK rL٧pm=$5w2K ;T1˔O-g+'?VjXGO8e'%)Ʊ D-W@yo++Rv_ ڤ[ Qc/ޭHIm4LN#5 Aal&\.d+Z᠊zt*:u %rwwk~V*:1+F[_co=\zz5m \wVaUV*{p|o 1=N)N n7IYf$ZYt0N2':ɕqgg:eqoEU.Q~|f5,_l6ZGZ(k:H4B2ݏ<5W. ȵc /,߭5p񦷈A&vrX-Q`-Rhi,52]J\DwsQqxl - P,Y|-}MlFMvxw~E/ozim7^STl-hB,Fug‘*fAmk3NP6WwQ( Av,0#B LWȣtZs:Yڲ2Xku)>1.L[PvCzMA `,([|mGbٜskD4b3 D9M6t܁䪙y1B":!u'`_mMG{yJ+=]C/)R=?UI=Hր(NL<-6+1&NSP+8[ ?έKTsM`Q9hm!>BQĦb\>izs b%.Վ"ULa8H2zÉ1kY?<Ws@{1%koesHA,r/4bhK&G u;[eߑ MXl1i+q"d1#{"&$!W\D#%Q31踲9TO8JW } ]ģ3l3l60U%3w69G4DgO8,:Mw3F2MHݴ["mf~4v7?dᠽ*IpCUI< )Ug} 8Xw9󿥧տpV:JK|.Nu"!6QŞ>hnX/`(M*}[M8$a9@<h`zDw)4xi6d[EUU':|M~Oܠw o~@p{lDd`,Ռ@e?UH?028 qmK{%vv3 r7E1` x \f~_FQzm7.vL (2Ĕ$(TBW:6FW-:b.+se~gt7\uәas25t:Tlwtw_(L=s;2*BOEזY=H-IAno9>g:aXҕ ńv ,< Ys- :(x!Z${H(RT@'5b|><9#PtS0IrZ= x]eꆠ=B{ScqxwdH EJ2q+@鍵v`zFMkWUvNqpk)_9^&jy>BaR,^˖qJ=5TKTdV(B ,*Qh05oV+Rmg0JgQb %@8uŁ%)1_Y;Nrq.1eiQObS nj3w=?_hɞm]}vZaȵK6;q d*beH=tVr8ZIL8kfEHt9-4 2zmiLl*:4U9;Mr &՗1ȱ3?ԄFx_39NŕXϛ YࡈAI'jV_ :ڏWˁ:+gƻ֖)wQ1VV=} \k-RyȖw w+Qg.rFWO2f4DmRcjCeΞuȔ ID-i>m\$s 3p00erzʤX  U +p CsB#Q``QJoUJx8NS  TO>2.eozRFj2114fq(DX8jT=NC1;j Q6g0m%i t y4|IiA=gc13gA9ȼž؀;dpu]Q$fŢ:|:@M//N nX֌\F!2 >zR"ȝ9+,6WTG>b%&='#z3=ce2Z+ATWM%ӢJ^MLbv L%B߲,5g,WEuP95"Is Ȳ.PaGcON">i^vRgz; z,l18*o> 6a܂56ń;7#FiE<`Gh;nSwZ̈́XsGXײe0[z lxX{pibR0Ua wgKs*ûUo"K+aC%FM~uVR~]*ZY"7ŏuBwz^̝A#o\[83,la$HXT0<9dV4篟0Pd dS}m*뫁 [uՍ/ȧmFv&gU1>[e)EiqjoX.Ғr2aj(P(9&n0n؎yaB}fK+QyXQ#Za_ߦ)ޱvpN!MݓJA !ej癓ܠ* pYb|e(C,n_}:!S//2`$\LZc8q'6~|߻HW8N 焏">Up E FR?ƎEZL_Qo=?A˔ ):N4^&BmAMj=" ájcx@erN! D[8gIU"zhXF=Gt0 }P19YXG'jE-C(/;8#+-F_AF' Y8/Iy鬟Mi[s* \8^RFq џ[_y ce|QM?E4Ghl[z$7K<z<Zӓn=j`ZZS?c)ZDڡ{_nbQ&J/ Ƶuaj_}{A~ۗ ƞy]Mi|2 jDH#۲Zja0U.j\%8PcG-3GU}!nНr?~w0 ZYGUGB/><])o30xNK8>Q#-_WHqt.AoiS7` e0 x@1D"ơN91%pTnc7?i&]DkdR-3Gj58I-zD߮`*>{%=00qbTvUyM.pin'yX4id\{=ct0qc]BA <`~H>7m:V(.}e+Wٵi6DZavߣ6+bXrC//gEo"thV[k7 @C078&FBwk] ^rB-H05MVi( J C|f)ukD;2u%LI>0TGU变aSsAN&R{/)aR+L =?wo߹0\?#\F T `E!P #"AVڎWQ8⣊QS؄,<}@"s)۾v3(vK"G#1%:˿".d!{IےQTT6YMճ{(mv*W X;B|uOoNy֧4=4V qrx90ց3 f]ip zVG"NnȺ)nbu+M)-k;w#mB+}Zd)&v>8U.].!}5gZcd)iOFS-֜e dK.JX/ZK85HkF..m/W|2xN ͕sBu0zzt7e]&ܤU&9# >Uթ0"kn._s+/l|yD;Zmϑb.R)8OD򀁟?[MJ8#6sQU*2 wR6 Er)e,iLhҽh_4' @oCvEhߣqԽ.RP}ӌu qX5ymASIKʷF:WBR]7FG Ie`=~6'g}D#J-J<*+l: V0-2Ig,@ Gu~sZt^ F{)NfyG݌Mj$QL)\7{-^j3ce`Ul>tR٘rT'ds1Iv 꿌+6uDiK3ywX-LA`Y']&-6VNZFa*I]D v,8O7ׇsAd h+ d*:H"W]C8)Pa-0hƬ?=ou܏'1[g8|wBB*\i-;\T޶T1-^NȖ8"L+V3`~(|AByO8 'N% ]ң/yj(Vd iWLT=A9PF-~SAʤʼn#?jT G.aí&BR1*/ .-tTܔ'|Ujy=7&XD-U@bj@ xϧ=-X%P(PDU cg FrhQ@CixBּ1ƜTr}m#V[d3]A eTɎ(ҴR=ȉ*ԉv a/UyTE۞y쭂q ?!cdw~Dx-M ׃ՑngH 6]]O:k,`^PMA}7-pڈ ݲ0FmxF|F:Sh*YP TYiv^̈,Fu؁*1]P?f%38'6| UhIR-d0D֘ȹd ٷsTlwuKiѾ LEb6WJXo ;:݃Fvy+-kBҞr]V{5j.ȫz9ekpL65@TY,v%)w\XhRo~t[duR8Ը6ڙY#R7r7&,6|`÷@yퟭH~o-2ު=P *V >5F<qzv Co) hvh`,t3}ZoVAj-QƟ՛2qfyWgJYPaq 鴃WޚuI}IrLr8P`)|X3*f[@*]w@^DQjMv;%).{!DFB,K]*|@(&u",@FS9NDԠc#@];ϲΠ0&z'H8ЙnldGA챠>W:rd{ZXy^=1^LHXJfVS{Xʣg B]sꩾ"N(/WL|HZ>ڡN(IZn.@H󺜴-4C1 WWKb0b?c9S84ś椌Xp l8\Ә${Ly< %0 bx$ J)5Ä.kb6R(C-)K\tq6ܮe]$#X9tdz9UH TkT[b=Xza>4 \xj1@P,ca{_\,D PHeuXqVSu󑞾(-ad!/N葉M 1i%g<@R3;& >PiI^ @vMoЖz(($HeoW )=h_OU8X8lV$F_6FNhz4|NlRXv/iIYќpBar`zb;WsҬjp)Rkد r]~R? 5iE\;kY8-?ui@DzQ$/B\ܢx_'9*Fu ps備~V*;cYާeG `,K@P+On0<^qe[q UMԞWfr܄Me۸ NUJ0h~@&dˡiL0vA*grP/^+7eI/Xh l J{ !NrʐO9?}H |_ړv6rvkDk/bJ}xVjw8=L@9hw)æȫk*I Urh_i[27uB9/[H %T$ٌo#>A)oD?Tkb')?sUcEc.^yͨhpJCzK۳vߛVamahP:(1]|RKjRea8fsEC\U&S#XTsFlq]w?1л:&.Z*ж~tj\SVAs&Wצ.~(4! ~3R,#DK̿#ȉD\SʑPx s=$|ۦ27xKu./0` FFBpUCV0'H &Giw.EIڑ ~'Fb8`!UzdALZ/8<1=0o 3~Vw:[L/ldz$4/WeO!>ΟJw|Dĭ +hsoQ.[nj T8DiWN1.:dx5Ғy=w@p>٪MqOpԬ$q@ױmp+Tlrtǩ %v{1' vu< b&/AK#>aeZ:KQqMr/HJˆ94TRxV&*OE4X~gm9U0 ݔtM4"՝6Ʉ$J_w{[j9 6h_Uj`3_+@eW6PP'Ze7mZpE@o'ZˢiQvv[|Lk {~e1ϪWs7!,YGavRS<9o):k.km5l@.f@Igh֦c&: xK}#V '&ഢ<\~hˇ>ak4/E;($ʹ/ܐg_\?i3d ,=M595̡tK$=Cs=n } XƐdLyw((lå䶟rNBTPo(s+cE"¤2Ѱm85 Aq\7^{8';IqP oBNk; ^f$_cO0F 3s|n[):^EVvo~6aiOwP{=7LθܝofZb@r1 ހ>a 9JY/jfʵ9yNT7\JN@mƊCY" ǽh$X%:iY?wR/KAe!HE\- w( Fc* [ G,E\e_~:#dg~3׃M^#z/#ƥC"bGJɯewjE0f1q}Z ̽b78ٞ 8+!1#f epT M\z5Oݣ;ߊݟOOΫ[fr;ΜIXxDv4Щ[g6?<~x4|WJ_ 'HI4zKGlkِ6wnU^h"M\wkmu>ڕm?>F`~Ћ)'3Q@ J.^GlaGc}YvXLnqĚྩZ_?$V+dK r̈́" #  $!-B:In4zxdgDO.4rӢ{= ЅzXe )RdYcy< \Q#}]q(|q]BLmyO/쀀i_,j>+/F޼4ECeq/s9%#mI]" YcI-U I# -wKFq]dAxΔ19 8 1,ś@ ΐ47JHeKԠŷry(%|`9NYwd=&AU ghhI( I;EK=c}|7jA+ g~-̨sw˪^UnxHe g^/>Ec\EZ S+9؊(` lo }:TL)DRh=*j9X'T0)t7GUG8߯ %x{;m8@8jg6^15yiWTGAO)ZR,gmTBMM/!T:i.