sssd-client-2.4.0-9.el8_4.1 >  A `U]O.Ǿwk<$%J[P 1ɓ$B}N7dW_skWjMMmH!| P=!јsBߍN[CafVOjj=/ޙwN^ӂ\)BNp@}AH Ii~YUO -] +r4]V P@5g~M'QC2NqHag}CDIwd.cO1^ƽ͘`k M`W/<ʈa@ tᔭY }~d}~mu+IuJhp Z#}ߨĔ*Sv0c%kzK"jwYTMhB\0vmFu\$m8#+AVG Pn8e177 U-:H ԚHwͯUGa={# nu;Vۜ98a8e086d9a74343663a9dc832e7ca745a9ba164d3e96c12ccf3d79d0b098d0708f5b2154bc74a7bee1ddb40cf31abf80f7c6112 `U]v&،w-,1йPIrH(En823H/B=)B%NL>W3,U)òALN)0L ݗE5NVv L9&)1 <~zoaYމI6/z)1 $0bhx89.oE?r#񝓃c:0u)ġvH}3r~l3uKY ʭ6n (6rDur-mF&]X!o H)#gN$na~HBQA ?,2R2>;uUޖ9'N<$>pAk?kd  D %+04%% % \% % U%  % t% -%  %  ) ))(Z8d9:e>X?Y@Y GY%HY%IZ@%XZpYZ\Z%][8%^]b_daaeaffailakta%ub%vb wh$%xh%yiLYjjjjCsssd-client2.4.09.el8_4.1SSSD Client libraries for NSS and PAMProvides the libraries needed by the PAM and NSS stacks to connect to the SSSD service.`x86-01.mbox.centos.orgpCentOSCentOSLGPLv3+CentOS Buildsys Applications/Systemhttps://pagure.io/SSSD/sssd/linuxi686/sbin/ldconfig /usr/sbin/alternatives --install /etc/cifs-utils/idmap-plugin cifs-idmap-plugin /usr/lib/cifs-utils/cifs_idmap_sss.so 20if [ $1 -eq 0 ] ; then /usr/sbin/alternatives --remove cifs-idmap-plugin /usr/lib/cifs-utils/cifs_idmap_sss.so fi#'<D0>+,_ =@nK <  1 AAAAAAAAAAAA큤`]````````````````^`_`_`_`_`_`_`^`^`_`_,_,`L`L`L`L`L`L`L`L1d0c3e9d51bd525dee6e11ea18ad6ccb1f38f549b779ae0289dcbcb9ce3fece2be1acca2b17621d44f0a0a9efad7a976e97472ee18da455652d39dcefbad0967f6253ed09b224d079952fb12e025c2b0c59c1298332b7e062eb9de03ea78ccee699cdfc83739490489dc0b9bae5dc331c2752e4a7276f8c3b23f63b7ba11551dcde3b59331e9cc2056735ecd6b5e996ca189545672c5d7cd8dca07c39cbde2ee71a9635d8f6b72c7c729a50391a27c6a7e6d478a659753a8977f27a309de84097e58c6a61c0df9be0d6972be6987ce0b7f462d820408f26e12781096ca887e1d8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9036c57f43c939054fd4b831f271a14c97a488c38f98cdda5e887c5d396e3b3bc589605ea4922766a5cb08a47d4c02f62b50b822023847ac590fc435672e95b93b6bded81a1edc7937dd27f4730aa0219c586310d063de8558a8e5219b93a963ef63f8345e5e19a7ea1479d30fa45bc948811dd77cadb7cb885157bdf5efe331a1c6cd5e3986e42c86d6520527f700ea736db7a72aea227a02c1eb60bd0f6aff2b66001f5a2c0849e3fc0341f455635905be77cc6f070d0d316aab8225811703cbfe794591048387a9061da8041a55d7870b397f367ef58334014e838afb7fccbd89eeb47f2b6dec48174dfed481d3af424522e1bb34f9087061c90026c7aa51d3d0014c8d4112d60d71bc4a6f21300343a05e877e1ec87490b426091f373e7bd2a../../../../usr/lib/libnss_sss.so.2../../../../usr/lib/security/pam_sss.so../../../../usr/lib/krb5/plugins/authdata/sssd_pac_plugin.so../../../../usr/lib/krb5/plugins/libkrb5/sssd_krb5_locator_plugin.so../../../../usr/lib/cifs-utils/cifs_idmap_sss.so../../../../usr/lib/sssd/modules/sssd_krb5_localauth_plugin.so../../../../usr/lib/security/pam_sss_gss.so@rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.4.0-9.el8_4.1.src.rpmlibnss_sss.so.2libnss_sss.so.2(EXPORTED)sssd-clientsssd-client(x86-32) @@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/sbin/ldconfig/sbin/ldconfig/sbin/ldconfig/usr/sbin/alternatives/usr/sbin/alternativeslibc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.1.3)libc.so.6(GLIBC_2.2)libc.so.6(GLIBC_2.28)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libc.so.6(GLIBC_2.7)libc.so.6(GLIBC_2.8)libcom_err.so.2libgssapi_krb5.so.2libgssapi_krb5.so.2(gssapi_krb5_2_MIT)libk5crypto.so.3libkrb5.so.3libkrb5.so.3(krb5_3_MIT)libpam.so.0libpam.so.0(LIBPAM_1.0)libpam.so.0(LIBPAM_EXTENSION_1.0)libpam.so.0(LIBPAM_MODUTIL_1.0)libpthread.so.0libsss_idmaplibsss_idmap.so.0libsss_idmap.so.0(SSS_IDMAP_0.4)libsss_nss_idmaplibsss_nss_idmap.so.0libsss_nss_idmap.so.0(SSS_NSS_IDMAP_0.0.1)libsss_nss_idmap.so.0(SSS_NSS_IDMAP_0.5.0)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)2.4.0-9.el8_4.12.4.0-9.el8_4.13.0.4-14.6.0-14.0-15.2-14.14.3`@`T@`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.4.0-9.1Alexey Tikhonov - 2.4.0-9Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1949170 - pam_sss_gss.so doesn't work with large kerberos tickets [rhel-8.4.0.z] - Resolves: rhbz#1945656 - No gpo found and ad_gpo_implicit_deny set to True still permits user login [rhel-8.4.0.z] - Resolves: rhbz#1945655 - SSSD not detecting subdomain from AD forest (RHEL 8.3) [rhel-8.4.0.z] - Resolves: rhbz#1945654 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-8.4.0.z] - Resolves: rhbz#1942438 - Wrong default debug level of sssd tools [rhel-8.4.0.z]- Resolves: rhbz#1899712 - [sssd] RHEL 8.4 Tier 0 Localization- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/sbin/ldconfig  !"