sssd-dbus-2.7.0-2.el8 >  A bמU]w0"45$fz f!'@zo艓/ p/U?ql<6Ѥo͕m{.F|Iw7;?B|@1 aˋ]En+#c;'nn)r-$%wucIp%!F<4R#Uu0%Rs;,MPq@NAR=eؚ>H@zbw#;mMڑ4 %ШI RS%d )>q( Ds+bϬ[ |*LTr9v]iw@]= OrinfBpp(#z_Ӑܠ!쳩ݛL`t _f>75AB$cH|mߘ> ij4,UmϪU1C'kR]s+գUZ80c659aa62bd7e88fa7b886977ce3bffb5421c54181abac92907551c39894964ec1fa3aaa3736cc303ca2628a94dfcd989ed6914o؉bמU]s x&ޓCs8XhF Wt$֦ Jyˀ:C;VɮBLqZȃLk%y0rZvXՐ1]xOӽ:U^/}ZG3!O`YgrvY3C8 V~ƍ)ClHi>GcN`Jq_MX茪pB?d   8 #7TZby 0  H  `       @ |   22 2( 8 9p:cN>x?x@xGx Hy IyD XyXYy`\yx ]y ^z b{d|e|f|l|t} u}0 v}`w x y'Csssd-dbus2.7.02.el8The D-Bus responder of the SSSDProvides the D-Bus responder of the SSSD, called the InfoPipe, that allows the information from the SSSD to be transmitted over the system bus.bppc64le-01.mbox.centos.orgCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxppc64le if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-ifp.service &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-ifp.service &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-ifp.service &>/dev/null || : fi%%K<  2A큤A큤b`bbbdbkb`bbX mbXbXbXbX4601b3592d313effe1a70c44167775b06693dc9b72e7bebc718b6c9e8b094b8f09f028cd5ad8b15e0d13531d362fd4f515952a830f6c821442cb3f901cf292a92bc5afdc3d1c53a7868079a73cb886913ef0b9c25547fab27df0f830559daabda2631eb70e5cdc8392c97e19924dc9aca4ddcf4b38a44ada079dbfd5f3b5c8738ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90387808ad0df89f5286a8cb1b99cfb6df6cb09aa7135889e137296e7a1f6d91943d1f67d7c8126509da24bcc0296875d8dbec0eea6cb0321a5f0adb8ba79f113e7b6149610bab7685bba081827c9cfac911f92385e0f0d4f0036634fff228e2e5eb8de891c2e09868482fdecbbb8abdbdc896cee801443c763158f9caa99a721d8../../../../usr/libexec/sssd/sssd_ifprootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.7.0-2.el8.src.rpmsssd-dbussssd-dbus(ppc-64) @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shlibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libifp_iface.so()(64bit)libini_config.so.5()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd3.0.4-14.6.0-14.0-15.2-12.7.0-2.el84.14.3baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh rusvuk2.7.0-2.el82.7.0-2.el8 org.freedesktop.sssd.infopipe.conf.build-id060b4a53b78d3348d2d371dd95b23404add132sssd-ifp.servicesssd_ifporg.freedesktop.sssd.infopipe.servicesssd-dbusCOPYINGsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gz/etc/dbus-1/system.d//usr/lib//usr/lib/.build-id/f4//usr/lib/systemd/system//usr/libexec/sssd//usr/share/dbus-1/system-services//usr/share/licenses//usr/share/licenses/sssd-dbus//usr/share/man/man5//usr/share/man/ru/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mcpu=power8 -mtune=power8 -funwind-tables -fstack-clash-protectioncpioxz2ppc64le-redhat-linux-gnuXML 1.0 document, ASCII textdirectoryASCII textELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, for GNU/Linux 3.10.0, BuildID[sha1]=f4060b4a53b78d3348d2d371dd95b23404add132, strippedtroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text (gzip compressed data, max compression, from Unix)'R%R!R RRRR'R R#RRR RRRRRR$RRRRRRRRRRR RRRR R&R"R R(RR,utf-8acbbbb5038db6c41251b9bca65134752c619b65eba49bf2ac1270f74bfb3c8bf?7zXZ !#,Ac] b2u Q{LT#HFބk8B)Z㘛P6׍xeQ%⍩2G׀\ ߝX(lrR:Hg6Q!$d: \ 0[,:L,w:=]}g0ke,U:k|A !sv-wt}kܿrR[FRDS;|.xш{vI˸6WJ1[S2 ݊Ȑ$VWAg-ί 2E߷R׮h.MVL{,ӎ3ˡY"r /ET kS3A8gυL B gR!/k?ϨČ:X SslPpP7KXl~Tn]S5&$zrJ#"fc2ƴf 0"l7崥K'JďLUuf\e(^C,uLW+-OK o4_1\A90t&IV6PS2y2n{0ըf5G,ZczoG< ?R!jơL!x.Iǁ 6"]OA)?aͿ M*Zy?v =bR; LظVGe&GHU^ں1C=rY-,OU6mMn\aa͐ Ƈ\^AZŎRj.ZJCⳛ HW3%PAJѫQ]V` llZY;wz:nUX稕%V賂 ofiT֦kyZ-3^(`HJ AhSȴ7]pfjK|}掂0ht6[ az𤔸_ihY_bE dcj>8)'|X~4{BF60e܂n'r5pKi]%::t4EAJuoJ@#@uH1:9g0A'/fWn.bP9"TSh3;K /[|\wjmYG'jP" :ϭD޳PamSy"\s5T$h_Lo.UŃl7 BjD\G4/NS@6`&PvBZ7a,$$;cHGW!*(ŗluY))C/~r! l/X2$df3]A"`Zڈad? kѿ<8!dZصDe' jN'U0xvz>(jtw»vg^VS$Bnd`]8V%` 8SfJ``9Z%x)@W6jF|ŵ[WB4 Ȋ?ɺ37ڊys \~BEF̬&kp $`c.QsJ_~miB{mY:Ov'Epe ]<:6%n&\o^ wPZ[A QՇF| pN'=reǩ*#~Kk^\6tӘ4d&Ϟ$7!5&:CٗU;e_Ԫ7f4olKeRU9΂L ? kX 3>:oK"vw7QȨv}Js?`kϮ*Ш2K7[}}mXZ*1?K]VOk Ը*>-X_d¿w@hTZMz1jHB؅ nAajV7 !vBMz7q֭94߇#J\0}9 hs Bq%>EmHkВ%ܐPNÝI(UPZI]N q1)<3ߒVMrr5"b~MF21HIר YXRPAMS_z,/)1ER'iIh K#&?.9;x;(Gp0׾gDJ/rG;0侚,(dՑR ENJv*9z?5s[@5u#t f }YI Hy~% ԚC/ꭖjOuUbjEAx;VF!ɛs' 3γn wr\*]Lx fUV¸@(<USCtP)1p@Xğ2IK"ԯCֶ,M:ȉfx?= >mA7ܞR%^2O I0KF%\X=̙#0IqPe]uv-nsfxV41k2DyJ )Gn* s H ]9گBt|-\o̵,(ji(.aym[[__ DqW:Y=(m/ݱH؅Ԧl.^S%;e6_;/ҀĵZp)AT"*@te[IK䴑q瘶Z5pN}\ y \O-AA #%6cz(d.#@&aȸہPI%QyoMld7ڜ"\eGȋЄuiz? l+h1v])\նD.R472]ܾX~ӹ0L8=#LJ5>I2a4A,fI&=e:{v Pg$clW\fIW»VUe4e-.2I%{H(I^^ Yt(QE dNF|τ'Dc>eXAl i,Gf u5áZ%ykYc#Ae/:R=;eǘ]c-uѦǟkp?ꕫWEϥjL/=S'N+?*砗<#i<YV( M!m'r-ן[eI~dE7~zΏo{PJֲ_* 7.+8nD'Y4K! Z/mΒ<> (8`798e1p]_OhAa(&w°fkwlz蝠ﶼ*+?l#vh[%lLKz6 XJ"zF#z^\Y&BUGt^\P0ک-1?Hp~|fELx]@oٜDROe"F&0Tc(p.7hD~S%I)Bdu4! u ~RQ{-\ZX~Pzw6xRXH :6zܴH"[7$\GbGPftǔv&e0V7- hɘOـ9p\x a$i=H>|Rt&jCXkGr&kުFHܻ?'լ,>|\ >r`KTk:O'Azl5  /=ALÀlFS]Ԓ^d[*3[??VGT N> #-02'r>0093ʲW &-i!wbBɌU;T uđnQU&]CZxC`Gk$0Aق~C5r{B<g_8 &NUW>fI+BTrEfC~KƩ^q<q+@6&$9#тV*Udb̈~ L:i[OP~]7˥][z&/>5-,a]q_̧CϷ˵J?H/"R:du |sF>Ln48-`mq2r*5lx{+ij8eoE-t PLGCiۻg{m̓]j;Ͼ ʢڎw0no`sNx09Tq-0"_q. 5! V~{gβDt%FD%9S|Yv)# hIb+7@;N-塡=ZBNؚ(ւC+E)F XfN_2AƄ^R8 SM0o G ( ˘<(Va,s]iV'xb\CМW.%ɍ,s+iZ@դ9lfTtƥ~tQǻAݣdm V\kVuj{A#0拹k-eָSWT=[o-粴8}PLKٖ9^ ͬ(uFүZe|evltˁ[նQ7^: @+* ElCn;ul;;s:k6v J eyx5QdN_x Jd~Ud?-':k|qh,JSKe<]jxt[|E*^̏YVc?1D6vmUY֗}C~VիX` >A)`/pv Y#Ve֧ȿj^&D?N8<BuV{NY~Mذ?wW/Ϭah0tzlEޯI&y-f|[s$N~IU/Lyђ'PPT5m.  