sssd-tools-2.9.4-3.el8 C>C   HG@@BCf))U U] FXқζvq9$/6È]u9Gdl')])=>́hZ7yQY}ɦn[02F<6O>ľ\d7EZ_nd7SAɔ@-y [d9U? ) ffo g_{kqĨTԾk WqȚѳYV!D}t7Sz>i8rIP3_L$n7f]-E7 ehп޼IW|-ٰiLQ{X(cǂ9=7f8`oTOQջqNO׼а|e)mT.F)2JMKP ƌ)pECq l:Йo~ݐK&C#V,J8 >+m|y/O0Md/9tVamЫc453aa3c96e9dd85d71875cdf2113c7e3225eca94548594e235e20f53d2434c8b9d80d4fd790cdb6d93f6d22cc066bfffc3e63ed0302047c435bb500663064023026480e5a07430acda3f688f0f0a0544dfa63fe69eaff2fd62e751f4a47cc165cbb34398c72eb777a8de78230cc0c2a8102305c1f5e77cbc2bc2d54407f81db275fb4db8c5a41462d6a6e474de2e80907e20de7128f150dda62d56edb712a46dc9fc30302047c435bb500663064023026480e5a07430acda3f688f0f0a0544dfa63fe69eaff2fd62e751f4a47cc165cbb34398c72eb777a8de78230cc0c2a8102305c1f5e77cbc2bc2d54407f81db275fb4db8c5a41462d6a6e474de2e80907e20de7128f150dda62d56edb712a46dc9fc30302047c435bb500663064023026480e5a07430acda3f688f0f0a0544dfa63fe69eaff2fd62e751f4a47cc165cbb34398c72eb777a8de78230cc0c2a8102305c1f5e77cbc2bc2d54407f81db275fb4db8c5a41462d6a6e474de2e80907e20de7128f150dda62d56edb712a46dc9fc30302047c435bb500663064023026480e5a07430acda3f688f0f0a0544dfa63fe69eaff2fd62e751f4a47cc165cbb34398c72eb777a8de78230cc0c2a8102305c1f5e77cbc2bc2d54407f81db275fb4db8c5a41462d6a6e474de2e80907e20de7128f150dda62d56edb712a46dc9fc30302047c435bb500663064023026480e5a07430acda3f688f0f0a0544dfa63fe69eaff2fd62e751f4a47cc165cbb34398c72eb777a8de78230cc0c2a8102305c1f5e77cbc2bc2d54407f81db275fb4db8c5a41462d6a6e474de2e80907e20de7128f150dda62d56edb712a46dc9fc30302047c435bb500663064023026480e5a07430acda3f688f0f0a0544dfa63fe69eaff2fd62e751f4a47cc165cbb34398c72eb777a8de78230cc0c2a8102305c1f5e77cbc2bc2d54407f81db275fb4db8c5a41462d6a6e474de2e80907e20de7128f150dda62d56edb712a46dc9fc30302047c435bb500663064023026480e5a07430acda3f688f0f0a0544dfa63fe69eaff2fd62e751f4a47cc165cbb34398c72eb777a8de78230cc0c2a8102305c1f5e77cbc2bc2d54407f81db275fb4db8c5a41462d6a6e474de2e80907e20de7128f150dda62d56edb712a46dc9fc30302047c435bb500673065023100d0a8b223e49a9ca77bb999d49ce174a18a8c17810343240d0624de779d9d74ec7fd6e1fdbcf959041c56f26dcb5c4ed4023012299d3e17bc62c7108e0ecc7a8921702baf481824e6a8668b4f0e866d41d41d6515d37eb6a9f98233f6f2ee3d83943e0302047c435bb500663064023026480e5a07430acda3f688f0f0a0544dfa63fe69eaff2fd62e751f4a47cc165cbb34398c72eb777a8de78230cc0c2a8102305c1f5e77cbc2bc2d54407f81db275fb4db8c5a41462d6a6e474de2e80907e20de7128f150dda62d56edb712a46dc9fc30302047c435bb50067306502302fdc3b6facd47fc381fe9118bf366d023a735e190ea17b7636b94299c2096d481d435ec114093bc1d5df18d6002ff47a0231008054096fa6cbce144e6138c9be918b8ce8a386a8a55d1acc1823231b5cd58691b9bb6992ee39dc1c4a8195452728a6540302047c435bb50067306502302fdc3b6facd47fc381fe9118bf366d023a735e190ea17b7636b94299c2096d481d435ec114093bc1d5df18d6002ff47a0231008054096fa6cbce144e6138c9be918b8ce8a386a8a55d1acc1823231b5cd58691b9bb6992ee39dc1c4a8195452728a6540302047c435bb50067306502305e08c7876cd9f357627a943376262ac564cc3c0b949d7ed4077d85606f9d11a9a3f949406e61b6d7e72fad1b748d471a023100e38b041331ad03e870d25163e0372888fd8ae5ccdd26578f7b0fc0e213d7d2b6bb94d63149581aae7ac2f10b723a93ee0302047c435bb50067306502305e08c7876cd9f357627a943376262ac564cc3c0b949d7ed4077d85606f9d11a9a3f949406e61b6d7e72fad1b748d471a023100e38b041331ad03e870d25163e0372888fd8ae5ccdd26578f7b0fc0e213d7d2b6bb94d63149581aae7ac2f10b723a93ee0302047c435bb5006630640230563f3ed88dde1bb6228caa8e8f2f57330bbea16444fd72ea4db9e29cd870c4a2ebf94ea7fae9cc6aed338a0769671ed202302296d649306bfcb4228107f5cd078ca5d0fb0fa52ed875bf0f51512838a4793260e0c384f781b0b0a0f3bb05e11db8930302047c435bb5006630640230563f3ed88dde1bb6228caa8e8f2f57330bbea16444fd72ea4db9e29cd870c4a2ebf94ea7fae9cc6aed338a0769671ed202302296d649306bfcb4228107f5cd078ca5d0fb0fa52ed875bf0f51512838a4793260e0c384f781b0b0a0f3bb05e11db8930302047c435bb5006730650230549e86f0b5984fd2324c55103ac87904cf979642deef40044596d46f304c528638bc6a332fdd32b78b776011286ab588023100cf0ee00001eafea2a30baff2027187c56ba42cdf9dd96f1837c507347a166685ab36c8e8351af82e82d6839ee12248560302047c435bb5006730650230549e86f0b5984fd2324c55103ac87904cf979642deef40044596d46f304c528638bc6a332fdd32b78b776011286ab588023100cf0ee00001eafea2a30baff2027187c56ba42cdf9dd96f1837c507347a166685ab36c8e8351af82e82d6839ee12248560302047c435bb500673065023100d648ac5e34167809585f1fd974a5e253880e60443cafef8ddd7fce00fa6da188e2b1d9f76bb311d48ee65a0e52265bba02305f83978af661cd1f1259e4f065e7261aa64260f631e839ce94f16a91159f19534ecd11519981f633feaeb2042ecfa97b0302047c435bb500673065023100d648ac5e34167809585f1fd974a5e253880e60443cafef8ddd7fce00fa6da188e2b1d9f76bb311d48ee65a0e52265bba02305f83978af661cd1f1259e4f065e7261aa64260f631e839ce94f16a91159f19534ecd11519981f633feaeb2042ecfa97b0302047c435bb50068306602310086ddbaa2618f76be7bdb64da8e7e0320efa2dd3897672a24143f1320602c7b7321636f7e233e0ace0b872ff74aa2c0a6023100ea68fed190e5833af3e58b4e20e5d844db7c57df74784ce9a7231b7f7abbbdbd679d1a1b54bb1831c59ab171ff4bab440302047c435bb50068306602310086ddbaa2618f76be7bdb64da8e7e0320efa2dd3897672a24143f1320602c7b7321636f7e233e0ace0b872ff74aa2c0a6023100ea68fed190e5833af3e58b4e20e5d844db7c57df74784ce9a7231b7f7abbbdbd679d1a1b54bb1831c59ab171ff4bab440302047c435bb500663064023026480e5a07430acda3f688f0f0a0544dfa63fe69eaff2fd62e751f4a47cc165cbb34398c72eb777a8de78230cc0c2a8102305c1f5e77cbc2bc2d54407f81db275fb4db8c5a41462d6a6e474de2e80907e20de7128f150dda62d56edb712a46dc9fc30302047c435bb500673065023100d0a8b223e49a9ca77bb999d49ce174a18a8c17810343240d0624de779d9d74ec7fd6e1fdbcf959041c56f26dcb5c4ed4023012299d3e17bc62c7108e0ecc7a8921702baf481824e6a8668b4f0e866d41d41d6515d37eb6a9f98233f6f2ee3d83943e0302047c435bb500663064023026480e5a07430acda3f688f0f0a0544dfa63fe69eaff2fd62e751f4a47cc165cbb34398c72eb777a8de78230cc0c2a8102305c1f5e77cbc2bc2d54407f81db275fb4db8c5a41462d6a6e474de2e80907e20de7128f150dda62d56edb712a46dc9fc30302047c435bb50067306502302fdc3b6facd47fc381fe9118bf366d023a735e190ea17b7636b94299c2096d481d435ec114093bc1d5df18d6002ff47a0231008054096fa6cbce144e6138c9be918b8ce8a386a8a55d1acc1823231b5cd58691b9bb6992ee39dc1c4a8195452728a6540302047c435bb50067306502302fdc3b6facd47fc381fe9118bf366d023a735e190ea17b7636b94299c2096d481d435ec114093bc1d5df18d6002ff47a0231008054096fa6cbce144e6138c9be918b8ce8a386a8a55d1acc1823231b5cd58691b9bb6992ee39dc1c4a8195452728a6540302047c435bb500663064023027783d4d0b1b5b748fdb13052c607fd1d79d57d30e26a4c1f3b912b5f110ecdcda3ed62800dee0996b0d957584b61a5102307822bb75ada17c27b8976c7d7b0dffd7e8b8e7a6209e1c354b906b90f709349d1e951e4ff6efb0b5ccd406b795beecba0302047c435bb500663064023027783d4d0b1b5b748fdb13052c607fd1d79d57d30e26a4c1f3b912b5f110ecdcda3ed62800dee0996b0d957584b61a5102307822bb75ada17c27b8976c7d7b0dffd7e8b8e7a6209e1c354b906b90f709349d1e951e4ff6efb0b5ccd406b795beecba0302047c435bb50066306402301a304c4ab3e8a89bc85168ac4e9db9b3f126d654d5530bd6f982964a30c7420ee1aef4132db6f96b6b9879e6008e249b02307d3f7e0a44d4dbe56ce8a6765bd5a3c88e5523dd75245cb3e637ab23deeb08c3564783ed7c5890b940dbdce49b1fd8e20302047c435bb50066306402300942713ed604da7ffb83ab81d313c7d6b1f42afba2adc6e92baec1fafa6e04145a829f2a921b696cfa82ae62e9b064aa0230168cf7d36d44b0a4c80df4f88fe0a1b563e44409906b1916cdcd9927d90b1f1219191755be7a200e4e8a7e634532762f0302047c435bb5006730650231009660a861dd71228b20addb39d6a85c393d0c0e7e7028ded9eb24945c8feb97bd916d4087d47b89fce5973f6fbca59d9a0230140604918537440094ce15ca9dfbca2e462fef564841f8729c9e9202f78cb46f08504667593b629b7a353ab01711d44d0302047c435bb50066306402302875a2729a4d43c7c720f5d588cd2c405b7947c984a4f40426b57ed4b41f0a52fa3a2737a87a8e3e0773796f6d120b8902305966aef7c3d2d4627427fc82ef1a4850a037fffa4206bde872b945b9da179770418dd096f419f58b3feff8f634dad9eb0302047c435bb500663064023005285059abfdb340146ad42c531a87bc60e268d973f3c3b70557986359759f660ff0c5810e63d762fdcc78be77bfe38f0230515ce0fc018565169e5dc508dea6571566ad0a52b5a51c95dacb3807c6bd2e597bc50a37206168b2050d1be30a28f3fe0302047c435bb500683066023100b052d039f6d8401b3054152863a33f0534ba79f6776d1ab149e31b612e389776f17f1bc6c4f54d3553bb713eb6099e290231009b01c91b207b369b0ff4680ae931a27ffba5ab709b67eea7f91dbe6527874148cf64c3a2f7ac37194178d81b86f619ab0302047c435bb500673065023100e050ada7ea40154dfc3b8be96e50cfc9dce3466f02e2e00f6c8be4432370979257c4e6ab320c909b2be2e4523ef69c5d02307f45619ed1918065395f768b5dc693b2a02fca175fc2365619438089c065a0193cec71ef00805ef88567a0907bea96f10302047c435bb5006830660231009a86d2c8b10affb44c75e533a663f42b72a2aa780d810cd87997a04ed0cbf10e69a44a61990987217ab522614795e9d00231009afedb91cc884b529033fff0c1e7cd6953951c1e4a52937ee7d5998df453075ae0fc6ee1ef9e0cf5daf4781df867c1b90302047c435bb500683066023100a35f5cf5023fb6fef0365f0df0c773f86283ca96f8e656b3547907d1761ac6ffeecb978dd0055d77544f5418fd4c3033023100cad69315cd9964978084d5f7b510292513014ed64a716a36282fa82c55ace204090b7fbf27167553d9011a730abf52560302047c435bb500673065023100ea8b4b242b9897c8aca5bd2782ad530fa21ca3d906640edb8dfdabd45cf4d5cf12c3e0fb722219e6fd912cff9e57702f023005d04027bc92b191840f2d61afccebfcc211acd8b6e7a152adc8af7956ee