sssd-ldap-2.9.0-3.el8 >  AdpfU]r&qDfvEKצ6Xڠ !a dDz_sH o <WoSY(lv*(*V" 7ij2jTVJms" *ȁEnoH@l%faeykVїasR,LΟ$?Pk" 0yS,I#^FA8M-ڿY7DnyR-!u;&aF"}WASsq {:PD.6˚h3̘)65W%=-eP_`[ œh-%B2*_ZGȇAdo(DA>O# #>} Gѯɤ9{-J5Cޫe0Mc,#rD ]1r&JؼAA$o1Q z-T K&dU;dbgQ4bac5ebe458d0da31d660c67dfc92c71a857b8821ea4e1976ac0ded99c007a48fc26b7fac4aba46b56a3a9aa49dd384411ebdb170302047c435bb500673065023100a14987c9294400d7da46a0685bd1d13a6861a331d80c6404c91770176c1cb8af5cb86581d41737ff48cab5367cd8b1b2023024bec0369ea59f406c569a751ad7ec11acfbb0fff397253757ac050b5d013c01f5e2f33f0b1335d06630affe74035a0d0302047c435bb500673065023100a14987c9294400d7da46a0685bd1d13a6861a331d80c6404c91770176c1cb8af5cb86581d41737ff48cab5367cd8b1b2023024bec0369ea59f406c569a751ad7ec11acfbb0fff397253757ac050b5d013c01f5e2f33f0b1335d06630affe74035a0d0302047c435bb500673065023100a14987c9294400d7da46a0685bd1d13a6861a331d80c6404c91770176c1cb8af5cb86581d41737ff48cab5367cd8b1b2023024bec0369ea59f406c569a751ad7ec11acfbb0fff397253757ac050b5d013c01f5e2f33f0b1335d06630affe74035a0d0302047c435bb500683066023100a60cdfbc60c5054b16d1661b34a352411a6c61c26fdcc38a184378af63a680c835c3196da1940d25efc7a965802198f0023100e883476ee22ea2dd9253ed82ef6cb7e0dc0e14b90b45e1f1bae2dff9252e717701ec4c0a288f7faaa74986ee28fea04d0302047c435bb500673065023100a14987c9294400d7da46a0685bd1d13a6861a331d80c6404c91770176c1cb8af5cb86581d41737ff48cab5367cd8b1b2023024bec0369ea59f406c569a751ad7ec11acfbb0fff397253757ac050b5d013c01f5e2f33f0b1335d06630affe74035a0d0302047c435bb500683066023100f5043a01aa5862c2f7f85abef3b4dc90d94693f71673e88cfff435d1a5b951d23d090d56ae0b9212e20153ab1f1a9e9e023100ed597ab22e9d8deb558a4a04c049cfabc44d0b6feec1c72c7f5e63bcde05b0b5e8ab15e722d798e9fee9d4fd272ab54a0302047c435bb5006630640230748f4b02f13a20ee9199a7289bb41ea8027fffa04e4f5491c211f6df904cdbcdd778c15717c7fc7785b2cd3abcb408f802300d53a3d8d4ed4e4748f0fe6a9d262386cf3a814e7d3f35e65750135342c6c78ea8b6baaac05ef7777745e1c8914eb3c00302047c435bb5006730650230353df1cd71b7ab329a72c74507ae3be3a66dee930319fdd1545adf062d4576a77c7edb4a08c8c34cd4199b75d9c217d302310094fa985c597050963a1fb3aa88a15b0a0a1cdce5dbd34cdc0b91dd15dfc731efbcd9802062ecd0659f5de751d4a3b0ac0302047c435bb500673065023100e927445979590b5f8e4c7ca19d9af65131164561aa7f0ce50190dcc4b74603bab0f9c142d71ca1008626f0c6135cc3b202301773c6ef0c908c91799c47a4cddd585ea31444ec001abc47f6023e42b9265ce93921418219d3125639dc295c0493aa040302047c435bb50066306402302a02f06dda013f3051b966bb3dd2424fa15cdd3354d12b6224db6f68060699a5a3f3cc55b184bb29903a1f5cf90520b0023055a9c90a488377dbcc60da92cba0a4016b50a616da21ae2d85f7c97fbb00ffa7cc6e50a3a22500ce3833624b23af1c9c0302047c435bb500673065023100bc176ded0cac68c4f0c6932f3562eabf39408eae0046e2f5794a637e703b1fe88f854564664bc46776edabb7f9a4e6930230656d66ab5addc6ffc79772f9f0fa98bdb1eb46ed5e4e45801930ef9975d9d13b5b29c61ab764e57f5234c5f0558c342b0302047c435bb50067306502304dea0147a8ca9eb0b3eff87a97002771c6f3f760d027caa9f42942a48932d6557ad58c7c26ac93c8417ef0edd9ad1551023100edb6f5467880e259de8fe9b9f6cccdd9b6087185557d9aba8420b0fc8870b30173effbf4a71a2f168601075d1a2373f20302047c435bb50067306502303dae788b404963e476502baac56716f43dedcb517e2a4d3c98454ee5e22ec16af97829da6cf3bc7981a9fc0fb1db77e5023100ac04778f87e7c1cb54cb2d70c27dd1cb190b0330b9700b76cffb8c6c4ce98979c89927f0cb42c84506b8e747041930bc0302047c435bb50066306402301e01a6987a8b1775cf1f1aa279683ff018a0c78631b38dc92391e677e09fb535bced5f0e90ea9715526332bac7cc7cb802302f75f4e0b11e962b146c43c843c4974876ca9ca92b8d9be714a7e842680a15c1192601af70b09eb494e7cc0fdcb828b70302047c435bb500683066023100e87d650ddd0d2f264ec3fc1c7efc1c636b9f4f04d44258d01e20cf5bc055c11d4f9b5902439babdcfbc1965e39b679b7023100a63029657232aecf2c05b806542c7ae74d9e736756144ce6fb8e6e9861f5410324db91a0130bb8919d75e01e202d22f30302047c435bb500673065023006705b3b3afbc772f50a2466b82f95633440c225cf5a9e06ce04cb87a80d02788f62b0402d523d2718ec8cf5f64c25df0231008d6ba2d61014b44b24bcf8398b929ff9d2c8fd6c305e610e352962ef68a2fce3ea8b45b482273b5ce5016e51c7d96faedpfU]-sF* 4}{ukDܚ>\j6(xǽOv!`Ƚ< {Y3K+G\Z1A|޽6h_M@!Ъ:NNVPF M<hx{`A}eGp ^Ύ޽8^^rKõc91Xmv =THu5,3q 6c0id TaegwtR%PsD`x~~HIY^=R py5| t N]C݂ K]k{N&ժ  K7 4 לe7?- )JJ~'qoP z6-uɿ~0{pY5g'-ٖnK*+*h/?kP%T1K1q3T +`VNөujn;>.w>X,e)@ ^XXաש#lp}~u_oGX{(>P??d   6 5;D     P0L-t- - 4 8 =( L8 T9:dGHI0XPY\\x]^ bde flt,ulvwPxy&hlrCsssd-ldap2.9.03.el8The LDAP back end of the SSSDProvides the LDAP back end that the SSSD can utilize to fetch identity data from and authenticate against an LDAP server.do3ppc64le-03.stream.rdu2.redhat.compCentOSCentOSGPLv3+builder@centos.orgApplications/Systemhttps://github.com/SSSD/sssdlinuxppc64le) KI<?!&V7C YAAA큤do3do3do3do3do3dTdo3do3do3do3do3do3do3do3do3do3174d335dc1ca49492e721cd86f2e2ea0b92429cfaf2152b1ea5f680507d43c188ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903f49c522a3ac38ad85566b60e63475e869b550a62418ddb180e175be68e9de70533081414374682086326b4be487eafa88d89ea4531b20b8887772713a4f56302fc0b3240ac7908d8ba610a132b98a96311dc15107d17972649a39260f0d1550f2676d41119b001f2494d9bdea82f7db4240b8f2724a320b568415f230d9a43d39600bd583907d3a9c2d4f2e679e2a9c1171112813a2820325de45f4998ce81745c6331244ef10207e431375936aa47beea1155ac000b66e039e0f33e52942ddbb9a0696e323e740f005f668b77ddd3d3a1aa10fc43f3058e68a05ac5117afc5232ced2f1ce9def9f76b64a974e79f06c70b3d72f3d6deebb8beee275595bf33b11bcb39b07f890a450f340a2fe194c1f1d025c43e2abfbc53c96cd1a11c6c7f7257001fc562436a58193542651daa16af9a0b28cc35e88c800bb15967f1557dc../../../../usr/lib64/sssd/libsss_ldap.sorootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.0-3.el8.src.rpmlibsss_ldap.so()(64bit)sssd-ldapsssd-ldap(ppc-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libini_config.so.5()(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.2()(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_certmaplibsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsssd-krb5-common2.9.0-3.el82.9.0-3.el83.0.4-14.6.0-14.0-15.2-12.9.0-3.el82.9.0-3.el8sssd1.10.0-8.beta24.14.3doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) esesrurusvsvukuk2.9.0-3.el82.9.0-3.el8 .build-id02e220623646f8465f4e734bbbfb68ace65af759libsss_ldap.sosssd-ldapCOPYINGsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gz/usr/lib//usr/lib/.build-id//usr/lib/.build-id/02//usr/lib64/sssd//usr/share/licenses//usr/share/licenses/sssd-ldap//usr/share/man/es/man5//usr/share/man/man5//usr/share/man/ru/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mcpu=power8 -mtune=power8 -funwind-tables -fstack-clash-protectioncpioxz2ppc64le-redhat-linux-gnudirectoryELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=02e220623646f8465f4e734bbbfb68ace65af759, strippedASCII texttroff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)&PR!R$RRR R RRRR R R RRRRRRRR"R%RRRRRRRRRR#R RRRRR)utf-888447daeb1e82afdb257cbcc357012084f895fecede88063088315d6beb6956b?7zXZ !