sssd-tools-2.9.2-1.el8 D>D   HHAACDe(= U]O5M k dշ]Q;G(MTiFg5,Gtl%}ҁ; lP3zUC,#?Rw_[/oV9+&ܜmo]?-H\&2G?2ŖRRЦ÷(:$+B9ERA`\Eu7Gk  uUrS9؈P}tK*AUx>H+T-BNE'sKc0"pF xN9s2_NZ/̂kCh΁b[Ɣ#N bzY&XFHr>\K!ӜG21DpoOpTZ2@au]Ɋ[׾rsgvwJp˕z$%i0 I \„|1$1aC׫z U߉r :frJ5+xWw#= '* :`8)1wmibb97f7e0b2101260d9d904d8c18f30cb527dee9f54526afc49f225f10bfc9ee722e43285ff5f163b47ec268f7524da55eaad51de0302047c435bb500673065023100ce96220f13f1061b56cdfb9a9e4236790f8ac5ef0cc9a43d9a1d00578268b8461b503db3b0d901dbc5242035d2f5dfc4023032577ad0190f2b29ecaa6bd64c1d03b06c5935213555350cef10a0fa5d7c5a828659101456979c1ffa7da10546d6ce680302047c435bb500673065023100ce96220f13f1061b56cdfb9a9e4236790f8ac5ef0cc9a43d9a1d00578268b8461b503db3b0d901dbc5242035d2f5dfc4023032577ad0190f2b29ecaa6bd64c1d03b06c5935213555350cef10a0fa5d7c5a828659101456979c1ffa7da10546d6ce680302047c435bb500673065023100ce96220f13f1061b56cdfb9a9e4236790f8ac5ef0cc9a43d9a1d00578268b8461b503db3b0d901dbc5242035d2f5dfc4023032577ad0190f2b29ecaa6bd64c1d03b06c5935213555350cef10a0fa5d7c5a828659101456979c1ffa7da10546d6ce680302047c435bb500673065023100ce96220f13f1061b56cdfb9a9e4236790f8ac5ef0cc9a43d9a1d00578268b8461b503db3b0d901dbc5242035d2f5dfc4023032577ad0190f2b29ecaa6bd64c1d03b06c5935213555350cef10a0fa5d7c5a828659101456979c1ffa7da10546d6ce680302047c435bb500673065023100ce96220f13f1061b56cdfb9a9e4236790f8ac5ef0cc9a43d9a1d00578268b8461b503db3b0d901dbc5242035d2f5dfc4023032577ad0190f2b29ecaa6bd64c1d03b06c5935213555350cef10a0fa5d7c5a828659101456979c1ffa7da10546d6ce680302047c435bb500673065023100ce96220f13f1061b56cdfb9a9e4236790f8ac5ef0cc9a43d9a1d00578268b8461b503db3b0d901dbc5242035d2f5dfc4023032577ad0190f2b29ecaa6bd64c1d03b06c5935213555350cef10a0fa5d7c5a828659101456979c1ffa7da10546d6ce680302047c435bb500673065023100ce96220f13f1061b56cdfb9a9e4236790f8ac5ef0cc9a43d9a1d00578268b8461b503db3b0d901dbc5242035d2f5dfc4023032577ad0190f2b29ecaa6bd64c1d03b06c5935213555350cef10a0fa5d7c5a828659101456979c1ffa7da10546d6ce680302047c435bb500673065023100ce96220f13f1061b56cdfb9a9e4236790f8ac5ef0cc9a43d9a1d00578268b8461b503db3b0d901dbc5242035d2f5dfc4023032577ad0190f2b29ecaa6bd64c1d03b06c5935213555350cef10a0fa5d7c5a828659101456979c1ffa7da10546d6ce680302047c435bb500673065023100aa4f6f35081b74002ff510577253b43449f378949a26ed0c4efd2721949c9ad4e2333296ada520b3dcb52e02a0d4b2d702300c76b81531b13c7c0ce8a642a505f2684d8e72ba33cc08ab60fde05a08f64e9f540c8e36f35c223facd4d7a9e17ca7b20302047c435bb500673065023100ce96220f13f1061b56cdfb9a9e4236790f8ac5ef0cc9a43d9a1d00578268b8461b503db3b0d901dbc5242035d2f5dfc4023032577ad0190f2b29ecaa6bd64c1d03b06c5935213555350cef10a0fa5d7c5a828659101456979c1ffa7da10546d6ce680302047c435bb50067306502306b330f0fa0e73ddbefdfff4e9e960b3a4de359ce8b8b83ceff75dfc5f221187b42c04755f5e0d289e8f3206fa45af6fe0231008d90fe887124405072bd6133a32ac6a55fdb8ce3d86539f14f79ec10d57d7bff74b71772c58729da33cc39bc5649ea790302047c435bb50067306502306b330f0fa0e73ddbefdfff4e9e960b3a4de359ce8b8b83ceff75dfc5f221187b42c04755f5e0d289e8f3206fa45af6fe0231008d90fe887124405072bd6133a32ac6a55fdb8ce3d86539f14f79ec10d57d7bff74b71772c58729da33cc39bc5649ea790302047c435bb50066306402302a64c382bdb03df1dc6294e621505bb7afd9448e0ddbaf07a52bb0453fbc3d434f317b1844f7bf12a8bee58453d8f78b02307f3506cf3ff91660a6247f98c9e6a1b99b99d60963bbb22f8e33a0fb4ee37e8d504d6009e9401b550a5d907ee461bcb10302047c435bb50066306402302a64c382bdb03df1dc6294e621505bb7afd9448e0ddbaf07a52bb0453fbc3d434f317b1844f7bf12a8bee58453d8f78b02307f3506cf3ff91660a6247f98c9e6a1b99b99d60963bbb22f8e33a0fb4ee37e8d504d6009e9401b550a5d907ee461bcb10302047c435bb50067306502306206ac6257bc7bf122b299656b962e0b00d8a38b6c69901aa058a3aa4f47e602410031ab21a1928e3b62a3a1973155e1023100a357a562f53498e697fbc00c0df412984d26cd03ce70643e49ff72b42439e9e94acb67ca62e7f904bb90ebd4a3395a9d0302047c435bb50067306502306206ac6257bc7bf122b299656b962e0b00d8a38b6c69901aa058a3aa4f47e602410031ab21a1928e3b62a3a1973155e1023100a357a562f53498e697fbc00c0df412984d26cd03ce70643e49ff72b42439e9e94acb67ca62e7f904bb90ebd4a3395a9d0302047c435bb500673065023100c7053588f4454d835310877b501167159fd279039a0a1412bc73746af19437dad49fdccea0fde756651c9922362a32ad02304e406e2feb78db7160ba9440e3f7a75df3496d7df975f7d1b56216c0d47fe15e9185d61feb4964e2c30241f37bf25c8b0302047c435bb500673065023100c7053588f4454d835310877b501167159fd279039a0a1412bc73746af19437dad49fdccea0fde756651c9922362a32ad02304e406e2feb78db7160ba9440e3f7a75df3496d7df975f7d1b56216c0d47fe15e9185d61feb4964e2c30241f37bf25c8b0302047c435bb500683066023100de581abf81c8f39876e0da4f14ae3379fc55cba375ae41e1297e7ea9b7af0c5bc72542fb75510d8773f64f7b170d7ad9023100f4095128b045dec63b73276e00665995dadf03d6c810c136e5e18803fc3caa2698363da093eea95ba73db4c60bfa52e90302047c435bb500683066023100de581abf81c8f39876e0da4f14ae3379fc55cba375ae41e1297e7ea9b7af0c5bc72542fb75510d8773f64f7b170d7ad9023100f4095128b045dec63b73276e00665995dadf03d6c810c136e5e18803fc3caa2698363da093eea95ba73db4c60bfa52e90302047c435bb50067306502305bd74f7f01a0678c7192fdc8f43d688f24003363a4312d75698d8e3744d2fe33ec47b15cdfbcc7f66ed59285decf120c0231009844a5cad707add94ffbe1c42108bc4f1da25351250215349694ca5e6553c7ba0d7c93068018fee2c5ce74052054a0e70302047c435bb50067306502305bd74f7f01a0678c7192fdc8f43d688f24003363a4312d75698d8e3744d2fe33ec47b15cdfbcc7f66ed59285decf120c0231009844a5cad707add94ffbe1c42108bc4f1da25351250215349694ca5e6553c7ba0d7c93068018fee2c5ce74052054a0e70302047c435bb500673065023100ce96220f13f1061b56cdfb9a9e4236790f8ac5ef0cc9a43d9a1d00578268b8461b503db3b0d901dbc5242035d2f5dfc4023032577ad0190f2b29ecaa6bd64c1d03b06c5935213555350cef10a0fa5d7c5a828659101456979c1ffa7da10546d6ce680302047c435bb500673065023100aa4f6f35081b74002ff510577253b43449f378949a26ed0c4efd2721949c9ad4e2333296ada520b3dcb52e02a0d4b2d702300c76b81531b13c7c0ce8a642a505f2684d8e72ba33cc08ab60fde05a08f64e9f540c8e36f35c223facd4d7a9e17ca7b20302047c435bb500673065023100ce96220f13f1061b56cdfb9a9e4236790f8ac5ef0cc9a43d9a1d00578268b8461b503db3b0d901dbc5242035d2f5dfc4023032577ad0190f2b29ecaa6bd64c1d03b06c5935213555350cef10a0fa5d7c5a828659101456979c1ffa7da10546d6ce680302047c435bb50067306502306b330f0fa0e73ddbefdfff4e9e960b3a4de359ce8b8b83ceff75dfc5f221187b42c04755f5e0d289e8f3206fa45af6fe0231008d90fe887124405072bd6133a32ac6a55fdb8ce3d86539f14f79ec10d57d7bff74b71772c58729da33cc39bc5649ea790302047c435bb50067306502306b330f0fa0e73ddbefdfff4e9e960b3a4de359ce8b8b83ceff75dfc5f221187b42c04755f5e0d289e8f3206fa45af6fe0231008d90fe887124405072bd6133a32ac6a55fdb8ce3d86539f14f79ec10d57d7bff74b71772c58729da33cc39bc5649ea790302047c435bb5006730650230281a81e3d5f32be14b4ae136177dfa754859b9f3af9f295da90dedc3bb0fc893debea7f68dc4988855ae2bd861ae4aea023100b56e7670412b7ab09c409782836c7fae0a5fe2c3fb19cf2908898aeeccea70ccfbb47ecc921614f92ed19b9e49a3cc7f0302047c435bb5006730650230281a81e3d5f32be14b4ae136177dfa754859b9f3af9f295da90dedc3bb0fc893debea7f68dc4988855ae2bd861ae4aea023100b56e7670412b7ab09c409782836c7fae0a5fe2c3fb19cf2908898aeeccea70ccfbb47ecc921614f92ed19b9e49a3cc7f0302047c435bb5006730650231008380ff92e8aaa237679784456a41a744731c19c7f79a426ed16101cd0f769e6b42c91f645597949f88737d899cde7cc5023022a957e5749a96fb469ab76fadc1d9228c3f7113923e37bc221fbdcdbd0efd08926534bdd200a2516ef537407ece30120302047c435bb500663064023059d21d719897aa37b6e28474785c099172e331a252a19d8e7dd29b6f9a5a11adf5487efc1f7b1049e1f3fa4002b2558f023070e5bcc6ef0ab4af95bc21f42238d04d5b4f07ca1e2531afd76b57d5c9349fd4d107e89e99ca3d65d0cb31d36c56175b0302047c435bb500673065023100f8dc847a2449320fe8ae3e0ff3c10b7d0c3a9d0944e350c9be42bb8e8277458cf1bb47f44d9b9059e2224f19481e919c023009241611f931d7199bc69d6667e1a4e6ac22bbb02cc75c85a155672690e65310a915bfae42ac0e1e03935f1a3ca315810302047c435bb5006630640230123f24016d5bbe5b2d56830bbed5df91ace2e47aef4e899f399028f1681741f92f93a4272d1b41443e6f3ebed30bdc620230096bdb4c7c983433585737ae94b08d7789547d74555e48189b76ea72de3186bedece65115f42deef2af540f7051d4bbf0302047c435bb500673065023042d8f7c314aa451f5efcc086a17d8a5e54f6db07e53614afee921415f329bdfc1d14351b0fa682d6c83dd7394006b4c6023100f22f72a5f0360e58851545397153614cb35311c1d36bff2ca924fe9bb0c37e0f1f47c252761ac8556b2147ddacd2a57a0302047c435bb50066306402304d1cad10e27f6d9c0b63e76536256b7003d6e97d824e4bcd3839ecc67872387f7e59fda7bbafb1605cb59f7894379e0f023030058d3cbad8fc97f9394cc616f0ee6566781073472e0582302a8e0b73d96671fa79d8f5210cbb6f69d2165503ea04ab0302047c435bb50066306402301e155d123aba18a10fb8514083093ffb13bdfc9dcec6ec0e5f415ccc28dd5b805d97f9ec3a10f2102d5c7f6a37a593fa023059d47f60360fa6fb63a916b1b02fa0e41917915ed7b5bfa3de23c3d4a03cf0051fd33536f69b2e12e67f1caca5c3b7cc0302047c435bb50068306602310090bde7d509ef45df5b2321cfe3e2fbc027852c5730eda00e14489a3b950f40285be08918c1cf7d5c2ce8326d318c1f38023100e0bbfc4c2062185cbdf390fb0e9382248beac2ebd54beee18a50ce2f714c0cc3d0055ee79bbcb089e8ddb844c749c5460302047c435bb500683066023100b2ae0ab637065e4264852accadd90a20fec90cef3859c842a4984357881d2b0799a48f16ac0db367093a44cc2a3fb407023100bd6a4683ba1b1a50254af81abd792ecf083dc2417a7240662fa6ab86626adc39d5765d9ab8da83ce25856fd97033b5830302047c435bb500683066023100d8e5d8dac25f26f616f51e64744b305f7