sssd-dbus-2.5.1-2.el8 >  A `{U]+E1*3b41li%0ZZ ]}.'+-=}FX$ k\OQ@11'2zR(m\`GKakG#P5.Ԫbg6)NobHZum>`w84BbFnV)`U$_aԊRawo5_Ue,PCui٨2]򉼎I>v̎?iҔozij"G9G<+㧫em=y/ I`]L!N`VLt p M$^2( f+>ݟEid 5MamEzGhp ij~Iw ܳf+@IE[)z` {G݌ec;?o$:/ ٭Gq5,SoB02>\sX֯$`rX84e8dfb7aa5cc66bd17693b2501db209234fda314e676884d6830422886f2e1abd835379c1e11ac80b3477e4638bdeada9f6833d5C,`{U]Y GJa&A6=.xy_s,2#0>V+"o=9 /B@ȍ7\8Hsf/`FH*pBk?kd   8 3PV]t4 P l  2 h,H5p5 n5( 8 94:b>c?c@cGcHcPIcXcYc\c]c^dbf*dgzegfglgtgugvh wjDxj|yj*k\k`kfkCsssd-dbus2.5.12.el8The D-Bus responder of the SSSDProvides the D-Bus responder of the SSSD, called the InfoPipe, that allows the information from the SSSD to be transmitted over the system bus.` x86-01.mbox.centos.orgo CentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxx86_64 if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-ifp.service &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-ifp.service &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-ifp.service &>/dev/null || : fi%XK- ?AA큤A큤` ` ` ` ` ` ` ` `@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh cadesvuk2.5.1-2.el82.5.1-2.el8 org.freedesktop.sssd.infopipe.conf.build-ida563e2419886a7f829ca180b21a3e49715612542sssd-ifp.servicesssd_ifporg.freedesktop.sssd.infopipe.servicesssd-dbusCOPYINGsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gz/etc/dbus-1/system.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/a5//usr/lib/systemd/system//usr/libexec/sssd//usr/share/dbus-1/system-services//usr/share/licenses//usr/share/licenses/sssd-dbus//usr/share/man/ca/man5//usr/share/man/de/man5//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2x86_64-redhat-linux-gnuXML 1.0 document, ASCII textdirectoryASCII textELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, BuildID[sha1]=a563e2419886a7f829ca180b21a3e49715612542, strippedtroff or preprocessor input, UTF-8 Unicode text (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)*R)R%R RRRR+RR'RR RRRRR#RRRRR(RRRRR RRR RR R$RR!R"RR*R&R RRR/utf-8936be749eb9810f9221bbe56b26cad12898b968dcd9ccf86296a74ee3a2df60d?7zXZ !#,K] b2u Q{LQ >#M {wÅ{Osr($B?ҭ7Y& k5[asydh&̢n,<®%BQC}i1bs +GI6*3͈һtt}$]6ѩYzsV Bn ̢ҥhBkx,_NSV Mxî.쾟.pSᓿ)1p|+JfF&Y+$gFs4/X &4p@xiWX,(r.Eo^M_L Gw3Gf`ap /9"v~w,B-.]WeN[Ԣ;"c9*hqQl,߀\=Ziw)KFLr!䟚Yݺ26V)P".p9"n~ .`c[043|_;.?W69}io 7vO2] z"#n=VZr[|$n[M~Lv0(*^ie>e|q}fo=U$뇐>ibxG [j/NTukGoc?%NxmJOSO8rUL.%UKQŸgs,L񱽂zevlL0h]=( Ŏjn ds74jd[ݤ Hyh^FultGl= O/^3jR=ld5{ri3|t=~x8C|'6_M @/|9)IUBȯlsF;$;'`֢se\NT+.i(Dj|h/*_.Jm^x}Ѭ؎N5OFAB&qSڰ2cjlf!Bxq 3Cv N?WYl<,IAe襭%"*j^uA?~ jߧ_%ʤxl׃h:ޫM脸W_Lf/M8<6Xo&I ?x&[-QrIgC04>aGBevmעOeju$~u*p_oi F>۠l}k,Eia PtnQ̀|Z?3n]%\n!PH wAG@ vnמJ~1}޶l JKz_ꖓ5h#LM P8?O,j؞wQC`vCΛX-륅ljy*^8 {â}G UF4mxAl 84^$9wDzz.:o%P.=GXQh"(Lk?M:£KήfTNujkD{,h䖧p࠴?Wj^ij E!P6B N5 3[Q> Fof\:p3,d=R^@P QpMxI|,fך LT,UT\axi6n"<ƗJ5HSnS7ZNfiU@wb YkפwXxmt*vƜVCG X%b'bbH?JOh~EYՖ:#P0L.Qh߯P.`̥$g嶑Vd\C!uqD0V10جt!͆äAswkI 7ndʟby#tŋ!,aP.- 1THm + אbgnkJBO_Z% ÓC`$oa;4+miW8Ƕ .l "[t N#z9i6b-go=Vsy(Ls{D%k3X ttNcpQ+PvgucR x/ u\BTbٴ[c~ԋ<@[닻xkimAoV)4K@z2==xCXQ_N})Sz|s9a Į']qz&`!P8r9`6oԡ?~.7AI?h7y6)P /c bvyo=kJZ 8qi,=ABExY(Co'xsz0dwsιf} tS60dzgȟ e$Q׳Odj6 {ia kpbJ;eS6ϜcQvgËMCdr:630(/r1ZGx=f5941 ;[^BtkGt+ص xg{g䝬3n򃝮&0j:$S,Kܢ?dL,8aiވ˫3N9H7IU3D&+=,uJ.";TbS<])3Z:Zm &(`۟ظi? Rt &KF`^Y0BD8[^C '봲7qq{afo1"# va%>ǩp螗zs5~J4ռ>ݤdtxi)i^ $x+[g? ;ڬNg42pƐ)1a1nӒ*d! 3%C!;tQ3g۲!M:hZđ|F4`:tflX3И;Џ|UOW d+r#֡"3N!t;d~Tv[|ul2V)S@{S@RVS!/:md7}0̿_=;ާB:1z ,K@AH7#/icgkjR+iG&uMQl,yr›O \@+@pSx/VXc'q1?S?%"v۬pO$8/6$vP]N폾w4* ^ww\lOۛzQ&E(4C{KƨkyMr۷2*;+PO^E7}(CAW)sdh]}=_+y~ r}W!s"@*2K1 :F<[*9ك҉Cij%]6=Ke'NY{̚dFsljVhI DVIiQ}fXugK 0pO|Z/&t)u4q ᥤG#u'NGH-H@w3"#<ШʘI_.:Sum'&~@$-_d@ H{ep ^Oط)U*1JrC)6{~<WO~5xp~Ka܃haҬ{6ϲDRL ̎vxФ:r?l vB*8DC@oP'hO?\iߐ'T5LZyf6=3R=et_3$W.1n,8gC)Mdz,+|`5A%$k301^5F.#E\jԿ z'jV\K4yj:qC]px/O-{ެ-M{D:W8$F4'/bēsH/L7 #&Lr}ZPBj>S *TȕY_)h `4 žS{\֙ נO*d` \`) \%߈Xŝ zVBq,iL=Y =m$?Zءjo4䥎덕U]9!(Ѕ*K򔃅ȇΡ{2:K 1E~W뎋Ŷ ݺNߔj+)dZ3::ЌHz}v yծftyV-`zxT4'I6>['5U/ M$ԘGuج$%u'^d 7W,iv}C󊠜}g#w%iA>Bs(hVZW`1/U*b9wZ 8gEA&FoFFѿlktru[ 03Hm6R2݀06 ŝ t]t=б <}rİ3h8y<k陈]PVZ, r\3f3XICϾgF X+%:D`M{B! 5ڍ5 bc8J ˀso~p+% {PX0g/*Ol /,g/KQ HZD8-! k dַf+;Fr7ێ>i"`!ƅK&ZM^9N]76ѱJ(X>@w>`AZ2^G0,GZ_0ӥv} `rEnm7ӡ44*+Mo;:]m(U`ҩ@4-r7 +*A\AYGu{Ѳzfф\&;֋xXcXx^u lH?dVݙ+D0@.JtTO-4.Ɋ<$1ҋg?I*JWCoLAr/VLppZu}gEz7+or9Yje?UhWW'0^,k+S%)$ Yn(Ƥh;*eC5_V[B[jH!^4.xzL[~@ҕ%R!/Q)8iɉrJ dcv}#h3L>(+''%g61)@e|Ciьau;;nL=8^w'6XD1}_ fŪezO#y_*\gfr"KYINU,$QiYή)0#Je{_HR pH1O,QhiVlw3n\Z/V%(Xgb%-{!w>~K gh9q^iUu[MވJaR|["Ѷ,X83EŊd޾a~FqeU<c$_ oUKX#Iu+oMm^k2|Je>J~祸K9NddtwnvaZD~]!hvb9F{`opK}2Foɧ1$FZZ:7Kc@4hV- þ5;`u"T2E/Ԏ;FD8Ms;H }>W8 -ԻM*bxh# \Wtܛ1-DooKbQC/?wk<> g资ƾ hy;ovh-%k$ߖ:8ʼ-yʍ{.8ӰY8/$彔G&D&si]!甶Sj?