sssd-client-2.7.3-1.el8 >  A bU]4UC5t%$0 @ZOPUwmAyZPtج~wq)Sb@ۅlU;U|YM)6` ~7]cs!Go3:7:1x>eXt>%TK[.Tֻ6g kÌpn #[s&NOesLZ3'yiR11q<U7^c/*fIw.9sWLJ]$V/{yhuMv vHspw$]PH@zZ.+)|f):nGx-n 7=~l|`$ 5덮r3M[ γH0<$$QZ>abǬԠؗpBkgac/x;*.'Ff$PiM)TO>͓G6H@TqU)!x_* ]btJQ3#ߵ$0e998210ac5c7e83e762eb8b828a45b9fe57f1c22749547a67b86cd1f020520aad6aa964bfb0d6a8a3c3a2915da107e5fc433410bU] 3}0ypo|ؕ{ ^q}@3L \1[  rQFP{#GPgU&~̱Io_YdP̋{zgib^܊ʔ u|Fc#ŨΪ/[W}n8fl=-sKG uaЕqۡ![B|: Q[! a.Ila Vl($.P;:'i=% (L/Rx }fǩ؇} =Lqe1 4:[C<#|](aXjz?9pA?d  @ !',0.. D. . X.  .  <. . ..,,i,(89X:k>?@G.H.IT.XY\.].^bdeflt.ul.v$w,.x.yp\`fCsssd-client2.7.31.el8SSSD Client libraries for NSS and PAMProvides the libraries needed by the PAM and NSS stacks to connect to the SSSD service.bڇXx86-01.mbox.centos.orgCentOSCentOSLGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxi686/sbin/ldconfig /usr/sbin/alternatives --install /etc/cifs-utils/idmap-plugin cifs-idmap-plugin /usr/lib/cifs-utils/cifs_idmap_sss.so 20if [ $1 -eq 0 ] ; then /usr/sbin/alternatives --remove cifs-idmap-plugin /usr/lib/cifs-utils/cifs_idmap_sss.so fi'D#+0><#-_=¤Ox,K = (} [ 2 AAAAAAAAAAAAA큤bڇ#bڇEbڇEbڇEbڇEbڇEbڇEbڇEbڇEbڇEbڇEbڇEbڇEbڇEbڇEbڇEbڇEbڇEbڇ#bڇ%bڇ%bڇ%bڇ%bڇ%bڇ%bڇ%bڇ$bڇ$bڇ%bڇEbºbºbڇbڇbڇbڇbڇbڇbڇbڇbڇbڇbڇbڇbڇbڇfb0d2df48642670b63b67c5722e56b3b1cd4b0a20c90121e0abb0632e7248ee0b5497f1621d6ea4089b1b2bb8ecd774a41c0d8ec188a5b54ad11ae669a87df964cee75b5aca6060759ee14dd25cad9105445b52c46ff67d627998aade1503f17248143cbc72988e936094e64867f56dededc215060d34dd3babcf82f54db96445fae66d164307f81a83bcab87a8235a4e38c682fab35013ccbc411a001869d8ac83bc43bdf80ce492406947904c79070a1920f2a38488c445cc6f44bd98dfb34d258320e173ac28a8ff11bec5c9fd4b1ce565d0974c7711d30e8d3bcd03ab35875f8f24e8cab0d8c7390769138a328cc71e78e7ed15dedc950ff2de898ae5fd88ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9036c57f43c939054fd4b831f271a14c97a488c38f98cdda5e887c5d396e3b3bc58c6263fc3e6815f8582ded1b9c439be96e1b710c99e72011087c056b0abe6423b6e75d399b86478b55381141c47ca1fb619a8354159ef1df1b9d74c83221bce53ed022a030fab97fe7ad6927a91a494e85ae96a2b503437e415dd8547bb746546ff1a9fbee0d2aaa19c391061c0450cd687648256992ab9cda46a060910396e783b79b21adf7eb234b8439ec82ca434bde16f44a4cfbb64869b90e487e5079a10657110dd60d0b4de52608f0f00d88fc477443efd60bb4e8c4cc38af77f518cec261f298fb08239486764abf07412d4e0a40833cfa5b91a2b6d7b0c0c8ab172d16244603420654af6d722d46c156ee973db064ee78340ade085ea6fda320ba0e24088ba8fe6dc34639200b2f6607d2597f856bfecb9d9895e2f2989273225ca91b17d7205d098a22d6bea20dfaba81ee9abad51556306678ff0d62d583588b38bf7500c0997f9a287b28e978dd9fefddd6ef146aad15bb36efac2001195e1aa3dda49096167a11b8bde104731d8bbd01a27b71888a683fe89cfdc59c679817f90524a377c1e598f960ea3940df3735286dfbc0194d2de7d228725397ba85e2bcc0d6795c9b2ac9d3093334986dad6284aa324ad58193d7873ea6ef853332d9b69../../../../usr/lib/security/pam_sss.so../../../../usr/lib/krb5/plugins/libkrb5/sssd_krb5_locator_plugin.so../../../../usr/lib/libnss_sss.so.2../../../../usr/lib/security/pam_sss_gss.so../../../../usr/lib/cifs-utils/cifs_idmap_sss.so../../../../usr/lib/sssd/modules/sssd_krb5_localauth_plugin.so../../../../usr/lib/krb5/plugins/authdata/sssd_pac_plugin.so../../../../usr/lib/libsubid_sss.so@rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.7.3-1.el8.src.rpmlibnss_sss.so.2libnss_sss.so.2(EXPORTED)libsubid_sss.solibsubid_sss.so(EXPORTED)sssd-clientsssd-client(x86-32) @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/sbin/ldconfig/sbin/ldconfig/sbin/ldconfig/usr/sbin/alternatives/usr/sbin/alternativesld-linux.so.2ld-linux.so.2(GLIBC_2.3)libc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.1.2)libc.so.6(GLIBC_2.1.3)libc.so.6(GLIBC_2.2)libc.so.6(GLIBC_2.28)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libc.so.6(GLIBC_2.7)libc.so.6(GLIBC_2.8)libcom_err.so.2libgssapi_krb5.so.2libgssapi_krb5.so.2(gssapi_krb5_2_MIT)libk5crypto.so.3libkrb5.so.3libkrb5.so.3(krb5_3_MIT)libpam.so.0libpam.so.0(LIBPAM_1.0)libpam.so.0(LIBPAM_EXTENSION_1.0)libpam.so.0(LIBPAM_MODUTIL_1.0)libpthread.so.0libsss_idmaplibsss_idmap.so.0libsss_idmap.so.0(SSS_IDMAP_0.4)libsss_nss_idmaplibsss_nss_idmap.so.0libsss_nss_idmap.so.0(SSS_NSS_IDMAP_0.0.1)libsss_nss_idmap.so.0(SSS_NSS_IDMAP_0.5.0)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)2.7.3-1.el82.7.3-1.el83.0.4-14.6.0-14.0-15.2-14.14.3bγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/sbin/ldconfig  !"#$%&'()*+,-.esrururusvsvsvukukuk2.7.3-1.el82.7.3-1.el8    cifs-utilsidmap-plugin.build-id1c134ac1bd88c4dda76677f794dde698530f49f43008e567c586ff9170b00d8838f5004c534a36638d092528b89b32cc84b7f20d36df877961196d4693ba20364d345de926f0fdeae6282d8f2812c2cf172ae7843bdf1e71d2f0759c499f9f6c070e38dd5d91936b3a5b5b682620926ac14b34b5f677d2eb5d3ccecafb05e1c91ad8c602d1e7502e6440e4f2071fb154eb56db203db06e3203dcf64b6608eecifs-utilscifs_idmap_sss.sosssd_pac_plugin.sosssd_krb5_locator_plugin.solibnss_sss.so.2libsubid_sss.sopam_sss.sopam_sss_gss.sosssdmodulessssd_krb5_localauth_plugin.sosssd-clientCOPYINGCOPYING.LESSERsssd_krb5_locator_plugin.8.gzpam_sss.8.gzpam_sss_gss.8.gzsssd_krb5_localauth_plugin.8.gzsssd_krb5_locator_plugin.8.gzpam_sss.8.gzpam_sss_gss.8.gzsssd_krb5_locator_plugin.8.gzpam_sss.8.gzpam_sss_gss.8.gzsssd_krb5_locator_plugin.8.gzpam_sss.8.gzpam_sss_gss.8.gzsssd_krb5_locator_plugin.8.gz/etc//etc/cifs-utils//usr/lib//usr/lib/.build-id//usr/lib/.build-id/1c//usr/lib/.build-id/30//usr/lib/.build-id/8d//usr/lib/.build-id/a5//usr/lib/.build-id/cf//usr/lib/.build-id/dd//usr/lib/.build-id/eb//usr/lib/.build-id/f2//usr/lib/cifs-utils//usr/lib/krb5/plugins/authdata//usr/lib/krb5/plugins/libkrb5//usr/lib/security//usr/lib/sssd//usr/lib/sssd/modules//usr/share/licenses//usr/share/licenses/sssd-client//usr/share/man/es/man8//usr/share/man/man8//usr/share/man/ru/man8//usr/share/man/sv/man8//usr/share/man/uk/man8/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m32 -march=x86-64 -mtune=generic -mfpmath=sse -mstackrealign -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2i686-redhat-linux-gnu  directorycannot open `/builddir/build/BUILDROOT/sssd-2.7.3-1.el8.i386/etc/cifs-utils/idmap-plugin' (No such file or directory)ELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=cf172ae7843bdf1e71d2f0759c499f9f6c070e38, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=eb5d3ccecafb05e1c91ad8c602d1e7502e6440e4, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=3008e567c586ff9170b00d8838f5004c534a3663, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=8d092528b89b32cc84b7f20d36df877961196d46, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=f2071fb154eb56db203db06e3203dcf64b6608ee, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=1c134ac1bd88c4dda76677f794dde698530f49f4, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=a593ba20364d345de926f0fdeae6282d8f2812c2, strippedELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=dd5d91936b3a5b5b682620926ac14b34b5f677d2, strippedASCII texttroff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix) #2>O^   R"RR RR R&R%R!R$RR R*RRRRRR RR RRRR RR*RRR RR R RR R*PPRRR RRR RRRR R RR*PPRRRRR RR R RR*RRRRRRRRR RR RR RR RR*RRRRRRRR RR RRR RR*RRRR RRR RRR RR RRRR RR*utf-8db3ac23593a5ca84c2f6e57306357010b6cf0961db59b2a1e2d0d70df70e7ca3?7zXZ !#,] b2u jӫ`(y-lG!qǭMDYCP .CW$\"NGf" *4&HXhZ^҃H4f%3p;MibVg:kmZ5QEt lF 7t6$#r:H$հjΝ*o'*/S|Ka-}W@2(.͂ 1Iw Xzv0s<Bqz~ؓFuy{'zk;\vk֋4:^BBrRg^<y--J_ifNΈ\t\x K9pI{^@nWTߞtQg o3欂kD_l"H !y#v~lal?P=Yh qs"a+J ۽`M/Z`ӣcv5@ ]SeֵR2)5a# `UƓ٭r+@ȴb-y]'!,xubߪCWevf{^l50*] /c2ኚ>6e\PiUxb<}tsFZ6Sj֐=2fIr}G!>Cdֈ\,zЗOzulN?!2Y@*b]PWRodѤy\O n 2bjݿ^[6& KkٝX27GI=iTjbSN䙺`O-[dj C'e2zh܎ҽN3ͨ[IL%ɭ25!a 2]Chc?!2p^6^z#Ä%0* <3uc@-hh_n2ނL7pz E }A)^ū: UQiCگ8@gniiEКTxOńn accѿUف^| Ԧ,m%cF\:Sr }mKt9rY]iM 'J '}Eo3KMU˳0}Z]roQ}W_rI8C  /9ua0PU3c u߳+B2(H='aIt0Gjc{6u_%j}qzRZIʗ:]9л`I^Ӝ5Nw}&hÜD2N} tLTNZv$_̸u>˧5g򪐠7ǦLsR|٪[gM0>iM\?)...8ZBݙ*ք'. .P>PlRUs ma6H̤4 g]XsP>!$NT]=XM8w Bv3ݚ~#Oyyֱ;:zww{ڝP!u12*ŧc\ޟ6 SX˟1,8Gj_6~M c(ڇ/UOX," s.ExNw)V}[ヨT@:eT'?$__XGpV{\@WcE\\&;|Y8neMn&:}CFd&,c_3!J!` 8s}Lc%=F !\fiz^;'XJ; s,X!0!ps1Uq4Q23#L3%^,~sp9\Ɲ:#5h붛5tƯg (ϙa"\'4ppwn-Im2i @p5b(=lfB7%ZW_] &Q/وMY1Z@CUpt:(l!e +0m^]FFmD᧭TG: vf}lo-AoQTaZ}j9?ފqԚ%ݐ\XS]f<UЮ<*lrZ eZsQůf'20,54ӻ` Q:e 0&Hb֠d<&R&G[OΰM+G>"yRuo4z0j vs|=#k=O>aI&~4$o$Wh<岮_OT"D>UcsEFoB3itE)'vx1x4yWv[2D',sH5Q$*wz8iB ^˘{0ht'7wM#<;uCYt${~ f,wi&|V o힏Hk.NKZȬn;?pmr.PSrKIQѿ O4;A(^rC.]Cn~x-ZwsdNϭ].Y4f3#|c`-r0޼1ڟ=bRa`dy< t :ӿ nPߡro!:=>C&8](y5wdΓIke:}1Z(j`>"gl&YI(VȊǍkw؋y!&do$&H6ێ=PĨuosʅ_CzS`{rC>D vß`gf[RijKi8_S$iHh~Bl+^@qMOw3mG$qQN^l\CPQex96Lnf'lǹX=-f2ِQ8+Ip8qn`TQ^?n6߂d>`aWC*oNn`3KOb3(Zf[)EJ؄]:U m\l!b8D KѰ &IvXqSȋ:]k/f<JriS+ }v ۼc]M \臄rqẍ(Zo_xNeEtqjӉhk}8`b'e}NH~LL-4=$:=Ͱ#F.-  J3=sRTWWcZ()%|4x.K `8ό/4wB"|FKډ;e 4K!2¼w|\wbe Lո#+E:HUggK`g5"`Rʇ"_TkD>Q)tr"HDMԇN,MjwMߞZ-y|]A,tqY[:u!#-Z(r )b;]T~A; ];)OBZ _v}ʏ."w{[_C~ČKzۘ H*c] NZtEN#җ3Z)`8VX $"iP!D9d>vFg]J5FWqQxߙ> +H>_)s|?Đb[|69|J -0Jxu46 -&K_iޤ/%mf%W0I#3f_ ϱUyz>Џ^@b>ԛb+Щ>>]cv9!}$KɁOh| Gآ${aJ1ñ?Hao\ p^5v%IhW!GxZlnY>SLJ~qc& 8,o0x^B;T2h];t R^svCaQ{UczCgj-OFN3sOAa{2'ܣ]P;My^6&jXw3iWkzrމ^D)D&Z6Yr&@#j:_|d,DZ;P$y!`DpbwP<~n-Ē^k;*xH2kBN8ErH,>P"1/s Vzb"wK[lSy85Tg'V%pAxѫA[ ,L# mεbTw(QN\Iq>PIߩ >nRB@DJO`RPjd.ᬿ(oF~/qBɪH Kspuݐ8o}cK[;P^/wL$(oۊP%O[$L-$$=P+iVc;Ɋޖm3>\XK6*}$M}NXο)\đco4@7'=}U1; LfV' =\Ŕ}d6g@/˿%w ξZ4S~ _B@~0VaSڎzĐDz | qB]qX=6$ExNRw>Mn^2N`*;ɟEgc5Vd ^Aq~%҈JƈvG3sttsHMIr't;iY`lҚCT7qEz=ĹfďrA5["RZ_iKx|)O\@rWWUeEN+I]=c,Wz]D6`BwFDo5Iׁ}@j۩ A z>%Z5%\)"7>|DN|uΚ^ZUHgez,Ӵ:j$;pYX FVaZ+R-#W b1tMzj1ԬO";ׄ Y*C#@C*R0;SOA8TY:e\261/+SJU8ȳa{=zs9(oۀ8?F]pCV Dq%E c9VVla c6tD(]uB9JOd".~.ҲKb ' Swr*X$A6zJ6jyTEK걵D]d8$mD nb,D;Ojݨգ/kBmP׮Ցi.ݵ| 2g혓ZɋYmDVJ{n޺}.K!:ľ؂rmp:11VB{J{[+ΰ%R[ެxu1@!p=~Ȇ ^erEK$sS띟+FwOJۑxHhy hYX-`fX͑.1gH?$CͿZFR<Ao㰓|_AQ}SHqr43BnQ'Y}h/ZgaaI q-sLL.SW&#E$NQ2)[7$(%uʪz)iooj#\~9+۔iiI$EA3Qo5$!/#pC9vL .iK%PoQGDT-p=<K33oKk\lm*Ж )jj¹pTmH+⡑+6\т@K_οޮ'3q]Oa:~<Θy,figs=s(KwQ>uE*F{rso!!NQ%-YY2Zw'3Ĉ_Uz>B~ Whg~Gud ".ݏYv$toPoP~ηt{Ϲwe\&9tXs߿ZU~hh޻<#(,4@q ڰص6kYFՐmS"Z厠Ӓ.܌mcÃ֜vroj[B)a}Wp#+cٴhU10$b~ڔq6j:foQqx<{,Kt7́0L"2spɮef"e C1YRo#9'MEbz3SnQڢst4; 9|6[]>4=, M͊ú\J@CaNGEXuXJR; rVTs{Jpl9u%m Z̷=AӉΐSFeECLXqrrlkD%m,Ud'l2t4]YW^åDu~Ew%=ǃÐçY'qdxpwA eFM4̅N7>s%(4xn^Q?Qϔ?}"9ə>\`|QQ`XG7/~ ۾3sUNIt`YӹG7 :;W0G@Ќ;0jS0w JJ_DA1BO@&8`<`3 dR?lG@u%!YtI\&1'tq{&{u1D㮜,+,-Б[,)GåY|׺e7a^[!\m Ems$ \Hӿ#*eBܰ ?泧_w~/dܾ5߁Zs.:TW@6?3k^ JߢteSqYqU*NM] zh:#Ʈ+$1^ʗѻ#8Ԩŷf_Q=Ӗ>-hgi9 冢/8W4ASi:Ԅ,\[UҺt cIsΑOz,g0)9ږq2 FLJsX,HĢ^p k~f6uS!\2HEH_l&z$l,<M9纑CM_#g|7_'=Jk#09Ϊ/%5(R13H]ߠ7$m°f n7p BQVY!1Qx]J)oNl:_Q4 HG]EdH&rWFK%O*W/!FDz,pxݮV, !J9_3jڎcYLc@Ӥ)Vvh3,σϣ/D]Ŵa]S x(䣨H?VBN26~NuWG `WLM"J7}HX-b֮g(y)^t:+36lb6BUga1t]DR# 7^>]N~Hp\凜-YجP-d=hوB=WXB qnlyQ R1=HIyq.0X8VƤk;DD}7fk?{6s4d]0Myұa1d$aѬЖ{/q |<ؤcF1H0er򵙍7N5;dUU=ԑ0wFO6 3Xas}CL=Ça-6('xG++|pac~kXme:gB)j*3߲Rץ%!bh2x~P4J^ѣ%̟ 1- g {6屿bsmqWu= Ȯ1er?6;Gcz@"_-_C#Oyb0Ih)=-\wDS(!e.3، $)'4|MRW \Xnn [S5Ar&IggI:^Zal5F:}{*_DZ휲GLQӡbxFX[I~N4 h8:6C,͢31]s}P5evhrF wD%+l[N$`FF\j]Y j&;dK1[]j(YMM/挛O.#{}X}F&2 o:V9CCm^vڂ*ϜUAr G) *âÖ^xbC[)8,(5_zVhP W]y?DPm<(4," 1rDŽ 9+%ClQ2sF+Έ,Sq[|7iȾH߂JƇR24_LZ֒頀ӭGז}4/`}P{[>_`(N9y! j >8g\yIa_ R,yZoѳrq>:8p!l,?$jNdQF`T,W$mRX&26?n#˞̈Ӏn 8%9cMA9QI,Cl{9_6 nI\t:`Y^ qHԍjXOXtޭ"8Q%Mt]Gz,ͩq};AgX tZD˒F;eem[-՝>@ ͎7jzܹ?*D@o0* gvůmH#n/kYA'~;n/ّUQԦ>l{ M ‰1݋l^a'5^ldjt #bS/[ ]cLfl سH(hJ`1{Ѣk]SГ] ՁA|S:"jfbAad~1 v_ fN\)&|3ߢ[1gu8'ٝ"&9 ֖,i>-eBH%J6XMpbWO*~ O@̋="L3(+F! dYf:&?2,oRS^x㡖d~<|[ g%Rd N29P7Vw" yMGfWL x'1kcKkD;U9^emH)ue/}\ $#똚}*HPt2FO@]=l Nk:6+?rz,Gc JPAQFQ[Y 2{ykw?!pnI詩jhLjDKwxIÝaڂpx0[yK(@4+vA/|FyCeD/Wk`l-= 7,ŗ~|#OۇrL VsAj_*pttЊ\XKO3ݹ'_ A -z,uPr|Ef_[؊ʑhFPQ,Q~P̖ H\+{;_7[] NBԽ*pSLJ.*t`͉jcg^g}3|1# [ꥤK/ ܤU_,d29f;wDY1y+P%j[T_ \/s4`*Upǡ;>g0!_?Xlj!:5gYTnq彠lTRU7OU.$Vܘ6Uh.KzM- q q ۡL], 6ѐ\IqЋɾbxUi]Wӥxx[ 5T=a)R/VEہ* 3 .K@V`vy6d]Ƚj9r#xC$GT[ȿFچ Df9΀fJ>]`vgʉFu+V˛qAm&rl N,!LUz@hY_/W5J |>#Eı{MH(+@6nhpGoI%wE0bgs :TN1c@Hj"i嫓99@ :{bq5 =Zo3KHzy!?R(?=qG9Dx|a!