sssd-dbus-2.4.0-9.el8_4.1 >  A `U]̚)@Yump Ύ $%")靽eL4Q; YU\^Pamw3_,8#g+]Lys,Ls~(l}Q»?5]FyX\'ʎ^^YD 067a|pv:tzwdoݩX)! ]NVb- PZis:ʷI@Urզefd76fcc84880aa2adecc863175200b38e3b018edf54baa8fbc497eb0eed2dda0e437f8aebfb873270e6c7bba2aac8e957a8a6d7Fp`U]0K@,: NYQVt0xTQMg!XID$4^!p0C-!8Fu׬g<ůR:bqCqq5|nIɶ8 bEt==>/*e$ݫEkAUwMsv*+$VGB CEL<]=:~\2>Ec2%#%WEUg-c Te3bxt5 C:˟_mF6[FDWQ.rTc ?> 0;_*LbHS%jlfc,I?hąX+]%}P-(7JI8t2yԄU1M]9ETԩr{'xDb>woI4YUBiH'c%9VY-ycxY{"2`=[ Rj,PuD[ tuOg׏ %}b>pB^4?^$d   < #7TZax8 T p  6 l0P5x5 s5( 8 98:bh>Um?Uu@U}GUHUIUXVYV\V8]Vp^W_bXdYeYfYlYtZuZLvZw\x\y],*]]]^ Csssd-dbus2.4.09.el8_4.1The D-Bus responder of the SSSDProvides the D-Bus responder of the SSSD, called the InfoPipe, that allows the information from the SSSD to be transmitted over the system bus.`}x86-01.mbox.centos.orgCentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://pagure.io/SSSD/sssd/linuxx86_64 if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-ifp.service &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-ifp.service &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-ifp.service &>/dev/null || : fi%e0K- ?AA큤A큤`C`p`p`p`H`K`C`p_,`8`8`8`8`84601b3592d313effe1a70c44167775b06693dc9b72e7bebc718b6c9e8b094b8f1018b8062fec54f73a99b3e6621a491cfd79f1d5cf7a27860d6f3d349c32fb31dab271b71b25c8049cf9ff1bfcb3db6e94a5c56babdaac96bc2c96caf4df0452a2631eb70e5cdc8392c97e19924dc9aca4ddcf4b38a44ada079dbfd5f3b5c8738ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90364f0fa800a2a70504dcc296d99df5f73c85ce5eddcb620d42ea21906143f0ea1cba77389e43a484b30fd1367d270bdca0685acf56754b422de097b3ff0bcb390c9e9725c1fc46e906c480cde3ec411b2757aea29cfc670f1a4faa21eb782212e8c4fd0bef4db29b74304a1f87e4b32e7ba2818c1c5a4342e0820ff20f7e3842a4808eaf3ef0293bc65106233206ee023b1976c25273b8689b418600f29c9e5f0../../../../usr/libexec/sssd/sssd_ifprootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.4.0-9.el8_4.1.src.rpmsssd-dbussssd-dbus(x86-64) @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shlibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.28)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.4()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.2.5)(64bit)libglib-2.0.so.0()(64bit)libifp_iface.so()(64bit)libini_config.so.5()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre.so.1()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd3.0.4-14.6.0-14.0-15.2-12.4.0-9.el8_4.14.14.3`@`T@`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.4.0-9.1Alexey Tikhonov - 2.4.0-9Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1949170 - pam_sss_gss.so doesn't work with large kerberos tickets [rhel-8.4.0.z] - Resolves: rhbz#1945656 - No gpo found and ad_gpo_implicit_deny set to True still permits user login [rhel-8.4.0.z] - Resolves: rhbz#1945655 - SSSD not detecting subdomain from AD forest (RHEL 8.3) [rhel-8.4.0.z] - Resolves: rhbz#1945654 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 [rhel-8.4.0.z] - Resolves: rhbz#1942438 - Wrong default debug level of sssd tools [rhel-8.4.0.z]- Resolves: rhbz#1899712 - [sssd] RHEL 8.4 Tier 0 Localization- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh cadesvuk2.4.0-9.el8_4.12.4.0-9.el8_4.1 org.freedesktop.sssd.infopipe.conf.build-idc9121c6cb473f8fba914059853f893ba956dac56sssd-ifp.servicesssd_ifporg.freedesktop.sssd.infopipe.servicesssd-dbusCOPYINGsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gz/etc/dbus-1/system.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/c9//usr/lib/systemd/system//usr/libexec/sssd//usr/share/dbus-1/system-services//usr/share/licenses//usr/share/licenses/sssd-dbus//usr/share/man/ca/man5//usr/share/man/de/man5//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2x86_64-redhat-linux-gnuXML 1.0 document, ASCII textdirectoryASCII textELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, BuildID[sha1]=c9121c6cb473f8fba914059853f893ba956dac56, strippedtroff or preprocessor input, UTF-8 Unicode text (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)*R)R%R RRRR+RR'RR RRRRR#RRRRR(RRRRR RRR RR R$RR!R"RR*R&R RRR/utf-87b214233b23be9e5f88f460b2f85bb1b046c2c1e7599bfe83a1b4371be4efd08?7zXZ !#,4] b2u Q{LQI*_*'wϐ,+٨[A1 e/9N"_!>^.A0FO)5zO;SM.C:GDxYC7mK9qR^B`}:r&'S@<|2MaR&TUwQߒQ+xbN*Pny!ō+Gm;8y9;xf#$&mhz>ȔQ Z3&oL?-7>X /뤮dگ*@)ƥ.E'o cѠ~\(^ cPи_ RG PfS|N#^5W|/0ydEUuJ+K&Nw_{wf8gx+maf+CݫǐZ8wv!YGuYP V~ݩb;SGEݒkrXFWTlkm)JzY^a*]?d=] $KEn8Ғs+h)@&H9@JU`̇D۞4Z8wR$#d;I/F'|dmGrC;ZFIw32\%-t%#L' 40:XÈ~;!J77G Z>#" k Q;ɌշSR+R :ӽ5άߨM[ӓm(IHq2,[nȬ1>7&An1!14_ja䄮lOsW* }݁ղˍTv& 2yur.[G1.H\ID0q0g;Ix aעE2Hl{A2)+yy od$J *?-e}1GzMwlrp(à7B' li$_ U뙚cN\ be"/dLQ@Kj, #1Z5 fL,x/ ,*YI'3눒?t#MwPX!Zd=T/3fa;U#>#1GCk02>z;YX,)|sۙW3,(DTNj{ĕ(CV|RXP b3;r,Cv$)ܟ}*嶁 w7y}Zu|TLgsN qdl[FO4=LH0pvWo5X٥2BT8ߟOl$We/r~ o8Cq-ߏ^QTRoDw~I֤qR{]7e *p<^b,$wg$^%k3)S|* E8Ԣ[4~:7q<$;¤p ae`n>d[)TH܉NKCܫFkn|kt5fQ΁:SRsך_VT%ȗȾ_HZY}A)B"jRqEaOW4I<+?teM<|T;1ű4zɢTR ZBOt8W.dx$?!c0'Oxq;/1wI+OL̚媭X<%r/# iro&^`ݙniC{b/ W䴺\2Eq7.&.dk75KE ]"T~8nkQ{w‘b/)Gfoõ_ә?mb\F1KKŠ"LJ'Ū;q\HfJ1ᑺ/(Im%@( t T cʯx\ưkdb4/h^Seb gmrmHLa*يں_w] MLb ?'h%PAAavO/LȰ)"$=޽ߵG7{^BTm^])6;hda:uN|s  .6쾠hVOF~IPJ:94+bV0}tޞӼZtp1ᾥPb+W[Ń;R4xp`PEVl{cXr[DJaؐ[M,y+1*N gP^9<0\}WU1f57nJZ9Cn2E0mS:axÈڧ9'Z$f`Sh.WHy =/jཧ( 3];zZ׬edaZ6דJ(T^îȹ"6K nF(}^o:VH;"Yz&I&IO\NY& Q{Jvۖ@=D#:d H^J1҆=CUT`_=WցG\bcT*ˠW}R8!