sssd-ad-2.9.3-2.el8 >  H   (,e[U U]M__bw^~ԓպ֯, nݞhs`h)l?q-0K wr$A}+G<Ӿ։0³ɇqo锗p)zsw]i K?$M6F&7#”Yvx-$4jطP>JZخ2jT2%gؑǻSn{FiOTITܘl-R X ֗Gn 9#Mģ` $zW YOsmu.{bywoLppxS்4_yit⨾jsG4x7krB P6enl/Ƕؚv[Qџ^KcaXZF0(ZB=+X{yn{S_;W#Pij|AAdbRޥ`ۢHB ?dΝ5*SF7]T㣹p Wq!2,ѕcWe`?b334398186db6ffea314d4aefe30d15140fbe44eb9eff3bc969a99b657278a6e991333aaa8f194872d24145eefc979a655a9b0af0302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb500663064023034335a1cb241f6e2c9cb41e843a0bd6f0abf6b479117abe28962615cc777215944e97a214b5e8dcbee6ad5025e39744f02302a49ddb427fae34996a861155a26e87e5f4a8b9e60b3f1807bd2e11622efffa109debc616d92ff012d765db155a401e50302047c435bb500673065023023cc6934c5bb99a195962d6aaccca567ce5b21cf2b7c3402eec820a587a60cb2090a1a0beeed5af9fa198e21b4e4cc3d023100af2fcb3f5cb0b628e2063639826b3fe0a3fd247db1e51c6ad80c139da15a2ccfa500d229d145cc42e752777dcdf440840302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb5006730650230304efb3685479d3c0b9b3c5b56585fd00205df6c94a7c721eea1678011d4622074fdfbd1ef290d4192fbf1db6f02b5d9023100f5720c01bb887b750482e05a432405ea3dcfd32bc0e4bd029d7781fb313400331af2092c7a3a6581edbba195bf0358d70302047c435bb5006730650231009ca3573ee5611a1970fa63b1fe080b4107da97bd537394a2b2baf1d375892335f9366251fec95e1fdab040469c1c406d0230239eedf4855df9107ec73e455bf51f92b83d2e49a63edf1fb084c906d473e355647aa66cdf589baac2b4f6eed3afb6aa0302047c435bb50066306402305569f18f3c3d782c9fc3a7ac950c6dd5a47f6996fdcfed5371e93d1c0bfbe330e0ad07b8f8efa52f4bb34f623bdf6289023079dec9e68c313cadb8914bc4079a7be289025fa82e44c18fb947a30f23ac9a20c4e80de22156bae897dcf22dd63fbbc10302047c435bb500683066023100d9fc17ceff2fdc6c0dd589f18451414a90174b862df8303ff138f3c0e74ae339ec19219503462aed5a3e933abefb0f6e023100dcd33082c248e217f3b6340f57c97debd718dbe68c802b42dc1bb337935fc673459d02c155950af9f193fcbbe70c14040302047c435bb50067306502302cb42530d24d532208c4bb027cd65e182cfb63700881528e115554eb5470ec6ef93953a884f4a31a39764f5f476b204f02310085deb82d13ab472f4a0a1d168b05edda0405cb544f200969485cb83dab01dc111fc0e606bbdd918359a565932a25f21ePe[U U]e9ZRV>ҝ6&=S] 6&%߼܏:_o{ﱔH=7t ,3p"bˆ)mN7;]y.$<һLjbT̳DE];Dwٔm!Hndj;woS9,R#Lx: ^GHڙ{w@LŤ+C'}.{k)⨽$,5Jbenɾ"e2M9V1DzoTKc W&a0w_"͆PHDa9ƈPݡZ iXS|(le[C8.Eȝ(lᕮ2"C!&jγ4 ?l*)eDѣ~hK=LWTW;Ͻ5=Gڇl| `[Dy;f!ٻe~|ڏrI_l$⸢_cNaNr]οIQG0}6l-9>`EX?Hd   2 (EKT            L   LFdF FLPU(d8l94:hBGD Hx I XY\ ] ^ bd$e)f,l.tH u| vw x< ypRDCsssd-ad2.9.32.el8The AD back end of the SSSDProvides the Active Directory back end that the SSSD can utilize to fetch identity data from and authenticate against an Active Directory server.eRfx86-04.stream.rdu2.redhat.com1CentOSCentOSGPLv3+builder@centos.orgApplications/Systemhttps://github.com/SSSD/sssdlinuxx86_64&'K:N>pQAAAA큤eRfeRfeRfeRfeRfeRfeRfeRfeReRfeRfeRfeRf31488ef3f390f4ff53e169c932bad240c7b29796d346ad06d45b3f3de289a5cdf0bf402f2bea0fa241e060a95a28c63fc561a62a3868dbd0d48ee693d09429288ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9037eef77c218983c7b64bcc10bbc2df7b3b12a4e0fb15a4b2e8a84f619f5dbde56381ec374195a7c5c73e73ed11a87e9b124bc25c83dbfe4cbba4a1ab04b19e8b59b9d753fdd483bda04debe7eefe677774062e62a8c87cf07eb432a422788dfff27263dd1f408457c1c7f5278c49756aa90bb0fcf4d930e9ccc956a94a0e68be5../../../../usr/libexec/sssd/gpo_child../../../../usr/lib64/sssd/libsss_ad.sorootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.3-2.el8.src.rpmlibsss_ad.so()(64bit)sssd-adsssd-ad(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @ libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.28)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libini_config.so.5()(64bit)libini_config.so.5(INI_CONFIG_1.1.0)(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libndr-krb5pac.so.0()(64bit)libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)libndr-nbt.so.0()(64bit)libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)libndr-standard.so.0()(64bit)libndr.so.3()(64bit)libndr.so.3(NDR_0.0.1)(64bit)libndr.so.3(NDR_0.0.6)(64bit)libndr.so.3(NDR_1.0.0)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libsamba-util.so.0()(64bit)libsasl2.so.3()(64bit)libselinux.so.1()(64bit)libsmbclient.so.0()(64bit)libsmbclient.so.0(SMBCLIENT_0.1.0)(64bit)libsss_cert.so()(64bit)libsss_certmaplibsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)samba-client-libssssd-commonsssd-common-pacsssd-krb5-common2.9.3-2.el82.9.3-2.el83.0.4-14.6.0-14.0-15.2-14.18.6-1.el82.9.3-2.el82.9.3-2.el82.9.3-2.el8sssd1.10.0-8.beta24.14.3eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) rusvuk2.9.3-2.el82.9.3-2.el8 .build-id27b0676d8bf546ae1126f0ed09689abb9543609be997b8fcb1833e9e0f3b05499618a0ffbb6b2643libsss_ad.sogpo_childsssd-adCOPYINGsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gzsssd-ad.5.gz/usr/lib//usr/lib/.build-id//usr/lib/.build-id/27//usr/lib/.build-id/e9//usr/lib64/sssd//usr/libexec/sssd//usr/share/licenses//usr/share/licenses/sssd-ad//usr/share/man/man5//usr/share/man/ru/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2x86_64-redhat-linux-gnudirectoryELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=e997b8fcb1833e9e0f3b05499618a0ffbb6b2643, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, BuildID[sha1]=27b0676d8bf546ae1126f0ed09689abb9543609b, strippedASCII texttroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)99PRRR;RRRRR RR8RRRRRR2R&RRRRR%R4RRR,R3RRRR R5R$R!RR R'R9Rz͚{1\|>T=zteF!a~#C03I z<}BߩQU,s'-i$SzftHe@svdmzJ @?uf.] ydhk7go,b) R7  +RdJ+Z@i'zp`P3@2۶5>9M@|V6 `Em99u=]Y &6~Qt?[^$~&Y[؎ ~#/4'˽zx2k3UEn[=BB]itax@Zt!uvX2hCK~=)7(n o&^?kO^AuKe>gV#WE#1H9ū-ݽ૽n T;5H*Kda`3g8磿Rߢi{oXZ2)=|F{ڹ;=F_8.紓4qHuD㬂m[pga|;eו~q=JkȡZK~ٍb޸OUoE4*d7ÖV.b1Pv?TTKTĺC|;mUQs!Ĩ<+TSakۡ;EU3+jiUt'~gYU&>2SR$Daw1e!ZIwßM~?ZcX2c7>kO 3!(<Ɉ}a5&+eBcDNp~k"/H,l'd-wL(H2j}+ٕ8XsDA9} 3|x͵W0@`yX%'ot"W';G, " zꊁ2]{V[:,`n}^CK'hN:SFtir+7%}3Rޝ$$r$/Uz GПԆ:g>_(NF ӟfiG{ua=jnA6U>}e ܙ\(]paiDl n':慴hW&JkěRE2_fDzguf (4c Xsz>y(:Jq~@=p\qd70R:@vPD ?66ګN MKP:X02ph@V GAmy|_aĒ>uTu26d;]D3U<Ңba /banv$+jr6\38QسE{>ZJ謘ݤ⏙} wxa]"fpұH*R?s]_\\~)%S)jY\w235dWN;aq,OM^Jm; 폌~Ý5Rr:)hgG~W˭2>"WlOeh2// C%knR#iLc?A^Q/:.W]a cZdEv ?8}!OhHep<ÉCNe64? ]򳛻6~b!XG(%Ƀ`S|l@: @G,VϏ)=N+!w<r*ndt9{s0-o|b65n+Jtux,NwZɍJ(16ߗauCύAwEskS6G$˹!Ff6yyy};mȦq !Mj0:#Z(@MY;o{2%&`@Y lo^6U4k7dX@]$bؿ(hhxClFZ販?5r/ RGp4ϬIyH)d'|L+k}a}&"zkgi78y-=BWbgu`,e!IށL=~@eDt͵I̋KW `nfؾX`㥙P_{ |RUzE˜',M914#:|ye2vTRx^c=Uf[ hz3_Tӵ{ZH]e]RJj Du,:Cq_ц%ʿ( cXh@ȇ?`k5(ۂSn{o 7IWV>M e#,T`t^2FliU0D0;yǺ6JՇncȎR}>{fj¶ Q@_('P^ i E #}2K,w?+ PBt#ErO (gx,I֐`^uYS+d 82MqQy gO[ =zTRjvx]@W{ m`h訜zcWXZQPtȑӨUzs'=De:ey+v6A4dt#+4<c*YXpR~м2>wύh *Jd=WsiȚF 4'x!n9յB+=-$g;ڨZ, #K8iWW6m1:Tcq9år*iY ݆B< rgDfb~Bf%]u piZԬZwTFUR;/O{guė6r>A*^5f~}ɳfDa-bnFKW²L.e4cY_?V"`{bw0JNuxŒn3µf`60Z b)LSS%~[0J v3 rJdrDr6$ȋ@)gQWQV¥}NV Ң4_bXu)>;A-MY'<bijAe-6RD`b?DchZ% i:L3I s!&lI 5t;!M1{nD#Z"`#m *$s:GȽImm~T*"8SQ91i*qMe;Mj+EDj4< r86zV6~A'nW#rΝѲ 3s؂OOqMߎe JƠ  r>P~}G{΄) "GK }ۻcg|;FR 4Dg?mCbZѽ5_z#{DMhΓ<&76ANo.ٍ.0yܞX# zcNC G̟ZPBV)겭(cg5MoR}! 54H#G9?+|2i(8K8, Ai:iqF;ъl" M@X3ӝvk3s*8~odKc@r& lUi<?~抔0-2UM;rH!!*̊#CC [Dvõޔ(rGӀBӫoう!p1 Ͳ:HBU]ԘҨ^kbl/# ̵͚%Pa?Om%{D.;{kno/ukHٞ[(i& >zz/m'%=2CEG#@7x+ڑwn1ީSc"[F^!'=Vbqe'_$^:ʘFWw~=JBQoy1c g_:ԛrnZ2a @$;:' !`LW,gI+/˽\-Zj6tGJ lPJO p[y?} a)! 2;&DvI S)*g(qxkO _PC(${=9dş#p\LXg `" ½1 #k#w vm8d$-kQ]CN x-rʇL;{`ϡhb "vZon |VF+={{ эT)AT!]L|W{1>D$'F}Pg0O]sΫD|GNpMSpVjvh.jay7"EleE5e&)f\Gt-K3_O\ۼ{O4MCRëF xz: +t+w73w}mr}Zc]Җb֎kữ{10_?E:c12̣;gP^=(ֶT38 s!tn<k2 "0MAm OY~ٹ82 LFpI`A9?=Wߟ٧&XZFQh4οk<[޲xEXd"<}4\dҢײHuO=*Pn~d1A;Tp >M2)0>:`>3;XPRzW,US j3c}J?N?3Do{89lANL99HBi@B+_0?F6̬ƹowhJ/imTHG׺Ma`D%R!mqo6'T̉l̶& 'gZs${4 J-e$[$QNզFK~UBQ;͈ "&v!W2[47IR8KJ,0mD*VqD-[h*7GV]xl9D)^*Sj{dqV=+@g,xq>fb.T}o^Wܦn,.}[+;[Dr!WQ;)vd8gvXk9yҞi8D!m;#'mGf4CopȘ{-W24ѹJ#F ~8ҙ'B3lA]/i.fHX -(̍-<{ )Wkd㒷(١F5wfF΋atV5em@"LW?miR-"ߛd f^qG>_x[@]TT츊/sP4Qe3T&f&Ÿ98t"t&y' )UjG^ޅ+&3H"PD-fj Z'lh~ 2qfFiL89p?@* ?&w1@Cn˛hE-kܑB%mDqLq|v֪6nF  =g z&@ٿVw{^o׊Y/瑦M 1]G&%[?$ti.'̸'}Xp.?*]OK1ߩ~;`+;+tF*Ȑ6ql }v{ݤ@?y\>f5xROmSM[r4Zv !;4׼`U=cK?0?Iaq wvqQQ9Ԫ@'f%%U)qÔBL-)&f} ;oL| ѓա.Ph w -H۩k)~H0D% 3[.wZ +_Oʐ2[έ/6dfm֋֗V/G/D@Jz3 MC#[SoCv,fTs>"j8W>֭׻o/ccn Ij=!mwyY3L YV)=D뜛'[_磲oڕd] G;{yh󝬽̏39eH!r?6SCK} O8 }=ǩ{,o[N+&g‘h Й\(KtEW6pY쪭t%7њ3;faCk:]v \4=`zΪbQ.+1]J/޻=bx"]i+@l˺јC><6|(R_'ݩ{DC^nl#V|v ȴaw7佰ˡhuHeޣ+6d{07O} ۆz}+sD<4` Se Mþ.˵3{6#n_hM`b1[o{ f[M"]jR b姗t㙽rP|9/-dm& c5w1j|.9 b&Tic vl"Af<sAi-@H3mI72@z!T"}N;V}H~CH(j}) P3lO>Ygj!OI!膬+ ,j3:)ԊYuWP9BcZILOLSu!6@0|& 5%4m-# YZL%T/@U'jƪLK[,&Q%0jߙ x(ODʳ'nt^ QbKߋAG`#!9IU-SF;2Ơ! §lr8e[$b"غv}\CȽfG{ %RRe£i njЛps?tIjGj&Zv5 MvO3evx8;m(HXތՋLWeO3[}] GP,-ﲃ`Ȧ-JmUeH=8l6|~t"AwKd` . 뿢1ɴoD^rLͫ8~ ZiYt,*uk_FJڈʭ6o= Q@CqP!f t \hS7--GmNts}.syN-mqz;'~9:ӦsA)ZQxvtûE($?fa.R WRjpPgY[0rd7qx -ӫքp OH>ԂCɲP"NeR>%ӷu/!/ZoIc0xL-l y,e ׯK(K#Fwl4@& +xifϥF!Ja:+'+D`(/,37ÏQXwB l4k'B?