sssd-client-2.4.0-9.el8_4.1 >  A `U]Yb3l9 '5fƔ9|*w} (U>D{-#[Ep_u?Rミ[nᎠ]F[[5) &=s{:z xQEa N~ ^a rgvJ x= *$cR٤ p{ w&V:G2[IXT[%ZPy^#R_bBdJ_Vͧ=&ne/Yjbt2u|j ]0\LſGp2AgݣLzmbS(BWpmY#RZ~ 5#*ޢ|+0?80XA- 'G~M%S6 g&+f[qпXδf/͐2ޝd"#'<P۸d=].a lvHluKU*F['x3nYS74cd501ba691d25f821cfbf773d021122c18b00650909f504b384f7e97b1cf68f66e16f7f108e658c4478b58e5a3cc6451eaf1aa `U]\rR F>7K5άOq-wR;P Fa?Ƃ{(4 ڀIl9Ai2mYV:9Լm1?*hDBόd_4J :z0BoZn@j"q[WO`Ї_:BJ"2g_M`L_'ߞeY>!#p(t9yZ t1TaNGwpAj?jd  D  )/7@%% % h% % a%  % % E%  %  ! !!(F8P9:e>X?X@XGY%HY%IZ,%XZ\YZl\Z%][$%^]b_daeafalata8%ua%vb` whT%xh%yi|3jHjLjRjCsssd-client2.4.09.el8_4.1SSSD Client libraries for NSS and PAMProvides the libraries needed by the PAM and NSS stacks to connect to the SSSD service.`1ppc64le-02.mbox.centos.org rCentOSCentOSLGPLv3+CentOS Buildsys Applications/Systemhttps://pagure.io/SSSD/sssd/linuxppc64le/sbin/ldconfig /usr/sbin/alternatives --install /etc/cifs-utils/idmap-plugin cifs-idmap-plugin /usr/lib64/cifs-utils/cifs_idmap_sss.so 20if [ $1 -eq 0 ] ; then /usr/sbin/alternatives --remove cifs-idmap-plugin /usr/lib64/cifs-utils/cifs_idmap_sss.so fi)>F@2%-  Xxp K <  1 AAAAAAAAAAAA큤```````````````````````````_,_,````````ed98d957a7109e758376deae8fa13e42223d61672a4a204523dc000a0c604cccccd3e06ef175230ae4fc058215a5cd7870a7f643f4f19005d836818c019250be38400d97740435e35844a62d632fc3c2461b299d171379f2b2c82e8a153bf5a70e3059ae7a363063ee262c3170081a597c7bc3dac430d8432f8a171965bde11836d76cc0a11b6db6e84db0818fa704a6edb4fa3efde76fed5c7da27eea7f79028ce443cf2caba540f4fe225416c85060b37c9bd632c3c2011385d42c2024053cfdd90e00c7f26163377285cc3da276d92a1ba3c70d2f7b26f81f529f2959c5748ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9036c57f43c939054fd4b831f271a14c97a488c38f98cdda5e887c5d396e3b3bc589605ea4922766a5cb08a47d4c02f62b50b822023847ac590fc435672e95b93b6bded81a1edc7937dd27f4730aa0219c586310d063de8558a8e5219b93a963ef63f8345e5e19a7ea1479d30fa45bc948811dd77cadb7cb885157bdf5efe331a1c6cd5e3986e42c86d6520527f700ea736db7a72aea227a02c1eb60bd0f6aff2b66001f5a2c0849e3fc0341f455635905be77cc6f070d0d316aab8225811703cbfe794591048387a9061da8041a55d7870b397f367ef58334014e838afb7fccbd89eeb47f2b6dec48174dfed481d3af424522e1bb34f9087061c90026c7aa51d3d0014c8d4112d60d71bc4a6f21300343a05e877e1ec87490b426091f373e7bd2a../../../../usr/lib64/security/pam_sss.so../../../../usr/lib64/krb5/plugins/authdata/sssd_pac_plugin.so../../../../usr/lib64/krb5/plugins/libkrb5/sssd_krb5_locator_plugin.so../../../../usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so../../../../usr/lib64/cifs-utils/cifs_idmap_sss.so../../../../usr/lib64/libnss_sss.so.2../../../../usr/lib64/security/pam_sss_gss.so@rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.4.0-9.el8_4.1.src.rpmlibnss_sss.so.2()(64bit)libnss_sss.so.2(EXPORTED)(64bit)sssd-clientsssd-client(ppc-64) @@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/sbin/ldconfig/sbin/ldconfig/sbin/ldconfig/usr/sbin/alternatives/usr/sbin/alternativeslibc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcom_err.so.2()(64bit)libgssapi_krb5.so.2()(64bit)libgssapi_krb5.so.2(gssapi_krb5_2_MIT)(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libpam.so.0()(64bit)libpam.so.0(LIBPAM_1.0)(64bit)libpam.so.0(LIBPAM_EXTENSION_1.0)(64bit)libpam.so.0(LIBPAM_MODUTIL_1.0)(64bit)libpthread.so.0()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_nss_idmaplibsss_nss_idmap.so.0()(64bit)libsss_nss_idmap.so.0(SSS_NSS_IDMAP_0.0.1)(64bit)libsss_nss_idmap.so.0(SSS_NSS_IDMAP_0.5.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)2.4.0-9.el8_4.12.4.0-9.el8_4.13.0.4-14.6.0-14.0-15.2-14.14.3`@`T@`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.4.0-9.1Alexey Tikhonov - 2.4.0-9Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1949170 - pam_sss_gss.so doesn't work with large kerberos tickets [rhel-8.4.0.z] - Resolves: rhbz#1945656 - No gpo found and ad_gpo_implicit_deny set to True still permits user login [rhel-8.4.0.z] - Resolves: rhbz#1945655 - SSSD not detecting subdomain from AD forest (RHEL 8.3) [rhel-8.4.0.z] - Resolves: rhbz#1945654 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-8.4.0.z] - Resolves: rhbz#1942438 - Wrong default debug level of sssd tools [rhel-8.4.0.z]- Resolves: rhbz#1899712 - [sssd] RHEL 8.4 Tier 0 Localization- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/sbin/ldconfig  !"