sssd-kcm-2.9.4-2.el8 >  H   ,0e U]_߅ڸ7)BUFm")W09s0_ID@A]: "7gMBH1PCݎCO8kXh(xڰ@ q\BcIs2hG1\ ֯]3A7  _9nB!9Bzu2NR DBre`C,Tc:KZC{e>ZB&8I߫E]Z`sN9w퓩fx3%KT31bbP6-PC~ !B‹$ n|;yfQ|?u8}g`h+?S\ݾѯthnkseDql4_7pvӤlo#?e"t_A n ֮L$QQP2{m)3)h՚7!jknJZJ8A{uuXZRv/[L'ӓ֘T]b;Q:8f1fbec2cbcec8934a3c82a819a87ffa4bbf4673dae2e6f5b5230a247c3c0c30f5b1a73615ae2f9d8445b65d7c52ec629c4b1abc0302047c435bb500673065023100e71f3d08e943403130aa085a1ce46cff569cb2754aad2fa82f320d355e40e68f08211823cfda1fc46dd8276c989c7c4302306f6b2c2c3e7661b8adf725a1d87823947a3a68cb722788c49cccace0521c18905eeadaf75d2f8e6d4c049efbfcf755e40302047c435bb500673065023100d7823fe9107320fbe6fded4b2916a32fc75ca2431c6f4fdbdb0c19af4a7bcc35bc5c009feaca4aebde77347df6a1552d0230128830ab81d4bf81f049925701efa8bcf596c102fd589986e3a59c9b4d9a4f849a58a6207dc8556c80f6706124c63eca0302047c435bb500673065023100d7823fe9107320fbe6fded4b2916a32fc75ca2431c6f4fdbdb0c19af4a7bcc35bc5c009feaca4aebde77347df6a1552d0230128830ab81d4bf81f049925701efa8bcf596c102fd589986e3a59c9b4d9a4f849a58a6207dc8556c80f6706124c63eca0302047c435bb500673065023100d7823fe9107320fbe6fded4b2916a32fc75ca2431c6f4fdbdb0c19af4a7bcc35bc5c009feaca4aebde77347df6a1552d0230128830ab81d4bf81f049925701efa8bcf596c102fd589986e3a59c9b4d9a4f849a58a6207dc8556c80f6706124c63eca0302047c435bb500673065023100dd124c7dd4f9710d9a3699735821f414bf4251c98c0359bc3aa19716d85975bbf8a2affacb82c6a3c5de1a6af5625c2f02300858dc537672a56b42e7c68c95a16731dce5b14f138c025bfd5961639003f7a40e614b975c9080aa858ab1600e0438cc0302047c435bb500683066023100caac7f8f2f19ddbe8e4124cc42815507cddbdcbc899b03606a04ced2ebe1773b98e7d150933ee4eb81c760f6366b438e023100e88daba29284b618863934bc82bfb87d746fda219eed247a4d717af3a0dbf935f55f069758c83f768a64d206f1374beb0302047c435bb500673065023100d4ec04ca8e7a37ee93363197f1e92585fae14b4baf675202f212e7d3afeb150560df7fab87e33c67ecba19bfd2097fe602307b965f57ee5019d477e9fe5ec58c774c80c4842392cfb882011b3984b654de4161fadaa9cf202bc13033179783046c100302047c435bb50067306502300858bb27630b3a86cb6165c9ec5d30f117abc8502b73242e4e79f9ffef77e33d141bf002fc4600c1fcab0d619aa42364023100d943940d95b3da3dceb916f58b9f887d54b76113b0198d2c8966789b3982817ff78e82e02627086f6989a2b3b19dc6ee0302047c435bb500673065023100fe2e22d60c6e2adeb13a38fd9610c6f71f5ddfedb7828c8a62c4fd3e994a8b74cefa3a3fa2b4adf78f494b8535235f0002305ad54c57420941c1e62792ba65e68a5cd77729146a8714189e57bd991ee55cffda30f9f823d9ee9bf571bc3c4bdaab5a0302047c435bb50067306502301677f1a55d6d7be54512b0050119c2040f1ca9306638fba6d8c8cb8e86308c7b770aaa9ce112dfe78d06fb0d4f30e059023100c94d01df228388ab56789d0a8bebbb8b9eedb1bcbce5e5e9bbe5804df134e6c9c4b374df300a609aaf46abaf92ccdcee0302047c435bb500663064023059483e05655267c8e8223900383ae094bf7e799afde44d74c31a13da669195320bd6d742662ae01e62b8d2fe81a10f0202307cebabaa42f53385f4d02de967ceff926d1ad870bc5f34a3355f9bebb29166ef930ae340a3a2e3e942c2e786f70f93230302047c435bb500673065023100d7823fe9107320fbe6fded4b2916a32fc75ca2431c6f4fdbdb0c19af4a7bcc35bc5c009feaca4aebde77347df6a1552d0230128830ab81d4bf81f049925701efa8bcf596c102fd589986e3a59c9b4d9a4f849a58a6207dc8556c80f6706124c63eca0302047c435bb500673065023100e71f3d08e943403130aa085a1ce46cff569cb2754aad2fa82f320d355e40e68f08211823cfda1fc46dd8276c989c7c4302306f6b2c2c3e7661b8adf725a1d87823947a3a68cb722788c49cccace0521c18905eeadaf75d2f8e6d4c049efbfcf755e4!@e U]&:&teAld!X#OO nC$P(6h'0IͤP%zN; }TN0G{]*bZ(fLu-L8 \R ~r{%c[Du>J9_KVoi3B;$4Ӂ/( ië/".׻pKy8N֕{W!7IV&|Y-*R [@N Y Ql K+{':/6N}7'Tŭ>p 3lu;kwP'1 @V> Jv#} ] ٩v2 HLʿ풃MONeF).g y B"nEP0آ])!RBՈ<9c~P`B@?0d   B   =CK`p         Y     B\ 99 9(W8`90:h>v?~@G H I X Y\< ]p ^5 b&deejfmlot u vw x y0,,Csssd-kcm2.9.42.el8An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.eppc64le-03.stream.rdu2.redhat.comCentOSCentOSGPLv3+builder@centos.orgApplications/Systemhttps://github.com/SSSD/sssdlinuxppc64le if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi%6 ځAA큤A큤eeeeeeeeeeeeeacfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6bbbac31b33f419589e342f20381138c0dea737fa71b0d67a0db97020b4451afd8c2f6ae53e988971d19b13a2104ead7d8f059bf8e7097a1a5d82ccb81764fd479025425267be7704efa9971eda214bf7ded826999f42b58ad29fd03ddaba80c9f2d3b3e2e74812d889cd0e4a8c1f2971e0cdfde1284e5f67ee8fadcbd5509083b44bd648cf46f1b905486e147cddeca2dc8dabdb0dbe16cbe21b5704e11662c5f38f3dc983295fe47ef9a481ec58e320d309049cf1e76c49f3da3c7453ec26b91e76481a8b8e49c5ab94db2b842f6c3ba5e7986ff859e398b12b7608dec7fc98facfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6b../../../../usr/libexec/sssd/sssd_kcmrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.4-2.el8.src.rpmconfig(sssd-kcm)sssd-kcmsssd-kcm(ppc-64)  @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shconfig(sssd-kcm)krb5-libslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libini_config.so.5()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.15.0)(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd2.9.4-2.el81.18.2-113.0.4-14.6.0-14.0-15.2-12.9.4-2.el84.14.3e@e{@eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.4-2Alexey Tikhonov - 2.9.4-1Alexey Tikhonov - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-25064 - AD users are unable to log in due to case sensitivity of user because the domain is found as an alias to the email address. [rhel-8] - Resolves: RHEL-25066 - gdm smartcard login fails with sssd-2.9.3 in case of multiple identities [rhel-8] - Resolves: RHEL-25065 - ssh pubkey stored in ldap/AD no longer works to authenticate via sssd [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-1680 - auto_private_groups does not create cache in IPA server SSSD cache - Resolves: RHEL-10092 - logfile rotation for sssd_kcm not working properly, sssd_kcm never receives a 'kill -HUP' - Resolves: RHEL-17495 - New sssd.conf seems not to be backwards compatible (wrt SmartCard auth of local users using 'files provider') - Resolves: RHEL-18431 - Excessive logging to sssd_nss and sssd_be in multi-domain AD forest - Resolves: RHEL-5033 - Incorrect IdM product name in man sssd.conf - Resolves: RHEL-15368 - SSSD GPO lacks group resolution on hosts [rhel-8] - Resolves: RHEL-10721 - very bad performance when requesting service tickets - Resolves: RHEL-19011 - Invalid handling groups from child domain - Resolves: RHEL-19949 - latest sssd breaks logging in via XDMCP for LDAP/Kerberos users [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh rusvuk2.9.4-2.el82.9.4-2.el82.9.4-2.el8 kcm_default_ccache.build-id1f1b03365a22cd694e63eb83741159395c4cc48fsssd-kcm.servicesssd-kcm.socketsssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/1f//usr/lib/systemd/system//usr/libexec/sssd//usr/share/man/man8//usr/share/man/ru/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mcpu=power8 -mtune=power8 -funwind-tables -fstack-clash-protectioncpioxz2ppc64le-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, for GNU/Linux 3.10.0, BuildID[sha1]=1f1b03365a22cd694e63eb83741159395c4cc48f, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix),R)R%R/RRRRRR'RRR+R,RRRR R.R#RRRRR(RRRRR RRRR R R$R!R"R R*R&R R-RR3utf-8251fdd35aff3e33a4ddb077961627429628f81a6fc626d8d38ffd24b62edd62c?7zXZ !