sssd-kcm-2.9.2-1.el8 >  H   $(e(4 U]Y_oC_!eݱ2xQ/Fās709 /a^g |K71P74@' pr<]3~bd ש" aQq !gudg+9+&Irr90йox+҆qי?D|`{GfOb{%:NBTZc1K:646xЍNi ">*'4N 0PKW8涇 ;"eXQdYC4?3YkwnCAEQX @r䭸dA+~2H9&rOt4 7Ndhf!JΖNn0!1 pu˦ٴKJ"!m+'ONHz2!R:6}/w/ {)FUmv]-J5'CY*NFT*IY>y46]6t Sso>0{D'rk>֫{̔NPFB)ÿL Fs@gUo!P87=Fk,]7SSlDՒ\Ӻ:ʡdrj07Dr]$oEv΋u,1&~< %>`B(?d   B   =CK`p         Y     B\ 88 8(-849:g>c?k@sG| H I XY\( ]\ ^! bdQeVfYl[tt u vw x y+Csssd-kcm2.9.21.el8An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.dppc64le-01.stream.rdu2.redhat.comwCentOSCentOSGPLv3+builder@centos.orgApplications/Systemhttps://github.com/SSSD/sssdlinuxppc64le if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi%6xځAA큤A큤dddddddddddddacfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6bbbac31b33f419589e342f20381138c0dea737fa71b0d67a0db97020b4451afd8c2f6ae53e988971d19b13a2104ead7d8f059bf8e7097a1a5d82ccb81764fd479f3438062ac0b74876cdc545ed646f144b35736b59bfc2c368d2b204fd72da839cdae3017096a1e504092e196dd4a03c639f78092c332151e26663edee1cfc9792477b7788cbe2c6b1d51e061e39d4a5fabc3d7147a648c21b91b6ff3a1e210d23b943cf029bd820eaad7463b1234ffdfc7e4a5e378ff5c0dceb7ae6e463264ae280eed4e941573f30f5b9eae3bec516fd17095ec7a56f9467b26ba3ebc2b7cefacfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6b../../../../usr/libexec/sssd/sssd_kcmrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.2-1.el8.src.rpmconfig(sssd-kcm)sssd-kcmsssd-kcm(ppc-64)  @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shconfig(sssd-kcm)krb5-libslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libini_config.so.5()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd2.9.2-1.el81.18.2-113.0.4-14.6.0-14.0-15.2-12.9.2-1.el84.14.3d@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh rusvuk2.9.2-1.el82.9.2-1.el82.9.2-1.el8 kcm_default_ccache.build-idf1b470e3358a39d9f1b73f17feb4072f449d807bsssd-kcm.servicesssd-kcm.socketsssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/f1//usr/lib/systemd/system//usr/libexec/sssd//usr/share/man/man8//usr/share/man/ru/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mcpu=power8 -mtune=power8 -funwind-tables -fstack-clash-protectioncpioxz2ppc64le-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, for GNU/Linux 3.10.0, BuildID[sha1]=f1b470e3358a39d9f1b73f17feb4072f449d807b, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)+R)R%R.RRRRRR'RRR+RRRR R-R#RRRRR(RRRRR RRRR R R$R!R"R R*R&R R,RR2utf-87b6ac34fd03d6d5f01d4812f0ed1f1173d0f9a7c69dc25a126c03791d86ea13a?7zXZ !#,`O] b2u Q{LV/ƾ[B%Le"T_/9wBਲ6]$f 9ysF_4 )cH"5oKTvoaZ['r/e=0F 2_CVkG+ Bes%]׸>FiK<(`d4s~b}M}nZNYO Yh2OU8DpAnRт9.#"\< B=F\FɕTn=$[2_M !%T5ft7 =׾#49Kr1J^>x!f D.o *mT6/UzߪȢxB3˛<%|wPrNz|_Q*'@=~~,mjؕW3$ZQ2ea+wkЉ_iQƏu._E pUt%vQڥGG'D9sEe 3Ɉڶ`jk e܆́tGtve[$:vy#8^U֪J*cup}x{ >z_ͷwDOh{‹Wl9lպ~ג=: |p5ǻW5eD[[|;5aǡ g::cSIL?#+2F3/8I,; }f O4\KҫSBf\zN=>$"SinJtp]~Kak*Z<7PlQ$٨[P{O]7pOPAk}0&c6ۑ5.a!T hY.[r6'~QoS@\,lyդI37}8tFu=h~ѺS!>Lc;^Db@S+Xd q5fwςX]֕\Կ_Vי2 0) 95G8'T3ps`Vp<`Jo:>2PGm9?JNo 1lWjl/amy"Z0rЕ|i;t{ eF +swz}$#\_{|Xk׷![©l*0Zͱ}'՚ ?&0c3Má.|oHI$@ =E(|WQǂ֎~΢t:mH*C\2Nj+LNGԝOg Z2!ucI_t@9\糎}-z{BP(X%.jUp$C6)ݡ%{hέx_fAn@QO#>8 m Yc7cSu9S˺ح`8!͸+9ɾ0\|$G7hPY !AP9 wa쭀>ڀ;O5^k^DA^hE C\UWJG}J%f;eNIʌB҃ZhAQExD/Ef/ 7xQҔr!+M,.1V%{|md%ʝ,;Ǧ>u2<}M*ՁfEJ%)ެ,KJA i]㚶0s%)̦X$&n3G#5Hb (|H$U | @|FG)K\ӳeuH kCԶ!N7 `:/ N]vg`QMCŗX#BDx1&5em{ʩz?UO@Oͩc߶T5w0rq/3$Lno£qȱ3GGB (0B WfE2M/z޶ CG@'7@+"^yb~okK]::fQ!8zR?L1&~Mםò*3|%- fTb6}.uOG,9&@V`ض3jbd y.xD@0 թ1u}5p| psȔ5#/ juN8h"Z^k귐N+$& dzusoDXJUߘӀ_jt_䎔dImg9$|7]'LpxJ#0VЈ>D\qq#)R 1ޅy@&;ȿ2 .4{~?UCS[@Bȕ?t]jk(MрlQmȖ8mߠ Ո~+|0 L% IW÷줔.G+Q @%W"^ {v; `aA}7fJۣ!Vf_ުXk/UMC'HXSr߅Ia*ʬV! p l1ZȜ YںVh`(F\QFL 2 hhH tAĮB{8p<`q<^BocQ0r,-/3њVyectOfwoViWAmW':tܪug?)!^ oVe+g^`Q9p =m{Fg~ri~IXY+fکjB1Ѝ孼N{82(}ja51DaO!琢 ]Ԧ8پQY ro7(;`:Z=5R|I^ƥU@1ԀrmLoM+I^"> ,nϣ5bj :]SvE{WI"B4:)\i>Юa\CJdS)NUm(D ? ,P̅cbĚy&c䤌 O!ͫW?y!G-S#B83]I/FBЯŚpa=kzu"[ZC̀P){$2;+,!הC nJE_&~R2+DcIg)&\#oJ!@V_!2,*~DyM)mqX$rph80^aà7迼|3o1Υ8r7ғ][oZ%Cbwf^]:o ;>=+(dyGKK#fSc |x ;t Ԉd_ˊOnm`I̙ig-w*W$iq BUak7$'Ivb-GR:'<.:G4`r:ԭJh7ZrpJ(̭GovYF*k7+^^n\Ժ%8Sdma#QWbz֠-;̟Gtt༱Ym( 2)/s )~t_A/2:[N擈DJ,BOh2aUKD|PSF{4J3m䌳0+T+5fXx CX M)}l4Kl6к[m?*r׫TCXwIZeA͞A;sCO5z$&p̭>ZD(P^w$ZZe<8#:b*5L3c*NP.p:#i:H6ʁO|RqXŚV*{\y*8*0Fyl+`R֠:l&{yH}0zVV>ژ 8~[7`55S5y:]i|jl󷣭|HXyf4C ̐g.Xx  &|?C7N] R2TA9%ٴ#8q'\eޢow?׿vJoG-D=o]O| <#fO+Q fg71c";(~Wt VŸ};Ud3Ҏ0R7&} di* J2#Q1 &!!LN@%;oCπ_V #ƒ¼1`fM'n?av|D,2W\B Pux+ ~ę}TB_P١sl;lչm-D%,|4DJGeSon_@fe=B9v3 <Ą3[9YDz]8s l;fngU7zԋJNdG]{;ܵb@87ź[ۥӧkrneC&d#)9:J!Wе)Yܰ"g{?lk%&+y=w'YCEVQ۹s"L<BB0 |B9AQa 2H19+g@t->="id^݊չ[fFiid!Vn1 )W6B a,# :Eu?H.T~ 6U&MZ Zu>A P_gOiz*\T01S9.Jh}YogmB@&S(e+{$;+ʊ` ~Dn󇻅.>PS-3@B>.]Zeu}nX&\Dc81Pz۟k}ڜpxc!Zq=m7 R~v3`)ǜYay-3V]^!9,m=J<+[R agxEaT*SFФolϳ.OѢP`{2%497x2ΊW2 -Yؽ "]ёeRcj¹Z?;s`qєȆ{|d#yК"ǯ>^cft QxPֹ|9f6O5On@vl !YZ3G}bU/dc4iWInVYJϢiR+Xw+ϟu(sfBrTGJV3J mèNߨ`TCt/"znen .)BtK} 5l VR&}ٞ]۩tI &RN 3~> R/қF"xQMP9ʓ2͚c=g2퀉`MyAYlsq#l3qM /N$ zX'{I+}蕽6qgY븀Etv$ٹ)ښfRG,۽(ሁfoPսH/P-g_; =P=bY4`em\?Z. k +S-YyO:Aa[6?F-iC1L(mOsTd/˧3I׉/M $-ar+i:rӬ1sc0I4S(24:-bNY624un :MV#Ꮅ #Of {IG)I ?S mXH-MIZ;zsC㥡]@sEְ G'ar*dp譒)EU4Z!YĎQn)cl_v=tȳSH6zbV~͹-K&=UrվͨsM'nJW^A.ZR̺6™`>=YAuطZLT) 8uerQ@1D:Tw__oi mx][u`6Y )"m6П,?S~HONr @OkzbҁSM = [éY~G[8DD.Bʖh^oڢlbڊrC'498%4,]~YZ~Hbj$TI~m|AlIEl)&rp7hƕ4v'>xm4?0s}1u'4\c@\<*JZVEf9¥Be?51!퓔(:ScUf\WjC &f^JdA3O}Gu ~5u@(m>45uόuõ`;ִe5ÏUØ"8T.bZ2 Cz3L+ѰX.l9[<=K T#->e1 o-s3+ByG/͐Ӳ$Ds;ݽJ"-1PX0]X0 u|!RN?o)j2Kd%޹f6=& CHP`oK_y4Egԓ@=\Z6LϋhGF{##zH,Å`Bx=sU}(Rx*y e)-ؑ(ǘ-@"Zp`U]|xQoKameE{1 ^ 6c &e=W<`<YG%}ܤbG,` e:D@7Nʵ'G|_ak|E: +l.DC_4aﹳhH[K<u}-WO*+ bA 8bIOX$2cFF^6Z~cbիѸ7V&bEc p_lpKCVZ{e7v'۴{;E=ҮBæ6kXzo ARl?zP?KoOCufwi&(^c4R&*+-x 8=ϳ@2Hk, # AuIݑG1Rpnj"PaM{>Q;K %-M{LŻš@}\b3' }BaBNߞi7.oG0oPc&Κql6Ks$K{orT:> zE=SK?zchY|R&K8)")Rx8/:ljD5sh-Gdɍp8H`דRTi&oMz=)mM.]!Z,:y=G-Ak :h>~"Gt#C%c$B| +kƸp5v=J,7DGE'.>r|Cէ9*-.<@2Ni]l)NT-@ͲZ԰8NȺy8T7#_76O$FzՏ>mO\? ſ5M2T7Z$ڷ ifNGzRkw_vb9s>{zO5)^hDS 01(zC{2gVP|nhZsF >ړ?a٘(H$2hoڏ ($)鰍$5^;똅IO0>Nڻv/-y֊bǷw)42lJ/LNpN$VBߠE&aL, UcCm}'2+7BjEj}EvsI#D6 6?zc`0]. @88pS {rϽu@|Vgj{|vuPK}y@L-[ *쪭3d>1&wN,6F{Zȷ5K+N>8cљ Qs!{ |1آOvSB1CӥiN-mR.5[ TVWvf^}~0g~}D-¡ % bm['/RMHG݉8='qةA={bćx95' ^~Fp b`Џ jb촓5YjPxy){ v ш䩷(uI]JX>gָM yRa$WAJtI! [wm?H裆'L+LY;Y%7C Q<8ϝ ^$rjnb.nƬ1 ^\:)*a9iEC++D_|+ n{-VY& HOGimVXqdݽbvFI! 'oQVxN!U{7 ϩi/π߄ .^`>ոO[l2-"0O?fy䞫@K %>_ r'1Уs=D4vU3`+3<Vjql_t2٭O gEcH+!