sssd-dbus-2.9.0-4.el8 >  A    d6QU]-Zɂ/}mACx_/Me YhQq\s*˟mU@p7܈X ?"wݯfۧ#}g]MlL s]mb4'l&-̇D I;!JjgdQ}BL}r;Mۣ* `Kվ<`S}y)wm/A6Po}5zήV7K[ Jviعu.ڒX7Pzc9alp YLqqwocd>u +C+*"&nW"YC K#OSFiubҼe*.f?yتؗ|W+ryr2yRvYt[A"ٝ1ˡt߿ wk#*Xku;#qs'$'•9? U-۴]/K"SjQ_zѩLRg4f m&AeF7fb27c422d7dab08891ce09172ddfd3039b5db9c8979d9cdc9dbb86138722771cacfe9b27b6a9a3191d74d1cf08c07b1f9d967640302047c435bb5006630640230652f92f76f3962e7ea6843a255026e55f2ee9019d5effee777f3dba1c438237634b513ca550d7d54c6d2b28beb01e49f023022b294b1bda09a00fca43b18085b4ccd11962028749c048b25932a73efb32ecbfea81304479b2e14d051f2b38a24059a0302047c435bb5006630640230652f92f76f3962e7ea6843a255026e55f2ee9019d5effee777f3dba1c438237634b513ca550d7d54c6d2b28beb01e49f023022b294b1bda09a00fca43b18085b4ccd11962028749c048b25932a73efb32ecbfea81304479b2e14d051f2b38a24059a0302047c435bb5006630640230652f92f76f3962e7ea6843a255026e55f2ee9019d5effee777f3dba1c438237634b513ca550d7d54c6d2b28beb01e49f023022b294b1bda09a00fca43b18085b4ccd11962028749c048b25932a73efb32ecbfea81304479b2e14d051f2b38a24059a0302047c435bb500663064023000daad7a482151e947375ca29190520c634d652155ddcb5956a7dfe2c17fc019776c0e8804004f35bd41c768041aeb6302306ab1da82d505d0d1c0040007b5fa22de1a41ac37adf434a4f94d10503d98c560f501a93950f4980618ac11034e0f01ee0302047c435bb50066306402301822960b183a1eea23e45e9819564b3daa144ed9936204c6df3acea7d63340e1537769d7c4e1c7ac61dd496bcf176ad3023002dec0b69b90c981aeb1ee656d2fe7ed3c236c95f46f85e10c64c39edd13e67382df362c7a8fe13f15a633fc2650b2250302047c435bb5006630640230523d81b1d1dcb25843d75cd45d2d21666753090161cf8278f3b59115943ab9043baf78d999d97344c560bc9265a4a33202300ae149d8fffe1a908acb615ec1fc3ec21b576f0bc7407ede1c5efce06d2be94296002e7c6a99e54f14789a22ed3a27a40302047c435bb500673065023043e9032822615e4e213cebee4dcf22e29495c78bbd199c6d0599810015b1053ccb20520f96f4c42a2b8ce9fd3186c924023100864c3739ad8c97c6d75b7ad856009e7e7ba2b17ff374ff50638450650ae67e45effa0d9071ec35452983741afa7eacac0302047c435bb5006630640230652f92f76f3962e7ea6843a255026e55f2ee9019d5effee777f3dba1c438237634b513ca550d7d54c6d2b28beb01e49f023022b294b1bda09a00fca43b18085b4ccd11962028749c048b25932a73efb32ecbfea81304479b2e14d051f2b38a24059a0302047c435bb500673065023100bb44a8c22b01827cd01e1646ef30cd9985d34526bedd5802866102db96aef8df83af010cbc16dffacc23c077c999271e023069c68e3d3a057af7524ab2ab9646b2b40ce41d7c55482fb7688b7ee86304505fbd0a837938f33dc2a0be95b21e1ee0660302047c435bb5006730650231008fd0ef351aadca0f1e7be6fcdbf8fd87d65459537f242688f47bb97cb340fecd6547010831853b0d7fe6be8461e37f81023077b767f66977a376d09b9384e3aca02b932f376dfb3d5d719121f7e3182f74df3f4bc1095f6e57fd620d76db03b3965c0302047c435bb50066306402304df2ff2fffe87b77df864fb85ee6d9e7657fb9979e80f49ed1c47ea0f0bb461599ecd795a73b7766aded83a5ff1f4d0a0230623e156eb8bed7e777cfe8790041cf57884de672088c05ddb401d01389d1cfde737b066d864b622f679652f11aae06170302047c435bb500683066023100962e031a2a090cde920606e3c197d47a14760dd79d394a03c9e384b71d2841fd21abbc4bfaf36abc3b95fc63708a07ab023100c91ae510409338803e4fa8b3a631aed3184df866dd5f8f4963c2c7a028cf6fc8b48b51ddab2e5e3a3bbd6dde59b219120302047c435bb50067306502303fa2358fcdf01715a970d13e63890550822acbf5facb25e0e98056b94c30fdf898bedf33a138efc4bd08ba59facb7c4b023100b4ad7fe84e18d14ccb17be524463a9261e4b256acad32d4fb9d3cbfc9286f011d12a6e47a099c092461a688d5c9897c3d6QU].Q;{%-x9HRE!Ϛ$obU9CT >&R+ѲE4@A3Ӆ샩ʠEW.u0E<︦)tN SXqIw2m5C856< g@u徆Nb|yN?ܵu8o)dR_)!O;wn?X1A t>+B2t 0k2Uɴo:b/->i3k1jӴ~z@Vw w-)_K!+@V[ %N e)4kt ʕYjKe͍~_yŨ<*vهR8?ȻtUL~P>Σi0M$~OP5=w쓒 0 omz׊#)+ru246q6xNp_ܳ6FG6@X$R; o`x%7Q_KLNd>PBl?\d   8  0MS[r 0  J  d       L   822 2( 8 9:e>?@ G HL I XY\ ] ^ bd9e>fAlCt\ u vw x< yp' XCsssd-dbus2.9.04.el8The D-Bus responder of the SSSDProvides the D-Bus responder of the SSSD, called the InfoPipe, that allows the information from the SSSD to be transmitted over the system bus.dwppc64le-02.stream.rdu2.redhat.comCentOSCentOSGPLv3+builder@centos.orgApplications/Systemhttps://github.com/SSSD/sssdlinuxppc64le if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-ifp.service &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-ifp.service &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-ifp.service &>/dev/null || : fi%%K@  7AA큤A큤dwdwdwdwdwdwdwdwdTdwdwdwdw09f028cd5ad8b15e0d13531d362fd4f515952a830f6c821442cb3f901cf292a915c5e133db6720564c7c7bdef8861911800af147ab8862620d20ffeaea4594cea2631eb70e5cdc8392c97e19924dc9aca4ddcf4b38a44ada079dbfd5f3b5c8734601b3592d313effe1a70c44167775b06693dc9b72e7bebc718b6c9e8b094b8f8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903a9a4ff52c8cc02d66ec54fcc707ef9b4fdf7cda8dad02f6e2e11315ce6d6555a2aae1d912c0e6215cc1ad69104ba0cc4be45043cf045d3a9068a9077e4109ea173d9ee3ec2566703583d96cab625c3e9cfa6afc3cb2d77c9f0856e551e2e969e52aa53f277b5b3e56410bb208c8446938f2c21e8948336ff13d3b7303b4d44c4../../../../usr/libexec/sssd/sssd_ifprootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.0-4.el8.src.rpmsssd-dbussssd-dbus(ppc-64) @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shlibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libifp_iface.so()(64bit)libini_config.so.5()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd3.0.4-14.6.0-14.0-15.2-12.9.0-4.el84.14.3du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh rusvuk2.9.0-4.el82.9.0-4.el8 .build-ide68dc552f3adf81a57173205be016ebd2fb5e9b0sssd-ifp.servicesssd_ifporg.freedesktop.sssd.infopipe.serviceorg.freedesktop.sssd.infopipe.confsssd-dbusCOPYINGsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gz/usr/lib//usr/lib/.build-id//usr/lib/.build-id/e6//usr/lib/systemd/system//usr/libexec/sssd//usr/share/dbus-1/system-services//usr/share/dbus-1/system.d//usr/share/licenses//usr/share/licenses/sssd-dbus//usr/share/man/man5//usr/share/man/ru/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mcpu=power8 -mtune=power8 -funwind-tables -fstack-clash-protectioncpioxz2ppc64le-redhat-linux-gnudirectoryASCII textELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, for GNU/Linux 3.10.0, BuildID[sha1]=e68dc552f3adf81a57173205be016ebd2fb5e9b0, strippedXML 1.0 document, ASCII texttroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text (gzip compressed data, max compression, from Unix)'R%R!R RRRR'R R#RRR RRRRRR$RRRRRRRRRRR RRRR R&R"R R(RR,utf-884d30e9e8e60ed24357dda4bba785e59b27527df0a5aa8ad1bbd3f4d5694d557?7zXZ !