#,<] b2u jӫ`(y/+ dT}Uh[OKeLY!]5;c rªQTcz"5Vjp/s2HzjhjwJoм&f \~>gBP42QtDUjDLQЃJ RD 6FCnXpꐧW[{N\tsLIiǿPB[W By~)#3 y8t+sʻΰpj/z~ ư-$_ev`SY.v2P:KN' zN]JmVtbZVĹ1K ,!1h,؈dT8jޠZvTrXL |,4P p*9AU=qs0hF+0T7vp7JѢEj)|F$I*cy'❂5@Ս[FŨ::zfHm~$(4љ}9gł e&(J:ytVl-`Uk|  alV黺g6ѰUΒCz /SI@P,$s(ϚϡaRq>i&z,>^ѱ@BQ}ʿ[_2sJll}9NH}^l1WCҨF+r`OO\q`)d՛+U݀lJa&<hٰXk<8B4Nuu)% b.S\'oChI!+ݠs}H#`5InpP?K#2߀V$&gKM]}k9-lD "jS\ ;u⊳xX,7]2#7Q'TPT'jLȬ@(.V~LGrcPױ=?F(\)T#lTGO I]R0ׯ-PA!sb ]9WQshs옭_p%_6HMyXb1BJb30 {ҥgY6Jf9Nƣ[(Ni^w!7}A31q'\"睞 YfT.bֱz4 F lTi}ٳP[H6Q}׹Y'B> x0}f y{^?ݏ]&׽UB̐8op%=>U4{t?ARcK57;U!by3% ߉sTӄ:.qߝJxJ6 ]GY:G$p`,.|{\;߼ن66yY|;J^zVo^{ ZpG ncZk$$X`e2Tܰ yr $wTpUT= )6QL~6*2-8p^X&"V;澡DSWS G*U`h $#UWZX祄 IVyÖ=;Od"2E)v?둣 8C\o/ EW[ 0m+i|(gFuV{*0ʳ ` 1!&X&wV}=U""uCT fh풿`~Ͷ'#u5G#hn--[ǁFsVF #c37Tضx *YG\L/[7 o8 ,i~v{/_ۂ弃Q Iű[EL[EnC1NvɣmX)'\6tӂ-޺d뇓2=[f&Ss! lZ|RZ\^(9rvcVo UەiNpaM:9":Lud-fp(2x'BaLDf1aO;ꚧI\դ=;?LpZ@R('% BVr|?UKrsM58SNہ'7f.Z:3|>ƕ<؜[p*|щTzǏaS .jť]揂rB A _&UI?Z>CK6/[ǔNQcT5Ym'|7SLZnqbI *pP) AQhT/=!lKNfש X#娲Q-/(gD]H.晭˧{=oO^t^Ӌm?Ų ӯFKcC"C6{0@en1m;PiKDnr)&%"6?KF 1u4t.nUSכ*"RװR6P@XIGŮܹOFJɤ='č+0 SDUG[%u$"ngoQ> U `)$Tr' .^yz$> KZdKukvr 2A*|,Bq4`[wn/) X_7!N{i 6k4?H288ekR5S=OB1Ib*Fh$" ;&+4zzCb}be)zg>mP{`Q#ِ<͂H;]-6&.w7ypN5Hy0kj]̲3sc|(! o*`RG2D ge r;`3q*(/q (p2..k_J!ꎔjٻcr1:H0zɱl ,;gB$;"o:'rL!roTV|E~?& '\ $S=dEB# jYuh!L)Z B k19 hgbՁ)LՀԤܩӕJ81?%՜}tr.2S ǥ&854[pc4&O CwP1DH|eY -aUJ7djI+UqMz48m2wRe?h.D}߁OU =/ 5\='OڅQt/#\!roT˛9Wr2sHxșDyL(^:3ăz/w?'͢,)cj8ZBl?j{Ԧjx}Qi֙Ky%=36[9?<#fY}Jۋ4|j[}oU9YZ~:k/< lb+<̿#K,z"l/ oAt WYo'5gt_F )'(%{,າ|S$:-lUP^"X\II.O'c]Լaz u,o3#LEMohC3p+F1~a2qܴa5i'{Uߐ"/:(|heqU,f)yeO˹Xf@RTGTQp^𡙩W}+p=V#e8Nf({hoT'Z*oV(ӫ fUGt95#0tJزCx "PШ1 n:S1D =_qeNXeP#21izn|gZs)GWϮ!KNwa#ɺOWȰ=LJ)n2Rn07Zm~+r2c=#{5BHgq~^]&37/v -y?! &FQv򣔥*cF,V-`F:NE'=LSOl{@ A-+ Mu [B9G┳.G5dxILS@8nSv""e wfYT`cUAvW6s&=O&;| q;Hƍ?,vi)솑p'G7 b99Gn!@׍Kړ"ou\C0u WЭ[Wr]?d7AE gD4b}r1ǫ}˯<]΢1"ay/)3#kKƝCWjjw5ӱ4&hؤ#cHjU"iNMٳfBPoG~o`LcfOClT"fQrܧ[w 26ݎ)er~WduvB(y`5 Sq jb _m OхM9Os73ǁ)xHzNp(HQ>6ZVdR]=zq7)dqy({D7՜ ٕ}R*b `ʮm-i{(Cކq< XqzDHfYV黡!S64ܘ%RJgQ̣9TEPDOm=bK1P/(tw{ë֩¾2 qBzPcY61,Ql'-oHYC.!SD=)-y?/&rϚmp\(='zaTG}b hEq/yc=~m[]!ݦp1s׷Iv[\Q&PĠ@.zJMB&Vt9Oz8١UUkxHy^'?+7OIjO[ASvhQ>2t3SugʯsW)] XgzlxT-5 5!h[֞P+n&yȌ'0GFMKؘ%Dޅ/?xs,#lub۳̤~nc/*Eɋi7U&zȽschFSOsɔ"oh2gRi"bv~|i0ȵzc1N{ͯb̢LU,EXjP}m$ xR)h+5W*fTݴS+Ά^_(F~ƭ4tH& ?tҾ<ʝ"kT89-+gja_7ZnequEXNnjAyA?R$e!T(e@K-Vo69*Zƙ'^@/e PnLVyԉa"_. .zUvD OU2x}Ca}^Hxk:l}!9+eSH ?$s"DS߻b3CсfQ]͠b8ɍހ8$gs=/3:huqߣYhΫBMSrWGVM{'i9+);t6`HCʻ5mR dWN :lR@MICff sV &{0 MX]~%FQn'v0m:Tz4ļu=ۛ(ʑ=8t.Hb7I0  d'>Is=Ԛ(Y:ZKA BvzK oK!C?C|4~03=Jv99h{B?,Mc hc|MCX N!$ճ\ C: Zރ՟ "|C-$C\U&hnRpNW(k)J(b)O-j_S_CQl^9e ыz*̾: qw}WQ[hiK`ϲSCjOb h 5 ZwS}F6s1Ɗn'ZQ|T ~ XڎR쉭3rPЂAMW56N0 rTӏh= bE= g;elȧCd>؞w!x)LP93c@3~d/IHsLA!YSQ^X*y(6%y/##Ww|#[!]{sT!Tu~.4I:A//To!SkP݁k䠚^tq:AH2vw(Ş*C1w֖ F}:]b#vC yeּ=ǏlsqM(w[*1MW SW8gMּ yPM@ZǬr>t}E:y +E p^Vvc'N2k7,@"lX:? P]r$W!u38ix-e}c]^gfa ov_sj&lxj@-\߄~v񲵓uZ]nz/yc>frÔS&wm n፰ M=̰Fq9ʰw9MBI;~-B*cٵZv[7 8S]tvL#h{/|Q͠{eq+%W64csM@Ӌ) WZ!^ZR}W$ l}٠XlRIWjED階D@JFZ}{>(iW:~.[INU.W=^߾1MMԶfphLf2-{':@mq xpuOvpc(bъdS;()gH1V2ȭIHeO F MW:sTb_& ^S*)tu9CcBw<ĚbXZpY)#(HrWuBσ[JFRm!,0O#ʴ Sg&8 >;;Cp*R,IaL &na@Y%)Xv'. _aC/B D UfK%2cݬ ,QȰ./dHAegnY·v o>d%PWta(~ WA"A!e/!S%4A({jϻ/etY|Gi0nNzѴCQXs\~֟6s?ӽ]0(g8PT"v!)Ɠ3+_+6''b> 5)fV ,]g=BHϰ'v=&=|#;k'[yE`Z+iWr45&݊v']^\hZ$bFҺ@=5]t.|N,_с@f5eG eÔ'J/75W$]WM3gn1$Y(bS?cz8շ[MkOJDŽQj<۫WK0]ګ>kBILx6O'mb+r,uKýpZϰINoGlwr[:C-i,Q4bp~FM lNל;$w1dESyP5k  }"jz ߂!HSIvt. G%)}ܞ|"+l]U: 7(61'uWSE^1YoXu$&(+E$a?pouL>.m@xU,fnwZxdM E;b[J;Z3*l2kziS`ldJ[bz}sDͶyX$}[7dƟw0ոu`v-Dg,F1UZCIeř!a0^CU\@8Ca8< 5}. 0ZPN s10Asٵti*H)U{*ycviءIs0ܤ֡/^^4j~cS]$J,Å`n%8cŗX@&kth%=4W$*J2(=$Z_3z{0 `K a؈c=\Rdݱ.ʅ=6N:q| 1HL'٦ )G;̫kwXwTVm3!f,5{D^jJck)D6b㶳 `n1iڒ@=k%)B*)8x֣: T塹Ë_:L)"b#4+Y @Y1JX硡sEuK¨/%n^@<#\ L[fA h{ZF|AVbKްK)::ˉԬaĝp \̢+5X`$2;;74fݜ[Z,?&9G6_v b ߰{U,Wc/ 'fwStk]x8܈=_g!0LLn[%u<9ix-Y<%0cPq9U!6s+|؂ Oi5f'F&65 CtAkU.:X'*`'VEcL%<9 Fl7ܻ0Csl>YaYIRG]`]Lo070ni!;/ug罡whuzNGFPcی)zA+DݟE_33,?.zD'wރG@F 1<uv%Hs!>۰% gq{ܦ".Ġ7Ȑ7[)6 ~mpU"TRԽ_H1RS+ }t@-#~c>48;Ԉ+F"y!I &P~&JpjZš>+M%6qk2e!b Vje:5kQSB&i[3~ eҀ``I|OFV\-g,W@ɇxń5D.oY"}KuaH)$y/ZcAr^Z~Ʊƚé߿- "'Չ=/;LsƶZyLνAjʶCᨺ!/`hZ!-Ju)k*ے U[S>B/"f'JB`0[2>EN h9?'u{`?kH4~K+ÆYPGuQ6`q e4F*VE=bzHT^w .y^dtzv uS/PNowq$3U8BTފl )AR8 F6ӗ D kkuVu0"I ;c/ݧ }V]DDm!R:7*%,0 Җp\bA;4/[DYFvmp_Ŗ`쀋_4wOM&>ëQ<īn¨$uXvS&HxfҙL׎FB!@|fme~ ~lA|MdS@ r;>Gz7svdҞbo6 -'R";# y?4]RE#u2#MAp%a/~< ôpSDyqքQ־SGS@6e"dI/*{ t nKzwk&yL&$ %a>xc~o3ME G;I6XafEuoz8Q669HoC2u|n群ԁ4mG`%"ՠ ]Cw9XL rކ_IO-!u_Dكb㩄ctk5v)YьءTѡr] *NiJP~.;;Q/e?YMLo'y{.Y:[5Y{Nn?:5o/y-v*3Y c?Ho4 Rg,UB9XrcDC`w[O^H N}Ț;TZsLI|ehؐUE-9$._' KY?IB2Qf'#Q:gs)Q~C (fIBW.$80%pKȷ';\XR[bZF3iyz+ŧ;WG@^g ,9X/AO0zC= s_P]zrG޽O5s8R?h{[NUN?V%#'׸IG=dCB%g }ɘ}CH4XX]a)hb2 otB,NDzrwhks+e9_.TRl4fiݕYaT(]yX>YF<=XcEI0KR[U@Cht/g߯$aItX [5L‚Ⱥɯ֗DwB?.Uf#9mҙ||?_ʙ;fv[n*. T6 i6@4DcPn p5еTHHl{m 5Ll(i>ayг˄FU0yG\Z~>bM,_C[#jZ6sぺ)tѸ7x@;cB5uX5H(FcGo(2fOWSKƌi@Tb oK&&SVE I"@ppRP\12V!REK E:84^x23T8ŏq닥5x*x5݋*CE Ax߭))& 1K`zIXc,z0:=Y 5ڀu )T a b`WPq 9-W+ʆͪNb#;,{(e9:@uU>&qq?JWZ8t(ikF|SE[(5P0xaGƯjO">jsY9c"7ErF/c7:h); l Hz}mcs.ewO [KIP>u> ;cVٺX`mʌc(Eyњzdֻ0Y)7ЍWrQsMɋ1aHP)˂>4ht0P`M#s3݊e'7^{bKPxѬV,HC90"-y8dOn@PotF^F˼]ۋ6ά+Ev-{AruÿsBE¬M3&j&TZK-f>ZpwBΐ3!0r4Zλ ]]NL`IgޝkpA ^g: u9-FR$b5jz:)Ws#F|&U8 .o8Ld 3][Lŧl, b)O0+5zi1B--]aȤ׹x#͢ *7P>N81{OGEwɯPw1U2 ruSb<[e(i[dt!ƞ2ʫaQGmq 3T]qJq[?w fË.?J&٣($=n%3Gm ]_lSѻňnVǖ}˩ 5Z0,X]r-7Lȩk"i207y U1VFO1Dp`VĂmy5}n~2txU|9kQ|KlY5.:&48zt7s]I\Ԯ PA;~]3!Lkaڲ';D.ԝ>%3)ozzZ,lZR8tL1 C_7=t2{Z&ur,"`3x8ΛL9hpG 卲;l?]VKQLN:}v'Q`g wvk TLV*X1qI aWQDo/u*VIjf"K ˺8rmV4/ÉyP ~ L j:޵:P–L7e0tO5aVmkl˄Gðj..Ȇ~!Ǫqo[ueZ,FF%Jw`Ac.JizRÄ0Y=\L4uI~,o+VSoNd$qņnڞHR?ytdv;\Ps!tHD>*7i/`S)u&P)_T~&sҰX dcvL !Ryyʓ~0:BS&rh5.i͎CkoIFq@=?] V3=%* WϘeBM #lzl}Vvoz 9|iU@* T6M^3|*0ᖗ*s>9g4 ^ Z х4߫b P<86E߂(/AsQI=USroLn!L V_h|oYypFxg'H_'G^,=Jȯ>: '4,-8kim29~a[x.7onӢp'kjY_? .Gw2Ky>Gٺ a/j0Pbx3| !37?lG84O Wl/ KGO:L}޶^n.eҥ/>Cڎt&F?scjm{C S87%l;& q=vZc oE.FXI]d#K;kޕdmkZC6(X6 Vۚ/u=|Pˋ|8s[xv4OSSXM>xo3a^Z(0_g%+Ȫ0tWNQVUhM}ܥ=Vs*tLWgْlZ ?Gi(ynri1MnP-!"On.żOG?(tp$f808WzBˮohC7ۃsXz:[ Hu }~[!!SK-{.PM=&6Cuؼ0~^┏g^0J "Sb`#^AƇOΌ JvpfuQ@SEbS|ѫR0R3| #r\W$֙7ϩ~/o5 WOS?RR5)fū9/2k} fQVF{idDw@}IAw%wNvޛ`[#M?-g= . ;>!W] #E CTVH?QxBc خY6ͪ4؁i!?f%}/.mR܈)Q]oFZ;ۢ{]"ITϲJc~R6NסH+2܃`V S6@ .@f%73?_d/ 8@٢4)aiQӋЅofHjDMn.w#n5='n,t.k̪ϭfF&/=@"'v˒yEOn$t≹ Q^C䐘$k$ f9m1m5Ęcjjh~S!Bae uD8Čz*` yru|V~+2h:<EE&nd>#`s"Q&d`D I BXu DGS5a' ~h[Q<77u:Jj B|쉕X,1 trId.3_MP(@HӬJ487bE>ǏE\ NAsCGgV'8 Tg>z~R{ |~H(~>hGKTSÁux݈ '00=Y{;$+'AJPV<-Zݡ%}JG@}%l5U*+߃f"-'7ψNyMA9Xy.e*7!n[+JY]70T:\2%3䈉Yq ,W7Rv{8iδzdw£zGJ•-6;01SUO&EBLR$=Ojm886J?.