}Lkwڻ\E1#m@%L\hFt'/f&dQX2eK舑U(gWBs͌"J\ʙ)Bu<;",/4Ū}wu5w֎+rz iq;3WkޓQ^jv>!G ʍLCHdto'2'YZz.wm]^6$ZBr}Y/.GXEsl< oUKAVT4Z(g Δs:iDɝ)-e Lr#,pFpEҐ^!a7q_ʫOqoJs95J6DE&J"fI7[3g DrF撰eV|2YiLyg[~]W$LYB0Ko_p3 YvX6m`hW {8*j όrҋߙQ4+W 1JIMԋpKWgʠeRb{i _~ LXD%ښ>5$ZlzWe֛]K-lBOt1])aƟ@I|Ŵ9Mf滱 )sjH`U^w&fܬFE.8h ' FK~N<^P7pJn*OE yEsc&YߗL`Q/MAzK1.%5?5}-t@I;<`0ȆC5G7ƤqPX?Zi8XEn5(_Zfjs ̬K*@>\:l* #mҐVB7@~FCҦh6~ܗӱŦ 0=UF~8"i!p8u{z)o? t7^*MdX0ˊ>}Du+kX.^O*.NtvV:ai^DDeKlg`PEF rPxf 3= ҔT@(k}r_cLNlst|cE%nB$~GG^r6'CT,^xPʅLZݢlq/@ yIo 9"OyD@f S`&HBz#?Q~|0 ,4NT@>r>*seM^}~D >k<#/;+MfhuYψ-tLdPXSSʩlkN]n/o+l:Syܑ͞R`K1Ji=en:? b[svrĀ6:aLO7I|כa^,?=d85*$=ə\X+wف- 緧* 2oЃ 00 Lƶ_%&1 -oeCtn@BB9~fBIC[dʨ$g 6tV6-Wxe4FrbCm`g)*HQYZp%G!qŤ`=+OsJ|2襫YtNJO Z[Ƭd>HRU\' "KNnb{~"mBTM6i"oݧ)X)eUur:?'t'e&\.{+?p&"b_<1XCQk2kT-£avc[IoRY2XG4jx q_9d{u-;boYe2 eG<#vIrE#F?*ܑuYQd:OU0v[d,mua?#;Cof@֌d2|i`G 3scD(N"}/&ͥjyы'_r!́>81U%v{8<_XqF|[V{˼leΗtޙ+Lx_+p=M Po̓KZfSWm?piN;6녗Û*m9&aXt`cҖvU]l ppdGȜsb2mB_q E"HTv`- pp@ |1Yuwا3~FH@*"ʊc Dv!ibsǸ<{T}XSL@"#'$\/?G,7͍GM\y{YDGj21]9EbFʝ2P{=7 Ir:xN_3Q9Z : R)b)v% 99ȅfC$nvYU #v*3(eJU.,lBϩ-ڌ+w>kw- oH`nȤI;JRhbNy >k%  Rwyz;>m?DEqQw2![!-hwKj p0<(0RW"2sO7B-7K i ,C]e>= 0ʺD\X*OeE)-)6 i3Ѝd8ɝH rIBȶEq83jP{j*Ԋ.yDRNwxm z|;l; -XC*뱚U/rBލ/UYR|)xt1_^y.S @|C&dž81 n*>(xO?qӴPY܄$gj2W{f{[K JqdrkQ֖ NteMXX@AԛF g1'Q͟r1vZ`jsB?57~2!Cl;bݎ)i!L ҄N(@9&la})@h(͛oGs/Bq),: ,^*6myWT׍L1HLL TYD/Óˇp頊\ ڲ?ה@rh/+{@OV0u\`́9}{4h{W4C/%?d*w觎/<;40%:&0ʞ S+#˞b;AHRims"a PwoxLU19r#T/$2T92Tj0*\Z:!.6BU k[}: #!Dσk':H?j'?zM[xg!XaPTbg:u+apEbѲ|BU3`9c9]n 3 0~=b^ H8x8 Φ92-.xjuϬry~q.Mi DGɸjhMZ־} 59ˆC{O ?L$ըE~BqKE\e:|zdTPtO$fWNA98&@* d@v_Kй qjzrl] %5۶bLaIF7.N^=<&( !oTӸ_i)A!JyJU0z!g>k4yS -x l-ngS kpq~ƺ0=J ]Y(@3ٰ.p@v[+;5arϽ=B`~n҂LP/|3jNȈ'IaBB&5;E(;(^o\}O)kqp 'a +RH0}9&ufN* gE,&wGwcٍf2i12\.hqmBlfZZ\MHNnn{4f$+j1bEa:r0AUpt?]T*nKp #[fSbÊ'<ͪ [t_c~n!g^W Өa2o EZdVBe$F&1߬a'zftTDhPXB%2*Fc3j@u?)6n%."9G<#]7=Qx@o~j?iɦ5yYXnd\w'dX7k /mho3GHIH6hU.cGJg^Jqd8X5vR?-GoקĪ{iUQ5?hR=HB]Dw ?@&ĆI'$;|=Ȩ (5}T}rF@Tfk>>IaZv~-"@=NW2.=$ ,liM+B&A?f R vNf8OCc{٢F+?] NN Ӕ@,5䪗F7otos|K;,pzgq rpgXgyQqn_R+)|6PDKq0!pLBnk탌ofS{ +F/S 3"{ֹ\6LVOqs{K+qBWND ʖX%)CV4E'<wv] PW3#}-9ŪO_&Dꆂ+i; 8#*CbWh$nZ3BcX$ }(kqago 6,j/~\n}~m|qfA[x!qiդOĎZiw y'+|GWv<^QSDF&H}@8*]Q)@òHcAa,슊B)m<OB$Lgj b6f[t,1`?ĩθE8 566#zy3ҳkYDe^5s$w cw+rNWۚU7Ddch >zIvLt GWO98a&.386r,1^t6\׊Έ)c~btZg`#R>e>-%`nBJG@ e6tX"٦ ,|0fgp4C~^ =_57 |vۉ^UtbUɂU߭f(IbNJPlh1\[|h^>!U>3V, 2 eyFcxUe"p/ZӜfcNUvK.4ږ 4"wǩ~0uȴ.!DXƖ|*cb7O*}eY1}(+*$y1v^%Y"'!=,x(^Zp`>DN8idzPөFJ#rda>j)2jyXC]64Zg_= lwGkĦ9Zb-_2T?(IiB+8b `I[T*eS:H!"4TTAQ8@C-T| l\sZ&sv 6(sB >g.= UHP<(Β;h+f.RcUjxScM55eX,Cݐ3~iâBy0R͞YMUU|X! VA-=Peo0 X-u^;]VVaU 5yδO-J?f33~ufԶ^zpWâ-s?=^_:k iP@{O@ ޲MWzR9vP;fV\|ʷES{^^;u{Tֽ E6|f-EWT6ck1+ď76j1_Dk}\-`HH$6ZmdDT*m+)%PBTq(M?;g{ԭأftצيy 35:%ŖEwQۛ`@MTP AGnqsMd q |k*ci {jt 5THUW,Ze5oCGHЎۉS3coKm%&V?VRޤORj(d7JScyiV6'Nnq/j/FydQxG]5q|$Ŀhsn69 %bSCV%j7^{HMf3ilyf̹lfbп=?nV߉Ȉw m kRdx!ѣ|I+&Y]h^SO_x 4pM"O,J(tާw%P]G61$.mvkr57h1֖d4mQL0w м'Π79Z`X +鹵8@oz &0E;m O.*Ca2'gbw@_da^凘,3}9ZKBF P(1 EpqK.QD_pWhl4V…\7V4S =aS; (p}/s4"1o4nO6j*AN{%닶R \m1*-b!?eWsG-`wԴeg$4L\r v5;bt16s k-2מ}L# MA~hixեh^ӮcLRLWh߸Yڤa px0352 LZ`b}]=ݻL^ɣuc} }\"N3>d]`h< sXA.pTOi+L9x %т ի]C/ ePG0wEsA&њԯ~ ۓق2FFPKP<ٴ"q05Đc*Bk6f:S (9/vC:tB$BK "p @]Bh꫶,"]>5|Cӯ28:K /dt;z0AxxMh*D]f/NUbwkB<9\vdtEU+fnڤ}9k%QEm0 iq-5&riyKT3Q(!,uB@P @=c1e'[L8Z_ Ya 3?B0 ޺W93Isco%鱥vAth0Nj Rb*E2w˜\w6u .quapV~a$y*lODr?xp`RI8Ut2)W*f4aՍl;k.B0p(uwߋ>+]b O 7UYA 0yɷu3VHb'^,s{[\rްu;fb1D!r $'Xp\G=ղ*,RџiJ${SVmOCV&ZC_KB*ƽK'UAWCf<*Fδ6ƺOg,pEZЁ%s_r$Ӳ=7V{Fzbs26 \,*M>zaO #iz̟6e8'J h_<'~[w^0].<U_Qw]dF=H8ւ$T,">E;r.twP"_A6v^6 |`$ eF5,Թ&63+߈BbxXXd1,hp1J %ɤ1]cH>pt6675`>T(!"T,}YAlյ6I$*E ݣ}]n-ߖߨ6~ ̸T0e%1ZyVsqpzKtQHoN5t!dͅDߏNTØ@uыHF}<ܖbs"wƾ͝\puZrs1iiԌ 52OgQ=Ց˾CB^Ŧevn_<yx~'&lf!kQ LOb vqFg7m #6̔ EdHJ;{;]#,MqP%"k]:4pjQKSdTޡ;0T>d [xA!8v!*c@e@`kxgx`cW!gbInϘ/U#hUp,+!|\';QdEcKΚО]I㬦MցuL%VL}jr{폡ɪ{WtLU.F%j"tT;"g QM-矂]W:4,u}lu k|4 dvț>x;}Yu+y[d7[[ʰ̽rmsFkɻBi"j>noE3{"62gRغ K&2t`(!bEùe֧u?hȘHɶLtlָaitfUz& 747=Qdr ھ#ۙIn~9&ՀDg֏H<|iۭb|9APR y?82$]9{gm(sl 0t9F3lf߱kpu\cmn30tT`(#*E^:PlO5-㪠熂i7"1t~I 5ە,m~ R(x8rM.'OE8?W8p⩥~.ʳF;\7M@1wI$oL>l剡*.j˨TpV㸤ᘶdo3;YDJ9MU֋H m} b ;oS==>(llPpcX-4!5khS]]42"W:FJ( ':Jb>]/eSXkv3iU[fbg)1#Nc2o]2`eىsBk.: i}'iN?9;_%(^!#)Wv)tv%U;G]*oeӫtEz a.D˭>+Y s%O.S(5fݺ -Mel_nK&:%[s잯C4w\jaHLp|jT7d䑔u Hj:BzBeIOt^e5NM<: ?=iy mAr_}brcPtnM S;{8eUmm; 8Ԫyq>pAe42ɥ 'uOqa(d -Ml^&pE P.0qfAl>uj (M803r]m+Pf*+ЪʪSFn/TF#7q{5?ҷI5Lp^?N](,YQ9zZՑ(슭UYYϪn8̺eL$`{> a ?bfH8=s.Hd!p}/Y$uneQ E :.=m2O"k"`oő{a_jsU[_+!NN-U\4J,|oɄ4 {#1X1 Y Gq+5h)f4"bLBF!b9*/"-j! h4V'.mr4xRrePoXʸm4e;WMnZ`H0TkĤ[~gWLN'8]ORsgXޏCU.ҌuT:x\^Ѵ\mh!}EGP qJ(ՁME iw%@Waut^L JϴgwIb NけM .","S\Nz% p{EeS5Ӭj jUu3z}C8}#J/m@?e*a7d~>v)*j D&^bUufrYQ'_K8lBEI3CKyl+h@O!V pae?'x a{sw4lH`A]m3vHK[;:2b@3^9detwrh~4UMB"'~(oNB 4yc\,Rj;)Pߖr=n}[e_iv!1UQ+n~j:VYrOXoSL~#mWs>ۏ W.2qR85xxGoz'HpmLu8/|-<tHV?.QHxn&XjQ tƴSnLBtjǾds4' R}Msm kftr(N\TzN>W+Ԫ3IH"8BIBoϳrkyڟK^uYa $2-M VP)]IHK#% 5$\7fkVUc1^{_lioDZ&$DuIԁX<MD;=tS0X| ^ q{ШWo|SlJ掃DxdJXU)y0{{( io3<"M9㐉$kLu볬Mgܪ&wSxɍ_yǼf~B !G5=B*%TTzGF\}jKM2@&Q3λǠ;? >'wB!P5n3$rF6kʑ0QxӒqֺcʺ㟒O ,:3j[ȼpl[h )RF?\c+h5QIT~y''x_0>C@7>5].s < Jâ\=FXbo"Btxy;xyy 0y"e mZun,փGjF+c_ݕ=r+3Ʀ'&nBPОTL21k`QG}_&_mCꩃ2ɥwyp_JgO )ѴMdF&t_]h7fo6/[e+&l/X5ESa'0&4}fQ_+$6-h#%862tGSKwk贆^'Ery7M.' h$}F:FxMZ tE{'۝&?|qdRў/(%_w @Atusu}]h5Z\WIΚT![2x[[1 Y@w(:R7y$Y%xȖc3y5#\qT<{&Rߠ,4xU晵΅PQ>gSC=PGNLU 4cŋ,1P w $oukPAʑ7?  6uRf_9.45Q 4#N{ԣy5@^S%Vnʸx}c'o+GzU (fO]ףadcꅂ}DsTHϸa"#}ˈzl ex&7C9!;l-LD*RhtPi]3łpzZ`\@kЪMwRr(q=Ue=~1{ ڕ*"TLUhR]"mQ"BQZĕ񖧭XT<0Cf@їv?N7a(!fh'ذR.yi&'BZfJT nYò!;c]| *L $;>EM&xՊ1qkV'eaC〫C)4$ ތaE&iyP]qi+ji/WI|P4iWr xސQs]^,+S^e#!pr,hܼҜuw_K+NnS fm`k~/]Or^`#b#k ݥ?2^c%#u0wv(L^y oy[KhH{r2@,|"R"aS0]c :rz\׊4a?fOrs4U}\g^Igt3I1Cߩ$Z] R=PwY@vl@ȉ@Wa-u,Ӝ",CbK df% 2yᨆ-XoRxo2`DD1!dcۓa_=QegPAʆ~hߣUyIˠl%Z}%ڤ y ^ R霁jOi K?ض+qFcC<2A_#'7x_/o8SEpϻ^xL2?ͅ6wp*vA šGF?f%f!8nq]@!=il"mãj+Qs~QuKm󵒦EINjzz"e4k12ѮAOLΟe] 덑m Pn6cudrhw:ZP$?/cNjBzřbb^g-!,(!Rr&o a[vGWTNj?w@vIk)KM^<~' 2QbR3DL4X j 罙gXnk)}/9DvQ&/nXwAjW غ >kVcgΐ"TT\R隯9o.