sssd-dbus-2.5.2-1.el8 >  A `2U]cyo?x@G]ԟҺp@@QSѺAŤb&b䣶$$ofΒAq[- 0yֺ8o\uM2F;)< M<9kSgk|^f r?LOt#; D"|\3Z`Xko)9\gib> YL[2s= F,̯l~WBd: Yc=(yIh+*o"䵀h><>H*ml=NS2IsEKjY|Qw3}sHBSĚ5mnΛ@JieGu,R.X1Ik|9K<ʵƐݧ~|G|+}xSdEJ,tTvr}0Q"w*]: gNЭ-,>/t|kݙHůS^;K%SYHq'QQ(uL=^[lUw13c136ea96f4898a6922471bec0da1cb98a9e819e011c39d8f0125cc573be141f53f9e4e15ab7fd553677cbd906190100cac5471Y(`2U]v!* nSfa}T#,شln ۼu˺'3| X`YZc% Pl #wf̒VHH iȿ2ͦGg\;$YorZx(F] neȇ֒)kKX;KM&py/ljr]rQ$˓=h`zR2Veojxy]GxǮܯ6tymJ5Gg2ff+#T pxwJOx7w4JR4bW0*$I5S:c 1qO8Sk=aFFZQ$#/o= sʪ;1`ҷfinxXpBm?md   8 #7TZby8 T p  6 l0L2h2 2( b8 l9:bb>e&?e.@e6Ge@HexIeXeYe\e]f ^gbhRdieifilitiuivj$wlhxlyl'mtmxm~mCsssd-dbus2.5.21.el8The D-Bus responder of the SSSDProvides the D-Bus responder of the SSSD, called the InfoPipe, that allows the information from the SSSD to be transmitted over the system bus.`ppc64le-02.mbox.centos.orgCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxppc64le if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-ifp.service &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-ifp.service &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-ifp.service &>/dev/null || : fi%%K. ?AA큤A큤`U````Y`^`U```N`N`N`N`N4601b3592d313effe1a70c44167775b06693dc9b72e7bebc718b6c9e8b094b8f09f028cd5ad8b15e0d13531d362fd4f515952a830f6c821442cb3f901cf292a9fb41d9735fa84361d9fcb0fd98ff708a53b667b78bf1f037e4f74e07137417f4a2631eb70e5cdc8392c97e19924dc9aca4ddcf4b38a44ada079dbfd5f3b5c8738ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903cd6780e8d29b8dd5544622f3246c020c8fb3abcaef759312180e27f103315e0209c3549868a4e0d43a1f670be3ebd03a7f4d840fa1ed4df9c391656db8d814989fe877fedc3b59bb29333910f6aed3e8aa4ca6d8269248930bbe1e69790051fc8ff61ba11f53d12746010e2efa0967c251e0adde9f453978392c717dc090c100e84b412c161f48a352d79decbb5eb960e8c892ebd121841b4c074b66acabf549../../../../usr/libexec/sssd/sssd_ifprootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.5.2-1.el8.src.rpmsssd-dbussssd-dbus(ppc-64) @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shlibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libglib-2.0.so.0()(64bit)libifp_iface.so()(64bit)libini_config.so.5()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd3.0.4-14.6.0-14.0-15.2-12.5.2-1.el84.14.3`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh cadesvuk2.5.2-1.el82.5.2-1.el8 org.freedesktop.sssd.infopipe.conf.build-idb630d23c85b77f3c144165c2c5857d062a2063a7sssd-ifp.servicesssd_ifporg.freedesktop.sssd.infopipe.servicesssd-dbusCOPYINGsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gz/etc/dbus-1/system.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/b6//usr/lib/systemd/system//usr/libexec/sssd//usr/share/dbus-1/system-services//usr/share/licenses//usr/share/licenses/sssd-dbus//usr/share/man/ca/man5//usr/share/man/de/man5//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mcpu=power8 -mtune=power8 -funwind-tables -fstack-clash-protectioncpioxz2ppc64le-redhat-linux-gnuXML 1.0 document, ASCII textdirectoryASCII textELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, for GNU/Linux 3.10.0, BuildID[sha1]=b630d23c85b77f3c144165c2c5857d062a2063a7, strippedtroff or preprocessor input, UTF-8 Unicode text (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)'R&R"R RRRR(R R$RRR R RRRRR%RRRRRRRRRRR!RRRR R'R#R RRR,utf-8a318780ef539bfa1b46a242a19a28eaefc5a6f4334c80fdd6df745d40749d58a?7zXZ !#,J] b2u Q{LQ wF(2/ROl">MI<0 n.&12553K(#Ue4FfS6 ճmh%T#D,~ ʋn@kJ_rFɛf|&׿LYJπi@+ZUXBW!f?8AФ%RXoƦ> ƐýbDZPB=218HGU+͜}q%1 1#`_:< qg(`M툯5]yf s=NWc+a-`Ck]]yB>0d99(Az ]v0DE%0dy=FV5y""گyAy uSg.zrKAbvHj]1,(o$!VF/\ F*}dx>ce YNDRp\cÎP/z(&>=9'SrHyVi-'md+̫ ߧZGG/1-"ѡukk)_505_zt78 2'/9|-,,/yv;'.د-6ǐJmniu`W &P1"!}WbQQDۛmb5|Bϙ[$ASYE4 xIYqB6g)ٌ^~`-yBDb>F/Tᆷ8Gw"y"Oͷ UfP/K~+GhEc fI.S uF~Cv§WԶON#Iv=OҦa+?1bVYڙ{;jR`p֝iS,!Lx$O\ h0t0hli2r -I%J"8%#mBrrK]"h+]N{fvfO\1$ , Тl2ylkhykȑXV=~9ϒ\%fl7_P7B^Fd'OyH֋0{I[YŞ0iL[G@*I B9UnzUo.(cB2X<|-Gqa8Tx#WuబЪO~i0,B> L I3jZ™dsd/L6;We pfﵵ| wĔ L-X3E-UYQ̜~9 rW 479](n\7GtI450.U7G[}K\B̰a8X`nCB ta;TbŚk`RLQ;\s¦/TcT6k$@k%fz?ZU,HJhũšx%\Ig| 4|I=*3Ym 畬zWJ#M8E&`BCrL|LF/X4҂(k BcHH /.f:{qyS_9Ns@h d_{i} XUܽ*`m/D} cMk#@G:1׸,[DbIDu #>j ǫKiosfuTA)PT6;cHQنG+my?5 ~E56k,T?ܬY@Gm4<)AeG@azB y=X4q-j<1e6N) P{ur?A}9n'8rN(S6t !$ikweK{6.},_RwGm G &v ~*BA:0vG_&Oʈ7v$UݗssכK_Hl?PtNJ6@a@#( 2[\rI %Yep5H'*4p ggڒ^rwiFkxJ-O#muL)hRW5n0:`x(? G cP9t'`P:8(̃7*I)@'(*H\t3:e ^z*c!~-m-.P+7M'mVqkrQ_VfY}$yNC9S2&oYvu-Kaز$,K'p3 Jr]aL={g#=~Z[ޚu ƲtVe"~ej ,y!8 V-6_- (J}\y-` r8ykϯw3RDz` j+LIVB MS~J>읞c/.@~3c:=rXbJȇK ?qwhڰvGRel-;2b@x*HiPi_8בzYUMUҷô4 c>*#Zp`BQ|\dH6!)DגNhmFgL=nKɆm "M:}i,gDm* uꕕD >j*\1-u=/XH&"x֩ynL!_cb# G%5XDF($`ƞ|PYxXFVt&$W\5u9N~qaJJVYk]*&2 u |aXBs -E֫ $vn0ؤ']sa NIYUJ|@Z@mR2&( ^Ǭ4كzF KkQN\ԱaZٌiu@[r3m0CK6=bL4p.l+@Sg֜?k)thW/>E}V|L73Z?: N>HInI3 |2$S^n'ӨgXRnȯڗiU7$=/.߽t.UNxߛ:`ʆᚧcU&߬+AP1k͔Af+1R&﫹X|(XktyPXRX}!"! GHYogdsIx uُ _^ʒGd nZ*`ֶk*U:0.s3H`4[wG$ҎZkjV/'ڛ(/4زpN9;fΒC[\}o!cwp? ~51=dD^kUH[pNpS<+i2dsiۏHș$=s(=E9S3& aFWBrdݼ>gAx _Ц/Nc?me] ]t6}(Tp6.;|YC?|%4܈RCiLg[L>9b`s*>fr)&oAfaM-Sԩ@ӑ8{ Uo, -Ja 1U'=;G+gq¤'3 5"PRЩʖ U ?T&^[sCr+c@H>5}mF9X<}AK4<u1G8,R6fؒUΤ4F̤kedۥ"2>_^%\Vg+!h$nb:fȞZ@z_PeҬ>GcO扝D$h<'"&JIzp(@]xsql1 i(~bx1 3Q+J^ON㳻hJm #&2D\ Mp'>뷕/Y9ż߸n,94x˲]ǎP|v~U-#ߥwjwRukaYUS,Eܑ«}" 棐{`'4oR6N"n?rl-ۃ?qVDxi*eһ"r`6e(Q*ڙ1;BY%uhMzs1˂ zA H=e$9_h 87;PŅ{[M.@ߥ~m p/L]E &16816JD76vPB[~붡[=ުWb-BvtX*JFIH3c̴/!;s 1wG]5gskPo]^#өxU̔!@m%e:]ln]E󮋃xnT:[[>iHgeyJw)k`Tni܂ VP<8/߃~;>t }s9N4 WL*>hc@/%3n]5vHHI¤h2}@Zxvq-<;]5YWq!=QZ]| 8FKصgDz_ffcyES!