sssd-dbus-2.5.2-2.el8 >  A aHU],a zځƗ{H`Nj QʦFרp6w.%*bEہjz%؜nˤA&fgQk)R98bعj:=~ B214JeDsΗN'#4#!_ +_e YBGw>bSf[xLaZmuf/jWq␊[5_n!2 ]B2o=QY4[e)IVH(d{gC&k]RM$ع*J:1%`~ nKY\{UN9r>xYL#SsOhKkyFi\b(s&#+ك+oAw^i$F0"rB [(k $BC(8_(b3{H̼Cxlİ% 98835d0290addcb82e1ddc852f214313df22a951b64dd5ae752145f4ee68100f454dbf0d83f11663380a8c1fb3158c2794bcae11GaHU]l>$IWmd=H9%Tmzt9ٜ2Ko9LLF~}L"?7'cسLؚztnoU:%P"~/ڤRM>seXBt2H,|Y]y|t* ГS@k*K:L>ɽ',H[E}"ciH ,'̶66:lkZ;'tb<䐺3McƍH%m/6`Up^?*D4y됚S0E94[z y)5 N8G_FVCiF=⚬SpBo ?od   8 3PV]t4 P l  2 h,H5p5 n5( 8 9<:b>fa?fi@fqGf|HfIfXgYg \g$]g\^hKbidjejfjljtkuk8vkpwmxmyn*nnno Csssd-dbus2.5.22.el8The D-Bus responder of the SSSDProvides the D-Bus responder of the SSSD, called the InfoPipe, that allows the information from the SSSD to be transmitted over the system bus.a{x86-02.mbox.centos.org3CentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxx86_64 if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-ifp.service &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-ifp.service &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-ifp.service &>/dev/null || : fi%hK. @AA큤A큤aIanananaLaOaIan`aDaDaDaDaD4601b3592d313effe1a70c44167775b06693dc9b72e7bebc718b6c9e8b094b8f09f028cd5ad8b15e0d13531d362fd4f515952a830f6c821442cb3f901cf292a91a3f16f6791be0c7c3bea890eeddf804a3d6f69310c229486859c073aea30a2fa2631eb70e5cdc8392c97e19924dc9aca4ddcf4b38a44ada079dbfd5f3b5c8738ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90348dc9e982dadf09cc867ad3698359d5f11f519898077eccb8cd45ef4992c0a680ad52fa60bfd0672688f6c75b9da4d97c33ba9e49b1e0acd8b511d6541c9e39c907e900fb443473166aa253ea718ae8d9efa6058bc5520d2ed92956cb36c89fe4a251dad11d05e00d3dfe0cf3d8d3d9288d783b1c7081982a8b5932a8288db75167bdf9210f51d09b3e067c73b253cfcb86597614961e6c232ff41009e9ba645../../../../usr/libexec/sssd/sssd_ifprootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.5.2-2.el8.src.rpmsssd-dbussssd-dbus(x86-64) @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shlibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.28)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.4()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdbus-1.so.3(LIBDBUS_1_3)(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.2.5)(64bit)libglib-2.0.so.0()(64bit)libifp_iface.so()(64bit)libini_config.so.5()(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd3.0.4-14.6.0-14.0-15.2-12.5.2-2.el84.14.3a@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh cadesvuk2.5.2-2.el82.5.2-2.el8 org.freedesktop.sssd.infopipe.conf.build-idf9353951d5ff51557cd32fc02b91fe9f510c3d20sssd-ifp.servicesssd_ifporg.freedesktop.sssd.infopipe.servicesssd-dbusCOPYINGsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gzsssd-ifp.5.gz/etc/dbus-1/system.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/f9//usr/lib/systemd/system//usr/libexec/sssd//usr/share/dbus-1/system-services//usr/share/licenses//usr/share/licenses/sssd-dbus//usr/share/man/ca/man5//usr/share/man/de/man5//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2x86_64-redhat-linux-gnuXML 1.0 document, ASCII textdirectoryASCII textELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, BuildID[sha1]=f9353951d5ff51557cd32fc02b91fe9f510c3d20, strippedtroff or preprocessor input, UTF-8 Unicode text (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)*R)R%R RRRR+RR'RR RRRRR#RRRRR(RRRRR RRR RR R$RR!R"RR*R&R RRR/utf-8cd1764a31d7420d0b30863ff70d6eab0a93e7947d0c586262ba93e906ee75345?7zXZ !#,c] b2u Q{LSGVqE=R~.AR6/ pYΥ:ڗU7xm343BbY!/?X.xWQu+l#zp@ez뜬 A6lkaɹ"Z`X4z;HlrT[8@{5 xQ!$:[=/_rON|mY*cՏz#\' {8f(iUtyZ,\Q;6|&[(\Ca Cչh{R jKK-ԋb9U-/10ү_]>B( UtLx|;󺩭9YZЁ%1&Y*]]1kX#^O/򞛴iv]W I_,^UApG\"Z07Fzb1䗲lhBEkT~^ZbBrw, s iwG`Of.’(23b @e]=pG_J+PTKO?ɵt;yeB Qf7*TI JE.`d"څO1䯘CwPB~cR9 ձ&SʟYrKψPآjG]z,¼(ۗP|5 h uf# w*~$ ?x԰A4nو,]$F;&PÔhN'3250M$ĶV5nq܄c^>N*~b!t LFr% `cλ:/#(ht"m O^ԲY in(G }]bJy7nU끂dAE!6rWH`^. y/gdL3_asP@i8swYB!"@+(]^]wP^4zKuy|Ưdo3mdwv{y [ yz?}2=PuwiGd{ęܾ"\yZf'axtϽ1J\߰L䤆ǽ-8dOI?D0<{ ƓЖ:A'P#!Z$-~Zdvmv;ώJNTNIH!Mz*;KHQݖZޣ g"MЎ3hAXF' 4ao#>D.]U/ޟ2w8~$S>_b[,B ,8ݘHsq$ْm5"mY)d-, _'B`[J 1]ݪ~z}`5Wj޽x9)o dc. @2ŒZq-fAhAT8]4:P 5ql@$t j RéƆtB㑕|1smN3Þjyأd"b!*2Ov&i4)pds%wwp&1(cA nuMbrd"No kгpН[,pGӝisLiΠ;άsʹ3@i0bcQ_޹Ŧc %W'w㠘ޡ }W"R C ~j{ Of/ph텧R8Fe>{hemJz~q] `3&h VrrXGR(yP֏_T,g_dZmR`.%樓8fTϐ*9|׺0? \c^7 e%ɑAkT Q3.ˠ6N7f@&GDi'Ri-V 虂\TofNq;tw9.D@2Kz5qʹw5F@t),eQp"2 t6[_\G`r\%oo.Yp6}̠X4"3Sʒ(f0dיMR"%dש3@T 3!@'~30^-:jzvz C^'#W Hvg2$MBǕ``0,řstZ,XA`=o!O ᩔMyWLI} `AV(~X5_,Dgݢ7,HMvH|P6^A//߮v(U-NiB}+%JR^'aIBث҅.孖@\Ζck@?W_OH ;ɚ1i 4lq#^A0a &vqV݀{3eFs W~.!OlTnCrٛ_yNVJ<(7?8rI굛RmeyW}`IDFdbD\<2BfbapSEFIG)l=ɾ~Ȓ=PHd5bc=5ihIsSul ZNn焾2]̓k+w :0O<&1͓\)MHZکϟ;?u*f) ?2\<; ȓ~ NW@Mo9P,D)(‰tzuB:eܑ˱\\wTՖZvaYe!ǣ^)>9+[Vpy/qܫxH]YWщnF35` C9ݾHLEkzw7 $ Pj56ӏL aXO.x>1O9Ed6I.ncr?4"n=U=a{9𵤷-c9\UO| t┉IӢKi1]mZ=0Mݾdxp'\M ~e妫>E݁* .a֏LEf|hdXER,񎛸O1_~w3<5J|!qfsIY^"7BX]4K&a$幒%)Zt!zK@SG;Qsk`q::1Da|o #X=ނI}oD_5XHBQ^fDߤ3LPaxc%ڟv;{VT} UӕZO¬S4*M.9E]6Y6_;zB8̷ VH']L;tQlcKFVV{D^fwkStyz)1\d5QuRBڃcSzXR\|?7dV~'E̹ef.I5GguhzÂy33 ,YG^HR@Ws7Z{[u-,dzؾ"fC<* b >,1-4W+V&F3.Nh&dvI:E%IfRL O?ɜ96׫W9T%ˢN8k^M`eIn3 sZ~^ck?7]Y>5+>MkGՙww I< zՓEz1-rOe\VaXSkslfh .O$jЫʘ#s˫f&Zn(p慺<1EbqJ,$IO71A GDTy;$騵B4'6ܛZ-~qI)RVu j!Z`S FB~G;SEk6[m'Zd,)+8 +ds^ v_4dڅqsY/b ,]bvgvFM7aIy7P1OEFGʶh f(8S.