}7Q'qףi8%Ѕ%0XK"S5qUzEUt|u"E{N$OfEi^XFY[ULO1CSf؁^xFl.cgIU-Q&rqu οt:eQ),u7bn2&$&(,C>:K ;g7`9|,}ڹ_zE}%ܥ+ A6dEu,ߩ`[fN,_ȿ^o`wO`(]kTIL%g0-; zC2嗭 `CQr~.i#j8_ht?,=B0!{=!r\pF7"RXe2?5A&hמ9[^F|R9i~h{Ր*.]2 Rw`>xy!Қ~f„Q&/`vJ`_qxs5nX%pNRr͎nX9j϶t)Шon x6]9z?<+1])C:J;en-"NSl|V= ,p)$Z!z9/rDY;mܚK(f4pǎ3,z놚y 4~& /']h85q)E,0lMH;WmcC>r:zI d:Mm<ԩa3{uo >/(jx2.w!M*HT,ؓCGy: :8ߋI]A%W:c!WlUW&r5-Cǿza.n!2uNa9H4זR/fNCn$Y.%=APU:Q y7I!$o1ˡ)KxW5@[4ON4F?p]=1;I 3.YDJUg!^LTTER*!d {ig.z/+65)枿P)HAE؊6lu=;8 ;tagV-%Ը &|Apd}ʮIYu.Km&Jɵ=%g†P a3u<.F$!--$V5KR8f{ʭfF>+&x#N #%'\ hؒHl Ԝ*S?P?]bYv1`d8Kg3xtq;0B%Z^S8 cv*}Au<2J~p'>9hG =JbB'H ;_1 [mBEW.x V΋y,3@Rܡz5TNe1!O9r<C2<9;zt(cDayںy2Ѣ'0ґ?4PM,3kp6V"I>:O.ʃ1 rjQ*szRNٺU-v=~m4X; }tF.J sѽ[V3Ag"wp:!Of1iX:"EݨH# ܺ+DJf #ŦE_ |5j`6>Y}^Tfl!٥C0Xsz"1r2̭&`Zy-_5: ˥pGWӋRрOAzY.{6 U;,(I\_{:O?Ҝc-^γĽoK-G =G]Jա|iB?R *+(xh1AgkʖD.@i!נI$ B.~uCk mC`nYju2:Ws!KRi&B@H2~ 6Ld!?2gNAjYmM@I#Ju~t&0!Z2gשۼ >]:C>#nEI^B8|Cxഖ2O3<ЉBTe@/\ *4x$%?hB7m'!tT+k-ÛQ:^Oek1^,YU6> w} ޲{0̙kT +rvy:F֬c\'=с:zB |:gygdr4)QIh|qPRMgu,_>wbZ8e2NdT2{HՐGdW(s1 n(H^z,vpWa|af[3x,ThW녴zp4,J/o+ qz$KX{eҮ5 ]}uFB33$5$^ 75rȤHTo^BoKȉ $apU0XB]<վEy"̿v3wZ;"ⵠ2c:,T?*4VCo%gݯE&I0&\ɹ3clEuu֭|X%%4&?yl4&tDz[ F--,YV,08"X?[x?bܸjouY/]G9tt]A+IG r^0=\b~ta|o+R@g Z b|\&d<+=b nUۧ_JYCh9.GP<>] n^D'YIG]nxwi Mt% `Y@ta{m_a UwE>P`%r2v :ۼdo|dێ :=384MܪzY<}^2Q&:'ckga&dOެÔ"~G 5O^j@%SVbY6Uk~;N/乄g(jy:i\'m\\7 HRطEάcg2L4W3=݂fkf:"aкAuKsF` Ln]/'Bmpws["dsm]$Kd&t}{F`d#ww"J_:u5!q~*m aJ6di.9KGuΞT^[@e4Bi;GT:, 3+%Ԝ^p y>%wsQ0HB@,[݀r=Z:V1y(4guIhL |!7 j̷ft+,gY4Vmh W}@ gI+<#M導ŠTis Ѵ}A.zNE'68@᳋ݽ'Q5qT1{vAl ߔإv̫_&b@>6r?OW@fSc4h:cutP[Fm@0BI춃"R }=>Ď%hbEu8Yg_(mENHXuvY]b`D>ާϘ&RCvW:Cr5biMwMVY`]|39 T>w;D79KQ|swA9mzv}R>D]˱>QEj:`nPh6`p(~j323тIQςb1~x*}hu{ -deR1gM)E;$ B^gdS)1u|aDNEn1^xr [(S0jW >\AT1L |!hĿ,(2pSc.ͱ$<:$^ ?hm7&ں~U҆שxJ ˕.V`iًwI&|#(*!hYlPѴ#á«}W `?^*/lLزxmYfya wj /? ݧQ¨-Z6)>E\eq]^—rn\m0Z3f?w(; y$LsDymUϕGAcClMo^FKuv}πdTG'Y0" P$3?S'==o$9C6I(=bo4JB.pAn3(yl$2Z-^.ȗ0ϳ=@g[!%ް[Jb[L}Oc>Д` -;D^96P}F4]lNmOcWiG#~y;Wt Kn<,^ [ tTC,7ɝwE=L_pilƦ5vt}+_/C[ "9 XNfL: qH7㠐pi8(&W s| }%Q.sGށXC@;6'*yek:`Z۞IkZ]ҵ境1": /lLw` $S[M/s4i򶉡_&.[ +o~oɌT2 mĕ;|`EϙgeZlp1w .`,c+j; XI *8:KP}D/; *Qю 1~c;^Hsp >Ϛ"]!Anyc09rgSQ2j_Dߺ_xuI=s7TaKI@9z{4+^$ޛj^~X7H8{AL= L@G#uO3|]nfY^&SQע6:πlxְS&b-cZG2)0)[91l1Јr3}ÏP?ۓX^`'rպ~rIp+~$`ysݛY%BZ~4Z R7{VXTR2w;w@RΏʇ -Go{wݸLafqcBT.2cLBRM)|2ރV_W Q^5`*3%˰9@s@YH}$tԽm]) <4d zo-aT> dרi[} ْz? 1aoJboYCv} 1A6Ni<*ܠ%]'OkiRcר  g,\gg)مi?>ܘ%:g4#jMV=JgڰWRk֎Yz,0( {(U=[4!_k&2i'.\ ʆ G%6]kjkFPW5ȂAp4͵v dn^$5I~qzIч,0 1 >QUژ-˱̬NTq-٨>>OoY^}FN=<>S 4? ks0FWkfMw0);,qOKߦI.jT.m=5G,xv✔p:̽_Zr8knEd k㘌0eTק7{0Rfmbލ_ !C6d]Wu,Mفrw]I?.-RR/p< sMrMqfO5YI\=IDg"x8z[yZ0]'!D}izb[蛞u*Ks{\f&T OFȾ7p[I='TzUjÖ86^%誆1<>HqLDkO |;KӪq>IN<.! @~u_ !6"Hyzς!&0}6^ ĀsT3Uoat&G$琻}`nXK~} 3A `Q=FMLT ~[5YbYL˗ܩsJ)VϬNÛ`j-CP]"8m)GEli8I@!H(e^bYZ/{ٍbI:XM(vڦ[d.`l `o@GޓzW[ QtnxC{;%[d\TL?IL"0 BKcv-դOr#!ZJ|DeU{[έ{*e*Bx]iho]o> 6"mI@/xNlN)H㟪ĻҐץQOM>w-&oV ?lb -6NB:q)ss K tun"T]=3G/]9z3KlE^G9j-O}CJ@̸P_ٷ:`t9 Dn^H.^?v=ގq{_ M_FΆkUV LNI %KpY,z,kIsKssq|Z@)XOb9P9bE@XЀS~r ImzY۷ZSh!;%ALXdsG|!&9HDu4DڜE *A'x$F*{ΞV(K}Pr[6;~}=?FS\`Цҹj{ED70ߏ  I{Wm?"( co9M'µ#wQLuHi7Vi'%T SFYc.Ic =ҢU4_}hEGA;/[; dU 4\{T|=B7X*-ly+9y+_x,6KG-UeկSM, wh /\Mղq-€; +݄J,dq\=4 >@W/nQP)sTol*)MOɒui+Vy@>5@zIHޔKzH?K.Q#i[b2%Eyv ]Qa_ :sj#gR!lt?UK" CZ.~ӎYŲlEhWzۅu0!"');:cF7n4h;J3T ['v4a6zӤ08V֖O7xxPBہ5ɬ*m3%8L\*גT,CurekVts~(΢MagaM ]ɽ\ދxKY*bϹ!PsauoC;yf-0(d 7I M5 _6g{`_ǐ58GB#[GhBDbElKTl."cX(4 Xմ}n_",Pn++[,ˑqaaL\pCnɀ/ ,A1uQj9^QF̘M_[֎q*7_,3N E=wxKbi!"&KZ?&f2e V 9 $Y|zҨeO_rդ~)r~3aXEM&2e`y4U5 A  R ^golhJ?rJș@s |,`YuGXj@< 5E&yvKڧds sVZRV\ue CAO赙#2C "d8uCT>B4,Oo36 ӷnzm wr|_+)6?;$Ou=/`Xo ٧ϣfPb76L],ߑΜșF6-l85̌~hGiMk cؕtD11ʙ "L! ȎcJ \S+;}\6Hvʱ+i6a*si١L0_!l3g\,cN)g8 Ơj,Aݜx.4jOI斘 K @ct8*="]U6H YgCIgm0=nŽ+v.\["maѿ-"Ԧ}XTë7ԑuz\OL952x h y!0J{E| C35w|IQf;ˎk,nQpt`_ͭOب ݱ BWbe"䝞䱔O.vW p#s@oc׺گ5c5w_~l9T{1 ;l+(&@*- tڙ2{u~ÍNu?[;\xdu2sĄe@cɼH -(\?8ѵ aK>l*&J2[!H" MeoO yvTϿ(#+_*yl(YQܼ\,^<\:[lJm> 磉kWJZYk$ǹ(U 3H3t}S,Ω` \FcDdd[FM"V$-_/Db=uu,P+r}2&b9HdSHHO^\R)p"bW2u`&Pb]^x:0R*7U~k!xӡ!TWQ),U%K~rVBrŲ3Fũp87^!\io kP(5Rg*4S? SY9nf;p0>AFz RaG­2j<7>g JM{2'J@ ~7ȏvVAyHؕ c8o6EU4\h@絰AY}\'4H$(^62evwnu >AYj G|AwB2"s&_oKyp G_/ 'GInwSTi*%$Z>O "0^jR!b7@@;G*-^!@C0s{ӓu޲ dc+A.jUm;- ˻#zyaYV/%v#URlN 4R]xj KPcKS:Kd("^FpsJ4Ƽe*hf'InzC`K=i:<VB hWbRnmP$SI2 t߈q]P3QhPlး 9EkkDyZ\#NyTGQDFi*ы!ȕ>+UJt\tx{sg KAtșޚƵDvѨ}_IҼ4 h>o%)v_4fy&r5W&\3Aټ3ߺ_^N8Кk_zԃ Zl=u ;Qc<|D;)(MvHbr kWC%vp@R1(=!W `Uh{Lԣx s,!N!֞>i:[n@=Mmj`8(?ƿ,@S-V+1[ނ,< :ªf2͗a (:?"? _B8lQtO;qo_KœoG]5L"UJٚюZv'\t67ǓEA*QۜJZԘKYcfKZ<̌ !lK9/NV_D|d*١Yّ&9WŸ-x!Xt_jovΦc~o^̤3ZexK5-4"NOӞN+CWw0tK@yYmhgTht!?aN(K27Qs!.nBL*r+fT1mcwGfu mLz E㨄J9 !R.gqFizSR^z&ֆw_deH[ܙ o-*8?p~Hq&=3)|ҝQ$TIεgK7S]²^T-ND>>Xl83WO ttYUwt2Gm<qb|6.^OMᑬϋ v{B(!p'Ş{,UUpJdv5_;bQ8,V)H =i\! g9"7 .z{ۮ7XK 5ذPNisZC,!ǓmuBwe?Iz<#P_7R/Y~ t鯦# !~4 YFp;*όjZ>" o'I˅+l;q|PiT4ݫ(8~1 upLF }0XU r?ifk/4".P^&3 |~޷Ȱ[ I˙ܸ^Ur##ʖ&nQº5j <΁)?Oy’h\K* &L@],IGo 65Ahʙr`/V==3b"2֙s#e"ϩѧ+>c81 ig4pnb$!p2Լ_%mv1=xjUaC%Z11)i'L'LkymROY`gy61Uۤo72JP Iq;~"9w@-=GG B05XޱzEc9< %Iȁ6x)ݒ(^XL*)j&kr8 %NzO#2'Fm=U2` ExA csǷKG tsx ab+#P8h svֺFtZg!s Js16'%wfzIoFX h(U>%Fc wtCAl]LG6\{Y3w"Ll62]o`:B/.Eg9Nn+= # Hx{xH)x+SMSEY6u`K, :",9K, +p;R$U0Vpp k3=tWUk͎69e2`28K%QJ 'Rmt]?_J$vwFoqZEr JVNI& zZV[p }U_}." WçTwˆf,TD ")We f˿7YҏPfޓT.OSp sØ> ;\7-\>ښVc|iQ6 9;^3=c">D*؟!z:?sn'~;I@zDCp;I/;#`m =eT)uڱ-UƬV/s=嬀mjs%EFkhD>D,ȶ햮\5>؜ƞJ48X8_3{,9(zgFeɁ\^aG%+0h,jʧ(0lGCѿ@[?ȫxqsU͝2~I&e/pJ;aD fb^zcp_[]F~l4,N ̫~Wc.C{WGI fR1x"\,{ 4}c'r6aO'"$Ք2kЛA]z)luѱ{(෥ѡW85RQT] aSرV',Og=&(g>[[o( 1T4«πGw k*3PpW<]1#1ɤKM}j$.ķ_Q\!`:\C[UXrd ހc>ڡeRl} t"۹gJf?p_+=yl|XU 0?{pPD2>xeDg:ic`^iqkiHʹ$4!i!'5O!fN h"CdASބ%t 'rW%AOӪ~jT^˶BIDKc!fԀ.Jё1)ea >>'yd=8[<؅f5A_0\W+2/MxRB;>:-7Ub! `ŽͳR;$[LE$BtOп!\'5S *~:htOPrHyXzeU jH܀j6qʖIml jr;G2FkIPAv!,BS<_#/H'4ЂHv$PEoƯ<%u6l&韰 Ɖy%`]> `%īGsd4>]5V{\ i|fH jTZз6 ڌ ,>L}w/1rʓu>g)\nz;rbGl[.p S Y~f pᙾи&s5 uF%ip>2z FIKJ# 3=qssv^o#P-;QAO-xuΗ~j[i+ _h>`n: O$H& Vvpr 4n76ш]⧁ꑟ{6xy8-i_S s(*mP}_)Jv7{. u5 \X`$o/|6?P/7# uw0,JT q3`8q۽g7 _{O_k㠨nܙF[׍q*LsF P@x#" LʡPW^ Hf7!{QJ{[ dZnLrQhty~:{ӆsvA7(^HƐY11Ӗ [>"^(땥< -LL|/wB͌t0Ga.)ful`;qp(35@O)R'./*PwXRmvӮ08b Zk l0;.r0suĝ_=_6Y4ܫ~[Ob6rMN YnqwVܫW);d;A^ƨ-҈3' ۓ^y&f8Z#jN<4~T[=C o6|SS#A豽ͮ(lDJU4_ÖGw+vhZ_-).- 3_2?&?XFXvk^gtvfBQt0Ž=f!) vdβy|2CAʮڴı[:ncQ|K "15icL1JJnx #ْk8^9\'˞q,J).KqⅨbnI&YcsP %rF7+hm>DFry֚Y.;J1G~äo+*˖#9̊p` Fme\Ussn4oX(?r|8o?#: jY(>wB!S h+փz`t z3P❋,U_RI!6qÐ4ڬ|>pq"矹׺m44&\(/U1B;^i& viA t R`p۽@!ao⧭yj_ELP)1"LHCďKLδf󧷣1LP riUu KJNl48={ݴX*QSME-^7tʣc|/Pe p)h}4B- {)8¤`jqr0Zg$,zj[B=p&U'@9Kk\bBIq7 a2UA3vUa->s5upO/N~~3!!34LЉ=;*; ʩ#33f6I 20-PSKS)᳍? HUEe/d5teygQx\nFÀ\C&$38$Hwg]MTūLR#DQtخgxǯ"1vanǯ%>d | ~om6zaDFڲv7>T] !c[^:ʄs2O1bqi!g)e'UVͲo`qݾ'G9ˡֲGqu^J{2~WJ֓%V^I-(iܬBy#84''y^ B!pwҀ79*XAeT㤍#@fj2H$1P;\|5[sDIS"1Km5EDYAeHq } iH &|b8v,"SOVu)MWd9m6Y>0A8yҭ;jeW6v /_ûqqfo [@l*WCٖg1<:5y 8%?lwGE~غ\ 0oWpJixB R&i(9XW$,{Jx蘾&s#׾z/Z>*Z/'#]AC %"{ ~/p?ZQ6/ n#D+oR1^kC܇D͙o@3=FW[_Ӆ%q[dAz5n]8'!vemdֺjr@|P]1@^YzkG:@ȭ-. Ai$$/Ql/1ATpzҧfm8x*ƎQ0EN·>.=Yq[HԳx^NgΉl֤zBz)!*XvL"g3sZmsl."w/~6I3\ן%LX K[#BB~F;Y>dyWHN~1+a䱖̘6yj^ \Tz ݫK2A b)A^(*PNB~K?[984q( TWni<[kߦ> \gq"n EΤ,>I+.(=IHs3 g|vnL~(RӃ>B6OGU;V}y>UKjnFc:ѯǙkPq}AȗiPuqZ[?䤱[)E BࣥQȏH.Ҙc;+ %+0N#cYGlE`I,ss]!W{XJ,l 㽥/qnKqt!uT rt߂v)4rr$IدחjTO] l^D s72dKy;~uPB՞)QmڜL]hfd7ʤ'L,Zoa6#FH?'a# }IV%g̤v}< =c5L Ya؍JBd4֢Js=3$T7tiƭg뢬%pt|: /B"H mjԠ"2C֎5~oeVAEWތn Z3AVǪm>J0iKy >ܰPlyfB s;+'B J>旳~ >D ># A9*ڽ|XiܖfyVD]?BIpģ'y. r'Em yFW I,E$R,*}åh*rk)IU]2%!IcXjֺ_ PV~tȆj,նJt$)Z%씻ɜz:GXpި3cߧz|L]JdTS3?Vd-x%G#NS Fؕв!3*9BV&[pcu-{rp =ud9Z C'AO56֭&dѦOZdt\%hHJfa1!e.?Tx?|w묒E G-E74Sl^oT)k4$+ޓEY 1c4=aK-Nʔ\CYF<)Vq6ZKҖI'}{=u͑\*zf)qM=˲6?N?tIA CIZ?­L9{&RwP`?1(! 2HYgFF1b@R, 0+p% M ^0=Eo c^ý;_::\hc1q|Vgzg9X ű9KpOPںrfFvMWvbvB sq秼 GI0N:8yj$^9 p\#K wm&fm&?l/a!BC_{zdXBο\ zYsEhjx4%HH)IإCA#wצ-KCfʶ!Nj+:qf- -b9lfr ڠWܵ9~hetDH~'p:2ŗFy(lcdo?ExefaFO6k<F[w!;w-{EWoc_hqK=NϺ:8JzjG<I=ujbB{r=FE'42ώS}@TFk㙮kYqvS!N`,u"_̵@on\vLg8^d8JIO:MIh}/F6&` v`[ >uU},mz?E!i2 `P1a?"Nɣ-[LТ.ׂҶ~TR%;(گS먒3p cbx̧_T/D,עۻZ.oȊ% ew<~o/)` ˩˟UIyU?"e#_r+_9uw'8b6$ⓁQL)=4LEQ'zX[`D۶_tifя~G7v{́&N"/CTJ׌LntjULB?%kT.Q--pin{m/z̈'UעUu c=4uB@|frR +kP7.;MN)< XHv@‹BsS"J"j:,ji퍡 (LC'vؒTV g>Xtt50%u?ypvz 9MhϊYZQW{)>Fosʗ8#e iYeFɩN%M& ?tj}?lk0#F1%4MFTG2( Z^.Ds I5Z]K[oolDKiډ.scI|W$׺%s5h'kr\}}l ,f}=[2>. S~gkygg{X 4]Fw,Ug'f2߯j-].v,c;}̘^LnTiY-#Rso?06KeЕu!"6&4+W6@ߑŵY@$"˝n 6!T2`aK0J"_ߤ>ckFV5a% _T"uJS,` [l,MP-DwE~:lqbь#`/'Vh3ّLh!&QDE$RPWShOJb:~`kF mx].:4hl!r脈yQVát3((}3db w3*緝GRU8ǡ7NUEDrĚEQ尿Zb_y'EK1gmTt-Ǹ+Aߣu2_vȒSDU]U*ؾqѫwRJ>ld<w&i?j I d 5h.ȓ+&M\fr;pa%E}y|(_fnF|5}:c {!M'!OfU=" 7ERwX}|^/YqHƙ~=,rq,rW`-C6zNW p|mlԺjd1%}ٔl-c9GC qEݡ jv!;q :nXl]=~C©28Aӧ#?FBAG6ȶżG''Cm|m~~4i7W>bl Λ)cGO8\._@Y}6;*KGk Qn=u;ǫ|!1n*TB 0'jhC:6B5A*XQܺ{OFP+vYǺ'P?5rkڒpɕá i0k3r ;_KoȂXIn~H q CH9*YR$7)8,PTʅe\-;tjY1kD\=p[9Sմx@~&4F͋R\Tfl-s_6]vedjx6e0PD.dctŠu wL Tacט EݙW V=@JlYX4Uu /umT%-£.