sssd-ldap-2.5.0-1.el8 >  A `çU]Hi D(@8%Nv&N ccՔ%m!LL@YB̊4 Ƙ LC;K4B||~D%D 8pA"";}ÔO ;yP*=ϙ)I$Am`C{P}˓{p?b8?b(d   6  <BL     :-- - |  ( 8 9:_GZHZI[ X[(Y[4\[P][^\ b]Xd^e^f^l^t^u^v_,w`xaya@&aaab$Csssd-ldap2.5.01.el8The LDAP back end of the SSSDProvides the LDAP back end that the SSSD can utilize to fetch identity data from and authenticate against an LDAP server.`åpppc64le-02.mbox.centos.orgCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxppc64le) KE`\<3@ V AAA큤`å_`å_`å_`å'`å_`1`å`å`å`å`å`å`å`åfd4ce153e831ce5fde1f852d264f46d159cb49b5da0a059967b7b92b437b112e8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9034b89bb4933252ee6dee5c212f3514a5e5cd38b794ec8f624ea2777185e07ddb7c1ff8634eb2a5cfe7d0a84a039642f5a47091ff17397edded7e1edd07eab65853c036294d7aa6446eac09941de7347bb181648b80c1cb039a42fb0cdca16fe4ae040d2deb5fc3bbd3ec3e204f4f56c10a08cdb3034e6ce54ff269fadda956531d1f7def760e8d896f6afe5e1effdcfef4fa22e5d8e23569b51de5da51f4c7b8ce9515cd75efb5765d4aaebd64405cd941d2a778c555a49b607e9f81c65c90c6c3c12cc9847615f322c2c48bb03e0f9b7298c01c10045417afe144832eb25f620bfec0838314c53d6897cb7e2fc132660c76de14e2c3193859ad8f6bed4500f50../../../../usr/lib64/sssd/libsss_ldap.sorootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.5.0-1.el8.src.rpmlibsss_ldap.so()(64bit)sssd-ldapsssd-ldap(ppc-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.5()(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.2()(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_certmaplibsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsssd-krb5-common2.5.0-1.el82.5.0-1.el83.0.4-14.6.0-14.0-15.2-12.5.0-1.el82.5.0-1.el8sssd1.10.0-8.beta24.14.3` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) esessvsvukuk2.5.0-1.el82.5.0-1.el8 .build-id1b23083c2d767a08676028a8232a32f9f762372elibsss_ldap.sosssd-ldapCOPYINGsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gz/usr/lib//usr/lib/.build-id//usr/lib/.build-id/1b//usr/lib64/sssd//usr/share/licenses//usr/share/licenses/sssd-ldap//usr/share/man/es/man5//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mcpu=power8 -mtune=power8 -funwind-tables -fstack-clash-protectioncpioxz2ppc64le-redhat-linux-gnudirectoryELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=1b23083c2d767a08676028a8232a32f9f762372e, strippedASCII texttroff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)&PR"R%RRR RRRRR R R RRRRRRRR#RRR RRRRRRRR$R!RRR RR)utf-8d9eadafe324004c47713a80e6d4717a53e336544e9ba1711f4611453f6fc37dc?7zXZ !#,7] b2u jӫ`(y,xoI (%Uoٔ7 ̔yi_Zs;0e Ns#Ȇ3y3eS⊓͠8"v%"uoN`/YdPT'IV/;IX_`E~?P lϧ`)@ ( ?~ռBIyWфRRMfSJ/KaM3 G/L8])ځ 6?48$z4U6D7IqluF!` #Z@jJta֡#=HљORj/JJG5M?h}`V3oyD>ӐYr}Aa}$Mܽn:Zp fF^2Е}a3CE4L_Pश(Tr֯`N.:TuRt a^.'W,EGKIl}GicATs~* D_8~FbAj T|p-{bWEDp3kX`ݹkkSc?`dEi^K3zى>4e8ȴ:4xIk5Qh]bє5QŤhJ%T5RvN[o071ĺ ɢX~&'NݫMf$M_w?--pQ?FCd(ӯEAӹk-mOΰPGH$i5v=l9p/ s0S7~o{^yԾ_J;7k"j^nP3 Ei $Ӷoɹ*>|02gl:?}I~huMxh+W-bO*6.K }Q1Ɏɀ( fׯ\,#{ޯHZS< ׵ECJqwhLv4ryTw9P21 S=ZO(;"J_U2A'<`ű݉..&/koՐļ󠵟mÚ;; ۆ]aytI`Eӓrr6S.@q N6wבA(W)gƥGZ?|qv΀N#F g܏U 4 /٘`kd C-hDmm͠cUtW5o lPeNnݰ͑I}tXںVzRٽɰj.ox6Ҧ*+Jt%騂i߂Hkoyߚ;,ݩp{6}g}`+F'G.N'ML<&m;Q LW38hAK6w8w3q7 ҀE_F* }Q^Q}@[ J ,}G3s.֝xe8s ٺȵ^"TZwߖЁ)xȊ N&7ǻ~ 73osG[ʮ=pO&l2QG('FG(n*^vkg2L5*TD5D?03N+u3h g";IIByAjwx'c=գ4<Zwͽ?퓇;z%A7XI(hߐ;Q_$Nt3kė,'Jgc!QGW#AJڞТ%z|6}l h.eAZ^G[LM/]9~rqw - մ[j;a(ǒ&ZMotD{.#=Y &?&T4;O9skuŌ3_?btm?{nu"6AžX-'օ;{Jo=$s<*Y6:bT*Z>3/hʥ$=kBgxI%b9y]"oX p 0 wWZ\I,eݗOO &d9dt2HҦS\S%{-Y\38Aޮ*҈VH9}D};tW7vw͞-Uz4 e!UGmۓˎ܁Y=1z"?@[B5&P4D(஖(F?0 N*%6O~aJƛrl CU4REՊ ev2Yq"L0'ױAѼ,O*<=|\p8:T ^ 9L\h!Ȋn:Gmy-SaN)H?廟CٕkTׁ`MׂU~>Z!,g9ȷz6M{?|vtٻfkPi:U6|uv:w.U{>[Nd?;)8Z| 7XֵRW\*Rԫ{ѷS3GɐiN@'עKcGV[_ͷk4H)F))~'}Ikd =}m:Yʜ7nşYg:Vu YTz>b pX{sOt/͂+5'K?$-Ku*}DECnPRSChb(xHvH!Yk\4CSUf'scHI#fsp c`ޟcR®OSB @b'+28aX5o*eEHՊ0COA4hlbt?FFrPq ]}ĮSGF]p4 _xaӳ# R~W %8<2+6gH#cq?<=—#MpӧrP7rg|?L+5gG Hh<fYIwȥzK DHed"}(5b::wy"g{RbN^tNbeNwsJe"l4AQ |Aګr,HlM o`$>eO@@}8΂B;4#/}|Z@kUxSU aL~4]U,VUo,<܎ X4;bƟp߼cnO^-۰2XG7I֯ PSn>)ЍR_JY4fiog R6q"8}C}ˋSgpIJ;A@@wr\G/8SM|E:c,pЧ_&trEf(bg*N)҈?_ϙ<69 "3Sw5Y!݃ׄ~}Cnڛ,yE~5L nzdRcAGZfܵąј@w ׀2xf~#)s0܆ ڳBխÑ|-݀B~Iu1rfQ2l6JEW!е:"JsHX񇤜![# V,KT5T+ޱD1 {vt S2?kpBGH hT%7i1BV/"lZp3Eu_ N!FG+7K0 ޻JD&8 =0iq`K&`&׼{)߬4S˴ћNmȞh@\;AFoQy.vp$D})/W hpV(g( a>u\/ޕ/iԠUHa+M0&Ĺ,Ϋkj]aז?&6T" ^aKu:JT&qi--y5e)3qdwVC鋧FƔv0dCIz.|yXc|SϺŮW(0JeL }±ZBW})y(kK߼q3qM-H?+jgV3Zi}<"QZWoFϞm> `/xxd%ɰ(lU!{vJ ݠP]աɋ' dܔJ 0}bL2~fl<څ_]yDžvI"Ly"C-YT,Duƃ>>_N1,J|!N9R/h[ I!޿t 5^.":COV|8\(=;H&,^L4N@B>b.|>Jjpv{Y-,> GAӷʪґM@EMBPg5\2։5w2Ʉ;r-OZ4&7Jm3&` ݻZ':ywE; ~!G8P\zc٭5#L)I v5<~Nm GA*Y3&7 8PĉJc!Ao(Se:$6]Ľ_pP(Il1ARlCsZM>/m@IY~\q_7po XRHڋ1(-h~+]c'Ε깍W8$6G=5x2e"= AB+}iAjXgMQ߶EO{APBLQCǛ&*ʱWY |?vf9-6z; !FXH5=ߛezV.B^XU7jIhI'K8H PTӿZ APWFw\mOmԛb% TgJ&7bԋz*.