#,=] b2u jӫ`(y/+k?~>룑-w[,xZlV+//ӛOA5l) 4$8WT&дWe`56dˮ4iX4 []:׈LRMW5"*v:Z %XWm= ^w`, ]-D*+ġ kNҘ[oǓqJ (^.L?7[ȇ ߒP{H ,SOk'=rg}KU8w slcor[LR :sBjJq\x[gXqu8-+!YB5Ďq2n#Ʃ  봙ŷ򕅑l>/C$#8pqj5"XLVOeU&1ؠoM h$8:~-%ZGvbWϋ$~oH0By(%%ڏ,>ȃ+$򕦏^sH`1'ܲG6nx4T(X И>|/ƒX*Ǥr`v4J'PQQ&"Dm :u5 XԹyM3r'^n'©"/SO.82]xmT4Ek.>X +D&SR\Un%a.73O+;aR2,&/^Tu,SⰨi]4*:7: ,+68oB   \i0vlBjŲL`6otW+Yy p!Q༳Dߥi׫u8pT9oN[x_йc)cLñ#=JA〻1J :xs^9ezYӼk2W)#(‰Wi{2G%&Cj3=~stDlts :v@JLv!J]ZEUfKcn} ^Pe `bUVüͼ1jݒGOGX'ח6aQ34~wzAF5pf e*M?xLdѼW _r%i0{G>-]-5^h_=xL"[ 7"g #l;,7i& }?tE|wCE!1Y)HE? ԁڥ ̭zW/iՄj]\H,h&N( -ohU<)=ף8!jN0]Ѭr_'4վԼ`k f lِq-bբKؚ]v1y0lipSYݟR1&+}?}$d nZ[QE!jrd5;8X[Op9+<Ӧ1G!Rc:k`8? ѲRSFg=`^*NR|woiW;ذx!'  z΍ASSI\?9TxR.vytg~7n*A@qx[e;Iz; "s 'O\X>Se%,.%qzǷkk q[g_S651t:7œ ;o70 z*jXbN%qB!:`q1A +>>nȔLVӉ#S tu[%XVm W;wt!{]PI4##tGƒ7uCIT/F8_ u6ݟ8?U .J?\܇e[Kb;وyV`X%|q3A晅HPkU'P{IH:\{W+ |CZw${ 싻% R%3& /`2K "?,}y 9ω5Y+2G8ug@"*A8ѺlVe@ƲhdKFY*Ѹ,`e߅\yZoq|?Kq57!-i .Uy-FҮ9Z)R ;Y5e{D=3]8'VaVJF\i4{8MVN!/q,TY| Cȏܙ.Pdh(KIFc{kTr * D"Ϻ):kTP"HF?RVҼ7UxRx~Gt|-ES*.cڞ)+':/-E !HCШR΁7 CCsO~5UȌnGW)+&K 'j+njKKpku©V?5ipuȢF>iz^}n){xa>5ҝ::߆ }Vy IzrE5a;]GķPdQ\?M>H@=L/dmΩ/H+ʞRE@&Tae+҄:+|g桏s)rkӴy}x"x\w.$DAQm-pSa]ɢ,κdaDr$'k(W*:16>hQFmzqO\Z5l9TˢEѕWvuZ℥;(;Y0C/P`{kpj̺ĜsNH@|bq %rpg4 gdkıF yM}㪌/rU}vou5???$cfW,ۧrgjH5=eu͏iEtpfBhs7[ Y;G_(m|;姀X FVW oo9R˯AA@ݾHwѯ٠B9aA&}< po4jxpcZH'jk1d3P$0!w`s-ޗ{$OAWlXo7mT\rud48VXMw.Z拍b3dK7 vʕa~1XA ߳[!01ZFr>ty\ ߇-&3"a?T[_xFZ yl&@ӲݐgF~ԲIdOuͲ+vipĖ+#{qЉD^ ?3-x)RkghsdG'+4/r ꂬ*z /+h'lRa/sOˤv >& a*s4#j$:dX"Vxg~fj];fX3!!owKFnH{!%QBQ@I6?ϙ?teR$E;߃ӛޮXELe [E/ejmLޒ\LDHF.ν-Ynw;?dmy_J.0bʳ} lߎ >^&g%<\42X1u#k BKc LRF2N VQFiL7 R~5 M+zW`J{P B5!?*u uqe#[(7q-dEj}wѫװIR-Hx/b3痃Hi ?< N6Y*{`AMl vtWs/ EC?[W֙SUu4I EIJT Û{L{?,8Z fCX`̂Lr6,q-}^1.`Ze#xڗ-=_3_+ q-wg-en҅嫢iYbޒ\BmWBX'1=ML[,,Z0 ˜&}i T`D@=#x2!5ߢRѾ.q fTIՀJG (&C~P]L١,mMo> c0edCaXMK;UKO$54w(WqAǚ^] %t|2'xGVɌ+u~\w@4htgT?sCHdp$$ +#FŨt8?ktbC72dCx٢lعJBl3+F$0?EX7؎7=Y(= xIl܌Jq3k{⛘2닪$vWsOB=˧sj& $$!UO_ Y813fL%q!}HyýsGWA%m/*ik{,WѤI&>I ݰ02bR2eCsN5nDQ>ڌvi-P|/‡Ξ Rp B?N@%@)Ng1K }r³P!Ϣv`GYDC`cßC]_54gV2}17n:.L0V_p"Z}Nc^?O>J}цz.޲'d` nHuR+zPSM-꫚x,5?/{;H74& &nUʺYE$v=wr4A^IEG>bzG6 "@ jPڿo绪9dТ8:DnpoNS\gh4>Jxc$Eg؈ֿX͇L֧O *?62}ՅL?֧')tsN';vh-ՕZ֞Qk0B*̌}h'sM֊`Lqx^SD;yN< \E3! ײa밈b'z]}_ν%q܅_VF?T۲O4>@ *bm˺`ZO#]IwJ̛ZCXcY3__&z4@(ɂՀR$亖H8w>Ҝס$DK6v|zJ9 XE+:!VcIr3LGɈ9ݣ] *VHF"b#SGJ8jea&Mi͋hjZFy/…tJzKqٗ6bbAӽhF2aiɩՉpD:m|p"\f"]'qH& }9 _l YۅvO5"uܺs>x6'ֆK@7_cT)҂D|?3|BP-4(*aw_{ji6ɦT0zm; )Am* $$,AV=a|ze {;ʜ]jB 娺B`Ų\$@d^/[! ~w7bVxy tMIPL.a%HhXhQ >`Lu"j :`jd\oУ #=@ߊ/ X@[qMb)viR4Ve,Mr AA#e>K'ynq'j=vȏ,#NQ(Z4i[+.(/ul91,^X Xu5Jp+c\DYQ$sRߕYEC@B}D-(j82=,rM0zk8c<4Q Gfj\k[b &w7#U&vXc@zzH<؆1HiEpJ c~N6eY- 仫ddx2[u+.Χʟ|1^=ŷmCRŲ4H |_=QtchڛN=O2 RZ7mmZ?4&iGG ްU׎<ߝy[dzi nQN ܱҷ3.qNqYD$T ?U{7Ů 'C= OLZQ.cvL\<;NE#'ӧbd+k%.ak^d~Dw4v 6_UsG|(&$4nc{ m#Ѓ-0}#![g8XѧK*dI&W+2˱1kEEGU<һuIkT @V}wAh\!4B{qNłO&FKbE|֡yNz4d5e`?1nw(=J2GGY8 ټ0:AdŢ@{B)n+JcnUϤYv\V4O3 hdqgCM 0~#ӜO3ouUɻLg֚95dZZ<+D#*H© {w캡;$'pHǡS(HQ[vm_>dj6;UqU+/tFb($AUW^މuV'!Vl֧H%{>altQJˡơu.9M젏Uw 0CkGno 4DPeN( /F S瓃L=X}vĞ7T6.4B Jƒع`2KOJ'A1[ cլ4ٌi MNkre;Q<xr\'{W 3:J_;Z3kN=r ܥ0%sqtLf! ¢Ėr an,lfx\WHߥ2Q)k;̵xz.Td~QM)$rܐb9crI:|h3"p7 ưڳ N ڬn}OYJmf5BTΒJf:ñ@ޙ$kd4})=yxjFLt.7OJ[+1?fb{lJ'>B;ӿ/GiBQŹ1at< 7a@2YVzKn)V$ 01*TY41ػ*IG{.EL2Sil)oQ~m ZIW<]dǑzy]NNè[w>/%-dHQ_"LLL3}dC#LQ3cޏAIʾc]TBBWX`?B:- qd첆{~JW{I q!V/S*T)\\siCQO3z"։n:w+Z]lP"ۊU( ֬)l?ҞMPJ85U8[|6_JlELyשcƑwF>?M@UިYUj Ȯ;^a@/inO:U{ǂ- "xN7ԅY y!%ul\f|rJS죖{Z 1/5^4R,hJnTPyfTª Mlcu:׾g)Yҳ gؑYRrE2ͫ )c0춈O2Qe$eER:elj z‘lC!:']ڿ6?v<c`;k$9 dtHEq҇O-Y[ϰLë^#ʸ3/.Om^&_9|HdYO^2Y'QWceSmϬr@2Mm,FhC:r3>',yv@mkPC J'K>1WlG=b=C $ȔY˺);q+ WۢlLirCwn-}~_@]o.?;l>mxedՖ@; 7bc"k0 az^.A# >$y3ja\S,&i<-6cjswH&7$+&窱t~g/}M>|P=QbYE3$Jh'l#9L&YH$OJ%Yr18k?_F}o.| B$G6'&~*y b1 j;;S2.**O0hxo+{ErC@tH`)*RV AIf!bXL`jG׬ kTK(7s!eQ(MʊJJ^o!y5Ծp,YFjeЧ Q,>࢟XsKgK9x`tԸ! ۈG)pFzaj֩98/-lvuQ - dbԇ9 rϝ>59tG%I [*dxz"*^|8 (Qg$ " x ؗ#z6i*U$QhtdpWz`@kz\n'3=ٰBY lMܦ'!H0Ū)m 48qB33ÄS[Xϙ2jJW9U4'\-swVߚz;.L'y##F؃ڢ%QJΓbLOtM[%_Jݯ-I5{l?C~̲2t_>~ ۫ƴFP fQIxT`Kw߽`CC Hv^v'~j0u'Y+QTW,IsY25/\F2X E140 qnR`}{mK]VL/MxAw8>ʆ[dUgH}8e0X +!hpHUuҘZȓUr5JT)ќ45d\D9V)y/hkТ6^FK2k[V 21JToBeK;-)*LN|ʅ ʙ'XŔ3Bu C+b =|}73~mix RY~]"?7 0kjtM 1x  $#8# ZWE^lGZr>#Wl$TQdBHlT<;׀( x Zh1>UVa}gRbŀζ@ ҼS='wT] h2ue'T*CP 3)TKK~o.*c88;7N-6܈.=b0H X`abx;ZwhK1]AYMU242bwہ¤^D!io\%k1̷Z-fƈyl Nmy1zf8vBz?<=l#֪v}%K@O;?zz D6b"/U+)s^ PO 32M=-{tue.Ug_UH`2=O [_U%w*#ъ+) $hߟ˳wyuH&k)'W:l}A^Nk&sq&GɑyICD!3&~iT io%.V?K&3|\LtNcQ^b\{˻:}j7 IJAP%b(KrCk ) T:KW=$lx#W~f+϶ P$F4b:^H6@5rzK婛[\3|qj86v5(p2?(Q[u9e?є#wcDE5rpZp޴Ov\b{+qM#ÆBxSE6[Dj NqԚBe.}_Aƫ F@w"բLX[S Y!;`\ R<X8pNRr }!--e3?k7I)EPG/xڔ<ZȆ$3!Cs[B@&8l}ͫPd{OspVJ\͔FInF~V-,XS=/ʏN5i4L2V|BE瑑!65Csy0AbȑI~~;俩w)ʅ1YFl9^ "F4{$i8BB9TO|5C*#`&翀>"T6?=%ªh||$ _".f.|frW'Vo7⒖/Jޥ]!8}( 0h m~byZ7ֵ=L>Vʬ_$ZѲ4roPVb^wy"-?LɷIhhdST@:wgJJ% LRiZ^+nȩ~"w%lf[k6;4b .ş3@OnO-Zߌ~ ^O\8Lwzӯg aNl3 OyGJ/6aߓnF5؉.Q[pSЗkɏ̀r֠SD٭P. ĬA|J 쪂)Rv"biJq LB0T`{۝d=\,ZVʣ\A$=eZpݴQT||hdy|Q#0i&Ԃgg߹6vKrZF!o;#899#U2aJ@`j$Z]Tf8B[N 3mͿ5^VHn$"9rYq5,j3o"&ķ1xɐ~Ie1)0(ؚ~u"{& p7(X8Ȯ0/K!A^.GZnvAn {K_wVKj&Z)yzA&D_&4*K <K%傝j0 Rkb(~}:*=vnUIY_X t3JV @F'ylqx"0yGpMjc7BP)5ŞQBj>/yrP&q{l"!r("Vu9֊@K:"/|[LeͰߞ-5u}~@`J5=¨C57@[}-wQ2̿e\&d| /\ZqM+k@u/9xkvpȨ=1˕Bj3r.Mc :wzX4;[41/ 4`h "* MQ U~K 0/78*P]vDPe8KI%#81Sj'bdS67]>އ1H04Si0:qMAHkDA#s`~n+&S+Dk2 Tۏܜ/S z٣I&/Cٿw0 O0k>W<|Ȍu BՔzS-/ .d ?h.