#,\] b2u Q{LXpfoFN4y>hܣXY%ѐ,1SjKgj_B sf,8C%KZ i*d+sYKpO/ym |8NZ_4X\ +>5T| p_jFfw4?Ex&-:'XU՚t}Ngx9O(m5q ^O39ͳљY.Bԃ~U7sK^kNG\ְN5 _%N@,|ePq]ċ0+ =7x6e mV3t[ -1Qߍr4OQxPvb OkA(cD86?ƢAI`;ڍmZ9#67NG娰,=y?UpSc|'Q} S;(Lȵaa'Uzg@a6bu3NLlĸ9!8UQKr?s.1\ ޜ)imJ}'o|m!Pq=S:475hƽv a#r}iC"F|9-u@pf,UkH?1N+iyfa*KYP!cV}\3gGuֳ5jbwE=wϓ0F%̆+!UVP$Wԩ5$ܮ RDŽ!Ky.^ ,x ?+;P <=L=zỿ(U(CMeaJ%j`$xeYn_aL2S#[`,n1[EtM՞+].576.n2ɠPp 3* e h}r8ꑌ)&[2z3ֻ`<QלPz{>ҜucɀKx;NQgtPYk/o~i@CG|4IG$Ȑ~~mb@~3uf@a;!ܲU!GwQHg)MCP'q!1q2e]Na@,!k7Ȅι&a2 w;P^Kނ} :v&'Ep5{L"GD~'ZMpR HvtA] S"0aFDLi+HqSnwMX1JHO"l<(?I8L(֖sL`*%`.Dw xA_2hiu+[£s5N/fѲXCR(smlkg*e%Smm~Q)Rb+bPg7-릠yY*07/<3f=u!Hz׽7.{|h_i$+rB)n<}6 [UgqA &Q7l7|L:vݩm9%"by]٧JjzN*5k1J3bva =RA d $s0+kٖgפU 2]|MIs[цe1%lD +Vڅ3$e!xR \ 1!<X| y+dMrr!iu_f\rze$-sf'N, iv5\inX05C<0C?ҕb@ykp|)_bȂMe #vl;Gp&]5uUJm]J]Aåg[zrfy 唠$RɰY0K<@{߈mxNe+' Q~(u1z3?g_'-I$pOM^X\ '6һprDEnA]:H*P)N$++W>k2r)!:B-Yonn6-S7WA&uNg.7HfkB` =o2@:"%4nRuzS4Ek&K|qr0@H+D0;5bdDCGrԅńƲs,T k64 ʉE,o_Sׅbj$^zekُp0o?i9{BpQg9;)Hfa1)(و kIn^W6f9?h6 ?kI1`_i;vMCh6U >=L9 A/&gRۂzF~۾j;h"Zn?r`#^E+ؓ 캭m [5vw,sSwv#uQȺ="jUu-EH8Gey`ތ6ld @z6E݊UntҙymNVd+kjTo .Y,:"%` ɄN4VqLn@l,N&X!JKH.8;E6kLk E`sqtUv#/=xN[ZVM|f_26$67ϴ4K掳/pc,"[ݏU5&pYF[R *ǥ=dy'v+U mZXȻek,Or.{¯ϛ yiQeOʎ(kҍǵx%a9H;lm7)kt=U0j"jnԝ &},ߟ NY{jH, 8a=Jm`vT1)-(6ܨ[u{T,l"K!Ao)RSTʁ"P-7߯G5?R\mSKzfe<@vF)MjtMVh?C}#,Zr(N2&DE#ȂW4hHn㘯q . EGq }hLa mg(5{dΖ2$,#nwꑍMx W;g pIwm\k Ή '`?lD#u)*.#Ik -Y;d4c\u?&5덊-xi/ @vf%vA"kb ֶg,k3(s|ccTϼ`IYFZ{YTJ6u ύ?_BϠOlP1f)Y݄|#Pjf)=BR9Z1sn9V%+bq ?y,D? OuA:#fD\3ࢂ㖮 E!LZ˾E ob] o^~u[NV. q -ڛN %Z낑cDC58,es *5U7`z_CtHO/TVbRXjD.l}7mP;fṰƖB*0y7]ۍw\"n/Բ VCvR]ARr[ww8pnT`ȿk@ }|ͻzhڅez7mÛO؍LF C>ځ ԏB8 K`kwoFKE(i^b?SU1l@R{4ЛpXܗ|2T왳kUv2/CWCr%5UTj'zsŃ )@Gr. 3mz^_z8Ljax27_W!rh vJ̧87^JTE 8̎ݍ^*ZUs{Bl*O)N\,դn l )^gyH f |jrFFælˮRz~`2b@$>_̡i;;'y\+-fٔ"*Ʃb-cq`= %9$9 ' gP`[*H')!L>d2v$CH@A+iEJ6Pşpsr#8WG6FFz6BIݔ *cm[wYAClt!rp}BilTPL 0w܇+?}ŕ[j@ Vx6cN8F1(Dvryz5~s9k9}+]& /8V(p74L1Co=p2R78L3:W&s9YQK~4}vCjU\މZ~ k3Os^0KjV , Lʘ)L'l)9lj` 82f4DFOT"!ov^02sPۇl.S` e_ň6##>nP4$OUlj vrƩ@14bi oZIdֳbK:خ<'zFnb\ta犌={>w[K [VWJ:"}¨s kU cK#HnG=A؋q?<)\ ;vQ t^]񻤖ZDG=@Fxpe[і%-<M8R9 ȓ"WJ|R65*qhӝS5O낦~r:֡^h ,`>dÚcJ~q_K/('_X%(C3p#a;E2O$ w,V:|gPfnCG nns8 v֜W4Y_7YEh%2!hrG^d;kJ/ܒÒdHe˒/ -y3GѽJH=Ghαn t~}KJ5bB'̺عmҿUo61ε9ֳCu_b"h}!JYmreu!AʒKu[ /I>ы?;}[J1-(Nu|}OƐ!^xd\T#s}Iot@RN]3y 4QZDoק/%kd,@OGК"g 'A6}6$5T~T$̾/t`<3cB@lNNIDMQo0J=]IP.VOEE -Ss,D8 IQVE)*_$հ,KTng&Է{ibJ))wz ;N ƞCB@FyX?9etbw,:Vm_}Wٖ+(|Eq9`2 9`V@̙^ xn #<81L!,0__(Pt3m7(p)$^'ْG4R u4ĽWݼ! R n- wAH:NAMc u(r}/B$\,_:."W"7q]?:1ltqKr._(iʃ;'<&Ii$1H?fJiKD a؇0o*>'WzSpaĺXet~.G>x}pH{P1ɽ ^M t7c6YiȬrAth?Ug&T;`d3%MeAsjv5m-6`#GڕkSL49$b$c]26y6xt ^wV@HZI`+ȌF \ R,`K lR?#_+(*q䗩s3J9{8Sq pOX62,g CaO%/VYa^^8:2ǃE>X ,n1+z_޸JzROEKbޒ~|J6PSD=5> ׬O > Q%(\h=\ʕ3y t2dyQyZ4sTH ʽHwZXk ?Ʋ7"V:nq07L#   ڕf}YoP ΰsF6C?FLP0hd C5 rByJ`~b=.׷>mV05Xk앺Q{wOSF̯GRɃL̝۾Ow<-^ͣ[sIbx+|ϾĒuQx2m!. 96K't a0̴XE IDi@IbcqQ?cl! }1X $rJҍԯfV'/pTCX%Q́*6'H*7^b/uf1O\Be,'~LZ %FuCD-in`j#?҅C:AͳD'X)}邐d5r Y8)2w6*#m"P+IhWuD_`.U}U&D5A[#1Q+q\r-UX3XS]m(13wwB8vqX;ri bD[FcX|5!Xu,2.54nxtuIb.՝{>`msKV|1*O¾ˬDCdHH/;2%`W޹yNI 6ɨ3]p1Iޯ^˱ֺԀk)T"GRidHo侫IG@ᖫ^zaRMzSǡ&DO1S)-VkՋ˵־&):K r8T|E:!:SC6M9uQeS N T:  RLKyosW=[`^G̓i@[yn 狀'*IJ /)C1/Tc!5|+'vTV\_oزmH!8`|1YIr%)54<Ž3sk֥`x. y;e_ WX-وw0\< $WɈ|psv@µq8)jgF6 w2"OYUg{j'UXg W&Y|7 ;ȌzvNw[>JlsNѧ/"sKVu'/.-?œZ9o;ZB$]qljxJ=֞Q#6Ӎk53Ir >!&nε|D}.Qgl%ysk3ŘN>R%$0i'Gک M׵;Lv%!} ] ƎFEo0kj$>I#kTGrnjƍ|3{ZNdTM.U-m1y?}a"XgPCT-"(5aZȚ`bFнKA76{t_M{_oP6^ PCjŲ~E(s~u؜ hmpYdzlrV^44́&ɲ97׻hC@~n3VxZ6fe?DCCOn'[+~8xjAP='u|rn*# "A(wM_ԝMDL4ؓi0КㅟY;o#_9pʤgwzN^L4aׅ\ d}w0\@E'NGd;ӗ}äl/79i#H p6h-:D:r}^󷠡ʥyF&okbSu.AK,Q Qļ 1c9`.p))E^]S2|M{Ç 5Yi {bI~Je%j8ȅ D6+N8?b^)_:2h&(VMs5Y|u#oVlxc2B3ВG Q|ےak.1 jaxE09D*k`jpQKze V[8kt. #EdvQU_j|$ k|ZАaD ͒牊xb[[mP&2e˾:(b)yvvsGS-N ǐ1}V@ڴUIn!3r.0JRU| p["G[Ce:KucA&qK 10~6 u8J ͥ.EdK.(FnR:/9Q{4UޡMzK䐌y;kҫ+B1S < oe$ӲoNQ@wriEwP6q,^#bB9P52Z[yL|6-gsOezd!Z0˃;Z~{# ;5HZ>u 7{w>DoҮI<9ܓu Ю֑OJǩ]{vf_5 أonL-B5wS<%S ,ǵAw/H׿B> /&Hx[^ԸdY{ DhL~<~F࿳}KZߖ_( n5j}0%ew}NiIYEu۩˟"LB9G_a|]ZRZde RG2 %m/^]L$ ݥpa'"\ }N5%zKجyOEp),0BO60 :d\$~3&|1aKՍhj73ZKϋ}[`NH?R]/0 ژbR$-mv}7D@&1)@s$L-C*s$CUCibyi E/%ZaWc88(J!{=MW,J@^ |!ThH͐=P ;ﱇc}!NC|t;be q'O!hw (T݇j257"k#ϰ-BO+:d 󃮨W'>zaXg?TjbCƼC9՚Y=z5B{ HûQR5*F**HBnbh|,ijo5@[B`mj%JZ ds{{"jL]*uP}};POK_m pQa MIȸ89Wm{=eiC^FØ3{Uޖs:6D],D$#M7u)Sv$ D<+n#3^:ټrb"Jc_~{vv6KpV5`Dxh{z^{ad+ͰS_&ĎW7 ?zM'Jyע%jƥcWhko"mqC>_bђN^GfK#E\m o_a].[lR} $&a5MT;B!eeR5n^hI'x1X쓡yD.60bJ7, &hjj`+r$%f}JD, BM?x T1nq<;HNƇTLKtA&Y֋qSx _,a#yBæΨ(!m>@vngcQ%* 'aרnV/FT:Z,> b̫xټ3yv6/ho'cǧ2*}E6ݏ߾$psT*R?sW@E\`S &t#6T5 w *rףhNXa'aD? eeDLqBt%fAAkܶU6!v(L_W{\]"ND0< 䜌!O&+dai-r\AJ<1 vZJ;s "7-e6wn {3 FYJٟ}D/g&N5OysΕ=YciDՉD~b%$$7^+m_. 93.xHܞDzi6*O3p#orx92K@=FK{tO'ArE4v8O shH c:hiz*fŘ3ޠXbaP7p۹~f"x?){KHSsL/bĭ !36A _lTV%Z66@Z cQ%nOOf}$䡎q'k+]߫edUќmw22(]d#N%SEfae뫲k[/!O[OByxh6Ym(9}kiM#{4- 턥:Yy E>Tr> Q^S6Y^ Ē~)H?QB+p>wy8˔(.8Rvݫ8 Ȍh#EhL֐ҩx+.;7s6(ϺN%;vaI9z_;N"k00QyeK,^ 펴Pp<7@~n+09fczٙXƽ8;PC?)ŠDh9WH)dHO\MWoPr/>e`mw h҇V28ϩ=Sοih̻E}!\:CANJNz15L>:TT]/05j\(G`[&M9zT_Vq ^T2=læP3え,|~﬈|dYG!бL[{=yn'#D&c1Z; '62z೥k`G>:+M;ݓP b>c Wgk_;'Z$~CoXh9# `wJ3a!I5L%ԙ@X)K FhÙvp~3deS*Ͻ g_kƒVb [ N}$/g/dxP"۩6/ƵJ1^1uܳ]+}xYЋeod'YsDMp6ўՈ|N1;q!O$X ,9H'.Fd?9dzR6xN/ @'WpH{u3+u\{gɺ(^(RCuAq- +Z$|OZɂu1 (F:k9cKl(+ IkVY5AK=#,"VV%UiLNsu*E$UjɈg'q1 $D@8ʂ4o7wDJ27 "sjs%c@qxKAϡZ/HIX05 +*J!謁hj m8$DJC; /G(5M% QB]KVONߪ̻E]14B`nC\\,^5]2bhfgao_O0QF"!־$J4lSe;k:=ؑnbuV6d/`pX)[k1uES';9a}̭vj AUe4qRnlR?W(UGE!gO"R+5_OLB*nT -p|L;aO1G'UX*Cb*{iwTjcP0?BI(6o)#{\{g4"W3M{A }6p&䊶dP6,sI< HNcLy;AtR2=i;͸.`ފ]ZFM3 ˬ<:/\};E^lrx-+'7̮=Gt7}ײSUi\TTc08 ;)uL}}z4t ȶ Ĩec Gc"ps=QU nl\g'A?Pu0Bot2>S9 DL϶BJ2fi) ROO  jD6N`#j=He2ف,9s,r5^,ICrݼgn M'pfPG=NI"\Ny-|9Ҧ͑O~-BׅȜgCeF Dwg;% "g#%ɌF_(;\Nnou3Y[U^lbH7U~P,,woGHHF30ǹ 0E,Za~4qSw݇F4b)гwN?g,R@f \},zN׬eN#}!3PU; F*XIF.MTKLeH/麩>1M eG 5TX ْP!!͟1u{]J;gp$EiVXiʎuc꣺U)~5%`&v>칹Pޏ5Qrէ_4C_;vf983IgE1Q_4N9Bs5< doɫyZQ@@Ozy)S(,*!;s'xTsk- nbAriBjrpL3QK \ KCoK4 BI8wc;+y2AfᴭOK2LCc˹rߩ#S9}PdBfzn/}=_es)@ܒ:_t ߼!l1; MȰـGwDb RuD4"9 sf]AVZd<]\K>7˅92+G_qϸ ]6 ǁII{8z!琱d Jx] ^&A9̤ݡ$p:w*==;x:1vak0'} )}ºxV؛93I̷[G=q1}*taScN_β&񱣟Uq1}/-\GadUj?|C{L]_i綶j^ /1 XrR9_kѸ94Q^tDHE 7:w%4e}Rs-kkyZ SV=W=&܀~J3Q7S͡BOJ Qڽd kC.~\+s3T{WH5n DT45tx ?n90mӧl5N"[Uj(12M \2˗5 I(oMqZDRmkY ~Ҋc1]<%tLNI+J{>'>|D}>ϔlG]Iѳc 3cSE不IM W.$E4{_Zv Zyu'4ki M>PfZ5"Q$>Ɛ?! q-rD7WpEK!̛խ4d z,NPBMZh1jx|N&pZdht&ҚaQ]8cHwOyEHlj}juIok֥} H= DSנ}h\y<Ěg҉"^q$(|Wuf߆*1`;oUM'&s5?^TҶ95x42:b7j8x6[SBR3c}/ KN*+'_ZBg.?S"(p;Y|D%QAmIxuŘf ZG}eaZ8Gd#V4Bh9L_>ffIWV6x|6g$ ɤc^hnex3=I0ď44lR>q-˫ ^e8qV]0؇A3lpxNG"ΡI;m?]