++A`m7rHvkOV7Y kphp~דYF(S#G@<ʦ[`FMI X4E4dÐȹ1JU^(] P|R9 4E%/$5,K50GٯO< }K6V[9h#Q!N[q(vyv`k#O̪(g{hSB" p*ܡxͺuah XAE@,6.EHz+}RiB66Քd pnet>%HU# BTjnH\Z*E7BK30$.Ws['B6+pb%[%v4r#_JxD%$ w60Ϙj_STʞQzmo1$Z@ؿuDl{ȾxBPrpPϻEiBwfP%z]0*]&qz+^g eʗTxAQ#,gm^&w&Sʭ]>.Tr9-c~]O::A~-6IٚO6P-H:ӷWFdfAM 0ز;]Fa>M/o`-9>PL"^.+HXu|wGR|9ʿ!)J4ώJPPD\ )`(cM{[PtWpd)yTa.Zǟ~4q'?4,"6B5S`3fu*ןCy ^,s"񢲐jvcVʕ z m7z?i\=K8BG5!@~ ؓ`eDsU hKE^Z(uu(}pMT5DX trvuwLs%( [g50{.^4[Pe-cٰmx}ׇ,n< —'Ͼev3"9)\OuBg4yXZﴗz$WsEχCCy԰90>TNIWDO4/}nV^׈|6ſX#MC ,0bA{"eЭHd2\|*襜SϠq3FfLx<~W>Y#F|}<y#~Z]6!%r O0ݖFDuUԑ'9K0bM?.nMZ9Ϥϛ'De c RZFl|8w_$ٳҖ C }48rܯJ]f-;8Op _GHj9d!9 "_rHAz z!gTʩ>y^p92Yq :͜{? Na 2R5Xaݚ&|&"_)}҉ݹY Zm3]\BMWo6=gL[#9vm346ոN?@﹄+m#|FoQ?wL'){pb) K4Lk]E9C:o;RWc8gꂕ:aQBP:њt$5ڭr!BNLzO-O?@zC#vǩ=I8{\Bjl]0zO3fL1삗Jwh"!ÕFtBLLheXvA㟉HhT"i|dlBM251`ԙX'kmm!ȋ8ft/x@kuHRǩ膏&xe?NE.G&!&uhL_3t!LSM 7p3y#(up$*Ka)'Ѯ כ$9\J .{-J/ "vQ3*ΕKM8ȒH@>bʶоŀ".GlW`r\ (ek0d[1|P_Kd O #v:JDG?`O=! /LU;U~]g2WeGtA¨QE,-M.yZf WoB40=|)K7nuZ_XD=t&1ɐ-?y̛'8Ҙ1S *m3۵݌0N_Nh05jpF|db5Z8M*'a$s>c Q~{9 X?}l%o{Le&ƀWt 7[ǫ`v}ٻE~=}ICi @s(iF3یxI6saU[esjۘ_pHY&2{u- :-TEoMwҶg`ĀВ:oG=A8)߾Nc#(#UZóPGHgq%ZT~&,Jr&>4kchq"3 oU,4UBm#Hn{U2']5](˿t6?N(-M@PU_! [*vs}& M1HPS-:4 _Gǁk?-l*1sɍn(7əWIO,@@RЖ8%;BVu贙3%eLAnA(8]@z77r wc ֘ϯx:b!R?u< g^-ݱhcPgXwϏ|pBbAڞk1T^mm #X ʹooNb&s'X%fto`}Q~'l^?Ql79M3 3M~0!2z=K*@sZXPDN o/4Ƕ> OGBm+ފ ?;d:1=8Y];tc؄GGM 8S~T7zV^mu?gXtCFNr|Qr~'cgZhȣ68mi"eŋ,FӒ(g$ܖ! "&L&Zw1g݇ yut+ |ۛ99Zcc^2h%Dr`b锟ňwBF=u{_'&6Y\ry.U-/y խ6M?ߓԨh6k;+!/)Rڸb%jĴ6`/ٴx_J`c't$Y Pk)B۽75&T_Ym͸qW /UJ<,ɠIa >Lz'{ꥋBZΒ"/x `sT=PC>ﺐ%-piqBx0Pzbֲ $K??S|r7"pR_PK8t'PxurxIym9Q8wۺ^ЀPr$w- DwGa}oܪڏ6Q ´焚 ɶ*|Gv?sq鍚aHm{Sv!GE;Vs؎ǣVpG#? {0Bs +>Ŝ7, H Msذ׵7+f*YбY rcJVC\ZUSHSKh斜I~x`${yN#Z#瀆u5Mmv:NĴ Rz*ZF 3JJ(36!aⶁk[Xq[}nidcAhw1d%PP>%kH-A.“c|곃Tm_=nܡdŨ^u|y+4u.<.=\uћfDVG)L2'N Zr@퓍N~; Bb}Z)R1۳DjDW.zO l P[) v\ ~2\_):U֪ Y@LZ4'g(G!7V/%=3SpFDC`*>獿.,bj_,1. Z&Y=OvE~y_ #lNrxCYt{гge} WUD]hflB^-ˉϿ-~fPn[ɩ!/c18Xg0lT)>>Tpi tG]GIeT5®8¿Pzh~]}ҀvΛA3}Nsg )C, RH.<,qJu5֟~wmT< +1\~ sN/1Xb~ _o,51( \/PnG_=p!@XI9Wr㆏57WKjmɂFŁ?^q~6s>gإQ[*]>Ol/B x5(ąE{5Ti~Xe|{UFV7"x%bb}$\G8,s)jkF ⩦(aލlWՊ F5ƙxa$;("$ \)#pb,(Avi+Wd417y7Lo,85w,,PfꈒxQ9ъ8{nUhxv>ӣi׋w^Fuʍ%y5M !aD'!c4i X6Ռ= wOx4^a8";s~E+Α?VK6EkMWOWaݝs2TQlh:1p];g!7n$nwKqu@3 ci)w:L{aёN`9wS<֜8S7t qXjbk8(j}jD~wp5#EdU]O%.,ļhE1uciՍknA( .$ăITkdrR3 d]Qb@faz^]P # r,mh t/\lŽ[&tr;3ט&8`E)nܭW֊uUi~rG xy2LUܻ{48ȧE~, MCmΨ}UD^!,{Jv2Qmh]%^jg1d%]*HS?&d Gn͟jd?srnM˳ ޳OJTsl1vl+/RG( 2p.3We{k s< bbmҤw[ԑ~ <ߊ6I߿+8l/ e:ˀ'oTUꕢ]^3fuZImVt W"'[gڦy赙N `|6k?WZkJV8AcVm;)!4^vL|:@Dp ² ߪ)?Q^ew:%)QZ";h8/o+}{Y€Nj@JXw3[$Cڲ OFK[2 Z2qyD&4W#r^qeV7c}HoX[KŢٽ(dp~Y+*Fq4SD$tm3 .M.' . "=!,Ulh d' 5Xs-K3wWUXUc^[JjYM穲kgkdս}[)o&Ϟ^DCq=dbl\O#l |ܓ0cYpaW}\zjih B8 heԅ6fV7\~6`E*r!Ztk(գQtZ&MdYy4%7w︌ҷ5jpGvL5S2ܵFSk9+s;r'id*LO0|$?z18LцCyd9윽)pά Ll*8a3O9{u΂H`% zB7'Pn+k.WCdd4v ҨYONkgxk ~r@B1G;w %Q@eԖxew1 Rzwc_$XO3s~FM΃|k* кSp֣Xm{)95HVA>.Qe咍'kmJj}"oitxӂL0 f&}4c2 B{S {)4Ыg[$iD>*Uvb#yx%ڵ HNlv"\Pj1:Swvn\|\Rن#Ze1(Ĉp6)R%ĹJe zZK1.:KT,;7&%sN![_2ISKH Ybӫ1ܽW*Y݋V\m梯&?qA;FGn`3]/QRD<;_,KݬlzŹǿe@bčI`aỽ oAEU^%gm)M׮nL>?޽)7m!Th5C u`_n斔74QIS]vď&}*A +L݃fby*gx[ԉPLWzx'KWooS x%ԏ($Ă?yME.ݱ{g3Xɩ#gmb,!ԥlut>?SUs'~6:[CBgXi8n_NOgm U2D8@>nԳ\$A%kfUx-9~/JH,$TDŽ~As huHw}<c j Z$rI&qH&XS0s8a@s ,^[ވ)WrҚwAtџtt4˷C GV ;6,de[̜Sԉ\xTe_WdHtm͟r=Ia0}#9-QQ'G{uFrJTĹJ4 0M>ssQfCV~(ĢElvѓyVPt 9xn{,u!duȊ=LŸNQ6um)136!V  7E,EVm])8OLRj#Q>>CZݹF~%ԯ n![Rn+6za UNts]{ي|Us ܥ:֭)f&؂&c~yTv Vx\2EgKQe\iU$14^'LMH%cѮmמ :?& n*&V2˳vl~K8KN:V-Ю+/' 5 G0SϺ\Q/D+}1k%]js*T!eǖD,?J}{XCvug>;鳊rEthʯ"#yq'g)|v%~&ƃ{7aỦ>~\o%LԐ. 5{ng2O|8\ WcsEz}gʛyz'}E 8 9nb BȍC)h$B/+f&3}AC Bu gs$05c(K ǧחCQڃvwF[k{f(vLiBsi%N]G{D*Zhf7Z| L6=u4"R_I<y7}%z?&Sm3X/juJ+K(AΡ\s7_ޢ*h:tc+b5 \O4AQ%F,G!^FO`ፍPo&*>~8bub{b#dL*=9 Ʃ^q8xW?FJGȠڄ.Ǽ'Eoұ4,B+Ps.Xt|:mCd~9%$*c$q$|AreV/ ] .m'U!DwuB5?DUC rjd;@ Aeg{&xk$A(Nrhgn]>'lgqbBv.]ǀAsaI9U+s($X@ެ`c {{>Q^PLd-h\D GZӢ1lmnyZ2_lo49WPO21;yZ@Ḡ0H|Wj=2pѱ_K/D#Lg?|(3\@ rֺ1\֞Vu{0=ƃ]V~YSZ:9OD;|2aCP_6eѭ"ބ9~k'n:&jLOĽ%)a&~ h8 k [ŧ!_ jb5DG_!Z+`yUSA \NvbW0#={J<T\'cI^-(g*Sw;[\&sX_.N^DޅMPh 8/Q.>39aDXS8=I}$za;ԱI!oRjV R+%eX|[/׎$UDp M}51c?ʽt7Y70zT;*$+mqTmX-d4n -]0*IC҉F6(nä҈7ちEb?t-XO~uX?t~PGӹPg{tyS_!]͒Pga,{n^"Nx7sʋ;~LJV!r{VWdك=Iph) VW ՘2|!w]}i*JzU?kyTUMOI1z2TlQ,` n 7&YWx&4XB64Lʟ9om>h!BƄLwQ`n#|T~h<)TuzႻ_@*1WdRg\* PWw^:d%W69ry~DdP0"KS4wf\sӴ *X\`D\-Y j^/ ,".(QYj`)/Vc`5*f'>H5Cbh. ʺfνw||*jH3cbc`KD_S_,9wuzutCyXY.{ %Q?<|~|JjeE-ﴞB׽w*}Hr)۳Q%+[ $z9/6P9 g+Jh3SrLJ|Zo7iy" :guzWg;67FXZ@>.o_!+d]$a$ʧ' .$ƙ0~o qHb,su+|'a 1|T6'Qul [LɊeU Lљep3ܙAɏ_ !