/9FE!IԲޫyQ>$=:]c&6zϺM{i4_=ߋ. ~;4Kǣ6!vQȽ\x"\0πWB@'I1D"`Wr1"ZMKas< \y(=l)V4ԁwZmh=3M‹ZۻZ^Ēc}nW6ރzT)a5E+Q w8O#p$q.zt gx |=ֵ&rD`<>DG[񭉮$#&+\61kgkCދ#7y@90X(]遚jna*uDR+ 0a `1PhIFќ}D*{IٱqJi{ճl$?Cţ _d܂߯5b*5\I3 !!ErEu}b@!wj3/<04$MgKS,WUQ߁mDpÜsa6Z e䙾5ǟ*8kk-hd%a˨j1] #&j&C*O3bFg3߮ezh}>o1Ji;0le7s1~E]ist+n!_6_آ?9f9K7/6 f}DWkco+{ʴđ<]*LV }%/û莽0 .ՉE){-uTX4- E"W F=xȌyPrN҇6P?FZ1Ab_յ,Pαi/Qj<65UK"\+рnU%}0WW D:v}dƗ cI/W 6|]a 9u9Sk6證iac9ԲPK{ Zv4.2p[ɮwŸ)3rλoh.GkxP߃s0Wk.99;hE̟זz  Lw/psAA2q޹tO)` SG $M°?J*nׁܩ:3 yqb \"VLw!(WN+˳* o"M&6}o"^^,jnrF8t[9l_`"u\RrqBBσKf؋AB%UV=\7re@Amnϓe9FFg+sB9ޫHz@]/1@bm&>nyNuD$v˗% `piﰧڤDG&{$S.~R-C,)B(Sn^Mz }2L}T3tW$ωQ;);.\D)kc}BU",HKZ< LC\䵣pUL"f6!P(· |zĝNǕ43ǀ\0{0SjO+w_+YPZJN*gfAJhEp9f{+t6N2ׁ ns|t퐚%- baɞ45`* xu߼]sw/ c[FyQB~:3? i !y9^% zϏ(;?+QIE%rԔڑu\UǬzV3{;AAgm}hWҙ)뜌J#Ga jpz"3d!mq:;YA4ygqDC&fN1L**-ξ{nPK %I }oqPS|_>Мt(6E[-+ :Wt&kbn 7y8 A8d3jqPdJrpg-ElT9Q ή~N*K4|됋MzةÔ,X103*l3ePWUc4!Dq9ֽslcj|W/ ܰQF9d3:ZQ>xת8iNd2ⰔV` .W"X耆" wF_;#JS/̢>1~@!vqS9t:HD6_dMOSrOwc*ImCO`D 6Liga,%3B6J1Xm~GllɼLp $%nlQ]IyipffڣL8E 7VVn$`аtˊ;坵. N%Qs++f 7V/[aqNTH9OVx#at[3 jo?ΗA`5˧5]ΏL\䐅,¤e'_Cl֢Ӈa> ^S_sxR`E2OTIv44 pk8IWMq^w l(%jkshkMw~"Ԕ+H/l;u91o{ޑ׸[kָI&7z>h7<HQvlu5o6j(OwDD>m,@QPtI=\FJ/ȉ %ǾltEg( o?ןiT{!>pt+Fo#/@ola:h? U 2M>"*lL7d;hAZ<.$To#Yaa4So]~#|q]8bӰ>]f.*NI!UDa={n}AGsxDX1$LX dʙ[`QO c5l' ^n4LW /;ka) ذ3ыAp`)R{-?{zREaLpI>lϔ5b-,anU59Bz+`4R:wlTEdi|isTfvdXg1q6_CReowb *<zN2ĀԸ8M!$[~h*#i޷G.DZ'c/LE—-d /-O;v0^6ٕGLtN4[oJJRcu.D9E#Ӌec R!ē>y x D| j& \cG8r ]vawFgՉb3 ֫rc2e=tC #k iCy}_I%_fA&ͣf_,x k %9&^G吸+Y,Ͷ2X-..`.߉O[g8Cp%OdN6u# |qQ#>%]Wqc|u` TpJ5/*_9π_)#IJxgdM7G=#s~7h$؇xko 9D ~l@0;gX2}d6Vz4ټSVb1cq,ض*Qsk ВWI Ϻ(IqBU\z7:Kbh @7 Ǜ ݇̌'VZ0x0aF :w9{n-7<>p'-xz:̗x E;XHVSBWpD|˄_{Ɔo@4$mɩ/ x'mNf:fa!E&t0 Y E `fJwiڦTº(4ɧ־u k-T_i ܜpL[xeIGf c>; Ԓm+ƶz9k@:Xӷ"aP2}D"WRUb.^3#s&w d͗Rbw|Ph|W!OL;>˔8pHywWJ>خRSq Y9$ uZ~ YXI?r+r$e,?4]k 0SMug# ڞ5l 4vTpʶIS,G>34VAD{=ߩ4ґ*DhJvJ_A] #ņ:O:Tv5nE3[u 2j+Qc k4q[tGcܱ헥OD(%F\ xKDeiS rcDt]__'(v'篁קu({=1KQSM8.QW؝;M5DA+yY,@;ֶt1)m﵀dN4AKv%Ms}/=gd8{G0ʱ,"A,/}P=عԽGؔgK9V~2E Q^RL?iO x03D{AHnH$Q7^f>KAvXqt-8݈:ŴKqC#;SZ8WZG`,ӳRs[/i`J߀|YɭO ue&MR $H}GpL]{3}_' 'V^bPn; 9 1kDf$@9eBh[uiwޟ׆wh?[L̻(DʭZ:m m2)X]e5mlM2Hn3)̺t΃d8*0p4mp9c"+3jYv+d;nH=c(2/񼷧cm"JY*ٕӇ~9"q)rXWͥօ+EWH DhxI@^N+)BgZGuEޘB2쏢ͧee{m_]P^xsLJjb-"6wEnơcpӲ-tM*zפ #bPɣ힒oe0)9yXLȀÛjS:Xˋ+;SxavzkޔDygnnfYE+Esf|8;BKiY;q!}vⰉrJ徂*BuZt3ʭRK!U hsx%72[:2Gk0bsO⛞Λt2_XN.TʏmWqXL\;RNf"h11pP_L/9غv ax+5X =RR\qɜ uM096vrK#JI&n7$F&8dѨ[eֿ~!{[z3 x'+o 6Qb4)Zu&|U]@ڪZk?/!5sZ``Шw1XQWkI(rq%_ghrK19|BjuXzipx)s$DyGwG7/0mQ_zUfYw.=.EO2,@.$҅EL%=9FDs7wB} JOvDF]VR`-wKΌ%ncb+1\VGqW"q4U;@tį w ѣ &ܓV&}v}RȨ lBuBٛ4XMmHK҅O^y PfS ampRF5p4Q8w3OsvFeәGsoLy- WEY-a_˸jKwةJuW OODUB֫Q/6zKvœ1sA2GiGKGlVc͇5g._9;:?]*(!)$d =lԼ_^YBl&&I:N{ź]yZH-ToΖd[_?e* {n#(М QRc p!iٺE'%uSk`!b wo }8UǰRцqb"{!xKm&[@m'CL&u_ l[<: lTC` Vz~v8QL/Ǡ M$E]_8֟tyqfC2/glEqin r4f1?г!WBڃq3`B\d])ZCs:n{"r>#΋C| ?۰-m~ݷ)g\+2n56VŠ0PeCs:/ģƫDY9NU(u+!<l/ee;)Rf4G:A O|Cg: 7ٛ?S=Eߣ 3/o6"0jCjYd^)gۄK. (뷑|V'Jߔ| U@5y Ĉ )NL*ip^`5?v%)HJON-p%-zv7~\-C8/LGq%֤aJO:NddۯX .WP%H?x!qX&Թ5/Uns\>(4J9O)$-~ ||kf#64ߕO-_㼄 >E{Qw 7Q"%yk(^b{nB"rmp?cQ'+ Qk&XCq;2p[Lp# ֮x`L2PVI?OB恛Y^cA6bh ]aނU;>:=v[)\. +^hZ.]05N" m8Bқ>DhpG"{|˄>צ r_K=zO.ȳP2={qo_k]&MX;;6QE,ZkHy~ X 9;;p_ ^Ÿ)P2,TO*@/[\zY 1gk}%MӀih59`'4{ːBR|"kT[XC(޵ Skr{ 8aT9!sq"Aaaf86> \G;%Ⱥ} ۶;r^WVS$SXƈm`K1^fk56d^-"A#!,Cfq5b *EqD]{HI R^̈́d2~- uTdM}"7AN0fC㞤+V1h)<'*b\2--%d]Ws߮(ُ]X!Y u F`;C_;0r\5?L+ڤΟ )y{ Ӈh)Û+*1&'0sfX= A%F27242nJu4gNC]y91 8lwVܿGzHX¾jt̬ Y[CJ4鯩k _PtGN;RLHwpL90e_xfm"3 #d3N{(}Ytop4jQuyo(B>4M P/fFRgD4y@ɻ mdciAf͎f\XЀpy\\p,! `:U5TPD NQ߳Fy5ˤ\oQ .leh.S' 7.3Zm/C+FW'RK2J-ryA!7[ z*EὃVYǞkk:vhYQt? UNL?j7$ЇT1R7ˎb ؙ*%<4gWWi%lmϊ&KLH'$&~ h+^g>([Y;䔔C<~"[0 `gG1>_ znK>OlY7 vãf$,\ґц$BmSC"icKIɝnYmJ/HYcpG=<t  tb Jcv3aGXLtd"cǖjoA"U|k Mܾ,3'@D)tHvH=͵!Nj<?is(9n5HU@ӒVQ%OtQ¶pW`5u@%60HxOB9_ Hƈvqt2LHDgMީum.˖{wB[WR{u:-bKqod~pP 1*<1 g ˌ%j4L c Nk{%}TޠOP3%8{1HmBXE-V)؞ d-P>hSZ=ס , #u HZezݒf*3E7b!(zK~ |H(L%7"u/yߟQVR>1, :}y Y{;{0N9 xE MVup*S8S y2*8} rkG53 J{8J!x)\Y]YУ䑡ױކze!YjbM?t-хj-`' kr#Q-lܘa=JGЂ1ښwn=eM?iy48fٚD!w1"b2P7y&<7|b' w?/>n763R8º$4dKj Yߟ{ܨEBYqqN{xT&{tU4P+6{ GyvaG;a[* [~J‰GQv4O7Vb X37QJ؈HwC>T@8 m: 2y&p,bOt5zZŞ3ZY#8.`$L𷄆dcسE3|%ɓͩ~e )P( HXCRa!L#+JvLW!L]}GUZ1RCE!SӰFd9J}:Ĺ;яRP b=vqE6Gz/g|+sA9À7>]+(p}Dw'vuږm9 ,R"m&Rm.| 7xHSJV۰W>5,و+8bq- 5AB*A{`x!HA]ȀV6O{k$.{P?5hD$N @V }$Vw4~y'ҭՎ b=B8Ρ>~8f3Aқ]A!򆮍HɟpRAcGBvmhE@u6bF8CQɑP>GHZGFQѪO9맑P;|r2Upspgq,V_A'ӳ/.O>?RP9KyzqDYKCbӘOگZmub WJf$Py?.(%E֞4jD.fܐʂmo87W9FSVZ U Fp?P] 9vO=;jl,WFuJ})۟ҟUnJr[Et|MX߿ce,rz'3)Y3ڐmGzn=nd&zi IIpdѼ>2Ԇn ,"ΨθT 8)̀6鈷G(gj^U:̡}'*j2E`9ZM?Z[`}K=VxY2VqtD6V~Mk8A(8y<応&\oIP}4pDYFGvƮb~)z0JmO5h{+Ϸg**e" T$xqmyShвݨO4^x AT?n~>Q 8Ѯz 'RB\1O/@:J4fz $ݯ;RSK;I<[rU!֚b '߱|J^6]gvnnrmO #,*jR|l!n7_5_C^+>_cF XˡTyc5KsK ztX^A߷4)-WV謀BnW'iT/CN*Q/MP\>/Gg~.+w%Ѱ$G\w pUa/ kE;ҷ"_N4)@rg b:zzҞɼ"`#?u g~~G,ꡧoC.j?=}D)x щQere#C|ahLx76ٝwր^E[U[ |jn-ӥY.okDmrD]I[Ț/+#u9d) pY@Tog\Ț >m[J[ˣ}0SGVCK:ٵ< Lh,1%xBX)fW&4m);(X^%hu7t"U! I^o SᅒG0M+1.9d9|'*Cc -}|&U兴$%=o}ueGưT;Já_WlYgBس*y+`Bǚh]Ju+4 ,;#/isde~ f_O,(Rɫ)sG\oUxEo{4xIPYZtr j+U]%dI: 4rgmK%Tf)yauүKo Xȡ*&͏8VX+=b{@c7 b S3 byS)$%&0-kVZs{ʥ-8H\qISNU'S+9*>0SqQ[T&_zAfhY=%2_S)NS)F) 362hfAۗU7'kԛFcB:}Eo*\Ltp4.AC XHaU?Jzscم6;@4uMzx8&ɗ TpŹTօ<xS\'?ԉb_ ^6ER2`GvEWQ$Lb;>. ՛|nk:8OPu}Y5'j;HTA-M?4\^: U^ \$l|4+^#6pȑM3&9!h_ޞa?o1 v+Bn]j++ #-s7Eo'J2]||\n~k`>(/T,dV=}rRKCCR4qluQS<7:7 Ѣ/}ԂLm̓XX/tgu" }!(ۈ賟~h(J)8VWC6y1xKXRA\jsť+zzPO 7Ũ]|"AɉA pHT۴&7k\O+vvVFa?MVD,B:ktT]ߵǮP<}0QJ ա{iO67U C!6>dh#zl!($-_EGIPg%[Rx+=D!&-!̺ЧѤFJlr \@mWáS=d{ײ*>ƼӐ&QI,M)$ioЦxTA".l_V>kPa4K'S˩b.`qBBv,Yp1;-g; 9ʀђ=+ɀo'xQY ;_!I8q;4A#G s (I\gGߨf.^rc8+/9L؅uyJ)N3~T{ªxT>zDd^1;LBF #M l ką=mDՈl S1?[Sh2j:n [LWS9 4>C&gm<|hvS%dS-7T?S |ZLqQB$ ^}^]y@F_iK!@3a'% ~5RvW%P?K-ݓ:Pbsv1WLj$7' ٵxbMK |io)wd}nW`jգNkɞ%{\h.{1dThT&K~`?-\[FLQw=JNAdf{y*:" 9Q7$Ep~Rcm)0 ~䮌* kmjJ}kY0!/ ڡxţgl˹D!4$w}dˣ+ )JoH5 q(j? [ʋ(ldY@& vh(NFs\QD|Xダ]a9-*oL4ӣ(kfPm 5AEm=10aJVܬ Ԉ{܂%A]:'^>X:՚z%}-xc$Ig$Yy#pkCuNBJa9G 1<©+ܮA,[DBofTn9]Fav O:TM<9d,O]k?/OMƑ_^KD;%X)r 5VFk1]<PS[jjWsZBpNP ߄fпmLvܧ[&06`d~9~xa˜4 NͅU"vK_)6? ێN D7CrӲD̆nGI$s-x|sٌ-Og$ Mv֛(6 PMEOC$R͏.3^chvJ'f3,+30ʢW5"I®K19`޲pV?Al&2p6a|:RJ]?Q?rRs;%rZkXt:c,q.͟$߁aC3mМZ%Ü*'{B*]sI$8L~"_iZ5TX`%2`BdrOR[5AtU9"MҮaL4oP̫"yxOH|LՁTA4)C QgWjj~Z;?גUhƙ113זwQv4hoTUk~/1=:QIKSN6`H.k#$ ݐ6oKug_=W6.3 c(?yK,W>5~D!c{^"PM8a=N2Y\,R_ҨDC`+F4w_K>ћ+..