&pi*2J5RPG[K}ȋCd!GF&}Nqimh@1H;l}qأ^Jη q7V ٿPg.4uh 0̩$SP9M%_u+lBb5̺!svtFNúܯ CԧEg`3+Oua +b46֑trbl kK*=-RMwpQzxC 6_x 0OnRuN{kKƴewe -1-?HyR[mfBfS*ԣs:Dyϵ  xk;6&+'ŁHtAhlp:ق=}S+Z''-7"}Y%Jtm/?8|d Iӭ{)DB9Qhpseu,[@ U I;p<Q`J&G:Ft-`Xs8kqe>eCfrEs)2Z:d$A(_ksvGyqP, Z Ë|Ug3s{/y.> O=bnY.4I=eAb&[[1++C%[xbKlm V%F{J!A~z֫6^zۦbS,ݐyz%a>#j#reSV S6H{+9*A"TOkt9ňh0N}oƒQ ;P+v㶥elVFV.Ҽ\_yŃY10]0Pq%b IٳZQϢtTp3~9K\QXn?~ Q7$E84 Yt(5wɃRnAЀ|KQTEL[/2#JB”[{[<7rMoҐ&XK+(6B/ h]D( $ӕݑd"6T6"rx !/`쨝.7,rGP(.j rM/0Y"LP!_p=~0_e_DNU-35cԱ4lK/x% _ aA<]Xךrs*z h#5녉s-Ɇ.Kqɩv1n7l Aҍ-]Lyb Npo X )A< T5I`QJu{w]Dʁ)2ׅ[w{Pe~)z7T@ ƴ¿}6UA[.}ZOQ~=[?|L RNglTGeS$HF{\mNBzF)u#XO=i :N11h jވ C8*/B˩!hLwr Bv(d)\4oiC";ͮ`7MQxǝNBm}-Wzǚ1E|)PF[uA[BIТpe`# ={?LioE"nf+Yb5 Y]Q>ntf0LrtE>͒sz)?`Pz2g"UČa^;9 6qYx1#X&2"tVn>.d4c`9Dox[fJQ$>&wUu&~ހX 8p[6ۧNdta[}%?b3^Zs&_ئ~VZsOw*!Lt~i% "e{&.BA#չ& S4HT'&ˊx;\n]m*-7ʹq~=IYP:~cʱ77p$~`Rp~$*}yb t)r]Q u jֈ?K3Z};ݰ ó@J mH!~-iwR)\ \J¥CO (> P8F@*&$TYܰv]x ި|l)ϯ򰽁4wQpl檑M֨A I{"~L{K O1*њ+LF( ֑ LlHf,){nN0ʁVj43=cBm'=F H|xzo7 zQ5+EguEbe$7N淺k I/J4497`פ֝v$y'6.䁳rI\ֵ059)|^0EwWJކ&ߖc=q>6Ԗ|klN oL 5T)^XxsE:/x F/jC)T?pͲ'izn/TH)LKcͨuB'WBa.5P>ÊYK{>Ka4QOYJl9 4e^udH3d+̟1ќwk'~LvQAifv8 yNrBDzn}3Hf?sL]z\c|&r|891"\ nyfzvM y&z'֯a#a_nT)pA1 O>~ݭTy Wfu3fQ4}]e@*>OJŎؾ!tOyejt? >ye'KFsc%kx,@n/AMϤNCr?d{s rvWh)&_u<V?aDMeRe¸d58)nϖ,mXA!lT1sa:wnWhaɺ|ܔy )\]P0,8).*+&G=$,Y6ZCA:S%F6h7uH_Rr#)0I"GJC}"rLZqQ,sps,#0"m@|,j 3_-p&SDFrzfd5VcAgFܤS'*fOL|'DSdg:̀EO%IApؗIgM9^׿,ȇY H36Kۖm[-g&XKƕt{-q}K,NjA>{*̑3w;,vvzgq/IhuO>ӺB*xgie@U§' f K xjZb,k\bYJ^,@ V̼Νӈ9bǫ0Y:K; -sQ4ɢ..0/!' =0Fˇy4e9dmˬJѐ0?/d/r:~[0ɥ%D@'JԎA49 Wv:p鬤G"oH[ZFynBVdx. amfy{ĎLݒZe6,>)e5 .J?Y[x4<ϫ/ct]b9g>x'.S=:xc E A?TkцlqR4IJu~Ĝ{'fmҔiY%ƒ R=֕C/Uh0 3-aF:Gف8\XH} ꯴2,:D}K&=d) RBUP[U!jY 7ڣVŰ1YX@4PƎ$I3*Jئ:<-EmoZON;P֒2#Usph_J=*}b| Acaݼ7 2Ӗe1;auznw8Ri-9 |r7~d⁼5PGBD% l쳭&lQy9Vk_gMNwk{El(MxҢ1YAe /(䪃1 Q/"vlV~2f}˽ҨbWs[3NqUE/)jxޡ3 Ex[6l*+EB?]X8Jm|޵&$qYTN[`^`\ܭg |V{dD@ R`j6CTb#STv>C7}܂9"p.0@E" LjUSj ۙg.]P\:g.c{fJz73j`yh-XQurSp ':mMW`NDK+SW`NThQT#Ɖ@EsYC9P5Z `JGYԏ 3sT8G3K暻&MH 1XXXn%*n.n8n;}~ۜM'#w5AE{Q%Ssjs߾S[|mF,@Nb JP\fB6*ULЙZ (֩D҆!I Hj-1d'Oy!yI;\3tL{0k5 #."k7F^2͹s Yx$ C<DPl 䏞 &A2!dMNrm)ʰ r@ࣰ;Zu7>xB!.%A E)UTE!ރ^j:j!|$w71})u8qn0&]HB ztNab>+sF,^NʦmS[=vː/`ZVXXMS̺oZ ;!fMKkz-H&qrdD&fw3x'\w=|Lf☂5o:oHV Ķ(tE-t@E؃9gY{%bH]uK3K気. 8;f#pߕ:̰<#D$4V nNuONUtC8%[evU>o(3ybleה`t'Er`(]t1"V^ Իj+k_&Pkn;C=a6lY3"9;ؒAEb7d3T5NftNMD 3)ADNѲ3_3 f4hrS}\w;@c݅(n^*O TM7-,$(I3س1։tqI'e1i͈s<0Pa jYn,<3ZX(2E1[ t0OS\>]~8nG1Lg%>0 [2_)hc7/ḧq[%[T:yUJ26"3͍iqwY0s瑓8usˁ8a WgC@>UCvڿNZIн=O,): њE|C8k^8" Yi+2`IF85 ;peI]C bV{YTbK qgTmN9Ñqn}6t,A=$ ,+g4uKIzΛSחzI * "'oe] ړvMj`?k%ޱ$ p`:4(!Wy8 X(ϊקivxZ[@#C)ެ@*SN+[Z%::8["")F4d?! J,Ւl:t]@&ϐ{kܑdM/^ѽ/: RUkEvS#tɒW;]8C@ѧэfGLNGQU#8jB!u"7ec_/Eh_%s fakI/l o][q{HB?qGRyK7LU-ڰU6\QuWoK}b}ZK"#xٕٶ5:(,7lBFCY]RTz{\r]!A|vA1.ѠRQ؀?쵽_~6toZ{8kAU$!31 N1y8UhW+p׵>f7X"v]wF=s{]-vaa1>wH_` /J3x&`ۡ:bDZdwH%e#"]O94J2elȲ ԋO<+,*PG1nunEC{5crtm($1vIJTg񽫮mBKJ:d%-$4n/_c2Wf{]t0'hBRrV|3-paLD+ ݸG:OB0;fl% H ./գ9ohc?d .FPx.p(ó8(bV)t] 8K~d|piFGYĄe \dwvFX, ^F~ )"聗i"s(3͋,2xMR"%9d`LUw[?9Y6҅[qc#`랂A~@ 5ð Q~g?>1e@_ V[ʽؕ!ܥUR=#ktAVG'TH5F>Uh@/KRc:.sK4aټa2/A 0q(;Z:fZ$/KK^I"WS :}pM6!IG:;@⍑#E &>11yhe[eJ:Q)Euy#FF_"Z>T)7'레æl4[B̹&4)9] (fo1a |/j!ܡE;7?!7 =s3"uLӌ;nQo:.;˒^cjh=? =S\6 \$!ٗM]QuKNLzB4QJ8CH="̾4-O1GoN Ko- SX |_euS4ǔ$]l'nymF] =`TW]d 0&/#هDlp;ēQ^I fŶZ |u!b ݀l\2EWԔNz{]D$56Gp;rg/! 0mQpڳ`}] 4UakBC|aX,xJ jys^-]!=5،aN)U^RT $H\ό>M_ 4ʜԙ䌹f[Bmdn5a"Cn T"R0(O=&nWwSonߖ4@RRCA뺑]mB`Bp7]PcayUY R[jF$w1YTYO K%;rl!\za8sV+w?ryۄ7QNĦ^ |1^s.`;"//;[͔Njcq]5+z?ӡ;OJjŐo- 4+erçqv@ޞ53~SNẋFKWˇTWVw>"͂wU{\@D:VX+R1԰*=^3PB}:-CE;{*kZ(aª i_6v)ü,tPhCz[\9TQ>uboh<t `Z?4IdJꮹ(REY6Է(6gG L)?˴N z>%zlA^~ݹKPI2I{s^*᥮(1V29R9urX#`]Ttqx(oYmE*MT>?g"*YV=_~g)V %g@%Xȏ^匤qε xȠd}IVlfʰ,3#nfR8\}@w YY*LЭCd<$pAz}KC-Fkv" xo((J~ܘSm.餛*@'lI,?#ƈ-KT{|) )^=SB1݅9Pu'ٟLW`s޺ewvi!f)f;ySqT.[q7uv5#BhLUZ @V|88pl`/vK+f1 z_ƼPzS,{EiŪ¬Y-^X˘-( Sx5X]~i@̒ O3LV{0"i;/W=ԾPbQe60/ @06Mh;OFh=:ӹL6b43ppּQI`[Ft- (hGA͘ۥ7 ;yϋJIj(_ۺsD&stzBW JWv:&g]QqЛc_g)^PfZo"B{d&`nqR%_g#ٜI4hۻ\dWFxx)-?΂Jp%\(|{?|w噉u:Xjj>(ϛZM)EDXJ;p7f{4U|DZG`+A$Q ?=5'1̝a.]K}t\ _*!r,=o^bǎ 3 LSgTE&~ߗ̆Dj\N"tB6[?jȊN3 MS|kSzTÛ^=]9l@y.$XYSMn`8Uҁʙ-6GyQSAٳB] Pk簧p?s 38H@YbnW^zU,%Fs̡{ 5NC(^s-{nשi+1e߲mC(A3"]iΆeHS6kfniM|W3I8:.9AHJ%(@o ,"(^dJo@I&'C/mS+=ZahBA~Aq/ne"]SZQğs*WOOV=PZMTFeOcG|4x^h[Wzx{^ RFIw4a-7SN&uC?:oK=3e2ez<%u%MK'wWI=p0pfSEziϫ(ڌ `kcR0kV% ')}hC6Ō9,[GuUTxq$KEo>*(-ye`ei3P BɛWC%KἒW5kK*|KҺ#=~ /zi#tӄ2a,"r-[WƝń%XTK8E3 VfpH.>nDsS,_JUB#IՁX*yW:w! `G~gx"gf-KB횞tف ΕϻxLw Jfbe`0~q7{%*4y[q;dːy&{m5a!fq+2J\wwqFj$@,?ҋ D3S!y4bOsb(k h9悧IqT#ZL7Gd-c KσHYs.ṺL1%cKJh* #<S 2Jy:m55JS;BK7_nCJnu%(☬ko^k^A| (+Hf*i$=xú3^B 7CR6Q~O@T߂LBmdh&a\yp/t5skhڄx99RC)-03FQ a Ⱦ._r4o7JZ XMSbJF#Kp,)*y^l蒘J!w!kL#%N4uZbXR}~.@͘0Hshl|dyӂecR n4B\ݟpRPi APL1ݜ5wΏSWc&bO 6H\#5`W377vL+rIBt:SPYZK|doOG<{OIv,#ey2)8\طGy @M3&ivYXdAށdě)(^jÜ^j$95-g,>BjӃ7y{3( |d- {c Okڈ~"1HPG}!Zn;c57r>3C FʃF%;??lm|]3V~i[9X]:etwm*56w.L04Or۷#mv=h"+"r{7km=bÖ(l@{!ɦs6w{ `{CCi, 7qvw-+A0\_46N}{2Y1Z|_?kQԘFq}S-Hvt*TYRtv49: ?OXZ_k"{ev8+oj5(X!F77 , CN'Qg#YX%QnplE؇źL@a׮)UѼY&XVO> 3&h6,?Cnãbgn|;Pep5r^ܤo/}`,\@bh K˓ʂA%ƭ\6T)wnEV21q[|e]r={@-X&2jal_ئVXveLMI_ G41Q؄`}<"r 'Gn5u6VC&s~kF6+290`Q'[b4g*{NI -_ϕ>Ra;$ ; c BҚK-&wlRf/Q/QqC|Oyu/ 2EF. KŸ)d(=Vw e`an3+v~Q!D+#|C8z91 wW5(> %<6Ҹ, )GVD}X u L6Z,FFL"%œi!fQB03'<< דg,{ج| oUk54H F xLW9k,(Tt15PaxXMT{u>ECAes%tWsޯBv̗62݆>~ZKKZr@*fUi=Zy*q &΄j1ٖayRS!RXg"IÃ()NQjZu3W, FC) &:j BaXЀs= w6:,&jpC_pe¯jF}JȾpRrNͽrAsCYo7Ma.A[}yxc^)nk/)=(P$n ʁ[J\R?R?J'ɮS:Il#L.Ȏ6}+A)*[!