#$%essvsvukuk2.4.0-9.el8_4.12.4.0-9.el8_4.1   cifs-utilsidmap-plugin.build-id1acd4c84de1fe316b5d966a79c5d21e0158c35b8fb84f193ecc0a371b71a537172d3d0e1bf5d574116d5f41558cdc3c56b0b1af1c45f84736f43d35ddb9552dd21c9943cd41209f5b4ad74de35ea7266245a49bc492b14a5a24d1fce059bd4148f065f7aa538d6b5e7dddb5eac8d8ca6bd1b21c8f816dba8f9309d563f73fbc645bf11d886c72a1908d794cifs-utilscifs_idmap_sss.sosssd_pac_plugin.sosssd_krb5_locator_plugin.solibnss_sss.so.2pam_sss.sopam_sss_gss.sosssdmodulessssd_krb5_localauth_plugin.sosssd-clientCOPYINGCOPYING.LESSERsssd_krb5_locator_plugin.8.gzpam_sss.8.gzpam_sss_gss.8.gzsssd_krb5_locator_plugin.8.gzpam_sss.8.gzsssd_krb5_locator_plugin.8.gzpam_sss.8.gzsssd_krb5_locator_plugin.8.gz/etc//etc/cifs-utils//usr/lib//usr/lib/.build-id//usr/lib/.build-id/1a//usr/lib/.build-id/33//usr/lib/.build-id/41//usr/lib/.build-id/5d//usr/lib/.build-id/66//usr/lib/.build-id/7a//usr/lib/.build-id/a8//usr/lib/cifs-utils//usr/lib/krb5/plugins/authdata//usr/lib/krb5/plugins/libkrb5//usr/lib/security//usr/lib/sssd//usr/lib/sssd/modules//usr/share/licenses//usr/share/licenses/sssd-client//usr/share/man/es/man8//usr/share/man/man8//usr/share/man/sv/man8//usr/share/man/uk/man8/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m32 -march=x86-64 -mtune=generic -mfpmath=sse -mstackrealign -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2i686-redhat-linux-gnu directorycannot open `/builddir/build/BUILDROOT/sssd-2.4.0-9.el8_4.1.i386/etc/cifs-utils/idmap-plugin' (No such file or directory)ELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=66245a49bc492b14a5a24d1fce059bd4148f065f, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=4116d5f41558cdc3c56b0b1af1c45f84736f43d3, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=5ddb9552dd21c9943cd41209f5b4ad74de35ea72, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=1acd4c84de1fe316b5d966a79c5d21e0158c35b8, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=33fb84f193ecc0a371b71a537172d3d0e1bf5d57, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=a8f9309d563f73fbc645bf11d886c72a1908d794, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=7aa538d6b5e7dddb5eac8d8ca6bd1b21c8f816db, strippedASCII texttroff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix) !.=J  RRR RRR#R"RR!RRR'RR RR R RRRRRRR'R RR RR RRRR'PPR R RR R RRRRRR'RRRR R RR R RR RRRRR'RRRR RR R RRRRRR'RR R RR R RRRRRRRRR'utf-850be9620bb2b8f56fad9a6435d03d7460a317101d40cf1e8ba20130d66f1cc6f?7zXZ !#,W] b2u jӫ`(y,xcOa~8L2~QPcWm[: ~iJZΑyM:Q`BЬta;Vg Y}PJ{1DC(Nmy{Am 8.yuá%0$q%T6FddzcWC}9xW*MF/~] 谵$wqce#KWr+U( qKTemCcu}awF7T Ֆ5*^#`/UȨtĭ,#ѥ5ʱAOC߅Uvc̹%P ]NHK1]+aw%KJ7H*+Q3H[Yc#r936) $a'ۻSE$GRzq#Zvݤ>K=!X-4b%`](' QS(tYbٵO!ߴ l8Mg!=*OM+WALӟD K * -閑8ߚ"^iU._j>LU.o $5z2X!J}q:h:.')tL݊_(7U@ubb-W>ol*ZM(7StG?2x#h3<;ne gꄧo($Y օAN@x52Tr 7xIq`Hv?Jg/DzERLF]d2kJ p$~"=ńe)f#4Ƃ.o/ƒ$9:AL_v7#@k$Hx%_JseǾsJ7QcбtAqќl<1ѹ5Jǽ[57_+gaS|S.t 1C`ocJ:tgvA6/J;>Ȏ㕪:ΐI8 p`x,Niُ5R?ʉP/ry^gA O/ \x 7jSgW̍һX5$ 1i_֘,}zוG5uɻ6<Ã5B"C=fmp9 ]%J; A${8c|OήR ǵ(DP~jz|D X2k "'L֞J%R>ikoH*IE9?,y%Œm!^ $Q⵷"a3| &oH@@+#HVDrۆBy)h =ɛo!keYU潖RS7S#g?9O J˰~/AD%VWj\;̘glhlD÷f7u{xIqźJee'm_RH£rxJ^0KkD "a myȄMYY 9jo% .86;Y :` DkXFw"!c'9/1M%B勺ntdu,c\1ŪgΠ-%`Q$l-uKGJo  wh0_,1x{7h#h*M^cڄJ!3 o羞[4g7\%p19~\z`gqMi4E~f9L`k߹AlOXG=)/; \Y s"gqf"!6`3-Z@=5isgAktl5]͇B}PpPQ9L4JM7<"א*r#ԸB{9L̘()/r80H3ʡTx`BjUWf9ԡdcGA )I+uƺ)/MǡLsՉ|&~4)8OtM}TXPAb_Z~k d2FΝ9=șܑ*~2ahM4JcpkdD Tky5xǙ*E#H O \OL_?vU KCk{pSSY T<Եǜm MW* ;0ӋVb\ÕӔR뺑Gf nA(aP6|LZw5Ŭ ~}EђBev::Ms8`{LcE0/+24-sHnvLo*c4$6{ fh"HUc&+8歳U߅ 8w)rʃx[|!ߣZя{F-}̜杓"Mh-4׫㺵`-ѕ&(s9HmE7bzW'3s/4 )aL{gp%8I8Z&7,\l06tFݣZK'> ŏ 8xGrST|{܀tQDbHL$FyK. \6oͻ0m6L4(p.mI2;0'`+@{yK;k,!|K?/8Ӓ$$[1BG"E9CEjhmE΄PB{DI\zR~Т+<ч\XEq;tci)&N7vR\e#!66M!NU &X&oFqA[%ᵅ@rѤ򠈟a>P:KU:\9CpDԪHJx0m'k`%YO#c3]C1>.v\rl@Uk drj=ZN1%v{ımM7t_A \}I"V1"# An&w(mSEq62weYJ{(T[ǘO]6#-_Z]ð-uST 9m;qju1F^/ZtоIUQф`-bTEߜR :I"P>.7U.yP[`sɤ6o؅.z(l Xld0G \uKJ)"@G}W)Bx6fI8&eɉd)gY؋sQ  6hI"N8LbλyT+/Qh$]{x1jy^ ~ O&sSSN|/C\K}VYqLLu? f,I A _[Ћ-lyoX;hr|Rm{P0-T}wafkp`-:E&Atj*"Rj1RO}N!~~7f`ugR:r탽:Y|U;;thit.llgB2Uc-A*$&To_ T&Dp(on*+v!( fh+g/+8nĐLkNq/C]ZD$B]pb'Ya.tmB2:[~מU|hQ 筣tK\䉴piIHfnǽm[ K`ݿRwov3RJ4D0xzO]%&Sx2eIrc;@0^^\ _SVoU7vF*< B{>m K9#|,@*;cJV陹>ӡz^oO, 4JKOFYE:I O(*^$d.ŋTO%Ͼ4:S@36hڈL{E Y @&NFM'kԍIC}K +({ФJ#3#6'W£kpHŵtʮ^[)llB15d0\'U\Ú  @3DmBM FꁶWH|zP4[F'fST zke WfoK ̯q$ޘ]Vs=WR}3W[/Sו.8TCKI٬ &?ձZbc ڋ9 d/5MTG莸s99? 8+bUѻR)C怠/WVb ,[%7YQzm&Zኀ%~p>dcH#Qdemٵ8>4e|{7On0ZF lSVA4뙠c\6z&HHMIZR{lo|_1fDtNJbqPF]8X.t݈dL|ySO&$ӫݴOv*]+ ^5k~ K˂iyهz<4&y4`aJl(&Ѝxw#-^I36XW1^UgI!Ip*j[%Z|(ydon5 JlmDd;cv b"ʍAG,Xe@%Rz6>Dsرb N"CʚFsR̩+pI\MҍtI`"garY'ՊJDB`t>bs){EZVV 3zQUzA-4uտs3 OLP7hL9EPZp2_bݸD%XTo/!pVV+msȵĠ3I+t=}o$<4K4WQ? hz2gN5i~uo,=|v뮥;KE_i)YJ[l | Q-+x'^.>2X-]%<OSW{͝SB:yI^d'۵Ntr;x-['&],̋(J3%($2zD i ь)w+!sM{̈S', .Ŷ +מNl*t)ufس^c/yKF96I>@BUGIEjW0ӗTH{8Lpk@ ' =c˄w~F{d'laEZI sQkϣ@Q0-s a>.N&{7ˡ Hb?46p0VBKm/КTʫ+YGET!'ww8pKƒH;E :'dP#JVHq/AP5~{tOEYPp:q_=Y@ajU (+]fĺaHiLJ/ dP2V@\5 Ux3$!JZ+]868_ 8l?Qg#[ O į8WFfںGgx$h mk3DN f$?oYE^C!ͅETR2(]﷑SтKfRX/n&1"HţP A9QjdhΦssvp4g{N*$5t*3LP.*Se> c©2WCf,dg oO?]dn-rm+ol?)IB;I"ǬQ=2sZKz bvXIshAؽ%K2iz%ȱGiL<Sr2 |:ch0*"]D8YZ KV˴P\T&Q6QJHY:ؤ6ǮCd˸2EM&Q 6ONN]?NÂ.זȦ=}~/UDXժ eqz,-+#0KkV((P9q!f8ZPKg AMw{0șL;3ٗ~Jv?*{n?HM8}[V5%0C詅5qvf<;m_Q(H';50 i2l5@lZ9%2u/n <6;ݰz/|'!!qBJ4UdYiPYHсIu>d3(!t;JeƵYr۬HuJ^Fҷ{N@#(ҥ.̗QLJmE”`NA⁋-Tv]ځ/K>t:&Kkݩ{Q2 zЍ $؊b6ĸ1թ*TSubbcD2> -X됚z/j7W(9v=y>![şKm}E""\yJM?P4] 8gʱ֠LO)ZSz8`c-;쉲kr_6U3n2eϲ>g^ѮTgH9#aOɚhqE`pLx߫T?a6,фԹ_oj+R]p`b0 (J@_%{VsĬ7?^ݰdO2Xaӄ@"Gw/:\2~=폈ce r˝ujVpE &GP,CM_ÇRΉߩTUIe$ 1xL#:'#5HRꗢ`1ĥrzbr?e_(\efgS?/т[fy'h0tq;:eSq?\%-MӀ̖'@qS<wL}^'/B<d5iC~&`Y}0cNDugwIC I+ <Ƒ''9.}6#Sri?8',wV10bo}Y9(!