sssd-kcm-2.9.4-3.el8 >  H   '8<f))U U]̢0_Tހ> )s;} Aw׭۰#SD K6y+q +8!|l@V)!DQ+/+?1ṹMFPp/ɵҡ.c %=b*A=xLlIZn{;RΟϡJ`6(MYYX˦`2fWV+mbR׏-M,(|/<GW|=ll Rg' EHZRox {w 9B/mʛuonmMR T~:7H"U/hXaij늻U7?TЭOJofI٘XS+;N ٰ5̉N3~/ί10(9" Jl)b y"/$r}ݣHN7 xvLc( ru[*!+h:,kWr`y 烬7X 8X7vtfabbd3451b2c06752e8d78efa0e976ec1501aafd4d1002ed45716f9cb1fbef4d1928be033d90ec0d7137bb60910c72506de9348dd80302047c435bb50066306402307627cc1143b8a795d90b82f6a260a079d927484af69aa0d176df01887e5dc12d3d4a73eaef0a9c10f51b1774d2b27548023012df82ca39c6e959265d1da8f919f56d56a89d5ced873b1169253d8d9f83dfc3bf6be4c394f9418112396789f76781630302047c435bb500663064023026480e5a07430acda3f688f0f0a0544dfa63fe69eaff2fd62e751f4a47cc165cbb34398c72eb777a8de78230cc0c2a8102305c1f5e77cbc2bc2d54407f81db275fb4db8c5a41462d6a6e474de2e80907e20de7128f150dda62d56edb712a46dc9fc30302047c435bb500663064023026480e5a07430acda3f688f0f0a0544dfa63fe69eaff2fd62e751f4a47cc165cbb34398c72eb777a8de78230cc0c2a8102305c1f5e77cbc2bc2d54407f81db275fb4db8c5a41462d6a6e474de2e80907e20de7128f150dda62d56edb712a46dc9fc30302047c435bb500663064023025c033c55119124518dbd95a65ac311077b66a75e31dcd69db5f5726ac1ef13146ac173fb8c9fedd4e52aef7c3bdbc25023051256af2a1ecac3b86e1668c2392194e88f4cd64d37ea76e8da105af465898f6bd64e5954785fe5bde7abeded5936eed0302047c435bb500673065023100ecf26718669695d8d434bda7a902266c7b967264a01fafcd1db92fe8c3703e4e107f3782380844302c3a15c210a628b60230353f150be583ead65f16c824f5163661931b1f755d987dd26b20295bf3d2adc98648d9aeee5b152f6a77a50f2dc6b9cd0302047c435bb5006630640230584be821fcabef7ffcba028b2f95f256878930d0886a593d3d7a1f6535853c17679c97b5265e99e5f7af456f3513c06402306a64e09a752fe62f8c1cf89ea5c8887ae1691bf3dc083adededb7a0a91f91464469436977d84fe56dedaedb3e3087e640302047c435bb50067306502307202f32e179af1906300aa70478ff8904de21fe316840975f5d92c5621511d20657ad8c518239fa2b26851f57e68f59e023100d8d4a54a63a28cd607ddd0889f6d3eb327dd643995dac78dced48ebfcec64de10d4640db83ef6eebf334d7d0f221f7420302047c435bb5006630640230525a32c3dd02882efb190fde7235a87112786fcbb070445961a4f3f0cd354948594312ecd57f753919059c8fbbbcb091023074412a496cabe0f8891fbea53c7cd192375f9551edc7719b591e428031b09fad49e9de759d0516a53202d528fc155c220302047c435bb50066306402305fad2e6f0e133f27862c1ddb0e7c346766e863ed4cb25c9a2323c8b93137bde1807fcb0ee1652135d8e1043c38d2f8ac0230422df6f0dd5de7d7051034635b227794b64ec0c5d11408923a6325fab7f85f9c4d354c6cd1b1483ea793d1870d99de110302047c435bb5006730650230426e44beec0a56f65bf99c6e8cef8d0ae506b2fbdcc5993790454f05b9337e2e3768a685325cddd6b07cc9d2b4b5e4e3023100eabef678de3efceb53124e953697596c004c662d893e41aef63de331bc65c9565d2d2b67a50d78fe53ef1bbf046195650302047c435bb500663064023026480e5a07430acda3f688f0f0a0544dfa63fe69eaff2fd62e751f4a47cc165cbb34398c72eb777a8de78230cc0c2a8102305c1f5e77cbc2bc2d54407f81db275fb4db8c5a41462d6a6e474de2e80907e20de7128f150dda62d56edb712a46dc9fc30302047c435bb50066306402307627cc1143b8a795d90b82f6a260a079d927484af69aa0d176df01887e5dc12d3d4a73eaef0a9c10f51b1774d2b27548023012df82ca39c6e959265d1da8f919f56d56a89d5ced873b1169253d8d9f83dfc3bf6be4c394f9418112396789f7678163!f))U U]=r5dmL~Û,sig.r hѭi͵]V2TGR^_{8T '!@QtE[̇'֥1 SR\s1#_`B?d   B   =CK`p         L     (D t99 9(;8D9:h>?@ G HD It XY\ ] ^ bdeflt u vLw$ xT y,48>Csssd-kcm2.9.43.el8An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.f!dppc64le-07.stream.rdu2.redhat.comCentOSCentOSGPLv3+builder@centos.orgApplications/Systemhttps://github.com/SSSD/sssdlinuxppc64le if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi%6ځA큤A큤f!$f!Vf!Vf!#f!#f!'f!f!f!f!f! f! acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6bbbac31b33f419589e342f20381138c0dea737fa71b0d67a0db97020b4451afd8c2f6ae53e988971d19b13a2104ead7d8f059bf8e7097a1a5d82ccb81764fd479c624cbcd1393c779565728d31100b3ce04ca8916f675460d1b0c9adf195cb293dd8a4cb4ab1f1094e996a5e379aa0f1498a9f57f000b8246fd1012e81942e347adc19aaf4fee0b700d2cc411f4396396494551a8cd2c02860159d38bf063bf5fcae12f6f0a582708d6870df8d682145b102f832bace064c65820bd6f582057c5893dd60d013b32539da83d7bd8d08203af1e30fee23993483db4a8f1dc790e4cacfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6b../../../../usr/libexec/sssd/sssd_kcmrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.4-3.el8.src.rpmconfig(sssd-kcm)sssd-kcmsssd-kcm(ppc-64)  @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shconfig(sssd-kcm)krb5-libslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.28)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libini_config.so.5()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.15.0)(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd2.9.4-3.el81.18.2-113.0.4-14.6.0-14.0-15.2-12.9.4-3.el84.14.3f! @e@e{@eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.4-3Alexey Tikhonov - 2.9.4-2Alexey Tikhonov - 2.9.4-1Alexey Tikhonov - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-27205 - Race condition during authorization leads to GPO policies functioning inconsistently- Resolves: RHEL-25064 - AD users are unable to log in due to case sensitivity of user because the domain is found as an alias to the email address. [rhel-8] - Resolves: RHEL-25066 - gdm smartcard login fails with sssd-2.9.3 in case of multiple identities [rhel-8] - Resolves: RHEL-25065 - ssh pubkey stored in ldap/AD no longer works to authenticate via sssd [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-1680 - auto_private_groups does not create cache in IPA server SSSD cache - Resolves: RHEL-10092 - logfile rotation for sssd_kcm not working properly, sssd_kcm never receives a 'kill -HUP' - Resolves: RHEL-17495 - New sssd.conf seems not to be backwards compatible (wrt SmartCard auth of local users using 'files provider') - Resolves: RHEL-18431 - Excessive logging to sssd_nss and sssd_be in multi-domain AD forest - Resolves: RHEL-5033 - Incorrect IdM product name in man sssd.conf - Resolves: RHEL-15368 - SSSD GPO lacks group resolution on hosts [rhel-8] - Resolves: RHEL-10721 - very bad performance when requesting service tickets - Resolves: RHEL-19011 - Invalid handling groups from child domain - Resolves: RHEL-19949 - latest sssd breaks logging in via XDMCP for LDAP/Kerberos users [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh rusvuk2.9.4-3.el82.9.4-3.el82.9.4-3.el8 kcm_default_ccache.build-id80994730b1c162b6e26b6511e798e036834071sssd-kcm.servicesssd-kcm.socketsssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id/a4//usr/lib/systemd/system//usr/libexec/sssd//usr/share/man/man8//usr/share/man/ru/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mcpu=power8 -mtune=power8 -funwind-tables -fstack-clash-protectioncpioxz2ppc64le-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, for GNU/Linux 3.10.0, BuildID[sha1]=a480994730b1c162b6e26b6511e798e036834071, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix),R)R%R/RRRRRR'RRR+R,RRRR R.R#RRRRR(RRRRR RRRR R R$R!R"R R*R&R R-RR3utf-865cb695fdd7b6cd95ac61f836f009a5fdd0ef25521da77dd7a069fff9a63f209?7zXZ !