b35b76b71e8cc6687a1ba49979228864abc777b51dac3b2ed3d6d07a36c05d4023100c143975bb83a6775433ddca9ba44c45ae21183db0bd81000de48695888d9757247e0cd46327ff1a7eece4c16d42d8d1e0302047c435bb500673065023100b935181627f2c2a2e60f9cfd10435e1645947303bd590939b5ba1e724e53011e0f88f6710095947fca83a8a78c43ebfa02304f1a9bf10fc61fb29e88ef7c7562a393264c72967306fe221ef888955d421f912d3e9a690f1d5499ac8352dd17a4d43f0302047c435bb500663064023004c378acf1482f5d2b0ad120f36f9f7b951c28eec8d37e753fc5a36b4dc1c7d89e614e8e640b4b251ebf6629e24b9b52023044b74366d4fe23b4b4fae0bf83da83008baf31e248691ebf2bbef744f347000b3cb5fd325d9ebd5c5d912678628184650302047c435bb500673065023100ce96220f13f1061b56cdfb9a9e4236790f8ac5ef0cc9a43d9a1d00578268b8461b503db3b0d901dbc5242035d2f5dfc4023032577ad0190f2b29ecaa6bd64c1d03b06c5935213555350cef10a0fa5d7c5a828659101456979c1ffa7da10546d6ce680302047c435bb500683066023100cac2ea055f5da5809fd28370b1722270ae2498a5209df5b51eacae20d1527dce03cf9c872ba2858319010dc2be29c9da0231009f769864f7bc8ed340df9ea51b7bdfd1568a500278fb1ed27c42a347ea6796d33d1985302e9b9690dd0e36f48f4b53c10302047c435bb500673065023100cf80d5f6cfc313c136b19890f8164989af30fbed711b3fb351a911428edfdca62731925637a8e32f5b71907b2bdc14980230499b0ed4ac361fe5540ffedd5723336a68179dfe236ac501002b76e5eebf44a84400b1851bed79d359e1a8e93fae28610302047c435bb50067306502306c350aa499cde955b0d54f7fc432142721c57e1ec072945b33035c5907fe83f89a05a9af11c7fb492aa4db345ef5fa710231008b0b467f807bcab779e2594c38a5dd9cf389aacbb64df60abe35aa36b4f4ee262c67e2cad96c9298988931797bb05bdb0302047c435bb500663064023022fd72d7b6f28d7681154848b8adcad87ba704339e4505aacc0c025eda8cb830e20722af1055b8db53ca2b55e0a7a42c02305fb69b037ecc50a4c6e69402cc54a543f7e43abd87251a733d1960349669b4e53b9d2aba2cec3058a70d167e1f520c7c0302047c435bb50067306502302f4a42ec6db526d35066de0ffec09da93be51df313ccdb2a406c49489f14d537fd50b982a9b8a2266666f6ec8d4e8040023100f0341d3934c06dd15bf532799debfd27ad5d49b998e7bf7894f4e5335e238273274edcd1a2c70ec6f7bf98796fe855bc0302047c435bb500663064023077bd8ebba9a25ab0dcf0adf919fa758b99058a58fc511b2173bb1763b90fd844517e6ba2126983a014417c8ff3ec335f02304a5640a429018197dccfa9da4d055c6041482638a37cef58091c8dafcb26aaa0cb1fb4d0a4904fcf98800228c3807cd50302047c435bb50068306602310086a4ce4af391a8580bb236280deb76e50e571e579fc134a310e22b78a8c1c9ad78bf1b8d335d84f706d475eeb6a7cc3f023100b8126ec2ae8f7eba3be0b40b3242600e0485e979f545633973b8159bc583530176a0d8cc5c31b25bff6bc3d54013fee80302047c435bb500683066023100e5dbcd05a28d7f8240a4142a80b44cc90e5b62a57ca1bf1ed85e51e53437a5e064bad62f408465e22014aace179aa525023100b6ab53c9f45c981d49c42db66ac37f87b86a757acbcfc1b13476f39c8fde96ba8b3785b6af49f5ea30102399e3b445a60302047c435bb500673065023100d74fd7bc086489e11e463e29b26a1b136bdea767d4f4f5129e44a5e8bdfb33779465b98290b1c84fe729b01b425a395b02307158d43a06665d9d37d7b19bb730bb7dff3f1079af4b2d8e774967343a4ab94e1443024dc1a60fbef56973d0ac3d70ea0302047c435bb5006730650230359116e6067014cd8eeaec984404aede8acc55571ade418ebb2170ee836d044e438d86b01e4441cbb167a84675ef5e5f02310090bd37714d998c5f6e83b64596287f9120e59c90d5fc6f0d54238cc60bbc70bf2165d8414581104092d5a6475e31fb090302047c435bb500673065023100ad1030865d07143bcc791ad7908471eca6ba60298260efc4193b1173d66aa3c66e64d9d41f6f02caf98aba6f8ff8255f02305d3197c7bd0e3e917dcf839c77577c3b20325c29ecc913d839d497cdace3d04b988e3779850d75459813a747eb5d6e7b0302047c435bb500673065023100db36cc9e8648eaa8e815fd392a35a1cb1d5350602a042109c5caf22465e9cc47204258bb670238ff55d3a1082a53620902303bc0b20276fa09b1173682be3ead7a71b71c19ed0916b858328234b5c4d500bbe6ca2bbac708f46565551568e797df0b0302047c435bb500663064023065b1410b84c9b06b542276804f0a7e8892c3b160ce90b62f2cc4c4b96c33e0d0e3d907c89e19e34ba6fab601fab3766e02306ae9391384af5e98da304d787cd3568301886bffc96e77dd11dc9ad72ee967b3ac67d72f949ff11cc9715bad5da9d1c40302047c435bb5006730650231009cc7ab36f344414d569480edb44971eb9d7c634446c2c385bd21a0b560ada068a01f1dc102a1fd3a5da0b71edc7fafe20230635ecd0b4ecdaa9a731ee94f734a732bb255898d84b9c27a908f5a9ae9711b4df04af17dc0ddbd21787e27f8cef0bea70302047c435bb500683066023100b17010aab4dc96f33cee65445ceb1c8f767b174de8d977a0938c686df10b59895354d1c0bd3d1ac66b64aff163763aae02310091cd4018733524f8d9c9b9bb4ee1d88b570c3848b9002b780bd4bc03be8954261b6bd7286ca612388f62f8d05c1c61880302047c435bb500673065023100c26342a91d3ef4935902c9f9341f4dc72d863a41b118c1cbca6604f02386948fb3ddbff2264533faa692b740a8667f3602303c55466b1771e79a01c49c56cc4d2a2f1573875a0623773e8d590064d82843d34e859f8686377f2f6b0e100d32ff20da0302047c435bb500663064023061670bcb2555b4a8571102a6302a150b54fb3f0b9eb039d32620470ff6d9f2a1f869271967b316950132e77cd888a0f10230136b44666714093b9c4eb17e2179afb474745cd80be5488beff95e62a7d13890de602efe23615ad1ff92524076a115780302047c435bb5006630640230294bdbc44891af744c8d989ed9c736117c039d352caabae5fe95c5c19d233edab10ca3d132d352a1a5b0934ab5a209bf02307635fbd56b470c7e11541c19493c0d914cbb8c44c5fd08c6686bd12edc184b776ad17eab4ec669afc71519a72046c9200302047c435bb500683066023100f5efe3a3fbd5bd4548d3825edc0bca4a5d96a861d5b5f1ec739fac1a9f9aabfc66b6e282998f167dcc8e4d40e3be968d023100ef25b474669fbfd099a7016786155e6fcff544fe8ce4630b0f37672c0f52a9672227d68f9ed0b92393f3d913d94a6f360302047c435bb50067306502300576c36d10ca4855df1310e36373c867184bdb9c3a45a0ee5906e8fb208931175f3d6dece73f6cf219c0fc3b09a5e984023100c4c44cd93e12c2c080ce2b1c97aa680cca0446101d3fb3036b21e22fd1f47a69165fae1c5755f01a401b44c385de97ef0302047c435bb50066306402305549f4d0b8d915ac90d0f9597e98b7c3abc4b46ab79dc68dbb9584e1e8a07de7270c8e74fb12f94713b104f5504ce1c9023008c2f9569b8d595cc3e7648584c51817d84a63875ed8f6edbd614ea4087791acf8a354ab32c798494e92e4bef4a46d270302047c435bb500673065023100e57bc5eb3754ce8bc2bcba52d826de3edf9902cdb1db96b44c0ca41023ebd64642bfd0f2049d2f9fe973c24468a0ff650230608c081cf6756d7ca5bdd70619978451b7c93c3cc79d8be1cb8366855cbda177b325df547a99d52de573149d414410c40302047c435bb5006630640230150590b9c157dae78100f070755e67db0b76762cefa4e1c8f0c54d387af99d4c8af8a844044816d18b1a43b0c3f0a02b02305a28c8964242511f3f3067aa52ee8bf91abb7f662618b656a00d12d89b704634484e4f54bb2d69c8126dc151fe21dca10302047c435bb500683066023100d76f66e708b6a08d95d49e1b1c4706faa5139ac7bd54cc5e3284e4a636b15d7c8cb2630de85947e5a7218c204e549bc0023100fa31d64499f4513e346805d912ee48a3472db3fa96ed65b109566e0aef11087a88e17945d4d20e87484c089c5f42cfcc0302047c435bb500683066023100c103a2e62e6b0d182e21aa82406a6d344ba42b2432cc198e0a70a9f6019f0cbc2d070c2490cbfc825a0ed88e00123a7d023100af2fdb2769933158e493b1ea832b9cbba2b8a97c6a8af33eceeeb1e8a3ba04c816c18cd8a808547cd7200416282628970302047c435bb500683066023100f743d517e38abdfbd0ca4d8fd2c8f064ba916eae2cb1c2f789d8ba0d483c9952bcc3ee079d1fb4e23d7d5172fe78de1002310091604de4f57437bbada22edf6273d78bcecfe143d7744c05cd378e9cc03250311354076ffe66e41652ecbda51eedf8b00302047c435bb5006730650230675b08322764f1b4f0bca81ac241fd551f8198bff1eb949a85145b543d82affa3b4d10966d8744e416b7c6a2b76cb39e023100962a1e27dd6dcd3aec37a905198021c16a332422201637afcdebbadff6c2a75dca7a078862130486482753c46432ed370302047c435bb500683066023100ee986a81a5b6945386de9dcbbd1c11411ffacb958c7cabefc143e67fd49a3e648aef3bc62fe39f27adcbaafb0e1086930231008f5595a5fbfd246a360cfa69f1afd135430a75f0b3b02c6ed291014c78c870f3e89de2c77c272bced9846d41705669720302047c435bb5006730650230577aca1091047f796cc374eee38facd1d5b43ab27ae14aa99d05b1f46624285e7597fb5b574f3e92c9040b81e32f7fdb023100e894ffd5457d6e06e63936c5bc4bec3561b250ce06142e0f5b77cf301d2d402d1b8700d4f5e148e1e3c09d7c45c3e9a30302047c435bb50067306502302441854b5be674d3d9c920ea795e882ad24375400f17c4fc22fe90da4b69c163b01ef9ac5bab47d3be7ca1eec0a5d572023100e5adcdb6333539a7b6e44cddeb55d64ae2f6a8ba9f1a2bb7594b2045f085b6c38609d3534044d20a755442245d50db7dPe(= U]#}3EA"TɤN[3:%%D(j`? Fr&m`'9TB'O]`Tݣs[_mp\Wdy5:ۙ~$E{5 4۷VK@6C2? c@3Abu]E::+?I8m}ܣE1sD9õQg#R+$c3-uimQI0w\3^1nK^3@om$ CAګ$XJj\"vjq*t왆u &\E!ڃJ{+6|2.ˍ% FW| k4ѫn.|X"Aچl)nz 4qcw}fȊ S< ^  ή\z[;￀~Z& s凉B4eưCJ 永/Q^0g#{]4]hZLTB\ n:p??d   ?X\ H H H ,H LH H 8HXHH(DHd:l:!7:(!8!9(:{6GHHHI8HXY\H]H^bdefltHu Hv,wHxHy  $.04:|Csssd-tools2.9.21.el8Userspace tools for use with the SSSDProvides several administrative tools: * sss_debuglevel to change the debug level on the fly * sss_seed which pre-creates a user entry for use in kickstarts * sss_obfuscate for generating an obfuscated LDAP password * sssctl -- an sssd status and control utilitydppc64le-01.stream.rdu2.redhat.comBMCentOSCentOSGPLv3+builder@centos.orgApplications/Systemhttps://github.com/SSSD/sssdlinuxppc64le!qq R R // [ [qq!!