sssd-client-2.9.3-2.el8 />.  H0,,..e[U U]v!1sƌ`fb(;?U4=GW,X:cGX܅BQUyf=-/V~DlKZZ+% +)3FK$Q[]lsz{JBjk=b Al% ͋lVXL/<Ȏ_;O@ᵘ J;yB2mLwȍ+bmHM|v4RxJzӖ\)6mҹW&~L' ;)egaS[Ҙ!M(3b.&??%ee֦(އ'" MKA 3ih+H\3oQReP7I?M83C4OLaWK_sydSts'C,j{*浨D6#87qpC $6\ m9-'?aDj]*l+e77%H)ھ* $@8:z 98b19a4a197f5900cf0a0e7b8a2ce471380f3f97ed1c00bd7c7fc36143303552a9e98468845d9551ea7fd1cf6c2d927b5116484f0302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb500673065023100b6ed8a3783f94f390841bb66cecec60ce86ca3da2e019acbae6024ecb2aa47701c2d2c98920baae2f4be150740c5327902304821f98cade8683b411b7c87771431b566748242846d75a7cf1af0cf3079a25d8b64ffc9e9dc819ff40833eafe5ea9ed0302047c435bb50066306402301da20173bbd105f81ec332504a88cdbd43fca4e09836804060039f380ff05644dafe951449bb07674b81a35aff696ad102301c13278e91d89112019b7b4fe8ed2e21d1de42a52b5b2f0cad4dc809cf63b088f45cd1559adb3a10827e665f0d3582f20302047c435bb5006630640230640fef22968261243c549e553e246d13554e25b82245b55c213086c16be9fdc1eb7b368752569c334914bf16da559b110230134a2aa1c487f92964567ec347ae97dc61ba184dfc59a149a7b26fec2e79d9524855834214a635e7889352e4615145e60302047c435bb500673065023028dcc64f2676dde2822d30f2eb0e4669385d122b4c3fba52ec15cb23f6dd670dab7026559b3d6e4eeaf65016087a485e023100eb7cb5074bb2d2676f1b45ac8b5a538a6c4267fdf7780a379ff05cf60f71c150e6a37e10daab7f9bc7011fd251a6123e0302047c435bb500673065023100f8c0665610b63bd6bd6b5afe8571ef46e53e6a6559ace27b56d3d7978078813edebc2eef47b126172cce061d0431382f023026e1eefcd1cb975ae7aaf75cdc3299997057e95e50a507acdf9435a84b8fdc6c3fc0b2a8e67d04129bee43bba5fa37fc0302047c435bb500673065023100c83219ed868e98d1a1ca77d502f397248de40bf5f537c20bcb7be66758764498633f1004906d36f1a137a3e9150321020230400bcede2f12c6438293076cc4f8c312a39efbeb2afaa5207aaa3c2778ee06d53d84b882d650b7360783a8cd1a675e8f0302047c435bb500683066023100c77287bad94cd0c402164ad2347584d629903ec8c399fa44c1f28a826c6e00f17579ddfd2cf5104d0b31fe5dabfc9580023100f628fd949098e684da4b59e6b6c7130a0325e1c21a9105060c39efd441e17cb8e0260e03c89cfa5e27734f3e74d3a0940302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb500673065023100a5f25ff8139b3bc86b7fc105740486ee3b28a3ca66f2b7525466898570fac2ce46efa2401879867b13c595987bbd4daf02301073eb38fa8589abfcfaa50b1c0a0f27124a32150d997383d0eae2d06d87157ad1e9d08ef2b5fb1acea0149e3cbc12ba0302047c435bb50067306502306e2b1a7a5c184c479b450a5fae9c3d2f6782992d38b40381bcbf6f003be05577de74f9734aa642a66067806c65616ba1023100c81eeefad3e98b6f4d0fcd09038e7ff5b3fb95d0a0e8995796855d64e9a9823df94e267d09047f961850b77d9e933ac40302047c435bb5006730650230304efb3685479d3c0b9b3c5b56585fd00205df6c94a7c721eea1678011d4622074fdfbd1ef290d4192fbf1db6f02b5d9023100f5720c01bb887b750482e05a432405ea3dcfd32bc0e4bd029d7781fb313400331af2092c7a3a6581edbba195bf0358d70302047c435bb500673065023100d8bbf3c73f10de803d2db4d432e8c8793a7e225098e15fb7d0c3b41a395c91bba5cc825ffa793d39c8fdfa9e0f5517bf0230026e1da6b649c797db8bdb269e008d005c04aaf816660ead043c64504f4768288c90c9b2afa2dc6cbf182da0d488debd0302047c435bb500673065023100b7cb84ce4ff2bbbddf73aa5b42e747ae0c36afbbd997e6e44b1768b2fe716341ab8e9db1ce405219cda83e5fc145e02902302fff163bf3f79bf640165a5c05161d34d003f440d78d77006e269469b75e1cfb59adb0036a991dff8fa572d3a33e635b0302047c435bb50067306502300bd70c904dc6bae2ab134aa2d56e3f736fa3f182eb3dee97ce1d51324be7285d56661afbdb4637ae7f35edc083d4344002310085f06f7669afc68a4f45bade3002d07d7ac9574cf71b8b3975410e8e41cc806da93f9efd1f30e7448804d14feec71ede0302047c435bb5006630640230505dc1f1ab01d26c08c046a372ec5013fc22bce2c735d5a4c3fe2f0443f0c413d942edb58966608b610031a4bdd847e702304bb906dacb0a786ac72bcb055d89de9c6d0dcb7167408d5bb2241c0ec6f7ed2af59cd22ac3e21f84bb4a3c08f001779f0302047c435bb5006730650231009c8337d381558901492731afbdc246959fd0fa6e0eb70f7666fcc51731e97a44db47fef39e27fca80d2c630bc218a29a02302f91cdf9cfc8a9f3dd622dab48fc5ea7deab1ddad2287e0af36584efda2eef76b00fcfd35789ffd5288e4be14630d4ca0302047c435bb500663064023011c883649d57fe2f8d6856968fd96c747d5b282ad54f0186c6437ac0013727a6e5946ecb36525537e3c25411c4b0869502304a687c99d59d00a457e3380f80884ce4df2cf84aeafe8938ea3a4bcbaa968ed47c7099efc0122b9ead11f2cf1107fceb0302047c435bb500683066023100803276e8e88ffc133b22706b957b74257afca5c2ad48c4b1e54f02c5f10579fdaa1ebecc948bc543daecd7b399777075023100d27f9a141af5f609489f36febc20d6da09b5116d10c846f801a8216528dc10661be640b1efeedb350bd4d5459672872c0302047c435bb500673065023057725ccbb01f5820b92938b3490eb9bb261f631f4018b6009b06a8dcfb85b626978f9533b628095deeee68b4e4d33bf0023100fc8ef5488216edcb580b50685ea56a208cd4b3c355d0988279d9f30c782bb131052054710cf271425cd2c33228cb5e1d0302047c435bb5006730650230493ed4596df09918c61464211e3e5789d3b5eadeec895874835a864decc3339206168b2db5a765d88f29717ca499efde023100976525e57955d9a9af974dfbf87da10b461fc2cbce92b83c033d91b1e9cada6fe30da073aa2717d4cc9373dfa94668d30302047c435bb500673065023014c0f6d89df845c33ab1b6820450fb920c4635ca89d581268acc85ab119b04df5038b69bc66e2940c636d8903d4857ad023100cbe990a3e856e34cbf8a21f3af5b2ed730ae3ffdf8be5d311df5fb7491555ed9ff86ee50f49d57c24f2930382f5e080a0302047c435bb500683066023100c50261de43fc22544244788e047181ce99dec57584f08dc12ce17109974e6aa142409fb88a1c7ee40756a97f44cd9b5e023100fa561f15493f96e8aedda883112cefc3f28439a8fff561efa08e45db401f6b4fecbac127b38861930a2282c837d199b40302047c435bb50066306402303bcdd904f9bf0f90268ed5778f74df0dc7b86f5b548e356537339db54ed8367c3d33494326a288cfdd28e1d4ec2d14d2023035035cd420007b8bc40b8a9537fd447e66e999ba3527e1b7c6b7a1e12f4c115d5cc40e8d47cbc6c01b221d31cc618dc90302047c435bb500673065023019fd8303d89dba141a336b5b0e9136a42bc8defbc753a174e5cb5c7f02421f08caca2990b9699c47f7613c72549a0fba023100c409ca3814d0f807ad1bc7607197b026fd3afe2061a390d8441a6dbb2876db45c1636dd49b38357ff49564753ad441320302047c435bb500673065023007a61e7deaa09399ec86f7f0f9d2ae53eb2be4e768eb2e695e43b59336418cdaaf8a211b0e53f73c8dcbf542baa76821023100ddaac1e6ffaa24997048bc9b0a1c786ac550de59396f3ed93c6718a75c66b170f25c81780b26dda06227030cf103437d0302047c435bb50067306502302ab74c7e1ee5973dd938a9776f4bbfd7f4b5a24daa4e30a424d416d1262717b41506e53a218dd504e24bd978588909c2023100c564ff9524dcd3290bb868482acdecf69e33c5a202fd11144239b3c588dd0924ef3d1fdb7eb0c7f3c44de3d9de41f7c20302047c435bb50067306502300992a42c7858842bfdecbef84398206e0cfdcf613dedefbb3cc3efc82239756e38e00f60cd84738be64a03866b19efff02310094f582880a55f82a1cc5e8e958ebe9829d111474213bf4e0c5dbe1b813fb6639f5577944ac8faf02579a5f6284070a320302047c435bb50068306602310084a65049c3a1ac8203314b82b9583a975ee712fd1d50eea9df91fe6f6d13a5f99934d3be23bdf7cd092d7460666bf2b1023100973ee411aa59a97d3ef4ea28ceab04265bd2e7b3a0c42a0aeec9a6a6c8e55f2b9b690bee7bdd501837562af81ca153a50302047c435bb50067306502305cef4784f0600e28b9aad33a0ac2d194d3788e50cbd7f93029480d5c9b9b4ac5674e4b7903894f26e7b4dbc2990c6a43023100f3cc365b461341fda40fa3d47118aae971a337f457979f1d55fdbaf31bf18a5b9828615609bc661553e259b1454ea81be[U U]F`HZhߨsOTMA~n>S; D6p~%7 w= O -_Jx5!9%؞woR%v\hOFpj\סZ0mOD8.jQRCf7oe[HpDǴGڽBvVx{kJƜe{cPVH V$1T*ԂgɛDdM"ڳșWb]ƺ/Joo\/ޤ )+Y&Iq!70S:`-AtSqlEa;#''vg5橇,4x"Dmin !i P;\# Va^Ahfl8zu NJԺg;4Pg7V[xn (HUWx6){BKe mUwm iVgYF%f$c.