_B3%. ʈTs!ei1ڸ0+V Z+S(yfR 1Z`y]3w9qTITjA jzEO.l\vN,@fy]A k5٩ZXYy*|[ ym }u-Rv)siǾWjG嶭SQD`݌FԆ[V)JWk֑F(%HE.ƟYT`[ױXI_PzY<\"7H&@'F8p*Y cp)TX'uFNur5Mʊ_<^X(Upr>ῡbE/P{~Q}ȫq}<*4~tqKR<域Cf)eOwO÷aDSOKzY GH71++p)#2MeG{O/H鸤s8S"cWp9/xs5z'Q?,\LaP5h^ۏe2V~}L`69K}ԂM%pC kYyIg¾~zfgO1VӋ2k [|e],1Bomy:w;<>h+!|+^a޻;aHr&I 5D,y_#U{\ o۞Vqj;P݀w PS0PvQ D>UC/f3ꕊIh鞪CnnYr f)M(Uk.Ez-%qc^{IE~Z[;8܋`?D7J@8 DNcA>ɒd29_ l(0xegQ'=Wr>IȨ3"gxzMā ^Q (V3̐nIdѥ]E` i6Ê);{οHY (n&zX3؛CمUwM.I߆q'6D)Ejj vM@ Rťg' I  x٨re.LEG${p6/ \$/N0έj=/ J^s;g czXA'e Y,#u ƮD-{9Ur ZUJ;^1?daBV 'JC$ӷYM*ax]gr!ުbu6>&> ܗXiwn:0,?55VsX_>Kt@Bu|dsJԈtXY1XVKЧ;t^+; ;%&[zu%TEJ,=$ FUl1oע)n&bc&4yg8Sr,:̂,xR%[`Yl@ؼhN%<8A5 Of{1^@IE#]> U_ -ۡPcn_BkeqϦDpƃNEĺ 9|+rtA^7m쥴:~+ӺCelS5 +Ń[#1t+]{^3ghcoԯ< yNU)r\K+3D`'n3ZE2;D`1rE{}T U=$ iЄ=D"#7,{tI[/`p؋0'v&Qx2"`k]PW2y;-ߙ,l`-&TT\;\stfEO^]jgKt}>߫JlQ]4:JJIxlaA~gکhQhB$'r{bEAW% ͌Z&j@EH,K;McؕQbXR~HֺC ɡ%>6x HfHlM&//,3Y>VVu{@s ]Ors~KvV1tTOk,HF׳lr`Bvs[E3ٻA[3팩]D$]u.x7کWgi`[j چ ej;;Ci%ݚ{ UWuUb}rwpB 5"ǐV:ѸN#mXy_s%Jt`.D : ts8kC:1FBT7sE{$nZAȧeCD%IiWJWbVnJ)ckG@p09N^lk^mx>5Fb55$-[s-i@X\uho9']G) 9szTF#gI _U {ʈjۨŊٕP# ɓpsFWͱN{-4Q<hH/P "D%㍠iP..:˦V˺ ݒNyNn 0"ikR:wM"f/߮ߑk+k}?)qb1I 4U ( Ƨc;"p5"gV K%%"z}流eci4uoyG+-+@kIaߓL|'đ]-|k2jG<5|i}Q}Ca ŕa-x+ R:ʊtkNgɺ>s19*P/q>*wW}]vVݡ;ub| g(!tXPT]t?hIӢ V 3Gq3/wqz{ T2A ӛ֣L!P{--Ncjkms-OviS7 w7ނ+zD^÷8Y;%Cܭ 2@i87# 5JWIp quqF0:>nlI'Wkk ѫOQ\p9.1}ĩ&T346 7=>]]_NZặ*^*0e-ct0J@0f\{iON;t#C<E& p:ڨ_4x#˥vU%X!QlW{0eR~-c!bsa1\Xx'COFH~{(9Cӷr\x0L5Yqz:cU:%bZ-oxVBˢܿg"2m%G ?H;? UIgK??ҏT vw/ dYTSukëW>9bfWsYo^U;b+xS 5K7⤌{Uyԡ>LЧ˙u+[bw惿2>eg[_VJMe0.(r3W؜W{ v_]/n->CǸL N|\5cB;:p%G'CJ{b` dIᏕ@a6VOS7SYu)Y*泶8q!亓\QQs=NbV{ eZp{ _}P Ux{ͷuB -`< ,@;gmσǰ̓Nɬ7a]y m Щ,MLtUf+sX /c@{*P3> q bD!U52㙛IOhU& s~k@&d[u.^$z*U$Ec1$w|16rXy#^)ZzqUDz5eRIi/(%`~;,THۑ2 XBޣM:)<ⷬxn*3[TJ=JKl7킞@5JHdžM)U Յ\?wZm5n gƁQT{)=!IEѻ c@,ya^rzS13)R 2gIU?f?[=w"g9D)ٚ ~o?t1E5y4׍ nB1h9V6 T5r׊pw2,/k 5^g e!6Wb!g&>vŽT^R]5.oz҇i4Sfok@a 8W{9qLgh6/32@#˿1/X%"&So jt9 ~ K89dќ$$Hgp۟3jfkmi8 v O^h,}M*hR(ݣ(7HȿG튔NJH(kGL8Ђ[Zl Weލn4NH^jgi/A9Y8''\k&>bIvm,eAZEnZ7~ʺ`Y2 5*"xT<FGGnSMQ=+(6z?ȴug+hP,]G]p&DM`-A 3BRqH谀`W[8|Ȃ(LMvqzP{mKn 8;U]:TAx! 5= 귥ϦW6QO"^N0WDa7K]Wm#M8B<+ݡFɩs]KR>iw{-ˆvDROE|ȈAS\q8kUW AiN2kR]s)Zvg?6W0˲ĵA.-tzslaj[rf|Lm15|l){kt?I?1.WcO*<976 hun|w'I-汓ѶUeeYWQ灚(m%$:i? t}*B3=YF5$P IGCCZ~3N64kċwv2c)8qaĚJFT?Np 4l.E7"N-|e=H㚥NG'& "EE07q/n:K] A3GUBםnWj,㘅nzF8Uۍ,vȵ߭GuN1Sv ǃz!: |x=$ Vt.\G@j2%`C /Aఊ/R.Wl-6n8[׃!S-rg;3aߌl'06s<7k P(' HA/QX@*e n&1|s#-0nzUM.T!Vv0]d$r23=i Fqt(+ZqWomM=cHx\h2,/S9s! wGZKf%i [u;}h6:YW _L˃J|,6)SH#Ǧzy60ˑ;|5e4zogem)ߠTH<֤ڊb 6w/ `8:/m| \.g%0X ͒{t&TLzj"3NcpW` |h}-hw&?5 :GݫVᨎ8ef{ 3&$;DXEBasOQ}ƁgB0S r| JkCs6;Vh%&eU-͚_A7ƛR-n.dIpO[I/m?CknS/l\`Vtu4꼁UP3q/VSUw]Aym8zCNMPxpeqyշƹc(dC: Sb[2rCR*ńIXObؗQ׿`[1Cl x X:g _q<XW:*BsdޔR)x}W4;UUrB6*X9@tԤcؒ&b啧9{4Yyx㍓/vC.:e(V훔D #=^èuۿAp%ߵxVn0ZkE1:\kwsI %Zty'tCbaKJ#^\|LA$94ACAIݏS,ltC~ִ8IY᠀dž?3F.#\1 Mb rPΏR'Aԭ?̵ c+.te 0p3]NC$ŅCmDn7$;Vk˜2-ujՕ'4^MX.3&\!ojZzfpDkLH3,x{e1WeG=KE{Ӄ9V VC=ӧg[2ݺ=;1rOQN*1!y|joH6ʚ5ȶ;cID`dRER/8휇,ޞ~DX&yrvӉniƒ,V|ޓ/"Wr |gJN3G0-ڍHxԝ*#97Qp?]ĨXBKw k &Tǀࢸ߅ޘnb*@Mv{ܭ`}ߵod'<Ì6|ZJjf 0iej.6*3=qla0sO_EITpNy%wuZ=5s/);[ {ɰBKebL-EmҮmARRcgyq4qm{ :@r'ֲ.n{H~"\04FF[suR/2*^CʎBC_^;)qܦw8Av.Ъ-x|!CY? WjcecΉBrt%Dٿ0*եY`9YB>$o u.vU?'6M/}ci(i 8VnMUB7Ns"KiLj'&HV:O _ǹ<ȮcBƐ!t1[c=G`q*vcugK9 %;VUK"N6ϣI9X^0Da1 $Dv%~I'{ӬU)8Ybp=Vr**Ԑ*ʴ *尤S 0,--s&0,6IfԳ#:H#5wcN K6B2Mc(D)]xzDyM aR@@ 5N՟Ӈc/9 5“grגEZqUKQs4xLD5l RDueu>4ۗT|(rX3Ǥdb 1 i1X,\A@HE+WOiж &KyS,+)Nj\4QASmx:gp)zYiX*5YI u`|2emؽb@-r1٪JL ~,,zlEDsDmGW8Zj._#([dI?l7\6BY>J͝+VqvmBu6ReWTˑ 7U}$JY ljkxG|X&ۡ e]#"!d .CEs'K$t8Tl4;Ƴ] {9nYW9yC !x1զ% ǽ`&%"dMquܖvrŠLzv$JRd/O8$,cr͵L6 Iكpu dl<),}{!ˏYиٖ x? ^`gˆz)q`x:c꡸F|9rsp`[<|_E "q3FqNL3 :@cT{aQJW 'oa Ѡ*W6^1Ѳ X9IFwgY<,zj.A&۳"[(%˖e2,xN|hxg{E{x̎L&稐c7ڶfL')Iys XoFV20l8%L?<7% )>֙1hu tho%xHVANJ>;1ē!:{n+I$md$k%vT%SCIπzPvdz= }U_8~?q>ēX ^t +g Z I8F;Ioj0M>x]0 pL}}LֹeE/cg ҦժDKdJWvW~:z} VB,ӍeoJ#?P%Mfd@]ʝ {aξ{huldz}R]|>%CM\ ?UOoK;KHs!$.`p0Q4r -FϻN)C8aģiJJ)JV7߰z63sb!?0ˉ>d9Zx(\0|]` 8s\Q;a_*v2RYQ&?O\I:m<^Ts|W⃌A928U ds_m\< p%zo/(h޲2:6Z\l\/E=hgK)o:CP59aOKmYXϩ!~W)F\۸fsQ 7 7 G2X%v jV'Pg).JkAR}9RY;/qc 7}}Ո^tr{+9+ Z?yADX̗>bEƱ F A:!v[Y*تgtkR.uڔ)y,tJ~^ WVJ|V Q:YOǂϪ0l%%+ CRRRvP 5ЩFq_!?85Oz+v밋ЃM ߛKfgL0)۪SH[Xbݠ-2d}g.q:9xT,SUgpL-FlDGd#Yoڱ$,8hNĕaxw0ׯQhAx${Di4/*iYÐ*6g-hlkaO"/4kW8#f"#Y%%(`P EmC5lȤޖ`btC[zwIg2o>E>Bmi饞.D8JֹuO|99Us%qng,׳IT0-f,\z'yne/}rpv(+j5n3݈i$>dX25%n =0q(ci>ǔ9o>8ؓ$p!܀wȠJZˆ8c)lYDezfKt8:Nqpdy&ߎ嶿0]iFg{W_!*M0'wwUZ{FA+(L0~O2uJJPY.lཀ L8ouh@AQ#ۨX6[WrghUw`Jk(^%o ]pz{':#ugċ5 G`9&+X;huM87@o9k@?^qcf=vv:vcEu' @8ʭAvg!Y1wq'fJm H#s1eYc- îTBDRCe:d{ăÅdu+iA+rѬf@#; z5*pICۊvsb7ٔ/-Y4?6|5.ulq7*;cr}ڈ b%*e绩bN7M dž')ڞ.5/@EGkڦRWr@$T~Q[u!ɬ)jvQNgOWDޒU71/:X׫w,&}%G{acmE+tݗ]٘FFG F6X-9=VYe9_C6VT è[a54n>u|)U' UqO*cŔKj} HP $ ?N|}"CtN$ ,^ⰱ@?YBŕk\I> @?x) (L.ߊ\𳀔x'3VhK39/DsA繰ΎW 6TqJ]CbJ :0xN J`B!6o&Qr 7!nR6\_ 1&~>Qa+S  pzp.!/~@v=9Pt&2om獖"`}T6g>ɤ ۰  Ia 1^ݡTzW,մ}6U \8]J Pi䇐8mY'Q&^俦\[4ʀȈ9|3.XjfEN ?cb &- 9IGѳ]; ۲C'R ]((Gx?Rȳr7:^uO:{::{iܠ#iRu7ǜ(򬪚Tq~a[6 :0>lC)5s3-8u8}щ̙80#֘4YBڀ|0:hr@-l4Yv :O2,}=E2&|ZZߩw6=i#\DZT$#T84j[b!R.hAz/&A!@^>ϊ.6ɈjAWP4XQȰ6jO(S!t yڟlɸj-,lswvF_uʀƐ wO?}IǵLIi"J x ͙Ϡ*JU5S6#D9fϢK:y0?B> =dK%94o /h4ȋ)&Td&J8zm߮Vϗ"a.Yġb `[8 ;y .f(}JB9K%zMfje‘VY(jD=wBDHq%,3_p PјD6Nć>KJ "bBR?>e^ !%NV\HsQJI*=v w/E.uެñ%;U9g⋭.