#,\6] b2u Q{LY-i8ݙIHQʦ!ͻ6 _sx= 3 _n*>H5#0g!|ɰT 6F~^ xЖT\*N<LQPi"Isow /moT)>e^KtHuNvQ3;^}}tr*}^D[ɤA PVwQNwz/~n)|O`0 /i;wi]ZXJ,(#.j55&-U_@DA{IU !קSw"ٳg] 鼂\,}TZF6&{C[*Xq^؅c>mV_En7l}X -B|)uS d,ᛠ̼f0% j!:=P drhk'ws:S V@ 7ԏi(IUicʴSG'OU`LSLbĀDl(RI)C-W vY]y֪Fd@9)EdI L WW.L9K4Hn f⸤Bm]׆tmfsI1Q OuOUl=C\&^Q ~fbO˞34֐/ӈPKB@T"C)V&Yܩ]ȂEٴ83i>c=G+Simt:v͐tm"x ^Łiw^20Kai?[w- {-@h`-ŋ "^sR,kXm ZYiq r?Mt,\5jj'R‰,tY}z:P^U'ύfTZl&&ߝu&lFHL[OvP-o7W@>nILaVCjGQ /A}ٝa5^1z(Qǹİؑ&` ד>0](s]FN.AO/f>EWE=>*oڝm G`F2K"%x{h[x\8 vU6 -)y&%[ܠ YDv"0he䆩-ߐC81L2.U)mJ!ruwUzg12ԅ#x$̤JJ*ӿ'BT Fd^nqժVȾ,&c}iW]()oLZU }M ''TMIM\h?VSBMŖz ~CD VE!6g$OnnR55p#{i4}*4q,e2?Cq'%h/*C~N$`mO2558s]M~h,SA`JX1׮u4$#y?!Hc8=u[E?k8vչ_K{ՅBavGd\jHy!Ca5l݇=Z>nB7I(Xș琇@h3wƵ !(WV-Ax`s·γD֫LyOx^vfxn!&%4Ek?R[q3kUF| W+Id./B{] s4C>ψ qq ̳V\Mnl͟&y*kЋRcglDq{Th $&~6e.MC dkP;+  -Ζ$7WP_? Vo] |;b5us9Cs-Ue2_lC_5&INCxY/+jA&5(yG8$zIfDD-.VOwBDh&1NSR/By{)yb4{&K gWVԾ^jl6qޅ6OW^YSz:́ϕa#wq|/OXt%NY,k]U3>Tnb/ɆI8<x3=v;ɈY=2dZ)vcFҴ4F;}|/dȀ 5P5٬ap(u !Sw2+KSk^ʂXPZgȹ+1[V7?Zҍr"aF| t [07])F""C= D|j4$0S#HqXu9/DQ/EqP?8pWlz<#IQ_$>wyYҎ{^_4Վ]s5M.c1$e0&OKhr(o3Jύjԍp;vZ>S~t׊cZqoPXn>L&PBL{,h,+wIF[X`B|jv.#I (a@BTW2,}2 OboT< #0l-)= 9*èUt8u-{ I(ڑ"' 2 譑'ijK}߉LșXi$ǜi~U*ydJR1Ud:_@֡uigި“往fa,Xq]lqp&Y e$=j<Fp,1x>*0*Yw%c N@pOȆ{>IiG5a0C S;$Z_S&5y; -RٯoV*D&!@q#cF0Ϥ`"}tԮd|֚.o 8B|!zT\qh*)KxMNfe0 sinuIlETćU_ ֥=s;`ꥲ ,K׌ v xA>F x,KS_ҷO *@:_j,T FyawOW1 M&xގ#!h c߽{{]gUpJc*oS;m$!a  XVl{LP(so;H1#n`Cs@y$hF1=xnփ|Deet>9Kr꥙:6JroU:XedUI[ Q=3 %&αy."vKC76M,LE:M1QSV$vp [ cTWoo.喕3Oܥ:YQx]+u +;\f*h2K*LJAtx^ի8|  xP?qj\m$\&lFj?ܽmc'UK .c/f~X&4BҨ' ODV&xb=)RểU&@(ҥя|* M V=pv+VE':g3:to7X3I}"=m?(ӛS q63P1OU8?Ȣ3m/Xk6>=(_%0n+" 0{Qɏ59IJ,,3rdn]&Mp)ˉ =00(/ֹ|5;p`H`W$lR0.ky[!ZnZDx ;3![}WQ'3$\`b 60 EbZ@SHqcb^T"닒bXiOF.(3[c[8X̰4X_ X8k"Hun;T21buZgr,tHɟkC.!.g-#2ˤ$gߴP`K8^牖J'MC%%.4x!ϫ|AhN e(2L+8 %N#"pF>rQvTb>lB]8Z }npirA91jU}/ nF(){JmtW-n Nhm[M\`-f4<ӧ-;|37.tWzE N/a}FbR$^JBo:Pޭ_#͂v /%*rDi!@K~IqH%.K c|h _?j,tJB엊@/1uZ)!4cnijG dH?bsg :0xi[2\9]ÇDaUwKYjJ1D,k*6 Nx*#VFGr8ROTax:> $QF;\m)@|1fXhÖCS'c `{,c.E:8DH L 9:o 3yx]N{V\ ކ>X*CJ<}Jqb'A4tqϏ;o0n:Ȅe5(8DENCRy<>*4tm h44ɦe>_k4w0ns^>glw.qj?(0ifV خQܖ}PN +hR `]DH+A$>8]Hm;8~7 5SYX_>%c>iX#7TQ(?b73\CzRtl}7⎀6Nv+Jc傅adVDňع0r? nC\oF9Hm:s\딳q]Ǡ)bˑ_s+ya!ɖZ,Cc-N~Kf̺[uֿVVmƼ̀puFڹ&yG'0XP:څ6~dp>jM;46r}|_]o.ob <@ OJQ@z6HTHyD<.*i3 \Ak=4`j7LUZ2|2/ܟ9`O,Ib=ʶ*W. Dum.mҼ$ 2aJ xmb;: QsWU,UxNq<lѭ^.9Q~5-~#L:NvY3De%Ej~ Ѭe[-'OcsG FGңgqS_z-4â!yJvgSeKȺ#H/3S_ -8A$l93u!F |D&…|dZ~alM]|f0ZB0(,MǤz88#$:\P7 C&9y4 %4HϷބկQ[e{A&z}c`# 9" LK9)Ǯ8hwqt&?Z5z-?aP.j%Mg V2`Μ,{~ b-F|k"J=OD#dC]pp|oG>0O`;ˉLDY1PhDLzJ5ֿd$jS[P _g{ $@1JLRv>a *ll`^l<u%Tԁ.UА:*_z'<ʃP.'D$ ~(Q%J$5J= 4S`~@*ZkTL+)j?U#G*xߵ*-IXB@p@Lju , }91[4j_ѶH e Q>'%<(Pܟ)c6Cؽlz̡~a4RGMا&?:!yS+!Bjwl$2$:,Wo[T܉eA}Wu۱-!0vL6BvNEN:.LnOb=t7R A X>5Ⱥ}5fecq&PƸ.ݤs&fWJTpmWMb&n yBr-vfQ"Pz8)Ow{JږIT{=?qޓj{>q|qYS uA|Z.:&D b$Λ@CaPD\KirV{b+[ el]\%> R,C-cQ9.|ЄS,p-d 1gse#c^/˗6 [W!ے V".:b#oH"wK^$ _%\gD5z}[ /( %Z ^vc0Ot)ZݓoD0I-}UU3]|^ !) Fvv 0HOߞz LG0[mآ=%Kuq5 nbM(+O?~tהw`'sVKv^Ja5^i;LgCvG]M^$M +/a80&7Hxxöq@ bdCsPB^ˮ`rkZ,p'q;$=`+='t$WRd3ѼFһZ1F A @"ΒErBQ~ @_n %:_jת—˓6Ji%'^lvZ Kd4)C t9)=C}AO/ 1d2Fj`q.-1VI]A#E9'wKBAyV,|ߥ-J{pF0IPJZ þd|`?}|Q(Dkʹz/!^6a{"»=+L$d}' {~PI@c,:xP]>TE5jѼi8؋6TET~z͒f!t!_Q;FϞ>U@}Ar:0C#m yz2[Mv⊅-qI|MZ)RkkYo^W+Ʊ-#'FLlLȚ1R0e%ؐgXXw(_t֐3~vj=A4σrƎE!&PڽJqDk=X^i`xr+Jٵ7GD릑P>HRH]y{G!GCH}BΆqwྂz-vb  CZyV*$ꑯcf&/D_iKbe`w0ε>Ȱ J؛}"}Yq( O 2$uE4ޗ>gn_Ǭl%ˆ@B܂Q{L(`Ѵ 6w9SwQs}Uq iu<S7J`" T\} TO 1oAi h.P6g `}o&}KܴA;]r/9[!e| j;Yt0(,dT8,]/?g/ '+=-Iq[S3R:xY cR$y; &'L{y;ԭOp+p/0mʬ/a(O]>W?+Y-$Gfio/8( R;M`ðw>D\I6;&4|ܼ`!,%5QZ%? +u`h=0e_ZaYr+A< ;ǩxB3؞/淒+f"M` "ҏSE0JFk,%oi2~+;Rv z;Ae:w $D?qa;a=[e )qd;LGhH PK"/Ѭ{|qX\k==yzgٷ7AS5_b!yqP|?_;.:Xg.S5ϑa]K78PEukJ %exTxFs-I6 k-&]n-7fX=01y z"=K/R s)~w+IewfMh4rVu1]LђY t^nd HKKcVguw=YN7vlo]ȦuFH}v&JHOZ .*> `ΦBJި*ir9퇉+z*DHHQ6Dɶr0!.2 hv1F*|f gn7o'ŗ4:9B(y~&}t/Pa1X9Knۙe޶ @W`HkNS>S@qz2.zП}'άW \DN 4n&r`"R !Z9S79'Ve[6H0-FHz< \ *Y)|4b"W$T8V]@_3S$x gPdŕÅv|N.5q_]ɡ /?sH?hF:T<16I8l-DIӓ0hL V)NtLD*zu-uB+қ6&)z7o2y?6}\qPwo(5Wy]^:XMFE' VeEAk P1/;kaVRmI: F..5b졇=T7N9[cZ/ƘzlA\-;~k+¤5M sE B([{#þ=x|bIjv{ro8NxVfbdϧ{?,XNa}w[N`"^YvӘLq0dZHJz޾ad/'E,o6@Y1=(Bn،e;_RHUd8iϵ4v0#W 4)g10Hf~~b) A,J8R UVWg[GXbN2)W^㌜Y #9F^O5J!%ϽF[E$d3ӿw(-Bj9\ мʧޔBxFKNI;L OmO\})dz&t!z@NxHUNh8q]MIl0998A|$RJ) y御(z*:iaHb[X.[#\U@j"{r?Qo+ gnF{\!bh;9bZKt]u_3RbޘZ[ sE*LXdՊudV ݫ4Ǩ5哎RϳJQ>-Ww ^ES$+ؾ8yh[;#-gHt_ڊt ̿Z6F>"?_ADr|HU}JY9F^ejj2X ns|Xlt-Pp<+K=Lfje JBkhnfa-)볟1+aO#ǔ UK$+RR %ioM ^lѩuF%[=D/Bz<uFu=Vb)zxI(׽XO7π)!ùQ,rw9ܢ} 9xTqyˠe@)JM2-UKǓm:Șhf?yTiXÕop:` +'ESi!hӑu Ls%ZjD)e<¸PrNް*g~*W(,mZga sD״?9Gknas:"w Y()Ԡ|*l|ͅ}w}sՏEsCoNIηlUJԘ$t>8nA *qRQ꺗00jZ;оцV}T0ٖ1HkdVhh@rG01>εZPJWZeƽXn?%Mv/.>sPBoQb=|X, ҩ^(ɛr9(CHOb7Xf%piAi׊\ W>GQ!DJKFYsoWO@XЏB >iZcoA:Yޯ;n4xY D[%~\xWc?۹j$%P8ɢUൂ3YwfRxw; *zpUvfy;hѠ*&x%qw=d\_z?MSEѶE2=0$C Uw.i]I)zSM9&"}ղ0ց? ǽ{ 7րL$&w"Jf}$grKQ<{dAvP8k錮K ޲|q{9X +vÏ{8u ;v6N1Qr8*VTH!{wQ&EbSa0>SӤOnW>?>u0̳z;ڽ';эk<47QrAT*؜4YSrI>$C`6@ X }u/ [D3:ta7#RCJs_l Huewm\VJݛt=DKB u&[gb1r)9M VYdAQ)ĵ!DNlW3Lۂ|]:]:JH^_Ox5ׅcpG{z^땬أұ=o R8%nl bL, cB#^#7 "n vd3Եgj& αTbƴq?J&MzOΔv|o_QX%ٿI, mNbqV?4Gz2gja9;?5 lu"e]~qgm F:*@}B&0Ӳ{-9~dԷ?{Ww@B"7ʲ7|H&e_S=pV 9:ٷfT-Wx9\: l{D\QQk5k[=ǰF5m⹛ѹFOm}AC@(΍/b c`Y~*šU\| ?jN+ =5[k;q n,k+Pd[3&wKv"/RhSzJ$9<#0gkKF]C)P77@[!DLCJ1kz]_ @FJ;~W]f3٨8׽g `^dX3J@7.{= cڣ3oLbmFRB İbVk/8Pȼ$)FI<c +c4B%0$.NWw"y89ڥ֨glN#9Rj}650g`ܑEZ-ȇ5\;m [HO8dֺx8evr7ԁLja0*<|QK1>Fն,lj]NcPT|qBOm(;skЋJO.!:?p'w;ץzOa_v.߉TႊtG:Hl=,o_[؜0iG텓u-%L4 ݍWuZl.?+{ .>@CK(YpXٶ( q;j>2A3i+X\ꄪFv`I*W)$tku:^yq ^ M')1gh} c1B-߇*o\$R^kM;ZrhJ LꍙP@I̳7PhAuJ;N}0I-zh@eM#iFWNX}[/5mڭ=O(He?N=@w"lh4oH"'Ws ހ.S㟮"Qz? ֢;3`kpkĬI&Jݘ&E/ӏafZOJWY|FdIU[R짉DiYSuM!@暈",+;s\y[>!%%/ΟCLz#oafU6ù`z?ǦKjNCq@e򻇨KXҎg@CA}:`5 AH ֕jC =ׄy1X9 bEDRϧy҄dJ2<۹ݞ\^" ˙`eJz q?b( +cX"#H%.s))x$'SsR\x_Knwj'VpYCA̽|)ӱ+0wZ{uNfmoO}'E' Z4.W$1LOw P(p0]5܌d8%Gp2ՃHm!z|#ĭv)~ZEacFDELUݫN6]-a;* {` ^'Bh[ZT9gXr+>6t0L7X*v-Q]4J;u∵f2Fx6OuI%Jft]͹2iiW_NF^=',NBj^ݷ X(?m .7Lw!@ 9ʲuTkAdV,T)PeH"93| qQk)nk5AER՟jsܞ>|x|S#9[_5_UD>Hd΢` P3ʶak|-ԓDp rI_$uc7 AwJ)sjI^kwi!gh JS>_PS (7 "3[>vo\"K"-> ~ٰ8N^껡ll/W1**ʃ1<8TV t/+ }E6QH", K f^.w@'I*eFd7X(x[0Z7ldUފbx >y=͊8>lS^Xk p# Jw.]۟z#B>mjq3cY:R+ey\0E]zfԀq$ ߊK#웸IW!lԁl<<zS 4rD[&`nQ(p$`0Q^9-d,QLAE6 |DF< *ʇK1uZ6 {вm3:&:l'LM:ڗ_-+zU6 G4#Np놳3g|ƿ`7W6B^ x@WYϧX ba"3ir8Z eu#K|dܹcۥ?QfNhd}bx40&Ϋw[GP ٙ6uj^ lfBCDS }>72ĒmmOXNloIwkq0iybJ.Q33V[ɸ"'"+V4C%!mj.,+4#Sglhu="$n+M%/P%';7Ehm~|@$- ? CG E{A&?><<7-7$F5;;x%+yvydKtny"J(1b}S67T7[?C,Ю='Y#~8LnKH C?{ `as2WYLy+%05iG ha.1 P2ʲ.5?20W ?V[ϧhs#֯uTAb%bLiWPcVߴWefB d#Hp UPr[sVRfA?; `Yyʢkg/яވ^',ZDq w!Z+CuI!`V2z=SR@nNi qҏhW8e׫CS? ̲+msR=ځf=;@溯ǣʌ$+!ʱ8O/)P(k&>wJتQ,܂0JMhyúxFPZ@NΎ׌p 9*9r31ؙoM|Bױ)IzO/tn?--d 9V>W>eTiZoL)pL;^B 8E' Y0f z;9ם]/^Q8Y}qvk#kjBE mn>?:dRUkN:Uj|TYQDmzsS xR0Dg=h&MW0.ly4ƃ'xߵ֓-oAfҬ?s;=K9.g4Gf})j ec W+x2rbQOԛfn$TW5Po?H$-fKɫ6H|J=}{p8O*mjXBLzxíVeq(Й+JB[k|v ջXp|HgJ_C74ȭɖyYgh)Ą*.I"wUOcE%nQ*ysRe. Vl}u|_:2&lYޥf7կOXzv|C1/[VB;MOWN{*佅%/5 %XupgALK&w˻iy6R5 TL@ uf1aX¯u5tvMWôX4mU{J)ÏZq̯8mH&Z;0czs]0zl 'ٰ2s5i, ^cF rmPyVxhi&j37bQ5cD$k/oiIֱIs:\)KkbQ iT]:3V%?#[7/=}]~%Q|M=⟴)_^#LXq(T14SGH%]$mw0 \5zoz`v n щ椵EM%%y\y,0KL+a-/H]ް*ˆg#|K+j oi4dk>7@m3ed-iewǂt!#ْ\yMڍZ?5ׄ`M7,usǑ =AߘgԶ>ٜ,|2lYE_^]<' 08NrIKgZjcXs)aD?fԴSgi!~AS@sM.br6FO.