/T0nh`SS)P4V k̒*'|[{(XNq-U{R(0m.DgU'ORl K>lsd[U6ٳd{+ŏxg5AVuqo5X^=a/-7Sp[H}w3t)jJ@XQ6U-T\a,gIufӎzdDll<^D3T\7^C ݅<#RmXlϛ!77N XbGV i7#y 7OQwu z%1Q oV ykp$CQ﵂Xpb86㞶_۠e5kNNV^F={4E{FOղ]C5Jyx(T6#2^Sj%Mѽt~,9)?GNgp(?~Pf>UOECUwBAbD;|4ᑧpB+8gh_sЫk=h1eOFHg/0`k|=ÚS4C*<)r@-:>G^dΎvtuC'=.m6e*sX~ۋ9F)xy$rdUوVp5_!aWtge }|p^LRbzJz 1gGhFYCb)+n+!9_u2LvoA*?+n1#Sm\EBD]-c[ ,|)>UE|jeme0_qyqRD!*J:"A_ŀ @'lS }AWdo`gJA- W֚j68WA'.;A4A(i0HwײgA[x>YlajCh;Z~ ;x_P6W>Uԝ}ixG©ҹՓ .ykHh#nk]\@HEMđT#'ybSB>$|MX$YTŕ(U`,u=]"Zv`BqTw(U)ƭl>> @Tަ-ȀXEE%/id%q@#fm}̪* Ii. +}M$c1;"I*\J]@n?;ʡ^/ˆmv<'bO9{L0+[5W-qXM[& n(9 oBc[`eugnKcDY{dhxG؏AûlB.379R}tVFJݯHCBG5K`KW77(#;%4`>CNؾLJF 4|u&$ ^vc4lqx|g=rӶJߕA:̟o{bsWGq҈6f9忷V sXߞ15T$>*f" pǿ[WjE2g-(>r¸3/fvf1kH5 5N@,Var㙜?ÜH[Ek)’?ʇ1XDcf?4GbceXm+` Z1!U#&@`2<\o1sʠ#p%c";"0O.6ä%Ͳ+B'Rc@YBrq[2Xnk,M ܩ(&=ꢷU{=ީL1Yo|=tdDnt3Y+./$A/[niCM\%8rJ堆S&< @V̘:)MYK IC)u@b 70hXC L=̡Ig ܶa>2M>dpTmWl"M78߇-F@ֶ{t}S\=ˁsMÆ´ã`y=ٱ0f+ddF&̖+$,NqIQ'9|6;Ǧ7~hgV#_ׄ aRؑR;%t8JtrtF !(xvNz&4zCn4 A Q\Sl#v:UUN~(4p+2 ,T3ffK֯,:ߤ{ʤ؏q'*/2uw/DNF QWJ4'35R7d d9@ :Nlyr8 (yNk0J t.#SK-KlRn YI_+_mށ ̣Q\`3PW;vzNJ+!1ӰoOB30ڙ/f@4IcP_an OpٵxD%C9\ UA} ϧ}\5$=ؖ`. 2lLqg ]IxH~<5,PDӈ3'1DbM%WNhni.6,&SՑ N]7]] Fa= Ji= ُ9]]xF[~N[ĸC9'y &J~ ΨN8LrI>?Eoߞ2P[K*Ef Ty*yy!MB |Coo0JB >ZdԂgIs@u5RoT>)6o+ VteVPRw#A@ueng8oA1R䉡y}ZOl݋Us:PvNá+nSMMI(S+ОbϳM1~y~_%F 8 YpGQ2썬)/֑v&1ϏgݜV<'NjjL~VAN"Cpb^--ja!ܥS7^@3q3}mTmLUeS:eo+' ^4&y{N5 -snھcGn*~I80ahCwXgHPa>E҅4H}Sͪ N>jvONu̓Xd8[X [eRF#2y$d~p-­Bw/ޝev’{!wMDRMPRlƲ:5v{&mvn$rDt)DH'K^# EYz\4 <Յvkgn!ٹƚ'J1], $ w :K6H]Yq27܈UΉ:n #3-Go;o7]#Jxk7HQ쑇b&Y0-!I".KMx^!z0qxA־r!j1'.8(;:Zj=ry_S|>j[ls?4snruCB̗W5mD31?gRT[W$T&p!vBu9]U·(2A"U+ \g a?h(nB.Gk\D4r9ods <Iu#S x5xĹLHHsezL#A6"-C)s.PN/P!!-p7K 􉿜$򭇹nviq4IH?p,碫 ҵ4"2()+jѮ5lc8. :ܯډS% !5 CA^o#NeL"OH",Id;m֙Y ۦFB(DC*Xt>fZޫ$aK3A'!x@RcN7lA@AY&u}PH^08"ꃉ+ c )i@Bҁ4 7ݥm9:] "_yiiݝH-NůǞGtw/FDݬR&=_q%njW/fC8^kJ@^A+8"S0Ӷo '֜ȺE+$b|(`. ` +).SIlU(蛐D8~c7'P; {)ꎶ>VeOR8wB29g'2q~I.]COê1Sqr4;Fr-^ZzoAk#le?qghiQL˷=F#tz4!69agq<=V h?jGv DhڤYg\vᕿNM%G|㯄T`}$ƞ v?K{gX3AP`7@HDPd nlu1\=@/Yfo[s,׮Zz&xm$R cOz}L~7qCS&Ƚ9ࠈSd/^%%;{6/ O[zLi%"86X;xc7ۙJ~|. Qޠd&hݯ;9(  ǥz"T>98ۙh[K1FyM>_X]SV@B.#MH,IlWjizxцego%w/c4'_4QEUnq:{՗.)0] dM~>Pd7ol@wq uGA|T|sl]&5)ׂU$w֢XVh@ffBbg %T"0n:6]|'AWlcEv}T4U/bF0rϑ{vUr=*q8ǦߨǞe =-<}V#tGWTuo𦂲mqs\11 gK'L:U::4[0܃Nz}0OJ(~bsGD{$fpOjKo""gUa? dP&ik!dR3ўl"xn֋/A)4YVvQ+5Ț{iZܣ,t?9Hh@%-֢k7rc6ZQƿp|lYuɬ/aT1Ʒ\4tj9d1mK̆g/!(_XmXv܋UZ5eǐEbf'F :mJuqӟxd㎂gxy7H.UI/h<, WfIE1">_Lw l-jWa$7Bk_Á_4=9  ;ɉfc| i4؃q#%DD9KXPМ &D"og1 6%ZcdAnbb&QŪԞ{ʶo%yg᱘m'Lhߥ$ 2}a@#0HFG{'Za0(~#- ӯ|Kz%KI5HAd՘PFYwoVЦ5+>Grpy@CB$A(GA;""'n1wNK~؜Aq8 o:;=j<ئIDv^䊞:p/wO"GGgYiVe95F:c͘yPg">Il%`fX;VKA x5d c _4O(`J-ux$.qIa3 xV\M, WYѱ,tqsHW"p7G /Qh5_=(5Ju8B mI|):ܭd쮺dqói#4CxJ\WT}͋nCz>>wE^hj.lKqLr\m ku](\џ/f=YҷOG9[ǽCˍ xzpEQC;Cp]djJ:7զm|'#iJE<-.dӧ;JC@E%gs{:SYk̙#fF&)Ah?nb'a-dM6A0yRS³c)h:ј94B.y׵v^Ξ1üy*.k/p4HIItha[՜j ! $ٙ~T, eg'шZ'yt1+{].qUm 1ߩM^)}S$8wxsJڕlaI\OFv+n8*dI`*j1VUKM{S9\qN1eޢ8Y mh7}~IPΠ.8ߔ [ LE~%f7FT+k։8|աq:6~w-4Q/)27㦫Y:L4d6lcP7\hP6vBv-!x`VWH\JU[%G> , 蹭N v1N>TS#kKI(m ˒}`Zē %te-A! 4Ԧ,7]Ij!t".LyZEQ(YE=Enxՙ~%vR8ޓ<$@uڜaq'7ħ^Ҁbx;?JXyH옸w>u5bHFkp3SM1]Y] >:pab4r=ÅWa(֑\/Ŵ f)vlp\ T0PhYLXhy`#J5*D^~,JpT6 \Lvg֐~Fv>G߹:G#;e5]YXN3N` tJ8=#s,FuQ»:XZN][zo"K|"?ʺc :}L#.7Q?Uxj O!)swxm'`3In5]^5306ђ쇫՚CUjX.xo,ɜx [ܭn|JO%hD+'Q[Eר]dge< lx~9@]|fރH i}bGqz}I-㘈.OF L/NոVuy%L-rb 5OF1 ɏ}RF:.{"| (t&tO-9GH]T<P!@xFj1͹D퓖ΆYPK^"oʬDUU.p05g}+A>rn Ez^[:5.߫v}UD:][疖eMcaeO+B_ғ噲^(Rֻo/6eY$zIUɐϖrjLϬc\ ,,+q*MSC;hfT)!TF;y8qTOB>nZdlb[ ͕Y^r& z۷SnDѧSS_S> L//Qǰ=Pܜ6DSWxD8A^k[r֢uʚU o)|{=v$sF2nyt~P_`՞ڼ+f]\k${5Ӹ`ߟ Y 5}jߤ\T0{o??rlb`@,gv:_i2f[ -ޒqZʂEXNM3V4Fwǝ/x{\,LF6"Kt Awb5QPцA ],&p:>qܚoP*C!1h1H@Y٦TW;%޼#RgVQq h8:54suK*UjWf\$w M wUt:K6u1H4Ѫ$)seՑC_p;o3A96$51ĻRgDL̡8W nxٖPjk?~ 쐹U-X`et'4Kuzo&s䰟ra ^H%"x,V {ҁz`=bXSRe=uJʱy4pp@^ܱQ㮐[˧q$?vI;! A>PP\e%TD4Z #K:28\ >"ҿ藓ĝR=t b?}򽙱gpFb||x-W}Iѩ2a2&t.Bx?lm%{w88c*B>n  =FOZ5 }TKʄ=ı1?!o$\=D_-=U.|Db."p*Ub#\=%E&k>ZڕճZrkYsZz / ɭ;S&H†?R3Jlof|>Nц M$Ûh#Tv?Dk}^5@z0oD ΰq!zQf ~FrFHWXκaD'v3nw@?pEU5^wz mjZn6qbWnu zKhKDȜF fCr&~ZRupCu˔+9TDgVK AQJ(lǮU}pL~>>b&8BG(v-$Ph{HOI~ 4ċoz o8KmPVYc27o]OYY;DW1͵o!j[1o$ 4դ?TkeǞmfAS^ApH8gb=5?ten"!qLHN$?mڎLJ]^rX,UOmz9%h)dcu¦ov| ӮK&)hAYp 2$h*>?owuL:PB2?J˸0hߔ9xy;hd毒؈Q-U/? (0S-)ˌS9͛~xzk=ȅ}Iw՛Sޟ%ɀ;E楕qD!RaS$(J5]R˛ &7q$TLÿO9`-SO*);CbؙV4BбMGJk07 _ք+5L~E7 `:hM;Y9çvΡj7xh/] UƏ7wpk zO%KNuV(a<щi5c˪z P& cCBLE`tT_-h4ɠEG"/ҒgrDEGퟶʥ\Ki&xPv`ŭs}GȘ0M}ZA8TuCle n7Z[3b`k>zD^u N*X5_*]Utbnvi?VˀW'6.Jlj{uxUvef2_~rYI6tanc!0G*V:wl88&iM(v^oEM0='CPWp>N<1a~];6%ejl'_T1uYOΝb0ѵn޵un*Ua5ݪPiz,+˚ ?ݑ+H8JQeJkc@4~/+_!'