# V8eJD耗,+ֱ bng@E;xxSZ/‘';k%a"2T {Vғ uE,=rB>\v0qO[l-4O:8YU4lAk/KK8:y$E)idQ]2Q]vȐ. U,3ڱje^w j&qCYTRl}|AP-:z2s0Tht +B{ Q/M $+V e䐁/xDnŋ.//b>?,ֱ/3AI JELwJHN^_XF 8%_YO1aMu2n'EC<^b5>cըFf`'hjr ySAe)M2kM~FN6blO+۳-Z9vP|c/[twIlz]~Cv(;*& .:VX**Kw+uI6Yܓ9f)1-+?r&h Ua0XO'+`a`X kϒjLbes(sڴR]C*!4\}YAcj&lHVHI}^[7CpӃhk{Jې'\S 5/Y#?3=*]Ju;ɪ~:3;F#2M+CR.ũٛ9Y}VNx,{@"H%ߵR4v(Oŵvf,Y@zs`*bi`qW34TV@)+쑠v?JZCɼh2w l>aE/V܊9+5~d9.6OJAI>"םa^l-y>šFܤS3%sՅ] o X9)VuUn }NoJ,ڝQs&;4!mvU:PalWɦphz?{ Z)0I{G[]gXoi˥N [ o*b_Y]lg^|,f,i sc/cG$g*gYw|& L 'rj;GjY0K vP-g@T~:]wSPSjqa+PgFqv\jO ğ!b:|`t*y kw㘎Ur }K%? GfK*EbNIv7Ñ- Mn*&.eʸa. z) Y"9c~b vZMc<8ɪ3684^Rv+Yt[ IP[PG!^I2ΐ Da ~@֫.d[ !&ܴi#˱Р@QŃ<ƩljamG5N€/!պ&G38]-ptpBKJ1!'\dEԺC[I¥ist-]m)Ɯ:dx@,J%0-#2 G*/=W3ق9*?4Ie&e(SC2ӈ/H6D7\*iv߳=H4m4D^in&N@tQC5ݛffq["]= 6h$Ƞ\VјdwtD)TdMhS-GT99*nvĘd;\#ovҋHqA|Q\@bYmѹA!lPK쮱8LMEvR٥u@ 7dLvOa^﫣}WK!:2c:9o1t܌B-bmg( W"; Rytl'S5]/8A˅D0k/7OFu5fa,v5 y|sd9j#UHwAۡ0&h2).T@{Ӊ@_0Jt"$GVB5X.Pƭ^NN:j6@}kLʚ4S g~pVZ24B!s;X| aOLKֽ7o ! G3QZ=ppr u?c3@ǧZ٣3(m0a)v;Q:C]F5adÎ[@':k5ARB6`RU{%)3{zcw4Qs 7!QCdPG}~?.F`66ۜn4St,U(r Ż_Ύ>X5[.wnpÅvvV6K5>PW衘+#1PS~\4ؤi[!yL|m^)3?9m~s(";S12hfSq QLGt.#ar2?ԿT"}"DBx &;yٽDvyYE7|-mOZ݂Qy}`O?Q;㦒5;YtA5駆󔗛:d^ jW&]hQ9QC\<5cN]XhK28 9g#630ꂕWYU0ӶlG+D׼^f:(7[Ei6ߪ??x]Oo-32 :G&`3aYROeh nn;|W68}UU.(T[]}FkCZ/ b&.(D1R|$>n6h2)gC>f=c袚S@BSZP=;OA&++<94jz|̿ai;Qx˄ Y UB:Q^޴㱳2M"c3S8o(F&}+ʜaߴn)) i@b*tܹI(k? _`"3BG?^q^Nʒ O!4?i*T [ zsxJB|-$7D{E-%^xJX?j`>$ t#( S (.zrˋ'MpOʄ.A Т_xWXGrqұ vP c e"'se.DJ.^/#Jh0Z?4bʏZ] yTÌEdNp&p*)UsW|An; ڂy՝me >8+kU(ԻjN /,cjeAV Y3)j~^gwBɷx[8'8JNׯi7rHb@?Cޱ ?.^z.TmƄzMm%h+=-E6 U'р\ TeF[v?/9Rw2-GgĪ׍wJ/8Mz*fa n $Z7C\i'"E7@6r D+l?ETO5k$ANc2亃ⴉd0miʗ@ƶqO(B}d5($-l_:v (x{K/kBi_Af  )kTF(h=Jd/,v;!箜g2WDOno]ŴZ#"Q 2E͌x)hE)W?J|agx9ĹB 3 %1]^7=!|-23-aS0cÄ\ Tݘp0m1>%4_;Omb)Mn)UdᠳcgooQޏ] 9qUͿ.LLgr鸷ADbD;]_\EORTm[+ס>Ɗn27Q:.c>l)GeŴ@o_f*oϯDa_^ߴ NJgLi͝ʩX^|ǷȄ{p-zb\J2z/J{ղ&]dwvQ_ZmR ^uqebH >m.D|6rn"]6Z2aj^zt g%] RJELħpNj,}Gp_n-rU%θp'pbB$KLޙo/+_篘t9І3m'eI͓ eE;((a+3HnՄ9sQ$nԱ i'ԕT+Tۡf}?Ny?^uyqM)ipp*nG:)' >@1B_w}}!a 9ŭj5gnP!O6p1*oyșO'1f. 6q 'Dc Tua $BhʆXz$9e΅vLBގ#/i!P @^(_UCjWoq]n/QAL\huT8M)]pMLp[mz] m<-m,^hGĿ*a(F7o2nq?j&UleZVM[g"Z_4f8vWܾ$SSIP>%Uښg~Oؒ2!:.,][m_:F?;aƯz^}&..la ;S"z_5n [,tP Iqpx-S* &o5p|Yvk/xtum&|7͞lWt8g}2mDԽCCt,.hZ,!Юi^Vf'p)|H@G9lV2ss#u:8j HxZP .|iuclvA%ۦY`%`J$sz-_l 6<@/I,-{e>*1_!Ʉ0M}19$ު.davNqDŽY 5A|rZI^qrB qC`su t 6o?U"0&HͦQ/z,4"!!H%L)\>luXAR2$Jb7gHKKM [S;6̾{i~>}q;EF93>w11VpA1K2)>ҩeuxfKmRA ^rJ4uq,"T'1 yuX?%1ى^Fq2RN6: 9Sl5nMh+VDӒ"F,*F:+ 26$Uα!6ՌeiH4zġv~`Y&߱K.>OqCX ﮴yCɺ%N^feKc)$o ;HIdKw5vjݜҳv~CI`[z} 6Ig 1ĂV^711+˚WX 'j=/vBƀJl[Nmet}YRY8(czH!Wό5kjtj˅;Sc)~81M^9- ӬrX=k zu \k#X7Ô3݋Q 5iR3ByYp1QݧlY!+4$-`ш㨂~4fl8R`Z;;r&!^[ĸC ֤/0)ǺHW$e^UѥQ GUG7liU7Pf3xJ,o;-8IvsGlWY"ЗQs_WF7K`ot-"vQ;w:sŵw>UkBc+ymd*/zr( BUsz!|[C9iNB!Pa [rcU>wn !.Lm+Zisb=L& nM _DI!˕W,|IR-Zb 6qCMx{ƴg)ĵg?7/Q{)@03ĐUlpLB%X:񄍡_B-k lnlOrA 4jj,]M̷F0c$>DĬ{g~XRim29wD.-Űn]=tMjcw BRe@Eu a1 { ;LXl8ѕyg+Qfd~YO6Ay?%n7;wܲ\߲꛹XY¿81eq4ve(pmlƝ;aL%2>~qI?͇Hwp͸pc=x&Akf1W`-5q`b֯lڍy=-fQ`RNJfW=d긴 |P ℡dD @ Glլ7Σ'P!>O%DAnl\u%12\]]j$H3`v u)dຝ> w^rr]%'sn2[rɸ&BEexMH~n?eG,V|(Hdb ? ذAE|E4^V-лEEUqSI*:d->D DF zV舎Li# |z'JWř%:b8,cnrN$$z*`rB_ yx,;f";֥o!t\&A缕wr rX2O/Go/ w&Ch¢MGTQX]9Namq$?l*];8\p[XpY/E3a?v`=mqig\O 5b0̌F=V2%6mz`U)AabUA[N" 7^t~Oe7;ٔjV79}PQJ^2*4e7u~cxIX4Qc5U={ HS&/UCpj$jqX,c x:V4xц%Zg:Eq bBkw ֆ;kTϧuӗ_|3?4I -j wF 93]W~o=iܭuWok~)`xގTDth?/@Qo`$;_ @CDc/4d\@?<@MRKÝ+h͉F]$+a:B4#j{#9Mes㐞KGA ??˖q11j4\raA3t=bxuPU&Pm/WJ')W,c^{p^Ḛ\ڈ8{?x2b>Es8go-a˓ ´;C0??|U[jH#PVʧ[M|&[|ЄTLp&e||K2eqlzc|d10<gx9daaI-:.*tsjC(Y;0Zx+Pm)},f(:?Ai6"" e;ch:A>E~4 DˏC<.Rd$ u,,U VӰ*,vʨ'*3)SwpIg%He;̫TO*hSoɍ;I=vJDz6(QEi|Tӝ\=4 Iz7 qTH^vqLX9קR\g]R z"M"xs:n7/I{"wr9W< My]:ޒĞLW<64SىGZAv>}{9kV]Au[Iyt!D=c"jv..8RR'm_,1Eي&8;kN{K;(h\ l'N޼ zE=ԫp`c'u20ٜb")g _wmL岢%RG/\r,$iYL0q{"n&ڒ-X Cn% ) aԞ%8~'>e5ju`K"^^.חpm-P?b^jA&1[iU B-[\F3T.kIpіwͣ,*M]#U]KL8ڝS/ d}@/㛹I(,[r2 Ӽ"("b9܄5J=V倔'PiiJ9Dy_%)*]S| IMxPˌ$[m] (‡m@! &/)ki6dv>+K Jh}ܼMjm`/*ƫ#ӱg'O#{oB {54dF$Q^#Lj^Oi::ablT߷m}OoЎKF3xw˴j|P@uU51#奔N^}Xq.BBSbnɺ/Ra[ R_)8}]F>kw7OuxD):(ە>6@9?9@> YFx`Ρօ ̺ƦQ*|͖1)xsC٫! ]1G5ΟU5s漟[׃ 39L YE  1^ 7[Cg EBw![\A\˦ݯ_mN/!|wa)U6Ql\@VC^VP25^yL ;h#lĶfrJ+$c$URTv)_(m01WoKbp{|m~H6obޕ<",phzxX@4JMb\i#R!nj?g8#]3䶖t 7֧|fn4J;gb8VM)'9kjr5Ь=0>![Tw >=vv'N}TzI`mv{hΣ _'z B>9>Ahb#ڍiT8cԦЖcc7~h- X{5Z_Q9mvj;KfR*B؋0Ǩˉz8 hbAs9PEasX)nFvv7:.NZcF~\,ڌ*HqIξS(:Ɓ96mh>B=tֱq8dMTflc4q!5Ђ*IoAVNж23Z+PB9AF<[UR9>4} "㄂o4׀(\21;WR r()VsAoI[PNEK*x*ݪIՓKf^; |}f.vv[*G2OO ]7Q"}:7775qcGb= VnGX?5|Jٴu庻_k:тO񲒢_^x>jbE(X Pǁ/nSMi&JLQ %!l+6 OeCH 7ʫGYOcOgaj)Q?$Y7۬-M0ˆ[k+i"ooWU`80*Б pK1W ~mI|*̱ "nOf*@|)6{WgNA`*#.T quU.<N-G`gBD'`+IzRڨӐM w0P)E8hus?>cb]hǎnu觑<'ߊq}g,f%Go)- P(=w~Fю]r"|/=]Vq , YUf2TzL>l_HUS{ .oSNM3Ƴ08kS|-]z-ѱ d"it]xA6tj}4H*8`g;ym!@k21':8̯g` :! !WDa"|^^S8' %7%(nf)^>u\;Cb΄FS>+8ҕP=yc*S:r[Χ/!P/Ky ^?`xT0 bmp3DY❘ {O\ۂ:zӄLxwFO(OMlb uts2؍tzLGK(})"ҎY % /HIi^A@$~ KT~]WY!@l4%֒f|ޝ S{;oL<649_+;5\G tř.˹ud_B`HkH1~NKk>Ts1zmN'1b']0źgF#&-3FD#!G,`57;K_SܨBᮔDtCh^w^EF["\D7K6`>(qq2pRqeXَ5aB`!NH'-xK!K{,!d=k%Jj& %,搌aRC[HlR`' =[ XV# 6 1+ۥ9tjhwq9 w'>ӓ}?P#3ئ FzQ|Rɔh&02dS>b@ ߬rJ:ϸJy5o܄,uA0Z8S!z'rcŧu/z.=JҞqb BQs~3TF Pg4v^2[L* *{Ԩ3''"1yEuwO $v4!) Ք.wD N3XmYn~Db$;MjV;?}[Ǯjv;iKZ@pCjn~Crˀ?u("\JGx9"2v/ak 1A,Kd`%#9Q|\ϡ K(:A#xN,nc{2UIP>_n<lfH^`Ti8cx b9 ʔT" x4om,hiqj=Y$Nт~g07SXP-;/tQhUF7a{c VmmeX,aӕ/l4î_!/ؖZCu?V"VݯR{2b 'iK0Eʙ&b* m7 N$dH?