~hP1TȚҒS8n^j4h_P$d| ~=EY-\/-;r]06scsGo_ U wpnetɜR @ ,9֟ܙRuF 9*8~ F#1 rJj͸zamBጂz©̰߾j< 1Guk* jPAg†q z߀ױt X(=~)x(5h^- (Z0x`Xl$BUQT;ݪcԁDۨ]0d'}!k4 M'|ge wY3]A8OFe%b P#փ%_f5e_f8Ol2T38܋E)Ht(heޣAI|[cxoB f@IE54y">RZ·- +rVzepI{*xtĔ);Lynyu.%VG*FOy= dXj31Qyl\$f,&꬈ ;xǚ_PBC#JPVGMajdowF D7ܶXB ?s{LrtMM;ӟ:w`[mA|$ -m36= <;8ɞEs\}C,^}0H.t&oݰG 8GR|@;'Ndw``~CUwz ݲ?Dg)pdOE?v-Y3I sHw1Df-% Qsx,ZBbGղ*l"A'Zd\hgnzOxtqV]boA[Icl;CA\[x WR$d}K؋'xhS {CaY :aS{ʼgN"qÇlT{6|'1o™Ns|@NNeAk,܏@Nz#Q4@]> Z@ԡܝ[ w%3ٻ=ƴj@MBB Rˑi<<^'^O}6(Dl( Nsx@)+?ՏqAz%źɎ58 `5lUO%Ɩ<-,a{Bun[mo3zyŨfpt cX{q 8ISY~[&ei&gϊ rׁ ΈSq@8{~re`f-.D84n~IYg~zqƶߔ?33xW/) Nx`"`מ[g}k 6^vPN+C/4T;*&^96oxfw/L)""0#k4ҽxxԯ U^h5K/5YSGk,cdY4Ro8g:%=T(@e-Es 3ާb0]s; "ؙ4:9Ef2HC)m|Tчnj\4ttN4rzF7oiÆK3vs+%PQZֈZVSg; >՘d1icɋ0T@][QumYۢ54t|ʯm1*#ޕ%ikb x.Fq2xgw?a+Hjէ @p,^CjO/fE| mjSyf)w軈C4`Mc<<>^P-:_ aNր'oc ?6㫫'?&G$~S pm#"SA\4t03]  dB> %(g@ p{Xh)%+;~;BX'_n5S-CSX,TgIaļƒBlQФJ#("p<ֲNBz1sU,-p_,$ G"<wR>5S90i}3 `>5d"`\Tp}+q.Ce뭁!:| ^;MbQ:#mIP8pHpcֶF.iG S]:m? q\L{"uƓ+&(>[ELZM! d k p(MQQ%_rfs7C&TN:o]>w,rH+xg4'(t@j3r- g L\iVPꆰ yjUz? *H17N0;|%۲f0rHX>JQ" ݸ9A><v/"vXisIcD&b{?ۮ[i#g*  925Nw$@aOxiRXFuκ5D?WP'v26ʼ,Uz-ؘ/~ /4zͩqoS/W~ԗTNmsr[ 3|TU,_aF0Q3A2\Ps#4U]|o\I.NТČq[OV^թB]n`M|:bzOr\Sr1hű){޵SGmw6'S(>cϠ`e nCΝg!v#l_1ѭL$JT͕W4\RoLE5ZS;#h8 p$6K)bt8{Yhxn4ܲRP,u rM}0=4WPCoGy{'K[ΖU=t?V1~[pD5qu3/O7`jƾXlDH!4.ẗBj/}EsVSzDՐ&.1i 6qvȼ4\v]&nD/%trihJ+Ol}9ezD "KΎYŒ 2G6h](8PY/N!ؖ|ɤyx TP6M5H!ti]Eq(=MCP#cJshȱgA#㼃dTT1G^ʼnu /5ǚsouc4i@ =Mh,}i3|v>{l(I`b!) } 9-?UNfF!Yu93vΐ{Jr{6D$W+sX C=y:RE Wn$#Lo~ũGŮ*1dP*L%Ʈ:e~!_Acz UHEBr^24PڝD8THcPaFQJ.3 aNVį `6ˋ2TP& wYJ5?6}\ӏ#peg6VR`CD%'$E&k @7jo+z F|.XM32kҰ^AzYâJJz N n-/Tzd C &f(SG"xO@o9&8f!.$ .{nzT;G ]2ř"f > *z{7F_ONQ?:Ut_~mD1kddg7HRaΙ[BT˩7mf*cg C}{a_cˍP{mgΝ w\~0;Rd+\&T9̳4q,> |>rׂ1+^|14[J/W\`}hLCF!Gkz|o'_w`Z" O-ΧЂ"ɸ=t5soI(c2p_Yɻ E :yk$`6h#Vu΅-FnI s܈_tBRO(H_ȾظkL5IݍWld\Dq|JaG},Vn:|ucXh ew]*VS?w!O|^Gbc6ԏ]R[&Ƨt2Ge/;bvA)ĈAn}eNvX Ǫېm// .MhzݺH |ˇ+*,0Ac5eY֧1p3g1X̫IefQ0s7nm-a8`Gysب!iASrIB⠯eLkĔYgr$<ýK.wiZ{bQ-s9*~D-elsK3\6KY3#n}^u$C"]4 F崯Árr/O~m=H"ѭGWU= I/$ROA_@3ʙ9*&ldQo7?}NB d>wds9h̲L=.w`A1? e 6`2^!$TDt,$K<`-άځWuV >>tjhyxRih:7ZJAe<uWd6Z R;q2LrYpVj#UHzXLOpXֵ|̚+Wd2]8ѻ?hUiqYB˜_lAJ7RR-Sd+A-#vjel]iK+LMLl衔D/ÃYzsӒA)!j"X΁[PW7*^jawew0EzVt}M[¦ ӷOξf w[Z"=+ģWc-)'?":qn ¥ZH%2؝ZlJ;V[ gdm4Ep ^{7h jtO/|x!ln.%s?ϥL[]'q@&[=y \L}~Z RYӍSId6Vc3nLs;sEaibXGXYKQ#E,2YR&iSŒYQ \+E|ʐ 5Jp >0#zG#oCF`]M6mڷB Kևd 拸Ɵ~և-:J,dqKՀ5~vp7FoaIVb;beo@^n}te Q }|=}PW']͒Q+%6ӄO2gRybzCT(O]\pM-qSQjXmKvɎx=QS ~^!Slڬy1 $R3&W -:2D".~$b}'C{)綳 +TCˊ<dxg쾍}e^sRFRi(uR͓K9,AAj`= _~)A S`McEb`hF7?ȉZw>~/~^kICtQJ MUA`&;Rm<+Y/wtQKC##­.iGZO`ru]F5%3HuaoєqjᗊU;N~Z `Q)cɯP7+.8 ysB"DCoAΈSZɃH~*+r.`cRM0탠Š]V#80lÄ^)+SzXALnnIH1wω h;Er+YnbU@Ɓd=<8|Ml~E?9)ކmYWM J%pEKOT jLj'Ez_(_R0'Aށj5-V ?4 +pI``j\Ѣkhb*43ƽU-@(d\juц[R~8klQdžKRWv䂏zbFyʦޭ(z䁵h,x"#jY:;9y-~ U4gVb$>u.c>Ps\?/jX, R x4%t.e@@i:|lz(֛o,XR)Rh [ZwIB CO4)kT G |wKz)Mo0EaR-Q-%gH2a";zZ&8Mnav:`:h ŲĿR;/QP}LO*;]B>ttðW/5uqEVLʫAԋÐz˲5  y}oCo0sљSm@EUz-;7učZp'/V@, ?MѩŅ3/N  C Y-X k\oSZL擠=(BHÉ%xDd,hi Dz/%00#U2 | }K~ 6QA^Z[g{kw3KkRpqP5&B|lZZq))Yܪk\ c")j":z1w#3a !Jaqb£F`UbAڂ/X9> 08&r*L]Z&&R;Pa-q3eF>m6! eVuŌ8Dv7T`5r,ͰƎhn_gK~{1D!W(leю#V#<%C].*B/3YjOmPw,CSv(J&tZE|d 6m}/pکܾr:UQ+QOY0?} + (bG!vEXuT0KDX40R.'vV ]|{Ҧ= MY P JU}+ϑSSH|0aa1Nw͑1tuV#N"/"SɾrVs2aI 霭 0eKפ/2G:ֽ;T?&D-KY-ЖKPk'e@ :yEٶ4k~w=lP!7a\q1,k_}7VfveD ٩g~9Ff0PS&%kIcDU$Yy>eӼ#;#,esrݟARH%u0jru|%!O}Tg|#_&*29A2ܸ`ըsc1FVLFi?iu<ԈPvԾ?#hP2>SUC@ђ1 ̴^e%[9cG_k YDxDb;UB K>RMEvddqO^ZD'l.jQ[&dC?Mi ?bE(fՕL<鬠vԙKf *}" 6Vh ϤHq=";$r}гE:uUXQ{;ژjJ1B⡎0{غ}”4*Yᰱn#` 5+7b?Ҽ֭87;U֘ *c/?ܬ/{ǂ O鴑xĈiGk|=zA6.{Szλ.$١k嬝}0zςdbǎC:hr~v*`ߔjKף+p[w6tƇs1XVk:%X)7C-=Ѻ4عW&>lqr?X9s)9bNaRN#ymr#O}n6""L׆dϚ.GR ϝ$w0<#Ol MpdUN[܊=g_M¢lg[[Do g- 84T7W")m{v֌/Vh>>:CPǩSڭ@O_m-@%< R9d3:`nTx8ͯǐrƅBaK֛0/bCeDv˫l :hВԈl"IdjMV]s߱Gn/1BetnWE)5"u[m|;ƪ(塨OXxn9MpDlh+rkMRΏ֋p3Z5kp qCtrD?)Z8 w~g)U褡YLtX=}on*q#k Elj׳}_QH6mg#!dQ^:jk&w*N^*}{+%%dw4(f6oؽd`fx}BX\ 3C8 mo0'0z kjoN34!4!҃- DT:|~3g6U[oa-t$R'm E^KRn[.ںOK5ܺg|^ƒ "0Զ/d,4 p-oo-(>P<ӕ4=&ϔmFq[Y*"g"þC6 񥺐xK-&eԃ0]¦e# IcNeRw& q zC%Ilu_n6AI;Wb|dFv6TĶ62hMꉗSoۺ%A'B] 4 IЅ.ߒ/PP Q栃*K& 7Cenpx) -( E ly39JU\<*|qd;3q Z#vel؛F=oS $zVZ" hrߵ|q.׊P  ʅE!fg^jn=ʶj},=at8@_͛3l-XbKٶYÍ*@}Uokn([pP(Eyy{62&B2T~`CC4sBshX@/ZP"@mVN9%c:/n3Wt?Emɋvv!hǁK#itj'Q!vxt2hB̊k()p j!(6UD̻glFh[S[㛝K9Iիܠ]k̏vT]s1 >o4=05\cTj|+d˹Y>jR(5p pZgΔpB2d@FC>̪/zfA6LB+ W6Va T&,3>|̄ Vw#T"+¤y7?lp(ڣ.dBc3ExX6‘Q' mVTp큷0*ݽQп>f+} I|ib1laK՞E=\+쒋&~h2 X2}Ϛ8o$RLʹUey;V /R J&1l@1ZOAFÕi^Uw3M| z E5Tz p\+Zw rգ 74ek+-Ɗ.bSzrMi恟t4Q:|.Z\Vh Pc:҉B&T3uC;aZ(6-"d^$^@̒ܤ.5SL,U~äwë@*".% ufD8|93_%}&>?WdFCb5~ _B)ۆtuJ7e|q^,kpDbP͝)ԭ yz9PK;__dخ{ƃAZKdq !{JZE%#$/[O\W&Y51Zi_ߺ9k0p;r͟f&q.C69TL o7O]CN'薬 )+9*Gáԭ+䰧hDܘ0w2ѽ?A0ژW[^^8s)+#G%;sw=ۀtx;pG$2y]I1uv/Pɐ!|l(Z׀ ,n_(1U5 Mg  VL]|CX,5Q&3<<;Ƹ7¿oZJr1O0ORge}aqDd_ ( #7˒,!!jDAӇDv7k~n]t<І!3rD%5PU񄌪CSy f| B!G Dj?&)T$PHFFK&8~etc&NWIp1STagJm0nKrl3"ԈȧhJrMQӑH ;j{K|;K:Ԍ šbE"mj />{֭‚&4Sǜ4#bP\/D3W, ւnMObCvl\w&lQ;˺5r lnaD6rHNsr"#PiDLQCRT+P?KϴS  HR.{ءYw bF)Q/T͟EiϿ P=;[ydB@ptzb3] *(#n V _wRۊpd,\ϙLD ZubXJZ8B؞$'uS{l,]ޗ\zΰxD[$k:r _6bLpxS R`1BvwʼLҧ$A%ڜ!qO>"JL%&o['s|u*'sK%ӋRFpq ޹&iTkCmy_ܧ @LuPdu.W$SRCW!"bt~]Yȏ2w4JI*6arqb#54+Z~O3uѸ׉f^>#4[U0+-0G ƈDxO*:`mxSSdw{1W:aɯp+P£>[mcIؾJnb$gn6=|3}O իɃawȎ VXI0hx-Braؗb4X> =!:-`@Zd-4~s< 8,ČˎZr8Q2=#l$1VL>nS3X{vTGx-ɊL˿%ar|̥Jck5Z@F I jsC_AqEp-d$-WbPg,Yj`?^ >BA<]fPMdw 9Kh;8I1Rρ@ڋt3ejU|uy̖b]dq5sBj2P#s;o?)d]K30R0:Zj6FrW:cIM) {,-8G!ByPp6N/kE0 wk ngvo?_OO"q subq j=G8xסY:QK}Øl,fHY]bZq`uRCR5 WJ|ք1"8&_^LU=NưAR:/w8Dh|TW( p:РE}VḾcY /v,!7Y΃/RX3![g*]ZloƸS-ȇS-{>rO0UΊ=3sCvޯésģmx*aDV =q mjX@-HgXinS5v:T֟_#=rRG&ZB.o򋅕i-j>qx$osVlM.wAXy00`#6D;ε䣝)";TL@_cy (²9 8,jQ{{yuIgAiN=-^“5xW+:J/XlćN$-4!f\WakiSI {©B]y'uҾċY|DV ^@ɑahXǔc)]@ '6;v̖g!W)G(itTqVв0LJp@F~\t۶B/vl$m*[{yZgb+̍:3 c%ΰ. xNƆ\D4 5@CAk D^@i ٫-4y/U;1)&vv e-W耤kwҡ3: bcZ91PD% f|S8ש]c-D֏[I*3^<^Ǧ,j NJ9n ɱ}Y`zyX(V381 Z zh֋h̜#@ qX4lcz.H\Bz;# ZV4&OE@Lu4ۊtwlzvsiܧKb C-^%q0UkM"{3MS=3 {䩼 ƑB"֏ qαl]Xlԃd_Fͤ6ɴHӝ  0Faz.~4kXrgd0sHIsv`P$HeA #BQ=P:S>s=dicy;Jr;-'Z'UAqvrQ&Yk2VKj_ Կig_W!Y&tYS<=o _߉E3 abZ~VUWѸn%| xcnImWxU]M `5 /){[SSÅ~S+v>LM+[+ܼINdpA9zƲ!8`n{D: ig0ۭZT71eDzS^\윍Cxz^Ñ$tԈ T`91Ȯ\evjӽ*2 22ƅ .\w"gO!|_V~3xm 딹o.HEpqk5KYGȮŸQehė8]YJp!^qs4B0la"P $8.!ަhx85C~'[.p< = ڦIah9 l/^Wzġ̑"})!k1Y.6$1 pw\Ⱕ<ʿ6)/ZlDrikWO`>/spowMg4V|:A>@OݎaL5B7g fpni©5Ke+^\R %-oCZЊg_5y[5\8"LEdO?U[Q" 1<^Ai C!TFHʷl=4H= T <| {dw9hxa`DUY'TAc,,/]X(JN03aÙ~vr.YO2'M/w*&Sap<ێ_@}Ρ%hW6[wd+ӉII<͕a-R8j\ FnFzjCmHZh^<ȣY⒳pe.%S%ˡ?(&!Q"6E_*QkZ@s9f*x"b>@P>|xiT8␐ogQF[oO,.*`' Uuf@8Mk\S`f;X.d Q3iAf[ (4Kyg=6\7}V^ɾOB6Լͪ$[ڧ+h9f9u`a9l`8T9"񬇠R-8׍dO0C42*H8Ͼ"فq]%s="E @?㛺?PFPrZB1C>62( d߲ne3+ŏxVSe豱"ƹ#OXh͑PD'vf7}Kmtn[iw+s14?}J:zk:8b9;MiY"GmtrhGmJM+ub*#؋p$B^'mY&̃&ڒC'x$BPuW r*dK9GlyX)F/: f>9`/I{ D^6["u;o#x.ZV]bz:ǓLJ㉳ ֬AW]!;dD T\~ʅ? \s[f=OSZ|(WP]qiu> KL[G02IJc+7D :P[u={S]nݘ4fnoT'|8HOZV+? ^@o[p;f]J:h˖sm#GR#'*Q@Xt=Y Xǔu=ka5Y!W3:hg/-MB'zd{y\Wkl -看J…fcW`mjN i`%ÁDb&L2ӂE \~je oIIm6;@ﭢks9 HC W_Ɣ$ N=;ܬ௏j"A]7po0yజlطө:k|EY5rrڱOZTv~jްծzxNg-jjQ"]`~ VY<`A惣2X"x{l$|?@?#K.rMew@[qaj{%3qV%9ߪqj Cgv'2ݧNBtpU;ɯXyl*֥Hiwo218*~ooLgJyI!7WF]wk8`U˭N0H^!( 8}E+wJX˾8d –q頥ͨҴ.f8+)U1Tlj$%57AD;d!XPMH+.=]{\\ Tzm"xsUrO~lACclOӅJڶH%YiP;o7BrxjIO~kS9v& M/rDb7e32cAy1oZ{Gq1腸 }zJ֖ *hICk8%p@ &'%3^N Ɖ݁(}Bq)0LWX%3a+05jCp"UeI?;ī~"BjKnN+MzBէ__ M?70N+E%*xWR6ًygiUZzW\>Ƌr@#C X7fmK!)vM0w^[vrij4kF|8QOz33;F+-/oDٓÚB eZco=g@aeT Fb0IPC>o%D<.