7a39fc7a973ed71f4ed6c8afd1ede3aba8fd0302047c435bb5006830660231009550e19fc45013038d495996bea08c325a2f455b514e1ceebc4b9cf75bbbfc1ba57b963f3f8e458c753fe6f4d44303d0023100b4ec06b7ce2ddee867193ce8a23ec711c47c222fe7482f9726a67901d3b3c36746d3c7e3a081a3bbb501ab21e4f3c4700302047c435bb500683066023100b6bc392a755f8ae1448c02e69a38a66df608529b579596f9ff44f3d3dd3757e3a219cd344be97fb7ff0d45b12240c2b60231009cd0ca53ac7ee346d36d9d6926802a17f38bf5f8a46b12ebb9fdc9c4067c0f9eba52cced2840a6e0b003855b6cf554720302047c435bb500663064023026480e5a07430acda3f688f0f0a0544dfa63fe69eaff2fd62e751f4a47cc165cbb34398c72eb777a8de78230cc0c2a8102305c1f5e77cbc2bc2d54407f81db275fb4db8c5a41462d6a6e474de2e80907e20de7128f150dda62d56edb712a46dc9fc30302047c435bb5006730650230540b6d3ac4705639090ad57d4a4f2851f29592105714ee16793691c809bebd4097739630ff3dbac735ae842cd7cd657802310083b07517c14040073e609b923999e355a5f90b57309cad1966355bd5ebe3371ad6faaf2a39ae514c1471a208b03001b20302047c435bb50066306402304aaf0d0d93c2843aa91216f4cda882f406e156db5d60d8907ce17150db1c16eba9e633554f736fd69fc3d0182ae7f539023046da46245a42a03627d498369f16cba96b07f38543af68874da1bcc5e2c5ec38f58e9073157774020965177c77c85caa0302047c435bb5006630640230260d4f73ebb9e3a8fa3234995b3feb4dbaea9fed167e625441511261105a8b49d2b6c964b5690e8677dca2b0d5d765ae023078fed34fac06fa75e48481a2e6b58ede606d1dc6eb60710590a9041691637f6601cf86019b6933252ad7881ca5874d130302047c435bb50066306402303f2dddba78ab1ef2f072a034254b7480d407f3ace553510a51f142d3c09e84917b33168cb9a77bc39629909fe86cf288023064695fad157494e16bac1c6a5b99e82fbeb1c08124957b32bf95bca1545e725dd3f3aec42754623d0fe70eea25a599590302047c435bb500683066023100a6113a22d344c34e451f86cb2508aa7088acb2f0a098843113de12910dbed5687495f272e1aa4ecefcd2fd3c937ed7f0023100ea42b2e3ef647d17ba030736c70b7cfaa26b5054871e03751b407a2ba96b9bf72f8f6574d2350e757f1a901dbe688dde0302047c435bb50066306402305156625113e6327c5ad3cb5390fd5bbe729cfa9d12ca5f4d6535ea95578a57629e885c3db111ecdaf473271f198ea72f0230038ad125318d6b15f192e196085981dad2b626ffea096aa6288589860c900a44b3511dacad893076e611dc458e2145280302047c435bb50066306402307d35d9b9c9682f6e797975acfbc7d2d66dd7afb2bc0ae03a8d4908c4b16a9c7808dd4879380a51bb8198c56b640f335102307ecca55bd653eeb157d503cbe15eb96aa337f507fca6aa55d5af8e97ae8d1c3fcde64986f245f827abd1e51e3c0faec60302047c435bb500673065023100c60e93611e6ac34c5892ad473cb8976c858484528ef6b42f7d012d0d902aa36752c4dc734c397f811f85eab14c42474502306a7523f1b893b24c09650ca33a6c22b4041c803ba39988030d66fca85445b2b3b00b5d55a2ddf58b9c43f6a8bfcca0440302047c435bb50066306402307f1093ba02a011d6299179c1090cf8759f6c606aa483af168518d6ca4ba3638ca7547ba957e1efff0a14e086058d2cda023071536332f11e008f4e6a2b6b42da0db9655e8e9023207e1270b218b9056d9bf84636711341f97f31e3192e49d56d13e40302047c435bb500683066023100e046d6e56a7f5d4eb629cf212210a7b80ce53468fa3784e8c2759ce6703eba702acac9ef057b9ddf485d249cb7e0f15a02310093b68b7ac10b04510b7482cdb18afe983bf3a9e8f8dac11576bbd129c2924a1baa0958ccb38a4710d637e37b0ca71ee10302047c435bb50066306402302c55a1885392d15d1d430723d7a52e2d6109d859b06280fa97c61f21379aaf6985c93e7d42e9f9f75652c3b3d7fbc843023006ef474f362fc1cd983b39f7c716195a64072a5d849939fb871f80f863c4051b54a0907874183e9d0bc3c3855e4cb9a90302047c435bb500673065023079c31848c5702a128cb00703051969f573c77739307f0b63f8e41bf83f51fa80762d9b6adc50fc8d1dcfbd5be9a07fc4023100c3a1b3dee8bf472e2beed3f93fc89ae52a3f34d76285ad033242f089a2c507eb9693bf68f07ec908dd4d2a12c1ac347a0302047c435bb500683066023100f68c3dc843cc5d0fc5e4f26e3e370b030b8023d769d2b891d04cb650cdb7b11d5f6d245b2965878e8681982442b07fe2023100d5f864be9cca532f1100e618005bbc445e1a3a907de8d340e2e0bae95dc0173162e5e06ddbdd7b673fc1c022e155fd210302047c435bb50067306502306b82eec53512685ed8302c14c035a445bba07e37bef728472dc363c38e8dabf5614ca9fdca538724d3e2b914286d127f023100cac188d11317408ee01cc228c904427e79d8be18f5ab84fc5054f81d7da17c4b396aa5df9d44177cc284268061e968cf0302047c435bb500683066023100c235dd4955ff06fefe061269956b96cb368bf11d3571affde9236add1f5e8f199435a590cc31fd2a3b385dab72d22909023100cd064e61da8a7203702f9816256214d3216733dedc5cdb610b65398e8a83178392f8c1f290322d9403b6ca321d1311b60302047c435bb500673065023100ebd3c805b3dbd2a6568cbc6e53e0c1c475d14602caf308f70a8148c501987d220cb998fa71b9890b020af0d3123c348302304d986279df1f92272cd437856ba52891a963d2ceb108e7073d81547d97a2031eaa46f7657b8afbe9b49dff1649ba35ac0302047c435bb500663064023011ba8b596f5cb89c319551554ec115936022e65946699b324e54f85929589f2543557d527d2e366c4514825c71a505c5023038e2b1115af9c79a70fb9d62718f76f340b08d34502c88143b0513bc932dbcac018f799381f2199772e4644ce0d8b9be0302047c435bb5006730650231009900c62ddd61693ffce2a7bea21356103a94a0be3607bc5081eea86659fab968aaba64141051c61c65fa0de3af2d44d902300842373422afb1968bc2a45ce3c42d11ad1a83aa7611955e58877c3b589ee8179b19d22f22a7a4b1cb31f95e0a9519e50302047c435bb5006830660231009cb7c073ecf5fbf538f2781e0b5aa858f9f40d0e51d504612345f9a63c94ac1eb05c20796594f8ffc12809f232607912023100e53ac193748a2e7ca9a0c5d9d5bf838331fe6d3c1de95c03f95c34f8fdd6b987d720336230fc6145e217a458f8dd8b680302047c435bb500683066023100b1e1136047d21fdae1c5201b8c40f82dcf8008b67a265f138a38fcdd63dce5cd9d1bd668587bc10dfb05857323b8115502310083097b27a3f137735b04b82b3e4107a584cbdc5d2c35f6a8662cd36719c0b622dfa5f734cb3f8bec9b96393d64f7daa60302047c435bb500683066023100cc2f6c98d2549e7e91063a6d17b54a2ae4779343a5530cc2d49f023d7df36de26f47fb09d98562507595000d93ca86eb023100faca5f2033e0b2646807e0b4cf2d4d02b7dabcd8f566722159db01c56b8dfe1cc2e6ec99352e9e1ab7028f7d9fb4d1180302047c435bb5006730650231009937e6cda74934ab6c1223871a3bc161bc4ceb358e7169991819bf04e4fa949050d3699b7a11d79441052416a9d42479023005dbb9e8690c68d00fe6d291c613b1f4a36ee356ac317b2327a4d97f3eedc6493910a22142538fcc5ab4760ba55297220302047c435bb50067306502304f4fba4ac0efb8b39989bd66e88f0e6449aab011f6b0ad7c6e47710f0617a187825d9bf6e7b1912e7294cf856ae48684023100903c37c4e0985d971212f762848f386498f3ea4b350d029ce4664ff2489db92a8b8652ebe89d44637175572afd1e919e0302047c435bb50067306502304609f39227078a8d2563e86ebba36d63ad436f575f32ec89ec58463405c2facf567afbe45048c0340cd8675e6d3735600231008e1d26fc82a707846bd57b0bd269e05004f36c4aeea0ae99b28397aaddfd99fd0fbf89f64c07f1f7490ce9052dbf53d20302047c435bb50066306402305c94fa70c004b7213548028e5d4e73274c63973ab49d986fa703adbae2ce99366bb025a604a4af76b2d71a0d70c4f1b6023069e805e5742eed537f9359aeb7e9d06bc42ef8181bd1e61923f947223cadfa7a53424d9cab244eee2da757a181d112c20302047c435bb500683066023100ec1a9ebfed06faaa562fa3b80a4ab9c2678c39226df1580bcf1b8416b5bdf62258924240b69be94d27f2c513b036f680023100b68eaaad487d2fcc2109779339fb3255e2c3c26855b5e753abc2e32ad398bad1af82a8177f607a28f11d6691abd5395f0302047c435bb500673065023100c0761dc01521b4c0ef58b9a8cd93553ba9b2a7c29699d8c280266af39da7e05bd6c7c8c5c9c84a182b09d1511656853b02305a1d4a3c7fb9dcd7b96938d4aac553619f2087923ee4aabea3af55ef3bdbdc3786b07717bd95afddb75c684dd51ad07e0302047c435bb5006630640230767e780794999b6b8ecab3231ddc4fc14e2ed6c614e406afac9724dcd10649a25da43a6854f9c4c98e0bc791bac53b2a023044e7fd2786364762806a4a9265cfba0bcd28bdba177a15add09757a365f7ad52317c1459d635abb0447329c41a17e1b80302047c435bb5006630640230406e0f079cc599931baa3b7d08d854eed9f8a212cc2fd0edfbc4d23ec340b3af00a581d91670f08a31ebeef425bf3a6202305cf1ab026d4eccd42c347211e566362c0a5a090c46949dacdad4c453704643b87da44c936ae8fcb154f346e81228d79f0302047c435bb5006730650230364aa17f641465c409a1f7a2ecc6b04d1a647d547ef39ebbc369e805c300315ef5bf6180cc407dad6f5557e059d3901e023100b23f196b9a1f631f43362444a06acc4a08b28232e4ddb0a0c84c3db8acaed0ad2c5ccb3b650d002c5d793cf9459df7d4f))U U]JF4( );QzD!S#\Րro^-sm2-/F 4+d$*Xl(c+y:~ 06(}غ3ӬVCLN%PCTƺ9k"L!} ?+f*f$lGWrpk$Gҳ~j .SpxS6U5mtA.}8|gOA:9Z+Nϲe%M'ƴZј׈l,-eHWnŵ޽--6}4e#FW=jw8 +$TG/mBØgFIM:򦈖ZfcըvgXa ,cBA`pi7(PyҀf3|KKrS;/BR{M8[eGzv` 3m+z)<(yKלQ/]-3 :_dRu|'^Apt>p??d   ?X\ GG G $G @G G (GDGG $G@`:H:!:(!8!9(x:|G\GHxGIGX Y\,G]HG^nbde#f&l(tDGu`Gv|w0GxLGyhhlvx|łCsssd-tools2.9.43.el8Userspace tools for use with the SSSDProvides several administrative tools: * sss_debuglevel to change the debug level on the fly * sss_seed which pre-creates a user entry for use in kickstarts * sss_obfuscate for generating an obfuscated LDAP password * sssctl -- an sssd status and control utilityf!dppc64le-07.stream.rdu2.redhat.comBbCentOSCentOSGPLv3+builder@centos.orgApplications/Systemhttps://github.com/SSSD/sssdlinuxppc64le!qq R R // [ [qq!!*x 1 TxpKy$[Gt7 HN p 0b# AAAA큤A큤A큤A큤A큤f!Qf!Qf!Qf!Qf!Qf!Qf!(f!$f!(f!(f!(f!(f!(f!(f!(f!(f!(f!(f!(f!(f!(f!(f!$f!(f!(f!(f!(f!(f!$f!$f!$f!$f!$f!$f!