>+bp VۉI6a(Kll+.AD ;d:UlGu> L?ȗmbɈf% :pifZ{IÜ8DN\w5vNS9iVcA~:LokW*@vw' 4 YX8lkh3N(ƓY)|'aڈQUe '?mD5 7]u,p\2}XBe2ĝ¶{]@ Z"tWq>\UMM>$ynu5j3ﺅtl)U*}P0x{] mu&9[N-e}&)/A~D]Y?9{3#? s[VWc6E@$ _?(N-܇B!FR o qHq#SXvm:z5Nu(3F*=qB emۄntBf7 hc{x.) *@8#'{wxVg }wyiiMf,DRy{U#KrDDvlɥsc<1 WDښb=I(={' 8$,h[^:5@E*GL5ďEGf'Z1ڝډ&vh<*|O $I'TLa@Խs y"G(dv~wfw| 8k=WfƬ)NeTTP axL׷thA_vࣲ=cf:}@uk:} Fēl~|xJP\ aQ!M-%&&*U( @Z[Ip֪sv_D3kZ b0AG˽BkMXar:Zt< *r:_u$5 ~DWlwvxݴ":g0?b?t)/[~ݬ>]}KzPtKqV\§&S@+[jB"50FKT%&Db蛁h"璆ȹ\(\(꯭G[ैwdTn^kwLqg6]З"Ppq0bW]$CrH/&딈׫cV&ٴߩhƵZ/KB~˼A\6RZ\kl*$b\z gf{Bi2xĞ?vG,n S Nf۽Kj45I5JN{w YU1 7!LL^Y `YK(1Oƹ\ ʭ:Bʫ هk= 1]kӟ-izGcLp 66ۘ`C@,ejk[.:T اrE3e BEdm_Qn-=۶c.d)Rƕ''#9LԔ&?лKB"/ &.?}.f9֔:bI=iDу7Ƈ.Z)!>JOZ1KJ@q]$pi9HRuu opjE+{ˆ RJeIj-eoF \1`b&i)T:$P3@R-:Y}5@s;1hW%^ѧvEQss=Fcs$|kFeEbI.U$F2=T噷rgbia6Gcw9Ǚ[jgC[$Dů 'H8`HO+Qh tx9'磎.guz}2PėP CxBeBɪY),ZwaX0!q/ RyO ﻌٰ3Mc|;B}dxڙt\XLLkr[ԉE Dٴ;;oo⿙9Z0e/1>FI7c4oO@T*pPp(rGe3ξ޻,A/Ql2;M2w$71a-d* *}xAN&Pds0Uү3B4xCTF"D}vn/ "vٜ 7nP@Wx{7Fsгo׵81yLti$_)&+q:$D3K")''wHu^-' jE~2 TxĊJQ@5vRQuO^&ϟ|2S4Z L^!egb(+迎dQŇ/Vk04meȆAY_KӁgf%tsSI{6z;D\Ax6jv.Kp\d.6K#|Sg#8aƜf"RE!ۄL> ܍} .ZG#3.,i;Ɍe~N./ DEXM٨*SC.R+פEB<ǧ_<[Dq)Ga9mwVS,;Y#)V.Ѽ7иb DԟbǍ䐁ؽZ"hػ(/ %Gpǃ dN0=WȿӖ[Z+[QLN'&#nIqASd"dw-o~MxdB35xw6cѷDefJt7*xӢuNV(Jh؈̹A?iHv8\]k`E ,}Ӣ0z:,ё O7Kra4U%e#`jEl* 7tasBEeCsOOD j//HA=tv8B(U:Z8 /F`q"}P+4Mv<^ ]!]O'UCpY3M% Q($UuϾ{sq[X(ǘP8!F+@M5?jXN3Eum)X |2sh7 pXdR4q!sk_iŁ!3T% @æWtH 5Lcl_N =c N==T/\u8 pۂU8%鯕tss݉nڒ0iOݠ}:fgl29GYS&5=htor*lDm 4!\v_f|f.X e:fɧ0DO:,&Ô}}~sy:l#M8*G کֱs*t -S p{$ߦ'knM9o YT]ijiyq|ҍ.{yʜ--^|@ Z`PX8~.H&Lٰ]&F`}%Fc[[T銒ۿo˻B 2U1i6ьΦYI ú7>e[֑F\an_s0ƂiIj7OhG8\HH?y ST&S'HjV6"TD4f&n-V?>q"v7F:R >z_J4~ >S#a!zL7G. 2:K+ЂOkRf?SkT먗W)VS?WpVly[WymnD\U $ۯ}Jjq/BZ0ZKMVÏafjٚ5*ޗm(K !S"@_%酬:Ƌ]u[GƱjI6?^ OGYP&),T>^m2ceB4%"Z4ZmU&,]2ĄĊzRp( 82p4cc^(!)/FIK7e;p"<¯ ̤:. I{yswƥ<Yy{ƳɸR߄c^&4݁r82`Ґ"((D"^I('Zj9W}?gZ;El;ÆSUzi{i`Z٘XW4t?쨀&J-~cؔX%[z#+Y9ljX$.Ǫ&Qz5s0kVSa9#3655šJ̰b+^!f70B$SFWcO >Ma \ҿj= >H8g)Y9j^O]s PAƛ|5ees1[W2ViHU7N l!}-=gKqtr0 n a>{7[*"ISqMirzWﻇ5op9y@OzA8F&&..\Z3@}!)z?+pkaN暿*7k/tQuQ tqq :r`YFM?pGZC'^ߩ1z1iRi }1?>a{Vs[ MVQ0Sܑ#6ĩxQ[r),OA&)iseK>I⚨!0fle; f1pMh~aXSJ-Y+ZCQ i+^%mQ)z w/sZ ST* ƏUeOQVvm" [?9FL#`0A~K0],Mfڊ = Eã]^RpcRi(<0Wnt73Ae#Qj{y\P-g"GH, {6m9}9#& 0-1'YNarmU>݁/ޝ3܈.;!hvqt-"5[uB'4dLLZY~lKel'/V"%* 1MIny}8ǬlƛtM'%-cw͔M vmڑKKhi[a7F/߅ I4 ܧ?.e۴Ů$'ogj ޴ٱhW4 :9wYe{9DjwvhtBiͤŃ~s-֊/7"Fjx |::8kps"yt.iJƪV{L|-! +!TQ* U*Ce;rG ZHՐcr\: '/4~U- ؈F5bG <V@*Ah|ǮxlÙXUKe'vv&h҉>7*QšMdKy=]VƏvἣ\U?t1x'$N s'oﯺ<5ܺUiA]oFHT"!ƟG܀ӥ]m9>F~G K<.tJwL>=/Y(O oD@iWc4k zu`L׌:Hܢ:pt[c9nPةp{LwdTO/ )+$i* g9O@Dq^WU8("/i+0<YuV[c %"Ǘ/:;2h>I$’ i9LiG;Ҝ"{GwҬL i:a >]A:2 <@/4teijM)TL[o9d:-(.pAru_[ąP>Z-I.} u0pa2 h|ۥ8!ŚfbD]R~ǫ" iwQu^w6aq**CUv\']DG-|ȯ%Dh+؋-TP~FbK_f!!1fRq˞ z@I͘0^\:OoV#K#"دbe7 цM“\N̂u r4}@2ډ}kEp ;C6XqH331" A!;ǟ}O kps^?QQe9O-'h5; 8\㏆{ؠ[qep> EM DFDŽkA"cܞm>!}_ @#L# 5r0X6-"-3(Qiag/tc"3| zS)GیYgbR>!:Re{e/qW/ބ;-G-?:\o/P;IFt0k0~6xJ!71}"&xٱ%.6˦3j`PM*sϻ6jY#LGVY(-R'.y\/֩Y*m,j P=+d8侙PwVÑ{9zW6Tr}є0:n1hɡ(?d}|tX!۴I@= xx5M"X-bb-~ iNN b(iXIՌ6cTozD0=f+(ܤ멈>߯&0쩁ÌqtElA9OzԿ@`Ssy*5Nϕ|ZOM$%Ko[LEoӧ;: 470%A4RN˺`VSi oJ_ɟt^`(lA?#t@F(Kb{u B(m#O?犰 iJãc2#O"p .u95*Ib#o#iN&MAZ@V>U "PU_`#25vTO3+e3_KVT6\Jhᷙ'=YD7]0a?k=8,sc.zODH`0z(H־a0ߜ;\ҷ2}upnPϏRERAyPbϳ7з1d ~| QUVQ5$5jZKOE0ƨ+;gٰX朶x$FOْ̘l DR վM5>xp;h}|2ev #k94( Q #GGM؍xXtB,zM[3+t39#ZR: ⶢZf?}13l@5;ʹBЭkxm[*,T}C;aK5:1I:0bTC0%ꃖݿhkHGgS;,l 8pl%nUp0-MyLzT{ ,ցžsf|lDRLcd .(uh^9{g f`+g@Y5D%mK&AvqC#0iQU^yIL''3gܝb(Z& aDR7iIz]/:xՐZ{0eFک$u1, ;qxyFUG2z-:yjД;T? sڛ|4+KS6R.|6:E.=쉆j!łC5Tɢ!v68DH8$Ă {,p>r3ې=jITs8(5j| Kyx#^$H*0fa6 LB+_%0{[J:TiXg8VٔWdidK1D-9Eؽ< # {D괉;`&Z 9Ph;ן&v/E *"?BRF/J -h%PUHR<$WU@~w8Sja@:*r<ڒ=Ϸ2k~_e{2XNmY{-@hT?ӨiHn=dcT4[}aN?4e6s| *DdF|]PKmJ{q 6u8ӫ %|$&Qt1˛@Ľ $zKp\ u 8Dd:^Y as}у2'[ts =\>Vxlۇ7Y~N~_MSfDQ=>ږݲlE{SFrƨv9߱y45bhmͩT{}!CŒBa턱: #O. =g}ߢ}MȀh0&yDΊ fK.pƤ:ȝ9WX=LkaR>YnJSy|\MGKtKG9TdCtYm<|yeIhIXV%bz@׳ Ȃ-B(6TeXæKe%tE8E,G xYH AkAFy"YWz,kPL2 +\L-J;ƣOZ}Ǽ`_ IpTQxH-Z"Yhxj LmR\hQTȱ%'()5aa̺&%bs]e䋸h2v G Pw`1Sw[;;&uARhX<{| '!kq yֻu<ܹc|9Qk.X/2PsPi-~ ׅVcaT1'sf-x٬ݳЂ?tr5iTʼnkhjKRQP&?ze0սsV0̧Q' oXߞpLhĜ6 /`hJl\ oK=# SUX|S9'eWi07WHUxwO7jNp4EMqp. )\DߘRb"S3lvk-$ތr(*vo* \vvY/W6 _dۃ.;ߛ [Wɋ9lbthcufH!wM8o4BnIrhn>iyw5Yy u%g{B.eyBFj <͙p;ɯ".:&<9dOe\VsuHLǮqjNOJtbɏzCDw8Bm4,hQ2t|R0mP~<=H%FcWt^mbjg$7EěAww &k S?I(k)Q8pA~(4?L8RS^7J ðc,ܓ|UNW<綥\t^YD^xs0ǦDOH~/` wy$F?2!.%PgaW?0nнNgu GXV{%dĻ+ B:F̵2]V[,xO E :ŀ pK[k +{9!/EK-`3v:^h6z):9Oep AǍ+BD9;e2@} b]d>@iʋ9񶉒C9>ݗ 2!`cwM+!UzD7$: (UB$v4[@ 2)+=3AEHxy %"/? U@QNsٛ~?~3Es ^H+w]g}973nX{|l.V*K.Ow~E/ &ն3/z, ɨN}se+ m<-Q}q,x;=L(mkFlIh;э.1m%]CBG@< IgЁλBIa"MUj `!fKX7ܺHāe|e{bWd;vBVr {zjY;M@oOcl_Y_ Ct}5P+v$⧡GQU^U1'MCHeLB CsM1OdʉzۆX^6Kng9C߄ w h+ng.<{|$/F8e2&C&}WABLjW;qAɱc-nTũͿED qT2*ם.k0g|-3UQKq@et;E3IcZpZJ`v|fZ1E530 aNx] &:y>f!/ '"΃$ )XPm L#4ݕ4ok.!60=*ib(הBw%HZ'293/mC ZN!,eS4:;6+e( dfaCsYaHgȏe$qU6Xr>RIur[g`6be!\kSPݧ %61-aJKynxߞ,g20>Ee]6sEG.CRBχ[ Φ-j+f5+5*k4Nu5zo,{uJY R<' 们Tf@[" RaFk}ÞɌwmî~]?r,4gz&i8هضz32C\~'lR* +P]mU:m@MG/ 4pQ|mz[z̑LVYٟJjJhqg'Bba왠Q@iyzaOM ԃifҍm][nn xh M5xE9??״wGbs>lVbP=-9 sGMZYsmno`  tw]:0uڸj葦HLx$桏JQ( 3zĸhΤ9?ѿ ^(wF8 OF^/ n%KzINn01I9iaA ˬC,n«\Yx@mNDw8!1( gNV%}e^\j^/UۈPOSGi-US9WdCh"S i’='{62\iV1R')A75vn2͜'9m곰e2g-Y(*#2ބx|~\\?gx Bޒf77 )6dF읒`xeL9d7on~xڴ:HE|Q ?PF'{r\~j_ZmNXg\9xqkNhefCW"io/# eWiZBjO֘[3@EPB<oi"%ɱ7Kp3s"\>[ swT,v~g_o7pL $0a/.