{f] Ō>A%G)Ӡ߶h(v()tĂ/0.)R/)nVfΑpB+YhJ;%ghhhFM?)e5ꢗ0BH4x=sJ=~'+,#;9ڴ΁C>Ų0͠*erkn~OCŊGG4)I}$S8zC` q2:=Wvρ\>vq~Z덟!uV}D/|0%`Ǐbv7EbWj.Aڹ?r\]0>cp2_, ;cʦ&bDis_ x%cY,/豶NJ RUS/ ǯǷervR2:zqa&66L4q"gMV59jvҵQD ъz ȁ@+y!v]S_)Ŕ-jKbZcBlQo? Y,uJ]/A!Ij78;[޸(ɣ,{)Xt5޾GvG<;? G|qK%Vٖ-Sas?3Kn7ܘxS#k|s->"iTR-gR:y֗,Ru~@q$2$hX3,%l|cMj%?<: eL A6$|ⶾ݅ohcu!kmY9xO3Lr<3*f|/qx{t! zjޱGZ +Ap~C_Mڰmɡ@QbSjB9J2≎Ƨ^nҏM YNn,l^H`{1nĕi u7;7ã Es:xtbefEr'`d_-OI;}Mc >g c4/?w}-d]b~2bi+QUݖo)~?*ْ-Zddڂ3GQ) =7B' G^rF5f+ӿ0Z+$YOCǠÐm{M[ԟɆ/0dis^_j AL2FTG+Q6V_P?/0.͗ڃq4$*u䋡dN>>O߃*{L\2~Y'8qG#,uM65;wC<{̎755-ǧ\M%?'r:l75vk^L"yX0y[.*P@+ ,>mYP?ԙɼTdZ7-{ӞH0d\Fj8IԸ2d3KiG+?-Mʮ٩v19g*k>RW3$l5⸧mC 4;U$T\I$).h{a=Ӳm Kh!YZ&aRoh}JbD+CqʌAo}] ?IߘR 'nxݨlty6L7JiD@8H eN|3W)zqE h}>.S4R*wǻX{w1;HMS'x.ʋ'>yv?z3mL8L'WY=WAfNYHǹՠKePv- >Boef21#v)] ]JyCOkRtam L[ Y*nֱ}@=e}ZQ %Cwlq.Γ޾0k6c_^,ϿmGD@[mRɼPEEgI*I#V߫[aQd[t0:NhOm& 4rY[1nb}CŭBo c;v Zh&CIj,)#Cd(8sj1˱km(D o#%_L]l56Wq;+c].T$@?&]O:㜐P+~Oi#b'0 LgiN5>qYC wmAh F^cDTmS)y Cqư(pc:.qN x~UOAUQI؟L6~8}CΠdF0}ΜR_nDSMjx%L1t}hXtڤ4rAtE zӍ0_>+H?R|!Eߎդ^)Y9f`TZM84ΌBmk"G\/0=6qW +w  *pQg]J{2{Ij {v]ޘM CT+ypɀѾޤ!Iف[*aHL/u8S}uKrG9AjLCZ FS]aS=C]uo9EL䉔G'TTB09w(f(lX0(/ '"~ۺ6>30S1;.4鉿T8>ڞ& ?,} F9a1}gDs!^xgѻDug[pz.}} HR߁3sonQI (+k dф+z_ו;h*wqzZH0GY |@i]AN;@bjkx}%kD' ɮ}PKmKvY;8:z9>/,o?⥡eK&kO3tUƈ;_5RQum2[cn'06RS!soΆxdzִZdPdSA1f{esmݧF>|ah JeO.wRKԪgJ8H3vݯ5IJ J8C酙Em OLU貕&ZS t{̧s.7[n}x-M[!AAZnN@'ʷ1"Ow[j6=Zi Yo;u|PY1ېMڶTs.zH2E!W۵iRMRbK..(t[@-UG mo^BI,_VAQ[;!-W/~=D%CӅ fE_ii1IưO}{F7:okQwbBَZwRݾY{ mԎv[NlI&)є{l~3!ي*[6XACP3՚=<\2%,$ցud&]Ö8P>W1Z>Yzv{E]Cpb?{݃2N*>|l>LjN#7MmOu6;xb.s◈a)U%_g!_a0^E쎲(?Hc˘OZ!p{pSn̘<uhM74.J'C\(2F7Ɲ4@zKLV0_zϖ#.HՍ9/El&iEi  \FY,?eZg?Js`ٴDWu Wy[o 7CÃ:n@/+.6;8 Xxz&TX\!6:%yU%+αU+q'$y#Ca[eܶWF(`{ [\,WmHF頦U|yPSoe6!k H Km+LSPWxVHR(q'ma%R #4(H<ČTE}FtOv5,?ɥrz^P`-0ttnw3S+= b=FZS໭H%C|j}e+Wb"57x`HQexO(䠹$H3JUTWzM졾'޸6{Oǁ>X8|滞%2kgB򨟺q`%)*@ߢe@"E)X+ F[.Bdk9pjQW6Eyz4}o3|LN//Un޼N4Fdoud*~70$R9S3CyN$#[Gó3admy/hn{ͭeX9it'-HdUяyD!06, wXvtOpM9s}vgfϖ49lIG[j5"9+=B+j?JJsllw"fN C1RvmQI} =4ETҲi&BZ eoRGoc,y_'uCBֳe& (s?꼟*$P=@;X,]{Eމ1QޑA 3qω'8>}"oE8vU@3%ՒA@gs[/|/ñt]bf]#{a+bD8Ս5X/K % *H MڔJkPFvyS\>Ԓ*Vgr 7A#s' lu.BoĔku]26(nL  D\=Kv.\;B#V񵸧b kUX hVyYx5%e5ƦGQ5ea]K LKU|UTȘG>I5/&!)A9A/ͬG.rKti2*9a]n, srwMPg#b,W^Pq޳;VxfG+6H`sGAa;s1G ]׉+|!O*|(/UWX/!੢EMT2 ViaY&p! Roc]ȬȦk[I42l SS7Mhe#(c'"3Z0 y5W:g;N^!Uy~ I)5{21TJs9eHauTZ_Y$#~alr 5ϪʭMm.l#oc͊wJBBg^ERV0HfG>poSKJU>$;m% c ^{+{Q{ڛ?pd ѣ2}NA aHmXW8,d9ջmsozi}A!3&Aq7/Hr2kN:c0)"b-w`#{75,_FҎᑡYe$·j}c׵˼d M, ~ŸǼN}&kb]hKLCIʎ-r^'*wގ#rzyQFm鸫ƭ(RwEԭ8uXT˟UPICwbR>9PYsVPP{'DY]iˑӖ␴t\|"7 VFdG8S{r=SU bWÈ2 <{u;0TImҜ3Q6NuF7(  RwHC Iׄ冫e8U\9vJɏ"Ų 뫤BFiv> r_zS#E?A#^c G?a;|D(Ci8tS*OdͿ{l%CbE`>E5Jy>EVNc7X8N " ÁJ mIL8s@ 1[O%Ak&HoTUz/:-AEi@H3-bА1$(,&& @k9Y-UՇEad!Sf}Bs PVxcj󉁌>(2qȁzc, ΔUsQ2;"-7j\Zd .Gkۤ䌶WȠri?gtI_+^ۻ}9u,f&Q|8 s@U*8=嚧>r\EFSߐ޷7GrB9>xFt;neWkפCayEҋ*ƽRHl<if?Hl.ӹZyorS@S=12uA6Q'Z@B W8RQ2RJ6M>$j60)*Ãy_hA. T޸IJ>Iޒz&?MэSl^+-*q3ZތYi1 'nZTV_^6(4\( >Dyh"8j'@o}0u;=ܜeB!'I]ዛRR3&~Rฮ50%V)%K2 u4Rzc("fֻd,1Yӝ!O[ÑTʶ,'١RBzƆkBM?rQq&,-Nl\",򨡲}w 7'X%L%ܫvwG&tJ4qܙP zJjzXq4өUZ>un<B}a"i=ϣ xVp&;( %寞mCn׶\a|1q߭O|{#) 4ۖu^weHpƕQmpѽQ 7LA |JO'?,4~&ohLRgԐȘMAWDPDaqrz p(*.9:vm8?鄘EY20lSoAIꪃFLȦ5m ͓jsreoHx|)"yMNAm1fW=#)q3[caEBڛVM+#' Ƅf|tz\ϔt:ɟ"5ow_p%˗!"XgCetXvRkt4Mwg\㭊DVy1:NDH jd^8j(ێs<~rxm<Qw?}Qrg}Q8W k=f$.үy(TN;QW?W#|dg Jeytm jEv=g[?.eNK$ƝLȇȌdT F컄cMtĕ> Mrs](t_ Br葒bC}a`H)LW#1c  L%opgt{!ڋvv m*`na zZ22 wk7ꅠK:zm4V $F:F]:eLO,F^`HttkP*[Un]H:CfU_#9/]-liӔ|Qm=Yihx˄jҨ)tjrB`+DL)CᛩjG /5N-%t 0(h,;rcgrG\_$:y mNǠɰzGVkC9\C Ie܎1v|W8\oX- &E@gx{2 ӒƲ>ŕHp a*)jpjfDTϒ9hIvmx~ו0BIqf+;+VagK胰Z|!#ۨݼpm1`q,$Ěth?&x9ө"Pz.L]%sBFYc;LIl> UɾɏH`u39w_Q{faS48OJ'eeTyǩEn"sT`]IGkER[ՠz™5\sùgnPNbX]9D"7@ h5jByVpgNn_lqX q'E%CgyLL mĔBZ5%ޅؕهQ5T0sZV/pRИ~eZ%fhjX^.&6]̰P-o9_z.cZ䖠KVT,:9iwJVZ|kY1 ~?I,wI'I PQ|i{xdqGV쵹]; _' Ӯ+o;'c?a=R>yKSmCm*R`V Q Kw-"P:+4n$aoн42Ը5y2hN1ǙƝf"|(M5zYA`[9JD?!KOE^zN~t~瘶)P@v&O vEL*-d'8c& &"0L-dL2 oAbIYԡDAb<ݨd8`Ed =q-X'Hb4sA L?UA4䩈"$<{hܿ<t &}T.)gL:\ L.=+ތC~𻟳7G얍ѥ֏ &mq/԰pE/ R+RQAcFS6 !$k2}E%.wKhf$6mwBHg(c=.oP/_Py%P+G?.Aq|O1YlvgTE bsݖ"䛴w/?ŋ=؏䨐]pUKO᷃Z38R4^@HU;;v iD^ jǒ#a` _D71+y̢+ gK&BM߹^{~ +YҮѼ@Xo|iD%3KPH[Bl(_K.c Nde* 8c;oe0aCbI^Q}Uz)uk^S'扴mڞpxGdki %͏9JL k59D ,{T!aU5ccE)Qv:|G$ů;rGj_S\UuښvYk.F  ַ-Ψ |^:}#HrbGX2Obע4^q_ /̄_zdI:4Ch4=(JNvUmXrr\j"ҟ%`GGoNl+c,mo%2U*h(צ{+5n ʥ YD{e8-gESoR1 #Z]h^n>>FɷU}eCwG?q*A*-ne!;?uu†b?B焇1}PkDGfv׀ղطcw#G!u9VD8>ۯR+!;A>+\)=PLl.t{<}'`kRܮqi66%JdW`C4As# S[ Лj !hE9Ggn E+Zi 7=;Â|6kФ ,bY0aAƿŋstGv5^mO =guxm1"? LbP[19.ܦ͕?PaR]mn^NOzSc96n旭Zy_|u+E l$ Xww^2ɕ `$kpK6@D6}\݋k/ /[{ʢ٧تE6J΁]cTMMd =* .ҔE18^̏=&PiqDc~\=:tޅ$;CeRZbN ` Y͕ϭ+UA W[ ؉P,m.⅚<(mde)aᇴg9YꎱT^F;q_AȸVrp[IS'+|Jۙ=/E/}7K7FɆtG98ڸę`eww>;5z;&\,`λ8ykM>RmZdĢŀ&M{M~VD=:>YW÷'? dž~RĐ{Ɛφ3psP{yY[aɽO$[SNg@7IAU̍V_r=hʠ~|s3gkh$|&^Ɉb-n'lQ.öIR@KDS8L:Ω6P6[{zUp֙Z{ҝ`|ץLbkYhac\$'$#22beq1NwuHMHS8*>/zeO -Jj<+{`,MYr ҄7|(}'zl0ic0;Aw}!qWת>,U@GM]m Qc8U VڻU?= ISe9R u4*UQa)#^h;WمOKR!cҙO[g]Y<|]ͥ -=dU2#Ns8A3 Cۨ&S,SL5`DF9`zXrL٭#9MeWq!nE/ש_UpV\*"XI_JCOKt蔜C @Z0nՆ=męful~SwT::zJv]5Kh& nUF( 8 2mii3O_mH^=\[KE'@pΑJ.rA)b~0C==$DQB\ $n G=QLP+h3:b{8\+BQfq9EEΉj\*?Z#VS+دRXpwD˔fg|sUH @{}DfБ',y3[iH><|,٣EH@)6uͤ@J`H!B]= p!Wiu-"?@9\f[~5DV!Q 5Cd|/ʾnhϘ wd껪_v@,yJix"1󚢲 Ia4` /3+J/i|H~<=XHd3o?Fv1 a"7(I,޴nlPsFL,p5laCs-[N)YIFFQ,f+" mg&um/KjGt1WBXPokMYbUY3 @3Sh_2pAq/bdq੏c}Ȝ  i:f́Ώe5}Y/_n1Ihed>ҵogT5^^^Ia:(*}>#DT:*3=yzxju5K|I zW LS/DfeXr/7~6WtsH}0A78YԊ3ݳ;aG $9LZ*4oAo%V8'JzLHW?W~Qw/(1WRA !M)"hq!|%W#'$RqD(:k[z}&N?ԡɥ{5 h8(,Of &#"YoKVưD}7%C yܒ .Gsi/i,kIRbͧ"#V+d5 rԾ7>ǙF8+Oh謗ruwxABnEU+Z@bM çcb)JI 6ɌO!+ >CrMۊ$m&ӄ1U`Qo?^AT6᤽RʍߊRS蒐Xh]4P3(hQ}"9 |)k}{Zi8åĢ9gߝ_TwZOwbv$&-%dR pיҨ},J6|(t0dҳz5mh<5c@d/n;ˆl8p&w ].JukE M2Ҽlwox o EqI ~j5N&G ]ոJ9XYe|D9M7@3xR.H{簑&(TWh!d +X(GhuI|ρl*(_ICFJ=HE'鸲NWN-tp S|s7], Vc n4wr)YFb`(e HX(1^L34/Uؤ zh?av&^Wěf{ʆf&D#B֫5EZDžz fi@zFW`"A.o#J65>Rv[*IcPM5̔0bue9都Lr q ēit;^ m=ًsX)*AV:09!.AM+LW%3 RA~_l|~ʿҾHfC_GޔߍI29-dE'ADkk4F/'&}Rz'VNp}3ШZ~:,wX$k6Y8к$n=8? MVsAq+nz/Fͷ42uzxRdc%<4:7e+&Y%C~svV\gncc.QO|qf޲~R-Q$/LNfŠ,1gP(7If=Vap0=l&1*ǭbeUZŔk}P@g[n GU--#qB x"!>\_l0jD"/@bT4&UEQԓ"*>W㐖7 [aR-_^2:bc=1'=+to_(&j.Fe+LFN1%qOȹ _]^oZڣ(`V6h.@ }vWKN!ޤ_a3U\l\u6tvMkb6U!)eReXf&5 \Zt8KO Q5X媗[tl28/(fT0 @E:LE&]kauIW ߼k%bµ$J aF}]PkG=ee,blJtO:gPKW92Nԃ 2۷ς6ډAt::VLłX1$&QFȟ ,ǩx9Pn y"9Vc =gy{·?fӻ%_ﳉqȳ0 45]1LK1PIP ΨJ/Q]kJw|Sskxq>|y׋;o(~YIƟOX"p#)I?GtY0 kY#t P@Sƻ˷B!U~%@}f )ju ȏXH9q_[=Wkv##_HvK\Ҡp$Wv&ͼC2pK@(Y i& 'H u88#M޴YqwQ*CriE)\aN$gt*1'|{7jٍȯ)7=6wo@FBSKH:ʓ[':`\y%Yh;O8zA*M`n</1LL/P~*/~[:=r3-6vyR!>"A =?5 nMF fϙ[hC`m`M!UcF&| -(߈Z #5 c&gX짗@[`#3 ֽv!B~WȰsNMg[/nim#_`nh]@.Zt~#6;dc >c}yxYc,[\֏镰B M}ŚUN8b;kAߚ(ξP|LHV |%VʽCY.!