<,78%f(HVV,1,H?h‡`NVE Mu0\} #`2Z'bmC#7z_izvo/ ;( h#<HR(+6i6[!Ҷ+'r5kh)j!R~iuV e)% bm_ò-Q{D֕[]>#x%"tL_cX.MFaZ @|$ x'WX*lx@ҳҔz@|lȌaK\t g؉P7Mna8 EbDyΝbqc4gx/r;@+xCK[dZ\*wʂ8kYT{VӁ5خYTC@XjEѴ!4GzuQJ: SҨr.cwm4}.\WB?5sc>N% 4iL* 4XYw󫘢;ξ9c!EH;'[ MXi{;Ak5ޣ zo|v(!*u=W3f2rFN?;c~]F:3FZO}~(`. $ 9PCC;%rid$ q2ձh/x1a&ʈXfmNfTqpcb/ebf B'Vggv m*J`Ꞹ{OK?5XyDzpo*Lseீ^84%iqѿ 묿N أv7">A:cr5ԦqyFgFWN,ҋbY) ;Wd(0H|ҸOWnEN:Mܖ ՒH J0jՠZ_dnYg5JL n&g)RmX>)ɋAϬ0HaùU5Uk7WZT8>howmP*wAɾF1zC[CqN܉ #]P쉭>s@LKo8;$6}Y Z s#Y9ͿYU^62Hj]^Bp-1Fhk˶S?n\kԉ^9rl:3 lu8ߙt _yoZ;!ɹZ۾ֵS(/_0i a4 Qe|wP\ ԓ5\[7B<̒y7p߲ W ƥ]L2b9USO$P5}x;7Pyi, q m/k[*Xui:?{buD1wõ}ؒT1i2?el-Z!~XlHڱރ}ݩΆC#pڶ!e9i |DtyWߊksv IPY$є~$&ӊ)(5 bVE@i+%8:X$7i>HEvoW{@#\2 gE4ղ9RUv ^*yEE^t5cN-iws*q dp-I1ǩ<4dcpyV`ɐ -æ-?28*Wjz1ݴ⏀~\0* %FH L4+i"nzO*\.x=.2`F[B{bj&L.pЍ5oV&Sچw+RBK 6ǵM.HoSbjqlD7~I+ڒ.:tnlE fk8fCh0)Uǹqt-`]`I)[Q;yߥ|u2#D0(pANF3t] ki.a2\ɺ-"NsOFذB9!/`PpNN1a~/ia644¾B:VHn2:[LͧR|5B⛥3MJt;Tq- V4\ӗS>bx0n3H`2Q,20cUZpTG%5tf{T { Og 9X{' >4Beb07oB|0҂y.l  `1&)0՜]9_Bi|VoL"b#Ff\"c,{ H5ȐģM-@8ЇpNvBKTn0KdzD'MJ9eƅyӆzNTDU6Ol^PB3[iXZ鰡QBó.< iIyD  rh7nm__V!B>ԙruܶp|?YqP{Pl5%G1Dj b;w88=8W9 yWn}J.ZN4"FG؞c3Q s hdfzf ~jB inq-$Ė|+p+E9˶OPq3jWW+Pa}@'9&w\ȹjRˤJ,7ap?;<dz745d))^F4mE@#=D)BŇR?t^#i[/KKJ)r5Y<5 '9hWQ˂eк֝`|([j4pȽ|"01HKM|)&Oic(2PAe`.dٕWQ<<5C >\j?'!|_fҌĨ\`2,jxs#&0GSd;fhPFLv? {ڂkHm&/֗@PUX\=<4`=Dԯ8OHc#L] -LFV 9O-KAlK#̦0zZ1uQGFUDk!bkI >R;2,ifyJڍq)dqsmWkB=?7TN3a[*v5t>ÜhJ<%oyoOaRJd+puz8inaJ#`3)>)COfC)\A"X|V%۶̼1t /Y])hlI./P]ћd;ت/w1?|3D[g(v{GGl[|Pcw5VS>/+ !K͋6T=Џi tgWrd`37ZgaueRnCU5+Q7ᑛW]8ߌ>UJ,6c%PY7(k>aPg]DzyNޯ{8w ӍV-(EZ^ύT|>`l(j"Kq:5!kZt<y4e-E/yOF<#Q"EJ/@"t]j+11*&iyc4w^]O4Hj(5tWjy'*m*L_kwŏnB1X]6Άs.1ZyDZRt c ާҠx-כY_#~[? bjԥC;7ܟHFR͹`|;?7 !8ZE38|Yq>AK%e(m&N?ӊ=\"(u7 'L (_Rk!4jZb^Woo ˂3r) { v*eYJ\6fz9?JQͻjbfkH].5Zr^|XpF5@VQdY{i&--kFvNԹ9 iQ&sCH /n> qqX,,P&x2?j)F4|dGF"1"QmIYN׌Q㴤=M\dRFTs_SD/O ])>% B__֔3"o!Ȫk4<K(E?E5ԃa8Ovyݽ=U:nl:  ,9p )e`I={(s硯'DP N(w;S!?ջ-_՞WlJ`ʎYo>iin4b%\DUMFuv|1/^y_O tR.ƛ*/QqCBEFMrRc9+8"aNOZnfn z9A>f~O D{=pͰ"dfw+t#I!?dhfuntnQ, Ic; zOSb3\oÅOz0֧r>e(/0{=k*^M̮*c8FZYM$Px{GzK|y7|ߎV(I )FHRN1F[<|Ue9Ϸ?\kd"QO`ޟr#ᛢ;ID~sFNRCBֳLkE?u|ȃFN5N0wq'׬ w>ZKPgs+yف>TԶ$emh} P{AtǻIK4z1w.~wZ{(pc€ md҆\bGaː~5nAS0-1 2oz}?]ʤHQ0(=@3V+q^N_@mk#J=*y"T;؀x[s0z{b-IqٜHJk80*fdZ 1 a<ݳZoߑ# gmQ[6OM# J<#{s?/Ќi[tsD^}׈ä$1kA^ b b{DIMβo Vh6_P(.))H񜄣/O&8IQ fMhCCZrON 6_ ~/NV6,T%O|69L#J.7!62%eɕ} 6­)3nռ4E\V2L*Xg龿iGRnl>z5?Dwi,`&[\ŶR/ 6c5)j髦)I(f@k,&lĀP1%NE} .BP5s3zhWj9wccCKA|*ZUۺq5)1YO*P-UiN IH/36 v1LD bb ps*ae_+.>¬ՌD/Pɭsj`P]P<;Aiνʴ# 1^ډ,c"s[ySy(UIeAk޴ѽ_%/,j(ePi SPOڄ>9:=v$6^Fr*5Xg34{E 9tuf` ܈j1ا,1WTLYq*)&_WJ:uBP[S{d.l/BK#z)PIr:?9NZaFHx~18dUW/~vuD^nv̤I/H ;hQݼ'؅E%UkPfxURuThX7rW!EJW#t@iMI%J ΉYg E{xǷcfbS;t}*oCAy &i;z,Z{dRh{9~Hj&h} *곍Caz([\6-GV0 `"6}=rbV@`(>A~ H?0>qs@+BA. z gJ^zNNa,bC5Y?H3Gϰ($3DkoyМ0ecbR4L͘Nn|6?~퉎TDix@DhAFˇӋo?IqTz-`*f]/Αf;S|gUނp`s Y3S @2篱Q(ثV 7:9ÄLǂk($$o>Z 6*Ճ-*bH4 GB#zO4͑q["wvw5s̵?N rF'C6_ lSLm >Q;Iy2HVнXvmyF+UE")w^0B #1kŒq=qe"F{y ]!5M~0$IjzRrDkݢR?:~EcOcMĿ )MZS*&o@][&>`e.sU2 !(QC_1]mV^e| ضl/n$x%I%RmCj[^Z̸[@.dw<H~jT7IɑCVW5a.W8{Bպ2\ -/ fgxq*X`<~S`5C|3q1fd7(k_/Œ/BIydήeqBgd9IYoOFpu'¾ ׅOG &;e&~nE퓊,O% k~c\)KlcX1;g}>g3D蛵e8 pUA&W%j-}Q)$'ۉWwh< UhH,tE]M9],U2h_%,9Vdhչn-2ZO<>7z;y8(L1<8&@Ym9izGE&&Ș-0JvC 6uFU.oZtaҘk)1mvoq=ȤiIH6Z>m%:Wɜ8p%Y.ʡ% քAT8\,q:_/nP4Utsb sMh$ n$LJ7H[.jv㾁}%K7pL>|=96n~ѓ #>e~Be$PڦmUH7=U"ϴyЕOl10vd^ZM!meImnO04Om nS`?AZ/wN\j52;R=$C鯀@e2>?Ϥ{Ovb&HPwV\_ۢXz=`rt#^2ҡ­Z!MKaE93ȨA$N?}9ix$UxJ 0֧؄<t"cәInssdz'<$JTko)VuTjٍP1m JvƇ*bMPcsɠD^U]X{cjyvpNe%QCQbR8Z"7cw҄7l)HA~/r:M}g_KP!IWdVkepD!" *z{: "%`Nt6nDI\({-'!Qs&\)yJ 5.Jط$K`P7>_7:D9<ʘ5lKwyQWkT c14 z?2u v/C>_Ȼ"̮ cl%erFh5I:-ԹeLQB6Sϸ%0UsQgÃ\}GnJ>})J ],t"T-$\xJ=ʖ,z9(ZV-Gy4}D1G0= ;}#Nh屓jkEslBV {J0kpSSΙئN q+\Փbh@c;ӷyo4'Kz>fgdb?T?Ut<"8-9B$[ @ohpT*],㻊'mGhsT,p 7DQ,ɾ >ӎ9h̔+і##܌5+Th)*ohyFS;~[Z>Ǔ`m=O}a/4<ۆeɀņ1LN򤠽" M/VkzUD%  $] y4JZȁgBY{7p<ɘDٜ)[v4$kAـ-j/ "L}O뻩`Fj1 jؾC C~l~9Hq q)^P]$OX#ӯ_Rn :9{Pr wp,Db#%g(8kҌؒl5EO3`B` .o_A.6Xt\XQkN=P9fy>{` YFT!:P; -”RiR:tO?a ԛ7ЊP뜧v}?ۄCiQU ]kY%ܷ#SϷ;Wl&2)r@Ci(UL+3)Kg?$x .&㭼th PʛTzX$"hB|POyE1a蘏b6Vv-Ѡ?6~dN?_/8o&sM{(Bk11i:^LR>-X 1LlBH-T]oA:Wi b`"rD0RtАH!{Uj=c9*3V܅'ԏQ@W lql0h#xlpr;frMM<{Yb .θj? [Hʿ1y̘T`=a7*c=dx]] p,D׿jcPR(g6K7 Y'SWЗKFJޜx";LqucSլ͸'nB $Ѱ 8-t8& a1o>a;釡iѬxJhՊ DqI5f @WG;0]lC2CoKĆUv\B\W "nm%!  ]/Qr]GZx\m C\JEV d  E$slC7]-oPݨ5HQKkB|HD٪qUt{4do۬ I?Zvqե6Pt,̻~jnqGgַ֏.bpOJ5# tB1KF%˵X"fZSےmzoNd;U &Yl2;& ~6o_9M֮eqGQuKih+MˀL jT\vŽ-pX|Y ۇxq5x 1V/|b98?%G;kqK5%+?^BXPtc]~2ΎqxW ?lXJMVP,7Zz*̪^h%xkb;D_ж*rD剶i6{HzްK4:=q> Nkt7}-1CņD%#Fк1a%p./fpws!ú5i, 91_B ˢ02Br϶˃p>~Y+ ;S]0MW{PKV&L_6K3qmfTkz.AfU.:@=鄯6N ۟.MǒI"b:`og=1 pf^xaƨ^OJ14.*?HǦ[8@1&ͥ>9a(BT0AߪUQwB"{M} ?<'uV̗ L>zL(\X˯P,p Ae]'ʠE,t ܹ\%b~E+$Ahcgʘw{zYG}C}ǥzRW.9,5nגwp-;9ǧt>Rl8` zVe%j"('\nm=g+ЊCE[lVC`E@#dk*$M^5?&4P_|kfiN'ǟ>~d[9ͅnin:&oUإY|Clc5FWUxfSA)w{*/m/'jb]*2˷v6pk]eXFM$I;D "#,x $lwsV[U G 3 ~ UP8qF EN4@5a^I*1K:ĵrZdx]JJ+lbg'Y <ߐ*?ĖbJO TK$?2Y._v_ڏ&~XoR`$aEX0Лun4o =҃=ޖ/LYy= 8xx 0K,TNqu/PpzgfBx|nrBx\_G5iqdjQaDTKbG\dXVۀwKg_mـ1-A:~%Hi5fu?({h dJ).(?M|p \/ucg oƋm\{\6^b<~"M+ 8NHeWxkgOw#(3S䉒nBdw:0̜FK& /6|`SN2SW}f(Pfq Ú6+k;- mԉtl Gt|:[04p/yyz>8H wМ4~Mǚc|)1lE` *x$U"~15>[BHrͭ@mLd ?z!&ޏ=;W+~J- %)vu o}BijQY4BGes07MlV*rZ S=VSNA4Íb([ѻfh-P ڽ<&(.hHT?Ӷ o(7J~aڲ#Ж}ҌadqR T? ^}. ).D7Wv$j25Yo frg KtCVƇM{I}"PҤLĄC;VU"+p1zw 5 H7² O. M)ME$;X3>J`V]j#I +"J7:%#ND2~r*!='W/pxB1p}įqE4 ŇF34C&bb#j/ىfxWB hhG5=TkƾӭpP3+b[zbR7H?PӊU*9l-}T}!Y^n_ w 4~xXPHL.p4͘o=`:_I/O)K"g2?ɢGAaL 6QF?yP.;҃`*#%&Ym0̜MQlYwN=|Vޯ,)fBSW'r߮0Y=- &Bݻrfg C& (ĎD073 o"}-7L:ӵ$@}p`9) wDqǷ_J'7Z _"jZX[o(,ο|_B>y N4 IW}>-nN7OTkpxarx^3 + W8 ױv4bv$|YI~Hځzr,ɦ ,2а cV";F MhjL7hT1L2"'1'LKb^{X"$Pz)u ut'9B:@}/[pXn/Hr"Uג~d,s,FrNPTdCvPܕt oͱ 4ײRRAHsT38Nٺ6?=t39% mg9 BnMBySa0OAR/Da H6Eօ*XEG>oRdVa6][]Q> Pr@O02 =: ޭߩVFp˯g%+"m=/hfKPiI4c5̄{5  ^c >~jf䂊TwB*$=ztZvJYYK7'v {6o R (-}0 Hhcu8vDS4_W^X(^{PPrbx07'\τ⤺%V2ߢHܫ[d~([( GZ_\X2i! ރbBW7AN а读Zi)jO*X 񍖞=#8 9cy=ڇ8^InGm  WOv@CR){]%9h}u=Fu%Z^PƤ-00IT?WҌʽIEk.5YCBm]Epv]i48}O@ZV\ ƙmFgcJ:?ΕLh83x~uIbӌw܉`&K>f`UMeeF^#֋<38+qr+i )K(Gh3U'&( 2LeHMX#'E-\2W:r;'D5Q_?|ٓL>e{蹭_ uUͣɳD|{~A@)D`phh4_cAI[ijM[?l8ֵ0#L6{x~R;037Oa9߸Gui*Bٔ9hɲ㻙?j񙓞VfQ˃ɧR+"S+=$,mDdkZ~G8]YP&ھRf9x9hfIX\a 9I-/MS7GGY iL13X9ȎTZ{'=Dk6C0vhk6Ir VczKKה1(s׺M+˯dQLdTIw8^yûbB ;Y^ lƻ3%bLB{[|Y<"P?f*{7ri/;`㡔L'mJlFb? P4h 1pyO7 o9k:MKDT"gqf-a .%s_!8BER5m o*3bх{٫Ya`_|Vl3 ڗi`mr[rd^ni$)E'ʯUyB/Ic2;y#3/Ok߫!ƫfpcZ/*KS):n IϚ:lcr dQh&-J@C)j^j[ʤ4_|29K04`HWܪ>4a%)¸+ǒM:4Km3'Zqԟ%U4?E$0'_O"t+5Tp&a;D uG aa!~jq@8#o׹sP3I<>=NWL U6w2S B!~haZ.xKMW6솵duq`-C&>S'm Nb}E:( U!,!Jk*j󡉔SƯgh'KDLl/ i; \UeP!&^'\qvc`3ptkfPmqNCZR)b[xRox|B/&xoKnOyk(dzPeqnr]>U;'CkIGTQ Fע2OoXQ?Ƕ޷V7Jc=K('m< X)\9/Jrd+.?I3BIh}>r59L|a^=IJPny@-6gFҮkfPKOgi*g-* 725D!f5k^V c.>Cuc 8t1rCevM +-+ =P解v|cg'S1J?{*g,UїZfcJUYKI՘u9ONz p-u\bGF⌤2+,'qOn:NN1Qu‹tUAFGBPږ3DҋC#mx26A=aW x:xX`' ǀ ~/J&)JcxSbPoZ~ZZBEҵV'IiQjdz`r޲3[4AS,G0=ب]'f[ֹW2夌{X2OK3i!dgkrJۣc[ypm^Uip@.) ?xV\L0/Bv Na$>jsT~^&n(D] Y?9ho zS*u;C-(>d6 `R_2JkCCUk/~N X4u@\HF?!