$`]+z \ ;5؆At?WV0%CSmp{wm]/է$I}HL#K{iuDIF-B屛&,W0vo /1A+'v/ikWD m؛<':q_$O (ʈwq/8yKbG +ascɚ77xut3?~ AzM.ؖyŃJ>J lS3(mnƅTI^3WͽЍ]Ъе ;8KR?RMwxoկzaf-D~1 ծqo wƠڱ>B;یCo+t_L5 h~!LL5!6(Qm/Ҩe9(;H:tG5#mq!ҋ i]hmj{DsXyFteja6"5d->=DדG!^ \o y&v"* јdK8k&DK|a0 (|ٱSˠCel;_Huhi l\oQ-ff]~D~>?DxoY5NTu9z(n` SLX c߬*|=.{A:i f_)I['{ra%>"QAuٕ2V`~%`\VPLXê")rz59rSw*@B⊇gl[AxK So7}%?0 ƙ7\[$;'œ|?|R(/2?Y)*sZE3*ZWAlُs]<ށ95 wk<ݳ* ^ՃA̪uyS f.8υi>FNG3 Uysi)P@)66*AP+d nI`RA݁,n#CwT|c.Au\ق!|C J{ \ R]#c՞^K~:Z缰 _x[zz&0[dԮe`FSmPPoZ n }uOoP,eSuv}Pfs[ƋLcACb_i'K(׼w}a!^O-J3ל%]B0N+MltWO 5p+c2/,~FxWQݔWG9̺gЄWIia6.Ew(o 4ZcnCER9L [A |7%mf,u@&[YG=FvF؎O6UN9 X9#bv#|^`{u4>JCCKvkZ/ů^䔸f-9"jtuw:Gиt#N|+\*<;a)*T/%!=;m+cxLFU4 @85󇐧^[9541Hc#vMtPNkl) OMBLzZ͎<ݿ ,'0 Xf2b)HkkT4'A!z~ۛ2B YBфMS`m…1:DE{ z-@mi.$\:-(wp,"#%ل\OR<%hSW/C: FBw]":R/gJɧ[\銖cġ_$+{k+ ƻxSAe呢[tC2?˩ʸ U>XKG,}k| D.oU 5dwo̖5*L/՘Ֆiqo7 :#T0=Yjh]"v*F >ri;vXauBqgr8 RSI>MlC8Bun/2 = %q.u~e\&SԐ_]E3Յ}ṏDť֟oi~QҫÚ"ӿ?>خH)%="lz~&L/i+< tc KWx s`ya| +0rj{flA~ ewG"UN$=^S®贜0`Ab9|rȓQ]K֨CAwGs[^Sj._լf:d`9gy cФ!7yb`rZœ|?ʝx rŮ!]ѧK2J铳b:D0D|3"s;! F^ 1R=`b6CV! `JÚ3Vֆ Q1i"yOcgrBK9(eqS ׌S*+' t4uW#{PM?j~lEd7LZe{+ƽ1>'K 8uR+QO؇0\H LG]mf< LZOK[hWV" KUknKܝnPWpI*b"Ulz G{ESw䃨Q|9GʈC|̬i#)Umt$%A'Fw@ϱcKU N5Kr \ )=6A!hd!wsOb .2t_n3`Ja+"sJFv3TWT~x4#oY [-XhoK;XO6;qtx kb@ܬosA\*W/軓f!0m mnkP|+G@[#RP6ĉ\yoO= z43 \abvn7PZ^_<%ҍ0)$w2kT+2XJ 'S=a%}l79'oOZ6,MTezr[T6ZT0bʙ!AM\pF+*Z4s߅DC6[uPB~][`eN{=]]|oҀ⦠[qa0w|`6rx72)D歾_X1M|6`.&]unM{Bg8dW#LqxAы l^NVH~?%wETrva +׎b_mtZxfx n3NM'WA<nQ" ".Tg 'T7kgsty?iPiD0(&QOm,$pAio9qߕtbv ʓ>>zAV@֘$xjη7M!35r܄4AEJɝKd jOKP{J9)n"р}ɘxX]ΈB֤zNYhVefX)hҢ#J`|V|a.@R{ۥ{}Ä:>b5ݮYO||ރ~}Y&;qk:IRgHF2tnĸ2 yMOKK= -{ _&wF{2PkUv_eЪCs }Ch#a{cjEF}"̧0Kz3Ǵmr NM>2wv]mζ&}rބur6˂MT!O|w+$LMԒ(d~: Sj5*>"[u%l:͌k`P7}kV{"e ַsZ"}Lk8Wyfd FRagT9ɍ Jz\$X> A7^ѕh7UZ<^&(W^^46F9 4IYdUD\IZ#w [c@QxXyKw bP4z4 RK;><@)-2:#7] {\?nԤ"o 1 G<<F脐LR|̚Im?;TleOp rog_AdWM5[}|sKޣ"v'eQUA! >쇆̭}:mufAM~;QLwYdw"N0"BAGJzt{.a?2ӓoxS"Skr1a9* YF+J!CV׷ %gJ MB]Iq܉uadj'Lݮy,;R?ӏ+۝"bU|ͤIL2P?)F^cQ1"]V4+3rL$,\V9w~.գ00 oC+PΌ HF9h0.lk܈Q&o2~@0Y ; HNcOaBa=y[At/i̷ .(<!bU5Zs O?"ɻ)j~53b qCjH[ A,}|Y|(wqUpy[7l﬊snɟ+o<DIJ ߉̯11%NI\?Z~iC4Es{D&!Qtۤ!fXkz745E 1w,*x_ MoA>̮\(_cC/,N<^F$Ld2I緖^ۈB |}o83H:(_bPyLiǣ,㿴;)GKd3:D ʡ 4QԭDV|t|bNsoZoy8hDB}vW8 Sm8&$ן|SDSҗGXb|ĵWa&tz׭y M~YB†oo9y6(Y焷mE2&0DkAX0=D=OSEn$vEj.mg*|5va=!P\Ơ$oh̻W5t.bqn?jH\|SdmQpA CϮŅɰxmk d~49ХTV  ?| p(F>6dFKBbd3n;5)P>IaNaH0dc{$/DVM45fG@7=,c{N$!(v,kVV=zxi?'% Kﱩ>" սu QTn9VVa~ ʴ?d^g+婻OEL+ʏ\4os-@ASشs 9L`R8$CWHi.7*̖(Xڊ4(;ƕfYWSIB#1V$ڣlw,f7&ԯZ#__PU)TXPuUB`as/wXW=v)jOgtZ>_Pxo>2U,N3aPo9=m\]6itz^_@#<DZ7}җ!hdaqhŠпl~\tqw(4"EgWAkM}l (,zL=B^{[Sjٕ;+FhX}UP͙)@{?o[¡vƃ+ʐ?F$Qgl{cZ Q҇)&u7K4G07:qdh )F6l9~E5͢:j"e> #*cve1^CF-JZ+^SІkJ? \JYP>E (S7q~SC7¸#m=1_:n,=TtnAqSeKPIf!A`[d6ul8Y|c0S1tki='݅ Wrf!&v% P#ĭRt50?[3*tܞd=\}[ejr7_q 3*'.[}kc`kM 2vM|mzf!'ag"Y`[i*[nTV~ų$4.a̢tnav 29 [^򥕾_ӞRf 5{E c;'r_O0S q(lP7˚2$ H43UPF=nrD&rgE wrY@e]+<$g {S_=. =۶s1_ e}̵1vm(yDpDGgcZ;]vdp Sht$̞J"HDS3bGo ,)ӎ n)T#w8PW%qWO=niqTwx,@.i$[u-O=}ȡU!jEm1z Eiah7ݟAΑ!d}'QKu>pBB&yO']V6j%Bj`Dd}|LTFh釰l8u6*b;hO'TFo0&UNÄ L],6,ZWiJ -qz?gVP\*xI5ϱ!NCV!]>2xMY >h)U"xWPPv\"Qf=~fꍑ2LO|u;GqDtLd'NӦ:zXOk$f[N [6=~WV2k&o$?oڸ\D nƮkaEښZbսnW4iVU_eSrBRZ[bXg?©Z1-@ͳ6o} H:4='ߐv1N U Yھ27!ƵiV6a@"{qЦ\;lm|#GUҶ{,DahBJF1lX%X+sq-Սm%79Mp. -s"!YK63c’K cG3P ˀԼlDKEG,K@+F; ɑ=S̋[oqIseXD2sIdUGǸ=ĉ9okuAkubuVA[2\L) +`/X^teܕZlL>Âx,tD irF}^PKVK"`T2 bO?c9;Qzע4LJǖ,n1nIc0 `>0hU4G7 V5W-2/EK >uJLf𮳛U  q.max2.ٴX3DVژO1s.݆=U+U}~5ZYS ڛ5^_^9\{ې4n0m28t'%p~?vn?Lch MȹzZqtt}cᖳr3(#/liZM#6F_UzvF;O k&J=&뽫 u@rX9:#ӍV)rrֽ}Bar]~zWt%0A~Ypۅ&sp5~@g-;ք@H<%7u66je#n{KTfoFޘg1$s_O mUItal? .=h{TPj@׬?Շ6hP-D#hJU{EN!|m8ANm; C:{ػɎ>]/h9d~^&Tp8Jy 7f2vk;>WMf.aS3kcJsduu=iMB^jg Qt]ϧfulSBum.ryOa$E8Bq-X޾6e|pOW 'U+>m'ՁeHDNʕ+$aR '>4 Z#Gye;þRZE5td)CԴ&zIk" Z6ȘpCuћlW- wY g.yo{]o2l3 `idIC%#SZO3*d-8$R+“mH?Άgy)y.,'CZG3S1rn)J#F9tlAG0=;qDs" 6?R<,)9Qp,O_Ϳ!p$Kv~;pop%7V((Ч[H@xlHKF3HߒTd1xx/t[7i͕Jƨ)Up(R8Sr-ܱ0+D+I!̤w`_8g_ Pfw?daǂ q̐LP$B_#c7HxRN,F3ˮ|n*_ loi`鍠V驃sO)-%e U\QA/%O"ܚP< DW3? G,u*Kwc.*LKCKh+ Xs1-{&:}!̑Al\Zd|,.?_*B\A@K9 ?sl/+ @]ZKgnZ¡_((Ә~#-H&$U5kԕb#<9wGm;یRPHM WyuIB.g$)}ch;YF!Zjq@&_(Um]sw21 AG y֪kF1w \R`BLod?jwBͳnKPD#A}AVSHj|3zKT>ƞHVWRq[$r^CJO4 DpMKum; z`nt?ɼeb%F!#`!"bySQ!fap~e+2d&pI䕶Mtŏ^`,0}Q]OBϖ:eA?Jmm#pdojfA`65hgp= :hF +і3t:ձyσgCpmA>\BmQE:$Bb4=|f5E& 8P#Ӻ0'FXx{-mTOos8h?,tH8APd);Uq@r~Hh29d2yY4G؝N sS=q.Y=&#x߬“fgxGKIݔ Vj@0r BqP\gYՒdKe7xS+[p^A\| n#c'@~=X۬!)흓SW!_|(} 9RBs}L{7'淕^9I2|F_,cbg@P6%{Oԉ57}WK=gvٌF{d˥p>džj(mz2yp#I`i 9_u0CzTpK+͊Uϵ1O^+rc5ɩ{TrqoЗ Nv i.a_Uk@av;Z0:Mjq\kdp Wk7H%Y`;ԏ|bRϳ$HrҊ7 HҗhZ *M:7_q.9G2!)3?l;d/TvqUL m:#e0b0Մ74I`py݌I A\US Unub;D҄Ψu2qv:obG#BxDbƋ*i¬T۱1cu^W/ooJx(ݛ(q|YBi'\^AJkᅌ󬨥R.w"t 7D5_NGj2se:}YWMQ{[YRCQʰƙC 澧pU2],\599VE,'Ul-K&*DckҮW HA]L+W?0'Eqt<́ q Ғ**~C{^ɟ1}ۅr|i,Bf/~~ P͔ЏE9AuD*c={. B!D37`ib" 9ٲSRSIUU^>ŽjԢ&"!X{I l.Ῑ"_OX 4o]Ot (75Q0APpޫ1i29Ax].Мh^)9EGcH: %fÚwKHPr`!y7Z!f}}`FEIR`2|]l4MaX6_,nɌp3 Iêٮ3O*.l:qy"e|tlaLDq FO|\qҐbN<%@9.ΙPKK%AA_6m"Bf?͉cW-z p~ؒ)L"}{ (-A9蟮<pڟE\t #Fc1z"P. o %*I>:3B˃-Y㏪P7ihqYuqC(i?V[ziNh%UpYiDD R>j[DaR̬Lq ugcoڪHcHQN%[ fLkw:C%d3C3)zUn^ M?G:ƞPoQSB=Dc3 n0O˖q?lpF{c9 [-ζ[uܔY}MļbnqWd3bĆFx2eaVZӌ%'E*2%۬ +MN̏WDe gݼA 4*i;( p*#X:r=GҐ~Z 0,4: 4 gDLFP@F?Ȝ^bYL|.Fxx5JP@}'B\0 8B%W 0iׄ#;E8CC.rFxܭ9hcZv 4cAPyhPͳ5ޭ{B-^.R;9*9%4ӃOI-E(+ę5^蟈;:'eCօ5N '*&Y*ՁMs8kWi"$Όblcv[U{\}vXR"b`c[$}Xj]X{NKY W[{E7Q֥n^d6Sq0dA)'j=[. MU=]UUF"NqU[N&'l%|/c@&_E<^Jq 0i&9cz=ЋoDC0>(Ԅ<Se#?w3+ƶęП3_O~quyOThNgVQ7<g^j)jڼyy9Av aG ~[%5*q$D.