ǧh+6%%x)VTf&H f'Q4K"=bh>@zcn0\jzcAPuf7q]r\(/^s/L=$00[HF8$M-6"8$o, fbEK8)([d&u%ri÷F_mHjv_{kP .c~P'6S^NA#w_xUخ:V;,` qȐ&;)Fߞ_)8{rm5lmk#f2#QȰ2]nmk0-X]PPg vȖz`w qvLrc]jS.'yW{ rvIaW^f/HwXW z!BD 2Rg{z~&Ϫ߸>* 0BU5s[U,Y ?REHOGf3i'|ꁋ_4w2}7[* [n=K~r&r-6iĤƐnK9nRki%Hnح*jE܊(R"HK e","[|ĨT1 :c/9gc=o,g /"VB01Ԧ6fgaJ@䭁g=sej_P+TWK-j) K߃N]+ 5IBwHV;nO3#x1]F"@-84ǟy# IQR,:`Y\zX ;ȫ}Bat5"搧yAB cځUB~1\YA% a1\{>0nC=mlz|~#8,%txFP4^S~\(]6I?#YY[MSթG꾔}17jZ^IaAYfzH GvA4y \Y=ڀRMc.e 9e:4X rFAFhE[jĆn#tM_mƈO3MN革̻J4%DTλƦRՓ2+lcJ#V`W :JnWDYg(xnb2 ` a䵐&(*^̀r`q|#F{Đo+ۭr{j |#*rrEKh׈gQזxE87!/rnq&H^> gy; :=0iOXir)44Ho `gd`IGdG6/{ԙ\.~\6Si##kq2W-kH.;VJlV8cEwJ,'=`p9!ƜT&QN-gaw62 %cmc/.H@pbQ9.1tox^.Gd˯k0@2+ aߚMЌ(8W_@2t=M#37G8\.,j t;C?`H.oc#^ViK#y҇.qR2ƃWjc?v3"~惑;DR&5~) jN1{:+me0Ց^ϸ RyL@%%"| u=6珠$@L%Qu0]n )ܘk! I8j%lp En kcD[XdjZ4Z ٯMW\FqGG?P$ g*m9+׊wO4y9NQkcYpM%l?HY6g$!-@Ѓ,S\M;afr/oezľV|oSSׄ&I*,ThڧռÏ{kvϞZEQp`_7F?xlF~a)ֆ;2]; bDzp0-u/tVu:Punjn*L1Uwf>26)i_p+Bi]+qG'Qm9zO$ پ)W#IK A B€؇w:V;\~-WYgBYpo j%&wWR`:K8R&NYQ}Ns$yb6vhM 7]q]mf|]Ct0!l Aj=/fhD-ys`Z ±ͻ<Б0$~D" ׽;6Ύ@LxY%;XU16TVv\_i룶%է>pΥ|H{(Li=l%Nv 句! >#\QSXړlINz O rQ"Fe2t͑[JTfß̰(eYx4uЮA͂OGD5&1)+VOm}4*#*v?Ǣo5C6ЦUYb7Z*xkYiZbHge:ejdCg(&& 7-۽fЎJ=*j:[e:ob%Jo.+j`v52hLlpuBvC4騒\ϑѧsUːŴ6y)\җ+1:rZvvL*15;n ]'^ϐث6PKR |dR啧e1sڞ;1B\m]WEaNޕQ7Z-' T<٤H`gN~?!s/ĝGkH;m- kd,KXqQ{^a&%씄 YK98W.v=''txluV w~2ؓ̂u%QV+EZ&oC]J$9VEb`1$ &4 Ys]E d6dT!߃АY$BdkWlwp7 '&dHL5+XZG^\>QʃgNԭ*mɀJuoչ4b*QGwؙ~y8<X7<65t}'D\|`DS2`7pYIe'OWNd_vu&K{) V ~)H-c9m's~&xJ\/.7adi]BڂLq]蕩;ѹnR0Yu=HAI3'BNFd(kTJL~opbzi*wR uE>sJLF`sQ3 Gi2U$?: 6FYGj xlI 犣4Ttw2S>ǹ%F_a.TiiDcd4~ܲGB&\ASdNM82+7۞. H:qb`,vqێ>BS!U-0sӸ/Jx9-kϢUT1/ȃRp¨UY Bqhߴ͓B8 _:FS%?U_{]zJ9[H0d!7UIHGl?AurzCeH@Px6=Qs"Ը~.HdCޓ'0|Ɣ≸-[\~U@Ҭ~%BEg{Yʼ)"泩>HV_r璊Ŕ ֥~;tW$ۇt>4 o+TpGH3h+Qep`[Libl!Oh'z5x궄N H&_xֻEYe|hќgSDhRV_&`~-"4M*Yכּ8+5m|Z"A !+9]nXVQ1#'/>Y4@H#[r+ɻz;[Nk.2@VYkq/pAƹ Țm!KgOȒd50"|DžY'Z$/]y5Чta.ٝ;%9Tc䬿! f*i&>z ӊDfcBPHeBeef_ìD2JebBp0iC.(B󀲆/9ʺK~sCH5+ӎ`ߡРsTf޸@IZ qUGQ$]K@ΪQA pNBZI@^bhZ)AR;#_y-LRp879϶o4MhB驂V; , N><]^0NgC~_2#-oubâ66Jh9e=gNO(H=x剐-C`4d EjG}p&s}j#)6 KР6RZ7iڥa*c9ҵ" :tO KeQ`ΰp΄o.A5R3iV2 k1{r}o)AX*6vHECfaXv@-GsH 0[*umRT-+S cx8O?,Ɯs=7K9OJ@1撲! >U4 lJ9_m{D1stiTņehP: Ȳ ;C@eތ X~2Vv _ ͜?6M V_;ƫ6?jWKDf{]Bm X#~V\8N+rjvE3=8ٙ|ޏ 6-CU֮esĘΏ66-,q&1s'Zvv fReM;%k0-Z|W=(hD["Ek ~[-󂫛\:LV@4 AEbEiZ.;ŏ)Ux"\,t~O].p{WwdS/,7pKوC@i9]@3#NϖD݆ ~YrE,eEjҕV&@97(o-utxت;752(4d!w^~ppEXq[,")dXG>ZC*Me~ْ;k, ”mtCOs6qz|h0]jhp62*7wCC/@D-C1A܊Gu牱 iR M|l90\z-V^+/]A83)u>\ާ3Cp-~,TfiIiD1eF*W\DK|i FM:")I62Eh8 Ft@wR2@Q9{߼|)m5 ˹iLT3cWn#քlHЦ//Szh72{*oNa7YrM`R|z꒿zg, !\xRE؎eN؅i*Y;T3oO slMx4@#GJX?4`zHtk#7"fGXQg]v+3^9ڱL]Lp*|?Q~&;mU?A3ITbr|;a_Y#6N}ʤqc P Or'duZuRT.kFyu>ZssugK'bbˆKKZ_Q S5:4 :onj* έS4vsa7S%1\J g͙o<=¡Ѵo`-:6֎"ybi$[y{<`:;h0dX?cղn'vW ϣu];5:\)}Q>E?;H٘)`6׌e@|r(^x)bٔ)12NQ5^K hama-]D5liP'a2"0 'o]O0L⍚N) GVu~&T>.P[Z jqxnzJ1p ^U6K\r`=x!6G^fkRadGws~H4 ܛShLFK$ܟsխHwlp(NXV` U y^ևG+׍OP8d(,%XZAra;$D 34+ػEx4w>+$(hն#~@U3 ژ +*.?xak4Iѷ7q}~DEː-٘yyWor7k$MCK dkػ^}=?O!8sAQЖU ͬIe|<dH"z)mˎ2 M_ƒRsSb' 8 9:i8 $ЬRÏH e6Dxtch IT(P{`eJ -Zx ),x {d*Fb@_VE:׳+^8i•řF%:O8/32OCA5~\C,鏼CfpȪ|Ryج=V< ;Y9zX_jȔ?QuĠx[5،I-hVjh5XQ>( E̩ T?ۀ PbײM&򔑯v,e*}c&DCsO뛎bfgcq5a"Ŝݢ'#u]0JN" H2Դ:@HQL#g$աOg+ nm3i*/%4Τlerڹ[SMIu wKMr9J5ƿbXaUWeB~%BH͍NQ*d+`@|9YcZr4 ݮDT*edw qă%vجnd玜 q+DqX |U3vmxQ jxh"+ 6Fr7&*"%:godΪvHk\.Β#8Ȥdw=dHƶ`0z5UB.aKeJ/ i41O=gyOyS@#u"s\AK9PDޜ(:"3nx`)jjUpEoe9 `]d+=N>M%IRt;~ L@w'[ a4}-3ʳm0S,cYC~A@%>6SѪ B a8/`[u:N{Av)=ec^bhX q` PT.RDI2Yyǘ3C|\m0}NJx`(4jJ39uP_},TV͸n)4=Rxy>z_uGw+\fl]6Cq٪E:[蝽`ebR+aV^]2`8Tk7b5J򆢶N%ds^mi( iۿߔ5Ń"ZJŠșVn{@J0*9M˫ߜ Xy`&@ t7@ "A-;!Hg݈2#~iـ *|_y'%i=Yi2ˉ왱cS. |Psi#Ek~rvw-Cz:Un)uP&dYa)OWʻa84z{vkum!Jc0wkED=ù5`X4!De:Q{rפ#BmR7 rg]'<^~; D1[6J[ѫĕEQjͤw!B}D^=r^5Nj4NFh7^<ז a1byT[ߊ앆?bh#)kָ>Ԫ900FxZr;;i舨k50$4ٴGDGŠp>.c;B A"#7F* K͌} ]18$zX~^VޚUZ3dqeg!Rk]]3#Ĝ*|PB.82>LmFDb&܃o r< I;.Ֆw=_@Ńp4؝EPQwmqܧeGU^;DƟ*RsSݠ7׀h>_B6l8C)d#"p⣹1%ς |6xTiOq78קڔ G;`B y?52Ͳ$ُnCyc! {`e9y.LƇW<ှTIzf͎݇<%oS3k-GN/ 4Ok(W!bܥ[ cK >Lct^HCYun,"3۩IޯrWϠPO#Ӆ:[PA wy >"ɷroW Tss ?^; I0Lm®G?I} &?j \B&ڠP?E&=̮CRq([1]JSmU;/f`%?qʠ4ve EFbK= ;} |!FMI~@ȼMاC듍Cև0e95IG2UTvutUἸvX{hy ? m2GueL^K[lH ĭDD򾝉(7&hݴ]d>+!nT@ɳ?|>,]i|p1@cƛwbv)7hQ/K疳60 iHj}luǫ"t:;jw釦\9o *(Q)?y[o7߯]FPT3$c4v}):Y[C~d36-p @*mU`բO >q&CvJtrq$1ҡU[ xsUucF;t  aA'"Dɾd8(kչ1 xx߀f[ QA8Tj&I 0!KT{3am>vk>/ANW2}`u.q3gxPuQЯV2%E Z $2$0;!WuF:úAJP{iXt mtGbj !IN̎j,!':AHB #lE4LW ,͔5I\1ǒ+x9-I?y[ܕXB|%-Tp׋u K>'K"iS8\cw0ny3?QD%ԞOJUK ܙjY~86EXp2Mr% C.?Xvh~rrbPůw֊^Rm|#Pa}>0i֭:9ead?B=0lVϊlJO5\#z-2<(/L1;o1ڲ*0!̨ŨU.9`P,GFG`& ^&1$Z4|쀹 ] Ocil6{OBZP(GjWu2P8=G҄{7_HlQj +s&(g|k' Mԉ4d: JU7[UGU`AՀui R὎.ikj9%Vo獎f{s:7BiD!t9~l!Z|$ɟyv2IZh">]#5lPn&Gb׭g;]ϮC8ޘ]CIzMer&\cٻٽ6S2ֽgLcM$ex tߤ-TK3ӃDЄ v8Vf nxiFε!me j|q$ $Vٌ 7zZ 7<'5#ļ$> O?Zi(>2 6uȓ&0m*()O`t^!>;wC NK:~.c0pRQZ> 캰i+e^&lN~TTi2({vvPlzk7t)9-W7BA+?<'ų~L%[ϕuhtqtPOpJ)|VFm+z3^5 ]]iQ 1F~__(7W5kUQw \̃k{a'L1yW5*Щ-l*\p$ ׫5B:UX2.qi{mC(HK]~Zс"_9#DjA)+#Փ\d:/:ED3S H>׮'-pW4cU y^i,?