邋TJIv.?1qzQPH>pA?d  @  '000 P0 0 p0  `0  (0 0008'''(48<9:p>?@#G40H0I0XY\40]0^bdOeTfWlYtt0u40vw0x0yTWCsssd-client2.9.32.el8SSSD Client libraries for NSS and PAMProvides the libraries needed by the PAM and NSS stacks to connect to the SSSD service.eRfx86-04.stream.rdu2.redhat.com1CentOSCentOSLGPLv3+builder@centos.orgApplications/Systemhttps://github.com/SSSD/sssdlinuxx86_64/sbin/ldconfig /usr/sbin/alternatives --install /etc/cifs-utils/idmap-plugin cifs-idmap-plugin /usr/lib64/cifs-utils/cifs_idmap_sss.so 20if [ $1 -eq 0 ] ; then /usr/sbin/alternatives --remove cifs-idmap-plugin /usr/lib64/cifs-utils/cifs_idmap_sss.so fi%%-@F2>)-bP0QqXK G 2  f ~ ;  AAAAAAAAAAAA큤eRfeRfeRfeRfeRfeRfeRfeRfeRfeRfeRfeRfeRfeRfeRfeRfeRfeRfeRfeRfeRfeRfeRfeRfeRfeRfeRfeRfeRfeReReRfeRfeRfeRfeRfeRfeRfeRfeRfeRfeRfeRfeRfeRfeRfeRfeRf34390953d83d0c882f3a92d94f9030be137c3844989b52ec376ec76606f99dc7cbb6040f22f008985365c5e110a98a8f0a7443a0160627d567d4706bdd1cf74accdea10f634a0d2610a3b4cbf0512da206ecb71830dbcab5b8a7e973494b74098fc163d3c3ac5828b7abd1dcc20913a826955cc58f800c885ef6d7f012eacaf90f5b166bb929136d3ffb2ae984fb35dc0566548ca0fb2d6a5820ec3b95e8affb6837e326f23078dea9e35eb18faeba689e94fca59e3c6ca1889af4b5bf27b919139e1903277e829afe61586716f1cf4a4d4322bf7a7435e3e6b5225e12bfa730923daa6eb7889ea7aac9ef73cf3dd736659a5ddcf089a0d303c94e31eea2a7508ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b9036c57f43c939054fd4b831f271a14c97a488c38f98cdda5e887c5d396e3b3bc587d45894ae9b861b91b8ada1e62662bf482a92f6e7dffbe8e17a5615ea6af0c50b1771dd14ab3db68a23e617df8b1437200af24f2093c70574595c4f7625a54ab0cc2b914a1138271a6dd8a36b45e3208934ffc77a04f548d53f15053abbfe36c7d9bad4283f1acba2d90c08a578a40890c27dd5dace255f3a1b5fa81a5c8416b986cbc0044e549cfb8493f9c95738c61cb86f45af1c5a9693bc2773add2e299a21c42184762ae6666f5dec83a0b6223e4d30d7451b7a4a5641cf1c0f0a4a2fbc13ac8e03ea5e88193c47726745e90bf716ece393820fbfec32f86e575a5ba920c3da079ab6934c74446fb3a04ded58d48e1ff559db66edc3ab4a938242033922c1810545de1c52559aa99ae9c83d546a100aa501b07217b253198e4a3d86515cda966870b0b95d451c8bb490833f61bf877374f4b2b6b22c5e46e36345e4bf6092ed59f8e7511fd4383dc4637e9676afcce49393eb5637c94e60556c35d8729a87db4531e938526745d953325cfe81680ea282182de5351de5525036023a13d8298c1a78555c833aee661bd1ce4975d86c9d50dc4fefba191b3d94247db815ad5dfc79a81f4f9195faf7fc06342f97dbbfd690a4108f5ff5edcc777b65c40fe2f4c68a2b89487ff4e62dcfe70fbe7984a6d2864058bc5aa1682bd3850f3b0da374c67f35eec4e08493fec7cb765d5626c3c6d7df7eb8f7376c4a0f4c8b456ed9f4d7892c2d2230e8f91673573fdf986b8ad210346dbbbbd33d026b5b33b16f72../../../../usr/lib64/libsubid_sss.so../../../../usr/lib64/libnss_sss.so.2../../../../usr/lib64/security/pam_sss_gss.so../../../../usr/lib64/sssd/modules/sssd_krb5_localauth_plugin.so../../../../usr/lib64/krb5/plugins/libkrb5/sssd_krb5_locator_plugin.so../../../../usr/lib64/cifs-utils/cifs_idmap_sss.so../../../../usr/lib64/krb5/plugins/authdata/sssd_pac_plugin.so../../../../usr/lib64/security/pam_sss.so@rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.3-2.el8.src.rpmlibnss_sss.so.2()(64bit)libnss_sss.so.2(EXPORTED)(64bit)libsubid_sss.so()(64bit)libsubid_sss.so(EXPORTED)(64bit)sssd-clientsssd-client(x86-64) @@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/sbin/ldconfig/sbin/ldconfig/sbin/ldconfig/usr/sbin/alternatives/usr/sbin/alternativeslibc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.28)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.7)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcom_err.so.2()(64bit)libgssapi_krb5.so.2()(64bit)libgssapi_krb5.so.2(gssapi_krb5_2_MIT)(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libpam.so.0()(64bit)libpam.so.0(LIBPAM_1.0)(64bit)libpam.so.0(LIBPAM_EXTENSION_1.0)(64bit)libpam.so.0(LIBPAM_MODUTIL_1.0)(64bit)libpthread.so.0()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_idmap.so.0(SSS_IDMAP_0.4)(64bit)libsss_nss_idmaplibsss_nss_idmap.so.0()(64bit)libsss_nss_idmap.so.0(SSS_NSS_IDMAP_0.0.1)(64bit)libsss_nss_idmap.so.0(SSS_NSS_IDMAP_0.5.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)2.9.3-2.el82.9.3-2.el83.0.4-14.6.0-14.0-15.2-14.14.3eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/sbin/ldconfig  !"#$%&'()*+,-./0esrurururusvsvsvsvukukukuk2.9.3-2.el82.9.3-2.el8    cifs-utilsidmap-plugin.build-id4b054b8354c61ee49d4caff844812a9c33a8f7f94fcb9699f9a01023d1283982e4e38f9ac424415098ed7efe1eac0641de7a164228a4909a17ca2e01c18c8555d8b9918a5d1631066e12393078fe3862c23cb1480cd3cf1a42ae9570d7e60ae5c441df0efa1293f46ac1714727eeb19e0efbd4a76dedbe13ed029f6602094382752a44bac1fd3ea4be2dfff860c1d72cf40b882bde91fde58d63731d73a3cifs-utilscifs_idmap_sss.sosssd_pac_plugin.sosssd_krb5_locator_plugin.solibnss_sss.so.2libsubid_sss.sopam_sss.sopam_sss_gss.sosssdmodulessssd_krb5_localauth_plugin.sosssd-clientCOPYINGCOPYING.LESSERsssd_krb5_locator_plugin.8.gzpam_sss.8.gzpam_sss_gss.8.gzsssd_krb5_localauth_plugin.8.gzsssd_krb5_locator_plugin.8.gzpam_sss.8.gzpam_sss_gss.8.gzsssd_krb5_localauth_plugin.8.gzsssd_krb5_locator_plugin.8.gzpam_sss.8.gzpam_sss_gss.8.gzsssd_krb5_localauth_plugin.8.gzsssd_krb5_locator_plugin.8.gzpam_sss.8.gzpam_sss_gss.8.gzsssd_krb5_localauth_plugin.8.gzsssd_krb5_locator_plugin.8.gz/etc//etc/cifs-utils//usr/lib//usr/lib/.build-id//usr/lib/.build-id/4b//usr/lib/.build-id/4f//usr/lib/.build-id/98//usr/lib/.build-id/c1//usr/lib/.build-id/c2//usr/lib/.build-id/ca//usr/lib/.build-id/d4//usr/lib/.build-id/ff//usr/lib64//usr/lib64/cifs-utils//usr/lib64/krb5/plugins/authdata//usr/lib64/krb5/plugins/libkrb5//usr/lib64/security//usr/lib64/sssd//usr/lib64/sssd/modules//usr/share/licenses//usr/share/licenses/sssd-client//usr/share/man/es/man8//usr/share/man/man8//usr/share/man/ru/man8//usr/share/man/sv/man8//usr/share/man/uk/man8/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2x86_64-redhat-linux-gnu directorycannot open `/builddir/build/BUILDROOT/sssd-2.9.3-2.el8.x86_64/etc/cifs-utils/idmap-plugin' (No such file or directory)ELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=cafa1293f46ac1714727eeb19e0efbd4a76dedbe, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=d413ed029f6602094382752a44bac1fd3ea4be2d, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c23cb1480cd3cf1a42ae9570d7e60ae5c441df0e, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4fcb9699f9a01023d1283982e4e38f9ac4244150, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=4b054b8354c61ee49d4caff844812a9c33a8f7f9, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=fff860c1d72cf40b882bde91fde58d63731d73a3, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=98ed7efe1eac0641de7a164228a4909a17ca2e01, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c18c8555d8b9918a5d1631066e12393078fe3862, strippedASCII texttroff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix) )1>J   RR!R RRR R RRRRR%RR RR R R RRRRR%R RR R R RR%PPR RRR RR R RR%PPR R R R RR%RRRR R RRR R R RRR%RRRR RR R R RRRR%RR RRR RR R RRRRR%utf-8c92d793856c19f101b26b15d1662d5ebbdaf85694554910c596d6e246bd5d104?7zXZ !