Qj5GڭFeBÁjÛ$d07 [O:,A[S2M=Ei2Ru?t.S-|O\rrjW’~M9Dpv9xdG"9ILNS$Uyqz|gg̼uR-Xʰ7 *Ȃ%? 3RXʰ¼DZ soKk#~-Hyg `;ZbOjNH\4&&NtO(pPJsHcU o!PA{eY9vp#3T3kNdx')!Sm[ppx 0&-Q:yT& lGYfTzDt85}=OPwvd px{"NR')]Mzܘy&SE!0sR+0 _ FH 7 a$.+9;І1킣6w C3rCIAa_@m*w"J Ib}.$k,v @^*Cw]I"}yz!vF2T};sWKLr{x=4 kYn*9F\ˀu-y?A3/|^ݬd}]WfqT|UlDŽM#2j&Cu0T&к4:єt#(b=!d)~ XQC.A&7P66 II 0 @pU31zBk+<[˶nmyܸ(:iEh!t4'(Hk5#D5k5(rGJ14Dv&a,T߃ ³Gg=VI45}.5=x&iɯZ,b[NW0p;aiv,ؘ\/D8TBJ`,0Y=:)Г_Tj*%ETq|JDV)4;J¡[yT xf Eph ;Z,u#⡭ luBs:;Esmf"?"_MKעB,0kFj8ǟRV7Dލ{nyxk!1U<Y {"k:ލ0 QFK ;be6jt ;jZ}tmp5s_܍IA;}Z*ņB;s]?fK7l&;QgHƑ/ h`8dsǟ$CskUR^dGGq$[c2 p|8H^@2x:{'VL Rp-Ƭ:pNpB+P9iBE= "+nwq:^`NDY -3]:MH:ĭ )d\lzMvR<4A [yT֔<$L8 G3YoSbA6nПqwWG1zp)\fbҰ8~Ib<r[G\I 1P0Tw$d!q.CJ2MwxΒ,8<8ǁT9Arq,-W hfUgOXa,w'u7$^ЍZ˸ g 41 _xvHyY8U;ucA3϶f u̎24 %gRN |+tyR-<+@eÝx˵_Z)4DPs #zkBE51}}V ;k`6i>2y#f\??!k!?((ΟOUK=4Tk;#7H:{.9˸!i7·)I'ʿ( U.j^v7_t=ߊsY,A`XwƵ/4wEUE/pY4t7@#K?frdOpS@F0m$dHoEVww2*Y./Y fF (:NƳO dʊ)]TdFk0XF9q #` \:#$upރ2C;>LM /,wWI `qr'@XұH׿=L`OX0Ҋ/ PqGvyIf1%LyW+fB< /Exzn0eoi)0&SSlaԜPαܺ<%YA٩ yNL=(w2?fDYW\6/-.Oe.aŻH2>pI`AӸ1 }mcK( Vؙ,nf:v>JQ\K/oqsa 'EuMY-xG[KYO}rc ,'V:'vg(.Y C̀1C fĕ<5dPFf^`Je :}Z"C纤Ԓ%y)l M)\v9kklWd&ÝSc. +x8 7A9|5dr}۹Fi'PDFt> ^$}>mzt7'SĮ J in>C6 bm L#UwphGh&}o緟o_^pܺYx`/=H^y.iP K>$K3Rm)0$ɪzuHS?i{$·kv@j{xa j=:y]kx.,a%s^o{4{Vz@N=M{տCʅkZׅ*d}ˊ>QA;^p6Sҁ 䪨Zs=TOY>c[駸K,pc3>`sG5ijR\ ((+Am2: ȘVh|&o5|_=uBE5 U;7')xA5фvZyMF$ʳ܈Nڍhdz}.m6X;]VG*az)xΥn|dģ〠thsȷ[)joa& Y&)kdZWx. |MRP~/D=iEζjl`zDB=l*Zd6vWd//Yu `bC#*ZG):[&"]3Iݘ_ŝ$oM "V8k;z#QH5omt >-f14&; 'a_T^_:?B 6DiqqrZ H;tjPt8X1:ޑkJZ%gvNNhb٤Os )|Lm5YKd=˯7(#b~g°?Hx"yKiWtYS.rgY - 4OHīXNu+LxᏌ )O qN,*_h!0o$ᴜ9l2$ scF Ykg۹%Bzj6QkfկsA q+-j3o:OA!0m{"gW ]73"6$M[LٛـébU(zSM 0$0v'1s `!R.dLdcyw޽$JH#[ynV+y-EAs{wlQ8o0)$$\GdǫIW" V^H1)9|ޔn}fQ`t빠<.!PSd:3$V0K(6oavP;R[K۩sD3|R6_H8%_x~gGL[2ÙJՁJt k]BZ׈u:Q>Dٮ^ۿ͛G?"-2ZP00tΛI oHM=4=]AUkca3a`eMπ9=eg4!veߏ:9ȃFfc 4HqM;zW+GDb$ǕmG7Re@=5nUIӝ])D2JoN錭aD}s7׶#fzQ9vH<+e^d 7:nN=)ҧ 6#ʽ+p9yvJaypdׇ =w1@~c%m'J#qo&$TaOv\l "J|D--I\URt~Kw|{dI&,DfF?3^uo_4w<:)=mcM4+OjMM2>N`͋U\I'mU~S#(^Zنuڲeub]&yNX1=^:GVmŕ2+Pp"~JMIDm(Q3sh awzXn[ghWU Υ`Z@ѫλ@I9A1af@F[ky=:C\ΰ 4l)3aX#ȿXY84+ i_{&k (C<$Q%SGEf/Jv"F E$NyhubJ^ G(E a2Tէy}ehȋU<̄oߣ#eU+B&p@:݂#V~ ,p[A[>mמ#T"8I.wiciB#8`Vb9ވ#osg A@ZO:x^/qqZE` A2hkvdQPؠ0l'9(g5 hwC'%; ^2Ah#}ϗoLwm8F>HJ9' d gV%bHUp?U.ȑ!]&ޚY3?{;|i#@p J Pj Coߛa\ Ix6hNPK-9:{Ha0{a(O`25-/1Å*b]@:1R@H(Ig$ 2@ʾ^A+gP)?LM}O-~ }Gio Gej-(c'xϺǺM sYe߬ҫW/~T7Gv/ſDŽqP XAhOlN׍-| ď Kl@KB{܄| 1N,q8 eI/vSoWc|?$glaжdeY4;Vf| >0 1 OqP˅d$8.w ;9o4ŸnUPXED!0;qJ94H*Hȕ 0# $|H'gdh9ֿ.kiZ!ɯA_^HdFj C%ӛ ʊDRܰZ1Ϸ؍'_rtQAz1J词0V`Îc+_ b~QT+9K|)pFYv?f횴d|n?"ƪObٺm8 -6T+l㨉P 彷F͚7ÞRt7ts6ZbA l/}Oc6oa5_W[JIMY&r[9;q k99cSa [SR#>RaBgp3‡(@kX *)+`K|m-5ɽTɣ>M1gok5+z4y.nE5Lp%H5ڡΉl+`>5|J4?.B$S,5zI~?vxN,TI!\ Mקo^4쑔$SliYSw%w#?;c K'a%* Z!A#&oyS<B(mK!v/8>$v/V”Գ/Ƅ]kjv]%aӅ sYz&eqE(nm<Kҥ?ϭbz0a8+u3`0m. tA7ROhM  !e@c9{o'<77s"Lo`Y1`I&֫ 괖28&˫CХVX.pN${+^Ob; ]`v֑v"XPy}7zRer_ {g\^)]ߣ$T?ٟגy3}%2eJ3`aNܥ'9Ӷ`2Rh P}r9oaw򰘧j)0r~-I{ϰ[@k`зL pVX_?cp[TBCɛ_F&<{ ՙ d<%HZzg }!'$ކ' @K2|j'~3!E-aB8b0]3#nh!7bZ*+{G=$o.0"F\

ۼ|K"\ laz/f/C#TI_}sdL;*[%2B-N'%DRd#~e]}5|9)b T?T!րDBZB˅+2LqOΧO:G{Yv]bm҃24V++y*fѥïxyjQBCU̚]h+^s6A?W(Hp91#$-8YQ[PCƪc$Ҭ;Bry9jdZ\V^c{er.1̻Z0K3fz4\Bg)sG &e\Tk~ XN`㘍۲9.h|X';  6E E b(95 ,vBۍid!'0lr焾K9sy=*z5&1bg eQܚ*2` ~zKcхMC4lo>uv̢-;|2 3Dwk0-.z (\W&)om8AYEeäl6{E_!" ŀ:+):S.{b(apVQˋ f=B4W?Ⱦ," heeYff6&FEU$,$]Π@4A2ENAi 9%ťVTQE{J9R~#6paޓ;{m*J."@5E(~5ي([o09ӿ'} UO*uM= +hjXZKg"%3%Cm|wmvߥQz~ Z/"/KD k!$`1=*$Nձ5 5񛰾Ԭ=cUqKu@;#Z^ =u*t{17Oc;MӲ)nf@{D>(]FB{ |āhG"X\),swPmlG"3eߎ?$-f{S1gm"(]yScv'/EqE Y>J.ּE8řy&]y }lr)~ l\`MOn[ O@nTz. ]m6 %w͔M6vkxr4 5*(mkC*+S,S2bE Ou}칠%oXؓQjHњO&7U+xW!\`MAl6嬽Cl͒S]”U6h3g^`iT0Ёt"_ D+(9C[EZ:}moS#7v]7U ˊ_n3|vz|;dG$H7 tP<;|C2^08B|8^qci:*Z(kZ 8%L'^@|QVaI)?&"~ Esh7S.ҷu(yPqew(olHu|VbTk\1!4r'HKcvmی:%wE[O;oF@Gl+wkhAH%YT\{a;e rHYڦbO z*`,oXN(6nT7=++:"d,Z$@F&ڱzOeH,. p!׹!R:80`4]hKM` Zm$Pb@{Ԑ. #e!kRɚ"aA%260NhlL*ֻq}0Fc;;g7(iavw5&qcϱ' hGeN-JR >Ksҩ=s)ǰW{'?^^o!/#h(*}Bf) tlq1+Udnl07Rap5c8vUo$t2>>-YC)yAz$LZ}/Z P D D)B\yX yk.u 8;'BQb[&sf!>5+)d?ݲ$/n? _!Nu6~(XL[xULӅgȋzP8DŽ0N޴{VC*ѮX8\f! |N fQ$I)BZgؤd+",]w KJĭ4^=_1q:(PNP|ZU1bQb0 aIB } MR]zuv17ynS0laC]9  L9Y)G`"-Kno`hAfBQMʌ#uh&u\jXwC2gQNOUX3s'Zv!YIY};IU|bźN]>kAo k{<&kEr6wI3za{e&@GV utkBq++RR@1aKD?!XY=JH%)?&Etk ׺(^cj&`7[GU01=2<ġ|`$EpM",|UG:ZFhhBс m>t>1vOKW}~Z3>F_Jb!PwgҾ

mU ʎ*.vQhcJ`Hκ 1Z:y sF&q~ LvXw`Kr;Iq*H}r#NSl仢\YfOyQJ"!X͛ݡְ&4."vHXzg`nv(+'g2轏 wՉJ(v1(>![!mMVVh*j,XޥdFsʡqGeA5&NmOZ#{Θ(FS4̿!@|ͦ,v6iWYHL>EtTU=SC`2|\l&#fnPXf5+T,N/=ЮBF|2GPQGOuv+F Z-jL1^p2HH>]E#-|4I.Z9/ٶq] FEh%!|ҧtTc3ve`'DNP_y.''FV*N44ΕY﫹ݙ\oP˛u-dGߓ|ffy2^ZQc..Q_&QW cↈб2K{7} @&H?.c?1g]L| T5?y+IE<QJ3<[#ug: ҤUŏ]DRH,>oU,H۬ }2WG'9q'e.2q`P߷49uxV{O~ @CÝWX.ozSw'}37~նE- ƺV2( D6IOTäC/H- hCUՈMxwhqtyuRdYkڻ l˨6-uҭL#a6_Z1JoIIx@x9o<33|WC5\B°XT֊x`Ǖ7TV.VL5N)xt\֜(uO?7ݎK~_ra|U;,Q{,HokwàbvÆvxҵV$Nd|/j{#+pw3_zyh,ov67 Tc 'Nynnhs7Cft/nOqN t`}Hukޖ$kG$FV=+rqlLjV'?oz~I b3DĹ("|ggPaǕ2CITXOBo #e3os7+P^(^f>8N0LӁnDg&[`wE7f܈8aE>jgVYѷ8+#.ʈeKG"7rzW%1bUQ;9(`3$5 Nz D9B`wowH4+>z@_f7OTOT+gߛM꧘ױlR L"R/0}߷e;logsxQƨ`2 4)= CHɼGu&!;*4E[J.0yXr\H hZA\ms_c'=J\KmY?.aSoSp;&%N$_su}rRa9*dFk/&h8~\b}" ~bQݝ7~1/vuŪ[ mĴqh2?TZO`OGֻ oA~ULƺ&s_"u1-">}n!d[A6bCq(_w g0&1> 9lv4VFn&.3ub!uځUlg5}Eq_ج rU#xKNNj @[A ݀W%Uk8@k hƸ^%c $ed8]N(jb+,cQ4Šl'ia^1&[psk=Uaq2C稶Ps4j b1~zUg0)݌O?u j6{óVj2t^E6#0MFnU*3/ #c9m."0/ք3vXL.ga_jIh{fÒj*wlfNTk>ܑ9ZS/X;$?Acá}lqf6 w+팊S!MEJcNN]W8~V+~$O5gU{0ӛ?