ͫ57S֎c::v$ҷNrn~XҾJ e䖲bgKpY,[q)TỢk7T֏/4Q4OSr<~s Wo'iѶa~Ur^ʬ;^=V WcZ]} L C;VJvJ+C\0Vfz0Bk}^r< ^3ԑ+)n\Uxj<I d3_Z}}sK]ߕ!|m(P[/?94tbP4IP{hGPc%GHW*Oҹ}&fndd Uza MRG $f, EPK0LX//k&ͭ"챴g[=UG |Hx2X3w.a]@-[uU5wx_짏!5 z] GaJQ}<ԃ$ RiH( H`/{#bLKMw54;l趗E AE/LgKoUe[UArN7drg\]QdI"7 š~%7nakS7IX5x[Hk^Rmjo8{x*ruCz7FQCZ@Nh|B2XV5er >$̫I0.Mt[$+F~ IPm=X/aORPe%Xz扌7.o`QPBAĕ灨<HӣST*ڭm)>YJǭQ0E6;}rTFXANX̽ʺ_Xֲ$uTS$15NO -^10`GJF _?@+IL>W|.,2RnLvmxub0VD}^QSDF( Cp?Dii8?PSw{9%ELk{!N_(}GUbIK4;'/ׂ2",p/~] $`FC0cIrL j*FX hܜy*1bfO|8Av.j[!VE}§õg̚'5-U%Lye1dgE HTAGf/ze׵ĥnUs ugݨ ],%vp|C؃uQ5=i~p`&:p2yLk _SWwn~pc!(H_jOqy"okj44Aא'_`hH֐l1EnXO\W~B!İLZq]Z"7Pêyh>ƝX4VԦB+7Ks^ϻ[xO ܽ%~jnDh7gV5<) V\n)Av7IadЉ}횤'΍Ld[cD@0Mo{ѧ%'v:VʍV>"c7n`F'E]!rk꟬\d +#_֚XyY+Xfjtz7EDMHq 9MHU J Nj yql$ pʾˏc3XJ HE}JL(,5ZǓ[F^ᐸaQ%67iI┛6pvwTKhQ ՜GjA$1}ܽ ꡻'‹?za}S[}=s)җ5Xk3NzO<齵tN~Be᭞T 5dZy3][ K\5mDAqbvͤ8H|\:t}A" Ior@mL_.4qL͂b!83HPzWiݶ輵a82)m{zds|CX(E;߼Mu)i۸>3WƆ*!gMaRq?`F͑QVEu.٤?:m:(s(asqpOOX"y~*N=Ljf-L8,q ]QB!>1~,I(c`i kweG\XBzD]vtDis,GHoڜb:A|jߞNuM+G+!0v9cU ᘕ9MiO ,fxwHuw50C70?+n YmY7JA< rywȤT]> 1ocW&X$ 2*57[@Q_0tt$X<ֆR[rc$)]}եZq7aUܖ`W%cUξ@XR=\PeC.[=/M\IVPvL ; fԝW"]{01+t[#9f9u#*&AyY #&PpT:/Ok׊-QZ;x9+;[i1SfC(NpCip+hftML@$}b23 Kȩ Fju`VR (-bRR̅kJJ^XgS0uGbT8 ͪ%#QcfRlA1aД9.B"hK 5Δ|eQp]i51vl0o߀4Vj V/w!W"$%!+E6c c%P=)E%P"ch·U`‹{PGBg$TnU-}ZL(Dיy}8 0 Ll'˙yg[9[W@9X76-&wKMA_io<0F% \\u~1=~md24/ZRTl=~ m[[  T tZAɓYRQ &q{1n@zaLv{.,;ݠECb48O BekLXS2_r`!Ɉ=fLBVw 56z2:|̊=Hg[l+ DǾ=R `nSN:r<ax`W]e}~ !N'^JsG6Xnl(Q ?!ΖƬ2 #>d5KOяX&E_=Cprs.v8,ۼ=jRCϿaGE1#=u\+qEiF_Kdػq^Eϝ_T?y,ӟEN&cld>?h Ʊ" `SHEoO.JX}f4K[LЀy²%> NcSvO8KEeC'Ul{"d?7r_켅ZEHLWcf` qwt,ِb/y:q&幠u1\ȥZ}tak+8b!gNǯ 30}QᄿT'7| / E\T* @Cd{%0_!7g A^Ŏ5Y89 %UM{@= i[L5>0KwHAa. 1$޼;,6ւvG ; Zytpl(=<=^有->q 'SJ - $60s#rTQ>&Fd'fHDÉF-R/۲!6\ڸ[&|*yn a{U9pttȣb^QwΚQGyry-a )LxLE;yG+sx}܊2#딍OJP:6㤖J) qVt=` $ Q,s-8!=NsbN"IsS؈|p&ٖmw}Y\ͱ:,A/OnEBכGҢU73m;c yĉsr&XC(83&kE:!H: D!)9X?cZ%,[8|z)faVDx5F*LAߑx[ow@9Iwɘ`zX8w$s=PidZpB@z"$ȝ>R6; %Q;<{j_%2\,f-1mM9?31 02^W4Ruܲ/S~SgF̀~'dJEZ]F.C&04Pқғ" xdiSXA$,`W@,["Y*.Iމ.nq85{Z[=pUd/d1HL689o,q% RިDDɂNjFd', vi>3 B W|Tv[76JLb&ȁL^- |ZЍT~+f %f*ʵG3QVW7MBhV:UhPVwAr'TՒ֘YYsmYGNJY 'Wބ; ڊ̎ + k`N;,c!1łԄ?Y[O+ S\Xj_ Tf&}r$jEETe7ވ1,/+(xvIS^n߿P65qyR%2[ެkUITR XI |ce_JÕF)܆qŕ:ˋ5qf5(#Y64$n/f҄Uנn47)'[x[Z1F";'zPz=t(kL22z@"iZ͌?h߼VC.nfzvamJrpNJ&3NJ9E? u=ͱwdħRh[hwS?:=>IL㉫ P Ix1HU0,&VtOg`}U:l0g[r kE .NlΡ#iSag t,BE<0NNcVw2EF8 CQ{ lƃz/4912X&zFP !ؘ,;f}o.AA1M8de' Emj9(fѵ .:t,-FQXkbPAfӭSF- %'mqA >,?u̠bc >@idZS/\Y(IæԳr t]C$5vQᦈ#v(c\H/"sS[=rཁ"0KLz.CQuȴI,zRݥNjY=Sc,n|lF3aa T@KN핋1Nc -\ gEVJl#rL N\~|MաC70hֽ}E AwZL%oX5%U:nyjpagX\Zk\K)NL/1ԎЁ]%chYl@lV:h-!RG~lھ<L< Q!2n-F߆ɆzơH+PӤ8ZbK!x8Ǩrcq™!ߢSdS0Jfa9tSK='i ~C}S?Xx;cgY-ER0?x5>/mB\5o=rP)Gk" TP(`!qG'V!_}to)@ mY&;M'5qשw_zJ.4ZgtԔqlа[zJGS(Tg$J6 jzv. Gh~a;py91.O/NcGhF2c):블9.`L [Cwy `4aŇir$I򸖫zvLuPb+l)4SpiI[Q·=Oأ[]J h0|KjtAE1d(sz3rk lWEUa9α/7Uuaw#5}ņx~ N/L+iH(tRSiá.ϗtW2MI5Y#>q(bJ*3|41>F:o?RƬZӹfHۢ ѤV>l#dA:۱5@[phJh^3%L +6o 紅? "ѐƫQ^&7y {׆uH O.H\ˀ{rXl)X \1hrb|`pSRg6H+rŕjXjHbTP567bWih,+L]i-Ou{LOz6'H?h*^'*>}y:H}i-P%|lON0&I'c;2(_>/m33,,*Q āIk}ܐًAEg|rajqGWT+ *0&R&;n.hٵ-9%R$"v|X#odQ)'ߋl$Gڶ{-qX/m_.\dw݋A֛v"8 >g<|<ܪ1d?l 5 3m[qZ=Y ^O:>Aq梆7@Jm Vb6ddχ@c5 c:@sYn9v7;G^H_ _ YzP2OH&=cbsHH Z'Mj8G څh ǀm}^ʨ9^2R:v*SIko-vYcL.hIlo@W5Mr迹ܘ0o,I`gѨ.XLuMZ籄GHѶO>'D 8֩游؉e^l>8 -Ul7_GvJ'2 ;42R}\vs/m`ficz~À+.-d$wםR1:ZTJ:đjlR17Q~r>|0ԖWEc$TkedhܬhOIN\G^3lqZ/>/{'b6=T^Dq6e(Ck]BzɐBW:\ 6g7ŰXfx_cUIwhvc_y>=UrE31Sl:rzfLٻNr%LF `B1Ayw`'p{.1m'O"I+{6x{inް :[ Y3:ͿV٫,~2 9&AOC+WO ]9DgG~lx/5LW|:aWN."{'h7{:XG_ BDԋgD(y+NO|i?\&)A,~$/z[w\[;Ë;Oh@ݚh¦ ~Ήv[[2#% 7ղ{LMߖ6qA3C;I#v8LVAz=RLΔړ2x|$RV]2.7g*  I"}uߵ֓xԪ03_@~R`rszxSYɗ"J}-Y[JF X>p,dPq`J-!rwPXf`5ŗ.RGfHP6q.8=В!'"iAV,/|d7Y՚/plzCHJ@'b38RּEҋFc &X2:e>B>tjHF%{_xl0:vEQȼDnDH!nJ*oCD6PH5D%{qxdqmh?z&O#~%,-dOoyxV0_te=Gې+>^+M [-3]kLA,; K7e$C ط =95϶W%Nk=ٞ`M/6C:+rY.3'Rh p\` ֽpH ;Rw&%ڛz n= hsL!fy+sG  PEʣt*>B}&t$ u{u?v?[zX/l;r/*{[h|2*(J.:fL^* 4h<`8~Bp&N(3,r ֢14i֛N$$xf]{8@7w[nsPI={S SvէGCw.$&eG$Xj^_kl=RBZ~g5DTS+N,Jhzf1do8UިX<^ptIqk.=愫:y>p3iuo'GrL-ޛ}/Zb;}1h Sp# @@"Czc7jeˎ(W1#eo4$dL_xWWvek] BU<JdwOccBvHya Ųqjq8uxȘ)<L_HXǴ[xtS]V3У\i/ ҅ p#[q̔6Dد24T*ɁTc@]mq'8}!'k䆬fHO%˼> %5%Po2neIKpoug|T*wIu](.%(QiB|SJPͺ^8<0W]gpb舨٧^3Z! l_L#1ױ>-7~fǡ`+18t.%x7jKn$|8*:cGJ)Œv6&Ji{zs;rd8dl2|X Kۋ|xj?IiJ8ՠ_3d D݂ۓպkTYA\CrJ+HSq>;Tˌ^Hٳfy¤/2}7b[з[]4*eQ^z°aZt 3>.C=~k׺2 6ȬX GNšm7dc-?Nս6h81c=kZ |{En}X%w?;񗷃voeچ3z~N[̌a.D#qZ"Dh́@# lth?^r*vD?;XmeFf=LEY?M>#ܐ8کVq0?ڃsP!jK]BO'AL{T߃b޺\7I0jkBⵘMĕ{4?ԇ;bA١"2Lhw?Re.SqԄnrp_@(o⇾1qb2M|۬Ye U\6)#tfM%$$VQ5Xl2H;Ι(۟Q1pD{]d^'g wF#K'b>SEIv&e T6 +nf#Ƹy+{ր{RN#& Kr/ $M1ˆr8"9:yUS%m~k "GwX.`uĈm%|6 RN3 -AfryA# ˕E;#FmwD'Sd HB =Ԇv2ڝCq=#oN OW &Л͍LHͿP\q_@x_2Kc 'Mw%\čZ 1$ΐ쳎 7'OAFo[u(_2^y!L!)?RxSa/fJ A^-b'@Q܊I%J o|fR(ۮ AcX>J4.^s+tSMlcs-/ݰq&]$ scׅ8KgRx%+E8+)LeePuʉ/so1LA5 QA. *, ZX{>M|S|tWVH'j hnpǩAXY*R_P,EfrۊXyifˆ&7x!nmڽϐ8] yXrա¶^zMF`Mϴgrv$qd~j$~ "b Ad,=3%'y_L&ȩN%urtBbA5"ʹ=[`>Otx J׍o)+a䯊CT~'/d^Nb#(b$VdTF;| -5t̜MnWu@$dT$t블ClEtHv~P>؏7#e泡ab؟vs$\8-eyl)Hٴar`L + :%T&u~ƾͨB2}D%Zjޔubd A> *ߙ ibh3-ϳ9ֱ&۹8x*Mm9gfre&=/;u*Ayfa}Qt92