@ڟJƯoEM[:cp)늑pQSBg;0^cd%^|rnؓ֯(hFرp/i~gd]n*KaF\ٍ/I2 lMI)txv#ltPi'.IkYdp<%ΚR 0T)'ïۑA0ϒq2ݢzR$r)R4 7]AM+.73IaIb9HNvx ȚwP,|.J@@@)DZG<<"nIF{]8q0%_W&V-V7i['ۯ:vYHuSKKocװe$viXngAࡿSC=n]Ơe%I L-5.j 򉒸V5=H'ӯDR:k Ⱦ{⩃WЋ}嚞!-g?{:&Tf&\+ *[¼rR(82 d 0%r1E7?cRxtn~ѭJ 'UkZ^wm. nH09Ϥ㿭Ol` = 6)XOݠ793^!)-Qq__D\*,kio&j<2#ӬFp^IS^sL6dq'1㻕&w RQ+c{v9 矬 K0NTs?U63/?&ؠPpV`mR'KRGސ]`Wd 8u5sN7Óј-9D!}%c~*?:>L( kVƈ[3Ʃy26\5l[>ݓ;HdPH+q]6F-R ACAC6z"1;CqY Xc`߶d\B c[cԶ%ۯ]sf AizoyB`bTqu37hE7^&2/ƫCgt3*b/3/fӚy>'jM ZAt{'"8y^eH:y|GI9-ht[zD_lYe'lQGG:[hqiD"~ĪcCrxJ9TOsƚʯRjV".FV jŵU?UHr)a & v?ү1r*9AZACx;8رh@Nu}copCa|e1/Y`i+Of:d L.:~C٤#.ѯށ6h*Ʋb<48߼% lX6Bc8*":@# f2w6qYzޅÅҸu`19X475cwoJ)O BErM/R_S!eU{Qn1haq!o搶# obY#X>VW7*87<% X? )P;A1xCl%mt̑cn٥ 8.lAat쑽,r0.,E, ,*`4?ÍtP%s<2]%̏(vL!Z45 foU~{-~\W0e}@J;=B~:pu\esQikMhp`.֟üNi>]x}ƒ(Gwt|ֿXw??4=Brv>ZzĿ=@#ld-U_ X?:=#\JPK̛ߛ^`$Oݸ >=A_]brIlQKD՝bUo1T?U}5y+gA0WCRT'K CCqoG; XMg3ُ\ut$62sSMWoEk(&?93Gk`g7fZ.BGBs 󃵋DWd. @"DjJHKT|e"Am)&3nUS ȓŐ.״NgP,]򵉌 *i0io37tԖ+Xux _J҇ĮC Ä+y.[vrh܁ 7.4Lײ|#-KϾd~c{0ҡrWbŌ{7 *R@gz1Vw|#,Ө8D4OSd|1rۻ*8Y9ftC۟J7IcHx&@Q~`x=  G"f{Z\Zcu53T슆A ^W;’M1F.šWB1.__d)yC9v[AW%.g^_<ȆZnK EN>9t`=1+TaI4vrtx.lߎ E*YgE5dx7s]ҐlW0GɷoC>ThWX;}Hru%ſ _.]:`C=q rJAşby*^\oSA'KښR?@!\@;f/? 2O{,OF=&udFdT.W#WuRB}Vͯ)Ɏ*|XfmT}59Ñ[_Ǒ-pF %SE  .2[B}9ޞ;[]wZ**fZlYARʉɂngix"(#[\1ẙ}O!^[ΈFuQP}q'r, 4Ju%It6]ێM *pAߡO-U8l ZG֭\X }QL%DCK(3%QsS~Rd,gU%b`}`1mlԬE_0M P鲕{OL\RaaҰKݬu* ͺAx)`'R!~Az?x֬(ʩ&O -צ*ʅ`+>]Jlq{AUc,R%>ƦаznEk}X/Q|F'{Q(SM3rR> A4f<6/{[dE>9 IA'yi9>|W-Ћ׌gF)xI_-;+J ΓŲd)Ze˷jAyy).UpDVFL|H >34M=ÖosP:bIO"[19w[vi)G/<0$_#v1{u[8%?yBP7X? )"xtd`?bź#ώd^$; 2.E QFSk Ջ ,S3I~Og=1GaD`9˜tn_L{u]`Ǐ\mXW\OQ%I E?#n;Uu?׎Q@F9>0em<"*>x[=0 @̤q/:0'kcC; ]M6%0m\;MF={5%JO>vd̆q@ƨŏOgtJcG2dEf`/Jj{dDYIK<hI};VzDCI߻\wypX^`A590ϲ o>1V2Vi"Q׿p*NͪwYݳeh<3}z+ՑyҨ6NI (4sӹIGVU33X&|jsQxoraǟR;> wSSt+!TJ m!uգjJ H\r}L@Nfԙ@]"-xSjdX1LIR4jsQ*F)zJ.R}u!3LJߟ^g͜tY 3u\IC3ÿ6iYE2RC&Q`+u692G.M `\m%"هMB/ V{q2ݚlܿZC"PY!\_u,9m=ꟕ~@2開-`L^CZ$rC"_MȧY! XHS<;N54<%<+ڢ]Y<8:)b;čxM;OHSB*=jYK!tdqGɦ6ʨ{$(f巿q{-i@U7gC ?w}f*3*/bBp1JЇI*G*^)ܼcT؜^Beu2 -Q+E5a۽pUI>!p:axgDE6!'l{h@-Usϻ $p6!@ B[Se@} )sDL;en }>nD^TD"дLFg3gRERhݩX4:!~jByFHP0o97Db|N&m%㲋p`BQq,8zd9Sfl'` 2v}к];fqg55}XB5 $ rك} nQ# \ToG|DӈA=æ$یXa wL Bo"Ng7 w1ЭMW]RC0¨H>Sx| T磫qͻ{w4ob6eP Pu|nPE*qaxNM;/.82%9|pp9ML%%T[+G֝GxN*( %ttQZ@FjρmRvB,ȝd2L0[Մ_]˾ &Z;!2QPp1^6aЎ+*]nMr k7qMp U3J{F`;&j;9Vtb{S/T_5|v7'Q1ReUG@2;ח'fU|FTv /)\$ r ')\}#t 0CYJtCE=2p[?&nu}<0]14>O{N՝~@G LMKS6ٟ[:@#"R&d.։k`vB̖d&2^IDkfͻˆdfa&P]i, =McZn GEH!\gEC|.W 9yej\ ,ڈL&E!p+7L3q"YdգU)*[?-U|WRIJ+Dy݀?6w& Z&1#b?5ǧsDJuużXЭLJȿ5q p n]LҏwU] |s>kZ/;*(9tݯ*㥂 [- A̐O|3VzF+,у%gW/.Hhc§K겭, n.9 ݑT*;0^<pEnK<#d):EQ-!Oa=(gay1hkc %TUNN E#M I8>7NzЌ`RȏpiE) C<´f3rXt^qxySwjsnp'ys(DuDҏM2WDIB[y^涣ugUAv ~-jKgB1Pؽ@#/TH8;4ֱG[:^-svކV suW~U)$Q?^6yaxfqJwbs 廇pU6*#?K2 6gFM..U3vͣf ~ȴsmʆ~cZ s[26[E PXRp?U* =o'Ȫ6X<(mTaJdOYJƚږ=U#x%vK:C2& oXWFsK{ P|-BcQ(^u0I-@S<1YMe٧9p9 {v0uq@q6 Vb*ixD$܊FD#,rD֏J7 &4M:?)`bYיFv͓23fqY?/:tVu+_{*$Xf|'%7>=֧PKP.QIfv@!}Tqϝ\GoDk>Ha#&w3ǣt lc,xr,ⲩ33BeYBqlF(Z|]HK)SGc*ρ}20,wj^b+CA$`!jԍ ۦv}SoOi].`寎Alr pc:WG2v~K_Vۀl}dd  ; 1*8G<zrBՋ#KRm1KѐlsjS3"/4leֶZX2r[C{cƖKwQnVc=Y:x'sz\D04>/RoTaãduC=Ä'0ta)PN|T|Ht!)"L)F0dzY{MeOۛ!kaW7ƻ6?|8̸Ӝw!v(d)$){h\ԨMgvvI碱 pXp5􌀨~pQaB~ @ 6Ypנ.۶pZ‰s0!$`<[Vz3p(x Y}k7[eƬZԊN.gy]ƋdlWfi&~9IAt xڹil1X7 ݺ[۾`24's8.\8OT՘ 5Lȴ*`!#;u X:EެEjFWP&5X%jo1F7&cEhhuFb0fk_^y8*Y5me Ԟmpz)e dg80bUEK!z"x9D:Ƃe ?b&n "MnTy;-!Yce*DFg̿XJPpiy|^~؜E ePEݑ|aLr4=kT89+)~dhp/16NJ hL;;+x1*gv:-4emڧNßjى_ =--Ii (LgF 1gdƭLc茨ӂ]!m?gGkϘFrl=TYWxxQ%U=!Eא>3OQ&2?-5zkc>[idE^ˡx-=p &/7g&pq&?7ȁÍx8id#Rh_ֆ~- 1G£F-Sª U/~ tL`mKZkJ4? {. %vԾz[.thx"F*#ݖL仅={xr)' ~=x e$E+]밁 #nFg5@?@`kC;C}}޷i7k`ҩ}{t ]}k#\$İ[s73Yƒhu:+'ɲ r&(C\fa } 1(k~58P[|HgF1٬>)YxTn+Ҹgre^y*^'Vܚϗ͓jk OJ^_mC_ԅdޚxwy;`XcI /hq0|`3I49,gYg9 YτRr Dh L] r=js[ew6m,M Xw5M(QxR$eޓIwcc jPlU1B>]&x:liG lhH),IP6r l-BX哃!e2wxN$05XmsV8S'ty(k̬pW|ǐ3 +fDD4z(Uyc'bBw:ehkH)f.rg_\1ȿbg^:2~F \[]Vׂ\&oyMȋ>_ SFw~XS2܄]Vea~ + :Zw+ִ30u$׳ۘVzKMj-/kJNbtFзRߋH(n(ڝ p'6$PF[ iVz)rKMV좡.*SҚH5_gzLOIdrB`yP,o調%u2zc<\b26_*ڡ_kza[\%2!jsu= isS}J² yBAZ| #3qagp]a33j=V;Jg%F1ޤ߁6n@On I s#Oa@y6?36,XS;@ R Uw|E'PNaDRgS-$;I T-U(ӴLhH8[l%^n2K n&l!>`ae0V;l9fa"e܎jϢ.rD<]׸CߦrE;#kLw3j$P~v\Pj4iOAvЫC|3ծrF}KE<}Nd~U?#"]N!}.\MK6fRE0FX!y_v7%*rlV*[c <oo±zN>66c-J@tZlU :LH[zm85 uG.4ya 1=E *i k~ miԉ.QrU mK쾙K/qOSZ P?"h'0Xz TpwM+7ci\̈́@"Oc$8Fpx)%Av3o: ]{(3 :TcDUg*i9?B6ʒd'Zp !nW[K!,GA߁ * 쳽M:ڬK\6?vԪlV{L`(UKxB0mU';L7AZE<G 7g!fjNf5CM^-B2!pŒn1<~b`lwȸ`\=1fyeܻоZ8p}̈́W=ȸq ?;3m|83?p~Z-tE$I>;} ߴ)EiL>$TS1y VbU:tA+ ScX"UդxP3QZfKh={!bcD^_U. e:7/#g45Wjd37/8 boLA,R^oge5fZT^B,z΋#O6ֽr$pק%o@@~'WZ3V035+_}V&v{9d:ѺoCT3.WCЙuB<.;27D3q>jz #;D!v݅CbTB^GOdDžS+p x {3pxnLw̌C ӣ&m!TpsEٌs%dP>!u^&w&o&Zuh`}0w؃B!,7lr5}@'xa9 Y^Kd7wlGnPE ٙ' 87!(83|jEX=M>QH ͫ S96U*1o x[UqS59X3OYYJ柟Zt:jǃɬ뚁F}hL2%:PVcidl+gAxH.2놽̇ƜR>>wB(`88LH f0ڈH^2_,'9w4Y6"]lGC],4[-҆F Ik陿ΓbjS++!gep`_r!C-|: 31 o ^ٶK*߭؅ÅCddў^ ݢY9d-=,[g%RG -P-mi=m`cĻONH%9&&FѼ"RϲWjɨ@ALReGyϱ󣧽 :>UDo{ mU&LʭSBHpU}++lӏCQ2~^1Կ)m(c2zD]ûBN zl? p= @w*> qPfS=SӘҨvmJ?g\=p8jɟJBP`Z1(v>ZIhI'_'9ݍS:Qv!B@&}J`M͐_{q_0$D*2(u8q>"!f5U/3q st>ViM } *t\9Żjy5(zP b}1ZGE0h0Aڞht,)l/KpCr+qc)!zHy+ٽ"RZٿqG8}0ΓɑN,@vmn]z*F>_3L?;A+y[@s bL:#֋xwzwoct_c[8'Z5 (xٽ# 9'IJm U8 ER娊D& jޙ9"XSZ#jT k{p|G,"C9 aoci έ3V +wz?^ooY*^%:`=P*hk(42qNx%s7L5<6J=/ nЧfYVzag4H~6Ԗ7 sֻ(Uú '}SD~OMY )e*'Ë-x=;ӌ^qhk߆Icj\s0x^y0inO|Ul/i >(],pt[T/K86Oϝc IHODV)qKm+-}%*y3F~4X@5X]Ud*^",xfqhɐN*SVC&DD W >] Ȩk(B^5 `o$CtDH{^0T/˨dOP嗦ckKiNCrD> |x}r> 俦bE0K_Tօ=G п@Ya^ #+ޯO+aL20˓+FF *7x-}*=u'YԭL]R1!g·/~LIRXȣxȋ`%ijSn ,$&Ր Ȑ&ԞWiT}I."YXTQS۲|ajk/zpfl5-4Rnΰ/,# ,b2~֛!T?O4u\i FMMK #/͚h;bWҰ=WCAN8᛺O㉉z}Zb{ i^XVZǢ hF-nU]N!=N|+LpF+y5#E(ZhphCHʙ>;bvhjS¡X(DS" WꝻ?VU-B;u`[SWHr|J’oEˢaeu |DF)yzɓtfR_x7ڗ\5ð(m=qvDU;[Qk̶ėXtep@=LI43@DZދlifF7*g s}83㝥nTGzks%[krJQ؊Q+ Wx9LGtM z2Il[7tyė'CN﫨Z)BpJEޖU* PrlVZW.D)_Jts?