(VGQe&^%&4\$ NgĖA9zKT.l'uT |"~Bj&UaB&]@I;ރ6l&c· B (wzvX:vT5Q0ϲi#~%H0h`Ό2 'e'v˓uFtanrpX,>K?qYB)NQwvޞB:s{v}!4Ȯ&"ޞ$^ c{Pa?*nPOpfEjii'j=e~Xѷ$v9R;i\OLV3Un~V kjԶA`kxRҫj{!> v EgdIKNp9)+Y>FVc:kzi Ks~wl\ZZCxYu'82 WFYyinb.j9ؒIiНˏΉ*zd7[叾M j a ZuEhM&&d9og3 }`wmg+k6(BJh7!ҞZj<N&o:g}pWHyFBXqMr~YJ{"0/3y/ܻ5.r#EP\YQّS1L3:}T )jDʀK['Y  0f~^lLv;SKL7_G5 @ Aсr)}D؆,\qa,ӎm=`ms޸]6h>ᢈ|S=6ӫc [otE . {z1YqO4aQyP1jP̨&Fk@}DAIcb*&˽.MR2R88L䶖f3:󥾺cM6g$T( \#Z56bb "~.t8UYLzΗYQ`[\BUg 2IuLz7[R]/׏;= :)ƿLl.K2O!6f3w]]cFԹ;h"^"?olB++$.yjvў(Ҧ429wi7q\YFO^H5Yん,XUU-! ,,ĭ6 q`W\xBGT֗޶({-CVձhUĀ2oV qmgGg1JEɴObZFqxxA8И{޴;k6憰(:"wPA9\vwyj|\!"`eP bxĈ͒7 k\ v4l~4yqjUaJH҇ j,9'wU1O:\1g }p)De@<0M:37ݥzjS StcS",3+{|bE12v4uR7LJS~ qwrLi)X,Lb{2'ȢP"}h~@ڦb]=_g"Hp){x|W,/.H=SWfV$̂Amqms [uۀ傹:=tXa2 R VxnfB̵cWl rd r)( wGA\+̍^cMO"ƭ ouqnв2[/DemY` ` $DuaDm&k ^0#;G:id8yh߰ 3BJ -wĦR^z|h9BҴn`!ű5i &`?KRuc`.~Gܜ G1n קpQ`~<=Xdec148 v X`혉5k_Dd^utc; ,ʴvO/kp>wC'2z 6 ߬;V)"p~TƷ/vՄ|+;Zji$qH0 bXطpDO$Nʒ16IS"0(.D s%8Qb #'V66e`8êϲl"?-H2T ێfWC0MFvÐHc^IQp?q=)û\w\/D.R Þ{W^=X~ɶT g[V ջ'(xXhk?(Y-_x/tA,}}}@2dQu5뿌4B>X`O,i=փ_ھ8x?aVx kvc La ^^-ciy7Ȳ~TwXx! ]n{Ρ &E _ʌx??̔*6t@sVTmEpEdM*K5f ^7x)RQI{&R2ԑ۲kgo- -B+ BPC~"kw 3~mȐS8!IĪ ɥsZ!FtQ,qÜ:O]޸q%yvU eq~~u /Ǖ٘B4Fbxo6~~o PWڀyjobd*] On۳/w< os[V:3S6=4?L` } ]M4,iqJ2,_"e4^Ym6EKb]ѐ2sNE*$3ۈ4ERRZ~O3נ䚋C6COv#z2/V:.L  ,(֧K}*<~ME` xBi V[71owt_U Ёe],tzdZө/W6^m( &1 TӱE9yiѾR>ӗyMw귽%9Nl7t 1#WK&Oуit,Az:͸d'ypwV[z98׃ ԛo&Q ZVW_pu.3J\Ku+[;}/)g* ˻)΅ՑJrA]{rJuD2m=o) E^o;5qzImO=P=0[ 8g ߉<6"`8<;,fHYѢdp 6~AB7x*jh}aմN/Z,N2p]jUK =d25HuYh.klIk$'uh d J NQ Q\ڦS}jRskxY IJk1B<yAp pE\օ`]g{te6)Ƒ *tJҴd<5݉ Q}"rG'Qq/#L[as*/؅XQ{kg0j/5$zj-vfS9W_e'WJ%JIv~=6aXVao&&BїHGmpeyGmspQ֏D`M^uݕGwI_V5՘ʈ{8ƞuÿ#K\@k,p`ڹ`~<8?$t-%ΗprhTNWy&^tvyOlȭT1Wcv-Clj/uhC{fEcWwkG)M_+% ֥ζ9 O8g] 3?lj+~D9prD/NzJ~FL7w|۠H S1!vI"\ro p(B{4[M:MO.6˾ExfgfpX7ȟܩ}}AհGW zR|ՙ ߜ6rK>v8G-_lj]5=HJ} F%3A󿞓V$\^'8nҧv2i+–o=fS/݊jEFSn2J~nDŽHPc!io=2Gv{kj`KB?CƉeWbYyIF*{,C=;|lTdͳH2ƙw@L׫LDQ qU!y=^󥉒 6f-40ʤO;pywiDJ0\%9wkC=jh(7UHV0{ z뒴ެ>f *IQUɃbR'W12Lif׋o@R6AB?x zb3 ]F8WqOJS} V_smQXk앏zHC9OœTѴ\9#]xۓs?S#̫zZB+k5"LN2 ieѬm7 ` "]ŤIԭ1vtdP4r'tNyVQQ=v8VļZ'vٱOqn )?;6Y`uwL ZEpԥx7,,Uq7MSC1:k!i.8Yhd2iV{Ak1Ar0 nV7pl)$?Y=Yc)Jӛqs ;U.kYBp>j(2x}({izs[ &?e͖B>opVE#R2N>jC^alY/ >b{dQO- |\(.ʄ\h`C\"IwJe>])VޖE2'ǡ0>PZ\#Kϸ]-3 xLsXX& Q~} OUޟCVa3 +s=f=x.$-(},iH 8/fx gXp8\uv(Oy8SBuY|cq>ptFfU>k}27 Jg  ګpkȯc\r? F#`(*dWkl# BHv ׎܊r쾑[[V؄T>GBz`&P{ҥ}Vه\>nZ2~t}lm=/@`zc 4LgLeQv yH2/\w%'t_>(ZwP<(]A,&3`߉=$L-J9W͆XiS XƤ$26F[L' ׀$%v.q1;kL:Aa!׀jFj Lj ?HMv`W9ԧafk3er䅰Jf){J轿@!V[RjQ)9?9ݢPka=Yyp sގebαь!6o4\yn}5|1 sy </vT:Y7?/C![6or$7Ÿ?Ph8%^ToBU#-ΐ=cbAgڴX4ٴF{}PH\6 I$q|!L^Jm"4Ms-! ֋?CxEvxlfЦ #$Ad8OèT98=rAi+fވ7k"c)A{q/]puL _dc}faɦ"ᦷ'h&؁Wsl^-LS@CvuR"{3=#1ṫ޽$;kDC0GXWƺIDEZ=83ـ>az4;(eܔp0:(f;2JXmpr$IcRdZbmPBP(DSbA$SjXQ<鉹k@TR$ߌXz; lbpG]ݫ|*V1"|N%g`$=KB Գ<(R&CT`V5u|O20NL*hƲ4kQ`֜]  .!DҪ9zzqX ܏d'x M6&r#=UuV$royq);ūy+QInR[18wja{w YFsh RKg0 1Ō9uL=2$AzK(T59(K3j+BMP\JܭԶ R+)ƈco+6#(B;j%Y6: ڇ8!.S킢Jo _p`A>KcWHtl>,\'>3? /ߑۂJˉadK\Mgk쓶}ZW}o#~Yj%PI!mq9h=pcP3n!W2YNZGA'L(cH*KS[/HMԨ.36&)E ?q<+g}7 `4PQb刓Nӯc͟l%rW֙TN@?#$AÓen;~BfO۳E,=f^; /1㕺&kFׅNA.=U9c>L%i-]܅0{2h/: h1pk_ F?n+C{ƣ|]>.*/޶6P]i-Jd]?$P4Ђ͖n'3Fp(rH_AՄvݩkB; JiP1sq*鰕GK˽ɔLsx<Q5"@KH:+&j&J-BeF҆yZ8nïGZ_\39:#Ըڇ1B׶ 0 NQ$J鴼 ?`ޡMidOe%# 6mXw*R'Lq%Z^,S+@]FPC%ФViY(zH*f#F  CuNhR贷ۆX!Z]b\n mt}DӔ)xI8ڈ)wiVt6vDORv2Q6.,ԝz+-bTi KRk\evT;lc o /9icTGf ពUW']n~ tdOO #ޟ?D}jxųZnJ.$oyOy XggVe#İ@]DW@"_-KP]=iJj|),0.cgGKe$?XAšLӍ=egfy>`;ݣMYp#}<"K`ȅLAgWxQ$9a|r}N#&K a<#F#S5^JkkgQD`Yu"N}7&+zr֡%`F~QQi)`J#I=kSzϞ6VWB`iףBodF?P/ j+0qhZ ֝ˈ}N;&em$p_qJhȢV s }Kο5MI=Hs/dB*L)*GM4W޴_.Ty|χee7=rDOY_/0ȦƚVJo(9Ǣ&/HEu/"tg$:I j~vlAwrw3 \?@|rw9QL 1C'H2Z&(q}F;oལpeZ nT5P] c8 EҴA9 Na#M\,ʥʨk/>2ˬ *o'2<CKS /w [`+o%tq Nn qK"oS_c3ҿ|Jfv$"f<,\jNcD!N+ׂ?KQNd]CU:X!&Bd=eI2l d V Sf%*ZLNyCYmJuLʾᣒlRSto:,&v$O~SulNʣVRd:tqܓ^$S\-K"uGE Pl),DsD%M#y9G3zy1kĿ^ՒI1j'+oxDznK/*XecWSꥨmu릶 f,1= JQbŪ57shoĥ$M|=>84ېhN~Ш^e)l$s, w*aGhг!o~?#13F(zjj (wcYkB-(f*\mʋc9Ob;`qu]q)w&鵯3$W M*B^K+͸`[{5k3\q͈Uۣ''tU}FqN:ҎjxRgS)p*j{Pǻ@ݷON0 37K$֙ =3m24FY x#{PąmB[r9 _&)V}!گb+׼ >=; e$qgg fzMP\4R+^ Y}}8X-տ{Xټ߾nIS`}2;ڳgsXk g?I ~޳ n6oȌ>PaJp7,/c,HA)89w{jԌ u0U3x/\ dgX8&2}̝g,Zynw4DL4۳rقڀZz-Hx}J5상[;QEʹ; ǕOĜ3OaFT_fG3UzM%o :ȉ{hthQ2ZxJv-HŏH‹ '/"E M:Vs ־ڱ,[,k Qv.b ش]l?7@?9%x[Y{|jp4nhRVnۏ@p1 Dc/] @f]-MmQ[/"פi}7-l7{|74xcv#'M`Na^&a/>1:c cC|%P\IbFpAiSN߀2C]+ԧjI&A&.'J$ePT7^'9]ym{,IQDE >$g~r@UzBPT#xÏ/צKL_n?8b6q Dxƞ\ʥdVw(Յ-Aŕ@|rom95[ $]5Q6\3BZ$h MYQؤ e4JqVDft~[،PZ7lV0:rߨLD1=#5“-ۯɟqӬ/#܂=39;Sq.u XxE|u[0eI0n>,jp [` 2waFDێ:mouu]LsvT˚-/G@^JKy}&xYMm3p]0VHncVѽiA7 tp5Á [FcnBƍM7 1OK^h D#eK? d\T흅rpJ-zVv]MJlՐjL|vu ]Y(%Y@?^R##Te VL4i$7d8lp /GJ$igg{KC5qf`ÃBns*wS UōV]nE>zտ5 ,7À]] OYkBE+XCde]&*xbO eʵFv.inY*x9>LDx#&,ƍDcY>gk1!xY]d" &-|4p6p '#H4 \L9 )>4a 04F邅Ο}{>o~iuB့R^î0l#{b,N~QERȉt-vtoCT-*,nGlm3B9,a8}KdNK_1ֈi%%:l,EP,TgF08 ST{ᧇ`ܰT&v813֑žr/[*#OCu2/1H1fP0VTy*0 Xl@w u A )K28׭3/aD1X8 YCz{MG(7-Emʹ͏j(ЎFQy)T.78-& Z+X7Ɨу5*d#K`m7/g7&'y%:Ji&nƪ=?]_(OѼl!@4!xH vչ['eoZ\j*#a5.[ 2/9%A-82aOD#61NpL07 x~[U*6rCj1_pG@SU`mێe}pIc' uq⬞[>&mnzoC酯&xqrfz6e1eؙuE|ňK9Z& ql8S?#mD1gCep ؅KW+ⰉDfN?óBͩimG`k7zvb6w` W=“lny"49K]L?&cHMbXj+MάNG.Y;!g[]9 _7Y*3@KB6 Q۔GjC_ܺ<Dz7oy_rO\io`}mUh q0UTs]!C:V~Ԥ92+V\'&Q[g6]I~БSnG K` HYgh ZܜxkgRS\gvc~#TLp5v)ʴWcyQD <Op/Uc{j n2V#N铉OlA׷>nb ű>ϰ6Z(k&ԫf:vtpr˄$ŏ`̃?ܦ3r T\C/\-h+4IZrCcւJ!A4_OH|MM~a17MDs((7;6P|=&-ޡ9Ѫc4+e{Duܫ7KA@jc"Dj=WVvcdCB̥1U3pVKu=ILX\E,-(4 †vPnș}ycuVb @>5' AQGeE}_;GA.+n^ c7Sh~ ԃ"@uA>R"$;|:ƹJ@xcAXA^ 2Bxp)ur4MّNj~X#O^. NBu++'ӄɼd"5& _ٟ"&ẗ́bQgꥬXؖb t 7r"40t7˾ cvL0$4Egc[z8UM ^tnx.™=\91uxAVd{xkZa+i.).wC{xPiL]akF.;{vNwxh$=P%<#fijCB6P2"\(Ŝ!ϡqjuE<" jI865mLpU"ڏpyd3*IN֚g"{!T[ǟ3ݣy-䡦wTdN# cI ~A7*^pT'[0xXt&JCI#O`Xi>%Ebl2 I2/BӒ6 |zmjGZc|Hjrg(]\)d_S?rsIm MTG管wCۙzq,hݐW5<5݄'o-cmB=]4vӘ43p8}CF;!. CLGoM9_7ЁJ駩إr:|+%Fەjؙcw{)3 o11#%\$]r)0ddI;|^!5~uN#Zں'8iΊ!&-{|ұsI.o8ppj)'JPN %:X헎6ٞ!5pN;%şR K l )\LZp#m1%VgbMVikڨ=bUE%{fcaUhr3IwgRN{`p߱R\e.F.Wrؼ1n"= hq:]ILi6o,]EZ~ e[ޢJr!V(\M5WӮa?{Exڡ5?rovTx(L;smgNIlNčOTB xURI9fQI鷃nb`2wk&QZya(vt_x4Ox0A/Ѫ.@Kci1*.`6snQWHE yKu]r(19[v(6Lv',ϕt` 0䒞*Y+Ӕe; ^DƢ+p4$&R܏6Dʈ|+U!iv[x 7gNE}nMV=_M+ayʗ D,j2Xd$,T(6ֺTvP}('N} ϗHek݅ڼkY A{~j7-*Ɗrh`h\FKLWxB@R>lm )2Y }`KXKJeg.V2Ǐs l-F:phij^D\ڇ7ȥ0Ě<|?6ঢ়RCs*`fٗ%Pq`;HU6\a[ a8Z߷WiJx60lWG󵬮-uONB.q1?3@$_|M<6f4+رC({]67p żНxcFg +dJx3`Sm |u(h.p~9Zsg?ֱܴ3iwӌO`-58Ja8Uz]<7E8Pe#ҳ#p;81s|=s|[:HE:Y Fھʆ՟LSCS%TEWb5U=?UoC;:;L#{۔3ET`^ʪVDМ5R^s#nRCL4U7ًoQQ= V 8 ΰ)MҘo\Y ˴vd6F}&yzZ !Ga׮"V;z⪢ A LGR@a jƝe˿.P5+X~;.aI"$5[/Sŏûd#C ~,4ϸ\02l*P~wɄ:<}=7%Btz3"EՎ:aOetYɱhAR8%\(/Vy@954#U[F8;<ŌM,VMZOOsi,a-w1 uto- OX޲ dF:F_2;Sm?i&<*u#)+׈ ?T€imgt*Dsdwﻳ\C͈ۖ_iK5?Рs?[Ջ]VsT {/e/%;emq񒶗7ޜ4٘qQ?wIB[q}rbd̬axBoh%EbQY"$(!9"8ASÌTb|1v%cR.VߦQzȲRKxόkn7SP9\v ]Q*w?hB.Uwӓ8`GksBZ?4[t1j>j =^o*of v6z[Wti~}kA?E63@#<dns}usP1"3i,<8jz vD^{0lCa^]gͣѾ_-3zAREYTx5)ʥH,"{\)Nõ?kƷN/B؊O_=5٥@C`ɋQl1,jZ8cWɀ`#s{rpm2QWy5E˚ǐz`h7s>yG)_"8Na')lj<rWH)A.o{琌 33yx*}O)(Ǝy®b ,;-!wz^!N6 aU"J A"򚿁XQ\,<04z;}w,Lhb,;\p,EKxBc\ nŷ(cH 9f29+J(52)B8~:ҌզF_t?"!P[M "x++F13 D=³w*E;$ #-ZQ]i>R[Y2tҙ^Zj'$rH%1{@i: .Y&[ GSN>tD?V}S"RG'T*@*-!