#$%essvsvukuk2.4.0-9.el8_4.12.4.0-9.el8_4.1  cifs-utilsidmap-plugin.build-id39156b8e61e9becdef5695ad3f452606d0004f548f030541bd8c9d9f429e0a8cfec9244dc63f9159987105c70f96aa5011fa1508f85cffe5caa3967f7fdd2202fd38f46c03c8877e0bebe23376626fd05d40351331f2bd22ccf969071cd2ab326363cadcd915b2e39ae3b1caf8ebcde11136e0819d8eeee0e239038e40bf4def4a38bd789d0aa4577f0d23cifs-utilscifs_idmap_sss.sosssd_pac_plugin.sosssd_krb5_locator_plugin.solibnss_sss.so.2pam_sss.sopam_sss_gss.sosssdmodulessssd_krb5_localauth_plugin.sosssd-clientCOPYINGCOPYING.LESSERsssd_krb5_locator_plugin.8.gzpam_sss.8.gzpam_sss_gss.8.gzsssd_krb5_locator_plugin.8.gzpam_sss.8.gzsssd_krb5_locator_plugin.8.gzpam_sss.8.gzsssd_krb5_locator_plugin.8.gz/etc//etc/cifs-utils//usr/lib//usr/lib/.build-id//usr/lib/.build-id/39//usr/lib/.build-id/59//usr/lib/.build-id/7f//usr/lib/.build-id/d0//usr/lib/.build-id/dc//usr/lib/.build-id/e0//usr/lib64//usr/lib64/cifs-utils//usr/lib64/krb5/plugins/authdata//usr/lib64/krb5/plugins/libkrb5//usr/lib64/security//usr/lib64/sssd//usr/lib64/sssd/modules//usr/share/licenses//usr/share/licenses/sssd-client//usr/share/man/es/man8//usr/share/man/man8//usr/share/man/sv/man8//usr/share/man/uk/man8/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mcpu=power8 -mtune=power8 -funwind-tables -fstack-clash-protectioncpioxz2ppc64le-redhat-linux-gnu directorycannot open `/builddir/build/BUILDROOT/sssd-2.4.0-9.el8_4.1.ppc64le/etc/cifs-utils/idmap-plugin' (No such file or directory)ELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=d05d40351331f2bd22ccf969071cd2ab326363ca, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=398f030541bd8c9d9f429e0a8cfec9244dc63f91, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=59987105c70f96aa5011fa1508f85cffe5caa396, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=dcd915b2e39ae3b1caf8ebcde11136e0819d8eee, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=39156b8e61e9becdef5695ad3f452606d0004f54, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=e0e239038e40bf4def4a38bd789d0aa4577f0d23, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=7f7fdd2202fd38f46c03c8877e0bebe23376626f, strippedASCII texttroff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix) "+  RRRRRRRRRRR RRR R RRRRRPPR RRRRRRR RRRRRRR R RRR RRRR RRR R RRutf-83aa0618b87e1155dd17f98e86cda5ef162625c6e2dae68741819b2f32ba2ed23?7zXZ !#,星] b2u jӫ`(y,xcOh #~S4h8>{6DXG6u0QHn 6zyOqWqaGڅJBS)cE% cK~%nI gظ+$T6TU-Y^ Z}|Nm SYw ̱'1; _gVl-FdD^?W:AB=Ey,Q)XpF+ vWq.Fk vL$hV 8,<}$|Jl_aS?B9&3^&L{y  fXD; #, DZ=w|$(vqalRr OjYt:<ȢO4/paX!e]7g;|@_ę>Vb ul:& }Q#Ysޝu0y=K2/4)SC^&| g*ˤF{^Kp5TH1<ٔKYToBw+c msY3 e6L}j)9Gf8mΪ SVUR+v1/cR祄jR;|񄱘]*, Ca壘LJ2g)%ԘSJ$㩲?xEX%rb[~m`λ ^V#6,Nlĩ40P>&fA_ fn:- _v^! :j榨ŻuD8^$5U #Wp@˙ǜgy} @k d Jyq]>}`f $_2~k]!'EG/Y7|Wݕ]LS$#UZL9 Uܭ{U0*!y_;s >isL .>rxl<_ j+32 {qA_TFE 9MUu$ge?utLF$IaCPl !Pgk)J`)&'UD{uxWE˼YZRmf,ɠzHשzA$ӊ!ӏ:]R?`sq[*o oqv2"2 LZc, d;44+;#`8$g1Dcz7&fr*|׌t7Ӻ:w6If ,Y tbI*qq#:NM94EZzE<6V.E (osE 5,YV +5 ;vx}ZQ+Wܑ O{iجBI9˘-)$ؓ[6)FOJ!M5`_Jzp7zwbfZӶ#C¾åHb}_P֯Mꗈa=TjM \2~IvL(;9P!l s(dg[CJH=r\ys5}"Ǎ(x&Q""M>,S!x*gsy1ȊŊAd*4L-8U>6Ʉ?C=b6OBv}v`pU*֦ NG J܎ U[v yMl  ʰ[f_%- ݀o ̯Y̪kUmY,0's[)?npC}$.ںx+rǶ=** Ƹfys]mO}?< PW,&8y_]hFOHqۇ:+D,-_ %Pq&9 f3m~c J~ZӧT(1xJ[Tp\(( 淘Ulc*[X֨6oA(*yחսK;˫Lp (^ XOf X[T_!}s;<etg aSB1LÙuao߃WbbNJyݥ\zA&A + r8@rh5P6)W\KW^!3&%rS®AVVϒAع{5u+W{*@WJO,!͸6ERr5,.2 ;KPlT)~JI;ۥ9AG:Q%(LSn8`C$Nðu՛l :p]GA/JW邽xZATSź2)h<ˬ}O |$J8*c;׿ܘxڎ;{]4 վ]b<yQ]ա*l1tsZb!2syާ>^Tr [B+ 7j߬œkTG61Ɠpx``[m9&+ @0ͧ~QJT SΫ1i&3_;2rP3 陋Sb䛼~]~i&dD# D%2ΤB GV.EaMBSnsyJS㓣d{Ί8dZēQ!)_|Fdv<;Cw()@F30Ìy.A|+0&ԁGƋtV(&RYf!03V bIp :DF.,$ߤ1XZЪjwp5ѤD4agX)ő (`ncrELxν> AP#O8kc <\,܂cu,0,c-|PlhyKfT>@6_#T/^X~zTwݼ9!%Ud%W1,xo$橻\]k3R j@*Iy_Ἑ }dű<ged4+=η˘R N˪R7*)Z]>"Iê*X_lp7rkgK 1p,V!+ѭqշC꾌["~:5tIN]QЂ Ԑ C]Д!OS:_2tvM WQ :Я_qdLi}l`bXy:Mk:_Š3ưLvoH8^I^T!%1#f`8 vrUpRɐ?#h[.~GW7S`|FA#.{(N<]|:SϮۂQgD++%_m/`)`1=Nػs-4fXE 9DvhcoCS*scR<63`5[r"e~ _ NWWHQ|3PA ,TIR ([0 !fpE#Vc:WJNp۟엟睟"UxGςy r9'-U]Wak&G#*Nq,욗&#zdjf8k%i&wƲʅw%!Ė|ρ܎_:6$ ݭ ZhlOMX_${*tᝇ'"|?P﷛[PFeh TJ υ>Fj,Q$H-K Ȧoƒ~%Z@> 2Lo^Te|Z@SK1_̐AATb7*,C+?jNlRA*sٺdҾPRݰ) ڐXH^tKx@Qɨ,{Dt@-OJPg[&jZbX'2 JIT/L z . n>H*/yx :rƐOW!vx?gsB-$KomU|,C6M Z[uk#;|mD%G2Yv<Ȣ3))UuS>!殬&7%p'zRpYUuGw%]}/$d☘Λ6 |=7Kgѡ䨝acV =~rƢR]-9Eت?,*Unv[sϦTu&Skv^'^9l&LԉBtd]$^1{l_襆x)̦yF{ QXL,{:XŎziLIc0bW`2ӻ-]>sM t 1CBQ a]#*QSߏQeeʃAaH7aFn wH_sbSRq Ho/@x r㟁(zr z2IE5#ؐSkS"KyUĸe4=7<MCDT8lJTJ@Qjip3>D}B6i/kF ~Gj[- 2 ]T=thg<6bBDC|롛H.0MPW,Hio&:;U+Ү5S/L?k6$>_RgXKH{|pA Z4'1>`"@>l¸E 9sw* #z]4}5-pTҷF@(! ǚ#e +Qvۃǃ#%5 mG U@5`,}z}3"\ɜ/r;lkWgG6]5 U"tt?ĠbF"S8'.@[M1#mi6 1RyŠ3+>v#BrCPϪΒj'SR䝭0&$P:{}qwcnHg'yRJOUM[LF{-y[- Ku,wtWRJwG֎``,&Ր+{ʕqib@ lXEmf ,*mkcxR1mrRa^ L>%x(/ց4 S5p&I=N e|v6n_+A2*] Aty2k VL&4@^j^X/A pc|LJו6yzqO'6߅nB267#X*L$:V` LClֺ`aK]f>ndlM S;ڽb5,< /&el 1:iݵDBR.Wmzn<6 {x9!0 z6a]{/Qn=@&ьl`!;HgO mMSIknnA12Ó3ΝJo3(GPOm-Mad"Ӑ{k>|@xCǡHJo&Ȋ ! Q*2귄VXYdB5\ =289AT)4Y=E22?8dSsDb{Go|u'ܝHVW> hVx˱k?ZT2u.&2YXY&ZR*YR=41x "P00=olK] ;xԗ'ipNKY(D%<kihإW$A˻0k_<3>I:'> -]ofl̊Ў#WLq~>YSƅ6s ${@6X!q_wR~KӚԇQ[2 .9lãenOIH^<4|0!`T"r Z}\bѺ rXF)_6uEXQ,ʡS!\sTCNVgxpsL,4%SV QT`nLyʋ}gfg>s댂"(Zv$n, W }ݼ> }),u\.u6M˵ښԴf@yKW(iSQfi$5/$ts=sbmF1$o̐ȖI]Q]d#e|ޒtQ>PŌ yJnܾa.wm;Q`/<֌< T(Y0%Ƥ٭j@=}^ nUt{R">9 ͲW"m1/_f%Ϯ7#b^]7r5V<5dV%󛟘5+3Mb8eMI%7y?4(]ɗp5quJ1J(-t'lW,J 5 Fm<:gQ6ьт#4 $.(ia#*Aw 5a ?"zc门~h/4\Ai}ȿ+F[Lt+AY(i|<:(J-(tH MZθyDQuR$AFtKr p3 )'[.Ǖ2ҷGHԜ3@UF1&f"AxtFg}Vt `gͧlsC@X ,qфXi+P3r65 &6vM9nR ߸]$M7gm9Sdh5kq:{NKI7r+{e+w-r9 kZ§EܸZ8hGoS/ՒU*.SXryEjHa$grY_]v (=R™G}/gf_k5&,2=@vaY0nmwrSYWB>ߠ/H|}}I|uI[];kv{it&?Z׌q:d8bP{:Im@Q\s/>1+W<)??ȑVUV@2kn bP:Y|@A{? t.WNV*J197Oc& S@xwor4/}*7p@ A(RK_뿀C_ۇXH-PU> t⮩T[59V+E,X| |'R%e9Hr*YR)u YzIz4qdW& mrAϟ=ثo^C}nu!x5qgWOܳ؅*kk58w`/jV6`Ise6}D)>kUhU8/&䔱*y`oЪ#?]D|w|$?i;FDë|3c UPT#!D-9{Nԝ9Tт”;b{%_vTgXd}(KYHSKȘW3j<?$3+H˂łKIq}.U@t9)#_cb7Q0yϏP` _)t2&fZ[fPY:biٗwHYzUe%.~^mcley+iV )ty@G+w.3'G;2QTtw_I Wn]CĔqkz2"rLXcYK-G絯jp&kbJ%IE.,^k8Td|Y<1|o<`g;cx6lK)(C`.O<}8b⨉VĊ#/ nΐ`vu,6x?"h IjK2eNp&,d''.qBM5/g 歹`Q`=Q^_t6g' Bf.V>30AU_J: K qXCYB10۝1x4OG?]GQ8'Љ["{+6uh{ -W5clS7bd$ӈ3^XvmsUa?