$f!f! f!'f!'f!'f!Qe+f!f!f!f!f!f!f!f!f!f!f!f!f!f!f!f!f!f!f!f!f!f!f!f!f!f!f!f!f!e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855eee5f98e0dba674e4670ff9bfbaa2f1b2a7cc6d288ef02359a60c1c4e5d0b912eee5f98e0dba674e4670ff9bfbaa2f1b2a7cc6d288ef02359a60c1c4e5d0b91247321814547961602f62ca702121adc9170e32a4a13e6d8fdb0913a05ffbdae547321814547961602f62ca702121adc9170e32a4a13e6d8fdb0913a05ffbdae5c0667c0a0715f03bc4e2edfbb4bc35eaf5a04ddda679f4dc2bedd92b91db8d4dc0667c0a0715f03bc4e2edfbb4bc35eaf5a04ddda679f4dc2bedd92b91db8d4dd7f90468a89655d3f365308b567016b80190df48fcfb625e3eb0c403767a7465d7f90468a89655d3f365308b567016b80190df48fcfb625e3eb0c403767a7465f39405daf7ee757c4e43fd17f6e046f6f0d59b5365459569651e53cae3713231f39405daf7ee757c4e43fd17f6e046f6f0d59b5365459569651e53cae3713231e7cc278e0da5d0ac83fe9ee301396679726ff920ba1d939b66b811384c076eaee7cc278e0da5d0ac83fe9ee301396679726ff920ba1d939b66b811384c076eaee3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855eee5f98e0dba674e4670ff9bfbaa2f1b2a7cc6d288ef02359a60c1c4e5d0b912eee5f98e0dba674e4670ff9bfbaa2f1b2a7cc6d288ef02359a60c1c4e5d0b9122d2bb997a499ab7fa4ca135862a85cbaaabe7bedf73d09214d195e7428f071c42d2bb997a499ab7fa4ca135862a85cbaaabe7bedf73d09214d195e7428f071c4d1527388b4619d2ebc0752c41a9c645235fb3c58b5eb3e82b4c1f751c36ff3fd8bbf3f6402f93ebd7673626798f8bfb9263532407907cb8f3d2bcc86bbba34a78170cd384dc74518bc7318764855a7a30e67ee8c7e11d5d21fc49f762105e67ed82122c936ec008f153b2f9fb52e2e491296fff87eea33f7538a1e561652b279c2213728d475326b657d1479e9bf46dae662c192eb6bb98917cf92cd0073588ee53c3f06b33c90ebc6539c459ec8a21fd0dc92bdbffa1544e7c37c8daaf53ae6320fa35fbc4badcc77d42d6487887dd9200191ea438f9835be7aad014bb2ea969c816bdbb3d6e375a19c3e64afc9ff0efe82bab45c37d24282d76ec0d052d60c328e635bedea0a04ca0cdbd14cf68ca2b34a0c96b603f2e9b1bb732ffd4deb5bd61b729d836d65a30010c829e4803d5919439bc213cc9fb1f8b8bff29519d884af2af041d5c8f71b5681b008b9b7e268aa656e357d5b01e67dc018798f282176f3b63ec42feb1d0055bb28394a280135e5820bdaec5114ea878fede6c88feee78ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903ba39309b8061a40093ac796227e586245309cdf6234dd798c031bd5b4d304a80a3531f4e4d76b49e9f7e987ba5133abcd43520ad5282caaceeac4526a233ffc867c360c75de2656c0cdd9d49613d397148866a391ce16a20ced694bbee444bd610f54c31337a53d30af2c95b1beaad8ca9d846563dbcc060168396af4746db6333405113021da472cdca01bf722385f5a271c16e0f5f90b412370b7a6c9fdf589aa72bef9b16408006867d43c48baa8f6bfc9f1e31c9f96500237573b0c604f1114b750105ff181aeb73edfeb2e3a1608d8308a2ebc8ae0f1ae6e14b3533c759232c6252ac2258add5227c3c3247162ab423096cab3500b1754f3558ca3ab30fadb51d81551e04414dd30eecaba3b0100c1337f36e00e2ceab56e73d2134f8d70c842a823a6a40528b581ead190bd3ae0028b9de4cbc6b8113e14920fe9b823bc4a377b7349de550709d34caf501580557bb4982d24583e2ae5166527a3e606517f5a73e041ae4011d97587046c136982d4b4aebd4bd079626fc87dfe8fbb1bd5e60de743feeb59aca7ab0a12c5c6a70cd564beb2e8aeb3e4ffe50a24c7a249b855efbcbd29fac45248ae185460483dd3d7279a1c7f28cf7739bf0655e16923f53c18dab4a62018903834513301bf91d9660c1efda406da0d4a1793f3f5a4382f2faa19accf7c86e4dc1d95507242101b1f62af5d64e51498f881bd62d1c8758825b77d7f8ac20295d80853e1c4857bb50490c8308887a2b78b3d893656d0ea1fd57e48f785fe238631b00d86ad34279b4a0d6467332c9f5ede07f0ec1f7dbbc225375fe66de67e61eb92827374a02f911fd7665898209f097d72bb126ddee8b1719755de1b9a2a2b370fbe989e80d1a9d579a692d19d735d715590b1ed94f115bb924e39f2aab07366f0a7d1b9d11b5645b5726fe965b5c4a627f8e324f278c9bc62da628472d2a5a71f292c8149a0438e7f9b33d7697c37f94dbd2bd8f98ee353e4469ff1c58e660da6f356cfa78f4d056bdc1445c7f9f2051b8b8750be735a7384943bf0917dc62528adfd2423579f7ff8c9099d562c968e77741784f4720c1f304609605375c8492fc0614fc9460f65a870fec953abae29f102ec362329d10836c05a1522cc44862b5a0822eca5d3db2841ed94d249ae16725a25c9b0df0c894a8f49ce9106ac93709e8057ada321ae0932b775ba2224ebe267551205958922434edcbcd28f50f61a9599848cb5cdf93c99f421cccf3791e96fb1d1f8b8fbfdea2544d4578b60212ed841466e008dc634145b4331d62fb494c712bdafd42../../../../usr/sbin/sss_override../../../../usr/sbin/sss_seed../../../../usr/sbin/sssctlrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.4-3.el8.src.rpmsssd-toolssssd-tools(ppc-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@     @/bin/sh/usr/libexec/platform-pythonlibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.27)(64bit)libcollection.so.4()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libifp_iface_sync.so()(64bit)libini_config.so.5()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpam.so.0()(64bit)libpam.so.0(LIBPAM_1.0)(64bit)libpam_misc.so.0()(64bit)libpam_misc.so.0(LIBPAM_MISC_1.0)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)libref_array.so.1(REF_ARRAY_0.1.1)(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_certmaplibsss_certmap.so.0()(64bit)libsss_certmap.so.0(SSS_CERTMAP_0.0)(64bit)libsss_certmap.so.0(SSS_CERTMAP_0.1)(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_iface_sync.so()(64bit)libsss_sbus.so()(64bit)libsss_sbus_sync.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libunistring.so.2()(64bit)python(abi)python3-ssspython3-sssdconfigpython3-systemdrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PartialHardlinkSets)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-common2.9.4-3.el83.62.9.4-3.el82.9.4-3.el83.0.4-14.6.0-14.0.4-14.0-15.2-12.9.4-3.el84.14.3f! @e@e{@eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.4-3Alexey Tikhonov - 2.9.4-2Alexey Tikhonov - 2.9.4-1Alexey Tikhonov - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-27205 - Race condition during authorization leads to GPO policies functioning inconsistently- Resolves: RHEL-25064 - AD users are unable to log in due to case sensitivity of user because the domain is found as an alias to the email address. [rhel-8] - Resolves: RHEL-25066 - gdm smartcard login fails with sssd-2.9.3 in case of multiple identities [rhel-8] - Resolves: RHEL-25065 - ssh pubkey stored in ldap/AD no longer works to authenticate via sssd [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-1680 - auto_private_groups does not create cache in IPA server SSSD cache - Resolves: RHEL-10092 - logfile rotation for sssd_kcm not working properly, sssd_kcm never receives a 'kill -HUP' - Resolves: RHEL-17495 - New sssd.conf seems not to be backwards compatible (wrt SmartCard auth of local users using 'files provider') - Resolves: RHEL-18431 - Excessive logging to sssd_nss and sssd_be in multi-domain AD forest - Resolves: RHEL-5033 - Incorrect IdM product name in man sssd.conf - Resolves: RHEL-15368 - SSSD GPO lacks group resolution on hosts [rhel-8] - Resolves: RHEL-10721 - very bad performance when requesting service tickets - Resolves: RHEL-19011 - Invalid handling groups from child domain - Resolves: RHEL-19949 - latest sssd breaks logging in via XDMCP for LDAP/Kerberos users [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGcacadedeesesfrfrjarururururusvsvsvsvsvukukukukuk2.9.4-3.el82.9.4-3.el8  .build-id7e6dcc6c8333e90a1388512dbbd3c774a9bf3a51b89b5077ca46350a9d510e79328008b5a6b1d372e9ff401f5bb46e9c74a6125c4ae4ed114b113fsssd__init__.py__pycache____init__.cpython-36.opt-1.pyc__init__.cpython-36.pycparser.cpython-36.opt-1.pycparser.cpython-36.pycsource_files.cpython-36.opt-1.pycsource_files.cpython-36.pycsource_journald.cpython-36.opt-1.pycsource_journald.cpython-36.pycsource_reader.cpython-36.opt-1.pycsource_reader.cpython-36.pycsss_analyze.cpython-36.opt-1.pycsss_analyze.cpython-36.pycmodules__init__.py__pycache____init__.cpython-36.opt-1.pyc__init__.cpython-36.pycrequest.cpython-36.opt-1.pycrequest.cpython-36.pycrequest.pyparser.pysource_files.pysource_journald.pysource_reader.pysss_analyze.pysss_analyzesss_debuglevelsss_obfuscatesss_overridesss_seedsssctlsssd-toolsCOPYINGsss_obfuscate.8.gzsss_seed.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_obfuscate.8.gzsss_debuglevel.8.gzsss_obfuscate.8.gzsss_override.8.gzsss_seed.8.gzsssctl.8.gzsss_debuglevel.8.gzsss_obfuscate.8.gzsss_override.8.gzsss_seed.8.gzsssctl.8.gzsss_debuglevel.8.gzsss_obfuscate.8.gzsss_override.8.gzsss_seed.8.gzsssctl.8.gzsss_debuglevel.8.gzsss_obfuscate.8.gzsss_override.8.gzsss_seed.8.gzsssctl.8.gz/usr/lib//usr/lib/.build-id/23//usr/lib/.build-id//usr/lib/.build-id/51//usr/lib/.build-id/72//usr/lib/python3.6/site-packages//usr/lib/python3.6/site-packages/sssd//usr/lib/python3.6/site-packages/sssd/__pycache__//usr/lib/python3.6/site-packages/sssd/modules//usr/lib/python3.6/site-packages/sssd/modules/__pycache__//usr/libexec/sssd//usr/sbin//usr/share/licenses//usr/share/licenses/sssd-tools//usr/share/man/ca/man8//usr/share/man/de/man8//usr/share/man/es/man8//usr/share/man/fr/man8//usr/share/man/ja/man8//usr/share/man/man8//usr/share/man/ru/man8//usr/share/man/sv/man8//usr/share/man/uk/man8/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mcpu=power8 -mtune=power8 -funwind-tables -fstack-clash-protectioncpioxz2ppc64le-redhat-linux-gnu directoryemptypython 3.6 byte-compiledPython script, ASCII text executablePOSIX shell script, ASCII text executableELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, for GNU/Linux 3.10.0, BuildID[sha1]=237e6dcc6c8333e90a1388512dbbd3c774a9bf3a, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, for GNU/Linux 3.10.0, BuildID[sha1]=51b89b5077ca46350a9d510e79328008b5a6b1d3, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, for GNU/Linux 3.10.0, BuildID[sha1]=72e9ff401f5bb46e9c74a6125c4ae4ed114b113f, strippedASCII texttroff or preprocessor input, UTF-8 Unicode text (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix) 7S-R/R/R/R/R/R/R/R/R/R/R/R/R/R/R/R/R/R/R/R/R/R/R/R/RRRRRR+RR(RRRRRR,R.RRRRRRR"R!RR#R-R*R R)RR7RRR+RR(RRRRRR,R.RRRRRRR"R!RR#R-R*R R)RR7RRR R RR RRRR+RRR(RRRRR,RRRRRRR"R!R#R)RRR RRR R$R&R%R R-R'R.R*RRR7sssd-dbusutf-89447def90b6c0ee88ac44cbc6fb3cdf58b195a350b5b64d9ad480cc997583a94?7zXZ !