^ˇ ._)5ϒfљڏwauL-)/`]Z:8p5as/ıHijpVko5e*/42W4-ب?y@c8:C(Q*\`B:y!,;C9/}:2 NڳOBb$jPݺg@.sGDڧ'QXPNkeb!AÜd* β$5}c}*k5%\K5`U}z#֋ ?`O>ZK&i!@6e,r4=㵆lʆ5dT)qMH .r)R_r|~)\P1rpㄮF@ppGN{E=sGZjj>'lMAE?hx̿Ag"ϻٻmŔ7'v'MԥԢ-zTZm6\lhh t_3ɋc(oqfU5ł~Ïq+#@^'zQ5y:eݢ,Tb7#E'VQUb9I d &F [>Z mIe(Ÿ]v>ޤ CqNxd%Ъ`K|oBدC]|'T5bxxlA7=; @:;<mdc^4 %}Պoӕ Mu13Yc|%Y{=;]Gv4~ 5=#5>P`cMkHXꋵPWMtRL۶ u&,YGv,Ǫ!ЅE cۋaA>a$Ʉ§Hb;xc{рmP/B;["UuljƪhVef|MG(YKt8Z^~Sep%zkŞk(+Hb͎Yz_.]|Pp/Ͽ 4q ȆdF *R9:![Tyr>L 90&N)uKS3w7Jhma}wz64tEɾzy;*aUʖ \P"@]-MU eL>H́msh4|VO"D97#-[c]XB㱧;A4&(;ؐksAi矤oVt\RjwRCp@k"C+m/n_= otW5/$AS.O9Of֤Hߙk/~iZmr&@--~JtQO~%X'd-YmcnkY*Vpx,N&P:Xr9*3nL\C  M1G{?D۹WTcBP uTODL6;,#-j'Y8_u I ]ԜG܍5Po:GJnƶ}7pl8>օoް2D&!@yIc A"{bbߙdo|+P䦖 X4uo"h9I;x}rWE82~Şq$Fspݡ5|>{N| K)H^~0 vҖ+|9&Qۑ<$B%Q0CT~o_86')㋝cbE/8 oNGƱĽ(ͨ1?)e[ttFK"eOdڵ }^TȓPuo`)z$t]H?:UTxVVT ,K wƫ3!S*:؂xЍ/-2" wHni߹hʊJXzHT}p~Dl:`7ͳW264Smf̡b D&fmRTl/UیK@ ϹG* n |+dŸ7u,6 xl w!nѐ a)yzj^Sz @iUSV U2pU@= 槯q>2NhHBK/Eߌu9eLs槊*fFcߦ7 ņ`gu#;hPm<#"6W+fQ]q)ucA oo7E' no*ZTG*\,&71c$/V0L -Jd~,Z-yCMw ^!bd[ʒ6\)̦SAVJNA_i(tλ}>~%G .i_#ϯ?;SHFM"Pd]S ^RYDh5ì>jp^FlXont%׬Rïdݼt̾ >f?G:@:vX-5VP;V]bzyxcyߋ׷}L*/3;Z<~7!W3E(]B䧅(*@z+QUqϴJٞWbg^*'atLҀa︕ SB>%2fcQf%t?oXT>"J/e]ƠW-SYHY"ܤ ZroB\¼,vuF/i8A*kb$%ID f|вIh6]Аo]\lE^4}.4Ty(a3=ޏfڎʍnULf9#* {$H$xODIã,(Ӿ'(!ʚED|z8"Nj/c?ك v`*fjG!OOet~k]mRlL =v=(2 9eq uwS=0Xd+Y#l#.Zc̼L%!W3AɫvE/t€H|gK`tluHMl,qO~0HI蛄۴4KR]s;G",Wa$MsA2n X2)vXͫZܥ{!Z0kɚ`2gƧ˯ @6Ln6D?4s`E үEcX&<9͘|&%(7tșfR.%a]k1WMV2 (_H^ͽjϬlBӆ0”X|F.\LK 'EH H8Ȥr4Xs aL."ᶅ/^4~&41ff4:;q"5D\if0w51.뛸p!96;]SbLOHӜ\u3[Tӑ`7zy9ItLsx,}sv$P)K̬@}@; sHT{,4SKΒ'{}ת 2ͯ4W>/X܇ZA^h@pN&1\$fzqҤ,}R%;@\Gh(m+}{p>g؝顤d7 ѻ恱J`| O*Ncu)5͇ǻ:/Ws҈}K)LW$A7>eI.G0hj fE-8tT1:!H$ &Z<{ZRBp[z kT WlGIɓOYPz BiJ`$w V?Br6m6-I6hV@'βw>XĦ@gcLk-xy';B2 BSDrC^؟9sR(tOAAW9GײXw"dw'~AC>Ǯ#JJGCv&%({ 5GxNmfy8i,=|2[eA78%Y/ ym2ըC3ĭ .kedso@Q"4sֿFG .P4Yݜ1iiѫ\$םg5Џ`!Sx@h%j6vӒsY-UxO}WnC_|GKXݨYf1b-hq#)!A6ȱD cTPH;8}i+fTvr\|?WT2L3"x mEN5q^bNmm5#?_2X%nx82i޼RTOfQwVΟW~?)]6I_9Z3] P*t9Z=FL]>3zdL{d|K'0Wb|A+ḂybB]Qbq@Jr~b\P̒"R7#rE E6X\vV+Dr;4ŒD }F8r0{)qw1K ڮ4`rRO XuM?*$K/)a}+jgb, S$~IW9oC}p Ρ ƞWl~fmFd#pe{Jbat瀁u~9ԙ8U]!1 yAbRTb O|] 47-R]Ώkҏ#7'zg da(ܷI젊`,,c(g׺gk1Qg1#eM1/Q5Ȥ0T I ]빴p{ݾ>֔$^l>'D폕Đ*e8C%O7=**D[S)1;id_{- ɆDy$ieD z5##H0 8owI(7()6ڷ&7k^| Mqp)5ө}ŅֻAmb`iN?%|'xwvn̯|-PSo5?ļJb$:g ,G+N9\,7 ƍO*gR,"tƖ:S!&QE5::&ܨ赺әۑ^D oík|Pߪ"Ň*1+M?Jk7yM+F=v#>?8+mbSLJNDJJ{==z7g ]HЂ)id\ͲA߆%o;E{۟mc83cT`Xe ?ӤVYnZZW=᳙%HH+ϹΝr5T,-e<ܐ=bCX]Mo~ܲn`f ȷF|* k4)p0Bb3.RK [3!**( \GtlHanRhJcٳ1pb¤C}J^5tvay,[遡&,.ђQne(kZ oj!r?q\˜"S WT+ug а$[/azfi҆qSij0WF)Z0~>5ƫ%'uZPe$?^3YU3}H_iISPA(u"5ua=$^C"#nwaQwjK4{*pw'S_yC8W8sȖ9jNq/OhXֶRKy,̘$ޞXwgLtxQG3[6BM4t#ǝ q$e;Cj.WBhu8aY8*xH`oBAB"|Tኖ!b,@6 }1V#X;!b@ 71}SF p!Xo/q*y\z*J]9%,,r%Ӭ?ß@MMt=&W@r -CK_ ;:ˊWaDMB4ߢ?Yr>1)} 넅N)[5Z_]7Jx*|iNS?a[&"uo"lv}lCݡt Gtbjۏnʨf|."Hd%m 2}ۗE7n_E.D¦T&QR6IPV/l\D:sTp =y?xknqjs[`EeI'_$vbX5*ThHH:˃-a`<ɮWf ^2A_|:I0Drúw8->܏šf wib2i  sbcS< 6IK ?HR]|znCZt=5Ko~UJ}!Uč~M$7ޚ_Z?%\VlA.iJT ҄ HEji%(P49VS8en!JuѷjIxF)I`> k6ǯ ԅ6;g%[Vz:%M5sTiS kjo= s8:{3UqCk6mX:6Sp~qY[&NM8TZ#(zݛHJXHC ^YypSՍήvB"3 K3-b 'W"$3Fu7SFdzyeոo.f-l: I>.HIW$ ⥷˜{WejgQ8-:۪,KX(jD'1bAⶡEqFCJ.p»w24%23sSw9'QDžު3Vy>Oc+) ~3=%e7 (釈V/HQ]iW-`@LdiLm#;1UyUH.CqlW4ӗH5㕒aԳdE4)p Ѣ}a-Kfs-vjO׾l^7+aؚ]13eqvUsF\k3Q~PmhC"=SkI9S -1:d!N5+Tj!7pẑׯⓊ03[l2+~D_13J5 M9RyE @o  YBHnl^K$Ώ]f8_@4gD҂D7M‡ѐcCx/WX4 i_ tHaF U0<6܇8b3:Kh\r%Jf_ֆS"86/VD"l7L'/ pH*saxgi~ۄ,v+k|2bn V_l@M/mֆ0Cm ;dD\m~7\-ahua4E"{.>Wn.>bU:oӐ1ݸ0p'޼3̟Be}f~Zu?uiP⌥B^fr#U \j^̗s" } 4 #w#k1%`KKvhfg=˓򄋊֝O*%.fBbϦa˥rGn\\\g|_x; ''"|2]ұP׀u{3ef&[@P tFlޑ D퀤ޭO6>M5Xq799Φ$™ t/scБKజH:w.{ս3r"r#Tđ8Ԭ0p81[cdjc%/CJ4*YX ?xa%cBzuu X }Z+b&`I7mSqwƽF~]cL5&K!&Ph&v>uGk@ra<*!F~cf$/࿬һ We0M !>c.B&*j=WeW17gn'ğ֚th$Qa25=EQ̜fXt,(ylw=z􆅽s &A&YC-Zك ֘#Д-5E%xw?HO'}~\kʞyM3smr;pT:t*ޤ9m$z< x1^,[EvD ^<<5+QxX*%"I#Vo=0i6?Y@NA(UʸhT{U:y=SfS8…@V|WV>i-K FBys3婍 `?li<qiQ[UB247jcХg_x_"*8pd)R @Pl5I :ٸTV_ኸG!9sֈ}x)[n΀{tZzp#-J};ƅ.Θ<#+;t[,-)#JߗԷԜ5't˩M!>M xȌ +ksSP;$܊pD{- aeQsH7U _N\+DvLp{0,l%,"ܝ(Or?eP+4Q"xDuQ+@HCݝcҳ/W%$9/c6hkL-rQ3Wk)%x:`̍(D*-*i0ƕgV7O߱'u#)kfT_]2vTퟪ.5}ƭ!1|@ SPr\/+~R >_oyEQ"?vƂ)(D3W~m`&7yKX}Ofۮª4V?fqTc ƕcbMA nq*v$gM&=l8u|ڝe7*"ɿ! Q`~@C(1Rĺ3$έ{/ɼ'(IUaVlЈQNGn6YxA/#_S;Y_<#[O'@8H#sKڟmzҊ醨h&QvƚVH}|]wb,EFи5bI6O Cb~OQutm;}CO `#^ :}vh'B%g*w7q yo燔{(pi g &I oq7]"fnR[]yk嵥yw582 ,> X]w^:;’ˇq6l齴8]F("v)lVtC"NEw tqׄ\lOvK=_Ԟ0NIشՈ^DjXٓQDӧD1uF&%ݪ'&weAT(A})PA FSj/pS¤RS|o&b+=))Gz56 !(q=,ު:;G<0XnޠRoO3,>uDuOނBgj"ߵvGl0c3Et&Έڶ6\H  bc2&Xӂeba<{ǭyFPeh3MfM,5{0MAZEb29f6yӳRUovE2a!6H=U[HM -.*$m=BXLxZӳk߸7:lcdv"qt]]5q,ȽV 9k5-rr'aHsqq#$o,sn2mQ:X=f3L*GG1{rҋp]{W=n14 h9JYE~(>$8V_?הpve`: &TnuqNZ#y$0Y_֦1ȋۦ7h_њ={tH<ӱFDcOI3T kف?w]Wy8K Ft5e5Ѹo&TczSf~Qe9ao! %^YdGAc{xMZN{7}6l/if= =$| HYH!$|73{Wglr? %-8+XG+ b>q;̃2d-yj ,&Yذ-gk"Y/ƈl \=T$%qSY3^tEZ9~ |V q/#H瘄O:RXJA #9z$(Ӭtj\Srd39qUZ䜄} eRV"z~{%ڔ.\yG&r^SHTP/^ħ04n𮜕>Է*}a&-2{*BK`!_, hR; ҥWJ6BHLpR_KYV#<,1LkI#[lؐD ħC+;#`W$qgʫڝTv*#Fsp9ZTdoCaa!sd+Z9I+,]֟᧥RC݄髝B #S 1<+7"j,wEHK:B^)G12!X5ѷָ񑱘8=O>Ѧ]bZK,0B!T~ V MAwgMFQkqGA v&͈%<@5|"۵Q B7_#%\%GHdɯ6otvFӽ޾v f-V'~bl .FP)5]! Z^oU_p(kTlq]OypP  4x*A3BgXS*=7gUmd*I]8Ou =M`>SPXc/N/"Mk IdbZiGkjp?q8)aY*BݳxQ"ijhe^#NU>nB(5 Kj!@܆~kc0cjz{Rj?I,C"96"P3(mgrZaMwa)NtP@vJtR ?+^^Shbomd)حw0`ÏkjSxHٰ?x;^HsMK#J2v )&R }I8@Z%e(uc@˔ju|loç> fߟS'OVB#2@wPIݒY.FJѳۭCkujQ"fK݉\LqvAPz$م (gS* 37w: SK`|)̶ގ͘s g^!HE 3! 4dRcqmA3/7(v7x^w.H sI˅D˚n?i_^}!s6,SЀ ?;@NVx}bMdIru< ::ϊfIS xlyO7Wdj&ʋ,{Rz7.*Xfp =G/tpEb/4㺦?Radg lF>b!RykSb*[ 9Pb 6mG"&2Z 5ED3foi &9PyNMdNZ~x۾ɍWe*=?0w`5]5jP"ٜ ,8hX0pʏ%ͅRoT_1ݰ'yBae/Zԩ-㕒ܺN\g{|2g#! 