豞HnoBq1hF►1W^@fj+-oWɧF}kA)n4b҄qe|Ռ{ 5]$:dy%)zzT_!5ӬÇ-ge}m1(.fMgt_9}IWD[xζ+j%\ u~ys"*"co@[K˃),'6[Ӝzx\S덃GocA?p(>[ܣ[B2=+{WtH~Utm9._SnkW~ΙPL:Yfv کou>:bU!:hn"yߞhXh|V[C@,:Zh?$P-gmOp N+4w┩L[vO^RByA٬̪tUWImΤO˗Q\[.!oq#rW+n{xs?02 O$!lu*oV,uݪe$kþ2 n]55S@ɘ֦lE[T@πu? L ( f/oXъQ}<RÞW!j7.ԩ/1 Xf%d;|`%FM' <`DU(/$ *lwsqYn =V,ÓPDrYku*l|3:Y4H4;U|vفs!')/%O~2癔\nJI>>4=A7K# $uxwuKJ dvZilS"ݠ-+P6W34Oi'?r҈U+l]В/š2Cpg:h!4<Qg X2MS %]ɲZNcGa͆x(}?U9+ig {[ &N~e8Stx3p^RLoĮh լ08f$1׆c*lګc t-l.'P\<5jo{=pnS>_.XyUj͉qfGϤ"c!g* 9+O{2WE⿑:~޲߿0& pgk;8|P8A0D3ҩ"8Ѓq!6LN;{-)᣽~p VS,4VO Hd8& P Zˑk<$ ^d8 ] O1xЌ sgS#17 .w\e9zj`{{ɅƮggO9FTej?IZ [> ^bYiJgDB |?~N×aFeijt# C/843{g79\_C #.0 u^e J EyRTiO6lp,\_MUt:p]aVmp*ex9G?+ǻ˿zrǸZAY/],zcm^)pHdpн(eh "ĪQ_lJ˙ΛpW8AVxJyV\s ݐ|#1UTI{ O);#fà#93w{jѕ_xîet F?`&!%dChSY7A.29F/>$9#IWpZkJ69e90L+:)I]kFl*8xVduDRN n+I~%\hm3pDjbhR;P0{? d#NB3PO,}GIJk!Em$@}aGtb 9,Oߌz~xq;Wl|,n9y+2~JxX]~Y;fȪRiK܁bf dv;Րb,jk{!A2 1 > M]4pYg@1}B>CUp}:ke. `)jB|5t%#lEtA1"׾[U+ю0LvJ7<;ڄ|g#Ib O_ 43 MKe!4 ^q;®Rt@rMpSI wZ2eCveu!8aDǛ;9<&-dk.'Bf"ܐ|M )j7.-W}͞| L@8堶 {)`p 'AG'Ihg<26ϵN g*__1xZvG)nsB35,1$0q[V\1 Bz~%g5o,KQCwQq$y[@kZNU |- r2pϻ'X즗CcjwBԔN֠Ϩ9r ,QpxS[00sÄd:k M\fئκN^8߿꯸ |F1 -[5OēzTˋ$}A{_Ct$֫70j?q2P9c;«7~*|wXcPR#zXl&IpF(BD}Sﮀ\8Q .ᴼdή3Czisg`,y.ջ7 ^L_@u~\ }brv7Ӗ.a._r]C9ژ^ r.H +h*ZG$FoznRsJl]@\@#'/oDmO*) Vz'$T*NJgdͩY&r}t.B.vD2꿠v#?6Ʒ'OL7;gf]3z;Y\ 㷇^OW`*F }zt0LfQf[vm)2HXFL$ fH>XYCf{^ PY`V[43Kݥ=w}dޭ8E M|aCE3AY]}> wm)9FA_|}:WJKwϞTj#|^H3 ,i2%+Ԇ@UTՕWCb1}< WXX&TOkMe:Wih$n@Xͳ$j6Z= ]ɛ`P#[,⿕-d[׸Y' OjpyC>uR,&NݝQ#P?K@uS%FHeiY I2sM&rRc&!wHg +ΟibUcBxXpG9GCNRPwPY ܘWeq7FWo@l%;i64j8d)VS%w1c{Zy$Bn]g!pD}?R>H ߙI݊$Ҕ3}S|!mQjܮ~-3AofAE~.4 tᬺqLi  0 rns>~8z.9CW$tN9jSLcZ%-.O@dp}ũ@i^s DNco^3CBܵAn%"\wfYHLe򿵊ڃ s6[w ǹgu(Z OO۵J6tA_ Mmrs(AeOonC=2e[nRDYIž,T fGOH0,+k k$hWw&F՟K1<㤄t㕢gZ7.DUq&RGrRȿmsN]`PM:8ưPh[07W xj;’8z3f<[Ip.o0ʂIZ(J^Yr'{)+q0WYn퓰QF`'q (̗gj) D;z*ټPѼJ#рq(R]&{p< [^PZ54|{k;:hh^)f. LeG_t:NL3\>|$>j$rMymЀF&8{ZW8˪Ʋg Pe%tNnUjWM3ެ6&ʢtSgKB.1-Hc"aYq9n;OX%)8qN,[Bq``ԵT%:z3 ٹڪ YnpcfY2PT4! L^fV7τUp RÐ7 ut탋rB \ɤB5hU/ |=hKu0{_ "~4UupBo@]w ]Y'~4݈_+-riI@z/C֬CXw0+>N-=; v9`6mWWyt} R[Ƹqx-\ 58Pt?EvM Փm[ӂQnۜU嚤W+<- J>2E!Ez;vZ2ґL%{`X"hqǺ۪8T5ev0M'ד]0:%)kdrƺ>I;BX/+g$Ry|eP,_%jr iɽ6Sx/O0USTvD` l_lй;kA`פwo&89~z͏S L#`Qt#E.պk59%8 ;p;z rvD|7B\ CP&7{4Jy&hOy(?{ꃠp %阫˧EK 𭺃 Еh&S=W6\+A5ӋS`N>U;"hs ޱ.x?gcaSi;/&c hpFCi`7M9{wx|Ao2uJlfq^Z Ɏ?dHkJ1YwCُ̚kv[Atx.&vQg6pqπg݌؅fܲ%`"#BܚK0 t*C.L<!_9?muclgp_۠no? })F1W&q;_QިXDܒ1{8gj- @0"ԕCYѢ:t$B_4uVKwb3+qk9pۚsnCby-3-1:WLGӊ-h CC'ŏv/+A'u,8wH /㥮Gٿ_ĢSJ)Uovӗg#I{!ʛ8F zcɰaӽ\XNxr n qMVIV *$!#*dFM]yItrY GT,ODb.9v,1] )7ee%%s[rZ!? nO . ޹ͭeP7hI!sT$g^Դ_ٮ90oŸR5ZVAoTe/(ك8WᨃB#nFn8pLucj3q!&HY^#M'Uy821gsB1VAD.J29WSyab7n~иf7pD9m_]úb3Bo瘾2gD+FP#o6eQף9RCD^߀h k٩Qu)!ȿ<֫\ɻvYjMo9Q[d:A,^(cGLR;wI9 7Io@)tmӓsUvRFz pڪa/I/9Rsk4zQw"i`t}|σU =|,S+j V^%ߌ,å9Li0i $=o2 ;kf.OSU~x 'H$|J[٭yTS/F6`ߩuX@U(JǡD9x+vmIłxj#o r8aT5?cn@af7i(UꤵUH`'׆/ m:}}*şY(48cF 6)oM;|6miχT%dY ?`am䏮>`' UFgQt"(tq2`,,8㜱[ui)z43jd|w3n҉P]YV d쇖 X?>j9/y fn+ZՑnwHn `I(2o/.%^~64L,ؿBF(:;Lz3|=> A6SSRj1OwaQ`b]+h[7aNmGc#ČD_4S^=79P&#d ?|B9"Uz)=:{ a7j b$_Of?NsElzR)iʈ DaֵGŒJ7Q.ulrNSKAWKQBTbj[WJ`񌹞_"tdvhK^jem +U+ Ert_>"Z$d&4͗{WܥZ,r]ʤŬgfonYӽζyec{G&Hɇɣٟ6!΢`H m̸ L"ށ$ GԵ*k5Qݭ ȱxt  b1sIAlB1~TuKAْf:7_BGNߍ`o_6Y_8aq)ymFNvf\p {9 > qOeyes}OQ,BY TA}鈞HaR8,.k V#zX|],DYn4J]*3m?)H9ޠrMЖZ' TN}_RIڌ肰Vyatc$2ϰA͟+{GTף+q ??pUiW5\D{mWbUpoM+L3&aE~Q龨MُfȽ3-tlLk.7B84~OF4rѩ?T,C6)whe -`H* n3Fqzk8&"ڦŰn;[O -A GnFkrm+VֻSd XE//GC [3la |~(^=Ю2PG7: FAtYl?'$Ef7R4Hּ:.r!*O:U~)֯.=[˖KH 0n FLi}!̶  cKĒ]txT*U_su'ȹxQuKNY*]'h\{҄^Mfzmg#)gK5õ)q XL}izqr) W"Uʠm~B5bxBFؓ*e%EsMNN)YtLVB~`mWLĘbe%Ґ;_x(#&6z?;J;cf zlHlCQv[7[ Q0K-HJ^$xe4$!ՎV19)9CVԞ>Pz >:NQ1THv TdzJϒYypj0p2WuRiR//d^ zè'TnQl+Dpd*56i'`es 9=RP-4 k?%(an6u)t*V[1(Mȋ"2HN8ݷxb-AA u :ͨ:+?z i3⦸jRs0$9Fe#Cxde%qCqb4g[c?IjfMW?Yzb۟ ֩AI[|XS\@9<ѲD\@;P8yD>x`4ΟBv)Ă<`h BG!(5F|)ZmkBpB^ Tόr. &pC7+q(.Ѣ'[' ;3icEyEX҉zp婁/~Ke%#U.%Oj" 3OAG_m V57Y7MB_SEzF2-Md(m"O?Ё&%c [zt\b@ }<ځRM} 5+$z8n ?i!1b gN֋je F$!pb #qO?Bđ gazOzVH1;#XBm'좽FS nsw'z`zvUU4묂7bL9o4P$ʥ %4=߮vX -oMABpwĚ~v}1'_ՄV̹v ׇ*0ʇv񡺵Oݡ`+ YbVFIO`aN|/KCX"&$OL"/6S!Q8=R*^\ Yрs_N<\ZG&v?yJ+9V_>BbYgB 1~\=L-,KLϦ-Б k (~|ɪg(NP! F!) hHs&<<],XP*@Y]R2`EQ8 ~HL~O=HE!z tVBl EzQmqIV(@Wyv&hUP !Ai=]D qBN#X=Hq)qt (C"4f7:-ht,DǮN=( /?`x%׺;&J < Va: Zcӓ0UCv0)9c#[ua@!nFi& Ek|x;H8qnt?`#|*Fc51qzv9qNSHQxe;,] {sT_QBnA`~*#%hN|ULW+y;)|]=_9pqsu/GhIXS*F(dYuctrz3/ Tvh#J>A,hrUs??}5]^Ǵ`X$ (.Q.|<|<@p6TJ!c;G,R{^FDT D yFE6S.eoboKT~C G]T mY.Rmͣ6=+vXrWK+[?$=l w2l[o2Q=E荿C-Gd$68@GH|Q(Ew yDHg\C!UC'a.6Vy)dD]._:8o6nokv!^q4/9͔|55ˆHlP|((#Rwimļ;-w`oO5yi,Fɕ 6$k@0<\5-7Lȏ g\>c17?f)"ٰ\`,I}..yUk{GUeNI"8HMEy#)^ Z$=퉝NmSv@xԧj>D(g:PA6Uo'm?[vڼO ꠙa杂}6@tM|,P4| 3PY]FE.~AxoY{ޫcTL,fȥ!P[E0N7X1឴.p̝'-x!+ WZUA\|zvW΢1Ufb%O:>Lw$w! `u!*aN2th@ %(j@Elt{x,I_*әwftػ'[ WMd]U8_4/ewjUM&6hޝ\hѽ1&G)Ŵ6Fj/9n=;b$s_69m0.U.#Oz,Gl^4R Q_ō6`N%Z 2ԊٰI+O (, V@v@`>䩺XT%Ƭ_@mBUs&nIYn =DcE16+$zPladAJT?-U!aߌЮ GնںP{{ajw۲${5?rc`#ęSt`ŀl $Iv_#F^U o14~>zYH\4UZs:e\D asȗonZ>Dm蝈#Jv eVފE 3:QTķĂ}BN?LSw ic^ 7|& (;>+l׎.?IxHc~S̹!0gV8h//`d.uW(-wOtz56j Crv6 ? ~Wqȑ[PmپB?uS {K3 A P̑fGB T 3jh~Aeߝɲ(A[#ш$`ڜ>K,;)}L';f#fǩs!$UbcLجڹ7|F̿< nYaV+벏%/]uIg%k$bI#2Z[tbf7G{҆cL]\>SZ,.f=}yXM Vʅ6fsӤ NdaF V7=R0@R(gDsہ=塗*oo TJ.v& 3Cq,WNkTQz'SSMN?>-.jJJzlze͸>qz  Mhq]Fݟ| iG]Bevd:VʭB8hrF>6L}[+ݫS oCVb>:)Gr>oӇE1K# ʟ⡹)u(\=uY6m[2ߥhWECn7޼?