&<ܠu`Dk6.8 (u VnHM*xJKU 6-FyT.kRӂcI2җ\qnnx/P|y>ɖ߸ x|yL9wqD2q(cQYDOH `gCLCVOտuQl. Чz$^ӯm0ztMYR>WչeL8_1;l. u5:1XSXdi|(c8t/)`Pgc֯C(=vc?o)O(P67P׺EKf qufYyOiK[H[q{KWVgv4LD{.3ǪǛӀNT2/OH愽F[@$^S&HoA*n <3v Uj N,&tQ%x+E"qE`R'gP!UٟHҔ+Xֹ C+qF~{TD  ƻdsڧ:@[ZpR'X&K<)\:o}lz5cܽXC^O_ (4hbʇ,JG"8|ɉҼ哃I Z>A0M%Xh_QVyA /Kr؍c4;"59C [x`c 55݅ 5ހK4 -dM>~(ve0K;J>$HL{ɩ‚뎥II;bUL=^ek0K Afc!ݹ#^g*~DxDFtBhL1Lo._4mqƲxql;#X%*W,8P}\B4g.}K0PY;=G&5 diԍ2Ĺ@ w$b{}ߠ[a/W 5ɪMD{-< pt”g@(E',ye\#,lVv]yI;O4 ? 1v'$M6!l%MY7ItLUf>V\" 'Z)2Us= i unH:Ԍ (76\{U0fܬb뇻cTiT ?Ԯ gqPoi>6U _0ɍ 5r""OoH)q+^!j; =e⒛=PN/?t渗m4R-/4XR(ՕJb8FTr!)gK7_ Bߨc/s$="0[s gaJͲNtzo<%{uWĐ6 F OyT,rmGsJ@&L xuȦϩTq\2r3=<06^F!$xP3b@9ldkY餩E7hϊ$-\Oڏ<Op&'2V&e{~(ou!Ld7:6WoZvsMfxGj>X#J;E e$=~LUL ?V1_y Z|mxlYXel~qxBD9@ߋZ_є)rA fĂtJ$`ZQ<,u*~dRk]&m]_'~2#.`5f (M<tvT XόL??{\F1JHԣ MG U ʷu>b2|9̺)$"frZ:G33 ]`eF;ѦA$V^,B1z+EVc^NVd }<<|pm*T[Jr٦/횿$/>8ODdOX{>Y7or>Wil+)se̤seH=+% ?sW夋t7mҽw}`9U,RU6,-g1ցEH‡_ H}w EAfը| ^W|\>.[Y:_n+Ue_gϽm*IY2geJ(xحfwB#i0і|r3jn>\~K|4pKkRփ[y'Ecko k>&\logNd޾%-oX֎{f> P"1xB5:"6_%~E^ߋXjhޕぅ>B>Qd-[m2n /\>H<ξ@~ "˞! ̄3>e( ۔mqfWM4'*58[PC)EpkhJ^L;[ 4)~t[ftUى=CΜ`|= H{Ǣg" i"×u- kr gCi,|NWS5 ` 5C^דf|<.g IZo_sc̃iމX ԑSc4 V>t<XDŽ[䆦ijJ~FRfI.1.Ȩhn`yHgrI+ O?v&()ZҋJF7\T,9!~TS?u?УՂjljuK`TjjWՑ] "3,:cR+5]>k#_W#{pMsBlOܑ͂q`6ȁλyf^@M]A4а%{65xi 2^@gZ>~PslędT߅<tInPoyTLM1)Pb6ڼx@ߨFܥ{8Dj\bNX)ŇcX :\}݆{n8$~4y;錹5W",iikMm8}ŪrA\K`-z ڽb)te9gST=-~LO\%meJ΍bݥUcj?u4Y3W|eUL]WJ>uT C"&ȿ- Q= 2pS8/}&{Ξ1?e_dwFgSs|3UMͶ 151fU]p >Ў=K`RBNYOV1dX=\6 >fG/M_YRVY 4 c/#/Cf=:( yؓI aZEpI+6m ItZ˗Iv1T{N+X,[ JTtZ`Y*Ni΃xEaQZ:}+;_bK5KL{h?rܑXs,T`k(?aw<>j7a< A[t[RAP߲<mz"Ʃ<+  ɑ (K9ļ|3hs\QK /PnR?lt+"-R=@y P A[XbĒrT. `W“蹃wjٸǩ{W2^4Ex ys~X yBs.($6?G&^uo"2,ii,̃-:yg9* vHbx챡hq^[WJ`5VYy韋>ۃmoJt>2CLud410W`4 &vvdV,pbGx[S N 2\֟o[C4\GkoݶB K~X67`Tnm;…MQ Qdv[%5s{: 21 <{ ؽiyJ==ty;R3=uE-"JmI#ɦA7=&IF- ^V,G=.+{]* ߕ]l^3RR~Hx| ~g]M>ŤDp9-DF{zƈ]9~YJIqB5K \_Yd&>g{sY_2;~^Q^Kb-2y՟{< !܉R OXu>{'7Sj_ :2=31@7VƁue j'_CXw]O]0p!3+h.y$[)4*r`¨B 0ԈgImE9>k9Tm#d2#~m&7Սr&4]Moe;i5] x6x՛@@Rb:,JKaPJK 3;?abB jvN"UF [CLʟ19#RێuZz~DY O Hn@_aЕ Q*=P}´sWV:ZſNJ=c8lu5eX,~edT*as|rNb jkEn>7b|^)K虥tXi۞FRjR~l,5S,O*Ɂ;eX+9* 'P ڱ*JqJJ:Fn"Nr m%vq)ĜTؑsܻ_Exe/&ֈi]2WC|pGn]. P,ݽ`tr&ػ]+,SDnt&:ù!xYͱ@BPUP@|Ʀ'Y=NJ^fnt/ y\CF,R08MQ+Կm;j q\͖&-Qn5i]Oh-Ǥ}؄u̸P/Sղ# HVL5(?CQx`yQ>ʢa#MUq7)̃<5}VfSz9s܀.+!ql*̵ J#7E3|5J .}x#8WNaYӰiP\b};aT6Du:qf5u_w c=qլzE'= j|*xμ4LG<|*0ĉ^p2D1Qjg z3i*YNoNũ,_-CV6ri+Xao9opF>:A|c̋Xވ<1Pzp]s?Q3NRsb(]g:[y.;-o~>u1[1gE;2a@ (*m&Έu~LӚ۔F53B=Hg7^qO&K.o\B:=bnIr0/*pD>kᵮwe*_o*< [(4jUz^ TWbO-F%6y]׊"j"޵RL 9hf:^n@!L1^$Y5oۆ !k!>ۏ5g yIM1'i \mIȓM׳ք25WaDvoGt 4$1 ȁ"[]: !?.V@^@h $tJ4PQہ50g3,@vp)O5G~ 4WԒX>"y7ꠅ] Ccu#W]Ţ4=.3%uϒ8'邑$'*B<0FDkt2^-P}-ފO/u DP7ڥV|>$849uaB>jP<.GKIH}W,Ͽ'{ȼY^XNĪ󡡜P,y9"6g1aCy[[BzZ5͕ ,FV)bioEٟܼ(0'@ŏ-x+]Txu*MiVq V"j|ϭ, 2w㔤D qPq|Ad^ǞJOy 5\MoLHoj::];rڙz#<٩=˄ˍ&]$[L+ k Mp@9\rL8rʿV-)0Ұ>eisۖs8nO"k4S.zhGeJj/BNvv!î_R):$GMX1ueGE2lɥq%1mC>ΚqfW1mY H2Ib iN`5iGlPP43vʲЭ&MfM=ww7Ǟ-6R> *XF%1 L2m"z[_PNQ3~IsߪRοtZ*N \H 4 WNVrN A-lnP7Ckx p'{p<_Wu4ڈ{={dr t{lj߼xr dRm65̊Wr,hzCER3JP:^SH*8_FFP/=M֋7j͠OI"!r~~w¬vqmGXx(WgT?o S:D m'IÖ%XTB+$I;Za1.C\lEs'Xߕxg?yR ;@ BFNSCt;=" nFY'f>^CyIjcrpWx܈èpk@>t7氍屢Q\vmnByQAjsKU<  Co "+7gQSoL*g=t=d"*3֝ݡL&HZ\}R1&ol{b e.g3Z_ 'hHMA ~eD"OZ@XrrXOW]M<$&e2 /;ϧ V2195!\^;6R^R(H㮂0T $aVeJ+l ,M(轞Y;"}"0 reN%BHQ8 b7̩A$cJbc#iQ};ƾ-N8Wp"w$WB.`IߧӝWeuSB^{ݱu fZ #/^t}*(QCKwD EG`=: MfXJ>e@:as[  v.|mO%Wwpg9aٍ&W>]Nj#=hX% bOMG!JяF!֤:/*OPB1gT;(b`t1nx;ROXh[y0qo$Pw<xoQ28Y|94mȐo|Ac>׼)OST6 B7' .!jD%"r"<#[idrNbt[ Nk_LY {Q^ :G8mxymg@JMB[#Aʪay ݍn3>~PEw~'?wsw6I,aXQ+!oRT0:G+с" Yf)1usˈ+0syº:F2Z| ݶLOeɖ!Ӭ9ؓCѱj6·w'5. !7;oCk~Ѽ')ZY߬aBeNWʝv-ݏB8~bfum0HyheNLJR-oq?Hj0tmmJ M倻8#&2γTvUn_Ҏe!:jWtYsvSj?Y:kB!Pऌ>ŒzԷ& s̅裸N&% PXB&eBɓgJ 5; ojn򊮷f[¤a0 K 㬑.6 $J5vJuC+`\] q@ -NnU<9-TN^Y遢c^ψԐ3 * Hϣ+GAbxp̭17.PO=WʴB}' ܬҞx5t8v Ю, b1\ia,eF?&EYdK;}&k S3o&<B{"B4aP|PmK"zbd?6){n3EK)hWЈ*N %GA9C; e21(¹XU9-P2;f?Ba:",-v*zj)x6$|UL7o~9r o:۬!>Kz|Yal:Sad BLh+ѧ6~񜱨[uq@lYm Ҥ,XJxPOeL¹%(~7]_d<1EBvy 7 RB Xqe6nGWxidwm6t$% e51t0aWQ0s $0kb~@pJ4{b,Ne SXvLj@9(~ y>SAzM:pd+Aa誽kyx\i1i mk, q^H`7;bC$aNӆ- z˗ܩgj{׏7˷Х`JGz,H+=ĜldI)Mѷu[ " `j,7?o  /}jXw FI;Iǹayr.+:KAA{l{=(BZQ#5(#kLv%tX 𻅱O-$EWCm`]c |(\(>-K3-~NIn'2Dn! ~o-cUᖶy޼$@yՄf)H{fGOlLjYp[* 7І4ٱW]b*#m<S;̬ tQR;Olib'v`po\Kn@}J ~VQ9 'j|L5sqIBw`V\1%R]y vq8/; +%,tl/6 @WܟBTwdDb0?