{"NAKd.ip ֤ OI՜qEyS9? Mv׋twA5-~#" `ʌiFPT6W& Î@w}XcrVY*c~3=-$>P[?\d6qU^Yw0xF&SmR U ?0*mEdB.VxC.f<)D73R@'G5_Wyruhs\e9=>3׾A B49QCZnmu@5;|A |o0ʒD 7t6Q3Pײvch4BI`+#fZHC,۴1  .h\mj6V%D3 >6)P?b a(y7@)#Wt\fvUA4'|?OfF>u7Vu<.#s2'fsS|͗eE?,TYug$UQAt|Fؐf c+(5J4=wPX3h-EdP9-3|g"}B%A-u1#˙ЊR Z6M* qx@\K}`e~d~sj2kPkF!㸹%u\SG3ʼn%}tzf̘9ƅ0>Ɉh&み8p]r vH&,t#,4p;a0"Vfn Y~b QCc2\ׅs꼚[D2Kܰ<*ߊ)~oVat3|'x(T LóT4_zmo:֠!Ҫ>SkgJ/j0f1VQ+1<<PWL,3K7r)X+ ҃J N+IqtӬX*Bmp $-Tcr ; t{*5%X=:Vn-tQRu)̧& u E;9?*m,*cBᨮe-笕Ql ʣu,qUJiq gƷB9dd<gOZU';K:aȏCkƠV925=#6dṆؽ9{Цg[kXԧ̿(AljKR a Ϻc,%(ܟV 2a@iQev^H3BB1S^Mý4aedbR6XțE;r,)6ZCz[1;OۜTس'$vYx//e^#:dE"?̗{ ޝ?j={6c!3լS(faEXT3AX\âm[&Ex \\vmيYj)an،YTup KSAoVIVAbvQM}|כ+}&yz+ɓDN1}PL3d IwIU> iBsv7#u+CɄ@A⩼=u_r#}=Ƞ:K@`0 ?{o*qQ  <Ifz !#i5',Á-W89Pdf;uU>nvw%x/Ϛl.6Jsܱ26GkNKߢ'ysY{U>2ҺJ!+i 3^>ӞK )KԘ F(* a4&-}4Յt0}$Bz$*10VJ~1M;1+'xB{_kͥ^-Nw07-Nĺ2,JufBwY-wlwrBg`ޤDiN`` oQ x߷ Uz6y<>Wj,'31^3%<`%:imBid-=ԷsE2;CuCQX5hF2 9GsuW$}\bDGC搸F*,q17Es x&}ӌw1hg3``rDr]pɏD3*SGvpc{ja]4HX=:~vȩ S( y7cp2qi/3`qb}+kc)qi:!h[5.)Uq\TԐyL\*0KHFn 8G6Dw unN)"띊ec/o=ӫTnb[ŎzB$vBza7 0jl*){Ct,;8p_ĤזLh#ё}9s,#:}8J醤dNjxʮD"N#{s=ӆ.0ЈR!"D$K%G·N|}RkUS]i\8HSHv"uP#3$EC:e!MYtʄݲV{ J"FRْƯ4欃4-zB'oc Y5OLMb?m ={= yh(;8Ts4F>#EPf!nlV]Y/WD}B.~7WvF =̡s9yւTWڇfOOOȕ,ڲLz8xXLHixGΥsz/B>d42XY,0o[B[:}R[.^`Q']/7ޢH6.(T$ %kNd9L%wD=ED ^\=@K묧Nk1KZAD KegwQr_L( (!<4.i(8tiVE$16aaܝ~# xM ѧʃq&b02G(W}eB[4loA'm,hz!9Ec#\<} ADfVGeGMt(2*F+j2oE%q'!B#!pp)Q "+l׎ ZȴRߦg:H"8"Dk~YyҬ1[_zDrKVRYiCdGm/3s FPX][K(0sM$nizc)MI;3Nk#&[xjC8ޭYJ#] {vkt>.\ S:Hs&G13%JaqWS7k®JSY~<,~8,oR{a{uy[zҘ^is@iL?1S.> osN閗z縼n 0#;#JJNj5ٵHaRڗ-?Z BcJ_MǩO6"bjTq &ث̕1 R*2S}ɸџI>4awoV,J7bœ0{p9+WB\2B8L#3NT%6&>lBHJ{P݋c8@[MFFinvح(9z &勞AJ֞.d-h& XPy}!E-!(-/Bkh(-f;m $}$jdqW[1wW+VI Ho}^8.R)~9ݩlI\(tfCP/F~c ($u%7;i"xOrnQ. *ɩ?j;;_5ԊQq:&OQ/`}vDaͫd}> 5H\(IL෋J~9'G.q3P3z9' `Zؾ@t,뎖 VqVyA[1U4>(!+m(0 u$`JyI[u,]%íPLt$l0Z 0&6C4@lwr{z-J[\s :;yV Ƈ yu} 17J8tS{ }x1`2?n|}:ޯH-vSU-tCNEjlP RR 5|L 9_ԗ.l}h(3l8Ij`hA+lzo&w\'l<;+x Z*t J'n-b9&iKW<3P W:"gevgo#r^04)SAkV9Cb||)"zMͯ2xP$[c1QQp.3bE{wʬ)03l!3;&'< f|d}Me?.sՎ%Ĭlof<&Awaf!R6ðբVeri 4d3`q$@1 .y(.nq)PbwTY䞐sB<І$~2읿>"1GAzV^Q.ʋgdw2{9xH΀E)vFEno99YF_ur|Q`*@' i/^qπ*'uWr3$!xW . {VrϘfH&vY\ftpUƂ"[^hEZV}Q|)y5Ui\ x9WDej\.@|AF*6@3|mbgY])~FW"\TCRjgZaƖכgKB$ :X!u^_ /֦T&H6VNo6G~i/bJ /{=~a6k@?}|WFWO:nQm9{) F9Fp2Ӗ{Ljdfj*= ,Tx&~R/JvIKwUDEm,}2f M el#$r#w#%AHˬ!xv8z5~KMJsゎks$OOmgmbd:IcUfa(ŎƋ* Ks䷶8066&}Z t5sx/ϪЌ I : bpc4OYU`.cٙ5B,dnS[^J.khb2)?f@ d ԂE!mE?t"/H%bF8jVJ>@3KU?wJ'HGX"hѪDzeV=.+Xh}4o T[ZY]z{ȥ]ii ٿ Zy #ːǭJ^UtA]} I4Ym(c4/NQ[\NH}d$fP9]…R5BZwLH@vp}0fO.>< ̫"aN^'mAhF yWň @gLMqCoXkDׯ#VTQJ.hE|uf1<'w.1SH͆Y&Wk#/"/;q.f(efij2Ѿ 1*S]BGEZdoY)+4UVc0ĢŸۃ nyP.V-%N!H{S7#8NDVr.Am? (aF`(/u@(P= 9*ex׭,E,~{{)LW3٣eF+mœ~$C Y { "En?X=Cg$?ڳsH>p {e!>C#zV)Vrl*;9j'm6=W<u:llL^M:h7owy @YivbD?]4+o-8.1Ŏ@\<>dS(gXgBsck`FΆ|;-íŏ~pE AQTamHw#]/l:ذOMG,M2r,߻}0ai2Ql+8i}q8=G N|#[ڏB^8 wnAgX1ryio}?X1&m+ȩ+zt۝b̥ &"TӦ XplE<a:J}Ezӣ%X"(RWˉBqBo&o+,q7{OtNIN Q!*ܶ< Z ;r}sȅ!za.=;~@CYw,p|.qo{}p"WY_"# Hx}SwAG+gz%-mQ+fƶLJޣ\ћyl0[-~nfFkeBIp,=;]18jh8 AR1M}a(LWҥ%D;8׮C8TFgJLG㽱 SQzc~P+4F{mKIj)[쇈ڵ#>,ą\f8GCbD-E8Ėe1Qa ULբ8B+࠯&5Z0+gIg` <]5`mXi||us+ם$э[P Z߲м$ !Z/90a8:݄^.u|Sc3gƓ|c$YoGxYq 1'4=ceQ% Vg:oA3m@"G֊b/+6~ qEN{bz>b  U.x޻ 8-­'og+eȬ fnhblB\M?`_5TaH0c `_3It{1IqN\ F;(g}j-R( Zw3{܌K _)G f Ҥ0Q5֤s2moǪGuܚHM+<ػ% c*8cX+B*kOv/ʧ~>RIK uaY)ʞ]*Cb #{{iʟ񓤚\HI)G#i_mCTuⴚ9 YUUt $wM@re>;;kDD('-Q?1=Y#baH,dov3}&͗}puJU$7,Z`FIȞ?Pdޡ=U/?ʖa J]\xb_q1ݗp2V"Pvcs=ﭞO WQ£>\GV'֫ L0O^`i Ґ ȆzmL͇ߒ|F=U uYw&>RVfDӊ{[9]7qv2d<-RS?1ȃPG=sd JAUr'E "Yk.|@+:w0%+^ ._P;Q9wx"NXԍKPZ^K~z} k!ferGxk{j2p(дաpD&a>-9 ySMt42q޺qf$#9nWp|P뿫 !7;^;7cH>!e.˝&Yft\qXH/&?vZUZ:m88h@N3_įt$Q0=.ʵ4|2H{]#J;%+\p|p72.8wbn}1bqtecO[lt[S㐕r6#ÂNxnj2FXYh@$mb+I|`e~O]#׋RR$zqFD^Z? oEɦ|ag]oKgRB!![wG/e 1}{1TI_=yY(F.xȗcC8%zoXhǟ0AZ~m%e>r`lڦ4)Ҿ)w=ީ@XE (>ʚ33z p5;m&ڼ r/ap_-} )$2D1y /ؖk-N4 &$HD!ȱʍmH̏ uQ3 }盏C4ìtU$n,] ˦IR{/-Dų$Q~U".PQqE!wu 0{coImo xiY5}_mElcYE۰g|7`2@\1 x\ߨH}tD !#ݳ'gle2nFC,ͳ x%{ -S[w*s g4ȲeDzfp8r*Pu{Zo<2DhMM{&U˶>?}=[89IcUU**($b5GU &ʐS JҘ#s1@@d`|aEqbRAQ숚zցߦv⢒>hlt^9n@">\6_~GK Re49bH72d[.rg=V@yR!Cj.%lmwh;u;%ėd@nl59$l7&Fnc-od/HR$< O ZL yS14J_1s dkíN@3Om4tgyރ< c@cߍ- -ѵak3L .Y՞R{]9dT}.OQ~)/plaNI#mjFv͹%qcG%6 t=qs\bDpIw`ff|ڴ_%8ӵPwU@PHe;{j}S>H+KO$ws@ʙ}ל13HmuF}YddGPkZP܁oD &_7H4{9P*^xj¼̎#Kd^gRQPz_NrhlS"YZ]&foGoJ]bz ]`檇b[ldCVF]Œ.pǢ.Wɹ &kksKvPc9 ֥4Hz N nFCY0V܍D dnE Z=g!MɃw3HT;5V+>%i罠 .6qENyXYi/ 1rHHT T*Y:?K(7F˯0V^:֑t1C:g!N?=}zҩ$F5*xUA\Jvy<%nHؚ1SoУG.nŪ Z- e  jq0s9Ci͵L W (j0O9|dה=5S)j˽i+(JA\h#Ņ-Mx:qڐŏ1(Nۼ$`1=jkl٤81Xq60BvM92'/Tg yPpGRz@;2 7](އM0+xdcIs_:,^&7! fh_"?5KMU{osu7F]b,„"j&ht4ӏQ&[ETw g%O v+ e0=ڿoW{ap7 z) V@>wBeJL ­ASh> Xg^š#W}2nG Nf=S7UJ<西̤YDۢ"0 4i"׈zB`I'Jةj|+Rʢb`w^crpڀHN8K}͜WؾHDhzQ+X{K:k*OyW|?rvrns~\0`'8Z>EDE!/!@Nu*i^$w5U;g`y7%' P**I BQ[Ȳ ΄\(MM IW.*gɟYļ) b:c ҿ )Ƃ*'ۼo$+a@3 +DY\'J/F~T;#Hbds/\r;lF)/ wE4._VE(GjҽIؠr;͌m9'/tM5Llt$VⲬ@+Ei$ӦAuc0g/Xh X)=?\x|PdTsNU<`n 0*Mb27I;2FI5ROnk }/b^\ەY?cKy" Pewv,~qwC7?B{vz@*ELeOؗ(]!3ֻr̍:EԀvٻ:n!ZzV7#ҋ0Q-a4oڜE_z2E?BW\'';*@} bvpewZgP{3%~D}=T0}( p b9W0@aro@j|m-ȸ n=W[}.;Tpx*·Wt!3嗏D~yOoOE=pG@eJ ѣ*0{ ̤8/ԟ2T?sLeZ?W k^` _1^.}N$A0j#fNPB|ܖy$xLFm<]I2U : H_N_ec7M 53T{uʯ,^ MʺlI^4Nv]~A2Q܆eD%HAD!hc*YgvĈlfTԅ\P)qw(O=h lcDH"iӥ;褥Թ;9Z\ M1w0>'? ] 3O[k$t2[޼ݿ3?wͫY*0 hެ8 II^ ƷplG<K^ay?+LZ*UJloq0(hGZsdrua9659URƆB&-,a_VOO2Pq8]Ki%$?Mh&F&)F#_zxqcP$3MHGJV\tQcuLJRr2 j{EȔ"fLY6H0V^Mi4xzt¬&IP. K0\߇4(+9Pn`W3>`/7'V0LGֹg7p~_D2%btRG"E@ln>Wv;IżZs'}ԟƆIbK4A{n>1}1Ցǫ{kY8?U:,0 k/ ;XF0ϪGCΈ4Eń+6܂{Qq 8q-zȗI\pםm0mtoH//#es:\Q+8e#(u5 rc6LXWHS ~;>}&D\A`Lf2N% LGZR\\$禹g*&0LK6KtzmacxZ[*pMK3Q(Jɥ|:|pS 6w)τ*<W tO}͠i##bJZV S` v +H_Hh ^DcͱLz8}S"Z,]ŧ3L!SFn@%tcmp׺?#V;=]jLOQKWr*^`7\]+ 79Q}Y͒}=Βa$)y~;>s@{<$ѽ?ӏNrl7]N}~fm#R>5oH̦xibkXpu.77W:K z˪Rt4s[2!3ٚ |śA2#k8S d@ݱ!9OLn{|č!*^q?Hp{V&󎚋Og06B)+q˫tYo<]ى؊Y~&7 dn mhUK_I#Z>2Ƒg\wJL[f2ְ.U:&aW"g蒃}w,(m\ޗDi9 %D 2kR)8LV]l07jTS}ʩ೤nNJ{bvUb0Yjΰ!AidnQH"?͹dcJֺz y >j,[iOhA/&@ 56aÃ`QH[%U4J]1.f-0F흴>g~5@r楄B\&4XfxAB +kV clTKT3b]P[BhӓvY~:p@p8 #/SMȳ[T)7HXp;DwQb JQ!0>/Aĉ|Ym [eghKhOOMX'H0~FH e|CA0Ҙ[%e$!72Pr+zS`rN=`I0쫂n@swM^]K͋1|ҷ-eqRqxavRy=V@ANBɰwSObLOr.jsٰf^}n@Wَ]~/GG뎋x eDMѮe1NRU,iFE:UKx{+?b+ t}<@v  eB <.*xA4=G ӭh{ķWev?Ɇ0tnj_A<LҠ4l~ ~[(lCquJ~bc('i.H D(yEx7,n9unW?b %D2ܫ{|?'Ț?Hi۾хWyS"x<| H㝝u{xNA՜18[l5,pIu ' wZ<4ͪ6vgFai\\vZ!V )ۼ泜4{IJUgok$%1v2ΜF`U3aPfT[rl.H#3Fz2x+=VI OP}S--a^l*DjGGi caZbU^y*{{1\T)I"}YCI9O:?cCe`7C0I`8?Ed,GCs<ؗO$X#J#\pǰ",ns.tnᾮptjA{n:0e nlU{̀W[ ǩi i~>Ma:G6͂bU,1x&&yU4nu4wPW٨tTliDT#8yo'-l:X,%jrr.^{^꩖nV\fS d$QC© 141EeՊL5R]I| :|$y =/XHixM!x+k)m`.xtZ[>#2wK[{v:0P ;|է8xxsw.\Tk`ېU)$p.@(|˭"$Ks$$8nK೥$o5uǒ6RI?)R\q=4)Ŭ/І%dQ9k/x]N#Ezy|k_rҒ ؛P"~.Ed;]$QUk)v#d}i;mo:;a$@vǐE^.%,{UlL w>2OT<ׄk4Ilr3cNF|?< QS":ZH7|:\4KMw]mFFa6g&8! ~(D֪j&Mc3oF{V\ 4s_A A&bZYtIx9r4]؟̊o?jKPT U3O{@``BK'$񣃎i觙pt}_]pr5S^E(+'HzSI:[̍ q Jᄥ]9WV%0,_h/ڑbźo`;NC˂C}9{#v^Rgŕh߮LAv0t{c`]P})Qe%h'CS,C. L[M,xcoev$CS{ezO ݐxLri]>Vw#ZQPTBPԙε5Nox-~06iE,ॣz㋕!kCQIo)g8,ϼR4 ))yZB ҈FGo릴&cv8W_GS/=5'xyϭY&{r#0XP ©e5@ DWgL;P\A#4t)ٽ ff_qo*z[A( .Ӹ;]m:8Z];7׳k٫f&Ap훥"'V2+QPgȉ587MC*z -[az"CWQ!O}8fu'/:Ĉ[/,0=֠Qw 6>h:?vCV8roEV\/(T Hi?O"uʆ]r>I*unAoHrn39e_D#7@8sCPKVoV)Xy`t 7jf66gF(hfǎf06gCԛ漇 k2ʮdʚç˿ О .LUݰFcͷcR9FGAi{?iEv X k@)WA* 1RC$?ԮN)*%璝2}N]!ܟ-\%Vn r<(m ?Y smko(m{,${Db3֐)!~梌 -s l \ }ۣU9v3.{X-m%4 +p)aG ӫ]rNB!3 A|f«y TECݵ\0n4FRQ"!,Mx|&~YP6JW릘tc ^х.+s2% {솊E \ [ 0+ߌIK-W YwȰirJ^lnH6f*"~%}uc}Kfx;lm74u4+$ZKf(8| F/J\ YLm Vs`'b+W_(hb3Ajwy0ZC N5D$sst^Gm@侩ne`Bhl'eRկtpNϼ;m#Adhw ƄbآF\Ϫ}.S7 es #je]O/9ec ~ '6")=-YMQ?הr죜_O5Rºsuj:/yC_!f-ȷ )YwW v͎ǯt˿|+ndKtS VjjU1#|B&Di= ߩ-BT'sZ%"5J?"D+% T _fY3[ a Dֶ"J`%N 6ju`0ÉdqK誳y2o%eTvfK Lُ2g:gnW)Jl} i߫z;ͽuiEAYS"%էdL"rI[&wOhR:}x/0U*Vrz n-ɏOP 3–5\㋜=_@gga^,/T]nۈɺVpɸtlT7lgޟGVOZGŻYtѧDڵpt>-ށ<~E;<J)*O*KIQK"jGRٷ_ˏ瘈2Ż3jU.:2Ͱs"7Vъ.y3<,4nJqDBzHWՎ{SӲg/Fߺ:$Lف C zM1@j'^"qWaK stYR z\O\<7#]I|V;-otJ/]kRVʭ7p,0_.ӜehNG"zi~K,d mܜ%)i-3'w܍Ry$bۜw+NlaI?HЧ{82;ӹ;9ux[B!'q"C_pR=j%'[$]}TkoBbޭr2 Zd0xXoa_R KI|dhUZrע|+?rczZ{`i͎օ]^Ux=I\={8Q׍cFJt-k=2yd<*+ ,dʹl`grZ*2_+Ƅ0շIWoɟ6 nA!O S:>d$25<5_rBvYJk7,6ZN-"N5`!u ҵpYL"AErQ)|1 Tf%s_ӰɕwqAP]91ZSJAcŐ#7cl9Fn7^:pBl/ {Rf X_t!uK톐Y-d#"zsh;LJ:n[8+;K9$7e|3EܽBm%4Te6m2ș+`"aKO! r椤Q!0"FN@w5GxrBG}v&jFG*\$\6夛:,Jrhm(Jɭؤ>xjlxrf>مGW%'%%? e[8!NDB9q8oMѝ}eQ@!2.gԗ]l5FȞiVI^Zt>"<1hZ6L  ^o\o*<%YGfz:͆31y3z4PǥߚkO`"g#V1/Hl'0kj|87~XG|d[PybAG4{.MIlQ;_RDAᡏ@6\Bgxyz=ߨ>BWa^hnX  #w;L T&%fBޝ 6d|FK{a)Jk3 J»?|6{BsE|0H|ZA=r!N3K3}>8"/QU\RߛBĔöEٲv%'L eSOcڣD]H˱!p3AL(y|1 J al =zvِ_ NWHWq 2$)m*ڤ5dϤvň ^&r6m]viE DMޣӥ=g akd T{[b/L w L6% ނ 7!bM))I ߪ!Tnryٚ&8@hJfyy*Gyb~`j::fy5 sJ_Ї!hP۬8l2 ,R ؊h #BH8sGeMơvCYDz*_l@W߈Ðy5꧖r\?5&MIߐֳ*Rc%+92_g|ea#XN"/(6Q?3 +2d袯|C "D!\W(0DH1В}K11)An|'!0ϕ&%#/$+]=l1¹ [uL:\;<{(^QDn1B JYϮ(|jdFG<( '%MuS*C?ɢЙ-M Y {-ݡ!ɵ4B 1#K?IJ~ bM]}˿ItuYT GQq#5$5:q w:81 pYCpP/{6d!0k/:~Ԑqbfe0\&1>ӛ 4Ś }f5k>"\4X΁Ԉo'. tx0t9u`I8Uxg;P`u݂Jd-xX|@9WV3ucfiGX{)`'x DΧkWZ.EQkpڜYË *ODEt2Kn{Ѵ}ޛ]{ѺA,2u: xzTt], x˕;;C5 cA0uNJ}4c8{UἪ'eb82k& IM "Y%Qn0LkIJ:=:+،v~ TjU# o(;9)"rg*y>ά{k/xh<֋9W.:2OU_1 i>^cJ*A1!]