{p7 @ÀҨ=_I8 8U}H֠D[&+%@Jyŏ3dlE)yP֯^&2(DB^dFM@lE* tLs8mYvB/~_y7hǗE-* ӣPz,f2wWT+a/l`TJP_SU?w$UF&lpuGKCbGM+ w-6^OV19w":42-?ɭ{ҴV_p?ls;CS2zr% *S[<<!)dddZQ2Ȭ>G&PYDܥ7YD=7RuN%Q F ڴc-A*~ƞQ͠0uR`TLByBrso;&h6ÿ' F:ߤa\оZnϜMM u>3$OThKv#|+: ?`yurL!׿&i'~[W5@·K{S K]fʻC!$s'_~օte޾tpgFr_ѻH>?{L<*wȜ_4ScQZu=y—X^n .̡"L=&A'OHhhF!23m=}XBs ,k욖p8ws0#&h˫nt1¬u u ?q Ne ?lvIU(4.O9Z.zH]ۯA?1Rc Ke`E00|֭p+cSlH'4C.w҂fY}6AJqWQ K P)E+Xk%ۡЧ^|rJj]R=ʯZ/?g6 Sn2_ ~ثlz`ZzxgF$f3ԯ39bic )4$ yYvAUʮHp§?P,5+ cʽ ũOW/ |_sjC%K#ay# RxjmJPiXMr,?6jʽ% Gؚ rOnȢ\HCn yu!*"܉a [%UAͯn"Ca[ ׬ y ĠXPSk_>`x|(3]g8 O!%$T:4k2: BϬ]W/fT:sjw)c㟀内dZ{Bф2ƹ&Ι(\mpKt/Y@y~*FDfN_q~D*7;L{-<7 ; e3Y L"UUixtm\5ӅcSW"7\l JLÝhC%^swY-rFW%Ւ7!A(ʕamQQV^?JR (`5u ?a*5̧1 fm_p[s;XƯJd$5=@z}@O umcH,2AZ[-gQޔ ;}?XjLUPM!'ÿT,E(ڣzz7{z8㲚"nblLCXH=/z!#k#sF#Nj:6"ʎ|&5Bl/IʹpYw=#4U`<T 1J7Y-'wP8aK8| > 9zy/Ĺ./]`=?#N{/^V6,~t/\۞sς?J&uW ;ε=f 9OŠ4?7k-~"7oI@JdsKP F7NAUpD :w2rahRf1 Zpsis$c5vOj׽mp^0o`"߶iZֵ6#_з6hBX5|r#XF6ݬIr)}ihKOt^3b7xvDŽسWֈ *U$IMB c,R'χcl !p%Y8Cu1򲣆i[-a֊< t4`S׹&X0i5XޛF .$iPzjԯU VgKoҎ t{ ,gr.ѥ*o`n z}:o+B8N+ :(|A{͢Vf#f(ø#lXaE0V`DŚu_Pt>h-{b yp'շQsB:w䉰89m W$6!5毙Jn >y7V[0'N%c.~]D.!$|vɬʠƼ~EW|xW|5D zހ)&mzX(kL Q@eFv{6`p{R;"ӕ m&vU$T"U14`^JGd߼GJc4SeTwYx(N`赮$qVχӧ#z8~P(6n^o3 AlZ4DA kE1!wWg $7xx?V'_)R>FZ%r;B2Jࣵ5Gҍ2N`jۏS-LSa9DUc|53kiKb:z\zlūx}C:.qbMq~I4{B$pAa..h!یFbt=@Ψ~Z `yTTLha:RnnP)}*"3=Sȡա=5VF "`o?@Hj1DJFTR·QVC-WbB$g 6zD_oWu]δ\N uċB 37l7O)ǖXlnYKVbA$@cvjx`ғ}}Ν 5^{hEd#m] a':D}Wz[KvАo>6EPT'iz `K>} n@êBQn$Fh.ڢ2e`~R (HX%W#dj~_^iHs`1Ӛh\*}g/-GW,Xk2YBjAۖ\{θf(i|,`N&,`>\ZEvQSJĂ_B]M 3:c G X3  rF|fEv"s )M 5 \P&2;O? |vާlE{xS'OI2>j42XfMաb1M{:hgs V oA@lr$<"Lg~U5'Q}z]"27*#F-'J:C%95J 1;,)G62v#ƶ/O4 d__ =B 4QdL /Ci\B kJtqNH1=h [NFNx~FR덟B WWN_U`D(Tpz*@¹:lVGQ95T|r2eJf,8 xL6`4y&T!G&C:]prgR621 +OLCOꅬ:-_Fd\:.b{=n b=|y 8=7g׹0M C 9,*fh⭀&3DY5zTnv%x~Jؤԛ"%i2]:аx8A׵ũI)Bҁr_9ҔP@WR̨NKځyNp;/<6OK0)潖7gS';"޻-j mbE~sODl]>Xߧ4F;!_U'(\V3(lW>j~͚U-Hb ɫ49ķÝ e|)$%$ (z D X5#V+\UzyN Ȝ_V³8٘YK!#;Y{zb,57No dDւ-!'=p`6ȮzyQ]Ko<{V)vN_Q;YMof˦8*_`0r>Wh^eB>dK_0<:69稠" m!Ltrg7UQҐx!:Sz^Щ2,|E*_:~HiHvyUO)bfDi×9T}`F|.ܕb[ֶs/C>~+@ocuwl7rm\C%p~>jg?v"qUr(3}}}> ,k;{jpUuY)ttyt>`(8|20Q䣙>W-($_J 8#G}BEz“Qzr/3l͎X~J3? OS\aw;"aiAH5"ӝlZq9#%={.\pacOܾww HF έ`i{;)mS~d &36 "$`] g#@,z6#bSǦ\ fDcо5`偙s K[N6~yhmIϤW\5D,ߛI5&k?AAX͌CepO^aN ȶEZDF| &$-O POy4v_vaCWױqxmďt!c\E`T)i-ptm?kL%:ߝsΥ^# Um--gƽRnukns\y"?VB]6%Э6gP119K'.J_6 18궋 5yR&?JpR. Nv}Hk-G]ʺiSi0R Ar8.=q~Q!3 /`]'4"f= A#=)oZz nƋ΀ؖLe:HOAMTĤaHwۀÅѫQw4kH=CC᫞ɲQXz4EPdI֥]gkzgYAJ2rHOsA,Eotۥ]㽑8ؑJpdH`P0߳Ǯ>W[9B lw7#E?æ5|y4VR7M@,3Bu+[bABɮ5<]x,җbPghze/Rjg'5x-ggb, d22}o3='Q-Xv\J؍l١VgPߐp\k҅q TRծ(e pcd/2eND.oB{^ Ua g0Xn~J E_CUO^D`&*TQފw1O&^w\bTiAm֞$4JY[B&uY+3OA8DXgD^Txx4|P,/_mxdWZkB@5% Y ;MPe+3uCNJBC w|r.p$UQWuE<,:1x}xvL6$/v`,!nMJq##hD^&Wo;co4%P8Dyg6g.\&WZlqWb<2Lr ~sR[.*=+Eq.Aj&J徃>6:+91uBamΥqDp mD"Ŝԋl/*!V9ϧ2,;2GcyMfxj+P6ܽ 9-?R U4``pI@mzLLmgqu`1v x?1!=J Et|cliVc̅C>4pb0Z8ꊜ33J|kp_Hya+4z?Bz::_ ܗgkG rs]ˡ2N!<9j 0 *8E `[|nNdcu|HԨO\)1PcD#7D)3dT9Hw[&#U=yqxsrMpr_o;0O|Jh2j̉#vqCћ)~> 䢶 qWjZGC&112U)nd~n@̀3&A FVk@2Lx{XȖUb$@soR_ԐM')ue-+@K=J#w=! 0鹀4U ;v7H~Թyޑ'^Qpi%}iv4lͭ?|6[N2U'cBO%%|1gM 87 ?bb$UI~Ԩ{t+e%-R ƥ+J0MXں䖶sr/r?1'huNFy-ۆIdvuS)3ZrZinfzf=K!G0DżTYQ2hcSx@]D[GC3)R,6K$ua;BY[G꣆c  w !GA.^^AY/`7^x/@1Ak5F~mbΫ/&Miq_zdi3VV8EԫG0?])T܉{VN5ƱLRw58IXZXx)+\b 3mYd]xI/hNt*,Hm8LWUc~Uk b7 g3R(OoLuvr*•j¢t8 sɳnL8q=Kpn06CBϧ8f#0 9Z}]dݜeSQRzi܅+z'RSmcGj8.7`9SCJI%Ҏ%3˝{#I}m<7`oIvc@xqNF ywIDI꫞FOn4%ձtjǓ[(HD0RFH4#j)(Zpv2XMz]+wɯGrœ+^K ,̲N쓡 K qx~mPH ad<)Dސ!GܾG5V8GdGhlI35Au+腃i#n*A,ͽ`N0{ Q[l'^Tw'W1eلi4=AGwX ##{vh6r űǓ2c7gMtpaY# ;}',S*AM$r[Id饕۔9[Tl1ɼ9'dgW:3QB-{Yd,(b7>6% WeRan:ZjP\ZFx Ag|E;hZ lW_rdo*bK4/^\3ߐ#1Ww끇2=]fG\R ULŰ)II7^ȅ#ٙ}kq;t{Ƭ5DъHs Cib 3[+TUEWT٨ X'h;Pv|¢ y;McQ,la5.KTx.*,N6G?wG1xF&)|vI#9pc U7ic>H" -Ѝӝ7*D,ő'b79Uv0A V(3 Z(ԓ:yͼkm]D8C)-ngr*xbXåFz8;#pRM{T1 zeLD/h]v2N(D%]DJ\u!E`X@/\qZvgo8/KռfȧH޶kx@, b1P;53?ֻbfJb/{^/ (ĭcS?/ihVɁkF)۹#b n4Q\{>c OBA hy4( y^n>Q뭐v^C F5=B-7Ԇ d2@^}u>e85;ćub;(2oYrףWEgƝGkVg},l7|+ݾfޖ4)RmwCjȷWCčq6g!.<{ojV=dyj>3(s,H:4/Fw +^ƥjnDvq]Dm3 CeuRӤI\!m?NсΑsZXNCØHJ]#w/}(H[ޗn<l55c8 RC/XED{633{hV{NDd2( QX9$ڻhOMH|m5utQMDlسmg C8x~\ybvp>7,+=% ֢G# =*BԡXr){3)led^0hv 4Kz[͂n^XǽKi(xe\x}<4Kxͻ-Vy0VLt۹o`LfV8{oA蔔Y<uU:ic3 j c*B/6ө; ڗ[&T3 wѠ2I5z gTxUsŜ[z;Ô0"= Q?:h) 6],`tOb@mE@`ɊZyCTՙ?Ny"*>RmBN 5M*WF?OCwժBnOۇ-vϒӶ+ɇv"2xՀя`|.2cM ȍ1{G5 y^V07|5Cx4S"U3FH>gB%6#q7T#I(ezXpd$4xBi^d;<%^ P0:~+ɚpdr3J7d^8CM|  NJeiiBNWd+z0 6 #}g'})7U.!+r-iWW¢[[ jb@;\s P uFB~ n^4"Q2ИyGѽ|{3JL)륵T̡B$:s.0.Д==J7gJtQM'MvX/(ֳzkyK=\aKϵuWw& Q dH柂eQoςy{1k cg,Cx7r|0yr{j[IѰ]U4JŪTZpՏ?>9—jV9(+5Ӽ!U;mLwuPKEH=<<)<~# japː 扲f"}A3 !of.b`[wDH]1JBS3g nœk-ݍZ"~櫱cJv>!Zo^].f( w1g-JeeD֐-0/Ä@Qy;M/5ˣOnz TD[/V/mؙ :ŢFL=E=TC;uwo5S^jt>p|tO+xPg~RZ^-"P(}Jb`X~,d~5z{jGeCАw j;T_>/϶"QBQ]orsÏ]Fborq*s ~c9Yl>~Ӵ!NFtaYWcFce*PHǏ7{=`7;V/@rjoCeX"% Q}DE9?1 ku@vv{ ?VF H^՘T`KyY-os}zzcj>b !H4yOPzna|taWn%^}ʨ(#sr8U`sfw+g?0x6!}eLArx']r58=}}:ez~Kz;qJXeиYeuB,:R'}g2h* 1ɖޑi-EZ&oAeG[zѺ mC\*iʛ0y% >Nk\WϘ~DD k!`VFWbƨWjjp-lt%2ΜAnrF߂h|lۗtdXHv~Iya>URa. l2U'z}Ȁ6Kʙ@"N9ԝΕu#:񐳁.7XQhҤ}+͂e]`[gP0}:)0IP{ .ﶄTpZ%""%Bx@CYXf\CGMEug{8p5>iO/:Ƅ5) ,Yi6V \x[n6[&?& N v*3k)"ػ|ŢM!뻈L~UL0` Ɓ5N(s؀QXUo!ר{e Kaj f}h= RuX^J '%; ؁}x^q,7kN l#kyNjIqz'Яa%a\s싎CJ^,otea&|kJ.)Y\w]70¶KkNq +O!\ N(>G Hfl1]ouJ*+os{C^~ϼ^.WD߰l•;@#an*?'%ʓ(ZyYT^1pKA(k.֤厪b ߋ5qYOٌӪ5uņőxW{ 7:{5`3Q�}`1sN萰#@ށPG:Meռ'4" JN_sie'>&W-4~._ҴX̿Oi#0֔:A2V=[\v jW%'LM2aa{KʵxuX;+^X9iL/ d _h<_TKZdž^Qދ¯f{è^>c` &yO]'D$} g"YQG)hfz/Ҙaqg-&Z_%jNigXC_/ZG5@ Zw##+-..~t2Qfh[)ljuv1z˚6Lk۬jǷ% ?I|~ݯT=q!)!Kc AŊggWK-pyCtԺjCz5IYul +5UH(+Z*B}Ɇ6t p*hEbJZ_9+͙"_[=ZyH!K`1֪Lk؆d@<;{4fz}_u"SO;!.=)zè'SxY ^ipncґJ~+L2u> p&_a[D9X2zoc%9T%&P!|D ,E߂7(&s9uXϕqxޜ=/&X`!ԑm 5|r4Z& IJtBucBEB 컲I ~ n*dVa30|W1}Jjr%W?C܇sFmU%4UH% ؤ^fB͎3ٝKЊ)!PKq!Ps7\&%hٗ#ơ"-Mx'MP " qd4zb]_>Ė3EbcFw9_@s-MdO<H?tl2ǺHab_g 1(`s2չ!fkú((´uy/C@IQ³~Sh:=,DO;6@s>`@虑 ;^y2'+X! lώ-^9Eɽ^ h8"\RD/ʋCXɩM^܌r}kdK05Gx;@QoPH~ٱaTH TB=L-/]8C&*Q2 j,&%k\[.pH7/Ml/pbI..!EpV^n;?WAr=SϖZӱCTSGJ4H>Ubپ'&㛟ymy#_ ,*ucodY%߃NЭ}3;)TS4m,R`WLe#5WRaw䦁_}}=R8l(]&FQ\vnɠP+xT$EIUضsW< WbgUhv݇3lx/yęJX34G_3]u]TLn' ͥWvz k %zrpOK-r$@&_q ̜Ґ&um,WT1dgkmuh0y|8A{S WmLJԙ)Y\:TNI-5:rXlX{fe]Bs(i6IH.g2:G@H@gs: Ye/ydJ'ǘ y:sՀ j(+lIk)6JDNHy?e7y3Ɔmq>$<Oi u0Pr Xtk`vO"sĢ;E{ZjI'Θ8H$`#WďƳdbf6j5ʠ0gh!jsr`î76Ҁ%=\)4a#vN}jHvnj!PR;Qi8ʔb;$̤圃<:9H* 8+1}:&^8`Dr?R{PDŽd^C'6\!Ae=Nyb $͆ۅj2& ?ѐ @(3\+ 9Qmt}ӄ%(ua򭡶@|-/ܻkHӛ@|V<c[(ifMm!ݽSjX1!'g:TͼZ  )5m(D*(^DGD<Ǯk$PS<4{V{}*Mjּnذ<0'ZeE6+֗u3 ԣϱM@Ԙ 4[ؠf1{ lb[XϴL^*,'&@(ݤB ˜/b~qW>(hN2"Jpϧ: nq6Od=i-K CUK0w(#m@n`;,%ot}r[.