~I6+oYGTH:rx>"<N*d|lY'Ja |ZfReA5ms9Wq^iLgu9X.Coa~i!hPbqkz!z"ߥso7x$B[~}{:?庩#Xj d7N|D}dɯګq4oDFv2C}6*>RC+UFg[Hz zJbITxcc,̘FUa*>8y:O"ƻp\lc7|es/b5T65_47J`m+G5 0BɢPPM#D9֚=rS䳼q9tzut^Ǔe:괬Ro.7-`Ĉ:pg0dE"wHBNϬX+C`miȦ;_ a~ Q8"@qSܡN$E+;Pw(K37}`]Pjv1FrO7z{s- %u3 Ef@$#QYys_oj' [Z]qM<[<:Eh $ڪIFFO%eC2.pFGA䯜M]ZYXl|a#m7xU\:U7|B0r_ L;ZXL`="?uB?PVk2}KE6;MЏ 3]55R|gspr# Q=E3*XVcSt m/JsJXaP{*'nb7T*AŌO/E͝Of@^Z8zf|̳*Hnh?VLi+iۉ{"DC.p{=w:®+kZBMH)@_ž;` ͺ)WS-=V w`0gbg 㭝AEug|$K@?2`=[ 3 WV|o{i\ad# o!9N py*!tX""Kje=2z_e3+1,kbr sw3 [V/@N$eJo[]M0'wzΨu"@gIU#1vY0Lk n$i[Ϟqy~,e' 8b,F/V`vK/Sf_!u%ȝ󢲖30ȫm"Мϱ9SRDNk/(/s\*\x(1~xT3^;%>Bl" o=\Po3\hz Ux"(e t<|nCw/Kk(iy8^N;`c-{1@To@y:LD#BA0ONuynwsa_ pÊ{x}DʣuN5zS.rߛqU,S[ s/*=kKCX (:2zNa릶qJ9?men<1%*<ۆ$LUWӻ بto6J1'Aehݍ ov-,v}Vk*ǎhMTGJb;fndrw(**Oj)n|PŭA  3 O[61{'^!W~v?t$Yo<:{9YhQ}:\!Vž\km)`U^y39+ ձOd!55/YMnZ"2cFz=G%Ȗ'k΀NRɉ\孉;VWk/3lH B􆵬>E+%m:lUWl!p2x I"L%vtw-.kdY-W}xX>KI守^qZeAաʻj&3IwF{/,ҔqٶlsJE^I4xXxkFs ?(2a?KjT3d;lhnhB(104r,~wu<_HL $ԠK2X9 쳰xQ.\BĻ5h(F&q\$`KJ7& t+bQb`+K#%w no:'.+E_ё1rkfVRN['җ AeCUsצ .ѐڶ1K z.3 eh)~g=Ti4y6@~AMƙR+;\Ws6ݯ"WJk a)~Uomyݚ^G=)sun*q2ǩrw?j\Q)jNYB4tUt\7QE@z&f3^ ~EI/ g9|NӅĨ2@̥HSR*QIpNq;WwyF׉LDwlKfGehOZ;CU8?t`20:MGq ["0J6aNɊx0MUS^|_s! 6uHVFBt -$OK.P}"Ui NxtvP 7gy ܰNz4z NUҦq ѲѣDl:ReEQ 9a,+ U0ןpkPoX9bwLBkcQa@酾<@  $Έ -F?[rǹj?d';'Z҆5߸R+ pA~W]'8(sXoRQc?e9Lj؊eƝ8`LҏUq[1~K8EXsi@p=α=xd_Qc:B΂G M/$_Ylv v-Q]Iy 6BYE'`9[wHeeI3Tlێ~j3$!Y 2u-e{=*%'/J'̤9KS# ,]}BcvX6g sd?uȓv'Yi1<чA뵎 tw{촒}դ4+t<~̯ZIO-N eຜTLE[(*d +#Q6mhfȭ3/Hٸ3WIp޴!0Tp3LMśm =6<ŴW͚`UFNDGinaUxx@tQsVľ~70 `ɰvgqƚ*{Gժ-gH9mYN ~%C۴r-; !7Nge HÇ3NQdRk%W.:zƝO *.zZ}Teutc@! gSJJi2̖d4P~=O# iG6l6xe F;l25{kCPO.wvM6g s-j:'%@Jy^!lʒSiͣZT7 ; c9fwF@Smp&e~c'zP:=]7q:0HE,ï~-L0afy03|Er"G k;4[̶m)5t'j)@>;wk,ȵy2XMq {.n* Y] `tTuiC(P*aʦɩB_T;1jDĉH b.U fҢq?yAd/ pIfNx]zԁY$PFmܛ=k8w!ǠmsrZr6diE>\|7'9 KtJV+Oo@A1h<; iU.*uzb/,` jFE,:DR7M( i(0rfK0y3bWC- *-I` idĺRLBFDE)c)M>Mf?I[+[[/\cL41O`LKm,xfz)ʡ|NYP3ӰaJ>F^v:=i!{&otC" G~?]GżEvqD:ȝn᝽C$_r_Ku JҊ(Q|Oޢ=D|k23^S@IYC5Z~zk8t0mH&m&?rTDdrָw*Rfܜ$@V7UO57xYP]ŲhUqP, 2L+~QnOPbB%2Zx{brK(e䰣" l0n@Mq^){O 8] \a~Ñ sA!\FW3ZLAHjq\K@m>l8#..Q+Z %QI`e7u$.IYNudB U׽fMh͍YuF\lT{dUl2QH9<`yc1;f6Q&mfဴZV2i壿~6uREԍ&)7BAp"2jϺ|#?Dp3~_Io[% KdtzB`Eix9Gz{=xy2r#Qd աqN9{"ԖξXDj K͂'Kyh]I*[`LYOlC`v툥ʑZҼ;E 4m*k/R8E$ܨ*{`.)"Aw\ o#4T!+ʒ*;\'5;H54&5j|u,vBfzQNoYs'aߏ$8tD/~p*v&Pn(TIAL?*1V->7"@֌j៬hwXbwkݸ5$kȴZ-9Y{SC_FfKax;_e]9^qgoh1‘(N 6c4uF7Kr5;fB[&//ZLSW*%:{h ~2iфk,glK,*/ w<= wg<1]ٱ˴bgQ(lE~Xm -2Hз[@ˎQsYəh:,j:"슧g[vWJ~vwmڊBvo<$syG[[J`榉Hֆ@F7EZkgU^eN._CܒrI({^icƹ-:+N,[=uIuob-Nm;W{J0# y9@=;4[;"B(Й궳&8* ~wBtg]8fL^ W.5lv`)=Y1ZJ"fC56}2uY59đlRr)EKD/riME*3+v>&YFM;eILpX׾2V39 GE% S~ZGYFTnI['ˏq\^=~Lt]O[p}jmE ildtZp#Q7=0lO]c#x&;P6 _b.ֲpAsߓ6bôDBt4qBRFm14Ub^c}S+?,bLO $I'iJ~Ô:HQGvډ*6޺qD_>ǝD@~aB(rw4Byd|x ǻ뉳zP1#5O$?9[μZ@z8eE(Ll/' |3_)bˠi`^1X󑭵\vXRHՔ?Y|۹jd(&fF߶ŋ j**E {%f Wc҈{iB#׵r&ɦdA(ّc$T5ⅎxۗ<2}n|Y nIp:kKeJ|6T&3@@jݭ,i2߫ifd*w:sR&QW!wmkku!8v~)](w67{mX57z&[J]^7tp:/# H@3Yf92sW̱GvdU\fAu8J҆@bP,9'= {WbnF|_5@ 8W7ބ[dlʜdEJ}V$fE eJz`+v,!` DB(/]J;oP_֒¥SqPNln]Vl%, Z%YI#)u5R&0ߏ&+4dS<{_mG!ډ9.]k1;r' x4:x316USkuHk1)qʢm{ӏeM!9|c$V|=yKr9u.b̼[Eʉ`p~+PB =u+,..{azqLR #;(&})8 LiK,EV6D[58VيS |]PY. p~oN0Lv^TZ$>RА7kW+;JQߍFGɘmA&Lv7 dOmF#~=TLepXI>(RKd]isyH'sQgMOEVM& ҭP^d ]ȕppvwH %4;Fjt7h ^]qP`AI@Q$O?1U"< -W@|quY!s\+Ur(yQ7T;wRAkwPM ѳiw8Ũ߮ WЌNo qxP75*T\G8 ~ U"?LqiT ' dUR؈5/T5AB#W =ͥFnFP@v&:v tqjH,wQ:0R{2ۂ)r/NrgF^'-{fAS ]`ojP$K@NK{P8L`}"BlMLV܁tK.޷G`uua+k < tb*b5mH`h:myH-7 wM6Sw?;H` }+0ѓ_[44Fw4Y *?vFXju-2\B{[I$!J -qn'܋&~('zM3 ˒ tJOw7G=5p9 "؜Wyj"t;("6Os;ĩǍ_cvrHn(# }qϳ?\ٓ] (%i B.H\zb>:ki"it[eK\y\ڽIN!Gܛ]] E=uRD" `5ӪHm.$nfdײH3I5ؐmE^_UuH^j$̒itׯ휪bpE'𭏈&pt;VƱ%eRʫ]ɶzby*k+Kѹ,uHȑ),FO:^F rv#z'ɇ`?+\yO[PǛ.I6yH!HU =Sݵ|Ck fu\(ʣnݹ )uU~ C:Xtb$z/z'oL_~5UEDfQ%Ibcq^ۃbia2zAM~TkA\UeeCޜ2/Z jcnzĶ10r| r$Ű cId-L rv2X/ǼAcU8ๅ({G&-|4?"BNtЭg"Zڟkڢ` (sZ2 u)YzdLGVq I-%4J],@9ciGˆсPuv[Av/GfeeרP:?2N0tdTM%Ua*TCsG+QiYRFݚ.znUHb  g)F6X )Ad{}6ch!Kub@ O1,vD8EN4f]Y9EcP5pOkiԍ"[X2%jζaٖ^sZ")Δ+ǠzM`=peRNxekDRκX'k yI op[G|!?7&pGsT2~ب4HNe ʯ&)Dq󣢂$6>,shA全'D9o_w wdC( }'B%bS 6F7rdqb׆Y`Y_oH8xs+z HW%2(:Lw, ,S!Xl ah+:e|g=,B"_B:p5417MH+}:Bܮ!F/l/6R]5 =ܐ,אж^+P5D7xfpXG'?7j<߃ 0?C̘c;],}xE{Ur!SԗbٟXη qp{hAms4߉!V 9Cb=EgK8ہ(JErQpnϖ"j/\s{Cݡ0E#'=+ TC$Û]fLV|AjAըe-Ԧp1gJX(#9 h/Y*zUC2ݚQs& g^T`wBv qN 0Fd1 *%&Na;)_|Ѧ^$"nϹ"o2vgU$EDNJVْ(ԥi6d<*<݃w) T@?y6&ɼ y EW?gcN^6':72ߓe55VʦNt]Ův:\ TݺF5,va*Sh oo)f72D iʨRZ>hNr7sSLt[.̯E)w#e?%;g!T-M{ag־Xku`AԆ:K5yRv7@ӭ{=|{/F9CL/ٶ|xn6 ;aFJo լ{_[qì\vYfRu?_}`1b` w.Tkig;~as}'JߺVD7tU]oG?YpSk3j-ץr )HI?p 8MfB#ppcɰIuw*e91΍_<Ѓj(MHl茧#f^kg'L׽T5Ovf<S`Y-K${PG4捤T$ߡ~E%ERDew2Ɵj5%mCt83ʳ4"{34@.C.<%LL{,W7k:H5E0m ־Z[ }PuJM?ؤQ8U;Y-5@tU%S-wyqR|F?َz$]g4Ʃ>;PbXMSg:0!d;haZݚõa&l#]ƞJM}䫁K݋_kY~~ӿt4rT &$\Z:DG.̧-5aMU^ 'hsɡAEQׅ~c2Vu5斺qizۡ҈q;Jpk nOt Vͫo:$dL0}q+HErA^%E1`1.eqb!K*#Ҷ8+,Y%ta I9iIƾ4DHTg\A1Q4*, Zpq0<Gl;7_T> ֫-tC3myݡRM]e2΋gf~L(Vp->!k@vﱶ ,GJaֲ<~MaC03,^h'Q&} rQjMzuKo{QG:H3j]sތfžkGg*![dd$evgL#Ff87ʀUPI1MfP"DE<=X}r;~AZ,=$^~6Vu ON4TZPޗ$gZE"!F0:q9IyQɤE/ |dM$V2ϋqX6;~^Ѭ?!Z*aB ı[ᐹ]ֳ,xJ-w#'t̩#S]O}NgQRf7igt5qXiճ):-<7?*J}Tk9T8; n0?Ql Ƨ"5dpdQ@Kg8 ! ]A?6h$Gvru|v8Y+?h"tx hOaZN ' 3#~^1)YHFlO-#6e53(և([ϏF0- <"Oz݂b 5Hu=v"TVgC|1㆞-vL, ]C2 kُK}1sMG%˹:pj֭Jre@6K~p8_ kBSlJqu(?9ҽ;m%Wqgf*jʙ'k 5'ܽ7.eLdO ROAg&L60~LjGJd_}i e{g^$>z-)ODzpe-vc3H52 ;ӿɣkY PҲ0u^"IH*3'y*'¸2?}z>.ɀћ/Y,ؤ>]F=G`:kQ!Q$onGٽ70*I!Hf. CP\`o6C73 dO/2m6I,6CÉW٘@K×K%{Ŏ0 f3e"^6[0Mr k\KΫ#H:UEvReR,V"œTXK. V!e(@-! jL3CD-\zt; }kiTn6dT[u?Ī2@,ƄuF[S;Lvh̅eUj'-Ru6OsbE8]@U媙y&r\N[=IQt4|˳P:SʹSpl-{Xm\8[@:HQz 6l  \5e6,Hw0! d6ӓ(OIG0 Ƒ*TaZ:M!gݢ*)F7lĹR~-ƙs{ƪ=D?Hhl? T9#*ܢth܃!\vr._pU_PClMwSVb~6 #0ZNTHk@sz5 O4aX +Q.2 ͭ!`r|!EEzٟW׊dvu-lVh3H,(R.d6ڑ,crJ +$Ŝ#A)?܄NErA?Hᣘ:]+9_14L?rc?b;B@0ε,zd>3"waEA;8/O6  ~1@gUBl2qwi0׃ 3ֶmyg8 ͢;g^7ͅ|1Fv,\ޡúrG,N@ {G`y=W /2 eOL<6Hs7ZxjBWkkW2q6KTŷ+$]bN`YaJ2UK ?}΋ɬ ;;Qwm[%3<\!\{ۯf τncK-!U'|T3~=ecXE31RfGC4U37+''܎kopkf]?DQd|I(;^j)[e䃏S?FK^3i50ܿ,jH5!wP4W$84nUĝha<=S+p2,5Hh6\-R[1Z |S->ij% [W ĄJgmϜGE .63|1Un큕G>5XϞjAX׹9:op.!2Qvt@8X0|B PKQ"7kp)$局Hy{/F?&+>Ą‚ymtN»&tK=<%)\Jk80ťwte̥NgA"s T,>cЕ^'ѰD\ԣb)\޾WhwJrèE : =ded$h8 ðlM$wOi1wUG'#X e+;F]Zl?_șYxUfDr'k6ǵ[ed *B㏑21޸|"g6CbAcMa$+P}Vʝ3q6"RE/w@දT~B)t^& (|mWwy'_$W@3+ z O04'CR̹Coֺ,!XEm-d@@)AM3Wv2žF =Q)'uKP\f.H\ZN\ۈO>ycBt 5jBd$v3hG3SHsq&G e>0R fJ\tfVF~w0ENRlKCWL-wQ`"+̉9& - e `i%X`;maZs/&XS/I ia8d>%'፳r*n9:s]TAVH38 0HHڣv$]i.BH[)^n[}??/w\8Kv1,/zy9k-,&ME00:\$b>&ű* D3_ Cj1LlϲWxJfѬȂ;V <UX%!"j㼙dv/wLM9ԳRgcuN0|is{sv0[99=hoAoA6n/׏gv凖Vh\{8t0sUCnI!! 8ovhު{ WiXF:&RmW|XLwjBV:8ʊRP3xwMSZQ|Zd)G6h"7*oekqߥN̩/[?3'_l4X'b*J6Mky"jNsU꫙69[.k84<%@(o~ź"~0jnnaEa_\isae.\ x-80z5H-}++t3ܿPTwAyлtne`+ke繺߮'@ X$y qw[fDC wHC"ǟ.P'C>͖+4ՌД L3/= ๢'7 _K;[գ&tt'M 3N\XF&!=^ 4ߪ*+"5o4Rk;N#̙7ǵ+٬Bzy7CYx K[a/Yؾ?Ҫ/kr[e!xoqUrL7;þ[ƴFߗb{DeZ&*cז~F=`Cw mǃ6+J)ۜ0*lIoN'=$3B\>fLD*.mߌI\yl[ܯ+T͝vؽR N?d>Ks4N9-.eC)Zz >|cBY7F³miL*؞XJH8"igӘ!QZp=7\tzP"0;ɏkzU\W֝cIB"UFk~74hOÂr+1ePY%O|U~23c#C4wʬwwՂjA*rk~ݓ \5ShH:Pѥp탯FksA,&Xr:68{ge +j,v 6gR/Ȥ7.]