*x 1 TxhKx#ZHs7 HM p .a# AAAAA큤A큤A큤A큤A큤dddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddde3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b8555c5306e74d3a5df3689a742d7cbaf2723ad50ddec0e5f079ce0dfa791adcbadb5c5306e74d3a5df3689a742d7cbaf2723ad50ddec0e5f079ce0dfa791adcbadb23b25371b36904fff3d9d192ad1a1e423c461999490ad0797eca17a88d77309123b25371b36904fff3d9d192ad1a1e423c461999490ad0797eca17a88d7730919c95928424e62daf513fd10d26cbb8de3226270a94501ce6786d9025ba2d9a8f9c95928424e62daf513fd10d26cbb8de3226270a94501ce6786d9025ba2d9a8f28b86bcdd0fb47727ecd5ea55a2d90bf18f0f5c8775bbf2c38ddd52dc004936628b86bcdd0fb47727ecd5ea55a2d90bf18f0f5c8775bbf2c38ddd52dc004936601d413c5d408ecdba8d399515b021a353463c3dc19f5f63828ae23568a108ea901d413c5d408ecdba8d399515b021a353463c3dc19f5f63828ae23568a108ea96bb64c2938ba15e9dd1b4acba8105ee3973e1e17ff85d79d99e70bf2df38a01d6bb64c2938ba15e9dd1b4acba8105ee3973e1e17ff85d79d99e70bf2df38a01de3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b8555c5306e74d3a5df3689a742d7cbaf2723ad50ddec0e5f079ce0dfa791adcbadb5c5306e74d3a5df3689a742d7cbaf2723ad50ddec0e5f079ce0dfa791adcbadb9afce05afb4f9730029ce1b8af0dfd47863784fb8d59b26009dfd867ef5c649b9afce05afb4f9730029ce1b8af0dfd47863784fb8d59b26009dfd867ef5c649bd1527388b4619d2ebc0752c41a9c645235fb3c58b5eb3e82b4c1f751c36ff3fd8bbf3f6402f93ebd7673626798f8bfb9263532407907cb8f3d2bcc86bbba34a78170cd384dc74518bc7318764855a7a30e67ee8c7e11d5d21fc49f762105e67ed82122c936ec008f153b2f9fb52e2e491296fff87eea33f7538a1e561652b279c2213728d475326b657d1479e9bf46dae662c192eb6bb98917cf92cd0073588ee53c3f06b33c90ebc6539c459ec8a21fd0dc92bdbffa1544e7c37c8daaf53ae6320fa35fbc4badcc77d42d6487887dd9200191ea438f9835be7aad014bb2ea969c816bdbb3d6e375a19c3e64afc9ff0efe82bab45c37d24282d76ec0d052d60c328e635bedea0a04ca0cdbd14cf68ca2b34a0c96b603f2e9b1bb732ffd4deb5bf47bd88f55443c2ee9b5aad198614ea4acaff1e78b9199cab1fd5f3cc1c15567013a3cf6651e3d3939163e27cc40e33a3c78d47772404d24ff2c9e9604d0ac65560796ba459a51c27965459d015fa577509e5f40c925f5a0dae1a61291d5cf9e8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9034d2d4623f0de243d95246af902ae18d30f7d94a8bd4e5b01504c54228de1357e73cdc0705e0d95ea5df89660a4b0f42407c5c3ebd16b7ae78b1a76adb79b9d460694274386f6bfff63c06d8b1ef60a5dd99a898e533752ec94f1b0ef37a3658597252cc728294cc2f08b94356e7f1d43b0e3326f316c687c2213128564464f9153c5fe7b9bcdb90396bb2d4c423cc3de6d2c7981117f904de37eb6913a851c36eca2ceefc627b60f1de7fc41be65d0e6e097815bb8750b723e24766c3bf8b91a5f08b920312a4ae099a287c4d32384853389696cbbeb1bb30fcb19ad2c5842977b2265b30fddf19af420750b306da40cdb24da375d7fffde01099e58ae1bb86eefa43e93b2fc73f2da79435bac1517e4a21a1d0e395c78af750db7a9c704e70dd2f40a611e41fb4e295738d4223aa6e48da21fe0ce424f4daeff9cf0e4e77ca4f524adef4d3491a9ce83ffde68194e699e77d527960855fddb3b5e6aed5b5d7a257c7a1f84d2aad66673402c23bf25e5c9f05ade434c48299fed1c5f9d565aea19cc406cfd413e4ed6a8bdf7534f41e67b59e68c3e2b56753fe5fb92a1311eb54d7f58757c790deb4ed23318bfe49df79c7ad6f591187a3ac804d50d759b20e170022db35030dc6dc39bfbe991ac31c8863c89a8ff57ad3851ad6855bb40439dedc50b37974f39557d895cd7a164ba29cd39f6e452742ab4a49e77ee243abc0148fabb2539131c5a333477cd6ff24726169bcc65a231315906fb707a978773e4fdf86ed671d4014e76e4754b74b659ede5f4b953a046e5d8460f9540e3fe16e83ecc851e9e77455f1a026b7c6f19ad9acc238547a32ce3f276a98101886adbf5258c8d9aca9488ff6a72f5921951f2f05f5310b86a0470c0ca116a35c19ed29c9ea5b2c1cdf2e182660d631e11fc09f92329a273176c4d12830febdd647c092653b4e3d7cbdd30a59d15322444fc8bb60d6657b80c30f9180d81ddded1d82460fc342e8f973482ba72e62b8392f52d3898c16a50602f48403c981dd32148ad0ce2ab663a5d8f8d00f90e0d1c89d671afae904bbb3c01686b717ce7a1a09b4372894fceec61b2eeafa85cb28190f578e88bdc96cca5272a51bfbd2ebfe00fc43f41332f317ec0d7a020a8b0453e96adb4b5c4047ceedf3d44b463b239c0f7f46c509171e5f0d1fae371abf7a5fdd74a4ec85e5c72425d991ec3f4ce87254253fa9ed6c06679e792b3a067fb1fca477cfdfa2078ce26d67a15c1726d7ac2eedfb04cb757ec07e2a0c8626a0f999458e04d117b113583ac58d39a2ed052e7410f5a../../../../usr/sbin/sss_override../../../../usr/sbin/sssctl../../../../usr/sbin/sss_seedrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.2-1.el8.src.rpmsssd-toolssssd-tools(ppc-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@     @/bin/sh/usr/libexec/platform-pythonlibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.27)(64bit)libcollection.so.4()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libifp_iface_sync.so()(64bit)libini_config.so.5()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpam.so.0()(64bit)libpam.so.0(LIBPAM_1.0)(64bit)libpam_misc.so.0()(64bit)libpam_misc.so.0(LIBPAM_MISC_1.0)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)libref_array.so.1(REF_ARRAY_0.1.1)(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_certmaplibsss_certmap.so.0()(64bit)libsss_certmap.so.0(SSS_CERTMAP_0.0)(64bit)libsss_certmap.so.0(SSS_CERTMAP_0.1)(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_iface_sync.so()(64bit)libsss_sbus.so()(64bit)libsss_sbus_sync.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libunistring.so.2()(64bit)python(abi)python3-ssspython3-sssdconfigpython3-systemdrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PartialHardlinkSets)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-common2.9.2-1.el83.62.9.2-1.el82.9.2-1.el83.0.4-14.6.0-14.0.4-14.0-15.2-12.9.2-1.el84.14.3d@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHcacadedeesesfrfrjarururururusvsvsvsvsvukukukukuk2.9.2-1.el82.9.2-1.el8  .build-id349cc0604f39dc4bed182cc108b2a7ab82956a4a644273dcb7e9b13d935bd3756eaa507ff3ca0066bcfdf0d68c13bfc70215f392c25a3d391d85adb4sssd__init__.py__pycache____init__.cpython-36.opt-1.pyc__init__.cpython-36.pycparser.cpython-36.opt-1.pycparser.cpython-36.pycsource_files.cpython-36.opt-1.pycsource_files.cpython-36.pycsource_journald.cpython-36.opt-1.pycsource_journald.cpython-36.pycsource_reader.cpython-36.opt-1.pycsource_reader.cpython-36.pycsss_analyze.cpython-36.opt-1.pycsss_analyze.cpython-36.pycmodules__init__.py__pycache____init__.cpython-36.opt-1.pyc__init__.cpython-36.pycrequest.cpython-36.opt-1.pycrequest.cpython-36.pycrequest.pyparser.pysource_files.pysource_journald.pysource_reader.pysss_analyze.pysss_analyzesss_debuglevelsss_obfuscatesss_overridesss_seedsssctlsssd-toolsCOPYINGsss_obfuscate.8.gzsss_seed.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_obfuscate.8.gzsss_debuglevel.8.gzsss_obfuscate.8.gzsss_override.8.gzsss_seed.8.gzsssctl.8.gzsss_debuglevel.8.gzsss_obfuscate.8.gzsss_override.8.gzsss_seed.8.gzsssctl.8.gzsss_debuglevel.8.gzsss_obfuscate.8.gzsss_override.8.gzsss_seed.8.gzsssctl.8.gzsss_debuglevel.8.gzsss_obfuscate.8.gzsss_override.8.gzsss_seed.8.gzsssctl.8.gz/usr/lib//usr/lib/.build-id//usr/lib/.build-id/34//usr/lib/.build-id/64//usr/lib/.build-id/bc//usr/lib/python3.6/site-packages//usr/lib/python3.6/site-packages/sssd//usr/lib/python3.6/site-packages/sssd/__pycache__//usr/lib/python3.6/site-packages/sssd/modules//usr/lib/python3.6/site-packages/sssd/modules/__pycache__//usr/libexec/sssd//usr/sbin//usr/share/licenses//usr/share/licenses/sssd-tools//usr/share/man/ca/man8//usr/share/man/de/man8//usr/share/man/es/man8//usr/share/man/fr/man8//usr/share/man/ja/man8//usr/share/man/man8//usr/share/man/ru/man8//usr/share/man/sv/man8//usr/share/man/uk/man8/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mcpu=power8 -mtune=power8 -funwind-tables -fstack-clash-protectioncpioxz2ppc64le-redhat-linux-gnu directoryemptypython 3.6 byte-compiledPython script, ASCII text executablePOSIX shell script, ASCII text executableELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, for GNU/Linux 3.10.0, BuildID[sha1]=349cc0604f39dc4bed182cc108b2a7ab82956a4a, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, for GNU/Linux 3.10.0, BuildID[sha1]=bcfdf0d68c13bfc70215f392c25a3d391d85adb4, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, for GNU/Linux 3.10.0, BuildID[sha1]=644273dcb7e9b13d935bd3756eaa507ff3ca0066, strippedASCII texttroff or preprocessor input, UTF-8 Unicode text (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix) 7S-R/R/R/R/R/R/R/R/R/R/R/R/R/R/R/R/R/R/R/R/R/R/R/R/RRRRRR+RR(RRRRRR,R.RRRRRRR"R!RR#R-R*R R)RR7RRR+RR(RRRRRR,R.RRRRRRR"R!RR#R-R*R R)RR7RRR R RR RRRR+RRR(RRRRR,RRRRRRR"R!R#R)RRR RRR R$R&R%R R-R'R.R*RRR7sssd-dbusutf-83f922cf4ac400fe5e76860377febdc4f82ef4f648e53045d795dd25026542c0a?7zXZ !#,䞓] b2u jӫ`(y/>(8I ekBꝑiV*Z^O2fU+Q\~ f~~iM(Lsl. FubT@3;ĕ'tpj0Q' mMrC--:>^CR>!lrq2*T4)1ؓJ;ִ8Bh:[mUn{MukPq dO{ (`spPFЊ+tE;F>+3iГdCD/~,R4#өyiV<.]Ybuxzp`I¥$!)wMд(ا6T$< \+^ѶAG3+ V)~*Rq$,`F剛0jPj+¼e͹|ӍUzaܛ}:R>)'x FDEIOuwJO`;I-QL0gSܚ!簉.%aZ)ڑ6KԔ +#^CGS | 8=ie/a#Z}~ի48 )poBzKuǽhH,4iY2m31KZ gB*Ȃw^u- hvGiB~mF]%PS=i&}\e.˵27ł e_k\4̜>$* x˺7sl6Ie{tXIM|ܞl4:'Yez'$o{.|)>FBUW@Wy vd'?]RUɟZ!2!Rs@Z)`bB7Mtg('JF|כFqXU yR] i8xYS}ln$T5)7?t|Vmx^TÉ6 a4wvj?]ŤXn"[y#3eQZ6\_\S`s +բ L WjTYPE^Ҥ)-0g7:*2~%V9/'{eS&'Fd v,Q7+'|$P}UjRv* UJ/L,x2^3(t,eDFepE7U 6ujm^=(m&%(AoSnh1FNH瀗:"kjb\Mҟ o;grFObƁ ,&J\vOb}t䪹)R+/Rl95wN;u]iw9_XeůBꌁ ?+$!:[pQ4 Ǯ"ERG^\Qy-%Ͽ8NA872&)Y-\3T ]5 pwg9#Ыu#@R^ 6ʳt|0kI$z86}8Ow$Ad>kYr WoG~M=[1UbsGƃ8vm_+A &Hf5W B겮)PTӞ9ѣlàpiq$+:dH`{~E,3I|n]OXRk.]#ke7!5+c~*AŔx9mC!-5CAEpջ((Z]`Nݎk081(_mv 5 uvdtmmYLW*r˜AAlE]$j .ǫ T=wnPa6ˋ|Ѣ,EvʉOZ$EUt\džw.)^e>5c\>OX֦IN<"7{q(+ q_"wFȊ6@(Uug`U5b1PnͲ`v1e#w2yѕyxby[08sгpӁ$ii@u笁XgWJ{nW样N#"gG:ՕŧW;f& &KTux$'90șe*> s0q *|ž>x!Ѵ>B%4O "H9eEk$>gnOtľhpsK G ..K,'=c %9D[н-uRD\*ArsBOᇦhV ӛ]&^A^Q R|1ěu1R<8ra*tkR{0쇾U٠,C̑&f,g( 6JaXo@ZlaC^lL!( h +01-[„oj FH횏[[ݎn ;v gˠ z7`JA-D#6p-o\1 0Yƞ K6P(p=`_1ͫmi)0yц@1zd/NZ۳?cK0Jztxه+kUÝ()\޹XQzMp*,"]߁[{NB|ew9JǠ80WN R8#N O*N:O2*d$5`U|ԛ5G˗ kncyIFFq"s9a"4~-ܽLy +k"a3 fz o+ojE|!GN5:Y9κ~>-:r=x554X# (j i~Tk4(<„dF(t" bm>Aq-_pӕČK7l'X<.;s*(.