\L@%zWjlfq`?L ʢfwtӍo]J^ WxQ}r}z}Eep,$9M&_6~!@GH~V6]||r?4Ew5E҃wgAB[S<#F+vO- Ll”l-ž{<2V uf{R?*%3ӶgrF([FاCd9i^9QOvp|{ۏo&pGR$n5wbY9MBr݃c#@0W<(k S1X-g{z*9ֵH <"J-DSs1!|Y8ŰPMUj]h;(uհN;/h&F՚㰋b5eϺ9饣QBGA v)Il" nQ ?߰iՉ)Up%!:^N)gp/"`5CK-d̃^ߝ#޶SqM٧Gi(;^a/[:~F}XJ"Цgef['食^l s+>j-9wtQ 7Sffǖw'wGNu,1Lj<ۣT~)iGYI+| `*Of%\`R4m8r1d๠;cF)h,lagȚsn fVeNDU.:甗S\^ F63ڟj S190$6d:N!v}V؞H{GD͑]$a wPX9iLV{)wגtNHX9E ~m>:GIŊnZ *38˚{DjjsjQͫ4UߏREk ;,=,#(ʗi 6- rkR(1XOu.wPσ~h q֗ fi_#T}q'rψsHrdg"!ճx#lO_=bA"$gzrˏvIy}\Ÿq$V.kHBзJ7%V=aBo$n$\_k1Q3IKGN Ivyښ$FҶ J3\ҍO'L 폃6o:ђZ ^ZAa`,b+.4bfϒ>"-T|r{AZh p7cV`DOk ܰ<M* `U%$uocjc_(,\osYH]Ȩ v\Ƣ<5St^cPա-ga/Fa^@j~iz+$0¶Biv995G cyhdZ˼ JF[#-l)F;4E_z3WkǓ OL5 A T 1O'ϙ #-7TzP Yȓa0|Eا0r .((H|Vb\4b*}y_=jb M_ 1e$Ioaꯝ緪OЇS;SY⤄j#~{z$O gڀٍZHb>m nx12$Wƅ ̕c,LČ|ͅsF,<[: #M-D(B#=W$)6m\O*ӻeE+sc@H?z@"'l*)8d8Õ׳pQW{9Y(m>ߟST;t%V{VGe[+7ʡ:50ݟRAs& J'R:# lĽN?Qus'R!3d=򨕊puhĿ]CuT N~h q9eAډ>sc0w t H~,oݠN5CbbdܩGZ Ŧ Ï|2 Z.zTN*AYt} Y4Ǘ2} ʡMl{dc펰F{ȡOЙ*тS/jY_=56H0Rw:(>GS~$_񖥕ы0 ßi_Z]3Dkr![z%>SDyJfI_|'h>Tְf A1U3nnl5# Idy3[=MKn߄~:3%:=7i}l9Y"X *="&g=COKM8O:)DʜkUjj } KR_I2c+Q}Z<}ޏ8(ObZm=7OC2`a-0L?-TiG6a.#d* tĒA1/O!UZz28.^=_Єu8~7i+.?P:Qln" x^W].vq~:8{0K窱s@SP-Fx gr,r 9mpo$y?@QZzZwOdCjt:~.K?Т*W'aZn<}/"ij3w JteMpfgޤ q\2tang<|rZ;xzpy k{hnofkcjvڼ,Lw䕳/N}[H%3OA tUrqR$!: {sH@ߩ+ Op)k5:Mie q&ϕS] tc/#+;4c<@wBMEa.K8yɊ6c4fFJc-Pψ[LT$RO3ם-Dq mH&wm:0O|ۋ9UI/ vgD&HѺ5FU}7ICwޑ CjD\A!cZ6q e<|w*ܖAᰄdTmʱnȧ.rțVq~kyw*j.O$XJs=+r5kC&M'A5-NGtI@8Qoq dh1ugUS+\_ L]^v `̦.id3ɼzmևirI)liMa}֛Z;˓xqjMI_Uu Q&/Z.zn5î~;Qn盫[BN}sg]6v>멑D k>./yhTOs0gtVgPG,1ŹS>pCLN5MVD?ǜKQ|9;yFZ|߫~&lȪ>*6p zWEN,}^\neufOɰ+A ^.<(<>Ӄ۽QFr!(Ʉ޽[a' $qhq%I4 ]-̽[_w{< :3H<uA5˔nKÌ]}c 0Z>{{10@L6sﬥ$ԗRR6{ѝ55BSpJa%Zi{L(SDgܕAyf or'q+4ܯzH xakTu*)ٷg]бsz< m .{Rqש _D"JnA$sѾ.3~Y K&Imw|7&i#+{#wweeSEqqˏЋl.o(&W,`e\,jpr*cNGU]qaS*,wiV^*?#c^27?\Xy^'f&GnxGj tbEt?5lZϺ[^NVp&X&zR%Q9}L@cB>rg{$}E++5.QCoH֩ %yYfb0j'2˧n"ټo6??Ix(0>AZ0ABzv;850#ξr(/>1ocNLXu|\m58NO ]덕FLxGʥ&gT!Ȳdt"TwRPtM@ߋYv/Πgm։}*14c0;rVЧ.Ս>]]?yQE_.`"yj ouXz)"U)eBJ-([Yuhm +55%yi&|^X!p[2IꅘeY_7.jt1zu. WҌ퀍xS%ZHĈp?fcQĀt*Jj9/I]2ְp]m=&(SVV۪GRHpH(34 <#U~CI+":m}!2"ԩ[9e5$۾"̠>VjQw 7k/t q=/Srv9AHPW/÷U6 <t=zn/xW:lWp6e {6 n@8K;.iIi  ,zۗBUA ۥU>=,K &aS6j00NPrۏmԖyĆ7-nֱ:}*TO7VnDZ9I<ӾwчbnoDj"p=[Kۯa{Xq4f.\.P-i+Гث)X5ST`Qp/#rYQcaqwc*01n8VxZ6M5%n/8}in6# pAy27-%g뵡 G9m)BbzpB.l*#sWxzo>J0y UO]Wv@/Y(Ey^ FB Me)OVF>\eHADsD:d%WkCo 3N^(,A;XF9'nj)W.IZs(3e fs^mI9dK$[e(!R<RHޥda6k1qT'xlynY թdvX*XޠkNo똼>2f!xrRXc|u)㗦>oW>iͼͨBͧғT%ht7Gd&5y,΄4QRX*\ƪ$E x1QjS) YK!^/{L,`Êk5Qgm~{-R|#͆9,tU*2Zn0Ryb[Fe!hYbhLԪ]nтt} D:DM@zcMrH-Qj[~[6בr7髸QAd,itK$MhJH*,R$hJK9G4FIYY\9v,7w0C=}KDKoϜiz@yڴ5-)A5oEr U5^@(@?[cpS/qцm .Fe%%+- <zoD8-p/cFїxD#0Ŝg?*讛c 3p/k>$ytϑ@P>U4f5z%D&.[cj<ڡ9k*u'OQ&oXᢝz*#Z d׹6g^1!"c։=SK>mrUon= /> -I|ӣ; ZDɃac;NuB\ĦzD}Y36fYsbDpZFmNAz:İlz0L%Q1?˰l:~wUWGge.ɨ?}5ګj4HV [Wp1t<3nݱ;}9PCM6yeKn` j>'8Z |:U1ͧSW.􆆦Yڬ9Q8^km:OfX+lDb2xL36}L<.'l,mG\b}cOTЖPjV躃7gs]NQ(uWhHL/O]NDLc=UߺT}_ [\ ku כ]bD[pd!}*K(ܪ @F<]@cꙣ;7aɌ4HjI|M=eqQL+ ޲L!,<-Gg(3ry61~GQ ;ާ!04^*MoT> "k?j@"F}sD9Z[Uz|scK»g_ !q bgsC{FYlS3!b{<R;Bc7uIz:䧞ޙi-^1Wop307vɉSKM&>N#83 EdQ;`/6'߸M$(LgCpIh`Jbbbj*c}@ߓs/f4 #`?4mHPk .?A+@>m"C.+)S.a%y5IvٿIT[!Za?˰uX*@ uxgr!,-yoȋ=l'cjH)"lʐO d拘p 04o֟eM{ʌ˙oܶڥ5QXZ)n!P!b>B OPb`\#.S& K UMQ"--f'f8H?8jeN &SiFzSw&40x˵2B> 2H0A@F NMl@),is?bJXDAw4si[:ޑtBxu|U5纭&eܶ2诃5o2 Q:TmMro]r^A(pI1!6F66I\dJ=vV_Пx~ȋ8A!ʘ?fEF^ LI]g_pJ!W}{:taOa A%p.!nrN0#S 8Io]9,0jҠ^=~;Rgؕ1m}VT,bq%&;x4WQb @!Yb ^[†SXF@mTQI{ FQf?d+N{˟}G_r,c~(-sd6/I_c 6̒9~ݢe90-Dg<ƸwJ(WQq,IΒUx`jGU!:BaRwL&WYԔI!4ki~d-e_E5u}&\ŮRak؉s7 aN&p ۤh+&jqڴ#[w"#qKg| Yё\4 EǟASf2H Lba…H0I4TӑKp J;e up7,iqJEba^JwuDBVDaxBmڋa1j sʤ(+$fssᗌ@q6<*xۯDRD?w i a ,iS7D&^wdDeKHîϿɨxܯnzu:\¢mCq9 K⑾Czjq+C;/ݯX (XNpK*5S{K׎:vwצL5K 8PV|v ͱ$?5tCU[ku,yӿ ?ѣ\[qbWOIWf*=9FAWtD^2ؾR2ԑ(VaA!!%[a4u{0̖+@U \D֎ھm;er\s(?2yvGέgFԑN9'pg!sp b<6,#z=yG܇; 40ޖAכf/(MN0Kk C=j[Ȑ.K[D5+č [Sσ@QlR]{. e_W;½a,t@),V>~TiM!Yd]sU!o[LU55$XRcъ :f&Wƿ~6,6he1^N^BHYKB5_UUIj& V$j_bwsh 1E38gǍƏ߯{ *Sͺw:g?Q<\!n \VJ޴#WU|d~vWJ6ߏP^qfR!&ܔ mW5jJ~i΋P?@,Չ/6|LMevgL&!&-n4>!I.|~Kb|7Wzb"rϐMGoNNYO.W_^;h FVT?#y+}gLDE1d8dT9_/6˰k]!_`X'K7 I ŬJnyPnSB.+ne{Tyds2p!zD &2O؅ FxF}?L͌Wu)6Bx8g]>(3+ ٰ̬[TJkYk!0~T͑}s\1q_-/,F8}<捭0ZJ?ĵ#~#ReC/hxqZRo ZR$2G*ZNz 1Olp'&O=h" d|Hɚz q\_Etyْ &9a17J'R ιlаJ0GnkI:ASr4|@5{oA"¨eN^1mq5Hx[>3__~ȰGuvwb_1{A~1&t S2wَ{A}$ja .ˁ#+ru՝4:~9Wof- 3q/-ZdiS_n3s1;A+/}"*zaG:ӽZC@.>A~>xQ}vOp(RZ cC>EN="@eQX.ȏ#vro51iU(R`Չ ] B{j0gt/bg(lI$?K`/P, ėt#!'&7ZG3GE VH- ]c&\hNxN$T#ۈd^y1kK@@qº'ܞ~{Rbl?V!0lYࣾ*8Lȇ7,S3]I,L l Lx`7A*I:qvPYw8anSVC$`:s\ijF r3Jn&ծ3Q!&BeAߋӇYoV k/#;|d"ϵ@J[eDѯa0I$GI)W z=\!_CF 50PztЩw̼_WwZKmtr{U`MF0pO,YnV6d9#,%;/ ep|Z)3E?R`^b( (N)K}-V3hA|Mr%b9(BjjVpOF;lD9\ pɱ.d򮕞ݜ$HkZ]VA_/zy"01n%ayց$noRj!`p_6醋ߔQ?∄vsTΦVPZ=l+%GX鄻6qsj7)&G$M-m&AԤJܭ;X8 W7!3+E;يԂKHRӟ"P4|=$lS pkP(eݡ9}zb=ݝw-Lhr=LO.W8;i蟘}G RUbS3ª7@pwHM268E><F.`FfBgkyB.XK.@r5)ȸT$,`IA+3O5D:YQ( ?Ð$K$rN5=MNAWD _+aK!lF(Piݱ{e[ R@d9{r >_NJNMS\8ja7 •(p!DZk+ShTL _8+c:m^=vKtؓ7u!@%U[D NaF?ѓ?79hP@2UfgdjI9bj#,2(4_1`1NyUA Zx JrI윝o ηy'#Juq{(ðĻnj( FlͫV838jҞbi(v8Y,^Y+ $p1CkY'Y$WRymL}>g.^ ׽ʡ?Sǵ ડCkgdL.7\\zV:$MfYh#p4z= ILAgVnzRSb(!!^ Q Pjt^0<4M#zZRWI60*,}ΐEkKχ@ϴش cujKHR H5X6"dH tqݻ5V;Pv9gl*eS"csw"01?Rٽu&!eI)i@6PO->ak9&H9w9A!tKS0z˄QF̽;͞uSp]֜#7>Q:c( FGTdה/6~?{)D(,zMw)EWvԗP--"jck~sSX2")Bۃ<!>a-;H[G3NL$yRebb V .%Q¥T&$OҮ:iNv=&<S;#}'CqG !#>C(#4wS2=4*mS-CʭC8veJȫ0J Lk6:pALƮSf/YVZh}ZN:IUgIZ,LmB([ww]`rq\l WC/*'>$aѺ#0|(vbN1Cw!*8SPFIC}H&!&dEV}ad=M^Z;@ɛ¡A5OqW Q:SPdd%[; Ɖ$̼8ّC_I~A0oQ#Y krKX塞?0_H|¾ ]ӏ =Nʴҥ : ]B[o 7zr*zՂ :#۱-+X"q@IJ=%-R7}nvB30-r4Tss荲V[U3[w(nQ{4bϔ2qS83~ס?4-J-6= zg]3꣈9u7ҟc654 VChO{Gَ`5[HĴ45CC}@22bm}5:Razd:Zb]#VQ/d9}0&P)R.泂u, mCAF¯dbf9*g'P<5qQyHEM8rlflvWqTzz2sJW;RKg3ҩ/Ӳ(J1i=;Fˉ4݈>6#Jpy{nMqw94+U.$HN,~ZQ>,[X͝=`b.2:-6'GF)-zql8(Iģa/>I 3se 1=ʇqHtk#HHj(GrRq-U^Ax"sULV8zDy`t[ '}e]} |0A\m !dSC&Y;>&d/LͿ_<'1m5,ٖEviVEg&٦EcEX0ځfK)FZ  YFkķTvtϒ;F7yKu=v;[=?ٵ>ej&3qH/ ,_U %D"Ub0@GGCȲRC*N5cj_ X)A4:b-Bݐ84}o$2KJc($֛4_N%2QnEuto^6d~-^n[Ͻ`(9Kɾr' 8aPxGP*WΰJ"#v!2/w0YU+Sғ$ȹ{^A){ QQXxmo)3)ݐrT4lcYՒCV񞂸t=9linI9['{oz O#;00B*黭-2l0ȓD;ovO@SM, SH1K9J}js73?`T^30*Z. p2Y 笭;R M`{Epu-mCZKBvW1XCkA} AzlILVVȞkBj32fvēk䢭v2s͝ + *06*_N>njx2+B.Ild, k_ ֶ t1(u+ׇLۯݟ+PK0 ~G*G*| Gp*f1)Fp,얰 8) \?1 Hq෦zY`6]T/{q(U:Χ?m4CwOHn<͖#SS qorY$dw*8x.}TD #BŽCK #|g)dU@ɥ, |M{˅xYдm!D>[ vW{}{rہiV|ƫ<.vqg4o(vA †G`"l8T\؂ >a˞Ɯd @wӞb 9;͐rpJ@\{ً9zH{ܱ1)w hjE=5ހ`YL(fiG6M·m|N?J:y~'F)/}dqӚJ~ 5?