@6>u|tv+tpſ6ΧJmR渆xj,F^=2/4Mu~$ӓۈ޻|^_D(PSn|jOrU9{wtewZ@6(3损D*5._t| +خ gZE\Rem9DNTxhW$gWƪJ8q_7EskVcg~ Vh3uR҂rQ0(U`U|JYZ@rhmXO Ȼߓw"J:_R`؉\B *xPHv(2;V Z0pťVWI }meH$`P8]:yۍ5k9޾rϢx #$w΅ޜWz)FkNbV%%XW'ae\uxކsn1lsIl@jN NWt#.E6զ]Τ펚K^N]#nzP( g|"gqBrdMb|9FruAKhw<\j/D'##_C}۹}?5+$c#dmDâڠ%ff0GuwEMMK=;ē{:+03"\|)L8 ʊ9:n!(P >i&Lq,>z tL\/Tp\#1((f 7Um t i֤m2sNDOsv2 ʲ(atD:8N$V6#R0ʪEaqb&`ce坍vzYtH_%lJb~̋Ө$PyNc3-NZVF8p'b hBQ@]壭hڼށ/66cxg d0׸|gj%g?k0{ @o cE Z{f$|̖zlr;cm^@`b:3f+WJ. Ik8l깶sc .ć͜B,82瀛d*pu/rnݯ1 R< gA^L<&(GfetYZ{(4R6^?k Z`pX(LFŠljU6_]vl*b[1pF]lܙWn?VڠgW ʐV:a oU-7s=XxɊV*5$Me}IJAfԨ|R;P,g'/GE 5}BD+ֿh07_ǚ*tc_Hd&Pwʲv_ \sVCN'i_^rWZ5.5TYvwށ= &)wF/Sk1::1CrxCDFfcd'Oh[A,wW"t ZM\ `"o7PiBX $BMw"1,_HGG;G"\IhƊu. _ϝxz0.s='ʹa5-u#$, zPĒk&}ɒc ^lO/NYM}H|r^aFF\HD}3m.@b&XZѨc10UVe{*Fa.mˈ.?;- j@NzzT(HXѯriOJ2sT"/XײbYԷm2q|[ލũ>`k4_:kd+DC%XqFվlSgNfUosߌY5zdڙr$c2ok}]GqVu}%ÞBrH3 Q*`6ǞL(Tʷ.߱g”_Cˋ识M;@v{Hwg-;2铂$mmlbot"89]L5/olNU!O햙B]8=ٶyo8ef1wd.On6a5j97 da\EWQ5 y^Xݑ%Y$.a_qЕ<'U9ڏl(܏} Bx iՏ;;zv}xiٹq-Pmc:02ۇ 8{bSQ-eAޭ!o!A<,3Iv"U=U.LW5e;14·4Vfb ݑD)!N(#8 CΏ ;m-6ɀP*Gu= e5MDT/ϟTA;葜$_ /O6s2<Aʙ nD?W<|[1sJYDo  l3jU Tt~IﺹȀ> >㉄?Hwg`) e>=D 4_b=#wC3ġq-y{ @XkxA~% ;ږlb4X5< Jfw{ ߫ueEͣ&=GkFA_浏N<%//>_L6fJ]21 Bn~p"u 7"rOE{Ay 4W-zֹ[!8ND a`D.iBjH~4"SۋzGS’!򌛴]QtC\nຬ6ؽidC߿͓Ρdzj#<:+Ԁ@Q൲Z?Eϗ+S R Ejf"1vhy KoF"(./`x=Y1VqKl/[Nscy=ֹ3)"nkD OcYu0QtfsHSiޚGEohpTqVUp.< F~mHn9f䶀37]ekCU,*]@ޛKP#kl*7&NI.ʴ>ps!k cp b #&)z<a9'iۤLU1KA0KbCxPkijn!޹g VT֠L&aR_i)WۯRVX(SCTt, ŝ-l%=t<+0?T@+B[=| R /zM^@|1+qǦAE8y+Bi]p)<r^O@ -S1&¾Y Y$Ffce@Voj8{ƻd0'gZ k!AE*A\H2Tg[ }”d-k-<%fmh-Һ{nX/!q4]ϊY@Cnۜ <0t^ ږTTJ+7a ^MJ!D2+~C;͉xRT+R4t6<mf#`*Is,64uFc THD&QI޵xdA%H$n8kKdlWGʩ)< %.f[AR)Ǣ:uFK7`m\M|s\OH75S<0|:݋*uPb,zD &ԭql&7 \(KQjo{K{KMtESv2xT!}kHlV5 ڶcs?_֒ Ec0K7"la'!o&Pb0BK^O]\:[U^}#kD]LBz޿zs~RKĀ%C>f*@{L,GYPRr& 3ڧ[Ufbhh\\ _"s*7?1qzT/'{zL4E0=(rQaK[a AMpݖSO?LɃ ɱGh­HGlZ"HjZ'Az*SkBRkE 2ԷÙV lBCsLGd_l[|IFdx]2?*;}ynݐb_.:eH5q䴀ڑ9zTҁ+7|*X(? WMŮ !vas&sa=9h] Ek{D$:Z׊7ܸR`,EStRXMqxM G ]Rj!$)6=*Lf{UPJkZh(уEF-ѦW R0p~OHnԢO[2t.w z=wl.Ь0IT٥Q۰ Ro|xn.{}%QFYbb[X13p6qӞc?ʍ*Ȱ+dvXY9Sh9}\E(<.9Izz{ M% Q\:ZjOTBԭMH; gwvB5cof{N_iQ ʹcCqMv}SjPm^taKaE2lFu]k+G_O㥦>_ѻ>"ffڂ0@?E°^S u2!C6wN[P_t{/qAr琉xw?5#da5y,$#O 31;? 'T6)Mbsg뜳&& :#loIFdi)+@| =7s|lƖܔ[%~bӑי( )T(BǯeuU %ݒ:FCDsa-EJzGO&PI k$Aé-–qz=- =s w_6g!*)bj= 6,Z<7ȵ"P6D*cR>'<"?%~9WH/jTB+=GNd[і\ceI]F8~J>Vh#co3c_V3S]bZ@&o_QK {]NwtMG`{C[nyDUĞ9tR/4{p-rU 8GUmC7|SlS(|b,},*!'DMS\q; ]+OUGCkg~Rj턏lr;C+~9kj$48EW\7kag?`taHoYقul*\dLd5LCbG0! J<&7.U`?g:)5 tY) 7ȯ (33m/h.BAQky $FqaZU!Nڙ6i͛1l'VyyDہʻڰ;v2zTSJ{ホDb=Pb >D[77r -\CE,KjUh$IZ to(Oѵ9&mN+ OH;In͏JzHCe"SaLPhTv1ځ6\sչ=؃}ֶǾY/4% RNːƵ G}ɐ;%ed q}q2$ *0rtFo:Wd*v*w`Ƒ3ihn/t x/)*J p-Jv.l3 YD耖.ٿ8H)uku$i9Y%@ vL~a2cԒ,N\[p\y:SOGoZݛh6e(?'tDo: U<&>:+eF5Fm_K83YM5ҫۗ؝AضI` ٴ:e+AIN$ڏ u #RKokEUi>)67'g;cƬ8f#t.蕪m'MǾ+8q3>WtNLeTj\ Cn2jijD@yՇj,L5^8 y ͇)J'N_6dJ 퓄B_}n%0}M/"j Q*`1h2͕Cc3w5V;۱ Aj|H0; bxѦQҿa&Hi?R O/IVB @&5Ĝ]`- +2DGRpx}H9 ƣ&^G_T]Dp51 m-9 /Qo "S'ms9]eQXB&\2 a+ MR3YĒS6WΗ8`[hݯ1:y"v'4`"\<,Fhq*q{Q_1MΉtO B 6/ciTeZBpas?aD] #_+3ԉ]iЫeK;[3Jet(%]HBq1ύt&/^77Ԯgcߝ'iJn J\"s!ߍ.,Nɯ|sdl@{Sntqsg 58IfҏVn<n·* ϯIra_ac/.G'&VkqspF{CRㆀ[%heyaJuew#=&>*=>~$'G%ʳ|5[9_:4j0bb$;&;ߴIia{緖;t_~[~+s_,h%1H&>/rP8[ $q?EY#XrJAIZ%Qj-dSM ßNpNHB/ }j3w{v"`|MG($շ@a/nC,D- iҳ]ac›"34ck;'K,P6ԤABIGkW}!BccUUOWb"1 tdu| $_25sf iK}3qҎL)`CpLyqjy:H+L?b7c'zJE<_;hzR2jP_RUܪ8wzpL<"T2BՎ|ӱ?}E3y PfV[c n Xb GLjV ĊT~_+x2o&)nplv`֥dIIswo㔴Tàx֕8@t)Կ7(!xy9ȸ[BTkG/3VAd ^tKlw!S\qrc GlΐH6*Z|m|/N5=G Ir9ߌy%*EVW+kkw V`k dj/ɯ*9G~z/¨)oA>\d 0Ȥ܀/pi12!@{ b樝πS| 1ՐXb fD8v2p=rk Q -?KƄGf"UYd\:#lqO#"UCD)ws=RW>}'e JyOVwQQP?  %2U(o/Zc8ܨʗךfEa괴p7l.cg":ll$QO]yheAɀݧTFwwiR^ 0Nƙ4w)`ywŽa$K^BCy.he%aTh/:(OAqtc Hf;)G5){W>LNJj:Pqn+jDd[֖8\&L6TAۻapܪ>nUc>Y.m"{YR7'"4la ,ZJw!O*J15"wLaHEs*gQJ&Jy; ۊٽΰToMfXd&L}ё^Q̂Tft`e U&A+J:E#W=*񊚺6uiWgǀ^w,Zy8_;JֳX%Y0[H: Q.e;c?̫N4)I \>xqT͹H7Ǚ6Χ: 9 r[d)&CqS%J|u-mNdTFM^Bul9I -#<|u$"R>v/I[nWl+ͦX;zlcIc8y;Be͜bd*m {C 1b=9g.9I6X[)* Y:;"NqZ!HA;)υW|ߣ luVX/J/opGpjg6,z ]M[<* YK2 -BĦq9nd/ba/HzCl!jOg0ho,ǻ@9XKћL_ f\;9 8#c¼b(H) ŘPx@w6rY _€&3$|Z>m@5aq]N7Ti)L3RVl\ayJS0},⪼=25!ɯwhTWgڣZb"AϠ ($Aلq[PR>mYYl?VDWn pG\`T&~òX؉ ܫ#HP=/1wtħ܇f1R%}>2*팊>B.qfNg:xmpVҁʮ+9P9b["!lN)-B R@Kf mcr}` čkzZo8TTwIT a/v]qX†T'Nj㟚TqIAt-CyOJiܞ-g"~MFM#{u&pDfEDowVgE}(twۍ(M _ h>?7K4 `S3tAz$/Z_`EWq7Jqsl?3ȮI&A6sePQȧ2VTe[(Tr0PsV+$~WLS.q@ISCy\~QBurgǩbKǫhHj% l9u1XG/ NW 5Sx>-- 0$PYW1|>rB3x1pm"l` p@wWj38hآZ$E+.>a_a=7>ݾX⬊;?2*Fl)} Oȕ)e_WE0!)yw@/}}ț Rś h`Fܳjvr 㵸"BiVٵluPN#OOpXͬb__S Up&N?i3j IfIv>*[y1}}IX:rjVhKAۍ)cUKk!UCv^~;=RY ~N;]* 졫׋:(QB(q:Kԛ]ȝ6=08,$ uqg~pT?I5wr14zv|CYNU6$ P!zBTJKn -H"oӘQ*$'gI~S7/O(%~UaL>kJu)G Cxhn)g'-Ti/:m߫ ]s{ P#6mڊjqրJ)8x8d3h˅qBˊǽmSJ`ކS $9H:jMХCd>+WQl,; eHB? }A@N#|N,1̷O @wEaqObng$>__J`6S:?MD5vC۠Vb$] =[[+t IbZI֯!i}д2x*D͢jls!E౐@$žvV{Rc7#YVЬs\r5VЪUs UAEx=.6RL@|O3z宝Gw^[\֍КQV:C>()F}| TC^kgbN &gNwb{#u>l==!R&耕p㘎(ha须bFU;]۳ԭe7MQ^ Q-᷏K>of"HO$AN6i$@\R&Aew&B!`"\{DLE3ٽ i㦠j6ѯr mzvOv $ͬ[ZyI6>۩I.ç N F3x:eu$dhr\Z 2SNk&-!ā\7x|K2~6+.&,e-)P?_^lL\mj6[B62.4;~T"\_^ssWwLdLe_s^q0= #] E-5uc W4\dWn= t%鲴Nn0pgH@KV4u )Gur4aB I.S{4c,ba_RefhT&.^ NkV braE-3Iang#%.pGtl$̧\@]Ί!rR0D5So͛؈h#VTP,&4#C{rȏ$QqNdGR1*wG\NO{",+bXc32LAM `%U!UHPDi]ܡYjо،@jgո6yy=2}k=J3HRD?ʻ//:I?1 >apu%9'A3 eܕX͌"C%@l>2'%ʱd&3 i _~]֕awfAaet#d_d r>ʧ|7w_`hy5@iP/A=7.r0mF`   TM[Sf|f.EOV<.U{mlry^k|^'~;\E%* n`hӮ0 nOh?f%5־3 M`K7e'x؅݉ΤR& RN`gW:+l:uXw)7UxZDG~E~1\B 8t@K89^iJ4y3N\AgЇW0Sq?{e˖Y'ƺ'Xި |nLXŚYxzG=S"b!o./ E*O3.߇iqwi[+ _3˟hb0s"F7٦UnFzV2Őp1WYZcʸ,u:_@i5O*5`d7K ~!gtGVҧYs@Іa yCuwl]nk-ވ`@;Q\a %~!9{bDsUu97SѐcKmCh>v & 0.d7'd]2E.JR"ܐ=h,rO)+"H 9 7^5I1e9r B\jrs L 3|6Ux;WYKiq՗n|m"Rqbrecuc4t\:MI7ܚr1 GifO(ʥaUU#<+n$$Eo;AO]NorGrsI5c `Mw)a3d<fU0E[:jJ T1QP[]-{x/ho~5/3;De.I9$b"ektY ܸ)si"  Rt[W~妱F­VQ `dԅ'sd+2mTU$}L1 0b"fCΙ݊BFMU2fhi@zosO#AGW~[CY*̚d^CEnLQڲ/qTO')ŹxsCF+5}`YZwΏ -_U_X'eȽTF~(Ʊ% i43& ɗZNܔ0+^kaĚ.MoYgHI9q/o\{}95tLvAsUpttNM{]iVke,K]x_Cdo> ̦~U)-H<`_&: 1i&tC"xaŢ^ qPxYsXݐVusM>;u"wy cci惗sn,kX#,CwϫıuPXp=ʶ(K<[,&XS9uO&=|+~n{6sqK@o@>ok>fP|E2wF'W/@9L3;'Y>E6QgTC;#%qcJ`J7Jwx=%JXvncPʹlQ\VNٙuo/'4 7[B?J!JŽjSL6ۦ2!pNX$%*a%(rQ I/ $T'QWA-s!%,ˏRL=?lꦁ ۥڳaVa$r|x>C@6:*t 4Ƴ24 L䙁~U}dG׹bR1~nnfԔH\|Dž!\f48d\@"kG˵&dO]v;A9!h%{ %s9Cy^`K?1JD?˅r#!fcًƌ/]MSЍp|>~Lh!V $,F^q:a(=6!&{~@y)[OvEo.f (TS;72 8]Hw6ιi]Ҡah|v a$G*)hLPcKeIC ҠuL!X O8LFۊ6BxaJX{\N: >!EhRѳ ctKyZqhdm ^?ѬPrw&vq??~y񪓀rx-׎ڡHI\J)1F o9n Bz¯L 䴽W^Uжecuگ9C u%[88ۊs<-0JtʿJl&.bV32ǁA$g @G/ӷFj|E|#*6_AD)丶\hStoN{eVcu24-tiȑ̝'ū%d{32 ^ p-:1 5OGYn6Ӑ? (DjDٙ]ץĽRN]#~5lk9eA<;v$jc-L甈{2zMةD@N0MeV*aH< ,5OIw4c=Quԃ8YKaU.:xW(UNn JʂmoVpm/{1ZzCzEȣ +"|aIy)upIv|`g#ҮgƫVH*Ou -& ̙%ׄOʼn$I:[)9br=Mn`ZR lQ/B[Oi^Qn?t.63SfMT^.:":͕wJ>CD:1b;+Zz Saߢk=V"t})&8E8_Bz8oO(aj+6td8~# f!?hl!AXBufÒElT߸R:R2 Ia:c➰u1lr&.$5,/lZϩB3te_00^FH7/͍/1Mt>4Ircxgn 'lMj8m/qv<Ŗ{vtKu( x}+sxUr5_' n'_#Ԁ>xB olm b7_`2VdSsl>aR ]9SwJ!zd\R<4̏+\dmx+,1~l aLmDBƊ~ ՙn\]=Rܵm/$㣖k~O) XgX徙l>XԆ-)>u~IF.{ >FTCX1x [{+Ǜ#X>!қ,fiEۥ?\I0< ;rŸ|~|ޝp,bq:뇙C (H.@`6CW" 0D~ }S(.VRIy9 x0$aD~G"3vwGhU*)GM##;1Ѧ~܌l\?6cBtr&#aw:SGv Bx/&f_f0c0r>]lಸ|Zw PF0$M!T|?㑺mB9G[ֻȽՑ%w*iu[V^**tNA߼^S x3\Oi0|S5iR"Pt+gO}~ Q?w1*b$=-y!y&;Ӵ[e+eEg[|V<7 8{< vmaI9I]Ŵz$O+p} iF= QXo<ܗ?4?rD% ZVX rY4OrjlgfǝkqtWˍ3c֕Rn +tRDeh,MfPXH< %f3؆h*H+bqz~g#U``‰&OmhC}ڽVxl=R*u:ճ0]Dn@ٹ.^')WDNO^o5[q~N$Y&Kيd@EhcX*5W}vc5P\О0$@tKLycxD3vOsuhF?l\&xk~R_iRDc(P?JaDFd;1\P~O' T">p:W ׭ۄ+i]Xc*1eDjyR%s߃wu+wN2Q_$U$u>(LQRh9-s?