Ȣ4gP=u4Gb.)Lzd6c#Y4q Y},{.MNѳԨɎ;voaJGNt}]e3#Ǔ;\ h7įYYXp}@^L]O5]T_勶܏Sl] oMЈ-SJ845 Yh(\MB :x4"OJ70JGPL`ԃpA Tz‚BxwQwdEz),D04^zCD"^jC{)sW"W@{mۺc%ѫ+(,^[OwI$sۂ#}{geݽp ־?Ar_ zr VA.wdlUǜ M@ 1֜!/ؒEyʷsWԭ!&{Mפ+F}GDVAoa?)9WoAWeSD6Q@p^_3rP{rnwnWEz\֝h߰t^x5 q3 FfkB؏$ :[q ]nf1tC`kABWGk9ws1( +2[5$J@S?^) Jt.}4MBM†xxe'q_[ 09a%YU*[k5`r "/s*>A7"r5T:,5M> " (O-M664p[ ¨9Z0\jk[c޺YǟFP\;I7f{^XcwQ"logZ1 :=ţ=lo&GdJ8t I;¶8u6ӃV-F5 'n0FEaO# tM< n6V\+.Rg!ʼbU60!? cj>#~p֓pgGsm%iʁ32_AvƷUF^]W툚aԍ9Z* gAoԩוk=j\OxyN5h*c.B)M(Tb>~  cPeO$,oPS>/hW,AZlHf9Z6Gp1̅p3ê ^ьfz$q[ bJkgF9ZvČiVr;H?̋yͲ\/79(&Y)H E_hEz ߰Q4/щ 5[JC6<V*`@mBUZhVg{S.;(% ZM u8㛷vj=(ȡuԦ 3DE;N(5F2rhĬugdq!nvL qr{_HF5H@|[i *EZ[ o퀮cS7:_G>Ҟ f)0%A sԨ!4Jg,d%jգYAks ^v*BCP1ҥ5J'"#V i=fhpr:}YāfR -_# cϵ w>c u oK)'ý:_,D⣒Q.Z'itNB!#[s!hN[攭_EŒ%% Yg \8 TL)oKl7+~f 'u4ûHwszL^ȣjzSw8$F.{ ZM>>c jvE `xgUg'%8>%k< NIB%@2z!VM :DǽTm0=<:Ybi0z=ĘW)e-n@z8 ڀ9&Z0g[t礣)~/ 4ĸFźw Ctoʡ:pBLm=k>`FMNxmL ZP掟)Yu@exH0) 7X^M1bX 9jq /@FCMy"[ [;qϒN1%'vi^+@âyVX2'vnu~ql4QFs'Ҕ)IAPw(DIL1ނnOpEj;`dh$e}˖'uԟ8E(prϸ 6ƾlZ] 9o.j*UoWt7V y@]\1%\9RtX'oz$l,&6p'bwKܤxޖryk1$DC@Ğ곿apd l <%mwO0P~3Ͽw_L ؁a})lyguzťDw^.F3 [N4eVn{!rt\0%Iv^}j/ B栌H1q }1賴]Jijn\5'_̑D& !.٭JU񏒝%/ZCdL Cad}рCg{'ntF2p A"*^;< m.bPvxl9[Is G4I$Wj{o#aZ#+~K63LpSMr HoB|I2ЫWJR:1c/[;q:8yEV&XHPNRQQZ1$O˼Dz#sl c0)gh⪕aQPq?#;Ȁs @y\or'V{yaBaֈ )5Ӻne"焽}Mz`LyEP+~ w-W`1?toK*4/MQ뷧k7G'Cw+d[n{GryIEj0Kٱqr;idd#q0$hېCy֦+y]ػnOm:T0*dfwohWzUwI>l_j紕9ŇƕxSr*-((RoBT=€_>~S՞&XMBJ00LGwo4$9x4Ϙ;lw6iaXں>k/;rjMϪ!Cc9o*r1yOW<&l&oо ݐh41ԚUeY𘷼(,Tp3PQW_s_>ܧ:E]8+{IY ʯ>chBC2q}.0 I;\K#gݧiܬd-~A2H/huҟTmu7XGl> P:-'eMKMl4l艦x]ψWlh!Vp.g*(a?T 0xޕ(c؏Y$q?[&iXS$ UQiu{} Wn][w OZC`ϖrxM(.ܥB>쌾ss4*3 :+^ӄKR2!v.=3a-L w vmK /ҸGXХ.׏pzM"آzGtˋbxT[Z*NuctPBsnK?-5n:XII(6`Jh9S cB 4֜ԑo*ܔ= ~>;6Gu;K%cݞx>,}R[W=Dܠs7RWS[Ҩ4%1h`f!A$8‹fSD%Ը`"kl!qUTk3 0K Aa v:߻4eڙ?d{ K -u+ZzԇbAE#2Op໮!3ё`{!9LAILz| һ91}GզTaQ<u"G\-;E`iE89bAo<4br j݇[AB4:r%YOl%B( 8A&esmq=`L/:҃fsevr큏5JӦ9 My;u5s{B3o_NK({˪$(^AZe~x٥›&x+󬫭8!Eb3ӈ}n?0xuzSf3]]cZR8 T+_*6J"#]E|_!/Zuk]Gjk^ -4(~hĉeg(ro$(ˁvQnZocq#Wi3uzY]64-OPo$+uW~ U :^>8_6p-j}28G3[:XX adrT{w27[ޮD1N#t%S_\&i-u|NMk%]3GH}#DHqkd^WpQҞ{zx=84y|Iפ5wh*\1UC7P}#9=&q!Kߗjֽ- g< Rb1T{gΨ9Wgye ʚOdԛw>6J3 Tpw&EW@T%[ct߫d?O^ǸOLP흧`f*my[ݶ>tρRN-HEVd ~t6@0mIQH:t⧌:RZ<#3l.IQ\3`s? 72 27[`9QKO`EͰ%u}M:{&wK+(痓/?K"k8S&:ТO)ճnz Cu?S4W* s킥#xawCmФ|8D)>`#e(gPpڤ4<Zj5e:cSp>qHFݐ~MkEEpGhjDNCL ->p&8 /h GlăqaHc1|Nt\߱K4, \uFj~!s #)XƔW A|5ܪ:{>')UG",hz¿kW-Z.:eF9Ed7\=ʿM VN ЇZgp=Vua 6E)~< -'.V:DxU~ (۴\uZq卤駿lS܉#f!r"fӊwq:~`Ai( rF'XӋb*1Ym̦ɫUegV2豍s?/IjWԛCGt*7D K39qw\'9D$Ϊ8Y-blfS fnVT.|\ Y*Vy 3ri)pjU~mdAREx5$*|-< (wg]'̀m6\Ęe~hb-˞kׯM7I`A+N22ۮB6#oR}y (Slb8ϕP(կ1xǛ&5ile4Jgܿ<Ѵu/r?y¢sܗ1u`fJ0ǶNN7_h (3;h`֞ˤ[OKTW%x6O;sBEJ@Z}PK6䦪 |,@aB0N;brDP-ޣ5K 䞝\&FJ[ynt#ma(}fre`}{unC"*Xhj6%j]={j|rB{) >j1:}agNjP_ᗹ7ӲO{cg #͗: _Yߋ9*\JvL]jؗbQUJ =[Bhsa.dp˝MdQϕ͓A*:eO6ӑY䡃,aG)΂Dzew9*<o:-0O!˭Q@c [%[8+iO؂™@vQqgGx[pK@Mx34(UW"E:f3(-ԅ tux\wq$Yڐ׊< tǟ@_ ~prGc+ܛaꞥbVBxLjSa#G}*B[zY!c\bc|z%c=qT[j`#. BKΕd>&܆@C?=>Q4<y=[:p%6CksdPHHl$|v܋iS52C#Xe|>S_綞N?dK.Clx ,h&_sp;[ZɵA/|1hK kfa+G47~g=FWY@i_}pA!1yTE#$:ŧ5o|=zFC\k 5 >1;(LA ݵNpmr gPkR;UI#prM9nMDQq_\ 'J(NK Vp:Nj;ճӺ)3`I{IJe"vo"t4W&ݫfџ۲5%>Jث1;i^Lm:OWKw!ɩʮAk}:¾i6HٸP"/l *,:\Ltವ|#ͨsYxV9q査ڲdj vV͊ާCX.(/S21-QixXo;]D{`V K_$6#4{VϗM0رD? 4)ȋkCf7Զ)#zb8vP35i)@ )@ՒySqU b#Y6# ċ"]!T6,wrZ}i!E`|X4DF&fܕZy>iFt?h~.|XAҋ}(jFNR,lxe9 |8`z!ؘy/ଗLFdA׀VF>x͝@'9_'#m/( R![Da/<ل\|HRܧ챡at~>i l etp=?6&nU̡'zv;p8x9zs|wyMl/\z_Ypݹ˽Ώ/j HJդ=P`FFMaMcEU ?E+1d?.pFU10/BRfhq`;2>:R]9>{&T|Z2Rzkl'9+bF|YtK,XN_h-*^ hwh,'qpi~fǥ{8k\[Qޗ ^Ţ122dQibl.ck"(dYB5E`߾P|)'(W@Pc^L}a1`f5`E_-d}W+hNҸeՄZap̶a}d߻*Z7챝=K`mGGХR|Klx2m>Ukt8LR$$=$vo?R+ =Q~9Byy=1nd@ G`nq$qt MH׆q)K5hD ޕPں^zH1oTKH ʇ8[a yNu֢Dqpeӵ% ?Azpch)΅m(]Zܘ1QeimUUn^q>c)N }`5/ӿZsr&/2(g؜x""^q M"RЬ_v9 m2f3/yj tmfI@lrn*bO7R\6w[O$/~GdU 4\ϲΦd^Va6Y9K CxTf`K7٦c!'[UP]va!;.Iٮt$7rL VjZ˂fqޛT8jU57-Ձ3rn*kwVc-"%mi3Զ]ZI"eNC~i[!xV"6K l(_ʄuv6,¸174δog`p>?aɭYw^+zpk% Ń0ylȈODZCx-"*(>G^QEu9Cא=!a7Φ) 8 P"~Z[|̫}$qWo—i#doprˆc(AuŔN$\Xu/pr~ 68K=0܅7 Cvr3¨.o%ʩmL g3ٽ1hZOz+~jU=oQLТN@d>0bD"Hjc5}@fҿvKD֓kf5gרWmtEĐ|%_^'~*c=MZa^̯5xeI)sHaib4p;TVV&*7iw w4E}j*qq ʯ4|; )dEe_{{kET!zF z|Dv4vƍw63H) ɼ-{ l_%/Inr"؆EdpqL3cnq9#ڭÍ 3O@gqj(PEZ>bNP'E{T[ȊsӾ^(,t NaD?c%ؕmB:pֵv)6H-@%;qP'KJM-"\-|'Ʊ)rĆ-pӛvmhr:ؽښj(Vf2Srr_D_d/ޔ̓Oj|RpYl1lv47n%lh!~ʚ7FzpU} @ nwh%tҦvuƲ8hͥY[9r\W0 .VOXV6L3uHmG]`q2yއ0ЦpEZWlf4Mp+;^sA♃MZr'IV!at!aeV݅Eյ ^Ħ?c]CMAZ4|cj}Cw3Xղܛv#s`ZNzT(NXFTr/7@fI=Z68{oM qͯ( Ekg{w :h~Be]%iŖ ݥr–sQC|b:q*nU$#n"fwXٿF1Җ_|/ZKzyegMnz*JSQ5l^ jjѵ|  b9[޼+dߍ ޓ^;V{MJ $e-( (&H0}m[6+-枨9h3ȇgpeјZyxs[ @1NVR᥸-+' 9H":6-Z {T23T\lPO6aMZ<6Zj%G}s1Nh^5VknfRf%kkcef1/"@qn]E2e2En  |7kD򀲤$1G ǩwC'(%|ݨI27U lƜ䝣6FM0M"M+~׺)VCcg_[h? ?iiW[&D5Nд`CM sP}#eFӉu!`w~i ŏ_WF` {ڡ 8)ajL-)n|b >VP{{ ˿ZjA9L^Htp J'O%` &zVݿVVFNџaApqxF6r{gyB?ʭ pR[<6ӧ\3d EWV6QNySG:CoTA}xWsD뀴e\E[dj*-h8z;E:U8l a GRmƵ!t|A=_Eξ#j=[B Nyʀ{9-G@]/'$"^,vY,ZGRMgP0"7AR_XWC7 Q-~EDc?m#D'JH?·w~9.aYF){J?tMv讳Xliw°7 6ynu__f*(4u~x; ?  i@m{}>RPu~!0F&_6Cf×Q!X5{T¹쀺Sä18LN8 (( [Y]R7|*`hȴֹЧNI拷SE͂ [oxUqhPhU.iOZ7 4>b9q&Ddo؏wO8`eJ>dڜ5T `R[ڤt_WgE56U4<,KЊX8p2*t_\>W5v)qRҚ/tvByF΁4&TK|pv* ҄Ż3"d^'3Ȍ%)QTWj}i #iˁC(}v_=OS[䚘cBrqoό3h=ѷӲv_'%Jg~Ԫd+HvbO Ċz23$j!܏|ozOe="LBԈXf>ϣD3Ya}BKXNS!T,QҜИpa-r1EYz)v+۝gH(GsE!O\ < [f4ov{R}]Ùs'UE+x/ IsoU7XAmN"`:y$4L{ق@Ф*ߪ|kM%yXA=N { ͝^jCcb=> ^_>~сZcls |lkԔ,:D0 x;'-u',X3{XH'YT6ҬD0i>}VrU<l Pc8Ez. Pb]d6dzO5*6?_rEJא7˧?Eΐ}Xu~$Lr|2ǦL᡿ Õ y?h5|29~F*6N$|rYuJbʆcye+5OjIr>) ]03I-gfI6e^ P'Ln5(\,gW\ek#fbzoL ™fZIx۴ E;> l(=]bB-Cm40Zﵱz13F<PAd|K". &D-,e%UKơ:hkm_k<,W#қgꯡp$2)P\fP¤|gi|J!Ue=ղ; -& Vؙ̓Xt] ?STsӎ듯X'?~#|RXOo'H}z7}=M >ƣt{s.ćL%A᭛/h.WS*)W  [ g.yj=TľzC[O~Kj3;_s*F"\+_ 㾦_TO|4\v!.Aqע6zR^]K95 +?IQzlcFiNy`92$P)w\+ᄁP`WW=ϵ5vRcfMHEyT I+Rq*FLn_$s}daNvr,۩FGbST9>>SHкS[̢U%fv@wd\^* $C/ؠ!{iZݣeT%п^{7^rn2$1V' u3($zXxOJ#9 +CO>ȁl{6@,˾mBniN}H58u11(P*L7y"DN9O~$&7Sek*pvs.\a/+>d\SYa|. <1ޘ_*xK #GFm+=,X%Z:y$[>#|(~чoo==uoIΓt"Vdt/T%}G" h*1Zi!sV]VV5GL9 Bt9)Qj\U)0TKXfm<|ݓWLycTO ξJi^FٷbbziRv2{,2@f(<;׌뽀KPч6xyI胜iA;cqHCQPŷ 6 XsTmB}EtI^N KBGUaslqw jm:l2e%n^+_F Iaϥ_Jnmd7id9갓&Q+X]2O7cK: ;P2'N9 W hkD\D>b)D€s$ո5 RE[/qeB4 Kr=fk}tLKMdfSLK ;wW҃#ܟ5g55 "ćn1yS l ʵp-*hrCKSgzI9ȁmy2ޢ䟓hC`EǢcPT_Gh<WSf/쉩 CBb>瞽KT@U jz3F5sFX) DPsgn'هc")E"ݑjN6EBJܻpjP4D>ޡpp1}ڧԫΝ9yBap5W-gi~Aq,+3d >o?