^нk65k^ܹaCJizԻ!=~_)ݻ:T>#hRۙoIy'dV+k\3*C$E{13ZGibWd^FkE7ɮ*._{-VS#2AC%̸l;z3'cjj aUܨϣbs5*)`kZOc.i> v_)+i<ʯ; x<ѢGS&Xt^D\1GƋLLXj(,25aU&}U*-.,mjjlcrlQi`}V+Ͷ^gjrw@ǃۓI?z,QQ bJ?w%؊b+x Nl>Ŷf[QuDhAu8/Uk&i]@FȠҁ.*)ᣑZŅd |rkW&%++e8mKs=WUtBk^ϯY*{,ማd)u݄䔄!*:b42ND))' W'c2RD;)+N55H1=gDr9x875H5z`՞*w,nG<ՍO?p6Ld+?"dhArQyh-|nU GBᮽC׭D-R(ׇ/>]疎ip`'HyVSK;/ʟkY*8ڛT-p_qBY#jZa#SSj[^X"El9H@OO]hC<$$B@b%^`sL֤Ck@&>ūr gj4Yp@! V\iհ[j;˵1hB~1x\)^|@"DM]`cT[$ f.%$CFTZgV~G/R+/oԘn1ju_~uN p#ɹ{/o}'hυ]C&4Lܟ9 ~MŹdP Y*d}SF2|nF[LQT7;+ni/B~a\ 6ga CEZU+{cCH( R2ޠ5Qu\z.@Q ,f[DX֩gT :~/_M놠1fV;hܘ>h Q="᳛u$s v55WO;[ WL?,L0bvLV1+.'1ى'Jjd{,q|{"?[^\`Ss  h6 |<@pk#YgQyakcV|8wv'N2xrUvt.!i9?k;BCY݇ ]P&өh*'ØUmB {=yGg',/19=X$TΖO'+9 2ը\I5Y tZ!p7yA[J{x-ȀQKkֺ>4څĈx#%#9&3<%\E>4C|4N^ytJрd}3 4:S^Y4%$ؐx-ǎ[+D eNQ<HT\&6kO@4CE`q8|?`| @MZw,M"Cx;p0Fkn|;]7K MgR4͜L_4,k@*l$c~t-WЈ>աY&n6X%v zV|lY沝t'!** Sktfm [lXG}2b &ost J\g4b荒>1~zPn&c4Q_j[Eܽh V1P 'x̥K+O(H 4dY:+q=?nu0l euUxaD|Dnt}V*hīsq* |U$:K`ze oT^"cy9Zwl$8K6_HKi G _5YxW=bc?xwm5V8nJ@ #9#;~A/9?u I҉d58@5/2ls;7ndCKd;pc O0Vs7H׈G2džoORydc󮼵_Dqi*) s)/Cubs!̞YY{W_5Iؘ/S  B-IV/apQ1PO v-eIB>{yxEݼ293VPT9e/39AՑDYDrQEWպ/=2OB^:CQMTzr:{lVDx:1aYou@:IDv[|ޅE#Snbw$8~qH&!O"HzfzKTBw ׌zA\e^Q-.̰ezOYJ;ܑ| t70Dt'5NQ3h țP9mBL.Cu_?%^vm++|!mQ-ӹ.-a !.f'sc%`sToң6mі#&1,Q//62moܳa 3At3D.WrG0D'Xj7w1aRȉمc&==8cpE-~JŧLt]/J:Վ,*t2dJq@~oZmj&{v|6giDgniyWձHwg_={]0Q9!M'%dR_r&J-3jO4A-K$`,(ʋ7c ͗|`=K_ NMJ_xK" 4:g LzgaufCI*=N굓sK1'nb˦sCԯ:”u9S#FZ'sK%fGl?M?8]qSTx#tYgf[H4%{?{m*nQhd8T^ab`†7aX\k@Sp&|J}.և9GoOFir,hK}Y<": qn^Q&QqT|y2Ǻ2~X!@DJ#X.2z<+Ϊ(CNȟjIQv o4g&$^_[һhkt;ة+aӚ8^ c|_'PTڿqTs˜=qaM6`Ϯo/xݟȦZj. y\ DO:0:<\AzG,^OPu muҶkC }F FHQ)r,i+ܾ ?}[!.5Bhk퉔J)q^ H욗&GA'$w):_ǹrGM%o!^bbacSZ~6}wJYBP[ru=ycwslMUɖ"|多jv r\kJd~bٺ#+gZ -=1,`%PaMn݀fԛF2AD|@'ALj\cXF skD;q&Ϳ0K^+OUio;D 9eϷh_ZSEY3o"Q*D\]PC\Nlѿ4ӣ5± A_'\)xI{c3"p16} YT9E(B: y%͇C:j5HO9fKVZhnmL5haRVwf.ŲS!=Čr>p1aT؄Q)C6zШ쑚PwD`T<{(MzoIDn]I|?%f !Ԇ/U_^tW͞ Lה'#9,I،8p &zyًn{/eҀ)a+AsGD-x9/jѴ)eljfBGC]SSZ$!?N)0KV˂^.Z JY62Ezp~C;ƩYIce7n t, peM6^TߤEFQ(J{=5GW8IP(t1`Q9 cV7fÞ\҂XU5][\ SB F^K-ڢ'dlgn=V Q% '[!,p~ px 2=yˍň5ęAOlkbDiٳZ>t_>ϚiHx-r_Y"^ÛNTov>mQ:ҽ% P: ݙrwZ|ق3}yDuA`A*h3ćE1Ŀ&1 IWRizZr{(;s\a$e!Edj_Eנܸs}4`6NtAsCt\8#.t '{uW+(*e'3/ Lx޽u ]Ɲ(Rju{Go]7nH 0\tYT>sDPc֬Enl$6@((E) ?TÑWLE; ƿ4HNU v@| bYPcaG7]3;,(hcތ:A^ɀ8m78;{&cCv DUV.|co VCv@3Ggw_s.ԍ ]e}A@"qB;IXmwAnԊbM E7PnƷ0Zͽ4,hI9l, {t*ǏsJ|u+KD??bKW&R;dT3rh5h3Z\QW۪mÔk=Πۧ6lZC@Z$Yk>ڿv(EPRu|>EP2 6p ]XSii|^hѩޥGr-wGlU#t ck6TW^+j `T}}Q]Y^n QUO±Kۧ*^< GBv7NVnTJu dekAQ r?@L)5zsT[cĒaرcB0,,*}¨)i +V{| ӕTB^8LYJ=k/sc sXbZv&Gࠫ6mt|HSų7QFTْn`n6]?P9ϩjԱue<D& TjDiJפ0)2ۜlXsjMF, w"J!=-w[pb3W9]9jS kpscJ| `_ `šzNzg J2ٸ`-"D(dCRcTnbp#)| M/Jorp}1 ^n{8:1t;"6L ?:)Зfؑ)G `q0m~4VAEd ej:5Ū\w{ `I SB .P r^ t"s9\6b-` F;:MK1;{ҟ7+z̷ 3WD)Amlrq궖vh?rzRӤ%X ҏxK w;W5rV(̻ b yU'ͅ));MtHGT" ʯ J{Ru70fSsh2OYaTAy5 O;&qc ӞT[ sqCڲ(*>K(KLV D -›,M`Û9bD+{y%'LYEbyk;1Q7o9Ai*DI*(A&>F.^B! F{k-s^ӄ/C~ IfC/xYxEZu)?'WO1SISgrf i ڧ%.P#>CKF\vUK<|"nraPZVO?: -V* 12M!!Z-c!4*g %4#%I^iy멞>YkC32]_n>ujW,8<+dž%.{-L ݻMiqP)ro"O)`},!Oci$H*lǢ#k KN#@̽ʥAC.1qKX o >x+f^H l !~S뎞`-? 3KG)l:9cjb76r$ʒxD'p!\c,~@~`_٧yd‹ Ȟ׃{×RۗWStۿdp]_kld(QhJxP-Vw,)֏FCSA+\tϨ}lG*l)cM^9R|"%@\{/WD μ<E*p K7YTలG/cǯd3m?g%<O]u*giH1>|Ր3H`S;F[T'0[L>5j'߲ȢtOͿ,"hC)ٍxCӶ UM q`l?'Egm^Kd䒲{I-Icca ctgnq-b?] "wؒ]p^%##Y]&ZbJ|-'"Mi'.^һ+> q0D/:b0 j~~ro$wH @JénQ5b}Kġ[N8d$ud&M^OvòEL4m"QKvl;9翩-'t`Is(P{!)gl\˯{F;#:}[A"#KS|igmSޖOk_R[^Rܥ3_8Gr D+UDcRiY׷ĕezxQT7!&/3^^Tgv{be0'74Is!<ʿVSW+B CmĽH+*uJZ6/"g08K@쾋~Ib5Η8N Wl c|(9 G(lv/q>5Ȧt!P1}aq?n9TtS 5[ͅxc|6}~&+1/QShn޾mЫوJyFct.Khܧ+Dh/IyfƗ|u ` $_ ~/CmZ.ypy2MK+BdPY*7|\%i6I<Y W %'o|W2p7?%<' ~q˺HE!ѓEmʧ.F ش9rsZo%M?rAk8yl2? BYJk[K9? T/!۰Va!4ϼ\S $xdÚN¨(yCHNYF<{|c)`\Nnz9kZ^DӉ| ;鶘 uÃ֯,Z^q#ֻ.4 {XZaPM3+,?„4U#^a20jyw('pG|6`^}lڳ%TtHE￞qxAw[mrʹ7Պ2+ I)ψB6=bMrE+y0H@fNb p({|2̫y ~JMڷi~Mp\|z!hu N_@|ܠ3 UeR | vURO0St@9(Q\'Ì8% ZCI.?#JjG.1S?*܈+("gX5-,\ eD_ 79-3̾J!:K j/Ԑ|qL9&r YV#|z^zEu4 lETHԡs$?M:E/@M`f๵ 'uo6?nJ~ɸY),$I&}b V3+w^:í@e2:z388(R+nFR3bU+NK M|w24lrqɳKc>TCH tH3gZe: 7aG>H?M9gag8GkO,lBO[C d0v8gE.kp;qN36'A53n5='p-Y%4_ ,k@lE)BSHK\z;E2'_,a9Ř<t:@z*.I"4v}ѓFcS,sLRB $^jx?fsy 2mQ "ĂαEp@l q.g_6[`]]It&SRr3~sZ[,Gj\e\I /aGoRBݸAd Ej@k@블gDLHOJz-F[{]߯s p5"L窥*H|RgX2{RQ/[ S!;a,n|hyK~$TrB5`to~/\ /Z"II7mMSү}Įn1y6#<C&XG{J{I3H(A@ ^ߨed #u~?chZi,sTd "wD+s Dypl"2 3sr-MQ0DΜEpW-F+5ne049"rcX3H{;=&2^_թ: 0Il(XA4]D~˓fi\nIڈS4'aX!ƻ%6 @at%,Qۃ#zJ{Y<ۿ*ew:9j/y?'Oq%,0QU4 nd"lf .mc2!=tߒ{6Nܪts6D{6N`CDRP;d.m8SIibDHDC1 ("^O:d[X5dbF\?s^G  wy+ޗ~W dדgJ 7.9A:+50X*5n5O5lmxе8o+o{"Q&X1>v$A]5pH>r]h;6thR̃sLWAP&˿n, ݗ/ +}x5iHçvmQfӭF|#ίKx4:B3L@!}{3]J> 8 W3w ?Ŧ? )Q4@z-g>:Ֆ0dDML^%1i1B(0yftJ!"c3D9hkn~*YyB7@֞[U CȠW6"oҮ JWVgoEv%8xZ*CuU}LjfR;"hR!r'̌oP"/5*cSm(m ?9<_ .6VWuc暉=4=nXY:h/EVDW=ĢvCK;-P{fswbn _c)^{,.Y0#:Qx@^Ş;"/Ȭw_o3D Ehx{B寳{%@s(KW4ɚե">Iڗ /(,zrwaZ <CL\5-_Lٹ _[-rI"==5 ~֯|Һu5WT,rIǥPc ųlKd37(e8f4{20h.@۲b&  AfI!ܭn . '놌#A v->!b1$w +M%w9j6&r;%ޑTI&O\MKR a}7MT 'wP4ޢx^'z)+Гɬ(yMoP[t&j2mC="Pu^E1W2m%>M:ԅټ/'VBiT%5a/$Y_"-Kc}nS"FHMtLlo#R= o =;蟿IMR sF8sE( E`2c 1t ۳=qI Y?rЗݴ;=Sd֠i푸~me~T16.2kN\.Σ(ڕM';|~ۂ !ZyaNHQf[B\\OoթaMoKwW|IE@\}wRq@&/п˼] T3$kuoEKIr'f V^gĩg\ j%H s W-ªzGL,T듎b{*,݂ 7\S/FCkt6{20qFº=I(։CdtQ e/֙(08%74Xv's)Hmw_ ksHD>?(Q_: &}?el.