sssd-ldap-2.9.3-2.el8 >  He[U U]D}ڪĨ /z{H2|h:e&7X=+i윕("H9yvd /iAL%Rb<CcSbNh1Hogz'S'eUJnoAM V%3V~Q8C^<)&1s!~R]*ti/,~j b:{b{R?g\5dQK&Qk0hIS /jt--BN^rȿ2fG4~iI65D&;_&.>m]DRs__A֏ʴZK*|ptbMX^[w[# ]uNcko5 uY :JNQ[án}Յ<_Ԡ;v&߮j`!HDg;r>6pj9*`~pkdRṕWRRJdP(ED˪4552b9360706a80ccbeb68efe717246e18d5ed55799a747693211a2ff96f4a8bbd38a75dff5dd935a6239bd9d79bdd28f2df59df50302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb50066306402307e0ca6e804fbb36a0298d8335b88d24bdd39b69600257e772a10808187469f57fbbae2a0ea27863ec43e136b24469b3f023020fd0d6da776f791ce104ce981a92d9016abcdf6029420391fb63256cddbdc80660bc9a6c4a0dd5fc786c5129abcd8b10302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb5006730650230304efb3685479d3c0b9b3c5b56585fd00205df6c94a7c721eea1678011d4622074fdfbd1ef290d4192fbf1db6f02b5d9023100f5720c01bb887b750482e05a432405ea3dcfd32bc0e4bd029d7781fb313400331af2092c7a3a6581edbba195bf0358d70302047c435bb50067306502307534b2d5a8106de2bdff101c3a9afe29245259a06c4bd9bf1dcf2e85c7fffff349a72819135e57ca154c72fca410216e023100aa60554189a090364155c2be7830749ac88fb967d9baab8b46dbefd02e09cbc13221856a37e586229d639fe9d8e460860302047c435bb500683066023100d4d30280c76001548ef5ea787c36db0799a2505ced68d25aeb2f7bc455d8d39e69b4ed5c22ac691a5b7e4376d84794a3023100b176ba384c1f087f12484afe4a6ec4442eadd2147ab99823e3b0ca7eb5bac91a6c4b04e80d6544400bf0d1c59716cdb80302047c435bb500683066023100dd46083048053b3a04ece842a4f2764df6ca83c9d5925229a11d6334bf7dd8153a1e16943ab09cb1b63ad45ce38d2f08023100f538af5815bafed4492542b9b4f51357ece4b07ff6f042576ed09e0c4cb7abf00b42c36a8d4f080f8b6541e1f3f270b80302047c435bb500663064023049b76feb2e68f5a4b511e5b67c5d13ec53970549d65eccfdb4e450db854d7d343b47d529d0af4d3aa59b01396062e1c902303177bd6e945874b9873aab57fce1d8a4957b47daeed4c75529481a2778e55966253c84bfa9413d53aab562799eff58ab0302047c435bb500673065023035e3ea004c2ee39e01250a856ef32d85c39738dda2b4b4b90be63c74c0dad473f3c91a53a80a08f7c8af7aaf410c6fb7023100f1081aae386b36c8e89c145d43eb3fed17bc54cb1ef84790319d492b8bb2a930ad59a7e0ae4f77c74a97ffe289a007540302047c435bb500673065023038e9b1d0c40f279167e722210bfb6d827161000c58785df4e54d0919f822712cbf8697b245560765485ff0b6fe74f5c4023100ec042ee4fba7478363d93ab8a53293f4533fb9d5d9fa93d17dcc0eae303c2db93ccd95a8efdfb7b12dde481f3a57fea10302047c435bb500683066023100e8263b6fb9de340533c8a9a4d6fa3960a7785418a74eaa6ce00bf55de5416ec1a3ad12c385782cf2cc1d7e06b1abc4b30231008a80831789fac3d186ebab4665a100e7d49c2bcb0c826715cb09f35baefe90e5b05c3cd44863d1547a25baad4b8de6ea0302047c435bb500673065023040242313251e8f0b6d2b43483f50079eebf16f4a7dd0f095b6684862bd1175157e3cd6f012317215f01c12213820983d023100f5957c76bf9b541523a1b907d9ab249616b22469665313eb549da251a7fa5a7827454f5367ff0688e1570094a7c277a20302047c435bb50067306502304431883943ec3293ef4bde43d9f795e84a6fdcaa9b45ecf72ed2b0cb62a147565b1c3630df6fa3c278dc94f840eff9c30231009ad124c67c62052bb70d1925d9aec342d974fe32b653de071b5a5bc482b8712d030711dbc9496950de94dc006e20a2b00302047c435bb500663064023079e478298f3c21ea8c45d185f9632539400deb6120d69062602b6a2656f1bbc24e2275b49c78ff0196a638a94f0e847e02303fab9e02bab3ad0f58017ba301fcbb23445c5cdf418ae169570f747cb444b3f1a1f6c16dad2e5498c4d2c17dd5b84434(e[U U]Dbxb*J_JI⸢d@ ,y[(nn`kFER'Gs(Pat K-+~nv0Wh~F|A?ulZH0=S=7E.d j TG%1r%ה6sDi Y/gy_Qr29q`L)\`e|Xz˹ Qe4 gMOWd"?|pP]*ia3 [nRRNIYL, EPXǾJ0ܫ}`\!(h]M21w) =#O8a:!c&|>`?D?4d   6 5;D     P0L-t- - 4 8 =( L8 T9:f*G,HlIXY\]4^V bEdefltuv(wx yL&0Csssd-ldap2.9.32.el8The LDAP back end of the SSSDProvides the LDAP back end that the SSSD can utilize to fetch identity data from and authenticate against an LDAP server.eRg9ppc64le-02.stream.rdu2.redhat.comrCentOSCentOSGPLv3+builder@centos.orgApplications/Systemhttps://github.com/SSSD/sssdlinuxppc64le) KIs?-(VC2YAAA큤eRg*eRg*eRg*eRfeRg*eReRfeRfeRfeRfeRfeRfeRfeRfeRfeRfc30c9c4209f2200286d4c02ca3e3a27b1c49ccfc0de2825dca0820ed97c77beb8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903ece1f06be42d51fdc7a9f5be812f629cb277e859ce1624399f921802bc732634430e60b9f18dde1c5ba6483b920319929a91f3bedee082d2b808c7e408ce18170a1293eeea7622a3b07d608dbac804a683f46641d451306a95233dcc2b862eae8d67d58c89757df11c40b80e2db7a74657aa9ebc13061a61d4caa2a56a5f262ea6136bb689c912bf2cb40e09c824271fe414f78c1ec17388f068a70bab85ff292c4bd00fca949585212db1ff88d397c05a68c8d19c86d113b534b736b526f3a844c92f9edf2e9e9427ff47cb733d1b5df0e0d7d282c98222940d92802c21c0f36c8910aa723951d35c717e74604715ded803385356518d823458f408a8dcbc490454b608881a5a8e96ffe30f95e8df85ed44a8fa0c4c616141e786a6d09622278f908a05ec3727e8842157f94cccab9b7af40085a8c22ef06aacb47361dce13f../../../../usr/lib64/sssd/libsss_ldap.sorootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.3-2.el8.src.rpmlibsss_ldap.so()(64bit)sssd-ldapsssd-ldap(ppc-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libini_config.so.5()(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.2()(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_certmaplibsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsssd-krb5-common2.9.3-2.el82.9.3-2.el83.0.4-14.6.0-14.0-15.2-12.9.3-2.el82.9.3-2.el8sssd1.10.0-8.beta24.14.3eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) esesrurusvsvukuk2.9.3-2.el82.9.3-2.el8 .build-id81bb76205a93d09c6df81e8eb39169e7e1a1579elibsss_ldap.sosssd-ldapCOPYINGsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gz/usr/lib//usr/lib/.build-id//usr/lib/.build-id/81//usr/lib64/sssd//usr/share/licenses//usr/share/licenses/sssd-ldap//usr/share/man/es/man5//usr/share/man/man5//usr/share/man/ru/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mcpu=power8 -mtune=power8 -funwind-tables -fstack-clash-protectioncpioxz2ppc64le-redhat-linux-gnudirectoryELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=81bb76205a93d09c6df81e8eb39169e7e1a1579e, strippedASCII texttroff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)&PR!R$RRR R RRRR R R RRRRRRRR"R%RRRRRRRRRR#R RRRRR)utf-812d871f67804f76438bb0f149f8f510f143a451d5606ef7a0caada5416628734?7zXZ !#,<] b2u jӫ`(y/kԫ݊ wդE=$tJncī~o;n>p4L˫c#Y7K ڍ^iKvfJACUu;T>;1Ktf^ Bˤڋ4z~AOX&=7\QP2nw'Z>mڱtbĤ2AR7L5Ѷ]M8†53k; f~ƠS} &lu˺QoxFWl?&@LuRk0Rt+cpZl5L5 ,KZ{R7Ľ}RG"'/]iq~Rr;he+|(b5?+zHo+Y{g!̎'BexK>~CsC|GWb'@j`z_4G]"[}9T|C8kl??q)cV; ؅_Y`hZEps6, /ttFXJoi~(G^Ɉ܀̐XAɻwP0ӿ;e4'FkpC$?M\N.N0tqѦܯ?Gc{5S ōPFDKmI#dKUSѽ}pgi~Ҝ"cRt \].NuXB=PR@ \ ln9-c ΰǥΓo;LTԤ0g@.4RPS<7_uС}7(˃#@\Da,;>܆GT5TXgR#kT/7cNlQQAT+} @9c흷PK\e%)ƍh-_-i[<wavC\*32XEהG_%ȭHkc0`.@EXJh$q2+AvR$=2 }ʁd6o{.~b=h7 Dz[~Wm7P4)XѦeى%?Šh~{:Mai0KjWe1d9(جQGJW''YǏZ:D+C6XqL+vI%DfTBp&z)ߨTd&p+ųnwv[>9 ( Q#9W5]>dHܶ1kYm/\^ofCCb? 