܊tIT&U Go~rE46jeu=̝@X@,*4/"\|k+/&:ϢWC5pI "]<f^nZL\B ׊*A+*!"(Vm)?2N-a|d $ d\t]{Xㇻ@g\>lJM۸;qh5pdPFܹEP3Ȥ%McHԥBhqJ"!a# IQXeG%/xI+6]FFl+q=¬V|$7Z˟a([%6c*>RqHc >e%޵6 &$=wE9^U5a^t[DqC lBQ`F Qn0 @&#߀d1fNLuEmFǯh/KG!zTn-)%'ŷA' ^AqZMÀMho2,{>Дn dq2C:2,C-S3|:*76:lϞ8õU >(28dt)/1Bԕѯs stoWgv pF@h>QyY jPyCpD􋂼lI󔐦k̢\}bnV 8,FU&xí":cH$rQ8n^pu[(ôC[u8$p>Wyv2>ޡ-ĦAչTo f6l^(Y~*:sS3(Za<Hk+NmOEޜըe*+CZ]V|;1fLJ6(뛩ąlu}E- Sū?Wѩ{R5=}%ҘM?ˣ]UL~*xTV+>y] 4!ggvfSҮz!xn쐴kcE?-mLow'f5ze5@bgee J{a +_}1SXxXi6NThg{rlz lևjtCj^f`GY#]g2N6Fϼ3h&۰Z@]eЂS=LjNb(KTQrP 3nueӑ٭_ZZg}y1 Rߩx'%r!d@)"Cr"_1nPo׻͟ѫ;jgFAT-.8eF">YAIʲNye 2,%bNb~7/(S&Ơ;E|=Rӄ+ n^ۈ'sRU@cj'ܖ:Ғ³iʄiq =kBWIi!_rх 3APQk o93kS̆{n6Km-c[~T$;mM|uԔG]0Dh-=@PRL<=r y?p>+= ƯskZsx8/ZGt}0bsڬ׆&g號D,bc%bnwܨi-spCt1sQ2teR6/2` Rӹrht MCP?W> g{eI*`*o#33yl ;oCϼ&'.8"6EqrG2zǁH<`# A5(>+6ʲN}"Ql#L,(3uꨑ~s3NxE2vc}Ϻ|b'F #~?VeDe7d/aL}!- ;R713ud'JDeի$1B=WS+ tbM;}unӓ)oN @ޔoBxB#VE:<@{#ڊze6%-[>!ŖH{;{>:kZTmS(>I<~>H&ʭop*+& ]-l4|̽z#=ACK=ڽhזsN(hnkUEr9Gj|wOHZ:9":xX N-y-;JJ' RHS N@_*',:g!jad}/ &wdvУnX,rnIqk.m˰}j!]"wU;:iQ(1r[옴쯜D%܋FO1(&"/t@Ō𢰡߇$nfwi@C^\pYu&$ZX.MYwF5fcZSb,lA`pr%1p. dᨃDݰC e۰B.B em D/h|ʼ tw[.QM:֍{%eH aN NK)y}!/)Fʯ*#|-D@[O&>dXzgIeG~-M͆T^G A-q#% pA%KnkibCвvmܽ&a-`F2(;JS$DX aJ-('C=yW %w> U4  "t qJ-^Zt5fAҿK 7ELhtJ"r0o21!w<QcQ#XZX34Ej~?F %"0x|:PQģ=Չ26&Lзt_^smQ&c}AAa-+ i le/{`X:'$:^g m}d+㯊xgvE0hAq6>uݢP#؎噒?u HRK *#O9k;䳆$g-$4Ɛ4Hz#x:[nc-/SDOBR !H GHD*tdw% 6(::Rڝ^Gtt6j6K5_  CTtr $һOh:}Z9&}$65"{gBf nWF:?[pv (iF B]lx{ &rB/LedcYdݪKҦX.Q X)Ch.C%<"a[T|yx ygE +qkCS >‚YZK_*L5tB. O]ʉx^_3?hڥ`(44Ȯ.k[-<(Ȱ ,>v'9.h󭹎Jr2}#ufwC7#BvmzH_c5Pƚ`%D/z= @?QfJCFDZ@2BG@滗&p긙wş5#-uRķ1" ,S&_*ܿC]tێL|֐jǂ'[}:qWHq uTWx؎4E\38C J5YbPm KJ:,6w6pz@R 7;{zH"b<~(9! s^nەiP X!TEeO$ʵO]pš PzZ ( A7/N:* ReZ&hԐ`#)A2,JZTB8̭(I*mxQ#<;s-"`hnLQ)t1}&pͥvoB@{ =wPb@3EeF?T[,rMCYfѦ?I|xY´Y<쒑N?KEݞ)Cǖx?*rG1`}}k[+&'LNnyQ/$;,(}CVV뱞"@PGS5@yG?%f)9x`4^fLA^G}eYȒSƚEz2Yw 쀗ə8ωŬnޔŰHOl46.bp8ld: C% im[8h'"U.s72׵g)S yunVn p1[ă(3JlڹW.|yOl&k}n01 w㍶}pUďFwl{6H 7 GAH O הC˘g#p#ަʴ/K>g65eoab[-܏c:ɖ9T˯j E2,֪YI~kIYHbem*~mʲ8) Q@trmlAy I${4~t {C+6>H1P3-Բ+#0}9C#nWwU.qbPV72?(wD<%D5(LOw+aQeC3ݍ*4F%8ma׀3:9'>WN^AΗ9R(sO)Z;2IKj[FXHԯ\)'/U=Bbk]uxpCɍ֩ a#-{p^XOj_b0k~VP]s'SO~@ɯa !:} >dlclo4z-)[s\Rڷ[H@qS?Tx'M [@R3939OѬS؝A/dX4{jn mAF׬}0AMz3[(bZꞳhٝ b''%npY4=uB~ofnwWf6guYC \kldP=t:1Qsq(I fwc$/ j~ BYdmy᫙ix n+:,dݼnRNOf<ycn4GULp~t /Lჿ eRas[i ?1^G[<~'ز8DQJ XGK_*,YgV=o0Pz4b\]١3vЁQo|_ȒwtQv(yTp@#?xt'ߏ,t08rl%sn.,LFϲ}۷ 9wG${;qpoRqggLRjA%Ra02誉!h`іLv-~6HP6V3C j ee:Y`zϞ4mW/Npy/W9k5wfQ}aHY}s\? ))mxE/5Q]lܽ-3{8+m]?7F%s7ʕ_ρEJ{ƻZ"ې$Q8I:$DXDS|„h=.ZcJ?&L> HofBb/,1!D>Zbޠ/ALcLȐ,RlC$'ke_Wo\w\,U RLb! Lo+mŰHZd=&%!Nq*COT<15A!@Y.8riE$1{{E-9a[(Up^ܝcӱK2V~TqJOlBVg6kkba=< ^G;1:R󟯃)D_DHML@>Zjǧ1.A?NT(ޮu\Ng2n"(7;Vu_{mkt2e퓡 fͻ/8D;`?_`]k5E844Tdwi _D:wІ6I7GW&T2˘RDURqH ߻'|?6U7BUhT\z q \ͷU@MAdgӥŅػ\%N+TW!\۫>j3n"|r$hxbsk"EZ7c(&thaF6ژΠmNѻ/W/D&n b}Tb74" `.GRpthɋPW'6#2@/ʹˇB\Oa!/v5K ik/0 5z!)9B6^ #X M>YjLE{n9O'Lzȩlygi 4A \|W 6]1#e':FÔqv%=a[i?"]5䢰m^Z c\]p*f:d(5blg3j8޸`C2XYv4i@C9}s'U kM"C㳂qW%xϰ8)$n~NȮI-mkܧ;j4N xdJwލS @nN>w[w@%@3hü 3Вܯ>sC,)6O Cw6wIM':@r 1)/s:- k)ۇ)&C̉ћcJM.#!XF( i7-m/feJDG ֌G T P\.'F6 t\=>8xr8[>7[n[_w֩5,tš3ϳ$j=w삲 ❆Z5ɛt1(jn2 ,*D\{WSBKf w)EJ4_krEowI ]ycZ=~lw÷>~#7Ep7fgeWHC8TS@*c*C+JF̳½qG. %e7:W<@ =8腗織C2Y7b**xjmLwT /Zjײ.W̧Ig) X/T+N QG VYfNPkNi!$#+BIKb]wWbH/`˻]c_qb.gwڡ/(oBJKyx"xufx#LFԐ$ּVae&/ֆڥ Ts/~*KxŊV*=º )H&Lvrwc{ q(7Xƞ?q™?R8̛q6P;j *)3n `¯^ŸeҎeG`\K?X \U=\bb!#5lsRK.ϬV92,̒*nin0ӢVV࿘An<֩4ٚI wU:{)DU%ؔ=_yk =TDxS*+As<_QB>Z٧T;{vu>{0L(w}G65Oswjuj@ehuSfbxksA{&p{>VLՈuE*S 5^}DKXov4o:Me/O *_c?q_1J[w(#8][@K>Wi.Dž]nAwqS&l)B͟P6.ʑIx&XAmCVcUB%i9ntxF쨀Dk?Ǩ*mWD٩Z9f~pذzj+"m ;3sh;6wFi(GP!q{\7@*]xd<46R.v2,`O{4:)kұ<'V:,Wj""efN\g|i:J|I%h_( Xj [9]L[Od@5MAPٽ"%]!n%c}ӡ)[5*ĒJnq P4 kUy\E=m_^8)Nx0w"W:ݝ>FfweL7pU!kEXWPԌpsi;:Q$0C#:^K#_0_"T00X s>`[*t-]ȓ48!0#{w\%neAMZ*c@M)|ɼΜEt`tWWV*Ϯ߆c̓۠N:I ވ*5BCwtQTqy?;X*YL}cUmݪX :$_eۻ'O%g۪ƩOh1DcM`xh;vِʕd1۝I"UF<%TS#]3W(f(a.‘j(vGPrs = DdM׼Dn{3ԮPT]Q\%'GtDtOc@N2N;EещA`2M{zftp1xR& 2&VgV]є#W^x|95؏, ơnc֒ A  kc$C\ WgV8M|J>d75b?kM$|f@.}\8IQ :c0IoKN Xgf:IWf&hƾ' O!V8ėQ'[gj<ǭd.\7Sހd&}a7yeo@Yr_|flɘKJ:|gjȐv:'g>(V$:#)I(3n N];8^u+L.P3rJ{^qyadiX٥G00Bf'$IImIJ0٢12@*CҦ\Tv85~%"8.;`1`-yw 1r+0}\iZ۵EQ^M~N o8?Tu9tDRx<ېk0,}[NhZtFg^>3FУƗ9s\)zȾI;D Ψ[jcX(5=rH8kÎ[HS{qL q.׶4'l>s~,? # Ո(͜ n+lҐD;KVC _o#+Ht9=[ޠ}z6Љ3bQAZTS9]q,7Ji{שN6%_6fX1:C^CQ짦z6o |wˀ8]b\|C a]UfRj8w^ T?Uӫc3RP'վҀ逈]qMAH!=ڭS:63%//}ҍHmf%2oY2Zw;8t|3T@+Cp[F6R_8+ BAVv85h4C|a ?̈WQBDsZt}.@3fEMq O"Fi\Gw { nߨGpzGL-oDzC֎IY{SVid׋>}9ҡ8[ o*}MC49VG KyO5$ (.F )&3jQ&Vn5ܦ}2 \ܔ[%"<x4%(we[)01_J.m+A)?2$UfUHB䖣|h9%e:mɹPδWlrG0|vY-ܘ<} BCwKl<r]ptέR,~qL˕Cy=^Zrjr# tGg?"z@13a\[^X\< cUؚzK4 z!.k$u/JW5֏Wɜ×B--4b!V}Ryև]OYc% {}3-Ȫ} i`t2BlBbDg;yi3fOތ( Hz|?Z8*+c6⺇JfȠNq>g5ߋRj&~si3\9'9nG%uGaٛȱ֬_zܸQzݲ.zvi" ݸGh>xX3L2dz01"#^PZudP9:< w<93iK~WLI߃Rjzes´{1OثLU|4tOحCQ8)zi[}F"5`Q:%d?*3Hqii-J!hu|*٬87|?#;:;x6HSY;~7(8i;<ߩ ߿P iwGt&-Fqo{W˲ 4W" 2GQԌ}J4ʘ1*!p=x*tMWLl)E۸i̖5Sʼn@/)Y9j3C9n);RNUWD_tH} Z6chDxuXԾ1z3\Dn1x`HEgEk/SÌuvc@w+]Ae]^Q {&!g-p0଎ EaUҡm FxTYUM^)+L4j Ύ だ:3I.=&e,5C] (etd2S<M,LT"Ha*J@i>ͿI5Ի%Vu &|57 69'76>XHVHې7K rJ1 PgCåRĔoD2[.W]Zq-wwbl'Ԗ)(5̏!Ή_ҕ\~^C lj,DW>M-9گix:6bHwSNPS~ĝLodaPU^[+$L^t1@U;`t 0 9ޓ5^)stra S9DeBiT/v:n 6 6aN˙Xwؚha,qإeIO #{ѵub\cXjqڀJWjy os$k '{Z@ U^d \ہ\V&@F%YgE'JN?V}({!QCvd^bhu$q1PYvb52("u.wQp8(Q/IECb/,:5bЎg"I{?mTdj?Yk{n싙_sW.