4땢epͽ`8D#ܙ 5D0hs 8]yi['ҹR@om_ZTZ-ɹ4o*$2OX^.:⠢ױeXr/iHXE)#ɑtf&!Z!Aso2δ3݅ҟș4/YWF7Rdp↱-N(- ߶" o"f_?oDo3THROOUDQ^tq7!*q~:!UjlFIFLfO '!F"u:~lbO)%DK,cæ`CDyRyq E7ٱ朥~Z 0%9@t%@l':/QL^hʞPpa-=}N/jc?(ZVyG5.Rd s-;įQ荷F oj \,ricvUT4ҟUVr0q BvtT;Pık.A<= [2XAtp̸r0'mj25e3ufW$(تqS~6yiQD 1'Kfzg|؈vEDžd0S¯MygaNP2/ P~\Qn 7A/`hhbnQ$ :K  V 8$MN+~1q mG1i`.~ .h~y3<|ZB]04E@f&A 920$m L-[}h"H1:"4ė[(V%CqQx @*~qQE}h it (yyWz8bϜ0:Ec]Fw:V[[Rb3rSB)Fx?h/7t kEZ1J̔XMHۆ2XFAn㙌t凔2ԭ;O:%o't_g&\Ϙ@' OnUYhdr{\A*?p.q^6R'L C +xLF+$~F|, /)2K=ݬČ$dĨy,~zH鉈mXzP̈&Tl+S|RD6n$-UCe~J  V=ZkH`0OeV Przd>L @/ɷt1~) 8 e1ϯv+bmz{Sq=GO0O4xeM@!m# opa 0nzq˘|Jc P (>A}3/$N\2y?,frLK ދK5#9Ϯʫyw(|qU}BG &IayU̙J?R&EPbtAyq˜0;sD8 MX I>2jڝ!I2̓ H-I_^ΑPfU/ϳfv >/O E \!IZ{@(8MR!'rթ{hcLxX=;];DN+>GbG{IQYWwI#De%f?ߞݎg+OZؠ 5G&Uo| 'j ^zZ'S9tbR*ofR/X\]jp'}l6r3 -V[9`ȫKq|zNolޱs d?FUkTgD&PĢHBA¨%!%0%ҫ+A4sY8^Ffܢ=ٜLGpZ&oC8wѡ" /U4}]%MaFr+r9*JsQ bѓd9;ySv2|*  #瘊$˰+ : NjD.HlVY ;Ftxiz7zݲDe ub($¸<7Bh# ^ׇ@ &h.Ǯ9޶D) ܎Z;'&쁀y&5l>~sNgAWw ~;f%)v*(S˶]qG57l~"VҝlzXJ|L(h@] Ek_ a*&k-Dl 653{ʋ%c^e"n}#k+A1W\<(UlY1֤)-l yLܪ/G^;:߳Bep=Pbgo{bΪ"|-o4zdAnD[^=@ /stfoYa5}j H]P(꘧ `5)6 QϡÔyi}_)庐tBt;ds6|BzOڊIp̃n_9z0LίG J:poN{|BJZIϸ֜ :=G.n>!{ВN^ ~\+QnS.q+y6mʾuIg(4|xﶗX=/99/izhVN^A_ߌCq #Zt~3>d8U^tԟY H+#eE"ơ{@y bY:kW20cO ,enNCaQ4[BrSxGx0@}h'`skk)X*ҺfK죣>>ozpٱЈh_"m:bJ8Lڄ:ˆcsЍqyk4K5 JFVP7CC:t:+DgM]>Ņ%85W&| PjʰTw^I8-h.1Z#8";I}MQM[YC Q^z@jCwvlsCqZM=!h77nƺƵY"#΍x+ tb 2 w*iD|ݭeXOMg2QnUbo(B]JY1=!j} 9dż?-/'aayښ^ڎ` 4,I.Q1 8$hƸS*A-"E8pwlMMSSPwr aL4j:,@ $L. q-{H}P)'L$+;E( λHd#1VT=&dIf;Pu5sw% VfQVb:}4%$[rQKcO_G6fo {?:$FY9OJbf:;7tu6A|"At=5CTZx!ZZ 7T:,Gu")-@9 =^/A8Lx\oD?̝.@4 9򅧈gL8-}V ը N '4 |t T7H+#Cs/ 'CISn޾e5!4]Ґ3-#ܧ?3$tC{N̓leV3IĮIM}"mG ^ẽӶ YVf>SC(8,ߘk"-HRBԄ-A %#:˖Zi.+8mjWYd2c5AB$J40as5t+Ug(cyV ,$ABmPo3)&!k: %ť|$$'z4p[a,[$^|;[{T+ ָT$ew& NдA*#P\}niNsCȬT?~؍) ⶗/lQ,;c}AS X^PH@%f+pZpx\3o^~FuZ Jw6Wp$jW9wE\ |dAHzFO4wK.R>KP(.EzF ߚyW[vAycAPG`̐}"ěy1NFj& Q!'+=V9Nw!HXjJ]0c6(=n=;s5<|RVw IDy) 5h.dXNZri&r 2KOq۱Ndg裃ct_{UtҼdEi*8V5gtF6 4y>G9TW iS"zՒ;LrQrO[ͬ S;Nx~Ĕnv0wP+yXeǥA$qj >uHwBN;taJE**- as~QcǻWz7g4ZM]TR*βvfFӲ͟v\w஦ 7+; 98ק51+<5]N)4s wAu,<2y5 &x6%mYxb RB^4i R³8zA;Tɣ-hcGj̯Gz3 G!Z1JM ^Bu25S̓ǵHK Xg]`B72OgnEO \Oh_Y^@°r+-Π\JH03H򜃋.py\QAجj! `x ŭDd}!;4x`{{(B5]KO>൐A~e *`zPpb0~;*]5rz]DDsS_0{:btnZe [ޜ?twwt}57x(;&ˢʚ2w z~Lk mGyHE"7. ?5K.0 {ڳ[J8GV.g–5$f2jHrScI%1ܙvEϥ3K̕ҥ~ap`j̈́FVF&nA/GBk8kh g_SFIpG)oݚx0Q|0ٗހ{r-'Ŏ;_YO)C_ z28ʎ {B&8`OlhT02/4)^1|ߠ1L6% 2&R_z²"KA o[/S=]S8Z[e5R8ܪIw(o˰LJsWG<6/)_kֿe` (e/7ѧ2{@? 58ŎlҒ\y%#3c}7C@9mZJ;Őr}ϐ070UQU@"}BGR^`m͛j@R( P\Bح_FE;XMYI֨pv|$A "k3ս}4h\(^,-$wy#W3=2O\\ywVRg%q%M\ܤ[6weR6"++M"H NP1( {ҩ4[OK 56BJH3830j?{Q> E8,Z~!M}6Ӓ/{?qqlԆ#ޗm+;2P5#/Q.ɢ )ViS9Ld~x(!\[.\Kw]/lli*Q!ݟΉl gm/D dˏ/ y ƵK:ڰDJ}b_daY!elwI$@ SF # lvE^S.d>(^5K$b!At9ih9G$gSTl"0܈D"Ku*bڌ`[Dn H[M.M%"Ć@ {]ʝ FZTbjG`x2?g< "MrQZx.QaF6 "qKmɅk ,q&|$*X:SĈP.@ϛ6MT3!yc{rA~}ЄNP;-s\pNǠ sw@$tߊZz* /Zq< @wv+q<#.W=o6}1 j]bVP51q+̦w%<wXIȵ 6*tm(@ _lT>VKgA%IEt?-d+ӳjk2E]? ^Yԝft*F Ap;^o:j΢ln%匶'A.{&BZT(QCcPlJl|^,h N)j"k U+~Vy2lS:jLdY<*考 ;LrՓYy7 ٭ĝ&nѸ;+u\Ỉr$񭾼RJ˸+ݮ3jəuNNokBFamWs5Ak"](,G;hGLg#xt`&rR# W6dR9f] K~aEq#X]qIIʠqT.cm"^Ga 35kaVW{4&֥TA㧈36%lA|_<џ1)x -b1.hW˻`_9On (h UiC033Wq0LIJw]ơGWcTE!]^\/*,o!#]mċr?S=bn i9Hhq D<4螠\`'^,pvWOʮ4*; GR[dv Ւ*@\lo:~77@z|Ԭ3>OTUAxP(q,)ݜ;b$-\_{E ,[ڮwU;`?!%&gJx̀%.&̖=qySiHtDBl P]SD]m ǡ*vcR̞[ւa%Z+`jM.),:$맜oK_`:@g{Ǐb')O^V%!xBdY^ ]#^gq欨4V֬p$d?bܱE3} W"6i왂kHrA}i+7ߌ}l)sPGʏ$$Ekk-vhfI/A1 N,>X8ap'xDneW^,Gьr=_߇ 1$f1+FB9Wjҟ2Ֆg԰ ,6ٶF)WIT܍CD4@. lmodp~.C9vhˤG; W2_r.LTJQUm^h:h܌;@U0]$Qڜ u jlhJe0ڿiM/R[q''_cFV%Û$(%ѐ[W`$pQHn\ee(<^}ݡC{sZe+N/5ͲDE[欫b>Ff.9 ])Sr'Gl~ u_&{FƨJnj(<ے ;y{_-HqsTJ,C)sx{ֳUHgyZN-qU Bcfg{`J&VZlPcEu*5~b,57jk{w/^\6oPJO,hs Xi%Jr#[28$Ҟtq6+ C"ˑTy̒\8W[ UEB:J9+p?Trp鐒Sav)+yMrt3 Cnw6 Ugk4p9"Sl{Ӛ{q`?#/aDQi6m cJҋKXfe ]J5DBE?=)9(Kyɒp)3iXP߱q{ڍTiKQjn")u#dK3-;v8b硎MaN{*Sz,n>6J7|:1 BX1B]^$O3 o {K^'5bzSjl-ߵvYU{!P(ื9mt6AnsjR:uo=&VY}&`?jo/䪀{Ah @ RG^u&{iy ҠP Z{SU8 %/%u\DdO4Wހ'pZ>Rhn ^5u3ƑOuq!0iNY*74Xx|ΒՕ6@9Mo#b*u3ϮEȅi(:v[k0Gsaϴ""g߰CFpAZYeE³ %--&G&lf'#=Zٚ obӶ98nF, QUZ8P1qX{`V%X 7:b\)?rCj*Gqj!t %3o*}ҫZvw.iW$N5P"|pr*|]BZEq%c=θ>W"M|(X,\CC{nV>&{ͱgyTӫc=30Nr$hl׳cS$3@}]M$hpߜ%bkiy~2aph~3*nF8!X:F2 H:\r~ 9,݉_" ]$x*Ejn 7kSFɥ]k!T)^zHe(ĺl #k"Q̄8:\,xpњ3.}/J͚z> whSfZGN'=rK.eC4[ Iű\WН6|ソuyM ̕>Y4/ͮ y̶#W2JJ1͢$eחboL'Z>FNA փ-gXGڷvB-3sO,Ӆr~R_o ]E'OG 9H%:t/<(m"ӻt?E~00VU4k$[;yX iOW"x鈦)8XsyNpP'JvV5 pY2yjjzv X2 nlcolS]!xl1C0bUR ,bIԖYTa<hC}Wi3T`9`cxQS:j.Jx#v. }dݥ 3h7AR!,8ղ]3}"|#1 waz~>@󣥾ڑYc \,/l S.w(Fj\|R4>8i[ \PVeDȪiLpARcSVrwg? $ آ0ճyCP}4QHOve7X N,p<e6FY/~e?~u)GҔï‰<1yI_|0ѿY}꨻_#YԊs@s3$pDf<\IT6y6Br7f)?{L1@GT䔴܉K& $"RXT,uEcm3fsd!gB $bBsev2ԓ~֍@ QxSԂ&"b5s_L'3cBm`Apy1iwj۾BfF "%E(SL0Pq}?뺐C-ww)EG-&.1\fq" VEXibm '.Ͽor v|_lo^RiNn* vsĶ4O#3o qx..$Zjdm<誐dk&‰ D^ϥ;DaqVq/U f<a|,sAڞ؉0+&рo [8qG$ MOac4f±;j?ԈU|$$\[5 U,Mi+$|d\VZͼvnl9j%F3L7 St>R,d֑Cm\Aq-j9ovmD*CVV~KH9ai: DN/a=%_TDŽea_׸ZĂiM+~5QgBX7 ~C40 M!ϞJk5OFjM 痀|)R -kr5u&vݹSL sK 6sjjI.K k9cgr#[(+wfB G%E}t(KZ4aAy7fYZTl@g🧳v9v+Ln4̓ƨJ'֕d.{$o"7>B֞ͤ5RIԚx%',cٸJb7˴'|Oy~XtQnosB+KTv[]Svߗ}cDa4t9⋹\kM8޹(&&ov81CuCQw p#nfz^xb860<ƲB#*u8& TGH[zR$duXK"b~B5B|.Lإ|0>kL;VM܆*D"r9̐usQ2M%v8r DHח[ITxqI?PaN;LhNT B b:2$c+z[Ub2Xs:cSO89$HMyHCG ԝZ.AQx܁/;J(2&Zu[VDi騩R<>M0& 㻲Y22d+7MXwTkf_HطU5op!1W*-{2eb>rCZ"i#x$'-vdWm$DG9./>13a.\cw`\ eΗQ:fU!!8 I`u\"R)%`"6ɕAxPhoٵ@7sώRk.f)mmյiH}Z/D#f b6qiy8j5g FkV<)Eۋd,q]*RQaLaq߅j=ʬ[o^U~$%6AԢ~DJ-:Dφ|`z!.f2c/9<]!M֩ Z ;N-p04X1 IL{6EPw (]J|_F,9n*};TPabщVe:x_  :8g_5^}Pdi,6vr1hL"vl>ms }bQkZKas͚v 0?X uU ~!čbst{aУ]fortߊ'{KC\GRĞ}H4a]rQ8+ gflWmQ`)&Zbu=PAj5%n9SLZ)h6-.c2FwL bm 0B}2ʔOhw<.{o<{o`+1K{OŔ!