7 pSgmpa10^!)q>^Y@_^MzadШe8gf3AlFk|.q%mFW0t#{|gqg{~&@@)dJgN j-m|x{M@c-,~o!XďYss=-zz~0zz EӉ_"P855Qגxu}&pDp, U*8`3ӎaE ŋ'Չr{-I;o_5Mժ`B}׭v*Q"$DJ~`g)]xD3=\&bs,n$U_J}oOM P^60rZvOoѵm rw? ]S  (rZWva& Zf*G"_cZ,$Hz2 8́m V{p#|r]˥&W u Y{Y?Q-b?+)p۰ }5Jb-g{jOe` @241YV7CÝXHrԤՔ.@ޑœY{L:N#ⵯDTy ͝2;(dVv_=:2(Df­砻AUB/k}ug]MR,07εZk籪q%"ҮPdQ5ypY[Ye; !iq_V;8|Tp9bDڢ$1us!%[jh͜׫*De=HdP-w-`&Œ!Z VIC3OY$P%F:m4m"pȧ"yNc^\9b_19~0]Nk@\Т㄰}C2gKJ!'f Tq*kk&X(ָR)y~9 yuݎiM$gGmx\2wk1zŅ4F)WuϜ|M\"E3 b}ԥ)TW-p 8 VK|=M#Y-٢7B&2Ke/Q؎;|V QLi8/!NZ>Oj7<<ޗjyՆRZl2qIRfN_Q$`P6Қ)8$ށM @Z[pwW|s\TyA=!1r;5fi@۞RP8 + ^F“Vto ř5Rf(H终ַ׃.eĿ xI@;w+/,@8L1'ϐK\Ǩs\Vhʒ[Jw[g*jz_S*>㉹ :6cD1+v"\k~XHF_mmtORhQixB.0T&W'&JAPYغ)X0H T˪ç%Fkz`x{)F%ZxP (|>P (c_,Lh^f)=sL П^*L5,%> H}`VF]QĴ f.4d-AN^(-dw d= lOd≕mmDh|9#W3z/HCe-%`&A$/DȱbSv_2H]8F/BHf2բjөR޿ ՛ MYEԼVLÖBw j,l?|D%Ӓ=&x/뫕"-RyoJ "1wӆFھ̉ZQI_\񁄘g 1I  Fp׶ ՂhEIWD6`l {MqIQm\}[𨝯d$`vS_ نQΊ/?A +EnifZ%m"kp. ^j4U|X9Sbk/`ˑ^p ک8IIHׅ8AwG56 / z.a=yX3"&q#vC}~TodER܄Z%"jJ⣳Ww@ij11nH~x v8{7U !9^WUi|_kG$4ZTVMdp`Hv@7†Cc| 6:O N]Oʶ[vFtaBKl(Ljm!nl!h6p_ruYFE~Nwc]u4lC "CٙǤE`RF8ظ󘲔cҕtstŽ.x܃+ ϞevzųN]m)KՀL"WӖ΀<#~?[!2Qe8Vt{*׷3?5gY^n|Sul ({vU+YJNl8~k%%f8%`Vۘzn!#%8P܃ {;7A.[*0DELe (7i%4Nǟi} #ϹgEjvj* JJZrd 8Es>\直?{)_;7soكҘ)P}]圌֐/0~x ȥAq F'RRǴsX]7ރ@ K)ßǡ 5)ۍS+rP,!k3B `4 >ꇩ׌/@+uj51,C1b|Hg1ւ٨D~̋D)(-v+s'>zS%`HNzLK l g=}v2N;ojl6zcכJ1m6BhȨݗoA A@L#{'**!<;k TB E&-fш{&KHFGlybNJ{=Q~bN3NNYvAzeh鞶$sg _(YoG#@A' ݽe[Jgk⸍UEYT0)esU3qa<[:&ث*=zLW2N}yb;~ヨ-b6EzA'f.sl{ "尙Y[Zr5븚viMN?SiV EhvYh?J}+]uc|tڛ$!776IooAG!ԼRFZ<r}/>l:$.3>dXhcv7ɦ-JAX݈ Ͻ?yo$5pvs[}Z+#x >]T˕rvbZo\c>ٸXw E+!җ)+{jA?K?jz*7d=^(egS(:vUn %r 8fO0R"opRG1!׫ 0Xk M#h/oƺ;$svѧ1 2kڸ>tkƹDT czuz2ԓݻĔ1'$o}nê<  XM|(2W*J&,!NxL=q"㱴E̱ֈn^c%֙G, <4(n7Y~T[Z(,kw`7Q^y59.) wfU"Q$r%'*Go;6N%ab+a<|X^M7NQ1C>}~yC: |Нj r`6-*ǖSҩaIs&uؑA<_ !"jT iŸٰ$D :VY䚳4$gW"^wySFe)wcVm2xgc%_z'p2,Zp_"$pꞟoeU=w,trCѧo_]3Ϛ.9r yӏ(/Yivmryw6~!GwA͔]%|9autDD?x,MΧ>sU5:~wV%_O'MOѾ?;o ;NDeUzevZb'# 2ࡃχee5-TGBTL5}'϶!>C>5v߅A8% .+CE+(N$ ؅ckqBFfLj$+v[I^A0\YВܪR Ӂ 80|~V_L7cIڌ.kpʵwZmxi>:H,*s )yF.9w"!ytT^cC+g5e|Wׁg.口vQ'p%ㄓE$>38Տg4 U+&Si M@,A0Ipc:HsxX%=Lz&4xJ0A!hD܎/0~s-  aiq(3t%r.Um/ b& % n+ Q;٤Ũ;Ba$ȉr;-Leϑvԏ^Jf6ԜW1GȠ*)৹B@T@w,*ޭ4MnHN;R3ԉyHl qd/>(+@3gqFKw(z۸w`8[ɩzO6EFAuWȌؼenPsn(c\>e,t>ʆu@^D{ fuo\P J/h-o¤)N^8^8'A7tI)#nֿ#)6.ͱ.RlyV|xⳡ/WtiuL^k-}_BD:*އXR;J:liVmU3ZnwE>{}IN.#$ 4b7&ZK59K]ngBȃA9ORt d.*YDvk ڥ@ja-k x$QR ,ĸV'H|-TT5?d{ו*~?0+Hvl;s sZ(f=jsC\} <U`r(ȅgAu*EL˳lrs0!&1D~4(NKR*0N"@ܞ{d> XXhi LV d^8{F9Md@#Xv23{:ݍh@y̮%[ {l/zBM> Q1:D J7#Y A;[Up= ;ąYo*D*+}$@QaUOMDk:tP88Xsi#~Qc V~‘aI M ^dͥ)hPZT`!\vϵ#m%zdW-K7^2j bsAVcr{YŽXLfL}n4S\٤TtmL G^׀Fqo(Ahg* ,NYlA{*  SǨY`fEOkB^u7k7]@SDZz?G7Dةf1''a,wݥH2D. Oe!aHL7>e\k_m[O@en⡢B/yc.@GO)/I"hj  nJx/mO/GW߫{z6^RBECTy$c9؏Y2^:qB">G7+>1H%p -/kKM=ZK*1geaQYֵBZfRS5˶b޸6^?k~XDԉBdؑ`=K3z{נּ"sj.4S6ٖȍg&zB16Is'+ X[;d::o8O-K minHN07([isPp!~2=!N-4SzE0esmU[$C{9rrF ?HN/ _Mzrb ZfҖce"|hUb=j? _^dSuf}e_/ph"Eft]5vw6<0t ]At1Xf &lMV|P>kKJF1S雞ӠdDÝz,S2}.D5b\_θ'&VmߚlbUe rNL1B?#|=tEb 8UiNG*z]DbWJ(#S'C"1`RBj]؊؈y@ 'նTF>gxqnY̛. 7=o4dȈ.~i(rуJZ7s@KZ 5cZI&~NlT{B(Bwh$N G6 c$,:X\_ (&u !:v}~3e/`7\<㗇]9ti`.dwlPQè1y(zP6Fd#<|}ʑgް \U)Q-eSr\|[548A1Mp#UD^Æ&ۅ-nDYuA׾P8!Cm0vU  eעxR~ǍN+o>#M(hnW7#Xv-6iR3804d\d?9žXüޡ8TU:Ld3W[bĠ$17vp/5IB ТvnİW:ht!K^n3;ƒ\Vg4:z-cĴ1QMY?M}S۴4a&e?/|JJZt"6Fl~cBI})+uq?;_F.M`(t]Hm=u;V9n*Ij )/`VIrrVu RanfSA cb Chc'W᫡kqdY 2?xp3LV #ԽCtarcEZXH~{KGWp~kcm,6AAdk{@ }jEvMsWiKe+$蕼AXO<j_:Zl/&J,Hcgid^!01šƷp}Uy7 liohzQ~82}ϗ-ysԛ,bJAZHq6WoQ MW6%CWh_W.9-@fBPv+/_-!9O?<[G#Uەˌܒ*1Uk tD&'?e?Э;,WD2H Z"_[M^*n3'M0T1SakK3K\{!@Uz]38'?@{L7|ׅcpģ?9Cl_ %\4[V+i3wj<7K;Lmͣ$muFe݇n!wjhBG]eTw/n`sp,EDIHPr^esLX>m -Tn%> Kq牁,:vO'fz=ZAz|n^e%#.$ {WZĜbŗ,6[K/7v7uw=~$p_hk\$) <!`J*~.ezǠ}&ኚnf u3` P+@ 'Ғ9r="is&|'Ď|-W'E|ܨ3SMIO\t*) \RT1FH,??X!=rE.{^(Y0:e)cVI5Nf=EpNh>/̨U k4 #tl6aһE};.i {cuGq[{2W_ 5nopYNa<г`]Y1uXwP8mጝ0'fR#]bYcȋ-q\࿵?J?45F=Z4EZuA[W%KۆKv pZg=18{0¬O2]DdYn~ 7'fޡtk~H\C4 A$R_k"6s}PG!Aԡ-P{-:=aږOl1Øzq(BvP),<2@<5^:kng>$$ES9[?]!KMPĘP,sۆԝiEkC榸ūӐOuHvkQAڌlŚ5 ̯`9br tI{V}4 ĒMSm=k!. ؘCSm tc6 r_hȁ8[,R1q{6Ȏcg{}Q{k"XfE[Qj#@FcPl ?,n =%Ȣd=!_6efp[+Ljcx Mpa Op0K*!e5N4?X=z3PRYsT!3{˷R*mkr4N7D@wn(B6o&!]aл ;n+}tw(M'u VVm@/H9X}gl`Wdf @]rtUo]pb&#G):9ϕ'?y|e*gB .PIM\`0gצ-HqԐldA6@ m8]~1޻0+D2|ϫuDkMp]҆]!h^Nmiqa*ND@T$6lRj"a=1PhkӍÌ&.2dwnFA{v.kyw29Ai<7T9f 06}` b'hɳG4 lVxŗ0ċT޴N$|֟ײZшk&.>.J&K^_̅n*9>jNܠ\YH4. ;+Q.tç!o?{_ELYg̖-X;ybn PUaV 0X2'gV֚zhe"xBWFEUv(jze߹Tt ע=!|đYWx]ߴGpzuoj"Mw2+zoDkNnaIL\^L{:!<ɸ\FJ'5E *#w6![XN%1חY"Rj\9gVö#y{Ѯ a$e8JAX29/#SPmE<,s/m-o[`؄a0mLk);1ox!Zg񕰃v0*a lb='8/j0<2:8wq<x4[^t@{Eq ;=Kum}1e g.Ya,x@ * )uܙeҌylmA_c0J* a-r"Lx$L{fS OJS?P.^4CnfkI(yT#0ڭ6"]ms3h~ԦN9|x&ssO>)ȌN~wBpũcP+~`u&_N&s3r18Jo6&5Ȥ*>}ٮ)rbI\@j^pscxa3l~nH(R3&sF|+.h\L3q[~}0D0bM-NBuI:J( NKNJY[JV'SCY~O&vBzhQM/씍|㻣Hģ#ng#76w5$4YS~׷R3v >Ƈ8w'h\u$ۜ_+ evM]"MgVÕ9CKXeSeM͊,>Ks|5yrnp{2m(yFP";[ddXԶxa %& @fۀx 4XEBҖ59!kJJF*vgTNC QӡkT_1fVWl0^3OT1&fIgK_IW+Y9._OkIy*[Wq\+dSSRu ʟMR!]&|CE΍*Y~C7{|{F]?FAꒂp]K ԎPm[EJ%T4ur~uǑl@B<+H;+JWM* N}{n䘏 [U"A(j*8@[ -X:=@#a = ֗XdId/auRVnǠmD;L+Mb3i\34\iᭂEFPsr 0]u6NvMǏoZ%i2s%==.ߤjq\O . ;yL Zn9 _A<s6K7 6KeUϻ+ Qm }u }xl2˜rRq )Wn#~K4HELѠ ՚i ntHd@H$ԞqeS_܄](#VD-z;;Vڱ33m>C?;0}o.F ٘);@Bֲ(TBޞR֧c‘ +SGh9!H~[ŀC.6pPl #ɉ}h4 Yьߟl ?w.dG'Ry^~lTj[-ok;@kuQ ;T\9`;1g?@/\_.Ssȴ,vJ@DSr޾e\OmQPF][c/P4m+h|f]~dcJ(uo+d&?uHg/።O[lzmx>\/v] S~M&N K*DӢ쐉/uh`uhWIi֐Pf; DLSGOx_{ 0_9E%O]dsO=b 80=][ dW'cɦA"\::֙CE/.s'o0zEduD< dL:,IH([%=#բa %uԂ UO[*EZ1sZ.EJ,UL1>5mW3oZl54?ܭү5 .0flYE[G ;'d@68ЍrZv\'=y8AxbMV?YdM*EIg*y^Iy&5?JYfݜ|m,2zz.i!Ka#ɘ9C~>G#󹁒}-QnЧI]fvviG3|Rݻ6X e@F:_1@y.RD^B*]3߃m0c,SV3v;LQ}҈%d5%m1ɣ>6) PXx?Gܞx#Q ρG<ǜӷl:; N`ܫ:AS"e!kV0i,o"HcC[K]ݽ:d"5?)2 X VIb̲1/Sd\*ȓ%'쓰M7xg^P>UF\?(RI3::@M"Yn4&%(U"~Gi'5- )z-)!{t  ړ"He߰uW*ћChcW,"'v &s 9kZw}PdȈDp:4{Z8[mCrFL <Pg@}xg$'bM /N=j/|4d+:BQp G>5P[p%hU7{TOۣcwX0}-z,0^s?UÙ=beA.aM+N"j)FSUA G r;j-N$4a'D띦;6{pW4}ADҘ/P /-c}9]*O2 ؁R!xP_Iho4a!ꁬFSeپrkB%Ka(i S1K_} 뭥(1],3ǒmrYb͡ +8[%==sz^hOE5 h VO*r.Ck%OԊѾ6iIG\8x9鵥mE˷x ] ƒhO7 )7۾ei:Ob =gƫcSf~L$^^H~yiyN4M_-AX:#Rz,՟-vGc!5r8W;a#fR/:3?UjH5Wq͓n@^v#ʄ%*oELjwk᮱5Fo>Mbq{אI" &;ѨJ:WIhA8C]zyI_h6V')P؇6QSʁpX}lgp-/:؎OK=Np%k0n/ݿ/;מ_84e1.yVc*u_R{.%C!y)x}PEJD6͹'V'ވqһI1j@Yr03r^:8u{˧$fC]^S{ nʵocsvs:g~yE03d*W3;Fx1W^Ȋt@[uÜ/UA$v]FQ5 " [ܣ}fŮKh$x)hC#˼`ܛ8w^מ,pGbFGc\P-eЯPsE;.h^j^@r4iy=z8bͦ(UY)͜OV9Q0U%~[ &5eOl6 ԎUoqQRM솃B;]R|n/in6;D\S [d5Z=鉫Kqi=}9o}]j*ܣ#{bv.`s!b6A]eMQ.Llz€X( JH͛D y% L]% *Oq}_R!̽2ihxyhXxj]fY1+:% fgv8JU$Zuǐ4;QA4GTTSdT?u99agB)ZTAKb~COҔDiܠ0t%)v ?x/Farp {0s쪐H(|@{I\bPhz0ŵC<Ţ>a(;:|y ؼy?+@\,Zr9_d(O#xM.̆!7]^Si!Υe+N-Y7)s0:iFKM"sGojܧ:ܶ\z#E!v(#]GS ~=dQ;V@hP1i(G}m)ԍ]47ٻx1!Nr}_L{uVkQ?+N9r4d'G V1S+aqz8qfޯ1^Ir7[ȯ+%c K jq-6 य=jIB`_ [f? ?4 ̨K/JnJTˏ>+!C`MsT^\n.jOp'9ՋY<\PZ:m7Qh) mq%PhI'd~;BpNބ^˷1qaQy-$Tv!whU4LxŅiR`dρR*t6pq-66s-$\DR;n8A7'禪A7^xh璦Nųi:D $V/ N;+B: ?