<ROWՇOo%(Nr(7!3Mv)j$?Wϰt"kv%C#mؿ(nz#CY:o^&V2Sn'f*fDhn[(iJ":}޾ksTDb]i)D$Q1k~߶!z|ﵟEkXF=4RM>)LCJM*@vNh i͜ ꈱ7X@ g?l6wqݻZ8U8z*W&fn&LCکZ6d 3tݸF1LݛGsZUGqN W:TݬVG+J 2n鈝}glԶ;=tX?buK$_*,2vn~AŕoN*@"ٜ+}xBlcE ֽEڲ'9wbbjb&)Mqq,5I}6:CC<Hb_OX0 vلgT-/.;2Fnav\5!kGV0R' D#G`ޟ޾OtW {ln L{YL[W#*h#)=0 7B;R贺 "^ Of~$Yz\~1+/hf6 i_ŵOX~tU"5\ϐe=@{y@@K#[i_ѐLNG@.eeǿ3wzIte/e/gKƋ{UOV--i` Pt Usgq MzP*?g”x+%T/( s 1hP\Ob/:ÓOp?jyk6.j;&) 3kqsD0 )m~IrXIrԗjy"W\9!g$t8&n0%6^ .'>-;wp[Mc[vpaĎ'`2khz<qz/Ii1Z q6+;%sܫj6ן>i:L:L iR Y 9OP w}[死56?d_ hCiښg oiw¸%;cUvBW)7cݕ`{O,m2}ȭ7LBdr"2{6ƩiAxU*Kȓxht P3x%?ph t[Ah1l6VӋX {榄l@h]jDQDJ/fB!ɎAX 2mʥV lYt 9'b3 jrhH ERWl%/RoDYBWf( . DvKY:>k@`b5%2pg |/axr A (fK|{_"OU̲'ZuZΤF, C[ԯ3N :3v%uӼqmLmam_)aXԬ*ߦ`|줫P^{P' oL|p۷Ãoe(p"Mf>ªyoPVVo?W@0:\fme JNAU_!8lmޓ ±QX < {*␸ q-OQmʏ{ nO.3 0 ~Ph`Nur^F ? m I#D^۰jͭ2tCjCg,1:ϸF#92֘J:suzP`7wIsUJ;A-f4Rb`Rcλt\KZ2n͝epTGCt}i}Y?nC0#~8͐ζsLH06}>o>:Gx}WWY4' P]6\ywkEH^͏EÉ<~ Jv/*\ǫL[(ikwbOIgo]0uem7>snن]`Z.)tk} XņV KTؠCH9=uʀFPx8.2"CǵsO{Dԉ@ /oU#k(ȹ{ZW<@ՒecAcTIM~2ŧmcUeh]Ps.eVl?nҢeԃ4]{| ^!|ë6 $* g͝ulr?bCBN9qXjX-Z} F,{>IIcː.R<94r2[( ^&|/$H-0GT|Az,, vpa^F<+;YgA:o@<5{<*Dq&N44;i뛸 PId1! _sw=7iu!AHŽmp\j@yNfOR6~cG:v#Wo)[rÈ\g=g8~ò#kȣ 2sjR (9BC2`z^#{jJCi*?Fϙ5w5:h!Mz0)fQ¾]:A6FIwƍ!1J OXknij z(XEfyIyBC1jCl\7eJ/!3%c,PGc/4Iw\q76gOÆ_넂R@qϡC p3@.??+"`+lK%s8 y pÀ4e HytR֥'$5pI^]ɲu%c/^F״w?@ s4O}.{ˡ 1;>(\PEv>M Ҫ{/r tկ}j`O lAÛoL4V]ЫⰊ-JZB8.]+ z1jBu9DI%yܷM#x&C:WK!b׼D1L8t]~ =ϘzK Z]<ۢr$ԖRGC5MLDC,fvQbX*BjD5ఈ>c$aPjn~!hm]ލV4_Vǘ'A|.)ϗ6:uǖצMvةHpd*3jwҶ ^DgȽ>Ԇ`> /H#ݷ,Ϣ:J]8Du4Ƶx^0tbLmH+bjiDiWJdT'beTh} )bo %p^8xvԞ?y"nL\X5uvqnL-D!Uu`II.pe@v$\5P*_0h9 vVyBQw\+[Oe {@iC֗Ep,TYҼ9k{MkiY$M]'trje^}A TV8ڲt,EZ >T(^,ȻLõ~V(Y,l8d#"X^P <'b#BmNt4(!bWVw=Bgf$h2DtQM2Pg9I.::L|?t΃Wnv}7Ph` Pqr_i?/QxKrLfM*\َ3VXItkt d U .M*qRd;a#2s?5WQ-a.q/b1RMClcqڣ~+`)Y}93 BGQw;>9t_7Pdd"K_A ];_~QYe ݢ, [ Q rи9I4w#*KXioK ʒER9Xٌ|/b!*iJ\T|i&Nw"WbE.F`cRngSL uIk rt^ivDg?l*j/c ]9^UH[N9n!B(Q,G3"&^>?Q!qRsm&:cAt<9x+3VR ]ZEA(m_kȞ\j5a#Bh6pyKZ{fdUCrCrEMo,=TI{EQ2O}J3\C" h >2hV;|ztꌜdLNl} ""Q$ipN=y)l LΠWk+%[eӓ52dRB wȺ.9D]n̬.ocyk޻汍QoEqG!ΑCi^`'4zQ6{[tlтV9fGŴICV dO`i1 9PoJ=Yd$ا%M"Q(i~ۡEkTTKq=.b(ADB~-Vv|2U-i ÊVG:W2<_ey,^u~WD ˿"V:{߯Y,yyo2&2 4g; cd(&Mbx;x.u|۾^ JW (Ruk:KwOLm]xG/kFyJլTS w2HL](`75CҫK8U"(rs #T-ѲJSm10M9$kg\BdEjb*eWI8l 7'[bޟ߀9`Ip2` FCy'5SKX嫆[芳,Vx!j0瑱`8 iqPXڻP\瑱>EB $2>:f0g8fr:)uu?;OoYE}+O R&$G ΕmU,~V~Eo$^g6%ޒfl$K|Q1B֡)j8]B(aEOj+).m)D5aT9a/5e__\yh/!NK~̐C!wO}`z.|E  滍eʨ%0Yw1D;A33׉ ;g5qב`'#iu}Al{VNI>_Q ̵=eT&A6;ߌ "zv-+~?$l VJ ; !+\ythe)\ : kp !#@1 ,3]Rޟ“@kU ml&W'3ȝf,3%xNɶRG-x2*f"oJŁ8Fra d凷ff(K_CݯPQS8^~l5 l'6 g+RQ>e gV^ Oݔ%=a(tC^79e{=4z)fʨ~ũfo>*]y_$XPR6+ӂS3 ٺe< b@2y2jK n7_ry#=}By2o4uӇchwV*YkdrwG!@ ,P,eCkET]dA= 0gU{ [SN%cp]+\~e)v<*lv?e3eC8c7BP.]A ]zɅ-#t)blg\D↬%i՗^%yC)ۑ+_<`L; bN4!:ܽ*GwUW+Bd*Mv2j.Y7 DG?;rW'u1o`C/ktc prx ixHgߪCY|y`xxDX[S,UԼZ Ѷ3B͡gbdO=Fn]_ ڜ^8&L9!`623@:RZ.h tGٷ;4m$8_ {8w*3SUDI;g߰g`e[qZqtԊYɖ:"y05vbghgy*+*3H.aun>Pd>+LyO>R98YQrޮ HB.y! f$Ci\+kuqѦyavqU3:U글PtB&tQ/]k*'tkE]{Vs / ܏s"$ݦ< h)-E/x˪O qSZJj{p.Y:vmbe/k<}r5x M<,W#ansidH&f"QG*m?ש /q o/ٳk;8e#L0\P[xC|A'Ǜbɪ8&ݜL&LLs o%@ʌ-`lw<] ;57Jp{cٳK98"h^KlsPW~n2L" Ocrm]1H8}HTsSJA[?{KCb8==t^1P5IEe"ݘfҨ4B<35BQD$8_5ûbZ,t?\}GwlpqtO]n5Re9&6&<6Q4&%#ALXPx-\9΄G} #(,i)"n5Y 皟z@ pҦ$'}Z1;}VGG (0 /Xώe̎ p;hBZK5^l 0Aa+@ ܵR?^:N-Sn1 rY)'q:Fq:B=CKc9P'!fVE(@F{~$ҥYՀOI3YU}kjes{5"${RG%11LM{ʦ%'2^}sͪ6v vٔХ[ZZ27S^E#U[99hr4wva%@*bxyB6Ơ"CA)XNF "Ųoމ#d')vE!TQ&BEPe>I9Q2$6>JUrmdd fQ;_1QHS*j͖Vs7%G^h}i=JÉlFgae y3xN u\:r/_}?܍4oULjS}SnVX3}tnaz?<3LV#VFYd5&)즪.}|<žx;ڮd /2I[Kۼ|:X}3Wn;Zo+:C7钐Or)nTD|ix@(&T-v sDA6m$hw^t1&nQjXsi,][!7ꅡGQ0NcZZwύIȾz: ~|\H.~my"1 ^'ÒKpA:nl-ëC̩ xԑ)K428rB1ѐ=M>LR9pC@V;exKa)q )DU)e Fȟ4%A:Q%Uǣ#,UbI^mGB{naA (< FRM"7;HF]i0гAurXZDr%X=ҩi"UtNxa[9TUl fٮÍCW</Mpww%d}֖r<߫wW.--M(f-lӅt"lfjKk4ϧyM%B?2fw<5"5IV) \^'qa۴y%x Zb ?K{Mˉ[2;^1bK"{T%rK ^Vaһb%cx͓D!$ `E>d&kJ4x#Skw)"zscsĽJmN;@C*z/;oq-իDns)`0@ַ;Wx4%NSJ";s'FL}8Uqg6R[Z Wv$%SoVYN`[} =A I˅dV!Šhr=e6O?9CZ ,ߤ}e*ݛ /tK7&qbal_?yf~MSN/D]^Q܊pK !]/:<'ڈ(N0}jAUiPeYbw @ORD3 ʁY"iݍci#mՈ!ViP1dUٌ~s8β/OdBO.Q>,fs!V9AցK#G 2}9<cw F{@blǽmpWجEb"d1k|LX]GVeY zt0_(jxJv`C+<+P:@fg ~XxK҈ cʸ31S}ORjM-6|0MvyMƽ_-H4mW-}2wM_;88YI" nuEꆳu`tu.lMx$mW{4ZNgʈ|V!Ya^ rng>f%?8tڻ@+\n/_A,#0T_(l,3#ʲɡD&a;WJFRf<z=ņm<@ ?h'Yͬ 5bg:k rw M; 44F1J aVp(W^+#X@?7 oIzh , 8?`UP_ (r!a>JtFqOQ{ g]E? ) PSyA*y{q^(}̏?^* C@7OFrWg`qIMz69:¶L?#4s/xtnnIh&Wn=T8.Da#[lCZJS&4?z ?/sӗg-LًMQHIX!SpCQ.:AeȃpiSOtK ;{h&B^"|]af7~rFU*f/ ‛өf  >6 | _{ 9*8ɂ-`1=ds?F9HFvU3r}kG J{KbteFEX]FMbsR:;o~c$uocABf0b+C\wށ ɡ|W@*` ᰱ6 LweLt(^$`őS*=,۬сS\Ζ~2d˝}w%bHfС]H=~5| Ь=4GB6;;6ȴ6Ņ2g &\3)XZFsZ9w9Gߠ.p.Lޢj[P:|X/bk}< }:u<:1SW@Da3g g5*j0cH*~~9):ʹPN踬l=K _fOEP˯ػjo$a:U`ak㬭9ZDo O`Ohzsg^pPӁ-Ce.KV.@z}A[}S=V '[-h Ss> OIJޖ3e1?1WJCqk+%}$f7 LY ؊X5}#4*H %U80P_9ˮwnS}E6 (J+CX:&t@Z 3Z!4nu~E.o\H:٧&a հ(63' uܯ"YDu(,xv=] K[X?vv'lAI֎ajmBr<A0J w%ȩAZמqXwf|h#{A /n*MKstT%M/8WxkىCdd<& Rv!M.`ޟd )\t$Nf 3,r&+C ~/=O>jAH6eURBrℎ$ܵ/Q-# X"g Fd9tDhag E"T6Q^fvXbXlIӂ=Sr6 cvQ)/M })-`~T1wZQTɫ0{M^E-)Kvre j:-_Y7|9E,):Qr.GQ69 L L:˦?kKav6|<t3KYK,\qYD>9[<DzfW|']VՃIH7#<cu%jrxeb*(Pc}~Gٹ%bDplK̎r9t`,7BZ$n!Fߺb!? D-Gʕ?5F8}eBf}[; 7oAzqtEAϋ3s:ѯħߐAL o,*9ypk;4uM?+l\'5Z{QXS&ƳP?`i{rdۄ4IAi󀤮LyCJd lK 5| (2wW{3ǝ\aM[W! ĻVq{IN$`5SS-8'd{oȗОG&~6oWMQEsf-ի<mnpI1nys=h˾HByYJCpȸ%S=QX*sᦓW/ Ӛ9ljnN1w@Q|8ܼ9/+,EDƂVrjo/jYl<8MW*ZD d;53nwZjkS23= FM_ӢG|؇0-T{0E6vMOn>N pCsMDz~ S /p{gZRJ `6VzTc }cb0<9&&l>OOmbR R(Z}1C8fXhb| Hз6Q6Zq: ~v_&i5<%@6KB2~+1a  ku֝ש\[AX-=vC^c1 .aIS:L @UYK/ЧH#1EկںZ==$k_~yFQBf0^ͱQݍ&B+$#v'@vН kUi̻{jYsOvL}HJWrA12Dh6,TAsq(i%[QX3g-&L9Ӥ2(3üľgn_]uT ɠK?rxgr;4q:;ҩEu-uGZO6n dYs̯5MUh{E2vv os~s~Π\uz9 8mft;ק^Wzµ9jj5VsUjaJ3_o(1Y==woɵv<^!pΎrO )FT{ɀ!'Vؐ*ټԪj\ek?n7y6ڶNy67Ddץ0ռ`Ix{Tk 쐜5Dau1Zu#A)f4e>Zojm4 G9h=pZ71W4$ak`\F$M'J81 ( 75%NV kSQN$瀩#LTX+GdHAF3ZrBd9CSm$|%lnJD@z1.IjJ+Tz6߫ 2qpԮgo@@ئ CYdzi-8MSIUN"=L%:ۺ3a֥ ~ cvR.