}jvP}S 0:rՄ+hwU{۬Ķhr qoJ9' o( ]HL9!1< t ҟ%W2XO֧ƯyZv͂]X),([s8pZiK1)ڰTxYܬsnnlOpS,Mئ^$X U8%}.Y~a*7ĸbI{1 %υkH>~^a9bׅ<XЀ|px$7nD; 7^n)a2 q#CBn^j?k?\8mB+/Ań;*(Fc3#D5$ep;o M ]*J6\~Z;PZnsoK(rq欴҉sAo=Bym^ g0}-.[Űru5ѵϛQZ5=U?_Ȝ-!]Fo&Э9?Q*hvH4? ^vW`zkujO?Zʥ ^hE6-FYg.ֹj#ηt[Tv؟&>}+s4'-D:=+:DŽ Ykn.4.\&̗Y t-[w* ws")vcѧR%<(lkLȉ=)# ) [qkx%4S{vbk "$ Ȍ" 1wg#}{I=5zrƢ־ipVRsbEոBj9ipW]m%zvv?bYаi>wrN fQ͛e?AVq?٧8H 4J-aoy? }؁ 2r6醖xm$|䠄q+IZ $A;M==jALĹpfefNE3*ө~cIda)3Æ kɀOPӨ/ɻ [uZ_7;eWrgHE/`$&# [EڡW*%"ly>enht&SO:iZM@>򑩱Gji Иt߇bV3S#)>?j {{5h9?$ܦZ, @.9$9k<>1:(Jn+֘v̸լV5ת*ƽ HW7*#h&N+1AIW#u_Fug-^7x8%CE <A0L:!fg7wHC3-OfOĄ|FDc)vKYoIM+/Kk8% 3R.QF tKڜ OX?~Zyl㬇*H-B웧0s{Gwƞkp#ɂMB:himoDtG:3͛np߷T %p' 0|'@S= O(E:b|'jX ݇zى!YS:wѾ43I#>&QII9j>/=+t[+d*MܴG ^oH:Sx䍔tC}r\ɋ:@H(@sq@ xS4GG4܁~8";JyE& ABj%4#Z%Jlp`Htd Hm6)AM\$*t{̐"WK}{5пĽсI+60$BG\*kEX_a;﷙H5iUt(:X)TH okUTB ƋhKKxfc<=l#=tWl>j;|gbx502T=v!Xn F]Lao/!}=!/k["D*77*V; ?n 훁@:k3kyI<9d`Z`\٫tk:\Kl^aqW S8s&;P}+0w1,iIމMLpXOk΀lr҉oP(QJ~),Wsృt^ܡt'"A!Ҽmᅲ_ H BxH҉R2D6iJNpէnSg=$`H%MIOUBtzQ@<2i00ā $7Ekdr獖#qu};ݲȴM}L0Eh[qr\Eb|B%Z};N, YӺ+G#mmhR DL Ѿ:ǜ=JOM/HN Oi1b.^7P>3mt_ 12 ¬z,BvOʤJJy1tDcB#uGժB+MlYfHwbPЬQO(Ru<%3g,8CZ vSa- R$)\8:dlu2hŰ50B] Zn4Z ~UPo RFpZh+DU! -8HEֲ+6 X"; K%MWOg=s| %Vr|)ti( ˋLZ~TJ+dEB_UFжC31u [cr\M ǢL+ 5zb暭~(ň lya=My|=9;tTc]cFڴǍޝ vE6l.D5%3\Us Ч%*|8.Mcz;5bp}hNgn|=N58]"*5k夯 -ٕ&\g1Xki/9`ҬG.=A(~P>U#;mvnI܄׊a'xj˽phf c.e9 >BKұiUu_|XI50@S o ݁`]w7#ZR-)Sv95Q;7%D?q@)_2[ EǹT78ړHOQbtHnMP"hαT&)Ω@4rRyUL3dlQp/V+8Ek4Qeֱ}qtu}_3zYW@Pc$S;2ղĶL#P<mՐBTձ=@Okڅc^?}6K&ӝ[NEZg֗aNb&{",y͠χn Iy%:ߘO ҮvwZfvyVRQy!µo˧Y{H]LY9%{ZӠ6R~'T`7FFOO=j(6aMV1{1ɹ3S~wjij5q6P(OYU,f]05Aɨ5YH.%OE/A w(Ob(Cn'at˻m0 ?pY7x]xrSeZ>5?>)LqӕhW=`\%V16^) 0dkN=3R;)^L_A5PaIDj5"m߁mLaBqgTjD/t]JDbT彋qm& i %BP 2|%yӚc3}#/qр?|$vA; !q6h+ 5|=?Nvov^ҁm3]o ڗ&(7MD#hf4@H[/2;|&=CWuBTqgyft-1!m[ٜqy pip`C'PX_&ci[XNX JH~*t_X]EAt]#E8}uw6Oإ yO]I%{D3Wx/\R6ȴݡHmwT(4f7n'89\EրBLOL!#z|!M2t\w&9QK<Rqğhic\#cAH wTetx_QiKy®.g*3"\Xlm_c>ҡ RB"$:2/v*?ŋr&ZOشjy`y̿ cP0$ pcwbp,62 *ZI?(J6p!YRN9,j3\*jT+ݙ( +E8\ONU麗sXmZ?m#1U$ހPaAM_y 0CV.OnQwZ#t$끜L(UCvNlWUP1q?tpP#+8S31^#PЩ']b~?`x;&X/M_/AE@ uKeAXdN>os?æBDͥN1?F(<SH%>_=#+Pt /z%^!hU^5- WS wBLL~G$)ĄYEC~ꂑ/ qDWR(Ɨr#{Fޕapr`n4x}eQŭIOlmwB <8)$_PK)<ҞtxTdcW?Co"=T꜀󂺬[گ5szFM d%WygPm\Lw~M4 B)kc| j=7QsTaX(M)<z:.]xV*V%Fa;Ә`tⵝQgLf9+2IsFrk5 (!6ۺ)$]bhh9ҟz钧ջ5!̸4W)'~yb3rqp2m0QT"D5?ߵp@=LRTp&>fnvKrlrg7ۚy'g3hЉ@(?Ŋ-p}_ nHR1BWZ"-Y:!Mڅ-Г]GU؆RD\bdEc ,G}6z7 `STr۪p5212Ic ĉG^uȡGO; Ig9foJ6k"oD9AǑdԄa}̅N^s"r?s>xNG4+?!ަked-/MJp?'"Mη:`ǑH}i>5(+[ݧvivHsr9kP'@J<|)5%$LbAU_澺78 N3$:EKTR:ۨ-Y%cҮ"lJ@{ )7UU5^]POI;{4OMMAiݻ6s)a1PߛNG8†MkǍkeLv~OMCGPJԋ^G=_p.*w7H >mUw$TMVnݮ-@#fM!Dy [ 9g5'b0ra/|ٔwיZ>E 6 CRO# 6g;&6m.hX)ws=OO =tA#/G&U,0:el&F~/tRmYs Fb|$,:?{;ٔURrKCuS9yT g6nIVމU2!9jܢZ ll% GX8!k:RON]*oD[މw=ykֆ `Й_]f9 #X`o?`x.M9Ho4fm8a@&j $*.YHΛ#Ba 3zÉ=nԩNLSONT9:ť?c-WCW7H)6v>( ;91͖7^ D)|Vn4T47B*' wh(@ 6ѐDf"=Y(PEHzk=ukS/}y{,5z9L_疥X$ٯ"C5@ͺ$u~-$|k.?0մ:?U:7J8e jp\QIHBl_^(p g2V TS<X:P/N7)9pZpN7*-9_E9 F:Iȡu%\? ~$ ABܝFj :~"F+"ɟC5UC_X0X&Mo7)&3 /I;>ܗ-J|YR§I͹ [.2]k잢:ZSE MTOm>4Ly!9W%mds=.3< HD"謹$CRRd`I$@S"B2IuO)| {OD.0B¾7e$-~T57O(+)0Ǡ!S ˿|LԌXJGѦ3}919N@St 1>{b48lxuv_%Qݳ dϔ\;1$Z_\wc^xywEbIKNBϵfX1﷠,?& NOB2(|VFE r^` v$WD2u:TaO˹An `ZO]_CXۢˊRsi7)n%;wZBDmKT4>yL Nîa&k:f^Jݟ潶,]P|{v5!s%CX~%A'U[K/b9K©ךN JsƬ^[; $ݚ0]ǭ?T _bk4;0呥0l]}u#W~ؽW0ȥz3N[ 9[m_sFڔ7>Du,eub)o^D !5X|WJoNQzGLeqsQɄgGjrlMʐ A0,)W 2 tea#9|"υz@5ln:7P$SA_p>Fh{. hXoo5 ,B21{۲-f ve*CqRNug'l(k: L ѕͷX\k eN`IMu8C g7yW̔PF Z:k> @錠)cĞOؠCA$qc(DXv a@6HHuĉFiUO@^طq6Wn+zknpumM2s?TMXѽ7ߕ (WԵDPFzQ=}1 f~uao% hÞ rNDbB?wnrKJڵ4 -q)BcHL_0wϾ(IcToY_MeM 9oJ/ |F 9. (?yJi>W:7RwУqb$B:N>Y:gEz5rL{ e>t \m 1 W[Ofz휺ay#i)OqbOjIu[ug0(9s uUoϢ*PnF$ c4[` +i0wyKM[ЅbKZ45C?RJnX/]1qr/l@F(,H<YĹ27uen YFb5UTB1 /D+-֋d2D+sCupni,"f$xXI 0weDX͖ʃm*EE3+f/ lcYd %*4䃭x)vj'_j'uq5g PG 'EL#^|H#6q|9֧jrcB R$#{Ɨc! ksEP8,^Nݗ\i/;m#y4O>p_ ;=ɳو2_I fyy${mE@fEZX#}B;1K$1i"6 {$iC-N[59JvHa/IWBa?8vP {  gC#,aOklmA$JL*ZsH3 ,T%=(PBhU_<ˑKrlE \qݔu qT'mI_)K;r6 &_>½tśA v ,/o$jq.IcD?'=NŒ)p`lm>gtCTKQ|[( N<޶ }ȏq֞,r6pew&?mË&!Q.\ig)tg_`-V? %¼m1Pdd[N?s.1.Sa-gŌ;vWYCfY (= H~=mTLɨv{^ 3@ͦSxЀ51W>DκG(~א'|ാ SN0v6E-RI?Pݤ%岓 :}T|[u3TA>^1TIpeu \`ӝ2!j|>=S dE9n\W 4tq@&!2/IET =kM0O(Vjtm} 0Shwiu@楾=bh 2~ŨOӟ AfOzLS)ќE줟lLl1wl<ѭJO^6Wz3SMe6_p;: uSu1(eF!8+s CzGO F*Yůl]j7 3hSK Cm'ڨr`"+Ce 멺ԯyo|mM O蝝1qrK:bǨ]-Cp>cÏx'[,02{!m\Y[;dO\Lj˲k"q-JRRG >D..HgσYIQ4 (ELkalۋ_Jm;}\A!1H&$j^6%?&/Ȳ<ә DU2-xQbWW5@XHcF_lK[oH0cۀvHxnlBΧ1Mg* J {d5+ɢEly/(3G&{LKݔq[H YV4觡o_b? O;);?F'MG,oF+#/^taq5u6zZP3D]B9:6bU)0{,wćdAfqX*AL7"yB%d'h(!a+ޗgL1ǚ8K?F3_}?UI: ~ =X)ɉgƎq2; ںjA?:@X`8`~inJG bvlST],9?耧Uy}F_z"&>k?{a.hR^7$/`KZ.#D"rziIp5xՙ+qJs6P ؏,ӻ$|y̅ޏEIu94CV&3w\QݚʛzT^LdA>Rrx|4 7`~6(65“y':ϟSb1a $ן\-;\}+h9m͸}c}O}<4ˠᙂjnfВsh6:xd@㗴7(HBvG;@=(SAhk]!BBX $,#*V)7SZ5vXX޳ҷg"k (њ;u ӋL_,>!jbqZwkטJXI bh+][*2 ~VGVX= ^kE~!YS8"=UBblwg-e%E72dE&]4f abu$G̑AIT+lTǽqlp?RCSnGֽi0gq(u$w[AI+-#Ԧ%?DGLBE|ɪ g A%#C)#k"fP[9`B ,gsek'ʸV̿H[1?9~\JSώCشLyߟ?!1F&kБ`B'rTH[Ο %(8!]$"@6fQy}$y.W[(.ݩG-ElȇzFX0>.vCyY5|4PP h;ņRB(Ћ1=i+~K̏?uY{YSV~qb *% cÛ^˼d_77TZ5-H"PDiLZ#*}Ǣ*m} ̦$ %,`IM9#cUAiIH(3醄1;+R7BOu:Vi)0NbC}|O1 x. >Н 6K cco.~ 0r~&Mi3)+rp1YiIJHҙg/hi?:-*7GU9MuzЀ@)R i耱R'/5%{5o,+Ac&3C/`%HjW$\{0c+ߏb6aƨèOj,$;A (wGk2NH=1Ȕ/QCP>.<m5l[\Y (@vǑ9ǐ-BrǜuHw)9'7Lvedr0^NKt㉠VܨiBUW )Qcï`٢Ps-:=4oeOcj- }_N fOHR/FsDt,A,qUuW%[8خU RY;+g4WG(ӾT r9OPiӿ"eX3r>myCէLC]avYJCIhrM8pwl0}Oe`EaIXcQ?"j8grB6mTvsI{ ZCGے$ApVh"Z!Bja/ͱv~]@%8O-WBivSY/N7|e<q&pb.~6"@jvp,H9p-\z?} I Ƚ H+=4WO^X`Qrydjw`w0T?_wIctL7yᇨ7AIxm* ҕݽ۷.|ߟHB:f !\=@fHwa!;_ 8eJS9 0Ok8ZN` ow2*Lc(GF#Sh hiuupR-GlzZf̍~ld%gXxHqC#(@!*dFA_,7eN*\,1ƵՔ:@aUaHkaԄL]'0XkǚVJWeF?͡X6+)bSoQV}05x42B#hMo 8܄ h!!]U-ʆ"0*6*((?fPSh*yJ IKdE]\zfP~BH`֢ >B*.Ggr T^IŸr$H%\`M'5f+ϊ S-t'٠7lNM4mlb_T^f \kNL t{ti GϥF35)ӣn-Uzxٿ܊TÍ@2_C0wTi77Tdb)341ǟfp򙄊S(!-v!tkSɻ NOK)Mz>ڷL[hp 2sκ zoԷ3N8Y9n12wgX~Ea;(SͶ+؝% 2ž!4k>W׭mgTݥBY;UD'I|Kf= ~E:OڻL,?7 r+_3"W̻ɘ'PFѰv<ǫ"aWM  DwF> D\Hu5.kpƐ_*euW=1 6߿a6PMKcsl@.䥿9 ]]$T%s:.iHW¥Sg^iV7tjHyn@Ȇ8;y5Vf]ĿgE87&]*:ࣵDҊ 0]xet2Y=م$3WL~Ξɖ#lVj'U!"-Igr<L%ۓ) Od| 4sfb}pɴe؞`UX]k'Hc|MHQa[8bIh(9ҁv`fc Q *e9(\L;i5x=IќpgM"O*MMjM3՚쟲s]_$4HRAҙiIr(H"5,P@9(\LsZg'q^?P^ULq%śZA&I@wYKq'iSP~ xontWn4ii94g뱟\KtvJ~26bc,ZDߥ_B!jdXb~cQ`WEaOa`}LkL6Z͢2WDEvP艓NMyjZߨ_")k.:Wf(ׅBa0{P 6,(ytqo6hƆǺ `Wݻ%WCGeL݂_U`[#Y}*?ˁ\\?/+օEmfэ@NR}^w29Խ$k\b*ijEZRV?hT] YQr|wԝ*t~S"t 7s&q%FHm ~+:e@`60jg{W#]|ijtu/N7N<Y*\,;1z`ȳw>*"|W]zLy@w@!߰F`[+u=sq;ȧJ{1}KX*eb˒Gf;BWGH6wf=Ic3t'dJ.0#TLoX}م6T9ayN޳ ǝtW?,p@ɿo/,DRY(Q,,U6P1`z[G+@Y6+/Tñwmf ZqIkxG=}pN]\) 6CjN(-N䙮*sPb10tfbLБ4KTZ$*8qSҲ I{w%( HZ' mA5|^W:ӭ5 Y0w)r+A"X^>jYiAPն\;!d]huh_T"N}\J#ƢM.M9)1U`*}~pj|# U$hY`{Qq"zYgBBr +Sc(o@ʏCg2UbL!g \ܢdV,&_QkMz#[|mE9#Z]NQOoDTO{{DhvNnWyS5#VfRrЯn&H=+KAE=6o+TP Ghw=CQP_{,ovN&DZ~yb~Nq!VE*Y׌J4 FƛQaM|`w V4(}}.$a]nsFf]/=)a zsvmJ-$fW%X/:ȥZ;Si77B"Kb (Ll0JYn9S0uB Ԫ2D _=i ;GQЮjs}7-86J̥⌎u_S>!qfE<3G}fߐHU GBwv`51Dwd?w_EOE"摐lv ҍ9M4@^;:=rfȀ;pQu'6hx3TE_Z@+zk=6^Ն*tk"Է)"²9~Fn;Iد>U~Tci2E{5D9\7^ #J[OBuˉQEC7e3 4MleBlɔ[@ ^.ǻ[%H}CI[ua̫Ѹd \pݥ@U4&n!(Se-,\8T5}sD Xl Tس㓋# iA*B=@@+/R(Gs$Bnxd]r#{ ɩF k|nis.(~yj9@{`+]ve>az<>xzdj؟RIwuيqDh"Tj*K{ N$@tdr5vh-䅇K*%#~wv+uKUig< M9ɦd%WDl*{ g.xYeQF"O+7L井A4kՔH˫[+8E֪eǻ>5 8Tufɶ|$YL-nޥ_k 9(ŢDk LBKF6@2bס[}1kum/#6DM&ܽ>> 亅AWjX AkbI/׈0ɪ)e+ٰ$lDz$uhKs#&܅%8`5!5O#4:Lfcp%޺F;s&6`-bbs zR9oxo{=f͞q}c8SƣL5 sgj6{Zx g#5M߄{aŀ4d|}Sy=Sl #U\&M r۵V5 ͅX/:NRwowoB w9O3}6OyDFeG"մOdE\-! P.`:ZUU6PK6h " "{u }qdОJO={RO;Sޑd3̙jʍ9E&8mJlA6j;AK.Ù8mGpz"KoIX 2ּȧe%ev09_Vm3/"`5-Udqfƪ:7;򾙂u3n7A~]-"h!@=qɶ=:CY ]+ٯp62['$c9.:_@9ͩ`|z^]%ֆ}H[YxQQIfIOe?ǖy?솼4n(60[ovr¡VwSdXI=wBGVKE([~ ?W#+ݣU%%#;OQ/o3؂pI@j"CPLpbs>RŸ#%v ӔQ@<s:Qq;X`=O8('Np ABc%؍{ab91xZIC}EOh#ʁe_cAL%_(/wl {>GO8FuZ+b$PS%6)kZ-۷߸&陛v?1;.u,"+M7eNs hu/ lJX8Pu"]Z:K?"{'@QaF^ޡqQk|#_V*v*hQD&IPrَF=0U0Eƣa3dLfކ> w& ĉG ϲbq~ѣe#"skCԹq#J<B̦ Z, E>֟ vT=d}m_!RNޏրmTF.t)_xg`,[$7ꈧW(^.P⺗sYlկx~13C Oմg|HUPAD0Ta}F@Vx"Ν#R}F1"82@JT =͗%aV+\!c@V7J:L!{P.˦9FUt]$d'lk1ԑz' F/w޹{¿U&rMډ? {. 0۩-_gB5qS:r4Uߗ 0$9M܂sw6.[5Y $ Zh'x9[;f(  ~yF9y"FxF8dͶox#ٵoЬBH9eIͷ9N|RKFK|f˞1nhurpy]ad׽ y؇+1z*#櫦_@&3{)l ݻUgcahQ(&]PeV,ĦPݘ-5rcv 7`5wѩ>Y߽5 !k鹴qx8g1/9jƍt~$yMb O7hg|W2R79z@X>-zWkX3 Ӑ]d*G,nblr S&GL{oҶ߰.xl|p@~-Df]Ǵt}F4r;Vl(14ߘe'1>9iF 9\[t_Ixhqܩbyɚ7츓#&53)Ǔ6Q3@ڨ7ʞ<Yy1'yœ1Py+I;FU:u'VXss1U%q(E%)36?1#C=h`rnBv2]'i5:sC.u@u?h܈Z#E]!D=%s'^с7xmc`)I\4\3d/TK]R neAD:b/X(8twP #bWshήiLo|+7Ɉ T\wļX(YG-f-ܖL[Eh8Bp&+14lJ֏pRٟan];^9D|t AF/uYÑ+ !'D"k ~,/,6OkC)_v!aaP dJ,TǠ߀x)lB84蕲X*A]Cs@{*1mS1g78%Kz~%t̯Z(M|ggy)YBroc3^e: b,& z)(vmڭ@Swnv fzJj:~.wX|koCK3)5/g4uЗTX,zu٘HaU{o 1tvofC0^"N/ 8'-^+_x,Jކ sM׹|r&v/7L{~8"pjPt&Ebt ڝrH3F #8 ·Hzj2p:UWW}R^ A#ԜGS7Z#&0Jqw蜫Ih_>@F|`C31k@vn=YCgfsV- 6\VX?{"5x ^wҲoԗ6Uj)|2,ۆم5D@8mٻ`_5T.Y7F+ޘcGJ-x}A7^7% fMAn/?nũM9V22N\^I-=o0PCv7oiziNmA|;RCρ+u` Х&!Nw2h2c,xK!b sty4ѵCCtR:/jؖlMz Y! ,rcUҾ k9jKc=hE۫/xCC!Ԥpu^@ݹJXѤt\Mꅕts+\tw42:Ʈ(Ǣ IQ^6NꚖ+RM^aJ ˉpr/F` 86qqJllw=:jס증`ސKCd, ЌVuvpw2/ve { TYH<@Jc NvZЄ0g' E v~߹jkr ]o(䞟Cs ?>auI6]ē$9Vm "#rV"kXYd4 f<f>qy@DsϾ81Yi k+~t[UN\N]paRlkZ\]ki{ ,؇ĘM{mANEAK6풕 W- .Jh|W @jm(2EϣKwH4x\fkWO)yHAΊ^b/ E H Q 7 )7-r* L4}acj@`NTE !shP|U,ׄ{N'T2#ʹ"arCUݾ.2] J2Yx)sכ!