\-zBAXx<{,7ثʽihEoV" œ;xjݞrOۼXREEP$4氽qlڡj j|2H`N[ׂ! &*g<}Mė6toL̤Y--u;R65:Mc@/9J~ aa CGƜ/[ȋx־:auKkz~!IhD1٤}= qS2?PkR dvv+ǹƔ85w6wdK4AtYTQE+ ] ,tB٩F4\[RjW4æ_ǯ ػi$cFwC_5GA*{p'OIr|Q'f %*',5QK])屺V?j2݋+RMY{g s`WQ_@… Ӯ Ed7+ԶRtu [BYչGvʶPgc"RΛnz5dO l9eA$^2y2REPR|?c Aq-|"SqEfedtI~NI:%&Y޽/bYzĪbcaKDHGx&ڶ?n?!1w\#ff[ W]ގJ. ?}6]hg ^3pغ31,@;dlNB&mbF GTөo7z<;cDQX do/ι1}d H2/|Q$ꄘȰ J[V122zwX'0f~` qWt96nJ×bb2k _/ \ڢ M AV<:5yA r^P@xRIHTEEW3 7$B[v9Dz t. 'ud1&B6^G:(~,w.~1PX88G@jEL.qMZTr+a`J~Nsƴ<DƃSV L M*,_b̸CqW=N N<4ծLfU%df$zWM9[cY^t4)`M߿&UjW4 -Ҙ3xq^M:῜TLWn*~JsM;5(׊&y@vFgn|CԽFBxhK+LR[N$$n+CKU~rv`>BiU8z?Ο#7Q`ig$頍>o7qhn<\._p<4M&t/cY[[$]!e4L0 k [cS!M:i[b@4A|n5YUIimBEܐi 5FzTt'"o!z#b"vӢQ-`*Bc{b?_780YBP\aR)BsC_cȱSGVVK @GYX(qrR>Q5o}07)T#){/:jDNIP6zEHf?q1 11]cX 0؊0x;c5Ii@~P53Jnw;&;{)9;d|S`1G+y'aw̷}s=ωLkjߐN 㢥2fS-KNf&t%.0v_\Tcu & %EDeaXVB>RE)j#L%bkeʟ_YhjMqdCFSǛYT^Ә:`Yz~#o?*j?=.<Ԁ (HZɵ>Ky%WjOEHzR{@ou#Ǥ8 9'JeQ> pi&6D[B:OGqQ*cӼDҫ_JNFM%MA8uײ%-ɩrJ*tЁG1#޼+mYzBw qx0C4JЊ  1^nj29^vٺ~A6kvkLHն;)vx0*" M(XtٖgYk/}`h2>(%)ks7$k+?5w=[tBT6J(qn袣?|z#QbDlaI{Ä+&/9u'{:gD5H]w{'{5MCò)2yn^yxH1c4RZ}YO=җ%Cv{(%J;bykrKܙ_BN`n1 I@?$^dr#sP{=PE$z>y\5r2;iKbpG&4{AI 'r3=gLM޵,Nyc1=xIZ{fy#1?U?BW*XR\=bXEҚ $3`tFdA͈j61-j-niBT1]݁?Y@?W,tZ\U} <!!.N?nZ\0:sa< :H/®QWOQ "`6óZƒ~qnῬsړ -TJh*Z*tޥ){pqCg~Y|&yNh8X$e ~L6\:T@xv,-yܭב< 5R@$a?V5 tQ?h"׊!j^hWLeRYwiMPx@-NDT-Cx{sLCnLZ "mJW?2Bzq NT/;S~/#Y2qDKeVo-2ݷM^vޅ$8h*H%+ڛe-f6Yt8Mu=ZNX^Ҋq`j7ˆgwc?Yx0Gj9K.Oj$mi!ζ5HmwIJEżKȄzVitL>^>cZNAOffz!ˆ.|W{뒁|֒A _& -!Rͦ xP؀s!Ev`kx*U(J$0^;L*i.HV}-uqԌL ߆P*'ْuԌ rM.+ ^.2t3Hn 6%/ f?{\nhԔ`6M5P+ .z*Z a1׹-#ƈ@x. &9GW=-bGtsdp-|{kV"Ÿ0A*+L|x2'M+(i _7~L ʩ-Y-5酓79:hqnȪl*i X)[rԨ=>S9+)V=9fPn6/XG>ݸ ֪D~+j U+%;oкIm' 6|Ny;Sj~tpo$M: qʞ#7ULa)^u_9Bo/k R|bxNS]1w%XKCbRR/ۭ|Bs) Wy-yX$5"?"u+u%8ĸ֢}}(jd{.dč9+E8Bf<*7wH LC2F { Ih6[F\a'%6J9MĢd}`?X)$fEyT#\= NV]y/RLH Y *whLZohͰ8lU":ekK^,VDasyK2xu'Xkhי8c߭e|NCToŨl-/@3I c Ɓ<=; ύܲ9..`@Us8 e,~~o<1X[c$:1m]A yg~"hXI tbC=a P8"ȡ #0ccZSX{R@22PS-}j5Srm! ЬrT^2J6Nf/-8{c+nl.7:Ci[M&%c9[NIso*1# ն^ǮfҐ 8kzqc7Ovk#a1ͼm&}N*ovu2\LT+Ԁ! !9@[Ӵ |rbN; fޓ.+ZjЅCq R MLoA8wo۩e]}q*]>:I܆ܹH-0&+૭Aߴi^ jlC̍Ld[ o*DJdG.)S1D] /ET^PShbGtT-+#ǖ  BŽͅ-*hߥMO`ͰgRQLiǷd#gRd,0zkcv7єO^8fZY}_ݾ1h0u%b; 0Uå3Jbp+)ih 31ts䑧¨s`sclbh>  E(m.Y |޶VHIP|Yښʆe2u 8 ~y>JԔ0qݗ樒P %lt"@eSJ~hHQ_J-zH" ty@Ծ|XÖ\]@/on~~LX) Rbbu}dW߹I(v1 B^)ȈEB^*t|p"ᔅZ| Z~& :}Yw@9} Kbi3C- EO\{ćZ&-qr2U)w GZ{VB R+9@n[Fcd&0z]k4=sƣ9éAsqBĦi V,=XfH;"B|/>JƤ>5j&=8=q6{6ݓ>gX!fR ,1lHO鹊cCߛw r)87=F^0x?}L2Tڈ:.dlaa% K,Vٌ"ўfE+RaO7"gxO&6<XINK #p:%ŚtPg8kΡζDd) j86yQGS9v9}[ֆx:o2(d#ԅbĞv߬KI<֟LMf m{W2cI魡o2kUͼ!וƢLFUŅu,ɇad@UTo.QYHMDx2xV >WKdY=]^GX]g w׆C +T#0il"ݫDSYz % 9P$+6v8>-y=W&{LQabAAc člXKL_*E̽~[ڛ,mHH͏\%fbǕzϣYeNPp_vivx OlyseC[V_,!E5~U>3KF sKUI#9574e{s_S.*+[6e>xcM7aap#9E@txy~X*!׍dq5,^{cFTIZ*b-ZtWdjmZ9Y#Héu̬ixgF.泂b1_sY4 eH[_%{[yh)&ԯ,sΓ k5!o{j %K(Į~SHs |;nY>Z]n؜Whp{fyuLm!27,>A+xH͕cu:Nj,l$CQ찄]ơVߺ;vuDkO3hEjT<A&Ga,?^JU0$/af o.^?J$fGA lmJ뇸NI;E" [TZjoRwPD&xlz3 WvrdER᧯LOk.CS 8Z yM&5 yQP$,ɼbKo pߚk&;0j{ʗzC.{y&·j(vDqA5ɽ׾?u4WCi;5i0v(<;lj1Olff0Seˬ2nrעsoG%LhZ|bq{,' ԇX&޿Z* /6ϋ@%7˝;D-p#.0 ĕW|HBQeM~%y܄Y! 9^_TͿ>!$xϞ4^# ^ *MtE4^MRA -No ,k*T~6oӛ=hHI R~-`,#tHRc0ԡ[FQDAU(ŊZЮ>68͔ͪƦ֠\b˜PVuQpA,g0ѱCi1RLן lb=pv-v =$#/O5|Q=]ܔ,9ʊDJM{\d$'s}lB v$n7Ҭ@^XhŽbX@FQDr5 OH|\r%&(BF9c 74{G5R".md&/|=ddPᓺ3 A)Pt-hi`#[sgUG`q#]6J,W;]u'qU2ېZeIu,{c_no87d B"JRg+0ko/mi|⺥:JJG )>&0{%MoMn*Hk?#a4|W: !ۥ;Ù/2}4Ww|pb2ELeZu 5x!²`>'(N7W[m _tm[o1C{NPyT30?Z<%Dutks; SZ`],JڹI/g{o4Og/ XhѭV=Zc~Evm/pw(ڝ$vPfs ļ(;'Tw*'=1<ȫ55`V!"Elxjοzi{S!fMqĻ,mxxz!JѱgHQ5T>&.C C\dg,AoP? ͗oZ~LM}y/Y!KI|`P}|(;Nߍ˴#wh[_~*L]sSnG iZƙrFY`ev=La*rZZu01Ex̷G IIh06>KK P`D'鈡Y (7fiς*,lZ`3 `k9Y/SNĈ{y5Mv)UrM[.Xk M,rrP ߨ66K qOj<b?D>ǝ[k*vtn n~8+ $z2r28nw7jrPB ˚ [8#lzMxMz uo**mD3QK!\ =nc>]eI-NfvB7|XlfB4ES&g5mh&q'ii?cx3V´*K5Jٳ4HYKMiM4̤->P|%k鉫)=g/x9V7J߈ݲh9A[cL#.H^&c *eKc9zY 2^S\y T8I ?0ժgFBHf MnPH/~Piv+= /EY.IՈDP v!_aBZt&ڒ3fAID~>j'/LVVQEr_řFTpR5~Qʹ$HPz\k+MU `?tI &[sX`~ \cԋZaBpW>E l KlȞ[$>f(;t὏0%~F1*dU_ lAT59oѮYPr؜{1hrvC[p-%p&ꂟj،B`5}%m_VD~: dyw K(*G³.т*#qi6RL k+9}oG/z>Kq~yYxo jRq)&V+`8U"=& ug1sCy!8AiT?A,6#xi'~"jpA}`Y"yL[=5 oiSfTCZƫ][hR)YFS%b龠(qwK6SF7RK Tn*3o (-&>jlWձe]AvhLlgw{R`/8{!|BoYG ͂ %a*?.-y/(@!$wj= Ok-ٮ*zMlv=_:!:-ݼUAzPz/yB='.DFlTJ>x)-`Q PU۵L)ai$mѓ./@ظ4:X ^g3Cu4)LdYnMMK ~ƶ;w]>9򁓪%џ LL>$rV޾ـF՗D;ss#I0C!UL&"/kc[x?\H3gg χrƝsdi_5jxq־//I Vё.~Cή!pXO+8, ֦ލWrz 4ZY?A0m!f4BJϠ^;"e֗Jo1% ,PpB i-2!9MՌ*Far Ʌ e$P (ScOSLe2U&//嵏D)H f7c,7M`Z5wehu`0|,[g5ij-U!*|A[Dml͐Qu[g+cBlKhF/J4 Py>a9${īCrg5"޿7:/벗qnľ#0S]Ǹo" LVɤkl5qgd׺Izm7#:؞ |l ҋwXZee] E(F<\k|;^fc8HiL b\& khuAQ9R" KUPpk/+cA8@n 7_KyH4\R_n /ѷuNQ'8R.$d^ L5b ~un$:iq+ ws vJ5^i}@l,w܉|f=u`4zh.e :L@OEЌmYN+Ĩ7t~/lYlj@,zڐo Kv:Үa2Fx=ƖDzC'Ѝ;p# Go xFz+㞡19۰$$Pk8W#~)6s[о{=sZh:Q> "]aVgE#q#BB ,wRr91fg!!K4X[_ p UJɤ;KҩcdB{^T1c>$F}gjj_^!jecԝYD ʞq@r/zcC?̚}IȨvgz/[؝)#3Cq!$y14cQO[~~"o\Yix!T !` _9r};rg}:®nȑ٫Xg8u"Iֱ_R%[mW{%?b1Ϲxq8 O{'Zb#Pxك>7fA_0+:iClFxMfG(٭L`I~ bV)c+b:CWD֥2f{n3[s?b'$:\+q F\όã'n%|B^okJ/[UܸF)-$ _ٺIx{o)*9E pU[Є0ϙ`kHTD;acV0z0aqQFby|m|E(D+Qw 9EBhުB/{pbed0XxBޯKF?3]:bHj!؄{fsS-kرŹ a`Uɩt@d ~t;pp&᫯ϏƑď`h. U /eIѰRbUN ׄz" 2uLc(7Qw6n`A l kx"Nv[Q5iLqS`NN9zSe0n3{&5sL3n1 ͆aM)U| /"@ Wkz_@_SCRNC'#M./ͤ$ȈKC(V.ZT[{}y^uPq_~UpZ<Sa|WwS/>j/D5j4{1Ճ=u`?N1?عIɃ[/ֶLW N]_;֋O䔟 =6J}h lƶI H a1]{&\}z߿Kb*YBYn+\'0*sX=uºphdA֑CjH'eBO].C5E}@e^!>³4~2*.Z 1i'ͧ#5K؂aJͶܶO:B2mC/9JZo#d UZޙZ1#0` PX %$ηx<*F㛟;Y*gp%u99ǕҔ*@9'pYa{5ޣɴOSb|3OCyd{=QGiWlI«>0~3)O簧T۱*g*>%ya:By') 6nޒœp0>*۠Fo@o^/rDv*Mb,<v [.]m_Z3ue`*޿p >bd#9x=>6?T)u% W"EF3@'c+J;=.Gn:\NU)}Q^{HXKh5F !orXuD.9xY~tZŋG @]=:4(A1K+26`9spPH6n ٝ Cr-kCcމ;4vK$'n!5 +x14sS3_j&/ǣȟs}`)%d០d}併lAe_e:?5f@͟p5j$nE? 0WI\[^s,kBK!yȰ`]G:`Aĉݽ~Hٗ迾%kD6uίqӑ~+ީUx%A+Q)юQQ)$_5[Y|:@A.C3ύ`Y'Mr#Mсd@X~}ִȯNnLS͟-F%|i>6zr BM]ޏ)tŇ1_ke~; C Ʌi6LhL;VK{oďYi Gw39ޜEdم0͔3h OM@:)_'0sC|_%~~ܧ WX5kJC܁hᴽ-REk|Z!j#ogؾ{t[Cyeϊ GܱTn;mlҨSJͩcgÚ,Y̔ }˾#kec_O"Xr 0^,,Bj@'Huͥ6\Gn5_Pt[+ӀzvՅC=*+tޓE2pc493FYY~XXK>84l ͥveBAӇlWj o•f#0{3E;\Ce8!k5cxnLM,_f jDsQﳸ T&U,H/gx Zb.X;<|z@ 9OeX>hxEm (OC{|[5Q2Pl0<'&Ӡ`8hzm{ghcq68e¹{E'UsK/r:&.i*Z`9(4rHK$:D;{o9K&"^O4g?;7,fTQ4M1z$iR&S?|p]NZT<2MtZ~@1_DT5-8[df0&ۉE< M"?A2IN ੠sĀ/x8 .ǃqΏK&}' ?kekl<Pa9`ju}IvFg!Jh>S/[I&'5{.r8! 1)tU). :\j_wD`$;Kuo\ hI?n'rC+G Xr);Z֌?'ċyAZfR`+\_Xr-et;ˇU #&S)M}]^kMmEf#\ eH""=I5. aYp ZoC̲V-taEjNxp˶t}f*p)<7$cFO|_CQ PZ'2So.g@2׾ N; HgL@w`_tq{j`AQ{QPIRQ7OĴ3"`jӵ^ "4Ͷ=9Q#k,Wv5T>|+MM!\Rc 6[P: YgO!RPjwnY;B4(]@d5PONu;`6-ॐW/RX棱+NHGB5*6pnÛJwVF҈pHH{>Mg-$W ej4j*yxfژp\,nPm)Y#$nšY10_ɰjf 9ǢIYd/&^.)q?۱ڿ*TщI(:ey3F֩o^Ƴ3J5[-1D,Ye^^8M<|UUP )>A6թF=IM[h] B@’\g"B_g__V,LF4?nV˷ݭXSQKe,М䰃~ՙ2֪v\e>QjD"BհGxXK8c6y̡ʜr[k?9i 즏ENa~OXv+X<gތ' 2|TPKc(jX W3T5hmFuh[u#'[`<䤘ɆkR0.e~;8bv26I˅3hFrcCz{փ?rL"Eϝ,Kb˰}4GY8 %kѵFH$a\Å$V2٣vudu,.$PR4{%TL]a)Q|ʏߠ=n!2,,呚&UX=˧)*v$kC馀8Dkm ~fib'b4Dm[󹟽׀.₣ȫc]|L^w1KPZ?