@胗d"l[~V{5C iVMب'R,gO(t"F lFx9屬 (Zנ敻GW]6,p2pWAG,͙G[{ak w:I<> J4yWkrU|_/S jGb4CĦEBr KTIkJJ[膻:obJ$r#Zw E*Z$M*ߜ d(O'EPqT=ʚdW9"FTc1{E$! ;D8ren5)o ^lw5|(a jk.Mvl΍+ 61ܺLXZ"xJ9]Je цW%X'"\q Y;Lnljbc{ačļR.y3zc|6noWTGX\LLu~r iVR.U5^k{DFN-&ƆȄ>Zu;s8_&DŽ JMLOM bHTސٟ}0xKOFPA/7`[[=ّF"ba>bTA&B9bkآdTO=b-hL:h{4Swi[+ښ#7yL`WU `vK)pY%kٶz,Om<% `},+Q[^],1s}z"*ض @ʸ[q.B-uOTe Qꆈ{0eoJ{E~͕3+\nCVjOU%BYձPG"%lO7: Q ApE*'cᆱP^}v5>ډiLPPj K>=bpLi/.Y^{d,q@TR/d5#,vMEdBYrm%6(TAA\#@!~?\0л^=7D**8C|UW_*"Q=CtXZzb+ >y0[:UC'fjIݫ_PL)bCYMvqh3G59)Z~e̎)6(٤27EֵQE[(te <KeSxRhƹ$) }hg[k@-( 9: ث |hjr3TdʢGVJyh8[xu<*? Q{oZOh(i Cx:lw/Cb6h&S?AZT>N']=:pǿwmXѧc=]-@W =4M#>H|.};YC=jg2@hōMm6 q_Xi?# ldL %Nn|>9zy0B13ΞܽR_z~@}?`La㧥KV2*5(`ʁ[R[5UD=8MJI*8@7IP 3V#R\kc`kQ{#IEYpmxbISDž2dPe}ELMa{)K}g\yv2oVc7^R*̅$0W830^^C6UA.K>vcmcXf y+VQq(59o f}B͒7!r>&TLSQbgu@t B o]7JiƱ&} VL5C.Ajf'tfe"fHiH`+䲍/tEgHB+- ppaG_:\X+NOIK& SGZ/ȘKuSU`+1e91O=-20#]rRFIL MdSqt`h 5VzuUi ;tg+DFL!9hb\wx)ԃ濲khtڇo!oIaTes@b,/ YrKP 2??M{]TYl=JkQ)e)t#WSyh`Kf;8C@ݿAڥzɿ.SP#t;'-(0^jaWn;"1-=MT9 ~CV񚁑HU7[%FJ5w6r-C*ӱng¥sLb4dmK0^1jcԈ㼖ڪ~.Aix̍1,BQm +޴l{d#yŠ)+()G%7X#<؟ Ր77糝R+Gقou&::2TtӽZEٟ* &Wq!(n|r|{aL<՘O)v؋9i ę{rdڒ [B`u6 ̢d4J)`j?1dNIm8+'um6Q߅nLiE)wT7퓡,D-R/YZ_mgYEx_ζ<#MS㕄+7yH2/Ju|R})W5pfݑwaxbfBL'fu!Dj51~4H%HWh!%IS S tIv356Ҫ!Z鏀ź&Ty>0JgY!b7}csdڷ$>S)dz8K<8W(II5@zNMA<`үv,8Q˽nR=H8/;VOG4UM>ؓU%"q\e^lƎ;pḬ̀ ˿5xl;5%e-06a}*}hERAd/ĢHb&mJ_Y\Ĝl+Ӄ\b!?~*RI3xF^v Z]AhtI]ɴzWS%C9S?pnVWj{O[[s,VaJV%QZu.v/:"ڝjK#mkĭtIM)zgPi>L7 @g*GXв[USk?Ϣ|V>D޺kQ`x[^$SZc\ȵ$| g,Ҁ!?'I"6}c8ݔ2$^>q+"Yn_vA<}cBS?\2;̊_.j3\n.:q {j,|X.-ɑRKvLo Z3EZ1NkDj7uTD#|*_G]?: S, `ln8<€|]LtdĪe,N0L"7C*阩|] WE3W1t6j+wgMN]o{Xw3(}(e|#PzOo{1)!"Z Y"j }@_*7_:WiXڐ#_)]?oi4_B<ٟUQ"7kxLLpX5bυюn#tQq"QFp>5e;iW1Id t7p?ZzoVv[VI3qn; B$Wpm~O.]~n{8n#tNX<޿V8̝VS13/^xPMw ,9NK tN tXkSb0bkyX? '~Dn '8:SfzRNx<öqq;y ȿknu*Pي̔i Ysr^Ԕ&KܯAD?(fۣcK>>ǥ!iXKryz -0"A4 sAU~WBsX*xdjnubg-a="2^R)ϣYk^x-#7{[84Z>+ }Go$NNnJBPe8;?b0҇o{EV|a641COБQɎNuelscڌ2Fб ϥi.4:1mW1XiGHRK ԜgY(&>O"hF\Z,gRv-?Pq6=*B^t?[(WR9*p-ml]1,~ÍG,ВYL!-j7E񂸾& 1?fö4 KD5#;g/[ 5V @%|\QiIȝ$ b;z8j4lŝ7:,1Lĩޖ~˵f}#M){SgJ[K4~ԥ#QVTz;]_#*|nGïdJV$+>׋ sGIil"6O`{t}o8s:]Oݼy=cc^NQŗ@^$&%*`}m3gV8ȑy,EB@ytFحP|OW|?X_ 3b:i<7'~]s1C[k3EGp >b?8 Y'__"o^3e *+m"nn*U?*" %3u?׼%F(܂4{h!\ rੳ-'!all'aݦJT&{]sydRf[OtvѶpr|ݾ%o r "IN~wj^ , 9rN]>y|+Gg=lT=_AZx&-g{oSBB ?lxmk@٣wJ` J)|UEgz Kgo{GQTۇf*w!c5U%HĦOh9L&m<T-)~0 $? .+g4%Vsc.w#Mb0G9QhӯtH>A_8d{(߽šYo8ʙّaL:g!S,jCLMq5ohB^}!DCsm]{r/%"g [ߊ8ih 1w T;Q$Cަ"dgJglς$u(4kSl3\㔛ϝ!e;γzfodY"[bL.dzYr1萵_忹Vrac|^}&eE14BJ2e]nֺ SE-; p}ԥTtϖ︐/חovѤf5۪>ſ`?VB!+V"F=#R5;/[1cs8uD7tn(ș{/j>{b+cP,ρ}p(2c[ـK:8Ȋ`,7ߖKZ0di5mP\KFb~\YR) '^dEs$[ ol/lN}^:h}ud*.vqkJ)>hRu"+ϢDQKI0iެ%3K@1 b8$ٶU;cEs䉖z1s2DZcfZ_w'- J$[qͻA#ܸ""7  υt%xtXE3#%>{jgS,2y_ɾHz1߻vx@ob%4}_*zG~WQ?R怠 ;P:YAMA9X5? 4:~0ݏ*.hg0`CgRiGaW UWdl}h*Hb5xCK89'D]cPܝ2:HvSGej.aUF@@?6{0x8ZKNj IGPB׫FMG6]C7,O/M a>d5f"sKV5&Ed}g"w_2niAA0ߴ? @jAWo rPI|9QvJT RQlK [Ȟ8nqNV;7s1gx /3w8=%~!9bcll41VhGޢنlvXo:70?'hп`{KR/1c`/)bƷx/ a% K1^[̭nyDYH$Poa4W2ogc^<q baьQj)nMVPCmGaد T}+Cth 8 xIEa$S'3{ݜnBǟxҾAĜP}bF>E|:s[+L놃kYzi-^5R&mSs[P{C>1{Ϡ-#a"),e*8yͶspqʄMI|xAD :hrau[˽m44$? qsiOZz'ZjQT9n/pwcp% {xB8&?a\T74 S|HO +<[((?mh ¯>ceBh 2hHr87F\@c;j`b/&s\uQ1ʁэ5wUb]l C7A*9 b!.bj E6WwRs162(Xs;iC57}%xοeTe\l2p٦Ϣs6R6 Ieg,!=UKV?}n_#3,X,FC{4:ՋfKu9| )jGkSu%10{.*RM+ɋ N Ǩ*jwc`H_A/x}qA,`3fQKȂ&AdJ[>W}p' g#:}^)9J0/iZ9|LhVOмA_[Œın}<τ,i} YQ+M(]J&:U@6>RwB!ߥ?Q=8P,:>塿yڪ9aDJQ %uDc@ C{j(*TˣXY1+a<TީJol+ꩦH#fo~ʶή- daò~apK`s(Uk] ⇲ߕ]/Ta +sàFiқG!_u :[FQk*QdK v>AO"|XRp$' uqPwRRQ.e ]m8MsڴX+h~k`U> +`[\C,(+T0q_%_ոZT;Lrc mU}jDD;f3衋훔2GDU/_%ndWifZ稜fGϷzJ\iC [R ≾)*rLôbg %Mf[ Z^NR䰨if^<)<Mh s#l4t]F`,R 4gZCv˃73E]>R6;?kaJ(c2pEB_mAX^dʄ{|ɚk_[LO`ai`IN(#F{q|4u ~5! ͧh1{bՁIyzz!S')߸2̷_`S,jPYah{;^cW_fa%C椮-Ӹ[s 28/(FHTV5 Heh!'A~0 ?5VW V%|JB]#FC%?'/g,Wx32/hѤiOGu$C2~oi}~%W$R$uY^f!SOGTi$mJ-C2mGGX]YK(mSxpShO0wE6xItf}Vn?hsu{|٦Ud3X P=E,rBʪ܅.Qj:_nU(dB44*rJb"rxb@[ccʋph1Sn021vKb␨pP"8X24 PxWZ TjM]WDk\ d}VꞤ,BiCr+~`!CߠZ*༣-!ܘHJw}8_ösEU❳79ݽq{($.>_b xW:]qw>=(䆵j pv jme!W\PDĵ(e(#V)Gt2VK=ʘ|{w soKe8rz^(q@֕3CÝu3]m`94&;ȉ+0D}0`Z$)cOg5 %0Fz]෼O=[FK :}"*q2 |b/|C7x0+œZS I\< DۜbPyGo*ˢխ@-,#db3ͧ>y#L Կq yi(q9Q-ќm }EEb7]H* %@zڔ7يIO4q,&x" ݧ/DlQ$˩&q9ux3_9v/vR[",||{s y b`ծH݌piY`%2X9QvmolJ홾2Q@^i dZ\q!Gj`W䧌-+hA`Hb@zP*΍\|&˧҃c$%. ,CjS$#D6 ;f~5 lN =V4|߇FͲV}}sTɐP6ጹ(GcӐ;.s,S{dVW1 jG)ֶAV˿Rt`Px%2 ?HpÄ;32@z/hb>6]{#RH!oNǽ 3ol Q$b^lzVDHVw vw.I#gc1FmY BGDv,Wzy-meŪHX1K4ZiD^J 0`$ז겁pi1H|9 = arJ2GiZ*.nO U' QxfR! ==Cuq(8)b^a%7SS_).WSUl0q&v7N\7hw;1Fj" \Ct\l63 +ZqiY2iӟT}+|K$VU26=}Bjۥ=_1A_ʢU7 [I/TOD;NmyaP=> tC坯W@$~8mOowb^x[%EQv et~tgq0,]dwff 6\#P'N Rձw\΂ UrId/P<Z9zXAQ8޴~S7}z9, _esgq1)Vzb²br˟J|k*&QlA 2>Y_/Рlk̤ cjG/}L5G?)֪3ߟNYo=i-(x /@cEoQMEJ tOyjg7+яkɼVM?U A+H!+O*JۇJ_qh@ϩ8ޑАv3RkUB{gƌp3}΍Bxk^/ݮ} IFeV2r*հwku89s^+ߗ)C@Hǜ qo*'\5tV7H]XW?Vd36IeU οD\LXY# H#턉;_VB ~Q-MyH*tO ?