ϕ~ #[I>o7 f`‡h/WFX, ce7ـxV$uf(w '7-h< nR@GQ{1ȩ Áu bW4ݔ1xSy,R,2m( ӑ!wc=5K@ P̟8f/5LXɛc> )j:\)hw ״b?Ӭ!T "`yn{`}h{m&|z\7PXՇ30}h`.XyTBe+ɧˤn`/Fw ݜ-L٤ehV(K ,xrltIFk wfDaȨ+ַ7F6r܉b{"2D[+?]D,1NbS^[yԯt̑qܰ 9(;n𨣝:exwޝBMaMD#TU90>-L#N,StAPڈkF>y@-vBԟ $[nϩx&`ogO7ɟ-.ݙ65eO#YD LOrWe+:7{HO .5\:a<N^~x־MkKŚ5r&:>ALJ1trr2a:*`(?"eKbē$o7L<#JOf{4δ')en)0Z1=AE6(^>ZN;6ȴ/y_f,3u*dTUf?ɢFLz0iKòO r7 JM m5\}}v*,lZ-$&nOX?R+~GҚDz.9`,@&B0a{gg==?ܷ:c½ L |WG%4G1P`kF/X??Aq' ɏ_ЮҨ1R_QR\"==Tv]?OrB_f4 onzz !Vaqj{ctM {.`ڲR c -XoO[P2_x̚;4 ؐ=s~Y`@~ކ`T%P&йN˂~D;4fN*VrʤLAHZ>X! FQ@Uo֗/6Lq&آ&Q(U#v*GV]VS.o>Whi#.p^9!ӧXVءg^$ޘCIӻ<1usmk]-`!w{7IP23(J 7j8[{V:._ot̞ ;}5_زpj?#̻Ζ #91zRZc4tݕEt:3E{Oү- ڍ̕VBHqWzpG$'U&_ ]ĻÊx!a;TfXGW-B­,n'>!NxRk].aoA?K&E0-\RX&A \FQݒ*V?߿u)uIa*eqeH٭}YMU=Y1'hԍm7ߣ2f?^@-S21=L 2oJW{TE3@"=/4K}; >Tp0hy`(Yq +&iR:"<7oN©U໿QȐľnj\alǑ!8 4LzaqI[ޚiTe; 2m%-'.`"['d4bvٽIIsqs|*F~S6;/iSKI‹`x7OCrN[{}wU]ajLBn& 8H+:.ޙrʝf@8+9^0F">M54R)o6+tC ܋t}U*E7j|;Y"@\X'Wn-S6t*C&~RB$/TODm.%Q03#ej1r&3"]ppzRO 29@(qd 'uǤE. l/r#X/쭳5sm0P^qr%]]~J"Kp` *ٸ̖s|=TPk΀^ڮii3 wN,Y#;raHE̖-@# W']$NX9%+ݺ֋00幺ds`9A3-j˟iݠ@&ve 5>88ߠdRgZf !`o9Z*FI ^0)%*?ۙŰʙ0m*Xqz+^dG;v=p60~z6|puʼٿ$ߨ  fp]P.Sv<|K PX#hoI=EN&t2 A?7Dj*`“HȲ`[eo`̮%z=:.x~\VZҮE}#F-M)6njsm0#:a*MJ)c0 J#zAH*A彛=XtJa;X$B+Q33:Mǻ-" ?0Zz36;oqw[>d%1!y"mo6;`ȝk$/0 9k3e"-+E +&7qYs#niG(T`7UϞKEy{i/2e؄W%2e!X_p: =!|\)S]8R]_.zaol8ctMGPt_G&j)ű  xǔk(a"gk9.!BR1r{$1Iv#$ GUJ /;{g&$R?D5;qm o_NjxD=]hHJKAM.' i7d,l[l$ ׄҝ8\5 _x2mj܊3*"z"+BT{ɁڟXI4Y)focl+aרS)-dÐlOnn#y׳EȈuZ8=u[oE( {Kn9LԠS}xzJ YϬSwE m ޅ;ãuzaRe{g5Z!/=u"y$zݪ|Tv7~DA^*!KGE_vH\Rm{1I$)..ys5l4w>zBʰnFѓi̡@WڱrkVKຢ'#l) |*ljNW_ЭN _B*E؝ 6yBP;p+5>~^"{JB\38kCF6H @v(Y t:Ôtʚ9SN<鎯(a%b ;wXyڴTqBt,7!yӎ=P8󗒘H߁篻[/! ?F7L6&X\'!$O\-#op^6qB[ k_R%=GLz}L + M kX7/:4? 'X՝{VhjW~9- ZEXGR)tc qi C Jޝrn >l<̖255+p mToG޸S|4ėsZ,475ҨǼO巕4i xℸӄ0vaU-]vZ鉃[@!K׺|5Ǩ)MR"\rE9GАd94%4}brO`-+Y:rXشKqEf-W:^GW11u{Sw;%Z*X:8wka5y+7\c &@j-= Tfhs~bfbpJZS_'q.yENqc~0|֔VA 8ά6˽OʆkXԇT XcKphD)ѱ~>hH%O=Ij.UZ{8\9݀zȪ.FЬUr1=EmT{۵̼NztaJKSplZa2O5lXtRz m?vA%S0Cqf3 A"PwK)-r< bYSe 4;/N#ȩlsNiU8E~G e /\8N|j}w1Nc;i)?z/^lc({'`dN)?:H~!/$VT ![*:dH€4sr52Dux~/Si ͝Y cԑ2Mrȩ&#|VI`/.bŧ De2ɔM J?4Y"#0{uCbkw s:-Dpȋ9L%]>/XajTK4ne(!#큞֪)RecŶ3bBW S#R-5*_cCB4سIDI1^ "1oA>Pq,zM8|rW*F $zmEХR2q5cfsz2'nU-dI*l8xLLEQ#T.?^l*eh߂ުoq~={'p'/I 1 rb_7Nd/ڦ+3#A_uivF Da)XQ;ze%;TxJoяeA38=9[N h®|VnPE=XC޺0cPfjVJkfjrPs.Sfp[."( BoऌQZaHV=X>hjl] %\";9HNz1Ы% ZYg JnwRLzD Fa}QYxd`v=YQ^Mʧcŋ!R!te#q6G2l)[14Q2B!&_" mfqL1mAU;1B?8OX3J$֖׵M0? Hĵ ^^[p1RpՐtyc#m6ZG<a-E^יUVogN)JиWx4W|Ы ]Sqȏ{jܟǺD`MBzW}k&.{jQAK,HT=Xu"0Rͦ58)YJZXM@!‰bgxGpIS)kVLfcj${V2:1|^ !&]P Ƶqmj~'Dsr?NfBZqגtF>sϟvIM ѯ}qZ\w"Bhc\J&21vH8_!ke|fJ I"/7)Tk sFc]@:2E뇁 CPgk-kU؈=@(< xNTtE, YjObHz Nj~̠x&jUa?Un,^$=E\:j ^!)20=ƂBni3I ).ޮD|+ZGUj ܣ`]s$LY]%[ 5r`x6j]Jydxn T,0J]^?P D +A-e,fxl+ZXdLJOGMGw5JN:%nLSR Ym6m F* j:Rt *khMcS;%1VxBN珒r\؛iH4,;ߴy4X0RXkʱ~Ue³gqxMФƀ}a{dJ C/ t*^;FJ]&% zӏt"=3HܫG[en@@Pfo#ˍo& \ n}RQ>Z )+ѧ֨Ql[!ڕ$˪䩈>b @##ue&`HMv֭  Gr>pndžd[EEAf[⊊j dE@zŸUZCiu,ˊC;&i$7_JՁxruv3)/+D.+bfq8N1`>ej+sf\P,oyw hyYh8;֗TְθH21GE1ؿEa[w%/~!8=%-׻#NY-0VġPgl5c+1xX'$[9Ѓ"[~jԵ^s}uC@gH? Q5w;Ve=}Rr}"6L( 984WQVMyln2P^2ӷKe߸mh \#6N[C*?Wk#P!&(̓'h]`[+.n3ގ%yC¿hfzØw'R>XTxo9q%IM¡jGx#wvYm8ݛMM_44%_O l <*1Bֿ~omhcu=~%VZ ?o]c}SCrHӟ>HLibtlż1)-\oAt?Nc>jOpq"+b) tS"P7fXunY7aqEIU+F %pDFKf(?K흚/ӉMv=N:]vT7!uVpVEx9Kyi`F@!|ܣܖN? OeIo 1}7"B+UF4tc "xQ*u`~mؚz"z=|m 1Z^5{2]p4Q0\ v:\zy_<:XIN$kO sZNx9FYҀva1'րQv ? 1Hf/n#"CG}-g,Ћo~ O0"_SLţ7)NyȚ_|3RlpLshaj7J5*Ac)b]B0k#+SM$ݠB 'ǰ:omAx/\JXVq졗&X؈.eY/!Iख़#Ҙ TGo |S:h B"ؿ7c|8Ϸ.!0^{,58b]X~ƬSKOJF`klbnǝ9ږ$F-ʯxC ԓ-jbfߑ]%SC.ќƟƉ#vp㴊sn :o\9,/B%ŭIC]]!{0. 8|+'a |d(s&A.<7H!ZYm+x 6N!̥羜ݾJNB:1Lc`xr%paxw*F 1g co&ve= S#uF B 4{B_NE0@$#laKe³sβp% Qɑ(rk+Yن/Ըu9_X4@k<*c2׭*ifjDRn!d.'*uo -@ ["aj$&6=9f2-|(lWZ0mwd=D^BVo)*g]3*Bcv9nlO&!.w!|ёzIj?p34/Є+-U(pˆכЧ(cm,jҴ%$X QD^I.Ckfÿq9SqB\+prM@ on$!w.;a^ԃx@a>Qœf>*$Oqҷ&u0p4 1:׾[/5儬R+*_,Kec-&P0uꄖem37NAYYiIYbiQe4|RJ 4TgR[ix|J_Rl Zm:t]lc 9MbG/~/o}62XS2ZZ,cz {b9;JUh/*~̶{xv;x IKLÕ ۧO3, sDؙmH&K3^bUi:ޱ ~ǿ '"%~K7CaˣkW8iTuM `X~ll H<[OdswK}Y1-/,ώ|N>i/C^ N#z:G-<l&y,wU2sn~k G-O^=isEb!O Dܮ]*:ܐ+ouM[͹G uͼ --8I3]—~X=%HGN@,fwhi0q 6]y 2󗹪Vu=0h4o]n3}}>5Uf<861I>$S^X1njHY]ıE[jXW8\UXeχ1Pd/S?-L fl{~s̈́v%^_/~M]Ɓf!;\YŸ!&WIJ1&Rxո=jvs& 7EXb0͆!P?sx :\(oDucQ JgARJeh9b+P? 5Qɠ$D:ɣPnО@:2[2yiqG ༲k.mP0n-I'_j䶆<a"7 rC|q%y y@(lG|/x(g2aa?Q+A(GH@'Ȩm%;#9wtp7^"^>. - o}ds rƘ?o߫HNd@J,~'cq"ݰIyw/CAUyܭUN:շqQo,Ԧ#CY\꧞]/bңxYp <'X3 Av9~,r?yxsvQ@;?-_vLnhSW7IKs3{TS)E=;@gƊSߔ^j}_cLM:oNО|G2}+^o DjF9t pkyR0O1olf_hAķ6z4sG:h ?bfTlqOez"_ {_(f5@\pYfJ>R=UxSWAҖtMF!n '!rP?pmPآȬ9+؜Ar=peOmhUg)6 4gBR)OђmJ7>{C n tgJq==T٫l^j7E4- %!"Yc ͧU|!uvI TgU)^q @5t/&nKRs&l[I*Ȩ{͍Xȁ*XN a0Œ7k-32។E~&,̙u3+o2 T7,ea?eZ37&P`JˀNkjP`|}hwC̡,bp:_R؟-=q9˝AghpĐ=AS9*@A{9U긹0\?椙{b|1ozoJ4t2;}i$UMN4&l `z6H^py^d2zSSXȷr]w~iӴ4hVc`2y31#ySzavw'Ȑ\.9U 飶>`K!\}f~T\EV5=;<UL݁$z7xkibw$z% !=gXUs8\u}sv/SטAb-H;dgm1*>>%E+ݒYx%80!cG$tPнIxN-^89viVhh؄.C" eAMFz/-42v!40r v*´(ɄTBCޥ5;O’\X{o[K'@ETU -GW\[fG6Kk -+ޜM7A<)Y'3Na֡a37*ɳ2\H fXl}șlǸJ]8/c\ ~=eщrNlN#/'ZAXO]5Z )1v[-m|UnnL&oɉOL<\vZNJP4SS!!M{^)xvMSDH;SKj26ԅit7Q{󈝠yO"$Ash18 *t @eq2mR=tRtPȡ;tT ] T8ka>>0 ?ˉ]{?Gq\ $L*/DQP-`K,ڰ gi৳(j%_!It̨Mjm柷HJ.m{<:f}jV};ckDLh 0uGM!0YZLp}`D,/B:Y}k!X9@oߜFnHM߆⽮#E,l0& 0/yHWkC|"paM509O |E-6[p;\`$wL_:>WiAHR5@tjNhݞ䔆ԡo̿}OU*]q'<=M5cҕA|M^츓̈ Pukr+sd$CUg=6o"L,vݑՀ~--]^rB H\>uӔ!#cR ܇i3aAPZȷjC\s~ %N~Rl+:KZh]0S=ˆ䩯\#vct )}̅Jv$tAc㑟;3+SˡU&E(μ=O$r|K*T;^&eWbhdcjS|C v2HWd u~}y{ۭe;/4x4u՛&W\+pF⍯qlxo9ѵq|!:\2?زʉC}НwfT̗|?@r [K 0oK;()Dלqn $Xvbʏ)%@ R^ów6͈*S5^T6xQAT,į 5a[APG,&|tŹٯvS4+MN:)a%^ bW_cAU,<9tt!%Ub!K}z(2l퇐ݏq`caDaьR 89{8t3zYF Sχ%i_0 P@8)ܻJy :kS` u:cѽwdy4iŗuA5qjϢ\bJ?5*={pzyjDz^S7r,OT#j` ܨ- /[z8GLi^nyY/)\.о:O7|S'{ ھS R5Ssa`Zq9KPVɀD׼KvdU r{Uf1K]A?Viu,G=l8b>ي88s;JGS)Ոn8~כrE޿tHeLߨo(0 EGJ= Vuh L[rݹ ?liD˛GXnz#6&is!|VeaBCf(Y@c'o]*dz+z9wI~IP~X.Hh\6)k Uz*A~ا'ߧ +m)^.--Q_l%x#:hrԇTքY>0g'T0nV=mOr< xzqK0]:.'\a"7+PnA"WXr{5FOT2:-xzĿ Խ[c0iu(V'@aQVt2oMDX%alߟ00~KrD1]4h*ߌXjt ZI㵵VjkWȎ]6u\հ!-NCa-4}ewΝybkQs yMJ@@[/=ޕvH6٩:`p2 '3 z?MxwI4#vPk|g:R}G/0qN.z=OE' L3sҭ,sF6j E,Fû *;+aՏqrR{'wm/,Q#7Lvq`<1A5,{ӎAĝ߿jפ扤3h (tQfdS-Je̪(,EdFa0:}'%5w4+'n|NqU2[_l6qcFq6|=O]եnqi} Ok)-Zƒq$ZI6_(eLa`7Yۆ}?N9zs5{7-);Δ %a)Gu)4@OΟ\?,W4O~8fxк鱵\Xf[~M0+D4i%^D+J%OOMRZqC%k4EHҥS5 UYnN[ *"rg'̽1 j},xRAl]!޻tsp{E f q&!/$ZuG.@v`h"8W/17oEK}h| Q](raPiO 2'$$7`$HߘGz\-Lf0e\=3AъڪL8i:Wi=9uCs/hMc7Qy>wn[r1nkjy`5@F4jS5yQ>o.h)iRgꯗ1t:MP?-r”۸vϘ+U:'3ՎٓZ>SN{qh0P+j:H'| 6@)+Αz h GZ9 {¸'dom=CPGMAHeX⑴<j4Zf,ZB9+ mY{C< Y >lC%=1cV`*|pcl*KYA ?g- EO bXc7-g]U2.ŭ ړƓ.lw]WPmDӴgtX[RQ&1Ӆzxz(]^eՃ$sl}?0mr1O'FEoZDBЦ7!1f0ji#rp6r0“c/fuT=Mt02HM}.i:Otc =6^fA\J@Gɿۈ O,1qWo!~DIAm~MnOį@qZkC+ S*zm;#{Rۇ4'.eT vJdya4O)Uyw ' !XZMgQ5τÍ,(#.@GT^\&+̨]"N`6F˜Txu/-cx<%˅p@\~ c,r\oJh|UAd4苯Nܠ9@7>lYC hţ73aJЄNL!ȱL 'B!iR IE,i9|gO9-ʖdՕLMs}*@Tj՘?єpr?