}Gw席U9C.DX*jTQpxjjl¸9}D+Y쭩)gb9?ceglO-?B *z98q:63.2$'iR68~酘vP_{QcU!K&"ِFDn+\^_N"؉,H):YEّTXbަWty e6iClR,VЃs+n݁߇"6B^07>,FxV<<,iw6OOIC}^܉àN! ]ћZ{edפm>|r7br+Сȸ C*X]vUhH_]m!9\>pBE+vqBZە <2+G",|ꎚ.fa%6b$,a6 (O,C\FJ!tj f)`4)Z <1s,^Ū>* iw&C"5[?k`F4O 3r5{ǀdfk}߁ZFa+ -%w@sBi.enuz#iNPל*WN)Ar7 7YlA,*fL?"t7' ӬmQ$)3k2!q%Q}KA{ٗkw(80I/-^|3VaKA1qz *{ic{e:=u \d@OHGۮ^e\&!m|3*oˤ^{S]ۨYHO06Ae-S[Ùʞ} 9P瘏ԣ UEBӻő4ݠ!QCJǫC"j ;`!#zJ9]hy/mp,l*ֈ #ViZ !g̴ΆL"y}#e6n2[Rͤ [&=]':߷ gOh&_:&S/Om;YP]#S #=66܀ɹ p!n2*Q >{;]rN#rtW$(GWtuąp; NԼc~x C[١#afwΨ5և)E&S\-_o?Hq)ٽ諮NWbC-0n2H4;(+`bhi }*-R1/˧}f D6r/=*0)-<'*6E:>oSn%]C˫LTPz&H [!QeŜq%$`?ځ~ l.}"9:r-Q(uOZb1vJS rv\ DvAƉSzrg 2cݨ-a]]z]@\|dq@`Moc5n+C1:a.+)$I5ÜR0HC{Or2ٶx6K4LJdkѬ*rD]Ajr豪8b*3Ă }fimoe 8 ,Ʃit>ĭqUwzBnoΐt %l/³8(Ve&+!N,N_@s@~uk[:V6L -1W8,e"ˇN[b|cJ-e<Ş0tm-XWQp"`|j]SXcKh.]lzz mדP#N۾fkyn6+x1nwX ;^ᅄ/R/xC>.z h=vvBT/ڑ D0ճsh&E:#K;X{{.e7iz{-Uj= Q@:}Ԑ=%Хa1ÑEɅK!l `k 8([ءQf|zyqC5HQ۰ѽ< `#(CJ&Ig0>+nIhnSr;VH{ܻʾe"]#yo`gT 88O4m{T.yFvH2y:1;-q&YJm@;\69d$z.@V f9&3*S`Wh1M>ZI8sAv :5KNnPh+Uk+Z!C.{hސ XY<9nvRs+*5**xI_H ۋ7e ,n =n5\FfpLexBvb 剂z Na^y>8CK|4ka7>K*$̾DGB QjZ:`f#kct-A6=> U8zz(C?B=X* pcCyGMXxA1#4-uuN{AWu23PjJ)a$xFvgav94ImN368``悌ʨ}-G[FH$9eaO*leJ};XIWܨݝMNf;#$Hv˹~4n5=0Fb;R[):cYwE=jk|J._}Kip4">́ϕRc,lQbwB}G(Q\P~\[ROEgԚт<Y$͂Ptm @ F8Շ ,`mSPWI|ع)(@_< 5tR@wVd߸0sY.<ۻE&s~n9kΨO>SF囉T6C%SSL7)DO_ p5A硚ZU{yF( r-R7IW!@~y̓=8-{#zTCS<ݐ# [:5?yWّ 5?0 &xLza;u}'l|5Qī, r%LEW:Z>qw1dҤNp5_S.6ڋJrz Wdlłd v`@5n9 ҾdPQ`ztn7.{m ־ M0w? K8먆x̖qP|XsOLy7>}*3 d(56z%SqnHԍ iDhd‘ÊJCZ^V3KJ8~u!Ä,z4\U1]#˻&# 5gpLإ|" O77wLf>C|9 ; U&0Vxa/GW^l%Aj:W97Am0I!LZBC|ilo""07[ݭGKFC]5/ɟ+g(jqxeg']XwG٥Enb(x;BT=Y4s  IEbp_lS:YSR:Et״#k1@ap<'WSxpH>yN$1_n}@0F85#|KJ%-mfiJ$,rVQjjJl\9a HA*ڻ'>n-ń?8zC{+-,ZaQsj\crJ @O `ëԿG׭+,ٻ.Ed}T]5[='AGn|Jw+sC45݁V/H_^ i^ ~jZ;(҉ #%[EO3ЭiۉE,tk˴},ᴧ9V\g@iHձ_N(V{0oDj3m!nEWFJ|ri!C}eEڀ^5av pň*$'Pٰ gDϦ\-.K ôĞ'dM*j9 :<ǵ%p>%?e-)cy~H46\g&F(?DD&Ь`=bJRtXԲm!!8@+UIdkkI9 FffjbG|xZJb{b=pWViB>Rsv1U7b@aZu7NN ?$̺I cwO H3WV'%|@E]S;ϛ:sP}K4J[}nNVXL2/zZ^2B>nѪIb6q$tsd0?g1±H=O,lsW+H#9g@4?nR粍2 O*ඐ{q:-ˬ/RAy>}1UO g*i\ե‘GAYgؼHe?TnqN=G1Ȗv?4((@L׀O: b¦7a^ e}O jDֆ]Xj H _˦seUxܑv͒a  8DVCѹd ͞a\94- #}){;NИkyG3+`& Tw@*mVѹjTM\$ZhC!h˯z朏vJ]I"I_n+SQFJ2W`W PU M4q";1XH`fJYuX1d]~jƂ='2>Њ%|Ժ4"8ׅgRY \߼k38/yaG|Bd71m1)M섑t~TH5u\!L%2vUl4l &N~ +eYnH>ɉc}ggv$o)Fx\ہe0 @"~~f )upi?D<7A{@Q&TO:SSS;y@v+R/M8!ޅI:>Z^VcMN3Ğj U 8 Ĥo(ķLYW 1yzQ kKS A;SkW6'^Ⱥ4%7p`v!}8zfM1!Iӝ#BjfSǂRRi .UG dAevl5=1S˞ل .D"kzMMfݶ%3D@n^6}:·+Qm6J0R{,Q,,HsNn^̶znnخ雗bkZe*% K7K4'RDW "0z @5E|GY 5i| ֯N*Ku Bviwgi.n1,d2,O) ruϹi;E مN5%݉E65:64ؖ Uc.=|hɨ҈TOvvRTl[ hթ`o@wCN4EGQeAI_cxE~ ޻P6mD![ʧFQv4z\&i~{5X M+^2 /ڽؤ}MӼXHüh"/C|JFnD׻\(U QUt7vKLUEZ J Ev4ztKqeDCjaA,A?3I=85 ,Bńlv%y֒CggN5]T4̋=OԸ4IRr,@CAB/$~ER/kvjzαPe{^^ĿQdGBB 'm=,!X/h_-%`E6o,IGM蠱^.tIjp|;%j"&a"?-⶛oArC k=G&V'[^7k!6TR!gyMҋʦGD7J9\<׎Ul #|^ -%5bqf>@Ԉ>|Od\ՌvD,"G\!K]Trxvm]4csiP~^hpl~?"j_Sa_w( @g yaw6'u]. o8Zz-&nJD^$0 iDKdk 3W'|0O4h7 Zr+ tƔ7z `pM$+ ,bTNbgrXFl5撾hEl.1֥S6=xE.Z #1GԙNNs|Ʋ!5LI6_Ƨ %M1X<X3ЁhV1"Jf0樔d+Tңn.LaXreXD{o|uOOU:X6'Xn:suY)- DL z]tH,\𾱜xB{Z3(AU33](wetMCV}6Ayk1OV/V\:4X0lQPylVN݈bБlwf3Q4ei1+Ǚ|3'3{*˖ȮڢIep3yTABxqL~wx"K*l[ 譺cM0 ~&(H¯wTb4TiFF%H1OZByz^Ss^c6[UIy <Oz{/15DŤ'ϗ-|̾HZܾCM?Ȉ.*޿K/EұA]0 ZAGٿެUd*~eb+I[OK/ ?ayG6smP$F,AiN ЅIx]S\RRXFmݥ!c$H}Ƴl=MU:?i44%ӱxO%`t)hGqZmJ\8#P՗il& \Z_PհfZZZ943*U/ߔC2, {"PO`15v c?B+M¼!-y'‘፱:CI*/ϯ>Lrsv:R)uiu!1@UFtҒw:H&F= ;VqvHhr:u__'j)?l㧻c\T,޹' `=>0ŕ|lQZQ?z0FXzI{H46D@wV 1F t*AnW*LOOsYK&SW4m> D ^FxsBz4f%G D)_: ΰfVC&zH e9AܮMf&xx'$& SQU< ɟP *'&ۿw˯7Yt{h襖֞P:PK/[v+8͂,){-ٮymIC|Q(#׌*r%S<=nIk8L[ =CQTG j?/:0,9L[u"Z!`Q_D/_Ao?%O e"m'~, DNi%/X'SX"?]o"v7c㒛윴07z>JB9:H?o2#:϶iG(3{9& i 9RwSӫuZ^;|7>VPPI Qz[`&Q7mU#Zl>+]ѩq<c5YSp@r,Ms]T+ՅOX;2H?%M"7z.wJ_eCi LI$ oI̜~51O?Z#Z=2;i+c'6.f LVq諎aIdMO#x#u_Ko<.:9l"e/JmSo\EHX:<7~L:cRt⌓&;"G+"֝x7lH1F?Ȯ Ap/B;;JYzb%Uhpi#e/f{xz ⩚q4׈u k hި~jj ,O}@+YDJNN\fJ̓f狴ݦ,Oi t2ْ MeaA *F2vM07seLytG@0RָQB HOF&ԥ U#ꫦ;:et7z]n4sY HڽNVq<`'͵.j"D{ߌ2s8E(F:z =Bo=Gq0E-!؇|Z00r'x^8 -6u۔8j9)3~n]Oͫ>\Y'Ç\~A JGxt!{[R?A0Mfe7#o2+u۱)xnPˠ~8yb|D-عǔIiԯNF~J4V iDUiWJٶT2B%n1Us@_z%hJNj{Tn~ ~Fmy%܃b"g^b77qsl rmZxssL7v{ !!mcQKkԛqhLV"$2=؈;%AVVe{/# \"dS_MX}aAl-7HE^& ᛚysg0)"]'4q2;}qYu kvG`X(6CKE9C; bzs(ԡF-TH8o='?diA"<^h\C&^`P,g5 h|2)zaV1$H}.;`zJ*( \2\pV_|F+[ r9A0 ,Z6ߪKn.%"i paAWfou pCm8^xT%BD^, by]8ox)=&88X mYc;M!cN5vs*nS&y*r-5ճJy!ygʸ P*Gt`4UB5$楌725Х?n4>S>_Ne)=Qv<sj>T6(4+E:qgO7oa?ِ ϶ݰJ.#)<]vm/7+m-mdpm=ǴV[.ïFcl嫥@d0:LNP,$3ׂ]]QZOɣZivPi6e[_BmBHjΓ̩`ɷl]Z\@+4=nC`@f"jr4 &GЦ"Aσ!5-ւDV_KdT:*/pg6Ï~14<όWYa`kGU؊A&RF!&l&zZJZ@!{ߐƑ:qvǠ:Hi2cx>\ 2~?({n>0 $<@m8wpФ雸yBxa8f@~m0l^ לb.Z gK +xFmm|,>oN8wCwgDGjg K|d#a@t<-H?_ U᭑~m'f>C'|9hWT~Ke\c+eLrp*Dbo|{'GBN|{(y6~X1mK-3OBpG(?m nEڇPl< Z %BL$AbA}YG>lnDeYg8Mlv-al -YM4pb Pl)&rCI}'i9#r˰~Go>ESv8[VWJ0j}角̿Wl6U"Ze{)~f@Rٛf oRYfWR%(CiLUw:B~rw<#YQ@֦x Z&iBB6\$iTz՜M 陮N-}"s@=Yʹ@&,̞w>wbNQtZdk#W\"Rhm!"+ )Ou_K5y[BOݯBP3J51}E/݂O"8)(*H2AgcG't2_bnJL*;Ў -=nEŶ4֧ U6p_ #"')~l7σnLdHkwrلYt2͹?n">f1=kt6J {}>YƶUt%_m9TOhߗy2,ngi|9~ LA9jBrpW,Br¡@[<]f𝑎HXrJ`\+ ',E{2ӊ! ,f74!s ?0'5Kjf>T5OZ2b[!@tv&i8bݨy6--IOCkňDr2 ܢEtK F6-#ൟ`gJ( Nxӆm~tN$6^)XGg:!x]O9dQp?H0U® :DꔼGz gk'&"f%̍5V\ +C3xo`KJ&L~1sCkLp. ۹1b2{kx^><Ԇh.R`DhiY~d]a65iˋMs%](uS"ěZ5o'<e˺:L ӬvŔ$X޺ lnHLa _~B-8I ΰ(^5w3pWMƵ;ȇ7r$|:~awAK ̊<,7c~=(iykB0p?Fɳ;#.ΰ*_hSBgAWB݊ ߬C@0ƿiP0Ec+TV:GݿpBd36GK](N 5vAȔ?;0.>Dr:aIהAE'ŝ(]Bi1DIspdaW΁$3"ٯ g M "6|Gs&F-Jcu=`56sGOZp , ͻ Pvi~:ny.