*&/Eq'nW3koϿNǫuQYHĴyiUףeIH #:Tw(ZR0ò8FCH 0ܓᬨLScZo# VWu> Ḏ+ x̊CҚH0+*+]S{!5Ck|yh PR稒^ 'G:ToQЖ0][JZ4UJ7o+u9&jfAb@zľacg-dS02.6DYGM)7Vf„XF'Nx7uo60˗Kx'D;u=+@qVa|S£d?6a"!q\356t16jՏzڌ+AKH;-lh_#sQZ~S' >&;)盋 0Ubw{'4Y5 351hbLÓzH:pOGsٴr>{߸ы]viwHB 78\ehYpI6=ص($)~'4Q:\#Cn:X^m#@1H.ab:o7|&۵3 2|JVeK;=?tSMN458TM"Ҭ7L}!EACq.Jngt\,B@#꟰/?b@ ZnXc³?F0#AӂL&٩-[Cg^ډ棖yd &9G@2n˹1"~?ݲ1.58.sjP?JKWs>R p a,@K6=2N)DIbX 8dm; 9b5mSgGW[Lj.H_hD%: 3 ^Kc<: q\o8s$_ΨƙVv l2V>L֧H! GoVfTg>mR wZ =Ə$[{;}ۑAz7{T8*`̅o9C9$1~JrcH4AĹ"pv{ |O:]` g`}c},k aW霿afT2/Ɠ.Qc4g)2@'yzFvOO2Ya )!@m(Y2^%}tCѠ򟾚KXb)[J9@lqbMp/Kn'M8H~NDG$Az76&.`ʓ0䇆2l}H?:-'$2'D$.p%'5L=z~ubNk[{2DXKɣfFHlO)"O T;coֳ3Q0 ̅>.6؟G!>)- LֿBY\=gsy9\0-P*lc zZoI_70l:$LedGLU /k|* acR>8Z#H&Ρly籍5or!ZeN@2Q&+~ؘkdB M6S6έM:|[HP+Z0m|3 1!"h.ӯu*.rFW]Ɂ( LvpWm G2t;Hf}H˙pAPZ@4 OW+Ҥ] h`" 1q}9gB|?~ԺKVgAs*l07zkseFB0j5jVIhCoE@dՀ_[{E; Z49ޯ_+6lfǒ qQvh׭|{Zgp/bDC:qx Do Qt;LDsf1J0L\lmEPu[?&HFɩdPwQMEVvL^.=gHq׷qZf献1QVZS)Xc,+UVaObb#4i{|9C3T.'(^RH[Vv 5xفlM$yΨnrh>U=* ]ݪamo[H}d,$ \ E[Evw)Mg^#|PazR`%tׄC-FzFkP8 .? [` ]@_8(F"w~Z:F4($Y;oO1TWɧK_̇BY=d 8]`ǵz]b1<8:tĨ~xoO1D.T(yV="fȟwbV:=ÏMpq;XLzD)vi x W?sHA-',߫Yh0ojxŴdl1v !?W~d. [1"ڑ$r[zl<Ăd,[5`d ɳK$ű/1i9R,=dYzi]P#މְj Ҁ-Fٹܖbq#\#*lx]`_wDU9t_lԤ:uwi]U^f_k1 %E]CW} 0M^皱u*GN#Y{8b6:-s*ҷ+WS0wsK=gesRgU$n$)k.״lv^%*fGWk1N@%9[閷]8A!7yd4Ȩwt%3lp+6߅oAat6;ċx&N!Pn 7,cW&ٚi|mp@ȃ݈ħfຶ-`4z`WO>U9CWzCCCu9Le]ѕ/tlM~e6e[QsUhn%M@9;o/PIZ+ny)bYyn-p QF=?eF+޷[*{5ǭ" pikv=.z~Aؗ(R-+Իڮa,?f@nzJ[7t&_aYbIԸxd|뗊V,ɣJIݨq}to!£KI rLS(N۪ȥd_p!-e}R3Cfy)cuL99Éҹp?|ǭ"ASmr<>DOv(IIZ81~w<='6ņ+E,ܔe84H08[5el{XL uP CBBʳJqkDZNnZNQ Ttk't#/CH@f+Uy)- qVhmlA9-㦫0g+?!/f'ӰϡNh_mڨ碠d¨,>RDK$$R.GX?u/ɌeCs,5+JyKn6BszŽn"aیHDL b_Agx*Ţ^T46="߂^z=U) ;5FNT WA٪2x}}hIJɳA|G侇0#PVnTͻgUf7kي蠿e򄣩4Is 5hb/ Ȑœyn^}!&(0kh˙N]zMzGɹ2BQ%,rH5F'_\tb/b|y'>ϰ5}~48FQ0O`늳WksOX|ǻ T4%J) t` 3_3>jqw91lsoWJ]AQD*詴uFkMdΈMI&Di]b"sENTK^.!?M䊿rTm}gMQApskq쮀&F-mty6V%xD wF[8we<2`RGJ݋ .wЩtmT S\8qAlrvsGO][]b%Ш9< $P(ei[=H쿮K*uoVg5Φk &o?v.#a4\/!XRVܾ,X+JŔBSkteC <{3FsKȧKF;<_}exB"(>d"dd#\lw^(b#D'VxgrԦ]!+S`kp}b~܇pp_F)=oj_T7u|<9X &|耖J(VHC(eNB|pO@PD9!6Do}|$cB%5(A 1Rխ$I'Rmʍ}%z5sf+P=z&YԮ Zޯ":I*gf˛E;BFa1ݻẂ|@BC/,ݨS{PTYa)twww/KCDO(L;Ra?tzɩt|QR톻Oɮ1$;q^0ws81m6hP{C׻%cnR~ A6 ^܇O^1~aI \|k.,B[Bo5:sx^Օ4Fw&ȉ?(UA9EM@9ۮ]LJd?E1օR=T׌zAUy[Ha<̯ZvغsrxN0-Y#/N&Y/ V!Q[πk⤝r%4< GWD(²$տ߀&E ٌ$N!c+6M+NNg_Tg`X0<Cpl%Wت9ƶ( BhA̒iA!,T\1m4)c νb UR3e0wv3wqۂ} kdlFݮ{WEWQ?^],[ 㫳gP{0I *jUjN_2vSƵ gDm &&3:VfKq8F[w?gMJx%9"{A(Ŧ;f]a7MUϒ^h d]q5z-ī5)nݢ%h%O|/VaЇWd}`bQw[od~pr^@g1}%E=b&qmَ̧?@ *-f=m$9g/ vNu7@~{ ! nSE`ORA&bH2C/Շj1ˊ6kq([yI@ [-lO0Ln_m?I5'≦Y7bP\IN"h_ʷۜ^u$phV5؝0odi.;*ڔƕկa!$Dc} 16$އr>1.@q%h] &jfUC[NP۶֘1P>.ݓ|o)[EБk+EĄLνF>=Hk2 yFg.{[FjY\hS_֒Nzw[eOh铋e+Olyu'51%VxV3L/Qڤ[Jh*4rϖE˂P3ik WHxMg}KUt'$/9~V)jܐNN˽ZKLcZ./FXqr`} X&wӏ }Lp6E|Zs\>}rxiZI0{y N"kb{nڋSLж'd \h#=1JC9p,R턞!Kw+;b"b<BhchA8 hB9"?PʷE{fcX&&j'7 Z#&1#ExKRYUF%qA]5\Hs5aq+@xza?HZ0eqGg֋l&: גu7 ŪtC/ Fm=6nAɜC8E6XwL΄j5z^(|%a.om2Ű[47O3,*Drqb8_߅)~N"܆B({.=rppd捚>{)#^Z-@XF+D(9RveIRX]+w_>(aĿѻG fL~wjZ7zݿ羚1N )G|щl00=;Ld|H;5DN 1PR8V\S씥6)琯78'[^,~(pEuWqWX=˲ې7rBx7x*4jzC?L(n7U4*{: X{BAejG1vЗu9q4 C#ԗEa4v<`jWSoH 7vR U< %>_;1S![T)S1QeIؐ.AlŭIzt6YJ0Q\1szxTNu2}cچ]솠]`PRՂGc8y\bQ9b S@Q_-lV[`+zr;X7q'mEEsʍ, LDJߔwSV0T2KmAV&5ȓu$#};HƇ ߶,i] ]nݙCtKG507s}1 qF ȖYE<J{?z#/I#D.OZH?%F(TB3ciB cX|RZ4@%&-1R+G, 2~ 07*V6N4)=L@ߚz5L|D )I\RlYBI~CwIT?g+ +q=msQPZC1˽ػէ\b-p@v8".D#H3^lx7[FJXCQM ٲyxmLA/Nc IY)3<8yV&Wch;][Z.ԿGT]vn zX<`jlǒzJZ\)`D&} eF|﫚dyDA+52^TFFs Ydxъr܅.d)~$:JFgw!'8WzR}uM3g9?bC8j+4bs&kp/FJ B0z,DʽT=Q7Vf_( Ć蔼y+J8M'My2jRQ^)CtH;U%ϝ!hưg͔|.䨷5DYqaR.T'P"(MYcx)Uىkb hwIbQ,NpE; R,LKKvڀ?N{d22~wRosڛ,dfֳCQxsQp>T"Lm:Qፂ'd݀am˯A _x_.f\[D] tBBF l!_K*J'~Jc{%.cm|a.gOڂ#4bU@AL$̦Oλ"?ylM{~k7SgܮWhш(1 Jf)c 0KUd\{CjCQǦ湎- <`T!^5`@Z$B0AUK*J.pںW}'mfN*8#At˼QS*W*flؔ^WfFTU3aqܴ}8[!ϛY\0pȩt/gͳi{<)yyp”6O}MXzZn[7G|5K&/1нQ=ߙf}"sV6BWO|ջP}ٍ؈fcfDZFu.qZ 65˖NJT\MMbRm`'rKjV_/|R!lvK&+jϯ֬UAgq qQK3z4>˝֗q }K6 \jc$ ^.nm$( :3MS'pثd>|n^y[sMV*?Ol5; !31F9y`I61V )NC0sC(4G[o3/ӆLO vEC]ne}HΛ{'SiPy,P Cvt5| yBң,LFJiژDjHoiͩO}@:u7(RȠW SZRK+x'f7xߦpL<);q3{|7 5aDь[¢1ٓaEx 3ŃLp}!Y| |@SUk*T=HY$e6I`P0ҴvԵ4 ±ܜg]׮͸f}q.N(KP8*# .#^Z 5]F9,.Ҕx^smD *lTmg#ȋ {`I+|`kevde8ԭ85og-Aٍ_16ȭQ<39Kv\]9ْgQ"oH4Pnwu]J:O]^&XYTS*Ywr4)8 RSֆ`ʕ~r=8P)؂[~F7yw/X*=_ԊFm(/+tXUp9\<-ڰӞv@/ 㛪 5ӧ5O{WVQO@ԖZɅBݼf/38-Rm𺽧{c*r9q读9gl*/vpinCU!٢i)~X.K M쎐q _Ẉx-"{7R~F*h|{]E??t;DtXIfݱl nOZğ/bkzLSS_HI=A9ZpͱWX*& @!uߤo+%S0c1-qxh4Ώa!#D*d)|ѐ/U5NWH^YCr=v #՘֎x!{bQ yUzкa3']!嶶,?晁$JkS_*xB) 4KA|Sw$Z:4%UPzf-`IRy?gIA~O@O{1=l ۑ+ w݉oAr&V#)=Z۴" W@ (-l{eEE` &i.ˤC9ʮ?i8١0`F`U*ɦߴ37KJ&^H(i;đFˁ#PCg8A*'6WTkt40kx N#@_ֹ #Z_l?xx-j5\GZ7co!ˮ赤cD Ԅ7ن&Tr5%h<@Y9w^KJ?FM0A36?!}:UQAՂPswӯTz8)b7o{ǡC4-WfHzzY|jdQ@KH.ce[LI* >}@JP""}J{S5Rd4`7@&I6w Q?G^s'eqvǻqs&ᇔ,n 4L Je*P=cs<2!_'R 0 3ֆ wx,TS¨ fum cWz߉P|ҊH5_L:'XLOrAx6[@G.