#, ] b2u jӫ`(y0=-ԓJI($&26$Fwb'Vf9(hz96s #Q Q G;4\Es|mLآ{mvKȟ G|${TP3+.s˾<鱬1lM STu}fs>ىS_)]9 v Z)з.e!95ˋ}]jXVYhLwWB( nB itI|5&/cҭnpl2q֟~jfzj MK2m(#2T$[>h8Ãy`ѯ;1>ۍlհQ@Z T`V~phy"Z9Mt)$C?/Ƌ>V:Q Cx4ep_iN$ETMX:r |$PftS߿6c}=2.쬩۴Z{,&.";ҫ-)7fõ8{ ,@4: ]|jtxKf w|ٛB^kb)F=9ʼn)\UN肜.ҵk%E2.NC 1a@V!0»&)Lteg~TwHm%c Lro붆пGʟI.'K9N 4Tآp#<أ^?ʍF۾IXA̒Q|FB@_m.xJyB4T;o|BB)%:V~prEt:~:+5((pfIњ/p- = 14`TIA<$jԉbc:QT?U"3}̾6s/+`uF$w bn=! {*}@hltmh#-Mm_m,dTP kP_kS+kDe%1!V뼫U:hni~fCAx* a6/eL ' u<Eu(XVz:6# ,+ H߿S[M%{,僋}kݧ$}E֫K(˓}s ~5>$Pw`ak+(GlJ8;:qҊZŠO/ȋsP;ɰr!`7 ֱWʲ(p5/yf~xLQ# w#;~mfZMx娐V TklvJG)DhxD`] ]z[uٳZ-'{Q'񢸌1TɳV-ť8mM<̀^>4 W-Ra +u^E_O;Pu7FÔ(B=UFME83Jυza1ex=ÄZrDH/'c&36r^fhR$6CH_nֱ#H'wprRIY\8jN~^eWzf mg%XABĮJ9N[w4^k) T@X=2M#Zg-)F{GQr7D *yrF8O(In+Oo+7BUc. rP?ƾ*V괎kqwncݾLKк_T+=@wR0ksAfrm*p<}j&!sh"D0E`JT}[y CYg 8`Q,Q+l|j ծ:mhAƶ9jm)ۀJm7s˨R&ˮf]0OD0?K3^흴f.{q [ K m8kxf*ڑk<&_}sue3Z`XgJ7ʿ mAz% @< 6oXPWM YwsoGX9ۼry]s>gzs([Q[3P*ɷ4sS'$o EDCnX{aKïLFѝ o OYz6S*.Kf?0 sL9U.n@p[i0qf;[c pѲ0vEG \+ p슽h^Pr궖h>i|i"^)) WL+AWU Egvh{Vߚ. t ,Y<@0BwTm 61CR , >.<6Eug dq ˌ 5"p_wPXS5#7N/?(=xLsj$4E$t\GK8MYGABx s-E; |8oa֮A;>uKE4F?L ]!n"aB0ܗu&'q>vƔv -y%MG,-3_i첱i: vP5@[X#Bo: Uw\p|EL$l)礭"ؠp`XY<Dۚz<F]!Y8 j{^/WA(;xeoF^ 1D= n;} -#oa2%͎% f '^hPg3BN}oCw}qv>W,Aߍ4llD6\cQ nO4D0fw~ 9 0̤ܮDs?%.),\zl4m3Esx׍R!ݭ~@qZ4}ye*3[ωMJ*!:.܅xJGD`Էo|'sbxc }6pabh>sNoKOm=scCWD3 @Lڛ6zfZZ g_O`1+C4LH9a-#;*9#@dH#5:.p>3!L v#hOrȱ9T. gsȐswsq'>M POf 1׮NLxFvw`|?Wd&M[E(ldedrE٭4h$͂p gW xAz ZL:0#[eUI6&gi:t٦QM-ެq!弝瘳ɔuo V4Љ/6G @ΫgQߴݴ]oaQ@⯛tyh11mЮe!tu? Ż >|PQ. /A L/wۣ7؊X_v0I$6&4{)/h wɹk~{ Qx05!M+2&-*no0y]ooNPhL": > u9Q68 X*p>q UT oΈmwW{ OiQ dɆfMԯ嬎% =W &GYAzP|zqok)D/%a{_ ˤ#xE䉴KHФ=3WC+`*H;03@$`7}ãz%&~\F:WdžhuM=sѵU8L,{tAT*؄]W[$0+ ߛY驪b8kI;H"qM? {a?[F [8Za8N}/"eڛLdHYwںw$3{˱onʢq|N =,dXp4yTX)˜sP7JM'Y9&[fahl?Rp9wP+QK\L'.~[5K+%v'A$K}˒\7*+MV}<b\|?aAEлsCjCʚmh97l%-RrfPyNc{clg -;XԖj=g C +BI!UX.Jk ѽNـVx[kg_tKG+dLekuStȬQV3]&x uYrTcJjt`p%OPOצqL%l Zߖa`gk,_TEKSO{^$bI)B4ݯ 3 Z x=YV$DmRT*v%Rnuݼ >e~p(K*3ɾu !9i&7Je4ѳ[^k]$vzz3t/ '6C{/.`ֿi7155JalHIt*@GotF/! ?Xv"CCHMgT WT" T-hK=S(vkHӂi^̟s#*I3yưיvSk'p 3`1+F2k]胫y%*jhvf C&Psh@VVAxҀ0(9߃@ nfՕo _b?[U%Ƶ#+7 Zh D NYٚ_ ,anjtB:1ۊ ` e> oP$I_.>hQe*SB]-$oe^22.6zĩPiVqeܷL>$#Y߭voYwx/CJVk0S89P!~)"%ߑ&"CvvM̾C쥂QVqSKUTA?j!l^if>53Ebzۢ׼Zl+=͍+P^ @i4l֭eB-] IT +aKJ|*"@LXCO:a9?kU)2Mj߇j,k6E8H1Bd\<K^q:O oX:aPY]̼(nf́; qPTӝ1ժ$6Gi-[v7ɘ>Y^vo}q'/_=>:]Qcagay! m:pN&XmzS8+sQ|:Lz>Xg{]G:B@g>x8jea!_|0ZɆ]lB;}_|SyjI^ReNy/o\Ȏ~/9"5"n6/UcZeOEvj$$4]-ʖpCRӥC:F0H#;"Masnujv)I'O FeGi%{_9hUr]7p&[63@ ,`GpoC~L9n8!>go;Nx3~\(1˖r[Ό-8mY: p`i>SΨ|άW2< TТ'9ڎA7ô>HԽvƠRX WvyW㼉rk q\<*kߔ(p=dGvр;LB`xY{ -x!˫x1 A+dTf\3}9L`==D~}&a k2v8sX,*.} wE`Q/hQ:J4_E8o4L5rW9UlO5<}`l2a s`&YSؙr![kpg{r ;*\^^TuJ*Q @~g|w ilnd (A{}=[tgT;HO+s"kνm?z=uԖi. •T;p؂՗_axMdD Ĵ('s` #8Sy4HXBBpJEɆIzD{1`KifMtB`19NkákL4\*hj{P 2q鼠u-9/ ח FT 9񘸿Țv5Y?eALB8t8(/^;(-J#j3VvۖĖWyeBzug8 Y ;vԿІ Z򜥘ڰ ~Qڷ\1F aQf Ebɿ뷙:1>ij , 4F@݉$?-׫ۭ]rA`.z3:֝ /= wBEpu|a˚< žl/1^ЊxSω2pO$]Pjb6)kuR=ҟH.p7l;%$*#ut'޸BLھk%mbzmDܬ(UD3hna2z6?o! "V_«pSXfhK{Hw:`}j1WgDrCz5io({pҒU,^jV]s=)T]W 5 {=N|ՃJR[d¡p&CK5,z4w|`"HIԁ=R.SP Hj#~]ʏ+[m^[yy,kV" y!xߋ=Ek@ȫg!'P0An4,uC,I.'b7aL`$Z퇂)].Y~d'5@AU3«s}n~K0(䲞xPU52 bv]ˏV(ʗ2n?CȆU.5<@yNgݻ-w;tf|O}9ճe-3vr&N&ħ5Y`rЛLŊ-s^KnJ5P_#7AKc삯KTkCܸB;^5/^}Nư(ݚKJ/T FhzUihyZ;@gm%/ SEҬ[é.4_*,C8_MQd˯HY_t9:|f[YY|#YU]'e8\U_@nMB O ^"ߪqn&K4PnlM7\猓௨;-v<.V0Yy qNG{)t}d ̱%x_oh cSq]FD szyJP P<` 7>IxG6$Q h`h!y$lQ NAF()w_5fԐ=]}0./x~C\ưLL+∏2€K6=?4)72 pBo V8Fʟӧ^E(A2~Z] ZP\6ms3L*iPw%٦G4xwm22a$>8"()EaS*V F=TtVz;BwRur+g8L6U27^T$ln:'؏挥MU3#F ]tZつ ؋Lf WԹ=i<?eޒ*'86; 7G>qCx9D($66!<,)=4bB/:NF?FM~mm^t؜鐍YM&w棂q7 "91b9 B9(u:,5P3JB壨Y:T!4`5(Ŭ7/MН9uLDn)]imfk*t :cP9$Q3fҝ+>sCͪ}"2:nj{^ʃWq$Uy(8 rz\/JCO99>vяk^(m )k7TGVF&fn ~NoX6IgXr`w|\,^7,Jz0e캸Ă :ZGbƾq; \DWDј2:jkxYL Cÿ\jfic0gPe/v!qc'OTҲuD4; g5Aq>3?sԇIjQH4K1jkq<&c~hk ;MϊϝkXƤ3gvGVpDZ.+ad槪ֱQ=4Q&IDJ٨Hr6B)K#eѫ>"ځ[ZqE1Ds%:ncmz{EKDEڳ.`O1E卻9N &|Ad&j@Cqih4;.i8٩~(,l_B^edd ETm qCed32X(pE ɣ¥?%]hu90`-@8k{ 3;n iJEz-Hcyt:wP>8Ώg/_fWmׇPxǣ6E74-E`DUj,T$vڗ-TkB-#y@_eWAcarEd%:*W FPbx^p(kSRtW9?4ܟ{*9$zc\~'k ;|@XQ5^uit(Z2@"βc f`WPRbGQj/q%,FO(cUD|!>߆ct V2j'mS~*%_I>$>eɾ7s"9/kI[̭ 7_B/k%zigpq]ƛ-l*~'N4 ps`\T6+c6 S $HzCbqx@ɰ`8dҽZm7w6[[p+*24q?.0<}w4+n4S$dYh@ b3Xi<'׸f"@пkMz}mjHoI0tZl7p>X-X= sYjFy;"|nroj]:ϫ%!u d݄cEXlW᲌h JUOk|:զ_ź7FzŀE OCi5ENl}%J Kܑu`-4G&0gU.@G)1{ WeF )`><]=>X6د!ryQﶢe )?+CP͍ MXoŮ-ӡIhHTwnTPu h]GZ0ZnXDR3a۷vtꥹ-YMUS>RgfKOXv,Hvp!ʮ-蓛+:T vXZBQRNjP<~.B<j~b4WNWafv q8\cuK,Nvo0F"r̻m[$iwLJXh#AFIsObF#́7P7;F#V 9c"SsXjh(?ڜ%"Oc.'mvoKאָ`(O7du9ݩ? f+噡m#_0?(}H*MMGiz,TSy8x*<4ɋi /C/ԞY^ ݌:NPw/_$SR.NJ-x1^|ԚЈ6r*Cܾ++,6 ha xrkUCul#r~T>daU-) fYv!%XAlW KLĜ2{ԯprZW/EqG( :]K]BC;eFGwm,!EEtkl#"ET-1GL/\O\r8`<RRZKed6TSni|≠]}Z Vxp@[ȊE%;aif*nsn߮GM5Mhj_媏=a1ѝ̌ rwx 6f\ ĚFMsx;Ӧ UIk!NmRj]&pF Hl1H4PcpRViQx٣-W>yBA[u\FБY&pĥ,Yu\gO>9yxDUjs_:: |㩉E&- &:XWfJDfBq/a=#dqaB: ~Aprreu ]4>{p"/cz#K6d$= yPaQ5ʆKNddY[;f#̇"2Pfg25]ƨx8#Z/5E_*Jn4P~BKPB3W䖝>p, Yt PXJ2Ve:0'2/+qL.͉3(GTf9 sEώ03?4vUk20XT4*(lYA/Ө[Rf̃>!N#+N7=ʎ{C8IkTѭTtyݝq{[bIW컵L8b\1 lҼ潠yN h:;2\eG/P1''rK=Y!"7;sی'b>ex΅JAyV;G/e!L@Fe6F0/ jmvD[I^aY"KlJsHw)Y&:Ts|\HbqufRH_ZXLMfΝbDe$dzrzLfnLbĉϦLkA'獋Ow( 65YFky n*(&,T4u5jMu$-ztl'^0\>35[ӮbĘۑo^T[Ӯ?\,?Zj`V$ؐ%l# L"6pܸup],> OV&(6U96!&CcT(Ggk?QS{J}gt[ p"BVy/іތm9ZDُ{Q45 `5QyDU k[zM}G?VHÊںX߁T ] /'],DvQBcP8M X'FTT̒g +YtsJ @Ɇ.6v@ 7b3*UE'(\ޑ!Ǚ|DP>b5C 6FDoR;o`efƦQC̕+H w:GC<5/Y*Rۇϯ貵ZM*(:M<"UU.D=R ?aijC4}Y6&3*5%d'jv["|{q9$_:7G wmCT௫-<5r3zppH} 4p:OSɾ2^ 6)Hze2H1E;ỏx˯xzfAhc]2+M? ԑЂaIa.i|Jv1Z]0tKMTE';l#]H%o$%/!NY{K in)(d\nc.L'Bm]481s1 _B꣱mU '{VQzoftj}tyd 4ɽ/r_T% P_ǒoFv$Uc-FoAfϴͿT<:[=$-ɫә$(?pTHmCゐFkתSٜ? NpYe 'rOU$'BZ_Hį s 2ta3.WpP^equdoh54e jaק^NC.BO~jg_xZڼ#S99lŗ4u=h5fMwKXU6^1lQB^EGsģB kG@@Uҿ6H ׻TxЎ # XR̼v^R A%ජf b 8EϦc$("N+(m%=oZ:,.2H.,dN;aT)O_VX(SEOʝ.EpS;1U~},JB~eβ`[2 bio;Fl!Ǥ0j=ov${:an t00f2O$B ?7Bٻ1+oWrϛ>2eP0a]7-bq' YDBo}e9Dm߇vlUiQVtwyi^ mki؍v{^# 6/2iHW/Ϝx9Uy$2,//{5ē1uO0k6X9ſ7Q-(*ӻƅGΝU3 `RSj>/Mv$؍^[[Q`׭"wLs i5I$}v~488Y~"r}L,Lm(BLh_{ˎ$/&I@P\'GEJNM>>WJ.:T$Rckʍ8|Ih'6ZWdl"``mŢ_$/KZIhŬ]' 5DR [*kt':r4-VmB' {oZu]I`P^͟}w:,,30jE(G_ww )cSF2 ϒhBt|`85mV5y9`ao!$1J[ .e2(`Z )}L ah3D=cSb E%hhr߈e)̥^(r{(nm yat,W"\_DlSIftAu ,"rZiP5y$ty) X\.kZxV|q f>B1Zck6]7lx}e "m;1B1ٕ mD|Heͱ08ާ~ٝmQ)XQ&tK-P= [!PC!v+'[/qY"#ۍ^M:7Ip-b{0ը7Sע,fF4TUM ;ΆJ'Ua+B 'Zz_K SZNc7p( MyG|C-۞gvP]@=׆aTmq CR?@j_2Ri.㻏2~1FIi "GOCK_ƁB0bFyYKͲK}Q(hm%ԝ˯`ZJsK/& $@N] S5e+.dBt`3/,w:5OԻ¦u8U2! މT30W;a,@L:HS9XرH?f V:hIac6pj ER"&|}w*"&Su}* ^gз!5~Yi.V1gTB;DAn5ܶyj ?]8"C5GDZ[OIp&jvp,l\!ئ#Ae晴+j؋^ݰE}rSkf=Dr%!_E|8np!G4_k6_;fLSɍLsOmOT6l}D4L\mO}Ñbow NvR}F;&ExpܺH^W跇 pÒX2iW3v.qxV}ާ~*_IlYKYm\$iF}m JX?=Cok7^52tS>%ɥ#/T?LҿHi=XR ,Np4p@49RLgE~E4a|t(k:ehZa;QDx _?=irqX3h6k_Xjx&i\XM"^D3uYl0ܯP Vyfo|(D@<4L@f*8iz&l\I(,ġja L 5hT1FMl_HL؄g+#Y+UEm iހ{Y<ۑ'KappzjkB:6g@ huiwt1x lvzcaUyL-qNn>LP:`'2 Q@9cl0 w!;s  QPYC-=EQ(?4r+z# ]y$+nb6Q|iLB{;֯ W,>(;- CW,*t`2 h<}˹@|.ܥ-Wv~ *9%" y_k:Bޭfu7/ plƒ֮fxVV 8~7qiq 싏O~vd(Ώ( ࡭S/͑w@/q)Tg $DQ=lH5kPx|ٶ&n:M} P҇&:{Xhwiyf'cF/229|<{mH:Qkg@!"m/jC׌QPzh(c :lqAh+9+R ۛG-B-x`n'g; eF C7Mbo^#WfyMCv9*DsQIbA4kFsK`FwI = pa$W)'J(g>z0ӝ+ "hjy hL|Zp;Iŋ;sdvjp =sњ[ikԒw$TptDd ]cc%;g ,L z:XYgnzj`cx rToC)ݎن2! t{ &8* l,/J$:΄foEQyAiД.=AjٞF<jYct8y PkhS_rsyRkة*ɵx'|o'Mr*nyޭ<)و֏+ _Pg\.S&d>Mig v*Myr)ҍLq)| D[lgmGgOٶa}y0ly,%2 Y#rUZe\vHd#MEZE-`%;ٕ~l"UXZ''<ϜI"=F(c)zʋC`im:e1@5McG\>-p$|vn$AuSǭ0h05 ^ۓP=% žHcoOZOL' @ 9B;s=^mXz7q'֏d̜jY^7\1<[ fѢ~ 'B܄&,ה@T=fYrZ6F/ 0u!U~C{(⢊!(~Eמ*|,?/)yZ(0+`u@Gn; EA4f&i3L˵'/Rlޙ,5<84ՙR7łqtmj`^̜P=u~(wf=v(h[ƣދ{uK|]uN[m Uv,P/NMH߃hXT8e HFM&VDUԙ m 腪5X4&~n_k$|Yγ"q7I*7џS?'yWjH-#geisvvѱ 8?Vbr8*4׸HBpYZz)^~@><;b \VTaC.m>8æTcݿb9~y3eԮ]ȽT^=78ğgZK푚ֶ\|B=Hu|a]F}GA:K怡o:KfEc #gM يwKh.y+8Z f.iwL]}u8 =v__`lw146ibsQe8ͳ<#TB>T|od[]A&zTld}&n&kE<<(K<6 [mnq#KR= I DD(U$1P:Nv1h}A}Z jm."FKrE^: [QDg"bfyRMÛ Q 薏.Di/jvzϜT 8̐P+W(,Ec*A)#ZBM}Q! *Oₘ gURbE %/M^Hу=b6ԓ|V箕y2y 2JpG ;IӮFAN@KAdP;%o1x[%/;[}ɑ^CFA",YNYc?NCpzt&7Wި2 @6{Oĕc/Z+#ByJSWH7%zJLC6 c͈Ȳjd\ JQlUgcSWH2𪨆$f|׭[{Iyl@*75!,4FIzN9fAfdVOEq<=G4F[G qMޱfgֆW)y!8 -<9AmbbNJY}婐$֝߯Ihv%:ܴ< M"r-JUi/%Zao29X@+rTq+ϛaМ>Xm5n8`51S LN'͌"fFa<K6V@gDV?>lg`u@n /e{+BE 37θ5\(=!؅C]0dwϥN),g#*4ˢ9=~VYGx0ɷN:wxޟ.q5Ru]Dg yR@ aiK kwyQb#hJOP#(OJlDPu .\C ~oLt͗EG2GOE̵izG٢Φ3 zmH6UAs^덃/`7nhra UaDFB >M/:aƴt݉g4v$.?mj%|mѓ9Q]x :1$: #fh?$ mLs Q (xok1^غ '8S}Zw biu}K72VU{4[si^J-[3e=xIs|t@|AzH '/U ka#+faZhNdML(J:DolDGu@3z*}ÿ^1O5uKv X{$p/556 ozѥ'&\)D5yEs=|BăĴϖYVAe=D`.qHnv ? &ŠFH7E'i.' 3-]Nm*,bpS XC\ Cb8ML؊5Js@g2*0\|;;8]i,Dh<?}Ў/]pa;YKop+ZFByrzU|t sĴeثD{Z.? v_pV}NoJ^< fu~S՜>326ALJ:y:x[o  Vxqg|BO֑ ګukL7[3vW[[{_5Vuߌ7L$8㤓mƼha``A&n)W'@\m i㶟X&&>ҟ9kVp4:7yFʈY:{h']qlyiZ1NG y8r T4ce|ňf F8쟃j%w?E3zi_y}8Ȳ:HTh f0d2WzcLk16[w re0%&$1߅3~8رmF,έ, Oc㶡Jⲯ}W4VKIeDž- u^ :IE\hxI ֓E/Ԁ TpEńvuKNJ|G;P+-+!