ͥZ:<z_Lvj\RoGf2^ؗ./6EXs5Sװ(s ?^Jd+nE\'"B}\g"U?/O";sVRu NW1t>MuuN1o9 IeY);`beg(*e!EݟOˏ*Z48]9W{ƀܠ]ڗ?DhLS$i-zs762'ZzoVtqU֩KqBj=7.4Ѿ"+t}_$WN&^5o +8.CH :)&B"|JGj}Kqхb킇bV86Fߜ#,.E!䳪V74* @U>V^fJtȼ*m~ə HaPvDz&s:X) :4u^ZQCzOA_DW `Hc`)LP/J():y}73R?/ v:`C0Tlk*.iIlRARCa)2!hl$3hj#LjzIjy.,.ա֙+@V}Q.⎱f)iXVoH;[fNvÚe/>h_Z2V]$9nU-n9NBnY=mF][T8nbغ3u\I]pj;ޞ-]QM`03̱c^+ר  ex'DڷcQыYCzߐ0AȢJLB akOL5%3ImXm{68rB{kk%5*:|jlLn4v8><*hآv1٢C$c-;%z'n=9YD*-&-!QtBJQKJ~t:at5h qزƉ7smhK~%P+G9@NdO|?ߑO&ʺp#px"y0m ׽leGU;0qsKs1,,sV~tє%Nmo3S|$dߺ2e=]S6l2~0a`R RZ( :qN@TQP»Ņzn%,h|ԓ4>-\pŔ5zz$Dfd1j&`͝qDaBC(kc( ooc:Ói&ꍬ5P*P $C#3F& '+GZfr _uu5jŪNLuV%,d|nx=.pyQ_ҸM-o\TErnf\MeF=Α*B#E,e%dBkYpǿ/7B$R .(.7t1wFr"֓2; =4q1QPM^x5dQy =Ň/hLڹ\vABnzd=Gi'MN99 ÿ;p[~ ׶D 5{OB1ȅ^7s,hr.yxb4+K,9 6hg4 OxKaYA;m a d-xp~HjpqLmbՖ̂ù}*Xʳ T:ܨVQG9g =6hl^wRCBz</x `;a {KOxj5x!6((qztՓAӠy5…C>uf}f <EB)r_9gj5MPyga5ygBc{#6(:|LA\螻@RDD R N0?U_mCdwMȉJTRpwy& &JҴ`>i(*I7AeWB-EpN9JUqTp 7UqF+Z$0?$/p#a9X6#x\C|qy4UjĖqXG:R7BZ]4zG\M D:8cPE!gQf P?)/hQgZ-_'W t#x#-M-B& z` U04J[B:zozƣ~8P(=>(P^gѠ 4Nqۿp1 HK*)@>H#Jk@-qYCX~A`$ t*ɩiiÑF TQ8B֑oQ{+S w5b P)S5njgCn| G9[mѼbu+Pt7Tl'S uؘJCNI(z$j25r^߻9nv$iU$\ȉ(;,ZpʴO=^\ޣ= <(p.Os Zzj:dQ:Yf~M\A+ OkKvg37(C8bG( !7%`U'|>֯(߻|N9kH'B idBDܰVs l_0y!7$e2f2'i$@1w,3\{fmbq'pj(Bؕ8~,\76&0=2ZF]E0uŷe8aZPv侀¬BXimp>\%Rf S9f~8.mLleDzr-Ew{9xt_؎ (NF/zȳS*M#F&(谧Gb>4r8rV1ٽdit!h0S !Jۣ :8Tը1}Q¦w WAISl=")%+EH9}BsFkeRhp$^U-+r7"^dmh ;i3Yɑ+@P3D/jKWt4gdk͋t,)p.&UU FE凔F/d04*LO|.~rt҆]Ǯe[*pRPKxcrL^=;B:ʐ%Gl.[ܻzp]zUzp2Ua%@_4mtQRx@ajttؔ~C21q z5)`Βs7d焘MW'WڹUR Vv>\ w_l>a$2%AhHgŨTq5P4:NuX3~`+Uخf/ӗ}-`U$S5מ/M7@ qӱWBTTҍf=\bwU[ 67c޵pɍ›&#ԅ!JQ_D|V&r=92KFs6dLkLk$RB%ig;!亩ŋfD uPT=>=>GXNvޞf+\\+1{DWt>?Q–B"O r4Z|N(2Uf0 5PBI-5ݤUW/{T6m*kEJ'T:fXXiWP|-de'N1~U2NAQ oW~jhjІ+S#ڹOݹJΞѶ A%YԔFrѝyJ_$Vj&$J7v+j^ 1e~[ڀg2 ]李A)SazDh1ǧc '%gi7H@B/uΠiTw7B,ȇ3Yl0>n,R,^?Y @E(GrσT6bcpC~Ɋnx3L5?WHKIWGqAD(X#F*]>۳֌%=P0; ģ?k(afH|1~~*M0ܢSUhɕǴ(o]JVHHm;dN'dʻ]dX L>nMrO&~~&kJXEq`L$?߅h> ˷0f$PÐ4V)Ý``D`;S, O b % Ftlv5uBBB5D_"7Wy5?*\"ֽwP_TF7Ϳ1!d}cy SG#o.~mm TUE!E37Cømgѩt`9DJnQS8g[ax(' _WFH~Q>]"" lhS~6dnQJ: `BRB'M {MER3T#6W7%u0oeQr87qÏ.Xr{ 㨊u%ο4$& -˪WmWI\BPYPx?!^(e+$2A=?ϵ։x,?l=geY" @+0i (36 M3Xؓ XG/Pc| L=S_MCT&+ ]BBVR.MIgW:]N TZ?NQ4h>1"Fr;# N/Sdl Z7>Bp )[O>)ysk1~TY᷒2No ))8E/ Qc3zV>Dc&05{X8I pci{fI>ݿ`5X-{C5No^׉W*ߤz'@ŷV8q G$-N-B%l5EI!`F' ;S//ZpS:!ov*@MJp^_Ve9c(`%&~{ 0 Zj ֙uO#l](x&\LDPylbN?^fH x#ipJ#c 2\"B4w&[QJ@&g_͌<52x 0#}:KB#<:r{+? ,, (JBb8>2lfF@jY$4 Lvw0}!!Q G݈Ur.@/{56zߥj/Yb%Nȵ"^}ONHM1H҉W*rg=8fh|GIP"M܄l0K_vq. ^5W$8x7t&gKmXɍ7  k&l7OO0χоS>qfXZKCDџ=uvyNu)''%ps^HC9Ť .(`9\*^J#7h'>2)l!w !FXm?RO ^2 |_.1˪͢ީzRET+OrBH>lUяiwpac !ك/_!4޷lN=z/7[~胺Ll+'*u'i{ϧLkEk1y(?,4BZյo|TYW(`joeOHz-L=hݎ _(ڨZAj\C$[ܦLc B/\p!&64*~Fa{B V֔RoXa~Pj'/-6]R I$b Yt[#j6d>trj>xk7nf73INo!V}Wս@w05,RPΘ%ifdV-GDa~&av1d6ae~;` `!67]"Ŝ r_cG}FUK Nj֫ >Wie!vҮb#B=s?. kحS/;}2G܏t75jQY6eT S3/!)9|wja*oB8P )XЌ-J"GB p)R p1s/ ٶ"5B@*g']GaJLQ]+۠!/ 3y+DʂP%幫S7{>4@jn'EJr zm~j&}Aid yl7_TDFO \J8dϋ8yZ6G9eG\.߽RCSԊG=4x0OӱLxC-#4;a>h`ɧ)Mw6 2V>?4z^ܒxab3vlN^%yCM"¹7!3Co3\MmST7je=v c9ȈdY{9?RæL9V0,hk'5{Q-RoHˁfTx>v- ĩpLQD6TEMgoO{SLar`}h5χj_^D }8EZv5j8R"4{VA\6`>r$~~ = H7=ޥ`>+?n9͵B0>Z^ ɄV2 C]$ehLFK$<[AkAFfx2\g r< SՂmgW_Sb"םj35š L4LjEl_b+ h\L_ ;59aֺ鲡D2N2la[Or3ImQ5/ 97xL $tH{],ԹWfS2D1VDDv3>ؚ~j]Y>.u@qwZڧL:8gAyA2E8'_Ͷc\N@ZGHB2@,nRPUp{伖5ZKq{:VӋ?dst}Po&C ¶u  _+"w:%xw‚u_H=|fIoH Σb,S`_lvHD>ljt[XesJ/ooVөyv#{Q8y 9P6@X1i4$a\qc1n5Ћ?OwQVɕ5dc,+,0}m•oi&az{zCY׺TMHj (/a*GqwXVhAtѣp6AEN(HF[N>psq5rAKԯ} c4*&9^XF wKjv|1*e`KQ0y[܃ L'yb'tµѯή{ p 9"([VΘgDw =!mNT|E~h/*Ùs**TL=o.$12@<wB/`#B B*HiTE7NkDRq<W4g_G)t풨xF#y El0HVƭ ?oUBGHd,*S'6Bӌ? o!X\\pP ګH}WOw@tc81HKxjeL xuLenZϷAN1=eoqN#l\qٯȯ p l΂c1<^,uDgkE9٬骝JIBAʹIX}>^ [!23T9hGAKzGjR8f*~wesO-hn*?n+|;bX:[B#m6y n~͞ŁQD?rjڏT d+9lnbNG? wsx^Vm:$"m:WS֝S| ڸ4 k D$l ub (kSceBShA- N57eT弃E8"ү* fT= /jy(TxN6[1(o0Ɖ vܬ@AMK= ΏdؿDu^œO']UAk9w.F+d8hy]Gc4KL L_+#fb#En2h]^:زX.]:6cDgzS Rþ+?;-+C*pg'G]D9_(^$MEP3"/Ro^8)j?U~9n1rXN7;BtT!{}j3  䟱ezAP'*``g"S)ts|,W2K4gJm5-Z^u T7W8lޥC#{U%鷺P&;3XgmU4:7HOK ,+;h NtyXkxރ(Pk@de|0LZ<nsɞ%(N{6ՎpfT*( 4.6pO|V_eP7PI 92H `8nbĵE|6Х # g SH~M5 ӔmIkQ;08]k6 yp8}dB.5Q?~$PP \h2 YQWIsܷa#L' (S"∐.SOi-ё"qJ ҉D"vZ*N!Od+ !E7<x4EzwQ-Jߺl_%7#F:a [;'*Vw}U{j]哽 Bpa%HԧpS1Kg>.}^m86k`űI#q!+E'@dѢ4v5 ʥf(X3~=;'Q╸i{^"Ov"& [q\z8,(C, |2ۑq{Ni_t%bNx؎>ŀ`cR$El (F) @ 7[:&MOpmL鷁vVCnf֬m Х _kvлTW C =LP%M k END,3XTv N PHEq ,cP)8QN ު[w) ޸o]Ë>J(yQ:"&}kmQ\zKjb^zC|쓨 )owR,YOf:CHx+KapiEsr mRKSRጋNC-Gˋ~f=FnZ3]Hu y21PNdTL%dSx(ApaZw-W\R#ِrx?Vܱ&?̌uA)sgϒ*$XzWt~D -#bHdx3΃4CH`& z~tK*F$nRGRNdڹHpڮ[.zQ90o$ [ rXu!$ac~^k@XL/$n3xEeCg<ۈ#<[zÄJ$ wZDgeM^Ͼ{3Z1ޔ閙H iIrۖ U. E]C8@[z0g|JAqۗJd,#Rl!T F}ټNw_d',P[+e,3t̯>@1G͛sO/eXA /;f:]w弖M5[Vy68c|1 ^-;D8LJ&+q" 눐1mE*QveSi}+.່:;*s39v/0tk_!q) 0~?NLtHҥ+-8U:N^*w.wŁ+AcE{zߏ;VCp:%my[oZ(Mݙmŭ48vZYׂGj|{\>\Ng#xD^6?^QH(ۉtko2i(fcBϒف[Y@"]HS"jٌ:x,dPX0e ߷J@H֎%Hp4" A+7sEUVb l⫇:Cxx+ᆎ#=03%IIN|ق}WMTR)hX|f5!xhGٳUw/mD Jl]8~E 30f;8x!H"4[VN;s wDKp IO*Hh,n|F|n$oE<"7CEڲ?20ܯ4'暇rOs29W(ia%qǧd \O?+fJ@2$y}eVDvA$~B*\۶<hư}y(dֹ&j5B\ 錵)ԽBj'_ N;{ϪŊK(-|iЕօ^gvV!?}dRE̗6V=!k DLL1С^&kH:oHp^\޸ZBIDJl|n|9/pK>{ !>i`}Ff+YBccw}A0o=$2\&%6?3ܙWr};VoUn@1i' DVeR! 9D\1ũJ~2k6 8toyUQɠ^ $G_xΊsK<[-͊М(7Mdu7lu;X LNTNZɗ&U:wDK:+mgcۨR2J\3hXVEHaD>Б\noUbnX[g~0Py"Ƅ{L|8cE[ؒ*&^ Z^r m%߹ kg!짋?>r_QRސǎ,5 ƶLEȌ"bVP2qۛk5İV%3HPbMḐr.8RA#30>G9J|㴙Ր Tl!_>8jRS& ^jXRcG͵c~N1㾑Ҟ͇+K B9^i*_tpUN2]îB=h3=@#h_iTk'ʫA)@(bG+- ,eʮ OHp Iɰ ~c`PMNʞBX x0֍-dIEcٖ4Em+bbqPUWEt*E)x$=@74!,4VwO:^m_{H`zbڵ l"~K 0K[3twn#?W_mdMﲋBV%Z c gz< nbٹ+*`e{p󱾙L4El01*xP ӴMU @@`*w.OJ;h 9XiT3^QB@~ E89[UPDIAy)XNT?m#eńqK_\paw`VymLU|DM}:WkBd@o9bICʯV򟥔4.hS5pz-OcJFv`Zzi.x8(c Fݭ`木 ; <"Kش`{-s:X'fntNBCa_?`;#<%mbTf}_g?"5Aۏn4ٚ/*|LE=rU3uG#n{ЅA<D?X6X,ڇBb"Zj(u'ӦZYH@<1Rֿݵ_[ڷ@)j}%-+P#{=SU:5ɗq:W5ӂǧ4VF1ֹ! K9'EŷݷuU%b=tP%awOOjp~t\x$Z0ՉB]Kz l{3JMŏ݂Oc<.;㒡}d?aqZ({h.E#a27@z'>L!3yn,!Mbcvv(If;]ѡˤKiSw5s&#fUa&rl^sMM75a}P{yhky gT:ns :4ExnzOQG~,vpr._Dk HvC?VwXП+WJ>2DU<5FI~ 3 lb5ƍDNQ*u^Y#~g̰Aߍ Uz{XO.6 02Ȳ[ lh3P\}Ӱ܇>Wh3-PA0k'Pl j+vEFbZJ&pj*=\ t+&v/~Pmy6N‚RIo  oE\Nm5>@I;z'\s c g0Ƿ S[Fc6 k$!k_T<ߩ]Q[TDn3MN| G0&EboݺK=`Qñx.}L.j2ۿH}lXg>}5yiƬ. !4j/Xb:dmeC1E*lɬes/A^~d9Y/RNth$]x~fD*g@X0u='ԀvW].FQ)Hj[[)BxIR1;иZOaX?wo?qWx?[$@ ۣzbއe*#g^^MI[`{0X4,fߢ$viAeN\% ؐRarO]3d&0@ T[[ͩ'6꘏#XRXdS_ 6†NA\z\Aj++jY7I3E)x_b934J> +{rl<ɞ$?rUu$znLfEIJz ;T {2HjdXl("5E_R NlQKQNpG{yޏm]^7ه#9 Wu`l A,_/6d8rhx/mH x0vKpCQ%nQx" ã{G,vY=U)$;PY: q|j,29} HXqN#KX3}uY{QHQ9`i'!gNt ~?$l%~aj9m.MNsϲ1Xe)ށ)[\նT!~Q@-)vYW}ǎ7rq$wmKvBmO1|djk |{yXwJ*2Yj&oz'5C R4< MWr-\ $#0F3l4 bQR,%{ cYYΏ0HYk؉p;DɌ ZPD=1p ]"Yt,pnj9ABtcטyp_dTk=(9BXXtyJb^5+^Lxzd)Fkl pA`pu#Mr8x \l}c-( -4Ft V P/-:K-Tf7N’/RwRD0W0'hvrMߢSL$ӫ(v KI2{7j(/'~D7K^Ħ9sYFkGd?B׊b GH|JlAEqUTߌuζT떱30QcBqW=J49c_@U+UH?(YeXFCb^ \ =gGa$KpL?\%~5UG>D%<1VFZ$K(QV^jfl1Flt[M#l>%wuj=! yzX v%¨x0)W^:E?4&FHKJI6I_c{{T,챹┄qQ3(à+PS, G⓻S^xlΦ`ғRi 6gM"p %OS<4ԔMoDF,a]"B#W2?4UD+w_(>˼L۫VrYB7<]D?h2ՐVτVcyko`]EظaC~2Dh 3a6טڪX]Ī%d OrQfYІe2%*M᦬}*#)U} gF[{^Xkqb,"/[3n'sY2h sL6𭠇408/R(}m*`wJOF;;I~(USJ#&Yh1y0'&ƧubNBݽI_s ɰ˩q-Fr#`Uz8j?ukbO-RzՉFK&QZ+cӂȓ| {}#7` <ˆ "Ys`.? U!?8`\J**{z,ۯ `- .zW)IWR ɈFlֆ v"fs0h[صJ/IŒan򌾱}%o_#k+:~6q6 8GA;ݒyyt]jzu~sdֳ[E U_U8t#Woߋh b@Uv(c\0Pj[̷S8~3+Fe*j\p mu.h̚HKMXXݴ"Im2ԩ$ba]+C1ݴ1R7T)m8o$fm,I*GɽR{9XT h6rGoHV%@y^wOM☝9єj{N8IP߬)h@#-I+]_i't*\;;xBm<L*,V/3&ع|ǂRgXkxцwXG`](JUe<*ƅ2:`ߒyb 6Gס4 >7]X+t%PtP.խ8$r(gYםBAbŢވ{ZdhĻ\nUZK(H4Ș,\sШ(9f<6VVR_%@4ĵӪO-&<֔3E\M7䋁(~ggSا!&<~=usoc<#0C:8)LIS-_ut]Nn)Lyhl1L yͬƇBJEͮpiI_33bpŰ6]V`a=JiD﵍QE0\g@eƺ@>.1n䁕B=𹉧i\郪579r?*at>`Am@iͷ<.AQ3xh?[T ޴v`DVDx?C V≱{#(*}q' eCWQUr2Grz9kmP_K0^gdx JfV\֟1E|KhϤNPe N8iwydBIw 54]}d)e$@nM+Ew8< h{Exm efd c %5Y7gEv̯u^`Ht5g֜\SL8<Ccu}tA.]-9zp:9W7J3^2VU6K!tH C# 4XM? \`p}#=U<(t^E*ٟ vEy)[x72]>C=9i:xp37 \gs=F| ߾]6CQ%5C0i,j*}lu`j]+Ͻ ^3?2YN=PeD~6B Yٸ6EW'OD׳UxCdVFՁd}3>DyIw5!7>jwS+\/0±.Plhrɭj؃?Nh$YՖ ?* 0Oۭ*G,)k1cO^YtdEy8梋CJUx^~Tz[M/E):gC'΅-hVF%b5GJjն(ޑzƩ2 q>4 0޵ZbBg*]iAeD~HrlTiʅCnAJl%ibN/B"!ekٸPG/5\E볹#@G܎:cYga'MXS>] (z MUYNotW>o=YI55Qx҅z6J#@? 5|8_4cj4!2c{ }eRǿ XmGu~S8YI71Zzg'qبM9©Zxl2gIkq<ɝ:mIatz q]9\Gt 'jDt_ ֹ"mVx![Bx&;qңfh 2>q\guwmA$" WkO-!:e~N)Iu!6@a޽T^4e捶vL  m I9D]l6j0NXmUp`^5.6 &lC=(+_ V)t5>j Y͖;S |{\5N~V""+eibX͸Aa._Gi8I o ,L\X.J2c]ee$1 r s}TzPc8plU Nkq!Ga nd6=XiZ*+Qz`tD1e XNZф %%ogeOL{Xx(u2bwt*/#0==dZ$xeW3,빰3dժ Xg:[az>8QeƑ^~9!c~ WQVZz69-@$Z-h۩,y䦞k|^~7%OMf|05@jkYX:E)۵uN~-e&!$"+D=; d1B.27I8 C{ rVDNԪEnpwi뾟4;=ҚYWH_ʛ\w ЫyJet>08Բ/^h{-ѱZ? fhIm Kp/xAzou\z*OxB>64b AWds>][>BPa%9wRΡ.6ۊ9U:\8\Cwmr=HoTTQ2 TaDa?M,r,!M-ڋr|'p}ӕ7^ d;LIJ4>1eӄz|JqR)Cugz  VJ(2) *Lk&ZY @G1TA3xHS(E`S ҦJ*YEXŕCi/|MaBpSpQ=m]ܡe'q)C*2ŔTAl&'Rc/r:fؔtBLzB(ړu7'SaгШxߒHոK`E^-w%Zԥhinsb)?W׫B[Q8!Xa|"\##%6ɓ_Z\N۸ͮŔljJ'zU wWA1DN rj>X3m9L4eT.@ZHlڃ#C(`>t;;undQEl#@?껾j-2z^I;vG\X[!N?yR%0"}!3>Jy8w֡ܖNI7NR3\ qS -u٢ѭ}?Ya ^N!o^! P0(AL>$$םI𝪫; OP2ƿ@]0C][wA^CECD7c-,QCwJ-dϯJj$e }:澰zHm^v eM5&]lP,fzA`7,cs>Q. Or(EgvvVT2Mt3qA: B.