ƷR"s$p)Uc_p]ԍ"No>D-ёP4= vC/,$Q bs8b_X I.xs;}`Z:_) /Zzk0?V)]ƵG 7UR?k6nXI/ %a:.`W/XLh=g٭hF(Yʩ Tz/PFd S'4'$K?P?yߍE L #nCT{L2!B3\2a+H!flTh{mk-Eਫ਼8٬˱h5^u1 =wke|F 9 UR۳HDB?+yT\ʩDś+ pn&{^F -LsEZ;YB`JI;Yb1e8u9чsg AHo;)(…0Puqꂚpaɶ0kwj0 Yx*3I@'~53ɂ˦TIkbFA!+e~|-*hl`x/iR'굅)"R[ xR!d#DUA z2UǣzϨJsvKPO1M>#`LusD̸etФD/q%+sepu Gr6k$iӚiCq;33;%=aa"+OYI OmĦ>Ɏ`E-v{*Jܥ-9sWt!DAnc~OΉ+ ,8JB[19Sdc/եәYx9S, .ԟw#چ*]7XŴ!"sȐj~_I\Gܲ^۪1rY dd"w ;iŷ*<~/å1q '(){򡶗~ TWTPIEO "5V1Q1Sh"/)~&nͳRĉ?v9w' \=}&] 9%"yt[e]8{0rZC],f?kю|&Aͼ& A3 _yëL:U oײZ۳!E*5w=U}4./@"~֓*2LTA~hlR|Y=k7o(t?]FR cݸ ]J1Gxhq K }*v8od/-<5<*k猛*}n;p?;0zDPϻ%u E6QsZewh(k7 pѧ #aS3㥰 tˋ_*ۡxªb EHkO}t̹ؤz7";fY4Pi*5̔$Z8m1 %,!yVʞh OyllY={nS90sܱl /r gm޹-$HO6G5ߔ05Kn JQ^6b=/}&jmAzzoM9#!"-t@C\19 KԸ|oVfO]@RkQ4DO,و%~>")@vi 1 τZ38.7]ٳ^#h002NNմΌoueZkœs%s(|0О){:ئiI$H<\"uus[?j9{2[ #[wD+!2%X08νNߐA-'MB@un(2.GꪐI_?vrj\M^aVNahb:14B\];"´!}f_T@;xm.Of驓.,SDo}gI5!wOL~PWn4qn5q[+eH8}GuBZ-Axn0˸j<-,_%u7oyc%o[%pڐFgr7hռ[U#BqHW-eK3 q"Kw?(aHQwFِ2Y+PPN d 'hDMр`^QըZ%VOs5JK͇&z4+j]Za±xr](mg~-cdG[rvw,{rDf53܆>?|*%_ (x2q @d:hwd40=4B6ڦ+@t?j?Ƃ ?,o3B"XD-֧F4ZKf⺠CVpFĔq[+6jA89T: PULZ0DŽ2[~E?xKVc!˷[,LR"\zT> 6R+_#򰔑*ORٰDxȍ.j(T8e>Մm&[SYtC#?0I܋Qxw >B/˄ oIxUTj|LHVͤ4ypY(=Q+Z" 2'֧ +-HLtuLJZ5XwbO?AkgT.7WS=dB'X] !oNO-C rI<%+pMS V}]ː\WTa`l.NW)))  'GRƨq&~kvwG! ȕ;0双Ӹ; AO8_Q;(_`ZcV+SȜMe— cS"BSK0eseB7,*:#t$)%r-/T_ձ*g6QG<ݺcQ}cdFDgptLAeaRD9!RQ; Ol%Ϥh1@~V X5d DR*i!#d|rІ'"IP5]Nf1D.ޤB!>ӱ0ҷPw>*A*.5,~GWOe›6~9hd[ipeT`6dUCE*"8f DG(0@MM'7@,fji,~ՎczCKcӨd["͜"Ŗ [͕eYM4R6JdP Woc: #Kyq+' "/ТO{I`H-UU!Lͤ!\Hns4Q3&ݓr8|l0~25;/u^frϥęYz!?U E*Sgbm\&ˮU; G)Yހn9PRWQ`6iuTqY#rܮIc2yj#L)?"o\GJGPB=n2ze~ e KYW|<&WeЬ~֝z2ٶn||ƺ1z7;B A ÀQǸ~v4R қ}x`Mgw^/]0Sy ! :JxZ];vQ>+yidhCJD79ޫ=4ڞ=*X5GhK䃧}pXoŶT`V< G2|2[ h(9s[wzClu#hy 5w{L]lpVN^L2"&KcS4KKI.F8r1 R֒|\# 5@4Uo[>k撔fV#Xæ59?^o/,>'~Q=I.k$ȒI mqY~"q5M|-m\Nz&X!## q6\q.ğ6۠߃4\b gsؿ=.>#D;;*Rk@Qe>3YzBbljz -eۍVhE/F釔] x?23j]hP#l/em9K/Êƺn!}u,!V߆F,ө0Zu;g-.0!s/UrlfE[S~yiK0v>VΆE+ósz>eٰrZ_%G>\W\dz94,ĜϾA+v|a30E!ԠA#'+Bp.khV _(SG'BSSLwNKP$ 2~QApJ֧R1 a6b* )ُEeg&)< N#/=A{76_(w)gŝ*p4"~pLճC׿,mH/{_ O x&CL&CiiXfCBGc<[RCb~@|V;P.AhUw 7BA/ BC_BC+ ,ónąX2UcZH2S!;"_5}Q{ƭV! v  ]^%q]ɐ@Yv,m3zd2htcx A{U lEwYO2m w{ ːKuUPc MTW NwG no'qw\27sխ(-L fTֈ7"ۻRyҀڝW^j乥ʑ\$"ѫlegv]񛂗$X1f.〄a%g;:,lY12=ṦQ/eôR㭱. fD r3?G!Y~,?en#͗+[VB+/&#r+ oRܬHͶׯii¸9?M蟛]$ʄg9.҅aQY&VdS]zHs>mϦ"27|e:M\͔:َ*qrpO^#|Ɏi KjF! GvCTxossV͆bjWN[((s!SwqMq ʰ 5쌄Q?MQH7r3<ɯ0aM(p7]xأP(&ԏxdrmo1YDd+{fx>q ~n*}Ԡ  Lo | o` ʊJ畞4!-fŒۂ Ʋ~% 80yέ}P:%׆ita5~)0= P1sRpڌCŠ 4Cz/2 8X(p57/\OIw RXL$FIh@?B6޼_(k+ٜv >BD}D"$`N7>g$YL#vUwF7r2%K$j%wJ6 ӛf>"/'7V-5~3tMWW)[!M2% V2sӠ4< /NHjJc⃹)/|&1&b+8M% UG/L5k]ud}hhgcХ9aM[+5KaըGܳ!P'NBeC΃?67l֮ckKeQ98V3\RK#8@]xKFo̺%nuBx/K"w,)H p:6Tr@ z+$̫Dar CZ·(cX"H1oH})LU-p-9ʧX:Z+4ǝ;t+eRpQZlفa/~ˁ-1]2r4mA/$%䞈cʃAщD`<^U^i@d\xWâZm-kfT: T;U \D̺̚^,PW#j _4nbh̡J۴'BIyBA]ŗ۰.r2Sa(OƏ*:`~09C7~eS+t9ͮ{gO5+."񵌍 Yk%дL$(8iip_7%(6GiL 㛎Q{C'WZ. ((|PAAi=xpb_> 㣑ȳ=.Ȁ'(JQ{NaO/&%wŕ@n$[l^xl!wP!V1TD9HYwVgTڋA01g0]B)ev223=³ZuBqC8,ֲ:nt-+5#A!YcJݥHEԉ 1X ÃU,ԦKvAF(Y LMžX=~bm,:![|wŢq6y_RZ.B\[)NyȨ"RE.YyB'N7&s 1itFpx\8`y {E"pݺyjuގ~52"L8>>nJ'TtN}]?j͠oЋ]mtWo1[QFN/5-f<l4\ Tiޡ0n|KJah< i͐.)RƲ:Qs<ܞNn8FS2ݰ1E*2Cogt9a#Ch2mDذD@"t&pZ ,UQQ{65n(nmVI*L Fʗ%gN]ꊙަEhi{ʌC,7w2_xb])qE1]3;`%4lj֡‚(fm i.ߏ?{WB%_tc^!L3eן%R s4_ڿX8(,^ϓGIjMfu$7EO&en!CϠ>ɶ<{T{w0ݤkZj2~]/I3~$ DAiXL{!i3]}TA:ٷ`An` ;$.`ƒ?pnr@c>3=TjEIMVDek*b m%F }Kz | apE{[ۖa\OоVwET8cr4|˭_ZR:y*8[gѯTpVP\?aPcM蕊GB%GH,7Cz_ ЫAᐟu3Z٢Vx #,;oI;h]aF"m$ȝ4ҜA4^Qۢ\r:*GYZ7?hjJ*~Pjwޑ_r( @ve+ų*oQ/Zp'"5JPaWƚ|C8LU_`.cH)@W̵ˈ7$Z؉^m4>2 d`^݀3r+dzWisb2?6$&Gj 39_Z$wn|{6XLҍ8ul&D-`jq? P_S39+{A9smN%*;AmTp^7˄+ Ů*ŸX"*jƼР _ʙ@0bcqkaS0T)d3˨=9#~2!tE(flS1׈(!-"KG8bL;fpQEwaOF:fnȊx8Z9o7O~p-n*+Dbr,\q4a 4FCzrO|Yec+'*t vRQNBOU?Yfp:{DH)$?(V&HAZǴǦDe)؋=-X-)>'ИϺmabOBg`BznK6*O]Jܪ,'-hf;^A IKK^ 0sTk zC "B _Vb{{gg^?V;@oL;{IC[Xެ_bD#~א`(yyEFG,}jjKvNo\gXh_IXNaӟ5crxD9z/>^WʇyNʔb?TvE =vw\ij&%s˕)RX2b3A:[Z8 ȪZ7&um2Δ;$ǎ,c'wX IH3me^5l3N1*Rl !P/nË<ڿbދf(v$%piP#(j,z̭d BPת,B,h;‰0?Jb;FEVB OfnߛtTg ׵=qx PȘ.q;쯛t>sBelB:sS%B6ղX=U.ƠM+oyC2jadukuu#N{Oּ[ C]fpjZ2̅Vl>u%Np6 ; O2ˮS4mDfJؐL$"PO/L2KYH(,!+=}//8~^ An3W% >2l2y/(~4Z heŞe۳mC@Zͻ}Z$tM Z l*or4D;}|p_˞)s# j^ x Fk_##R/P)rAA.vȋ~lO'!