Ȃ ŏfINk-MYU3ƭf5Rd=MS#ntpM i & TnT`e{k]wQC7U+tbybE>L,ʒ6ª}Tvt7&y@Ej\89 #x0/uc_/b#$ڿ[a4.?;Ji,î4U/]Vc`7ɾ jXL^b>V#?ʇbn)XZ5^ė]B6At>,*x?BP,'\eAۛjۆuD $FK$@ط KeR?,k$bVd`FvW'i'ʤ"nvj~ $^*# 1>_5x\M{eW g_8:`qcjPB Jiz:PDr]wD*)S_s7T`rׅh¨JA(#A~5<\N,./z01u'蹞b21ɂ rH]FJR™2iogd8Gw+QZXë}5igu5tJ~ 0ߍɽpHJ\6 N3Ұ|RӺ8"vק1|P{)jH Y~ YQrOn$ +Gm{zTѾ?aoݎK֥zc* WM"h7``PstBVثCO̵.:PeƸTJڽNh+;xq@ hiB3f2P T'),PK C>X,[T=l S?p$IOfen&yƘ3 .H&K{`O*]+RziSM7-r(@2H?eiwaI Qjtr%n`  jaUz%~!|ج/6MQ)/|FYʅTs\+"jңs5Ki:T~n\Sֈ٘UX~d1v9P؃m/r{r̍a[& %;bT4\%@vfk\YK7PgO)$`6: i $CRg))/|%-as%Ɠ$׿(D|c`+еk!Rz2Τ^ΰ<&R!BML5Ejlb4<֒y7ž2znʁX2&8Dn->l&2H̞j Xi4+&B+sεK!vيD]}M#Gm}!QQ@BX'oÁw`"y29{tYO{ZjKܖ ]he}:&M xf-/0ggoY$ߐZ(tKjszt Fu%`t›!@ʲz2&cTRFLV('-)/*.LFv] j}4M$!6wH%~O_`kPmh}|:-At=̧R݌m` @q6lHMd X"!LNM;xrŪ#X47^C::^vdثp*rum>J@d{@ єPB5JmEx !nLI{ڟ\ ܵ=>B1{nF*jtfo< k ;O|NRj~hBăqOyCpͧ\B>n=~sum߯;wUrc$ Ia\>Pj#"?{r,ۨFeu檟V2)\?{OKԢXSK22l,OђAPh1~+6Qwn7 )TH&\wg0!2bHalW^]oOM֭ɥZQ`(;tΪ4AXR[nkhaurEoƓc=7#S=eTm+//RTc`] u4pa8 /fx#τ2%@kQ~D.߲dc'ɏv@m,&0BAI"0E ۔~-!J\i ASR(泇:/,h{˟!!խa&[ )-u.3<"Tq]Pgn'8K= e<@=D.,?-iW ۞6d? TlY3GֹhIB^Jf{$wqc3HQhr|gm)E;w5H^u yfu#~5u /2-uQ=f2Uk_B} O': i-_{}bRi|2>,a*tAE'GrQK'4&PT{h?B\|P$DzCr ben@g-BE@R7gGˢK0xކzH(8ib<%g;{O/z4_Һ~Pr! D/:kMKmV\ 5cO"?ks9l+|WӧpK\& 6@-uH(MUؠ 0M;͢8Ub{rg!I|9vxzn#+I+懙Xl©_w$F<YXCq xM~<+V&5Z:V4MK•mA¾55!4)ANV3H5}.nf&f)L.(GSYZ1p/}ia w#(;꼨hhq F7TݨK?Mmo#;DbKmє/(YgںFToz0VE3eyez_K^YgzEz˯,8<>X97:{w q|ßr`H|ŬvCs+=&SD<: ,*R@#*6EdfpffEPԱ [φ)ы\Ϻ<HZ^bߵڒŇ>+KߤQp iUzx9xsu8fEKd熠L?CS,`N,BpDX:!чqr49KG= Eg'?dko;nL+P䚦 +p%?$%D>k^X|XCbzUR08(s ,Z~+x3I]4vV2$@Nx)6HMC6LVֹj'ı]%؀(n- d:hbBVC!S0&_AIs{Tp'\ 4آŖ B qtLi.pw˅[O8]n^c)τE$wR"U$Ɛ1hʝ<p/hbeֈRZNjqd,꬐OŻh#ٕƀ?,hE%).ucT%@IKr$1 i$>Bsl[ioxL祶$Fޏ' }e2<$xkk s3΁*w $2*C4-"%b(<`eR YbMkhLfCþ@}BșP*x/TN`{'*g_l@TGTjϐ~OϠS%ZTيk fhJΤݤ4Z?K65Z_edئ!feh판lϢtg/)=L%("A,Xa* u}hj}u2͎!!ǂ:AGCxGf{Ě,&[YrT͌8i.h \)zG\tS,-xEgQ}T3a)3g;GWp,kV@њ! ,9f,otʿƔ 4I@U ,{uȿKEF&`g-r =agq?^L ̷H1`¦垚!/%iQ{t4Iq`SR'P L:g2]~ Qt^a H9=Fh 6AF$;ǺJX*bvD<uR%\~ѿnZTBzy9\b|w1<*}ՙj>N'<9NJOV&fjæ'3/ͣL]tff#>A| ^[CuA`+vjC8Ea+I])BïH"b+KŐ,bHVE1=Ηt}M?DG R$} Bc9p{1Y\}>UkAeuGLAզbD: h *  Ȼ0oiI'+rb$Wf9(h֯q@cK@Dx֤FcN)A6ьg x+F5\+mHYّʙo:wZ.67X% A\Wn>D dQ2RF3{MQ"] >Q/i_,]؊U#ܦtE MP=VG˂\*;TC^'NT0\5SN~phO4 ;!2=pt&gzѧ9\eS6xbXEo6:{#=`J&6Pup(D%d̙wjE1 Ǿ(g 7Ɠ<~Q}~8Zkiv]JV2"lpy} q9cS5`9 )Ʊ_bY S$sSeM.=be,hw38gV(=zQ!\vuNYɱ(V_>$R#ܼǀPEr.@M{[yPUB7q7ۧ")Ѹ phJ @у!%=p86t<wv;߮N8_:@=x?Ѐ@bOx?!Z]KIe ֨fW%\Yavf5sGװ_{X Iu3E2UT^\&\Wb.G|D+Gav7%_Boj;-#*@oȒl\DMww gm08qFru_ۇ!1;{) ˋME*% Ɍ*|kals9Qå63BXx-z !֕<^BL`19O&qC67m638|Y0l`Ai;څo_#T>Xp(`{¿;(.99snPs>%]:$` ̀|ӔҽblY?.<ݠ=a3#0 X߽ʝPmsʳ[G՝|kX*g(kԺ$ޙ~org)֘ĚYeoJ:@C0% =Uv`ZoV>KR;8hևLMWm[jP W\ªGCr,m+lxٰcvRMj#R^Y[;IE! ESw:4'ԍFϼIȁ[_r}6; q2O1NęYB2Cy[ *0]9twtDz_k9ZY!M޳w,i=;qy7O"X]Xwy_R#0F̻3'Foj@Ŷ)l6^'>;kōd^MG5̩Jl~Q3DpP,edjگ.u\?>in.cSЏkN "8zb/]03pAPEcXE`a P?' XQ?[`ULRDgLQ~){N#hэ,F;+ͥ'm| |Ө>5szc͋ eoO՜a"H,(,k=Ü}PS؏aP(u=%mJ0K١Waے .D kI7oR _2d-k+i\h8 PKߣg( 2XpT0[x@쪀qWw𸵘9MmuLg'P16  aVn^s[I>ЋmZƑ_ IQx6""c̭#*u2՘2"UOsR9oC7ƍra]j2tm@)zR!'G{8^!4tD)[wF.>'<8P|N9Vy RxY<EAдЌ$#Rt=z\c?d` a#-vR ޻^֠a[Y حHQ4ϬqIJ| sFV*LA 9w݉ {ej- Ӳ=M&VV)zW0?M f]|S,-ޅL6Oq,|f} kn,#^%1E; tvb/ch)nh$+OG-QuhFد=]LD"}F ]HG%` QZFs6F3vNEa LL6OMՄW,Rm4̣Gݱ0Ŭq6{̨#1-=/ eh6Okc%?P6^H6Tc[d1[" !2B it^sQHYa{|oy";v"c |vBx3CVQPYPʹ:3 /t,ƻLف:q&/d\X.FqdB#̘{ZE3%AF_<Ӡ a.~_MkCW5/\$ |CZLMN-.?&YߜxQKdwU-ܿrh}h>JR6k'1^JEy߅7ܻB,IvJXkɻWߑvyC<{lzyVu5!]WG?jԧCLa;2#k)`4SeSp+uoڶ=8|𴙓r}䫲Z#)/'>r0n&uf '3 W-cÒ,tJaPgj2X; .DlHY#KNaLA0?nـW*2ȉSx`y9gm 3|SSR5`? ;! U\_u][WQvW|"̙Fn}>NLݕs|!,>I S2 7.7>4@K]*eQ ?am^Ua!V#tþiDI9=3BA>6CuX!QɧF(@#aM@3_Js+T7Ngq!њi^0qv(5$K@|d|,nC'FI_ۙ鼗Sb'g9+:<lcwYvPJ YY֬F- ]9%F 0Jne@3Lܐ#Hnt] >BL=/ϱnYpUŽvqr+&D6x"NwZe}K)|"UǘW1oǴ)QH* \+Ǒ謒EECQC ҈XJJz&OmYq 0@]@?; bKXa9}US)e?5Db WM EeA@]/bSʫHmKJGmل댠sLҸ.Jy/]9א':~uoqZ<:n\HO?.\Dߎ@Y)2>Qʵ!V٨I'!wڝ1>kBaw _&vA Aۍ$ьk0 A"3Z,mVơșXa3(7I"IVts-J#EL5W5ꈈ5?9lwv1\= '?Rĉo>ghФMާ 9QڽRO;rzP{x@::j,h$?`lfSX |M_&!^x՚TDB,z!rbZzQZ4UDS56@ b/t-V@ tт9)t80pRWSe;Iezb57i" n i5!{ߪ?lI"\Wwt&_=/!;YP1 A\p۰5\Au:'NhQ+o]E0v;T_FhROU4u+a86>=D3}4ټ0`ǫ/\42>n(7XуCSvSe»89dU^*:ጟ< IˠU?օ~?c-KII*t, 1p]ZV{]ә0bKTofpru M=!R+w'@JSxh2XT\mKG(,dC0fDe#k"됪uf/%hlx+nsM kJ~|k.P9M,t'EЃ3V#IsZx( k%@ɄЄlhJr ( RDӕ~UjOm+Y]!wp~т009{}ɰWoªiFnMȥQ,<Ғ!Ooo:֟Qr>+p`U,~ 9%sߜ(7p{5F o9+'7L_Y?޳4t^LeD{cԈ ?L]V$0Yz{~7aNFH F2vLHx`c3勠zGG?6?1)e #9?l:L3PH~Q)_*1)QL-5q {]XzC)$ޠĭAIFSg"߇zӑf Wo 87Zp:Q5-nxZg|[x(veW{i쫛߱ٔtɳ-7J)3'YZ&m?D G-CW-xEsbiXDb'W >H$Ǧ[e QQi'm8%CD=[I=%[7(b"X?aG0#&X3`J[vUx3`Ot?-y:?3Ζĥ.esKF FiQ;ksS]rG*M`- nXTR Pj<~-یsv§o'̞&C9*MU]^->Ji v{tҗÇWg_ h4|(ąDֱ}Gq ư꣚~LV$"q:?ڝqS*wG UͰɺ2UJfQXi_kHT} }@O ;VWPfrO h?=Ê&jp$榐cZf9ɝ_ O#gG9*%w\ OV.6}D#}g'=gxNSC{~F:I;SJؤT啕~MDk#br̛o#{ovKppdIKOj>6߭¨3| Iݹ{|҇9'Ogi.ݽkS!4Q4yW, =uE|ʸc2ŚEk8zL,qxYInhe(crI7*Y6)WdNӑ0(Q3_`&@XU?l7jřU=C+h99x{-wi`o O0( x<! \/=^c4a*׳wc7aٌ۵L)y|g&ʏr6. )XA=ѵOw4,0Bdnj608NH-kI\O(0\ȁӢ;MȢvb&"Sn9Q**?q->qB8Li\>ܪB[lG}DҠv!zWZ^. $4hrO-C%uH6*I֯Ԧmσ5hEs8j `L3}ǏCH'svXB-.6H%<*Wnbl8љ~h|"TlF0Rw ::JilذrDpz3;=ð?+ :`n[m;<rz) X987t.SY,jֲ$#o#soAs1jg:W:wV} &!w՛xdcyn&|krN\ij2׭Ww(?X~]tuZ=[sj s(6)1J { 8а֖Z]9J;aފD,uC$ЁYI$LDv N v8=VJrR\h.ysLӤO5 ]WZd̗7N_XugQtg9obX "~#KɆVvrW(Xש{uyFՔ~ SZ?1~X% Yk-[1o>/8*|0><7IBҰ;٢<.VFOg@ޅ,n5ƒ,@aU-%\+}i!|&Apf3IiDLOB Jj`kFM_dِ([Q8ƕ VR=U,#2Hͻ UDOB==HgGPsl 5aDT0y(0~}N1H'#eqG/s¾^TGL/,n/1ی%Ѱ])ܟ/L35T_6d+ /RlsƟ&:ey(x:B ^fqNzC~C' ߞ\~>Vs|)EV#M2!u9U'#}ϽVCĜ yIorŠqM n)8.! ZʍR킬dc)6)1hMwa qE%a|i=̑&B\$M84ZQ dj\E}NR(SKdwrs3vJ\7aZ֫l5J!㈺oN+!H-.F/< nx%>&9ɗQu:7:OkUM-\r=-Gaa1Igp v4 IBa1YLjb֕E?iE&P2%aT$-5! E)Xl48RN=;z%λH^h:4 \&u| 8L+t]PP2jG}2JL~L[./mP'RAki}xM*|*P/KFQu'6*U)e);G ru_ }V>1)W|DmH2N"HxbrVsc Ew_#2u+gzX 7S&g PSds{w]l~mn$HLFX" Qa|ʍ*˳;&u[b;up}d'ϔL: 󪳞c6_Y|3O|S^y4Fk{CE[n|XhWe6ΌW/4IraeѲ)붡!ioˏWdX΢ͼ6Rk-ŀ/ &Ai.|{|D*gn _K\ JñL̖RU*ʣuI!N3a9#F5>CB;cZ&!*1 )Xo{hPš/Jή镍  a7B<TtMКVY{~Z>RWYÃ, "D\ۂkY+f%ڎ)_Ieg/>tt3RuKym=C9Ju#qY*KP41:2[NHag>NJ"U3͌,I>= E|L&.ZwC?743wQ5gYO7vE6"TiFRק3kbj^5) rv~, sǎ?%jr)EjDSߩ`y]fp^a0x:yFOI؍Kݽ*ln:ϕq¹ Φcv-40̣Gqv9:;59ӚڍL -.!,e%ڭJ_hc1`(d>5ڟe`hQԟ)\Ա$FQ.hƽ?\6lS\n*EوŊJzN~c_u#p%sZxJ 9j.rg-SE"bA !ayeudW@[tH@Q[9Vo9JI3jD-/}D}2fIжFQRp/=!&__0ݓOWxw䡧s%6a'Ȓ$~~Su6Eɜnvx%pf:20`aYTq[(ڸm՞,K:as, :Oxh!8Sj:ڵ0Q1_}ڠׁ-ayu@0d_JhuY78VMA<>X!SrٚFZwR\}U>bÖ1x(yU >M{d zZX@C f֥kA#SG2k*¹U!*U܊{ B+=`BdDglq= ~k囮KBDFGFJ?"8ɘ=_`8&~$seVVcfh&pވvҲc n>%MJ˚ 吆w##!R݁Vύ㯱s4 >Wl3ԾAT\Ľm}Y.6r j Y:޿B!Ꚍ$4!BwswnO;: [74Q/ *M,^QՐc s[1wFQ{ب3kLmD 2d0b^ᇿ4C4#iܧf`Go7ؽHMK\sj&Mc4BIG/rA)m@sSb5R]X;CDeq8hRkl|oN|Ró ,e^$Sﺥed=qn5˫Ѫ"޽Oxi3iOfa|[_lzr+>\83Z|A=?u[%O%M <=R a=HhO^R|\e[\c (̏x Ed:xh jJ`YϨ}:7D  ~J#k{Æj6)kZ19Udl& :Pې1f#D-߇+l=xrY/Yv?~Ej.|*S-moCXxWxs>8~92Uz)\!D`-~RG:g-K]Ղp-$Ǿ`LD㭡Ǟ,~qAgIG+1xNeMub2 KǓGQmVtʟj#]gË H{(:OJ-r`p^tS;Ε$BY`Cfa*6sZaD /7?7O-bOhi M:cgטٸ$65oɗۻz{D[hP_YC8HaU 0Zeo->eRFm=:~pC%C섨xy^Pw:WK{qv3elHh~]2T*ةfDGK=$wI%,kuN! ÍA%yuc%kҀ^%N']xlz!bAUYBMϜmQ~.MuyO-8,@Q2ble=7M(XjM fٙT>Bʁb`nr-_)J=  w1˜hJyc %D@5ě!?v:@!vZR%Va$P¦,ʐsn b@k$^wlѫƉ)Ͳ,|a f<U2;7 c I=*a'q#)\Aũ28ڡŇ9֜up-kMp2͌%nٰ/ʇ |`T` v&$C,DaȯmMOz)6~ioQ:s 󠄐El`5KuA3b|$S8 |c\dGۍ&_N0dFg*ai=C-I`ST`ۅ t%l!2m)XMig=lGMHVY 9n;7>V> l)5^ mr'2 sHk0ӫiyuU/ M>۴ٜ͚5zTֳQ赐(z?;ESHO" 7CscZWԝ/RTEL^Ү@ T: جRd&^xP%+fm@u? ]+\t@we;Dz3;I$ki`Mu~fYױNPy#%%W=Pukȱ-OCn;o=~&>ZIY[xRI5DX̓NAi3@v,iHB{4(;Xqbm,;zu6. .~Ĩhμg/d6(W$^72 k槲mu@8^6cFt__cgER%wW`MOvoiCpu5TX|2qb wWxysce+,hx՗r??\g3_ ~$X\"4ye "r,p1;3/HO.D^Yr~e8[aJ B>Oe[ ogخ̥dFy<##&ς/40\b$H[;s^l%}Ke+a횥H|cd mĚ~q:ĉڬ dUS\: ;\~, 5i%^c74&ѫfS䗟9 c(7`^c9GvY)z: d;ٳw0z9#G͆?0q˘ѐ?ƈo> kF8Pgp_%i!G고\d|fvK\nO$a&Qoj)ɿ,Z ٿ:5if|hw=yΚ*WᲩ/HBԭiA? ';t|bo^1WAuFbw6VTHt&آdI^yk9Il)Jg [ES>a#It},փbU*GAY䚄ayOSvAw7x njR0lݴkEA^HG' U BPB ޼BjX?"w PTARUנnCr%>e}opq(ek.g34>L`$2񢻧nxU8V}âH[eY0 6+-OFv!ӐP -g|j SvDm)jCm9G= cw秏Z_OFFO<Օw2K[p>vFeBb(߼!iIgh-bOE󐒠D:~m$46$Q_Pkp]ZW&SW9(4di1>MGZ/bBy$s$ ([yHrR!MERqL&dW~8u|;ӱ79A57 g\':- :A`Q+["_b5lDEeZY.[M''Ok-)@xSI'wj( م=nL[6Y(%8] SRXzN"Ch[}HU&R؀}nRcjtYb 35S(>xy?>CPlb{w&9?->=`#[i>fSW;i z*<}Ff[S֌LFRED~*;L+oÂ.Ms3S^2R#]">um:p*9Rl '176lJf{AVtUۆfoӘukw/$laBT#Z1MuP$"̔)'?gewGr[L[ {wFsuYxwK -&t 骯?oޱ~aKC?5pQȬZbe^ƻf>& Qj/T?:ox?3>vІCW"*C#Iu;}+J1M*8dOn\d`_69GBGʟ>įu:sf||:m^521ŌPawFQ4}h~;vi6hqS t iEs"J \@ {cZ-'uW&]q$(8-xqC{)7ί^V| 3a(3ډ#vf5N6~6 vL<Mz]}mK=AwR? ֠yҜf su_3r5 0F] bq%a^/g21f(֡37J;Ýc1|)* dԨ^Srus%EqL0`쯥q;Zs(*4susr.T`~Kb=񻵕{g5$Eh,)e̿C5~;%G"hzEE4YS}IIIm_a4$mh?T0T}J]Q4QY:nl9H 濊0C%t](nc ­p:E;ͭ)i{3:g RÚq86CmM;{)7m^ߡfC1mHa^+D j,iRq? ͷ}^:HbҜ>/6?UӴX#b}8q'kD1`/؄A[']w1|>k`˝BFvWAR TC̩ gZNJۧj:3 o_:\IZ|3-.,41?&6ߛA4i>]y$ Y $zD"W]t{ & -qBy<|5`CNrEYسs,Ti~zUF@/ f5s|SK:4NOhD{l6 x$Ecp5Plj7ݶ|J%8F~ٙH23Ŕl3Ȍ{_#8?0}jW\4Y -J:h:,V _G}308酵C\o÷/)|3ȗkǣC$Pԃ777RYV3,y=&\,|HE_U y t%.ZKbx2 磎呁%eJ2 ,fVaŃ.]F#6J`?y(Oʝ#[͆qQ) OYo,_uB=F1]kXJ p݆\HN^%gjAc?JdQM-?_k5jGC#eD٧h_WT;i 7靵i2U_)ѵ)̲"%]`|kdE8/_+xɅ%zKBjuVu߈IhDZ zN({8d0ue]x_*ֈ۵i+BvK\oCe'-N8[=q&N\7_mߋ jC2$IJQu_2$1HJ$'p,* V 9GM@iNPkԈ 9N,NNMc1#[w(MZ4OaR;(2)V4[?vC Ic W[ M@jIۦ}µޱ-Qy]U2ByCQa8\KVm-\?mqL9rTtRP̻u([,Z RFOSx{(&l^bfB"k‡i= yITHn6M"+_x\/QX8Y#:SD\T4 -HF"/\8%^dnKr |ND G? mA]%򭫟kn[U\dM,I6"H<;ZGR<7lRf/GD,ԞR1=PqpYH uyW299uvP5YD37>ؾu&q1~FRz0?˖Gq_i `B4pڅsHs \TKY&,~kq5Ȅl 8I ρqE_Tp>Fe-%e-v宱^74❎cTeFΧ8)do';"{ -E{b=?`N߫̐µ=<` VV]SSG6H<Ґ+ .xbrY)s@)b'܆k^/&+mZjCtà\'H ^Ug=gͧ3BʳZ[ < P;ĩWm$e&q3s[pmo8Hٞ bܕiTjkȾ,C4oͲPΪNM5qߍ0Ø6tU# =xk<-C. ’Ah1oHȃXpK,RI@pvSҭ +C7=3pF[sjƠ,q #o1mg%CQ*.7Y}\,.ccft@~fNJ'tݣHm#@IOCҐܥEJ.KRsb_;DpK}7/,GD ԗ~-aseDh쁊-vD:P-x 9W Ć϶NBRJl*Uc"A@כ*yApۄf;8R&։aHx3kmu*:[TcBN$ra C/]U!zmM~WMOuwhbT{!q7fj#[Q9-hgffC鴀_uߡPbHv[MpaYl+Uq;p#y |R+ hCGaq{"0h1 80LϽk6{) E>4 Q!