$09Lf>GBHU4#} e(J`0Sǫ^k(dw8G%*[pi7nfIX =V_EYPF 2#V>j!SHF[ Nk }3ִ 6]/oh$Ԣ=um)%+BSr_Bב8Zk]j!ZcV1s|<~^30e㐹/'Ny!nf:B1B/m_TxU`:9wBj}jU~?j7`3l?M7cBm?@Ffqc;ͯ|O vi~Qˉ|sM A1J _B0k wka[ÞqUӽeL;_k5L`)8WG]mo VT6El1#Eg0t.2@\C2ߌ!T5B6W)9 k|-uoQE(Mj*' qaE ~'uv&Eܐ)̮Cu}7C 2d#)hc腧 Vp?!7~B_ӤxhĪ#JeFZ8;Vg$~k5NL=JmX\U r0g*O4^6&g  k Qty:Hݧh8v؛/XM ^}s :E l"Y~h[O(h-U&njREp ϱ4W35q߉7 o5w,&ů ZׄaU D4eH~rǣp-k2$| @j/Ebl:(Zmmvt:B؏q@vntSG}Hl=*.UrB/})~FZc;ޜF` RuQi b2a TNJhiXwѱwQpUg(@q;)j"y97&l^'9ҩaM="g8[th,Xvd-p aszDS2e3nIxoL_ iJS1`{.&&ťg!p?0}!Q5 $T[g$mJrWajKdY}b|sGjIg$8+ ]foJUn]-gD"ۮeH g+{KATa١(2|AyLwݍOojjO|z/i6'/|R1y׋B Fu\>_R VTC>\Xh3ǗŢ.n.E)dR#bXڥ]u> Ma(.upj\ fu!8hb)_<.])]lG6;Jjğ,gRԾXCn;˝a|oʮ"dJVlUr|9i s^".a̤עzLL]j;~3{Je7&@PH IiJ=|URctWu_ǻmgp&b=ZKd{?#Ё!]7~\ ı k],π/$b0cb{]"R?KZp2 £QDv6+W S*|SfdSۤHWd\&4f A&U`8J{=\ 'Mim6'G?G'cgXkÇ+\[ݯ DE5?'ώt^iy\k{dDi;Pz#ϥ aU8n"ӞݲV~17gwv{NItJͪ"Y_Ţxt=;v0Gw %;FzPMHIwzpLƪ8ܶNCكdQXLeleR^mapns6FlovJhZvFڏ,7CvDCLHI4Z1@´29WTGX_y+2P#-l܂ 5YZ*k2C-z B kOqΨ ;',*[P)1t_~<=cTp[e,ή9^wC|с4FKS^E#8#"V>hfi9WXTT;]ȏ߰L4f|nZ4Tz;."%jA`(R :"79gFcTCAXݵ$'j/2xe!B}{XONl "ILAA;ſngtlnm]$ż g獃?{."X"(೒5VEԕӺ=R0 ɺ2յ@ z(dsD|5srO(Σ@0~4cQbU~W$#C)h--|n.d㖗{hEh.z7lC. Z(j3ڸ>EO=+iȂQh_2"HXeo=ɌܪĹYE!]Q'-Ē70(TZdhcYfr͉֒˴6vUI=:!a=i2Gi_w1zp=; ;v@Rؘaaj ҈Dp ʃ}axh= 0M]籨42At>8oRqCQD#3ō 61d/Ց$wFYڰً{(e܏ 'Cj;_H_en]0pg~ΈK{nIzC?^P!K8R:I5ޘw lz&蔓ӎnt&>OH"tEw cr^}L>{l DX/l4I"Dzydp&<2m]6$u\\%Ce'rwn;& b5?OԴ{ Vߞd NRe18r:F$lz_UĚ/N!`;~[XFnA7V9tTVW=.2 Z=g"73 ĸY檚6td-ˡNT…!jӈc_2s6 tZr0g X !0vqR5+l"G%E2&|H1%Y{qXj"e)8+q*պ]*y0gk#|z gͻQH)@d!:|W$KB)7d)? coqAS7^Lz3d.^g~ iG0V% LTM/zkLuGJ+MQ` x4Q'tNe;/M*JL}Ǵin Q'K *@q/a<' C *m!i{j8xzpci>6EL2_|hr 4H ߁rX r W)<Y!ro5d3J{CP_90*XT.v|ZrUkr7ei o Kd7ڎ/IM [ &U!D@&CYȓTPu$ݴiLq.J )~ 5Ɩ{92 oW^MVY*܎9|JjZ:(8 ->`@>}W ~n;)l `z:hZu9 90^{noS&Ļc{qM!*7O}_fՕm"a~R{B|U$Dd? ōS1T)tV<<97)t[pnV5:qW%Ў2Xk.vB%[O>]ʍj>*ԉ H$cܾ eEvɊp߁> `= 2`>l ïPW_=J~!n[j G`ŜB3<{:tD[ Xm9TMJFr&1lqJ em.]ВEvXAxvMA]}0ʝ_ʘZ,Jqt?E:);@4m B`E!b2<]@'ڍ܍| v= 8'b |@ MA%/9bg']:?T=ߵEfގ=0?Ԣ WC{ "rL'D|Oh/#`,T*K🣐/W AȢ%H{VԞ{ ?KQ$Jq(g\=q?xzquO~.^ PYݺźC\[L|2촆?tBH:0:"0A> Gl?=l;\>@z کNu驈B:#RCB/H0r<VK 28%sa ޿ YGׇG 侖9@~e"y'H)Fy3ZB"zt;x\PINEB 'ʄOtD7yO& PDž+R@kbyBWi`*~GyM`.=-B {) &4;σ5k͓H#~q .oɷ#lSL>!sɋv^Ō00`yI,@R.7t(ڬL{s#]xp){}&g|؁_Ktm 1[bw9{!Qtzm>:?X%xEC Xsjp$ʔ~Ro/6s-ݘ)EBD^_MɐX}3耢 RbND/;}o/o+8x$pX'2o1Pi4TUM4uri& =\e3aTޓ:E+\ 6 k=h(ec&QLʵZ*i>VeJ7PqM$,x"2c8ϭ(/bUka:ct xD'`wb5!D"n/d(@ɰpLZ@1~Z-)fZƙryQ!'|u0e1 ^V%WU! |U$gwB&GJzʙ&,0Bsvh,p0EcqnI.>LQ(& 9lަֲٙzvprIB/7h~GO gJUscxJFCoP%mqs}/3e5 Ľ7s1 Ed̖~EL|Zag/og3#>f0MTg3 k.yIfc%TлC}f>(Cbо@e趐{hҼz15{>$jKCL1rޔAUcD@kBJgi?_ȳΚL 1HM/$[=*bKx dSLɿSmѷ #jvUW~-77`N[1M4!WR cIE$HfUBKKv'Wl"6`h a]T鷝^ 4JF$i]`m7N{Ԫ>2 ɭxGF/E _)鋷\;=/;/NGUQ4)[eGa}{w3?䓤#?Y!><6=:9ζZ  iE# 7Mo-Dq[oV9(UHxMic @D]ݸCN:5yeYw7ēŀ6Ά5T#uT%xz5D∽78X EVe.v]pqL>줻i@:|?| xWXػmWo,G ?!$?Im{],rl0hI(՚u\;>"2G:9w_,IJ8)+R]?΅($8w*o:9{cj߻8Nӳh3qg9.mkLigaS9F8Cb(X ^=ģYB&0tr|mV#&i7p燙Igpd+~_Q8 [gVґljpqy`ͯYHM(ߊnHv pU VyFͰ*87\:?fppI[1ޥz$uWaĢ UGbK}O/i5|Lc0{ xR)kXsTQFLIr mB? ]cvVfJ\LxίZN^~mK)Ծ#&[ַ ojS;q$@_ہ}IO .sf\ƺ́uG,96&poU|GN,J*OCh@j(PI)#^VL Ʊ>q46MPwpiި:fl~˂)Qsi$C͆ȸ%`U'08əj?~ICi[. et,P >Ӫ'C7o ފShy)Qb.fnN_H[ge{#UK l3^skNK9ގ/q#xwcV}Zs. %.~$hOX}xgb ;i㟽BNR]gDIiso> Vґ 8p_v&X%{&5 ~8k (e3u?LЫ'JV]^=>|Hh2:\Q$nύJX)b޹ZTv,’5๣A^oN[E4 gݭ^ O X\ߢ?Ղ7 qx>`O¹ȟD7EDtCq!Zg [9E3 $: G#4oLd2~_"c;Px!܌]UBu-J3KQ_lP:K7!6o7#E*V;{m5֑u8 |[E - 7_]l53j?CQ0Z0eV-hvH)q\HE٥^]> QG6boo;B NYJp{8r%1EEN5c?ۯX$y-$舌'^^XҀ6cfSyֆt( uZ'?۳.r "ohQ[هٍ sI |;1JIwX9bq ZÚbxp>^)gxU# לNT.^ǔ-_jl\K e)nl?4#- +fవboDҀ/&v[RO}ߏuL-{meXL|1 b6_!:eh 0 H#Ej%=j"OMKD6쵌{oYRpݭ7莣AyVlGwg-Nnn_A+i) f?uOdlb~< ?O^:] uPM}8RSG64I:KR, b\m8YAe۬td͞-,PElWSBh66gj9䗐 cجWCJ,jn 9~Rv{u{:j5PKvD%U0Ћ0Q dx&P26.dnpGs@Q{ח8D IĨP9`mӁS$+ 2ym3&#mBdeBKX$50 BCjg2٦›^'hTg*ti%iOoΙGpLn_?@b|yÓr]Mu;bI`YHGk }`K6'K B QCiፙ~HQiѳUDE'6Ԅt"ݰ״w 7[Iސ8XK".YY3?5.#=ɞ/+B\,O &.{t!n7ΤpE=KtPn8Jg_'5qX_%|LwA~G;1drF+Bo8>FoMT7Jqnfp"ܴªRPx)_p++~o!\V‡'Z<Ur4vVUF$.E큒 X,̯)0 !JsD3: :qבEZ?9t>N?Z`Cz@ifW1)Õz}hxxdIn/?!C"#%<QɩwLCT(3Ҫ8P-n_p|AUV6M2+YB$L ',fp)U a,ry#9U3\v: B.wSC#٢JS\Xg! |W60ɛw|ws7mi8oeQB=UQᬚƤ#VmzfT;(']+x_VC2;% 6tE1:^6E|+/n\ŪT\t[ҕ"n]PrARNA2UBJQ5?zM+r@jKޏŦ36_*jjlҤ6 FWrت_\1m7'aR$ u=u$sќ79"Mע>4ɐӰ4sMeuW2?+P,`E?7U{p5~j㣌bϬY3u V˭;o8)ρqxuw.Bѡp)c*t_V[S,%IQG.`{,$'6[sڑW٦ ;>wshBvnؚป£Q.s |+k.liqrq}pJRN ;X&DǏPb=y!98]aژ|lq*~tcxN\Gg찕[f h8]AȰ>?5.5'hN @x7q7 ^q@5XT 4,Zwp{Ph])V(Ko"];-={**,t\#U$Cl19ɕJד.\%VZKm6o|&ɍmkEd <(yPFGbTMU][5 l?1/r4ÿcۣcr?/{j12J1IjCmC\ƲΫ)jK{O|U"cTE sCUΨ횚#kz lwq旋 n?>czL&ADg 7'F+LddɓeE υ?ء5B-r6=ͺzw $-F6VE`m_&N~#ƅ&*cD'z`ݾ"DŪXy1զ@^ ًtW|ԡj R%{%tD4ԃHb?GDr"ֿbLU @zVfc͇NL+<{'S"(*'GW\4|j:T7Bvb'o%W?Iv^oXЎ3W up!30=gHcnS4?z8U?rz5,V^ELlw߉u64i/B*L#R|UI,.Oխa&Ɩ'tDQQyW` TW M4k1c4b/2Kс딉"mDG:׻Ljd_#i0 8O׭RDZCW 88dK/."#+T55'DH 2pRf}+-qReOXZ>%>!#_24d.:M%r!HK&ssD4H U\U誡Á(ײΙTdqrOW!TӍ$1䥌VORxKNv`!! 'Bo dJ֎!N^'%q>/yƘK*4ppWg%^bu;sW0/L9St#kAT$Hv{g;{Qi1Ч9=BfGnHu㐌hm ?uj@ Q L_: '1]S忞,CA{AO^O䬮%?>'Qэ}#jceRJ#C6$*{rpC.L?ybj>/8絛6X?+%W˩xPhAX*#dgr 6m=FV]*1շHBf$)y?E)v <,rĘVsr<*^a*/|>.ބ!P|Ro>̝ gJ6:rmNõ)""UF%i|s{fsToI; ^aʸПVLRDtBQMٸYF=B"8ĖT- 0ږT۳ tװ}j` ,w1v9,ev~gB%R2 %@Zk}S9XBEMI|LlKYU)ʿb=)*,ݝ gJFho;7.G+\a^J>?hfZ-NDAvrWXmx#oI\2L b,ɉ3WNsx5ox wT~NLx}6 !.X tRre_Qz\V?Lw72C'׺e"5a[Nv"a.wSOm"n;d/th4 tZE[_GUYPòqCD,L4S\wpJυ?