{^z##Y6*j$RqKڸ#Ŷ&4 sEZg>QcLZBГbjTL_s|ս٦ \=5`lƾ"{лUOrbP,CXxus-~x;lhB6uJ9$$ %S@]+PC=(bt8fmr@9TK 2Ϣa8ݰ$*`$Tit"z. Pz]tƜӔʖ")I5|B[DG;;>2u,n&a:."nLJK ˹ꈷ1!EYX+&&i]H}(3O2>W;_? Q6s _\}h:t]+_I}=έ@KV"R<9qƲ{puW#N2=faPʅ6^a])i7JcOuM't&IQT|%~7~U%TWg*۶Dz˯գNjȓ!\3Acw'@AJ,X@G|(/ WO Yɏy%h%n$:4:l谄i+$M L'.2OćoRf7  $G/ǣxˆXUB܉?nN}&AhXz.hqpUSQVL(p`#nVaPه4M EOYޑWdEA+0V Fr}(Ő@ޢ]32Va[@H"NEtٮ7|Zc\SrrylBpA>^?^.j^w ~43C  ޿-lu w@]c6U-^_?{IP/xK^~9%uJSL'g2fXlv %@/_QbψYAi'[ qY ~NGȁ+&,_J̭UY׸~[ݢ#E֣! ̘U ]sʇ=ɉN̋J"c<1eϮDʽ!S:gyGGɶeGgnz ǖ1z !p O` OphHO(Pef$l7մAAS#.Xj*bNjqJ f2 t([,NMIˏc.TR]=xQ1ށ'HVPLu83j,q}_miM@LA8%Vz׬ڿ3q)lD }f7UX/+S! }@w<#l3N+^ 9}i0=.&Wv1X]z t,<0P`E^Hw5 e_L ;a - }i֒;lCcp%8ׁmP("yl~g{^RK3Y] ?Fqfe? %w15g?˝EзMGKkNbVk0)209'җOI@Z_PmFk!ACg˨F2aÝ  ..呠'nBC3ݱ <5VU䘼1|\^ށ|EӞvsX)~J0YGˣcjIKa68䕫cH۳Q֤Q*`-U>zsBw# z<¶ʡ]w"F%ss9ӿ:uzKV쓼V9% OnA{)܇p ByR\4f 5O|7 0տmANb% 𬘦a r׉QҤxvr2YJ&3j@BAe-hM~ ?&s )LgmԤcwT"?)w9k>mj7'ddM# /&fˢ !O WXIj'|n͌Wk=Ţk)idO+x0|5‚ {ST\ 7Xzgei;Щ6=!ktC |4˄Ɖ;,AgA?z\bKxH 2'֞OcwOpɛF @^쇭ۣ,6ٴ]{(W~ܨYI6ޕ x0Hf[J*2[s7/B5ۖ_mdiUOP~[5;NQ_y_8N `'-EyŚSz=CXfF =<Eg~|_)6j'.h(2ډ);W*V].1ٳj*ur-og"-EOq B4>=6 n_8Ćc\kb+t|MM~27 ߮JΦ,gkAaR; -dHmy6SVqB9+x*eC N=lD,;E Gέ%=:~Fk:j*cn[EMw4S./٠hתT+<4.nG.cƜlF.-]c(}6 G O`GCz1w2P -a"m2oR(@)12mII*Eܗ XNme@lz6]G{ziUVxŁ_ڽ]x~B:zmT]vA6ؑ3OyאÇ5Ovv1 3h rFadgc}{\i.q]gv^q07G*im{}; %ҚG)؅q$12F[ʘMZ9M,[81O\'?!0Xr7ձۛvېh!I}t{fm@NE}4j9Eѐ\=ǻ$|ȇVmTqm&|*;l8+O1+ݬs[.ⓧ?YR!?Va10){JⲒ-..IUs`Z#!IbmY`81L":#s76uF"̱'naZy"kZ *gRNFђE_[dƝMmi էX2 t7& !HEIҵ`H|»;u%vǦͭ 9>lwdK] H1IGZ9jN뚥i"Uhgg ?@;DѲC>toT Tm`f\C&Ws[R,n4O1]YsCɾ>1ts P T+F!@Cknq"=//Xw=ʨ;y'zk2z`jsV2&ETKv"XN#)#X&R3֔B85ceR:$[`hQiko,\T9e t 7zK9֭A54RGUl7*c@dDZ#B&x=>y!f&Uwi3rJeӈ50泎!M4jA?!iqd3tP/M 5/ܐI4GKZ9ʐ+:Lgj FE0GSf'duֳ{~SHr4`0cL?I g7'L`=T-M  U?sGIM]/=̋EnG͂^{  o%A4]A/@ 8G`bbq>:^b\څYf̧<-IXX_u=lNp$9_!g9p6:pYOR Rn˂ס ꩨx?d&(Zc }8/9~2vm:c :ރ|EFn 1+kqjO`-ުߠI+/P<*f:m!Gxq,:XvRc)ܔ8f9gCvgY3#^K ˱X4cM1 ]S(`HAR!,Y<"{&[Zgc9mOJ]lkC\{'b!=1%qk%O~ "1=>yW9زw*ιW9u2cN7YWH̓?nr@u B܂IAuzwRzkМ–zl wywqXQb>n->p&$꒛Ĵd&y"׳'Vno 7)`l<",{bMI56)lh` 4AE /⊂ LcvWkV zIxj-?޴{M )rGK3F7-Y&uDsޙ2YH̪p^uȩ<x]U$΋ SKBeE*pD/H LGHKU2DkgS[- ȖIe|٘&Y_uz BO $j]h9#uV7W=r0 )|=Nj]:I`$~p@%<50c ՑS$S[T(ִ}ɗ\=+בeD T .FF;S46Wu4I:_R]v֝zqt1E@n,#Q Kw /qdWg7iϝVNh~.km!"\\(Kgka1lm^?C?@s;%mhð 'F}=Ums6 IN6v:r6rEk78:[>- /(u . 4lj6;>d s=^4ZseY[FbTΙ59e>BI6Z21}x"hRԟ4xc8dfhn -KutCΎHr96#+r'[|ZP]Oyn>jQWY IJouIr7 ?%|LTYC&=zO˩rݒܣDO&μjb=Lo@zn$׮K\{\=RC!\ -|}0!:"R}M" I+m),^:Cr=UG gqsgBz [ܷ]aJ0a%,R0N m.@}-2/\x5\0O >V$ِAW/L)(aN ⍍$K$g۬nXwUkdB }tCHfPj eJy0xv~'G&*n^c ](68}db8 ˈJLʣ74_|a#V5]"-ۅȘ;}FDo[x˻qIg m̬ٜxɼ,oz=ldHˮ|Ygs1S Dюuq`Ifn7)e@5ڌRmn<#M:U((#SZ= a(.%0XKdsnٹ_X"T6g{ϕ84IPd=B;A[ ᗐgZmMJN{wi-ke.HJddP 'glף8x}pvBX5x<U `44wO@ڌeF |/*_Ѷd ϕ3 l)laxM6SG2qQ*w r6nZJPyn4v{Zꑙ)~{ lQ=bP5ɑ AT^jImS`E.l:$@u [)y͹:R@ 5P&rR`AⵇD;ۋK -)^P9tK\=(L"jN۫YgY첁0dÜ@{ Uv㧶PQ;YpY43ɒ12-=D3_OREԞUٯ*a%oDYlGݸnVYe+!P4}lt$-UPfDݓJ) TE[r6t(;[ FA`|zn1zJ-r--Q6uuQ,JѾEr2BHl7pש6֍ddH ǬC*v֤XA)U4pnWf#lL`(kD'&ezK1AzYY\L8/?`GXK|J5TxoUpOeҀ~2vO= )ҺLc_$xu|%3Sֱ` ;%CE=UxS1WvVk .thJݳ+bHŃ񎍋E2Iʝ" wG|oq ns+L엹u Fy8$ *?ӎ0FT4me9A~ͩFN}×F$ys0r uD#ƌ{8淠i)A){g&YHN b 0}:-d9Ʊ4mZ/Sn/? m ]NJ },- ĨtK`LmaRypTx!xLE qݺY|Fk@?2kӟ~9շcb4>K6AhF~8nt1 Zڡ7d\VMv j=ѣ< sFD2c}Ʋ}leAcM7\v ,)hK9zd\ (/UJ?0yqWOl#a,ZUV^ pu@_9d>>/hf& rͶ4#zekЭATpyң%էLA;N+&mWyNjY]b#zŕowQNūkAjAzvހ\܎xB#Ln?T5 3JgbOSx%}'\)3Z¬}%T-7-q+%e޳ jÞa/GE 4=(`eE*v[t)5~sE ʀ9T^ٷ_i̬jd_cUQX2KgU]yTC g*1vne,W 3DIf J?zP{qֽX#N?՜|Q\O `U?3I7Y!uS\9o~rC$-WkOSuĞ(Pe;m*m'R<30;TpD:Y(=Hqt:{ـ&crorǍAȾg"%btLԁS=r4,&ʱ)U]!O`LfBcS ­φ}QD^ f)z~mCiX*ɄˀHX "dO.ڶ¬VC7S% IdDE]UMP rݥ?qxCOPq ,eϏ`p892^?Q!z- s0]mT F<n=#}M<ȷ>1OU/ Y%Oڸjq9:vệĿG$uYB'xNd^gc+NrP"z3_l"clЀ .ď`JbJM53׊y誱1:=EB`X1 )&U!izԺjFSO|y0͘j uVT^4w{ *<nԸdwshr;y !SgjHM;F׺"02[8q e|ؖM k‡6JdZǃTGibrqL\":pk짫eũ݀za[ؾtfӹipsYN,~H Kun E  S Qo0WF@b)%*=0o:8esH|߲03 ObRO+(U>mX@A[D 41 n'$#XcNZ{mbU6s cU@b풠-`/@fdცr*d[Z-z@3'7/)bz?£ҕb=`oFx-&os&aXgKl >>?{>!}Fuu4\1jK8I/i5G| bHʅ-δ"7léaXsjFkW9=p@r.my?\G}e^{ee֍oϖV,GAVIeGU(ԍ 1@&:$UT3.}Fx$y v^,%׉jTY !z\G>no;'|*c/ȧ\suU|߫PWCe5>XcFQg &7L׈ȭ!93O 012(cvn2DJoZ5'_}˽iv^澀UDsk*p/Ҝ_KIL2 &|@dlyJ f 2}Jۢc|jɉ],|PZh',FMiL /F)NFUOʌ/JE!X,ab!؏M$ Ȋd#s0ׯGH;_b5(E+&BX?)q!_8$a[KQVzL8 6$S? $ZR%-Q[ #0 Jz_|wCqvXJxw,Er:Y0o&$U(;~H9ZH cMxP;n4?i^EN\ֿqQԧZoXeޅ(?7G'm-t&U5 [*AϛȤ2gM!%8f~G(aE5tAFrvP.9t(/gG'3A@@f-UNsc:( =Ft5#u6^"FR-NZSl_uɳs$ w?7qz@z7$()xn1*Gr*o}{;w`_#ƫFog?G^<9+T 7!ǦFԜdD0p*[dA,/?ϓG&UЙ##epS7O|k n7~,OSBW`́P?T% ʆfNhi:_k Eh[#Zk)CMi(ÝҨ$2UcoY&n}m?xZ<8i5+ N X3eFwՒnJ<0H HIu~KLTtɼ{ߎ\u J-i+9~я D cX/M=5A2ڙ&([ [^+X5iD>5FݕUYEA݌P?鎒mnLM1˃e Zrw cgo6RKA${Kz:XU=U$Řw͹7@OM3hqU@ 0 mCۡbt9!c kg+!X Ln̛ `TF@pAkjIHvei0u#狼PQa5^jf޲}xC&3 qgdoD]_tܠΙȚSG7x w^Ԏu[UzEd# [q[qEãq] =\gJUyDrsf^غt~YfؙH=a.tk+æ`}1jkNu( [>0)Ȧ>Gv ߬X,$))m샯^4&Ǻᬐ0bO6'Q]iS4Jmze&g}XPޕr\:9#Kԫ(AEE\CuBP_X \FXT(Z`!}; -d3C[8+t= & W+"9pi]۹Na궰=~y#25NHb*Oz%7$&|, q Ӿ 1 V\觻hZB1{ $!6pPVdC1VhhzvthymhxO"pxI3-ȳkğiߏ3z'G⎘ӦFsvW5ʒ/^>,3lze,AI9~ h$YBMbٔSqe6緗f{sQt'e$7^]VN;է='zMAoڴQ6ԡz JE*~3wF:6e[f_ iGERKUf+)wmHټ<ٮ0M\tsyR}`=͇Y:3Z[Chwd! bM]7ު FXnZ )y(1]oC)c=X5g}8w!