- :YKLOQMmUx~gqojɢޥTyvܳkyj?RE%Uk%ӹs2 5B$Uar8oΉWVw+f\| fO {m4wd4ߖ7S-V!vxݪfd 5EGʸ˽γWe 6(8kJ"/GUA!oK<#|(]HGsDyFYİ%AGE >rh^<~ފeo_8t)\gH\THAZ۫j5'gϊD[FY)F3oO[wdp-qúBO]5(d(e,6Vѕ"WƙӤԞǢZλ(s2vL- mk7uZB*ʕ&װnVU:ҀX"\Og,&#yXklZ6yW_܂)?g;BͮYCʅHw^M:pߣRWS8T7T:;%q<A0hQr6bͱKvj?! <.v ^ -N7Zq];] %c l-1G!  JWdԥ=%&5|@t &opI~ ,fkwǀpŞlL(ڌ|40 'xOij|S Lu8%`MRbs\c@cѺYOb 9ۄ :8Т`!b;͸07t)N9ik}`ާ!"#BuBе&K~jZHpaue ইW%uB''$ɠ23 H1̢|ӡ:S}dta#|(U$\̼S="5YˍdK@o,83x: ,d{W/L]}|aR4qCm^Oc[1=zÎxx)?sPG)0]EY*8b3=ꨲ&,IhWŌZՑgΛd5]2J ulOtG''y2T9~.={|25ygRxu,)%"#aN6Qk }d7dKp"h@WE-ДՄag|I iN1Cn^ֵpxq>_S7YQnoӍ9 B5%S|oYr~_EC*!+F ?A-rՒYr<o{9 58faZG-B/?Bۜ>1"J}*776ϙlm)u6b s) q|΀g2rW/* o]-vKZûU)mE7mޘJ@ZXM| ".͗Ⱥ-]dXj9,8[ 4|/n`ՑҦgku}xW-,~ROPW/Ąp*' RЂSbyO u. ,"PX-#~\Y $e"sKH%>!_'J|Id7P~QFW?noY1ݚ2&2p+F`'+8jr 9 <;J$FIB!c8 DGpuǹ8-×ڝ~&Ot^1 TRt݈|:C zD=xБWX"j(^l^t"º[lXĘ`qd5#ìr/S*JOf0:ip_`qH""0} jq)FDy[e"X :Y&1c&DD-;_j"O7kO :~FRFyRȘq`=9l E@zؔ;Ƽ (-:eN֔Fn{/ 6 ^HptW{_]6E5^XuCx}jъ][\_ij=נZZlСkmqMhE͏><ࣼZ[[t@[J7]cD ԬՂ vMjnD a3TW <~/Of)˺:]a6Qww^K"W|[>u0RVo ]*nʘ3Wv>DLzZDB ]7_5c{cblU(]/?(.,wҕ(Ux}o伜^Woi ʄ9ʇlsca("' SB.bL=)c'#MZ2Bi'VB3k"[e̦&u.tp>~!ƈ_+T Weh_o'TG.c QW-o͔n;5\ JiG]uA5g~pZ# {B$f{#eFly-Lyږ+ڬŵLFvehX(ۢaljKEO2a;1iY @i3g@@F,cAUO SݨSjgtO^`!JGDgLl3}}0`" }'핖Xw7`ئwe_juW)pIQ)9=-A I٩:z:蜘N"y-ކ-$,ЕÇH1ԬP_ȯ cpzMT2GptUc*yaYPR.њJj?Kjw'xs1|ǎ3?GgA`b ^>f0gd-`54X)>`H >LM4Y6!i"JL yS;?%U:9iJ/2WET~)&:xsnQ[Y SFۿ4S˕_=)Qcx9zkdԊo&W&)͎J/II/ˢ9֊x%OuNo"Վ_ed0è%1ל&:eebʑ0+w;?ΕR2Fvğ1C_CP1Z4 !>Gx6=ݥfD[@L i ")WJ k)zGQEazL_O G>2l~MF>s԰<;XS7c;gL/\(.xFAHG(=V(ZLhݾ[ ]Z%e3%lb5=^3+rn2: ETc>P)˕K[LDMtf? :K+0|RTW@W;T6$+HqNqm4TAMz2FBq; x?UKNorTXl Q3Ċ&1oѸ.+DH8!i[/B&hO'oD%d{{ݣx.rq(䮂SZh JSx'/zɑEGJQM粀vmÚ~UbD:8s[nnک0V"xde`YL >}BGͿz\0A9?' 8 :Ȍo.n¹RӃRTh\[A{&Y toިi͎9{Z-W{{@o81Z `7yfȍ o7/uVE\BK ]mfo>Ϙ/pE&7=Z߬'vN[ݩ'hSި^6'[`#i-t+6I o0f{^ R"7~Y VWq|h9a_{`ε3=);nL i/|!P\M=@-oY^.(k >0.ڥs ˝Ҹ %BHn/ kF@*[ԡe8`jLnCxe'ADZRqvV.FӪMFDc1z)0HRٴ{fc%Mak)uhv=`[w- .:s/Y{(2izR_ӆDN](_|08j:VIF#2WѮ; +`2*b N˨ Ĵm]yWIck5A =x6>sjYKx̑AIYr.`9B4 8d#>Dl~- 8&CFՇ뉤@ vߒdhO\͵s˙l].Ƙ{xI*5pV"sc5V21 ܁$K?7y#Dj<*ɳx$k%;ّ3r{I/FxT!ѽY/8 Lb"RVMπ4g_BѰ/h;i(? b.`B\gWg<מztwa=;@h"}Z>7`؁+\Vt*rv~b[3oľklbB"cߦ!4 B?ĹU[Z^^ Ͽ]Ɇh}\TYkF. )s?Ad+Es!&S7#؀),FY]FŒ{632|] ή%O t1C|J1fAZw"ɋcW k"b"4:tVު)A?f3Ii'{e00'аu0eܪp91NKɣ͙/^ X^< HŁ-g8d0+#J 52W ?YLjPz%]<8l?Z0:: 6qm<8@_=$ʄm~w=36a^dn(Wi.HW~&U7׉PTk=JTtJ? D.tK Rb|E$,ƾo6!K~xi%]ؑFReU(==?%vlx'GZ۫d>%tm^a:W(P>{5dφ5kMPjy2:*Fmb Ck?,m{{RLc/4Z#=pgV3Y Q=R /m.lMW^ 5kym'ixNmox5ɟC|P"g+1$!%kp#Bڹѵ< ec,rRR'6Zq}U\Ae|W>Twᅧ:յٙJ7x${# KՆ@OhSM@B p}3 kh9U {CgyMzye%@̛+gK_Z-S⣑6ڮ18U]hG,K!w 1B2^;vh`#n+4{K(2Sizy7s?Ӣَ3gA{~ kq_Os,S[6I5-2Z?dt3b7pPϦ3uvOT-ⶉlQQՄB qBpiˋv>`Xe߇AF-tjN%_יYdg_R< l|ǥ:pd}HP"!Ewr{g0CR|u>:Bj_K.G#02,nGeUgfyH6}t-q9cاOy-,YdHvD%t-(xTGW⯲ZluO־+8vDELçtTWY*[V 9vғ[ZnzxoLE 6Ơ2{_ށASUO!_Tt9yucKqVRp3#VO\'JPizTw4GQ*)mb=?jIgˆuZŲr& .*sJg]-pUM-sa}yB~40 r~`=W/--艆f:W$ Ppeo(S}P#5KЖqyY3\ڥX1N#FASM]\Z ͼ"_#A6QQF;G)6כ[1*KMڙ]|NA 3&S0:Υ]"FH}v{|LoK?2;] 5RfcN~IQF7e,!Z};IҴ}^ N·q4wN/v@o8irV)_CNOdˢs qdy ^:B=C;? LV~WoI'mw3*=mӵ ل]RXgWc?͟rI5nMiE^jxv. UwrVܻ,UTBL|fL:{V=%| 6`E/7}-J_X(APʏF@,Yo$:#C@u-QN>>Om@5kCcߦ`f(0`G^ dQƢ7lܶo(+nZob@.6I^Q3>w:,ųo[~;3f)fhV.=h'}ʲA1Sбz/)t8j8ݛJGŝNh![wLULzZ`C&aE 0,CZ%ʟeT_'m<$. [ck:d: V5Y>ʇgej)#ָ+ ]G5Vhy-n94"Mt ep7h&H}EB"pM!OQmz>F鲈F:9Ka*ؖNˋbKVnuc svL4[!xm!YM v˞-m݊qN"P]j3f'~^4|d`)$v5{fٚ1=ɋT.AĆ{׾hX(pTl1jܺ? QrɄBo >!Ke^ϓCbcCK0"?+?D )UzеQ.iZa9/%IĆ?Zk!'y'&e-& dbGG i 1ֽa:6ݴ~$ԧ~0.VaC=%TF,p?tp\}t ԭ4ܵ=$`tTSI`8nD \4"1زHtor/+՜*_͇ν?΍55v  rIV )^\6R٫iAU[;)3lN5K鿩w!1ʤ? CZ(썯a4ۗ I4TWkgkhh̿ʳ *._ʦYb3(mP-X<E<0J-؏vr}$&IPHF&Dd"x2N5#U\ʵ#(bPznq>1hc@#7(}OUJFR nKa&穠Vh{e}4'y$ V9˕:qݾG [ջ}YpXG @%M0])jQ`fB6rZ]QK!, X&# hK>~7Z=7g9>&o%kC- ~xff-_@ؓ8QLvP 'k*YPl2!9G巡m Q2p ^VEѹaPF^@R!Ną+WR3ٴsSH 5!RF;!.f벉zՙ]_Ӿ-u7 k9F^?+y:U}~og-#U<4('ɲ*9߲}MzⳚ$l[g&jeN/32۵ZG3 (s0c0`.nSq ٨hbrשYjq.;`΂257BFd5JQWN>$#ƤkKWa:J!րG`JDt5Ľ& ñ+Wʶ`[H!r)q wڠ5f۾cC W^׀^S XF"`8y8;ݎkڏщXNW+?_mݨN80/uP>p3gJ'vrLfu[a_[[u ƒoTbqQ.\YŠeX&Dn/nCaBR_5OMiuh xX}Y.?0@0Q=f^ 0z$.Bż$ɶki7]R+d&P˕\!~K3kK!\70_-v V'2,߫xyeaV fR "5U~䅃oTWV?5iþ_wWqIeJo,Zntjnfh({ޣeWN{ )~ .?B9WйBAHzYK @eiNPzO3!uK@7"hF>_):z^sD)7!H A5TRh\ةU0j]*&{ͻ\Fqɱ _ D/bX 瓹Ve#̋ \BP69q K2BSy.w a6RvB7waGĸUW !hKb91 y֭AQO'Eqfr\L|Yہ?0zk(br _so|󴘖` %Z8Yjb'm?;u|l3Y"mwy9W"܉7}my=ikMǜ(Ӑbo7Em?|#I^(>$iҾ9+ 9(!۹ep鵕ǹv ]ҕi˪WF_åߎ$XI&aZGx̄N;D5o`>ZW8$[BRz}Ut<1 M OʵNP_HsF\7f:yxN hޙ(SVd$x{9:O $Eï9tXBM{;oF qBLw7tkef QcIY*kiI$ 3kZ~R0SkM]ByX >z7\vjY1 nʳnG_rE@nZ5huD hv-FxL=U#hYv8?~t,KX\@C-,(i24JrA nlK =]vla"qN, [q[.-9~k!h*:f.2|\bD7g!^ T g+ _kN;EӆTZfz7M%q#N—ܼ.Km'& Fݗ@<_Mu])%:2ێ  3d˸pEixh,CԠѥFb.ACYY$HE<obi8A iAV6AV~3_5Dg14|?z`&x$8eLȎe~N . T[~$ȈcGA7뀻f,7iĺO۽j:-L"Kj  +dC' .d9;Zl4ka]}a=}$ 7g:4Qzyڣǎ墽2&I|NտXɄXA<+tET 1y:Lf+g.߆h;.ޒBKWߒ\mZ?qFDT\ʜF8 K~ {F^*ThǗɔ{ Kd Ʀ2xp[/6v+u ROOsk@l[t[=-q׷1Κic *}K6VW7"p1UCby ĸjJvXAr+|"e}`XCn\K*͂|XG^||DZٵ^$W T) Nk p bLA|+Rݽk16HS+9Kď$*ي*U)ѐGZn@~*K?b?~N);ٚ ZC=\H>SzJ&aCnmq|jɶk_{ XP},b&Op12a.OP6R1{ Yi8Q f g}R h Rxp$T3z'-2J{gs΋$ #Ȉw/Ɇxރ̥`Yv}!X9u&h6EdJ#MD͑o h\^WxՒ6WSwkB'n܂>@ cial[ͤܙiz;ph-:eR#dU(4z? Єj\5K!kU<H'hI0PK=`0%y7e|}uLlƉtfJ o&Ԓ:l voo1W^,GYԕݗ{EUl(d)d4˜qaQ=,mk/UBdY` 㿈j xjz{ѴȝGC_֩]U` Dy",b)ӝt+D%hRBt[T௛! F\XeU IQU'଀1d}z`mΨĴ2ִ]oJԊͥv#+D/;MaZh3f/-EȌ*9Y-0m':2CcT4,)YL\ =[DT]++cw@J%ޱ3%0gwޒQleK9M @[!z ,: ,EWP1>\cjˌp(3!6\@rNt_kg\MKu'$xuKٺ͚Rs.PkJ,5L(jJ0Z3:Y"tΜtlXQ̔<p0R$iG} iN— տm@,}/\dpgx2aA3:4?hQ8Rʧ]MBuw oE!6ʠIv .i?:YǵCБoHJgBR2g5w5?2ˈLrwe81i~&$ӈDD 8.E_9k KWN/UΡ>lIVvFK,X7DH ^LN,ATѴh A@}!iEgn39ր5ڀ&lT#^ 7 i쫕pwo&ra>e4u1%.D}5궽TmKI~T,_NuJ@DsNKW2!|( w8A6} (YƒDӨUnoog/_b1*J؂8C 0²:am-B,vW93`Y3iE㎪3¥,})<~KI*O4,f<=ESx%$lC]r#T@O{96`Nɶhz} rp}9mJcj)/ޏK' O+MzO@\ʏX~ :k0t6\*3">aVԁ 6/Fn_UmZLܘgh *N SssH_5fS|oS1v6f?͉B`Q0D|^,d8A7fNL Q^[\$nD\:V| v$ا,I1p&|h^:[sUͧɏQ=V%2Tɒ|&?sR.1siؾr 1*d.%?G+iKpІg (iE12^u~zIqjK^X&Fζ טZ| u( ==bdMt8tpOpQl|jiD_fog)B6b|[2BկefV3%{}&RknK@R܂|);*ג],4V瀩;*^Z1d8 =?+#8J#p7vek ]*כ /ߑӬQu0}CAުc{zԻ"_ϬA^;S[tr,jҁ$` "2ڋ>vr5sWmF9MoN"sgE9u|\航خ^Ӧԉ6(oos %j#=h8T_ݫ8u˟\vƮM2)]l:LMؑV<4vR6}vߏ<=>h|IM%]W7o$3F.Q{gJ 3Pq% ;Yբa;7]+0o{8jq3IWlLpooh Aq~rqTvLp󔼳oDtP)uG6&phC6C@ph~גf*\ۜ¢UY1x>w%\;|Y\Q+ {3ҫO+hm K]vKg4kKOl\!3$N1 7.9g&-0DpeA]oBۻc(n7=U{EUKq}4"_l'JM8" -J-TMHp!⺩oglD1uZ{aяnځw=A%ҁjɏq}=tu8u3!t~3(Mԣ ysLB?,ᩲv'v7/MraۘE]unKozoε'2Sf.wYA15|؛0qCJ8'vA[IMXyS4IѾ4lW沣`$`6~ HcHI1+{JH7(۹"? ɽ*|eI[ ex; Ul ot;2ܨ8UNMyRi Bgu'NgU JY) R\x6ewQ_q?}s]+[QոTs&Z3PKH~R\4؃b: c-٫KET4Fl|]i%DcNsCY q*cb,P?)T!چM%ae |rH[9.۟9`pIRtQ$%T.符pt)u͠n[tPirPX!W@/=@׎GOa`Wednk9׈7ʀ2PP?N3>.%{A;fJs$OK8L~~dJ䪋ׯtjګm]( "`)x1D+sZDVy~w%,okr0Mqwe3DƻgvO3L5 Mo/Bخ:0u_5;D31nsW;bjl\L{ .ӯ-HnOW W;liiEJo Bau^㕢XJe Mc=oli5X% ‚Jk5mN%ܴ8 \̄֯wFdpD\XSiNF/n'겈M zM T$XpR̩^ɽŝ[xowIqh%XXy:h*z1EEstf71 ڞ\4Q^NMmtU֫1D 0)$}ǝlCq4.mDF܁ (wPN8P/xTPrP (U9ъOF"kD]*wmh Hs#z܇en%PtO!*ʜpv:M㫵]_)- B42>'V} aDz檶舴-MoHA+u;OuЎرL+Vw,)}H4b:e9|9|\&V]^e&QD]{k`F~M2Э1g]HܚDF*Ƃ)@}8p$ iK,S\`vS#ڬ29V}ft+ =.,<7*ވ۞ #Jw& '%N}\u[YU?j#ٕ/a HK9~oE:l0ZšAp3e:z[ R<2W1Ǖ\:BOqn,|F"!.T0ؘA,NJ)y}Zf4B2ct)}@ڐdCZ8)1OIWCh/S+>e6 lBxm}`RL#%4*\g5[9s8;Sdu UBAdY8^es/SF !m֫5%&Aq=4uDˣ)Fx3#:0Ԁ@=j8xA!:B KP]%  \~2v/x~``>Blb7ZIo1+5)Yr54 3G56J 2iSG =f_?=215eHGP鬕;0cIգK\h㩚-;"d q:iyĉAr)g yA&Tլ`deH̏T7q(.Lcv` W (0 !YlýN[Tr;i>\A@wa EGk4d 㱷_>(klH8WIppiʮF0Cw3@߷3#!NƾRc#4#ę,BcpFY  $]@P.b2n'ijLk t ʟdP+@$ ~xljt&m8{_G^/|&hp.<2Ino>zua.B:33(8;S 8}qݿA]O\Yw, ~mjɗ"%M,YI%š|lsWsh"; T'/Uا]n'm~FW;ym7q&9՜CzEtA8{lkR^f .-F\؍@ 8V@Y6֊:qeKyp-p;UM$ @30G(:>J_ Czpf!Ddj6L+V8{EJ U_[p|wԚ8 S!1*ӻkۜĩ,H/Jуtv㽚hGQKUUI\*&BL7`DIaߙg/DTȊYP!5,Ԁh~ O gd_={NãTSL(Z C;Ql kHnzV6 0:=a9ķS^bH?A! 9`sp "R/OOjK 6eܦJ{Pb<̿KfVpph jl;T;z"_aӓ?ѯacka5՗mU6;Xr]5Wwxu$.Nw$'_(5Fs4S9۬ b% cϞ!a+HݢJYܰs)4=fCx'u3$р,VʯG,pM!Z$nyAIQg|uT)/:!^tPЌ&()`'ƀ7)Cs_j" Qy8%8;.k8w5ρ4S<ɨ9nn&:GfznUg(Fmw}xCQP$*uqQ稅8 h0wtp"C6f/Y}+h3%ej^:t?gʫzjxa3X@ jZ_R)i F-Zso:%,>\\|;CDM[AԜմ).uf:Bk2|n1un hlZJ~ޢASsn{M^MJ%xud*A&-r*:BJp_s壤F?SKȡ4R4M<2`U;^-3_x@Z)YV󸐎KaAWlw=}zh\LcCo^Yةo$ogi5 Ӈ @߆N;l'th 4kwC]iU0ksXOmV!ДTS<&^Ԑ]TUF3,%MZ/g=&sS̃0@rn“.qxQ jڰ$MԟcG^a\PȀCن"HuOĖ W0i),Fu`&u p TR XV!0F]‹29͊Bp݃4)bbLbI1Y99p[) *a3}64Gzᛛ<_LJFXM۾fK?  `gZks&ID LPJ,O"hla,qQ7*/T42?|gȆ\=UtsGeT#{l?*ćV ᨧR" ?I|۶իgH&9@4frpoyg/*;~~kLWFІ lfhz suEwKXթib8WZJ?W=췜wk,)Y'Vԭ&#-OVR":(=Qi5M_qWEm%,rլ\`-*⚸tw ?h9} 7|>p4tmBX.6bp߯xxzS{AP(t!\k'a5ݨ5̬Fk1bǡZlMp׋?їiݿ֛࿦wic ?fZYױ@:|lˏL_H~PV|bTgn>~0|'m#x8%/~LKڶjTk?x4j-Zr},/rr9+j\1ڻtɥ1J"Z # &i@Q-"/9"㓍igGL}<+틑 kQO@M -@hhw$PYQu\5^C."# TSӋtXfT<2@AWvhE97as"?##9c ]3b@#tѶlHfDcXaqIJ5cF_oV 42l䥗AeB !- Xpʫl2ewS6BfЄ&nO>M00 9Ӳ'a5,Q!"K?t_]< z4Ղj:'i\" B?+)Mip G琌Ѡ i=xoJ."/rsvyjZi+#RPDV)CJ+N"d:ZS..W(Ot-D}Wڐ4 &89 ePNq xm Mm@{5D ^g9VSt&l94:"ǐV)> <[Eh38T9_uZ=tМpdKLT@udmvh ܌_=fA%ƽ@tPGgoEUH#ibݢvJ7IF&BkQ{Unzh(oiIX>F >{.@qsˎDꌏzHRo&K.Gcx£_dfu|Qc kX]~Gs;!|}|0Bٱs"D/ ϝe8c 05H}6/J!i1 ApR6/1OfBLde}|}z!LO # 7˕4ӥf[f(PtȢk w] .'_~J[] ~5BvJZv9x[,y]dy3öCT '<͇[vៀxڨh$It-`_Mi}C-eAz@x|# (:D@VVEEsh*l:ubzTo2J'~r|ORo8/[W7i!zkkT'S=xi!t&Y[8G3-V\a ReFfe2;:P3!ο]srnj=hD ՄlߨD-.+ {Rp:vLJQFDξ "&`h!*1gE1`b8FG#r:`+XxCkU`vqJ%}:/Z22M9/S{VΦT L~ai"iޢSCUJ #0 @c {KTLVb-ik=0ܝ*zDe(_o3dܚ GM*4x`|P]X15U|`S7v+-ET׌jP cjc>Z Y$t l%ElMzǟ i|o<=OnCPf/ ڋ?ț`?[FJ-!