ªƿ4At1@ch-_c=$Ue)RDu{QʥU=9؆Gzbihv'ZTOʆkOU/`Ku71h« wHzS]U8o:oHc)O9^>ziq*칼H&XL_2mUu%>"qnt-GC:WG*~[OX\YH!*_=p C4+`WnPH?wa _[d8!^&?yT&3S)A+*g*Sh\x7Q}_Asl5g8v$gnг۝ dhMUW~]OZP@+Hd)+xt --oZ:wG>:[)ֲ(?nV _~gt=G?;4ژ_ is6 uxLH*۴uEԆ`_XO7¹)? a Si/ V`4Y4Et,nNu-,$T bzނm5&;% ?;Dn&&0c?LʹS]έ$g<("==N5Ӻ^q'V20*;~\-0)@D#:Ä8]e/P+8:_hL׋go L_ȿ^XDж(k蟇`MIB$UC؂?^ ze ΍R 1E*@, d :Y!4|"{8N&EM2$Xeό8Gi|}0s+Z#6-t?=\\ܣ\Lae6:X+&}UInH@cg[#&>UR,`*0Y =ۼva!]D<rK4Lkcsvk# h篋VNzYW6:sD1۸LtZhkUT HPӎHEz$0V_`]p'1jҢP=}cޜB5A%&F0],>BcåBuEb.N1iYGVG\}ZS4}/%f]?`I邪[e!S,I􊭑Npp%5sD~wc后C,lLNqच3 +5^4Zz+_=\xi +cIѤ3ynv8}oN|cdn;EO}-BicG! s-۹cIbH&M85OvcyuqM?,{V`0unDUEZU#_vWD?SI= [rf.ꋫ2TZT;y 1Y垷IV -AzbHK=ch} ɮT&§V6> QV):ĥ}&tf}(H*W(,k0f깉pGz&L~fT-2iDp:ǹ̸ m ݧꡳ8.TK&롹=E(ݐjPJ00!&ȉVvk k)۳ʯ~$_*hɾ%8tͷZ6 ++44śpW@-}\B +tӉAZjVy`&HwiG3_l3jjC0R ? -/\P0s#|Bx P9necޯ&]nU& ]X8H倥OÞM2Nrߝ oLyy_-'%̟.Yә^n݌3*ЖʖS֚N&3ct(&(F pjL}WT)Ɠ 7drA쉝I=bY_3FTu:̂5tu[t|>aiƢj ȵ>31=hKBQŴOż*6LŖ9ӿ 8x}_}DG! 1'OEx4tSf&X_q@gW3>dEVt[^ިԗgJhjMwm-{h%簥Vo/EC_z!qda,2Qݒ2F4=T .#<U>6PW3qʝa L0[FIƠ]uʲ?"WxYM)NڋvX.VV)W?aJ]:+E#I°`ͷV4uP1xG^H`^,(qG![`l3|8>muڗ.~ U'x8>*ˌX%҄=k=i&p}>rЀ?,1' vel i_m5fgS5 W2mcỹ͋N^Y!w4xc.K'o.eGq ynȫ!r7S ݳVA3fcB'b)*Hܰ8-}t="Z*jv/SB$ okM?{% aʯAڝl^QUiɶ2ꨭā6y!X$k >z#{uxjţ[? ĈiJwABSLْe޶Uoa=r\1 D<#̾% $Nm5PG]B"U4/@ ?ڝ1Us>Ê. AU}uU字5!76ȓϱ˭$.%kR QG1eO}t2ol<`+qk۷B T9kٌ>s>X):`mA}s}%9=TcENVi>Ngm,yP؁wSss9>.A6VAP@=t):CCE@@[2'4~j6JfN 0h/2@C- qP"\Ӻ7uhEQIU/IjK`BCLlpn!V!Nwdcj+|_#3Cܸ2C:ĉ8VOua<|PpWDhWM˜}Y˰'Ulh}2ͻL3՟4D?0{&CȁcV3%#9NX.w䚄;p+#C&?`D{}N)emFG}p]DԞ:IMm.ɋO2w=v<>qTSb}VZ8 ~5At!"_Ki&_pD2P),bqUɹehK?GD?k3"OZ^qZdiK^5 Kv{ÚZ 瓪txxm2pG@L8ݨߔjlq㶂mP-=xK#yZgZe&XZ qT8=SYJvEn%xH: LhB:L2A9@07pOPo{_Z. (Ù0!\_(e39#:8+&rA=MBE}&ؼ˒AWFK55r=K^ўquf&πɎ^6 a5ŋ{xsj7Լ{sJӯtBMzőW&RB~ڏ`_ЛbńgS^\8F:謫mP6UUm1ϰ "MU\ZVn:R ^ T~E]4v"gdr+N(f^%4?a5$DÈX=Wegк"[wU;dnm$H5+{)NȀ$[2@f8ʾ,*ĘdAp^tO\fᆮ{.tqv١VSHjO6= oP]hrr]ީ.ur#6ϱiy"="kw1uO [Xƭ {E<\!“ Ic{g g+҉&ea'wˏ~vhNz?v,dJvzД#b~ L[R-` e{y_`̼KR 9W _ -)W>:A?~_VfV8rP'_M?ʆb5i>4T z^߃{֧ңL%Rb#$^SKP(J0tƤ4Uk;WkX,(K Ks :xbCcYcDC&&B@ l(B &NX <ǧ)fμ9( x䟮l*pz9;o ER /Cǜ>q YZ7RfT/犗+I?=)I딶';Ui*Blbnlb4&jR>v U55^9@{!TZS!A8هDԗgWf_Ƹ Zy=Ui~Ts>kVElRW[ٽDux (mB ]SdQFtOg,H`ތRy0~lir[`NuϬU*{lgLYD!KljE qeޝy']U@>)Dې/8ߣ[U:Crښ.M|ܙNDoh%+;ϮA'K0ZOhqD (aHFF>Ҋ (BTq<m.6ue%I05F}K3eN󊄩nN b3TwKN0sx)m$rgl (1&y}#7q:!h*xvLh_- BSB%CM{-oJl9ӯUd˾[Ŷ0yLs1PZVV[cq.S ؠ3C2b“@"q)7?1[?-?@v'v'ХmbmMLxYnS؃ljn@IQ8u/m)5ӊ c9[dFGZ2Z3d 3R* D@bN0u+`0ꚗcuncKdKx]xY yL <[!\b ז`XJYM%#{wIzoF8VώYM.y2DŽJWN]Xix#?5U</7oqX# 8帯W}JhMOh#:OI96ʆWh;|]gn ٱ KE %Jʳ%26Y RqȐ SG8}gWw7/SPr ޷[ #Î9&4ALR= ,%s_1{tv%|MN \y _ZK(dǰ6h?o HZ/ﶊy;"]h剥DeVp,W=;Ć mDjDnj WC?"FG|q̵0ZqngH-,{&u}@{n:ew"4Aɗ$$+졘͌[_;I`r&Xe܋gĻ)Hx,G #dX@e#\R(R..(s]lT1G wX FFl?G ^v{?}/az#Ň`#j pr Ťh`x:^°6r\Lc8=~G fuQ>f s#HJ h#OZ:g>rL(%DAuNt!%23`PwRćhB@g{# w2*tu/7mM6JC;z2s;t;Jb!EN=M2;0 n,&y*GtmmO>|0 y2ogIo86>;5m RQ=8xfע=JJs ;L/8 IM֤ۤG"$#񉧧s|".EC$nIKQ93iq1;꫸:zD(Ϊ?G5w'#͕US^)J<;e9,A 6Tq,v2#>ύ:\J$- #:M}~&亯1rS[ c:Gz^,R}&Bj$ )ši# )bX+ ̗ Z %05u Rd %Ai2T>^US= L·zq\/aդioh R F^$Y+J2`=d([PL6O@f5۲'2kC1:}qm({z;,f5t-"*i_ck9Ym4V݃E2TP}['zx 4:g#Idz^*,P !rG~K @XL/]K*) <@DZLtbtc-B౛@2}=t 92=12iPjck/8a8S.&"NF?B!$^0{uS dk-tl%:xBVD+ ^vZa1Q ^KIW{*lmm[dY }e3 pfH&.rVǰT~  ) yw{_쾮:VWӸIkoL;-%)_I\@g/ԜS)8 /#Q/7BeU\v#!c5  xǙa cmtC)T&LTUY?5O v\r{PkUl堻4_l^Z{'cks"2B7SZ'exL홱.5uqދeïBXJDUCoŕm֎1?Ikw%&UYbmh}C@5ջܧﯕtXh@w^˧<>'k0tTHSNgNA ~zا,;#鳘&m4%>Qñ^`gFkɘDhvWO 1O:>VH=BД'z1C$^ )2׏Mm'nMXQQZ"Du`sKdGv=_1ti;qSv16xL҇jTas68=zpLkp1FJ jQ=-%CSFFhgvC0 ^! ZQ Op^>l@Q ƩTBoȚ\4EZ"x~4+97٠ Cb!uH#?_T l&) T0AFPJ$.ڰ껻 @{h5(>_5FwD^>e;u*(,uC߾05<1efgm+├U\,Qc3Gs2xgK!],[w+9XQNO9?dj =I҉GP+rdz6{M6{Ӊyz7<00YcBDR #HX(b׌R#yԹgD?Bˉj@/PN_XǕ9&WV|TwST-R-E!Z󲾬 m,bȦ:~g} 'x_1IB j ݄Ҽbk"ד"E\}u,VDvl'ZpCFQX}³~MJI-\k4B9ZAQ(DLߝ2N灂ms8?0h*dR\X~lCebwaN9ʼndaj:0rC[r NtME'`Qlvtx K/6)j{ _*?Sv[RUZ/& w<چNKXΏQmC0P`^ki-"B&=m#?INv( e-dĎ_sb>iU+=ǒL崉AB +ץDS |n n2Mvae o ]ZcP6C@ыVL1ʓQ軰(G<^J,n0b^D'؂?=+.K[-##kwPN_OGiR8;7goUtWCdQ7E=flCBVڿ AQBl$ߌti:Ei8#SGDVK-}hĭ(MZÞ`SD=Uap z2u (ug:%eETfȉ.\A鷍.$q,']ؗuy<5qIn8e_-j^yV $3ɥ4R\ y V-lf6jz+A\;m2l'8yg|1x~S HsY}8(} *ًw_҂J\ZYh3zC1MbFF:2|S8߷`8}^WgܖV݉v h~# F3s#T2^#:%Nf/<@_}MR NfFMf#xzSTJ@9U ѐ5ZV0I휢h]=o9bL`u-Gfn/e .}+w W]If\8 `Z13QFvYd!_ ͱR_,s[1ϿYHdlCEW2(|S,K$ ͅv՞ yهߘL$F;U;OtƄ̩/7Im]% vN*nbKdТLoer*ފ\2. +2Ahv a: u#=ufL{[۾qif'W&>7Ja7Lh-]vm9wX5|XzTx"#ڰ9ǝ !1Fz A(B$m-÷8&_w1pRNaSExwКl5J +!Ȱ3{֝1 `LSYqc,9~m1*neM~QR%~BAg55:,2d)f:fƎ2LG2^%~cZTA格x4hW%(Mʡl/qʵ` ayiBٻѼ3 Ga]* ]Fxī-nSxc$h T+ O"aj'4*VV|@Ji,z\e~Bb`CiU gWkq{ ,9;Fǘ׌^*QeLM.ׅ R|L!~dGΩGt%wNY.HxĢSEj{{m7 A)M(l۱~rq0M&;Ark1E@ F^o2j{J5d᫑ v1ƪWA t"K=weAi$O߆ӝ_SZJ]%RTpZ#!JqgkJ J lEQj+C&9ߏ=dDש`U%f/dR:qKQSQF^AYQ}XEj7jtUF '6[DWLb.NS0k!@)Xl!ǁWW@X&6|iPN6W/%pDtExat@nfsz<֯\ãDJk*VoHw_.p)xhR@}E`6sz `T pOdoJ}rs-Kb`tLLzw'(?.u3[|K۩YY[j0LngE|CPe| NU`XgcCQKIbB3ިr#k`Z+Ejo ߈ _ڗ8B9t,O>E* {}M, b{JwOPJXWs(T;7~.ӶVL(aЫ^;eNYxdO`AB4_ԃOq;1'&2OUDy-,4<$t{J$\uB|k1Ifϒ+73[B! 0&ēkybGҰn\A"G}3'?{'HiQB"5 ԑU8>#1ݓSańjU@n1t%#NC%0{}W,/XŒW?%G;f40_$3Xq1E*1n20d8j ~iV17wSG']Ybƒ?< B&x + ˗zQO90D?șqoJd+Gre"atQJ `X\}hrR>3EAY2iwPɁks_E{`|`wn 0 {Ikpig. :Jߵ +_lSևVeA"/ԮJu+jX&hqj y\%IXre:[WΚ׎ԎN):Drf_`?e+fTfT Mד#>Gp˸?F OJާ `q}m,f}jhw7 Hc#1 @[g`dcUlzNmKϙxʬp/A8Mѡ[,ۛS P]<ajLuYà6Z-`.?&FB#])Y?Y&]}ԇVc KQ:oSIgBT_i)'aid~x$"?b)B lp %'x;G܏V 7S,7H!r +ApSլ΃˜aD'Öec([/r?g##T»+qĂk[&ˢfP01¡W\)v2CzIS2Ľ&4]J2TsY/@\;¢)c&3-+ӣ6Eh6TY[\Z+L>ע71ݴT*e(@J>՚seE[X$6nZP7!zN{z)33xg :1bsk1zH?斧|mۣh΋ sm57-AH/$6U5: WdJ_$zo+Qqz)Nc@ٜLF{8Hg-~1'V5cD{r:,H7XKя K uo֊d[v06{6İJ%mGer}u䵀wpM}Jq,ZO7Mpv&xxX@;csx:+GRrۊFBwWdlqV~Zu.=TWl0CGܧB IǏ7 D54 żDI ̣,}6ssӰ&@gޅ쿡U!NY" չ -XQPMnksn YMiild87/ט˯^YؔVT-G&4 ~zt#Kֶ<:",k龑:d{VH)qlQelv&)}nvEfQ:6 v5mݏ> Y ϋ g[alT+$PUt-mȣ1?٣o+6mS#~K "uE`B$ϋM8i{xs+dxFW+9kp/|Y$_5}?pF%'GK2›#?Ng kd n̓U>Bm\PȊQCG6nO-y'ɿo%ͯaB*ü%&XK58y']8յK]}>䤷5-ַ%SnʗC {y 4udG08[IG74Ğ3czS]_.R""'92@Vq3;Y/h ??8 1|w`~__oRpۉ-Ėֺ20E"¾YZ2^Oa)>1d VI/&5 IDlFG$<(Sɋ_:Z I2olnAa)h56n? -\وE178SbNXLq̦^um~Z\, hCt?OS'FOo7Qamw(Z.{ʼ+;lOrңR2cWSR4 c`c`xK&#$1vձAgDǭF=,f 6e!Ae5Hrm㺽jC"!T \X"-زs|՗CzvBP4p+7.N$n2@]e WϺ.U<[8Z+Qqv_|>Q'ƊlDqb$t" OAhj<NfKث-~P$^e;od:%ŝ&s#vU"ʟ1DnM\6 9rmXloi#UJf!VGٟ̈́i=~ Mi`2թ;_tVnS56b914y p<$Ƞ2 e29x۷==G݉6т*n995SN6"0;uuuUPT4 "un_sRi8M[w_t#uGҨIy c#t!ՀHfJ]eKgԘ yZ {7N TVW*J.CKDwyp UqXVٴeчB( 4T@ S2DėHny"DԲ(<[e= {fǎ9TLJʴ](!,:|x-R|&><gNޗח d$f#ǿ3y9IO{^ccpXE:cr2.~l$-GiFڜ0 UwܫŎшp;5ڀJ&V?L]B.ψ?@S"1)$Re DW+^Ջ!Uؗa ",x,PUEKVH~av@O&Ѭ5ɸN}"Xjx; ^4h k"ش>3-cl"țl>joũOrȝi;ɑDﴟJVX|n2>z,VL+"-:pi)ܙ:6}! ;l7ȕ5/O#Iނc2N˪Jnag*;`6f+# _hk 8kBQ 3E;N{R2X4}f0B) +hmK'~QYӀ'N̪x">s|YWz&jy~\N̐ / ,]3 Rl;~ |6A15NC0ԣ׭gBqeӂL:Q{e,[gRV`ZAܕƓ;i;Lf%T*@O+EP}#zpd+jt_дxߕZw[&?jeܒBq)_(T]hCCÆ[+Q.摡2+xgPZ9`^|eQ.m,eIWqcw=訃5H'r=k8(жy8z\k>+!L[&4O˗%Ê΋:| * (9¸2y-Y`ʆca$Sʩרm[|^}cs91cn+v_mviF]Srz q>`E {V0/S~VeP"%]=jo܏)UC ̄ niϐ;$VĜUK*B*lk03ԯٯ\2ETŽb~%n.>Fլͳ!K6xj :KgHR:Aس<$Hr+9?b?m#ȁ <{Vb(T؜L!R=:m!?s}> n}Ibp˒.=n|T.5]q1-Nɺ=[ebXV6:&PF-S}R ]y \MH2ӂm;ȉ(m[54XR}F2r˱R-RA26z'9x0k>x5)BYraĴSjnc _B%_d$(x:WG(~},Q/( "jeo둈sUB'4s; =3x/7';,~(F屢Ԕ5/99 iԧ)!!HS|h2Z 5C7o?