#,=] b2u jӫ`(y/kӟ%9:Z70{?⫓1 y%t#}U([׭!2e?$?4w̚f%#p̏4Ti+Om6$qF_3<܂o`!R !bk,O꿭 YNy.ouzᭌ=a^I| 4^@d&F4Q(MnW}ӷvqE >v1)tٕY}蛌)DkRH!>rq "vn^b6EITN_S%Ґ4Pҝj NNѯjV= HS*5%~EUhR΢KlӇXJD^Pndn֚j nc<3nwRFuz 5y/f+HbkLX Oq9r(` apa!@39 ̥0VhMɄJ 7*Tм3և*vzwQ'#n0N6B7ct| چ'|V[CHoз7aֲF1*i}ԇ3qMs )eD7lI"&- ++]U=v9`M?TcLH;{ t%g0Vήm=W@{&7l; h=$NBۻ;WgPُ{Yb?66 t"Rz)I^2'\߉le"H‚K8 ]C.35z*WQ_[EEOt7g6O^* c#Fbfy!ؾzԣKt^ycTu /;,X噉MA/߉+*oci~}{cp@9i),[T`/I4Gb܉iYE;ݹ'wOep39]8v]dj=̫Gbh(7F$,M%fg6Dkeȕ/Zٮ\~|{Y=R}.?JP z=)YSLzK: y>oU'#.2BE>5`4)i{eK=1b=5A> nólP:~Qc#j`䁧hvvu (\kS_홤?˲W޵@$=hټݐiɵxbVkOp[ QӫC~z^c)6@4K嵽8ί_aʹخ.Ԧ?:TNy\3T]KP.Qd鼥`R_J:0+ RѿBڧI~QW=@ާ;(XìCr:*G;D^ |ihܰ{X"o &)?ލ~E_#2DJ -LJgnPS+'Yq 6M#ay9d޶[-&zn.._EǙ [u4ChNdf Kn8f?VOI\cn5ωhX7m#T9B8%()s00ҕPM6VJmTE mıE4E&1DtI»Ķ%n1% ebOۜ$&{vĉ1\H*YU |t^+|[>gKx/ ft+;-7ĹT=i;hO lK/4JP2!PAO!|~ Pw+[\Ƒ9n$,}Ɛ#S|GxᐟDP2k׻1wn[fہ'-g:ҬTG~z_?V9;b1 ŷwĨ{ #ˑA@>Kr8{((v˝ T5hM\Wlm{Yӟh3&?C `l6䍼4zȈ&U&GYlvq v>Ac}5v]$+pAIs_$k\bs(!uj ; K|Y:Dfhwz)Vc_@͚5YvGFv0bE||1Y1}ۛ}/GmjX+ :D6~3~ "vty^$r Q.{+0t8jڂZBŊ1= A{;`{M F٘ ږC+m8A]'F#T,59yb~\]Q«R\xY%7"}P~bZw&adkܽ{=ۻMPptbO(ujpc)*j BY^A c(\_X8_W&ZG\xZ8_&M3l Xз ]lICq-"gL@;l`bKۓUȕ:^UXZ*AL5s%|2EϤS lGkM:qϘwWJs5J-ɡbqSWnČ/n_{7y$i! ˍ~RDҸ.} fpѰ8yT}۬A%>+y8 y0KN U1He l}2eh](Q;ڎ cvJG9ԭ S{A wv[ܩrO؞8I};̀uY<HhZta'&_bDa̱2mw_g*IU*S#V(UTN).dEDff0 C#M?|hQ,v́ak^p\sJ݉`:u,!+jquv5㜡"`DUu@p($noK9ǯjּ5Xnm̭IeΥP$dku o9SζEO"HK>?V!6? )rw^|AV zvؕ}K‹J7BӒnP# |&ef0 X"5Jދ*#ឪ NB!M.YzXt Gv0F !-T 2i5h_ؖ}mq'1kٔ&!yж͈R62(K袘3jN `C,ySz qa|3~mQ~7SBz䖮B#ʤ~}L0R AmH2&=K6,߬99{t_]%qHhHϻ~P#ȧ`թAPlIPHQs!Ӂ$Tr`bФЪOW>C*5v#6Ҕ_ h0tN5N %f9'/ZٹAbh"oUM^9F8]UM~~M؅k͘  w>ϳ(Hˁy> tƕIoUzGZ&S< H>b+ %&Іv1x!5ީ.Z0 hMv*&m}{CT ):ƪ˜i+h涳cFYpAm^4 ]xۣeLR+ߛǟ~oA]%CfAGGK)[;%q wV@ʵhiiT+Ցn?+i8]qݶe)&.>>!߉.S5:a;BLYm$Ž+ /(61Λ sd6#Nv}XCGuOv^iEΩl(0ҫ1qa8*W QR%,|p-t y3"fE6ra:UV/Q"ޡ6+/Jn(C]oB:s},6ⵎ0 )75p/qYiuϹxǩޱ )5ys~K yg VoBa 3R),9vD~~=Epd2YK5NWaC`alyhm^H?0G EN[5*Rf&Lm6ް6$3")aIz;r$\SICA >Y5z];l'/K=:S{ɘ[hC[aTե;@ k~j.i6kXBZkh܌ ~HX|@IUkiUi؎wD"lN2XnĜXz ^tg|z Òw$L%Z ̣NsۻZu=$~pRK Cɛ Xv ĉ|?v]E(2I;x3{<{*8TGCYQ9?dȠ=< YsHAZ?ޭRX$LҺ<7R+~~i){bq`~ Q*Ł. `_f5HK`{şx^Fr  yL#~b Ŷw&\8oP ԣlB/ImsBL^LtV&i;.ofp`gr6BRi{ D O5}%mw&lOdg5aGؘNŗ9'L`hs)GXwyA*NhɥX3^9zTPu W SֺohA"I'/slè Sp?{|Qya.-s (22C xń:;WpV?SO5X4u݌/m=cFAEПQ:D׻J6[:FmiX ?}w.),W&xO}3'N`x-vOZsʅg ŞOɘ-e^*E*3١-$]|tf 'G~p|z1(Sl¹^Yif̽!>fƩ3zB–Ca},U}&G.Zbq?;d z.ņ7r 3hl&=[3f-.GO8x^yh3zLc (P [Dcߢɞ1. ‡+<-3SI3ȤF/~U_⥑Q%3S~I.Pȵͨwɣ@ cQd_G'whk:K3X3OǞ&/];6#|79B9~e`w7ۧM.hg͔m'mRD!ZH/xS"cE(Lo9`ÆKaͤLe%"4eSpONt ^+YvwAױVQ]>봶AVw|? `e"|O-DBE +)19֮r4 S'W8haZmlX=r!B 2ضDO/X੅_+\7fYV9'$^ \0+葺1Ve&T&3de횱 uZHMHh4&x~a8? K?\GdpnUU{Y5B0B6iÔFR]̺AB,a\"n#쑏[$ 6"?[d}hz:gK&"va< ^3>ꉆuo 3Cts!Ȯk>"Ƙ/DgI,M;s̜#zF] (;,>*ME-WQ2lNO̶gsjgҔ#e2XZƂǨW 2+CyW!tW(&}*p2~ps)ǐX N:ѓ! .(W#k]Bvt"l^O(1:]lsD ,@3zWAsmzg$ $͕ү/ZnmHyIl3W]y#"{h< V6w(wc2jSQ֪f/ `Ml_VIpx]1#j膽,vS,WL|TW|;@!VHO<|o5gKgڏ 꾦'La$TyكLΕx| {'Fl>m}>!uX1b:',]ηXL{5|-uZW>1}=S/C?XlKn_\}TSÓ7D -nv_My">`Wx/d"sq"=ۥ \+bsJGI4yj dMKI.TĝöΈ?mZYҍ3 1ꭂ6Aa r2?rO ?j=pnJ-fI#V_e Cp!%vܰdxڍĢB'i9 K >~N{cU?se u M*=m"Zs95Eb&0bi\֐s"W;MfzQrP+^h~aȍn1=JLnvVy*y\:򵔾*4*l|U-Ex%H>b̛ Ah9ZK= HGkIdmKs̼w%Q{l+P ۻP*+HoU 8s]`t瘾}zd*}b%E'XHVVu]b^48 oٜx|$ASIsSW<4v4^ t%6\@{/K{Em!ri8 C32OwM^JPWyv<^JЋX/ Pe%16Iqihk>{:ƈ\P^)NK[ Tz wZdÕr!oi8QaXK4N{9QTn^LDY$ȒZO9~iPto_b-_6&J^Fg.5z_=K}W(uJ d=#!CERuU;=LT-KA>wCo^~4(iKT[I#,Di5ݟSJGj6de ;(:!"m奄f1`|zS}=Bd )<.1$0b ^um }-xAъ8oh, F|>·A,bm LfCNϧ0>Z[<5/dpO#"lo4iLd# gQY<3(y>oYmG=f"t`|j5R&TwR@ ȉKd͕DIѝSSTx8+ny!Ι;7c⊄'2~i[mM[g@V)Մڱf慣a`1K9Dw5#>+n.o4v:sM&Mulqu:,aoaa;\~gγל/HheQ {w@pE,QP{ c#=t%1,ydal.wTj,ϱy#A{ƹM9!WZ]y ԕx](by:vd4Ro~ {fDtC­bm;-\)FDBfYf(@,͝ ]E뎛Ⱦ3%ص%0P/Hې4agdc2,{Jz/}S~Ӹs/+OtaCR)Pt IA4rn\ :4+U^z 4T1]\٦HT]FpiO,ԑ i}GW $=ōHKs1ΏZNzЃtcс蘁#ȵU50zB;t05YƱ T >f4 s}UO9қ"sO4/`D;;QCBqH4$jh ~2\0=rX[cwꐡ"k5لVtRɇwl3R1oZMGp4>րiI:HI.hA &hY57 o2aΖ9=*x~=𶗤 ^XS9yd)KU$sZEuLC$̱Zf ZgZ92$a:|@[eQqbR:ރTkyǩ In*jgEƒW1J;Cf/#W07HzjQmIqz9] 4j3׊"T^W(a'7 'd$~֚4]Ɵa/0!| aN7 q?s6\({y6KK3wg#%\{G Gę]_֚rRE#qUJ ^+Ʀp]vL$C8DO҂ۤI'ΡOriD;mBa`y軲nYDIVFPY fuϿI1X XzP,7l&"BRX1SJuG ;d@)XIlP2Bb0I<|˱t]G1b*:j` -p&hHNLX6+r U=%o QyA7]B3{k;hDWSVHo*Hq`v>:ܛOB*_=U!-fSpbZk| Ӛ G J*=hlv@.B|> ;ct(Z$yJn8Dl׾en?!=" t^l?憘]qWPQ=b%g~:؈܇O1g+$ojx3NvעI]Y@USqX؄^Ex;f ϤU9g&.??b_t k[Ae`¦NXb9D1%߳(HtcrokN9=O ;A?$Ki2D@%^Ijs!ų D} 0:aTP1ʎI5+v*z\c% {)jS`FBr'nur'wtd*{$[B E}! ýl^qo9jFs)s")6~,a>M^pP"{_AYjkC:($4eZ,P6TPQ tx[|kw݌ SX}XYOoj㓭nFަM=[Wb:!Q$CYaQ5%Hdχݯps=xe=U*G0ȁ <;8@u94^춏u}sUω\VaVߙeHJ MZD?^a N>#IPZxuqm&e %X[[qԏ8&A>8筫L GW_'+?(yEdshEqmD<mHKװf/Dlé +cl+XQG3|~5زPmPrptN: }c^jŽE\,>ck;HT,fad6翰l5"3*k<#dv%-n^=X5P_> 9q F>畣UdKep:E':Y&V>uΞ8Aw`gr'>}`d^LSBZ DCҗ"w,\ȵ?E0Mi&?ݢtfe=_QDvAl6T?Ʃօv ,n3n#v'}I`-L8Bd __eTA kY,n14['M{Zw3YWǡ_Q6ώ1CIdN ;mS ԑ }hL_m;Al"Dnoǭ0x9:_ltX޷s\k[ɴ*HW!ިWt DQQ'ZίeDEklwSF;Δن=?kx1 A {r|ڵAXe[Kt:Y{ꭠ-_"dJE}_\rwnJs͕- l-[L}LIΊR߆xG >Oxưy?|`y V=*qQ(˩=I]$kjqAaL4Lpt0̳JtqR'̩Ysn?aC83]LtmUO%"" ZOדl~d5ƥaz-W]6q1E!jk?};pf&EOOU& ixJarebl>`MVώKCJ xzA8Iu>8jm*7d(! uNJsxf/@$䔔ˌʉ;ݤ(%PO| ٷ P McӦCSwz6: D{# -\I6X#-O |X1q{RjΏDft;^kYR)*jR]1Qxʍ1+DKa,iNIٕIluwiw ?q`d!ԩg6QPn{/B}cqA~iߧ;"vX ,>Jsf u(^R*Vj[ń&XֲےڽK|g!8S, E[DW_cg0H%;53Ȇ<_2:rf;n67V c0:fBMӎq!XףGT EGVת=Vpdit0DšqS7 Gfj$-R]e\ϼ-XX{QaKg:ajOW)`Ȏ yckn/eY`E*QGFd{&@/ }"wx4eYdHN*Z &Q܂@M1mGў̜@]VjzȮB$#V*/ Il0q oھLğluqO^j[/K@e; &VDXdM&H'8xw5K՘Ow\vVHy5Og?kH,{rrp''Iu qQ^M p֠O䱮+ꨵ,Ygw0uHt>F˴ wEq? oeJA4kM֓y)V W95Q^E01*3.^ux5JLkBn $}= ߥ,h<阪am`+E6$TѨmTC|BJV w^A;^P4 L9; :ZAnޞV':B~ 뵳TwTb>\XpDAI)]$ &,ZQADEpqAb#vGK ٻޘBp8ώIXL0x 8}@bC(i%8?gN+E8MlzP׊`QXR:1(P H^J:}: =BЎ`ǷCh=hM@ 8nmӘ҃lێ#h;/H1Id1<;0v2(jͅœ}[#c8] rF#z}CxuHt'aPRnEdk-8T E*DrBfO>N Zyͻ$zv! }3<$MoŬoP<(@Ґune`FTn_"#uȮc{_^WnJ)eYOӧ9 t$RM9\J_TAh !N&|g0lg=RꞂ٨#Y '(.U< \} e6PtLahWS/gwV+>kW,0$y*WDKIXyZ5Mg]{+y=E!!ߕ\gRr VM3yg럢K]`>Jg7"{]27Z~1Uw!^UFuTЖDu3eT; wz㛨.> - ntH(f ܾiPWy8_kGskRF~ ׾LRMM3J8 Ȼt)Cy8| te k>AUZU$lņV2)$2om6Lq6x*MBL2;jdzmnCc^G# ô$IVČF1&jaI@檉4O0sx0yA CAb>1ous6+|-5yp41LPU־e {Rjr+u'_? _qL(υYCfPk;H7| {X/&dҴ4[ 9j R11M;\ndvHgtɶbny)Ʋz[pc??}2MMA৅Ꮸ 4 U +Q^l~Sd~T I~Le hy!icsy)قY=Khd5%p˚>'p;#v籰{KBJ`| _/)3 q?Ӏ;P}Z茂 aV|:akk΄<|]b mCP+N 4nWL 3ʳG0ga/OuOXq5k,t"W`c%{]O(~08h!Le/~by(C30)y#!2}|)⟐k=vsY_ۏZ,c䊃S/p+Љz}!Vב/ 1ndt7=ɍ/R f=Cu83\vG08[d@ƧD~c}H5oϟsZל^@VXc'ꋥpB5on8i}C,chVM+ U華>_c+FFblB:Ab!|e(=aN#mM:?ac`}}Ђ)$n0OFxoƅ;[CHa[mgF8ɧ6_6|Hn-&ȳ$Pmd\p?MTY@,f@89,K93σ1[5퇃-HmPnfhXoGd4IGWqrqZ#Q+k eGgwTN!(1OY5Y[@gҮx'9Ș?2j~[oTTv0&4d EvI@?ޛNai J |Md3!wkK-"56!N&%rZ.VjBƑv'9dY%wI7"5kgAk1!vRf|,؞HRǂ}N^l'r7 z{((è.Mo<=?GH34@Ԏ2Ep ѫWIARU 5>?CVGi#.>Q%# }^{w݅W*A@ ;vtw qb:1 F_]Ji ʳ;RcCk|r̈́-R"eWv%[?F(GS|@l.{Tzy  _yNVma7D8{؟$uo{䩑=0y̔P<6ۑ^Ox<]Qk%7WKV2q#p@8n|ҭG{ߣR Cy)&e|I6*zI2ki}[wԶPF$-'_x#W!ZPӚ뱰$/iR:kq[^stB kϩbVDz+93}3'Zno_*F9AmYeh6i#As͹c~u+@#uc-X|n4/MXs8Vd/wHI:"@!TuR4ock[9 y?