ۯm_PJ9O!Q} q?\>`_]8L Tu=HrHnwoB!r6`M|*? Zj ,KFEqEjf?l nNh@%h459ֹj i| |nʾL~Xhyt6By'Gyl؄+W.`YE0Hiێ DB!rvTf *7\&{ yQNOQT~|K޻AW,iӄ7R}ur!?2#-ƇK*Ry FfoWZ5ِ{C{ЯR+0Lc_˂DNA"pNEl=ۂH7)(UN9@%sZwBis(+Ӌ}An5@ uZi@*d@&A]ԈyDrYkـ:Uc(2 "vp|\Ii<,ɱfBvǃW*ʇ^I`˗.mх >\ז!ahaW`(l'gK ҹ9J-,KLx7mx;n $\m.8YJI-,ϵdd-v4ca9LȁRPHH; }QIti@Fa r@M_NHpIcz*ǣ"3Ț4pµ -ŃE털%4YMZ(.}z{l.6J̺m^mz|WIkPy0=kBհp~f0+Ͻe|:&=I/S6 4, Bwua )bjJP2mjps!6 JJffR(&vUk@_(ZD5,AL;337Z]aw-e9 (wI]X<øWs65rb]Xq }+/xmT.ㇲHHb}P{HRspe8Sj˶i"*Ubο+nb(qz{Fn7xϥ=oDbM~{6d)O/贈o"T֍"AVYq!;9-H#d7*X?QQ--eS tX{Wѿ٠mÿ3JMj -b liI4Lp?U JcA?X+e O$MjuCg*nu:9X)]O|fS>"ޕ9)[9 +nykZS @`jflY.g<{Q5XN.Wװb7P]72 lG^f&q,Z^ceGHMy fDM ('DI0`n&/DyJ._˦b#SdW MPg>q+ITsq$ZAcz~&a7]cxP m~w[>7O: !W5Dz! ]kPp" kN'ϓ'/вQt{t"z`:AmV'];hvX'!8givz vo8DI6׾q[̐eXtidNOh,~ 3nP.G x8_r!̜js䛼k9 d˗pNU3Y$ׂQ.66#~n*'T]b]ORa}(VE^jEK`+mB`OwLOˏ_ئ&rnUȇ-vJzjv|;F?kerg rOy=ȁ.@|8TSevPR߭m>`֮ta2?a$\Fo!^ ta'聍 H3CIo @:b?$ 8Shyd}EF$%Sb ǛơG4 0|]2=d^R=d$n|3&O OPw4On ,eB0$Ar,-fbszkIShɐ?DmZ7 }sam==읤{ 6™35ui9+M< &qz!gZ 9΂dn@] j)뼞)7Pg/-6BT RƐȽXpa T0z$RtR ̰X{*F82@* SWM\4OE9J`H eҥ"86pa܈x,{ )pohP~RLf$sr)5O${k7)B?WCP< a3%k4cwFe?Ώ]DŽlQPDuO'(2yKxvSMg գ##OCȄm9jF#Q|YdXwBjI cxɉښomsp6ʋŹfŨGQbUi\@Hv?)lUn4̧8oT+b&ܨΎeEwS =˭w8a D|#ziS [&W|vB\}LIr5!w7^`oԓCx0T/r$lOj~㐍sا `T۞ISg(0iPD)t1n6m[e~(#0O_dkn}L>ҩZͯ9[\l.BRЅA0$ qn%j4Sl:GCNH$SVvxp5 4?7J|ZxqdAAYjr`H#omWHj, cC#>~%dD+uީyn]Jy܀/q|d#nԀtA[m&y?-NX @ME͟oqɪ>W7tywۋh|ZH. sJ'Q]S!ނ4W˪8Z[*ws#ٰ̈`>@ Mҳt%Iټ>H lF-Pu'T#Ѕ5ɁCP F|SXnnHԶJˁx;Pi& K|%m3SEA!#pE=fܟZP^rDeXH5jpeʙGA..Kw^zz)"⭶+0Wuߛ% !^ތئ%̳lC)vy S3D4{K6 Qwؐ&'`"S]UlkN.py'֦&1"wOp05׻c̻xiial0cBzQvKh;Z_b@xUIh: S:>r~>4l(٫XWq; *9itbmb-1E9| vFf(?Q|UI,D91OI 7w59ϐhZWTNs3i/)16nfdK=SabCS-dd9H?ouÔ P?)6 ADԻP*<:̰Di/H8P{I/T/H ([js?{K,EoE}i.bp"d- Yt7(qeMPX%'2KqTf$I"@qn:(CDCX)n͈-)Q6:(G`^ 'b`Pv^¹7V+6 tlp,7v ^\^_O% O?6w. ܐ%|əTo*㱐 א|w!B Q⬈m0L?[*h7T|I36EgIt:r-ҕXufGqyt4pGE[]i.Q7W}oQ\__`H,& SCY@oP7*`;emP%$DuJZ;_O%h7;fkR{ y..UThs,ĩtVIJN4C:y'0Ŗfcc2O>bO#fdYq<PN+S~JG0b'wر΁%f,N}G|dd+M`K+>fyAWy&\&x7mA-#5|R.UqZ}+4G&R}\K3flD`#7ЯF FkUн!goh-"?=VsA3}{SG7J?<@?:5YY5L_ ІMH£e )\R^t 3τ?fbZm3^6K IABXQM  5ڿ^r v|M偤ߑ&)EiUIh3UL_{=1j]I U43K z ={`;)Zֆ @\ .siTO青,7{hӔ.#!J|@dN."jq~nZT<ii;L.u~p~xuuFi&ОCF6p㌕5%J !Jt" fSRiP$$$cn`+?]E=B, c81G'41K8G$q:D-DJý N] &5 Eu0WMtaԝj3h ihDP WO;Â]9+u=|k06ƔSU6I*}bUZ/.8+ 1Gɨ*gÞǬ6X.4]׺pZD%_*y @-'/H9OJ<_DsFz~{!d' V݉8aW! %5+itMe1ADd'#Wwͬsje=ޡBYҎ{S1Y %rw i:ؘ!ѮhGCm1˵#M.5gr9 SLVi}G+zkC88].5&4X!kQ;$j!H=4=k^WF"0UY'!'FF =A(Ynw ??v(X\۬jEowsC\UeC}uF Rs7+>euBLX+eEwf>VO&3[j} uHv-oDcOpPJxNX'+7fd䫨wm$ WOQk)mr^';|qhq7XnvPu g%X΃'%|VT"[Rb"2}OyoζtF |3mav8`4<ڡ"#K.Fb2{͆[f&)Sz>F9 ^HhϾ&,_ƆaPSDAßelf#[Ҭ;u,vA;v"S:20ikf1=i%¡aJ3h{3z`xVd:\aDž[jazr5?oΚZNyWQsHe *&7e} Zn?%~U +Yo,δiQ$S^޳+D˚]/X#oĔd&x:LE&l21GōKҘ6:Xk񨄳&h @ *ũC*+0wC\Hx6.ߐ3gz>W&mn 1EO8,IzbQc6}Dz$<КB1Dc+pC tPƝLmR\"H3y`qwD59Sq"Iz-^г}:0)d DY_ePٱ2rlN 9fwqTSwEx 9^3 uCM wGWSS̓,Qꏶ-\ +f9~١+r AhQ$xy!d,|M8}"XZ^HeŢ+cHf y# ŪSI,kb#\C ͭ{}E FS؂mԯgl1l4 X`2{ygҌM<"ֵsn@Z+Tm+*ig@Sٯ=ղTp6֥_aWz*{T!oڍ,K Gf,$YU'Tm*!0α}`UvB JoH.t稍sq2$ƈ'e%VJYdbDYGQt; Ӵ zZSQ4E(jհX߇o'4g;4;7輅ǐ\IIH}k\~Ӕ|Ve1Ѥ} QӇ~g@3 GyInZ #m̛䐏LR|UM>t~i7kS0ͬc+,Jm{D8tu}DTP}fjZ\(:b %xֿ.`Wkvbsd=Pa3"$uxlqS- `M>QdI7ԻSXhzCLXƘt5s=UiF񛌨ۂXa82$HQJ,g%@lPOd;&˫VPw۱R2˭}cM&״!Q/Լ*oK3Lui>B4X~K]iRWLj(ρ4yLX7SmnAQhy&Lx L/B,IW`y&Z( i{ j_-z Bok[8"b F&R~1quɐ.U(Nj8 1'HjtoPgzJ<#k)1œN/AQzKڀtL`;/uwajG&QыA\@*##up@R3H6!f=ZJj{LFIgK}S]5 =5kh%s*fiʐ8*SHlNt:l%=? `(_wȗ62aʗ"6=Wk#~kTTi-3:fCw .AjA5s4;ANhIPa5Q;Upjۃ7Ip| Xma<>,P?ț(74!۫#<*2g6CX9\e"͔?yϼB͔~*Ml`y.e|(98<}Ͼ֐M \gK81f+Wb$F[],ݪzv c4ʺ$+μd:8ui< l:Tp<:BsGe|}Ջ1XBA"V G]WƼj$yk_Bt#NeκFeq&[}Gx_ Tn):(+lHI=]a[v&MK2>$\НBVyL]>5s9Oa[7 *5 7/.L#5s'*ʖ'#w[~Gxj-Y7`i ƢC%k+@态p|u~YnsuP ;BQUhiiA1k]P;O|ܾ<EamA\$!T y7u]. ^ Җ)&v{%MZ3=z$Dg3(J>=V_StW9:3Au%X=} ]7lӍv/ri=FVkg.iQCc~ 8+shC2~՚B:=~?30Kk&Ўavؚ:;O~C -v !tf =|o]#u3 ?nHŊ/ LQ8u|GߘE0 sӃw"Њ8D5"TG蜐'[diƇkYz9?rIDIx&0iG< Ȗo|tr5AMbJԓqmju>FRh@ KݾchgDž/!|.ܠGJ"&ׯ=d;ީ||Z@&9Uy&j↟\9К+վk&L~)t8fM tkר%"VT}kXޅ/%9lUXaRH1Wx*u( 1hofHLUշ*-pש@XȆ##M.wJ io:b'yڱ>{ʐfI ;*w.Äaj+D^0/&_:\Qkq:2*m0!i#}clw]+( J\Rf Ͼ?J\s鄍:;ӐR C洿b-ɔjGI?ヰ@Y'3ZG#P7B" ތ7K<_/O/.."9؝H:~]RۂM};GYߴl<\&<]p;ٻJD7|C)ͻՠfQ>1`o-ܻ :V g2𽇈v+Fkn !xm=@HFP r̆=g\*{oP yf1|()/^j 6>TQWqGO;D>Pc^ĔKʝI`}AV=M |vUF m4O ]OIl(k!Mm{nEr05!;*0]Ju׈> P7XR[IX7>?ԦF:k*:bmpF.F6/p[z,v^cM^R. ,/1|IݫjVW~3ϭBqΐɘ>gi='pCF7u1~W~2w;Ʒ[~f3<9)H_s 'L 2DN0N$M&K̜gW9~])?ȶkdOJ`N,0~8n@6K:8棜mqJۜDڑ'-K9s\zE>]#=ɒǐ܂`fSVWw0u< Q'oU丮 ڟKH9܃hH$VXHý/*>QՅ>ԲVL##G)8B<ꊏp)+zdlK '<\F<i +N&(иG_dI/WIux"xɾ5HΒoswS $FҐ&o(*3(HqǫzQCI*fXS6xj!c wg@ar{&r>;2k0E >ePX|vԅ$jKTʅ1H紒I6O4QcP̚]dXC+)zcZ #F4LP b[iy*'H$טym#<*qd}>a|UB#)ln+߄؆ 7sD%}6 eY\Q~^CAF1 *˲dGsh:L10_n+CNE@WB5wVrx1#O(=-\$lɈaû;-F.@1y%#tҕXGΠ3}Q3&ݨ kZpr7hIi~޺:Hwfݻ\e-7BnT>)zиΗS(6@Q][{Fu^ lLr ́)HIF@1_9(ʿ器/Ω:u5j 㦪 ) n?Dw$20jOf?@ 2<&e~OQ, _Gjg HXo&7ʼ@jIwq g&EPVZ #RƖ+O8 Z9iitl{2LAČoB/T:/9ȋ$s6724].,X0Vp~ )7?1¦6 Pg-eafzRaPBOwG^Vюngd^>S0iL|A!#!