`*\bjX) #?r1+# KY 4`f H ibl=J7T;maS"~Di~SKv(C¬VufȈڗO>sDwŅil:C:8;aRnkNֺ?esDI΅NuYIh1_ >.9r$v"zV޾Y`(,7ywqWd}A>Q{'<8U%y_DZm\.h"n{Yv]jg3;P `h-&")_ϝ.Y)c6P =: C <πM[1R{ӄ|J㠗=عO]dnDԌ{zX>] MSbROg \[CUaKKU-Mȕ3Z̗v ij>эw$r&m)=|WU-&وt[ΰ 82#r 2}g]N)Ž"1lDsI›Blc ˲}NBOcWil7y8gH׍i: G][xiVԃ#x*D?$ wr!DtC5f 2构W8N7QSTZ͙uE6kǣ;UJ ߁ ,crGWd/G2nJlT#y>}[}zˇ&isK"Utx&-vXs@LJTnf,YyFho[:ˋvqwb-N KMQަuչ4|z翔'9f_#3/MJrq tD>19Ӛ ~<`!=!mv8v)X_b`WV?vk(knXtxȲT/ȥ`$? ڷ[N)&r{D?A&bO*>Ǹ3^y#uP9#UԤd@~PYyqՖ&{C 턌Msyqgw.{zБTFdMScMbͿWtemGDwķ}`mI]o[{P_Q>󘻅Γ$%P2XbxKrvw.YaYF:R՞y4`EynxaXB1/yM+8;Ap3&z 1f/*+Tgtt? 3+I'?6I:6Ce "%s,YNWlI1((ެ/3KJi t&wmiF/S.]ؕ [s粉T۰0aשּ !*D\-T_C [tS=U jY8Z=ix𗀙:[?ӿQVmxS{7J4\#eX-/;(ƈ,6#hZ&FУu (Eʤ$DDR4e8EE\k#ߌ$h9r5@y =AS#!=dJ #qփYO_)c XHy%EbSl, {dxF*?~/3٨7̷Ov|Wte/ͧDZl:to &p2ѯ+DI%x\-e({uE٥2OHˁ҃e5s,nQ x Jl6u}Ãq8 P-3 `laIΜ=(*=_ܮ kˈ0d=ŨNzAKU{\ò@x@Jǒc$aU _4xn=4/͈{e${1sл$_Mе(0臮F3k:ئB" ߶W%re1!y!c U58ҐXeNBh>ɔ, or(Ů ѣE۪_F!تזqNw:2|҇wbf89܁lqeԽa>Ϲ" N1K  ` +qŽMP 4 8k&eh*nϢq<@4?#B6]:{RʫyLDq''3}h4+2oFJd"oK-~`3ȁh/7E<\ddB>r—~zoxI:el-(9LǤʩJ-ecJ55 QE# +392]R"LDiPH=o'/5i[/uWj"KZLn\S.?PZ}IB;EjaFc&Z=f_} \h` J)6Z̆A3f_}ױ\vxN7}2(f}?c}"RU{&Wb^I, D4a&+hk$I!drx _78ָ0oDA)D\'Dm(duA"nDfɔ|ܰ!"k٠:ZJCfcWp"}gH@mF_ }*kM45Ji LQO\ʑ=(h3LܪB8hEyX'B!_T◕~x/-TR㩣{f:pYۆstUzbqTg@ fEUa߄W(Z8QMYK,mHMkRHrصS!"WD+mª84>nM"CIGx]hfP["6%mC :5-Dm @#YZۏ~-:_f W9} ZO#{LRyd\!6L?C},dfi^-mY ۈ&:޹[#:)BBpjla!oU{HS#=l S ' [p PIN)5$g~2&(s3\_2giB}tC@B^؊0^Կtl~K!'U֒cHRKvdyS5a7^ܸ0!79.$H] ;Nfy2\KhAner{Y!"II_E4.؅G_.Uw3I>&r QQy'< qL@hK8t2BXN /ޞm׀gXŇ+v]zG(-#>6dj&~7'QJx`' iܥW dY=du ]jMp-0<ĕSv镇2%4 $Z4dw|I{UFwJ-n(E$,wVk9),YAY39nԀb'!rc#f ;VOgR'(\k/%g{j3(,>@ 1t!~s)>tloi;zLqalm%yNVoŚSC\umë͆fsj0^,S, g2p;9\ӠaWX/$lG { ?v6OMtgTɴgJoٟw!y S,] EI w /|DRn=@79>`#ѝq5,?rp d}JVS,ර]d]h`4JraRo%A"\!i`#196*a,DoNkC'D;&3T*}Ck7.InL'r3šH$l>jcfBXPbДuE- ζ%3Ju=,h}\:?'~ƣQeLlTMj˔CWRh`z/.usyak'շ_);|д`.J*d) @E)BgcV54fEճn_Vޗ-DgM6fe|7x0T4ç@Ci~cguy_Rcwh~ L)gX/*,~!zc!)cq%o5|+q h`/ȋUU++|̾3cI4Ml$~<^#V`hkP|n@w= Ë~lc* g_ TEBG9܌--U4jb0Uj:f}Ci(#Eow_7DZ O'e4Ic랁A"I6?~0m. WtW+bXRFfEF ץ`uQ~/>D8L@EtuL*=}ԆDKیwɊ@o|,="~jgaĉTkLdv+?5 [.-Xɞ6 X]yGhȖxuHİ٠Tֻq:g!y 1v%d#E}{s(" waU{|VXGItx8[lk + Q+;Opk"O YݦHYb^jNqOMCeA ==OLًDI)!> Y>aWE-b.,<_̇ؒ. 5edwoś .+ԭ+XSb rڭYUYLq\% (VF=K +Aͯ{c~a,դ$V~ ^) 0W (aR3Dn #Y؅GRs@nO–~s3gb' }$WE"Si93s$m5_֌& /srFs{LD9Sfa5+P1vkC[# ܆TKB*͍fLOE)OʅRm̅VTg7p$'ȡH; =Dnx7dC{79.~Ӻ4bZ~Y|l%mN!Gù}N/rq|B6n)!v1yhY5< c=ق{;.RL(KE+J#=P,)!WyȤ˧Eh0aGr ݢCᜈaYwwtq,mkj\wU%uͯ(‰KUH|*LrJDzH+7R>8`m++C1j@FXnqg0  f{e;#߂8p/Gӗ4'c1;d"a0msiPKk LUQJ}s{5~Gj1{!'E6ڔ:[\_ÇY\ s3:QśjCmҚΝk  H/#"{]{ 0,;F yv!l9Hf!TyR;iǺ@DhI{֝eZ%:&{VU9z,W]R:0$Z}{8_dLL:+a>#dLpsޏkг"<ۦSlq {JqQ薏FNk]Bݺ>U'yE]/i[#E.)uȓtX똝YC,IstUԉѝse:3fJqmQGYʐ wW@X5`{}>j*~Uw碌tI*/Oq ;+zTo\Ճ3L$/z٩?qZ*H++Ĩc~A9 d@G[,SX>O%6Uȥ>CUHI;\WcpOvR 6I Zv5l\& GWNa6]!s1YO" (J 66):EKLi)zdaSF.OӰ-:H&B*eäͫQ9ma `X*[%sD]~&?3c'd-6)uT!ҼiP0.Dhk 6YﶟR#w}7EW8\vO=?{m;dZlgIR Gg(2u{.ֶFoy*MlWIxS(@8S9TաR1敖L }[= )31#ʴUdK`-Nb?)MrТ2p@B|rkGYfwn "EJ¿$]UV+?2O.dgɬAz*}-aIHЫL1rWzVDb δy.J8鴍c~OMc^ дF'7rQA"wKbb/@*_V= 2Sm*Ggewyv[b/8ko;ښt"K^ n\/s(8R|+lfʔ_%5mZ>/`¢#ͼ4yh<=RhGW@m \]eagE{xu<Ϙ}W8@#zf x4 N[;6GDH^` "6'` NG fK/EDX*э}Yg}Xd&CG-Z-NpJBt ryީVFa(@4``4?~ -# xD+"'z%H #_WՍiU-Po4O"gFǭ}"&*w.ricɁ},ŽBH 映KtN7̵{@P9ZA+Zpt0Cyb*^|<WYG(*RܨkշJutmn~Hn#D!FM'kK>ѢֆQpF\kЬ0X@ otFRqp۾FX*mh'fou^SLU\&As9B&tiӽ*NuN^16K5V椷B[GFΣ}4\Kgu8T!n厁9o{pW0NY[v+m0f۶A Kn Jn\ cqgDDma9oijYZoۢhϨZVɨppuva:K/"7~!>p:PNZQPfV;w8ҽ2 .%.yK\XtOJ2hLәi¯r+xOrW-'UYTw>JK.llgs¯~ePr>E"i*/DV(v>P@S )ZҴgKL:$Qx!8309 }ԐҊ9f~l !a9Z5dtK 8P(<>|bw[QEF!Jn gIznq9bbUznJs#l9znu `H#(iv`U ¯ o,ޭVG6Ǭir &ٙmXJFCckE[' EگN,D<,E+$]tN߼桚.·Jȃsve׌m?~qH"*!f< ɒd9pPW'L|Z;W(q4l_\13Z/B`39^\nx@bVڪKfTH&nV,|j'(|g1WOO `a7R˩_k+ղmht2\%/WH5\.g6< AwB( v7 UV,3 lFFɮke h0͜&2Ft.xvF1^ 9]H1)Gc.H S_%ȭ6Jy""Q3׈5!k3,6tk z=Y~r+8ѫ%q\$V:nRo,&ņOWU3JUPgTwW" 7.ӃH"k2gK쪺Mq{:o-87Օs,ol}c|z{4&x02E :8 #v:;upgEvOu0Me(\7èj}Gԅܭ g @-oU$^: 3% ' mb5ՌJKa+:"[ApG2 꺲8QCΑ/jG+zzrGq^ffN jQdXT ā,G2?fiCf}oA"DŽߓVWœBggƕ6I ߙq!9bG4`:m-Aֳb8ߧ/_O[u 4͞aJV ~b VU^}^2v>unN\+8J:%qXux[ev; [^}xb?4k|#EF7mlid?[D3QQ^鑾rܤ ˌ{q3`W~Y ʻWl۬=KNT8u=Uɍx?VHxP?H*n@2Palop3#aN>Լ[\!Jsa4KiחD>74nl—*XDP~L?"1pV(fpwdSNš avb^zSԻlRYG_,mAN*nHj D[4pE!'=χL}yZOIsCΚO@e% \/(! RE@f_L:2aEbncAEVjcYQ8p57ߪ Brܡ85ELJ"Dh`%0O2Oч^ GEx6ް+KTK^og΂t؂%ϣ0ⶮVL3m?7uZI|`NA)PB |"u믱\Ѡr,(UXYF97qϛr )ZȀF#`%F}f8N^ͅ,^P2VXwvEw>Uk>MEY'k) CLq$ȾC|WzҾ:8E^ ~2rM~wL~)AuZS 5*R­UXj7s?Y}|ʘ]Tc\nnreFHpGf.m5Krp$Y*jA`JYKil,O'SC͡k{"k9K WOlb;KC (LӧowTrL'MHp `È.S|O3m(TTSl K2q"y;[ok)>ZOXA3HYbc1VJ?%O^$EWFVMF40*! m @HIkt#fhb5}C*dm/KOj4"̍t  ˒ho"T4,;$F50_>'}4^  7[A&?D&Ӆ>RPvdVL^™e3<ǻ&p~kxRXv{Hp9zP GZ%8ؐ,ykG;btIv(KF֔w}fNT Z BtTgB1$jDEfohbL=:wsCSOԉA(4חBd{Jk?B~S󽁼E*Vrڡ`#9VL)YN1ssD[&5y_ǃBUIal=5'KJL1jݲa|"#&qr (i @5`\A75\La@[=4]Ø/-;bn)11y0|tHtV]R/ﳄ{Z]{O.,WeAŐsG%VeuV;6vHT] = MF+y{ 1?3'`)SݜT/,TN&xMxe@TuEqU:v{dn$A9¸wUwƄmyTdDם#Rof {sN^^qs 02Qah$ b``OE2_ Cn'Y)irVٷ v|wNO4s^o y*x{2J4 }ՐdqYlTȟ[_ 7L"48]{ >+p0xW_fCI "ޡ83y?F}7A tìW=O+l=3h`)mu+]$ԈG򐘐.5,"4w cCxދG%|}b>SDx>RV„|X'Zz9@{wQ!4>Plg`{v4Iw-x*Cwٍ,.IaD$x{`/o/G*0̊وܓGU݋`֦ʠtO>s~_8۝$xjQyx 8@b>mZa",?ݼ*4(©?Ι&k9򴾽~LlE(6i~} )O,O+G_y9!G ( ЯAp[o\Ay%c$R s bC. cmxU8Ekhpc1-:"#T>4wE=kDz'9r1//?);.G,Ͳ36=U/֑*ɴO@BEQ7wgްFZ|(z[~ś[Wz/ۛyYXi͐J`)ej``⺊}Qj o4zS ?䷚-#>J!PR 2"exʩXke},jGN@ dv2&bzIr`h5LC.?߶6ъe?^-e!1|| *fMQ|v YE[l70)VcO1.bݖlܡB\Oz`N:„i7{Lōg}1Pr^"nC>Y#!qόR$'j#*5e%%1O[MڈEb*5ZJa@B/`n^E로["%( [tvt*@ [H,LUОwnH>N,5EMԧ:ޗ 60#8z#6)*P].̖)x 7VvH:I@e:L guL| \m ulaeuțzOs y.QvH̓6s;b$@ hfO7,vixl&S5Wjxv:B$ ]1$ӡ88h1U[!hSs@]EC azOÎ75xj3 qX,'sMQj7lRnyR\bQVu;;J re]2bwښҍΩFd?V8ac Rm!қf14ҒF d5%Y04<\gUgiTv|VV3auRVZF`*^M~jN1'\Hp1!c "W @{0ɎzշRGܵ.ⲉ-cur~BÖ!Z nh>ΐN?Ak.4cPE,@)U.#K9d`W"Y?H,Bl{gYQ++*dyͶ &?W~tcyadH1Px[|'Huyc&!24ܒKe'ܽ9ADTp{?l_J5kкT+TxdVY޾4KTsӭ ;f |ŠT¤vז, %`, SQ4.֙}d\%MG)~6)@/,Wf-nԉ6yHMVo1~3̼|FifAakퟚLiR0cZ0p[w+K>--$Pd^& ' 꼢!g){q?3m8mQ ke{x~^bh`KUaĜ<q:SJ~pԕ\<5{KfNW,=SVֱ 8 J_ `?B,`q͍f5edr}mHRAz"t(Fx'P$;1+ 3獘P?jzG$DP7n"4T֒jzHBWFM~+V*n_u:v.~ỵr@7KL #'w1N+TTM]s\Ưi9$;G ^KxmaT 6f/r ]P3>v֘R6x20cFQԃj^b] A $C70^iPӂkC%5_P@7 wPsi7ݫK,]3Ŷ BVaom{8kO%t][aBg0-u%Z(f1-kIk|!Kƫm_䜙0[urTU Hڠo%^ʑޛ!;$*{ 5U]:.Xr1o$>$rR|OS7O6Q欘ԩ Fѳy_%3a!`!me]&pD*71 *C-e/ja︳SQ>D1,I+5y~%*FRð>vKɖ`d˭ #-u+oeSӧ3,&%36@8Gi(Y 42rw>#0WeQJn xϊyj_6LĪA"=ړ=ASma. 51a;>ڐ8ij퓅A6hZx;J0&7v%;QP]4ςU!왎D>3obq5]٘&ߢsd ,@:I7vdj^Gߏk\;9i6Zaibsˎ=Sj8؍!nSt3 B.r&ÿj\jc7/-ŦjqTv4V*[P ZY[i3E0z÷ - ۊo4wmr>>d~," գ}_Pp$nz4*MGO7#q8i۷5c(ZS3lkp@GwCW{ |Qo3{w& z; OգK^׮MLDʢjQT[YlYl*rLƆ~1GvGA@F0]yNAlO4dvx~H@MF@T4K[AjCRt:tP |N[g<ݸꂋuVyVvHRV&dUZDZHc?94&*.l)x/ ˏ+A;'3D\9}敥$ zeubP# Q=H5xD-_e ]Pzґ}3'B(l=-{d%͂w#ǩhէEEqmjaqMJ)y!T誁K,sbu-Z㺇g]!bd6BaxAtqBA caI:ՈZt_~:Tb]ϋt#kfM&ޱilI Y݅uİ0 *Ry1C',°2ZgU۝W/D^8#85sM3Jc[2zxj,W D4:oy6( )C&TcLzڣ̱a2 %J$ 8 \@x^Ku6Mmi.fJP皖2Olj k4N#M"[X,ȲX$LctFqva\)3c5ȸQ H4$C o'%^\ϸ"MݯDT@~I| U$ssk D +3 ,PCU*3 "R_AoEL~=ПK8v6f_` f] ǛrVK:!5D?Pa\pF i )čV;#ʡ@XlhTeή4bJi'˰Fc8 l&]DYfB_엛-VH|gz,狓[;,Zvp/lIǣKN*8aؕ yv-ٛ);0$;}㲁tmB;hnM ފ&F(zG\! mKq7MЉ0,r8 %2l΋ :N2kiГ旑4g?MM[SevNa-/X|e>1PkcG~,=%@`aץBG-g +)2 ιn/$Y 9YέuԚ\e82gЇb)<Y!