Բs{rC4^9j'hoZ;cEN#sI3eHV}veԶUOЏf/f}*. ]VVD>a?Y/$ǵNpMK($Gb@9 DggBVݷGxƭk~GIJ:&umAќv;)22Qfn6eO )@R9MbW^eEL]ǔH9jŻwtxOmV 8#vHK|Rj %⨢/9߶Sw`GsV+X,X.,Vri1s&G>R H<ņmލ1v;gV![(ʵ-hx>6){V]b4"a5 $j^1C, -v\Qj^)2%m1ݞr<$p#rU!E2|P64malt{IxZ~°4?ku/S"eVbRޫo\#RyT ~iAyb|7&&jKT̽ *8O^<}n-j#W_pES Bfvo ~ q%I #^,}G~v(|$0)Ay+N<96'ѐdU`Fl ZupNR|Fu0C0;/^`.j{Tf-9g 9U0+ 6sSZ@?;c7 kʅ} 8Txd6D܆N6'g'B-6Vo%GTjwIx Շ$mNA_Lhŝ 6Lj0zSOWY0RX4ed`HM_ 3nA]1dIakR.E_=-}˜OueEm8C9n^S;{ v1Ģ_-M"Ife8n"Ck#e}ܷ),j0}[|[ o){5e [0 ~pinWҟ_Pe-[+}Lr񍇹1c-5iT@+0_~nDxtndZmdZ-S04m2 `ʄAy)@cltOP/ggZMw~-,`2w{3秌{[e# GY5-}..<z?[RW54W6݄b9(@r2Q)+ ;H-?4#9}A  Lr?ϱWq`s~@~Qfwe2 ?eMW0TYMR铃'k>K9gI fT !txN*#m* UJ{݇a,vVX(?+%ΥD!&]n#SK]X{P:x], l NqL̋/T!+"a@][峇v-?L3B eq1 N Za*8뾗+Ea3aNCS8a}l"2~8(J6`Ѳ~1SuY(hT-ϩi֯ybE=%<$R3eU'$&W QSvOmt.6 0<%eÀ=JI?LU9n7޲۵sd_ p[tnfr 2yݷJ1ϫHXB%t̄Pݱk9΋[v#9'V5|-1C6%0Gj>QGjAAKńHK0|m f*kb/GR@R4o8˾_:ڍl8Xkx78zv3T jtJ{^9/c-LdMQcE+hJW.AA؂ӂ$|lO=:#gb5٬Ql!ӫk-XI%'NҦ0txqߺ ~%IElrUvW dCtH1ٷ ?QGuT9oWhZ8Pf'1*78x8D&Ysa1{}l%ařM@4KCx^3wXKbT(wT'I$[ss`nlKLjLuC[3͞0J)?nj @oZ eVU(r\,-+Nn=sm;rWG="Ɔ Vo+x*2{G܏i?U΅"!0v9#&'P&%E4&$v'N젋R~xõS2\h/׵c}Yn=3Aq -q)ƅޅO-t$d!p2%紅YeNlD;,F(O_lvt't'z^`k^uKGƀ^g;3ʛVÑgz+:}͍o\LKNxd. kM5KԸv,pDXIӀspQ4Kz+Ev ;eYUE:L,Lm?&֥/}-AIkzu[_c5McҌM+p]ĬbtQrQٓc8W'! :Mڣjj`9W,\ $}eCyq|O Z,sMb>*H­4?+E_'?:žTo"ixybD)Vs@~/ jH C A#ڵ{dcrKVgMr$W e@^ #hI9o ^ #AAup,&ϝ^d 0OVexTXP ҹ`Ws@K,^jh;4kOHDE*hk'Zyͥ=Ϟ*. e/UbD̏m[7o/ %s dn.0#`2@l`jʢA;Ӌ9b1.|{h_IorxzK-Wԕ,CEdu4|)}9nƐ-# D/P58MAiG~LW㙍nu0 _wOr;+*_n4o@Xb8,A S]{5at<֞ZΘeɨ~_$a5wIӔ ʗcgˈ% )Y; ص@@w;o{>zLmyH*[a1MqZĢjNTcz 9$Z':+",AWڞ7l4 WΖ4E_oѮ(@ԘA§g>1ҷ5x4Rt!0qY~e5'4F#_|5ߚ`F|`]~ΫG3vҵy$3>lfk\r3Չ%{b|JV|tPL RٜdkQ]S((kVesR/jTN}b5Pr$xcMK@-ߨOжeπuOIT$FB;#|"ʻK1m-r֟8|ϳ; N81, 䨽qcCxMx5"f ޡG:`cH ?sEC֐͘\O LߥEOo/o :߀X!9jU j_/#Yp@{x R1G<͹5{_ :!ծJ;5b mxP{CܪXt=( 0PCBw/̘݅Kȷ!7&.sD-;cɯ:&Sԝlɿ>n"0yXG`!S4eIdG5W&pBmf.?O|<|kHK`<]ϨMPNNnje=EIdM^_Ț!R\Yf@ΌFL%6C} [QͷiufgQdos=:}7gl*AQuWs&q0RZ*QӢ/*9ϨN/;XoTmQHNK!;c~@ ' w’ Ë ճYr/ryvA *u|jS23ū-6I pr*& vőq:9ZĸFc$]0FU^hC^#yg\u}o$Ȋ87Di 8H.cs\U\Gk]G-Jِ6VJ" jȯHo@)E,bGfՓrFXtU7{R}{)R^5hB(.+NjdKj1bAQSI1"Di%oKDP9xה;N3khW`>t 7}hQ `h\ٽf1s5l5Z#!dvwua"& ¤6"3V_:L6@9D{BK-vW}[rvua>kG֌?4ф{"FI0s^J(,E$$]18;Yuo _@ڼ ?q5?`OѳmX>vV1,Iz-" #@5b qcBAv'u*5/"LJt_pD&$xV%3 E cb?MmF7f^8OdDW\whIެ!I"($yڶSj7->ihaԃ0[aFr\rJݤn~iUu-W}nj?FUS$kՂV3Qk@WB3c U C*'ȥ 1CPV84M)Б(t{=Q"xd|&+aގLjR.@ϑltfA 5 !")dm{۟L.>o}'Yp[A ?s+R]ٌyFN/'_iCTQf8|3S9Ǜۤit2M[ޥzKMаwyF.#}~\JyqIZB7 ?iKrT}ڈN#\g" pR%,JGK8.(R*< tGqTIS&XfSZl%gRkBL:|-F`]97ۂY4Seި _͞$) &[=wv^04K}TE*$*v6x ۙ%S o+M,$جv``^XW)*{0bV,_a4eR6!cz|/ԆmTZCOtXM%49m*@ }]g+p{b&AX˯B| \#/Ilx-L+fı٥hzyNLUXW̠FDŽBJ@"<6d79KM`g#c-ajqC>a:p]˭nҾ@E} ;7&B'I@HRC?HUH 0+bj.T'G(I_9DŎ Ơ#w%^4bdFHB_Q@FkB381/|J N~:ߖP .0$)iVriR)v> 9vYg~!?ㅀv5O/ [| }-l?( Jꙮóz)~@[tVd;UWpBޛSBI3=)u?A.qN,hǖ{;(OCu((%ENn`?Gn8[$e^x0  0!հCǾ]i+$8 Rrv]$(knQ{V7w ZB,ZDS= I~<&h'xJub^_C(j̲ yjA&9"3sn@͢Y ^?'&jƜ~BSk>,'3?'iY-QzJv>؄EݱD%[V.u !G3 0F'&lz"҂Q˄36`Q' =!gA_'SvB))d  s`fXYc]2϶0L×UYEm,[Uo9pqwJ.TV6;ggNFOZ̼anHW9V4fNdy y[W^;e 2JeD8eX:"' dp\ M`|^hgc j}>$}+PnUz@JTM;Jr%8j0,]ĘA[!G8 _\ܵL K5{\`yw-a.'RIq]g8rX;"mK$Do9+(|eVWe>-GKAؠE9]f`}i!!1D .5XIv?c驽tT*LWUz:7>o>Ox U] |#,,3* $TI{ \@h|ڷ085o{v?<%|3i~ lH~nO,֡& +hVo$*Q/CgY7-um,,@ "݇Z$xi |%ߞӢ7mU+A{,> 'Y0l ]4z{bXчm#Ɵ9,9/Gi*u76LgYA#PH.}XI)w/yw{2m`0fM&"Z5@tZgnVn7O^މXzQIA\e|ÆZO'Sf(ݥT84L%%!,%c 2xyMhyD h2K+ċ7פ>Uܶn#:`H~Qф?xK3a`3FM3hZd쁹Pӆ1YBb3u "E8}{).i~|cpi `rff YSMR Ƈ4ifț ć*ѧ޳\kްKu-#%gcGԠsamq4L'0H\ƹ}lnLrLXz3aN /Qn^%~ tMv bvx(-ij|[?#vTW†SC$\ǖ_h jM } /YiEǍ/x{Í{1DZ}S *}]lT{*n:]gjqjzAզ W*9cŕ6"!*D-pA!FVĜI0wxp眪).u|`B.<Ѩ@3,Dp2dF0vexf6G pDGG٩f-ՁBSL5l@5rq֩>l|!+}ujf4h>fJ4&ܷl{IL 1k irgu!<{4"!lۏ-Asղۈ<R~;D*)4Zl1ZkS{OCƊ]DP ZF; ȃÛw[ b!mnJaK&)=r1+{O`Yۼ2zV<ۉ^]Py3emQ C/r=V|C푢C,fr;d@ϧo=8+}59,Tpty˄K{f{:8Bv{j(9T,n{ ^찕,oυ딋1*Dk"'%1Uْ.BOK>VP+W> c>>#KGJ(刀G0juO4xednm4cvjx* vJ`SK$>_JuWkrr_W?8voiQB&|45;~hh`2[uKZP| Je%Q 5V+_4+~ 땕ݲQ$|7>o tŇCS;mqq<ZyHV]iIDШ=QF 2i$?Ag#"m){RkލYBƺ'He<0bnd8Yc`ѭ]`]|g`H1l,IQP6[6Y8Oj C8'm\ׅ2ߠtT=\nGLx|AF?Dyєs؟G^)-?I3YfWM30*HC#8~8OK/+0}f~%z.wa92* xW _a> w%u$LbZ{z%J]A%y*.>1u_^C2Ll:kh,*2(T麲×Q}yu;z U) $hƶҌг('+G驇I1ύl&soJ9Ikfa {si~Ւ잁Q ٍm]ѭCcݯNWF|% %9A3D7bX$`(\D0>;^3.&Slfۗ -שC0-O1 [׷aBEw3|g5[g–ȏ""xqY= t"^:ؤ[-6E>@a Te*9C/f:9] ⻉DSvRq͠=S@{H6z6/#,hfwDYDg}x5Tfh72W kVek1!Ww17N3 NN4Fg0>p#JŌjCX#*͖ҤC]q]2sE8 ׍}P>(VFZg܉Ȇy}KP[Ӭ5_C[h,5 2,!#XxGLV@~E\ !/@$fV^F OW Qe}VD g|&CQ~2l( Rh|ǭX;RiȽT$/#-ɝ g;@Q^`7}Z!|0 PK5[6wdio*s݆݊g9ixv9VԗMk-l26W"0Ywb0XWt|G#q(YKƯSvxVA6dTW ?^L\bɼޥ\Ij4l+7=j5U6CUd ,yNi`Ee1i< ,B|zKjӚlG;nvGv0[ B~oV*LmIWD/='$w)$d#h :Lno{/ <^p#0bt:NI/dyl-JW]-pm[ETb%p̞q6uғ3Vbpș=+Z9"&[iw=x`!پAi.+i E@ m^ N`7@t s7ۯљV!ShJ|Ylĸ ۮ Ef-A3Rńtn0E5;' s(-ekxFF ‰sMÐq"@k ˸mb]^^ֆ;&Y}"5^QS7O qui^dh3]ׇmFK@d,: jWG{*Щy6j2vDONGM~bct;F%̚9ҲXv1%K`C{bXφ7-0df^([ ]( F*&6PD8uX*/xK|fY-&Xdx\#>e}zq;Hcx;K":WMN+I}ͶghgUo룜=21MA[t0J-YbW&'5T9Zq}h_w}/~H95VamZR̉NdP'{, `ΰyu5S="z1'PdZyjg%,끄hXcWҍQDtęk9&L\ ?yϹA"%, 溥֨Fa ZH_TZ JەcøS UWYGe]Vs-9lph@2{H596%2!YZ$/og96_;tM+y`W/!Kp-F/K6^Y]Q8| ~̶!* RoR Q8別fNUSj#%Sf[K*g)HNWlx=_(1q3ƕrK'D]$\JFv䘥w;_+ZѻZV-JM 쫡CMrA?;'Mෳfy gAKwЎђJZ6Gc/zuUlP? 脔J@,bsۻ;\ep} 02c$4y;ϋ>TVa,Y!OLSAs:p6o{p_4:D@,5" Y_TIq@1UH+:/שC.I'zQvl0Ӕ:*r͟0\!Gd;_ҝ?ˬ h,"DЈ\Q)ZqbgXLSfkq*/tJ4hlԺa2dϰ*Y{#szP:I.n1Oy޿&coשDU',,Aq|Z gޢ [#xKOiUt5c̓xf)FJ,SY Pp.MPHk1 yBdMK5vi!:|5ƵIynmzcW9HPz)փg]hA$$ v睢>(t-3T,ĠixͲl~eĥ\Cb+L«a[>'bzmRsKaqzg%9C݅֩Rde`YTh,ȠY9*3Fw@u js8k$mN?ݫ.y:t:Vq§)4\pm9]q&x9mE[eX? Á]EV)3GzSeN^--8QL>s&އ؄+sl="_n"xzVI (̓J)+y !SD@5䝎2v@¥c"v݆hP!vw2x㼌z}c_7t`^N=Np1g^l(sgQ2.3 +.Ҷ%[RJ[?}/CM:&o2mOwOZr0m* єKIm3S/<@eg!y4FNdO|,OIXԑG4gQjT&׎9OlFAysLx}qf96pm@ :&sEQ-o ;j8Kc><!r~DAiC<ěfIc}xЃH(!4Iɖ+j[AIpZܖ=? 0;m9yZPw5HNb 5HZtL,έ)O|=mpr ?w`LhO#tpdTߚ_AIމyP;G וKCV'5H"vT{KL[)"|Mu9璣E.S; [fCO02 PYe?Ffq͊V`)TѶk˃ɸ.1FU ǒ M;|N}aP,c}p]8_»LIj=J=d1 ]ڙBVkm'n&{Nd\E0؋v=[ve8j?-8"CUhHg!<%}f ̺IT>;ʳaWEȰ/e)9,N)Qh6%D/S$'+/2vʂ)Lx> ۠fv\UE68 }ЭtF&QգsvBљB/PU@n`M O{/6*SH!xՉaK~HUT1l1g$z U^PR 'f\3v퍣k!O_X2R,ttoBH깘"3O;Ix訞br״(oе+s; Q]pW;L7:x7@`jɒ)i.% ¥#;=Mw*Vsxګ-8U(ȼ}Dq=?C%Cl0rh5bx6Vj,Ő~U $-YG4xM8I66;d; 'u yr?8@a;M (pS9%uպ.'\i?d4M =mPjnQNhV#e;7M=>Xss&IJ{)*{<_+ws5\7.CFHU"-o0؋B%BP0^UɆa~kkxoˑ75nV uktٴ?تᅧTc$WAi߾m;!X97S/>h:)/ #!]mRnS@D5A47?LpQoK.zB`xo2]Oi) go TgYoFStŠ?GP~D ^q:*H>|OYxֶ)$yZLAɮUnX1Qҿ52+䇎.LCalz9o9V M!͊rPjt#AdAkC/[hJ)1DXDۛow`T".̠Xʘ-v:>gNo#=kq@/ UX:_((ZBs4xp*qkez 2¤Lv9-22_џV[w⋙B(k @,TA||^yenu)M!c8pPG>Pbr6ZobvL}7<˖] XE{9]DߥGWf% tBDp(5!{c%݁pl˨.\puZF]%o]rɷN#BBG]0gx4oϽ톤WJUއ{LdrpeHiԊw5oq7{˔0u~A$,fkŖEmILSPOE18`CPU8YXMwH/ c80ѐJた/]xw/sxkqH=>7ГlQY/ ; ]8#!?aJÒJ= N҇P8vd{A?"7@G2) |!sH4! =:^jMtVnqvt\}f*mUs“P4-߇W8R%}f 4eaΣͧ =bzB`wVheAs'r,-jتXJUJ9Xcʯ/jT"0YW_@:6yǾZ2~Q)aù%pl2&e_0`Mr(pHykZ@5Yʡ)@KL KV@]Ω>yI~ۓ2DҏzyLa}ɅpiCy.{oLս^рDnYOղ4WfDlx\ I%Q%Hէ^Դc2}q D?`yQ2T­ԫ{lu$5s'$-Z%͎jnZP0L{OePO4igQ/77c) w͘MoT]WN$Kk0D@#NE B! ۆP s{ŭ[dM8R`I{FT1 =2OTB)p OrE: ق۔rɭڴ ~ʯ)E-dJ8nh9Dz 8{XSKGO?a.f9 $5> ا}),JUf.vOtz_C-#lh q"0 m$mue6fřdi4և}0Ycnr2N%Lt @zqycߦ!'Ͷs̆9ptHŜja;#8*[@;cTsP9Qҩ`Wrt 盧I-|}DPs:SU@R+ë&'f\̏u1ά<HQHx3EwAN>~U O jBѮ3)#{&{UF7꾁!G  ?W'A~>gMnYñW(C]u){=6; i ,9v3MWHޕc'ZAzC rKY;l+v#!" ]L/#c_!Uá¡C`b:?jO Kb, &h `P- ( vv/ح-z7JH'+u⽭ ˇ`KfMv>PQAm=PaG>twvFAq&ANu϶eGx=pYiE~mc4N*6H&4MO<,D,@I5:Uu, V>S S89~<QHFh.؍O%M媃ˮ20y>M^7#UJES= /Cc"1x10<@9A24#?4 siHpRj ^ّIT3CjCGz)e!^*d8MĆ6Lno&<p/ T S^ Rӧ[ -tkȌw ǁ)28 قhEas4199rx/JLnJAg*!Ao5Ag6BoLS@{Gj4C?*iNcߧ;)>8*{R/D|a+:OcԊ4Tkux5:tsne..(u&Fج~ %7aCsn=  (W6s.,[ȭneXEYDt""~#DwZ!B,-Ij~20ak251tq^C4üg\{S0,<36{PW8:OqFobB.G0@Gt/|"HOPolb]C#|bUNDԽ{^s#J|E-pF P/A dΪi4ކV}6n+d6Zl:HhhH}7Ixf{oVT.k $o̔)لKudnR1|b }1|>VpLaKs+>hf%@O=}?,C)&rI͌0?Rє#/p 5x|+p[(⺋=VS6X^(2DQ)F>(`^ͧIpȦ|~wSk4HZBU(w!%$nu ͅ}xHo`⦯6ߧ Զ2іbMHr-V!EoJ$(ϛlW,|+N iD[84w(lyjָ㯋օkp[ؐlEg$Vzk8)Cn`P1)+LSSRL;?U,T,75=md{}0O*RߘՎŞtP#b?_K"`1LhBsƤ`jWh# C0>\j^68.RsE|Ji0cA <Ҩizq+TSgc,N&0^'CyD( Z ;O²s{`Ik#tA">TfoqLrTbpݶ>)zDIbz&csH!S&T#WTi9YNʚh&$"P0.o[xXtKs+k!C"jC4.{$ wYu 8%#G3)*v04VsY `?BCHߓJS'(X2F5U3ӿ.s~Hn u66LlS'J8@W陨8õ'/7*Ϛܿ?K5O$_T/FjA sU? ( bc x gJҹlJi~ao3=$:ٺ8M.0w|($_%F"3 nn;G2X W2#qs?B&Hg$SjsI~ʈ}צk"}#w?UC]ldu嵸]E 2 $cDq0G]Jx4I>ӥ'f ' `soD*ZP8& wg\:gSNjk0k.*:a!7}QS V*# _uN!A q85ɠ3:1*I\u8kcup6ad|xǸSäԤ18gB/?Bb{rbwMnwXp%9jRJܹ38v˜Pi %zQ/M2!Za,3ı Qދd y<#ި@G 8..? 3Cu<"D*a~|*r"\Gv1A83"t_\Be+7g*Də'O8o28OJ@dӚ³\F2Wzx {@rM0TИ@ԶqsPb*}@x½ NY=]ԸAWƒa #GAd-V\\ܯr*JrEU3*hyQS7 hF+qΌ~Yyʎvl, pT#c;jlȰ^#ne=/^*"$f\v<*⼍vT1t,*/cE$@q̄ Z: '`=X;7 b}L cjz7zml&= M͂#Rύˍ`ed,M{E-j9X|b {>+9s9 G-i)-Y|wdX:܀IEm ~<v-[݈tm|ZPӄ76awqnGt |ݏPO[:VJMIPZk]!Ob5M˪L\M#s0g ڳֱYP\3}f'[z%`g]WYMдGg^,bIz[@n|{deb7k| ZNyA'j#`tc-:{ç6* KCbVûE  9I}hj pO2ZIF@6+(Z󨝑}~)t(!}Ld/S$H B}쌲'2<~{0ēUȀXҿDRVrKB.OB Ҩ|ʋl;. .3ٱ=BptpЯ7#$4rIoGM񒃅_ʠ8讧,Z8lM94,>Q;8&fϠҗ(!"U!nlbn팓(ܦL>UI#v MSy5,CCYttB#hۭO2Oܭ %$Mw2jTi%1wHGTx[^o})"s 3 7%Gb'XFo)afNbV3h_H7%i$ ҵlG9Tq_l*+hBXvHlWI<ͽCN$:BG$T<tusҘβ:GzIhp)^͍OHP m'U1M"0r)BŸm6?`!5ھ)%~MLRDAfϖd /y R9AQm4H}{S1_P}e:ɋ1+=ORL_]K5y<+;(o[5&qы^1hS'^rQD$uIAd݃{![hg}ꁊ4gAyEHu%F|F -׊䬲soK.'YÅ t͸)F9w4#/0& N u#[T5=׃ gfOg&9F.ج{0r2i($+6C9МA)hDFNk4#ع*D![/ZvL Slj0/P0+] 3tfK bu v|&Zw>+RI;lY5y6YȯmP+axpsAxbȌ}̇J"]?TnKgU]EASq%2AȋEVrE`3`e#X ka!Iԛ82_>re$:Cb[Z5Ug xiEq^a63Gټ쪻4) א\~9؄SMYLeȦ-҃%SAwdP&Myvn+[~tϷEGW|G0A3'a1^*q46)57px!ձs}]0<Bu'+/ۚ=AuWÂwakue7n~ю5kbxBrg PUE}7,m!