~8ĵkIPR5?QcӆLcOI0NO(VI^XW7oɳv"_yjwً꼖r1! i;,APs WTO"K|=}Paμ .g%3-e8jP#o_k{1k,jǮ/m<ƔffߟS謡bJF;ehW]{l}.Kx7BKI4}̢SS|PBZg㮥ٱ\)>xCU_LdcxT`ݮ= 249\b!PY;[o5?8t}qHSnYNqKJ# [ ]$ټg]O)+b<`aY, *3~HYsj_8^”NKN5y]t@d{LbM˻zs||6^HY1XqA>c"1{/6R z@G#Ii e6^Xg1nOALI{AX-*^C)P`,_h3KG؂/LtVob?\C)]I'A4j18fenLE^ 6Np^hl>vw@͈w8??4.*UO̦sl':oܳC4"~y.e`e s%*`1x[||ڶRmPKwΆ1M9;c:+2qKHâ(+n)$O fX @.?,b`%}Nw? PO9 p6Y/E>XڟFt~f"E6`[5?K"WUs8!ɔ# O'=}]¾װ wz^%wM(:$!~5UOu[& Mh hzU}?Nu y0/ESRt?Q" cPv&V9]QL9DRK*՜&l=֐,v!I(-Cjkw:;5D{W:&pbs8D5P~hiN9uexT0+YJӚ⿵j #edG @u78 Z阴HBw 9/4 a/Tcj-p8R4k8` D`QJ}n)5_P\`"9R-6x. '1b5bJ3v FCK.(KxDއuaA),Pb&Sk٤E_vbW5O{YԬh +,ו3:Hv5ɾC4Z˯rtVJ#JR3K/̙ [)67XSkq-Z4&Ew,ve6G.HUyNIh8ni" avbE=,^!M^h[閧u܆ljNbSp8.탮L\{Vɀ ?Gr" up+/(TuHw[T0}M9{ lham r|}lC t_aZ-A4ʕ8"o)J9^iHy#* U䛃HOດF0PffqfI!;mH +7+HdT!B/ vtF/yǜ^ ˺m̱P3&%Fl jpH;LJd3'[qDT6xq0ܻ p֪:) i[(.h?C8m`dö:kx`!Djul7O((M"&Z:T)XA]˕?LhƄ!b&1=u+^^o;Orȏ_y$w}9J@ TiKѧ>姭à֮c&He/T^Ōvl2N5m@FĖ6 kku^=RȲAz*"[.`'H| 8# r_ . D+5om(-|F׼Bv'u@>Ix)Ora}#^>63eA15ۆ>&$&O`gQ_A<~ SN+2 us;|_;,©BLओ2uhvH_4H̙9VLB:YQfHh W=O3^LDOHX/65bxiuXaV q/;-LIK0Ⱥܮ_ZS n̰cKD&]aΐ3+TE+4@ʄ{;eR 畀+ڂCv/dwLxSjg/%He'N~*Q#3"tyrEy ]'mV,~]q\`E/-gIy6uGA47s[a`xTBr>4ߎ{_Z]zWBd_ۃ.<~&քisXXll`L4ۿUO#96#Qmn­qZq%V|㴿lCAN_ͥܙ#DŽ(p>1z`pc]c14lEx,Qlvb -lVf B~&9_armUàƶkTfǻP-&G;Ku<am{zM~/F/|FrU_`Ey140WVE&6KYFV+0ؑgPJD|g\{p"u >gJ]utMSTyyѳh#>b !sa/qМOGaj؍V# iPV1xVZ.5?FYD9CU?7fag)v\㫛-F'[Cg _"t.27@pmL–uD܀z<zfi퍖 K粆80KҗgR:ؙ鞔c,tՀf5j y!3Lo Af##7+y>oe el[O0< fYusbY4-F?%[a\M̍d;?hC}OSd?"^FU5fyx ҋF9-Iͮ<t<:Nϻw )X)L,e0g+9NKVQ 8]9t>|Nxv *POnudC%؏5Z%\]ae2AkDM E>,6]j]jW*d$T 1\@#/2!I@SốRGѿI.`fwey?3"XQt@E6 DŽ$nU d`pWQF8s鉠Rr\Y-~w"pW 7_.wg rkc(ղK2XWUfUzC"^O yA64M±_?'@0Ćxe[65*9c`P 70w1xQD '>y쾢`]|G%Re bbA -yxS?Ao3*|h^g^[ [Y vu:k+KӇvi־9::pJs2SʼSaO0mWn:Ri-2`]nDsdyƑY/(Iᆨֺ"n)cLi ‡^s&k϶+umшHcW,gX҈BC;P@Q ~YнSyw/>yޤ@bk̎شiؗ`8Kz$DB}e-c0dpF۾E~Y͇l,Rk rYa6p 1Y$Z9/W$& F>^Q^YRoK&B\1]%{Io,+2w F|1C#A-4,EpV#M7d  Sz%5u TݹVZ|{T&6wJ,wyfinQ$"xʠ2 7H_[yJ{֗v%t ňFBUsN48 3F}TfUSiuS Jf!+idY]%NN&}2@vN˚NBo7'Z5UTXҢjKY02Wϼ$ǛQY:z1qK(Ƈse~|4`fu&/v'o^Q;bh+seܐ mۜ$ äS~ -FO9VX]~xl$*0d6 CfC e aP̶ ߪYQDH"O Awsvbk k~5 \K&."t/pU&Jo,W}e5Sne>8TF4+ыcNA aԀ5^ϵ-?viqO1οk:8f3C$*tK sމR)rΟ!<W7;I Y%c{ؘ"oJE1"I>) IE)\tA`Qx,_y3>"Qض,8w^)emlyļ]y^SAɌ`DMx i%1#T ȞILTx$+0}J5DͿD_q;PVBJ|\Dj1^v!aTtiSf٢IYBw;.eE's3$vjsCt.ĥ II Z"X辜.Q,hx8Ξ*,? zAਝHU&1D0% M-:ZT;`g* ˻4?jSQ֟tL !Jtu%q-jzVXpj4rR,AA; * j`ȋsϴZUXLO1X\uج E-6W0_J!dL!{ɬydʏi֍k.LfߞArz!nm>eMPdeX.r^{ǰ2t28z:g亻;V'3dZC=.h+̖#ARe/ř_>oA\E;Tȉ6=Q3oXy njE@SW>ttYHBuB/e ;+Hq _J>5R!?3' <JO\ }' OWk}JB1IXK#Ӗz-O+? G21h]$n n&9oh Yg ڵg4Ļ1o>H(η3Nc!V|@t7f腘^d4_"a'r 63ҨA' 6]92)$^ UzCpG,aYnTVܼA-ҺUHrB. gC>D( ȯ&ȝ+llH75yHLþsdCH{gf~(PNS%ؾ%s敼hy /wLKF0H|=ڏeqjCYM<ᖥ϶ ~~X ^+B}8 1K#Bt#( p!p,G0VFT`}NÝ ~/*PHAlm4_oN=Σ@Cj-{9ri: 2;MTM!_$'­nezB-Sؒ0zxݕÚL|$c$/ `t 0K B%R[05CZhkqf^` ̙/C}%Q\' APBGԴq]˫לs;(݈*Ci%̑<5"*LLw pF'c VG/{x99YC_ JD9_yna.gthR ;Q?"00`..Zۇ3s:(?[Ab9Ŷ%b&Ts]aj+D𾪇ht.cU" &RDM 碄s1f0t AR[͵2?$^]$c|g9hbH#"g[QFNㆆ~Vw~$)n1 7boD{\"B* ;MĻGDRqpnɗ>:p iݫY& /S?D鼪w}Q:` I%""sFgA A`!=u qUYTZPy], I3\U-ҥ.kA=.E[ҹY"Sh8Yu'69΋GmƲdVh[Vno9'WqZ!# T[$3O37-W8a5(3eW~}-9nK:@ԘTe'7w%! !@Œ &vFONOޔ+֧گw>bg;@irTZϾ|:$XhM-q$ ^gE a@#2 U3}/m+gѪ;[U3>|As[45'^1fcR&&r_-AeRzU^r⋘WPo֊L{[ 1cMp"ݡQ p eIJ%jYՓE"%΁WU1b`kMi\Ub' z.Lbht:q[òuo>aρyZ \@Mh\dAvY+h=;iͤrʪs[8h΍L} F)Å < ios9X'~:[A#?jWRF-z'*qoe v2.+PhY1 Q !Bf&k҃HtU]qSH 'j}q>n[\@On?JM|V+prxAUg3JgFZ@ߣ뚁U^uI}(Mvmv*9*`d}(ve\QȢx|S=8v^;`$sun$=j' !r?<'A [(aj}Cn1[:r/wSq']L\"n$\2]V:9X`CTQY`(dm#\VW!qG ]pY!а73. */7ʭMLXǖAǎe TTwXuƿYxA:?$^Z@bx=4Vu@\wgTZ2U<(=U0`Ia!U#e7#wO7 cu.|mԙNMT x Skq'E.vyӃ>Ͻ-9"t_!0cO=iGy5d 1t>a鉕%h)AN\wS]KD Pؘ!²3N/9 swRxM weg4<ÎC=u0[t ΐeԡBQ/a).coay2 3E @xPV?@#/+ 'N(+H6/-;O^m%1edkJ=L'`іA:- 8lfsGиfWw f Dُ[_ƌmh1ExH#HH>: q)yп_:.cC*btڒ." Lnģ_]q]VGf Ǘ1C5I.^[4hoAP]RaSW V96vFXT|_E1IzL=y #Y75&9t/3K\=ƞw$22723C1;ri Q] .Jbsv%.}M. ICZQqI7}TbNjӥSBfʜ/cǦs.\M}G|Dx>(}dde|q4y'82wfRk'+ =$,6 .h FM=@2Ǵج7EfV~%.`j1QW!s-?i{^TF vJ 8a,nK r߉]DƮNɝ:;{&&w:O5W4mq1wln5m~wjk;ϺaMϒw$o ϕ&0 utcUT`DtLG[{_6<UIL1{1X7fs Y$,̕Nt?gY7Xܺ<{5.;dLw>XܷJ0}GDž&4`RQH, GOG\ۖ-j/Ytqw4y₝x}("/KC-}4B"ny-F]=cҎ.fᦲߔ&`XOFO VFx \ xX~Py  \~f IdqO חdDN}>8b>ZqCTsf0H|)GPFK ؗ=q8g1 ceJj=/6`HIg0OlB {v:%4b(l<ZX歝FrufO{8 F5k<\bCo4&]V_@UZ9=͖]QUh<msFg*J+eA98[J;:VXt{I:( ץ!>F x|&qʠ{c( uN.{3!j`Rm8yxEk .SGmMJG g== ɼ~ۤQdo_$qw fJXABogyƭ5j@4% щ c/l$Q $F x"QV odžǁ૛}”WAÇBC:}@y8 o;n@0E Fz z+hq/mUa;x̑a&f D%=tQ&CoL3wojpb[ϧ*_8OCk-90}g.ꦙ J'U E:ZW9~F$8e7k"puD<4ױo&_; ,](eAz9:ٙ6w::q΄z^: _ǁ&9}A^|>BA[=]锸;أji_$GfP%,)ѺGR$+TfH%sYv=1RYj^ǎ1hmT*h Sc͆h ҩrURi \ NQuviɻ_vn0ΫV^dTBc6dвCEЧȹa.JtW_ Y׏,G+<o95,7HDjrA>O$6R_G^ȼ lgՂ֋.mң =Z/:wg܉1QZQ^'}3|k+b՛^Z!ܸw›6HZK{7j3p)]`уOTR6Ex>C;#nc:̃i/噭܆c=c_eFr"Jde vLӪ?pVe%3k]e ?(߂s78ԱQvG27w2DRd ~t|ûuUV_Z/QO~,+4/[i㰄x,6!V? K܁J@>BWO),iLb^-Ѱ$A2s뀐{_8k4ogञC) iBHP5m+k=&0cr4*WbZD(}W)K{?]۰+  .ʍzkŔ@uJaQ"򱮖2eK5\yFI?uhD2V![xuw1"j &o[ܣ:Ơ*||kHb'CN|T@/|Aj"`sM3Lpe%؇e* {,< -)=<\$1)I%0RVҳN6mVvb"x2=b%G0=/l6uZp(9Q>eS$ȶ2?\ mGX~-;zD#ill\/5`k@bi(b2YZ֪]=}ш mDk K(Jg~Hj;aԋ6*ר\VSM\[yClhχ_vPVʠ$ i_cP+D$=&&A0YӚ X[ qY:÷L:!*y `W7'tj~^٣ևVw| ȉU3'T7I%YwB4lt1v |cGE>aa@FCqKat˼:5d(ܻ)1cwNFi:Q>AdvHr6-1*aCq &N~qZfO@9|歪ZՁ)֊{giHOW9.е" :UU7tQY ;H&S^dҰ8rt>^9u;ieBߚ +^58}vyS`|ų}h̕~`O1P)\(yGD(7kK(^]sgz7R/e._QWyQ9HأtiL)xo\'GO&J{G ^ R] j~nВjo83~y&A>WCi7˾Y]ńtzRҤM3=mΰT@jĹx_B܋1d_0uc@gL=E'؈ @n,J\?aH,f+,,!Gehz2I?0u4 aI-X\'!uK028QgN ƯޖA4{ xod&COXl~rB9}$\݁!%kghWd,F15S쇢̭vL]fb9s4e4 M\Ce)xI(xwEX95yUFlSݙ\ تY#n#pd$<L3+Y*TuK{xё>%IqjUEf&:Gj2+֭,Mk?Y@o:WlHCI'$1ȱ] ׅSB ,5 EΦblψ=(E 76JG$-FHEqa16n|߸5Dc.rjJ}U_'7ji<*_vU%"qu>qbbA3E*V8ZUm6 ,H/VN7j;[ۡ< ܆;0<0Ua8ɍZ"G}Nӈ/-* B_U홨!;(C9R5׭Ć0g pDYaHGx;h p[7D Wt *ˌO6pc@Q8ʝ$4s+QU]5:ؼ #8o\_28Yڸjs:Bw^wѾH\v&& {Vq#7ӛD#^Ab \QvuhKa]4nHIB5h]FanU?kcߓNgFv+ oDP};AHiϩl{YqGdtN\8fe8N? ’,Cn` @(:[Jst 5$~b,'oEdc)b tՙS繖W>j2*[!A'] t<B%: tl^FG^V`9V4 KBPTEO[)c;1쁩Ҹ2J `a4SԻ_pylb^B:p,4dkwqgwi`-`62ʺ%kò&?ՔyJ!OVl~X*] >Q4z.~d&[ϒ5gמ,ތk1,ܫĹr)z2m zs|pl~] N M ƽ-rq RJ%#x221Lt/tJ;. whРㆦ,͇JңΌQ& `a=|4fs# 3o_@S"͏"<+@ ˟S;>ab ({Ttˉd| x # OE}E.K0d5[[k/4-ef%wwo|3#*JN%[UYh{eFC <Ҍ'NY!m3*jxw媿wwOہ34^\Zx Tr)(5D;G W1= B~: bW 4fB22Q+OyZNT*#p\[EA)WENU,}_?22Tu5|J8M5{o8C~'58NIH/kGZ@#9ED'%;U ;)QbOht*As080zk'b c-#diѦh eN(% 5#V)2~"T~ 1d<`悰C|wvn>+"~[e&dh$f DL.Wy6Q7hYX V@HM'~ :$wHFԍПqѠ{8R6t/k`@WuKg^)ՃTF 4dw< l4oT7j-IFF "b&K[$%N6р1a/ %`cx,e齆f( yIQw*T[3 >Fxɦy^pB_w%И!KC޹֛*PNU2*t{Dc+ET;D=&ڟx^O먪EŶA $9ñ]:k"4 gOOg>k _}ȴs)y=`738.InRwW“hϻ85f̈D#x ֟JSe>M[/<{p,=|/{ọ1U[ ,d"O"*=,nuԼ3 7ba%x|Iw ([LM XKcEQ)~ N]Ʋ媱V @,`ڭجl=JLr1Fmc^*3ְ[} ;)E\8J?,Rھf ΏSwERhO%:#*_R?3JA[~κhښsj9[bRi;Ǐԧ\`1§JvGEXM|`O03⋏H4D>CBH,4R/y8^W浇q>^θb ,__iŰ`7Uqε9G]\9AحeR 0P1{ zH(Ơ:ֈb@< )ʶYŢoa5}伮vb:B/9eD/$AX[Gvh/qYgSN%}CUF/'cLx`sV M0Y& h2X= }'(tӒS&ۮYF3;-{#w^J;:Jw!j6z6(G+Al,:憡V2d[#P_623>)tƓ1l_=<1DF >ڞt:(r%kJڠ3 *tGN"G]ͱkae0+]cQIZ|3CQa8zeG濈^6hMzVRL|:Y1Cn}uTg/ `6oςM >Ӡ/d_q.&·0u`SF99Sj~8nhqρ8"Ӧ=|ZZ]X/$FCg,[?;qth{$m!q餥Te RyMնA[!ud^iJ7REyi cRB{U4?4[Us⑈dPȬ* R},;k3mpvãk?lDJ #-a8aNFqJAĚFql<xNhV@ v M;ZG3.Gq_qơ7a@_,:W\3Gi%-8Emakno4/rQMiqߣh=V6̋e^gE!~IkJ'E$ u-)۹o.m'_]Fa&iJCACa^~9T1l% )9.