…~i@(6?2x^1()ۏ!˭bʮ@e-%NclcԲ쓾^eɦg)Dw|@wq:Y$63^Ҡp`MG( `;\5 !3bU"Wf -gɫCѮm鳌bS~i)ݴJöTg>[beJ]EqC oYd"HeI " r6MEYOaUt(X~VNacH}=$֣3+2џo`NY#kzL_֌yar P~&0[iy(Yo{iἱ^"0;3PcN2y1 Fc'~_z-Ek'CG{ ~ȗ\k?Oˮ[4_L`aa;IY}a/}i I=\iA5[wv)/ Sc@{.G~ϺR RI/|~"5S3 GP{ $c1I+Ky˶a":teqbHȎ߆\~ x׾^aB f/T8+[.XƎ vIrCHĵ`lUY6H~ֽV!+@O4]s 8f ӮC 8piUQd9=xù@:^^C Z~^p%okj'8w#K,=NR&@&VV4`wRzAuSBN<2I3]IՆ4sc/,W񯣥02izȠqEYETSFٟv#{qԏ\(6!G)kp@WQ7ĝw`Zt%ڕ.8M#wW*G+p62ŇU&lh22I5cd̫ M}Ұޘ~1v*ޡw4FOm//so>vssP Vn,60Xx{e\ƶ]'LrE^F>'kQzR(Y8e~"M e0;<#cn*@pQYQ% g0.2\JSC"d., ;dbc鷾9M2͛4#ac@'v< ȓ!<ّo)'3qrVnVMuBN7DIIB74F+zDno^`8@{@eyX{L8% -N"\ Dd7v,_HݥѼ8h~ڂN9DFzj9f2DC oeLla^Nk߽bfX+[&42FZ QBs6+6 *BN]3 ! xA1&ニOI3+PH݆K+fHȵp$7/' L~~}Ѝ5ӣj䵺a+y"ԞOA>{^ $q3F{C}k7=&oU}lS|GCl0u H偈) ݃Q"Es!fzd kэb:PA"F Ur>fGʍ: c3 bϮ'xbV-,HD X oF]W}kEQB,oԵ'`pm?vmX+ðbƠzd+1#u7ln=-BjXSM&2֙-|еЬJD)Cy||o9۵'Ɠ'b]+Re%PyAЉ<]P.)D_Z :ELS݌'u:*pt,ݕZ[nVX`wьHF$ζƔټ_0Y剂/غ&Fy WjŶh΀oZJ!y$ʄ=حA3 @ ^ ? E."?g˱kTѴ [$hy?Oma$(nE<K˧8[q_C`(` 2:?pnlun{:nr푌[;b\ j?.I;ő $"q@o3 q q]p9ƲGܶ 0s;ؚ` 9ݡ~qV!%WjҪjtHMV .S ֑pf8|^Cf! i `"xO ತ8:=),2>(5Df V].@߇zBoҶv{lv\W)-?S5 +#i6jDBUKihL+ϩ=! lBҮ9}/eJ則=pmCXNbR&1j֡hT#Bq qFqy=};\1@gO1Gpi,v4"LUe\:J/56Ʀvv''˗\{s/qmw;\`1{Q>tq{/dn/b"B$6g=ְW`j%)4☎ EL6S0GjĬ>铄%y؏Xڸf>3@G d"wKm9|B:-"1~ɸl L?Z?QƒN#濺QWo̲-E;p`˙.sUɪ82%z5F!,ӼpNKb-eaz~: O5$<_?| 74BނSrGHq1_}EbvFRňG& c|,n#,XL;RS+Ar&0k_6֎3?y^ʐ$l !7]rFOYkOPV.)NJ8#YU62fd^{׿16}8L*Cs w_2`}o0R>\`N|zӰ@+'Le\=MũD?B RdJ!"w=nPY@} eQ\s7 saWTۧGᐽmN-ZljM&`.^[QYQX}kkIǗ\'V^y-ϝ ׷b">)=p p7EeeETfGCGHkl?shF/`;p_}~,(SkWR[b*zEc^}SaS_9C)aFbU s~V}h=t 8&ھǹt,%i/cgm}M^:=H!9P!ܷ̃h*%y2TnECMq1~+PUcQXhUO؅7ifuIwRF(wg$ea)봓/hgf0TF8_6?OKFpOLI׮yEznהcE%.Jo 'zveriV"&.ϵ;ڼPVCA DD-9}'[=cA3qڌm;UjN7;@1B0τ}?)AW3+jG?aNd)[SF*_3<2FTYpSHqoVPP?OcY{>n Y69+K+y٤f||fqټ(`7uKc-R(d'wiՠ\\?u! h;u9=v"g3FTkN8_W \V"X 7.BEKs[  ~끝OP{$=Ţ0ŌE[nBU@,W!=鯓*ZzQ%=Bg5Eo`KP$lVJ`dGGԦ`ae9Y{m 4 Zu)⌲ v5 j(p^f/h!STk1vɔMZƩNaۈžښ,ѵjĔ2ZTQAA–O7Z[=7&_;n>;т%#$,LWc"qjb^Y}T ҩ̞~Z/U4q$- ߳rRGj{#)\o2UpskzZ#pFyHԉ°td4 *ǶL{uX7 V90v:PMYGA3gkSǂb}3PO^Ih9pW2I 9/&kQj3 +#dsK]*DehgP饞mcLz/;i&'m ߄f~4 Śج",CDPC-V$l/oH*Vkε)t(HOh($ ?Ήyv7+kc?CJF7 Ӻ#+^Ϻ.L[q,5zA: ISuUqfFZ=aBNXyY"[:b(a}OrJKѥu ;3YdŅ:U5 wE!%Fg+y$8EۮZ'¿os=B?5G5k;}XT.3%eM|_4M[uU y] L VvR]Gc \c~.XqGZq~u ̻3/unY]ByGFIhm˸[GEC.1F1q.i~f4=^,B̓9/E > S±@ɴeY aeeיu)mT"'(ǘtX] t nbs!%0PT:XRi>Qu?ӡ.~> @"D)eZly|Rs8 AuW/As0E=haIZݻ; ICN {PωQen0 u9=M`;'ߑpe8,+:N@< !> P]B,~YJTWYk-:B,"L>#7: ɜU+Nk>g}Ə:8q WMmc4+:^[kdc#؅:-kuiVV~dx$T gjȾ˳!(PE`F蒚] #׊;yGxEݤ`ei5"E]^ VRB~%Cg:e}myMʤo c/k-Zg8(tk_͇[5j=ھmiZ>ሇD+Ȫ щx7.dqخHh$"ٸ-a?f/z23k(߲TMv)?;4-׷[-^ ɒI#~Ӱmw~i/|ixI! |_Y VvoP^(fUp0_ɼdg8{q/elѵ&z B) C'P/A BmԺ P@ T\q5 gKcX2Ny*dz/J}W/FZڍp|' ̧ +lWػ)XbEC ׭m*# . k 9RvX ACFmٌN>iؑ Ex~)I7D/,Os & SI .jL8-zr)X)2S-ұ-aw,w$m L?v?no =:?z L<:hv,Th@keo>`kPA=#rʹ7S;ڢoh )CjsʹgR I؏cL>U8z:a]Pf%2O;Qm)cȭ/r{8=-' t mr%b~y`M= E]ؔUgNØu:Wus;V, $-r(4,\![VUpA~APf> 6^d'0dc )l(m 9d(L"+ YbU>KGl-?S-L YZyI 1G-oJvY>e_x_/پY^{4d%Z[`-ىYc&0)~D`ڄ7 )sq0(L\2^X&,K5uCC?cvLo6]EL'׼Z#V'JB2dS8XU 2زVgЁЎ':`: 4}8m7.A^u ?\(c}/1qZT%:B Im$.Ow!NADOHJ^}3AD9Yz,xes-)#r!^oJtٗciuOZ~j!}&Gm?}tT6%;Xe1ꂫ1abgSg_.ghTAGV{{ӷi2YlU)oyO~ EuF&3wz:acT;e6~"OlorZ9LI`;2Mg0t"P ̃ 5AKR_6GC ^ 钭퐄z6*w}6҆qA`1-l 0vT`,Oʟ~NjTMfio/Hʲ>Qmg! C{AL{4Y(͓n&{eEHk6ˈF$Ig h-uY騎-=`> B@b:S52x<|u)GE;emS̵"Z ɠf#R\cgp um'-s)SBLϠY ws%uG܄]4rq~ W(3M{ >wj0|If6-2{4I#߇EGOe,n&̽M%hr/(3aC(D*rlї'HNB* ׼Dh1G&hS NbYj^2efAh;5Xo+-z8BoMٙg:έFQߐ̦kn&RYd3Z2\ geZn!t|$3अq WP_NWqW N6qWSH LPsItNd;^æXc{{Eہ QW[xɖao/xi{nʬk3(*\6P۱Jf "[ca;5xp{KONEEWC9ev ]zЧ۽W/AyÇꕥuFOc/:/\![$ Y;gi/z|%Y]2|,Wx.<8XX&r+>!s3w!eǔ!Ԕ+DKNS$ tc1j2d7d,T8ȵa{}@SIǂNuһ+kE'i-?&mÞ1@IHm>R}}u6x An%c/nă\8[?~$$~[[Y+6Y$dTvP%KHhN: oC.3=N&6j=O5B9#m3כ1gmu1)2߆pBF`h]9 uM #ƑqPtè^S\ʌXP1Jh/&ψg Fl@O d 'db,aӔUڑJ nH1e:wEZJ}/(U4ֲ4"qP>.v矔׭CZBYetfr@ɕ7q+0߅U7n ǎzKRV g[x{vo'E I y qxL/G'駳F7Y3F>BE"{֮XQ^5.˜*1ՠ4[S@'|TڜZI +38ĭ.M *= M5Cʛ̼ޜ{i + џy0#@VY8).ox1\?TejZPK1S@{?K͂RCz4k$,m!j;Ɉ!(wcjak Sg0F.^ =Ջ4CJi CEԨf-[==w)22'(R.l.UY6{.tl`@<Nk|%P~ْә+ ofVE=!&Ҟl,juE6"؍GMrm+ZQVJ82jXa~fRfph|ڧX[+4yƺH4}j4(֘Kx՜yZ4neAo٧K1fpWފwYWVe͘ Y=H -r2ƺ`ט#"G K~"](Qh'2in\SXv 6D\n( )b8.- . z ǶPEǞ|Y)t3N>k&r$Q1,B=M/Rl*0Qn0CG%zNYi idzkmJ㡰OLi `Uvܝlϼrp",`~o%9>%#7¥B=k؋]$8D猀 6cTqiܕVfhTk,/jD/ cS⺨<Y;qԴ 躰=^#>Q$nU 3kS9Hnf]pHg|5 ԠTeDI4rqxNk~6R'dY.NF!İaQ/&SCqN up'yz Qvl4J,9nP\bfNAϷX[ڠHJ<7ޗ[NUK.UKՈ9F0Ч`k8,>e&OW->1jBlvlRQs}D KCR"Ј;xY_b{T-̃ e\ij ciW}d4" p_R[*X$"(PSG|:?D1Ixy3b:7B)%vm)m%z(Ne?bqhѣh2|#]I G\,/*BDgQU₠Gtr~9i/;uh{F uPUET>LvhDbX}EClWۛWC!/>n)ٓZ9|HЫ5Ao-])jۗ0p9kX5  #O>~LL$6J!χ,I[Y>Uvzfd퐀@|C`JN ZKt yO9 GA^H}E?ċ9I]]IO4W`SH-.7p&0DŽ)Iєr58B9I#$*B#֙)"/d -%i?`=pBzހ_K9_^>Q޵Y"G::k[`r LĴ=S ;]]b2GT }*oZ},탹5*z$rt[ʡaWO k.t1D'\ѱEoLxXn$iCEA YMeH e D,zZфrn_;JG]ՐTX 7J24v mV^ǂyucUH&rU. 3đ]zOpԟU*c@S3@C67Ɓ}:[.mc=\ƅj ]4f)NdxsbvG{,΢(5wg*\2b/W Q²oA=?M|sk3GᎬWV0KMP9|[Z#^p> 6F}8c3h=&8 BеTFA?۟; s/H6bo"NהZ*gmZsZ?ziGE fm ޱ.Wj}Kyő\g[^L Os.]^Ty;ZU!,KY(Kl#j }?z&_Cu0{yss8(`}SY' r@B;bj P"nW`ezވ':i_GdV^!l 7y}݌5z8TF I(`"1WlEZl*2['NR}]7Ӂf"wbw VނLH|LyW\dbĂ 4[Bн4.ⱻv$֪\Tė'n^&lP="Pɉn:ο^|WXXW!+eߠƟEzBӐ#}2#>S uBV?/kA$a"{m$j5Ͼ̉rXHj+5^6l؉ j&o:o@C``_PF|]`7@%<3vJZ!TKJ?&య Z)$nhea]˜m57NdՎvk /%"]*dJz-h 稕o#>|;;ZZ[tre239zHB"x3 uEAMt.yo]BcK}14豧af׆s242l+5 0=V6GG1 'L&rK$Fz ^D[b[nyP2ap©/̿tqY#뀬d,]ă ^ӲSE">!+>MXuL6nikc&_p4Kf4)B4 6go ?ʘ?qe\x4ܯRfE4WXš)d^4΀gub, Oz v,g9#@{)|ӵF2{G6j4y/An"Hz?B EǔRґ8o}+,!