(S]d|dF<m\.*+7/5c(UJ|=S~,u6d=\3@4jDUrptyJugtʀAŹ`=&rdesMJ&Τ^(hwL4ez +_5ErF z.L$ޏ`:W6";:rn=x1Y@:=(N܃`3z5p|mk,l<K t&Haz㹰c&C",`wQ2FN+נpl*Z! (~7L4:a}g쿸yM3pkӓT+r٣2r7r^L_B&xNdnGݝ:0\@%/]j4&}i^ 'YeZ?XuȝFbb}X&Iybz;v9`>alH=qR ?=4ƜySXïe ?6żnf3MrU;p f0>}р?0h%dsڮ8f>&otQ0syaPB <èɔzzsiBXPENC!'*fBjtaYB Å3 v$Tk<@r//;&>8'lyI{(`,R#+QyCQE'^BI6fR@ (X)υ!?Z@L,oi*TBhkg{RM?qԗ1<o. :1٬ODQC#Ռm'|6׷:v@*p~ۭ.ӊ#Ո䰗$n Ef٨SZvM(zXt:UZ {OJ,-7oxSJΦg6yk9l.q^ƌs>I;ʴ&p+YM1j#lUaF'MbQPWXaeQu`xR׽ճ l) 7t3i*p'!` ?skpbTM*E)Jm'|#0E5#Nf2lX 'XW q@NuZ^G OLٯܯZwϷkɖwIdDG~XF:X O717S,S`#`SOt_Xѯxɶq 0eyL+$96פ*^MQԾ"ѼNdt[P+&pocsv @>vE$\ѩA(g8)pk>UlMb}ÔGGIj3> /׻=oFxw۞`ʒX/xqa2sдNac1•|S2Fciڮ:i%%wY2bOQ)w)t-y"vο|L>+;px9TuwgyϛW=&qM_b9405|G񆎨ZQZ\y g!FkYˊsI`a1m4S2=- u4Z_0FBO|jåᘹ!>*ʑG}{6 L"Tg2%JñN}s"R/n+K0h7d;1QsVˎ7Sy S eT h$2n#i8 L?' %{H'_3*5,Qeq Cn25)[*~eܤ\:EJ)* ^Y*@IC\nWa-18φz+v;}N!e0ަuZMɼx#|asɠ_LAJ!4 תYw1@>nkXj % =\买;?z7=ܭi&SeھWTL]9VzDq۶l]}k&!Ɨ%N0f}v"kL Zņ'(}(C A{~k뭪h3zƕKAcz y\C d4԰z"-o7\zS0)/o?lhC8"p=pB/M.G(H3f#ru =Yn~<߲)/YLZ|L(+]dEfbƝrB 6v7#{L['EWȀ}X}"xHل'K,VnբV+HeL_h>=}EBGMށkFEgw\'>RI<ʢ(m=2bFឹKhuTGu5 )ES_3?`Wn&G2ܪ;D/q0wa*AS(vbghBcj6 oGK(| JK?F۩"%z6I6rTRYV{Fʀ5FV A:tDYAvta0 EVxu8]_qd`,Nyi{$:P2!`jdO~&=?dA+;>{F>\Xis8.;\LL2KlCW״wZ<18K0DZSQbr`FeM$4;.-a亘$iJMX1<j;w,U=\`sU- nQL|Ct1./+a"*u##켾!۸"ִ{]&qm:E¨JY_ef~redpX@ ߧ 7=x<_q5pѕkM}"OVe MؿFWUuJf>u_|˸20oogʁb0BMZ2{ޣ5w^/m~@h.k[d!n__̍PhHλagLmi%`D w7 ` FlyC/T+6PJNh$NE0O *sTC4P(>QtcXoN!30AOC\"mwQTw@{9\n{Y Ĥn|.HhQʮ8%R5^gU䄆&\+mQ4 n~ܚf /EfESGA qץKt{7+Ce/91X5:]@9q؀"&|?rP:! _Ӿf #)Ԙ'Ƨ[EJg:<oKso!nW8$@?ud<;!r Dhal!PD6 밟:pKWJp `Q; (Ӳn/Og5s ?6X?>$9r83;5%Z 8=+; Љ:p]dV-1k6Ѭp/^_cV+@dkS+QL.=)T5+C "褷kU®j#'9}Úx{4)Bmr"o۸צ8糳2˧gpJnaCk5R$ÉGlj`߅o2 0b9,OEt)H¾'b&8ϧ?-~k?kbRbE&9rL)%=73~*pc:(Mz ݫ[gUA᭭*P8Pp;SNU719;kY֢|7\؝}gKeEb事dlSC`i_HoQIEV[0Es>B)ӥoqoae A%baQs@pcqE}y7(;C[Қ%k.wim0k>$=X3@F/;ּaܢzxHS VaCG:LI0:oi~dB p4!O^$ŕd&@[?*vix9W"S,GúTbr>[ʘ!v$S],<{AJ`-tH4nՊ}VљM@/7ٰ|2#꽂7*MSc s.ȢχRq&_vwg8}] S&gTK'}.1A2),ʴwY4tJ .q"{C8AKȜ1aɿ].M9j'_] YYWDaxlGz7ehk!}Rt[*uCv}eɪo lzfJXʳe-AK3w#.uXPGfXis`;/ikĹ Ey\V،1qy枹? wGd d$$ +G=TiTYۻT)4ygnBwq<8 FF{c|xI1P0wO tDNFs:菕B?;df7wIRnU G~KA߄_cˠԿ'h.7Y۞PLr"ra •DRڝ-.N,n:]SOēdtQלL5"贏q/ j8"mo^Aݍ{>J @=x1dq6 '*nl#iagѹcّ2u͏.ۈ Z`n?@vTMdo̲q"-9c6q7&Aq+%3eK%Vs*KpɊ gz0čY9BN6Ԑ9θ %3P֨jhVLZdQ5jۼZr0C)">WEɥś텴mhsX!Ţ%d%;rCD($frrTEdl9ʼn\繨5ګx-bY/sCЖ{ RX*T:29 Au+m4׌X2V8rdjߞ")͖Dnߤb՝F2ie:[ u t>Dw tyDqSۂݳ#]兟xvo]D8_2$i+ϮpD#ͫ9lfOm*:oQ!t[c0aTy$.V((kR^>Ts`췮0#56Gca %NP \ޮ[3KpO Q0`EU?Md8=xhzhOe}oK8k,FvcF(MZ.cTce1dh w.Dk܉g >oMT,b2|<)`X4j{ ]¦噋-7Fj̨Yyi?Z|K3XAvCN G1+2VoҚp$& vfTe2KMVupaP9Ǡ >G9UXLPw>zPvۚDN+ilu|MJ9Uƨ]6c2Nf`2uù$mbmzmஂ=Nl {o 9ɆԦuU -~D6zt8NABQ2a]CRP͢ސrD-vX@%\ 5>Ċ{GEbo8d!Z1_ak=JH}V m(U?jvU.uZ +cxÜ^DjDyTʇ^HO/Vk m&ԺU%>67iU++JW!IRZ,POρEbc l)dH)^$2imNs/B|P*Q\A2] rw^LJߒoCO/[} b`);>6c4LStVXD24?Ω煺CƝy>8HDDBJ׀LfLfDTFc[k[Nu7_¬׬U` Zl &k*JwM,/H~6J,goPa_>5 ,7!Jt&hԇ ~2pߙKg&y*,ס(yCQT7c,ҕ9vH`V]Dhb87 B6n!afلns_0-^.0}2FU UI,-% H:f 9rE6BǛnMg/1%Ɓ{DE[ 7P>^ "I^CĨ9e2ĒpGo]UgFf?raSEJ xpGNrɃhe_M1.s`;}أ |6gc$.u@k@63$k@WOn9gFL" +]A)"Y(HW"1)CM̼gQcx?\J ՝J AbtϗE*~+o}epaܔbl؍ 5 V+&8z15M5/%1Yݺ0aQ>2{ G !1x&~~ghvB'ϗF? Rd_|Vˬ |d]ڎg9\|ëJN=Nо4۵DDbW)1?JYiEn[fz=0RW *+-i>X(`uHV;!t&UO&v]uFV, hv,73'CHRÇS\+yCaZN0LsNf mXd-.n<0nЀ{w2<\;y_4kmPc?w8C>]k)[/7tI3>.1dޢDt>Cl7l:s~(Y"-4tSxSEiBf?{?n v4}-L0'8yَ8YCzv5cU!)b|8wBi8|qn!mrJzS*G>*aޒj؀]1U8 ke=C7HZ1_:f)Jμ Ob$I2*# i"oUJ=CG8+mTE2K5MaSQsa0wX^mK8މw0e@{,ח Ί7e`@=ÑV U"F\,!M"H42G $kBF؝AfI2^ #;~0>;{Cf&>hL5_QS} J8AWS؏:l iͥ8i8}4ِY7UxUm^?Q1!an*qŲOvpǣNhܞ%; ֵHOhMတ}u>W-21 ֳs~C@pYq$}U(+q&@p,X`€qī ĸc{- >t~OiH)xA8^^b{ن~--@u0V5Z.zN|A^Ɏ*Jfb7܋qBIG;_z\ZO-6X"!8r!~ɦjbMVϪ3 Q3kK/ W.cue@am"H|dOE+39w" 2E;L]uҚ{dd6͘S[c8i"5yd7k"NP鑪u8Z 1@D+1R,4z_`#M5F]s07YȞm@D*Ba.]eb[镺1QZe,}V9rxuH'O.NN&d'[t˅˯^R[S*[lC(b'vJY?+84Lu0YGCG௓zd~M~|8@^g[{hOц87T>kk̄tsreޅolD녘U#Ma q}n\=oahۭt.kld~'Nek4udQG-AS[ 8hwTRVoEbε<,}C12Fx ?4ПĿCcΠ$;[rR]i Gw`T{eD`O$r} Ѩw_GwэFm1d gaEлc$~r6;†X37] _oF/_HЀa%(S_k Z-S"K2@Rʚ!/B[{LldƳ7tjyʚ"?fdHB{1p{M(:71V10Ҏ}-hb_n<ªį&7_NHQk hLBm|_+閿u aݒ 5i.k/Ք0L`IDUנ|aiyaǽHmv5bo\SgF]ojEm/F P_`fd#5(@F8$2@[v`g07'Y `-76< sGs:[xLv iG@UX1T_ZkE;b|J`v.\51Ϙ8v1k ' 1` R[ X?HVK+86z*hx>߈7.(#WNW|L/:$gFd|3竍*w}ڸ”^C@Z+^H37XXBcti(| aNAqNR+dVg8#J3xw6+i':޲iC_LcxduC%7*ob3 =#-;funA18VxYۭj3op*t\ Uw#"E+f¼ smdL6 Sh)<% Bs!ʹLdj6 .a݀:;Ƿͭjtÿ́c\o<'܀EC͢:+ƀA\==@WmۼH "bSsZƶIh],M PyH }y^؊UHG@ XΞ4$A{p  kPBҜzT1oIéSs̎aP ctrB'HknGV4s(Ȭ]n;F{Ktc0`봕'Gw~%0 ט?t}in.~\uˢ8v7WWS/._i4u1nRurG9GyD7`:N1D7<5':2]UoZc%;zNn(h?$QUhDCx?jb\4~2N~85UYv~ 1P._(,Dz̘ L-D z"Ϡz,IYRN#G8h;w}Ȑ+#;r 5c8&h,:!d]]W]u."Ox(JCufN TD $J+UKW ONph텬.΢y^렶 Q˻i2C;Gtxemj|@=qKz*2u'Mkn4G.BN v¿ ^pPQa*h2ʵ ܜ._kziDKh4?| ) z϶gl&-6r`Z@|0\HMkW;}P-{İj?.=kFk*fsY9 46.> F =jŔ'?fX(܍G=>X8r'+>s:Gv`i_ln˗`0БGLb|{$t)rw$:8U^Z8\=\Ve"zТ(=un?1v6ReiF14}OfqXk=I.=f*lst~6#J:wX";=ۆz&n.h0mJUwɊH49Vz#'X] S-F(~G -izb 溤_6:I b\f m~ZJFVo w/5qMM2xCA @)ga m@P<@!{a+*uχR~o=O" gI̶*"sIJCuy!>֫f~_Ў eNQ~eG7 &k]c-"o5GA8@5>RC{m>SÀt*D5#jY0ߗk7bHQ2:io̍]"Mjzupyߧ  jjپM'.5R\\# %Y3P@c)\/vMcN R Q- ,9W)15\fEG bӄLT :{W9x- Śy:7Qa&d[Φ/\Nrh Ne~ +˜w[ / no/Yp8y3]Eli?Rݣ߹^4>>'.ޯ6 \sJp.-^=[Ş]B{a2ּ.\ʞ.n߸-DZ_[i%lJ<H Vt]21HrLMf^Ww:Mź7ex9hgԵꤌ#Y?L&aX$aXaY8$Y$4/a:Ԅ 1ִz4z>YoC$G>o1!'nSsާW/l3C_9%{ c0P#˕0$x^-BiG{}e07P9;z&[C[Gs&:2lWJfkiJ4l*1@15S)CP1p&X?nx$*DF|t[gEGE¼j&HiBQ['lGY_L@CT4R->|g޶sAbu \5<[r%U{0D[<-J>N &v{Ƽ_gR\GyԫTeXږ ˔Ziu{r5+,Ɖ2|yF;NIBu(7k}īƒ"+JXD?Z;F+?xW嘾| nZ p dZ;j[ЁWߌAYh^VaVq{Fxǝ4;GqJBT;{k=(9`-D⢓4+L|dXn^ XQu=3mrQ10⢀eSm\F#i "Rٹ(!b }. `[gMMi^Hjn ؘ{|?A|G=a7+&PaC6n PPϓGJ$sVՙSZmo*"Q69_ǭJ˷ے!X-{l& 9޼?DL'Pu ulHT\fUd$G@XI״*qτXogk,8ԳX;[*s> Is1!RXnH voT ̨"HzՔltMl: wKy_u},yȭzf6]* ?}ij%g[w܌ *'/$L0bϤ3'zT!4Z\섦CzfJkukq~4f8 I$_"rN~?C2`S]t4tGJkac: `x]&ޅD<ʻf:RW RO)h+7dKr[P( \w_m9`獰':͐3 ]st`~9$Lװ u} BYuyt골.1 fLe5oNL35o/*C Qv{Yd="='7~Uw0 e F409n{к @:>VN]Ͷj~E#ǀاCNaP@:AHBB=/[ $.V5L^xFf!t+mFx:ImHY}Nq\Lр{Bs(fSW2cjFTT:2vH]>#LG9Pz^T̐e*oaXx+mt)u9+LM we%nl\9](`S,/!Cq0˯8 G( ZouJNC'o[Z9z, Ӎ;e$;qR1d#&:dUO4lr@ob"UnN=ɇ1v69'ϥ՚b/~;7#Ϻv>`IMR}@-YèXZ?I]QV[p쎃bi0L'q8vJ,wCbHοJ+gXxɭI"CY11eCG?&pR)l}#g|sH38=༊YG V)'XrCN\ed]H{1<\s:PPn]Wr$,⟨K¢WZ)_ 7D rJkDPFܣ8>k#E zf"%su^ vTO]9&^> q >'iԶY]89T@b~`u^y?"O $ Z "\! @k/ qg87CE",S<5PW$F=.a?fp%wj?e涻Bd6!>,j]a.BН 1Uz.R;M#ݛKZmP'>먝:J0xQa.+h>C:7HxA~A襜lk3g EߎBmsQ [4H[kYg uʏN#WAeB c9U3ILڽXClt2b* z&x>|32a&/O?ԶSc{{*G N|UwFi8OiOxG(Uzij[\Ę:|t]LѠj6x)"eY,;b`0<@]4󦍐V372*Mj+s5'7ڹ䭫G]-EW8<|Gȹ Ve{!讅\t6`Fh;"}iEڵ/Qd־:X6IsLXOGD%Gk&0ӂȓ.366CH?Z '/XKpQg` o+pЌ(ꈈ$+%ǀoO"h"uōm:ĺ+#z\|ì_Y\RPԾ?ҚBd.Ugmقƚ8Ty,|Gļ EwCZKH7,)f+m#a)y韕rs?REͽҬ-51?0ԋ7?f̒=dˁHm[J9!{M14+k·!C]8+Of_/ 2LI e_hyfW kZQ1E>zbHn-Q~85-HΧjur={Arau ?tjk%oʷX%dGmΩu4㵆5$ׇX@ UH DaP2)~'՛2(+Yȩ75ήKGw@P5VEUք-;!q=`G,iC,?hrJUĖ=+G*BM poc;}}7r[FL爐a3!yXdhEpK@d\Hq4xq:E&dK[u8ZVL3rA|H DOdͣI{+~$rptYo5}A!L\O sCT |SJƚކF}W7o88QHqӤV&]j1?pfrX$zUC Y i'?nXf4uZ!A5dLNw@V!zTU9R$,6=t4$\ɉCgp}STfJ7xZeU#S6CgSõ`6Vi06!'$w}I+E;;?5LmKuLgwvD.N`-Tft*+qdW#W`t ޥ a+jZ`Ͻr߽"aHU/`s/TD|ƎזB5{3CLba,FJ)ϻeHgٺD3QXޕՐ TG<=E}+=vuN葮Jј,%$f6smD,ηE,vnXwU>^Nn|54 <ƀ5J&lulf@nM8]5kxdb#r嬍p8DGtOS1B>>>0tu_5l#ڡZppms1r>FEϙڴGߊ$ 9'۰–>)pud5FꇽWs#-MrYG HM]9oر ٻ Dxk<<x7,FU9]=ZHDCma)z= 2 8`ubX>}^hCE#K+Ճ s˱M}:=v(lІށhU7;ܽeh .`fS ۡM@f]0_ ޾7 Z>X&X33Msd bp '[QK 6x&}4jaiQoyMM;jR{h~;C{lM5O!W4ƫ)H{%**|!Z`$ JXQⴶұ6` ̙lk0:['iҏl{孰pזP|TcRX D`/!3ВAVδ.!j\ A_ChN KaH̤oG\J|!H 8B鳃]_%15N ?[~is)!7mCE G4GFuQN? 1$6}o3_ gY+֏t'q;P@!c_ȖbШE2x;/-2![E\& _NZ۽@a f M(L0 `o.r=nwO„OT> ntv uOmDV?b~VN =ڰ/fֺD*ubI 2 ?gڷbIOY+ Ww3/|[?@YFz6pa1Id h@͙Ҙaucs//_puC@й S Ա-@,h1̄ >6#B2$F,9@.?lWY3+ཾD3[ G6*gģ-CY.7K,&TUikڷג'WD5JǮxL^d:(%) ⃎{Ƨޯրzޓٻ._^jXkk\>bYo@, gkHzDꏰIփ۸z"w~04̿( dq< - p(X`W ;|%cWu.@@pS1w%$nvFR7Z.[S0]X t6/G"3`7.@ L4t"#Zr-*yc/і_@( .G~v^p+kୋDlibs~DK]U;Xj}MQhfCg :Vh?WY;0=?/ͬsa1eBVܕmV=2/\; b[c3BU**B΂.Bm{UT*fg:p`?H)[EGsV6~ts>M1OCJ-HeĦЈ ';|ඛQl?<۔%oi8yq@ ěI՟>E{E_*/üꛢE0)tpU0>#+4:%e),9B 16bGupA :dz=a>? X8.㾽%t8SHIuW7l=mQ =TQE,ASOXnw4+K.ezGV`:(4fq_d+.+>-+'`n"NفMaC?`'[ 0-H8!)z"2oK <$NI-u82WKx l,x|-iLOέAM8jH5%^<>Cv|BJ!1uƸGt "0-y ׷4 'e+#H|[W ~9bQ麔/ O`U uͼW"$]AcN&O$ 1O{BwIrE>+K`l-VH7-ˮv8 tkMkҢ0`lG3GָˀRz=J``3!Rn/u^gHVJX07o@ 3B?Op$2wjW% kTN8`bKR%̈́`.HǯLU&۰E틲Pj!K&!=fؤSZX-m̯9AO Oiw^Z ,szx6x+`Q@toF''<[Xc Pdßs&4BY0R518msx Lh:%B mVTàaz<~4\^M.֎UkKa|?!1} aW,`]![2)ɔ-G5g9xuR5b"<_epyH8WNXHp'ylLkm&4x^c{2Tğ(Pxa>}LB*"Ö=鬘C停A~ ?UFYfIyזPHic:rwҶ . %VM~f"Q$dgS>ׂ-x|&pʥ15:tCog2퇸̎4֚2@}_sgEͷ!iRn hۖ-0DH,)c9\6x\ߙZ򹋰RX+1wk9GBЁ(qA UnB[20xlO AR-#5A F( ADeb2H5|_7o!lMڝXVoz.=l2XGqCL_ngPi`8e_ dZ:(B kP@ hu@B]./`P;H+t0$9VM @o9 n[\f<1O"`FHL* \T?nF3@DptaoG8PTNN²aeIo?ӑJ~&.kXc=…R@KV2pQGfVIں.Mhf'.#@5G(ﯻ*1fk.Nc2{Z mRE$W/ߧAͿ~Sw=s"TR|SV0YZ0:mI Hgn}I׎6N.P_«Cm06w^*0:d[ҝO==YθeXU;YX+fX0MR{K#%!;؍qb?FF(nB17n}9Iպmg_|n [fPk 1x DtD*vZ3KWQB! 굑$`JSvZ ,|>UHG7ԡl }" QC1r̷ tN3b+("v 8ݫ\epaފT,WD:zK2#OqB. QD ZD.[$jE;.&Ìz,XkD?/dWKW |Rζ,e{uO2*`c·v&/m!蔊H<n/ kyEul&9;ekFer !CC~9 U$( ]_Y)j?3"kmRWR(rCu=s IoNuPkK&x@=^M3' h3icV Neks0[N*n% @3xmŴJ8wc#9[qlF85xPSa Q跌>t~V< IcMǘ~5xcPQ˫p$ Y*q:"WN5קôaqiıgyR .3PA\BTm/.QJ $7B3{čT6{-=?@_}bA7xJZfMC 'Ĭ+F S7/iEdU]R7͈%TgRXu'Mßw0<]*Nqd:g~So(9{8Hd@ pB(1~WBIaCRߒ3*,8'|{v6}L U?eAڮt)l9\l M@|]]-m$'#XqwB*bXu:Ѻ{ KN [W| c5U*MO ;4ơsnۣ|1!o,Ν4~]$)'f:=c-MQb6YD2`wjW*K]":י,ГܼE0Iz| ͝='y&#,D'q}Bȓ|(e&wN︅'2 ϙ=Qǧ 1Vtu2U'kQ舫)1m7mZڎ͆nNUMrV 1os7&CGx3Ԯ Vw&Pfb%QHT!Y A1uyl~)i s8=|ʖ4Lq,x!