*J#G?ws&FwD)B@sYa VnO ZXHe`nE+ b{~wVuY#Ve<ayekY/:}FASպ/~myvvќKś4O>1_b0C,W{MmHFD`5?xh/ V ;Uś s{iY*"D:>Q퟈OW9WG) r1(+喭M0[&NxŃF!np~ JPm^aߎ_f5ELvy~+Ӂ7NY!o?H7f r }-Om[|>86&~wٿ)?h;-&Z / l_C3md<~S7 rwq,&j[™=uFϗ|\z)ێWwG1Φk̏|b̒]h80FW&2=hpۤ>A`tO5%´B"]=REj:s&22PظN?`6./]T[hōf x[D?po; F6g̔k_z~t@(W\r}sO T,ᴀ`dR k:!q{p@ӏ{>'n;|mN^(kKN+$ ȂrN [I6IY 9c7cA:1^N"OM9B)㺋UL |N{Bä$"=j 7SE,ݯ6^N:P|i=?zX?ɡh0SSp#'Ǽ'qQ9m׹k=_ Z,'oM֢RA7 p?t.g8&C*!fsDeB  G?^=A,U\FQohjaF3E[p_;$W]֡=v? !y~ D*%桃F xCm`|?lV^VPق~qDS ?~.d_'o4F{BK@xȺfц/?!| i&:$=>dDh]^.$IsH3 'HX!1 *IOd ٙ! ͨ-+z~c x4Oْh jwρs#K|뮐pc-!qȡ5н;}{!L%5|% s2F dХ ߞ JK3ޝ=N_\=tE^J`@FU3(3>Eǚ.j?)҆j6b #DN`6Jzy s5z4Ofل(ݸiY/[5)WKPf +d= ug.Ii@n.&26fXd|yU8yMM;Nz|(nDt}t S.jWQni/^?BA}\ zkqŬY}T7LC*2N%ձ4"O1 ˁڳ|RB@RWr|4,{.wn,z!ge/Hpoh&Ub˗ RDv'(CV7 ~k'b"baNjPT}{E5$'`:;Vn~lFJ[z.(: 0g :ʯxd4@@lőA_vknhE?+؏Y gi͵]€;kaM F+u۸3_ u?*{Yŵ2@K26HՀ~%l7z9īGdC@;h .3pJ9ߡ)֧W MJfDg +b$y"aXI,X yTj$3|5;'#03rQ,PDg|0:v*s3$L FP5twn h $]n[b?'L3?lH3y޽vM A~G] uFUovuy'Pz̥xɊ7 it-#cg:9ӳ~RM*@^r5 N"rɤ-#2M;7)/:CmpR6,CEB r'7i7fXP͏`, ktxIKt))ٷ{c `@cG`g#n}˳uvsr4vx!n5߀c*gUYqC x݈6up͙Vx<WեsO eC1շT8Z,́>~cSR=I xrvެ([ Hr*8*g *LmSfa4MQE`=ZA`ny p OځIE j" ͥ| VYEժ׏:>Ixj+n}d[-l_"jo?ǿIxsƨ `-Ux2 ei|`] &tP@v#?Ǹz- ;0_he,|gZۣ@ݨ>2Q9bP9h^q/U7)rUxX*K x"Ҍika;lo$Ute=VMMuUrU cÜUGW`7'\yWt؜RjW~Ef>H)r=@ Yw󵄂uBH(JkE [v[XB!Kk-co {A2XkQ2Ea;Dg buJoC}GiDt'y[2}!9FYëYZf(AɊ[׊oo`waS¾i SM50ӗM]-y@.MI,9H͎b袱C;d6E'Q&S&d̝\խ|UJ~T ӟ@Yܸ-džu{AZ5`olsx:bvs|J1 \?B!oʎbq\ik_lJs$mRgZE-3{93n )|&Y1m^7&Ic_fQ)o߰.,3:t~v\qxޠl88M{U*y6FwdԾm8.dYrpo ]l17M/l:U!)@QJOPH{ hҧ2qJ$"סwkZ߈(gd7Au{ѪN!rp̞'t ՚E nū;P,ڠ=^aԜ((hZ-ˈbm}nV^wd|\@ƭC5a:!ґ*v۔R>aŒ.{fʬCnw12[ypKIW#!aP``> ` 1-[a2[kٞO wilSL_~SѬ7 _DYJ2}?w>f X+O!Mz(t蛳V冑P`KPKm<ٟ)!uwFVQaQٳJp4iT8C̪#m^@gk?L#Cu+r'Uq0IS DBhaɬѺI_-d W.`o<^Ը5[m \wt|= ьߵ*f䖷ű"u+׋k ߓtk_G`e(R0ZVX:@5cʫ+1nS%}WPp^*Jʍ=E'GvÙByOj\jUU҆dBӔP+1Yl?_g$p9oa)zC1Yxغ$ Uǹ{ c6m?9٭%ڤkVSzz|~G2O{ ڏ<<0BSNi| JOKTmpH\XJ?Ĺ.TN:A>S?)Xrvuw=&t1-=J\ :Bc1&89nLnHM'Uudo;OT6kc*EzEC윏.ONsU+Yk%89w$ \L@%&;)\i*/m3I^%#  qt[6'G , 0BC*j!.gwQ(f8 L(,djpmTNswJzmn‰'~Z.[ʀ3_ӀGRb y 0]K`;*6&~eFpC'A(Fa7ͳ:c4&NQ9opM(igVvjO,CG@9(NS2VᆩÍjhN:T_-l7;? 3f i:zb RX;=Ȓpx2OLDw=._ǯ=I򎏳u)fi㭶r .!:3:])ޮw 벴IY h)+0D]=jЋ`ILD(ԧi%DZ6gU|#1|ȋ("}F#%P4_>DLOQ$l u7|6M{S~4Tl=%owck\hا@?+խ1 Fvly{C1ksZa[Jy0ri?"'oB/9/cwqAqxHR$ 07N& # ѥH9XyNԬv:!:+ϩVKn ̊Q<&s螩si! [êM`ѻ^.*Oף%vij\orap TfH#rh}yG.[1s!YNY;(Im衝v9 Zu4pcaJHoyj3OG~+oo8 eU ̙4EE^΃;%SlF2yd96/Q樅TM2=Zxցegn /f8]e~1UAa۰LH yOgI3M-B'QH@=|قM{>%jlzo9I1_n[\#vnZqBܟjpQ=!U+ҒS)VZ‡Ǚj|W4#&Is dQ jX8ê {nm=ގn̛!e%|) RÍ}Q8=jk)r7O2H[Ƃ.a}ژ -2M6g -}%{<2dxs_nR* )+66,ߠsh1-ʍA0L\WMF?G DhlB[ۆ#b(KiJQH@8Q44A6J%T-+ B(?dqnL5PVij+C[h|1 I}]S|kP4)*F]grF5Ԍ  "3}9* uTO-zêzt+aT`Mhz˄~1iqU329Hٱ-|Q2,j0W;m~;4nZ3)$^TygNdMG-uCM-5{'˒sV1{ }I}:s2\WBsAx?XkpKNډ,+BLxOn{兠R܅ r1:v.-o($`'$0v!~q7 Ʃ"}N<*26E2?D8x$h`aыM._xhX:*}ߨ,[*4 #2N{}'3(&OӴi痗.DRSM!~+ݞ*tH:J'XTZz|ƺj{ Jj[cabxn2-A lUrS~l˪ őΩ^o̅,&)7hh& ͽ2T8v]̔mD1 oF"bެ~NS")ǞfrQr ƁM5 #{Y!K n3_Cx36nw "9ngO,`gK3`@c6U2+@qkyu}d6+j6>S: 6N60=O  ľ3J8げJ`>z أ$ʾVO|=GRӣ~)r 9IQAe?E]v'RDʨtD9e= |O *ҷD\iZ~ pKo51t*%QhRC}jH}* ^t(C:iڮjhӃ\ȑ|!G0nu2W+0D"8x0m!3x%A4|3E5R:ȸ[jM/)Q;ڢ4xq KYĭYr2߇]=? TBdbTxj(̮~㏉i!Z8ɛ)Q=UPI"K7Mvf4npKH5j^W N;92V(7"%0 Vϡ=krB˔J8W+Ə񂮧ϩ I}8Fv]|"mrX|,jg)J*NeR>SrYƒ*P:.j_?f%D -Rq_oAR4!!~ Ux[ք,RXaL:y<脍Ixh{veˀ` =g6>iMS\$f34[“hG驔Dnlym!7i9`b4\M[c<*av 8pO_{:k~_(? BTtKsKb`5ޜ*2bOq&7LC_= 2*n=NP#']{IX`p-_SOYҪV56g2)bwcGUA m}LUFM_9?a7 G~n3߃2]b.#P8^ތ/I@p D LO~K"2gH&-A)5]yE"!z}3X9ձ'@Ujs3!e>6EffY[&DSךVp6zb`=2a`C%;>Z#y*H=&6AL3~pdgW%C|Ⱥ KU*qy$i,؝fΩ (f>5RYnI_IԱ>tdMY} Fz ,,6D]W6AS") /L]AӶ]W5t%L|h&/ ,:KǾ=ԽªPN>@e"0_Cz=iW ;SVeG1 Mm Kcݖ1~G?%a7=ӷS6P-G~64N~`yF1,K R=w7t4.'tehS6}i%42 =);M(lw]0_aPJ W.ئXވ/hoHL慝fy"N ݶ {TFˠ&J=B x#l~nnP_1hV})YuNgڑHN< <ϸ"ICZۜ%D *[ yuq3.q@&8-&)n䱊 oh(mcB~S 7٫ۏjpSEX 'WWp}FlYZv#*ɱÓ;ƔӤN"/u%ĎVޡ%"A:CI=-@#s]fzq͕1ڗ^{+3pJ2Tv.{qY;^i`:L+ G\41sΏ6bШ+մDCbK\9f*؇@]֧IKW0͈cy,<|*:0Z?I{h~OߨT?}8MQ[_pzZ} !c/F-QFN7=G]1o6a0\i:a=<3_NfS$o 7a-N+HˀpT?A?8%W[nc@ Sb/4j9{{6=}R~:(-b-WDb9w^4. xDDHib#B@t Ke 8"jqFy* P<ߝ]钿|Z,rxcm܄$n,S|9YNfkTyy9+Q wEFxÓ&':vSfG)xJ\wnAi?U2nt_h5?.r6R%Qbf'$&"/ k,&9Gwb!VP'hVfe4nتs f&ZCm ^1%2ԡ~ w@b d:LܰPF@< ":b6eБ_(2;OW'l WVy!Hx ^ahߣLU1r piM:XGXA+wւ9'A:Q0o "%~&Pо} bZR(mHj73}F =X7$=TKꩭ|!w4 25ۥ dZQ!R.Պ(I^qŸ]C`R1گT,MXoݪjX ,&)"Q-2 Hcgú !:.Ī(gF.<8&o3'  J8쀛RDc*1C䦴%73-h<ϳg5}kYmз;xވV#BGWݫ/%_îtiCcleeI޶h]8)w ]'!t^ibR$ɮxN韹KHơu>L|9.11$kN>ƌdd甯HgԯR8ZXlot{0B:=\t|`kM7u'6u?.!v97I!^c`Ox |[9"Ecȧ6JzNc:riTݶG-Ȟq}ʕ3rL8fU$gzKwnlB9J`:U"𶸂)$>!ha8J\+fk(h,_| ±OU]ٮ=޾d΋La=Z!4";I|nj%`'rٌf[Y;!}B ӌ^kbnz*P#,쭦Y"y^?xNƣp>h 7&45K[6HQ7!Nk*-1puֶ[}]1ݾ%L`lk9&4\Zߑn7O}3gIý)3BuxԌa ]¸םn3T2KA=qb"kY >GPύ:R?F4*AIY$* 3[a$kG%eo5q<~ Q3y¦5Z4:߽oi#'F,gyU-v`tp lH&4&VW{1e-5k71*9!"CW/YO&<2O? uA2R苍JL=uk]-)Ao:Ҭ%wn)gM#$G)!|ԃs[Yl ,fH缼CeR H]O7dPLOsF!kE0x[0 1*s+SEH-+RT\nnNVcaPl؛7 m)z*^S *3C^UW|0-têZ }4MkrH1!lŻQ <~!9&_XLXB`GF`M ,8*0 fݫT QXxb]o38+^T79ɢݯhh{W( afx7-&0_PXΪɿe%҉ё,_n;QqcGt\RhHy,j%׺KwM5=V׆گe'Eveb@$.\bXYsrnBp=fߊMI驞-&n~|nռEBEx*+v̮>jd~L*5[lގʣ >OiY!K0POn0jXĥH gxqGi:pƥcϝRF`zGԎ) Fty*8Fa^Gv< $'G ]%Z_*b_) PPDr:H% ƪ)o$>:bAdVCn#Fpp)z8 ]R} ~]H`#UU-twbx/ \;tS_Lu\fƦӢFu(p `0_m"֧_jMwk:_8/@ JUW5yY1l^6H{Y2ں,߿na<2Oi LA ˙a͵/`kz/I4bXѠm&JxמMX_@zIМDKf<.uWH-dDF6 TpKKogV%2 Cᾢ< vB]lRq, AE;l$ f9OLnR;VI?W]mu:YVhPWi-4Ugz[Wv51ֵH|.=k`Dv[~ԗ+1K5w Ͷ>PSsǕͩE(28 eWH7ӣ0x6 HEusޙfCs'qx@Bl*eZE0htqlv‹ʘ 3fYMQ)7FdZlJ&*`Q-u157Y5}q$e0؊mk_|E٩xԅ 8ow(oOfCA ȭ¡`Oɕb{1^g{gfpLyp':b4I K=;&?U3f|d/4Ǘ#QoK 9f)~H )c& ,m԰. ˓O"a22Ӎ-ػ dtyaoˋhlhڱޒu*4\ʖt12.h݁cNL\;$!Cr;O,C⹛Ip뻠ŰgFT$zXC &)i頑w]hb; v=ZxRE\K{邌8w,1x }N1>P!z k&M2 ~lӕJ?<"I%Nb(BhS!4Xr?8TipT1d(2P7& ÿ1zϳ5!AI' kⵎ~o鏕 Z>J{x6_0!c6аkF?<+瓵*e'=N|cQ2]eY3e#G:SSѡAxg4͞C%jQD!.?gyaӺؾ@x :|ҴZ`rSn;/Az1")xe>#%"템5q>~VH82u0Mh\pA.Me7h6:$ _dPS0/ MAP# F͉FݷΏo0e{.^`ɷ#AjjL(?{=ۿ5_vMqIs 'CQA߭7BfDXS6tMʎ&]bո < g vMF>':ȴ=Av[FJ#Y߶ng1-KKW[xoPaCF[ϋ,sҽyNv_g!y ݚgpe0QЩfb(| Q/>NP .tK 4+ɹ@n&W*].a'W/,M[vX'փw )%{h$,N7r"څ X[. ?ܷMS:z[{33T2&x/6or5x[vgVUW9GMއ&lOǷU|a0W dcG/㱌qMg5: kc4*< f &-)fDat=  aO(&mqTeΉ5^GqTIvP~P9tHK=h"AVE{_µ;qM"eE*,CuvVF[~!^~e ; \)" ,[AM;F]7  rZ1@;|zex#˗8wK |3mcN f~29><* S$G»JwędT!F޳BJv1j` Gɧ.(72!Rfz[Z+2od/vE7_sa:bϸpAE<ҳZ_ɤ+u-ӿg'^ -&&7IC[pRgI齶O4":$"ITguTךKE9&NeL َX;r2~ARMrPC~9iš;{E8qϩG,yH%3MU8APL&D_ū'^))BX։,Uzs;](8$ #XUY[9Q:֍!"s*xc3'=.<h'ZQA=}-lӶ0{ ȟhM`1|=W$QyU'@CMwi_鼾ϗj}h_|초a1TІX&dvc[T˟A嶓`7箩~y48%Kjf3lPIصxњآ&~UqJd ['k. *+1O-a,.ꍘ*oLnrb,_P~C~pL07Eӟӂ*ExoƮr(9 l 9s5ρEYS%M+s'(ۋ-\u_bőم _eԙ\W͠07'~bŞFLMTř\X0aCm(+ 9"l8VP綌&_iÿ Z㠡cw~]󟁌*&23-9Wr֌h[ &󕷿( ƕܦ눡xC!F-P"F迺+!TNr7RZԮYU~9` De^  V+{R:=51q&V=f@! =QQJi4'W58-eBjء(Q~U3 @9|oٺK[RUBOvwXQn,a+`/ FkdFx!E,@@H,9dk=xTj5AM3ŇQbU&}xUսbp4LՌ[G-NG`AĹ_g&81^Z؝ZAdM@P$/[Uc#XY2w@Tkz)4*c@+]&B.):}? ZM/V {c{i>UgN/S? ̫&[~ėe’z:J]k1C>?}L|+2aA|7ܡt :uِTf:ǝZ/[$Sr't~۱Zp˓˖Z+H^V(?1tΚeOAQn#X۾L)(UJsAwyHKG^.$Lq]J1eN?X<4f@@_!k/_AI+.i'Lu,7y ˤ8bl{"H&%WsB2LN9|K^Q&@qs2UT4(B^UE|]#Eia`q?{(Xo tZ!y>w\PiqYϤH\nuYwֱ>SD{2WIMKOzɣS*'_q+nb 'PQKF6eahxMb!򆄈)bՠ<&b牌&ƪA{[-| :u#_i@+QkJB4\t 5V-a)ni Q1:' 79 ;Wv` VbiL>B'm3жgPbg; @)x_o9P$w;|PN0T;5&^XUGfԳH-Sp`7m%5I~q-Ro3,=?Q6ۘ§z_s<tӊ6"\ap(6/ %धI|^e⻱kb|$"D/:yiYUSaL"FrBH7~*hR sJl:sT|4I^NI!W#uc BneSn@}¯4T.