@5m*^Kڊ=<'Zpg!IMDw=XC*SJBU r'XgY 41q\ZWڞG~uxVzqܣLyRŇR }/ B e[@ b7Ս5;XOf߯m,@%9cLyw/cMq@|UAڍMIA~ };zyƺZ@#Y)vϭf#(Kʳ$H-" U#r*'W*~"WAζ֒wofs '슯:?Fq@!c݃//D75.R 3=D ( kE9P6>p1 aef_MFA3ҹIˑQ^I"h<@όULZunS+&Zu__jԽm^%gl)glmr *5ɂG'7E2t^C1jWs-z$:"Q 6t P :_n7MP٭@0}}:csWٻ+%MeEz Pݼ}q `=5rOi1d},"|s т<^}3wzza=eHL,Cv4c #J]9mcAG$hКks>{/ p4-W݆c&cyT:aDI`Pv ;cn^/ٿ퀽v.P8:R^f!^6 8:TZ<,xgpm.MjhVb`46kqgk{&BO@2I|wQ"<Ã<=YHcօ^{J7જ<`\J^yeE/ĻV߳A(?v W۪::o“1W%!^ 홾6kcd-]c2Lj1\eWB2İU?XS"nؽ,N,]z sq'+.M棃p Œs[$8jWvYkGnIeLtF5jჹV/K~P4yRBj>{(5@DCL֩@6ooR=a.Rx% ݟEr @jҧBg'2aO4pANXjv }w#v:ᩢ>˜6_^v a.6I% t[Q_B5mp~8N{W\ײo6+|eGv{hE3qFs×k8⢛̀V~;|qhf-Kj|>@=s+\H𦏇.p)mU=.!)nYnA:FP{)#,kx=Bsܼ0@O}MI߇R{WʲzIS  %8m F@ ' sf|eA4GssOOT>a"KI67/ߟQe1o_PI̜+$z*ُ)&\h ͫ]@/#UlE5Z[/ЗC0}ZTafH 2WT/A?g+mr@ ߩX.iaWnB2En2%riSX!lVcdס^N(f`uK/07oSd^ Tpe|$Zioq%Šh%Yg`I|hX54;ڒ3cӚ;4NƼHQU^Ƚ@Z؞1MWY4ԛw b '_ ̂9Ө;&+)`w/TmZĵiTWT 6o=>e>.vrNrHף"g8At ssKrH(2$^S GǣNMـ+X˫ŹO}Xsh}larkgby%{ՙ$j,qRI?aLO`MO|M%FrF#=w}DJ9POVw:d]{N晽vǪH^>OR MƱffC^JpC%= r-~ wm+RM=iNaiMC ek hORtdk+ATiEU?hpkaאkm5;,4wԓ}(̒K8 &#S2͚[ZFKpl4d?\D= ]1(^Žʉe80o^sزm.y ?3Yv 0;PGEW=?Ej|`>ni 8=,%IRM0xɈhݽj#[1E #*%zmcβ$w,(,@kIl@e+NLF|d1g^Iw4Ib4,[P[0 <ǂ?SE)m_.6d+8>u;2~I b~XQ̛,O=nTw+|1[~;a+oB/1d9@.QCs{WE4 . /Xf _&&7@D?_R~vq4k*N(M[2hc+kg0/>Dv29nCJmf2w66smӑL n4xngʫ/ޱNI5™O9dF]Q&*( 8}XdmԻQ{)S.eX,ReLr5bo^)^KnsL=e%e(ؼ%5n*!=+pgG2ŠċQ<6ARa*x1`v~7SŒ]0 sz=5-C6Il_U?0 i:Àf,tGH8o&"7"4>1d"ljiZ(c8V;X$|/=UغФǻPWoyv,< -QQ\VFi䙝=D՘~@﮹eO&LWs{ g.I_Olרv\ǰRUxPgّ3ʑ8: nyhS*a U]T v􉟭]+(k'o}fpR4vq4[4 ?s)}JAY#IJەO}W,Vl"G=sAoDx$\X,HmE3Zm;ѝ8#zek\JXKN:ӡ1xFmƦ1D!V(_$9ov0Uކ/!:D@Cc@¨ 8xرjCl'le<d`}|RLG\xr ~YkB+G\:yhs `IpYV8?{s: w#\%0Hegut Tq#u!v0M$+AIJfѦb d,L0<mmžZ rCޢ=CI1JB30=S6/r^!-m" qg.2,5y }_U1~_ωSbB~PWFS2dM-Lܠ`YD )01F@׿͐sUu#Ka!iN~batYTm^tUb>pԲVBEl>W}2Gi۩a6@m+V) XS!Ut6 sa?S{Z9ep.mS/ l+?h7qP#)d NOCv3 ~9kHq|Iڛ2MVvH 2c}UH-87M1e9( ``RڬNs~ F\eq7PSB$vDY7VMC$I$mq~lq Лx]ƹߛ~l)Vp03RÚ D}o| 8*[x#8=^!9(ܷVf|\9f]X#|:JH`Q8񷖕e6L=l-uvJ:US~-Tp5Ǝb(F GbrKq#{GJp bc#ZLHXc`*>)C#mξ8['0nbAchZf[#XTQh 6F룯/6\^"DR%w+ml|@%:Shm8YcHĿ&w`I3OʽtCn`ak MDO V~w&0icitwal0;a E/p敲Lz%震|˫na0]T p\>uik̅%PtCYf㳚yznS$lwL; !fKZ&k TS M"; OL+fgU06C(N5&@H.AĺL*0bUdIo3 -įI/MOx/8-KLSԚ4E$/p hEKGB7 v4[#R%“ ݻ k#$e\Eb8T׶E4־rWgE@` Yϥ=l}_TWdꌕ*u_C ђS҅o_&V7Azk^);5cjϥ<7/d۰n?O!`~g9YlQ G>4a$,%p77} d mEqn~ Q .כ̋AWj 0m|XbZH@QQFԲ̊YF R0IADeĘoE&rH-6BXbQk#R(9ۼ[u{n<5J$L882r#ܾNV+BKNҶDE 0Q(6vIAjvto# *RZ *a-S=;t~mm T@1#}n=~Ԣr1e9`{հD5 ܄ Hs>G@'W6_ 4v'HNqhp`Ұ(4.߱ "u9ʛMlx*AG_6p"!I ]q_q 4R] OD +qI?Ddi n-n,fDLjK蔓кx`شB:4u7ć*6={637!N0F_Wt.>CrWn~-0Х,,xIk xLכ'yS@Pbt⟬2n`];W#4ǯLk h9V]meix¾~]4ړ~Aɸ RlIa2$@݀p%^S uDS3!cd쏔r^\ N(@S8wlx*G}u}>K΂c}hYRsB RB2y{d5"ۍCkx4P~Up2°G9 l\w!fFD+~Sj8:DS~/78洣 ? 'Kql^$F /"ıB7TLj~՞W,I`oSOp(*mh<8 ZK tg.d]^Hm*2K |c>gh 5Y|\J +.`iB u#eLWm] &Ф!F矍 BI _SdעlBPw\oWGXQR5R1Ѿݎ&]^)Ħ[NA SaU|v`q2hk#`la Lμ' 굶In>KjfЅr e3IoH~ <iֽum~dY),./M] dn >c;'/$套}ƥ18h!7V*tѩ$#`j)S7Torj|~Ge#7מ;a'Β_yD}|lVwS/N\y}]uGGmw%1^@Vp咗`ȼ :|x YciD@j9Zb~f#U2i73viAy΋kZSF`0/%Ko~&,ҧR}0_ta5m!I_lLt_lz38VH_ ,LWOKjz-Jwrls4-v͡ѳ֮'6,tpc6ëY Dw-==/Vx4?]]*I6O,ўggL51ฆ@íLX|4$wwƽr-zîGmwP,$zk[ݳS-8 \snpnTe~&NRHu^č1_TK<~+c %4I,-Swf)\|)'y6:#SzI')BK4nI%q0Q/d e +[;ee$CF^QpoNfPnLJp }zL6(G3xcc}eLwUbX_wot>"|`nc B@YW2uz=$ls Y"3N7gKVA47)e^ې͎/J73ږߔ ixPKlxa>lWjyku$L.=XLC܏|:4n1NzqdL9U௏_8P!Ņ[9 w^O&P+69UPD2ً҈uHT6Fnp}*PTM&)$r(zh;En$CC0FHc(%@s%yU Ҽ)W_ʙ?o5Po $!!A*`<. T/\_ `?VCPfA)d4V2.n[PX5;S fLk D{P;q_M@R'<л q=lo L([I*o0.Ո}(D U)7qXWu9>W!0)O̦~%|)2Scը8*kvaT̞/]_@x}ea0n8mfQɇc *mgMoTZfuٔDM6uSRK4+jUcaCZb}N.xUx6Ej˦YI;qnlb_[#᳧XY]2}pqIi7CȆAkX \vBеMVֱXO0א_]$;:vP婉|:_z3Sl$DEJ}^q־"uml+:EbU͍_&V$nd;qզcѭ~q}A! 5О4ixL +\ أp$w}y".!!= J3#Kz}}0 Ȇ<·%{1gW?ބMn[7?2SҧjUjZ:)F_B}0ȃ%E>U~ے ә$*Ɋe<hYv6f!6^7wP HYA HwQ<ᬧy >LNmo| V:H>z.2Bp5B; IJ<%QmF$4NA9o' $sp/&S]G捻+gA}q|,ۛ4(ݛʝ?:CӤ5&TĻwW? TT /iuĥIOmsjg>$an~'lLE q )N3Vrm9:[5uW]_d|*dN8DռfG{7 bVy ٹŵ;vݓOR"^Ēy@]R#$\t55fRju1MS #)XG04hM0c]\%K߆li Nq}.b|魆? Y<\X]'3J¨\XR.WmJJaԢA:I=Lf/$%Nu RW71ǃUtu(=ع)JM;{ċ~i_(Zlܖɕ~jK| w?nNWJ.Sb* WSueyr7k Q8:d7d! I,rÍ $'JMU R?WӬ#R5'TȘ,x3/kοSA9*.Nλdr,JɉZ[ܣ'ΑB?FryubXiքzrWat:7&nDZԚ2OG&׮*x[uBdz_h<șNII{((=IHZ3a |q ZL _H,l67<ʡjX[L@-kϏ11 >|[Ϗx߭HB90ݫ&PLkr?ǥs-cfm(CQV[p%|vmDx}?ral Ä/ޙO7< `,#ԡ|\C`0ϒ~f0K,,"eI0((}Umv^TNn{,Kr6V[IR*)msn1n#RI0.WG.,HLEG*e!n8Frg|NhdXMԲ@ѵT'&.ILI&\sk {H'=:bo3Fs Yɺe)D. X .je2WSB}S=BTYNV;;R؟6KZ&픹>' 7q,%.oꌢE7Mf'v#×MR rHDF-[ݿܒUte^v;FV4pVCXTCB+[$/SqolmcBG͵s<W /$ךLzlڒ;u.i\ .. =;`)̶Tʿ )Ό˸=!M@8K|Cf+HgzVO2^:ည'4㉎5$MN4IѪ>b=X_Qtj,N}ZA זcQM{4[Dwl'3BEz!ؾ|hZq05K;J)Hd*?9 zkMfq`zȁuر "!TYs1~^WҀ3/[nqC$ʯAU9{ϕ )b,'9ܥ -TY |lV/px@:J'X*4 HKθ͝KLJU/qZr+vMĩ~\y3ChʺVUBF nuOZQ@DV ad;F4S=J [GL(֧ \qڒPeϢ>5SKiG4GKPwON "oSۯ䪚Ul_;.H}:R \뺮ӵ xBFaM5[Z2זe*ݸ 0I, vg|1. ݸ|6muϕ!?s~.Օ3=s>OCŲwHz*'yeNV^KolG.Y?`̎N IIdK(^?=2gP?3\tp]v]+{C!==z |ʢ Z)B( 5 THձhqo:NVQja>"7x[VRf@mVxְX#pYDZ M],wV [lA\'__MHwFD;9؝_G:6_I\M| k*-b~3\|2;qGeIU!kfdRu\C!t 96O:Lϗ"J)f }+p'_[gcݤ9Wl5OCީ.M>|G@ ߎN24mw M@ʘjsyDh :ù^xepu=uFJoVjT4j#A `,-YT];a:+~]%ul@IuҴ0 EcY&+Ph~yptŧ;^VDW٩etEޏLSe48B_k6eYr,c2N]%Rh֔l ff2eޘ74c ?C'RA |=JԳȹR|\V>-'n'J} &.j%2kk.ee & 镓@řJ93(o?WH|!a{֤͊\mn_6~`[UQĈlv{ A֡_Mh>"9s/EclT%;"0ȯ yKyX3~"#U$ܪv?O92+Ncӂd'k,b5 ,&}Ti l(KڠOuA;nAnWTv[c >#ʇc̩ \3~B=8Jp2Zi#"=֋({I<ɰ$\T3 Z MbD8p/Ip_ .+@Łs4%跔wV.x\RDTL?9>mN$;;^g],ΓP߆xC!W`B6V!WѪ7ՔT&;v [5|]4"yaY}uVh_OdW.\0` JUVd]CЩ"ϦK}"Q\0gtdI튬ғ]I>f ~|ׂuLd(xtqk̻K?ÓI{P@X@(RZ̞=Sҗ-=GP8QmQ/+GN̝Lt˟TΞlTR[w1,AHMp=eS2AȴLł~7RjfIn7yO$:QdO=j[oKn0r}H} 3ܺ :ZX-mW%5ZG׃RΗu#RX%RE-7hę.|״ w\a2{=4<&ŸMTY_runb`L"iͽq Gl8 \ 9ZqR΂ClxH/d~)~a>s E@M9 `,:1@^?_8x hءSLJrP,>Ё}b jlsJܑYt:EG|ؕC۞/EOo<уedCb:9"<o,;vAH57N4ܹK8NG/ -ƃ4j۶%WQR+rM{ ޛ45\"vDP焎=^_U*184a ӫ\$%>ev]х-~alUE@ ص& kCN08sA&iTDin5/I\CK{ZhSo[_T<`-QZz`YF,{Ʋ"hAKD5vD6[ƅ¦fisCClCo=@@H(I-$fڮʹ [_gADm5>84~XOb_`cSo{}nx@eo'i998xtq8y\BѲF|v2lXk6st;0{0" ;/` |&Ĥ);J37؍S=74/2V#EU̅>Jq}JMв[?y *wz biΪVBIզɠ f%O(R?Ysl0IR=u:U[Tz!{*?[XMT+6b,K(e8.0EQkz3A+>?I&]Y 0IEC&"̲ɳ^KCe/ dםdSӟgQS!4tv}[c.j˅2Ɛ.S|`>*yO%P^fB @ M'89V !)۫Pʵ"T1`dp c%=6r=6D{*i?USE]kB0m[ݼȈv$zIuπ }v7I7_)!Gƅ?i4˼d]hManZv8ئ<~rٕ2.-sx~ENN9H`i:B{|`'rSLȡXף9*A5IMփCUC;1(̿!𬨠z""켞%h43(E߆1-E7@7}Q#Q'CsƳ@x#2ٲ>50Aic#>̮r4>~*sKttM)cd7Uwкǜ`? MwN mi?imį5㠁ե?