Ņ}~d.r?M`C`ž}wяdr*+CKIhKDjl# C;w~VFPÛ6LF2߁Uj0k咘l43 RFMk =>"qTRI.]15 5"t;ڕeӃ ]ILvRuTOfb0:x׬F H$tʒy45ݓEAtڏ@9fi\fP\V[1Ô@(qj"ؼ㔊HTEfb'.JU^`W%}">r踖lm2{MhE_;mGnZJZivO_TN.gER8!͟`l%Qw[}eR xXEKƭYN. W B?ST]v 8sňJe%EӪ-9W nEq42V6'I|ԝc{Khhe@b)VBmGѽ4pZTϥ1ٻdsI{LC9ľk8:_22n-x@eqj͵-*)^H!]G Ypx,MnS*I^R8i)S5;eT@̸˓MM)k?d|x٩~w0]H%]LJUz~ZB~9 !/H`**b \@e>@KN l JtvI @uP[5u;m~q('ĭDp4MԲ&Y|@_RMg)fz.FpY60<DԂS?!JٟY)Uޫ̊ae$-}ܱ~UX5 l)掂.xAmk]@[23g{5n|IiU­ib&&VOsh+Hd`,'(f,U`J[|1LJ8ˇJy,Tm̓%HlҸ_ˣDܫۖWss[,z%\j23 &2*S{9׭AOd- җ@Bc_f_^&AT'' 8ˎ]HdLȈUV ( 2[$'zʘe~NӈtZ#%JYC>n\v+ht:(E5|,LvbYn_'yuḩXNao259lY]?sbjR#ggd*&hJSoކҰ• lv"Ftێbuv r,rhC `}e= I$*~ Lvc5 l~j f"۽mhm#@sg#F\iBÏDb "TcmY4Vz:i;6,zTR_u/ҸƪԆjX]p8P[vH #JRy^:ܖi5F56]O+ Ȃ)9Vaө,ŧ«$#4k̽DV8{i' fx0xJ.hBB"t8rK*j%s]s? =9-cWgeW^Td)M0ijNVS΅Jm9B4xI/o=6+AtA%dOU!U˲aԟcbc׫^FQSTo? '_?h7 )9]I-?ȠX`UڪJ}.NjYLdu/kB=˻n8_}t5ɻ^΃]<e \HEG9vgd` ^d,H8qU+Ha<nB9Sܸ4Չl(PJrNc!'VNYʨ޻'5*iH3n"yGO~BL7" GesBu[\~ ɆGi,kn bhKz7wDBN >:} 8)DTI6/fPy4OAsԔ.WaWSBȖӒ/qn,θbĜ"-G,{][{GMK'/KO#`+],oLM NgCű{V7qB#BD{w&T$`ӟśwQ?} "ۤ[KKD)+G 9"!L 08g[Ғq;rTbn OWNNyg;Et W@Q|hU<|kyPna!9ić伭A`/3\![Bg>o`kٴPvX cq{%N~', RpFT$|XE& с uyKIl)0΂zֳFemw$!*C}Wڑ"h1YzFŸIzடj: 67an-7VKuSOMW46}A򂋹)#fPJTĜmo%AYK{ tr ?\FMCLwXGԴtdRDḗb"u#; BD!8ϷaXZ]v`4k9`O3* 3ơ:}}6U=pCp0w`"}buXrd_B ٖqp+X*m2\:|ـ1;\WO*l(}vep.dfBH%]:~wm_]V`֙Zԓ!gf>wXyY0O Sn!(9H7[3/ $xƶ6I*x\z,9Jl"xuL׽94Jٔ*mcƕ\ 3a 9V>o| 7.I{6OQeD;'^Կd kx *xBr ;t)'AT!7t9&sO3 И x~6 J0!Ez,!! j[zSD(3a4Mp=mkJ dØj;+'T1Nkظ=*yi<_8_Pxc/LY+THFI6<)*8A>Վ\6UI|oOˍGxwdM87nǜ[= B, h$?{Fqpa'JDO3aD@r?SK٬V?#q%H%~nM`"4is@ )ı/2l}?:uK+Ax%R-zOt( ?5.BZ[hCP><̉`]ZAP|;X^a[ ]d<Wٜ8 F̟D]KX=\$t#8)ҚM}bpIg6V)=P wW4OUeY+Vqm;*NR"! L;,^槚<,f "x%5tQ}3t`L ~ W\p^hyZjh:@:L"psd\]"VvB4ޣ/lr8H}DbTe 5Ws ϓ+4Ϭ0o )[2#<|`xTkj4%9Z$ wO֓ZeO i:]kٛ;f% ۯaj2k[Ͼ{J4U~/RiRV;fv^hw40;'%NKN#O><Te>.#FϢ\^hu$"w`/|y)=f0Kf7qfWU*[2"iZOXO*g⏎*Ɋn) G5巐m]V%* ZcDa~:A=q?t. glzԆw,c Q&7;TĆ(\Ym}s%u2i$tP;Ky[Q1@ġ(xQtz 1i]Nٿ}>n% i!~ ⓵!ͪn#[\j 'lJCcɻaA=`^ZnJ pX_AS"g=Aq? H(m||R!WdÚC z|V' cC'7e^'Rm/ԡcPvq۳TT&\tbNT"pUv Q`Vļ 1RJ8pPjb9Ǘx7 ^H3Rѣ| gK6N =ڧ<\SS`ڪ'ح0n_P3?d nM"({F=9>^ `#m9w?UeCmDq:Ą ~1N'TKⷣЛ¥jGp2#D"j;-G$v5B_iέ3_w^jҐ |r [ՅIs;ٝa΁ <@ou $THi'G4`3ݏiPwJjG#L39x:T :*5-\T^74 @6HMGC.xC#h -Ɏ)^By RX|2Xx]Սu: A5Rr+WkyE,^QQ1WEo_ AAT3ʗibIVzS!#7D晌`f*- Bte*aPhJ>jk(3+ڙx⫱e֊A-\O`> ]C{lxrg`7kw}/tq\Yɵ-m3e醸©щי|+2.g`iiO BLx9ّLbK&!'w;(AE }״a&2 ~ditN8Pz1gxR_Yhxnʌ pU&|70T[x+&׺)S #LTxi-35/T`{bkM<*RNv&UXbU~9z4-n!e3X}fK- r|K/+V 5\vC#4r,BE"?};/_;W)-cNg\'~|>@SaXݛufz]u@VCp\,Nα?Ve)ɭ5S. Y#@S22ԋ7u&Y_ ;'xl0E:3PeE֜ +[+FJjM@B+7\aiF0s^԰zW`tӽQ6z&z_ȴzPlܒ͙EO1򌰢@#_T洀apzٛ2{6Qu?%hDr5zMWIGU`DZP=O"pQ"M {2ev-7QKJ)ϳfx,РIK W3/D/NIt~>jDzSHWX>-2 x`NرY~qHg}f"si{:rr;eY-UҞ}1(Ah;ͽ!r+X)wKd~htN(^y{FcM0BkwoZݗXD=1Ѵ^-Cd=7U$]$nڳR[9(], @G.JߖI喊t@Q1!IŚB eJsT2u#;<)+.UFчoʼn1Ruáڄ!uI[uN޼V{$䌇5nL \lo#uq.xopYb&'KLWy$WZDjqekkKf6֊$1뿐>|d;~cLC$=ysbC_.ʷ(nCfY;j2/sK97; iPXwy{zߥ^c.=Y%zqܡtPc|=iGpޣA;LHcM_+ʥvӇ*9yn/ !H@|#F2^l0@H, wwoN0E6=BnÝL_|֎`BՂ/s˹&5X-tAB+ *1a"Qؤ*ZK-5,?R #Q.IVf4)QT `"n 5r<_1 wnƚ$Tg' 7BE;ްi̡b *߫; l kavRiHcdGӁ6{ [犸ϐ^U_!Le T+|)^#ʅ%`<l&n+*TÅE MMaABAQe>آ^g6޿ ksZj她)`ClXX_s- TZ`\hp2ⱠE On^v|u0{FxmyҽG+)#R &]ϱဆ f|`jڽrlA0O'|;dJ`-ӭK xGpϾpliOa kC~(xyQQ̲i3o:x:%\$|:w{jt;݈EH Y:3Q vQJcJy+s+rҔn>;v@(}hntKd֕?J3?}ri}}DB &,/s'g)Qa6" JDp"?^X]1I ~VKZ)heتg{q?bfCVVkQ"C|]l14 6ǁ{kh"ʀ$s /pΛ[|~Ylv`_y^c=Ǩ=:VicW2.~il'@q*jz&Z=S~叚EQBg$[tTޕ{T#9{A NE6΃has`9C{Hg 'l='x}Rzv9 p$w@(,,_A;G g.N<m"ExB7*у(݅[6thV5B -;zlXBE>qjn2. sEbXᦵא f$U5,JP/8<"EuMDP p~ọ ~c{kPML?oN36DH4.lfYTd|ׇAi+C,ގE]. /tڡVJh^iʅvy@ b[s1G'-G;yβic_Iˆ\(R꘶` r*UgMA>:AivX l<8x\IF;<Yz0pg1ÃU垣IڷHctjEɌ}1=f6b#`c*#lgF.YdޞlƞVFܚ'ncC>nM<-#¦;-h`&Rl;|9XJt?j\ Ef"&:mAV脕F*q:A7cOLwk"\;<[[`!I7Ss73? {m\m.G|yp sg*GD~?{Pkif{ՍaTUbLk gkLD=(AgP(kg;>,Ү.(KE cĘ넪Yz)c*6"CC6Aʀ"<;^P` ?1?¤ضgQ>_X(zG6JqAdMAɴKSH MKeAlqqS BxCP:+dN?2F],J{W&@h u3X/hهښ  4è'kp=SԌ5.# /]s3J9iy#M*}b%MQ&l*}5&hBD]زM] T˴$gn=rM%,;t RXw4ʶOȷuFZپúlXO\ۺ6$0KՌT4W1Bd/53=/;% nǵ(Fl-~"hQvzotm_ t*kfyp=lƱ._ݘ]TGlBlAb[l#b4Z m}'*tgMP8$n?^9&SoWt-t1[v=HTK-*TT0J,ڮX;="@rܑ!S[i'^]lIGD+j9ڿClv2FTCd$t:#œ[w~$?J$K Y`l>qy"W 5(Nj"%' hL>q}\[[W- dCFWz}G\vv^ V̘y]W#=|@k5⧛HHx]Qڻ"WW?wq{"^q^xam}f|TCOR IMA]^p#ӟ ݎi'WW~INzi|Zi+_Nk;`8j2kin8cac0`Db!| As" .?S^6[\jo6-=I#h2:koȆ5T }7secAyw1°%~I랿gTH!>R7#ӖCvͽb-螹b:I˕΢W! Q |.l{ \mz=[p)jڞZgI ʃƐM~P#VEwbtt!7øG5' Q2r:s|G2go0j 8o/1hS6z1,_SX'(<*y_|׏iYLFKc_(Yk8z!mKgwUS~ o2<ݧ gKldf)WM 8H\o;]ZG~A QM|xrI wP|rk϶\_ y:=ttk;?z4OV73!O(VH0½hx`2% jaSk"\.K~F-3&6Ra^Jx [Zìt-Q*(l*9Rd }mʼnDo |mWӦ76E!<X*v@%K;$vV!ۙvZ&{_W8[Onm#n7 ^bdf+_ЦZ#t)<߱2d̿׶S$,BB.(#1smKx*ᔼdxY@eׂ95GL^+*b" 3 % ?*J^Zer钃?nkb+bz@?͘gu 2nyG܉WaX#sáZ}8x9: NDA=al=sXg"*w^6x3XvͭbhG`#>'?2$kbiM$i^0|NF"Lnj?ͨIQRgN0/7HJ$,랼Nهh| 0k5_ړf66 f֛L,YFKSnX:Rs߮>aQ7E=q -߈k:P5:s6P2 Q5Qa\i(xd7t_*?{ԓ¡V17t {Qt;;nw/6:3|:cWڠA&3ic C[chyMXwG UQl7{bre@ =οGr˝t*/kXZl?}h$h z+7=WQcKC$+8YհI*_D|=G*J&y/o?ő&R/t̋`MeKĮfV9Zm8fvJ|IY KOD\#m<@M$rTOnTME ;i YM/2$P+y? 2.bE&7WX a|%-2͌ #B{siRfln|RW4ݞ0נ }wʩm vOmD_pE{x4 zxtN{rao֥;3\.^<Q;VH#ڋ`=ehQ*3E0.gQdQFM˥vN^uE5S=Sآ댢=1D%\5F~Ƴl< GŪc"~" fіl)]co,I4Wõk 0IefA); Ov8wլVY,Eg.O~nRqBC8\Gjx1ѰI1u+'Vɾa/*+FnPSFsϴ6r]@*_Ӎڏ6],܍/rOڻk33!^{6u'Ƌ-'hR}lRy8beY\0SʻɈ#ۘ^IHkmAzuG؏ELڔOkI - tQгT`cgxcH͸`#bozi#j= QË}1d뉜űbȡߨɧoBW?M\NnTw˕.Suh~* z0B C Aȶ>~? x>=L~RXwZbcy\ cRa9&2e()r]ZYnՇ{9X[9 s{Xuh03ds%S7Q: I^-c0AE5M/Ѝ-8:ՏkYd!# YZ