^PPcH@U Rn[ܧOv^zU(h24WB[-,KV?7\@iKUg2 PvSHLHmU8gnV4~mJK3`s1Lȍv5,pT@/TSAɭ-/Q9sϴ2k^=ay;:L3N%x/%H4tiarOT[&Q!ł-7 0.Bshy ۀ}x">+J-71ֵDu~ `do.`utNri 5RNdskL}j@PtɊ&:6"X8hP=ʧ{(c̈́[BJh~꙲`݋Ms?aAv׿Uys셊b%ޤ rrer7 d:c˽ R<]iw^TM@pcw0g?`Vlui0ްgӓE>c΅چT,Y4n2S!(a_bZO@!(v ';qһx~eaqLo /䘆/hN~j) @ֻܾ ? XŌ_|JY%i_i^ 913j]p,̶~t7ķ))mex:GWʧhBRS[>U?3䭯]˗14foPVp`IqbG kxvQʂSdKH:mԠ#W?eS0-DE= %MaBn)Ne6(D(Ak["/ + GHQd,YݳlP圍@am'S{6(vܜ_0uj酦gOBsOTa66GN.er7[oII޺ܟ5sZ(U-M| 6qʟK anSZ s5ԁ% U"s_NDڂO8{(2Wg]*O.0(` oK+-+)񭋶rn#-wtBhBtL8^̞zw-%8fmr~E" jӰ_<_]pNإ8/(6 8zm 'ǎ|kNr6\haO$=RN $YhEaw&A_H;}64DT>WmU|ԗͯQp\dWv/ l–RVQ&ַ51p?߸ݣ= o 2 1A@E:Q Cб#Gy'/k45SQbhȷTN4kEWl \0z1) ɉ:PQ}2VPbDZڧA;xEb:[nnN#!Sbp7F(%Q@?@e05L4Z Rqws>Aùu[Xnv@6Jݣ%|,BLq֚,G;in l`B>A v/{Wwb:,#gtcˡJhPB4Nٖ%jtYW)E9QŅ13`qg822^&nIWN+;Q =/L&UJҩZX>IˆW\r,hc *wgfhoW}>c~O`, G3 _"jZUSMjkČ0JrRe&wkL\kja͞ Uƻ++uŦ#IR7(z*yIŕIfJ` E8snyMYj:J6v<&ֆ[M:)7S]lѰ`и[h~t܆g D#;$kG)K+ ~SK[kYe!cPA%cH|`ۿ+.PV|?4+FESl;{UE9?Aӛfppţd;׸ʦ"2+ƞ[Wsg~,kb}({矊kd"#Fj2 3`" !>Nl#):&rz8ZgUo)UE❹Ф&Po*8WZNI<_SOoNlyս? 8~{\K沸"Ѓ9@TgJX%^{Ka^kGOI|t|f5@3?)١bHPzu3²#A^,Oҁ]4qYL# juhgA?T>܂K)`|ɅM ")2Q&TL)/r4qeHhFI\͋@ceS z%J9_̾Wb ԔUvݕIhzu MpYxR-1ZK`}L{<+k$n\d ဃSpw1yO $Ic!#b}ϮĕޑOxƾ `9 MR~{CC7 P3?SSW&m%7\sAd&]'nJ]i92+a<籛AcS鹴xMt<(u7J@ҽP]ptJd'uwt{X> y(v1w8 E7!%( KXCb* Zh"<3;ck'G&x-+EѶ߲E7y車+ m=_"u} )8jQkU˺#j]"Q*t7wIvF}vd[XFwT6ܬv84'wg$4a(=>j;bľi(ҷ J~iW^MuǯY ˺fB-nۉj{7#˻6 &9&T!ˁX=P)@A=RbfJ,zڼ\i#ExŒyմg!TȺ5yGXXN!6} #ԩMC-[ˉkj҂==nd %iG8YյZ=JmےJ%:`6@ pigf.Zt۱V >]\v!&M`/_"DFC~Sz;M R+m=3 i %2eE//Y~-Fk[FXwj J;YF,CElO(3TވlQNJ>`(w' D?PB^0b6(JnVp"EZ%i) 9ItdKi`PCĠqc3".~dHk4|Ϛ<^^U%"o\iz~m# s¼&Q5?dq?Ii +s\~E!f\ K9لHJ %9f>T"` : yj 6Ȫ:N;\eh±CdWUOvuFɺiԉn:Ahիy f:/]yYW"I'EN* 7$0bxz7< #M CwZ RFxa+ j,Esq%H-) -RK OxLPڕ!@1jEk*Wa/B%r6 ǸqMpTu+l1ת#,DXT:XD!L} i)#Qˋ1(Ņ:ӛl708Bn-/@ nEJrQ9 Vc0xG" (lz九u)j᪑.ԙDEզ.TF]v{ןkBcSzu8E=xjӆ?}[.9~_H0T]-.Т-klf*?\ytp#n%aOG' |A0$Dk[R_?MZ)¢+J"=@14TT+=@BWEdȀ`ZgA1K U\ {߰C Eoa 'Cb$Cڭ~H̨B LT؜z?iT?bJ\haʜ6i$߿]!ʐV;+{m%Xh<{/7G&hpY`dYjmۺgI+53{+{!3讗a|~*mCG\dw$8axBA&PItvxE^4c?xg8>_/eB&+~w(28:SbkiȓE;|y(Nˢ>Dn ۏ9dda]Q5BCu%D1Wb)wif_L"vȈ/КQ>k8s闩:a"j ߳]q~ݾވU1bi#Yqz"-huFEhA pa4ds\0Ɩg${̰jdOf|S `:kWfn"Ďfh&{K=ZO٬ah &yd;I|EӰ{5q]䅷#igđxi9`aGfږ;[M_miKw57|ݰzmC*޸I|/Bʢ&۽ N7Uzr&O*{%2 ?Ǘ_1 bWIH7(\#3C fcY|.CעRr@ tuH.hy_e4.Nhԩ%=!}yq0hZ!4t-d,dKaEt)i$Hx ˊTA ATS':!Vz+Ӯ::cz|Rٴɂ̆«ސy~6u?KWKN1 B?adCIE{I"x$2+WXB8X%E 5n,kבu9a._7=P2J^-e=ZH V:hN1wcB+E@潶c@j@ui 2߰ el`,H& 3y&giFYRZD@p A%T+lI3|c][De($0i6$zLgmcd)8v 1[>_>DRXO'‹$6c@'_z}D~\7٘˧n+z}P:>cy/tЈ=SPǟ"!"">%$[ x8ӪKl0Xs:'}olŠj;[/j+C BƸeɄd6W yȺ/@`;5wȍ=VGaCsn緥3 `ˠ^UOIG JŠU (%3RrV `2/GGLSDZ 6Vv4VD}N%I#$3^ŬZcS&O'V 1}# v:nہOzBfp"Oh 8%̵`Wa ޯb] sztWg3X^|rJ7znROIA wWoU:#iB칀XT"nЯ@C2Ix W5:̷9 EH&砫'SijYzlz]{fF~0dA~˵BKG"0҂ 8 J?F|9JIE`|EGQ1+SXtQ*Oy%t( '0]7NpR+VKd @AT,XBRlQ0﷢ >yop |@+BA/5(D:iL=Z"QꅾN'O_˔\qCR4OOVsgq͓ jR3 "ȼd kE §5f.!j~*m&SRcg1P$ht)5Lg#S x\D&9PTPױX@?9T30%lY\>2v{ԭNӘ쪻#m_-Z-flI  ힿNzc=._GhlUMGqp;or?A (Ҵp 4i ԰sl1 p0V^hsEحlyf#o;?a- ӣ3T\ncsLĒr5z%&w 85yF&Q?J?(ɕF$~$I=@ḫW8!2R%(d,rR@gqptb2{1;IfdMX['etЭTɊ:R,q{jj kө{4nݙzCr5V_iyj5[Бln$IlIr5Hz' R1(ʴ,aЌZI{@Mɭ/u0Bm=)a;;h Q;yi|.?j*9SEoI88/jyLqBQyk͖{ NBK4|LkCz/{Q?\SF֩pzbGZϪ=e1=X}!d=lЈ3%=|bOՆ!Tz MԆڂΠG{¦=#r- $a<ƶ8j} (zArR T *=7ir8@7աl9Ӗ:qEEћoMΕSlt@:.43)P> ]g޴]U72 o#=q6!`ثu_㍢dp̆Pùۦ!R%zkM`fyrt){Og6Hbټ>%7?Abu|+L xRǕX)>/=- \V0_1Od3kQB֚kvs ~H 4;!n]nr pPgvfɝ!bѹy=;`0px]=+QPYLEa](Fk 0@o'VJDJUk8n'Y&ѬKdN7kMK`1?0EMoMbnIv'Sb>i &k4 7SInE-q`N1y&Hc3K{԰])ͪx~jҭBا&iwUOWR.$f7:Z! `h* F۫e*o ڈDFCz\Jg]M}8$ Kx M/ӧ~cf(N" _!E26j‘};עJڗȞtFKaUyY[D+eϽ\=!e޿0H }7UdDTl2mw.?yV EeShTL}pyij+M_syu@(߫@ 6 v{Wa\ߒ[ړ[; &Uh:/ݗQ^I׭!Y-JBf`R \`=ނ^LkՖjzW=^?:7G^iUB5=6X) 567Z.sΓPPBn4:mTY -@L@mf3,-Wb?'HhRqCq#rXU)(g'0rԅ>0DY=_}Uh |-LS3H$ %3g+4dY9e"Ch*g%(f}!sD~]׮^/iI):Ufyl Xz'bOLvA?c>Vlb9iiOhy }. -K'AMYU4|/LvU(Jys"c5[PʵEWh{eȠi; uA+t@};F{aA+M灑;)ei޾"M<%b :*NiI7Iy˜0]^Y}߮VZƺ&'D*419(zϒvmQ4ҫ)aLCwd!}ml4mCfI=]d^wzQB"uRofm|(\H;Ab$f].,!~xT&#>023 (=uлA$|;aFatrOߺj~Ee!hm 2z"E[ff:su5dPЖEGlm3Ռ >ֵȾ h=zE^V, "o6 .Bm0Ym6|*a(\+OPeu%"KK|٨=1NΦ&:#H} RDMQ\a4Qg~3D xJ4< +"~]Y|%K&@z@rZƥIefP*R_դS40h> p/l hz Ϊ=x11tUZƭtyn"M,V uf $铑]HP^hzbYK!\^&V`2"nNҢibk>_3=m.P]@}2]?✃ľY֌{ɒi}d/ѧЫ y0ԅp=zu ;O:xcJ%3R;c9RW#7QWAEw@CܮQBAfώ Y;(Tv3<_eq죈V SyK.BB8DR^,WqN!{!#Qnxs2URMO ӳJ"ED.\DtR`m' {LLÜl ;>+8,f1JnVUoOanM,q1Yr$.zen#l^O\a.i-(){}̣7:k wahZ-p4}j~7}4kY(:Gl!@t[lAHdhCjz\<eB ȥoX~G۹N%PjGo .]IE~[*I 6Ώ{__3{_vTlJZZCu=OC|1+s@pVz"2Q}eH4!١Sl~pnOռcE w|R8p@\c)krhY-:jMՁB U^ܢ+?=J?Lh]WȮcLI\KtE&п13{p+ Ǻ^R5>A WY Y߮bf2jK+lɶ'PqBΜ?|3RTKw8jX"m)b_+ "coj|YL_B!ӄYÇh3bbȚ]y &#@fmUOwtjDg{`2<%v[V\f߻5(I4S`u' YU\ѱl{ &)BTўN"Š'w+)Zgl^y.>=m{V+2ᓩ[(f+hzh"rS&ɦsH>rZYCu ]X`e9zȱ7 %Q3JĻ|rS x4IeG)dWLix>jW*M:AJF.Uo*S\R~.۹ak~s4@,nHFsf!D[[!#/=>kkr22QTW iFN27"Ӯe$".Rb`*p'EkjΟmЙM>%i-m2f^ܸ9_{ '[|?bzpꏬ"wklŏBZ .#MF$4z:j_:H'8.; v%*n 8WJP:?/N6T^a\{q,j|c9wk.#Ka٪eA~}Bciw@ҟ'<=Hjtۨ3mj/ 3icz|)E!pAy CA: ]}뗇.$;ѿKA1r-C4,b~?nxY+y;]vRBx56czZ~ adyJ^w%ӚGtD NTb+/P['r `QŶs!!L9=B2ZGǽUR VRݞ(@yʘJV{OZ40TN,cD s\'^ɬ>B>|4c\ sB@xL>xbzPna0^|WE` f§8L~zMSc s1?\7*@KHvaBy2/h?{i~xZe,LnP !R ;31DL!<&eխ[x[/sq|\JqTk=ʴ gv,9|!MIIWlAa;ub;JdrUۆ6AeyV )Z|/̪rhr`:B2O,OYr_AIKkkw7Rs-rvNdI.9(̑!7) Udyv/Tꚶ ̘aOskPa)<.)Qp\Џ:edC8΃͈/Ѩ\4ڶ)Djo߲0a*Z5!XT|v Xζv䭢q*cmd*._ &w#G2 67+d-}rrqo+-|"+|8xpp%㜪͚KC l9YMO<4+qW#ϛMa1%_EA(O8cJ}6 '"j o/޸sݟ2EYF3𻔸Hoi7NI|:An6x+%w5 4A0%ԸJQM>\?.4#WGy$!)X[bR>l:Vm(B=6܇2~ Z$,'W$Ӱh>]fy~<[d uaˈ)NԁTA{oHT3C_KWJhfEW,4y#H Fu9kU4\*> <(\6Ee#'pt~8IZAu@6'nJ=B(߁<6J_Q.uvV`zn[!7u!R2 &i7 Ɉg!