>11Kdt@e.y*F ޗ?h =fyn>#E* ~WZ EXi&h^Nm!7,V\6m**&3}F:N9B_rer \,/tqW;REݤ_` 28'DM&UlE!WnTUA!+(72u q|.J!GnXQL&E<<VVh4#;Њ@ /U A} ,4F޹>75+fN\+I]!^Ɋ DbQ ĉ7Jmv\ѝ=a+~N߰)F]dO4̘\;=_K: dSQ.JZ>I?Z[V\Pm%\M _wJ+8e!*Nf㵬~< IELSxv=|#0ہ:a3xÅX'.{` q޵R@0*p_Q\Mw0`8pCzHJFnYqWn &W99kmM[|@y3dG]˖R]q 푪.CfK??>&6h:b"-IuD"aF18d9I *'~,#awqF8%cxhh<,ACG ˼~|gFGjw[3 #BG>1|kx}Qs֒W7ˏ ` G2UI:U)p;`-C(Զϧ_qlR:jyO`K 63eا_m (;Aj9`=9]g>aFrUS2xf#'4[pgGHʟ)k*49eLQ=$k6sʵs\'8-o\=8?mr`WHP8G>:Nfef0>&X_ڔQ <Ў==e6 Lm+m&h۝mz nlHYM\>>S bˢ s J%/[c-v .מ&oӭ=T35|oLx' be4B<.ڽ_i$p줗ߵ}t8K j<@dk͎cAo9XjmXm tL}61.P58tESF lN*4pƲVo]n$4XVU$ Yp[™ꄾsyhX۴ZsjDUPH1` l<%^^#:Itr/__~R W$5n># Wkw=T'.['q)âK wmFal eվ@ݨ&!]FW6D{'tiغv7IYS%k~+vc˙\97GOz7Q*BԚkY]* T9ǗFdٶpwt>[?Ak\חuO̤N3lǓrU dqc+Q+~>%cA(P6#gT٢HRHoO&l~ hF & ;Ŵ^ݢ23"Nm)xqYn(F;6mGtJrծIYp%7̛:*;d6, æB6 ZM6zǙP4`啃ޭth!92HZ`O }'nG*ֹ?v>yʦHM%(ѷUKԏMQ$-5TN)fORٍ!w7Ӹ,p4$nX!js"M.諆/HH0C::oߑd̑?+g=}µۯѷ/]\gM'_7%var s+A;ޔ *zN1b+qѭI!}\ƈ  "!ӋN*5<6wxN4Џy7Pd^+rƆ.(<>gLF*LaOI Zue'0GsRho8(]3?&PAV򫫒TYoBjq [GSWјChN踵-jA8W _yQ,+=!PI N8OˌK<|j4,R q%Ý)T%HS w ͋Rqv>7m>:.WRFFCm5ާG[Έ)l=8& ;p"["e*#ƩġdLu+4!&WǿUͻFHbgnR/nK}Ά*gXMPi dCǚ$mZnPUJQ:2ʗ3M?V3mxƉ26PMuCȜ>zaB2sXj4zAKl_K}dd/I%k7:e1"oCc p-JP}/@]ρP0)_a_OEl7gXc_wm&5sVإPȈ_O8c}풻7,(+2g'\ɞA5؆xbosi-psD4/%v{9z/AG-Fj-;e] $q-4bMwxoA@wK:M]jؤy4еHZlEX(kX}DofűԻq]WӹFKX*nGq)KJ3bh5aʇ9arW*Bêx6q\Fn #B6mIDgſ J7<|$o3s20aqŒ~/:woPI*Q]N MQ QI&zc(Onef/M93tMB_hAr_+)JXpTa6A"(kK* M0]T''qfcw{ʬqaIЦ V4L6K}:'lUӺ   y'?k-bن>-EdH:iL/e@H'F:fÞ/`ass-c' 1pXԛ{AwNHK$7ͣ0pŞ'הv܎_&n6…'(Isj@ZgB9`A(.r)u^[X?]BE%LWL6* mlk{zqdG1R>-철Fz)e%IZ(Ly#UsoRa:v o‚;l缴eJ'_Kh?tyʺ'żù >JM4rhpۘr\)HI#D ڨ2_[c|EH#*egӐUfʇD%4vYA7sڽ?1A&XiI}d@I?cf6ĕaX|!64=Be~xDF/01e⢨?amy`t\FJ= *􁕚Λ% D{)`vWFyw\tN/~}>`!S8l+6pSXHlDкLkbu 1Ja1La[r1RryZ "Tl1pG`)= W@vCi9as:$˃"0) 4h<V\X KL8PXC)YFiQmh/a*4^d;p;ϺvBNѸ0 4 FPBPJhҸl ~txd J<K znⰧpUp 7:QYˋ^Gݭ u(wYH mxh9E/s -N rp]F*@GcZ kA(ocYkW)u=#W :5Ǧ-\ݨO&LR,Vȗ!i:}Anw;;J xVZ<`yXq!JWr ~ќ2o.PlB z}P=K4ᄴh_ ŘN=jEBX;9Ns&<=e뤥,ҞY6.%_LIZ18pEaMmo VMvJ7f8ӹiNŹY2ieh-Xrmʖhc.="[TbA^qQ#Ah@dͅ{ Q(0 Kf F> 1yɣ~/Io5wI8g1x[qv?0T?xxbGUE)5NCohXz-]~RG~-N})y,.0V${ ո''9ۈKpHg~Ӕ,TO^?3I Q^e~.)ְ:lMq۪;B@G\$02K;x х}M4=!(I>-渚/_{ژwBMաiR$Ѹ^+mA=tӳ.bz{OuJΫhͿ\Xboᤛ@yX]`kypCbVr"38 bo9|';!e+C`nf\O 96G٦>\gP;ż\۩rjֶl&=1Wn摰׬7bY6jRL YP2sN<[GeIkKi[}8rWnq{b!b n6Jg4juLm.U?7^yr)u+ȒWqpjսzp,="-m<:rumR 8f4m/ER31 S4>>I܍yTpי-lշ"5:c_/cz!.|yEGʔv]@֌¸"M )ZHx'd Wi,5p%(>]8WO}r'7 /Z4?L=K: l#Qel,y @W@p&Cٓ]`T~B<zv!Yvŏopۏ˘7(@wp9S_޴_;Iyvwm3nCۏ'c,~Hiݤ78lү3N郈$৏οlHU)),:4uWJȶ3B> w{-RCq,}~w5_X[dd:cIГ=*ld /Vk| pJ&s[unNdEN/}}mϣ=騘70h3S~]֧WddG*+O` >ϐAǐZ3(MoS9V{\Aчe&A;ZiةL_?%Jyl ;PI#Ϋ(p{..VMg 8jT@DWyaհV_bYCBd14>-:C|^юƢύ:G\};sUHe l2Z19 eci"l" 8TtMꓓ7?t^,뙺R687hNXH^O15(7!sdG[ir.M&vj4O44KJ߲`yayioG̞k턩~ %|F]j3n޻_Z[idcIr\4,L4Č=;` xg'BtR27J]c\(3"nclґy\)N sfǪL ?ŀ%E*t⿆>eNtV]2 z4ME4ʹ_Ϲ/O`&n-N:yş.L֧gҎsxo-nW7E4;$1@t5 YASY|D-"w ɝ4a/Bg"QU1:iWv-F ""F w]%aàE5YD_`EΙ>^Rw&NHaey[z<:LH=Yr`+_5 rJ! .?΍zeƦHCLЦgswp p,3 BM)Yg(u-MHm,EuC̲GI6ȟ0: $#A;# :C`acʑ K~T,ے9nt '%?r\e8-۶5I.|# ߌD\ک f2ia#AVz-syX [{,llno,Ui8,je5^ya?) ^:^sl;vXhAդu kIڵ!Tu:܆j Jt~ԣE=Ɨ!c4 , ˱~g鑳F^u r10BK"p>[hhRͨ3MU#׊Zr$EF .S^QZAÀCQ‘ISܷ.!-Cиs0㌛[3%|G.9PgwjW+nR׮_q@%Fd h'wEW%\os9^aZbT.Fi' "CYA9.˽j4I b0p޺0HB?8xy0 cvsbt29 ۹{i{{0__ڽ|j2#OYeWPg^8#&@g&4bڰ韃*;hX-k7KA ɳ=K:&i)+}E. @V`(V/A:xy}q>*E#/  m13 透 |*Ch+SkmB48?Z㕏b% 7~څ cxɞO+)-_r ÂCN[bP¥˸ S=D9/ TvtWߙ;(ەx (BDs 沾Vkv?;~rn#чR^kOoLylh.=+ vz!֗K_= waO ' ak=LSnfx;}-sanS~4 w @N(ʆ"5&CQ^qi3hOψRb,.CnZ9&mݜF4牂2= 0 =zTc\'5-l4bk/ae;g^>RG5k(X>i#93'V+C7aL9% 5|6I[륩*D(Y&?O^8͔*nVs"ڳdLz1HǓA%0s2y=ձfDѐ6d^[17?(y:Ob0-)PQQl<]"濲6$&OvlL"N@rdVk2"+;Ja (DJa]{`UyUۭQ`Jƶ\EȀV7NmUw+<^/!wd 2ڥ~ڌ@/K* Û@PړUĠ@QZZo=p+3Btq;XZuEҜFf͗=EQ^杖 !? 0Mۮ$m Ta|6̝&Ά5m; N?qr~>#"鑍=P/c"Pɓ;ʻO?u˟lɐ yb[cގ0gε7n >?Q/D9}P[0ٱsҊxo~bR٬o\QNJf2m/\}x^tiEgdvK)2D)L1() "=yЂRƣ`<3]秒vl;'/cpҖİ6xWU¥^!5ճ_`7#}lTg: bf|N%A픓^% PiEݶvWs 8F L>?US̕1I&xu78_{;4WyEc4q*KåYDs>G N2Ypqky9f:mi?6;5QaCO{pU;\Сy=,]G ȱyNvVueseטl84O Œ\arOT{ `#}-wT+F7XKYb-&LJH6f2 BBq$S2X-=D3+!9+L=J5-:yYa}:kb}ZxFa+HU'F hZ4zYf줮:9Ev#?M nYXy/.ʭdAw/E!ýTIR +!4,G bq\oNq8r(2C]u@Z Oh! Tp'!h&G%Q\1jsr-*Cv;'ް85@Fl\iD)B7krfI_^ki\b/Z%pa}A=8bA=fa긤*k^^IߋPLt7^sv;1~%%0[G]X ! v ,+Ir'Q0U"h& ,5WVNqJyt g8ԎE$ tI?8+LHs駽̾=n";*Qa:\^T2Ro9b_1FTvrK )A.1450)t yI-W9.m4fR%hv!(hN77@'f ҅XhŽ+JL:49MIUgvD:ҋϲyE.|d J";اxW]2-'"R tPL^cs+&k^O.)*Cظmv!HFS@IlIrE{'}KkogX%aqJ駪nK^eZhDA.E XbHRUVv|Vlɞ * [uf: ~I7m`[ D(K._/PSΊe6 +%q9×I/7NT0KyoZ~.t=Fm!MWj[o|Y~]o\Fp#PXgCv$5 ^hUAgrǁ1I>#|8K:'?ފ" @Hx+)qvHx},\ x+m=@<]iK|~4Uݬ="E=Kzͥ+k627mgq0[Kƨ#q#޲e.?V8mU;:PO|p!k0R>`1;x WՒ|_DGS ϥ GAlnXv啌Pb9!FD>[ X<@hB 0~p3ZʏfM+TNAtHx|5f)T].e'ps&X 5|e(C?zEQAșj~5%7kYg8딻†zX$ɾ[JkKRl2HXn;cp_y0"N*=B&2FKRsXs=*9ʽ̒E{obe9p̀1淶B2KJ8_4\ww/e5y8GF܀mmEjULXN.B֖9 Jņ8"T<0@N, f5 =.O~i{bpLkz19$yEv MDɛ/nU:$8M<0U¤EdjmÛFynBpRrb)==6У xj;CLzQzl[)ue*؋swx7+p+woXDDN+HĨ2C~:@~X?eZ7G?U8v;  lL(Ggkg{!.,Vp77]63$]M0urd'rS,>_nRōӾ:b Z߳/9w-z0m?+zNtnB?j{1#QŌCHF^R[Ly& -,z4v6o_|Q@h)IB$և,Pch: 9Hfm>/9;sP=C~N^Fd$~T?Aݩ04@y~OpqfXQyX!;("MTn;+9&(GVMs`z"z–~p`7ギl8y&.C튇^Sz߱aܲڒ`C i dEsͲӲv\aX [kPE-rOP}lAܥ,SWVs2\~g-sfqw 0rH&GGn1% nk>{/|͸f-QpYQ%3~z6wd+䲦# 3a`tLYγ5,E:24]G%˗;-zrhG载k_lIp 6dk*E/rݿ"LWM*q*/Xe y=?pTǘ#@RꍥJymc.+`(!dα,s]iRh[&:՗)mk6b7ΈRGNۇoId% `SVy~4l,TW|5_b@OwL/ ]fVC!,:jOiLQ0_8N@d_ 7i1 Iϣb8ɜG&ԛϴ>/XE,J}?lu˱Ĥ2lZ~?-G }BSrM>feߏ(:TBQbPfpv%Qv xUJ^o|;eɬU^LOܻ^(?y l&._ثmz5:NJg֫d[9Ǎ~ RMP[KJdJgk ,eq^?` #*EB(zee{崗m2(9c+sR(4eF *CkuOra``Ul;qb=gt8/\ YO I]<o)!&_\hOu W"!3r%^ @UA~:>!1gуfÿbBk+My z=`W _|L dpVbL#=@^)WZzpaA 귙`RfHLj o@~: " SP9TX J:O?lC8n?7֢)bX:| {-t*$OEZ~hd{iɯ%ؐf+xnKm}QU0H`FMؾ=Q;bJFXBAku٘Tb9)JkUJ >Rɿ,$%L,nOYVx9a+%ܣ_şid×TM`﫥>Z0T /)Xgl=KZ_R1E\Ɇkjz-G e#>TkCDA43_bײTD|8ϑkIh8g>XOJOZNsS2^!UDV3@$in|40a^7e[k$|{Fz֤Sl\ f4|լdn@r?% `("2÷L ŽXP@w -٥CϢ18ˢڅajoySE]w ^mFWH0u KrD?+[th~#xQw-muU8,)@3 f7?y.{%  rW|72ǎnZ-;UcS %H_KG&İZo5Et:ׂJj:_CxYX&LN]l$:ŤٯGru&Lb 8x0H|5X }^|wb1*qB# u+\Fŗp!N. d9ZH*fW6^wd - M4hlro:-7eN(&H?7J48cluOX8 ,tbh@u L۹^`64ˬɔڭ'~؋w}%ѵQ.S5]YlX5CE;jU^ #c"B{'{?국=GII&<0,,POcwe˱4*.}_cR1+r߉ ]#!>dK_ jd o&gv@U6CX_A*N{3s S%-IY4JEI>e PFLXHߡ(M|x%x)24 ]/gM"+(. G0M/ |6. ʈ X JWJʤ6ՙ'lm% "Q\f7Qp߽WWߥ@y<6b\n،$/Rby3j$mܴB`YT_V)Ov^Xa{2Lw"HI5'ACđ)=oCg- iI>L1FYU4f\+nXuAr!K{'숮,SwNV-0g7ӊ+W_z( "^*xhfB{M7_%ld%ӔJnj0,'^L,9P8m0b5Ty^x#ӱPo!>ݮy Oܮ20/{َfR rtd`Ҥ\$PQy đ z[}zU1B<b h.L=#^JP6L5Cd& 0:4J s!JONW;\]ḋ>v6IaM b.| èp >-OXC 梋όdQ6$HL,Us)n_soĀ +HZxx-CT a737(V׫h`}yV̨X3`wQ!'ݿ~4"'gG2W<Qs ᩼DQ}u1s^cT$ H=~nKXq!4t.u'֍k_ϙMAKw6i}ϒKD"V˕pw^`-ޭGGDά瀻(ʾy7Z4x32sGjNgZ0 ȌeS 3rriUۯH:r)[ĵ@"gTd9O !lB/e [DKH&ȋD0,a1/"trYMݝW-,+@.*Ny˧gdOsFNH##].Pؔ*'j"S}q8o#'btԨq&85>_(egK55ɚDIuӧT2 _i`j~VC70C\*]-u@iơfSyil,^\L][;U0Lz 1/yqA{W;7*~ [fV0^is6+1_m#B@bǨ \Żc.DZWx!56 o (o+=aWTl@ [1$T~4QPJhK4٤s6Ew~W ^wqhZn{ZƟ_\C4ejbeX>I0XkhEFAnO\XŅ^M}rdS;d{x@\u [jX1<}u*4FX5/Ah@\ZkPޏ͓^WWWsO5XOTPke#)bҶ'#IR7N0 NN9'̹- d#0͂XG2 I26Ka hi\F,XGt:ãٖHX~oM &̵M"y?CxM@pWhy6&!ol5b$uħmUD+v!֤h$)ASqKfCp4Txg^Cʟa@| Al;mn PW~| P?=Š'"`PKYж!!~ ǹx1 zTM>Pp> ݖ{f.QŪh9.ՌT r-3=p+٪٬H 9s8=v`ٓ%sRz;@A}S퐻F&t{n&TiJ"DQtyOj10Y~i`f^ Z5c0ΓУDx9˗|,ZPBu29i!9E&bxML!(w5:c_o/UC妗4jqJW}[ziiqnH}ܣz 1:T.贲kGNJxzl#qG=:(SP)=9| Pd!G?߳Zv\t㨄[JyP tB*ggCGBPr `ysߊ cA7gaI>luxWȔ am =bE?[rXS*q1%SGG'Zo niE䓘Ykݛf'.j/KL$ TE7KطjȽ3E|.W0} Bu/IH¯[fEW.Kvt:}q |y<nfd x(UJ!ZlHMÃ3b$8E06䃟k f8m&^4Pxes~u.v^@yN~#hE|1JW%)vU.y*/zb)tƲf:`ٶ=\?Va|gΨj@j(Q;xܵf~`eiKUt86 L[:a/eDsR,\`aۋ bk0ds?4 +ʼkf%E\V;V U?C|58r*=Dzء1#چ[K=navU'>|:Ǡc:r >YbW& GJ5 ^{{A}wX޻"me)͏BE& _vihYQ Ϥb-|v=HERZ@069}"OMamOXhC3嬳 $cboxKkErOIJ;B0=BK o FK> ~ -T9SCnH-%F<$# 22!IFa i7Q/]R+5ϐ~L?'XY2GfƗ,P+>1f\$ \ ^_7ׄkPxo@jisBCQωRRl+E 3ƍ,G#t~W1rX'eUh1u*<:Uɪ<'aMun]EX_0'myׯ ^I)j/Vg:̚ԬRz+؋F=Abq ϛ%@sOZE~܆0֤ܕЃR;{C.Gkڵ1휹M8X`Q}`R*ݠo&,1|tWygàդ(3N6_;0O=[YĒL$0o[OZz.8?V|sx1Ұ5{@$+zpǂ"3߸]h B.}ce,i2QUz!dvg $Boh8n!͠L)C@e. )Xk"v Sf*g ֭iH*RE T\[0(vըTys:zBi[U;zhbӘgfSX m_?Ȯ:hMFqiY܀;~W3'E*_qdag!QxZ9S,) d9gi:hfcX_C%&;{5;{YAVV_`02@6F,G@=oD7U|mv%l>E[ss-z2P(Re[8LHkW@DeZE5C6wn2L#aOyL8[)\-`AC3<2->@Nz][ؔdPfz1uDE$`dEb3:lx"VQ- mkPm]SQ?|ccCݖ nD MlRW#aH\W"ۓeǗnw(z!\*JR%l^fFjE]SCz2pFX-?Bteߚu9y~fkp`8˻钡CXbڥی}7Tn7{RN3 r`]ϏI~!X.)i8K*_g\o-}As90Vjc4A uזg7zj[_Y-w_=G*j;v<+ڇLG`iD}#H^'bbR#.Qqs#! kUOVG>C;~Un hS!gg S*J#tsf5W|CטA 8r7ؤm*2_m^ Z[V~ېAxM_wŸz0+I#E®"S劭N ngI'J0Cϋеzt־M2?'ER] uZsc)ūֈGCL˝pT")?KyՀ6cL82R.^4A!EUWf~,slx \cmދ 9[tU)u=tW ԊBPs#O,op2{t)ɴpqM̾irPcTA-ҞJ'dsǚpbo? -2_ !<7{KZrZia&N^YHPgpYXT{'"H~,+GDf ,AsPNdUr`'!jO휴0m:kVƮOM6i^cpԗaϾc[.5r@iyOuP˞4Vq.¹素vx@͞iPP\O WSp :ʫ+ ;oA)k~ Ȃn32z\%j-[b.FZ^ 89 rW`Ƭ( @n3"=rQ rKj@ JNO77"\'?9iP^-BZ̯fu'})*5\Oc\(hsJqY;b\: 8vC,XE^0a+&+ħmY/Vk6?=N Ys2VT7L٧ijgCῷu$îbQ212s]4XCۡDFߏ|$cgZ+^)FׄޙDǾ%UICܧEpp|k'o\;TD Mk& 30$n{Jf$C7~0??G`70K9W{E (c4ꢑŒVvg Y1Bʢ`ݸL6|Ub.al˃H\'6+*TLkB?F4pc䢞Blz? Gg:঴yA{: e>`HEӍ 8H%8@R Ahb{tW1/{I6b ct!Tm-0 ު Cus,EчCb=QdWۥ .'!;暼`^t4 ҏg]tp׏S< 9`uUlۉ{1 1=)lഖmgE8Àb w<րxZOaJ b`> >F"rz# 1Ck2BQE%LTU[4nnp1  kHdҹ*}{$Ob$ γixh/JbrX +I"H8Sj ($o @*ЭO|T6yږ(OnxK1\ıubӉwNT=%AkLsSO?pߴJI^PG'-7`9h FNʵ, '_:0 w6C)dYUungxYfx^AG; X_9.~i˸xcdjEgjEr%y~y4eLwf$@ӡ~l7] R^)$3A4XRe>NL_f'CT:< }^vU8lq^CĔ\}cP` C*`)=ȔXGx#\$XsQ(Mijc1A<}EdM&A UNT:6P̈́?t%Ǥ0t&9+QYػjf}AU򇂷58 p+&"bIY&ӤuXu))YG flҊݿHd2S(Oe3Wt|e@)]DefQ+I$,'mDk $864e1h=֥~xQ lG.\O yj[Du"W;)|}RIfҞu4]$'5A߶4l^G}G!.\%p`ٯ×6 m0>񳂬`hl͌C1\v$#.r=R Rg+-rGUߟx !baqW1 u@=j1X6k 3q3Kŀ7:'wgnIJ5wL=Nش".c !FWVovn:Ĝfe;>&d p\3Z #sYlʓ7/#Iy 5 +jczY.X {H@}ysEt(hL/y9d~!EUuV;Lf2O8ЯP{lK-()r-:y4:8]f2}he.>ezԘeqWf9Ŗ4u|$ 6sJ ӹ%ͽv23*r7оsuM$jyN.J{6çm܊#V`+^*?7fkWEr%d-tGdm Xj]1ѾjeqjB6V2QPs)uS_Muh6ir s탢uUV{RWkz}UW=Cgϡ10ڈhIuAתr֏<` N)6a0kO7 Q[h}EXI׍P/Nk=$C ( kr^  uZ: X+UX(.