=VײTj8R5{>x9]?wRC-y)QQ? 6H*hyBӊo6$n9řO\k[6s:yG E؜tsvJTP_w*Q1X`hfZ$PW$;,vG-),kh'~ H zI!|7r|M Dh-ගZ&F>v>a> #A 6D#3w95'Y _M+~" Gg'Zo IK?$;a_W܄%)TzW/.eˁh_k`u+ᶀ8hn\oz@B05{juB#p}h)ԷTmGв P|Seׇ]ŔXxpzi$S-(UxSukoYodwň]ܩU4!ii$#YQWX< FSD6TW&R;%ҦA{}5 ɓ14 b G ;'WTKqEeּ@ n W2mi@ yU:/)9I1F7nS£J]UgX,:U[&WHOۨen3:Or,﨨1TtvsS_ 8*ÿvkȩѷ=(Mcb>1(U`RG i\2 ~F U([JU) i 7?lY^$ ' +DH1Xjk77SH2B*M{ZX 2c!\&*ś+mMM?=¼=>u\;霥V74~7`*\ X,% .r {5JQ U얻M2'8XnlA(DV))m0>='-0Iy7#n[iy:2<[҄; X8p3^ϵoJ45Pxh^A|CVmM%~CnOmN`Z68pAŕTo*N_j‹._B9xa:'Rù8K3k,JDn#5\/ qUw^naL+3i$3{RY+d P5s{¶'C-NgGP-4ΑӤ4H< m?V " sz@L{(bTln0#*]05ؕL݌ϤC">J[AVi5|f!!UX+^t3T6oUCM`DΠɾK 9̋Gr-=s*~T ZKn?k &tuVQѴEa #Pf&,֤F [k$YPYR]ա΂fAvدLgEًsn3SJuY;v}#>6M[rmV+5 Wp@Z8E6״7v6`F mA %:G]t<{"D4T2XeEKVgTЕ1lv7_JFZƊbƔj݈O(. `%>~g%ŖҥhCAZNq[mᖝkݵ!PkL45~p5ꤐq3&6QFFВ~L TKVs !t}`2 pmZܠVjrL"3vgz%ED( h8zug6~XnХ}WUiz/@/}@-9ּ < ULwF,vo^b<|N+8#?k m} p7OCMxUxҟ7ˑս$U$4=PQ3֓3na++>+ T~zFLS eF`ZU7nҿsxr.V} 3Ex ?b94~'́^:xw 1`gADW>2MFx{-!OL1WTx$,G4Lfj˦"&g(߱==\BEsLNz wGOd/`/dD'>M=?E1B ?zi,gR͠t!RZ.j>6SFS6$jQewͤc/;mJцRhAv U0xzG&|oZeorє_w$S}˗@+DRir%E1<~=_ 1gSϖn{aa'4 D0i w9wr2 ͇\=I1VgfW 9<@X@}/[n)UQj.fɬbC"+ _fi yI3I]Sbt+*bgD_1H1"C@4+?F$ݘz'.@ [|z3eJJhL=z7\%=Rcqļz݂_j$[_D`L@ЩċbhT/\4{TckF? 3܅cWN.&*K#*VXث\yY`mEij)9!{R=crM ' fQ.K:}vgO2-RA5sPUw2K=JjiARJ6HTF*<bFn|`_e?NyF-¨H&,cci~3'|)2U~:+=ߨ1($*BCpXU%`Xerb€]JkaAv^p<|x''*;>m6!6< CK"#$+ih?uFDmqrh?HhڐX''@ @yʀ[JQ9CPS!U,e~Y*}0blc7% {/9$A +޸@M^8`I|F:zmڮt8B'6'; L4{Xl8GrP4̆'+1aTlN -VǐxD<(LQ:L6 OK1+[;e;.{u -:[I FcbA̜y*Hb& F곯 3AR}F3d 5 ;(zE2b ;1VIp1軾Y;`%ܧ9V b(ArH\&ԯ#Ţ7I+RNrfiUW>_JQ'tAqPǶ/ Vp H77wMz3m܋) |P!>ItܼN*uеSj3`T8%\c:eH{ /G`5[,ȯ,Tr%2wKVz&K5 K+ E&br Q+5ZP/oHS1m)sk3"sm:N5#˄@+4gI {6^РTUQD0.0o סxޘpEvrʕ ɯfn)K/Ty7: @` CwRhqװZԒ ΡlN3EE zY<=5'WtbǮĴQY 7)\;iTҭ}Khs6yͤJ~ XFp5"{ߺ1ñ>^W[吺&"wz5b3ys",-DX8 /Ď,>¾ ;O+}GMSJCƨT5ưQ3iYĤpͼS !!u`(s\]dOƌM.}ze~h}˹5%@pUpME3"[LLVo "U=Jc ٓdGEMd1 Ui3WlN3uI<-X:/ٙ߮snZFr@,di:K|m>Ҝn\d!3b/qlb𲇳0!t)!<ǪXt.B}#i ]cFcxhӼ`*Khi5.AqAN\:re@XRXqdNF~cjSo2@md57>߳2fYl2=JQW6BKz Km'hwoASg!ˀ`lıS-P8tC<t?ڼ! &)cwXϛVޥ,0$Gb]S# [k'܊5 f+M QY]}Lğ9#jfdGByTFF;F(xbC;?ŴY&~9QT pبZO쑀Os_fnCE A~ME>֜=\$& 0*yi- rBxej]*'Rٲ[k,u2J4^R1*E$Án }*50XvwZ4*~/x}6wU'}@}uZ2"IG^?@wbrs&OΫCRr ~# u5]YݴUI fJl)B95*eIfVyȎ_"D^XYLTC 2iXߪ弪_vqz}>%a eD +P/},qҿN(Pռol!KϗܯE` 7UL{:?42Wc0m1jrX=iKmDJl*5In"N{)Fww_kN͑6|V sPj Y/QY)o[w ҋ#)_VJTV߫{ri!6*_<p4~?;(Av*ѐ 70XqKgC-`)VKWUYSBǦfrڅ\bS~HS+Sx1ZLBVRMFfI KWXy<Mͥ߿ =pkv3fZomCˇ-rPS~R"c4xs$ل3tNhKx1Iimc90?DHv1?jϳSmDZ?,* Lh97$ ,]a$o,[/P˹}Ƞ$/]Thn;;ɴ jb[c]=cRNL1_}00PXZ.SR>aS,>uI@LS,-oa6m½} ͹.aK>_XBQp֟c )ac~P!!a5B sL%PtwqQ,l(4PSQOz?-H^Ꚇ_B7`Sf 8ajL12ڊpXO-XI_^|}\37śXk47ngO؏i⟙7'$ղBׄm(50idՄ،a`v WЃ)N*`yg/.0iv]fx',bg!:2_ZRGYiP 3: ^ l)P)wZ(KOoFөpXG;q9#3jBX?eVhv߰h+m< #U| 5 *@|x>j t߽.8'0*5~ޔE.0PpbL$Ṵ v;vƒqv,SmNVX>[>)3:[OdKRM҃G GP1]ylV>Җj!'0G\8l@Q{b1D(Ւ )Mz VlQ %hHO@c MR_EZ@KB5C[D| J:b/Z2 ̮ECiA@~ek#x`)X'db%K/?ILpUhi| S$>ݤLP cbۧ({c#DՍz Y굽LL_#xDZb yg+vq3pj$v!:'-9 wtFD]_A+"ۂy/UzPbtr;CTR$s;4Qu/<%sꉃbb2/5?Tο^R8GsTwAq\8A j/Os!:'CLB w< OS_@!ȵiA|V鋵 ]樂 ݑk%tFE4wH둕Ji 9xұ{ H.u$vpY2#T#T߬FVcŐb-8l|l1p?<8L: ]U]JE(c]\§ c/%D\<*r-o)DSW[r jMke# y_C8hGO ym nir_ }k`ھP5H|<x./M.yuVI>s 'd D٬"sxXgndl ~ӈReJfU[C i} ^yiՏbGl@l8fHiDC@}r- Fs:g/swr;ӦӵC 8>s/ġq?bcmͷo<[a^LT(_;Dg7?P-^T7UɱV~\s]"%5BWgxEmHSW/hfXv2KG"F:$ZSVWyÓ(i衵yd@4LUߜԧ`ݸڏ]z] u6.˨:"YXrPvE죩A~#0@?36ht@IJFΔ0{K.j2ǭ(G֛ݝ_Bj2FK;晝%1\H(KbH$TD !I t2 ./)ce/1RK^jIښp^]l92#(d-N)=fM0o3hpZF{,W!{ .ɱJA:`7vL-)ƕLLOXHGMK32Xs 95&s6)#\x^![5VtnL7 p6lq7l;go^t3-~ӺY7Kː+;H YF@4>~LGetjI+fl6Z"cB@UMDci 2k-+OX~Y#7ɱ15to w_B_Aܫ5ӟI ?Iˋ]hߝ FbN͓ DQϖD4-622߇8b4pu3HN;  MEّpOk:8 i8іR{ wIobL%qCe`Y:VB/e^I?`Og$MA.1n!5zf;ܼ,`nՐQ Hя|GR'6#s%&&Q1ӈm8^+4Qػ^v7&!R6َ(HW93 P˝?+V7Kr:k)’-;&!\ eT0t"/:Tv9(b?!*Ǥ|En/CvP r9DWF \}k`O;57N(q'FW/A=73kPܶͩf`Je'ZHY[%Uf8Ľ~.#ㆾ̃Ų]jyVETKԵihlLwm3H "tgpwT@PmM+f\])&⇂ fw<42H ?bw)|t{WW0xWN3bΊ>_=Q(t 7hʤ5P%#6i ul([]k02(QD"ZtnvzĔ}㢓3;8QTzSOA]_(gYs{b\"YT}[Xn,Ĉ͸jy]h '^U/Ds|4 (yoH|(X&`PI88U D]9 i#;"fuXם,X%GW;?/?K&@+\2n.E/M'Y0pEѹd>Э5ۀ9/K )7³)Q3F,.ԭI3?du ^ʬʱ6|O_-xs3+5SGƄxֳJV+'4Br0V[jzS5ʻn7ڶ+{Ph"O+yX7Ly V"OLoD/=c!q8i~H\֓WX7ri)33 +߃dCT`[tÄ^Lux3+}wSpķ]ZzBLh9ETD8 2oMm}c_>eM5WBt;#28hr_)̑ Kj-GҝZYftWج[W/_>_^Et Fxvc`~BZIc!Lǐǒ &_vҥ|@ PEgQ4i` itFr57$\zP*mmiBͮ|{lAT=d~{lѨZe-5>Cp LI%$Eb Fo}\ݵ\b×VN; p/۵\;rus6|:n ("6uYkȉKQBzôձcLXFyS4V@g>2.9'f`XO+Ч\H/jMs܄0K f^b1<2ܱ@7Z:rܢ\/& u0sT##V_ ]TI0q43κX!h\}g=;[48v@;E  $Ƃo^޽m/: Zov!&^8 h g?y bZAR/ӏ/'_]ri YROGC{輑TErz%=pB(tVk%&ML3j!\tIU{XBiY NjLS`H4<UȠVx1*Lw68=J*whUncJ0a\ kpOn`I(hEnpu!2ir o&ԸMbrus͌ ~oتZC) :$&.+ Ic{nw-}+6S@@\"xKnj~;Qa$4.7(BOtOUdg dBo'i`l ơR 9ϝ6nk|k0DYmLAZАDjTbrU|NCݕ?Yciя,r$URwO|Z%D D LZQtqR/&?E)kp\LQ-q4D`pw2.Ve'k-zü'$r{jTIV@+F]~{1AW1R,`N̮ߚL9'99gt=O9%[k4-KFD9.woJ*_ fj E1SI` ̌j&TB ;[+<Be aXQW:k6p?YFK hQ`O ܢ؎oMA"$d8GTѽTAn"-{ntOMSTd'Yr+ƢN~%nſ1ې(,`[K}kY X9L0J-7j0+dcSzƜR4 aRb5AU.n@ڀ ;yْ{~%|QDe[;->o b9~gi,ml1aP:t\>Ffu$w% p+Y 't1kI|Xeoͷ+XOx߰GI &̴c3Y2D9`1[7h=>{,X^0ʘaY^2V )ze?E8O{Oo͐"ߋ)aFҐI*vwfWumq䶿_a|G",d:1Q U?hَ姬BC^mOWiWƄ{зyP~Bb+Fb)v#XL3ߴ(/Y* EotkO7 Y 47rg=ߑZ+@۟eWB_2.X[|/DD _Z k4Ah-0zh}ۓLz c?5ˢ|GmDcu]8$G[+RbKt_jbL̓gxj;\i\b<K9FiGEw.E%DS@؃TqU0bI3-ޏ 2*LFUo2|qTIt¦W@ۭ jb۩HA]\BSFf RRc9p+榺g(TDbHt,8.D)eE>+VØչnVKcMf1d /ώZs׋Z& }au 8HA^݈ ɯd}Dy@7I!L 18bR_6Snv W fX}b]bWlךr[LR0AF1eMsHF9C.ϚjNOPLNOvȆ[] =r/LU.k#6sO$.]J٣N"O|8&[ }W 2ud0)ǥDw C;78=(#@Ud=i/%v2{ѕy0kSt,t|` O|V9>uf\~1#{8a9ck-wZ#  n?(=iռleZ25E([dd[G%=ee4 ^$y5!lEOL |M"&SO8N{;u,7w3?{M#v%$]_G ˹{03txB5.MA+ mң)M.^kge'g4)f%] f?SX"p&lX,D_kO5Ԍ7r&Oxys@QU濓 O/^:hMTO/u!Ys_9 dxe.;SOӨ*5¿PL`gBgx^Qi;gTchQِitwam.rfb+9'qV"Qv2.Q 쨃w^EfD'i獶 4W ԪDs4Bt%1H)z1nrf]*7Yݾɥ ЉԞ>5 QUXVz+B @1Kϲ#=%w}A pn/^w6z_ 'itsZqȤ:ڤi3 'C VG $ ,-9 ր>D(G'ۿ*RzȎؚr;a@O/d1&ŀ6iJ& )~6<ļsFx#s󉱣 G` 5nr5IbA$C)%+ۧ7*0{}⎼s!(5*rEC[B#:CұD {E_KtϰIb:g-n BvjAPo͊b%[4(3w`B'nJC+`zM#Io@!DZ3H6Sp+6@v,ogO!i)sK0GŶNJ-;PgovM=T=p1&Pt0HEf!梻bRCW0a`O/wґ ӻ]H?(N"2,[)D,iOf[-XLcf#M5E*?}ͽ1W jYxb(-ʝcƀ0 Lh}=s sU*}_sݖx禍8m=;8òBoKi>*ӐլB$5R;ĥNѫ]S.#C#xD,X6[0cQSå6bBčk`y\[OW+;j(ω^;(GxcY(n2 *-J"3 8 [5mmyU3}(SMt7b$n w[ӕ iˁX"VT gm+rv_aܤ,֠̈Alb+F@Yjw@NFf&^tC^GzZ@Th<3k`v@62'}0j=gE "qǶ|9^&Gq] zȔJ0 |a#suN.b\1qWyn+LY Ha/ٔOo,<-6*2}徑%\[#$zd?s > s6PZcgJn5Z"(ٌEf h͖ $-,Ib[mWg.m*(54J } ,"\_F)!A-pΈN8e,T<0vyR+/+M)Knx!