࿊.Kf]GM,q+/9kB=<*x_$IRMnuMk!' 2c4ræ,ޖ=h#8jf}3Q/xQ؊DPfoS):<I'PqgU3# 5T΁6 =p?%{-\&a= jxsjl b:].d`1Chr/y=r %Tˏ!1N7QB#x<8' 9H{S+C΄ ٬$dvP?TZeT:-ID2]L@GaU4]Nu 4E̅o{ջo]w6A:`7SP;9q܁IuQdFgh>:4 Ɠw|^˖gAyM[%|߹v{x*25fΛ_K3l 3[*%Oh0ے1T\\o?aJG%-ti{NB\/Eї y=pet!bSg+L1ʴ!`/MLe+pۻI0+JZ~6\シM۲t|kwp>L\vb4$|]>!I1Gؕ н:?)KMp {,qjlr)xzcؼ@ W#͢tW;8cIVX_xa\uh"i\e]Rߠ$bԒqCIQ{MFҸU_>ְPaDt+HPۏ!v JcF@6ր5n9A2;VM^l8:"EnϾE2m]xbL.J1F8gidC܍K4k?Vϰ¬!Z$777WT2It:N)LjZ-WD`|yj(,;LKpڵ5GAxSΏ=D̘ ދC:M (EU_B1P_NF;./9Fֱ֪l,&~g_Ag̫յzguXRB۳ԄZ<:_m J`?Qrg/Luu&bwѭV5Pf'u󝅵[KLHM_׎yrhjj5fM嫺F_$z>Iah*.`h3? y%!c[bRuq{p.+]@\h"uuИ & @-aBVyXS9cFj*6{-;|feiQ}" ߵqv{|h6j)|.b&ѓ=p%BEtӋ@ik\[ ˄5UӞ[ϹCSV*sG*] 6 gt<+g| %u>{R'Ű 'O*,@3x>~]Ó*ui *(EzXVr#.P,0'G^" Y;lJѯ"dmy9-0 UdOZ'm<R] *5jGx'=!l@cA;v7 ԑY\o.m5l;l%Z+QJ؉MA{gR>#T?/ *1/xV`ٛ)$Wb}] 7 Ǖ"@ĪG[v{WȭM|0ėCuPX&yCau;#ڤ\! V0m5Ƀ,([M2 t'hrB.d6(VN_ZLf25]n2)G&+D5q=R8$Ws:Hx|KqxTY:j_ J\'FuJ'6mc7Z;9+1;[%>WbeZiFnyz=n.,,}궍_=O?bwD^^7^| u#G)=#gj}B/z+}?n87d;bWgB]2 MY?}` D=r}?oӹ>57..yӕހMD1:vgPʝ3@lj-waW1 ﲊUfOJMܓ9rɟh|bCxDWaMr!.Qaץw9'ׁ뵤Q'o],2a_iA) 0f8cω, -{ڋQףvF똞~"cͩt7Y1U~yۓdLA:2d%X_fntxi H;]O.|sOy88^jlF 5f<L2;Ouu)^^W/|nqQ}+4r'xXj™aQjǀ )/,c?^t#Z|> |MlQrsY",߹vo`7%@AĻ’+~^Ϯn7Ȑ.CU\Ck $kI_1/5+o%eX5+a!gN]H~,p o#{ZW_@lXRC3Kw CژMl ܂ TVs \B1qٕI>v T SS̅w]LDý9U'_tq8IcB㇀L*u@ɎjJ5 iٌrRlZrr3Nzt ?I+<Ӑ)>.z[ؤuyO]MST}˜Y" )e-}%+n# ) 7qEJ@@Wܛf1fkilc#iĆ:Y/u )16;pkaXaF=Ԃѽ*CIh]'BS?NR~WalEMk8Cc*"gc5@ xҞZ%(M)SksHaRRY0hu'tTI<܉B0ohҭ YiiK֡4 r?$x=N %x5Ap:N][fV\XIZ/Nz"sj2$x$fQO{` U/6'!^tPNէ`Ձeь}@@g!%ٶ0VT5H|F",Cy{Y2%ܙ2S2#Rf.\a`5G] $V9fwiuٜXcZtP|O 1c#΢CW~-Sw.JxۥpNY;o %aq&0u- A*fk-6{Th8s'hS~TNd唧tɓ0RfT-=wh;H)$}A9f &|EhUmH⺏R6c8o [Ԗa`RAEP1>HGFcr}8c R^!OXm812, {WZ|2*b4Q} ֓X$mc=xay$Q"9%sŮ-r~Zsn_;8x͐w,T=p*|)%/G$趹EIBv`gxS쀙86Yv`\BBL6>Ҫ>9kN~gL](Wuʿ ZwԠq*k~4F!c9_$3TEFF#KeD*C*%%r eC-J;q9^"SUsQ]W5.${xi$i*uT+m"/OVgD_ =Q}9왚wWj[<ɀgP9 AgX` FX5{[+o*}c#P)|n qT.rRI#t zդ1rz)s B@dvQƠϜfepcm*o89CL~t!Fd_+(+va$y+>pjd,C}Futkf1&]&(Q]P'+D[S/ HԺyВvHu2rSaJrv2ɞ2m+_Ye>#AA@."N! HУB 6>v |k}6;>}/rAZYaVTҌhM.tb[emY τc40x,%BvCW?+1Dֵ<.jl.pP{r$O a3k Aƶ6]􈆵5pbP3;V&X aDž0Z74D"\PہJQNmP$~ c15^?e@*[hc &!l2(|݌石 Q>׍rxĸ~9rw9Pr/c0"SU٣Tbs25_*=?"{ 2Y-o8PAlY`ֿ3QmeP# H tU{3W-_pu$h&ps#Bߋ`aXVL :d:ү%m.RZvpiQd{]:+,ꌁ?TR2SjZ%aH%J%y~ +kyP` >q:0Qn/ nQ.inT@[ JJK,KT)=."T0/9\{Tt8ad{V#%#+7N.DYYNm`>ľ/ }H2Nz-4-?a:?$ㆤ+y<.yo]"Y>E\DҭI ;S9\~_,sK=`L(!Jd)٪^dB iGrzկheTAdz⥑mʎΐ`5נjja 8u[Aڤ~~Lڊ2zeʥڜD0H #xAս*M x7BL q+0o;rNnQ,;oOۗ`Y46Q,L``lo?t 4S@se ɏ BI,Tx37@*j8KFŸ@uKʦShWyB8B!JHL3R(C9c{Uxn73>H|G G\)΃7io{ Lkzt#i0݅9h$5]I_$BM6^у CcCg&*ENV+0.+'Jc3 OGm&ۢ9OƔ҆gu֏,;ؓ 0| .AB8r?K-c sLUG 8Нbyl$%;~0tIon\o] LP/NW5B)!Oy5<˻ ~ zΞDSႉCe1_wKS]:Y8 O<$maoa3H@K4#s%eʀjδ9S $vs(TfɊOa/S= xCk8'hޯ .,YʏG1PSc h–|P1$=v }ng6YFFD-abh 7@Q lFy~P5ߌ*0E8SI׈ {(O%U~&bۆ vF7D5r?Qz@;pnb|8!n@[㭼 2gD~؅QFH̖Jk޷.ê7i ?`JN+g.xzk#^Y8vX4IA1]:/,3ϕiqՋH \Nmk1JUBtJrNգέ`KV$e%RF6+"'VϢ2@nOg>iC;FST1Y!'-0ehNFj $gB9 O@HƤ S-m6DTTݿµD`ING3"4۵e7cġl'&Dd&)5RAAtW).tXlÜ݇yNk5S)`A)GHVu;17p "SCWikdDA0X1zjni\?2+UlR%dRn_*vO*r6xRV3'6].c*؋TQF@} f]F 9}Z2Y;PL86AfRm1QȄ_O/yR ҕaR"KI"St{2+{GD V2+ M H)--c uT@`Z^c I7Gmsa?}u6\Xq6aN/(YcRqoAW_惛ӟ.5Z <Kh](G?C8;!d֖o91jtO̚Jkf0QZ9j8%JBNT)'h߯FY#d;Ӏ'7=3 nIj\2N<` ~V?h㢺ȖGغwB tׁ-JRA|c|M95ͼ?{/PW65FզT:Z#n"Za۬K/ PKRҖQlgSw]tU7-?AE&\ ,4(XpzPcZ%tA3~25 iK!(P\lcՃiE[E+=`!p* /z› E+enՉX,Մ'&oN ;Re@: Ej_w@ oIY)Ut`jA/eL?_2uDv(1=ovу4kzn}<d]FU `,\cYFqm-̷ZaIԟ$5ƠR;k5.kqszsY߿%_$K2b?&c 0oI24uWM^j0|R}==4AeEܢH<BwOe_H!LQS[|"0Ԋ tӀ{n?Z#xw>_ в 1*)s&DžIuLGB&FWj|a0k-K ogtu*P_Ȫ˕k"Ho0. 6;,yZpX_e\UfѰ~ K'J[{+IYnHZG &D`} % Icp7ˬlJW?~5HW0OM.t\2 vl~tIokPPA\gܧ{ɓEn/KoLpʋHf8hHB>1˜dB;+6*{"וUH=܏dϑ:)v4qդʟ̻\܀&|/NEO4BAyp=!W=]~bx$ .=H =DP{m?J{'Qsq [~OdciZr&`a~l^YE# >4,4U k/T}@[|fX}Z]ZZe.XSXOU3odkAḓpއ5٦7-4(97U ?U$`4A#gjqvR [6lIMliu& Hw͏"rE ?=ɯ25~| ^XƌՌe ʙqTÇ'z,:kha,#e=g֜qIuMBAX ,k!LsCeOib#;`h }:mPEF-=r&Ro0^#:wPqZ%{\ =?Dc톁/ lԨ%HW:76jZIӲ>3Vr/^H8yTtPU!q=(} EP W ^nSetw[tn_ 9Npe! iD{^2DPq~Ńm$> d2a kWsqb@EvBUC8ݕڀcR|~ep15]fYs]ZbgMXAT 9倁) 1lU!VYÛJ?.@~d!-e8:Y0+#Kʆ5]}ZO4D} /p*چh*Ukf:; ,^dO޶,N$!?|UV#n:dAЙ9&?SU$8HĔF_LlEq[ Mu٢1*n.kv0]V}ߢ5RvPb!q_֤)&~d3>)ZY&e&B.1bWijw \\KwDWD$[vŁ(XHILM>OygN+t|5&O*3Ҟ̯-HB4d^(1Fhu.fGK\'Z¶&t4ѣ?6iY/byt0ep39YOR>LUqde[eA|x$QJ˕a #sddz-hdv$1r" Y ] "vi))ըCf~َw($pc/ȃP)+Mԩߢ`Ar BI^S5||/2nu[B+Tcxi!rJhNw`nv3öՁ4$8ri3](:ƃLXO&('/%ђ@LyԒ E(֠<] 7U{T⏔1V"V_'q_UiNbTTZ=/0i몡8:A)p/-l)>XuEDZ+8uy 9U64p(=A3#RLYQHC捠uapƘk+-Ӳ`1`CPS XF}Ct"[oҌ˒O#6}=*[]jո6ٕ;Tc5]tTjki X@- !%:V;:wA=}82mGVIۚc#żԴSZ]zFiuk; p9~6=M91کnt ~Z\MbUO}髋~E@"s,,FS%>M2>:=:1nzvV@agj=3eQ"d~-= ez1 x@ymwMSүux;j>]CgyLU@!pCoV0ޑE Vc1Q٦/,.e ,z0BIfB2`BN 5>pGY\bv̬f E6CReFp_8c䧌2nK0]EIdϳ'^KcR b(6O̍ vm\L|&%ϐ_<0:Q>FT.;(]TK !CF%n>HaElp. 6/XXXM J%IKk^r-bzBB,w&x=r%U͉Ydu޷ D aJoTo,bS)kfp_Y33*9@HA<+Jŧ4O 6L ZY0+lQ={*D:'SȀ@Wi&{+Sq!!O_M U{Xsk0ݓ[3~4nZkF='7Pq'l#QZxlr$\fGWY߯;߸O~Nrv*EŽ ҔUx9X¤\_uF;Ec}IӮu?u&2D&b&W{jv_"w&>ܖ&{PKSr-Yoc-*{jkYJ-&%h"ND-%,%;>HxI(1X$.Im€aW&EIͫ\hŽԨ(bQ\ CkJ;LXgXkv8VϷ -^/jLIF~(: ک#J[ۡ ?N֔"r{klvnK~zJAiw!%'e|Qsk_"OV+DT?dpߺ%ku(4XNt Js>r}I TrNio"AҞ-> 1,NZgo*ͦo4JؐS$jJ+b2MS .y73YX [1C 9hDem41DUQ\fggmT1V[ ?5m]zЦLfM~YlL&M mwSb?fOwzS0?{˕kmxd2KcOk{beUp^,KT ngNYp! wC۟oi*lRCѨ< v?V(J\rMD8ۑ'ҁqȐ9. piOA VU8Pi\.q X;,OaV[$zF!Jvw4rM '2nr88͞joAٙN'F.,= ;\|dqF|q&nlp:s%s)^ؒ,z04yNsaj$lPYdlS,;#³qヾJS.