AM^Ӹ$H<=)S$E} Tuɓ5ͼ 3E[UM FJ aw}?tœP',Ou/\1 +sIS _jϒhc}sL] `g%ySRs+`ĕ eW*ya8ϔg!_֦]etu=j% ICPtHS^B=X%#ƕ7j^ xrŅn|׼j|<癒 6$ 5"S4ܭutqw`2 3JV T'ɞc<4,f#*I DK`jG{׎w "\]7p}$;HQ]OuxRs%zbs(Ѻ*^4#ap*>hô/]Nh-YHEw!twlWI[l b"n wrug[,fw2S(j1Eo-AUf>rCka_fC\<9ꑝQKɮ%1A!)2-ro,3rBzZ@ J~= 7*p>yIcJ@[$2T cڟTn}Zc $eS$X; 6׾@"c:gEZe7pblA1ZL"]u"woxaP@n7Zwӻ8vFG6f ,%EJud䥕 @ D8$9_zĵ@[l~pTW[Gz`Q݈_4n]#M>˩=?R"U823sxBk|Xr_NA2b֝$\+Ba &K^#ai .'uCOp7nmh_Yc֦P^x.Qfg|IN8aTqX ]wZ/ܪpf++6)בn:s?a/nO 7噋z& c! 'FJN7&D6eJ(ɣ~FII9Xi t0s\GY)r,/u#h%[! / Y>l%/VUF`f.)L'MTK&ˢQ~nX t)6& դvEi4pZ׊Wtz fg&ח黪b:K9 Y-M~0H& 7+)Th gd g_N. @ZQf[(NH Y' c).sr97J ; Gn$Veփ^*t)W3Hё,89T抐LhEi!u]Op f]&J;8|c(q)1G\D x W=jB O`&-;FHk_]|~@x;Rh_zfq*wQoŠTJ ^?O?۫sv9 dէ`{V`J/Ğ Bjh C˒T vYM /?#a@=Wj1}zK6) 1 s&6/=Ne',9}R𔢂3e ϚߔT@Pxٻ 4l!'"j !z{pmܱU8i-<~ftY(5§k8؃o`*i ~ϜrRW<ƺ7PYZ@T($ӘeE(NBDBQE>iO4:,({DPyh u?\zH"Q'#vdmnAk?ܨpxȫҪ @-ͤBʌ{q+֠&[pƙ]Ǥ}%7גd i A:Ihv ,#f Lm*#{0WC,yc؅ïTBԁM7r@Iyj3>zCm ,@.炾dawh$p&ת1B\zMju ]/h7l TƟtGza)OT?3}Mఛs8g.i)͈0Te ӞLjf9{Rbts7Yk&T!|JFRI2Qort(RƷ5=Zz 3 ևNQƭE4|w2긮߳m9t#MUhV:X4`Xkݖ)W'*!Ѡ&=+ EëgӃq*5&)G7ӾsH=C:!u64+iǮzVM_M:Lk%`?DlZ İ;o[ “۹B\Rf)O-UhO2KJ)3 9+"dKP$K,5o'h[4*TNVʭ(z:('/ [x`fqts8#`b$cL-keHxY(z*Vھ Y<3vTVxvǙE%iY| ] l+٤ R$۩БsٹZ]ms5깈8Đ2)ׯAtY{>qdh[bFysP7ZuSo'{4Wx/ʅ][ ͱ`$~^⤤;˔|}gb,Nne݊sml@>OL$kxVyR#0_Ji Rwx h=o zU vXz)d217O{*`B d,!Ik&axwf(.̄+gz*o*YȔ٥g>0&9ll֙8^GzGBJút;HV9.u>9$,i40%)dlDm{5?y<Ԁ1i|pf yuɦ>E פ} M jIJd!vn&ogk&TLIeğݭ錎.$.;A& ^R bw Z4qN38'`ҖR|~$JkES޲H`0SLծ1[);'t^L:ƿ laB.+Q[Ǔ6{ެO@tت=Ka xyP!F^.#3:?> h3eZ ]i2Ѵe[rڍ YOݫv: H$r z1 מbsS=q* ~ea9bV@u-nnO(TQB0jf^2A%7&-=6B֝B_Σ5EVOVzd`!e~~'%DCgusi 6N#'_.4E!B S6;sD:ɺpb$o84Nr?+zz18͐ k?PrR+ ~y4  ҃3$H(Ώ~nXWǏV?Ix ;SsR"~ &!X^ΌHJ`ZO.W,;OrH:z,'2Q 0f#>B㪻p<_rO"4j<`5M}Zm,# nxc: B턘3w﷗vY\40}E:#sΆI;jTʀf?Y:-֏s~)E++BVW[ Kaf8 l6iő.е Mzui.xcG-7th.t ݫOfF穫XO]cV^nnQw0")Mȟ<8&׬f& O~nTuOz?$c# ceG{\g?qze&+A&e,q)QЧs2V`D#U X~DL)8x x2[WWd+ ~uTxkav(Z+HDǠ_GqC?ϕA5rI9Ao0{?Q63܁LA+~s*Iɉ$MX]`+kUB斒[Nғdw6m<&G{ E8Xbe yĜs@2@()RE­b?~f PQC++=9ZdMզ:y:D=؅^rYjUwWjK tdߒD|s̆.Rb=TqmDjՑ df"gMLBjsfcsEkfC=Fg)]f2wٷa !>dDsM) y0u4(esLGHVmY_GN[E&z7e@g^?N͸@Q2Cp~9ZzTc\P~t|^c"J1ae\]$#{H-gCE.A*A*aBA'$Ef3C4qE_^0ICpkmMƿW=:vuqLҎw1S=vVEaRah)\Zj> ff|1r#kICjďQ%g4yp˱s:1rޭC)\w=dӣ~R&N 2V +̐OUztC'3]l|n[F5w갘QIg< Lۛ#b*[Yp_F9e7 Tͳo'Db!J]5Yt2|#о (u|xc)gsdwF jɒrcZ.ey_ɑ32F:ۖU#7.C_x|@a2X%sn}{˲)H^r:T6˾lል5Fxl$M ^~ Qk?\`-[ o \u}? i/ 'Iͭh(H79bY"i7Da$J9BXTz* <ֽiz|?CaθOv*9XL~LuHm) O]C+sFS VFeCV t{m%/)8n5H+ȑ'#2f!e?{55r#_SJ}C!紲p(m۩FC?b-G, k iI>qa={00>*m6f'<=ʦ8ʧS 'sy?Zba';"LO=:k4#ICqLf 'L'@= Jcc8}2HCi9fV璣),fb($|VͳgU,R> Bimpy$#qLP"FWV9ddg}{){r띒oFjC]hWǕQ9ӆk8pC>g&0 PKi7?{H*zI>++dŽ%_ ИEk Y#g#?*}9ῄd Q r/HίpvC` (ew)rZJClH5H^)Nzc}Xُmpi]Y$!G掀xprМg`shi,,%F:77_z{?ɭΙbe=|cil{`|z@`HOHy37[D]w=/=JX麜[G,邑Y6.8XMx[';:buM׫KqĂ6r}=OHW.Rm׭U*-MLJV<Ž' F7~WʽyfaT\jC^OfҐ\ENc:48 W~<̍Na9ylgM9T,FB:I*FK 暗=t=Z,v "#i#MSYT w<֌<&yКxS}9yg˻R3m*lջXF'.=p^oҾ3Rz#ռeRW|>Y͚+8' @ M3bV&G"^cE]?S(Z3mqNtp./? S P'V|9Gsǯw0S[Oo|(|X#{F=(C-45+r`~١M'Ҕ- PhSi8Lq Cv2|o|DG}"9<2U*("ĎJlmKqi`J@ڍ1uϸ793ZF`$DaYloJ8I|I?M%\7ahr|WOT"fӹ:~p#KMAz)t!jn4?oV3::e#܍ 4L~`? >Vw9uNn}$0xg0"=␂p^WX9fUOh0!ȓ<:4PUV%įsNi^CCKs Ͽ 1#%? J#H,O'$ps@^4Ia58`\PI6ʤl^*:dhy{H&Z aO L8>YݲPnɃ^8!|\FTNTϪ 0{3O5<&J(zzҿNbR$6n2 )F#Y#s^e*x}OWxƾMh9m\ҁ*Tt[R4L:+0#P="R9nPB`͙8]bNlVk:Al暝T9DpkpUD\RE2tA:0CXin!UW VOvbҲٝ;DAq9XxX*HլA'om%eD?hy01˞ʜ8V ` t`i\`m1]-tZ^" PAOܭjk#av6<4`ػ~IۧBh+Yɏ’2\&Pƛ a(;&0 2xyM XHz!r];J O-s`|*ٚ)FN1 ^l]ru9A>-)yWB kZg,9s+mZF(ujY~\~ .V9`}C*|~` & tr̪8pBNm69߬5m>TnY Q0vBz,z|-DՊ5At?牝<xZ1UKt}:Jjҋ͖`_ܩB*pTpF:Y(XL|% Тw=) +{}nFRz$l+'&c`H}/3gW.+\i/hkolA=C9R0lqB-js]=Ԧ/K> :fVΌF|S3EIؗgsL5D '0T=A`+`y 1$!6OevgPIѫ2~Y6ǕxR}P,N_O+. 0/!Ykv:s?6ߗ ;DI :!!A..A'sΞ' ^د>to@Gzn #=܃yPg$':5v\Qq ua1SDg'I2A5cev*/b.v CPG@zh?oTJQ?Gn0$Gɑ>)đKDnf´[ykڌ4G=c2 Rqn#(ɗtJDOkˋNw9flFgcXXlUɪynD{&w8,&!Sm+t{a5r_+^&h]{~\UV,jJVە#́ί$7U].Z`M0BH+mɁeVRX \r]DZ4T!a u2O梉LHnl[z9IFT)[QIEbLmK=( }hB#\/F\dU)#8]w"g٢%6-;N7Q_]fsqs)&WfFgi:wM\eu#H俪8Ƭw9.௪7ߺ6\3,9Yvr̷+wd֩9 )^AqtꔂNF.0(Vl-4,UԖ$ך=[Lq`|WgmHZs MCe!983ꎂtx|4P c38`\v$ L7b4(3}8)qdх0f qv5.mNж2I{4xR@ފA+O)Vg@l~^} @< #pXe3*ߚ־5Sh76w{ hB&}=gNY߷4TSl!2}r5.}N{ƪ++Ȉ R4!؜vSӰsY{/WB~gnkKu$ؖ!beY%mHv<Yj[qG2^pg*׍UhNv 뒾#A_/oSg_{y,cN̿BN;wKtD Վqgc);&`y~"uŴwikR\߳Z 2*XGR#{^g8CEIB@V^y,\++ISo^KXi@GoE{ubRF©3/[Wj BVa?^w_h".dDlZܶ0rː[lg㠛mpw`PkiedF_J )Dhp >7& urgdkzdǘ. ǝ~O䊓 Ks}~uvTaz<x:w=ݓV$#ZtFF>UҽEW^K1).Vj+[ /hr{FĔrڻ%E8EĚ%PK>s##Pt׭rU/Nuh l.|p꡻^]yø`ur7[׍?=X@pPY,op2Ajb`1p.:_tFQ2N묠lƞFmk9'۲Q>;fZlLFМ{j˧iaX!6YZQ*fR%;8.;s;#"b^}KYJ/6CNR3ov;N3_j%vRC\@K+G;LM7ږ[rܴd _-">@g\# k/d%*ףc K3v]҂*Ɩ ދ: 7Ksݗ`jY\v L~m}!Ml4_I7P{6ב=xUi ^~VR=h*cz+6j_u~3C%v-=zI3Fa9>_{kO/ZUti<9ܬFg>M2tc׉,4D]ӝ6| ׼.[ HɼJ4[|lO޹s?,8^l\1٤n2ڡAC `5?PvnZ.}pT|?WXk;~+~qk h{qZYUdcA5/x:/rl޺o30"!$*4]}q7jK? nkWl( PB#FWڐwW d^!fb$KKHpT4 'b\xz`@h*' y  ~B3& dAlmC.'d397`N g%m-sA!]Od)dņܹL$ e51OE[s27^LHǗiy?c76qr%yc`mzVDY-%G[ݔHiؓ~-2{ȼ1ͽ><ĮFԆ~yCs|[P ͥSIxUF QxeNTJc]*>H_o ȼ\`z!8cLkjk&#qɅ181*|>@>tocxA,>{k"|dOoe)}J6Xմ 6dxl0q:9֚s5z,2B2g ^}f=r>O`VS%?:;hJݿ<"( efBV .CS4 TٓƎ$ 0bXx nckCynpB&n7 7f'{rP?kxrM/⴪¹0pfnʕ>Bt3DF,\o)ٯ_`~%=X5 jPh-1Awp=u=/:ECDlKƹa9 p$B,&>6~Ӯ>x0&91Z՜Ó½oo`RD=)01ً>@~/3Jw'DM5{3YApfnw۠G`x47 ]їưNX~堾,[ԤN  [i:c#EPS,q9Q^˜$>]V}o &$Zi*[-Hitlu9 1 |rȸUL^LrQ;tDsGt؄zEdػՖ2rxIDi*ӽJ؂?,mE .P3d("Ԣ݆y$@V/KBO Fq V:o >麣/M~Mf FJJlER\#9EB׫(PfYY2)*Qj<:_E_I֨ Y @]>6W_{\9DC {;{:ҥez!{F 2KK`q?fn%Z9(1r5`-/dO TLN]Ɣ""O!g4PЩ#[p A:G:Cg`Ue,®C#k3bb# L%D7* ./x3\mYQ^vڨMVOj: }j:}Bz/_3uH5rI;"9sLI9wSRr_Jf,Ŀ',lךxӥT(Wa g?