ցb>IlT؉aLkͤp3̵LEqh#ˉV %*&M}q3E~ŰH>a~מCȼ]WD?3yPʻA|Uaja}x\c^L`Mji;Fl۵ SnkǼPm d .)"Rô4] amݮTFG=nƨeE\ 3Arr[VMsOg<1M[}Τ\Gq/?[Qi@huQ2V: m .3B1v:%6QJ1-6j6Yrz/Fzs4aV\/R)'\OX \I[s%u? -vOoݘ͌ufO#μ?UDÿW!}f]?id \D+X N-Afޔ\9ɠ @`Lj069VFm¿ܼK\/-Ԅbs#|vlYʄQ<wa& Hć1P$N.Xjyt o-jb/u6Iv[Vh[jrQP9Sx!mM1F8gZa^s¯~3Č#U*pdѾ^FxE~BVFGך1z2掙䧩oQ{`V#ba Kn4C*{aS1z_mky[3C3aA+VC*:[* ["/>X$AgD@㶓6~DF)0Nc7-El "_+ck7hI8z7OJ쭯nilxcr3Mt6^RTʋ7bq>J;}MѲU <7R*K0PK;~zR ZVRHF}HK^F';}b'" Y)$XF ly:&4^i  &c'!L^7RxpڨW*Gh *@=kNь<4Vx3خl_ޣ~ 0!KOA,?{0Q2*]NXh,q7O R in$Re=PN6WّZ]+nе\/PѦڳY|& :9v[~. 2LVuXU P{.%K_.vo,E8uδ*(Ly40MYw]D=F G|;QѾ8헵.}%=ѠvDaH[D3d~tE铺\[o{&-1gkmFW3ۛaopB&mKY@!m\E?bkȔ5v&@՗ )/l F,5\ 󦻐 >F2Fe5شJVe&kRv<13}'g[;75Ż{XK^!3,}_G_J|M]t}iGsqm̟*ϻz;|񅫘5)`5 [VZk4kFz;$QPdI^4!!- ݁fUb =s,eꇣ+d|Y#POa@Y)Sߵ}Hvg܈<߼w.=>7>)Nϗ _N&^Nz"WpW})XMl1 6= $*kBYώR/[67,p[">_: 7q.U֠s8+}UflUs7U$W@ifhEOgè6%@"/r^9Pb䕑>_ \Q OdQ<ǝh@k}GQ{ eCA> i' >iKSY%w*E֞Go`6\ċtMjȳ{) n^ %),Υ ы*@_*bwqB&V! (5%RHSq /|8֧P%\v&RnG@b&{I2<-q!hp^%)'߫|弮>N&*Vُh[Yc&Y<$!O7O-l#R<ΛJ:cZ3oUrg)jezqe'<v+bi4KLO;>+T1{p DF,= ,kij|1#sn"kh*6b(x 2pʅom+(F>;#CT)$z+ 2u= 7_CQPlb S Z:ayCmԹPY=N2)SvzR*n2 gRG%bhp~Bɗ:, /J .4:p'msq,ەEJ&.opI6(5 ;+C v(&kgFTZZӞzb D~*̭5>x )#nZg8>1HW`Dk`5Ee)*?WN-oqNƍnx@J9$ +$]qwS1r|h"0qbWfߚbqdc"A Bوp yrca&҇ -%vA=va!beru- YwFOդƠ%iʻ)Q}: vA mO n?2.;q򥤗{(nhkd:XĢ2OGޢtK1s+I :[|^\q{'N 7~ýn2j <{Xzj^%?pW3Rttј" 7(S\* ﴮVe'- rDH̀U49 'O/tSG(y!bC q5]Xb}ZUEؽ"u(Dg5TjG DKQBǵv?"EdL/l| 6ͭ'(bgكVֿ9R_EF_9w}.6vh!PÖjjJcXL^ uVۗ&*%WFT*@0NP5]>ɹmϿognTDꒄr 䎮ꌯX*dcg>a(#2La;q=IXxL,Ŧ!Ęq> :{w{@`uc7޲NEVanĀJWCLl!f zz&/ب. ӤWJSkS'(dᇱթNLn7+֚v[3:(;_eUys-|t#9TEIJmLTE'ַ8= us!`/8hrTFSt|@fE(mdKZ;ebCn bߒu3x>qtc:Hו(w(ĩ2GϪq Ẃ>ͪ޶b%YL 6K!&,GNTve63%gCB-r1~: Ո_XWm۸{>aLևY"=GD7% ^+4xP{E2S=Z'P8ToX:@H@~\(f9ɦ?փ?p.E7Q%<$Q !}@kVh&>~i)g@sV?ۇWCI,gRbY!JlZ ĥ q"zpfxsmtꉨ:- ݏV鿸t k ±2bvTO"nY f\Ʃ?an]*c Cđ`2.gGjw`Q;N@s5KO4`]F¸LWqNE3L^[d$?(VOz#gf h 46qf kLzo86Xs}k2ŖULMjoGsѴJ݋~bZ%P,B92&åBUVi1 S|1 o=#k*PxeU9r=F sK>EYr!3`t]FFYbCH*e[w(X3eKr8 fFI8~Q r!9|_ GwI1VUJSְ)ֱ 'F0MPak ˕_yV&IoAr eHmt1ƣrm!Z?q 2 D~H:cJW懚Zֳn2HKnwD@2ӣm4U2cݿ;d#ؗXXʄ݉m! |1ֻMoz|Z}TAwļo `:-]x(f_nij>?='fVzC_椺#}sٟ>C쮞YW 괔>dE3h>sluLl]p~A?Jز 1z^.,4z] JlIbM\67S:bAXlMlk,O&`L%s8\ h& ~~s)-ʑQ.Ec`)lm"8 w'z*d}ƽhڅ!7>oM%p5# l4ottw$O:HoS$wFursJ FCh<*B6[ԥٰ{—QMC*K6}E~~]izzbAŏd?`%WlK0OTɔ~VLɕ2[hgDpUphuw0H_r3YQkHK]SL<3w/\OĘc`ȟ ߗtE-ҁou>7ӓy+d :Fiw\6K;AD۲]uY*[^avl3{4:(:^F,y++;?S3[~gk %@ *N!Ey[QkqJTz2=yV3ENɦLxHƍ.f_jkqjbAV2D]ZWo@|P('p/ݰ*Zll`V!0{ߦx)(~hf :^=Yx)uŘMFGA*:kH' uK7o srEX~2͟r'\75>|?S̋T]z馩)֘kԿ"Pj<Ҙ}Q2س,3i:p k ,@﫭Y_AwRT LIYa4HVܙkxOc3glFpDc p@  ԰sbcEW@L 8f {HکCxzIQq'Pklr5:jP[?fR^zg:5o'DcjnFR-K[q)6]:ȫ@> @U`l-SGm1" Nl`VRh-6J4:;w$Ah̙ѠNR,DtZtO³)lA4 GSXKit:tId_:N0mjŋc  0 KavI==drF1_ӌ,;9u;ҐG8JU{s_;5/UC( z$s2ͮ~Dr\v@#We)bCb휒(v73] H.{Id ͝lLzdX7(wSZMv5#f]^L-X䴠͑V=ͺM=ܨ7k[X[D;UInjX5^wRIǝ__]YHGFξ/#Cr3[.L"kO||Lj> P Kad~Un$"'}f%*p6oת(Mׅ;n"aӜ`=k뻯I \Ur[a$磟؅(k5&<ަ>4R̎LF4(TӇsnF4=c_0ΰv2 $IPm ܼs-SQ)8:\:`qލ 4XM`p"dو0tf`9%e6919jXn?p(9U~#Bww7}a͡kG~;-Iގsn̯-q0a!1 O@ufX*52\w.4EƖI@$([;IS9,Hb!ĥ+GdM٪om;0`-#x,<<]Cԝ`KP^|Ymw 814BV0 =ȇ+%3jIn'P:qƼXv H]oCu~J^B:3,`M:W:ғ+w:>AÐD,ՓF#[k.fZw0huy-2yRNhT[2r]c[WQS-e%B%eQ5:ߦQb nGMM!!X=ZT ![D:,]1t3MB܌7 &0"Z3}imЁZli>݀T$λ 9HBm@Ni7DYہ'1KDl]۸!WlZ,,eKMX!0Xj}RקT (>o* z'(8?/EmjNB7*h}ns1Jaewc0ݒPnBftDc:ۄ0ҠQi 9\c m#;m̤|4/b߁5?$=;!!i{L hVL="c !'0rMΗ8V3!n\A =#/xIV́*e KHj9un,s֡*yޫBo+a~dADY~N>êZt;%5,&Ūr}Qǘ"J]pPDY c~J#B0a~RvߑW-^4"Q9zSrQseIӉ e "gԾYLa@vx< F{U7t5AywY eI zTD-}E CB(FMFoCu T! 4ӻϓ l}csjx0碯ⵄX5xA;Kf"֑CHۊylNiGqJć( :/)tL 00OKPD,:B4o*cY_-&>_.ߖhlյ^i`ZS0{ `D* ofJgu>S'8iʅ} oXzhBRF1\ٛA) E >~<|?tŮi^PNTљr48VN[i٭t'=){Ӊ0<})`jkBĠ*xwnJ(&.#Ǻ2H&OXNWWG\Is5Ӊ w|;ͳ(Mcȥ@,ha*:*e3c٣z6_ΙX-eW 1H&&š'v]Qc4J< d:6{:Vc}fTT_TT%{\Ht4_/.)FU-¯*>S5 OvCJu*T _Cϧ\čF+w 95 "_ m#kRނhճoG< Rt򷬳bK7FK|C J3ҘP2 Ѧ^\+6w ^6m~w%(i;WsΆRFWQ7q9N'*&v5j-͒YP3 'يUL2t8zbh<|?Ygqx~42&SLgue"z۰QfQjPʥ(9V LVW}e=q>\g#= H$3K$t" o EV>{&0P fE8jwJouȑiA (\*FI`m% rn'1Cq {qZT ۤT8@#*XuQeM@)~pkxN(k_rnil76P&Hfp np@6Y&d)x%_}jAn*쀞u;ul-ح']qGڵ$~[).^X~.N6Մv:Nͪ{ ݑ;|:v[*798nv" :2aAo a%G.Ĺ>FrDK"<'p5DCjtUv1~,}1ļ/hTcjzpĂV.آڱ ;YiW6=*r{HYGBϣi (6;z"ou꟟ȍnWDXɼ: 0JYxS-W+mKYH ; v 7cUB?2ැ 9't߲AOׄ@1\[-9h^j8"M9(nTC| *\u|ҮF jc|¤^C@2o,>8Яo|6F)% O$X )X€Z|c=*WD6%UK*8[jF~to)~~Q_p1 :HMOuh.ss4Q97X?B1*BPځ`;ҧ?.ٰXɄdsE)zit~3{렴>+݀̊]$=]q]}| o47H'W/ KүBrܛNT4dO#V ʄpr16d34ÍcekyiȢ ?@FO&x-oː={ٲ<*Ot-[g#^p^;#LjeS q^/4lĴ%Kpdup[^xzVDGuL6Nɤe&{^?KI Y8j@&/ק3 _imQN߭!5 _ ."3*dweB;!מjߟ:-\X{" RY9$ :?I)!_eÃQO&W2b o qevh kGj x&^_ūuovw8\ X_Ga 4ZVYz ~1/,P Tg&??)l[3@.Wtp0ǔp?.8P:?_djd/-ɡ7NP|s"2tcԘᴸP&o,(a6b/U_#OMF*!YF!hp<\'/vd+I7q|AÊ)V3RMaS"8kef*(E&Xཛྷ]S}Gkǀ\x>}K:FU G5WMc>ƒMW{=ꞻ#k-N.ya :Vž.ŀB7?rS7i8X_njjv~K\Q'lh\%*)]D1Cԯ?lH$+KIx NU03ςmuG?qoxSZ.x7- l˰}Y/~wCM=EJp>ޞZ0c:KcMps{~y3`Z"JX jpwcgTڽ֫k59ٽ׌Q}IฟH'H QQ ]VN6#aԥ\|wQO^XKX:Y?Ӹ@-\]$3~OBe9=-1`f ZWFx_BhbSE2e2KVL ,) nzTbU^'K0c˒*2\vvEv-{4}By(0r:a\&KxTHdCz72QC%,.PvJAX!c烉bv:^ڟ {N2@FM bahseܴ B j&K矯tY8f"{T ™ٔ*3.)2PIӖv$8HSk/+c0b̼~ _ ҧZ$"|6y 2s'k8jVT{,@3 4kh)O|0-PhQҹv-ZvFV-Yg !"sL38o_9.g1DU Od ]3y$3p~:g$$qxY֣M]]< 1_$ x4BPx(/%̌ԟ?qF~:\ǘUY$H6OKe'ی_)ݫi]Ώ 9bh4жXGGsj[.e /N*`,jߤtmxBaV W9&:@8D7;PJ Z9־LC|[4xњA:6^e){c@E͟`Wxs/. Mdm$3 Wr-wCש-]t9n*Q$#l]Ь@UX> 6~Nڿ/`\dM}Q2^)j/"S3uN>ǠFĨ8&f= ?vtJc( O 21^^ WhB?`N6"SbS+LkQ5U7Ӽ~ا)XU$j3מ+R=(-IHϕkM*J8_jqF"0չ7"+)M^極 683IL|N97t>Q+B޻44Rn,^(flr^'wwo@/>W4qp\uv @{8Bl[̓q߀rSPRQ,Bm?҆dd$AC74"vf 'QIlV+Q &7sBiԤ۠qAU)H]ǝRYNεe ! !VP:^gQ.pNW؏Ub㹚g'vA7( d%wXs/MP3xAJC%HȘDkCGwm`tX[z 䈽<( UF7 ca'vyw,0c8I]hA:W\zϪWT k0j/L'@CSf!lzOWf`)f}b擈O>V}qLð~,pOs؅+8r-l3zkM/ Cd@lQj ŇL7/fp%J;!% XHImػ`] <+oa#ײ'6[Jl纉qEGŃA9y0b1!.]:÷78L'ɫ9@-/u*zhLPQN4q,(6NεU>טX|^:SXl Ru~|]^ u+u%W>;SZп0)FnkX+_7_ %|#5|:9k͎_0*X2>!Ij\ Duin˪Wxh *80K"`Ae25,Ucr(79>{H{_NlHPFa hLFZc~o7(Gi`PiAJzszהyq;ɑuXH[C~o Gq ªy"F!:C#Ƿ@9}SZ 婇=tUTЂ_ v +["<}9pYz_wSp m~Dc6[vfDސ3 XKкc ȓe|uHKQt|Ԯ0D&R,hw Ie^`Qi!DCnId?*mj֩t+3[j iapZ1X8aXÚt ә494򯳻ͅZ =ew)℀}SuP&pePWUqʯzȪ;<+,pIKj`( ܪ[\@D`yhoBEG|0W9!j1Xx#nCE~+kGg i7rp^(L^|"f%34DEd~+|}Pd?XQf. dHrӚf522lfٛ6;~q=pQ9[a2WBjT}'_﹟0T>5~Y9S&t7X4na7qV\Ai]4q'xz(SIC{/,zbHiY9&Hv-[:"EIѶ<WT[sE)ح4U_ƙYn; 8GJfί}.<%Mm\]Er)M#@~$?K~/;ΘqQ;h.Zᵇ?CRKlr83>bHX 'ᘧ0C|4!xE?\ q:àȴڂv4pJ5xb"UjY3zx.Opt,)В}dS2iR 7WF0x#[NɄ)_XP%%/[SO}$> >2=@}h@}OE{pO"͙(};[[ [fzi.dXTQ"h"NB,(JJUx\3-ַtܼ zJC t{U<RǶ&RٶdVFt٬PM$u-\~WVy䱘ibz%-B.] #my/6 '\|͑zqkbmY6J_cSy's6~ =Y87XdX5Ɩ#ivY(/U'9u Uo5EebQoO gdy0>ILVw#3ߓ曯fN06v;{?AgvR;Q?~FB&m ,R{Q},wRhex@ښw{ 2(\b@ 8{ L@ڑY-kdd̍F!r1rooI8@ZĦʠE-^vRg9L#_uD;(ٯ8冀A@ol^&Ȩ%)Oݧ_uEBFℂr 6Mr)~1/y_R&JUYJuJU {Sg;g$DWJhCOLrץ~A=a\1E3Dk2{m`x=qFE??0 CiAP@-ͶJdgtX@Vec鯒RvCR~w4 իµc[O%p^Auntw"{+->\M*/дŤE #Sg`4,'FdJ $My`T}H뗥y|DL2/{}ݡ3n?Pc9DD y!iGD_:?4Bs 6 >V\Fږɔtj4+" ݚW4%x!'}bzP1J$tNZ y7Ҧq?p @SΫ@=5 وhXt~ Q=':܈,C~)B[0%&轚g^z7ROƋQ)XI!~y<朳Kwb_—dInvxT@)M8q9aPCs|y.l 5%Qd;ATySɡbD&Y?nDFj̊ ..;&||=;+ J"V yS`=kg k{dp86effc =DTsBm& MϠ` sʼ9i e 0':X9鑆cԬ_?Sǯ Bi S]4('Ϟ8&![A ~k2eèĢT*N6p(_8n?볥H,60#ˊx:R\`^B@ LL "LR(3usNUO(oLhd-bD=jC;8 ;s#yu)x#$~r 82dW1\^, 4 }%Ԅ#WIZr 1½OzZg@wo] 1iОIL?k//Ԓѳܬ`GlJ]kT#\OK c `MIZX,oc^J+;=>8=;+*iYӳq7Xal̺k14=qRgO/jO Ql&۶2ڔk`Cp=Q &.%˒ڌdg+CZAh$ԓr=f1V1Gv 3t}-sa6N#H$Z.[7HgXƊA򊥥o7ORO@R: BlJ.aM2?hT ÔOۚR^L3ӅLdn)ՑP7ϓDfD AѢ>ur emSb1" \?N+sUmKdpŸWu|l0&JPU4Y/aKro s6SI!^6wՈl/&7rM^``FS ߊe#7I7Sw _*jk𧽾i 35yIw.  %"EBݎ[3E)C$R(qCbαHс;]sE\ׁVIby _n3ogO I' v5؍˶ + q]^uS<"Y}\R8Ϋ:i!ݕeDX(e 5Xp9fguuUO%{߫_S*U=BvC13 4r;%Q-C]MiYqC 0Y0Fe_(=lH>#?PO$rr]73g5;np 0dJ`$떕a $x;z[b]MN.'K׽[,\^V/s%Tu<|p*?~df;*ޙہRѼZ4JS6Cd:NJn܇j@f.qJI*Axv>9nz\:.Rs$dxX"2kkh"T7;S>-C44y_T4[ZcX|V*3GnùDGtއy/eMh)Sxh}iه֧ ]&[2_Ub4ҧD״)QADt6( *2<-RMK8_̣FG %d'+fA`ޏ]+D0X`)hDeU?&\BΣ:_ "V/tL$mMH^#%CW-4l7*i΢!+Å򮹒E}ސXbo'Krv$54vN?,[~0s$)1#VyhB"NsA+`7d]4[A&3í~.'y K0aJ! W|qU)4Pr`,tkg.A3[th[9fH$WztZP^ EEDʵmI R`~ﯙ9"Rܱ]ck~!غ:LNs@۝B ;@ʐw]!6,vZ"xz'b<Pp07]23c$d:@Q;`9]ߴ8!>M9 '-5~},PyjmMNEZU#|=ғgOg_}o "UX>@W c[: { e$g d[rk$L,̾un#g*F= $7,Z^(Wڗ73%J&q?CeP[ ڕI eZl1d?RF}zʶ*Q}"v%e_`4"*ʔz*/FR$螰Ҏ8"A+TӌYl/uci\LMɋC%*Wc ̑;{!Ot&^զ>%vYA "W!2on\{dD^pA|^.-G=QLh#6U7A{o:g[C*QN0XOсmm$| Nֆ&Ew޲n-ٝ@gk5k!ivb=w؋8禫g7@1sHzآZ͜{|px{&~1h읫qNax R 혃~:AK ls:s . ͌\dNd0%_Q.`΀3)GӖ@ @>W(V^< '+mha+HQl./5_Nr̭ͭe -[{Ԍ+7Wұ)Bjı|e{ T|&e)l0^qP͉1$xj3f'Iw^1;ʈ2Fg-Љ-NaZDA5z +{o|CDF}PP|[Fuy?_z̭b  h.9Ĺ.t$sx8x߲Aq{'T#<@Iǻ/-$AbK]}h;Bg1(ݜS]ou% XS[PZLтaN>eZf_n>RqAM~ `Ll v{뢆z)RSx)eބXV=0Dp1}Nvh8'$X%1:4H^2l+ nS3 T;}gL >ZMRP&ŒrxcǹQṽ>@ćh# \9sDc}?K6fsI|m-SB "U"Y66=oHj "g؈9 p. G&J`n/Ql{'_QS[q";΀obT]Z l@!dE?GUK Y ફoN0햬X!xImoW!.*xEAJ(!9TkD 􁢬 H%ՙ?gs$_2 TkU!)ib"l U] _TdpZzxNWdS@sEP ħD]sx+%3y%0yL4GM8Ymv99TN6J 5rܙJ&b7m݂ 3L(xVQ:3%3+o_Pud(S'X==4N4e), 7/ԼꭌP5]}|puH6.z@4爁gg@]L~vVx9KޫVhHHgTN.+`Ľ/K{Eբ6:?9/JaZE$+*4c NL\zޒr9 [`XK ξ^URr@0 'neLD#$w^%w}NJeJ@l# s^FqR\t޺6ib=)wo`6ck6MBoL  jn&ŻvA|t)MuxqKuC\D[i@A\9At؀bU{/Z}=n]x VW~ʜ.k.ϗ`4nq^a{:0H:0lOE!Yw/vAvY a)2=Pぜ[+&e8^!o= 5o r.>!m"hݩIO'V) $(LqSLLp֕ev6AJN&~zn}ݸȄ^G8V,7af+iiH9ч?%@8z)% 3#B2H vd_a.a*@Z U39\t{AKܴnDz)-Y64q_sDӋk!0MHsymO+mb.3HMϥ,XZ]mg'Jx ,J+_T_YrGE~gwkdd9@M\f[;m\zӉn_LÀ"GfޅZ%\aAa4p!s; ZLpU’td rs1%x@}̦_; '#?]