俈Ƴm/Kև*\Pe?g}i藴jWV:!QB0Qq+EOْ&E=:~ f.m]FZoYS$8>pHc\.:Z܋8m? L2,AhBJ}#kqNJq:!a3r.Cn-VRԦ0DehLAUq{[ˁv(o$d1qc[|ą,&e bSϤ 򕮝Bgަ"C22dž qkEVfThH倒 BhNB*N+}VDQ0(|7RȀcπ&DE\kHRj87SmpQ+CwWIqx6|/Xr2$3 KGrU_uz9BwvȘ ˡF-eH4`+5oFa4uMN>F¢hz2d:"pw 7Zåq!u9 n|s (ʚJKQE|_fL6|ySAP=]"Rdms=BK<{?M}m䊿j d۶4"viݢJH|+V3BoOi&/B(qnd;kvU9& uYey|w\ U&x}Iў'SH6XxG.Yҝc{8iI9H1 @=ny^c ,CE1++wu7#Hg䚬fqҤ3F«@y2nN,O zI 7q5Uk# ds'pG7k<%r5vh‡LV%oOi[uu885)ITM7[Q4BS&Ҏ/$Ϛ~Nzch4f6 T2V-#6'e=s7(+U%[%'b;2#'i`Y.s23F ي@>,v%w5O =^{#-X=H߯TO;\,~CJA&kFrh/E V9,tupx+l'tl:EQc?qI{qW~qΧT>b-x(ǵէRu2ٖI̭cft|"0 JTI*.I˲R藍D47W:\SQۿBHɾ}hYfF RM>$Q`tWwMI $M>5tmPQ sxwg'uhgЫ Ĥq`+l(6; a{9ܭU.39_J~5>Dy_TGЫ1Ͱs Uu\0/*-]ѩYi9v5I^}jRvuV\2 ^7̭)9}j)=;FGŠMekD5k|νGMC,~]hFr?T[K}aQ9}zFz ^SC&P%0ŝG ag\Zzɢ~YM3⾦{6ilI kzN@)X˿X=*۔mw@0)q\pPZ ]?b*>p7&=aB§*ԝ$J1PQi2Ⳓ֍.yksƒ")%*,n]KV3l7J{xēGa`ʺdKgx6 m0cˤmn݅b ЌimSͼtLAQݍWt1=c ZI-im@#مr(b<tx6o\_"K}$UR\HrX1̪~2ë+X *\C9#u-j&BE> /V")xMBwHjuGHh:62W x9s VLosgޭV4|h0m>-lȾ9"Ypt #T+g&>t4i,TWY*5Lg)?uZn[5NokYv@=~ݘcn UUUA?d˜̵K4u*`G^8Lϯ[4Zy0Tvt\؜( 'J+0X,j3#% ZS"ÐOe@'S H:Si쾜`*$'}K+zr"([&&Dd'}=/uKFf]n*ӵЗ\C e'_25?LBk ѸM Ic$VhM{5o; *^ Jcweˆ>|/AKvQ;\0uW%oMMȣ+.#/5 '4I$kzZoBG,vjǾYƿe@ "běek`DÜx*.#:-?SR';uQTVpO@;{iT GcHy* P$g9Q}6>; hFRϸ*ݓ|!V GX͑gꙮA3#뒪:$W5rȼZv r=v?#HζR k4 PovM""Bٔ!i=a6Qʯ0,҃T̺Xs>55a-n[q` L]I^ޝ]]91esv;-( TIɛL*6O6gEY%2Fhb?sjsf>L=9:SW%g#mG,MIۭ^t%J00]kvNY 1!EU46(I}Tْ! !cc!.98!.q; i"D 8pmq`|uUƱc&n0j;Ԇ$Q] q(]o4$4a_~ C8L+CBuvɱ|e9K.$_8A+W>TlNa,C$Jͥ"8#1B-߅.lFCFr ŜOtGIˢ&gK3鼅!q kF]?"9/v4ވ dYk.Bx?W̉;A7LIԠOZ\!&d=5M%~0r+@&ؼA5+?VO{O?|zlmg$GJ:njf69uXAV: %Sd'7-L- jvdHfmN3AoLOwwamNzYALun>Lk3(m -LręzPSiڴ̡0l `:ݣp\aozy w* zb9)ư$%o2H<2"SDWA)횝NYUz7lV7`'}@]5}4G#騍<|U%w[S`6Y,܃6]w*MlٹjlzДHTC1Sw(CpvЋ8`M7˷:&g+E% ;v(W2>?v ݰ//Ppj#1yΛ1o9;C/G 쵮tc2ZsÎYdޮ40\d^_ -;Kn- Meoꬕ\nK속E8@T!Nð[lg5kc/tQ-*X#f/b"bW:QeJ}V]wvzيLW _s&?3`v~Q2e D5dB. l$!^N`ړF_t ¬RA^3q%BX4"7X \ޞY2}8O. ;>wcHKcc,σ˱'@ ɑc|Hߐ%Bţ՟G' <V>>%ZE^Z\θ;:\iۮgR *PF 0-N O[VHu6x&;`Wt>Wybo '"U R]9 c$ǫ':cz 36L-6O-a* 598\&q!`<>3!R)h尻)#Z4Gi`z TשX ,tS:_6mRM$Nܦ@@pio|$É%6PbDNS⛅"9ݡ|,yop>ʂEnb+:C'ۦv`_1 GdȩRq‘!9yU WĔ/J|QJ!&ue'sh>[P]@UOj9-X梵3:`<~,$O}ZL:ķvpJϻ30,Tz$I<|[~+BocO2ĭ9KY>N"Hux+26 jF" !/woTc61 G.#BPڠ1i-s+3BT}$w%Yj7x4XwybzM5KO}" Luꮢ,6YJW$v~BfXa?8it)Blõ`@N r٠;(.&C'bX00A14-*+!\{,=I 93]!DZ{hZnvo?xܞBd&vu*Z)+7p_i''D^E2m^P|*A {'04XRS3hoد~iVntN5 N ksBWkW?N.u Hs*=9bcɚA K MdUj1L?1rs8}|!L5O# +.Ax&]z|׮看h3 55Sil=-_ ZBFҞ73Mqi"8Θͼ4 ej2;T"p`o!ΈxDQtoLഒy"*g7%t=e_ugs՜ +&ּGAdˀ--53vSėk}bٔ+a[-<OvĒGe-EϜ.*zЃ`[a*b^g{'r+c]Z ET!YN8:a|gɜך4*ΦcRT`;@Ɲ ahM{w]*?04ړeأ5G\,~@ `{ xIƙtYֵΜ,r&rt#ge׻0NCyD'`KJdM\Q[ Z_ֹg"lG|f~yfNwF3$ӢowA{7 Ps0\h/KRP1S]\\;FA9i72qhgx ň̓PML4sfF~ B1it ]IP_,ӚU~sȈ8.} s\ww\˸"ȡq8;1"m:1zKv-bp^O؅n"F3pPUi#~* Յw pͲcX0.OE劅3qVp#r]e1s"Y(#{ycQ/skv5d#.q4]1䩤)Wdkm&Y:ƭ=ym_ץ(dd1г0!jnhP1D.RCZz 3GQ!<^6반4de+YMv2!1x0W0cyTR-,^Ŏb3DɩyH~5)./ -ke\O' ~Ia k|^4)LoM/,<4@~T*猋(Gxepi*[:\߰-yWe ' ֽݲw0r }S o@ u)(:P#3q!oRz9'UO9u_eLF8kyU eTr1EhK E6 g^rg$>0J  a&'\&X-$}eފjc5Ym-I\17+Յ 4wz'lU nzq6&񍺺r3lO^{4l(p :*Xɾ=/z0K0t\ۺDƦ?F9'駑z0" )1J?/2 v>_Hp Sk"\Fo#dlFdr7"q[7{op9V}\C;IQqA739اV4xs;/`zt}5F، x/zC- CCE3lƈgt*3d@k}l!`^/=g_: BjBqf0uG2|`"=v*TZ;<$r$θPjp|#%0hhjc5jľ@!@ >#CʞNsI?C6/=3- \K[3lbLr>*Yn16e8`&=_1pB8-(u @}Îu}e;sb`IyX(:}ILOdbئRlw LNyeyre2k*=e* uue @kaf. $dQ9fgx[j)qy;TZl]$MPUw dk4ÃcO fYwԅV׷)w٨ Jpmw+hB+Tm.ºb.5f:tWפc8>+ > 0+0(г8J?SHG<)Zo )1Jx+oh6mcޯ6wM" >y $x ] DGK^C\5lT$" Y ܧ{]wxn-p@/})kBUD%TZyhZ*% IJpss[+ԍ(uhU=Of#ײ4e7psnTa]$Li߫J.BfFCĔ~Tߏ̂//z"!txjg0sTPW+ 8"ùÖOzb&w3aՑ0ӑ[r.mNXph3o\\hiR :5Mp9xh^cΘι*{LUIG#s"BEq;ZP`LUpSb._ULyY`ã-@@HnB0W 4ǵ@$;^dr)b|n6ay[ə.jce;Z= ED|ccɛĠ/B*[6iqN8Jid[SrcXb ]`.\xa3gpBqӪ7u=,gTkѿ\& rZЉ8I2MHIGX۾oXA)U}h8TB  Оэ57P;!׈;voX J)=x9UTczEsl=g,jO0t=GŁM_=ᾏ_C>b1q?55Ʒy2rϬS\v˹v/ѱ&YQ9{I:cMI'D}0VaM GIFx QO{od G{^MӒ̃5b&5zWu%ws Iblo +>A5*~8n9R5F!_> Alb<֌ loy Rfpm c>h!PFc(&(_W:wΐaH'S|KEO>Jqz5ڭŒ+w)XAJSZ0f:2LcmA[GXϫwV `튁݉hq?= Q˙mC+”%"~ӈahu&<X6F@xP)>IKEӠ@p}&-oY[B.]ЪVp_ݷEQ .ՃU | "c>@+#ɱJe}J-q:bysý+=s?.eG(q>)Q Cl$EUھ)T)yhK}Y׊R}yޝsFgaڒVXkDHzQ%£qc=.6 l/Kw#h_:ʂrqU__+A*þel {$9RMLlO9cscuZ˵PD\<=Nn}%m91 Qt *ъs=P&!Y}KbxVOG$@FmMtA A6r;bqRr]<9C4gz&B16d0mG~Amd[CYNM'oz8хmG,^ޤ(H:EDnQXae#A8Ra,9f&kImSfm?=,Gj {vTyalX F ؠ|-r)7xW17%-$(IQ^_#-t@~:8I{>vxr(Z1PE,Zs $LfclI"RË2]]dL)T/jfcuLbq}[4*Nq:-Cʫ]M,MXc^S>PWcx=pUXZXi[2آ8K_uBA 2VDXdD'VSOrp~d VW!G ׁt'?T޸ng= g51Oos9'12?E:e9iv#($~E(F&-T otԙ f9O7 0CV|(r% 5TŖ'?b[S>"hzL;ђo}{N Hû1#A {Ǵ W'R'D(r%B̦gh.j6eޤaŞW3UlA/UILoH?2x[=S6NX !ϒD[{AL6A9n!Y=6gN 0xK_?"ԊgdϿkq|\w r7g RwAQN_/`r?eqص^Y9/XEݻ LdNнcw)ts-+dwCPgsֽ %`k*'nIΎvZɛG>>G`9Ρ*l^Q6jbcRF[Pf0{nwUbp \mf2!gveq*viDz@Չ /2hĭ|$}63:Q*ܯ$rQ~]8rřZ47h l"֛cB+9܈ AVaU_,?ܿMd I$|5|ҋUg⤰3鳷泧Z9 Bze\׸,?^.O{mPzXPE ׹d,6/^0Zp@$wv L=P',XJ6imi,qs= l5/~y/Vџ'YkK]) Vmt0KG1py82.'ʚ)b sb1lõHv7NZib7# KDBAEЋ7$z zQ6i@؆if.ħp >HGT?*ebLV8Cp6oJ552oNV$}vhOpA, V-oY+Vn2bO|rj9DoɽL27DR[j/8c;z)zr&%?챠>Ik=f-3?wgXEsS3A*/txyBqѽKחr},:ѵ5ޱ,W>/iPf0 roG?m!D#VZfQjnE`?(b 6 h$Kk&Y.ɷ2K(d@خ'rjw 4K/ifg/nX猚ts=P TMorW׭;kqHr!̺Tdnzzh{v1'*+aY`)uŸeA[D0ֿ+LBְ)X Tp@˩$ ǣVHb 5z*&'r$`6_HhЯD$Fh9 ~CUtmCoM蒪*?+!s /`eJ2xRHz"*o\=8~”˹QtۈeT]u>gJK9独 Bl{ڿMZy(O/bIHj(KOz RZ2iW̏o^ }Y}C hԵI- oKp_@#Jђ{]9aE2k`bVq1B{ef.K."&S`SyNueŋT]]+4u3rXc_PH҆l34x](KIɟ= 'U W,àH mTIQ %e\@CGvK,4#))Tkc46RGβQInj̋7NԲOF`!4.<k3wx׶b؜6olܚe@E<ɭ/K`XkXI] r ?Nq( \76x;53}{ɒMو}]&_Yty!xT+a)12<&<l@QQR3d (IJ:q\}PηS{.1tz@l,8{ƹ}oD UG2H.D%Iz b˞+_(on(cjCq-[ArG7# KX'hoےLjGM U|2Z @O*S^PV\c{OC7H0EpjW 1q ]A$V7!JܜGa,v\VK9~Q-ǽZ{.yOS]HlCXϞK:&"<c|Ķ*P)d zl|TkE'm Lckn0wUuK'iY`r>lNդvPV_ ؜ bpL {}Ŵp9#E3g&ÈH,bxWH8G$DܚAn>mRMu"yPE]?`֓]WBsۡDJ$ݡ${ _}q{) 3&g0|J?x*ȂIQnIĢUXH#bn GIl*J{򡡿972z-_8E\v޲Q2Pw= -fuCņ&~tdyٱ1vMx`5ۿ27g FF& >@I^JeZl&˘Fs}#i &:LDG)n=(mMz5E&Cg4:UXaVhœߊlq+PNL#ܷIJgml~WM49uڢ-uTGwuOeR0E tW>FM^WM"t@_HF,>O|ەpÌ=.+vlbuUk5:y\<Ԟ[ D,U&9RxDui3YHs0>oM!"3 >ڟeׅ4M·`m?n{5;E,tM⿲'5&V2_>iLnGQ*sf=jwD[O땕ݎwx Q;ߎO٨&rpG}/M Gps߶,Q8$ w)д6v(Y!