\U2{<#]{i[G`7Q6w2U*vF%q⸸&: +aTbŀJU}y).(=spLَzƭ;׷$|2.ЕFLifQe ?#Y.t/$2M TVf5L:X t&!""赂A4Ob鷃{N,S$4 1@= /#J7湡/q[3f:f#L#e0O0y;_v(jHmy ,7`y'lZޏ0dW(K,x *"#}߲eˌ5{1Mw`{̎Yc99\8AQP՜KRбҙ(FwSbz.6z ;3E{xb\7m2M29Y0 dYim!g1 H)6PW:uRӕL%pu},35*בT5%R!?nZNgtQ(^ `Y8"| ̈́1GK+3M\Mcck& uo2#83l' mऴ-ݰ7z&Ԛp V6GH]!!?tIHv/2Ԉ,Sڙykut2|biG1PsǪ'GTڶA S D4U϶o0$ jnVudژ*A~}OLMhk7G͝Ɵbj9"OS3T}$ 9$Q=&GȔojFܦ6J19[E-k2[TDĕ Rᄃz:sX% KSt" nZ9[ΡXGVaPz)nj{[\km *5rtWXMb3.:vUnCAd<ܪ֨u90F%f&kzcuukO@P$ďʰkbjL)"ŘSDJa2*&9&(*`KFB] x'&B ˈ@ ?G3rݰQ 2:l#j<>eB>r# ojKiAe|yԄ^?B&#mW!j080؍PANr;_lٮ2'QHe, -:DO+Qvg@ݳ|9ylJK啲Ύ> NXi!S%&\w ?ZԬ:x fc%scXr5IMmF[ BU}=<-ιss)ժkՒ69!Qts:ېHYMV6Exq UPLF}9{a2"zb|( v^;Դ2Hƅ/=$8Z)Ѫ8+ l)n@uKLW?I›D1`m쇠 l|4w~AAkhcMw"<'=0qbcEqYű6@7H xwQlSOs Tj[a:gHutvo4>w:kdY 8̇r7Җ[]r|:dwѷK;.z8 2d I˛&>l({mIOol"e"%&ݕ[C~:LVB%"͉1_H.Ua(wH=~ӎMqg }w&H,Ю)}ֈS)˹{նʾ:ݫUI([QRJikTF3CkQܔ-Vka|c_ƴ½;,9߯5D+}SuR!gb_o:ίw<ꡅ1YMUyi^*rWWP"|+8ʨC]k\m/(+h d`RYn7MV-SbJIsG\cöG?>;z2g.``G SD4dcRKVB:F-S6>>Sc\XKZ>#11$"Jq3Q5R+Y^'E1 s@m2`{Wvv^jY5h1~x>!g@ R 볟Ǝ% $"'x>CL#0 X޽:LLD7Dx#AxݡuNቯp=)\s.qNUS3,f#eҶ3/Ėpp :L\2nmIꛜ?!k+XXk0`k+@u]}o A]wwB+ሉ(Lܼ<(C ַl!P_= 0XxyHGIXp:tr'KLvIrߤHrg3CA y[JB[6d%G1P\VMaêڸ ,"6c`v&f᭵#~F,p$5 PYG|@7yIs_c=,Çt9~L-e4",JSa,!ƺ+9p oh9(hZEM=q~3ai%dM Mqݷ'sݿ&L\fKY80=,VK7]%7Ni?o7x_}'ټoM/l׋j2Zl\@[GkxJc(,?v~N쭑aLg/7g w26aAxm #l\ ksL3 "?ϫ^:@.8F!NOG1&IIN"q9Y=0q:&z)^J#ei,Z~DN&v 鋮|OMɦg~;$+H( OǺ y0po),Can`Y\qe:d+䏥"nޝ7Dd-)c ?իj| vT6X4Fq/:,NH`kdsi~)]C4>*T~rCqWw(^@7REq-1r%O. ݇b#HzOWc8UTsMNQ6b=_160<+`Kr` eymTDƑxF2d$Gvu`UԩI|U:86VGnvvImzn \="z^.''*d+SbE&s@WZTy[O>;PCJo+zW(3mPM13D]T1/=Щ$FѾo2dπah=}/rŸ{,qj}E{ߕnTܦаŜb6/CϥGt?Ȋo?4t́Rut-+|F9[%@5)AMHԏ=vron+^ηk`"s9G$:&{_<5-į^ cbVxN]ݢG,䁅k(*Y;sxP^?-SkN4!AE)OHvP\jk6<4 Nxgc8Gn-)sZǟ!LC2~ 2|4ԿKZ43BOf!䬺DL([+ٛz d+hҮ?d+Uc}sE╧9ȝ,FU^?쟩Ia(-1 gBQ3CŷxVh; [BբPtZ)C5}=}Sm{?*TZI7Ӂ|5Hts#Ɗ.! fK^;0h(pl1țRY!)qg^V;ꐪh[mq6aj kJ[4vQb$7@]]UM $pFuZLNR]K V qs(kb* mUQ'dE(Z֍3;'U*V< ш]i{(Cn?OBrriucm*!Bb񮶄ƻqAX/rw|>@G<,hn8 LRxޔT -#Q~BUtZEVT SE/C)ֺOd~q5o) \2_7+FKV =`Qy'_o4{u/짥3r' ,yQ @ʭ/j2'3ۑHskb\ꐾ@(^9?G\eajm,oD@%zJ霐@qq t`Qsԕ?w;̹%T~G.w<X)x\̠O;4EO-Hf,wJUKC%Mk q'rU%*U(|S}:T%`Nzk5b@?!E5pF|bixH+t;y+Q(ob(}unW 9?(ưw3ڧ-`#.Ֆ{Rf{﫛mOQXWU0au^bPmcg7dXz)JJhX3-<Ne@5ڌre/P# 4s4Yb2~q.wSY̜M Ԗ̫lWUQ4qt67CI'd&BQLĥb@^GO-ΗIQbXxťmr|gYӦ-`P@JtX[R*F[obR$xFOS)# U99TD_^;L^S88ىv#EqQ³|{j 4Um<{>w K%;,Mھ IBG)TWo%C(8OU %  5>*4܁"ׅϕP\.dH,C mAhvrtO-jCl 4_O5SO `V̶zX.W@.E@IT#k݇(r6  Kރ_]2)um9ȧ'7$S 'щ}Б&_cak5o2[@`R`-}[[ˁE t'ء+e;A}b,qvlSx'=JHB iGP\Jmr؆}!xdҥ.Xie#pՇ(%6NΣU_&0нLWJ)n7пdhy#Z`M/;ICy㻰` ~ ga.)ITx9l{ML(C#6{ȯ"gd]`}ˀ»D!І!<fK'sC{D#Rϰ<'?!b"S! /%+wAV -^23҂NKu.  _eJUU6{fV볂8%ùĵ`"չ=I`9C,Dh0cYLv!Rjb< [Nǵ=^ܾV ]‹T;Sul(9gbG򗰮]Qb%cPlg>08fCۜ'mHŲj>SOFlJI`e%=Kޜ7y9밃K>%;P3Jd_$+G*( ,FOIn Vҏ!qyB R/*@#wky9,_QRLRW8+16VVODRh_aVy(4_)дܪTq8.ӯdV^5jiпz n5^, (:_C+GUEI{f1* *\}w2_~r2zVGLphEe=qL߱o%6zپ(. =^wl@e\4+36g?-򝰠<^r5Ӹqي^S972[.=e Rm_0zĔ64rշ(oa-ҔR;C_R)*RE OB ں4ndu;c_5J聱l[r? 迟9%{HfE hFꝵXh{qM6S<8Ys< 3jz~zCQPDSIr~+ZԔT6R7cWD3am4BKsYYMmA~Q3b4)hrﶒ}H7;nY~œ6 WGЪvqq uwؠY~s[ջr_;{٧E8#=eZ9-XH~g&k6tϟfzAPxv%HL@n33ONIsw0| @$?]c^ȑʡm T4,P5MٚHnL"jyo@$ w_:9ky]X)B\-$ ~Mef(P<x% jN4|?O(<SST MG8r it3 xhn8Ӭ={yQUI?;wqVR.;:l_m_B+"&=lZtA6hk2*w*,젠TLdyˎvܦ c AU̓l{b ,,?!&Y);WGAJ;zozȖ+ش=#%]-s ]ף1![vN\L'?yj)olqhCG&rz==UI38']eߩU$?\P;+SP!Lo-K=(Tw_xSVs .)Fۘ.=/EWȵ_ Sz3AP;˲E\@{=DZ8RyRVl-xZD{"h5Wk"g<`'j `)]eU DE4UDh8ZS4K[)x_aTJY|»&ť$`3]MU1#l3U=!.鬠}SfϾߩgG $\08 <]G}ʘ,vn.L qwOt={ͺ*;qxv w;5mB"pz"8LkB(p0nZF?Śp"߽})>)04H2TF?;}t q܊\ky+5NӶcY[Uη{+DJJ!up'dC>_r#K Zᖂr',1˺I[(㜝 X=oaeLHKߑ>m7yp&F+ܽ$` }c,\yYU= 'OphUQrQ=KR ‡yec I)13gLϫ>m-0;#yJ`.^c HN\[u6Sp'`!q+7އۚ!.`A$U7h/?5kޢGm?%5]Z2eJ棺l*01P380)=jBiCyTacq2"lXUR* ɐz񏊘g}azDim)'W^ǼΒ3yɐ|TW2h3 ;LǡП~"8ku2lQ9ml;2gʮj,x[)Va1\ ~ʘgpn%R[gD˦9uJg@I^϶_6Q<}R߸> Ǟ6h-\m©n¶㠋eķKyݬȉA砖=C _LS* mߡֵ%:6j tM2 ]Q_ɟxț[1J]2zncƖlH!Tkt)ZhФBYPoMq{ܑ׭3@ιgؠ ?+te>DV?ϝ״nc@1]=E"}% z% 7ZIHT_ 3N-%M| fm|K#NF>'FS,1Dtkdpo2 1xjNl ې#]rSlU?FNktf fxyu&`޸FЗ ܃sps<]=='ۢ8QUQ{e[1}Wg D־c .qWdR+]l5!>o=ڥYeSoh7qGq@Q8<(MQfVw1E?l_OrXesa0!DfkG|Gn%"uAfԩjUV'dًObgJ7:G }ӳuZLr3@̙/2{7C8W[VğtW s$~Ic_{PꇩDr ڗ#D"M?'.Q ҏU]=ZcPPKY3oPp27a/W!Panٮ Wey{mBZ\ w,C-\ǐM-ulŖQ[,|qj8n_anNiJaBpS; t*w9) >Zb[X_Z(oJ`yKt$`rA[2Az[Ò_$`l5hR?ԃ !'^0pO$'YH  Ě`v<*!gBbdV;_`D *FT/ܔ}HIʥ8ÐܳOz%/K?` ֈ @Ԅk NBE4EYOYJKyGFQ"_U)&v j'zDZɟ?Ht~;  ժY.cP2'ػsr)w&5%D)(*#\F?TCPֺCPh3躏`mR AaTMYbqhEYٶ˵q .ϋe&͍[u=[ ]wml Uc.&b%@V!ي%* Br[~aM]nOqaS-k5]zwFw΢+Gp ;fS2mդE1yD̗wTSdDxԸN'TA=L[-{gISQ=./ G/c;}dӓe/RčETjetX=uqOMݱ4Z J o%r:0U$o"Q6]sڅ$\>x,ٺǤ{Iе8![LB n_+$-҄ Sp q?4׾O5_p0?I4Kbڪ FC)W}i VܨewtFqr܀[IyO{a91yHՁ*T!mbH0zBuYas.~œ Q\>Y8yFy8G}tD.nMi)4+nvfg]pb ^h!FK@i!9icrcYVc0﬊ }%ӒbGOH+oVnh! ^0lSjE(Έ@`&go5*sw~R$ B^G-7E"I#lF_. l<*ՁEa76e154ȭl:Z.Kp9y55{:Rs]pR,`X=*Z1"#8=^ЖD ag1mĉFT$qqVte~\& _.M|jjqNSmV ][t>x_5yZ_c Ƀ-go$dHw[c{+K+Bw[BKlb4'mJZ $ C?+3)m- NW|/^]|]c!6+ڶTJ>3f /z+jY9)aWB 5IYquzhGÏi\I;!|sلBTVKyJ[(91ϮSOԊs=Fj1iz#ԛr̐ȹEk2ӻN k-?1߆9Z[וZ.t1I如j N芲JPpn+],XҬ}d5:VP J#&<1;-[y/RdoT?J ֩o\Ψwd02= 2ɢ+w&[#*K%i OKBK. TBXh52<'z5ϦѣXmF /3yRwMJyNgƓVhL;2dN{%arncosͣ"PޔsOc:{F}f)}h*wrƬ0?LG?gZFHVr!$\Yjc W:e(|cۣXQBvm.R{+V ߦ 07j,qM 8/b+yb ul24EH)_΄'Q'Jڐk)L%4"/5_vǡ{U\Rޱ+Fl՝Y$o9WF~aKyW7t9Z748-)mxUN ͬ[TR 7[-2n1iɝF^\~C$b5!"-H.n/wz&u0ގh%+/#x95(OU!oLRUen;:^ղ$y}7 N:R)qO{O,w>xl%bm%9н9I$m2K!)KCla0o/OwMgZ)E]~L` IY[o-缦¼`Z;@%T3AGnpaIi1{BOyu2sgΉu mwG}`!}ӯ:Fvqik\.o`f gAyInb**0+ ;v-ѕv_ $"+.K =AQ~ Ϗ1(Bl'8@]e0 œڷhZ]גw0:Y6  \a2UxC+28|)Y=|#d%˾5@ªTF %Tb5&f@#=O];KO.8{Bn$|5R0a AFnEj6Eع?"(4],҅|MJ8 bueͷ^m>%cwON^h'M"\ZHpJ< 19q~]ݹҊgJaP<ic@۳XBbֳ*"PYXC %qgׄ2ǻꚆO/D!r3PCI3FAъyji0Х K3ʓ0dg[JZ-5ދ>U)*wts(&kȂ"|W_nN m_Łj t7pp -1 6BSϒh+?Yr!es 8̾*xlX,SA"I#jϒ1b`ƴj;?Y|$bpOs=W}rm_<J\#-gv e'{duiúѰ } D{UHS9\\95PEM/7yaO|zK;Cĵ`} \*WDj+ ̵߬ق>x 1W!v/U+Ex$2VM`ly<)=)(T;fV}e⡶<4]K;1BڝiğJnu$H»E_Ѹqڧ>q?[ ,zJxL/$Te"ɗu ^=L}q4Si)=FmZh0m:*w'f36N#Z S>b,_MncιTJ'* pjK߲`؝coD%bL)kY.\/- dvΧ+BW '%bSlquT5A|e<>!DYYt6 I;. o׻!%LZxجq"Lyga4l=;\'ba E?)X/Jf[Cr'A )+'k ~0D=\,tY< "v@y${/?lΡFJUz]<::|=LU76,eoUR[2͖[Rrb Sf$1{RuILawyV8/~ tOiyfpiXWX ]s<mƁ%J`5,Α'^~ 9.[IeT`6H& ?= |9[xc^1I۲~sv?:#Q1:캎;P\h|ٝ@,Ysh4 C>`酱TROR_Pb~3fOՒ^C8W1(`fI"\>%!LEd))=Y 25jsualMomG#2YZ'R>Us*H1:c ["CA 𯕥eM Oaɧ=9X&j$#oS)a4nRΠ&~[:e폨%'?.!dlү{b~_rI(%gkj ]EPMfDX%ay_}=D}"AN;U!a=j$TB$K5ly=5gTL=+5QM_% VnY,BFJ{(jZ9 +qsi׈N:^c#C\Nݢ+LQ,}Ck;@b> p9Y0yq}2Ǻ#B`'|w%|5?ttS&sNmnIR"IP~%t=m",:R Pjڤ+Txf 25Wy:z2vXY\RH-[c(Ɛ*uSL&~,n {<jnYX|{KR\/Xg`>m fE/iD^Gn4:!J4<T#LߍiҿM:6c8v }0Se:4#oҡ g͆f 3M$(z8oQ1zVܦxy~z@DUG58,"gmL~JI* ^KB׋y-Gݒgս-}Үiwȸ}޹*jWJAcJFdwM=֜5nlkcyDT 캞"(ݶv&H'XR񛞥26~SRb#= ;"w'% g G]>]ssSU<HN>\nHY\OPy BK4bTH+#fl 0:,y-B]} <ׄY803gP^2f03#]\(z?4gz8eL.%n'PVߑ$kFwVqx`.ʶS=De]Hb4]ʇØ'O줾LoO pS]Hn/v "-.RGvyA[$:@'_9L]7Oo|MӃ;N2L}A+k &21uhwyX+ J?Pm 0[|#by JՔ = 0~B08@}K^Bg!hxwzt pf#DuIB@]6ò%6+5]\=@Q8^MG(@$u#_A5]Nˣi\;wzV` % KW,#"}J5HV>!`W(f' +=RZ xF0Go| DjN,!h)][5( >uw0fRWh0ҿrcfxbsӨ 2ECG?oj͵n,q[TAk BW/`buUntD$D+,q\_vբL;WØy~.eF)6yv |n27]ۈ6~ԸO@ŖPgmrVD0[>F@4}P$j,j3 o}HC+M]wL(A<˜4lPL6HO#Fmѻα*gA†F0Ԗr|ܧVi # I pMeARSZ!i݅;f"l`']uRTYPȺ>3poZ?XpWl Q7Ԋeܓ3 7q5{1!n2qwĽg%8w6o}HN+payuc@s J]3ŏ^uДt*0՝A9mh٤dNttNXjNB/e` EY% Y4 O8?wCɘXw7$Es94_ #%P"'TԘCm\Ьl N(&Uڽz Q%bЎ,;Y䬗U0'>Wuly[7Ek/<I [ʋ:^^RI㤈Hb*3m}} '\$.x,Ӑ-GU b;ׁsiˤ\B+u6+=Duf&\S]\;t+nMl[o//#bT;Dikc<(8S `*^D`Q#e< e uّHU&V.Į..DO8.@szpH4U. ǖ2p7*]xC7Z2}@-3-'jde!iMURj9'r} (rE@gnE oah,vce$`ߨ=I;lM$fa( >4q] ] *д#Ã+6~ԏy͏J!SwZN  G8K֙#ׁ2 38̀>PW+NJME%3!L $$A ՗;"^KY =ƀ+gEHվc`YÂܴ3)K)h'YRZ4$y1`+F T| 3c@?DbԲ+n f1~ "rzCkgδkjw4b3&eyz^ G_5퇒J8a_/WT)!9 %ҡxfq5&x>?m1;7RWcG+ۧ|XS ,jĹ()YLf:E|!Z59iڠJM%mx;*!WݖݥgD`wƁȤ "hȩ*́B>b/M.)qgJXUqSذ1B9"ZvсBT7ĊV?%]]\Jǹ|lI0 1\T[x8H*34K]*-;qFAM)).LQ_/]OcHs0d™g$DtEE_#-R@b*k$$( ;tv[68GDykT2s%*>z:SFnc;=p6ljK}@x EsB6zoOrL Pem| GjX_w)u!1{T,Lv N_^h{.Xx$$ >k5m;g3j(Ǡ\yYeN9+ iSJhnlB0Uԩq!/rձ[aҰUOhdwK3NMe$ 7\[܅5n"LY#QLԉƗ2|ÏjM$i k쭄4ۨ` 16|S۩l`|4ɧ]2GF}W!*--'DIa`&ڃx-v4Fciۭf7‚!aikبX]3o;BJp-`ߺàBQ-1ɻp8)G ak!eJ^T+ܛ}G!*h6%ٴ!l{ %#ƦIP7ҾM?Wy *FEj ;/?Ҧ㤧37dexؠG҆4_R]?EE:u]LϦT~-~h2bW@(LH{Pߘ|" ޴G&cIy= QNߊ YUN5!pe,}x_ZLǩ'̘eC),(Rl X0f*bkm;Sg)Cxḛ#|9V*Ld} +5ݳ$D/je6^O yݜ M|QefBrP1| 5q# pzeqQI2@G3%N7{Z}sRh/ef-'9;((S6MG'QW6TdK;:.rLzĘVǼ\hV{d䵏3ReVxo)-A9"*OZ0 cco:+'MEWX1`]ⴞHF9 NG[8\dj5HᓸPwAsaFiֶLD_o1;H{aAiڨdUl_AsbU49=fE*|-K.>< e8p&mqI#F\H@ J B|M,VCf.s~^F&QcTtst)~LF  1fZȂ@Km!L.u}aR(g2 ,ZjVQݻWD[>3| ML !0 +T-,W"w@+a8zީq"D-mOsze 09L7i%6 vp {暘";Y!z~#ͩ &71,c$i- xoV`3rWya3\*^⮔Brf{mp @l¡bkCnHN/9L*"Ҳ}K m? ӫ8Ti(Jt,cd׺NI}/j&𵌯m;y)b&ŽU2?O jƱE&> Y18>5Zs,4C=?")xRF,e{&"+7酢,H8Dmt#w|)3&L'`{oH>> &;:ڧ_8r5Nr4Շrͱ.<ɁH5:^cdd#I.L*o RZ ]Gg\V-v Nf,7`0ܻ}6aqJTHZM{h!O7N2 -BnTEl>)1˕v`VWQex6CNAx"y;[⇙*!5|w46&a8:> N6?P; *zĬ[N.S'Bm\cg5U[*&ݦ !'qlͬasbi~ZE{xΦELnK;o Oq3K~qw ;j a:odlIRLv |? oQHFM:(CgiB`~ՙ^q>NXG .$>XxmuVj1LhDR>@$lRJPPV-Tu0$wݣĚqA&*rո9d+yQ ͱFmh,,6$HNr4zg=Ln)suCunwDЩaY*חDk;ȝFs> ؠ~Pm[{\,w@!D** h-4WTڴ#ϓNKӍ^e#û7QSX_P(k൉zd ulS3ϰ+Ka#?K˼EƂVXb{ʀ"*+$ln|^''9mN,/j׆B iFS@ڿ{+ՁsWnٓ6)?ԅu`[4J@ jCuf*PoL1]EʳtjNZ3>:ĢR(|*sIs\D;e,5;{W=W|v'ʦq+;W!C^đKSoir;tu'K;{w}i.)s`Spwcr3 HKafP`i %Z0A.ƺ߽[Z()?p4n"h;k܀SȐc˫iԎu/%l#nS*<%Dy VtĜ,/jZa]*m]OG[^(r#ea,V^r%pug3@AAGo'e~!DɥN >e\>(3{fg-|SJR9[y>HiRjlׄ1ҡn`v&IldYv2ˡ*"OC!neOtVܐk^q"E7AљʰMʋ\0r`&\@*a~iN6Fa&s4q=:7N'Ceg E32_51GO!_*>Q'̨YuHhM%8nur $%`ΫGY#L¦6} hz8Ok!