ƃ 3}ln$T>#m]oeX]SD3.8Erbq}mE-ljkerK4BB-\3ٯ}o7 Z,8"jm$KU+9 -ڸ7b/ڞX&0Kh17B#߹R}q+ tg!fI1UA)آBTY|K1 7S0k yRܻ>:0T/mh.$-c1uU?-Vxb@ASy@Hf,Ns`7 ϊ"'1e`ٸollF`~8yYF~Q{+@4RX~_fj拨\QoԴٷBo!g5A 2͞xQڒFP[ rE=CE'L)sG*#x* P޴(3Tl+O~dR;T $G-䌌v  ggX}}*-:\< |e|+)%S^/#2' 8 [Q%՟!1DOܠzX:K*#; B;wl=%(swXBVO ]\$\ I*.[ >"vrVW5,7wX3-ў MFIU)lRZ:Y"'B>)A , =Mx|"z5FϴR 2_ FsCvйX!";ݬc&d}RvX$w?δrl@HfD{t  M7p#^TJey?K2s Nۀȱ}:}3/C6P>UE`+sB?Ca$8$.9 ܷĿ$ B^;YoYng)2 D(i?f'k. Vn"um"Vli6=o"ɚsmz=tK9z}M=X+YoGjfrB6@u+QIyG99>< {e"P50'OR!WZO2)h(VÌ¡(bҘ!Zd&k3V\|j۝6C rd٨S sIZ2/8cqF1 l?]Z*;Dsk/~ma< X{yDz_Lji#sC`!S h0sB=S-_+ʣwDJ \ f>ywcB^R8#&fW[)'}G%W5PBrAaN+OA Ʀ+MjdD`5[X[g xoϦ[cI؈\裭gd} rq4D1!`q<|U1d0 `!"G8H)_ϯNˁ]/&7 ޱuIU ^;kmnًqH|C+89'tU$,7WJN.swX(&HZY&*U?LQyVd5}9AJKR8):Og Nu`J}c)d"xm[W#H#7s([iwN 2gWءr+h Y]2u"$xNAY _'kLfHmBP.v, [Xfnod8h 51{¬'lhm5g-_`cGҒ%tm|5kA[~Qtg-͚F[uEPbNqi-|V 06!ʮ]1g#&4e-==MDB<'e98FgY.)9VQ4I+OHMS 5 P75Nm %ωVw+[7] g{;{ vVZͽMBZcF= ܈MAĎη9?HMg=3]lI F5gbpM;{ ~T}(API|6_dy+sI; & 8/HF1K'14C{r6$[-p+L>̇{PX*o~ >Ⲫffok".[6EzȭQ'A<(!gٰ,L14,OF<[x'l/-ӣў: t^!P>[$o$>}̮%"Q0707010000000d000081a40000000000000000000000016552669a000051c8000000000000000000000000000000000000002500000000./usr/share/man/uk/man5/sssd-ad.5.gz}ysǕIQ݁DZb"4 C(t5ᮆ$lH РG,Ϭ'±nh|7|Gfʪn4)$GV/{p慨50Z2iZ+剕b9u:/4jcGHI3n5ʯ5F?M֒t1IZi^ZF+0(ϩO#5 sqKԩSgFO>y+5w;j{ 5Zz^Q:PoSfY .xAvP s/D/Ud^?G gGQt.֓(m,%rي窵jjVIYQVґJ2W#ٱ_z:V:P_fy^2Z.4~28Th◊_$5"K ӤUx֊ͥժjՒhbR[F}`+i:_-`\VՒV7Q]+QXᭉ /_>i:q=fJKoayc43u?WnpU]ۏ#` gx7oF喢\<~7z_2X-DPB/_7`X@ÏoI۹lo>\77հjhxz@}j/8 <3?9ߌDqj&[D`_j ?>IܫV?^ϝe sS>Q7`/]6:{Og[OԛegPewO/mܨ~?,:sH1p&fwޅǩCƽ<~fzx_.lYw,Wa}h3?}:*lmGaxPq|2?V>bqh"w@jʰaj"؁'whwj2@ouVqA -QaVބ'Q RMmNL\=c=I!<-Ox:%IwamX5c<>to+p>f{ H g #pppj~mT 6uqt┺@j=[TdS>M>EOgIs.i6Rsc%Qjwhj;@qd?X^mh*YJ4y:Rz#:9p1\6 Gmgt#x^rx戛WmұKe&}R= k8Iy<2 o6khN.%Br WKf-6D#O15# ^HPr"jUGaa)2̈$ma-l:(Zu}M*hoXE152RUe|/6Ȱe`3n֫mޤY}n(W r< 0aVXq$ 6iL&!R2dsm-5C7pݟ@EY#\HJbuIU:͈&c>|QngG8:[IPčp@(4gMc!)m_`ۼנeNG.ʢs)R]RJV2RJ'WJZ\;og4{K:kJn:8z**^t؛;AdU-2Q3LW*!vqx՘OpUk}=}}2`ęhXmE W 9[t՜gj\# 5/4?Q;_é)KbZ~/VQ.e$%^s8K2QCǽAƾj/EoHsoo;jS<%.6ldF~Fm=u}"n|OS0Be' n/cI>*mO,O'&@tѷQ8Z~MoHmV4\G3<3029802/#`j}!z5i\KH702_u8O_W=_tr .B q9_Ek0~e4p۴úo:,F;n_t 3VmwCOm Eq/"N@_mOh)2?.qҨs)x[o3, f>R;#ّoy<%+]<$Mo >H8 Oռݠ޾ njE k5]TvЪňh1xsc=vM73pv-*⦚[ޞ|C%#%Pb2;_m-ngbw5{^_/Rӏa.pŶ.dy70Y2*vWexn ܷ2$\}G<ЏH6#3XjSh UvZ]E/@48.IsY:M R?*봫.aDr0;W_AJm>ʊx^ǂn# GGsӓ-m1q܉>_Vwޙkg9'xL:|zfޙ̤?>-.ʇ<Hi hSx̞ ^U$9`W{c0|ޟ3~n)̬15ڔkl9i"U.C5^68˾־xW {d6P| WK_=敚{&Sv٠Ud@sUi#ՇL̓ZiWy6X \WfHQr·G ڛrBy-5o~QfR\ l\?qJlWѠ]jg>, :x$˘dİOǨڤI$/}șt`'?Us7z;J}zluh*?RkF3bO1I!|ox ;Ҷ1(uVt@} ~Rz).Fl|O|wYSn:$4!ʍxf8MfJ*Y|<P}B6#ޯjQuh&Q\7TWXM27xkӤUb5D%My=|6Wħͩ'Wk0]}V`çHWaQg;_fXi6IE5h/6jVVZIPI[0*9>(5=[Bj5W`/xR{a'R+Pqx?y8W׹d.b6.qD:ʊ~=l;{ux'ͯFi\K`e$ u#Jj_/Bqe:;+IS\\~we_ oiGuT(Zz wPړ(p%lE[OXȷHUm1ZP;)lkpêOa3]CqL^-|Q] }4נ(?P'!@U<Bkzc`g  5AZyuKby~}RU8c `[$R2h҃q17΋jtޤ6(V h_|[VG*C +ɥc ך1l]1Iq_74wc7 inHAkX71Ѻ FtSqF< :83{fy.3*0a!oCCGf$Ĵ ]@ ރ`QEXۧ۸"֑0N Jߐ?~9nGg?@gQ<<#a$nj"Z,˓秦x# ~ьF#a5TaŜs08dB;h}5GDM߰8J 4-"]С8\s QC#dx풷]ze~(g)Bae"߫atsƵ7цmБ2 M 4+$4sxtDw$CkȈ|Xi!BƁ@( 1~JʋcSΜ=S㌅]G`1# gɢcw8NqA:^Fsaʽ- Z) G7\su!ˈD%YcA![SW>KdP%ے>dOތm9 \.Ȑ!-B iMpGEm_5SW$a?B!8'zzهmc=#L9-\0I#t~ǔ#B!2xK@ŃZ9eYv5N>Ix*Ir$H1ȹ`v)` 7*4PM \C[ 0t#7Ԓnʂq<ħdi.i^\5,UiB*WSo44L }MN5|+ϫ|]Mnq՞eLfM^`DJЁCKR4 U[I_LqaE%@BYr;d>#{[uNs<= ~]Oc{ƲCD f3=2B=it[譄Dq(nߨ5Zz܊k!$;;CaU[ nQGJ_*B7L; s~p dՒ y׍["Qqò-T,5mDйGg6w*i_BL{`ϵ| .:c1ɼ\,ߝp`n6nN,893ǩ/Ssx+g\H\?|a}FlԞ͉~ Wd @rq2Ge,+ǹD1P4۵݄~s:-8dSfe-6(1w}`[3%€U0^ .=iB4ۼzB" Cq]권㬑^md#r'bQLؾR/s4rxA[g~Hz%ioĈEw䶘DL@"{eC5==z 0=i =B3gN^|q@uluF1@6={!u_GBj8Te5MWѳc/DQBJ3U 39X&ְ͕Ba0q//HA-^XHuS3مY8VإgRQiD)6&xvq&IeqKf],d8{c,.0qL-sn{8 z3\xՄ}3?{3s+LI r4|j`•>9O&qex䂟hR2$hWzyw8_v G*ef&/칩fL^r~rHhW,FU p sȄ̏Hy@am[5h{@ }.\`*G:dT2yjo^nHIsIiPJ"AB<(C]csC+I/nM(2obr}@4U>PhcԯBiMcZ!fG&y3u͂-r;F!FIҩ,]M9l(Ѳ:v#iƪ9'::l否QYL$_!Q3%(p=}rFveNYHu =|ǫyqS0Nۗ&/aNBx'_ֱm!ߓ؉M/~+H2 [~Xq@'&iϼdNwl,ʼn*HDa ip0塮TN6)Dl#c"Sl뗑Fa?dž wHCuiYl%_7\@! AwbD8A W9Pn$%Oȝ^*P5^i7ϊ%=h^gp/(>J7CތgFT U%e65 t ]zC{!r$TOzQ_swh;E sUU8 iJTI&oms@q8TRm2qywm5~\w G6tXgb&c:sUך[+8;cP{2I8f"Lj.\A~DG!Ώ:=5jsV<78>?ʯEi? V"bh`_pZpsqNyTWs #8?TQYs<_wf&VR.pKo'@=~M:kO=a 6g-m"1 ?/:_.%aglq|;^l{hETǎ`nr?S"\a9Wu2͜hF M%G/Bn8?_\FK|+bIwچxNl LPF -Ssߢ~<3l<#h,[尟R X q!,\4  ¸GÑmn53|$NȨ3jJ*3+ZT2#Ts/D߫jYIZk^н"j^H1^58~|1q]t?d9Gq]$aS^ԏpcƑטeѶ]Oϐ[+u;MCy( ~٪ۢlb_W{}%yWIdž++=2Zzɪ-aaċ܂~bק8֞l%׆uʁ[ozM+ ߥݡ= Ǘ3p(4ff7ԌcOǬ; ;~u,t`aPQYL7(& ${K+Kb@Ro"BRX.wKpVbѶ*qZ7㣴GC@91rTwRD F5pL܇HsnbvsNa9]Et*553}ff 9fROޏkVzF"V+iKDl7;YM%p<&Vi?Q`f8#7`J;b`\"&Lޜ@r[4݈lR!>ϪyS-bSm,'A-P1~V03,e۹c5]EwlRwP4R½gǢ/FXBpO$KNIؕJ Bs/Pm< Hv/q/kaw myMm3!\Ц`,~PǙE}6ءnn ;@7l?-UES `s4N3Z^n>rޯD&JKQ~Vpw.ٴUٵ7&Dg^IM7jbyy+'o`%t'>t3 PtRM˘!'\# *i ?zvIm%vBε`:m&.155q傶K3SW.ro.y=EuȑR!t *] iPR=5g.Pi,,V4]@VzT7^-u+٥oƾ)#.-éN_Δ "FiY}q~MWwUk`δu6Z0jFܛ5vQ&c^v MZpպF~_K6Kn)a touT z" J,DFF~=krɱq-tڢC]sz@s]r;xA7U_B~hFD\M2H*,nK[_v3\h6rѼZQg[]%#>~Z!w۟"v 4 ~J}o R_ƞϷ[P_Hq?ǙI$;۸ۜ.O!*)17%lH |GB9fMy<4ӼP>_Ll.ۚFGϱ W.O]Z}z4W>wշ84ɰ(lsh1~4Sr0WW~,,j$>Z9CZ"GFj@/2\;&\Mޡj|RnV eڡ !%$L(N$HNsa=H7w}|*]x"l<`^JBV"Fo϶3/m'ô5t%jWߡ a89b}]ALaQu\>&"ZC)EMm[esSS)poV5DJTGR/*pe7O:[av- Jk浝(P)Fe&]e6Gz[ȅuɇ&qy}T@*t~޶vc(Xj֩zؙo)iI>ӥS={tv16㢝1Aߏ^snHi@љ̝9X(HAo)B<(ae/ [;˭fO"&Ƣ:^ޱWj#W'P],PLj LyBB5Q0I_BŸUo+|T]XR +$E q&ZY)/FDqjA'n JjW$Ω^Nf[:U/txj= ^n+"Ug H+gD4ԓ̴qf$ ܥx޽0J^öFgܘ1sLtYmMAC(p=4h墾.huz-U%6rs* X"MHM9Y]9Q.z)oA0Q#veB؊! ILA%3H"\}t9Orק5%h$t{6:#jغN^<0Ҫ;B $*-|!wu[O %QN6o`+f5u@ ]e+R9#9*FW2tJS3lr6;h4{/\yEM9:Kxo[Xk}OO&C2g=>qb6[lV+bc)T,2ijב>h7(vaP2tkАywlAF#UD>@T) vPՎ`~94VW p'cnhV" ;>1<% צ"Uꁯo_ Go+]iVr\.)SKYߪ g{r`Nŀ]DT&w7B"C~wT "NƬe-gb>.poߴ) Hg,%`%3MWҖ:ه@u\-ľLYC6}l7"e,NhWQqTgO[jx˜ytD::Ү9A@x*e2"QPQkisQ:А4xA,*%]6wGǠ.\(I+Rm!Ɂ͝UQI&8Xdhl'{#L\D#]^pl?"t_,e~RW?Sv./:M |`U\^,m0l h<0d=iB d;?b @ٖ)qXS< p-a7:0R]P0;rk|C&HH Qfݲw=xi||ǪYC?a 89zSӷLH=z,eceI iebTHŀ!5%XCtCcqyjI=[V*d.+cSoF/(Z!@/_$}^8P!`m &|X3e"j{C X*B-QbXqgy1e $!b B5N %ms%(&xmtt8Fƀ[Rq|.#kg_8jȍދkU.*B'}XnVՏDO=np̻Hߴ,jV t'PqeqXE3kK'*TX^5Dimv)"KLR4{9զ]*~$ |g!jE=(xk #_z_I\El)(n$>=N|OUx,@ kpc'!u_S"Dq N>,od7=B*Yq&4~=瓁k|"\045uY\\~7'(<&/;$T]H M%8_t=vK\yVҥUh8N+O;))_HXи+E ao:8]i"N#( mi-r!e2ntH}k(ƶrK`KFIeon};b8T5Lގ$ Bmntm9]|[C5r*R-!VL}0!Es2Y<5Z6f)n@M yWSߒ`NOur YS)`Sw)tkG/ʐ]} [ Q'Gܢg[޻LI'* fU_=<_QalZ3Hl"0#+B EEH"#}؀[ea_p]`gqdtP5|PN9lWyxk+sRGߓ"J2BOl#&|P"ȋ%geL`}[\w2zc.mLUJC_|ݦxbd؏Kޝb $tѶs_&HA;W_Iٓ E8l0bA(b'3N)ZonAy>u(gN9fP7)lǯEb|5<*tJnMa'\w8SPz&Jx•0dXr%w;ŮiWȖoRi*>< }; ,ʂF?/8J5Ij#YX-Ώi G򡩵(c;B3`hS`(j ~i# ^& uE4l=́@<(/L44Pox|U23"ud-c]p)Sirkݴ8Jĩ16V?'^`s:32>iOm}zc8}>K,,`iFioVqʑ|.p~Ui d`}W鍢&i^dVu)i4|~ GGګb< $w2/^1o/(_2M } lKV(r/[ xjllf n,nnvS7Ns 5Ln+u3Pc9D="4US7qzM8 +󶽬h\5Gy{ESM*\o(=|J^ /hXrTr_LY2huiXRss`ʺd"sƢ)nxUdX+[\IӢܶuv9KYa%6{ךrmZTȵ͓0m.)T`ꠈ kEٖam,ցfQ[8~^d*>`gؕ\ #8CTZldu ,x(N&cz͉r4^7Lqgk4,؇Vjf26xuQϓ{(}tՊzc냜/*}di9h2~`}\PI 13QJZWQ.( 'T!7EKa3)LQj\$H46ߛ~6*k{yCGw؁ pШ@/E㴿#]$`Ͷ-5SO/?S254z="_5d .i*\qDiDgĕ(YȢs'+9UeH5}{HO Vk"b.dFKq}(rŅ-2P7KDA*[Gg\i8|/dN}!\ﬖBKuh;_Tĉex8V>T]zG_~M>ā{&!)3Uh΢sOA2ob˖/J-_7lmS.^Ba( g3W8`[1!TTrp۹5O8wgE3qwN@uE񲻹OKٽ[V.,%Mߚximv.o`NphC*ShJ-YΆ3 t.ɠn(/LmN`cK$64@܁9`*r+\0(8˹?3=̹X~g @6y+6B6+6d(,H ):OմMRGR÷KMT<˶Z-y]l˙e#JMپ0 J փGorɝh0ev<l+.|0ǰ8R=hvcD;"xd\IȠ@Z Nm].VNI#1rQ\iq({xLM:2dMw8/Ld&?Xr'h%/ 'ںxhߜmmdrdeZ֋KI +-߱MՊgi25u\=ٸ`ɸ(RN&,hH"8 C;jfv"D;n/ ~T!mq5pn۱}" iƍ'B+p~&5,j(2 "yd$1^m"b WEk-%' (ۓ0h8F! O_VK'lz{.#sZRg54@"\m}d) jINLVEWC4#gu:toYOjQZ~5mFN=z _󛭕ًʞw[>'gQ& 9xCiig2nFe2^؂BmH"3g!}N)"9kQ;CL["3[@.',C4y"yجB,u?;IJT;Dh?=:a C\3*idѓ3eqeMQЭQ2vnNܦ'NlKRALn 1Ǿ[k0@.mߴI~V2=-l@jW,uPuR9;&$1L5]Q톔LQA$յ5٪vR@ {=UݚH {;A?*4y}iaK6 +յ :w1aY)*391zSĢ@ @ X3sA/(n7wOOfժڅ_t}'C$;g aClp}g Wg@J s@I[066<+K8N*M9屈G?LSs`T(쭾,"\i0HpMNr2<_Sfk^k,яO i]h}=DD2y,A}.UGh+AjCԜ1*3Gnest^*e?s#o:,O.Mvd8SҌXk/z RuWٰ+xX!_,훬4H=-B_V>2.6sz~TC,:VaƭK& .NoG΀b/f o%g١ ("uӰ )('\DC>\&0싮NJx ܰA'/#?S<@E{STc5R"򋧱eݖb4o {~ MwMCu{qۻ3"g]a;iFTn!?i\7,Ŗ}]7um YnKge*`~jfv3&KcUjxc[5yr/ݹ}jeBjYc+c_Q8 8WB{]j(Cb Q{bWd9kv=:7 ^^fcяSCم~kJJCm@2?m? Gݐpyǻ'4kUQ.cX;;Nl s?1Di`b}&J2ZWOa$,Y5Cl辛e<77B>غiCwi/;e8LFGʯKfp.n) a)J.KA ӤsUd3{3N-^QZ-7VR0ǻC(N cJsD?HO"ESs*7.Wt4i2-Ux BBԔ߯>_LQkFVQOQ]Xi&RDFWkh.ZQ[I%J[q.(UIOIJTIK uzz>(TĸϸiJm*Y±f˔֙kT$J$ %Hq(GUDmn S*/L@[g߹rW>o5²ҁ3p]NuÐlȭBd}^&.cZLj5?j.'>գ Ζ2-M=KVY_|ur3Ň36_bwVvk`J *akh8ao,z=}ݷu 5lc}x4^j9ax@4VSVƘ=xl nsXSnSn;[?K+JXi-*-uu@Xsbh*';S]TZ =S:sn+\';/jJIƌ9'0o rNyK4nɞ'hnَ_[Z3պh[n9xx*l ~,K$> 5nYxiQ`Õ۪#~/`,/%t](ш|-2r$s\oе71"q߼y~bd護&.!8/>1}'iWG.Y$Uب3-{H-{<~yNQ55r-Ztr-g9pv/LkݳM$}m/s `Yzo]xjevxZIKrދ8@\hJ"OnDVMЇ_{XyhU<]f%IqI9/`&6`"w"s;Z HH2pʇ?!#td@9k_1J,o4m9 pY^IoPc~ɟs+vKzՊ,-s{{fv8FReP M_g[`qZɵW$9BcY ktufrʗdz=Vp.WdԮd3@BO_?}fh^MߊK2"Pz:z ѺS/#2އcy۹itԧ.\o5*'} q`.ƅk!B ǭV:JRwsg*JrWW櫵3ҕJ#bpF}Xmbs8~̭,ԒFcn~% z$‚g1dh.Vu["6W?%w.!>.( S?=e:/b9^R_axr]Լvsdȅ4)Ch y[Þm'tDx,Zr L5jcb<$e&y5bv4yM? ITtdZn6| Ѥ>_Wä*Xo)4 Wѥ/$+u%V\b*c`ғùƹ⭩sS`I*["Ľ<6RVkͫgμH.s9ȶ$07070100000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000b00000000TRAILER!!!sFZшq_K%)bw4\ k j YZ