(&5 j [<2 gVX 7 0Geoˆdbqzl|6l:קZ )14(^t4W8?|a25&%m rQÛuwd9G*EFt:*CNؠdުNsxv$yӜPLxXL$2R d5%`Mԛ9BWuEGXox.PmФ-_|@}U_"n)0h^ЍCwF0*pڥi{ۀ`aB;[I IŢqM5&Oe?#J5嘗UxY80`p^{4K UѶqty!6Nբ̚vg("t("`<:tܱ659k_QC`[%ФS >AA>kޝb6c`ʝ¿ԠXi*+Q|sgbd-ŘB<{rJ\|O|>K$(_:y29W)l+SduloaUq tMB?qknA"zjP17\9Xppk [::֦3}9/0*ӗ%Lb8 :<{Y]'Ȃݵr0Qhdfs;}F "FbV5nY0(d^dVt*Ta/\eLw9I(%Ӿ]z=f$ܭ/֣pyv1i`f⑁vЩOMx!1B be]QV]͌yx 0@< ~-Y']FS"6,3ـ.ǻ`ы-;W&Z%*8U3iU-g4\OwhPRralq;<(.$ސI[n'dLMjݿ9Y*L q9&kkTB˔h/ t#= KWq(? -"A41h)E"͋Qiؔ/8]+ 4 D(R~h'Ơn^a!>" QU`$WӖP돜M\5UcY6.8#:6{6S0nڧ,eN9 yXt @`Px҆!?1֫}# $u@ BK~ U7U|r6:i=ɧ̗{hͨkx)g.}֊m슨 $0k5$8c_źɫ tA0?D.-r;V;@ǑI$[ JqDA5νy_v,RʪXݳ>0`)P] x9AKf=:̄fevǾ{śc8s#ʺ_Vk? dGa÷h^ER-)/'StL wC՗9kwU2<Ol`G#G{lngW> 9Vٷ"ٳgo0XeY9[ -jp~?517f9̂Ǣl3'@ƻۀLyݸ bPۖ'o顰I UJHnџ} XieRǡ3T6 0C]3<>e!l#2B}䣕Vj \pX-N 4Jztr޻B?aǍ#[:@d?S3D zV)U<U iິ=>2 !WovGTs\& jpt5mY៝sê?\ŗ3|>G]EO M8ξ,t v@bt›^4*UCw6,i!@_uދ6,by1J;LyI}<0މXy<6Z^ņk&S me yxs̀GM|7z4Ou&k4 5d|`P;ΙiIJ7)II?"E2ѕbO+V>t*1: ϖ\?CN6ωR72;Nxr%+9reSą1?M1nсY!e[m8L0Κ$15|+)M])ACmnLRƱ4+ittq&:'u 1*uIJy>nⶨۥVpUGXÄTWqN3,ԃ3z ҉7|q'Q&5+oIWa](R) DyCr0 <Ӧ_㍸Ƀ~g>(I;.&ǐH))vdYgl:'Vk˱Sۙ -"lEu@KY*SG>&$#j2 l)BC< B$^#HHwvHyL rɉ1_6'n@YVpAcJJs&1,G.,z{R=YxXn:7PA=bL[7LU-C.0?ߛIjӆ񵣨ca{=_]W)Od3?f:{h/o4I $: 1Qdrs#)~|*O!هrWX]LPsiTg9 { C+Up.Dl+2{'l#3<5ԧn;tADW9}~KȶI]zqX7֬9Rremv;p G&"68 ޻ EAq1uďIѯ|Bd=㭭pQ]\DB\˗N) Nǁqz zVJws{F\|0Ltd=j/ضY^x.(F3<n#w(faiB"l,!8)Ds)YIy+@J6n ΩL.X[m *`0Hϕg&֌ NॷjKS#QmW=1GxV,44V2r{!|t6~lC-|0t 6Αl„PᏇR'$CG΅2񋽭^m ]QĻuwhQmO5>f@))O#X-CKP $t\H6#I_ٍ*1N6w$lқ̣8tl|IhA6Rϋ_2#$~;Gnz J_ƄN2 [K|" [[3+:!tkU³$.9% 0W-g qH {zoI%Bٿ!U]գC- Al^` an%gX[eslOU|(HXE<$?EE~6jtrOEAw?pLqgdvy7e5d؍|Q& nĢoLDPnW%:dJX]U i9mx 2QYuEx %63/zAwBU1enuFh &7e&htRvxRI8{r-4ȬX"8>J୿&TuU=W8ġt|c{3>-6ӟJ\zfH %<E|ez9p.ʢwW=, 4S٢S,=$7MuTbn,VpRy܁70֜I=X>')J2ݦr7i9?ܘ߿T)BRE9]oW&@sb34∇Nb,5t>N2- -.Ò3 ~d!EoP Ϲy~RfX5 U1cto3n+ pX`{V`[YgPgPe6awl(|ޒQ6M8~i#|0ٍ]87"39/MFϗ1/PPRw;v骗ydU-_qkyo]đ>sͥ|֣Ťm^= K#p6^#ܗI2ϽO ),u&ϑT%$|9LsgsJ4F D){um s$Jiޔ729Hمe5',N;S[`H̰%n%~1)̎rN먋v|P]% 21WQRF1a=b6d3FQ;#t?8U5ѣ.Q~3 kM?d)p,F҂k3di&=}s j,BPrW$wGU'ܘU>Va[Zb Nz/vbЖC.m+y=T~܍׈Un$.1ІUUe(۰ ϙ_\/.YPpd*Iwu!+JDK9l\S^+1h\}i_L*t˖Si )s᷿N8:%ysV#uT4~<CпH<^jIp%KJa\nڹE/fERzi1r XlG1h+)e}%_8X J:^]&؂ V/)+y'у/R I/G)V &`'λ|%[WiN7$SęK~_߬ܒWTy&eٔZS8Lus,U1BΧ~Rn :UQO!iGW 6kmIy) Q;宫ʠ$karfay|ei k (9{,ehBE'CiIzk=Em@$#MȽpC7eiL@xJ[ߛ˨va֚q(&>AA<pR Նw drBsOrGJjD>[G=W *ksr&,dh.e8q  ZbeYE1Ty -*XQJ 5S'x1$ipތ e\@ug*u#U999": "NѸ;PINFYB) =L/fkM6Dž ? `WI! H\yv-RN'M :辽YՏ,ow"Fv#}J2h/ mmw?c{ 0[PYH6{ 1$w\qRō1&Q1…;fWǞ 􂲓Jb(Rusү9L/6/ )gs3L5YZ?Q/2ڶeYt\] =K@hEY6ztd! [Tp&mXh}&Z4ּuɗRQfvR!?0ɟh|Tܖ~Qjxo1w.j:|NvAq{N <{D!e1!Lp0s<ԍ!im ?X+YMMC`!')ˎ-KZ2Z'}(Mws2kL{Ӆk$Ɣ8gq1 b %;C ݧUJȢ0(6agrѧ~_pq9?a.Ixhƫ?Ak @ .tvG?NeQ d!$u%b>ziQ䔝B=pgD?) y@]Xa n+Hy}S˕o,4E?A M:xLq-[E:'k.*$>)3g' +-Z jbEd[qum2'WRHL:7E jP@[@0 0:Xc#8b? dӑWe+/u[;Y7"ǿ稺꒮~SH 8u#\X)zfrh Ӹ <\ug:GvBD|Vr|$ nd:(~ u;1wAT^ث0JAbϬ?ܡlL( ,-id蚓v6/>RV~0[Ȓ;>Ra:XUfqOh5gVSiFAT|֦8řk;*X9eK k>?CZ *tU-!EqUZBo?̈́([\br?Q%Ojq#XtL E{-P/Ydh_l4ZD񟫊߾1Gn-(لm]#о2s j_9ۭri;0KXz0S^yŨ537^5H*EP%2װ4C6ֹV5m7¡M%["]dCx^AnѴå9,Ɣv:tD #L^)T@ћ_ќҶ[d'h3ZePɷ1(rǗŸyk#3Yl//њ"4L7 /6 _i'C-i}=>S SJ"7wqG=`v+ժi\r_gjv 31\GI0D2 /dea\v2#^uI+/1Ґ{v Y% i%L[3k$vRW C{ia]FfrCZvN]V"xRIp&[|Ofn5owH]~"@WqbJh: vi&&pG.>?v=j22 kZ>Wl w ^emK)hʂ}ڽIH&(aaKkI*+j%(,i d^1E腨\;6uH\Ф4f6NzB=aiʴlUeŰF*sp5!,OX$qYcAڛS[Es mth|S[a{atd;LH+][=zP NL#\R(4@S up(u4ocm/Q`az!lWFCNgl9r `$7w5o3>H˲ngҖlnPv6>N<d:v`rMkҭ`qțe.ԻVhڧN)i)x@"~ϺGd/]@g[\ )čʜ\ iwa-Ki4 g zy>~*;ߪنtؤ ?1盀<=^bM}Egqy]iJUt i L{0j"zFg^QTFjU&&3g2S]ح\>xϻ]1Q?΀CS\yUZQj0I&ABԎQxDZT;y*ZTfq9z/d\v,,vm[ ])A,vbXm+BLr/ɑ:QVOd3sL٭J D7I:6+Bl RDxst+ēgZȃHܨ1Y8P\xb"-};p"m *KJ->D-~_'ʌt /ai4`t'cjtC%%N*n}c}yy~)U"?vNvgKbi2$uHiH)+=ӲMLYXlNSe)_jqY~#Y<~`l3,Y˯(pPpqi„DZjZ󎿯w-˅ W j<#}~.ڞu=?H=6:BVh7M[aؔEO{b5pw~ h_LpXNo9108@jɑ1>AC:\o໪pGP{ Z =yI0ʺ/?WjAv)PUBXL{ÓcM!rQl)eOw)wgǁ-:ȧX?k.YvcT;gpUgL$ CI+DMn$q #EÆ%25{l3@ =NPx ,pH~c !xQ<`"OpF`I+_ Q;DkqUCŧGz. ZI+r٤yJ3{x(cB/c*?-]f^,}s_Q|`w3b ա? #=h5ȓc=8Q[gKۮ햯Ug]G)-vUJ(g.@nwmX%@0A(# ߮&HtF:V@?O=Pp ɱ8ih_yix *5/*%:p36e-VF21lil.c CAG+ŐXֻ? ndZ]7̬COBx,M;!>Rr.\ DƮq}LրS6FCepJWu DӖ7RY,)nFڃ *,ॴ^,-}5_F2H:/E1&١˽RzR 38|ilK*ȅXXZ `4b|q Ad]NsHS_$$.Uɑ]{S'GOw [,Le2spV0Ąs愩u7ǜN[toe$e=5&<σgDK%+dSLW˲|(6^_ܞB'[ַ5a }(H/! XQY(c$|&0be"Y#ӄN"ɎdnĦkr8-xE4i1$h cyME!w{@?oQ`@b3H#` l tU ]բFDrqs` AA_rtgoq4E1c=\@r,yUjj{RqKePQg(_d/}ZǓp]m7c3R=F9ޡN/y~C̋݇qg x7Q3F" ޭ/.WηZfbhZ{DZ&U;T]Yr fSsjkgڏ+\HZ@M I4F2YźRrr#Der;=QRP؊->\v(7svU]ܚ\Hl N#FVo*¹ՆQdY2>Ru=ر"+| hkco}w~E@gQݘ~pwdS-YmO UI5ћ,>:?0(s_+R8!Wm!nջm Af`u^u4syŶЅ{;3GDQKb v}e tm@WA1m؟%&nNE,1~A^l_Fd|Ru/~uD%xƎ5Y];wbvӿ{ca` >PާMٜ5!VaQsnS[ #35 txlRmANN bPNV6IN#|:񌗿mPѶ@!Hb %aZ:nI:]SہiIa}i=Wn:mQ=r'3GwoxAN&K5Nۇ^lQA9x*gV"tj %ccdى%:گ]٪Ư =/fQM,ھF@(?#D01WȜnFN.0FEL`Lyx"2M.@čDuЂhS#hT_!{vG<4 b `LW#)?@B:q5!=[b J _%B2TpC@-D&`oQZh>+JL %7/z6XASf膚&=z=mItAnVk_8G0L5 BK }DnEG5u D~.41tef:S eb0qu4<ٻZy%qӸcSq3$M;{fFV)!{S<|q@0xdtcˣ:YaxihV i}Nl.+ v Fhnl&ՙrJ XvA֝|<*J%pU݀%} ;Аol98}\"f[7 ^̽R<?:材kKdJ 3 iB/ KHUe+S>Y;`:gYPG=FymD)gUk ?LF[#V@7[ÅP0K yfF) @]h0d{ S2NȠͶhCßyG?y 8#C6쌘lSA8 TMfq#ƽmmȌ^~z&Ж%o#a2 3ANnrJ!ߙ [ɟJCϗS,qujXWi.=%893iK{TUo6#e\Q4\E3ܙ&`GסJ Pzc ϞST{ !t5C1Z@ىx9nf*FC6M#}z3Te0 $rE(#֖P"QK14+!4Q&;'%dN;^a`Lȃ(OW47y`CA=l9D0Rg{q ۳h(YV'$z9ʡS8dm͚n|D/I {q9`ˆV1]oͷ; %7vqc5Ćyi*C?Q܌@PlL/6F-І7 ,;:i]L0аvZD6 /W./H:ɔʜ/WekV00눿v3f8=!A30]=)4ֻXL2вtJ/ڼ@=fc_)h32d,9kj@e*5Qm/bMU+\UGve}8ե y"㒧go"tǠ}N~SP\d.!X֞:[[F@ 8-'N;PݗC Gi])-r=$,6\SsT}}+Tٲ]gc1U#.1&2]8pl_a+}rr#"eqꢘX=} /@1.p*Hi*f${Ґl'%E MPs@G (;zz#̑4XU)xk*} ĭ-xr+mZVL?'oa"&S?1ЁF:(݂_OaH-Zo_۱vsF,)X҆8Ilh_ ms * ⥻,P]=\|&8r$~,&,$ LE5rq09mS,]0-!*):l&B c(Mr5dga VLtߥAÔ$m'-GK#RCK՗`]#Zk9Łx Gl)}XttǤ~mkXxpS))q\OMzi>Dl8$?N+w-Z~n&: fz 6sXÖ~%=jK5bm {m.3@OwԨd^z}' Z,8 lxj)G䨡j=z>Xcs͇YAU~-=:5f~rڙ߉+5y:KvHmt~jJnW:2eXK>I][?۩i{#'V3Qo۩a;^M6 |o5!&x`S@[b^RNhW׌frْiա&eO1SYKNoA?VH;Rt_[ ǕB"aۯU]Q[.5s'Ա Ĩ c+W'eâ,(@eXh'h4T#Gl=1TDxٱ`e ]Rm(6'?m Saoi ! u=|fWBKn<^>v9ּŏlZ? +(W4Զ2a jo7{4$ip).X}KBTvtkBzAՔ-Ͽ3pj6&˓xCYOv"z .Iw{O2%7Ai5[ x37?9Y)([w(PhSz=yeZU̗,3[nJl)' 1D!^LQje[6jR{Q]ʃfλJyF apyX[O1Jwªħ&ldS_pPD>8IxNpԜN"+ħ'p֍6yi=8]q2J3k6_Paj`;U'Ɂf2pQaáHS7v. &(gNSɄ%pQ5xZ-y!R_PLc}{c$#\216 Mh82SͱAݲ>fs*TEAf9gĩY$uj%߀sI.(+uDx{(~[+\'oovN,RuA'bD"[0}h׋ü.^L0N8XsC#^K6Ley<Z(1#h`Ne\CimN=IpA^<"ӫڌfN8G;~?K,b 7 ૂ3J.q>tml0hR6F3)0)S&0=yd̉`ؠVtbwˆp!HNLvQVixU3٬R^.2Xr*q cC?@v%χ%?ϿGQ& JBd |5ɤFیHֶ]:%7.҃<ەzs?r}w!m뒨)ZKoI^E`OMǐ9J"~ ןsՄ"80 ܼjwSdm2N ldZFM)W˓xÀcR>|N uGo@!wRbtn.74iBbXk1C 8"f[VMI:up*R%9E66YyTQ^H !$@5Jbh͟sAZA,<”l``J@Wߨ#\?a>P^I~+@sk4 CɎ2v"{).