-KmQbn1/;'fw~}8Ӫ`:ђd?Z Og@(zi\▲&FLrԬ [l 2 e`ÉdZ#_uf<1'Gk0eF*<@:Uˆ nLvIj4-U|6:mЯ*-u6AiuRwALj%Y 4tulcoqiڏgpۮLo4v0(*}F= ͤd. m!p 8VUW}>Lj{;ySMGtvS5>9 E'͂ s&k) \VZ(d<6cBʳ~BwP<И"/_>a;éIʧ0 +줄/_Զ|EXl^R뒙;-?,-ɫ1 Ja:_^_OQaƋ"US%8|cٱ&VG1>h^TUlP02,\S3w^}?Oе /0x{6Vmk6EZoKi^`$d׌Wt}ܓ8̀Xj@9ܶ@uO=tK4PuХCAMDX`27tCJ$ xugk˜tAaӃ׸-e:={١LCZ(3`5F2$wKC y)vjo1,DU5w1(+2R?l|4wTQ)rl2e>2C50Tf[MaiG <&qSU(][hGT.R(w4ԋ-|p=̿|}[O\# &$jK]5#ə7t%v;#{o=Jvnl`:n9vl@4~uS]JBxHW;vטA>L$ IDy>x&ȧ77<'NS&Xr! ^2efm3V{epLǏG /u5.0L-^9pE=qHGu [BC9ŷxk֌E{oKTΙf[Ɨ ďs83@nҐ;D`Q|nͤy@]G)ZPYwN[FUO'Z-IFQfS &Fj,1/_\w=ڥ!? Aq8w$p,+DC ]=Ҳ,t)?w<@ILJI4"sc|h}ď3C +vc=7sgCq}v+@$褈(Zru`O2(MR~W'5ִk6X5|9/U{˨_+) imlCy?0.lx0fo#.)v6Nq+$ĸmz5N.}Ѐ^Jy9z-ҿ4Q=K`@p;2pe]=VZqL&BoGx(5i Codtdi4?l|I ܵǃ;*H{_U6d!`=s ̳ ,T}Y, "jBDCl%ٻ:@n:`y6X/sc N> EsʾHwz>^9sfaGlu^xnEWwcu[M\pJfvsst.WI~hYJC4~*8@ň;KZhh['5v.贞Xũ8V"'z@}І$ahۡ|)vT1 =e=ˍ ʤV|%fܮ6A>RˤHG?VvxkA2h,Fj,' cg 4_tB -޷k`i""k^&i"śj'QFpŰ\0 YwzӸ&O79Zd^[P~l}Mfo:).0co1퇇L$ L~>C7PzoA8sjd}h>%$v)8yo`% iG|0/..[~4|PQV-0{9{;;mRp9mʣ.)8ْpبzՁ5 Gn<\sQ}[ŸŴYu ZSւs4VA6|h:\ܝ,{-uv\xjPCO8e*I]m`۟ Z1zQ܁N&@nt|$ު$PTMٳ*/k83Y.Z6-!m.F|6_:3a%w0[T –q O|a,ZpIL8] v\q`#gv# E+ 3o{1f^KL}D8Exu>pM݄FMB})&5y˟f]*,M78xbVkޑzqpYry_ʯbDNG2I/IK'Kz"-Z)Ttj؇M#V47^6^N> q̵͢ݧwRVqm)L'G Ԑ 4cD?kRTۄڝMbY NC9"z h\nu&ʲ<Me^L'X* Fy+FY+[_Avu X=U\ ŊZU\;-R;gR\5-; ҟv^/ɗ RZ%Ά?qЫ,y_ٔ>[`9_Fq WgZDKC eitE=ҦMqD ʽ'e(D oq~팓2[:+^z/ڳߗ٥ `w7nTy *Yz)B @B+V*%zu,5HRZRn.?^ 3RWۘV:p*бhzI4{qvFlW rGXRsܘ W Lۄ )i.({􄇭R|i-"u]{o_[$cO?dJ6zp1BJ/nz ٹ1Qj8"|TAec&k)Aj B'5T@#t6*q4tTV>͕KY^vlchhwd+CWY}fVr=? D׺5)Y^Jqt6aC>B)е]ew-,ѓMbUƨuUShHl@J2 a7&䌷dm>=,2y 8.81y҂8{٘J(A FKؓ+q}(RIK=B!(ZUb7éS3iHlR3CPt"cVQYk\\N];#{b))oWO}AAcLuEN<% @H@* 9  &=9|dP֠2HDe_ يq`]]Q_il q0f0 ] 6[7rP= B%i**άHtgm!9 A͘ Oy>-y?nBEfeIta_]]v(Nt6h0Dq*N_"s$ cQ؈eTo]KUcCu{ 1]"Yך\~*W:ZuEٙ]1K+Uv?9zhJ8lqrdWYoLymΥq[dc5a%?GQ`t w9و$Űd="ļbSHt5&Z ߱DtT0+Rh %ݝriaW'L픾þ^x?6hJ 1`!qc8 p#0kڱCpX ȗ$}#pO[)VɈ{h\UMR| Kq~Դ5w0LOt>%L8HTKSv?I0@#ɗHݡ4csv&- ]'%ˤ$˥O[ӤKiH|3`siNW*Ȇxm4⚣gsM~LgECj"a(ea3ݙ(g'z񫶸>ϱJtR]@Cq&4C.ȹ'̒k~: lHC]:5b>`E!jf~6ZYvF/ae4qG|Z| *cjXedIlmN4 ƧY6-keaƈiY\1>j $ sN0ϯb>UVeOy257NW&x=`&6}=:v)J0s_ZpP2, w/kS,=4a{-CĦ¿.~ڀkn!DtNf~H;(*%e= ':ORڞ*௻(#7o7/GS*i*F0[7( n,sv^ʦ KrqY*I~Iw{kuZX9/tE'3! BoҸjC_fGSu196H_[_gL;z !87{ZÃz2PlLZ<爉 4 ާp+HS;C3)כM@6mb58f"EnMWWxE3"C8\;]P <ǐ^2墔%1*9`WY)ZV@¹落quDN\Xp1$6 9j=-34j܋(Ú ]5V7=ܫkH{F(1 Q7aNjA e5&G]2ڙ;6jxO x_C&I)fyv2^`^M*!玴f *+[]}u婫|MG4 GlK;ir`(pl;4_ k87 v J=S`,`` zH;mϟ.Q!~UYiAISja,(+ =AȻx0^wCpK;<,l3'bͰޥvшoNJFxtD֧]hi'l:Zڝ5ɈFFTLaʚ]B_!5Dr4}w*^,C"3}x*GFvZf> ,=<ﯟ.::(9ciM-O9梈!ۚQOf>CHn1\.-ͤ{͢p(l q+Q|g;mG{>ʖmÇFY@Ύ44^CªҎ\HͰ9Kr{wX vJtױ~.9"DUF)L՞*ź7`qK&Iش;gPr7iǒ;E PTaDѓ=m^_+ f!v܆XGdc{ P~J}Wzvh8낌HG?KA0r7:Ns¿AЋtꜭ,2>isӻLXEIvѽ$oEr-{Ë`ČW;wErM;= hZΒ=7V:9x0aT"eBR/^4!%\TDf״Ywiܩ6@S9[Y"j2gyaAVItXuq{q+n DH]r?_tv'KNV G>kY~B"f-]XqQ>h FRA Tjdsl9sdFL'䣱+$Ч^ѿ%;G*t3J`ƃƥ0yDr98yaWcQc*.-jYqA>\|eeZoݤLP̲PxYQ6N}-~48y^2P{Js1eEI֐9eEҊq"7Ka0)˄eB4 >Rך/ @ QSkYm x"tN F_X*"N~|DvkWQQa#*%ALemgA& )HOjLyO6G6P]*tνL- h!ɓ݉,}d_97ϑfJB@]uDM-Yc-{zr&-5)T[S29k=js56k l# MI\ַ}Om9 桇̞b=3(e9õb*iїUp;ϵ]ܕz| Tv $[Jwcv?Sݘl;F.Tx/o=O(!p3}yu%2!ܘod؈Ǭyzb ح: @o(PeФ%@J;|+KF@z$/7%4~/ʊ2nkLԗP/mt#3b^L@^5T- mjv$;fkX.f8p/(,6T}6DL`'^1:3 U i34!,/s^9cG·nilyg"ǿ\I<3 F\0tV&vb0 IT99-{IA:OR/|)Xf>[O/+4e[y9\I#w5}RFg q~\fXek |u!S>Lty O}&bB'X[` fLi^\w>Aإe3l2Nl0]93wc.^a)` D4 Č25=o6Eepy|b/?$f13/(Q!#bѺBs&H0d~aݩ_E-\«U+g`oK~Jrl)Zͽ%оygX R+ND~x䙁l8qn7f H@ " #yBnq g8UW'͕5 5J9FwtҦ@V*ξ5!r$m nx[wړTc5KxǢfy~ p~(WbWث7HJ ٝ+Zǡ{75[0.v?wjδyr%w&k9g򵙅=-O-֔vFE2,f:ucd-؍v$Ǩ: 绌~h,;Q=fXԤ?pog[>TnfԳ.=:pF4Lֳ>>zkvs~g92zVݒIj}m `$b^LKcPUu zXæX$@=j3%eOK0aoI?Ve:0M E[ڠDH.1< zmfH|{_ŕ`CeL ,akqfPiJ֩]`?"[FR@-<3(3 _nc`mV<aU/ [ҔN1Tn`/8 [̩z`0=C1kڑ!r:+\LeV]AJ̣p~ +'z0C:%/,R[,3qڷ<ς,BR{6LK7y$6{uڄ>Z$Le]B퐜+#StdT$KI_G!C^6KyնtXAfF#t{(9g4YR5ݕń_fu]A1$&Wpܞ>RG4|fյ_߾,fU9:U9ǹ& rq+w)OoCdZC_(K- ٻbݻP\ꢑ,,]Jd+i:D8` MxnٵOAk܅6Am*˯"k@?:Fb1 w5;kQsAd>l]`diڑ~FhtP'!(,YB'):|k޽q'BElU ^PO}P0(o6~өbmW7@rcF 2BȞСP?4'HaT RdKFA{/DG_?Vɉrx@e`\jaGA!Yk/P⹽^ȼHe*4;ex7H璙UK+o ѫzV 7]u?Izd2^$Z-36Kv]̵c+E W.Y2E zx% ! /q LEInkZ2jT vD׀DhUW@ NAƭC.)>Et~ f|vu`յR"?Hqr[kŰK b{zVɫ)Grjhwk'J%TOM¼nW2]2J቗7ުu>j'Ì؂S/I/s@o%L׋ `|̐/׾ɕcQ氓,=HLWj698"GXL{*H8QjAT@Qs`~fdK=R \J/') FDgAn+J=;ㅓ},^I_q?FMm ?;( uZôgz(M` F*=`s64>DMK7We _Q`K .7mdsTj9 +Џ[h5:(B@Pk~&_,P(& Sv͞\ҭ}$ !j>7$]Oaw0ڙ64ΰqOm%uzF01aN.qDTN6u?