=f\gz -ǎcC̿I)1<0I˿c F6Kh`3Xp0Oq YRk_cp~޽L4QHKwE"B}맮?T],'{ U ^P& Cwt+ncYMCr6XN*@`k]pfkGЁ KC(2ia$^S%&ipSU}O$kn(:8t,RSFEIGgvS0e.(#"8[pzsr,]9%b]X͓؂)!)b `BDw z \jGGcNtQ6N fS`:RfpN9Ax?!axlxΡThA#GCl0 WS`/mȳ7rYJ&$~ճ)o R41gPgNwO߭ P\>t*+Ω͒ ;;uKEoHxb.I+K}ƟڼƚFčaI[7e0 b [|]DD7Iu4}T3X&z!an5Mn9@gÎCܡFv]SQg;>d. rnr" @ T6@RH19 L#o4Nc20zЩ ' 6n25z kTecI,*_jQ,ȹ!+,~"iJx%%BXF8@ |C؎YE;4+ē }qVį}ĵJqr[Hu}aH]YmTv;pρx#dO= x-X 'lY[$I87b\{IC4t'쐿q"Kt~ߙ? \s_M.oSEQel( 4)|5?ݻ+DXﮍ'8EeZDbaȚr[7{$.{pK qܬ5Օ~NpuŌUxjS fqfE&Χ0`sHJS*۽?4+{7k&3k j z$Ƥ v%>BW>˞.Ns1|]j 3$+]Z$'@YfUN"gl܇Zf@k/Dy(ASX'̦~偓ME*`4 /LF}Y:ahw ߨ@=ԙ-i-7g8)rR3rQEHy2pEĶJqt6@57jj}Wd4Ҹ1v&&!,\d_^AI4~LX B`XcCm.Z~C (4^=.j2B y%5WuxS r`G ;xDoCIEDH:DRh-Rk&@ ^E+CUh ICފsV䤇Qp$f%ӮBAI  {sݶPk"`cYWUH>*6!9M]{[5K [1q Phlod voݗM?:1;"0]B4RA AM`Q3#bAy>+؟x ՞!F W ÍŊ֍\"J|5e_}8"5 ե\삉S4t|QnPևCaa.I >E*t㏥qoM9:H`sEQ1 P6.>wSgqݑ2j+oƦaFLflYC!|GXYoP|c[ ;AL|Rp $E%2Ɏv_hcQ33R+;H\=@͉kyƚvj?QC@re^fN S$2&w.q_ZR%s6xzvz@=3CqlXv "~h7+kÿ:xɔ6k()K ʧJd϶Y.sN[cjk'm &s/^vA;Y0HГ؄ڱر|Τ.\Q@`mgױL i-jcT #"%0;@+~HE= E1eE@su % E:M!vSk]H!7TV6-Ė&=^ ~o hfdF6ĺF4[H%ۍ|f ㆞I6d2+*YNWd$8bx$SC`3(DF4NFTT X{W5qх'<@Lb]w3b^-RI[)Mȶ9[T~i|\nB},HE'3XOHRCa"K]VX%o\iɚyӥkEV &6)TEkʊL.ɟnpŔ"d=UH.Xza ,\B Y.Pij?z[4 EBڨΧơ0F'cǥ1吂z#=e1\plM,m';R&f8OD5k$2f=+ܤ?ڒz9 ,MߠOn =Z.t? #ת?efcF+N!q M!p{ ) VK{eQUF V.Ά&n1jyc*J'nʪ+yiBҰhDN] nazA5X ^ rvJɿ79".#IޅWvԖhe,F\./rtQܲ6?Lq ќp#~SI8쑘yٓa!?}Y>kHgZ}e4՞CNySU$AG?r]u+R8Q)z4_hˌĜMˬ] MW#a%'ӼEq~'Q"U Rm?wu8 O9ち^tPdjSbEǥѣKޗ|*³h 4{d_fUczĦ27iʒ\5mVY_rQ ,!/(-rT?Pft"k[s$c%CcPՎalj` Z1`־JD"Sā;R{Ta;s 1W^)%2b}!ڕUd[Vq2Tiu6uC$V#]!` !>鋦 'v}\sN&ND֕O_"xCWoK?9>vkAh†CZT,Р1"Ty;pы.]=L;1D \}FYO+ۥf#+ 3Kkz[q!YeD[PGYa1F9FC)%BV.@W"' Бw>xdQP<ð(6FOa?I1?.^:+ePT4!P2Fw3DG+o+L},$[aAÖT0F$&S"e-uLeO<C@~UZ/=dOGBy1_ib^ 1e/N-My=fs ~!,޼tn0wv1]$|u'3X]\QHAM2N%ϕ⬜ uD?>/mC}qG9ܐ㣀>ڛ{0Ti됸9sa5`a| źK"_EGQ?>L{1eI͌Zt$RWU <քPGuQ^@qӃ{$Z;VP9ar\[fq( T*0pмgt>Fϡ^,ֈX=ǨttrWF' n( A%и a $fg ѕcۺƌ;e5(ehNe7epl[jc)]} ya\=u*#Fx2g\;KC~%bF⪸Z߄<Rmyق(` xX]Z}N ŘRe:1'D9ٰs?-$ѹ$Z9?M'(w&!LKnG^2>0{4\ z#Pzrl׷<, B>iAưP_BVޕv!lWE8 CS@C+lr Ao,6f?'Ů%$sjг[蹭,оiZx @UD? ^ Eg/w mjB㌊?V Xj-6PPpf3ݹmMVxUGOWDGeny)&rCܓ7cC\G55JW(q1PY"9o%hh3%.6lx\cp> ,5zʻ6%6M.@_$ā/5 ٖޚbq"{+@n)sʵ T?BB| tAyW8JC/08,S!X:sisҦ݌uʰ(g/q=6 B~UFDK9aDב fa})̇NKc{/$w( TMܷEt4뵌JvdU1kdzÛdPv(;W2.pF'oةb۸@MYI?rQݯX{C1> ތXHjeܾ T$Sdu XYAgxުKF|Y5+>ciJU.[ƼN%K7{3/ )@6*gaCаoAJ% @Ar _;~B0-B`F+29zb27>0^j U8rЛ)UAi !H<3W3C)~Ff2:h䨃8FI'|363\ΞaTV$, >֝8a_$H5 I|RLj=̈́Mǻ7zYfiѭ:_>R+RZ?*wzԶdT>~5.Wet7-Q:0}3ZkM]X\z":)bU}$3aebra?(2b?Ō87k= qC5э f`kr쮿)?\+t8MWz-v]Fѽ(e}O/T=b!|HXu2@i) |4\1l}8$M%9ʐL p’CAܓ67:>~oxD\dFhXJ! AdVˋd_G}ˆ薭g1FFq\S0.|]z̺ ވZ"#e?c$P9Fl h~ķLWFcoƿ-LGu2LfJ<u` eKWI}j%A_n/32笄DnDǵF<ߕ.RĿ@<φb_znAKA  sW鿇IT[u|pgnY3z>wĢߑ!J"4b=A 8t疠8˹ltDE,ࣝ VX{E'X( <$ΖM$ 7ڌPFWj`E2PJahk"-t6} |o?fU᠉!FjOXJv 0t^vVcF%e DqO ߎN^gϯg)dc&13' Jz|"?acZÉیD̜hG?ҿf{hxP\y9!-?|ؚL%sM3&j= TGV}3E| Z&RSm\rZ -䝘=egju5^@(ȞL-V) Qۋ,hDY1(̥//+ AeYL 0AyR8@1_sDLK/`?ׂ" noٻ5r=jӥRmctpuOEI]*UvZ`q*5Vpx.Q*Әh>&y ؿTyp=٫L#[q"3>(̶$zᡬ^>%E9vK.EfJ RlGƾ/u+Nm_j &ݺcFZzwR 7.ʳAq;XznT 憂D>n4>:ICNTo*UȩzOK!< ݫa) |(mD " 0?v@^~“<ٲB] J"V_yA !ueqb "C>]mկ&*ÞTm໼|$dn֢[uBk%kGd[sOW|X}g=),t23U*ޞߺEՊۅ. Q?&͕:u숹t&á,jO.Td(-v/Q*5ֽEtc,OXhrSql{҇_4 y(,oSK,cP2VRR>'3 yd[Std64ښtSy R_Yt`*n4pԒWܝĂ>70@t'ؚ;<~,NaDu>4%80Cv ڸ6vvPraQc=\ bJT|_ [K" O~F\ ZB:(F5bQLA~z'(R}OuC g>sP 6Y-"їnt Ћ:-M+7wѢ޶y.u)vfA2ЧJBL!6i= i1՜m~ x'tY7b9рA6Hr(VVJ29>b?htͧT t=ner,]\q|l/^n%z[4ydz h"quS{v |5x;U{-9NKעU`GUtj$xK[ψSo_7~R{|S݌쌽;L?8 .nD"$"g:ftWD:hYO>؜S#T:@m![鹾C(XjzπUv?̢)RS'؎`ǮvC Vm[YxWif6O|yo>y-O\uSzt]/*ݰsx2)@TW=97۟m:\Ÿe/p+E&r歧HO!؛ڃr yij9J}@Ƽw>`w>ؘė#iߡv^ <u )ʟc/ 9aA 34)%%t$ZYӌDa|~D2̓! $L``yoBFErk땠"q&;7B'J\`"v|gv=hnSJm;f"7%g ,QP]U m̤c<=h9V L/i)oΨK'lؓ.u`a_A,'2zI5l % n\hf38#@ hۮeW1ȐjddNklؓʤi;[Y\zУ& lK~V~MHXTcv9%isPn~]tѱ ޟx $|wg2({*ީO^)ohpzM2`Hdu+쬀Tw_`^JfѺ&6!k#Tt<"CT6M+FO7J|Q Qe\1{g/э-|93OʘK Hk5ޓ^<1 )EbnF3M.WOGI ؋3GNqV˧9UXDz,.Q tzNM(Җ`A|AL6 k{F(ұ Him>D]jGWYo`ώ:3xdjNn;r})ouO۪r)2rS|^0JQKj62i٘HBzY?13_qXNg)2Bb @Csgw-Y"l_Et>ȷIyzQ 4临*Y}XJ-s%*D2YgX5U8472+^uRsRfBVL c0f;CܨQKFsHp oeHDPM^ ώꉔ^.{9=_c~,Umls2^s )uDD/Kj r⹵.'Ci1n:l5P-pwUI5#\(2AjV:{={(o"Jo6\65}0oWy3=:\,4Z#41eqb%ʤfݘԬUOhͥ ~m{Oz8fZ5*w{n)J2X{):΃{tM.KlRd i~ _Efm9;U-viUDwY0~ThM+׌Mx!뺣`"[U՗M}8.sKZAGZ/ci'<@vѽQ0~lh+3Ju)dM;caEV1'-S+@nUz~`%idxM`a@I:/V;xYBZ Sfz|,HdnhگC,U}F|p"+x?Aw{/d(—!tWū8&7lso6:т ~`eU~Hr jT;(K~H8 MC’#c8q’K ZV4oo,v~6Yrͣ&@| F*DVS\/`VWX2Wg-{q*}mx̻X(6h@#)<}@#A!üXS]tfd[PlA]Ng4`DsV5Ca6w]Xkwد \۰nHV/'8>'#: JH[Z"1;ӐW8 mYhX_UWE-'b@] l@>>`,#hճCjnǪZq :japiE >vZt'0jGr?@$#pzMFG1ŢtNN Il'Af"k7uG@9^{Q7( W5R ŷ92л֓|\r#Qˆx +)#p)ݑ+0VclYoYݗ8STΥ6'G^(]fx\2t5rtDQ:Kݗ2AG"+z}d{z5ǨRȒk<{L]X Œy3T̳Sb6z|Ub<44̕O6%J&dAވ֟luO x$w}# Hx)-*ݻPPsB#A9S ,ge=1OSåb]xV{杂Mؾ%ҾC`iJ{WR1ݓhY/08wH8ǍDr)*f6/ 3T$PF/]&%zizuU$\<ঢ়se+/,['Tq 4*L F"uqtkznj@+w3#r_]{E)܍{D6'm5T2g΃ j1DتyBb B3ۂGͻ\82uEnބh\}I^.}]80}Kf62u?B ]ix7֟N^x[OкBTt/bݪnJ .E-O =];(]r@gj3b4⴦[^3jW8|*θ"5$:ȋ^<\+~hY7&]Xwi; !BERzn&A$QZs5?(_Ĩ.3/7鵦+FTP-_ȹ8˨Ilة.ϑVONj o(d xoX 8Ӷ i{VtWƳ>Rlk2a?PE, (ˠl[mb m֙^)5/^+1e^e;V3ʂ)ǣv6N9> zI[# 9t (=^khu_w ^ozw! Ajg֕ZwӀÜJWeŠh 1W_̣('ؑZvCQy<•lRT6pX Op/p3LjR#0HW4!G~$B%Yi?N4Dcݐ N,nYgmYBi-.j?c3 a bx2"/M« #>Te`T^[2r$8ehͫ % :ɥJ0s*oKg}9~{{hu\R#b>W!4)#4cl]t*X=;2˽FwzeӪul$}p6ɢD+ؕ6[k.n^$+<M =)ZKXO0&^YlI[%kx[~e>BVt<{|XARnAa~qja{QS6Ł1bSyn ͊fm CW4 +qzvjkJ\8VG | gsEYDVK-1X ?Ib::rL- 5;| \nDrn:Q?ǘ@/gsyE4_o#b7\Gao)QC|9̟FkcH{(OͼXn"'0vӛxA.x<8uK?E٭8EE1\˩bj{:aZm@v:yJhKϳ&fqwt:aև."66vv]U[LwY?!)T^<њ|rbC$4Zl%]exq_;KPtC5F3AHݥCg/`ǡ$E|%E)`(y> T,d^sRgL}4 o:f86*>D:Yg@`P;J$_;ƒ@^JqݪLWޥKR☧Nf3܏x1У?` xGb9`Fǥ /|j2ew $ ơt3@*/Cmv!&WMX%&>OQGf6ˎ<'O9cyQetoZOEw`@4/X"&/bih8H KM k<*,՝X!e]bVv:m36Gi^tkZLVG#)ht7o;3Fx N&+Ca=U%QF\%f )&e Fo+m°\v4wRQD[o&tkO|௃F6#o>v: r4inz1^Enr/Hd%Kq0n&P+ .ϦӕclgU#@)"jH:9=pD]f⢥C`檐;1)#17 T[%fLxPضvT!ŇW5gjJɺܻ(T :]ar3m.֚ ]f񳲽][3۪ i _7WQjFﭢ7)BoZF. >m^Eʺ#OifM[s>zn23DnˮAϪ qء 8.8R\g0,%Ve>-AUdt؏ygyn4PB},<3Wph1fKg-nxyX(}f)2K'd9-"̔YLՖ֛{0(PI^B['3>* NCֶl0DALPh JNYe4cƜz r#Y;ཚ"Ĕ+ "{kbI8q5M l9Ux1Pcgʩ^zN5J}R/MD)AD(1cexu-g<<82q}5??,1څJH Z:}|yULڛW&Al3AM“Ks ,A.GYɬ0>rOZ!vB&zt sٷI=qcp"0.?Fu2,B/vH3] ^-ԉɝu'i1o8RVcڀ"I/n&5ؽv|%QFY3f D3:Nb/-]8ovE=rΝ8[ԀM _7Bb"d]+W/9FnTO}ڼ6MW+[8^M5QADArL90ݚ5BI?%Cݾ¸aQE09s;<=w貅Ey]<`8knq+*AWL %;m_QYY<!I$|_쫧EUHhʒRK$lRl@GRByOEĢep]t7l+fj%-$^wVf˷CnV21XX^|Ę=W=리Xcщepi5 bTe>^ L˨epmT`.cl(%MZ7u@sq8&'Qu!4fx9W}osA X<e CO#XGV{G.pb LZzɰMdGaAfS͞gͬ|]L۱WSXxra՝HђCD- }uۀdV=]}g<[uva ;s?*E'2іF1A8$/ hvK#{GAWIE[6~+KSȜ^ )\̕#(q?F 9)uur쩙o.#s{ٌ#(% 9dlkA.V^WVef0?)dFoi`;Q})54Uz!?bQ ³d%àv3ͳ(.ˬB*JS1 !eP;sd5["ZpnTyԶz d"neEo};&2q.F+:E)ħHHĈ r8X7@IjJɥ?/r,LɋJ 1"ju:N,ؚxԛ !GޣG !|1ۅW~,nn)'QTyá+>c&$\R~fYS\?1 1BN0 =0#˭v`BEC2H& ?/9Fu$my[qHb7GA<+USE0B"[>4q܌/܇ѠV{q ;Q_ Ϭ_u=`2%T"+n{rü :7*s Ӑ߶IqI{ ]2Hw7FB~,dh2Ò#Iu/AҩBg*@So3,)1&Y%9θK_~[Y6`PxOSTA5p"7GP. 5D1>n-nD[K)fR08yA4حT%1@K8}Cx9IэP>TqjJyVftr1] QfW<*-?Gc3N}6KxՐ%zϲ4$gG;j|-x9c{ԛP}+I$]Ac4AL8zVFɼ-j槲]=u\pYA"f]\$~cGY_ 8߂M^y#N]\j 7[%J} n|{>ʶB sܐirgY5).I he>GiV7TT**MjZכ1An<߻~[ zI,?pqw:i>YSGP@z5(.@s>)}x6t"(o4))̴4n$<\6Zg[ɋJLsɹ#(3e?R&%amXXd*MWΟ*ho jN>C*2X%?GjTS_JWv->DCqYKt8['=UYz-vv2/*hE^Ao{6ŠKЫdF-Ze,`* ŻHK)hbq{q-췽 =c$I!So n Hpb;25(;Xq8皒Ebb|]N,MG /<4%yTz ܼ"OGJq~ۡx32klFE(TZA ŋԨ;L+nQ,1\DW7J hd}oov5B!AqiE5iR{|c$}] "o]3cڬǝ\qjy ZE+s:?f?vwb ۼF=t{o&>(7܉~D 0Q *3 [9!YY6]E/OpjIp{ձ_R,qaи2U8N6?:HI>ðp֨!0m]-%/Xglpe(Q̐].]