|>vhoi? JNKG0tXJ9HEq> mnBCn^dr&8zawciϠbטuCw1@B0h- ,F҉B곧t5E@NoAym# *"4};յaTUIHk]$/-dR< ٬MTVsvWY|4=J3 MȘn=^:q'2y3LBZNUWsB VY&~ 9l{Q3qVa+ r*&8^/IL F,4̴0pd`@V"$=z. ?U= %?RۧN#,lKg.e~y OQ$u%$beYH Rpl_&#|AIVTds">< tY0ͣ]23dui*s$!7|kCbJ\祉rS~U^-t8@/df3rOv!82A'9ުK=kx]WIE! "͋N(nf$s -^'54a# d+n"U$R'G/h]xt}(UH4qFw%rgߑٔKUZa$dut>;Z5g %<>C3ܬ/5 T lUr'p-03MA(:f[8Tұӱd],tfd-1Kzz!EdHPRA87۹YSG6kɅ8 g)LJ1X&-O;жFi$Sz Z i4uG> ,%@KGBW?_uk -Q[K!Xtŧb]o( Θny|qPh>.9E/pqk{ڼ~oyµ1N"}@pe}O1N)=muk92D[̏npɦ(s89w,cjO&ٱ @QQ^S)`%'[=Vk7M^y@;T eX/bj0YTPۦъ^m׮|7@Ϊ)L!ɭZ 4lv@X<40oD 6$\eh}zkbV1@V\LĶyQA@Rg0gX(7_vFɐ|HEt݀1G 8 ;RпZv |X NĵYN1 o菤Xj %bH)*d'-Hl v^CYԼ~dmvQXm%!t*h|lMT$m'T?j>d= hB܌ķ9"ޏm Pz(F9+Ņ:U$=06J-vG'jĿEM|PSzr+ 8e ȻsBt=|"ègjRō)셟aaF4ZL[ybÖ7" 2~C:UENthavp6F'{5z]$Im"#K8ޑIw5~a-jrؽVIv(Z)yղ69Rɬդͼ7 re W"D߄3e |QZ%oI-ʈ)0~lwrT Ypy__:/I|&n!u4n Iysyى\\J^jV3I2JH:Uofer>t@YUY.k`!9{PG(C6// JsPݯRvˈN6T@iƭ&KY֞').6<}x(˖?Jze&~'㞶ATGjuΘǏ n]Ĕ'Gh?MAZJ.P? NP]hwcԃ^$*nlnVrQhJ3џp-`\6?`l,WqU>4 lY"8hk:rd@-Gɞ |KHqHƏkz@*'ե :*J?@ֱhK\[ԺK(u٤l/`lӔ:a4mAٕL߁ \+&f B&wBg)Dfڅj @*\s`Zx z1ܝnQ j 1i1ǀԾ tXd zp8xH/9L嬀Z$ae'$3nji&ֶJGcBbHt8- Uw3ޅw$؁ oij7j,P2;B#賠F  2 ?lw_GA&;P㐘W"1*[~\.@s7Y&"*?pYzikr}]0,;>%{fNNy~\I~'υ,%1P=>4ࡳm0=xM}2w_I\Kb]^~z{3alySG~zC5)2੃b g+<zD>W~s*9J{/D0vqwLd㲀yhXX갛Hx1Do*H^',J hqY6 Ά~Pv(=ϧd0w(KŽ!jmݗHԔiЅƸ6vx iw;x0dK}9;6LdE ⮰$M?8ےnMyX2uaYmj9[Ib7ٌt")Z1P ?R wN ²G'@4/ϮMp}ng/ĪI0',*gkU޳>t }_u=6xZ\-#\dW2i󈢏np)T9=FXZR+aK#`nЭ?It=[/J ؖ]~MGwckެO ho~ښ'GeᦵȺL ;Knܭ"x1#.'P >pzQ*3rx!Uy_o*KZU H.#PL.R*\UK#T  =MbcgsS3u7aJe#GMU/]tPSn7TK Xu^ƫDƯ~Obj1fy@W@OjU5NЮRIWX"mߗ{OU%i~ [mkGH{g[ Yh 5Z) Ef"1 ٩F,P]rj {[Jƒ_kCJԺ=Qp6%kVpwHipVىū3pOeug_ء "t}?7ғ9mΝ+}b`J'B'+LYTi )<߹(|Y uA0opvZpI.XKЗgUh:#!%ǻb4H3gE" ,%fkg~)@U%>1P*&ݹ.e_hWo2T.a`qF?&kl& }ӀmG|1zKYGuH‚SA'%$ᷔBb6Ɣ>^ٕw$%%'%@u>J bh1qħ{i>3eO_@{uk_*G@¤VD2~'>C'|:H4?ɏK}圐7@Ь% *G]yT6nC!eK?Cֺ\p=ןVdS_n9C&&qE5y,O:7hDq¯g)RCX%Tt5 E8Diw>`=âE^B_4s"'Sɟk`|>z70weHǚ:dś;f鑎[ђW D(E)B78f~6DBVV,d&0ZF(s:;װn·;Xi,7'+LSFm'Eu`Ehk "'* yoJ5#}QrHѕ~$ tZ+Y6?dk3!WDD<2B.V{ %+H҂|s'mpHO>h3 cv94Hx^Œ::ʻ/RIǶOaN̤q:sū/k5۫Ixi6Y^72-+tKP%Jf";e)oyp3C4LFU9Ml]x߯3͠ҵD݄>`J*-=2ɺ6ӐFVxP@R%•h%{SVph7;ܧgmX\TĎ8z^VY(V#>|+1.J^UGou>g庛?o3)d?Bu:,M|\ũKm]U.ס C*d*a Y0ЏI",A-[01zH4;N\- :]I& {qԽ}I&R[dhm đO.,_[hM;+YN@/bDx%&P<sEtAe533*~+fRHIZfոy '\OCcXlFt20ŲKabJn}ٱ(I#\|hAD';;N'#Ʀ^)4W/6=E) |}hlZqgħNkmdxH+or;'O +Habqۓ0i~}=KH]ZK!.Ȁ8%R iܴt'lzҤ6žkC=L3q8CsiJĢzl sGPNz,z;]P-j[{4S sr&IÑ?oapH Z^l{X\-zsãg"6˩4v>к7ѡ^t]f4J^|xɘw;1)jI9eD|jz^H1_Oyean\S(P-|4`A^t`Ds 39<( [p?d(< r6D)h;_ZԞ'_b)g+h^$6_q(e zQlYeuXCYaySyN\Ŗ3e¾~%440~Q}t~!gKTm4K8H@g09Su~AM@jbSWEH.~C©l#93@BeWW% $p|]I6q#d_QxGEY:_L,SV1йgZr,ochW@8;;`7jheQ sg DF7gğMB~q@uZҐ1A7b-Eh ^JWXCPvv/=\ edm`{>SԙӮAflV>ƕy%ZȢtJm~"OY<5O #.uxsx|WG^jrZX/|(m[zB4oP)T ݦ~JꚪA\t?XA2ZJ⥰\C+Y/ߧ0с։-o p!'j0AhFE}J#ok,C>?s"FAZ|\1`uke}ib[СrD$qBX]ٹtOH[ZZ^+>Ğ|Sj1% 2h!Z 'tu6aQ?-qQLZx qhr=n~g{44UݎPPHz` <#uim?jDγ]8tQp׀ Ex0WbTSe2X x(_ F 5VEaWO?qᖬzVxPeP{in) cz){UNJE7I ^]π\~$<؀ o&icVbBj g\2SuFP.uNJ\Gvޜx="ָBd] 96[PeNp{:^W޳-VAd 眒+ph0鋻*D0.L{恾_0xӋ9{,3AxDUu{JM{*.΢ȶ_`Ui5 njNָ, iyA,65Aj;z_ta e~}cG<\Yq |DKv_֔ o*{MT 5n؃{ա*$3:(ʪTԛrmC2َ_xՄ<;%ӬQCpoƄcV?[1*n͇x)pJ'eCSCcd&Neh UY}Wez77Zz^vǨgOI Fd{S`l}2> ? [F2܋MTLMT͹C>3\(AJ2F JsJ2O VXo%EE7K$jfjv9!IqwWu*4i8@$j,1&3$ Q[Qc ̺Tg>$lH8%M&pO4a ?NJrPR"eOuW# ʤ(k4Sݍڌ7$nV<50z:űd%IȂם=r]&QBW\nOrc*dA?;M ц@~_&ON;\ '5.$ rȍjM")ou_x*@tsJ<f $K%ܦ3穀ր!idͤ>(P4 0VsH=ݹΓP<˦ v9PpyRY%g=zT{H.SH1 9˵7hv A GSTjwBtP L1&RXUD٫ R;.FY&gcfK',VL _a/>B@8GmKšSY^7{jUgL$fm&v 'zaV|S5W8:2M`n {%8ނ7A,9>:O@QWÌgv33WaXnTO#ǻkR _P!IcK1Dv"6G7J'pmM>/-I$l8|)wꡂ() B8wԽ~GO5!g9mIb(`v^nU#^U m\ b.vuQ4o\eYz1SZ]h4vɀ8WԒzw^.0Do͢y`B(`:pS6s&Kzm)e!Bi:*/U1lW P"g8695֘U۬@3lK4\g*m1RFS$ N&tA.Q-GKI.ORĉ} 5`t>.cEyʹGi9Ns"B, , $KNE:q*R"zCTN23 xdMvj>LsJI/0n#9}%mrg/Q$]q5 s:d/Q6cF',{q%G"E_0N0YSꃥY~pO󸰘KFJLpvcéoـ!m{yJAء0?/KVeol}̔ Ķ4uL7!%xO==YC*FI%0I-fΓ1I\ eH;oZI%$*,x] }TcnOKΩ g&]e600a:s}s\caL zNMFl(MEaA4 MY"l6|ӌtCQDN\BȹЭ j&3eG@.!]鞗T[hKTԙ+W6~vgT1hj@t.PK&@՗Ri~.Ý驤;4"Ͷ%JE0:j> 8@Pr}%aIp qQ٪~`%?U4{5]͕7@S eVbǝ(IЏ?.m~pc;#|sŜż`L|=~(bv0K`YW&F{$2'Qp.6Wfr5}Ib]} i#2#B#ܮ!TN![Gn(@!-#sfQ~kC* P>eLƒLj&eNZlR%71a@+ae<`cS~`Eu {n< 1>׀C؇9F oBGqg x*U4#!1A9%-j^:\MaHtL7S|+FN'\diC{p풌2!5~*R^EL ai"z0\HA_'ͯ?oж!o\1l] R&(UcPϚ[Gϴ1!)~^)޲!δ sn d֙tb?=v])ϊB p ڏ5IXZoXM]j5r<->3J!, q/;1?q[{D`gS83"8Pg;5@|&"*Vދ6cLçIivg}s^:*oc<c*Z{|^&ނR~u8/]lQM6(r2c}x,Hۡ|Έ% ;2%#A95i Yٞl5}cH}<(]Bʼ"c^ [vL1IJ%~#Q "9089#Rݔu-b:A/j$U{k3 Ϣe$:}Q*J@XrMne i^+[GISxKΊ*rtfMF:p٫NueT`FSͲ-4)LK)'Zp8#Ӡ8!"бP1dFR\[!T d'SKkLPlT÷x>OQY>Ax [J PvtE$9Rۆ¸aǽr?-g a1|.tT\=m_eUKd9^lv1mR 5@nÅe fF:.Dܮq-:$_@(A Y뼢(2̢}C^5 b=  L]S4@ga+)y $\.óڻ\ ph-vtF?b5 Fem^CqXMCG˗ZMci{O y`7Vtbą>pQ\?};|<].'$2} P6n "oyKsܩ,sukͪN.jAG{_ʒ뚜 gR(=jQ|#hQ؊2L]_=N~d3P҅b`.4@ !L]w__YE: V_W "wU}o`9{[&SSfaU{WdH8]"/ܓHVbN(yr6KD }@:uJLٛ_F*kٞD.xl]Bzx},}(0du /vvDwFo|UV 14N¨*]%5Ee粢֠F,-W6`}zjj(pȹ |ՆaP(]}̓Z}] &yN.\_٠S$_8.寸w k7[H3ɨ}^B;%[N(! =$>u; _*LK^tİFd&qo x C|JCy8mK72ٚ]yH W?,:jЉ<%D@>_F| F} \9&rd#PSt0QdĮȟ Hua$])K(J4&6>b_^'b /%\juz;[6D[?xk :6 ~jxdzq"{fퟏMo}.=*f+/B?N٠S0r~ @_V)W*<$';8bD!&,2]W*S:P'q_aHnA c W,ˀscj0B3)s(5sO$ $GBg) }T8K%j$pXۯO9?J1_`SaaH%}s“1ҵ,\%Uݣc豨NX`[)N.-A'K/1|ȪJz@j'ŧ[k,V4Hv h(Dȉaxh/bx-CafveWAF"/Pӱaμ8-IQbF f0n^gݡ@tn&YۋGy~_VZ{ŕQDZ~q9upYCE/U M%\62*9zATl@[ cح>5aV\^;ݰwG@;?Wfn0Cۣ`VIFc.9;vrEKڜ2h`0(dd4@GRA.Ÿ۸`AoҴTsX}DKaeLղY{Û}6iB?:hE+ߧ̪~8K19`=l'$$ǹAlj蛷3 !+IMtS-K%)ʼnIt /$M  07I$~ęLfQXR|Nk*}Xm̙+&5M(lYCBf߲U\F酩{,m"\sC!#UWƊ/HKu33#򃝧,I twY9C-@NXi1D1OY@HR-aQUb# }])}k!};2 .GEG}-ED h\\Le̵/9(ЅR},2W9?ړ'&+X ~ߋ*7LZi*!"MSdBGNKa\o;WkM|,a 0=*0JLyw'PWGLۅϋ@=)Oοc:/e }Աy֡վҞTJv <#zp R'31!@{ԋh'[6%*Fu]8ŅGb# @p*AmE#^tP#GkУជOmU2cfrgؖ2 grr`QWYˎ$$Dc  }cr,9%s/D9FC(vL}ϭFlZ)nsf5%@QO"h(mg=yN#@Q]AVFyX`y!}4*3CKke-p}4d#^D3h<]V8/քul﷞$R2hO Vc:Ǝ386К[Ы&X-=jI23Tvxcܭs 1Vscg&~MϢ9n.4LG۪vc.#cȺNϲ%g>@LѪ'eK"ǽ13GթQ)=?"