@r8&Y[~.J#ʁu9yĸ`HJ8 'D-Di}] H[q-GaGIegDW\粼+e[8JUb~ l\H[ܿCAh\\hL>k2奉NzHLd*枛"$J,^'s`E5e֟u}fߐ)A|\Bdq!q|P2}ImnԐ.v59Sն(w.|M ۦ(XX#s۶0u Tbޒf|\n?/ +U%w|7W4>á a/P8LM8! . :qؘPmۣif< .-K R9oIZQ,!x)skuܳ'y+^Z Pu{?^  2Sp GueX%;(;!!K&-ޡ(ň;MA@QbS(*y $@e̊))nSG2ޯɜ3x{s=$(|XN1eEDe2N?^rR&RpYOAY l+HZPY'tr2wjvM{~KnL,GY0:mk*q\T#jm̏~jo,ԧ,TS?EnRr_C'c,We@L 0z[}TL*-,9Q^څ)jmoϽÍ\ -N7!X;i6'pU CC޾r|˶^PSH=e&pDيܪb2'Bz36C{u/y΅wHSR_WD-&u5c^r^AA/DAy\x i{+WkOfA}- {Δi]Y(@W(pv?P9 pBQ/+aCR> DS>B{xY*h( ;T4╓%{pH7K}ILe$2]"c\B&gE0sߝ.ǯi[e0 CPo#X K-ָO,q/X[XYd:5[sub#(ntAiHϴ 0['ij0F%̨0-dr}®+ k3JFZ/'4p ,F֎GY8`6ZWYt:8v; oÅ;g2y_[׿ Eshtd&gCvhC?z9=}׃Zf`+K.SGCz\*r|5bvs vGC1~iE 2aw1V{d%h;d$1 M|?@3F0#&rF6.D=~SkH c&Q509gHҫG)TAf24QV@tp]KNibǡR<4N8f4-f9"ZƼ Gv}Q'J( HH>0TtU}7n,.y~2j]McqT` [JرYdB؋=S7#{]+:rg+I/b$$7F@`e-vIJU6R1jyQN}Nt>o*B%"J4""b4C8_Qf.T<[Q;su9 |l5j %@&miVbfJjdv}n[5 ,< 刺&oMo7/6OUi1f.hȭlÿWcrsjAu ZψK Swe:&噞kgTZ|\O/u hYɍC!2 L5Ǝ:zQ:HV/wOn;N/qEaX|vGI)[榱|l8kݐ=~|L|Cʵ&R[ 9ݙ5[ &B%rF]m:CmU)'DS.bl|`E'йVl;2` KL8˵LhϖK^++i]^y \0R w3U *@}$+ħɦey1y >Rʱ9iMt 5鳛P% w cL f{P}5n#zeդ\bAc 0KEZm2d^`bUM`RG?S<1BgT3&^AW1#A7lѼycp4Ț^YN^Nf?\yZNO̭DC%̱/ F˵Jm{&HسbM6.aYԋpB AF9]C[Åd^&"˹_rD[I_"ym>ȡNKgC*-3~ƨv(b}iwR(h XEdRKž5?M&p^4lZ}3E3< m!Z kN4es'f,}C젂vWFiCGܛ|V/h߾<#:F!BedםϹ\S/d6K.x:*-v:f`P+Q$3-?ݴT#䑕^#bHf/т[hQ'jĬj =d ì?Mc y\(*V,бY3qKGb0V7Mׄ J毃yKk OfcyΎ[%D.֖*34ԏ.y墅Ld$Tq7#b 2O#7b3kD7nx:Ӂºo 7 `Ut7xGqOF(PYˊar_7;%.=f 0pE' Їno, oI@"vQqX0`kz. 4l)tJBs[5dzO_vJڦLWE2>Z•0'Ko1c;q37-LdHMܮn0^?ק7Eu| auQ"6VQ򬝂dڬ Z&6wOP(۫.KRoL%,ސj ր|gxk1MG)ֽCF1=id#,]~4m,K 7źC@ C1$nrL4D Rx8i0R<Թ*侮9Y?ՉE1^:=_fg-*$ )$E Y*I,Uzh+j`LitFZ gCg&p1&okHկ& B",!e @ xᳱ2l思&}Pg ~υ:;%}KJP]HOk% Ӗ&}E\UGoQ|p'DI\vV ](Ӛ>>p'1u?eC<*M^o`,ݔ@cNN.: EEd&ݢv=`5U-L|AG9 '޴8`S Ŵ`1CCRfqS(Nwu_heX0 Ap܎]z%pp\ +LBR<T1/$yx%gǓ!w!(\T7IH!Scn@NzXlď;d\1[1.ϱ:@h҂J,LLu@qTSOc @P{=_:P/c2hĢw3qo l'-m;G1DAm,O %U{9RI,6AՖHK`6-Z-8@ŠѧD㩟xq. ɤsx,FcY*93w9b$pw(w@6. ڋ[a *sD<^1\KeW͘O@yPlaf9̡$޴?q*h.VFV,)ޜ"i+3zU&*Dx,HuJ_HٶRj]6QH^ZwpPJ(u$qvv>4'?w3|u{L^ȉvin<Fe[l52B)ēxɷ1%D.mP]Z_@*;+]"FwbcFWk\-T,*f-/ 9h#•gQ8xʁ>oX56;J\ &G,I=3@5*EZh:;7 R3y- 0תM:'BQG* /cwخFhqrofg0&Z=BCʐU1g突iv onr}qlƼ"zR-bM4.Н!;f0C \7g('.igi`Έ5 m9d7"wԺΤ5^]'T [AzO}Welst|YafeX=SVza]2[`qEytz(H2?\[iLu`zyͧ@VMvKhţ+!BfdrM`t1BfjdnЭVs/{ݘ(P8mu37k!_`(cC9v"Ǜ(8J^9bؖ!!\C(u(j 澗>" ~]Of(ys% ^l j!|PyF(=3&1v4jA LglFnpHa:]oWYf7FCuKl>Lv3-|B9'RPm>=XQZ[An8Lrx-ekeN".ptp2Mwdr' .̜-k#4w3a{y0?QT/|BE: Ot+O<ΐN"!1Q/x p o6!pڈCǥ`)/m(pj|{-v-O-ǷAHz̧ &4Bq퍼T ܷ(ڬ,h!ƭw ijN O.Xr\^ҫuTZ'$iLOQrcCjE s/À8㋜g]8KuuS|3i>q/)ߪR>|Ol& I26Q>1)xV%Mh>7ͷ6J0`EZ0@06ɔy. $; P⠭Vw\Ƕc3>_eHD.ʶ(?B;z:MF1C߶Xu3Tk2bkUA;;@Yln6j+Mƈ|<8'CW:œOvsw:$?Ϳ!`φdǍƏ;r/^["g8^AmAD[U{`:h\{ !pK諯u !/wځJԟ9țm$6@VVK]ՓDW&2| V`$ۋ\yk}+\pt=L{WE d Я@cɼQ,WA|YԱ?gﺿZWR[ 7y=YsO=b1QπLWAϖ%n$ndQuU[ݹ ~L=sE789Viެm݊2a:R«2ԩrjVZ۱^= ꂹXjzсa|{ܐiV6uj?? i|"Z*>ǃ[jr#p՛6ˎ(bW/aXfAJ96^w0!k(pgXڔ[4a`DaX5%!_w'WO9g[Z~KYy~,hQX˥1,+1Dkcwy|M\h; ft /?VӬXAۿ ?F{^^x ULt:%}f"s4W8֍W0Vmv p[,n/-.Vyx -_6nSF.FIH-$ &OX/Lcxqt 7MHݤ;I0ǵӎf 1vm&>_Bu3㾚v#)cE*G&;9?ǟŽG_.YD-FmiZ){}6 r@^8 urfEѡ1!U-7;ɖXŠ_Fb)qġghjF sH$ 7ސc$֒j^ j fNJ3_繈Yl<+ i}y^[ԝoj.&_JPvol՜z;drكsE_Z7{ wY'&͝.ͬJ(Z\Q )E晊dmz%X*S9\'J?X#8WvMgJ2C),dƱp1}I=$5ÂDᄽxeL]Uq3cf"z[NN9>TmZD zjLit~9o\uP2Gx xFd.r3=2@w{B=rt>rK|7ն :hivUP1߸_c!RݱpQBq㊈oX~i.cB %x1L3m PB>r%j|p'"G9{u4sݹCߗkI1s_5̍4yM'oJEF<El鳙,R4dK qeׁ2ЮCLqcOư4C3'#%,,A5>)'V!!;s(ƻ{],' ` 8  *0_,]cWJ3y7lr#mސ&`ei1r9D ąWo| w \N#a%Qlfw@J_EuHubO9_]-׳->JQHd^_* GElf.:KČ;oIcO̫DI@ܹsP҂yûhdO$hJya睝T2EP}’Ɗ)Z*GҾYkG΂qw{:VT6 ҉-[n"vZ7`9Cޞ\zY"/g`.L78++ | HG$b&TN'9*ܧۖ ho̧,nĸ_=4WB!g=Is QnnI[x0R[@ZT3.y]A ㋕o-@Fdh2 (X`AO,V]&gumV}th,:XoHdv2rDt0]~Mn{煢9Z`0SP6ѝUAT/xu.nfb2D( 0/8ֵ@|h][{~+zG(!o6bZs'}dt;llHn0Mҙ|+Xᣥ>V$22 n#xtS/OA&|֒h6 2f(䚕 ܔmllWL `S%Ұ ѕE bqLMK  ]jX! WrN<Ϣ!!?2sPQ? #!ԓ۵ٔK FZ`m ?PY m4*x٪;JR봈}w"{:р"G$đ oCol7G>^y؉Iқuܟ.1.&TƚE[oJ! ?#<{"Qd|f5[gL>Б_fKR&y\l^MG6aʨ$ӏDpHiLĘQ ]%~Us3 lM=45Nq1$˚uzz"@^`6H<. D93 L-c-)>!=.,F$wjb7=]5/^=v?Juս_/AzF_R1yԊETZ@~QF2ŏ/1b ^R߽~CRE~t> 9qMbMk2Aoع\宒*ӤolXAÆ_RsQ^k?̞NSH坾s֖%ۈMm@ $G P(ܴdCb Z~">`4F9Uf;-fj}iߝGJ>񤢧]nsR;=чC;Ħe(z4ۙmaFs("WF}m`,*P|NŤQ5/oIYŵ$i3}f%9 j*., Dt 'DNMH%?l3ԸbAH UrR:0gO)AFpVpߕ⷇QOmao6 Xܢ1ړDQiAYģxG&ϻ`S/h$V֟riLyYpR0߻/*a&@\ ]1^7?=F[NqV݈}u3~?>pWMue8գ9o:z: +fɥ-R_=X'`dTՃF&@H P]T/dX"MY; nd+'u 2N~pPCPs7>7(w˲0m0z ywc`Ԃd ]膂M=4P~ LlbY;_cī+&>o;iuq0>@$`}) Lq]C!\f,享uS8'bpYPvBe8V^؆)=Zӑ,`Q"@ԥVEe䈊dtuFu'U&ќS UQcexj>]u0)(!GWesxlKLd@6/d +|E|1_&jhp-SX:Bt MZ9(׃1 ?+u dv,VyA'Xϕ ob pi;';ģ>`|/ڙ!z[:?^_ ]YGN8b"nΡBZsjKpxl="nR(<Ǹa~U@[\M8@ жSw :1\oߛdvy@,$Š9\,TτO2κ" !ܔ U#ЖWZ[d{b#63=^fIQD`H\ Zs][?U ![ܗm3]#..RѸgsXXFK'z㶅kmJOꉇܞu+I !|,D8>:fbS{ŜM*}'fD 0\+nni gb賑IHWn4f6_XBqFaX<8Q(+&`DL8N8DI,K L 2ƺkvA_}?Ty.80ZJ`,18Ҍ )s8w1#kL.a5$~ziqkGW^- nf#Y6jBDWv+xjzr 2,`RC_֍r( XSȰ!*'h|ah~eg8V߼ "Gמ4!+ ;1P <[t+GFZar82Hhs%-i6`30!sUrdc^M?Rd8!B({@)O9SW̝uIH폨hg @ȑ[ۣH+t1F^{/ B MZDXzfXWRŔPf\[~'F팜ʖyRSxaYqZ6%~l-p>sXuR=e.Rl`n@ :qΆdb8A=S 25UHbi 8ȀH"2Yr:u||U&:vSqگqfX |+"@N](t-ѹri|;T\$m7XV"tZrs?&OD @ z02d!UӼgU09X,?;7XM#)ͫ(,۶ [1|Y'!".