@NVza&i]!?;5WN5`826NOU3;g!lg) ݫQoLF/#Lxajcv;@+'f'^64KG @ D[V n%Ôşha٦YѤ J9IFXW AFaj㋸zҟg[aF)~E}]EH))~ʒWνE#M?2i8.x-щFCbRѽxy15qd{9jN]C@j'ێhARe$iE]RL +M? Nr9ŝ^e@Y޼Ks26+qN7Hs%wU\F, pG_a]{Ҡ`- EOShwVVa\>"3QCpICΜ)>ӎ;ZDdo7%&Jb]Z rzG0Լ ڸ_.HNw\Ws'Q~4×OlZ}6<-K1~K(TWUjȘ114t{Ud ?6Blb5i?3NQuozAwU g/P %24!mJ/[yn^^bEe18JNh ,[Nd.zu>^7x3f1ϣwc ^*΍W =iˍ_A2@A9F*0u6NTV`-21io^G\_.0ȳ,wTy=w25Jґo@Q@mZî/A6wLc6 zw߂4oqgzK;SҐL9/ƌ_NH-Nx mt zf_.ը4r+5+ƑMoB' F-4}ʏV1|d&55巁O\C(fHH1|D9~iMHY3)t w':6ב_.>l#3<6HVsb/Xk];:KCC;zjλW*& @nȬ![Ae>N.\91T|NP-̍_#:uuR tO0J |?g[m6P[Ur3Bԣ1M `*N041|5o a ƦH**m3eсe^EMa^Qkֿ`7{T8,<.KN'9+R%N5 kZgMH$'ٙ9@3aIGu&M6h !iYj tm,̓  {aOQ:7ĺb3 Pe~,3R*"R=z}aPbn,l9B`y1R]r*VcCzJjpqcw{6UI-mĭ,wgeRL?!ԯFa,df1's]YMP=Va2So6\JBq|z\TW3궑 j$%1X'Rͭuw#nklᑜk, }ò$lc2݈BW,J?U0L Bi%Z{Y  HcBAT򮫀F`C\GSц(g5B<}?|#Bl,Q鶺O)MQsš:61VPJ@D[fi8Ic^po@>l,j0&i:f,cӂ]'0d<{/y)7Sgtv(<G3'n; o$zX 6 Ơُ/ucm+ |<~m?}j݄ /LGy=S}X3c! zd/hO`r*U)᭶9Z%)ݩot3zg|`̈́x ݋,Jh Ry$-J1:n']~a!n@Fτf)cp09q  5a7mƊ.M)|vOeڤ J?};rT պ˟*M1纸ȹ>i%\>,d .ybiqO$Հ|),wa3)_ (#GOsŏa/`F?͸E><iB"=^+r1n]:h`oKeVd9E6«K;'tL'֒WȦMRA}ZgGqw>es+A pb -G  Ü6#Y FhS7s*Do[auS`3-wyU؀$36 bcG q&dBěHa% p|W#_0j"|XܝkP fD[ A"!\_N€2_%tmZ1?CÛ@\@!h\O/BDCb%WܩœLs+1Z%¾ag\§V>4+z8ed*%`{UҦ*c ,3 w$ ~TC:W>r! VIrtE>Kn>#Hj+"Q=4,aY{ZID2E5RW.{e cR m#`RiwLZiWx#,ĔK*@&!Wr<!%<ɽj5~zrɰ:yQeMcVԏc]OEֳ:sb>XU8lU|*z !_ͳ89S^UKu4GH3qQ쿁492fDT)Q^D#4| ͺjӗrhoVADOe1KS%Uߵ:t-r 9cRgD'Lj @z_nЦTk4o4$hGY*٥m~f᫖˰/Bn6_<pnxؾ.?.pJadѬ$#@(@*ẉݻϱ,#Lq#~3bn +E&}V#@4Փ'**j'^8&?ZSg hhjq{cB|/  i_GvK+,n PQ]j ݽI8PQaLfaA\?\!v2;?6}逮L'ZE\6rҙliFڣa9wgVga,1b6\>"mDk!2q2^R"P9n{L !O"*Ь0n"RӇa7)XD 'PH>x̹OjR7]E466g\/eJнc K}/mmݼ^hޘ= V%r H"8cV[Bu O5p|(c"[RT,_q HuxDӧsF N'ZDCC0Z([ oY.9jRotUDeHkkX[目C.$= 4txg* sc`kQ{;| jbӊy|m`yVidz&EۉٷbQvcyЇ_$~MiWuS-US\N,*%eCa/|-Oi4 /RF(% eN.烞iOM'2\8N=yYU>o!!I~k\%*M:Aͳw ~ݢ#_-L`1 Y3mi阇UkA >k闗Ms`nN}@Q %D*h8ǂ'jݸ21LVC2ե GJYQ`>wT!__~ɩzEy΀f!w'3"W (!r`ү_iDӉ9 Gg۟X!R(ì*zB烵2j¸4Sj /Ao??LJ4WЏ wa2PKHigi݊!N+m@j(;s@0*` 7w O’#h:AQ$,|}Md8} 0-ђaOOi$,[ݽXlSi ZBȵ:)~D?2&Ke RDI v[VBgEJyhB>{7񗰕9aajZCY8Kg,vf)&K ''!q>N9/XdpG}pTPFwRqѿ᳇7Jb`1}iPKMFXDY{Տ6a!j#引ܱjAKhć89uu VdKV&:+i5PK@j a  X 'R[ߒ ,* tB@͟"'^H-y>YnRK<Ύߞ'ӌzPK7ڼDz{he1i|auOt Ow[g>C|FtjiF1|>]!aIU|(I+{w]Xߊ[%Ld˲M#lGQ{}U5>A"wիSdΈf7Dd@ .O>/;M:QSP4aX*AJnrahS}S sH`b 9OTT`YâFG5Dͦ j80|У0^_fpO\d<?2e>'ݰgN ¼7<5q|1 Iorf>1SNidr@Y$ĂwKjh?O+qP+(7|Yr!wN'/ԓe *k%'|xb&"4VGECNXqӆ: g*z;5b^M*>lUޑI=]WǞZ6!0Pþ!Ph7<[>rC]~2qH.ntl;7i#(+tQ˚, /* FwI/]4;%VlHNEA@b1R# ,@E^;֊?j>sJܵ6h3h3tƱ<W; f%wNN'j4<9V\3x tvf͑Skm<':w ^v GD!eWjE0# e>ГDGqs:> d&HȄO]s"9&QQ^WEھˍ;ȝ;TU΃=>)B`4"MVrB ˆ\nAS-`Y`#>I8'_FƤ/Dnf4l 6>H)sDŽAdFYRo:ik$JfDYlߟ82$0㋒ܣ;RuW-_{-hԍ]mFuw)5x<"urv>Q7.G%||HʣڎLTOӊЎX0mVy7NL@ͯ\V`Z]*_hR,m2̠vP@9q됲E7Og N*䐓t`g'jS:,)BŐ?vWMZC)]£ѧ{XmYɄ 9s 'XElmGpŢoԇg< Md߱w_4.R(AT!*(ɖ"Lw)M GX# rRo+2jO = 㿰WA jr3JE_Z- F`\;^q78M^]y┟2]EUsږ7n`lFOrtx%„;4)3ԣ9Ϭ3Jpl-Ar!A)m Lrcp*8$Nجi3Lki>btXs b\Fh.4S'm ߰ "gY879ߪ(ʜ"82H2VdfX3~Z;t=kHheDO Dfe.H>FĶL&05vqc`BO{U|'q|O D\Bf~A/,8"zvegŭFY{]'Sݗ nH_#u?4Jo otE..&.%1-~dr 8:.cTѪQ2yG ŶŇkIhd? Qɦ@3HT U _tx|N}Nxϐt;Pȕu0[ Zj+~䒂_$F1NxPnoG$8\J?$ފ(-ܚv)K 񋵄"RmP{ؽ Sj|~[Zw970} L{bqm<\C1_ͯS!?PFzv.^qIR̍p8@B3->G8S4ealnwM 9;CPjҦ>J^5hoċ,@B#T`/C޵ChH;Ae庆.5Si2ǘ-2.7IY g+m,_aQ|z/B()Bc?{8Mfo):r!y #?5}r{>1! &pi 5v'+?&RTtscDu+2[Eg3+2 bq8At 6tA5t&=XӎbRVp}ԣ^bjĕ7w{oeBQώϚZr*>l'HfWó\\}_DUYg[iyiQP Oz1yDEf\Ddˆ;/~3#X Fk㩽2v؍!EL0a{K~ژ8FjR:V@iQHG^aŲ$Ak)PEKaZ6}mH;Y499:kh7M'_!*s#O+h (ytؚ.궝/.PisD.[K*ý{+@_A3 W͡ڠֿI( bHGUnuSTHP ?,zI"i=mh V[u4> 6l'QgYM5Hcʊ [XÀu~`L8{]*l&Rpb 5xL#huVc̼tzXŹ`cY81 v%}Eћdk FTJǜ[0s6]UB,ƒDkNרA$쿾SaA5:S`0tE0h'}-> mڮI5رN`օ^ `YǦ9j԰?&Ph؝o,ny"@D.|eb|>d=^o謱)2kx-grR1 \Q"aϴL4` GѠUvx@F;.JHGlȏ^S[! (؁3Suirdc"{1Hlz;fz /~g拿KŌE)Icv*C(eqP?c6}HV%IcƣqoQTpIyK2]2 Ck"gr;PUéss2 3VDA˚d^xC҅|U_e-,!^=<5GfE|cIS(D$>r6Ҝ?C۰v{>)T׀IC#SkEto%/ڨע'͖prҞn+UFͦ06MǦ8[l:`JaEJWd4˹qgY 6AQoS(%L2wM 5dd)QMσE=&ƒ]><&nWK v%M4߅U!5*ʯ_Nc;| I*UbU *WCCzޠU_j ՉkDqx05m#,?[s=^$ӹ'w<0A_x +齪?;%ڈ,z*: O l}EK0~!S(DWI3+R<$/C9栿SDbQ<4F\·L/:l=\Xf>/>5T{:"Eb9h8ve?] W!"/Ž)o5WUFEPצ&+ QD 5[SNvm\}hGĿ^޸YvF<Ə VCp] yVY" qښHR6MM{k$ ?3.9*M~>OyՈ!Q0XP1;ÁA9[]pRMPkF(grX ZiNTjxZ{<5eVMB*H.) Wv/'"liTn1\X[;SN3ˆjZOh#xLv69]{ ci7"* Dl^_MFMĶS3U@rF;e[%=)E .åy׶S-)r*Q1@9LǴ>;%5MQzFL4A9Qtq$miHMaHXTO^Ck~;F{81|9GU[MAGL8F+./y9#0 \ Ec[Jx&& ,XM4C5u6 ARN(L((aQrR@-ʆp#~] ř+g} ]>.@z[k R\$l^_GfVSA[Hq5 ⅱoN(# ]ŀJ/@p+-vO7j]*Y *z_0SH_6d?@bJ'5M"6m6s^Jُ!#DtH0";&'Py# 3oªbӎ*v5wZ:YM6oq I 3 ; / Le&̥{#Y]hD@0Gl|Nk1ߊ mPUQ_>?IZ^IaFCqXA-!"o#x}Ileb޳@eSuQ`2nF:T9ax<6BW} E'tQ.dOR).,#t fuC. i?@l&DF Y_8qihaЩy;+8ZkzӳEYSWBN}T_yTg&*<p^ l!tT?on35+-u =JrFu8i}{Wl.42 h g;mt2m zy;1 jc'?*`Al]T{.  _2G'ᅦue1 i(#Ww_2+qwyx~cac\eR^X? 18ryB=tmvgG8s9L2V,m܏j}bp|E$a4 bgNL#ߩ-I n~wٍ T7;dP9Bhj=w,> s,} #)EBtQ{*sZWNy.ӀٚXMUc pH8݈h5d H F=:*s7v@+8]|v t"E-,U?)۞N"FQ9]P8a\IgISbLĞ: p$cO}i5oI}sXl;TӚ6-6 bcnQПz Re*NЇ^}y-@AvʨC<]kx+ Q~ FJP+ϔ%ɲFц HWSi "p{Зd?D:#B4d%7i(l' Y# !r؋*fg O]#%XN֎~}S/v'0'IkfU9\e6oYH!] >COc6k5zvi2%PAѵGdGxKب>ԁQrRֿvKt$q\Mب^ӛZHז\S RVu!kF&ʠck._|՗4NL4Yb}R/109U[&Gq':yg-2TJr(e#yΙ2|AzUe`X傯 ݫgpλxtF|v\ȍuex"s07cg)zRͅ\M~.z A*\f TZ`GPR3If; #i<45{9G+lx<OƐJCXM(谧gχ䷚GtswB@C]Sbu35T>ߢor;alnj9R=60DL%JhH»ۏ P3*u ln\!h$ףa9K.7&[[뾚z?Mדуu?LTU<͡`?TU)b]Gn4I,?|g`(ů);z.ƀ,Hų1n:'&KVWe^m1Ɍܥfӓ 2){*H[>'p$_(<#.ZE|O?K.!7\הh./DCn]Pu3&A I8p\&2*0NDW]8B+M^8F[y3Zmh-{)7>m~LExRMlSyeR'QHc1KZ\DxL˹" Wۤ#V=NoibʋZkt=a (%r !wv/cӆ3z)WNҾߡHu_F(휞oWdR?w7Qfz''lRPk߹t]br@`n8w]I)  n&M"S2C:&WdR/sO? / Xc s;n(vh&WGA-oNGImA"'l]{<;LBR{ Xf?.Ic  U^ ƑwegGw lz%)IPv7ȷR tg(W`.h;6j sDG/5I9P~[ɹ먁SR:S"l*Nsmdhj!߀g&d[=x(!ym],SF }֏k3K8>rKX߷鮤Xg+`o͑CPZ;Bgaf]+z_yZ@4ґc㹬w<(BѪ.ˆ^S.5VEW&DljY\MjLj7B&0aqt!rr)@ִ) JSvT';DQddu+q$maҠ0)46$rs7,>΋ֹ䮣ĠYeٜw`Q (1%ȖT3mi#4 mv=~9fE!^ܩ=B54Olf\w*ZF1͂1_RzXΛJOXj'ŨMS$; N^C0EAjeM- $o6 ʌi,PE7M%gʒ2y՘̤QJ+8?V;|ŠУ%+Wx]ru=aMMw9|T鹲`[{'m~~RK$"yU$K?l$^UFD̑l'kPU(㪤NtT#VE) a%@΁ g)"} Mqb4Z=`@'nc2:iJSwR%뫺>"fVқ 10 V4gMIN~;;Ђ$Vt<HiyѹϟW5!A#UBSag7W 63H\NY+*ɒ6FYC"3VU[|q%]|j 77acB\c'R $tAڧ;~/ˤb'Bk%.P\8%;轝G Ԟ<9"~qPuɞ,l{X$d斚k a~O-|mm&"tho5\ WۮBeII2?ϠgOOyPM/ u%\^ɵa],d.^fHBBӀn|2iE~Rk j⑷DLHpIu2bٴKמx67bz bKC̜aۅrPt}ysR"k~9'XF%I͓_XWNj&H;L=f^1xRxǽ7qіjv@r}y/zZ[#& [ĢwΛ#T Z}~[ӎ 2S L'E;=4!fJvp德?c 9p %MD-4aT _qǵVy81x| g7ø 8lLZ7#ǹ0 J[S:2RFoXgVhGE ,e ՞Q8H5רl߇Md9Gj8QhVz:W'7 t$_IavcnN)4 ;`SΡ2H]7.c9mKQeB룧HO2-D_'@@+ch51D?` .EM;[V ϯLe0+\ʶGL克{oso} ɯ!) ]z7#kqGô{bB 6c,<&tRhu2 %9d{]T>P:+#"sNF;-+๣ Sw+ݜV΂'kD- ?.IAPtyl/xwp7"uyZZ ===Iؑ[AroWO=8P\ 6KrT+W!N (e:ԂdUM,jp+:hʖgN6<8IkKC>h=BѽCܕVb&6#62uXIҐ݉.VWN?aw0?E/`#\8* WD%s]B?hVz~=4r,HN6bhg׾QM` > 7r鍙:3ݬg#.G i4Ir8m=LUw\[6(CxYb)­`Xhʑ*waؽtd!{VtUnHJ)~Wɬ`-#Vs&w5'hB56zk5v¼pv%e9LU)W mZ!Ub{~.[(hsRۦdوf(ڼ WzR, R.7Îh\PΞZ:n|x;4ppg(Wz9-Uo-ګBïLq㒲Qc<* ilU/_Ję7{165aOZF@tLSYgb"IxAة3{+Y =7b~1IѠOpFKaW`[9l5ʴ"ݤ0#i4j\Vͳ_yKU݌z9dsxns֮* j&3"8".VXi Oȝ6ƅ n/j/3wK_\)0 U2J#5筗Z(K}gEeܛ^x$bć+)u8s^$6R6z6q*Pe] tjjcDWp8`<0N{jkB5.@(_kJƯ prɳ]vn[qw y\_O>a9P㖂ԴJ.i@sܞq_anVM+q||pG,į32 򁤻X!'`yr{?ip/O_,P̙*b# 31VAάtL6x\ެQO4;ao#пr4H`q0QnNg@Z4܅3q ةNR΋PpP:~j eGYnJ`}SV\GKO$WRbW5HVfwPZ50w62֓mY%h"HүlP~'33:= sZx^U $m>j#b m`K #%(QF.$& CÇGYC@<ԇhиt1G`\ i..wgd ?J$5캞歽jhHn@sEE*LӪzSYmQ vB(Ty‰6C 1]ܪI|8\"b-%Q -;.z,OUv136Q2ƅvC5!T ' p&(nI\5h!]FŧRGIq4`, -mhEX_LJTT}.|0C7_&4Dv]ӰwBER'E:r@>> A[̫1IP#)#喊6EAy0^Q "Sf1#;DwjlLq-IJOedl$y#<I}/%Gg^頏֑˿Hsqb!:GBk l^ /0>TV+%^K“<|q7os$`4.~?0~f_iOgP!}vJSB VtY'ÎbI~nkJcn 뷯@,rچ1԰}?rh8MR\DS/'SKlp!U] ) '|A #&|I ٩(ŇZ J K l잘USUo{/"TZv?Zd5X*u&93%LZ<󕴀lx%}=0 J{鉥;]ک$M$K\1Qxxy|!ݔ[TGA|J==It 5s zoig)kc͸vqQRUAO3ȘLƊɲ߆JkIJR*߻&d97n]?|(1P4Q/3Kg[hl6OZCo>i4qxfZPOI&cM*ؿ6OLVQ+ }"l~=RFgbݥZCNAоt$K{FA:ʄ)IQMid*PX̙ .V{J ÆZmű/@ֵ.P/Uˍ1*gPѱʸ;®\)5އe@WaL?8J')kV5Un̲#:/"BxmZ"][%qgy!X[2)^T@37rD]7jC©[W^hWz!3di( P xYh5CfmU~#,Nh|jRQC2bvXDtA&ma' [U+VN>mޱMyqbrPSPV_OJ{>뒈Wiu;&>6Ԃˤڋڏ Eձ˿[C-DL ړ>1׬U6 Ĝ_^6 M-#2 :$.`*. 5|񈒗sy-NYǨ;Mǩ/7kR7+/9nan/bJ}HQ;5E9˺'Y/=L¨ UɋPGeEjQ2%,e^Ǽ zG1F)܊)~KƺЖdH{x[Uk0m bx<+WVb ;p7#2%H;C .~t)iT)Z-s녉hs{Fjs؞6UmRpEi3~CTrsv'y%qv fz:ylV%Tƀ-3I[f{Y(ʍ:C;PsY.G8OXTo.EJwV勧0PtKE0j3Zd{RoloMdBtbxqa"7tuKs&eCB=tq ` I*A9518m_*;Cfw+*۷ t¡w,nUT_U ¦EH ,!tpZ8,WCu!d~S8D'|q2"! p߭(?Ʃy; ttkU}geyi:مd_y#ҕQw``Oq!oetJW)u7.Iv9V;4d{$BD 0!=瘮Ļr`J2p~(0+8 jgg}X5b_nv>+-فM&*4UK4M6Q rJ^ߛF-N&hzUV1GɁ{3gA.9HFGc:<@j}>fsJƄ= qr6̶ hCUnjb.H9: (nu$YF8IlR nM,Yz\ߞkHT14РLhmG|^JhQ ɪH ,8V ^m^ƲC%%)$3#(`fP|8u:6ֺ|Crnȑa\bYD$ zGI :b~َ<c;'A+s-g{s~^?L5JE2qJ9yC( =}iưjz0_>TKB<:HLx33FCI ҳyS bK@AE,-bg;{4%mHUڌ20dBCuY$h:[mG܏*H+(\qTc)d_RhIm1E|Q3OY:#y5V[mo+V] $ajC{8yk1nk3{d>1F2?$mx07FE|gg d?7.*˭WDƈytRaSm 9+&)[UJvb^G\ЅeD/h\,~.mƑ6IgY|4GD;/^owN96]5?TS-MT>Zˉh)E:C16ؙ qM#M^TcB,I|PAbε$ÿA(j e6/,نY^"ɋT(,Kg"f8_6D佬#s(ۆ);(Гl&-FWGw@ e31` `o<@Ĝ4;bd̠Qs38:r2h}xug@{ i?c~i!qBr9W r&5A%3 =Ϝҏ%~jXOCpP222avtbi2w1cjX~*S zocA)YWy_{IxyV \Py"|ǟX2;Qc^-V~D3!٧aR,Mi*\ՠjM!yZm?bp(g6`z&nw:YQF ̀J֋(T=gb-u- 1GqjnLtdץ)Vw~hΟoĢ(zxofCaiS}d}ʿm0OWOzhɕug @{UQ&2q۲i%B&} (͸ @ѡ ?zAdʓ8[JM,7S;!n3M ŕ+Y =G|bP=r_YwdcP6.uL%>%^njRm `Í^Ur%80눴̝":i`qٯ`4YS c?5ecp۫{ٞQ'F6ێ gTf%xC 7zOzh&ʩgDb,srnr cD}*A[|!rq\:k\76Hiz&&jfHl&xJ}FSݢ92C! =kY%bRcMYQ|s̟,27Vl > +T^gH&b6S:KX/"rLVRmI?ҹIƕ%E1 fjX,٣I 9ϯvCGbA45kn ;XZ7V_4CFi( S䖻u0b? ?m_mh" 3}4[fqmb)Rp C\&ªXV(SЍ:në;.+'9&`xQ >oS4grG-BK:$ji%d!j~l`Lg-qzn pF_5oܹX_[cy-, QȺ2DZMB|ycRsAM+սmb6Su^zVjg䰸f.uEpg^X:^ђ1N$ƕ&R] ^{JilvXiMi=,)9inP^Bf`}FhQD0e)xh*D]zA|g]ӄP ?} ֿc"#^s`tE^x꺹Ό?zTX֦ Q#hgOϕ,UG$PQ7q,ҷղnp{堪އ|Ab#I&,1Qd\BV>Xev*hC" F@s^t,:,id㠚K NZZd]mVL0*P\)/ǁ4qm:w|q v-p+ƩIJ'>Wlӏ j-'i_I:̒KSciIK_ObȹV']ݩK䢏O(#InJ=5WOm~8"Qz"UKkqNu /?F'Y`pX Y+ 85új$a Y~Qh|_LQuc%O:QP"l8nϠK0~ͿyM`{.ՍUx%gnd.cyk/ Gm}C x&Vcwz>kTYMO,He8{}/l-b6h2sVJ k" 6n8au,SEoM8J(I#;c߼UI.]O[U>atJJ?x֌GfF@ҐTA`ʚ? Z%Ԃx / P.FmJ}'ϸ:B]\$+3%$sPL=ő#&S cU4T0J{a&5]iCFpf{'Y9MʞU;9@_ 6Y lrBhۦU}Yc"qRroY-7{dԾ+V 8* 0d#IPQ8~ȦU0sQUE?@lВQWi#> 6tqd 1CÕl1: .