%݀[CX]U-6֊qyo7]蓏=T:K&JlsHQyŎIuv5x(/*r-%/ 'sZD>\j;%0$yj,#=K _иcM:4H| t.^K { ?oM]lOޚ }ICmuQc ];-i>\\± 4V}QwZ-+>F-ւbfxjs#z<QȺuޕei:IK72IY~68x5e.[%K::Ҽe܈1'"5M]r60Z# 낏O")iFaXbjTUp?)>E'8g:S/dxA~91ʍV+lfEZq (՗,%K9dkCXx?¯1#`a^v1A\7Q$ޜϷZrCcȜ>-NI8|ծ W0 [v彐 lb!΋]Pޞbe m5 nJ&o(N@T6Wh*> ).zvA7- Hژ{دͬ mzVQds>z.)_% 8]^QKAZRLa!9߭C?A$_Ik*g_i^P*>(*~D]tHav()wo|XhA!Zczrgdap7LQ*7 ;؁^pxN'*>@RݟaWeDs Q@%e[ c[ @zM>D=`>lۻqFX)@&"Sb=* ޤȑ{CFz<9 3^:#XZ Pف!J|<]م 1SZR~n+j s6ɋ|zKwr6tă$>dįXpE3Z pԒ#؆X>55 [Q&8mε7ZdHaO2m Ip0uZ7p˒j痏K>#=J G(l8OO_`9J%r8} ӗ\G _%֕\ΙdsqPv'"/+v US+VXw|[Ofd~>(HTnEM_Tq[ǧВN oįʠ%=ʹ [2pPq2KR>2 Q0>=y§{h`m3]aVxy T-B(⫆[ -1a|vlU~*pjiH^7+dF;u$(Diʖ;_]d}Q tZ&OxEwA l"g/r!tB 8} D@kI~GK r])Й,U JJ()DZGi wEv'~6]C;fj3)OƵ^',~ /\pkPZPӥ1j5⁜m3V\E* X9%,!'bY#599>aH5ad Lsp& fJ`#ă5v3>=T<ڟȮxyqv[c/Ԯ"w|: LfJ|9UV3^u@)tݘ{)kx/[_@E D& H ËK. jVc6;A2?oT&C-C94u|RsL MRZhazjϕ}A:{%Ec9y@΃, :U)ELmay?OC,bscCL#[~߇%yz2 >} >Ѯ>;z;4\;],(: ##3ǯM{oZa{O|iâe'aἶ0܎*4 r'?so3o_S`hcsR۷$g84&_dCXU[ő-;қ j>OBh޼u`R$%x0hνf4)~QrHJ۾;RayWMӥҮi߀ߨF /\Smn 0B~ʸ6~V3NZf՛7EJm 5>Lvc1#Y-8&[Fb&} 36`ʧyNeEkWߋi&sK;D*}9kHRsz&$,|sKq|/sk#!3_W zciZjXk@N7S/`&r55Cdo ocվFnC;t1SnjbvWF"; 1dd/8%t}kEĖApaDv]9# 3W zl.<[J~]P=j6׮QNJKm6`_yז Mo:}*]-P-4>ΏXWHA,ԫ}56&*N>s[gPCM"~nt- )m(۔VtW&OT)-I5ͫFAW?u/5y=8"}HȽ!C[yUpbpJs"/_͆A0ҽJnL:ZV αdOjJ\Yqj/f~!bݭI͗g)+f'b|ʮ4-x/P>wf,*w[Kb={{Ʒ .H5.e F/3p%Lz7=`jJU9\a"_Rݻi UfmRTZ~٫' 1硑zLȟ Q I.![ WiF!.Vvϰ iW># 8;_ƾG=fIU HOH){QX:V1W lg;@:T<㩷A~(N:^hl hГ 펂M7ɟ$ocΗ~#"S IҸDgJOv]exr>K{&Ǝ%j\961; R,pE N#Yz0^,Й;XpC$i}yףo >?ݷv -Eic"7=Su&:ɱTU~&S׽PLWR\BG3s&J6QHpdg@@T`Ƌ5H%d8;zSz"zgYK9GE|C*̽&; J{)(+ KBF@Scn 'M#WubjFxˢMd>"3thN3L]r{pX{9Q:(H }Y MvҙWLˬ“m6Ժ~ֺ•Z>x8'=˚M1;*rrɱNP(n?ɜN'GO k{!&RuL C*"Cs7? |~iϕ%r04e *J"d1tDJ $6ً&9|1ݜyOvKBrR>g.c K_ƨԍS-S Ȁ>׻]Ga& 0 I7 -; B )Cȥ?)e P>@Ʒ[;CWU0d/F@ c$7 ;k"7KD"¡3F-Pkh+MB'-LJB*W% +ֳDt*}Io߫qUuLnk KxEyôRE?}_z3w15a6B3.omfD +EUʍWJv2$:C)tE_X^xvVG)zDf5Jq1x? E%qWg`u8& 25& Pu!k$ C*ʋE*}qGX/VsâsiהD*)ptS/n@Bet$5ׄ -aR# Q"''!M0a4t dWc, bI򯽽{1#_?e༎Q{unے4X9zK^e&'e`QM`*&^v5,c"Ƨe:&[fq(>[wyOk+h\`pq >𥞂ʻFg\D% X~ PTwr(bQp#bkJjwrĹ\S:i:pFU}?2\D&hʺuϝ6fJ~.3l޴? bplgX>|Z(7`Mw;$O!h7⣖` @4?ra/>#b-Kj@C&MkbOdO! $59dVh#W'mm%*\"CwZEFV,n ^th;O/ZWʲ~(FR:}SOa@ԤƇ, 2̚BDu[Յ볰$(f[)m j PN:;5L[&)G]y}3TQ Ԅn{9c-G2hs$%:˔C/IZ_TRdpV>S.{<@[z$DP)TNS1&n Ŏ0 T0;u&#kt-='~_V44;/j9Q# ݦk;b{IjTɠ!_6,F*i"KZb@v;|,Em\'4wBj Daɋ PMH5<6 \/;_rSt27"R_rCBR*C eT9yݝU 9`5CNN UEpRTJ;4tQ;vq?ѩ+ \=’sAchP3^%1P IEti8 eQV%|;. #DEZ&#g[-Gb0sƸ m;SA=[.]0VQT*OV%y-El Z10;>u m&BG f==(S`ԵE\/$r$~TF#QQ^h=tl:9y]vW~iwa8ž/me1Q%V|._w¿`;Th<q;_|7X1h-̐OJL֝6:;=u%L8y)ׯbJBZa,D|WXs^9%fic_QxM_Kg:ӪvxLPbN|h[ض mDQ3`,J5|Ǣٛ)ljƚ"&뭅 ];O:FJ҄v&e)ʯ5ua -KazdEEY YΐD~"ҶXTcM3 lT(1V͛w%3+#˴Y&J9̿M4^d6$mhC1@g 6?+,r\ͱcjjE/& "~'yG;­&xsMr%Ugą"" C4PPbUe|]h4ەʀpD VP*Ir<:IT`b e m}8h.2hKlOȐ1Pk^L^ c56?Y 6y0?AK0ߍnUCN.>hrkdg+w4@ZK`r_ ݙYO)DMC#tz\CQՔPtNZY.tR]v)ۦQcP¾}X)B9>$N)k!):Yfl ]UuM[H[5,fmMQři1L| aIExvvȘ<) 3dH/fF@F+Y. NkBS ٛqwbe2T\t_<?CN\aGmhcȸJq{[584yt+EMs߇]|kb⺌XOlI'k9Hp"{ic{'gwʹ37ܿxFkU;>';Skͥ1=TOeQ*s`_88#NʩW<֠GS>g%ˏ^!j ]Fquhp]ߠL |)hN_=2;7_5E7 &Wmqzp?/dJ]`|*gFFW:v1$ʍ1XNdq]ҕZ6hj[pɖ:3DR%zЌg끧I7^;,bi,AJ)mN#:jejI,vİcP]R]#IƦ},h`^ x/RKSQ%}K%VFfšX{K.uNAJY4xpUS@/z&9+P9jӈh>*|2exF9hQH~l Œ{ v.Rp[ Nw=R5@9mjz຺d:dvD=vvLpsҺ4^钪e.W[cYY=H#$א&:7Dz69`5CbylNo< $51ܙ4bRY6}Or{itwqf)okƛQfDxM1&bs A4ª*IǖxMPm~cCrKLJ5j7J'ѝ2ԟyB&pBOF_44 q\rc4ޠku;/v}ga!Ӆ4?zv\leճwlﻞEm,^ROE` ;N)B`ؔYU>tf8dOB9x֥O3C,F!njk7E@@oX3]-MTh>?U"8 #{j[p*0n@$EUPHSEt陭Eǚ} l_8;ie#daMW{>1Ԍ#̷J=^JJ}]ABXX0VS(L&v|SfUslC=؟[SR2Z~I2!g/nQ#eYك;;\#c-V) K/v;;^ %RQXg遲,\bkFJ;1sHZj@%!OfNVd0Ua/E=:غRG/^gG(l$s?ri]7`b[!uGP9PÜqS_jv f1u͖}18R _qYRaJ>OƁTHQn Q)?H%F Y{aܰ›ɋN ď_ _S;^.q|^'@iԷ.ٴ<NN;t5|T&{'+KLh}Y3|߶pEll^睊̐2+u/B|LÚ8,}Z7ϓ:85W˚1-=^ s I"`2ª=\:מ,R0g^[hS,Mm;#ꋽz:B~'ZHj!wI^D¹3B^燛Ct>u&,HE>2nj BlETʕYk9";0,) LxvuC9 m:f.Vљr "Af4 ` (ok|}W+]~efV51EE%0??aIeT90iaVZDP36g4ͱѭ`;1x}Uƙˁ% PHt< xD.AarTh+f~0>-Q}?4ͤkbeأ,?KωZ pՔ߷ N9*-NK= _3idiڱH-uP2X̲݇括՜*ϊWW=Iyfk7'}j ] Mqry D@c!V,"ԺV`!`%#Ʌ0!hKM>wGdtҗ-%<%3Bh+լ]1#stl-K6+9wv~d%W c$TRy}!kx*cL,e<k_9Fu[D7vZ5/  Dk"Vb*lFnڎ@l[4-!-;o5C:VUg0Eޫ%~O$!\WX +\Obf,MC:ŷ &|qj^98Vwz8G)D)_Up痌: X!eNcgAbۄ5FxG7ġ*ĤyxB%t$,^qPȇ3M@ H [GC+%AWEGB[P&VA~ - 0W ѫY]"48Π Ǯ—ka Қn5AabL^,h]ia6mpsFdq÷a[]? d-mӤ0<0<)Iܓ{#C x~i^u(jޤG-ӓ٠i #X=۴NܿEB#t,nՅ2 =|Nx2"2\!-Fܢ"fAZ? nZ&57dZ'.-JHeQuy&jO?-eNM65UR9M6eHːP9IT[^q\HPdN k㤶΋3bnZOFChcҐX]L oVEiH}i7A [ݩ^!8 鑀ǎ8nE #C;0@}%<^?#j5P51 Jb AYpDBꨱS8k@ʒ~8,V`?Ǭ?fZߐwΪy(bg >%PT%V`l y^oq'CeP5ZA{gq08\QK۝1`^"^9U-Hٺo5;*Gy-F-  eiPgҍ-v|)S1 5?jQ({Uh1*&,WkF|ݣflh$ثiT0}O .f()%r vH4>H`z?cW*7Woٱb> LGhTb^U x{qec_- -j]n^,O֙W=e/RԦL?}_ 8u+fHPrt{~1ui!W& b a>i'ۑW͉%7MâC1 ^q{E-@5G{7)Bq/00L?rEBq̇eI o#A媙$Gѫ2iI@{QH ꮕ[7oѤ3yXa'HFL@ol",ˍ5W;U;"JdTcr<LC|΁a ҳ$a~@gA` rs5r4}tD, 鲻 v$l- "ĽQ;NzGgU>&j(xo'_u`iܰ@}4ǽO@{ſނM Kd!ӡ_G!VGAOf9<XW(o!@W;jP/Yq@0NLP' ,z.mѿ>Rۖ<aLQ]BV+i12߹-ZÉɛ`A֫Ig,=2LچeYf:~J}$28C6欼u ݠhKD Ye%l> $#6%1 S[^v[*| x- i&[GZG~ϳX>mOv3/@ΎFk™SL+f ]jFcbӰ U2ɐ#/"ys_Q..М-ָS _\ԌmpNR?$/HL?;g͒!SάOC)\'k w-uGIkp v-\UD)I8u(?dzs )e ukIȰ\6FMO$ygD.\pn:rZ9'BBƔ7ricT :v%C+uK$*F08,ov-=B'OS` "$N\m5-t^ÄF/;j:yE43IrVTbq}8!9i=z\ VF<%jT0Yn $;]#/ ߔvbԛ3$yZ, ,~T9xgDc)L .0cFl![%E٩r߇#\H:Oz`_4IzN֌O)b|\Z \DMa,w:|rq.c(?+@GH[IOrU5q Fu{ow(aIh-5m]agByy҈{A'AQSHxC0?(-uc"[e719)#/zV~|8FpCoxh;s6- xA%Z&z` $ՔO&u߶s}瘪/FMXɹjQOCN-E@h&h͈BLD%3dW~dC "2uỈ6Fi9Xqs[/W:NZT"eI:VBVj7P7t\gr{~z52$ё _J:ev`ު oXM<;.*1#n/0S ;Elf.UfNkH-Qzi{sYz"& ^=;(Zjr,(xpNÙ2-.e@c%UHf<< l>9PkD.|J!D͹aJq }Ga^ܲ{Ld]2Sk'tZSfó담.x jmZ0`%_T~|a#/!r2pM CHKL֕ ow}3Wa@l[tXKt"#$|a{OO fx](Nڌ|3Q|brV޻\cJ5\\e - D"`^k'O❣f~l ~+$b hY[ܪ9xhY%e[+~$t7)0:Ss/SG++^v)0\sGhGcm@3`)ҹDP.mhYvrB?Л7);c^NCHz,b=S..˓'b1_6!ilg$8pߎ%zPVk|bǨF"3<"% K$^۷7c;XS ;EZL2e[oc[K6ર!K5S.w!z4@ :+T]Qwllx5v:hLj43~ZeЅBPo,_k+{Y@B^CX9]bb@4}3&iԼFXo^v߳(nP0ҭsPL9^vXJ"J}h+|ٶ jzqQQA6ڒ}-t煢w͐3vgR'Ht|i'΃|ԗH>HNs0MGEq$K&t4KZ+~[å f!8~pxsj/%V2=T鼨~û_/.WQ("-0cvɚ7ۊ4})^6_NbhrUp^Rwndb_cs>XOUa W/>a#Wن @*)ݡ 6U\6熗YL!l]qf߸(Yly𝥘R ߃C.똨Z}lN]prlAKwv#Otk!E{ܛBJc%4\‰c9UH_!=%%qJKO:hJ/|k Gݗ8}0]cL+%ڶI;Z%I+#vb~@P`S&Ujuިy\S,@^yi /B;S~ű],av4JKj]:FKNG)¦IрWyuˊƅEO7~/Bޟ1Rз-I[6,#jμ.ftCeYGsVQv~5'*<e`)}j!wHxq^pR`|ŤNB62w)пmbzC@f~u˖Q/FFL|ǐ'oW /21% w%Cs8x`8̀ΐ7JRdȯ`GT{Vk"L4R>[]mEHʳ#]'ʒS( Rkӯ99ToD eqv8Ny]f|H,Ukuu+V~Mc^df=w=q\^D|1U_,ExLB2jFf`֦'7G} 2E"Cgf߆yvZ >uAwlSmvq_T[*;Bofӿo.8r 74S ԥYO'a6s-Oɺf03p?DktH9b*^eqy>0xK갧$V/5JQyjqq Wt#4@l*J*}IEw]odI:m-tw 8M!Rbi.F.Fkg D&w ݅0~[X=G(9]i ǗҦH|h2Lz cW~{tƚT&kγ0BW)[}%♝yLSkgZ4%x;&-J<@hSr4vG(ϥII:Slߧُ>FZtы Asx)D,}btx̊VCʔvZ.|$~,qt F;e("0+GC75MX f`/÷ue§/@m(_ulԆ<"v;|j5wl9<Mr_hx<\3o28>FrU{b {}uCF|, ܧ3*% }-\K,=5XpO^ ,NqaQvQjl7b^e( ,]|@L2L "ѝ5{0ݑ%G5Z؏5Va  v=",r_$(`s)Ǻ^}1߳~_L18[}5"FxB! &!}$I CtMU{ƅUhTRAk$^1Wy z[qdbb9>`J ;ǟ̉l7pOd5a%)-ܫyB;`2'="8Fыr&?ҁx.yrVnN|ȄoɷP@>2"EnoT䤋ǚBhv_H)AKߊ[C:~ʨL~LyYtXzEA{>R(c)oзUU{q$5PQ2{q[)`t"*viM72ҵ~Y&c>њr!H;2+d/Q"1; KT&-(o(fUVb>7L>vo3<+QwR|2,]_;Kи$)ާ5췣4_/+r "{Gaڞevߋ[R; BC, RhҰì2rX7z\@ʬZx>YH[3aq 9Z5& JNtHs@D]'><=g$#Lp{ἩhWng9SK8g>;vݩ!9.r=74i({UJ{=]mC+PI>Wj_Qg!'{\Q[+ %L\fNy~ Zfi-Yz34+|( >/n @3MmPn qs. Q^)?3Q!<uxLM2MCa.to;yEe'Bii`07z~S״(FNAKnnDCo*dTT.J"_"m(\̐yRxy2&zh )3w whܢ:>;B>oʖL"銒̺mlVNl=7cŇ˩$xnjgDvbbU `P멺ElTQ4[m{wL_H4&+אJFìSI zgO﮻BD:n䄜Ftj!