#jˇZز q@R M/gE7Sm=},\8)/~~sϼimPq$fth20yR8CݝOA͆M780@9)HmLĠکRujSAWdÓ'џgOpg,\LŮxkiRʕgk:wCK6rE2q'3U W _ARĴ5#gq^!w`\Lȕki!!ޠ M F{vNc1ծ75Xh:x^\ߗ@9? $H5|yte~,3+H|1|&icOl΅t/w4oǔVŶ!tUwtQd  ghCUUʁR7K(v n2t{~N~Bi =?J@ītnv|^.vIAܗ܏9Dh"Vj(/0qY:N`,)UEx9)PߠɌi2Թ/ق|G\DwVȰ`CS`@ zPJU&iHWp }hg%%+k [Bҥnm/<E5y[urQ_G_ vAs#is9gGߋyq\MŖ}ܕ|j@u5˾ 04Y+fm @)e3?'d=F>Tmp\Y;-&y|MY;?E6¼}be7drܽ{A:So>Iݍtj߫JCvd=1"t&kvp C-L;3&7BANvUǒﬗD_7H̥|qZ)V(;@e1yi7035X-E`f wI)?r讘F䛚55~])Hchӟ[?*(D^#(CߒYB/*Kc)Vʓ T茦ҝ(ǎک{V{͖IcJح5vMʔY`./lJ|k]f,} xR00WSbO.132e!{襨GFBJCT(vz|̎~Y:Xѡ"*hY5}77TErk*6+^uE'ȣ0cKn 3``vؗ~d d8ڞ^1fuY[*cGyeL&h:Hz; <Ϩu}%h\ 2HZJǻn$nU_ Ig,j$W1#BTF ABp쟜iԮꂴ.I>l[ B =*jnDJZ!1iH.ȍ .h 6S)Ҭ"(G QCxh,EL[y@Vw._^gIgzY3f4KVx>ڞ;pJϱ<٥d! M3/iהD- H;_ٍy͏NH*M`ּG%geJ}ۗ@3 A4iH >ߖbU8Cl@i\70 zqpz^n; ЮIA0#}ֵBMH_&'D=XѡݡdzwI)4qGƋIE(#r*咚u_?:SkDeFE!W!7 |i0;` OY@)3NZ 8*1U/Qa̲ntJ\il@s|}Ĺ|4ŔvbEI!j=:5xLCכ2XZ"F\/6\C k7HYʄSHt3FTvQGI-F` ׭HHiN;6*t"rKR`SrѺ0HX]se1oh 6N(bsGij4K3?+bgBj+ U+Ѯ_e*ʷ5Vݠui<'z>-UZ]3ZCq [ȁb PyEלV4cmbaP{ [4v'xoNly~4]@[b!XXh}p+Qx !gdHZ^ {0P,s:e#|Pa9>Omqed,ay%Yc C7is:1,\@Ol9!=/(p[Z'JR 1QH̱(2~OZ4sN;_\r1\كШd 3x'DQ*d :bg+IEӼ a7maJQ*+psV="X4^o\PgĂ&w[S}p`q f(rxoG6qB&7)]@Y?ܙ] dzMnxPAvsi^5㳃'pgCkeR3-]}T:V |f Q|h)AopO5^R֦ctE;l'V&.{o_5 7'p-iNP`DDk6hq HIwgX5^<4b^` ׺օb qmz/5 (s}צۦCwţ[ۚNFڷAvX"ݨg?yf@]\naEH;UU{zGF1'E?Oιv4 /YphXZi6?3<^ -$edwc˲ l.[>%.k,Q:Qo0gA8#hSG@v0;rùb|kxX~lV-S-7nS1fi-ļɥi~/ej) V m(YTJ:@;Zґj+B/b>96$NIer9UwÐ@Yě[K>sԔec br a0%bOk"USC嚱.)lCMDrX"#jQ)ȷ vI[-/'|C.d HO'up5Mѹ"m^&ON,B@]SRjez l(zhL.Ud_zo,:KG?=&haݶkYR|#(@=(aoȶ] ECoACP,KV*g^W1\_q|@̮5dҴx $pXe3&6Va$(7z0 $joX֜2,%|><*M5vCpxtH"n&5Et2&$ x 2W=VK/d$G_]4FE]# {hE[u)'P9M)wޮB*#|cHS,Eu#yAn!zk #9 Cۇ2?Hτ^+Uaj\ŽA:ߛzQ`$OuIJh*¤3# %A2E'&fjD5} zp{I2o6D b+w{28z[k3<&T ^Blf~#|D?xnD7)u5N .ͽEd)(da WJpƄʜj@=(jGX*Omk )|uKXG^%v=L;|@vA7*O-hՊmNCxT=a~4j}=D8wo!z"5+ɒ{RC3\8{83qNpR@18e@<\sgP?B4u)~`|q_3"NAGGgc}G  LsaTn|hY\ I%߾ycAUb0gO-4a./zPRf"6?*EK üW}Jܺe RӆX(oC_%-R,idgͼ/ϚlY s,?kMUC< AJf5MUHhc0:P7$~:}-R31#6̡GxKSX;6l; 2d2_9# g _!Ñ$Y/@Ud hQM>@„X>-⌰"Ϲhq+C[֣(Ktڗ: ,rz|]W|:BBR=vLT:PwF˯8iHq/k"pI&4[ % <ɈCV+GA 1/"LVx%t#[?`dn]'zyU*.-hͅ~NwْL9@)f_Ew@nKg""Q dҐ8 ~y.Ȃ ÏѪݞپ#Г8Z[_+Z7/Öɍ %nߔl"@T5_N9Zd'q.Eԏ{_7.p^|’guB^HwohNzY 7ciLvגC.垢i!y y]Te znjt+)Hz8:Qh$WoI 5,Qy؀6 0QcX~ܓÉz+hSxt([]6E0dK! Mtz$91QkSҐLEhf]:%XЃchAO8[])b%dׄSЮU՝'4!K뵮bWV^t 4`49smwaϖ,2OF{>q.pU߮? ?зdך#驮 zr^{:*]Z)3 JH1XZ^hșW~NԜjrcqe\M<|E&Tń,tHުז"2rdο R Y@w)UW¸f# }x#:r9vEr<i"8Ȼ[W$mShO꿯m^]^Z18(QuR$IPis٣/V'SL n~>LנNf+n:`V| ,#"6̑5 |-PIcRuEUtuS,#sVsi[ x$w[-?&^Gu\ ܱ#XbH}Wa><&=cWic$5MM- 1Uj md [.ֈl nm*$EJy#WjV+(gO-pVb–f(\ۥ;ײ$;$s煎N 5'α8G?&hjR9JQxW~h}@.B!0;~̵+( v(h]k\6:@- 54~ ~ڧ=wiozKQ#]̾1Vb5dʯҜ+d0&$]Of#{PdM˜戛Ň@ C hyJ\ǂum1֔K޵b_E /[V;箆m #~31kȬNE94modDAС ^D[ϯ,i '{wF34" OAce1AW?/yZxY.gl}(Q΅U=s߻L?ޤPs#v\қ."\@_$9oHPӏl?Mqps'W/Ү%~2Dʔl߄} )tDKa(}SR2q>x&7,bfpx0̺sٺ}KgY/:HZQ6,t\#>,o.DcVm4ww9)1**jFwg͋ 69{LS|n%,}.OhfTtruNshKAr qtO8ṰuYDuhaq8 nZ nUJͼP \T@ENX2B)C XOf (I:oDo5+cu N:(_œ@'6{#ƇasE} Y^bX,~Orvi \ LB}6mGx`- +-^?$=sy :FqP)EyجxJ8>'҂]ǭ2j&R%T( h ٱT#kz#@Ot0M#dSXƗ(VmB8\P!p'ײ kS&x0l\[鞦?By{}EQk:"eTO54?m^7V= Lc jsNނDȕn˯D/J:]ۚu}.Q .O:ܙΙ|[=O#^vp7#qed7a/7{ޯx]ָ w2L"V[~*%‹ieT/gA]Nn?yL M[5ܬan3 3(mF.vce] ;C_UsHhE]J;%g@_ފ!do+ĝ!?%6B&TɄl#FJQCp?xmOkcK+,}ԿB3dѿ T,PuV7Ǭt` OQ,EOco4 f1`A!3yZ#3PŁZut_i]=R^ y7$w 9thvHfK'f‚wq+COo.m/CN8[ |9',"N#dž=J")2Ђ]W[@[T2mRZSz;S8Wă0%a)B ?0!q#Ysūl`~Wh"xK$ۄ ~ Tmtm lIh|{ ̢#8!u؞7;$M 1KfSE/a!4vW]؍uR-1H{PodA1c.&fqNTHwvb&Rʢk'/ۥ*@CGtm4W_&.P}AYo &ffb-*/ݚ(h$i}Y]9\T~!3j" xwU_(++Ռt{j*(+-Bhh"&>qve7tDXPGMdWg;뭗٘!*jИ}o+w /KƋbB0j66F^iѵb&{Y95S3WG$(DMW$q- $4R:Q/{S"!k@ NKxiox5CULU'q,1$w1{s0HE+j0)jHr8Q@=W1Ŝ <2F|x9e~Rxd9WތϷ c! 0&T 80а\sM:#vq@RȚkMKخ6U:[S!ϲwd[9dq4 ݥ#RQ0ڢu'aKz,-3ڵWB^D:f("e guxGKLj >" AvD\I{qEӦK|8URdŻ燯ďK [odNDQb5oQoZ߁% hZAvLD?2E03$gQy4@)5S3tRfmlmIw. t~1'~,sW i_T~T7Fr~ ^~YL;T҃f1LJ{/)Hq %gNYǺT "l\%Wu}ĉ6hpqux4B1[mLQ4%X!˽82H_ݽi'PUDЙpL<) Ѽ"9yx3c^ )Vc<vgiJ0EAsl+)0yrtDë<@Le8S u^k _FB5~ƖKsHnצҪ#vڇnNd~s˿܌l$qS_C=E&پRP\̮~?yVtbr:=g=NP^k{uӺ)۲ x 䧱&һu3бedx{$J\ ܥ%M1uMWWI~h^2NS=Thsر4pp.Ug)ƎTĸ$%aFD#XVF_IǙB~f֮GjEIJ:wG` 2%v^'4>ijo@.đv$HY<ϖ{DE8 R|03ZɏƨgaS #HT&ɝO1Ht\ E[DGc2 ouɍ,"TDۗ)^Bf +R e?y}wz&^(q!4-l׺!Vzd97Wui$Hf[qvrq2O˸mc0rsS٨ (KiVJ2Cf5:LyL! 巏/,6Ϋ} -Zi(ǣO. 'm|Z<#aww8n'SsɻL!p0z]c +"Ey q]?˰aNp뉑c0xniTFBh~grFYMǤjX4bR~s?xr~gRTݥv#ܙw*+в8_e,ٕOxA.n>;!0*hrY#PU9!*5Ұ35G1qDuFaxfH\v*QN@f;lwbۨTM`[+rktwJDT[xŽ8k̡%L7 l:(n["&"D qHI%iՇOtmMjQxɣ&Rm f;7Wb:6?j}e[/2FqMs%܁ !ehԪJkLH7dg)@'nKI'M˱e7KZqRYeF ŢIaYq&@zbZNkP.|a;w~+e*K¢YNg#A@ˁ潸_V_d~[OI8pʒ\¯HSG4̉Mz_ͷ>+;ŕzt_%=JPJFh=~r;Vw?]=hI$0~TKy@,~#@r-8pRVAEdmFjq#tI'_A#.Q #tRY1 y}GeS8/AZ <eA/ =Vp^ /9'[/>QK;7Kx" ӀOLdb 0BE{7D`RiFrѤk=Jol_s{2˅f(mu71gwY3-]=C[LIqE*MwY[Ke3tOHg<)>s@E/|B&\H+Ur .,Eo8UhB>c-d/D!^e:%lO'_p~M"t:~5<ETv`a}nW[_$Az;m7s6]TEo;*+ /׹?hiyv./m$GGv~|o+"7 PH]Y〿,4$T&MegPT M 2Ȓ`^)q6[gEE,X:\_Gr.`_? Qhxe"nSQ{k#x6|cb~{[ |_)C;iH*?ifV %C-jV/SV <7oy=` tbXwOꢅ/_x pj%` y'bѲ`%neiNLTY: |^tS;*YB*30pK#Gr8{Id;Eܝߦل:D}fL]TɸrbG.siĐYrzyzj7ҋg&NPD;_`t4%kN/mJz* I EMvaeTA`Յ@}HP>&1Gtp6mcߓV^(l&[w{v=kjera`Bٔ[۔6Q}TY?*^}PQEeBÎO!N,͑rܺpސ`k`5.e.'Rg*m^]$5O10 ev6 侼t2dE2KϮtޗXQG'^͘IW:6c%]kQEgAbr[nG0JYœ][.PUuU߉0t}Ԗzt^_jQncdz`9H=Fqo`xI"Y #e baU= zeeq};2/zjx*W1W9_i#Y5AuLO(oqȧ9:jM%gäC@P)3IP,&~H^ZT 7ń쬘g{"IkQ!{o$5YpQcNF!Zޡ@E8'gB~CfE2qȵjB\R 2½(&3nH:!6y Ze?M3'< 3@@᾵Qmg癏ȿv`)c%/#ՌDo10Ћ;Ӟt1.`&qy[ 4Ů#3$*${Pf =Qϡj RT66y4w#Y{7 f>|F@PLl eS^MTЯ:~#S B?P|qX"q1d;eRZ"d572̡dgEm]-wU^ Qtni+KG{0I=A>gzY՗ y) B͇ebs Yvi 4+!t1MMRJ8x$Y ffaiQ}؝b S+,->Wom6Qd# Q.