هz:ld7c+YF xj֊`az&<2;1KM1VK ф\F3/T*ju Uj_u(_sXw1m)DҠqj Cem, KjvκA:vh> O(seR/P=R<s. 4>uT- dryv70?q}X$zQ?IooBOn4:%O0AAQDUSe.sp+XY׌Y7KWwx|,O-BrRT{;(Uu0 +*ì_y0ϷMk*j~ec뛯.\N5m,ZZ G?c32E{)"P[)PS[`eqF"-j|#"kRG(EUx~w'W=|=T d_$6)CAq#ae&:Cy,<;&l snI ޫ?zkAW=N{ qoz@k! hM38lc7|[ ̰/$0ZUZXY_Sa?ZQOr pm]8@+޽QѐEB)E?gS#-bHeU&pƱF,wL^˥J_'x~g@ʣB@Tnu b[5J1vj[& нBHDT|sψ'zfGc&RQDb Ϫ۰w*^9;~3YֆI @CYY5GaH\;e&|Y~|HqyglX')D~Jfa ,Fu WĩS ^O|~ś{'9w%EV6ۅsQP~cL~lZa6ʘ |Gx^cZ<*k{xxEtDTULĪ)2@+&W4V̠oڻ9! X}dI8%4S$4kIXT6Z${Fa/~aXE]ΓUj\C-4?NR6ܷFnN Z*>Մ1cD:58:Vt!r6VoYOyI^4L~9*Xfg)\Q(ʊ^r$_/uBҜӺQM0ZP,C}H;n@yy;,G%'?Hkez.~%DHiZ[HL7SM8Z$BhJhµ']hf> ָYŜ s|#8< n O0w`)%"Nq5 ԠIq2a8#Q Ņt,uUw=\X#ʨo|*ij6jccC9;wxiPS?<~)MY$f5=p6=]/*d>1N#1`jI%lgLU҂TJ1 ,WZYn. z%$x*ӷu,JPĆLέ'zB2W>xvn%mW4[C -Ro&h:6o*dap&3y.PSSCܗO 0U?>CaIqd}of@M&fc ӝONܳ+⃕HR((@;BVOUht\&:[e!gWcMT62+& R>)ȴs2az<`&G rO>{gTI!a.,i{yRz% JDt!Y9"3` 8e'4OaUw@cs|,d,>]|e5ð( !xHX, \ 8mhPV fb.ےO( ȪU*v% lWfrweĪ(h%58 :^NU+Kx+w-T!oy7}_'>wEt} ze=ڢ 7R7SqFjh5L[fڰ! #q :BkӮiKHҍ\B iA? GjoOEDYa_snk7_e#Wj17JW5;b0}-ew,p.9cw8o~ 6Hַ j{^r%|'LjBn{^0JcY6π+r{j t?5A9=f@BE]p볟@`K Z-$c Nls;$7?d ʹv^kId6߭D4hPeo 8n9 si -3+aU/e9bC:7w m ||QdS}D/ᡙ;ȞXړwa}JQVs΄ls˵DtsoHSݦ>F8(lPGWjuLq}TjY$) aӣ mYZK?KJIc*q _f+F-د+BeϮΝ ak.O8qp!3FtI+uL")+zGim"gd*qIKÑsүB]`FS8LnS-"Nz]#E2 8I΋9Ь:W\d[hnADBFX9HP#m^]^XL䄬GĮRǁbM0lx-I}aV[KQ&؁ͅRv0T%I$΄_e#89#':FAhou51n2!̴Zޭ@\%T*j@@SMXZ}tf ̕lVinVs > x^5X7ƿ'i]zS黤v)&4LJm)>fZ׬GcX'@5),˿Jl{A?5 O7tِ_φJ~;o]į^Ҵ=Q^1G`ҜZPkwwJ^wܦLH8Jݘhyv@y*{}Jx؜YzBHfYWjw'XpR3R*cu `O=6dCJ `eF4ASHMvT2+T#>:QQܟYyɪwTdcK-pȝl_?v`r$nK#^pHzS[rahcCU{v>qHe .% SCoZ ۆ7e4zcZ>QLe)խMd3@&WˁBBrQR'- D fr~PB9X9L|ӂFx ݢz J҃yt\.̦"BNw#R e>o[wx3b>zo!>eYGu RtM|?c$))?Q LpWćQhH[b ]0TCS^;CgjFs9 IKj56RJ.E<,')!qVp4ʘͿ{P#pGa(`.Uhp6?xxS *r^3fSm]=6H{ Pdeirr`p+ktHBs^W[刂if1Ęr#k / &(pDg[d0 gEih xf?zBl?aڗQVDyH*pN|b?+ 7T̓STbe r+zZQ?s%XX hr؄Қ]Z+HsTn,-e?F#nUM5Y'ҟ v]iKTW4izޟx$¸-`+^Xx6#iYw"{FgrBK3ho V(ksbp\֥*z=t˧{\XRE/Lb7*E74 /[O/Dqe^@=V dN*E޾q~a ]3_qVKe\}xאk1&ԑ-Mu5YAN$iz_zuW.LqIJ'm _1 5g!V)}2v̜VJ+F}U (OlM *3:YUaJR8t&4_6*@oq-d^ԔV=J;fئz@ؓ G4B 6V%PH.碓{v&PMa d^ oNi4åsf;~xUSޔHe D ]Icت\8iH?NCl^jMp}J}/jS`08X;4CWyCWU٪Qg Lf6Q RrqHiR^V#)AzdUWjJ9)gʧ 1n j+wlZ^oKH1Q.nLoH&"݃MfWAJ4}i&X?H|pfe5v7KacTo.RbZ%4buAZd='PV%~W'xTVz M&K<{9vk*5]WAq:,IvFQɔ{G<+^j#0^y˷Eظ[+cVJ83_S?!0jYXh ³'P[o-٭NO3I7<Řx:֗O: ~ӳ9I'|TxT/m>;z˂KMr}oA8PzIc/\ȓ*!S.GYUs9lRԬRYl <ѿ冇(Rٝ,,(zPLz'-wH 72CUƤ`AfI=Q c9] Njnr()t?ߕ::r_kZ ZVy/2#g<RT 7( > =_؟}5:GlFS$&47˸2Kψ.MP+4c`lSa`hT!N4f7ъӻ !c~Vl lOIruI+ 1N3^QX9.2 ~򆎹 H߃Rs&/D鮾s`Ms'd-(|WQrqȢ6fAz啇qrL)؁,g/*4ho ⨫jo7X+םAAqIO(ҁ_oЫPlm 8;ɘu #U.4Ǟ z|/) )ɒ(޾ cF\vsY nXzO b'P.߶.A;sq5,rA;&z,+q(. dtJ ;#/6Tq4xbנs, Vf`sj9 Ѳ@y g5vQXkjDe\}[(bfيyc&W/${38!YUf/ymN~ +\\>Dk:6LuH״?Q||jX]:<-%5%G_; ׍4ڑvS9v gdBsj\`r0g2m )b7,.-Đ効͍[j)6K`3-ddG |q!MJo@)jl[)U 2SF6P= qİtZS,{$_xh7sbKҐ W|°R>qkd*x%E귁]~2}ĪcȰcA <;b Zٲ{jQNpE ,er99AFZ'ڑyqkQ"⬡id҅zr1=\+]| `MN)ה.Æ;Hd둕Wcp:/?s*w;/h#Ƌ#]P7ޯ'!珬uY= j͂L#Vhxw2\M}nO2D*_YSlq0@uꇕ4;q᫧P$:wr)KPU$&"CC=8"{Zb?hոߦLy+@;V>둮5t$lpuP_uA޵m]65Ah@ pVZr+Fm=zōKM9rriøbZވVpxY'^"r?ƥBi&> ,6{V,ѤrlKdS}W6lI$~#l |_b=σ;7}taڮ6of3D#p<$R9!0 ixG K.ghUT*Am[$zXZ+1:)m.URZ 1={q  t0l[*9D8UؖwOm*D'uH IYiB0g҈ K TԦYq{@}"dil;]`f>:fD=5tx]s ө5{UjQz WGϐA.}q[㩿R{IbTvөvi9mњN/%H%_) dGcфMb fįbfЫF<3ޞlm.|8 9DTpIʬ`pR~W򨧎--88\pBu&B Nf mm6d5]~ƾr*b7w/=r{HG&iﻅk?x/S1I! ql;%=z]z2<]. >W3z\M Y!&JsN`݊j>")IL %@MQ<,s B"qVS?n~Ub[ 40#$DҎ>惞O*uLw˼uV$Ɍ6FwޛqjJ *+[0C鮩rKN 9>(@R.rf%cBQ2͒Bt;˖ 7}ᖘg{ u; <Jҏ촏eic]]h m3$fKفF ;U P󑀜(J",#+Qsr\hЦ d`"h-_,[Xs15D +Ӿ5;$ q6HwzqNԙny>$YoBTr3\v׺h)jj l=A^ !;ax;da,"_ vOqֹ֢,*;^:ZmH6H܉+gA+1CٞA^d aq5$ I#-h˵fpqĖMG66f<4D&KQ [=zlp&]撍gWRUVw AI#]h4h}2ϳQs-*Ԏt{HP;GG"Øenpx%j͖ F 9>f"P~goEja}J#mQVG9>e7jᶳsLSCv=d8L)8EuMRlb =E_R =j˓dS 58ΌKŀ\|72.ϫ\ -ގ ܟU P{g;shn31l!(֖Q:3hrUԃ]̾^M']۱S=$&̬-Sc)4s"xd ӗ`3^?H)ʀg'ɉ~ Ip>^Ҹ2£vXMm]WIbi&3ΐLM227+0%eܳSc`xlW<8!3=i^C a<܃8a*uZU,;k۷22М21IPn*ٍPxsXm3ku*C ⥍B#\W\%ݡoGnuM-ZT1Aq Pu6$8QbPTS&lG|-nta^`krO=O!|p՟{P}^ʝ>ꙭiMrIBQ(st'&:|F P]ܠ`q>b;oؖ Q0z|. Uny+ߜȀ̈6b]z۟MTad-׉uً3X'YbJz}{c\+@| a\7IɰIqԵ!b@r>ĚC }E2QnANť2,D8cQJ>ZGǸc'CkY__u 5$TH> 3e+(nO]y4P?Y{׮VIm ^C )"uR@@p>LΘeQ`ӐEX%g0voR-M;6mG?hpڌ~YVHX-Eo\rE:EA٪hh=xE*WTbI'Y^D z7QZsKl]Z/ @"e˲S$XJ@TODlLT-L^:>/VJ l0ENwsQM)('͙_ 7䱨Xṙ5tv~aNwoƚ̙t 0ܗnYq{J`':_!q;}*cD`6OAE83O(ze @ieW˔\;[ .@uhf@~EfBaJFtLwyx6wn|^&T90}{dAM@+#~FUtC~!=OTײ.P=ńn =>w @ZO w7  嚈i3)Mz̛d!J3htoǍW=T˨Ws)2kYGX6FFsNUL3ӲsjٔR}Iph[-qNj%uY8poTm^w4EktHI InUUQf:fAH.B0||FoC`%DS$i /D) >- Bc#T :r,0`왼. Lvϥw_G.B& \M`s!ͭE{}p&y{Ҫ30L2h&I !blG5_Xfߑ\ms\'~0ij`Eݬ]Ȟl}r^>lh0uh|D b=g;贱'j]cBBU\(:SP eM-;&NTc5̈́,FG/$Di CK;fDp6`P@U)[RؔȲf#\f͊6XhE"qS#<*]+s*ȍe$i9B%gsy}0Vqa"DA59,$ㄕ aQӗ+?۷q* ŲR׼+sqGV-PDr/<2g&$TޝǒbL\$^c?sUbOS߳[4XpyO#+0Xa,0ؕ mM/z1hep~* HOip*y/q TX2N\d2m30QEbnˈ)YP>Pҩ)u O1-@VJv6sJCƠȩ|vC5[t{b9Қt<:##(g  yY{s> ]Z:fWO)kO:~^!cYRn/)Y1Fm6wlE7/~Rgr!a\tQ0hj˻-Cs~[FY!ÌUP=aAY%zeoV=YļX9&pvqFR[}M3]M17@=?Wy_3ݠRNjF mBnGˋ۝ed0!1h? b >Oan֋^ώҍPƲq йrJZHN;}ӒB@ ,ӄy$_џFYsњM/ #::m*/x E^&aU"ĠKcNWRJ4B=[Qf,X8 =Xo[XI`Ez{ץ{4:䣮 q9t꭪=Dݠp >N_3Y;<~pބ)pEH۹Fg0ToXu3ε0VZ.Q '%t7;^i vlP'`<| ڇUb?qu#t^>At,Us*1{pME컔voYg6uc4!!'UJDDNq;JʰnQ9tox^LճmovM?Y2HKWk8%&_ٍP:-@xq.b}Rt\{tI3Ɣo% ]+ P+9aXk&Hq&#vx+s\ [ZLEGHӪq3`[UFDiA4|CDc~E n#e/;%g(qsGab_7?:noSұ?rh_뺋%-si"kθ3U %Fvm˷&j4'~/EZnND%\fk% m2ކlXW'wǤ~ ʜHxM*1~4-z/ےgNaȘ(VΒNM`K+I/e s1ZrC^~QHpw}'ڗuiuA$7D H2 bs6!pwH&u3 Ea`k#O#@Đ%YNB$ P+uoFfnKzF; * 塮PZ;e>)uF | t:ל!t%M3}S5tF?KBdUVKe~L}F!