{L36@JZ#N I}zz?1A5ZFY~/Ѓ._vlZ]QG D=4TA19?{;{NY-z6s'qӼx 7j67J,E+U s:&[Ok9^ ,7[.O# QQYqIsd5zCzU46*I3(41C8AD㮝$"nG:TE3'O?Nԙt0tL~[#OdoՁhQ}OoLR4 =l^;[;@MqE:z6MI}Sp,oNL_{-\V"&;K`CnIɤ9CdϏۯ ΒUlA.'r/?ܷtd@OCegvɰ1,(HHhBlW=b0W-qmƤ,9fg ,8 zjo<ww)^Iͽ+A.6EjMT9'Rm~x3}׎)"l( 8W 7ިZuv4~ w-Քw^|IA(AXlE/Y:Hwfy}}ݺcC$^S|,k4YFsխތ+*RPZ8,! z ͐~.?LہT x aѩrZ<ǡ5qVe|1J[+9 Eakw%d& Vٖ[pmæ(] PsHzE ZQeg퓬gM7R Vs4)ZZwim]2G=pP/0ݭgNA9/MUՁUMaVdwZ~na\sjv9n ĸ􆧶[R^|jn a,P\'X&;gR"$&3fع]粡wUc+q}P꧁IԂҚhk3%ܸH$2n1{w USbF&sxF} Kzjɂ.e (U-HU.NYL7暄q4d9`$i:ͦu@ZQZ8+%s'⌾qm\lJI;6g7SWPSVwntw;3_Ʊ_ʩ & gNw'foTl[*Lxʼn6u*KQe_5( T,8yL7yKf`vN#hx"{$,LL)R}IC!!Pfq/PtX,ve[|שuUdu>7ڙ WWt7^tCt,啬y9_;, Ix,Hy`R#_~3t!o:*2B1Ͻ:yk7o3 +YoUٔeAxIOhX?B..gq܀<{7tԗsTMn.i}eD(+9}f _C%U턾*3[+|ʴF) ] BCrz- S4LQ ^āw[A"-$i{[t ?alY|UeitE "+-Gm|{,.'XqE\0P>hzvYnSHi;痘™?j M:C䍖Cf jVCZۦtVcWܟFmcE/Ԏ?u[M3p[& G뵈R(\%+lx Î:FH,`Uo1s N/.5cJf$ԳMc'Q;7?,r6q@*_JO 7p-ģK0o\1MSˍ]Ւ:}" >oBP 峴¢0AWht_RD5UΎ)%H>B2W@x^bAZ?l.?V Suumف f=pR¦Ngာs'@Y!N7qVf4s{S `RЄx}SiCʪ`Z+gg_ZGi ݗǗ_]q)I .۠.(CH7iH'8xro\V 3VµK%4H6;PtZ ?oÎ8$N8!/qG9}ݯkg}S@73>1C+ f麰8Nިl hbja6ѽUx؉4v=IiH{ep.װ@gK+=^S ѵߌq6QBWlux$+'ݰk*SP)cA,L紥h!`dR&֗^UD3e i/әttI:$; t@IVNw7 vw~8~"Yx-/vl"?0'\S{er<8,SPZ IuUkmh %h[˸vetf%*7KT%\YcQ Cj\i.ʏ'ˁrc_ tQO:} 0@cDIH5ć(ݱ^kL]d8E5:a&yf fA;۽{?F 'y5Jj&V O0e.tf"pĥ!3K~*f|k.y|,.< Km>6ŁVO @1tZ6Yg>t!|8R!:`;ݭ5D 鉶-C!GRg(T\b>׈2by[^:X_D`3("W'g\F+=)9쥔ӣۈ`Ъ4pT~N ɺ6]0-)u<+'GnP[쁬pl1WB],pDmMv (&/uڇ֩]h"٫w[%GJ=ϸ WkӝNm]Z{P_TP7tQp$/W"uA  } d>QVO@Fhfl:yYE8)L̒h6YqCDS|B\]/h:'Rz\w?nomb#9>&E"@XO3Wz,4Z+^4$= YJT٧ze2sy;8oDI!v$kskj6!۸*"˧֞?jOU8f"~-mw3ub@g 5C$\/c?0ϝէ*z Jh쫬hE:GSjHQ7Yv/_sSwv;~_ږ  lԚ2 p|CG@72 `Z![_Y*&6)n>_Is67DR[H!QLʐȄ#M4hhi݃$Iy 8bbOױѓuOJA8vC1MPFxVBؐ2sҴsΰŔk|v-YT,i}J9o4)'͉g%`%;7vI>d36ރ5~К>r?YA<-7l°R 9,OD4kMNI% ZqG|F)mѭT+`f)Tc=mgtRL,Sx_)~ZB`p= uAg.jF/u3=ۨ&y[ 号?|sX5% vO!J7% &쩔-pII)i.4.BD+L/S$\2'aL&BLl.ǔ ':}ws!>/ߪ^DJ ZǬ%wOއ CZw5]yve4C~Pd$C2z-rSO_XèH3BZąGA!ۜl/& "Gkݥ# RwΰHʇ 6)R6.CBI+R$͑sa ܺH<z3K:n >@A~LQ N!+fBn9_67Y*| >6 ^"_v0Q2YSC\pDT/BVcN3jBY!֊,??sŅjhS_zC^Wa}C}vƠt.|KDcax|V|u̳IԹgx&{df;dQ-Q..s86@ϛP0U5}Ό# s[o%jaaW|QCW^ ;)äe>/zX9ev0hi!S#1P FgpN#!VP Wy}qPn5t2RheܽCC ss&yj%NK%s7ȳ ˾+41R"$$}A1JʃxH·3eg1 )$V=yeODJrw]Q^:_ BA&āwǺ {c#.ثځ_=ʛVzk?0 mBj2Xo VuMO7d孙u;1^9w* Y}~76WO@)uv:~}lO*9s8hg ̵QC0MЅ7-1sb .7E-UZ"vq '>BX)>&K[׸@򤰈4P/\ɕ] mvp}!< 1TjرG%ޮqJax`+2uYMLe2JeEVLԁ\eB``zXƴP3b?:1dvw5/MkwP6I/ɫzޱ& _N*|>=aO\C0TB,yR\NjڲϏA\6{4Sm*8eUztڇ} #M*1Pil0`Ec,'@u+C@B 萰qu=Ց=7R5?^K_#OnJEPS Y򿧊zЉX瀙Kî(<&f8ۈc*l 55*ʋ;!ClkAƮqS8xZqz?d&U!TM=HlC>){70`"p z>#wk}/cG"unHH0L *7,UfynSpa!As^2b4]ipuv a@i`e $Og _le+>|0Plxo|6bGolr~^v9aH8GuZ☍R3@b\7UT˫K`L&N k QOҿUyh y-T4/.V6M'%X#󾡜-+W H#Oܴnд3@׉ErQr[wNMF$OS `xǛ*̂QRkY-Mh`s.V>`*`.ʣTd{·Nφ{h+FQq^{™*0U$ւwQHȇIYzZj'8c:9A]wF8Tu>xgyk=XNiEEfXC[CK\]Ęկ. sVe9-$ƍQD*cc >m$TTMmBOT@(&Bve bd /1mlC {~ V qelApmP5jV{z%6Q/V<,iyYUX'f'+U&~sv.`cŬw#a6ulט* v+ iА㋨bݵrl%Z󾔂!Q~(&fHOV M*,N +[OgvN$r̶x(SFy`B)|΁LEX;[bSTEiO uLK3 aIPE%oVQP%Zxcx,@g>Y<ͥov#/*_4DIZ߆Vn=W,[]{ᏔS{z_9oy%Z\:G/KHN Y bCtc@ V7O xZgS}Wh2фócibRm/Z*&t< X{rRŲA`^mZqYTJTJEqXP@tHp_:2V8fU @EVeCٵJߨuX/DEV hlϲ/?+n>|/y&!N_2j3 w# E)OIK;ҳ%4=Ag:ϨnjUDףHq&n cu_B1߱TzBK4'Nk[}O*&8iTVղGA]>9'z3ouDz#6Vq͂c ʞӷopE:F>(C BcDMK9]Jұ",c1Ċz\%cNiڴ"DF:q xT3snlt% Q#惚zv9d0%_(8=0i4E+gجlQe[kа JsUC4RT ;jk!jjM P:aeq` rY851Ӯ@у2$#EAڤwZztJk5U|1NnVr&3HW,.3mW_:NS嗒rkYnsR+FS}a6mR! _. bs| q$HvoB^ l^}EOxhib%mYMgi 6*V,8*D%.u/J;MwP kz޲:$}ݿ:M "E5LMɗ~՞2؜60˞ #/vg9!MH6 {Fo; >]ds!l#jMI%ӣjЮײ9 Mka|`89(ҭŸ4?7)+O}V7yR\B0bB Ī:95-!Ch= me8Veַtuh\&!HUJM_BEEުF?ZLM&.?(\"ڄU!#LWˡ پ12,nL e H aVŏݎE^7\P=gpIkmJu,C,!(EB:P</\LOKqT"|N3rI=0},qBH:dxE՜q-$וp$^jiCՃC#d%yDo$ݹ8i / }%'g_R_{A8d6=wr="ٝ_~_Tn(!mmhOI7ݏ.-z?estaFߦqLBa)Q%O7sK aC&3v$,UÍ_` 0|m^JAZa/&Gzc΄Uŭp ,+Vk"=7EuacJ(U?rŢr$:oV4 Bjՙn\Iۓ/5@MuZ.*q#v׭Yu 0Ą}q=8uC] `=&:贆ިd} 庄mss?υikUd i:zŒɉwtߑұ}-uс:bʍ+݅[xAA dt/VREl)?.P/ή<нo(\ Y^D~LYE5t3Y7\~Ivs5$2Kk-ۢ:e7;KZB/ܑ8ꎍ]OJ':HO\]yKbR,1Ѓ@8ܯ( H8%dQ[ج_hgzCN'Bo,\X &[T+v$l1'TiyKh[W- q8wK@@%GOec?1g\af2s: 6R,Ue6#Sm笚 %F'ttwkKjPz[~ p DQ.Ɲgvm+Ƿzodu,T2 >8~TVhS$KVҴ֨z9-ۣ|y9,!5jP1 1 pUA-tsP(*Vo::e5FB<>gIRGCg4 ]"`y)|jLTzgF uf뽉<ڡ]>dZ(O?X[} Gq=lG_awY*6ڹKJ T=!ol >q/.6׹Utc (^,:j1(nr  Ɣ?CT!9;l3{D_ަ)ṙQӋw=3#'=ZB0lDDj0~G>esmP%1U Cfz&{3gUɌ]~/D`cS7m13\xd+r8aH$ >?c?za 4Q-󒟥&쎅_,=t-HHF8'Yxtm6uJL`ZYUO9|xL~,Z5f\sD%ѧ{A%s)zvT יּxg/ƗCfֳݣJ2 UAG Ga&Dг&Pq4 9HG.?]l!7*y*)1 ƫ>hb$G6%'zڠЧhmOqE:wFͭ;g$&,e%]5ĝRNqv KqB^˛?˴P[qD4SK<\lbxp/,d^S4HNɭ~__l$=?; ;]񋈐~..Y~F9 ¸{7x?!qzf׆LΡ/HrYFF+^PP'K*H." `ֱ.(_+\ePmjD|ۭnܪIb7͜+"` 0߭4#Dlȃ>NQsݟ;9VͧW=+X] oA%ȶƱ#9 a BӿD hs7xdk c&U]Ըʩ|藍UyIl4-ՙ)\a@[R d\F„ ? FLEƑPʸ*v2řbCgR;ȇ($MG7bj9+DID ^%u{RAüv8;wzsr'B2㳲# Jt8TR. ML;a  .;WI>:IH=47WK;*+=vi}P룎~Z02*u#8J .)+>q~+8 ;*\Ħ]įz3ֽGM2\7Ńa L,C8R"t͟q pW}ʍoToVuZ <"j @ċ+1VeځL. O4@^ʈJP(:P81Lmuc _mWWʾFֆth, oZڀ.6mGrg0q\PYKY&9DZPU/=SOYGSp//e h6GA=%~DՐ̚lE]Juod  Szdr0/y"WK/j/ctkLL}QdɃ[T>9 9bZv@'8];\9jb,NZ  b8 qV:)q ~% >Yb W-@EDռh> yx{\ IJmzLK U!pH# ^uAݮ\F^&/ՑKqc9g>B$3~N%\ 4"g85G&x#HD 3 &DKd"*J4Nqn7T0gKfE۹/TwON'SEfZmT/ExTh;>ƣDF(ߋ&5<&j Ynh|=ф$G[UrJjW- ay;˓!#;2br3p0_F AMH "x$ԑ-?{R%3k;(0B5.M~=8^Ty ry˺5b>B0`ݼpdn^g{LA$w8Q<-\ɗ-z38˙4@qF?dռ,J/h>d5Cb@pßs˵p]K$D\ae"tHsjԉj48(F>>նD;g2B-BZ6e6$T BQ[3* ]i )1`_L8ա5,=L" .Y%Uj#LW]rRㄋ*Tۖqkz=gBGLN&BBrԊ%g{d"rWg~5(ذ)v>}'K'( X"dOzO`xD~:PE#oj^b=pԩ؀C@-Bܜ:GUVv=<73 NĎWqBMg.