&($'Ʌ4( AOubR/{l&61uza/'?Ǿ vt#i%CYfpʹCp?Jewbd^±!1vjM v%]ʾ;xJ2 Hl,U+ ' `5y\}n_oo^ g sseCu-t4= [%;ԝ<}3O-ݫ NQcV-?dܛB|ņfcܶ% Ď# B Hv,U6_{p$cy67l 4rb94̝SR]ȷ ?ReQѻ,Od!2 tDfzLCeiމsCPc7y}hO2'mdG< {wfTOuYאѪX;Z`${]C!4| Utm} VsvC3&K%3cVdž CBt6~)_4AxUTAoUy&Nmf+} $fg ;"ocV]at,b@s:'?(oO:*QSԑ+ODb ;12V*tQLwOpj5PT!3+!SԳ-rngMo[,ɉY4` K\yGz:nPߜxZOߪUk.Xpa97 ݷlO dd?+}z{ِ CU1'f[m ;ObڂmH*YճaT\,Amf(Ȼ{wnAY)vgaa6"ؔ,"}݋7u3ǵ"{y[jO`a;oaJoe]0I;CZO]ф2 =cԐՓ-=; !ȉ 7T9Oq㷣j05ZIJS*ؖ>p.+ŵLUWkpG'BӰ3 Yf]/Z1>$KBM׌5XV͌/h#J"0yࠪ :' 0`J5%HȂg$R>QKme|4b\GmȳԁGK;~m"}_Sd'..10C_U_oc{(wGߵY5mEEnȑMpmY586*)#nS0/}-Pީlt20gkH?QCn0Mzc5. ԘY4)_iNuZ1p])OR~ QUܢa;%q^`$Q/յu ,™0kJt6u#\TݴV쐸L蚃꬟e8e6tO= ZGywWz2c>!5pxB=TB.sKP8T"\Oe:w{?fr@^Cj >직H6!:EdjȻ̂$6mu{34:5!6*% fM O,ljױ&Э);6 )υ:th$DdyZ "s%[#>J*o(@qv'V _ztّUgԜ6ZjDxo[ߍ]DpV5eʼb!_Uw3ix%+0ID1=") 2Nb rBlRpxA߱D=u婿8T~Hh'Pe#@(\::Cpp md{/:j (C4\gWKL}KdSZyS-Fp[*'VhOjf;|',]O4yϕ%ܼBNO`Dm0AlJ| 1U_"/X )rtXcMTc|@A칉m?ڞRlo.8d.+n鵿> 0zecŵIK`]nOEudm@>T։C6Z'ˠH%|}]D8śSjE>v SZJG+N/0 "΂&(JM#^쩸0E*1nSW.gѕwO\)/ٟuF xXiK žA#1ںz"ad-QH⛶tGБ9cwx5KBrH >yITL@N}{ˑL3RŶ5w׽'Ra@J[*k([7IfFwe2;!Lʀ V~RY7•Z[v3^ H<|"[g'%6*o:l-Sae)f 4ˍe/zNR-CMq}n֮:}+nL/#=S!p,Z 9ޏ |A H9UDvzJ"q| G@$*;!H->n93OWm#A^ĕjq3𖘳yێˬRhd+'čgL^y K gנv+ sGݲ6Dl V *d6ϓoGn?/qY@ ;Oo-*l棽m% XW4iڒZA_kۏdg,q/K=E/)cx,/4 x ov|/m)y&szIV>ݶsJ ` 8tAS.P_rXA.;`}EO9b#IqPmU6!?ӾA7K4F߶៺Xs[J)֐صxRz! ,eLyF>A2b !76٧vVt`f=XWn9-'uv,)Z&۶j&}H|,N#DP4G#J>Sc[eV# aBn'*UEFM}y?NUH׫3ɪ8yEҏ, ΄03EpaCn_סMX~(n5qTkwL~D&74ŢUBi Kf.@HIC'BoZ3#S.7xvǑeՄo֢bj)~$̩Lmq5gR6W Ko;cp!lSV(qG9 !R礯8݄Jm-2![Hrt" $]}(jь!9ntgpokAC$Zsh)S_|ds0LriWdYÒ4: \2wIֶLJ7UƖ|$q%!G>=nslH)M>d߾TM[r+.- @q4Zl?J).rVf% u9(-a5jMAZ # 6`6/Ocn[S(1WWΟʫNBXc 6هѷG&%}bo]cN9 \N';{Oc{]CbQx,`D g{c=$BVZI>wVq)kci傰 WԶ3cVmk+eV8EP!Q0Nf}Ӽ=j9 }Lh>ZG)JWqW~LQ"r)%] #F>Z[H~2*lE.'38- aY r>E Z/ S F?9~(Jmn`~cBgȕB#n;jЂ/ ᓽz=fu#?a~;xwaר̇^mZϸju\V+Fr{ Ь%*~Th><;L:ϹKȧstO - i%0=^]B (4a#G2Ԧg J/:-A`Dz%f8L@]bPt,œ;_Dk$?@1Տ،>P_u˫d`TyB۩]JgI8{TiBLeI5 YQix J*`sa Qo=j[r0=8gVo j8pVloUйtrT ^( ܪD!:: w"z|M`KoiP({#,l)@eWI.d e.LOcdQEG&ֳםQ\+~56Rpq<3ӾFNKFB$xs3W!7q(}dh+!SW J&v3Y}uFTs CJqRs"}3eRg3x / 52zCY"r ~SSS];w{s {YaH[GtARi.-'㽾-?/B0»; ӋSonLS-b?kAe_?Sz [V v^2?[rF9@`]:=,e]/je $Ju 6J&mY|6$>C/ۗ* ]^8&X_8x$u=ҔZmG vX:⮛j#X66ڢ|~*OwaD'*9h*i:Mסkf'>9tzW|ҵm j;ֲ.cT}zϟF= ΅ 7ԪӍF }};}%]&*4L,1#d"}[{UI:.f`P222 N_rlRti|7Dk2ӭUׂ/ëƅ:,4Hl$Cez5åĭ{}/QQ[(+d‘Jj& A7 `iLDbK2<Y2-Bm/y,6`[IHt}g^d 'ۤZ\ȃ0/.hE˗MݼػKx[`.HȚK)W''$߻LABr':3f#+֪ˈt:4[x$8N(=dA~mHW7-;MS-!@]쨬ʀ 6xɮSߕΑJ 2`/Q}SMpi6# hd#h:=HZ0e wT3d)C oW{3CJ`?f #ݠ+ CPF^FuQ@20 ܿn[mh}bNTIΑqMAe[9 ה[[N\q3 .#5B*"KBjst ftS?`7WgIAX|I@A#\, أ21{!c?Ů?(zU+Rc KW0:B<\UZ_ 65^򵨪AĮT@8p,YcDž-%GS4j8@9b몫 t2e.#A32 h t\!X|]ԙŐ1(ТoI#$zyS.[|oE1"p0?_H%]+F-%o ywe`61mWZU-ڈ)Wt$Z2n#H^ ' ;~ mU>5,*U$rR{I/!@liA8 nҢ&68Sܝw<^vr}3pۄJr'ӡ:0뼗Wnؙ&˭Tuf1d\ޅ6#+žnOx 3O0Tup$qٻ簚X@|~zĞr!N`t+DEbw稝e6G;*;kw8<+qhW3µ?yxkJI>,g)W5ȃ4 F'- ד͍xڰ9}<㸩do$Jؠ{.ҳ{m{ULM- Bq!,}-{l&px$S~x>v)Ēr^hrn\6\z$0X[`X֔%hH$TEb}tzu,& E$\Ht[ӓݿJՈ(:@}I }Yv+N 0E<"G9aI]IO; C#ck,1UUEְ$Q hބD>Dʪ @l4{^ K>f-82j3#/ E2):tD¢vґƲJ?oi44mfwVZϷ].+scyq$P/ڼm@NGw t׹$%o^:,L:z@9Jo&ꂫpQ"=RɻmՄM!G#mߢ_V"kCu>LiۿAJPnW ؔ<Zmzt6[n/5N_/ scQk)"Fn 3lSZoךCHqX6-ƫ 5Ls0P\$kC`I"I(;KѸ# <;DBHcBrxI ٷ*b<J>^!U\E5&Q@%/=EμޫI,0$T(/Tq6jW"U:T=[{% s-`po `gC X-xo89s3mO]Nei:];^Nѱ(놿n($7ǀ{Tdr]ѵIm#(6݉jb j:eT™jAM=wvFcLftPd"  /Assf}<^gV:QJkѵ\2`5Fq]dsISN9=L}E(s><ᫍ+h0' ķ]cr'NRrWqwKT`T1=wSkpCїL`fW 4  #rV!  5`taWw* hX1DfA.A Cm}O<Ы*v^Q-p ȞӦ[!ĀЬގa\kٖ tiL[2Jo9l Qg8(\h9+8DM57`pWAsqDRUbM3lK` nlΆ[^[K'jD)'ϱFVps?:&"f 2 vІ_YÍd)6z L Na9GèjRuSo5YC%u.^l:p+Y5N<35u`=/S_ԶQҘ׻HIqftʁN͵|b\kKcKBe)Ř&R~3o(H?IfqRVWրFm+hKj9:)X1F8˹|"4Inm̓خƼ_v]B]^$D!^6oh 81U>r['| ɀ 3]l찱s,;=- x ֕W m Am=/mf3{8.c>ZrWu9?qeAyVnCȒ @dfaI{Q`>Jz(>Mf] p=-zZՏ9?0|_^OtEd4v+Y#_'d+)O:%n,o%0YC=usE,pġ{96pY4mL8: EXV翜AQA K !ǭ&"q{{5^w@vK]69GEٞ"89I5q)2ל7k<.c?MXi@3B.. \Rȶ^rKV#,Ol7RUj5&XhK2UJr_t0 +y78錬CqM9(՘ Y\qB{٩ b}Bd๷ĕZTx5?l}J+IpXf6 B!C^osf[vfAn39]90D߮2czBB 5Hd۱$ 9~ȯa5^emwm`S;,c D^{67,:F-5&b)r6kdu-?Tbse-s~}EUZ|.{ X8037 ~)OivgE^rA@Áɚ~Z1me;oyB/킋 ?un"hFVgPucU2cXd7j\n< 4EZ Rr5/-4dȾbK4 =-)sHѪ0e=,oRWG?uLMd'n. 5 5i5:w4%x*"܃de*L"{J*Y;׸ ^`,2/%J2LK;I /.٨TyH^:C+ח9sMtxAˡC.*]7EIԩL*YrR䂹 z6u:wrղ2Y_ {2=PrNct!x 8RQ[n87)oFs_/a΃S; r29Yoke/:{aO)HXk 8"$ipdNpP9zo~s%Řx謥'[Ȉ\~=zm7G\Ke E)0PbvQo2J>cK}9Ě*`ѯ6vRX$b bX!)Rjt~||-Aы,zFAU6]qH ̳ ˵Ū:$>CTWQ2*[NXBƓ{DMH*;U UodoV7] ٙ|pERG+D:;(zΗ~;53-4AuGغN *FLjo<$}ƨ Vʝ4)p*l>m/!p-?