`O LMqy7/ZmX"I)=)nzl3e.7Q?Qc:ҡF a4Y ݰGfߧZinHGĴQ(N%f~< ˆ.@_t> /lDA9(s\.?xƵ2ɚ_$5@/ɦrZ6Qx9= >B*efAHHO*Kl}ie+ ](\dd*( 8T1, L^B<0q<(9D zXd0SK^ïN\zroѳf$cy4UR?ثtT-҅tyG&μ";kbb@\鋍)x %HjtF"@ݩXZӱ¬d{ 3Wf.d  1m %[ ag#z"mh gn`[Sv2㚞/)>:J*TE]l jT0 D8mXgot*nPlv5=(im[煦N̘k S&i"+p㓞V[דnc+]#Mt{ivNV.m#pߕ|H߶Q`xϼABQ7nN!!ÊёE\!oz„gضJŐ~ mӌO3}6JcC*z=@av~f+*zT#^ڞsw*dfnUEȴI7'`4>82%lG:1,eV'E_ ю̂ϩh9pFiؾ~px:Rx!"O;07ŇBJ qG.fe'IVe -k DZJ yvy7`׻i=7jyCcG)/zF'~cᓗ\\pޛ$K&LO>'Z4܉ѳ״U ql'lIǟvlvHvɀhv<"gMJKgyUO;lǸ5s _?)Xpܢu[n\ ?u<67^O:cq'zϪ侤!Pvf%$R^=_K6t R zsWe`_񲥉ko-AEϘޤg=3 D3qwq s2ÌOܣ h+9FBlA`ڨ,D6;T'DΨ'yO5 ,7*e}%W`}dƺ);W f U6:^35xXR79?\ LJ+,!#*)klrYKl=c7D^vZYa!j㰏:2*䓁w6 {9<{)C נ L]e[fAd~ FSRiVM-k0XArꥑl,`!l@FRGg~n]1Y#R)> Ѣ==f ݦtmzpkALoan~H͚W,R!E)W`5e\1el 0=I'*gmv[!(9/]*B*ٴ rzΦ 29Q{WV?p 4CcfkwA,q>9T#ct ~t)OE@ʓjx07TC !`4 k1+;OSQ辘@ ȤW)zYLk ~Du5%LeBƣG%$ SXMnb;oLDqT@&M}J-X¬=(aP+."6(]2M2bOg Ud>[DJWW3!7HQyIw䤹N23 =QY0&ޓZhU w%,ϱqe4[ 曀4|&.^#vt*#,f,eR R%,m{xG}k"(dTsA4 ,:%Y=P Z79dCv:`w 1BkK+GN =]zN0vK Z WaR { G9z>&)MJEdyd!$bLCvDW0pP#/63rhy1ꟽACS=|` \(7c);r`QøV+7ӒeIil]m7g/ `TNu=+HRr6롋fW~{2 @gRmn[j"W}q]+BFgTnQ(I"uvY!}<$Ak*φ8}Dr#iG2'(cH#X/4Jw"M~=*LE`vCu'4NmNv͚z*"/aoCMrlXn>_,?ʞS@ppj?ؑO+ e7,:_PhQB 1d ҅BO/0(tC;%n_V\[I Voވ5j%ӆTv*#ژ{$xy҈aNY+|szAv>6<4 `X:rF jmRף$H0B.Q H8Q=[,4!D[6r@U݊嬞3 A`EԈ1YymL}QA9]H^D楓gL־أؽ@r*{yu-c:ąNT{F!'hۚJ`G@Gi8^1=cx-5LOܞ(*C̓C#WI8}Ch%[c}Wܘ8jMD+h,kDd}iًQHw4mFy;`yJ41u, (E>~{Իw0V]n$|ސ d0^r,]Ɲ ІC@hvtқIb-bMY}掺6U\,mЦ>UkoCHηX^rfj;̰;4XotڍYBXpxTBvc r:%dLAiM{.p'6 jָ _hL. ^Po}ώڎ*590hЪ8On幞tmlșec(T;4F 8\lY]Tulܛk,GnHp%/'ߙm}{FCFK1Av-oG(يP|F%{Q1gjkE!7DBisHZ_9tpީ:ԙpNl ;N$Z~zFZth_C!USOҷ?G6"=j:ٿǍ! (NF;oq ]'t gR>UWe,edB0)W vQ0V,O[rq~9^-"d1P&^xyۙ4[ͦL*o3.k=3EPp«e3= c.‚S7ӸR֯0=ֺQm_qbݸ8.n+QjK bה" b ;$^ TF^Q=ڸg!&]G$Ȇ%\ D9A!!kB&1VJK> V3CjcyJߜ@UQt%gIYjv9[h9/o-ܮ6̓NlQ2.$Jcgй ?z]U ]A^v}BfUEoLuNlx`8 \\lJxZWUIEƾUmnP4_=`5 ɨ"YȏXwP w7 .T+mHqP/[\c̦]1Fb,йcٕզd̔ХG\.㸳!qnVȒ8a E~(;fuIS7 \z\u]T,*dgmmUXhVbMizv,bm%jўS -0K\T{GUe%p3I':XE8/2(;|C98$:8@JZ]iiq;|GY0Y08"~u /&A3%FBc|Z•dlOh3Rp=ڧ TItRffp{r><F{2]Adb@R+y 쨸pW黇00x. .߯U("Gi ~lϞD@i)ax^T\e a*OchqEDxUIbI+NWkLƪ_r :TVWq,GV:v V ~VM @w4}2֘#ήWo"miud0v vJWWÞnM[|v׊iB,@uK_zv2 ja3&Pl)D\<%m,ua*,L5J묂|`g[N$*[ǑW錀޲u>PO.>G'fš#u o> Ji,٣s9kjA@)r2 ]nL6XgYnX!'*0 Y^(&hi å@>b=3RtT&qShs䟣HnykpRʙn( fwH1F3䊣0[-hOΚh +_\ϔm e 75}"V v};C`T"~<*ܕ=H'E+^#|vu :{&Vw2re~ $?G?3^*vHXԬd⳯r2+AJ ˷=Y'SUZ -OڃxP ~sS0#mNCt6 X \g/};)Qc!D7(˫[GŦ%̛f}!܀J|32[Gǂ{q[<-,C4tG@B@Q ]ׁo)(Jun6_}g,NfM*!z*Cm3T,jƵ{5&u;N[*v~IY U"=o?kY/ "kt;kuZOHgq7:::H%"ƫـu?2 # ɧuS9x@JNmCD%+e>:R3J98#j3':~z84Rf}T~0V q)6IL7"&|[v5X,5B>ύ߫aW uXP-I){l]]Z-\HiA5KaZyHB]G ;̈\d]c`A0l|Z"}fk/APh-/bMո;91dy/8yN ܇4IF}էġV+{(G8>X%VQ=I3,)3~4dQT]O555SUۇW\fW-K'ં<6NZ:[gg%&B,23A: bdrd!US¡tgvv4ٓ0 w d(a>fo`Byg%q`^AG:?ENQV[@c-’ !{{~z #+pHcoj~w;^ >3#-:MiFn4޵ 1,]nu ^'Cl@bMg?6~*U8ӹܨr (Rm?$6tzL|o!FY\웜vHV¢!{_0˷e3a"K)}X\5::R;cI[ OPb < -T4&PQTζz%UEVWt{ Sc+A[哠-PCV C( ;#^!!d<cvC,>wbQ,$&|\p$eB+LJuΖiP8B2 FQ?펆<:#dv 1d0|wmFBiA"]!8u_#B80qT}b3Q96 h`yZԦK8!u# Ow[;|pJ%Us X*5r7$8cBk C*b/d;'!y/UC6>C\2[e=epǑc#ó7svt\FTǷ+턐:nHì5JgӔͤ,WA-(yTghme0"8_Pg9cQ~cʊx}hagpU1^A9:cW40W#})7' WC3||or}_x]=B֎y KBzK_ȍm(/ (B7!FYy2>]V|S `Q[ bDuY+b}bAqw=&[ V '[Iދ߽q5nHgH庳 M\8a˞#D"hos7ßueĤ0uT@{v0f{X"8GBDjzދq N 1pt g?–؇mJRƠ@Vva_9 :h&D7a%o\S-aWѯVYM"@/Q/==$s&bU `#Jx?plJ^x4RGRb%˳C ?0L/dT&JxԻ>^N}J1JzJIJUZ&m=AQ ;1XV%^ ' 6GZIڱߴH" W^Jc 3"6vF 7Zy/UWufdhˆ:(^וgivK8Ҡ(d eWPbV7 ;uQnC^䁴g]+tKMu޷G894%2o&[}H5%wZ?xȋq5P's ٬}c(jx66F=w&aN CӀ#JviHJj#SuLu q^ݥ w0""w%y簥q v37x<$o%>8))Zd"óY|Xq$U{f\T KvZd Pw[̞gXx=jz]dqƚ \kE73RFy?kkf)z թfzqOD%.*vA,$jlma͐ѤoBMtl^xԄ\>C&~iXt7 e2`v 'TX|ZH7jJ8W'ڊ;m\UZqԷ09V;q0\Wyn^ޞG$tH?W.' _6Cn*6~ؐ,nS:_,~4k9Z@N#tRo HT.>#M' XjvbjbaS\>3XqY ! >&_lUZ!1hK|<N[#9-S6j[[abrjSMw=KPXdB/FRMѦU? 'TwcWukx, L'7ʇs9ͱ-ry;["nVG?ײFftUrF߼Nv[/8paM8Cq%%G6C[5hܳ38AϑBEr;b{L0nl03BvX-9>5Sj/Y%ť8竹ȓ-RCo [ Flfxɯ9 ߲2k& c^994u-[\WPhmrĘu'((ܤ^GA٨?63Yg|Ĵ|a% Lp^mrԆъbS$Uir//|\D1`1 :vS.%U%…L%;PTPd10  i-$W* TM{'a?q$,96`ˠ0!65ErP_SHqOwpˏ:`*G`X'@>QpW5CWAąGf(np.sΧрg{>;`܊R%̘GKi*\jN 4zDca32{捑_[6^*KDžnq{^ϒ)t }^%΍ e}ԞBqu!g''={Geɚͽ{ڥ&wU[X 1WfO1Sv|ԴWs OضZxUBv:y! aT=np/Y`S\ڗH<| &vv>g{±p/<.ؐIÓzt"ڴ-z>+pG=Mܻ?e_,ooP;ӀFɮjjG]{ɢũj&4> '̙}g3Q ǢB+ u`ǝU GS/\>7tIOU8^-ɴl}$h9JG#%\q( iȷ8KJ-BmŨlE=o $#SCv&Ul,=<֔5_m0!Ior] Gq,^ |:H> .tކje,7 5a*ڇAHnH Mɞh\ t۟uMeM;F~{1yd^ۀ֯r"^]qĆ}7N2?@ 377B VLC 쒴&䋏vi $9}?^%+Էt+3T<`JR~ Ғʝ<@ % W=A>\盏,32PknI#|Dl%$t>\FXe(Ӆj/J (,Xyc͊08(VN cNؓb^ΰ?i+ xqP5wE^7͟PYj=Z>aP7ǴM 6c"xz27VVs!ʢ+IVTz1H$_^'3VK#P76)R:9Ktt?/1Ew^iMu-$l `hb4 \pS'Wq/ t̳Ol++#ug{oU;N*NXw^y[vL&7%ݜ$r=e+0Z^Q/t$Nm>s@K<(Qk..Qf yx[&3Nd,TbY:Y6,9\K? w5C\alƸyknnmj[&TYq-N8H ě$sEG2J0>Y:W{B\iz v5''m>)| n$8_FC8KM+Td|DRO`-˶O,o!rRfa4W0kYU K ,8 t |+x;d6$z]5FrJGt~kpG۴OD?<'<nbj`!!*XHu!!Ir?5)Vj"BMY^&7[1ݡIOZl|LN~%=_t u*LLUċo0YaqyBE]^Mu:SG~ʳ3,O ~;#VVH؝io=4 ͧ`Nqh4騏tA%gmS77@6I,[,f?\_eS_VW#]fd^ԞJW#A^̴4~)n >T@:vftv} 2J{ F}u uW_$"k4B>`N!Tu- v` l4 :}x. a™U x'ewi)ku ƶ%׬8RBSmVItYd(u8Q}:|quJK!7 c͋ a} !w${Pkv@ SׁjD\wbdKMҠ9#DM+]"Peb7Hy>;0d̚#X!pM'{ߒ?Lt X-A2KN3SȢZT;$7S ;Xy i#.د}5Vʦ˦u%'< UYRGROkf-kqդѯo\b85/-|UF үcRor_]qYV@N jν}G5Nlc6m wK$QNpv-Xb- =%Tfx J=z(]%%ǙYS s3X8 QGlZu/a0f}eM[V"[IY8u+{>K~g8\qr:/)x _ta(po'4CmْhiX>FqX :E0=LKj.