ؤGoxk<-3G&$ –΁ssD@߼B{>)XmG$:4 sĽz1tp.󿖱lwg rH! 0ѼTuc{I{p@~4#Ԍʮ-^Zc7F'v @ ;oxWx ~bCz V\8B\[* z8C*S+]awb9 NzIR]$+ExӇauBwɰU!w\>ޘGjI# JPH^ x"skUw_^iÁ|61],Lugj0}H˿,55OD݉Jfja6k$ OѰzr1hU-j,OئmO9T[XuZIj)]۔{"J`chd2vw; 6ʊUQzuR|tP\82,qz%x]_q`RAw`K1%QsE6 ^. (j)#ph}4suzNTձH ? >iOSMpW-O4sUݼt!(OԿGMa`SUDː.R?*lW"{!FFTd<Dmu޴ƗH3=K3ÝR9L 4 woxny{!rk=KhjC ?N'q[p|˅Xخ׭If60j@T/TD0?cjf>/3(#RR+k9Fk Occbu&]?8y$5T( ^!\Qiؖ7l!z1':ڂo~Q# &&eJOYRV!{$.*KSA/M.0@'BTqCJV U:BD0d"P:XT9֣QVɢ;XB/Y=pX~V o1k֋ݒ{ /N)F?!N`.)4x!X%Gbfٯ}',+ƨB7WrB=(xd3Mt鉥@<{Ia%)S4&e!{JMH_aE,S-5%`Vro!1@*Z"^2|􍨷! ^,*o߿i”rb#rTInP2{zN]u7X`k}v:V W:+xfɬ?IxL2я8"TS nZi${tu-HYY~GMgH#ց>qSPźԣ*(`|&8>5}Qg(r@2/Ū{T٩! z["9[7#T7_jC*SU'' F ʸF@h?l@amfC:o>M}j}ދ хLvOYܧ@kO'q9fP}2RBdg)-GW/9kTzn?}y3Ihv TsۋεRQHkǜnXa}'L4iI }Ŝ`9x8ryI;&_.kEqܙ8gYW WǠe]",<[]<kM70 7w0v)H0aF u'+xxbR:%?kO\='p6Wϴ% c5I'~ mQM$f뀈,͛NCO@5P*RQf"T4Uo?\o8Ȅې8a %*R\Nf|y!DeOp2!2sqe۫?Xs_fgnA Ye(.]ُ/%bfLpQ/ZCi|ϰClBz:(v,1~ŠPDoYDKJ>"^tXd_}#g ؇(,n1!] bY,F7б nqa0[nlh@+0P}gCEм_R,UI.MIqs@T $iaWiU֙k[Q8ӫosw쿤V 9!h!8CAr9Ytޓc|Ȟܗd1Jy`(CR/}a1bRAH 6_X8(۳"M^lHaE*^SNIbR ?=Y0-q-k T9 ~bQZ'~_pzhHs7h x&?67W3[iƮiD >s*.Zjc{uM$^dܜ1%ɴ%4ܓ/W4E58咆@oe(o6/m/1ƾOitҘ5Nq m4wvX|2H?KA6O^⩿y+!="1 A[d~:SJ=3C%wq^Km8B7Z MXDl ͥ!JK1:P;:6' H`!%]n4We}d/:HI\6IA0{.w@er(- a缹3ɴvkAW5QjW4$'CR`=:X   zm#60sj2DA? td^6ˍ4bș!Qh7$\Խx0+*,DgJ\5AC3A,.z|Ɍ2?| J}`icR1+rypf$'1[SxK LH^~yo KM(;&~rIb5} 㷵=LS kus$7Og4ÙbAXC Y^͕]:b."~r+7g&l|@NzK0 ֹ|ݎ?[.<IF/ȡ`q^1nw`ܦכů;iͷi|x墩/ w]H/Day9``צsG<5kf^q{zo~^HUs]c(p.2/Lκ]KD0:d}RuYVg|-7EUd`k+;;\씎Q:U7NTz9$O vzzmv?w/f쏥Mbo:&uo `!|zQ7=U}'0g dQta|^[T*3vj}t$=%J<*GX8L*,ʐԷ%f "q mXg`.b#mEB'KtQ P$-;AW|z!'ȁ:ltX|G-EEz]F$68)AJ/ Fbl+KzԤ_Ӳ73J;2F2,7[{Å<ښw3fxW|^Dm"w ϥzt24Ħnr l60#{OG2u nV-_CNgpfܑ< W;*dQT-fqIbY&%D`;czFj+&(\ С̘4q Eҭ\~F-;92b̭;t>A}cTBڵ)Ջ|_C v0GG2C+b6rP,SZ/[U'*D7<(OeOTIFŢB1egp0w :rٽ<`u( ,.ZO%`+F-.\`4:j^$8(.qc}D/A/Ρ@]^Kߔ!6z`v'* IawI~ 0Fh|4NA[!cϏ('ŜN>&}b?u\biP E1JU*-}uc;F[tG&?At>P>H& ;ׯ$nôAͮ v;UU.},2Q#>q!Su|8u[]&BQ[LԇZ깣i'%.?Oy!t֏h ˋڍMJa6ݶi<+J|;+ *gǒ;usL7&oM(lx([oc z@:r͡ MRIǃ4>b zEvZ@ :D< Ngd)bVqz5~"Aͼ%]A(D9_ף+<e& F?`M懿ܯe"d]Oׅf, g P"_MHI$Sdj* ѩN`gZQyi9J>jIC8M{S>Až8bSU#Y#6ߗKQ$kyogrjBbXV:f2 5!a.r&!J}}s[mi{ʐ׃͵Iw h t)DZH)ʊ cN™רc@Xd՛మo EWҝՃݨu3Ү9e>~Fqm}S`?K[Bɩc*Yq>yڗ> j,>;pw-gD؀(Ǎ*><PuB6tQZ[(Nr[FtxXE}W!rR|3|S +4OBB5@:'WY(ʗMQ_۠WުqhY_jJͲt-^11w5N@ DMj2HT2B0r$|riI&(|A5(v=kke~*x>] *gh|, 4͎4F4̐}`W޳XF-\ GCsvWpq;J>KÈ0@NF'C<*C Ǯv3ɉZHt͸>線~ ~d:ʃlFjav+n\3w{sNqL5h{!$f G"#qmC3k.c8)"N+{5J+ɥP .# *>i0 ?3X1Ԣ^ag бǚFȪ]xdƩ4>çސaT=b(" RǾSld(qj8C>xW_V"%':2RQP5/pH\ي ]Xd1%MLA*=2{>~d\ &f1V7waT0#.n@ 6 ʫP駖vپRvcr py=qjB5%옝. /4JMK";[`wtF?1uNaYK3M:a^N9B#gqcמսe/5sKS^9`?yvd*wB&R}"2ܧzBb3u4O%,MO ׼^jH1> ϵ G=~RH8GN[NbvES2'Xcv]< )^I^ 4^F{ U )d* zȌ?+VTSW:"Ƙ_\0,P٬i/ [J }HPԱY__(B:7^e9xWy[Tؿ&,|명hê6/8-s=hznќv*)ٺ }@WwWWw[$Nn4'><EeMz0&Uڑbe—]q o d]ha+$\x, ԼC8VNiG(BG{e~Yfɷ/Iv[;W5@8|'jCЌud"PXN@p&7RMc=+d>{eSNrOfFmc&Z"sz¬9~ *)[tDXl[,>=*̹s&ASkJyAnou$)=_QhBzىBm:$ A? v2~ |-0@4]1 %|R+䇍ˠW[cFT[7]!Z߅F~i)-lP4g~c<iLJ:\x{VS*EnNd˱&MF-H[bjI1v g/|,p6[Md2})bYm(>ѕJ0Fb}! !u[ naIG$k|vHgAe4](p5qUgF֑ѮyZ1Kvmʓ說%7;jC8o2r"Q ˕*h)|(\ |MT&sV t;JC&]lkyj .q>c$>Wm}@C,l>V}nj\ A:vMnb`GIpF/Ö0k"\33 "ch98}s4.׃N0_ jRw'E >N5h[[7یB@w,=me%<>yn8OOv㰠$ 7 9  9r`Rׇ.{MxZ*U5, HLC'`&8"oٝ@zZdF*Y~T!#66Tya%Y_kaj:''*8. [֞ 2p]-quic# IFN52"2+b[LZCL';1.ihI'/ :M0tSIt ]%*W?0˶ /Ce3cӏɫ/W2|SOT s.0"=# '0@#뺨BZ~ofi>c=zX[>o/3?GCi{f^yd Ys8Dhq Os޷SuWKPk!#u91y \Pwy X4]BEM&ctyj#N AlU9Y0Lx̪xeeHbMN;Gۋ;ƀvq&f4lNz;v1qڍg Uiv PKE*2pIa ,ډ~~a&uz0UQ\yɅ`WA|="h'arqFWBE^ =(~ݱ'qwz-GUp{w.k;-T1dHbS3=N/!C4/{+>.Vz@lר)xQ{TDk9T Rh[& MGGM93'r[Mwn>J7ؙ*Ȋ|nN0sEs=>uK/)m׃H7D(Qnb E^1 ;Ā 6H!^خL36 (DP.?Uy Rr KG GB+b a׉Jp n{:RY߃X,cۅ]ES l2Y{ag,˰6`z]`æ1J?Æ*J 0V|@65Ms#]]0]=ﱑ u毷(@U%[P#) eMc?oNB5~ɡAT+BX nk #7/IPNh <&t6eږTuOqU|twēDzv!]KC# 4?f** fX~l]a襈6RgR" UXJ=>\Yαی229So`02 I. c5 ضw*-ۃ&-u}nBW##"F~Sŀ&c/ZY'n6:7Kd""Y0  Q(;ˮ%r/+aȤ{w5 4m5 ]TD V {?6+zE216hq㲥ȾZ[|*t1Kp_U1 $nbQ9- ?6YNI/?y ^=}'3b7 -rs![/Hw U;E~csd57xUF B(RN/oWW rE] 9Y:y߿w!͛C.ե&a$\#\VLjci=TpэL?ु<&Pu`| q*7LEWU;f,?:'@ڼ[5toRAss@}؋.Ks^ G6\FnYƍlf.ӐU%GcZvVۗ Z-4Ƭ6!7J49Xԙ"(8|Vv7[Z`H8AM`Ml~ڕdJAffM B*hԭ?l gF*[tqKͻ. ׿7։PN6m2G[UnH7S~v'*ՋNA0/";I uG+a!$ >sj{Y1bptӑs|# 9NHO> Jy*tXK#Jh{wc˒2/嬁c)TN\F|1sSXҿAAPE{6ЈTƸ&=h2tI8Y?P!KNVSf0ަF:-fZW  ATfuim299%|ak8tT,(AUוFƅЬ *$/,[iSxq@+Q>9)g&D?`S 4כؓ)[0R5ۥ8|d qt ٨f?ŭ|;hrJ$J2*c:g1-;d}{i ZSbg}E.;4mFNYi{: %rK=Ab)ԝ2_@d,C?x~d#ׂ4EF{ ]I9-#i)Z]v:I%4yASAЃ } Gm9B{a/^#ґ%V.p52>/)-W j)v7 g?cd5Seo. }>5)Szt@^u]=,M_mz0¤6G=="=*Dr3JU>!HYj6'iևF@zV*i "R5oSr=O"]җ֩RvU:PbR oMktewp9ǣX9ԗg0"}Y,M.V`RPɃf+hiK~`gkf0֋߷M=Fqڼ Ɇ:^ ` Tbb;(XI=M{DuMŧHnpBHDW0m~H5>Gq6foki[ědhfeԕae1vzBěm1ieOO.I@pi[msas}_8x԰WBP G)6WMOD lh=7XH``n^{֟JZBx͠_~$m&K 23CJİ[ Y*A`KԘf7g׶@RsWtmuwQ rmQr pFb=ˌ O(2 Y%^64\ۉF&4 pϤMR#VW#Sd&ҵ&4S%6zdV<7G|Ɖt[7IJueh!#CG"LҊk8+k%fC|c1""FU%P7~'2GG V,@W xi#51U !aow2So͆C9-@Hͻd4Bl%~`BÍ?ãmr=*Yȉ7z=xl3]ZI<[j1CətB9:9mB>2P$cEرT9 %y9\8 db0$׭\6,W7;" hq3?~4eK> %^5 /qtNQo?`{WiТWRzƾ({YbA<'w;?0ԟHጢ䠦=UYP;w"%:GZ[6<?[4?* ѭj%`l8-ļ|OPW kk -;SK'3JnYqeL$<}83mg?{d]; ^nGE%A,7uxC6 F,X IYԌ?\Mu>-ĥȪPeJ,~ %&j:8NPM^xOtba SчEkE{ K7RDD$:ll41 ;K&\=0z- ,*sUgۆ!m8gXK?dGbV`vn_T;ܚ˳G,e8=.ΛQK ȲP{ӟ:lk~w7S\8YQfLeg8Mĩٿ&/Dt$ӈ7 |35[,m*cYcmccqz?5z[Y`7#-ldr1cF9ԂX@+1|0 f :UV[- ^9 ܆w}Z"38'#TmeaBt jBekA2^5!=sRo%,7r00'/f'^1jPEBbb""% n^q5(U N>CƬaYR{dzY/uSMZ;7_S>HGWHúmU}Y42w_=aVk6 D8A Z[6럾7B)DeTNvA{eHf >,a5鹡[+T,Ek*OT03) <[LQB̵,*F%xP*uPesƃH}nC;J;)4{uh;bh٘%׺ .