@=) Z.R!h(h*=h(h{lcJI ON`WEw"CMߝȬ>Zu$2>YLsF 4 S}S(,JNZp Ԩ^ےKKH[ɼXp6hqs.Ad$ZborD\ۥ6;䉨;6A"w&v !SBk=Dh$2+} +\܅ʵrO)*?f&%cƁ߷ u;j4}_#6| 0V0R BR>Y4v6b_Z^mn »|ۛ?Lf z;h_$ |H@e~Xk#x 8x4(Pyfe.!b޾d+6(T`0qh  {jvBZ9Z{{ʰ>ΦA]d\bٵa{j\/{viiWnn:iuD`npTFxzd GY ;G zޝ O VԐF5C Hw)7{Yba*0U*;շ лċ5$n,]8񆋭3!e=X#v$E BX!HxF/%?aS)4y EmuJY TthR4`I2б🨺~C"66O}Ad*з M/8ŲkN3s 'L+1-d!6:J@-?fhR+X=*F%UMǮТ7 UD~QC`rY*­pNBiT4Z-7^o֊Ge/, !jE:V;qVs]^YZh:,T/u5g LJx0|k>6+eGEKp(:&g' jg0XSymct|B6"^Sm8nQ"Tǝ}>-k/\X_+&dy$Ĕt-J 鼻U}_7ECJ2a3m=<ڑbmljARp meE1wf(uZ)Afӈъv .~+d<ּ鬶sJ0(2wkCC,벿5t܊v4_ۻ_8,'𖡉%+5%_Yc~yGrk?% yy`}I{@=pB$%=Lyul}ρvVNY< //sjJ>!.A~9WhѲFU.{ߛaFZ@; (7f/xjɈV| E,Z;suƆ UE NbH1 M{. Ue #YM-2\a )CQfZzNs)KN&I[p3ʄ$֣ eY `0")i`xV~s?wKh5H!"$7QB?Dl4%NB3p#.j"p.& A^O),\aRu$1~нS]^?(gC-3Ae$(9;ƎN-Sj3Zvy̰HڂYmg 1KL_/x> -ʳ7u4$RE7ACtELqCu5eCc=ޘ5(3G™6[%]P~ ojLCT a;XE]gUk0%uj9W)GZ(' Ybϝ' JMHެ*- Z&HO…2(t4eſny_ < DΡ_Sx Sv`- +b|N^ LQx[h6o@Պei9 v&[܁QG}f LCnLɉN Ug0\;JAV6 D sQNJxG׃|V #N( ǒD;RlQlB4Ee r ;Qdq0^`R?ټy~B#>*>2KJޫZM,RmpГ V%ZyH<%$掇I`ٟx l-|'q>5Zs3''Di?'S wU\-q knvCɰ췱I;i7EoShZ-b?"Km2$;uH2JORw׌E~"~nF W ('f]{L Ov悩RZZ ZmMXH`*r}hPx}?'ge뮍œSܑK̶mfTEqvhO/_E ͚%ڌGjHc=fx+v◘[wS;s`LxbRA"(`1ڐm:,WC}@7 9VԬࠑBw,]B'r8k:Oӌbbzae@r8= Mg>(8HH["1~x ; r/UDv xBsAO(̲jk?6Ot3QoaP{"'0E,nG1" {m=E\pp޴Py'pUFS%*hiBjuA츽$Q$7 sjz 14&xc5.mY ȍ=@& TB "%}$sϺ8@O1 sXВCL˵5h)-6fC>Tکz 1 F}*:f -`ě? F{-V &v h{urP@ Vp:b )1Eks#oFLzVK$x&^"`o90+^y'MFMu3eQQN^j !mɬoW}.H"^lG c߆mdm(V|Zp!Gx[5D世nR:MH{!t~7OEIk#Jq{IU{| |n!9]6YiPcψ:vNt`Q\\;AZb3QOSbz-?(<^gƦ nI[xAS^#"ʯ%VHJ_o4- ߏ=oWs6˝ߋ7Twd[cWY2y{?ݐ S_yj՝fsD =Vn2OgeիlL`Vֲ+;KKN1rt$#P聖0r*+ A_8q#k~szteT:C&wg1Y~[C_4G/*c "H/=Vir(IbML[;BۇK9VyЦ0vx4ȷ(C|#s9|t͔Yqg@YgC+jO#rM\I`[Z)^(:~Ehג淋TDwؐٿԈq?aUϥf nqZ|!?bx`.U m<)6ҙs_h|~l"xCgr˱mǓ/|'a%LM~9/+9y\/_$fݾZ ztϢ?j7aFVgԝ`=QWsln O5Yټ F^;n1f';cq) /8Jaі,C_7T[XPS,A?P׏.4=le7k0A)Q^^hFUST^Ҫxb ^dhcW0gDmCBǩ,v9h-zpѰTPٙdgnvZ&@듬ov7, ~k[|>VFx>6Ɋ(||^HQ@#:|*#ض9ߖ<+N0`j]Fv{S(),fg߱>%LZd\.n_d"2 rF%1 2J97Om|;Dd~ɳ.@GZ㊥!>g\Xy^ʒ'|.42N¦!02]UX/yH {<6u9s//2^Ԋ"Wtz >ݺ_haȽxS&[.sC,j~ E l] =)>N뾷i-r8B@4鸺b#ָ6_ !B7sY/JTG=ISxyb;@"Q)KoU·nq9g ҍS.`Z.ؿ5r8v?v 3cw};\t_֌Y)0m{Mk0 o}Mm9p";pKK9ܵf۸vьn/L(8"@ I16Ћ]Ӷ#%|)clDOĭ\>^^oe/|u{ V:K/0lX<5k-mq΁ !%r' sWalRz63ia_q(½J:q_ E!D (:Eoz(lNqv!9ȕmxHMPx9 QI3ė)СA?_GɊ YMV>g{R ~]*S, N-? J6DImnQ;iDT?_,)$wB-: Z<`L^fƓԶc:UYh?XBCh8Re#v-g.V#B_ 3 ;.?@gdA˾ǔi}?FO!<t\vBD|B@O\?]@ 8EG"}@\薿h*vO#/|#|J7a d`+޿#V-}:N xbKI=ɮnt>zo#`6.$NS&=k* *hrAf`%XK֬p֦o,Td9TUܖ>PM1FxA}=XZ)AIKXZ-GמB.Rю`sc)ݞNj6W#⃄ <$[[!== 'mZHHIOsqtoW:Б& {]#lHWΒ! Wӈ kl{)hk֓{HWtjYSҮԣ )#W308~k\W<>1r>U_%.M CxjLWmvUo~іN[O/$$PɂA~&r`N)o~TއNf+1^8O͂ܢqaJ!aaX73oJ`Q=őIF8'#,\u|YGX ۚʘu^ Ty_Ґ dW 288VaRG^_M{e{>T*0WTp(,cH7(@3t8P걓^|оσp-ԩ/޲z;iQ.☧cG\: Wl P >u o(AdYm>@̇5-εCp[τ/IIGsj\s퐨n qo‘kG oޛBȃc{Pvja"ʉ{,ERƇR z4Y*{洧) .! G 9Ws p*&lfh,G^qQZYuqj^գ˘HQD.Y&YmKdDTQw"`[1W~⣟>^]nM )@xP/ی?z\mREAp+x1" vw߃tbAsWEM]?9_x=}>7)f yO5xQrM,i?+vs2>oU+0q|G4vNXS Ov<oݭiʹ&Z^F_[fȉu]GC2KL mbLq<@ Qx"{aވZd6#٭eA]YF5V:Q:E.F䪚j퉢%soE%PԎ/ ز(=sJ`vJatPoG:9iddzZϟ()uLcL]fj8`WZdx 1jb;/]X+3,xc]CL)mX63_#ˀ`̠I5mY@"#-.*l;TAXp--[GtXH.2g,e4|qWdC7[2 ,OJO 7"&{Fyp_BЖ8OVl7M͸4C%8)ǿ@$l%VxxZ,,(+)',gb1'Ȥ)3Pm&kԟ* yc_BA(o:dZ2uN`WpKf, ;HͶ:fu[#hb@)ѻdx8nA:" 9dɍEy &?Lg@O@FS1 }1jҽhh]4Z*=(|wzV\eXW|+M9Ŕ?x۵lif4pH08MV'KkOxP| Uas!G[zBi HE8R}$t-ni+-L2{-kpJ>6kOO ơz? Y ZpPy^, 򽟔0B$wHP̈́Kt )X̟f+W(iUDR:$ļ>tSGZ0G:Dq"NB] |D{pUX3X!1FY@F͟r4'N.7axdߒR_=";Y UD4WgJv={@~"F8>WhKJz]#VQ!9 w #P\o'QZti:X_^UwScmnnPE@R51fpϕW#R?cTt*M`!Vw^Ey8`qv{_}uxh3E)$X@@Fg'Iu/:𛑭Q܆,}^A݈kOdXhFwb +;x+?PTQV&zBx [ >dQO{oE9a Oȃ]aFE;OӃ ͱJP2jH%tΗ ՜%AB6 Z9%e7bRMݓV¬0[ V^?m! R _HIm.IUD79PYySUh8 K*M亿SIB- 6S]5Ap3Mw~3t%K pnwW{kwQE\;[V O79AܸGvxpgg( y&R0mܳ"WpcC+'Jo MLHhμGKXD\/ޤ*s)rҸkt.ız-yٿ եAkY"{4wcjs)k%Ջȫ/>|^=t%{Z̙ JVNT(7 \f ئccYe)'6}O<)y5e3 j s#U#ӲZA龘;1r( Uh lnzT<.P|oa wڢ. eqX"J_i T#鞟bQn5s$۸D3l'4E̍sh>VFa%Z\Kpm4/wW UD)Xhtƿi .&X}tn ;6BȠ垜zCg&TኅnBi*E8d6ˍbr#CW!6`* -g]4&EDU0|e%I]Y Us'Uu ` *iEYe59Q"0-^@H 2:4@64h_<jC|O4ɤ}]1\?GoqLj+Kt(q@W͝"ҥ(R9S!py`CKUT2C?ǟ﬛L$3%Kh-6^POij;OأK'=;MA1Ac~PeF}"_vVj"׾=[fig^$Obq4ӛ[XBxgXgtx$3sTXj̡@pQ2Im5ؿ[\/`fg$.noVlY(n&G\qq ,r^[_u㨏@?Hڶ$(3<#rx1kӆG%2RGx46OkqV~EMkE(b1D-' 9ȍqO{rB Kÿ.^0Bw׃̤Z۷U7(.qP$ KNaT82.)F~4HJ #{O|!BAtR#&͋pJ(LmU9nU&P{dKSM iӌe+b򬐐<ɹhS tA-6"/8ن~­4a3-L-sS~-s_}:ȄiNyGC8zX^S;JA/!J:C5_Ƭi΢ )9a4)zw1vI cuIMc6!=f|$6 @3'A.0.V&PuZ:@ߛϤHlKО&Z?*ω6%=V1(|JlەiΌ wI)d@: Hťzfclck0lBE΅Y0#c-㣍R'mB*Oœ ,el Dh9,Ӿgraܾ 6d8+/!aE Σ]kz3QuC<@Wk2<څN)r%_>mpx@\  DO=! 0mKm+8%ln>UX\SBc;gIr~[WhB } TX'vWqo8Aϝv616V jx(peKgeX&3Jʑf攡'CW#GAߢ: g[z{l"7.}Oko+C6N(W#ze#8GVt^ie7FRȗψ :Y+酐T O*DȲQ*sn;@{Ѿ{Mu,#0G]+1 \i8p(n1RE9SE Z_Ώfsc Fw*E6_x ޿^$ * Aݎg(г$՛?QYSpVR. jQՁWK#s+# Va|%bJ ;;ʗG m8wšC?m#qaw{i]GMu,M$OJMi/ ybKlmh{ F#'膭ey..F['6pf#c 3Jv;^bCE>%25U:ip%&o)( Z@6lCp@y P,=ʔZ=EB5U4/Gr^RaffO("Q ASՄo=OkLHB8W{,=?9 Z½Nϣ!Ncǒ +qpt@FfzcA.TJ p|iA3CaEmuqRD bmM]9v]׾PcjZaB*rjU𒰋\ bژ&CU,, dyt)WSb+.͏J!F]B e5HUVQM[\6 n؇C̶|خcf*!ȊyGlݺTe(]0"*^hSS\ܣ 0]]E uȟ-МB;yzFnKd(*5Z%R`bEtY_DwJe "pO7ÝЛ1%w%KwT,s_L nA| CIkk&b.7Ĝ d W)uKY".УpWiho0W2GХdM82ek=rR"9O5Um[ɔ! / ނDp E!! ͢D yIejٳ8y$2N$caLSh%"/yDzM)%AiŸ}$YR'Ă]$c'I4&p(0m·P6D"jk Uf\IҕLMYɉ3Kf .}g{gGB+p9OdA\P=ͱ;u4v/ ϔIL<=zkօ7B0Y=c(\ok4L[, ,Qf^5Hَُd/ھJ`v7?aJ\S?i!0iWqakN(j;cNܫK`_j5e&R;;A%Co)0}ݠȈ@C)c|L8s V~߱~&N3ngEؠ0~&GSXNJtxՕhwjt$JSoFMR-v6EuV%" T1qz7D@>60]-&\?W}7←]sDgB$)yîfVHsEw@~*Fz1 G‚/qa* (\ Jj\-Wп߭X;|[^ .(xqĔ(uJ*gr8"R0 m>6+t3Fe}Ъu"։27kf.Ħc4TR8k?z֒g08Lamr)Ju)*$ aDtZІ@E"n&x! )!A ոط`e#Ey"ǜq fq"oKr ~ xcP1VXPV(d`SwV(2 Z~H 6U_;6 oXN 2kj8 1FxnvPRNfH"ky5ryx=0 `[[l&ځ(G1ä19ZDK'B%.ԯkWH"$p'7rX!1yޘlD3Zre8ԕ\\.i՜B. ܵ#Oszơ/#n#~TA!⳵u><#ҰUŵ[Կ`.e8r>^.{%RyHn|W|j$͇s=rf$b0acM=ή|Ac R pR#*jyWlQƖx'y`p}gSh%mh@ DoU [HMw|a/J520K)&$"d%tezdpߨ^WU?Ѭ6Р! *v'/Q[} k$VbrB7E-ґ#y+ßlp,ҥ,|ȴX?eŁ_qM$3OcNr5U5ū #f[ 15H7ZoK>XM7~1Ln ϢR4 qH]E~nAH4ئI"[t/=5rh33\~Ь֘ #ڃĴFƤʌ)"i N@Y_fOس8ǡhga>T.^tGl1 ל XB Yo=x=l72+(ƏA۟2K]qa謮@.{%и a@%BHqͶzkBuc&[yw)-ޜnF{ʢ\a} ko`'9_|1Mj{^yVɵ0\K+B5| R)zN6 J!`%W0-[Pfxbd(1D쮏Po'Rg? V:? ,3BFN,s (J\;j{+y+oo"U,wC% -hђ+<ӵЊXW{}q=(K@(kTxigS6U3w@gr}7PpiԾq\BߥX'Iv,+ -$-tt@F\C:w"쿚)w۽2+qAkI,OWs$_9ZKǶr\W-oWLjVZnz u?!R a-<-׃hVh?8$S6& ̩#Q. g$JE6&y^hK\;v'805}q õ{]nvn2[ty;r1 Vnw }E IRV&]c5~Z)T;,N:[01Вy/k<"fI֡ğ8c,řRCE?fcj/u(/~&9ٷ=LT_n4b5+&Gov6L^R}8Nzu$[S.j,t=X˦8+ ! `f]}GL-06<#nNPӻi}jۦ,XĹ\X6U˨##"!_L0㩺`o_]6rjG#z/ŒN PѧLPY)Lrl[Gf?H96{i}r񲳯A'wWY_ǚ)mZ5ˣM(BG7Te)Ⓕuߢ\ei8dBYNicmp3?m@og9{~iZ6H]m|dj1(Sxr6BM \#e@?̣wia_)޳PyM?ZJnQ ih?g?h*'-c&Sb` N)rNa>v|>Whb`-xq=~ҏɂ\}PGΞ̂I暙pQ3Ae$Ӗ!X/Pع`G%,]IcXoL6JHZ:ԽIxc_y3V,d'I‰Z)բ]o6hB`VvPűB//MI'7v9~xb1q2c&cSR:. ('}R6שyNCn0yJT#XE%p|3i5>6 qrZjoS pquv:YQlVS)uKSڍn%{#* .%TGﯷ6B^}NTFTz'9]'f+"pDw SMl D[Q(FLm+XArJV˰C0kdv_t/X/{v|L~`_̾ӸnS6L\jPU=𐸈NoJtb,~imCPyLW1vyf}L3zs5r(z6i]g:iw+}kطDKnp+@>7|D7h,8 BmV*|Ŋ.jRVl9T'0 : 6 7`YҼ/MZ9,G/эu 71ݳV=j4 <{ .i `' J١EYyk&\uh\Ԉ4Q g4"Aam3+[ots"k-v(q$g1DD/R z.ð&Γ3f@ f='|׫GVDK:l^GTYo;G~͡{eOnUvn"$K'<B9oe^%2?P _Ւ *&lsӭ<1 ۂ}0P9;|L;7a^k\DLa>%7 yW'$PI|H5 7[nNx"W@I*@5N)M@BLB &5}ĸb/#n2pH`Ɛ E2dޑd_|AJ\<{TKylY M P>8_C e:*0rJUU{DcK(tjA8ǵ.rȎ `/0nMclDb)z֜l5`T 2nX vV$;:QӲDx;\2Dkdf>y<`VmNՂ,E`5+B>zbL%+V8Iԛ5/P $ 2tÀrIZlJ O!L],{2TwWpHbTp%Z~܀7B&H\R$⃇fFqR H=j z 9U S\W~:C&&L(GD@筌FL`Q̐PSqŅO zᩖcxy/m[6C9,{\@Į"9#K %f t-e9?K5>O?fhi,3IV%MT~V36@:mǁ!l0bG Xor5=be#ΰYq+PڨfRkt4տws堿,)k26/:w_u?|'@=1]H(bյ, #s}&U @e4Z/q}tk(s z8EX L2+g8q\wag 鈋͈2b(jɿ:e BRaVJ<"rّBh Щm|'%wi[D=Ƶ7"MpĶVGզ9t?ngD8ZtXAh!J2$RC &9Q1Sdk]&//j\a%"v" [)j7K**UۋCe> Y O;铪LfBqS<}KC>Po)+Z|Υ*TӻqĝȀRDZjf LG7y,vYQG@d >0v.