ғ$f#-Bf3b.0(. ~fi-Y}TGae: ˏMY>; I r4AxaG4W|4ʔkq@]}ġfrsi(QQWם\HX ʞF9BN YυАV4qG^l&.TX ۨȕRS`@BꖁaI[Vg{ 9xaAy` 1KŴIKeyJ.WηD+@ڽ*R8$@jCd7Bi#rcsO8{"܅=]oԂ^[aXw}mUuy5އ׌ym'<mSdŲ2rLYNKUj33kLmZq2ϊA,kmG sP6ϪmiPM9.=J8xL0W]*-/Ֆ40^ZDa!JBaac 2WݯWL) fk P|U67ʛ((Bޣ;:^tWgP" i>p.}9?&Vߦ_N TJSU*7j2,2L~X3D;?1&/ y:[AT?Д;$MI粒K b%MpdhǰS]˓qO&(OjnRє#2C?|uT>t0qwm ^ԝNz.|e5MGJSW<SჶSEɏI’8!J1PKxn8Ov&}SR^ToI.OzrA]YHd`_+ʼS<=a:)fF(^ң3f Inc_.Y[.G?7(/7 I`d1N.!ǾI: LYS%gbO pƝ,iM~>5-&q$:RJF1&= Z6f? 5**3 cqxbd'IU=;siĚ܁5l⠿uK }[Eş&{XMdHǰ1#/ >Gi"\fCQf ʶ'0BԖⁱ,+ҩ)EIG+}7wveFP)!G7T\۱}jErT%,Z|G76W߉EvrG\JbM oJVtAl9m|4sN\KWvV*7\ګ K!\1U["VeMa7}j7b<lXUn*/k 7ILx l2Jۡ/+, R{C0obNB djy*1!%NDCPz]יk%!~˟}+)X:XuM!hx$)=}rYm\&.L)З~ Rs"nE,Q{Dx>͚ E~ R%/; (sa'F+`f#/K,2rυMj cZOHXm*DƆz*C* VJFhzFqUz$N'zy)'km[WPE6͉ r1U\{VzQ\ݜA?$R %Zŵ?K<#Fվcn.1׀a 1oC&:0c R /Y/On/GF!FUQQ)]0)ԅHo50^K&h$, ɏ3 |A cq&q(9QJ#tq21@eg'ρOO,51Qe2˟ %&p3-MI(ik8fzh*v>Uο[xGv|Zs|\Psmr3" u bHCo {mn_-#kQh ZST05kͺ/pwL3kk+ok" /vX@Mzu|YtnFyc'~K)SZ>|~={X4\-{gGٯ *r=bo,-I ކG)= |a!̳Ý!:J"ÒX(h n# O1DQt_ ܎?x cYm+rhK}|> ;e]`];*S?O-#S,Q;Ŕ 1$J&I -FBU Y\A/O-U[ym\fp*]S~C%:h0ڀ9?7lֲg@A SBEB'I4[?$_*ΧiI 5I ow:B9y$a9)^]2; 8=r8٪KrH qiY8Byz"XzYTknw Q Gkku?Q/5>3 i[`W3N>rVS_G #c}Yϣ1כtXl -z Σ~;KN޹9qAܫp|`'HZUTiԊ*ʞɦcߞy_T̔j?aΒ 'E>Sx fˎ2b*d @SF6u%o DyrD4 P028>Mlmj|$Ω`Bϭ{߶LJN*yl퍃[HEݬXW ȟ *{]~IQ 1)JDdxoIl2B~VCux\?1ih)W; l%{=V )/XeO2EKD,cuTX8F,' ?(NYŚ8sEdck04m~DaFJ;9.`XG\?◪\ћޢw2G๷sFd"4T70=s}A_S.m{63\آՇͨÚFʋda_3.#$XF4fďl]bkJ2mh?E'C5.uTu4r hfU g#;_D,X&6愩cG9+50 mآvVQ aKwtf:Oí>< TeZ3M {MKje `4A燋 hA -d$,! NTXeR(4߮2e|E)%r,:$?RKK— [.~׭Bz5r G=e; O%̡JBL pC'm3ǚ'3^8} h϶UJ.B2] בp@H/2wԀii`$1TuJ!Q0q| Et |C냛:`Tvd*<)#J?+5Aߒ#i*ւ u&d6kIV;y16Rt)b_ հh01%{kbkA!JevQNNފ }OL&d6~7&AHHLڭ} p*1me,]"Wqך#YG~$ϔX+ņt$0hh,׏Bx:BXq Zr{KPPm4AO>W&,__? |i*]>x, \,Rwg6iL[t,⢉.`[auI{r638Ѧee$_SM4'hC6XVgJK-dkW{;'ב=O\jwDW!s`=;^Z>*%mB"uŪ VȋAiwc~E_ٯg_"wrH8JR":eVS&{]a|{V1C{m1YO w/>SfxAbԂ{HK!g9?7v,1prQ_Vsz)xoNŃ`K6"mA>I,@l ?WIu:դ%8#PuR_ bg<VidxlQ7jF㉪ Qüsψɓ)b.MUzB1<0zM Wv\MA*`>d (6bI +KG]v$Hx&*'nb41eT{6S$7a?b s3Q,Xp >~ZFI"RGzo0mLq\׸&b@xzT b8ďn6*xRK^9"V V/Y92 xlذ)lzWх?w~TMK>nnQnaFȘm؜6֓T营T.uo"{lnbo CȦC \"N{>] {yy܊ӓ-3 "|KGWgAIn67?7_n''LBH쥗15^2jK\#nqfa}-DLLA7A`j{јe(j)-dcmzq4u_Z=?(GBm3l @zBs;/:VxIOn EqB8~xrZQUCQr.-l5]sΑ8rWfWy(Jc 8\U~*4Hpfap,a5 O1IVAʷ(s_Pk5ic5Ӂe<(Zc2dV>P[_\7\k 8+^qY7S CRqv2'Ίݾ"c-f9\9ީP7B0Af0G!'yj@ YDq`#hй> "!ү,9 ySJ 0_TNJaV>?$g+N-GSxl*&L"`{0ye}:mҭ[ۏ$aީ"TN)ώʈHk= G.~/|pRdсQ%;#6Z_-K\͗S7ӈjvgsFq,f5͜&,"LDp)V G+㟠BӄU6yx^d5*0ג?K^ӯ>_\`]fly~rQzhss+uo6dXUɜPoh񨖬W*롔~z3_ٴnȉ&wQop>Dq`HRp3m(1 *t+6s2Xj4bgiK^65{p0bnK1v( Zݸ01C'^ͷƹA59)t:E|{V^Wk505-,ɂdNu,OP ޢaQV>64䛨Lo1Ȅ =w؂"p/C5`,ČhޘĆVl#oJ{/ǫ=<ڒnՉϻ8%GO=5whB&!+s-?@HGKSD,rPܱYR3\u{+A?r+F3~+\9~x8YƠ6kj4BTgITݘ[yu{ qlD~rb|Ju*Ct2gi\Ys4 hP4s(jL9Dͽ4%?`]pNCEC[\jGbSzZy8q8}Khn09l;Jţ*p"(Qj_!6W3sZF$2Px qW|F 7ry^n}&!hܿZ=a*JqoY<~|(;Y]gd$b4ܣREҋ]ofon^!e%1K L|*b~BEpHɡ$h2Dr51k\/ i|`f Lmo'oys36=-L 7ӶG, z:ha;XCpXҴV*m)CϣaR#2*0Pr de"\C{D]2`-Ƃ'Wn]fbY8$,FyK,l],\ızIV#f28Z 9hTbWﱆ @=V=w{zk)Οߣk֚֌KVKi8o;́ []/ e"*#rGKHOC^)FkoKvW6ǩU~$l7m+YG^+aK x/O㌘hYpe,C6OFlǝy&6µ>Ɇ?f WaD_0ѕ@҂P4OýV3m_ sB)l!l:U ͇$SPtJ("B +ͫ!ܬt&K7<%IF zf}'?$ne#iQ) 0 ^5.1T:72TK Q b.歒:VRI~V3`GgK=+=wBe5Q¸w"PcGQŔVCuedz=g7-Q.el?GN2is1S>Z_.QZM.׼[hxQ X+. dT=9s1u$H e_)_1XJ#Rba2?'> z'7~"[RNbUϰ_@Hc ta`z)|kuJHJHS%lO+)abJM/j4j%3kڼ ߍc,-)F05OGWNKvV5B'| ;(Np͍Zo$95]EҔ~ZFՈIa:bxM'2knbt=LaV6:k8&n[,Or"U5&&]Y:@쥰?b:s 7*ZE` A˂?\h%'&*uk]bpgyj`H ۀE[Y#޾$4op⽺( ˍ?s8]o%N(C-o3` a[IM~]ć7SR x݁n; )Vf{G|eQ| @l+V{0ďJ m _tBf IfRs J_;BNLG@JP|}z*T[pq}jzP}2_>%3>+XY9-a{%&dE TuC_Cc{!1Lm77<[)P} xd;K?ܗu:zLxL LP{1A"tHpoe'Kv>3K.|0]' &?3r;B<ܱU?|eͻl-p5](* N/v̢yUXjt]_c:k 9eok,Kmz+c78 PS*5l |!۠AewuJDm1Mޣnn& >y>1poCpk6:tDă. S db(jZ#Jz 5.ѧV3"4\I+yJa @ul6<Ԇs0E&< 'o(>Q"\]ÍqADƛc!_{jdO>Yv]rE*x@D:kC9R)=9j ]m 2M.poF괽5Zst*Futj ^|RcC%:2sl8MEYӰlegEw`CJ8ֲOh$V=L,)W7= UƀH>!<2QrnEbmX}1b >HB?;x 6ge r0lԑ-rny>'*czR^H!N׃2(K SA^3̛x>u򍢥6HOg0a|PO۱4zkɍ0G”$ 3FCNSz 4l@^-C>d_Y̜G |W4|(k_qڗ[+A|[o;mZ;Cۿ,M՚3_ܣluz{-N4BW w|2+[*4~;Xujp"i1 6ZT? Co(Ȧdbt[=yS}Z,5f^\kA{D̅DQ s /ϊ%l*[_Lf09]#h5|cƦ9`䇿 _/AY;^QRV'$6cF-8AdC jo?(1VM!݉"gDa|fe|eV4%Xu ?)MjNC>Gd2HBL]ӣ$z,96G?xnYFvj% HbKRZ Ѐav@O/k 'i*KlޣaT8UhǪ6|#؃1Ug&[5)s) ^.ӜWn1{^5*re+y:):ME?=GLO E$GlaFPeah#~R5p<ѨS[u+g)Y:prlnUZ|+#;հ"Ush#hc0l.(אT m1~6Jp99TT$;WSM?lJh= 55ǜ6~aki!1 4vN eIy|*M@ o^Dy`FOM2J~MVbc|h>E{\U82`6!-ZC~acd{o}J )hId77dͧnFՋa(/Kja]?>: f~pK`: :^k f8j4@REEl̩YZehi}8dǞ5O ?<#s&E>O#Sd.0!6qAF0C 1RU Jצ3?X5r,4>xF"푎bN]anjXԶ,8GeFη3>kUB´)Qx#U}qU)fWGE/`5CN-}QgB/5lssӓcse>qi"07 J*go~3gZ_NB$G5?@qy@vCNN4$4 dzO0^ŧ/?\N_a͗鲶)k azExHL&'8:e7)TKm'p{s*(Y{.c%'hsؿA"p0x uY~j\6 ({8 ٶ r2U[3T=uʥQ]/ O%?I^6\NoO`.k! Zpfvsub l&5c  " 𑦯BprDkX^]yM+̷߸hrN{lt|:(XcC/lwR̯] zl D.!EѲ6"!rZlNJT3?8Zv} 4Mdρٹ" yQH%5)U#]x ^c+Z%rXPbV%d>={H6l|䏣Ů\*cI 9 &⌊k)Yw+&ZD{SX(p'/ nac."?G@g6ӦqS1&*=2AfPoKh1o9̺QĂ=}ʉnGDp%y;h!#hۜmZz58*kZ~#1"7:Eʋs 0izFEX;'D|ȝ& B iuK!U5 _#cʕb_6s㩊'TnH3`Hjxے6&ka T=m^GE+ǁ']&7잿8p)IYBf:> ~*3T|͝k$,vO|c|/?-KEσ˔d)kV栛vJ˶Sj~ʁr (kmj7aHgߝ/-w Gq"?Fsl|J| Yjq2'ڐX]@Pˉf}ďtw9D$ Xw0jX ͏WT{}2QN< ٗ zA W벒sv %fU5ȭ$ݫz9A0s)[%#F3: |,#'-"ݥB?w6+Md8T1ItWroâ'9hvWKX>wQT;9NYV9V1EM=+M~JƤVLиKp|E(yO@ݣ >ݳݫn*@6E(kH rf{5tJaL,I;@Ps{QYHcL(粗dۭF7x{h'O$zq~Ec[1c >ܫ7)׷BO J0'%iSRZO,֔ Nڻ] Dė%V@T!F{'2CD WN9\@K0'I%+éBA2 `,zyɑ򹋻o7OG:)dmݳx~"L:"9~-iS5H. zSiۘԼ*ynټrB]4ᬒ0}.d#avMU-+lKMS4 0X },j؉1+~Q` 9̀K٥G}SMCKPfx,Cpݠ) ڝ^tDq׀ڋq{r2RMi~+. O'`d_Yw |XDo/Xx)(O p`k{ e4z֯!F'=Jzt/F/Qv :58}ǵOs>@%̈*.x~ RFPGGXOc~XФ8hN ɰÍI,/`6A2K }%2Rcej"Kl78QO,4lڟ˕2"[0dj*MB{䋱A*IT}@ :8U0unC!k /qJf(7#aߣ`:&O6nNڛқVpŭ—>̐Kd6dȳZN+8 ¶sk8.XnD bH Z7dM1>JgaylR)G_0+t/ `c^I,Y$;0K!^[ j9-|ѷ0`Ѣ-7jVѬxEBQ%B%v@q5ނMC?=?nU?@EQw<{ |Uy]z,Ě|scLG-d$ UWV.