>ptш };e,aqy=rir;#_ǒO%.}p⸐}{~§xw*~fG}Ӎ6_3ML[sUzܸRAZ191W %7&2$`QK- :TCM |2+F[vo-.6OX-{0r %6K1$dThd{Amaq|뿐lۈdz/ D\0mGkTOVsC2 &Ladm"]&ߛ=+Ak)7kd_Nx^V'J]kϏſY*WxT!.?ahGזǩl7bi2[i`[4nqUv!Ҧ9d}2D>5H\0Wwk =ebZρvi`7z": .nIɋ9?p?~ {%齝9VRJ)+%r >Ō:[ w#V'\ ^`7m5$"‹]v$َn{DzR׉fһw\{=dk|`'9+N6vBH, g lRi;sOߢX BJ:zCs- R0 7ѹq%/ CP aw40@#XBlӌ5V)&Qz6N"!{O=/ܠm;t=ߣ_%B\z%6>9{Ƽ'=D&P"eq͖pu5_ qDnvT`'}LbVы]8WɰP*l&)-G0 d8;L_YMo^bj^_҈ꮉܠwb #/^j;Cv"8 F hJ1pBc} rEzsr *!s\9(/*Mk9⃂J Z?疗&`{b.N  a>vه$帛V`-ޓԑ_j$ iTzPWS|cj]/%1˯ a==b1YL )5,+x8s4ZRw4c4m916}c:'K)[ߦ1W2y$#;old )[Ǿt;6L/m\vv%\Y#UBCwiH8$Ԭ*ߊzFmWLsqɂE־[:) xCj*L r\ދn㢣4nҨo͑PǚiK WB/:ӂhQũWMp9zVyRjSm"خv[|LLH?/ jr\\_F_PYRjM02/2ms ƿ6yGt#K5%e_S ~jDZIu:!7M[K #<ݵ4[Cs3;.H ϝuRܭ2/R5B\Xs1y}iT2U w+.Km?/5OHe˹.Q)'דWmY!W92SPz #kLSs"Ug>f+XB?_%L96ć25;cM@%R ^b.̠WQkA`F;]^5#~3 }JpS-J1}IN;!~8aᕹZX[^'u])6@h)`# O\af*#ϧw Nogrē)nԵױZAj&EnnE/R TP"=,j&cB'a:;GZR\)Jlh >WWi^1*v5G+`vnm"y7gTW +lWO>_?f70K8Q9YxNL BvOyu5oZodGN@@Pyjv J(fgՇHGh"]EJrC~.3 K},? =EڇPm;ECAT{)e<3 v-r+fIMΆ aVPZGx㞳SYn9](d<ĜmlmE q$jw$7 1z@c/2N!lgZ#H"bBͅQ[>UK=deTJm@ "~e a=ҍ$ ddi./!staw5僔 *s20;2|sݾ+2I5 GO4Avc鐏;-F^p2TRx5wO}YWk뤆1ѶhbϙYfR]F?oDm#>9ZT(ȣ!EH!B5wHJB.3~V.1lQt`X<) \a~eɚ7nAJ, u%qza6q Kcfn 6>.8L') !h갬@у4AOaㆉ"Lh"r|d(j9Ȩ(@hx$ QY0ko]~IH J/$t;on&qiʐP%I%DWW}uSM ֌ayRB2,Q^;"^MI 65JVRדci%@C,z8W S)E8 5-wjDsF`+awr.pHHd_/{x])//Ubu18' U# mwv+(L_b"HKvՋ-uĠ { } D`܏ޅEBή)tkq\A]#10i/ꏶ>7Z:Jӏ^ =Qt MxU p{snp8񐡘os~6uaa clj5f2Q+3U&T a˛z ƻd4eai[]O92U.: aoL?UOf(c6@RxmU׺{50u=C:'ː=6l,޿,Mؿvy %^ÔNW__%zA35Z~{HZK7Eq>/(ɟoiɓIU#MLJ5F0W^*bkmɂ:*R.Pϖ*m/<%_Ivmۃ$_G~[uRGN[
&"|*f]1Gz;.C繉 ۪{)QvL^ߏ]zE?\;ScS)z~ 8į=*׽27 a`4pRgJ>d0a93e3!]HKn #=>ΑR](!g<kK+)c6?U!M89=,KRV/,F,A)JT1 <tt1sltB۽`lQ'ibtbqs*l'$&gazlD* ? Q.ijlڔM͟9 8Lkl+SMaĞ 6 6IdPxӋaT^&QIWef^%4 …I'/wt-T}Gy 󕫗1R7Q +jSp1mӻksb}IoDO~5 W$^H""h ܪ<ʓymkrK,8]~CxPxյk?DϮ:C!$6~P丑| ^d"Kj/V:5V%Q =u|Z ;ac~AfmIj^栰F.늤#u..d"P'n0T&jJ=[(V犦|P)<@Ol%Z0V,Q㠪z=UdFlFruƔL2%{bj)}Z. Ԧ7:UQ= ̮X+ {F^fQ^PU~NL"W;~: *zgShH6|YCl/l;sC4҉HGZQ &Xkx}~h څaL5G]#K6!Ou}kXZ7=>~ "X OaϚ]2 C~wGaZN2ڍ"Cu{V=:LJI!ρy&RF [ _:b1Ѓ 2"X9ݖH,ǘ_ؗ$\2R~>*t[X3-Di( x[ ̹.2挹Ǿ(oG;!e!7I~_zƌ| 6AڕBp(D? : bZm*X Rb{zs[.gty'B +EpH&o\pF5P䨜r`P@0)۷T0'PNݟd uQ_yBeuO;^]v S`iؠZ8=7i*m}{Kį0stq])CDK~-.\AaEXSA 5fNmH7X{F˥%N+ kM^: 9ߛ FyC|dFх[qa^斳Bҋ|mtbCe|zarØs@DE *@. ` m8Ւ=AOhk =׭G@KL =ȿ?8'_~눙Q:k_ÿTOTU.<#fqKVtC󭻆WnnGizH_?Yȩ3{] 掮15l0L S}Wq?GML}Q֝߃oTZI*ؽ!w؊Ld$xMĩVr-Q̤q?|a+؜E@H(fǬ=r^'Q\s4dχBzb@](ݐ7oǰHKq󪤙jt4gCIAq W\CzPSH^.=2AF-1bF宕NAֹ$V84:~Su6_bYͪ9 sA⫗K7فTpޏlWXkEnE ck{vV$ez`@g m=]WxEhf?8gQ1V.pһx Ʌ)Aj|4{G[}Q`_0o9`In7AH(*F*b)f_zӨޢjBd[sD9 k6QcbSDy ߇lX Q7ZFAǷ&HOVȧrQf83 Xa+~\ju&#+3 .S $$.emcӖ6Kgt4J~+!m0; e0y:Y+PlܴzVk5W "~0ׁKyPg|LExU%#L.n$LJj,F`!aq뜒Wɘ> F(%?a^7щZD X8Rfm\.T0 bX᠁+-ve2j!Tc-8,;nw;<4Jȹ[ -Cv.-7(NTi9Rc~R-1vfTh4uSd10xՌT&AƤC.2j(d"#V[~ 4_0x !ЇU|HqIJLA"؀0 >JhΒE0#a mȬ%ϻ^I Lچz?*C Gt7~K(߄D}^y0Bi!P(A9V:ı`S1 yǸłpw`:%* yj)NFToPor}u*O' ].l P" ^,Xqz7.I4 ɕGsG+[/.^vwNi>=a@t{)6?WܿC[=l 2pUd؀Cp/tE!@܀"$:'kg?$[j?a ; p 杬:2']b2iXn}ڹfko^C|L',$uwOl=-y*WMezPC:% S"]K Sw`݀wx]kv!V /k锒9DΫdez]Bfo~H.{p9u9Of,M95!ZEDϭY<VF/S@!4Ϭl7ɠ&oUkjA˲yD\hǭΩ.0b}pX=1k2mנǗڄ8KTEgYx)@q׬&{5顩M%Kf -4k|[YvhUq3_3" V@>$(.*Af?}W8uRɌ4]fN)qb![eCaAqz;Xq6+g #]qӀ;VswA]"U'lS: 7.o+Ndf[d 4#;3jRPz^Gqg.A4|֘=`QE1z?~w:n9TijْҧEa^U7YTِk1ō;]ָ;qw~KM^N;'`OX E;f7sW.tN:4Ez.:W:i7櫋@/'vbʳ77@~2 "d ,-e˻js{ZH ?d@@NFw%E#7LZ@FZ]Y +7" I]HW mʱ/X}:.>M7Q6_Z}*8 EtǤ$EH~-&]#zo1W sN-9pd4*Oızq+gZF"dN!qEWbfOPx8 0G Qq y*'t H{-DZLKG}{KfA_[|7sW@vw26" _xEJ^T#iIDrCN81o(} [BQ#HlaRdn:-*[cySg@ݓ_ ??d73G)t'J:W@<Ϡn`W4m.j3+nʮb *aNc YXVX97I6Xkd`֡%@QЛ-ǥ <`1]ph: sb_ ]cOg^lve'C=wa!:|RΪ1ɳ.-3HzT3a )m[r7C)2w]KA@*:xyc?epJh~!Il>| ֋CoƏOl:g?I{Lqhw ~I[I6"no? ԌjalJՒq~;!/%9;Q9IŠ_t-"l;Q:ajc"NM0a/^sYc Ɔb˱DaȤ^I ]wn6iCP$L/ɬ-Ma4's]=Hԃ9@Ɩwy4Dv)5?C-;3mb൒XDRhpgNZd4v>ѐA{Fk+Y5 Bq}Z9)s5U C0i?~٧}z˦_Hki8zC^=5b=_X_b*"095'FcKM!$޸+O]ԃ-?AF l:?\LH]$V7jL5K\.>@<uoyJ%`b^{fr`LfA\nªOMr˼/]fU{Q1 gPy@Ze6;bBHDk2Iy|DÅwٕ>!SyC.U(%ْ=!m‘lVe6ieNSqzӂ.3SgQf"be(0S1"KP+!R'gO aGZ4"{AhMf29%?MLY/q^G: U si̥D,LerH*FvT&jAe^/H0++GqkR`ޏ3a, ,v) ڳjT_lFqo1:Ƙ $jnߒ\M&GW"*SY9Wo=_hII`ĤK&]$D+ymVe #4_xz)J:-c080!E%'CvS+7pfyq?E{4Ⱦ /CG8!^EJ)Fry?+5`ӝ~li037?%GWgvjtE Q դt~Uv{IzfuLe54\\)[%4*4;j5oALJD:s237jw.Z)|Q,2"kg4}/sUDH}\ %tV*Hp Ʋ~RD^,U-Ǵe%-bI'Z`|<'h?S(K g9~FTZ:8MPyLI~;Hٴы]IWU V=Ē8ZP#-Wm 2{#af sW5>AW]7NU9:q}5WىEc؜. &{t$2JvED;#tw+Rr iQ\@IK m+B<%60槷FZ_t-1ZYdz(;$ ;Y /GN`TZ11`ne*c#F'ϭSNQonHŜt?2I8Hx/Kܵo'J;DxogԆ Ja7/gڏHx/2oź D+ л{g*(u^E&G?8MyŤ7Za2tu>xՆÌn>IJ.UwAİ |)QR\l4 %{3}1RX d̐Í#.!Eӯ:66[`^lbߨ92$H^M .cduOQ9EjVyJ ]rॄtԪٷlf޺8h 7z"ò}ٜ¸z q5Sw-)6j]&LIhn Kz@e6:V3E"\ۊש_[O^:m? LMwbt Í  ^HU:&yS:1$Uɺ+j -**w0wmf<&H:Oz΄wj{I1[cbEYj'%VMT#Cܔ c,\vpJC<&뚸 x,Ū iB_/!0e-v g((Mg/ @b `vpI/.kXg k2⏇Ϣ=\J 9={|g]fD üu4!+2[\/@haˉlNcܬFg@CL&ڇTnu;d'goT"~Y.EMo6lb5{$N30% -,^RmsFL0[p)Mhe-b =x.@W۬^'wgQNԞf7'޵@g9,r٧FX>-]) H|HaS V w&3:~=@bT_X?