-n-$Ј8x!=`->s BrsFktcgu`s> U. F".M_cZո\﹨&P b̈ ~rP;Hȕj8",`ufiAg'a>)Hhx Qp*zhʓU/nY{'JS#:2RuZ 5l$ tEk/u\dJd%X ASP#sb9[j ư/Xla,m1Wr5/C J[K| _m5|"cz*KNzz MNб^Km3A ju4 bԱmI\&hf5w&?T*:܇"F\M(Hυjdh*׮9(,ך5Հ@~DsIZ`/9؃Ώ/Nqђ VBޱ{Ba 4yEt7Qz^sk)V}j,'ȋrtnz0eb'/B /V;HQ>-US.ͺ ){QvW3R?qq/1.bۊCCHΗ^} tbev̭z% eHG,Vt5Dm%KO%0ZʷHb\y(Qm~y]o `9rK,=e+sߞTdʓS572/wx 20 @Vnٓ؞moy n*}og:=Un3t`&T{|=ƒHG~..Ffh"H>3.)`9r܏]9 = ,MLql3㒞ya9ŅM6im@ݞt44n$3jА:K";ʿ{g7#h 5BEk !B4Tf&kDIsC 1ZB#P[Lzc8 eA4Ud$'*fvت,LR)=BZ1&#BGV 5WI?/ndP ne-Y*7RK?-G#TeEdQvrRMm|"DApK,=E8 YmA[]J,s\Ib蕢Bg4D$4&kŧ<x6(,~hlesK+9"^]1:_nL+%EaZ6_u Ra W%W^w 4D`9%!QyG*B%B٦£ e%wȸ){+}K|apl"Dp ?!bPѓduri:{C5K;Z?Ź>Y&`z{9 ^oZL< 7oIHjљubH@ә0]^e#zrgQ尴\t2ƈ3B1|* Ez'.dlžű+nth|㠶\7MƷrUj$Z mQħ^$Ybv'`=vk 3d[In\µ9\p8)eV0LIZ~g$b-f46|~7;R9nB=7~T߃lި?_~DY3caiaֱC}~PTµui!x-Tt4 o ?Ё5KiJ,vWݧm"B20QS<ё 7 *i 6Y+ہ'>"AV~ug[uOk9m}JS1yn}4]yM:uw2@ g(w$'Qf`TD+ xĞ{XRf3֩~LЬUr!̇hTH Cp`RQZG!jOvjdz CLwXր,,9~I)Bdb(&Mv2I1>X(~so^Y @cl~y1\A fW?ž2) |M8P mM_j{"u1UˎG]BMa 䚵GxxU :C3Aԭ\x9򶛞5W #Sѩs$]q [°j1~.-B~`j0aHWOGIjԵ,#ӻWثcs4r!IVGV F7>tf z; $öp! Uy= 4F @tA01TXP! >Iu;(62zkր-,;K{tH3<"x:& 1<Ֆ!>WGmL\$ ˜rDVh]rkϑ}xԎ\C8KQ$8GoyD);MHħlA4YP$V8"%)AfH@*.u3BZ1m{͈Xʪx fҖ˨?zWF rCNz?V 3xlDp<{G!| Ɏ1JdOWNL7U0ZNoe{wG͢M1nG|t,8F*3lK{Q;ĭ32+ڥ JC븽AL&vmS`8ٱJ cXjf~OSl:D#tEl aBs 569YO7;ͬj~EJ|4I/1bev|=ְl _ =Uᮌ(NFhڮok?#wr2~ Q:5 Z%Wk9]si1`V3xnF#.1[7i "Fӽ|_jَM#xlGL .LP7LQkʬ{$+#r'pj IM?VAўQ _wn NX[qg(XnsA՟7M y7SMYZ?8J8$Ifa5Jt]AY2C/ڀV?;g<K,Ux_*| 4Jx֋v6[p /s8Z`#tžT_zr͌[{̟ŕL͛{Gi}tbYIa n?L%y 5%r4;%6*ڋϐ,y@Cu+W%V*C'OzO$>PH^TaYp{ٷ$+\׎gu4ʣ #L xg.}@yu2qܥQN%#5)̐A wiuS[[>F~7ٛb.6ڷ:tnЬǼ긵nF~3ZW9Ss2/>lg9On M#T>wa+.l@-+dVߋHD JA)C/'⸮# %` VSi"b}6dـ kѡXyl ygխ/PXP毮Pg[.5hދsHy0ҖZM툃s;6%@+y,ȶ}I$d fBv};JƔ`elٔ 0gTUsƪ ?EdXlsD>`'NԂm=Zɏ/#S6?Hԥz{-jq)ɹaY1sb.9s$QmȳspCvҰ'ȌMJYVl?0::p1޺{Co+a =4I8&\qB|w3©2Pn'E~dćw4` E*cdljY`DU~TZc kcK =ǛGч(ZB5J^8QtšȤ!5Mm灜v >NCOHap\Uyv E6',itj#)}1Xuė:8R|!im?>M 8vg(7>$ڔ-靑™)BZ3O{NcH&ֲ Jhhѱ:fk3}{8HD`d`,O:{rm+Сl@3JQx<k5=ay/I)k8>9^= uEmOG)'̼+kdk!+P]t!n64">% ϸ;!鞂.­P%y3:tUOuthqy?v.vWa8#%6 1j`vgXWJDUvTc_e/C LS<]UaYM/? TՑs1FvH؝T~YTw9ه$A*pgDyI R5,%z^CkyYa:^9E󘽺E4{&&ȽЇ5&rVN~ۈa` 1Rţ _?mZ8 -C/s`6VY?{we^0 )᧪]n7og`=ԶK(@,T$Q4#CByHuM<;[[ޥiM&Sw0EQ\q.C%ۗ݅^)ɃxKGL܏⺞22.> D4=zoC w<*8R/uO:{r<'HM dniQPGYxb{^'irR_6ɂ&Ѻl.X]ygբE9w@ػƣIt8whLق_)!h6WL>]0dg;W䩘82zK2)(Q*j@ncyl<@Zz׈+-2&g#1ۏO5wFLأm@O*.'#{ķ{<>gf=_? iiHv]akԖ x'l-i={" 3A2Sg;}a%@6!E^µ\ UCZF` II, xk Jcq,mt{F'ǫ,q~dgm`L[+:etj ='ᑛ`%&?-Њ0 q[,lwHJ dhl`9S<WއonY FI*lؼ ՘ut+7&Nee 0ȣsKVQ8s˴&Ng&n Št"#!~w~Z`7w5.I0$#V#UD&?+ 9 :*& I!Cz-~`Fwiݵ,UwbAtJak1|AKB.nU?뽰gb(/Qу/'y <^6븡C/$o@,t:+yMQ3R`Bٽalm4ǹtoTt(ك6 x*%3U%6D݇ ^P &-=ixTq8HG|)q`A V|)ܽݴ*Z ވ^O`*ZR/뱓!-)y i H5[Z5p0&@~H5yl'F5Y zǮՔ7I jh4mzq|ǚ"”yEz(0`tc(#vo, Uy&zfb*)u *_? 5P&4fWx% ׎t39dIhVA/`wLF&;$je0:p> GN SN"5Q#6LT4)%~cW =׾44(K|"rQqqS>!3Vw{" kJzlԦ2߬nW'Y@rn=|Mm*A_U3lͿnT1z$?Tpv׶ /ay2Pn(U|,)D`p3P/`OzYQCtȿt y %/.U>r6SL@\ہm }졬NON'Ul7؅ jDfPFzySi;. z/>ê? J$*r21,Ƽआ0L.h]AWżpBTȆaJ#> {kNj5iJmsQSl|쟋n#;? }AD) :9uݳ-&tfpk'T=^ ^JJ84*GRvi s5$P<{pȐウ*x7AtU!r1^D\x>e2/>}z?ps┙˞-]/Fy)"F1C5TYJqCNS yHC qkHeE kYz^ͻzjcG ? ]%H|Ce4 ۋNp#J7`D-"Y4נ= 7-+Dh$E:VNw|5 T'#9Y'?[e$1F h # x  iO|0J 2q`6JTzPlʝ&8>зs̱;z%VcwWU܅K%U=#}yMh 6`:Bvi>4\Wfԇ{i h>gN[Xϖ2虜ضtSdL@+!# _fB;V>w|tT/"sBD4nv0R),mzMm܃te&^U >=5[; pu8a鍮-ʴeI(W \| I0"2~Wж2ʸYQ-Nso<1EJ]#Kg˜Jκ>K#@xp[вqnCn , jx yR4Rry}X`aH㤊E/?Kjj ]yodY΢=#ŘB10E3&!恰 ]Il+'wǗlI?lH3"|0*"/83:1 zl|Xy:3Y$ ]$GCCH^ࣂP.ThL%AG-GIOQym{6=:_́ZvTu#tKH~cDwJB"L߷7ݞv[!~֖|t`._*Φq k X]=T2e$p3DvD|«[S#J"s$ޘgIbU0_=-hFD@(Qtǚ%8u_--=Ƕ$8ݏn #Oĺfd _/s҆ʺD2|$.0ג#CՆ'0|#N*wAa,KL\ +V fkl/r]*ƨJ줢l>Z+H=Zw攽D^ʿc,FP.KymUNtM}S-o\uĮ73v_Mk<aM+_r6' Vzo<`_ϵvSrC7";C-7Dh`KX89莶F0J`֣gFB:':*;,Q,Lʚ_–x $v2̇~!]Ͳ4Af܎J}'# ]BK]] bDq)) :C0$Fac8&=u=':ohޣ,hZ0OCNr6W:-fi)Eti 1@(1q0fWq0&ck91 E Nv?HΓ9u;_.+Ińs@f XnϢKM6#nZ:F1o>w~a`vxqLp_ YWJCD lgb|awiAÚOQ a uaVWf,5 E/S+RXYc (,eHc]?)g`q&SE ?,EӥPzx}C.%ͮ{"xPDxSm5;S93RGҘWaߞUЬ#ЃXVn9AJSKGZ/a .WY y MsJg@d+SΰS-=7@IHW<K?af~]#m[nz|l:zjlS4 CNWǛ`8y)/EC=`&)- (1ʛg5RxWobeusW/ŜYGbLh< KL "g+ybrP\ϥuYi=%P,qJ@H1eig[] o!Xp<~cKӲ,#TFXUtX~r,,F؊sodx ` CTAL>_< Эh+b&{"j n->;ncU`|j̖5\IL"ٵr78M0v/w'_@:`_Teo9K#EYӤmmQlծ!y]Aw?5i8 𑱴 NKsLqN I}8Q}ߌvXl/ WsUizo@<~'&ɜvþEoIx*?3'.l .x1c0br$NSF\-fsXQe쳈w 2e?[T7@fy`Sfv~۝џ! MBF i_zEPZV)bKPwhd?TVe,, {gx4|zgGhrzϝpAz  IMNy4 ̧0ShʢL e dҹTO Yr8:!pZyNRc5fI͸%ހRp-)wW i9(צkiK/4iP"s N0Rd"7MjH2E] d7{u.EY,^pohk189Ԣ3 T7;MpAwug?%.ۜLR Oך_[Z?#ce1Ȑ: zF8 '1$̻UIHeoYlso0*OIS<2jvĢExކs LJ#0cQ) X3*Ťf\cFB:,v[\5w@ w߈Wxd{z!$iP4hfBС3iʕsz=Q1RP1DcK4Huop/F͎é6Ga"J~g?Q>f\\mtĠr dP0kb5^1Մ[i|N,'r+T}.s +3NQNxl\@7 J;%[.fs#S|=z;DaױY" nl (;)`!=p~W}f Q,mSXΖ$,.ڇ!uȟȗd nGht:tzq[5\(gTE2" C&pd9fky@?8±VbUG8:f8ٟEʢd{Y1iR=ސu0@5|[O 8ً?e jkNհa̫'Či8&4kЧ".V+hn@E|*8#{ӜYю?ջV⪔jFVhk~ĢPQE>w>ˠKhϋ^s%_z]kºʊEJCx$5T ̶&%!Z8 _iCs<$UKn,za\I ˸cE1L[IG򢃀vEZFAWnɨzYHr$3pЋb"O(򛄘&lxOq)"4I N@i'"ǵD6Yap|sLjb>EMZ5iޗ!bIKJ$F[X < Pz2`h`)NfJQbJO&ik+3wxA3%}Y/)s8(Ҋ h x>b ܌$q"SÆ'&@iC&[$v ;y} a#G,EJEh v׳z Fl䎝gFEWOA|g} h]% yk 3> zïL*&.r't%Aq pPXXn=<-t4b2K<1SQ9OixSE ACM.$,>uAz_"&셆3l[Db`HvPnbHE$+ɮ-OSQ=u̩l+*r' tWpٹ}=پ/vKKwP|3 ;Af˗A8Y V/IV Q3P`0`OͺZc9^% $⊫Oowi/}3DeBmFS >!lT~ᙁߜ.Kr>mYF?d&FF. wsU HӃ dW>o飌ZY6p 8\a TW6@Ov].2񒪕v&d?s w/h-_WoW$`. z%-(<=Zt`(b<M2:Dѣ/ q{P+8n?6<AĽ%N56e>z\fHlkO5t~lVׇ֬@Wi}DJI|4kꦹT;9 -gCe3ǽIN~Y$Gu# "=j\dì-4}>Vր5uX M˕]G?.q턱kܢ2 w>H9+[ ͹:+>  ?ʨkC$Y2WGD<Җ^od)#BD{. biJ|X,M`|<;fiE 1rz5 3usΑ\)Fa}@2IeZ8!daYx{eb@T)ӀֱEN.Hz1]1F .<$e=(P&'4dY2!,( ~pP?Fڜ$} Sx;AAJ6}C|Vߪ,Yk)!@tBFaC_"fd- 3bdI^(9 #'gziYiQ].S_l mKK]ퟤ*jAazΊa9!i@aw|ZFUV8_y 4ƴ M+iA#]0-n;CJP=TtEF4/8wF1j_ *g!k} >w.-YyN9DD%cuBmsd,[$CnHsb1xe'.PI U<|c#^uO7g4iLek4G#/3g5Me]+WFu}n2gFUUϫ6YSF ҽsgbRcpPq(_+b?@w¹F78:#f ^ 4c.'p=w)!s3ɨ$+H90?DPA4  }PiÐ6Oǡ/ L4(C*\)Ł[{u%0p+BⒸݭ7hHQ=貱x bDZ,pKNT{[EG ݯn^ҲCm0pIyꇇoH eys%ԙ+.5Ӥ^?