Ūfyg*I-];5e"&jK@Q+BG$u)իY؋j+T-x!xR:Sw >6|&5G0_f_h頊?͔U;I9@$߀#B I2p_ PWܬOs0@ Rֆ[]>R2^ކ| 5nfJy(@+I1tI0oj P۰(ͩ1Ѳ_ 77\۬z-|ZVOuUc%ŃYh}$γMZ{C: H7 m[7BYd?5 |0<'\`.hԇ[XWXbMN.0$$p\|U/`.Ss -1j(*NMb.8.otK U^8uA oAn/| , PLrgLx'Y9Zy: GCXSR9v݃SNL< \u_D;k#דq]t~8a*RpK)!L`.˪RWGLjJJ*l&[r%d8R#Y ۊ+SJs5l.7yhn34FrAS 7>h?ŏq%n4= t pY}AnEU~5Y&9ƂZ`c}l,Xu$a7>'GSu˔6_yshaΐfs2ԐtMO3qg']? }lw"0Esɑݕy!6[bK6[<1@Y8De[IZ-SY@ R1s3>Gb%Tb|/X',|xaq2߱x'8; u1:Qî3'mΜ i~Rtge猾7f풴$'8n#crPDMVJTΚn'NK/+_ B< Y N/+0 :'Z6BOp βKBlZ<-{eSk=ٵ@C4X_6T^.s m ^@wQk<`XLݍ TTY81(gg01h}WsG5ХflҤ" n~rL777҃P*Nd-q1/\C?b*My;l^)Q be~r$ucwxTVF2hf~^ֈ9 dS*&Xun?wWXxNs i2άm8|rvBnV#y0 kUAERr#\ ! b-V,s#^u_}@Ь5TLX}E(3gg[U7)uUFo]tH|=,76@'s!ЫEvklrWyp "'b_Iؠy#0ޢ5k=#Qef.ʼǪ"׊U\Km`Î{~́$39cE>l5v4f=bxX--K D%iB ϊHTE!؂ òeo7F}B)N5 o2$\, ,v#iJzamT< 5Xu_ëkS .OҮeFV "vr3Ē Z>-qZcЈo<\c厨0#~I"хd~eЩ HViD)~꥝PtEy ;,8oĝ9#st%EP7'vQ$^y[ +c۝pQ#~oz5A,^妅ƚ|JE8To,!^ij7!i-j6mΏ+Xo5? LkB{woy|3Na($@[<fq7QtLS#9*m^Aa泦ʞپ>X9 rMvm|=~KO ?]j^T=@ Mh~;tv(2HJC @?`&$, 7!N+\p~ohwI |ƥ5A8?M8cAc6_UHi9Z_3#nOl!,FVLF@2 |_eIyk"d6C'P{'Hկ'pq%9kQ˜IJwVEY$K ѧ"_̅ xg:},=AI~lVoأ.9)%v-OYX/bc?R;)],i/ oFnwam F@f/,3t##!#טmkq^$6L$C!~^q-[xM=C'IvfM/Q?7"N_]Py -fxwԐsqM87*mxtd+=ݿ }ӞypR :1 _MB_7+'JqTN(#LO Hk9BP( H|\ jҁ{yfVN4a@ m@:"Q׍_|ePPG a"UD*zMYӲD%RPPJݸ&yUX+^'ggSQ$׿uWRJoaJx\yWC _w:qԭ@ d1 ʵ9ZzNo("Z1R Pt\ )u;9?E{ڽ!nT !{ظ9L8W֣ZY-*$ ~hbXS(火t [$1 CloȦ?q $3i`"<,g[,/@i(޹G( tgr:Rl)}jf8ɄKӔ~#dž􁨟RhJ:6CQ;N@w8 ;%Yg>X:# ltcI&) /2fQmdM7NJgUHbOځ0J<'%l`[~ϣSC+JP( Z*7P n`ktg;f ?QgBň᳆҈*%.J5l/=SKPw:FU7 خ c1*pɹl<7jIZyǖ}^9Ѳ5$ީbm5G%[UXF_:BAkUH 1ҥ.Z8ȧb8MO ZDA(/~ۺt6H W"2m8&|~j~%3% ~m$1~$#9i<Uz2UUYXg:wЧ o`;Z^^0Y&.KĤv,-zPݦ©_Z@tE9 0RVQ0;<Bԝi Tu.SM'웒2Ff~C'^+#fǿϓL[̵4{!d>W\N)|{R 3Dev֢s Ti(3%[w% \ev: `ZGkXʭ^l1P5H¶nF^U@OG4XƋEwmcl³'0q8O@)&r`y=$HO u !u ͩ206g~7"?[4Z V.0E>k;pDzv7'խ$]Z! F3: TCXi@s!\my%@p8M )Ŝd^7v8R$QrSJ@+ !G뽼g \^/U#Mc !4j|*I4oK(,35Hj` fB啕3bnӲ#Eg9{nSi]Le$LEf?(xA0~=t PJW#xY5sHr~?C[ߖ!=PD(F蟚wt{UNA.MRZ|tBdĭ*zּ,'3yzgu!2k[7u A/X*_{G45]}76cHgRj78Ucw!I"x a/lsA\,ŃcXN MhyЎi $k0?ž"!b}7%99> рp #?:A9MI! *bHyF-5fwsQ[$2[hAv2yHvPҽD[,.鱟f7V]탣H z[$ e+Z_\ *(Ժ6{"V#Xp)<(* XeiGK/1-w.q=HUܿO3|~0yRª|㇚/닞\ Ai+WA"RySa&#& 6lhzu=N |(#H˯9[_ʏOlL@%("X *Ϡ:aXkcwbh)sc뎜3TZGņnm& Xz4C큒Kx`g6,"E! "*܍D^-RI: ]PfE5<'?I)jYqƃށ&>ۺʺ?F6?{2pVN:8` :D||ȥ7XH` BTzUK;#u7)r_ "jDrva%p+uތ&@2zfDp1O|6;IkfA lT(/[ Vrs x./8?TmӴ"_e?_ò3t^S%z$Xd[LE"^~S$ڛG7W9z]Q;[w'xK5*1,X#(5щ$ _\rw5:CsWuJr >qa_{d,׹.K9L`E/Ўi"v=jYcٕ7!,AS~6KZAin/9kS %9$^AOf F y*n6;U8&7 #ey嵗i?-{{ˋ/7jfZ׋~cI ^ 7%nl,qo8cF{n;|}zyp-*(_:G= X9{8@[}I̴|(;PY}wcD6?؂zxx'֡p4w8KľxomxP]MoEG0>m5<qUCG%ak s`Hgц?uSoMr>пc /AI:f llQPWX*L DdKga qUb9Er@L4/,nρϒA pA_~)$^u3H^4RW R\[ڱݒ> iƕ{2ii&!#! L>v[37`q֮zRc -xT f_~G8\)^|P 9-~(I&vL\`Xz 83L9?epa-){@ױ>k=K fwL{vODP^QTAeT_ ցj3Qqut`u`[m< >GL7[X4h$zrrt1"e$a1 * v_nm=[pnQYR#7tVh׉iGc:KӼ3fw'6ȅ)fJS ܶP JϓU`ud2t%lqy> J ChEQKKLMe?7mω? H# %O-:} ګ;[-q"u0f_1c?hd4\xT HDj77|6 KP`}F בED.P)ouR% ;C)sYDwv~pq\n'_>Ih^A>eq%z0ф#_U UD(`(Q >Q 0AJet}h6iz`َ=IhW]L׷ΜCl޺ʴNA؅0iApعpIR|[FkuFfpȯ9۶^Q|e(m]8X7!,(^`UIg`R"N~߫QY»lp/Yr/`2 $@Ӧ8M4 -\dഘ?Q@PtJEPr!ڛ񟗪`8z}bb%3fij%k?L*#V2pkzwqnx8Y91 lLw3ۑ >H"}9+ߖ [lC"V`a mL4W<I:~" U J9&]Ќ)eQlRCAq,z!>ΙxSe!#Yؤk?Cˌ$4;4߻q MкnHF1ʏyѰ!favo;A$SYQG*p1]7*>E69 V6*>{. c1(Ȑj$qiBKU9z FA1|/|ΎU3S 8Csk] #G\„` nm{rp,uZL>-&T;TH!ol+>b:Iݺʞq'V6yhFAʱ}ҲT%q$o[Yj \y6wG9t(sQ&l˷W̺UJo{wb]0y5!3UkVL%@!'XQ S{эLLЃ,_ ×ĝ̮0ssECć00> j٤ vjICs(DcE<׌xzH@IA#tk]fqA%I%}cs&juA?)Q){ߗtw҃ 5Vɇ6W*EK)_뤎n`h/dsj7ڡ0$B`4qP!gx }!+i"vH0q_ [@sY0gh7CSHEݬ+'RadMZN}l.XVF} D(@πsO~[^&#b|\rÁO TAp[w8w/CPk"|m-ֺ塽UF6U\SA[`90ۃYRs9tlR֒ 9G3LCJsxkf? xu'OĐQb9,BE /rGcuk }-(Nzon^ܘ`5LkjnjRl:^= Rł(d5݇nvKzSN= R_\6~wܿdV %Л+$YVC*\Y~$瞺㘃`t7#Vġ(vګVM*/J_h yu&JڒL&8$M ROduYaťfX)bLe[~ys ޴boC]*8e_IhNFoeVeḙ) Bo-t>Bl6[2Ss_S"Vpz4psvâ|fMr܃$Zyz>{zyY5qzu-̳*nk>n>8!fDMv8y<:&篧ʹ^(Հ)F }(_Ӡ%VrBsv$b>^ In2q30MqH/&О4ccJ\!4_빢\9~R(g)՛EZTۉNJxKvVVC ᆊܳ6;F"YFQ)ݿXxͻB╋W(DnA(|Own>>\V;iL{U\t-rm^Aosv*gKA$fHFc}i^yXFDU;fړ5qWA2 5DWY+xC VGewFIY\BpGNᣀFVLQ \--.$WPo/o 9ט&ΔjCaUDҜ|G;֖́#uԺX앞4U"J~i-0#(`_)sÿF~X.oj2`'O T:a'Zt#20Sۅ5>Js8M^ލK"oە=(T3a)lzp~wyl}3V_,%}K L5 30 D]pǘ}ɷ̏wsvz `٩/ـJ\(:&L$~_c_x ۽Ŏ6_|*}/Z.IwF:Ggz9Еfr8(΄Ȓ3cp ^ -K`wF@~}cg]+ tRH.vR*|q'FC \[Ϗ4he]W#[?ZℷVܷov:tPvn.W[Ԗt5vW՜N\eHu2dT:+ީ2pOp.{*H;S$ܰm4Fi gى7:HG`JP/o GB 0exO:Y_Ur;X&PÛ ?-V1HH4⣢Pﴘ3+RaQc8_ʢ`4扚)3m'gizY%t R('뮦Я1lTjdaT 7vإ)ﹹpu6>J3- .ΤV='ZElLOY/>/7$iΛՂjN1?7bX+]КTMh`&t # M͹li#憈Irt+Kj]$s% 00v.Vg>ǍcO'嫗K x1h?[L 1dQ8\ ePd\!0~*LOrvC 6>qT{Xfý|JIa8P~=RdD '6%mBGr¦v'nQq@X(EM2a.}/hYz׬x2?-LA_3y<%^W˳يwM6|  AkUԴ)iIH'ضG4dDԲ&D?cLvI`OHh졐*C&^*u.NN{QО'!2:ɡ2}|u>ߠ`Wپ,Iw:{[gq`MOB  hkJ) uKqJStؼQhCA%hqjSV9呐9^^UlC|T82F']\봍w v4NM1Yܣ%1ه(3 }4n;d 3]tk.-QOz@QC/s9M4 Ɇ#X=mEjzZ;_=6 Z#/. 5_-;XnvI}&Uixi@x3"I*jmx]XWMNF5W&`Ґx& ն]fdjt[?^Z/$㈝Ig\^|`-Mb͛z%cm/w JtYEugr|J*yAz}96W1OJ(UشH1񟂟0uLj~Xa_'< G5|K]vHbA.%{(VE¾e5dc' rJVolGrUWGd0FD1`";,Ft. 8kSYicq$D|yFiMúԕ1 HqADek<ƼlxJB!q](Wuy '+T@Rق e=0C- OU $@ jM2]R@\ \ xZM9o-&ɓ  I_6Yuh'M,W?<3 $N[̉>S!+uNrݾf]<4檲G$Z ޙ]}])/1 ; _O@IB RԾk' 8Z?JG<kҤ \C*Tʗj"^wd1Ć.YgpUvbs?Gt! ly$@Wc%k_Zϋ<*TE("9Qs"B#!y # @z-KF瑭zQ V0.@2U$3- z?4@ n˸˒Z`CAZhxBgĢ$/t:r}/Eaݱ*f mv1|7KCՒ %=MEHRMNq#CHT9pAQ,jg/42)&/>Q$5e !Q`ďo &KKhXN'οׂz|?38x],Dy3|siLWD鸄|C,N48`͘%'VmʍNҰAPH&J{Ոۑ/˶G}nZ(Zt[N% #q@Dަ[MN~Q*=m9ް3cl zL,Z QM.f݁>lpVػ2nJT]̨F% }@%KSp)`'.YM|k%_Ka2st3g9O~Vw8%Z~4ޥv-pA6Wx?* X[[t/[tEz܀'Q@Ə#)QOٴ *hlIg/c~pHi1:?e @Vlc'674I W3_uo5-jH:xf; |E!(~qfae݈zta P`Z(&w'b^G"R%M[Qg #ȈV,I4$Kwh3 '^R0#Ngʂ=upV>RqU4bY)E <6ckA8ʫ,YB;f‰ Fgl۶.n7X%{FdbCyX:9Svv&I @\X" jD3C"G/ZXthXB2o4'|܇>0n(dwj-?b!