͏1q^>7sOuSOE|Uw==512Jf^c-ϚJ l+ghq{9'М#R묒:B ӂ gvGzXZk99t!AL1{pX~.xXAJkkհV8e:)[~ VϨi1S`N$'ߕMe]Y6q`YoB5ۥ܇T. {ݦ"dY_c&sy$.X6rٽwD}ZzէXMRqG j%HRFY2;NPBe6t |Po@1Vʣ ,QD0~~e$*Gh݀봎WBsG24Py t-t9Q혭W@jŅƗ~uVJW}ٴ׎n?凮+k)Ei 6$4u 5֖y[jwNI*G&E)RA֯0dex>;/;)&]̡? &tcPl5(|j]yF~SZmT"soWȤ8*vp~:e@hylrץk!oVrx%.'bHDxe#o0ƨj h-`qmW?V: qəof{(ޛ/5@`]n@;ڧ wST?E{Bjх ,E$ ġR;*bܽ!EP:CS&GA>vA'5p3d!q*$}v YDf*qu Ư;VM11I'!O=ɝz꫘GƄZ7(čqa˭;vEs+:拫XpHߋ].7ÝrkڐQn<;0hRȱ_#pU \?4|7NqiUa@k)#q!y~2uv(QFňb,a6WS.m{ Q9>: ;Y1-; z 3c=JS >fl^DuxHٛYW8as9JY !ծ.`7l;&Fcr9`J*5l#7 &ɤe^(ZP:ʻE XҌJz[#:LI~?>Ģy, 1u t $\RB&p/]ib52Mz=QWTƓm泄N(ɣm։VqIAg=ڻ %^ D[unn8ReD^b)t7??Yg7jK; u"=1ݘy>X [X l#tPT/Y<_H U7Ҫ@K/>hBJT fcxƓf' 00ŋO g/+h/R}%dc5jbVsC1%Ha*1ͫs.T@ZI$^~6ʝXX:zuէj[~*ÇvmZshoSmL/~~V*5X ْ3o|Llѝ"\o-"spȁ/N3Q}xBZвϽB B-911$sC-2Qv@JkT<4uc rp'N#UvR b+f:}ܢ$}߭psM񟠎SYfͮVFU9-8խ\ȫ9իű3/ 0Vrl}CǞgsNDzCFuB=Xq1!Q7b+0MQ3s<^ހ6Bno} 7F8ſh91~PL~ س z;75֡YՄOZDɴe%weMt % r>;Ma}}ѓϹ}jk̥5fv1qX:\N!N$ÌY8=vEpX:PU@ q=m3dcz5Piv9Z& M?t֕lR8+v;* Ai2pasz/e>DWo"~g_7CI.qX5r@xZdۤziefs _,v诓k/eUk{}L9ءg#:_N Yͅg *DK#h\[IeN~A^әbyӧ gccbikc%ZR,CܺP0TK*βMӈOpO9@-mj|~ZX0M8>^op٥鼥6֢FG\6"Jc HQ2dK6: +eS%ۚ] -bUW$]5g VaV -K i;:]r 6#{㏉ s2+٫Ch,WEfOU89$85Cfˆmqn!wAJZ8g9 x ]2Zm9FWFi0`4vW%$@ xZb]P/ɁT)Ey1~D(&po#Pȭ(skܙsU+6oW`>c,P0*nE7sH/:rbp;R{vEQ ػA${KdGck1qWP|ڝhA(#` M2ǽ̚ezXWOp1O VCmMm|,¤*4z{zoR&ŝSk]h%F1ϙ0NPpo6XOӦ^$*}E(2W0[AOY}WR @aQM`Ьॏ&mGTfGCe0H ²y0.*d\0fn41*`㺭#v $9y&Gw Ϩ שچ~&*FP!0+Z.) 5M #O Zx]m U,eX/['CG3{Ӓ':\D‹44-ۭ7b&$15\6Y1ͣ>|13djMџbz٥CB]lTYIzxiX#s?E$ '<U`S3-QYҳE)/cXmMX8uqq/q_V9~!{Km&ZBJSj/3瞎 sCܱ-[Rˁ-)n>YOPqRZs Ո kL]q[I%j#(Ėhtmd çP)#@]qǮ\DzOgdMs*)LGC/GIc5"!] S!LSRY󿦄M&BDD'ථ! ?Ͳs!WE|FMQAJ#bt5&3;{BqJDt\, bYZٔḦ́ɹ(b(|yr|5T&hp?֎G4הEA=+A>be=nHxJn*8 Ch\)5_ WM8$Ş'gv&[dDkuyXOvUfH}`,AgN)TDue}A>Əq\+(!x@^gߑ&پ8~$_^^|dL}AvWgt.jPǔk >|DUt"4kG-]P#/Gp@ .0^ k%EgLXWKԼ D^`rlY:_G[f_;*C%UΧTA9=kO#e(j?6ޛ *.s`߱Ҝ:|oMزz. @kwx?oy3JYCj.Q^zbe>]OʿPb|Y ,+ SMkHGIPDɝɝ/Yju/eCe=zoNyT@04c4 Wo/, 7K=Lr L zL&txY|c yeB$a[Nw_2n֕]OUM9njB9Ϡߖ9V8&,Z.8b=VJ?(䡚.y(ŧ}kDS87"jkxcI+zs Ivy:cDEA[g|/Q54J/Bސ1;418\W*u`"aD_~+Ca*N8 Єj͂rxY908Y rg&cNhk/Qx[&;3lݘG9vT3쐵gL-G3cZ3ߟa"Wkm+8jZ Yї Vt4YCg#1_|Ĥq3BJV9PuE>=:o̺ju~+rLvMu+k( HSa|vð 0SWglq8'kӤh'fWu_e'Gޅ*$#\^}k iF=*^Rulm"k.(d@c6ۖ}c\1SƁmfR5qio2p62c Ϳ]QZLLߎWI'x)^Oҩ,?  0U=d 1ΗW D}@_ An<N#!wo02cdҐy[_+WTD^AN,R&9VI>Y)2'5`~9͠q%E X8Q*Cxԡ@';Ѕ9t1HocI\@8!8N(m/ŗ-*[L 4fn[q]y 8h}x0}w7߸{TƹS~+KzqD[j1f"E p*%!"aq=~jG<5YԱ#7*[+&;r2v2e;OҚ5䃙ؕl-jTtN_{WC}ԁ C&mEh EZAE\mǣb3z& \uPap ?vLi3M'%,adhTxM)9xt䂐t?5P$}Y7OۓK'hO΂Q\rڼ{nĐEͶ9Cu2_!D1I>Ӻtso|آiu[#3lPY1\/99̤s\ǔ~O)=΃ʚ.^_j 6BBkVψzm? Yp-ȳ*HwLew'@ Y8G Fk .xm)61S^(ZF1f3GaV^&ߎ7 mO0ԺΊ )loP<QڧAoȢ"U<[LG7eg:鱾, Ekw:޶_d] OfHym1I61e濘Q'\˕"PPKW39тrK.(FsP'=_`Sywִ8gC:TRõtր6ۋjH2.V;Ii}r!΀+O4~idjed*ZwJCc3oD?i2R?H ZNDEe7)b՛+:W(Ff~Ym&]8e}~s?B FT? k2W])w(Mќ o@\_-yѢZ>2śjW]9\6ugtbgnKD791e:ct:H\ec+:9?8V/~!Oօ9@/b{ٜPd'xEng,ZL-Dl\!fP8vF.^X"M'(:״kx(rі^"C/- T7EKYB()<4h(AA變gDU〲JÑq9Svd 3e0}m"7E:Zyf VLC7$#@F?Sz;3Įpl&Wѹ#"eZM<6k6ɮ$٪GWS_(/aydr;Ty[aZI3_&ծ,2nm0.QCБ'Vu^,8Ӵ6L#1ȟ4+?աw>-0l*s}02t&.&tI8?o"7m9&֡"lSA4.8 c9=`TP9Kt<4JW$s>=7FSM;c.Zc#Kn @[ R.LxHx%D-jqp'ng Qj8-u#4h>-,ց"HR3ncΓJlN9* T5k-Vc^=7lI3>#lЦ$\m*-`8͵۸>VkKwJ7r,0(mԕ @flM v~y K%o8d 6 }nuٝ@*#:ljhij>`KEmO88cYz޾}Ot*2 oc6>м-uHk`MIN DZVb@P/HS ׍.Lԇ85Ї`rI2tC {45DS<\ǵsJ,*{u?|Iǩ7 d>JWE*9 FV fz~?psO# d/ ؃6iŪXpvEW@Ӟ@?OZ`؆Jؘ$$Nla 4NvJ4-cS2]B r$ǡ^+i75x_b]ӒvAhQuO 1n6$&\BT(tHY3$ZCmtP WAq)%'j)D%%\&Hw.ׁ]fQdt)o6c =xLW+ZҀ HL_hVH|o<0V=ANX!O]yj,V%?$@PmS]l;sE7id|aUVٵr/<K>hmw@cq'jqź=fsMじE1B(LOoF\DӂUq-Z3ke,!"xQ!CGau~Ӆj]GJVM䊚^6_@&*;rV$ˮ6spxgh!V>Ųɇ=*TửFU)Y#O"ܶZb}[Ngp쌾}/Ҥyƾ uzm+0m0#+K \{HmmA$8VP˙"3dpҹOOYұn xU>w>y_.ÑkD#I;h{/8K3 E.ޣos$GϭeуO7> t|j V 辌#p6 ߖšD;a5_9P+#ZUguΊTQ/oP21SG7Tx^})U}j_fcg Lv^F7{t\ou2|; YQ%+a ?g\W2ֽ+K I+uT1[4(r_I^5f3&Ef|tcy9f՘/[ࡧFRe>z,#I߭B$2(9W.%#2eH6`o|b:^4S8 gs@+~P"#"QBzTϏt`nWԽvjCyCs?P>:-%}}7y3I-"fa>ڜ8IƚyUq\E\\+q#aF&#A: /u qfJס J_RċG(ުbP'x?2Rj7Z\aӚ>\uNj>Ԕ˵dEXYPį>ȱVzX-tĺu> 8y|jw?9?)w S⁏kP1le/2`Y5e8_pvX†7B)KtKu4F,&xFusMwdJxvNNSTPV͏;<;el S>˚"&O6`Pl#N~~p  ?_?FjupGD@`BTɐuN d:CПY*8[m,0YU~JJ3OW[9Oxi)m*'Cd?y# v%XUe}T@TC+Ȑ7-lVv͞Epb-;ms؃; Vn9fR+\u$n7]$/": zzƂi=!MDɟYBd'}vŭ-;;Uap_k*UUEX6Kpf TS&Qg0@*x盧'svKL$E+Xȼ{zn:~`n)v jna^9|N(VOiRY)`C\WT!'.HjI`=!iۂ>?8@0tecvP!8y uŴ2:[ƠJzco ䷸|m[W* JGHS}G~Y,:0c:|2at3 mZDrJnv"m&~Xq|UW֤e{8]'ZǐO4; ΏSzE0џG4P0p~/Wʎ M~w*RJf3Ƨi*.:w7BԌ@S}mz!3IB @ -{vJJ u&Š,]A**\7вMuZi/yh0LJMXczW*P^<?9`|FAјǮ`PEK=ӕρY=>[rF)Z;M Ll͙&1 sFJL䕘37;#7"кOT#k׉Vgˇ~* G<݃A#x"BrqDiT8|ZAq[b'oXMQ|6;7FDZa|a"H/`T}1,9y.4ʻ>LX0z͒ HZn1\qS~w k5nsĆ`.{\$D!jc'4ObsUq+kp`wq~):a7PJuE'j6[cʈ|GWLehJMk_BMhM!x34P[Ɖ3R ؍u#.o474)i):pyŨɕ؜ǒIETu-Mػ8[Y" *5`lvdZ4/MրdEsd3ڮ"`Vģ5Z$j}\ё{UXb,c#h_3`dI 9|< ٸ*H&$3XK:y1fTkE!c'/1M5Hp'^W՞8'Tw~7{Ajhə`=K=8up )q]\_Czm7i1ލX*>OF 1bDW*[gQ u+9B*Qż }g}=568Qb+6.XCdr/n(/h% MY\}q\Bbᣳ؂8A5t%r_ldxьBt6.<ȻX^Uc KOJ&zr3.w5v$ n3Zu 3.L:h}zXFT= "fZJ[FVOML *rR:.$V~mǺu_ӎP3&9pTd/21jkY 7M;h Y JDCђj<};iuV90W1{5t$`DM@'[|aRUI _C x794M[RxjĴfH;oOguE!l"AmRckS9r5Y1V.Ǐ3 L *d\Pҟ)*7OCږ`bf\aq""n\t_ v#PZ/ՐSj4{5OCm(l~=0 Όx!^6]2EE˦߰ dZk|AmGX(bTImiGJ PYf>`$Ia~GE<<%2Cgn4DY5HۘS;܅ɈXyt].vͧ@q\cGK!?!q 8eΉuh<=W*Z~61Nke0/J/:rבk4΍aF /ApGv$lϯDN˚ ҕb(R F.ukS8QC^сO[ۺڶBe!O)з@GG_XI\7"{5V׃viŞ֯[`-f(}e7 jөZӔ&/9kXqj.ė'۷ :q:_ya:Ӓ,>p(.]Gߤ*}s_}""H.r09mԋIj}&0iVT$2D=>yQ\xg:G ? x8,+xm4j:wdv&q*5ii]]#U.!ȣYD_ϗ!DP޴KKK]n3Z͎6aaNTY;}HwIzUǦ+ZqcWWcb03wLǂ/hm{:Ř48W=<ؘBhƮ4D(S:Dj=ȣfg{]B`_AGyw{ہ6r/+:N_m6cǀ%| 9LbN^0dVV*"ݒ]@y ݞa iUblhwӢ7hPp05_bD3h7u>Y";SC8i7pzՉuT)6ɧi3O;ߧ/g~3"[pe~P}a]fD+J&ܨ} J\k]?XGN6fo"'rOA?Mex@J5L:~{܌ : mfa [_c 0 pV2L!q @qS.$ÈZum<1PUU Sl M'k#fTB|W>`)ձV-p @z=f?*zHs:y:YM@6X*L=ӫßP`]/K1[v3;+ȎWso|gs}: 'J0>z5  .8C3MݨH3{->|ETlF Xl!cMrlҺ{ ((wm0"P`>e<)uoktbƚuXR-\&'|\#~3Ntu(/1Td]b{a>W g61[jj';pϔt6_Tgmw׺VEB9xe wiĆ9#Orok uBgtLP(q{'PB*ChŞQp{C,CXW&{,3WGQ_iJYc8Þ,p[t2t[ C{'sb!)v {M<24I2)aToLvkz9IcF f& ܞi )ʹ !?W䷚Jro벛CK)̢kY'Om>G _IdnzfxI7Z̒*n{oQ0`+;.ȰHܳ遐WE%o% tC + {"$ b= TaU~+sj䈷16;rejYv4f3;g@3E?ne1vDjطa8Fn#ԭ '![}.!cND+jsx[z_`]9 ?-w`ZQPt3#'Nu쫴OohS2at5JmotK= ~bX !cGT`g4B tFg<%.@ι9eC5)1`IhopC?pQ"v1wZGl9 hh+vP`’3yW9334#Ϝ/JH%|cN%M\־@1Ѷ|K>\|@B }4ʱRCn˰,vl[t/֩UL\!+;/ӊ'ӡVbCчT[_p5F!crIcϼ:N׆>68{ ΛȟH IZ1S-1Rnq: EPy7Gi;.9 6S襕ړS?s){lƣލ~!$OBDN}^2)FTUC{O1?\!Zht:ϏJj*;)|_^+MES㐨s٣bdQrmhDH|l kZ,a,G3ERB=]|[ DQb ?#R0LjHj-hwꖤy{KhH2JP y3D2YԽwf& ;Z#ZhjµC񿀵y򃥑0<܀A;%3_HR҅\ .^<'-~8jƈKcJ̮JvCϖzEfLGXkhj‰R<..0N!ņpsf8'΢yPxb+9JL^PtK}W؉ӵK-|ڐ3IT6GVX}J V[U@۪D>"WMYOOy9བྷwHW15jϸVa L`NnDqHu3(vY<e,DWIE*hOUM<+Da|R&OJ|h !p I飐;Ψ3]@P"R:} ӠK6(cpԗr=ݴfm {Bsk:9 ڝW7ceyg*;[1dG.ռ!84=-k3Xܭ"yq-7 5".zقӨP !Cx ani4Ȁ'?y٤4U%99~{B鈒/JHMt#/2Nqm{[ٚ;t쌻gNN4m`vP|e 2G#_$5}.]uC:HpٜI0'lMjP駇,yDUG1d"(v[:ecAم(!Y.벲"B Gv{:;ۄ܅؄^L^2UbmG>"}b"!7ksl!ȹBDs 9"Ѫ#aȗuV'H]%dя6$|}AZ)v.Zz-W E5\s'z!esfG&  @x?_1wHE吉[p|TEW}&&<RewtH*c˓zW>a疒w%H{ -&_<WMz>VNC@hJMx8jLA\5 wCܐ_:עk xZ><|u",p+d+|\O m_죄7ev[ FX=c+ ,cZO3Lx69eZ?ʎA_<=HE&r+Jк&rT[ υF-H;h^k !hi151sZ}_\L{ADA` }c:H6!l@C֭X.7؎z@evH7UOqp!e3xh %x`<+ l㾟RE:zn]('LrZʉ_]hq%uUaZ}%\?Fg٥)]a0>J01 p`RQýEվc4]7-V .dj+kQYDLu OH)H_A:MCU73>,73B0?hDE`_F򪒥xoUZ?NsƳq34r' b؆&Ot-9["-syMNL#C;p ֏0y_ae}Q%DQ-_?DAHH"C[qx"ܬO c?X1pe"䨅H ]8'ʮzq;{hkQ2rYlrY96T|q$U1X2Z{ղxGn&1w- !ڗs>YQQEfTw0#`^2OH;Uc&vh^wuDLٝv?gG̛7\J6@w5x5X/",onJl5Ɇ:WNJǥ],8 CY\!E[K)§ij<`ye@pwa|"!=n~LӖ,CuG+y qL>ޮo0kg5]((mo DATxT Z4GCx) "dג YZ