䷄'E E|NMYa%svk%z:bN~m3u}~Cmz:%wG>9;ǀ}3ƅnQ@gw_&#٠,5XO`ZCZ@m| 8n r?b;@7J@yr#Q8[R%m dHьMϦ  4WbE`/nd;Fv&Z8-q|C*S03Ñ*:$ȞZ.L^W )7) W$B }ne7ɑ- YBv(8o1!KIS7=;OV43x#'Ay7BkG$Xf E/)".k̐`lO @86܌% fr c]!}mo_=A6iy W+`#uܤM˨Rגa}ʆ>D e Ѡt yBzJ Tt%1EP8ic{[)-۞gl eV~RMky/Qg76`ve:t}0ШȈYo,EJJnt!c0%zDLz}14؊MF80_;8^"UW c1O&wXVsA q߿{IոrK|_HDO6TɌjG:Z$Q 9ʢfs}Xtw)gwjN:i@<gȎ_x^@JV;U9r]<b]ZGq_VVڇLod|U(cRe e 2f(h{r#9اzȕz\Kz@[uj!iշKëWDC9[i(L }<.q㟒4},ȷ+Pn07ki5~.@$ԇC9l83vf&HjJ7p|;@ӆՎ\'"Gnx ]vlHZx-0ck@^̊nd^j${)QL{Jyks,*w^R;}\h\F=riF>a]2M=WL#+W*qr<5Y.٣;l-"b$gem[Rb OξDUs@+5[;~-\3uMh%2O!@p*Dsx1?sD-j^I2hO󐵿 MPBi] FF|ѡ0``~פ)ʕqfЅknp#)t{_5r(pǣf{u S:҆hMT(9;-)k$VR5NƔEa0RFպgrUYblߑV6.i>?J4WFzăg ޠ@;m3%.Yΐ.h,Dp3P.4LmOM3,g`褥ϼ JðD^YϡGtוHrgK DߝŖ{Rs^O2i=R c+@ri:_ҌD0/mIt* ^Dr]g~IJj 6ƼKU/`NGPt26軉,2Ef&GԺ ` x3P-y$y"F-fv,3>]&Z3ޙqg( PosNl("4q `´ɨVW T3 (iK(ѐKaè* BmZrfͪ-I'/$qx蹿DF pwC\lA3f$nzBdLeH䄂2~,j2w7uٻEiMaDڤwۃTr2O IDQY`c{ܴt,5jo)9 MQPr ^׊ bUM)2.m6YHzDꮾ>f3vb!!uG+;.el&[TU9B \R^[8aPǏ-ΆR{L3k1;эG(D{dHІ_SĠ+=brjiB*soיzs:kZ?UD7G6E 5xHlca3^ `iX95Huà1ٱEeۦgpg9զPQ47`JNx&BYaNvz>e^05tN1nߺA}R~ <iV\b҆F2U-xM %e?\Ui>|>̌ǍUwaU&.O^[=8}aSB}+ 8e'oوu`?Q˗AL&dd>K?'ߨ̠!RX w_`r Ð] BQ#$+(zu Tl1Du@:aQd371ٕ0瘪9:#l\mgT癸\C}P NNd/W#V^PMݟWeScJ0a%R1^!NI R`DqI H!4d̽3s1J6m-v:4{IWƐBnztVM> H=Mx;B`?#dʣH~hV&G[ڲkZD[±--F)E-Ԣ=V#{滒SV}ׅ- `gF-|(d16n\P.LnlWx-L35H ŖB"q2?nRq %*"S586>fcd$Qk,Hr~ʄb@\&#YP]Mi(aiT(V \OQCsMV"h #)ҌU)6*qgF^$6 a4M\wF?Pwv0]Ӹx&)"w~6 aT{Jo #ٮ! 5Mj^TS[ga?G39SX}`? sxYC)Нd8KLX5(R6/n QEa~U1-9RR-30|ᾮ"м`-J#ߍQ%ugvG\<Ę3I[Ɛ̞1kG[j2 F>{ $dU/e:7)I jV.V(>ohˮz4D _!|'p>^ l˲ǘr^ IFv8&0AO shVc{v[#SAu&)Ph3̫-~5yO/̸Di|iN Y4Dq"?nCDOQ'j򒊣'֡A䔽}7X{ubP8v뇒^DklB^]D+9v 1*x|CA|6: '.hy*8}?e})}SBmW\d  93w^,RD0*zhAkJ4Bku  -Ք#6Fҵ&gr/(zPyo%_J>z !׫y,B#< 5RUaV\R N|5[y i;Lغ 64]{&j粳)CW?PdVBFޥjv"_C#н C\n)#t:vӬ"nBExCYil綦[C sJ*ùǴvɓͳ%w u^a٠"qx#<ҭ> `+Үm7"Eu@1ގFu ]wf<必GoE|E4/x,x]H<-N7ڐ"/(ORÝycpiׯLKhmpˋjΖCLoFtEi$ E!8-2 }k= =ZF -ƍ,.Jsίg4iZR$j/ZcƝ){JSGc 4Ow U;)6N2yJf{^ǩYe u 8@߱zIK7R1Zoq5xJ:\NJʮ'bi|mZ*!ǀi<(7cJǭ?%ɟf\|2szZэs)T,?ȷՇ<5blKP!}Orۣ(tY|xNf]I>_@<1FPeQWJFsEpjl Qk˝IxKt0!K0K:mbN?y;]oUă T &1r9~8UN"nTC% q,řw@a>2?MR4%8n(8I'THρ&V]Ъ9YWߴCL>n Sz8 tp>hb=_d2<·%]fxqt]}Ok+;֗Eq5TԊn^`}Xm"sCisFQ qOF#,nJ~jls"HRU#[j\Cl<^yW$ Wrh<L8ǖTdd{qNZ_ &=V 9 C H~6< k^zv|bA7 $ίVuhh`'܍ Nai7LZݓ3:vGW.LBCӁr ·ݧL A`5>Ns1j8/diܴ,PI K<#Ozp%G_ɮDH%ZBK ʓЩPvd˥hr~G[ W-TGϬ!SĔfvL<݉\ ^wO@SsuX{fc*'DxgПՃ!1`؁99d k* yLXU|h?{eOY瑦YXnڥ' X=ޔʍu{5aC 9]H]HjI# ^ś9B!l}՜"'d7pXA|;?Pl¡]1CGNQ6x$.mImvtcV 1[IIuE+˘_OaӂL+E#A8'~!st~=zXTVٍ($[p#x<oSiN071yN( /;;{֯8/(w)PXKz0n%n "DMV V_ElL<1C?E\.B}\)^}j81izהrtufu!U_Ccny(>%4;$ꩲ9ǧѷ#-ݣċ:伵w.BYwRKw71T蚠C] 5hrc(0MRGJ"U>7;պeB>>509~5N6+rs}cafYC&>#LIu+Jiz4ڬR7o  $q7Dڳ,mJ X8^SߚJ֑ˢ\y۱?+ʹS+isZmtAOj0oT`4C^j foj-UO2$lm8%d=W5KAݗܹ#99Z 3̻gkB}>TP3GoSm76J$l^ )s>\ttz\"_(Y(rKe{HkD=I׈tsRWfn9B7Ӄ"ޠ+\rFf׉팫n:CFir8gl= ?3˺:[ Ƈ-V"iP|)-tGK)L2Kg/_Ŷئpי+yڝr4?cAPg3\&m:n;07K}l]DDQݩ싢_/A M9s0hX0zxn]d}}\*?GPkUG`|D#;1pۿ\[Nlr%"=e Nz l<"# SK셽2 ڹ^(j2KEn)JZT*$ڱC0v]~2 KċU>"B垩O]6 r D(P@2#K<" Z>1S9^bu5q`Q?'pNT0ו-V+X/%|)'#=4휟2h A_9E2i|f[NԯT8Vb Z@mIY1,> s13zvv8E`o&p{r3< 48޾8JCcrYr;錦QWjTCrBՐXVp &!aaEn p{J~K4FBl$KpIԔHѐފ~M//ғ닕һ s$r&@ύ3+ Z}\H/ZI1k̈́bpa7,QI΢%emr}ۊ]~exT3\cW5w.c/\ ](8f /+.,,=OYM1SFTih8^T)! [L:EeX`0|L P(5^6U<+~.B:9wh}.W[&܃UDN Lj Ȁ)5>r")oķ*# jK>#YGLד貲M@IyFvg72Zg'݅QċC mBM sӓY ^}@;&o~iV'^K"|*b2o0Y'(lbMj?n ğqwzqAApz[2o`;PG$R\!mj{]ɠ{^F>vzHz[ f39B#ڳ#C08*\73ZPͯθ|1ymNtL09S-sXY@% /l1y6 ܸɔ A^IdV3t->~3ie$d8˙G'BX (c$&!aʲhf D|c[} oc|]o_хh"uŵڿj v`dtCKQ<[+͟|4uA/ptYgM}X!{\zWSpqw@j-&ܯDTw7(KeWHYb|pD; T+&М# TJ\}JhdVHϦMBq֨@D;[ \\sM$N2!ve%1D$֕Bc" G,9z6W̾BE}vV8s[ln CF|jg]v,@5Kh<]V8"v}ۦLyY\SNg>CKsZiφߺ\J8+P^sPI~ZW c"'XƺMMTp!=u qK/g{ o] (l 9b'tgЉ-&U|(kNOhūB0{j/]<MEeR ?#ZLZ-s0nȔ.Կ2cuDx"I~4˅ KS ג"8Ϟt#]\kBp#u(h w't,Cg#m+_JhSE 5yY|W45$ü`ފU)^pfVYt TtlDl:݅ N4ĔЮKњ-#t9ͦOUg\س-g*"/ڲic@UoA1&$Cdg\pۛE~Dg_/?tt8=F]z6>:vңAy1(T5E@|xŪ{/o<ȕZwx|*pwۃފ:}2)![g,:/b¦̒84a7^V?FfUރ.bORn~Une-$I7[.v0R4eaƙ&XU@kw:-_tB;-,|8^;!mʀb*C {yB8$ր4)ةeNG\dK +=Rpҡ!RkW/v^FۏA":8˾733M}B\ά#x)>4Щ&p|ZIE)ck:՟&zehvitT)W 2YeKc?F=(Ɏe %Lj?KSG/!yVzofK @mc'*K)|+/Y=#/F ]Z3o MOg s2[-4a8c"4ʷj|Iy6b+odFYdSQeCYsp#3NOGvyj|{4rfC|9^:EEYɒam~/WKwGJ+$q-#E@eO0nwׂJL]<ԼP?&s!{D_c@{y# -ˆh$!*YO$!Jx8 ~ Lrn;꛸4,r( OLe^i)9K%@W)ES}G׍B6Z0҆el}Xj#Sa z ]^d5\ߘ^Mu:aV"PEבwh IGrNg-mvkuZJ(\xԘOoPvY翛fnGg>(P| < msQX`P{@ߣP2zm:)|8;$| gj_ ʂ24ًC"UuWf3‰B3O'NC}G$ ;yQd3B?ä60!wx%l 3#I8z4rҡs(#{Jt"Z>Qfߑw Vw>Ќ9w?_!Z Nu;E4>C]Fag'm6+Gؖ[~yo8Ju KMkMUOw ~i8LRb^ce`VEE "kM;X0`I\k^J39FA_@#MQ"s 5Kܸ7GZFמPT$DQ'SVh3[eIv+'tHV;B۷kWa^B"Ahv1던t\4)9ldvN>^ )Wr!+ iE<[NXkL*ĂMs }XM\ Y]&BauNdzWܕ\= MGZM;`O ɼh"9((XEtN†Eo]ޙ"¼P61/7:纤F?uF:qyh nVFЪu$/$1)t,wq18y[[Ǜ*JXs_#ϼ]VJ`x5l*1OŔ\3٦Awu0YoHj1'W-@TU 'M9:'< ")sA;9PԞYbB$bfkLl97iX5BXA7ƹoHCol*_߻tw*Dۨz;82 sj9)jj֤y$B*{3<&;_(t=ep1wV|ٛ;`f\@n?pOυPM f_U#|c8uȃ8/opug52$~8j8мTNޖ*}~zi\/Yʐvlkz-h'C걒wAoK}pIRÊMM 3kyb f(Hҫ03~;/p[R(=vs}8[0ږ"C)pd'<VˌNdwrvZv^x{.p^_IvWHېBt }UZi>Z/זk2E#1,)ESr5yU[a;9ʽ;yI"K#!pJū+ֺR76Jy(OϚG aR$<0Y@3M #u˅47At_Fi:˂ *%eC.DsY '厔)1Yp01԰ K5۷! ME&zzMD?j6)Ԍ=߷zy㚇d$uHso^O8A]I F/6#ON0؀=Az2t) $H T.'סl<_Fd?edy*5 1y;~~B"B1h|"fHuk! /%8|*Y8y8Xgͮi<=zb8"ʯ"c\ _ o¤r.# RS'Ud& ?'.٭>Mg5mP{q[*8':jfW-$c)~1){Pfsw >8XI\~wD iȅW\js6@\ &zLj QERRcu͍DSsUv2-p IRU2)ї#IDea OySw* 9VT<ykyƍJ$Jv} &|WY2v:'/scyKS{~TcÛܗq-塒A G VJw9:I ؘ᫩0ͻTs{d|$ uD>Hy${fw 4ԛ~֡\ͱχTIgiYwgDz ZmrWJ&l(EЛ 6#YXt_Z*~=zzug6DE-l ɪRb m.6a/|.4E}Hǿ0$g:%r=i:Axi2[ήZl_tDF$L^9.^*uma!.Kʲ[Ni-=o$?*͓yFbEG3xpl.F.|\`(t@hz3͕5tY \^DqMA.d^,yC.Wt/ @b>+2XIf{௕734zxS\[av @`#L,d݄,VYl۽ rj$[ltt3>d.H̴ ȮP6/]^-ކrX/`E,s֬Y[aarcĻ4Pޮ8Xcr;`qZR3AtVjFFTuF'n tx>ibPbє|Ɖ ]h <"++[fןC Orq n88P j)YOߴ7^K5CYQm7hY5+Vg4=Rnhҿ?w)G4¼`&Kֿ^["p ;Ӄ+[=U:^ sS>^Ima! %(,Nv1즭zLBx p6(I 0~r1FqyCwM~Y40ڏzBb<[4Y+85UK#Kc@n[;)92a|xݽm*u1t([J^h8u 3/ʨ]vrpZ7FgQ)tV\5?Ɗ6@}3=͍t F.a5`%[?4>X#ki{oBCºEz(k pm&b;@WP3*vBS6  evtMoIUiQ q"G=hD߸.xd0Dw_E~ ZʯEl<"-DRLPWƛV^ǎMB%"$?e^-X&vnwZ="kK8NPj4~B@vȿI8VHECNl'=>?%d&,o\&BdMNK(J߃)t7? , 6(?ވ2Q?KlD/z=Mu^Lƒ&& iƂUZ}DZڪ"r2_ɭeU26P+\?^pU+n sv(BR9<y7a_.*ncJe_yE64p2)xǓ˫קn_/}iݴ4JX~K G*ZhqĦ_y2bגͫIb,u=J8ŧMՉdYNEhSqYX6YB6a]yp>=%DAAD@6pOK?j_.NX3)dOg~EՋ0j9 u(WxKZ?a+`~0SuFe{vQ,+`Vd fF=jo5L`#ÝETJvZzo;/3rgzgfz:envq[Y$2.h)fLhxj[!2G˖q&x(ayML" Z+?Gjr^$QT(++C7ZZ63A(IJ}GlMnj'^:,'iݛb;J u=IAhzbԞ,%!jNb~>,U ZMŒCbR C EMpIƖja1~tAm:Ak}}dC?&a6DJab֥C\ێk]Us.M!୶]ě'84d(p~<ڥ8"%^_޷= |C҇J#>JCbUt,amقW4ZAgS>0t2`9`m?(Q<] G P@̟/Ӑfp qSV{D[1Hǒ/L7qU _Z5׺bL U.ut)z[fCFMe# >-XLޔdž&AZ嗺d[@PYK'(#bMd$,7-r9 BFtfbTpBmȽaRb¾Vw]1igϢc>CnK,\*Li~t}!ߑ&ú~*yf]+6w|u!)PGBm vyǂS̐@K Bmb@!Yzu !_z S~K*QECJhor 2a tz^Ft0홑n V]l9[:si$N{Nnm7{o`7VM2~;0 ~!a_pֈCtp#ϺMRHTK_?MMhꪥ 8DMJfil^b u*u1mr9 U6[%fErQ:Zr0ZU>q:;ޏ- wAt#=F=GB|߷ߢҠ _[