Ƭc":=eN;s-H]ؚyQ; `)(ΔnA01Kbsſԧl$o"]?8/D"Ph+YeW[I.LCHt -X.nNlП|m ۞O]|]"SJ ?T7QBB/*%p#W*y>pV\*X&},x;p΁ t_DBrXd؛22 >TĹ9)p%و56QT n{=LM7sOWk3{B yos,-vZbkD&ۯJ'zk9b>T㾳\cz6#yO7 ^d@cb`A=3RNJg | 5Yw{76|ыt 8s;;|< 1Lr fq!M+\ 8QΎ#ql/߿O=`0p˚\QPtN$;W Ց=G6=4r5B{x'em}g)ESK[ӡE i'DqzFM0魥M;";%Km fLt@QEŊqԊrUȨ^fDZnl(0M,s^+#1}ũoń+Yi$u5:n_x!&,\'56> ş譮O*ēVQ~\id*4Th=$~[TƣM.Op6O1QCc8N"[(MLJ"V}p%93~4Ŷ$d#=5g<KOpłs<Ғ99V߅ܮjN0 ÄTQ#wZ[q49^{NJb94hn~rLޑ}9m 찈0=h oLzdLd mV/(4;"|܈(9߁ï>bή.ç. i YE%jow @AaWTx_ƒ`$y+]Kx=MN3R8eX rӔ-R$q*fB2|So'4"U5Xb(zCٗ^3ٴ޴+|P?P0{vk- ~ɚVр 樾C䕮?9ާ"/nH蔈s6C}'čVfGg,vXl]2EtG2[^AoK/4c $[D73wZe>苕w|0dYA #Ithlf hƍؑ/jI)֐$,!Upn.u`f:7(Lԟ[+71eܾxL{C$gY^%`U2f|Ɏ;z 3eH {P_nR:$.1,S6몞szRDŕh]nz'c0!}BxہZ0AG,^⠒}:fF9"#zT2mD'}O|[ǻyuUPwlrO%3{"AnTq$ogt5~оbs VWԊx0s,-4Lϑ+6fMݿ~l9(4E|#V*a0Szb` OFԂbZo|w,!ˎku_2)rd7H_UU:6EV׋1dgƾ qM5ö@< @E%_w܉oPFo⾦*#ڹSh?#D#C,e-:AB@#٪@2z Ԡ,!'Hl!e|p}_=F!ّ&N!kM2/28:<MܒCH"4;U%T^\s@.Z"~K,Y+!VJhM}tt{A߱39= 'dJN¥]Z/Ӏ29IRF9S`tRelsW 6[~5f~t w}1ώ|LޘYz+&UdŅIyab1٢;(SE3IV@ޮ݌)ߡ"}ṕC|n{$I,b9Ta`2kST'C'>R=`ɪ$'1Ѻ oT>3%KSyy95Mvk&TѫXh !TS3tJjgcq?RO{SHc7Kzm`Xx7󗧨@D4qƒfED ^E (ļ(ZkC>B9,ZEYEUzx8'Ց2<^Z9hu2j1PXXl,"! h &Dn}AЏ`?yBbWs!fxAӱIFyz *}tZT]TޑkiA > mC +^a7ӳ|19/24N6 VN66^>16u.+⩄VデS#PBƿ}gS)X4'F$yh[^1sW :^Ҳ7"6|@.=!`g?d w|T穏f3ݥ_M1xeϬ?VdpfyRl#h#e0Y\!"#r9]03TO8N ᚶ3n?t7D7z[ەSv:1!\ {@$J*#l esE%!fַp Vuܟ$4}Q|RB_aA9^9"s}qz\`IS渍z1Χɋ,u+?PJ<0>>?KR/=l/grywP&~,@ wo-$Ȓ A{kiVu ̽|!k/_/oߋÔ:#-LՌs'Aͭw n)![=.~lvݱ268oj]̗bu;e pYr j92dnc*I:CNJqr;HzӋ'i J=DhPDc5`8P?Dro6c֯2Q;G|sJ h/jkn1 Jh@p)-_C3`Wk&~Z4dL}^Fm2,Hr'iXxb v|C3ԑ%̈Յr)xB^h5 ޴8D7o#*\O;/Cܣ@=z g7}tj#kpeUI[8l?G*qi7oq-(9ʧ%߆YtIIL>HncPL+yv%ZI[3٣lf٘N@od1`3&2$6 a)uZS~[NҗצSvl8[c5^|t.N dT,Lc>*EaT hsSٮ!#- +cbfQ|`9'^sv%z%!>Y1Vv7Wߕv͏f%"ʲ[5==W7Iv]uzq xA2h2k&.YϏV2m.ah#yu |t`5}[v)PvrrH¤nnK5+c'\ lT|qzv*q!SH@*R6C.&lĜ$9w Xl׍9C;]g<H֑v5Z; cwo\[9Kz|vNh7Eg8Qۈ?ȼ i*WnYC l oF΅$ߜcQmv^^'9ռ4VQ`U$/zcY T.U-=+qFJ]_r F ('\$,)ߎ1p \.>,Z|=w%Pm !: ǚy۾CQ͝`Pn<aJe8(KLA]rhV",x`*Z:\R^ˉCTeru0dBAmtwpq/r4+,~F: ݱpM2[J9u@暥I^ўekŪ!qa/A)Mg(0h)S?ە&!MԟZzO"KX7 .+%/s׌ F8}C\C7rXxQ*:8'QG\ho3adN*ɱ*kmA|3jQl2pNw|j^W;9B ac$*ŝt`DEYP\,Yz.!M!/SZʺ%j@[N״^cvu'6VIp)&N_w%ƺ Jr([U\f>$[||hPiϥ@lK͝rR!!GK{,yb6Ȇkk 2U"z0(Hyh©C>͈Fi`;PYK޴oOa=xRe"Mm;xI%&D|Jn%8P^q?ۯksFKXW4?J4LUZi3?Q/}V" |Hpϵ <{rT$]Ynm|9FtlssuVcz.e* PInB-dNɓjQxAyȾ~R@qq-9 BnR[);.PKර ;566*1߽aю/.tdž0vU+źtм(E~j5xo4!e[4p)6x ^0'•PT Oc52(2YeN.z$h%sYunʷl%h3oHNS5c;L%T` MXBA&6<>`bĆZu8R#'G^!ܾJFybro*NsG ]ŷ ;^*$[3"Dq=.S@穅glF*תMhN!h^Qk|~TNvש7U|ZHQXA2x_*j#A+kd/P)C:+nH@,l,5Ay{J$+SwyC[c;M6e_\)_"vnN{Ug3ke#`n縺4[l g(R-]S&ft6Q&tҜUcsZ/ZNսSGaP$0ڬI$Fq||Dd#Zrr*:KttlyWnӰBd\!ņlu޽9<fمgvj$:)Rk ._-nQQ2JU  ڴ/bҰ&qpZuH~)7{ڠ% ͚%jqc@-pA`8DQFh7t^F% /~ŽE, i[}4rZߝXv8s-%IdZB:nCm ZR9A^v/gU.=_4σXkВ0Tg΀ڼW" dm-jɠ˅Q 'iz9aC3H/E#jBk᝞92{D>|T Wsi{N+Ph_aXG x mu(#y{r-(W4;aSS Ԧ*3wM6|r&'49-ۜp6t-t \eYδb/݀P/B$cJbcuȻ1(o4fp!kKQrIv f(Ąd0&[CYXx# IywF45U:X2acJ[Y#n',xW\roX7a(PmBБK3U?n3D`A-;SNX%/E6weL=y͇0{I1T̃YLuhZ-P}P6sBV~qFBg՚#CfzRf)eֻ0`b7hމoVzr844^'*Mh?J(g'ph?2I/+0I%ZoF_޻Lr[]YX45t] VFJ)*<NOIޘ2NF%U>. BQe#}O#Sv;i|"2X DT,zldisI(=0#d3pD2xd &K;-.yվZqEߓY=nĭAaDi8"F&|x?%{ HuI)T#])ǙD${I]Po3;4mۧo.l٭K#8OBFt?NYk1CdmQzvԩM.v"ɯ<ɗh_q4$"fvDZe1s,}MnQYށ)aC3Tq}uَ׽e.JxnU'<`+ HϘ: ޑJ qկM]DN>EC"-@g\ljcP!n0ǟ;vF`CIF "0,@EtaV$׌' \7`*@E&x迟56:V'u*i,;3}*'3Qq^l$~m1 LCbfRܱdZ- 種7E*V.no=}ϔ*wِdBPLI=9f>0A9LDYLg9LgqpAZ/-U=T`;:(!v uJ-k'm^d' h09zE/5&]Y^Xg-{aɁ_Է:qK>a<h?xaV5,6GM۟oڅGY2s꽗OJ8XooMzPѻcG;j>hr:Iį)AIk?[R^hN aS߀o7,Bd4T3f_lx8PM#ɘ֘t@KcV iFЄ WF ZB.3d[T/{+1Lf̝X' kO>-e3qt_q&jWC^T4m@;psީk+(sֺ@;}{{א<&|,6&nFIriMx*|(\)Si|T$#W̴ "_j #'Yr%CG=Y9^p{+HB NsV!`F2䏪UH" %'}lB60Mڂ : >g*φMi[p$ϼmi%Fy%w]zLXa0WYExjYcj7{f0vxG}z060Bh&rǬʪ܆ԯ/&>q@SwØtaF8Mf9?y:'G?v4P ɐǾ{^d | /+R3'-Fbm>JPFӎdάvJc(v+ YFct0nˣ5JʌMq Wx?岫Np=XY@WDB|SQ) {㨉 A.a'@BCس%0) 1#h} iѕ _+] oT_iLEzefc٣BCZbj!~P e:˃JY ߉ IW8DW}'ݚP J1_*y7*JeYj E7hpé_$2{xkT^$hu.2K{iք5_w1kIRZdTih]r@/8rT7j|HP,1y6(9+0~nJ_IgFlp >DsWuׯ& to@ {j[Dk( Lf5KTl'tk4wbWMs3:+\%>QѵTX#G`["–Ppr/th; "_,won𠬳8.s_C+0+8r~~6O_cZ0/j&pp;Lx"cdnqE47.Ӥ|WcˋVv?; #5`(Tl< @R4 H:m5$˹ͅ ~݇>BY0>PyWO5MX²ÄzZHsuHX-xͳxjhUh*k h@fyd78ȉv]!7,Ύ-$&⋑8J -o]o4s:\SD9,=*E@ ds⌊UF DťjTGa O4cpH`Fܤtًd")hdb5 7|^$jsFHjibݔo({m[zKO͑Ja+gxL3wY-*{VT9DlzxMx;z~eq~FSK5}(~8lb142v+g8axEwNYi-2PF15`wHF3kݽ.!/{>uWe`'Zj|`ܫn6bݵ{nhҶUC*UY ً%AsԐlfBP $į:+>Y& bap[`5%,ZY6 Z3R gۀ _cXާ3gO+L'%fxRaC DϺ4<ƛZ(X=4+4{>AۦIk8}sBչh]rz$]a5esRWf*CP•[r4h=?^VmmHKp_Z\GFyc5p{{!\8p%д#KaYKrs .f0AV>SX6@o펢2޵C!CKhVFzx?Ot iTY|i ίD S58V2C/ÆuIkH:=J6\yRrGU/ 셏Oy6lB.͎ę=}h`,®X!(  }*Oe;Xi0'ʵJ PS"STHi >4m={k]1!I>\ TYD0('D~髕J'%&i]*th|V"&ahY<* AT 5`@y7 eXGYN'IU~g,9OgT-L ^}eFr[Tn^iHI1QϫnrXOC Kzrł%v]xrreC0C o+ EԡeЇ@0r&,wKps@4x5v꺚rBy.7+PlPޥZ]LUhyDXks|D(BIe;&p?>|*hp\;q v7ΐʬQH{\p7΢ϻF1Iؿ9qwk 2Od[fǺ?uG5[OX` -[ 6eqglF3 g^Ồ=ҮG݌y4hbrh oAGibՔ +نܰ1PĻY$egZɻ!|ܧtbq9- @I~  2#gEǟ2)zG^w]6=՞'ɯ'"z4;'_GNvj s_'KwsnSÖe7Z)\HfsCiHRwXHK FGLpKFE؂@EYw DM`@yP 2y+~Y hSdF+$A@tih (Yx#/>69^`$z^**o,uHEƊJҪhsy򞷧48TnzH;6Wt" oqEJJHOUL^mqR&D%]G!848!n7X66IHf) 7UhN.Ȑz/n%f{ua?eoWsd ^4Rkۗ}PHr+7$ͳC2 03|#BQvxK`M5KsV䊺{b"D9b$b~$coo*aߏ W|i٢$>ARlF OZSZOxȒ"rzב z)ɔJbH:%ՏZvuM|ͫ'ѡ;ydn&sDՕiRzCe5KK`\j99l(al0O uI.0 ZרM qO&ܚ2iuuN+)`U2TjKxK{l ul;xdCwv^\cCyO:E:Ӎ[OQS9yBZ39;uK6,#kz頝ˍ-9Z~BK!hka6b $6CܟJ⠥Ī7R6 Rfmw9`auYyA v!򂃍Zt9%-A'Mʚ [IQSr.|$7qoW4,:-!&v5-Tzq)':u}E&(o$#ǓZ꺥MοPgsB]|bIvbl =jOޗ1ɓY e(ɱ AH'RV;?]FL`  G08N[~j&y 6%QzD=p+s Z ̑`fSƛFT. AL7vQy&N@3\IQ)V;ݪX<87tKzF d) s'N V=(IZk4cURYcJ'BLotv9TwfMCtoz .iѭw&(+!3BW"КeYbMH(r-@|x\ ,C~snN[: }(Nmm5Ba׹GUʚ ekz]P*AUO%hty |z5I~igW"6^t+8"Fb>jKm9 /؏@mrh˺@Y}Y\E Z0LiM,S[ ~UEq?%rvեTɀb`n"htu<*;-⽵lF[HSH˜/=ɍuX׹UBSp7n G7Ȟj4cok M1 8EgyaЛ3RΦCNvzydXmc% w *xR4 Xܸ_\xi]n*4[O>$ʒ%FRG PV xpzf/W[Ih@*`3)AتOsZ}Pwmf-\zK$[(L?$὆_}#X(SXH<] l3m+9gY{e䈣ĞjW(~d?K^Qm+hM@!bp3Ҙec3SUp-&f8W}9husg$j}VT#aqDg%H08&-Ș ֋POG45=)嫻{rTz)ܞ3)UDNjLxhqNwR2"#c24 3xU"P Egp} JhbG=޴, ZHi"Cc&+Po)񷉌[/lRED@-!r)4x!磙ZݎjAg|/MAxcDx`_[YM~Mpl'-m0F.3_;0xnyViUa_ޖgoe(OU 2V>l9^cy`=ehio뻿e..EOlf"†k~2dZ@gowPf >t4Ao)X 3Dw,(A8Ꚏe7W5Rin—l*TT1qoC T瀶mKk4@eU(ԇq!^}ZJ_P-5yIu_.ހgOUn6fnOA ij#bMnj $|Q[q#b&C||',uQĕ3{uZݵU;+=`+?Oa;K)W5|=yUU[\[~.D9$i˪Z(?8 f-y|`dZ[ |ȓV̬+̔E}uNjF4 lIcB~&5EU`q*։)4aNu1hqFйnN]tK/q.1^uE&HwN մoR7-G#xYP'N/<\PQ5EZHu87kk^i< /aǝ3Jy Ecқ_*7xJ@|nrJV7}b2j43+[`ԫR2ڢ/xv >a&h"s9: L]>3#z g7&p/Zx2M?V,E:@}%nY=FNцvhPb06Bp;Ri\beT}f/`$JRKB iKu :b*G;y pt<y^Ɗ$e:KlYrJ!.˚V%+$|wf5wMn`EZD)AխnrQx@OOZAS<|#q^R]DP&V%̮v泦J@$Kjĺ&D.gh]M]++c?j~!]ɮ9H3H(qV^J(']bHc,o,ڃAfoEP_=k>`Bhb"ĪmGpw=ڏ&Hf |0/hH ?>O]H \IzO#ɞcY3cu8@G(Ĩ\bpEnT@й&j#9~8(2VMWѕ |bg S)GAW]85UK! _aOٱׅqР^!!6FT} 2E1xZ&/ .w4R;JIJPT)RsRi9\'dS">fvF #@%@>˃ i]Y[SjAv]$|t{z3#cG^s$bzx8{tO^d|7t*= ou As[X eׅ{Ppis/R(J h:'v7V|JRU$ ZcC⚚t(/jKzLٱ-tIܠ+$"vR]^HF5 Qm1@ܷ٪Օ~\F$osm@ {ʸM2z8I1`W0?!̒ٽXbуg6m\f2zx$jhƵo zٜYps!%W $C?v@k+%fB5?*\V OHVV^F*w|@CPO.bh:ܺclj%$MNBʘˮS|lXPus Ei!N?/P1<οwIe-Мo B}o$q'Z7 A. cQz15K|o5j@Y+ <z& rkkz<8l0il 9\3:| / (i^N6I |Mk$=Hel\(ΊX<'Qq1 ݦYlYKm<~HooW02P8SRcP[7|xXqvΟ?INdǗe.!