{}m=tǃqod*~kۯD<(/qc×j+7rg:s %gT Lo6s U.3>{x;;rkZ YJ;u@Ùm7ŁjYW2*1.@%qd&p/)^EJs˫&tu+\&Bd"L`企L-[5h,Qrn#zm01D#OBp=q4nW(Lc0#^wrnd`J}=p׋{-訃zSͪ Ya {gOz4}',~J~\OtOQ&Ejikh&*Cͳ'Rk !Ł%}mx2Q$uhWܲ $|j0(R1ÍJb+Wy)ScJ0]Pl\fKke/o4p;FۄʄU| v}{~1n}VDz+g scUqoXr=-,I14hi!`,㜬QطlzbM^Cm|%7ovl̇&ʽ&=1w>,>ʩDK qݑ2uJm4wHBrLOgs{b3h~3@xDoP*JhDi8rl9DY4p<%NFz t 36(=F)ZTꭘ#OBB7i[An@cGH6! \)κNVDdSyb1?J٨=+߄j->d'4Է4U4kyI$8tgDh< t yk?#hllٷ++g.'cpڜB֜i\O@Keiq GPH2^k9流Cүuj4LŹ/?'kc6 J`Ce{K ^-?,k1[?T/)zG.-⊅m|brmbۙ^UF:"*6!coepO`o6HjgQiF}9?LϦwqF{4 2(R.!C*}sİfnY9s;^K8Do-M*xiρ[WH.ݪ}%23#V0=(;9wjFǘGX֬QaWpf,(DG xD?|۱jhɀ{ 0'R1&O:/)h"$\yIYXz vmkfKGr@}ĠxM Of24[NRiQh%Xm{'0ʓWUeWXS`94,MQ~eSqb>w2HicO,5p; fz3nMY-\,'._cpAU&4~5MPF{Str`\|׼ Sr;_-ݿ2w8Gt/tH*8 m,XNl?g\N޿ԭ<,_p ޺ !KECLJ%9J⼰LIبT*$8I Mm/b;DѲ6 ݗKw%9,?HӴr'M6a^cԭkTiQ]U%ߤI :|,O9 H&YH5EIʗ(oz8H[J`BUEb){I$r}A:u.{Y'%ڱzq_~c00yYA|X@ -0RIi&7HeQ5pWv4{lbD?%>ԎY>38NL8e$xPU7:] jK]\!x;dXy:/#N2ZT|VhRPTẕSWq8tbj9с-~{zd6 O^8G*@ᶡR)H|s\BG UQD;sI\cD>0_ As{,%b'C"`xF.)F`S>.goBwbN*󾹃ZxL¼Rj*;|§̓̀-<ݐuB(9k3~E5y^Ѥ/O%['!MBv`v&m{K]Je,>twU{2yXOvjjf ,2h?6-ފ8FNϠDVFRMMcQ@l oCѲaF*uޏ틣YK|%   X'(DOf&ŁK7qI>灹-iTVMHu"桲ZJE${C|.ۍYjG\7OL KQ 쏸5)SpphyKQ^5?z:@Sr.3H p>gos^Zr]~bOy,aMnh˜|ԆtFQ¬i]Jf49 I-xSWP %%;ѵjYԲg<,Dԯ9#o䘩N̨21IZ6 齿ު:yzi$'bFS7@9<2 ]wrk)-Gt!5|eygPD`mѐ9{|)+ |zw6(/'v›OT߸ZP!*kzt%LfޙP;5VORb3x5_K1] 5lţF^U?`33|cc`ePzj9/2EoIe,C`H)<[( 7dݖK򞳿[9S:"WlvSּW C]jt5'A6НN ^v #bĥ3qd_jr ?U_ 0X.,)nY~ Qs8"NeBլ9e+x1_hŽ3B^FX^Ea>~Rݐ'}oYS9 JI:)RZ #5 螺 }63T~P|Nr f (Bg kP? meڥ(%' \.m-r|3 /'&9gaES˗D=߿WB7)[v^$U@A+{3-+MȞm%mo 0޺PL|@J\(`bbxߍJ!̲Ub/??aݶ:2jqrR cEȶfX, mE4_-1t8"Wr$Hǂǫ39h$l5>sͅhlV6mD:jө;cfw+U`>Hk!8-yJ._:t&#nIz>~79odپdQ0K}?= K~ +oYQ'\4я٬L! =p0y/ӥ17\fdFQ2{PE*,p0*<}Jts& #yuﰊ h9:#E'%8P9)`FY=f/^^4v̖jesabߧ&g E&,5~wȭ1ۃ#$7H2rW-S-Fip_,񓄸S jIRKlkM4{~OàqqyQf+;=%y ?7J3ZJRiDN6[QY ĢB $J<4j@H NجpI_it;z#"E>9@&Kk_#ȯ{F(K.@HbCoS[Tc2aBiLCqc A(5T>^b0:R&*UCo@%?ABÖ>>OHd'L< Y'_$?dU6`V8TPl-؄چRIT<η!`_qߥ Z2dH(ɣ= ~.^g?7ld UCd$)8 $"Pq_hI,ޒʟ+ZB7g'nAѣߟq9 ^o{l0~?)4KKDNaF]:ýGV5PO^mf`NquӃ׏#*Tc >'V6N$JT.ɠfn 69f\q3j8EުNUGHo587ћtn,pw?!lνI# ԝF$|"@{̼^Xe#6a-?PJv%̍ռG*O/4v jM^fk,&5uz 2Of]wV I):DYkwg2mNFtk6+yRJmf`ؿۖė$!řa3iLa dk[ykakeZ}/y6}JirY5 3S2Il18vϔqh4lkO{qC} ΂Eyȴ :D%=(h2Hفu۳(<(' B-a4Y"KqC7qLtḴ3Fc֨@B b%[L϶~{%=/X!u vu\Kb_boKei3[򧋷܏$Tȩ>lH;3is02S$ V3l~ gU)Jݴǥav\'7 1/D< )DSɪQr7F :+W;mH&')?u,s)R!h@ 9!n"Z,']m3D$(?(Oڜ^K*EF@`Že12~wG~?T:EGa䡘lX8~yQc;=<@: zWPiw3ü8.l- _]ber:Qǐ~GB&&nT 4t1o*kHk8^ ׍į(|28e=m'R:4:vYI5H(;70xo%uٓm Z@(˿9Bi$Pm3cn>WJ8lEA ZPQ fSt=9O?NRv")/%%sLJF8'nϦc+a똢N{ x>cS/ّ ^rHQ: \%уѰ-v C'񎓠Tp&1GNN aˆ2'}'_;쏋2VҮ%vFU:4ScKlq3ugLr7 Hmmz*XW'/*O5:1MWf J77eLTZW䱐38;NH5$Z7!3^Ѵ((uݝiF.NnF{Xp)H!Tde JR}*_14\긟Ȋ٨Q_|3xkg\#߇-}HFFrC+/cd}&ileb:w=ۏj ȕOÇC7XY2yJN۳Qrg__+:8 g`f2՞OBzڌp0] @ؒv,xj̳¯sKI,CwB LCk(&sxSHI9K|5sKD[^t.@ZNrόRI8PpqzTxeJy.Ү $Jd n62k3A8nj̔@ުJ0{ASK(Gv U~ɲnɯ_=,@iC/x˻X]mnt<]/{R0;ß5 h:97==A[5gM %8% pdMDє$: tɸ]euŤ:p"q(u-,~1DFtޚNll`Ʉ17aBDPB$P7,O'>zn2+ gfi0hg+*K{"osϕ3E|+JE2 g7gi* ıďw=AEv:È&)ʏjV.^6P!1lm7]_=]UȰwgtNi9:Q%;G7vUeowG ۘc{{qS|?tzhMUߥ^ a̹f|G} lat 9p4(: 7vSX"Saf-_URueNZc}vS4S!@qq]}ߍ&ve"|&jikzTv@()s軦Kܽʇ W~w( %a-: HcW[4D}sߙF2r0@աDk?YU+iIVͅψ>e=oniʹE%bDA8&W~endsAކYUb4ɦ4i$)zW[AC*P񯝫kNm)CrU~61J}So:@AM"_{7ۍ*c!cQK}::|=1BDB(%r8CӤ6~\1W`g]g^'bqtK 8߼efF[ 2gC~c}T!\$E䐼;ĵ#z} @"fT^lNI͓KiD]+N6@<z`>S+.CO B"lΧcH&C=Q͵ :Wdž ֢x~ $G1E-ךȑ4o*p[g$eT%h`fjfUo2<@#c)EPEzɉod@)t̀n&e CpoW"u, vj'INM^EBvȬrϠX*&h7g]ѨߴyFMhnz(cK>i$T1*ݜ=8IlƃFrJ˅c+dmȊdN=ʢE WQn0~4 H:AԷH9)ڸ*@Z#^M=Ȧ]Qs.H!X:}dԢXYWsI-iO;U 7Z )htOI ǭ`8΍4Ȓ(7@U%S'}{WxC%'^.#sC7؏_*zr 'piKn&;x5:H\?c tϳYauNgXDB!YFdB +W :pIfoՄ=VYVGTa;mNJH/4:&[ĺ+zp9[O:ɕU|-:Հjڄ#3G(,4%QB,%aoYwnmǯj7z+W^zie1nx&_INضVITa.<|s`5DOx;<7b[_i,~&q;qPW_tmB.-Q(NagbDP^7//JөxG!fr:R#$dvRW!`04Ca]KG#]wR`H ~ D~AT1r5ivG1lVm2h/αЦXx TD $B1Fa񥋎]ܮNFTYg*'M u ϣ(Lǎ$6^Me'R*zLz0L nC!#z8 R<^#Ѥs76Fljv?,QS7.AeuؘMͪji<_IMpb~dB@d K ڊǎUYv dceA\8[(r^]rVï/&l^0D` 1e7Xf"{T #= .z3u7rؓǪiZUX2g-ӈpV5Qyk)P"-O[WXrtx@#|iS/ p@ 9O.3J'1~J]غ!ʁ3|=/o3wP.Eo>lӺ Noǹ0YYwnߒq%N-Cbtω랂b> BNtd* )" jnXs+Mv+\PO(mGSr[o0(ܛ2Z7.q%|805>N_MJbhtFFǫ _^`ΑmN|,3l־|bmrMٳayf-Q0R^Z:>'ؤVy@X8CE؅2Dֲ+D16(tcLHF7Ex1_݅NQkNq=ڜҊBRb*Gdr8$WeŹ_)KZzDS)!tc8ao'7X,s ,]y*.9?I7)鸟>mptE]o(<ahT01<Ӊ$r̶LdžI9"@{ݒ·f LD@X@%ץB8b5GyV7֐3g#b隞 H!9˭Td ~g=Sf+ Şɓ &~,VA- {6vg]vwx۟ION,Ddyrm~1d?