$x 67U]#lVx w$ni9L)  kx9N~GWJ8&amjRÕv ȧYpfdCfx+w׌r&aBѬk. z$k C!z ?+}`:$ۗu.*j9SEɖ/Uדmf]ֽ:m)vOQ[Zq|}8Y&_OLe:u(ǿ_w΄T J+v ]tnYq\Qu8n ̡ Gw:~< YrP㯓-f`G穊!XԖ7LSI KZVŻMPK5y/  R g@wڪaLnZ%XIU-K8&(_o$GGżZ(a,pR{h}Z6X]>xRRr)Ux4[-\1}dpa'`Y߀|I5+Lec9$p?}K *RM28_Ӧ88xXScWghO:grSFʵ1eݣ+ ![Z7+v$U&a7fd.Rg]<`_GQ{gw BXm8*"n, z~_*lpi ~3!DmvGZ}Ub άhh G8E^&'JZdu !G߮@珜OERvK⯚xbsם_Ly CAƦ;̿UqUîEM@@sSljCV6`nE"C?sQt;8) ح^ kY ywgniXjɚB64a|x_@j_@V쬐.Ts>QzQJG Lmݏ䄙j+d7Z 8?gm+E/+5hBPhBh+qi@0 ea 7aAH"ws9ΨʳB'-s:+M[7r]ﰹX9#vdӚ-|Pb-NJ5`%,yKF,+r/Crrr|HkֆjNJ&\"zGKv=gRoR7@;)1 n1h}wa4oP59+Mڷ}o%W;_ 1!ZkաK7}#.l \kz}oSlCՄ1t"e"QN}8V.A=`Iw.y`biVܸoʄN&I%Q 噤}p >6q7KvƐdH\>ѓ`v(R戸 jgJƟ[9 p:8}!6F0:X8g@o{~MlRT=Z֥LW7"<^^ffUʖF(pnHn#P )#ggl %DVٜRߏ ǟN1ϔd=3eӻb?տ:<8&X*g@גtJQf* L9Ɍ|U ?f:["v7 ']'bY]r$a&>%h(-\ )Y[~R>b0.X vۋt+$̄ݤ"iz-kɹ@=|\>򴧞V XN-cu5fe^!٣+N\gDe}fʮW}>4{ URX-q5@.7= }#$IxvyzC1}s<' ܼPGD*{r(CDvPV լ\n#b7h[dZͫ#u%[|=bbgs'ᭅ=O' Y@ͥ=W#%֩ z~3=?6P=p=j~{!62]8̟._$lf$WBP HwD.5͛J2m幰"$ CT03qqȃi!:,7 m\Dz^X=>֌)' mVT@rjWXz=xd?vw nV+Ly Ng ~/6 }2UH;fIgzXQ agmCTiոRE<I "MB`ݲ/DL.oC'Ĉ)u !ۦO?XT}Zy< B K0fDx 6LZ0\B $n V 0Mq- Qϝd[z8y/fH) N 4R-@C@ݰaaAuߥaVcTּuf _,p|Cyf+AʪKQ\^~)ΟO[U:ÍX̢$].q!Δ4:_Is^⬒Luk7~"qLHݫF(2.5 -K)`kjJ~VkW~ld⻶S5V!*V8rv50URDnLH.vRv<$j}NԵsS1qjJޕ n ߻.VH\HU+D*Tm^BF LWCtUҁđ."dN<{`gp?NJGڛM3gj_D( |(mM_9xAO4.J|J# (W69kpy2Ca+'f6F:aTe -Tչo(Q艣FP&Sak>uEL껧>k[rrk[:,J8`T +^d4=.\hqrmQh‹SsUY^;*)_6\~/cξQ:tNt4%I!m{ͤ@r_Ic(ж露uVԋ0ꩂi lwp}NX3ap%#bqsr#1 R.LZt1R0XL g.V% h4gh{8LW1Oh-OS-tJetj~ת\9 s~WDȘײĈ,5>cstFTY1 +6Cf\K^ H2;k~%ԇ|Bcȷ=bfts/*h B!*=*ơ VxP0y<ᒘgZ31 N5̲7/1x}KDA/|b25eD`)?`.Y?+žl|.6Mnྕt>FY ƞS(.!6i g*b5"RNb/wF^}*1fOp1L"d~Gr}4o~Ǣ;kJj# @ EW2Ȏ8VɋIҋ j{JgQJAmhmFv6ɶ !K9=sM4(oEm Vj 7%,3=f NX~TqWF~L/ۄ5,jdR{k˿W\ێR%A[Eāwc*ȭ]/#s ~=]W%^h@F&9J7@$CuNi]O߶*S.K4 Zv͋v8/8u-l9)ET=tLu]rDtDa$$1iBTۿs#MTCޣf]j!!M;ȘicK(wP]V#=d,eڏ,fVHہ^K]B8m+*բ8?Qsmq$L=vnV%D):b͖Ub UIu#E!:_6h-}_ 㳍1!@_sɞ4!ZPd]yQ㌌ovu) Xc;逬Mw4{$rihz2IDqIRhV5J+2r5ܾ¯A 4}9o9-*ҲS u9?-b)}PH/m QK_ti5,"ORsGEybYyG|W)VPw3(5?/ZuڠtB5[I{+7ka>$v:k\p>?b@c%C@88VfMIo+|rG$S\9 #?3M@*F.E&U}K)į+C0xSB`@Tmٚd|vt(@ق],VO߂_AXĮ@(ȡ3|a `nոbaE>?#sp2[>7R2ړiYOPm>z^z3sXe2>ӿWUXpZgcugkWdH%{:s)/oyqnAX2Dxry4~A Fh`uiouH-k Ȯ+w4aT↎5祏&,agޣouH@ә'&Є}T0$hmrTwz'l <?9$ xU[h҇WBr$Cj4&]tG_DWgraOBa bo~U`&*#mlu #[hx!z3b0lNjV1i_(3j׌[ހgKDŽ9{.ՁT9OkZM|q>LK9Ek's|UQ<X9t悎 =3̨x =ˆȂ~&`,GN JA F~Ӆa@'V(eU-U JXj¿ђǨG3U1; j9Aq-,Iy>˚Sm|hs}H=]Ms0j[(&Ř^ojLS {:5g@dn͑zEE])/2U$G.0%2\pa6灂!Z -уGS I8\ C@vZg}d$q^49ܪtHh Y1.:~|3_Jذ`DUm1'2dItp*Wm/\g֋rJ$#Mmŵ lu$A|Н*Ȣ ˃6׺vgXIPc@ig^q4w<틲{v^Ӏ,PQ7 {QGJz+؄|zԪZ'5âk>r9Oл_Zlo9[C(9*hD-ŸjH؜%Q Ȅ~g%^gɟ1{#HA:~n-?ayD'jWkL mб?C gikPzcDݍj[ڻaPH߭Z/-NՕT3S+yBvW*J GenuvBcP~s޺@rJ&p@zL+sTcc (oTKTktzTF9{ZY[z!K,xYKXvqt*ok~Ruw鈗o]64u-Zk [Iqߐ xHݲ#0-9pz:y&HTo^8W`w[Y.a٫T Օ E$գrq#+ (x R܈$#]l6ԝE䵱H+!L*?d狴̶1Eˌ|)Pye[ f^{_B[A?"+ÅۻhL k:oL<MF[؆?x5A0%F5O1 ["V39bidh'a|{k ͗~(`xa}9 }<#^? ?] .r#XK;"2Wꬼ"vzȍq t=APo#R "_g7PFE |p<>=cf|YHk5K>C{GIt7{$ sCc.i`DI`mpZԛ}9+0ӐL7 :9K+5K]RJ>4߿#i%̬ Q5wg asFq_LЏ okSgnk}N5\AK<,!;r@ЄC5' J| ;%.~2B_G18^:فQjTq9B5eivoRİeW6K[7-vU=o^p+M䴚Y_Y*{|1᪢ O_ zΊvǛD a*g3UeC$Nj@ CiFSXNx*ݐ%"ŭ D,@ "`it"8Fz&Ghp6,ǝj_wҚ`ՇW!ܶ8bOȀ n404Z7ce-NB дlJɅwItRZA fEC-.ɕ?)30f!Ww/v;Vzhl |S 걿e'JzԀMƫ<YS癧v-o2|'`vo*M^z6VDl4\CbB|r6( ڠUr($qFM\asR瘶|9ޯ_T훺&*Q'6/y׺w}d/+BN m قoUzn._'+0Z<{wSj ܋HBfswu>i@%+WK;.:!SɗSXBz.NńU+ƑGXK6 [v,z}3 gZr6Fl'IqL;*}~jˍ L [j`Qhg藑]bkJ[6wF?cKmcr,T;W]P Ƹ˄E# -(ӈQunD{ѰG%C1>$m+GC)g&\Z$SP㪧f)aJs:9|] Qb:ƣrвqvNlQNo~ 8ȚPLnilBˀưiGPDZ$BP7 7ھCvVq|U6D&ʼnfA%BLM8ϗkgqe^a@_VeZ-[lTqFe[ȏBhƙGLm!|kԅFLSjMB-h8lFUy}d]ѯ|֕VŤ!*G ۥc#ܵ̈́Xq㇇(8Sf뇰sؼ~3 .`-rdwBcoF`lvѻ$;cKӗ>$ƾYrk;lĉaRA8.d}]@~Itisld_"6V- eZ\_jl-JSK1v4dN>յ疜l\DP+0ʑVRi5\Y1:Cp\Kuqw)H"HN,ݎOR!Q;&X=Րo. XTpP:RPHwB(TP)МΩmnp苟fϸǚeNl;zc3%"3{}`.l1N69QB=MAt LPZRղ"rqA2=%XA5RKmy>u/lœ.0U8GU\<Hӏ7-Ư ,R8U|7!^56;J@m9>mck$X.`"ŒA+F2O;FtfoqH{TEb꿈H,#D?oYƮlq85C#^O7I^ U9?a֝VC.ፕob4ނO5swL1[!8bU{+)&ڲIAYx!qf~YQՌ9x>[RAke$Kf,(R{k۪] AEy@ YK=OկWuՉ8E*;v(>c `&X&4sz$`(f^P]kWp\JG;!%!dZ| 3EO3PH߼f4S/TA+4>NR:0+4$ 0#)[ " UMWhij[7i-&Jn3Ll yU 읫RAFpQ lzܹ I~{=,b>s1a-j-V*B"څ軈N `*Kӓ!^hqjSxYo} 7G6#n;hk E'؆)sM``d.wYyhu&J)1ʭOqЖ w~M4i%LQR9 \"?8r#0V| bj =;9ϦW|4+nf+ߦVnbb%JLy7`L*+ MBgo/Z5yӞhaIQ ⋃ $7YifQe,|LGhrZVϕNx,E0H< [pgvģGX| }h!q.~-鱠1;ˍ~3鎫K|͸ahCZ 4w'O }}ᝊcx'ԙd[U>-OCZ,c::x0IvR'x{|=`5Ifl[-bYM܇@;J9ǚZT|Hv7߿fC(T*[{ XEOsxHea| GQ)~8's]2ci),vQsu^Tև{.*џBo mej]0]ADAP`\:A:zJy2Dz(&#,Lnd,kI^B'Tr51afmHnԌSV4Fqq5 )BTVeB1<,VVB0bQiMi7ϫ[jl3 p~pmu[= (l?rPWSwkYBMeDA'մ!2>!gQS$aABTLUWTJSG@|%)%xjtof* [eR7KB{_J+aohy mݳQ\56~ˑ4U O@βJќPV3)L/IL2&)xC;qᤌoPǻoSxŎW;g$6a(<'x B1ƝKOp/2H :QZ{{e~-28dz Xl=}*o <@b,jK%\VbXɭaek2Yh87Zù=J\-  !cϛ_+yA^MVau2+i@9|כxҠi͌2pr[RLdRzֶ. fhfiI.4t/?XM#]Yi H▩әVќMkDɞ^oO,ۂh˜:mPQj-I ќ$ċU;U;#%f^e:ޫ55 A\Kob&qJ*e)hPj\WM§ eYDkCoEDhH~$Rc)[ʑ8;H@kUszF,;^n/^ BT g9obo`QGPSr{PV϶ \p+50 Rv#1'VX!?X#JlM}yBrz^,^-xb.qm:TKˢ> tmYTy0qO@л9tDFGǴ"Gk^0y"yy֏.m/bMFCadbSłfkZqJnZ7;<-@Fȗ?\JR~ CxE9s) uʛcdOW`ƙ{&sTVd`NfNXOJ:'ڪ<$?ؑCaв7> K9QԤM^뗀3uwJ'YE~P^F OuL-ͮ5|F8mTP3]CK-2#,*\a&ʺlM;gs|r:ɾWblmGDN A,S\"e&AH{XB|! ^U?nhwh?lSMH@ƕQ<,{`m2j] S|}޴N)쎸ݍ<gb8{ B/ȘCLmzOmS!S}6ҀSHlJH @P@M~Htq1KķK[Q&"|G qs3軯ًabqO4}Mxh/r3  0v$Q48Z+4JnXYE z bwgךdp Rm]شIZ#|C5 Oat;m?71zɹ+LddTNweȑN {1 mhJp6T0`#O % aq 1HM/Fڠ6G=i^0TLt1{st^l2=R=)in^Ue>=`m/i`AKn#RD->!uȃ{;vS>;KG@=F],|@<˽}rj肠0DRgFFEMN!J7jFъ>]u }WHH, 'LUA?jYXP y$r戤Lf6C`E6G:´q-01:`VQ/-W)m)s<1Mvw"Mi9* i?Q$>XB?.e껼 Uh^o.Q_گ>eWcH0I>Cz\_Dk5̱x#y UuK$@h}Jn(GtTH vf`0X/mC.a9z _WFA`7%|0R;HGUs^M&U(l:܁_8vóJ\k4 FZv3: -+"]Rȫ2A(K~LsiiVkWW#j(Z2Cy_8FM84u⣶b+ ,]%,B&|X;5v\TSC" ϥRaRh^u«z8NSe+1W2䘒H I:䦰8Fu#pw.V/Gk ~EzQn,?/EɼEs$5rbPm,"?5np^/N>:@#:tum]!埦)5J)|sWt,卒3BM/6Agx0]DZ>H.|Z;$axސwDF ^ed1d@g(I .|7؇7s o]VYڇG{fJλS?;Z òf_μZ4QF}Z{rɠ } 9Wf:[i<ܕ{ `[շ% UtseU7E@| zl2Sv0]5QJ7/zmqJ luĕ+"ؖ    Pqc.0Pݸ :kmyLsMb¦XKr~!IK=,Ǩ[$1\d2&UF _'B' Zd)u'D A4dKv:@cwq(3IAQ]?"rA0p(M؛Ȳ2H?亊Gwxd?vubU $x {=Dqǥ.'OpjIeN4"ћc!:!x,fPL%B.G_c]l7dVEV4 kjgO)nJp1Z"P(Vq֒2qy4ZXfdmH˃0Z^]lm1y~.t' Ic2k&hI93^R57譣{~4PMW(*ݻ'Om(]ĥ$";=Wjxa>@ ]4 7:CLԿYO=?yjpP5{#JX 1YX;DLL0.?M2V/Rx>.