&yʂz.w A]x{J9]h71dA;Xj!_5C/&&" جDنz|ua<5\~m %=h5 ۂ_H=Iܫ\!:X"꜉/֌ @&mh : zmjɋ#w$̓-]vKE&YOzO}̣ʉ65*VjI`28 o0ag1vi=S#[$;4דHd݉~OkߤQ|'fV[(`8=*bE,zm/,ExĨ._#z hk孡 Pxc3p̴;l6$sʤwޛC/Fndf|_ ƚ@'.Jv TO֛}H t ԺʟLX:]EeON {OON[>ȗ[H% ?F fo־rC?1y=zվjkk)h}wLPʹBҖ8T+7Σ+D)+x hח\@뜟9qieP˅rNJǰM3Lj2ߞovFt 6?\Z läԸ(+V2$<7AuA\VazX*A_9 56Yy6۞\^0\mwn@`6)Pyd5zj#2@$!o28s!M}EΗLs5g;FE*;9q >!IXEk@dSn#Ks˶I^]eIMH xMT='|&'_H6R L5.\2,N-VϱSbc;p&Nsw2Rzyvk PҫHI09r~-AF8gŚ-hdct Vo8냠w 3",Ea_+L'KW?C?vwV!pֻS nLQx=/}{F*Y0=nV&qL/*[#R@U#ILZ(~c+=׻N`|JmT©:n7KqEokI t_ͪXީ_d|6MWy5O]]>6*JV{/ 03V7>~^=MX=D:lN+21g5>=*{VsPUS 70ŻST&Np@G$2|ih/0h;!q!!}P5tj%* T3M/v@ϝy}>-(#)r|ƅ*xG*j?i~d`D kKy8=!B{J%f8heL뫪UiQV*?UDBG5&\R3r6,I}KO}S gIG( ?RϽ.= n"bHyo&B-x$Nqp3%0 ,P۲ Oa-}R?u͉ϬzoH67Qۓ|(Sp+bq Ńj֓`V N)` ]~;P<lj1A߈Ɍﳜaxxf XCR(ШM%uFrC"=kh7Twr/Ɇh-n [ٔvθJ^%r H S]|Laq BlNȫ ʝHܿ48 CB2mkq/tPc/H# CDuWt^ BA۾C ʆ=ܿ3I `sAxcK 7nTɄ&mwUF1Dr+E6жOFT1+ cc72~bV-J]* xW'N /A}p8yF>5إCk,7a(F4GUD}0R]@( !?!$p%PĐm'++kR WG#ǻф +S.}\?*8m6*uY2`f[h4}ò"wZE]V[;I3zo_-3Ⱦ=kMfw3 r4tHi)6a$.ᆀn UI%[$è>;{izMPE娋^=CFѥߝ=[Uy$eY᫧c- nbۘUT?AᄗMrJ7Q3 2BQypb : T A]Űy$0ž]F&#Y~t{P5`o?v{|IӜnߙX'%rDsi^V^7k.p"{ BQ,O~1hHS O8ؚO7{B̃N˄]P@#4rǼ,N8}]'\ґ|6n̑BbT#ͺxnՎm L:x"D| Ú5^Z`l^(&F 1#LR7D $Df_>S |Cn~ L60N&O&M$ХdIy9HL|L6w7P1ɬBxx ʄNf].gj' ejzjYjOsEMݴYHNOtu)RE>B/)+K J=o9қu"t9w\*:P2ٝgb:6` çT >MP~µÓ' 2,B9[r~o߃+tϛ̶B|9y ~8O@ׂZ,e\N`7k=ZJwk&։ S (PX|Vk:B/+Me+LP]їJ'6jo2C%5oscqFbߥ]Icfc貐"CӲSdc)ԕHbzT+tPwYA9M[;JbwA. qmu[K!B&4oc=>w{Djdhϻb1Mo$W/l)h2aa m4HWkYu{guXGY[hFJݚ S~]/3 d 4"@O8BYꋸ }( ol+x}GIl\:iTQi+L7 &ٟ6|9qHSܖ"6j7/"wN #T?ewqDr"ɪ8_yGppO&KtO 7 |>輧9.ђ,L|F˱6ۛ nydGr 2EM.R>3K-bm =;/N8.rO*Ԭnyju•ByfB뿳ML4]mkг*ls 4 JRFτ3J|vzEIb. ١*[V3 BY]PڳB`*iUFM1AW p/&J `ubą@VG[|D5RH:?a¾Lгȕ0Ӛs+VTc5:z,⻚8/];ۯ(V xB^;mRVBB~*;Z,xM1{dpHb($ΌT` :)'eĔˮi>N7U m+I)T[B~O6@cgo&¹]lO~!.ѹ>M{ۆ]VmS TGB!_>KLQKH/R>Z.Ưyq%TM0%ZG81C*6!'o ISzUjn-2Îgs*&;;$x3Sn_.4 jnf_!PkM\Իa8lܙ(BT Vp b"H$o_:OSBږ@EDQbJ3SRc JD^JT(Cl "aew>w!En{t`A+㠋x$8A?(H7dfU[.~mKG̺-Wb(ymC$8I7BDB hMx (e\{ɬ^a}$-~qǴFb< P@ 6qշhȐ0!8NиvEII?f%𹣦3'd:\ QƉ[]/U1f!xn8;y:#Dp ug1nz=6/T<[ݚL+hAg`;.WQ)[y!Z+Q ;p:}UTEy~aE$kBK5= Xuܶ8H)PSyL)"a!:2t6Mh&jF9tj Fwǣ=EtJӼqE1QGB-s%f;4&w$'33-lYuG ܚG UJe.bep[x@.v4h?eQeJ{rm@7P>Y8uڎUqM.=oA}iFS۱IмfE7E NAsQp `ɰx9E$RVDeam_ ixL\3ܓsFW_\LWmXY -{d۰Δ aog)qYStr8t}1O? d(аh[kR`:¦fV"Ȩi] KZو@  %ZmrZT;Xu P qSA M^^Vs4z}Oۼx5?&hAnVd֍E(Ć#1X}&gV0`}܃"ٽ(Ø.(M6O5\Am3ʁ./clj)PMLGmmL#*Ӓ@ 4YL%fĄWyqV+͙zfA wh{$:w쨮St1PZ\,Z b4XQ򠱦dMɯ+kl/')^m1zphilşO:#rX%0KXBq ZVJ'λMw_!l,4IO{Pf.ÁdLA5)sU?m#cief  4@zJ~H%o<4EL ƽ4 %,qya(`9%me/>9 x"AEgW&~;ů˜M(Ś jhJeP3=s^= t 3g#<-mfJO2~`I=R7}7 X޳)s9). }3DNHa%8jSNύ@ӻSb Oo|?\c鲣ȡ> @mࠍs=hfAgĶiA<=jsiL*Às"GK]|bL\TuGY?U[eԋ2| B?^)&f0}^'3l+_4Y 7Vq7BkN$($8OV_5 ߠuLC=%x+ˍ;A.UCݖfZoQZ$h4UZ^rM04H BmC.wݧ0>QS8S>zJ@\2AS}in7ź O)L-BJ _{Ǡv%HQH1bs-(N򾼎ĔqIPe4Muu<F'fL[Jv":n^iW(+bj{ gP]iW_5weqAAG˪BXʭn_{QFЃIiO!bw׈Ag_uL;j4e --,JAY88 X}vEuE>*Hy& imf 5#&%<\h'}Cstv1ٵ1x} @5NL),(~J&g@^C+WOCm *h =!|]th>]y腓&lM8{{_j-EE l@p3x\y FDcOj?lhsj[, Վ3fV$Ni<BR{vFȷ&saKnsN%0^+S)rKՆCġ]M#Bƿ?W !p<8'ù6BhIϭW`}RD$WM ,oQ emQHkyYJu}buS5hM%P 6 'Cbq_DM!ryBn|hRoɾ4zQ8MncdHy1Uy(22Eā:PFN[B\eq0cD =/ ~8n&킵Cr&_v 65>-Yk)o댒?V/a,+(#D>OMVԓCÛwɐVy8l#RiP <֘ygnD>߮#DFDS]LԪh"OaS3HhjXWVc<&:Kkij=M0FyiЭEjp(0~'W屒aLDc&Cs.j7ƩEԸC4 cI~ibmҕ<π_\y@d^ I#xaO҇:ῘgX͘;F *o #՞-&ю wdc<-,~adhDedD:,B3V"@)DZq.iY&_6Wf]$wңaug( ˻@6>Z#4bxO26~x(@ՐQRLb2 >qc08|p>In(׃'xmѩfFꤙP7rOZʃ~I2?sS#Zd/ЯT LVXa9AiϔJf:Wѿ,;˄+J;l; нJާ bdΝrDU_+?XvÌd?z"<sPd3T2"rfhuzOW}hb]=j)ۤqOW~>=V RckkB\ 䛠Hfw{r洍o.pZQV2R ] Ԛ阦ѱTQ}<ݻX"U".2+=mZ_#*86nOX="l'K[bl7fUzާ+TahkkZ徆,r-8#$8&,kUP:%(ӃZ#Hȥxӏ 7 ,&_< ?5[6k7WYP2 VbC٠] ({Tf5LX)fmmJH y.>D/hV-/րH!`Itpdް6/fװ! GLP( Dzt-2QS Ch䰧e^o!H,yQnX'5]<|0[X| '`V:aUB''p<=1\*[jsf!ژ 'A9k'ʮT#jȵ!-6lC_o`(ԅ=:mҡ䏬iU7$E<3K#}%m ==tW yWPw©B-Z̭x5.ohKَvlC':.B8AJ9}c&J٨m5+o˜ŋ2hriK.qq*נ 2ocJ11W>&q|v R2V3 j+}'D1p9Ib9+N;6hꦉTuPo@^^`Ke!S@(o!ܒ5D³n9n*gVGsr5 y)<81%lՓ VUrwZgՄ&ϕ+ґw4 qːfxjkPAcYi^Aj 9A)JZàNUeL|=#L\ٟRD9u<gOm sCxA# zɝ]_F<0D%T.k\'j2 B1!)8cY. 4oiZqT+oةN9L#`|u$N@F}#yv$O7䟌i K&t`ם# zVg%j. c{]pS֦t,FSKH1N6`#K!i_xR7A~ҧv#ky63ٯ `/xok dG/rڬ$ Lv4_0ȊGNv b0ʕH=-yH7Ƥ+MPB ݛ,PP?ۍh9cZ_cvNY7i ,.-3#|B3~}t*?erwLYHS5uSuni1f<f0:DmŊDX"˪A @ Bsꀿm$\PbJZ&S%? Vx ck,`\ku@ɇ*^kY18o9' םHY݁ nc7Q\X+4X9tSGb:M $D"Rp,d*|RDj bL'AǗ>lच,`~o∳'r] k NJ($lMcy@hLGu>g YR3 W1tk<bDC#פokBV1Z@5$=r6]YkP'oME̜A3eC)*lO1{F _24 QYL_ L,{ 9|Nkڦ;903f<ſy|v%C@ޗ=/W.AXhbF%C^ӔSaSGRPFjA"u@gOxJ#GŇBYRO/#4tpR(,8U,Հzy S/Izę ,oѣҭ[},ȓRra/eΦJyf`E)@nb,wFwjqA<1OhsǬ bb BmUI 4ƌ9ekc!`D*c'sJC"sCּxӹb;;i1 G[H=rmt12׆ϟD{MWSufN*JmC)2$*)w {2\W^Mb5:aqdJn/S܁Ril*mT9aAvVjAb H/BVH%*ɹ̥X8x edH&tioXȀ8(423@Hz8 Fj} ~pR6yNTN_Eh.ۖ3D?@1%6}{JCvqH o.^ H{m:)yq’x f} 0'Q&w?ML$fWu m6rw6(߉m*F5OL(C6l ]45Vp+`v7 uXgvtJz9NGoj9Z^!>-JryKhSDdAn:SVMa3R)2 zK^^КD~by5Ϛm$L³! sF.6 Vψ Vф6 oURm󨫪e|.m/ pt Utۻ R䯈 *ڽQߞvy $9߲D{t<;jfbԢ]*Jewj"?4AQhE&%Iuwߊ@$,BEgƸ{9rdۂg: ZK?[L(ScxK%o x++v h7$ !/B }s4ɔ劝"ʳ wwxͰblL4m,~J|Ǿanln څ|og Ο:WRB_Y?VxoDq~.M(^uwEep,WJvotqF']g F+y A}_Ʀ#oByYu q+)ː:('34(2v:%֠ƭrѯr'meg.oῩ5nO7TF&-xEnJ6'+k;+NN͙@!k"$l,}AŜuI?kc2ߣƾVu^!4Kv1]m V%ԀkJԴLדkfv!MvDڀO$O8P6NY#,+Ф2kr~"G_o/A..&P613)`6L9 VtܱIakGjZ[i2CLO%!(YĐv(s>!.YX,E/*>6s'SMY/<$=ڠr/\s `A]Zͼ:{r򈥜4Pv޳>30-g]"rD(bF@-:gz_%5@Q.E_̀aC/mۙTf=k \)Z?8#~un:yw5c@?ٝO(5?VpHN S*qS|.7%|8k?> A@@ϰ^JAU?3զ%#G9%1dV0})]s+Vŷ E JWi]Efyb {dx6{Rwxր v疕l>ܳ*,Г`TU'6rOVҮR)2VzO5/o‡*I&Ax8YN7TjT3z™WFG$͠~:v0pxLC@/C8N$PP*U؆NO{?!7D$NU)eĻC/, kTҫjp54 CR:Z742j5) he*eyF>ke ɛǻB2?D' /]=]a7sPb*2Y)TJ&fxI[U}h6 6hsDu(Uy^Q}y2t4`1$[e7dthQɳya:_ e4j}Rj6q;)ڬGtxwEv#JF;0hgthbgIQ FE`DEi`DĿ::Z(L&|@\q^^=<ˢHĚ.@,z'Wvke&~ M'뎠^(q1@m˸ )K5QjH}XhddI?Y5z5Bnv?Cl}s`~jDRAEu魑sd,W"OPI19_NPl`&fySRo.SU~J c[ř5r©Ӌtoj3gwҴS@SC\_C.6tGJd4$-9mSGh_\8H=6h)m$Bs6;x5mI,MAz2-` i'<#O=hH(X_⁵̮raTZO7<6`y/VɱpmҩPht(۝-P[\.T!g%urm; XoD=9-|'lg־]ˋrk4ico\Nj*o:AdA?bn,^ʵXz+}mQ|p`%OW..7\8VhSơ}[r1|6q:qHJ vjlzzW$*N}"hjAYg1%9螈Vu5֙RDrY:@R{N2Έw<J$M[0 ab)ax#u@(1>dشE8׳82Eࠅ{gV-` TS+WVLڠً 6e[4Ykl5|7^~f WR)SȻPpV,&p}X})2G`r$91f5@ uJ2(V)WX}Gjظ%CG?isWsWIjEȀ\fo&@M5]Q x{J,*yJ0O)4~+Y:->0|^scT T-gLq  kem(=Ȗ#gCHn|d#ydՖI KX<9^^ۙ]? jX[(~a#]3グ t/QA5rjqGcѬ)^P45+I>9_:܄J@q(KOUJ_^.KMb _gDCG(WILB] MrO,a Zs1\/ $;KmzLZ"<ȏz`L(VcMf]2Y?w_D5(OˡT"*Dp>(ahCҁ&(H 2:OxViO6e0)5}׈itPA 7ʢ Z'>$C~UqU륂'zT}AsV39# &1ND67G}N^d0zhdwˉ?Qȋhe*\zѨb1j~Q"7ưث"ɾ#'ysoMy[gz"$b9W /t{ÿV(UWjir;Anxtwly^,i1vNVfMB nŽQٟ0G*J=aTSuc]%yR듵s"S~ndqcwUcU_gŲH@Ŋ؋gmBمbY9ҟ*ۮР{Dks{WTH?m&ٕ^[t>S{2ԖU|ֿq8ix|8Q,:1L==LnP.uM76;zq{5zA.c|^ڤaMׅeY<7MB|J٩Bc1D:L'rͳkQ"[Rsn@O/mbӛ Sv#DP9$KV4ռB~:z 7USKd<3#jt:0[$!PGkU?pKDsa˭Dnm<+ڽğ9WoƸȅ5na%~8p9*65#-)w>*ifb5r{|_*]8XtldkucMGb`Yk$/K]p6#,ITLsӺ; 9\qrh'`E fP֫p+s b8$F톿|jK1N_5)mt:e*QCg5ЩhIHzW~ULTHs%!QKCXuaqCB ZaR'o+4Pnw=uMr f#ӽ:Z HAQ_T@h>V$3Y>+W&VQ28=쯬\P_1k 18H8S 2/qZ&ޛ`xO#Fyϯ_|k[ ED 6`m*NQ""@T+G6g#3pRXNe/ D a2M{'YA1PįAYEa+4, >67!|/~CѦY-9Qʽ2"m`X)[M#w3:%03,pfsGWg¨ቤ: ۍ[OE~~i榔yD-bvRāن ;0}kз3B*P)>hߓ`)u_'"qdN?