_/Ͼ/ rχ; ^:MùK r} :bKDrpW&kOq"q6!N*%`Zd/̼,l+Q$Ut{m*J "fP,p6ܿcH$_'|fުu|+ alJf$Ml`ʝIEg˜nNk!6NwщVn25`&5.'Y2µpRX^n#M\whFAGn?G asuJuh0cx }A8ÀʱL$5]< S!^)'w;hɻw79 ]6뵨ro'&/PC,1k2@*0=8z3cYhj ShY5ӏJ"8}跔k~֯@/{.yÅXV}ɤ0]x&38=xQv,8*p^/XY4iy øAs:}7<國v9]%\(rhdZۅC5He+IwV/{B{c>y%p(L'ݡW?lM;kU/y|mC\ඍz9=pOw.a7뱼֏.Ʊh)>KcIrGnwsOSޒ(  $ze/WH@ay/ɯ_ X"]\scPAs:V~OS>03sVH8b{DZ'!Kk6GbcÝtv=3G5TVYF7^ƮNkI;:|"ZRg[Nޭ֭Sj$/d w~UħrњD7`?F"`AA5lR]mw,ԯR]X ƒZZ>+!'9ԿWҍэJxyˁs@ӹqhO@5~רXaF㗏.^-g@mw-lwݭ*yG,w!28E,xqSy ӯ}N0׿O[;aԏ#DRLrIo`rA0{WU1Ԁ 2~ƛDn8X[j^f܁Ync=;6jkI4a*59z/Y6#sᖳ}4ȶ#y̏5Z4"v14ͥ\&n[[>p+`ˤa.e4a %s%u&3bq}%#ix  ,mRȁŦ1C1{nu|CnXLZw$n @Zpk_03ْ[;E&)!H2&R)`4x @cs"kYx$Bz lga~؇bY YѮG sD:xHg[rXJDFؗ CT#)faz:I"FΥKcsB/ M- IDG`~ GEbPLt'lg,nŒJp-fB< &>Z30T$v]^`^ݳ z쐏h&Ooxfaڅc79pʙavvɉݎ*4_>k @_:j 3Rt=!f5ۯ3mۿ@g4ʴR{ay Md \pdb_Zk:}uGkJ8sW1&0,܀&B&rK*P:j({)WQ,aPăڽ `Ry .:@Xn-P# <փz%'Ěr _9՞JkxZ%_+D6r |:Hp5o'A~}+;NH "m1׸U8jݺ:8[.z>߄i^uAGmj9~!meN_OR^Ppoʆr: 'SZWwӅފбC0N)XXc@B< sӉ0 D!O'S L+I >Z(r("9h!)˷suf Wlzf{T'x+`ڮ$`rR?AF4ɽ' x/1 !9i<[m183ZO2;z]M? R'M!u23T|*2Ny{ 88~uFV>4j#21P;<-2l$BSP養jPBx3s*Bi' Au8Wkgb: J2o М%T;<9vZHOp+zq)QzDEAew{J]zꞵv˩Pu^DzgBnpC_La`{M#8xuyC@;$^@fTp0:L`w\ $[xͱߚzbw HHNa/AkBO+hž/q{/6ӶF2AHP`hgl]k$#3s1nbU vYU/B̵0.8Xf?7}FWc}+}+}(2>UcPrFvX0$ yC1P*zb씠>9:-DqGF#|ҦE _nb F3͋${Zdu_tM;b:m/wwQh-ʡ6JӼ1vl]hOY }*J`N3 !$irF~~("e}f1D*6`JeLM!F;> Jպ},:f+sv!kD ٷ݂s-#wNZ ~AuԚh0{)HI{F5@z0/~UbY}qDz~D6>yWU=: >K9gSU>&C7l]߽`q 1^_cPpSD _Qz߿4@ (ߛ  U;aՁmĪ4ŷK+CΣ>9shoDgk2x0Yn =tT!Z{!r{{v>HjX:zvzm{2W6q WNnR0DvLLUU3KoIֵbːإnp}Ew5t\78Ɍa4prU,rD&]X( T];#EA  0Zϝb"xddxMkX{RnL2jV8py\ZBKq}w}qt* 8#X tW0̈#MU)rjwu4!LO_DN lH:#2ɝΆ55I[XĕyUH&aH$+tH0zAYOI+5+LЁ^scLZ^t26!m M$8ݥ}t9=9r'/m:35Ssb{{p)hsWCS1DW11>hq MtշNPi0N73#ȒHP~>8 h}6`طmP Ig 0ŗb@Dc|vچf8-J.EZorf PŒ~Gg#ÎS~#k_<0h^ *Nec ut]8gYDr8-G@A0WefO7^G.#} )r:Foюy܈,"K0sÞh -Yd/- K׹G'gE=ndh ~C 8yu܋x{T] u-"-)BрwUf $v[}C/ Œ}PPj3A̱{ZݤbBZs6v299}1{sSx?;4z=$G8yÚԂAL^gxnW}ZhY 9~ZIؗ+~cN+9#)нxBB"L!:Y_DŽw|EXGV Wж\+?ɷWtaggy83h$iU1?Ue9Ʊ7m0 q$JǍPaNACcZ"U q獾pٖXj|O5uZGF [4S IǗ;݂T򭲺oQjd },)tju}Q+x~C U7X%vfr@J5~V$)P' B64[aDw ͨ;he9i+,>' i)YfyD՘@'//IN{>_pD-QgzUc\D UBɪ{ >14 QB ^48QC; I"[fFO` e~oz][f̴@QdWW4Z?gڥ+Cåo<c|=cf`X߭'G6FXצ-'o?Ȝ?lg0$:’d롩#>"+Os Tm͍ÍӟtW8hX;Z74MLJ 6m%eDzSѢ s ǎ73L,=p"Snf t^rKf R}zqԜWh7kPYQsq8X\1-*ԜB@\$f:N p~g1HMBJ6Q3#[ވQX1}/A<{p ~$K͉=hPGT+Qnay1C*QuIMP ͢o>jfيk.͟nŬ`x5A|~m!i+~to߯!\.c |TU4c/n=Šsh'MŠYO,}<чZQI&4pde{wkgʙ./8ϲx1~ Vp =@khVԪIݽ^hChq=Z+!Հ/9ÉQk瑱2=Gxjo&5@~DX*}u`1?}a)0$XжRg\Rp[7O7k^}S,D S:%8 %I@7JZv; og ~%2aA$*|cPŁlo-= S?M+p6ˏk:ܖ*fЃ,p_ 1Ct_FSEڗcܤ ;2kE$&:];oK"/q4ƯW2uzf3{^ϘL~+a0pb# R[ C00ZƔۢxK&S1`ք[( ф5Yޣaq|CeJR!l 8E8&1I{]p2A@-|ݼ6K9uaP xb*E9^$YRNE\;i{x)ܵ\޹V3;:,FZ 2/5Fλ zc-)Yܶ@= Md+hU)neI4$]k<{:OBFܥS2.$jJ6_yg n0 t_[&lAHiqNA oeH`+{<'j !b|^w xbbU"U}foxR<3kb(D_iAqHĿf͞fmZC, 0x 2F0mZntsWsF) ug--ߒ"3 $]ENx ԯ~Xe*bMfڟU#~BC}ieW<\8j0A=LsHٯ6M4!._S+pӶ]C۷35*1.C kNM%}^p(x{a.x癚)c(y}M-cp|΢Y*c;5es)ri dJ֓\b9{5ל9pmY GO|LS%Tv*dР&i*7V@x{KF@3xȃmE2B6'BفbtjU(H@ǓIŔ|)+p=-j\J-fZ ^G5Eɛu߷ #F$5eUlB(!sNPHt U}MGNsI?.tf屭=v@]yCcv9Pf=)YѪpYk)7=JH?鎋~?2_:HqrJW/1ATfvߎ_䠡}ć,TPkC k|Ae+%{ ?ڈ7 G6m Ut8B d?h%wAϓ1+ro+{sZ@ XmԌ^Nߣv#!eJL5 w'#h_aܷmZ'):7K]j| ꙑS!]'i DSFzrZzh9ziV,yn%mZős=*d8\D̶eVI kD0Eq{Kq~';X>h~} Bb6^X#W36\zr+)9LGl4kF"hZFU=]X\3Q!Nti&#;(@5c-\c˲Dp&3E}'{ *}Tw2uVк#쀩<,duʣ@ / G OLmuT -?x Vjې AAĹR_\vk+/OIql< Gu矫9nW6VLtO+*Sםbf{(V{Aَi~1?hOr*=,E.nfZ.6 v~,XֺW|L)YgV ᜴{ɤ\epHs17/YŇQ)4Z4(<0]]Sk\I-2_7VU 3pOu3:Xx0m0Hu)Yj78@( VGsd1]'?B\Yj7 b̲Iǃr &O^c2f#'l~LO*xCP1dX-\ω,˛pwO`bjsp I~c%ͺyxS(lfMk5r,hZƶ,$םd”.}d_+0X6eX)_Ԁ"gEJ ^OrIv9-6qJge8bJ텽ρoaR1vMŵ߾gͿ4Lkɼw!qtm8é`ڹO'Fkjȿ9-&f o3ks.sB4</t? DNbYmzpV|7ayj&_ 2`p@`~/u̅K =.ztouʮ+Ʊ~DƪynsORuv]HKzN6BbyeQ)MB$ z#Mjr~0u烥LXcn)Ru| WU qHT=wh4)n'7wpyX] 䞙tT=:&E!lN_D9cբ> *Ԏ%} k)) zڶЭ l͢rQ| ;KM9E᭾OA6my-E9а&4NI2j[1:Lv[{9n /htf#˙ʹ%,3]oJ߿=)zA Jb`:aHPv$q?;,ko;~u ѻozĺj FYHTH^d' ğ+`3p/{l'LɳrtoZCSJΟ! ?ޑnO&S;k)W#F y~Kn!1O- ?K:Rw̟M4e a,H:>ɺVd/c1a*cL*-%ԭ'ljJF)E7.ViRyº{OňdRQ;x㵫T!k"4: OyǘL31#nY7e^5 cvd[-d*Q(4 |榿/G6=讁mčzػt c;A g91ģ6:ƫ-Zz6"mh|WXXif6XIJCZHs_H2 [!z^ e+a8ٔn@Gʔ&1 eσ&̾Gv/XnJD Pm"$Ц Gr< Z:6>Bu#YV ds~P:!'dKDQ)H &C+v$5[YS*#Ja $R&aU:5XMth#3T)˨BC MCOl ڡ PY=,VMxZ ;F7x{ɥ&Ҧ 8^2}ܓZ!0_w+.nxZ ;<S;j6"-wQrE6PШPk)7$(; tQ#?PjL;t+p2E[;1?1HXئ 1]Xl ZSǧ8:tX1&Wp%0Y&'o)ܗqƢ=:0{2M/|DSVy [UԸ&K4F̱D AbK Ho̠K ʴyi;s?'YLuF_Rko(2]ɢp~Tq ~fY*Q!R٭Q\}-ÇvjhL! @.]#Xf3d,X<Ί=7O><xdUoǵ+|OXgVwmH2{w;MZ[!Q抳Ul#|[؜[AèFߙe,41e&bq_ڝ8ky3Y\j+%YR7 ywk7+u#*L6pq+9.KЊ))Jˍ[i/* J}XtP~yeBΤƅ ,ڸNo+szm{Sf܂Z 'T(j$l 75o26c{=&K x~=bd|UA``-zwk1ˤ8 JWSgɻzRJUԠW% OU=MdCH . +$ *aygnKFʉ\CM))BTF t|=Wq9(fmQ{ }D1wp( (.sb8+L2}` kFʩcl (5_cO joL(u3&Ѭ M felTxpA";px7W>f`ӍPβ , G*c*4ꖲK|\>#L=N:(Xi3T PVY^>2VIXzXNZ&XSgf?fy4=L518QWjTN Z\Lq͓UpvUtc9T g׫*lN)\nx\#{puGFpUA; g%7 b2`;*t`Yq{TTJ-U ,_#S[^#'CͮD G}C6e z:x.b`$"H@, n^7NpYx'*3BvMX%/A+{Ol_1%ɗG) (IA_R)R^,ؔ>@ɄmO I_{e|qXYfУQjzl g>ck>ƻӁ8kW7(}WOynfyUn$/瀗b Jbt!xXWt\!XI]X) >ģ-MbE[:+/p :6ʥ^1# sϯje՟u5 P(:2a싚iH`};uZRH1.1<:G59zlvDzΥ*Mu[ٵF׏sګO!c{Bf\b މxH Ow,+/JLadmkNƵS BW5g ~0e$ '?W^$*ҵaҨYC3J),ۓ1RᛷG IV`XC^AV[]9[:@ ͹%{P0N{]ӫ8<3拪 rP{i6D`i.J`0& =ib:ˁQ-N]W`j˩{R"o=~BF!k^8ZegNJSg9&?XߎGx?rBWAeQf P mU^_% ep[e ~yN7ґS7ș+ʘiaW^<[;`(yE U0́ W\|Ĭu# [%ڝ9>ӱYvl6o9ԍI #[:%|zuhs~` 7Ѿps=a4$OfU;mecpġYו87+,7R0X51u=12T׭@5]R mm8xp,T"ݛj+A)M\3.FJ!K|TC`1͒Isٛ*o1@:forȣ_Hv.6yܠ|RjjĘ|ڨ=mx$ZqU5]$"P;ї2zXF|Nu#o@1^uThDM0Dj+ވc#<~Y;-JըјbQaѪBdD=5ۧliAYFSh, [\ GzAL;{0zDcw`;9~>]Sj3s!S-,S>AK+,??&j]b:5?ɜޓ~0|I׮fŏhv(DR-rmP}Oy=V'I8yYDP͸%}A4LBBٟ= G2cWȃ=u|P}1RL/1)W;Xy+d顾:7_2UWp[<g.4v ~|[Q|~͠Ɯ7C禈v&ÑWu'Sujn l}YCC7 xrb6o2J @SL]g^c\ź+O,'󘍦kR9yTq^3 =f^=a=Z ^/(M*Ӱ?{r{D$5G0Btg)ԌP%Sc O%4Pk"w0ʨjƪ=ř܊k]oZ$&{^c\./enPZu5jW ~z@'*-m3Wھvd#*~+5>?L/rGG_6wvh;kkZ[e8Ĵg>@7HDZx2| b|o%b;oN^uGxX07 >?#i.򈊞4 Y $!GQ*Kjfp:=ay wCl^z+S9?P\y! }"GdjIjb2";ϡQЅ &=릪 wHpw su~XGⱀHؖ\_FE%.[ډY v?Cpi؂&K{wAhKX͛r< O֞eg=U'aNЊZ./6@'rtƚe3=BISk5s#g|e@e֙wz۩Z矞ֹӝ9v#-}2$t;R"c )HAbדg#nĤ\5,Yj1vdqBAVf!Ou 5(Z>1t6d.`{vq$ňZ'@b|4(5mjB@1qxCT\yRfj=9Ɣ٠*wD""-IR6t{Ѕb#2=- *39}IH?xG}ё]ؖ˰O&j{3x@%(У6-L Po5_NĿꃐo)J[YIPmMZd^XneMKxI(g +Bx6ZI람?n;Y\8Ġl89 WvSY&R+uڞE2B r*ynG 3"ELיښedi)޹9jTh\:b9y>¬kͦ*?)6r\\զvFf 6Z(z:' ٘xe7ՈYI Q!pib_k+C5CtŠÄ=~8YUb)2TND@c43RdqdZ8d!]\@ zbhtRFݟ:9_1mc&H[s_%=Ȯu#|[M-7U;rw_%dΨm=L!ԥt1:8aL>ڏ~=}i]J_W&r:gZAݒ(hY񦁖uHdmC{ʰ^[P< ^\:0kx>enC]H8 SQCqol밓j#3[M`|D=B'L `&dDa]+.H;x0-Z)sFa}Yrs.N,,QCeZZ._F\^4Y!;XK.^d{tڦE=WF[f.5kj'^gՉ!Ч~?!K~wvd-!=؁ANq*o8eītA'W ьחƒå KTLz)qeO}6&ɯ亢pꍃB82~+=@ 0EiJU(_3')/2H6qMNr!0_K\ܵ{3 tJt/\37VuP 3yzkrEsikflCw,!T!ԕKtX9&k .ra𜕈C#nl፨"NSf.I%tfhm^Ф.o) 2ʹ #̄/NwCYzO\v8щRI^`A=Ȳmhr:;NZYRI 9R㳞5uw"J! IŦǾܻ^ڨ&ż->$K"\2INDiNT"r1dz y{p˘lfy푩q)L=%ܜSwѨK=裩UE=b0g͟*ICYv BBWs(!T!{z9ej8>S8e$a@}UPNrzP])+Dr1kM/{%A5w%3* ,s:s AVءO FI[9VR6TcGƐ+304U>q,=:Z?bukց x8 |/;ߞ҆Єk[꒲Cg +Qm+*t_ɡgvP/æ$+\mԃ{(rXYFR. '!0vΙ8fxy6ng:`ӫ1 $H×/j3 iw<6$۠.X> c,]uk#|7޶y|҅Wc"bNYwAQgqUT3gswUٿP. BlّlK*&aO?QoaDB:wt|br(s*URʹsl<O&")XդNYXFs8v-\Bo ~8ڼ?L[VezvU49ͲDŀp&n5*Y-q_pt}"GWa4}I\cAHѧ ۟SuX/b\T[ϸ!M {c.}otLMMz`b4pnyOsTP~TZ!}BpP=[PB#Wt#2=J/hQfHah@ag.QH層i9'm[&AGj.DҪgӠUoѽ¨y?9Z pgB*$I^0,9յz_1 ƢoO;"lo'jUhU^5+l5aiư\M111gF "t*)I~u 0f=bP.?TuU)9 ='\v@MVI ぉ"(Xch{( ߴXb3=RTt)e Ǚ !79~zhj#lѲ@!AkL(iYa Af7%F=yti73 cAGGQ##GQB<, 2i˓s.Ehh^5uN=gK~ԥQwbԼ'ߐܓ\LA+9>"֓'q+wCě3 ?S'5>#vB=!t ,^}C_0eGZ^P巤-/io9+T^2࠮gM,.3aCѳU ǯbB|gc҄8v;`{oJyV![sz&3K*Th*`UmEbit=+}F՚˘avXC"}t.^ht*Jx#d0Ք3ZDv.$BxMuw yU'#Cn<[u@nIA/ƺ5~AXXjsÔJwy?FSpo7:wS$(K%HiŕD[ > .`f21Htu@{T`Ҟg0W|?yGϸ@CRrM#J*ZP0ܮ\]VAD l \\!נA}oy^\d48wbsɓ Z)Ny+6)U? Rx-cxkD%PV7kOBAB7cӛ3iqNXwcVoXS FPA:QH  \WML@85*@qILv&yc1[qNb؏(5)D)H\y`o.͑1fd0bF:k*$b2r)0Bnc| ~Pز9Xd* 4ւ}·I-۞J<0ZГ?V4a' DNhzŭCh3Fm$`Baي |k0w[c-n]=O٨Mn*;X#&xYR} t3Vo!ep3Ss B.;#6Xso3nWe`Vs@,C[+ Np1%]ODu ^Eнl1 (pT!Qr)b=?X7w7~]F-?_=B+KȅQmN=E_sb5 |4E쿭x>HR ԻL}WNJs;gBN8x0֖BۇʮR"yt/Wa]Sf]1_iˀ㼖 jv U(Br D /3:BOSV!\w=_q@6©/~=7ODb§ ,Rٿt_ H}~ZzRP56tT܌x Et M罆8)-ubFI7 aU8swHvדF\O%g4WI%=wWtLQ/^wZc'O7].}​*uNW m"JXȌΦ<\fT\l;49-sL-rɝ̓2];Cݫ/oBg<[G֗俯 -5Ak:]u)f]uD>H2Q)u?񸙴h 2K:vX>.J@|I~S}}ա}N]/%`hJ˜E)jB7uB`v F\1ںQt,1ŦM8& JQ2۪;FZw:wR=1 .~nG6$5@I%jL;׉cxc,|hS%HF7[\Z8!Ll*+Ujl,eO-~_hS?aNhK0Ig؁gS^_qQ"{?O=VB#Al-7hi\x?Pթ!A(D1>₷DȼR"v[[jaU>ט50Ph+ռo5t FfIۤ!z:u\4y) a1D |6*ҲO5 =>c*JMnH|7:,GqʖS Yְ"UWئe<L}/Eī7`LE9'2Bȏ۞v'gjzx]*N3M4w?QbV;)dB(_j"*K0 Q6qZ z*u0 3NTvE{ǽkʈxy| ӓJ=pjr}8eɆFnfb3YD9"{ Zha$ S9.&p%ewu7(ֺ@G0ǃiOEH(n[ ҮlG8T_ϲDa? U? 𖿭Ka&+|~$]VkHEm|2%6XIC:]UozYS-Me'rtzZς%? 7h[n_DObG[z^l1Su]kJ o" jC\pZ|Y No&d,2w+rz BrW/L5L٢b*8]9M=FZz:MS&+ss§@;݃=^rMhhz\'5#,ZNϸ|3Ril12֩# DX^Ǥv%"̔\N_Xڨm`K,f_h,0tgRe$uw1vp%8˨Sa9<*]̦yD!96B5dGc\ IdGJ3Sw53b 'd#NT/x4Dݺhٝ҄c8-hp?:qה'{J +gw[m򀷎Ff3d4{Nbݖcp[g`O%ݶ7<>Zޟ@2ʞ@U3o5S gF5 aПKM[5^R1[j;5|-?`lD~Q_p>s__g88kGE%,I[vTLw׷f?Uถnɤ!9ug=dbds_jS\޳-ẻÂ' /$j'2CK ӵߣ}R nĢ RFItuR, 8k- hVA~//V2 7]hT+k &Y*b{6y1uVBA X"Wz]{uKe{LHwC^g"oKcm"<lՅ𭢱.m8&SWFO_cl4v"c:=1QcLHwj {dBw6S.M2Z(f+szaÍ^!^BEx#" +gfksh-(END`NA @ W_@B۴c@a0$;=Ŭt~@lT |rs& 8Xqo,l?>k+-ȑgڝv~ с)تF<~m_3 ~yw{9aE8J%}Z@N~o6H}\T} [l"GȇT &<^625=PTi2phqr5Vnϳ:Ɯχ!PEb=Q.7u[WRYJy#mLa!'s ~>(H ߻ސbŽ9{QFXOqgMdmX#CvmRm:_RU@/Nw<:^zpf| ۼ<վZ;K"шm:d#3ţ,FŹJwSQO98WSP[5YVH:')fG9F@*[xX\r|<2/@ckvԚh]DB;lE zd7,5lNIJwo؀;hAx=+CZ:8 zCrktZ-Cё }0W#_|:T?xDdp~Q7z?7] %&x|Hk}vO(v:]aIr /&L`"oDk5whFQ[.&"JiգB?UÀlddYΧQ6L:^8#jzNgѺB@Z$eL#?|udʾ6u;o沕dN0M,m5D _{pά9ÞӍvuU=u)R) ١+/-pp FẌAl J.S34*ԋ<չ6?[B2 " DFiSq4ZpETS˒@J N.gYJ=6o7zV>aͫڭg Ry; N.śȚpkesťgU5x=TULr'~@0=t6edUmJ\#Z \YKc0,qZ} v!?wk\чR"#8VVU?mrX%[N OI0i21$Z `nLW\Ӄ_a@Kjvǵ oL  YZ