ا2`Z O +;}D-] sNZAZ^aO+ I4&b(ZxQg5aߩdIz_ԤPE8j&r/+BGR䠮룐#T8ؙl&T[4貱u"'\T+4*dRta鋞8ΨYi>N OI͐ାGՀBa6mȃ" Le&1%2^&m60O3f_?sȌNW M"*}.ee;{ !y̦GԛˍL6Lit0\AOW/1} ''7qۨ"=s ! xļGOkQQB KEN6c1n= ~Zz,@\*59J&Z4YovԊo].ue>ccB|3<w"M N܎f>L+~N#4Sޕ/"ŐIS,/T'eן~jMP9 ʔWGlp A@qj'tX+Z* ꅔ^$dQ#OЪ-;; w:CW\׊"f0+g$UB5d|I~KZ- jW>كS q+>)~+SbJul m-?^nR`nm:xOxKSu&૔89E5HZ6RF-$frA0Mxի5JGߙ#g=n[38ކGFI_L韁DApYB_6) ؙ"[ Kf?O=t5YĎkxL6}156I2DF&1ޤ ꄽպAm5)1BKۛEK9tR$iH {9g@a0L AkN?巖3h\99eLZ`5';Z)[T| !f(&#oF )v"eW,C]g'[|#L'wJ<$|AH~{<| .,d+)]螣t]˽DPK6>>jA `X @k8w)TnhD6CzCIH h(@%9!R,qĢ:0>K? ߓW WP?:S 2fEe*yii(j(eaeg.VaT8n^V$yXK6ՃَY]%Q~wOh'sb ]23>1h:,(̙zj_2\+>)n2b]W Nx֋2."E~ |;Mc@ OWkR}¿,@ x$D:-L]Y@D7d6}Bf*]gh%6Ev@A̓KqIYB;}g0bվyӥt؍+cߌmMQIusjs`w6]Ynl=zox͆@6r' ej\::n(B=W`/I^@$J]Ǡ$kU,uߨk(kJ.je=E"0舿ᥕD7vR&  6^T=\xͲ΋Fm_n+Rn{~ؑriVR)E,H 2h堘)"IքyCʵgH z" Td5-لkwWDS Ee^O bZ]B,,8gN! S#cΆPɇ5>ؕ Ȏ̺Tٜ$^+ahu;UA;s3ؼ~Ҩzi]Fm=Q >I뜩kը.Krz#]J@qmm; _"eG׹2c=ݙ+;0$ aY&~GOUEnIHq{p%b9HJq[S'hG+BH*z""7"+P'YL[2ϝ?ߔ59`uROo:uhLbm!R)A>~Ž0Ѕ7E;4+ϥNYv#)MtOIYLipq9Q{d*>@ CK12]Y⑻%'yB/Q#y,*f>3JoBq՞Œsz֬5})ro~nOr(D!`&\ŐBy?]ڠy\!\>ޣP|~)*n3Mm<;k 39l 3) % @/}F[:v ;H3hj!}Ԕ (>#rL^a(]pWH4|1 cLۡusXMt(!0&( 3pcQh"NPS_?]#oH.0(WGP[gڧzj냸P?,vNȐ;s s9sg2mD||%V/ݿ~QƖԨ~,I0멤zT ~_&%AF!Zh潏]|3F`紭/tpj&c_K4N)mCݨ0_ l'ָz20 "I.C~)7_v1Ȕ Ԋ_ _^|//~` J.CrBJ#2絪ն:^H%F.i)ma@TƥDv!o4~,eq'Tw#!|ˑr\#u+u)kuK.' [,eAa$i6 U[73b^7*K}~dE S g=E(wʀ(ʭ'ǜ:yGצe-IQ&~_ [ &,Y1s@W??DP@,v ]{e4K[HߋBcV*#\qٛݮ霽^_baOL~o FjW943Ғ8V*0|+ZXAs0Q&+W0ZK; mc,xJ8|+PGNӌR,{Xiڗ(N{3Js }0'5| Yv'Uy叱-;ͪp1CxZŗ;t&|a AQ?:G0 B~dck]+ ryQ64xqX"&TK~'0$sa8I^xfxjD4\~MzI2}.oet]g_`mq"A @(b W`’WP"C$G} ^zH]lO܄z^g'1`] r;>ob;;wh//"[qXqHgcf`]iX{ "a 6CU)g{L0(gt >Ymuo!nLJ:9C蚯"Jt Q҅^v7Ci0g> *A*>S{8[ xT:T=%,G5őIKi l.`Gy3+vL$zWR =2㡯~B 6HU% -F,^qjk]SZ$yZ D\ce1;! c(S"'#NsZW <}&ɘmE^7:v^?:xޡ7) \*L$Tk#Ke9\\EO\tM_QS6m$q bEi1.$FG+udNߥ )g%yc_H}öqv !+z`SaVJМ6”uGX|x?_RV)ݟpKS .K~:Կ6a^L7[AͰlߥ_߻nkoG@7fQs"fN.=Ƙ 2LA+ArgZmPu~^1H08r d8MOEDlҠx^QfljUy2{r> ݫ{e+_nnQY iKSS$2m%UK*8>^`Jm];bxgx}63eރ`Ͷ8qtw Vk5CvDڽD,%`1.h42i#Ա" 67&imX'16xbqvNNCTB7EreANs*;fi0Oy̰uLˍؽ85X aLΘ_lJ[7_`lBAB?fáݑ.6Ѵ-i6xo.~~.J^s6d'HWKj%NͱU5'pEOhognL2KZ,PsɄ^-f`dՎ[ơ06zg<ԉIGr$i'RmAdxgKǠAv }$Jme8W b'(ޤCٙ0^PiIg!8~@[?6xq7u~3WY K@H"nIQ&D~ݬz]VDL1 {6>Cֈ6L;qbcVBoE vr\&aYPM[\)_j0}ⷦo2m)J ^WKŞr2[Ip),_V524ҏ-W^Ejَr˔m2C~./{JD5OIxLTXHcվ~%/tt§` ^7ۂza;nK<@}e\ ̪iRV n V $FB?,0wz@JsEM}F)hG3m.k-Ņ/p1zZ $9M;eRv'n ,n8_%vNkЛ!yGi,{oĉFy%&JuДQkiPZ_#D>]98 xx02_sBFkm:i.;9J.v p4pt?.%1%x3BmS#\`o=w:o\Juf)s3LU!ֱVB\DSԩM (PfY+`ΟrݚsSsP)2:[9P2,ߡЊ=5`l`.Gb⥺$ڞLLl45ٝ!XDM^D$\`{؝1S7FWaS+ZNhXU[ջ\Z> b2%(Z?s>#lk;;$&KLBkEc·PЃHxEojGe09(#y ?Fa/ kiVe!28DOIF;>X"O/Zm 0\zHt@͛*ocքb|M~78 N-s dMݴ:W #J=ެKo^`T2޻g8ݼO]NՁ$rDL.<|yWò^'jג} UplmCm16&txE A7H7 8&)>8lstj,U^Q^=?Z/=nɷ/*R`D52%:WuOi5߫\n€ .^XQpON&f Ә}D$jɯC_!5wg/O@[zh2ƎWjz2'D^0,wuϳI{A`jcڨJU)3mbC7(~>gw}\2_9ݼH ֟;jJ#6JƧ)4u ՕXh8Aҭw'bR28$!5*!Oq6*iU}ˢؿV-QKh7k_$it ?{*B v2|҆\lOuh vգKeA GD{/uņtN^v;' P~y j#ɷ^'B0=tC렉5Y5x`r<"7[b+6Oy<+YEKDƭ#MCnf);c8x]ڡU H^'D@0M^/"tnOw1d,ZU>fhWP*=rPӖ,}} 0 ^ѥFqsdV Kvs W5KlW-1T#@LE=30Dcjo^"y+~D$? JT$v/j\iKy_d%H⃹#9Wr3K(P;I.3Tn!^g=PFRReCHJYR Gy_Hc^OΝS/o|i. &a-!(>(rVnaK캢g0dq^Ec[ݺrQ&2gwQ$]Ґ|4ӌƪk9|Jh8Ko|'.M`M4forE>"uA-h.~ sWAtWr |?w1]韮`C9mt=rTM \O~B,Efrr6&S{}vsGaG}~0A&՛#d.Q7dNj[;Q-Ԍ|lڑi^ J+ :t"xzR7mBDuwMHyH9Ë(1A"Ҍ`7D] g}\Q+A>@Wnf Dx gzg-6brd刡P ~p&7JnUvT`nƆ:@H0h\mT7uډ# A bkz%ЃDzu&f_Kw)8{l/? Y5oKtYq gEf>Q<{"wmPQ‹PB:Lh5tN K>Iڊ'Mذ59] Zإ?i: ~>L*1 'AKw&f%Ķ>ˍT'`iOR `#GgC!tWHFۻ1>zg l<&مqq.8y&IN+)vx䠫I};3 񠗬sC5ֺK& a#6;\/JK@%x } rBGH~#OWA'̕3S!p%7gœ$՚RUb,B'z[x4XI0Hr}EKo+'iHaX΁f _Vw\o,}sgۯG ޚ{$Spq۳E`SUĻ _Ѥ[jD W6'$vƼLPW}fT8EҊN%m@G"0oR/`<tn/mH&鷃|rMoG)Ajн־.q=\$C`buCAɆ  ٓ!Zu}{RJݏRSLxqlPf^']/OM7; J|(*X܌%a`(_"1 H?{eMv5F߉ԋЦ}&^[,94@ͥ..td^ EӰb,KT;REg+ʒ; 7HvC5T3갍b70Iug8;G#Q;h3bכWBpe-S&d5QmTA)aϖ̈, XOG(A:u~ ?SdƱӞc$Y91)v%e>m\.[8%Z._6*rEC6Q!E9$f]zde:hpr̬+g 4#1l6}W>]CBe$* yxsscF)UpF# 0=_/HwVw/2Pp=|9lJ(pDA5n el!gIR0 ު"ӥ.S-_8RMjJOC`xID(o+uRXHǐϩ{D=Da=lBͼ쟽QsUJ0#Po~C6}˥i^xd{^ q:7gNPsS\} 9pkX DGF-GKD4٭1V8p+{Z)PMv@$<(v-l(;4sli7>=d8\yAn\uKC.6d.Ȝ'"2d#G6G϶909ڴĆFtbAqxt NZgiyиH5TMO\|Ih܃e a!RcU 6 Xzw3#u]B®XW[kݱ`-U7;uϕAvSDNw/9>} 0n ; ;丞tlL Y3:R>ќN4KaW] ÿpzX֤cӗ[;ސROU?Cq\% 0>uZ惈D@^= B S)'vSV!fF6EJò̸#fwBs:.meĿPQEM)Zi)VyV( [u5أ'Ű!`Z4ڔTö.E]FlPZ>Lr[gۦnDVN_R Trd1{CkF_\E^e\cϧMfбE'tkWZ+ L%Z="ʀOVuנ @LO4f ./CZ5Vw_$IN| Ȏ!4쥱d;4ܯbB+"F|n5D$+lm0J=ȥ+'0(p[*;3pc$5H[;ǫK1e^ $ |T^ZEGJ f2y? Oߣ+Yc 61ctlmW_pM?]h4Fh& > >>tB4 9cuI=Jp@ %5Y*RS'}ux_샧!H|ֹ- YJ]b.Xp'C* bE] r^4,yһ;Srax9MU~#cz7Jy.]3wt9"I,GenU?s̖(h5dJ«d=,5 0|Y܃i xo7mYkb7۔Zw5h6/~Dz_jH-hF7Δaora@w@PG`(pD&{5YKL{ǮwreAPy&=u%ioؙFZlfahpPSSmQnU:7R.N8~%K+#DZLض!WfOuu+pjvK2)*_BήrU(KZ%4c)YšFt¹ğ e8R.7MԟE͔gȞWσ@`Qu&MqÆ48݆⯄?@_n{Etb.=&I f,m oeAe'MBVHL:۵dzy5PZt\'܆pIj=kIv2`w|2xTl ff~QK:g16 wU0f5Kh4ZƎX9A/gV7x_k2sp?&K' ;IS̀p`KoqhliF=2ᕬĴvIǪm#VGٌaDMߢ&Asaqbn>HDS̳LvB/9Svv!ۋ=ݚsUj7oQw }0C}4ƥ_;|y>y_: M#E>EĢ1-DY>[ce$\CHN3ۃ$ /ů|Qbe2C3J R(0[?:1 .Q\z),B7kh;oبkS֦|gR)5u<Ȭ@#K4BHFz_Kט:!Yl怎,{-&xg(*h†K0l%}tBfAIDf RG3/~¡ċA4u@EpTQhOSYyfrֹ&Q*EHx @1^DŽ-|3[-rrm.AJUPwtm)`]-x`U|%5,k)63 q64&CЛL&Ց <`_m fmן5=D0N #jSF)'?5eٴW_{45Q'6ljD̨,Cb4<[Vtoy@;m lr ҊcQjʯg-U<ԕ{z[txm V2)_M4 ih>%p^Ltwhx#(2\e|4U;r0 Ⱦ'w{ C$uKB,5k#M>v+XQ/oź /[jt*t^Oŝ05p_2įkƿP \1ZLS1 \4QuOV.n EBXtbwп.''ڸ``'cɬj~E ƛ(մ=L,6Gad9c%ɝL(J*A=86~~^Kui!0i:c"UٻR.`x6[ HB&M&t\8;"rMu}{1j#.dz YNkr.7K!hfڡ¿)PFոc eBHeS: wÙfpJ S~O?8St>%{*6rO \.6F`CkOvt]~HyYԆה_} &VUx#4pNHm$ɡpwQ7HJp5 H\l<ԗ]o*(DQ/.QK  ~RX$Eݹ+Z0jo/2uZ?]Rz,ɉ"A QZQw~'}U!>܊uAa]r/ ^fNYwc|XvTsj\r{fv*Ё;IPyKdYAI"{z8>/y_R)Q h{9yvHi"[e 6SN0?Yh[sne?!ՖHE!eH!ed`qW哓qzЯp! Y#!2_ְm,5G>OuB\QS?1PLG&Eq:Uv-Q`%=G-U:.M F?ЮlM=ZYbKWp(';Ѓ FAA KooPOJp klz@J/WiE| @kQ< Gp0-a |" U~jj☃ԭw ;ar dEM7cBKK{~9(ىkdoVAڗj׷0W:I?-Ocl'ЅKg~u5 v;fke!0|rS_ʲ {3͈f)_Oq U?\|:]!OQoȰ 6de}s}..Wo5k >.DN˝Qk>l )I6*(BcyN̿(r8\v_9݀ qxI~7v^:KaL8}m{Qyk> 2'^A`IKkgy&Y?@ӯ.O:F L7+akmh [Wqfng]}*Ueg`KyX 518p鶪uBv/ 5谎ϨqjVu9j!vǡ-tt-ДcS9UػzwͶ!cӔJ/>̕0Vxdp*xSĎ Vyx~Ee__|mf|8mƮ)~G~ J5&.e.|LCJcfu5>&0*j%q"ݨG q3}c]@RZu zHNɠ1{I!6w˱i\7??,!@.F'94PiĞ3'}}zx8Zyλͱh&<@v|J1Twa5w|Aщ^IcxwzUEMc7ZFp3.Unkb`AӞj`Ҏ\qMlFa!JQoXŃjja1dHwҜ 竁`z9͆Ne|\ƨ$Wuq?X>lo3Ei֖|X&f[ REuIʈW2`^Eڭ:'D uTU֍: Fߊ|ϒ?gV_Gulz2wkMiCJ-Wh\UxhC9[pfA*:rD_تXiPVX|f((3$zX 83Pо-L xٔ.)xY~Jy 1*ɑY#m? Ϥ-86Vy˱9_'ج7T٧Vzp7w&ɣea3RD%y>.