^Z*sۂK^V_z^Yuw=ilPAT($FQqWdQO֫'6}lLr~k[#Nٷ֑'4&T`p̈́wѫ^tocS(n)Ur&+(+F3 uZ5jn +౤&X MZ}9#k}\ܓ 6S8R#0yN$wSb)vrLڈj]?aNw|Q uiՏ^/Y F1C]rigGe-5R0'""!mAdg_'q@ 12o(5GiIy?Kʧzںҵ`|NҼQ zovJg~(O^S 9~/(rBh@oNjsؙШof[yOs_ﰯ@i؇Q*jk؊$=.6ZĥoFW!?>q 9rphH?1r`$$i셆8UOιѭ;q{KUetDycjʽ>(_ϐ YY'r0:͜oh⢛@Da 71$50N1n1;JwG{<^b` (^cKf.7+AB]Kښ -[F O:,G1N3/ EV(+, LqE,kr+ {GJ|^w$cXJ!}ѧg D  "C '̥^{%!*E" `\_Ju>.F8-B_F]:dG Z,lMtu]y-RhI\q)U FId^I[8,0@%aǐ xN[?;:bMMA}KTߩShUc߲*6\nV1|(ggk~fpj`M XpȚާNY}rWDevK.$%J! P鍈lPw{\+߅ 8K[ʼnK+&guT+ n=I),(`۩KV4tBp֖%%127ecGF3|A #W CQ*ǟ2*09۸8/eV`( t4v- yUY4#?֕6wg"::B?]Tbdnas z /LbPyK!oGܝ}Vh:a@={ue>W'=|O_-9U4,0%fAԧ&%A7Uws w#V+ ~\m \ -gpe"8_BcXKJ,V`$ ؜(Rc?LZ ~0 1_i R i]|MZE21$dYgY݇O>}YgݝG''%Ʀ8ˑ=]u:Dh&k̀ SIgr;2yP/a/]*c@B 9QȃR1IŏD(Y-I\>B(cUcD/+ZA] ($IY;ʍOk6ZOUǑS!𵰘C3 4[gMpMc!WdL޾4"-kiH 䋛QZS[mG?eTE `[`QgKl2AHdyo fX!(1Bn k~95I28jd<[:@bA~ffm$\ P OD8W,rTߜ)tscWL;{$Ĭ#¦^g=ԇu_QDAZaZk 鸿u/.ݝ#6Alo̷-B*"nJu,J:&Sռm% K$@`k*$K eD[ I~KP'3 $'0-Fr56 G㐙O2)cܾ9~XH-06PkA9:o/^N1oO~8zųӃniOX~{tk|tp?|>n{>$H7Gcn Sk7F#L(HM)%W˓%Sc 2U^/ey8$KA3 *hńᬔ lKKa?|ʥ^B, qkĊ>4/ SY4*{%QP6u_j Ҩdf*aTt/#ڻ[3ګZ`{n)vXd-Ap% @-4k3&eYJcQ٤/p>7E崤BTYpJ׼ ҤM%ϩb w!AAћC *"A# XcI4 n-k|(AV='ίf&cfC>?IYyDC w#ť4P 1"͖q홍>HMg=3]lI F5gbpM;{ ~T}(API|6_dy+sI; & 8/HF1K'14C{r6$[-p+L>̇{PX*o~ >Ⲫffok".[6EzȭQ'A<(!gٰ,L14,OF<[x'l/-ӣў: t^!P>[$o$>}̮Q0707010000000b000081a400000000000000000000000165a2baf7000051c9000000000000000000000000000000000000002500000000./usr/share/man/uk/man5/sssd-ad.5.gz{sǕ'?>Ez $EI{uB"-1" C(t5ᮆ$nH РWoYYoĺ Wh|瑙' $ m& #+'wKQgwXim8Ǘ; XFo[SwNo[xx]?R/lEd1Ztұx~Fx>୤<|F~KdZ#IFx)]huSZYSܩf qG`#gFϼy'n. ?Dw{ÛjHu5nu'[&O]zBsQOSSoG/ϿtNySq/3?gdLDKv'7kQY;'G#]OOՒzQa/_:?O/z{7<^کj9;sx>TG"zJtx6-zg \aMlpׇpz밫MYx^A=Y&}1CPS|ST+ 6gDICMzߩܰ/}sM=/ >9T}F(l55 f,)G>dV. m<2}QïIJ&W&/2tIPK-sT4p>5:=pjb28՜&;z1^Z7ף_č4jXY xHmkΡW_Y'5p)'6mrכ1K.]jvюj',08+UxSyHQËW[*/SdFLC܄4\62֛' 2{'j%;Җm5bdkq5ߐXA_M\ǝ TK [pO|VpUAehZPƟ7<=F#o۪ׄy<gO~^!n7T2RZ5.$3svaF:~v)|W=Mž< ?ܚ* Wl:F-z.s,bw\Kǯ},S=N><z*d3:?1:3U6u@ZjeXm}|ORџ4upxq#L]N;FĊ.q9 o]Dڞ~ц-U|*(PN>°zt47=R[=^lc9yO읹=CHe'<7{o3˿:tm:tQ>DXtNSD*d\o:®"Uڳ+tHafyѦ\e ȡNuubJx_wƳu`X## رK^z \D3ݷe}p" ☓H׸ n>tuM`BMs X?Jhr00cGȸ?W}2O^ޔ#̾UC%n4P tfB8N~R^VQ0+k3b\oFjsClO4&/0-c>j'늼a#g:@Ё8W ΃@Wj#Ӝ`CS|E?^.:~ڏyuLUW àE[+!R\cEwԗ{y.'7.^VJzs ͂Jt4'7 xTm-.iNR"vV:/EaшV;plupd5Jz \c&J!j i!ڭEt95&>mV=郸ހ<>Gx<;߹zrI. Dsx^ͶŝN>IRO5`܁Qa٤т'YV5nj{iù %cuEǴqx#ڜ}QVseݹmF2c^6q#K>ԍm_tCEޢ  F^ƌ!Lܗ\)M6VgKJP~H}|4@[C"ډ/%pU] YAKFXD|)Y3f7j 6uǴؽ<ѿη ޥзJS{|  z=~ ZA/VCJS_ni 5wx#"x%=k|RZ"/߲w6OqBxGv͖(Pln znɚE%"l_;$gwDZzJ;Xtc/#B)npFV&BdoɺmBRT0z>ىhaK[A36Zg[Q^֡g*rf^ύ0 W8L- 9N7uMC$j4#hCk;@5gDZjd J:9]=wG})Ɲ<?,+%W$ N>EMw5qWL?aH7!Y[`Lg:h }Jsa &Ki`/cC3"(JkNϒ}1Ljp0ɳXEvMi x5Ⱥ%}1v&HGֶBA7P<+ϣc촚絗GߧO=wAyO1wƌd&ݑ~&4;u#x[1+6-h٢ .Z(vbtAK(֘@.#dmlNep_Qd.E@oWJb4r-+g!;$$ˑ 2kAΥHKdQɅjZd0NܦUOL-wkE>Vy]'>=6.&IqmL+ۭ奴Rš`bgXX)53:9p2w^NM5үWΖsMU4y)C*&i&zťYfwRLqa"`ǒH_ Xs,92d- ZWǏ9ɞjYfLϡ CfOց38z+!d9ٸwFk~%'΢PE|r[fҗ3M)ӎBŜ_.წZ2r\]:a6tSV1*nXj:(N%뛝SpX๖/1_=!~rz"&Eͦ>- 'g8ej{tkX#G/jvڭ9ѯ#L X.Y&3{zQy1.Ax T~D4 v-7}7!fߜe-"@@| Jr=@ 0YI0`LhmOd 6/;::Ðu\צ%8k$+&Wfn.g܉p~ w&T˜)i1^rV9=q_7a~IaZzmt}-&'8^Y(FM}N^8wLzb)鮐=9=|zz3ꟗ_m8b{(~g(M`'^{P)UYOd+g#:Gxs@CLzBL5lq%uFPE*EֹF8L >K%iP;&V+RԌlvaNtvZϨ4s"Q8r$񲇸n v.{d21zKY8V\9wjP=șG.z>酟eGtJNANt)>=p>9uߟHX?դdHЮhOCpZTʐL\|3\r? zy_Zj\StըW=E<e9qo^2X4WAD]&\OcߤZnS >! .saJ"_vs)䗴;ZѲ@V9@cOE.kJk6<n5S?gfiΫ: Ó#gň(;,UH\x}NG\Sd(HyF%sS\]7*^%>> V?ST5g0t #fF 2?$&[ci$wXmk`a]{;\ UX-XqD5]]J;dP߼">_Ҡ&:D=9p΍B<(C]csC+I/nM(2obr}@4U>PhcOԯBi&ϵ.h9CD͊;y55Mf6wr CNhSYl=%)?vPe'RuXz`:%Us(:Out$v!MgI4ܬBfJ|Q3{9Nj9 b˜^{WR㵱g`L'M^8!47LmÜj#O:'cC'EdV9F#8d` 97+ ==`OCM]5ly+XGW0@7`#]ӝlRFx=E:/#~  220ꝙZҼV6\P! AwbD8A W;9Pj/'Oȝ^*P5^i7ϊ%{=h^gp/8>*7CތgFf2IXt.xEd*ҧrȨ;p`\"鹪_*Tbrޅ4Z]C"̍7綸`le8U)!.u be/D^e=[j{7Q]7֙؇I_%}ŵV <ؤ?Ҟ AY-fS hhQQNMčl루 74J\ES!ևFK8 rP^5neR8Ⱥ,4iv򇴖rE_};@Q}RTQ=;g\"\$Vʍ3Li뙖ԉjlBV2A#l35lXר2,@ZݮIW7s G\"b+b!kr  U!JD,oxt3d bP vEEMFNs4B [4雲M Qsyn?c<%Tpsy# -"-[К1/#Z))y{%蛝T|+[;Gr%BĶζ=7~v[.[͉By%IoXAQXp51r`ݳrB˫t _. `.j^[^*t=r*"]Fv&$rI(# q -fJ92g y캍032 o'UqVWw)ҙ:crq .NwOOMH _3mHY512Qoԧ 枛m i}%X13-\OUIQԛDgd:luʼUKbfX^MCv5@*xoڐzswzjø\X[j$pVJ;qsv:=DZGS;_[7R[ =a)N[ .N5>߯- GNdNbԴv.7k?s,: :lUOyaaib[gzq t >?,ޘv>&7-cmN*dž3 $+ޜcw_`dA~MyOr/3~u@.7xVlDZ'VzDi&e+.veڒ5y r6H'#DѾёbg HDQ2wC¶ < 6w1 VO,uW{=AvH!