^2.\=4%'oo%@ PpʬOn:rw28@;BPY jZu7uK"C h8=6*[koqep\~/Yq PK`Ũ8(`D-W{!jp,Tiv A(ͪHVO'jH_΍x ih?4!l)gjuh<䪸xO#I[>auB5d">WbKOew(܅3#, *=7*h;z:E|y|!H>lOQKuo k'y۾bI7tEȒOpGM}p[NsD1KWN#/R55{(mnyh1n:7U( IcJ] |h۾"|n$ |Mt{˷rF#w_ eTɂ:4nrڣWuG?Db+z5Uf. X}D7z#%&^? p?zȥCAT [_ݣQ|wc6{cs3]%?f8uKBA@dYw M^ QUN)$t3 %ɻV\+~= h8@ RN -ҫuukZb"pJk 8x] 9_xvy PQ䆹 U -5Doqg:K4?Q ȷjW%7GXTMjk4cnpt"_+4 R*n!a/@r:Gl.VLh{ȭ=S>TCk|L0ףoUi~,IVћٳ h,\X#N _gજ셴e W?tW%2~0 r)r7d^@ąf_0*x!ZLtx]C;^vJTQ uyڱ,''uSnpF 6ZP}ۢG$N|*(zg(dž,dz[@,Е NHU*j%A?Iœ:ˁpv޿sжQ* Qx[sĺMbVSߪqB%ZU_0h[#' i(Rʤ\&1Rp8b y_67VT0pLDZU/r\WY@P1 ~][׽i-u!&%ikW [Un ʱK9M|$2q$зNWwl&*X|bROp6Y6?-OOzG\P fjAE쑋w<1m[b zJTi-Gac^KtxX5F;-ə&Ԑ&nGIMI K;IcD^u75f–?kys5jMvPNt⋿qb4z:w,{%dX=u￴Sڽab5 *>e,:)CNjWsa?ggÁth+.Poi6^6ZǻIgdEِ9R)S; vOmpșsթI^}xK~P߱Tn$d`ˍ|/zQfx!ɒ0k[^ FR[Ϸ^`AuuG@ޖdU%#S1Mw>!f|h€؟Uz&kwwov/֗xz ܨNxmJ>T݆%1Sɜ+UdaBw]Б6ͧ-.na6nm͘Uڔ1Yp|/8bE:&kuvKjo" AK>Z @S:n'Ɛ`)_nBa@P2ц _f1ʡӏdi美K)P;)}2g;3e+ϻnn#$lŖ Y3Zr#:աZeG@)Bftn% JύyWxso6 G"'֚AfMo!'w+T!fJ?*A+)V2mveVJUۦ%d[MRrVLP@BjyL} xʞ|{6evu=EerlJRq`x&V~lqH\K?ܠ턺zT53&Ōk-IgbVe?ޯ#q5i'n>2.5nÈe0+ER7#JXKX%&lCh%7kv.3T0e\} 67|"*T)Y00ewM4v0FӰd'#~_*L[N3T4" QRkn/ =!ȊpP:3Spī eR\T—{s?ꗧ0ND2h}|m=\V#./j U,ȹ SV:f} 8Qq_]9{]|`ug[ee9$uDG}V #|Z=Fc[IZYDj) Gq]WLѓ•z&EMAhDY'+P v*FB氤+үjQʫp_x0mȵ&t*rEZ`]8xԨm^0h ;^@6RTcFpyMwO >aY#>m7V>ndwa$R9 w6;t6K}@n_D4R]U6=$Sui%! 9D}eؠ k5KO'ݕoqό玪Q 9*DmN(pŖhĖt,>6D#7j{um ̟uڮ:P;xp*T\ I tjd;6{5zdzW/ س ?bjf;wۘX}>K(AH'8I4F|Jצ6l'Lb?+s6j{ ƮU򰹮u'yc:ɾqQ,c[^㎵Jyu$`U ocOIPȆܸU78c6xhE财0Yf"\bǻAC9Fk_Io2$K-\ypJKB8# J"!ze--~'û_m[Dg8rIߦVkf-DwVo.eEqiFoc{Mjl/@2G<$ߧ&:EL~X rs"=mx½DD.Mc^:L꩏Gω;]n&`)͌ \#b!h>pO\ܹ%ALLZj5&H*m`bI{Z bAeR a s.^N{L0h%$4UF;%i 3kQ*[|Tj09u%B_>4Sg,ERuӥ<>%=9vňȆVs> |ipP!`oJs2N˶(,> >@Q(C>Jc$%h^ Xgu&ιhwsY%O#Hk -?psSI; yxB\e*I|`?.jorιCniTqfhv`҇z%#9D9=KHW8PAaL,.8şL&zc 9%M+s+יۻ|T#WwotL:vx+uXHQ`W)nA|-؍@˲%ة ,4ݦzM;D^0X3nšvwHBqMOy6 I5t?M9yFZPӸGȈkJOefձoۏ[8r0VR* n !I5;bmb?n|H_p""UԆgy,uDK~C6csvFY )6kҌ^TF-1:e 2Z)Jr鈷&:\mt #Z'r~-2j #va ۍX^5K7UNYJ+fpM"] ?z8؍LpEsɃ@LZ 4]wmU:+k>r6Y .:T+̲޻>F&ilɳ#F{J ۧt䛓p籚ʭ7vôρYU|7TA4 -١JyЁ!VovGf Dᐆr`:nW(𵩨pʴAUk<^>(> WC/o¾8 SWsB! fA't2|+&iq:|K ?|ێ""Ucx6ھ>)}1c3>9.O@_BcLDVQHRsܸ*09;Ik/C_ڄ`A0Yׁ7$/؏WGsZ= T5-3+Ny[⡶j"hh6ۮӟ0u<&qR>r.<L@6g M jpܢͶKԣtroi GohDR z?@}$('=?Z/6Pw5T5How}'ω3| WwzX/6mϷ|mO9E4Bp4pq>R}"e51O \ s Ծ'/E*(ȁd'gJ- zF{k!N '/^r.|W< X> 7‘ Wc3~&PM-Lۑ.Ӆ:tBيq~2"co8$HhƉz.bjTɌBwۺA(D;%PU?*)ΥbڠjBppiXspۻТyTi3s>oo#ʟiϢy1V9]ĻwƒoM!I([%FbV;i =aT 5MK 6n ^~P.5IOɺw{dV:!uߙE+OmFtN@^䌑9V8HI ÊVXH{foֈdpOU4ㅑd+c^1v #첵=lHC(_NtxYW'y'@|D 'i|? 5`"$%W~B9har;3WI2LISuCƼ1jd s7Q꽲V${xB,j0.:ީoR+j70>#n j4ק0B!EW#Im2<&?} ؤ|^\#Jkh-}?OCSh/|Y"'ډυ7|8R}fuU8 #$NjbuL۸DP`ϮDz !js]h;~]bדOk!|@Pf'y",y1@ 2%yğ7J+ar < OÁ: Cu>H̓Wյ/o!ea[tKV;2 C|ec~P EEQ8P΋ϼG:-5qe~GȺxVUEM+?{#\i6x1B uk%22 S z a n;"[>QPDpN˖i" xUCS Cw_uI*пt ΢6%*kpG͆);5Mjm"8U[;7V@M[c(ĔcܡTl59>J8־fT)RA-ٙ[PEC>le%x3vS|&DZZX,d & H 1=R6A8dRm!Tb3,z4;ّŌt )b, Jh5EE_B:kՕꉹlKx>}^]2B%&"M2ӂ5n8|d1K?UcIȣ lR $ǬCcP :onlzj<}`,%sǿ} Y7R)JֽO3[„F4uT~}Hx2ZZs{LV~y SPhK @҆a OD'==Pdºv1. FYLDIU9A_iz?#)~wycNld|Ƽ-?c &Lν 򙦣Т̪PV"_P( dF;PR@>`U6h!,'rݺy,py!c1oDiZF  yq39#r|cNw4Qɭ̭)Uuil@/ЌnOV&Oue5H7&MWהU QݯUOݖ˴c ޒLC|&"*[W|0'`l}zv5/ !)C*_J$ d8Khj z;_O_Irv!FX3shuO$mhTvo9QՁ ' #k}pC+ߑհ;9b.N_Da0f*)a/Rl*ﶫ`-eztvg8S^)`1]y X>/2k3Er}')ӻX`M&S9I12QA8q >7dzw:p|M89'(^!mBG]Z媐mhԟFhJ`<@mMx2JavxQXoѕZLYH4a$ˎKkPP1\uQL~z;?g} e}æ p7IPm8TTSG_*f\uvՉsbGC-6tuzmHIA,Jz^֐^A^*!\@9uVPOBj=@Nw wQ @/Z]N$o?5+*S^L')U!gd8P"-fp)L@:LF ۙȔfc{ RH'[,NK90a |.xt৙Ȱ])&秂P1p9HyZ[-Íu󎴭.Xs_C 2_!Bep7* 3 uӌiUx!(WQj3y1Kt@~rTQ;yfKʏnꏡ bHT*k+w*M<p.J`/w ݚp1$0AP<-vSk.$ dpHımrXA-JavYOyݑ|g[ ݄Cy^teʮ|m1: wAh\nyNhO p U-isWˍt\ Y8w*BhUC'X/oGcrj#aÌ]Z- <@mA hH}pA"ZGkq0ʞyp|܀!3MD$a\UL.a,:i׃\t9؅B1pD0#!K}:Y(fHxU-!;piˋ4kȲ=Uyj"`oS(AJqmNM Ys`1H8Tٖރx%d;?t"BudٱN" gz x`:^as izѲ[G9L^QbU1%΋F)*< T_нrc6I͗ ')h!KQi1am*'pp+d97ކ| _,:qAG"p!j'ͼ$R6;M/hޕub{6[~G߫5t^pYtoX$󠬺usGLC\>ϒ˷Pq*@d5a~0u'5II81t S|_sNon{|{ۃVH.Ρqϲ3ٶS*A$u۳ؿAדZ]#j[$R7gq8:HOz=}+S6޵,#K Հgni 8iy_D]V Ug~1e^+ڸm*7}#Vu?пxĝnP$a;({t0tNYj]CkV.+ a[ɖvzTd0K\DG8tK u__pKt i;z3dȘR'-pXdH 3@1;fSYhH(Xd^ٹ.23TL5Ϝ;L0@ iwek77MA{6ԡ#_1X?z3I<.?P;KڹqFRކl9I{0 4WհZn{V><Fm!R3AboPנ-)P}Y[1U6^?!4p!\q;Qtrj&TD|u;x$^ի,"a}\7Q,IPĮRx]m@ zJhY&+0U;,/3 g 4O_eԷ>a3@~a0<VSCZDNQ}8,W+Eت =ܬIGpk ,w2mΗ8Rwe%GX&d|%8v;f>vYzTޞ<%IT뢋 ĨĨ耽펲 e r"=3iq[m_wZVmL\|d9k>؞Q: 0zZO(ic߭ is >9S5\r2cA퉪f>#E(گG!@$neڿWoUnuAz^SؙG$+$ A~C6擁+>CUgy8W6_G ԔiIf܃EgsC{CZNKjON+IBAFUttj gK'έdI$±,B$w&aRk4X𪚷UP:34xԲ"0Y(@ꌥxnH]&V3|TC KѽeoIL8c@:1* E$Sm+$&g>FlzmUBlѼ-()]:w*^#g'?lJfH W􏲹"CbO:/;Stbc1Re|OzxZ,riX'RIm (emgdOO:G) UO%s P(B5  PX#͂DzA8}mg6`|n@-'MuOǂVVʳs=""94P=eM@KدDɭS CW&lj=LuBNt( 3(4Tl0J$wρC7<ն"w\/J?a 09c'F7<:SrGƫAvlaW - "|bH&D7 k:NG5WgI( "=RSd?7[ BE+O KwnT) gte`M\D# NDj14:lJ ~z02bWQ = 2?ZxF`KVVXH}.[=hW*/,n+5 krl/[ OƋL6qZ{rQZ #W9@\aZɈnEAU)'L1JɲoF_Iܒ+iD-qil$82;1~cϊ &*2E\|r?WթG +Kec+ϛ 0|c ȨS3C]Qw&lGg-7Qs<4/oߐ4Xo\2|y9cnoll5̨i0<G[a<Ưv+KVC>b!'˛fhSh)枛C$!4aRkd?@2DXR׎`&0<%ajl?RP .jP -F|fg<2?m8xu+z lSAD .غiXY1?/vxG,R5eW.DȀ[K"șOJYB"=y[MXqA5ih-LR;9]*ZcX}?,#>4KĐ2zLs{Uajp{y["-nrc.Its@soI1-~^O`_F<` 8$:f'rZh́z)2(;A{[`9=kHH{HNɰE94qQgwX3cD"ewxVLf%2DɄ\Bn1WԯgjnZZ\KUpU;[On9$}b zn-KS6v|;,Y|Kݭ@!Xm].Op KT":܂) ?Ɣhp8at(@bvH8Goux Nڅ:OO @t_$zA*pY {R-2bs87<e1G.- กYfZ %e G7BU䵸M1?!O~A3l),9P-'?k-dӦ(󉚺FA~3Dq% IRĭȶc:a?9q!SFyEeqClW8//sHE&Vͨ g19Z6eTv Wḍ, (.f#9@G]Ik) lzGʴP*(b8]8 Κw> PU?}2C6'8+DRKs#*$Dub5K'2w1E.:K~ aM'o3<(Ze@#ֈ0Hڤ[lG̎OΞe35%*\2atXB azU*!0tW"IU$JlIyIliNOE `v/E?qK"dM:W e V{YDd[yq3x%6soa^:wCLOkZvQ\.3|eSsY} ?