^ࢄZrBYB})nXN_(x3$χ)ԽX:ROs_qW0r ˘֚¶ݲ6zT U%mOqӒ@TCx i#Gٜ9U{ զf^+$ZNAo`~B v+BR݄j2FuK̒"lkUcj> mlSO`ڪ@*L_[<{uH*ȴl6ڗ01~dig@k+.!ea=v3WGt}v%C$`?][Q\tNtTmc s<+u+.@ƸPkԭ*RSG]"Y|?0T2 k iR f@n3zU8}[ZIH fC/\_4{Gчj^|U{Sd.tYħ$7~ރh%Ӏ"ɂj!iv}!쑆6!n5=f뮴(ʹ-n`ahKɧ⇬J,qo IzZħ ?5S%y$`l=CLV޶AhJߥ)[jj@F8b+[v H! Y 8%J?E"ԿD.G$[f{V[vX|k|8O ~Νby 9igJs +wެWH\2C?#nq+Bu*]cP~Cݞ<2'Y#͍ 㴗#,\cC S x=ɊOέy&Xј-)qp8 p$u|}9{@(bayRHJsb/(Xb@^;jje%< =kî N΁(U"(w!V͞:??.u<V0%;mcb"@c /F T2"FWF?(j"ɧHJ5ьGAd(XP yHt* MdG]LS0uXK?e ӛSD~ s);,$UoQ-NgD몕WLoֵZIfy}ahomfXTlpX8'rjIUM Z9sV -To^q09uʽ5ߞt>fn*zV]Dy"8x/>@E牀$*¹qGT}2tJ|xx.$) Lq?gXFM=S7[J4:RI<VlwY &swӰN̘OS5=gHRWb^:jSQ(!?baчW R`r N$i$Ax]BƊr2|@jJN'0a9ornilP/XJQ& },v"zD Wܥf h2AUcf$)O>A[xG9#8F-"zǛ'.eq*3=?}-tиMc?@ZWw*"z] Wd 6:RRi%Ɂ#Ӱ/PD nltS W k `‚hò+{*jp+0 ;Gx tK$)+ Ђn/۫cVAԈ޴@zVms9ۻ\*om 4$HF\);@:ϐdqEuG.r1Q?R, 4|+)QnDUwȶ 8_kE F1/fi !Oyda~TB!{z=@L3&XU-iǬ*"/%;V^`Dp $JJޫIlQJ CXiF◱ Uȉm;w{gJ'JN=.<#vo5\zOP>r݉ *|'L :#$Av/ XTBC.0GفMrS5Xw- v| O;[!*o1W/r"3tVsY8z"P uxcLW-&>|NKRd1.v[~>+'މ,]J~f$qQm}Io9aR֘soFHj@ EUsJbMqI m-xOpD'R ZX.e224[A -H6h( WEv#g=Z- mBb!h߷ bVca[d߰i+*t vxqUShWhRYޔuӚJֻ!P.USO3ԙuY?ܖs% d.]BG #ٓ &?$9G8tR}{cv}§b!i㚠k77b2c>fVV kH8 6fA F'k^|Y̟ i@dڱwNr Z[}5HjHP,Ay)]B7b0XsiZzz5:rգ~.1r+ElhJ{[:oyjb8H7M#ì>aaT9@n#!L7Y))78ѩ0rg}GLh+).ry}a_͛/T?vÊ*AT޽2IjlimiRFKqƟ;Ҭ#ҡ񛩚$q0!!q1/K-Fd򀰵p9Q{ Vw;^i.+hIڋE"֑R96湲/$ȸ #ALM7Fa53ZMyLlKX27f l!٭9_OICҵ+rSfU- -1w>5THMP4 '#`!D@5،Ҳ۹%{yM{j qj_ʎɖŊ{:L8yw| >byR{%\s>8vto=Y?B԰ Z]ySI髡Y@nu 6h 5KΉ}M\le(g'|^OcX+tG$QjmSVZb1; H6<8&jI<- Ĺ ̗㞼]XS3 vt,^*晇@IgÉg^{x(nTWUC (?` 3k"{bm;XC93v3nZU}e gPiJ M{yEw(kƈ2^o6D*0D. XPP}ӹ7>]όH?2o[/SX8ᧃJJ)|ZJR<0aF]qPL(+!{Q d^Y[}wui7M BNAdz7-|0ۢ}AF߳--zV_97A=lI>`z;Ju䱷^v߀,k$hiStZ~Ua3-š`T jZ!WQ} L_XfHSnnEo1 Ԓ x  IO= } G"~G~R!ދd˥GP0mHPLt֍=vn #amGh(D -}:N÷ًc3oR*g:#SD`1 ,IE,tG ~PI6WA%t$ROrǥE v|$7▱YaƒID*aA.~loC f1(׶WiߞyJ,klhk8giD蕁7 0Y8gGb[ JsЗlZ?(KT9AP'q98նLEzp,yG`f)^ s :S;1mVőކ M,dP_I5@ F=|L7w/z)ZJ!j+ ٮ EB"æ>kTJQr`tQ_0}$aFs2W+Tvhڕә1nZҭiD67w+U(vW2@IZi%BQkp tgNET)|B3@9ÎpvX  mاѱ&#bf iBp?JB R/|i$!ٴE`n$T}\X%dqe9Q;Y~7tu΋#46h]q^i;͈*Jf />OLS~wn yHY =;["|fd-.bAau?Rb}̹nN[_ Aΰ7!>vM([_g@Hc.) ^S!v0 c%L6a,+C8乆itpY™ԧ912X9Q<[cXPK#TV gzH< *^?x2P{X.)5~}>A䦩3`ND) lk^8k?̃}/Oǜ X0o|^e܏}h ꗢx~^K<<`Z@| ݕ,r뤟o=ji;Tl#șjRhvwuJo-&Bi쉩@Bܧh*L 0 (; sekZJ M'(2 |`D~R'ۮTZlp˗'xR8NWlDj6q`OΩQˮ"7Ď/bڙ#HxNz_r.~&R%R0=Gb>TÌĩح'gx6' k`[[/Z=*q*׆X|#Br1{-;O߮`q|m\Hcwm@Rs0]%5Z*.[|Z ;Z*&^R>϶ ~9q`=18T>-<"ڔ2 DBKAno\ rCzb}tU nG¶alTi&3`bW4Im^b?T#K_x}tSgv|97)"WlCՁ@cbU-2T..iyJy~Rh^9B28~!{qh(C%Eh P51fS!ahQMVdE*=[b3\ՌEطiYi%J5U8Sg^E@Z _p{㬿ҨH.Nil񿀬 )a_4RxK o|>wyٵrЄ޶mk n֘ebqCrƢj'+1Hi`v5|zBNbX&6`X&MABV uz=2$Wg1 ! e* f/+VaC#ZxOrxiMo5>СE`DL<Kb0.p),8gh$ oH4{3-Gmߑw ~1@%l@7pQ?F؆[wW鴸ԏgdr9kmG^-&%b})+xAlVpN 1y_2~+q8h84b+!ITZf sb:T0=$Lh*B^MKhs,B5PFy&#&]x˘ӖzimS -6U?@d; oHN-iCt2Dt Rヂ1ꀧKVWl;AH xǯfi2ljFˁ]F$`jtWh>Og8[R ~~FR21bJ+  co M7Z\{|r~\vm##)?ٮbSCD1r<D98*%ifi4Q;$C"_)LKhYSõhb*p'R:4)ѳ0w}ܿjwdRN)MRrmw>Jo9߮9o6-Mͬz.\QBUQ@}mTTqO  )NOP_]w!(l|(3Z47`@ahzd]MqQ4SzsPeƊ֕W2 4vEn3@_xUXNl>'Z0*`{L {3՗' KƋ[zä䣕aڌ!{noԥĽ;uFzW 7~"jQ䒐[0|޴64q&،}Iycj1V% $c=ؾgLd3pT=fqsI(A~!1}w`(Q-tqe\ϐM]ftvM Z\F=$`mwho9M,[MȐL{1R4˛4\Cvj}'>wȿG;I-FL/UKގ5w!1_ ĕwlt&S ;Ж6ȹ:*z4yN "q_*] ^3uCJBZ^5=7]1D9zwYU4CnDDZ"6yQ-XeްVCN&h7p3մaF߽݇P+;$ }el.\w6y4]u]4>06Qі vh%t6Z8e~(urى]{'?G a&p, d^i9W:hnM=(5CWÓ/rM~6,a'chi@Vim֏ʩYX`\}^UXg3j}JI2FXZ*ܹ0cg{2S'Mk,-?@SVPȣq^KdR0\±)02Wo']ŵT%pJaw1֮扬 =Cg(g@@[ag[,ر3<;#UJ-HAo<,E8R(lA/fi2"-97'o~l2 L;[냄Ƶ[9*` 5BMs$3jZLة;Q"޽5%Aac2/ V0!839V^EҲD)U ݺr k{q T.%Zf[u4T$tm:j/E-*)spR ٝ$aXbu: l.:ݝqOiAsJ?=F;DӮJJLjM5Svw vǘ"o;e Y8&*iec! _hxS4d[r}r@\[uC#ap!5q>`Pyvi8GQz$Ѻ; :,40"K.ݷx(}BOb뙐CJWFI Hdhq~7:6|IsGj4r%@v9o< ߽w|$2*](Ac@ -E)&5|UHji]KHj9dZ?8#x#}CQc|M*gڴE/z5vjt%*qߧ0Ob$#QTF_=G[5 +4bZI#**<2d 5rVՏjZ!pj1}18!>>0#ҢR~Or|svN3bzho_K] B}kн*Khku\_sSLdh;'mvuws"XSgt(.)e'iSBt0nu_$^`&!p(9j\|QH5نgqa|#1dVL oĈd̆DJw}jIp'TQfLCu-<`iY@;B~F]׭!8#˳"o.愈Xvz*o(cy$e v㠶 ώ [v?+;rEhBj{(D\Nq"rN#`tȂU6>S)'&= z̢l6;!+qRlCB>nIUEc rV:5W?xіzMLuiʒ>>^ V qnΌ3[8ȟi:*|1,| &.=Xks3y"},C0~\H9"hu~-"r< zZv|Ņh\$..nl_S$*B 60p)=QXNEiw0Zi*rOlOrʽIRoi2[xhoae椕+|[^ E~ީh# s[׷.Ia&!'y)Oa_"">+h V:sH4 M4-66xݽ`_*ІŽP17KV}&' @il>;t@5K2HJ_ ƯǾ4x[~C'FgL.t?5҅8+5h.@O5?}.gA Fn9U2g=ZP~m@隔#38-;9CkB;2[k%%p߳ )m9u+ spHz]'%`K?!L7o/-m̎]!E ]gldG b+U նՙD*Y8Yh7anI^1>iq'aE5,tUl ZкP'@DP],XD_Hw~G]^~cgf&cVz}|*`1M ARH$$ycH^KT/~D觼wm7`a PASKeb-R,A|,dneDCnOQv 0]SV.'8v-I^7~ ᓻcd˭m/Dguupmf FZzO{eL3F$z]=Q,c tZ(\NLNo_h$FJwr,˴6EA}'|fXۋ/Rc BNVc wԓ*ׂf饥W}v d;Kʇ s*8&"c`B~kkCAH@_tv⚹Y=BȦ cpFkM2ŹqxG#`yoPU^ov+Ԣ#PͯNo=TDCk"3bĽ%z}:pCL,"lNB(uM %I )f`oKX]¸Iu,vLL>O(C8;hF)m=ɴ7IwmmJZ7Q7 ʠ)L|b鵮8ukY% MjFRst ʮ!LyLymݷaMUy{ pN4 :.](0ʚ b?xӮ>i s̫ ;Y%ür~g^=z?AQ4-=h2E wޒ$ ?-d(Mxv鴥/0VǝDcl'Tpa>1f$ L(< b*sYEUqBuU^C|YnCW= 0.0{}=ks56*)Y0di8ɘLpA]I.[v]רGkjIʜIDwgd)=a9K2C RpN7ٳ݃&A- y+~qm8²B;`j>ʂҧ)R'@^#G3=M]>RL P'_GƏGܖKs.<4FnzSM2KHK2 n3.ijl4s$2Sr5,Z(pz$KD@`ō&sXl7;qy51`٠. G'p6pJBzUӝ<;']†̇&J7GWqCE#>+3w4yR9JEU;2xdymܦ2Ԃ;x !C)vO˱Lx6hZSL|]GTxrtI!ތת'.$eȑ=* othCWkh#* ^ym[?HcXf@un!?mu5MEbjGeqo]JtDiLAl׎S8Li8'd"m߷`^!'"e3_üG1reh 0 gn*!yPu|sB%c9 ժqV*w36 (EYN'lV#VY | 2%Pm78Fjly #b8UiC>ek)uxtY">ԁrvպZʻ>GDDx< NkA 4- -2iXC(XoY 1eVПӞH1-D댭E1GUp)?G%<4S}8؎Ov3M@Zm{DZ-a365 /gyoYW(ڭy8<^@7bOl9R\}_4C]L큟_ Q\C'׮vt"l4Ω{ `Sx*?Ej 1QE&[el|<$h2y0%U *o2sLDޓJ"g`sײÏh4Ą}@:&nK%q^h"oQ@>gwzX3,8 <1Vp:3'kY.L4G yF=sriE^:C@NXManBxU>Mle$I7;ʎ{=fv0qE A*bwѫQ.]bo)f|TM>χdCQ`̛ː 3 $?es0FAM}h2XtdI6ēe9ord6I F-xOd!lNTՕQjԵ$ aϞOt>Q0Ϥf(qV9enzэ粃Kg7"w&AjW=?U I`7?dmO34͍:OQ׸^@y/5y2{v5O!ح'> bqf,~UY\n7_:Zd_1DN(QQk_9ՐEhc4YsCl<8)|_ʂN39~i>NW?j{ EU?*U괮"I~ʫj1׈(&\M %ƺ}u 3< w:'XodIM2hb 42q= n8lX/O%Ԓ^Q6d瘳/O>7k=& (NN39M,Iw)lqIP+r{c,Hu+ ΅r5'CY6{wϲ.$[vzzq/T@w+D# h6"vˀ*$rDv˭aNh4j1=k e+yXJcF:N\D~ְv% pɛ0(G]5.\+Ր:Y?zlxØA\c" lA~E\MI (!mL~2Kp uPy/ŧ$-zcbĆ6qNAfu RMoV pr_ ǩ!ryFˇp_qzy- .š ϋ}EJhCq>T]=O$"*rwP , _hr:y'w 1̺3giW(c5xwȬtLoIgRdE몼Cڭ%4\fqM٬oQitJP1fJAOi,Q>|}7lUss7*~*:!U$ / 5e۫]_'k#G^j{|¾kcl~bUA(Rd'Oܞ߰T F~+1],$SA8k[p,3Md4G1i!?:e1Fw"Z&X܊aRݼ sFqRQ`~9 ' b4WzIz=qXQO>x| GsрX~ ny[<+b dI}KHg%hpPqY mN3Qg6r2 pj9o'y,(Ͻ?g-8,N7A?b4"bPI2a7%@D'F|J5NMHL &> 1A>+}b7# kAdJr&PàI^mm(90y T3?|YG2 <Her',@r$zNB$o\!}E}ʖ˧w Q&3>ap\]DZ=Yl~]dcÌƯK?vP&Dʏ%"BX$xWgt|r՞!w>]O;$.|R4s[11t( >a6>[2AV6"͠.d1 `:fH,b#[a]@r6FY= خ߾o/qTTPw&67>̡2ɾ5S <7MmyC? ('N<KO:F^[.((>+Jܖ7rXހpC-5I ./ n@f`CޡPNeZgin4d _-MgrtF0`*ݺ\#.@ c+qf*3sAv= j{W0isN/0UT gGd{*`_Ya&T ,ܖ}/-8h#U[!OWy+߃g<)烰S~B6g;p'|{C_͙߱O[~8؁))]s 5r"K iB:@ f8IUY!胫w1a ''yq6ʁHuzfq!,"&2۷Ը" f"CA[_?|B^젰D50EyV dY 2n`}Ҟn7"FM&xu]6uG#LKqjL-#yOMS3 e rt(SnSya> 9kz#X֣᲍;Wۍdٚ+_g)?gpwހ焴A odVz9U|K^W8?F/-^j4ކHqũ2Yְ0<~Zv; WL-tdz0DZ6r-qB͂T8O-Ƀ67)gR+OS!Svϥ[(بeEj*?פd W !~7u^<%K&P$Aj]%SK8ƒIC2P3 Amm=kF 1V(0_A 5eM]ƔM:o"0#߸`~VPom9 ݑ"mrSK:YLLBLΔF 6Ξ h\,vTHl3焹$&>lVa[#Wϣk| rNQuFxP*l2n4ģoub>"ٻ04_=,ZBUhokui):EHu5ē =$J3H ̣+EG.uh+uVOd :;jw3YmDݫqRg\{G6$H9AggXۆ5w(bڜfƤP r]/4J_qZn}WtS,yY͉?>'/^k~Pq aBLnfKxtJ稡OPhWp3[ zb;G%9iƛ;PUA*/jr/#sQ2رA^tT ~k9EHdI$MXϲ8:4|p$ gE {B9x/5Ma"؇G] k΀ډ29("`DD Gzn@zbmɑEvbh$UǪ>{T.'{$$`MTlf\P5E] 'B[%{/%̠Ͱ2gȹ-NGIhiMDw Ϫ?iْm$95{u[Hj0?\U~f\):I(@ ˖k?%}!MYekMbOG@sy4_s-$֥2jyOʌfy orE;l=?vEY=75.sU1=Pt_Z Ƶ{FyZ k樗OG,/QS'zUu+D+.2;/xqͩSr]e':iV+Qj wnhCרtc8S=xAoh$mɅYmXsXC 7[A%;x Y$ UFYeԆgdIe1֖y?y`G:HR$גcZ~6*Aݍ? c,WD8i+?Ecy4njI$2sGőT DprF|"hiLi6>3FA2 uzmnU-peV]^G< m݄oq3<(qDDce @JAОH`ybLs6 $_x\ipO,= %21Tm Da$aufsʗͣ')LI$kioCٴ* D1y`NSd`A:kᴿ)%8Sг̦e y O6dyVx,w,HO*㞊`=~~Dberle.~d>+g'A6ԒqUns;_r94 íO̹YMͥY+ZN'q=Q",g|cRb*YZx[$(U9=DɬwZimzLAkD=*&v~ڮ)RP'I],y {d=]Nא^Ӕ^E=|);M飰5֐(e4 l"P&y Tq,;َ:m~ܷiEK%p;Licu P? . x?(DuΥwkN&[l?̌W)t' 49} YCwIfhMH&L73z 3W@P@(xTλ Fz<㲽s*]/ա *J6!}M Ybf_X3tw~EV90!@l_QlԇbVKI'$'Eϭ م3Bl1Z,!o(f/,JFkфct^Q[{A4eTl)"lEG;'JP+7kҁv؜dz)~eVܺ< F74Z"N" ٜڡstNl sl@UL-%j٢ddleA,CSnᩉB*ypH嫞..f`,,m4s.MN<5>r3u%l;!9t&s6~NcʵAvXg%wۄ .^Y wwUr.}1kyln+PQ<<5zӻ~ Ѻ 03+8~耗Z{z@Gax}nnfTe`(%B vaJY9{u.BOȉ_|m*w(XvrUԛLA)Y)}i_Bݿh80 p97Nq 8ࣣ'xۺҎLx+>Xv #[+XMωZq=O-Jl )75{vMfa+l2D2,|*_ƆsJ) |k5KY@!Jacx`F@9(\rt-ȦGcgٗ-c:?!Rx4gK( M$tyMV:,%?^8z\` $ZaPqɯ3{h #ފy}spk/Ը|{G`r>KHYa 9: /{g'cWF e=.uhK8][DѳD D=צp#mږEK DM:vbe0DMGf_ ʉviS?AH vKQJw}i6tFP|̋1=qE:vx$)1 !+o&:ۊ0!=1*6m{ Wފ(=، v'X>5U#5i.Wv Cfb0,绹uvpnj~jsOؿzG-wJV:V ւp %͓.|F, E&94iB?F}W7&}uvbduKaw.nYlٽ%sܡdT{s)ynfߖ+)rugb1hP5k`1Da_୘_7jL +7 I NX sm5*E;v !oQ?>fڙ(xKQ)GE[&^ӷ3)N](o /2\3R0W@*"~ iX$a{P9pwُ/ [[-{o4QyttׂCuZZ 3 7)/ߧ E}1@rkށc>}qty=U-eWLςU` t}@d0Y!l`"МqQn/Jӷ͎b94_ E* s+:[}ʸh({3u&5hŸߜqytu^MEq+r9 r+OrEIVeajtqki-8㿁qIWZb{-p; =eT6f.?”e=`£1BP=poG+1$K7[)6FV-0OO& d )uќ#Km`v\Kq ;qE_ "^!{[kM&s΂4 $4/7]ەjpy2Kn! ˎiAE8P&SL63K;G-E=;~`jݖPFҫ8JXF d~)0 rVK- !O0wS]xNhl<F%Dh>b7\ӦxmE5B- $qrppkk) (Bw I |eGڃ?vΣF]r)TZDf/6lw=|KPɓ[vW?5\+;-|n#BFQ)[J/kS&ǧ~R)b9ȎC'3u%MgҿIJ앩o*(8pA_Ϋ@-Ѯy\x}5]/ A'AMA΋AfB' A]i3ۯjW_BJ ωsߒ!}7묲h2y p5b.fp֐I!Pw>A6BUUR֫a?M9y4b^8-3YN7\h_@E蟉`\/U K^<J| 7l r̽ڳ3p{)zWmJ81P͸HM5USlӶ .t 0yJlj[ΰN&#dP)w@HwJw!CұKഗ. ޣ1'Y GEW D lh-+25wYDS2[7E) TBc7:MZj; e]";.q&8qK=GB~TQp|MKϊHniNsk!c10#z=ȺrW'BV|mze8I<+J!+!MW-8Y7fW(ۍ0Dn'*Qxוݓl?CHfiɒR(L*'$pNztQa7v(/Gh͠q~]t4lN%A,,Xtv.H ` )(827Fgnpwu,TeC'v:^+ E7s9C/twѳ,ߑmU3bW4: fog?NlF C0 Y|mt!vnKrq6Se2#ț$qWrcfGH迃u Nzj:^ᒪ%ֱ.]A,ũtCJ!6u9`C_jڣ'Q~R`#jQ=~aF6h!IQ[U6ݍ6f \F(*L^KL, ^,k2](J `er,{q%ܒ5;l[B>ʝbK9ɽŐ8\?G/9بfԅ(w C7i6N9ʁpP<Vcac2"#EQ,P͹RiNMWO^Rəd*ի}f! !1 Ĝ~-y)?Gh>DJW$M6ۓ$elkWX֜%Etxf$ˠݕ>[Y >Ӫm7wDt =~BӋ V T"r?e]gs3SI'ouL`f&( &=T0 hi{lטYLj jbXP#Nh/Ѕ73C~#sf/`vnnʿO0Y"CV_Z}[yD bZg_f*v̛!!֎&A<ɋ,"v{^>M*ެ3hZwĐ6z RUç%;d#)2}#wտk{n%lQr0́ĸdE0?5G7Sk\%Rr‡b?($n*N t?N_/<E.ʐ"qrIgN] 6X᩟4@"氎\?mo2˅.q_UAJ;i0՘;{eu`k@)$c{45!