$lC85H5@n9ï={mpsugNT}yfTί/W}JlG%d3TMc]1>F-Az2gVo`ڲCRe'@᪆s ޙy@Ǵ w4k>BG0y׳VjDt)&-!l@:ALW#TGS$RsY>,a]x*^RoQNs' '>Jf-"AWܚV_q "KL(ߓ^ c~ҌtQO<>sv8*c,/|8lArZX \Zi`Lb84WPÒA M+E 0G/B`W)UcgjЈyVnѐF$8>|-y"=1gxv_ӊF69!E >-Ph@\ oU V7_|'{#ɐ&H_4氦,eRx)޴\X)n`~Sjp%."BhCt zdMu? ;fK$V*R> HoO m߯;=f4@c0nvUp4ݤ{th4ս- aǞf ]B?%kÛu\Xl,{rXfi_?nD*l[_t})R [iL-*gD9+j);W3>("r3-,a-E5Q2UoTOߞ M?xYIY6vcT3ɉjFt$X21ok(2!1Q=gwbbkHk>lM#>;&C ?iwgW\lی(#OvdmM7el+LˮXErzUL7H& ɸsTB5j03eTLVfP F ;&c{ ;l4O! Hr֦o5(`L i5h Tɘ˓9qQKىƲ%HrL,vBgo߹aF~*fVGC7I:7ݦ>ZMBO;jݤ̤0KR} 9YĄ^Ciހe͑p\ cHY{ \]PY`ZןIe.GOI[ L8F Ve@H:vdAB8BQn<$jc+c&͖ù1SݥQVZ;$XrWG"-^֏ (o|l(h3L4vsy=WS̿Z^Q}[gU;F1Rüt%6::!5Ɩ=IS KZ3bgE*oAw紃Y夻Z+@Y&S!J6%EZO׫Ĺ.NH@s?=top5(*uC#5p-e4i|BvȂ>;J8#//Ι}o$ M88Qw37R}փişbjx;LI,fe;H:TּL 1)NGowD)@t5f!궕}_5˩A\H_R23BoX BE] gHUpR0&[l~u)g ko+O7u6Tv[KV&tin(ۣZlJ(j\5B^{Y-32Q O֥(IJfFq " %!yL@&eq~KFh\lU?huC##O7D|o^!k;XJby9.䕌ŷӜynC:(|笯]^_@ɪv[` {?Ԡ=t-1H/-jO˅ h3~20qOFZ$3KƢJ]`3{/rC)!V;>c \ _,?V3Eyf0Az "9pP`V:UKz[9Gb*A^Bs4$s~eNhʣoUI4 9 Vy*Xzs8PhI[Sr'+`Cqg /f<~&ezݺs qs!z}RWC.01#\`YbɅ._oRK}DI4::Fl>^ eꞐQ[ [bC5y2x3eӮq oD;$xg w^w߀a5I<4SRP}HV#\_HKvќ=jꆸidRlXh#LJFXProAB^,(fm3:<%נ`*=ľRӋl(u @B<>ݕ?oѬGs}? &qvDex=)ɬN!UplO1Fk9v}c`"tmMbJ%Mni.S5[9*+TUdޑDzwR65CbxRΑrxJl*LJމ !PyoG$.Q&0wX,NSZ<WP,$jC dZ/갰A|yR'+tߍ^X iO.P%%^ˤe;,bn $.4QڝytEozʒ~vI&m@r*&B~3-?U?|C|C oDX/y$)d{2FPmvL]CKvp_M!4wiG?TMs!"7^k v0|#l| F#%@Q?S lx JV.7ݫzEs#‹YohاR"6f38ѝ?I65 )28v1vv xp͟DF}郪7gƃލ$IXx4Z_D mATdH;}S2NB%x ӁVo>|HE^5Љ*He*k=J;pH!ݙƤzq6 nrV|Z70y3võS3*ltxaFHS1daxǨa$6EP}?Z:#OD5^HTM'Lk IuL ORE לu{wV EH T 4\(2hk ;Yɓa^p}Ӛ+zUt!>8UˠE<1KV(;+N tV rxh탣2?: ['E9&EW##gׅÊ~.9Wkc/ja2o[*3j4*w$كgz^?QپRv ĪL1-141btzGPM9/QɪR6,$Xb\!lUۄ9#U"Ⱥb:!0 6K"-._EB9VzpE.p/ ;L*Lja"GH]Ӏg2{p'±J!ﰣKQ/Q.8M E\C{gXIN5]BqN 2U$gKs abMV+"' q^ +ۿ:׊fR:e{pTbM; d7ORF(@D{y?J`:@kD6vT>F { 2MU}8^ifRWCzlLoZ =SSU\yj=wI_l$Yja/%?m]#/bVCen4%Ef3';RK-~b199Dw# qjrEܪU*pyqDo d9%$9;'- ܿiZ.sabաGd >q祕@Up'7DJG23uކ_Մ{!5tt*vcH}ap52iA:n^'-_Z'jsUUrzM {sqϬp?P&`Dk.6 j{Bfr7Ě`o EuKQ,8)!&P}D} FY t.tCASGX4& a"拸vTCo!MfjbXs?x^%ùb Reg`h?=mדd~n$;Hm}p20WC*h>PZRq~W鐺r }I7jL f)aAO :25v-Ǭqy~K!Q)uHJn> "f $[N ńyD?unsWWFE˩?O.Z{9=JYH&M@5:;T֚|0w6^\5Mu*?kGM l'3 瓾=;) z.)d:a*URY"I~:QPfjx#t7]u%:>kGVJUXnv6Ośk춺+Թ宩 pWwt-0izzuՊ>Ln sHTiWc/G#z^'po0TD>8MHec%2YP7׵Qa6]&nu F)J~< IHdFRH> {~8[&We}7HK\ZnL.suExS7͊wXSy۲tS+5<[dòg䌥O,|ATJ|LBq/}\$:]in܄m'6Hx/X{T͵&Cw38*Rlr _|=BwqXfBǽFo҅XT)cT81# aP`5KUACoy&J!!\FtE4^?ڗ6Ok;_Fqun OlWaj0Ǡh4/M92o{BD1R2- Q0ҍlwZH]OɴQY*\SEHgDфkB/3j3d0BK=$.mSc-7-e?e,!:*ooTMMRyN2*F@2GJ1ŗA&rT~IR#"#[6pA$R^ 5΀7tg)Gk!J@wo}7ܢ]񐦳怐Axf-L)zuk-Hg#oUY@"wf:ˍ"BM%A~O0E )Gr"Luy}GW VV!Y] >S9:6`qh- 4 ^.' *SxWRYzD2] g&Ҷ 4}5w>^@> ʅlL|TKR Q ~ w ~T_P=tofn, X8;S)kCVᡳ ~8YD &7 g_@W]c~K:Pav- 1av۲AKyXHz0ϦPj,\Iz0nU<8k=~4s>/{%n^3CB%D0E) M~rE^>C:)f4k^ v߀HEA`VȦW>&R{SGѦ2yMoHL-b[?1_zvvòBo"R eRfQwYhPamhQNG@:N "+{-CfO{. >ш<Al7dYK`ǠFiq]MG؞~@R͌d3[7)Dj+t?z4 Q^TQ.F "]60B wf ʆSS1r202UK kbeԈ iq$?]Er4SX B>'֗)Q١gH=kGbaj{=Ƶ[E9 d9#zWN@#Pi+ﭮFׅ:LzS6z܉j1*ϛɹ7ƻ}y6Rw!-8}u5sdt, Ei Ј(xTi HJFZ&~: wr EJZUao͊-~op5°=̡ik]җ.At岇Z[$!6S 0 P^4&Ƣ{ O}U~u^$#G~rl:( &Y OhHޒ9ޟT=p u'UBNO uZ"_~;e dw`ދzn6eΗSW@eH`6Bt$c=) n@waKG!eL͌MT]5M*P(K-lޙF*&tn$GLl.PK{oUQD厍o;EF8/yHGRxs 㺵}N%8"u GwdZR7int Ӱgnʭѕgܯm-jRM.6%W inl=7?c%^g=xR7X qUֺ϶"SO}Q"\ЧO wZ l?rԊz7O:LM:x~ y{NͧhaaiP2+!U07,3ҹBtHo.x irޛPLI64%7M4NB};sҽ(S \6q_P>E+5[=K4^8 \YHӚNgN "}U^݆Ef!Q i#Rwv6~tR=l2Ŏ?I8 bl\xZ1+ 28:@4(MşUSꍉkۙ_:E"zH,B&bOE7L cztS%KS @hfmpnE;;idژY]`(^oQ[] 8@h$lȻ kWf),{;Q(!A2~#˼ ŏ}F"ήH )x.fOn%+CBxy^FJ96~P;qX3: ~]J:/8nǐ)Pe4H Nd2}^d\(i{MAt\P@A|9oiDЏ00."!e<5gIBTS TeC:fߟӈv'k@8 Քch( <1rR> k:T5dk4@W7`P͝=\j p_Td<}4>xL@U3:!^gX-/XvGjx^!Ad>@I:О>ߌID47W~3P4Rѽp h| d!yƪFbb'Xt HT"w#dgRʔ~Z'2aeԊ6 IzCRM邫j-̪mȥ-K#vKKtDj$]):PuieN(%bk_TR YU1T7NM({F>Gp^ȴdˍp%źW$AM?Yl$2usHċ;sxL\k{4nhZEQJʉA-{aRD'|74Rt] 8 9 hH"2\ G%xn`v[{3B?kh4 vf5%T{_{127|x72*2~#J¶bwST56g,fUP^=gRAHc(' a,Yu!&;B2k Wn' *a྇'eGjcCg/W&CCj\6v_|~"i m[vBddz z4H NE0Zr껥W*~砙g>Eemtv XVE+HqPO[nO/l_>c!YI|<{ԻQ! Q^bOsUYH!Ru'fGeu)MV1xJ.>s0l"v$ 4񚻫" Ш <Lך '5GivBZ/nV٫qO"ȬctEtԮ箈h-z3d@ZW(Y_5%:BtƒRhij@$~ŇDxϹE}<Aݒx y|;<7sΌ wү>*>ʱi%S\MCpsR45![ ް=jR6W& >J#~P]wf?l/7[o-`oRy惡k^sC8N,vj&n5 #\n'lBgx\wntŦ9C{T _CKzۮYpjcҭL!φ(Kg9$V7<]2;MLN: 3-|=Ro FǪb䍝)HQAmEI=ll }KtDIkzU`?@f hqz\dSNQ/$$jt{:ӯtV5fQVF'M2*}.b SQI*vbW252sE^rcHI>he;_۝t0;]X7qZsLcU}Bt*kd^gյu{{Rj6% ::_GUZG{Y=R Sm; 3q|Gw[q2q'ZWPn83+d8Sa,vu (xq]yLʻ>o>.$i>hሴ%R%KC&=7]@mC{{Q0$3:mf*ʞie R-c  d~Bq28Z忄"k8C9t:| Fpe9|y1! c;R/`hM E,R5bͯ=ÒOz6R{I0j=:© q!B AoCK[n-ְ|J6OC169Tl}n%U5` PJ\VLPz'=X2]G'/M573} GZvnj(la>qdT cq}ΑC*nx~ IeHDd_hoT /&?KIAgovǪ+&-2!jOgVE>gJXiP#-ѓ| s$J6nxAz?YvN G$vʍa'bYGINrf$YK u>/*;1o :VQ\hfݞڶ_e$G7Qz Z,%a{$"3n0}Y/ыu(eWp.k\G(`!_igߐo}Ֆv}Kk60ۺqusgB <6yZK#&r^/C_ҙW6h݀S4IhռR$KldE}X[0*(]";PlU/j8\Fpc.