* MS,^Tp:^JzlZ 1o+?MU2R}k=1d~l_$2~P\ ~(-kVٶr/-Nu1r=gHRM}%sޙJ!UDPy ӽiQ42DA)SQET|TkiQ{%]zH9a LלZXUvڸї4&>mq}#DGxPF!{[ZZKK8M`HZ;Q2YWJ=/C(^n*[vΪ:[o#E+߇'|5Em 7ϘR@1-|˝ /g\s C8FD'E%ȯlyw4]$B8Ykۅ37{؀候]Vz4g@۰#tJTUH Xn|؛250~tҹ1δcFIifgv1@\ً8Po8HZg2fC?Yמ<"#W>~$:Ѫ$Pg}: ςr/ݒ" Rb)P{w^+ڜ0\]qn1\ėr#W.8JכsCETōwCxSxT2dktG{iM 7I!# EEܶ|ugZ:˭%bx])Bୃa Z %ϞL k33K%R_izo7wc)(n78eYL;cZ=$ HU-.>x,$̢qeӾ8]n '57v6ʨcӛA+3nyj!s E&Z-yn4`Ϡ\BPo.'"Ijl8I{l}~̍syQ:漡椚ICVp\$nߠD.7n3X5V.siEqIf@]n`}zC".׿^ l9I 7U%?vIkyI12A \[Z9m:`oyO:{yv̱}*hy na29ZII>f!ǡ}}g?*KPCU`~DCDN#dXpvfX>̴KR,d=[Ԭa6 wGS~G$pe2̾6.s=wu?w4ϳ%RÚORBP TN){^~=t Dei*ѕY =d. Hd8gHF ;/Dmբ4si.N:u%A3-Ǯ/#rbvxL^}uߩbs]թ̶r 9&xԨzmM9V^CB}FQӑEUe쥨n  SH"kPt*g*3AqVϒ듗 pB-`Ie1s-(.Zi"j:J p Eo@O?Wp:}IdqipVV3?06і:N^ͬA N1φ7'l.\c %1}oqz Ɂ9@bƧgI$'q|Z>ryf,aٚpH +$.ɹWfca7,?RkyX,i&Ҏ\~U3s!w[%"04P@r^GЦp~R j &: ymMf;{7IU1)XKo%҃pVl)KKɔN4f ⧀xfuK~aObμ%{t:tRhH~*|Y?bG֞q /+S,J6曕RFCpeUҵ|o(* Ud]y=wnlۨ2 qRֻ|Z&‹zK]W~qes1cv1|X]5>@ȑf8,?jᕟR40yT)/LY(9RETuD.\. -Qb/^1u]@ĝY_,o3ǻI+x wYޘƸ<+b4[ʈl5 at٣S9bV]\b"bVc3C^2r_Fva9V}G1VUN4aw=g7@ۗ#ӧz_6cw03Q~xhy `SMP? |ZSqe'j0ڤ W`s:#ۆhM=ᱪ$WDxRt2v$\zZ@Ca0J& F2rD@ 0LGkDb1-}RrwMVz{4b^?ێL{^xnZq=cn q$ hR(0˫7=`ϣaNKrP =zttPa&a;UEU=6CG84{ѝzj=b,$5ճ6n8;l` \" [m vb +z:JD ${% `' O" G^W\Kѱ֝_2Pެˁ~ a&}:cxUCm //  qYMSnF+j!hr)x>{/N#rW[đX-rc]hE+_q7d/2Q ^0-0;X:CLdR5IP4jX}/G`意vbjX~9a:[.

L~8X#ͽyqX'§JQ:LydB&鎓nJvey.Voq( 8OEˆa'uƩFt凢bwAG 燌y6\ (yIfim&G"M^%Wn}ޅm}xoi)ТCV:ė1%kFWHfOxYx)瑑lz4-Tdi䫌BaTprkεݣKOJrRdCnQLG5iCO/Zgzcʾ; \.%9u1OrҢ")3?:4HURt(R4PYma8@>'&Wkh"; h 5^Ix܀2wȋn]υ[n@P#*yY]CR"Id\dGO;+[F!M&XVݸ!y ,y4 !x+,VmCgn!_h8y=4VO? E˂OZ ϩ( ʅ! wv\-jvD/NZǔIM$ȋt6¨r{\0&tY Rs }**;vymKjW J'D!F߯K޴H?OS=b"$_uːƆo tO2v' *P/XPc~I}E:Vڤ-flTY}I`=2D}_N^5:_Rta@Vi0.[u~JD8=A5pH3O{>]^oC4/O{'McG@]YrC&N^ݿpӟ˛9.kMEQjQ.m!V\&b4{TԍZ9jZN>7' -|{Fo|q@R5K&]~SsZv*{^ͲaQ( z,PƟxp~_zk(^귥Y-̏ZA^(z Y8QKi6 lGh^Q\T,EA }t> a}D(caҧGwV?Lrk]pJ#n_[P5JPv s9XQGڇUvS̎KY~ĞEAA 2y n2  UXW/$ɔ|AF jkd3ʇzW;oeA^S-ST:&hK&4e6)qI>rHʺ 37h7t!ݡMniFp`2 {[yn6h3o"$` ްo{Vɻn^E4 sQ#!^]deJPah/n~l?^>ʨJ-n5d:nzCܺ@E=bQaSTc^55]7)ҘQD1^}nڥi$|Ėea{_Alnˬ"9 q'>pphX'A@a"u:U/}p_%+O!dދq(yx VmϩqFPķ ҳ9^1g]h'A#=C GOѶx=8kg`r;oX|LMh }:"dA!HIO#0kWauI0,+#oWs'jm*v, <儺yS)'=n{E=Xa`m|Ht7m<wA0.mSk. !;2cX8d2gDQ;K)z2}S3xvd ),—N^#]Fݢ .ڜ;gإю:I7,Y1ZʢncՑ]x{5"NGAIYzF}.eF ?c \ejM:yF@*(?WPơ iQb }W>fsJ pNN# [r{3E ހ$bmTucvacP |יAl >bj2Dvp.U!VݮX$<[6wR/&z\V/W5m!5\ڑd0E>Uٵ]xIlѧ+ {WXPg왰;8k^Lɭ3v!3%g3tzS?bIPUsk6[t:=Y)Hɟ&a{|U&&HYU.yoz(Y}a^29;|69~"7P&٢H~[cŁ笨B('5Zr &-EWc9eE+#%i z0K=xU[Ic 7v`NZ4WBXlehslýLt|K6[b|ׁ~3N9!Gf=yRjd#([!`^ [|CgX~f2'cc]Ls WׯCL_q.z;7:6eE 읺8Ey89<2EMC }WEyh5=!ӂM 375G`otDتMj .@h TfDT&I{%4X}l0@:YI5R=Եcy#()TF(Vj;>qs9&\Io? 9 / ?>Y:Fy~|#Ɍad !2:>[+bzZ.I|lKYLٱ >MЭMyyÎC/w!%! I-4 Ajm>/Nrpt{a,7ҙ36;OzPi]AE1&$TLޜ LRN>@X*!JoF{e`#1^KKQDu95ZkX‚(e\ۍ/k-6RqۖhT˂x9r4"GG,1^c}[6fV^ymP]N,57N('2LG_@\-[Zi梯U!cm{sȊ0no3jvX `8mDoeͭ)#xZ5֣+eRzȭh2նǯUz1QMuD~ C34kZ e#+G*߇[,Vmƀ!)Em%/R%J)C&p?S otWmn,i=J-$saȨ~'*A f»eDn+X f %zx Y4/(A>^PUwCq-G±^LjfQʏpE 1۸|y߽Ց5L,VkO-~-6On,qtaB0@OYy5%|Q=uN<cyTWB?f l{uel3B+; m46LۦX0X^oC[A!nf+hgwÃ$0q F2Z*QgB^ Z4n0>ɔ i7× K;y#Ӫ<^SaT|FA4[X<'zM :zӠ=IN^4Ѩ G^VGY!vx`>X%h)A|ꚰ:s/OeH!Qy[h 3)居@7o6'p(J6³x|`$pzfqP%]0o/3>v-R{kNDyYzri%512$~~{tu&{ҫE[X jߕ.thHwzK=LMk ]XLGR[t?7Ir_^P$rMЅH8; xB5ܵ(ΠPu Urw[%N繅!&gN *1@iD[Q4YA㢼rJ}ukye\سb m0{5lK+$3yb@U* ~dI]5fLҐuS|'a83x`_\dŘkL8'tI^\T8Q-J/MN R+vG&Rs]㳼pqHp6v޼3:habUjhk~9dX +EsEB&9@RV0s:fYT,<9@>g'SPOas|<;0ab &Y]Np_?]\e '$;=ޟ{V;-vIa_d<K{7W3uP0Mq+1 t-O\~BS$0ZDwĥ+(Q܈1*.2F`ߜN+.ϐL6-j}Fu? %}хoSCw*'w}(B}߉r-Fɪ0hm2.'/L=*oh'?,4qvz+D5 ([JxyoV9bGb?it1AFd:$(ne*L*,LcIu)dY;-[@֪s V5YO"̮l_X)1)qG Lwi e+=ize ByzHs6}w?|1;T;~pb%.114,4 .p ܺyqB;Po2PD z\BSu}e&x^ -N|-.װ%&N/ܦ)db&82 W;KV ot~76 fpjzoJuBgf A~f$*1xW x!rŜ ([։!*;z28Bvx[94SMiyN8[:wuƣ nJpWVn{u4Y?St,g4T͉|,6Ut6㇙|[j;TNæ{{YiDK8(4WڍZ^n[$I6 %epɯ (ݹ` )GĢ_:KT:`PlRpx}9m-r!Jj-( Hf0T1;_捛UyK#fF?'oyLv6j*xۮI}g1 hAkT<,XVr%aklf4 awq;rs ,z y]a0EVa<U;gHT^pWhaa)B+6coQ!ڙ|d vɆwUv"i7>=}ɖt2~n 6dםzݧO^7O#iH*lG CL$sK`п5ՌNopw]o sogXɥ=EfpIS9 iocoPtA>C憰J0u6*dcgmo㒙]~w^kiDzT ^mSѽLޭ Q⣆" } jRjR%V5~E{ mjmN[:{tTsIp J Q7+uuz81 [oO<8zX0E/𰴅Bǃyo7=޹s{KSa祈1GF:宝\njl88kSP^=@僧 T#ڤ!q6 &’Y)u0-k7ᣤ{5 Z0u@5LF,m޴xjڋ>|H+’jrrlHOrt$.}1 }y@e0DfI l7[iSeDjQI-g9?q-=m[.a.S5du&`qá]f 0~M.? KM d啎*T;C?-~u9?v[3l&nɪ24{T%= bmeD_ ?vYBz.oH*"-%m}<'\ΐ!A0"Facћ8P Z5:,A F>v1[Ѷ|gKwΗ?4Ü1cG_,9r2c;f4!z3)mJ~c5}">*Pd I"7}¿aR0>߰zؓX qN&w[j]X]MH ю+!:.4Fz7w [ϖ޿^?g7`v7h<^`j- &BB,Sz :? ڋ HJ&_Wr.[4ٷNh ?<68/<0C>$/}13'yD_.eEV 0ZN}:K񯨹㆛CN! ;~fM*P79_!zFү:xA>DU]a:CR@g M[u0H<੗KsVAF76P u'zuZ4Ok|+JU#d,8<l7;7ң e#XYgv$qMu=*B0niGKb4u\VpAզ.4QS/,Q@Ud;4[WK<yaC(=ɡ^ 4rO <^@BOq'=8]>`YYfm!ZOR^tmsCn/)p9`;}_mMKH##B5OpLցRpKf̬zS#LƗ}|$ W5o1jv:`;Ё?f,""?6͗+gCtE1j/Rz`!Z`ь7ju3(pP_ob߃-ߌ4ۼ֠ 0rO-K38&"UPq;Ed̨s`5 Tܾ#chlѨ}pQhFCٔST@A`1O@%OnTlZ8&H ʁ(x>X):֜_eW[0/殪Z_$v.Q,{* yK?0/]SCdcF$ЖgZ Mjwf)vL_P~39LaB֣mZsCl}j`lH65PP42{}M z'HhadƠԱ,wx7/0iPaXuȩ=F _׶E!ƽ+%4CJsO~iE)^MGD=!ĘTJ@9NQ?Us},Ӧ$šӸԢX:Ht_'aPg9WaN '5Ԕ~$\ҝ  wY$£&y.;? s9 <(-&nf-~^&(IWʀYIUxv7e%Y>da-r&v$F@r.[2>4h\B*$ؾͮdtō4`aT3wn\|<_X Qh%;Jdި }o]Jm ~cxݚ; >kB.,`L]-ÙKLu8BW6`if\$/Q+hRߏNlB12ζxmX:O =ϤJhAY! 9`?X/t^>-%8 m%n`2DtQR-+'`bȦ'09釡Fͯ0NW-a|Һ }SjP;Cj^pdK}^sµge-в&Cڑ9|Q#lKBI*_Y1cAM/JP*L6CY&P~ġ矅qVge_adNOa ?!}cy_qN-A" /Qؤ59b1YaHWYC, Gv/M2įI Dag&[\>w)['ovc[GgTaDLۧ K jɖ|0C1!?QA7FDu[2 _B\rY};s`(׶ ]*^,߰Ƙ>SmGn'yjQrYπ*ێ"|~s7Uqvz qĪ㰛jӶe ; BU⵳y.