~g}*ƪ5JC.Rke= "'+{y~'ԞѾ=T9*uSw;L‡IXF279w{NrvWV/KJH0N FE la7㸯c*JW&΋S%4@ -\S"ΌOh+e?Bj'.zt}=0~gX?xDzjv6ݱ*ݖeiO]aC1 eg1)!U5K'D$xdWgлCYA K+i +m=BXu &9"O%. %oJ͓v+PL%bn+㶳ҧ\ 38z+~,#}*#F)X6@3ܶiw 1LJ /#+e/g\;]ֳheZVTbdRٟ((ޠĠm`}Aj+OC`xdѡ`od|7n*8n,yNd_֗W\ ‭])Bdp+TF &:Ar'I8"V8fHӽ*K:eEaN*T5'r[G7''56} ]μnh"{<xHIA b|DwB`C`C`ov PY5L|ki4'5*0L58) --x 4+ )dBHpkr+K^>G4vlB;ݎŴbA<OUHX ? 1U oKpվx|KbC n. Pt 2 Ź{{\'1:#0--J4 rkk~mPei\N#y{)= wC-Gw"EoMV7BI5zS+ۧ*(魞n3OT}="&+AW<6x-P}`8n\eDzD9B{#k +2UShBܬL#rv1dwne$?29 6Im屭)04!E'D7c5ʿFmɨ5ml܇E. P{{ O٧. ڱ!0aS.KH8/4I*_rh'uppƲ,j]^r+4yhUB~yy,g:'ZH@W) !VsKȢY1E$Z@+% 7-ЃJXnnrӵїzlc/Kb96pkʌԚZ OE/7Omg"/bc[Ol\/<2A̋u0PU,붊2S3P(Jd>a\t-u3.4*pugNQ&יmol_X]V-;[pMcw7d!VQ8BLf?zgĠ<*:V!Leeak!P̪E%40"0W^N11V TN#I7$Cqs |?qËpaf_Boj.*IM%AFgւ>eA_+ma [pQ#qk1WYT}2UsN6~,I"̍_{P`d-i(̱Wny)g t;Q#b CELu4{_;tb'-7G҅9Pm0Xϳdz6_-#l%VYyrm$C% ΌQ YT2 PVSAӦV3͑ss|?GVƨ k?sL͹tvjd}a浹f"8a"u)+d Z49dHt#pw?gu}?AD= ,n}Dlep-đs(wCdQҢ#>$p;,ha;+򲶠48/==JNdg3?h~7[gLD5lUI ɃR?6AGiH%_۹;;DkIBH b0n_HYX(Oh3[S1LɚW Y-x3w ^5 fUnY͋oAkm+$lW('-̩'C-~1^ x/e^mLH7F+c;@[p⻧S颈-A/WTDּYE)V|TLy/sGazu@cV9hO#F!W;ނNWX@,Ctn"$L9͊;K%df 6gt$[Ѷ9E\Q=?=j'pUGcV@P]]kT/Nh6noS+ޏSXZhPb"7fO.Nz| %Gnh`J<T yJBOffzvo l WUfǙ!R)\{B_z^ĻNU2u =WХM ˩u5a#KRs%#xO煨ݺVpun!7 oAQAAOJ fM`5зi=^a}ju8gp%6(,.o%{2V34#Mű 8a hFwBX,M/ ø;]M%l &acI_e3Stb`SHDYCl[cf@Cna5zr OJ7R&&EV9JA(ԥ&FMp#KcvCFg>njPpc]>yb쓻 ۿtE7nr3M_24ѳ}QVFy ^&q5gTC^mh'A۹:οe:g}!XqC+0?AW_8pt;-= %(Eg̛DG_A<QQ)8&-\%?֊u86]YXsi5SôHpr]{ekl>E]/@q^F~os#VtFYl}y5(˺4NQu",JI 8Nq%⒟2Sʚ0O*`wJ At޾I]fY1:^~FN% 4VDyF\7lW~1m|FR`XYd5@2ċybH =_djtF| ~$2.\v %!ڜz`IӾ1_oeueJb|$`iVֆF[fNq$tW g~>'NIFC@z 7;,eyizUN2Abfz&bԖV,%:>aU[)[F64إ^Od,j;/*i. Z\eQz>tX'iOWt9 LYA\N~%br~xZ7M-T ԰Q#G¬hĄSOT#JnYNުY^AJ"['QhvzȋCH@w,(9wۓ;>4 *Ÿ+V+t5y 30OȯHb FF Es$zo{Z^6Xf&PbSAʡI3yQ]8! AۂE*ByN 'ů IJ0!?rSJYbph^Vmt*Ύ@\Tpu*TR֫cf >kNGo2˜jrwt:p6gv /q5B_2S [\W[3j,W%?*@;7#f3 jqѮFLl9i}ÑD hŚH6b,+<YR 6ꜯxcyN}97Yw"^@!˙CgreT$ @#ʥrz `ϙHIJz_--I5Q؀e ɿWϞsLحAhA75q>q8WMg>V Xϰc7yIPPK&LNqGUK shNVE.LOOĨËIT]r+&Py.-E 1'gk;?s4Xbր͍zSdsVNOl" JIDU;괏oiU-n z\Uu5ǤJoa!(^4J ߇LӑU1mV~['`U#o̓ʞ)=a:-P=?7Nؓ՘xo^'!+ji&JWmd5ozՓ? V X]WYىLs+y՗=%=du(}L\R'&LV{h1Jb&@_gV+!T-%֣mpHLfa@9wLu!T9tK7֤@UZĻ:A wُ%5a$g+y-%/dx#[UKLTpd9m|!j. k(fZ5rN1)s7F31.j.FI6BnC?D)_ LCzvET߬Σ,r;ѓa |/֍Xh ~r0EC ň@ppχzٛ#XۙlO4F˗SVz=U~!:&x|Gz~Η?ax8ZZJ% kպJ8}B $an󤮺PWWX ]6؇vhe$;%2 '38z눧gm]h!M^#39J%} Fx(n5#t0m*S'>4ydIQ 1UH$kgQ#[`S5e?8 FfN ]3ؔ(KN'ƼncFD>mlLbёKo\EvQ/+5N自X^߭\?iLff⚫(QzK}9C!M&zݹx847}##ӷ 'Uk˃Q!PGqҩV|f?VJ1PӍۈmP1ʌ y.EdžQ3'bLooPc::t uuasH}g{&kfP 2 cNk\nrΨnmJϋ$f{q~YOMԷskҹ~sp{-_%Iiti@,2-*)}&  ~Kj~ف^y@Z-7 ^͂˺9״.M-7r ͑Ñ`YDٺ"K>T@ESpIP@&5^Hc޼#z <%js_#X>.&bѐx!e#PHG/^}j5 wM.w`9F쭲jH egiY s¯+񧡁2XˉlM }帎o\\MQ,*d 0:@EHnM&rdTZap@%\[ʡ!Zh"QaIamJ*'>a=Ssu|g8QG7Njˢȵ(OSGIAƗcB":r} W`rێL5VrSphAκ}o,DZ%M爪s&VMF?3ζfBa =^6•;]bYl$_e0FPpЩފ! DWR% %,9uc8V0`9~'l@K-0'Wr@_ U:hN"s Pg,NH"$J##T[?]4jt`?-b'J }th>}b(1 hN \~;J X:khtĝA /_.+(v7,퓜"{)>]ľERsοWscIR'$]q]M;|QR(=AY|Z`g)xj>r*Vu@pɗ:zHrA~иB6N!:ml f!Q"4 ^mIVa ֪Y(N,#٣71ʦEbʨR zY= ɣsΗ2SyjIbRX}ň@x5k#zmztNdztGu&S0:LjGCQ!I9-{2mݨS 4纅ދ9j{" :@y-QyL%e ڞ:gըr4?3.}燼Y/1h?uUy4s[(cԹ@@dCI;! \[+DO; .cr" "яVCVd4\nwXrv /F*p&{ISDaj+7 @/wŰ6{Fؐ>R0S۳O<9UaDyl2*e+k1 d6 icɗ1#ړ06|4TXީ, Nk FWv?tyqI q\mydWInK ]gs쉯?d01Xdvr0M%VY~E`D?b \)Y%d?{nW{?N*ml2鼜b:ߙy}HGѹYoA lWw0T@&5mr!}1P'jSp5'-2 RY#*u )9[oЉR?!d%J+{SL.Q*AOSwPGq&HfD ߉Wcǟ+[FAD߼ UQv7-.E&҈ 'Гٰ*4Rj.-)4AŶ+>5 !\QX:닲\|c5ZQ3#TL+QcCv̄Q' Y¿ &xwZØwm4|p(4|Om  AhFi +p8#d~H7l$I uep0claO4FEј0_kVݫ*SrGDA*W. zߡFB@$r}^t zNP(%HHxe2ln ħ*u3VW6Y6RRl)}gI_hE"ԐXo4p#kmч=tO (Gj2غ\,אYHڈqi}yا19Iz[HA7XRiHg[۝hσ婊qm/8m-Y.0Ld+kUy&݅Zem4|&$Q:GLHpDe:jL&ގTAWl4 %S'tRZoJQ=2},P5T˪gGn iwkXGvQOٟͽCEf;*yuKf7g{ ͓X$}&N`BCF+N5%.LD '@ZNΩo:H9iT=:k,IJ5PRԙ ]b򁸈o+#6nCB7 pc<3%jkIneQt)զS2IMoO_e)kkrǂXu*Q i!x,6%ұ,9=0RVk]Os]$*0'×}V Ci4ph9Γ.//Kv ^;~( .L!HVAS{iQop2b4pD)yUޓ>v!l"w2U.})UV)`Aݭd.s'1 Wi'v:3\&@%bro_ی[eүlQp3uÓ¼:p%,2k|HHВEP; 9QLLW%21iA?0[BCh ?\4Ʋ{/PJSۧM%LY;aւМ!p <-{ >iZ3~6ہU旙3#FMxʇ`d[[225~`9ٻ ʹGaG4 R>ؒ޺\8cE(C BxDUTEMJ:&3E 〺;bӮtRlK9933?^* S^^SmT|`WJQ͘$f$y,2 cDifFިz 7ZkX S$9U$℥˭|a M*:k<fl^hQ<}`d S7 :L]_a#9{BL2;F. @}Rl\>J@e-Yj~WЃ\Oyc 3" ɔB2Cݺ[7c䤶b:A(/2l7CYoȚy !;oX xN4A"A2E<  A&HB!62lWtO8 PgBp3NSW'<C.6d/&IY Kyc+ŚǬv/g)%p]OހL05i5"@LsXƣ~EDl{.C +j.R"( yk`˱7f<8Ock@F|; rq4<^EЃF'~`{T5d)c "klF%E 5isM6a{@֥hS \]{hA*^^f(l:)']5u]h~PFcc@5!hgm0kl- WI}Ŗq46рvI`Dkm7zpK_WFm4+#QH_bC0j1a~7jD^$+< pk&Ѫ1Ű?/ÖRʟ.bJv>Q ?ycז9Κ$Aq9px,$VBu\ǒKJdM\&Uf@ڈ*J}@g%K;Q<3$?c:'\ |fj:O 0[d=מٖ֜T& =+BNX%>?NOzTP!xFr|47 ASY%i ChYgrHP7uI[E?4pTnJBspi\!9eY5&p+?l,m-N)w5`5U{{{ 5stnx"p5Uc_4u2uˍM\I5OuբJQc򵱅Xd,EUAs>bDəHgDNqE3tE j ZY[4hpW T*?3ķfe%)&ial]5:V,n`L|2 )t 76j 4X2l\S}$b~LJVq5v2=A1BlTͨ6ّ zv$b֝ 5L+wyC-5ZDn&e"m\ıw@8+uDH#5y/DIcX`sU~)52c`ħF@/jfy ^лw{]㙹DUN2ԭ(ܥE4zXŔ-Mi=,< vUDMuGnPoOL:>PYIagXw4 (0qPh>ps?S&5zcpwJH.~t4t񪌚Z }nW ~g0Fm7*f2Hs kp)b>%`Y_8\CaR` w]#<#'Jg=u Mv+~K*Ԁt,=Tɚ)HtJED~|Yv"vJ|Ko&ޑ jGh/cq1gn=ԹT[5BjcGZu2;²濒 g45;nx%Vyv$0OWP̺ySƙdNOXŰXgx-@Zq2}T.L'?ΩȾΪ:zw a~;$jT/yM!Ìk*1ʾX R2ǎnw?etn#R~ G/J o_ d"mU995eࠝ܉he_H Y|Z(r>Λq;V_4 tK&zbl+v,TXOjgg1yf(%b-LElthXӨlR;j{gLo=Y{Q͐<"@>n49J!G+"X q/2eɏ $Yf ԸlUD/jUwg*׊9/wè(y2: taALnvp.ƲAƑ{oԑ*לOםjU )U4ZIϝN4u"gO$I/XLպ6Wx j|yR .acL2p\n5Ձ' _Z,g;aj<y@9ǯlIB0abii¤GlQ$X*ᢏLjfRwe:忚c!I܌ʨb1"(\kb؂tЫj7M/`ޖl3Hx&#0K7% [:V'5Z"w9%gE7[-Rqc$hBκ@\ږNyh±LSE"(% xb^ÝuGtWSL|.}F:×eWR[zև/<{|Q`A{߆oꅄ1(u!1֊4E2^A^(+;wc9U۾E/H5t.NϫAD =l7S3MNeUβ.kQ|{ Ᏸ7w7eGs\_> $ "Q5y25t˿kH}C69.ɜM1L܅S~c(4 ^vUo1jAt\ I>h落2 J y[Wj.%̹ڨ3Q:}pJڒTA׈=Z7s%!yH[~>87i>x%:?.ˆN5+@ڴ\o\ĥ߽$/uKTaX[)0GG%)Oy o=yd~YaV+WUGk< rXKzp$˩HU>چIDnުX2Z[bu;a (74ܴ#L{ ,şWeXyal{d"l^dAʌkarz`sF!{z2dr"8 JlAfAKEuVۖzk(w!]2Kgg48Ii9g.gRw@4h;(CRJT_u:gAQk"Ma-1fוdX (Ş ZqԊTj[מ>1# %*̋K:ѿ27TA /+dbS38ػ!SRdL=?'%`y;q:cmwsT`p,/ɿjր++U${hQ>|πndyASU)OR\O-괤 zJ a,*ȇeTP9"y*?ӹH|cOJHJ̗2ùUy#Q'3WfOUsCylǃ} B=ī;lt^SRD#kS^81Ї]RSˊ\btKHV ܤũ{!αBٔ]B iE*s#ZtGnB Y*l,H&ʜzF=7xEOz.Uc?Ht(cdvAQW֔i̪! p"Ǎv~\e#TE ZKZfgigYyN{]m?L: ӵ=C3uGepUkD|hIIѷǖ 4ҰZ,oৗ?c)c^of˶͞˹$n»KnO>PlOi\[E:$0(a%HQ "io*g NB E!