\q UH('R$ 1lxma9y]|[2>b)J{W,Ir Iiơ~> !ݙ@([NPVf&Sʄ&(,KEhOoAFpc^g8a%VMbX$ˢPs|lSN^n}D C> ՚yZhW|w -w\`ΟNDdd6H&O[#G: t3C&o MS9 E i`xf"(Zf'hdͷC4}Е{噈Wɇ+o37sjҢKvK]>jee3t6_ KtyS* {.utmd&1ی5IU̢ހm*%ӊcߍV_7dT/ZOlsK֠"aO"KtIpV8Xubvod7 _"Ջp^XT<+cd8Qad`% w Ql )2R `2k_"5۶"jTBR)7*LHVHKCgh>z̟A1Jbo$v1Uj4p4o]IVG.=fYn@`G8]$AVR8 Y~o1M7JUWT:\y&3C NiDI7=?$DFoĂ7q |)rV1^,cQ"> cV ųWmL\X%ri:HiK㿂aq5d ) `#A ayU)9cDsxk]>|I`̜svPdL utiAUaw82F|d'G`8Ӭ/Ә#ʜ=B6ʡ{ K ޾.4ψĤGJWBni=@~Aٟ2~iiߓYŽ[_ 4oj~33(6jG4-Adѣ߯c5z'@)ĭĪ|a|ӆJj䌍7EC1bN4z͹R7oFE ‰^>QXo&i|hW.4/2osA%tE /g`MdBF ޷G7C*a{oe~.r0m){l v'ˡo_ 1N zׅnpz34Dl#ac*rfb{JT 7%Cu XRPk4 l$FWC H$vgP NŮF2: Yڞ[K$3 W|U؄Dqx\~%èDr dd1P?> oY*' ?|*сmkV/o@~'u`GuP8[$wx΋Skכ3n !ʥ Kc30΁?IQJeXs7+!UK96kB#AGz)] %gQ[hI 1Yӂ9$kqG29 Z_AX@}hѤ=5qAynL{ΝF!#du%S{ɈoS@ ƾU;^$A< 4>c|I *?iϬQ8^l _n4Sz8t*I,vuMh7y*0kv%1DVEy'ߜV4cK:K7 Yjh(Z:?`>ic H~ F۠J%OSJ6pq4;ȍAK#ܻo+$5 0S ۧ>+GAv{S@1J14˦ƋVy,~7!`%|)G[*+i.܏.5>xU06nѿ[%ࢦ뚊(yV:!ʎQ$&kԊ:yEj%IXTgBZ1(f hq:A*/*"P'm4<t05*ߞ1qhgg>&M:K{T4*mv~7{T9_pW+ˍU8xWOXdѝ1 /:&et j)fltF-zrٰOѨHiA-黅1lwZ=c{@X',ah ?”mz{Ҋpީ$J=WM|ls|pzڰiP_,>o9$DzVBdzAdG7O")+ څsdpV}AH >^3z tBlK.9M (g-R%R.biF!` R$d}/gV,CJ@[EZ <:[hvH 0 6u4BGO; gWEpVH6$!AhxXM8/A8l^&MWb؅l"{iumoJu*k=7òlЯci3Ͼ7xN^Yy>[&<5"9fJLy@!hY)h:(pu4Xt'1|X㢂Vgr&pi~o3$JܬRiZńu/ &p rE/?Tɯew .v:J@Իi0߇VOu!1'f|Lm7}/؏Xko[ h7,i1gx,=C7[ [^8)gZpSju-NwB 4f?<#LK*OͧBux|2ƛբ"ys]{t(r? ܘ^`v3Z2>kp14x]t,*?u !;3 Qjav̽k HE~o}\<ԤX$[D۝7Ǣ0eJNnp\_u;eJٴz k)r_H IQ bԎ}7w$V9yIG(G;m+q:/@:#rk` P:#N둉jnN`T,b{'%O&.5)?czW_{:$bOMDퟢѦUB䰜[G |dU i@~6grnL|nOxzMuJvAS;<Ӷaվ޻A$NFCR>X9ʨl9?9NW0Lp Q%&՚sьMgj|;8o@ay$lُ_rYpHE]K[O)K `bHT8]wlސA0 * Cv[teJE[k!m<b#MW37y=iĞ~~Œ < Kv^ F˅Mk9#̀$wF@􉥻/<`M,IM| :11$ sEj]6wwuiЈ#b\676b<^)p&Sg܇zvH= )a Q_2Ꜽ<0^] ~飅=HA 2JT~uMA,'2XM>56U =D)xNA\W(q[uF="C6 4}(֧۬duG'f?>{ܱQᯐku2E#21"OmjJ(/Db7c Q,JI+ux=ճu6i [pMݟ\,+v%TY0ǥ杷Vx1W&7b:ZB ;jAoMM% ܨO3HA"}AԖ?aX;d'Z,81 3Y/A2 `8-N0d7tLyG&mP&8r`&Fȴ][m}-M8 %>/#QܿE9m36vIeLmfR T*A.@ƈ9SMx #<<Ҟ;&.ɣ^]Pc*Ȯ$r7R͖q0Cujͷ$ Oq_w((5Q!8bx$.F[ cN;ɁZi=Ї! |xD R%ӎ}s}V# ]KCcUUL(a9Kxͳczs-͂;ˣhfc)r('.e1=5)/ZUuQ݋ӥziNw9 V1^C礑(3F4KdN%$A{T$\zԝ.N(I6 j,XM87JW0rsU*. gZ@fxGM A.@poIv5K 'S[w%?7ۨPuĴ:y^PpP'-C~jxkeeU~:%S ONçPzrK*7.ʠ//>ܫwubٿfcC Egf>Qc}o_⛿`CQq PLp5&䍏X0}rٜgAz0V$3Q.q**d,w=3T_\#1{,:HU@M;um} 3XR0|m&/w !mHCJ)k{x#A@$ bDѣr&iMI9W#sm`Ly!-)P(.f.j58GQ'wr\t\ݕg,G[35zaK Oy)Nu7̖Xo87 Ψ75ZN뒋@@YYF\\ϗV35^4_+w8{Vc#\n <|:}1ii]<`ZIm*|h6S`#_U5设 gFc^'3ّneƋpJul8@ <#;=@hVf~x +H}Xi/W~H`UI-M(H&0,7eX_Z+G,թN#YAqod-˗MPjv5MJ.F @ ^ǧ</Ѳ((}4wЧ~ŰF)ю#2vtG.N۠`KPjD( NV;j@R[I:eÕsGރBK4Jf0ވ_=)y]ިzv;Gܓ`Tt 5(+9n ~m]Tk)6U5oq8 amY 11]n.8nT$ήN{ha몄Z{Ȁ^@|aL# s=⺷UFȺ gA(BVOt)SԕUtδ\Zl_q'ƇH6~8Cև :,Kv?{9s0dI ZxN_Ͻqz9?hĩeƷ($6Б-unAƇ|æ^CO˱Odݹ耲O}$u/`$f3-+a_J<{NSpɫ3ZػrbiX>p-Z?4 wdDh^]=J7HOvk$;NgJ;MVt_QHZFc g?H^pK=Lg!nGv%>ӟ6e`DxX$lpeOalq t3CJw3 Kdpje8ځm;FF$t2!*QcM:N6HZ%eﯟp ^#xsЏBylimiTU+. x}xNUL^2g"cMCt&w 3|*u^'crM%y=ZT&gNz({E{Iv{(1-\UՃ9N1T5;VV ^wk_ҔdP箄d@daL:n3tI4ɞ&:J XY \f66o; /|!THV~- gYW ˤ7 Ȧp-uM2 Kb,R<Fqr9hz)9C25-C.Z @-1 .>m1n?KC\q9%Z˛~-k4}@A]a&\. w‚Ãco (k 3A1vº-e<nN.w _K!Zέ7J@~͢z.vr r2©r55~t|KV7IFO˚EP2孡7?v1O;R ͐,Ƴ9DO#J|Pd"IHnb%7`W~ʙs 3iitFٛpIs߅>2?Rudq9/Po7 zylpIiB i?-ɒepO&bo?݆z(Tޤ,p\䂬?'Y;m ^_"Bk;1tD |D(IVmkׯYCKwR7(\1I:mr=nΠz?qVl50tVu㦫Cef?)E㡍ԅ+pWBbE nos(}ՈvA%fM7^JxEp0y"W$9 ֑cz_I,+.&9%р&~:I-FƳaoI{҅ %ɨzd~y '7 axtm_Lg뷒y[$? c,_YmH=c{a E&Voi_C >3Hc0v ʟc鋨&rNRGJb.]x9lSל{aM$c)>D49ݾU)56J dh i_ds%YG~~!xfd/4F~k?>Wq) T oT~,R`}V'N&$!3t?桟ȌXVl4)DO*\USP+r-̀<r-dnI4 lw.eyuXԬpī9@޻q]?Z3A uP &@~:% M$ TZ[YK^MsUpT2)ɷ4^qNnɲ¡e 9B#s/E ]]\{6$ƥ_K[Z*!LRүuoMd;ؠu|g>+)b:(aU,#i\.>lI.{vfhɁPPTDi-whԡGE*ڽPqG6] >G7)N߬⼣TPĽmQPv8E}*NHVKnY㚭N0`A fAlI{h(K情oہr.y-B9>JT#T5`ϒ v~Ԧ:xcm)har9|IHI]5|kEƎϒqcʰ+/ 3ܱUVp2ɭ؋dM:nxb\&dm;H&ПLd ##?%m8mYy 1/gw[B,m#`5p=[MJ)c""v އ$o`U ܍XUN%"}Gl\-}Vlu7 |Mn=ʌ ?c޽]*jk|7L<|`RfSytC2j/aE|0 l μs { gf;c+:ɇqY#,5KVYP&saIMk@yۯ>M/J;(@f>\-ߤz1tI~0()R ȉAN43 w{ڷ\DC;/@& x~8??uS-m-ޓ&1) c&5U_}a1csy-Oo1Lė&'ư%ˢTN׈uWrϪE8pd"픽'ݝ-r Q:cq,oM$alܪ|}}kot|\ WeWf?[5줵bok#ˠUS߄kLNI;Y$YS8Pd8@_Z/ otjPK (pkFl!zmlӭxe;TI&Z/.Y>9C˟P#4)d檩R\ vD\*r폰Gzu"a7V37U;rGƐ.KݨE+Avn-"+)z)$}0ZBw:8$rx;/K>lc@5bu s\k,)u&qw7U.K+dڱ؆vǯZu!(kdF<$è8 jc@A^хC o!8ӈe=# 0MDԤ`S قYN$sbST.FͰv.b!QJ'V>"YC (jw(w#D}oz)Re5:dM VI# R,iGqW,n^^n&b&H/*DePO}qR<֨Fx*6|N$6`OxHٕFN%-;7-,#Έ)!j܄!=.S۷?48@5ݩ=)"8]nkh*ֶGԇcktK@w)'v;z;75 ZLy3jk ܚ:[1] .Ґ`P)|bHLKqU^җKJXqb=ۓ[:.1=O4ھ`9B<婆#`Ey˽F>23cګ‡OqzrS0`26/K-A,z։bj)qTtAlXf (AAQzەe2䦆h ۯ?bY0k>cLfYB3 c 7a7 !^'}EkT=&~+#m; ̙ Jk8,$dX 㬾țUy?dMUKyQ$K#!b<cI>r/m&w$K&gjz)"KD- -c ,v#8DD8+͇BFz\8# _Ţu O6&UUg$ ˗]0'IGM%%uVGbk%|r>ˇKJ (a B6-^1b$ . ȫjTLBA ',Ѝ8P{׳0Mߨ{J&N@m}gaf̘Dc{xޣ 1Z0&gӵIα㝷|s;rteevߪ6%hh333_%1\FalF.UkuLr𒒻'ZeL+f{xg?]:h_kY3wƍ`v gc)N-*ȈE  [i{K?kJZp3$}'w-!