+اy~3r$)$zȀhxRFc7BF_ECj&5J{a$U saGcQ)4\LoJ,RI5'68zc|D\9EʥХ6ĔkxIۮ"JAz_H@_=,^r/h)I] ico KS$u\5?fį@{;Kd_#BSj*烋 ˢɝaͱL#{LwC?7i KyZ[Xe kXF*ѴO>$ۼnF}~@8ym fAJŅtHϲ ݣ!vkْ'nm}@PaXgAL5\K-3]Mٵyf?FC̀xzgka( eK |SOK G2j3ǒK__LꕉۨyuMCޠ|G,P :{JZ efA֤FOxf_Α/Q3 }nm>ryn\ ~P/Й`ԅs- §Pl䰾HVW XƜN. +ƠH}@"D@AcrՏ'Ao_ZD?XUo̓*)IicIvk{ԄkJu%կ. %| [;Gڂb_z&9$ip9 +b2Bckբحq0Z_UXB(^+VW`wi}]''N{ cAkf'yJ-z\ Ǻ".k3;:^a(^p8|*掕Gќi8L~IۇwaQQ3 ؇ϩwj B)Vy+ORRELT_wmX v?FJ= _V^8ōU1Y/v?~K>e,ͳqjdMl7 M^?6J:ZF*4dRXȝˤLDy:bPRW}Xy.R-&6-ЧCEȧ-vg6˘4̯rD_ Zʚ& )I(P Ö y~jz8vA.O.H jI۲||2GЁXl }"Bs}Vh?ɠz83X'|F fp X7z%؜F֣2rӨc[tBOvIITDW`>phƺ"hrf߰KP;sa>ZK3 ̒Uv:W6={TwROsK'=+Vk )+jr+;';hjtS4T+<tՂ@>4Uymc`)h2瞕]N͓JPIM14umcek]?щUE)G&廹З2s/XC-zu0o!vA[qAϯq\ZłƔz,~6N49ӈX#{ lѰl#j~[]Q~l(zb n%w!?x@JB uRup.Xl%;I2VlޤM3ˢ@Zl kf8t8F(Ky,iiMX7R^KXDffHyke ]H+xo# ʙ RE1ɣe8=>ƊDDI*TgVO(Ԋk&ߚve1s90 N(ya] 'lۄ„`'3N=dJJ}\g,dG+l:ga ;* i #_Θ_wcRv{V{* X5cK8Vhoc uD<6GZp eڔMLPj)iBȎ21d[6y:T,3Gp=O Ϗ)!r}p,ܑZn@hBF ?R${fAgB,SJ2H<@!S,zwۨ2kg8֎Ej7-o!9l% 3h?vVBY &g 􁁩%!;٘A ;a87GRW8kNF"I$nl|u>GT#dԡM,5;>/sQoX>DY@|G[)ƳPU97ۯ^Yp%rO =gjHjѥVTK`a6ѓߚ HJGCWB(Q$t֔ z3-R8gg 6c5>e*G ɐ.MJ*̯% @v"vD B_qa:?Bɏpgt6FJ @{WX/*.\N;,b{^)%۳PjעWs9ܝ E,B=sFJ( dB'ACL92-:'KlHڲL\Jm~] FL'ljo>ѳV 0H_}Ęy|ȕNZ_[Ije𬽞7v7vo| yFyCyLЂz<kz(%{bzx|m 6x 6c{ژZ5i9өYG>W^<\C \.0^"u̶fkQrlJKUNSgڄaQ#ifM嫼.$&2/?T V 2 4 >sfquz`xIra}zsL莤,oy_*|*n;y8[)>rk&ZKa_Cy/wS0z\3eaȠ؉IGT'noK%qDϥ{ȡ)s0Mgklrsr$\q ZvV\6S4g_dg='ud,hư1By^N2 yGe`ҵꔘ\d8#_}F6)'>](",nrWqKք+sz_@ x3uH-4Ϭ "G`@|> \ f PR6!Guv/q S$*u-0a),)6TP_q X;Re*p.a-oҼ7pH//Cͪ,W3tsYX$_IqRj.iц+vM-;y4XR c-Pu-a5xՉ&5w1ڦmFɕsJ/$Nmy.Vs\D ÊjMOSŚz,"`mdzXG Cu!RSi:Gi^38XtQQ&GllCPR{,CnavFG Rt }(U/ ":m)n[֣>'뵊Yoy\3!ICߛhK >in@`Lͷ0cgDRM. <]k[%7>yHҞAo!ѬHGi/ ҒAPpR;s!X,b+8)u*8V]V9y_qJk/`i1L^95 xZBb'"%t lF6H&Y6@f]φjRX4 Z^͹?޷(~arWsփ|)抐 WbHdm-xm}(n1>JX< vɪT=^'F6Aie(9*jc%&ep'LK;KlZ=%dw䞈86eL9x~!n õؾDDx!-FڄLDv U&х',RFao o2ӈ'ίwfx l`_Ms[q5nł}r5\k~Y慎<wq%eJ+m!ȁ31ʒAtsP 7"l'FD\& n*HԽrR8e~%" Fߋe6d:!tpk "DR0"uB xhR'{-m5p7ۃfp7|4ݷ0x|AZF=Q6:{iT/9 T}O"X-j*tsPC6Qeyd1\0p${'ar6 鳅;5='icwNќpN'՞CB:Gsu ?{W;JILz<|tFbodqC,54R[Wѷds#TuZr]|>D腜=%byנ#s 82xzF;CO=wB.ƩA [wSGLvݷ\sZ%/ڞ`/L~sjhokMLy\9^}F)LnPY&/_hy=_u"$e5IF&{IL C־P[HBE{mЈO5s{"6~@4AQZb8dЦ(a$c/{iU'n0y(Z鸾r'ۏ-{9f{Ū-I%0%kUk(O q*ٯY,ܽDk`+0YU5{ߏאY#dNپ3c˸(c Yb'"XZPIR$382kYme 0k(~{jc㛻*qV}WeٚHv(>7Ws@x;1{Zk3q!:dXsvGa[Ȯ΍ /4 Hvn9g;u!ݪ!-ECE#h$BM rNn3n)j02TwBcƅc>$ѳtY::C~=eG'd AC; cfT[~:|B$~s6FfJ<aڑѠ5K>0 2F.07#o1eʰ7z4dN3]3WUm+{nqe,fZ28bW!~ͼ޽0bJ *:H,!Z/G*UZdF;Ba_K"=={_A/9ZA_U~0CF:7R~%?>㬯4ʎ4Mj v1b5;bH͍}Y&(ߙp?V Te/ϰzW# [@mJ0u}QWcfVwQ]LrlP}ffu5qzb 5hZ<7I 8Ъjn8_ר(7Qo_/O|%8!hBz\F#Ԝ/gE$Ea%kn޻ XJhS< Ϛv1Z"u9տ,m$QIOhJ\j5;2xTݻͨ`kgI{AcHVV3eu|yg|sE1E0OIVx/9kye3/-4Z5&g\BӻM>$osOwoD4Ha/0U'􈼞LXK[=+i"\XoQS날Z]+I}&N3CA8QyLދ8b!*1iJyhb/{a_ ߑ-8_17{~b NCIQ-icE<<>ˌ w4&sfp.њIÐybpłot[ֿ&˂ [ JmI.> %u@{=$jR[ړOBh#,86sςĝE_DZ+hhL1XOOi9TGR?~2 c<#Oyk` kZߜNWٶ cTGNaKÛo<#1kC-#߳bXtJ}wFY-ύuݵgb/`ahg ;H|Ϳ Vdbmpy\;OyŌZw^c<70Ť$r٭4b8>BP c%[L+qV+xꥃܯwY^LM1DsTq)qqfD1eH{u߻剗!>u (&9 }|Vhb r/}9`:995pΙp`pĿO2Al%bb1QL~R*QajG`V: bFF_[r#}+**1WY E"%ge&a6Z#>t'mT_*h+Aĵ\N s<Gж~D3̨2[P#?yBǹфsI|s ukt`8Ύes4fzuz8|ē Î{'+< @. ߂_0|r(S곢2ݱ~ubW$='yLDxs @ʈɃd(`yob!"!h|[(AJ>Nۤ% K>5A\9oKv|=t6 ~W@(e[ܱTopWt"ZF!jiYAK*(#&IHxmK]+*\=b.I?f@6}aI_*J~k&X')͐G&lѰc磮`z˜P>e^yHKO/ǻ> Y6j,UE[??&mYjIN7 Bq}r벚Kq RGX!'4#⎥|G͚h;m_rW839%E["]!({H#$apTd-?iqN8 ~zHֺIޚ3̨O I^v>ִF<@Ylh!Jx0 g*PG6<(~łI BĴf JSHzmg#PKOđ;<3`ykhܥFuΆ=qʍJRkg6{fώsZ˜QD6@  Ql'v;27B_qdLv#(8f.Rhd9E|% P_@Aciגg/S(B9ЁY? GΔU=wj:YɢS*4]1 nRTA\L9}$|@JGAP+XkF:hю~ZDJt}V ǽe6@ Oo2 Ni'p rNo-D<5IdywR{S9mL|{+E~`W)KDq KKa Yٯ[76-2qd0oW {i1T40ؕ4hIpR}6^q7c²wbT;fV!܈ S9RU t= `);SAFyϻqF:fҪlns+i;#BThlKgتluD>T2&k؇mОT͎gh% :@`0n(WrfTd%I* Fh&7p>z ޙۡ.#-`<*SCwA ~0P7~*)~4Ae0p߇I7shȌ<G%vm¯b2 uheԠwKLM.S(GhAݣhHēѝuRh5Sajʙ7T;3g 637_W($K# 6)90_}"=U<3Tn=YN}BgrE$/j y%} g%%[y#Z^nCW(>wXoED]+Ec9!(\a@^b8w`SKb3@W܄)z מYe57D>KWal~`&$fKIY[+Xu3 xHC̈́B ;AQ<Th6YoS2r&f؇ mEձYV9/;˫9V>k*>kp9@'Qв qiuVC.> N\z/;S3Lk:~DB0 ‰Kֺԯ^Q{y%w/t$8GJ+I ;57m j] 9oEMwOKto)G oS֧ޚF=LƼX"_4cd9Ё iO4sO(PIpH+U\(U@yl N2q- ЅBql҃(N/#ic-)1 Jv+ })b΍[Dҝ ~wetC, { 1^9㕲' ݦ`ẽځ \x\]989 eM2*7?rn`& ` ~9.E FvՍ$S}&,$=Yи³'GM|-ANF2#9\ ۦ]kincP]:Oy"KĠ>hi Ǹ IY?jCUPۍ g@GYGN<3'S6} X~sKm:[}ԪDuӽl\yXC:o 9A"K_i@2Lf~@&mL-muK!:3u朸该~=J l Uhizyĝ`~UׇdJkسG?ӛȼ bxsu)yΊ{u ثtn WX:͐p%┿h[]rvcFV(m f\ae[~ y~ξfjwvƶGx_,{Ja*JGBԑ2s4,wy:%A &IF3E _ ^>bp`o6*/p7<2TNy-N&}<#j{hZD*-CuD-!je )8N h7u895*3U&{WeLi 'GC lpRM% @ IqIE96EG%$$,QJhZynN*0,iLmyCy+ ބG 2-kсVeLQ6CR90ROTºh.08R6^ wo,f6:1}5"uP5hNfڥԲ "n@c\bU>[ 5;TP)MzG{@Q[-˭UQUN|=񮼣Uya ފc-6?^΂<ooj館Xh3 'S<>-ۿW7Le_A1_U(ʵ08`汸-;Vr`͖XQ7X񵉃`1z)M3y(1s,Z^Cp4 W\X{%O^gJ(j$9Zi+/߳~~F !&l_':`_ Lq2@ {,~R$KQRM[_gmBs;gL`I[.XN p464Bĺk4p?)܆ ,' hEvOɣ۪\d" ϱ J j3A;'ɜN9 =Y c9n  {9Q#Kb9D}+ׂopc -`8֑LHJv :)3 smPRH,mtGu[K XfhzhfṢnoFWOy',.vڑ f2]x1 %)u-UVhFڇx+iYj/m[ݺ48xJ>O/PnQ^ ^@,\řD).jD,Dp}vPtȈvʵ&DxAAFqXxI,a䊫 Ŷ@z3fGwn"'g0ĒhF=`pœł@hTGlV]1&daTMi[}6+2"PP^rؾNnnLpF m:7c[v>@_ E=WײXϹSk3K|2=Q{\2vKL@b&h5#–[bmSU\݉7r;Q)0ihBo4hkB{NTbXq@qGiN!VO>$a;,tcI]"hͨRټrTD&R rdH;e.pHerLGۆ2v@ g xPrd+uQ!*=,¼\ m5Sɮ$^ oŢZWty$[D"H:[jybG&Da5$uODZ`. `t{AmkEILkeGf~$Œ6)ȺswyH)ojJ_;D.oGPo4y\С!C4 Eۧ>£{GIIkcIQ!("gS;WjVTI1DNECy)| 𾪙#1Sha]15 \ 4/tز J`joٶ`|ցRUdWFul8oFϸ$¦o2t JB̳Bf_'^/!D9Xx1g6Kh;IQo J P+4OOpI>裎-Kw7%VH, 1bq{&y;tZIw&%}Y |< 5wS:lK9 E~NHCȏѣ1@ w#+qf*fdpIZcW`TWVI nҶ<ɭ?1BEOCLn4#d曢c@,JerCoY_Hr&3s$,bsl1]"w67wtا(ݲقuojuU8,Ro-*jG$tEgs¡JF+gDDL!sNaj1oO_͟nK 0ߦH s-kp}_ b pn$^ 0"^L c~YMc; H )a4f"rrG +1lSZnx`9KnHOf Γׂ(#`\n,go 30L 6n5='Lg2s,_cO/Ax'N=3Iv,n*HZqV&I%*ؖ"~ք.bOP]er3cN>47B[d ~Ѭ٠Rgb{}1m3H*e@^.2W4|I{|h(-࿔ ͸*;q8RNrBxM6ß^͵W&E ū:[=!Y<]jdU% X uF-)ᓆ# 6ahb?h1-+Jv@QWjp騛N. +^6 î!IqX%\+nn%UڲiՄZ31\f5'qm 0um3Xjy:ω7] tK \uOs&Ѥ5:l_Yr8t[֍j|NԌ?[\zkn!YN ]s_b0 RRr$VU2X_~=v(?G͟H0R7%5G_+] yLFz(" trZ;3nW&*e}Jbm@~0F"/eVĤ}K)l"]7t2kb'@l XLa_s7s#qğ@XBrF3j?҈Ndw2Ё2AhPB뚿jn TeWۺӮtN:1',(ү,7;]&@d>0}yz޸a8%?R`L<sg28J5 ]]"oXpD@~^+rk8_pK;Bґ^8KY@'Gԃ82 A| aHcd֪{.Hh7:0J} r;s() iA~I E~@[_F?Lȭe oAea@϶%Wګ;Abb\iE @[,kƍY|̻tE;i&$y };Dvj[S9LN͗X fޟ骓ٷi혌a,_[7A_`9:^ܦVhb!e>rDX z-[M"K2?ߛ ]u+G4^-w;@{X'Fs7sF*4AU N P3w#f3JW+0 }!j] ˁ{VF2)F-l[(n~%;6cI7B5jj#R D2 +KoT9moJ!P