#K+.-NHW [$x8Z jqzbWߚ\C۷|-NX%/7'i2" R/.C)2 7l+;fj%DqPRJ+BJg~_G٤ jثVy\2>lJu_j~/WsA6zm Iq3c6;lR3CK$xs1.m΍Le+e[I#"K: JVWAFgra6e57&7m$lhTJMu㹗 j;!aqԺbC4 y^|\B !kJU. 4xŬ)}f&d٬i3lT]a`7<LTD&GOHqjR=WQJk< j7f}͔m4eCdQX|ÁgMDP7!|Ij%Z^VS5F˧ξ̘D9j*B)xzì~xgB IseD勢J J5D-0NuoW XN|s.]}j~. ;oڔ HX~P!ǵf:lI j]c1ȼ́/fېsy30YRY^4S:Yq12a7"MS!; ^ed>J`?T\qYt;C(fcgn8ȤQoS9@ZTj>7)Kr0+.a(nk<h{מ~1 *B8m4~9l] )=x(sǚ9*ulu'|҇MI<Ɖߞ}PR(*MS*$|. ˞/m@Ȩgm$`OZZg,T (M7D0;r1{P )(VYn+jrM+5 /;v_>192e5rR*;*p7)ƙr]S]!$zD(G=FQ@',s5gK{8(J؉\C9gB]QC*+sg9tq=#O0]P9 <9s-g5L1}V~4^&GbzUAVŨI;w"+큦V5.ZZ`NJG)kΐ'KRY3WNUYT:'6XtjhpL__?:= ^ 'gNC3h!D}$z-nkmcx1=bey"-~],Q#] MhY;ź!g±)( >nCŘDzhtAJl*\$|3 qRM[#*$=ٸr+n'FzW'C;BkcnXɄ') Ktk4؉y6m$- nė5;2*կ9?Ȟ;r0t3CtأCLuaQ1"Gf@wwA'+`4ux=M4V%Y:D!&ܥhR$f0cu7^[fL}/lXSnd U[ 1HN( .1vr{Edu{tR@Y\&x@drG}D2i+C j,lP}x_Wd  UtrJs~5G.kA1"S aakrL4ZU7G3 D:%ѓ ??H͞񙈌yV*|><>7*)ȞбBl5E.\XueIЪNÒb2l,w}"O&Є ,HI٠Izݚ&z5"{'H}Pن/8eߎ^ȍ{O7-S9jh4ٟҝ1[|93aպY_h6۽VQ։)|wU/-5jJH</~=u7@:Y[+c,°'^Xxa_GT]k̇:RP2R0UcJv0bgkAQp5Sߛ촓ɢ#SjRn>3IRyMNҴ)g Ix)Db؈ >Nּsڕ̷8z5lxjC H7 nW/zmB2 \(ҎoC$a Np- 9š/\2:n?aחb%$m&AY*a):ڢ,~M>3Ĥw!㪹^u(IcwZ&Qܒn0}ϋ* `^wbw],LVu K{ \`Ԭ[;u<{I{!g qS?ÿk4&Ǔ6:6v+HwDj?m tnN3 -%4bC /q](gsYQ"<k.6Ǵz 6}vpTO6ȬpYz}T-GLxkUd=$P#Lg. lU(z1P+6sd0h|Es|4*8C `({: z`pBr Fh@ۄ"rp Hkh(\n[:u`mG4ӗw*o(JV.w~-ϞHHw J*qʁ*Ӱ7jt _n&[ tvoKtV3=.<2'U6ჰ쩛{$={Z[m_3ierR q~A@M? ŏ{ǭ@zqQa[H7qik4˄ l.)gb[ckZ4pkʴs *w q>Pxʐ=Su\-V/z:D_KFU=VKmM^WX=.P1=]ֹhJ:s*[zGn= 3^l3a4jYFm\n_׃t툗:/Uxhu+QaG]*nZ G([D"I)T̈́<,:ӲwmM*dĞtzCI*)B{`];SzGNѶŤ?|B6VK \m|H_y2yȌ!sD;3FnA+tpZb8@AͼKhp_R+sA0o|<.wFu#v](m]M,tLې#:Q˞`4^" ne#sfq Ϝt@/Y#n=V2X B!E̗8TU_Ǔ~D0xAXq򤁡Tupmcό9&@aŁޚא7_+1?)$^bMO@vwIxKjbV˽y^f$m%oor9.lS-m V;5xbwy{l"Gr5$&eyR:?޾g¢,&fL΁U ^`~k=-I_ msk:mͺ0QC0}mjZ.2&&/eOxmq2SCPLAt`)I<jyd0rr͹<^=[x$@VqS͵zLWyHbQݠa{`ee!x8"T*8ND:h#ņVˍI&|ZvQꐞMfсcNF0fS̃ToebAm؀%vR)u[ է= q V1L4BOQ-9g_jF"lzRI2XҎ.3c{?.7A9 JbAmj-#1~YCK.ڠsMV,"!@İ)hJ$/W fF{)O-{,C?LouwW`#Y9K_l{.;nwpӽâ} }>nJGNh=XR)2GfZ0u;/5 )9<̕1UڱUӱ@;?Do04P.3Υ Zc!OOg*JBt;E!f0ՊJI1_k~W/xh6ӣ4,v7Ow!Żc8v{w=fLse_FWguÓ OfzFBK bjDr?7(oBVm[AG<e YȾ[Qt졆 [Q(Zf "[S^䡯n_s<ܠ$M%py{|ܸ JS?GB[@LpMdp_=(?3Dhz-C~fSe:3hAŢ_Z%wT}#Bb XBiYzȀ Iav\4մr 3 +g<8|>ل\N|];9cBLPMpH_~9rjvkeo(U)^4 [[CBTӼ(~ ^/$s]LoY/  9Ҏ$S`RۿKwy3#j~|8pڞ6W[zq]+^ n#u[&<#eB,gufMAfYҠs7^DR|нSj,!*rzkC.>G9ZF"S`s0tCSہvd6x!ʣ9>"9_mDFWSGB^| K?"IہfE[I\3l 8 \4p&?8L=sI|)ٛt]۸oya(EB :wo)Tnxhaq l'?%гɅ{.ɼJϴQȥp MT:~FѾb{QJpӮJ`睧vmقjf #Es{V0rL=YnSL^Z8g  W$_H&A${ŞfQ)f"06_m%wI"Ԙ9;m3챎yA&I TH)<z[Aܪ5G'؊3 f@8i%M&|/4BpfPbE>ypej[|_3H_~"4T c/ׂtpqFDl67aa+%mR'R.GUt*y]NHhJ. MڠNvk9mE&/Bމ&¡1<nCMg^5eא TI9,= i;fពZs7Rti{N ZkWO9(v((ûFNၵNL`8#>/]!)[5`_yӟv4>[r^kRL-k0|LE\#]y|4VZ+1wV-g4 K&|zX:)VShC9P^d$PrSZ2s&@cܲ$kbm1gK:Wd;[P2OF&=oRzEX*1w  +TNo:Kk;đl{Ngne Me/ K00}uBR^3n;SbަQ`4 ]t' xGs] PB%'ʫd;-YAm%$)t'XoB{2JEܸ͜4vfd hT&s&y(56_ œx-LېYXUvEOE pj?!8'45/P @tX]rjY:ɋByfa&jomq#N|$$6V@kSXb0=;Bb/(q~""ҷ+:7^ai(#$`oL&)=hoV8xCcih >G #u#ѧ %S<8:`NaVy(pds5ϊ7ʷŎ`Ή fT('^!9 s8z@˺E6̃ %}c޽e*P.jR`R5MmRdK y1Vb|Sz$; Fnzk”+H`7c=8c"=^afgSƹ \6R-: IDԄ 0&Z3ΔYO94b~m _m(g(O+&jt{{YSDI Yм[nZ87} Qg&(Tȁh Tq cR /ZIi6k?oQPa!_"eeFL ߌ9Ze9 y&[t($tUL2Ż];M#6c2,%9v4*v/-c '7E Wr.d{+)8٥&u}j{bE>m|0iz~ z3d 0z';u: -8"IX~Hx$Ӻ4C٢3`,5xH`=WŘOX Jg ðہ /  EB>,"D(tQ̂ORCňr?ZEgFLLiHe"9`hyncaLdu&6y @cek_8{?nF;z86&NtEvHUMYqE8LBeS#'bfXld k:%wWb em(;8= -W(.Fb\ FRޖ'69L/Ԭ\Q7OTa`rgRE8&d_T dA7u%:fXʹ-%VS`Zd7]HM4C8&;T6R{h-4S!9r3.oQ;#mK#t85 AQA5y^UJ(V#Z @[6=Owt\2}!0=ZS,gHy׷ꯒjCJx6=^1c=6̘􋥓]oP1W@#q,s76;G`Z Ϭ~y73 ;!no [{DvG9b+QCН]1e@L{(ea^Jqh8R-,Æ/T"Eiw|-uZSid7)i!>Qo! 7Uql.&N+ Q i$˒yP.9O+[[ϧgF $0Hxҭǐce!85\w٧4DNbeW+4g)ZUjS>$ʤ!"}QF[Tu>~2f.sT黓\IB=-f,Ew/?02}_xuSЊ"ŹgR.4㢅ϐ~/~mhb j ׯ }~H?[<8R0BgF_dY&x a`1?>AuKVz"@,*g饱0rB֧Xb`^v*Lh KZ=1z2}Wuǖ2|zkqȤQ$du2mU!dp̉%hc/VgА.4ܮW߃ T S-8_!u¦CkgȰN΄ X8_YMJIBd V'* ^lnEƷij{U0FZhn& VɉL _KmQ< Ɔ\ǔgSQ m8Qћ/;h@gXӪ. ~*'G.<y~kq>>\M\'yzX?I뉶mR{C o{??r-|VVGzV/u~d75b{8Z*aPmO/BK$cqr$(V]Tf̭q~mZlGf gtHG?c:b6& )h}sFv  XQZa0w}dQ_>m̱ㄳBL05r,G> -"Ȯ)8[i3_{(ɝ$¸d̮ MA.vxSsaSSlKP|P{K(!vKY ˯{ R]<)ņ‘X9&m_T*>8Uikꤤ.žmKhe&S'w,+ S4 6@Ͷ;W8b沛((|#^F*k_K+7$6R ݏp-ds4[x+[)`1duܱo3fS4%n=-y6{X|ܚ#=اoUdcO'.#>>_MB&rZ]rEHSD^OƁؘnQgiA#jfŽMCܭ͟GA+ƋdOz RQ Sy4~8ɞ`+uK \ JEcdDv?v2*,y mϝȁwb7ؕ^o~7UC3iH 'S՛7QeKAsgپ:^{KP!KGz@Tx|HꜲG)[12;F-bO3L1#i|P[wXkF0O㥰IO3Q5g"LaLDFydSG6 Rvxv/d{30OS榍$jsmvNM6 Tv b Ds;nvݏIe/˜>p7'z,v2{yX'p-j> 3 _֌ NJx \5HZկfRI=/z)VѝMeemß[&D]d`4V ΀2-+0doZ\j" J=8}'&iKѻHb=h"/X$UaT_ KO/<ߍ 7HQu]/]}J;G9|({ٽS=Y%FNmUU͌cY_95G[OXz*uKg3S0;8D:\ ~ˊ5Jj堆c0UKm{6:Öp5.♬M~DK{Xhf,:xFMïFZyFVibWe$*5[@XaS#(s|aŦPeb8,Sy4Vw%69t]2Z@)Aj]7_ULT62c y읚 ίGI y 'ڄQ3i#6e N3fG_Qc̄vD΅Kꢦ"U$PZ7o ߣhjS_" n1%9!(0x8F k/r-cEW}kWr :KN$$cZcmg7:p<"RSR}@t2:vl,['%;6qى`8 c"_,} \'h͛4FaRbv l&Q?03PCĽX*|tPl"qre[ɝev]_XZPN7@VrMa)uVͿ}) &!U 2U@s8m;W0@)s#)|^w@dc=p ؛N;/l+)5q0'8y@ "~/2搪keuȌ;7  L06p(sL> k:cJ,*!x)mfM 2`Bi d1]\fZ0PC5ROcjwPM|%2%D£6,zcdZB5 բM1=";T.Dٴ1;Pɦ McՔl(ol3Z4Ts@t헺-,o'$T:t:em+zl$q%ʦ*y2r}w;*#2%k XʳTP\vTߢbթ w` ͕cY|Ϋ("T#Dt7AP*,|4h2!>@I K'r?( :ոI ֪|frU8<.}](Uw8JsnҖ5 qwgaočBZ`"Woo3wnj \UDOoWl2o(b(ݨ=e[JBn.?C i{ .>(Ή&.@3ȫl]{8LFQu;nx3t]j|1tJuQ[ o02mV6ʃ4t549]= q1 ._^f]2|X:[o ncYB6G\&hb붞vu2:30aF q^7 {t['8!zxu\ʎնuCJTGzjC)zXTT)ڳ]v͔Zd҅X MHf>-YeŠ2?5J'%>j2}4[!+yD ύ ,4jUF*d(4Pl—[_Q!0N"4ڜٙ/Q&W pn 9" 4&Ԑ=@dدJ_I=6 m[@c =}^U=+~'jw׎gq"P/"釿 IHߒ:Xx@ NkA Nڌ©BIlқhR|& k5Ʌ֢/_)gEޗH]$o2#\X rx;M4j!9 Lzne7 z:pW :hi>'BuO!DLy Ïw1'篵+ r%c(7E0Ku#d+ #vEnVkcjYi1)6B~h^3gpm[~;\'rq&qbåb|٨P'uQoky0b9R _e i rعw3,fȚ>v*Kc#|^QoxWw)lZ,'aygR:. HNApL۫Gmآ_ h`CIh]-;[U&~*n3(ȝmjX=7=p-_EOƓXWlSЋ'*|7omVwt%q.:l&tmM& pM>Z6C*Щef懠R,LBDV(]uLĬ=jOx`Ƙ8rE#G S,i9S,0͞iu/Wm>6ċ83; ,/j{ nI

JJcR?^Iԙ$I4+@3y0? 3^zn]DV{@ҭҌypIhӔFdcYkkw4T|PˌWgt( bjVzŨE~f&i9i]Ic[cKC jIn7,]˺؆ aΙ[?5)E/{0QR|z}.ܶn"ߏ559Vzpg H*#s-T-:΍c`J-d U.鿺Ϝ'Hh'RZx1{ ڴ$pGy%Dr ;Ą`cςge[O:]𒉀kԠcxC'I=o "_L7n~H'=G?;6妮10>Rl^%'esS5eίٕnWZ!3kj辏h%c%<ݼr!01ķ w0Mt3v6 ӻ1:3_~M]j. U~VO'<cfq?UZ_R za 7e⬲oy~p ]~FX76nGo/TNoc|\IwElrm #SRC KbZ9 "_}`مIX5qsL-uQo~UH1)y-h@p"WrJ}#1$`6}܍PmiSqsKٔzL*c}rakVk4/ aޛFE}g)1N՞RD,X'T,w Yw'\kc<t0k?{:0u &ZYF;jYbFzP@m2Bj=A6nVbґ&scխxXݥGfX<`?x=]]2kR)~BwP)RkU5Cj .'*^ t0[]HLzKHӾwDP,>YP=`f&MP0^e Uns/]e 3[z;Գ̓ Z-|ˮF݋0}sy[1̊e%nyץ|gЗE|…d;,k^71w_[, t]#d_KW܎rK);X)\GepnL}?Ɍle({86YTGpVPMfS'}~kw|/Q(At6䅑dҩXK^%/i\[hvᆬ]09ܸt- cri[ej\m5׶yVS~P ќE }@-'n}4̉.NE4dd{W !@(6;ҍd?' M#^a޳v=%j]"3D;mt,42 .Du11:ΎpGe'EO_v, K.)9aKO;}7C&\T Io[ZОT&oL+CEԻ]D0.h?ewLcdWV @UrZ͘f~]]W cxh:}H- h’ !`] ޥ2̑QE,BOv-vX mg1c^~F~;$EGr2һRp^ثI]yū/mc(%}8I?rI)u0yY1`jht>!eHvFJF:yjP1N%" keFN/W)0g\.UD_uϢ vW2pY-Q(5gPL4RR2.7zvPL{׈PI5-kkCkoi:YŠb1嗔Id5Іp=s.y] \_Ptv,ps:5ɃWOoR2fv3rncX1aaHxcƭi온jd&ߌOJ^Y&h 3Z(_ LF.^:4y-^ F_$K;lR./';ZXC;|]vS9|?b![r Ӧug"f PyLGҷހ]}Х4"@1_[R2t4-6{[tR/3g_z_%Thm0RsڨjWK# b0 {o`QQ>mCJJ2FDHr/"yPI!-, QL—& H(ع{hp h\eC] 1um,O!