|Neߜْ P[bVOkOY&& vF{%2>xr,_O+A;_,a|+&°oHeg|0<)ibNnFK"`#:쉽0I Y6^eDu+̂1y5K7ЖhHڙUsuF!&`ZfQn g@5' I"d'ˣLr\֢C3bD|d5O ry2jKjOLĮْRQ.g^`"qy/pD/\"ܢdМ+*+=W1Hq@V279&R3OCL!8}zp#9,q)|rS=ޙ]ՌG{<W__=]7,VWQ˯SV_p0XH&)! BPgl#{k@+:0V:S]yA$7Xфmyj87]2FUaMФ7OC@Apķ@O6ʳ&p 0cigQ y^V|Gr&bӔq[ TIEeXx>ب@ I*tC [ݸJzinS=2wDK,1<ȁZkS$ ʌ]c_t? EL#j'&e I`XasfdgS^*d~d [WSN0F:TPTZa7<8^6@j1jl4nlފ *lX|r g!0q#/|G@{a`o$E=Sxl\eeRPz(.]reߢrFhޥ H `.%:44\Tf6N~2[YX-z$=h!ވs#piXeÜEa/N)ч%̖Xc#X70j!z+c˜25JS;7]DKPN){ Q?>g͙J olNç!޾,|~1:ObKS3XXBҜ>d;h! "_#hQZy(+6vp.UDCF(ZfoiIѯ ~Mc+qȔje\Z;c@y{DmԬs?nZA:@TsURfÇ [Xj_8H-f!C#,z,N>BDZ.F`sR29vqOi: 7՜YJ5Q*. .V>aAWHmt&,1fW9cV٤6V@0ktfRŚܔcdQ*d*2 !Y~-ioN2ϴ&Ti~S.$6,]0ΥWDNVNhOy]|DbFEै,1A8mCx9~6?/b1(ϛ0e6nhqw{;6D鐈|fRHePtW\f7fcWήLjy Id٠Qcڞ߁sCC?P ;:y*uݦ&Wvk7r)L NiCjj&ҝ'+rg^}qw78R#-yH' .S%5ݒ CrM`m":]ǖuаqL14fZ$ղGv3v^{9 4]0IϪ42kCE"9`+?BԞ[DlWABra'89 }@6LU20M-Nu)W/#z<ɔ5B 祃NtcYD,-sHͼK;Gy1 M@=7Auζ Bz(erhԘ-u٘9@JI=)Ws` *(UXiKg⺏~u~5BuroF :eG֫3Εp a+kaYL ;4xsF&)ZզM"-1iSrc`aրѧ޿}j--tOX\vԉUDqp $Vj>.9&`7uO d̓R AaQ *LJ:,Ρ=38xF S=9N eAQ{A4̒NQ!*%W؜ȂdXsrg l /0Q|OpbKZIz`=C9)Q]qHv)!ݺZtypUvHAIVs] ٸI@E>qОv(Tϙ}4Zj&Y`!iJoĈ{6Hkg3A?kI!=v`r+}6E)?1Wk}F4%3Ecw_f0].tu$&óO2p;pQ8)ҩôpY#{CNAeit {K  U.bo^[<6X0~}$Uy0A|]͸CaJ õTwer`ҭ{lRͻ?ʹ(ogTTmd< Kk;{w7-3J2oA*eT䣁e (*'x xRbP3P ljVᒱ@`z%*\Q L^wZD!+h≑+dB-Ag؄ȥb '0$N0Ç N|t(EKq $yŃm*>`.PDW;`IYJA/!-.CpzAD΄)_PFfo8 zA1_fKjanн1iM/% 7/YZ7[كĆղ_p&v~PdT᎓AǗZx\Et(Vm,@|6X2hg'ŁHa77I2yIAHn%Al6]A6$:WX,wк.ɩ!ayf9Ul1d̡*dv6v˙˹'TP,n䏩c/%G5&a![ʯYHCAIn~29TsY(ց}|@6otg A?oUks?8eT/f n@_HwQC<qŒh8Vkeg w4=C QX>7G >_pk`Ht˨u(=/}l.YX㶳]Yj[d,.l%^* HtpT RO*ir|GU8䍙`Q\ eTHWiLL?3ʌevv+(Ggu2͗yV÷iA)Jymtl>z:` Yet77J-fr^ARֈ^_%-Mhʩ?^O98$ 6ϫTUc97eӒ{&NK !%B%T_I&_=`M˒C8,}F$uxI?ˠM_B}EWW`1!Y7?kp8jӘT3vWy{vv/euyT,ظ#6;sЩFW{e7fײ+90Ǝn'B;yn@JPOCVִ%ݽyރCXөIƠ?쇂"ͷ GEhߊ^.n|| 9]]}&l6UB[imOue Լ 5GǛK'/NQ[K t.;B<`\ %ǛĖr/:boģ64ԗRQa|c̓n 8QZ3ҥ;+Nqy) t{!ny E:RjC%5)9fЇ*XA+#f{Uw[x2}ݝj~?S̍yxk'Z翅e#߆ret2.-1UN k@ABgE*nSŁ cӜb*F| ZZ϶( f"miF܊Uɧi2ۓa-l'xc\?~V`ٝsC?=m].-TΓM`bK$ZÞ 7rtc|KaЬZјZ&|2%k5y\n[\O7cx(; mڽySZ_/f[hItg1 u\nZ"y=aM9;6"4Oe(=o< 0Yl\$?"g,N|xo{q1Y %+IY}~.zo2G XG.Ba=Pa#nn1nGq?U[{}h"KɨwS'ϚdwPz@:n#uީ Q[EE4~~j-BTW|3]6"<{tG:Pr$޸,¸o(GpaFi: Pͼ};uKl7W:"}뭔 g[1޹ͅ_ ڴӼVRT(Nؕ[KYiZrTu ī,5aP~ae6X^Ֆ/O6tlܸcqZGp)CEv PPCHUkQ$EάZci?缍c-k,cȶY T Ey:@NSkGҎ:.cam/?GŶ0 pٞG14Vp;NZϱ>WS?6 T q~U Aǫs" ~پk7Cpw6Szj`qnHJZIտmۦvLc 4hJhp=`CXaV" xk:i\GXL Xlf-[+,D]c n⷗*#m$ټ+Qa~㘞7ak\Z%/VMlF kIf0 tO8²;狋ƎhӞ`Y+jյ=pZeQUݺ%5zEeI (7{ho8% @A'HDQ `WeEzBrlӦg;KZPdgEj֥+*/ 7whpY3NX"t\7Vv%S5Gs>?r34u6Q2iڨ-%s2Ӫ ]*^.-).+Tf=[ R z pCevu* ;ݩ]&/tՆXaW_c,Kb$cxg);2 jZ[X"=ߞT5ҾKd0ou!hTۚ3 ;䷈DRwA%%=g"_$$.Uӌ%"7,@dFIb7vGlFU|ю&Tw¼22nymZ5RU+u BHٍ RrfMc G. Gt;X;C/8v*۝yC1,9UMH1g|]~$UH4%.RJ0=|ɖǤR 97ª7d]/,RJWp<^=Z ovgwXT،XN, %E#BG"ݹidFIȕÖ2D0o3;Nrd{1ov[{XBݤY/'Ԯ^Zp-_qFe3^'uӚ Ygl.3E8fvtu%TRtu97 "aٌ)%n3y hMA"BƮG\Op0(>l9AF {+(Ck )~I SOo\!rgn+} a:82ǿ~NrxCk0&[Ow? :b!_9LTbb9CW.Q=,QxiMzTZU`BiبC\fx@v]FO$@T6ŔيBZa5+3#Ӗq^p7ѷơ eȾط>8(3UL-Is$pYy8w*-&^7xb3qqV``q%?&` H O}SE ޅ_Fb1_m~`ѽ3`WYT5+AVC9f"+p}ǐwƛ/[25-phWBEl(L‚lAg%!B?2IBN=1 8C)x=i',(qAK*&^dU$}>;OIC8OHcόbpE7Pvjyr4Ap* Nnk*Fb}[-,L6Ԑ>Bkt !ȾN=Z}v[ zѳ{B`A-MN|p`Ix |_[)C9RznP>X Zs_/DcxG&e:_;zj@)LC1y',r|Yy2v\{I&jpe_Hseq$5G\ +}y>6ko(jk蔡>%9}ק%8k1> [E_;P//%~ITό<¹t]Dj'+J߀꾬dcuZwd Xzzm|Yo*F9*nD _ 0O)cAM>zМ zNTX4@zqB(-C.W2-ϴNTX[:Du]09D_m)S" ԇ)T'e@=o6aN>B˛X[kx[vĞH5oMyr~o=8FZbބ:RaimuͅЭb (x͢+/v9'5rdB.:fQŢ\Q[ʢD`7;\@mm^Cs wq~͞6')3 R/n *1b$}rZ? ԧV !,>:)kXTV\]ңbx\hDl|biX5nD^4gsRx 3~>8l1: 7v(- 71L8!иZ k;9iﻠj 6fZ5J#H??"lէd*`v#?\o4ZYC¾Q$op=ˠ5E)+HÁ#;jE9  eCT+m7">zA[H0Hc;7gJ>ÜKґ;E/{L4DuyOAp8YX\KAJqIցgMQXiK/Ng!iLt:Vms'Y-rfo]CiA_1Z&#QU :w*Ph/j >T?=Ӹ⮠72%{6?"] Ah71iY3wѡ8}{SwDe۟ >!@UjSc<`_Y $ǡXs:k=9+K_)u$^_' %!+&O`T9$Me[s1`a0>9R ɀI :ؽ4M{E'ԓdc y,D*[%S=ZR튼fx Ə'/8 5 J#H_t; ؃?]mUry!6W_Ykx˓ Ej5蠟Y3+\m 8e|g:ʭ/ ;)4M[ pgM P!eϺglבX o!> /L;GKko&V;p4CMwͭ{UP;;n\Qǰo܇m$З}A:H-L($SbEicyG 1oDNC]'ŽfKFw#VE'f d#dkoxɬd .|'\;1N_u^ kl**[N\|y(|\.vlӗ̷($~!bߝdK?3u3vxY\_]X1'O4hq@l`{4Iuj̙7pCeOvy-[ȡ^J܏ԇrRr2iyFT2=v[^y! Q|x) Vo0{sI$c<2#u興Σ!!y?nGSb+QY,߭ܮWL+ضڙYGs~ de/R{]Eưsl V  w sg}t; B5 Z;νs΋69c 3zb&Dg%xkQ6"\vdcM^`IGc4g&WZ^SNS4NH\R?w"bvC_mL rC&Ǘ\]/BЌMT]3n݄1BkBDs`MgzQapZjǽ%h鑰eC8Ñ?͞">Gzk7b'_f(3fktlgЅSa!wb x:yIv`JQ> 9S_X昙~(VCt58gU;зΕuEJ}˵W\]IL όI;l&#4뇖U߱ 6 #w]程_PgfRA p.Dpg/˗mj;v4V FG%bD)>^uƂF|>/-8l$Db%U6TzBiֱa2Q (shK04tsS4=~6eWS 3.@SRE,r-r@YOsK oS0$T35bPMqBOFv,@'#%hgGcO !lRhX8@>ʹ/Лg~Hs䎑}c<;Q&KcH=[  C@8:s%59rS( _1l検SC5%lR *f0 s:(dx8YcGa101[ʖsi.Q p{uՕ )u`ɻqV?^q;mKl{[%_5R "88A[#W -e?bD 6+!@Uk3Nsٕӷ1, QQa\ryiWL^8Pƀ7]U,.L?V!.:m&5Ziʮ=__m-bGwB:ɎhR$!&#d9Zm]lHn4~IH3nԺCIWtK΀̾'x2|!/ o}@YD\S-Q<ӝw]9s'cnFM=6x1.xM<쀐8.U ¶ a.XiZ䪯%aü̞DrT$Tva0XW}|>KFmt2"F>Q@=ҏJ M?:Ə y+d=5fӧ}.B9; !bZE8oA1VH|OOPix oXJ͂r_tYMЅ,:(Gr˜QkU5ApRD&啞]OLICi$Rce3.-CY7s<+)oU6C<}Q+TY{'d%9G MayRJ>B"\ҐD)k%"3?6I'gbTxK>m=Rzw}G~ĚJ)9bS@z߷q+Jr Rd07䃒f =0S/#z;hWGt XkFƿAPw <ŁF=V6y8 flM[wX.N]nX\$v԰n::7CtЫ꾢|UPcskayQR8줾.uUJN&VJs'0I5ԥ0Rf'p3o[d@!0b;b'KK{+~zPkQz>?Ͳz(AC$y29)ڟ* p/4gϑKkA:l`eD$4}Oڇr V~c8ZX0 lٱM~RLuK@.iv H>Yp.v;K#GI>Sk<=i{|¶=N"MU)_3qƠVVndQ'}ȏLIurto%A/DY6%?`.J't$WDx9.;#)ӢYj>Dlu[WƂ2=FiX^K|j@ި 婉",W*8Nb =IB f{ڻِ9X[}2F+)@$4 Pn7,w-2Inק~_,ZU82. BYxR"ӥ'}ض/Std|1m̷_:* vѩ$/b`>5f@_.tņqSZ]␘+UIlqgۺy9 YZ