ɔZM|f>|YB+Fh dko{EnAQ:~ Y+Q,9i[Q o%,`I3Z3֫ Ǔ*LcՍBh!1UDA&x啩l~j 7xRRk9U 6De{tC5G/'~61=w>GYd } Ś^{o-Pߒp93C@:f4* #0(?>`m- n) FQ PpЃ7ST?Ve w}`Z2șO EcO9kUn?ީ%꒰fixM$Ք縻FoBU؜۷Χ0hE| l(sm5*gᘏ>\R0"( `cʡ|N)ŒQ73&"J+pv}nJaNSjY#I@%GUnc֙bsM" N5=Ghڥ>b幖eV$hV^ +4@~9iE{ځRiEܖT$ !=LߗJ|l&! 0z_8,1pGy?,B#Ieab6GO`,EG/ٽ+!6dMd6Vq̶hy6B|>:2J2yYdDtBژ6t-fT_Kr .=|_#03~WT-rKkH|S&z_߄F^N,,Y;v$*+XZ$$ee< ZyfMi`XƯ!R5BLfxQ-ǙcS0pKpZV.cEA)a{5KV>J)x[ٽ8zdv60KJ|m`i\zFM(#н"Uf#T:(.`apKO0ѭlh\Om=z;bIvIH)}ŽS~:hm7Uƌm3Qč;q7x|Ҵhm2+!o-*-K9uպ[xFI_%o}덻䮸T#Y48Ҝ 75 \W:PzD-=z"C$#A8$T_xѿrDuI'e E3$/>8Rv@eoiS=l/I޳S:i=o"s\*`ʎ%C1w:2C* ^@򢬱&t!.{ =iu1ISduzgTo<@)}Pl3<J%[~!5G׋ A*LL@2ld9}bH۠f34j۟I&d*NRy,{OnnCMm]WHD:>N?8?̽ܒ'bY tUo|h 6H 1+mbS zl$%hsC HTYg`)d&qFaA(LĆ@fF>=NA3@ MBFD5˲}\F:^]hq3/4yYl|ݲM 'Kģb#@zyyZ <6A'x(eF %= ئhx*9{eSK`fФEgʒ4!g"MzTf/Q0 kɆC8]Y3CG6zB൒Ý8\>Tm1c+:Z%">IW42EB+{D#Dn*W-(3kX-) lzgxz ^ݨSoɃNbq#HYW8)5;XQr2#_ l{U%Gsd٧.X9~ }fWIu;d$CWG$֎03ӵ<A7LF D5fk]Y96Ģ>e.O^۴֌hN+W29su o漏WʨvFu]e_r$hX-w'I{pPFqʃWw=}Q1-^ëSHs-؀]?XUU>Ӓ07 D$tkFy|%&@L$suF8M4~Kz(dJRT@Y 'kІU@8 ྛ(@*GqHL]@~!^턐o 2tT)L/ cfY3+yB3]A1_OǙ;@C*6n;pC}+zi왤_Ű+vZ/ϵuz #U]cZd(چ lDrv!x*L4.ݛ3v?̂ 9v#+=PE Ou:a 0TFN>ɋEDe] S%gR`F :W^Ih,?07/elFRF爮oA8렣K"i&Xp~1 =.\\26;}?.:Ѧ#MK*4@ 魐pu9I wZ3[նkQb‡hkYϭq]w㡏㗑:Ђ_{hp;v!Pm_U e(k6!Y%9I4V'qP84ъOc[+Ka]X[ Oyqu*>|}:K*2 TTC⺄.VJ1qQTM1-CGxy%O QÂ;=Vٲ<+~ٍK.+ބ`jRJJg E;JV2']cI^hk.\n&anЅe3Я9:(9BX+hN56\~w^hYP{CєHяm}5s%%rًVTu֞'Tm|# b괛ĮE^hjjtWA})eWVyNDaY<*wep|iwb'-Z:9bՠHX_He2YWud9}tրC. :beXm d3x0:AGh7$DX# ʊQ?7y&km~H5spHnVRC u]TFBwҫCӝ)UI=Hfk:BS=M{zHz!T>ߴ.cLcz@ cLT@Sq-Fy̫bC&FhW/By-FE=ͣ!O ^$SVQ:CM:XtjYqOdմ&(T5ʛ)g' pA ZQ/A^YNN$H7s!?6Uҥ*UzPb;"0^ UOurߘ>L g>Bf+񼐪 Ёf0 [Q3DrIOR{8|h|AM1RD*Eβ2:ߞPx_ׁŋngD$"/?c\ McXmMRr5[ y0:h^2eQc&.b0]H8ðƈ>!3*PL&fo~ ʸdKߊ&%Dsق ʄF F :ZנhDѼ(KΘCc1Ir^Uq4|aֆ D Fɜ3k;Բ>f6 ?ȪS:Op$5{K)ޣy}I03bu9'+\K<@\N;Gu nPMEHzA^R#]n+h YӐf윻4\h^rg jh뭐p9G ~˃g<~P *.*X斅LH* zf"@nkmH]LÀ&F"VD3 zAK l`XfǗ bXð_]xxR>m%xFv"9Wl:(V NcG󞑅ǡ ޲t0Xof'9Uo0'@B2p!?W0:A0joۊAb}+QBѱ`yՏq;\hb~\4{oQGr5 hDn\;O@\51i7la75bIp1AU7<8fK~U-+juj>9B_(=[Y%pKL{tFONdLvna{jK{ZUKP =$dG#&PCp}ISMQrpM@HP Y!%HSdxK?gDeNDJZzaQpe/2f>cls>w,W˰pf ߜK1JBK)IcB_ZpqwnMZӰl3 wo|gX4Ɗz]1ٰ$YW>.-{28'??&3Fk9ijYT|H'AQ4Q7pnDIy"j8(}*>qr2,m[,R_. ~A']2u+x-{ [)X@L0V2 6hgn"E"ndIÃXxC9 P޸n\@Iw-ߐA _bC\v1h Jv^wco a*@X9<R|^,XD=0+24NV!eŘÏCu=*jP4sib~Lf/SUϒG nK4~ / M_Y sdU~ű_)]&IX, v:S?+}.8k '|=(:d5PMRvg&3P@WVR;!dP_61xW< e}1{Ag"6 }q`QRi ke>PNo\}%ʕGQc( Re!^%c2۾y*#Eq?_GM{b|fۛ`P-kML=yh,U(ݡELee % =^ʅ͟uLDi+@M5ȨWaÕzZV*'D1|VvT)Β(qӻJr`

6)gGTtH(DvYY\p0YmRkV a<1n P!2E;p z W_d@JE@ !.'Yx)J8;N?[D3udRU+b˧u{dx$ H0]wIxSg`/y/w711\2W>;tMQz5zh@srap++|>o OSˇ$1$AzlB{؀.,nh0@W"7s?\ݝJ֏ _%WɓCʦ2ϣYu6HS>ih iJ>kdy~Pry2W Oז=OnuW1ۓCٖDCU-R*>!zfU͌hfuiM[v*q@L\%gK"\%vi5!H]`Mh ܷ_.K?ϣSȄ7/b~Iv,pVKЇ̬ЊA E%m}cŴ~@c6@|O#v<ơ1OyLA˶7AqpQZ>jg}N$7Ɖ;6˾u89P%\犎fKcq!x>1"MǧfV aEZ豕W "/dD"N+wPʄ[X3~MŲqQ14ʷo7U3^Ij*;q!+?LyLp)GbءDmQLejq k#v]A-_#RȽtmM+7IF?֤wM #6ژ^j_JI{L\fIv?J a8ae~`NjܸLj/.\MRy4@"f@܈BeP`M?U<۲BZMUYVlSՠXy[ZC"/~ԋМt.;U'BSᕿnDMp2omGᒹnॳ*-^1;3lb :Ϲ KыMK {GSU /$R@ޯʪSZ2FF g7&49 2.1d9b%;Iq4x؜zZbU9kx_Da EXe59*G_'Y]&;S.F#-akJYg/c6'* 9#~Ll" ڹ,?_j8WڧU351šy[p]:G;e>Fހms^pL-o|ؓ8}dH:ijH8;;r 6`vѺ5|}mΞ~O!$MftH=~rϜ\Ŕ>n_5_L/ꋮ[36rH1MndGamn/up-9LMŔp?D3G]B[uhdۀXN/݄<ԍ0gB5ۍpR_A2n6jԤ F%qr۱/yYqNWm=xsɎ3P*8lZet 7'AcεF9c5s&Ph!ZCT. 3tiq6;"-Vb4v>ʺ[KTª"xt^qR~-2 ݞ{G&C|oST֧ Elzo1_NQKyѪ1Y}ŅPLˆcNgu' soQ1YyoPT#0ww]+x8%Hp& ɲb~[(7bƬ,!}>? -s mi>ҮרּJGRTL~;{ם oj Vf)8׈8+'?+EةKfE*s-YQj P"e I),Gn?kYO5F )YP嚲2jYYQd !|8HYa %er^ʦD\ k“^W}!"9G>˶P#&` ckng0N(NFX6XXOuTBKGXWT6M籹Z')jbKnVKEYAb\QR^]I 'P(1RETH.BlW 9!єsfw]l1Z (N)A<߶kژqڃ+بk-m<Dgr.I[M\|nyF&y` /Mz6AF}zZ+Z<܀r3}7TJAC+ S, A~'!Z_7jbFlEƲ|;ҍb6ZKm2cgznqJ.]ŵEc[Fϡ*LE56$0o ͈$:ǯ#* 0S`5/eWp`nWv)EKE#JG6,đX$s.+i*p&GƈĹ?[s+k N-pq˺_O7}>º~햣p;_OSlY />]őa5 VBwc 9>۶/t6UnwB".&~? 5,+< M)b:F a m=U%ИdBOxQ<'5ZE(b{~w#^I8G 2}Y$B@ )u2Yፃz> H@*x34vhNQ%g< aT;c .hMZ:$~!- U=P!R()[<5}t3vKj;0|V4 'Pΐ*qx@S!a#8=CY,kbgR~#iƊT.N'f AM},#ԲߔBEr3z 鎳O3qc9RxW\{|!܄vg}R5ML^t/&qP{Q6Ed5R`1~*'9:oT0>Qf_μB*g- qU)8+vTv: x@Ai?uYrAn!C IR\О kYz1WK fm,3.{=b۪&i빃_^i,w'ˊxIVïSoZ8,#zNMwӥHY: 6Cl Oa!R]۷^E~Izrضp+T^j Nů}<ՂЂ vw暕XMv A_8`Q|h`SLƊ˙>9g V|^C- )g?qbD?y2TA[~ 2c`}P6GW" H :U+{at`} Tz+!i膸][,Z _x;ck5if}s,qG7u[?WLyS1eHȹroFy8αKRdwqݎ%d>o/QsoEђP)6&c< y7nVLFO<=hx2{. #o?GB09*✰A#OIHZ~UU.taY 4VJ?\~ X&fjO>k>YGZw1bI2n4I򌔪 @_S״n[ SA :Ct>Q1 cudVxE \dA}7姖TE4]qD۬ѡ͓c2&5ᭆRAܿ:EYcʂ\1sЋ~`GhOX}mDA_ݓOTge΍>wQ8/ɇxsM6 2 |W GҳyÈ261<ݶIghEl[T`Ak1iԸdG y6OیHc=i8fb.,@=N- =;؟8t&M%=vp[}- +>UьB Nk8.>U}o 2OAbG/Q9yRlÍ i*5yF/dI:Iw磸Uf͎]S2׼Mdז]VƯ}Ċ 0C#5],63Rd#>DCy߿X .g^yh. Ma`&242[? Bwۖ+ S]}eϜXCZaۥS22nrAX 3g 4L☙KDUgIiLbm(c;òԐrc0=P#Au0cmj˘#O?$T/ϰ s1\/ΟVG/VZ,my_+[:B9:i1Ԗٽz ӟ5NT .Z6 0g2=_JjM/::+UYeġ{TqcVM#dKšP*k5`F4iQm`M{QμlbƔG p8=4au;$f? y_6L9,hQ{4s?! <<S2$Vׄld7b7QkS:mB0CvNQ?uƉU)DB!C!ڄ6 $5t}2c^_l@䓣UmE.FtWH?9qHJ9.z_[ͺ`wv߿x1u# nM f6v,t='FdIYqӐ9K`'G͇pJ'<ĩGId%ƌ^K:LJ CgMQ3J %5Mzifxn[ T0s+h㛔{Y|1K:mH;K[sU#(<~ ׁ8>bQNOywɈȄyy|{TJ?\0{;~ӘsԠ_V%۸ͮ&1UGD=vcPdHڳg< ` =O f?nL *3_95CovrgLS;HI]u)ʒqc 67=r"13at(lFs=X{b 1TӑÁj^ay0jP{P-<`-pGpl [;2|P)TҍȟX`E30_Go_m"H, AzꎣJ? Is\)'AЛ)3*' 5)]la6MAE[cCawUM6!­iyKԷ&V&p,_oQ xu\Jz|gk谇iѭ&A-܅,G}F-`4>*7S1[]MɞRs#!@|jw:;~ jF]锭?t>HZ2T]fBh)u b/<?-ٯ.o+y jb}#/  e=׮aqٹ7(73cTg <8rx[? n"TN'H[ oool@=Ǻr=PZmϴ}cU1;Z9.kqA|>Wp|t~Yݕ)x\whF&PHV-Z~P3a?O'V߄^:QEˮtڏ"VBQNws6kyLiوK/ݪYIV5Dvj7@Ox Ps:evY;Y Yw ZQqvP:rmw[- O_6?IK-{@_/]{O&ʏX8$r\/g5c<0Q]Jsv[if{bESg9Bq{ t<PEf3M8^A}qI˄yPAe*iɜl^*шﭙˆ8/fY[=({ؚjmIN{)sg7<]M㚙e'|m#n!õa9T=`ETmW?-u,=E"Ty܋X19ZIr*`DVgSWDA҅)Ud XEʦE>Fꫝ>3C'T (h+ďK:;@cD)*H /8mΒGY"G쳧?5%#)k5%pMF,Vv4雷ȉnd;dhY@{ z3W'6CdG{A:1כQy:]HR\/UW+i/ɽ/5a €$W{+#8? @?oz ?( G| 4xŒ =Us /PDR7<*> Cő sHO5*&`\Og:-pv~'*X#xr┰Bu EeR7HK"(ymv$|!I%B3[8`lks-wKX #J7EZG`.igt)X$/!KwXw˘7#I#$("ba { "Ք-W(SKxiQ+{UĻ:?;ryLCbӜmJo!;B!