%# گ] uTt2Mw9U`A!hQ|C4"ͥ[`_{J9a$? PpZ!`̏2Yܮ@5w ( ( I=}ݧG Uf*uMꓖn/<3?u&4V a!nzE`lY8E)-_LxiQ0EDhM%l3uߞZW9P5ںk5CqS9Z|Tvf),Ey .}%/ ܥjfF(⇧K("o8}]>d*oi8j}Mv&ѵ?Au18<.A¥cMfZ.{ϱ yD""p 菐CǘM5OP?!܅"Kh4_)a`׻ ؀()*9R~zq G- -UT3~K{za}ƳCmԹFRA9;=' ֳf^klL_3n8^yG7, 3 jtQM9!YukX'P_3(ɋ%Գ0.է.Cʪ/tƱv>CCyny!HMM-MݔXrȟVXxgFYcofE{Dn9 iMTX:2wA _Ӯ^7ܠD"V͊gKN[?C*t}hFߢJ21qX3T̗N$'M2>ֻ>PoVޗPFbKDXY3dJҥ9`Pqf:.puס[0dS1|C]>nXe(e#>XvpeKq5oi<%X^\!M]ބqhq[mvѠ ,Dd\,+\@ՊpC;H6RbK鬝2UT;TvG%n:dD,S܌Q+L?<,+]9Ёm."%csOL]8~CfPOCH{߸Ȃ }]x)mC[#(@y= &Z1"SKz+*ni JcU9r7<[7:=0?O4Qm:"c$ Q0M3 yenX1:)1H)Z2|vDZ?Ưz3㖺50&d!ݿZ:zEEDG!C)3B#V-"}ך@7^@\~ X' :CȈ'w:2X϶\ I˻فH T ĀbVrO֟="K;\Żtg!D';G co"y*dy%4ybӚ6 pARNUlFgy9|srX{k̨ZMX3 Z{t 0q LäOehtrf@!#^NA z{1 #2L-a/w0b'G31螩BF,^^T`v?uț#oȎԓCtU<?\%e~ r@ ᚩFZp0{)5;قa;A@@l2RR="7M#[q `^Kpc{dT7K԰UiͲo I&ϝH@5x Ν3/)W:B~jsz.DGkEJ }0A&@aL,Vap^p`9WQ9j#Ƨ&M[D+^ٟ0 {x4yhڦ}s qPݽ>r@iǻɋztʸ-"55/f^D[9n5`r1)UɆLu>KnLmrrn0o3,M~a)GB%wm b( Y"΍${)i^rL ё$ýw.|xQ׾H >+@ B|xNQNy7SQpV݊dD M?m n_cRf>[8u?͸/B&IAA2 P$dc0 ˝gOu)5 =v N`bcaF`= 6/ cm4X 9'kO7弐a-ir)9>jY  :/|666 B[5ՓHq?s*mIϞ~?. -#xPjvGhu džN#Df4>z4ge!d#rtǏjs+Ɍ^Ԣ6: =)…N?\>;xTl?w դD=U-*j'{r.c@7#A=p"S>{sOSojӥ?lg0 6|T͝QUV';-\ {%4l~k "K D: ꍅ%:Y?h0Y\N߬jI` P:\hݩ}¯w,M^X_YsBT^wڳݜ~[=^€k,6bQ~XMezzz!I@` N㗏T&R&g5*4,ʺywz qlj ' ;$ݬh< [ؾoL:@ a (׊⁗Y/K/x櫌d^E*J^uVIOqG+cdm +-ӷCy(-"Ү)3OCn@?;*t N ݝғu7{3X?KLlvy'G-O8-Ӭ.On-鍧J쬸!! s*ɽڴ9 tt+{|.8zlxr`X!ٶ~@:%F2M%4;V"@l/&&aMN]Tr Dj\+\n{D;WVߴ mX]ReHUKSw7MXD]=/a<* /$*Y/J>{3ndt~8}QVlM Cd`f!w*?1uMu)>[@bS\&1[g<Z Cʒ (+S8~-] 8AVIm^Rߘ >>XӝBhnN!74KO%@L>PaUrCqA5yyu!1$Pc%$[!^QLaCuo|K> DA&2Nh7NkRo%j%mAq1"]O,P{^ARwBְjrl+B }Y>H-A#sPQIQ,P-$y*/]+-6'iN!=Wf=UI¢N+sg{ˆ ĵ ^ZHC H:vÙ0N1:R=}( T@#|]y#HZKe5Y;谄\#q"3\tKX:Ͳs2U3?nagɘn6T#@L}fcKpĉ>G@qnhaJQ9 Ҹ[GmVvm0胁ީB+4J5I ,/Gk@Ө˃Sx,ӎw$ſ u9r}|=qQ< D»3l `}z+4%sPDb5!6r%fU@ּ FK{yWl V|c}!*9|A+ oG'BU} )2x>de$f,7]0%ҧ&r~YLdY4 "Ÿ>B*'"Ę2#W4YL^wwa7h˂\s)D5g:VsϿ/Wf*7U lߵ7r9 H[T72|zkW0J i œkyd0, \m:zĻ5j^8\̋xJ|T,ꔡC#T9EW T~\L%9; DX:J"+ʗMVE|ibǫg ѯ"0yGFRg~"Rn Iσ0vA]!Ԭ‡[u_<<]|b~CiJҪl T:4dљƱ[d0lͽ㹼׸Bw9My84}Z\2-ARc`qmnOfOk#fs9tQ-}D۩ _#0iUfd6SbfNp7/1xQ+^iJ8y" yq')TB-|/SxrSlD•LBUfUe`O}^T}Q*3\O(ʿ1r˛bvcۂ;H/ERwh1CS _ĈMp{<18yr (K#hKˎ;̡Y/*We\߸M'~ƽȞS dsF.su^~2gFje}dnm]0s60g2Ke=oLHV; N;/>^f$Vɤ\SL?3+ ]ԫXBUSC3a}LN8p$$.|#b:KI7Ofǹ?ZțiKvSsI" #~R>%HU 59Xz,yS>[?j +ewxҀs8/$埄 ǫSAY eLK2r0Zn w*+I&"e?6P˲vqwTK?(R%#/9}F+M) vc rzϟFG? j8⮊'M1( LxEђn :*xn 2YcT(lv2>ֻVKCte-z!@SOk,Xr,q&PF߇`@˧]sE|aGx?rpِ[5u|fBߞ (pÅkgOH`a!m27; tcvQh? yґsnK+0`z y['4@nEL _J +*4ȓjo·btyWg#lJy ="զf"T Si hЩG Uv 6Aq0,fcGngj|PD'y;_QY,"fbh\5.iN?i% %4?Cd/-,5- )p94CPJG3S,1@?thgA{%63{ 2fEh'7ۿaı-~ʺca<^r~@ (wTgДwu7(d uY4UX`(6"Me#L[$99(Y*}Q6!=kΔ83t^F`8]c0ؼ|)5sXI[n  p- /BhՕ"dJ_]{f,UwWi>*05G`m%\蹭sp3$W0}Hy_}y24υOEOU"9 *+ݧ0`H IAJ> ЇFl2 P&7Դ3v2r1-k^gEE+d=#P&9Vvtl;f?z]%\jׄF '2[M &lˣ>Sb-Vv4A5~)$4Ghx:%2}(Uzf~EdX,mЛ/:ք;hX4KĐd&سʩ`(?}Nh)kjЍIŘVaGe+ !E>-&'V[YEZn&3,eq!5RC1 dZemGl֘(O¶\ bὬ[x۱0I a薘Ɩ f/cv1&o!K#a(]C.Fso}=S8=(rdc01_\`0(_iu⤜kOaQ #dm.qfĘo{wX0z3|^B sSFw%{ʰ*3ӷx:]1 .FmfӦh1#@vF'P>Dr%!9s6 >oECNW\JrcgĆꇡCs#N ePs e*_WJNHj7MqRuxC=!ҏnS:Z+]*f[]7g_,sxԣ>{43%VY#lI?ڮ8lNP߯0N`5Tƻ& aUSu&c30}W uA\T妍do;5:**~'_R]Re]˟L;%ȱwHl?anK G1GS>S?"ָX.},!eZŁ>ߚo D]2S-Hlʩpsx0u2nQ_nPLÙZ{lK莵W}rjzǪFCOe:& ,rlJgW3`R߯ b01h;l7&Or_ s.iK^~W|ЬLOeyut= Bl eAC %F5ET2^S2&7N dy1d'+miF^*暔j|s/}OR0E3^c ňvA܀Jϸ:kc-fbYڎѐB$G! 77abFVk =\JU)R3h/'I{#?A-H!Б0@Oݏٶ<5bRn!Q^3c&1bfIt ^#.N8sko$4L0v2By$]I$HG}@݉SQ%KN} BjXIީ_0'B-;yEldDrcW*ۮV P>:@y/yEyNĿ}Ew<OԬdW~kjg^qT3MfO7[x"P_B :{ ?= 爵'A> aU/`ت)ߤĉ2ğ3^:74N9v Io,^?ZICEޟ\x-RNaj m-S',#jQ?Y q۱5UZn!̨͘G\(lFMpE=)FdMtmZgU^#=A\`ʁӋm%cT?8zc1PhK~ ; OJw;^կr Gs *uc'4;WY.=vG5 daQ% .DpγCk6u/=2f/ę8z(w)dpp< +(%F(#jCآuu[<+#75Ќ#O3WVPCSڴ ,)%"=Bv|\ׅ &ۏ(h>j\U>xIJ.$@"6[g_(}: D! ӾX$U2Զ@/4^<$Q / ]lExt8y}X(1(%/RwxaS양=lLTX 7fc8C$5آmǖ[{,JZ*BeBdjŴ~D`B[YduQ|r@q*t{QY{Q*f70p nPQFmb E ,?1i,+K ,jbehJy@ P1AyCWtRYz\hAa 5s j6l||\Aل_R 6FG/϶BbhS לqֱu+6Dp্sGa 1u =dS >0򴩭5 Ϫ/%ZMڞg_[WRA\Q]!W;t?(ߡǗY)’sI@s,Yw/m9YcQ4\r2OƠ|~|<ñh֐~9&ld?z6bFӕ\}OXf'5e~rSAͺ/Қ1VJҁwҤO_ؼ.ٰ^V_@oKu \g 3o-P qdJ+d e>TZÚ;2ЯZ:E"9ģ|M "hnF+fP$-6!4VFhX0B7CeN[tA$$wY>+z5;m~Q^9;W-wx̱d;D]jwN1w U&u_/@FȀY^*DvMZY=:T);Aޅ oeQJ6yP嘫]4k&e_e#h뜔i gl-DԺU{{ԕ^y ݀-I BbtaxӻAkdfPE7߸?>)AF ހz2*Jgu,:4ό|d [R1*lT8;.;FtZhH]OD.#_1QTpڣPgЩu$Ro EY|G-¥2Jsim0ET,*JJok'}: $)Ac]HӏUEv (vSma$qj)M0\zHκZ|[ǫi8$ŝ$;u3_MdC2#Vd(/D݆{rJAy17jPZ'CoB$廓f$IT>|ğn]?l^a7PM #PӢ >A ib̺j{۾+ D 9\{U@qpQSw^@$Mjv~7 N \mia8Um,O #_qo&2fQ(fs .[$*z̈́Ubu-.oƫ 3@NTRX7C?Fijk 1aJ@jBLXbw( n *;)!ϝ|g"YVLY}a*2OCebߖ:Jܠд 8ÖʦAh:Cc'#bSx >$ fp14Mm&}v vwM7e/tP6̱/L$03 3Ղ~:4%k<̻@f&n^ @&7~,wyǀp!g|xGDqӉ}uNC_A]nHwO9Ū-CƖd1T:^eӍ9hk3z |;5_TS=T޵V)~X-XZb ߮%;5=~6h*7СӚ(dPPGV.m,7BU :Siu'XKRIW8fѢ9DjeeOO=ʙBԂ/-6ZUd;aM ۲_lWr8m2S9³WێHEaaоR.#x`_F>;ڟZGB**`bܛ&nY&}Hzn։zE@{!q1QN+3*)GnoG7.w?cpDdj5h+ )Xa mQh b7? axpYk|0)Vnura> δC, ÄdSkvkqq -P` ˆ_lrnN7\DHh/bcmR-kSG+a- Wr|_삇͠euY4ّN|g>a%2hpbĠ*\tYhh>3&5ZkqW+(P w9띞- \xhqE:܋µZ%@LJ88'Ii(Wd59+O΢KjG7diab֭d;Iqhჯ}D1H%DF JNkٶwXG޻j0.AGüE8 "ݠ6qLgj"oj^P,b˗Skk=r0TFE6'@_(MٖLGE ;ujg@h Qh0,u+.Ч\[[`HCB?"s< / K.\~4XζmSt[WƔU)B%qH+X>}4Y.Oj+СrS&{m|cbpUd]/?2-=2WƗ57xY-%i^FGK_2C־-V`bY. &I34th@6Ыyh`$5"Y'L'DH,!"MѰ.{gwo2uȨDm DG*@9 PjIWܵ8Ⱥ}YjT!*]X#E`7ȰpD*,}ev u #xՀO}SOPbg1m~OP2њX<}㧙oỹ0W\;-<Э7AA=IDQ.J:NJg :'cis81f8s\q>~Ch \smcyoB9)zޚ  Ø{-ٺsIuSFe*-Dc)ҟ)Yapxrϓ.Cx5FifW#qZxZ'3ןM 9IZJ~W{?C]T>ץW2v*e?kЍ ~ 1Rqbd)\6m\^$\A mIK>*%)+< R}gʀ^VlyK \o6*o;v*"7tq=EI?3Q^k:〳5ȁI'noW~|De8Z1EQm *[y3lXZOOj:JX<`YܸnQ'k@Y/ee7` Gd >2Ǟ}9ǟtrbjVlxV kg{*A8A0#ұ`*F2#_\ϓ8*œy ͅ<}ӠNʊs8?Mv(&R/L tjB0a~t 1l]l7l734 fbbv z^Aw11>O'yH=&X7?gGpCΘ:+YmtWYO;d"dr*hÖxct˔ūJ U Xwg6v}{'"1=]?ےPS ~uIǦU6"Ma*WOꁖq`0Yec۟ BLQj2dDŽ[ Qm[or#:ePQ^ D&T©Lڑ܈o gC/gR8{31wmjwBZUQJ f,?C^qYmmCPbqګEX2RJ7 97~B.;Ʈ(=Wc%F6{/4מlC hwb\ωԬ7Inesf*1i !880N}]ygWK;"W=̞-γSΕ2t,`J; 7JtF녢]u[SpPHRhVݴf5tNJ/%^ةNL/Imox裼㧩^h[X%5c+$G션J%=mtq {g; ERm34OSH GZQM`AVZ7u\o%S4o^]:.FG"B 1b5JݻjHũ57rm,@m#MolwIIYR6bo ӠSFxg4TV8U9”G,'υM¿ɏ3V6FK,z1gJ/Ewml;R0|CT[ e x: }=f+F@F:jC6<ߖSFָI0FpvͽnC&Pd|SxqPv3LC1d-'*ǜ3#2y F{jx`ϐ`簭@n}E!!3qs/&Wk%ܖ.v3 6$q6ӔK--b -X:䳪whӇ1Z8+8F"cC+㔍NYYVMʋXG'tN^%PY*q[ R=_0e&/Jj/Y"ViTk47u^Kӵb4(,3l p::?Oj& jG_X K$lp-F`0qpW|##J3$a#gTzm~w_F ] yGh4[,1U@6pn  vsJ9eCd$`1ݕ'%:K(ۜlz7\nN0RFZ 1} mUBڤgM_΁Js5X)^HJ4b9x ZpmV'KԜlFd$m&[cO46.¿gEqxT%Ve{c7T nCPbeI+=Ks-ZqD$݅AYpSu݉r\L̅v ?/',||q:p EBNY})V&&N5~wםFD05I1W"{gsx c{M.ƀ6?I(bC*6_[wO#ŗ8̚8Bw؍-X%n+k;49B)8 \ͪ/{]`:ASoJg9Pd^>Si+fȥK)M]Nx<-~Mae([B5(t$4A=E_RD7CM̓>W Da{HVVP7C1Pе\YK9f_7}/X/INԇ"T^9*$\#1f:Y*Ot:r̈*ߑM&|I愱 t-O d v9eX5Mo'+mV^Bk`{&y-=vwSf ne&^9^SL* 'uel7KCFsk.8/;ko!!( YUWCό\ޗr?~'yA}X6Ε`ϭ.TZT70% (%Ny'>l$߰?ҹ 9@/a[Ֆ T2)*LslEmxtԮi `N^--ђ~Ʀc2J,xB+ UQ4"T2QT>fi,d)AcFqƍTm/kw*&s>ElMIrѸx2IFDl#G_|%&O8]9rtbV>L?r; |(9q$Wi=  ==o?PV'?b0 8I&' ,1 M02|>)K^,Xc^B(46IG.z\Aj!]M[ )Uhj@]-A]JSM_OY8c'lC󲐌HH9x%<᪕NzJٺ|uEo,43ꟴZ'qq@'===U8 |:,]c$o4="F| B''_91~W֔ƈiMerb=Ҷ^jwfK>YUَzh,+QD7QK<_a_Qvʍ` joq:nVKN*z~,yl(U|!Nc uC1yZiܱz"cx@tN1bz[ Dg{|9. XBuATEdBoΔ܄NWƱ43[kTgxnH9YzaP݌=[:k39a\dž^{`$?a筓^}4gڕr'8g sIAw0"Q >co0l ]ߣcz)yk[m٪3KikRn3\"mSonE #^#@0fBߨqBŖ7Fmq'C;h±qB"j(a*2ךMU!)Gܥ\}WeVIrqYb\8l Oĭsz;ukXZ~P;ug:Q.