ԡ97Su^߭KQ5(bm5n8WXN'-i.s?e;.B]M%.Y,Ư|J"4O\v=9-cnG}80}P܃ C("za)@` uF2r['kyCҽPNQZot3ryG/A_&wcW>!h1߾rJųj6J'.\ђ,*)wj4u :_l=h]Y VVr ]eȫ᪽}qY4~ܗJ 8(!=[{}9{>Lӧ%#Zܿ:;}B%*>l>M S1s^W3Q"G^UH0.G[Imj8E\yMnJl@ToM˺2ILȢ2bۘf儶/ӣB P l+:(NjamȾ:k|BIͤ1)ڗ2c0g!|FB^zgw4_n3̶;*spL".-* +fvy(!M'y2y柖[[#3A~֓@uNb&wJ-&!+ dw${JV鳞HTVC{xY朙( pE[3 yc[a)bSfU<3S˛8LH3{X4W\Bk+Д .[8nc8`5:<"H4'"0K~^s3#mOU-T dIצ|z?yibjZ&Ffa).8MKbΫjM걾px?\ikPL"h0j!_yOǰ9ht,BIܡr[  BӇ]8Qgg0} n !|6qPópj}I/*W vX5Ih'V2:Hv5O݂GFlY!0פMB5vsQt S6VM;TZB] je);:$[kjFGтs)4&OF>@3 w4$MH MQlw/blCr5@[4x4%iTEǡ܈{DoX=C),aˎ1`zL)Vm HM-pTuyKdi B){^?!߃/q43m|s6ma`v*ȋٱqs?ms.kfXNU6ջqkM-_e:ޣa:j JMc|;ۏx6⃔V^d&*~{aNZbaUru2q5 ?!9L/- Lmgy?Rbt@xUoIh _CK2=lrKBp͔‚OV=+'3Z TJW~?v>kPRw!΄XNQȓI܃s1rقm6z4Ci3>W[кJ'2@GuD&2C8"PNt{ 'D ~e-)eՐCZٳJq+#n%|Q"A~D?j+ȄP+9yU̍U.Sa,T/zq7 6(٤=i/{i~;}Td-1FY;ϛ^/ΐfB;zA[cGTN>ܝoc?,I]օn5g$;`JG{tgSsZolaw \<1dždg,z-Kic8$|09x^cp%[_ >7;3֕5 e.s`jrc$n!el:ZrklS=)G[gKQֻF+3rմ Q=bܩIeuV4%Йp8 HdP1jzj_|%UȽu#8.IIUҶ5ۂ;ٖ\!(~4#W1t>.O=`lGqԠw\J{iG1u%z{>ā5Ԃz1W. r213FUlE ު'{zWdvb1D+O; 7DsP@ 7Ε^ne)qj|1MA;v5[PBZk5CH9F_X.c4@pί/=槶cs[M04h2@%P#e.èvT^|, u0Ib;X̟P^,\\i>%F5_yEK% 62.j r"}֣1h?d^<ݦ<E]gBI(jZ3*#â% ^UGFkK&@:[-Hz3\:&bBR.0Xc툈Fj`Kg]a?#v G7l&Vd OZˋ*oa< D*IGhƱc' 0u>g \cQqۼŭ40+Wl>L AZr@Է+C0pr[ I%b~^2]KT3ң,%Hn0_eId*v z0]׎uIA c7̓%﫹W̓K-M袍PEFv]@D'AĜ9Ք ;kmLCLW" >mu ukh/\JMT&~Kd)3b< ȍE_p9-qR!á'rw.'dH 9_ޞ'K(mN`Tٽml((Qn 'w\eS 4[ ꋧsH)# V#Mq S^_|yzkF?NMB˝tHp;cy1"BMfKζ;ԝI&.@G»RBwTΣ^ry7pZ,Ult_uQ聟M@f\ZtaUzl60oZY4+РŦ;}06/H똃u_s o󴇨HƓC8/jmY@:]wB0E sOϧ gXp1cXNqL̏^ddL7=~-PoA!Ci d 9Q#ojT;9yk&oQiTptkOŗyJwfr H60EpL"`i3ЈF[KjuBƥ1Ńla˜t+}zf-V̫q}9Üž 3]~9]*jT`ǟ38q덧à_i/SDQW,RfreE nͻbΔ@ 2DusrIXlY ?O-q#IS3g L k%jB0n 62 #p@LNrDF71Hj A*CnS?tUdPb8=t#nQ.DqĩcPzJū񵝚oH|M5M!Z08Q>EК>`)h7oB~:(nvH_]U3"~I Րa `-wd8-Smsk{SS-Aq8kydcb]?ܙCZ{(.A:4zQ5^[#8w4׺)DGa` m4>ͺXh`ȸ#(W&@~Nsb3ŏW3&eWZm8ZhJ Hy# aPV*bcuA/3`? }taHz8?;'$N U<˹ s1mkT!j0W*;uVت>\pLn!ׄZT  W5?Λ:͐=gvQUOuy,fo SI8* 7+T0S3 lP e1[)kpW!J Wuu֚ˬhgIQ@Yn{\ V3&KdbpO$6FmH2@ht.dƱĽL=!YugLxDWI-gǂ#&D0XɱP%z(R+m>FyLh_S5D܈W>Y~r 0\|Pu!BUE<\A8̠Ao7b^(w<#&GChuF̌1FpeVISbFU}';"mSt+ dN!Qu~+gWDjP&*[H:T@AIFT Dk&[u[*[ lzِ 3i\]Fq+ibǏ$r)PP߅䤌FY?UᜂtV^$%7*_xvM";PΛګ$z!G!ҽ,zu[xK4{X^%;n`D0)F>cN}/De5`p{B!T+G|QP#>/ 8aGۮS~WڣeF< ԽKqv@ƅY7O dro`ۂYB v|dou ?kQi?6ipą8U=Y]/K @ȰK>2Y&Ў_/(A,,& ʲ:!݄7Tn|`Ȏ2) xA9LG]!-wp2 뫾Ƌc ޣɊQ6gKqjD>-+CrWhnArΑ˞Gû WᎇɵGB=U2 .$17.\>_ iU/{V}u\NJlXIviFRⳈ8g!l(sB4;bPH~pUt}ԉZ'J5C>$ۛT%8HgEZ*ay_*q!;G b7HБ2.-*L}Geާ0rV@d׬D@1}C,Е{?dn}yp ]Mlmwa=."ߥ4 J>9<&MhPC%W Įu]3:1Ix=@`hD'&3o}b5KFb@d[{8d}佔]&C'֩jP.OA?5ޟΟxCp"HF7, qύ(_-uz lr]c%ixʚD*:z AZ Ie$!r%4 h֬^#s(e-Mb'yJ\0JBNXؼT;zifa~UJ#KC+NO" ʽUy @#-I?'ꔝ58?JHИEϩZ>$ESc~(ZXmԣGW5e6f mT>gQlV?ԧFA S,5gGU uTFDGk]jk2퇁}DIԪ3'脢h4=Ş~d b6C?+MbJg]O^'o<}U@'v(?O ~!uUDBcA}\I@ [5`>ۣ!pI+J5a?S&w&\=ѸOlUmx$4Uv a"I{(/:UNv`d]7)ܲkKkA$"WW]C`O] \ 4c\fGd`̏/Ak#򬍮,^($=,S_S('m7l$I~_צ )ڼt 92XEy=.#FDCDW7IxK%ӓJ z4W{?nlgQŨ'ш$PrCO,I:}c@['8,N: p,2I%Thl #P`u~p Ĺp\񛾦*%.$K28IEXaV? 1{о*:+G! EIDwBKEoϩZ{xl{cu A2)P0t]T.X#>Ne"gei#Y[ˠ$/^d$:VI3ϩOfԗhcp$bT,؇ xhHZef $o-O!s([cvMqR?Nk>ٷiN"~;D(^a8=C_.jRSt6)s( W ȉ@@L!g)&hLŽ$%&Rym|ƽ%ua %K6ˮ-V~f"X@,}UoEg7kLC=7)-MxN3ũK߸jJSN3"g`+ ]?&=HFWY`ض :D.\qTd>%g џ42l$Xu\CɅ5U[6~! p0oz̓@ޯ PibkSeRfHPڟefOZ_1c_QxHquy+%A:Ye ѕV1V#ytGvqH20"n^Z}#=1,B+L .j `+lX@;cRĨ?$Gk葔wج7^qOw㵑eFB{w]7'9B^AG3*=o-N?U4HE|<=,kU/9.NX&۞>5ķl@/mHwE"(69v{ZJK $?uUcSU3{3t ug,QD5l]PYBƜ ];1cޙYQW8.~, Zc s ]Gy] L "F&=ߟdGVub .Q#J!*͠$\Iwj'ɇP*l] t#a!N+ HO]&{{{Cɀ[=XM?o:)`(B[FrP ]̋łw.ӡhƱ8_N:D<x(2+2yvfP,x˒Tbe?C;47x߾/MEH,>2L< P`B,Qo;ڪ*F,)3j^'n1K 1 0 =DppaqcH>DڭI{~W I9aE DH?6 a&>aL bLdbA VmG.tfsN=9\ȭ4Wuq/#syȩ%VzjAIū؞d`v9V^,*K{9 _/F>VF@N+<PD Ջ*Qz^tr~>MvLȂ0,Pohٜxe>/}ؖ8{Zl|ӀTI@=dq Ml8'h'jzbܲJ ?vu7x㕂9$=*?^<}'wg6^lP*ii w~qzRgfŞϝjYjA ,=3Uoko~ %VuP4t:^~PDK\3_pi5*|:!tAZ5žL`pӸi.zH/ݠ 3#aF;hN?{6q7Ls_*J 8,ktji=PX.ؔbֶl{d Ga"Q%ى+RRnNe{\M: T8{^lrOmc<bcvs"F~@a±g5DKtʐK!E?rg6uTA$Rj/Hl(2٫sC'Qƫo3[2ѢoȱPD4 q"zQ9BM`a&vfHcvފZ!W[}ycA rbCJ T8PN- jw%Dn% Ҁ\@9fbhZTHN4.y+"*+8S񮊶 ^ةo ɡnjMS.bqj 9?$N=Υf EȹFC=6Fիmg$h XWmL }F%NmPF~Ku-nҬ۱R"Q2;}s}oI畟Y !Sܛglɢ.( 8py QŀI V{:^ܚ6`Ln:??\G;f4,k$ыPN\K$^>hj p{uTvʑe|-C<`(6 H0̈zc 1hυH2[=X>6o/b䂁#*Gh:kP.Bk]k.$pB*5 ]s) j~t?tWJt)iP#ݥEu 61%9ElGnian3Xm든f 1uUaPZ4ם0wސaM`g a6A0Vp\b՘8kј5yFϣ0 Z x2C39ꚝ/] gfл@R˧*J,C\_b]MuW(9u yk LJŧ3R,rg{; Ĥ63lMES WP4*e)hf,$>%LKQje< ˣ<#ߘxrg.I/q2?ҙ[X=nR.^lGV2<1?ijp/ AS>[Rl47Wюv\V@ *\Ve;I[^z5j1}+~ƨ|0V/['[NUV;ɻ$Ix`]dM {C2gÏP-)S&jGP83dQ}Ohc}m /r^KMazRhK0,bwhqY| Gݕ(%KYYC!)݋ )=X#Yc\EЋj,qt j􇯲s,BZn MvT\olxd uZYGе CWŊVfRD<yCv*Kĩ ۯd[q׍J#`~cg#|܃.tcAFUL()2P/STFx5=ZʽoW4)ф@3j2xƴМZ`m'hO F\z?&fg4\ đDo6Nde㐇Ux?/GKL?( e~l2s'mbµid:Aq^p;=PN:=\J+|+A^ol Zp߾KG`Q}Y2K#~e٘ubq`~RGP.b}:L0tLIl5x}c`ݭ٫ o*8HB6g}٭fM>Vk.loƁ"jNma-?SHL,HI!]牃Fp7Г|@ GW{ TBOOF8ab%Gn-K^n$,q敆?pRds/=sǨ63MhDw 0wUFra.JASɼRsQy*8DOp] )ިUk@{C0*a{ȟj솷 Cq:f$׆ԏz_5 \.Wu'u15o@sbq=\m"] ɟ!s*@gl7Ӈփ(g11A74=Q4h[B#tiRʛ/>p#mZ & ׇF޿NYKDb\)rRi? oAmYJyiC ~n|`׻_P"xifxjmNu4>;9w`8TKjvI(h#X0(VPtaVPei5/Lэ5M ,VM\K35_k6`$~ux%l-j/@&㕓V }Ce[,x`+ MZ*,;hud1%=kCIJ [ȑ}*g?J7A|:1n17Xk_1_PQN &zJm60t9PU&;|TL- zjmEDa^qQmt%.WjGB%.nd7V%#\ĺ^ эhX˒~I[[n@B:aseeB`cU)Jёvnm&:TZ9kEw@Q ^#U UqI~5 {q973, F"yZVP8 1z ŔuHeg?lN<ŌC5ʂ318hD']ԗeB%k-nDPX4őg={QOOֵq(FyLn X%ZkSWtMXiL<bG;$NїjAM8v@mlsypJ*,&4'D$< 'ҥ1=!vj_3u-s5l%tL諡M`p[i*h:CN-[{NktcAVń=Q/RҺJqx HV>tj\ȶ(f窋~24n`iݙװ -- qߵGNΖe (f`u\1 GEQt0/x/=/6#R1F* ^e\Cm LpV\} dztok$r?ZV@3Mgo\1T: lpF~tk4:^,9 kmlq;CT8_p)þ%}c_@ͱ?)y2Y~`EŶHvT|(*S ,"[@hj0HL87sN& uM0қ&:fکH!u=7A;fOxנK ҥ"jt'LksEB@SG #;#&Y 1T4P%:̃W3-Һe`FYSa)ܚGMa_Ϯ#*/W{"g+6oYoW -]wa}/oǥ2/1B)sR»iZNYEY9w|ZXJ F~xx™AwaY9Rʆ hII gRElTuLS eϫZ-KJF|9ehln‰h?"Z{w\΃ۇ=v^aBKmw.!8OĉM{/6AW9N ư„pK$$,Tb r8fSq!(@>ڷ$ZSw/2kͮ@j.oDN ak%S 1>Vh3DB )ViԵANdѓf 3<$dX; V$v@̙ i8Tf Xa.-57gwAzjj G=BMn{Ǎ^t~d^bP),RkaEK u&ܾB1 1#_d߿%sګ|`[Cw&&TB`BΦeKƨp%։ _ɂߐ#-? 8|;CMё2G3~`ʈ5ҬN!1%8 c!vNu0+۾5EynԻFFpkP}qrwqr oK*FU+ kFp{IQq2u7Ry9W_pzPs̫YvEع/X)%%,W(Jjw*-޾//p.hWp>G>vٹfM$Ү,.iwe͚iN-r8ð' [?HF4>TVHDƀ߀%{fH٠ ,7Ʉ29 tp 3 Pچǎ}-~^yJZ=  HR(|b B.vXڍ(.2CW}A@pr bwMrj) `яOp֖kY8KT<܅ƤK3;狎XCNS!i^=mfL0gdjW:s 0۠p"b60:.b]>x ^^FR2je(_;^J7M%0a %7 Iu^c!4׫j (-|CD*,-yE|.9? OΒbJmg!\r-pSцD=jͧEVS9䈳sȺaf_{2x jv`$ >peDf"SèJc\"Ӹ>vCvm{u;X" fxm~3Xd=O5-9{t6Ps՝' h0 SUhTG1m*.ޒmm o$倃 H@ ' %Z1YЀ圵OKdB!mAh[7i/h"{:3p:r d oe3cP=b/`QD.pk;ٻ1Ja{ ee=RRS?}Mq1&%co{MRTX3(OBϢn_9;)7g,ѹ?a:n4f!B~.7v0c "`dU#YWh%X+4I J Xӄb& W(31j=6fqAƯ ~p{ \ N}kHV>d@zn6"E7lz6Pn]lPnZղrwT+~1XB| .O6OXǽ##c3.[ Rt9|j$ ^"+7?7.xƒӆ!5Xm]VҬdZJ>G{b<̎ֈ\8"D])xB%< #(׻ Q7@rY=#x:6\eoBJs~$__a&r*|akeJCڅVB^H~lhCH\]Q2SBoR˦?c9zMdbZ.EMIv*-W Hc{ҲtrEcJ;:Y{4L~SUkOM=$voDV>hkPZC3eՠ͹Vn9׆%Cej+i6@ 魬 z ks|~s9^O(([h꼇mяDpydk?;2eX"G|}Te_ukDUy:}+\Q<&pbgO  p6R=G=-7*y?ÙR@@#\c&s|:i4bO‚2xS"1&j]])FG*7u47{X㶳mB|;YN> |ʊ}m9>GU'Ke‚g+ʳhQ7cXY̅&,#P1/3tтM~M Ӡq"A LM[HCj(wnPT:YTG|vyFoA<˵Lzbq?J3<\YKb Tnv1Y - Re7E,㙆 %Ux A!RωT0oVGdۘWs#$W=-u^;OL+yX.mA@*,8xq"`?~L'`3*}  LpD$hUB5gSLJ?