=h͇v3.2=}vb [VE3s^;8rfXv'PtjG]7~tHv0UԽ-/8*UuCn%uX|͞6]!h@hBE<_v“ɲUDj=V&Z* @8CWP7""G2F̅j{?d #l;p 6fgݖO}7I$pܮH,U1-vfXp[R\m&cMqx%mz#XLo mqE!M5ja s25RY){hF>Vf5LRSdhy0zӲbF0`kZm 2WKgR1N 7c8^2fV L 18+lL z;"Jᬶ1mP~qV1`{_SQP1{8>1DBhy(xZyġ'mVL%8W˿F !4a %(WQDGӽ2nj[0W{ :*h"W7ap '&N /e4Sb qV_Yt3f :@@+> }hPҊ "F5_ݣbI'p/Iϧ.YEbh l(W) '5r] Kۣh)^|Z#N6>8 yucy'xe6%..|,MšctNTF˳義kdF1|K-*\B8]owUyMUͼ_q6y:!{x5~/A)C:y~f!ߨLc2@%}߉m@* dolnU7Nq( h'v GH@ .fuAdt[ [ SUe`7A+vE4d*C .4r#Ҁ&q%cFw+QCEޮfXSWoS%5'S)P@=.>4iuhq(X ep!Q/*8s^sb +%p<8@#yz2|(ݖ):a$'~L'n Mߣ8 z4ŗBJDT_>7 L[6I^= ">ul>py34*x*64{ ۳ JÚzv' CA~񹃢 9m {g@hS*pedѕmׄ|y|`?#2mUxz=tl.T-<(ޠ֣6P9#KW/jh.MU)Qf]  lN6⾳#lr[624SCmhJtjDs. uW{;rHԏ/Y^{2?آS)(R,u,oyN 0 5j*z ["R˾N]s_n6+6xs^|ѝA/MV*v$GߢAt&}Ol yQQg?(6xhdH-VZZfVa\OJxy8%g'z#TZl#SXZ{c7gV0VɁ TUP>!y?P銛XYqRl߲k#2+;.@ǯ h>.˲҅$ .a$< ADD ׭bOL?LjVk.\b@OUlKrKE0FyGYXI.r8\,}A,4ҞL J}̌~QWrJ{ ŒތN.1C:ScX%:Q恨 9:>z{> 'm.ԊP8X(C0O9O8xQG?YJ`Pen?[SLH>V1_Iⁿvӻe ýh*1Wg,bI{ʎó|pTDВk4FKJ,>ZkQ1ֶ@7뇓b/n`9B jC fŤ5hQc 7NyKlk5~c_"I{@N\!<GЖpȠ,7'W9䒨^%kPދMY*͜8:U, wm:7H$R+z&[JV@^,2 +w#)\jj%L-wۄ,r-e2nĶIm?}} >PEp`.z#Zc xx_0a \}1 B"lbR7A"Ffͭo`oPcг8.݄aGwB maqWKs#OQlJY\ wPz$sJn1)MlC Tv9fXm$'\Cd񘭅8NV{}Oť(+j 2WgFT)hMuNh⦓,-ђX^5tOh9w~uJ܍մbyH1V;Sk9 ]|%+FM4W@ oh x)Jx`|v׎?$9:cˠlk stf Bwq]x~ͷEzh)g-QFi>>=Wd!ZOY)d3U\rvSyA}AnvG^:lZael=%988zag[cRf>' hҷ(w3+KӴQ%+?NJ`fa)V|T4 цNM-j@ sSl8} 7E0k~Dyn}8 ;god)(2iz\XY5'z1eo8k3삾`9z_DoxD|_-g?i,H^ZSm{kK)5"rBl?O_:[d~YП|z` YJT;J[:TiS O#8ôz긤t.Uź'{HH~.Dh soZQ|Uf25[_8Ѭ*yWQ۴85p^dȓ Ut)_F hiSKԵM(LtF>;#HGȪȓWO 蠨û8&GjMPJ]QۊTVo[*Td LRj0TegmI(+o0aE!E&/x~/ntC&M H  7yõc`"bbnnz*VP4򙩍q^gΔ\ 7#)65iiB*so³M;dx8" /CyvC{[B똒iDuUQܷg@&bA +0&-,wحIVdGQ6yqlX& u7 {׉_ =,R7H;xvAَ04Ԩ+=]2Jhw]B߶D[)\nE@,qMHQkI78|5*33߶K+HFup.&"=(}ϟ2dU*!›'U?נg/| κF~n\Ш!]A1%bk)j+ <.ֱV5 G+Vv1܇Kz} !=oZ=lꭊo6A=z`|67[rjjAp{[B",.\oNEI2#U\ pM>챞G 0F:TSZI$8NJDrYQb5U* -.}f Sڑf?W?a4d#lgOB_a.M=*HAĔI&zgR]+ũHR33w r|p r/7SHmT=?+@ԃSMZ7"^eJ'+qi\H"8TTMb#/Ga/ʚUNa?LHo25Φ>w[-M\G7bB㦞è V0FOƖnn@Gnڰ^Tfrrow0*=j!ygd('A@qdå3%@]Haq,NR;WE`^+]񔂙$2Q ; H8ɬE HM+A1](QX,53w4*cq4$42q =ѿ8{ACFwrQF SUz ّ걿{ - (MWľY9ERi7g`fu|iN]0Os=Df2_-uY$܃$*+bS]}=sMGB([mNNU?_P f%aY(_ u眯! E=, \۾.FLuex@l;s]$wj2E(^dkwr~O"J@0BJy)ʫy8X^dAr>pGWzl֢`skzh=+U p^ʂr謸M<M8]qb&Mgg,YrK](59ȭ[yH}fq UЯP髹h^k(~mt9$='y^@\Q*W#Eb"Kj~FXl\,Ic[AKͰHdnŎ$]5{v=Dh>id#4*gYН.w<н]hS}u濳e&Sϑ>%քK5X @st&o﫻gFdsd=U8x0旎>e7=4t v GwY"HGqA:Whٻ]Zaipj;4ꈄYOUZqӌ+KQ1-,B/˭|!5@׿ BYKՀc:5ŗUV cЍև(XS=uv+CI vZIyze$2- : 4W 伇a4 qTIO9fHqlXRm>-Dh}#vLt"q~݇ e,H"=z5`hœ \ļ z"Awۨ^ E|jlʁEO qSfN9ع&o0ޢ] 2xԝ >+&҃4Q1nhVu2N~+Da<_Il:I`]ܺWJd8ȸ 5/a:Ӗ{z'wΉk0ԭޘA5#"RZC[0B^ü12 [ ` t|s$)_I)f4g{YC2jsV_E JϹ&Ɵ{r+3a+O  ^ѵob3hS!s`d0%bRuMYsOum c͡gBظ~#( N,LyС13養-OB݁3-ԖMy)=?%9h}0]XPLKd[`:ᙘ5@QDu)ezf.Vڪ]DKRҹ*,4] .P0?Z+-q4hD(F)TukGn >$2nX"1\ {It*wsQk$6`T2\8ʮ׾wp;-.R b፧֗GΕ[҅IiԂqLUk qoDa?\? @Dd`ܸ9Z@w NTEYH$c?:Nn WI B7@W[)!bB7OUXJ˿5C m'q=^ҋ.VU;PLo;#OHPd- >rʨ:(s;E/^slXg5}*Bk[nJ [6m agjx->[Gk{@h~.ҳ3q8˼jS4j9 h:EZuXl[/t1 F-b= Nt䚴1;*@-Vo b62"Zi. σ :"1콩 *mz{^%D8[ Fa2EMu4Rsa P\tP_j@Sj^ g3Dg. umw-VJDip0!VHC&;"Mc?^߁jۖY~Ώɑjۊ֐9ZJI:t~3%kV4J7dXJ@wyUTK5TiOKIb)uuq? j֗}CɝxvH-lH6 d=Tuˤc&'kkoI-g@ʁ]2jfR:"fufgAG-[lG&AȣK!kLn,qW$jw87B ׾-RD 4<3}'q2a !=GZ){Wz>QF}]X)|bB"'esDU^-6կw,\5n\Js2 3;e*7bkܢ9x[[\*a&J8D^-F.ѧU8VhR/N4)>JΆTz?Ӡ[ x2btSK,.uND>? ~<-|BWqF!7X̼"wSZf=Y ѤemHنfzn^2"ش9HprJ |ERgWL ibXLE4ljl qL}*p)N q87"V Yg$)@d׳(Db<4VOFcu@}PO a+~5a`!^lI,˚W'h~hD锔Cif/Helۣ|A=`Uc/R\Ůrc-{ uAn Ymwf̏H,<_UmsXTp՗_?,OSMT?΍#Faa>H<ȑm+G3j.j82ݝeݠdT=3vȡy\ȏ^ŢFZ(b%SˣmG?0gTT`6f~`o fLcp(MF,ƑMQΖMp/.ĩ[TXhXT"wS̋Tkas+SAINjpz2OVS^SP- Nk7m5#Ǵk]+1otnՍYA,6}&s+ft~Xe)[g9*H}l7y4:CW?zbzMŴly;.%[J?;t͋7M]g;uÂ1nWHo0Fmo)gURW!(ȧIeRRɐ m+* )adc0$? . ֯2umx<+B+HH"BOyXlA@%Zb_G1']ᩃFW$3V0t'L@sNvGDO44\;^X!"ǻZI:ȜJ/zk3:k_OCad*-@p3,L%X8UzWnY&{^5Ol I]P+>8 [j)F[Ҳ:ѧ h!{6fJD,5,l&b TeS&Jf@:qbD%5l4ұKqe֜d%MX@ ,pJJ ##P3A~Ze* vBpt%^9^)B,Axb&N3} : S ;|9I{) tܽa# a12<{ɜw^`9m}b.|f.Sa0mCM:Zg;)_M#Jm(" yg/qwgpM]+0ZPzɫ$e$U+_da0mRLg`yi>/,gR~wc,#NDޞ,v$&xV~]Σ]i"~SFR 43?8*9:Xl32o7:GF?! l IOs+A_ퟒ㚴 ٥¯tA(~QPeP7Gh?gz[K mS OXUw\ %by]S_ksj%D#M&I53"% ;BW=XNsyeɶ|od_-iš:蘿Iލ<  aYEHmB5m ԙN֑2aj'x0'Q(S[;ʄR~ZugO`eTdtS6aȌm !xhwsx7 sK,z$i00 4b`o_Uo>@?yMh^{L*rBZ 3JPq- Te Vln5VELc$OTx:P"eC8 QM.3v;o'eˎmY%jBuD9I6p$QCB 4r7+gMEP8 b2_ q4x90z5c@{6/ PKz_+] s$(n51>hs#1 g2Dy v}mUqS7 vJ86>WÄ  ˍdKQ֡E e0=0mdqlEzPy2~|Η(>p0- X <]l7Cp٘O}ܔOl x#T J0H\(yeDzkmkqCBF sBջجĖ,Vu*ZA)tB~b'DhlYR$-D͎,'CdijbakD٥ vO,{OS3_NvВ1ujpY1^!FyHʣ`X]`@cG/bI l<``VAT[բdpӵcܒ,j&m)Ƀel kpeCìru.Y>!o?Md"v/6/lg2ޮći#q+qȟp*+\8\7lW_~_rsR[ƚ;t҅M[$|6 |X(C(~cʔ`|;kZ\Q V'i.]ؕP”{dE uGiHO=Hm@1 D+/PX:Sgn$M2"5c8 wHj*jIGQ# _C3mZ@D"7qHFnFaP!a dM-an )D_BJV|= (Ϲd\~Z//d́T cUf5ֆY d!0}Y܂\AsÒ]۝%YI׺H*PkH޽K}U)4m7Ch)Ѡe|xj!C%0AV$.MO, fp=oSX'p*/&~~;7 jwԈVK ϧjW ] vq,]w};׼ U_-<46`A&>2nL蝞Fv%Ӗx[q $KDIiqof} ySeS]3ܳp?^g4R/,uڪkvNIOp6ѭޗ+Kb2& 0.E9޳m_sJN&V@( 3{T$‘ |_Rp+6NlcgtR8Ƿ@&+$xZ"$khEq߅+Xy@eYMP <%Fò68G&dY3,sTQjnaQbQ[5wY[h¹#y ynj]I uk1gKԯ,/½}0RsȂ: LlY;:NSS;9:1IƳ;٤cd0' ӫ\:zʙu & xjFvP|W_J P)C ms6Gy:#jo|6ůP:]|tڌ,-Nn8)y1*GGPbm_ԽC*Hf1"5ȸWOnnT`7%BqFC_Z5 ̪&hyjVo" ])C&+uM(e-ɁH|oK[ҿӅƙᄊ=sxGE #U!CI3^UVh$##.ob&,k;ߞߋvM9EnJp #|﷤ *zAzD f韬A5\(;"0C`HKu- V2V^R;V5HI6}U\ gO:u@ ӖCÙfPӺө-l> @ F=Md&e) 3B: j+"~mew!4k1 XG h&ΘwdQD8-. F}Gۡ'ӄò)WҞLSg<0co֒qRNG 8M~x?lXl6%i(9%R2H8hGnp(>EjZ8kכ#g]SL1%>{ Q]acsm 8f^bJb)ftWrDY}BhнQHpЃGђ?lt&@ڕ}e*u#' f 1 =8t{wPs47z/\sM1 &)5b6%_ KDi^7o-ǀ&M\I޾" sXִ\nK.R_ n%mY'^? 