#JF^vቺxNLg$-WXt_$AݶFZ1w!NcwpaTTfe}*3 5?rMʚ hZB_{cR)k (qEťTXCexekܛYI1]V-}dk09\3C**,nWoAF'xl>wb';)RCq;ִe1+`$s/@S<$)uD#2sB$:"WgǙI^KJcDĥ]m\YKt)pVm3."s< ^Ιkӓ:o"80kmlzAt+MNt89 ! H O 8ےNz |XmQ?I Jt@>^KV5}K:y6ޒ&kPy sP7kB RI25|סMG-*b+H,;SUOB. 1yccnDaZnmGmOwVWqh inhE4@m8Itm ! H <20kg[QcBIM,LdSr㨦 8`5Zh5hZ!CkZHP]h9x='lv¨qaھB6uR &Hǒ(:Bq*RoCyUXUj:u!{A{LaHy9*lrpjlo&kBsAEKh1u'?2hO옇Ǜ.3ɴD2A@Ϋt8"_.T4T [W[Lʅ SA⮇IgTpv7='>$K '*9j um<]ta"r#5p*{GeQo@ F }ASۇ[t'ڛYs]ArDoM\qS!VxÞ_^wTcCbF ^[+d`4^,14҄Ezo{J%6RvTlJٺZ!gyNI#A7Coܖk| Mxk'$XU ؃.r?e۹Mq:^<8 &풐Y](QI%1nSKT?zʫbex=%]+KŽMĄChzI1›,NL˖LQ9Kگ|qZek"&? b1~RII,2/~i]ԫt|:4_ EbBINgmg?OHs@ p71eOm@5᤟Y2X&u;=zC\~hi@Du *S|sFJXy='3[hj'u; htɭ=M{ & n8K=~ Y3P 쬻Q\ =)|~8hG uV)H8(aoHc=wF1\nAM j\<ҩRx!,#[*CpїѿslzÕu mUpQ>Rı<}85n/`^io ˝J Q 50l Ƨq;#wqya+qejo5R^X+Bﰐh)Z¤dΰ`~%e4]3B6Vr /Xԁɭ^<RpmRcӻFN[?6BW0n[]bj&o O:$ncpbP@J=F鑛^r&q%ǖ~WP8;6P772 li+ uvp$iq i+yp X5|Zn?N`s ɴ7"5Zx ?_`H\6CI4O@CߔĩdMZo)AAi^O 7Թ 1Xsy[F_au#.0ɺ5b%Wki !čTkM/}$kG$ fd8UrmG" y2T/""h Xh L3lfu_yUmmJC 3T`A R,D*V Rb yC?-pEЃ6 :aQ#8ǯ.WgT,DV@}My&E-wk8}-]Jؒx416$5aXgI87xt_/n9v񖎌nq08|n( J@~ʂ 8 }qT89DvZ/!$3$8ʨD3n,GO:|5tCMR3Rܢ#Ӯi@ $3 kAgif+I_MY"^SK~ £8{g >WZBɟӧ$Zgh0D&U)-1xs$ aekl)lܲy(Q|777!Z#:H6@}d`,augC.= ʴ^ė B d() nOƪ[ SO֯n كRqc!0ōx*iK#vqi1a! [$LDavZnDd3wjx7plC<³z"䊰uHP6L,+o)oa #FpߠAr~?}43be8 AԢNʕz{טn=W:Yˠ Ȁ"QUq3j /bo f-{h9V͈/AZ5ŅQ?MI+N=5X2rksוe.1YT9f -|VbU~&1ːekۮKdBy50 a]i|+$/H0-l;LP"O{m8+;W笇(y #7V,?gƼjBG/JmM~;ZSŠ|i!\<۱-%o)wឩM4L8̹>@hfa#Ё]A!8륀O+Ϡ}v76ݢj:d$zq&3cfx+ 3&nU-cpP9h5X=vO ҟ-WP3S,;)ntd;3[B;_EEoTw9Wȅ6\Z=,t [Uyp}9v BH:5eV3f)1-'.Y>+M*:ttڢQd$`?-ZrSKZ"*^9P'0,'£7 u{{>o3HC͝ܪDAmFZ`u[22ɜ2v/R^̆(E(ܿ'6pُ#:;-liZêtv켁Wn,;1teoNG .1vϒ}\[fjP"@V35݃lh@B4c{^M3ǖo>"!g԰L~`Œn;ICa'+?+,ML/j򕎿&Kr rk1.V⿆Pjx83V'HjQs;˛Z<o>pyZgto1_Mfj ܰgU5@7Et .|H'4q1KdHwװ. ؤf/rpG/2[~ ڠkNO^*/kDjd@TdVl|= !OlvYCK k:Zy v'y_ va,%e$xn[Z"dmψ͙+cfUCW. r>E _Ku:n'O7\& [!Iupւ.!TYBj.6x,jCR<`ɋyh L@jڐZ'_3K:^! 0j EKavz(sGUpyr4N$j2yk/RI"m {s:t3г=:<½b3s{++Ța芑]6:`?)׺Y(#8JT|".P4 )r@Ո{t C3 \K]fox r'v2=̓3a emI9b6i^ߨI.Qd.HI<*,8 GOﵘ]rRƈq V9zC x&oE02=t2\0a0U΋Le+%3bZRtߝ}V9=Ow% qROҬhA /=HI#hio"VL^1S$t/\C;ox~ Ӧ9=WUq3o2~"nܗ]<ޟSRج'V#R-S JQ%K>Gk,-5\p |/Gߎ/Z}`Ma̸U@Q+#6M$M冗'ړ.24ͿHYӃY~i'q(D=hRv8x1*)8J~q-`d}ZaXi}6syĎp]Pf3Hx 8?\)ϓYKZef)7DA7՘>~.x]2 _ʻKr#ވ5)4A}ʕλj$3T<=kŽ˔/XxnY &32ERHɓC|@{ $9J(̝&Z2\%\~Kx֊CE^@Ƭ_ɿ Vw;6uY\ %anG8-4  N Pvꕡx m;Ƨw@ QCo@ZU{ cyEh5 g.7Zw(V!@(5\-fjo81)L񜰞iƣr:aF\9!h؟ՁJ{iqL|+M2~J5f8`JE3NAFߍ!96}M%'5ɿiB#_~COO6Ωv%;YʍZx>Mm;dB'o$7<:!vPLs {$T/ 6D*[ÆV~؊3Z9r?=fl+mar+l*l9"RC, xo}nP*^s^ 3ӥ;jJă )pX(85;U4T7W=ܐ?7 Y@ \ɶ"Ϳo uy UiQ\qVXM)6LA*$e:j%o+޸)q1|)cqוD1W~zNPE/LqUf4ʲ ۍy¿ԐiUSJdEg3S9p+6ҎޭGכҴPNrz%JYPRPi;,?e c_oiB  k[< ?%V2 +]V /ؙYoizpEIH!hN6c]f-x/_eJ-Y4 jNW0Z2;FV 1=B@ w* ztz0bT<Ra\fPs짔Tu 3yli]j~9uoUh>hU9:`$aa~: $4WF_ead*KpjM-@=XېcɲӯbNG<^w~=\CJZ~XYcyQ4Z̤GcS(߭fO }KCdkH|)TW& b"۲{U<%OGǶlm[-r$&J`h8 3[2.Ɂ%&O|l}YG{`G+-c*w=G`.'eNFpg/q/qlO2gsT4I i;!ʫY>Ps5mKn3nXdUVVH܋aiV dܕOVd}lF}8փZn.67Ҹ#e&!M=Mp cK݊d2!w`j\"w_iڹ|^ΜͲƅ,jI4?=%񮼠",ATٚ$Y=Kٺcoɪy  A{p %M`4[iʣU8_M(weB+pFL>L^ \ Sm畷ieۂ3Ɇ "H kVבMO漜_bx/?ƜB< Mj̙WJtCF1Ŭʯ۫,u{$GAv FރnH@zL9W\dϮS!z 3%g]8:Ӊ|eQ ߰_΅=iݑyPb]1a/߽3h.XVy!3y2Љ~쪶u DuBa1=r^ܫv2B^ؒՅZ|):わ-G#ڞ Ż -fq;Gg]=ЬZ% CG_ s@RB"M1ϡt-}f}F*$u#VGFx:6-29ܝ_Sf{R0єwBg &Ǎ$ [C9]{xhIXv zuKw˲xl:^N%tc6v%AiSV(os #cWY Gr`>ʥ^n[FN<}&^19qnɛyfЯn5g?|yi m&vy!ŝlA Ae'fldP^`1v8 ^\.ҾJ[Pw}IIK)ZIypHyJC\6SI+/Y(Is e/E  g3s:CI C3{keFeC9 ?7d=bsvF/sDxH&Gk^Xɏd_LN?#BVa!֎DBoV91S&3vfrVs4@ lr7~߸E2:L#c>Рwuou҉7Vd_A7cO+- 1 Ux0U&8&Ls͠jvLoQ>̗x%{6~G'϶ g#Զ:22 cTo0r VhRlexa"FI#p 86-Z갆]~0[Zt7 ;zwm5;mqt3G m<t2I.eZHV tB֓PfC惦6;T3z<|gB-b{q"R*a#1HXc )ZڛF3i7 !Kv1m n==`0O."mڞ9Z(sν_eK6(9 ZMޝ;>e7#4^RjOY;Gc>:37"p@;0MǍkdK`lK ^ *|%poX+^a.7`tKd %Q+f.0~5/p70|k3x)HM{F"ifԜzs`nyw#Z|]ӹ0m`^3w 5]^@wAzhk=3y$U!"7ra3*lЀ}_ub8_Ȣ1;צNFikLkz[U<#(Yb,1m)G$Ƞ[o,D;5IO ?٤Ulz޶U߂/PJ@W&CPۥ,i~$74e角fi8^r&CLo k1LE=jc 'opլpI-4CDXJqǷ!Jزp_i X@)Z\O^/m(w6pVl^O6%Sh""}Lri43~đZ4fk-ݫYwV جvUEjO|> z3C9ReZ_(Up#5ʮEwSI.2y%N巖@I0ktWSO;XmW;>gUhռ ZwdOk> a,&̤(h[dLōx^-EORI> e N#翜G iv~r*;l lp u܋ٮ1%LhNe@,xk_A94:ikNynݽհ܉_b(6oЎ 㦰x;. @} WCUȀ^2T[Er,N{8!=!ĮLb{^].Q+ +ɝ$X` >*(*6B#+E']-׊ Q"U`KtRL%q.#|I&xP<%=dœܩ'Bh!!he&bJWo]g_ L#.DHfuܡPɠ,<2^05eGyq+{>yM@zJf5'v{QK" \N b\.S;%R-f4,'a?|XD1DaH7>p5\4_^ii(vޮqv}c-*O"DዝVIvEPPqم{Sζ%c>Z}YX+ ΰfƠ6s"">mbu!M&g?UUNw|G$3Z1* ҙBG_.OC/Wۤ[zǛ7Gl.b4l FlNϿ%(|Fp3n=oP{y0|!\4b'r_ddhDAQ *Epݟ>>Ɯ4 |Hr Dgëv􆳈~e6Qe$K &4];sNWz) + vG3"dFUzm_nڋ /QHwblyEq!)?XhO1w`߿xwg} JF]Bfa|Q$E(H܇="!v#j*(^m σ;K;IN|[};_aq'®}Re+RG Da kboype}ͿpCB|AV* YcWϨmw|^~۝1]"C7kiLuVED(d~>Ecqw>xOqO vR;މSA_E2)1>-r+1ָ9,R(/kH  j1shy]=Ϗ DMV'[+:7}/㓣obMCEDu|5XN["i\dzAŧ$"|}сq.QZrxJ]Rfdܴ:P3<= %z90A^ݡ Ҏ~FM K9U5[T뜟MH^(V>_5)}"VW; 0U\W8' 5* Rֻt#z|R<8`:,Z*dL1_0J/ 2JylP? c· 8^TR?򳅈 |*>P~)]!e pLǞ=ɮ rw̄{le8rx&yg7_=<Ybݪz%MA . 'Y4imkql[EX1^vfIMqfQܸ`3bd p O@H[5d!yj`ȱ]Ų2}U^P4Tn~0րze:~! cqD d#O35j!%swy:e^30Z eӃlZoP<}!$f/i~ԡ_XW@ҫuN~ , 3.(igBR*qRdNi^C'ji.Y MR cK773 ɸKMA~k_?_+ &ˑ.꬘Ȥ0Myl`~S#1焗Wn{r[9DY1orJyo)iV䣀BV]a&!͡Sh 4G4gCe.ZpMV:waf~AIhmtFp DÐȇqP}[+ο"+*gC$ʏHI)X k&rVD'3<1!roK%˜BdA A֤6sXZ7Lڰ+Ӽ-AO{"&%g,WMwQis| `gJi>|yUpeuRL2Z)?-,?M,a)_ØFTW"/v ^>ޗk.qBb[y{8nDwN9syoiccaO{)`ZE`bK iȶA9{u]%n|ڠ۾T6M <.X)49ȱ1cS|7>szemcip һjk=+[oe2ŃWI>iʦxC hq!Jk̦>S׽u0"a-: }1  V'׭#Zha < B L)g>RNY:6"z9zLtϽBf3Y}ttjlpM7.iLu ٞtCsw:|U#"W+qxX\%D#>ITEW ϳ؎l|!e3:-WY)_@!&"N0/|p G1$uB0,楱ۮ8ʞڄݟU`|իeL7p ~!-()>uYF px1pBh ~9BKI0ysGޠV$1%lڷ7+#P ?#*!9ϙh*9ŇUzE s$h| z]r5Q8ԇqNr_`EUU^P_ZЩ*41QYTʇ_xmExXܶ%k5Bex3S1qTB6h*j|?lUgԷ~F&.(Ɛ96'aB H6m ujLrg_aPإ&f=U]ˑ*a7Lpve\u84]. 42(k٢{ ".KΕ&YBG vp_6, \ixfՋ]L}缅MӉ0Rߊ7vT)!U ~Bx B P_v.3M5_[!n"L-$QaȘڣ;">3hriUn*/]cnbY=.e53.Pc/^w@G#EV敱Q0pdS G?86u"Zf-hF9U>+|ˑ"[k[Y|BƉ(p'׿ܨ>e=}@vɓ{z߮WS{I)~2B+^EOn@dg{I=o=MnPޕu~rrg4&Ӣld Pt4lLeJYOA/FĸJSt5N ;)JKdIS;yc#hV:3|B[1cUjF͝ A?K!5<:~Sfi u~{Vi`t4A_[,<( oAԜV^!rA\ O;'g^+{egdΰ`:1 \5/IIѼ 6>egEHfV_.g,y6gUZ28eI`ZI(-& ͚?<ĵ(%1:ɴ0DCpƼ7똝XO @_*JDC}28$*6EWƦnB:iI ?