^g/zԽn#1 ZDIk9Hv?'wёB+[TDbM&Ti/ڋdk ^+'^ӣBWs4F`}6P=4LyNkʫL+[w1kE H6K`χJg'.^$cx>(joW~TfzM)GSWb\Lx#?ƍ-M^FɃT N:P$p=;Vēq9yg$^?̜& "1̫L..i[lʴ6*=Lfs-uVU`Sn*iwߩ/w8l~+8RgdB#ٻN3m<@=zjggyV3b{c,>LX 2Ohmkܵs;aX JY͚&(4Vc,Wk:8[qZR'jS2O[[YQ+І_5mZO6{h8ľ$at}g37p->Ytj][6a(#j vj0Ꜧc}XfS[h`Kz)M.4cHf0,/Fn/<ifɲtlw|+n\3?}=-!Dװp吴߈~! г&2\}PڪZ۹"^J[fq,ޘ~TGE"9m`n&XuMKn/OKtD*)4ġo&#\*ao3_{2(u?/䉬W{C`bOD1[/Śx$vNF!ijr"5x.®LM8>6Q`f1FR HMs5ϑ(C4oU$&.@ap_3W\>0 "FZEXS`4q7&}췈2BRvbt}tYNشzRo',jOC^ͷ;\2sH$+Jx4DaZ7K1peB\T_˔[-?jiL]a`n'vL)3ShK9b]%Q\'soҥ,tE}9LcZ03XǙkoZ#+ejf-74T4;s Eo1 K`}֓KP"-7f + WUz_Luկ0]A@ALu =KES F\+u=,;R/tF(vA.гi:8q$9o nD#!%~~+8+Z+6JZ{x7k^~ MZX,%kuCYbw0da nThH!mvlj+8QδD-pai#H+ C4(-.|Y[dI& |4a0\ly"w jPFKy*H7[jTARu9;0d** {~Yc "XBaCʃP lū-:N!) o͛z'u ֗e|F6?.cYrDN 5-t KH@<;L8ξke>HM!ovEUլIC@v \꾊~տy ed Z3R4H4aT*N W@_KK /ygQ|BuNcR>IgX 6AP`zgP&qSftcUev"l~)0i V~sWxbc2W '`mƱqC ]gfuI!en dzgYrCuD;TdzzC哖s_ͨ> M&$D#Vl` {a<ޗb`t-.pX|z@D ܒXy/mMa?vd Pb;Faf.AD =|2h:tւ HS@1EljNxAi 'eha1zqԧ"z*WuKHDm^߅h|Rb` )pM_2b{ 06Ji*I0#7Ju vP K#Ԑ@[v{=ac; |:22LKFx,e[Mo+ƪrψK椻eb';,HOu$Fg_h=]XE0 X F"jXv)x<# _HLT÷ wpGv:vp@FKo9|ku14I% ,ɫUiW`6[osA2~2O =]^/ۈN;E.¨3A1VD^ GHo1!y'uVO y1 bx>+vHo Qq_)J[\2i4BNjo@ ǟ.c>drZ{fܓnI%Od-D+U=H/Dwh$?uEσm!^㻝 K-3Er!Z>?C9/~ _kLN[ Lɜoο~(LNWJGm\SާWHξ !_Mel[5\^gV)0 kCC~3`0%pV>εY% zߨwZ4j6xRuK{<<6H 1{,^,)86*Ί-lM' ;wԈ<)@m7w&Dއ[My#%,^QՅ.説O2T|t?X\>HBRTwA=-b6t{!nBF`[t,g@L{ +QIw5ǠNT J7L,iRN.NǿA}<|Ip4*yξզ&zS4zM߈G%FTn`a~y:|Xď31z9\.JS omG[z!0s 4_=4]4gg`&>,[lGb=7uow%!u8X%Ll" I|a7fb bw3jCV$<5õ@n0{n2.8g0cJU)[Sny* ;lb:,]jpw;_Mq`Z5r5tJpV֝ Ei8[suFT @CE+n42;lq'A,ە-!V̜kӭ옞d9;[c",H-k@*6Qu>CNI ':*蟽|OWXz1*j`lƔ#u6]_IƃƹP፾mU;dBP}jI])+ZbUfDŽ"2%ltg#o?te*󽪚/pk^a8c1b 7AHDMiT=kM @M k)$kS eaCura`N֡}K ^a;eQ8#CinX)T8>bXH٭-%#j,d~nGI0L tSו6$Ĝ㹄f!Kְ& M9&eԻZ3K;J%yFTah Q[20B qݱEY38HJ^.ц '-JR 5=c1.q4)q+d_tF xFwQiGW|sGoخ3e҉:6yaz ݯGwWZ4zdRbY+Ra͊| dջa̧]uJXJa7?cO>Oiz{9;,!6*4K"XۺFh][>GŬ?[FC(6ԳaHn~n1_ekè_5)3> mǻӅcc[/fAnXĝH׿Λ '*% IEdϦ##@ Jet"jj !'Qkt-"]2\"L@K=ĝrW+j_F!7إRfn$i䗕Q y2ջgX)©.D&h2huc,$;|?4!;R+ѝ淚 `w& 9-G({P(}Aܱ+yjd("Q(io|V5vTgS <G [dP>hܕxx Qa)eVCgzjkʹ;|t~+/A#R؎)>^ZLQM =(H[E|ͭ@6 >È]T%PW~!mg|jCvE}'~Sʛ#ZH+e"l_1sTqwGkmN;fI˃q!t wc;$t35l{h8]qP;F h$7;ߢ!}1P k^dv,N@ ߢ=06`7GIJ{v5gj'g'U(+3YwЀ=6Y0j/%ES$'Ebu,Q 5rh/+6$ -\BAEizZ@,2;}lu;>wam$!ĩ:#vP6`ޖf^(z6 }zVy$1>|]TuWbO$"͎_F=X8q[/}ȫmvM;^G(-<ΗW.uMӰI B̟`6\q+w\3Zb[ڽ_'Me[RdEhqdZkM2UZ4mN u.F?Mh d ?L/U_ Y9Fr3(g@Ak~oCvFhn\-̆E?1lm3-m@/o۩EË Nۡm48ݬ YǢ9W1o5zvk\{JDL>sxJoϔ슀\^% q>g^?KNJ B Fg.zJ{\V`'x;_:BղԏBzWxvw֨ k3sr.Y@0GK+| I&$]N"\b3Hb: ~3KU&VPcP8G9QQH=ƤA  ` <ܦf%L- 23/^]Tw?B葰Ä/=2 zz7+C]#M]g}Pxu, (wH x*B(}Kt+O 71you!Z1F^M:(T!5کc8CQi򛙸o eEZ^H/ٽhdjVU׸_?lP35ΞnYxxku| ۝.!+nt5IXTߠ*8bJ%?_̨ ? Iz^Ռ\.|.ƔpyML3pz":4HF̜V[.2x V|^ TyZ+A5[UuCq,AR}[ڒitSt!FuTpjCJ9|l!ߛF49847.HvՔJTAtP M㏧fyEߗ@&2@ OOo$ 3ܕ BhN*NA+7܁8g> 0qKr^ߚ)E_ƨbA͖m|f LR`?M"d{߁289U?O5)W@`D: ]YB _N`Sϔ/>"yRZFwlY, ]4Ћ-z^"FsFmlM}7Yg%.H"j'bUjsnMSH[mغ$շR$&4$"RB_|YK?l@1jr xG>_>\[9-:dA[{_열#)14Odp.NU@y㊾X~D*oxH'f ?mM+lY:H`ee)A[;Z7 #tв?RO`)j;λjB*?EZe B4sZ7 6]/]7^[v մFOQѥLL5CKG;.3]]b}3,j+| \8URl]hB` >g.Ƈ} R3_%8DQD*jBdi: ]w[SMBpwO=~E|ђ1GgfCy$ )kZA6H+L[?UΕyf0ތ1ė*U d5[V|qsSDU>?/ ?h`jYq5ڽ|-5GeY19OW\P刎N$y#4$йtF cGo&y.{Xl]yY N\ڈ!i{ΔŋjzD*ȼZ^62]BWuDJ_8Z4Ff@bb6(G}=)$OWҎyBYdC"9 KGF֮`\o@&2 Y",RVrǍ0@pʼQ `/R+ 1ViweSe`C SǷ+;ԳL[h "|3Gffل߬nhn&F=e9u;mr!.1yԒL|ؽeNu>Fy)v  g)^{v 4ۡEnnW[9ĚrBXg>N3ֽ+3*%h.V!Lwԉg[DԽo߁psaTǏTW9N/-tU%%B7x[.N!AA!8;`x6;XA6s7N(^LyKďCD|kB;T"mթ}=ʻq=Rڟ&Y'8SL.A!93ȁ'lǛ[LvzׁS<ȡ1ǍE 横7qJ8W h1q_1> oTLfG(iDa>֋oTD0Wysˊ™3 %Ϭ_1,&{p{]8u=~_;3}\%"or+lǭQ>f+ kLԦLS L~ɼd)|.#8~ysQUWQg" k׈eq,@lwzJh2R*'i1 P٩0(s.WH,ܞ(´"Ph0L}j+(N7PhbA`wY~I/F$Lc?~ݫY(m1ػ5B ]2CnRne M(tf z.K_a V`Mzo!q36u QT4#a/{N^ǒa+n\m4 Jt e=s@ Vv ^,QhÚ6t#߅>ӎ ߧqN' OF2iWD$⌞W NGX2KrsE ;kZoѬsI9.C8d!+O6AUSW>A\%'/m4w۸7b\ 𰾒[a=Te䓐=˘ƖXf 923lyEd$HZLc/9/ڱ\bѢ϶l.u0bۮS2u$s;7Z/^&FqIV[4mA@wJ2_ LoѥAlA0PD` B-K3`%0P]T=fH8:uTOaC͎&v^co g"mivipfkmUȈ5=>-1OKe $JXq ~Ԓ}kEC~qXX[}6婟`R_(iHS,C>F?2=T^sw摤t1W<([<% wVWs?,cvAĜztg%VԀ0ʻ( Ma5VQPgZ;M;gW` AfȂ^ħɾEUhc_[MUW'&NMiD P" ;?=g$j|*sFUsꮦ1Rf7^;eIɲ\Sx^<@GppW"ͤLc@,y0L.Zѐ^upm"HVd2zu&>׬O^MADƹӏWo&VT,8n 3>ZSW91M.yp/ 96Fj*'c|ڗ 0>wu# \o{ZmT\DEΧ5SV"]_x/Bwݟ++2@ @iǙ]O/+͔I_}oyՊPhG7CO2žaAF"x XwhPh-,|T< xk)GO@ՋhlJ< . [ԤbF;u`r@OA@;^)9&J|-Xy+$Y#+eH@EXFM[NzeS7THp}|Uފx< N8H5@d1 < 9|x"ۺ ?]`+Bt &hnBCv<8^Nwd%jnJ BjrZ zg<9Y'(HkU3UaN0^}*GYNeH &+vb뢊-=ϐ"D [[N@_='r~}Z;X[Vfc+FWڟ0*)*65D0CK,VZv^>q(7s93]f>MhfA@ i"Ӓ~HE??z\Bc\YI;@d.X֟k8vLt;%_U܇>FXKX &Hۂ `a⽜cʑdv߂(@ͥx3q` kv=d q šA]Xz{2E pđXy!VXA$+Hp*E\1uً8gK +Ci,م(t 'ƫz˖] ޢqxELjr?ʶ*9Pe#܍`! ^'b^T4sBq0bGEZdeʜ^ dԞ^hCy)sv#{L%ڑMi/7 ~aj:$"td/Xdw\\6n2Yv$?~ RN'o*}+릗 @ deini}&k/@ vh^CՄ,3O:$Ovo{Z;,~#ܷl/WtmIRHz3^ aE%?9Xh@" YF5cA#gwg93eAKUQ}LzSeI$*\> ̦)~߳i]g`07A~H%(+ V+$E :D+Y Ʀ=_6֘SwFODž؛\jBS;)_%|C)Ҳ *N'AC6T vJ+$i?p,! =t^V~Q#;cK."X׮ pC/XDqpyy ~ &KָׁH(Q\f4<]1*05QjdĈ81Q\Vyd@0V"d⚤ 71B5¹BV XRQEa"–ɝ|'s&FpNkf.h2A?4j9+8y~ϩ qW} 'g a˯AFmHY8YUϋ0.OaS/#@&R70bQdI&[>H#Ml3Z7_VwF=&}?s+Ϋ6, I H[J \#jYQ|H% L&<>6>!SVt yLPMCw;oH:8gN. !l] ي+2n,^7g?`Vw 1(ث\Gdf-uިXt_Z* U%9?s "bth36a7ɘU7Be|#w A I2B*(3f*[B6BO 3*?&N{ӣ2op1,;#u/5E3>[s(A) 65 0!]ikQPl!8椿(9. ;Րs9\B+u:y2沒 _[t,#춣̢S@.ykSndBX\JQf9AlܺQj͹sn0-b@Q{Ph- Vve_bITUݻ}7"w:+x* [SP|IƫoXǰ9odʬ~SdOeQ84 9m lM ߑ}5V:k8?J [ .C'!'johL%'n~h"?;Ə^ژxbd8]Ü1>fA B*m5 xLC%iNNSE Ouh0[U|h!>(l=8>cQTł4Kdmf.ͫ3]QlC}ء }fk.(!UHµ=ޜJqIH9WK "ۇԥ<9E'W7]5H/;]p 6 '۽1~,A얿؅߰)5 R+7{: IߊGqt[{zsVanDcxmHϩvBeZ5sBէ!xM/Ibߺ0VzH68q̱wRc~#ݚ‚G_m,Y0s 2O[#XVQpT9{k=7'03qbwŽv jdcdE˴nќ м! ^Dyӊ (g3ݥYuLH7zq7=QXV*~wb>:m9 3Ϡceh}k?%.|1˜ @<;jP`Wb!4۬3uJ8r_P8O˥Bg8I tm;O'L=Ժ9S-_G2 4Yf=hn߇?qX+XʻSEWrvO5bʻH)AM⭞SuUH4aɩQ5G+sbv,rrO/1 RaCҌ:ml(Kܣ'8<YO#Tm=.E5w8eEIX= 6 2D j\3wFYCEGҵzX7'HKxy&7Ty@W(m@H*tƃI|,PpDrrZE^_«@V)4GtDL'"aq 3Cs,6|8 NFa.Yjqұlm D+R3I&`;9Rvmĩ6XAE뚿IǍáHHZ101"Iu<\'2QY$g~㙩ɏŦy{ Uk zqn9ߡ$C/`$.ǽF/]tCHI- [lIҽ`A0(b8;wjOB5x@[&<4AĨWpgKԱ L %NUn ϝ> FFG69W'@IR;61d?J}| X0\|0[M'#G?o4n(Fsds%ޘ E9:aubP' }|汭 5Å0caG\C> dKq9!܌˄{~##اm'ĥ"֒vjZaLf=!q:Z$efnI3 _3AKt2YqjrXe٠PKȋQX,tZX^Cِ492iX@"#SOb>Eߴ̓Tt25CڪGYɼڟω^(\5NkH([ aVNq96+*FP{ѥ\!z-}/(A0q7A3r3VNt#^).fs_XDD͘ O[[bλUYVPӵ̇\(?Qd^q:ri b C h %Bg58jJMސ PR(GFCxOcu4[ .ھ[Ekŧj̳Vˮn02Q\9Ov̛02;:Q׸dZDأD/4PCwG-k"|[l'Jhu`xaaJkW|\8+şd1M1zbR<[nr[O7%湴޸.qqmyBm%%:.wR^@2vI,6:V4MV*<{å;M2iU]ҠW1_TMXF5B z:Ku"ܟ2H4">tdoZg'=v`ZLޫhZi/h!uqA<#fQ?v%.&=qNcC%D'w\EH#3zL^mxbUh39k2ڋ]L_M|bb ,[u_)a}$gVG9)ָ%(:_u\bQm>14ݘLOTQ)k x BTN-.%$Yvn%6ljQI 4Kb yŞ(InpCCE[:Ŕjrx @|ߤNxHx{P=(h96}I Bm %ܓQ 9+P19E[jRɯU Ys˃ND*aֹbMn ! g#yc|  Sv=ϓ3(-;H(ЕagKV.v% 56fH?-toeyDp"|?,l >]uV~t3.mГoCq|3-a›E y\mCilBky]|߶60A&?; SۆL +yF[B#B;W)"vv}+5nj$tű8\K{e_XTw:O5eSR\Vej_8D+ 鲷ޜ|bt]XdZkcC %+ Ƭ0l@Q.[p[өS;:|qjyJ2@MAj^BM-0 qhQ5.ZfQ ΅` NwR8*/ZOg?3vⳠ0Gf4u{[ݲT[-vI1z~(0=|#͓Ù8-ë}V~xԐ'}F\?YNN3>[67jt>;5~rW\K8z "0sfۯwF VO^aƕ,LbׇFفŬq[O!V$Q#%I],g9' ΗHØO\^dy9VBE)) IgvGhEvܮߗG!8ƽNX,|wԚ-Vbf/̹ĸquh?@EJ0IxU%;ӈ oT5>"2c/^ǯ~& ]Z~ L7q^] hS /0 C nnF[֯W:}?0x,uƃ7P3HͤR҈ab[>URyLJW4|H F6Ţ{Ԡ^Ddavu0[=Bo[PZgr]8I24&&+Չ>D 9愺Z\| ,csv`vC]vHT4k}0"cCDs2/'7(;SLʹ1R/Eo{d:[Aэl$k\yu%$9βK˪A ʛX$>D58iٓz;܀pl((pWj%2TaZƤf7 dUԷOM5QF;z%8tw+;W"Z(SX-I1k~_%` \kA΁\ky]h2)EAbMG[g+<Ϙv$i?/@a},1(Gy$3jfGV|M q6o9ǺSFlJ`b@SYCf:u؝S#‹6D|Ϛ Ra |؜|Kc}U&517l91e9K=2Ts 0[@g{͡,I5D74Gٟѻ1>uڼq>#ڴ$bnvs])W̑> <|W8Xgfg_T)Irv?J&N%m ^@fxGn@Жw[7,Ȓ9#`fBΖ|U` 9 =v];\'7 ?>1x'Z9l a &,~n°*wk㰎v珱F9xOz2{@kؓ.wWJ{ nJmČEnaaj˅ 8 ,h=.m6.#~ ~d۶%bR]UԷo]*= D >i[<-O茁n+wWY64H$zdeԪy~2\ᣉE)1?{7a.nZxW3[PWT4/Ģ\Y~LNdz̿ZF۞*'7WQ [[G8'ɀCpمk3k2znVؘ?L$b&&roa@TȢc#sh;d $W Y?~%q[,vKS&I%őCiDjg3L0&/gn"6&/!)Sz6dwyTG %""iP [ojV¤. OO5?^tI4̐b1AfNM3A}::OoeUɛcuU}/~Dہ5&W;X:m/'tsMD`Q6CأRg`ԕW=a3N"|5J^9x+A~mЇb> iD7`fMQZLmt 5 6Q`7S;S6RMk挱`iZx85 ;h_V  Kѳshڳ8jn2(?b_fcd',&8fwּ HAWo l _|lYUaFF̋evs:W /1(ι. 8hk`DD:R4oHdȃxin(rk 6[$M}WT4r~YEY=YC17sA 6Y! 1kߥD_/)呋y֯)J^;aC5# ~$О(r ߥ XKr;I#< }>Gs;m7C N9%כK>>ؓwZ%q.(p2cJ.Ye tW0}Xe3Flva?^rvE]+=b"slAKm]ܐO7!YzH#U`ƁLcUltL9V1r2#x8z7~%#"= uY!SSR⢬3V*+a!ێ,]7`ȨT*W=aLTkHc|qsJ q~B᠅u}?JWȧ`>:s6}xh=Vkuw#~~Ns3y?i`:џv|$ֈ}sBU)Es$TCך/{`KVLn]D1H!@ 1kW7 ga^@29rbĖRGZdG9eoMZд* + eSgŚh{nQvndfQMLt-WkRvXHñLhiF#:j|*4,)ʌ%-t)Nj >m͑S(5ӻ;F*kpwOA)pn5;d;(ϛs+J #8Y̭"n@b#j|o[扴.}k?À+Q)G&zMTM9@/(aLz1:{3ƎdA*˱!יޭKa!&}Y Ndw_r.p |AZ茁O[~" fDyx]Iɠ`[r&'`kDʪsxzSy$\,CETBk3`]AZ`:ko<3,)X>GL z[ibLzcqItDKے;RzYgAOjlUq;)o/id?j${W7Edkp0 i"ѻcY]A5DYePFwEWP6¸b5.M܍Zpп1IVN&@8_ҭ@dB u)ҷza8}g"seY1d;D߄]u)od\黣+h*ky*z Ψq;krx,:Bc{qQ㉔bKa)(2: /YYRM\$V2@[= `6nna[-8XY@/dE&$V1}.Rrzm3 "|$,1ZPxH/g̏cVt\t-srڷBF!G5 C^:шd Ok`_h/ ouA 0.$!HD4:}A)2%**iGD " !$3%`jsKsb(#LF>CqMh, 3;kyDB9y6n mJGe)uD_5}`(S9"f Xo(m}>|=kNuxsBE1SEC]ծꨛVY8@zӲHC,ĀV}ęrz> f]l'!EnGjEO f+#8Xf_Y+Ϻj,ǀl( զ0iQ 0h# t~HJbufI0#?AN b2L<64Oi4~`{~2]ӎ\V-mq~lnLwEC\8'7z\ FG` */W?StAP!X ȍŊO4eػl)ZZV H@4a І\|YZyl1M5s\)ɾ d\Bсŷ3,P6?:uXR*1W0ι Sف3,-'D]x* 6 C+@2y~i;/s\4T%/+z0D0+#OPX`$,,ebx@ dY?t/m0)$xr:SxX(LW!pҾ uvb΍I :cc@?:1Vc'8˅Ea@gjಢ_xF-lpʖq +P[^L8NX 3nfm8 ,bb;%JF_b?e`:# #RQ}0ҍn[+јOg*AD{M'ӿdp­&=R6?i5M6(:*e4޽WcԱQ"ΙCqSKz"Z=SJeBohЅ[)2OΞ #F;0,i\094oG B:X.B݄`D]^bɺX[o\3je*\TZOnړj5H`vѓqi<-"i eSc dpix.X19q/[-Nk|IHn?+(uXlc1ҝNyf/e$F+y>,;ʅM췉~1u DS  D5't{ՖMZ C8Xe)˨9 9TkE=O3`l+%uNz~ϻ3W^><#[4zַKejkjϺ*mWUZ;Ўl~ic*|ro(wi,uy<1$zޛNy0炸kgE.tfnY|\WOTQ^Dw?1œ@4r"v0wFo$ vFE=3z 3P'FmC]Io!.G!70 rU<¦F ^s-t>ז5ƪ)`4&zրWx[U5T_pk{v$FLw2H\s>?B3jwG@}o6Ì_0] X{DY"Iw,.nq~ƒjէ% QM&Hd55'D:˃ɟi}Й@'?W 2ՏoacJMatY.Еjۍrlhٴ谖U!4x|W4g|?GlO8BmJKeў4xUJjf$f*>[2X1^ CZ4qGc~>x@vvfΆ>n]b/S*D전S*)K\I<8z9 jJ֋}oz޲ICPhW҉+6݀Q e]lGdu2<ʕw23xlC;f'P=D1&DZ6{<;!B фQ.၊ھ,R =3YȜRu%6޵@u\ңw+c53ҥjN_RDJUM/A N'##HƸ YZ