@iGy= 2¯f˽Ds7bw*0g6Vi"rLRuTZvEPsS-a G󼩢WQLy @;jXhdzHs?,:s{Hsh>ƦBwq܄"cʊv(+QkuD%d C w62x=`{*kXS,;Ǵ܈EAqR a5ѓBwj#l*E^0}J W01t&6@FBb:n74EjJeOTAaWF!ڱv'\ZEq> jbleBw p(|0i+Ie>KVҒg>m $} ^`+4 _i`VpQ9 O| U0&O0G~]M6UIGq3g1^AB|Yԣl*I7pi4|An;H]z=ݍ~j'Qab H_oVq7\)cEM|ԻSUiƧٽ1"6Mx4Ņnr_dhy<LF:1 > H8{$hWoeZh%PF_"L7*ՃXHO۽uO+7y OSb Qgt,@Q25[VzqOR JQC kէIdv9TQ7G^L*z{xŽ4E8~nНkX*a75bf/+`> <4zܢSR6b4>0܅L יd\S,+v|=> YzDwԻ^vvDVg| O2xxYi2i#Jd)\IL0v(ɞ24MC0 j[u5sM5e[V?-#F 8+*$EqZV]3Is87WY7PHԁ}pq3`pKmCG8(ozR 0S Z6Miq&վl% _|WY.W:L vU& >@+0_\*L9un4vgW0s+ ʫ`F. +3Nd*+bEz,HrzzF^M^2\m%^Xod`,A*;!qynFN5@藍gm(!{;-P27?X4FQs'&.pfmSA1YȬ<) H`),xE^gUъnFJ~A> +6(NwtFA&븚6-y+ \~0r5oy+]LF_|9H$3~@1ξvl[VS(׼o FΌƵKnۡlsflj86.~^.V~eZ 3ݤy"hW!R`+6am~8D]Je믁s 'c"A=?-/VQƗl7kko|vWre5FpP%.*:l ~h㋉U݌(]F㋒ ¥4ha M/ IYcϯq]-WEō°JHSyn߾rzg~Ejio?tɵ ss{RJXDx׷i ,>"^ 0.,a84a٘KRR0soT4hɾu,5>}ގW yYafWz (B.a,pS$UZ)e/r7!68?#o kT6KvLAF'}/ tibrCzz{$ b_owX=R97z׫,7VR'%3B޻~)zڔJh9V.[^d ALXjCm˃95X:,iy*5Y)NTt%&Dn*2wQP FW:m۲6YLÀ̇,FnSuNr^)D^xEӼ21TD=*<5485Ffҋ8lp!L~ߪԛuUK6GtTXVt:SiL梀DgF!qқW֚|[yьd۶PE+),b~T*3$"Yct`Ew)$9󀣣h,148s3IbCI28?|rRP58`Ib^S&U71< n C/|5ox17Wx|f@P!;vsFcCsn{ d9zT*oF ːw1?ʲV.UP]c}6"bO l]G\]?7!S\]XCC iLwhH("YhTL^OHGVu)Q,n*cxqQ3fV%'c&?[@⿜cw0)U^-{EjuK3 Љ(0pzÁ gRH:e@…Vީ.܎fC>lKg(FHRRE֗dB嶮pf}w,b(XzM5@X>*^)cCN3(Z*'򐶐Y%Q0wdPǗPz!j]Haٗz͕!Iєcj5cLIy uH Թ<Źz}^A᜴9*  (tK=k)TrA.Q\Yrw6ѓچB&0C琀U!+ѱ(ڂ ! A SSOVԣ-8p-1dzMH'Qfx9*d k!cUP &ғBP3N4.FZX6*d]3hTgL==x)ީ1qrꋜf/?d J{M^]VpS٥t):U`yH$sC7-&| ף\G'𧺆Ż}5k]6nRx<egutVvݺc_@ -Cc])}4F"Qs-Egq~z@Hpq4ka&&I{ldǮ7;f K\ySmZ#Iۇ,h^PR%mӖ&p`PwVjo`sJGGmҢA BU5ot3?"p dp8&01]OYJ{EJGXqhzi =&LSL^}0@x|=``$O՟&jw93Njhڑ9<0Z݉4:|= Gi G䄠OlFb\2`IP+hhU@o%Z5NyT&M60W*BTs_l2y͉<32Phi''A 9YPXHՍ!\9bAqӚ&~ᮞ=a-'c|DR_B_촂V֗ՙfN9 n % ƣSd+?=kbJzZy|f% =͹p}aS!ZPIR<ӥw(<)oYG(<ĉJtܟR%LM8Wá\uViX{ ?=<{߄ skUiY*jȱwVɿ ٧:GH~U6/(#O+{K1:?lqqz<d=&Ok'KIL4X ѺH97fX+NBiI(J &s@$?mwqo&K 'hʱƛ*v9Xށq54%Fk hpf×*kߣ]%X=N[̮X;yg[/c0I⟘zi-K"i0 z+ h5z]>4ڠUyDŽ{NI۴{|EIk[!~X;SګX>lbOl>NNڻӴ?fP+Eq0צ$K|u@oeRطd Ui1i5|]G z  rP [8.u"~Q}kNhi]}8fQ4ԡ[n^V 3*t29U˽#ޣ'DԔ9Bhn I5ڔC(Ɨ!Y;gJq b y@][nǮfk_Vעt j > 2!f$v8*i8Ԣ9xH:q`JeGdlY19"{>SϤݏƁ:I:fd͵>E` <Zj8oL,L&K;|3 k]VߕE%^=mW@>U(3TVpM ?Fw3aFKEOKDG!CF-0Ǵې3ChV( .xiZT/ٟSQOr5 <99bte[7OԾvzzLsvчZ)[ԯĺyy&X; byɚԭBvF/'0 Ws6BOmVgʾ}o XGp EyrDW7~=PJy.m SsZ}d he&bUٶX`Eq+a܉|SR-<6**a@Z~&Y,VHy\Nc/(Cz7mu5(Ŏu5{t 1)ϙnq KCG3}ct\RR$Jv6p^ZO7*oF>dP ^YU^.Hpq-a ֠#.dC3UAu4[ۄgr&rJ"ʔ? ǫ /oPZ_12P,̱8ڲhj}1zۣ/C*w.k+^QW@{' vY!mVMΏG 5~R-a;FS!7C{#\2=c6P- ""RNx0?J~gYs4vvU΂/D@te.){h!A}Cֻ2Ԃ*HVC3ġsdpg0 j]2=~W}B VE#si7Hu:㳪UuJq 70Tގhw%Wu ƫ Q r\ŤQe &u4>S2 `C xJ n76삎FH 39-=튟%6n19?z])mqS1nXC#kx0.Yq-fAlȖc^,z!5ĿU.O-Os̀Nbd `rr^na;?FвC}\'Gu#2KTfs@"t]E At1rPm;e$zF'4wآFEk-T#T! ĢVq9RUh2_̓tN.gھh<0%hfdHưR]ҁHZ  ,RKAF9jI kK<AQW:fZ5 8niC˶N޼ :r? }Gϻ;m?4rbTO-l$H{BׅrŠۯ:V GHMbi[If30Xc,2:ɖÚ/&C}#1l/ 'w`K!e,$:9,DQ;|w@Hԅw8=$MO&-D5[;`oϰfUPl8=F5ey{ʅmSoS)$1h\.]OZBж3 nQbQm8%=/~N'<6q\qp`t1tRR^(|-A{3*gy!-IIMx5R,y BD< Ru4c"l=eV! a }i_݃d |"Q0@fuT,W?ؙY5|E?,u<՘x![fE g CԄ.?%JY+UuLB])BP A]Zfn!H0vJ)m^sKQFɄjknK5fi9ekkȀMXqW/[񛨰$ ث?[;!tW['m٦Q5 m:y2eXy(VkŢ=G- 윌UxT˕ic]}\0u7r6_LvfwJN)gn@z=+?K3ɶS^eN&Bi?f7< >!׉Glv/'[ T 9NO'#-!JL ʈU6p,-Me(d+&W3L"#B;:ʁjyd@ߪ 7tcb4L\]^',E&xB )P&OiIoCe_'~}`߻&xۑE ,g[ kj½޾r.$)،*27}eI8bf؏DFޙ&lY JO./i]HDlwLM5ú}#PB3'J Y߲1ǸB01G5.j&昡1Bu3C`ۯՂAXE"#Z:%$/ 9zwo8P- TtncNm) JZNUr"a[-R/|/;l2|9O!~fG<9mMϢlut r I5p^͜x ˍ|LҧV P޹m!? E>J螳T>m+xJ o0'TO>6b?7EdHU8 !쓐0Ͼe#?.dwD+sVgZZuEWV5f?Z_BJW8qFyD3'Ҥ6H{ 9WE|7\X:(sIv)Q}+d6w i=h7zP1Vj+ lZ~]sK:eOH@p׋ g ]|CT]G:',Ab!iK1bȪpy\S5եXIP3P#f\tB6({PAQLm/މ+Z*J!|dshhY?ijM 3떌w-3z˔4ŭnO 87؝#,lrl `˯ܺ-NUyQ2/j˨pQzJ M{bsY-…W)cA6M5#]H#ƗI 8AW7Y*]h&TĽZQ*D3 ϛv7Tgf<`ȢRh̿fM,W'* Y*/ h0*dF r;)]G=u-] 2k< n[C:Eo35oK0Y+U]",:IV%Ĵ4q ՗!HfJb &w),:3jg9"ˠ4;݅Gsy'G(3|jE۲B!Q`U u#BܾY`M!rtG'3Y;:tܻt # DSӥQHfv"-vmyg[_*k:3z=Xҍvv9$@=VK#^|(xOb ӠRaYUՎz .Z7]nҧvΝF860 uu(k9e `(CzW1dhtʐ7!/%ĐUȾ)7`IVmءԗYfMoR2nGA>mB{1,-s98ũ+NV$#90~J xq,_ pJ3_jO ; ' n^C*%!w=X5opH8W"T:%cZ>d5--czsYa堇*s9M6SOiVAI^E05Tisv&.D<|yMfb+T8ZVOs· ]D4b;KvUlb;h_Zؽ>kx\T~u7>*She(@Qf)Yl}LBwF|{'@F(]s-~~PsDI7Y:H(cT86F&ҊA)r>:? -記?.Y+m/H<2V"v.zc`5;VG=}X9bobDe{4KI:X" Ȃ6_#/ljmSB\YɨOȇ:]j%*]4b"- KwK/?pmjz|J2/8&̈;̓6EugʿlDtT 99-*Ce'xz3P^i]r[*089yGO:RPrX |#}ꎆi5-C#P"w9Z|nrڸ^&z=[_3, s9dAK/0q'RѡWpjysDv<و6towd4rv3Y0r8kExZOU/GB/\WH]zqcfNF\?جmė|:=Mr z *'a0/ynzb`WX1ʱn \ȞDS*|Ir-&3:_ݬg;y?GYS\B{irZ>|U),XTu7lXۢTFicg .28,n`pLj8&x㘙f_Ui> ،mTjm^QAEʎlX&uQM? PVi}R%3J^ZO L'ޞI+1wӿ`mIr̞Lrc>oǑh7Ƶz(w{d.-"(>-/WĦI8Tb-0/Z6;Jh1)c`弽U[VzJۄ8^bٲ%&x)N*TH>I[ܚM"_4~tl j4 TTm \>m(cn0==l 0,,d*0ÝȢf*{ԟԉpI &''7M`qiGA RTS15j7Pq/e}GF%>vdH$~123%[\.<d $Xd97neN l3qFnLeoTb72+L '3UrZ]s{s1c/Փ%9ՁH̨=./bp]q> -Bj6|F3Nя3*h;}9FR䱨㴂]d)yJbΤAX޸"VM<_} D8?6a>-) p:gzJڜңEy+ʫ"w>Ym5H߅ Z46/.9(xP0*h`BD\"l :@RnmW2~LCk-J_8n*(P?Wu;\"/+ o=^#arS^ 1yP9L5}a2WecQg Ԫ&}ҧ=tFW˃+"ϻUg22@/ )>Z"E6|XTj/\YykZpߣFZ D]<<;U֒HUJ!b@Nu[фp+@52J!r\zTH5c(V!`qi</_aZGA*d.M D~ot-yɃ]8H |)3s!F+m>Q<85H*ok\PX|%&{\[.8.h) >wH4sK{}%oXD3qEi,'F $‹*(2'Xz'%kJk&;ܦʋX,H3 }үxL&E?Nd>\1o3+T_[Χ_cG2WWU~e0@82-v0MP2[gاOpbS.v;+GZW~Vۢ:kOuU3Lz6~jRN=bλ%rnX \ZvN2-͙y6]^ @ yЪ Q+B2D//䆽r[Gzu/,R)A9ZƗo1 &cX'ˑe^ܪR[+({QF!e{$ΰXvEO5'Ozz`Ƴ? BJE3 IN_ (c}~A&h K#!C $v3BbMt/S``Z![3h"IDRSVtMBM"O3Y/B L(`F(#+RIpP^]!V]'cVm /ECH^O wYa/]tob>8?CŜi+`HU &D6_>$HBdž7:p{Kiv7N+7b2%]X~\-~f;r`x9\/f) - L=kW>bC%, I]i^S(20)L;&s&4 a %X’rXw)CCwI4Y"mpքJ>o86:vDQ*`&Ku4+ؘǣ| kxxW >B́Uú}quHZRK|#GNl][f`_8ɯy7OmxhkJT $imU?ĘR/L hVF$ n*mӦ˷ 3ieD:uPO<4 R&@`/e(`6 -ruN9'6sJd)Eȥw* Ye|R`ͲuNZ˂֛@ GbmV7a_"C%ec6{&Qmy;k=4z'*Dh@u$V a+ONT,k.-cPm6ffޘ5$H 6'>vy"ZfFs >'/Rզ٘x|?/LP̀Ʋj8Ow$(݋Q0w ni~=IP@'/ Dg !\W5h-=Ԛ[(G\iY쨷p0<Yp`DKxǸɮbw¶zHDm LTDVQc ;?