+(Jv $m!H:qbe#+Kw$6B<0[ ~umg͙4z-?H6cժo…O08*9aӑy(ZWU% |3\y%ꌁ_7:%,}M*Hi-M`R5ə oGMD%e3ͥ4/  Hicܳ$0GN|ϡFwyVIԂEWb+r"?.JnpNm[DI'[5kMBor{F|LjM:R^{'}0@6H,\eF#HYPv#Aikqn{“ "5?5@@Hm&Oˋ̇?kAbbkO7utԻF0_1n\pQQ@pGӌŕC{:=.OQ zHg;~)TD06PB Z(P {)lV8 ei_~8@/69a5PHU(s sf ?n-?T|Gª;&QU7we2A~+19oN[ڈ]!t:!Jȫ˕G(:&09 NFDTġepWWLfފڢaƓt1nbt.σ ?]cQ"*>Oc%2\e {K|pՄ_AYlpFgߜSV-NF; {|nz.=檲s3/=$/@~}63})Sޖk)bݒSlH\@bf7d]\K  1u/hN--L7 YWRJ u[W{̶r[D+*H(N0?ٛj^M_]@e(kd@=y0+`3+o/JopѻB~Τ$~aAXq9(n0`kT?C'Aj>9P0Ttj 㰫xO|x$#o\I\]\*uNņR҉qwz~"3IJC {} A;[>C|mȩa1x*d&a.N>[\}p3!qFqLmf_~@QNj%JEM;ƙQiJhh(ڟx+>c63<@.+8/Mr20ӄ> *_ 2.wi%˲) / 01f#lń1ZD./մ7"3W0F@(vo7pw+f&Yлh^IE":Gx[܊2`lTD7jd@. wgdƥ,fCoSXɭhHB(^S[-qil?8QBxM>$51t{Pʑ݆yp,zZQۄB؂G-V?sz4HP-1S3͢zh!ǰ*Dň+x 1OX\+;BeG㾽|'>TjMt|E-.-f6Ll /|Pߍ50>ƋOi!db|S1rQ֋]^6Z,CCM4[+$: y`\JknIf50sY7Ct ʳ H^Qd*SGȈNN@:#!hِ,M&u9 @?Uh=$Qđ3`zz3 X7#.*v[ڟ/8;"{3~nMK heV9/1lٯ4*9*Pf-_~)sdZT⑲odք>իDhz05SÍ(pgUYO{j""pgХٺtgaY2ل_7~!|\=Sk_z=ac*Tғ~FGpJ=ch3+jѮ9vO II.|>`8J .)?l0BOpx"ZEpS3H!!#;2S1sulA[q0E5FrUĩ[ep }8=yw/V bP_UIB~+"%:#_d9$+c,Rw?Nү 55iwG )ԘBl}$ߏ\8 K~m7-s/Hl)@DAj2 _lGᶪ0RrzRf/e<.oכ[ԵügЕ":^jܝ8&C~Tvq:O*j3 m?K5<ɗ7w%5uvPx(-p=!K3v XNgz%Ed_sP_Rs1x}  2a;>DO Ӝdt̩갶i m.p]=(J%!DV/X(QڠvRj@zs Eh!c!'NEN{/,%YL9Wvͦ^ht-'IxUEU2[ZOb\iIz!1ᘥ v$ aW4$o&@ZkIc7-AJhTi@3Vl ߝ-`)mݏ*&/{u&O~"v;3N0 tc$uD{xˀ؇(P",Q]v*;uRZ6w,waJ8vE lȹzɶùCݒ!#V;ovL.x׵m(c6₰G!GFv\]R$%[N@*fȷ\avz[ƱI!b|1$6BF !{bԜcCc]97 'TBeay]uyɆ更HXfj&=/B]Q RkB)TDo-}r\4O6AŴIAJ<ړm9n 7.0ߓpź;VZ@P0L 嶢`nAJ<]7cjA_T@(I.lO;K,˪g"PL"MOE* qxF7+` xr@e% AvCkO/ ;.A$MDOǍDdHsΖ]͋wgB YȥHo,ew)2?R>KxeCw7+2xQ s}! ¾;D!AuQ{ǐ$ޑ9I企CK3儭e|8!o8&5r6L ECM]@z4R(?jy)4C-Je3 x; o3%0PfnyMI4 ,v簸&;dx_?:#:60 Kԥ0r5 8Q!w.-D7=7K# +dov$) "-8{ 5%VڒBr=21 E7 :sw_f'*}Uk >3Uz%'5Sz944cұo-RG.o)RG*S"߆vGeS mw30~lVp1mtvQouQPy %i{\ܨ-˩alXЄFɰ6XE@ic'Cvdhc=k"lEl_#(΢b(;n1 *En:fW2!OE`p7nWiOBig K+6"2]$^Kb| T',tP YxPϜ 5]:UsKN a9*[XF{²Rx16A9q1 b4K< =ufnϡ:*jtN KUzEE8vI| ;> ʚ[_E26;ȶ0ZΆq-s$UG(j# o? ~L\X'1^C6Yn U;b3TV |Sz=V% ;b WlVlB.9/_)F+uW>![pdo)Aw>rDP_|*%µf;wƌy}9ʯ:DZ.=~(Ju8 o+48` QX2 <4y#l'\&+e+!ld_$Xl!op\ra5b9!AF U@E;,8bbUѡ(+&6,%O)I"3%w涩HR֣KGe1]Ԧd 3w"ۊQB{NVJI6@ӳÓ "%0ObϴCG$Vw=9d9{3lǽL3ѽ%cz4 O '9J,Н%ȿ؆M';5a|d,ʐޫ43/}UM*K\#*.BVkbf^-{}Ti&JXl䮧 qz')l@S4g"g\2WNh#`xJd3'ަMْy^TK-Mӥjz#`FTIaB"|o)WyOn9#2txTgi w:}r~ }qЍKkEU>|VQݯ5PDZәo tQ ~ClPTte,cJ ďB;|d|&FWYcr}9oQ%,P")-ñO2C !9jĭ"٣0OwJ\Ċn)>:x.qs^`m1*E:i;<3HղwHa}S\x@qС0ב;'c)~Z{M f#bLY0z ڨT/zw] nP7ʩ) hd Wr!'r4EǞvo7`漑P?A.W.Mv~vWACCg}ץ-kq8g/=emOxt"7>8yP>i敖+lmXpv^hOTYtp>_XdJHPot,pӠ_y2629ф>RMXCZ,Qv2 fY&`y) YAk`).x$ `֧4j%GԶ [D?Y hcO+: 4j2 ^G | Œ逽y3Wj\&A72`ME:v7Cm]Iw~:TZ[兲 BO zncW$V^Q7Y'v7"24 jo&\E ?)jn( O@n%gumh\6H%CI >#&**EO鬟aK߱S{hyIEXs'f;`@$a[kH!ś-Z =p:d!lKW O @I9?թ+d瑸=5Y+]'@jĹ͗WY?5,;mF1,['942= |IT'rq ٜ~n=Ol:V+Mcs|G>׬!%8:afaHsIǺB=4g&8Q4mnέ?5+w"mQ[Ly"@YhԺkO) Ȅ6Rb6m"DϞgoY!*{H2sez gi?޳V֯(&_RHߪ?95991JB|ǯm6udNT\ػam8LF\^Zb>w!s3D-1#aL7ܰtM&'nUT!Rؐ`vR>ss]$\#0ZhmyS 4;[Gցrh:^߇n$ ]8&*YF_T؋|g9$p&" M6NWB;E_\̳y&GT:gFflHcCi˚f!e4Xy| @OQ!X^P*B>nT)䩋rrZ"Fn+!=+rD7nƥrVyW= 2R"a; +zgx4- =>jLb(8CJmw92֍S=*قbCpY}1 CQ Gyw:Vt3y2sW-dwN|V2\:NXxl",3(Tܻ H9/kr#4&oQJ={9wf^HJ%qd4פ1n=d_I,e^53A*Xk{>Mb^y΄l^Dn\&졬O!9OKb+{x]n䗪3٭X92{psMVScʼn'D 7U0r6-3#Ijh=%Iz%շ)}cX՟*-F\^EO߫!i5BH1yj/9.V,.ZZ7jP!T'g> ٥5$]&ǎeL]O69 *hY\Rgaz3-ĩ.pM 3 ?&Rdtmzgsܳp1\XB"uS3pQu[T Ts] :j5ɄiQ礪Uڊxv`qe}$uJ(Iye'#<]-:4Bz+b8t6Q#y5h-!z-ׯ)|&`iX# `>B+d?u-sPNpPIMN j(Nb^&!kBˋԄrltgX_󗔁b]tEL' K3h۳ x::J *ɉV 5ǧ۽vGy_.d+PWQ2 m ]-ԗ7!Ot9˪Ɯ5fWRJM$"vd#`eySw+wG$.ކpJVsV@-aOɉ)4F~S>38.!\yK)^7$T K?cmA<{ Iɘ$itrφl^{2 x'G5aWM򻤫Z937TfTiuEᜃf\C8wPX+%)DCgY[ >g.Cv>yĕHx F"71Ǎ!&=gQe,곥6Tx L6N=J@I='ѱk )NA0S32i5hpFKM? FB2JLS=|g">Rg\m`Q7}?~'kc |6g3 qC>4 p9PGߎqQLm2\g=ʺ+ `$_NLyt  \88tT?NQ¼(n^[>H@XbY8 ?~VQvG=;:Q {Ř4[{`E05ɹ<~\eKEsj>3ʻž h~?^l+Hz.Wo@+liβO2}EC1bPIx_p80)0ڮqrؒ>,@ rD>uLN*$yZ y#W}tپWSAn\O|"iw 9DN2p g_SimaXf8غSa58'(;eLBbNأVEM ~*s 6,0iH{V5:QR.!e 4ns9#߾o8 xsfl+,q}Ol^ 5= =;RJ$(W*`z _x(sTe/}iɆrqB.W/,Ws|}F1I֒9f|fR.w$8g+\l8qjGP۝1Օ"]MB ?Wm! @g=D0+کpo27gUvXKƜof| [_ 6f[ ㎋].Q`Cae[}nfIjy# 5 :'0+eT*B~Ҥ#C;U׶U}NJKOMZT](e#da9F# dKNi!Y "eW2=Gu\$e>;7=m d5ɶL8/ NJbi!\U6b~ǡv˜.4}$[ x h\0Wуa ?~̖j~DC-Ǫp9;erpnO(m?/GPdޞ`Hh( BO) RWԜBQwnP}} U: \fӴB^Wq5cڭzXbClz\!y!ݔ[邏LSՊC*{bE/X:7}?Zjf`5fjШa +> q&9T9$~" HUk-{HspӰe.o16!9i)ןw ^~p_q,8\sʁQ𼄎!yQh 7b79júZ|Ҩ95sU%@C`x(P{:c (;q wJmY6ֳ,V \%B>էzdzrAE5XBW,hR]8j~RQ*M8ɷJ @6UhԧQE=2,A /9CycT)^XQz~D$16xqF/.b'.2d4 M,H'ʧBxu^jit:(y) " 'K*@z^z1en;ٞ> $4i'<;(0bn=E 3Q\5b/tW05bSD?п 4uuKXT'Uڞ0^BZvU$_.":z}-d=lv6+D4kHzB7{npl2 wgQ(y.'46:oYfˣl1N-?aSz†jִcˆzLo 嵄OCh>ŭ4XwXsj$w2s.to:zvLbv~`b=9"Y6ٰ`(_*l+?)mQ>Lrxq:%܄kc~b#k-،w_ٟ_u%&U0|(!ʴffLZT&e$.eki2|juu%KĆI  #ĩVvI%yX,Ug'=rX/[H@.xiC-X9X.`Cv"%`bT]nۯ~S]F>}qZ4H~wmyH."wnxfIFTb/h  B}ҦWxz̰Y=`.l>3EeVR_O$j=laX (Zh'9'Ma)=w<(6_&jVDNZWIq8LWu-VO>%-#lL3bTBrabq9"B8}?pid I`ZK 'ejo:W/UOl3xM 9SdNYcM@9UJ'|K@A*͇S1N<46&?a1~ 6,qzwL̡tbż0v ܇ؖh/C_5C|㒃xFw qq Bףg+ K-Zv΋W $ңͨVz 2xPE1Ɏ }"`HpҸ24z pXmFe]=- d<оĀ,6fP fhWQ+>0컫r(K ^y  (Qm2!X!ː-W[[PY+yA#}+F`h";RcLʴ4wR,\e Rc]-0K¿]VNJ+)7!&B|l*C\Ǣ9p_7'r2J {(ŨO7C REG(fD"?{-I+=]:F͸˽x`,(?dT#7ux1ԙ]VWFx7<:f'ҍ솔;/׆L1OG1:)xQuzA'+,@M^]WۢfX\/ <-_m.]k\EV"h 9P`4j`u._P#P wFVe\1H*13 ʼn}=Ȼ͔螮}':ϓWԿ"X*)3e.J5X12 !p.yp*ăJgC֋rs`찙ǘ%O^|,mIct%ij81 oK'$G$Ԩ8]([%'qE,6J5a5rPڵED!6 L6!qYfF$FM-av݆ZY\6Sq#eGBKX*.v:@hrG >TjIl *0T6#n G^A~\y+kx rMO%!0V>13{칋(¨ KT=_tE^𫤇1G |AWI% Wx~ j$;v2}uVeL $8yFeuG -An!8@ ==ev](?pSWdV!(,V8@?7,C:PD'DkBJ76H8V3nΎx9vw╞N#204mVWfC[txx 2K` V'I"I쑧?tWmrlK%T:wXɿ,MV&oIcgM1=$'O`vƝVK9S+Xg,K`=kSge?mNdp3Gƍ#eXo|kryGӑ)!ސ6tʼnunax7ĀWxٮ~og0 x٧C RMΈUfdRm"uW8q ،XQطg8&! :PҲJB(ZQ7Œp'M 0dnW]PT jvk#1k{0} ˘*([s "]PD7笸bN rS‘n ʙhz@jm 0cet g({?7hlF'O;@Ghnrq$~Ւ$?dNoa1i3s[r~WqtRE 0ȷ1aL(<u=HfR0%:0VxѲB֡ cj^OKk;$d>( rnpKPS7zldWc: $J}e#x?fȹ,2(v[b!>q uwWHx*G'PJG-D݈ \˝ LˮVp|bD @^ $S=e(swI BK~#:; - 1ڇ%nF,Lۙ!-bwK<P\)T c<(73inIaߘ= pr$fujqSW<;5+X7'6.F22#-iF>5uJ.M F 9܈1B5jLC9*CSbB U?A+8]- iS_vs- :42f|v1Ch>$@GCCRmjGꄛ>DwBBI[w6d@4p"1|1N\(cZ os"2Ou=PV\ڞcb ahab"Uψn0UIlD&Oup_-qZf ;}}g~;VXb ܀+w,0`4'?!_<~5{ ?͏忔]< H븳\ƻ^Hfn;5qèlRDnYܫrk\$q6خs2'>O: f=i`T7 7~-0szRʹ(k+S?\'4^J49d.yp i3͹șչMyZ,w{#yvZrP>]'E@s/5$IxG2Ͷδ;yt[7z 2'[FR#ܔioNȖ+xXKi{c*2u%:l͟ 1{/Cb|r3ȋHSXMEUNȯ v.~yrZ< `}90 z5!{.&۳|Ȩgn*݌-X0kq7}YS<#Cas6Ku.qoFs%"o;6RU-o09nDcwJ'/ :t(Fr1\IHu#̧ϢHɦB[Td| pj߲9is3; fU)?7^XAd>gQ4's4@0 3rYjkn5фɳ1')Ό g7q@KkM@`%d4zS{$zEN77O6\Fl߅2^;0ò^J#ejwni0rQZ+ЭZʡxd-fft3l_ƈv˙- XK0˒^S=)+#=mۘD3[̙ U!/D܍ASiɖJ}6 A \.vD 1 c|*aj0Zd6%i kh*ksx<;|wփv] yDTs  9-nŻ 119smsO_kN: bmb^"7U0d ǐ1?.n<8͘Geg@h/~p(-;f(w';Q#kCOPiZ %8f}#0]笫xmGa41##h`]Z.~,t[1Lj5&X5*rnKHN7q¬Q'g֣,5ZS:P&%|Jl%F'[ybS]9++ Bf_/ET*fAt{60GQ5 TYlEx᯸(G`/+vx_쑪K)톤茌 lk+Aڛ*G1fWUزKad(DQIL5DE){7S^?gPI^˻7x=EjEib ͣydy" e5 M-|!s\$ |ٶ'Zn<CUȸ]6y`ud[I&|a{4lҕ[p/Y=;{<c":w*+2^- b.P8R2tnBGoӂyc״^ ~O߱RiNu̺!t$5K&IW1M7Jy?/v|ozf1*2p63n+hܩR9ϧ[ 86$e&y\6L۪m=pı C1n M8o(k?: fny錨-wK ʐ>$NSQ CA%7)ɼ]@*|?-j=eCυQ^G Ɠ+k#BrhVؐ=7FW;.UȖ8Զ;Fi]O>%nӛ'zuc7ՠkjYT6eEDQW$GwF=ڸ=́B3+fݣL2}3~D{#`PNz'6ԭypץS}@yMyl:(`*Z 8M_;u &<#ZB%LK]н yۊ׶VA7N| 3+7{k7KpvmgfbGX.NJ;T}OK] =3?%k^ڽlYǯGerq`idmծu EPe˃BxH< ;Ķ!a#2=5vf6gK0brrSdptīGKv~2bĖ,/HCH!"c@hG<6㓄kiaz QS"L0rWk! 2zAО%& SmA{2%I 7fru(gֺO#FD)i#[IEG?S\Fၣ 4խyD0RPJ.