1yͯjʭTDLsz(>Lj}gBeDbY|L a+V=]l$^YLkI DɡU1Wg*`dIמ٩Tf>dWo=rkN]Y!EZ?PqM 4vZa/#{nA7C,=U#HѻG+Vi^Z%P8vP =,(JM.2F\R6sTvYnI']+Q=x]AGmw"lr ַO'O3,J ])$x4̿p ׼[ϵe''bB}!StrS=9T+{=˿f͔1kf78[Xϭ8< OZjL)v<{ b{c(vL8h:%ubg:U [*5K1Nmxy|(0hɸ҉ DC˛@.;_潛Ұv$&Pcm#D 뱂rd̖8z?t|6ZBg"`92j< Rg<;iϵ1pd9!=X-NDp)>SlwS;fb|NlL~fg-_Cl%4"{F$˞|{"Kz*^=C s2^ZϡL Rĸ6qdm lF3Sݗ.: 7_oy;~뫹&od#m6o}QK~}wnb-;_U!"HJZVa3v96ŲD.R27ƹ^IZ|e$v{جi+g@J/ 3Ek m>g5òj">,EjRCoX#>I h%ͳa1il~< 1,rR0=IJpT ҲވEv%Xe&zAC;8ޓR"E+-Ŭ$VT ݶ(O1_VxĊq("~ksI=5- /MD'+Dݻ(1']uCmO3غĨ{_\&:DX^N{?3D7 Jުy6(ZBbj/l떪NcX~HE+8<H![U&@nHANnP(e" H:9K2^])!E͊~g^'[A2ʒɵxҠ0E_gvOt~Z!$:iJ DmeKAq.i6tsDLu^cZJ)!3ijl&rU2E?Wx?ݲ`AWtQaFfLw=`&v ;[\\-Jz[ma!I_9ޔ3+YK|gy "K߿@T>`RYܬ5oi\rց]a춃ETpb׃_z е&fnDZGCW1Dh@\s>h~W7՚C/l\yл0]yyĭF ;8o\B-D١r3%IFb'P/.fhmvQY X7q A{.uN q^*ЂڧZÒ2-g~@5n%/`5eF~WsM̾xrc/*_Z޲^="xɗ"xweJ]F)" 4vHU( J$CA wxgbk֢3X/!e&2fBՌMcO+qt7ց!D_?lᡨ^=_$ J8PBi6z}b ua9]9לĮ٘ňOk")R/8衎zqwbS!”=u?Wd)ܒ^~:|uhY=Y/K$]kxwTz!!+ t184w4Q:TQgdVy0Wh!%嶿/de |7RIe`;vvLZ\\hFBbAX)8[ êVh+a#~ #Jf԰nzrlbݮU:ʼǺq:iN{-&"ΣOdKşJ7#E騮H rv9poܞliNx\j@ 33~͗M[,_*j0OS2_ iA jC!= 8:u?:GcY9puZj7>p|0>1L9ޥugGbyS70-[4 y2Y@f. ̷ av$U'C^ѬXK&ịA̺YoTPmy&^0#2H<BAp'**tY?ki-.4pX%voo鑝q0;.훗ky2˦ Pn<ڲGj>1 `L>DJOؓ*vy(uKPֿ AX(0 DUeW,\۾g>E RP7>Z+BK(A/W6/^}8e8U/>XiVX( 4Cnab)v V@NAYhsAFI)~*~&cn<| ;7,wЅ1'>?i;?ʪR?l:I&!9hxlK ̇zĿR.G j%Tg 2E7YPн.Ն(ia<O|j.u&@4]6֤T^-}MY^" Oޡ=`jJ,V3_`Etpb|sVl\/fPL"OvZ>ײӍeީ!*ܺ,<FG_ %ϪCqJcκA4V$we,k9Snԭ:{>Źa] :l/eb 播eda AaP+S|7;$܉qECw8(w\Ro~طu"EI2u ÃEwϣA$̞ ]H#%n.PӶlIk]4y%Z:Iyz<^tG|QH8$d\ja`iqSW rNr`Q8N &!4/bV)8fܨ{!'rc;rQB&ѹSaVpؐ !xX5.B$AHǐ->^Itz0y},Éě x NsBFj`wK#sGlyyF<m4ΖBsn>_y߂ޟOl%v(uVI8FIڏq^߫ gMR@ͩqGZ`bI[~,dJu~Y;/EӘmW5srkW&0U$3߃|e?h<,mkn9uA%!9ϲ+S=R+,6[ž6+:VtF|RwNJ=|`#?Qb@\{Q^LTh$bBt$Hhº4*e6̵ Ro:hۜ wۊ![t~+7)J@|u>0Fk;Kcː-9wΣh RxTY4:x"Gm,[J$j.;*kgG*-?d;SriJTw rnqj{WAK[;CC䨵^E p6ܣۻktCR_X H:˚Q*DS~y1V}PX4o:~sOKA $4H詹q7\G!i՘(߯@SnO0cL4ڌfpOJ' dm i~cfGij;j>~7N3Zp:qL~vLd9 }hN {UC zs)<-N ~U`5VԌzǕ%Ew77M[Ke>O+ORE'? $] `_"Zyt%bVFy0ϧ=$ )~. VByUf/7 )9>7򢇅 ڮy*~*\e٬aPʼZY.uN^Zw8< u[D_ϝzV~f\ǹ35 gNaz:t/&򨙿,Ux6_>ces.Qd$Loĝ'ԽT~ȳwy?\n#M=G_^T_9 qHe/n֔^W2C/QS3n-Eu޽ y o@Jطb]oPΘt֙{>ݗ ɱKi*_k H  (Q]-kKmslXdId[:Cnx+QvwNMm6,[RRrp$^V.iWZYr+w+v! К z 6ZŁ-*ic-{RJy~ F0 ll. d/KEb3ߴvš[(Jl%3q&͎(^e۱v m*" ̂ݗt?}]sߖ'\ [<jvE؞$YC#DM<]Od-9gT qf+OaD;{'[ ӄƲKV xB04du'8 Y0bOkŚ¤*`[ي)Bl~Ro]<2 3 EuV^'u퓍A{ ^ap4_҃:D-m/RQf?,qsXO`H~ O.1 \xM'u6;UYn͟{DKxC;8 >;|սp)Ŗxi @|N{an@4r O=7̫KQ`v$O?)& Nv KQ3MyrCqdF bXU$ M8aTY ؝lS\(<ϘqnVw]3ԲjRsk?u{"M9Y?7h1BتXf0ɶ[LzMx ~.k(;قWh,T۬u;A&Çy=4 D@BiaR!]#v+/ ޽e33aYR&c *B,?3ݟ1GKz\ܛ}!QѰ9懸b6a![YbJ0I7\m']̧ZBLKGrZ+i?M?eA Vp иL47V';Knv^*uprWA'p|& (r׳+f4AsoVѬeupr*!Lz[f$4j6Jm"c$\Chd? 7SKXK2j}JI G>6*s_I!rrA/Pgnz|zOU /ӛno{yQBX,W,3zre9pAX'w-\5BcywFmûșS>@4iP %Ve?RF\P"y՝,#QbNj!%U~Lg#ߜ<C<9p/ǐ)@VVҷ*XqWpXHI) %WClM?o˳EC-jUM;n)֙-$5Wr~3۔4fEL)|=:T"`bߞD'am;+uKFmK'hYNšg U]lyYzۊX9B A-Dh{| OA{2-A%p +{K~Fw0k]LM%v%t5Cn/ Ԏ FG* '5%ҩ:/| | #mܝxViDG|뾀Xq:Ynʉ^2']rY#l/~UulkReD!ɛW A/"z=w}[p,;"O?U_i(h5 8~y2R¶T}Em2uzZmkA bU9ؙ9* >M!J-8 in>n!`i꠮{=(>6eA1ifI cX0eUH):K@dpyxN6X ;XbHۡ쇲XL\T"N}Б|<0e,dA o'q=>8{xvVp 3_-KDᙤlMIy/M(X `.U^72B(MFKZFME"3 %hu- 7mcW%\fxhlDc/](.J>ky#N@N0xԚh>'7(s/rUCKMp%s 3I ڌl60 Ž2} VBKQZDV6 .\x T͔Whr&W^Qv[H]8ӗjfSJTs*[\x;BΛO[Q Gj1S^m0M ĮdlyNzO,|j/r{0Lx` gy3y!(dҶ 5J9 W(XI;KؗT X *T2k{#eL8bNת{`*8hZ##&$(6=<7}Hhj |h'= K*rm)أz ;2ޞ2J.(W_MXa/ ʩX'aKwO~AArj|xإ.44èUwJd8/׀X ۂhvWR>/lstl.LVd%#Ǽӝ'm~f?WT3|!K ƙGɕrv| fã􉳗%FS.AUugAafȄUAbTQ6yקF+M;de4ǜZ'm-P/t 8'T !դ|¿Ĺ mTBXۘvLE}z$`b)JbPY ($C>iL( nZvonsr(GC RY%\ԁ^߽I $U ) -< a{~[HOH}pV![V abKyO yj ^-O=Ν-G Dh}^c_6u>=_pg' {$4;^ϬCGc 35 a|[qL{eQ5yAT 0׊_X%RE_JHM]+9ߚWF|VCzf][IܦK"{$puWPDP޲ Ts8sJ1eUÌSgp iD>?^e[1>%c ]gc) '%q3L\J])LF_cs{ 袢nqꭶ7~c=a5Ku!zސ~&o-> V2MDRb~;eZHE@bAcwO:p;nB&F}t-f;$a[V{ڌP$ j0#æn|-SH/g5Q{+"=@R/&Y+Hީټ⍰h#J.s|ߖpϗ/cBӈ4S7HЭAe1AZZeܹ_!eƗqRW@*p(9~UYMgCũS.˼mȧ0?Nk;.}Xi ofE 1Ņ+RhwjLؙ? d¬f7d &TB0F!| e"\N -:ߕ-T #ⴄE^۷_XAsoՔrek=c#:8(+mاb''"˿kwy#ioUdg3\1uc*QԹ4AA o$%4lΡii5^c]iQ 0w0Qn 5QM-,>?<񸤢t_'5LS* {H-~&,^ 4޻s `W2yH*Paʈ< .m>zd=xaF+| ҭeE | ~D/ԾBoN,和lg!?f;'y`OoI,ɣ֩9{N" DG .?Ћd&miZL})$wbgfh]KMQ&e9 B4lkR֑0 DRIlQ1[PԸ7eDCQi>T\Q޼JzOu+iPLhh鲦>qvm(CNwg==ԣh*s8Eʓ?{ L3&ۉrʺ,i{[b'kAt|@=0 :C"'d?oGHIgϫWݺ½ow P{x0[kJ^F>Q}D"Hyh/pcz ѯ2֡! ,j{) 8Oڥn6}Cu6Gr"{I(ZK2ɰַ0& O| -C#TeN8˽Wt!PEvDGrjewfcOg+I'IBjוqכUr?z~ٹw (,p:,' _[}^P,? Nk '66A&]ڈ.R@ڸZ'C%PaYUL*ǻߴT /t:ſa4=i%B,<9 g0aZD@ ]nh.7]@7(V.@5Q|?gĺv!Y*؆4ǁT5 <:-0yCF\ͯ᏶ _EX<ʦo/A2q~!0:!8̿8o t{w'O}G:sYS,h}돲ZMixÂ{KOjb|7HRżEH6ÊhםzE4W2kl,[i WZ(qt"kllCg 1! fmP-^SXQJKʬzrq+bp|Z2u/v' J,GQPg HBS|xjpdin{}[A cJчӇ33Ɂ?hͻUzyGT4܋okoervƀMBJ}ϸՑY25tSx`7M\5)8k<;+T8xugɯAAC, lA~[CLyz̭^5fAؘ@*{BThL5%_0fr7Lj9)מ`Q{H"䞨EP4ip}gL&lN\q=xq%Q:r5&/ mmC,?XFB(1*ru|Fo],Y$FۿtHK w~DԵuoJx~%h,mBrHFX:XC=TE5Pz=zQ3|u+^G-e(iOmʔ .MM̏q5 ,w߇t&I?]X|G_Y n$vx/r⾠9DL+ɺ'Auae*.Џsٳ\Ks@>#K'`ưɼ5F7gޭ^S;D#i+> K '*./[\tY&3.ȍ_L0^AȰLJ"ühZ[ov 8U8JWMTl_ Ҽ"s/Pv3cxVN޵G'k r-p8"N[}0 mWTjNC]ZjK.M3Xik2y2p_/+:YM^qŮcb361OK\/:  CV@*#T + Dǰ2ɗOƙR/v#E$r+׼p.1ld~ƈ~`'rIȓoNPW5n8k3dZ#͞ i::9qYP6vօ3S )#+ ;!ʯ[J4w`Odzi&q.~摺sCv8Q(k ~~wx޸NL e+r:F6Hy:=ߪ$8X]Dh jzR,% fo+%O* tv"Hĸ?m ' 9"퐢?]UXlK );x ~($!xY\ze>IY#ݿ(%$寙o^[}/-0ۘE?n^xG ^^ޚp )hk( O-"I:޻><]UIT٨#VP`~dn|Z4 gvb8FQ'ĩH~>z'W7=-̽|:.p<[XΠ?<]}(?mSUDZoJUN*,E?G ,p`ϾEĎt& eHuos)Ax@4 Y>&$tF.D1(70 줽Yum8[},"g$V3533*5 h~!rE=|[Fu_2l!J#YDJ1.?: y=e)(1nWJwFd_SZi7ݜNIZG}ߐZob7/}@er/ 9׆*^1lJZN7#>tĴCpJ,\@}apQW$?Pi8^h+jc 8\EP4 >_k@3_jEpϽ, 20ŸLwc9"ӽ8k,t\?^N &YS|HT i˜|3B ].Q8*OaVQϖB yHe4wJ$# YZ