[5Hg'NSBU$4E/_.ϭLTi|R ~W,r͐X {`1~ 'VݫY_TxYiUR_4Q:m0|~Vl9$׈ʨ‰MӎdD,$o>@! m.0MꀴEJ"?y%Ѕ,̀+G= Y+=.2I\ -`>e-@M-tHLK)3V/#Z|W*". 1MpL{ϟY.jqncј Z֗VZ$LX ׷<ǥDLkK46dPAyx7wsME S,9RɉН{- ݶ2ure}iřCS@4EC?/5m5us+_ 1^KLLy]An N 2ytQL*S} ? 00"qOĤ]VR T529NjrKan@E~窽4-rn9];b 9x?!R???]ύJΰw"(JJ7ۿTjV'4U?WL 25YU'b,Xivllo\N#{I`$" hHLGT*L`r{Q#l>$zs=@"ʌkxJos*խëb UzӻYћxs*Q!`uIE>C-m>vHaz_^yG3|b8;0KA6XF,ay^FE x)GԢR;]ƞވ#xggo$2*wC8.>3dd"CtVg"PdQ^ xGc >%ө3)S4<Cj~"Yˬ[x^[14| 0Oc4Ԕ LT%g\g؃=nл"_'UGbΏsfc(e?j[XSZ\^ d5pЅR|r::3F9qW*f]y:*z <@tP(v-GbsEN>A !m,Iw)*\50KηN=yJ}͖*-nop8d;'~V_aq)кNڈ%T 1:i44"EU#R>K4Q# h >AY@))@OٸA0h=eI m) ~}{>PUܦ&Wn9t3Yj"L_KIxⴋx'LCJ1-;XmVCAT&z DE{r{2sR @\-Ģk=8)?H+~kk_pӸ;c&|^+VPiE 7^5H,@-M DgC[X } zI Sr7 aK-7HY6U"^qF" a%7k;IX )z:rkP|S]C0v!M׸A|')owK+" aH[(JdCE`/L$:DF \>,YD.VrQ -YFj2fgʪo=ĤzbƯ1ot:!"k8j8Ja`V_Aџ}. fʺ",G k&#}FBOrt,?Û ݀bbgTAHt(EЫ.7ߑau9rdݤE+.Ňddᢾbkk }؆m5s"4‚ЖXa|K8B@97ܺF - &?jtVr-f uS!yp1G:+z5 1{IcQSLlT`̧ :ɨ)q)z;-gi"2ie/9A [0KF'{E7qdXSf-yqs;>Ncveىaׁ;3D?*'W*hy١tGN?3{/Eq̠ D/t<4@=kNo ~D/P4^S"W Srqj&厚-33R0g+Dob-NrFiT?mbBJMji^B~ͅ 0N9B3k.0y̯,G-ek8pMp SaOHl--D_R!Ń_}_0Ɲln`5 Fz)ie+_˃uHG0r#ť&rz5$\$oiש(&6?ߛ:_d;^UaGOp?Q(P/l&+ا':)0ey@ۉL>)'T3C)'΍|}j1*' ϶SlN _0aTﭒ4c^WMi/ b ^*kj-:obczI'{Dl[bKf+K;oFK3TS  f*1J' lXL+ dVsJ7X. JESW\%(kа7 {c۾@(f 3:EI Z.f*u\X1{=[Ԃ$k/ZwѴÊ~j֣ y)U ӜDtXұT&~aE^>"   Q{nBc,v6^Au]Rxضw'5,A{y"㼲%Am(Jebf?gMwXFY( ѴDj~K\\ϡ ܛt,?* X]6Rf.z^ix ]xJ%p*YƜ3&Lg"BX\BŀxIFl ЙGrjʍڙ k }rj M<{'G]8zJBGHS1pC OAY0;r)⭰EKi,)A)`$Z@ݬ;ɋ 8'. KQ{>mh,&cKhpH`|Ũ!`Z1&%:gDz{/W?^3eJid|J$g#ǟ?t.Qps&%#t] ?|a{(*X&!~PꞛH>DFpN& G5il0[jpW3K$Ajost +)08!e@TEwgU#ȡސ|/eynh"m("kiYE 6e?o~\4٬W-/<0x@{i߿ )6f+[FR\w !yB_3i ݑPnSx/!{WYTtyI谮Đ1` ħɵeVS|7. .e}6<#CPugOu͝~C OW0t@DOc?.YM>J we[s}keos ˕[Uc p7, M=Z:Gqf)WLL 4S$/  6Ι#*;)RWJP"TEwٓ3ȋx-ewzfppQk.JlHA4CO\Ct;S c#=]_K8oj^tנ_GgmWÓcI7Η{%{=1 1+)3OW"3iʣ(=RK*vpm܌gC1Sc+7oͭtRW'|ِ |kZ{ _Sq]>eH ]"r\rJKwQܴ(_H|N .B4# ntޛ$rw 'Y-G,R dd-0 sDAjTT0L`sY-O_壠tB6mB eD2?> 6>X1Wv}et&+9/>a:%>t?m"ٱ{66kK]lSZVtT5@l%*Kt ]X1:&!9*imJ q=9듿@pr*ez'}[6:R+1BN')+fwêeuLJlFovtr ??quñRNG 77>٬vQRb.*|.{9x[Ku>/{hK 8<03sgME?X> zGG|A96S|[tiqwzwв?w0{"~hrAh41F>p7p)nT9)P{RfD S?]pїV됬yUID8!V/f'T9!z;ҁ(T@wvϜo&QfY2b Lj A<T|+,2ٺ޳/OفO\DeS>Fkn;[_a\F ,D+,>dŶl[j'=(,\G3`ZҹFO6y_Vf:x" |U&ƈH%$9X$n7xOP}me9 jhšaVt$)YLy+EGu t<ɈbXWxu 񹐴t,o8pE4,twJiJ>t{%gj dzY_j|DV3b/}z߹'딪2<{Eq_Uϓ 8%\ݳg)þ n {DT<ҘZo* 7˥fH_%vhkz۝TmC#{ \| 崴aI t7Jd[4&J[:"5GA_,b){%Ud{Vuج+)?&AֽO>)D!c\I @rlUümɊ1-.H`أf9W#c]6kW@nЃhW}#\ ¶HU&5pz_ Ga%L|i2Crl ̉_,R794$֤egUw/=N% %-쩥¯]>=NO13izLZ?!넍%Pbl-p4whar9"CJ&? n|$U$A"*sԻ6>Sf?mq\,1ZHwu1['34+ .צj,S1fL0y4i~LBtڹAnJ4p, ,#AQ}hj=iP]T&pLBS_gZcեuKBf'} ap%ގYzISgƉֲ5c|__ F]0^Q.k T K@dy 4tᗐ%s |_np/& I茋xgW2ϘU?>羧Rt-fEŨ4F`Sq l7N)SG)B6[M㵜 vFeF+͎NПr庻ږ# BʌCmH #I^3$~&z>3(N]E`HO$Sx=JE1_/K9܊e*{oUNS貯ⰢȁD_xyk3͗Ơ];3li0Bu]ﵘ2F/ ^źxZ"$7A4U2Q"{X(@S ĠrK邔[4HkX5AD.ru ʜ{*qu>k޴R|/hn C(>ό꧗w<-wR2js8<qϪ9>2 . M㢯6(y"*x*({.^*Ͼ@i_12,%\7咿^fT&/9T}bNAN.*]4dv^' ~@j AkU7w;TqIkKC~Ψ%T5;aG0+U"bzz@6t=ŜT մ^xhP;AJmZy}em]Q\Jxk-HMEQ!]wߋYrL}뵟ޥ;M)Fܜ:-S0.1zkǨ[sZSkV'e&A3~%VO=Zh9]|].WAD4>^:$ !'|ȁT5_ '^/;s'TLS}?b)O폴 4էu/5 ?!ʇ.o:vhviwP{SUF!)ZyD?S\M.| d$zZU>J#ѻQXՍQA )~ 8F_yٵAb? !$leKԕ.4I16gU~i2vKGz5!"tI Sҫ7!Y@>TݘE1i6)[mLlu~j_rV!~f~l[Uǻ@ Idx}u7* {/bh&v@A%VǟS Ȭ#'=4l<"TqfЯWO /%J] eoEfcވ~V"yq MXY[Rgxcҭrw+̐{lR6ny AcL0^82/pzv#6Z.Sk #w8M;4waUUW/0:Owʹ\i^(pUQ3366'7Bbo+-;W?O@/(d&4hIUU䯹`|Z9PpFmnY|:9eSJ$sdЭR q1:_m`*oAZc!3WXWkxD|D~ +EBbۉmVQ|L"N'6ijg klVkoSu0LX28%5檖䱰UVΨ0xGXpc_iLuc C}wK^m;MkGPEܽF(.:G_3EgLl,AVM ]U\9kT).l&mr4Uh 絜`yoq#UO2&G9ۤs;<;X 6<ᵉ+|zz­`P Ab^šv~(\jt%+?傟]J=tUnp JYr2,ʮ& wEY;I }rwΧevrz]dO.C@xrC8&zZ6*JỈp}cO`$?pş?"ץw)L|V7L)̞a4i9/fEwyԄU "(7U kۧ*OC @#Tf۞w'Zʚ2U bVa t;L+0GSȣP<ֆ]ms9q&fIrE*/OL-0'óVAJWO=@TŠl,da)SMP[9{_hWN2-zēǂau}a-StyDNl̈́omNέt[r^DtfxG«bV)1 KdvR>7 cc1~` |AOxBT,Tgm17^?!Qu H 8f>0A)AhѴˠ }J9@h)4q>~t3GK3׼.A3]R\d(71}KbmVd |Jc-ZNf`,947 Ʉ˓JFs 6_GMQ.9(DHu7Ur0W fAV}pr}&/L[VKϢVaGUo`&$*#ajY 5|@r Pr6ޔ}2ëta@3hrEdk}KBi3P,qU,wap*kNKp[u*19"Ao9( FWTU_X+G@YNcHq 8T&F=dg %v͠xp;(sܗk|'=4t.Ɩ7w+@NcAߧ+C noeI H6'>^;jtp: "p1"tko3-.C_\+wN[w9 I_kRD ~||#Qd(<E"Y _]? K8F0ha] 3[ZV6)%?4w+g~˜bO^}@ gsW]LH^ lVF,[1 ʤ'!l6&{֊\2c ^1y1I""ZIb(;ziH Ha}OcIn[f硨ˌͥ1MM;8^MPw!}MR C)G:TZN1qA/0R$=A7 䨅x;鲲؟M{}HcL<*mƛ؛]2E&:F@7~iX;ś(^vUO쵟JCxc<2A:*MaCP˻OՖ@'sE7-^B>',jGRXk9)p -_}&֧>KPvNEׅ7jKef @[Eɤ}>sGI1m $qrPʎ3֞HCoV T嘓5B Vȴb6e`8y>Ey /܉qFXLy0夗fgD9z ~z䏣kØڻy;]>\SΫ)f@Uz ѝ0MHi Os..z hNũFR9?b&^~GS8ob]`+CCԦLISԸ%|;bx!KS[e_>MދCÉT|3oC#.ml)`n{x?6"XƥGY/CS,սYX2C 3A x&Va``aLda$ra@CDk|91ϭI{uՐWB5r͡QoZvDuӒdF?󣮘Oq7E=m~b(AK"|ҾðoBf~NҗNy-tQM4U[<()yM?6K3KWӕV7E73Fv]z>a2y ̮խo˜)nEߥ-*$ʙ`9[ʱXL<-o{(z\-14!P@+nhi2k4!Q6R~mʁ֟ҧg|ӽW%D%;פLH3!۱c[s`lnz{W8Jp"Ї&/U1BebԦ/h5V1L 9P)j괔E9LIq@bX'JAiKFdg Xԃ7`Zr/v)66YQ?k;CN[cE#Šv_ҞϨ# ^%Y.ajB!㣭kGaUׅULPv\/(n.~r_u7bѶa ag}clc{46/}g(}AZ/4b[-޿V^}>{'Tʸ D0亥wVu8U+;8Ix+q֥ Q΁ZYG ^s" sq;g=ߢr6Cą HT I3^|5Ӊ1]>n:(}+8Tf Gn5[$y4bh^8X̑䤱pۈy_Gt5VLji(~3QLvlo6׶y#jm/A٨֑EИYvp ?g2sEv3YYDžQݎ =XV0>'ڔ6S SwY5ˇGDeH&JT `x?E+XR5&¥so^} 09הR:rʓg,S[lGД+pf3ҹE覦36N'wLp!cjRf` p5۩IF%|G 9t{/>({ G5KN"-S^5t7*[3"hI;a-V JYnCCS1iAWațʈ1}Dr Ql)gcChu\F(DUR^ۤiMFG;WbB4tQ?!vQX͌?X`HHrD*z!qђT*TFzu\mBkf<-#{j(yf8aM& %Dٍ*"UX]9]fy KXω(ؒ6epf J-%1Xd)&@dz<@A"BW\B{Yr~Oo-b8QchU{%9{tXcy)ػ#k)WEكRA$^[H>'Sо<*Sڧ')xk uM?>)1bA o@e|(,T# ViTjW>Hjv}^kg.R 'BD`RH=fiMb3EvF{8R PP[̵!z 8cnK0uOmƣK m] Y% nWٵ ]IfA$R5:Cy[#PQ\rRMYT"\+ZYի_sxGYׅ@ CGJ(Esgj'nY@O맶r}C,9"6Xr[q @2NC}34m| i]+CWF9'"&;ΰ5=ZCTLVebe8fGp~(.hpv`bYtӤ7ƺ0з(d % ~mDDFº6#=2]{]$P Su:daX>cae)f457?A!FlyZwGz «->ՏT~fnW 0-t[,jL8&Ԃ:XؗñoHoy)aIMIոys} 9OpZ"Öri mxx>sG|V|WGk&+,Z`g6n/rjfA[=%F5ܕBPѶ#Vc7PI=,G1[)W`*tD ԓ}-C2 Sթxkx2뿤j"y:|xgXzͫLcrr9fRڬ(HrrJ~~H}ӫH] ĮDžL~Z_WwTڎ&Rؿ h3جuhېE7ipnH5r|QGA{A{,mLBLfS,^@̋YImFJ9%^|ݤ9;f?8|;f <᪾߽͊$s1\`ʎ,hICK-#7JóEvH/y:x9uF\9]IHVSqے&v^h@O4n1AᖳR*b+7}b#G |Uw;q=i (J>B0sFZ5kgQ5d|%G)Cm%$C]NNm0o$̈́hũ kE?̐G!@*ٛkڅU 3YכgbJ. 55f}c D,߸BK,orx\x[ xmK'{,u`|Qk` _-{_~` @ tؾQדTdb;QH6%Cx-*f 7/=s@u:̙DyFD 4ZcAm!zW_zG)ƤN=D5ZSt5r%v ?бiiZ#0DQk;\~RFJ'7x2wˆ&4 VhbuMwLquHIɩKp ZWBrIVcX /eįʽZ34}gVh4'[)pWOϢ`b"WӨ\hF/Osfq$ H=z Q-5Gx)=3UJ$WpǪEvAҿ#A"E5&ޞddPo vȽSj'.mgڕdLْUK7:/Cߢ mK&M!]ui‹p\+GtJ8_a+I/mkyF["| c%Wu۳6c϶+ 'KQe}4iڇ̪yk69(Gc#宾4">EAdӀ݅fȱWYB}AfL_@wxm~q/0QC6ͫ7b=f M TY!I!λ!G| jr8$qzrxٹ"dɑΕ큟D&b u@ W@{9Bv]w b(Z&K5:BeSVpUغi}fh'dm{%N |.Qp+ N'c›Fڪ1)ÖRTjӦ)" ʩWm4>bMJ$9w$!YSt8fÜU?+&ZgփzynدZΎ%gw|J'Ӊec{Վ:()Vw`- /WrfdRO <|2\-o00 d T:e@rʒ[ HU$pp/8U 8^9j}~Pޫ%4'ۢx& uPgHpm"ItLDcH_pN4ׂHQUg(“Zh6kt5?z>Oj8C%6UY?"ߗ"5Yx(E#6Yx<cԑno|;'ytY}0J}DuX4]G[Fz0=QJ*ڨB\rK) Zoz_0sȞ=]I%7MλzS!l'0Ȕ=] 2?ZR6&ؼZ;gWQcȊGhڷ+#X T!B§S%.>" @‰V'QJȋѮőMtiqct57"p8?o5r)XOfVG 9z?۰TqT>UN9> B`s_X|E2)=T'?F q"iCI@ #%זBce>%%TX=MB.1U)4x+fG*NWx| l|ր-]q # pZ )Bi^,YsW93d,ڒ>|pg+ob.K}%}2zz6# v6|<|'Q?Pu?i& 1Zs uTTo ]Ysm'x̐%nKA&d3!1dMAwt7Iiyrq𺟬Y!LHi0"|zXzbwOvOrniL&_-/;sN'*C7~ø+,}zo|e 1S˸"5g|N|9۔lXX\CS@vo=eB(D^h87|WUkKiSeҿ>Z4R`c,EG#T3LV{7aК8CR/$:I`G^Ӥ5o([Vnn IPIBz+b4 7LաO=UW7(  T{CkE/NO)2f:DDr ꤜ}}l@0S[.zSrqʣ?zFbTd`}ft}3ZF_4wpTlp.m,X'ZXE`eZk OZ=a1YזeK _$0V[a!rpAMgtk?