&s"hVG@0Bl厜 ׽@"W|+vd_1)ԇjAI}.44G:w`uR*(2u@lKD u T&ϛflO/&ٿܡ46?|}ù,CdE^c|Un;d$6Lc!)@Y\/BJFhףM. 4Q<j Xy5m0~ 埙I m m6'VG"Ŋ_h :x 凋3@ rrxQZ?ڛ'|UDݗJ`"\2Tp*3uSEonWl^@F[fFg֮1$ۗ]gw_JLOAjo)eXtCI#ʣW[a]7/pcR&Zסr$d&ucDŽG}s'{OOU<ңPh鸴 d'ro/$J(3!aSOxu9m2B4vgvln}Q(Ֆa4WV=C*hJjfNKk7fp0ͤ~< ܳkkVNQ w>;7U!z_ROg5r ^K%|l(% `X;R#=@fw]C<Y<)gN߿8|9ډ9XGb^R{,{(S(&ZktR5{Hx+ ?{ŒtrFӝU=RTml@2VaNg*}b. {{H.^G&#Ϫ{uֆ/&@vf<z;9F(XEXHuOa%XT-~p{׋ !!N05eȄ}"STMxz:hH$fQcNf.vZNk& u!\:)eMv̂"~R{$^y5CJ,򯰏,o4*&' 9L,w$H25/FuٜJ>]y- WOu~Ípӹ=g֋Xpf^g#%HQ0A&z1I^.wd|.o.s^qjV_(b3H$%*6}q'h7x^yfRk;+O%)7ԟ6,>D2 qeuJ2JҬ"41A0 WZ++' (m+[h}g;O59~Ԕc }84 fr܉%?4)bb*+ Dž!$rp{?s_^Ro׻.~S¢ӪC(k &v],RFlNҘ∷RsaqASL[K[V\-3 ZzB۔3$Q>UX\6Կ~558YvP70<ss=B 3xTm wϮIjw(C+yzɒyζz*kVpf3la=ܷ8!xLUL@;;)& 8:I8M{-\Jܯ6 )'\͚L]1MTg%W/?4 H N/LfJ 9KR׾m )!?ɔ>n9>d3 &QKD7n6ZT׀Oq(N;fV¾`z2 ku-*3%.k}i걦S-jg^εK~fxgBݼV?0Z_e"i_ 4tف 0\(-R'9;тM|8ԢREd>خ߉F4LLE q'%f w; 0.^t2]kf~Jq7?&ݤ([UMwn5[=9 a:, =CƮ\ݮs4*ݎA#a Ô6P_ :E0U8N@k+gZ4s&g`AtpQMss`󐟍 Xe|~†`CDҿ](MDki}? 36j-!](k ]3v =VPU ƽ\{u-y#Ԓ^W0 8 ~j3A~"O:K;U:F,bʇWZBK!FG˚o45HD+;DbĂIqsh6jF9a-*"mc64]lT?Jo9(XeS` AwU~Gľ'8h144_Qp`VU\Ə$2TsZaO 1᠞V*;۷ղaZzEV ,Pljq0,(ҟz ܂Ǣ F 0 m|hiuz\e7] ãAsh?څ'z?68.k.A!c(1G>mLR <+ޖvN%2\Pqˤ>$ċ"Wgk_.btc@gedgX(-q$22NQŘs]ȀO"Hu i} 7HN#uvk :"l$ǡkP 6GNdxb_ѝրT >4^ ∉Z80^MdjNl-xT'Ɓ JZ.;[UEvxinmw,Vnc.^F1:k 'KLVeG;4nS5 )RਊU0W+]#]p7ɒ=>{5W?%[kݢ&ZPPa~.4h%0!K~nsk7}Yybxs:uD0;ĎszBY`#v\rqC1m?kW?!CZ@Qh_u2)t Y-ktŸCD#*Nx2_o"E('v-@1Z74orx>ٜp=R!:9I8o~߯<$[zQ!+DeFz.<6Rۥ6^&=YFǰ֍cMD!ctDs8#[ځ5"3ū/,c6 v<b #.ɦm#iWU{з=`㺍0RoOl)!a+٥u9e#8GyW_{7:0^ʸr:*7h(]N-M89(&kVkc|dޣgŶ}2;G-@M9&Z ~ >9t] aM{B\CU@S-r?3AέomGd!/}dSk-uJOJ6ϫ)2 ywF`TǑc @Esu ̬|0iyærG԰95 }b9PgV7#[:HfB!ӕt[ҤdA{F'l9DYM`@j'1 @gxFOwOK5c| p)/0Ls9BKX41F JۥziTV fi|PHuIrV/:{ #=9+sk<,b7XJ/gDDŽo6JJn׉y_e4[0la9<.G{VȈ/"Jr{!EAwaqGB 0>j[Ƣ|^Ex~[N<-U)ăXi4HaTWsqLOBoډ;״L'?AtC'O|YE nř[F~鵥w-'us5E y%%x՝>J<($pݹIv:xoET0<(~DZyZe 90]Z jq/ŖWffOU0CdiJl7TnXNyҥ_Y8U(8Ց;vRPc1ex ˠmX(tA֖q|p;TWLWCO% hR89ς^|ᐻ@s )|=tPObJb ifɾaPmлKT7KL1pccq#lʡ/xS$`Zż;K#hH_8ϧL7[R(aL^k`;zڑ|l5$+BOsw g-J}c&0usʭ?KOv[ ,lLʥǪ_Umly7b2<8_5™e{;gn8K<\MM E*.uD˯ځ#ZA&G?a;9aƠs'bQ"!k!BL#"V{ch5]<,㕨#Ý.;auΓa]Dj`<6 h$@NS$C[|*nu j4;r=4rqZJX]z-3_2aLL!z3I_r^>\x 'IE&= FҔ[RsmVx 8T,Mgf*5$ղQNGx21Eߪs27.eU96K kn!&ywމ$,`0z%ґS\ʕO!n.'ېZuY6j;TģbYxN-4GCGXɝ[LLӡGTGۭI^M~7KDĨn^ˉ! e񝁓eT 3ى̴bOZl l'<,Lܣ'I9ITnJ(JpÀƒTAz2(,$N-=W hϣL͵*I(dT%zdOJ\kFuӔK7/aT{*'x}`/5-c@T*>ϸfVZ؀wrͼpr8T5fQ;6YB)ܞ)%;G;\ica֛Na"ĕZVX4/{`ͥ>n4m+7s}n$"wGS~r bJ E-\<ASqd<:<4-uvɈuyky0>,oY!~w/Tҵ8AɈ${lP `Pi,_V!r(1nלKTۜY'@NFfD$!ux5R s4ɘQ>y !Lau%vˆtP&‚1x}P'5Aݠyċ"'8r@d\X4yt>jvդNpJf Ŝj*  2EX@ o}ː>=[:3c DnPTxV,Fr`1 _E_Zo |p}D63 r?]Yd\`/` @y$;`qǿ`?_hJPb_KRġ|JȁEh_ʔSRYf~fYVq%*)joA˖l dYھ@( ̏s ر~TzA{xf 3Po1O 4FID:4?!ZKBs@{1/KS"$'x ! MJ2v".m[m|<_*''ovƚm@aY1+^>*0 &}.?qyaĒ_ aN7cՅg(X䐴%֭pKKRhBLU(06ؤ䷀p{ Uny:H G+ޏN{0V;F*&λd~QHc ծ/J͗^ZKlP|btCsw*!7-Ou-{ٰ㻘2B2kMkkVڲۃ(p08ܢ3yѴXkžEfA&_̹l p,5{"ʮ|J$'K| ոL^x!UՐ=(nH&AfD?^w cܖv6$X(}^.+ {hV^Tc|0C{({ꨠ\˩2T;nPvc7%C7ЛcA! }:X7{*|6b(B3w0]cāǛjTl߰'d>?zgj 6C΍.Os(Z),~0Ђ?n nXG.=,+1Q-6NڗRlZ* *=Ě"eVN{jkĹɫM3|(0 ?S;wْ%*j(V.67N*1LCd7JR L3m/*%=UٺHm栏(h]a\,EQ}NϹ۪,MS@_jʳ.z+̔V@z`s 3ҽ .=Uʕ!6Ojp.CsXN:~ZZGoCx (ʁIB1p'1qQRWX+(ݳ+L8t]QNH)="rA~ZJ>빷7z;b|#[d9I8VR*aox>iq?>N`bF!sB)ƅ%\PuHݛcB.ឭUT'5qͩ=q{UNi#svxy:zPu[(rGP7}ܹSY,&e}Ja7fh#%w$̭ݘm@S R\ZS! i7>?=Ӭ t*r,s/@$ 0Y\q@>}G99FC쮮HUpcuO…iTC+6Սls-%;< -pW *='Hypw%lR<St 3U`Gj#+MMxp?_0joԋ-)eJ [{`#?/l1H8nRq}鼎iNtrH 4tqږjr6ỷQ^m5*$ekC~ t9/dyɯ&!g>=_[iHXPydRiJ7F(& FѫXS)ʭ~9m5^tTԠWo!E"im T.0n~oYY6"\QxБsd [_AHBOtEL8ıۄe7YW mxmU9{T^9ޅHq 9n>@>Ȋ>(?\z/C1^ރʹ$ab3%%j7v-x"!R 1ǺOH;<@Ys{n^( 9f~m^,%ti0 0y5Os7fHIHKݪ݄uAx 5LȹN2CSJ, 9cL= qթspfՀLǪtdݧfG;nհb1 }Ξ#1WսvZs`*(dsB=&µTf*D~6< ds="*C4{"`ABLk#ɫk[&"AxŸ0xOQ|OA.gI=iyCXNѻi$09$cGREjUֵxT+ū_Ti_ -?h ٟUf~s;I :eb6s_ C՞2͒2H]ΥJV~54e-ua+wyҿ3r˜a 8  #K*:O!:/Nԁ! ̲|v34YiE"[ɱƒ$fUnKq~:qWb/>4mY>c^R=Iܵ֟pV8)cAsy=wZ͘n', /f,S2q&w)j3k +fPNfbANIKȚc/ BC9l_G:._ uIKqNF֗pQ /"ӰjeR1?r\.O!?x ^!Vi$n_-A*-bT;z|y #Qh. ^Ɗ؏,\ bfԙJa$WfyvYvYSadLvb](Xj+7GlsaMӈ4&Mᛑ.̆4v;=y)Rɛ=W֌׋iVV#ҫLbL,B W\JS+Zs)D&䦿 5ӮE(}3!<.6cnݵ"9Ky{2~d#+PV u{?; 78y. 7^-RX2%Ct@5s+)&7ȚӮ!Tr xg"X>5ձKvBLbWZqMlr"Ɗ݉<3r=Ěog텢~GoET!ۑZ~tє['N(w~D'w#T𱽭!gY9i:K|M(s+8# >o؇I sN/@d:VwWxB_(;iʦʰ C1}+.إ-6tL:d뫢b]_/R}$[ ZjX!g "!OA*xZ]`0֖[ -cׅ6[R1WϠ 8(} \${3Z҆&JsP%5K**My xH4.W$GO,+YRz ]?.т}x uB݆TH`N[T.G9X3S$ECfN W,r^W:@ImQy ?⟶1hZ@|vJM Gh< ,}VW*{/kKP!w/Ö98 k%*7V<m/4+ XS.9!EFfM eIl<1r(ok|.2,RA[f[*4` nI3rJb1?i0x3B:yF/ę~1%eiY \)LJa[Tjilt:CtqMx <4<`T6j% 'td6"V$vg3rcN"Ge=a񎻂"|A []L'q# wn $e^σ(ldm?z`VhgO鏨ŏc|׹o(D@kUįm*ؙAzj$f47  9[SRa xE8UYףCm%å+Vq|Ze C’(a{1qNu+ Qhjh:Z m_=s~4(:[j|9h{cr#UۄHRB>,%d7Z3,9œ57K6?PVi2s[:!*_Idl \(a [r ~ 2\΂Do6c46~o[Ű#iʹvc_CA_K܌Ck,)oXqHS5 NJA*(GIY{q\XfX\={Ёg8u (@s0ꅫ6J;HfE9_ CY>Wv0Ovsv :kzGƚA|.гL| OT%#3=eev'^ K QTk#^J]?F6ɜ©+uMEfH_\(l'iDvh8$rUAm_>GclXysW]+f'Y; mƕ Z`[rOX59A:?^V;z칱9ٺXh!bphz%~ }V}+twySs-j09>pc%ƥc>,EQj57{3y\Ef6a`<1ܾE9 dѴIPZKn԰ b 콙~w႕m(̹tjLޚ]0vEgF9Gkya;(ZcLՅ9c=,?,ZspXK_5|4Ap;qđNӍֵF^#:)ck)P*H^rShzD>ޭ'[q~mj.X% wҹ[3 GrA<tш z[F\|%7N4?j)F-Vy.ع,:ؗVbMzVS} ]B׭z1WP ع_mZ%!@D_{π4a/l`r.;7G2Qgި:a R c#d\ݡxԱ:6:Mb#%^EM\ΣL5h8'fz%;?Ϭ/(dU(bj3P<}2''=HQcUhXPAeP">lD¸h%d.+_ITj8ڌA,[ڎ{%,s, ~P }@ډ ;w^B%$C\k*gxDʁm[%NG_[['E>E( c)Y&';4TaF# lwʪ?6Fvb[:)mYe$S8@Jr(2qj&7%؃$#Ġ_w C1ЄW h=G3B )F.Em`UpW&ԷS*l01'з_$X iq ;PA$rr5V'BH>P / ogIQͅԘI]7[IU_t&PYVLe8 ^NP󉸗 r]"Z01p) Kp{l#pkT- Zt2_: VuԱv9ơa| >]JTx:7G*ϑnqN5QeJL?wҪuD} ='ĒؒڀY^D°}% x$;p4jY4 Mmp v 5VAr[;V .G8پe@kVGfYEAnta]cJV-&}K@dJ/'4DD&?J;X$?t?10b̀RS}O Hc Pr&Ql ^Ԉ}:yh2tO%."p !/xEJ3! #"$VtL/5 J+Xq@҂hg2_6T$VgJ<--. lπ%wz? Gs,[@ OZ cc|w/zjrD9 H5II{BV殷Aw}EBz&}vjL:ORc\aAc};(V+05X7rr& xm}h5se`I©SD*˾Luπ|H.?΢mxϬ}RAfd;%y)ui(|W6$Ū@EW mGְ8yժa 1z0~Oo/V;Ciw &qNOz!oԈ4:euZ8$"24 k\M+7;R~#uzkDa8dpֈ ,9[cu|gdl;c [|m{S|xD-1ʝn#\MGEa)Q9_ȷ+&Ni*LM y(6zן[F lOިwz͐xGsъGMD}Q%U fl;~7?6.s&Oz>6m_P7H&\ީ1|''-fTkA ,+}WbCm{_X#/|ţWakؘ]%LG9AWl[F Ljs^ P2{Z'rJ #,h@8uxctՀQ){4HچqKiWO5f XpͲռn:0ANəϵOEELkwT菙 kK;oG} x*9%H/}d.xs?#9x?I1wQ nMu~q2A)oYTpKE##UŠd%\v.`=kؖcrOeEMxg:r8 '-3v [0?Sֶ( YZ