`#:5A cS Q +䅕ȿ%&- L[]"Z  5?P[pHAƊ&bN$Pz\F}6Bj/V Zc֘O[9_EV,J@U}Jۘ"FnR*+QbSL]Wh_JG +ZbrĶ?BmEVbqي!5{\-8wDECidQ] @#DVPUhw'3ٌ䌜j]Z{(sd]p0@*(?a.@_*,F{HL;@ǩѧC`e)V H oդvwVsiqfK2ː19KΜ=sڇ!1XBmmiK^~ R>". @HH !K7.j$9ek2 )u |tL AM'OaDxdHA 1N2/.=NGPlݟc9;%,e=ЙC2BHr)ܻ-0x`\?wt3g86iY"כZu-߼8w|ی^\zM.,? $''e5e&EpOv%'%a/ |9 gSP%έIcF_L,URcͭS{Baujp|3Komo;=aSiz`?mڱX6BE,Ug[j:SrUaIkgT턾 ynd dW/aYa܍ FKmepۡCз=C2/_WP͟pu7FKd[NezȦa0 cFOe)m sXۃ'?ASJk)c<{ަNW 'a7aoq: ~I ^eJ\Ofi紆m'vUFSE@h}sj bW`O Mab *KyJnHZuЮ;*@]?MP މ@t|ٜqjS msJs1}=|_nC,\͹tѿ|s^C=-^G3^@O?p2G݌b4cF\SǏ5"u+FPиY\jZavA+Tv(pbh\@#GA*h 6$F_?lSK(@q&ƹFG.D <˱A].7Ӫ0X[,d;Cr^ˡz9T/Fڹl];0PjC saT*؏ӒTܣx 5 2y_wa%^Ľ Ӧ:lNdS&Jl9q0JO m%^6 &5vAeK&nw*J()(2&I,oGkɟjDFFGrk 2^fEX>OqQdCjNOhz`RnIb$ -Ȁd`YCcP^J~?Eh:}#IJ-&C 17 DO\5;ĵX}#<*.\62ݥ_² $'BX܊Avy飮=6}gw "9.N!u3%+:;u4ަ ]J/0p2V2W~pSnu\ <@m`X.*)r,3 pF A3`@xytA{ 2桽–D\A؂uj5MܦʈQpEv5:! /ξsax3дQ=1@h|1rx]0V@cB,qL;f{{P4&`ÙpPI{5CouLThI`ͮښgShmO@ FN*B<&T 'Lә-+-e2; *llA7gxuj; $;W3E 438 $m>WsnSP?LƎJ Hx.ib ɤ)f5p:@@;tOa.X_9??uUyFP8{pf)rw&!I45Nmdm;B@7 xE3<bj:ӮKZug7,>7M M"|`MJyo(G^ROl|L[7Y~4{|h"(gTE_`%jE$>uV}F.Au0C;HY9[P(by2IwCNH qh)! #qSrהi%wupײo.E{bڠ)nSfKSR3 ;2.,m1:ϫ Z:Y(kOm!e=vX&v`h#b9bC aܲZR=djhIݙ`L $eӛ!N-H=ϴty4)% "0RȨup&o?rc(9~JiMW U1*l"`PѹPɸMh#e>nbȽQrM;HxO,.G[}ӏ* Dqqjjǩu!D2[ @5V-4s?r>PksE| NFɃf.* Gr'FX'xVVbZecw$ SyĊAO)! Rp8ɎsPO"^x{ҹ<Ѐ5aFN?1XL\%cwY4fY4c0|S6 ik6T00Y^*"hՋp 򿱽(YRZc,pM9^_ĩJ$lPv rIhjJg\P@:F%m`.1jovqn5"(دͪV=wielAaiC@ ˏщ,W} -7 _[dߦT _5Vb|xNzbrJd["iFߓ4`;OCmj U%rн9P$*6lASwMǦ%c<2nb@%Ba39Щ:Zgh5+7/w*!MOz#\ q|]4W+dnvR ._XIʶniulri)ǎ.[< и+kP F3z9| aGّܡNN.@_ fKw^Ug8Lݻ,,Gb-RFzP#իQZ Y J悵ቹ Fkzrg 8WZ'nA J\Xc[BG|YJaǾJ;\T3p f2,@K;cMyc"JZpS!6X.˘MWTQA W`sg=hKZ=z+ cjJ#@Mheڦ(:W›_ Y:0%RF|=vlt$:}|ń\ۯ;hvv -9]>Hz#L{))'p]سv?U(̄hCf5bZK5A6Aު:x˜/AI;k" HVcNAnSOZ}P;ePHt D f hΜ#jHGDfC`yvʋ#'wE1,ZI%f@9ܰ]myCfk/[3V:Zܼ.fH+^5onFd eO xs' Dl64S'bFކ VK?TwlзśvUaԃ*N/R6}Txk8 blTޛ0$6q5e/bwSƱ)u}H}ȸShlz||GA8Cc78~j[2\dE';L02eud:@?yKltO>QUD\MNVykmcG0@{£6OmQc7apdVٝ^ M]JG|SIŊ$Ο WW?OOLs_ߢ'nO p:AroaҬ+\APJVEv&3UUDk)qc=)Bp鹳 nv-"`cwc#BlOpF+Qaz89oJRsA'@aÆ*|8sY2Tå .10]ߧ-eN4V-@lL32͸i"?+|V1c}ЀMos;~k\d&]k͞w։J(qx}rYJl*:VY]S Km2v|D=j#p}D sSI6dI fZC&(?!%6Yp ]pv.pi'pEeCWo(0jީ@G>czb>&va-a^:XҐv0db+szC\[,7tθ&X|r/MyљU g]cRu1ާAot*^Wj կuJٻ[^n2l~h@5nB`(u\ih `O6Cօ+v:z: 5psZ#2uQ"5+^y? `p\ߘH.=Bʍ 2 :;tT) I3#ӡݬjǁB"' [li4n0Pn| 9`fifKWk k#w}ffsFz7[ݬ*7C@$wi"pD85R}:Q }mt lxicEC[?ZeY3TpO6=]BPzFE@{\ z!8?IP0v:Gd7@G19ۊpjk||=hG獱(y#Taq{/mṼInBXg@*?Мn#ͫV}ZB.ݐ MY-V? ƥΓwm8\D}M >S?"KU9*VǠfQ RCE/csj߾ɪGQ6ϯȭ0u:چ9; 5VhwfcJv8_9LMqv[D OB$(FҘqtD|1cd/>h"៷j%s{K\c h,iI#RKP?_< t׋I5X$|Er>FPK4˩3xHaix"҆/] )@J<Dp{R,j86X&*PT[\??ChcXVIgQ\@9{lC^ؘ.iP"O Ѳae ]v*x"B?9#Z3d"ߗ]̏.bIgvGDl'0.IEۓg a"?n):Dn m3eWǶgp 8y$4=/?'T ]E&6!;tًjǁngrOKvv#+T\j&q|)^0?lѻ6Zk_ ]3DEC %anS~kk gl"4hB|jH,'BC!L Rf$Ohʁ;DI`[eXvCS!Jht4q-ZgdVFnpǭgT(K.g咦iƠt# hѥ7j(.q!\R<{;f8d+z#}AMt?3]6aFܑ:V=Ѯ-,S/9CLIRu4rs1=S.Gg>q7Ȕs~Z?Sj1GI1wɧ V|hYu#m7Z+/-K:]&QQHb|VBHl.5:[ZNfǴ aQа>|DLvnth0!钑(d|6۪A[0C! n%V)m6h>:ȌɡN ^r7!GfXx%4jX愐ey UO|贚D3r-%n8f-*$4AVϐI$u5 7}ƒ洢&Y!ݿy?j[UȬbYxC)klT.H{etW7f51 hRRwZk CfZvUQ~*Y}l"ft8bX(АiUCVsepNMpᰆ^e9zrF<+V~a\A`t\0>Y\C+p*"~ ~}v͠{g%386x w(kmmYn楚64Z .N릥 g1ߝTma,٨/[ߊ`iK}ld3BtBk=N .z}֑e%g#qX[=arh3=)%CLP]u#]̘+j;wAFk!N~FI2ֵvVHjKpj+4ӰS /v-)Hn18`KSz^ǧdžNc>$p\;xCeD̏+=/Җ²yKΫpd VEhx1Jz([i#qqJMٰ Y}8@;Ԍ3^ (>C ZFb Ao0T[J",tAkC9ԯ2&If΍4m$&EpI /$ t'js W V)>D\|ej)_|%&O8]@ZA{18~wPrI|?k%4ujڨ)ǯL%0`{A;z=O<(5l<A5(tYL^3}0D%h x&˩)-)TgYrM%raa b`Ȟ@u ZK?-ka`,%)TV>s >U# Tz[xaV/< ^ }>N=q`!s>M2GwFR[t1tX8Ã(5O]VΤJ?V EfƵ3xVe~f arq>Z h\AeL:U.Ǐԡ[;M2STby},!kqkJ X/?nzph<ѥP,GުᗏKaQ}of~y>R(l2>cc~NB`szˈmJ^uo34Xv\X$5W9qrՙrM3&1XKJǔx]BP2u^* q!=i3nB o9,#S_*n)4+N,Ѕ{mjɪ2SG$|3osnJj[{ra8df!nCUàGGކL譮k~A\pY{lDYV{ɘ x%Nl2<8SmmToY7^ȜŏQF}֩ !ESrjSݚ(N~9vo4fq^ bD=#(Wd{Q[(ja8E99Ժ}˙Vp/o$+ztuRW3zRnUg굅Zg4*G^.<`{0C-,r<Kt޷uHB H/0[:&==1S)[=;g2 zXw!*ИkS[L 7yVH-, ']fG6*n*wivL]Y(a;GeVtK:rG]~xf-GizE"dIC}}  Vۖb|^I `x0#^1Qz5r1tT^hqBt|MOB_cy#6R+&;-w UjSJ^|=d3uoK= ܫ2*#q|RpG39lMpqQmIsKu`kZЂx' WYtV|,-3~DF!2fZxCV)k bz}BcMuY#%8a$%)XigO0QDn/@`5t1̜ k<Ֆf\ cd U_;++UIh$AGY8$d̉㯀V{EPrOx9 9oX*1s%{C76<% M(<=FtX}U"֑Rji`斕]@%Jf)$`-6u *M{{xszѤ"B=0ssjt@(q=chr,l]Qg_S:5lV3gaJ}4R;Cu,8(f#qg;@!Ɠ.+.vrԫJ*|iEen"r[[eiIPj XOʍN O-ќh/+\|59_mk֑8$ .5;Z^73[L)Rm``oJ9i2t/TL@] oQ:Hq',9z:nR:J3L &U?z]L1{-CtGC(3%6 l/Uڧ[i}Hl(##v+o9erb=N (?(k{\͘K]yWyӜkGEJC4gkR/><#y4ը*+ROczI~!~g*1Y);iE"mtZ7G(d6;e-8c^x ^4O}P3қY FJӛ9Sy\_J'D5j- 5uFd${̇(LbQ4IJ%'E./)l GٻwzB{M]\a{A;4~NS}Cgτ2JDO&1VG# kZg^MA|8J.3HL/zSP7H-I<ܓ| DƁYO+Rk@ /ކnU[*x,^A,&~鼅^.m!H>'^oWݾKt٥1Fs*%wƊ117В"UtԵ ^R}U`]cMxX6|]2deVRT:{j%c:f>SK;sfBR,/:~_vclXk@5wHƍՠ;v"*6ƾ'qD^"Źr|~nA {H5'.{#1$h嚔GJ, ﱔuҦXf.:lW2jP15 ( ǪrsvKV-rPOϯJtJDr|Kj}wì^r@d,Z, \(b5ݠe֝ԱXG;9Sl^*Z>Y1\|ֶgn\<4 ΠQ%.]Fi//LamIVM3썻fqy =gwENތM,eۘ<%4ɎJ7& #++*i;}KlS 2 ?ܵgiCe:YOmjh`[Mt{\ 栲pqYxJ6+.)y{X?=,=I(88h{Okձ{$9R;2yamp^̴aXI1Q/ Dž2nu<1@ӖЬpdþ`KSmGw߼)|nDEq82HAMAC, y}Q\o3:nI96&< envE|ˬ9 :2+2p"Y F Cml>Uz#4Lg52Aݢ=b5 Xq¹#<ýa(z¹I]ȉEJ+#]\hDA?FrqMǓ{V̮8,nkDn%57M׸@o!E4=;F{X҂wU/I1G3U2ҾY']5@_$5rL\$ GAN[smJ.k}'Lؙb䆓jO+nr5 Nʼbͮ]<J.x >N< yN[/IȦD2UuɬS62Zm3Yj҄d~5S/4quwhdDdyy-,޿FPf_kIR;ĪO=4n]ᶋ~6:Lfu$'o=Fdݫ1P"E't 0k`.s idE9,ip ]D?/XO5dl劧^ D}fV @;V Ј蔜-1R!Î=U+MnT ZQnfT>fgu+>VDzuLf:EjAiOإƩdG! RhTxEDp VUenV=DVg /y.9k'm2I|$PF~a~MLR'|nnϑt7<[mMrYܩތRFƼ'M:;*ܘ 􀷜Żݘ=pݫf>R=u៌2d2akLt.JHH݁u)ZQ_5Z*Gko3nS!8r1dpȹ5 ۫0EjNs6Ҟ+50 ar7NRȹ[ Uܼ5ԏ؞Q| H9<l$a涙cŒaM`ۗ[ml؄ W~LMN.m-3Fkݷ A ?gr;ï$fFq{ছ {GLGTƜzhn-F:3NVb ̧VIS45[l|Tʕy{m$X|m1n*.gO jzʼnɗ_]R?lJK/GOƢgBl >pkk'p-0Cy8K]]ʛ}١xu7 jaRږ\K mB /"\o..[pwCbX1^&1":Y#&]E?8,PE'rMfg?"O)Vc% \8ڧ.У1"L5^M;3Yt{7EF1+i`|j1e/r2vqox1ObXo}\9qoh[xD.~זvu3XE ^օ%{IEm''ck,.gBdzv2W2IEpz&u,0[Gj@UXN}dktn\>S?!~dzt-3F=*4j|$o MLtL)儝S7ܷIi00n3cD u֌5` E"d+xhpʣce[@.Ο֨kzs&(m:VJ!ZaeVG< cb1#h,l~6ȸbq((_>^ĸH {ě;/– K1$fUˠСa:!!( /&̟cA{;n>_`&q2N1<*tZ5&g+)*BYTfѻh\k8ێ6#r%]nppm#/xQYqQ=/O&'^ }۞E$ >́Q環֐L quk7v@̈>ycHhhZbfPTk/]9#?P=xBlGhnEq>d6{>chRq#shoG#WԷ ޶y#v+^,J @I]{6 VWW50AI9=N'AqNYctٝ NBժg'OO8q:y++'_>yצ'NW j,֋tT0B\jWd$UF50nAP5P0 tՕ67Dߥ6A#{%3r8BlZJK0(/=Iig2g,1G [LX(^JfX=JF'R}=YOS"V㩱kһ:vDҁ0El `v-lQ5bg %y+1h5pi6I04[rDdV2o97dž>iIu7 ;jn2NMRi[{i,t.;`jӃnj9tb#iN3*G&E{Ynv  5W!-fޒE5 &\$z`((,iL(ΧE,.֋x_D85%3w8< aqHkĻeKVuw/QIK޿˥J~ǁKJ̋˴- [9:xv9:IE_snK#1&K#9Ovjd.t+ R; 꾠!vn7"8L7Ǵ^FFcfю^ՔX́󘅥Ȍr!_mam8&!Ftji $%㹧( sx?Δ#UXk,}x NdP~Q>vi+R[ťYʬM#wƆ, 0mdW/kn~ir1i\hQ|=Be0N_.e|R]+ ss9 Xp`lիwdwGvY)?9Đhfc;Jy ;{8͂Dǟؾ#,z7zKWԉ|WS &cX;!u6.qBM{59wm] /aqkW!XOkU2$1\t6{'Bȃ;&1 r粱C(-1f!SŽ+ *Rf]ʦkz8{4]h#ǡnG4ĭ\zW~ Wl|7.}l.qۗcouyxgF\8wʅ/>BKJ1x^x%$o|4'cDl7~AوKѧ6(aR|U5\<,`1tT.^t0\>Ņjh) #byVM[t^ɭ~1Gk&S`#~3jPIl>թՁO FTZi5mtjz[jvȺ'HT+' bg{qF&Mrr3͖Z3f0=;EAoTjCYiY\lkKYy{EP b[js͊XQ)CRTN0q?G^L(Te+vTs5q ou& g4Yŵ(䵉rӪ.uҶ)vmaK\Qk6&ZiEZ@VMgR[SRR_h?o33ā5X_Ή