ʔq!DQt@m]u{>5G}B?N^ЍGDpЦ e,eoctEGP-1EARviId6.QD0 G8Tߨ-bocǦ EtP\{ >{w" M꿡0ap  ,B%dwBFQ~* @,qKD@4Q#G^r Z zG1Xp@X~ɧ&ʎCod )>+<" &dԻc,{|'{[T 9 5ж֭ӻVB-2d/ |̌\Dg,`(H*I޵ kt/ .i.0o$cb2vo!A..OHBaS\%a#4{E 7d>z4hdi .ZRZQą xƽ()Lֲ;qE[-z8ԝw.0%H/>b.Sb(%1Ke}Yó]g%&3NWXz"+؛Օn:{ rYfS+wR|+!UdgSPpn6KKND[-;-Ivy{uR^=|o~xvU3PoeS4YXhw^}>VSCj~Xjj)F3cW qL`#etnznu'[PiHXNjCĭH![M6o- ؖi͎HX(uQ,Ō>e7I ݰnvI>i]E$x}8>L˥6}n5]pP/nixhq\;H w[ ]j Ow}0/@|V(AZԶA$E`Q'y֙t|Pd{UQGƩޱ]2tw#=M F 6RL#+pRtq+揵=H_,u۟?g{pGC(/ӿXmoSy^6\R sQ釗ZM mYWv-uqfi;T@qh'Ìn_`{ݍ0 v>1D]:'K (YW<.Qo'L SƠLS\˴$zТ '1_yA;SLhV(͊BSH姌Dg8QmPF]#S!Q.S1㌞3Zp*Ck䠏9|!RV|3a Gc$F٘d@y-\K `Vj?*ߠ'u\i6j)I {CVYį{t*.y}5etyӪtE-hPIEzTZ{P0DDu6X^ ;EQ$3BQsQge֎~FNV-.RƼo/RBd^rTJZzsao3b]ȀJT }oh2 U-ĝPB\uĔK5j k/C8UP?4 L$r(O-@#qzJ#,^&z@ϋStA G_lsAHUEݎeaj Gc? V ),nli@ #{b bG6C `T˔(l'~s03P_j dBv"Ą |kwuHKG%T 0w v}L0ϲñZJ8T~E<R3X&lw i鬘(!Mnvs^i>m؄,bkp5R,g;sT wYA}oI1@zFDE51Y%^<*'.yf{@ %FD V) )H w"YΉ_6hƻD4Y4V `jFN5O~EuB 8*c?}Yx߫$(uߧ? w5o ĉt$k+UTMkW_hƾ:?߮n. &do5k69-(7#??\buđ/߻ʪ$^Z }^>P0 U#naQCi/0Pxmzm1UpU23kP;UT].SR.<8J*?$^[J'HSm[(b/\[gf_G;AĂ8LRxȵG mG<&9k\^4_X[MH@71ΐ?)rA)rQPEYwN?i݀)w|#  5v&9K Uʋ`WT{ԻZd180QidmFFyIOq"V>?ؠXDء 0N{ q'.YyB<(l줎rWjH/d3NľcÛ䦓~ juoZ8Op-؍m&^{\G!mG/H<+.F~Solm (hs U#X4ĔiXhNjUT*N.O{ߊ\)/DwE{ 4<~_'S-pp1h؟ߣT5f6 F]7-D&mt1B"|{I11nj_I+irRU ߖSeDvl?ܪ +wɂp.5I٪ayts7HaRc֢kzä6Rv闛u4rWՋ1zVkQlAKh'&A&SC]q|65k[<+QHWaTtx2_^7(R? RdO^T&Ka`=^o^Π}Etq^Le dP_nQ ͬ8OLOcujE`N#SG|rǢP+_53]ByI5̊?E;qTb>|CCj1lÈIcUB3 a0B bx%F| :m< LjoيTmk#ھq,&4DWm;dęP1ni2qūj: DHk- `#e٤!]s =Y} _Fy-Đ#0VjGpUA'L9XKBFM!_=e/CFB!A1v"q{%8r{o9l)آ{uri=-dg)%~Qݖ5`ݝ1O)~ x5va/_Pz1&}[ ﺐ+UTo 8gFIhg0yV)Qu%4S6Љ]}r ?.F3eYېٌo^墌]2e0e78\GHpx# ׹93Yܓa&95==hnbnI>RC شaMbw~PNRXʨhy&)0`_ 5gO2L,h>IxDrxCDZGۻX{'Y/uو`}J7F!ql]X} m{;e=ʮ0YiՆ FXs y[zUi0j:~V+Qw$U#jۛt$O9F ꚿ̃)v^E0: ڽ9鿹j揻m;8E4 PԮ#+ZEWVB] RyY0P]VDb⡈uZ.Rvbރv |= r@tP v~>sJMK&&50[`LIeEy.ZF Aʾ::HS_9;2HO*70 ;r0,*Hny/m%3H~K?̚x}Fl&-t޶jU+P0I1^C`pco3Fi)e={ V_bPi#^4ϋUU30kN֮~ի#KWϾ  ΆZjh4$+h$2 XuvpSo.2p˛CRH]/1gd(( !0_U@JJq2[hvR(^ I4a)  :be9E`UMïW}x]N8h]5|/U3j+(GipUr-Y*o1C`-zH٠-&ytjQz$,;ka:@'ģ ,qPHФ94׺r O4PʷźD:HC@@_Sy W/ 8W5#x,&7GݦGb{A^K'u{hM@nYl\^ d($.%֕ZlʁB<IExg_ q; 7v'=?1xj7&:Ϸs *1e^n~pPցk<3Y c% 4 U QȈCIM7ѥ8:2VF֠v2t=FLmfy7gӯ"g>r#ʷLdd&IsFzҲWS޹G|ΆѶ݈?K;͵3(-̯fx+c7xմ(څ:3UjJGrb*%ʊZAo{|wMO:fygCZGrUњ 2E),݅~N-}cF瓬3ҜqJMMLO}BU ҁt• JA f{R _zfM'tyV5X,@A-nwDq=Mj>^NmZ^Gx;nPR=趩_FYZ{~ lG]NۦZdQgD e&9r1I&x@7c&Ut>cj˱MMR7P? 뽡^(OWE꽵Blg(M[ 2%WLKκASYa5˘%j?k`W촤WN)>,-Lƴ)M] % }w~~yL"9([+xξ5ʗY܄vZ05KcZ?x)w\KoM(޹*M3Y;',cQ`{aw@w)_Ab$4[w̴v\ 4z4$T82Xq@462^8`x}8fQ[m%% 0:¸K"]T?jo2μ %97۪LkXYZ! B M[QuR?"Khtc|lm#!'j^` \(L4nH:#gܘG[`xEVI\VX +`T~ae?Ee[|Yɂ&K|_)x;ꈓDRSq)5S!3\ H[2Ot9z0/sTa1eC?tn$MDom:OєY߰;O}%ĎNk^rRN΃2|yF.0CG 8G_hxȇ6|9`V) OkZ3j0?4 :lFjq&veJ;$[VED0'P%rx_ky=EUǯb]>.rڶTLO^iJ$}d胅I9a21hvU_|̈́/|),F+\HtDtu6%e;[uCMD(;I L|3(#JGh>FIڢa.6_؊l&CZ?*GA>-GZ2m35|a jUf=If5rtLS{8ư&٩ N}Ō+ )9`FC{fK6R+T0t QYq[ Xһ=wK{O rI۶^Cqφ?9e?LgZ=))ɲD-8 Ӧn|`>\Kh.eXE짂S m~,̴̝*52Ls L&+Y}/ZAZ9LT`89iZgм KHrEf)wǦڍ)D>£1HZ ?-ƁERKZ3JBZ\3?91MC떦8٤.v7]i}9V>ϖ`!ݮB7X+TdÀ-2R> ^WjkF8ҕ0,l, "6'fz<3v-lVC)© k܊@6 U; OlQddH5*HqN \{_%zl܏~FIQֵ.c #%J9q{{Nj±}<֦&YQ$ P`r3EKőgBl5;~@3[*_*SFȱe+U& = bBe y;^NjWYF* ɧ_H,R|F΅%s6HvD{g\&b(v!ԫ{ [)֟k c\9ac Ff3*ߣJG'ur>9~K9UvGY\[=0U1=H./̂t]Q-)P#ۼ?\lYQAꔫ B KL܄6f Ļ+2t1 J"䴜;NM0(W i4,~4LPS#̉~$FOxm"PK窴RpD:eAnGL>IEN/s]gx 9|JJ@_9ˆi!Ƃ5V7!  aj+J0vo65ɒᏂ4{C<:\7_)MU囚2Fxrb@L.rc:V_ut4/?B[[3'a i3r._Hebh\{AC!i$f)uWizo#^?/{޵- -n{cN ,XU3"'nE'[#Ꭶ1&釚8<3 %iu*=b{o#[nzjG|댹Do- ()lS~ZKv/ުUh"=eɾiIkN0I~)+4$ዊd*Vz'99;:6B067Nhڵj JI}p8-?WڼUu{FA/OJ]M$oܰ@*C H]c%sLbbJMU]>FpI^t(e9Y(,k!SiX:ҀA#8{cҭx țD+YVϿ4> z2!W2@C+#xN1p4YeK-pzE"u t%᳙&Ig_|Rq I̫9$(Ӣc)}mB$gAA .XGz]Ty` YvO#f:.m0k ZrjhhA(bbh-uo[P׵p0GnS uA0e2N$d^-иa'޾͸&}q'Z͙l^|KB. ʏ%4{ӈ#wς;A Ӡ:˜pe@87=9z! ʸX9F!K2hq+Zּ§&\[X6aR>C_S.{ws_A- \)d/LɸB>9{3ja1ePbfEYZFdC/~q Uү.b1˳VGBC֐TW¤qŠryfCV'{ wVC$?@tӎfdvZW3S-, u?UG8yTdnBkc! HNXe,TpʃKq5P r $p] ̯b4ɵJ^H'zeOs.V0XpI!?S)-r_K©+ժz^O[h(Ͱv@ i: >7`Ko'8'ECtEZǝd'PYwNx #?YӘiKVO\=YȤ2)RH_o%f@NCTX¿y[gMX?T';4]kKI&w} *QY 3G":ߠ<@ViA3L1e~aZd&WlK f[)CaK#Կ% oQ_-ttzmfN O$9HO*mBnN ]&&bqL T/y & 3mXmx%C1 Χ;ޫ5(6u!H0U(,nѠV2f7KF8,E=M3W?e>Sa8bc7+NmdX{0Jf%c_ CǐIJg+ N7SUD0[T ɮE]a| ,Es{K3u^3:2.?>E?̨,s󾦯]4bc$UD:g窫, {&}Rs9E zId݃ڱhǂݵ5h.%-ya,>aK>, wy@XB`u/$QCJbmGqr@~ølNA>*}1P@g\oRݮbϪ- Ih<xm 9J=Zch3__⍎:Cs`\0o +Q8v^5<$8Ǯ%WFUC?q\ m7/KDeNi3OP@n 88U@|Kk&؍Y<7I%~~1Cqth yid&v-i/7ƽ D/NT?/0P,a\.:7۽Ƀ!]L$WL?u-Lb7pP`\3|t˾ 4iGHB~ c#Y84dhzo*9t iX'0u/. ?*-S =`y4hn4్d#9DY.2./ 207G7W1PĤˡAF`zutrVnb˼]C^(_* "nC(+vo(v^ (zZ(_k#`W[V, wGYB/w5gJTE*WVMf͡Zω r)VjpBϤ/ ׂT(Txv*^[Y"K/HTOopil; g†Luz0_߂J jM?]uPpAwe噔j6kJӍ$A֓Ji׭C$ϨjǵX 0/3RoJifz$npO}t%6{phvS*/כZ#XdDug5i59gv!4J57i9Uc PTOXo.0cl&̞2yhhԘtICLQ]wC-[~1O}\p6#R9=.4}tnD4B1 9(棲4+8j;nd3](]œ ĶĿji4&ޢHcóWl)e3uv!I~ ӀCTo9^I9JbD Ts(J:c,k#+ +˕NS3,,GN6LZeip+ga:̔ހd R ȡgk4lCPynR^kйsT"&k'I#" 8EϳkXT)W1lĘnqDwGCksChz&:oߍgbu㩛0n1L%DGƫV?TP3+E裼)LOłsqPA`Ʀn cD0<2vw$2-{/y͇Ol`<HE9aJ~$.C܀vT&EZENLi $}`؆\9^T:'QLq{E['F'K}W'"q HZS6v?Tbk|uU#G! DxϘ鏀$_uqYLĈSXvߘm \ r#{YXsEh6[=Me@ P̝Logi;ɪz͡:g$]Y~qE.+@I25Ruiu@;&O`:?; ~xw =Oʱ]];!,նF#H߻b ҃` YuLIiiQ hgT9$8n/G=4:@.tk0&y2wYVڃR>n?9]kHUDUЃz9"twKY˳=Z7y: 0S2E2)>K8%>8%N ]1Ĵ5?ɤϳ:{!*~ MTAhe㢃 GcCؓH:WժB˥a6#wN7k{Q= BK C5PFi0@Kdrά FUqE+Y#a}8btX_/lY4S۬a؂[~ P;J@CO^K@rA%9f'g3KYr}_R!Ƽ\}5U罟icQGyP͌\+Abb:{?-&ً0#|MOQHþ, G-:p}h Z"J3̨,-[=qPV0wP$ѼIՀ&+vzDm4N1$N |+dj7TB3Br&& YZ