әb(/(F)Pꑁ_;5>rÝ6o$ ݎZpy>TI;ňY"6b \i|ȭ x:m0cQʤ !v^* wܶ'.pb拠ʿ,5:k]j{Lа׶yL S? oH6p`ڤWk ̍;8w$fʃͰ]ԉXAdl1a!aj;ԨtD䞸66r҅ y ݒgAF߽jF) kyz>:'Tőxc+&% 1u_Oj:KTǒJtp<4cciř}US9_\ +OgWa[[DYZ,,!t5Yl2]OFŻo&>ٚZ*!JoCUË4%&j%!SŒW8K7QԤ.;1o~։o[!XOCL}'IEr S#2bzmb4 a= 8biU;NtU(n7>'vlLfﵚˌB943tP;k Sn3 5x,O)Y+"l1 bͮ@ѐu ɸ-12 gf\ׅI0pmn{[ aB# ZοƘgD?"|<z֧ տ2-{9-'y)n/[Ia 6Qu\Uk7E#Ѱ(]v%DOq?J|@^+/!{K{jsǽxU1kd-xp_iמ;`Y-t-;0l@ oYD<~3_7h-[#>^`R EAsC%`ة"i X5J;; KHM_f~ixTА|eƵp#p plͰ: g'*&QyM>êmSl4P8%$}-|att#([0^mރ|4u4$zX\F5vsEC7NY)>6u#ڧn6yq#sRyhf[ zt 8kֶ!ãkTnӡI g6/(ld*wi"d?mMG_W#5pw2e `3o{'ڣv Mkڔj9i{HT@'S:KWJ} N5͡cysѾ{Fdޑ9XYfэw$ہ(Bɪ?t@$[\֨`t&H/BҺB'S)kj I*d8Jc'0fk]«JFm D(\+H}M_hot22WM RPqer:Xpf.=t]WKO4&N0OIY? tܖ36v^.`}S(zfX%tJc.Uqc~0'9~ ++=Ŧs%%M_t<Ň¾; /nEi(pasAt5P%&2ͧ@d"4kM V*gaV+ :KOԎtztV^*e1,i2FTz]Œ'@Ym} @C'+R~L ֨8n2!B.!JlIPzA g7@Tb(pJ ,̶l([_p{حK摤VuUALXkiX`SCIFCWDlY?cy&DNI0X揜Ce0 c_o*/Inf}/<[FLQ. [wlTqtB ~eI[0 RFa"P'n϶YiLaђuλ+^Xy@[ gKaaA&}&:;oCaW' H4$Gw^v9Xzruq'Ӳq9qt_TwKsKW\8cl]fІmsňS(F+ߔd"̏ȜÅ.pAKwE6 <8E0[>N[< g+%@-C 2o1LҽF^:hھ(?aGw:u]p U<,6 nAWHI >,[4'n# #-{s8WMǘS6O]M0fR= |c*>B ۺ^/E2O& nFTuUldZ{ w`{7ʩM8OaعRg^{BډK҄-]VNe*(:&Ư;Qg\#n>U]@ lO NPBfZTd˼NLtJXTѫp GYSˇ$ CH?[W~6UMzIFmj%5qO@6mebCti/9"+8|p7d  ,M{̩I ,K>umWTC2쪚4Y>俹2wƖ+VTd:ͬw$Qk@>aD.t_} d)' R'*q!A;-mEyZ)&V3 <6=ԝkHL5*¨vo8-Ҡ+@sLeJmqU @lȪJe#MR#Zr X|?|bN,3ПeUz|Ƭ}َ4jnkwK '#\و7BFܟ&!}-U t=4`?-afЌzO8dJDD]V;wۢe>e.ԥ%^32O =zuu5<@`ng@1,vQ foiN[@*ZZJB_!"SVBD.uDbP%O/SI%e#<X#sc ?D5Oevn%kLu\&M%w֘Aǒ:9Om(SRNT ػ=4MZ cJ\=׾*O:p_DǒvRuTDTs7tacٜRBmC@@ 00;Oe}WjwnHQw{W޻͸碴/‡U _>x@Affy^`7\:a8]:RilH38c,dJWG>yY_rpS(dv/|2&WVYD %BCTvA !E:O%;NCѮWHlG钿oY1)ҥ0&spMDw?ψ"BG{ ޭF~9ž1=@N4Ihz$@1nf1> E''ջ(loHʏv8s./.(+r}X_껬Z-.} y"@x3+jM!-P1c ԝ8ؑT}ھcA{@"Poa?G#ʭ"984VA ( h%h46]+K3oHCڣس/d@LA~h,aJ),ٽ^{nĽbo,Pb ZHJCWJfǵ H$Ǐ5uΰl{Rs 86_l2Vy'b᳾ic?=؉C8["Rό^v?Y[pq p;DPD[9Ӷ(b"Ghg)eR76gi 7T-rehXo!9ҢVf"!bvSH(˩1TZwXid^SPl]6e0($u,?LIDX'-M獲S\S(s& ^ aoǪmiG[}g[2z_dP?|S*"N!bs֍rfNoۿzB |4*vDAs8q ҩxf"*5{9䭇kv3nc~z@8n6@kSf@لX7uAh#>&Z{/)##rEdu>7Cg 080 Q L_a?NMged^(D{=c_Avִi'@? A|.Ч✆*:~^#-M=DV=X2wF8snOt@eJ !i#[KcEB:՛xuYOrFxT16=E EM+0Sy"=s!B"´Tvy&pCV{McQ4\dæ9:0Q ,?@B{y İl<*7blI "e:;iե6q0R@PX&W[G*5D unfrT~Cɲ:}j!pLH2m=(aGV H5S}t8 Y|A[A3Z$^p)wBZ9v[*+LCPmFCdNr#H\;%8bto=Yy;*ko֪*…bu ..l*Q0y $D(va8uS |Rrx}b_  բn3\M:+wLI[3 oTp9 ]'5i 7m˼Eܣ du/R2Z_4VG׎? -Bkl'  H|7 U /Xc'-3ȌdR4 l+s/ B3m !6bX}c;ݷӺPw绯֠XW :*)dytӌ2¶?T e.P& U2O]hYZAn!AJti{|(-BhEH^s|n8R٤& xFŭca(?{y%xlb^!Dܱ9:,;<#-V۵1N]SہUN7 o|*T*E6d.Of5>W湆( _F 0o?a?nPX2sl-Wå!Kcs=>gutKZh0f;oh8STJL:= tO{+E1M ȻE%AYE?&z.r^G %X8cZ؊vz#e<;LYr. jV,˜ L^EUFQ$|-}Z b :J/j#4z?%dzL,SSဝ0G830&@EDDX:RZ@$>eZ3ŏMKSΎD0q(R޶1yzх\sŃt ZӲ$T]A`VZ}oG< <"+ekfCh#}ggP&;^ā.3 +qMxM+h _yߧe{{%F,ϙG+[PȖl4A'R=iB"` ad͓=aMT3.⠣ #7BU`?%ebs+^@AAp^(a,+W舄7* @.T zwp4BY> x"t*%_"j(j" YqLi}SM2VqAٽ+&ڤRbH~YV2DiKgز7ᢦvGH6)SGsKZc-"ni_L5bUkR6V#J2cBE/mG wҜ1/CW.:Bܭ4h ^mbV>of\g kh|spZ56ǀV&ljǸu?0@s1g& 8)AxQ(c ޭF~^%Ւ0SUhEP@ ;4kc1EW_ה rݓH(9?.2a)`5uFmBeMc43vbMyT:wUuC;FE9g@YCږ YƪXLzw`0 {w`((;pTAI  4IL=ڗ1$/ԛQ%:pYژ6DZp'IW1ꜵ|)7ltصE3e >] upݭ1VCNJL5U҂eξ:nXMRyMLh~"GXq[ s()VpK#]p$e+Q'FJy!D$G&xXz 5\t@b*qV#{3Gs?^y/Ge8cS niMZa|@0N,wV Nsv%K(A@pY-y&IIQ /}ԇP,ld[s(ō6%ɭS}n~MC(7rEiIOJ(wp54HK `/"Ǫk"hEL@ Wdpm.ij_ׁPNoa! 1[x[^πG@mi̮ 6%b-3^ђmMmW$5StcNNDsPiX:/i=[ALfLIT*W"ۿx.S0psvyhh$Ÿ_a%!tZԠrw^1bٳP 3t P0dى=?rT4&HK1r!bKP'|!&G^XقgO@tp0p\7*dx*ާMMc#+6`}ݨ2 !'2( z|j_Zȼmmj$gEB1M/X$8Ă.얭"r:٪ _(b7=AmF ZPcÊɲ0||9-H3oO)% %ls͹rI+bzDHE?ez0zÆ+ yb=z*l_ќx.5Է?^Onv˺go4UqV-z4l(p>.S,) XȪU7'LVSQCOlN$Uu<[>B9ŋ Ozx y;uˆ Kv=HwGD-<ٟg56v pu>l9R==km)EbEETŲ/BԺ{a^+A7I"9& o_sbS1HZ]5^QdV]# !RфvFUmO8yGo K Bꤣ⌦#ϡ &i\h,J??]STļ`(ܛeZ HSTQ*ѬH,Q&i0wЏ9oZ8ǃ[>7@Wf(\dm{T"yۉ_ug;[}TN1UDGSHDjT|(d0Iu1ޚ2ef 腎|]]:JtEW=Uw:aa)^'-W߃>`vђ ghI)e)ɲgb@|r{/e`f3|҃UT/n1WAaQ{+"`zFw@Fq1?҄pS6X~/®/j7).{R=1oQaW'^/[!|(kw"bQR>m>b_E];>#2m~G< ^vHF6Q>9kfȅh47KFC.X(vR35v)@mK2eéǽu*R +Lܳrߙ]hB_[&E#>wVżOs:)#Wo’35@z#A t#ᗿܢZ>Eͳ8l 80܃e(,;5s UVi,&S S)_NC3BZQ#YN/I̊;men$ouC= 8)')CG13VA1\drϩ^imH윗<kaWڼvm tθ]GCЀ56gD ˄I浂V%ف^TlI vF&XK%ʎ1]QJAo~ϊ/萙AX! Pr 88\T ?M ijipɗ/[y^:N4Ry\j/2Rlz *%s7#6Է#AONz5S: ̕A ImM sgox6nEQ{a ڌ|ݒŪ^~<\E(!UbCj&Pf\;V 'P!T>,ǥ! bYx&TC]HMt*=> Jm P`H*= %ƚ݊[63Ձ{z]#702yCx~&ObB%j}bp?g?Cuxm {\uDGPިt*PDˉ@y< ,sv jlνz5W8[ΰf|PUĠ]*ʹߡyM,8{o{L)ժc]0A#$5jVtM '* YHoEVfE(VSHKt51,(p!)6ӛkU)͗ib wLch=[5'PCgJHjՌŨVƲ^k׍Y7/AB/tS_3tnOdPQ$l.KbZĦ>^/HnIr ^ZJukq,{v=o4z$^vϡx87eGǡL4yFo+Ix#Kv+H02YD84WC9_Tb&лY4)EO[P""<,o į(+u+K~&Ȣj0O{slqf_"X05?T /hQj+ߕKHwPTme11=Cb.gG-p29ulvK^|F]x<{u4BEiucF}K4GǍ*@6 ({t,wUYGЧ* n\_>6.$MI>JfMآ| Q]3f߮veH.*<Dɫt2KIUfcP^v<(7XM~*82b%Z;(X/\' Dep+Yn_shօէi:c iEkDBFy6Oy`8&cuWМ4M yKϑuiUBn ~-Z% $z >& ]@ry8~*\(.jz &R-rѨX_Ϛ@:R1a\8)ʐ=8PxDfT1n@|k9.+G*Y4h6N ӰW427mCp>2%G95:i@ܱ޶2@s;uHཝ& *ȣ9SQ9y'uN Hޙ Yu˄3';܉ a >K6Ps f 6kF.\ !'iY.kk%\ӯQSꀣXHɠ(+Nf!\j $yR7<eqڱ^oثFjB8`WMP,ԦQh=%W$vOk%䅲$F riؿoMzt=xXڸPVWM㻃X Q;Q| V{! ߌGR%Hx. n*0h_KsseG,'q >a2䶮]@E`-#3tW[BCX|}ʲZl#@bN?)KԪjm,B{{}akz,~ѫv4ef6һsv*rFvDd\4fB<4Er&ݒo # l*1DUy.LB1vs cۙ0+aSK'|c`0A42iY?< u&rDPTr$7͒WܯľqEk*)g!lqn&$r'B"dj2G6$-z;'?CCCohܴ>]e7;oLRw|#n~%U ,8Dtń݃;~  Ɣ{bōbVqWTlu(][w/?w)y!]Tmuw"eT Mro#G%(D+ ~ixY,Qq syd ʆI27M_b! X(WK,RLi?јV=%8#5 9*Fz @&Q=#]F-D=Gt۽S^mdGq9FXa laΉ_on>_O~D$TԊ%¶_ew~MnN Qjzwr>*@v#%H*8ha<&t9W)N j/U .1DeX7R"VDivt/;g9%c+w9~lLWx 07o Pޘփ- J\AmYSܢsř#B?DRMbPrer .Cyah=1<R^>74T1$)MzSn6!D#AC`g4U$kY pc0KO''|zBc1+]#裋FP`bFUh7/K.e-.6S|˹bǍM" s9K-/ȍhQTcuڍ5B3΋ɀsLt}%gLJq蘕2Ϙ3_`{cа`mW[Hrn?@S Vgdx m60{lL 8uZ$>nyWj 3($n /.dt]Jkl>r1 Io@d)P k'/A |1fHyFۼR-&hP N55+WrpeLׁpX6PRw@am MÈ03!4>ar7975B&y-1C*i/3Wk "8CQ4ZG7s@t? 51׶RH +Da%Utya+͋㬍tvk5̅= yL{Kk teH&dWC "X5be%5~6H&661O\h'hɐɰ$qiR5FJ#P[H3qJ71\ сD:r)Gzh 9+Jub13?Ki*"K&I9 pJbGousR(Z!>/i&i 64y4!c:2gU0 x[ :·Ƌ- e̯N!~U- ;qlk dņ2ڪnՈ7$'VrSBVb_"qu8P4Ǩt. Pqp(=;Ya: r<EuNK;Lr8ɦxW=|SjYU1dd-r(PD2E&hU˚|"5a/’9 19``1w 1Dp9g :x.MV~h;Ij%ÑVՙQ~ݸwqBn.Jڴ)hQ9e)seŮNԛBN:2`ShЋ{?c@!RW`UeU5NxƷXMy=AS :gZ7j vj^ w'C*LS@n*ZD!)KIdw5#5u-fx"Ύ-#jERW 0OV-' m)2Y?&\;!.^UH Կ y/  m=gChQAt[Z&S'p4wál6ƨ[ 9~ʫ(J]:3!y )Q_F1](sӴ~hHɡz$ EN='!PH6)܇Wcv#XhѠӖ%-(ƌ@ҁT K40ٍ[Z3h$ RZ#)րfRnםG +Q7ڎŷrV)/zQMleUs褺`C[ H<-,Jָ|`ta"N°^K֥2#gu7goI},3Ɉa `!0iGZ")؟3ՀCoGehg^0]4`yE/֊jd~τMV zN@tI\Ke[xݺ אG4SOtE,(`1X |iGw?5vbCJ 9!F WS@/0pCnTN14tHtOmFإf",+EeTԫ)WڿGwzz_)#z.S'Z~hg`+)zSX+2a[ޏZ})pu,xp9fa!Tc}AZ&8 䨣5//M GKO;59o{F\^,4^ R0&KjiAAJmmK]]7¦ z* TizK?>S펈a^7Sy7KBeIqWg8{T.L.EQbe2Bj 4p%j2)ꕜcJl>$4[DETJ._k{쨲)uUhi͗AGδ HAPJM{x=u_jy 5Lg_{hfLABwXz"tf7΃\ܴ7{/JxWtǰÀ[MRCc6VlL9]d1^W˙dc ~Ujg1kA( %ƂnKi){M$.ta@ 9R4]n*Zu8{7⹙)PXg;y'CJN7iNlT%8]_f+nq̧}>[Ly\̵՛d8]=3E 4rna1o,O*[c>(f<o18> ߛq7^wR2 Ve'.)woިh_2o OHae| TqH2ᢥQ;cb!) V% ͜C?a 53y="rh=kpxnX3dS<WD$dA=3/[JIaqfO-Q;DsD+l_ma+`e5(Zև}Ae!Y_?C}f!ݘ$9l6 akq_>/A)\UG "oWK3Kb.Mʎ_9@Y pgXS_h'ҋ70dYW+ssxwڒk{&F5hb**cLáw$u] A)IawEw1\u=-C'4y":z|9{?Jlʶ{ sth/uˋW!ďr[M$|YQ4BzpP a:rB\8+m5-#~̱t׺Ё#`=k,{8L4lFg& _D UߌH ڮSߓہ@ߺi#zHm CMWOT`{G!򃑨1a!bQ+§Îq4NJIgELgޗgYDY&4;寁xputSxr74 ΰc+XbFEq4x Iq iXȔ=d(?ó j=GLkyR@Rv)9p 7<8TBu^Ta&&O.ځ8O:+(u2]"˒><fzӅ{ƚ?EkYcgT5!=2DÐ?UpXJ~nՠ%[BArKLso~hB {@Х"=o-keuE s&maKoKޥ4*f,`olvO]EhzCDCې+ V0'ܸZ*BYϱO,o4w;n&B+I7 )DxMu[%^gv`r3O_󎟫M{Q<$([wUѷLrP*$#k$u RH"5/1FLOJB!ٻt|xAhJNm= PS;c.gҞ]gLZHXfז2Jۘt\yuy>o3 y T- YW)Ehj;x[ʾ*tblZ-P!O:#2^yLSL0˹9xY.*!!akD#$rJv3̐A_3 @2$u=n,6v-|Ӹ8w#$B@ܯߔ5va\Gɒ?7q8W"񻵉v8͞eˉͺdBثgE}m#l7 llc/&,_~ W $+yNJ߆b1}8`f' PT@ԸѳgjO8YDGivyo] ú&eR=3YᑯZF53-0_U)`R%{@|ZvEbHwӕ1=ߢ.