ʻᩲ Hbwo(оn4[=cj<|]:ۑR[)^FF`mۂGKSor%4o1H( /LUI€e{U'L'I:"A~}1+խ ZG8-3+&R YӴzcزs W*;b#Q%ϥHTmT݂ 1/]9 Uo@V`OMQ5_v9mCSMPc+Vܒ2єz}* 1+1~t -)!(/ؚR`5^Ryҍ~7܂}>`el5\#9tھ]*Uv.r@e;Ə~{^lχթGo-o2Wz Jz*7v!]mxb'MbIEڱQc)X'cZv/Lqa V Bt(]a:r1̳`s^Vr#:-kyI"ؕFYZ=IFcʛ5rV%p_*!-!PuG ]}Cq!OQɞFeh]H")B6¯@qTC Rgrʕ1{fLe&V^7NMZK{h*jjF*bG`{3.`EJaPVi=?)w0L< =S 38EU)N4Cri~<u]5|`E${`lJ3d դ+s:T]1؃ c Ƕ4,ɓa p[o_ q2>:nhAރ>z)uǹZ'gqJчup_𷤝APkxw yu]gQEr Tx^7%{WYqdMF2N{ql'Gԏ?dsid$> _#{u;`dh%Q'?b08 g!\/Xc F /M02' t`[6[BE`5Ś /JcE+ḨiN Xbإ$=dф\U }h{HOQGOFŴ?}fJ:jJNr⊠Nv0Na7<,m\KV c3 !o3卑EV_}rFšp,Th .7SE¦Q'4/nJo5BS.Gл)2[%RCOxcgX٧d *qS|GtJWB=z gR<0Ú^m5Ea0"&B)U֟)-f~8$ &bpEz\DoEl6ˉY6˵T1k]rqϳYhϦJAU҃Q=Jۘ"Fn,ZTW8+Ŧۢ}s)1H/j5y)O-z-bG;[<&Pv`*#4"C|*h(5  .xϠNغQ=m]Z(sY %aJ7ӟx1`S˄0[ Ax`_sA?=%LX _5@'$82^,F<|= ({%xexXn”Z%CO ֞@A .ܐ>]elT~6  +j9{[(J!ژ9&7:f+}=w|_nC,L͹tѿ}s^C=c׭U?.YdQfqq=Оɓ쳕CjCIs}h\,ExZ .5Dd0N;H+ڝP1g?IѸFуT9)ؐO}٦mq&ƹJ[.D ֋A\-7fjm0Xkx9:^e㥑vo4׏N9:aNPO^`Z{pqFAf`4.4ċpA۴aw i(t'~=1qC|ɭ{#*b*$)Fka$A I喙GW@^F3q$ACjƹ>oԕ2Sy$nl|L'p4r|<9J\@jwtqI5؈u6/򞌛bV-*i:ݧB09˯QYQ֪=#(<87` 4Ѻ.O)e]DvJ8|ܶs*tCT"hlgөNiqם߰/4*4E5}(CwzIa?uaj݊Pr'R]#DA9*$'mn+G I|V|.?Ӎ^ρ!`nw(VLfY49[`(Za;!'dc8~呸)RkJDz{:STL~ُkٷ]N=y6hJ6I~R\li ^7Cj![`GFeS7FyYyb\k^:K&L.L_c7Q)nRzi8 ـ q rw餾 Œ+eKե"{~57qgy2,tMo,"Z9!<֩ᴔ(ĊܷK!" m]?@@Wԩe1*l" !PɸMh"e>nbȽQrDLĦX6:3-jlV1nJ?Qk\|AZڡqd*wlP ƨe&E9XNS5:"ׅsQ'#sA3U@_VXP࣏uffsY<+Y d+1f}ecw4 SyĊAw)! Rp8Ɏ31y(CĸKKB>+ մLuYr0Htlbj 2Fqg:exOc搝EcˌZgH^3bRA@^K(}BOW3 ŁsWr/8eR2P931B d9&Xb?, WӅmrJkՐcWsT.$st0;X-/;cp0$ǡ;6b 9Ti{g`"C]6DN"h}2DOTx~t9{s4k6N,}J Ccj\:݊]ir߻mn2b[tSlQ(GPOIơ5Oo.LlAY0}$\UN`V&Q!*+f\Ԭ۸>^j]k1`,(eEDN¦Ei,`!ǎ)fv:h*rڨQ%F`=F=Dpy%`TGWfURiKSY6 0NC@ ˏщ,W}eQ/-^2oS*ۚC+Dm>['=1k%@2-edZ.9A(q۶#Xޜx6)yZxz&cSƒ1~Jb@%†f>t[(-A%mw߼AH4%<#E`\0:;rr҄L_N AXŅ0=K3C-6<϶F!\9v 2BpZ˱c c(<&k74ўjzyk\| aGّܡ'~ÇZs`;Oig]eW)S#-J#Z>*h-%sVr5F\3AhJE{H7ȹ J;| rereR; |t T*\Z1ud7CmfAe".xDڭh<Q¬ր vXl{eNu /Q9p*9nCSo 2d<҈<7PVms +ƕ&j׶s:GV$%Lz6W)]631oZN|tvnI7GIXyZk.mOuj݂]| Վ={ZqhGD}WVz,0ה}j} jV}K| bN2pdY UDls :p#$ZkB|eou֪Hہ+ ꍞv\JAʜXn2&lB?cǺD}Uu@4ܢI:v1[Js~>mTj2l+ ,k]xi6:ﯣ<_n%N=R׸$FG}4Wug/|ׅ7*XsaMܞjN7$Zb}ܼ.fmH+Κ c#*Ͳ'Ye|"5|q NCYG&LMEm\؆n)uBq鹳ǕJ uELFFz 3vFdVܢ:5'qr+Z)L pw~W*9O}Y2Då1.Y?meN4;X1xgeq94z)[|mW cƺ?޾r ;y{T;MZVhIhG`s"erٳ$0,0Fy>oFڝ5;Ἇ˱$"`ʸ ]$Rv3FN͊KߣT{3E 0я]\nyA!CG+ ߸v$qω:w06.'7~Ea]he#Kצ*iWy%YX' 5/h%#̗)4fH)Gv Qo)6XƸ"aIg,BVv굙86$3C_*NSf4Ĕ ~ԟ=ܫ/ĩ6ʂ>%:˕ -~By7XȋW&0sjh Hnκ"3W }Ey@X(S)ފɼ_V]طQR5<8iB¥{C1<2yn pn΄}EM0<2iv T2H7՟o "[ls8`NNy?s%nQRxQ[$_jXء S[Jt*a5,Ҹttجqlh7nM682|U Ԝf1v[Ӑ?2M462G9Lw>S jdMwS}<@׆O"tcyHkDFњ.VP$f ?/{KCĪ(+G Sp@z|ʠ9S"2!if"c:ԳUb8J(CA6?Y}R mG1#ƨǐVoVf{U_5ٚ=*sn(YUn 2WHD48KuL[ʵi6_XicE[=ZePUnxnA *5wI}8>#nPQaiS={H;vvE /]zmie +ܦDoS{Br|)a5i,uiU2-9\mt0QS(f. ܋a=mC/clL2(ng'HRyose.:;D if3L*gGgU-wөzӝҚCbiŢ3pZ`c{]7E}"-62]AtıY!ܬV*N^ M ՊrOM;fG0?]̭o*mM`m =L$'R#f =ƉPouSH8Sr6=na;-3{,!d쮐q%YjzY9ɉQpZi{n8Lh:CqkYa= ,zi,Y.i"=aꨞv` z@16]s E%_7ΧPΌ@jҁ.x[L,bCPoy@/2ɑ{f{ =k:= ̐cc|zo@.9bd$UjLk7[ru=v8+ #SjL%\O1L 8>ԍ4 hlh 2hVd㭉M\N fmFzj/r°`rl41f;KUnboyϺ{K@d?evT#e"g/0 ) 6(hXu"=&;Ds7ĉg0钡'd|۪h᜷Na^=,Cݘ[K:Rlc/M#FXn03&v&w jR 7!EfXx%4jXSc愐x Uw|趛Dr-sJhi8f-2$4AV>I&uOPqo$(riEM^AC?L2窐Y-ϵVYx_ klT.H{eTfXC߿  4{W[SȏV$pUvJ{g[W…"%]2)=-;[2m t|D c'NzHƭ9zZGUF֘$-iI[6 a1ÁTvƺEJ5`ס[VXW؜`-gʳbEN kݨ#Ấ:^݌eA7qh9_ 7'V2S.npWl-ͼTSՆf_m|@ӺiIaw'%Q[KGg6KV A[L6mϳWlFNhYۻ)E :{b" ygwL6M'd *"ۈzE.gL͕5hfZȨGIJEy6Rc> dzu[{|J"^Eck5ӮS /V˖$w0%f-Dc[Sc]1wPsW=N""'n+idJϋnR+*sv<YD7ynF3ިoLS+%;7FvHoA}sPS@n?fV8{n^"6+ŷYHp8S)b1I!h$6 C1@$BB?CFKǵ4fL2voi?;ilIj$-qh|]}6֔ Ur s/_PB SJN;~JJN?gI\29FCPwrDzIQ"/[ӭ ~#Q`ե aZ\Z+wM3y]Ȝ?VMwr#/|- 7!dSDXa ]2dНkkM5L'f\ALLwflHy; N؀0u ~/­t^cS*$3-Ҡ"bxp%?ᚬƀnG{X6kש `Z1]:tcgHg8X^CAZc^)C3 [2vsAGX+:[5z)7-, Ρ/##2Ay& [tZ8qu0':dKV>fʼnxI-Y5*wx[YVgCdͬJR87vz kǚk: JK pPHxKR'̞8+ax3+ܙ.k@Ƭ&34lHl^\V[QKs*hݒ-T}i䜬T$Y%te}6!'+`N|NWձN*g;͝寂gN\~=4}S{.9t ꒢y97p6X~C 6 3΅1) f6s^ny%bh134aM=M NKZ{]P&ߨ1*$w#O;w7ST72ꩍOC9w xˑ1:¥N>N\-Iza8Ө1QW8MXUT@e#^!"#[).7L'-+K"ĕq5Oy[fNкKT1r"=9 Y}m^8كZ}uSp9Pu˷w,':ϛwŁsw2 %"DdxIoPPeN UJ\ 2}sݫ6BeP"1!4^ Rc!ʸVTaIST|(H$ĊheseSWXnA`XK xMMvʇ/P}(bm FLyKuDśPx:ii{W[.XGH9Z;[V*KڕXRI;6[6lTLM{{xsz֤"B=03Wsjt@(q=Lpy_YZkT{ԑkKѿa5qVIX5*j:H9t3-3dLwt$L!Ϙ Oh b4 \bgzuʗVY4+`KDnkl5-IJ@ KtI1mi ?7cV˳It;-_7MW'!Ipڨ`J2l}SI {f$\x'A"|˜dAj1Hb[sOTSm< dVT?-H٧ /\\{ "] lYzYi.37½y =B|Nd1ѩ4[ݾKt٣1Fs*%wƊ17В"etԵ YS}U`]cMzxX|]2deVRT:{j%sn̉fQO={b;_?_9y߬Pu;clXk@wXƍՠϩSw?Fj55Um\'q{D^"Źr|~nA {@5'.{C1$hGˆJ,*ﱔuҦXf.:lO2j<ӱJDaP>FqK=a7Av[/9rYFv-UhPNDGrt.Grˑrt.Grt%``tQ^h9w5m^OY"F+ (XYn+S#?:^x9:^8^~Mc"t9h]^rkK:q<@vո`AtKvW2+iwa(g`ݞjE|u@h 5߆!=SmÝB^(%? 6#c\qj2#TNo K~)DMXF WJ5$/h%F|S܁ap|QT k-G~I F#ImNhR׫ڶ x{\PJ&pM6L }lx]end%1c-0Ɋ \93g?uY\H-)]!A7c[c)G]6f~&w MZ.&:z!QuD8{b]Ev0ݰv %)MnܟlryڻaiCe:YOmj,i`[Mt{\ 栲pqYxtJ6+.)yY?=,I88h#=6Y&(;f%`Q=}G|m5Ϣk`e 5E2b5 Xr¹-<ýA(ùI]ȉEJ+#]\֜,%܍ x,㚎'+ G]qYkDn%57.M׸@o!E4=;Fgv$ 0N_>MTHrNdA$@_\$5rL\$ HLs;m͍)1NvHF7C0bg '2!V5 v"k汩-dyQ5:v68q?[No0#dMϓw> (t|lJIO,30^Ug:)a#ǰmf +U͓ւXPl/gvEB&&ǭ9&hOe8@HLݸbaw,ƯZ%c85'3m}qGOhF6[$$dQl77Ti)?8wlVא{?8كۂ츺~l/)dF >w/pqIU?OihXAR0BI,e'C$r(a{⁚#lbvo0Ƨqsm> *SqfPgz~( |aYbq/o }LHWY\E(wE[XKˀkݶ%>whdDdnyy-,_(u OI:vU'zhp.h0QՑ bW'?SceI,NxW8va" ՛+ZaI%,q{n^^D,jp0OYaY Dl}fV>wơ)9[c2BsZTꀺ9UmΗk DAZK#Qm,{_3=̽`2խ/ r`@ '>wJQ1q;a/XU릖Y] kɧ$IS3ӗ`~MLR'|noϑt7<[mMrYܩ5t]cpquq KnLQz[VnL?rU jP+L\Wc Fc.5:Rmwk] nV=iԳWk ^\h-mZAN,k| 8r~&ajjZ󜍶gJ ϝn4*7٤1J+n[A ú:8p@ .ni8A 9BA17o&3/!oe!&,x6sLX2۾%lUaaf+L_1579nWpKOo 7Zie;-h0z/+| Ěiuq{ছ {[LǼTƜz*ZnZv䌡PHx7EvNص'K0N0`Ɣ&ù^}H1/s 10,D,%@OMA 7bc&23 c䐹vFnlD2 2?:$W⭇*4r#Dx7ȈZ+чzjG99ڏL.p}HZBQfQMMɗ=EZC{v7=M42 ܡv&b#!fך|< HRw3,b3 NyFXb.:=OU-\ JjEȴVHsJs02#نYݘ46T?tdTb\[[Kl9`p/b\$ EMi]ry/–lvbH̪ACôC)39zCQ %0FA^L>? Ƃ`(owBo?2 ?Ld,DԪUk&gk)*s|YTfѻh\k8iC帣J܂ppm/SxQYqQ=/''^ ۞E$ >́Q環֐;ޙ,aԭk0!1#E^10hZbjPHGF4R'sDG~ `3>4zф؎Xܔ>|!lФ,ӸD'jh'G٪̾wOYr42+42:ߦCj0@2(g 6~I,N`E00l4ȋ*yMw#ÉcuRBL^{(+RSlhfF6'/kYȤp PX2sT8lG .&[xu}̡+cH-IQ M!p }T ϣC{Ze Fe)K^}nj!CPA}P.7"+}52ʾ 0,Z29'HN.ehI/Y(u umrddݔy^{ 4kQQ-cȝ `S{Ԋ{TLoyvXsΔ]FP#"8ʨ 9 F?ؚ:[&{T9#&hddFgTMKRrIEG7I'^%x:ġ=wV4[RP߈^Ɍ1kTD2 tIzJ~(b56)3jG$(\Ė fg RQkLU.26\4[+sIZuI1{NCaN ]%7,bR ^*E.ݦ zE_ Eui^^kGzY",|6Uo/tӁ+ wjK&,ArYʻjz\14[P[jqz\I"qkqZ%ʉw n^[׻/ϔ`l"7ȇԧC丘]cl1ޛ)axN=ՈXk8`o]tOuIX1^rFȁÕi=gb*KnX}A'CzNn\U3/i>9ύ( -iomկv瘇 +KC#b\QL!'tY(D$'((pa L -#/OnwXREN1Ö,oWf+u6#2 *@ۂO)ƫc(uDl_ msX4S^q({#wn;"łf^}#%e%?9Yf.c;Ls<}5fAŌ5ald*=g=kj]{)Z[$#Zջcu͵ ".S㮅9 (\yksd0ػ^^U9p )6)Gt6uBΞ:']#$-\R<3)a"a|.o|0ҟbqA0*b*D_I] s)Ԛ:.GGVNŮ^}QM/N u \g0#qKs^;W/^/D";W/]q8s޹{s/{%tWoF /y]|r#w~K.^Ibd,~֓bs" sD 2I)z tuW ) H.x]!զ\f0 O=`r xX:j7?UvrceuD/Rv?s5ٚc~ 2jPIl>խ݅OFNUi5mtkzGhv'Ⱥ'HV7OįsF&Uqrv:SͶZf:=;Ee@ޠq{U}PoVg[fVYj.şji%A}Ŷ=92lG),.cEcRkI7P) :c= }6P}Vj.gvj& 6g4Y'䵱rۮM/tӎ+k|ZereV=ÃԆ5cE1~ЯUYj-ќY@.{MOaٞjf>ՙ< MӛU >p왹fQ;]j3r!Zy% ?_ݪ`NN7$q}ƺA&@ m)ш+t?@;JSʐU @#ڻ07070100000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000b00000000TRAILER!!!B9[ͼ+OpSoQueCT 8 YZ