*S=$mLR-` /M~0|$^TG*?Mvj1HOeXD|]fp75n%#" -m 5ʽ ;0jpunIheG]CXp/BUHF+j"GFƉ뙻e\ qa~q]"1_ΗVu /GHVĂv;W_5{kv~[Ë5zsSe6C9f՜^HMpZvށ+뇾w~yM֋&bgSտE7u)/rB |gRz3pSMrӱӊG\ 5'p`Ɂ62yi cUPA@A0`W"1~->]F45d{W.1gr60*QWj@E(z>Dud|u&H\q1-[| 2(Mp0ŊV})ъK209m2?$QHrn앺XX0%U+dž4}*ȗ ~":9 XXX}G#Tk̊}\2!B4)$d\ U9*8 ("4U2q^ wQN@I|LanN# %\^hZG|J!°zֈʉީR/:\kQ'{5_E[gljгfEm1XAaff>yq%inp^qX1hƟ9%jdRM?J)03ݢ;˧YҖ[m)s"Q0e)J)kjOENL;\{g&ݬ nW{!Ѫ`h[Z?sr!wqVuF#/e=uk#z&]H Q.(2)4o^'E W\ݒtu&Hf&`j,!@N]6' %5S1,~G E;3#e@8{ªlp9}ځ`ƒZ.hsug,r $p`LrΧr`k WEQϺ{K-&6;{h&[alԮcx;Agy~ 08ՠZ:q9@h'C|>5Ev^Za\OeygX$Ҋ-wIuO]"0"/Ղ6 iFj+ThfjxVTiy@]v aԽ'4ҳk]:tU HEb'FŠ.=0@I=:葳zH2|1\ !İ[Sv@Od8H8kD!b/oPЩ,i{"i@n'[!r]:@%ln|~ڨOZWywZmɍ2 !E򻠖9PVR*x"i rg;QE'jԒͽqO,sHa53_K";D- -]xtDT PZg8{/| cya~B;BDXDn+]tMXUEw|t:ʢ w"g>J7s7p ;q×zg7I"  yoV6zcq(6 ]DLtrYPV~WppbAE/I,K#" 1_"NAMVz962hH}n+ $jfK.W`]Ly7pԔ -&<^B/w,әϙAK5=Rze`ٔ{v^ @ M<;g,)5XO=sK6:}c'.V;*4iZ$vASܬ碅(fcza?НDN770A7yKҹU `u'D//ln}a" ټS@mϝ~H=2|-)_[T|S赞uGsW%u02*q|!:rI<Վ$pI|jQQ@uQg7":5ޮCB&d#\M R/ %b`4-0gU=  nqQRjH Cj.Bq 5`62OHNdsniY], 5W)ڇn>Pc=['Dw_Dnyowy8 6wqe%%^f5i+$J3㡷{d4bèo%g6(f|'HEsB H*a2ͬXs h]I>DU>.ufYRw={ƶJkÍKfڳΡMh>qa 0p.1Rk:9%hl'L)[Ͻ "\z~txLӄc%LA2IFm֭"# O_3AW Xf %zWne-籯G.0QADbk ji~Hz#?T;!ĿR}YhI;Xjm~uyAߛW'E6l{v"xKi`^8|}WD\swmDWy*0g>I1fyNe\aܗ0'bMۥ$W߳6֮e3NyE 1S˛.wGo0O nuv88gsv,9ry}{*X {a%A"F'W޸.Wf(W[4'q&R A:C&٘f)e+Yom]>S'O_I=4 bCY8PDuu [M8Y<$]k-"Ό2kjd3Zq<ѤauqS8MsOĦEI^nʨa5wO&>,P\FZj\k*7w 1>Q]=\{1' Rm\(/˧$φWfR uMC0J7K+*υw+RW{fYZeIpR3 H[,xPGDmJaZnj%M[< o\9otgP!̙,A(/wN2`Ij2I|,h ?Bq(Bw${Ma_ åa~EV 4L4ڐKė4qu[t9%l4p!W`SBRV 7~5v G͞X4Hת=ou*YF[ӡa~dNF|Vi5Fcz a $Q;Nuۄ/`{i,:LKbl ̧O M {-RC::CPVƕr˺xM5Uyd([,I$nxOZA{ǙKHMkO0:(.|!Ҡ$]A.B UO`s꽗*ug0A+Z,Qy+Q9ځ唀([UA1WMKX䄌Y^Y>:ա%ET[O{.ۉ"9|ӬƟQDof?ѓBCp!1ߋpdEmb(Np8CYIWx cw;a[ [#tY=/TlAӘQ}M3֤nSS^Vx&ne-u:%Eiw ru pQKWpjM>?*&:EN!)+Y!e+gt_ֵXevq `P^ /l]zuajӁpX|S2[B RY΃ }=nYdZN 4g<5Nu8>jJiEU|8jW-r oYqnFP71fazQݿ=ZJEyt-ӓM` W[ Ȕ\jV{"&?5LGwS HJ8 w? k3yd2,_h;olZ1Q3_״E߻43],j-FNՌ‡z8C &\ƺ/¥o#/X.Il2ƪ2K'&KR}x4'v.Aۊ${Oo7G!kY_Lm sehSC^- )oy飘H\4~ ]dԗNry7uHdX~#'`dzH""H6n}Q8pl$<@xuNΝPjcG 6}wl5ѻ(i>1R3oZ:\zJuڹ w5${ Vhs}!$ hn\QΜI&neQ>ӁY抃j~bH@jsߜS9(nq,=Qǫ Y'4SBpSS>*R,򗪹ٿXz9_J(zxCvZY/ >NG=tfp_ Wf+઎ў'7nw;cta)Y2BЬ`+RnOb"G3_'P.{NbtA!8q KRԠxdbւ)9J-tP1R)޼PWe/;)H>ݴHJezT5#y8r?v\ U]sR~?~bO.{/u <;)!1@ϒ@'eRȎ@)0C~Wp.:5?1;7>N-@~unB$;!4VJ^7ݛl7e_!RM/ wQ"FؙjS$Wxk"j#BgK̋9ѥ42{|Cas Z-W!?ܽAtBClp7"SBukX<cGc3WtQ9 Q_õ^q iy9dLOW4@\3`PôMM뀖t*\֖N! &9d.kW?)Q6XC̦);l]2N_#ź2bЧ3‚Ώ0n@}MU~CD1qDfj@^+#̓Wn5knujx$ƶd眾+sIWIvw^݉x =NB ^R0 ۽jF@T 0f/8/ %gx\ҥNcu_'d3aV7O͟`26BF`ɋc; e 7e8,jEŷPaFs*.O)^&/8KMWѝṛO aOy~=M&i7./||*h /Ia_bǑhWlRʳ[85Qܦld 8yc}x4]'qA|Gd,ˎVP0[B\.{E7J%_Y吾'l^FJeYTǔvWgG.2 iRRi#VCOYUX;YZWM3#s HpsY35mͱJ;qfYGH<~?sʼnҤBJU߾g>Jf4@NWy\1p+̤TRk!5_Jq6 ï(Du~<[~jøm!*ųo9κ1)a/k ; Tƚ>iw[q#|jo5OYex6ةU9͓OP6IjzF]ewHrS,NȐjdUfb;AۂoӖ?JfɽP Y-]lٛ瓴g1Ӄg4i ⏬0>, nɊԓ,~zZ> j"4N3 C ukfHUf|/bl SYR6@W>qJE͞tgr\"#s|HdU7I^=`(#?6+@ 2ևc]فI$ OԯE=؈N˘s* O,^> LZ{)Õ=َj~%.qZ@ h^!; _\c ҩkf_'9`|.XX΢[>5ڑgS> 0v oNw/ԹAYu[:r}៚/%O#?.*)ۺŕr[qryS #Z^K0v(y\Kfx ܋NnZ f/LzvIax2Zw#Ĉy7y \%uH ?UO=xnBz WVu2DTHCԺ "!GS{ror i%cujuyg;KoXuFeJP6Q QuhB@'x/Թ5'2c4^:[<8PQs30[RD%IyAʕ wcP7'm~/p碒pr40V,qY!x#mQyTQͦk(gf \٩q@wzV2|iF>:R^Dw\Л36e۽aP%oDw C)8μ5uVN&2L@$1V1~ ao3X3Dm`~D(faFVh ~Wsͤ_Kkp"6U|*qZ7 cgRc>+ryH{SԶjPf;޽:b $`Sᖌ~4n\g^}ط/85h);(< ЋcDƒ5轟6sq5r[;>WUչ$-pғ-~(~DPc꿑Snu/V,L (xv!whEm ;pvAchop~B;ȿ m>⵩dX 84r&:J|i5~f>2'#ykNBWP9G-"@.)tԂpE7`TZ77l)l'>EG FILY[+v)1 $}[,4.mB ;r2y[B6 tIn><`|5y#A>^ICl SdXY^$4VJ(;rTvqaLUM""ܯc`nN'aUN\Bs5v9[lXf-yZy2֦$3gTaOg.Gw5rHbS 88Xl4EEu{YD F)&ql0Ȼܬ ZFRX*]ׄ{§j<%c#-kVu ۨ p%\ǵ7&_HCh 3&+˿Brf:2Np7󤴄6A[&FLcɽ4K]!`9]N9!B2 o 7H8R9.Kʳ]Q]A!=_0߲["ƕ~A}1P=MgUvei1g6!X~*~Zj[0n&jڷ7v͙;N olE/׶DAaoZMB/(Q֙nėZ<9ȅ+a]CZ/w-j& 'ۣ ij/ 1ܯO$BJoN1ono30{)BM>>Jv$"[BOBѡIYTG*A54Lt C؆MYT4w.A\lY8D@ĚeܘBt#U\/}0]i||CT:erNs+0P;q0>IMB1k3Req^ aA>UZ&n/腚~z,mN };Q1a ɺK}Qy`~jL&E$;M~H,y:ҖJ߹P? 0]e3?(^^^F-0f]G'רũ_`@hmvгcTKע;  r ?zv-c?d +P A[FW)}&5ٖp_v@o7h"1F%WCa8K^-MUK^ ঢrUoLAd=A^)>@ ^}J j3VYUҬ#&.7r72a QnQaNliRT6_۴7'N%'0nYau]v oR4$jo *3G -@&$p(KnvJZLjjhLql R]p{)lfLlyQWafcfW_[[ ۽ w{GUk Tafg0l} 83UqEpBQS+z8O}o#I _ IF8Ks/h&vm9K#H ޾;Pv-Ea&j7%r{qʬ3nU:jI asUQob(]@^.˶O-'&!~: NF;A#.ꧤ8: gu\,%\;Y3L>Oxi]a&- h{T] W27B{)7'rep RJstC&SU :R6^BE=Zʧ9Ժ qv06y C@݊}{r!2*!fcS׽1oZ:c˥Άģyz{ʗGMuZVHwc_bW+TSh U<=ob`\g`"2F$ ;x3C,Y-\77vNMpvOr*IL)|ZXmKQ=.~l%hn?EG*K$]LKJ)ū8uI3{1}t(ʪvJY!ͰD*@Wq( L^>b60*M}pG ke!O b7Fbtm4u+\sz[ş.ȫW~jS Vu#-T; SƮt6`z6H5S8ˌ@6P5ԖL`y U!l=,lUdwr[I`qI y ʪ@k '# 3MD(J bBV>o1\Y>Rقkpj;?fc t € S"}4jFר~;=I,+,%_mKA:Ťdd}:+K@sCAwgy%@GWΊ{קX'DGSv~av򽁺vK3'CmmKn a7:%E٫mw~R=?Gb[~%Doo Y}iq#uq}W`;zEb`5a'3aǥZLٺ+WSEP9@l?̍^tV+f˞55E:{",{KYL)|f$kkVi僲ǫ/{p=zYqAMgݳH<Ջ?`Fo9st kwnzUm9|R4NWtPx<s0˓fB9P``AU-لY L <]mڛ!Kdxi(&j3VbCVb&p} `kͦ0^-c7z?Yz]n،s "9}aW&Ym:=;<ڊ/?l͂bn)k DRK!ARlB2[Eٌ kRSpaSԀ2'"5O.ngP%9[p@.W1KZL 0؜<5jIYd(y zmۂdבfKt'dH2(;NRK"B;:<)sGJt.af!IHyҶgiߘo`!.lqKmv'7](*GH^򭹽-$!9Q*)M~HʂW[)a6\y٤FkW$dv6t<>Cju]X7yZsՔc@d*XEq+,:Shq އ<=>*_Qu\&d[Cڡ<[1;shTvxY*{b+L+`r19@_j ..Ew#ܘ:nvL&p1(ho0[fb2tY 1V$q+s)2+:5GIbۙo($6 ܱRbɥ˛%ʼ {vc!?;'%>A»:v~aΏW髧e]7ʹC}٥sW4:͐a@Y L܊ (^\u>f=7h;]lt1θl[`31Vz+I4^uZgBTwy/Z0sH#Ofz˧S1T{RU^Бg; t=?E+׶,j2xz,K ސ& Qz5sUiyx^-RK 2;g<7wmA5ł~KD:I{^?SbCh7 j##_OÞb9@B`LaN6{;t8tgG$YcJlLƙMTa)*[DP? yv,l2;!g-o) ?wC=VHq {rJ@3AnӀj;muYXͣW2&e`TH@ԄJL =?