&M4*(_>\nUL0Aŧ.?xQ옛ۺkIܽ A۶v.ΛPSXZ LkH\fx\DY4uBiUoVp/T\Dk(_L{gΠ2G&+*3sd7 .:˰OwmfPNRU΂bg$Q'ht:d3u;3Zb[=Ge|(`?Rp\xa&v[P˧I IkiR1vbJ+&-m'7 {3i=$jKW>-1U%sIo#V!EC6&w )5 k/QDq6Y-tRp*Hy57X*b} &Hؖ_KPȉA'^X`:;ΰBjҼHE mh=SDJ%97ufߑ-nb,Ї:SaDYC6ItK4Ne>Y~emAL_gׯ JH=SɋM_# $ V!4F/ăNu5 1͇r;f Fz݂NaR*D:d2T8bLDe 30SFʝq,]>6RƴkԂBW}o>L`:LQ͠ƨOt-iy_)?Jso{.+aLï(BBtfEŞ- Z#VY".lrc_W,C=˰Jߚ8OR`;c(?U3}v|*L%-~fV4l׾AN} ВS+gy}<XXjo5`_9)Kg.Rn,7j X^j.z4,ZglECDxj!mŖK~-ؽ<ؐ+]̆-YX@A1xkz7S=+ [hDu00@3EBKlKҐ#oq[Ƥ%IF2o :7J&dEm,T.-w)@ WTI-X4?fȶcz4l`e;頍8Q.֊aUZjҲ(Г3 ,S8@d'}ٶHuK,g.TfrO>?rZڍoQ iLy6]>Ht=䰓܎}It?/#-6|Kj{, PNࣱ?prC]>bc hQ:AА){JE kdv1#pPףtأK0!dipDk P{hXflfRsW0opzzj1U244Lr"jTNDkJeP"0f,C_ؙ "X(cNk3_A<<qΉρL>k:g'Q%MtH%4?x60/[ +=Ŕ`>kIoZGjKFCpy7W|^jNXh=a&,cVE`$8$m3ۋN;İ,F70r>p٬"e',RkKEwu,t>FV3t?V:O*H"n 4FᨾUxW<4^ ?6*F w.,e8I2z0{ABKxr Ǒ{UV/vZD 4|?" WA.5fsF?zDx5?D_V:sN *r fy }k ŒdnA!wx-!}|aH|Og<].+0mݨC.0KА P%?44I]U&WQDKӹ͈`g)#Gv}v9b3Y;FQx 9BlEnDEb4f醯T"RF.aG|х:\! M[n S6d2$SP4M}D(BPoM /Xc }}2؞skl0ѺWքT JdSI0r>A.༟Ǘ09m]~GP?[[Kw;sO]`A+,E2*}E!"R_PMCB@K#\p ^?f,j2lxMd`tfE0M0ޯ7 x MEFNhl9`ɓBŰ . Ap-R`wTY(8C:寶-a퀕 hX96&~JP@vx?$ yiD:0QrKeQ@~_H|:5zr-$+>;?Yd $:; M!pRl`iʶk|!w5 Ʋv Kic}q j@@.sKw`3#, m;LU;D.%GTn aMIT{ahٌ:8@R!IbZ.{_F'/ G^x*uc""GAc\U펭S>TH0{~ []䛰=i mUͿ7tz.*=w6g5϶A8E5C8F.rX/Wu,mf tڊ(2L˾*F!|iJ/J$(iRqMIoCYA▷[ZPgK{*'DGLsRZ V ":L#r6~?ZT-n& s:fa5hz/yRbfZ2;] Fwl4ȼЀW3)~ ICMNÆiݒa0K_ %ِpmx[1A@V#[zTljo/wV;ҟQ1a̮'%G.K1fx’"jPt8輵iU`k qZ;JZbBD{!YF"VĪ6ce%Lug!1ǖ"ڥՆ WM= laP>,Q8G>FO'hd̑ j 7QTYC"UY!1*7KE;ySՙ)؀\e>US뻾k5~e | tۉSӇ}vӿKՕɃhz|c״nخOHHƔ=E=4 M86ƺw )'MvL"6g“뷍h0p})}>p% ,pWrAHʤ=EU%@a?‚ȭ.]֏JG }0&j|vo)ypbאho40cC׋7Ց}5'07HrH|67l$)NN`VvM!PkYK_"6{p'5ϝn5qm' \Kof2#@SR7:+;>\#t{$'پ?_6c. pwAmT:4msv]dBhˇu\TJ+vIsp] Z~O؜jya>dʤ^ nxi5]f󣆧Z[A~0a͈\b$Hde.^k5G|dh9 h3֌9 C{![Qjoh0\HS#q_Wb],䦈pF

[΂o̴^jbe^O 32GjS-括Z~r Ӎ`l2! 'OoߔH/YA C'$޻;_SLS韱]omp|\RBD[{ʤ\=bBʤ3_&"=8҂ke|i盶dTmY}'Id\}GsK%rԔ!KY-z$e \9j:|.PEAެ1p3US;/D n~۫# :V/ sY#fl$di>fZQmsqI-x@Վ"xUFz퍋_T0Z9Lb .q|E~- w*,nv.Yߛ?4%N`e> v&y;. :dVL?%S`b~cHGȀ}qAåj˶JImΒK}E>**`ؖj]|e.~ Ҍ,ʮ{ :y!|\;=775T.54ά,&kNвLyx@5?CjQmcWCxDԀ 9Ď^óqʒ@Hska /Λf@D_ѱ<ɞ&_QL ߌ dAT͎CRx5ȭܙzm$1d<އ<*O.hY l@5UISƉiڕ3hGV;Ϥ$*Fbdgل4q:Ky2Hc.@.I _vۙr! 7?oZ3)vu۶{)f\Op<b,Ͷb, #4juJf4e w?qrEeGmҁ9Kη?12[Ѱ@%BA-󩽿N+p_}FlbmMq'ۄɮCZ He_H-I󵈄I H6$.btMyTN \Ii` cDXYZK2q_(+sܬհY㓶Wu5#~ @3t+]al m<A#6;'|eoAc*>JP׆X66&X5L2Zb6[@i?_oKͯ?cXO} ~='_$Nu?^Ak NNۄh>=8+2 |8YHW>V((볏wOFPvƚOSל7H-Q&z|lԎQcd+dvp C<8!mTήܭy*tVPwijg<"  vC,hsګdPsl͉ԙJPuOb#@2b~jvwe0kӀrωg1!,0R1J {~+rѳ\%U[,< +#VHU!1亁@@)40Fj#Xu LJ*W_8&͒@BS HnPC8`uv/CD9 %KZ )UOƸN9P[ |(|f@{Zԏgq?%L!5rwRٔ˗70c?%،Rֿs% ς2[VX*: ;Yro]=س,T٦S9v+bz]Dl B{yhb6"p⋑|9ܐ{<6]}qx+_H7u>5:E-8wc·auFzwwzg3}" ]/y=fnc'L^vw=؛Y"PvaI%BA ƟzL2ɤU*qnN| ԼhR}8?IQ`f@? |!][Ա{PF` R]!/emb-hnm |WzF|ߎ#?v- 3 ]՘) hz(Zb3Rㅔ\ǽIl+ڶuB.f׉ʐ* vnє>,MTG4<7h3^4eC! :ĻtZ @_"ڛXH)!Je]ټ5E%7%\8tY2Z+E=~OfK^Xu;A r|kLK4Go0d!/&;Zc2po.I칮>k 25~g+A># XhSިRN ؎L- ߫L?t3F^/?E/pmgE/Y 6L4VW=yq8W8 B$Ok8}QgWZ?<>}B2LA}净Qٰ18R4ʴRdݸ ܜq.(1ZhWh2vCPb8R*y2^Aƪ˸0wTQFKV6|a$ӿ@Be8$Y, `syTMo7_x%;:o0gP|eosCE^?X`? B!DM/I(6g*MgǎxF>&AV}e;!TYl^]h[R*H yYDdETį9xKaLi#0e9{LT?SV׎Y :w0 cԏ.^4^Rʈo9tJOvFyxy0u?!Z<]ݩ4 U'zf4h+9&uFXWQZdc'<1lÓ3h'ed7`H`,%༟` ;ߘ3l`vJm%5߯T$jC *n){% \LѻG%;ވFs^v?$Uhg*pB2:lH$LlaŅJ٪Pb @-d4DҲFVv0 ESnCe.](y7jQ/y0J# {)^*'E\VsV?+:]9HU26`Ѷq1YmW5&S[hhuo̐)9R'.΁<ΎY4xW3EMF elq` r{t)wxÀ0 M2>ǻ0XqV뉃]w xJ۟߿j| yrm 4*X(^FOF&VB u/nw,2!OqCs"\֭caj02f"[g$woxv_}tX> )`llFzTm҅ыJ^o| ~uPAڌø]el@aoU2D- "LT4! ^H"؀EɾzHD;n6\JLe7sn&&-@Ԗj0'np~w:4Vф_ ðTȎ:QE(+ַz>T4t1AhӠ\"?gAgܩXyViZݯ .tkHp{,E<4Qޛ 2p?%]IpS+wT1(,ePr|/WyM%m~_J kxKt'hǟLZBHpjd7n"θ5}f|uAհ.}df*jqck$jh"I)fr+= DSWa/ȉgDd@j.w\M̃5mf< Gm='i14Rw lڬ*;fJt䌰Z%m>M*D$,\(L'$ +١# #UZ1E5t?\;%@t7L/Xb{+M>\(",i%VxagY dgJKb %xL$HF a AԼ YXUB/ FY1Vj&ݺv݇'D3N;$Ҭ(F$V)tmӤfN;D~x0ށMTǂ^t` CB:7Hͳޮ1IlmSݮ&؈NX7*'@>-q%> ϰ^~$txc$w&nGm {pBY;'PE"Jd4˦Z5N4UV*=4Yx"oeeZ75-ѹƪorFpٻ1R˅!^Jz*- ۜ:9q)kmc#<%o]Pgm>UuYo9E` $Nj3hSzY2j T*XK6yt*..6DPqSzqJ7F"MJ;m :2YVsv e ߯$[BZ~ĩ|_8h;V:o=q1,PicKk Tϡ,uHm< eykc9I9A&: $PX,K _9Ӄ#ײ;/YʴjƸKnf[M"}K\l8 S6f}Pu*륏$H;e_~\(>5Yrμ 7ߝ rʺ~&M>V<.</ = "u+>s؆ml܌O(1xJzlbҩDU"ČV-ipx,MYa4ѽBVԽ#?I3 wW3~ x7,vعPˀ(#jܧ-kaucht.3b{A6ȶ!V Y3濞e`4U?7}Y$;HC*l_QOOv5W_]2 :X?[6Fx;FI_~ {ZB1K)Nlu:VO%bϛh7SABThFdGsl6ɧ2Ap~A' t7 .<DK jTWח]- 줁)Yvۭ ;W;f풱[gM[+<[ǴE 2*@{vs(mŸ pU!QS:(>z QȣT^ヨtI~1,;-26MV] o$''H{?֍ۄx#: R/+*_ZRQ.Dbތ}o$,\-x $Y?|3srsB4ʼn6e@?sP_$yu}J!T:2SS Q/Xl-R l>l&E8?Xp:Twlq -u)M-6્Qƫ{qP!wGk2ϔ;e %,jkbQ`cWQ!.ztfg8ʠ.4[~ADQ?Z8n8#ScI/Gcq-A27LĆmA7]R|"C)$;&<- 7IY;vסCarms&\&CY=8'#y]6\Q=l8I\;zz;8£lSe19J`OZ_ojpW(/d/In͗dmNMi?`ǾFCs[OG Yn5csٍlM6(W«Kp+Y{C*%1HZ̋3f'vu(i0,e~uY/Ь=AOFbm9GPwFz@(zׁAjIe-I2H1Mx=D9Gua+fLEPVG})U֋{o? q|`yG IbeOzd,gBz!/jnŶ!atS% .M})\[\`W[LL=G][2T2M//W5qWToď'ĂtcR[{N5L868#.Hܡ'&qNIT-YuS}à[i扴򱷟rn{EG 6j=+]I1;Vu1>!Kb:4@Ң?}1S'gxpIMsv&K[r*4+Gvw,-v@򣿛_/sHMԢÒh:% }5WwM iU>{HY{U]b ;!Ap ѬV#f-h7c޴lFk&]$F'Xʕm'c;ɍ߿D<07bԵc4ypYr5~|ZL_xJ#K/D?\НՈ\O`Y;0PfN* ]VkguOA.1_;_i d%޳K`yNRL}~P &UMIfQѷ=]h ,sFF~'6q.^E=^$&9lF}Q@K )m$t- K%)5W ęQ]ּ46Z K lt>Ilbەb5+lf.p)6 bi3E/ݔ=[`AM6/鎇Foӷ:ָTt`f 9'w02ZHaO<%,{E` r_LQ'ǻmC"_ %aHVHاvݳ s%TǙsn܇XR8)8`a-㣡Yъu4JB;ռNP<4;ϩz%}pGFR|o1MشZƺ Bu,iW>~GR-v |9L 5Ն!ja%ಫ :?TJ8AkszOlNSx9ܡdg\Б7bћ LjOEi5 RSdիuhij<#|r='W%^؃7'_B\{tڮh ڵr)⢇QY% \&^F>!⋥SgJ0:;g@PZQOf '=lyneo<sq /^gulH:Ɔ=j/Qc \ F,jm`HcPNL03ꔃkOJ=z.B`RaZx7=d@yɇQ;UaG/ʔVs1INc9TђE6:Z%*j9qg+34|#~d I[%8mB_Ґ|#aeQ;~iqZ2:UKSp% 1됨`GI]Ѧ BTERbxtVu- !qk; .uɱv^'tj .5m]l*[kcͽ؏τza&|?ϏN\Ԛ;ѳb $,l3foּk 'O{k> \m*&+E&8CiFea}:nv4&Ik"4Nxy !~fܹg8c0.C*i}_]Ba`!w-LFf5b ]c3TPN<`c 0O$8.mL\K[#❛y7IHxA&BD,IR1 J#@HT ʵ̮ڇz&>z%e;˅o.