~F 1z[JN&[jWZ+{l:?XҫcWmuuGgt倨=Aؽ ={Gz!Mʐӗ64d>n錄Y\/٭dl}WtL HF͘VJފHPK4>FQRe;.ˆ ?K(Kѱ(ϙ렉kbnÐơB#M|+3\GqYNkɱ|2)ϨͣNA*^dZϡU⾻]Za'-qHt,ֳP $&KON9MoYz@#A!K??9Jquɴ{s;429tCFs)6@R*~AVqNmAr`cSL RPє&{]jXn:XywaD2y^nZ6U)E\oY A;$8򋩫8 OUR;#=x4w<<4_8IsQu G2.\(i5SK@ gf)dS|.V>>E(Uf[ Gn/6x (,#p(ـ!bҞ/*P gWo'*1,;w DeDb?˔XV: a2UC,J{]-fzy pf# 83}%`gv$Mkr"A䶂LWI P#JVC/!C?02K)!7TGlt=tKO?9^QՑ̲Էr@r4cFf!= A6eEJtY țשZ5(5|ICNtQ$gD]}$wĢuoRtly@Z`:w' omcLႀ|VmbsT(|܂Hl2Q.jno]Nn=Ѯݕqҝal} o'4KB!U~ע:Zy G >`! "œ{,|9@CJ.@tV!0F.^'' Z\@ 6=vN Tꁥ3;\(j+w.W6D۟XwO!d_,"Gb}lSŕq?d* [Uqw$vO*P%_ U'E'U <\>c-L"v'~zܰ [kqʙ̵z+5TܝjUhE,Ag-rB" q?8nj ng /Bgf~!uL<+;WzDӤrsU Z*+{z,=vkz1k=Du;1磌SM\~i/p6NC oElf; Թ_YOai8^oR*(1=/P4MxaNƐrDnߏgSh?`kP{)x癙|_b>"LX mRWy>wg1 Rgj{CvOqN^<# c|aV>{#P}!Ύ-ֻH%UY CYg X\7!8i2kʕXlu"vl!aˆ^'>nC LvHT{lI?b%qVNpq3| NP9uR#* d*HZJp$X((wEؓB.Y] `^4)gm+a>I=4U╻6Nd5T:Lᄚx(j3䏵$OtPqh 2p MB:Zm 䌾ŵg6_v03є`яq֮n1Hx](#X إZ ,+, ٓ(L3c31Cd yiO{8Z6#/hgq_o6KKp5,BFzyZ'pSb>5bs'꧲-4;]b!J*ؤ\mө1Q4}>`U7.|skY>h:kE ?"3Y܋7?TǪlر8 Y[+*AYpʹmRkӭ# Dw+I2{F]'@˜dBE:/x_u/xC3)x7dl4egCz}RWĆߧ.QP3E@467aE1=PAoINKEϺìpcI7>i%bD8XCє n!g5}jKv)"p_oj㹒Dh<q2x% KԲxX[EjUxuvh7;g>6D'!m76a" {/B2JE%f. d(R ar1j=uTVOWNѷRAZ߶Q=}r 'I `&Ies:۞3l{t90ei$Md#-Tܲ&GGlqpu0Y5:|&L~q-'M-Om+`+oƢ2PQܼvvQZbjOH֟j/*ˠ_SS¤ gP\ktLjvϷDʻ:Z l-s g-hҶ#d !eG2C7"0'yc%ЉuSLZߗfЄ0Sx- QbmYpMK j}۵}yY%]!3:IE5tnbabLpb( =<aGJpP㚋̈́|8EC`)յk/I-~Rw\"OgnPP&&eָهwlU8ԐUIR0F~/ v3N# pC!BP(avUO hwN^ ?eA$J% \)n#ξG4\,$H=ב| ⭅ܔc;70p7nbH1@P{&;˖zoP?%81bO.BlƾHsn!',(%&>% ,&xMlM(j'Ҝ%JfKX"AҧsV 9i0<AEӭBr%tʁA dИT)GsǾ(Mqƀ ('0cnD yW\{rn5G+-B_p#X.=iU$/μ56n,Ħ`Qf7kF)ݢQ&xCZ¹R(E%ͪߏ.fѰ7 0k ̌Ǩp5 /H 3<4mO HwLʣͺ9mq}!SΗDYZ1wj5,K3ؙ6iB0Bi}#iJMH2pHߕÜ[^Khst솫$]Z`.}\喐F[vzT/G3JGVe̕*T2U`zC2q "o[#䅁M޸)H}o0 Yr"mU1 ުOOsp}lI# ָc/ 0b(5{@ILH=\dTa\&O~h\pAkgg J~6eK%6&6u u$FH\ȁ!Z%޴lʴ)!]?S?7)j&wJ=|Kh= ְLQ{ME$cU氎v 5e HV')ܚ@s$zm˾S>o.{5R~C ^AnIR/qt.(g#??!5@L[T;4B'G]CE0"`**f%c)=J`j{$Z@Y Ga?q!QzdBr]e#1)jRvcT~4|,8L[_zt- Akޥ'(0)),&⺽)'e$KB `&{;Ow! Vi`*%Lbiw / WʰApYAw\(5A`ޔ9M:aQW*MP-Xk$f*Z~q(" Ϥ,DsLF4U+J+e5oS]$LECm:ԥLҵZ8^ҕqMKYj-#(a7Q_axaf 0[XB_SrMڣ/' KS;֩rJ s)d"\V>CBƻWE-SEڡMC%( :- 70X)#T,;zPEg{+d{FgZg gY|Ɖf9-19+NՅOܪCM 3=ar%aQLi5'jv(*B̪E '_7NԺExP/Ffo T"K&&QTKe^ΰN] -yf ӭ7 TeV2 >@ LAM)`w5Zr {._e])J2E6j'ed5X8rEÖlɏ3fU6ov՚,G%LI2:W'h M\).F|[S/R;sy8FBƻWdrFQ}050wbEߺKuK3F~ Slr&5S-v8f|G?MCyuEF{ß*YHLSY2` qs6Lz[$]Rytrl;/]?u s]Vr!ҕȝW k`k h'ؤqOE`_s~s&c?Ec:322rr̢uxjvT6 @C-ҙtbg׶V!+٬@L=&,ai3ix?{D4UGhĴd?QR3O~h?w+RfٶSkQbYGIef~Q јqJiD`p& P8JM?NUI.'SU|(qL~4)tJ+Y0d$ 1Wh6ҶG'3V= 3rO9)pʤ"_ Fڗv#Γ%!<ޙP~]Tq gf 7IZc=|K sk]\+ױ>[W&ݕJA')Ev'(KYs|nrZ!$p&VRb%[U6T~&Gn{ڻ-n;m@SZ# 7-  mڪ鄟 H2#87&9WW&])IE^Vțk[\}Qn_^O.E!V;}b5#-7oVL8[g_25,º{:w\>-u7p>TaA`CdC&HwJʿj( _G'|Ț\MKLO5jǸ-duwH<awfVӍaq߫H-#/JYΰZ?ߍlafGɪ &5yo"CE/Ps3'k{vvJ)ݎfX. /sm'~hI메a~J􂕀O^`]:6G=MIm#Ωqm9TXl+4"RȘ> w̗-PuDŪx!+HKzbh1^OѨ[ t yJw37v틖+W/\ Շ<*OxZtcwmnEo*yy^gL*Zt 83gQ9iz^ Zr"\z_ [1$f E| FEn."T#^ZX0hk[\7Q I8{ _8mI(צ핟ė{r/Y̯L^TOWAU4ZYٳ⨳ @$T[5<;]>?1y1M>_#m;/JJAĜwX Ȑ/lQHH@rx}r.ӧ=as'}݅kq]^U@\T_>l&5hXvMqx+6"bѰUU1z'hD#!^a9=%\VA}3RdL#ӊsX J.<ކd[L0@x;$ĞL!n୤w19А {}u6>[WƝt&Su "6Dyu@3I幫Jh~.M7c DN1p@E[ꔞ%@֜#e0Kf2J[U9'Jl^uv-R8E4v3Yn_|!whqb SB,eZeܕ?p6d~ r68Eu3]G3VoF 1>a,Kț-KԾKe5g 㺵PTHuRius3רcIZ+8`Bnj+aۻ$:Y rJxܞh· UWx6FR: h<_8˅As&M _,f[_۫Vv0$`y1<1nɈN\b߬RfL:̽s$"0o@HwRΘ7Ѵ1UVSJk,$^pEx6Qs7[z:&M%kvI6dH]`JǂA`TÌF?cfʔ~ /\sc\iE'ݼ@cOPcVᆢˢZ7IkE.pi=:NYDM(f 73>K@R*J +D ɺY:*wut7{賯?4XE$VSN4AHMLxj?@eǣ >=xSJ|VԤ.b)Nsƃ=K.u*2h< d|Lx@鳔TٌemA,ZdMj-ȗ)p Xxv㩯HջA(6AFҩ!hϢݘZGx^kSŮiHJxdWۼ+:w%#oAΦn9>?W?[.ζӸu |4e 怡-x0r_]AAΈ5Y_M$^Bn~C~YocYaФ\mE'F] BS,X3XB9f-Djm]d#ӃtIW0PM@^В7G<u*b:x4'"+QJn3RWVoP5zh)ցk׺<Ơ+2wws mw׆97BqUM]Hz.Ycbś9e>pHJR+eMQ`Pio B^ ?g2MȄ~Ǻ*i`jXn;;RaimSad`K,PFɺ] 2]?4EYӆa 3n&+j3k%!a)JB%RPjP {Ty6ԉonRfԁۈqFsFYsݍtg&U .{"j=[ԇվ0WyKLU|KȀ If\`89h $yɑ1yJ[.VlZSu 5rT[)ے>?I;&Jp9"}$ys^ת3XDCFBzq+uN(,kyɋI <H-<ㅻ@۰ /g {28,u;58]OV0]:,趼:_\]b,O AE$30go&b+yɑ0kWl,уpzpX5}?}Rr1B<;6_Z)nHB֙KXf*L4 V5Q?B'LJ}-l^xy9\ F1Dt ] m:Gs@PL#EM:c"\^/*4+TCf%O\| T9=%AIt^e! 8~-S@O4?A/7R5p Tk`+5͉, ӣQىQdݴ\x4v"Op!Hٜ7HA򃤲 W~ 4A rfoUϴ !b/AFyZ]VIdMi>\2aqZ) '50ە0[hp%TAb=h2刦|zifhb+ݹ=8OY}F /cdyp̰>T<~oJ׾Kɫhƈ&I *jexa(YvE|4PcPV| , f R q1B{C)ԭi /9w~J_]Ǭ[bY4{@[_B#m;΋J>'3%p^kJ|h6{]Y**So4DWyǏv2 !ͽHiW+\1#%0 ~ԜrjrO* /b f+eEmAz4¡PlDrlhn ^2i7ćFe; 8Ȯ/6gHvGkg@FOGp6-0rq|F n&,=8ZOEůjCrG f>[maeZ$@XoyoCc5ɪBcO5GzoKa9Ynv>-eߣ%է^e' osc PE$:dI66۝%k/.9严I3jb1* d6{\LLQ3n.}o` ?Q%9 |g]2&j@PjjP*ԗCdWd2O <鬟"s;E$ H*H16[7 jm@WuDNz1y6NKҝUoT'ʇ6nq*PTo22R*joFِ]݃gEJ-U+27 [M o>E_g Y$1ѵ7h6oˆ՞/36,c0L 708iߥӥ '7Ӓsou RT JY>-H.@ ɯfT5]u"sDS:M |(}6:.H\mb9uR)' wEI]yULk%CaTiԬᔗ]ir^DcFF^PgPFrD?(&#P]}ihgm$&.r -a Isf5t׸4Ȟ>f\@RMQZ40aj^[.ke-UhR5| }=]6Yz%dQe7eɳ4;=:78}ZUjُ `rQQ }tUdgCZA%$PՍ91%h1Q.BR7@X=jAmgFj1YvMY2FhWg>N }!v}zba2pUNA2:zFQ+jY>;)