si.]s ]>Pj=Jx-8E./.iM&!caWI|XMuO@Mzzm3->]+N{:/?G:ЭuDHK_%֍ZjJ"MTQJN+$zudЖF 'pj N9w_:z"Ku?U8<~'W4̴,፰ Jʹ'NbʇLjZwdWEPc:}JSt:tqH,wwtAXjBS* dϴ`k6]ڔɪmՀTZv[otu@qZ$x{ 7ٍq`nD&v;4jX#7!"c H%>|"CW;Z*OVZPX `/R^Ғϕn<;T@T>Mabjl 3KpiTm~yukrO ?J,@SbӇ UU뗎(l葪*'wgN~J 7<֑  d J~+38|3,4粖y{YQxB1JE^Af0R&HoeBH`Q#o,Ow NKjrsZpF xDv+_bܒќSe&=Xw 2vD1!?"9c|;-AyYHm"3 s%EOO%lP@0 qka=oj~\zRվ" i BCP4ļ"k͋V&svX2ceMC]J#t lÊ?Ƣ^8u?ZC(8XNI!}CJ[Nw9GXEm}g&A9'AY(=>bQNΨR;$C}Ӭ ghyÅ6 tF6s>BpÉI_Y :{!I tjwXLn8T.qsf2=_#Ns? J[ӓwR!1GhGi~`lzxz18s!q B~(P7 BlKDedeyTaKʀ>O  =(=zZ092U+C1F#n̏0k!t0&LU#\'y WpgM,Nb+~ `$X504IϻLs 5#>=9QfFKB8ΤnV%#M 3ۃ~37s_iWv̴^mkvTjbi2mzK!|:ѷzZ@.n"Ѓ-˟z3T3!/kĒeεV#3BF¬Cױ`OY_Id~{!Jn%E-ٱO1ɜ=pA|~_S,eLәZ}nZ}'+| `H' U%Â*)/Zl*]v,[ #q$k8^, 6H GT@YCOI۔IJ7D3-sLI[ qN4157Q !6a%ńEP9gݒ(*iWQv"1JQ,a|,LVDA'jR2hYX9EV湇S3(*Ն63hZaWʧ}7Y}OzP0jM\|G/L]'^GĩUڼmٵ+DWQĤ.E~KP,fxV.@4j066Mk?~G9pXg7C%"|ɤ0Q;ܘnJƼӁm>j㵹6 C0G/fҔ71sՁtBʝ59k)/2 栔fXoIWqb/|'ذF[ T}fKWZe퉺*^7KO^Ew׮Q4Ez%8! iwB8b^M-xx/BFKV'u>qn3,EZTe+Bݬ_f˜*LqTT*Z)`dq+6*AQwB\ $- bE8Di$&aR>D4-qX@)ھhlJbV` ~YnE(3AD= +J^\^RzT1nYm ؕgq:YE~⯆ #ڴhSZ Ib$5Ƌ |DrD#2n&!0~7Z0v *7` ކ/ֆgzw-mͯZ*`c7-Y(*XECV DW`oXSag]N=y%y$__eC2፞3&.ɜWv# 2]`!jY8,1H$ǎ0J9u`#\u\E6"S^$y3ucЄ vɱ4)X_/D4L~P`u! +I=&k;D10R#1_DbҠӏ ytF:Li '1ٮJ[zxfpƭ 'FDx  5y~q{M2s|1^{m9 okJv@k?.c!u﫩JEo?{n)Jmi*׿CF X{l C7Q ~3_|rЀҙ:Ucol,hWCz ƗM]ޗ뷱3z#_m\wu: kxA7/(R]To#&t39%Z+Y>ڷ 4|az'R%,T&q P{fRB`.zbo-A"tDlb[*t864|!2 iEҚX sNuJ٤mok@VHdٳ#2qu?E܇NUP_ %&qol&~$m|ԩK}z>iï)@T n)JIxOW*aKVZm9 |D\&~D7!L(mvB}V؍uPrٸdӨ|'ѼXEvc+7˺G~$2)Dbu]ZV|pB)5} X\Uˀ}p d&7pfoL9cZ = i}E3deNRߴl~֢8ɕ+N?vqV^^"Qyk]ެmQ`D U.k^D[||[.f|~nm;COĐ(R<ؠ~^*з#-HZ|A;<$\?|,/7YD^!bj}6A&-QQ~n.(*Ž?voNo,Ϸ _m-ʓjQӐlnLe٤4n[&lH>I - }%GyzP`St;rƊ?5 ߰uZ$,}cGz Yao5;A=YWˮ&}bgjnDxRĉmȥI!&5A~9 Va ȚE(]F>3Y}9@AzgmOqD2-fC%cP|R/CJ7Ҥ#aޫ sW3e.Z}MD?@FJ&0 ݂squ'pUHOڏ$;W3sCϽchޢoZ.Z+HTS2w.3H:d5i6sX2Ti#BFd xP@< >Js_+: ߮!x z+ `\ #wSF)d,P8b`[HW$${4<%#1K '۟栍“.DaBE8 x oy&tp]PZAinp5ȻM-nzԺ}N$,95m4 $n`LI E.1ӛ+ࠡfKShU?pj0Kc4Gy0Rt}bqdOOz_2/Okj{,eDTBWq{ @l%j+\V0uVO@ \Jg>:n'@=wSl&X 1w:IlmTo`_nW75G$尉>V4hXzW Pb7PO EOY7F2O@Fț =3?s ({^}Z@=qsT ;g<}ϒ>NT̡b}[Ȥ>.MyBJhP0nW̍/,-8 f@cItVڀ'3SG'_0S.tY٨RrӃE@.h!MVr+ecvڽ&$eVeGQKnP8.?93hSS;&J{OBQxI'qK"_n2rr#1ZM]qq -X?]咱}a3Y l?{ՕBET`gN!Ebq!FPOmV3mW%Dʳ%8e U H<9~֬ՠpŪFDvCE0xG%B@ Jw^Q GX$8 <>"$6tQK$1u\9i]2 &"OHDQ>Oo68kD,*t򕒟JjU?cl+ET~:Ek6}I3W#d#!+m;*e*]U"5H}zײvZQ0Wqi]}~T$"QԬc!yE^8*!E@HHSſ^(d? @htf q17 ]tIA R??piyh9Q2ܪֽ: $$u0rQ;ݣU]7̾mI-s @+"44N<6yoOQEOB<0 R[haf6n':`]ub0m:`>5 ?o-̧>K"#iVm>'1^2ᘷ$fNŁQ=U+@aRR4@,:1L.Z -/PW"A%gV6N/.ѐ| lYO9P^2"(| *`/Ó}d"pwPL__ 8Ap0_|:.w'6S~SgH穰 5C0&+l^`RH;HƢ{C 5!+ؔD:{(Ђ6pH2:̗Mzps$UQÀܫiU֠YwM|Qe8pM"JwM"PE!*G]t}lR|83hsq4M 4BUkrW)\.CF_Q.^iaaJN}|ݪPo!t)\O 8GBS,^kh/<*I:v#&LU A;S)9#n:;:aFRju'?h+L㕙=> s{iPzfjm. )L ;L;QqU/}lV{ |[,e8d=A!/?n2UMhs!7tD'ΙsV<(̙}euP>RbeÇⴞbk(BkO+/HX1{`T\=iTwXXdL x5%֊GeEh qD3U-B30I8< tn7%Lfw7Yrq@;h'kZ8cdx/kT;/u0.9`! 2H @;u0Z) H6c"zɥ l"nt) 48d['=P 4C@cD1ʾj\g[)뗦 Gs3jw6Ǭo&V)קlHAدBc3-e08p鿣4H '?#up`Q~Z޸:3Y{)#Y94lƚՒ{t@~p רpUCC8?X[QzqN?閫,~ + 6|(">hҵ=ݛ^G[ޡ@VIq_y)G6j}oY9U iNPP"L}Ӛ_a4s(K-Xs$8":Y HťkKD9ĿJ<(̫ՂqK! ;B.FVGc5AV[q 0~F#k^=OcX ޠISĤ!T`ex)>]IeHU7+(}(И.oTcMGj |R:᪔cvN. b1/w`o(叶h< ˱;>=ps+^к^i[ (3M2`h}U!3ͅbAd)B޸${ 0}Kpc1[zV~s-_~vf/J+?JzgՈ!zGl$?Q,u1|Km`}(@50+S,B ƖH]ՎNɳwi, &#^;_#R yWfͺRq:)$xq*wNO6H9RSa!h]OvQUԕC9cx1n,JGMʆ"^Kxƚy},FZGuP7ם|V6`:,G1"?zEIh \?G5J/}ˆ "vTFOxtxB7 5R9@n琯^bPP;:m- .#lj]Jdv˵*B#HJ d/*+SR$j-vbàxr! ac`oGD$R_$1'2ɒaV&L@bPX:}&vU@cexsdbT b4CX'G/= 7_jSnc'](mzi8Gp;@OA"aÆȋ@^˭1_aOӃfӸ?ᵭ5X)žvȀF9wUr\hz4ڎ2wL+(@fxDlLj]O!h:smY7u(f/]KMK"cゕ?uW=h@p5_nQIgI5_Cz\,_y),([j1EԝK9(5~UljymUoMrSn()w55G<4ɗ(4"FU=,q`vT@k6}Z=xOuvD-@󦡚& (}_OdRmBEZۓ3:u (\oNN>"!kmm}aӇH8 [vl;Y{y9A1((Gz̓L .`c7q# UQT6(?}S 6bwgوR@DdWxr5CTHo&/ 'N>k9a$؈&wkA?z(KtxFwR)D9HA`B~9 3R3fX9GBvdI7%Hj0UarOfFW2^ n;i٧c4(k4SA\,7E+$n單*ޫ2~8cP0KD$ Znjͼ#E渉ӺN:z8ٴI&;/f w]M_]Lө6>pʎ|WB<ڟBKAOvvP,; n\b]^eU_ji|,O2M{I7e!6Pr _5~6UtZ/} ^?K!z#(Ppڙ0Ь +icOz ,;ikNw40zb]01 }S0$YwG QdW  z:NRX0n*ay/nMѱc昰L*b4Kd`Q2Fٹ螋UqW73~nRl0Y:@/ߵ҄s1vw Lb~ $^/_z 'gK]~4K[΁EHvɹ1_4A砭){rd`ZUg"'#c uR_pȴ.ZӻHyn{At:BH_ ZMky{n v70n.N&Ql2XPqvUywYVESri,90[G#3F*Cm;>DdZaEbi|ꮖ8Ŧ5Ըǐ.zV9ӕ}L^"<!_#pZv.Sp'oXQJ0mVBw ꬚p݅MFAGSWHU9-5 ;&Ir{iqyUPk6Y"N۫Z_6*{jn;~ lmlnNK ;V,<4U>⛋"?~.-zB2ȷ]cC\ MDk$N_d!ښ0^\s+}9iڦز, jˠ j)ДaݣdrшV עhl5z׸H&G9ܰ7vYv; n]kU"7 Y),m:c"3+zrxw6ZhJbѲZp*4}^NG:,:CI\ p_Ua={hz>1R{c@9hs0v]&vz +4W!jtFJ6c1e%N O@$%ng4:=vv n7 &{6|Q#{#_&f2&NG{oLbh7):%$a7Cu$C0N_cRBL5)}>5B(h+>4#:Twx % #KFVl0㏏F1Ўئ-uur[_߂7j^[KXA̱@g6O\kIwθZYc%`6rGK%SlEΞprBO}X'x0 aݞψݵ_7J۵م"n$aHbK$'S4ک;v J9:<[e"$7.>s 85x¾[(*Ŧ7Po Р>A+~l \DYxJ%?N|!NKf] U/B&x)`>0|+zdF pr$<@kJpMzjߟ)~f֥b@rɻW3{PZl ]ȟi Y}ulNJ}('xC%xtWoRĎT^ktNLN RS.EOS">~3M! 5jzy{b. }}3o_pdL[ >< qcy )oz>ҿ;8{ektPquJK&w_b+>0{;kiy/k48E"=YE]颮&L g35u^բek9I֫Fkїeat"%=|>AԈgvD˰Z AQa4C;h:vǀԣq\5( *Đw|YKn`P[%O']O&"f|ccTZCwpBDWZEGC&xIc,M|=fTk! Кᢽ~ BdXV T.?2$@4F7x3?c{Ek9vou9FODdE <0.J%^ht~qS̏APD6eBnnDO}u Q&6"XI,2G@7ϯ\5; ($o|({̦Ƈ>ކ>?~mgpBu%RBgUdB:ckB2+T݇T+ق l)t˸*4DsdFvb?+Es؅#Dx4}cb Z#\˒kVhʂwsѓK݉CSQc%HO9 +{,+WT(~./e4A4*k*I L9{DDݟ_kD43BM|,h?bVOD*Ž{GE:?"ut=%' OB`T -&Tɽ:0QoypGҢx!*qVDfR*j^t!;icPt`:A)\xϵ8A{twY$a9vq{NNxZl%}2A+X`iarH* ݢ;{o9._\$`zay>ڞ;kA~5^<¥hݒu}bUwSsSSYq9z0`eK;Xr#f}.yi'bikejơ|6t1YGt[mY_ϕ-9*s0\%yÑ] n$}҄"Z? i$>x%`0>(jS)jC+ Z&f5U6!ь#g)ڄR.zZe$LV%JX(ҲEfNuPӤ^(adbJꕺ ckKwGh 0Lk 7"_Aƴw7yW#f-06Xo0Xu}|mpaZw S p JW4^@Ɏ^"O>oZV2 9$," ܩ 2ԕz5f&}\3j] ^kv'ԳٰTv[Ѕ¼ߚ1c<m+J](אMՊ4\F3/̼Af _ML@Z7']uĄ2s0ܡ>ƢrBNXGh)C-I>!寞P odnt_S]f+j,ZL!d9]~}; 1Sƞt4^9!yj`d\w2En]@-{_6i-!TCXO$GB?TՒJVP`+`nAsN\Gk8nUÝ8k {t`IQ4VFl&/<89$K Pq˙Uhh BGbީ֯fޝd 9Wk}_9A[\D cܨ@MW]SёC b3.`=Hf/ UF]n߬5å}WDF1+pAUH2vc٭L_W}Ý\֡6-\xqW, :$*C@)ݱ!Y׿dUaK0: ,3]@wRgKS~r<EomJ¶\Te{KT=Q`r{&$:khG/L>ٶ GZvw:r~hvkVH^tG%<%BMwV!S@QIKCNg_ÉH<9 Z"6R[ܝGΊI2F&߷- 텑򨏣E _weܕhk+M$xoiGvlWR*z`! &b,0VdHGϏBUoX9R%[ift֪|Z"vY@WJ/ ЍSMZI(:%Rs֨!|8;D]usULG_.R0,A4'~ZxѐjXr(]Dq؅2V~19 "&̰e½`d|]'SzgV4xb#k!$`J\H`#$Xʱzt7OߏqD,d[㶡z7dI0X - z婠ZLAa?މ/lBH)7%ݚԊZa^&W2޴u-`'e[gZ)N\uYi8Q:kN ꥧ 'Ce_ i,S[1n;BpgNMډ|'&~ԣ뱬~b3QDz="sںDi)G")ȸ" ,7K!l%$ U cHI V{/ ٗjuR8%0^X (^iLB1P1K5PPxޮ}Y=XT4\IH\IeY_X 99}2Vy &;0ETҩX&qm# mq{I}K:"$!kI&::!$2/4HBBwQIC >6Irȝ>5hh؊XB_l>8J)&r-k">jM妱7!yӀ  ʌ#-SyP p>G$f浍u;aV3,mCw-R֕8zwy 4*$q7Ѭ{qZAgհN/d-C.@ O%2wff X&AޗX`'x=cq$Cԃҵ,^S؝rYcͬZMwN.$(+| V 2fOrV,f!&}[ AlN 4 sϵ~ɳ6Y+-fUSލ7/n5Gz]6DC*N0aTj7b.qZzC%>APϑV{T:0TPrĹrFHA{ "HfJffS&cDe|d6N$0~ Ĩ7nSj0: ==Sт"t.JQՏ3ݩ%>&a i]ײFl߶F ɞ}TM&-54J9ݟ,2!)Ϧm| P%UF7G.MV-R68aMTW=s䄾p`zEYPs5IQs~U zJއb7̡FrT9ϒxX;#M8`gBu@ L}q@p9|r1X_$8Z-8d]tn$Pp`q &TQ 5)"(U*BƧ,!W)!1/4T%ARVB3o27vSA3u@.&)ؾyPq{5|HJ">jpzgz/ra=S^mnEİ )i"RAwE{F>=,Ҙ+"޵DDkCe $2'E$/ 3Ra`/ݩ//47H]FٮUVjS!`U}>pfL`n)dtpƀ]eMmӪIkNR DfJ7 >' ||ł~ L^YTSKS促 y珮{ٿZ,Q }[Y=u<Pn DΗ=KcƋPyuQ6Ln<8d^ Ns]?B998 #[ k[- n9q ?QaS#lwR͉j:haج^{k4_`D*ӣF3.Eqeq1Y bŗ}n4vWn6)uUFaRtZN} @^q6,+xI_5uS $/+Up/pD >,a -R?GzJlA1PMpi{;] !c:'zeoʘѳ=)neYk%:FoP m}ۥtDWS`Ba[꺷(THnxuϙ xs=!oJ&Cgm\ ckr ‰因_k4M4p@2u.ME1Vd΁H\Ѳ@cPl5pَ9cm'zf;p-ީ"Z(9c'Iq1JaiqіStM60` !`W*|K>a©nr:bzowܥٵphL^c YZⷎ?x +xHF \f. qb9S}fG >,/xn?Y= hCŔ<{ݦ<0mqlicCNṷ4~w>ݴ| =3AN}; fsGjth)QtQ#/ɑFZtTd!Qt|P([Lݖ )5>+2ޒ3\c]`i?(ILH Cd.|0^]Z2j |]%!MPyvt; yu[K^m`*l>dB@m40s-"}2],M_~JantG,;@_e'uY#SUH!LJϪS.(^AQql BΧ$e,h җ{QM"aKn3\}0O3&Pģs >˗*!8(]%:*Y4/bT P?6Uѥ9F%QZve{6"C ~hWQJB|ZG5ʚSYK,emP{W6}.3ȮB:ߌs"9I $蠌ԼENu i3B('O1s&X;'ab,o S_lʣ+`FT'W,/9n{z_yŨ@"dfnzǶ4ܔAk^W ϟ%y#V(1 =| t?zEBT(G~Q*[ wYݞF݁R•@SUx3ϒz񻙛DO`s_'[6 Oa50ۿH3}4ʆE4|̬Y@eN_# tԴ*_*F&o/suKItzJ񌋰?