&\9YqRE'&a2(҂#$c w|0{!ٜGxƴİⵤҡdW~~)`/G"þpwl~$n{[S-p<@~B5%E4+53:{3$,%:Ս|b^8{U?3nebNY&{.=(=w\:C\|=zWO!P ka)w4?Gpmi7wDΝ$/Ǯ<ѠLt pp 2_pw}vơSQ TCRf;Uy0 @U.aVVȻbMCk /aHSti33V]xF- 0\byY'#T׸t%k`^JG? ٻK 8pF> b7L4.W|w>ZO]Eȩ3dJ JqcU#g'-&RC?KEb)GPb;,BNGH"{O>{\n#s=| :}~!Xgzݿsqdq -?j.1=?Ob]I1 [!ΟXY&h.=*͝[PjNToa;"V$~a-O_ëz:0W#eպһ{3ID 19w>J%7{ji*1eYkbkL-  d5^r79 *s׺2hԿR6@9.ߖH,]U;y&qV"ڿc[hhpqb?ko%:㏢oФZ<Ѽ7^߇5BP\Q*u yS1{ `nLfZ_'g)I/Cr!8pnɇxԥ$jerf$j(&BoN)c~FiBdv>d+H4vX,8TGCS(p#@;jn2 a`"OK[l:: wa.=4w@〈 CRAl ;AF5PPJ yIeLeC]zfT>Fx՝cq5OB%( ̀W"nu3u&Y;\*h泜Ya՜t]?Đ2ytd$/ 0mI؎̺5;tMvq5 PnRE{_'TR*%EĎO+CBDX%0F:Q- dv'^F$h2;ۤ3{)@QaI)RmOd(e?Q빂ZTp\KCxOŽ!%=؃ĄIM8Ӫ>esa ɡe1LJi7Ȩ!޽@l@"L.Q8@Ju߻ /C#[GӰ]O[+Aޣu`LSe"Ë.TS=b覹)KlL+1n sƌ]v jF6U~&Z+3+Fxe?8\o_ӱ CF^.c,E𠻓 6N.\؄QRgtVFOoKrPPvFJw+B=")eXH\Wur"$BWc}{Z֨i~" Z_e"CJM(0 VGg'D&V!S>&)p.>q‚T CnԶ҈Ԡ>m(tݵj ~V`|?Qaw4};N`/% ߦXtP@8@Ѯ`*ߺis4k0%s4OKA #?qR,J5rDWò p܁Rf-S/4J*[Oϛi+ewEſ4 @wbZUb@R܆ܶ*8OW.*꾬g>n."!rj`h;)>l+4NVCr `so`Bhc"3$q)u\˳|ğ6kl/) 0G,B a{)iɚ.]jua\1.decv.6g]0;1M[a=p5jȪMwEsvGY ѵn?sH+)".Gt°F9z3hq$X00uoM{%T`"6pIp&"ܥHQcm.Lb2G/R[@%I))H^bXNDi23 `$7RJC- :?4#`kt"Y4X<xn|UcLB;{'BikH6qͫmý>6n[Bll"$(~ JGZ`0R7tdPkXIv=4Z@W1xe/q}K_&E<i6](3] )SE$ `O50&pw"_hS:ϟIoCOIq>{5_/{&0(veJ8vv>sdQb Knp%3}nu3T$KJ8 1ܺ|5EHyډjL+3q#?3V+hx>T-!7A 7 A5e I -GM8s%7OlYdd/;M" ZJnILSc(s݈۫5G G a(3#*l1l +K y"_hM𛙍-/fD-OϮ6&Q<bSy[C9T'9}Z_NKɌr!]͡V@T C>a+:_d4oUbY,\ 깚cj`F_d\_ X"j |fAvL:WSj{wr]8jҾGh{"s4.>SFSntϮ1ϯ"2EJQ(:w. ép|imdau34;+hD~o0LbmRcꭕ=ƏԀCPS&Pb1PhH\Р$C(8 VP$3.y2P;SUBn#MR_XEt-*p67+ծV-L5;roi?&ubٿ[nNJ40ҳUڷcRa+QO:N7XP P#>p0D9_7Xe)h'kt][Zj_ Cp}'qk@qjcEԏ 1¨bF$`Ma_ml+x|&"B[XUvꏷԇ0ID|N[l|'I5SJfRJ 3e"rAv,=> !J4e⪊ VVlepry$+XL6] B:Գ~@⏻!78&vNu G$|[gz(~\E@P+k{>I@`?D#! bi_ٳS{Q$SL(fR-cYi' 莢6ѽ18R*81;eb٢!zC:6"c jr"P!]"L11= ;d]-W)z.eYN8MWtȚ 4e,YV(95m@Ps؛z+Wט٧AJLUZUl]c}q\ A?[79mIM6+ԅɺRG @g`'IAv=0FE[K!2EgϰH̴e8ޭWOf6n/s+iЖ^|.:UсJV!p0Lh* ?LG/"ȊHK/WVŝ{]:nAh'4$3'z$"y鼺|"U񓴵^/"+R 1N{% n_M}>l>7v)}ӎje*-`1ig(t#Y~Go㿕P(Eb||jTȻ]=*C:Zk{bQ҃Ju'ztITHEe$8.簘+\vC[ 2)&}@ș|o>YzGWf=lc}wר#Zok_lۂ,*Yl#}@F <9NjD;Kغ fgg,HR]q85[ýs>%Ė.>]4$UrJWU3!ˠd8~K1x ӊFr#EԸsw7qWږ<b3:k҉r^x]9$M !CFs* :;fe- kL%2&zݚU<=4v[;{c9ӒʼnS?+ ~x|EdB6ɟ :u9{n سd"&lC%mʠ .T ӓjUjeC*Q'D|gmZcgLѓ`HIZ hyQ{8pB@pŪ ӣcX-aOu߲@|y8yu屯7xr4 &9'~Y*k6akx/,yUJMʍc^e焳\d$!! FɤT\ץ7 UA3zV.{遁C]oT=M :\՘ebB_HtF_ao;cWQK ڰ-ceDн%__$d2<0(Y:\`j?kA&Z$~Ep1ezeXb(oJ@W}aPr؅QEJ"6 \u JBdR0 ̙ ]#j@^&8|#vqZ|}ڡtt} =X דՂal=C a 52| d*ցS 8ŀVU$>c@TJh:BIޘBF 9uog+E])1# 4ˢyKu?Uw-Iai/7f_E_ 8{]L?Pl7@6CyVmcR8>uI`90<5yi:.NWaJ:MZ찞XNaX]IZ4-U%T:a~AnDu=nגmq?w0٫׏^l|)P|NYe9~j!%lp_9 F$mlXl2 M';X= >V!>n#Z\`E?S39Bx¿^y?SJ5Rȁ%*ir/{;ƒm6xai&\%br,ʯJMxYȽʐd^[?@'g4,;M#Y5BA[?ig}Ґ-~~z\+˚z R36zky1_"!tzG?QRUyDvLZ5 K;2Aȶʯ{YⓍ=_.f8pfbG=^غߢN:"rM-/\;<(~Pjt@,P#.8a 9#' PӁt) 5dl,yZRs.cti 虗-w#$QopUK. :.w+7PMK؂ļZ?z8h'c\E\m3_H(!eڜHmD,g_2|ߩܴ32͚˭r-8ԞY~~ci e"hE|LPTl!<(^msP}˭xYaTǑḼ 9`,6Z/x#N#0^5ot{"Ќ|# 5s9)3L }.J5BwD"{T"^ҬEv :ID1cCl~:]=w˄ߠ;i=;v7T|`NvcFJ@2`r}OCe?÷ ݞ1gNzر1{:!0s^73T㏛7Ԫ7fad'c8OKϹґW*2hIA\ AH*KfR@RiZhq qTSY'?C#7 Vn`4nгi_LZQ]Ϭ dK{Hì8i,!y"m6kLwȽ "mY.~!'N&nFJ"h7 ZcB}4h\҇"K{1l$gK`w=zUj@}_ZkYhE@۔'gV 2(2#2ڰE>VՉ"%d?_0GBV#5>xl=Qo-QYK3WD, Jw`c>hË ]6S|趰T7ʙ{J;yRb ,з܁Qx~^ a? ۣtq]A,$ES,= 5!ߤ[5EMQꚉYE%^ v32D,k|PVٹ;+^\d&2+Ldgͽ@Sc啸ajQ@gCrihslHzL~!>">)?'( cÊnJv[O3dç?]+tͫdYYi@ 4my3SlĊM}ͪ_:{RY3aX&un QW@I+Ju37=& (X9t`h~e}]g%lfyBLȑcH퐂v,C'QڮTɄerni̦&bo27v .1*_:1Qo8eQ^sle5R鲵|iѰit&[>.a~x">9QF /s !9*;/ }q~1*hy.n>Shm҉]ZRM0 ͮc7մ,bʎt^&4D/jgT|Q͠Iyq@9Q_p pIi(\]DmL}yb |V5oAӑW4{B<`LW?e(7J$@LL̹E(w&TY~C)%rYPv 6eY UgFzJ82&C !bia%d- ]Bw%1Z16gaa/Xns9=1H fDaӨ:WHB$`%?t'&w+Pkx) VyuW$c2L>P3"6@,HLteaP>keu\{mpjzx({ڟ)Ҳ3 `JԖ\cAEm5'-) ?d2JDfMoɘ-p8V,vݝ:"q59t`DgkDD/Lz gT\|PӾȅvmCBChB<2l՘ȡxը5I255BBXr~V.4kD^SQ)s -gP*|sXFd6UJ>OIߌt Ԥ/JHjmnfPZ=d)amʩNly (+MAjvjwY^IoX_#C F͖2^;|'z5~nt-fTʍRN:sԜMq2YEohV:奢t;DzW%GiRcarLF%X>n ],S =۴RLL hayo OY2 -fbnP \ $==.ffs R "V B0ƐmT aU&_aҏߪE(pJ5 ͯtۉ嵊2qX|c' G0\:swL)n:dy  iv g'AmZ+KO5R7? r4D̓rK;dqҨ5Y.䥦R1}{PMbq$M@h&ŗX]i ၅5/Nu5<# ${! E5H\9鄺5AmISEv* ~Ge LSnHKuPX.dO) R.JF<82Pr~ztnvt{1iw"ez%s{GekIܭn 4[n7*z1|@A8S**,M'JYp@ٖ ">uӅl;{7h|$&[QC+ n_**Ƒc0g2W:W.ۊ^X{Az\/c*v~'7{2W Er CH4|I exm dǂސ`MM4O4_dxH-NG4A[]nC[+_ZF.Qı /UuN֭6z'$EQ1dRd#%!'R;WGU!Nn9%_v!(/14i4L=OLgƭD (B /魥e{%3K66?^R.@o'^tJgRcC`PB} YWxӌt@`DzXx;i4׶ "P+]o a:SZł  Ǜ m`qRcJgկFCnѺ0^KiybyA.8H}١9n:C={HdZSt1bT4zڒUXh[ID[{;pU@؋r68᝚YQ1 e@rL y;eUHR!Yָa,GA)%Cȁ}I}U#C@Ne ٯl+3aOP`j80WOAQpg\j"{༐8*T'>jt$S*]$2X4̀[=z=q ^Yavh>jSVBcQ' PiZ"fl`_XSܖScX"mpž-\]VMx9G9s?ʘB]ӻ7\CC,@k"GӘF!ꋀMHijCOg?Y|eGA?ҧv.)֪r| hl1JQMOb:Kocv9w@%e-&a^CIڳ?;<&POV)!Nh3V`1~,3O$y+Om M1 % jn%Ϧ#0*NԳ7GH C˘ι5'|N6XZaswyІ=[a8.N8`D_zsf]M|h> w?XR"lbli*OhO f cݳp^F4OFz :^6wb, >q(Y6nR\7^PJVc{b5]8iuu~ϞԝRYt VIf׍4d:^1z#Fj~0\0/vɀ9_ Qc1["Ka_]w"TT4ڒVW) lyHFݐ ȸhZELG_ P?dͮznT JſIPs )3Av gr(=9aP%rۺ;7;|[^h(_O-?g+XLXWẪF3)JAS3d#uaKw\!"|^o8͹Չm@7.$/An)jduuէasvGfϱc" acӎ#s(O\2 \Toe9x}bo".UP?>A}] ^ݔ|ʾrGn&nz-ދ_9k ?tF$7%9VeDۼ`))݈U+jPMCڐ.9bRLڕ]wmalr5RxL_ ,zYa%qLF棳m'` >:`#9/r9hε:Y:[\dʶ?٢ WS`-8x#/951k-G56ۋw$uB=Q{8(Sx+RhH'{*NڍUXW6Bj-My xJd%—G0ݩiG BF٭:of]E9~?Ë)cM؀& g&8o&l}]Podٷ!z#2V [k7BZtƶ x $p3wッJ18|Z>$&;hbLF1|k(<$f^~c7 DIonl0cA~[Ҍc,AXkԫ!aF JUd_ݪiJC,e̲Vocځ;A (.$-2/62dx.)+ _KV}AL?wk%p`6yd- +>z(Ud#[_gp~]D,рvy@LwXX}e{lM3s߿ҙu6ǖe11mgCB/ l}FpC7Yic0Sq@ 1/^ j*=\36z1fBe9s4˘b%v2 XEN_p  ~@?vuec#:"g.PH u)jW#Hh#ݠir|?;p ]:k.nTHy6/=RǪPLu qK Pܲu8T&Rm x.Қ*4&F])4Kayyc~ "5jrr>|AOh2k+J3WGw0\`RPJn(Hds\\SԊNǡoe :.2E@#4n|/(nJ`:7FYdٖPDxoxjtt~RvqR)%6o`Az}|nUS'v;b(nSV?aVq? ;S2pFz݅ra` YZ