|m"팺A*K3-ɩ1dQ7"`.OhYW\ M>(=օ;\OТHE&P[9LyWIגw0\3b]P[#=0ީoF}AiX(Ǟ]d$,}х2ܸ衵ؙ>_92Ѷ i<v/Ҋ/b;rYb^0|х> G0N{uA&[f??)dlWl|Y$ S&ܬW%*p9Of%|T>ПCBA`XBXBXg$Nœq ּ|mz Qq Va}?r+fF 4M T,|G:V!4rDJ@IXꎓDe;bJzw)~aT5W"ޕu9|Jg@2㿗x=^-5{+Mޛ9{۶A r}ļsnl7uJD+N4Vn!0ēz~O8TTvloF3 3]`MT.Ѐj*Hgj&XC)Z[WWˁ0ȗ**van/ϟc|]|HH"'nT|Gƞa̶P,AREhM[ߩ'Mwǯ@aA7_Ԍ )6Jch7P?B,',AS:A׆x>=8MX6*FzRuEs l2d *]N'ַx~alEض"(gȼg7|;] b?{ֵs|[3P!>+kI 4~&n ޾׫*J?[p. ۇ3ͨ UXV{uqMwݾ>;Q @i?l̴CERdu?AIjȖ~Ia9}%Xc,=ڥ;) Rұ:ktVbQ+Dpud"0vKE yhd!++_ fZ`7עF2{aJ O@z}dp%l{5ZÞ؄0hMPrha}!vkcDj w Kӭ4&fc HlBICyNxʵ_k Z̯ߛlXfs&F6[Ce`+5QșR~?j$X} {z^Nkw(x &RPUE9kej!}R< ʲ%͏zKAFaY1㛟bUIIv!q=9/nICKptV]jݶ ɴI4\u+q-h`>PvB%,T^&{r8 ٳjܬΎQH8 qtYTO[PPPǤBҙG'w6Op6d&V/ KjjxoEP4S2/sKoE'Y#3PX?$lDY$(M[Q(uF | ǾaBZ\ E ,:[2vP>SX{(\L[xzon2ĖX8]+V 󻎱%:ة/xr}se6/ L:y&f- ݛ;Hk5`W0ݎ~)~U,|^SZ B"&iNRSE1NӐubmk+Հ+"ڳ #0 =>2z(acMZ;ۉZ ]%o?~ GiMNT/3L^ ,Ȇt \l=!Y\/IHB]{.~e0KkʑS$_$ϝ f\d q;Z%tdUmhϹ6*QAxSQ Ƭ/Yx1.uq6vh28} u2;G4}ghI9+R5Yq1_$f)4Áu h#\]cC 䂜j39RO(]7J::pcg!E n].IT8+9HcΠ (J;8%\gDO=6t%M}C!* {`)APBm AC>vJu,HU=Yo>-[{ZP'm<3 z7(g*/ )+S'^(ڧŧ${XxL{یSˢ%x`;cFw!1 N,Npٲ3\_gڿ5& 8R 2 Iew$/+ӝk3z&8()e0GQYS|]GPt=|?'ΦYbIq*/> c^qm#pPDY-v  $*'Q=#!EQH\}J}Ů 1y9F&RqE)Y"K+ ˙X5Ja[tpknU֫(*}UQj(cWq _X.QBkR){i@trp4Dml=uͪqn2߅f~B&ŝkkRS0Fp`JToHDsF*+ s+Ssepf"8Y7O*mzSz%i,R5s!cAO] anӡAZmo g6!f tfp:a&!>]"SLsj D7'EHp?Rв}oa_aڝIJ6; %m 0L=.(.\{ܡ3}|&^z l'^5nH;>'urgwZe7AkoVq56r6DahUsrT0&6 \/TAItQtiG=Ɲ/|+& xR$N۟O#̀.&?_A-c@CURIS/^ȾjEZ[<=pvt5g i@EDnJ+׀rs`sTzWIcڣ$*LTP $şnؒ܋U)|H3>%Eqda߷!4vbbI _KkWy}+] Ӏ$~H곷j$?LqG֢fyč'ƹN֌iԱXvëq2ɾ;νB忣CʐplP:v V,&nrDM=8lh~sTEחLKe[XTXQL)m,:稊/"ŕU bWÄ JOGpgW?-48!J;6JV c{9 }eV\Po^ x}fO[%bKd,l 4 olN`'c᫯feMw`%8NPFP+;uAݏ;]4lmj N:l ~3EEYci$DEl lWdqޞ$R+t3j>5=vG_щ:Z)VͺG)&2 E^^g=W':!}b1mujj GkwxP(oW&s1 >VSb-#Yg0ߥ6*O㶎|`f"VvP|C:(5`L:A03RiwT),,G8Ӄ6I-ڷx+=J+_&KFq擒L"LG,c>_9ԊbgUho͔_=GUY$<Ԙcz#]b>C I\8dI.AJuG:o#R"W'r7UE{LVc'տt:&Zmehз<A\qPyϗ?(m!a*hH%ޒ<6cTJZێs.;ndZ8,MūeC(s,"o[(;+A }WG"K/v)Ϭ3GSĒhU `p2^2xԦ61 yOWQ,kuCcT/Pq4[s%Wlwϗ:|ӪEu _(Uoә@CvpzOަ[XlIl}% ]M~ZfݻHt{`P[+0!xky"*SW-E4K1WPs L0V 8ȞWd"`&lz=N"݁W+/V0ί_Vdh:'@!Gr 2֫LT'KYhFQʛ# /vy#86L#&l#O%&1x+j<`(6%ъU1 "2OĶ2#w;"𜣞Y~ mNRP>8$BxR-9ɹQJ43T=H)Lߦ'a% 6_CVA;QpW$B-pB{ᆊb61Íwӛs$. /1puGlf44 r6N\3$F=JomU'(渙(\+sc*%D߈B.r /ߘ)x)k`$ph۞n݉ա! *RA#Qc+j>Xa jaA5% P7"nP2Á ӗTd[Nen8i>FKkp|F#AJUbB/|mv;MCL$ddf%*t'ъCgq>&:Z.{+ROP;73%,)4ưxfwiu[t(;__4w#ľ$hs}bf%,{"¥-$YɹPwc͇z]`/2.7DY e.;\=EkQA5)U.HA'&,ЎM)'.-qua=7ǮEazdrכ=md 05|G{c٤ `U@qq954_m0|XU3 l`g {Z64XBפVe/Ĵf( *mjc<<WD)-%Ny 2?Xea*56i"xՍM^ENsg2 ?KV( B@-w)nE-QZ#3y<}/̙Vm _թ=]0>xұf337@<B&S7]/oyYGU\ު-dXb2e%R1:Y{6zc ;]gxs;<֩Dw%M)"̎r&}|`N=#7Eݹz:kZMe[|UhJHw}K㼈7Im'W}/UTjz~ hlYP^}x2czYծi PNAiMjs!4ƴ,!TS{ L2?9TOZ3 ɐ#:OgT Ů BL$15u/J(!U ߼=o6l~އf'p zS>7D ;V'EN+WKZT|52Vᖭm:,RIx7F_}S8"s2¦pF3Cm~\b I-MJ,^2I+b1 V 9='D;  RcpLE;K'.FZ>S˨"iG,MԒ-Μ`ݑnRHycPs;{vswOR=T Qa;,\G[Lqdi5Ut"e^es1. IEzXاh5w[1_}hi"0YJ5&1(8K=)cjx\&cp=r/ɏ5/A;n.LSöbs!P44r">3/t vf~2˚=> 2W3QqnH=GVBrLpvF;,}|z]Yh0h[¶j⮃FcP4Ba q9 5O) 狌/q|F[I]!ÌmRc'4 W f"Y+Łt 8siIm_=6UǞFѭ;;69L@:ؘL8P, 1n~B '4BF=\kަg*$3 ܧr5v|<6d}vf :!H6" ={ˢld7UFUN\l#E+4J/J,P nzCl ϥu ~PF\_E56[evEkpNJZ;Ͱ 6 Hk)S~4&w^Gbhbl\m,2YK!ɔ!z;0@F ^@i ZH;Qulqr\ܟ7ە|< .OEJt- vnzT˖*=ls3Y$kYPsچժ1НCVB>^ 1,cO>&ݣw~&hmҰ^SU{ܸHYD]>/FWBQ|ؼp!bN9&tAIZ ;:3q,j[%%;I{!]Zmi\{:f~ 2*1/%r{,mu~ $n57r:oȁyEwwM (|MYzIhnoQ[6 LݭN޶%@:NƊ#BнBe"oiqqI2`EBk(G!MKE2T%j4OPurwgWش#"T*']NrMR$Eoy1exlgQa)BͰ N5rRA[t b$, 1 (ւ Ey}S #\ PgtOcUJsbNT/ oEm5?7zn_crw 84&"?M5=ۢ'a%m?ɿݱAVڪutv՗qwЗMD&jj#ܔ]}t@#XΩL8pMjlUlճ͖zȒ?%(hY{j[FÅf@lCU,-"FRo,PH 1xX'U'2ɥ`Hp^g܍2ACfdы }9C%nLTbsax$\ȓF2#IwJd0Jn[ZS2pNޝkU)I )) E9s`uRi9g*:<)4WWK2nb/w2$Xaha}b[a[U.ԋ^6.껶x:.#y7uISM;79ܤVK~' YѸƪ NQG{ڿ2QÆJsVSqќ'><}p-%Ɉyf ߠYAgSI`| l)A%k"[ߎIN ^vvo`"v؊zh)Ј!vY57>N1 5'U|'3ſMmR4r_+5e7IKV2{d% 9暢 ս{Ș xTWPÿ&WKAgOlܨK4~8*`̑#M ;HL'}VTmq@%ѩ$Iv|)C0I'wƪ._X{f Q!.:a\T-hP:U;%p&Go(`s`_Fh^_p \8\Ti)h_P_dx֘e &Mka%!={gMKLb#d":E->ە@E  : ndX)M͇mR,SxEaЃb?cmVwʿoֵ/N7ZgxٍOTw@. `7MR(?EZJAw0%\1ŪtG^`APvtZgqaO?ޗlYrΕCA}Jjb$oru5}Z^ u/& f3fqi c鶫6]Nw0IFdb^,w/,1,k2{uʧ錇 zƠFPPLKխ2Io+uAZ~:2q,f;іRy"-3xo\؀,[! gÎ#5qS6z"wl7TEY .Kp| AO|b=JSTK(Ă FnQ[v֡j,L 2e2{%e2{6HK~`3 il3a~:;cXصꋒEuy^ޅ"P*$d |[2(kTEcATYU hP<'](ލ9+ =sH7ƯsCGu0+Ϩ)㡤ҭ 9Ho'ecHh ?,]% 1 5v[YHt}2`g~DtR*Wg*æ' &cNnŠ(B .oCBxkh]zЬ(_nLL@i^?6Z*4V Om,|ioU,xu3~ ]$_qMLz,wϾN8GnӜVmڿQvQ$'>YES*R|'nT5Lwwv'Ov>!FgD$ ,cɴD3&  ń%QUXf6(\C4UFjJ%~_%lj /_K}-;ݝ4]LK 1ƵsVv%*vłtR4jj$-9VI/]8؜O!YXaۃ~W\_)! kh4gk}!n R!rm l3jEw$ZFa`pP-Н߅# k9Zֹ]S~h)L>G]]%n7gN#>FE/e< )Bs15Xޭr- O9X{Hkco1%촌}<:ygLWQ tOP{7M@V ˇ8#[$U`8僳J5`v$T[Iñ{ -1sp@4#=eaa0RnkI s|üo%6MIo^Ҕ/?4p03_ $%|m$hwcS1 [@,F:O3&,sSٱxcg(ꉯ h入A88^IxI@!_cUjoL]4Ō7+TOYa-`(Cb6Xػ wZd㩱XO5aUjl|GK{J/z2Ϩy3Zkƹ ><^yf>HS(}qa3zCbiZ z&ȣ++áZnaj+krqXܯėωh[1>.?H9)1_:+:_NRҜoT5uS ,Yg~{R$~pY!T% {fXpD`5`q]L%bl~x/HF)%)5`zf"-Ҋ+M]HQɺkH$tz`?F;SK`ܲ^];{R3gN,Q$Q;8۬fJUسCk&#IX嶈P5"yԘLc%t̐g:Į/y39"Qr*]:0A C)R~4v7$,'G8VioFd\=kρ)\\9NV.,wHܱ2ΝqgR=],)@(٭̊Y㭿cIPԀerj72TH{W;֓ʻlkp/<x5R缄HapwK_Smalv!f`J|5Ԅ`flQnxc蕚^:?UV,j0ު*!9AMH_ Z<#8jTm+:,CU^C˺\*_܊+{wtP[ݧ⎈evG8Ozct>3B&w^#@* 1MB-)mq iy:,g32 Ť":3_L?!`+1S.y0m=LF멓,$0LsE%~1>Z^/Z\)x:Io\ȁ=g: 'vvS09U$GC=Xפ"η*AmIvDVUFv5JJrF_ɸ%P_[ZcTH]e=*Z;O9ck0{uf,IWnqomzoT_kuS~,*"Ȥ Mz}nR$]W*;ɑ]K\^% n"Ɋ/g j$ V^g50-1\z2w`l-yR@%'ׄ5:$z8s}l/h a~= ӦK j!GC"zgj^MVg$fov6<}  F[? 9w "Hz{PQb(3S%*St1 R"wRY|Z{oAәghɓB5đ'g|fϻD ~VgߞF؟9*u&;?(͟-*~!dm8qiKOwwPGDk3AН㋕u㐑wkј1ySN:Dͻnv9PDbm$vx K |ЏSܤ 7GXYŲM\ &oi;^H.Ix횴\7M &ګ9A (6ob5Aʉc3zAQ؜ ̊^$)O[X}r󨈤B`xZz33pm?զz'5N:Z*n"--L^ZeϚ7Q͡;8良ց|vOY/`;;XB8]Q"?zL)=e̒VfY_0vKVMdN 1yw&c;G=34:ۥUk~/S7u؃0,"7t㐩EJwisݠ1bwN"8%g7 p5,&[$C`p'W5K'//ͬUAR<2E67`R|esڃ„zNbvBx688vs(+vCHYx^W9t硿Se ɂ$HGhnJ?#VHUɹVnHi Ѝ n}`1 K[۞U {gME/%/yY8 4e$JܹOv|':GzXy4Px@ãX24^Xb6P|Ơ@f 9. ;3)沅J;X] ɖ:KM=(_#w|بqR3ΰNbԼ"̖ļ[|rF`@"#8*%-ơ]R{#UJD>H*W\,Ƒ4X܊ң%R7