+yi3?FLf8\rK^xC]I,4U>F.Hм&q9j9錚L8FS?U(|S-6W#֧ û~q TٱnB?gPk#y( usl0TXC-Q.]vh@Jb&yg $>!/wߑR<)K<&bE/^&M(Z W7/OXH48Bmv!uNH|5(|oN`TӃVmM=,H?fcYSqDlL ".r}rmp#K +×opvu'vUiHH036RgUoS|'h[ה&GV$ _$c&C"Y,h$>m~ UJD0O9> _e/Lt{ԫ-ُ|4Uઁn8Ut"÷¤h87Nџ ~C- R!2nJT$gdsZy=X5Se/)z"#X ) }$*m%%=x͍@AƓ>9J;i:d,RMЮsxdop.;pɸDiDmU$TUxGڃ5Zx̞!6Ph srD*wm)4ŗ}UVRMXU[ kOo`P[XicP"Ρ:wK8utf˄UuX2c3d3"s>q{ KĮ :DOK()s ̌{pc?phgQɔa@81iW/K_OQ-oqSS@v֪OZT4SڐJ_(o{Oʹ_[G͒HCH@;$ D }@bYX1%= ϘAu; !@咴赵0n_# $4YUmT0o2,*D<Ԇ?$c֋4W97@q#ڌe:%J=qϒAeR V:).-=D=c<|QU/ߚ_A)xFWXrޟ>wxѯlR˾ԓ/; ӠvٿmoʭmblgPf s(Uxmyנ'SEI^5=UB *-<s(S YaXGG{&lX-lC|) +TsԠ$@u8X{ۡ!m>+u%ȵ_k"/Q56t8"HnD-)NO i}Gr^ik)^H0}jOUΔK THYX k5\>l@g>yҴLsʒ-BI-b<QZUnB<D\n+=q ȭ:,8t1WC\¨rI)E7ީ?>@"Qj?륿^ڸh<֔+¥d P(vBeE9Vz0`G78PX] 3JҕJ{k\G:U ?YTa8ἯxzbRNqL27~ L{f!:]~qtOqXs/cw]:TqYo'N$AH"StFA41`y O ԣ rMR#ԙcx -H KLƶދNGJ*l- AӷN`eﶥL1C.U,p4ZU;9zNQUciJS M =* p̍1{W-S6#A)ŎҴ,B'\9Tpʨv(Ax2 D? 15-d\[O.~"8)nPUAhk̕:?ZX1] t|`s1 3(A28l ZVI`%勳bBO`xцe;y;X$H zHOŔ8b몙&6Sݭqĭ!f`R$N+W2AƎHߢ@?Ylj+>xC%%3ŘEW": q5k2ڲ;ˆL$6xf}gF%eOB=~ 5eɑp) mnDy\51JTzAV$K h5;rZVB^7)-'pg4ݶA#_&di:l^ ?q1UJy|Rũ])Bo; s*}7}̆#BuG2H ֒`)l?kC$p<ɹ>nL`gjH;dqϖ4vf4 y(Y 2.5̧]}78nWa}Q1Jn)}wJqO05K,+p K$' @ujy:hE,)*ЮѣNl~ F׊\SKDӕWrGhU;/SkQ" jka8WzsGA8jTi>I7c{Z 3L5'eJG6Cz>!?;N1c40oj)ހiE+}ȁ0k~uX*x{_!.O?`xSOEc&@p_Ю>~#Պ xQ1ԑII39M5,b,ᦎ]3c|#|64!Sz|_6QUaYCJ?e Ka?D8-ׇH6$ \B>rN5 @>'&  F\G6VN*|&3`\u4^BK=iNusx1keLt1wh~vue$TLݏQ֌t9 hgk5L?!d43ƥ55!Y_?]Ҩ[ۻ ];憑%v;8jQ`xN3p)1h3m-}ʹ9D8Bm#z/"r.NYB-ե[V/ ^ YJ^ΟUS K*BaI410P/== jM+O7ʴZ8fܱ%^75q>qmk X *+qթ-g0cݞW&!{Nѧ|+y 3UNˢXO{̜)_f 筣? ڨv9|( !{Qhe'x8xHuąc{TOF"u z Xwle :)e@aR}~ILC( t;MAOsTcy1BIʟ gp$+K.h/hTߓjC_ɕZ)KhljdH27/ar__cRz -zM92iYoMoAJ5~WB)='Y ּ,Cr~yNH,<)¶$yExI Dha'@658S83f m`8vKXQÆe\0'<,>!Hm·і\l_9 2E˦CXuqeC=A k/ 7Uݭ!wy&;'[~d)!bn18-ΧD+pZ4а +d8l-_ML,qBm4҂ *|SolПwˋ53-|ط@#I!{,zhkQ1`2GS5A >Vة'S%>0> t ;!pMf; Hq7+ij詝}b6Nu#6 t̶A#CijʯL :ޒi4e`t9 ytx34dzdho$| qQ栀Ѳ 'p7̋m/ngΪA*_@.$*OZutvBk BLfyQ큲͗LM\^W u9](W|Ic$o6rc\@S^C^z _U7bVp|շ&bDŽqխQlcҘktG,H̘1-V}j2?[e4S݅1 BsyF-@U'E))FFcm%}0:\?;X`{tYa`&4GQ: (!#!"x9 nt?<6Z-:KޗʴsA sH#\/4ZIomm=%~% F˟BW|>O3:e]l(&QXqh'B}M2i̶K7XDwUvg-__ dPj^d+N0 mf Rd$Kq7&}e׎8b5Ԡ̖Z>JD+T,ij.]B kiqXRL[A"Uh<I0D(d=[}F~{@>3—U$g辨WKV*i+f.j47a#7&SsWz:,5$.: aCz"@PTU KQP0[5> aRqv! cI`~T`oխ0rNJMju?7RRJUX Ld{*JK^8gLhd![/R> 5Wχ <'$eLKJ|pp!Z/%m,HEeW_>lE8@05\w4)=ZlPիflk@fQD36bxFS1wDc Ή LGƋ2]Y}Zd|WqW:6QBw>TZ#lIonUk Spuu?DiA1+%%V5Ӷf0i鵤ҟ;DyLEW!%k!m'zLm# T}"BB5OQMdCmƕAGɠ2+ޒ|91|:2VWQUk88qׅ~'ﵢ(5Q !s 0PqpoP5}-CZC,?฀{%eY,t ݩJd"W2|<".{b›Vb~ skVdgԀtYOR;d1@X9FRO͊hjqxCw)8m]j,#Brw怉Ru>&>[3VL)F2 c )9pe;9a]- ),h"KâŠڍ ;S4FPIC`Bќ+`7gTt]0!uw*q WWNdVUJ1mL:ez3񞭀񗄫0ɵj7vKnXlePkϫ@8̕%/NlAej 4@ 4q K^}#AB~Lytnd}^7opj)lv @euT/KM ʯISy2^]d\H!3"1_0UE l(3Nz!qD 1y{Ol i=)?MI`sHMR !y"v=aI fg&69mtE(+4uWa0  KG7A8#ph6?'=ڐ.0\݆ N(P&qcmtwO NY\ 'r Aҷ[,(n}uȚ׾UKegiz-+d;P$txeӽPᄏ >shL{pH@yqz\ꇌˬRd0w5ѱȒ;?$ϰ2Rm[Szԇǘ))'2Ψfrы*XHKdH5]˃;x5AILm%GWa0jk`@-a:8TsL{Mˀ" kЃ6؆X7K;&z=TxsRЗXFv[%v{GOYJعd 6/3!7۴0WdUKxQJq]̰(d@waBcr--ł E~WƍWg8òm0xt)'xfm /Z(->SZru%D52vpf72 KT}/X-hAmRG:_*τ;~I@Ⱦf9:\cGXkPkmΈcR, dѿ?|F)Dq"I׾/m#V$s)tnͼcemQ=yp?Dz#eҮuGyBf9.PNĊSTQ:3[x'ũ(e8c2 S}0aB1kY Xߥ#ˆ& ՂF.k`$IV skze@lnH'I+ gW! eZ@W.I&ff;B~CnAk>#qcρtR&sQþV \-7Ǽk;&>؉9Dˬ{BP=ΐPm7}#mkJs%w_U_ ?=h"RH,$?g7ħ9)|SDk ]Gxkpm>oP]&Ag, bH\zV]BBՎAu«3oඑ&}b^'~sފS*%)  ๤p٬~3^Z(T4EV7fEtD8N*`f.L}":8DMj ȵA4kٚ>5ǹd{lՀDpq{v@BzU8A`KH{dJ+ &zgF8k?~w/=a?_F./r<%l >/B-i"]R"E#`_<48bq'gV4\h|i%a`؋;CF`IGyֶTxQby1,b8d/sAN7Ņ;+^dnVVcU (@d5VWd L/x- K-*C+= Ɗ!t/;1op' yꨛjR' K-~r\ygѹ0;e" F+S}Nl(᫛y d| 1NU!z`u'e]"BjBt{aJTVC\aU^'.`ܴ@FzA%-Mc H8n"CoQP^腊mYgz 39B.*yOߋKhhȎ|z~A ϒ,mGW!QVX% [ɒZ f6O GEߓ]jtd-# iրRh?QNq<`(ԏr7=śS(CD7ivT!.l"5vȒ(C ɬJ7Y!{ MpZ9̘hR':lPkhzQS+*&F |ei? U@NTϜ0% sՉ׆zB$51)dX*R0௫W9@0N؛ Xe@dHl-Lvs2rLrDImPkOrԲŘz*2b1`䚜wʈ VW5;Dtl&JSVq7b3(>`Zph]fmYOU4\섟wxm$LI , '@-ȁKFwfiTu)P/1`;{7A9;3X/!`@ҋJq}egj=0DtZߦ.n5~gۃv'|'4 O8wќד344o E$Fȣ-[szM=m=/T'UAqUR$ix'Y>m3 w*'KcG>♆G$N ^05 :sT6e}Q^SPo¡i%X `0'gDD6^F['~sjȷd'xG5`N"^9BDfG ʊ?&Q=8KD&+{.i?%2]&kKsdj6,7_IDr] M@^rGKi'`bc*jBTqDe^>u[>M]=x+A4",mH1Y&4/7VRsG6-nB,蛮22U%[ʋda0~ =_x?2>Ӡ_Tn#2ݣ23e$mOaJo"f a׈̇QΉCj<묺[@'J1W-;6 \wE1x#XFu1~︳[8\꫖O򵑿L Zu_HVL aI#!#w\ fVE8M.>VkP_RGO .9l&bhU8^4}术ʴE׶c# ы2ifųHbyr$~aHC{ 7S&0 !;TRz:~V+UFpɎ&b<)JWV` * `xemV5 D=UW"^lkkG1sf+X#e:@1K P"oV)2_ fLϧ #={>P/CW  X IA0'G\Ǧ/_ivPC E6֡dϮףOh'ܿ|R݀$`/z.f ~+8[E)dh/Evo/R&qвD\@[6!tSFbX^|DJ#BM_0V~;fBMaNOI=_x@7.!Y-I` %S`(igD ^}{-$*#ITڒ<Fs ݕ ;x–tTRv^.p31fyQ*SDD ^(:{KɈ}ѕVvK!w,P sbRDPaurb+>"Mյ"\ a,kmB`&wƼvhnГwG5]:6\QiYvT AE bG~OĶ5;R@ئ,I_ݝe& ӵ Cw< }9r2 * sg (Qcұ}busfn`؏Rr~FhV`òNNGFZYDZ3\4]%AIX `JhWVL 5_3#[ɧaaG hˑ 盛B'0.=,^p!۵Kx% D jnp7Arć~U SK]0.1Ҵӥ1SRa٧dʭG` '^'c MG,slT\bP!&.òf;tklݨּPb={c/ow\ !q8uQF\|@ I?( $4N;r J\BUs9lIAqNVޡ3IL:K tXQM kAi1PRD!8є yM:ۘ *782>yU=XX(v 'o$W*ǔc~m"֢< lz9wV  moԫ< TqȗoQm8 m iZ#X0<~Mijȴ`Duiiަӷex(e[oogxpP}ef{ r̘efXj;Vm|-㾜6_N0g/7DX#`%<],u d;S҆ohe[n)FA*ܖ&@B&t!W k9:^)@Wn,8 <+6F8B)3b ]u[ %-Eu38"Qm>+jR rĤ^qKUwH>-}jZ cV(/׍o(3`y(@ՙymMJ] `\ 0;R CyY1JU5,.[WBnq*26P$,^ӸDB)4t#02\j.6&yZzݦkKa .KLԧE"fPxߕ>>H)5 9!CV}ǹ-xM>IEZl~qHQg)a9  scx #9],\O@;b)crQ,a,|p(kU $_2W$ĺ^}Kpۻz/ +KoVC[ ?]=1kb@p(BQH/~f-R[=VT7 r?y)]^@8}u7U5ػx^qN騩Abj! f'kIXdQ1勆{z;>{\n缳ٟ[+ҭʛeHC|.<'62n<IsaKQ( j(S9a-;igXa+ew'?dS}`Gw1Di왫$NT839DŽ|/E[sH˽MH6y4US3=#d_rSC4#&{-eP$%]d%ek\E"Td]Ax?06]FE瑙 n1"uDQ$ULk Ϊvy)Rpԁ0m}NjK&+"+䴇i-GX ]eQO}Ӛ!zD})Ci!YʍՂ%&q|A3`h " zсtѧ 8.W6q]NY-" (3{(6{VY'+3шrѶ]BLVd?OW_:KZ3,6QoK/b`pKq Vwr4?vtyv[Gcd 3=118TsFf ߐfZqbc4T?R8$;֏o]QWږ>Q! aiY I<ꖙee)TNm(pkTq2MIJ bYS*vv*`╸hR#  ab8f'MlL+Z7jAL)<"ĀX&0}Nj7l8Yu@F: |ߌZAs ^Mwyn˿Ϫ"oUF'Vr$'T,~:@K$BMRbYBs΁N8=zՂwRoS HI.3re3ԁ<;|]=Ch*_ĉʝi;<Wʵ" UI&}z1~Vw%i߹L IQȶrjtDYQdԮRR P'BFJ,DE Ad3xwD 5D{BE}nBO֧Bufyf9 Z7Je9ExH Aq;0@/ 0} !.qPg+ufsƦs9)S)HuZA&r/S%cҶx-N1 @ a9Dhd7Z4a?p^Fjǁk5D#oQo,"TI@d+a:h ˹7-#bYfqV)Eq}ZE# aH, 0(q<]Ky{=&·omdgI5, e fwFE}P *M͈==`n<+՟4)rn?}(1z DM86n }<]4WtP\jv1=ټN!J)]Q5_0^%iW!s|>7JۏG9٢IV.>k !qGǺΞdiK&M.ZQV0na$kT%ǿt B Vp"CYR  F<_]zp UW5s= A@?_mȭ1`Z. ēVf!} e}L1hQ}:˷]>>`TU@@8Dd6bOO)S@/~=䒥T}{ݓ_BҡF `2#۴i|6~G)C;+1iCx_yԯLEÄϠ#jΊIxFkxRv_:6}r:h<]ߟWϣZ0k>ྜྷrm؋Q pM^9"N:u[{gD-0([Tj/X-E ru! %?c'o%R Ƈ:.bc1/ *2Zt;mυR\UBᖨgaL.vq&/kOh!TviOʘ|8 z!$"{jd,>Mx!紀 nHtFW0+8ipbrOnBRc&pYf KΪ1XۖAڗ<>+SZG\\(f:*G/+mH/ 7YV#EWebjO=8Mu_ .fD?ȪB&Pfw'UMSۅXk$l-*ʆu. qw-,o^R~ 1ʊ2LRzϘ-kk&5Dآ  b'E2! /92 1-TzDp/y]3z_~9§+ׁIB“n-=LO2O癃bB}?̼)hڔ\E P"ٝnz\ш(b96]% [n޽cwmW8H8o*q/z;c]?翛LDz1`>yVfp6+e.@;<+'}4\ 8Gu+~)o9<~EC/¸Fb~* SV4 _FWj#_W M=Ẍ{UIWEW(ΐh7sGQ9+>cBeP.ce!1-*<6l?W?/M[^-Y$&2r/%Ԍeۤ]&t)BJ'o`-v6ʰ(a$ZYI%oΪ:j5NfpNIFD&3-Yn{cm6W8'3;&׷> c(y7`|I"FvELbtLNt"P Z:rWll(4}ƃ}7{qfh6E_h7ƞٖ;A;b;$nRgE4yY{,!jB7::Q^KN3D>'Zu⽺g&'2?Ӿ!PPNJfaRR*Z+\~fOz.ǖ0/KViAXb^[@$\b\[(|Z`rkcUB1+=am.d@:xJur>I <$jوÞی]C1oDЮ=' 20xH<±<@D|Gp$!XO +aϩpp$AZ;m>a|IYΖľœ KF6zYwD?d{%x=/2T[oA5_d3IȠ.1d1m"_d\Z:<  )pȹ^wgoyvIt_1vFP4eЛxv(jbJiY􉮱 iOrZ"-\sqHTcu;2$POMQ 1cHQ@S;3,KGKW# =ܶ 7DĪ:{)y*-%uqI.ړV,?UáѮѯFrlN560j yZhf R  /tw/q3sxzd J\'x;Ә W5yL?>!ΐo{: ҃LͫG~CJXukB-ܻc :e <đ)k5^nШ2gd:Vǘ;VD 6[tYv{4%Z4v+KQ#/34u& 7v7䖭d*L;}әƠU.M;}DAe_bKFLΑ֩ VXxViO{'#CmM;FwiDE)P^ybxܔys BD|ŚBRj|\PwFx