Ӣ;}J] a>sǫx8]:'w>YћbaW:Azjc]H@ ePr=?}1|^gH c`;SRt)O묞]:z7~v*U0k&Te ]vD"?ϝ>nUe. 68OX2T6󓄾8K#DkjN*q_ʹZ מ" *;hIjR X:NʥؤXt*%=̗hmwAL~GշHIKGMM{-i骡tZ0p&ٽ}ؕ_h.b27xߧ\481+ &-9F%)߰apo ?YeHCjSQ:D_oG r#nPSPAڥ5׿AkLngvP:%=eO=NLjE'j`;.yݎ)j-݃&=ft!'yO:7u|'i $,#i^=<s\GKHd&"+ a2D [13 {OPW@.c= w—|vVJfBhsٶi vWkUh)TFܒШBivIba c<;S,E}JK}= -JeS*O0џVb=^:#jp=vaҮ[.xG{J;?v_ ۔\+/-  D/9wpx~>rc'8D46:0R KsPTv*> fk;f .Eq*?#?uJ `q(_-$+ IXq (D #KjFvv ARnRr&'LB~яp3|ڥ7A$q_!9S ?EdY ;|cЫ8P`NFv(N0eM-[d>}ʷg\m :ߪzWF"JLcc7HkQ&0K-(1g|A:1e jG 2ͫZU.ӍJKUt':&[:kz՟]̮vcp ؖNgB'șC n 3omBw墙x}<$*`F|]PRu8EݾmL).i@X޲JÙmz+g=؉rJqlּ&w=o|rVĴ~(SYs{jW7ϵۇjvX8%և q_9ߥXK}04Rxg{NO|$Fƚu($[@ B?Foo5ɒV!sgΣE%٦emfCЭHyCҖɕبq-K0N`Ռڱ}ϰaRֳS6XFU.uږ e 404b\*IpФ8_L[a.WITPɟWE]=}ڥե=/ˁVֻKU{ JgyR3 OQNv஄e't ܒ$8Moi& DJ1NFޮ,rB\ֵqEkbU")=ݖ[vsŏ da`Iv( o#RA۴<ں@Xq&kFظoJ?0?{ͼ6Q k(ckn? OemMW\ ^kcrwRAPB*FY@]biXb5:hw̱= 1ceiBr?Ss# QS;H Od mYbi{ AG)ty5͛wwx ^';^7ԁ43DHnR7n{Ǯ42ZhK 2Ҍv<٘JKI3|B4x*2ܚʍg⺜ިiow97 MG%bǨlr $܋ح[3٩a'99\^qƔ\̶:|gn8hQ4܃RVtFMКoޱ *{xpc3ofqd0X3J020mJRk2 1:mCD7䨿I9]\@y-Mv.sewn"&:I>E!@gzt>#?Ʌ6G?qꮢ湛tG(wWhiwI);kyWaTP;Rޘ^Y6uVk&@),Ƕ1ZñP x;7o bvʙJAr,IYV{328 kdoÁS喻$Q`A&N25*.*O˜1]U{H6հ ʢDUڵ*DdgIEF&x%Uj08}7٨x *CE=X~61LĭVkϴA&npaRg*fLN(+iW cOrן=o+k3VI2nR='!^tT4пCuyQxeRh%u ҽ[ Xz`6iZLj0tJSBUKB7 -Bʩ.*BDݠGQ3nUۯJ iGКӶ@rP]&C88`ax`/pobO-mo[S]g#򆱁 i&b&jqG0H"V&BQ+1'"Sk] t _Rd:ܛAu[;0_P,n3 A~( 4KlW_ٶP5aJQš'>xW*qYxDmCj<1݌$zγ*c5$T6."؉oԖ?a mD`0xK$17 sd&^̜3q/ARmq[$ '(*+q3p Iʑk Sc\^S3M̀gF3ɫ(Y6L̃?&]/*s>i!~RB)Oi@f,= QPgdޤ o)H) Xʓ=]\@Fl}iiIM֧ å0#4Uh}8"v Ďyȅ qqx ^gMFyʆX_-Q:4|sxZ][>,Ede fz$r~ʙ.P7>ћwk= ^؏YR:ki3o^+DO/ ]\B萃=PB]EyQ Y?aoH5As͠1n;tTZRN g; )zt a:U\ȿG5F.:VF3ʧveٶqH\ր8S2)ߊ2>鼪/*={2Aޕ}MBiUIj"oT,j;h=$B/ 9?ؐ*O_Vфx fpR|Q{ݒbCKxm4%+g+Mls5=u$k\2%&!P(EYR1U~ijR@Ff2IcOВN}mDݕ|ʍ6-\ Ca-y\t/ El"wD%}smg.yd_Pez>wޣghA ZZzwC/ @Ln+x7﬊݀ذp6&O>h洸ZMSr%Gن7LY 3\*P _ 1e)ARʃhzy;a`Xto{d׿RwZ*gV n?Xˆ{7+˯XY}$)j\3WoS JGTf6f֊ E&FfΛEɏZ;fyB ,aq)%8AEըxox͔RY@Lnzg<E4,(Ő{GJ ݺ@:8%r6p&v^رseΣsh|IM\$^ˇ.EZ\tOy?uucqu˓"lF0D0swN{FY J,}Ru=k;a>aGu(:Qǒ9$C]cSA.ҕu#Lgi[$Dp@1to饎_=3XCC[Bu~LFt{@ wg vAbQ%+|؍\RMAakjX Y=1߃x Wi 6CRv|° ORۉLDH$NMUWLҔcSV* o᥇ыGiY9d@{$ Րub ̪@d-Cr7vqi0ZI:3˷Wm]r} Od:0=K8n陃pbHYv݊.HIʋf.Fwxe\aRٿPs4e=8-ǸcQA**"!R:OIʕ&IH!=g%.+(DdD$KR P7œ7&|%2*<\xݝ/C>>.a A e5 V:&l h$-pѐbX;d7޻ʸ. 9sc :YU`35SB[倖$wg۟//o< {GsHL]E8qnF]ﺦIz#t c`}**2z` ~P|6`whMP .cJ/6VlSP%9 ܥP?+^)`c#`*/8-tj }|zGJ $Tə}7Qcƿ 1~f3/*e.56ê<%)h.Xm//GHm1 R( \:]d7 oI=WSv "PRYl@Det Mk'z#J/+d4fb`(T\k }$@6ˢV ;KVK 4Z`?ȱEI8و0`_ǫ5~.e`b50+Wvvk)5ZWFȉvmԂPԑ :s`y=8[ppRye$n"0駡KbYV'REPP]~=CepcB$R:4ؕ?Ÿ|=k Z46{Si>FpgFY&y qLL%@;Gz-nDO|&sȋAB+Zo U莓4cW&SIHg[J4DC(C'l{/t#/'cDĀa;p-?oϫʃs)I|~I3%m^ݘYOC%? 3W!J6]4S(5l>aVbGvhFEH"EnrZ2b`fhJ~J9mE&✙FЂ{4B&ߏe'<ժ' >;MmpӌQǵs8SD/8iB`A-\TXd2m>c]}[4J*a4K1'_yLTN3}Qox yfZb v"k" c |80WW7 秾wDuOμ懃N[zR1d? *N=DB*ުaz8T: }*‰́3LPފ]CHeQJ\ {#.zz9} ߉-,=?}mu1"~N"a͵xh\R66D6>娅:j"|WVo{-l(m\}<&;Q"<,O챇Jx <+iy-2#5;td%8M*Ed+x#Trܴס\!YDXA-qlse-m󥉘ZZ\z'݃yzX|7QHAv9X\wZ_Oof m 劊|ZH9_ܓ<1MN{.خw H t=6GTOϟ!BG nd"#g8A!.|\zg^⬹?J64%kV˘n`K?O1cANC?eXӘK]Z"{2?UW 4IAbBa ~2cZEN( fg$,sB)&.b?ЫL6.D72ȊC $H=xt(.u.4.ϓ?j n(}ԴG(wY /h)z.GIPYt\κXOh^4s]oT?#EZ<63r60/JN+ZhMA[>do*B%F;{>&&ՐȦu013Sw {\q"#T,fI?0b6ol.x-,,.*Z7izO"EOBuіJ*ZXVѲrE A]i|}`w>Oe}kb\NKj0jwdJh0{n)4Roѵl8GֈFN\+xB3ʐpbҐ{`nHL&ѧL=votD^0AG2߰J\YS{ Y=B ,=ud!n N7x;D?9DzUH6ݤ9T3^'39n3\?3 [I'&|Mʘv@ݴЇ'{4#ݬ#1F @Pv3H=Jcf|BDz絕 Xmv:jx31%Oݮ%;ӹf%i!9H2T]W2&@t#pۯfDyQSoM4+%ς* Vz\=@?⿑.$Z|QD(bDj:7W`K#PGoTJ[dng$K̊GЉاɚUs(U3d޷ǻכp66gNJ|$gyVnмxDU'Ts:!s!}),*1Ce-n>oȥm5@.{CtXN|mnj#~c @'Jibay+ {7ȳ/[،mqtBך]ޒu Kr":ZcewS+^:v\߻ded؅Gq~e،m[Ym:$U8+_Q)6`  u4ػ6I&ڻ%L+yhj3'ot+kg6wgI6#|8 !)Z/yo*]e+4pVja5'FSH6̢-/OX/\.3clvUeTL7ToQG|+GPvhlջ=dXBZH!jyuq, U5p:3[}IVX&r4H++AJbֈCSD\PgE0q4C9TX,)wΜ"1#wk6c=!ƶ^D.ţ|ͺ!#FhfX+9M[M2|}fyrhq'P-_yU&i,yo~?(p+hBH#PO@]~OmK_Hfg-lhzm#pdv:eWkGkRMhmR2\aXaA粘wɘD~RVJoth"u?;}85쫥k.%w)|< CԤKfnҌ3b`΋f(H;kQWsZYVN?o'_F+8xsv6p3uK]̿Aj՛/4W9>xC匽H[(&v098]>1_rdJ`w*oR-2rӏ ىO?z|—qh'KD^ hCs__֫":9vg?龂p׾[m:%ѥ&Hs;G pv ßǞwVYۯP^4LPS8E5 ɫ݌ƿJB$>8pcQK~"f,1BDoP7[+RqS$w4G%Mv Xho7٨gItOՑȞSOPOWoljowbNRڄVvaTgHJ Pw=Z\͔EoW7p*tq'{&|xnva7!f \Yy Xq;>YkXʁBEȸ9HۉU"1_O6e*l 8!u}2{o4I B?cwdE J zGClJ }6ח}un|v{TOIDIwqՇy":+l=1DXRGVct7_YNP* μ>,U0D_< 33~ `%To|cx V]) <TԀڹ+%I^YI<K rp`>?3bͽPֶNQJfG!9avPpz{Lx)D́<\4} yfq6nD0J6!w6T4HѰ.O)!J/ߵ:i7O8@:]8x/hhz8IћKSCfWi9FYx>,qlc.b EX9 `j\/Abx!̗Vu{1n! YLEEssIJle'PwZFّ>>M[ IU^:`18!Lg5eTK$͔ :j6@fV7BTŪ&oeLɋs$4_yEXފ~vIbDЈ'3V/9p'F'B:*Rǀ`SC|uXǬei#z]M\Qk2 %BZ,eM W\"t6/=U&b^M\*u2wJȸ1n?2 N*a;R,p\ DSb^ǒ뉑}rxm[DEHodk&a"%`dxh\&7:ڶ5oY5q? ^eo>5U8QJ|Ǟa!=0)8_'L?02j+ީ>z:])߽i̵l)2BO^%mN!y8RK hٸt97ZJNH7'FSFLUbg(UXBL?DXl`%Q^/BVh܊#!X|;1~$?uC"Nwyn[FiX:8!;cgV=CˌV %KĹ0t)8:Qers KvFkno7pA0Jn^x40tVļ`rYa @ W}XZQc59n޾y!`@9{21})2f]J ĺp2|L ;hNC^: m`E,Wn0# P0 ҏy}#M5;r¥:RlX7K"޵}WZgb©;|<8/cjlx&t-lʼn}U;.;S}(2Y K˯!/쓺7 ,^R6}TSL-̾W8$/izDpL`OvNsQ4]qKWj]koZiH[ bw@@wQWKr1rg R&Rgv4R| g1?pqOVX..eO4Kn{`[IEc~X%gt Ǥ:dANp~pcG[S>柆w~J! ŧq &&*^\Y Q%Kk| ;v9K ŏ;;3j,Hб,c0K6ZA*&v5#kڶʍRCʡ~0ԝAQO>2uآb;soru4ܚ9{Qȿ=o70S{Oe)A"cCEԙ" ? ǧ h0TGsy-` iYݔa[Y[G.<\- @远+fܺAQ%n1@T&[gӰP7RŇ lU@.WR$y?dDk} 7`Co&FX $8EcOwS'!f񺟶`0v0VhW]T@QlY=n]y=?&7=r,>jx́-jS=$B3$j?OěD mAp{7%-jsjg3` R{AA :M lew2)tG43b/{kh56xEZ@B_ʫfZQ:U J-O}<<0!KGpF" |&3WgW/ܕ7[_L*'|G|θ0A1qÛ=yMOxh)+}mi;Rۤwgs1Hm_5Y5 ynsztDI1'B(=lHBK)?Q,š❶/1;S.41v,ߙ$b#Yc[~JayK>30A<]uO+_YKHcbhˢnԌR-ޚf(>^ :*htmmS [Ɋ7OaȠR A x'ꍍ\(9;.-NKm;Cu%QET<9WЂtMPaJ75|*Ld rkkZvZ'Q(-&1-aZI{4TCYq_$zf ~RNN1 kgH+8kFuA ̎r7Y\UӘ!?tD7: ?W! Eof2LK#LyE 9t|TLyHfRO8(o&ʏ5]MUW$:#"']EcQޛN׍1w^ߝ<3춎o wlTjɹrO6TJ 3gwW!YS]|foXhSjnvo]:lRtE#+i5D"_ /LC-`a< "|30阊\{1TةŠ3Zv٩u?T/ $B&7H;H9líA:< _;[e"~2eK,c[Lџ+SmWn˝7;c+F31Bj{]) Gh7^VC$+kT0I|~n YFDܥe0e 85cwW!_&._d BTyV$&4LڮGWfji)|Ai`mw䉅÷3\AVo7Rj[s_Xx MF Ԧ2R#,)f컓cGhIDAJi GIG.1QU^u0*ZAFԪnS Q\F=؅nNb0^Ý %=_!N$P R+̀O%ɠH(d,o80N.ѵg G¥=.kt:wt{I-?q%cej;a[T8ẏĔygQ,ֈ@ ٬F ,HeZ2T% P\:3~rV -.[-hKpkzJ1!qB6bU?P*Aj D&,HΕ(؝$ >_*E22]&l}~Oqٴ~It_!&! qT Q{oSP%K\|PܐMt |:wS=Yb nH:Mk#pt Ȱ]8+ʎB78> k G}II脤vը~-