ك{*d98E;KG5XyK;X$|s:@{R -|YCE bʕ6r.SZU 2'u]pGz,LȻXyAє,0?JQ vR-׍XJ\iے6 h V3D硱uo6^/_>x p`!2-}~w}a |bW0o+_([Ft0QV_4&hIC}_źͅTZ7Z1O'y8 ]#@z9DlιJZ[F+#1Tw H4 ~۳F Zxo$Վv}\'Fl P ^VjxQk'?rIPk8pA+:Ux"3g̠_EL Ui~× >,fbv.ݳ M1Vd<XD{{dSz3γ¾,UHxZ],7@w-;}.elt6"5qJ|CW#:Q9lژhߡc"ҤGN욓LXםឭԑ{t[kPMz{ղq%g{K_혻%.2Xc|!Y6yye"y#<ѐ}qT2 K1:^q푛\#9;OB) 1<Syt@)0Nzbu xk^k_8fIi&;i#$xfX2L*o1nE!IkԾ6ebKj 3]@ưud~W}{pg^PNuoNl1NrV* μ͡ mKXvLaCylP l(iaWn&;WhiW M.qLxX=TP*㣇DBdiɚj/gu rÙ~>"i@Lv6,qIfZ"]@@2C0k[޸By ~C|Ꮲ@?q3Tj?(m~/LOYѓaXPh}o# M*͝H mMj&1uL&Z+YV&"֠OUQ>&FNO\f& ٕPb2eP}Tņh>8OIS&Yr\ٻ%y! >}4FlI(geFRmg7 7| t5$S)rt[Go`!46лi{֣)ʭ *TV}i$Z ^F3"wc؇ow AtvZl`n$>rgΉ{/YMFb7ڈ&pC \x8\QP~z=SWLPAC,`I(M}rnK5.M@X*bgu_3[ #jϮk%qSh"gڭM^7mR[Y ?a3H{ َ9b'26Wg/i4 3}Hw_)[7&*(,m&7xpa<&yjZ'@o) @SXek A^"M1Y/*97=6@:RGʁQ=̙K A3*SR²CwF 1TkZԬ%u~`@];Dy@PWiķ1rI-#Wލp\Hn}PFn!ty:1UH*`C wմ_v.CjZ'3$6e'MSjgL0J0LLh۪GMN^.υ '/S|-XTa )7{7ܴKzڇ*(ZIࠠ䧑6IYJ)!n%T.h,&tSѐ8k-? Ĭػᓝ%ɍ=9A5:_9:qϜX@zu }z6;'3=NHو1 "o^ߛ' 8)Sy?^bEI/ur\|5Sg|L4Wʵo!PXcx0ZbeGG&tPFp{/ۉc jD=v#BR7UB4t@B%X_Cc$5ĔEƘ돰DM m 3YA76;F`L2E|*srr=Q>6hcV:0-\J#`w^ZHgY&*Ҳ +p&Dd9-<.s$g r7_֯+m#ݓjFin %Vf  ҥHo*E_~ҌQoו0Wӟ󤳴㏞Dil67i-VYt SՊ/9@eРsfL$ff $n+7aW3?dQن{$c-!Ի:C9X1=R)IxW'H}lsnk=U@ElNدJLl 1*'u زWV)UnŧCG7 cBJ\VDߨȗ:X7Z$6ZZ v#[v&ŕ]!uH' Z?UhĭщL!Kݲ S̔]!޺xܷL V=)}Y$:'4~1|Z$Ch] &jTLߘMmxpw¾IJkhz݈(JQNxe?E4xc+'&AցIZosyT,92Z оʲcj>R^zF )M߈6 i|NY-8tv.ËA9Rpis1oXΗcQHt;Dx@{Ғxw~Xwӿ!׾ Q^ԕˬ8--NkRjN_!{saQ Ĉ3$w'-1nN 7Eu^jxWmcMݔoҙW_`CRg>xV׉n )>f@A@r< {P|6-øS٢\tkWϟ"?h|]#So!PAm$NO}7Laoi!ѴUD٥? _h{x=6G {&٘dĂ]7T0J3JB^8J22Y}WG K8;-xM(^/>zR#P=-nѩ67GLFx7б &F\ C DoI{N E23u'h85w#Jܒn֬"tՐxZq0څqՁy43Vl5zw#u@Pl0pgh_C*0v*(JXn1/ o ~,%ؽ2X K+v[tf+TPg b;~!8W3<<8K]8If=\V* G)IFa|7~T(?]"2ﰝ,]jT֘یbj m!`3(=pmB*,σz&?<͘xAsyO ~rPOJ}{hs6Uc~ﭱ(YL)SPRe=|"B˞Z9󋃰~z,JH{^O*Y -e?JOnD֤5Y]nsq֫sO >F.,WS|37! R̍u *'YmU9&"+kh=6q`XQ׵z#j͖2tGNC=u^Y:7A߷sadwy'E-KW "UEmw^qCa*[-*^J2?p~8uurvJZsNOQ*!EUNK+%.12|SGU6v,s[N}d5;ޖطAKQ|CpB!$L!$% bJU~tl(#GҋPft=My u^Ϡ=F̞&|'=jx,z}]t݄P2W"=00BpJ6ՍJ4cA1zPA$>::!z $oc >J(<ܤaGmX3, ; xubS`Xs}&KDx_am š0*k7w}zۚ[wǮ]; 5̳S {}YZ~[n_mjH9+Ѫkv/<nTG|ڸjap 6"t:~E *˃z^9!NNR+G PϞَ]C>|®38pYBO%ϴcSS+᧜,y`ҟdtD[V n6{A~lS ,Kó}ג8)K[H0D˂I;7u]\`o_]k zubW ͳ~$:nqݢapma @JNɷ?/aֳmj3A`<#UGe2*&<~u}1{ x( %ImT #12W/":eN6HUq6؉X⊢ϻ\&̚9v㘩G@h۰^"zsiI$?*9ϋqH~jgH@!/iv6\z5V=E$r5qtdz F 7KGӍ*roL6m iί؟yُbH-h>PYE}'^}CR .G7zTh|q5^?LYEYP /f_(`ABYW0XYJ\uI^[-Y' ErՑbJq@ ʡkk8H;4(cU\p?}kX˂U#kdY;+@I"n0(#/@7.*"nrdlo!nRy5t{qo"#7!=e*RMh7方;L;n^4`gG6R]ޟcTSp@,YJf:=AG6/yQab`ԧ`-p(PȩD7k= +*aeDMhl]]'_Bv"qWE~,7YKwXpr?ĭvS Ua,jQ JP݁;cYnj*(@G&zd lj?dXs2V;ٗtZ97GťbF(QOT d#"^=+JDQᄀteWY) Euŏh,#"R A+-D8ovvs%+@XҚ%!6p6sB:^k4v 9 m^o%2-[!&$T7sinV640!m{{M`o5} mޙ  6%3ּ͍vA*\{.ُzt53#;-}&٠Y@ " 6j_/5yݏ.X_biBrgY\E^Pߵz"8a|JX y?p c<3>VFSn{*8. HM|C0Zt/5eJjhN2`7t;ubEvg7:/JfrXކ  BW]3M2D%X./T3}\ݽ.DW3`&Ōixzg'zFnTha2/IQhr󀆂z?_B|k7 )i, [B\̡Lɨzr[u-TðF4 S ( _gƯOha)inCrxF;hTnɧ Y%*w閹ҞBuku`L v lafχ&ͳgR#vj,.F:R7*o`эIFǥ!Y)k6{zaY] GꂔϞ(&;2BiKe=#Hx%f/4v'R?_bglNkR$pO?.y2|3N[GKa<ހsmcr(_;ΰF2 Պѯjk"F68ǴQtbɎI.g1Gُe(CXb-p=Dn$9}aib!XBNQU^ɛ) ӛ"jv5=J7.2]UQ*}Xc ( luhO s&³C+(T +2!ڙ_[(_]FH^mp210DR 50[*͜w\Ў$3q|2%WC]ĖGi4(XN /=ؑ8 /*] gϝg%ixD9B|4M3֘\ b'Jc聑%k? 6-妴^1zvhui _0Z33%O7}ܦ'K(o XWp6lDw`k(96*[^"9 2mNG)8(r'M42[5H(=WDUM'RܣȮ[9`4.-?3Q&k fۚkm/*CF` 0$`Сt1v2*8e-w5 -˳ڑ'(sÔ‰BLs&4XLQU yGuW3Fzҵ~-1? ]C}O i5U +>ʈ^(`E6p)k/rmSܩTUIJo*zگM:*^_U 't}w8e̩I+>Z4m? y힟нL!4:|̵b'%}Pޖ.YaQWGS1`U27+~^{߯4hQܹ8Aij D@;**} [V{j'CfϮ$Gwۼn fv%ڏ#!^OLŗ MXF{ N#_3:4;6ZfbCWM]oK;Dsxc і8 U.*A!,՚ަgAw|Bv*|HϵF#8o̧^Ч5Y=?jp] uQ!NM{aFcmQ ,QL?ͭ6-"<[xfgEJYc~jc#%wG3E(,`fKhK!{R*TwQ|sDsyAqFyFdR[=#oo |BĒųߤ#8m+_-׃%0F"CmB2yCCn|*n@n.1ݬkHhN#!6 l.GГ"A'9I,^pέxMŧ\Sl(`. Q=otOEp㱅tm=@DKU X4Om YjmlK`-he<*FI/tao%XcsFΑQT7O'y[kϴW|z;cmרX[yE_-m 9!2pO@/C?c/ “lqWcm tz8~X+AR4Ip7La4ȧ:ߢttjiYӃGTc+d[AQ'DXRiclY'Wl'X  SJ/3wY8%)=?3;߉63eF1[<&MEΝaۇ-S`t"ќ̇Jk5gA*RP)xwR<ȗaoy Ai }9*c)@kꟆbI\JUUB׊m%dCgax FЋ0XEZUi lPA͝,aeK NnWF^ ikKߓr6& ~J*J?a.vz,_rJ m[Pwza #!NR`XԛmM+dWkWtx1 6Jr~GDxÎX R`ğc,ׅTPH$Z&n!Q/ƮM8cD<tu 2(>:Ax7!GȏI)sF8ݳHy)z(;ŋLeMhQLDBO`M~*;@ T}Ԇԡ38pgHMJ &+< LBŔkTAp}w٭F* !?޶Iۄ.E:6+6*+P9u>}A81-"FdZ%y XKw' 4=@ +gt\|]3~pH IVE-A#}A^Fm<[YryxFWAU*PY {'Y2_RY`2H83s\>HO; w5]OQiWkeJ6^Sua΍NV-ٜ Ǹ8<.n4iK>1Eu3brpQucpQڍeKlwiKč1dG쓗(.D)@R'Hr 'Vu3%0]$A(ˎ\ܼ%aŝydǮy3( vёJT k37 ,˦ bK?PYA!%\a?s#`4` 9OG=n8?z_HU8dnLPu}ʱJpgih3/܈68EM 4:ۨHDoM~'}S}׋>=E$y2ayꃹ~;- sM=| -$y Uu&o.GkQфJUM0Wxw%͛Vu2pg}JDawÛh>Z35>VO_SY.[5fЯe9-w#^-U#t yeEZ{wpc]] $VaO࿞!Dl;VlqU} U0I|ܳa s(+ #Rp+>gMצPy$_jVsd-a{O^k }`GT R9+P"?8MӇmJ7L?%H}/޼ß;4(Zop$٣pteA6eoa1# ;yXBBAA01vrBc O*tDa`|P$OG~#Ͻ s{K# .kQ a"R@a~y ,i-2j|6z1e}"j7܀h'kjWv?ZB;cCVW'?~RIA  !U-T,*SXb" UTm!YV}R$yH)VP]I/Kr(fs#! b?(0!ДZ&9VKֲTk `@>W|"'Ϋ6D- N##גKSJ8R q"KB?\eDW:-5N [w֧]qEE|&LV ̭8 y|5Գ>]g_T,S<4F5pˍuZZzJs'vdp$GhIo ~&V&2ȾaEf5vƝ>z((r̬ht WS槞*b:Oh; 1k,Яʚfp;Vsg7R؍˰2 ?bŇd$t7Sc|mU}[sw&.LQy"ɢ~hTd[HUUΉyt(*ƝS;͑*>o'c/ {@Y= bT +*z E/~;%~VBms9uď_[frO4%xd.$@-oќX‡l+Q1aQA}@>hJI5;j!/FD/rt+6X9ޘbMڳn3ޢ)BVDUgY8M*a3SԜcB:_Q&.vM/O/Vt<_uz*d6?2#ǫ:4U3`5(q%zJoyvl&8Rfd3 9u̩s0ui2|(JAʴ{j"ӓSU<˳/ڕF8/_rΆ4v=\gC! Sx}pOV %1Lx0$gEvX'O׃o]' Dar:?հ[~%rDb(GȒHV&{Swp"Vs zٓKU&ߟg*CxG?\?e}A1s){=7Ǥni=VP/f4d馋&=VȚʆ=-ZMy=0_ -%]³+nZ"鱅U<1Ŵו}sT.m61A^y9m'cbTa+{.-{l;%1uy~TqCi0P9"f{X)i]Ӧdi$ob3<Kߚ٬%lT0|Y;@v[cLXa8\Ow|k \䔈l(6UJeA?*4jkV95i-W.B-w֘ዌRA^H*.TU,Ә-Ėy ;{xٕi( ku]PBi]l:%C +uS*h9k8ě6>ܽ=K0aĮӈG>"jX{7ڙ84GUVY5h6hbI iWwRN:vQTRƠ{tk]-N˱Xk!Ӂ?Zѣe;W:>*rm$1-@*$;#R}^mC4:V!x&pWYY|Nyo#5&Ue^J_}W*8YH}˟̣MHT#V}p^d&嚉Ĭ-IfZpt%,{ak@2wV`4:>hMJ@(C. uHmx6@u+4xLiEJ9A3qdbU :t L\)^3* 7s ɀz0KcjM k.#~`*6++W+)ZV_΍mY(FX]>P>;' R&G~V^KfAh-4vEdy16`}muX7p/Tyuz6S\[<Ngy(t pq}ygW}/aN$fً64. imQ8\L( M9x[kq8 U:>kP|<™\I/Q3oFd?!zB { D'_R22)X'P)> NzXc M3&ȀJ k pBt.%867/PR! *FvsFc@֌K8LP 5\2.OY")Q@$*/ᐇ$] P-; tPR_s'[߇w-ku՗t [+R|JWʨ7>+2kc!HİfyjjG9%[6,3+THL{ueIΚKB:jӼ`Qo&eMQf0yϤ@F-bj0e ; >*jJ8Hy 5?B# 0Tj˷vrK&.@͆q_+iZPR9G4@Eu5(5[#3w},{KҊvyM`O~]fbE *=6=%!ѕv#ֳD׺q#uziwV%97,65!1_"lեu~ &/X4!ՀH6 iETw,XG?@ĭIk;IAι~_}mq>05UV2ҷSCƷ oX\. %@֦8eQ 6+QpM2ns_z#2TyZM`E#өjHPd'6$RSMTrnܒkphOlq,HJ%jvgtrOVLM+"DpA.D@lBV:as(VYVBƙtU/&ruzL iHE0ll95 [~-S@-f( kV'L9ꍜ]'~FL=x-^aA vga59|;\);/!Y?i*~ 3y/5nҨCFiqod e=$ԊJeM7s-ݐϲX 3ΗQpnh'VN\;53)qul+V7[gbfUQOQ NDZuFy`"bk'h7۵Nj5C?@hZRRMՏ 莬U;#:H{};vϣxܕ,5QG_r]Xo"#vPX-J7 .Ws~ϖU=@xޔ)&=Ѐb9ʧэ=,2Q?$ :*YT5'G@_5]i˝5nK"tM Asz`ߓЋk3N*t!-$  qPwBT=h`j_\_zDx,+ucBz.d;+@i8ɮ_ @Lh J$_s'u  B{JjCf4+anx}8vn\B a*z@2_@8"3&Rh:KPʑ ᆵ^r tρ=%bGҒ zP選Fe)AČ˙g|WeUm#d4[$3=t8A ?H6?2 _|rczC:]|q{S\~侻n;]ED>ydBx&7V@( RrUtGݣǛ=!zS~`~dZ;' މ)zVkwGr B\ /1,fzֿbA9']Q*SW'Ar,5 aeЮX}[zC" at_tajQ~]Ģt4wp KK ob?iG15jC[*U39 %IbLOb|Vr5MǡWf}hzEW=~I{MHa"$)t+5yFK> eFph5j?a4(eUQmC!\}4T/ͻ~UC-Q$;u<մ$ γm9>bj別4$98NDC~= ĩ|Ս>2S`&ԁ*>[`h)\!R|$zM9{ٝ M:68-W|8`/"*#]dqۣΎi@Q>ux N";ͲxB2o0naM|0cDqo*r]CmիQCW0&xO)E3vau!Ǻ:@ÜXKNI/'5iϔ'CsxxU11kj"ifD,ziawv8:3bͷwqB k0H?8qz8(!k & 1m7YBNcLL{#5*f_K0IoJcCryF >NxgYs"jl .N <Я8ʜ3.]Eу0Tè.?O#.,cAzWdK:A ڶGɝ"?&˲lPDST?ؘqoK n+ -[=ONL5dJL/1(;M\2PͯXnUح{UX;cG;6' RU(SpQ_k5_Щcju+RXH㧿+kijdŖ=Ҫ'f=jyZc)kf+p! $E?&z63e plZu=kW7 NzjkӲT3uG!۞ \N%y춱}F.%UWY5kn B^cmE3_Zm1;cvߥ!ާ̂=rJ; 0ZgM-LIzں|lG,Y h' "v YZ