`˙6seJ%qӂ{OXr47 Jv!vzq"s1ǪG.Ư HMirO&=4q)`/]iꥬO<#9E2rh8s>dtwW}ڒm"1'P^gWPD"=F+ _$U8ƅ`RZE2mSq:`\7ma-!rbJ*94$ȴ>-`gjbq;I?;Q"#r>E%o2;B%6+#q1 LQouIx4rm:Q ?HQA5Rę$nZiXO3Hˮx78w ] ޡCr:4ɢ羐U˧;8_֓"Ŀ)>=B xrruXh(A??кo`5&ExQq_U}ͣ'܂̾8s/ H~n) $tdw7;yx}\-E6q:˷8W9#xcٺé<&Oa?Q_Uϖ/{71ߐ {ތ*F}1G"d(aH ‡QU:AE6E@߶mtuVN%wdWLzjA&e _`r.}?&@N˸/)2C%35 Vp/ńÂ`vЗs,B'#40^hC}ODI+AK(т[Qa=B,VC ZbcW$a$6eͷתM6MݼHt ) 6Lad#gpx/PmaV R1[qZ|*#Q; _w衸G:2 \*:ԫ׮>ǏQ٢bM\+:[x&<ӠZ MV,d#֫Ր^b陝+gRIM S0E/U[("쟭L=|ۘHB5c41w,o5ݺ;<Np\Py+whbd)<\XG}3w*^x2.Xb_D>ND=hHv.xDRl+5"8U;c$VD "_ dr͈IR,|.RV3K'3ܓcIj#Z?{ܬ_dNEۻ$ 8L*jF厩3P'.}Ə:dȱzB_l E&YxJ!;G^קjIUTjϢc? mC+U QNkxktrfMu~,=0TR|}hnJFTkN;EXfԖu?1 _>t%(Ogq>(n\{42kt? = /`L>xj7g! ~ g[j ~T¹Z:vW`@cӘ6 (Fwr''ZgꨳsK1I mcn/ke<`Q[\9ݰr,ҝ.J˚XOj6umFVe=#l`|%k"v9Qt稅#73SXn4]8eT<u$A6/T.u\kQpAZC>{8r%Gƥ3$UňNn2w%![wۯ<է(OѷdnS/'Kxabuh2u;gbjrXoCaHI5.܈⽭sEItym"f!ɯmaPyc3U2y`tqt^h_n +Hr1}vʬFGrU6ᩇwX?ՈQ6< zKdFC6RN)~\K2]4SAnG7WE/ĖtӏvqZԅ:yx*7x:nXfJ(fR sTe5k?OeYvuJ`nfvSn 3?kҠE̋"H, . @M==Y0”6߹% b|\8YVΜ`+B]O⏎/~T2E|_;ʋӯS]+FAI?9՘u\G_m#^:m2p(kSY [y#qHBR:vfP[hhv t!t+D7 J[\TGJ!4Bб([rWռScqʪ$3TuHP(%zi1rj 4dž%gYR{ה7Hs@6n@#"N\HߘzFSn8әpܘ0EmGGZ$]ɐ&YiJτZPɵLKԒXT{t ȘsTy V(xnq CtMMS|##-,Y}n>Ί6@/N/}od )Tjޡ9Mu*=tw4Sx4X6p5. ;^2&D(^8ev\GۖGR*z/3=*mi A^DxJa iDL L7*|*D LFs_9܍E:P9M gl/J)/BTNBWs/ !=#a>4*x_W 2{7+ص219?. J[x|yC(;{4 gY5֑ܟzÅ7 gS>żB/0&N%cTAFXb=r4;K}gGt1pf DB  E)SRqߖ9NU|w\68Gxĵ䫣;RyEuR':xOդ)EqdR?\v)s74*ΧvG'mEm+ gMY~O.8%K#$m7>8j+vI+Y PKjO ">[0tZ9])-auPB%teޜ$Xan$če`߂zY"(RT ${d S!\ ~02-pdhϙЯpcxB}%K9`|Q7Y2ڷ6Rhp#iE L.i?E_񇻬UoG"̷]^ \Jj2G^fSϓ"wz0lB&:+M\i6CiX`8KP`1ޔv$݅U!c7a~{k!~M8>@V)r`9kJiaanhɯ{NR%ȔLܝx4δy 6(ИzrګA͜^9wA,`~ `~ V"'z7W=ۣ.r0N `W" e@}ٺ#85~e8"FկПsF aZSP41 H5,*a~le'$ڸ؉Y7noV$#n~(຾|;\ybq,(pw%BQ™ D'agӯ^ӟX$N{dn*î~4ڷKZAl7$iK;}>!Β,[n0bjgkVͲ+sta;fV[]iaH Rsi gՌ 9&^/xb L)Xb3Q`c6C8U-]@$E=P.A-ݒkԤ|rCk[Χ%OmRc|[z_0"p jN<7 ?!r㭉E 3@ qLT;<}A\' H# [Ak`e oale%C9eg90!c, "9dp&Eo5nB2=my*P*ʏ\TG=Dƨ`='h9C1`I>ƃdUl4/t{rۻ6MU)Gʋ1]FN6+x,V[9o|s X6}2q|s>wj7UwsPӕ[?Vvʒ=0FIo G"(鲷M\ReFxTjD^ΞF|R (K;m@d&TN1{Hpg+JY2Z7X^?(΢ /*6$%qgϤkd "|.> ^\*1@C(1sϏ9DWW;׆ 4[VHhS!n}s4IC+SEV:ߘ@ {Čn/-i(娭Ur@:ᒈOĿcҊ;WP9/{dAtD}ޭ̺5O `7wnԠچ𰯦#uP._w3a-#r5vޒo1)d p"ij[pKt!=QZ&yz?3+TC0ks+D2&a[;h z_( "޿(-TL0Aѫ zrKu6JW9Hz+vm]yUZ~+=aHFw><3=U?d94bl_/*j]1m,U$,6.[|(qIŷ~=#l#Ymyl<7բkϞ [\.cy s*jq>B%0{\wDޠ\Nso7Vw^8hF!5*b hN)v@5|vk0PlOx*XJ͆ÝyQw2%kBPS\QZ$(上Z"ɪxbxKwk U4Kq_чmwu3Ȓ/v@%($`I^1ѱ Q!`~pu ;!kVEܢIDB6 ;K?2䬭j -7`RbĨO)#K?oi围jDkѿ86*3A x;Grg1± YRY*ttit=O3$H#h p@w=*lrMl{ 0\.Ebi?|kZ1@%be,e}NMqRX#]S]Gt: w&0L~aJMQep* "_.^t4V~ɧC]?i*2PߒpQRtSl-'!bP9GAH$*U,bU2y&IJB@˸7W~o v;I^"%Km}]x)KA+Jw-2A<$̭PO{)s:cz4doΒ"ޞ\0˕gZ=U0lRVʂx+\,\Z7̧O<TNG0Oſ3!=KWP ~Ͻ41$: kYXx<< 3B.ƈѵբuu䦨xE߆}HPgE!&(,$AGEMɉZcuڰ ~d9<{S]V%]@,_ <|7,2±CGe{SOdD2jٕz(gXq!M};M™~o0*ufJh, AJyޚOc0HF8-FK=v9 Ԡ`r$:d hEx.o.Oy'`M0~v<'d)R8J O T%9H=ݕ:h8O>}r1ȻX 5FwhC; h@oT/.AaaZa,90R#3Ӥ1r /=oo{ fsf0=31CAVc?"*o bE\G=G(gDRga;m|)ʉ^1+AVC@%U\ȥuKd|`&5~@8YɝrO к%FykMHwsr^yvLBUl6nIW7"s2+p},VeFZkaʑJb^ iA=*O5Y+@m|>G0TS@0HXo;݄t=x9bfWrl D>W:{G6ssjg5cb@Zȴ A*/tgzb~[hXDEsbšdykUMIMQ&@  7KpNnc|l0[A ]2<K@uN,`d=.eW~#{WmX{?+slq! ROo/=WbijW,UYHNg\m)~kї׮v*CtQCr7Hf 5S¼'#2&fَL] F&!#qZ`_hmo8d4$Qte%C:[Ŕ:c^U՟՚EbKmunN' L8tĘIooy92HF)2j\) {a-+jŦL@ReTbO ZɑcuD=|6 \YVv] [4Xշ^u#;K~Niކk 8N)s􀣫lidhH3Rՠ ԑTKvr{>'tgǪ;W?|)~\}U[a;[AO.~Xn-r7}j*`P[CMi]`1'YԪUS=޳HwlU.ݴp=1fr,R,`3>yI{j7&A)%9d-ApN|ù^"N^}ɺCuU\8HM}V[P~>U{BiW5[귭shW]TifOed+|ĭb#*:z eo|$i˒c)GoNsfxBE݆P5@QA33=٦vW7Xo-8t*j$hNdynGGÖ j`8U@_1^ "~1ޫ/Jy!ađVēS" d0> zt!wE_:qi_< Ǹ)]BOFB3At3B念? 19U7 p1st'Pot{u N().9 N#]bR8Ɵpth9\H}`0}WU%b A@F4v^G4N,o%tREp15<.r9juK?;^WB&otʮqבX7ɺ-v0yTq].:Io`]nggAT5(1VN DLf\$ey8Z+7{'4O  "A̙B-x0ұʟ*ʣW'c,VR"TU@QFr١7$8"jf[g.̆J龧#NiY";t#popX\OIzUkdPCqsϮo1~06#e &0%N2Gti L¯0T'Ȍ RgoJ D+xiw8Rmj n $ kF+wvv[\UD֝V:"aX}-.gX2'ӧ.ǀSZjBA>k;:#Ɣ+.dRUhWԭ8 !2"/%ݯz52dn0{kaaq`TYDsZ dpQdݦy~,ewgQ󹸑QLڑ+8h=Oiks)+* MaSP]451ʧ 9oeT~)ԧj疕!vkq5W[I>{3/~rJOEq}^ƫu4h(bxxksoQ(+ YDEB5!\ypV{څu]{^{J*D#Od6Yz=pg% jEA]9ي6/R|YKzks7j3'G6ް#S9. 2QzXknz٘ؤme$dn,j`*4duH'>E/3yF"+`[w]m2碥$.]"7"~& Q2P~$#390 *o^t 9¡~!ǽN؇›ha2*j'N;$u`쿉sRJWkF>%,`oNCBjwZz.`g [1w$Dv-a½BTnyo#Ⱥn=mRۼ v|=X<'SD]W1cW.udO]gX2íRd0 Q:[j/?n!OC~JHCD hlr_aE6 ßcP=.Ikz,5;&"TІylR%#Z;fHT ^1 p~cF;ʲW(Ц°9#^1ŪKC;L vl9x]1cfxsKE rғ֙H۔ gdpyP5_&[Ll:3mwI[bdC'qb̀ -<=Wwlz,,l.:I}UOt.z$f-8RfVNEcaƆ6ԏMTqU_-dyiX:6LMy+Ёt-846U@/tl5lc$(~.(\T)yUsP\>NƠJ6 A͠^j7K]B})˥Ɩa7  tZrcsn)Hڪq!M]jog_"x&*Xnx`9vb 3:chQO@̷Bx0ߜcڔh4,3 /r#\8pl[}FD(&}jvwZItXV昑W6^(#-Y$6ߟ$2PJ̃|?U8T]cvmXKHŔYg }"p_Ov–ѝJ)[QJGkJ9%t+|R27;:!7 7Mj֊8DMb ?⧹K.sO#w2ߏF\ Ӣ&~e_€Γ k39lYEj/Ѻ"K@ >mUC=SP ?!rVIՏhpP pe!AUȳ5* JXKg}$݋0oXEfgJ$@;2qFõGPE ꥚_Yg5#&U\#9ISĝm}LՃD t̵=$,[ YZ