Ҹ2FFKRw/aȷPsݴhg\ r^9=!`WQ6{3 ݃5%YSZA8L7PHUEN?zLπ>qgop߻&Ƞ K8mW⛡j SӹV=Jk[+#)?@5Q( ;ϸ}_S$DjkQ:37]_A]oXn\⨌Nu);{ϸ3Y((գ?D%ɷ9>xc-}o$*'fB9XnB ,˥G*3SewА0b]qg:,3'PؿD e4KC9㟞l}?Mm=4-Hef<9<ެcQ$MK5NGgLn*a$@]3Y4f=TL+j@;˭(i8\R\7'umCA[S=LcG{¬ftg` :vI D(K?W%~jmAn2^fu8گ?ԧk; Wm??[cOH'4 LT&bVS&znFGP[m=64 X*1;]iʇmTo./~WJv=M˻p!ҝAWyW©rq`0Z2Icѱe[@3ە&umO%u GRIѿD&k^e#Y8'ۯy9L*1!{0 tjZBKМ@[ 7,VEѬ&zA?E1bnx›nu_}BƈG9 KF8sC 7Hi@iYhE<6FwѯW!O.u 05}o[+-[sQD(]ԃ!DC4ܧ^tvj%bwŽ,hha@4_I'+t|&8?*+,~%d_y:~^0H7ñ]=zG|.U^bze)mW?KIIpppk\+(a?7kؕЪw@7+}]\ v" @I`SlNog`}_ hָU*yy&ZC%~[N[mjp8Χ>#Vq' Z nXJ$ ad֨VY;\nj–-ڲfǦf~#6|dr[0KhCD?Fϔ6E MJb4x6kWTD$+?*+M80Bܯ,v>ըoh2yӠv A_eypr>z5-a ^t߮:@bya ~Eð? D "v"'\g"`K5Һ#L5S}X{`9Bo`,,)8YD0L2hدe0L~dz54`9ȾHu~#aPիl`1 w(|}3: K0*kʖ .~ȡߢNT,}y_臸So؅-vH>.qzt}iQyCJe$1dXiۜ. 6!9bs[V qPO4:R,ݽڨl~}\[學rܒ;I{"=hn ܹʘ]G19etT”%jX`}ю>X0# ia"? J T G&h$F.0?pE z51]l6x3vhgAͲ+ep2e4(H86H)) JbX_?h:;1KdC'/ypd*Ar.A=!꘏Ѿ iX,qTc%``a5 uNT(oir I20~qt7cG-xﮎ[|ZD~_M6@CSaʭ嘑 igX<c *6! zr\K=Ԗi4pίѝR^ 8wTY +\UA]v^Tfe3xbwkkG3FHԺ{t<{@[,w?Vnb3ǖmOקTR*&ǷkFhDۜ9|~W+;B;6ܥ˜ըeWʇ~ iח`3VD3nяVi^hT}ePX賗ì~[1iLi[̉$> {kZg~rBTl/CP$4V`ZLN7ӫ#Ucf>;(h*߇o%hwir dV-34fBnmB &[KоKs,yeǶ#<{#[}>QvTXD߽A-nz='Q?#kL`^@Tx#MvmMW4G.CSi)Qi)~i7%jj!pdfҳ'/T:6Ր}r=7Q477R+b9b4:ver>m׵ (]Jy4>kRV\ m{oKp$tpUQnY:;ZG S!&Oӝ֛iK<{KU*a9?firKYݎR n5l5{E9";^"  qEo!x*{km>ckV!ʇ|N 0F>I1A1zKE׉fjRUŸDVJRJg8VK\D44oMf0DSy?w\_`ґ[6g`+Re+^l On%އ17,B9'7~xQpjs` ϟb^rjmr9,0T1WP׌g [] dc.\msoǧƎٿv =ž+ČQQ{73 P #30\7޿t!{= bӵT&F׏j7CŊ.$htce{{7SS}:"i=|@Gj=a3;1莡+ 1H_|褕B["Mbz9ŀdP2.]hT]۳P$1xG?'Ijxo;ų >6cmSm͠*S*F岈#Zʓ xxIPgޞs)~a6z ܣ9;hW'o -Q8>uJ3aZ<67VHfŅ t$qw(բWǚ}܋ P:W !Wz D›H n4^*^=1ҭ[Kẻ s4A=?)N3f.i1/0uMJcef[fΫtaTdp`.нN*qjws$\,,hZc^3=̑>*qN/~&n Fhz$+A$='_f0v.&\H]_#M(%Ş-/_Xt[7Ԇ~*7z$mC`)'N|j?>ɽ:mV:Hm[rα#>g5ƠJ "ٱ $[rC8E'{DHvϯ b/z *ZrL3i#dqz\G)'_檝ct<6Dwٹr"2&]038e2sb4/Jj< =H(>y*Ԗ} BR|Vu'// YgfZ{!#@yʏeVhjx,oc'}ctp lH̫2-Ё!99j,jf] %5aMkEІd%0H'-sZ/(9@d`@Q5MP\T3ndbf@#WRS]*b,|1B> ]Wgޙ/f ؕIzOs vVn`1h}ކXX|kVsr͐,'|zm2vQQ!6_YA+E %dczw=1DJ5Z>w7sۼ)6N ^ #({5hj%WYb 4AbЦ*Jh8Kvͭkw);ks *1M\$+g%+,l`0<ȻK50V'l9Gۇ2`r;E MoՐ8b')+EE,ش $a'bDm^0ASG_}SO:ʓ<ݖgh~TFcR<>ckz~͊ֆZ+&4w&O:FNUv5[dEZVuaKZ rR(5BEڅ5+ֆ{$ѐR f_m@܃H/^ɌcJ~z[ZvHE.o/7߈P7Z*09SWC|)()a&'mۏɩ^1lxOg7vR: ࣢{hh"GZ{z߰M.~TIK ɱP61} íe[K 4*'cg >N6zT\ *\g7L#t:ī] &Ex*]Zb QPSj_kCN_Pw3g/JqAz+>z=hz4~L ٻq Kޜ`^4c6$zםAYMԾ̣&UhK9#Vqfnt>YZ׹ ,3"j I R;gӾLldh!BYC(RG\NM؉G(Q!8"(Ɏ+Ϋ8~8[VBf{i?|t*;C\Yqy XB hX\Uh ޲جKx̥‡e Q0&vA UxvngzHh2U&nv'C/݈R.Ҝ@"F^9ҏ}[mP! "<) 09*#@1=w2Ѽ 0F^}-=`L 4F9E,k,gі6U,$.T*rl&4 X|09-cc:EXM3-c1ޚarg!$xEd^bYx}f]WOFYє$-ep ()PYy iܶiTjl5{7Ś«2_"Gk=dZEY)h^eb{)[V aZ| I=C|3~NA(.9uUr"V5aE9UJ7(MhWߑΞB}#.=zlOݣHfLK;t.䴀3M:[PjU23redҖ>0YY"lB >XJEѱq̔4,@]Sɸ ς6ƀ?$Gk^>"b J?L4!Ws;%v(Z3g>r+HJ' }g^c"VXmĥqcp`$p^meBⷆp(ԗ 4$Q`twBf/*]ǘǓ\J$l(`GJc>Ӿ,@jٝ?|w"ˤMO=mm{'H.RQ],e˺~㩑19 ϕvNS JsyYߙQڮ@?-s^xQcJ?8meÝa#^c_ n14ܼ2A阂t#z<߈u`Ole{1 ?z&;]/u=&0!opd@F@"߅Y\Hf6X 񇝁 )z@* 0IO}6S ^qQw ٌ FNlKj=rSsF{Lg6OgE=T(n0MTL@D[+xQ≓=쑟^VIO_sVذWsg "dDB{4GB峀1rt%iXmZ \cMoTTn>ou7jt=.RVY sX%J~XG qɄCmOaE 23>GК>+$GޣE e qzzI'Fı8a ])Ho _ݓE/ ^z`­nD\\1C<S*5Few P#w8ŲEB;^k.U¿9f, -Pp4R!PTꍯ][N4r!@>F =/o$i'$wJߎN*nOURnlh$ '10ѱEHtt>7FrTa!OѧS^`hл )u'9r6:=|/b Ƅðy&Vfi{)L> >Xߨ0nje['ê M1٭a޿ ^:Lt_t8Qڶk|b˱ f,bv䫨;84 a܂2Y"Ok{E"J@?噼XM|O,>&:%wq^ɂ}> ӄC䔃(l*b1r@b_6HwU+9zU ]0!=yd?L g=ӚYsH85bVy i`I<4 ϶SI6A2XJvf"sON?]i,JeeDb _Aoߏ]n~ )Mj?"xuIU0/ϡ"2ݲh>6,a\w1sYOCY1!9`KmFf+=u3#:vZBF"6k&s_TM-w}nWx4 1h)Wm?ȱKN⎻+آsIMtt;q܉x3 *$HN IK$^bֺ*)&׼9`/1| Y4n]ZdT<5Ů4U2oV'~+U4}N im􈹧+0 Ƅ֎Erpy{^"N.PB41*djXikTPgU)jsg{t=)ӄ3:?4+-%$6×ae{ID"Fڽ(ɹDkBɐDw.Bn*%Ѡik  害:=yU*T5or)mM@⠹e{Ab3C O(9`6BQIPm)f#a2&"W?Ĥ+C-祰9a3b:9s d3yA ' oʧ1.133{ޟZTl\m-E h{^'u`°:?xO<2"Z˪KH;*an_j؋. jqU|w.ќ=4pR\iJXVFI^v7TZluB `ҽ  6)hRҗ90P7 ͂{QgCMV=5mh@b+ZX%0K"oFTZf"jvq}aР} S*|V&iNw+  ?Mcy#.a_c;D>H?8~#bh^! lC7*kԯ1çHh 5yҚM/A*(~4IB{{K㝡+7nA-JekoRbOX,_W>[OfY5iN>hk)ZyvWdL B=1Tu4>_3xihKv"w¯BuWןih z2Uf'd߼GˤcyH@ޑ)+y)@rˆve_\O\(ao9Lq 1Y\i-&Ӷ歩KA!,}XmBI^<|p E~ շ=!;fX *7.4dΚa7(2am|ؽB$e̝p&OA\\1(Oj4!WXgC/HaN`+(k7&y.(6[݉`;bVPRXa3?6T0fНw F˲,,m^NhɝcFLz6ïL1dь@C.GGwc1J)­0z"%FU&q:#M`QlqnV}E놮jT}?ŕcT#BxȰ+uėQTg[r84uh=LBrE|5aąfq=c:aa(:ˠw H5偒V!#\ށmL)K*RXrlKYkWͥ(yK t2iФ}jߓ%V,,Dϩbd *C)TQouH6Kد'׷{'u)2Fa@:`: +~wҲK⻀9)dpBb4mn#1K,ܪd|7-ltT{ +ʂ}~mV%󙧪/Oܠi¯^¢DtbQ}Lqzm5BFBH3GD G{6mWh<MAy4m"VFףz eT]+02Q7 jH<WH$t@Rk8.AY]5[ *'䕴N`5E? -S*W~Ǚ0{6kR9!eYWNT*ۘw刉~!0sHu)2hҵrb7 J.C+O/r&SB4^9w@Vޛ%%^Pi' T Hman3ٞVt `\iI`MlAZE|U)ڙRZ1PW]&r$pdV~abS[,3)55wX2mv.VDڴ;^͏ifCE AS # Ei?CmHW)s Av %O25)j k,Py, FK&kiuσOgD'^ML[yHh%XlKX @5`xf$k̀7ԫ/>s<9$v=TͺuA :u ߓ}j ziфS=mh| %vkMwr=&[zee+["Ԃg2r8H!E5E9kPbݿKD0o߹̙)Ttv޾N$ 2O^s5MUׇ=[?|Lu֢ + $-q)C#ʽ)p|0)*_S4^ b`] 9_DK+ Y{)8 d>ROlcz1kcltZǽT2v}"`2"c~|OfxҾPF$\\כ4f V[ߏ z: 95j`&53q/շDI<dC/ Fc3^ċ43Oa\+oJbw|rANE Ō<+Lw)29 pm\hkNIVӿ[j]k~>6Ij?jyGq*X8qC3~:qC{ゾ/@ ]6fLHIfQCI.T*o>A.8,,@EԟC3_.xLd4 `Fzi {*M&v}6ꌦZ@Mz<1Ù1\3?%'{7BE`v =-gSSt'NM%F'KQV2]KmOb<_Ct(BFkzy{vLXª^M*ŧG+lel Ks:m|f*Z N69>:9D'15 ODLB=c~0\>-i+?I8d o3CK[0dUIv_z޸"OeV`+yN R3Z2nX,j0? U #r>[]}:o-z`b \?f'&Dtf2ȘxQgm}mfp"N \e9 eQyl2,b[\|H.N3#K nE1eYJessXp SIC_9 xb,N9Js`8f 2LU2nɉ>=ZH/NrΏ*܅Ra|%).(_T@?'vW%[kz}ȨF[׈34` b 68 9ꥃR B7b:TJ\F"k7կأr}`wi*=i?: )`0pDB> 0H>6` xٜNYn\^LtN(kL};dٗt@0p$8wyV5rІŷRV_-1!w G=O: }b)}8`"|J8&(1v^l##/yݼCנ 䝻)?"5a*['4y"0wyɫA9Q:Ea*GۓE|u߲B4Ξ,(&jd\W#/+$] ,ÃbKC/W0]7;_d:'`ŖgVգ`SS֒/^Jһ2SY\kX}GݶcP(ƿ+0*ifo@SPՏinyˡ+ ;/%ǝC)=$=_FdYeZHGizdi9$~&"M%vW9|;:6@Fa6F5"Y|JN^U| ٗd4s1&V{ݚ`lŒ$BEf%fvc{^Z>3,/͙X!S.[( ַ}/kZ ُMؙtlv'?tOy#pbd| $/#q/=qܑW!w+لʪrX6T6wߌCR1b9``Qǿo$1FJeu<> w ]olZ  1qvH3d,CլG1'MҺ[#0 W2魺 DxXi܈NMڴ| nԣMͥ2 *XG,5KrOjYS] }az ($dft\,45ojX_9u_u_9AS'֖X u ėd?>M+LUբ'5>"SBnӡ<**Fqěs3iNse&XBR"} 47q}! [R=yEkZHf!HİTULqd82voIqTTʹk6N0 YHzNۆg%. `RƊ{h "</'/NĺzI>-d.%8*4GV› 䳪OecF!Ġ7.p%2%%|bBWdG`wy ;ߤوE;1!KKGxQهuToi㚮 j HAM2pֈ!PVVӈvZ5%nU\r;uvح9 *ǚ}M( DEE'mH;rX$WT Z ⩩sW{Neء }؄.?bAEiЩ$T,v& oH2zznR:+A4{:wpܗt~ƪu4_]goyKf t'b9ˋMB`|\PDuS]ɔ2XgEfIrpR/y?@MPxy qxh]P~Hb<䎜Xo%;IzHq!F s2wYLac;M|DRs'i kט~r7?Mp~VaW*{jBIG'n#^=Av=3s^$Wqp$Uc/qm k\g,KJi{0YH5UiyzU]=. CaOLdN.8PUw~)bmY":fטFy09͈dCw~'[`WDWQq7 '< -sf$33ƒRy"~~$@s.󷭙o0mK/ +)-SO;},Qoz){izImarSDLW͝\5ƐI4NVuh…=>::ϐ/c*'9ëi_nv~Tg& !rB 1x{YEjSLT_ zCaYcJ1RY٘oIiq& H)AGUk_`_`{%C-@п=UP'b [S[F˙FArOO3N9sjvX>~4-U,pXIw˸ R"3\$˶@>޽ʀ>=[[{cX`2gDN(Ё7|l!s Lwi#CKUI!듊Lp0{oCpNχvB=5t\Z+91HM`^`ZH6 P "DteT@&kDg1dK2sUzsW d0| ?U@zUE?Ou[  dAd\i!)ÞPuZ'i&|5Yd֧iK rt%/r.bDviI%7H:[K`?n}yoL4>rdVeГ ޭ6H20pX`SiasUΈqJp+bN W08#8vDј ᤾7ZNufg\PF-cI\32XiEڿsjDsm٧b|o;=hLxi "F$?̶ YZ