ťehhaZ>d;d 9YZef[::KFVbڂ1 `7?f/EVlܩ.1lH^~a_}q׌{e7jQcXr'?2Y'/:AnT%T8Q0l ٞ)G0 ͂j[F܂g6 -[" v-Vt\H$7\2}u(%~M:kO=a 6g-/l 1 ?:_./%aglq;Ql{h+ETǎ`nrP"\a9Wu2͜hF宨 %G?Bn9_\VG|'bIچxNl LPF MSsߢ~:=l<#h,[_Z X r!,\ ¸G/‘m~3=|$NȨZIkˊZTǒ2#T/ D?jYKFg^н"j^H1^U82M8.liy.)/g\{8܀1Hk̲Bh^gȭæ<]l-J6-g@IޕwʊD詖nj gX"߸9+[IڰRyDڑ=**(p|9Kcmm|CH$RV 2q W"[MU;]1ty]өԨd(;gs|7fZKHE*W`Ӗ7ovzhJxL,=6 IE7q,iwG,oQ Ő D$M(9嶌h;1B%ϪyS-bSm,'A-P1~V0=,f۹m5]vpo:jh{ثF3/GXB{pO$KNIZ Bs/Pق6$ZW8֗Uذ{_wQ6BٙynhMHFL cOlS7 |]7Y6Bg斪~XǢk9 -/hI+Q/L/e)J%=*sftkqe|Fk6nDoƝbg_9I*X4݉OF}hĉ:gL }l g ;$E]~rg|P 06fuQ㓗FޚzQOɫ/u?}W:mpHi:g.uoX ܴ`uNlftApz3Amzs+ +=*?P7cϔ}CI TnGgrg; I*50gv:^-N#*Lf1/w|WPV H8jM#PS%֥p7ܔ̰:7]:Y%z"##wublu9ظr:mѡ:=ϻNm</!\\R4#".{&^$[ vp-u.ˀV+5D`;e-.iU.eEvOɈ{_U}.uH}?~Mg߿Q޿«D;}W5}E4{wm֟ԗg޸͟ $vq;Q Z9]B(Rҹc,of7*#+ v%rͨ!yh|y|Vؒ]5?ڏc^K>ioXSb&&&['iȢF?L}M@3i1J>-zp,?$٤JNgI_*#":ti4x1&$5rM6ᎃxk^g=GjѶ&i`'D$A_b0cAVi6J O 1丢JfQ#Q)uB}".A0o =G~Ֆ.RZ~ 1jUC&tn) `*@qFr A4So4Q:y\ʆ2h W[WHBafU,?I׮]k֚)Uj_W ȍ&O =Z]jv.y̐oɼGxuz]C_j%4 wy2-7қ6qVg~ȖMԠ-̄H`9=FtzMֺ6QR=ǤO &&JiCLx^aUUE.ouvBA9Fo_r CW |@DxB]mΪ>ЧU%FNu9/Vs 9NQ$F"ng϶ni4M$mځIS,hasjW*(1=ξ2:׶Mޟ`J0#".q?r`@-f?¢v|LDJ2߇RpǶ禦w(Rh]m#j}I?lKXئmޔt"}Zv HWXQx}L:\;IA\a:}k;Q]R0ލ,Z#MlΑ ^9gM&mLTm!PԔS-31RSӒ|JKz btmE;cP2`$ 2 3;s QR6܅dyQ^H5vf:O"&Ƣ:^޵Wj#W&P],PLj LyBB5Q0I_B򝅸Uo+\Xo\Xb k$E qs6ZY)/VDqZA'n IJT@T&3qW<J{?y7Ur|ي3eu@`6n)!$3m)=dR ^)װn97&jj7{m= ]|VoG) `ϭ: Ziocv ZVӵ^lUpM0ܿCEjS`5'> kvNVFdօ]X/E1=&Tb®_B[2\u?%? 9>d.)RYD+#7Y $:mpF9y2V [K&@ZuG"wX2ӳ/zK7b2 5 l彬ȮTa7~R J`+3XSRk4jסVq4J!gеF+!O^1#ˏ6^JWJ x"09پ8<8ljRl]%3 ŤVȐV_G"OH㜊KڅeBIЭFCC c޵=>Ox3WlQ!3 3#N@HkT;e8tO[G<\w/ɇA[Պ(@{G;' a/ ep6լ/FR|~hz8zWjެ֗FtYZп}ѻ(l K `FBd|ߐO]a]i[,^m6ջ8A%df3lQG6O hҼŘ7FS~) 6wȟ:&}r>Ps z4?(ViA c G>N䡣##R[%, >E iq`;HS;J: Ģb YRe1@[x{u "V"YE5f9%K&q':T^I?% _cB׋oYR&dX}%+3e'Ïqn OLJ6_šmAEbv <ƝC}`L(C; qGҲA22%Nbmg<.%lZ@Y F]s*7daDuѯi^h-|׃.to{ 5./3h'qcvYKKs8m,&@d)ɜZF&s9:U ' Z--9' R\NhP2U';7 m\ѵt- ȩ(JyX1U_o" zgg dChjbiNFh7u#a(s%q& Z4w?"R=8*R׎\oUz(CvLpW;( Bn3xNQԿK5.ny2%6i X2W}1v|E=jD#&htM$IJ!b6n)J9}uaQAA9]I!-Wɗ'EdFLDKʘUy|-Ӹո&7r<9.&0^0@7Wsh8K1`atVR]} dT\n&&1Z+E 8CɰKޝb $tvs_&HA;W_ZIٓ E8l0bA(b '3N%ZonAy>u(gO;fP7)lǯEb|%<*tJnM~p.7wi} ^0w_M U|9+aɞ Kv]Ӓ-_ߢZ kW|xÑyvn s 4]Y(^@q9j $>u F"O8[&CSQVxυf *PԎ-@(=F.L(; =hfzxPh_d15ii=y {-p@eZgD62Ȧ[lA]p)Sirkݰ8Jĩ16V?'^`s:32>i_m}zc8=>K,,`yFioVqʑ|.p~S5{!Ն+Ir^kG֗*x$&>[<5X-v3LF%e+j4?nς=!>E{]m]ƀ[tr攅dQ3bu$[o/M$`]3 @A;hDe|8c;^s߈am](Hd=Y:NdYgPPM?2?R0S0M, xXbI, :|FFM0p\Y YD!%'䭫hMYi+'%/&*jd+=lEW)#%xADBf\-a5Ҝ}gXM3W s!QT$m5>Hڜ :ө/&1`B6P1B{Vtr@gA:}QF+ocm ENeӕ%!GGGmRf7խ}4 _ֺr_=> U96OeMڃ*A.](>9_wLgae}޶5u˒J w_ej0:ts*SjAu~Eb4{eJGدHJ=]3T%Sɘ3Ovu,ǫjtg9corf')Ns\/k ~depV=kQkR!7OôT]zoFg^}M>ā&!) U3h΢sOA2oc˖J-_7lmS.^Ba( g3W8`[1 TTrp[5O8wgE3qwN@uE{O+ٽ[.//&mlMo6m;70j'8w1ѩZR-B7C_K2 퇶Lam'B0o 0[. tz-ps.9_93/MJ ',|s&T "0QV V*Djc)wgV9/A-9LyD =۷&AI3|zM. FΕ'mŅCG྇B#:2Q-^#2h*#йV~K˩SH?蹽a1nZ;d+Sθ Yg{| O8>I*ZK,';𙡥.7'tc`G~ĜJ~Iܵ!s&-wy- ]XL!y<Y7+VtLI_⇨9T3fJY1>U2s#o:,O.Mvd8SҌXk /z RuWٰ+xX1_,4H=-B_V>2.6s~TC,:VaƭK& .NoG΀b/f o3PGGde A{fP!y`s.DW9neUF:PC7Ae|Vf{ʎ]ttftf֏IѲ~1 ]cET<nؠϑ)"݀)p)2GJNa7Gtgc}ݙoz 4#*k7ߐ0.vbK[6,320 Vg53]|̥˪N5\ƭ=*!,ڕ(tSzkz._!P=1+5A UF?B[!sE ݵ=i% Ρ6 HյCL#nHOZ1Q `XvÄ͟,0Iqrˍ#m0%fs( ]9Zs~sS tꃭu:Shtz)\2#sqKP KTrY: K2twONc9bWw9xY1zmZ\;e[>dw2QƔ斉:DUJot]xh d,bKԫ )Xo֛5}.4B=ZKz K>Nj">7lōFwZvv\; QڨW_v+ެ8[p[zU}}8 Q\qRθiJ*Y±fӔҙT$JTo\8T٥*6D)j&CQI ]׃ϭҷ\F+ ͷ}ֻ5²ҁ3KwƉaA6V!r2˘tij2]-\W$U7ǵr2^C搳G{JA_]zc/L C]acծ`9 os5N؛'0 /~GTHcV#W]L#9W,WPn]C"ݍ/?077ɫ!zNiU3I1=և!xE]vUY2,M\O'n_0TgШMIrJl8ðFM%z?7RGorѸ[mOfKu6^-G37/J|J>^]SRC&|P6njU#q9害E3΂";׆NDXŒVQ;ٙ}gvIi'gM!\T2Nvv_(|Iƌ9'0 rNyK 5n[xiQ`Õ۪#~/`yk_.hDȖ~rf9m9+2A}~[wQS= $r}݅e,}5SOJE'/4 eRWf"KY{jUF&VYOɮ^ܽ_b:>\oе70"qKw޾2qq꟨ W&.qʛo9qa|Dw/)4ƅ .9>u'iWGKS/[$Uب3-{wI-{<~y~kxkťF [? Bs^ϙ>u61cTJB5/߹z{RA  =J$M KqŁ*D݆uFj4;uЪ Bx&x[40y/`&{6`"G氷M?.Q+\a2U;~*CF/r(*r>Վ>pcX.h3s*K0}Vޠƾ#?CV^ӗ~#!7 YZ\#n̈q&.%zd Ϸœk/IrR{mADz$1ݫ;/08Z/{̥~@d\"Sn@Mθg !xWf=}'^D+PNB3e֜zY>,M$ >Wv*\~U ?+Ra\!P9̼6 "p˝$~={-^/Kqe>#]2)Wo5(6WoλpSj|# ixofSyI ,xCvRcy.`qekKR{?"" 9UkSs E%hj/UEh7ZI;0\H4D U5}LLTB,TSFx:._ORfKS/A&[n>EqKh3p'zV5=X[ikzH^NG>7ka҈F|lv?׆kb܌瓑妒i'n1U10L I$]^AYbZkWӨ϶j̙g_yT.}sW$07070100000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000b00000000TRAILER!!!I@vл`>P}=ֵ Ĉ$& YZ